From 6ed010b19238be79435238df604a78b2e10e9c4b Mon Sep 17 00:00:00 2001 From: Johann150 Date: Sun, 1 May 2022 12:23:34 +0200 Subject: fix _misskey_content of quote renotes (#8533) --- packages/backend/src/services/note/create.ts | 2 ++ 1 file changed, 2 insertions(+) (limited to 'packages/backend/src/services/note') diff --git a/packages/backend/src/services/note/create.ts b/packages/backend/src/services/note/create.ts index f14bc2059b..ceb5e8cc71 100644 --- a/packages/backend/src/services/note/create.ts +++ b/packages/backend/src/services/note/create.ts @@ -187,6 +187,8 @@ export default async (user: { id: User['id']; username: User['username']; host: if (data.text) { data.text = data.text.trim(); + } else { + data.text = null; } let tags = data.apHashtags; -- cgit v1.3.1-freya From edfded7fb7e55a83b21256469fd3a58dec1bfe20 Mon Sep 17 00:00:00 2001 From: Johann150 Date: Thu, 19 May 2022 13:40:16 +0200 Subject: fix(activitypub): add authorization checks (#8534) * fix spelling * fix(activitypub): add authorization checks --- .../src/remote/activitypub/kernel/announce/note.ts | 3 +++ .../src/remote/activitypub/kernel/delete/index.ts | 22 +++++++++++----------- .../src/remote/activitypub/kernel/undo/announce.ts | 1 + .../backend/src/services/note/reaction/create.ts | 5 +++++ 4 files changed, 20 insertions(+), 11 deletions(-) (limited to 'packages/backend/src/services/note') diff --git a/packages/backend/src/remote/activitypub/kernel/announce/note.ts b/packages/backend/src/remote/activitypub/kernel/announce/note.ts index 680749f4d8..052751c654 100644 --- a/packages/backend/src/remote/activitypub/kernel/announce/note.ts +++ b/packages/backend/src/remote/activitypub/kernel/announce/note.ts @@ -9,6 +9,7 @@ import { fetchMeta } from '@/misc/fetch-meta.js'; import { getApLock } from '@/misc/app-lock.js'; import { parseAudience } from '../../audience.js'; import { StatusError } from '@/misc/fetch.js'; +import { Notes } from '@/models/index.js'; const logger = apLogger; @@ -52,6 +53,8 @@ export default async function(resolver: Resolver, actor: CacheableRemoteUser, ac throw e; } + if (!await Notes.isVisibleForMe(renote, actor)) return 'skip: invalid actor for this activity'; + logger.info(`Creating the (Re)Note: ${uri}`); const activityAudience = await parseAudience(actor, activity.to, activity.cc); diff --git a/packages/backend/src/remote/activitypub/kernel/delete/index.ts b/packages/backend/src/remote/activitypub/kernel/delete/index.ts index 4c06a9de0b..c7064f553b 100644 --- a/packages/backend/src/remote/activitypub/kernel/delete/index.ts +++ b/packages/backend/src/remote/activitypub/kernel/delete/index.ts @@ -13,37 +13,37 @@ export default async (actor: CacheableRemoteUser, activity: IDelete): Promise Date: Tue, 24 May 2022 10:12:42 +0200 Subject: fix: wrong type for isVisibleForMe --- packages/backend/src/remote/activitypub/kernel/announce/note.ts | 2 +- packages/backend/src/services/note/reaction/create.ts | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) (limited to 'packages/backend/src/services/note') diff --git a/packages/backend/src/remote/activitypub/kernel/announce/note.ts b/packages/backend/src/remote/activitypub/kernel/announce/note.ts index 052751c654..759cb4ae83 100644 --- a/packages/backend/src/remote/activitypub/kernel/announce/note.ts +++ b/packages/backend/src/remote/activitypub/kernel/announce/note.ts @@ -53,7 +53,7 @@ export default async function(resolver: Resolver, actor: CacheableRemoteUser, ac throw e; } - if (!await Notes.isVisibleForMe(renote, actor)) return 'skip: invalid actor for this activity'; + if (!await Notes.isVisibleForMe(renote, actor.id)) return 'skip: invalid actor for this activity'; logger.info(`Creating the (Re)Note: ${uri}`); diff --git a/packages/backend/src/services/note/reaction/create.ts b/packages/backend/src/services/note/reaction/create.ts index 5cb7ebdcd1..83d302826a 100644 --- a/packages/backend/src/services/note/reaction/create.ts +++ b/packages/backend/src/services/note/reaction/create.ts @@ -28,7 +28,7 @@ export default async (user: { id: User['id']; host: User['host']; }, note: Note, } // check visibility - if (!await Notes.isVisibleForMe(note, user)) { + if (!await Notes.isVisibleForMe(note, user.id)) { throw new IdentifiableError('68e9d2d1-48bf-42c2-b90a-b20e09fd3d48', 'Note not accessible for you.'); } -- cgit v1.3.1-freya