From 32738d83a8ab4d474411f48a4af09653e1a6d053 Mon Sep 17 00:00:00 2001 From: tobi Date: Mon, 9 Jun 2025 12:32:00 +0200 Subject: [bugfix] Update `GetURL` to extract url from Link objects with href (#4249) # Description > If this is a code change, please include a summary of what you've coded, and link to the issue(s) it closes/implements. > > If this is a documentation change, please briefly describe what you've changed and why. This pull request updates our parsing of the `url` property in incoming ActivityPub items to also include Link items, and not just bare URIs. The first discovered url is still used as the *gtsmodel.Account or *gtsmodel.Status `url` property, so this change only really affects our dereference URL anti-spoof check thingy. ~~Should fix https://codeberg.org/superseriousbusiness/gotosocial/issues/4248 but I need to run it and test it myself first to be sure.~~ Fixes https://codeberg.org/superseriousbusiness/gotosocial/issues/4248 ## Checklist Please put an x inside each checkbox to indicate that you've read and followed it: `[ ]` -> `[x]` If this is a documentation change, only the first checkbox must be filled (you can delete the others if you want). - [x] I/we have read the [GoToSocial contribution guidelines](https://codeberg.org/superseriousbusiness/gotosocial/src/branch/main/CONTRIBUTING.md). - [x] I/we have discussed the proposed changes already, either in an issue on the repository, or in the Matrix chat. - [x] I/we have not leveraged AI to create the proposed changes. - [x] I/we have performed a self-review of added code. - [x] I/we have written code that is legible and maintainable by others. - [x] I/we have commented the added code, particularly in hard-to-understand areas. - [ ] I/we have made any necessary changes to documentation. - [x] I/we have added tests that cover new code. - [x] I/we have run tests and they pass locally with the changes. - [x] I/we have run `go fmt ./...` and `golangci-lint run`. Reviewed-on: https://codeberg.org/superseriousbusiness/gotosocial/pulls/4249 Co-authored-by: tobi Co-committed-by: tobi --- internal/ap/properties.go | 25 ++++++++++++++++++++++++- 1 file changed, 24 insertions(+), 1 deletion(-) (limited to 'internal/ap/properties.go') diff --git a/internal/ap/properties.go b/internal/ap/properties.go index b5154c0aa..722c3fca5 100644 --- a/internal/ap/properties.go +++ b/internal/ap/properties.go @@ -135,7 +135,8 @@ func AppendBcc(with WithBcc, bcc ...*url.URL) { }, bcc...) } -// GetURL returns the IRIs contained in the URL property of 'with'. +// GetURL returns IRIs contained +// in the URL property of 'with'. func GetURL(with WithURL) []*url.URL { urlProp := with.GetActivityStreamsUrl() if urlProp == nil || urlProp.Len() == 0 { @@ -144,9 +145,31 @@ func GetURL(with WithURL) []*url.URL { urls := make([]*url.URL, 0, urlProp.Len()) for i := 0; i < urlProp.Len(); i++ { at := urlProp.At(i) + + // See if it's a plain URI. if at.IsXMLSchemaAnyURI() { u := at.GetXMLSchemaAnyURI() urls = append(urls, u) + continue + } + + // See if it's a Link obj + // with an href property. + if at.IsActivityStreamsLink() { + l := at.GetActivityStreamsLink() + hr := l.GetActivityStreamsHref() + if hr == nil { + // No href. + continue + } + + if hr.IsXMLSchemaAnyURI() { + u := hr.Get() + urls = append(urls, u) + } else if hr.IsIRI() { + u := hr.GetIRI() + urls = append(urls, u) + } } } return urls -- cgit v1.2.3