*/
function api_user()
{
- $user = BaseApi::getCurrentUserID();
+ $user = OAuth::getCurrentUserID();
if (!empty($user)) {
return $user;
}
$called_api = explode("/", $p);
- if (!empty($info['auth']) && api_user() === false) {
+ if (!empty($info['auth']) && BaseApi::getCurrentUserID() === false) {
BasicAuth::getCurrentUserID(true);
Logger::info(API_LOG_PREFIX . 'nickname {nickname}', ['module' => 'api', 'action' => 'call', 'nickname' => $a->getLoggedInUserNickname()]);
}
function api_rss_extra($arr, $user_info)
{
if (is_null($user_info)) {
- $uid = api_user();
+ $uid = BaseApi::getCurrentUserID();
if (empty($uid)) {
throw new ForbiddenException();
}
-
+
$user_info = DI::twitterUser()->createFromUserId($uid)->toArray();
}
$user = Strings::normaliseLink($contact_id);
$url = $user;
$extra_query = "AND `contact`.`nurl` = ? ";
- if (api_user() !== false) {
- $extra_query .= "AND `contact`.`uid`=" . intval(api_user());
+ if (BaseApi::getCurrentUserID() !== false) {
+ $extra_query .= "AND `contact`.`uid`=" . intval(BaseApi::getCurrentUserID());
}
}
$url = $user;
$extra_query = "AND `contact`.`nurl` = ? ";
- if (api_user() !== false) {
- $extra_query .= "AND `contact`.`uid`=" . intval(api_user());
+ if (BaseApi::getCurrentUserID() !== false) {
+ $extra_query .= "AND `contact`.`uid`=" . intval(BaseApi::getCurrentUserID());
}
}
$url = $user;
$extra_query = "AND `contact`.`nurl` = ? ";
- if (api_user() !== false) {
- $extra_query .= "AND `contact`.`uid`=" . intval(api_user());
+ if (BaseApi::getCurrentUserID() !== false) {
+ $extra_query .= "AND `contact`.`uid`=" . intval(BaseApi::getCurrentUserID());
}
}
if (is_null($user) && !empty($_GET['screen_name'])) {
$user = $_GET['screen_name'];
$extra_query = "AND `contact`.`nick` = ? ";
- if (api_user() !== false) {
- $extra_query .= "AND `contact`.`uid`=".intval(api_user());
+ if (BaseApi::getCurrentUserID() !== false) {
+ $extra_query .= "AND `contact`.`uid`=".intval(BaseApi::getCurrentUserID());
}
}
if (is_null($user) && !empty($_GET['profileurl'])) {
$user = Strings::normaliseLink($_GET['profileurl']);
$extra_query = "AND `contact`.`nurl` = ? ";
- if (api_user() !== false) {
- $extra_query .= "AND `contact`.`uid`=".intval(api_user());
+ if (BaseApi::getCurrentUserID() !== false) {
+ $extra_query .= "AND `contact`.`uid`=".intval(BaseApi::getCurrentUserID());
}
}
if ($user != "") {
$url = $user;
$extra_query = "AND `contact`.`nurl` = ? ";
- if (api_user() !== false) {
- $extra_query .= "AND `contact`.`uid`=" . intval(api_user());
+ if (BaseApi::getCurrentUserID() !== false) {
+ $extra_query .= "AND `contact`.`uid`=" . intval(BaseApi::getCurrentUserID());
}
}
} else {
$extra_query = "AND `contact`.`nick` = ? ";
- if (api_user() !== false) {
- $extra_query .= "AND `contact`.`uid`=" . intval(api_user());
+ if (BaseApi::getCurrentUserID() !== false) {
+ $extra_query .= "AND `contact`.`uid`=" . intval(BaseApi::getCurrentUserID());
}
}
}
Logger::info(API_LOG_PREFIX . 'getting user {user}', ['module' => 'api', 'action' => 'get_user', 'user' => $user]);
if (!$user) {
- if (api_user() === false) {
+ if (empty(BaseApi::getCurrentUserID())) {
BasicAuth::getCurrentUserID(true);
return false;
} else {
- $user = api_user();
+ $user = BaseApi::getCurrentUserID();
$extra_query = "AND `contact`.`uid` = ? AND `contact`.`self` ";
}
}
*/
function api_item_get_user(App $a, $item)
{
- $status_user = DI::twitterUser()->createFromContactId($item['author-id'] ?? null, api_user())->toArray();
+ if (empty($item['author-id'])) {
+ $item['author-id'] = Contact::getPublicIdByUserId(BaseApi::getCurrentUserID());
+ }
+ $status_user = DI::twitterUser()->createFromContactId($item['author-id'], BaseApi::getCurrentUserID())->toArray();
$author_user = $status_user;
$status_user["protected"] = isset($item['private']) && ($item['private'] == Item::PRIVATE);
if (($item['thr-parent'] ?? '') == ($item['uri'] ?? '')) {
- $owner_user = DI::twitterUser()->createFromContactId($item['owner-id'] ?? null, api_user())->toArray();
+ if (empty($item['owner-id'])) {
+ $item['owner-id'] = Contact::getPublicIdByUserId(BaseApi::getCurrentUserID());
+ }
+ $owner_user = DI::twitterUser()->createFromContactId($item['owner-id'], BaseApi::getCurrentUserID())->toArray();
} else {
$owner_user = $author_user;
}
*/
function api_account_verify_credentials($type)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
unset($_REQUEST["user_id"]);
$skip_status = $_REQUEST['skip_status'] ?? false;
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
// "verified" isn't used here in the standard
unset($user_info["verified"]);
{
$a = DI::app();
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
+
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
-
- $_REQUEST['profile_uid'] = api_user();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
+
+ $_REQUEST['profile_uid'] = BaseApi::getCurrentUserID();
$_REQUEST['api_source'] = true;
$txt = requestdata('status') ?? '';
/// @TODO old-lost code?
{
$a = DI::app();
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
+
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
// convert $_POST array items to the form we use for web posts.
if (requestdata('lat') && requestdata('long')) {
$_REQUEST['coord'] = sprintf("%s %s", requestdata('lat'), requestdata('long'));
}
- $_REQUEST['profile_uid'] = api_user();
+ $_REQUEST['profile_uid'] = BaseApi::getCurrentUserID();
if (!$parent) {
// Check for throttling (maximum posts per day, week and month)
if ($throttle_day > 0) {
$datefrom = date(DateTimeFormat::MYSQL, time() - 24*60*60);
- $condition = ["`gravity` = ? AND `uid` = ? AND `wall` AND `received` > ?", GRAVITY_PARENT, api_user(), $datefrom];
+ $condition = ["`gravity` = ? AND `uid` = ? AND `wall` AND `received` > ?", GRAVITY_PARENT, BaseApi::getCurrentUserID(), $datefrom];
$posts_day = Post::count($condition);
if ($posts_day > $throttle_day) {
- logger::info('Daily posting limit reached for user '.api_user());
+ logger::info('Daily posting limit reached for user '.BaseApi::getCurrentUserID());
// die(api_error($type, DI::l10n()->t("Daily posting limit of %d posts reached. The post was rejected.", $throttle_day));
throw new TooManyRequestsException(DI::l10n()->tt("Daily posting limit of %d post reached. The post was rejected.", "Daily posting limit of %d posts reached. The post was rejected.", $throttle_day));
}
if ($throttle_week > 0) {
$datefrom = date(DateTimeFormat::MYSQL, time() - 24*60*60*7);
- $condition = ["`gravity` = ? AND `uid` = ? AND `wall` AND `received` > ?", GRAVITY_PARENT, api_user(), $datefrom];
+ $condition = ["`gravity` = ? AND `uid` = ? AND `wall` AND `received` > ?", GRAVITY_PARENT, BaseApi::getCurrentUserID(), $datefrom];
$posts_week = Post::count($condition);
if ($posts_week > $throttle_week) {
- logger::info('Weekly posting limit reached for user '.api_user());
+ logger::info('Weekly posting limit reached for user '.BaseApi::getCurrentUserID());
// die(api_error($type, DI::l10n()->t("Weekly posting limit of %d posts reached. The post was rejected.", $throttle_week)));
throw new TooManyRequestsException(DI::l10n()->tt("Weekly posting limit of %d post reached. The post was rejected.", "Weekly posting limit of %d posts reached. The post was rejected.", $throttle_week));
}
if ($throttle_month > 0) {
$datefrom = date(DateTimeFormat::MYSQL, time() - 24*60*60*30);
- $condition = ["`gravity` = ? AND `uid` = ? AND `wall` AND `received` > ?", GRAVITY_PARENT, api_user(), $datefrom];
+ $condition = ["`gravity` = ? AND `uid` = ? AND `wall` AND `received` > ?", GRAVITY_PARENT, BaseApi::getCurrentUserID(), $datefrom];
$posts_month = Post::count($condition);
if ($posts_month > $throttle_month) {
- logger::info('Monthly posting limit reached for user '.api_user());
+ logger::info('Monthly posting limit reached for user '.BaseApi::getCurrentUserID());
// die(api_error($type, DI::l10n()->t("Monthly posting limit of %d posts reached. The post was rejected.", $throttle_month));
throw new TooManyRequestsException(DI::l10n()->t("Monthly posting limit of %d post reached. The post was rejected.", "Monthly posting limit of %d posts reached. The post was rejected.", $throttle_month));
}
$media = DBA::toArray(DBA::p("SELECT `resource-id`, `scale`, `nickname`, `type`, `desc`, `filename`, `datasize`, `width`, `height` FROM `photo`
INNER JOIN `user` ON `user`.`uid` = `photo`.`uid` WHERE `resource-id` IN
(SELECT `resource-id` FROM `photo` WHERE `id` = ?) AND `photo`.`uid` = ?
- ORDER BY `photo`.`width` DESC LIMIT 2", $id, api_user()));
+ ORDER BY `photo`.`width` DESC LIMIT 2", $id, BaseApi::getCurrentUserID()));
if (!empty($media)) {
$ressources[] = $media[0]['resource-id'];
if (!empty($ressources) && !empty($item_id)) {
$item = Post::selectFirst(['uri-id', 'allow_cid', 'allow_gid', 'deny_cid', 'deny_gid'], ['id' => $item_id]);
foreach ($ressources as $ressource) {
- Photo::setPermissionForRessource($ressource, api_user(), $item['allow_cid'], $item['allow_gid'], $item['deny_cid'], $item['deny_gid']);
+ Photo::setPermissionForRessource($ressource, BaseApi::getCurrentUserID(), $item['allow_cid'], $item['allow_gid'], $item['deny_cid'], $item['deny_gid']);
}
}
{
$a = DI::app();
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
+
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
if (empty($_FILES['media'])) {
Logger::info('Updating metadata', ['media_id' => $data['media_id']]);
- $condition = ['id' => $data['media_id'], 'uid' => api_user()];
+ $condition = ['id' => $data['media_id'], 'uid' => BaseApi::getCurrentUserID()];
$photo = DBA::selectFirst('photo', ['resource-id'], $condition);
if (!DBA::isResult($photo)) {
throw new BadRequestException("Metadata not found.");
{
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
$item = api_get_last_status($user_info['pid'], $user_info['uid']);
if (!empty($item)) {
if (DBA::isResult($contacts)) {
$k = 0;
foreach ($contacts as $contact) {
- $user_info = DI::twitterUser()->createFromContactId($contact['id'], api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromContactId($contact['id'], BaseApi::getCurrentUserID())->toArray();
if ($type == 'xml') {
$userlist[$k++ . ':user'] = $user_info;
*/
function api_search($type)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
if (empty($_REQUEST['q'])) {
throw new BadRequestException('q parameter is required.');
" . ($exclude_replies ? " AND `gravity` = " . GRAVITY_PARENT : ' ') . "
AND (`uid` = 0 OR (`uid` = ? AND NOT `global`))
AND `body` LIKE CONCAT('%',?,'%')",
- $since_id, api_user(), $_REQUEST['q']];
+ $since_id, BaseApi::getCurrentUserID(), $_REQUEST['q']];
if ($max_id > 0) {
$condition[0] .= ' AND `id` <= ?';
$condition[] = $max_id;
$statuses = [];
if (parse_url($searchTerm, PHP_URL_SCHEME) != '') {
- $id = Item::fetchByLink($searchTerm, api_user());
+ $id = Item::fetchByLink($searchTerm, BaseApi::getCurrentUserID());
if (!$id) {
// Public post
$id = Item::fetchByLink($searchTerm);
}
}
- $statuses = $statuses ?: Post::selectForUser(api_user(), [], $condition, $params);
+ $statuses = $statuses ?: Post::selectForUser(BaseApi::getCurrentUserID(), [], $condition, $params);
$data['status'] = api_format_items(Post::toArray($statuses), $user_info);
*/
function api_statuses_home_timeline($type)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
-
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
unset($_REQUEST["user_id"]);
unset($_GET["user_id"]);
$start = max(0, ($page - 1) * $count);
$condition = ["`uid` = ? AND `gravity` IN (?, ?) AND `id` > ?",
- api_user(), GRAVITY_PARENT, GRAVITY_COMMENT, $since_id];
+ BaseApi::getCurrentUserID(), GRAVITY_PARENT, GRAVITY_COMMENT, $since_id];
if ($max_id > 0) {
$condition[0] .= " AND `id` <= ?";
}
$params = ['order' => ['id' => true], 'limit' => [$start, $count]];
- $statuses = Post::selectForUser(api_user(), [], $condition, $params);
+ $statuses = Post::selectForUser(BaseApi::getCurrentUserID(), [], $condition, $params);
$items = Post::toArray($statuses);
*/
function api_statuses_public_timeline($type)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
// get last network messages
}
$params = ['order' => ['id' => true], 'limit' => [$start, $count]];
- $statuses = Post::selectForUser(api_user(), [], $condition, $params);
+ $statuses = Post::selectForUser(BaseApi::getCurrentUserID(), [], $condition, $params);
$r = Post::toArray($statuses);
} else {
}
$params = ['order' => ['id' => true], 'limit' => [$start, $count]];
- $statuses = Post::selectForUser(api_user(), [], $condition, $params);
+ $statuses = Post::selectForUser(BaseApi::getCurrentUserID(), [], $condition, $params);
$r = Post::toArray($statuses);
}
*/
function api_statuses_networkpublic_timeline($type)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
$since_id = $_REQUEST['since_id'] ?? 0;
$max_id = $_REQUEST['max_id'] ?? 0;
}
$params = ['order' => ['id' => true], 'limit' => [$start, $count]];
- $statuses = Post::toArray(Post::selectForUser(api_user(), Item::DISPLAY_FIELDLIST, $condition, $params));
+ $statuses = Post::toArray(Post::selectForUser(BaseApi::getCurrentUserID(), Item::DISPLAY_FIELDLIST, $condition, $params));
$ret = api_format_items($statuses, $user_info, false, $type);
*/
function api_statuses_show($type)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
// params
$id = intval(DI::args()->getArgv()[3] ?? 0);
throw new BadRequestException(sprintf("There is no status with the id %d", $id));
}
- $item = Post::selectFirst(['id'], ['uri-id' => $uri_item['uri-id'], 'uid' => [0, api_user()]], ['order' => ['uid' => true]]);
+ $item = Post::selectFirst(['id'], ['uri-id' => $uri_item['uri-id'], 'uid' => [0, BaseApi::getCurrentUserID()]], ['order' => ['uid' => true]]);
if (!DBA::isResult($item)) {
throw new BadRequestException(sprintf("There is no status with the uri-id %d for the given user.", $uri_item['uri-id']));
}
$params = [];
}
- $statuses = Post::selectForUser(api_user(), [], $condition, $params);
+ $statuses = Post::selectForUser(BaseApi::getCurrentUserID(), [], $condition, $params);
/// @TODO How about copying this to above methods which don't check $r ?
if (!DBA::isResult($statuses)) {
*/
function api_conversation_show($type)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
// params
$id = intval(DI::args()->getArgv()[3] ?? 0);
throw new BadRequestException("There is no status with the id $id.");
}
- $parent = Post::selectFirst(['id'], ['uri-id' => $item['parent-uri-id'], 'uid' => [0, api_user()]], ['order' => ['uid' => true]]);
+ $parent = Post::selectFirst(['id'], ['uri-id' => $item['parent-uri-id'], 'uid' => [0, BaseApi::getCurrentUserID()]], ['order' => ['uid' => true]]);
if (!DBA::isResult($parent)) {
throw new BadRequestException("There is no status with this id.");
}
$id = $parent['id'];
$condition = ["`parent` = ? AND `uid` IN (0, ?) AND `gravity` IN (?, ?) AND `id` > ?",
- $id, api_user(), GRAVITY_PARENT, GRAVITY_COMMENT, $since_id];
+ $id, BaseApi::getCurrentUserID(), GRAVITY_PARENT, GRAVITY_COMMENT, $since_id];
if ($max_id > 0) {
$condition[0] .= " AND `id` <= ?";
}
$params = ['order' => ['id' => true], 'limit' => [$start, $count]];
- $statuses = Post::selectForUser(api_user(), [], $condition, $params);
+ $statuses = Post::selectForUser(BaseApi::getCurrentUserID(), [], $condition, $params);
if (!DBA::isResult($statuses)) {
throw new BadRequestException("There is no status with id $id.");
$a = DI::app();
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
+
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
// params
$post .= "[/share]";
}
$_REQUEST['body'] = $post;
- $_REQUEST['profile_uid'] = api_user();
+ $_REQUEST['profile_uid'] = BaseApi::getCurrentUserID();
$_REQUEST['api_source'] = true;
if (empty($_REQUEST['source'])) {
*/
function api_statuses_destroy($type)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
+
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
// params
$ret = api_statuses_show($type);
- Item::deleteForUser(['id' => $id], api_user());
+ Item::deleteForUser(['id' => $id], BaseApi::getCurrentUserID());
return $ret;
}
*/
function api_statuses_mentions($type)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
unset($_REQUEST["user_id"]);
unset($_GET["user_id"]);
$condition = [
GRAVITY_PARENT, GRAVITY_COMMENT,
- api_user(),
+ BaseApi::getCurrentUserID(),
Post\UserNotification::TYPE_EXPLICIT_TAGGED | Post\UserNotification::TYPE_IMPLICIT_TAGGED |
Post\UserNotification::TYPE_THREAD_COMMENT | Post\UserNotification::TYPE_DIRECT_COMMENT |
Post\UserNotification::TYPE_DIRECT_THREAD_COMMENT,
- api_user(), $since_id,
+ BaseApi::getCurrentUserID(), $since_id,
];
if ($max_id > 0) {
array_unshift($condition, $query);
$params = ['order' => ['id' => true], 'limit' => [$start, $count]];
- $statuses = Post::selectForUser(api_user(), [], $condition, $params);
+ $statuses = Post::selectForUser(BaseApi::getCurrentUserID(), [], $condition, $params);
$ret = api_format_items(Post::toArray($statuses), $user_info, false, $type);
*/
function api_statuses_user_timeline($type)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
- Logger::info('api_statuses_user_timeline', ['api_user' => api_user(), 'user_info' => $user_info, '_REQUEST' => $_REQUEST]);
+ Logger::info('api_statuses_user_timeline', ['api_user' => BaseApi::getCurrentUserID(), 'user_info' => $user_info, '_REQUEST' => $_REQUEST]);
$since_id = $_REQUEST['since_id'] ?? 0;
$max_id = $_REQUEST['max_id'] ?? 0;
$start = max(0, ($page - 1) * $count);
$condition = ["`uid` = ? AND `gravity` IN (?, ?) AND `id` > ? AND `contact-id` = ?",
- api_user(), GRAVITY_PARENT, GRAVITY_COMMENT, $since_id, $user_info['cid']];
+ BaseApi::getCurrentUserID(), GRAVITY_PARENT, GRAVITY_COMMENT, $since_id, $user_info['cid']];
if ($user_info['self'] == 1) {
$condition[0] .= ' AND `wall` ';
$condition[] = $max_id;
}
$params = ['order' => ['id' => true], 'limit' => [$start, $count]];
- $statuses = Post::selectForUser(api_user(), [], $condition, $params);
+ $statuses = Post::selectForUser(BaseApi::getCurrentUserID(), [], $condition, $params);
$ret = api_format_items(Post::toArray($statuses), $user_info, true, $type);
*/
function api_favorites_create_destroy($type)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
+
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
// for versioned api.
$itemid = intval($_REQUEST['id'] ?? 0);
}
- $item = Post::selectFirstForUser(api_user(), [], ['id' => $itemid, 'uid' => api_user()]);
+ $item = Post::selectFirstForUser(BaseApi::getCurrentUserID(), [], ['id' => $itemid, 'uid' => BaseApi::getCurrentUserID()]);
if (!DBA::isResult($item)) {
throw new BadRequestException("Invalid item.");
throw new InternalServerErrorException("DB error");
}
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
$rets = api_format_items([$item], $user_info, false, $type);
$ret = $rets[0];
{
global $called_api;
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
$called_api = [];
$start = max(0, ($page - 1) * $count);
$condition = ["`uid` = ? AND `gravity` IN (?, ?) AND `id` > ? AND `starred`",
- api_user(), GRAVITY_PARENT, GRAVITY_COMMENT, $since_id];
+ BaseApi::getCurrentUserID(), GRAVITY_PARENT, GRAVITY_COMMENT, $since_id];
$params = ['order' => ['id' => true], 'limit' => [$start, $count]];
$condition[] = $max_id;
}
- $statuses = Post::selectForUser(api_user(), [], $condition, $params);
+ $statuses = Post::selectForUser(BaseApi::getCurrentUserID(), [], $condition, $params);
$ret = api_format_items(Post::toArray($statuses), $user_info, false, $type);
}
//builtin_activity_puller($i, $activities);
// get user data and add it to the array of the activity
- $user = DI::twitterUser()->createFromContactId($parent_item['author-id'], api_user())->toArray();
+ $user = DI::twitterUser()->createFromContactId($parent_item['author-id'], BaseApi::getCurrentUserID())->toArray();
switch ($parent_item['verb']) {
case Activity::LIKE:
$activities['like'][] = $user;
if (!empty($announce)) {
$retweeted_item = $item;
$item = $announce;
- $status['friendica_owner'] = DI::twitterUser()->createFromContactId($announce['author-id'], api_user())->toArray();
+ $status['friendica_owner'] = DI::twitterUser()->createFromContactId($announce['author-id'], BaseApi::getCurrentUserID())->toArray();
}
}
$quoted_status['text'] = $conv_quoted['text'];
$quoted_status['statusnet_html'] = $conv_quoted['html'];
try {
- $quoted_status["user"] = DI::twitterUser()->createFromContactId($quoted_item['author-id'], api_user())->toArray();
+ $quoted_status["user"] = DI::twitterUser()->createFromContactId($quoted_item['author-id'], BaseApi::getCurrentUserID())->toArray();
} catch (BadRequestException $e) {
// user not found. should be found?
/// @todo check if the user should be always found
unset($retweeted_status['statusnet_conversation_id']);
$status['user'] = $status['friendica_owner'];
try {
- $retweeted_status["user"] = DI::twitterUser()->createFromContactId($retweeted_item['author-id'], api_user())->toArray();
+ $retweeted_status["user"] = DI::twitterUser()->createFromContactId($retweeted_item['author-id'], BaseApi::getCurrentUserID())->toArray();
} catch (BadRequestException $e) {
// user not found. should be found?
/// @todo check if the user should be always found
*/
function api_lists_ownerships($type)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
// params
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
$uid = $user_info['uid'];
$groups = DBA::select('group', [], ['deleted' => 0, 'uid' => $uid]);
*/
function api_lists_statuses($type)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
unset($_REQUEST["user_id"]);
unset($_GET["user_id"]);
$groups = DBA::selectToArray('group_member', ['contact-id'], ['gid' => 1]);
$gids = array_column($groups, 'contact-id');
- $condition = ['uid' => api_user(), 'gravity' => [GRAVITY_PARENT, GRAVITY_COMMENT], 'group-id' => $gids];
+ $condition = ['uid' => BaseApi::getCurrentUserID(), 'gravity' => [GRAVITY_PARENT, GRAVITY_COMMENT], 'group-id' => $gids];
$condition = DBA::mergeConditions($condition, ["`id` > ?", $since_id]);
if ($max_id > 0) {
}
$params = ['order' => ['id' => true], 'limit' => [$start, $count]];
- $statuses = Post::selectForUser(api_user(), [], $condition, $params);
+ $statuses = Post::selectForUser(BaseApi::getCurrentUserID(), [], $condition, $params);
$items = api_format_items(Post::toArray($statuses), $user_info, false, $type);
$start = max(0, ($page - 1) * $count);
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
if (!empty($_GET['cursor']) && $_GET['cursor'] == 'undefined') {
/* this is to stop Hotot to load friends multiple times
$sql_extra
ORDER BY `nick`
LIMIT ?, ?",
- api_user(),
+ BaseApi::getCurrentUserID(),
$start,
$count
));
$ret = [];
foreach ($r as $cid) {
- $user = DI::twitterUser()->createFromContactId($cid['id'], api_user())->toArray();
+ $user = DI::twitterUser()->createFromContactId($cid['id'], BaseApi::getCurrentUserID())->toArray();
// "uid" and "self" are only needed for some internal stuff, so remove it from here
unset($user["uid"]);
unset($user["self"]);
*/
function api_direct_messages_new($type)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
+
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
- $uid = api_user();
+ $uid = BaseApi::getCurrentUserID();
if (empty($uid)) {
throw new ForbiddenException();
}
-
+
if (empty($_POST["text"]) || empty($_POST["screen_name"]) && empty($_POST["user_id"])) {
return;
}
$recipient = null;
if (!empty($_POST['screen_name'])) {
- $contacts = Contact::selectToArray(['id', 'nurl', 'network'], ['uid' => api_user(), 'nick' => $_POST['screen_name']]);
+ $contacts = Contact::selectToArray(['id', 'nurl', 'network'], ['uid' => BaseApi::getCurrentUserID(), 'nick' => $_POST['screen_name']]);
if (DBA::isResult($contacts)) {
// Selecting the id by priority, friendica first
api_best_nickname($contacts);
$replyto = '';
if (!empty($_REQUEST['replyto'])) {
- $mail = DBA::selectFirst('mail', ['parent-uri', 'title'], ['uid' => api_user(), 'id' => $_REQUEST['replyto']]);
+ $mail = DBA::selectFirst('mail', ['parent-uri', 'title'], ['uid' => BaseApi::getCurrentUserID(), 'id' => $_REQUEST['replyto']]);
$replyto = $mail['parent-uri'];
$sub = $mail['title'];
} else {
*/
function api_direct_messages_destroy($type)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
+
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
// params
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
//required
$id = $_REQUEST['id'] ?? 0;
// optional
*/
function api_friendships_destroy($type)
{
- $uid = api_user();
+ $uid = BaseApi::getCurrentUserID();
if ($uid === false) {
throw new HTTPException\ForbiddenException();
*/
function api_direct_messages_box($type, $box, $verbose)
{
+ if (empty(BaseApi::getCurrentUserID())) {
+ throw new ForbiddenException();
+ }
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
// params
unset($_REQUEST["screen_name"]);
unset($_GET["screen_name"]);
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
$profile_url = $user_info["url"];
$r = DBA::toArray(DBA::p(
"SELECT `mail`.*, `contact`.`nurl` AS `contact-url` FROM `mail`,`contact` WHERE `mail`.`contact-id` = `contact`.`id` AND `mail`.`uid` = ? AND $sql_extra AND `mail`.`id` > ? ORDER BY `mail`.`id` DESC LIMIT ?,?",
- api_user(),
+ BaseApi::getCurrentUserID(),
$since_id,
$start,
$count
foreach ($r as $item) {
if ($box == "inbox" || $item['from-url'] != $profile_url) {
$recipient = $user_info;
- $sender = DI::twitterUser()->createFromContactId($item['contact-id'], api_user())->toArray();
+ $sender = DI::twitterUser()->createFromContactId($item['contact-id'], BaseApi::getCurrentUserID())->toArray();
} elseif ($box == "sentbox" || $item['from-url'] == $profile_url) {
- $recipient = DI::twitterUser()->createFromContactId($item['contact-id'], api_user())->toArray();
+ $recipient = DI::twitterUser()->createFromContactId($item['contact-id'], BaseApi::getCurrentUserID())->toArray();
$sender = $user_info;
}
*/
function api_fr_photos_list($type)
{
- if (api_user() === false) {
+ if (empty(BaseApi::getCurrentUserID())) {
throw new ForbiddenException();
}
$r = DBA::toArray(DBA::p(
*/
function api_fr_photo_create_update($type)
{
- if (api_user() === false) {
+ if (empty(BaseApi::getCurrentUserID())) {
throw new ForbiddenException();
}
// input params
$mode = "update";
// check if photo is existing in databasei
- if (!Photo::exists(['resource-id' => $photo_id, 'uid' => api_user(), 'album' => $album])) {
+ if (!Photo::exists(['resource-id' => $photo_id, 'uid' => BaseApi::getCurrentUserID(), 'album' => $album])) {
throw new BadRequestException("photo not available");
}
}
$result = false;
if (count($updated_fields) > 0) {
$nothingtodo = false;
- $result = Photo::update($updated_fields, ['uid' => api_user(), 'resource-id' => $photo_id, 'album' => $album]);
+ $result = Photo::update($updated_fields, ['uid' => BaseApi::getCurrentUserID(), 'resource-id' => $photo_id, 'album' => $album]);
} else {
$nothingtodo = true;
}
*/
function api_fr_photo_detail($type)
{
- if (api_user() === false) {
+ if (empty(BaseApi::getCurrentUserID())) {
throw new ForbiddenException();
}
if (empty($_REQUEST['photo_id'])) {
*/
function api_account_update_profile_image($type)
{
- if (api_user() === false) {
+ if (empty(BaseApi::getCurrentUserID())) {
throw new ForbiddenException();
}
// input params
// check if specified profile id is valid
if ($profile_id != 0) {
- $profile = DBA::selectFirst('profile', ['is-default'], ['uid' => api_user(), 'id' => $profile_id]);
+ $profile = DBA::selectFirst('profile', ['is-default'], ['uid' => BaseApi::getCurrentUserID(), 'id' => $profile_id]);
// error message if specified profile id is not in database
if (!DBA::isResult($profile)) {
throw new BadRequestException("profile_id not available");
// change specified profile or all profiles to the new resource-id
if ($is_default_profile) {
- $condition = ["`profile` AND `resource-id` != ? AND `uid` = ?", $data['photo']['id'], api_user()];
+ $condition = ["`profile` AND `resource-id` != ? AND `uid` = ?", $data['photo']['id'], BaseApi::getCurrentUserID()];
Photo::update(['profile' => false, 'photo-type' => Photo::DEFAULT], $condition);
} else {
$fields = ['photo' => DI::baseUrl() . '/photo/' . $data['photo']['id'] . '-4.' . $fileext,
'thumb' => DI::baseUrl() . '/photo/' . $data['photo']['id'] . '-5.' . $fileext];
- DBA::update('profile', $fields, ['id' => $_REQUEST['profile'], 'uid' => api_user()]);
+ DBA::update('profile', $fields, ['id' => $_REQUEST['profile'], 'uid' => BaseApi::getCurrentUserID()]);
}
- Contact::updateSelfFromUserID(api_user(), true);
+ Contact::updateSelfFromUserID(BaseApi::getCurrentUserID(), true);
// Update global directory in background
- Profile::publishUpdate(api_user());
+ Profile::publishUpdate(BaseApi::getCurrentUserID());
// output for client
if ($data) {
{
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
- $local_user = api_user();
+ $local_user = BaseApi::getCurrentUserID();
- $api_user = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $api_user = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
if (!empty($_POST['name'])) {
DBA::update('profile', ['name' => $_POST['name']], ['uid' => $local_user]);
foreach ($cid_array as $cid) {
$cid = str_replace("<", "", $cid);
$cid = str_replace(">", "", $cid);
- $condition = ['id' => $cid, 'uid' => api_user()];
+ $condition = ['id' => $cid, 'uid' => BaseApi::getCurrentUserID()];
$contact_not_found |= !DBA::exists('contact', $condition);
}
return $contact_not_found;
function post_photo_item($hash, $allow_cid, $deny_cid, $allow_gid, $deny_gid, $filetype, $visibility = false)
{
// get data about the api authenticated user
- $uri = Item::newURI(intval(api_user()));
- $owner_record = DBA::selectFirst('contact', [], ['uid' => api_user(), 'self' => true]);
+ $uri = Item::newURI(intval(BaseApi::getCurrentUserID()));
+ $owner_record = DBA::selectFirst('contact', [], ['uid' => BaseApi::getCurrentUserID(), 'self' => true]);
$arr = [];
$arr['guid'] = System::createUUID();
- $arr['uid'] = intval(api_user());
+ $arr['uid'] = intval(BaseApi::getCurrentUserID());
$arr['uri'] = $uri;
$arr['type'] = 'photo';
$arr['wall'] = 1;
{
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
$scale_sql = ($scale === false ? "" : sprintf("AND scale=%d", intval($scale)));
$data_sql = ($scale === false ? "" : "data, ");
}
// retrieve item element for getting activities (like, dislike etc.) related to photo
- $condition = ['uid' => api_user(), 'resource-id' => $photo_id];
+ $condition = ['uid' => BaseApi::getCurrentUserID(), 'resource-id' => $photo_id];
$item = Post::selectFirst(['id', 'uid', 'uri', 'parent', 'allow_cid', 'deny_cid', 'allow_gid', 'deny_gid'], $condition);
if (!DBA::isResult($item)) {
throw new NotFoundException('Photo-related item not found.');
// retrieve comments on photo
$condition = ["`parent` = ? AND `uid` = ? AND `gravity` IN (?, ?)",
- $item['parent'], api_user(), GRAVITY_PARENT, GRAVITY_COMMENT];
+ $item['parent'], BaseApi::getCurrentUserID(), GRAVITY_PARENT, GRAVITY_COMMENT];
- $statuses = Post::selectForUser(api_user(), [], $condition);
+ $statuses = Post::selectForUser(BaseApi::getCurrentUserID(), [], $condition);
// prepare output of comments
$commentData = api_format_items(Post::toArray($statuses), $user_info, false, $type);
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
// params
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
$gid = $_REQUEST['gid'] ?? 0;
$uid = $user_info['uid'];
$user_element = "users";
$k = 0;
foreach ($members as $member) {
- $user = DI::twitterUser()->createFromContactId($member['contact-id'], api_user())->toArray();
+ $user = DI::twitterUser()->createFromContactId($member['contact-id'], BaseApi::getCurrentUserID())->toArray();
$users[$k++.":user"] = $user;
}
} else {
$user_element = "user";
foreach ($members as $member) {
- $user = DI::twitterUser()->createFromContactId($member['contact-id'], api_user())->toArray();
+ $user = DI::twitterUser()->createFromContactId($member['contact-id'], BaseApi::getCurrentUserID())->toArray();
$users[] = $user;
}
}
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
// params
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
$gid = $_REQUEST['list_id'] ?? 0;
$uid = $user_info['uid'];
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
// params
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
$name = $_REQUEST['name'] ?? '';
$uid = $user_info['uid'];
$json = json_decode($_POST['json'], true);
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
// params
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
$name = $_REQUEST['name'] ?? '';
$uid = $user_info['uid'];
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
// params
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
$uid = $user_info['uid'];
$gid = $_REQUEST['gid'] ?? 0;
$name = $_REQUEST['name'] ?? '';
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
// params
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
$gid = $_REQUEST['list_id'] ?? 0;
$name = $_REQUEST['name'] ?? '';
$uid = $user_info['uid'];
{
BaseApi::checkAllowedScope(BaseApi::SCOPE_WRITE);
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
if (DI::args()->getArgc() !== 4) {
throw new BadRequestException('Invalid argument count');
try {
$Notify = DI::notify()->selectOneById($id);
- if ($Notify->uid !== api_user()) {
+ if ($Notify->uid !== BaseApi::getCurrentUserID()) {
throw new NotFoundException();
}
DI::notify()->save($Notify);
if ($Notify->otype === Notification\ObjectType::ITEM) {
- $item = Post::selectFirstForUser(api_user(), [], ['id' => $Notify->iid, 'uid' => api_user()]);
+ $item = Post::selectFirstForUser(BaseApi::getCurrentUserID(), [], ['id' => $Notify->iid, 'uid' => BaseApi::getCurrentUserID()]);
if (DBA::isResult($item)) {
// we found the item, return it to the user
$ret = api_format_items([$item], $user_info, false, $type);
BaseApi::checkAllowedScope(BaseApi::SCOPE_READ);
// params
- $user_info = DI::twitterUser()->createFromUserId(api_user())->toArray();
+ $user_info = DI::twitterUser()->createFromUserId(BaseApi::getCurrentUserID())->toArray();
$searchstring = $_REQUEST['searchstring'] ?? '';
$uid = $user_info['uid'];
foreach ($r as $item) {
if ($box == "inbox" || $item['from-url'] != $profile_url) {
$recipient = $user_info;
- $sender = DI::twitterUser()->createFromContactId($item['contact-id'], api_user())->toArray();
+ $sender = DI::twitterUser()->createFromContactId($item['contact-id'], BaseApi::getCurrentUserID())->toArray();
} elseif ($box == "sentbox" || $item['from-url'] == $profile_url) {
- $recipient = DI::twitterUser()->createFromContactId($item['contact-id'], api_user())->toArray();
+ $recipient = DI::twitterUser()->createFromContactId($item['contact-id'], BaseApi::getCurrentUserID())->toArray();
$sender = $user_info;
}