PeerTube/server/helpers/custom-validators/activitypub/actor.ts

132 lines
4.2 KiB
TypeScript
Raw Normal View History

2017-12-14 11:18:49 +01:00
import * as validator from 'validator'
import { CONSTRAINTS_FIELDS } from '../../../initializers/constants'
2018-08-23 17:58:39 +02:00
import { exists, isArray } from '../misc'
2018-05-11 15:55:39 +02:00
import { truncate } from 'lodash'
2017-12-14 17:38:41 +01:00
import { isActivityPubUrlValid, isBaseActivityValid, setValidAttributedTo } from './misc'
import { isHostValid } from '../servers'
2017-12-14 11:18:49 +01:00
function isActorEndpointsObjectValid (endpointObject: any) {
return isActivityPubUrlValid(endpointObject.sharedInbox)
}
function isActorPublicKeyObjectValid (publicKeyObject: any) {
return isActivityPubUrlValid(publicKeyObject.id) &&
isActivityPubUrlValid(publicKeyObject.owner) &&
isActorPublicKeyValid(publicKeyObject.publicKeyPem)
}
function isActorTypeValid (type: string) {
return type === 'Person' || type === 'Application' || type === 'Group'
}
function isActorPublicKeyValid (publicKey: string) {
return exists(publicKey) &&
typeof publicKey === 'string' &&
publicKey.startsWith('-----BEGIN PUBLIC KEY-----') &&
2017-12-19 10:34:56 +01:00
publicKey.indexOf('-----END PUBLIC KEY-----') !== -1 &&
2018-01-03 11:10:40 +01:00
validator.isLength(publicKey, CONSTRAINTS_FIELDS.ACTORS.PUBLIC_KEY)
2017-12-14 11:18:49 +01:00
}
const actorNameAlphabet = '[ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789\\-_.]'
const actorNameRegExp = new RegExp(`^${actorNameAlphabet}+$`)
2017-12-14 11:18:49 +01:00
function isActorPreferredUsernameValid (preferredUsername: string) {
2017-12-19 10:34:56 +01:00
return exists(preferredUsername) && validator.matches(preferredUsername, actorNameRegExp)
2017-12-14 17:38:41 +01:00
}
2017-12-14 11:18:49 +01:00
function isActorPrivateKeyValid (privateKey: string) {
return exists(privateKey) &&
typeof privateKey === 'string' &&
privateKey.startsWith('-----BEGIN RSA PRIVATE KEY-----') &&
2017-12-19 10:34:56 +01:00
// Sometimes there is a \n at the end, so just assert the string contains the end mark
privateKey.indexOf('-----END RSA PRIVATE KEY-----') !== -1 &&
2018-01-03 11:10:40 +01:00
validator.isLength(privateKey, CONSTRAINTS_FIELDS.ACTORS.PRIVATE_KEY)
2017-12-14 11:18:49 +01:00
}
2018-01-03 16:38:50 +01:00
function isActorObjectValid (actor: any) {
return exists(actor) &&
isActivityPubUrlValid(actor.id) &&
isActorTypeValid(actor.type) &&
isActivityPubUrlValid(actor.following) &&
isActivityPubUrlValid(actor.followers) &&
isActivityPubUrlValid(actor.inbox) &&
isActivityPubUrlValid(actor.outbox) &&
isActorPreferredUsernameValid(actor.preferredUsername) &&
isActivityPubUrlValid(actor.url) &&
isActorPublicKeyObjectValid(actor.publicKey) &&
isActorEndpointsObjectValid(actor.endpoints) &&
setValidAttributedTo(actor) &&
2018-03-19 10:23:42 +01:00
2017-12-14 17:38:41 +01:00
// If this is not an account, it should be attributed to an account
// In PeerTube we use this to attach a video channel to a specific account
2018-01-03 16:38:50 +01:00
(actor.type === 'Person' || actor.attributedTo.length !== 0)
2017-12-14 11:18:49 +01:00
}
function isActorFollowingCountValid (value: string) {
return exists(value) && validator.isInt('' + value, { min: 0 })
}
function isActorFollowersCountValid (value: string) {
return exists(value) && validator.isInt('' + value, { min: 0 })
}
function isActorDeleteActivityValid (activity: any) {
return isBaseActivityValid(activity, 'Delete')
}
function sanitizeAndCheckActorObject (object: any) {
normalizeActor(object)
2018-03-19 10:23:42 +01:00
return isActorObjectValid(object)
2018-01-03 16:38:50 +01:00
}
2018-05-11 15:55:39 +02:00
function normalizeActor (actor: any) {
if (!actor || !actor.url) return
2018-05-11 15:55:39 +02:00
if (typeof actor.url !== 'string') {
actor.url = actor.url.href || actor.url.url
}
if (actor.summary && typeof actor.summary === 'string') {
actor.summary = truncate(actor.summary, { length: CONSTRAINTS_FIELDS.USERS.DESCRIPTION.max })
if (actor.summary.length < CONSTRAINTS_FIELDS.USERS.DESCRIPTION.min) {
actor.summary = null
}
}
return
}
function isValidActorHandle (handle: string) {
if (!exists(handle)) return false
const parts = handle.split('@')
if (parts.length !== 2) return false
return isHostValid(parts[1])
}
2018-08-23 17:58:39 +02:00
function areValidActorHandles (handles: string[]) {
return isArray(handles) && handles.every(h => isValidActorHandle(h))
}
2017-12-14 11:18:49 +01:00
// ---------------------------------------------------------------------------
export {
2018-05-11 15:55:39 +02:00
normalizeActor,
actorNameAlphabet,
2018-08-23 17:58:39 +02:00
areValidActorHandles,
2017-12-14 11:18:49 +01:00
isActorEndpointsObjectValid,
isActorPublicKeyObjectValid,
isActorTypeValid,
isActorPublicKeyValid,
isActorPreferredUsernameValid,
isActorPrivateKeyValid,
2018-01-03 16:38:50 +01:00
isActorObjectValid,
2017-12-14 11:18:49 +01:00
isActorFollowingCountValid,
isActorFollowersCountValid,
2017-12-14 17:38:41 +01:00
isActorDeleteActivityValid,
sanitizeAndCheckActorObject,
isValidActorHandle
2017-12-14 11:18:49 +01:00
}