+ // Once we have the author URI, go to the web and try to find their public key
+
+ logger('mod-salmon: Fetching key for ' . $author_link );
+
+
+ $key = get_salmon_key($author_link,$keyhash);
+
+ if(! $key) {
+ logger('mod-salmon: Could not retrieve author key.');
+ salmon_return(400);
+ }
+
+ // Setup RSA stuff to verify the signature
+
+ set_include_path(get_include_path() . PATH_SEPARATOR . 'phpsec');
+
+ require_once('phpsec/Crypt/RSA.php');
+
+ $key_info = explode('.',$key);
+
+ $m = base64url_decode($key_info[1]);
+ $e = base64url_decode($key_info[2]);
+
+ logger('mod-salmon: key details: ' . print_r($key_info,true));
+
+ $rsa = new CRYPT_RSA();
+ $rsa->signatureMode = CRYPT_RSA_SIGNATURE_PKCS1;
+ $rsa->setHash('sha256');
+
+ $rsa->modulus = new Math_BigInteger($m, 256);
+ $rsa->k = strlen($rsa->modulus->toBytes());
+ $rsa->exponent = new Math_BigInteger($e, 256);
+
+ // We should have everything we need now. Let's see if it verifies.
+ // If it fails with the proper data format, try again using just the data
+ // (e.g. status.net)
+
+ $verify = $rsa->verify($signed_data,$signature);
+
+ if(! $verify) {
+ logger('mod-salmon: message did not verify using protocol. Trying statusnet hack.');
+ $verify = $rsa->verify($stnet_signed_data,$signature);
+ }
+
+ if(! $verify) {
+ logger('mod-salmon: Message did not verify. Discarding.');
+ salmon_return(400);
+ }
+
+ logger('mod-salmon: Message verified.');
+
+
+ /*
+ *
+ * If we reached this point, the message is good. Now let's figure out if the author is allowed to send us stuff.
+ *
+ */
+
+ $r = q("SELECT * FROM `contact` WHERE `network` = 'stat' AND ( `url` = '%s' OR `alias` = '%s')
+ AND `uid` = %d LIMIT 1",
+ dbesc($author_link),
+ dbesc($author_link),
+ intval($importer['uid'])
+ );
+ if(! count($r)) {
+ logger('mod-salmon: Author unknown to us.');
+ }
+ if((count($r)) && ($r[0]['readonly'])) {
+ logger('mod-salmon: Ignoring this author.');
+ salmon_return(202);
+ // NOTREACHED
+ }
+
+ require_once('include/items.php');
+
+ // Placeholder for hub discovery. We shouldn't find any hubs
+ // since we supplied the fake feed header - and it doesn't have any.
+
+ $hub = '';
+
+ /**
+ *
+ * anti-spam measure: consume_feed will accept a follow activity from
+ * this person (and nothing else) if there is no existing contact record.
+ *
+ */
+
+ $contact_rec = ((count($r)) ? $r[0] : null);
+
+ consume_feed($feedxml,$importer,$contact_rec,$hub);