]> git.mxchange.org Git - friendica.git/blobdiff - src/Protocol/ActivityPub/Processor.php
Issue 10262: Don't accept BCC posts from non followers
[friendica.git] / src / Protocol / ActivityPub / Processor.php
index fdb97337fd93d64a793088b5b30f62cf75726a1d..aba285c1800e941029d0deaaa2449e610e7477d7 100644 (file)
@@ -21,7 +21,6 @@
 
 namespace Friendica\Protocol\ActivityPub;
 
-use Friendica\Content\PageInfo;
 use Friendica\Content\Text\BBCode;
 use Friendica\Content\Text\HTML;
 use Friendica\Content\Text\Markdown;
@@ -135,113 +134,20 @@ class Processor
        }
 
        /**
-        * Add attachment data to the item array
+        * Stire attachment data
         *
         * @param array   $activity
         * @param array   $item
-        *
-        * @return array array
         */
-       private static function constructAttachList($activity, $item)
+       private static function storeAttachments($activity, $item)
        {
                if (empty($activity['attachments'])) {
-                       return $item;
+                       return;
                }
 
-               $leading = '';
-               $trailing = '';
-
                foreach ($activity['attachments'] as $attach) {
-                       switch ($attach['type']) {
-                               case 'link':
-                                       $data = [
-                                               'url'      => $attach['url'],
-                                               'type'     => $attach['type'],
-                                               'title'    => $attach['title'] ?? '',
-                                               'text'     => $attach['desc']  ?? '',
-                                               'image'    => $attach['image'] ?? '',
-                                               'images'   => [],
-                                               'keywords' => [],
-                                       ];
-                                       $item['body'] = PageInfo::appendDataToBody($item['body'], $data);
-                                       break;
-                               default:
-                                       self::storeAttachmentAsMedia($item['uri-id'], $attach);
-
-                                       $filetype = strtolower(substr($attach['mediaType'], 0, strpos($attach['mediaType'], '/')));
-                                       if ($filetype == 'image') {
-                                               if (!empty($activity['source'])) {
-                                                       foreach ([0, 1, 2] as $size) {
-                                                               if (preg_match('#/photo/.*-' . $size . '\.#ism', $attach['url']) && 
-                                                                       strpos(preg_replace('#(/photo/.*)-[012]\.#ism', '$1-' . $size . '.', $activity['source']), $attach['url'])) {
-                                                                       continue 3;
-                                                               }
-                                                       }
-                                                       if (strpos($activity['source'], $attach['url'])) {
-                                                               continue 2;
-                                                       }
-                                               }
-
-                                               // image is the preview/thumbnail URL
-                                               if (!empty($attach['image'])) {
-                                                       $media = '[url=' . $attach['url'] . ']';
-                                                       $attach['url'] = $attach['image'];
-                                               } else {
-                                                       $media = '';
-                                               }
-
-                                               if (empty($attach['name'])) {
-                                                       $media .= '[img]' . $attach['url'] . '[/img]';
-                                               } else {
-                                                       $media .= '[img=' . $attach['url'] . ']' . $attach['name'] . '[/img]';
-                                               }
-
-                                               if (!empty($attach['image'])) {
-                                                       $media .= '[/url]';
-                                               }
-
-                                               if ($item['post-type'] == Item::PT_IMAGE) {
-                                                       $leading .= $media;
-                                               } else {
-                                                       $trailing .= $media;
-                                               }               
-                                       } elseif ($filetype == 'audio') {
-                                               if (!empty($activity['source']) && strpos($activity['source'], $attach['url'])) {
-                                                       continue 2;
-                                               }
-
-                                               if ($item['post-type'] == Item::PT_AUDIO) {
-                                                       $leading .= '[audio]' . $attach['url'] . "[/audio]\n";
-                                               } else {
-                                                       $trailing .= '[audio]' . $attach['url'] . "[/audio]\n";
-                                               }
-                                       } elseif ($filetype == 'video') {
-                                               if (!empty($activity['source']) && strpos($activity['source'], $attach['url'])) {
-                                                       continue 2;
-                                               }
-
-                                               if ($item['post-type'] == Item::PT_VIDEO) {
-                                                       $leading .= '[video]' . $attach['url'] . "[/video]\n";
-                                               } else {
-                                                       $trailing .= '[video]' . $attach['url'] . "[/video]\n";
-                                               }
-                                       }
-                       }
-               }
-
-               if (!empty($leading) && !empty(trim($item['body']))) {
-                       $item['body'] = $leading . "[hr]\n" . $item['body'];
-               } elseif (!empty($leading)) {
-                       $item['body'] = $leading;
-               }
-
-               if (!empty($trailing) && !empty(trim($item['body']))) {
-                       $item['body'] = $item['body'] . "\n[hr]" . $trailing;
-               } elseif (!empty($trailing)) {
-                       $item['body'] = $trailing;
+                       self::storeAttachmentAsMedia($item['uri-id'], $attach);
                }
-
-               return $item;
        }
 
        /**
@@ -265,7 +171,7 @@ class Processor
 
                $item = self::processContent($activity, $item);
 
-               $item = self::constructAttachList($activity, $item);
+               self::storeAttachments($activity, $item);
 
                if (empty($item)) {
                        return;
@@ -399,7 +305,7 @@ class Processor
 
                $item['plink'] = $activity['alternate-url'] ?? $item['uri'];
 
-               $item = self::constructAttachList($activity, $item);
+               self::storeAttachments($activity, $item);
 
                // We received the post via AP, so we set the protocol of the server to AP
                $contact = Contact::getById($item['author-id'], ['gsid']);
@@ -557,6 +463,7 @@ class Processor
                if (!empty($activity['source'])) {
                        $item['body'] = $activity['source'];
                        $item['raw-body'] = $content;
+                       $item['body'] = Item::improveSharedDataInBody($item);
                } else {
                        if (empty($activity['directmessage']) && ($item['thr-parent'] != $item['uri']) && ($item['gravity'] == GRAVITY_COMMENT)) {
                                $item_private = !in_array(0, $activity['item_receiver']);
@@ -695,6 +602,12 @@ class Processor
                                continue;
                        }
 
+                       if (!$item['isForum'] && ($receiver != 0) && ($item['gravity'] == GRAVITY_PARENT) &&
+                               ($item['post-reason'] == Item::PR_BCC) && !Contact::isSharingByURL($activity['author'], $receiver)) {
+                               Logger::info('Top level post via BCC from a non follower, ignoring', ['uid' => $receiver, 'contact' => $item['contact-id']]);
+                               continue;
+                       }
+
                        if (DI::pConfig()->get($receiver, 'system', 'accept_only_sharer', false) && ($receiver != 0) && ($item['gravity'] == GRAVITY_PARENT)) {
                                $skip = !Contact::isSharingByURL($activity['author'], $receiver);
 
@@ -863,12 +776,12 @@ class Processor
 
                $object = ActivityPub::fetchContent($url, $uid);
                if (empty($object)) {
-                       Logger::log('Activity ' . $url . ' was not fetchable, aborting.');
+                       Logger::notice('Activity was not fetchable, aborting.', ['url' => $url]);
                        return '';
                }
 
                if (empty($object['id'])) {
-                       Logger::log('Activity ' . $url . ' has got not id, aborting. ' . json_encode($object));
+                       Logger::notice('Activity has got not id, aborting. ', ['url' => $url, 'object' => $object]);
                        return '';
                }
 
@@ -1019,7 +932,7 @@ class Processor
                        DBA::update('contact', ['hub-verify' => $activity['id'], 'protocol' => Protocol::ACTIVITYPUB], ['id' => $cid]);
                }
 
-               Logger::log('Follow user ' . $uid . ' from contact ' . $cid . ' with id ' . $activity['id']);
+               Logger::notice('Follow user ' . $uid . ' from contact ' . $cid . ' with id ' . $activity['id']);
        }
 
        /**