]> git.mxchange.org Git - quix0rs-gnu-social.git/blobdiff - actions/foaf.php
XSS vulnerability when remote-subscribing
[quix0rs-gnu-social.git] / actions / foaf.php
index e0662aa2fa43cc53ecd526573941e657897db18d..260388ba447b72819ea0f908e4da35e9ade80391 100644 (file)
  * along with this program.  If not, see <http://www.gnu.org/licenses/>.
  */
 
-if (!defined('STATUSNET') && !defined('LACONICA')) { exit(1); }
+if (!defined('GNUSOCIAL')) { exit(1); }
 
 define('LISTENER', 1);
 define('LISTENEE', -1);
 define('BOTH', 0);
 
 // @todo XXX: Documentation missing.
-class FoafAction extends Action
+class FoafAction extends ManagedAction
 {
     function isReadOnly($args)
     {
         return true;
     }
 
-    function prepare($args)
+    protected function doPreparation()
     {
-        parent::prepare($args);
-
         $nickname_arg = $this->arg('nickname');
 
         if (empty($nickname_arg)) {
             // TRANS: Client error displayed when requesting Friends of a Friend feed without providing a user nickname.
             $this->clientError(_('No such user.'), 404);
-            return false;
         }
 
         $this->nickname = common_canonical_nickname($nickname_arg);
@@ -51,7 +48,6 @@ class FoafAction extends Action
             common_redirect(common_local_url('foaf',
                                              array('nickname' => $this->nickname)),
                             301);
-            return false;
         }
 
         $this->user = User::getKV('nickname', $this->nickname);
@@ -59,7 +55,6 @@ class FoafAction extends Action
         if (!$this->user) {
             // TRANS: Client error displayed when requesting Friends of a Friend feed for an object that is not a user.
             $this->clientError(_('No such user.'), 404);
-            return false;
         }
 
         $this->profile = $this->user->getProfile();
@@ -67,16 +62,13 @@ class FoafAction extends Action
         if (!$this->profile) {
             // TRANS: Error message displayed when referring to a user without a profile.
             $this->serverError(_('User has no profile.'), 500);
-            return false;
         }
 
         return true;
     }
 
-    function handle($args)
+    public function showPage()
     {
-        parent::handle($args);
-
         header('Content-Type: application/rdf+xml');
 
         $this->startXML();
@@ -94,11 +86,10 @@ class FoafAction extends Action
 
         // This is the document about the user
 
-        $this->showPpd('', $this->user->uri);
+        $this->showPpd('', $this->user->getUri());
 
         // Would be nice to tell if they were a Person or not (e.g. a #person usertag?)
-        $this->elementStart('Agent', array('rdf:about' =>
-                                             $this->user->uri));
+        $this->elementStart('Agent', array('rdf:about' => $this->user->getUri()));
         if ($this->user->email) {
             $this->element('mbox_sha1sum', null, sha1('mailto:' . $this->user->email));
         }
@@ -162,7 +153,7 @@ class FoafAction extends Action
         }
 
         $person = $this->showMicrobloggingAccount($this->profile,
-                                     common_root_url(), $this->user->uri,
+                                     common_root_url(), $this->user->getUri(),
                                      /*$fetchSubscriptions*/true,
                                      /*$isSubscriber*/false);
 
@@ -175,7 +166,7 @@ class FoafAction extends Action
         if ($sub->find()) {
             while ($sub->fetch()) {
                 $profile = Profile::getKV('id', $sub->subscriber);
-                if (empty($profile)) {
+                if (!$profile instanceof Profile) {
                     common_debug('Got a bad subscription: '.print_r($sub,true));
                     continue;
                 }
@@ -213,7 +204,7 @@ class FoafAction extends Action
             $profile = Profile::getKV($id);
             $this->elementStart('Agent', array('rdf:about' => $uri));
             if ($type == BOTH) {
-                $this->element('knows', array('rdf:resource' => $this->user->uri));
+                $this->element('knows', array('rdf:resource' => $this->user->getUri()));
             }
             $this->showMicrobloggingAccount($profile,
                                    ($local == 'local') ? common_root_url() : null,
@@ -305,7 +296,7 @@ class FoafAction extends Action
             unset($sub);
         } else if ($isSubscriber) {
             // Just declare that they follow the user whose FOAF we're showing.
-            $this->element('sioc:follows', array('rdf:resource' => $this->user->uri . '#acct'));
+            $this->element('sioc:follows', array('rdf:resource' => $this->user->getUri() . '#acct'));
         }
 
         $this->elementEnd('OnlineAccount');