@ -15,8 +15,6 @@ Makefile
_site _site
_config.yml _config.yml

View file

View file

.php_cs Normal file
View file

@ -0,0 +1,15 @@
$finder = PhpCsFixer\Finder::create()
return PhpCsFixer\Config::create()
'native_function_invocation' => ['include' => ['@all']],
'native_constant_invocation' => true,

Binary file not shown.


Width:  |  Height:  |  Size: 1.1 MiB

Binary file not shown.


Width:  |  Height:  |  Size: 41 KiB

Binary file not shown.


Width:  |  Height:  |  Size: 272 KiB


Width:  |  Height:  |  Size: 79 KiB

Binary file not shown.


Width:  |  Height:  |  Size: 11 KiB


Width:  |  Height:  |  Size: 11 KiB

Binary file not shown.


Width:  |  Height:  |  Size: 29 KiB

View file

**Stable tag:** 1.2.0 **Stable tag:** 1.0.0
**Requires PHP:** 5.6 **Requires PHP:** 5.6
**License:** MIT **License:** MIT
**License URI:** **License URI:**
@ -12,39 +12,39 @@ The ActivityPub protocol is a decentralized social networking protocol based upo
## Description ## ## Description ##
Enter the fediverse with **ActivityPub**, broadcasting your blog to a wider audience! Attract followers, deliver updates, and receive comments from a diverse user base of **ActivityPub**\-compliant platforms. This is BETA software, see the FAQ to see the current feature set or rather what is still planned.
With the ActivityPub plugin installed, your WordPress blog itself function as a federated profile, along with profiles for each author. For instance, if your website is ``, then the blog-wide profile can be found at ``, and authors like Jane and Bob would have their individual profiles at `` and ``, respectively. The plugin implements the ActivityPub protocol for your blog, which means that your readers will be able to follow your blog posts on Mastodon and other federated platforms that support ActivityPub. In addition, replies to your posts on Mastodon and related platforms will automatically become comments on your blog post.
An example: I give you my Mastodon profile name: ``. You search, see my profile, and hit follow. Now, any post I make appears in your Home feed. Similarly, with the ActivityPub plugin, you can find and follow Jane's profile at ``.
Once you follow Jane's `` profile, any blog post she crafts on `` will land in your Home feed. Simultaneously, by following the blog-wide profile ``, you'll receive updates from all authors.
**Note**: if no one follows your author or blog instance, your posts remain unseen. The simplest method to verify the plugin's operation is by following your profile. If you possess a Mastodon profile, initiate by following your new one.
The plugin works with the following tested federated platforms, but there may be more that it works with as well: The plugin works with the following tested federated platforms, but there may be more that it works with as well:
* [Mastodon]( * [Mastodon](
* [Pleroma]([Akkoma]( * [Pleroma](
* [friendica]( * [friendica](
* [Hubzilla]( * [Hubzilla](
* [Pixelfed]( * [Pixelfed](
* [Socialhome]( * [Socialhome](
* [Misskey]( * [Misskey](
* [Firefish]( (rebrand of Calckey) * [Calckey](
Heres what that means and what you can expect.
Once the ActivityPub plugin is installed, each authors page on your WordPress blog will become its own federated instance. In other words, if you have two authors, Jane and Bob, on your website, ``, then your authors would have their own author pages at `` and ``. Each of those author pages would now be available to Mastodon users (and all other federated platform users) as a profile that can be followed. Lets break that down further. Lets say you have a friend on Mastodon who tells you to follow them and they give you their profile name ``. You search for her name, see her profile, and click the follow button, right? From then on, everything Jane posts on her profile shows up in your Home feed. Okay, similarly, now that Jane has installed the ActivityPub plugin on her `` site, her friends can also follow her on Mastodon by searching for `` and clicking the Follow button on that profile.
From now on, every blog post Jane publishes on will show up on your Home feed because you follow her `` profile.
Of course, if no one follows your author instance, then no one will ever see the posts - including you! So the easiest way to even know if the plugin is working is to follow your new profile yourself. If you already have a Mastodon profile, just follow your new one from there.
Some things to note: Some things to note:
1. The blog-wide profile is only compatible with sites with rewrite rules enabled. If your site does not have rewrite rules enabled, the author-specific profiles may still work. 1. Many single-author blogs have chosen to turn off or redirect their author profile pages, usually via an SEO plugin like Yoast or Rank Math. This is usually done to avoid duplicate content with your blogs home page. If your author page has been deactivated in this way, then ActivityPub wont work for you. Instead, you can turn your author profile page back on, and then use the option in your SEO plugin to noindex the author page. This will enable the page to be live and ActivityPub will now work, but the live page wont cause any duplicate content issues with search engines.
1. Many single-author blogs have chosen to turn off or redirect their author profile pages, usually via an SEO plugin like Yoast or Rank Math. This is usually done to avoid duplicate content with your blogs home page. If your author page has been deactivated in this way, then ActivityPub author profiles wont work for you. Instead, you can turn your author profile page back on, and then use the option in your SEO plugin to noindex the author page. This will still resolve duplicate content issues with search engines and will enable ActivityPub author profiles to work. 1. Once ActivityPub is installed, only new posts going forward will be available in the fediverse. Likewise, even if youve been using ActivityPub for a while, anyone who follows your site, will only see new posts you publish from that moment on. They will never see previously-published posts in their Home feed. This process is very similar to subscribing to a newsletter. If you subscribe to a newsletter, you will only receive future emails, but not the old archived ones. With ActivityPub, if someone follows your site, they will only receive new blog posts you publish from then on.
1. Once ActivityPub is installed, *only new posts going forward* will be available in the fediverse. Likewise, even if youve been using ActivityPub for a while, anyone who follows your site, will only see new posts you publish from that moment on. They will never see previously-published posts in their Home feed. This process is very similar to subscribing to a newsletter. If you subscribe to a newsletter, you will only receive future emails, but not the old archived ones. With ActivityPub, if someone follows your site, they will only receive new blog posts you publish from then on.
So whats the process? So whats the process?
1. Install the ActivityPub plugin. 1. Install the ActivityPub plugin.
1. Go to the plugins settings page and adjust the settings to your liking. Click the Save button when ready. 1. Go to the plugins settings page and adjust the settings to your liking. Click the Save button when ready.
1. Make sure your blogs author profile page is active if you are using author profiles. 1. Make sure your blogs author profile page is active.
1. Go to Mastodon or any other federated platform, and search for your profile, and follow it. Your new profile will be in the form of either `` or ``, so that is what youll search for. 1. Go to Mastodon or any other federated platform, search for your authors new federated profile, and follow it. Your new profile will be in the form of, so that is what youll search for.
1. On your blog, publish a new post. 1. On your blog, publish a new post.
1. From Mastodon, check to see if the new post appears in your Home feed. 1. From Mastodon, check to see if the new post appears in your Home feed.
@ -54,25 +54,34 @@ Please note that it may take up to 15 minutes or so for the new post to show up
### tl;dr ### ### tl;dr ###
This plugin connects your WordPress blog to popular social platforms like Mastodon, making your posts more accessible to a wider audience. Once installed, your blog can be followed by users on these platforms, allowing them to receive your new posts in their feeds. This plugin connects your WordPress blog to popular social platforms like Mastodon, making your posts more accessible to a wider audience. Once installed, your blog's author pages can be followed by users on these platforms, allowing them to receive your new posts in their feeds.
Here's how it works:
1. Install the plugin and adjust settings as needed.
1. Ensure your blog's author profile page is active.
1. On Mastodon or other supported platforms, search for and follow your author's new profile (e.g., ``).
1. Publish a new post on your blog and check if it appears in your Mastodon feed.
Please note that it may take up to 15 minutes for a new post to appear in your feed, as messages are sent on a delay to avoid overwhelming your followers. Be patient and give it some time.
### What is the status of this plugin? ### ### What is the status of this plugin? ###
Implemented: Implemented:
* blog profile pages (JSON representation) * profile pages (JSON representation)
* author profile pages (JSON representation)
* custom links * custom links
* functional inbox/outbox * functional inbox/outbox
* follow (accept follows) * follow (accept follows)
* share posts * share posts
* receive comments/reactions * receive comments/reactions
* signature verification
To implement: To implement:
* signature verification
* better WordPress integration
* better configuration possibilities
* threaded comments support * threaded comments support
* replace shortcodes with blocks for layout
### What is "ActivityPub for WordPress" ### ### What is "ActivityPub for WordPress" ###
@ -86,7 +95,7 @@ In order for webfinger to work, it must be mapped to the root directory of the U
Add the following to the .htaccess file in the root directory: Add the following to the .htaccess file in the root directory:
RedirectMatch "^\/\.well-known/(webfinger|nodeinfo|x-nodeinfo2)(.*)$" /blog/.well-known/$1$2 RedirectMatch "^\/\.well-known/(webfinger|nodeinfo|x-nodeinfo2)(.*)$" "\/blog\/\.well-known$1$2"
Where 'blog' is the path to the subdirectory at which your blog resides. Where 'blog' is the path to the subdirectory at which your blog resides.
@ -105,115 +114,19 @@ Where 'blog' is the path to the subdirectory at which your blog resides.
Project maintained on GitHub at [automattic/wordpress-activitypub]( Project maintained on GitHub at [automattic/wordpress-activitypub](
### 1.2.0 ###
* Add: Search and order followerer lists
* Add: Have a filter to defer signature verification
* Improved: "Follow Me" styles for dark themes
* Improved: Allow `p` and `br` tags only for AP comments
* Fixed: Deduplicate attachments earlier to prevent incorrect max_media
### 1.1.0 ###
* Improved: audio and video attachments are now supported!
* Improved: better error messages if remote profile is not accessible
* Improved: PHP 8.1 compatibility
* Fixed: don't try to parse mentions or hashtags for very large (>1MB) posts to prevent timeouts
* Fixed: better handling of ISO-639-1 locale codes
* Improved: more reliable [ap_author], props @uk3
* Improved: NodeInfo statistics
### 1.0.10 ###
* Improved: better error messages if remote profile is not accessible
### 1.0.9 ###
* Fixed: broken following endpoint
### 1.0.8 ###
* Fixed: blocking of HEAD requests
* Fixed: PHP fatal error
* Fixed: several typos
* Fixed: error codes
* Improved: loading of shortcodes
* Updated: caching of followers
* Updated: Application-User is no longer "indexable"
* Updated: more consistent usage of the `application/activity+json` Content-Type
* Removed: featured tags endpoint
### 1.0.7 ###
* Fixed: broken function call
* Add: filter to hook into "is blog public" check
### 1.0.6 ###
* Fixed: more restrictive request verification
### 1.0.5 ###
* Fixed: compatibility with WebFinger and NodeInfo plugin
### 1.0.4 ###
* Fixed: Constants were not loaded early enough, resulting in a race condition
* Fixed: Featured image was ignored when using the block editor
### 1.0.3 ###
* Fixed: compatibility with older WordPress/PHP versions
* Update: refactoring of the Plugin init process
* Update: better frontend UX and improved theme compat for blocks
* Compatibility: add a ACTIVITYPUB_DISABLE_REWRITES constant
* Compatibility: add pre-fetch hook to allow plugins to hang filters on
### 1.0.2 ###
* Updated: improved hashtag visibility in default template
* Updated: reduced number of followers to be checked/updated via Cron, when System Cron is not set up
* Updated: check if username of Blog-User collides with an Authors name
* Compatibility: improved Group meta informations
* Fixed: detection of single user mode
* Fixed: remote delete
* Fixed: styles in Follow-Me block
* Fixed: various encoding and formatting issues
* Fixed: (health) check Author URLs only if Authors are enabled
### 1.0.1 ###
* Update: improve image attachment detection using the block editor
* Update: better error code handling for API responses
* Update: use a tag stack instead of regex for protecting tags for Hashtags and @-Mentions
* Compatibility: better signature support for subpath-installations
* Compatibility: allow deactivating blocks registered by the plugin
* Compatibility: avoid Fatal Errors when using ClassicPress
* Compatibility: improve the Group-Actor to play nicely with existing implementations
* Fixed: truncate long blog titles and handles for the "Follow me" block
* Fixed: ensure that only a valid user can be selected for the "Follow me" block
* Fixed: fix a typo in a hook name
* Fixed: a problem with signatures when running WordPress in a sub-path
### 1.0.0 ### ### 1.0.0 ###
* Add: blog-wide Account (catchall, like ``) * Add: blog-wide Account (catchall, like ``)
* Add: a Follow Me block (help visitors to follow your Profile) * Add: Signature Verification: .
* Add: Signature Verification: * Add: a Followers Block.
* Add: a Followers Block (show off your Followers)
* Add: Simple caching * Add: Simple caching
* Add: Collection endpoints for Featured Tags and Featured Posts * Update: Complete rewrite of the Follower-System based on Custom Post Types.
* Add: Better handling of Hashtags in mobile apps
* Update: Complete rewrite of the Follower-System based on Custom Post Types
* Update: Improved linter (PHPCS) * Update: Improved linter (PHPCS)
* Compatibility: Add a new conditional, `\Activitypub\is_activitypub_request()`, to allow third-party plugins to detect ActivityPub requests * Compatibility: Add a new conditional, `\Activitypub\is_activitypub_request()`, to allow third-party plugins to detect ActivityPub requests.
* Compatibility: Add hooks to allow modifying images returned in ActivityPub requests * Compatibility: Add hooks to allow modifying images returned in ActivityPub requests.
* Compatibility: Indicate that the plugin is compatible and has been tested with the latest version of WordPress, 6.3 * Compatibility: Indicate that the plugin is compatible and has been tested with the latest version of WordPress, 6.3.
* Compatibility: Avoid PHP notice on sites using PHP 8.2 * Compatibility: Avoid PHP notice on sites using PHP 8.2.
* Fixed: Load the plugin later in the WordPress code lifecycle to avoid errors in some requests * Fixed: Load the plugin later in the WordPress code lifecycle to avoid errors in some requests.
* Fixed: Updating posts
* Fixed: Hashtag now support CamelCase and UTF-8
### 0.17.0 ### ### 0.17.0 ###

View file

View file

@ -3,7 +3,7 @@
* Plugin Name: ActivityPub * Plugin Name: ActivityPub
* Plugin URI: * Plugin URI:
* Description: The ActivityPub protocol is a decentralized social networking protocol based upon the ActivityStreams 2.0 data format. * Description: The ActivityPub protocol is a decentralized social networking protocol based upon the ActivityStreams 2.0 data format.
* Version: 1.2.0 * Version: 1.0.0
* Author: Matthias Pfefferle & Automattic * Author: Matthias Pfefferle & Automattic
* Author URI: * Author URI:
* License: MIT * License: MIT
@ -15,37 +15,31 @@
namespace Activitypub; namespace Activitypub;
use function Activitypub\is_blog_public; \defined( 'ACTIVITYPUB_REST_NAMESPACE' ) || \define( 'ACTIVITYPUB_REST_NAMESPACE', 'activitypub/1.0' );
use function Activitypub\site_supports_blocks;
require_once __DIR__ . '/includes/compat.php';
require_once __DIR__ . '/includes/functions.php';
/** /**
* Initialize the plugin constants. * Initialize plugin
*/ */
\defined( 'ACTIVITYPUB_REST_NAMESPACE' ) || \define( 'ACTIVITYPUB_REST_NAMESPACE', 'activitypub/1.0' ); function init() {
\defined( 'ACTIVITYPUB_HASHTAGS_REGEXP' ) || \define( 'ACTIVITYPUB_HASHTAGS_REGEXP', '(?:(?<=\s)|(?<=<p>)|(?<=<br>)|^)#([A-Za-z0-9_]+)(?:(?=\s|[[:punct:]]|$))' ); \defined( 'ACTIVITYPUB_HASHTAGS_REGEXP' ) || \define( 'ACTIVITYPUB_HASHTAGS_REGEXP', '(?:(?<=\s)|(?<=<p>)|(?<=<br>)|^)#([A-Za-z0-9_]+)(?:(?=\s|[[:punct:]]|$))' );
\defined( 'ACTIVITYPUB_USERNAME_REGEXP' ) || \define( 'ACTIVITYPUB_USERNAME_REGEXP', '(?:([A-Za-z0-9_-]+)@((?:[A-Za-z0-9_-]+\.)+[A-Za-z]+))' ); \defined( 'ACTIVITYPUB_USERNAME_REGEXP' ) || \define( 'ACTIVITYPUB_USERNAME_REGEXP', '(?:([A-Za-z0-9_-]+)@((?:[A-Za-z0-9_-]+\.)+[A-Za-z]+))' );
\defined( 'ACTIVITYPUB_CUSTOM_POST_CONTENT' ) || \define( 'ACTIVITYPUB_CUSTOM_POST_CONTENT', "<strong>[ap_title]</strong>\n\n[ap_content]\n\n[ap_hashtags]\n\n[ap_shortlink]" ); \defined( 'ACTIVITYPUB_CUSTOM_POST_CONTENT' ) || \define( 'ACTIVITYPUB_CUSTOM_POST_CONTENT', "<strong>[ap_title]</strong>\n\n[ap_content]\n\n[ap_hashtags]\n\n[ap_shortlink]" );
\defined( 'ACTIVITYPUB_AUTHORIZED_FETCH' ) || \define( 'ACTIVITYPUB_AUTHORIZED_FETCH', false ); \defined( 'ACTIVITYPUB_SECURE_MODE' ) || \define( 'ACTIVITYPUB_SECURE_MODE', apply_filters( 'activitypub_secure_mode', $value = false ) );
\defined( 'ACTIVITYPUB_DEFAULT_TRANSFORMER' ) || \define( 'ACTIVITYPUB_DEFAULT_TRANSFORMER', 'activitypub/default' );
\define( 'ACTIVITYPUB_PLUGIN_DIR', plugin_dir_path( __FILE__ ) ); \define( 'ACTIVITYPUB_PLUGIN_DIR', plugin_dir_path( __FILE__ ) );
\define( 'ACTIVITYPUB_PLUGIN_BASENAME', plugin_basename( __FILE__ ) ); \define( 'ACTIVITYPUB_PLUGIN_BASENAME', plugin_basename( __FILE__ ) );
\define( 'ACTIVITYPUB_PLUGIN_FILE', plugin_dir_path( __FILE__ ) . '/' . basename( __FILE__ ) ); \define( 'ACTIVITYPUB_PLUGIN_FILE', plugin_dir_path( __FILE__ ) . '/' . basename( __FILE__ ) );
\define( 'ACTIVITYPUB_PLUGIN_URL', plugin_dir_url( __FILE__ ) ); \define( 'ACTIVITYPUB_PLUGIN_URL', plugin_dir_url( __FILE__ ) );
/** // Configure the REST API route
* Initialize REST routes.
function rest_init() {
Rest\Users::init(); Rest\Users::init();
Rest\Outbox::init(); Rest\Outbox::init();
Rest\Inbox::init(); Rest\Inbox::init();
@ -53,51 +47,21 @@ function rest_init() {
Rest\Following::init(); Rest\Following::init();
Rest\Webfinger::init(); Rest\Webfinger::init();
Rest\Server::init(); Rest\Server::init();
// load NodeInfo endpoints only if blog is public Admin::init();
if ( is_blog_public() ) { Hashtag::init();
Rest\NodeInfo::init(); Shortcodes::init();
} }
} \add_action( 'init', __NAMESPACE__ . '\init' );
\add_action( 'rest_api_init', __NAMESPACE__ . '\rest_init' );
* Initialize plugin.
function plugin_init() {
\add_action( 'init', array( __NAMESPACE__ . '\Migration', 'init' ) );
\add_action( 'init', array( __NAMESPACE__ . '\Activitypub', 'init' ) );
\add_action( 'init', array( __NAMESPACE__ . '\Activity_Dispatcher', 'init' ) );
\add_action( 'init', array( __NAMESPACE__ . '\Collection\Followers', 'init' ) );
\add_action( 'init', array( __NAMESPACE__ . '\Admin', 'init' ) );
\add_action( 'init', array( __NAMESPACE__ . '\Hashtag', 'init' ) );
\add_action( 'init', array( __NAMESPACE__ . '\Mention', 'init' ) );
\add_action( 'init', array( __NAMESPACE__ . '\Health_Check', 'init' ) );
\add_action( 'init', array( __NAMESPACE__ . '\Scheduler', 'init' ) );
if ( site_supports_blocks() ) {
\add_action( 'init', array( __NAMESPACE__ . '\Blocks', 'init' ) );
$debug_file = __DIR__ . '/includes/debug.php';
if ( \WP_DEBUG && file_exists( $debug_file ) && is_readable( $debug_file ) ) {
require_once $debug_file;
require_once __DIR__ . '/integration/class-webfinger.php';
require_once __DIR__ . '/integration/class-nodeinfo.php';
\add_action( 'plugins_loaded', __NAMESPACE__ . '\plugin_init' );
/** /**
* Class Autoloader * Class Autoloader
*/ */
\spl_autoload_register( spl_autoload_register(
function ( $full_class ) { function ( $full_class ) {
$base_dir = __DIR__ . '/includes/'; $base_dir = __DIR__ . '/includes/';
$base = 'Activitypub\\'; $base = 'Activitypub\\';
@ -130,6 +94,19 @@ function plugin_init() {
} }
); );
require_once __DIR__ . '/includes/functions.php';
// load NodeInfo endpoints only if blog is public
if ( \get_option( 'blog_public', 1 ) ) {
$debug_file = __DIR__ . '/includes/debug.php';
if ( \WP_DEBUG && file_exists( $debug_file ) && is_readable( $debug_file ) ) {
require_once $debug_file;
/** /**
* Add plugin settings link * Add plugin settings link
*/ */

Binary file not shown.


Width:  |  Height:  |  Size: 3.3 KiB


Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.


Width:  |  Height:  |  Size: 12 KiB

View file

@ -41,9 +41,6 @@
], ],
"lint": [ "lint": [
"vendor/bin/phpcs -n -q" "vendor/bin/phpcs -n -q"
"lint:fix": [
] ]
} }
} }

View file

@ -26,9 +26,7 @@ class Activity extends Base_Object {
'schema' => '', 'schema' => '',
'pt' => '', 'pt' => '',
'toot' => '', 'toot' => '',
'webfinger' => '',
'litepub' => '', 'litepub' => '',
'lemmy' => '',
'value' => 'schema:value', 'value' => 'schema:value',
'Hashtag' => 'as:Hashtag', 'Hashtag' => 'as:Hashtag',
'featured' => array( 'featured' => array(
@ -39,19 +37,8 @@ class Activity extends Base_Object {
'@id' => 'toot:featuredTags', '@id' => 'toot:featuredTags',
'@type' => '@id', '@type' => '@id',
), ),
'alsoKnownAs' => array(
'@id' => 'as:alsoKnownAs',
'@type' => '@id',
'moderators' => array(
'@id' => 'lemmy:moderators',
'@type' => '@id',
'postingRestrictedToMods' => 'lemmy:postingRestrictedToMods',
'discoverable' => 'toot:discoverable', 'discoverable' => 'toot:discoverable',
'indexable' => 'toot:indexable',
'sensitive' => 'as:sensitive', 'sensitive' => 'as:sensitive',
'resource' => 'webfinger:resource',
), ),
); );
@ -81,7 +68,7 @@ class Activity extends Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | null * | null
*/ */
@ -95,7 +82,7 @@ class Activity extends Base_Object {
* @see * @see
* *
* @var string * @var string
* | Base_Objectr * | Base_Object
* | Link * | Link
* | null * | null
*/ */
@ -110,7 +97,7 @@ class Activity extends Base_Object {
* @see * @see
* *
* @var string * @var string
* | \ActivityPhp\Type\Extended\AbstractActor * | Actor
* | array<Actor> * | array<Actor>
* | array<Link> * | array<Link>
* | Link * | Link
@ -129,8 +116,8 @@ class Activity extends Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | array<ObjectType> * | array<Base_Object>
* | Link * | Link
* | array<Link> * | array<Link>
*/ */
@ -145,7 +132,7 @@ class Activity extends Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | null * | null
*/ */
@ -162,7 +149,7 @@ class Activity extends Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | null * | null
*/ */
@ -175,7 +162,7 @@ class Activity extends Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | null * | null
*/ */
@ -189,7 +176,7 @@ class Activity extends Base_Object {
* *
* @see * @see
* *
* @param string|Base_Objectr|Link|null $object * @param string|Base_Object|Link|null $object
* *
* @return void * @return void
*/ */

View file

@ -49,9 +49,9 @@ class Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | array<ObjectType> * | array<Base_Object>
* | array<Link> * | array<Link>
* | null * | null
*/ */
@ -65,9 +65,9 @@ class Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | array<ObjectType> * | array<Base_Object>
* | array<Link> * | array<Link>
* | null * | null
*/ */
@ -80,9 +80,9 @@ class Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | array<ObjectType> * | array<Base_Object>
* | array<Link> * | array<Link>
* | null * | null
*/ */
@ -115,7 +115,7 @@ class Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | null * | null
*/ */
@ -210,9 +210,9 @@ class Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | array<ObjectType> * | array<Base_Object>
* | array<Link> * | array<Link>
* | null * | null
*/ */
@ -225,9 +225,9 @@ class Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | array<ObjectType> * | array<Base_Object>
* | array<Link> * | array<Link>
* | null * | null
*/ */
@ -239,7 +239,7 @@ class Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | null * | null
*/ */
@ -287,7 +287,7 @@ class Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | null * | null
*/ */
@ -313,9 +313,9 @@ class Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | array<ObjectType> * | array<Base_Object>
* | array<Link> * | array<Link>
* | null * | null
*/ */
@ -348,9 +348,9 @@ class Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | array<ObjectType> * | array<Base_Object>
* | array<Link> * | array<Link>
* | null * | null
*/ */
@ -363,9 +363,9 @@ class Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | array<ObjectType> * | array<Base_Object>
* | array<Link> * | array<Link>
* | null * | null
*/ */
@ -378,9 +378,9 @@ class Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | array<ObjectType> * | array<Base_Object>
* | array<Link> * | array<Link>
* | null * | null
*/ */
@ -393,9 +393,9 @@ class Base_Object {
* @see * @see
* *
* @var string * @var string
* | ObjectType * | Base_Object
* | Link * | Link
* | array<ObjectType> * | array<Base_Object>
* | array<Link> * | array<Link>
* | null * | null
*/ */
@ -433,7 +433,7 @@ class Base_Object {
* *
* @see * @see
* *
* @var ObjectType * @var Base_Object
*/ */
protected $source; protected $source;
@ -450,7 +450,7 @@ class Base_Object {
if ( \strncasecmp( $method, 'get', 3 ) === 0 ) { if ( \strncasecmp( $method, 'get', 3 ) === 0 ) {
if ( ! $this->has( $var ) ) { if ( ! $this->has( $var ) ) {
return new WP_Error( 'invalid_key', __( 'Invalid key', 'activitypub' ), array( 'status' => 404 ) ); return new WP_Error( 'invalid_key', 'Invalid key' );
} }
return $this->$var; return $this->$var;
@ -492,7 +492,7 @@ class Base_Object {
*/ */
public function get( $key ) { public function get( $key ) {
if ( ! $this->has( $key ) ) { if ( ! $this->has( $key ) ) {
return new WP_Error( 'invalid_key', __( 'Invalid key', 'activitypub' ), array( 'status' => 404 ) ); return new WP_Error( 'invalid_key', 'Invalid key' );
} }
return call_user_func( array( $this, 'get_' . $key ) ); return call_user_func( array( $this, 'get_' . $key ) );
@ -519,7 +519,7 @@ class Base_Object {
*/ */
public function set( $key, $value ) { public function set( $key, $value ) {
if ( ! $this->has( $key ) ) { if ( ! $this->has( $key ) ) {
return new WP_Error( 'invalid_key', __( 'Invalid key', 'activitypub' ), array( 'status' => 404 ) ); return new WP_Error( 'invalid_key', 'Invalid key' );
} }
$this->$key = $value; $this->$key = $value;
@ -537,7 +537,7 @@ class Base_Object {
*/ */
public function add( $key, $value ) { public function add( $key, $value ) {
if ( ! $this->has( $key ) ) { if ( ! $this->has( $key ) ) {
return new WP_Error( 'invalid_key', __( 'Invalid key', 'activitypub' ), array( 'status' => 404 ) ); return new WP_Error( 'invalid_key', 'Invalid key' );
} }
if ( ! isset( $this->$key ) ) { if ( ! isset( $this->$key ) ) {
@ -562,10 +562,6 @@ class Base_Object {
public static function init_from_json( $json ) { public static function init_from_json( $json ) {
$array = \json_decode( $json, true ); $array = \json_decode( $json, true );
if ( ! is_array( $array ) ) {
$array = array();
return self::init_from_array( $array ); return self::init_from_array( $array );
} }
@ -577,10 +573,6 @@ class Base_Object {
* @return \Activitypub\Activity\Base_Object An Object built from the JSON string. * @return \Activitypub\Activity\Base_Object An Object built from the JSON string.
*/ */
public static function init_from_array( $array ) { public static function init_from_array( $array ) {
if ( ! is_array( $array ) ) {
return new WP_Error( 'invalid_array', __( 'Invalid array', 'activitypub' ), array( 'status' => 404 ) );
$object = new static(); $object = new static();
foreach ( $array as $key => $value ) { foreach ( $array as $key => $value ) {
@ -644,7 +636,7 @@ class Base_Object {
} }
// if value is still empty, ignore it for the array and continue. // if value is still empty, ignore it for the array and continue.
if ( isset( $value ) ) { if ( $value ) {
$array[ snake_to_camel_case( $key ) ] = $value; $array[ snake_to_camel_case( $key ) ] = $value;
} }
} }

View file

@ -1,23 +0,0 @@
* Inspired by the PHP ActivityPub Library by @Landrok
* @link
namespace Activitypub\Activity;
use Activitypub\Activity\Base_Object;
* Event is an implementation of one of the
* Activity Streams Event object type
* The Object is the primary base type for the Activity Streams
* vocabulary.
* @see
class Note extends Base_Object {
protected $type = 'Event';

View file

@ -1,23 +0,0 @@
* Inspired by the PHP ActivityPub Library by @Landrok
* @link
namespace Activitypub\Activity;
use Activitypub\Activity\Base_Object;
* Note is an implementation of one of the
* Activity Streams Note object type
* The Object is the primary base type for the Activity Streams
* vocabulary.
* @see
class Note extends Base_Object {
protected $type = 'Note';

View file

@ -5,7 +5,7 @@ use WP_Post;
use Activitypub\Activity\Activity; use Activitypub\Activity\Activity;
use Activitypub\Collection\Users; use Activitypub\Collection\Users;
use Activitypub\Collection\Followers; use Activitypub\Collection\Followers;
use Activitypub\Transformer\Transformers_Manager; use Activitypub\Transformer\Post;
use function Activitypub\is_single_user; use function Activitypub\is_single_user;
use function Activitypub\is_user_disabled; use function Activitypub\is_user_disabled;
@ -65,8 +65,7 @@ class Activity_Dispatcher {
return; return;
} }
$transformer = Transformers_Manager::instance()->get_transformer( $wp_post ); $object = Post::transform( $wp_post )->to_object();
$object = $transformer->to_object();
$activity = new Activity(); $activity = new Activity();
$activity->set_type( $type ); $activity->set_type( $type );
@ -102,8 +101,7 @@ class Activity_Dispatcher {
return; return;
} }
$transformer = Transformers_Manager::instance()->get_transformer( $wp_post ); $object = Post::transform( $wp_post )->to_object();
$object = $transformer->to_object();
$activity = new Activity(); $activity = new Activity();
$activity->set_type( 'Announce' ); $activity->set_type( 'Announce' );

View file

@ -17,12 +17,11 @@ class Activitypub {
\add_filter( 'template_include', array( self::class, 'render_json_template' ), 99 ); \add_filter( 'template_include', array( self::class, 'render_json_template' ), 99 );
\add_filter( 'query_vars', array( self::class, 'add_query_vars' ) ); \add_filter( 'query_vars', array( self::class, 'add_query_vars' ) );
\add_filter( 'pre_get_avatar_data', array( self::class, 'pre_get_avatar_data' ), 11, 2 ); \add_filter( 'pre_get_avatar_data', array( self::class, 'pre_get_avatar_data' ), 11, 2 );
\add_filter( 'get_comment_link', array( self::class, 'remote_comment_link' ), 11, 3 );
// Add support for ActivityPub to custom post types // Add support for ActivityPub to custom post types
$transformer_mapping = \get_option( 'activitypub_transformer_mapping', array( 'post' => 'activitypub/default', 'page' => 'activitypub/default' ) ) ? \get_option( 'activitypub_transformer_mapping', array( 'post' => 'activitypub/default', 'page' => 'activitypub/default' ) ) : array(); $post_types = \get_option( 'activitypub_support_post_types', array( 'post', 'page' ) ) ? \get_option( 'activitypub_support_post_types', array( 'post', 'page' ) ) : array();
foreach ( array_keys( $transformer_mapping ) as $post_type ) { foreach ( $post_types as $post_type ) {
\add_post_type_support( $post_type, 'activitypub' ); \add_post_type_support( $post_type, 'activitypub' );
} }
@ -98,7 +97,7 @@ class Activitypub {
$json_template = ACTIVITYPUB_PLUGIN_DIR . '/templates/blog-json.php'; $json_template = ACTIVITYPUB_PLUGIN_DIR . '/templates/blog-json.php';
} }
$verification = Signature::verify_http_signature( $_SERVER ); $verification = Signature::verify_http_signature( $_SERVER );
if ( \is_wp_error( $verification ) ) { if ( \is_wp_error( $verification ) ) {
// fallback as template_loader can't return http headers // fallback as template_loader can't return http headers
@ -180,22 +179,6 @@ class Activitypub {
return \get_comment_meta( $comment->comment_ID, 'avatar_url', true ); return \get_comment_meta( $comment->comment_ID, 'avatar_url', true );
} }
* Link remote comments to source url.
* @param string $comment_link
* @param object|WP_Comment $comment
* @return string $url
public static function remote_comment_link( $comment_link, $comment ) {
$remote_comment_link = get_comment_meta( $comment->comment_ID, 'source_url', true );
if ( $remote_comment_link ) {
$comment_link = esc_url( $remote_comment_link );
return $comment_link;
/** /**
* Store permalink in meta, to send delete Activity. * Store permalink in meta, to send delete Activity.
* *
@ -227,12 +210,6 @@ class Activitypub {
* Add rewrite rules * Add rewrite rules
*/ */
public static function add_rewrite_rules() { public static function add_rewrite_rules() {
// If another system needs to take precedence over the ActivityPub rewrite rules,
// they can define their own and will manually call the appropriate functions as required.
if ( ! \class_exists( 'Webfinger' ) ) { if ( ! \class_exists( 'Webfinger' ) ) {
\add_rewrite_rule( \add_rewrite_rule(
'^.well-known/webfinger', '^.well-known/webfinger',
@ -252,13 +229,12 @@ class Activitypub {
'index.php?rest_route=/' . ACTIVITYPUB_REST_NAMESPACE . '/nodeinfo2', 'index.php?rest_route=/' . ACTIVITYPUB_REST_NAMESPACE . '/nodeinfo2',
'top' 'top'
); );
\add_rewrite_rule( \add_rewrite_rule(
'^@([\w\-\.]+)', '^@([\w\-\.]+)',
'index.php?rest_route=/' . ACTIVITYPUB_REST_NAMESPACE . '/users/$matches[1]', 'index.php?rest_route=/' . ACTIVITYPUB_REST_NAMESPACE . '/users/$matches[1]',
'top' 'top'
); );
\add_rewrite_endpoint( 'activitypub', EP_AUTHORS | EP_PERMALINK | EP_PAGES ); \add_rewrite_endpoint( 'activitypub', EP_AUTHORS | EP_PERMALINK | EP_PAGES );
} }

View file

@ -1,10 +1,6 @@
<?php <?php
namespace Activitypub; namespace Activitypub;
use WP_User_Query;
use Activitypub\Model\Blog_User;
use Activitypub\Base\Transformer\Base as Transformer_Base;
/** /**
* ActivityPub Admin Class * ActivityPub Admin Class
* *
@ -23,15 +19,6 @@ class Admin {
if ( ! is_user_disabled( get_current_user_id() ) ) { if ( ! is_user_disabled( get_current_user_id() ) ) {
\add_action( 'show_user_profile', array( self::class, 'add_profile' ) ); \add_action( 'show_user_profile', array( self::class, 'add_profile' ) );
} }
function( $should_register, Transformer_Base $transformer_instance ) {
return ! Options::is_transformer_disabled( $transformer_instance->get_name() );
} }
/** /**
@ -164,47 +151,14 @@ class Admin {
'default' => '0', 'default' => '0',
) )
); );
* Flexible activation of post_types together with mapping ActivityPub transformers.
* If a post-type is not mapped to any ActivtiyPub transformer it means it is not activated
* for ActivityPub federation.
* @since version_number_transformer_management_placeholder
'activitypub', 'activitypub',
'activitypub_transformer_mapping', 'activitypub_support_post_types',
array( array(
'type' => 'array',
'default' => array(
'post' => 'note',
'show_in_rest' => array(
'schema' => array(
'type' => 'array',
'items' => array(
'type' => 'string', 'type' => 'string',
), 'description' => \esc_html__( 'Enable ActivityPub support for post types', 'activitypub' ),
), 'show_in_rest' => true,
), 'default' => array( 'post', 'pages' ),
'sanitize_callback' => function ( $value ) {
// Check if $value is an array
if ( ! is_array( $value ) ) {
return array();
$value_keys = array_keys( $value );
$all_public_post_types = \get_post_types( array( 'public' => true ), 'names' );
// Unset the keys that are missing in $keysToCheck
foreach ( array_diff( $value_keys, $all_public_post_types ) as $missing_key ) {
unset( $value[ $missing_key ] );
// var_dump($value);
return $value;
) )
); );
\register_setting( \register_setting(
@ -214,7 +168,7 @@ class Admin {
'type' => 'string', 'type' => 'string',
'description' => \esc_html__( 'The Identifier of the Blog-User', 'activitypub' ), 'description' => \esc_html__( 'The Identifier of the Blog-User', 'activitypub' ),
'show_in_rest' => true, 'show_in_rest' => true,
'default' => Blog_User::get_default_username(), 'default' => \Activitypub\Model\Blog_User::get_default_username(),
'sanitize_callback' => function( $value ) { 'sanitize_callback' => function( $value ) {
// hack to allow dots in the username // hack to allow dots in the username
$parts = explode( '.', $value ); $parts = explode( '.', $value );
@ -224,31 +178,7 @@ class Admin {
$sanitized[] = \sanitize_title( $part ); $sanitized[] = \sanitize_title( $part );
} }
$sanitized = implode( '.', $sanitized ); return implode( '.', $sanitized );
// check for login or nicename.
$user = new WP_User_Query(
'search' => $sanitized,
'search_columns' => array( 'user_login', 'user_nicename' ),
'number' => 1,
'hide_empty' => true,
'fields' => 'ID',
if ( $user->results ) {
\esc_html__( 'You cannot use an existing author\'s name for the blog profile ID.', 'activitypub' ),
return Blog_User::get_default_username();
return $sanitized;
}, },
) )
); );

View file

@ -2,7 +2,6 @@
namespace Activitypub; namespace Activitypub;
use Activitypub\Collection\Followers; use Activitypub\Collection\Followers;
use Activitypub\Collection\Users as User_Collection;
use Activitypub\is_user_type_disabled; use Activitypub\is_user_type_disabled;
class Blocks { class Blocks {
@ -14,9 +13,7 @@ class Blocks {
} }
public static function add_data() { public static function add_data() {
$context = is_admin() ? 'editor' : 'view'; $handle = is_admin() ? 'activitypub-followers-editor-script' : 'activitypub-followers-view-script';
$followers_handle = 'activitypub-followers-' . $context . '-script';
$follow_me_handle = 'activitypub-follow-me-' . $context . '-script';
$data = array( $data = array(
'enabled' => array( 'enabled' => array(
@ -25,8 +22,7 @@ class Blocks {
), ),
); );
$js = sprintf( 'var _activityPubOptions = %s;', wp_json_encode( $data ) ); $js = sprintf( 'var _activityPubOptions = %s;', wp_json_encode( $data ) );
\wp_add_inline_script( $followers_handle, $js, 'before' ); \wp_add_inline_script( $handle, $js, 'before' );
\wp_add_inline_script( $follow_me_handle, $js, 'before' );
} }
public static function register_blocks() { public static function register_blocks() {
@ -36,12 +32,6 @@ class Blocks {
'render_callback' => array( self::class, 'render_follower_block' ), 'render_callback' => array( self::class, 'render_follower_block' ),
) )
); );
ACTIVITYPUB_PLUGIN_DIR . '/build/follow-me',
'render_callback' => array( self::class, 'render_follow_me_block' ),
} }
private static function get_user_id( $user_string ) { private static function get_user_id( $user_string ) {
@ -52,56 +42,11 @@ class Blocks {
return 0; return 0;
} }
/** public static function render_follower_block( $attrs, $content, $block ) {
* Filter an array by a list of keys.
* @param array $array The array to filter.
* @param array $keys The keys to keep.
* @return array The filtered array.
protected static function filter_array_by_keys( $array, $keys ) {
return array_intersect_key( $array, array_flip( $keys ) );
* Render the follow me block.
* @param array $attrs The block attributes.
* @return string The HTML to render.
public static function render_follow_me_block( $attrs ) {
$user_id = self::get_user_id( $attrs['selectedUser'] );
$user = User_Collection::get_by_id( $user_id );
if ( ! is_wp_error( $user ) ) {
$attrs['profileData'] = self::filter_array_by_keys(
array( 'icon', 'name', 'resource' )
$wrapper_attributes = get_block_wrapper_attributes(
'aria-label' => __( 'Follow me on the Fediverse', 'activitypub' ),
'class' => 'activitypub-follow-me-block-wrapper',
'data-attrs' => wp_json_encode( $attrs ),
// todo: render more than an empty div?
return '<div ' . $wrapper_attributes . '></div>';
public static function render_follower_block( $attrs ) {
$followee_user_id = self::get_user_id( $attrs['selectedUser'] ); $followee_user_id = self::get_user_id( $attrs['selectedUser'] );
$per_page = absint( $attrs['per_page'] ); $per_page = absint( $attrs['per_page'] );
$follower_data = Followers::get_followers_with_count( $followee_user_id, $per_page ); $followers = Followers::get_followers( $followee_user_id, $per_page );
$title = $attrs['title'];
$attrs['followerData']['total'] = $follower_data['total'];
$attrs['followerData']['followers'] = array_map(
function( $follower ) {
return self::filter_array_by_keys(
array( 'icon', 'name', 'preferredUsername', 'url' )
$wrapper_attributes = get_block_wrapper_attributes( $wrapper_attributes = get_block_wrapper_attributes(
array( array(
'aria-label' => __( 'Fediverse Followers', 'activitypub' ), 'aria-label' => __( 'Fediverse Followers', 'activitypub' ),
@ -110,12 +55,12 @@ class Blocks {
) )
); );
$html = '<div ' . $wrapper_attributes . '>'; $html = '<div class="activitypub-follower-block" ' . $wrapper_attributes . '>';
if ( $attrs['title'] ) { if ( $title ) {
$html .= '<h3>' . esc_html( $attrs['title'] ) . '</h3>'; $html .= '<h3>' . $title . '</h3>';
} }
$html .= '<ul>'; $html .= '<ul>';
foreach ( $follower_data['followers'] as $follower ) { foreach ( $followers as $follower ) {
$html .= '<li>' . self::render_follower( $follower ) . '</li>'; $html .= '<li>' . self::render_follower( $follower ) . '</li>';
} }
// We are only pagination on the JS side. Could be revisited but we gotta ship! // We are only pagination on the JS side. Could be revisited but we gotta ship!

View file

@ -43,60 +43,38 @@ class Hashtag {
* @return string the filtered post-content * @return string the filtered post-content
*/ */
public static function the_content( $the_content ) { public static function the_content( $the_content ) {
// small protection against execution timeouts: limit to 1 MB $protected_tags = array();
if ( mb_strlen( $the_content ) > MB_IN_BYTES ) { $protect = function( $m ) use ( &$protected_tags ) {
return $the_content; $c = \wp_rand( 100000, 999999 );
$protect = '!#!#PROTECT' . $c . '#!#!';
while ( isset( $protected_tags[ $protect ] ) ) {
$c = \wp_rand( 100000, 999999 );
$protect = '!#!#PROTECT' . $c . '#!#!';
} }
$tag_stack = array(); $protected_tags[ $protect ] = $m[0];
$protected_tags = array( return $protect;
'pre', };
'code', $the_content = preg_replace_callback(
'textarea', '#<!\[CDATA\[.*?\]\]>#is',
'style', $protect,
'a', $the_content
$the_content = preg_replace_callback(
$the_content = preg_replace_callback(
); );
$content_with_links = '';
$in_protected_tag = false;
foreach ( wp_html_split( $the_content ) as $chunk ) {
if ( preg_match( '#^<!--[\s\S]*-->$#i', $chunk, $m ) ) {
$content_with_links .= $chunk;
if ( preg_match( '#^<(/)?([a-z-]+)\b[^>]*>$#i', $chunk, $m ) ) { $the_content = \preg_replace_callback( '/' . ACTIVITYPUB_HASHTAGS_REGEXP . '/i', array( '\Activitypub\Hashtag', 'replace_with_links' ), $the_content );
$tag = strtolower( $m[2] );
if ( '/' === $m[1] ) {
// Closing tag.
$i = array_search( $tag, $tag_stack );
// We can only remove the tag from the stack if it is in the stack.
if ( false !== $i ) {
$tag_stack = array_slice( $tag_stack, 0, $i );
} else {
// Opening tag, add it to the stack.
$tag_stack[] = $tag;
// If we're in a protected tag, the tag_stack contains at least one protected tag string. $the_content = str_replace( array_reverse( array_keys( $protected_tags ) ), array_reverse( array_values( $protected_tags ) ), $the_content );
// The protected tag state can only change when we encounter a start or end tag.
$in_protected_tag = array_intersect( $tag_stack, $protected_tags );
// Never inspect tags. return $the_content;
$content_with_links .= $chunk;
if ( $in_protected_tag ) {
// Don't inspect a chunk inside an inspected tag.
$content_with_links .= $chunk;
// Only reachable when there is no protected tag in the stack.
$content_with_links .= \preg_replace_callback( '/' . ACTIVITYPUB_HASHTAGS_REGEXP . '/i', array( '\Activitypub\Hashtag', 'replace_with_links' ), $chunk );
return $content_with_links;
} }
/** /**
@ -111,7 +89,7 @@ class Hashtag {
if ( $tag_object ) { if ( $tag_object ) {
$link = \get_term_link( $tag_object, 'post_tag' ); $link = \get_term_link( $tag_object, 'post_tag' );
return \sprintf( '<a rel="tag" class="hashtag u-tag u-category" href="%s">#%s</a>', $link, $tag ); return \sprintf( '<a rel="tag" class="u-tag u-category" href="%s">#%s</a>', $link, $tag );
} }
return '#' . $tag; return '#' . $tag;

View file

@ -1,14 +1,6 @@
<?php <?php
namespace Activitypub; namespace Activitypub;
use WP_Error;
use Activitypub\Webfinger;
use Activitypub\Collection\Users;
use function Activitypub\get_plugin_version;
use function Activitypub\is_user_type_disabled;
use function Activitypub\get_webfinger_resource;
/** /**
* ActivityPub Health_Check Class * ActivityPub Health_Check Class
* *
@ -27,23 +19,16 @@ class Health_Check {
} }
public static function add_tests( $tests ) { public static function add_tests( $tests ) {
if ( ! is_user_type_disabled( 'user' ) ) {
$tests['direct']['activitypub_test_author_url'] = array( $tests['direct']['activitypub_test_author_url'] = array(
'label' => \__( 'Author URL test', 'activitypub' ), 'label' => \__( 'Author URL test', 'activitypub' ),
'test' => array( self::class, 'test_author_url' ), 'test' => array( self::class, 'test_author_url' ),
); );
$tests['direct']['activitypub_test_webfinger'] = array( $tests['direct']['activitypub_test_webfinger'] = array(
'label' => __( 'WebFinger Test', 'activitypub' ), 'label' => __( 'WebFinger Test', 'activitypub' ),
'test' => array( self::class, 'test_webfinger' ), 'test' => array( self::class, 'test_webfinger' ),
); );
$tests['direct']['activitypub_test_system_cron'] = array(
'label' => __( 'System Cron Test', 'activitypub' ),
'test' => array( self::class, 'test_system_cron' ),
return $tests; return $tests;
} }
@ -85,49 +70,6 @@ class Health_Check {
return $result; return $result;
} }
* System Cron tests
* @return array
public static function test_system_cron() {
$result = array(
'label' => \__( 'System Task Scheduler configured', 'activitypub' ),
'status' => 'good',
'badge' => array(
'label' => \__( 'ActivityPub', 'activitypub' ),
'color' => 'green',
'description' => \sprintf(
\esc_html__( 'You seem to use the System Task Scheduler to process WP_Cron tasks.', 'activitypub' )
'actions' => '',
'test' => 'test_system_cron',
if ( defined( 'DISABLE_WP_CRON' ) && DISABLE_WP_CRON ) {
return $result;
$result['status'] = 'recommended';
$result['label'] = \__( 'System Task Scheduler not configured', 'activitypub' );
$result['badge']['color'] = 'orange';
$result['description'] = \sprintf(
\__( 'Enhance your WordPress sites performance and mitigate potential heavy loads caused by plugins like ActivityPub by setting up a system cron job to run WP Cron. This ensures scheduled tasks are executed consistently and reduces the reliance on website traffic for trigger events.', 'activitypub' )
$result['actions'] .= sprintf(
'<p><a href="%s" target="_blank" rel="noopener">%s<span class="screen-reader-text"> %s</span><span aria-hidden="true" class="dashicons dashicons-external"></span></a></p>',
__( '', 'activitypub' ),
__( 'Learn how to hook the WP-Cron into the System Task Scheduler.', 'activitypub' ),
/* translators: Hidden accessibility text. */
__( '(opens in a new tab)', 'activitypub' )
return $result;
/** /**
* WebFinger tests * WebFinger tests
* *
@ -169,7 +111,7 @@ class Health_Check {
/** /**
* Check if `author_posts_url` is accessible and that request returns correct JSON * Check if `author_posts_url` is accessible and that request returns correct JSON
* *
* @return boolean|WP_Error * @return boolean|\WP_Error
*/ */
public static function is_author_url_accessible() { public static function is_author_url_accessible() {
$user = \wp_get_current_user(); $user = \wp_get_current_user();
@ -178,7 +120,7 @@ class Health_Check {
// check for "author" in URL // check for "author" in URL
if ( $author_url !== $reference_author_url ) { if ( $author_url !== $reference_author_url ) {
return new WP_Error( return new \WP_Error(
'author_url_not_accessible', 'author_url_not_accessible',
\sprintf( \sprintf(
// translators: %s: Author URL // translators: %s: Author URL
@ -201,7 +143,7 @@ class Health_Check {
); );
if ( \is_wp_error( $response ) ) { if ( \is_wp_error( $response ) ) {
return new WP_Error( return new \WP_Error(
'author_url_not_accessible', 'author_url_not_accessible',
\sprintf( \sprintf(
// translators: %s: Author URL // translators: %s: Author URL
@ -218,7 +160,7 @@ class Health_Check {
// check for redirects // check for redirects
if ( \in_array( $response_code, array( 301, 302, 307, 308 ), true ) ) { if ( \in_array( $response_code, array( 301, 302, 307, 308 ), true ) ) {
return new WP_Error( return new \WP_Error(
'author_url_not_accessible', 'author_url_not_accessible',
\sprintf( \sprintf(
// translators: %s: Author URL // translators: %s: Author URL
@ -235,7 +177,7 @@ class Health_Check {
$body = \wp_remote_retrieve_body( $response ); $body = \wp_remote_retrieve_body( $response );
if ( ! \is_string( $body ) || ! \is_array( \json_decode( $body, true ) ) ) { if ( ! \is_string( $body ) || ! \is_array( \json_decode( $body, true ) ) ) {
return new WP_Error( return new \WP_Error(
'author_url_not_accessible', 'author_url_not_accessible',
\sprintf( \sprintf(
// translators: %s: Author URL // translators: %s: Author URL
@ -254,20 +196,13 @@ class Health_Check {
/** /**
* Check if WebFinger endpoint is accessible and profile request returns correct JSON * Check if WebFinger endpoint is accessible and profile request returns correct JSON
* *
* @return boolean|WP_Error * @return boolean|\WP_Error
*/ */
public static function is_webfinger_endpoint_accessible() { public static function is_webfinger_endpoint_accessible() {
$user = \wp_get_current_user(); $user = \wp_get_current_user();
$account = \Activitypub\get_webfinger_resource( $user->ID );
if ( ! is_user_type_disabled( 'blog' ) ) { $url = \Activitypub\Webfinger::resolve( $account );
$account = get_webfinger_resource( $user->ID );
} elseif ( ! is_user_type_disabled( 'user' ) ) {
$account = get_webfinger_resource( Users::BLOG_USER_ID );
} else {
$account = '';
$url = Webfinger::resolve( $account );
if ( \is_wp_error( $url ) ) { if ( \is_wp_error( $url ) ) {
$allowed = array( 'code' => array() ); $allowed = array( 'code' => array() );
$not_accessible = wp_kses( $not_accessible = wp_kses(
@ -302,7 +237,7 @@ class Health_Check {
if ( isset( $health_messages[ $url->get_error_code() ] ) ) { if ( isset( $health_messages[ $url->get_error_code() ] ) ) {
$message = $health_messages[ $url->get_error_code() ]; $message = $health_messages[ $url->get_error_code() ];
} }
return new WP_Error( return new \WP_Error(
$url->get_error_code(), $url->get_error_code(),
$message, $message,
$url->get_error_data() $url->get_error_data()
@ -356,7 +291,7 @@ class Health_Check {
'fields' => array( 'fields' => array(
'webfinger' => array( 'webfinger' => array(
'label' => __( 'WebFinger Resource', 'activitypub' ), 'label' => __( 'WebFinger Resource', 'activitypub' ),
'value' => Webfinger::get_user_resource( wp_get_current_user()->ID ), 'value' => \Activitypub\Webfinger::get_user_resource( wp_get_current_user()->ID ),
'private' => true, 'private' => true,
), ),
'author_url' => array( 'author_url' => array(
@ -364,11 +299,6 @@ class Health_Check {
'value' => get_author_posts_url( wp_get_current_user()->ID ), 'value' => get_author_posts_url( wp_get_current_user()->ID ),
'private' => true, 'private' => true,
), ),
'plugin_version' => array(
'label' => __( 'Plugin Version', 'activitypub' ),
'value' => get_plugin_version(),
'private' => true,
), ),
); );

View file

@ -52,8 +52,8 @@ class Http {
$response = \wp_safe_remote_post( $url, $args ); $response = \wp_safe_remote_post( $url, $args );
$code = \wp_remote_retrieve_response_code( $response ); $code = \wp_remote_retrieve_response_code( $response );
if ( $code >= 400 ) { if ( 400 <= $code && 500 >= $code ) {
$response = new WP_Error( $code, __( 'Failed HTTP Request', 'activitypub' ), array( 'status' => $code ) ); $response = new WP_Error( $code, __( 'Failed HTTP Request', 'activitypub' ) );
} }
\do_action( 'activitypub_safe_remote_post_response', $response, $url, $body, $user_id ); \do_action( 'activitypub_safe_remote_post_response', $response, $url, $body, $user_id );
@ -100,8 +100,8 @@ class Http {
$response = \wp_safe_remote_get( $url, $args ); $response = \wp_safe_remote_get( $url, $args );
$code = \wp_remote_retrieve_response_code( $response ); $code = \wp_remote_retrieve_response_code( $response );
if ( $code >= 400 ) { if ( 400 <= $code && 500 >= $code ) {
$response = new WP_Error( $code, __( 'Failed HTTP Request', 'activitypub' ), array( 'status' => $code ) ); $response = new WP_Error( $code, __( 'Failed HTTP Request', 'activitypub' ) );
} }
\do_action( 'activitypub_safe_remote_get_response', $response, $url ); \do_action( 'activitypub_safe_remote_get_response', $response, $url );

View file

@ -2,7 +2,6 @@
namespace Activitypub; namespace Activitypub;
use WP_Error; use WP_Error;
use Activitypub\Webfinger;
/** /**
* ActivityPub Mention Class * ActivityPub Mention Class
@ -26,60 +25,44 @@ class Mention {
* @return string the filtered post-content * @return string the filtered post-content
*/ */
public static function the_content( $the_content ) { public static function the_content( $the_content ) {
// small protection against execution timeouts: limit to 1 MB $protected_tags = array();
if ( mb_strlen( $the_content ) > MB_IN_BYTES ) { $protect = function( $m ) use ( &$protected_tags ) {
return $the_content; $c = \wp_rand( 100000, 999999 );
$protect = '!#!#PROTECT' . $c . '#!#!';
while ( isset( $protected_tags[ $protect ] ) ) {
$c = \wp_rand( 100000, 999999 );
$protect = '!#!#PROTECT' . $c . '#!#!';
} }
$tag_stack = array(); $protected_tags[ $protect ] = $m[0];
$protected_tags = array( return $protect;
'pre', };
'code', $the_content = preg_replace_callback(
'textarea', '#<!\[CDATA\[.*?\]\]>#is',
'style', $protect,
'a', $the_content
$the_content = preg_replace_callback(
$the_content = preg_replace_callback(
); );
$content_with_links = '';
$in_protected_tag = false;
foreach ( wp_html_split( $the_content ) as $chunk ) {
if ( preg_match( '#^<!--[\s\S]*-->$#i', $chunk, $m ) ) {
$content_with_links .= $chunk;
if ( preg_match( '#^<(/)?([a-z-]+)\b[^>]*>$#i', $chunk, $m ) ) { $the_content = preg_replace_callback(
$tag = strtolower( $m[2] ); '#<img.*?[^>]+>#i',
if ( '/' === $m[1] ) { $protect,
// Closing tag. $the_content
$i = array_search( $tag, $tag_stack ); );
// We can only remove the tag from the stack if it is in the stack.
if ( false !== $i ) {
$tag_stack = array_slice( $tag_stack, 0, $i );
} else {
// Opening tag, add it to the stack.
$tag_stack[] = $tag;
// If we're in a protected tag, the tag_stack contains at least one protected tag string. $the_content = \preg_replace_callback( '/@' . ACTIVITYPUB_USERNAME_REGEXP . '/', array( self::class, 'replace_with_links' ), $the_content );
// The protected tag state can only change when we encounter a start or end tag.
$in_protected_tag = array_intersect( $tag_stack, $protected_tags );
// Never inspect tags. $the_content = str_replace( array_reverse( array_keys( $protected_tags ) ), array_reverse( array_values( $protected_tags ) ), $the_content );
$content_with_links .= $chunk;
if ( $in_protected_tag ) { return $the_content;
// Don't inspect a chunk inside an inspected tag.
$content_with_links .= $chunk;
// Only reachable when there is no protected tag in the stack.
$content_with_links .= \preg_replace_callback( '/@' . ACTIVITYPUB_USERNAME_REGEXP . '/', array( self::class, 'replace_with_links' ), $chunk );
return $content_with_links;
} }
/** /**
@ -91,8 +74,7 @@ class Mention {
*/ */
public static function replace_with_links( $result ) { public static function replace_with_links( $result ) {
$metadata = get_remote_metadata_by_actor( $result[0] ); $metadata = get_remote_metadata_by_actor( $result[0] );
if ( ! is_wp_error( $metadata ) && ! empty( $metadata['url'] ) ) {
if ( ! empty( $metadata ) && ! is_wp_error( $metadata ) && ! empty( $metadata['url'] ) ) {
$username = ltrim( $result[0], '@' ); $username = ltrim( $result[0], '@' );
if ( ! empty( $metadata['name'] ) ) { if ( ! empty( $metadata['name'] ) ) {
$username = $metadata['name']; $username = $metadata['name'];

View file

@ -4,7 +4,6 @@ namespace Activitypub;
use Activitypub\Activitypub; use Activitypub\Activitypub;
use Activitypub\Model\Blog_User; use Activitypub\Model\Blog_User;
use Activitypub\Collection\Followers; use Activitypub\Collection\Followers;
use Activitypub\Admin;
/** /**
* ActivityPub Migration Class * ActivityPub Migration Class
@ -115,30 +114,12 @@ class Migration {
if ( version_compare( $version_from_db, '1.0.0', '<' ) ) { if ( version_compare( $version_from_db, '1.0.0', '<' ) ) {
self::migrate_from_0_17(); self::migrate_from_0_17();
} }
if ( version_compare( $version_from_db, 'version_number_transformer_management_placeholder', '<' ) ) {
update_option( 'activitypub_db_version', self::get_target_version() ); update_option( 'activitypub_db_version', self::get_target_version() );
self::unlock(); self::unlock();
} }
* Updates the supported post type settings to the mapped transformer setting.
* TODO: Test this
* @return void
private static function migrate_from_version_number_transformer_management_placeholder() {
$supported_post_types = \get_option( 'activitypub_support_post_types', array( 'post', 'page' ) );
$transformer_mapping = array();
foreach ( $supported_post_types as $supported_post_type ) {
$transformer_mapping[ $supported_post_type ] = ACTIVITYPUB_DEFAULT_TRANSFORMER;
update_option( 'activitypub_transformer_mapping', $transformer_mapping );
/** /**
* Updates the DB-schema of the followers-list * Updates the DB-schema of the followers-list
* *

View file

@ -0,0 +1,136 @@
namespace Activitypub;
class Sanitizer {
* Sanitize a multi-dimensional array
* @param array $array The array to sanitize.
* @return array The sanitized array.
public static function sanitize_array( $array ) {
$sanitized_array = array();
foreach ( $array as $key => $value ) {
$key = self::sanitize_key( $key );
if (
) {
$sanitized_array[ $key ] = self::sanitize_map( $value );
} elseif (
) {
if ( is_string( $value ) ) {
$sanitized_array[ $key ] = sanitize_url( $value );
} else {
$sanitized_array[ $key ] = '';
} elseif ( in_array( $key, array( 'summary', 'content' ), true ) ) {
$sanitized_array[ $key ] = self::sanitize_html( $value );
} elseif ( is_array( $value ) ) {
$sanitized_array[ $key ] = self::sanitize_array( $value );
} else {
$sanitized_array[ $key ] = self::sanitize_value( $value );
return $sanitized_array;
* Sanitize a value.
* @param string $value The value to sanitize.
* @return string The sanitized value.
public static function sanitize_value( $value ) {
if ( is_email( $value ) ) {
return sanitize_email( $value );
if ( filter_var( $value, FILTER_VALIDATE_URL ) ) {
return sanitize_url( $value );
return sanitize_text_field( $value );
* Sanitize HTML.
* @param string $value The value to sanitize.
* @return string The sanitized value.
public static function sanitize_html( $value ) {
if ( is_array( $value ) ) {
return '';
global $allowedtags;
$tags = array_merge(
array( 'p' => array() )
$value = \preg_replace( '@<(script|style)[^>]*?>.*?</\\1>@si', '', $value );
$value = \strip_shortcodes( $value );
$value = \wptexturize( $value );
$value = \wp_kses( $value, $tags );
return $value;
* Sanitize a translation map
* @param array $map The map to sanitize.
* @return array The sanitized map.
public static function sanitize_map( $map ) {
$sanitized_map = array();
foreach ( $map as $key => $value ) {
$key = self::sanitize_key( $key );
$sanitized_map[ $key ] = self::sanitize_html( $value );
return $sanitized_map;
* Sanitize an array key
* @param string $key The key to sanitize.
* @return string The sanitized key.
public static function sanitize_key( $key ) {
return \preg_replace( '/[^a-zA-Z0-9_\-]/', '', $key );

View file

@ -4,6 +4,7 @@ namespace Activitypub;
use Activitypub\Collection\Users; use Activitypub\Collection\Users;
use Activitypub\Collection\Followers; use Activitypub\Collection\Followers;
use Activitypub\Transformer\Post;
/** /**
* ActivityPub Scheduler Class * ActivityPub Scheduler Class
@ -104,16 +105,10 @@ class Scheduler {
* @return void * @return void
*/ */
public static function update_followers() { public static function update_followers() {
$number = 5; $followers = Followers::get_outdated_followers();
if ( defined( 'DISABLE_WP_CRON' ) && DISABLE_WP_CRON ) {
$number = 50;
$followers = Followers::get_outdated_followers( $number );
foreach ( $followers as $follower ) { foreach ( $followers as $follower ) {
$meta = get_remote_metadata_by_actor( $follower->get_url(), false ); $meta = get_remote_metadata_by_actor( $follower->get_url(), true );
if ( empty( $meta ) || ! is_array( $meta ) || is_wp_error( $meta ) ) { if ( empty( $meta ) || ! is_array( $meta ) || is_wp_error( $meta ) ) {
Followers::add_error( $follower->get__id(), $meta ); Followers::add_error( $follower->get__id(), $meta );
@ -130,16 +125,10 @@ class Scheduler {
* @return void * @return void
*/ */
public static function cleanup_followers() { public static function cleanup_followers() {
$number = 5; $followers = Followers::get_faulty_followers();
if ( defined( 'DISABLE_WP_CRON' ) && DISABLE_WP_CRON ) {
$number = 50;
$followers = Followers::get_faulty_followers( $number );
foreach ( $followers as $follower ) { foreach ( $followers as $follower ) {
$meta = get_remote_metadata_by_actor( $follower->get_url(), false ); $meta = get_remote_metadata_by_actor( $follower->get_url(), true );
if ( is_tombstone( $meta ) ) { if ( is_tombstone( $meta ) ) {
$follower->delete(); $follower->delete();

View file

@ -1,13 +1,16 @@
<?php <?php
namespace Activitypub; namespace Activitypub;
use function Activitypub\esc_hashtag;
class Shortcodes { class Shortcodes {
/** /**
* Register the shortcodes * Class constructor, registering WordPress then Shortcodes
*/ */
public static function register() { public static function init() {
// do not load on admin pages
if ( is_admin() ) {
foreach ( get_class_methods( self::class ) as $shortcode ) { foreach ( get_class_methods( self::class ) as $shortcode ) {
if ( 'init' !== $shortcode ) { if ( 'init' !== $shortcode ) {
add_shortcode( 'ap_' . $shortcode, array( self::class, $shortcode ) ); add_shortcode( 'ap_' . $shortcode, array( self::class, $shortcode ) );
@ -15,17 +18,6 @@ class Shortcodes {
} }
} }
* Unregister the shortcodes
public static function unregister() {
foreach ( get_class_methods( self::class ) as $shortcode ) {
if ( 'init' !== $shortcode ) {
remove_shortcode( 'ap_' . $shortcode );
/** /**
* Generates output for the 'ap_hashtags' shortcode * Generates output for the 'ap_hashtags' shortcode
* *
@ -52,9 +44,9 @@ class Shortcodes {
foreach ( $tags as $tag ) { foreach ( $tags as $tag ) {
$hash_tags[] = \sprintf( $hash_tags[] = \sprintf(
'<a rel="tag" class="hashtag u-tag u-category" href="%s">%s</a>', '<a rel="tag" class="u-tag u-category" href="%s">#%s</a>',
\esc_url( \get_tag_link( $tag ) ), \esc_url( \get_tag_link( $tag ) ),
esc_hashtag( $tag->name ) \wp_strip_all_tags( $tag->slug )
); );
} }
@ -120,7 +112,7 @@ class Shortcodes {
/** This filter is documented in wp-includes/post-template.php */ /** This filter is documented in wp-includes/post-template.php */
$excerpt = \apply_filters( 'the_content', $excerpt ); $excerpt = \apply_filters( 'the_content', $excerpt );
$excerpt = \str_replace( ']]>', ']]&gt;', $excerpt ); $excerpt = \str_replace( ']]>', ']]>', $excerpt );
} }
} }
@ -365,9 +357,9 @@ class Shortcodes {
foreach ( $categories as $category ) { foreach ( $categories as $category ) {
$hash_tags[] = \sprintf( $hash_tags[] = \sprintf(
'<a rel="tag" class="hashtag u-tag u-category" href="%s">%s</a>', '<a rel="tag" class="u-tag u-category" href="%s">#%s</a>',
\esc_url( \get_category_link( $category ) ), \esc_url( \get_category_link( $category ) ),
esc_hashtag( $category->name ) \wp_strip_all_tags( $category->slug )
); );
} }
@ -390,8 +382,7 @@ class Shortcodes {
return ''; return '';
} }
$author_id = \get_post_field( 'post_author', $item->ID ); $name = \get_the_author_meta( 'display_name', $item->post_author );
$name = \get_the_author_meta( 'display_name', $author_id );
if ( ! $name ) { if ( ! $name ) {
return ''; return '';
@ -416,8 +407,7 @@ class Shortcodes {
return ''; return '';
} }
$author_id = \get_post_field( 'post_author', $item->ID ); $url = \get_the_author_meta( 'user_url', $item->post_author );
$url = \get_the_author_meta( 'user_url', $author_id );
if ( ! $url ) { if ( ! $url ) {
return ''; return '';

View file

@ -4,7 +4,7 @@ namespace Activitypub;
use WP_Error; use WP_Error;
use DateTime; use DateTime;
use DateTimeZone; use DateTimeZone;
use WP_REST_Request; use Activitypub\Model\User;
use Activitypub\Collection\Users; use Activitypub\Collection\Users;
/** /**
@ -23,14 +23,22 @@ class Signature {
* *
* @return mixed The public key. * @return mixed The public key.
*/ */
public static function get_public_key_for( $user_id, $force = false ) { public static function get_public_key( $user_id, $force = false ) {
if ( $force ) { if ( $force ) {
self::generate_key_pair_for( $user_id ); self::generate_key_pair( $user_id );
} }
$key_pair = self::get_keypair_for( $user_id ); if ( User::APPLICATION_USER_ID === $user_id ) {
$key = \get_option( 'activitypub_magic_sig_public_key' );
} else {
$key = \get_user_meta( $user_id, 'magic_sig_public_key', true );
return $key_pair['public_key']; if ( ! $key ) {
return self::get_public_key( $user_id, true );
return $key;
} }
/** /**
@ -41,32 +49,22 @@ class Signature {
* *
* @return mixed The private key. * @return mixed The private key.
*/ */
public static function get_private_key_for( $user_id, $force = false ) { public static function get_private_key( $user_id, $force = false ) {
if ( $force ) { if ( $force ) {
self::generate_key_pair_for( $user_id ); self::generate_key_pair( $user_id );
} }
$key_pair = self::get_keypair_for( $user_id ); if ( User::APPLICATION_USER_ID === $user_id ) {
$key = \get_option( 'activitypub_magic_sig_private_key' );
return $key_pair['private_key']; } else {
$key = \get_user_meta( $user_id, 'magic_sig_private_key', true );
} }
/** if ( ! $key ) {
* Return the key pair for a given user. return self::get_private_key( $user_id, true );
* @param int $user_id The WordPress User ID.
* @return array The key pair.
public static function get_keypair_for( $user_id ) {
$option_key = self::get_signature_options_key_for( $user_id );
$key_pair = \get_option( $option_key );
if ( ! $key_pair ) {
$key_pair = self::generate_key_pair_for( $user_id );
} }
return $key_pair; return $key;
} }
/** /**
@ -74,18 +72,9 @@ class Signature {
* *
* @param int $user_id The WordPress User ID. * @param int $user_id The WordPress User ID.
* *
* @return array The key pair. * @return void
*/ */
protected static function generate_key_pair_for( $user_id ) { public static function generate_key_pair() {
$option_key = self::get_signature_options_key_for( $user_id );
$key_pair = self::check_legacy_key_pair_for( $user_id );
if ( $key_pair ) {
\add_option( $option_key, $key_pair );
return $key_pair;
$config = array( $config = array(
'digest_alg' => 'sha512', 'digest_alg' => 'sha512',
'private_key_bits' => 2048, 'private_key_bits' => 2048,
@ -99,78 +88,10 @@ class Signature {
$detail = \openssl_pkey_get_details( $key ); $detail = \openssl_pkey_get_details( $key );
// check if keys are valid
if (
empty( $priv_key ) || ! is_string( $priv_key ) ||
! isset( $detail['key'] ) || ! is_string( $detail['key'] )
) {
return array( return array(
'private_key' => null,
'public_key' => null,
$key_pair = array(
'private_key' => $priv_key, 'private_key' => $priv_key,
'public_key' => $detail['key'], 'public_key' => $detail['key'],
); );
// persist keys
\add_option( $option_key, $key_pair );
return $key_pair;
* Return the option key for a given user.
* @param int $user_id The WordPress User ID.
* @return string The option key.
protected static function get_signature_options_key_for( $user_id ) {
$id = $user_id;
if ( $user_id > 0 ) {
$user = \get_userdata( $user_id );
// sanatize username because it could include spaces and special chars
$id = sanitize_title( $user->user_login );
return 'activitypub_keypair_for_' . $id;
* Check if there is a legacy key pair
* @param int $user_id The WordPress User ID.
* @return array|bool The key pair or false.
protected static function check_legacy_key_pair_for( $user_id ) {
switch ( $user_id ) {
case 0:
$public_key = \get_option( 'activitypub_blog_user_public_key' );
$private_key = \get_option( 'activitypub_blog_user_private_key' );
case -1:
$public_key = \get_option( 'activitypub_application_user_public_key' );
$private_key = \get_option( 'activitypub_application_user_private_key' );
$public_key = \get_user_meta( $user_id, 'magic_sig_public_key', true );
$private_key = \get_user_meta( $user_id, 'magic_sig_private_key', true );
if ( ! empty( $public_key ) && is_string( $public_key ) && ! empty( $private_key ) && is_string( $private_key ) ) {
return array(
'private_key' => $private_key,
'public_key' => $public_key,
return false;
} }
/** /**
@ -186,7 +107,7 @@ class Signature {
*/ */
public static function generate_signature( $user_id, $http_method, $url, $date, $digest = null ) { public static function generate_signature( $user_id, $http_method, $url, $date, $digest = null ) {
$user = Users::get_by_id( $user_id ); $user = Users::get_by_id( $user_id );
$key = self::get_private_key_for( $user->get__id() ); $key = $user->get__private_key();
$url_parts = \wp_parse_url( $url ); $url_parts = \wp_parse_url( $url );
@ -215,6 +136,7 @@ class Signature {
\openssl_sign( $signed_string, $signature, $key, \OPENSSL_ALGO_SHA256 ); \openssl_sign( $signed_string, $signature, $key, \OPENSSL_ALGO_SHA256 );
$signature = \base64_encode( $signature ); // phpcs:ignore $signature = \base64_encode( $signature ); // phpcs:ignore
$user = Users::get_by_id( $user_id );
$key_id = $user->get_url() . '#main-key'; $key_id = $user->get_url() . '#main-key';
if ( ! empty( $digest ) ) { if ( ! empty( $digest ) ) {
@ -227,7 +149,7 @@ class Signature {
/** /**
* Verifies the http signatures * Verifies the http signatures
* *
* @param WP_REST_Request|array $request The request object or $_SERVER array. * @param WP_REQUEST|array $request The request object or $_SERVER array.
* *
* @return mixed A boolean or WP_Error. * @return mixed A boolean or WP_Error.
*/ */
@ -239,38 +161,28 @@ class Signature {
} else { } else {
$route = '/' . rest_get_url_prefix() . '/' . ltrim( $request->get_route(), '/' ); $route = '/' . rest_get_url_prefix() . '/' . ltrim( $request->get_route(), '/' );
} }
// fix route for subdirectory installs
$path = \wp_parse_url( \get_home_url(), PHP_URL_PATH );
if ( \is_string( $path ) ) {
$path = trim( $path, '/' );
if ( $path ) {
$route = '/' . $path . $route;
$headers = $request->get_headers(); $headers = $request->get_headers();
$actor = isset( json_decode( $request->get_body() )->actor ) ? json_decode( $request->get_body() )->actor : '';
$headers['(request-target)'][0] = strtolower( $request->get_method() ) . ' ' . $route; $headers['(request-target)'][0] = strtolower( $request->get_method() ) . ' ' . $route;
} else { } else {
$request = self::format_server_request( $request ); $request = self::format_server_request( $request );
$headers = $request['headers']; // $_SERVER array $headers = $request['headers']; // $_SERVER array
$actor = null;
$headers['(request-target)'][0] = strtolower( $headers['request_method'][0] ) . ' ' . $headers['request_uri'][0]; $headers['(request-target)'][0] = strtolower( $headers['request_method'][0] ) . ' ' . $headers['request_uri'][0];
} }
if ( ! isset( $headers['signature'] ) ) { if ( ! isset( $headers['signature'] ) ) {
return new WP_Error( 'activitypub_signature', __( 'Request not signed', 'activitypub' ), array( 'status' => 401 ) ); return new WP_Error( 'activitypub_signature', 'Request not signed', array( 'status' => 403 ) );
} }
if ( array_key_exists( 'signature', $headers ) ) { if ( array_key_exists( 'signature', $headers ) ) {
$signature_block = self::parse_signature_header( $headers['signature'][0] ); $signature_block = self::parse_signature_header( $headers['signature'] );
} elseif ( array_key_exists( 'authorization', $headers ) ) { } elseif ( array_key_exists( 'authorization', $headers ) ) {
$signature_block = self::parse_signature_header( $headers['authorization'][0] ); $signature_block = self::parse_signature_header( $headers['authorization'] );
} }
if ( ! isset( $signature_block ) || ! $signature_block ) { if ( ! isset( $signature_block ) || ! $signature_block ) {
return new WP_Error( 'activitypub_signature', __( 'Incompatible request signature. keyId and signature are required', 'activitypub' ), array( 'status' => 401 ) ); return new WP_Error( 'activitypub_signature', 'Incompatible request signature. keyId and signature are required', array( 'status' => 403 ) );
} }
$signed_headers = $signature_block['headers']; $signed_headers = $signature_block['headers'];
@ -280,12 +192,12 @@ class Signature {
$signed_data = self::get_signed_data( $signed_headers, $signature_block, $headers ); $signed_data = self::get_signed_data( $signed_headers, $signature_block, $headers );
if ( ! $signed_data ) { if ( ! $signed_data ) {
return new WP_Error( 'activitypub_signature', __( 'Signed request date outside acceptable time window', 'activitypub' ), array( 'status' => 401 ) ); return new WP_Error( 'activitypub_signature', 'Signed request date outside acceptable time window', array( 'status' => 403 ) );
} }
$algorithm = self::get_signature_algorithm( $signature_block ); $algorithm = self::get_signature_algorithm( $signature_block );
if ( ! $algorithm ) { if ( ! $algorithm ) {
return new WP_Error( 'activitypub_signature', __( 'Unsupported signature algorithm (only rsa-sha256 and hs2019 are supported)', 'activitypub' ), array( 'status' => 401 ) ); return new WP_Error( 'activitypub_signature', 'Unsupported signature algorithm (only rsa-sha256 and hs2019 are supported)', array( 'status' => 403 ) );
} }
if ( \in_array( 'digest', $signed_headers, true ) && isset( $body ) ) { if ( \in_array( 'digest', $signed_headers, true ) && isset( $body ) ) {
@ -301,12 +213,15 @@ class Signature {
} }
if ( \base64_encode( \hash( $hashalg, $body, true ) ) !== $digest[1] ) { // phpcs:ignore if ( \base64_encode( \hash( $hashalg, $body, true ) ) !== $digest[1] ) { // phpcs:ignore
return new WP_Error( 'activitypub_signature', __( 'Invalid Digest header', 'activitypub' ), array( 'status' => 401 ) ); return new WP_Error( 'activitypub_signature', 'Invalid Digest header', array( 'status' => 403 ) );
} }
} }
if ( $actor ) {
$public_key = self::get_remote_key( $actor );
} else {
$public_key = self::get_remote_key( $signature_block['keyId'] ); $public_key = self::get_remote_key( $signature_block['keyId'] );
if ( \is_wp_error( $public_key ) ) { if ( \is_wp_error( $public_key ) ) {
return $public_key; return $public_key;
} }
@ -314,7 +229,7 @@ class Signature {
$verified = \openssl_verify( $signed_data, $signature_block['signature'], $public_key, $algorithm ) > 0; $verified = \openssl_verify( $signed_data, $signature_block['signature'], $public_key, $algorithm ) > 0;
if ( ! $verified ) { if ( ! $verified ) {
return new WP_Error( 'activitypub_signature', __( 'Invalid signature', 'activitypub' ), array( 'status' => 401 ) ); return new WP_Error( 'activitypub_signature', 'Invalid signature', array( 'status' => 403 ) );
} }
return $verified; return $verified;
} }
@ -324,25 +239,17 @@ class Signature {
* *
* @param string $key_id The URL to the public key. * @param string $key_id The URL to the public key.
* *
* @return WP_Error|string The public key or WP_Error. * @return string The public key.
*/ */
public static function get_remote_key( $key_id ) { // phpcs:ignore public static function get_remote_key( $key_id ) { // phpcs:ignore
$actor = get_remote_metadata_by_actor( strip_fragment_from_url( $key_id ) ); // phpcs:ignore $actor = get_remote_metadata_by_actor( strtok( strip_fragment_from_url( $key_id ), '?' ) ); // phpcs:ignore
if ( \is_wp_error( $actor ) ) { if ( \is_wp_error( $actor ) ) {
return new WP_Error( return $actor;
__( 'No Profile found or Profile not accessible', 'activitypub' ),
array( 'status' => 401 )
} }
if ( isset( $actor['publicKey']['publicKeyPem'] ) ) { if ( isset( $actor['publicKey']['publicKeyPem'] ) ) {
return \rtrim( $actor['publicKey']['publicKeyPem'] ); // phpcs:ignore return \rtrim( $actor['publicKey']['publicKeyPem'] ); // phpcs:ignore
} }
return new WP_Error( return null;
__( 'No Public-Key found', 'activitypub' ),
array( 'status' => 401 )
} }
/** /**
@ -367,31 +274,32 @@ class Signature {
/** /**
* Parses the Signature header * Parses the Signature header
* *
* @param string $signature The signature header. * @param array $header The signature header.
* *
* @return array signature parts * @return array signature parts
*/ */
public static function parse_signature_header( $signature ) { public static function parse_signature_header( $header ) {
$parsed_header = array(); $parsed_header = array();
$matches = array(); $matches = array();
$h_string = \implode( ',', (array) $header[0] );
if ( \preg_match( '/keyId="(.*?)"/ism', $signature, $matches ) ) { if ( \preg_match( '/keyId="(.*?)"/ism', $h_string, $matches ) ) {
$parsed_header['keyId'] = trim( $matches[1] ); $parsed_header['keyId'] = $matches[1];
} }
if ( \preg_match( '/created=([0-9]*)/ism', $signature, $matches ) ) { if ( \preg_match( '/created=([0-9]*)/ism', $h_string, $matches ) ) {
$parsed_header['(created)'] = trim( $matches[1] ); $parsed_header['(created)'] = $matches[1];
} }
if ( \preg_match( '/expires=([0-9]*)/ism', $signature, $matches ) ) { if ( \preg_match( '/expires=([0-9]*)/ism', $h_string, $matches ) ) {
$parsed_header['(expires)'] = trim( $matches[1] ); $parsed_header['(expires)'] = $matches[1];
} }
if ( \preg_match( '/algorithm="(.*?)"/ism', $signature, $matches ) ) { if ( \preg_match( '/algorithm="(.*?)"/ism', $h_string, $matches ) ) {
$parsed_header['algorithm'] = trim( $matches[1] ); $parsed_header['algorithm'] = $matches[1];
} }
if ( \preg_match( '/headers="(.*?)"/ism', $signature, $matches ) ) { if ( \preg_match( '/headers="(.*?)"/ism', $h_string, $matches ) ) {
$parsed_header['headers'] = \explode( ' ', trim( $matches[1] ) ); $parsed_header['headers'] = \explode( ' ', $matches[1] );
} }
if ( \preg_match( '/signature="(.*?)"/ism', $signature, $matches ) ) { if ( \preg_match( '/signature="(.*?)"/ism', $h_string, $matches ) ) {
$parsed_header['signature'] = \base64_decode( preg_replace( '/\s+/', '', trim( $matches[1] ) ) ); // phpcs:ignore $parsed_header['signature'] = \base64_decode( preg_replace( '/\s+/', '', $matches[1] ) ); // phpcs:ignore
} }
if ( ( $parsed_header['signature'] ) && ( $parsed_header['algorithm'] ) && ( ! $parsed_header['headers'] ) ) { if ( ( $parsed_header['signature'] ) && ( $parsed_header['algorithm'] ) && ( ! $parsed_header['headers'] ) ) {
@ -404,7 +312,7 @@ class Signature {
/** /**
* Gets the header data from the included pseudo headers * Gets the header data from the included pseudo headers
* *
* @param array $signed_headers The signed headers. * @param array $signed_headers
* @param array $signature_block (pseudo-headers) * @param array $signature_block (pseudo-headers)
* @param array $headers (http headers) * @param array $headers (http headers)
* *

View file

@ -26,7 +26,7 @@ class Webfinger {
} }
$user = Users::get_by_id( $user_id ); $user = Users::get_by_id( $user_id );
if ( ! $user || is_wp_error( $user ) ) { if ( ! $user ) {
return ''; return '';
} }
@ -41,14 +41,9 @@ class Webfinger {
* @return string|WP_Error The URL or WP_Error * @return string|WP_Error The URL or WP_Error
*/ */
public static function resolve( $resource ) { public static function resolve( $resource ) {
if ( ! $resource ) {
return null;
if ( ! preg_match( '/^@?' . ACTIVITYPUB_USERNAME_REGEXP . '$/i', $resource, $m ) ) { if ( ! preg_match( '/^@?' . ACTIVITYPUB_USERNAME_REGEXP . '$/i', $resource, $m ) ) {
return null; return null;
} }
$transient_key = 'activitypub_resolve_' . ltrim( $resource, '@' ); $transient_key = 'activitypub_resolve_' . ltrim( $resource, '@' );
$link = \get_transient( $transient_key ); $link = \get_transient( $transient_key );
@ -67,8 +62,8 @@ class Webfinger {
$response = \wp_remote_get( $response = \wp_remote_get(
$url, $url,
array( array(
'headers' => array( 'Accept' => 'application/jrd+json' ), 'headers' => array( 'Accept' => 'application/activity+json' ),
'redirection' => 2, 'redirection' => 0,
'timeout' => 2, 'timeout' => 2,
) )
); );
@ -99,110 +94,4 @@ class Webfinger {
\set_transient( $transient_key, $link, HOUR_IN_SECONDS ); // Cache the error for a shorter period. \set_transient( $transient_key, $link, HOUR_IN_SECONDS ); // Cache the error for a shorter period.
return $link; return $link;
} }
* Convert a URI string to an identifier and its host.
* Automatically adds acct: if it's missing.
* @param string $url The URI (acct:, mailto:, http:, https:)
* @return WP_Error|array Error reaction or array with
* identifier and host as values
public static function get_identifier_and_host( $url ) {
// remove leading @
$url = ltrim( $url, '@' );
if ( ! preg_match( '/^([a-zA-Z+]+):/', $url, $match ) ) {
$identifier = 'acct:' . $url;
$scheme = 'acct';
} else {
$identifier = $url;
$scheme = $match[1];
$host = null;
switch ( $scheme ) {
case 'acct':
case 'mailto':
case 'xmpp':
if ( strpos( $identifier, '@' ) !== false ) {
$host = substr( $identifier, strpos( $identifier, '@' ) + 1 );
$host = wp_parse_url( $identifier, PHP_URL_HOST );
if ( empty( $host ) ) {
return new WP_Error( 'invalid_identifier', __( 'Invalid Identifier', 'activitypub' ) );
return array( $identifier, $host );
* Get the WebFinger data for a given URI
* @param string $identifier The Identifier: <identifier>@<host>
* @param string $host The Host: <identifier>@<host>
* @return WP_Error|array Error reaction or array with
* identifier and host as values
public static function get_data( $identifier, $host ) {
$webfinger_url = 'https://' . $host . '/.well-known/webfinger?resource=' . rawurlencode( $identifier );
$response = wp_safe_remote_get(
'headers' => array( 'Accept' => 'application/jrd+json' ),
'redirection' => 0,
'timeout' => 2,
if ( is_wp_error( $response ) ) {
return new WP_Error( 'webfinger_url_not_accessible', null, $webfinger_url );
$body = wp_remote_retrieve_body( $response );
return json_decode( $body, true );
* Undocumented function
* @return void
public static function get_remote_follow_endpoint( $uri ) {
$identifier_and_host = self::get_identifier_and_host( $uri );
if ( is_wp_error( $identifier_and_host ) ) {
return $identifier_and_host;
list( $identifier, $host ) = $identifier_and_host;
$data = self::get_data( $identifier, $host );
if ( is_wp_error( $data ) ) {
return $data;
if ( empty( $data['links'] ) ) {
return new WP_Error( 'webfinger_url_invalid_response', null, $data );
foreach ( $data['links'] as $link ) {
if ( '' === $link['rel'] ) {
return $link['template'];
return new WP_Error( 'webfinger_remote_follow_endpoint_invalid', $data, array( 'status' => 417 ) );
} }

View file

@ -160,7 +160,7 @@ class Followers {
* @param int $user_id The ID of the WordPress User * @param int $user_id The ID of the WordPress User
* @param string $actor The Actor URL * @param string $actor The Actor URL
* *
* @return array|WP_Error The Follower (WP_Post array) or an WP_Error * @return array|WP_Error The Follower (WP_Term array) or an WP_Error
*/ */
public static function add_follower( $user_id, $actor ) { public static function add_follower( $user_id, $actor ) {
$meta = get_remote_metadata_by_actor( $actor ); $meta = get_remote_metadata_by_actor( $actor );
@ -169,24 +169,29 @@ class Followers {
return $meta; return $meta;
} }
if ( empty( $meta ) || ! is_array( $meta ) || is_wp_error( $meta ) ) { $error = null;
return new WP_Error( 'activitypub_invalid_follower', __( 'Invalid Follower', 'activitypub' ), array( 'status' => 400 ) );
$follower = new Follower(); $follower = new Follower();
if ( empty( $meta ) || ! is_array( $meta ) || is_wp_error( $meta ) ) {
$follower->set_id( $actor );
$follower->set_url( $actor );
$error = $meta;
} else {
$follower->from_array( $meta ); $follower->from_array( $meta );
$id = $follower->upsert();
if ( is_wp_error( $id ) ) {
return $id;
} }
$post_meta = get_post_meta( $id, 'activitypub_user_id' ); $follower->upsert();
$meta = get_post_meta( $follower->get__id(), 'activitypub_user_id' );
if ( $error ) {
self::add_error( $follower->get__id(), $error );
// phpcs:ignore WordPress.PHP.StrictInArray.MissingTrueStrict // phpcs:ignore WordPress.PHP.StrictInArray.MissingTrueStrict
if ( is_array( $post_meta ) && ! in_array( $user_id, $post_meta ) ) { if ( is_array( $meta ) && ! in_array( $user_id, $meta ) ) {
add_post_meta( $id, 'activitypub_user_id', $user_id ); add_post_meta( $follower->get__id(), 'activitypub_user_id', $user_id );
wp_cache_delete( sprintf( self::CACHE_KEY_INBOXES, $user_id ), 'activitypub' ); wp_cache_delete( sprintf( self::CACHE_KEY_INBOXES, $user_id ), 'activitypub' );
} }
@ -260,18 +265,11 @@ class Followers {
return; return;
} }
// only send minimal data if ( isset( $object['user_id'] ) ) {
$object = array_intersect_key( unset( $object['user_id'] );
$object, }
array( unset( $object['@context'] );
$user = Users::get_by_id( $user_id ); $user = Users::get_by_id( $user_id );
@ -284,7 +282,7 @@ class Followers {
$activity->set_object( $object ); $activity->set_object( $object );
$activity->set_actor( $user->get_id() ); $activity->set_actor( $user->get_id() );
$activity->set_to( $actor ); $activity->set_to( $actor );
$activity->set_id( $user->get_id() . '#follow-' . \preg_replace( '~^https?://~', '', $actor ) . '-' . \time() ); $activity->set_id( $user->get_id() . '#follow-' . \preg_replace( '~^https?://~', '', $actor ) );
$activity = $activity->to_json(); $activity = $activity->to_json();
@ -355,17 +353,7 @@ class Followers {
public static function get_all_followers() { public static function get_all_followers() {
$args = array( $args = array(
// phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_query // phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_query
'meta_query' => array( 'meta_query' => array(),
'relation' => 'AND',
'key' => 'activitypub_inbox',
'compare' => 'EXISTS',
'key' => 'activitypub_actor_json',
'compare' => 'EXISTS',
); );
return self::get_followers( null, null, null, $args ); return self::get_followers( null, null, null, $args );
} }
@ -384,19 +372,10 @@ class Followers {
'fields' => 'ids', 'fields' => 'ids',
// phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_query // phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_query
'meta_query' => array( 'meta_query' => array(
'relation' => 'AND',
array( array(
'key' => 'activitypub_user_id', 'key' => 'activitypub_user_id',
'value' => $user_id, 'value' => $user_id,
), ),
'key' => 'activitypub_inbox',
'compare' => 'EXISTS',
'key' => 'activitypub_actor_json',
'compare' => 'EXISTS',
), ),
) )
); );
@ -426,7 +405,6 @@ class Followers {
'fields' => 'ids', 'fields' => 'ids',
// phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_query // phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_query
'meta_query' => array( 'meta_query' => array(
'relation' => 'AND',
array( array(
'key' => 'activitypub_inbox', 'key' => 'activitypub_inbox',
'compare' => 'EXISTS', 'compare' => 'EXISTS',
@ -435,11 +413,6 @@ class Followers {
'key' => 'activitypub_user_id', 'key' => 'activitypub_user_id',
'value' => $user_id, 'value' => $user_id,
), ),
'key' => 'activitypub_inbox',
'value' => '',
'compare' => '!=',
), ),
) )
); );
@ -482,7 +455,7 @@ class Followers {
'post_type' => self::POST_TYPE, 'post_type' => self::POST_TYPE,
'posts_per_page' => $number, 'posts_per_page' => $number,
'orderby' => 'modified', 'orderby' => 'modified',
'order' => 'ASC', 'order' => 'DESC',
'post_status' => 'any', // 'any' includes 'trash 'post_status' => 'any', // 'any' includes 'trash
'date_query' => array( 'date_query' => array(
array( array(
@ -510,35 +483,16 @@ class Followers {
* *
* @return mixed The Term list of Followers, the format depends on $output. * @return mixed The Term list of Followers, the format depends on $output.
*/ */
public static function get_faulty_followers( $number = 20 ) { public static function get_faulty_followers( $number = 10 ) {
$args = array( $args = array(
'post_type' => self::POST_TYPE, 'post_type' => self::POST_TYPE,
'posts_per_page' => $number, 'posts_per_page' => $number,
// phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_query // phpcs:ignore WordPress.DB.SlowDBQuery.slow_db_query_meta_query
'meta_query' => array( 'meta_query' => array(
'relation' => 'OR',
array( array(
'key' => 'activitypub_errors', 'key' => 'activitypub_errors',
'compare' => 'EXISTS', 'compare' => 'EXISTS',
), ),
'key' => 'activitypub_inbox',
'compare' => 'NOT EXISTS',
'key' => 'activitypub_actor_json',
'compare' => 'NOT EXISTS',
'key' => 'activitypub_inbox',
'value' => '',
'compare' => '=',
'key' => 'activitypub_actor_json',
'value' => '',
'compare' => '=',
), ),
); );

@ -185,25 +185,4 @@ class Users {
public static function normalize_host( $host ) { public static function normalize_host( $host ) {
return \str_replace( 'www.', '', $host ); return \str_replace( 'www.', '', $host );
} }
* Get the User collection.
* @return array The User collection.
public static function get_collection() {
$users = \get_users(
'capability__in' => array( 'publish_posts' ),
$return = array();
foreach ( $users as $user ) {
$return[] = User::from_wp_user( $user->ID );
return $return;
} }

@ -1,49 +0,0 @@
* ActivityPub implementation for WordPress/PHP functions either missing from older WordPress/PHP versions or not included by default.
if ( ! function_exists( 'str_starts_with' ) ) {
* Polyfill for `str_starts_with()` function added in PHP 8.0.
* Performs a case-sensitive check indicating if
* the haystack begins with needle.
* @param string $haystack The string to search in.
* @param string $needle The substring to search for in the `$haystack`.
* @return bool True if `$haystack` starts with `$needle`, otherwise false.
function str_starts_with( $haystack, $needle ) {
if ( '' === $needle ) {
return true;
return 0 === strpos( $haystack, $needle );
if ( ! function_exists( 'get_self_link' ) ) {
* Returns the link for the currently displayed feed.
* @return string Correct link for the atom:self element.
function get_self_link() {
$host = wp_parse_url( home_url() );
$path = isset( $_SERVER['REQUEST_URI'] ) ? sanitize_text_field( wp_unslash( $_SERVER['REQUEST_URI'] ) ) : '';
return esc_url( apply_filters( 'self_link', set_url_scheme( 'http://' . $host['host'] . $path ) ) );
if ( ! function_exists( 'is_countable' ) ) {
* Polyfill for `is_countable()` function added in PHP 7.3.
* @param mixed $value The value to check.
* @return bool True if `$value` is countable, otherwise false.
function is_countable( $value ) {
return is_array( $value ) || $value instanceof \Countable;

@ -5,7 +5,6 @@ use WP_Error;
use Activitypub\Http; use Activitypub\Http;
use Activitypub\Activity\Activity; use Activitypub\Activity\Activity;
use Activitypub\Collection\Followers; use Activitypub\Collection\Followers;
use Activitypub\Collection\Users;
/** /**
* Returns the ActivityPub default JSON-context * Returns the ActivityPub default JSON-context
@ -43,7 +42,7 @@ function get_webfinger_resource( $user_id ) {
* @param string $actor The Actor URL. * @param string $actor The Actor URL.
* @param bool $cached If the result should be cached. * @param bool $cached If the result should be cached.
* *
* @return array|WP_Error The Actor profile as array or WP_Error on failure. * @return array The Actor profile as array
*/ */
function get_remote_metadata_by_actor( $actor, $cached = true ) { function get_remote_metadata_by_actor( $actor, $cached = true ) {
$pre = apply_filters( 'pre_get_remote_metadata_by_actor', false, $actor ); $pre = apply_filters( 'pre_get_remote_metadata_by_actor', false, $actor );
@ -55,7 +54,7 @@ function get_remote_metadata_by_actor( $actor, $cached = true ) {
} }
if ( ! $actor ) { if ( ! $actor ) {
return new WP_Error( 'activitypub_no_valid_actor_identifier', \__( 'The "actor" identifier is not valid', 'activitypub' ), array( 'status' => 404, 'actor' => $actor ) ); return null;
} }
if ( is_wp_error( $actor ) ) { if ( is_wp_error( $actor ) ) {
@ -74,26 +73,33 @@ function get_remote_metadata_by_actor( $actor, $cached = true ) {
} }
if ( ! \wp_http_validate_url( $actor ) ) { if ( ! \wp_http_validate_url( $actor ) ) {
$metadata = new WP_Error( 'activitypub_no_valid_actor_url', \__( 'The "actor" is no valid URL', 'activitypub' ), array( 'status' => 400, 'actor' => $actor ) ); $metadata = new \WP_Error( 'activitypub_no_valid_actor_url', \__( 'The "actor" is no valid URL', 'activitypub' ), $actor );
\set_transient( $transient_key, $metadata, HOUR_IN_SECONDS ); // Cache the error for a shorter period.
return $metadata; return $metadata;
} }
$short_timeout = function() {
return 3;
add_filter( 'activitypub_remote_get_timeout', $short_timeout );
$response = Http::get( $actor ); $response = Http::get( $actor );
remove_filter( 'activitypub_remote_get_timeout', $short_timeout );
if ( \is_wp_error( $response ) ) { if ( \is_wp_error( $response ) ) {
\set_transient( $transient_key, $response, HOUR_IN_SECONDS ); // Cache the error for a shorter period.
return $response; return $response;
} }
$metadata = \wp_remote_retrieve_body( $response ); $metadata = \wp_remote_retrieve_body( $response );
$metadata = \json_decode( $metadata, true ); $metadata = \json_decode( $metadata, true );
\set_transient( $transient_key, $metadata, WEEK_IN_SECONDS );
if ( ! $metadata ) { if ( ! $metadata ) {
$metadata = new WP_Error( 'activitypub_invalid_json', \__( 'No valid JSON data', 'activitypub' ), array( 'status' => 400, 'actor' => $actor ) ); $metadata = new \WP_Error( 'activitypub_invalid_json', \__( 'No valid JSON data', 'activitypub' ), $actor );
\set_transient( $transient_key, $metadata, HOUR_IN_SECONDS ); // Cache the error for a shorter period.
return $metadata; return $metadata;
} }
\set_transient( $transient_key, $metadata, WEEK_IN_SECONDS );
return $metadata; return $metadata;
} }
@ -226,43 +232,6 @@ function snake_to_camel_case( $string ) {
return lcfirst( str_replace( '_', '', ucwords( $string, '_' ) ) ); return lcfirst( str_replace( '_', '', ucwords( $string, '_' ) ) );
} }
* Escapes a Tag, to be used as a hashtag.
* @param string $string The string to escape.
* @return string The escaped hastag.
function esc_hashtag( $string ) {
$hashtag = \wp_specialchars_decode( $string, ENT_QUOTES );
// Remove all characters that are not letters, numbers, or underscores.
$hashtag = \preg_replace( '/emoji-regex(*SKIP)(?!)|[^\p{L}\p{Nd}_]+/u', '_', $hashtag );
// Capitalize every letter that is preceded by an underscore.
$hashtag = preg_replace_callback(
function ( $matches ) {
return '' . strtoupper( $matches[1] );
// Add a hashtag to the beginning of the string.
$hashtag = ltrim( $hashtag, '#' );
$hashtag = '#' . $hashtag;
* Allow defining your own custom hashtag generation rules.
* @param string $hashtag The hashtag to be returned.
* @param string $string The original string.
$hashtag = apply_filters( 'activitypub_esc_hashtag', $hashtag, $string );
return esc_html( $hashtag );
/** /**
* Check if a request is for an ActivityPub request. * Check if a request is for an ActivityPub request.
* *
@ -279,16 +248,6 @@ function is_activitypub_request() {
return false; return false;
} }
// Check if the current post type supports ActivityPub.
if ( \is_singular() ) {
$queried_object = \get_queried_object();
$post_type = \get_post_type( $queried_object );
if ( ! \post_type_supports( $post_type, 'activitypub' ) ) {
return false;
// One can trigger an ActivityPub request by adding ?activitypub to the URL. // One can trigger an ActivityPub request by adding ?activitypub to the URL.
// phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.VariableRedeclaration // phpcs:ignore VariableAnalysis.CodeAnalysis.VariableAnalysis.VariableRedeclaration
global $wp_query; global $wp_query;
@ -309,9 +268,8 @@ function is_activitypub_request() {
* and return true when the header includes at least one of the following: * and return true when the header includes at least one of the following:
* - application/activity+json * - application/activity+json
* - application/ld+json * - application/ld+json
* - application/json
*/ */
if ( preg_match( '/(application\/(ld\+json|activity\+json|json))/i', $accept ) ) { if ( preg_match( '/(application\/(ld\+json|activity\+json))/', $accept ) ) {
return true; return true;
} }
} }
@ -420,7 +378,7 @@ function is_user_type_disabled( $type ) {
$return = false; $return = false;
break; break;
default: default:
$return = new WP_Error( 'activitypub_wrong_user_type', __( 'Wrong user type', 'activitypub' ), array( 'status' => 400 ) ); $return = new WP_Error( 'activitypub_wrong_user_type', __( 'Wrong user type', 'activitypub' ) );
break; break;
} }
@ -433,127 +391,31 @@ function is_user_type_disabled( $type ) {
* @return boolean True if the blog is in single-user mode, false otherwise. * @return boolean True if the blog is in single-user mode, false otherwise.
*/ */
function is_single_user() { function is_single_user() {
if ( $return = false;
if ( \defined( 'ACTIVITYPUB_SINGLE_USER_MODE' ) ) {
$return = true;
} elseif (
false === is_user_type_disabled( 'blog' ) && false === is_user_type_disabled( 'blog' ) &&
true === is_user_type_disabled( 'user' ) true === is_user_type_disabled( 'user' )
) { ) {
return true; $return = true;
} }
return false; return $return;
} }
if ( ! function_exists( 'get_self_link' ) ) {
/** /**
* Check if a site supports the block editor. * Returns the link for the currently displayed feed.
* *
* @return boolean True if the site supports the block editor, false otherwise. * @return string Correct link for the atom:self element.
*/ */
function site_supports_blocks() { function get_self_link() {
if ( \version_compare( \get_bloginfo( 'version' ), '5.9', '<' ) ) { $host = wp_parse_url( home_url() );
return false; $path = isset( $_SERVER['REQUEST_URI'] ) ? sanitize_text_field( wp_unslash( $_SERVER['REQUEST_URI'] ) ) : '';
return esc_url( apply_filters( 'self_link', set_url_scheme( 'http://' . $host['host'] . $path ) ) );
} }
if ( ! \function_exists( 'register_block_type_from_metadata' ) ) {
return false;
* Allow plugins to disable block editor support,
* thus disabling blocks registered by the ActivityPub plugin.
* @param boolean $supports_blocks True if the site supports the block editor, false otherwise.
return apply_filters( 'activitypub_site_supports_blocks', true );
* Check if data is valid JSON.
* @param string $data The data to check.
* @return boolean True if the data is JSON, false otherwise.
function is_json( $data ) {
return \is_array( \json_decode( $data, true ) ) ? true : false;
* Check if a blog is public based on the `blog_public` option
* @return bollean True if public, false if not
function is_blog_public() {
return (bool) apply_filters( 'activitypub_is_blog_public', \get_option( 'blog_public', 1 ) );
* Get active users based on a given duration
* @param int $duration The duration to check in month(s)
* @return int The number of active users
function get_active_users( $duration = 1 ) {
$duration = intval( $duration );
$transient_key = sprintf( 'monthly_active_users_%d', $duration );
$count = get_transient( $transient_key );
if ( false === $count ) {
global $wpdb;
$query = "SELECT COUNT( DISTINCT post_author ) FROM {$wpdb->posts} WHERE post_type = 'post' AND post_status = 'publish' AND post_date <= DATE_SUB( NOW(), INTERVAL %d MONTH )";
$query = $wpdb->prepare( $query, $duration );
$count = $wpdb->get_var( $query ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
set_transient( $transient_key, $count, DAY_IN_SECONDS );
// if 0 authors where active
if ( 0 === $count ) {
return 0;
// if single user mode
if ( is_single_user() ) {
return 1;
// if blog user is disabled
if ( is_user_disabled( Users::BLOG_USER_ID ) ) {
return $count;
// also count blog user
return $count + 1;
* Get the total number of users
* @return int The total number of users
function get_total_users() {
// if single user mode
if ( is_single_user() ) {
return 1;
$users = \get_users(
'capability__in' => array( 'publish_posts' ),
if ( is_array( $users ) ) {
$users = count( $users );
} else {
$users = 1;
// if blog user is disabled
if ( is_user_disabled( Users::BLOG_USER_ID ) ) {
return $users;
return $users + 1;
} }

View file

@ -11,7 +11,7 @@
'<dd>' . \wp_kses( __( 'The post\'s title.', 'activitypub' ), array( 'code' => array() ) ) . '</dd>' . '<dd>' . \wp_kses( __( 'The post\'s title.', 'activitypub' ), array( 'code' => array() ) ) . '</dd>' .
'<dt><code>[ap_content apply_filters="yes"]</code></dt>' . '<dt><code>[ap_content apply_filters="yes"]</code></dt>' .
'<dd>' . \wp_kses( __( 'The post\'s content. With <code>apply_filters</code> you can decide if filters (<code>apply_filters( \'the_content\', $content )</code>) should be applied or not (default is <code>yes</code>). The values can be <code>yes</code> or <code>no</code>. <code>apply_filters</code> attribute is optional.', 'activitypub' ), array( 'code' => array() ) ) . '</dd>' . '<dd>' . \wp_kses( __( 'The post\'s content. With <code>apply_filters</code> you can decide if filters (<code>apply_filters( \'the_content\', $content )</code>) should be applied or not (default is <code>yes</code>). The values can be <code>yes</code> or <code>no</code>. <code>apply_filters</code> attribute is optional.', 'activitypub' ), array( 'code' => array() ) ) . '</dd>' .
'<dt><code>[ap_excerpt length="400"]</code></dt>' . '<dt><code>[ap_excerpt lenght="400"]</code></dt>' .
'<dd>' . \wp_kses( __( 'The post\'s excerpt (default 400 chars). <code>length</code> attribute is optional.', 'activitypub' ), array( 'code' => array() ) ) . '</dd>' . '<dd>' . \wp_kses( __( 'The post\'s excerpt (default 400 chars). <code>length</code> attribute is optional.', 'activitypub' ), array( 'code' => array() ) ) . '</dd>' .
'<dt><code>[ap_permalink type="url"]</code></dt>' . '<dt><code>[ap_permalink type="url"]</code></dt>' .
'<dd>' . \wp_kses( __( 'The post\'s permalink. <code>type</code> can be either: <code>url</code> or <code>html</code> (an &lt;a /&gt; tag). <code>type</code> attribute is optional.', 'activitypub' ), array( 'code' => array() ) ) . '</dd>' . '<dd>' . \wp_kses( __( 'The post\'s permalink. <code>type</code> can be either: <code>url</code> or <code>html</code> (an &lt;a /&gt; tag). <code>type</code> attribute is optional.', 'activitypub' ), array( 'code' => array() ) ) . '</dd>' .

View file

@ -22,13 +22,6 @@ class Application_User extends Blog_User {
*/ */
protected $type = 'Application'; protected $type = 'Application';
* If the User is discoverable.
* @var boolean
protected $discoverable = false;
/** /**
* Get the User-Url. * Get the User-Url.
* *
@ -42,10 +35,58 @@ class Application_User extends Blog_User {
return 'application'; return 'application';
} }
public function get_preferred_username() { public function get_username() {
return $this::get_name(); return $this::get_name();
} }
public function get__public_key() {
$key = \get_option( 'activitypub_application_user_public_key' );
if ( $key ) {
return $key;
$key = \get_option( 'activitypub_application_user_public_key' );
return $key;
* @param int $user_id
* @return mixed
public function get__private_key() {
$key = \get_option( 'activitypub_application_user_private_key' );
if ( $key ) {
return $key;
return \get_option( 'activitypub_application_user_private_key' );
private function generate_key_pair() {
$key_pair = Signature::generate_key_pair();
if ( ! is_wp_error( $key_pair ) ) {
\update_option( 'activitypub_application_user_public_key', $key_pair['public_key'] );
\update_option( 'activitypub_application_user_private_key', $key_pair['private_key'] );
public function get_inbox() {
return null;
public function get_outbox() {
return null;
public function get_followers() { public function get_followers() {
return null; return null;
} }
@ -55,18 +96,6 @@ class Application_User extends Blog_User {
} }
public function get_attachment() { public function get_attachment() {
return null; return array();
public function get_featured() {
return null;
public function get_moderators() {
return null;
public function get_indexable() {
return false;
} }
} }

@ -7,7 +7,6 @@ use Activitypub\Collection\Users;
use function Activitypub\is_single_user; use function Activitypub\is_single_user;
use function Activitypub\is_user_disabled; use function Activitypub\is_user_disabled;
use function Activitypub\get_rest_url_by_path;
class Blog_User extends User { class Blog_User extends User {
/** /**
@ -22,7 +21,7 @@ class Blog_User extends User {
* *
* @var string * @var string
*/ */
protected $type = null; protected $type = 'Group';
/** /**
* Is Account discoverable? * Is Account discoverable?
@ -46,34 +45,13 @@ class Blog_User extends User {
return $object; return $object;
} }
* Get the type of the object.
* If the Blog is in "single user" mode, return "Person" insted of "Group".
* @return string The type of the object.
public function get_type() {
if ( is_single_user() ) {
return 'Person';
} else {
return 'Group';
/** /**
* Get the User-Name. * Get the User-Name.
* *
* @return string The User-Name. * @return string The User-Name.
*/ */
public function get_name() { public function get_name() {
return \wp_strip_all_tags( return \esc_html( \get_bloginfo( 'name' ) );
\get_bloginfo( 'name' ),
} }
/** /**
@ -99,15 +77,6 @@ class Blog_User extends User {
return \esc_url( \trailingslashit( get_home_url() ) . '@' . $this->get_preferred_username() ); return \esc_url( \trailingslashit( get_home_url() ) . '@' . $this->get_preferred_username() );
} }
* Returns the User-URL with @-Prefix for the username.
* @return string The User-URL with @-Prefix for the username.
public function get_at_url() {
return \esc_url( \trailingslashit( get_home_url() ) . '@' . $this->get_preferred_username() );
/** /**
* Generate a default Username. * Generate a default Username.
* *
@ -144,37 +113,21 @@ class Blog_User extends User {
/** /**
* Get the User-Icon. * Get the User-Icon.
* *
* @return array The User-Icon. * @return array|null The User-Icon.
*/ */
public function get_icon() { public function get_icon() {
// try site icon first $image = wp_get_attachment_image_src( get_theme_mod( 'custom_logo' ) );
$icon_id = get_option( 'site_icon' );
// try custom logo second
if ( ! $icon_id ) {
$icon_id = get_theme_mod( 'custom_logo' );
$icon_url = false;
if ( $icon_id ) {
$icon = wp_get_attachment_image_src( $icon_id, 'full' );
if ( $icon ) {
$icon_url = $icon[0];
if ( ! $icon_url ) {
// fallback to default icon
$icon_url = plugins_url( '/assets/img/wp-logo.png', ACTIVITYPUB_PLUGIN_FILE );
if ( $image ) {
return array( return array(
'type' => 'Image', 'type' => 'Image',
'url' => esc_url( $icon_url ), 'url' => esc_url( $image[0] ),
); );
} }
return null;
/** /**
* Get the User-Header-Image. * Get the User-Header-Image.
* *
@ -209,6 +162,48 @@ class Blog_User extends User {
return \gmdate( 'Y-m-d\TH:i:s\Z', $time ); return \gmdate( 'Y-m-d\TH:i:s\Z', $time );
} }
public function get__public_key() {
$key = \get_option( 'activitypub_blog_user_public_key' );
if ( $key ) {
return $key;
$key = \get_option( 'activitypub_blog_user_public_key' );
return $key;
* Get the User-Private-Key.
* @param int $user_id
* @return mixed
public function get__private_key() {
$key = \get_option( 'activitypub_blog_user_private_key' );
if ( $key ) {
return $key;
return \get_option( 'activitypub_blog_user_private_key' );
private function generate_key_pair() {
$key_pair = Signature::generate_key_pair();
if ( ! is_wp_error( $key_pair ) ) {
\update_option( 'activitypub_blog_user_public_key', $key_pair['public_key'] );
\update_option( 'activitypub_blog_user_private_key', $key_pair['private_key'] );
public function get_attachment() { public function get_attachment() {
return array(); return array();
} }
@ -217,27 +212,18 @@ class Blog_User extends User {
return \home_url(); return \home_url();
} }
public function get_moderators() { /**
if ( is_single_user() || 'Group' !== $this->get_type() ) { * Get the type of the object.
return null; *
} * If the Blog is in "single user" mode, return "Person" insted of "Group".
return get_rest_url_by_path( 'collections/moderators' ); * @return string The type of the object.
} */
public function get_type() {
public function get_attributed_to() { if ( is_single_user() ) {
if ( is_single_user() || 'Group' !== $this->get_type() ) { return 'Person';
return null; } else {
} return $this->type;
return get_rest_url_by_path( 'collections/moderators' );
public function get_posting_restricted_to_mods() {
if ( 'Group' === $this->get_type() ) {
return true;
return null;
} }
} }

@ -1,7 +1,6 @@
<?php <?php
namespace Activitypub\Model; namespace Activitypub\Model;
use WP_Error;
use WP_Query; use WP_Query;
use Activitypub\Activity\Actor; use Activitypub\Activity\Actor;
use Activitypub\Collection\Followers; use Activitypub\Collection\Followers;
@ -111,40 +110,12 @@ class Follower extends Actor {
$this->save(); $this->save();
} }
* Validate the current Follower-Object.
* @return boolean True if the verification was successful.
public function is_valid() {
// the minimum required attributes
$required_attributes = array(
foreach ( $required_attributes as $attribute ) {
if ( ! $this->get( $attribute ) ) {
return false;
return true;
/** /**
* Save the current Follower-Object. * Save the current Follower-Object.
* *
* @return int|WP_Error The Post-ID or an WP_Error. * @return void
*/ */
public function save() { public function save() {
if ( ! $this->is_valid() ) {
return new WP_Error( 'activitypub_invalid_follower', __( 'Invalid Follower', 'activitypub' ), array( 'status' => 400 ) );
if ( ! $this->get__id() ) { if ( ! $this->get__id() ) {
global $wpdb; global $wpdb;
@ -176,17 +147,15 @@ class Follower extends Actor {
@ -176,17 +147,15 @@ class Follower extends Actor {
$this->_id = $post_id; $this->_id = $post_id;
return $post_id;
} }
/** /**
* Upsert the current Follower-Object. * Upsert the current Follower-Object.
* *
* @return int|WP_Error The Post-ID or an WP_Error. * @return void
*/ */
public function upsert() { public function upsert() {
return $this->save(); $this->save();
} }
/** /**
@ -315,7 +284,7 @@ class Follower extends Actor {
$object->set_id( $post->guid ); $object->set_id( $post->guid );
$object->set_name( $post->post_title ); $object->set_name( $post->post_title );
$object->set_summary( $post->post_excerpt ); $object->set_summary( $post->post_excerpt );
$object->set_published( gmdate( 'Y-m-d H:i:s', strtotime( $post->post_date ) ) ); $object->set_published( gmdate( 'Y-m-d H:i:s', strtotime( $post->post_published ) ) );
$object->set_updated( gmdate( 'Y-m-d H:i:s', strtotime( $post->post_modified ) ) ); $object->set_updated( gmdate( 'Y-m-d H:i:s', strtotime( $post->post_modified ) ) );
return $object; return $object;

@ -1,7 +1,7 @@
<?php <?php
namespace Activitypub\Model; namespace Activitypub\Model;
use Activitypub\Transformer\Post as Transformer_Post; use Activitypub\Transformer\Post as Post_Transformer;
/** /**
* ActivityPub Post Class * ActivityPub Post Class
@ -34,8 +34,7 @@ class Post {
_deprecated_function( __CLASS__, '1.0.0', '\Activitypub\Transformer\Post' ); _deprecated_function( __CLASS__, '1.0.0', '\Activitypub\Transformer\Post' );
$this->post = $post; $this->post = $post;
$transformer = new Transformer_Post(); $this->object = Post_Transformer::transform( $post )->to_object();
$this->object = $transformer->set_wp_post( $post )->to_object();
} }
/** /**

@ -18,24 +18,6 @@ class Actor {
*/ */
protected $_id; // phpcs:ignore PSR2.Classes.PropertyDeclaration.Underscore protected $_id; // phpcs:ignore PSR2.Classes.PropertyDeclaration.Underscore
* The Featured-Posts.
* @see
* @var string
protected $featured;
* Moderators endpoint.
* @see
* @var string
protected $moderators;
/** /**
* The User-Type * The User-Type
* *
@ -43,38 +25,6 @@ class User extends Actor {
*/ */
protected $type = 'Person'; protected $type = 'Person';
* If the User is discoverable.
* @see
* @var boolean
protected $discoverable = true;
* If the User is indexable.
* @var boolean
protected $indexable;
* The WebFinger Resource.
* @var string<url>
protected $resource;
* Restrict posting to mods
* @see
* @var boolean
protected $posting_restricted_to_mods = null;
public static function from_wp_user( $user_id ) { public static function from_wp_user( $user_id ) {
if ( is_user_disabled( $user_id ) ) { if ( is_user_disabled( $user_id ) ) {
return new WP_Error( return new WP_Error(
@ -130,11 +80,6 @@ class User extends Actor {
return \esc_url( \get_author_posts_url( $this->_id ) ); return \esc_url( \get_author_posts_url( $this->_id ) );
} }
* Returns the User-URL with @-Prefix for the username.
* @return string The User-URL with @-Prefix for the username.
public function get_at_url() { public function get_at_url() {
return \esc_url( \trailingslashit( get_home_url() ) . '@' . $this->get_username() ); return \esc_url( \trailingslashit( get_home_url() ) . '@' . $this->get_username() );
} }
@ -177,10 +122,53 @@ class User extends Actor {
return array( return array(
'id' => $this->get_id() . '#main-key', 'id' => $this->get_id() . '#main-key',
'owner' => $this->get_id(), 'owner' => $this->get_id(),
'publicKeyPem' => Signature::get_public_key_for( $this->get__id() ), 'publicKeyPem' => $this->get__public_key(),
); );
} }
* @param int $this->get__id()
* @return mixed
public function get__public_key() {
$key = \get_user_meta( $this->get__id(), 'magic_sig_public_key', true );
if ( $key ) {
return $key;
return \get_user_meta( $this->get__id(), 'magic_sig_public_key', true );
* @param int $this->get__id()
* @return mixed
public function get__private_key() {
$key = \get_user_meta( $this->get__id(), 'magic_sig_private_key', true );
if ( $key ) {
return $key;
return \get_user_meta( $this->get__id(), 'magic_sig_private_key', true );
private function generate_key_pair() {
$key_pair = Signature::generate_key_pair();
if ( ! is_wp_error( $key_pair ) ) {
\update_user_meta( $this->get__id(), 'magic_sig_public_key', $key_pair['public_key'], true );
\update_user_meta( $this->get__id(), 'magic_sig_private_key', $key_pair['private_key'], true );
/** /**
* Returns the Inbox-API-Endpoint. * Returns the Inbox-API-Endpoint.
* *
@ -217,15 +205,6 @@ class User extends Actor {
return get_rest_url_by_path( sprintf( 'users/%d/following', $this->get__id() ) ); return get_rest_url_by_path( sprintf( 'users/%d/following', $this->get__id() ) );
} }
* Returns the Featured-API-Endpoint.
* @return string The Featured-Endpoint.
public function get_featured() {
return get_rest_url_by_path( sprintf( 'users/%d/collections/featured', $this->get__id() ) );
/** /**
* Extend the User-Output with Attachments. * Extend the User-Output with Attachments.
* *
@ -269,11 +248,6 @@ class User extends Actor {
return $array; return $array;
} }
* Returns a user@domain type of identifier for the user.
* @return string The Webfinger-Identifier.
public function get_resource() { public function get_resource() {
return $this->get_preferred_username() . '@' . \wp_parse_url( \home_url(), \PHP_URL_HOST ); return $this->get_preferred_username() . '@' . \wp_parse_url( \home_url(), \PHP_URL_HOST );
} }
@ -281,20 +255,4 @@ class User extends Actor {
public function get_canonical_url() { public function get_canonical_url() {
return $this->get_url(); return $this->get_url();
} }
public function get_streams() {
return null;
public function get_tag() {
return array();
public function get_indexable() {
if ( \get_option( 'blog_public', 1 ) ) {
return true;
} else {
return false;
} }

@ -1,222 +0,0 @@
namespace Activitypub\Rest;
use WP_Error;
use WP_REST_Server;
use WP_REST_Response;
use Activitypub\Transformer\Transformers_Manager;
use Activitypub\Activity\Activity;
use Activitypub\Collection\Users as User_Collection;
use function Activitypub\esc_hashtag;
use function Activitypub\is_single_user;
use function Activitypub\get_rest_url_by_path;
* ActivityPub Collections REST-Class
* @author Matthias Pfefferle
* @see
* @see
class Collection {
* Initialize the class, registering WordPress hooks
public static function init() {
* Register routes
public static function register_routes() {
'methods' => WP_REST_Server::READABLE,
'callback' => array( self::class, 'tags_get' ),
'args' => self::request_parameters(),
'permission_callback' => '__return_true',
'methods' => WP_REST_Server::READABLE,
'callback' => array( self::class, 'featured_get' ),
'args' => self::request_parameters(),
'permission_callback' => '__return_true',
'methods' => WP_REST_Server::READABLE,
'callback' => array( self::class, 'moderators_get' ),
'permission_callback' => '__return_true',
* The Featured Tags endpoint
* @param WP_REST_Request $request The request object.
* @return WP_REST_Response The response object.
public static function tags_get( $request ) {
$user_id = $request->get_param( 'user_id' );
$user = User_Collection::get_by_various( $user_id );
if ( is_wp_error( $user ) ) {
return $user;
$number = 4;
$tags = \get_terms(
'taxonomy' => 'post_tag',
'orderby' => 'count',
'order' => 'DESC',
'number' => $number,
if ( is_wp_error( $tags ) ) {
$tags = array();
$response = array(
'@context' => Activity::CONTEXT,
'id' => get_rest_url_by_path( sprintf( 'users/%d/collections/tags', $user->get__id() ) ),
'type' => 'Collection',
'totalItems' => is_countable( $tags ) ? count( $tags ) : 0,
'items' => array(),
foreach ( $tags as $tag ) {
$response['items'][] = array(
'type' => 'Hashtag',
'href' => \esc_url( \get_tag_link( $tag ) ),
'name' => esc_hashtag( $tag->name ),
$rest_response = new WP_REST_Response( $response, 200 );
$rest_response->header( 'Content-Type', 'application/activity+json; charset=' . get_option( 'blog_charset' ) );
return $rest_response;
* Featured posts endpoint
* @param WP_REST_Request $request The request object.
* @return WP_REST_Response The response object.
public static function featured_get( $request ) {
$user_id = $request->get_param( 'user_id' );
$user = User_Collection::get_by_various( $user_id );
if ( is_wp_error( $user ) ) {
return $user;
$sticky_posts = \get_option( 'sticky_posts' );
if ( ! is_single_user() && User_Collection::BLOG_USER_ID === $user->get__id() ) {
$posts = array();
} elseif ( $sticky_posts ) {
$args = array(
'post__in' => $sticky_posts,
'ignore_sticky_posts' => 1,
'orderby' => 'date',
'order' => 'DESC',
if ( $user->get__id() > 0 ) {
$args['author'] = $user->get__id();
$posts = \get_posts( $args );
} else {
$posts = array();
$response = array(
'@context' => Activity::CONTEXT,
'id' => get_rest_url_by_path( sprintf( 'users/%d/collections/featured', $user_id ) ),
'type' => 'OrderedCollection',
'totalItems' => is_countable( $posts ) ? count( $posts ) : 0,
'orderedItems' => array(),
foreach ( $posts as $post ) {
$response['orderedItems'][] = Transformers_Manager::instance()->get_transformer( $post )->to_object()->to_array();
$rest_response = new WP_REST_Response( $response, 200 );
$rest_response->header( 'Content-Type', 'application/activity+json; charset=' . get_option( 'blog_charset' ) );
return $rest_response;
* Moderators endpoint
* @param WP_REST_Request $request The request object.
* @return WP_REST_Response The response object.
public static function moderators_get( $request ) {
$response = array(
'@context' => Activity::CONTEXT,
'id' => get_rest_url_by_path( 'collections/moderators' ),
'type' => 'OrderedCollection',
'orderedItems' => array(),
$users = User_Collection::get_collection();
foreach ( $users as $user ) {
$response['orderedItems'][] = $user->get_url();
$rest_response = new WP_REST_Response( $response, 200 );
$rest_response->header( 'Content-Type', 'application/activity+json; charset=' . get_option( 'blog_charset' ) );
return $rest_response;
* The supported parameters
* @return array list of parameters
public static function request_parameters() {
$params = array();
$params['user_id'] = array(
'required' => true,
'type' => 'string',
return $params;

@ -5,6 +5,7 @@ use WP_Error;
use stdClass; use stdClass;
use WP_REST_Server; use WP_REST_Server;
use WP_REST_Response; use WP_REST_Response;
use Activitypub\Validator\Query;
use Activitypub\Collection\Users as User_Collection; use Activitypub\Collection\Users as User_Collection;
use Activitypub\Collection\Followers as Follower_Collection; use Activitypub\Collection\Followers as Follower_Collection;
@ -22,7 +23,7 @@ class Followers {
* Initialize the class, registering WordPress hooks * Initialize the class, registering WordPress hooks
*/ */
public static function init() { public static function init() {
self::register_routes(); \add_action( 'rest_api_init', array( self::class, 'register_routes' ) );
} }
/** /**
@ -36,7 +37,7 @@ class Followers {
array( array(
'methods' => WP_REST_Server::READABLE, 'methods' => WP_REST_Server::READABLE,
'callback' => array( self::class, 'get' ), 'callback' => array( self::class, 'get' ),
'args' => self::request_parameters(), 'args' => Query::get_default_args(),
'permission_callback' => '__return_true', 'permission_callback' => '__return_true',
), ),
) )
@ -103,47 +104,9 @@ class Followers {
@ -103,47 +104,9 @@ class Followers {
); );
$rest_response = new WP_REST_Response( $json, 200 ); $response = new WP_REST_Response( $json, 200 );
$rest_response->header( 'Content-Type', 'application/activity+json; charset=' . get_option( 'blog_charset' ) ); $response->header( 'Content-Type', 'application/activity+json' );
return $rest_response; return $response;
* The supported parameters
* @return array list of parameters
public static function request_parameters() {
$params = array();
$params['page'] = array(
'type' => 'integer',
'default' => 1,
$params['per_page'] = array(
'type' => 'integer',
'default' => 20,
$params['order'] = array(
'type' => 'string',
'default' => 'desc',
'enum' => array( 'asc', 'desc' ),
$params['user_id'] = array(
'required' => true,
'type' => 'string',
$params['context'] = array(
'type' => 'string',
'default' => 'simple',
'enum' => array( 'simple', 'full' ),
return $params;
} }
} }

@ -1,10 +1,9 @@
<?php <?php
namespace Activitypub\Rest; namespace Activitypub\Rest;
use WP_REST_Response; use Activitypub\Validator\Query;
use Activitypub\Collection\Users as User_Collection; use Activitypub\Collection\Users as User_Collection;
use function Activitypub\is_single_user;
use function Activitypub\get_rest_url_by_path; use function Activitypub\get_rest_url_by_path;
/** /**
@ -19,9 +18,7 @@ class Following {
* Initialize the class, registering WordPress hooks * Initialize the class, registering WordPress hooks
*/ */
public static function init() { public static function init() {
self::register_routes(); \add_action( 'rest_api_init', array( self::class, 'register_routes' ) );
\add_filter( 'activitypub_rest_following', array( self::class, 'default_following' ), 10, 2 );
} }
/** /**
@ -35,7 +32,7 @@ class Following {
array( array(
'methods' => \WP_REST_Server::READABLE, 'methods' => \WP_REST_Server::READABLE,
'callback' => array( self::class, 'get' ), 'callback' => array( self::class, 'get' ),
'args' => self::request_parameters(), 'args' => Query::get_default_args(),
'permission_callback' => '__return_true', 'permission_callback' => '__return_true',
), ),
) )
@ -72,60 +69,14 @@ class Following {
$json->type = 'OrderedCollectionPage'; $json->type = 'OrderedCollectionPage';
$json->partOf = get_rest_url_by_path( sprintf( 'users/%d/following', $user->get__id() ) ); // phpcs:ignore $json->partOf = get_rest_url_by_path( sprintf( 'users/%d/following', $user->get__id() ) ); // phpcs:ignore
$json->totalItems = 0; // phpcs:ignore
$items = apply_filters( 'activitypub_rest_following', array(), $user ); // phpcs:ignore $json->orderedItems = apply_filters( 'activitypub_following', array(), $user ); // phpcs:ignore
$json->totalItems = is_countable( $items ) ? count( $items ) : 0; // phpcs:ignore
$json->orderedItems = $items; // phpcs:ignore
$json->first = $json->partOf; // phpcs:ignore $json->first = $json->partOf; // phpcs:ignore
$rest_response = new WP_REST_Response( $json, 200 ); $response = new \WP_REST_Response( $json, 200 );
$rest_response->header( 'Content-Type', 'application/activity+json; charset=' . get_option( 'blog_charset' ) ); $response->header( 'Content-Type', 'application/activity+json' );
return $rest_response; return $response;
* The supported parameters
* @return array list of parameters
public static function request_parameters() {
$params = array();
$params['page'] = array(
'type' => 'integer',
$params['user_id'] = array(
'required' => true,
'type' => 'string',
return $params;
* Add the Blog Authors to the following list of the Blog Actor
* if Blog not in single mode.
* @param array $array The array of following urls.
* @param User $user The user object.
* @return array The array of following urls.
public static function default_following( $array, $user ) {
if ( 0 !== $user->get__id() || is_single_user() ) {
return $array;
$users = User_Collection::get_collection();
foreach ( $users as $user ) {
$array[] = $user->get_url();
return $array;
} }
} }

@ -4,6 +4,7 @@ namespace Activitypub\Rest;
use WP_Error; use WP_Error;
use WP_REST_Server; use WP_REST_Server;
use WP_REST_Response; use WP_REST_Response;
use Activitypub\Validator\Query;
use Activitypub\Activity\Activity; use Activitypub\Activity\Activity;
use Activitypub\Collection\Users as User_Collection; use Activitypub\Collection\Users as User_Collection;
@ -24,7 +25,7 @@ class Inbox {
@ -24,7 +25,7 @@ class Inbox {
*/ */
public static function init() { public static function init() {
self::register_routes(); \add_action( 'rest_api_init', array( self::class, 'register_routes' ) );
\add_action( 'activitypub_inbox_create', array( self::class, 'handle_create' ), 10, 2 ); \add_action( 'activitypub_inbox_create', array( self::class, 'handle_create' ), 10, 2 );
} }
@ -38,7 +39,7 @@ class Inbox {
'/inbox', '/inbox',
array( array(
array( array(
'methods' => WP_REST_Server::CREATABLE, 'methods' => WP_REST_Server::EDITABLE,
'callback' => array( self::class, 'shared_inbox_post' ), 'callback' => array( self::class, 'shared_inbox_post' ),
'args' => self::shared_inbox_post_parameters(), 'args' => self::shared_inbox_post_parameters(),
@ -51,7 +52,7 @@ class Inbox {
@ -51,7 +52,7 @@ class Inbox {
'/users/(?P<user_id>[\w\-\.]+)/inbox', '/users/(?P<user_id>[\w\-\.]+)/inbox',
array( array(
array( array(
'methods' => WP_REST_Server::CREATABLE, 'methods' => WP_REST_Server::EDITABLE,
'callback' => array( self::class, 'user_inbox_post' ), 'callback' => array( self::class, 'user_inbox_post' ),
'args' => self::user_inbox_post_parameters(), 'args' => self::user_inbox_post_parameters(),
'permission_callback' => '__return_true', 'permission_callback' => '__return_true',
@ -59,7 +60,7 @@ class Inbox {
array( array(
'methods' => WP_REST_Server::READABLE, 'methods' => WP_REST_Server::READABLE,
'callback' => array( self::class, 'user_inbox_get' ), 'callback' => array( self::class, 'user_inbox_get' ),
'args' => self::user_inbox_get_parameters(), 'args' => Query::get_default_args(),
'permission_callback' => '__return_true', 'permission_callback' => '__return_true',
), ),
) )
@ -102,17 +103,18 @@ class Inbox {
$json->first = $json->partOf; // phpcs:ignore $json->first = $json->partOf; // phpcs:ignore
// filter output // filter output
$json = \apply_filters( 'activitypub_rest_inbox_array', $json ); $json = \apply_filters( 'activitypub_inbox_array', $json );
/* /*
* Action triggerd after the ActivityPub profile has been created and sent to the client * Action triggerd after the ActivityPub profile has been created and sent to the client
*/ */
\do_action( 'activitypub_inbox_post' ); \do_action( 'activitypub_inbox_post' );
$rest_response = new WP_REST_Response( $json, 200 ); $response = new WP_REST_Response( $json, 200 );
$rest_response->header( 'Content-Type', 'application/activity+json; charset=' . get_option( 'blog_charset' ) );
return $rest_response; $response->header( 'Content-Type', 'application/activity+json' );
return $response;
} }
/** /**
@ -130,17 +132,14 @@ class Inbox {
return $user; return $user;
} }
$data = $request->get_json_params(); $data = $request->get_params();
$type = $request->get_param( 'type' ); $type = $request->get_param( 'type' );
$type = \strtolower( $type ); $type = \strtolower( $type );
\do_action( 'activitypub_inbox', $data, $user->get__id(), $type ); \do_action( 'activitypub_inbox', $data, $user->get__id(), $type );
\do_action( "activitypub_inbox_{$type}", $data, $user->get__id() ); \do_action( "activitypub_inbox_{$type}", $data, $user->get__id() );
$rest_response = new WP_REST_Response( array(), 202 ); return new WP_REST_Response( array(), 202 );
$rest_response->header( 'Content-Type', 'application/activity+json; charset=' . get_option( 'blog_charset' ) );
return $rest_response;
} }
/** /**
@ -151,7 +150,7 @@ class Inbox {
* @return WP_REST_Response * @return WP_REST_Response
*/ */
public static function shared_inbox_post( $request ) { public static function shared_inbox_post( $request ) {
$data = $request->get_json_params(); $data = $request->get_params();
$type = $request->get_param( 'type' ); $type = $request->get_param( 'type' );
$users = self::extract_recipients( $data ); $users = self::extract_recipients( $data );
@ -160,7 +159,7 @@ class Inbox {
'rest_invalid_param', 'rest_invalid_param',
\__( 'No recipients found', 'activitypub' ), \__( 'No recipients found', 'activitypub' ),
array( array(
'status' => 400, 'status' => 404,
'params' => array( 'params' => array(
'to' => \__( 'Please check/validate "to" field', 'activitypub' ), 'to' => \__( 'Please check/validate "to" field', 'activitypub' ),
'bto' => \__( 'Please check/validate "bto" field', 'activitypub' ), 'bto' => \__( 'Please check/validate "bto" field', 'activitypub' ),
@ -173,42 +172,13 @@ class Inbox {
} }
foreach ( $users as $user ) { foreach ( $users as $user ) {
$user = User_Collection::get_by_various( $user );
if ( is_wp_error( $user ) ) {
$type = \strtolower( $type ); $type = \strtolower( $type );
\do_action( 'activitypub_inbox', $data, $user->ID, $type ); \do_action( 'activitypub_inbox', $data, $user->ID, $type );
\do_action( "activitypub_inbox_{$type}", $data, $user->ID ); \do_action( "activitypub_inbox_{$type}", $data, $user->ID );
} }
$rest_response = new WP_REST_Response( array(), 202 ); return new WP_REST_Response( array(), 202 );
$rest_response->header( 'Content-Type', 'application/activity+json; charset=' . get_option( 'blog_charset' ) );
return $rest_response;
* The supported parameters
* @return array list of parameters
public static function user_inbox_get_parameters() {
$params = array();
$params['page'] = array(
'type' => 'integer',
$params['user_id'] = array(
'required' => true,
'type' => 'string',
return $params;
} }
/** /**
@ -236,12 +206,8 @@ class Inbox {
$params['actor'] = array( $params['actor'] = array(
'required' => true, 'required' => true,
'sanitize_callback' => function( $param, $request, $key ) { 'sanitize_callback' => function( $param, $request, $key ) {
if ( \is_array( $param ) ) { if ( ! \is_string( $param ) ) {
if ( isset( $param['id'] ) ) {
$param = $param['id']; $param = $param['id'];
} else {
$param = $param['url'];
} }
return \esc_url_raw( $param ); return \esc_url_raw( $param );
}, },
@ -340,6 +306,53 @@ class Inbox {
return $params; return $params;
} }
* Handles "Reaction" requests
* @param array $object The activity-object
* @param int $user_id The id of the local blog-user
public static function handle_reaction( $object, $user_id ) {
$meta = get_remote_metadata_by_actor( $object['actor'] );
$comment_post_id = \url_to_postid( $object['object'] );
// save only replys and reactions
if ( ! $comment_post_id ) {
return false;
$commentdata = array(
'comment_post_ID' => $comment_post_id,
'comment_author' => \esc_attr( $meta['name'] ),
'comment_author_email' => '',
'comment_author_url' => \esc_url_raw( $object['actor'] ),
'comment_content' => \esc_url_raw( $object['actor'] ),
'comment_type' => \esc_attr( \strtolower( $object['type'] ) ),
'comment_parent' => 0,
'comment_meta' => array(
'source_url' => \esc_url_raw( $object['id'] ),
'avatar_url' => \esc_url_raw( $meta['icon']['url'] ),
'protocol' => 'activitypub',
// disable flood control
\remove_action( 'check_comment_flood', 'check_comment_flood_db', 10 );
// do not require email for AP entries
\add_filter( 'pre_option_require_name_email', '__return_false' );
$state = \wp_new_comment( $commentdata, true );
\remove_filter( 'pre_option_require_name_email', '__return_false' );
// re-add flood control
\add_action( 'check_comment_flood', 'check_comment_flood_db', 10, 4 );
do_action( 'activitypub_handled_reaction', $object, $user_id, $state, $commentdata );
/** /**
@ -370,7 +383,7 @@ class Inbox {
* *
@ -370,7 +383,7 @@ class Inbox {
'comment_post_ID' => $comment_post_id, 'comment_post_ID' => $comment_post_id,
'comment_author' => \esc_attr( $meta['name'] ), 'comment_author' => \esc_attr( $meta['name'] ),
'comment_author_url' => \esc_url_raw( $object['actor'] ), 'comment_author_url' => \esc_url_raw( $object['actor'] ),
'comment_content' => addslashes( \wp_kses( $object['object']['content'], 'pre_comment_content' ) ), 'comment_content' => \wp_filter_kses( $object['object']['content'] ),
'comment_type' => 'comment', 'comment_type' => 'comment',
'comment_author_email' => '', 'comment_author_email' => '',
'comment_parent' => 0, 'comment_parent' => 0,
@ -387,19 +400,8 @@ class Inbox {
// do not require email for AP entries // do not require email for AP entries
\add_filter( 'pre_option_require_name_email', '__return_false' ); \add_filter( 'pre_option_require_name_email', '__return_false' );
// No nonce possible for this submission route
function() {
return 'inactive';
\add_filter( 'wp_kses_allowed_html', array( self::class, 'allowed_comment_html' ), 10, 2 );
$state = \wp_new_comment( $commentdata, true ); $state = \wp_new_comment( $commentdata, true );
\remove_filter( 'wp_kses_allowed_html', array( self::class, 'allowed_comment_html' ) );
\remove_filter( 'pre_option_require_name_email', '__return_false' ); \remove_filter( 'pre_option_require_name_email', '__return_false' );
// re-add flood control // re-add flood control
@ -428,7 +430,7 @@ class Inbox {
$recipient_items = array_merge( $recipient_items, $recipient ); $recipient_items = array_merge( $recipient_items, $recipient );
} }
if ( is_array( $data['object'] ) && array_key_exists( $i, $data['object'] ) ) { if ( array_key_exists( $i, $data['object'] ) ) {
if ( is_array( $data['object'][ $i ] ) ) { if ( is_array( $data['object'][ $i ] ) ) {
$recipient = $data['object'][ $i ]; $recipient = $data['object'][ $i ];
} else { } else {
@ -490,29 +492,4 @@ class Inbox {
return in_array( '', $recipients, true ); return in_array( '', $recipients, true );
} }
* Adds line breaks to the list of allowed comment tags.
* @param array $allowedtags Allowed HTML tags.
* @param string $context Context.
* @return array Filtered tag list.
public static function allowed_comment_html( $allowedtags, $context = '' ) {
if ( 'pre_comment_content' !== $context ) {
// Do nothing.
return $allowedtags;
// Add `p` and `br` to the list of allowed tags.
if ( ! array_key_exists( 'br', $allowedtags ) ) {
$allowedtags['br'] = array();
if ( ! array_key_exists( 'p', $allowedtags ) ) {
$allowedtags['p'] = array();
return $allowedtags;
} }

@ -3,8 +3,6 @@ namespace Activitypub\Rest;
use WP_REST_Response; use WP_REST_Response;
use function Activitypub\get_total_users;
use function Activitypub\get_active_users;
use function Activitypub\get_rest_url_by_path; use function Activitypub\get_rest_url_by_path;
/** /**
@ -19,7 +17,9 @@ class Nodeinfo {
* Initialize the class, registering WordPress hooks * Initialize the class, registering WordPress hooks
*/ */
public static function init() { public static function init() {
self::register_routes(); \add_action( 'rest_api_init', array( self::class, 'register_routes' ) );
\add_filter( 'nodeinfo_data', array( self::class, 'add_nodeinfo_discovery' ), 10, 2 );
\add_filter( 'nodeinfo2_data', array( self::class, 'add_nodeinfo2_discovery' ), 10 );
} }
/** /**
@ -84,14 +84,24 @@ class Nodeinfo {
'version' => \get_bloginfo( 'version' ), 'version' => \get_bloginfo( 'version' ),
); );
$users = \get_users(
'capability__in' => array( 'publish_posts' ),
if ( is_array( $users ) ) {
$users = count( $users );
} else {
$users = 1;
$posts = \wp_count_posts(); $posts = \wp_count_posts();
$comments = \wp_count_comments(); $comments = \wp_count_comments();
$nodeinfo['usage'] = array( $nodeinfo['usage'] = array(
'users' => array( 'users' => array(
'total' => get_total_users(), 'total' => $users,
'activeMonth' => get_active_users( '1 month ago' ),
'activeHalfyear' => get_active_users( '6 month ago' ),
), ),
'localPosts' => (int) $posts->publish, 'localPosts' => (int) $posts->publish,
'localComments' => (int) $comments->approved, 'localComments' => (int) $comments->approved,
@ -131,14 +141,24 @@ class Nodeinfo {
'version' => \get_bloginfo( 'version' ), 'version' => \get_bloginfo( 'version' ),
); );
$users = \get_users(
'capability__in' => array( 'publish_posts' ),
if ( is_array( $users ) ) {
$users = count( $users );
} else {
$users = 1;
$posts = \wp_count_posts(); $posts = \wp_count_posts();
$comments = \wp_count_comments(); $comments = \wp_count_comments();
$nodeinfo['usage'] = array( $nodeinfo['usage'] = array(
'users' => array( 'users' => array(
'total' => get_total_users(), 'total' => (int) $users,
'activeMonth' => get_active_users( 1 ),
'activeHalfyear' => get_active_users( 6 ),
), ),
'localPosts' => (int) $posts->publish, 'localPosts' => (int) $posts->publish,
'localComments' => (int) $comments->approved, 'localComments' => (int) $comments->approved,
@ -173,4 +193,36 @@ class Nodeinfo {
return new \WP_REST_Response( $discovery, 200 ); return new \WP_REST_Response( $discovery, 200 );
} }
* Extend NodeInfo data
* @param array $nodeinfo NodeInfo data
* @param string The NodeInfo Version
* @return array The extended array
public static function add_nodeinfo_discovery( $nodeinfo, $version ) {
if ( '2.0' === $version ) {
$nodeinfo['protocols'][] = 'activitypub';
} else {
$nodeinfo['protocols']['inbound'][] = 'activitypub';
$nodeinfo['protocols']['outbound'][] = 'activitypub';
return $nodeinfo;
* Extend NodeInfo2 data
* @param array $nodeinfo NodeInfo2 data
* @return array The extended array
public static function add_nodeinfo2_discovery( $nodeinfo ) {
$nodeinfo['protocols'][] = 'activitypub';
return $nodeinfo;
} }

namespace Activitypub\Rest;
* ActivityPub OStatus REST-Class
* @author Matthias Pfefferle
* @see
class Ostatus {
* Register routes
public static function register_routes() {
'methods' => \WP_REST_Server::READABLE,
'callback' => array( '\Activitypub\Rest\Ostatus', 'get' ),
// 'args' => self::request_parameters(),
'permission_callback' => '__return_true',
public static function get() {
// @todo implement

@ -5,7 +5,8 @@ use stdClass;
use WP_Error; use WP_Error;
use WP_REST_Server; use WP_REST_Server;
use WP_REST_Response; use WP_REST_Response;
use Activitypub\Transformer\Transformers_Manager; use Activitypub\Validator\Query;
use Activitypub\Transformer\Post;
use Activitypub\Activity\Activity; use Activitypub\Activity\Activity;
use Activitypub\Collection\Users as User_Collection; use Activitypub\Collection\Users as User_Collection;
@ -24,7 +25,7 @@ class Outbox {
* Initialize the class, registering WordPress hooks * Initialize the class, registering WordPress hooks
*/ */
public static function init() { public static function init() {
self::register_routes(); \add_action( 'rest_api_init', array( self::class, 'register_routes' ) );
} }
/** /**
@ -38,7 +39,7 @@ class Outbox {
array( array(
'methods' => WP_REST_Server::READABLE, 'methods' => WP_REST_Server::READABLE,
'callback' => array( self::class, 'user_outbox_get' ), 'callback' => array( self::class, 'user_outbox_get' ),
'args' => self::request_parameters(), 'args' => Query::get_default_args(),
'permission_callback' => '__return_true', 'permission_callback' => '__return_true',
), ),
) )
@ -59,7 +60,7 @@ class Outbox {
return $user; return $user;
} }
$post_types = array_keys( \get_option( 'activitypub_transformer_mapping', array( 'post' => 'activitypub/default', 'page' => 'activitypub/default' ) ) ); $post_types = \get_option( 'activitypub_support_post_types', array( 'post', 'page' ) );
$page = $request->get_param( 'page', 1 ); $page = $request->get_param( 'page', 1 );
@ -105,8 +106,7 @@ class Outbox {
); );
foreach ( $posts as $post ) { foreach ( $posts as $post ) {
$transformer = \Activitypub\Transformer\Transformers_Manager::instance()->get_transformer( $post ); $post = Post::transform( $post )->to_object();
$post = $transformer->to_object();
$activity = new Activity(); $activity = new Activity();
$activity->set_type( 'Create' ); $activity->set_type( 'Create' );
$activity->set_context( null ); $activity->set_context( null );
@ -117,37 +117,17 @@ class Outbox {
} }
// filter output // filter output
$json = \apply_filters( 'activitypub_rest_outbox_array', $json ); $json = \apply_filters( 'activitypub_outbox_array', $json );
/* /*
* Action triggerd after the ActivityPub profile has been created and sent to the client * Action triggerd after the ActivityPub profile has been created and sent to the client
*/ */
\do_action( 'activitypub_outbox_post' ); \do_action( 'activitypub_outbox_post' );
$rest_response = new WP_REST_Response( $json, 200 ); $response = new WP_REST_Response( $json, 200 );
$rest_response->header( 'Content-Type', 'application/activity+json; charset=' . get_option( 'blog_charset' ) );
return $rest_response; $response->header( 'Content-Type', 'application/activity+json' );
/** return $response;
* The supported parameters
* @return array list of parameters
public static function request_parameters() {
$params = array();
$params['page'] = array(
'type' => 'integer',
'default' => 1,
$params['user_id'] = array(
'required' => true,
'type' => 'string',
return $params;
} }
} }

@ -2,7 +2,6 @@
namespace Activitypub\Rest; namespace Activitypub\Rest;
use stdClass; use stdClass;
use WP_Error;
use WP_REST_Response; use WP_REST_Response;
use Activitypub\Signature; use Activitypub\Signature;
use Activitypub\Model\Application_User; use Activitypub\Model\Application_User;
@ -19,8 +18,7 @@ class Server {
* Initialize the class, registering WordPress hooks * Initialize the class, registering WordPress hooks
*/ */
public static function init() { public static function init() {
self::register_routes(); \add_action( 'rest_api_init', array( self::class, 'register_routes' ) );
\add_filter( 'rest_request_before_callbacks', array( self::class, 'authorize_activitypub_requests' ), 10, 3 ); \add_filter( 'rest_request_before_callbacks', array( self::class, 'authorize_activitypub_requests' ), 10, 3 );
} }
@ -48,17 +46,13 @@ class Server {
*/ */
public static function application_actor() { public static function application_actor() {
$user = new Application_User(); $user = new Application_User();
$json = $user->to_array(); $json = $user->to_array();
$rest_response = new WP_REST_Response( $json, 200 ); $response = new WP_REST_Response( $json, 200 );
$rest_response->header( 'Content-Type', 'application/activity+json; charset=' . get_option( 'blog_charset' ) );
return $rest_response; $response->header( 'Content-Type', 'application/activity+json' );
return $response;
} }
/** /**
@ -74,49 +68,28 @@ class Server {
* @return mixed|WP_Error The response, error, or modified response. * @return mixed|WP_Error The response, error, or modified response.
*/ */
public static function authorize_activitypub_requests( $response, $handler, $request ) { public static function authorize_activitypub_requests( $response, $handler, $request ) {
if ( 'HEAD' === $request->get_method() ) {
return $response;
$route = $request->get_route(); $route = $request->get_route();
// check if it is an activitypub request and exclude webfinger and nodeinfo endpoints // check if it is an activitypub request and exclude webfinger and nodeinfo endpoints
if ( if (
! \str_starts_with( $route, '/' . ACTIVITYPUB_REST_NAMESPACE ) || ! str_starts_with( $route, '/' . ACTIVITYPUB_REST_NAMESPACE ) ||
\str_starts_with( $route, '/' . \trailingslashit( ACTIVITYPUB_REST_NAMESPACE ) . 'webfinger' ) || str_starts_with( $route, '/' . \trailingslashit( ACTIVITYPUB_REST_NAMESPACE ) . 'webfinger' ) ||
\str_starts_with( $route, '/' . \trailingslashit( ACTIVITYPUB_REST_NAMESPACE ) . 'nodeinfo' ) str_starts_with( $route, '/' . \trailingslashit( ACTIVITYPUB_REST_NAMESPACE ) . 'nodeinfo' )
) { ) {
return $response; return $response;
} }
* Filter to defer signature verification
* Skip signature verification for debugging purposes or to reduce load for
* certain Activity-Types, like "Delete".
* @param bool $defer Whether to defer signature verification.
* @param WP_REST_Request $request The request used to generate the response.
* @return bool Whether to defer signature verification.
$defer = \apply_filters( 'activitypub_defer_signature_verification', false, $request );
if ( $defer ) {
return $response;
// POST-Requets are always signed // POST-Requets are always signed
if ( 'GET' !== $request->get_method() ) { if ( 'POST' === $request->get_method() ) {
$verified_request = Signature::verify_http_signature( $request ); $verified_request = Signature::verify_http_signature( $request );
if ( \is_wp_error( $verified_request ) ) { if ( \is_wp_error( $verified_request ) ) {
return new WP_Error( 'activitypub_signature_verification', $verified_request->get_error_message(), array( 'status' => 401 ) ); return $verified_request;
} }
} elseif ( 'GET' === $request->get_method() ) { // GET-Requests are only signed in secure mode } elseif ( 'GET' === $request->get_method() ) { // GET-Requests are only signed in secure mode
$verified_request = Signature::verify_http_signature( $request ); $verified_request = Signature::verify_http_signature( $request );
if ( \is_wp_error( $verified_request ) ) { if ( \is_wp_error( $verified_request ) ) {
return new WP_Error( 'activitypub_signature_verification', $verified_request->get_error_message(), array( 'status' => 401 ) ); return $verified_request;
} }
} }
} }

@ -3,9 +3,8 @@ namespace Activitypub\Rest;
use WP_Error; use WP_Error;
use WP_REST_Server; use WP_REST_Server;
use WP_REST_Request;
use WP_REST_Response; use WP_REST_Response;
use Activitypub\Webfinger; use Activitypub\Validator\Query;
use Activitypub\Activity\Activity; use Activitypub\Activity\Activity;
use Activitypub\Collection\Users as User_Collection; use Activitypub\Collection\Users as User_Collection;
@ -23,7 +22,7 @@ class Users {
* Initialize the class, registering WordPress hooks * Initialize the class, registering WordPress hooks
*/ */
public static function init() { public static function init() {
self::register_routes(); \add_action( 'rest_api_init', array( self::class, 'register_routes' ) );
} }
/** /**
@ -37,26 +36,7 @@ class Users {
array( array(
'methods' => WP_REST_Server::READABLE, 'methods' => WP_REST_Server::READABLE,
'callback' => array( self::class, 'get' ), 'callback' => array( self::class, 'get' ),
'args' => self::request_parameters(), 'args' => Query::get_default_args(),
'permission_callback' => '__return_true',
'methods' => WP_REST_Server::READABLE,
'callback' => array( self::class, 'remote_follow_get' ),
'args' => array(
'resource' => array(
'required' => true,
'sanitize_callback' => 'sanitize_text_field',
'permission_callback' => '__return_true', 'permission_callback' => '__return_true',
), ),
@ -95,61 +75,9 @@ class Users {
$json = $user->to_array(); $json = $user->to_array();
$rest_response = new WP_REST_Response( $json, 200 ); $response = new WP_REST_Response( $json, 200 );
$rest_response->header( 'Content-Type', 'application/activity+json; charset=' . get_option( 'blog_charset' ) ); $response->header( 'Content-Type', 'application/activity+json' );
return $rest_response; return $response;
* Endpoint for remote follow UI/Block
* @param WP_REST_Request $request The request object.
* @return void|string The URL to the remote follow page
public static function remote_follow_get( WP_REST_Request $request ) {
$resource = $request->get_param( 'resource' );
$user_id = $request->get_param( 'user_id' );
$user = User_Collection::get_by_various( $user_id );
if ( is_wp_error( $user ) ) {
return $user;
$template = Webfinger::get_remote_follow_endpoint( $resource );
if ( is_wp_error( $template ) ) {
return $template;
$resource = $user->get_resource();
$url = str_replace( '{uri}', $resource, $template );
return new WP_REST_Response(
array( 'url' => $url ),
* The supported parameters
* @return array list of parameters
public static function request_parameters() {
$params = array();
$params['page'] = array(
'type' => 'string',
$params['user_id'] = array(
'required' => true,
'type' => 'string',
return $params;
} }
} }

@ -19,7 +19,9 @@ class Webfinger {
* @return void * @return void
*/ */
public static function init() { public static function init() {
self::register_routes(); \add_action( 'rest_api_init', array( self::class, 'register_routes' ) );
\add_filter( 'webfinger_user_data', array( self::class, 'add_user_discovery' ), 10, 3 );
\add_filter( 'webfinger_data', array( self::class, 'add_pseudo_user_discovery' ), 99, 2 );
} }
/** /**
@ -35,7 +37,7 @@ class Webfinger {
array( array(
'methods' => \WP_REST_Server::READABLE, 'methods' => \WP_REST_Server::READABLE,
'callback' => array( self::class, 'webfinger' ), 'callback' => array( self::class, 'webfinger' ),
'args' => self::request_parameters(), 'args' => self::request_args(),
'permission_callback' => '__return_true', 'permission_callback' => '__return_true',
), ),
) )
@ -66,16 +68,54 @@ class Webfinger {
* *
* @return array list of parameters * @return array list of parameters
*/ */
public static function request_parameters() { public static function request_args() {
$params = array(); $args = array();
$params['resource'] = array( $args['resource'] = array(
'required' => true, 'required' => true,
'type' => 'string', 'type' => 'string',
'pattern' => '^acct:(.+)@(.+)$', 'pattern' => '^acct:(.+)@(.+)$',
); );
return $params; return $args;
* Add WebFinger discovery links
* @param array $array the jrd array
* @param string $resource the WebFinger resource
* @param WP_User $user the WordPress user
* @return array the jrd array
public static function add_user_discovery( $array, $resource, $user ) {
$user = User_Collection::get_by_id( $user->ID );
$array['links'][] = array(
'rel' => 'self',
'type' => 'application/activity+json',
'href' => $user->get_url(),
return $array;
* Add WebFinger discovery links
* @param array $array the jrd array
* @param string $resource the WebFinger resource
* @param WP_User $user the WordPress user
* @return array the jrd array
public static function add_pseudo_user_discovery( $array, $resource ) {
if ( $array ) {
return $array;
return self::get_profile( $resource );
} }
View file

@ -32,22 +32,17 @@ class Followers extends WP_List_Table {
return array( return array(
'cb' => '<input type="checkbox" />', 'cb' => '<input type="checkbox" />',
'avatar' => \__( 'Avatar', 'activitypub' ), 'avatar' => \__( 'Avatar', 'activitypub' ),
'post_title' => \__( 'Name', 'activitypub' ), 'name' => \__( 'Name', 'activitypub' ),
'username' => \__( 'Username', 'activitypub' ), 'username' => \__( 'Username', 'activitypub' ),
'url' => \__( 'URL', 'activitypub' ), 'url' => \__( 'URL', 'activitypub' ),
'published' => \__( 'Followed', 'activitypub' ), 'updated' => \__( 'Last updated', 'activitypub' ),
'modified' => \__( 'Last updated', 'activitypub' ), //'errors' => \__( 'Errors', 'activitypub' ),
//'latest-error' => \__( 'Latest Error Message', 'activitypub' ),
); );
} }
public function get_sortable_columns() { public function get_sortable_columns() {
$sortable_columns = array( return array();
'post_title' => array( 'post_title', true ),
'modified' => array( 'modified', false ),
'published' => array( 'published', false ),
return $sortable_columns;
} }
public function prepare_items() { public function prepare_items() {
@ -60,32 +55,8 @@ class Followers extends WP_List_Table {
$page_num = $this->get_pagenum(); $page_num = $this->get_pagenum();
$per_page = 20; $per_page = 20;
$args = array(); $followers = FollowerCollection::get_followers( $this->user_id, $per_page, $page_num );
$counter = FollowerCollection::count_followers( $this->user_id );
// phpcs:ignore WordPress.Security.NonceVerification.Recommended
if ( isset( $_GET['orderby'] ) ) {
// phpcs:ignore WordPress.Security.NonceVerification.Recommended
$args['orderby'] = sanitize_text_field( wp_unslash( $_GET['orderby'] ) );
// phpcs:ignore WordPress.Security.NonceVerification.Recommended
if ( isset( $_GET['order'] ) ) {
// phpcs:ignore WordPress.Security.NonceVerification.Recommended
$args['order'] = sanitize_text_field( wp_unslash( $_GET['order'] ) );
// phpcs:ignore WordPress.Security.NonceVerification.Recommended
if ( isset( $_GET['s'] ) && isset( $_REQUEST['_wpnonce'] ) ) {
$nonce = sanitize_text_field( wp_unslash( $_REQUEST['_wpnonce'] ) );
if ( wp_verify_nonce( $nonce, 'bulk-' . $this->_args['plural'] ) ) {
// phpcs:ignore WordPress.Security.NonceVerification.Recommended
$args['s'] = sanitize_text_field( wp_unslash( $_GET['s'] ) );
$followers_with_count = FollowerCollection::get_followers_with_count( $this->user_id, $per_page, $page_num, $args );
$followers = $followers_with_count['followers'];
$counter = $followers_with_count['total'];
$this->items = array(); $this->items = array();
$this->set_pagination_args( $this->set_pagination_args(
@ -99,12 +70,13 @@ class Followers extends WP_List_Table {
foreach ( $followers as $follower ) { foreach ( $followers as $follower ) {
$item = array( $item = array(
'icon' => esc_attr( $follower->get_icon_url() ), 'icon' => esc_attr( $follower->get_icon_url() ),
'post_title' => esc_attr( $follower->get_name() ), 'name' => esc_attr( $follower->get_name() ),
'username' => esc_attr( $follower->get_preferred_username() ), 'username' => esc_attr( $follower->get_preferred_username() ),
'url' => esc_attr( $follower->get_url() ), 'url' => esc_attr( $follower->get_url() ),
'identifier' => esc_attr( $follower->get_id() ), 'identifier' => esc_attr( $follower->get_id() ),
'published' => esc_attr( $follower->get_published() ), 'updated' => esc_attr( $follower->get_updated() ),
'modified' => esc_attr( $follower->get_updated() ), 'errors' => $follower->count_errors(),
'latest-error' => $follower->get_latest_error_message(),
); );
$this->items[] = $item; $this->items[] = $item;
@ -144,11 +116,11 @@ class Followers extends WP_List_Table {
} }
public function process_action() { public function process_action() {
if ( ! isset( $_REQUEST['followers'] ) || ! isset( $_REQUEST['_wpnonce'] ) ) { if ( ! isset( $_REQUEST['followers'] ) || ! isset( $_REQUEST['_apnonce'] ) ) {
return false; return false;
} }
$nonce = sanitize_text_field( wp_unslash( $_REQUEST['_wpnonce'] ) ); $nonce = sanitize_text_field( wp_unslash( $_REQUEST['_apnonce'] ) );
if ( ! wp_verify_nonce( $nonce, 'bulk-' . $this->_args['plural'] ) ) { if ( ! wp_verify_nonce( $nonce, 'activitypub-followers-list' ) ) {
return false; return false;
} }

View file

@ -1,619 +0,0 @@
* Inspired by the PHP ActivityPub Library by @Landrok
* @link
namespace Activitypub\Transformer;
use WP_Post;
use Activitypub\Collection\Users;
use Activitypub\Model\Blog_User;
use Activitypub\Activity\Base_Object;
use Activitypub\Shortcodes;
use function Activitypub\esc_hashtag;
use function Activitypub\is_single_user;
return esc_html__( 'Unknown', 'activitypub' );
* Return whether the transformer supports a post type.
* @since version_number_transformer_management_placeholder
* @return string post_type Post type name.
final public function supports_post_type( $post_type ) {
return in_array( $post_type, $this->get_supported_post_types(), true );
* Get the name used for registering the transformer with the ActivityPub plugin.
* @since version_number_transformer_management_placeholder
* @return string name
abstract public function get_name();
* Get the display name for the ActivityPub transformer.
* @since version_number_transformer_management_placeholder
* @return string display name
abstract public function get_label();
* Returns the ActivityStreams 2.0 Object-Type for a Post.
* @see
* @return string The Object-Type.
abstract protected function get_object_type();
* Returns the content for the ActivityPub Item.
* The content will be generated based on the user settings.
* @return string The content.
protected function get_content() {
global $post;
* Provides an action hook so plugins can add their own hooks/filters before AP content is generated.
* Example: if a plugin adds a filter to `the_content` to add a button to the end of posts, it can also remove that filter here.
* @param WP_Post $post The post object.
do_action( 'activitypub_before_get_content', $post );
// phpcs:ignore WordPress.WP.GlobalVariablesOverride.Prohibited
$post = $this->wp_post;
$content = $this->get_post_content_template();
// Register our shortcodes just in time.
// Fill in the shortcodes.
setup_postdata( $post );
$content = do_shortcode( $content );
$content = \wpautop( $content );
$content = \preg_replace( '/[\n\r\t]/', '', $content );
$content = \trim( $content );
$content = \apply_filters( 'activitypub_the_content', $content, $post );
// Don't need these any more, should never appear in a post.
return $content;
* Gets the template to use to generate the content of the activitypub item.
* @return string The Template.
protected function get_post_content_template() {
if ( 'excerpt' === \get_option( 'activitypub_post_content_type', 'content' ) ) {
return "[ap_excerpt]\n\n[ap_permalink type=\"html\"]";
if ( 'title' === \get_option( 'activitypub_post_content_type', 'content' ) ) {
return "[ap_title]\n\n[ap_permalink type=\"html\"]";
if ( 'content' === \get_option( 'activitypub_post_content_type', 'content' ) ) {
return "[ap_content]\n\n[ap_permalink type=\"html\"]\n\n[ap_hashtags]";
return \get_option( 'activitypub_custom_post_content', ACTIVITYPUB_CUSTOM_POST_CONTENT );
* @return string The Posts ID.
public function get_id() {
* Returns the URL of the Post.
* @return string The Posts URL.
public function get_url() {
$post = $this->wp_post;
if ( 'trash' === get_post_status( $post ) ) {
$permalink = \get_post_meta( $post->ID, 'activitypub_canonical_url', true );
} else {
$permalink = \get_permalink( $post );
return \esc_url( $permalink );
* Returns the User-URL of the Author of the Post.
* If `single_user` mode is enabled, the URL of the Blog-User is returned.
* @return string The User-URL.
protected function get_attributed_to() {
if ( is_single_user() ) {
$user = new Blog_User();
return $user->get_url();
return Users::get_by_id( $this->wp_post->post_author )->get_url();
* Generates all Media Attachments for a Post.
* @return array The Attachments.
protected function get_attachments() {
// Once upon a time we only supported images, but we now support audio/video as well.
// We maintain the image-centric naming for backwards compatibility.
$max_media = intval( \apply_filters( 'activitypub_max_image_attachments', \get_option( 'activitypub_max_image_attachments', ACTIVITYPUB_MAX_IMAGE_ATTACHMENTS ) ) );
if ( site_supports_blocks() && \has_blocks( $this->wp_post->post_content ) ) {
return $this->get_block_attachments( $max_media );
return $this->get_classic_editor_images( $max_media );
* Get media attachments from blocks. They will be formatted as ActivityPub attachments, not as WP attachments.
* @param int $max_media The maximum number of attachments to return.
* @return array The attachments.
protected function get_block_attachments( $max_media ) {
// max media can't be negative or zero
return array();
$id = $this->wp_post->ID;
$media_ids = array();
// list post thumbnail first if this post has one
if ( \function_exists( 'has_post_thumbnail' ) && \has_post_thumbnail( $id ) ) {
$media_ids[] = \get_post_thumbnail_id( $id );
if ( $max_media > 0 ) {
$blocks = \parse_blocks( $this->wp_post->post_content );
$media_ids = self::get_media_ids_from_blocks( $blocks, $media_ids, $max_media );
return \array_filter( \array_map( array( self::class, 'wp_attachment_to_activity_attachment' ), $media_ids ) );
* Get image attachments from the classic editor.
* Note that audio/video attachments are only supported in the block editor.
* @param int $max_images The maximum number of images to return.
* @return array The attachments.
protected function get_classic_editor_images( $max_images ) {
// max images can't be negative or zero
if ( $max_images <= 0 ) {
return array();
$id = $this->wp_post->ID;
$image_ids = array();
// list post thumbnail first if this post has one
if ( \function_exists( 'has_post_thumbnail' ) && \has_post_thumbnail( $id ) ) {
$image_ids[] = \get_post_thumbnail_id( $id );
if ( $max_images > 0 ) {
$query = new \WP_Query(
'post_parent' => $id,
'post_status' => 'inherit',
'post_type' => 'attachment',
'post_mime_type' => 'image',
'order' => 'ASC',
'orderby' => 'menu_order ID',
'posts_per_page' => $max_images,
foreach ( $query->get_posts() as $attachment ) {
if ( ! \in_array( $attachment->ID, $image_ids, true ) ) {
$image_ids[] = $attachment->ID;
$image_ids = \array_unique( $image_ids );
return \array_filter( \array_map( array( self::class, 'wp_attachment_to_activity_attachment' ), $image_ids ) );
* Recursively get media IDs from blocks.
* @param array $blocks The blocks to search for media IDs
* @param array $media_ids The media IDs to append new IDs to
* @param int $max_media The maximum number of media to return.
* @return array The image IDs.
protected static function get_media_ids_from_blocks( $blocks, $media_ids, $max_media ) {
foreach ( $blocks as $block ) {
// recurse into inner blocks
if ( ! empty( $block['innerBlocks'] ) ) {
$media_ids = self::get_media_ids_from_blocks( $block['innerBlocks'], $media_ids, $max_media );
switch ( $block['blockName'] ) {
case 'core/image':
case 'core/cover':
case 'core/audio':
case 'core/video':
case 'videopress/video':
if ( ! empty( $block['attrs']['id'] ) ) {
$media_ids[] = $block['attrs']['id'];
case 'jetpack/slideshow':
case 'jetpack/tiled-gallery':
if ( ! empty( $block['attrs']['ids'] ) ) {
$media_ids = array_merge( $media_ids, $block['attrs']['ids'] );
case 'jetpack/image-compare':
if ( ! empty( $block['attrs']['beforeImageId'] ) ) {
$media_ids[] = $block['attrs']['beforeImageId'];
if ( ! empty( $block['attrs']['afterImageId'] ) ) {
$media_ids[] = $block['attrs']['afterImageId'];
// depupe
$media_ids = \array_unique( $media_ids );
// stop doing unneeded work
if ( count( $media_ids ) >= $max_media ) {
// still need to slice it because one gallery could knock us over the limit
return array_slice( $media_ids, 0, $max_media );
* Converts a WordPress Attachment to an ActivityPub Attachment.
* @param int $id The Attachment ID.
* @return array The ActivityPub Attachment.
public static function wp_attachment_to_activity_attachment( $id ) {
$attachment = array();
$mime_type = \get_post_mime_type( $id );
$mime_type_parts = \explode( '/', $mime_type );
// switching on image/audio/video
switch ( $mime_type_parts[0] ) {
case 'image':
$image_size = 'full';
* Filter the image URL returned for each post.
* @param array|false $thumbnail The image URL, or false if no image is available.
* @param int $id The attachment ID.
* @param string $image_size The image size to retrieve. Set to 'full' by default.
$thumbnail = apply_filters(
self::get_image( $id, $image_size ),
if ( $thumbnail ) {
$alt = \get_post_meta( $id, '_wp_attachment_image_alt', true );
$image = array(
'type' => 'Image',
'url' => $thumbnail[0],
'mediaType' => $mime_type,
if ( $alt ) {
$image['name'] = $alt;
$attachment = $image;
case 'audio':
case 'video':
$attachment = array(
'type' => 'Document',
'mediaType' => $mime_type,
'url' => \wp_get_attachment_url( $id ),
'name' => \get_the_title( $id ),
$meta = wp_get_attachment_metadata( $id );
// height and width for videos
if ( isset( $meta['width'] ) && isset( $meta['height'] ) ) {
$attachment['width'] = $meta['width'];
$attachment['height'] = $meta['height'];
// @todo: add `icon` support for audio/video attachments. Maybe use post thumbnail?
return \apply_filters( 'activitypub_attachment', $attachment, $id );
* Return details about an image attachment.
* @param int $id The attachment ID.
* @param string $image_size The image size to retrieve. Set to 'full' by default.
* @return array|false Array of image data, or boolean false if no image is available.
protected static function get_image( $id, $image_size = 'full' ) {
* Hook into the image retrieval process. Before image retrieval.
* @param int $id The attachment ID.
* @param string $image_size The image size to retrieve. Set to 'full' by default.
do_action( 'activitypub_get_image_pre', $id, $image_size );
$image = \wp_get_attachment_image_src( $id, $image_size );
* Hook into the image retrieval process. After image retrieval.
* @param int $id The attachment ID.
* @param string $image_size The image size to retrieve. Set to 'full' by default.
do_action( 'activitypub_get_image_post', $id, $image_size );
* @return array The list of @-Mentions.
protected function get_mentions() {
return apply_filters( 'activitypub_extract_mentions', array(), $this->wp_post->post_content, $this->wp_post );
* Returns a list of Mentions, used in the Post.
* @see
* @return array The list of Mentions.
protected function get_cc() {
$cc = array();
$mentions = $this->get_mentions();
if ( $mentions ) {
foreach ( $mentions as $url ) {
$cc[] = $url;
return $cc;
* Returns a list of Tags, used in the Post.
* This includes Hash-Tags and Mentions.
* @return array The list of Tags.
protected function get_tags() {
$tags = array();
$post_tags = \get_the_tags( $this->wp_post->ID );
if ( $post_tags ) {
foreach ( $post_tags as $post_tag ) {
$tag = array(
'type' => 'Hashtag',
'href' => \esc_url( \get_tag_link( $post_tag->term_id ) ),
'name' => esc_hashtag( $post_tag->name ),
$tags[] = $tag;
$mentions = $this->get_mentions();
if ( $mentions ) {
foreach ( $mentions as $mention => $url ) {
$tag = array(
'type' => 'Mention',
'href' => \esc_url( $url ),
'name' => \esc_html( $mention ),
$tags[] = $tag;
return $tags;
* Returns the locale of the post.
* @return string The locale of the post.
public function get_locale() {
$post_id = $this->wp_post->ID;
$lang = \strtolower( \strtok( \get_locale(), '_-' ) );
* Filter the locale of the post.
* @param string $lang The locale of the post.
* @param int $post_id The post ID.
* @param WP_Post $post The post object.
* @return string The filtered locale of the post.
return apply_filters( 'activitypub_post_locale', $lang, $post_id, $this->wp_post );
* Gets the contentMap
* @see
* @return array the contenmap
protected function get_content_map() {
return array(
$this->get_locale() => $this->get_content(),
* Transforms the WP_Post object to an ActivityPub Object
* @see \Activitypub\Activity\Base_Object
* @return \Activitypub\Activity\Base_Object The ActivityPub Object
public function to_object() {
$wp_post = $this->wp_post;
$object = new Base_Object();
$object->set_id( $this->get_id() );
$object->set_url( $this->get_url() );
$object->set_type( $this->get_object_type() );
$published = \strtotime( $wp_post->post_date_gmt );
$object->set_published( \gmdate( 'Y-m-d\TH:i:s\Z', $published ) );
$updated = \strtotime( $wp_post->post_modified_gmt );
if ( $updated > $published ) {
$object->set_updated( \gmdate( 'Y-m-d\TH:i:s\Z', $updated ) );
$object->set_attributed_to( $this->get_attributed_to() );
$object->set_content( $this->get_content() );
$object->set_content_map( $this->get_content_map );
$path = sprintf( 'users/%d/followers', intval( $wp_post->post_author ) );
get_rest_url_by_path( $path ),
$object->set_cc( $this->get_cc() );
$object->set_attachment( $this->get_attachments() );
$object->set_tag( $this->get_tags() );
@ -5,39 +5,278 @@ use WP_Post;
use Activitypub\Collection\Users; use Activitypub\Collection\Users;
use Activitypub\Model\Blog_User; use Activitypub\Model\Blog_User;
use Activitypub\Activity\Base_Object; use Activitypub\Activity\Base_Object;
use Activitypub\Shortcodes;
use Activitypub\Transformer\Base;
use function Activitypub\esc_hashtag;
use function Activitypub\is_single_user; use function Activitypub\is_single_user;
use function Activitypub\get_rest_url_by_path; use function Activitypub\get_rest_url_by_path;
use function Activitypub\site_supports_blocks;
/** /**
* WordPress Post Transformer * WordPress Post Transformer
* The Post Transformer is responsible for transforming a WP_Post object into different othe * The Post Transformer is responsible for transforming a WP_Post object into different othe
* Object-Types. * Object-Types.
* *
* Currently supported are: * Currently supported are:
* - Activitypub\Activity\Base_Object * - Activitypub\Activity\Base_Object
*/ */
class Post extends Base { class Post {
/** /**
* Getter function for the name of the transformer. * The WP_Post object.
* *
* @return string name * @var WP_Post
*/ */
public function get_name() { protected $wp_post;
return 'activitypub/default';
* The Allowed Tags, used in the content.
* @var array
protected $allowed_tags = array(
'a' => array(
'href' => array(),
'title' => array(),
'class' => array(),
'rel' => array(),
'br' => array(),
'p' => array(
'class' => array(),
'span' => array(
'class' => array(),
'div' => array(
'class' => array(),
'ul' => array(),
'ol' => array(
'reversed' => array(),
'start' => array(),
'li' => array(
'value' => array(),
'strong' => array(
'class' => array(),
'b' => array(
'class' => array(),
'i' => array(
'class' => array(),
'em' => array(
'class' => array(),
'blockquote' => array(),
'cite' => array(),
'code' => array(
'class' => array(),
'pre' => array(
'class' => array(),
* Static function to Transform a WP_Post Object.
* This helps to chain the output of the Transformer.
* @param WP_Post $wp_post The WP_Post object
* @return void
public static function transform( WP_Post $wp_post ) {
return new static( $wp_post );
} }
/** /**
* Getter function for the display name (label/title) of the transformer.
* *
* @return string name *
* @param WP_Post $wp_post
*/ */
public function get_label() { public function __construct( WP_Post $wp_post ) {
return 'Built-In'; $this->wp_post = $wp_post;
* Transforms the WP_Post object to an ActivityPub Object
* @see \Activitypub\Activity\Base_Object
* @return \Activitypub\Activity\Base_Object The ActivityPub Object
public function to_object() {
$wp_post = $this->wp_post;
$object = new Base_Object();
$object->set_id( \esc_url( \get_permalink( $wp_post->ID ) ) );
$object->set_url( \esc_url( \get_permalink( $wp_post->ID ) ) );
$object->set_type( $this->get_object_type() );
$published = \strtotime( $wp_post->post_date_gmt );
$object->set_published( \gmdate( 'Y-m-d\TH:i:s\Z', $published ) );
$updated = \strtotime( $wp_post->post_modified_gmt );
if ( $updated > $published ) {
$object->set_updated( \gmdate( 'Y-m-d\TH:i:s\Z', $updated ) );
$object->set_attributed_to( $this->get_attributed_to() );
$object->set_content( $this->get_content() );
\strstr( \get_locale(), '_', true ) => $this->get_content(),
$path = sprintf( 'users/%d/followers', intval( $wp_post->post_author ) );
get_rest_url_by_path( $path ),
$object->set_cc( $this->get_cc() );
$object->set_attachment( $this->get_attachments() );
$object->set_tag( $this->get_tags() );
return $object;
* Returns the User-URL of the Author of the Post.
* If `single_user` mode is enabled, the URL of the Blog-User is returned.
* @return string The User-URL.
protected function get_attributed_to() {
if ( is_single_user() ) {
$user = new Blog_User();
return $user->get_url();
return Users::get_by_id( $this->wp_post->post_author )->get_url();
* Generates all Image Attachments for a Post.
* @return array The Image Attachments.
protected function get_attachments() {
$max_images = intval( \apply_filters( 'activitypub_max_image_attachments', \get_option( 'activitypub_max_image_attachments', ACTIVITYPUB_MAX_IMAGE_ATTACHMENTS ) ) );
$images = array();
// max images can't be negative or zero
if ( $max_images <= 0 ) {
return $images;
$id = $this->wp_post->ID;
$image_ids = array();
// list post thumbnail first if this post has one
if ( \function_exists( 'has_post_thumbnail' ) && \has_post_thumbnail( $id ) ) {
$image_ids[] = \get_post_thumbnail_id( $id );
if ( $max_images > 0 ) {
// then list any image attachments
$query = new \WP_Query(
'post_parent' => $id,
'post_status' => 'inherit',
'post_type' => 'attachment',
'post_mime_type' => 'image',
'order' => 'ASC',
'orderby' => 'menu_order ID',
'posts_per_page' => $max_images,
foreach ( $query->get_posts() as $attachment ) {
if ( ! \in_array( $attachment->ID, $image_ids, true ) ) {
$image_ids[] = $attachment->ID;
$image_ids = \array_unique( $image_ids );
// get URLs for each image
foreach ( $image_ids as $id ) {
$image_size = 'full';
* Filter the image URL returned for each post.
* @param array|false $thumbnail The image URL, or false if no image is available.
* @param int $id The attachment ID.
* @param string $image_size The image size to retrieve. Set to 'full' by default.
$thumbnail = apply_filters(
$this->get_image( $id, $image_size ),
if ( $thumbnail ) {
$mimetype = \get_post_mime_type( $id );
$alt = \get_post_meta( $id, '_wp_attachment_image_alt', true );
$image = array(
'type' => 'Image',
'url' => $thumbnail[0],
'mediaType' => $mimetype,
if ( $alt ) {
$image['name'] = $alt;
$images[] = $image;
return $images;
* Return details about an image attachment.
* @param int $id The attachment ID.
* @param string $image_size The image size to retrieve. Set to 'full' by default.
* @return array|false Array of image data, or boolean false if no image is available.
protected function get_image( $id, $image_size = 'full' ) {
* Hook into the image retrieval process. Before image retrieval.
* @param int $id The attachment ID.
* @param string $image_size The image size to retrieve. Set to 'full' by default.
do_action( 'activitypub_get_image_pre', $id, $image_size );
$thumbnail = \wp_get_attachment_image_src( $id, $image_size );
* Hook into the image retrieval process. After image retrieval.
* @param int $id The attachment ID.
* @param string $image_size The image size to retrieve. Set to 'full' by default.
do_action( 'activitypub_get_image_pre', $id, $image_size );
return $thumbnail;
} }
/** /**
@ -53,8 +292,6 @@ class Post extends Base {
return \ucfirst( \get_option( 'activitypub_object_type', 'note' ) ); return \ucfirst( \get_option( 'activitypub_object_type', 'note' ) );
} }
// Default to Article.
$object_type = 'Article';
$post_type = \get_post_type( $this->wp_post ); $post_type = \get_post_type( $this->wp_post );
switch ( $post_type ) { switch ( $post_type ) {
case 'post': case 'post':
@ -106,4 +343,121 @@ class Post extends Base {
return $object_type; return $object_type;
} }
* Returns a list of Mentions, used in the Post.
* @see
* @return array The list of Mentions.
protected function get_cc() {
$cc = array();
$mentions = $this->get_mentions();
if ( $mentions ) {
foreach ( $mentions as $mention => $url ) {
$cc[] = $url;
return $cc;
* Returns a list of Tags, used in the Post.
* This includes Hash-Tags and Mentions.
* @return array The list of Tags.
protected function get_tags() {
$tags = array();
$post_tags = \get_the_tags( $this->wp_post->ID );
if ( $post_tags ) {
foreach ( $post_tags as $post_tag ) {
$tag = array(
'type' => 'Hashtag',
'href' => esc_url( \get_tag_link( $post_tag->term_id ) ),
'name' => '#' . \esc_attr( $post_tag->slug ),
$tags[] = $tag;
$mentions = $this->get_mentions();
if ( $mentions ) {
foreach ( $mentions as $mention => $url ) {
$tag = array(
'type' => 'Mention',
'href' => \esc_url( $url ),
'name' => \esc_html( $mention ),
$tags[] = $tag;
return $tags;
* Returns the content for the ActivityPub Item.
* The content will be generated based on the user settings.
* @return string The content.
protected function get_content() {
global $post;
// phpcs:ignore WordPress.WP.GlobalVariablesOverride.Prohibited
$post = $this->wp_post;
$content = $this->get_post_content_template();
// Fill in the shortcodes.
setup_postdata( $post );
$content = do_shortcode( $content );
$content = \wp_kses( $content, $this->allowed_tags );
$content = \wpautop( $content );
$content = \preg_replace( '/[\n\r\t]/', '', $content );
$content = \trim( $content );
$content = \apply_filters( 'activitypub_the_content', $content, $post );
$content = \html_entity_decode( $content, \ENT_QUOTES, 'UTF-8' );
return $content;
* Gets the template to use to generate the content of the activitypub item.
* @return string The Template.
protected function get_post_content_template() {
if ( 'excerpt' === \get_option( 'activitypub_post_content_type', 'content' ) ) {
return "[ap_excerpt]\n\n[ap_permalink type=\"html\"]";
if ( 'title' === \get_option( 'activitypub_post_content_type', 'content' ) ) {
return "[ap_title]\n\n[ap_permalink type=\"html\"]";
if ( 'content' === \get_option( 'activitypub_post_content_type', 'content' ) ) {
return "[ap_content]\n\n[ap_hashtags]\n\n[ap_permalink type=\"html\"]";
return \get_option( 'activitypub_custom_post_content', ACTIVITYPUB_CUSTOM_POST_CONTENT );
* Helper function to get the @-Mentions from the post content.
* @return array The list of @-Mentions.
protected function get_mentions() {
return apply_filters( 'activitypub_extract_mentions', array(), $this->wp_post->post_content, $this->wp_post );
} }

@ -0,0 +1,38 @@
namespace Activitypub\Validator;
class Query {
* Validate the query parameters.
* @return array A list of arguments and how to validate them.
public static function get_default_args() {
$args = array();
$args['page'] = array(
'type' => 'integer',
'default' => 1,
$args['per_page'] = array(
'type' => 'integer',
'default' => 20,
$args['order'] = array(
'type' => 'string',
'default' => 'desc',
'enum' => array( 'asc', 'desc' ),
$args['context'] = array(
'type' => 'string',
'default' => 'simple',
'enum' => array( 'simple', 'full' ),
return $args;

View file

@ -1,15 +1,7 @@
<?php <?php
namespace Activitypub\Integration; namespace Activitypub\Integration;
* Compatibility with the BuddyPress plugin
* @see
class Buddypress { class Buddypress {
* Initialize the class, registering WordPress hooks
public static function init() { public static function init() {
\add_filter( 'activitypub_json_author_array', array( self::class, 'add_user_metadata' ), 11, 2 ); \add_filter( 'activitypub_json_author_array', array( self::class, 'add_user_metadata' ), 11, 2 );
} }

View file

@ -11,8 +11,7 @@
}, },
"scripts": { "scripts": {
"dev": "wp-scripts start", "dev": "wp-scripts start",
"build": "wp-scripts build", "build": "wp-scripts build"
"readme": "grunt wp_readme_to_markdown"
}, },
"license": "MIT", "license": "MIT",
"bugs": { "bugs": {

@ -13,7 +13,6 @@
<rule ref="WordPress-Core"> <rule ref="WordPress-Core">
<exclude name="Generic.Formatting.MultipleStatementAlignment.NotSameWarning" /> <exclude name="Generic.Formatting.MultipleStatementAlignment.NotSameWarning" />
<exclude name="WordPress.Arrays.MultipleStatementAlignment.DoubleArrowNotAligned" /> <exclude name="WordPress.Arrays.MultipleStatementAlignment.DoubleArrowNotAligned" />
<exclude name="Squiz.Functions.MultiLineFunctionDeclaration.SpaceAfterFunction" />
</rule> </rule>
<rule ref="WordPress.Files.FileName"> <rule ref="WordPress.Files.FileName">
<properties> <properties>

@ -1,9 +1,9 @@
=== ActivityPub === === ActivityPub ===
Contributors: automattic, pfefferle, mediaformat, mattwiebe, akirk, jeherve, nuriapena, cavalierlife Contributors: automattic, pfefferle, mediaformat, mattwiebe, akirk, jeherve, nuriapena
Tags: OStatus, fediverse, activitypub, activitystream Tags: OStatus, fediverse, activitypub, activitystream
Requires at least: 4.7 Requires at least: 4.7
Tested up to: 6.4 Tested up to: 6.3
Stable tag: 1.2.0 Stable tag: 1.0.0
Requires PHP: 5.6 Requires PHP: 5.6
License: MIT License: MIT
License URI: License URI:
@ -12,39 +12,39 @@ The ActivityPub protocol is a decentralized social networking protocol based upo
== Description == == Description ==
Enter the fediverse with **ActivityPub**, broadcasting your blog to a wider audience! Attract followers, deliver updates, and receive comments from a diverse user base of **ActivityPub**\-compliant platforms. This is BETA software, see the FAQ to see the current feature set or rather what is still planned.
With the ActivityPub plugin installed, your WordPress blog itself function as a federated profile, along with profiles for each author. For instance, if your website is ``, then the blog-wide profile can be found at ``, and authors like Jane and Bob would have their individual profiles at `` and ``, respectively. The plugin implements the ActivityPub protocol for your blog, which means that your readers will be able to follow your blog posts on Mastodon and other federated platforms that support ActivityPub. In addition, replies to your posts on Mastodon and related platforms will automatically become comments on your blog post.
An example: I give you my Mastodon profile name: ``. You search, see my profile, and hit follow. Now, any post I make appears in your Home feed. Similarly, with the ActivityPub plugin, you can find and follow Jane's profile at ``.
Once you follow Jane's `` profile, any blog post she crafts on `` will land in your Home feed. Simultaneously, by following the blog-wide profile ``, you'll receive updates from all authors.
**Note**: if no one follows your author or blog instance, your posts remain unseen. The simplest method to verify the plugin's operation is by following your profile. If you possess a Mastodon profile, initiate by following your new one.
The plugin works with the following tested federated platforms, but there may be more that it works with as well: The plugin works with the following tested federated platforms, but there may be more that it works with as well:
* [Mastodon]( * [Mastodon](
* [Pleroma]([Akkoma]( * [Pleroma](
* [friendica]( * [friendica](
* [Hubzilla]( * [Hubzilla](
* [Pixelfed]( * [Pixelfed](
* [Socialhome]( * [Socialhome](
* [Firefish]( (rebrand of Calckey) * [Calckey](
Heres what that means and what you can expect.
Once the ActivityPub plugin is installed, each authors page on your WordPress blog will become its own federated instance. In other words, if you have two authors, Jane and Bob, on your website, ``, then your authors would have their own author pages at `` and ``. Each of those author pages would now be available to Mastodon users (and all other federated platform users) as a profile that can be followed. Lets break that down further. Lets say you have a friend on Mastodon who tells you to follow them and they give you their profile name ``. You search for her name, see her profile, and click the follow button, right? From then on, everything Jane posts on her profile shows up in your Home feed. Okay, similarly, now that Jane has installed the ActivityPub plugin on her `` site, her friends can also follow her on Mastodon by searching for `` and clicking the Follow button on that profile.
From now on, every blog post Jane publishes on will show up on your Home feed because you follow her `` profile.
Of course, if no one follows your author instance, then no one will ever see the posts - including you! So the easiest way to even know if the plugin is working is to follow your new profile yourself. If you already have a Mastodon profile, just follow your new one from there.
Some things to note: Some things to note:
1. The blog-wide profile is only compatible with sites with rewrite rules enabled. If your site does not have rewrite rules enabled, the author-specific profiles may still work. 1. Many single-author blogs have chosen to turn off or redirect their author profile pages, usually via an SEO plugin like Yoast or Rank Math. This is usually done to avoid duplicate content with your blogs home page. If your author page has been deactivated in this way, then ActivityPub wont work for you. Instead, you can turn your author profile page back on, and then use the option in your SEO plugin to noindex the author page. This will enable the page to be live and ActivityPub will now work, but the live page wont cause any duplicate content issues with search engines.
1. Many single-author blogs have chosen to turn off or redirect their author profile pages, usually via an SEO plugin like Yoast or Rank Math. This is usually done to avoid duplicate content with your blogs home page. If your author page has been deactivated in this way, then ActivityPub author profiles wont work for you. Instead, you can turn your author profile page back on, and then use the option in your SEO plugin to noindex the author page. This will still resolve duplicate content issues with search engines and will enable ActivityPub author profiles to work. 1. Once ActivityPub is installed, only new posts going forward will be available in the fediverse. Likewise, even if youve been using ActivityPub for a while, anyone who follows your site, will only see new posts you publish from that moment on. They will never see previously-published posts in their Home feed. This process is very similar to subscribing to a newsletter. If you subscribe to a newsletter, you will only receive future emails, but not the old archived ones. With ActivityPub, if someone follows your site, they will only receive new blog posts you publish from then on.
1. Once ActivityPub is installed, *only new posts going forward* will be available in the fediverse. Likewise, even if youve been using ActivityPub for a while, anyone who follows your site, will only see new posts you publish from that moment on. They will never see previously-published posts in their Home feed. This process is very similar to subscribing to a newsletter. If you subscribe to a newsletter, you will only receive future emails, but not the old archived ones. With ActivityPub, if someone follows your site, they will only receive new blog posts you publish from then on.
So whats the process? So whats the process?
1. Install the ActivityPub plugin. 1. Install the ActivityPub plugin.
1. Go to the plugins settings page and adjust the settings to your liking. Click the Save button when ready. 1. Go to the plugins settings page and adjust the settings to your liking. Click the Save button when ready.
1. Make sure your blogs author profile page is active if you are using author profiles. 1. Make sure your blogs author profile page is active.
1. Go to Mastodon or any other federated platform, and search for your profile, and follow it. Your new profile will be in the form of either `` or ``, so that is what youll search for. 1. Go to Mastodon or any other federated platform, search for your authors new federated profile, and follow it. Your new profile will be in the form of, so that is what youll search for.
1. On your blog, publish a new post. 1. On your blog, publish a new post.
1. From Mastodon, check to see if the new post appears in your Home feed. 1. From Mastodon, check to see if the new post appears in your Home feed.
@ -54,25 +54,34 @@ Please note that it may take up to 15 minutes or so for the new post to show up
= tl;dr = = tl;dr =
This plugin connects your WordPress blog to popular social platforms like Mastodon, making your posts more accessible to a wider audience. Once installed, your blog can be followed by users on these platforms, allowing them to receive your new posts in their feeds. This plugin connects your WordPress blog to popular social platforms like Mastodon, making your posts more accessible to a wider audience. Once installed, your blog's author pages can be followed by users on these platforms, allowing them to receive your new posts in their feeds.
Here's how it works:
1. Install the plugin and adjust settings as needed.
1. Ensure your blog's author profile page is active.
1. On Mastodon or other supported platforms, search for and follow your author's new profile (e.g., ``).
1. Publish a new post on your blog and check if it appears in your Mastodon feed.
Please note that it may take up to 15 minutes for a new post to appear in your feed, as messages are sent on a delay to avoid overwhelming your followers. Be patient and give it some time.
= What is the status of this plugin? = = What is the status of this plugin? =
Implemented: Implemented:
* blog profile pages (JSON representation) * profile pages (JSON representation)
* author profile pages (JSON representation)
* custom links * custom links
* functional inbox/outbox * functional inbox/outbox
* follow (accept follows) * follow (accept follows)
* share posts * share posts
* receive comments/reactions * receive comments/reactions
* signature verification
To implement: To implement:
* signature verification
* better WordPress integration
* better configuration possibilities
* threaded comments support * threaded comments support
* replace shortcodes with blocks for layout
= What is "ActivityPub for WordPress" = = What is "ActivityPub for WordPress" =
@ -86,7 +95,7 @@ In order for webfinger to work, it must be mapped to the root directory of the U
Add the following to the .htaccess file in the root directory: Add the following to the .htaccess file in the root directory:
RedirectMatch "^\/\.well-known/(webfinger|nodeinfo|x-nodeinfo2)(.*)$" /blog/.well-known/$1$2 RedirectMatch "^\/\.well-known/(webfinger|nodeinfo|x-nodeinfo2)(.*)$" "\/blog\/\.well-known$1$2"
Where 'blog' is the path to the subdirectory at which your blog resides. Where 'blog' is the path to the subdirectory at which your blog resides.
@ -105,115 +114,19 @@ Where 'blog' is the path to the subdirectory at which your blog resides.
Project maintained on GitHub at [automattic/wordpress-activitypub]( Project maintained on GitHub at [automattic/wordpress-activitypub](
= 1.2.0 =
* Add: Search and order followerer lists
* Add: Have a filter to defer signature verification
* Improved: "Follow Me" styles for dark themes
* Fixed: Deduplicate attachments earlier to prevent incorrect max_media
= 1.1.0 =
* Improved: audio and video attachments are now supported!
* Improved: better error messages if remote profile is not accessible
* Improved: PHP 8.1 compatibility
* Fixed: don't try to parse mentions or hashtags for very large (>1MB) posts to prevent timeouts
* Fixed: better handling of ISO-639-1 locale codes
* Improved: more reliable [ap_author], props @uk3
* Improved: NodeInfo statistics
= 1.0.10 =
* Improved: better error messages if remote profile is not accessible
= 1.0.9 =
* Fixed: broken following endpoint
= 1.0.8 =
* Fixed: blocking of HEAD requests
* Fixed: PHP fatal error
* Fixed: several typos
* Fixed: error codes
* Improved: loading of shortcodes
* Updated: caching of followers
* Updated: Application-User is no longer "indexable"
* Updated: more consistent usage of the `application/activity+json` Content-Type
* Removed: featured tags endpoint
= 1.0.7 =
* Fixed: broken function call
* Add: filter to hook into "is blog public" check
= 1.0.6 =
* Fixed: more restrictive request verification
= 1.0.5 =
* Fixed: compatibility with WebFinger and NodeInfo plugin
= 1.0.4 =
* Fixed: Constants were not loaded early enough, resulting in a race condition
* Fixed: Featured image was ignored when using the block editor
= 1.0.3 =
* Fixed: compatibility with older WordPress/PHP versions
* Update: refactoring of the Plugin init process
* Update: better frontend UX and improved theme compat for blocks
* Compatibility: add a ACTIVITYPUB_DISABLE_REWRITES constant
* Compatibility: add pre-fetch hook to allow plugins to hang filters on
= 1.0.2 =
* Updated: improved hashtag visibility in default template
* Updated: reduced number of followers to be checked/updated via Cron, when System Cron is not set up
* Updated: check if username of Blog-User collides with an Authors name
* Compatibility: improved Group meta informations
* Fixed: detection of single user mode
* Fixed: remote delete
* Fixed: styles in Follow-Me block
* Fixed: various encoding and formatting issues
* Fixed: (health) check Author URLs only if Authors are enabled
= 1.0.1 =
* Update: improve image attachment detection using the block editor
* Update: better error code handling for API responses
* Update: use a tag stack instead of regex for protecting tags for Hashtags and @-Mentions
* Compatibility: better signature support for subpath-installations
* Compatibility: allow deactivating blocks registered by the plugin
* Compatibility: avoid Fatal Errors when using ClassicPress
* Compatibility: improve the Group-Actor to play nicely with existing implementations
* Fixed: truncate long blog titles and handles for the "Follow me" block
* Fixed: ensure that only a valid user can be selected for the "Follow me" block
* Fixed: fix a typo in a hook name
* Fixed: a problem with signatures when running WordPress in a sub-path
= 1.0.0 = = 1.0.0 =
* Add: blog-wide Account (catchall, like ``) * Add: blog-wide Account (catchall, like ``)
* Add: a Follow Me block (help visitors to follow your Profile) * Add: Signature Verification: .
* Add: Signature Verification: * Add: a Followers Block.
* Add: a Followers Block (show off your Followers)
* Add: Simple caching * Add: Simple caching
* Add: Collection endpoints for Featured Tags and Featured Posts * Update: Complete rewrite of the Follower-System based on Custom Post Types.
* Add: Better handling of Hashtags in mobile apps
* Update: Complete rewrite of the Follower-System based on Custom Post Types
* Update: Improved linter (PHPCS) * Update: Improved linter (PHPCS)
* Compatibility: Add a new conditional, `\Activitypub\is_activitypub_request()`, to allow third-party plugins to detect ActivityPub requests * Compatibility: Add a new conditional, `\Activitypub\is_activitypub_request()`, to allow third-party plugins to detect ActivityPub requests.
* Compatibility: Add hooks to allow modifying images returned in ActivityPub requests * Compatibility: Add hooks to allow modifying images returned in ActivityPub requests.
* Compatibility: Indicate that the plugin is compatible and has been tested with the latest version of WordPress, 6.3 * Compatibility: Indicate that the plugin is compatible and has been tested with the latest version of WordPress, 6.3.
* Compatibility: Avoid PHP notice on sites using PHP 8.2 * Compatibility: Avoid PHP notice on sites using PHP 8.2.
* Fixed: Load the plugin later in the WordPress code lifecycle to avoid errors in some requests * Fixed: Load the plugin later in the WordPress code lifecycle to avoid errors in some requests.
* Fixed: Updating posts
* Fixed: Hashtag now support CamelCase and UTF-8
= 0.17.0 = = 0.17.0 =

@ -1,44 +0,0 @@
"$schema": "",
"name": "activitypub/follow-me",
"apiVersion": 3,
"version": "1.0.0",
"title": "Follow me on the Fediverse",
"category": "widgets",
"description": "Display your Fediverse profile so that visitors can follow you.",
"textdomain": "activitypub",
"icon": "groups",
"supports": {
"html": false,
"color": {
"gradients": true,
"link": true,
"__experimentalDefaultControls": {
"background": true,
"text": true,
"link": true
"__experimentalBorder": {
"radius": true,
"width": true,
"color": true,
"style": true
"typography": {
"fontSize": true,
"__experimentalDefaultControls": {
"fontSize": true
"attributes": {
"selectedUser": {
"type": "string",
"default": "site"
"editorScript": "file:./index.js",
"viewScript": "file:./view.js",
"style": ["file:./style-index.css", "wp-components"]

@ -1,75 +0,0 @@
function presetVarColorCss( color ) {
return `var(--wp--preset--color--${ color })`;
function getBackgroundColor( color ) {
// if color is a string, it's a var like this.
if ( typeof color === 'string' ) {
return presetVarColorCss( color );
return color?.color?.background || null;
function getLinkColor( text ) {
if ( typeof text !== 'string' ) {
return null;
// if it starts with a hash, leave it be
if ( text.match( /^#/ ) ) {
// we don't handle the alpha channel if present.
return text.substring( 0, 7 );
// var:preset|color|luminous-vivid-amber
// var(--wp--preset--color--luminous-vivid-amber)
// we will receive the top format, we need to output the bottom format
const [ , , color ] = text.split( '|' );
return presetVarColorCss( color );
function generateSelector( selector, prop, value = null, pseudo = '' ) {
if ( ! value ) {
return '';
return `${ selector }${ pseudo } { ${ prop }: ${ value }; }\n`;
function getStyles( selector, button, text, hover ) {
return generateSelector( selector, 'background-color', button )
+ generateSelector( selector, 'color', text )
+ generateSelector( selector, 'background-color', hover, ':hover' )
+ generateSelector( selector, 'background-color', hover, ':focus' );
function getBlockStyles( base, style, backgroundColor ) {
const selector = `${ base } .components-button`;
// we grab the background color if set as a good color for our button text
const buttonTextColor = getBackgroundColor( backgroundColor )
// bg might be in this form.
|| style?.color?.background;
// we misuse the link color for the button background
const buttonColor = getLinkColor( style?.elements?.link?.color?.text );
// hover!
const buttonHoverColor = getLinkColor( style?.elements?.link?.[':hover']?.color?.text );
return getStyles( selector, buttonColor, buttonTextColor, buttonHoverColor );
export function getPopupStyles( style ) {
// we don't acept backgroundColor because the popup is always white (right?)
const buttonColor = getLinkColor( style?.elements?.link?.color?.text )
|| '#111';
const buttonTextColor = '#fff';
const buttonHoverColor = getLinkColor( style?.elements?.link?.[':hover']?.color?.text )
|| '#333';
const selector = '.apfmd__button-group .components-button';
return getStyles( selector, buttonColor, buttonTextColor, buttonHoverColor );
export function ButtonStyle( { selector, style, backgroundColor } ) {
const css = getBlockStyles( selector, style, backgroundColor );
return (
<style>{ css }</style>

@ -1,43 +0,0 @@
import { InspectorControls, useBlockProps } from '@wordpress/block-editor';
import { __ } from '@wordpress/i18n';
import { SelectControl, PanelBody } from '@wordpress/components';
import { useUserOptions } from '../shared/use-user-options';
import FollowMe from './follow-me';
import { useEffect } from '@wordpress/element';
export default function Edit( { attributes, setAttributes } ) {
const blockProps = useBlockProps( {
className: 'activitypub-follow-me-block-wrapper',
} );
const usersOptions = useUserOptions();
const { selectedUser } = attributes;
useEffect( () => {
// if there are no users yet, do nothing
if ( ! usersOptions.length ) {
// ensure that the selected user is in the list of options, if not, select the first available user
if ( ! usersOptions.find( ( { value } ) => value === selectedUser ) ) {
setAttributes( { selectedUser: usersOptions[ 0 ].value } );
}, [ selectedUser, usersOptions ] );
return (
<div { ...blockProps }>
{ usersOptions.length > 1 && (
<InspectorControls key="setting">
<PanelBody title={ __( 'Followers Options', 'activitypub' ) }>
label= { __( 'Select User', 'activitypub' ) }
value={ attributes.selectedUser }
options={ usersOptions }
onChange={ ( value ) => setAttributes( { selectedUser: value } ) }
) }
<FollowMe { ...attributes } id={ } />

View file

@ -1,181 +0,0 @@
import apiFetch from '@wordpress/api-fetch';
import { useCallback, useEffect, useState, createInterpolateElement } from '@wordpress/element';
import { Button, Modal } from '@wordpress/components';
import { __, sprintf } from '@wordpress/i18n';
import { copy, check, Icon } from '@wordpress/icons';
import { useCopyToClipboard } from '@wordpress/compose';
import { ButtonStyle, getPopupStyles } from './button-style';
import './style.scss';
const { namespace } = window._activityPubOptions;
avatar: '',
resource: '@well@hello.dolly',
name: __( 'Hello Dolly Fan Account', 'activitypub' ),
url: '#',
function getNormalizedProfile( profile ) {
if ( ! profile ) {
const data = { ...DEFAULT_PROFILE_DATA, ...profile };
data.avatar = data?.icon?.url;
return data;
function fetchProfile( userId ) {
const fetchOptions = {
headers: { Accept: 'application/activity+json' },
path: `/${ namespace }/users/${ userId }`,
return apiFetch( fetchOptions );
function Profile( { profile, popupStyles, userId } ) {
const { avatar, name, resource } = profile;
return (
<div className="activitypub-profile">
<img className="activitypub-profile__avatar" src={ avatar } />
<div className="activitypub-profile__content">
<div className="activitypub-profile__name">{ name }</div>
<div className="activitypub-profile__handle" title={ resource }>{ resource }</div>
<Follow profile={ profile } popupStyles={ popupStyles } userId={ userId } />
function Follow( { profile, popupStyles, userId } ) {
const [ isOpen, setIsOpen ] = useState( false );
const title = sprintf( __( 'Follow %s', 'activitypub' ), profile?.name );
return (
<Button className="activitypub-profile__follow" onClick={ () => setIsOpen( true ) } >
{ __( 'Follow', 'activitypub' ) }
{ isOpen && (
onRequestClose={ () => setIsOpen( false ) }
title={ title }
<Dialog profile={ profile } userId={ userId } />
<style>{ popupStyles }</style>
) }
function isUrl( string ) {
try {
new URL( string );
return true;
} catch ( _ ) {
return false;
function isHandle( string ) {
// remove leading @, there should still be an @ in there
const parts = string.replace( /^@/, '' ).split( '@' );
return parts.length === 2 && isUrl( `https://${ parts[ 1 ] }` );
function Dialog( { profile, userId } ) {
const { resource } = profile;
const followText = __( 'Follow', 'activitypub' );
const loadingText = __( 'Loading...', 'activitypub' );
const openingText = __( 'Opening...', 'activitypub' );
const errorText = __( 'Error', 'activitypub' );
const invalidText = __( 'Invalid', 'activitypub' );
const [ buttonText, setButtonText ] = useState( followText );
const [ buttonIcon, setButtonIcon ] = useState( copy );
const ref = useCopyToClipboard( resource, () => {
setButtonIcon( check );
setTimeout( () => setButtonIcon( copy ), 1000 );
} );
const [ remoteProfile, setRemoteProfile ] = useState( '' );
const retrieveAndFollow = useCallback( () => {
let timeout;
if ( ! ( isUrl( remoteProfile ) || isHandle( remoteProfile ) ) ) {
setButtonText( invalidText );
timeout = setTimeout( () => setButtonText( followText ), 2000 );
return () => clearTimeout( timeout );
const path = `/${ namespace }/users/${userId}/remote-follow?resource=${ remoteProfile }`;
setButtonText( loadingText );
apiFetch( { path } ).then( ( { url } ) => {
setButtonText( openingText );
setTimeout( () => { url, '_blank' );
setButtonText( followText );
}, 200 );
} ).catch( () => {
setButtonText( errorText );
setTimeout( () => setButtonText( followText ), 2000 );
} );
}, [ remoteProfile ] );
return (
<div className="activitypub-follow-me__dialog">
<div className="apmfd__section">
<h4>{ __( 'My Profile', 'activitypub' ) }</h4>
<div className="apfmd-description">
{ __( 'Copy and paste my profile into the search field of your favorite fediverse app or server.', 'activitypub' ) }
<div className="apfmd__button-group">
<input type="text" value={ resource } readOnly />
<Button ref={ ref }>
<Icon icon={ buttonIcon } />
{ __( 'Copy', 'activitypub' ) }
<div className="apmfd__section">
<h4>{ __( 'Your Profile', 'activitypub' ) }</h4>
<div className="apfmd-description">
{ createInterpolateElement(
__( 'Or, if you know your own profile, we can start things that way! (eg <code></code> or <code></code>)', 'activitypub' ),
{ code: <code /> }
) }
<div className="apfmd__button-group">
value={ remoteProfile }
onKeyDown={ ( event ) => { event?.code === 'Enter' && retrieveAndFollow() } }
onChange={ e => setRemoteProfile( ) }
<Button onClick={ retrieveAndFollow }>{ buttonText }</Button>
export default function FollowMe( { selectedUser, style, backgroundColor, id, useId = false, profileData = false } ) {
const [ profile, setProfile ] = useState( getNormalizedProfile() );
const userId = selectedUser === 'site' ? 0 : selectedUser;
const popupStyles = getPopupStyles( style );
const wrapperProps = useId ? { id } : {};
function setProfileData( profile ) {
setProfile( getNormalizedProfile( profile ) );
useEffect( () => {
if ( profileData ) {
return setProfileData( profileData );
fetchProfile( userId ).then( setProfileData );
}, [ userId, profileData ] );
<div { ...wrapperProps }>
<ButtonStyle selector={ `#${ id }` } style={ style } backgroundColor={ backgroundColor } />
<Profile profile={ profile } userId={ userId } popupStyles={ popupStyles } />

@ -1,5 +0,0 @@
import { registerBlockType } from '@wordpress/blocks';
import { people } from '@wordpress/icons';
import edit from './edit';
const save = () => null;
registerBlockType( 'activitypub/follow-me', { edit, save, icon: people } );

@ -1,93 +0,0 @@
.activitypub-follow-me-block-wrapper {
width: 100%;
// extra side padding for border/background colors
&.has-border-color, &.has-background {
.activitypub-profile {
padding-left: 1rem;
padding-right: 1rem;
.activitypub-profile {
display: flex;
align-items: center;
// right/left padding overridden above for border/background colors
padding: 1rem 0;
.activitypub-profile__avatar {
height: 75px;
width: 75px;
margin-right: 1rem;
border-radius: 50%;
.activitypub-profile__content {
flex: 1;
min-width: 0;
.activitypub-profile__name, .activitypub-profile__handle {
margin: 0;
line-height: 1.2;
white-space: nowrap;
overflow: hidden;
text-overflow: ellipsis;
.activitypub-profile__name {
font-size: 1.25em;
.activitypub-profile__follow {
margin-left: 1rem;
align-self: center;
background-color: var(--wp--preset--color--black);
color: var(--wp--preset--color--white);
.activitypub-profile__confirm.components-modal__frame {
// @todo: play more nicely with dark background themes. the dialog is hardcoded to white bg in core, we go #eee here.
color: #333;
background-color: #f7f7f7;
.components-modal__header-heading, h4 {
color: #333;
// resets against potential theme weirdness
letter-spacing: inherit;
word-spacing: inherit;
.activitypub-follow-me__dialog {
max-width: 30em;
h4 {
line-height: 1;
margin: 0;
.apmfd__section {
margin-bottom: 2em;
.apfmd-description {
font-size: var( --wp--preset--font-size--normal, .75rem );
margin: 0.33em 0 1em;
.apfmd__button-group {
display: flex;
justify-content: flex-end;
align-items: flex-end;
svg {
margin-right: .5em;
height: 21px;
width: 21px;
input {
flex: 1;
padding: 6px 12px;
background-color: var( --wp--preset--color--white );
color: var( --wp--preset--color--black );
border: 1px solid var( --wp--preset--color--black );

@ -1,16 +0,0 @@
import { render } from '@wordpress/element';
import domReady from '@wordpress/dom-ready';
import FollowMe from './follow-me';
let id = 1;
function getUniqueId() {
return `activitypub-follow-me-block-${ id++ }`;
domReady( () => {
// iterate over a nodelist
[] document.querySelectorAll( '.activitypub-follow-me-block-wrapper' ), ( element ) => {
const attrs = JSON.parse( element.dataset.attrs );
render( <FollowMe { ...attrs } id={ getUniqueId() } useId={ true } />, element );
} );
} );

@ -1,9 +1,31 @@
import { SelectControl, RangeControl, PanelBody, TextControl } from '@wordpress/components'; import { SelectControl, RangeControl, PanelBody, TextControl } from '@wordpress/components';
import { useState, useEffect } from '@wordpress/element'; import { useSelect } from '@wordpress/data';
import { useMemo, useState } from '@wordpress/element';
import { InspectorControls, useBlockProps } from '@wordpress/block-editor'; import { InspectorControls, useBlockProps } from '@wordpress/block-editor';
import { __ } from '@wordpress/i18n'; import { __ } from '@wordpress/i18n';
import { Followers } from './followers'; import { Followers } from './followers';
import { useUserOptions } from '../shared/use-user-options';
const enabled = window._activityPubOptions?.enabled;
function useUserOptions() {
const users = enabled?.users ? useSelect( ( select ) => select( 'core' ).getUsers( { who: 'authors' } ) ) : [];
return useMemo( () => {
if ( ! users ) {
return [];
const withBlogUser = enabled?.site ? [ {
label: __( 'Whole Site', 'activitypub' ),
value: 'site'
} ] : [];
return users.reduce( ( acc, user ) => {
} );
return acc;
}, withBlogUser );
}, [ users ] );
export default function Edit( { attributes, setAttributes } ) { export default function Edit( { attributes, setAttributes } ) {
const { order, per_page, selectedUser, title } = attributes; const { order, per_page, selectedUser, title } = attributes;
@ -21,17 +43,6 @@ export default function Edit( { attributes, setAttributes } ) {
}; };
} }
useEffect( () => {
// if there are no users yet, do nothing
if ( ! usersOptions.length ) {
// ensure that the selected user is in the list of options, if not, select the first available user
if ( ! usersOptions.find( ( { value } ) => value === selectedUser ) ) {
setAttributes( { selectedUser: usersOptions[ 0 ].value } );
}, [ selectedUser, usersOptions ] );
return ( return (
<div { ...blockProps }> <div { ...blockProps }>
<InspectorControls key="setting"> <InspectorControls key="setting">
@ -42,14 +53,12 @@ export default function Edit( { attributes, setAttributes } ) {
value={ title } value={ title }
onChange={ value => setAttributes( { title: value } ) } onChange={ value => setAttributes( { title: value } ) }
/> />
{ usersOptions.length > 1 && (
<SelectControl <SelectControl
label= { __( 'Select User', 'activitypub' ) } label= { __( 'Select User', 'activitypub' ) }
value={ selectedUser } value={ selectedUser }
options={ usersOptions } options={ usersOptions }
onChange={ setAttributestAndResetPage( 'selectedUser' ) } onChange={ setAttributestAndResetPage( 'selectedUser' ) }
/> />
) }
<SelectControl <SelectControl
label={ __( 'Sort', 'activitypub' ) } label={ __( 'Sort', 'activitypub' ) }
value={ order } value={ order }

@ -32,8 +32,7 @@ export function Followers( {
page: passedPage, page: passedPage,
setPage: passedSetPage, setPage: passedSetPage,
className = '', className = '',
followLinks = true, followLinks = true
followerData = false
} ) { } ) {
const userId = selectedUser === 'site' ? 0 : selectedUser; const userId = selectedUser === 'site' ? 0 : selectedUser;
const [ followers, setFollowers ] = useState( [] ); const [ followers, setFollowers ] = useState( [] );
@ -57,22 +56,16 @@ export function Followers( {
} }
); );
const setData = ( followers, total ) => {
setFollowers( followers );
setTotal( total );
setPages( Math.ceil( total / per_page ) );
useEffect( () => { useEffect( () => {
if ( followerData && page === 1 ) {
return setData( followerData.followers, );
const path = getPath( userId, per_page, order, page ); const path = getPath( userId, per_page, order, page );
apiFetch( { path } ) apiFetch( { path } )
.then( ( data ) => setData( data.orderedItems, data.totalItems ) ) .then( ( data ) => {
.catch( () => {} ); setPages( Math.ceil( data.totalItems / per_page ) );
}, [ userId, per_page, order, page, followerData ] ); setTotal( data.totalItems );
setFollowers( data.orderedItems );
} )
.catch( ( error ) => console.error( error ) );
}, [ userId, per_page, order, page ] );
return ( return (
<div className={ "activitypub-follower-block " + className }> <div className={ "activitypub-follower-block " + className }>
<h3>{ title }</h3> <h3>{ title }</h3>

@ -1,24 +0,0 @@
import { __ } from '@wordpress/i18n';
import { useSelect } from '@wordpress/data';
import { useMemo } from '@wordpress/element';
const enabled = window._activityPubOptions?.enabled;
export function useUserOptions() {
const users = enabled?.users ? useSelect( ( select ) => select( 'core' ).getUsers( { who: 'authors' } ) ) : [];
return useMemo( () => {
if ( ! users ) {
return [];
const withBlogUser = enabled?.site ? [ {
label: __( 'Whole Site', 'activitypub' ),
value: 'site'
} ] : [];
return users.reduce( ( acc, user ) => {
value: `${ }` // casting to string because that's how the attribute is stored by Gutenberg
} );
return acc;
}, withBlogUser );
}, [ users ] );

@ -6,7 +6,7 @@
<h1><?php \esc_html_e( 'ActivityPub', 'activitypub' ); ?></h1> <h1><?php \esc_html_e( 'ActivityPub', 'activitypub' ); ?></h1>
</div> </div>
<nav class="activitypub-settings-tabs-wrapper" aria-label="<?php \esc_attr_e( 'Secondary menu', 'activitypub' ); ?>"> <nav class="activitypub-settings-tabs-wrapper hide-if-no-js" aria-label="<?php \esc_attr_e( 'Secondary menu', 'activitypub' ); ?>">
<a href="<?php echo \esc_url_raw( admin_url( 'options-general.php?page=activitypub' ) ); ?>" class="activitypub-settings-tab <?php echo \esc_attr( $args['welcome'] ); ?>"> <a href="<?php echo \esc_url_raw( admin_url( 'options-general.php?page=activitypub' ) ); ?>" class="activitypub-settings-tab <?php echo \esc_attr( $args['welcome'] ); ?>">
<?php \esc_html_e( 'Welcome', 'activitypub' ); ?> <?php \esc_html_e( 'Welcome', 'activitypub' ); ?>
</a> </a>

@ -8,21 +8,23 @@
'followers' => 'active', 'followers' => 'active',
) )
); );
$table = new \Activitypub\Table\Followers();
$follower_count = $table->get_user_count();
// translators: The follower count.
$followers_template = _n( 'Your blog profile currently has %s follower.', 'Your blog profile currently has %s followers.', $follower_count, 'activitypub' );
?> ?>
<div class="wrap activitypub-followers-page"> <div class="wrap activitypub-followers-page">
<p><?php \printf( \esc_html( $followers_template ), \esc_attr( $follower_count ) ); ?></p> <h1><?php \esc_html_e( 'Followers', 'activitypub' ); ?></h1>
<?php $table = new \Activitypub\Table\Followers(); ?>
<?php // translators: The follower count. ?>
<p><?php \printf( \esc_html__( 'You currently have %s followers.', 'activitypub' ), \esc_attr( $table->get_user_count() ) ); ?></p>
<form method="get"> <form method="get">
<input type="hidden" name="page" value="activitypub" /> <input type="hidden" name="page" value="activitypub" />
<input type="hidden" name="tab" value="followers" /> <input type="hidden" name="tab" value="followers" />
<?php <?php
$table->prepare_items(); $table->prepare_items();
$table->search_box( 'Search', 'search' );
$table->display(); $table->display();
?> ?>
<?php wp_nonce_field( 'activitypub-followers-list', '_apnonce' ); ?>
</form> </form>
</div> </div>

@ -2,9 +2,8 @@
// phpcs:ignore WordPress.WP.GlobalVariablesOverride.Prohibited // phpcs:ignore WordPress.WP.GlobalVariablesOverride.Prohibited
$post = \get_post(); $post = \get_post();
$transformer = \Activitypub\Transformer\Transformers_Manager::instance()->get_transformer( $post ); $object = new \Activitypub\Transformer\Post( $post );
$json = \array_merge( array( '@context' => \Activitypub\get_context() ), $object->to_object()->to_array() );
$json = \array_merge( array( '@context' => \Activitypub\get_context() ), $transformer->to_object()->to_array() );
// filter output // filter output
$json = \apply_filters( 'activitypub_json_post_array', $json ); $json = \apply_filters( 'activitypub_json_post_array', $json );

@ -11,41 +11,60 @@
?> ?>
<div class="activitypub-settings activitypub-settings-page hide-if-no-js"> <div class="activitypub-settings activitypub-settings-page hide-if-no-js">
<div class="box">
<h3><?php \esc_html_e( 'Troubleshooting', 'activitypub' ); ?></h3>
echo \wp_kses(
// translators:
\__( 'If you have problems using this plugin, please check the <a href="%s">Site Health</a> to ensure that your site is compatible and/or use the "Help" tab (in the top right of the settings pages).', 'activitypub' ),
\esc_url_raw( \admin_url( 'site-health.php' ) )
<form method="post" action="options.php"> <form method="post" action="options.php">
<?php \settings_fields( 'activitypub' ); ?> <?php \settings_fields( 'activitypub' ); ?>
<div class="box"> <div class="box">
<h3><?php \esc_html_e( 'Profiles', 'activitypub' ); ?></h3> <h3><?php \esc_html_e( 'Users', 'activitypub' ); ?></h3>
<p><?php \esc_html_e( 'All user related settings.', 'activitypub' ); ?></p>
<table class="form-table"> <table class="form-table">
<tbody> <tbody>
<tr> <tr>
<th scope="row"> <th scope="row">
<?php \esc_html_e( 'Enable profiles by type', 'activitypub' ); ?> <?php \esc_html_e( 'Enable/disable Users by Type', 'activitypub' ); ?>
</th> </th>
<td> <td>
<p> <p>
<label> <label>
<input type="checkbox" name="activitypub_enable_users" id="activitypub_enable_users" value="1" <?php echo \checked( '1', \get_option( 'activitypub_enable_users', '1' ) ); ?> /> <input type="checkbox" name="activitypub_enable_users" id="activitypub_enable_users" value="1" <?php echo \checked( '1', \get_option( 'activitypub_enable_users', '1' ) ); ?> />
<?php \esc_html_e( 'Enable authors', 'activitypub' ); ?> <?php \esc_html_e( 'Enable Authors', 'activitypub' ); ?>
</label> </label>
</p> </p>
<p class="description"> <p class="description">
<?php echo \wp_kses( \__( 'Every author on this blog (with the <code>publish_posts</code> capability) gets their own ActivityPub profile.', 'activitypub' ), array( 'code' => array() ) ); ?> <?php echo \wp_kses( \__( 'Every Author on this Blog (with the <code>publish_posts</code> capability) gets his own ActivityPub enabled Profile.', 'activitypub' ), array( 'code' => array() ) ); ?>
</p> </p>
<p> <p>
<label> <label>
<input type="checkbox" name="activitypub_enable_blog_user" id="activitypub_enable_blog_user" value="1" <?php echo \checked( '1', \get_option( 'activitypub_enable_blog_user', '0' ) ); ?> /> <input type="checkbox" name="activitypub_enable_blog_user" id="activitypub_enable_blog_user" value="1" <?php echo \checked( '1', \get_option( 'activitypub_enable_blog_user', '0' ) ); ?> />
<?php \esc_html_e( 'Enable blog', 'activitypub' ); ?> <?php \esc_html_e( 'Enable Blog-User', 'activitypub' ); ?>
</label> </label>
</p> </p>
<p class="description"> <p class="description">
<?php \esc_html_e( 'Your blog becomes an ActivityPub profile.', 'activitypub' ); ?> <?php \esc_html_e( 'Your Blog becomes an ActivityPub compatible Profile.', 'activitypub' ); ?>
</p> </p>
</td> </td>
</tr> </tr>
<tr> <tr>
<th scope="row"> <th scope="row">
<?php \esc_html_e( 'Change blog profile ID', 'activitypub' ); ?> <?php \esc_html_e( 'Change Blog-User Identifier', 'activitypub' ); ?>
</th> </th>
<td> <td>
<label for="activitypub_blog_user_identifier"> <label for="activitypub_blog_user_identifier">
@ -53,12 +72,7 @@
@<?php echo esc_html( \wp_parse_url( \home_url(), PHP_URL_HOST ) ); ?> @<?php echo esc_html( \wp_parse_url( \home_url(), PHP_URL_HOST ) ); ?>
</label> </label>
<p class="description"> <p class="description">
<?php \esc_html_e( 'This profile name will federate all posts written on your blog, regardless of the author who posted it.', 'activitypub' ); ?> <?php \esc_html_e( 'This Blog-User will federate all posts written on your Blog, regardless of the User who posted it.', 'activitypub' ); ?>
<?php \esc_html_e( 'Please avoid using an existing authors name as the blog profile ID. Fediverse platforms might use caching and this could break the functionality completely.', 'activitypub' ); ?>
</p> </p>
</td> </td>
</tr> </tr>
@ -70,11 +84,14 @@
<div class="box"> <div class="box">
<h3><?php \esc_html_e( 'Activities', 'activitypub' ); ?></h3> <h3><?php \esc_html_e( 'Activities', 'activitypub' ); ?></h3>
<p><?php \esc_html_e( 'All activity related settings.', 'activitypub' ); ?></p>
<table class="form-table"> <table class="form-table">
<tbody> <tbody>
<tr> <tr>
<th scope="row"> <th scope="row">
<?php \esc_html_e( 'Post content', 'activitypub' ); ?> <?php \esc_html_e( 'Post-Content', 'activitypub' ); ?>
</th> </th>
<td> <td>
<p> <p>
@ -113,7 +130,7 @@
<?php \esc_html_e( 'Custom', 'activitypub' ); ?> <?php \esc_html_e( 'Custom', 'activitypub' ); ?>
- -
<span class="description"> <span class="description">
<?php \esc_html_e( 'Use the text area below, to customize your activities.', 'activitypub' ); ?> <?php \esc_html_e( 'Use the text-area below, to customize your activities.', 'activitypub' ); ?>
</span> </span>
</label> </label>
</p> </p>
@ -138,7 +155,7 @@
</tr> </tr>
<tr> <tr>
<th scope="row"> <th scope="row">
<?php \esc_html_e( 'Media attachments', 'activitypub' ); ?> <?php \esc_html_e( 'Number of images', 'activitypub' ); ?>
</th> </th>
<td> <td>
@ -147,20 +164,13 @@
echo \wp_kses( echo \wp_kses(
\sprintf( \sprintf(
// translators: // translators:
\__( 'The number of media (images, audio, video) to attach to posts. Default: <code>%s</code>', 'activitypub' ), \__( 'The number of images to attach to posts. Default: <code>%s</code>', 'activitypub' ),
), ),
'default' 'default'
); );
?> ?>
</p> </p>
<p class="description">
esc_html_e( 'Note: audio and video attachments are only supported from Block Editor.', 'activitypub' );
</td> </td>
</tr> </tr>
<tr> <tr>
@ -178,14 +188,13 @@
</span> </span>
</label> </label>
</p> </p>
<p><strong><?php \esc_html_e( 'Please note that the following "Activity-Object-Type" options may cause your texts to be displayed differently on each platform and/or parts may be completely ignored. Mastodon, for example, displays all content that is not of the "Note" type as links only.', 'activitypub' ); ?></strong></p>
<p> <p>
<label for="activitypub_object_type_article"> <label for="activitypub_object_type_article">
<input type="radio" name="activitypub_object_type" id="activitypub_object_type_article" value="article" <?php echo \checked( 'article', \get_option( 'activitypub_object_type', 'note' ) ); ?> /> <input type="radio" name="activitypub_object_type" id="activitypub_object_type_article" value="article" <?php echo \checked( 'article', \get_option( 'activitypub_object_type', 'note' ) ); ?> />
<?php \esc_html_e( 'Article', 'activitypub' ); ?> <?php \esc_html_e( 'Article', 'activitypub' ); ?>
- -
<span class="description"> <span class="description">
<?php \esc_html_e( 'The presentation of the "Article" might change on different platforms.', 'activitypub' ); ?> <?php \esc_html_e( 'The presentation of the "Article" might change on different platforms. Mastodon for example shows the "Article" type as a simple link.', 'activitypub' ); ?>
</span> </span>
</label> </label>
</p> </p>
@ -201,13 +210,33 @@
</p> </p>
</td> </td>
</tr> </tr>
<th scope="row"><?php \esc_html_e( 'Supported post types', 'activitypub' ); ?></th>
<?php \esc_html_e( 'Enable ActivityPub support for the following post types:', 'activitypub' ); ?>
<?php $post_types = \get_post_types( array( 'public' => true ), 'objects' ); ?>
<?php $support_post_types = \get_option( 'activitypub_support_post_types', array( 'post', 'page' ) ) ? \get_option( 'activitypub_support_post_types', array( 'post', 'page' ) ) : array(); ?>
<?php // phpcs:ignore WordPress.WP.GlobalVariablesOverride.Prohibited ?>
<?php foreach ( $post_types as $post_type ) { ?>
<input type="checkbox" id="activitypub_support_post_type_<?php echo \esc_attr( $post_type->name ); ?>" name="activitypub_support_post_types[]" value="<?php echo \esc_attr( $post_type->name ); ?>" <?php echo \checked( \in_array( $post_type->name, $support_post_types, true ) ); ?> />
<label for="activitypub_support_post_type_<?php echo \esc_attr( $post_type->name ); ?>"><?php echo \esc_html( $post_type->label ); ?></label>
<?php } ?>
<tr> <tr>
<th scope="row"> <th scope="row">
<?php \esc_html_e( 'Hashtags (beta)', 'activitypub' ); ?> <?php \esc_html_e( 'Hashtags (beta)', 'activitypub' ); ?>
</th> </th>
<td> <td>
<p> <p>
<label><input type="checkbox" name="activitypub_use_hashtags" id="activitypub_use_hashtags" value="1" <?php echo \checked( '1', \get_option( 'activitypub_use_hashtags', '1' ) ); ?> /> <?php echo wp_kses( \__( 'Add hashtags in the content as native tags and replace the <code>#tag</code> with the tag link. <strong>This feature is experimental! Please disable it, if you find any HTML or CSS errors.</strong>', 'activitypub' ), 'default' ); ?></label> <label><input type="checkbox" name="activitypub_use_hashtags" id="activitypub_use_hashtags" value="1" <?php echo \checked( '1', \get_option( 'activitypub_use_hashtags', '1' ) ); ?> /> <?php echo wp_kses( \__( 'Add hashtags in the content as native tags and replace the <code>#tag</code> with the tag-link. <strong>This feature is experimental! Please disable it, if you find any HTML or CSS errors.</strong>', 'activitypub' ), 'default' ); ?></label>
</p> </p>
</td> </td>
</tr> </tr>
@ -217,95 +246,11 @@
<?php \do_settings_fields( 'activitypub', 'activity' ); ?> <?php \do_settings_fields( 'activitypub', 'activity' ); ?>
</div> </div>
<!-- OUR FORK HERE -->
<div class="box">
<h3><?php \esc_html_e( 'Enable ActivityPub support for post type', 'activitypub' ); ?></h3>
<table class="form-table">
<th scope="row">
<?php \esc_html_e( 'Mapping', 'activitypub' ); ?>
<?php \esc_html_e( 'Enable ActivityPub support for a certain post type by selecting one of the available ActivityPub transformers.', 'activitypub' ); ?>
<?php $all_public_post_types = \get_post_types( array( 'public' => true ), 'objects' );
$transformer_mapping = \get_option( 'activitypub_transformer_mapping', array( 'default' => 'note' ) );
$all_public_post_type_names = array_map(function ($object) {
return $object->name;
}, $all_public_post_types);
$transformer_manager = \Activitypub\Transformer\Transformers_Manager::instance();
$transformers = $transformer_manager->get_transformers();
// TODO Probably we should use checkboxes and not select and make this less buggy and insert the js at the right place.
document.addEventListener('DOMContentLoaded', function () {
var radioGroups = {};
var radioButtons = document.querySelectorAll('input[type="radio"]');
radioButtons.forEach(function (radioButton) {
radioButton.addEventListener('click', function () {
var name =;
if (!radioGroups[name]) {
radioGroups[name] = this;
} else {
radioGroups[name].checked = false;
radioGroups[name] = this;
// Generate column headers based on transformer objects
foreach ($transformers as $transformer) {
echo '<th>' . htmlspecialchars($transformer->get_label()) . '</th>';
// Generate rows based on post types and transformers
foreach ($all_public_post_types as $post_type) {
echo '<tr>';
echo '<td><strong>' . htmlspecialchars($post_type->label) . '</strong></td>';
// Generate radio inputs for each transformer, considering support for the post type
foreach ($transformers as $transformer) {
$disabled_attribute = $transformer->supports_post_type( $post_type->name ) ? '' : ' disabled';
$is_selected = ( is_array( $transformer_mapping ) && isset( $transformer_mapping[ $post_type->name ] ) && $transformer_mapping[ $post_type->name ] === $transformer->get_name() ) ? ' checked ' : '';
echo '<td><input type="radio" name="activitypub_transformer_mapping[' . $post_type->name . ']" value="' . $transformer->get_name() . '"' . $is_selected . $disabled_attribute . '></td>';
echo '</tr>';
<div class="box"> <div class="box">
<h3><?php \esc_html_e( 'Server', 'activitypub' ); ?></h3> <h3><?php \esc_html_e( 'Server', 'activitypub' ); ?></h3>
<p><?php \esc_html_e( 'Server related settings.', 'activitypub' ); ?></p>
<table class="form-table"> <table class="form-table">
<tbody> <tbody>
<tr> <tr>

@ -1,12 +1,7 @@
$follower_count = \Activitypub\Collection\Followers::count_followers( \get_current_user_id() );
// translators: The follower count.
$followers_template = _n( 'Your author profile currently has %s follower.', 'Your author profile currently has %s followers.', $follower_count, 'activitypub' );
<div class="wrap"> <div class="wrap">
<h1><?php \esc_html_e( 'Author Followers', 'activitypub' ); ?></h1> <h1><?php \esc_html_e( 'Followers', 'activitypub' ); ?></h1>
<p><?php \printf( \esc_html( $followers_template ), \esc_attr( $follower_count ) ); ?></p> <?php // translators: The follower count. ?>
<p><?php \printf( \esc_html__( 'You currently have %s followers.', 'activitypub' ), \esc_attr( \Activitypub\Collection\Followers::count_followers( \get_current_user_id() ) ) ); ?></p>
<?php $table = new \Activitypub\Table\Followers(); ?> <?php $table = new \Activitypub\Table\Followers(); ?>
@ -14,8 +9,8 @@ $followers_template = _n( 'Your author profile currently has %s follower.', 'You
<input type="hidden" name="page" value="activitypub-followers-list" /> <input type="hidden" name="page" value="activitypub-followers-list" />
<?php <?php
$table->prepare_items(); $table->prepare_items();
$table->search_box( 'Search', 'search' );
$table->display(); $table->display();
?> ?>
<?php wp_nonce_field( 'activitypub-followers-list', '_apnonce' ); ?>
</form> </form>
</div> </div>

@ -7,7 +7,7 @@ $user = \Activitypub\Collection\Users::get_by_id( \get_current_user_id() ); ?>
<tbody> <tbody>
<tr> <tr>
<th scope="row"> <th scope="row">
<label><?php \esc_html_e( 'Profile URL', 'activitypub' ); ?></label> <label><?php \esc_html_e( 'Profile identifier', 'activitypub' ); ?></label>
</th> </th>
<td> <td>
<p> <p>
@ -15,7 +15,7 @@ $user = \Activitypub\Collection\Users::get_by_id( \get_current_user_id() ); ?>
<code><?php echo \esc_url( $user->get_url() ); ?></code> <code><?php echo \esc_url( $user->get_url() ); ?></code>
</p> </p>
<?php // translators: the webfinger resource ?> <?php // translators: the webfinger resource ?>
<p class="description"><?php \printf( \esc_html__( 'Follow "@%s" by searching for it on Mastodon, Friendica, etc.', 'activitypub' ), \esc_html( $user->get_resource() ) ); ?></p> <p class="description"><?php \printf( \esc_html__( 'Try to follow "@%s" by searching for it on Mastodon,Friendica & Co.', 'activitypub' ), \esc_html( $user->get_resource() ) ); ?></p>
</td> </td>
</tr> </tr>
<tr class="activitypub-user-description-wrap"> <tr class="activitypub-user-description-wrap">

@ -14,7 +14,7 @@
<div class="box"> <div class="box">
<h2><?php \esc_html_e( 'Welcome', 'activitypub' ); ?></h2> <h2><?php \esc_html_e( 'Welcome', 'activitypub' ); ?></h2>
<p><?php echo wp_kses( \__( 'Enter the fediverse with <strong>ActivityPub</strong>, broadcasting your blog to a wider audience. Attract followers, deliver updates, and receive comments from a diverse user base on <strong>Mastodon</strong>, <strong>Friendica</strong>, <strong>Pleroma</strong>, <strong>Pixelfed</strong>, and all <strong>ActivityPub</strong>-compliant platforms.', 'activitypub' ), array( 'strong' => array() ) ); ?></p> <p><?php echo wp_kses( \__( 'With ActivityPub your blog becomes part of a federated social network. This means you can share and talk to everyone using the <strong>ActivityPub</strong> protocol, including users of <strong>Friendica</strong>, <strong>Pleroma</strong>, <strong>Pixelfed</strong> and <strong>Mastodon</strong>.', 'activitypub' ), array( 'strong' => array() ) ); ?></p>
</div> </div>
<?php <?php
@ -22,28 +22,28 @@
$blog_user = new \Activitypub\Model\Blog_User(); $blog_user = new \Activitypub\Model\Blog_User();
?> ?>
<div class="box"> <div class="box">
<h3><?php \esc_html_e( 'Blog profile', 'activitypub' ); ?></h3> <h3><?php \esc_html_e( 'Blog Account', 'activitypub' ); ?></h3>
<p> <p>
<?php \esc_html_e( 'People can follow your blog by using:', 'activitypub' ); ?> <?php \esc_html_e( 'People can follow your Blog by using:', 'activitypub' ); ?>
</p> </p>
<p> <p>
<label for="activitypub-blog-identifier"><?php \esc_html_e( 'Username', 'activitypub' ); ?></label> <label for="activitypub-blog-identifier"><?php \esc_html_e( 'Username', 'activitypub' ); ?></label>
</p> </p>
<p> <p>
<input type="text" class="regular-text" id="activitypub-blog-identifier" value="<?php echo \esc_attr( $blog_user->get_resource() ); ?>" readonly /> <input type="text" class="regular-text" id="activitypub-blog-identifier" value="<?php echo \esc_attr( $blog_user->get_resource() ); ?>" />
</p> </p>
<p> <p>
<label for="activitypub-blog-url"><?php \esc_html_e( 'Profile URL', 'activitypub' ); ?></label> <label for="activitypub-blog-url"><?php \esc_html_e( 'Profile-URL', 'activitypub' ); ?></label>
</p> </p>
<p> <p>
<input type="text" class="regular-text" id="activitypub-blog-url" value="<?php echo \esc_attr( $blog_user->get_url() ); ?>" readonly /> <input type="text" class="regular-text" id="activitypub-blog-url" value="<?php echo \esc_attr( $blog_user->get_url() ); ?>" />
</p> </p>
<p> <p>
<?php \esc_html_e( 'This blog profile will federate all posts written on your blog, regardless of the author who posted it.', 'activitypub' ); ?> <?php \esc_html_e( 'This Blog-User will federate all posts written on your Blog, regardless of the User who posted it.', 'activitypub' ); ?>
<p> <p>
<p> <p>
<a href="<?php echo \esc_url_raw( \admin_url( '/options-general.php?page=activitypub&tab=settings' ) ); ?>"> <a href="<?php echo \esc_url_raw( \admin_url( '/options-general.php?page=activitypub&tab=settings' ) ); ?>">
<?php \esc_html_e( 'Customize the blog profile', 'activitypub' ); ?> <?php \esc_html_e( 'Customize Blog-User on Settings page.', 'activitypub' ); ?>
</a> </a>
</p> </p>
</div> </div>
@ -54,28 +54,28 @@
$user = \Activitypub\Collection\Users::get_by_id( wp_get_current_user()->ID ); $user = \Activitypub\Collection\Users::get_by_id( wp_get_current_user()->ID );
?> ?>
<div class="box"> <div class="box">
<h3><?php \esc_html_e( 'Author profile', 'activitypub' ); ?></h3> <h3><?php \esc_html_e( 'Personal Account', 'activitypub' ); ?></h3>
<p> <p>
<?php \esc_html_e( 'People can follow you by using your author name:', 'activitypub' ); ?> <?php \esc_html_e( 'People can follow you by using your Username:', 'activitypub' ); ?>
</p> </p>
<p> <p>
<label for="activitypub-user-identifier"><?php \esc_html_e( 'Username', 'activitypub' ); ?></label> <label for="activitypub-user-identifier"><?php \esc_html_e( 'Username', 'activitypub' ); ?></label>
</p> </p>
<p> <p>
<input type="text" class="regular-text" id="activitypub-user-identifier" value="<?php echo \esc_attr( $user->get_resource() ); ?>" readonly /> <input type="text" class="regular-text" id="activitypub-user-identifier" value="<?php echo \esc_attr( $user->get_resource() ); ?>" />
</p> </p>
<p> <p>
<label for="activitypub-user-url"><?php \esc_html_e( 'Profile URL', 'activitypub' ); ?></label> <label for="activitypub-user-url"><?php \esc_html_e( 'Profile-URL', 'activitypub' ); ?></label>
</p> </p>
<p> <p>
<input type="text" class="regular-text" id="activitypub-user-url" value="<?php echo \esc_attr( $user->get_url() ); ?>" readonly /> <input type="text" class="regular-text" id="activitypub-user-url" value="<?php echo \esc_attr( $user->get_url() ); ?>" />
</p> </p>
<p> <p>
<?php \esc_html_e( 'Authors who can not access this settings page will find their username on the "Edit Profile" page.', 'activitypub' ); ?> <?php \esc_html_e( 'Users who can not access this settings page will find their username on the "Edit Profile" page.', 'activitypub' ); ?>
<p> <p>
<p> <p>
<a href="<?php echo \esc_url_raw( \admin_url( '/profile.php#activitypub' ) ); ?>"> <a href="<?php echo \esc_url_raw( \admin_url( '/profile.php#activitypub' ) ); ?>">
<?php \esc_html_e( 'Customize username on "Edit Profile" page.', 'activitypub' ); ?> <?php \esc_html_e( 'Customize Username on "Edit Profile" page.', 'activitypub' ); ?>
</a> </a>
</p> </p>
</div> </div>
@ -87,9 +87,9 @@
<?php <?php
echo wp_kses( echo wp_kses(
\sprintf( \sprintf(
/* translators: the placeholder is the Site Health URL */ // translators:
\__( \__(
'If you have problems using this plugin, please check the <a href="%s">Site Health</a> page to ensure that your site is compatible and/or use the "Help" tab (in the top right of the settings pages).', 'If you have problems using this plugin, please check the <a href="%s">Site Health</a> to ensure that your site is compatible and/or use the "Help" tab (in the top right of the settings pages).',
'activitypub' 'activitypub'
), ),
\esc_url_raw( admin_url( 'site-health.php' ) ) \esc_url_raw( admin_url( 'site-health.php' ) )

@ -17,8 +17,7 @@ class Test_Activitypub_Activity extends WP_UnitTestCase {
10 10
); );
$wp_post = get_post( $post ); $activitypub_post = \Activitypub\Transformer\Post::transform( get_post( $post ) )->to_object();
$activitypub_post = \Activitypub\Transformer\Transformers_Manager::instance()->get_transformer( $post )->to_object();
$activitypub_activity = new \Activitypub\Activity\Activity(); $activitypub_activity = new \Activitypub\Activity\Activity();
$activitypub_activity->set_type( 'Create' ); $activitypub_activity->set_type( 'Create' );

View file

@ -35,15 +35,14 @@ ENDPRE;
array( 'test', 'test' ), array( 'test', 'test' ),
array( '#test', '#test' ), array( '#test', '#test' ),
array( 'hallo #test test', 'hallo #test test' ), array( 'hallo #test test', 'hallo #test test' ),
array( 'hallo #object test', 'hallo <a rel="tag" class="hashtag u-tag u-category" href="%s">#object</a> test' ), array( 'hallo #object test', 'hallo <a rel="tag" class="u-tag u-category" href="%s">#object</a> test' ),
array( '#object test', '<a rel="tag" class="hashtag u-tag u-category" href="%s">#object</a> test' ), array( '#object test', '<a rel="tag" class="u-tag u-category" href="%s">#object</a> test' ),
array( 'hallo <a href="http://test.test/#object">test</a> test', 'hallo <a href="http://test.test/#object">test</a> test' ), array( 'hallo <a href="http://test.test/#object">test</a> test', 'hallo <a href="http://test.test/#object">test</a> test' ),
array( 'hallo <a href="http://test.test/#object">#test</a> test', 'hallo <a href="http://test.test/#object">#test</a> test' ), array( 'hallo <a href="http://test.test/#object">#test</a> test', 'hallo <a href="http://test.test/#object">#test</a> test' ),
array( '<div>hallo #object test</div>', '<div>hallo <a rel="tag" class="hashtag u-tag u-category" href="%s">#object</a> test</div>' ), array( '<div>hallo #object test</div>', '<div>hallo <a rel="tag" class="u-tag u-category" href="%s">#object</a> test</div>' ),
array( '<div>hallo #object</div>', '<div>hallo <a rel="tag" class="hashtag u-tag u-category" href="%s">#object</a></div>' ), array( '<div>hallo #object</div>', '<div>hallo <a rel="tag" class="u-tag u-category" href="%s">#object</a></div>' ),
array( '<div>#object</div>', '<div><a rel="tag" class="hashtag u-tag u-category" href="%s">#object</a></div>' ), array( '<div>#object</div>', '<div>#object</div>' ),
array( '<a>#object</a>', '<a>#object</a>' ), array( '<a>#object</a>', '<a>#object</a>' ),
array( '<!-- #object -->', '<!-- #object -->' ),
array( '<div style="color: #ccc;">object</a>', '<div style="color: #ccc;">object</a>' ), array( '<div style="color: #ccc;">object</a>', '<div style="color: #ccc;">object</a>' ),
array( $code, $code ), array( $code, $code ),
array( $style, $style ), array( $style, $style ),

Some files were not shown because too many files have changed in this diff Show more