]> git.mxchange.org Git - quix0rs-gnu-social.git/blobdiff - actions/api.php
debug logging in __process
[quix0rs-gnu-social.git] / actions / api.php
index 21404e331bf1a118814e6e20787735eb86de263a..c4cfd569d61c66a1c90c56ce6c92088d2666c34a 100644 (file)
 
 if (!defined('LACONICA')) { exit(1); }
 
-// XXX: Not sure of terminology yet... maybe call things "api_methods" insteads of "commands"
-
 class ApiAction extends Action {
 
+       var $user;
+       var $content_type;
+       var $api_arg;
+       var $api_method;
+       var $api_action;
+       
        function handle($args) {
                parent::handle($args);
 
-               $command = $this->arg('command');
-               
-               # XXX Maybe check to see if the command actually exists first
+               $this->api_action = $this->arg('apiaction');
+               $method = $this->arg('method');
+               $argument = $this->arg('argument');
                
-               if($this->requires_auth($command)) {
+               if (isset($argument)) {
+                       $cmdext = explode('.', $argument);
+                       $this->api_arg =  $cmdext[0];
+                       $this->api_method = $method;
+                       $this->content_type = strtolower($cmdext[1]);
+               } else {
+                       #content type will be an extension on the method
+                       $cmdext = explode('.', $method);
+                       $this->api_method = $cmdext[0];
+                       $this->content_type = strtolower($cmdext[1]);
+               }
+                                                               
+               # XXX Maybe check to see if the command actually exists first?
+               if($this->requires_auth()) {
                        if (!isset($_SERVER['PHP_AUTH_USER'])) {
                                
                                # This header makes basic auth go
-                               header('WWW-Authenticate: Basic realm="Laconica API');
+                               header('WWW-Authenticate: Basic realm="Laconica API"');
                                
                                # if the user hits cancel -- bam!
-                               common_show_basic_auth_error();         
+                               $this->show_basic_auth_error();         
                        } else {
                                $nickname = $_SERVER['PHP_AUTH_USER'];
                                $password = $_SERVER['PHP_AUTH_PW'];
                                $user = common_check_user($nickname, $password);
                                
                                if ($user) {
-                                       $this->process_command($command, $nickname, $password);
+                                       $this->user = $user;
+                                       $this->process_command();
                                } else {
                                        # basic authentication failed
-                                       common_show_basic_auth_error();         
+                                       $this->show_basic_auth_error();         
                                }                       
                        }
-               
                } else {
-                       $this->process_command($command);
-               }
+                       $this->process_command();
+               }       
        }
        
-       # this is where we can dispatch off to api Class files
-       function process_command($command, $nickname=NULL, $password=NULL) {
-       
-               $parts = explode('.', $command);
-               $api_action = "api_$parts[0]";
-               $extension = $parts[1]; # requested content type
-                               
-               $api_actionfile = INSTALLDIR."/actions/$api_action.php";
-               
-               if (file_exists($api_actionfile)) {
-                       require_once($api_actionfile);
-                       $action_class = ucfirst($api_action)."Action";
+       function process_command() {            
+               $action = "twitapi$this->api_action";
+               $actionfile = INSTALLDIR."/actions/$action.php";                
+               if (file_exists($actionfile)) {
+                       require_once($actionfile);
+                       $action_class = ucfirst($action)."Action";
                        $action_obj = new $action_class();
 
-                       # need to pass off nick and password and stuff ... put in $args? constructor? 
-                       # pull from $_REQUEST later?
-                       call_user_func(array($action_obj, 'handle'), $_REQUEST);
-               } else {
-                       
-                       # need appropriate API error functs
-                       print "\nerror!\n";
+                       if (method_exists($action_obj, $this->api_method)) {
+                               
+                               $apidata = array(       'content-type' => $this->content_type,
+                                                                       'api_method' => $this->api_method,
+                                                                       'api_arg' => $this->api_arg,
+                                                                       'user' => $this->user);
+                               
+                               call_user_func(array($action_obj, $this->api_method), $_REQUEST, $apidata);
+                               # all API methods should exit()
+                       }
                }
+               common_user_error("API method not found!", $code=404);
        }
 
+
        # Whitelist of API methods that don't need authentication
-       function requires_auth($command) {
+       function requires_auth() {
+               static $noauth = array( 'statuses/public_timeline',
+                                                               'statuses/show',
+                                                               'users/show',
+                                                               'help/test', 
+                                                               'help/downtime_schedule');
+               
+               static $bareauth = array('statuses/user_timeline',
+                                                                'statuses/friends', 
+                                                                'statuses/followers');
+
+               $fullname = "$this->api_action/$this->api_method";
                
-               # The only command that doesn't in Twitter's API is public_timeline
-               if (ereg('^public_timeline.*$', $command)) {
+               if (in_array($fullname, $bareauth)) {
+                       # bareauth: only needs auth if without an argument
+                       if ($this->api_arg) {
+                               return false;
+                       } else {
+                               return true;
+                       }
+               } else if (in_array($fullname, $noauth)) {
+                       # noauth: never needs auth
                        return false;
+               } else {
+                       # everybody else needs auth
+                       return true;
                }
-               return true;
+       }
+       
+       function show_basic_auth_error() {
+               header('HTTP/1.1 401 Unauthorized');
+               header('Content-type: text/plain');
+               print("Could not authenticate you."); # exactly what Twitter says - no \n
+               exit();
        }
                
 }