+ $r_json = (x($_GET,'response') && $_GET['response']=='json');
+
+ if($a->argc > 1) {
+ if(! x($_FILES,'media')) {
+ $nick = $a->argv[1];
+ $r = q("SELECT `user`.*, `contact`.`id` FROM `user` INNER JOIN `contact` on `user`.`uid` = `contact`.`uid` WHERE `user`.`nickname` = '%s' AND `user`.`blocked` = 0 and `contact`.`self` = 1 LIMIT 1",
+ dbesc($nick)
+ );
+
+ if(! count($r)){
+ if ($r_json) {
+ echo json_encode(array('error'=>t('Invalid request.')));
+ killme();
+ }
+ return;
+ }
+ } else {
+ $user_info = api_get_user($a);
+ $r = q("SELECT `user`.*, `contact`.`id` FROM `user` INNER JOIN `contact` on `user`.`uid` = `contact`.`uid` WHERE `user`.`nickname` = '%s' AND `user`.`blocked` = 0 and `contact`.`self` = 1 LIMIT 1",
+ dbesc($user_info['screen_name'])
+ );
+ }
+ } else {
+ if ($r_json) {
+ echo json_encode(array('error'=>t('Invalid request.')));
+ killme();
+ }
+ return;
+ }
+
+ $can_post = false;
+ $visitor = 0;
+
+ $page_owner_uid = $r[0]['uid'];
+ $default_cid = $r[0]['id'];
+ $page_owner_nick = $r[0]['nickname'];
+ $community_page = (($r[0]['page-flags'] == PAGE_COMMUNITY) ? true : false);
+
+ if((local_user()) && (local_user() == $page_owner_uid))
+ $can_post = true;
+ else {
+ if($community_page && remote_user()) {
+ $cid = 0;
+ if(is_array($_SESSION['remote'])) {
+ foreach($_SESSION['remote'] as $v) {
+ if($v['uid'] == $page_owner_uid) {
+ $cid = $v['cid'];
+ break;
+ }
+ }
+ }
+ if($cid) {
+
+ $r = q("SELECT `uid` FROM `contact` WHERE `blocked` = 0 AND `pending` = 0 AND `id` = %d AND `uid` = %d LIMIT 1",
+ intval($cid),
+ intval($page_owner_uid)
+ );
+ if(count($r)) {
+ $can_post = true;
+ $visitor = $cid;
+ }
+ }
+ }
+ }
+
+
+ if(! $can_post) {
+ if ($r_json) {
+ echo json_encode(array('error'=>t('Permission denied.')));
+ killme();
+ }
+ notice( t('Permission denied.') . EOL );
+ killme();
+ }
+
+ if(! x($_FILES,'userfile') && ! x($_FILES,'media')){
+ if ($r_json) {
+ echo json_encode(array('error'=>t('Invalid request.')));
+ }
+ killme();
+ }
+
+ $src = "";
+ if(x($_FILES,'userfile')) {
+ $src = $_FILES['userfile']['tmp_name'];
+ $filename = basename($_FILES['userfile']['name']);
+ $filesize = intval($_FILES['userfile']['size']);
+ $filetype = $_FILES['userfile']['type'];
+ }
+ elseif(x($_FILES,'media')) {
+ if (is_array($_FILES['media']['tmp_name']))
+ $src = $_FILES['media']['tmp_name'][0];
+ else
+ $src = $_FILES['media']['tmp_name'];
+
+ if (is_array($_FILES['media']['name']))
+ $filename = basename($_FILES['media']['name'][0]);
+ else
+ $filename = basename($_FILES['media']['name']);
+
+ if (is_array($_FILES['media']['size']))
+ $filesize = intval($_FILES['media']['size'][0]);
+ else
+ $filesize = intval($_FILES['media']['size']);
+
+ if (is_array($_FILES['media']['type']))
+ $filetype = $_FILES['media']['type'][0];
+ else
+ $filetype = $_FILES['media']['type'];
+ }
+
+ if ($src=="") {
+ if ($r_json) {
+ echo json_encode(array('error'=>t('Invalid request.')));
+ killme();
+ }
+ notice(t('Invalid request.').EOL);
+ killme();
+ }
+
+ // This is a special treatment for picture upload from Twidere
+ if (($filename == "octet-stream") AND ($filetype != "")) {
+ $filename = $filetype;
+ $filetype = "";
+ }
+
+ if ($filetype=="")
+ $filetype=guess_image_type($filename);
+
+ // If there is a temp name, then do a manual check
+ // This is more reliable than the provided value
+
+ $imagedata = getimagesize($src);
+ if ($imagedata)
+ $filetype = $imagedata['mime'];
+
+ logger("File upload src: ".$src." - filename: ".$filename.
+ " - size: ".$filesize." - type: ".$filetype, LOGGER_DEBUG);
+
+ $maximagesize = get_config('system','maximagesize');
+
+ if(($maximagesize) && ($filesize > $maximagesize)) {
+ $msg = sprintf( t('Image exceeds size limit of %s'), formatBytes($maximagesize));
+ if ($r_json) {
+ echo json_encode(array('error'=>$msg));
+ } else {
+ echo $msg. EOL;
+ }
+ @unlink($src);