]> git.mxchange.org Git - friendica.git/blob - src/Module/Search/Acl.php
1016756008973291dca02bba042ac73454f950fe
[friendica.git] / src / Module / Search / Acl.php
1 <?php
2
3 namespace Friendica\Module\Search;
4
5 use Friendica\BaseModule;
6 use Friendica\Content\Widget;
7 use Friendica\Core\Hook;
8 use Friendica\Core\L10n;
9 use Friendica\Core\Logger;
10 use Friendica\Core\Protocol;
11 use Friendica\Core\Search;
12 use Friendica\Database\DBA;
13 use Friendica\Model\Contact;
14 use Friendica\Model\Item;
15 use Friendica\Network\HTTPException;
16 use Friendica\Util\Proxy as ProxyUtils;
17 use Friendica\Util\Strings;
18
19 /**
20  * ACL selector json backend
21  *
22  * @package Friendica\Module\Search
23  */
24 class Acl extends BaseModule
25 {
26         const TYPE_GLOBAL_CONTACT        = 'x';
27         const TYPE_MENTION_CONTACT       = 'c';
28         const TYPE_MENTION_GROUP         = 'g';
29         const TYPE_MENTION_CONTACT_GROUP = '';
30         const TYPE_MENTION_FORUM         = 'f';
31         const TYPE_PRIVATE_MESSAGE       = 'm';
32         const TYPE_ANY_CONTACT           = 'a';
33
34         public static function rawContent()
35         {
36                 if (!local_user()) {
37                         throw new HTTPException\UnauthorizedException(L10n::t('You must be logged in to use this module.'));
38                 }
39
40                 $type = $_REQUEST['type'] ?? self::TYPE_MENTION_CONTACT_GROUP;
41
42                 if ($type === self::TYPE_GLOBAL_CONTACT) {
43                         $o = self::globalContactSearch();
44                 } else {
45                         $o = self::regularContactSearch($type);
46                 }
47
48                 echo json_encode($o);
49                 exit;
50         }
51
52         private static function globalContactSearch()
53         {
54                 // autocomplete for global contact search (e.g. navbar search)
55                 $search = Strings::escapeTags(trim($_REQUEST['search']));
56                 $mode = $_REQUEST['smode'];
57                 $page = $_REQUEST['page'] ?? 1;
58
59                 $r = Search::searchGlobalContact($search, $mode, $page);
60
61                 $contacts = [];
62                 foreach ($r as $g) {
63                         $contacts[] = [
64                                 'photo'   => ProxyUtils::proxifyUrl($g['photo'], false, ProxyUtils::SIZE_MICRO),
65                                 'name'    => htmlspecialchars($g['name']),
66                                 'nick'    => $g['addr'] ?: $g['url'],
67                                 'network' => $g['network'],
68                                 'link'    => $g['url'],
69                                 'forum'   => !empty($g['community']) ? 1 : 0,
70                         ];
71                 }
72
73                 $o = [
74                         'start' => ($page - 1) * 20,
75                         'count' => 1000,
76                         'items' => $contacts,
77                 ];
78
79                 return $o;
80         }
81
82         private static function regularContactSearch(string $type)
83         {
84                 $start   = $_REQUEST['start']        ?? 0;
85                 $count   = $_REQUEST['count']        ?? 100;
86                 $search  = $_REQUEST['search']       ?? '';
87                 $conv_id = $_REQUEST['conversation'] ?? null;
88
89                 // For use with jquery.textcomplete for private mail completion
90                 if (!empty($_REQUEST['query'])) {
91                         if (!$type) {
92                                 $type = self::TYPE_PRIVATE_MESSAGE;
93                         }
94                         $search = $_REQUEST['query'];
95                 }
96
97                 Logger::info('ACL {action} - {subaction}', ['module' => 'acl', 'action' => 'content', 'subaction' => 'search', 'search' => $search, 'type' => $type, 'conversation' => $conv_id]);
98
99                 $sql_extra = '';
100                 $sql_extra2 = '';
101
102                 if ($search != '') {
103                         $sql_extra = "AND `name` LIKE '%%" . DBA::escape($search) . "%%'";
104                         $sql_extra2 = "AND (`attag` LIKE '%%" . DBA::escape($search) . "%%' OR `name` LIKE '%%" . DBA::escape($search) . "%%' OR `nick` LIKE '%%" . DBA::escape($search) . "%%')";
105                 }
106
107                 // count groups and contacts
108                 $group_count = 0;
109                 if ($type == self::TYPE_MENTION_CONTACT_GROUP || $type == self::TYPE_MENTION_GROUP) {
110                         $r = q("SELECT COUNT(*) AS g FROM `group` WHERE NOT `deleted` AND `uid` = %d $sql_extra",
111                                 intval(local_user())
112                         );
113                         $group_count = (int) $r[0]['g'];
114                 }
115
116                 $sql_extra2 .= ' ' . Widget::unavailableNetworks();
117
118                 $contact_count = 0;
119                 switch ($type) {
120                         case self::TYPE_MENTION_CONTACT_GROUP:
121                         case self::TYPE_MENTION_CONTACT:
122                                 // autocomplete for editor mentions
123                                 $r = q("SELECT COUNT(*) AS c FROM `contact`
124                                         WHERE `uid` = %d AND NOT `self` AND NOT `deleted`
125                                         AND NOT `blocked` AND NOT `pending` AND NOT `archive`
126                                         AND `notify` != '' $sql_extra2",
127                                         intval(local_user())
128                                 );
129                                 $contact_count = (int) $r[0]['c'];
130                                 break;
131
132                         case self::TYPE_MENTION_FORUM:
133                                 // autocomplete for editor mentions of forums
134                                 $r = q("SELECT COUNT(*) AS c FROM `contact`
135                                         WHERE `uid` = %d AND NOT `self` AND NOT `deleted`
136                                         AND NOT `blocked` AND NOT `pending` AND NOT `archive`
137                                         AND (`forum` OR `prv`)
138                                         AND `notify` != '' $sql_extra2",
139                                         intval(local_user())
140                                 );
141                                 $contact_count = (int) $r[0]['c'];
142                                 break;
143
144                         case self::TYPE_PRIVATE_MESSAGE:
145                                 // autocomplete for Private Messages
146                                 $r = q("SELECT COUNT(*) AS c FROM `contact`
147                                         WHERE `uid` = %d AND NOT `self` AND NOT `deleted`
148                                         AND NOT `blocked` AND NOT `pending` AND NOT `archive`
149                                         AND `network` IN ('%s', '%s', '%s') $sql_extra2",
150                                         intval(local_user()),
151                                         DBA::escape(Protocol::ACTIVITYPUB),
152                                         DBA::escape(Protocol::DFRN),
153                                         DBA::escape(Protocol::DIASPORA)
154                                 );
155                                 $contact_count = (int) $r[0]['c'];
156                                 break;
157
158                         case self::TYPE_ANY_CONTACT:
159                         default:
160                                 // autocomplete for Contacts
161                                 $r = q("SELECT COUNT(*) AS c FROM `contact`
162                                         WHERE `uid` = %d AND NOT `self`
163                                         AND NOT `pending` AND NOT `deleted` $sql_extra2",
164                                         intval(local_user())
165                                 );
166                                 $contact_count = (int) $r[0]['c'];
167                                 break;
168                 }
169
170                 $tot = $group_count + $contact_count;
171
172                 $groups = [];
173                 $contacts = [];
174
175                 if ($type == self::TYPE_MENTION_CONTACT_GROUP || $type == self::TYPE_MENTION_GROUP) {
176                         /// @todo We should cache this query.
177                         // This can be done when we can delete cache entries via wildcard
178                         $r = q("SELECT `group`.`id`, `group`.`name`, GROUP_CONCAT(DISTINCT `group_member`.`contact-id` SEPARATOR ',') AS uids
179                                 FROM `group`
180                                 INNER JOIN `group_member` ON `group_member`.`gid`=`group`.`id`
181                                 WHERE NOT `group`.`deleted` AND `group`.`uid` = %d
182                                         $sql_extra
183                                 GROUP BY `group`.`name`, `group`.`id`
184                                 ORDER BY `group`.`name`
185                                 LIMIT %d, %d",
186                                 intval(local_user()),
187                                 intval($start),
188                                 intval($count)
189                         );
190
191                         foreach ($r as $g) {
192                                 $groups[] = [
193                                         'type'  => 'g',
194                                         'photo' => 'images/twopeople.png',
195                                         'name'  => htmlspecialchars($g['name']),
196                                         'id'    => intval($g['id']),
197                                         'uids'  => array_map('intval', explode(',', $g['uids'])),
198                                         'link'  => '',
199                                         'forum' => '0'
200                                 ];
201                         }
202                         if ((count($groups) > 0) && ($search == '')) {
203                                 $groups[] = ['separator' => true];
204                         }
205                 }
206
207                 $r = [];
208                 switch ($type) {
209                         case self::TYPE_MENTION_CONTACT_GROUP:
210                                 $r = q("SELECT `id`, `name`, `nick`, `micro`, `network`, `url`, `attag`, `addr`, `forum`, `prv`, (`prv` OR `forum`) AS `frm` FROM `contact`
211                                         WHERE `uid` = %d AND NOT `self` AND NOT `deleted` AND NOT `blocked` AND NOT `pending` AND NOT `archive` AND `notify` != ''
212                                         AND NOT (`network` IN ('%s', '%s'))
213                                         $sql_extra2
214                                         ORDER BY `name`",
215                                         intval(local_user()),
216                                         DBA::escape(Protocol::OSTATUS),
217                                         DBA::escape(Protocol::STATUSNET)
218                                 );
219                                 break;
220
221                         case self::TYPE_MENTION_CONTACT:
222                                 $r = q("SELECT `id`, `name`, `nick`, `micro`, `network`, `url`, `attag`, `addr`, `forum`, `prv` FROM `contact`
223                                         WHERE `uid` = %d AND NOT `self` AND NOT `deleted` AND NOT `blocked` AND NOT `pending` AND NOT `archive` AND `notify` != ''
224                                         AND NOT (`network` IN ('%s'))
225                                         $sql_extra2
226                                         ORDER BY `name`",
227                                         intval(local_user()),
228                                         DBA::escape(Protocol::STATUSNET)
229                                 );
230                                 break;
231
232                         case self::TYPE_MENTION_FORUM:
233                                 $r = q("SELECT `id`, `name`, `nick`, `micro`, `network`, `url`, `attag`, `addr`, `forum`, `prv` FROM `contact`
234                                         WHERE `uid` = %d AND NOT `self` AND NOT `deleted` AND NOT `blocked` AND NOT `pending` AND NOT `archive` AND `notify` != ''
235                                         AND NOT (`network` IN ('%s'))
236                                         AND (`forum` OR `prv`)
237                                         $sql_extra2
238                                         ORDER BY `name`",
239                                         intval(local_user()),
240                                         DBA::escape(Protocol::STATUSNET)
241                                 );
242                                 break;
243
244                         case self::TYPE_PRIVATE_MESSAGE:
245                                 $r = q("SELECT `id`, `name`, `nick`, `micro`, `network`, `url`, `attag`, `addr` FROM `contact`
246                                         WHERE `uid` = %d AND NOT `self` AND NOT `deleted` AND NOT `blocked` AND NOT `pending` AND NOT `archive`
247                                         AND `network` IN ('%s', '%s', '%s')
248                                         $sql_extra2
249                                         ORDER BY `name`",
250                                         intval(local_user()),
251                                         DBA::escape(Protocol::ACTIVITYPUB),
252                                         DBA::escape(Protocol::DFRN),
253                                         DBA::escape(Protocol::DIASPORA)
254                                 );
255                                 break;
256
257                         case self::TYPE_ANY_CONTACT:
258                         default:
259                                 $r = q("SELECT `id`, `name`, `nick`, `micro`, `network`, `url`, `attag`, `addr`, `forum`, `prv` FROM `contact`
260                                         WHERE `uid` = %d AND NOT `deleted` AND NOT `pending` AND NOT `archive`
261                                         $sql_extra2
262                                         ORDER BY `name`",
263                                         intval(local_user())
264                                 );
265                                 break;
266                 }
267
268                 if (DBA::isResult($r)) {
269                         $forums = [];
270                         foreach ($r as $g) {
271                                 $entry = [
272                                         'type'    => 'c',
273                                         'photo'   => ProxyUtils::proxifyUrl($g['micro'], false, ProxyUtils::SIZE_MICRO),
274                                         'name'    => htmlspecialchars($g['name']),
275                                         'id'      => intval($g['id']),
276                                         'network' => $g['network'],
277                                         'link'    => $g['url'],
278                                         'nick'    => htmlentities(($g['attag'] ?? '') ?: $g['nick']),
279                                         'addr'    => htmlentities(($g['addr'] ?? '') ?: $g['url']),
280                                         'forum'   => !empty($g['forum']) || !empty($g['prv']) ? 1 : 0,
281                                 ];
282                                 if ($entry['forum']) {
283                                         $forums[] = $entry;
284                                 } else {
285                                         $contacts[] = $entry;
286                                 }
287                         }
288                         if (count($forums) > 0) {
289                                 if ($search == '') {
290                                         $forums[] = ['separator' => true];
291                                 }
292                                 $contacts = array_merge($forums, $contacts);
293                         }
294                 }
295
296                 $items = array_merge($groups, $contacts);
297
298                 if ($conv_id) {
299                         // In multi threaded posts the conv_id is not the parent of the whole thread
300                         $parent_item = Item::selectFirst(['parent'], ['id' => $conv_id]);
301                         if (DBA::isResult($parent_item)) {
302                                 $conv_id = $parent_item['parent'];
303                         }
304
305                         /*
306                          * if $conv_id is set, get unknown contacts in thread
307                          * but first get known contacts url to filter them out
308                          */
309                         $known_contacts = array_map(function ($i) {
310                                 return $i['link'];
311                         }, $contacts);
312
313                         $unknown_contacts = [];
314
315                         $condition = ["`parent` = ?", $conv_id];
316                         $params = ['order' => ['author-name' => true]];
317                         $authors = Item::selectForUser(local_user(), ['author-link'], $condition, $params);
318                         $item_authors = [];
319                         while ($author = Item::fetch($authors)) {
320                                 $item_authors[$author['author-link']] = $author['author-link'];
321                         }
322                         DBA::close($authors);
323
324                         foreach ($item_authors as $author) {
325                                 if (in_array($author, $known_contacts)) {
326                                         continue;
327                                 }
328
329                                 $contact = Contact::getDetailsByURL($author);
330
331                                 if (count($contact) > 0) {
332                                         $unknown_contacts[] = [
333                                                 'type'    => 'c',
334                                                 'photo'   => ProxyUtils::proxifyUrl($contact['micro'], false, ProxyUtils::SIZE_MICRO),
335                                                 'name'    => htmlspecialchars($contact['name']),
336                                                 'id'      => intval($contact['cid']),
337                                                 'network' => $contact['network'],
338                                                 'link'    => $contact['url'],
339                                                 'nick'    => htmlentities(($contact['nick'] ?? '') ?: $contact['addr']),
340                                                 'addr'    => htmlentities(($contact['addr'] ?? '') ?: $contact['url']),
341                                                 'forum'   => $contact['forum']
342                                         ];
343                                 }
344                         }
345
346                         $items = array_merge($items, $unknown_contacts);
347                         $tot += count($unknown_contacts);
348                 }
349
350                 $results = [
351                         'tot'      => $tot,
352                         'start'    => $start,
353                         'count'    => $count,
354                         'groups'   => $groups,
355                         'contacts' => $contacts,
356                         'items'    => $items,
357                         'type'     => $type,
358                         'search'   => $search,
359                 ];
360
361                 Hook::callAll('acl_lookup_end', $results);
362
363                 $o = [
364                         'tot'   => $results['tot'],
365                         'start' => $results['start'],
366                         'count' => $results['count'],
367                         'items' => $results['items'],
368                 ];
369
370                 return $o;
371         }
372 }