mirror of
https://github.com/superseriousbusiness/gotosocial.git
synced 2025-10-29 06:02:26 -05:00
# Description > If this is a code change, please include a summary of what you've coded, and link to the issue(s) it closes/implements. > > If this is a documentation change, please briefly describe what you've changed and why. This pull request adds logic for nicely handling retractions of entries from domain permission subscriptions. See docs for how this works but basically retracted entries will either be removed (and possibly picked up by a lower-prio subscription), or orphaned (and then possibly adopted), depending on the config of the domain permission subscription. closes https://codeberg.org/superseriousbusiness/gotosocial/issues/4101 ## Checklist Please put an x inside each checkbox to indicate that you've read and followed it: `[ ]` -> `[x]` If this is a documentation change, only the first checkbox must be filled (you can delete the others if you want). - [x] I/we have read the [GoToSocial contribution guidelines](https://codeberg.org/superseriousbusiness/gotosocial/src/branch/main/CONTRIBUTING.md). - [x] I/we have discussed the proposed changes already, either in an issue on the repository, or in the Matrix chat. - [x] I/we have not leveraged AI to create the proposed changes. - [x] I/we have performed a self-review of added code. - [x] I/we have written code that is legible and maintainable by others. - [x] I/we have commented the added code, particularly in hard-to-understand areas. - [x] I/we have made any necessary changes to documentation. - [x] I/we have added tests that cover new code. - [ ] I/we have run tests and they pass locally with the changes. - [x] I/we have run `go fmt ./...` and `golangci-lint run`. Reviewed-on: https://codeberg.org/superseriousbusiness/gotosocial/pulls/4261 Co-authored-by: tobi <tobi.smethurst@protonmail.com> Co-committed-by: tobi <tobi.smethurst@protonmail.com>
192 lines
6.1 KiB
Go
192 lines
6.1 KiB
Go
// GoToSocial
|
|
// Copyright (C) GoToSocial Authors admin@gotosocial.org
|
|
// SPDX-License-Identifier: AGPL-3.0-or-later
|
|
//
|
|
// This program is free software: you can redistribute it and/or modify
|
|
// it under the terms of the GNU Affero General Public License as published by
|
|
// the Free Software Foundation, either version 3 of the License, or
|
|
// (at your option) any later version.
|
|
//
|
|
// This program is distributed in the hope that it will be useful,
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
// GNU Affero General Public License for more details.
|
|
//
|
|
// You should have received a copy of the GNU Affero General Public License
|
|
// along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
package admin
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"fmt"
|
|
|
|
apimodel "code.superseriousbusiness.org/gotosocial/internal/api/model"
|
|
"code.superseriousbusiness.org/gotosocial/internal/db"
|
|
"code.superseriousbusiness.org/gotosocial/internal/gtserror"
|
|
"code.superseriousbusiness.org/gotosocial/internal/gtsmodel"
|
|
"code.superseriousbusiness.org/gotosocial/internal/id"
|
|
"code.superseriousbusiness.org/gotosocial/internal/text"
|
|
)
|
|
|
|
func (p *Processor) createDomainAllow(
|
|
ctx context.Context,
|
|
adminAcct *gtsmodel.Account,
|
|
domain string,
|
|
obfuscate bool,
|
|
publicComment string,
|
|
privateComment string,
|
|
subscriptionID string,
|
|
) (*apimodel.DomainPermission, string, gtserror.WithCode) {
|
|
// Check if an allow already exists for this domain.
|
|
domainAllow, err := p.state.DB.GetDomainAllow(ctx, domain)
|
|
if err != nil && !errors.Is(err, db.ErrNoEntries) {
|
|
// Something went wrong in the DB.
|
|
err = gtserror.Newf("db error getting domain allow %s: %w", domain, err)
|
|
return nil, "", gtserror.NewErrorInternalError(err)
|
|
}
|
|
|
|
if domainAllow == nil {
|
|
// No allow exists yet, create it.
|
|
domainAllow = >smodel.DomainAllow{
|
|
ID: id.NewULID(),
|
|
Domain: domain,
|
|
CreatedByAccountID: adminAcct.ID,
|
|
PrivateComment: text.StripHTMLFromText(privateComment),
|
|
PublicComment: text.StripHTMLFromText(publicComment),
|
|
Obfuscate: &obfuscate,
|
|
SubscriptionID: subscriptionID,
|
|
}
|
|
|
|
// Insert the new allow into the database.
|
|
if err := p.state.DB.PutDomainAllow(ctx, domainAllow); err != nil {
|
|
err = gtserror.Newf("db error putting domain allow %s: %w", domain, err)
|
|
return nil, "", gtserror.NewErrorInternalError(err)
|
|
}
|
|
}
|
|
|
|
// Run admin action to process
|
|
// side effects of allow.
|
|
action := >smodel.AdminAction{
|
|
ID: id.NewULID(),
|
|
TargetCategory: gtsmodel.AdminActionCategoryDomain,
|
|
TargetID: domainAllow.Domain,
|
|
Type: gtsmodel.AdminActionUnsuspend,
|
|
AccountID: adminAcct.ID,
|
|
}
|
|
|
|
if errWithCode := p.state.AdminActions.Run(
|
|
ctx,
|
|
action,
|
|
p.state.AdminActions.DomainAllowF(action.ID, domainAllow),
|
|
); errWithCode != nil {
|
|
return nil, action.ID, errWithCode
|
|
}
|
|
|
|
apiDomainAllow, errWithCode := p.apiDomainPerm(ctx, domainAllow, false)
|
|
if errWithCode != nil {
|
|
return nil, action.ID, errWithCode
|
|
}
|
|
|
|
return apiDomainAllow, action.ID, nil
|
|
}
|
|
|
|
func (p *Processor) updateDomainAllow(
|
|
ctx context.Context,
|
|
domainAllowID string,
|
|
obfuscate *bool,
|
|
publicComment *string,
|
|
privateComment *string,
|
|
subscriptionID *string,
|
|
) (*apimodel.DomainPermission, gtserror.WithCode) {
|
|
domainAllow, err := p.state.DB.GetDomainAllowByID(ctx, domainAllowID)
|
|
if err != nil {
|
|
if !errors.Is(err, db.ErrNoEntries) {
|
|
// Real error.
|
|
err = gtserror.Newf("db error getting domain allow: %w", err)
|
|
return nil, gtserror.NewErrorInternalError(err)
|
|
}
|
|
|
|
// There are just no entries for this ID.
|
|
err = fmt.Errorf("no domain allow entry exists with ID %s", domainAllowID)
|
|
return nil, gtserror.NewErrorNotFound(err, err.Error())
|
|
}
|
|
|
|
var columns []string
|
|
if obfuscate != nil {
|
|
domainAllow.Obfuscate = obfuscate
|
|
columns = append(columns, "obfuscate")
|
|
}
|
|
if publicComment != nil {
|
|
domainAllow.PublicComment = *publicComment
|
|
columns = append(columns, "public_comment")
|
|
}
|
|
if privateComment != nil {
|
|
domainAllow.PrivateComment = *privateComment
|
|
columns = append(columns, "private_comment")
|
|
}
|
|
if subscriptionID != nil {
|
|
domainAllow.SubscriptionID = *subscriptionID
|
|
columns = append(columns, "subscription_id")
|
|
}
|
|
|
|
// Update the domain allow.
|
|
if err := p.state.DB.UpdateDomainAllow(ctx, domainAllow, columns...); err != nil {
|
|
err = gtserror.Newf("db error updating domain allow: %w", err)
|
|
return nil, gtserror.NewErrorInternalError(err)
|
|
}
|
|
|
|
return p.apiDomainPerm(ctx, domainAllow, false)
|
|
}
|
|
|
|
func (p *Processor) deleteDomainAllow(
|
|
ctx context.Context,
|
|
adminAcct *gtsmodel.Account,
|
|
domainAllowID string,
|
|
) (*apimodel.DomainPermission, string, gtserror.WithCode) {
|
|
domainAllow, err := p.state.DB.GetDomainAllowByID(ctx, domainAllowID)
|
|
if err != nil {
|
|
if !errors.Is(err, db.ErrNoEntries) {
|
|
// Real error.
|
|
err = gtserror.Newf("db error getting domain allow: %w", err)
|
|
return nil, "", gtserror.NewErrorInternalError(err)
|
|
}
|
|
|
|
// There are just no entries for this ID.
|
|
err = fmt.Errorf("no domain allow entry exists with ID %s", domainAllowID)
|
|
return nil, "", gtserror.NewErrorNotFound(err, err.Error())
|
|
}
|
|
|
|
// Prepare the domain allow to return, *before* the deletion goes through.
|
|
apiDomainAllow, errWithCode := p.apiDomainPerm(ctx, domainAllow, false)
|
|
if errWithCode != nil {
|
|
return nil, "", errWithCode
|
|
}
|
|
|
|
// Delete the original domain allow.
|
|
if err := p.state.DB.DeleteDomainAllow(ctx, domainAllow.Domain); err != nil {
|
|
err = gtserror.Newf("db error deleting domain allow: %w", err)
|
|
return nil, "", gtserror.NewErrorInternalError(err)
|
|
}
|
|
|
|
// Run admin action to process
|
|
// side effects of unallow.
|
|
action := >smodel.AdminAction{
|
|
ID: id.NewULID(),
|
|
TargetCategory: gtsmodel.AdminActionCategoryDomain,
|
|
TargetID: domainAllow.Domain,
|
|
Type: gtsmodel.AdminActionUnallow,
|
|
AccountID: adminAcct.ID,
|
|
}
|
|
|
|
if errWithCode := p.state.AdminActions.Run(
|
|
ctx,
|
|
action,
|
|
p.state.AdminActions.DomainUnallowF(action.ID, domainAllow),
|
|
); errWithCode != nil {
|
|
return nil, action.ID, errWithCode
|
|
}
|
|
|
|
return apiDomainAllow, action.ID, nil
|
|
}
|