No description
Find a file
Oneric 59fcb5c96e
api: ensure only visible posts are interactable
Port of Akkoma PR 1014 with a few changes:
- comments regarding akkomafe changed to Pleroma-FE when applicable
- different error message for replying to/interacting with invisible post
  in Pleroma.Web.CommonAPI.ActivityDraft.in_reply_to/1
- split "doesn't do funny things to other users favs" test into three:
  - can't unfavourite post that isn't favourited
  - can't unfavourite other user's favs
  - can't unfavourite other user's favs using their activity
- switched order of args for some CommonAPI function since Akkoma hasn't
  backported our old change for that

Pleroma.Web.CommonAPI.ActivityDraft.in_reply_to/1 now refactored to use
`with` statement as in Akkoma. Some defp in_reply_to/1 were therefore removed

Original PR author: Oneric
Original commit message:
It doesn't make sense to like, react, reply, etc to something you cannot
see and is unexpected for the author of the interacted with post and
might make them believe the reacting user actually _can_ see the post.

Wrt to fav, reblog, reaction indexes the missing visibility check was
also leaking some (presumably/hopefully) low-severity data.

Add full-API test for all modes of interactions with private posts.
2025-12-11 23:30:02 +01:00
.gitlab Update MR template to include the type 'change' 2023-11-08 09:37:08 -05:00
benchmarks Ensure benchee doesn't run unless we are executing benchmarks 2023-11-08 12:44:57 -05:00
changelog.d Add changelog 2025-12-10 14:56:06 +01:00
ci Replace Elixir 1.17 with 1.18 for build unit-testing pipelines 2025-05-24 22:17:38 +02:00
config Merge branch 'rich-media-user-agent' into 'develop' 2025-11-29 17:25:18 +01:00
docs Merge branch 'mastodon-quotes-updates' into 'develop' 2025-12-02 14:34:16 +01:00
installation Merge branch 'openbsd-docs' into 'develop' 2025-06-06 00:59:58 +00:00
lib api: ensure only visible posts are interactable 2025-12-11 23:30:02 +01:00
priv Merge branch 'hj-develop-patch-37634' into 'develop' 2025-12-08 18:28:55 +00:00
rel Disable busywaits in releases 2024-10-25 11:34:54 -04:00
restarter Bump minimum Elixir version to 1.10 2022-09-02 22:53:54 +02:00
supplemental/search/fastembed-api Fastembed Server: Add health check endpoint 2024-05-27 14:15:04 +04:00
test api: ensure only visible posts are interactable 2025-12-11 23:30:02 +01:00
tools Fix changelog checker 2025-11-07 19:47:54 +03:00
.buildpacks CI: Add auto-deployment via dokku. 2019-05-31 10:55:35 +02:00
.credo.exs Tell newer Credo it's OK to exit 0 on single with clauses and piping into anonymous functions for now 2022-11-13 18:46:02 -05:00
.dialyzer_ignore.exs Quiet Dialyzer 2024-07-25 16:36:34 -04:00
.dockerignore remove docs/ from .dockerignore 2019-11-20 00:09:07 +09:00
.formatter.exs .formatter.exs: Format optional migrations 2021-01-10 11:28:41 +03:00
.gitattributes [#3112] .gitattributes fix. 2020-12-09 18:43:20 +03:00
.gitignore Do not allow committing tests with a .ex extension 2024-08-07 13:07:54 -04:00
.gitlab-ci.yml CI: Use the dotenv report method to capture the spec-build internal job id and pass it through to the spec-deploy job 2025-10-23 21:14:12 -07:00
.mailmap Add myself to .mailmap 2021-02-15 13:19:44 +03:00
.rgignore Add .rgignore for easier grepping 2023-12-10 17:06:28 +04:00
AGPL-3 LICENSE → AGPL-3 2019-04-01 00:31:21 +02:00
CC-BY-4.0 Add a copy of CC-BY-4.0 to the repo 2020-09-06 11:38:38 +03:00
CC-BY-SA-4.0 CC-BY-SA-4.0: Add a copy of the CC-BY-SA-4.0 license 2019-04-01 00:30:21 +02:00
CHANGELOG.md Update changelog 2025-03-11 18:06:43 +04:00
COPYING Revert "Merge branch 'copyright-bump' into 'develop'" 2023-01-02 20:38:50 +00:00
coveralls.json exclude file_location check from coveralls 2020-10-13 16:44:01 +03:00
docker-entrypoint.sh allow custom db port 2022-11-11 12:22:21 -03:00
Dockerfile Dockerfile: Sync with CI, make more resilient 2025-08-27 14:07:21 +04:00
elixir_buildpack.config Bump minimum Elixir version to 1.10 2022-09-02 22:53:54 +02:00
mix.exs Mix: Remove double lazarus 2025-09-04 15:49:57 +04:00
mix.lock Add Oban.Plugins.Lazarus 2025-08-29 09:16:23 -07:00
Procfile CI: Add auto-deployment via dokku. 2019-05-31 10:55:35 +02:00
README.md README.md: Update packaging state (GURU, AUR) 2023-06-27 21:13:02 +02:00
SECURITY.md SECURITY.md: update supported versions to only 2.2 2020-10-15 21:45:31 +03:00

About

Pleroma is a microblogging server software that can federate (= exchange messages with) other servers that support ActivityPub. What that means is that you can host a server for yourself or your friends and stay in control of your online identity, but still exchange messages with people on larger servers. Pleroma will federate with all servers that implement ActivityPub, like Friendica, GNU Social, Hubzilla, Mastodon, Misskey, Peertube, and Pixelfed.

Pleroma is written in Elixir and uses PostgresSQL for data storage. It's efficient enough to be ran on low-power devices like Raspberry Pi (though we wouldn't recommend storing the database on the internal SD card ;) but can scale well when ran on more powerful hardware (albeit only single-node for now).

For clients it supports the Mastodon client API with Pleroma extensions (see the API section on https://docs-develop.pleroma.social).

Installation

If you are running Linux (glibc or musl) on x86/arm, the recommended way to install Pleroma is by using OTP releases. OTP releases are as close as you can get to binary releases with Erlang/Elixir. The release is self-contained, and provides everything needed to boot it. The installation instructions are available here.

From Source

If your platform is not supported, or you just want to be able to edit the source code easily, you may install Pleroma from source.

OS/Distro packages

Currently Pleroma is packaged for YunoHost, NixOS, Gentoo through GURU and Archlinux through AUR. You may find more at https://repology.org/project/pleroma/versions.
If you want to package Pleroma for any OS/Distros, we can guide you through the process on our community channels. If you want to change default options in your Pleroma package, please discuss it with us first.

Docker

While we dont provide docker files, other people have written very good ones. Take a look at https://github.com/angristan/docker-pleroma or https://glitch.sh/sn0w/pleroma-docker.

Raspberry Pi

Community maintained Raspberry Pi image that you can flash and run Pleroma on your Raspberry Pi. Available here https://github.com/guysoft/PleromaPi.

Compilation Troubleshooting

If you ever encounter compilation issues during the updating of Pleroma, you can try these commands and see if they fix things:

  • mix deps.clean --all
  • mix local.rebar
  • mix local.hex
  • rm -r _build

If you are not developing Pleroma, it is better to use the OTP release, which comes with everything precompiled.

Documentation

Community Channels