2016-12-06 16:41:42 +00:00
|
|
|
# frozen_string_literal: true
|
|
|
|
|
|
|
|
class SuspendAccountService < BaseService
|
2020-11-07 23:28:39 +00:00
|
|
|
include Payloadable
|
|
|
|
|
2020-09-15 12:37:58 +00:00
|
|
|
def call(account)
|
2016-12-06 16:41:42 +00:00
|
|
|
@account = account
|
|
|
|
|
2020-09-15 12:37:58 +00:00
|
|
|
suspend!
|
2020-11-07 23:28:39 +00:00
|
|
|
reject_remote_follows!
|
|
|
|
distribute_update_actor!
|
2020-09-15 12:37:58 +00:00
|
|
|
unmerge_from_home_timelines!
|
|
|
|
unmerge_from_list_timelines!
|
|
|
|
privatize_media_attachments!
|
2016-12-06 16:41:42 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
private
|
|
|
|
|
2020-09-15 12:37:58 +00:00
|
|
|
def suspend!
|
|
|
|
@account.suspend! unless @account.suspended?
|
2019-03-10 15:18:58 +00:00
|
|
|
end
|
|
|
|
|
2020-11-07 23:28:39 +00:00
|
|
|
def reject_remote_follows!
|
|
|
|
return if @account.local? || !@account.activitypub?
|
|
|
|
|
|
|
|
# When suspending a remote account, the account obviously doesn't
|
|
|
|
# actually become suspended on its origin server, i.e. unlike a
|
|
|
|
# locally suspended account it continues to have access to its home
|
|
|
|
# feed and other content. To prevent it from being able to continue
|
|
|
|
# to access toots it would receive because it follows local accounts,
|
|
|
|
# we have to force it to unfollow them. Unfortunately, there is no
|
|
|
|
# counterpart to this operation, i.e. you can't then force a remote
|
|
|
|
# account to re-follow you, so this part is not reversible.
|
|
|
|
|
|
|
|
follows = Follow.where(account: @account).to_a
|
|
|
|
|
|
|
|
ActivityPub::DeliveryWorker.push_bulk(follows) do |follow|
|
|
|
|
[Oj.dump(serialize_payload(follow, ActivityPub::RejectFollowSerializer)), follow.target_account_id, @account.inbox_url]
|
|
|
|
end
|
|
|
|
|
2020-11-08 17:29:48 +00:00
|
|
|
follows.each(&:destroy)
|
2020-11-07 23:28:39 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
def distribute_update_actor!
|
2021-04-17 12:55:46 +00:00
|
|
|
return unless @account.local?
|
|
|
|
|
|
|
|
account_reach_finder = AccountReachFinder.new(@account)
|
|
|
|
|
|
|
|
ActivityPub::DeliveryWorker.push_bulk(account_reach_finder.inboxes) do |inbox_url|
|
|
|
|
[signed_activity_json, @account.id, inbox_url]
|
|
|
|
end
|
2020-11-07 23:28:39 +00:00
|
|
|
end
|
|
|
|
|
2020-09-15 12:37:58 +00:00
|
|
|
def unmerge_from_home_timelines!
|
|
|
|
@account.followers_for_local_distribution.find_each do |follower|
|
2020-11-07 12:16:00 +00:00
|
|
|
FeedManager.instance.unmerge_from_home(@account, follower)
|
2017-11-07 18:06:44 +00:00
|
|
|
end
|
2017-06-14 16:01:27 +00:00
|
|
|
end
|
|
|
|
|
2020-09-15 12:37:58 +00:00
|
|
|
def unmerge_from_list_timelines!
|
|
|
|
@account.lists_for_local_distribution.find_each do |list|
|
|
|
|
FeedManager.instance.unmerge_from_list(@account, list)
|
2019-09-11 14:32:44 +00:00
|
|
|
end
|
2016-12-06 16:41:42 +00:00
|
|
|
end
|
|
|
|
|
2020-09-15 12:37:58 +00:00
|
|
|
def privatize_media_attachments!
|
|
|
|
attachment_names = MediaAttachment.attachment_definitions.keys
|
2018-12-03 00:32:08 +00:00
|
|
|
|
2020-09-15 12:37:58 +00:00
|
|
|
@account.media_attachments.find_each do |media_attachment|
|
|
|
|
attachment_names.each do |attachment_name|
|
|
|
|
attachment = media_attachment.public_send(attachment_name)
|
|
|
|
styles = [:original] | attachment.styles.keys
|
2019-09-11 14:32:44 +00:00
|
|
|
|
2020-12-23 06:47:03 +00:00
|
|
|
next if attachment.blank?
|
|
|
|
|
2020-09-15 12:37:58 +00:00
|
|
|
styles.each do |style|
|
|
|
|
case Paperclip::Attachment.default_options[:storage]
|
|
|
|
when :s3
|
2023-02-09 19:56:58 +00:00
|
|
|
# Prevent useless S3 calls if ACLs are disabled
|
|
|
|
next if ENV['S3_PERMISSION'] == ''
|
|
|
|
|
2020-12-24 14:53:45 +00:00
|
|
|
begin
|
|
|
|
attachment.s3_object(style).acl.put(acl: 'private')
|
|
|
|
rescue Aws::S3::Errors::NoSuchKey
|
|
|
|
Rails.logger.warn "Tried to change acl on non-existent key #{attachment.s3_object(style).key}"
|
2023-02-09 19:56:58 +00:00
|
|
|
rescue Aws::S3::Errors::NotImplemented => e
|
|
|
|
Rails.logger.error "Error trying to change ACL on #{attachment.s3_object(style).key}: #{e.message}"
|
2020-12-24 14:53:45 +00:00
|
|
|
end
|
2020-09-15 12:37:58 +00:00
|
|
|
when :fog
|
|
|
|
# Not supported
|
|
|
|
when :filesystem
|
2020-11-07 12:16:54 +00:00
|
|
|
begin
|
|
|
|
FileUtils.chmod(0o600 & ~File.umask, attachment.path(style)) unless attachment.path(style).nil?
|
|
|
|
rescue Errno::ENOENT
|
|
|
|
Rails.logger.warn "Tried to change permission on non-existent file #{attachment.path(style)}"
|
|
|
|
end
|
2020-09-15 12:37:58 +00:00
|
|
|
end
|
2020-11-19 16:38:06 +00:00
|
|
|
|
|
|
|
CacheBusterWorker.perform_async(attachment.path(style)) if Rails.configuration.x.cache_buster_enabled
|
2020-09-15 12:37:58 +00:00
|
|
|
end
|
|
|
|
end
|
2018-12-03 00:32:08 +00:00
|
|
|
end
|
|
|
|
end
|
2021-04-17 12:55:46 +00:00
|
|
|
|
|
|
|
def signed_activity_json
|
|
|
|
@signed_activity_json ||= Oj.dump(serialize_payload(@account, ActivityPub::UpdateSerializer, signer: @account))
|
|
|
|
end
|
2016-12-06 16:41:42 +00:00
|
|
|
end
|