Filter incoming Announce activities by relation to local activity (#10041)

* Filter incoming Announce activities by relation to local activity

Reject if announcer is not followed by local accounts, and is not
from an enabled relay, and the object is not a local status

Follow-up to #10005

* Fix tests
This commit is contained in:
Eugen Rochko
2019-02-15 18:19:45 +01:00
committed by GitHub
parent 8ef50706a1
commit c417e8c198
4 changed files with 25 additions and 13 deletions

View File

@ -3,7 +3,8 @@
class ActivityPub::Activity::Announce < ActivityPub::Activity
def perform
original_status = status_from_object
return if original_status.nil? || delete_arrived_first?(@json['id']) || !announceable?(original_status)
return if original_status.nil? || delete_arrived_first?(@json['id']) || !announceable?(original_status) || !related_to_local_activity?
status = Status.find_by(account: @account, reblog: original_status)
@ -39,4 +40,12 @@ class ActivityPub::Activity::Announce < ActivityPub::Activity
def announceable?(status)
status.account_id == @account.id || status.public_visibility? || status.unlisted_visibility?
end
def related_to_local_activity?
followed_by_local_accounts? || requested_through_relay? || reblog_of_local_status?
end
def reblog_of_local_status?
status_from_uri(object_uri)&.account&.local?
end
end