+ // Once we have the author URI, go to the web and try to find their public key
+
+ logger('mod-salmon: Fetching key for ' . $author_link );
+
+
+ $key = get_salmon_key($author_link,$keyhash);
+
+ if(! $key) {
+ logger('mod-salmon: Could not retrieve author key.');
+ http_status_exit(400);
+ }
+
+ $key_info = explode('.',$key);
+
+ $m = base64url_decode($key_info[1]);
+ $e = base64url_decode($key_info[2]);
+
+ logger('mod-salmon: key details: ' . print_r($key_info,true), LOGGER_DEBUG);
+
+ $pubkey = metopem($m,$e);
+
+ // We should have everything we need now. Let's see if it verifies.
+
+ $verify = rsa_verify($compliant_format,$signature,$pubkey);
+
+ if(! $verify) {
+ logger('mod-salmon: message did not verify using protocol. Trying padding hack.');
+ $verify = rsa_verify($signed_data,$signature,$pubkey);
+ }
+
+ if(! $verify) {
+ logger('mod-salmon: message did not verify using padding. Trying old statusnet hack.');
+ $verify = rsa_verify($stnet_signed_data,$signature,$pubkey);
+ }
+
+ if(! $verify) {
+ logger('mod-salmon: Message did not verify. Discarding.');
+ http_status_exit(400);
+ }
+
+ logger('mod-salmon: Message verified.');
+
+
+ /*
+ *
+ * If we reached this point, the message is good. Now let's figure out if the author is allowed to send us stuff.
+ *
+ */
+
+ $r = q("SELECT * FROM `contact` WHERE `network` = '%s' AND ( `url` = '%s' OR `alias` = '%s' )
+ AND `uid` = %d LIMIT 1",
+ dbesc(NETWORK_OSTATUS),
+ dbesc($author_link),
+ dbesc($author_link),
+ intval($importer['uid'])
+ );
+ if(! count($r)) {
+ logger('mod-salmon: Author unknown to us.');
+ if(get_pconfig($importer['uid'],'system','ostatus_autofriend')) {
+ require_once('include/follow.php');
+ $result = new_contact($importer['uid'],$author_link);
+ if($result['success']) {
+ $r = q("SELECT * FROM `contact` WHERE `network` = '%s' AND ( `url` = '%s' OR `alias` = '%s' )
+ AND `uid` = %d LIMIT 1",
+ dbesc(NETWORK_OSTATUS),
+ dbesc($author_link),
+ dbesc($author_link),
+ intval($importer['uid'])
+ );
+ }
+ }
+ }
+
+ // is this a follower? Or have we ignored the person?
+ // If so we can not accept this post.
+
+ if((count($r)) && (($r[0]['readonly']) || ($r[0]['rel'] == CONTACT_IS_FOLLOWER) || ($r[0]['blocked']))) {
+ logger('mod-salmon: Ignoring this author.');
+ http_status_exit(202);
+ // NOTREACHED
+ }
+
+ require_once('include/items.php');
+
+ // Placeholder for hub discovery. We shouldn't find any hubs
+ // since we supplied the fake feed header - and it doesn't have any.
+
+ $hub = '';
+
+ /**
+ *
+ * anti-spam measure: consume_feed will accept a follow activity from
+ * this person (and nothing else) if there is no existing contact record.
+ *
+ */
+
+ $contact_rec = ((count($r)) ? $r[0] : null);
+
+ consume_feed($feedxml,$importer,$contact_rec,$hub);
+
+ http_status_exit(200);
+}