ChatController: Don't return chats for user you've blocked.

This commit is contained in:
lain 2020-05-12 16:43:04 +02:00
parent e44166b510
commit c0ea5c60e4
2 changed files with 27 additions and 1 deletions

View File

@ -102,10 +102,13 @@ def messages(%{assigns: %{user: %{id: user_id} = user}} = conn, %{id: id} = para
end end
end end
def index(%{assigns: %{user: %{id: user_id}}} = conn, params) do def index(%{assigns: %{user: %{id: user_id} = user}} = conn, params) do
blocked_ap_ids = User.blocked_users_ap_ids(user)
chats = chats =
from(c in Chat, from(c in Chat,
where: c.user_id == ^user_id, where: c.user_id == ^user_id,
where: c.recipient not in ^blocked_ap_ids,
order_by: [desc: c.updated_at] order_by: [desc: c.updated_at]
) )
|> Pagination.fetch_paginated(params |> stringify_keys) |> Pagination.fetch_paginated(params |> stringify_keys)

View File

@ -6,6 +6,7 @@ defmodule Pleroma.Web.PleromaAPI.ChatControllerTest do
alias Pleroma.Chat alias Pleroma.Chat
alias Pleroma.Object alias Pleroma.Object
alias Pleroma.User
alias Pleroma.Web.ActivityPub.ActivityPub alias Pleroma.Web.ActivityPub.ActivityPub
alias Pleroma.Web.CommonAPI alias Pleroma.Web.CommonAPI
@ -209,6 +210,28 @@ test "it returns a chat", %{conn: conn, user: user} do
describe "GET /api/v1/pleroma/chats" do describe "GET /api/v1/pleroma/chats" do
setup do: oauth_access(["read:statuses"]) setup do: oauth_access(["read:statuses"])
test "it does not return chats with users you blocked", %{conn: conn, user: user} do
recipient = insert(:user)
{:ok, _} = Chat.get_or_create(user.id, recipient.ap_id)
result =
conn
|> get("/api/v1/pleroma/chats")
|> json_response_and_validate_schema(200)
assert length(result) == 1
User.block(user, recipient)
result =
conn
|> get("/api/v1/pleroma/chats")
|> json_response_and_validate_schema(200)
assert length(result) == 0
end
test "it paginates", %{conn: conn, user: user} do test "it paginates", %{conn: conn, user: user} do
Enum.each(1..30, fn _ -> Enum.each(1..30, fn _ ->
recipient = insert(:user) recipient = insert(:user)