+ * {@inheritDoc}
+ */
+ public function run(array $request = []): ResponseInterface
+ {
+ // @see https://github.com/tootsuite/mastodon/blob/c3aef491d66aec743a3a53e934a494f653745b61/config/initializers/cors.rb
+ if (substr($request['pagename'] ?? '', 0, 12) == '.well-known/') {
+ $this->response->setHeader('*', 'Access-Control-Allow-Origin');
+ $this->response->setHeader('*', 'Access-Control-Allow-Headers');
+ $this->response->setHeader(Router::GET, 'Access-Control-Allow-Methods');
+ $this->response->setHeader('false', 'Access-Control-Allow-Credentials');
+ } elseif (substr($request['pagename'] ?? '', 0, 8) == 'profile/') {
+ $this->response->setHeader('*', 'Access-Control-Allow-Origin');
+ $this->response->setHeader('*', 'Access-Control-Allow-Headers');
+ $this->response->setHeader(Router::GET, 'Access-Control-Allow-Methods');
+ $this->response->setHeader('false', 'Access-Control-Allow-Credentials');
+ } elseif (substr($request['pagename'] ?? '', 0, 4) == 'api/') {
+ $this->response->setHeader('*', 'Access-Control-Allow-Origin');
+ $this->response->setHeader('*', 'Access-Control-Allow-Headers');
+ $this->response->setHeader(implode(',', Router::ALLOWED_METHODS), 'Access-Control-Allow-Methods');
+ $this->response->setHeader('false', 'Access-Control-Allow-Credentials');
+ $this->response->setHeader('Link', 'Access-Control-Expose-Headers');
+ } elseif (substr($request['pagename'] ?? '', 0, 11) == 'oauth/token') {
+ $this->response->setHeader('*', 'Access-Control-Allow-Origin');
+ $this->response->setHeader('*', 'Access-Control-Allow-Headers');
+ $this->response->setHeader(Router::POST, 'Access-Control-Allow-Methods');
+ $this->response->setHeader('false', 'Access-Control-Allow-Credentials');
+ }
+
+ $placeholder = '';
+
+ $this->profiler->set(microtime(true), 'ready');
+ $timestamp = microtime(true);
+
+ Core\Hook::callAll($this->args->getModuleName() . '_mod_init', $placeholder);
+
+ $this->profiler->set(microtime(true) - $timestamp, 'init');
+
+ switch ($this->server['REQUEST_METHOD'] ?? Router::GET) {
+ case Router::DELETE:
+ $this->delete($request);
+ break;
+ case Router::PATCH:
+ $this->patch($request);
+ break;
+ case Router::POST:
+ Core\Hook::callAll($this->args->getModuleName() . '_mod_post', $request);
+ $this->post($request);
+ break;
+ case Router::PUT:
+ $this->put($request);
+ break;
+ }
+
+ $timestamp = microtime(true);
+ // "rawContent" is especially meant for technical endpoints.
+ // This endpoint doesn't need any theme initialization or other comparable stuff.
+ $this->rawContent($request);
+
+ try {
+ $arr = ['content' => ''];
+ Hook::callAll(static::class . '_mod_content', $arr);
+ $this->response->addContent($arr['content']);
+ $this->response->addContent($this->content($request));
+ } catch (HTTPException $e) {
+ $this->response->addContent((new ModuleHTTPException())->content($e));
+ } finally {
+ $this->profiler->set(microtime(true) - $timestamp, 'content');
+ }
+
+ return $this->response->generate();
+ }
+
+ /**
+ * Checks request inputs and sets default parameters
+ *
+ * @param array $defaults Associative array of expected request keys and their default typed value. A null
+ * value will remove the request key from the resulting value array.
+ * @param array $input Custom REQUEST array, superglobal instead