diff options
| author | dakkar <dakkar@thenautilus.net> | 2024-05-14 16:58:06 +0100 |
|---|---|---|
| committer | dakkar <dakkar@thenautilus.net> | 2024-05-14 16:58:06 +0100 |
| commit | 42d9da161b56d38a04fb4f25c7d063bdea880ff0 (patch) | |
| tree | 7186a31f8e5219e26932ce9b1d649a12bc3f98ab /packages/backend/src/core/NoteCreateService.ts | |
| parent | merge: always align code to the left - fixes #436 (!453) (diff) | |
| download | sharkey-42d9da161b56d38a04fb4f25c7d063bdea880ff0.tar.gz sharkey-42d9da161b56d38a04fb4f25c7d063bdea880ff0.tar.bz2 sharkey-42d9da161b56d38a04fb4f25c7d063bdea880ff0.zip | |
first basic protection - #524
Diffstat (limited to 'packages/backend/src/core/NoteCreateService.ts')
| -rw-r--r-- | packages/backend/src/core/NoteCreateService.ts | 8 |
1 files changed, 8 insertions, 0 deletions
diff --git a/packages/backend/src/core/NoteCreateService.ts b/packages/backend/src/core/NoteCreateService.ts index 631d7074bd..d51315f71f 100644 --- a/packages/backend/src/core/NoteCreateService.ts +++ b/packages/backend/src/core/NoteCreateService.ts @@ -627,6 +627,14 @@ export class NoteCreateService implements OnApplicationShutdown { userHost: user.host, }); + // should really not happen, but better safe than sorry + if (data.reply?.id === insert.id) { + throw new Error("A note can't reply to itself"); + } + if (data.renote?.id === insert.id) { + throw new Error("A note can't renote itself"); + } + if (data.uri != null) insert.uri = data.uri; if (data.url != null) insert.url = data.url; |