logo

pleroma

My custom branche(s) on git.pleroma.social/pleroma/pleroma git clone https://hacktivis.me/git/pleroma.git

steal_emoji_policy_test.exs (5010B)


  1. # Pleroma: A lightweight social networking server
  2. # Copyright © 2017-2022 Pleroma Authors <https://pleroma.social/>
  3. # SPDX-License-Identifier: AGPL-3.0-only
  4. defmodule Pleroma.Web.ActivityPub.MRF.StealEmojiPolicyTest do
  5. use Pleroma.DataCase
  6. alias Pleroma.Config
  7. alias Pleroma.Emoji
  8. alias Pleroma.Web.ActivityPub.MRF.StealEmojiPolicy
  9. setup do
  10. emoji_path = [:instance, :static_dir] |> Config.get() |> Path.join("emoji/stolen")
  11. Emoji.reload()
  12. message = %{
  13. "type" => "Create",
  14. "object" => %{
  15. "emoji" => [{"firedfox", "https://example.org/emoji/firedfox.png"}],
  16. "actor" => "https://example.org/users/admin"
  17. }
  18. }
  19. on_exit(fn ->
  20. File.rm_rf!(emoji_path)
  21. end)
  22. [message: message, path: emoji_path]
  23. end
  24. test "does nothing by default", %{message: message} do
  25. refute "firedfox" in installed()
  26. assert {:ok, _message} = StealEmojiPolicy.filter(message)
  27. refute "firedfox" in installed()
  28. end
  29. test "Steals emoji on unknown shortcode from allowed remote host", %{
  30. message: message,
  31. path: path
  32. } do
  33. refute "firedfox" in installed()
  34. refute File.exists?(path)
  35. Tesla.Mock.mock(fn %{method: :get, url: "https://example.org/emoji/firedfox.png"} ->
  36. %Tesla.Env{status: 200, body: File.read!("test/fixtures/image.jpg")}
  37. end)
  38. clear_config(:mrf_steal_emoji, hosts: ["example.org"], size_limit: 284_468)
  39. assert {:ok, _message} = StealEmojiPolicy.filter(message)
  40. assert "firedfox" in installed()
  41. assert File.exists?(path)
  42. assert path
  43. |> Path.join("firedfox.png")
  44. |> File.exists?()
  45. end
  46. test "works with unknown extension", %{path: path} do
  47. message = %{
  48. "type" => "Create",
  49. "object" => %{
  50. "emoji" => [{"firedfox", "https://example.org/emoji/firedfox"}],
  51. "actor" => "https://example.org/users/admin"
  52. }
  53. }
  54. fullpath = Path.join(path, "firedfox.png")
  55. Tesla.Mock.mock(fn %{method: :get, url: "https://example.org/emoji/firedfox"} ->
  56. %Tesla.Env{status: 200, body: File.read!("test/fixtures/image.jpg")}
  57. end)
  58. clear_config(:mrf_steal_emoji, hosts: ["example.org"], size_limit: 284_468)
  59. refute "firedfox" in installed()
  60. refute File.exists?(path)
  61. assert {:ok, _message} = StealEmojiPolicy.filter(message)
  62. assert "firedfox" in installed()
  63. assert File.exists?(path)
  64. assert File.exists?(fullpath)
  65. end
  66. test "rejects invalid shortcodes", %{path: path} do
  67. message = %{
  68. "type" => "Create",
  69. "object" => %{
  70. "emoji" => [{"fired/fox", "https://example.org/emoji/firedfox"}],
  71. "actor" => "https://example.org/users/admin"
  72. }
  73. }
  74. fullpath = Path.join(path, "fired/fox.png")
  75. Tesla.Mock.mock(fn %{method: :get, url: "https://example.org/emoji/firedfox"} ->
  76. %Tesla.Env{status: 200, body: File.read!("test/fixtures/image.jpg")}
  77. end)
  78. clear_config(:mrf_steal_emoji, hosts: ["example.org"], size_limit: 284_468)
  79. refute "firedfox" in installed()
  80. refute File.exists?(path)
  81. assert {:ok, _message} = StealEmojiPolicy.filter(message)
  82. refute "fired/fox" in installed()
  83. refute File.exists?(fullpath)
  84. end
  85. test "reject regex shortcode", %{message: message} do
  86. refute "firedfox" in installed()
  87. clear_config(:mrf_steal_emoji,
  88. hosts: ["example.org"],
  89. size_limit: 284_468,
  90. rejected_shortcodes: [~r/firedfox/]
  91. )
  92. assert {:ok, _message} = StealEmojiPolicy.filter(message)
  93. refute "firedfox" in installed()
  94. end
  95. test "reject string shortcode", %{message: message} do
  96. refute "firedfox" in installed()
  97. clear_config(:mrf_steal_emoji,
  98. hosts: ["example.org"],
  99. size_limit: 284_468,
  100. rejected_shortcodes: ["firedfox"]
  101. )
  102. assert {:ok, _message} = StealEmojiPolicy.filter(message)
  103. refute "firedfox" in installed()
  104. end
  105. test "reject if size is above the limit", %{message: message} do
  106. refute "firedfox" in installed()
  107. Tesla.Mock.mock(fn %{method: :get, url: "https://example.org/emoji/firedfox.png"} ->
  108. %Tesla.Env{status: 200, body: File.read!("test/fixtures/image.jpg")}
  109. end)
  110. clear_config(:mrf_steal_emoji, hosts: ["example.org"], size_limit: 50_000)
  111. assert {:ok, _message} = StealEmojiPolicy.filter(message)
  112. refute "firedfox" in installed()
  113. end
  114. test "reject if host returns error", %{message: message} do
  115. refute "firedfox" in installed()
  116. Tesla.Mock.mock(fn %{method: :get, url: "https://example.org/emoji/firedfox.png"} ->
  117. {:ok, %Tesla.Env{status: 404, body: "Not found"}}
  118. end)
  119. clear_config(:mrf_steal_emoji, hosts: ["example.org"], size_limit: 284_468)
  120. ExUnit.CaptureLog.capture_log(fn ->
  121. assert {:ok, _message} = StealEmojiPolicy.filter(message)
  122. end) =~ "MRF.StealEmojiPolicy: Failed to fetch https://example.org/emoji/firedfox.png"
  123. refute "firedfox" in installed()
  124. end
  125. defp installed, do: Emoji.get_all() |> Enum.map(fn {k, _} -> k end)
  126. end