Return 401s when logged out of more activitypub api endpoints (#750)

Co-authored-by: slothful-vassal <89943360+slothful-vassal@users.noreply.github.com>
This commit is contained in:
Robert Clarke
2026-01-31 22:04:56 +00:00
committed by GitHub
parent 1005aa0a84
commit 029f1f134b
10 changed files with 82 additions and 22 deletions

View File

@@ -1,6 +1,7 @@
import type { Actor } from '$lib/models/activitypub/actor';
import { FollowCreateSchema } from '$lib/models/api/follow_schema';
import type { Follow } from '$lib/models/follow';
import { getActorResponseForHandle } from '$lib/util/activitypub_server_util';
import { APIError, Collection, handleError, list } from '$lib/util/api_util';
import { json, type RequestEvent } from '@sveltejs/kit';
import type { APOrderedCollectionPage } from 'activitypub-types';
@@ -19,7 +20,7 @@ export async function GET(event: RequestEvent) {
throw new APIError(400, "invalid params")
}
const { actor }: { actor: Actor } = await event.locals.pb.send(`/activitypub/actor?resource=acct:${handle}`, { method: "GET", fetch: event.fetch, });
const { actor } = await getActorResponseForHandle(event, handle);
const page = event.url.searchParams.get("page") ?? "1"
@@ -81,4 +82,4 @@ export async function PUT(event: RequestEvent) {
} catch (e) {
return handleError(e)
}
}
}

View File

@@ -1,6 +1,5 @@
import { env } from '$env/dynamic/private';
import type { Profile } from '$lib/models/profile';
import { splitUsername } from '$lib/util/activitypub_util';
import { getActorResponseForHandle } from '$lib/util/activitypub_server_util';
import { handleError } from '$lib/util/api_util';
import { error, json, type RequestEvent } from '@sveltejs/kit';
@@ -10,12 +9,8 @@ export async function GET(event: RequestEvent) {
return error(400, { message: "Bad request" })
}
if(splitUsername(handle)[1] !== undefined && !event.locals.user) {
return error(401, { message: "Unauthorized" })
}
try {
const { actor, error } = await event.locals.pb.send(`/activitypub/actor?resource=acct:${handle}&follows=true`, { method: "GET", fetch: event.fetch, });
const { actor, error: actorError } = await getActorResponseForHandle(event, handle, { follows: true });
const profile: Profile = {
id: actor.id!,
@@ -28,7 +23,7 @@ export async function GET(event: RequestEvent) {
followers: actor.followerCount ?? 0,
following: actor.followingCount ?? 0,
icon: actor.icon ?? "",
error
error: actorError ?? undefined
}
return json({ profile, actor: actor })

View File

@@ -1,6 +1,7 @@
import { RecordListOptionsSchema } from '$lib/models/api/base_schema';
import { type FeedItem } from '$lib/models/feed';
import type { Trail } from '$lib/models/trail';
import { getActorResponseForHandle } from '$lib/util/activitypub_server_util';
import { Collection, handleError } from '$lib/util/api_util';
import { error, json, type RequestEvent } from '@sveltejs/kit';
import { ClientResponseError, type ListResult } from 'pocketbase';
@@ -12,7 +13,7 @@ export async function GET(event: RequestEvent) {
}
try {
const { actor, error } = await event.locals.pb.send(`/activitypub/actor?resource=acct:${handle}`, { method: "GET", fetch: event.fetch, });
const { actor } = await getActorResponseForHandle(event, handle);
const searchParams = Object.fromEntries(event.url.searchParams);
const safeSearchParams = RecordListOptionsSchema.parse(searchParams);

View File

@@ -1,5 +1,6 @@
import type { TrailSearchResult } from '$lib/models/trail';
import type { ListSearchResult } from '$lib/stores/search_store';
import { getActorResponseForHandle } from '$lib/util/activitypub_server_util';
import { handleError } from '$lib/util/api_util';
import { error, json, type RequestEvent } from '@sveltejs/kit';
import type { SearchResponse } from 'meilisearch';
@@ -12,7 +13,7 @@ export async function POST(event: RequestEvent) {
}
try {
const {actor, error} = await event.locals.pb.send(`/activitypub/actor?resource=acct:${handle}`, { method: "GET", fetch: event.fetch, });
const { actor } = await getActorResponseForHandle(event, handle);
const data = await event.request.json()

View File

@@ -1,5 +1,6 @@
import { RecordListOptionsSchema } from '$lib/models/api/base_schema';
import type { SummitLog } from '$lib/models/summit_log';
import { getActorResponseForHandle } from '$lib/util/activitypub_server_util';
import { Collection, handleError } from '$lib/util/api_util';
import { error, json, type RequestEvent } from '@sveltejs/kit';
import { ClientResponseError, type ListResult } from 'pocketbase';
@@ -9,9 +10,9 @@ export async function GET(event: RequestEvent) {
if (!handle) {
return error(400, { message: "Bad request" })
}
try {
const {actor, error} = await event.locals.pb.send(`/activitypub/actor?resource=acct:${handle}`, { method: "GET", fetch: event.fetch, });
const { actor } = await getActorResponseForHandle(event, handle);
const searchParams = Object.fromEntries(event.url.searchParams);
const safeSearchParams = RecordListOptionsSchema.parse(searchParams);
@@ -20,7 +21,7 @@ export async function GET(event: RequestEvent) {
safeSearchParams.filter = safeSearchParams.filter + `&&author='${actor.id}'`
}else {
safeSearchParams.filter = `author='${actor.id}'`
}
}
let summitLogs: SummitLog[];
if (actor.isLocal) {

View File

@@ -1,4 +1,5 @@
import type { TrailSearchResult } from '$lib/models/trail';
import { getActorResponseForHandle } from '$lib/util/activitypub_server_util';
import { handleError } from '$lib/util/api_util';
import { error, json, type RequestEvent } from '@sveltejs/kit';
import type { SearchResponse } from 'meilisearch';
@@ -11,7 +12,7 @@ export async function POST(event: RequestEvent) {
}
try {
const {actor, error} = await event.locals.pb.send(`/activitypub/actor?resource=acct:${handle}`, { method: "GET", fetch: event.fetch, });
const { actor } = await getActorResponseForHandle(event, handle);
const data = await event.request.json()