]> git.mxchange.org Git - friendica.git/blob - mod/settings.php
Move Composer autoload require out of boot.php
[friendica.git] / mod / settings.php
1 <?php
2 /**
3  * @file mod/settings.php
4  */
5
6 use Friendica\App;
7 use Friendica\BaseModule;
8 use Friendica\Content\Feature;
9 use Friendica\Content\Nav;
10 use Friendica\Core\ACL;
11 use Friendica\Core\Addon;
12 use Friendica\Core\Config;
13 use Friendica\Core\L10n;
14 use Friendica\Core\Logger;
15 use Friendica\Core\PConfig;
16 use Friendica\Core\Renderer;
17 use Friendica\Core\System;
18 use Friendica\Core\Theme;
19 use Friendica\Core\Worker;
20 use Friendica\Database\DBA;
21 use Friendica\Model\Contact;
22 use Friendica\Model\GContact;
23 use Friendica\Model\Group;
24 use Friendica\Model\User;
25 use Friendica\Module\Login;
26 use Friendica\Protocol\Email;
27 use Friendica\Util\Network;
28 use Friendica\Util\Strings;
29 use Friendica\Util\Temporal;
30
31 function get_theme_config_file($theme)
32 {
33         $a = get_app();
34         $base_theme = defaults($a->theme_info, 'extends');
35
36         if (file_exists("view/theme/$theme/config.php")) {
37                 return "view/theme/$theme/config.php";
38         }
39         if ($base_theme && file_exists("view/theme/$base_theme/config.php")) {
40                 return "view/theme/$base_theme/config.php";
41         }
42         return null;
43 }
44
45 function settings_init(App $a)
46 {
47         if (!local_user()) {
48                 notice(L10n::t('Permission denied.') . EOL);
49                 return;
50         }
51
52         // These lines provide the javascript needed by the acl selector
53
54         $tpl = Renderer::getMarkupTemplate('settings/head.tpl');
55         $a->page['htmlhead'] .= Renderer::replaceMacros($tpl, [
56                 '$ispublic' => L10n::t('everybody')
57         ]);
58
59         $tabs = [
60                 [
61                         'label' => L10n::t('Account'),
62                         'url'   => 'settings',
63                         'selected'      =>  (($a->argc == 1) && ($a->argv[0] === 'settings')?'active':''),
64                         'accesskey' => 'o',
65                 ],
66         ];
67
68         $tabs[] =       [
69                 'label' => L10n::t('Profiles'),
70                 'url'   => 'profiles',
71                 'selected'      => (($a->argc == 1) && ($a->argv[0] === 'profiles')?'active':''),
72                 'accesskey' => 'p',
73         ];
74
75         if (Feature::get()) {
76                 $tabs[] =       [
77                                         'label' => L10n::t('Additional features'),
78                                         'url'   => 'settings/features',
79                                         'selected'      => (($a->argc > 1) && ($a->argv[1] === 'features') ? 'active' : ''),
80                                         'accesskey' => 't',
81                                 ];
82         }
83
84         $tabs[] =       [
85                 'label' => L10n::t('Display'),
86                 'url'   => 'settings/display',
87                 'selected'      => (($a->argc > 1) && ($a->argv[1] === 'display')?'active':''),
88                 'accesskey' => 'i',
89         ];
90
91         $tabs[] =       [
92                 'label' => L10n::t('Social Networks'),
93                 'url'   => 'settings/connectors',
94                 'selected'      => (($a->argc > 1) && ($a->argv[1] === 'connectors')?'active':''),
95                 'accesskey' => 'w',
96         ];
97
98         $tabs[] =       [
99                 'label' => L10n::t('Addons'),
100                 'url'   => 'settings/addon',
101                 'selected'      => (($a->argc > 1) && ($a->argv[1] === 'addon')?'active':''),
102                 'accesskey' => 'l',
103         ];
104
105         $tabs[] =       [
106                 'label' => L10n::t('Delegations'),
107                 'url'   => 'delegate',
108                 'selected'      => (($a->argc == 1) && ($a->argv[0] === 'delegate')?'active':''),
109                 'accesskey' => 'd',
110         ];
111
112         $tabs[] =       [
113                 'label' => L10n::t('Connected apps'),
114                 'url' => 'settings/oauth',
115                 'selected' => (($a->argc > 1) && ($a->argv[1] === 'oauth')?'active':''),
116                 'accesskey' => 'b',
117         ];
118
119         $tabs[] =       [
120                 'label' => L10n::t('Export personal data'),
121                 'url' => 'uexport',
122                 'selected' => (($a->argc == 1) && ($a->argv[0] === 'uexport')?'active':''),
123                 'accesskey' => 'e',
124         ];
125
126         $tabs[] =       [
127                 'label' => L10n::t('Remove account'),
128                 'url' => 'removeme',
129                 'selected' => (($a->argc == 1) && ($a->argv[0] === 'removeme')?'active':''),
130                 'accesskey' => 'r',
131         ];
132
133
134         $tabtpl = Renderer::getMarkupTemplate("generic_links_widget.tpl");
135         $a->page['aside'] = Renderer::replaceMacros($tabtpl, [
136                 '$title' => L10n::t('Settings'),
137                 '$class' => 'settings-widget',
138                 '$items' => $tabs,
139         ]);
140
141 }
142
143 function settings_post(App $a)
144 {
145         if (!local_user()) {
146                 return;
147         }
148
149         if (!empty($_SESSION['submanage'])) {
150                 return;
151         }
152
153         if (count($a->user) && !empty($a->user['uid']) && $a->user['uid'] != local_user()) {
154                 notice(L10n::t('Permission denied.') . EOL);
155                 return;
156         }
157
158         $old_page_flags = $a->user['page-flags'];
159
160         if (($a->argc > 1) && ($a->argv[1] === 'oauth') && !empty($_POST['remove'])) {
161                 BaseModule::checkFormSecurityTokenRedirectOnError('/settings/oauth', 'settings_oauth');
162
163                 $key = $_POST['remove'];
164                 DBA::delete('tokens', ['id' => $key, 'uid' => local_user()]);
165                 $a->internalRedirect('settings/oauth/', true);
166                 return;
167         }
168
169         if (($a->argc > 2) && ($a->argv[1] === 'oauth')  && ($a->argv[2] === 'edit'||($a->argv[2] === 'add')) && !empty($_POST['submit'])) {
170                 BaseModule::checkFormSecurityTokenRedirectOnError('/settings/oauth', 'settings_oauth');
171
172                 $name     = defaults($_POST, 'name'    , '');
173                 $key      = defaults($_POST, 'key'     , '');
174                 $secret   = defaults($_POST, 'secret'  , '');
175                 $redirect = defaults($_POST, 'redirect', '');
176                 $icon     = defaults($_POST, 'icon'    , '');
177
178                 if ($name == "" || $key == "" || $secret == "") {
179                         notice(L10n::t("Missing some important data!"));
180                 } else {
181                         if ($_POST['submit'] == L10n::t("Update")) {
182                                 q("UPDATE clients SET
183                                                         client_id='%s',
184                                                         pw='%s',
185                                                         name='%s',
186                                                         redirect_uri='%s',
187                                                         icon='%s',
188                                                         uid=%d
189                                                 WHERE client_id='%s'",
190                                         DBA::escape($key),
191                                         DBA::escape($secret),
192                                         DBA::escape($name),
193                                         DBA::escape($redirect),
194                                         DBA::escape($icon),
195                                         local_user(),
196                                         DBA::escape($key)
197                                 );
198                         } else {
199                                 q("INSERT INTO clients
200                                                         (client_id, pw, name, redirect_uri, icon, uid)
201                                                 VALUES ('%s', '%s', '%s', '%s', '%s',%d)",
202                                         DBA::escape($key),
203                                         DBA::escape($secret),
204                                         DBA::escape($name),
205                                         DBA::escape($redirect),
206                                         DBA::escape($icon),
207                                         local_user()
208                                 );
209                         }
210                 }
211                 $a->internalRedirect('settings/oauth/', true);
212                 return;
213         }
214
215         if (($a->argc > 1) && ($a->argv[1] == 'addon')) {
216                 BaseModule::checkFormSecurityTokenRedirectOnError('/settings/addon', 'settings_addon');
217
218                 Addon::callHooks('addon_settings_post', $_POST);
219                 return;
220         }
221
222         if (($a->argc > 1) && ($a->argv[1] == 'connectors')) {
223                 BaseModule::checkFormSecurityTokenRedirectOnError('/settings/connectors', 'settings_connectors');
224
225                 if (!empty($_POST['general-submit'])) {
226                         PConfig::set(local_user(), 'system', 'disable_cw', intval($_POST['disable_cw']));
227                         PConfig::set(local_user(), 'system', 'no_intelligent_shortening', intval($_POST['no_intelligent_shortening']));
228                         PConfig::set(local_user(), 'system', 'ostatus_autofriend', intval($_POST['snautofollow']));
229                         PConfig::set(local_user(), 'ostatus', 'default_group', $_POST['group-selection']);
230                         PConfig::set(local_user(), 'ostatus', 'legacy_contact', $_POST['legacy_contact']);
231                 } elseif (!empty($_POST['imap-submit'])) {
232
233                         $mail_server       = defaults($_POST, 'mail_server', '');
234                         $mail_port         = defaults($_POST, 'mail_port', '');
235                         $mail_ssl          = (!empty($_POST['mail_ssl']) ? strtolower(trim($_POST['mail_ssl'])) : '');
236                         $mail_user         = defaults($_POST, 'mail_user', '');
237                         $mail_pass         = (!empty($_POST['mail_pass']) ? trim($_POST['mail_pass']) : '');
238                         $mail_action       = (!empty($_POST['mail_action']) ? trim($_POST['mail_action']) : '');
239                         $mail_movetofolder = (!empty($_POST['mail_movetofolder']) ? trim($_POST['mail_movetofolder']) : '');
240                         $mail_replyto      = defaults($_POST, 'mail_replyto', '');
241                         $mail_pubmail      = defaults($_POST, 'mail_pubmail', '');
242
243
244                         $mail_disabled = ((function_exists('imap_open') && (!Config::get('system', 'imap_disabled'))) ? 0 : 1);
245                         if (Config::get('system', 'dfrn_only')) {
246                                 $mail_disabled = 1;
247                         }
248
249                         if (!$mail_disabled) {
250                                 $failed = false;
251                                 $r = q("SELECT * FROM `mailacct` WHERE `uid` = %d LIMIT 1",
252                                         intval(local_user())
253                                 );
254                                 if (!DBA::isResult($r)) {
255                                         DBA::insert('mailacct', ['uid' => local_user()]);
256                                 }
257                                 if (strlen($mail_pass)) {
258                                         $pass = '';
259                                         openssl_public_encrypt($mail_pass, $pass, $a->user['pubkey']);
260                                         DBA::update('mailacct', ['pass' => bin2hex($pass)], ['uid' => local_user()]);
261                                 }
262                                 $r = q("UPDATE `mailacct` SET `server` = '%s', `port` = %d, `ssltype` = '%s', `user` = '%s',
263                                         `action` = %d, `movetofolder` = '%s',
264                                         `mailbox` = 'INBOX', `reply_to` = '%s', `pubmail` = %d WHERE `uid` = %d",
265                                         DBA::escape($mail_server),
266                                         intval($mail_port),
267                                         DBA::escape($mail_ssl),
268                                         DBA::escape($mail_user),
269                                         intval($mail_action),
270                                         DBA::escape($mail_movetofolder),
271                                         DBA::escape($mail_replyto),
272                                         intval($mail_pubmail),
273                                         intval(local_user())
274                                 );
275                                 Logger::log("mail: updating mailaccount. Response: ".print_r($r, true));
276                                 $r = q("SELECT * FROM `mailacct` WHERE `uid` = %d LIMIT 1",
277                                         intval(local_user())
278                                 );
279                                 if (DBA::isResult($r)) {
280                                         $eacct = $r[0];
281                                         $mb = Email::constructMailboxName($eacct);
282
283                                         if (strlen($eacct['server'])) {
284                                                 $dcrpass = '';
285                                                 openssl_private_decrypt(hex2bin($eacct['pass']), $dcrpass, $a->user['prvkey']);
286                                                 $mbox = Email::connect($mb, $mail_user, $dcrpass);
287                                                 unset($dcrpass);
288                                                 if (!$mbox) {
289                                                         $failed = true;
290                                                         notice(L10n::t('Failed to connect with email account using the settings provided.') . EOL);
291                                                 }
292                                         }
293                                 }
294                                 if (!$failed) {
295                                         info(L10n::t('Email settings updated.') . EOL);
296                                 }
297                         }
298                 }
299
300                 Addon::callHooks('connector_settings_post', $_POST);
301                 return;
302         }
303
304         if (($a->argc > 1) && ($a->argv[1] === 'features')) {
305                 BaseModule::checkFormSecurityTokenRedirectOnError('/settings/features', 'settings_features');
306                 foreach ($_POST as $k => $v) {
307                         if (strpos($k, 'feature_') === 0) {
308                                 PConfig::set(local_user(), 'feature', substr($k, 8), ((intval($v)) ? 1 : 0));
309                         }
310                 }
311                 info(L10n::t('Features updated') . EOL);
312                 return;
313         }
314
315         if (($a->argc > 1) && ($a->argv[1] === 'display')) {
316                 BaseModule::checkFormSecurityTokenRedirectOnError('/settings/display', 'settings_display');
317
318                 $theme             = !empty($_POST['theme'])             ? Strings::escapeTags(trim($_POST['theme']))        : $a->user['theme'];
319                 $mobile_theme      = !empty($_POST['mobile_theme'])      ? Strings::escapeTags(trim($_POST['mobile_theme'])) : '';
320                 $nosmile           = !empty($_POST['nosmile'])           ? intval($_POST['nosmile'])            : 0;
321                 $first_day_of_week = !empty($_POST['first_day_of_week']) ? intval($_POST['first_day_of_week'])  : 0;
322                 $noinfo            = !empty($_POST['noinfo'])            ? intval($_POST['noinfo'])             : 0;
323                 $infinite_scroll   = !empty($_POST['infinite_scroll'])   ? intval($_POST['infinite_scroll'])    : 0;
324                 $no_auto_update    = !empty($_POST['no_auto_update'])    ? intval($_POST['no_auto_update'])     : 0;
325                 $bandwidth_saver   = !empty($_POST['bandwidth_saver'])   ? intval($_POST['bandwidth_saver'])    : 0;
326                 $smart_threading   = !empty($_POST['smart_threading'])   ? intval($_POST['smart_threading'])    : 0;
327                 $nowarn_insecure   = !empty($_POST['nowarn_insecure'])   ? intval($_POST['nowarn_insecure'])    : 0;
328                 $browser_update    = !empty($_POST['browser_update'])    ? intval($_POST['browser_update'])     : 0;
329                 if ($browser_update != -1) {
330                         $browser_update = $browser_update * 1000;
331                         if ($browser_update < 10000) {
332                                 $browser_update = 10000;
333                         }
334                 }
335
336                 $itemspage_network = !empty($_POST['itemspage_network'])  ? intval($_POST['itemspage_network'])  : 40;
337                 if ($itemspage_network > 100) {
338                         $itemspage_network = 100;
339                 }
340                 $itemspage_mobile_network = !empty($_POST['itemspage_mobile_network']) ? intval($_POST['itemspage_mobile_network']) : 20;
341                 if ($itemspage_mobile_network > 100) {
342                         $itemspage_mobile_network = 100;
343                 }
344
345                 if ($mobile_theme !== '') {
346                         PConfig::set(local_user(), 'system', 'mobile_theme', $mobile_theme);
347                 }
348
349                 PConfig::set(local_user(), 'system', 'nowarn_insecure'         , $nowarn_insecure);
350                 PConfig::set(local_user(), 'system', 'update_interval'         , $browser_update);
351                 PConfig::set(local_user(), 'system', 'itemspage_network'       , $itemspage_network);
352                 PConfig::set(local_user(), 'system', 'itemspage_mobile_network', $itemspage_mobile_network);
353                 PConfig::set(local_user(), 'system', 'no_smilies'              , $nosmile);
354                 PConfig::set(local_user(), 'system', 'first_day_of_week'       , $first_day_of_week);
355                 PConfig::set(local_user(), 'system', 'ignore_info'             , $noinfo);
356                 PConfig::set(local_user(), 'system', 'infinite_scroll'         , $infinite_scroll);
357                 PConfig::set(local_user(), 'system', 'no_auto_update'          , $no_auto_update);
358                 PConfig::set(local_user(), 'system', 'bandwidth_saver'         , $bandwidth_saver);
359                 PConfig::set(local_user(), 'system', 'smart_threading'         , $smart_threading);
360
361                 if ($theme == $a->user['theme']) {
362                         // call theme_post only if theme has not been changed
363                         if (($themeconfigfile = get_theme_config_file($theme)) !== null) {
364                                 require_once $themeconfigfile;
365                                 theme_post($a);
366                         }
367                 }
368                 Theme::install($theme);
369
370                 $r = q("UPDATE `user` SET `theme` = '%s' WHERE `uid` = %d",
371                                 DBA::escape($theme),
372                                 intval(local_user())
373                 );
374
375                 Addon::callHooks('display_settings_post', $_POST);
376                 $a->internalRedirect('settings/display');
377                 return; // NOTREACHED
378         }
379
380         BaseModule::checkFormSecurityTokenRedirectOnError('/settings', 'settings');
381
382         if (!empty($_POST['resend_relocate'])) {
383                 Worker::add(PRIORITY_HIGH, 'Notifier', 'relocate', local_user());
384                 info(L10n::t("Relocate message has been send to your contacts"));
385                 $a->internalRedirect('settings');
386         }
387
388         Addon::callHooks('settings_post', $_POST);
389
390         if (!empty($_POST['password']) || !empty($_POST['confirm'])) {
391                 $newpass = $_POST['password'];
392                 $confirm = $_POST['confirm'];
393
394                 $err = false;
395                 if ($newpass != $confirm) {
396                         notice(L10n::t('Passwords do not match. Password unchanged.') . EOL);
397                         $err = true;
398                 }
399
400                 if (empty($newpass) || empty($confirm)) {
401                         notice(L10n::t('Empty passwords are not allowed. Password unchanged.') . EOL);
402                         $err = true;
403                 }
404
405                 if (!Config::get('system', 'disable_password_exposed', false) && User::isPasswordExposed($newpass)) {
406                         notice(L10n::t('The new password has been exposed in a public data dump, please choose another.') . EOL);
407                         $err = true;
408                 }
409
410                 //  check if the old password was supplied correctly before changing it to the new value
411                 if (!User::authenticate(intval(local_user()), $_POST['opassword'])) {
412                         notice(L10n::t('Wrong password.') . EOL);
413                         $err = true;
414                 }
415
416                 if (!$err) {
417                         $result = User::updatePassword(local_user(), $newpass);
418                         if (DBA::isResult($result)) {
419                                 info(L10n::t('Password changed.') . EOL);
420                         } else {
421                                 notice(L10n::t('Password update failed. Please try again.') . EOL);
422                         }
423                 }
424         }
425
426         $username         = (!empty($_POST['username'])   ? Strings::escapeTags(trim($_POST['username']))     : '');
427         $email            = (!empty($_POST['email'])      ? Strings::escapeTags(trim($_POST['email']))        : '');
428         $timezone         = (!empty($_POST['timezone'])   ? Strings::escapeTags(trim($_POST['timezone']))     : '');
429         $language         = (!empty($_POST['language'])   ? Strings::escapeTags(trim($_POST['language']))     : '');
430
431         $defloc           = (!empty($_POST['defloc'])     ? Strings::escapeTags(trim($_POST['defloc']))       : '');
432         $openid           = (!empty($_POST['openid_url']) ? Strings::escapeTags(trim($_POST['openid_url']))   : '');
433         $maxreq           = (!empty($_POST['maxreq'])     ? intval($_POST['maxreq'])             : 0);
434         $expire           = (!empty($_POST['expire'])     ? intval($_POST['expire'])             : 0);
435         $def_gid          = (!empty($_POST['group-selection']) ? intval($_POST['group-selection']) : 0);
436
437
438         $expire_items     = (!empty($_POST['expire_items']) ? intval($_POST['expire_items'])     : 0);
439         $expire_notes     = (!empty($_POST['expire_notes']) ? intval($_POST['expire_notes'])     : 0);
440         $expire_starred   = (!empty($_POST['expire_starred']) ? intval($_POST['expire_starred']) : 0);
441         $expire_photos    = (!empty($_POST['expire_photos'])? intval($_POST['expire_photos'])    : 0);
442         $expire_network_only    = (!empty($_POST['expire_network_only'])? intval($_POST['expire_network_only'])  : 0);
443
444         $allow_location   = ((!empty($_POST['allow_location']) && (intval($_POST['allow_location']) == 1)) ? 1: 0);
445         $publish          = ((!empty($_POST['profile_in_directory']) && (intval($_POST['profile_in_directory']) == 1)) ? 1: 0);
446         $net_publish      = ((!empty($_POST['profile_in_netdirectory']) && (intval($_POST['profile_in_netdirectory']) == 1)) ? 1: 0);
447         $old_visibility   = ((!empty($_POST['visibility']) && (intval($_POST['visibility']) == 1)) ? 1 : 0);
448         $account_type     = ((!empty($_POST['account-type']) && (intval($_POST['account-type']))) ? intval($_POST['account-type']) : 0);
449         $page_flags       = ((!empty($_POST['page-flags']) && (intval($_POST['page-flags']))) ? intval($_POST['page-flags']) : 0);
450         $blockwall        = ((!empty($_POST['blockwall']) && (intval($_POST['blockwall']) == 1)) ? 0: 1); // this setting is inverted!
451         $blocktags        = ((!empty($_POST['blocktags']) && (intval($_POST['blocktags']) == 1)) ? 0: 1); // this setting is inverted!
452         $unkmail          = ((!empty($_POST['unkmail']) && (intval($_POST['unkmail']) == 1)) ? 1: 0);
453         $cntunkmail       = (!empty($_POST['cntunkmail']) ? intval($_POST['cntunkmail']) : 0);
454         $suggestme        = (!empty($_POST['suggestme']) ? intval($_POST['suggestme'])  : 0);
455         $hide_friends     = (($_POST['hide-friends'] == 1) ? 1: 0);
456         $hidewall         = (($_POST['hidewall'] == 1) ? 1: 0);
457
458         $email_textonly   = (($_POST['email_textonly'] == 1) ? 1 : 0);
459         $detailed_notif   = (($_POST['detailed_notif'] == 1) ? 1 : 0);
460
461         $notify = 0;
462
463         if (!empty($_POST['notify1'])) {
464                 $notify += intval($_POST['notify1']);
465         }
466         if (!empty($_POST['notify2'])) {
467                 $notify += intval($_POST['notify2']);
468         }
469         if (!empty($_POST['notify3'])) {
470                 $notify += intval($_POST['notify3']);
471         }
472         if (!empty($_POST['notify4'])) {
473                 $notify += intval($_POST['notify4']);
474         }
475         if (!empty($_POST['notify5'])) {
476                 $notify += intval($_POST['notify5']);
477         }
478         if (!empty($_POST['notify6'])) {
479                 $notify += intval($_POST['notify6']);
480         }
481         if (!empty($_POST['notify7'])) {
482                 $notify += intval($_POST['notify7']);
483         }
484         if (!empty($_POST['notify8'])) {
485                 $notify += intval($_POST['notify8']);
486         }
487
488         // Adjust the page flag if the account type doesn't fit to the page flag.
489         if (($account_type == Contact::ACCOUNT_TYPE_PERSON) && !in_array($page_flags, [Contact::PAGE_NORMAL, Contact::PAGE_SOAPBOX, Contact::PAGE_FREELOVE])) {
490                 $page_flags = Contact::PAGE_NORMAL;
491         } elseif (($account_type == Contact::ACCOUNT_TYPE_ORGANISATION) && !in_array($page_flags, [Contact::PAGE_SOAPBOX])) {
492                 $page_flags = Contact::PAGE_SOAPBOX;
493         } elseif (($account_type == Contact::ACCOUNT_TYPE_NEWS) && !in_array($page_flags, [Contact::PAGE_SOAPBOX])) {
494                 $page_flags = Contact::PAGE_SOAPBOX;
495         } elseif (($account_type == Contact::ACCOUNT_TYPE_COMMUNITY) && !in_array($page_flags, [Contact::PAGE_COMMUNITY, Contact::PAGE_PRVGROUP])) {
496                 $page_flags = Contact::PAGE_COMMUNITY;
497         }
498
499         $email_changed = false;
500
501         $err = '';
502
503         if ($username != $a->user['username']) {
504                 if (strlen($username) > 40) {
505                         $err .= L10n::t(' Please use a shorter name.');
506                 }
507                 if (strlen($username) < 3) {
508                         $err .= L10n::t(' Name too short.');
509                 }
510         }
511
512         if ($email != $a->user['email']) {
513                 $email_changed = true;
514                 //  check for the correct password
515                 if (!User::authenticate(intval(local_user()), $_POST['mpassword'])) {
516                         $err .= L10n::t('Wrong Password') . EOL;
517                         $email = $a->user['email'];
518                 }
519                 //  check the email is valid
520                 if (!filter_var($email, FILTER_VALIDATE_EMAIL)) {
521                         $err .= L10n::t('Invalid email.');
522                 }
523                 //  ensure new email is not the admin mail
524                 if (Config::get('config', 'admin_email')) {
525                         $adminlist = explode(",", str_replace(" ", "", strtolower(Config::get('config', 'admin_email'))));
526                         if (in_array(strtolower($email), $adminlist)) {
527                                 $err .= L10n::t('Cannot change to that email.');
528                                 $email = $a->user['email'];
529                         }
530                 }
531         }
532
533         if (strlen($err)) {
534                 notice($err . EOL);
535                 return;
536         }
537
538         if (($timezone != $a->user['timezone']) && strlen($timezone)) {
539                 date_default_timezone_set($timezone);
540         }
541
542         $str_group_allow   = !empty($_POST['group_allow'])   ? perms2str($_POST['group_allow'])   : '';
543         $str_contact_allow = !empty($_POST['contact_allow']) ? perms2str($_POST['contact_allow']) : '';
544         $str_group_deny    = !empty($_POST['group_deny'])    ? perms2str($_POST['group_deny'])    : '';
545         $str_contact_deny  = !empty($_POST['contact_deny'])  ? perms2str($_POST['contact_deny'])  : '';
546
547         $openidserver = $a->user['openidserver'];
548         //$openid = Strings::normaliseOpenID($openid);
549
550         // If openid has changed or if there's an openid but no openidserver, try and discover it.
551         if ($openid != $a->user['openid'] || (strlen($openid) && (!strlen($openidserver)))) {
552                 if (Network::isUrlValid($openid)) {
553                         Logger::log('updating openidserver');
554                         $open_id_obj = new LightOpenID($a->getHostName());
555                         $open_id_obj->identity = $openid;
556                         $openidserver = $open_id_obj->discover($open_id_obj->identity);
557                 } else {
558                         $openidserver = '';
559                 }
560         }
561
562         PConfig::set(local_user(), 'expire', 'items', $expire_items);
563         PConfig::set(local_user(), 'expire', 'notes', $expire_notes);
564         PConfig::set(local_user(), 'expire', 'starred', $expire_starred);
565         PConfig::set(local_user(), 'expire', 'photos', $expire_photos);
566         PConfig::set(local_user(), 'expire', 'network_only', $expire_network_only);
567
568         PConfig::set(local_user(), 'system', 'suggestme', $suggestme);
569
570         PConfig::set(local_user(), 'system', 'email_textonly', $email_textonly);
571         PConfig::set(local_user(), 'system', 'detailed_notif', $detailed_notif);
572
573         if ($page_flags == Contact::PAGE_PRVGROUP) {
574                 $hidewall = 1;
575                 if (!$str_contact_allow && !$str_group_allow && !$str_contact_deny && !$str_group_deny) {
576                         if ($def_gid) {
577                                 info(L10n::t('Private forum has no privacy permissions. Using default privacy group.'). EOL);
578                                 $str_group_allow = '<' . $def_gid . '>';
579                         } else {
580                                 notice(L10n::t('Private forum has no privacy permissions and no default privacy group.') . EOL);
581                         }
582                 }
583         }
584
585
586         $r = q("UPDATE `user` SET `username` = '%s', `email` = '%s',
587                                 `openid` = '%s', `timezone` = '%s',
588                                 `allow_cid` = '%s', `allow_gid` = '%s', `deny_cid` = '%s', `deny_gid` = '%s',
589                                 `notify-flags` = %d, `page-flags` = %d, `account-type` = %d, `default-location` = '%s',
590                                 `allow_location` = %d, `maxreq` = %d, `expire` = %d, `openidserver` = '%s',
591                                 `def_gid` = %d, `blockwall` = %d, `hidewall` = %d, `blocktags` = %d,
592                                 `unkmail` = %d, `cntunkmail` = %d, `language` = '%s'
593                         WHERE `uid` = %d",
594                         DBA::escape($username),
595                         DBA::escape($email),
596                         DBA::escape($openid),
597                         DBA::escape($timezone),
598                         DBA::escape($str_contact_allow),
599                         DBA::escape($str_group_allow),
600                         DBA::escape($str_contact_deny),
601                         DBA::escape($str_group_deny),
602                         intval($notify),
603                         intval($page_flags),
604                         intval($account_type),
605                         DBA::escape($defloc),
606                         intval($allow_location),
607                         intval($maxreq),
608                         intval($expire),
609                         DBA::escape($openidserver),
610                         intval($def_gid),
611                         intval($blockwall),
612                         intval($hidewall),
613                         intval($blocktags),
614                         intval($unkmail),
615                         intval($cntunkmail),
616                         DBA::escape($language),
617                         intval(local_user())
618         );
619         if (DBA::isResult($r)) {
620                 info(L10n::t('Settings updated.') . EOL);
621         }
622
623         // clear session language
624         unset($_SESSION['language']);
625
626         $r = q("UPDATE `profile`
627                 SET `publish` = %d,
628                 `name` = '%s',
629                 `net-publish` = %d,
630                 `hide-friends` = %d
631                 WHERE `is-default` = 1 AND `uid` = %d",
632                 intval($publish),
633                 DBA::escape($username),
634                 intval($net_publish),
635                 intval($hide_friends),
636                 intval(local_user())
637         );
638
639         Contact::updateSelfFromUserID(local_user());
640
641         if (($old_visibility != $net_publish) || ($page_flags != $old_page_flags)) {
642                 // Update global directory in background
643                 $url = $_SESSION['my_url'];
644                 if ($url && strlen(Config::get('system', 'directory'))) {
645                         Worker::add(PRIORITY_LOW, "Directory", $url);
646                 }
647         }
648
649         Worker::add(PRIORITY_LOW, 'ProfileUpdate', local_user());
650
651         // Update the global contact for the user
652         GContact::updateForUser(local_user());
653
654         $a->internalRedirect('settings');
655         return; // NOTREACHED
656 }
657
658
659 function settings_content(App $a)
660 {
661         $o = '';
662         Nav::setSelected('settings');
663
664         if (!local_user()) {
665                 //notice(L10n::t('Permission denied.') . EOL);
666                 return Login::form();
667         }
668
669         if (!empty($_SESSION['submanage'])) {
670                 notice(L10n::t('Permission denied.') . EOL);
671                 return;
672         }
673
674         if (($a->argc > 1) && ($a->argv[1] === 'oauth')) {
675                 if (($a->argc > 2) && ($a->argv[2] === 'add')) {
676                         $tpl = Renderer::getMarkupTemplate('settings/oauth_edit.tpl');
677                         $o .= Renderer::replaceMacros($tpl, [
678                                 '$form_security_token' => BaseModule::getFormSecurityToken("settings_oauth"),
679                                 '$title'        => L10n::t('Add application'),
680                                 '$submit'       => L10n::t('Save Settings'),
681                                 '$cancel'       => L10n::t('Cancel'),
682                                 '$name'         => ['name', L10n::t('Name'), '', ''],
683                                 '$key'          => ['key', L10n::t('Consumer Key'), '', ''],
684                                 '$secret'       => ['secret', L10n::t('Consumer Secret'), '', ''],
685                                 '$redirect'     => ['redirect', L10n::t('Redirect'), '', ''],
686                                 '$icon'         => ['icon', L10n::t('Icon url'), '', ''],
687                         ]);
688                         return $o;
689                 }
690
691                 if (($a->argc > 3) && ($a->argv[2] === 'edit')) {
692                         $r = q("SELECT * FROM clients WHERE client_id='%s' AND uid=%d",
693                                         DBA::escape($a->argv[3]),
694                                         local_user());
695
696                         if (!DBA::isResult($r)) {
697                                 notice(L10n::t("You can't edit this application."));
698                                 return;
699                         }
700                         $app = $r[0];
701
702                         $tpl = Renderer::getMarkupTemplate('settings/oauth_edit.tpl');
703                         $o .= Renderer::replaceMacros($tpl, [
704                                 '$form_security_token' => BaseModule::getFormSecurityToken("settings_oauth"),
705                                 '$title'        => L10n::t('Add application'),
706                                 '$submit'       => L10n::t('Update'),
707                                 '$cancel'       => L10n::t('Cancel'),
708                                 '$name'         => ['name', L10n::t('Name'), $app['name'] , ''],
709                                 '$key'          => ['key', L10n::t('Consumer Key'), $app['client_id'], ''],
710                                 '$secret'       => ['secret', L10n::t('Consumer Secret'), $app['pw'], ''],
711                                 '$redirect'     => ['redirect', L10n::t('Redirect'), $app['redirect_uri'], ''],
712                                 '$icon'         => ['icon', L10n::t('Icon url'), $app['icon'], ''],
713                         ]);
714                         return $o;
715                 }
716
717                 if (($a->argc > 3) && ($a->argv[2] === 'delete')) {
718                         BaseModule::checkFormSecurityTokenRedirectOnError('/settings/oauth', 'settings_oauth', 't');
719
720                         DBA::delete('clients', ['client_id' => $a->argv[3], 'uid' => local_user()]);
721                         $a->internalRedirect('settings/oauth/', true);
722                         return;
723                 }
724
725                 /// @TODO validate result with DBA::isResult()
726                 $r = q("SELECT clients.*, tokens.id as oauth_token, (clients.uid=%d) AS my
727                                 FROM clients
728                                 LEFT JOIN tokens ON clients.client_id=tokens.client_id
729                                 WHERE clients.uid IN (%d, 0)",
730                                 local_user(),
731                                 local_user());
732
733
734                 $tpl = Renderer::getMarkupTemplate('settings/oauth.tpl');
735                 $o .= Renderer::replaceMacros($tpl, [
736                         '$form_security_token' => BaseModule::getFormSecurityToken("settings_oauth"),
737                         '$baseurl'      => $a->getBaseURL(true),
738                         '$title'        => L10n::t('Connected Apps'),
739                         '$add'          => L10n::t('Add application'),
740                         '$edit'         => L10n::t('Edit'),
741                         '$delete'               => L10n::t('Delete'),
742                         '$consumerkey' => L10n::t('Client key starts with'),
743                         '$noname'       => L10n::t('No name'),
744                         '$remove'       => L10n::t('Remove authorization'),
745                         '$apps'         => $r,
746                 ]);
747                 return $o;
748         }
749
750         if (($a->argc > 1) && ($a->argv[1] === 'addon')) {
751                 $settings_addons = "";
752
753                 $r = q("SELECT * FROM `hook` WHERE `hook` = 'addon_settings' ");
754                 if (!DBA::isResult($r)) {
755                         $settings_addons = L10n::t('No Addon settings configured');
756                 }
757
758                 Addon::callHooks('addon_settings', $settings_addons);
759
760
761                 $tpl = Renderer::getMarkupTemplate('settings/addons.tpl');
762                 $o .= Renderer::replaceMacros($tpl, [
763                         '$form_security_token' => BaseModule::getFormSecurityToken("settings_addon"),
764                         '$title'        => L10n::t('Addon Settings'),
765                         '$settings_addons' => $settings_addons
766                 ]);
767                 return $o;
768         }
769
770         if (($a->argc > 1) && ($a->argv[1] === 'features')) {
771
772                 $arr = [];
773                 $features = Feature::get();
774                 foreach ($features as $fname => $fdata) {
775                         $arr[$fname] = [];
776                         $arr[$fname][0] = $fdata[0];
777                         foreach (array_slice($fdata,1) as $f) {
778                                 $arr[$fname][1][] = ['feature_' .$f[0], $f[1],((intval(Feature::isEnabled(local_user(), $f[0]))) ? "1" : ''), $f[2],[L10n::t('Off'), L10n::t('On')]];
779                         }
780                 }
781
782                 $tpl = Renderer::getMarkupTemplate('settings/features.tpl');
783                 $o .= Renderer::replaceMacros($tpl, [
784                         '$form_security_token' => BaseModule::getFormSecurityToken("settings_features"),
785                         '$title'               => L10n::t('Additional Features'),
786                         '$features'            => $arr,
787                         '$submit'              => L10n::t('Save Settings'),
788                 ]);
789                 return $o;
790         }
791
792         if (($a->argc > 1) && ($a->argv[1] === 'connectors')) {
793                 $disable_cw                = intval(PConfig::get(local_user(), 'system', 'disable_cw'));
794                 $no_intelligent_shortening = intval(PConfig::get(local_user(), 'system', 'no_intelligent_shortening'));
795                 $ostatus_autofriend        = intval(PConfig::get(local_user(), 'system', 'ostatus_autofriend'));
796                 $default_group             = PConfig::get(local_user(), 'ostatus', 'default_group');
797                 $legacy_contact            = PConfig::get(local_user(), 'ostatus', 'legacy_contact');
798
799                 if (!empty($legacy_contact)) {
800                         /// @todo Isn't it supposed to be a $a->internalRedirect() call?
801                         $a->page['htmlhead'] = '<meta http-equiv="refresh" content="0; URL=' . System::baseUrl().'/ostatus_subscribe?url=' . urlencode($legacy_contact) . '">';
802                 }
803
804                 $settings_connectors = '';
805                 Addon::callHooks('connector_settings', $settings_connectors);
806
807                 if (is_site_admin()) {
808                         $diasp_enabled = L10n::t('Built-in support for %s connectivity is %s', L10n::t('Diaspora'), ((Config::get('system', 'diaspora_enabled')) ? L10n::t('enabled') : L10n::t('disabled')));
809                         $ostat_enabled = L10n::t('Built-in support for %s connectivity is %s', L10n::t("GNU Social \x28OStatus\x29"), ((Config::get('system', 'ostatus_disabled')) ? L10n::t('disabled') : L10n::t('enabled')));
810                 } else {
811                         $diasp_enabled = "";
812                         $ostat_enabled = "";
813                 }
814
815                 $mail_disabled = ((function_exists('imap_open') && (!Config::get('system', 'imap_disabled'))) ? 0 : 1);
816                 if (Config::get('system', 'dfrn_only')) {
817                         $mail_disabled = 1;
818                 }
819                 if (!$mail_disabled) {
820                         $r = q("SELECT * FROM `mailacct` WHERE `uid` = %d LIMIT 1",
821                                 local_user()
822                         );
823                 } else {
824                         $r = null;
825                 }
826
827                 $mail_server       = ((DBA::isResult($r)) ? $r[0]['server'] : '');
828                 $mail_port         = ((DBA::isResult($r) && intval($r[0]['port'])) ? intval($r[0]['port']) : '');
829                 $mail_ssl          = ((DBA::isResult($r)) ? $r[0]['ssltype'] : '');
830                 $mail_user         = ((DBA::isResult($r)) ? $r[0]['user'] : '');
831                 $mail_replyto      = ((DBA::isResult($r)) ? $r[0]['reply_to'] : '');
832                 $mail_pubmail      = ((DBA::isResult($r)) ? $r[0]['pubmail'] : 0);
833                 $mail_action       = ((DBA::isResult($r)) ? $r[0]['action'] : 0);
834                 $mail_movetofolder = ((DBA::isResult($r)) ? $r[0]['movetofolder'] : '');
835                 $mail_chk          = ((DBA::isResult($r)) ? $r[0]['last_check'] : DBA::NULL_DATETIME);
836
837
838                 $tpl = Renderer::getMarkupTemplate('settings/connectors.tpl');
839
840                 $mail_disabled_message = (($mail_disabled) ? L10n::t('Email access is disabled on this site.') : '');
841
842                 $o .= Renderer::replaceMacros($tpl, [
843                         '$form_security_token' => BaseModule::getFormSecurityToken("settings_connectors"),
844
845                         '$title'        => L10n::t('Social Networks'),
846
847                         '$diasp_enabled' => $diasp_enabled,
848                         '$ostat_enabled' => $ostat_enabled,
849
850                         '$general_settings' => L10n::t('General Social Media Settings'),
851                         '$disable_cw' => ['disable_cw', L10n::t('Disable Content Warning'), $disable_cw, L10n::t('Users on networks like Mastodon or Pleroma are able to set a content warning field which collapse their post by default. This disables the automatic collapsing and sets the content warning as the post title. Doesn\'t affect any other content filtering you eventually set up.')],
852                         '$no_intelligent_shortening' => ['no_intelligent_shortening', L10n::t('Disable intelligent shortening'), $no_intelligent_shortening, L10n::t('Normally the system tries to find the best link to add to shortened posts. If this option is enabled then every shortened post will always point to the original friendica post.')],
853                         '$ostatus_autofriend' => ['snautofollow', L10n::t("Automatically follow any GNU Social \x28OStatus\x29 followers/mentioners"), $ostatus_autofriend, L10n::t('If you receive a message from an unknown OStatus user, this option decides what to do. If it is checked, a new contact will be created for every unknown user.')],
854                         '$default_group' => Group::displayGroupSelection(local_user(), $default_group, L10n::t("Default group for OStatus contacts")),
855                         '$legacy_contact' => ['legacy_contact', L10n::t('Your legacy GNU Social account'), $legacy_contact, L10n::t("If you enter your old GNU Social/Statusnet account name here \x28in the format user@domain.tld\x29, your contacts will be added automatically. The field will be emptied when done.")],
856
857                         '$repair_ostatus_url' => System::baseUrl() . '/repair_ostatus',
858                         '$repair_ostatus_text' => L10n::t('Repair OStatus subscriptions'),
859
860                         '$settings_connectors' => $settings_connectors,
861
862                         '$h_imap' => L10n::t('Email/Mailbox Setup'),
863                         '$imap_desc' => L10n::t("If you wish to communicate with email contacts using this service \x28optional\x29, please specify how to connect to your mailbox."),
864                         '$imap_lastcheck' => ['imap_lastcheck', L10n::t('Last successful email check:'), $mail_chk, ''],
865                         '$mail_disabled' => $mail_disabled_message,
866                         '$mail_server'  => ['mail_server',  L10n::t('IMAP server name:'), $mail_server, ''],
867                         '$mail_port'    => ['mail_port',         L10n::t('IMAP port:'), $mail_port, ''],
868                         '$mail_ssl'             => ['mail_ssl',          L10n::t('Security:'), strtoupper($mail_ssl), '', ['notls'=>L10n::t('None'), 'TLS'=>'TLS', 'SSL'=>'SSL']],
869                         '$mail_user'    => ['mail_user',    L10n::t('Email login name:'), $mail_user, ''],
870                         '$mail_pass'    => ['mail_pass',         L10n::t('Email password:'), '', ''],
871                         '$mail_replyto' => ['mail_replyto', L10n::t('Reply-to address:'), $mail_replyto, 'Optional'],
872                         '$mail_pubmail' => ['mail_pubmail', L10n::t('Send public posts to all email contacts:'), $mail_pubmail, ''],
873                         '$mail_action'  => ['mail_action',       L10n::t('Action after import:'), $mail_action, '', [0=>L10n::t('None'), /*1=>L10n::t('Delete'),*/ 2=>L10n::t('Mark as seen'), 3=>L10n::t('Move to folder')]],
874                         '$mail_movetofolder'    => ['mail_movetofolder',         L10n::t('Move to folder:'), $mail_movetofolder, ''],
875                         '$submit' => L10n::t('Save Settings'),
876                 ]);
877
878                 Addon::callHooks('display_settings', $o);
879                 return $o;
880         }
881
882         /*
883          * DISPLAY SETTINGS
884          */
885         if (($a->argc > 1) && ($a->argv[1] === 'display')) {
886                 $default_theme = Config::get('system', 'theme');
887                 if (!$default_theme) {
888                         $default_theme = 'default';
889                 }
890                 $default_mobile_theme = Config::get('system', 'mobile-theme');
891                 if (!$default_mobile_theme) {
892                         $default_mobile_theme = 'none';
893                 }
894
895                 $allowed_themes_str = Config::get('system', 'allowed_themes');
896                 $allowed_themes_raw = explode(',', $allowed_themes_str);
897                 $allowed_themes = [];
898                 if (count($allowed_themes_raw)) {
899                         foreach ($allowed_themes_raw as $x) {
900                                 if (strlen(trim($x)) && is_dir("view/theme/$x")) {
901                                         $allowed_themes[] = trim($x);
902                                 }
903                         }
904                 }
905
906
907                 $themes = [];
908                 $mobile_themes = ["---" => L10n::t('No special theme for mobile devices')];
909                 if ($allowed_themes) {
910                         foreach ($allowed_themes as $theme) {
911                                 $is_experimental = file_exists('view/theme/' . $theme . '/experimental');
912                                 $is_unsupported  = file_exists('view/theme/' . $theme . '/unsupported');
913                                 $is_mobile       = file_exists('view/theme/' . $theme . '/mobile');
914                                 if (!$is_experimental || ($is_experimental && (Config::get('experimentals', 'exp_themes')==1 || is_null(Config::get('experimentals', 'exp_themes'))))) {
915                                         $theme_name = ucfirst($theme);
916                                         if ($is_unsupported) {
917                                                 $theme_name = L10n::t("%s - \x28Unsupported\x29", $theme_name);
918                                         } elseif ($is_experimental) {
919                                                 $theme_name = L10n::t("%s - \x28Experimental\x29", $theme_name);
920                                         }
921                                         if ($is_mobile) {
922                                                 $mobile_themes[$theme] = $theme_name;
923                                         } else {
924                                                 $themes[$theme] = $theme_name;
925                                         }
926                                 }
927                         }
928                 }
929                 $theme_selected        = defaults($_SESSION, 'theme'       , $default_theme);
930                 $mobile_theme_selected = defaults($_SESSION, 'mobile-theme', $default_mobile_theme);
931
932                 $nowarn_insecure = intval(PConfig::get(local_user(), 'system', 'nowarn_insecure'));
933
934                 $browser_update = intval(PConfig::get(local_user(), 'system', 'update_interval'));
935                 if (intval($browser_update) != -1) {
936                         $browser_update = (($browser_update == 0) ? 40 : $browser_update / 1000); // default if not set: 40 seconds
937                 }
938
939                 $itemspage_network = intval(PConfig::get(local_user(), 'system', 'itemspage_network'));
940                 $itemspage_network = (($itemspage_network > 0 && $itemspage_network < 101) ? $itemspage_network : 40); // default if not set: 40 items
941                 $itemspage_mobile_network = intval(PConfig::get(local_user(), 'system', 'itemspage_mobile_network'));
942                 $itemspage_mobile_network = (($itemspage_mobile_network > 0 && $itemspage_mobile_network < 101) ? $itemspage_mobile_network : 20); // default if not set: 20 items
943
944                 $nosmile = PConfig::get(local_user(), 'system', 'no_smilies', 0);
945                 $first_day_of_week = PConfig::get(local_user(), 'system', 'first_day_of_week', 0);
946                 $weekdays = [0 => L10n::t("Sunday"), 1 => L10n::t("Monday")];
947
948                 $noinfo = PConfig::get(local_user(), 'system', 'ignore_info', 0);
949                 $infinite_scroll = PConfig::get(local_user(), 'system', 'infinite_scroll', 0);
950                 $no_auto_update = PConfig::get(local_user(), 'system', 'no_auto_update', 0);
951                 $bandwidth_saver = PConfig::get(local_user(), 'system', 'bandwidth_saver', 0);
952                 $smart_threading = PConfig::get(local_user(), 'system', 'smart_threading', 0);
953
954                 $theme_config = "";
955                 if (($themeconfigfile = get_theme_config_file($theme_selected)) !== null) {
956                         require_once $themeconfigfile;
957                         $theme_config = theme_content($a);
958                 }
959
960                 $tpl = Renderer::getMarkupTemplate('settings/display.tpl');
961                 $o = Renderer::replaceMacros($tpl, [
962                         '$ptitle'       => L10n::t('Display Settings'),
963                         '$form_security_token' => BaseModule::getFormSecurityToken("settings_display"),
964                         '$submit'       => L10n::t('Save Settings'),
965                         '$baseurl' => System::baseUrl(true),
966                         '$uid' => local_user(),
967
968                         '$theme'        => ['theme', L10n::t('Display Theme:'), $theme_selected, '', $themes, true],
969                         '$mobile_theme' => ['mobile_theme', L10n::t('Mobile Theme:'), $mobile_theme_selected, '', $mobile_themes, false],
970                         '$nowarn_insecure' => ['nowarn_insecure',  L10n::t('Suppress warning of insecure networks'), $nowarn_insecure, L10n::t("Should the system suppress the warning that the current group contains members of networks that can't receive non public postings.")],
971                         '$ajaxint'   => ['browser_update',  L10n::t("Update browser every xx seconds"), $browser_update, L10n::t('Minimum of 10 seconds. Enter -1 to disable it.')],
972                         '$itemspage_network'   => ['itemspage_network',  L10n::t("Number of items to display per page:"), $itemspage_network, L10n::t('Maximum of 100 items')],
973                         '$itemspage_mobile_network'   => ['itemspage_mobile_network',  L10n::t("Number of items to display per page when viewed from mobile device:"), $itemspage_mobile_network, L10n::t('Maximum of 100 items')],
974                         '$nosmile'      => ['nosmile', L10n::t("Don't show emoticons"), $nosmile, ''],
975                         '$calendar_title' => L10n::t('Calendar'),
976                         '$first_day_of_week'    => ['first_day_of_week', L10n::t('Beginning of week:'), $first_day_of_week, '', $weekdays, false],
977                         '$noinfo'       => ['noinfo', L10n::t("Don't show notices"), $noinfo, ''],
978                         '$infinite_scroll'      => ['infinite_scroll', L10n::t("Infinite scroll"), $infinite_scroll, ''],
979                         '$no_auto_update'       => ['no_auto_update', L10n::t("Automatic updates only at the top of the network page"), $no_auto_update, L10n::t('When disabled, the network page is updated all the time, which could be confusing while reading.')],
980                         '$bandwidth_saver' => ['bandwidth_saver', L10n::t('Bandwidth Saver Mode'), $bandwidth_saver, L10n::t('When enabled, embedded content is not displayed on automatic updates, they only show on page reload.')],
981                         '$smart_threading' => ['smart_threading', L10n::t('Smart Threading'), $smart_threading, L10n::t('When enabled, suppress extraneous thread indentation while keeping it where it matters. Only works if threading is available and enabled.')],
982
983                         '$d_tset' => L10n::t('General Theme Settings'),
984                         '$d_ctset' => L10n::t('Custom Theme Settings'),
985                         '$d_cset' => L10n::t('Content Settings'),
986                         'stitle' => L10n::t('Theme settings'),
987                         '$theme_config' => $theme_config,
988                 ]);
989
990                 return $o;
991         }
992
993
994         /*
995          * ACCOUNT SETTINGS
996          */
997
998         $profile = DBA::selectFirst('profile', [], ['is-default' => true, 'uid' => local_user()]);
999         if (!DBA::isResult($profile)) {
1000                 notice(L10n::t('Unable to find your profile. Please contact your admin.') . EOL);
1001                 return;
1002         }
1003
1004         $username   = $a->user['username'];
1005         $email      = $a->user['email'];
1006         $nickname   = $a->user['nickname'];
1007         $timezone   = $a->user['timezone'];
1008         $language   = $a->user['language'];
1009         $notify     = $a->user['notify-flags'];
1010         $defloc     = $a->user['default-location'];
1011         $openid     = $a->user['openid'];
1012         $maxreq     = $a->user['maxreq'];
1013         $expire     = ((intval($a->user['expire'])) ? $a->user['expire'] : '');
1014         $unkmail    = $a->user['unkmail'];
1015         $cntunkmail = $a->user['cntunkmail'];
1016
1017         $expire_items = PConfig::get(local_user(), 'expire', 'items', true);
1018         $expire_notes = PConfig::get(local_user(), 'expire', 'notes', true);
1019         $expire_starred = PConfig::get(local_user(), 'expire', 'starred', true);
1020         $expire_photos = PConfig::get(local_user(), 'expire', 'photos', false);
1021         $expire_network_only = PConfig::get(local_user(), 'expire', 'network_only', false);
1022         $suggestme = PConfig::get(local_user(), 'system', 'suggestme', false);
1023
1024         // nowarn_insecure
1025
1026         if (!strlen($a->user['timezone'])) {
1027                 $timezone = date_default_timezone_get();
1028         }
1029
1030         // Set the account type to "Community" when the page is a community page but the account type doesn't fit
1031         // This is only happening on the first visit after the update
1032         if (in_array($a->user['page-flags'], [Contact::PAGE_COMMUNITY, Contact::PAGE_PRVGROUP]) &&
1033                 ($a->user['account-type'] != Contact::ACCOUNT_TYPE_COMMUNITY))
1034                 $a->user['account-type'] = Contact::ACCOUNT_TYPE_COMMUNITY;
1035
1036         $pageset_tpl = Renderer::getMarkupTemplate('settings/pagetypes.tpl');
1037
1038         $pagetype = Renderer::replaceMacros($pageset_tpl, [
1039                 '$account_types'        => L10n::t("Account Types"),
1040                 '$user'                 => L10n::t("Personal Page Subtypes"),
1041                 '$community'            => L10n::t("Community Forum Subtypes"),
1042                 '$account_type'         => $a->user['account-type'],
1043                 '$type_person'          => Contact::ACCOUNT_TYPE_PERSON,
1044                 '$type_organisation'    => Contact::ACCOUNT_TYPE_ORGANISATION,
1045                 '$type_news'            => Contact::ACCOUNT_TYPE_NEWS,
1046                 '$type_community'       => Contact::ACCOUNT_TYPE_COMMUNITY,
1047
1048                 '$account_person'       => ['account-type', L10n::t('Personal Page'), Contact::ACCOUNT_TYPE_PERSON,
1049                                                                         L10n::t('Account for a personal profile.'),
1050                                                                         ($a->user['account-type'] == Contact::ACCOUNT_TYPE_PERSON)],
1051
1052                 '$account_organisation' => ['account-type', L10n::t('Organisation Page'), Contact::ACCOUNT_TYPE_ORGANISATION,
1053                                                                         L10n::t('Account for an organisation that automatically approves contact requests as "Followers".'),
1054                                                                         ($a->user['account-type'] == Contact::ACCOUNT_TYPE_ORGANISATION)],
1055
1056                 '$account_news'         => ['account-type', L10n::t('News Page'), Contact::ACCOUNT_TYPE_NEWS,
1057                                                                         L10n::t('Account for a news reflector that automatically approves contact requests as "Followers".'),
1058                                                                         ($a->user['account-type'] == Contact::ACCOUNT_TYPE_NEWS)],
1059
1060                 '$account_community'    => ['account-type', L10n::t('Community Forum'), Contact::ACCOUNT_TYPE_COMMUNITY,
1061                                                                         L10n::t('Account for community discussions.'),
1062                                                                         ($a->user['account-type'] == Contact::ACCOUNT_TYPE_COMMUNITY)],
1063
1064                 '$page_normal'          => ['page-flags', L10n::t('Normal Account Page'), Contact::PAGE_NORMAL,
1065                                                                         L10n::t('Account for a regular personal profile that requires manual approval of "Friends" and "Followers".'),
1066                                                                         ($a->user['page-flags'] == Contact::PAGE_NORMAL)],
1067
1068                 '$page_soapbox'         => ['page-flags', L10n::t('Soapbox Page'), Contact::PAGE_SOAPBOX,
1069                                                                         L10n::t('Account for a public profile that automatically approves contact requests as "Followers".'),
1070                                                                         ($a->user['page-flags'] == Contact::PAGE_SOAPBOX)],
1071
1072                 '$page_community'       => ['page-flags', L10n::t('Public Forum'), Contact::PAGE_COMMUNITY,
1073                                                                         L10n::t('Automatically approves all contact requests.'),
1074                                                                         ($a->user['page-flags'] == Contact::PAGE_COMMUNITY)],
1075
1076                 '$page_freelove'        => ['page-flags', L10n::t('Automatic Friend Page'), Contact::PAGE_FREELOVE,
1077                                                                         L10n::t('Account for a popular profile that automatically approves contact requests as "Friends".'),
1078                                                                         ($a->user['page-flags'] == Contact::PAGE_FREELOVE)],
1079
1080                 '$page_prvgroup'        => ['page-flags', L10n::t('Private Forum [Experimental]'), Contact::PAGE_PRVGROUP,
1081                                                                         L10n::t('Requires manual approval of contact requests.'),
1082                                                                         ($a->user['page-flags'] == Contact::PAGE_PRVGROUP)],
1083
1084
1085         ]);
1086
1087         $noid = Config::get('system', 'no_openid');
1088
1089         if ($noid) {
1090                 $openid_field = false;
1091         } else {
1092                 $openid_field = ['openid_url', L10n::t('OpenID:'), $openid, L10n::t("\x28Optional\x29 Allow this OpenID to login to this account."), "", "", "url"];
1093         }
1094
1095         $opt_tpl = Renderer::getMarkupTemplate("field_yesno.tpl");
1096         if (Config::get('system', 'publish_all')) {
1097                 $profile_in_dir = '<input type="hidden" name="profile_in_directory" value="1" />';
1098         } else {
1099                 $profile_in_dir = Renderer::replaceMacros($opt_tpl, [
1100                         '$field' => ['profile_in_directory', L10n::t('Publish your default profile in your local site directory?'), $profile['publish'], L10n::t('Your profile will be published in this node\'s <a href="%s">local directory</a>. Your profile details may be publicly visible depending on the system settings.', System::baseUrl().'/directory'), [L10n::t('No'), L10n::t('Yes')]]
1101                 ]);
1102         }
1103
1104         if (strlen(Config::get('system', 'directory'))) {
1105                 $profile_in_net_dir = Renderer::replaceMacros($opt_tpl, [
1106                         '$field' => ['profile_in_netdirectory', L10n::t('Publish your default profile in the global social directory?'), $profile['net-publish'], L10n::t('Your profile will be published in the global friendica directories (e.g. <a href="%s">%s</a>). Your profile will be visible in public.', Config::get('system', 'directory'), Config::get('system', 'directory')), [L10n::t('No'), L10n::t('Yes')]]
1107                 ]);
1108         } else {
1109                 $profile_in_net_dir = '';
1110         }
1111
1112         $hide_friends = Renderer::replaceMacros($opt_tpl, [
1113                 '$field' => ['hide-friends', L10n::t('Hide your contact/friend list from viewers of your default profile?'), $profile['hide-friends'], L10n::t('Your contact list won\'t be shown in your default profile page. You can decide to show your contact list separately for each additional profile you create'), [L10n::t('No'), L10n::t('Yes')]],
1114         ]);
1115
1116         $hide_wall = Renderer::replaceMacros($opt_tpl, [
1117                 '$field' => ['hidewall', L10n::t('Hide your profile details from anonymous viewers?'), $a->user['hidewall'], L10n::t('Anonymous visitors will only see your profile picture, your display name and the nickname you are using on your profile page. Your public posts and replies will still be accessible by other means.'), [L10n::t('No'), L10n::t('Yes')]],
1118         ]);
1119
1120         $blockwall = Renderer::replaceMacros($opt_tpl, [
1121                 '$field' => ['blockwall', L10n::t('Allow friends to post to your profile page?'), (intval($a->user['blockwall']) ? '0' : '1'), L10n::t('Your contacts may write posts on your profile wall. These posts will be distributed to your contacts'), [L10n::t('No'), L10n::t('Yes')]],
1122         ]);
1123
1124         $blocktags = Renderer::replaceMacros($opt_tpl, [
1125                 '$field' => ['blocktags', L10n::t('Allow friends to tag your posts?'), (intval($a->user['blocktags']) ? '0' : '1'), L10n::t('Your contacts can add additional tags to your posts.'), [L10n::t('No'), L10n::t('Yes')]],
1126         ]);
1127
1128         $suggestme = Renderer::replaceMacros($opt_tpl, [
1129                 '$field' => ['suggestme', L10n::t('Allow us to suggest you as a potential friend to new members?'), $suggestme, L10n::t('If you like, Friendica may suggest new members to add you as a contact.'), [L10n::t('No'), L10n::t('Yes')]],
1130         ]);
1131
1132         $unkmail = Renderer::replaceMacros($opt_tpl, [
1133                 '$field' => ['unkmail', L10n::t('Permit unknown people to send you private mail?'), $unkmail, L10n::t('Friendica network users may send you private messages even if they are not in your contact list.'), [L10n::t('No'), L10n::t('Yes')]],
1134         ]);
1135
1136         if (!$profile['publish'] && !$profile['net-publish']) {
1137                 info(L10n::t('Profile is <strong>not published</strong>.') . EOL);
1138         }
1139
1140         $tpl_addr = Renderer::getMarkupTemplate('settings/nick_set.tpl');
1141
1142         $prof_addr = Renderer::replaceMacros($tpl_addr,[
1143                 '$desc' => L10n::t("Your Identity Address is <strong>'%s'</strong> or '%s'.", $nickname . '@' . $a->getHostName() . $a->getURLPath(), System::baseUrl() . '/profile/' . $nickname),
1144                 '$basepath' => $a->getHostName()
1145         ]);
1146
1147         $stpl = Renderer::getMarkupTemplate('settings/settings.tpl');
1148
1149         $expire_arr = [
1150                 'days' => ['expire',  L10n::t("Automatically expire posts after this many days:"), $expire, L10n::t('If empty, posts will not expire. Expired posts will be deleted')],
1151                 'advanced' => L10n::t('Advanced expiration settings'),
1152                 'label' => L10n::t('Advanced Expiration'),
1153                 'items' => ['expire_items',  L10n::t("Expire posts:"), $expire_items, '', [L10n::t('No'), L10n::t('Yes')]],
1154                 'notes' => ['expire_notes',  L10n::t("Expire personal notes:"), $expire_notes, '', [L10n::t('No'), L10n::t('Yes')]],
1155                 'starred' => ['expire_starred',  L10n::t("Expire starred posts:"), $expire_starred, '', [L10n::t('No'), L10n::t('Yes')]],
1156                 'photos' => ['expire_photos',  L10n::t("Expire photos:"), $expire_photos, '', [L10n::t('No'), L10n::t('Yes')]],
1157                 'network_only' => ['expire_network_only',  L10n::t("Only expire posts by others:"), $expire_network_only, '', [L10n::t('No'), L10n::t('Yes')]],
1158         ];
1159
1160         $group_select = Group::displayGroupSelection(local_user(), $a->user['def_gid']);
1161
1162         // Private/public post links for the non-JS ACL form
1163         $private_post = 1;
1164         if (!empty($_REQUEST['public']) && !$_REQUEST['public']) {
1165                 $private_post = 0;
1166         }
1167
1168         $query_str = $a->query_string;
1169         if (strpos($query_str, 'public=1') !== false) {
1170                 $query_str = str_replace(['?public=1', '&public=1'], ['', ''], $query_str);
1171         }
1172
1173         // I think $a->query_string may never have ? in it, but I could be wrong
1174         // It looks like it's from the index.php?q=[etc] rewrite that the web
1175         // server does, which converts any ? to &, e.g. suggest&ignore=61 for suggest?ignore=61
1176         if (strpos($query_str, '?') === false) {
1177                 $public_post_link = '?public=1';
1178         } else {
1179                 $public_post_link = '&public=1';
1180         }
1181
1182         /* Installed langs */
1183         $lang_choices = L10n::getAvailableLanguages();
1184
1185         /// @TODO Fix indending (or so)
1186         $o .= Renderer::replaceMacros($stpl, [
1187                 '$ptitle'       => L10n::t('Account Settings'),
1188
1189                 '$submit'       => L10n::t('Save Settings'),
1190                 '$baseurl' => System::baseUrl(true),
1191                 '$uid' => local_user(),
1192                 '$form_security_token' => BaseModule::getFormSecurityToken("settings"),
1193                 '$nickname_block' => $prof_addr,
1194
1195                 '$h_pass'       => L10n::t('Password Settings'),
1196                 '$password1'=> ['password', L10n::t('New Password:'), '', ''],
1197                 '$password2'=> ['confirm', L10n::t('Confirm:'), '', L10n::t('Leave password fields blank unless changing')],
1198                 '$password3'=> ['opassword', L10n::t('Current Password:'), '', L10n::t('Your current password to confirm the changes')],
1199                 '$password4'=> ['mpassword', L10n::t('Password:'), '', L10n::t('Your current password to confirm the changes')],
1200                 '$oid_enable' => (!Config::get('system', 'no_openid')),
1201                 '$openid'       => $openid_field,
1202
1203                 '$h_basic'      => L10n::t('Basic Settings'),
1204                 '$username' => ['username',  L10n::t('Full Name:'), $username, ''],
1205                 '$email'        => ['email', L10n::t('Email Address:'), $email, '', '', '', 'email'],
1206                 '$timezone' => ['timezone_select' , L10n::t('Your Timezone:'), Temporal::getTimezoneSelect($timezone), ''],
1207                 '$language' => ['language', L10n::t('Your Language:'), $language, L10n::t('Set the language we use to show you friendica interface and to send you emails'), $lang_choices],
1208                 '$defloc'       => ['defloc', L10n::t('Default Post Location:'), $defloc, ''],
1209                 '$allowloc' => ['allow_location', L10n::t('Use Browser Location:'), ($a->user['allow_location'] == 1), ''],
1210
1211
1212                 '$h_prv'        => L10n::t('Security and Privacy Settings'),
1213
1214                 '$maxreq'       => ['maxreq', L10n::t('Maximum Friend Requests/Day:'), $maxreq , L10n::t("\x28to prevent spam abuse\x29")],
1215                 '$permissions' => L10n::t('Default Post Permissions'),
1216                 '$permdesc' => L10n::t("\x28click to open/close\x29"),
1217                 '$visibility' => $profile['net-publish'],
1218                 '$aclselect' => ACL::getFullSelectorHTML($a->user),
1219                 '$suggestme' => $suggestme,
1220                 '$blockwall'=> $blockwall, // array('blockwall', L10n::t('Allow friends to post to your profile page:'), !$blockwall, ''),
1221                 '$blocktags'=> $blocktags, // array('blocktags', L10n::t('Allow friends to tag your posts:'), !$blocktags, ''),
1222
1223                 // ACL permissions box
1224                 '$group_perms' => L10n::t('Show to Groups'),
1225                 '$contact_perms' => L10n::t('Show to Contacts'),
1226                 '$private' => L10n::t('Default Private Post'),
1227                 '$public' => L10n::t('Default Public Post'),
1228                 '$is_private' => $private_post,
1229                 '$return_path' => $query_str,
1230                 '$public_link' => $public_post_link,
1231                 '$settings_perms' => L10n::t('Default Permissions for New Posts'),
1232
1233                 '$group_select' => $group_select,
1234
1235
1236                 '$expire'       => $expire_arr,
1237
1238                 '$profile_in_dir' => $profile_in_dir,
1239                 '$profile_in_net_dir' => $profile_in_net_dir,
1240                 '$hide_friends' => $hide_friends,
1241                 '$hide_wall' => $hide_wall,
1242                 '$unkmail' => $unkmail,
1243                 '$cntunkmail'   => ['cntunkmail', L10n::t('Maximum private messages per day from unknown people:'), $cntunkmail , L10n::t("\x28to prevent spam abuse\x29")],
1244
1245
1246                 '$h_not'        => L10n::t('Notification Settings'),
1247                 '$lbl_not'      => L10n::t('Send a notification email when:'),
1248                 '$notify1'      => ['notify1', L10n::t('You receive an introduction'), ($notify & NOTIFY_INTRO), NOTIFY_INTRO, ''],
1249                 '$notify2'      => ['notify2', L10n::t('Your introductions are confirmed'), ($notify & NOTIFY_CONFIRM), NOTIFY_CONFIRM, ''],
1250                 '$notify3'      => ['notify3', L10n::t('Someone writes on your profile wall'), ($notify & NOTIFY_WALL), NOTIFY_WALL, ''],
1251                 '$notify4'      => ['notify4', L10n::t('Someone writes a followup comment'), ($notify & NOTIFY_COMMENT), NOTIFY_COMMENT, ''],
1252                 '$notify5'      => ['notify5', L10n::t('You receive a private message'), ($notify & NOTIFY_MAIL), NOTIFY_MAIL, ''],
1253                 '$notify6'  => ['notify6', L10n::t('You receive a friend suggestion'), ($notify & NOTIFY_SUGGEST), NOTIFY_SUGGEST, ''],
1254                 '$notify7'  => ['notify7', L10n::t('You are tagged in a post'), ($notify & NOTIFY_TAGSELF), NOTIFY_TAGSELF, ''],
1255                 '$notify8'  => ['notify8', L10n::t('You are poked/prodded/etc. in a post'), ($notify & NOTIFY_POKE), NOTIFY_POKE, ''],
1256
1257                 '$desktop_notifications' => ['desktop_notifications', L10n::t('Activate desktop notifications') , false, L10n::t('Show desktop popup on new notifications')],
1258
1259                 '$email_textonly' => ['email_textonly', L10n::t('Text-only notification emails'),
1260                                                                         PConfig::get(local_user(), 'system', 'email_textonly'),
1261                                                                         L10n::t('Send text only notification emails, without the html part')],
1262
1263                 '$detailed_notif' => ['detailed_notif', L10n::t('Show detailled notifications'),
1264                                                                         PConfig::get(local_user(), 'system', 'detailed_notif'),
1265                                                                         L10n::t('Per default, notifications are condensed to a single notification per item. When enabled every notification is displayed.')],
1266
1267                 '$h_advn' => L10n::t('Advanced Account/Page Type Settings'),
1268                 '$h_descadvn' => L10n::t('Change the behaviour of this account for special situations'),
1269                 '$pagetype' => $pagetype,
1270
1271                 '$relocate' => L10n::t('Relocate'),
1272                 '$relocate_text' => L10n::t("If you have moved this profile from another server, and some of your contacts don't receive your updates, try pushing this button."),
1273                 '$relocate_button' => L10n::t("Resend relocate message to contacts"),
1274
1275         ]);
1276
1277         Addon::callHooks('settings_form', $o);
1278
1279         $o .= '</form>' . "\r\n";
1280
1281         return $o;
1282
1283 }