1
0
mirror of https://git.pleroma.social/sjw/pleroma.git synced 2024-12-26 17:35:15 +01:00

activitypub: fetch_object_from_id(): prefer actor over attributedTo to avoid spoofing

This commit is contained in:
William Pitcock 2018-11-17 18:17:17 +00:00
parent 9c8adfb6ef
commit 603fccf175

View File

@ -747,7 +747,7 @@ defmodule Pleroma.Web.ActivityPub.ActivityPub do
"type" => "Create",
"to" => data["to"],
"cc" => data["cc"],
"actor" => data["attributedTo"],
"actor" => data["actor"] || data["attributedTo"],
"object" => data
},
:ok <- Transmogrifier.contain_origin(id, params),