]> git.mxchange.org Git - friendica.git/blob - src/Module/Api/Mastodon/Apps.php
Merge pull request #12674 from nupplaphil/bug/config_typesafe
[friendica.git] / src / Module / Api / Mastodon / Apps.php
1 <?php
2 /**
3  * @copyright Copyright (C) 2010-2023, the Friendica project
4  *
5  * @license GNU AGPL version 3 or any later version
6  *
7  * This program is free software: you can redistribute it and/or modify
8  * it under the terms of the GNU Affero General Public License as
9  * published by the Free Software Foundation, either version 3 of the
10  * License, or (at your option) any later version.
11  *
12  * This program is distributed in the hope that it will be useful,
13  * but WITHOUT ANY WARRANTY; without even the implied warranty of
14  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
15  * GNU Affero General Public License for more details.
16  *
17  * You should have received a copy of the GNU Affero General Public License
18  * along with this program.  If not, see <https://www.gnu.org/licenses/>.
19  *
20  */
21
22 namespace Friendica\Module\Api\Mastodon;
23
24 use Friendica\Core\System;
25 use Friendica\Database\DBA;
26 use Friendica\DI;
27 use Friendica\Module\BaseApi;
28 use Friendica\Module\Special\HTTPException;
29 use Friendica\Util\Network;
30 use Psr\Http\Message\ResponseInterface;
31
32 /**
33  * Apps class to register new OAuth clients
34  * @see https://docs.joinmastodon.org/methods/apps/#create
35  */
36 class Apps extends BaseApi
37 {
38         public function run(HTTPException $httpException, array $request = [], bool $scopecheck = true): ResponseInterface
39         {
40                 return parent::run($httpException, $request, false);
41         }
42
43         /**
44          * @throws \Friendica\Network\HTTPException\InternalServerErrorException
45          */
46         protected function post(array $request = [])
47         {
48                 if (!empty($request['redirect_uris']) && is_array($request['redirect_uris'])) {
49                         $request['redirect_uris'] = $request['redirect_uris'][0];
50                 }
51
52                 $request = $this->getRequest([
53                         'client_name'   => '',
54                         'redirect_uris' => '',
55                         'scopes'        => 'read',
56                         'website'       => '',
57                 ], $request);
58
59                 // Workaround for AndStatus, see issue https://github.com/andstatus/andstatus/issues/538
60                 $postdata = Network::postdata();
61                 if (!empty($postdata)) {
62                         $postrequest = json_decode($postdata, true);
63                         if (!empty($postrequest) && is_array($postrequest)) {
64                                 $request = array_merge($request, $postrequest);
65                         }
66
67                         if (!empty($request['redirect_uris']) && is_array($request['redirect_uris'])) {
68                                 $request['redirect_uris'] = $request['redirect_uris'][0];
69                         }       
70                 }
71
72                 if (empty($request['client_name']) || empty($request['redirect_uris'])) {
73                         DI::mstdnError()->UnprocessableEntity(DI::l10n()->t('Missing parameters'));
74                 }
75
76                 $client_id     = bin2hex(random_bytes(32));
77                 $client_secret = bin2hex(random_bytes(32));
78
79                 $fields = ['client_id' => $client_id, 'client_secret' => $client_secret, 'name' => $request['client_name'], 'redirect_uri' => $request['redirect_uris']];
80
81                 if (!empty($request['scopes'])) {
82                         $fields['scopes'] = $request['scopes'];
83                 }
84
85                 $fields['read']   = (stripos($request['scopes'], self::SCOPE_READ) !== false);
86                 $fields['write']  = (stripos($request['scopes'], self::SCOPE_WRITE) !== false);
87                 $fields['follow'] = (stripos($request['scopes'], self::SCOPE_FOLLOW) !== false);
88                 $fields['push']   = (stripos($request['scopes'], self::SCOPE_PUSH) !== false);
89
90                 if (!empty($request['website'])) {
91                         $fields['website'] = $request['website'];
92                 }
93
94                 if (!DBA::insert('application', $fields)) {
95                         DI::mstdnError()->InternalError();
96                 }
97
98                 System::jsonExit(DI::mstdnApplication()->createFromApplicationId(DBA::lastInsertId())->toArray());
99         }
100 }