]> Untitled Git - lemmy.git/blobdiff - crates/api_crud/src/comment/update.rs
Sanitize html (#3708)
[lemmy.git] / crates / api_crud / src / comment / update.rs
index f3911faecdf4ecb48bb8cee90d4e417c2031d752..558965f62fd8ac67434f152c6a4383792b7bb224 100644 (file)
 use crate::PerformCrud;
 use actix_web::web::Data;
 use lemmy_api_common::{
-  blocking,
-  check_community_ban,
-  comment::*,
-  get_local_user_view_from_jwt,
-  send_local_notifs,
+  build_response::{build_comment_response, send_local_notifs},
+  comment::{CommentResponse, EditComment},
+  context::LemmyContext,
+  utils::{
+    check_community_ban,
+    local_site_to_slur_regex,
+    local_user_view_from_jwt,
+    sanitize_html_opt,
+  },
 };
-use lemmy_apub::activities::comment::create_or_update::{
-  CreateOrUpdateComment,
-  CreateOrUpdateType,
+use lemmy_db_schema::{
+  source::{
+    actor_language::CommunityLanguage,
+    comment::{Comment, CommentUpdateForm},
+    local_site::LocalSite,
+  },
+  traits::Crud,
+  utils::naive_now,
 };
-use lemmy_db_queries::{source::comment::Comment_, DeleteableOrRemoveable};
-use lemmy_db_schema::source::comment::*;
-use lemmy_db_views::comment_view::CommentView;
+use lemmy_db_views::structs::CommentView;
 use lemmy_utils::{
-  utils::{remove_slurs, scrape_text_for_mentions},
-  ApiError,
-  ConnectionId,
-  LemmyError,
+  error::{LemmyError, LemmyErrorExt, LemmyErrorType},
+  utils::{
+    mention::scrape_text_for_mentions,
+    slurs::remove_slurs,
+    validation::is_valid_body_field,
+  },
 };
-use lemmy_websocket::{messages::SendComment, LemmyContext, UserOperationCrud};
 
 #[async_trait::async_trait(?Send)]
 impl PerformCrud for EditComment {
   type Response = CommentResponse;
 
-  async fn perform(
-    &self,
-    context: &Data<LemmyContext>,
-    websocket_id: Option<ConnectionId>,
-  ) -> Result<CommentResponse, LemmyError> {
+  #[tracing::instrument(skip(context))]
+  async fn perform(&self, context: &Data<LemmyContext>) -> Result<CommentResponse, LemmyError> {
     let data: &EditComment = self;
-    let local_user_view = get_local_user_view_from_jwt(&data.auth, context.pool()).await?;
+    let local_user_view = local_user_view_from_jwt(&data.auth, context).await?;
+    let local_site = LocalSite::read(&mut context.pool()).await?;
 
     let comment_id = data.comment_id;
-    let orig_comment = blocking(context.pool(), move |conn| {
-      CommentView::read(conn, comment_id, None)
-    })
-    .await??;
+    let orig_comment = CommentView::read(&mut context.pool(), comment_id, None).await?;
 
     check_community_ban(
       local_user_view.person.id,
       orig_comment.community.id,
-      context.pool(),
+      &mut context.pool(),
     )
     .await?;
 
     // Verify that only the creator can edit
     if local_user_view.person.id != orig_comment.creator.id {
-      return Err(ApiError::err("no_comment_edit_allowed").into());
+      return Err(LemmyErrorType::NoCommentEditAllowed)?;
     }
 
-    // Do the update
-    let content_slurs_removed = remove_slurs(&data.content.to_owned());
-    let comment_id = data.comment_id;
-    let updated_comment = blocking(context.pool(), move |conn| {
-      Comment::update_content(conn, comment_id, &content_slurs_removed)
-    })
-    .await?
-    .map_err(|_| ApiError::err("couldnt_update_comment"))?;
-
-    CreateOrUpdateComment::send(
-      &updated_comment,
-      &local_user_view.person,
-      CreateOrUpdateType::Update,
-      context,
+    let language_id = self.language_id;
+    CommunityLanguage::is_allowed_community_language(
+      &mut context.pool(),
+      language_id,
+      orig_comment.community.id,
     )
     .await?;
 
+    // Update the Content
+    let content = data
+      .content
+      .as_ref()
+      .map(|c| remove_slurs(c, &local_site_to_slur_regex(&local_site)));
+    is_valid_body_field(&content, false)?;
+    let content = sanitize_html_opt(&content);
+
+    let comment_id = data.comment_id;
+    let form = CommentUpdateForm::builder()
+      .content(content)
+      .language_id(data.language_id)
+      .updated(Some(Some(naive_now())))
+      .build();
+    let updated_comment = Comment::update(&mut context.pool(), comment_id, &form)
+      .await
+      .with_lemmy_type(LemmyErrorType::CouldntUpdateComment)?;
+
     // Do the mentions / recipients
-    let updated_comment_content = updated_comment.content.to_owned();
+    let updated_comment_content = updated_comment.content.clone();
     let mentions = scrape_text_for_mentions(&updated_comment_content);
     let recipient_ids = send_local_notifs(
       mentions,
-      updated_comment,
-      local_user_view.person.clone(),
-      orig_comment.post,
-      context.pool(),
+      &updated_comment,
+      &local_user_view.person,
+      &orig_comment.post,
       false,
+      context,
     )
     .await?;
 
-    let comment_id = data.comment_id;
-    let person_id = local_user_view.person.id;
-    let mut comment_view = blocking(context.pool(), move |conn| {
-      CommentView::read(conn, comment_id, Some(person_id))
-    })
-    .await??;
-
-    // Blank out deleted or removed info
-    if comment_view.comment.deleted || comment_view.comment.removed {
-      comment_view.comment = comment_view.comment.blank_out_deleted_or_removed_info();
-    }
-
-    let res = CommentResponse {
-      comment_view,
+    build_comment_response(
+      context,
+      updated_comment.id,
+      Some(local_user_view),
+      self.form_id.clone(),
       recipient_ids,
-      form_id: data.form_id.to_owned(),
-    };
-
-    context.chat_server().do_send(SendComment {
-      op: UserOperationCrud::EditComment,
-      comment: res.clone(),
-      websocket_id,
-    });
-
-    Ok(res)
+    )
+    .await
   }
 }