| 
									
										
										
										
											2021-08-20 12:26:56 +02:00
										 |  |  | /* | 
					
						
							|  |  |  |    GoToSocial | 
					
						
							| 
									
										
										
										
											2021-12-20 18:42:19 +01:00
										 |  |  |    Copyright (C) 2021-2022 GoToSocial Authors admin@gotosocial.org | 
					
						
							| 
									
										
										
										
											2021-08-20 12:26:56 +02:00
										 |  |  | 
 | 
					
						
							|  |  |  |    This program is free software: you can redistribute it and/or modify | 
					
						
							|  |  |  |    it under the terms of the GNU Affero General Public License as published by | 
					
						
							|  |  |  |    the Free Software Foundation, either version 3 of the License, or | 
					
						
							|  |  |  |    (at your option) any later version. | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |    This program is distributed in the hope that it will be useful, | 
					
						
							|  |  |  |    but WITHOUT ANY WARRANTY; without even the implied warranty of | 
					
						
							|  |  |  |    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the | 
					
						
							|  |  |  |    GNU Affero General Public License for more details. | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |    You should have received a copy of the GNU Affero General Public License | 
					
						
							|  |  |  |    along with this program.  If not, see <http://www.gnu.org/licenses/>. | 
					
						
							|  |  |  | */ | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | package visibility | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | import ( | 
					
						
							| 
									
										
										
										
											2021-08-25 15:34:33 +02:00
										 |  |  | 	"context" | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 	"fmt" | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	"github.com/sirupsen/logrus" | 
					
						
							|  |  |  | 	"github.com/superseriousbusiness/gotosocial/internal/db" | 
					
						
							|  |  |  | 	"github.com/superseriousbusiness/gotosocial/internal/gtsmodel" | 
					
						
							|  |  |  | ) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-08-25 15:34:33 +02:00
										 |  |  | func (f *filter) StatusVisible(ctx context.Context, targetStatus *gtsmodel.Status, requestingAccount *gtsmodel.Account) (bool, error) { | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 	const getBoosted = true | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-10-11 05:37:33 -07:00
										 |  |  | 	l := logrus.WithFields(logrus.Fields{ | 
					
						
							| 
									
										
										
										
											2021-06-23 18:42:20 +02:00
										 |  |  | 		"func":     "StatusVisible", | 
					
						
							|  |  |  | 		"statusID": targetStatus.ID, | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 	}) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 	// Fetch any relevant accounts for the target status | 
					
						
							| 
									
										
										
										
											2021-08-25 15:34:33 +02:00
										 |  |  | 	relevantAccounts, err := f.relevantAccounts(ctx, targetStatus, getBoosted) | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		l.Debugf("error pulling relevant accounts for status %s: %s", targetStatus.ID, err) | 
					
						
							| 
									
										
										
										
											2021-08-20 12:26:56 +02:00
										 |  |  | 		return false, fmt.Errorf("StatusVisible: error pulling relevant accounts for status %s: %s", targetStatus.ID, err) | 
					
						
							| 
									
										
										
										
											2021-07-05 13:23:03 +02:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 	// Check we have determined a target account | 
					
						
							|  |  |  | 	targetAccount := relevantAccounts.Account | 
					
						
							|  |  |  | 	if targetAccount == nil { | 
					
						
							|  |  |  | 		l.Trace("target account is not set") | 
					
						
							|  |  |  | 		return false, nil | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// Check for domain blocks among relevant accounts | 
					
						
							| 
									
										
										
										
											2021-08-25 15:34:33 +02:00
										 |  |  | 	domainBlocked, err := f.domainBlockedRelevant(ctx, relevantAccounts) | 
					
						
							| 
									
										
										
										
											2021-07-05 13:23:03 +02:00
										 |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		l.Debugf("error checking domain block: %s", err) | 
					
						
							|  |  |  | 		return false, fmt.Errorf("error checking domain block: %s", err) | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 	} else if domainBlocked { | 
					
						
							| 
									
										
										
										
											2021-08-20 12:26:56 +02:00
										 |  |  | 		return false, nil | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 	// if target account is suspended then don't show the status | 
					
						
							|  |  |  | 	if !targetAccount.SuspendedAt.IsZero() { | 
					
						
							|  |  |  | 		l.Trace("target account suspended at is not zero") | 
					
						
							|  |  |  | 		return false, nil | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// if the target user doesn't exist (anymore) then the status also shouldn't be visible | 
					
						
							|  |  |  | 	// note: we only do this for local users | 
					
						
							|  |  |  | 	if targetAccount.Domain == "" { | 
					
						
							|  |  |  | 		targetUser := >smodel.User{} | 
					
						
							| 
									
										
										
										
											2021-08-25 15:34:33 +02:00
										 |  |  | 		if err := f.db.GetWhere(ctx, []db.Where{{Key: "account_id", Value: targetAccount.ID}}, targetUser); err != nil { | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 			l.Debug("target user could not be selected") | 
					
						
							| 
									
										
										
										
											2021-08-20 12:26:56 +02:00
										 |  |  | 			if err == db.ErrNoEntries { | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 				return false, nil | 
					
						
							|  |  |  | 			} | 
					
						
							|  |  |  | 			return false, fmt.Errorf("StatusVisible: db error selecting user for local target account %s: %s", targetAccount.ID, err) | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 		// if target user is disabled, not yet approved, or not confirmed then don't show the status | 
					
						
							|  |  |  | 		// (although in the latter two cases it's unlikely they posted a status yet anyway, but you never know!) | 
					
						
							|  |  |  | 		if targetUser.Disabled || !targetUser.Approved || targetUser.ConfirmedAt.IsZero() { | 
					
						
							|  |  |  | 			l.Trace("target user is disabled, not approved, or not confirmed") | 
					
						
							|  |  |  | 			return false, nil | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-06-23 18:42:20 +02:00
										 |  |  | 	// If requesting account is nil, that means whoever requested the status didn't auth, or their auth failed. | 
					
						
							|  |  |  | 	// In this case, we can still serve the status if it's public, otherwise we definitely shouldn't. | 
					
						
							|  |  |  | 	if requestingAccount == nil { | 
					
						
							|  |  |  | 		if targetStatus.Visibility == gtsmodel.VisibilityPublic { | 
					
						
							|  |  |  | 			return true, nil | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 		l.Trace("requesting account is nil but the target status isn't public") | 
					
						
							|  |  |  | 		return false, nil | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 	// if the requesting user doesn't exist (anymore) then the status also shouldn't be visible | 
					
						
							|  |  |  | 	// note: we only do this for local users | 
					
						
							|  |  |  | 	if requestingAccount.Domain == "" { | 
					
						
							|  |  |  | 		requestingUser := >smodel.User{} | 
					
						
							| 
									
										
										
										
											2021-08-25 15:34:33 +02:00
										 |  |  | 		if err := f.db.GetWhere(ctx, []db.Where{{Key: "account_id", Value: requestingAccount.ID}}, requestingUser); err != nil { | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 			// if the requesting account is local but doesn't have a corresponding user in the db this is a problem | 
					
						
							|  |  |  | 			l.Debug("requesting user could not be selected") | 
					
						
							| 
									
										
										
										
											2021-08-20 12:26:56 +02:00
										 |  |  | 			if err == db.ErrNoEntries { | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 				return false, nil | 
					
						
							|  |  |  | 			} | 
					
						
							|  |  |  | 			return false, fmt.Errorf("StatusVisible: db error selecting user for local requesting account %s: %s", requestingAccount.ID, err) | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 		// okay, user exists, so make sure it has full privileges/is confirmed/approved | 
					
						
							|  |  |  | 		if requestingUser.Disabled || !requestingUser.Approved || requestingUser.ConfirmedAt.IsZero() { | 
					
						
							|  |  |  | 			l.Trace("requesting account is local but corresponding user is either disabled, not approved, or not confirmed") | 
					
						
							|  |  |  | 			return false, nil | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// if requesting account is suspended then don't show the status -- although they probably shouldn't have gotten | 
					
						
							|  |  |  | 	// this far (ie., been authed) in the first place: this is just for safety. | 
					
						
							|  |  |  | 	if !requestingAccount.SuspendedAt.IsZero() { | 
					
						
							|  |  |  | 		l.Trace("requesting account is suspended") | 
					
						
							|  |  |  | 		return false, nil | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// if the target status belongs to the requesting account, they should always be able to view it at this point | 
					
						
							|  |  |  | 	if targetStatus.AccountID == requestingAccount.ID { | 
					
						
							|  |  |  | 		return true, nil | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// At this point we have a populated targetAccount, targetStatus, and requestingAccount, so we can check for blocks and whathaveyou | 
					
						
							|  |  |  | 	// First check if a block exists directly between the target account (which authored the status) and the requesting account. | 
					
						
							| 
									
										
										
										
											2021-08-25 15:34:33 +02:00
										 |  |  | 	if blocked, err := f.db.IsBlocked(ctx, targetAccount.ID, requestingAccount.ID, true); err != nil { | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 		l.Debugf("something went wrong figuring out if the accounts have a block: %s", err) | 
					
						
							|  |  |  | 		return false, err | 
					
						
							|  |  |  | 	} else if blocked { | 
					
						
							|  |  |  | 		// don't allow the status to be viewed if a block exists in *either* direction between these two accounts, no creepy stalking please | 
					
						
							|  |  |  | 		l.Trace("a block exists between requesting account and target account") | 
					
						
							|  |  |  | 		return false, nil | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 	// If not in reply to the requesting account, check if inReplyToAccount is blocked | 
					
						
							| 
									
										
										
										
											2021-08-20 12:26:56 +02:00
										 |  |  | 	if relevantAccounts.InReplyToAccount != nil && relevantAccounts.InReplyToAccount.ID != requestingAccount.ID { | 
					
						
							| 
									
										
										
										
											2021-08-25 15:34:33 +02:00
										 |  |  | 		if blocked, err := f.db.IsBlocked(ctx, relevantAccounts.InReplyToAccount.ID, requestingAccount.ID, true); err != nil { | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 			return false, err | 
					
						
							|  |  |  | 		} else if blocked { | 
					
						
							|  |  |  | 			l.Trace("a block exists between requesting account and reply to account") | 
					
						
							|  |  |  | 			return false, nil | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// status boosts accounts id | 
					
						
							| 
									
										
										
										
											2021-08-20 12:26:56 +02:00
										 |  |  | 	if relevantAccounts.BoostedAccount != nil { | 
					
						
							| 
									
										
										
										
											2021-08-25 15:34:33 +02:00
										 |  |  | 		if blocked, err := f.db.IsBlocked(ctx, relevantAccounts.BoostedAccount.ID, requestingAccount.ID, true); err != nil { | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 			return false, err | 
					
						
							|  |  |  | 		} else if blocked { | 
					
						
							|  |  |  | 			l.Trace("a block exists between requesting account and boosted account") | 
					
						
							|  |  |  | 			return false, nil | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// status boosts a reply to account id | 
					
						
							| 
									
										
										
										
											2021-08-20 12:26:56 +02:00
										 |  |  | 	if relevantAccounts.BoostedInReplyToAccount != nil { | 
					
						
							| 
									
										
										
										
											2021-08-25 15:34:33 +02:00
										 |  |  | 		if blocked, err := f.db.IsBlocked(ctx, relevantAccounts.BoostedInReplyToAccount.ID, requestingAccount.ID, true); err != nil { | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 			return false, err | 
					
						
							|  |  |  | 		} else if blocked { | 
					
						
							|  |  |  | 			l.Trace("a block exists between requesting account and boosted reply to account") | 
					
						
							|  |  |  | 			return false, nil | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 	// boost mentions accounts | 
					
						
							|  |  |  | 	for _, a := range relevantAccounts.BoostedMentionedAccounts { | 
					
						
							| 
									
										
										
										
											2021-08-20 12:26:56 +02:00
										 |  |  | 		if a == nil { | 
					
						
							|  |  |  | 			continue | 
					
						
							|  |  |  | 		} | 
					
						
							| 
									
										
										
										
											2021-08-25 15:34:33 +02:00
										 |  |  | 		if blocked, err := f.db.IsBlocked(ctx, a.ID, requestingAccount.ID, true); err != nil { | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 			return false, err | 
					
						
							|  |  |  | 		} else if blocked { | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 			l.Trace("a block exists between requesting account and a boosted mentioned account") | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 			return false, nil | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 	// Iterate mentions to check for blocks or requester mentions | 
					
						
							|  |  |  | 	isMentioned, blockAmongMentions := false, false | 
					
						
							|  |  |  | 	for _, a := range relevantAccounts.MentionedAccounts { | 
					
						
							| 
									
										
										
										
											2021-08-20 12:26:56 +02:00
										 |  |  | 		if a == nil { | 
					
						
							|  |  |  | 			continue | 
					
						
							|  |  |  | 		} | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-08-25 15:34:33 +02:00
										 |  |  | 		if blocked, err := f.db.IsBlocked(ctx, a.ID, requestingAccount.ID, true); err != nil { | 
					
						
							| 
									
										
										
										
											2021-07-05 13:23:03 +02:00
										 |  |  | 			return false, err | 
					
						
							|  |  |  | 		} else if blocked { | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 			blockAmongMentions = true | 
					
						
							|  |  |  | 			break | 
					
						
							| 
									
										
										
										
											2021-07-05 13:23:03 +02:00
										 |  |  | 		} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 		if a.ID == requestingAccount.ID { | 
					
						
							|  |  |  | 			isMentioned = true | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 		} | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 	if blockAmongMentions { | 
					
						
							|  |  |  | 		l.Trace("a block exists between requesting account and a mentioned account") | 
					
						
							|  |  |  | 		return false, nil | 
					
						
							|  |  |  | 	} else if isMentioned { | 
					
						
							|  |  |  | 		// Requester mentioned, should always be visible | 
					
						
							|  |  |  | 		return true, nil | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 	// at this point we know neither account blocks the other, or another account mentioned or otherwise referred to in the status | 
					
						
							|  |  |  | 	// that means it's now just a matter of checking the visibility settings of the status itself | 
					
						
							|  |  |  | 	switch targetStatus.Visibility { | 
					
						
							|  |  |  | 	case gtsmodel.VisibilityPublic, gtsmodel.VisibilityUnlocked: | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 		// no problem here | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 	case gtsmodel.VisibilityFollowersOnly: | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 		// Followers-only post, check for a one-way follow to target | 
					
						
							| 
									
										
										
										
											2021-08-25 15:34:33 +02:00
										 |  |  | 		follows, err := f.db.IsFollowing(ctx, requestingAccount, targetAccount) | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 		if err != nil { | 
					
						
							|  |  |  | 			return false, err | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 		if !follows { | 
					
						
							|  |  |  | 			l.Trace("requested status is followers only but requesting account is not a follower") | 
					
						
							|  |  |  | 			return false, nil | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 	case gtsmodel.VisibilityMutualsOnly: | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 		// Mutuals-only post, check for a mutual follow | 
					
						
							| 
									
										
										
										
											2021-08-25 15:34:33 +02:00
										 |  |  | 		mutuals, err := f.db.IsMutualFollowing(ctx, requestingAccount, targetAccount) | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 		if err != nil { | 
					
						
							|  |  |  | 			return false, err | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 		if !mutuals { | 
					
						
							|  |  |  | 			l.Trace("requested status is mutuals only but accounts aren't mufos") | 
					
						
							|  |  |  | 			return false, nil | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 	case gtsmodel.VisibilityDirect: | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 		l.Trace("requesting account requests a direct status it's not mentioned in") | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | 		return false, nil // it's not mentioned -_- | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-09-10 07:37:28 +01:00
										 |  |  | 	// If we reached here, all is okay | 
					
						
							|  |  |  | 	return true, nil | 
					
						
							| 
									
										
										
										
											2021-06-17 18:02:33 +02:00
										 |  |  | } | 
					
						
							| 
									
										
										
										
											2021-10-24 11:57:39 +02:00
										 |  |  | 
 | 
					
						
							|  |  |  | func (f *filter) StatusesVisible(ctx context.Context, statuses []*gtsmodel.Status, requestingAccount *gtsmodel.Account) ([]*gtsmodel.Status, error) { | 
					
						
							|  |  |  | 	filtered := []*gtsmodel.Status{} | 
					
						
							|  |  |  | 	for _, s := range statuses { | 
					
						
							|  |  |  | 		visible, err := f.StatusVisible(ctx, s, requestingAccount) | 
					
						
							|  |  |  | 		if err != nil { | 
					
						
							|  |  |  | 			return nil, err | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 		if visible { | 
					
						
							|  |  |  | 			filtered = append(filtered, s) | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 	return filtered, nil | 
					
						
							|  |  |  | } |