]> Untitled Git - lemmy.git/blob - crates/api/src/local_user/save_settings.rs
Fix problem where actors can have empty public key (fixes #2347) (#2348)
[lemmy.git] / crates / api / src / local_user / save_settings.rs
1 use crate::Perform;
2 use actix_web::web::Data;
3 use lemmy_api_common::{
4   person::{LoginResponse, SaveUserSettings},
5   utils::{blocking, get_local_user_view_from_jwt, send_verification_email},
6 };
7 use lemmy_db_schema::{
8   source::{
9     local_user::{LocalUser, LocalUserForm},
10     person::{Person, PersonForm},
11     site::Site,
12   },
13   traits::Crud,
14   utils::{diesel_option_overwrite, diesel_option_overwrite_to_url, naive_now},
15 };
16 use lemmy_utils::{
17   claims::Claims,
18   error::LemmyError,
19   utils::{is_valid_display_name, is_valid_matrix_id},
20   ConnectionId,
21 };
22 use lemmy_websocket::LemmyContext;
23
24 #[async_trait::async_trait(?Send)]
25 impl Perform for SaveUserSettings {
26   type Response = LoginResponse;
27
28   #[tracing::instrument(skip(context, _websocket_id))]
29   async fn perform(
30     &self,
31     context: &Data<LemmyContext>,
32     _websocket_id: Option<ConnectionId>,
33   ) -> Result<LoginResponse, LemmyError> {
34     let data: &SaveUserSettings = self;
35     let local_user_view =
36       get_local_user_view_from_jwt(&data.auth, context.pool(), context.secret()).await?;
37
38     let avatar = diesel_option_overwrite_to_url(&data.avatar)?;
39     let banner = diesel_option_overwrite_to_url(&data.banner)?;
40     let bio = diesel_option_overwrite(&data.bio);
41     let display_name = diesel_option_overwrite(&data.display_name);
42     let matrix_user_id = diesel_option_overwrite(&data.matrix_user_id);
43     let bot_account = data.bot_account;
44     let email_deref = data.email.as_deref().map(|e| e.to_owned());
45     let email = diesel_option_overwrite(&email_deref);
46
47     if let Some(Some(email)) = &email {
48       let previous_email = local_user_view.local_user.email.clone().unwrap_or_default();
49       // Only send the verification email if there was an email change
50       if previous_email.ne(email) {
51         send_verification_email(&local_user_view, email, context.pool(), context.settings())
52           .await?;
53       }
54     }
55
56     // When the site requires email, make sure email is not Some(None). IE, an overwrite to a None value
57     if let Some(email) = &email {
58       let site_fut = blocking(context.pool(), Site::read_local_site);
59       if email.is_none() && site_fut.await??.require_email_verification {
60         return Err(LemmyError::from_message("email_required"));
61       }
62     }
63
64     if let Some(Some(bio)) = &bio {
65       if bio.chars().count() > 300 {
66         return Err(LemmyError::from_message("bio_length_overflow"));
67       }
68     }
69
70     if let Some(Some(display_name)) = &display_name {
71       if !is_valid_display_name(
72         display_name.trim(),
73         context.settings().actor_name_max_length,
74       ) {
75         return Err(LemmyError::from_message("invalid_username"));
76       }
77     }
78
79     if let Some(Some(matrix_user_id)) = &matrix_user_id {
80       if !is_valid_matrix_id(matrix_user_id) {
81         return Err(LemmyError::from_message("invalid_matrix_id"));
82       }
83     }
84
85     let local_user_id = local_user_view.local_user.id;
86     let person_id = local_user_view.person.id;
87     let default_listing_type = data.default_listing_type;
88     let default_sort_type = data.default_sort_type;
89     let password_encrypted = local_user_view.local_user.password_encrypted;
90     let public_key = Some(local_user_view.person.public_key);
91
92     let person_form = PersonForm {
93       name: local_user_view.person.name,
94       avatar,
95       banner,
96       inbox_url: None,
97       display_name,
98       published: None,
99       updated: Some(naive_now()),
100       banned: None,
101       deleted: None,
102       actor_id: None,
103       bio,
104       local: None,
105       admin: None,
106       private_key: None,
107       public_key,
108       last_refreshed_at: None,
109       shared_inbox_url: None,
110       matrix_user_id,
111       bot_account,
112       ban_expires: None,
113     };
114
115     blocking(context.pool(), move |conn| {
116       Person::update(conn, person_id, &person_form)
117     })
118     .await?
119     .map_err(|e| LemmyError::from_error_message(e, "user_already_exists"))?;
120
121     let local_user_form = LocalUserForm {
122       person_id: Some(person_id),
123       email,
124       password_encrypted: Some(password_encrypted),
125       show_nsfw: data.show_nsfw,
126       show_bot_accounts: data.show_bot_accounts,
127       show_scores: data.show_scores,
128       theme: data.theme.to_owned(),
129       default_sort_type,
130       default_listing_type,
131       lang: data.lang.to_owned(),
132       show_avatars: data.show_avatars,
133       show_read_posts: data.show_read_posts,
134       show_new_post_notifs: data.show_new_post_notifs,
135       send_notifications_to_email: data.send_notifications_to_email,
136       email_verified: None,
137       accepted_application: None,
138     };
139
140     let local_user_res = blocking(context.pool(), move |conn| {
141       LocalUser::update(conn, local_user_id, &local_user_form)
142     })
143     .await?;
144     let updated_local_user = match local_user_res {
145       Ok(u) => u,
146       Err(e) => {
147         let err_type = if e.to_string()
148           == "duplicate key value violates unique constraint \"local_user_email_key\""
149         {
150           "email_already_exists"
151         } else {
152           "user_already_exists"
153         };
154
155         return Err(LemmyError::from_error_message(e, err_type));
156       }
157     };
158
159     // Return the jwt
160     Ok(LoginResponse {
161       jwt: Some(
162         Claims::jwt(
163           updated_local_user.id.0,
164           &context.secret().jwt_secret,
165           &context.settings().hostname,
166         )?
167         .into(),
168       ),
169       verify_email_sent: false,
170       registration_created: false,
171     })
172   }
173 }