| @@ -6,9 +6,11 @@ | ||
| 6 | 6 | */ |
| 7 | 7 | |
| 8 | 8 | namespace Activitypub\Handler; |
| 9 | 9 | |
| 10 | -use Activitypub\Collection\Inbox as Inbox_Collection; | |
| 10 | +use Activitypub\Collection\Actors; | |
| 11 | +use Activitypub\Collection\Followers; | |
| 12 | +use Activitypub\Comment; | |
| 11 | 13 | |
| 12 | 14 | use function Activitypub\object_to_uri; |
| 13 | 15 | |
| 14 | 16 | /** |
| @@ -18,85 +20,71 @@ | ||
| 18 | 20 | /** |
| 19 | 21 | * Initialize the class, registering WordPress hooks. |
| 20 | 22 | */ |
| 21 | 23 | public static function init() { |
| 22 | - \add_action( 'activitypub_inbox_undo', array( self::class, 'handle_undo' ), 10, 2 ); | |
| 23 | - \add_action( 'activitypub_validate_object', array( self::class, 'validate_object' ), 10, 3 ); | |
| 24 | + \add_action( | |
| 25 | + 'activitypub_inbox_undo', | |
| 26 | + array( self::class, 'handle_undo' ), | |
| 27 | + 10, | |
| 28 | + 2 | |
| 29 | + ); | |
| 24 | 30 | } |
| 25 | 31 | |
| 26 | 32 | /** |
| 27 | 33 | * Handle "Unfollow" requests. |
| 28 | 34 | * |
| 29 | - * @param array $activity The JSON "Undo" Activity. | |
| 30 | - * @param int|int[]|null $user_ids The user ID(s). | |
| 35 | + * @param array $activity The JSON "Undo" Activity. | |
| 36 | + * @param int|null $user_id The ID of the user who initiated the "Undo" activity. | |
| 31 | 37 | */ |
| 32 | - public static function handle_undo( $activity, $user_ids ) { | |
| 33 | - $success = false; | |
| 38 | + public static function handle_undo( $activity, $user_id ) { | |
| 39 | + if ( | |
| 40 | + ! isset( $activity['object']['type'] ) || | |
| 41 | + ! isset( $activity['object']['object'] ) | |
| 42 | + ) { | |
| 43 | + return; | |
| 44 | + } | |
| 34 | 45 | |
| 35 | - /* | |
| 36 | - * Resolve the sender so Inbox::undo() can verify ownership. A genuinely absent actor | |
| 37 | - * maps to null (no ownership check, for programmatic callers), but an actor that is | |
| 38 | - * present yet unparseable must be rejected rather than skipping the check — passing | |
| 39 | - * null there would re-open the undo-by-id attack. | |
| 40 | - */ | |
| 41 | - $actor = isset( $activity['actor'] ) ? object_to_uri( $activity['actor'] ) : null; | |
| 46 | + $type = $activity['object']['type']; | |
| 47 | + $state = false; | |
| 42 | 48 | |
| 43 | - if ( isset( $activity['actor'] ) && empty( $actor ) ) { | |
| 44 | - $result = new \WP_Error( | |
| 45 | - 'activitypub_undo_invalid_actor', | |
| 46 | - \__( 'The Undo activity has an invalid actor.', 'activitypub' ), | |
| 47 | - array( 'status' => 400 ) | |
| 48 | - ); | |
| 49 | - } else { | |
| 50 | - $result = Inbox_Collection::undo( object_to_uri( $activity['object'] ), $actor ); | |
| 51 | - } | |
| 49 | + // Handle "Unfollow" requests. | |
| 50 | + if ( 'Follow' === $type ) { | |
| 51 | + $id = object_to_uri( $activity['object']['object'] ); | |
| 52 | + $user = Actors::get_by_resource( $id ); | |
| 52 | 53 | |
| 53 | - if ( $result && ! \is_wp_error( $result ) ) { | |
| 54 | - $success = true; | |
| 55 | - } | |
| 54 | + if ( ! $user || is_wp_error( $user ) ) { | |
| 55 | + // If we can not find a user, we can not initiate a follow process. | |
| 56 | + return; | |
| 57 | + } | |
| 56 | 58 | |
| 57 | - /** | |
| 58 | - * Fires after an ActivityPub Undo activity has been handled. | |
| 59 | - * | |
| 60 | - * @param array $activity The ActivityPub activity data. | |
| 61 | - * @param int[] $user_ids The local user IDs. | |
| 62 | - * @param bool $success True on success, false on failure. | |
| 63 | - * @param \WP_Comment|string $result The target, based on the activity that is being undone. | |
| 64 | - */ | |
| 65 | - \do_action( 'activitypub_handled_undo', $activity, (array) $user_ids, $success, $result ); | |
| 66 | - } | |
| 59 | + $user_id = $user->get__id(); | |
| 60 | + $actor = object_to_uri( $activity['actor'] ); | |
| 67 | 61 | |
| 68 | - /** | |
| 69 | - * Validate the object. | |
| 70 | - * | |
| 71 | - * @param bool $valid The validation state. | |
| 72 | - * @param string $param The object parameter. | |
| 73 | - * @param \WP_REST_Request $request The request object. | |
| 74 | - * | |
| 75 | - * @return bool The validation state: true if valid, false if not. | |
| 76 | - */ | |
| 77 | - public static function validate_object( $valid, $param, $request ) { | |
| 78 | - $activity = $request->get_json_params(); | |
| 79 | - | |
| 80 | - if ( empty( $activity['type'] ) ) { | |
| 81 | - return false; | |
| 62 | + $state = Followers::remove_follower( $user_id, $actor ); | |
| 82 | 63 | } |
| 83 | 64 | |
| 84 | - if ( 'Undo' !== $activity['type'] ) { | |
| 85 | - return $valid; | |
| 86 | - } | |
| 65 | + // Handle "Undo" requests for "Like" and "Create" activities. | |
| 66 | + if ( in_array( $type, array( 'Like', 'Create', 'Announce' ), true ) ) { | |
| 67 | + if ( ACTIVITYPUB_DISABLE_INCOMING_INTERACTIONS ) { | |
| 68 | + return; | |
| 69 | + } | |
| 87 | 70 | |
| 88 | - if ( ! isset( $activity['actor'], $activity['object'] ) ) { | |
| 89 | - return false; | |
| 90 | - } | |
| 71 | + $object_id = object_to_uri( $activity['object'] ); | |
| 72 | + $comment = Comment::object_id_to_comment( esc_url_raw( $object_id ) ); | |
| 91 | 73 | |
| 92 | - if ( ! \is_array( $activity['object'] ) && ! \is_string( $activity['object'] ) ) { | |
| 93 | - return false; | |
| 94 | - } | |
| 74 | + if ( empty( $comment ) ) { | |
| 75 | + return; | |
| 76 | + } | |
| 95 | 77 | |
| 96 | - if ( \is_array( $activity['object'] ) && ! isset( $activity['object']['id'] ) ) { | |
| 97 | - return false; | |
| 78 | + $state = wp_trash_comment( $comment ); | |
| 98 | 79 | } |
| 99 | 80 | |
| 100 | - return $valid; | |
| 81 | + /** | |
| 82 | + * Fires after an "Undo" activity has been handled. | |
| 83 | + * | |
| 84 | + * @param array $activity The JSON "Undo" Activity. | |
| 85 | + * @param int|null $user_id The ID of the user who initiated the "Undo" activity otherwise null. | |
| 86 | + * @param mixed $state The state of the "Undo" activity. | |
| 87 | + */ | |
| 88 | + do_action( 'activitypub_handled_undo', $activity, $user_id, $state ); | |
| 101 | 89 | } |
| 102 | 90 | } |