PluginProbe
ActivityPub / 3.2.5
ActivityPub v3.2.5
9.3.1 9.3.0 9.2.2 9.2.1 9.2.0 9.1.0 9.0.2 9.0.1 9.0.0 8.3.0 8.2.1 8.2.0 8.1.1 1.0.5 1.0.6 1.0.7 1.0.8 1.0.9 1.1.0 1.2.0 1.3.0 2.0.0 2.0.1 2.1.0 2.1.1 All 160 releases
← All changes | includes/handler/class-follow.php +77 -140 9.2.13.2.5 View file →
@@ -1,182 +1,119 @@
1 1 <?php
2 -/**
3 - * Follow handler file.
4 - *
5 - * @package Activitypub
6 - */
7 -
8 2 namespace Activitypub\Handler;
9 3
4 +use Activitypub\Http;
5 +use Activitypub\Notification;
10 6 use Activitypub\Activity\Activity;
11 -use Activitypub\Application;
12 -use Activitypub\Collection\Actors;
7 +use Activitypub\Collection\Users;
13 8 use Activitypub\Collection\Followers;
14 -use Activitypub\Collection\Remote_Actors;
15 -use Activitypub\Http;
16 9
17 -use function Activitypub\add_to_outbox;
18 -use function Activitypub\object_to_uri;
19 -
20 10 /**
21 - * Handle Follow requests.
11 + * Handle Follow requests
22 12 */
23 13 class Follow {
24 14 /**
25 - * Initialize the class, registering WordPress hooks.
15 + * Initialize the class, registering WordPress hooks
26 16 */
27 17 public static function init() {
28 - \add_action( 'activitypub_inbox_follow', array( self::class, 'handle_follow' ), 10, 2 );
29 - \add_action( 'activitypub_handled_follow', array( self::class, 'queue_accept' ), 10, 4 );
18 + \add_action(
19 + 'activitypub_inbox_follow',
20 + array( self::class, 'handle_follow' )
21 + );
30 22
31 - // The Application actor cannot be followed; explicitly reject such Follows so they don't sit "pending" on the remote instance forever.
32 - \add_action( 'activitypub_inbox_shared_follow', array( self::class, 'reject_application_follow' ), 10, 2 );
23 + \add_action(
24 + 'activitypub_followers_post_follow',
25 + array( self::class, 'send_follow_response' ),
26 + 10,
27 + 4
28 + );
33 29 }
34 30
35 31 /**
36 - * Handle "Follow" requests.
32 + * Handle "Follow" requests
37 33 *
38 - * @param array $activity The activity object.
39 - * @param int|int[] $user_ids The user ID(s).
34 + * @param array $activity The activity object
35 + * @param int $user_id The user ID
40 36 */
41 - public static function handle_follow( $activity, $user_ids ) {
42 - // Extract the user ID (follow requests are always for a single user).
43 - $user_id = \is_array( $user_ids ) ? \reset( $user_ids ) : $user_ids;
37 + public static function handle_follow( $activity ) {
38 + $user = Users::get_by_resource( $activity['object'] );
44 39
45 - // Check if the actor already follows the user.
46 - $already_following = false;
47 - $remote_actor = Remote_Actors::get_by_uri( $activity['actor'] );
48 - if ( ! \is_wp_error( $remote_actor ) ) {
49 - $already_following = Followers::follows( $remote_actor->ID, $user_id );
50 - }
51 -
52 - // Save follower if not already following.
53 - if ( $already_following ) {
54 - $success = false;
55 - } else {
56 - $remote_actor = Followers::add( $user_id, $activity['actor'] );
57 - $success = ! \is_wp_error( $remote_actor );
58 -
59 - if ( $success ) {
60 - $remote_actor = \get_post( $remote_actor );
61 - }
62 - }
63 -
64 - /**
65 - * Fires after a new follower has been added.
66 - *
67 - * @deprecated 7.5.0 Use "activitypub_handled_follow" instead.
68 - *
69 - * @param string $actor The URL of the actor (follower) who initiated the follow.
70 - * @param array $activity The complete activity data of the follow request.
71 - * @param int $user_id The ID of the WordPress user being followed.
72 - * @param \WP_Post|\WP_Error $remote_actor The Actor object containing the new follower's data.
73 - */
74 - \do_action_deprecated( 'activitypub_followers_post_follow', array( $activity['actor'], $activity, $user_id, $remote_actor ), '7.5.0', 'activitypub_handled_follow' );
75 -
76 - /**
77 - * Fires after a Follow activity has been handled.
78 - *
79 - * @param array $activity The ActivityPub activity data.
80 - * @param int[] $user_ids The local user IDs.
81 - * @param bool $success True on success, false otherwise.
82 - * @param \WP_Post|\WP_Error $remote_actor The remote actor/follower, or WP_Error if failed.
83 - */
84 - \do_action( 'activitypub_handled_follow', $activity, (array) $user_ids, $success, $remote_actor );
85 - }
86 -
87 - /**
88 - * Send Accept response.
89 - *
90 - * @param array $activity_object The ActivityPub activity data.
91 - * @param int|int[] $user_ids The local user IDs.
92 - * @param bool $success True on success, false otherwise.
93 - * @param \WP_Post|\WP_Error $remote_actor The remote actor/follower, or WP_Error if failed.
94 - */
95 - public static function queue_accept( $activity_object, $user_ids, $success, $remote_actor ) {
96 - if ( \is_wp_error( $remote_actor ) ) {
97 - // Impossible to send a "Reject" because we can not get the Remote-Inbox.
40 + if ( ! $user || is_wp_error( $user ) ) {
41 + // If we can not find a user,
42 + // we can not initiate a follow process
98 43 return;
99 44 }
100 45
101 - // Extract the user ID from the array (follow requests are always for a single user).
102 - $user_id = \is_array( $user_ids ) ? \reset( $user_ids ) : $user_ids;
46 + $user_id = $user->get__id();
103 47
104 - $actor = $activity_object['actor'];
48 + // save follower
49 + $follower = Followers::add_follower(
50 + $user_id,
51 + $activity['actor']
52 + );
105 53
106 - // Only send minimal data.
107 - $activity_object = \array_intersect_key(
108 - $activity_object,
109 - array(
110 - 'id' => 1,
111 - 'type' => 1,
112 - 'actor' => 1,
113 - 'object' => 1,
114 - )
54 + do_action(
55 + 'activitypub_followers_post_follow',
56 + $activity['actor'],
57 + $activity,
58 + $user_id,
59 + $follower
115 60 );
116 61
117 - $activity = new Activity();
118 - $activity->set_type( 'Accept' );
119 - $activity->set_actor( Actors::get_by_id( $user_id )->get_id() );
120 - $activity->set_object( $activity_object );
121 - $activity->set_to( array( $actor ) );
122 -
123 - add_to_outbox( $activity, null, $user_id, ACTIVITYPUB_CONTENT_VISIBILITY_PRIVATE );
62 + // send notification
63 + $notification = new Notification(
64 + 'follow',
65 + $activity['actor'],
66 + $activity,
67 + $user_id
68 + );
69 + $notification->send();
124 70 }
125 71
126 72 /**
127 - * Reject Follow requests aimed at the Application actor.
73 + * Send Accept response
128 74 *
129 - * The Application advertises `manuallyApprovesFollowers` but is not followable,
130 - * so an explicit Reject is the only way a remote follow request gets resolved.
131 - * The Reject is sent directly instead of through the Outbox, which only
132 - * dispatches for real actors, and is signed with the Application key.
75 + * @param string $actor The Actor URL
76 + * @param array $object The Activity object
77 + * @param int $user_id The ID of the WordPress User
78 + * @param Activitypub\Model\Follower $follower The Follower object
133 79 *
134 - * @since 9.1.0
135 - *
136 - * @param array $activity The Follow activity data.
137 - * @param int[] $user_ids The local recipient IDs the inbox resolved.
80 + * @return void
138 81 */
139 - public static function reject_application_follow( $activity, $user_ids ) {
140 - // A resolved recipient means the Follow targets a real actor, not the Application.
141 - if ( ! empty( $user_ids ) ) {
82 + public static function send_follow_response( $actor, $object, $user_id, $follower ) {
83 + if ( \is_wp_error( $follower ) ) {
84 + // it is not even possible to send a "Reject" because
85 + // we can not get the Remote-Inbox
142 86 return;
143 87 }
144 88
145 - if ( empty( $activity['object'] ) || ! Application::is_application_resource( object_to_uri( $activity['object'] ) ) ) {
146 - return;
147 - }
89 + // only send minimal data
90 + $object = array_intersect_key(
91 + $object,
92 + array_flip(
93 + array(
94 + 'id',
95 + 'type',
96 + 'actor',
97 + 'object',
98 + )
99 + )
100 + );
148 101
149 - $actor = object_to_uri( $activity['actor'] );
150 - $remote_actor = Remote_Actors::fetch_by_uri( $actor );
102 + $user = Users::get_by_id( $user_id );
151 103
152 - if ( \is_wp_error( $remote_actor ) ) {
153 - return;
154 - }
104 + // get inbox
105 + $inbox = $follower->get_shared_inbox();
155 106
156 - $inbox = \get_post_meta( $remote_actor->ID, '_activitypub_inbox', true );
107 + // send "Accept" activity
108 + $activity = new Activity();
109 + $activity->set_type( 'Accept' );
110 + $activity->set_object( $object );
111 + $activity->set_actor( $user->get_id() );
112 + $activity->set_to( $actor );
113 + $activity->set_id( $user->get_id() . '#follow-' . \preg_replace( '~^https?://~', '', $actor ) . '-' . \time() );
157 114
158 - if ( ! $inbox ) {
159 - return;
160 - }
115 + $activity = $activity->to_json();
161 116
162 - // Only send minimal data.
163 - $origin_activity = \array_intersect_key(
164 - $activity,
165 - array(
166 - 'id' => 1,
167 - 'type' => 1,
168 - 'actor' => 1,
169 - 'object' => 1,
170 - )
171 - );
172 -
173 - $reject = new Activity();
174 - $reject->set_type( 'Reject' );
175 - $reject->set_id( Application::get_id() . '#reject-' . \md5( \wp_json_encode( $origin_activity ) ) );
176 - $reject->set_actor( Application::get_id() );
177 - $reject->set_object( $origin_activity );
178 - $reject->set_to( array( $actor ) );
179 -
180 - Http::post( $inbox, $reject->to_json(), null );
117 + Http::post( $inbox, $activity, $user_id );
181 118 }
182 119 }