summaryrefslogtreecommitdiff
path: root/lib/pleroma/web/mastodon_api/controllers/poll_controller.ex
blob: f44ff997d978354457778c80f0f6154548963cca (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
# Pleroma: A lightweight social networking server
# Copyright © 2017-2021 Pleroma Authors <https://pleroma.social/>
# SPDX-License-Identifier: AGPL-3.0-only

defmodule Pleroma.Web.MastodonAPI.PollController do
  use Pleroma.Web, :controller

  import Pleroma.Web.ControllerHelper, only: [try_render: 3, json_response: 3]

  alias Pleroma.Activity
  alias Pleroma.Object
  alias Pleroma.Web.ActivityPub.Visibility
  alias Pleroma.Web.CommonAPI
  alias Pleroma.Web.Plugs.OAuthScopesPlug

  action_fallback(Pleroma.Web.MastodonAPI.FallbackController)

  plug(Pleroma.Web.ApiSpec.CastAndValidate)

  plug(
    OAuthScopesPlug,
    %{scopes: ["read:statuses"], fallback: :proceed_unauthenticated} when action == :show
  )

  plug(OAuthScopesPlug, %{scopes: ["write:statuses"]} when action == :vote)

  defdelegate open_api_operation(action), to: Pleroma.Web.ApiSpec.PollOperation

  @cachex Pleroma.Config.get([:cachex, :provider], Cachex)

  @doc "GET /api/v1/polls/:id"
  def show(%{assigns: %{user: user}} = conn, %{id: id}) do
    with %Object{} = object <- Object.get_by_id_and_maybe_refetch(id, interval: 60),
         %Activity{} = activity <- Activity.get_create_by_object_ap_id(object.data["id"]),
         true <- Visibility.visible_for_user?(activity, user) do
      try_render(conn, "show.json", %{object: object, for: user})
    else
      error when is_nil(error) or error == false ->
        render_error(conn, :not_found, "Record not found")
    end
  end

  @doc "POST /api/v1/polls/:id/votes"
  def vote(%{assigns: %{user: user}, body_params: %{choices: choices}} = conn, %{id: id}) do
    with %Object{data: %{"type" => "Question"}} = object <- Object.get_by_id(id),
         %Activity{} = activity <- Activity.get_create_by_object_ap_id(object.data["id"]),
         true <- Visibility.visible_for_user?(activity, user),
         {:ok, _activities, object} <- get_cached_vote_or_vote(user, object, choices) do
      try_render(conn, "show.json", %{object: object, for: user})
    else
      nil -> render_error(conn, :not_found, "Record not found")
      false -> render_error(conn, :not_found, "Record not found")
      {:error, message} -> json_response(conn, :unprocessable_entity, %{error: message})
    end
  end

  defp get_cached_vote_or_vote(user, object, choices) do
    idempotency_key = "polls:#{user.id}:#{object.data["id"]}"

    @cachex.fetch!(:idempotency_cache, idempotency_key, fn _ ->
      case CommonAPI.vote(user, object, choices) do
        {:error, _message} = res -> {:ignore, res}
        res -> {:commit, res}
      end
    end)
  end
end