2018-07-06 11:47:28 +01:00
< ? php
/**
* GNU social - a federating social network
*
2018-07-10 00:17:18 +01:00
* ActivityPubPlugin implementation for GNU Social
2018-07-06 11:47:28 +01:00
*
* LICENCE : This program is free software : you can redistribute it and / or modify
* it under the terms of the GNU Affero General Public License as published by
* the Free Software Foundation , either version 3 of the License , or
* ( at your option ) any later version .
*
* This program is distributed in the hope that it will be useful ,
* but WITHOUT ANY WARRANTY ; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
* GNU Affero General Public License for more details .
*
* You should have received a copy of the GNU Affero General Public License
* along with this program . If not , see < http :// www . gnu . org / licenses />.
*
2018-07-10 00:17:18 +01:00
* @ category Plugin
2018-07-06 11:47:28 +01:00
* @ package GNUsocial
* @ author Diogo Cordeiro < diogo @ fc . up . pt >
2018-07-10 01:47:52 +01:00
* @ author Daniel Supernault < danielsupernault @ gmail . com >
2018-07-10 00:17:18 +01:00
* @ copyright 2018 Free Software Foundation http :// fsf . org
2018-07-06 11:47:28 +01:00
* @ license http :// www . fsf . org / licensing / licenses / agpl - 3.0 . html GNU Affero General Public License version 3.0
2018-07-10 00:17:18 +01:00
* @ link https :// www . gnu . org / software / social /
2018-07-06 11:47:28 +01:00
*/
2018-07-26 22:12:13 +01:00
if ( ! defined ( 'GNUSOCIAL' )) {
exit ( 1 );
2018-07-10 00:17:18 +01:00
}
2018-07-06 11:47:28 +01:00
2018-07-10 00:17:18 +01:00
/**
2018-07-13 12:32:27 +01:00
* ActivityPub ' s own Explorer
*
2018-07-29 02:35:04 +01:00
* Allows to discovery new ( or the same ) Profiles ( both local or remote )
2018-07-13 12:32:27 +01:00
*
2018-07-10 00:17:18 +01:00
* @ category Plugin
* @ package GNUsocial
* @ author Diogo Cordeiro < diogo @ fc . up . pt >
* @ license http :// www . fsf . org / licensing / licenses / agpl - 3.0 . html GNU Affero General Public License version 3.0
* @ link http :// www . gnu . org / software / social /
*/
2018-07-13 00:20:18 +01:00
class Activitypub_explorer
2018-07-10 00:17:18 +01:00
{
2018-08-02 01:42:15 +01:00
private $discovered_actor_profiles = [];
/**
* Shortcut function to get a single profile from its URL .
*
* @ author Diogo Cordeiro < diogo @ fc . up . pt >
* @ param string $url
* @ return Profile
* @ throws Exception
*/
public static function get_profile_from_url ( $url )
{
$discovery = new Activitypub_explorer ;
// Get valid Actor object
try {
$actor_profile = $discovery -> lookup ( $url );
return $actor_profile [ 0 ];
} catch ( Exception $e ) {
throw new Exception ( 'Invalid Actor.' );
}
unset ( $discovery );
}
2018-07-10 00:17:18 +01:00
2018-07-26 22:12:13 +01:00
/**
* Get every profile from the given URL
* This function cleans the $this -> discovered_actor_profiles array
* so that there is no erroneous data
*
* @ author Diogo Cordeiro < diogo @ fc . up . pt >
* @ param string $url User ' s url
* @ return array of Profile objects
*/
public function lookup ( $url )
{
2018-08-02 01:42:15 +01:00
if ( in_array ( $url , ACTIVITYPUB_PUBLIC_TO )) {
return [];
}
2018-07-31 20:16:23 +01:00
common_debug ( 'ActivityPub Explorer: Started now looking for ' . $url );
2018-08-02 01:42:15 +01:00
$this -> discovered_actor_profiles = [];
2018-07-13 00:20:18 +01:00
2018-07-26 22:12:13 +01:00
return $this -> _lookup ( $url );
}
2018-07-10 00:17:18 +01:00
2018-07-26 22:12:13 +01:00
/**
* Get every profile from the given URL
* This is a recursive function that will accumulate the results on
* $discovered_actor_profiles array
*
* @ author Diogo Cordeiro < diogo @ fc . up . pt >
* @ param string $url User ' s url
* @ return array of Profile objects
*/
private function _lookup ( $url )
{
// First check if we already have it locally and, if so, return it
// If the local fetch fails: grab it remotely, store locally and return
if ( ! ( $this -> grab_local_user ( $url ) || $this -> grab_remote_user ( $url ))) {
2018-07-31 20:16:23 +01:00
throw new Exception ( 'User not found.' );
2018-07-09 00:07:14 +01:00
}
2018-07-10 00:17:18 +01:00
2018-07-26 22:12:13 +01:00
return $this -> discovered_actor_profiles ;
}
/**
* This ensures that we are using a valid ActivityPub URI
*
* @ author Diogo Cordeiro < diogo @ fc . up . pt >
* @ param string $url
* @ return boolean success state ( related to the response )
* @ throws Exception ( If the HTTP request fails )
*/
private function ensure_proper_remote_uri ( $url )
{
$client = new HTTPClient ();
2018-07-28 02:11:58 +01:00
$headers = [];
2018-07-26 22:12:13 +01:00
$headers [] = 'Accept: application/ld+json; profile="https://www.w3.org/ns/activitystreams"' ;
$headers [] = 'User-Agent: GNUSocialBot v0.1 - https://gnu.io/social' ;
$response = $client -> get ( $url , $headers );
2018-08-02 05:00:35 +01:00
$res = json_decode ( $response -> getBody (), true );
2018-07-26 22:12:13 +01:00
if ( self :: validate_remote_response ( $res )) {
$this -> temp_res = $res ;
return true ;
2018-07-31 20:09:47 +01:00
} else {
2018-08-01 01:58:31 +01:00
common_debug ( 'ActivityPub Explorer: Invalid potential remote actor while ensuring URI: ' . $url . '. He returned the following: ' . json_encode ( $res , JSON_UNESCAPED_SLASHES ));
2018-07-10 00:17:18 +01:00
}
2018-07-26 22:12:13 +01:00
return false ;
}
2018-07-10 00:17:18 +01:00
2018-07-26 22:12:13 +01:00
/**
2018-07-29 02:35:04 +01:00
* Get a local user profile from its URL and joins it on
2018-07-26 22:12:13 +01:00
* $this -> discovered_actor_profiles
*
* @ author Diogo Cordeiro < diogo @ fc . up . pt >
* @ param string $uri Actor ' s uri
* @ return boolean success state
*/
2018-07-27 15:42:30 +01:00
private function grab_local_user ( $uri , $online = false )
2018-07-26 22:12:13 +01:00
{
2018-07-29 02:35:04 +01:00
if ( $online ) {
2018-07-31 20:09:47 +01:00
common_debug ( 'ActivityPub Explorer: Searching locally for ' . $uri . ' with online resources.' );
2018-07-29 02:35:04 +01:00
} else {
2018-07-31 20:09:47 +01:00
common_debug ( 'ActivityPub Explorer: Searching locally for ' . $uri . ' offline.' );
2018-07-29 02:35:04 +01:00
}
2018-07-26 22:12:13 +01:00
// Ensure proper remote URI
2018-07-28 02:11:58 +01:00
// If an exception occurs here it's better to just leave everything
2018-07-26 22:12:13 +01:00
// break than to continue processing
2018-07-27 15:42:30 +01:00
if ( $online && $this -> ensure_proper_remote_uri ( $uri )) {
2018-07-26 22:12:13 +01:00
$uri = $this -> temp_res [ " id " ];
2018-07-09 00:07:14 +01:00
}
2018-07-28 02:11:58 +01:00
// Try standard ActivityPub route
// Is this a known filthy little mudblood?
2018-07-29 02:35:04 +01:00
$aprofile = self :: get_aprofile_by_url ( $uri );
2018-07-28 02:11:58 +01:00
if ( $aprofile instanceof Activitypub_profile ) {
$profile = $aprofile -> local_profile ();
2018-07-31 20:09:47 +01:00
common_debug ( 'ActivityPub Explorer: Found a local Aprofile for ' . $uri );
2018-07-26 22:12:13 +01:00
// We found something!
$this -> discovered_actor_profiles [] = $profile ;
unset ( $this -> temp_res ); // IMPORTANT to avoid _dangerous_ noise in the Explorer system
return true ;
2018-07-29 02:35:04 +01:00
} else {
2018-07-31 20:09:47 +01:00
common_debug ( 'ActivityPub Explorer: Unable to find a local Aprofile for ' . $uri . ' - looking for a Profile instead.' );
2018-07-29 02:35:04 +01:00
// Well, maybe it is a pure blood?
// Iff, we are in the same instance:
$ACTIVITYPUB_BASE_INSTANCE_URI_length = strlen ( ACTIVITYPUB_BASE_INSTANCE_URI );
if ( substr ( $uri , 0 , $ACTIVITYPUB_BASE_INSTANCE_URI_length ) == ACTIVITYPUB_BASE_INSTANCE_URI ) {
try {
$profile = Profile :: getByID ( intval ( substr ( $uri , $ACTIVITYPUB_BASE_INSTANCE_URI_length )));
2018-07-31 20:09:47 +01:00
common_debug ( 'ActivityPub Explorer: Found a Profile for ' . $uri );
2018-07-29 02:35:04 +01:00
// We found something!
$this -> discovered_actor_profiles [] = $profile ;
unset ( $this -> temp_res ); // IMPORTANT to avoid _dangerous_ noise in the Explorer system
return true ;
} catch ( Exception $e ) {
// Let the exception go on its merry way.
2018-07-31 20:09:47 +01:00
common_debug ( 'ActivityPub Explorer: Unable to find a Profile for ' . $uri );
2018-07-29 02:35:04 +01:00
}
}
2018-07-10 00:17:18 +01:00
}
2018-07-28 02:11:58 +01:00
2018-07-27 15:42:30 +01:00
// If offline grabbing failed, attempt again with online resources
if ( ! $online ) {
2018-07-31 20:09:47 +01:00
common_debug ( 'ActivityPub Explorer: Will try everything again with online resources against: ' . $uri );
2018-07-28 02:11:58 +01:00
return $this -> grab_local_user ( $uri , true );
2018-07-27 15:42:30 +01:00
}
2018-07-28 02:11:58 +01:00
2018-07-26 22:12:13 +01:00
return false ;
}
2018-07-10 00:17:18 +01:00
2018-07-26 22:12:13 +01:00
/**
* Get a remote user ( s ) profile ( s ) from its URL and joins it on
* $this -> discovered_actor_profiles
*
* @ author Diogo Cordeiro < diogo @ fc . up . pt >
* @ param string $url User ' s url
* @ return boolean success state
*/
private function grab_remote_user ( $url )
{
2018-07-31 20:09:47 +01:00
common_debug ( 'ActivityPub Explorer: Trying to grab a remote actor for ' . $url );
2018-07-26 22:12:13 +01:00
if ( ! isset ( $this -> temp_res )) {
$client = new HTTPClient ();
$headers = array ();
$headers [] = 'Accept: application/ld+json; profile="https://www.w3.org/ns/activitystreams"' ;
$headers [] = 'User-Agent: GNUSocialBot v0.1 - https://gnu.io/social' ;
$response = $client -> get ( $url , $headers );
2018-08-02 05:00:35 +01:00
$res = json_decode ( $response -> getBody (), true );
2018-07-26 22:12:13 +01:00
} else {
$res = $this -> temp_res ;
unset ( $this -> temp_res );
2018-07-09 14:41:53 +01:00
}
2018-07-26 22:12:13 +01:00
if ( isset ( $res [ " orderedItems " ])) { // It's a potential collection of actors!!!
2018-07-31 20:09:47 +01:00
common_debug ( 'ActivityPub Explorer: Found a collection of actors for ' . $url );
2018-07-26 22:12:13 +01:00
foreach ( $res [ " orderedItems " ] as $profile ) {
if ( $this -> _lookup ( $profile ) == false ) {
2018-08-02 05:00:35 +01:00
common_debug ( 'ActivityPub Explorer: Found an invalid actor for ' . $profile );
2018-08-02 01:42:15 +01:00
// TODO: Invalid actor found, fallback to OStatus
2018-07-13 00:20:18 +01:00
}
2018-07-26 22:12:13 +01:00
}
// Go through entire collection
if ( ! is_null ( $res [ " next " ])) {
$this -> _lookup ( $res [ " next " ]);
}
return true ;
} elseif ( self :: validate_remote_response ( $res )) {
2018-07-31 20:09:47 +01:00
common_debug ( 'ActivityPub Explorer: Found a valid remote actor for ' . $url );
2018-07-26 22:12:13 +01:00
$this -> discovered_actor_profiles [] = $this -> store_profile ( $res );
return true ;
2018-07-31 20:09:47 +01:00
} else {
2018-08-01 01:58:31 +01:00
common_debug ( 'ActivityPub Explorer: Invalid potential remote actor while grabbing remotely: ' . $url . '. He returned the following: ' . json_encode ( $res , JSON_UNESCAPED_SLASHES ));
2018-07-13 00:20:18 +01:00
}
2018-07-15 02:13:46 +01:00
2018-08-02 01:42:15 +01:00
// TODO: Fallback to OStatus
2018-07-26 22:12:13 +01:00
return false ;
}
/**
* Save remote user profile in local instance
*
* @ author Diogo Cordeiro < diogo @ fc . up . pt >
* @ param array $res remote response
* @ return Profile remote Profile object
*/
private function store_profile ( $res )
{
2018-07-28 02:11:58 +01:00
// ActivityPub Profile
2018-07-26 22:12:13 +01:00
$aprofile = new Activitypub_profile ;
2018-07-27 21:45:43 +01:00
$aprofile -> uri = $res [ 'id' ];
$aprofile -> nickname = $res [ 'preferredUsername' ];
2018-07-31 20:09:47 +01:00
$aprofile -> fullname = isset ( $res [ 'name' ]) ? $res [ 'name' ] : null ;
2018-08-01 14:20:27 +01:00
$aprofile -> bio = isset ( $res [ 'summary' ]) ? substr ( strip_tags ( $res [ 'summary' ]), 0 , 1000 ) : null ;
2018-07-27 21:45:43 +01:00
$aprofile -> inboxuri = $res [ 'inbox' ];
$aprofile -> sharedInboxuri = isset ( $res [ 'endpoints' ][ 'sharedInbox' ]) ? $res [ 'endpoints' ][ 'sharedInbox' ] : $res [ 'inbox' ];
2018-07-26 22:12:13 +01:00
$aprofile -> do_insert ();
2018-07-28 02:11:58 +01:00
$profile = $aprofile -> local_profile ();
// Public Key
$apRSA = new Activitypub_rsa ();
$apRSA -> profile_id = $profile -> getID ();
$apRSA -> public_key = $res [ 'publicKey' ][ 'publicKeyPem' ];
$apRSA -> store_keys ();
2018-07-15 02:13:46 +01:00
2018-08-01 21:24:36 +01:00
// Avatar
if ( isset ( $res [ 'icon' ][ 'url' ])) {
2018-08-02 05:54:27 +01:00
try {
$this -> _store_avatar ( $profile , $res [ 'icon' ][ 'url' ]);
} catch ( Exception $e ) {
// Let the exception go, it isn't a serious issue
common_debug ( 'An error ocurred while grabbing remote avatar' . $e -> getMessage ());
}
2018-08-01 21:24:36 +01:00
}
2018-07-28 02:11:58 +01:00
return $profile ;
2018-07-26 22:12:13 +01:00
}
2018-08-01 21:24:36 +01:00
/**
* Download and update given avatar image
*
* @ author GNU Social
* @ param string $url
* @ return Avatar The Avatar we have on disk . ( seldom used )
* @ throws Exception in various failure cases
*/
private function _store_avatar ( $profile , $url )
{
if ( ! common_valid_http_url ( $url )) {
// TRANS: Server exception. %s is a URL.
throw new ServerException ( sprintf ( 'Invalid avatar URL %s.' ), $url );
}
// @todo FIXME: This should be better encapsulated
// ripped from oauthstore.php (for old OMB client)
$temp_filename = tempnam ( sys_get_temp_dir (), 'listener_avatar' );
try {
$imgData = HTTPClient :: quickGet ( $url );
// Make sure it's at least an image file. ImageFile can do the rest.
if ( false === getimagesizefromstring ( $imgData )) {
2018-08-02 05:54:27 +01:00
throw new UnsupportedMediaException ( 'Downloaded avatar was not an image.' );
2018-08-01 21:24:36 +01:00
}
file_put_contents ( $temp_filename , $imgData );
unset ( $imgData ); // No need to carry this in memory.
$id = $profile -> getID ();
$imagefile = new ImageFile ( null , $temp_filename );
2018-08-02 01:42:15 +01:00
$filename = Avatar :: filename (
$id ,
2018-08-02 05:54:27 +01:00
image_type_to_extension ( $imagefile -> type ),
null ,
common_timestamp ()
2018-08-02 01:42:15 +01:00
);
2018-08-01 21:24:36 +01:00
rename ( $temp_filename , Avatar :: path ( $filename ));
} catch ( Exception $e ) {
unlink ( $temp_filename );
throw $e ;
}
// @todo FIXME: Hardcoded chmod is lame, but seems to be necessary to
// keep from accidentally saving images from command-line (queues)
// that can't be read from web server, which causes hard-to-notice
// problems later on:
//
// http://status.net/open-source/issues/2663
chmod ( Avatar :: path ( $filename ), 0644 );
$profile -> setOriginal ( $filename );
$orig = clone ( $profile );
$profile -> avatar = $url ;
$profile -> update ( $orig );
return Avatar :: getUploaded ( $profile );
}
2018-07-26 22:12:13 +01:00
/**
* Validates a remote response in order to determine whether this
* response is a valid profile or not
*
* @ author Diogo Cordeiro < diogo @ fc . up . pt >
* @ param array $res remote response
* @ return boolean success state
*/
2018-07-28 15:52:47 +01:00
public static function validate_remote_response ( $res )
2018-07-26 22:12:13 +01:00
{
2018-07-31 20:09:47 +01:00
if ( ! isset ( $res [ 'id' ], $res [ 'preferredUsername' ], $res [ 'inbox' ], $res [ 'publicKey' ][ 'publicKeyPem' ])) {
2018-07-26 22:12:13 +01:00
return false ;
2018-07-15 02:13:46 +01:00
}
2018-07-26 22:12:13 +01:00
return true ;
}
2018-07-29 02:35:04 +01:00
/**
* Get a ActivityPub Profile from it ' s uri
* Unfortunately GNU Social cache is not truly reliable when handling
* potential ActivityPub remote profiles , as so it is important to use
* this hacky workaround ( at least for now )
*
* @ author Diogo Cordeiro < diogo @ fc . up . pt >
* @ param string $v URL
* @ return boolean | Activitypub_profile false if fails | Aprofile object if successful
*/
public static function get_aprofile_by_url ( $v )
{
$i = Managed_DataObject :: getcached ( " Activitypub_profile " , " uri " , $v );
if ( empty ( $i )) { // false = cache miss
$i = new Activitypub_profile ;
$result = $i -> get ( " uri " , $v );
if ( $result ) {
// Hit!
$i -> encache ();
} else {
return false ;
}
}
return $i ;
}
2018-07-26 22:12:13 +01:00
/**
* Given a valid actor profile url returns its inboxes
*
* @ author Diogo Cordeiro < diogo @ fc . up . pt >
* @ param string $url of Actor profile
* @ return boolean | array false if fails | array with inbox and shared inbox if successful
*/
public static function get_actor_inboxes_uri ( $url )
{
$client = new HTTPClient ();
$headers = array ();
$headers [] = 'Accept: application/ld+json; profile="https://www.w3.org/ns/activitystreams"' ;
$headers [] = 'User-Agent: GNUSocialBot v0.1 - https://gnu.io/social' ;
$response = $client -> get ( $url , $headers );
if ( ! $response -> isOk ()) {
2018-07-27 21:45:43 +01:00
throw new Exception ( 'Invalid Actor URL.' );
2018-07-26 22:12:13 +01:00
}
2018-08-02 05:00:35 +01:00
$res = json_decode ( $response -> getBody (), true );
2018-07-26 22:12:13 +01:00
if ( self :: validate_remote_response ( $res )) {
2018-07-27 21:45:43 +01:00
return [
'inbox' => $res [ 'inbox' ],
'sharedInbox' => isset ( $res [ 'endpoints' ][ 'sharedInbox' ]) ? $res [ 'endpoints' ][ 'sharedInbox' ] : $res [ 'inbox' ]
];
2018-07-26 22:12:13 +01:00
}
return false ;
}
2018-07-06 11:47:28 +01:00
}