format.c 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511
  1. /* snac - A simple, minimalistic ActivityPub instance */
  2. /* copyright (c) 2022 - 2025 grunfink et al. / MIT license */
  3. #include "xs.h"
  4. #include "xs_regex.h"
  5. #include "xs_mime.h"
  6. #include "xs_html.h"
  7. #include "xs_json.h"
  8. #include "xs_time.h"
  9. #include "xs_match.h"
  10. #include "snac.h"
  11. /* emoticons, people laughing and such */
  12. const char *smileys[] = {
  13. ":-)", "🙂",
  14. ":-D", "😀",
  15. "X-D", "😆",
  16. ";-)", "😉",
  17. "B-)", "😎",
  18. ">:-(", "😡",
  19. ":-(", "😞",
  20. ":-*", "😘",
  21. ":-/", "😕",
  22. "8-o", "😲",
  23. "%-)", "🤪",
  24. ":_(", "😢",
  25. ":-|", "😐",
  26. "<3", "&#10084;&#65039;",
  27. ":facepalm:", "&#129318;",
  28. ":shrug:", "&#129335;",
  29. ":shrug2:", "&#175;\\_(&#12484;)_/&#175;",
  30. ":eyeroll:", "&#128580;",
  31. ":beer:", "&#127866;",
  32. ":beers:", "&#127867;",
  33. ":munch:", "&#128561;",
  34. ":thumb:", "&#128077;",
  35. NULL, NULL
  36. };
  37. xs_dict *emojis(void)
  38. /* returns a dict with the emojis */
  39. {
  40. xs *fn = xs_fmt("%s/emojis.json", srv_basedir);
  41. FILE *f;
  42. if (mtime(fn) == 0) {
  43. /* file does not exist; create it with the defaults */
  44. xs *d = xs_dict_new();
  45. const char **emo = smileys;
  46. while (*emo) {
  47. d = xs_dict_append(d, emo[0], emo[1]);
  48. emo += 2;
  49. }
  50. if ((f = fopen(fn, "w")) != NULL) {
  51. xs_json_dump(d, 4, f);
  52. fclose(f);
  53. }
  54. else
  55. srv_log(xs_fmt("Error creating '%s'", fn));
  56. }
  57. xs_dict *d = NULL;
  58. if ((f = fopen(fn, "r")) != NULL) {
  59. d = xs_json_load(f);
  60. fclose(f);
  61. if (d == NULL)
  62. srv_log(xs_fmt("JSON parse error in '%s'", fn));
  63. }
  64. else
  65. srv_log(xs_fmt("Error opening '%s'", fn));
  66. return d;
  67. }
  68. /* Non-whitespace without trailing comma, period or closing paren */
  69. #define NOSPACE "([^[:space:],.)]+|[,.)]+[^[:space:],.)])+"
  70. static xs_str *format_line(const char *line, xs_list **attach)
  71. /* formats a line */
  72. {
  73. xs_str *s = xs_str_new(NULL);
  74. char *p;
  75. const char *v;
  76. /* split by markup */
  77. xs *sm = xs_regex_split(line,
  78. "("
  79. "`[^`]+`" "|"
  80. "~~[^~]+~~" "|"
  81. "\\*\\*?\\*?[^\\*]+\\*?\\*?\\*" "|"
  82. "__[^_]+__" "|" //anzu
  83. "!\\[[^]]+\\]\\([^\\)]+\\)" "|"
  84. "\\[[^]]+\\]\\([^\\)]+\\)" "|"
  85. "[a-z]+:/" "/" NOSPACE "|"
  86. "(mailto|xmpp):[^@[:space:]]+@" NOSPACE
  87. ")");
  88. int n = 0;
  89. p = sm;
  90. while (xs_list_iter(&p, &v)) {
  91. if ((n & 0x1)) {
  92. /* markup */
  93. if (xs_startswith(v, "`")) {
  94. xs *s1 = xs_strip_chars_i(xs_dup(v), "`");
  95. xs *e1 = encode_html(s1);
  96. xs *s2 = xs_fmt("<code>%s</code>", e1);
  97. s = xs_str_cat(s, s2);
  98. }
  99. else
  100. if (xs_startswith(v, "***")) {
  101. xs *s1 = xs_strip_chars_i(xs_dup(v), "*");
  102. xs *s2 = xs_fmt("<b><i>%s</i></b>", s1);
  103. s = xs_str_cat(s, s2);
  104. }
  105. else
  106. if (xs_startswith(v, "**")) {
  107. xs *s1 = xs_strip_chars_i(xs_dup(v), "*");
  108. xs *s2 = xs_fmt("<b>%s</b>", s1);
  109. s = xs_str_cat(s, s2);
  110. }
  111. else
  112. if (xs_startswith(v, "*")) {
  113. xs *s1 = xs_strip_chars_i(xs_dup(v), "*");
  114. xs *s2 = xs_fmt("<i>%s</i>", s1);
  115. s = xs_str_cat(s, s2);
  116. }
  117. //anzu - begin
  118. else
  119. if (xs_startswith(v, "__")) {
  120. xs *s1 = xs_strip_chars_i(xs_dup(v), "_");
  121. xs *s2 = xs_fmt("<u>%s</u>", s1);
  122. s = xs_str_cat(s, s2);
  123. }
  124. //anzu - end
  125. else
  126. if (xs_startswith(v, "~~")) {
  127. xs *s1 = xs_strip_chars_i(xs_dup(v), "~");
  128. xs *e1 = encode_html(s1);
  129. xs *s2 = xs_fmt("<s>%s</s>", e1);
  130. s = xs_str_cat(s, s2);
  131. }
  132. else
  133. if (*v == '[') {
  134. /* markdown-like links [label](url) */
  135. xs *w = xs_strip_chars_i(
  136. xs_replace_i(xs_replace(v, "#", "&#35;"), "@", "&#64;"),
  137. "![)");
  138. xs *l = xs_split_n(w, "](", 1);
  139. if (xs_list_len(l) == 2) {
  140. const char *name = xs_list_get(l, 0);
  141. const char *url = xs_list_get(l, 1);
  142. xs *link = xs_fmt("<a href=\"%s\">%s</a>", url, name);
  143. s = xs_str_cat(s, link);
  144. /* also add the link as an attachment */
  145. xs *d = xs_dict_new();
  146. d = xs_dict_append(d, "mediaType", "text/html");
  147. d = xs_dict_append(d, "url", url);
  148. d = xs_dict_append(d, "name", name);
  149. d = xs_dict_append(d, "type", "Link");
  150. *attach = xs_list_append(*attach, d);
  151. }
  152. else
  153. s = xs_str_cat(s, v);
  154. }
  155. else
  156. if (*v == '!') {
  157. /* markdown-like images ![alt text](url to image) */
  158. xs *w = xs_strip_chars_i(
  159. xs_replace_i(xs_replace(v, "#", "&#35;"), "@", "&#64;"),
  160. "![)");
  161. xs *l = xs_split_n(w, "](", 1);
  162. if (xs_list_len(l) == 2) {
  163. const char *alt_text = xs_list_get(l, 0);
  164. const char *img_url = xs_list_get(l, 1);
  165. const char *mime = xs_mime_by_ext(img_url);
  166. if (attach != NULL && xs_startswith(mime, "image/")) {
  167. const xs_dict *ad;
  168. int add = 1;
  169. xs_list_foreach(*attach, ad) {
  170. if (strcmp(xs_dict_get_def(ad, "url", ""), img_url) == 0) {
  171. add = 0;
  172. break;
  173. }
  174. }
  175. if (add) {
  176. xs *d = xs_dict_new();
  177. d = xs_dict_append(d, "mediaType", mime);
  178. d = xs_dict_append(d, "url", img_url);
  179. d = xs_dict_append(d, "name", alt_text);
  180. d = xs_dict_append(d, "type", "Image");
  181. *attach = xs_list_append(*attach, d);
  182. }
  183. }
  184. else {
  185. xs *link = xs_fmt("<a href=\"%s\">%s</a>", img_url, alt_text);
  186. s = xs_str_cat(s, link);
  187. }
  188. }
  189. else
  190. s = xs_str_cat(s, v);
  191. }
  192. else
  193. if (xs_str_in(v, ":/" "/") != -1) {
  194. /* direct URLs in the post body */
  195. xs *u = xs_replace_i(xs_replace(v, "#", "&#35;"), "@", "&#64;");
  196. xs *v2 = xs_strip_chars_i(xs_dup(u), ".,)");
  197. const char *mime = xs_mime_by_ext(v2);
  198. if (attach != NULL && xs_startswith(mime, "image/")) {
  199. /* if it's a link to an image, insert it as an attachment */
  200. const xs_dict *ad;
  201. int add = 1;
  202. xs_list_foreach(*attach, ad) {
  203. if (strcmp(xs_dict_get_def(ad, "url", ""), v2) == 0) {
  204. add = 0;
  205. break;
  206. }
  207. }
  208. if (add) {
  209. xs *d = xs_dict_new();
  210. d = xs_dict_append(d, "mediaType", mime);
  211. d = xs_dict_append(d, "url", v2);
  212. d = xs_dict_append(d, "name", "");
  213. d = xs_dict_append(d, "type", "Image");
  214. *attach = xs_list_append(*attach, d);
  215. }
  216. }
  217. else {
  218. xs *s1 = xs_fmt("<a href=\"%s\" target=\"_blank\">%s</a>", v2, u);
  219. s = xs_str_cat(s, s1);
  220. /* also add the link as an attachment */
  221. xs *d = xs_dict_new();
  222. d = xs_dict_append(d, "mediaType", "text/html");
  223. d = xs_dict_append(d, "url", v2);
  224. d = xs_dict_append(d, "name", "");
  225. d = xs_dict_append(d, "type", "Link");
  226. *attach = xs_list_append(*attach, d);
  227. }
  228. }
  229. else
  230. if (xs_match(v, "mailto*|xmpp*")) {
  231. xs *u = xs_replace_i(xs_replace(v, "#", "&#35;"), "@", "&#64;");
  232. xs *v2 = xs_strip_chars_i(xs_dup(u), ".,)");
  233. xs *s1 = xs_fmt("<a href=\"%s\" target=\"_blank\">%s</a>", v2, u);
  234. s = xs_str_cat(s, s1);
  235. }
  236. else
  237. s = xs_str_cat(s, v);
  238. }
  239. else
  240. /* surrounded text, copy directly */
  241. s = xs_str_cat(s, v);
  242. n++;
  243. }
  244. return s;
  245. }
  246. xs_str *not_really_markdown(const char *content, xs_list **attach, xs_list **tag)
  247. /* formats a content using some Markdown rules */
  248. {
  249. xs_str *s = xs_str_new(NULL);
  250. int in_pre = 0;
  251. int in_blq = 0;
  252. xs *list;
  253. char *p;
  254. const char *v;
  255. /* work by lines */
  256. list = xs_split(content, "\n");
  257. p = list;
  258. while (xs_list_iter(&p, &v)) {
  259. xs *ss = NULL;
  260. if (strcmp(v, "```") == 0) {
  261. if (!in_pre)
  262. s = xs_str_cat(s, "<pre>");
  263. else
  264. s = xs_str_cat(s, "</pre>");
  265. in_pre = !in_pre;
  266. continue;
  267. }
  268. if (in_pre) {
  269. // Encode all HTML characters when we're in pre element until we are out.
  270. ss = encode_html(v);
  271. s = xs_str_cat(s, ss);
  272. s = xs_str_cat(s, "<br>");
  273. continue;
  274. }
  275. else
  276. ss = xs_strip_i(format_line(v, attach));
  277. if (xs_startswith(ss, "---")) {
  278. /* delete the --- */
  279. ss = xs_strip_i(xs_crop_i(ss, 3, 0));
  280. s = xs_str_cat(s, "<hr>");
  281. s = xs_str_cat(s, ss);
  282. continue;
  283. }
  284. //anzu - begin
  285. // h1 reserved for snac?
  286. if (xs_startswith(ss, "# ")) {
  287. ss = xs_strip_i(xs_crop_i(ss, 2, 0));
  288. s = xs_str_cat(s, "<h2>");
  289. s = xs_str_cat(s, ss);
  290. s = xs_str_cat(s, "</h2>");
  291. continue;
  292. }
  293. if (xs_startswith(ss, "## ")) {
  294. ss = xs_strip_i(xs_crop_i(ss, 3, 0));
  295. s = xs_str_cat(s, "<h2>");
  296. s = xs_str_cat(s, ss);
  297. s = xs_str_cat(s, "</h2>");
  298. continue;
  299. }
  300. if (xs_startswith(ss, "### ")) {
  301. ss = xs_strip_i(xs_crop_i(ss, 4, 0));
  302. s = xs_str_cat(s, "<h3>");
  303. s = xs_str_cat(s, ss);
  304. s = xs_str_cat(s, "</h3>");
  305. continue;
  306. }
  307. //anzu - end
  308. if (xs_startswith(ss, ">")) {
  309. /* delete the > and subsequent spaces */
  310. ss = xs_strip_i(xs_crop_i(ss, 1, 0));
  311. if (!in_blq) {
  312. s = xs_str_cat(s, "<blockquote>");
  313. in_blq = 1;
  314. }
  315. s = xs_str_cat(s, ss);
  316. s = xs_str_cat(s, "<br>");
  317. continue;
  318. }
  319. if (in_blq) {
  320. s = xs_str_cat(s, "</blockquote>");
  321. in_blq = 0;
  322. }
  323. s = xs_str_cat(s, ss);
  324. s = xs_str_cat(s, "<br>");
  325. }
  326. if (in_blq)
  327. s = xs_str_cat(s, "</blockquote>");
  328. if (in_pre)
  329. s = xs_str_cat(s, "</pre>");
  330. /* some beauty fixes */
  331. s = xs_replace_i(s, "<br><br><blockquote>", "<br><blockquote>");
  332. s = xs_replace_i(s, "</blockquote><br>", "</blockquote>");
  333. s = xs_replace_i(s, "</pre><br>", "</pre>");
  334. s = xs_replace_i(s, "</h2><br>", "</h2>"); //anzu ???
  335. s = xs_replace_i(s, "</h3><br>", "</h3>"); //anzu ???
  336. {
  337. /* traditional emoticons */
  338. xs *d = emojis();
  339. int c = 0;
  340. const char *k, *v;
  341. while (xs_dict_next(d, &k, &v, &c)) {
  342. const char *t = NULL;
  343. /* is it an URL to an image? */
  344. if (xs_startswith(v, "https:/" "/") && xs_startswith((t = xs_mime_by_ext(v)), "image/")) {
  345. if (tag && xs_str_in(s, k) != -1) {
  346. /* add the emoji to the tag list */
  347. xs *e = xs_dict_new();
  348. xs *i = xs_dict_new();
  349. xs *u = xs_str_utctime(0, ISO_DATE_SPEC);
  350. e = xs_dict_append(e, "id", v);
  351. e = xs_dict_append(e, "type", "Emoji");
  352. e = xs_dict_append(e, "name", k);
  353. e = xs_dict_append(e, "updated", u);
  354. i = xs_dict_append(i, "type", "Image");
  355. i = xs_dict_append(i, "mediaType", t);
  356. i = xs_dict_append(i, "url", v);
  357. e = xs_dict_append(e, "icon", i);
  358. *tag = xs_list_append(*tag, e);
  359. }
  360. }
  361. else
  362. s = xs_replace_i(s, k, v);
  363. }
  364. }
  365. return s;
  366. }
  367. const char *valid_tags[] = {
  368. "a", "p", "br", "br/", "blockquote", "ul", "ol", "li", "cite", "small",
  369. "span", "i", "b", "u", "s", "pre", "code", "em", "strong", "hr", "img", "del", "bdi",
  370. "h2","h3", //anzu
  371. NULL
  372. };
  373. xs_str *sanitize(const char *content)
  374. /* cleans dangerous HTML output */
  375. {
  376. xs_str *s = xs_str_new(NULL);
  377. xs *sl;
  378. int n = 0;
  379. char *p;
  380. const char *v;
  381. sl = xs_regex_split(content, "</?[^>]+>");
  382. p = sl;
  383. n = 0;
  384. while (xs_list_iter(&p, &v)) {
  385. if (n & 0x1) {
  386. xs *s1 = xs_strip_i(xs_crop_i(xs_dup(v), v[1] == '/' ? 2 : 1, -1));
  387. xs *l1 = xs_split_n(s1, " ", 1);
  388. xs *tag = xs_tolower_i(xs_dup(xs_list_get(l1, 0)));
  389. xs *s2 = NULL;
  390. int i;
  391. /* check if it's one of the valid tags */
  392. for (i = 0; valid_tags[i]; i++) {
  393. if (strcmp(tag, valid_tags[i]) == 0)
  394. break;
  395. }
  396. if (valid_tags[i]) {
  397. /* accepted tag: rebuild it with only the accepted elements */
  398. xs *el = xs_regex_select(v, "(src|href|rel|class|target)=(\"[^\"]*\"|'[^']*')");
  399. xs *s3 = xs_join(el, " ");
  400. s2 = xs_fmt("<%s%s%s%s>",
  401. v[1] == '/' ? "/" : "", tag, xs_list_len(el) ? " " : "", s3);
  402. s = xs_str_cat(s, s2);
  403. } else {
  404. /* treat end of divs as paragraph breaks */
  405. if (strcmp(v, "</div>"))
  406. s = xs_str_cat(s, "<p>");
  407. }
  408. }
  409. else {
  410. /* non-tag */
  411. s = xs_str_cat(s, v);
  412. }
  413. n++;
  414. }
  415. return s;
  416. }
  417. xs_str *encode_html(const char *str)
  418. /* escapes html characters */
  419. {
  420. xs_str *encoded = xs_html_encode((char *)str);
  421. /* Restore only <br>. Probably safe. Let's hope nothing goes wrong with this. */
  422. encoded = xs_replace_i(encoded, "&lt;br&gt;", "<br>");
  423. return encoded;
  424. }