Files
NodeBB/src/activitypub/inbox.js

397 lines
11 KiB
JavaScript
Raw Normal View History

'use strict';
2024-01-16 12:00:50 -05:00
const winston = require('winston');
const nconf = require('nconf');
2024-01-16 12:00:50 -05:00
const db = require('../database');
const privileges = require('../privileges');
const user = require('../user');
const posts = require('../posts');
const topics = require('../topics');
const categories = require('../categories');
const notifications = require('../notifications');
2024-04-06 19:00:52 +02:00
const flags = require('../flags');
2023-12-13 13:15:03 -05:00
const activitypub = require('.');
const socketHelpers = require('../socket.io/helpers');
const helpers = require('./helpers');
const inbox = module.exports;
function reject(type, object, target, senderType = 'uid', id = 0) {
activitypub.send(senderType, id, target, {
type: 'Reject',
object: {
type,
target,
object,
},
});
}
2024-01-16 12:00:50 -05:00
inbox.create = async (req) => {
const { object } = req.body;
// Temporary, reject non-public notes.
if (![...object.to, ...object.cc].includes(activitypub._constants.publicAddress)) {
throw new Error('[[error:activitypub.not-implemented]]');
}
const response = await activitypub.notes.assert(0, object);
if (response) {
winston.verbose(`[activitypub/inbox] Parsing ${response.count} notes into topic ${response.tid}`);
}
2024-01-16 13:55:58 -05:00
};
inbox.update = async (req) => {
const { actor, object } = req.body;
// Origin checking
const actorHostname = new URL(actor).hostname;
const objectHostname = new URL(object.id).hostname;
if (actorHostname !== objectHostname) {
throw new Error('[[error:activitypub.origin-mismatch]]');
}
2024-01-16 13:55:58 -05:00
2024-01-26 16:48:16 -05:00
switch (object.type) {
case 'Note': {
const postData = await activitypub.mocks.post(object);
const exists = await posts.exists(object.id);
try {
if (exists) {
await posts.edit(postData);
} else {
await activitypub.notes.assert(0, object.id);
}
} catch (e) {
reject('Update', object, actor);
2024-02-28 13:14:15 -05:00
}
2024-01-26 16:48:16 -05:00
break;
}
case 'Person': {
await activitypub.actors.assert(object.id, { update: true });
2024-01-26 16:48:16 -05:00
break;
}
2024-01-16 12:00:50 -05:00
}
};
inbox.like = async (req) => {
const { actor, object } = req.body;
2024-04-10 00:20:16 +02:00
const { type, id } = await activitypub.helpers.resolveLocalId(object.id);
2024-03-07 13:46:20 -05:00
2024-02-06 15:20:30 -05:00
if (type !== 'post' || !(await posts.exists(id))) {
return reject('Like', object, actor);
}
const allowed = await privileges.posts.can('posts:upvote', id, activitypub._constants.uid);
if (!allowed) {
winston.info(`[activitypub/inbox.like] ${id} not allowed to be upvoted.`);
return reject('Like', object, actor);
}
2024-02-07 12:50:26 -05:00
winston.info(`[activitypub/inbox/like] id ${id} via ${actor}`);
const result = await posts.upvote(id, actor);
socketHelpers.upvote(result, 'notifications:upvoted-your-post-in');
};
inbox.announce = async (req) => {
const { actor, object, published, to, cc } = req.body;
let timestamp = new Date(published);
2024-02-14 10:23:06 -05:00
timestamp = timestamp.toString() !== 'Invalid Date' ? timestamp.getTime() : Date.now();
const assertion = await activitypub.actors.assert(actor);
if (!assertion) {
throw new Error('[[error:activitypub.invalid-id]]');
}
2024-02-07 12:28:27 -05:00
let tid;
let pid;
if (String(object.id).startsWith(nconf.get('url'))) {
// Local object
const { type, id } = await activitypub.helpers.resolveLocalId(object.id);
if (type !== 'post' || !(await posts.exists(id))) {
throw new Error('[[error:activitypub.invalid-id]]');
}
2024-02-07 12:28:27 -05:00
pid = id;
tid = await posts.getPostField(id, 'tid');
socketHelpers.sendNotificationToPostOwner(pid, actor, 'announce', 'notifications:activitypub.announce');
} else {
// Remote object
const isFollowed = await db.sortedSetCard(`followersRemote:${actor}`);
if (!isFollowed) {
winston.info(`[activitypub/inbox.announce] Rejecting ${object.id} via ${actor} due to no followers`);
reject('Announce', object, actor);
return;
}
pid = object.id;
pid = await activitypub.resolveId(0, pid); // in case wrong id is passed-in; unlikely, but still.
if (!pid) {
return;
}
({ tid } = await activitypub.notes.assert(0, pid, { skipChecks: true })); // checks skipped; done above.
2024-02-12 15:25:49 -05:00
if (!tid) {
return;
}
await topics.updateLastPostTime(tid, timestamp);
await activitypub.notes.updateLocalRecipients(pid, { to, cc });
await activitypub.notes.syncUserInboxes(tid);
}
2024-02-07 12:28:27 -05:00
2024-02-07 12:50:26 -05:00
winston.info(`[activitypub/inbox/announce] Parsing id ${pid}`);
2024-02-07 12:28:27 -05:00
// No double-announce allowed
const existing = await topics.events.find(tid, {
type: 'announce',
uid: actor,
pid,
});
if (existing.length) {
await topics.events.purge(tid, existing);
}
await topics.events.log(tid, {
type: 'announce',
uid: actor,
href: `/post/${encodeURIComponent(pid)}`,
2024-02-07 12:28:27 -05:00
pid,
timestamp,
});
};
inbox.follow = async (req) => {
2024-04-10 00:30:46 +02:00
const { actor, object, id: followId } = req.body;
// Sanity checks
const { type, id } = await helpers.resolveLocalId(object.id);
if (!['category', 'user'].includes(type)) {
throw new Error('[[error:activitypub.invalid-id]]');
}
2024-03-07 13:46:20 -05:00
const assertion = await activitypub.actors.assert(actor);
if (!assertion) {
throw new Error('[[error:activitypub.invalid-id]]');
}
if (type === 'user') {
const exists = await user.exists(id);
if (!exists) {
throw new Error('[[error:invalid-uid]]');
}
2024-03-07 13:46:20 -05:00
const isFollowed = await inbox.isFollowed(actor, id);
if (isFollowed) {
// No additional parsing required
return;
}
const now = Date.now();
2024-03-07 13:46:20 -05:00
await db.sortedSetAdd(`followersRemote:${id}`, now, actor);
const followerRemoteCount = await db.sortedSetCard(`followersRemote:${id}`);
await user.setUserField(id, 'followerRemoteCount', followerRemoteCount);
2024-03-07 13:46:20 -05:00
user.onFollow(actor, id);
activitypub.send('uid', id, actor, {
type: 'Accept',
object: {
2024-04-10 00:30:46 +02:00
id: followId,
type: 'Follow',
2024-03-07 13:46:20 -05:00
actor,
2024-04-10 00:30:46 +02:00
object: object.id,
},
});
} else if (type === 'category') {
const [exists, allowed] = await Promise.all([
categories.exists(id),
privileges.categories.can('read', id, 'activitypub._constants.uid'),
]);
if (!exists) {
throw new Error('[[error:invalid-cid]]');
}
if (!allowed) {
return reject('Follow', object, actor);
}
2024-03-07 13:46:20 -05:00
const watchState = await categories.getWatchState([id], actor);
if (watchState[0] !== categories.watchStates.tracking) {
2024-03-07 13:46:20 -05:00
await user.setCategoryWatchState(actor, id, categories.watchStates.tracking);
}
2024-03-07 13:46:20 -05:00
activitypub.send('cid', id, actor, {
type: 'Accept',
object: {
2024-04-10 00:30:46 +02:00
id: followId,
type: 'Follow',
2024-03-07 13:46:20 -05:00
actor,
object: object.id,
},
});
}
};
inbox.isFollowed = async (actorId, uid) => {
if (actorId.indexOf('@') === -1 || parseInt(uid, 10) <= 0) {
return false;
}
return await db.isSortedSetMember(`followersRemote:${uid}`, actorId);
};
2023-12-13 13:15:03 -05:00
inbox.accept = async (req) => {
const { actor, object } = req.body;
2023-12-13 13:15:03 -05:00
const { type } = object;
const { type: localType, id: uid } = await helpers.resolveLocalId(object.actor);
if (localType !== 'user' || !uid) {
throw new Error('[[error:invalid-uid]]');
}
const assertion = await activitypub.actors.assert(actor);
if (!assertion) {
throw new Error('[[error:activitypub.invalid-id]]');
}
2023-12-13 13:15:03 -05:00
if (type === 'Follow') {
if (!await db.isSortedSetMember(`followRequests:${uid}`, actor)) {
if (await db.isSortedSetMember(`followingRemote:${uid}`, actor)) return; // already following
return reject('Accept', req.body, actor); // not following, not requested, so reject to hopefully stop retries
}
2023-12-13 13:15:03 -05:00
const now = Date.now();
await Promise.all([
db.sortedSetRemove(`followRequests:${uid}`, actor),
db.sortedSetAdd(`followingRemote:${uid}`, now, actor),
db.sortedSetAdd(`followersRemote:${actor}`, now, uid), // for followers backreference and notes assertion checking
]);
const followingRemoteCount = await db.sortedSetCard(`followingRemote:${uid}`);
await user.setUserField(uid, 'followingRemoteCount', followingRemoteCount);
2023-12-13 13:15:03 -05:00
}
};
inbox.undo = async (req) => {
// todo: "actor" in this case should be the one in object, no?
const { actor, object } = req.body;
2023-12-13 13:15:03 -05:00
const { type } = object;
if (actor !== object.actor) {
throw new Error('[[error:activitypub.actor-mismatch]]');
}
const assertion = await activitypub.actors.assert(actor);
if (!assertion) {
throw new Error('[[error:activitypub.invalid-id]]');
}
2023-12-13 13:15:03 -05:00
let { type: localType, id } = await helpers.resolveLocalId(object.object);
winston.info(`[activitypub/inbox/undo] ${type} ${localType && id ? `${localType} ${id}` : object.object} via ${actor}`);
2024-02-07 12:50:26 -05:00
switch (type) {
case 'Follow': {
switch (localType) {
case 'user': {
const exists = await user.exists(id);
if (!exists) {
throw new Error('[[error:invalid-uid]]');
}
await db.sortedSetRemove(`followersRemote:${id}`, actor);
const followerRemoteCount = await db.sortedSetCard(`followerRemote:${id}`);
await user.setUserField(id, 'followerRemoteCount', followerRemoteCount);
notifications.rescind(`follow:${id}:uid:${actor}`);
break;
}
case 'category': {
const exists = await categories.exists(id);
if (!exists) {
throw new Error('[[error:invalid-cid]]');
}
await user.setCategoryWatchState(actor, id, categories.watchStates.notwatching);
break;
}
}
break;
}
case 'Like': {
const exists = await posts.exists(id);
if (localType !== 'post' || !exists) {
throw new Error('[[error:invalid-pid]]');
}
const allowed = await privileges.posts.can('posts:upvote', id, activitypub._constants.uid);
if (!allowed) {
winston.info(`[activitypub/inbox.like] ${id} not allowed to be upvoted.`);
reject('Like', object, actor);
break;
}
await posts.unvote(id, actor);
notifications.rescind(`upvote:post:${id}:uid:${actor}`);
break;
}
case 'Announce': {
id = id || object.object; // remote announces
const exists = await posts.exists(id);
if (!exists) {
winston.verbose(`[activitypub/inbox/undo] Attempted to undo announce of ${id} but couldn't find it, so doing nothing.`);
}
const tid = await posts.getPostField(id, 'tid');
const existing = await topics.events.find(tid, {
type: 'announce',
uid: actor,
pid: id,
});
if (existing.length) {
await topics.events.purge(tid, existing);
}
notifications.rescind(`announce:post:${id}:uid:${actor}`);
2024-04-14 02:02:17 +02:00
break;
}
case 'Flag': {
if (!Array.isArray(object.object)) {
object.object = [object.object];
}
await Promise.all(object.object.map(async (subject) => {
const { type, id } = await activitypub.helpers.resolveLocalId(subject.id);
try {
await flags.rescindReport(type, id, actor);
} catch (e) {
reject('Undo', { type: 'Flag', object: [subject] }, actor);
}
}));
break;
}
2023-12-13 13:15:03 -05:00
}
};
2024-04-06 19:00:52 +02:00
inbox.flag = async (req) => {
const { actor, object, content } = req.body;
const objects = Array.isArray(object) ? object : [object];
// Check if the actor is valid
if (!await activitypub.actors.assert(actor)) {
2024-04-06 19:10:49 +02:00
return reject('Flag', objects, actor);
2024-04-06 19:00:52 +02:00
}
2024-04-10 00:06:24 +02:00
await Promise.all(objects.map(async (subject, index) => {
const { type, id } = await activitypub.helpers.resolveObjects(subject.id);
2024-04-06 19:00:52 +02:00
try {
await flags.create(activitypub.helpers.mapToLocalType(type), id, actor, content);
2024-04-06 19:00:52 +02:00
} catch (e) {
reject('Flag', objects[index], actor);
}
}));
};