userget.go (2642B)
1 // GoToSocial 2 // Copyright (C) GoToSocial Authors admin@gotosocial.org 3 // SPDX-License-Identifier: AGPL-3.0-or-later 4 // 5 // This program is free software: you can redistribute it and/or modify 6 // it under the terms of the GNU Affero General Public License as published by 7 // the Free Software Foundation, either version 3 of the License, or 8 // (at your option) any later version. 9 // 10 // This program is distributed in the hope that it will be useful, 11 // but WITHOUT ANY WARRANTY; without even the implied warranty of 12 // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 13 // GNU Affero General Public License for more details. 14 // 15 // You should have received a copy of the GNU Affero General Public License 16 // along with this program. If not, see <http://www.gnu.org/licenses/>. 17 18 package users 19 20 import ( 21 "encoding/json" 22 "errors" 23 "net/http" 24 "strings" 25 26 "github.com/gin-gonic/gin" 27 apiutil "github.com/superseriousbusiness/gotosocial/internal/api/util" 28 "github.com/superseriousbusiness/gotosocial/internal/gtserror" 29 ) 30 31 // UsersGETHandler should be served at https://example.org/users/:username. 32 // 33 // The goal here is to return the activitypub representation of an account 34 // in the form of a vocab.ActivityStreamsPerson. This should only be served 35 // to REMOTE SERVERS that present a valid signature on the GET request, on 36 // behalf of a user, otherwise we risk leaking information about users publicly. 37 // 38 // And of course, the request should be refused if the account or server making the 39 // request is blocked. 40 func (m *Module) UsersGETHandler(c *gin.Context) { 41 // usernames on our instance are always lowercase 42 requestedUsername := strings.ToLower(c.Param(UsernameKey)) 43 if requestedUsername == "" { 44 err := errors.New("no username specified in request") 45 apiutil.ErrorHandler(c, gtserror.NewErrorBadRequest(err, err.Error()), m.processor.InstanceGetV1) 46 return 47 } 48 49 format, err := apiutil.NegotiateAccept(c, apiutil.HTMLOrActivityPubHeaders...) 50 if err != nil { 51 apiutil.ErrorHandler(c, gtserror.NewErrorNotAcceptable(err, err.Error()), m.processor.InstanceGetV1) 52 return 53 } 54 55 if format == string(apiutil.TextHTML) { 56 // redirect to the user's profile 57 c.Redirect(http.StatusSeeOther, "/@"+requestedUsername) 58 return 59 } 60 61 resp, errWithCode := m.processor.Fedi().UserGet(c.Request.Context(), requestedUsername, c.Request.URL) 62 if errWithCode != nil { 63 apiutil.ErrorHandler(c, errWithCode, m.processor.InstanceGetV1) 64 return 65 } 66 67 b, err := json.Marshal(resp) 68 if err != nil { 69 apiutil.ErrorHandler(c, gtserror.NewErrorInternalError(err), m.processor.InstanceGetV1) 70 return 71 } 72 73 c.Data(http.StatusOK, format, b) 74 }