]> cat aescling's git repositories - mastodon.git/commitdiff
Add validation of media attachments, clean up mastodon-own exception classes
authorEugen Rochko <eugen@zeonfederated.com>
Sun, 26 Feb 2017 22:23:06 +0000 (23:23 +0100)
committerEugen Rochko <eugen@zeonfederated.com>
Sun, 26 Feb 2017 22:23:06 +0000 (23:23 +0100)
app/controllers/api/v1/statuses_controller.rb
app/controllers/api_controller.rb
app/controllers/authorize_follow_controller.rb
app/lib/exceptions.rb
app/services/favourite_service.rb
app/services/follow_service.rb
app/services/post_status_service.rb
app/services/reblog_service.rb

index 2ffd4a01815e49db22dffb0c9a335057132f26ee..552f1b1b399628b1527f0e50d65a08563c9f8dc3 100644 (file)
@@ -62,11 +62,11 @@ class Api::V1::StatusesController < ApiController
   end
 
   def create
-      @status = PostStatusService.new.call(current_user.account, params[:status], params[:in_reply_to_id].blank? ? nil : Status.find(params[:in_reply_to_id]), media_ids: params[:media_ids],
-                                                                                                                                                               sensitive: params[:sensitive],
-                                                                                                                                                               spoiler_text: params[:spoiler_text],
-                                                                                                                                                               visibility: params[:visibility],
-                                                                                                                                                               application: doorkeeper_token.application)
+    @status = PostStatusService.new.call(current_user.account, params[:status], params[:in_reply_to_id].blank? ? nil : Status.find(params[:in_reply_to_id]), media_ids: params[:media_ids],
+                                                                                                                                                             sensitive: params[:sensitive],
+                                                                                                                                                             spoiler_text: params[:spoiler_text],
+                                                                                                                                                             visibility: params[:visibility],
+                                                                                                                                                             application: doorkeeper_token.application)
     render action: :show
   end
 
index 5d2bd9a225e3d9b4acf66e3d105b9b53b94113c5..c2002cb796dc31469267c36e9651c8f54183c93b 100644 (file)
@@ -10,7 +10,7 @@ class ApiController < ApplicationController
 
   before_action :set_rate_limit_headers
 
-  rescue_from ActiveRecord::RecordInvalid do |e|
+  rescue_from ActiveRecord::RecordInvalid, Mastodon::ValidationError do |e|
     render json: { error: e.to_s }, status: 422
   end
 
@@ -30,7 +30,7 @@ class ApiController < ApplicationController
     render json: { error: 'Remote SSL certificate could not be verified' }, status: 503
   end
 
-  rescue_from Mastodon::NotPermitted do
+  rescue_from Mastodon::NotPermittedError do
     render json: { error: 'This action is not allowed' }, status: 403
   end
 
index e866b55993b998969748659f4d464912904c1429..c98a5f45f5dc62bd4daf7b957a7a6733ba2ebc35 100644 (file)
@@ -25,7 +25,7 @@ class AuthorizeFollowController < ApplicationController
     else
       redirect_to web_url("accounts/#{@account.id}")
     end
-  rescue ActiveRecord::RecordNotFound, Mastodon::NotPermitted
+  rescue ActiveRecord::RecordNotFound, Mastodon::NotPermittedError
     render :error
   end
 
index 359228c297b443c74336f22a48dd25e04c145e58..200da9fe16a1feac0449641e9f17c7e5342d4176 100644 (file)
@@ -2,5 +2,6 @@
 
 module Mastodon
   class Error < StandardError; end
-  class NotPermitted < Error; end
+  class NotPermittedError < Error; end
+  class ValidationError < Error; end
 end
index 81889830281074fea027742b9377dfc125f099ee..5cc96403cde3e3a7a9c7c65b42801c49e93071bb 100644 (file)
@@ -6,7 +6,7 @@ class FavouriteService < BaseService
   # @param [Status] status
   # @return [Favourite]
   def call(account, status)
-    raise Mastodon::NotPermitted unless status.permitted?(account)
+    raise Mastodon::NotPermittedError unless status.permitted?(account)
 
     favourite = Favourite.create!(account: account, status: status)
 
index 915f95b4c4d86b511ce5728c6da06db1064f4c6c..17b3b25423001c4233011ea0c688c11501511103 100644 (file)
@@ -10,7 +10,7 @@ class FollowService < BaseService
     target_account = FollowRemoteAccountService.new.call(uri)
 
     raise ActiveRecord::RecordNotFound if target_account.nil? || target_account.id == source_account.id || target_account.suspended?
-    raise Mastodon::NotPermitted       if target_account.blocking?(source_account) || source_account.blocking?(target_account)
+    raise Mastodon::NotPermittedError       if target_account.blocking?(source_account) || source_account.blocking?(target_account)
 
     if target_account.locked?
       request_follow(source_account, target_account)
index 7ead80430290d13d89ff249bb41eb79ca9824686..b8179f7dccfc9ca63389d001f75a57f836582e0d 100644 (file)
@@ -13,7 +13,7 @@ class PostStatusService < BaseService
   # @option [Doorkeeper::Application] :application
   # @return [Status]
   def call(account, text, in_reply_to = nil, options = {})
-    media = validate_media options[:media_ids]
+    media  = validate_media!(options[:media_ids])
     status = account.statuses.create!(text: text,
                                       thread: in_reply_to,
                                       sensitive: options[:sensitive],
@@ -34,17 +34,16 @@ class PostStatusService < BaseService
 
   private
 
-  def validate_media(media_ids)
+  def validate_media!(media_ids)
     return if media_ids.nil? || !media_ids.is_a?(Enumerable)
+
+    raise Mastodon::ValidationError, 'Cannot attach more than 4 files' if media_ids.size > 4
+
     media = MediaAttachment.where(status_id: nil).where(id: media_ids.take(4).map(&:to_i))
-    if media.length > 1
-      media.each do |m|
-        if m.video?
-          raise Mastodon::NotPermitted, 'Cannot attach a video to a toot that already contains images'
-        end
-      end
-    end
-    return media
+
+    raise Mastodon::ValidationError, 'Cannot attach a video to a toot that already contains images' if media.size > 1 && media.find(&:video?)
+
+    media
   end
 
   def attach_media(status, media)
index 7a52f041fc5bb793273679811247efc7acf2531c..c14b2925ac509e2478c7ed0e9499b274c12968d0 100644 (file)
@@ -10,7 +10,7 @@ class ReblogService < BaseService
   def call(account, reblogged_status)
     reblogged_status = reblogged_status.reblog if reblogged_status.reblog?
 
-    raise Mastodon::NotPermitted if reblogged_status.private_visibility? || !reblogged_status.permitted?(account)
+    raise Mastodon::NotPermittedError if reblogged_status.private_visibility? || !reblogged_status.permitted?(account)
 
     reblog = account.statuses.create!(reblog: reblogged_status, text: '')