From 163bc1a706e9a94687d28c885c1ff02089498b94 Mon Sep 17 00:00:00 2001 From: Fire Demon Date: Tue, 11 Aug 2020 12:46:50 -0500 Subject: [Privacy] Check permissions of boosts and dereference boosts before sending to public timelines --- app/controllers/activitypub/replies_controller.rb | 1 + 1 file changed, 1 insertion(+) (limited to 'app/controllers/activitypub') diff --git a/app/controllers/activitypub/replies_controller.rb b/app/controllers/activitypub/replies_controller.rb index 4d553fc07..1e1b342b3 100644 --- a/app/controllers/activitypub/replies_controller.rb +++ b/app/controllers/activitypub/replies_controller.rb @@ -26,6 +26,7 @@ class ActivityPub::RepliesController < ActivityPub::BaseController def set_status @status = @account.statuses.find(params[:status_id]) authorize @status, :show? + authorize @status.reblog, :show? if @status.reblog? rescue Mastodon::NotPermittedError not_found end -- cgit