@ -11,97 +11,153 @@ class ResolveRemoteAccountService < BaseService
# @param [String] uri User URI in the form of username@domain
# @param [String] uri User URI in the form of username@domain
# @return [Account]
# @return [Account]
def call ( uri , update_profile = true , redirected = nil )
def call ( uri , update_profile = true , redirected = nil )
username , domain = uri . split ( '@' )
@username , @ domain = uri . split ( '@' )
return Account . find_local ( username ) if TagManager . instance . local_domain? ( domain )
return Account . find_local ( @ username) if TagManager . instance . local_domain? ( @ domain)
account = Account . find_remote ( username , domain )
@account = Account . find_remote ( @username , @domain )
return account unless account_needs_webfinger_update? ( account )
return @account unless webfinger_update_due?
Rails . logger . debug " Looking up webfinger for #{ uri } "
Rails . logger . debug " Looking up webfinger for #{ uri } "
data = Goldfinger . finger ( " acct: #{ uri } " )
@webfinger = Goldfinger . finger ( " acct: #{ uri } " )
raise Goldfinger :: Error , 'Missing resource links' if data . link ( 'http://schemas.google.com/g/2010#updates-from' ) . nil? || data . link ( 'salmon' ) . nil? || data . link ( 'http://webfinger.net/rel/profile-page' ) . nil? || data . link ( 'magic-public-key' ) . nil ?
raise Goldfinger :: Error , 'Missing resource links' if links_missing ?
# Disallow account hijacking
confirmed_username , confirmed_domain = @webfinger . subject . gsub ( / \ Aacct: / , '' ) . split ( '@' )
confirmed_username , confirmed_domain = data . subject . gsub ( / \ Aacct: / , '' ) . split ( '@' )
unless confirmed_username . casecmp ( username ) . zero? && confirmed_domain . casecmp ( domain ) . zero?
if confirmed_username . casecmp ( @username ) . zero? && confirmed_domain . casecmp ( @domain ) . zero?
@username = confirmed_username
@domain = confirmed_domain
else
return call ( " #{ confirmed_username } @ #{ confirmed_domain } " , update_profile , true ) if redirected . nil?
return call ( " #{ confirmed_username } @ #{ confirmed_domain } " , update_profile , true ) if redirected . nil?
raise Goldfinger :: Error , 'Requested and returned acct URI do not match'
raise Goldfinger :: Error , 'Requested and returned acct URIs do not match'
end
end
return Account . find_local ( confirmed_ username) if TagManager . instance . local_domain? ( confirmed_ domain)
return Account . find_local ( @ username) if TagManager . instance . local_domain? ( @ domain)
confirmed_account = Account . find_remote ( confirmed_username , confirmed_domain )
RedisLock . acquire ( lock_options ) do | lock |
if confirmed_account . nil ?
if lock . acquired ?
Rails . logger . debug " Creating new remote account for #{ uri } "
@account = Account . find_remote ( @username , @domain )
domain_block = DomainBlock . find_by ( domain : domain )
create_account if @account . nil?
account = Account . new ( username : confirmed_username , domain : confirmed_domain )
update_account
account . suspended = true if domain_block && domain_block . suspend?
account . silenced = true if domain_block && domain_block . silence?
update_account_profile if update_profile
account . private_key = nil
end
else
account = confirmed_account
end
end
account . last_webfingered_at = Time . now . utc
@account
end
account . remote_url = data . link ( 'http://schemas.google.com/g/2010#updates-from' ) . href
private
account . salmon_url = data . link ( 'salmon' ) . href
account . url = data . link ( 'http://webfinger.net/rel/profile-page' ) . href
account . public_key = magic_key_to_pem ( data . link ( 'magic-public-key' ) . href )
body , xml = get_feed ( account . remote_url )
def links_missing?
hubs = get_hubs ( xml )
@webfinger . link ( 'http://schemas.google.com/g/2010#updates-from' ) . nil? ||
@webfinger . link ( 'salmon' ) . nil? ||
@webfinger . link ( 'http://webfinger.net/rel/profile-page' ) . nil? ||
@webfinger . link ( 'magic-public-key' ) . nil?
end
account . uri = get_account_uri ( xml )
def webfinger_update_due?
account . hub_url = hubs . first . attribute ( 'href' ) . value
@account . nil? || @account . last_webfingered_at . nil? || @account . last_webfingered_at < = 1 . day . ago
end
begin
def create_account
account . save!
Rails . logger . debug " Creating new remote account for #{ @username } @ #{ @domain } "
get_profile ( body , account ) if update_profile
rescue ActiveRecord :: RecordNotUnique
# The account has been added by another worker!
return Account . find_remote ( confirmed_username , confirmed_domain )
end
account
@account = Account . new ( username : @username , domain : @domain )
@account . suspended = true if auto_suspend?
@account . silenced = true if auto_silence?
@account . private_key = nil
end
end
private
def update_account
@account . last_webfingered_at = Time . now . utc
@account . remote_url = atom_url
@account . salmon_url = salmon_url
@account . url = url
@account . public_key = public_key
@account . uri = canonical_uri
@account . hub_url = hub_url
@account . save!
end
def account_needs_webfinger_update? ( account )
def auto_suspend?
account & . last_webfingered_at . nil? || account . last_webfingered_at < = 1 . day . ago
domain_block && domain_block . suspend?
end
end
def get_feed ( url )
def auto_silence?
response = Request . new ( :get , url ) . perform
domain_block && domain_block . silence?
raise Goldfinger :: Error , " Feed attempt failed for #{ url } : HTTP #{ response . code } " unless response . code == 200
[ response . to_s , Nokogiri :: XML ( response ) ]
end
end
def get_hubs ( xml )
def domain_block
hubs = xml . xpath ( '//xmlns:link[@rel="hub"]' )
return @domain_block if defined? ( @domain_block )
raise Goldfinger :: Error , 'No PubSubHubbub hubs found' if hubs . empty? || hubs . first . attribute ( 'href' ) . nil?
@domain_block = DomainBlock . find_by ( domain : @domain )
hubs
end
end
def get_account_uri ( xml )
def atom_url
author_uri = xml . at_xpath ( '/xmlns:feed/xmlns:author/xmlns:uri' )
@atom_url || = @webfinger . link ( 'http://schemas.google.com/g/2010#updates-from' ) . href
end
def salmon_url
@salmon_url || = @webfinger . link ( 'salmon' ) . href
end
def url
@url || = @webfinger . link ( 'http://webfinger.net/rel/profile-page' ) . href
end
def public_key
@public_key || = magic_key_to_pem ( @webfinger . link ( 'magic-public-key' ) . href )
end
def canonical_uri
return @canonical_uri if defined? ( @canonical_uri )
author_uri = atom . at_xpath ( '/xmlns:feed/xmlns:author/xmlns:uri' )
if author_uri . nil?
if author_uri . nil?
owner = xml . at_xpath ( '/xmlns:feed' ) . at_xpath ( './dfrn:owner' , dfrn : DFRN_NS )
owner = atom . at_xpath ( '/xmlns:feed' ) . at_xpath ( './dfrn:owner' , dfrn : DFRN_NS )
author_uri = owner . at_xpath ( './xmlns:uri' ) unless owner . nil?
author_uri = owner . at_xpath ( './xmlns:uri' ) unless owner . nil?
end
end
raise Goldfinger :: Error , 'Author URI could not be found' if author_uri . nil?
raise Goldfinger :: Error , 'Author URI could not be found' if author_uri . nil?
author_uri . content
@canonical_uri = author_uri . content
end
def hub_url
return @hub_url if defined? ( @hub_url )
hubs = atom . xpath ( '//xmlns:link[@rel="hub"]' )
raise Goldfinger :: Error , 'No PubSubHubbub hubs found' if hubs . empty? || hubs . first [ 'href' ] . nil?
@hub_url = hubs . first [ 'href' ]
end
def atom_body
return @atom_body if defined? ( @atom_body )
response = Request . new ( :get , atom_url ) . perform
raise Goldfinger :: Error , " Feed attempt failed for #{ atom_url } : HTTP #{ response . code } " unless response . code == 200
@atom_body = response . to_s
end
def atom
return @atom if defined? ( @atom )
@atom = Nokogiri :: XML ( atom_body )
end
def update_account_profile
RemoteProfileUpdateWorker . perform_async ( @account . id , atom_body . force_encoding ( 'UTF-8' ) , false )
end
end
def get_profile ( body , account )
def lock_options
RemoteProfileUpdateWorker . perform_async ( account . id , body . force_encoding ( 'UTF-8' ) , false )
{ redis : Redis . current , key : " resolve: #{ @username } @ #{ @domain } " }
end
end
end
end