You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

80 lines
3.2 KiB

  1. # frozen_string_literal: true
  2. class ActivityPub::FetchRemoteActorService < BaseService
  3. include JsonLdHelper
  4. include DomainControlHelper
  5. include WebfingerHelper
  6. class Error < StandardError; end
  7. SUPPORTED_TYPES = %w(Application Group Organization Person Service).freeze
  8. # Does a WebFinger roundtrip on each call, unless `only_key` is true
  9. def call(uri, id: true, prefetched_body: nil, break_on_redirect: false, only_key: false, suppress_errors: true, request_id: nil)
  10. return if domain_not_allowed?(uri)
  11. return ActivityPub::TagManager.instance.uri_to_actor(uri) if ActivityPub::TagManager.instance.local_uri?(uri)
  12. @json = begin
  13. if prefetched_body.nil?
  14. fetch_resource(uri, id)
  15. else
  16. body_to_json(prefetched_body, compare_id: id ? uri : nil)
  17. end
  18. rescue Oj::ParseError
  19. raise Error, "Error parsing JSON-LD document #{uri}"
  20. end
  21. raise Error, "Error fetching actor JSON at #{uri}" if @json.nil?
  22. raise Error, "Unsupported JSON-LD context for document #{uri}" unless supported_context?
  23. raise Error, "Unexpected object type for actor #{uri} (expected any of: #{SUPPORTED_TYPES})" unless expected_type?
  24. raise Error, "Actor #{uri} has moved to #{@json['movedTo']}" if break_on_redirect && @json['movedTo'].present?
  25. raise Error, "Actor #{uri} has no 'preferredUsername', which is a requirement for Mastodon compatibility" unless @json['preferredUsername'].present?
  26. @uri = @json['id']
  27. @username = @json['preferredUsername']
  28. @domain = Addressable::URI.parse(@uri).normalized_host
  29. check_webfinger! unless only_key
  30. ActivityPub::ProcessAccountService.new.call(@username, @domain, @json, only_key: only_key, verified_webfinger: !only_key, request_id: request_id)
  31. rescue Error => e
  32. Rails.logger.debug { "Fetching actor #{uri} failed: #{e.message}" }
  33. raise unless suppress_errors
  34. end
  35. private
  36. def check_webfinger!
  37. webfinger = webfinger!("acct:#{@username}@#{@domain}")
  38. confirmed_username, confirmed_domain = split_acct(webfinger.subject)
  39. if @username.casecmp(confirmed_username).zero? && @domain.casecmp(confirmed_domain).zero?
  40. raise Error, "Webfinger response for #{@username}@#{@domain} does not loop back to #{@uri}" if webfinger.link('self', 'href') != @uri
  41. return
  42. end
  43. webfinger = webfinger!("acct:#{confirmed_username}@#{confirmed_domain}")
  44. @username, @domain = split_acct(webfinger.subject)
  45. raise Webfinger::RedirectError, "Too many webfinger redirects for URI #{@uri} (stopped at #{@username}@#{@domain})" unless confirmed_username.casecmp(@username).zero? && confirmed_domain.casecmp(@domain).zero?
  46. raise Error, "Webfinger response for #{@username}@#{@domain} does not loop back to #{@uri}" if webfinger.link('self', 'href') != @uri
  47. rescue Webfinger::RedirectError => e
  48. raise Error, e.message
  49. rescue Webfinger::Error => e
  50. raise Error, "Webfinger error when resolving #{@username}@#{@domain}: #{e.message}"
  51. end
  52. def split_acct(acct)
  53. acct.gsub(/\Aacct:/, '').split('@')
  54. end
  55. def supported_context?
  56. super(@json)
  57. end
  58. def expected_type?
  59. equals_or_includes_any?(@json['type'], SUPPORTED_TYPES)
  60. end
  61. end