You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

111 lines
3.1 KiB

Support for import/export of instance-level domain blocks/allows for 4.x w/ additional fixes (#20597) * Allow import/export of instance-level domain blocks/allows (#1754) * Allow import/export of instance-level domain blocks/allows. Fixes #15095 * Pacify circleci * Address simple code review feedback * Add headers to exported CSV * Extract common import/export functionality to AdminExportControllerConcern * Add additional fields to instance-blocked domain export * Address review feedback * Split instance domain block/allow import/export into separate pages/controllers * Address code review feedback * Pacify DeepSource * Work around Paperclip::HasAttachmentFile for Rails 6 * Fix deprecated API warning in export tests * Remove after_commit workaround (cherry picked from commit 94e98864e39c010635e839fea984f2b4893bef1a) * Add confirmation page when importing blocked domains (#1773) * Move glitch-soc-specific strings to glitch-soc-specific locale files * Add confirmation page when importing blocked domains (cherry picked from commit b91196f4b73fff91997b8077619ae25b6d04a59e) * Fix authorization check in domain blocks controller (cherry picked from commit 75279377583c6e2aa04cc8d7380c593979630b38) * Fix error strings for domain blocks and email-domain blocks Corrected issue with non-error message used for Mastodon:NotPermittedError in Domain Blocks Corrected issue Domain Blocks using the Email Domain Blocks message on ActionContoller::ParameterMissing Corrected issue with Email Domain Blocks using the not_permitted string from "custom emojii's" * Ran i18n-tasks normalize to address test failure * Removed unused admin.export_domain_blocks.not_permitted string Removing unused string as indicated by Check i18n * Fix tests (cherry picked from commit 9094c2f52c24e1c00b594e7c11cd00e4a07eb431) * Fix domain block export not exporting blocks with only media rejection (cherry picked from commit 26ff48ee48a5c03a2a4b0bd03fd322529e6bd960) * Fix various issues with domain block import - stop using Paperclip for processing domain allow/block imports - stop leaving temporary files - better error handling - assume CSV files are UTF-8-encoded (cherry picked from commit cad824d8f501b95377e4f0a957e5a00d517a1902) Co-authored-by: Levi Bard <taktaktaktaktaktaktaktaktaktak@gmail.com> Co-authored-by: Claire <claire.github-309c@sitedethib.com>
2 years ago
  1. # frozen_string_literal: true
  2. # == Schema Information
  3. #
  4. # Table name: domain_blocks
  5. #
  6. # id :bigint(8) not null, primary key
  7. # domain :string default(""), not null
  8. # created_at :datetime not null
  9. # updated_at :datetime not null
  10. # severity :integer default("silence")
  11. # reject_media :boolean default(FALSE), not null
  12. # reject_reports :boolean default(FALSE), not null
  13. # private_comment :text
  14. # public_comment :text
  15. # obfuscate :boolean default(FALSE), not null
  16. #
  17. class DomainBlock < ApplicationRecord
  18. include Paginable
  19. include DomainNormalizable
  20. include DomainMaterializable
  21. enum severity: { silence: 0, suspend: 1, noop: 2 }
  22. validates :domain, presence: true, uniqueness: true, domain: true
  23. has_many :accounts, foreign_key: :domain, primary_key: :domain
  24. delegate :count, to: :accounts, prefix: true
  25. scope :matches_domain, ->(value) { where(arel_table[:domain].matches("%#{value}%")) }
  26. scope :with_user_facing_limitations, -> { where(severity: [:silence, :suspend]) }
  27. scope :with_limitations, -> { where(severity: [:silence, :suspend]).or(where(reject_media: true)) }
  28. scope :by_severity, -> { order(Arel.sql('(CASE severity WHEN 0 THEN 1 WHEN 1 THEN 2 WHEN 2 THEN 0 END), domain')) }
  29. def to_log_human_identifier
  30. domain
  31. end
  32. def policies
  33. if suspend?
  34. [:suspend]
  35. else
  36. [severity.to_sym, reject_media? ? :reject_media : nil, reject_reports? ? :reject_reports : nil].reject { |policy| policy == :noop || policy.nil? }
  37. end
  38. end
  39. class << self
  40. def suspend?(domain)
  41. !!rule_for(domain)&.suspend?
  42. end
  43. def silence?(domain)
  44. !!rule_for(domain)&.silence?
  45. end
  46. def reject_media?(domain)
  47. !!rule_for(domain)&.reject_media?
  48. end
  49. def reject_reports?(domain)
  50. !!rule_for(domain)&.reject_reports?
  51. end
  52. alias blocked? suspend?
  53. def rule_for(domain)
  54. return if domain.blank?
  55. uri = Addressable::URI.new.tap { |u| u.host = domain.strip.gsub(/[\/]/, '') }
  56. segments = uri.normalized_host.split('.')
  57. variants = segments.map.with_index { |_, i| segments[i..-1].join('.') }
  58. where(domain: variants).order(Arel.sql('char_length(domain) desc')).first
  59. rescue Addressable::URI::InvalidURIError, IDN::Idna::IdnaError
  60. nil
  61. end
  62. end
  63. def stricter_than?(other_block)
  64. return true if suspend?
  65. return false if other_block.suspend? && (silence? || noop?)
  66. return false if other_block.silence? && noop?
  67. (reject_media || !other_block.reject_media) && (reject_reports || !other_block.reject_reports)
  68. end
  69. def affected_accounts_count
  70. scope = suspend? ? accounts.where(suspended_at: created_at) : accounts.where(silenced_at: created_at)
  71. scope.count
  72. end
  73. def public_domain
  74. return domain unless obfuscate?
  75. length = domain.size
  76. visible_ratio = length / 4
  77. domain.chars.map.with_index do |chr, i|
  78. if i > visible_ratio && i < length - visible_ratio && chr != '.'
  79. '*'
  80. else
  81. chr
  82. end
  83. end.join
  84. end
  85. def domain_digest
  86. Digest::SHA256.hexdigest(domain)
  87. end
  88. end