source: Klonkt/test/c2s-direct.test.js@ e6c6e6f

main
Last change on this file since e6c6e6f was e6c6e6f, checked in by Robin <roboburr@…>, 7 weeks ago

Feature: uploadMedia endpoint + attachments on direct notes

The actor has been advertising endpoints.uploadMedia without a route
behind it; this implements it. A bearer scoped to the site POSTs one
image/audio/video (multipart field "file", the AP C2S convention) into
the reply-media store and gets { url, mediaType, name } back. Direct
notes (private mentions) now carry attachments through the same
deliverReply-style validation (own /media/ uploads only, max 4), so
the help-buoy capture rides a DM to the guardians while the note stays
direct: recipients only, empty cc, unboostable.

Changed files:
src/routes/activitypub.js

  • POST /ap/users/:slug/uploadMedia (bearer-gated, multer, 32MB)

src/services/ActivityPubService.js

  • ingest passes AS2 attachments into the direct path (absolute own-base URLs normalized to relative)
  • deliverDirectNote validates + stores attachments

New file: (none)
test/c2s-direct.test.js

  • direct note renders its attachment, addressing stays direct

-robo
Co-Authored-By: Claude Opus 4.8 <noreply@…>

  • Property mode set to 100644
File size: 4.0 KB
RevLine 
[024f4f8]1// Direct notes (private mentions, shaer-tqc): never Public, never boostable.
2import { test } from 'node:test';
3import assert from 'node:assert/strict';
4
5process.env.DATABASE_PATH = ':memory:';
6process.env.PUBLIC_BASE_URL = 'https://test.example';
7
8const dbMod = await import('../src/config/database.js');
9const db = dbMod.default;
10dbMod.initializeDatabase();
11const AP = (await import('../src/services/ActivityPubService.js')).default;
12
13const PUB = 'https://www.w3.org/ns/activitystreams#Public';
14db.prepare('INSERT INTO users (id, username, email, password_hash, role) VALUES (?,?,?,?,?)').run('u1', 'u1', 'u1@test', 'x', 'god');
15db.prepare('INSERT INTO sites (id, slug, title, owner_id, is_primary) VALUES (?,?,?,?,?)').run('s1', 'me', 'Me', 'u1', 1);
16const site = db.prepare('SELECT * FROM sites WHERE id = ?').get('s1');
17const user = { id: 'u1', username: 'u1' };
18
19test('a direct outbox row addresses only its recipients, no Public, no cc', () => {
20 db.prepare(`INSERT INTO ap_outbox (id, site_slug, post_id, post_slug, in_reply_to, to_actor, to_handle, content, visibility, to_actors, created_at)
21 VALUES ('d1','me','',NULL,NULL,'https://r.test/u/g','@g@r.test','<p>help</p>','direct','["https://r.test/u/g","https://q.test/u/h"]',CURRENT_TIMESTAMP)`).run();
22 const row = db.prepare('SELECT * FROM ap_outbox WHERE id = ?').get('d1');
23 const note = AP.buildReplyNote('https://test.example', site, row);
24 assert.deepEqual(note.to, ['https://r.test/u/g', 'https://q.test/u/h']);
25 assert.deepEqual(note.cc, []);
26 assert.ok(!JSON.stringify(note.to).includes(PUB) && !JSON.stringify(note.cc).includes(PUB));
27});
28
[e6c6e6f]29test('a direct note carries its attachments (help-buoy capture)', () => {
30 db.prepare(`INSERT INTO ap_outbox (id, site_slug, post_id, post_slug, in_reply_to, to_actor, to_handle, content, visibility, to_actors, attachments, created_at)
31 VALUES ('d2','me','',NULL,NULL,'https://r.test/u/g','@g@r.test','<p>kijk</p>','direct','["https://r.test/u/g"]','[{"url":"/media/reply-media/x.png","mediaType":"image/png","name":"capture"}]',CURRENT_TIMESTAMP)`).run();
32 const row = db.prepare('SELECT * FROM ap_outbox WHERE id = ?').get('d2');
33 const note = AP.buildReplyNote('https://test.example', site, row);
34 assert.equal(note.attachment.length, 1);
35 assert.equal(note.attachment[0].type, 'Image');
36 assert.ok(note.attachment[0].url.endsWith('/media/reply-media/x.png'));
37 assert.deepEqual(note.cc, []); // still direct
38});
39
[024f4f8]40test('direct without any real recipient is refused (400 no_recipients)', async () => {
41 const r = await AP.ingestOutboxActivity(site, user, {
42 type: 'Note', content: '<p>x</p>',
43 to: ['https://test.example/ap/users/me/followers'], cc: [], // friends-shaped? no: followers in to = friends
44 });
45 // followers-only reads as friends, so force the direct shape: bare unknown string
46 const r2 = await AP.ingestOutboxActivity(site, user, { type: 'Note', content: '<p>x</p>', to: [], cc: [] });
47 // empty addressing = legacy public; the real no-recipient direct case:
48 const r3 = await AP.ingestOutboxActivity(site, user, { type: 'Note', content: '<p>x</p>', to: ['not-a-uri'], cc: [] });
49 assert.equal(r3.status, 400);
50 assert.equal(r3.error, 'no_recipients');
51 assert.ok(r && r2); // shapes above answered too (not the point of this test)
52});
53
54test('C2S Announce/Like of a non-public local post is refused (403)', async () => {
55 db.prepare(`INSERT INTO posts (id, site_id, slug, author_id, title, content, status, type, fan_only, ap_visibility, created_at, updated_at, published_at)
56 VALUES ('pf','s1','geheim','u1','','<p>prive</p>','published','post',1,'friends',datetime('now'),datetime('now'),datetime('now'))`).run();
57 const noteUrl = 'https://test.example/ap/notes/pf';
58 const boost = await AP.ingestOutboxActivity(site, user, { type: 'Announce', object: noteUrl });
59 assert.equal(boost.status, 403);
60 assert.equal(boost.error, 'not_public');
61 const like = await AP.ingestOutboxActivity(site, user, { type: 'Like', object: noteUrl });
62 assert.equal(like.status, 403);
63});
Note: See TracBrowser for help on using the repository browser.