diff options
| author | Akihiko Odaki <nekomanma@pixiv.co.jp> | 2018-04-02 18:36:47 +0900 |
|---|---|---|
| committer | Akihiko Odaki <nekomanma@pixiv.co.jp> | 2018-04-02 18:36:47 +0900 |
| commit | 69763ac32b4e79e84d8338ba8e20b83add9d8560 (patch) | |
| tree | a3ac499dac06decbc8c47a3d393336f5fbedc56a /src/processor/http/process-inbox.ts | |
| parent | Distribute posts from remote (diff) | |
| download | sharkey-69763ac32b4e79e84d8338ba8e20b83add9d8560.tar.gz sharkey-69763ac32b4e79e84d8338ba8e20b83add9d8560.tar.bz2 sharkey-69763ac32b4e79e84d8338ba8e20b83add9d8560.zip | |
Resolve account by signature in inbox
Diffstat (limited to 'src/processor/http/process-inbox.ts')
| -rw-r--r-- | src/processor/http/process-inbox.ts | 38 |
1 files changed, 38 insertions, 0 deletions
diff --git a/src/processor/http/process-inbox.ts b/src/processor/http/process-inbox.ts new file mode 100644 index 0000000000..78c20f8a7e --- /dev/null +++ b/src/processor/http/process-inbox.ts @@ -0,0 +1,38 @@ +import { verifySignature } from 'http-signature'; +import parseAcct from '../../acct/parse'; +import User, { IRemoteUser } from '../../models/user'; +import act from '../../remote/activitypub/act'; +import resolvePerson from '../../remote/activitypub/resolve-person'; + +export default ({ data }, done) => (async () => { + const keyIdLower = data.signature.keyId.toLowerCase(); + let user; + + if (keyIdLower.startsWith('acct:')) { + const { username, host } = parseAcct(keyIdLower.slice('acct:'.length)); + if (host === null) { + throw 'request was made by local user'; + } + + user = await User.findOne({ usernameLower: username, hostLower: host }) as IRemoteUser; + } else { + user = await User.findOne({ + host: { $ne: null }, + 'account.publicKey.id': data.signature.keyId + }) as IRemoteUser; + + if (user === null) { + user = await resolvePerson(data.signature.keyId); + } + } + + if (user === null) { + throw 'failed to resolve user'; + } + + if (!verifySignature(data.signature, user.account.publicKey.publicKeyPem)) { + throw 'signature verification failed'; + } + + await act(user, data.inbox, true); +})().then(done, done); |