ActivityPub: don't delete anything if the actor is not authorized

This commit is contained in:
Baptiste Gelez
2018-10-22 16:29:25 +01:00
parent fc5acac861
commit fcf911fac9
6 changed files with 32 additions and 13 deletions
+6 -2
View File
@@ -107,9 +107,13 @@ impl Deletable<Connection, activity::Undo> for Like {
act
}
fn delete_id(id: String, conn: &Connection) {
fn delete_id(id: String, actor_id: String, conn: &Connection) {
if let Some(like) = Like::find_by_ap_url(conn, id.into()) {
like.delete(conn);
if let Some(user) = User::find_by_ap_url(conn, actor_id) {
if user.id == like.user_id {
like.delete(conn);
}
}
}
}
}