]> git.mxchange.org Git - quix0rs-gnu-social.git/blobdiff - actions/subscribe.php
Fix inconsistent title case in page title
[quix0rs-gnu-social.git] / actions / subscribe.php
index 71452e46ccda236bc06058c4daaabf29b2ee34b0..a90d7facdfaca15e60c16d03c376833af228d448 100644 (file)
@@ -1,7 +1,7 @@
 <?php
 /*
- * Laconica - a distributed open-source microblogging tool
- * Copyright (C) 2008, Controlez-Vous, Inc.
+ * StatusNet - the distributed open-source microblogging tool
+ * Copyright (C) 2008, 2009, StatusNet, Inc.
  *
  * This program is free software: you can redistribute it and/or modify
  * it under the terms of the GNU Affero General Public License as published by
  * along with this program.  If not, see <http://www.gnu.org/licenses/>.
  */
 
-if (!defined('LACONICA')) { exit(1); }
+if (!defined('STATUSNET') && !defined('LACONICA')) { exit(1); }
 
-class SubscribeAction extends Action {
-       
-       function handle($args) {
-               parent::handle($args);
+class SubscribeAction extends Action
+{
 
-               if (!common_logged_in()) {
-                       common_user_error(_('Not logged in.'));
-                       return;
-               }
+    function handle($args)
+    {
+        parent::handle($args);
 
-               $user = common_current_user();
+        if (!common_logged_in()) {
+            $this->clientError(_('Not logged in.'));
+            return;
+        }
 
-               if ($_SERVER['REQUEST_METHOD'] != 'POST') {
-                       common_redirect(common_local_url('subscriptions', array('nickname' => $user->nickname)));
-                       return;
-               }
+        $user = common_current_user();
 
-               $other_nickname = $this->arg('subscribeto');
+        if ($_SERVER['REQUEST_METHOD'] != 'POST') {
+            common_redirect(common_local_url('subscriptions', array('nickname' => $user->nickname)));
+            return;
+        }
 
-               $result=subs_subscribe_user($user, $other_nickname);
-               if($result != true) {
-                       common_user_error($result);
-                       return;
-               }
-               
-               common_redirect(common_local_url('subscriptions', array('nickname' =>
-                                                                                                                               $user->nickname)));
-       }
+        # CSRF protection
 
-}
\ No newline at end of file
+        $token = $this->trimmed('token');
+
+        if (!$token || $token != common_session_token()) {
+            $this->clientError(_('There was a problem with your session token. Try again, please.'));
+            return;
+        }
+
+        $other_id = $this->arg('subscribeto');
+
+        $other = User::staticGet('id', $other_id);
+
+        if (!$other) {
+            $this->clientError(_('Not a local user.'));
+            return;
+        }
+
+        $result = subs_subscribe_to($user, $other);
+
+        if (is_string($result)) {
+            $this->clientError($result);
+            return;
+        }
+
+        if ($this->boolean('ajax')) {
+            $this->startHTML('text/xml;charset=utf-8');
+            $this->elementStart('head');
+            $this->element('title', null, _('Subscribed'));
+            $this->elementEnd('head');
+            $this->elementStart('body');
+            $unsubscribe = new UnsubscribeForm($this, $other->getProfile());
+            $unsubscribe->show();
+            $this->elementEnd('body');
+            $this->elementEnd('html');
+        } else {
+            common_redirect(common_local_url('subscriptions', array('nickname' =>
+                                                                $user->nickname)),
+                            303);
+        }
+    }
+}