4 * @file include/acl_selectors.php
7 require_once "include/contact_selectors.php";
8 require_once "include/contact_widgets.php";
9 require_once "include/DirSearch.php";
10 require_once "include/features.php";
11 require_once "mod/proxy.php";
15 * @package acl_selectors
17 function group_select($selname,$selclass,$preselected = false,$size = 4) {
23 $o .= "<select name=\"{$selname}[]\" id=\"$selclass\" class=\"$selclass\" multiple=\"multiple\" size=\"$size\" >\r\n";
25 $r = q("SELECT `id`, `name` FROM `group` WHERE NOT `deleted` AND `uid` = %d ORDER BY `name` ASC",
30 $arr = array('group' => $r, 'entry' => $o);
32 // e.g. 'network_pre_group_deny', 'profile_pre_group_allow'
34 call_hooks($a->module . '_pre_' . $selname, $arr);
36 if (dbm::is_result($r)) {
38 if ((is_array($preselected)) && in_array($rr['id'], $preselected)) {
39 $selected = " selected=\"selected\" ";
44 $trimmed = mb_substr($rr['name'],0,12);
46 $o .= "<option value=\"{$rr['id']}\" $selected title=\"{$rr['name']}\" >$trimmed</option>\r\n";
50 $o .= "</select>\r\n";
52 call_hooks($a->module . '_post_' . $selname, $o);
59 function contact_selector($selname, $selclass, $preselected = false, $options) {
69 if (is_array($options)) {
70 if (x($options, 'size'))
71 $size = $options['size'];
73 if (x($options, 'mutual_friends')) {
76 if (x($options, 'single')) {
79 if (x($options, 'multiple')) {
82 if (x($options, 'exclude')) {
83 $exclude = $options['exclude'];
86 if (x($options, 'networks')) {
87 switch($options['networks']) {
89 $networks = array(NETWORK_DFRN);
92 if (is_array($a->user) && $a->user['prvnets']) {
93 $networks = array(NETWORK_DFRN, NETWORK_MAIL, NETWORK_DIASPORA);
95 $networks = array(NETWORK_DFRN, NETWORK_FACEBOOK, NETWORK_MAIL, NETWORK_DIASPORA);
99 if (is_array($a->user) && $a->user['prvnets']) {
100 $networks = array(NETWORK_DFRN, NETWORK_MAIL, NETWORK_DIASPORA);
102 $networks = array(NETWORK_DFRN, NETWORK_FACEBOOK, NETWORK_MAIL, NETWORK_DIASPORA, NETWORK_OSTATUS);
105 default: /// @TODO Maybe log this call?
111 $x = array('options' => $options, 'size' => $size, 'single' => $single, 'mutual' => $mutual, 'exclude' => $exclude, 'networks' => $networks);
113 call_hooks('contact_select_options', $x);
119 if (x($x, 'mutual')) {
120 $sql_extra .= sprintf(" AND `rel` = %d ", intval(CONTACT_IS_FRIEND));
123 if (x($x, 'exclude')) {
124 $sql_extra .= sprintf(" AND `id` != %d ", intval($x['exclude']));
127 if (is_array($x['networks']) && count($x['networks'])) {
128 /// @TODO rewrite to foreach()
129 for ($y = 0; $y < count($x['networks']) ; $y ++) {
130 $x['networks'][$y] = "'" . dbesc($x['networks'][$y]) . "'";
132 $str_nets = implode(',', $x['networks']);
133 $sql_extra .= " AND `network` IN ( $str_nets ) ";
136 $tabindex = (x($options, 'tabindex') ? "tabindex=\"" . $options["tabindex"] . "\"" : "");
139 $o .= "<select name=\"$selname\" id=\"$selclass\" class=\"$selclass\" size=\"" . $x['size'] . "\" $tabindex >\r\n";
141 $o .= "<select name=\"{$selname}[]\" id=\"$selclass\" class=\"$selclass\" multiple=\"multiple\" size=\"" . $x['size'] . "$\" $tabindex >\r\n";
144 $r = q("SELECT `id`, `name`, `url`, `network` FROM `contact`
145 WHERE `uid` = %d AND NOT `self` AND NOT `blocked` AND NOT `pending` AND NOT `archive` AND `notify` != ''
147 ORDER BY `name` ASC ",
152 $arr = array('contact' => $r, 'entry' => $o);
154 // e.g. 'network_pre_contact_deny', 'profile_pre_contact_allow'
156 call_hooks($a->module . '_pre_' . $selname, $arr);
158 if (dbm::is_result($r)) {
159 foreach ($r as $rr) {
160 if ((is_array($preselected)) && in_array($rr['id'], $preselected)) {
161 $selected = " selected=\"selected\" ";
166 $trimmed = mb_substr($rr['name'],0,20);
168 $o .= "<option value=\"{$rr['id']}\" $selected title=\"{$rr['name']}|{$rr['url']}\" >$trimmed</option>\r\n";
173 $o .= "</select>\r\n";
175 call_hooks($a->module . '_post_' . $selname, $o);
182 function contact_select($selname, $selclass, $preselected = false, $size = 4, $privmail = false, $celeb = false, $privatenet = false, $tabindex = null) {
184 require_once "include/bbcode.php";
190 // When used for private messages, we limit correspondence to mutual DFRN/Friendica friends and the selector
191 // to one recipient. By default our selector allows multiple selects amongst all contacts.
195 if ($privmail || $celeb) {
196 $sql_extra .= sprintf(" AND `rel` = %d ", intval(CONTACT_IS_FRIEND));
200 $sql_extra .= sprintf(" AND `network` IN ('%s' , '%s') ",
201 NETWORK_DFRN, NETWORK_DIASPORA);
202 } elseif ($privatenet) {
203 $sql_extra .= sprintf(" AND `network` IN ('%s' , '%s', '%s', '%s') ",
204 NETWORK_DFRN, NETWORK_MAIL, NETWORK_FACEBOOK, NETWORK_DIASPORA);
207 $tabindex = ($tabindex > 0 ? "tabindex=\"$tabindex\"" : "");
209 if ($privmail AND $preselected) {
210 $sql_extra .= " AND `id` IN (".implode(",", $preselected).")";
211 $hidepreselected = ' style="display: none;"';
213 $hidepreselected = "";
217 $o .= "<select name=\"$selname\" id=\"$selclass\" class=\"$selclass\" size=\"$size\" $tabindex $hidepreselected>\r\n";
219 $o .= "<select name=\"{$selname}[]\" id=\"$selclass\" class=\"$selclass\" multiple=\"multiple\" size=\"$size\" $tabindex >\r\n";
222 $r = q("SELECT `id`, `name`, `url`, `network` FROM `contact`
223 WHERE `uid` = %d AND NOT `self` AND NOT `blocked` AND NOT `pending` AND NOT `archive` AND `notify` != ''
225 ORDER BY `name` ASC ",
230 $arr = array('contact' => $r, 'entry' => $o);
232 // e.g. 'network_pre_contact_deny', 'profile_pre_contact_allow'
234 call_hooks($a->module . '_pre_' . $selname, $arr);
236 $receiverlist = array();
238 if (dbm::is_result($r)) {
239 foreach ($r as $rr) {
240 if ((is_array($preselected)) && in_array($rr['id'], $preselected)) {
241 $selected = " selected=\"selected\" ";
247 $trimmed = GetProfileUsername($rr['url'], $rr['name'], false);
249 $trimmed = mb_substr($rr['name'],0,20);
252 $receiverlist[] = $trimmed;
254 $o .= "<option value=\"{$rr['id']}\" $selected title=\"{$rr['name']}|{$rr['url']}\" >$trimmed</option>\r\n";
259 $o .= "</select>\r\n";
261 if ($privmail AND $preselected) {
262 $o .= implode(", ", $receiverlist);
265 call_hooks($a->module . '_post_' . $selname, $o);
271 function fixacl(&$item) {
272 $item = intval(str_replace(array('<', '>'), array('', ''), $item));
275 function prune_deadguys($arr) {
281 $str = dbesc(implode(',', $arr));
283 $r = q("SELECT `id` FROM `contact` WHERE `id` IN ( " . $str . ") AND `blocked` = 0 AND `pending` = 0 AND `archive` = 0 ");
285 if (dbm::is_result($r)) {
287 foreach ($r as $rr) {
288 $ret[] = intval($rr['id']);
297 function get_acl_permissions($user = null) {
298 $allow_cid = $allow_gid = $deny_cid = $deny_gid = false;
300 if (is_array($user)) {
301 $allow_cid = ((strlen($user['allow_cid']))
302 ? explode('><', $user['allow_cid']) : array() );
303 $allow_gid = ((strlen($user['allow_gid']))
304 ? explode('><', $user['allow_gid']) : array() );
305 $deny_cid = ((strlen($user['deny_cid']))
306 ? explode('><', $user['deny_cid']) : array() );
307 $deny_gid = ((strlen($user['deny_gid']))
308 ? explode('><', $user['deny_gid']) : array() );
309 array_walk($allow_cid,'fixacl');
310 array_walk($allow_gid,'fixacl');
311 array_walk($deny_cid,'fixacl');
312 array_walk($deny_gid,'fixacl');
315 $allow_cid = prune_deadguys($allow_cid);
318 'allow_cid' => $allow_cid,
319 'allow_gid' => $allow_gid,
320 'deny_cid' => $deny_cid,
321 'deny_gid' => $deny_gid,
326 function populate_acl($user = null, $show_jotnets = false) {
328 $perms = get_acl_permissions($user);
332 $mail_disabled = ((function_exists('imap_open') && (! get_config('system','imap_disabled'))) ? 0 : 1);
334 $mail_enabled = false;
335 $pubmail_enabled = false;
337 if (! $mail_disabled) {
338 $r = q("SELECT `pubmail` FROM `mailacct` WHERE `uid` = %d AND `server` != '' LIMIT 1",
341 if (dbm::is_result($r)) {
342 $mail_enabled = true;
343 if (intval($r[0]['pubmail'])) {
344 $pubmail_enabled = true;
349 if (!$user['hidewall']) {
351 $selected = (($pubmail_enabled) ? ' checked="checked" ' : '');
352 $jotnets .= '<div class="profile-jot-net"><input type="checkbox" name="pubmail_enable"' . $selected . ' value="1" /> ' . t("Post to Email") . '</div>';
355 call_hooks('jot_networks', $jotnets);
357 $jotnets .= sprintf(t('Connectors disabled, since "%s" is enabled.'),
358 t('Hide your profile details from unknown viewers?'));
362 $tpl = get_markup_template("acl_selector.tpl");
363 $o = replace_macros($tpl, array(
364 '$showall'=> t("Visible to everybody"),
365 '$show' => t("show"),
366 '$hide' => t("don't show"),
367 '$allowcid' => json_encode($perms['allow_cid']),
368 '$allowgid' => json_encode($perms['allow_gid']),
369 '$denycid' => json_encode($perms['deny_cid']),
370 '$denygid' => json_encode($perms['deny_gid']),
371 '$networks' => $show_jotnets,
372 '$emailcc' => t('CC: email addresses'),
373 '$emtitle' => t('Example: bob@example.com, mary@example.com'),
374 '$jotnets' => $jotnets,
375 '$aclModalTitle' => t('Permissions'),
376 '$aclModalDismiss' => t('Close'),
377 '$features' => array(
378 'aclautomention' => (feature_enabled($user['uid'],"aclautomention")?"true":"false")
387 function construct_acl_data(App $a, $user) {
389 // Get group and contact information for html ACL selector
390 $acl_data = acl_lookup($a, 'html');
392 $user_defaults = get_acl_permissions($user);
394 if ($acl_data['groups']) {
395 foreach ($acl_data['groups'] as $key=>$group) {
396 // Add a "selected" flag to groups that are posted to by default
397 if ($user_defaults['allow_gid'] &&
398 in_array($group['id'], $user_defaults['allow_gid']) && !in_array($group['id'], $user_defaults['deny_gid']) ) {
399 $acl_data['groups'][$key]['selected'] = 1;
401 $acl_data['groups'][$key]['selected'] = 0;
405 if ($acl_data['contacts']) {
406 foreach ($acl_data['contacts'] as $key=>$contact) {
407 // Add a "selected" flag to groups that are posted to by default
408 if ($user_defaults['allow_cid'] &&
409 in_array($contact['id'], $user_defaults['allow_cid']) && !in_array($contact['id'], $user_defaults['deny_cid']) ) {
410 $acl_data['contacts'][$key]['selected'] = 1;
412 $acl_data['contacts'][$key]['selected'] = 0;
421 function acl_lookup(App $a, $out_type = 'json') {
427 $start = (x($_REQUEST,'start') ? $_REQUEST['start'] : 0);
428 $count = (x($_REQUEST,'count') ? $_REQUEST['count'] : 100);
429 $search = (x($_REQUEST,'search') ? $_REQUEST['search'] : "");
430 $type = (x($_REQUEST,'type') ? $_REQUEST['type'] : "");
431 $mode = (x($_REQUEST,'smode') ? $_REQUEST['smode'] : "");
432 $conv_id = (x($_REQUEST,'conversation') ? $_REQUEST['conversation'] : null);
434 // For use with jquery.textcomplete for private mail completion
436 if (x($_REQUEST, 'query') && strlen($_REQUEST['query'])) {
440 $search = $_REQUEST['query'];
443 logger("Searching for ".$search." - type ".$type, LOGGER_DEBUG);
446 $sql_extra = "AND `name` LIKE '%%".dbesc($search)."%%'";
447 $sql_extra2 = "AND (`attag` LIKE '%%".dbesc($search)."%%' OR `name` LIKE '%%".dbesc($search)."%%' OR `nick` LIKE '%%".dbesc($search)."%%')";
449 /// @TODO Avoid these needless else blocks by putting variable-initialization atop of if()
450 $sql_extra = $sql_extra2 = "";
453 // count groups and contacts
454 if ($type == '' || $type == 'g') {
455 $r = q("SELECT COUNT(*) AS g FROM `group` WHERE `deleted` = 0 AND `uid` = %d $sql_extra",
458 $group_count = (int)$r[0]['g'];
463 $sql_extra2 .= " ".unavailable_networks();
465 if ($type == '' || $type == 'c') {
466 // autocomplete for editor mentions
467 $r = q("SELECT COUNT(*) AS c FROM `contact`
468 WHERE `uid` = %d AND NOT `self`
469 AND NOT `blocked` AND NOT `pending` AND NOT `archive`
470 AND `notify` != '' $sql_extra2" ,
473 $contact_count = (int)$r[0]['c'];
475 elseif ($type == 'm') {
477 // autocomplete for Private Messages
479 $r = q("SELECT COUNT(*) AS c FROM `contact`
480 WHERE `uid` = %d AND NOT `self`
481 AND NOT `blocked` AND NOT `pending` AND NOT `archive`
482 AND `network` IN ('%s','%s','%s') $sql_extra2" ,
483 intval(local_user()),
486 dbesc(NETWORK_DIASPORA)
488 $contact_count = (int)$r[0]['c'];
491 elseif ($type == 'a') {
493 // autocomplete for Contacts
495 $r = q("SELECT COUNT(*) AS c FROM `contact`
496 WHERE `uid` = %d AND NOT `self`
497 AND NOT `pending` $sql_extra2" ,
500 $contact_count = (int)$r[0]['c'];
507 $tot = $group_count+$contact_count;
512 if ($type == '' || $type == 'g') {
514 /// @todo We should cache this query.
515 // This can be done when we can delete cache entries via wildcard
516 $r = q("SELECT `group`.`id`, `group`.`name`, GROUP_CONCAT(DISTINCT `group_member`.`contact-id` SEPARATOR ',') AS uids
518 INNER JOIN `group_member` ON `group_member`.`gid`=`group`.`id` AND `group_member`.`uid` = `group`.`uid`
519 WHERE NOT `group`.`deleted` AND `group`.`uid` = %d
521 GROUP BY `group`.`name`
522 ORDER BY `group`.`name`
524 intval(local_user()),
530 // logger('acl: group: ' . $g['name'] . ' members: ' . $g['uids']);
533 "photo" => "images/twopeople.png",
534 "name" => htmlentities($g['name']),
535 "id" => intval($g['id']),
536 "uids" => array_map("intval", explode(",",$g['uids'])),
545 $r = q("SELECT `id`, `name`, `nick`, `micro`, `network`, `url`, `attag`, `forum`, `prv` FROM `contact`
546 WHERE `uid` = %d AND NOT `self` AND NOT `blocked` AND NOT `pending` AND NOT `archive` AND `notify` != ''
547 AND NOT (`network` IN ('%s', '%s'))
549 ORDER BY `name` ASC ",
550 intval(local_user()),
551 dbesc(NETWORK_OSTATUS), dbesc(NETWORK_STATUSNET)
553 } elseif ($type == 'c') {
554 $r = q("SELECT `id`, `name`, `nick`, `micro`, `network`, `url`, `attag`, `forum`, `prv` FROM `contact`
555 WHERE `uid` = %d AND NOT `self` AND NOT `blocked` AND NOT `pending` AND NOT `archive` AND `notify` != ''
556 AND NOT (`network` IN ('%s'))
558 ORDER BY `name` ASC ",
559 intval(local_user()),
560 dbesc(NETWORK_STATUSNET)
563 elseif ($type == 'm') {
564 $r = q("SELECT `id`, `name`, `nick`, `micro`, `network`, `url`, `attag` FROM `contact`
565 WHERE `uid` = %d AND NOT `self` AND NOT `blocked` AND NOT `pending` AND NOT `archive`
566 AND `network` IN ('%s','%s','%s')
568 ORDER BY `name` ASC ",
569 intval(local_user()),
572 dbesc(NETWORK_DIASPORA)
574 } elseif ($type == 'a') {
575 $r = q("SELECT `id`, `name`, `nick`, `micro`, `network`, `url`, `attag`, `forum`, `prv` FROM `contact`
576 WHERE `uid` = %d AND `pending` = 0
578 ORDER BY `name` ASC ",
581 } elseif ($type == 'x') {
582 // autocomplete for global contact search (e.g. navbar search)
583 $r = navbar_complete($a);
588 'photo' => proxy_url($g['photo'], false, PROXY_SIZE_MICRO),
589 'name' => $g['name'],
590 'nick' => (x($g['addr']) ? $g['addr'] : $g['url']),
591 'network' => $g['network'],
593 'forum' => (x($g['community']) ? 1 : 0),
600 'items' => $contacts,
602 echo json_encode($o);
609 if (dbm::is_result($r)) {
613 'photo' => proxy_url($g['micro'], false, PROXY_SIZE_MICRO),
614 'name' => htmlentities($g['name']),
615 'id' => intval($g['id']),
616 'network' => $g['network'],
618 'nick' => htmlentities(($g['attag']) ? $g['attag'] : $g['nick']),
619 'forum' => ((x($g, 'forum') || x($g, 'prv')) ? 1 : 0),
624 $items = array_merge($groups, $contacts);
627 /* if $conv_id is set, get unknow contacts in thread */
628 /* but first get know contacts url to filter them out */
629 function _contact_link($i) { return dbesc($i['link']); }
630 $known_contacts = array_map('_contact_link', $contacts);
631 $unknow_contacts = array();
632 $r = q("SELECT `author-avatar`,`author-name`,`author-link`
633 FROM `item` WHERE `parent` = %d
634 AND (`author-name` LIKE '%%%s%%' OR `author-link` LIKE '%%%s%%')
635 AND `author-link` NOT IN ('%s')
636 GROUP BY `author-link`
637 ORDER BY `author-name` ASC
642 implode("','", $known_contacts)
644 if (dbm::is_result($r)) {
645 foreach ($r as $row) {
647 $up = parse_url($row['author-link']);
648 $nick = explode("/", $up['path']);
649 $nick = $nick[count($nick) - 1];
650 $nick .= "@" . $up['host'];
652 $unknow_contacts[] = array(
654 'photo' => proxy_url($row['author-avatar'], false, PROXY_SIZE_MICRO),
655 'name' => htmlentities($row['author-name']),
657 'network' => 'unknown',
658 'link' => $row['author-link'],
659 'nick' => htmlentities($nick),
665 $items = array_merge($items, $unknow_contacts);
666 $tot += count($unknow_contacts);
674 'contacts' => $contacts,
680 call_hooks('acl_lookup_end', $results);
682 if ($out_type === 'html') {
684 'tot' => $results['tot'],
685 'start' => $results['start'],
686 'count' => $results['count'],
687 'groups' => $results['groups'],
688 'contacts' => $results['contacts'],
694 'tot' => $results['tot'],
695 'start' => $results['start'],
696 'count' => $results['count'],
697 'items' => $results['items'],
700 echo json_encode($o);
705 * @brief Searching for global contacts for autocompletion
708 * @return array with the search results
710 function navbar_complete(App $a) {
712 // logger('navbar_complete');
714 if ((get_config('system','block_public')) && (! local_user()) && (! remote_user())) {
718 // check if searching in the local global contact table is enabled
719 $localsearch = get_config('system','poco_local_search');
721 $search = $prefix.notags(trim($_REQUEST['search']));
722 $mode = $_REQUEST['smode'];
724 // don't search if search term has less than 2 characters
725 if (! $search || mb_strlen($search) < 2) {
729 if (substr($search,0,1) === '@') {
730 $search = substr($search,1);
734 $x = DirSearch::global_search_by_name($search, $mode);
738 if (! $localsearch) {
739 $p = (($a->pager['page'] != 1) ? '&p=' . $a->pager['page'] : '');
741 $x = z_fetch_url(get_server().'/lsearch?f=' . $p . '&search=' . urlencode($search));
744 $j = json_decode($x['body'],true);
745 if ($j && $j['results']) {
746 return $j['results'];
751 /// @TODO Not needed here?