akkoma/lib/pleroma/web/web_finger/web_finger.ex

288 lines
8.2 KiB
Elixir
Raw Normal View History

# Pleroma: A lightweight social networking server
2018-12-31 16:41:47 +01:00
# Copyright © 2017-2019 Pleroma Authors <https://pleroma.social/>
# SPDX-License-Identifier: AGPL-3.0-only
2017-04-17 13:44:41 +02:00
defmodule Pleroma.Web.WebFinger do
2017-05-05 14:16:54 +02:00
@httpoison Application.get_env(:pleroma, :httpoison)
2019-02-09 16:16:26 +01:00
alias Pleroma.User
alias Pleroma.Web
2019-02-09 16:16:26 +01:00
alias Pleroma.Web.OStatus
alias Pleroma.Web.Salmon
alias Pleroma.Web.XML
alias Pleroma.XmlBuilder
2018-03-27 16:45:38 +02:00
require Jason
2017-04-28 17:41:12 +02:00
require Logger
2017-04-17 13:44:41 +02:00
def host_meta do
2018-03-30 15:01:53 +02:00
base_url = Web.base_url()
2017-04-17 13:44:41 +02:00
{
2018-03-30 15:01:53 +02:00
:XRD,
%{xmlns: "http://docs.oasis-open.org/ns/xri/xrd-1.0"},
2017-04-17 13:44:41 +02:00
{
2018-03-30 15:01:53 +02:00
:Link,
%{
rel: "lrdd",
type: "application/xrd+xml",
template: "#{base_url}/.well-known/webfinger?resource={uri}"
}
2017-04-17 13:44:41 +02:00
}
}
2018-03-30 15:01:53 +02:00
|> XmlBuilder.to_doc()
2017-04-17 13:44:41 +02:00
end
def webfinger(resource, fmt) when fmt in ["XML", "JSON"] do
2018-03-30 15:01:53 +02:00
host = Pleroma.Web.Endpoint.host()
2017-04-29 17:51:59 +02:00
regex = ~r/(acct:)?(?<username>\w+)@#{host}/
2018-03-30 15:01:53 +02:00
with %{"username" => username} <- Regex.named_captures(regex, resource),
%User{} = user <- User.get_by_nickname(username) do
{:ok, represent_user(user, fmt)}
2018-03-30 15:01:53 +02:00
else
_e ->
with %User{} = user <- User.get_cached_by_ap_id(resource) do
{:ok, represent_user(user, fmt)}
2018-03-30 15:01:53 +02:00
else
_e ->
{:error, "Couldn't find user"}
end
2018-03-21 18:58:31 +01:00
end
end
def represent_user(user, "JSON") do
{:ok, user} = ensure_keys_present(user)
2018-11-27 18:31:44 +01:00
{:ok, _private, public} = Salmon.keys_from_pem(user.info.keys)
2018-03-21 18:58:31 +01:00
magic_key = Salmon.encode_key(public)
2018-03-30 15:01:53 +02:00
2018-03-21 18:58:31 +01:00
%{
2018-03-30 15:01:53 +02:00
"subject" => "acct:#{user.nickname}@#{Pleroma.Web.Endpoint.host()}",
2018-03-21 18:58:31 +01:00
"aliases" => [user.ap_id],
"links" => [
2018-03-30 15:01:53 +02:00
%{
"rel" => "http://schemas.google.com/g/2010#updates-from",
"type" => "application/atom+xml",
"href" => OStatus.feed_path(user)
},
%{
"rel" => "http://webfinger.net/rel/profile-page",
"type" => "text/html",
"href" => user.ap_id
},
2018-03-21 18:58:31 +01:00
%{"rel" => "salmon", "href" => OStatus.salmon_path(user)},
2018-04-21 09:43:53 +02:00
%{
"rel" => "magic-public-key",
"href" => "data:application/magic-public-key,#{magic_key}"
},
2018-03-21 18:58:31 +01:00
%{"rel" => "self", "type" => "application/activity+json", "href" => user.ap_id},
2018-05-19 10:48:15 +02:00
%{
"rel" => "self",
"type" => "application/ld+json; profile=\"https://www.w3.org/ns/activitystreams\"",
"href" => user.ap_id
},
2018-03-30 15:01:53 +02:00
%{
"rel" => "http://ostatus.org/schema/1.0/subscribe",
"template" => OStatus.remote_follow_path()
}
2018-03-21 18:58:31 +01:00
]
}
end
def represent_user(user, "XML") do
2017-04-30 15:00:04 +02:00
{:ok, user} = ensure_keys_present(user)
2018-11-27 18:31:44 +01:00
{:ok, _private, public} = Salmon.keys_from_pem(user.info.keys)
2017-04-30 15:00:04 +02:00
magic_key = Salmon.encode_key(public)
2018-03-30 15:01:53 +02:00
2017-04-17 13:44:41 +02:00
{
2018-03-30 15:01:53 +02:00
:XRD,
%{xmlns: "http://docs.oasis-open.org/ns/xri/xrd-1.0"},
2017-04-17 13:44:41 +02:00
[
2018-03-30 15:01:53 +02:00
{:Subject, "acct:#{user.nickname}@#{Pleroma.Web.Endpoint.host()}"},
2017-04-17 13:44:41 +02:00
{:Alias, user.ap_id},
2018-03-30 15:01:53 +02:00
{:Link,
%{
rel: "http://schemas.google.com/g/2010#updates-from",
type: "application/atom+xml",
href: OStatus.feed_path(user)
}},
{:Link,
%{rel: "http://webfinger.net/rel/profile-page", type: "text/html", href: user.ap_id}},
2017-04-30 15:00:04 +02:00
{:Link, %{rel: "salmon", href: OStatus.salmon_path(user)}},
2018-03-30 15:01:53 +02:00
{:Link,
%{rel: "magic-public-key", href: "data:application/magic-public-key,#{magic_key}"}},
{:Link, %{rel: "self", type: "application/activity+json", href: user.ap_id}},
2018-03-30 15:01:53 +02:00
{:Link,
%{rel: "http://ostatus.org/schema/1.0/subscribe", template: OStatus.remote_follow_path()}}
2017-04-17 13:44:41 +02:00
]
}
2018-03-30 15:01:53 +02:00
|> XmlBuilder.to_doc()
2017-04-17 13:44:41 +02:00
end
2017-04-28 17:41:12 +02:00
2017-05-01 14:07:29 +02:00
# This seems a better fit in Salmon
2017-04-30 15:00:04 +02:00
def ensure_keys_present(user) do
2018-11-18 19:33:43 +01:00
info = user.info
2018-03-30 15:01:53 +02:00
2018-11-18 19:33:43 +01:00
if info.keys do
2017-04-30 15:00:04 +02:00
{:ok, user}
else
2018-03-30 15:01:53 +02:00
{:ok, pem} = Salmon.generate_rsa_pem()
2018-11-18 21:41:35 +01:00
info_cng =
info
|> Pleroma.User.Info.set_keys(pem)
2018-11-18 19:33:43 +01:00
2018-11-18 21:41:35 +01:00
cng =
Ecto.Changeset.change(user)
|> Ecto.Changeset.put_embed(:info, info_cng)
2018-11-18 19:33:43 +01:00
User.update_and_set_cache(cng)
2017-04-30 15:00:04 +02:00
end
end
2018-06-07 06:26:44 +02:00
defp get_magic_key(magic_key) do
2017-04-28 17:41:12 +02:00
"data:application/magic-public-key," <> magic_key = magic_key
2018-06-07 06:26:44 +02:00
{:ok, magic_key}
rescue
MatchError -> {:error, "Missing magic key data."}
end
2018-03-30 15:01:53 +02:00
2018-06-07 06:26:44 +02:00
defp webfinger_from_xml(doc) do
with magic_key <- XML.string_from_xpath(~s{//Link[@rel="magic-public-key"]/@href}, doc),
{:ok, magic_key} <- get_magic_key(magic_key),
topic <-
XML.string_from_xpath(
~s{//Link[@rel="http://schemas.google.com/g/2010#updates-from"]/@href},
doc
),
subject <- XML.string_from_xpath("//Subject", doc),
salmon <- XML.string_from_xpath(~s{//Link[@rel="salmon"]/@href}, doc),
subscribe_address <-
XML.string_from_xpath(
~s{//Link[@rel="http://ostatus.org/schema/1.0/subscribe"]/@template},
doc
),
ap_id <-
XML.string_from_xpath(
~s{//Link[@rel="self" and @type="application/activity+json"]/@href},
doc
) do
data = %{
"magic_key" => magic_key,
"topic" => topic,
"subject" => subject,
"salmon" => salmon,
"subscribe_address" => subscribe_address,
"ap_id" => ap_id
}
2018-03-30 15:01:53 +02:00
2018-06-07 06:26:44 +02:00
{:ok, data}
else
{:error, e} ->
{:error, e}
e ->
{:error, e}
end
2017-04-28 17:41:12 +02:00
end
defp webfinger_from_json(doc) do
2018-03-30 15:01:53 +02:00
data =
Enum.reduce(doc["links"], %{"subject" => doc["subject"]}, fn link, data ->
case {link["type"], link["rel"]} do
{"application/activity+json", "self"} ->
Map.put(data, "ap_id", link["href"])
{"application/ld+json; profile=\"https://www.w3.org/ns/activitystreams\"", "self"} ->
Map.put(data, "ap_id", link["href"])
2018-03-30 15:01:53 +02:00
{_, "magic-public-key"} ->
"data:application/magic-public-key," <> magic_key = link["href"]
Map.put(data, "magic_key", magic_key)
{"application/atom+xml", "http://schemas.google.com/g/2010#updates-from"} ->
Map.put(data, "topic", link["href"])
{_, "salmon"} ->
Map.put(data, "salmon", link["href"])
{_, "http://ostatus.org/schema/1.0/subscribe"} ->
Map.put(data, "subscribe_address", link["template"])
_ ->
Logger.debug("Unhandled type: #{inspect(link["type"])}")
data
end
end)
{:ok, data}
end
2017-08-24 12:54:53 +02:00
def get_template_from_xml(body) do
xpath = "//Link[@rel='lrdd']/@template"
2018-03-30 15:01:53 +02:00
2017-08-24 12:54:53 +02:00
with doc when doc != :error <- XML.parse_document(body),
2018-03-30 15:01:53 +02:00
template when template != nil <- XML.string_from_xpath(xpath, doc) do
2017-08-24 12:54:53 +02:00
{:ok, template}
end
end
def find_lrdd_template(domain) do
2018-12-02 15:08:36 +01:00
with {:ok, %{status: status, body: body}} when status in 200..299 <-
2018-12-06 03:38:33 +01:00
@httpoison.get("http://#{domain}/.well-known/host-meta", []) do
2017-08-24 12:54:53 +02:00
get_template_from_xml(body)
else
2017-11-19 02:22:07 +01:00
_ ->
2017-09-13 11:59:56 +02:00
with {:ok, %{body: body}} <- @httpoison.get("https://#{domain}/.well-known/host-meta", []) do
get_template_from_xml(body)
else
e -> {:error, "Can't find LRDD template: #{inspect(e)}"}
2017-09-13 11:59:56 +02:00
end
2017-08-24 12:54:53 +02:00
end
end
def finger(account) do
2018-02-23 16:55:12 +01:00
account = String.trim_leading(account, "@")
2018-03-30 15:01:53 +02:00
domain =
with [_name, domain] <- String.split(account, "@") do
domain
else
_e ->
URI.parse(account).host
end
2017-04-29 19:06:01 +02:00
2018-05-06 08:58:59 +02:00
address =
case find_lrdd_template(domain) do
{:ok, template} ->
String.replace(template, "{uri}", URI.encode(account))
2018-03-30 15:01:53 +02:00
2018-05-06 08:58:59 +02:00
_ ->
"https://#{domain}/.well-known/webfinger?resource=acct:#{account}"
2018-05-06 08:58:59 +02:00
end
2018-03-30 15:01:53 +02:00
with response <-
@httpoison.get(
address,
2018-12-11 13:31:52 +01:00
Accept: "application/xrd+xml,application/jrd+json"
2018-03-30 15:01:53 +02:00
),
2018-12-02 15:08:36 +01:00
{:ok, %{status: status, body: body}} when status in 200..299 <- response do
2018-03-30 15:01:53 +02:00
doc = XML.parse_document(body)
if doc != :error do
webfinger_from_xml(doc)
else
2018-06-07 06:26:44 +02:00
with {:ok, doc} <- Jason.decode(body) do
webfinger_from_json(doc)
else
{:error, e} -> e
end
2018-03-30 15:01:53 +02:00
end
2017-04-28 17:41:12 +02:00
else
e ->
Logger.debug(fn -> "Couldn't finger #{account}" end)
2017-05-05 12:07:38 +02:00
Logger.debug(fn -> inspect(e) end)
2017-04-28 17:41:12 +02:00
{:error, e}
end
end
2017-04-17 13:44:41 +02:00
end