From 7d31bd97ff45ccf404d4f06b7a699f0d62ba85f1 Mon Sep 17 00:00:00 2001 From: MeiMei <30769358+mei23@users.noreply.github.com> Date: Sun, 21 Apr 2019 02:41:12 +0900 Subject: [PATCH] Validate Note on createNote for v10 (#4757) * Validate Note on createNote * Add extractApHost --- src/misc/convert-host.ts | 5 +++++ src/remote/activitypub/models/note.ts | 30 ++++++++++++++++++++++++--- 2 files changed, 32 insertions(+), 3 deletions(-) diff --git a/src/misc/convert-host.ts b/src/misc/convert-host.ts index 8f2f1c7ab..ac8b24725 100644 --- a/src/misc/convert-host.ts +++ b/src/misc/convert-host.ts @@ -16,6 +16,11 @@ export function extractDbHost(uri: string) { return toDbHost(url.hostname); } +export function extractApHost(uri: string) { + const url = new URL(uri); + return toApHost(url.hostname); +} + export function toDbHost(host: string) { if (host == null) return null; return toUnicode(host.toLowerCase()); diff --git a/src/remote/activitypub/models/note.ts b/src/remote/activitypub/models/note.ts index 625162152..87764dd06 100644 --- a/src/remote/activitypub/models/note.ts +++ b/src/remote/activitypub/models/note.ts @@ -20,10 +20,32 @@ import { apLogger } from '../logger'; import { IDriveFile } from '../../../models/drive-file'; import { deliverQuestionUpdate } from '../../../services/note/polls/update'; import Instance from '../../../models/instance'; -import { extractDbHost } from '../../../misc/convert-host'; +import { extractDbHost, extractApHost } from '../../../misc/convert-host'; const logger = apLogger; +export function validateNote(object: any, uri: string) { + const expectHost = extractApHost(uri); + + if (object == null) { + return new Error('invalid Note: object is null'); + } + + if (!['Note', 'Question', 'Article'].includes(object.type)) { + return new Error(`invalid Note: invalied object type ${object.type}`); + } + + if (object.id && extractApHost(object.id) !== expectHost) { + return new Error(`invalid Note: id has different host. expected: ${expectHost}, actual: ${extractApHost(object.id)}`); + } + + if (object.attributedTo && extractApHost(object.attributedTo) !== expectHost) { + return new Error(`invalid Note: attributedTo has different host. expected: ${expectHost}, actual: ${extractApHost(object.attributedTo)}`); + } + + return null; +} + /** * Noteをフェッチします。 * @@ -57,8 +79,10 @@ export async function createNote(value: any, resolver?: Resolver, silent = false const object: any = await resolver.resolve(value); - if (!object || !['Note', 'Question', 'Article'].includes(object.type)) { - logger.error(`invalid note: ${value}`, { + const entryUri = value.id || value; + const err = validateNote(object, entryUri); + if (err) { + logger.error(`${err.message}`, { resolver: { history: resolver.getHistory() },