]> git.mxchange.org Git - friendica.git/blobdiff - include/api.php
Disable richtext editor for frio - followup for #2938
[friendica.git] / include / api.php
index ff8127829b167e55977d074e65262783ba2e4820..7518d4c0c4ebbb0b34f61506787e3e34e6215746 100644 (file)
@@ -1,64 +1,68 @@
 <?php
-/* To-Do:
- - Automatically detect if incoming data is HTML or BBCode
-*/
-
-/* Contact details:
-       Gerhard Seeber          Mail: gerhard@seeber.at         Friendica: http://mozartweg.dyndns.org/friendica/gerhard
-
- */
-
-
-/*
- * Change history:
-       Gerhard Seeber          2015-NOV-25     Add API call /friendica/group_show to return all or a single group
-                                               with the containing contacts (necessary for Windows 10 Universal app)
-       Gerhard Seeber          2015-NOV-27     Add API call /friendica/group_delete to delete the specified group id
-                                               (necessary for Windows 10 Universal app)
-       Gerhard Seeber          2015-DEC-01     Add API call /friendica/group_create to create a group with the specified 
-                                               name and the given list of contacts (necessary for Windows 10 Universal
-                                               app)
-       Gerhard Seeber          2015-DEC-07     Add API call /friendica/group_update to update a group with the given 
-                                               list of contacts (necessary for Windows 10 Universal app)
+/**
+ * @file include/api.php
+ * Friendica implementation of statusnet/twitter API
  *
+ * @todo Automatically detect if incoming data is HTML or BBCode
  */
-
-       require_once("include/bbcode.php");
-       require_once("include/datetime.php");
-       require_once("include/conversation.php");
-       require_once("include/oauth.php");
-       require_once("include/html2plain.php");
-       require_once("mod/share.php");
-       require_once("include/Photo.php");
-       require_once("mod/item.php");
+       require_once('include/HTTPExceptions.php');
+
+       require_once('include/bbcode.php');
+       require_once('include/datetime.php');
+       require_once('include/conversation.php');
+       require_once('include/oauth.php');
+       require_once('include/html2plain.php');
+       require_once('mod/share.php');
+       require_once('include/Photo.php');
+       require_once('mod/item.php');
        require_once('include/security.php');
        require_once('include/contact_selectors.php');
        require_once('include/html2bbcode.php');
        require_once('mod/wall_upload.php');
-       require_once("mod/proxy.php");
-       require_once("include/message.php");
-       require_once("include/group.php");
+       require_once('mod/proxy.php');
+       require_once('include/message.php');
+       require_once('include/group.php');
+       require_once('include/like.php');
+       require_once('include/NotificationsManager.php');
+       require_once('include/plaintext.php');
+       require_once('include/xml.php');
+
+
+       define('API_METHOD_ANY','*');
+       define('API_METHOD_GET','GET');
+       define('API_METHOD_POST','POST,PUT');
+       define('API_METHOD_DELETE','POST,DELETE');
 
 
-       /*
-        * Twitter-Like API
-        *
-        */
 
        $API = Array();
        $called_api = Null;
 
+       /**
+        * @brief Auth API user
+        *
+        * It is not sufficient to use local_user() to check whether someone is allowed to use the API,
+        * because this will open CSRF holes (just embed an image with src=friendicasite.com/api/statuses/update?status=CSRF
+        * into a page, and visitors will post something without noticing it).
+        */
        function api_user() {
-               // It is not sufficient to use local_user() to check whether someone is allowed to use the API,
-               // because this will open CSRF holes (just embed an image with src=friendicasite.com/api/statuses/update?status=CSRF
-               // into a page, and visitors will post something without noticing it).
-               // Instead, use this function.
-               if ($_SESSION["allow_api"])
+               if ($_SESSION['allow_api'])
                        return local_user();
 
                return false;
        }
 
+       /**
+        * @brief Get source name from API client
+        *
+        * Clients can send 'source' parameter to be show in post metadata
+        * as "sent via <source>".
+        * Some clients doesn't send a source param, we support ones we know
+        * (only Twidere, atm)
+        *
+        * @return string
+        *              Client source name, default to "api" if unset/unknown
+        */
        function api_source() {
                if (requestdata('source'))
                        return (requestdata('source'));
                return ("api");
        }
 
+       /**
+        * @brief Format date for API
+        *
+        * @param string $str Source date, as UTC
+        * @return string Date in UTC formatted as "D M d H:i:s +0000 Y"
+        */
        function api_date($str){
                //Wed May 23 06:01:13 +0000 2007
                return datetime_convert('UTC', 'UTC', $str, "D M d H:i:s +0000 Y" );
        }
 
-
-       function api_register_func($path, $func, $auth=false){
+       /**
+        * @brief Register API endpoint
+        *
+        * Register a function to be the endpont for defined API path.
+        *
+        * @param string $path API URL path, relative to App::get_baseurl()
+        * @param string $func Function name to call on path request
+        * @param bool $auth API need logged user
+        * @param string $method
+        *      HTTP method reqiured to call this endpoint.
+        *      One of API_METHOD_ANY, API_METHOD_GET, API_METHOD_POST.
+        *  Default to API_METHOD_ANY
+        */
+       function api_register_func($path, $func, $auth=false, $method=API_METHOD_ANY){
                global $API;
-               $API[$path] = array('func'=>$func, 'auth'=>$auth);
+               $API[$path] = array(
+                       'func'=>$func,
+                       'auth'=>$auth,
+                       'method'=> $method
+               );
 
                // Workaround for hotot
                $path = str_replace("api/", "api/1.1/", $path);
-               $API[$path] = array('func'=>$func, 'auth'=>$auth);
+               $API[$path] = array(
+                       'func'=>$func,
+                       'auth'=>$auth,
+                       'method'=> $method
+               );
        }
 
        /**
-        * Simple HTTP Login
+        * @brief Login API user
+        *
+        * Log in user via OAuth1 or Simple HTTP Auth.
+        * Simple Auth allow username in form of <pre>user@server</pre>, ignoring server part
+        *
+        * @param App $a
+        * @hook 'authenticate'
+        *              array $addon_auth
+        *                      'username' => username from login form
+        *                      'password' => password from login form
+        *                      'authenticated' => return status,
+        *                      'user_record' => return authenticated user record
+        * @hook 'logged_in'
+        *              array $user     logged user record
         */
-
        function api_login(&$a){
                // login with oauth
                try{
                        }
                        echo __file__.__line__.__function__."<pre>"; var_dump($consumer, $token); die();
                }catch(Exception $e){
-                       logger(__file__.__line__.__function__."\n".$e);
-                       //die(__file__.__line__.__function__."<pre>".$e); die();
+                       logger($e);
                }
 
 
                if (!isset($_SERVER['PHP_AUTH_USER'])) {
                        logger('API_login: ' . print_r($_SERVER,true), LOGGER_DEBUG);
                        header('WWW-Authenticate: Basic realm="Friendica"');
-                       header('HTTP/1.0 401 Unauthorized');
-                       die((api_error($a, 'json', "This api requires login")));
-
-                       //die('This api requires login');
+                       throw new UnauthorizedException("This API requires login");
                }
 
                $user = $_SERVER['PHP_AUTH_USER'];
                else {
                        // process normal login request
 
-                       $r = q("SELECT * FROM `user` WHERE ( `email` = '%s' OR `nickname` = '%s' )
-                               AND `password` = '%s' AND `blocked` = 0 AND `account_expired` = 0 AND `account_removed` = 0 AND `verified` = 1 LIMIT 1",
+                       $r = q("SELECT * FROM `user` WHERE (`email` = '%s' OR `nickname` = '%s')
+                               AND `password` = '%s' AND NOT `blocked` AND NOT `account_expired` AND NOT `account_removed` AND `verified` LIMIT 1",
                                dbesc(trim($user)),
                                dbesc(trim($user)),
                                dbesc($encrypted)
                if((! $record) || (! count($record))) {
                        logger('API_login failure: ' . print_r($_SERVER,true), LOGGER_DEBUG);
                        header('WWW-Authenticate: Basic realm="Friendica"');
-                       header('HTTP/1.0 401 Unauthorized');
-                       die('This api requires login');
+                       #header('HTTP/1.0 401 Unauthorized');
+                       #die('This api requires login');
+                       throw new UnauthorizedException("This API requires login");
                }
 
-               authenticate_success($record); $_SESSION["allow_api"] = true;
+               authenticate_success($record);
+
+               $_SESSION["allow_api"] = true;
 
                call_hooks('logged_in', $a->user);
 
        }
 
-       /**************************
-        *  MAIN API ENTRY POINT  *
-        **************************/
+       /**
+        * @brief Check HTTP method of called API
+        *
+        * API endpoints can define which HTTP method to accept when called.
+        * This function check the current HTTP method agains endpoint
+        * registered method.
+        *
+        * @param string $method Required methods, uppercase, separated by comma
+        * @return bool
+        */
+        function api_check_method($method) {
+               if ($method=="*") return True;
+               return strpos($method, $_SERVER['REQUEST_METHOD']) !== false;
+        }
+
+       /**
+        * @brief Main API entry point
+        *
+        * Authenticate user, call registered API function, set HTTP headers
+        *
+        * @param App $a
+        * @return string API call result
+        */
        function api_call(&$a){
                GLOBAL $API, $called_api;
 
-               // preset
                $type="json";
-               foreach ($API as $p=>$info){
-                       if (strpos($a->query_string, $p)===0){
-                               $called_api= explode("/",$p);
-                               //unset($_SERVER['PHP_AUTH_USER']);
-                               if ($info['auth']===true && api_user()===false) {
-                                               api_login($a);
-                               }
+               if (strpos($a->query_string, ".xml")>0) $type="xml";
+               if (strpos($a->query_string, ".json")>0) $type="json";
+               if (strpos($a->query_string, ".rss")>0) $type="rss";
+               if (strpos($a->query_string, ".atom")>0) $type="atom";
+               try {
+                       foreach ($API as $p=>$info){
+                               if (strpos($a->query_string, $p)===0){
+                                       if (!api_check_method($info['method'])){
+                                               throw new MethodNotAllowedException();
+                                       }
+
+                                       $called_api= explode("/",$p);
+                                       //unset($_SERVER['PHP_AUTH_USER']);
+                                       if ($info['auth']===true && api_user()===false) {
+                                                       api_login($a);
+                                       }
+
+                                       logger('API call for ' . $a->user['username'] . ': ' . $a->query_string);
+                                       logger('API parameters: ' . print_r($_REQUEST,true));
+
+                                       $stamp =  microtime(true);
+                                       $r = call_user_func($info['func'], $type);
+                                       $duration = (float)(microtime(true)-$stamp);
+                                       logger("API call duration: ".round($duration, 2)."\t".$a->query_string, LOGGER_DEBUG);
+
+                                       if (get_config("system", "profiler")) {
+                                               $duration = microtime(true)-$a->performance["start"];
+
+                                               logger(parse_url($a->query_string, PHP_URL_PATH).": ".sprintf("Database: %s/%s, Network: %s, I/O: %s, Other: %s, Total: %s",
+                                                       round($a->performance["database"] - $a->performance["database_write"], 3),
+                                                       round($a->performance["database_write"], 3),
+                                                       round($a->performance["network"], 2),
+                                                       round($a->performance["file"], 2),
+                                                       round($duration - ($a->performance["database"] + $a->performance["network"]
+                                                               + $a->performance["file"]), 2),
+                                                       round($duration, 2)),
+                                                       LOGGER_DEBUG);
+
+                                               if (get_config("rendertime", "callstack")) {
+                                                       $o = "Database Read:\n";
+                                                       foreach ($a->callstack["database"] AS $func => $time) {
+                                                               $time = round($time, 3);
+                                                               if ($time > 0)
+                                                                       $o .= $func.": ".$time."\n";
+                                                       }
+                                                       $o .= "\nDatabase Write:\n";
+                                                       foreach ($a->callstack["database_write"] AS $func => $time) {
+                                                               $time = round($time, 3);
+                                                               if ($time > 0)
+                                                                       $o .= $func.": ".$time."\n";
+                                                       }
+
+                                                       $o .= "\nNetwork:\n";
+                                                       foreach ($a->callstack["network"] AS $func => $time) {
+                                                               $time = round($time, 3);
+                                                               if ($time > 0)
+                                                                       $o .= $func.": ".$time."\n";
+                                                       }
+                                                       logger($o, LOGGER_DEBUG);
+                                               }
+                                       }
+
+
+                                       if ($r===false) {
+                                               // api function returned false withour throw an
+                                               // exception. This should not happend, throw a 500
+                                               throw new InternalServerErrorException();
+                                       }
 
-                               load_contact_links(api_user());
-
-                               logger('API call for ' . $a->user['username'] . ': ' . $a->query_string);
-                               logger('API parameters: ' . print_r($_REQUEST,true));
-                               $type="json";
-                               if (strpos($a->query_string, ".xml")>0) $type="xml";
-                               if (strpos($a->query_string, ".json")>0) $type="json";
-                               if (strpos($a->query_string, ".rss")>0) $type="rss";
-                               if (strpos($a->query_string, ".atom")>0) $type="atom";
-                               if (strpos($a->query_string, ".as")>0) $type="as";
-
-                               $stamp =  microtime(true);
-                               $r = call_user_func($info['func'], $a, $type);
-                               $duration = (float)(microtime(true)-$stamp);
-                               logger("API call duration: ".round($duration, 2)."\t".$a->query_string, LOGGER_DEBUG);
-
-                               if ($r===false) return;
-
-                               switch($type){
-                                       case "xml":
-                                               $r = mb_convert_encoding($r, "UTF-8",mb_detect_encoding($r));
-                                               header ("Content-Type: text/xml");
-                                               return '<?xml version="1.0" encoding="UTF-8"?>'."\n".$r;
-                                               break;
-                                       case "json":
-                                               header ("Content-Type: application/json");
-                                               foreach($r as $rr)
-                                                       $json = json_encode($rr);
-                                                       if ($_GET['callback'])
-                                                               $json = $_GET['callback']."(".$json.")";
-                                                       return $json;
-                                               break;
-                                       case "rss":
-                                               header ("Content-Type: application/rss+xml");
-                                               return '<?xml version="1.0" encoding="UTF-8"?>'."\n".$r;
-                                               break;
-                                       case "atom":
-                                               header ("Content-Type: application/atom+xml");
-                                               return '<?xml version="1.0" encoding="UTF-8"?>'."\n".$r;
-                                               break;
-                                       case "as":
-                                               //header ("Content-Type: application/json");
-                                               //foreach($r as $rr)
-                                               //      return json_encode($rr);
-                                               return json_encode($r);
-                                               break;
+                                       switch($type){
+                                               case "xml":
+                                                       header ("Content-Type: text/xml");
+                                                       return $r;
+                                                       break;
+                                               case "json":
+                                                       header ("Content-Type: application/json");
+                                                       foreach($r as $rr)
+                                                               $json = json_encode($rr);
+                                                               if ($_GET['callback'])
+                                                                       $json = $_GET['callback']."(".$json.")";
+                                                               return $json;
+                                                       break;
+                                               case "rss":
+                                                       header ("Content-Type: application/rss+xml");
+                                                       return '<?xml version="1.0" encoding="UTF-8"?>'."\n".$r;
+                                                       break;
+                                               case "atom":
+                                                       header ("Content-Type: application/atom+xml");
+                                                       return '<?xml version="1.0" encoding="UTF-8"?>'."\n".$r;
+                                                       break;
 
+                                       }
                                }
-                               //echo "<pre>"; var_dump($r); die();
                        }
+                       throw new NotImplementedException();
+               } catch (HTTPException $e) {
+                       header("HTTP/1.1 {$e->httpcode} {$e->httpdesc}");
+                       return api_error($type, $e);
                }
-               header("HTTP/1.1 404 Not Found");
-               logger('API call not implemented: '.$a->query_string." - ".print_r($_REQUEST,true));
-               return(api_error($a, $type, "not implemented"));
-
        }
 
-       function api_error(&$a, $type, $error) {
+       /**
+        * @brief Format API error string
+        *
+        * @param string $type Return type (xml, json, rss, as)
+        * @param HTTPException $error Error object
+        * @return strin error message formatted as $type
+        */
+       function api_error($type, $e) {
+
+               $a = get_app();
+
+               $error = ($e->getMessage()!==""?$e->getMessage():$e->httpdesc);
                # TODO:  https://dev.twitter.com/overview/api/response-codes
-               $r = "<status><error>".$error."</error><request>".$a->query_string."</request></status>";
+
+               $error = array("error" => $error,
+                               "code" => $e->httpcode." ".$e->httpdesc,
+                               "request" => $a->query_string);
+
+               $ret = api_format_data('status', $type, array('status' => $error));
+
                switch($type){
                        case "xml":
                                header ("Content-Type: text/xml");
-                               return '<?xml version="1.0" encoding="UTF-8"?>'."\n".$r;
+                               return $ret;
                                break;
                        case "json":
                                header ("Content-Type: application/json");
-                               return json_encode(array('error' => $error, 'request' => $a->query_string));
+                               return json_encode($ret);
                                break;
                        case "rss":
                                header ("Content-Type: application/rss+xml");
-                               return '<?xml version="1.0" encoding="UTF-8"?>'."\n".$r;
+                               return $ret;
                                break;
                        case "atom":
                                header ("Content-Type: application/atom+xml");
-                               return '<?xml version="1.0" encoding="UTF-8"?>'."\n".$r;
+                               return $ret;
                                break;
                }
        }
 
        /**
-        * RSS extra info
+        * @brief Set values for RSS template
+        *
+        * @param App $a
+        * @param array $arr Array to be passed to template
+        * @param array $user_info
+        * @return array
         */
        function api_rss_extra(&$a, $arr, $user_info){
                if (is_null($user_info)) $user_info = api_get_user($a);
                $arr['$user'] = $user_info;
                $arr['$rss'] = array(
                        'alternate' => $user_info['url'],
-                       'self' => $a->get_baseurl(). "/". $a->query_string,
-                       'base' => $a->get_baseurl(),
+                       'self' => App::get_baseurl(). "/". $a->query_string,
+                       'base' => App::get_baseurl(),
                        'updated' => api_date(null),
                        'atom_updated' => datetime_convert('UTC','UTC','now',ATOM_TIME),
                        'language' => $user_info['language'],
-                       'logo'  => $a->get_baseurl()."/images/friendica-32.png",
+                       'logo'  => App::get_baseurl()."/images/friendica-32.png",
                );
 
                return $arr;
 
 
        /**
-        * Unique contact to contact url.
+        * @brief Unique contact to contact url.
+        *
+        * @param int $id Contact id
+        * @return bool|string
+        *              Contact url or False if contact id is unknown
         */
        function api_unique_id_to_url($id){
-               $r = q("SELECT `url` FROM `unique_contacts` WHERE `id`=%d LIMIT 1",
+               $r = q("SELECT `url` FROM `contact` WHERE `uid` = 0 AND `id` = %d LIMIT 1",
                        intval($id));
                if ($r)
                        return ($r[0]["url"]);
        }
 
        /**
-        * Returns user info array.
+        * @brief Get user info array.
+        *
+        * @param Api $a
+        * @param int|string $contact_id Contact ID or URL
+        * @param string $type Return type (for errors)
         */
        function api_get_user(&$a, $contact_id = Null, $type = "json"){
                global $called_api;
                        if (api_user()!==false)  $extra_query .= "AND `contact`.`uid`=".intval(api_user());
                }
 
-               // Searching for unique contact id
+               // Searching for contact id with uid = 0
                if(!is_null($contact_id) AND (intval($contact_id) != 0)){
                        $user = dbesc(api_unique_id_to_url($contact_id));
 
                        if ($user == "")
-                               die(api_error($a, $type, t("User not found.")));
+                               throw new BadRequestException("User not found.");
 
                        $url = $user;
                        $extra_query = "AND `contact`.`nurl` = '%s' ";
                        $user = dbesc(api_unique_id_to_url($_GET['user_id']));
 
                        if ($user == "")
-                               die(api_error($a, $type, t("User not found.")));
+                               throw new BadRequestException("User not found.");
 
                        $url = $user;
                        $extra_query = "AND `contact`.`nurl` = '%s' ";
 
                if (!$user) {
                        if (api_user()===false) {
-                               api_login($a); return False;
+                               api_login($a);
+                               return False;
                        } else {
                                $user = $_SESSION['uid'];
-                               $extra_query = "AND `contact`.`uid` = %d AND `contact`.`self` = 1 ";
+                               $extra_query = "AND `contact`.`uid` = %d AND `contact`.`self` ";
                        }
 
                }
                // Selecting the id by priority, friendica first
                api_best_nickname($uinfo);
 
-               // if the contact wasn't found, fetch it from the unique contacts
+               // if the contact wasn't found, fetch it from the contacts with uid = 0
                if (count($uinfo)==0) {
                        $r = array();
 
                        if ($url != "")
-                               $r = q("SELECT * FROM `unique_contacts` WHERE `url`='%s' LIMIT 1", $url);
-                       elseif ($nick != "")
-                               $r = q("SELECT * FROM `unique_contacts` WHERE `nick`='%s' LIMIT 1", $nick);
+                               $r = q("SELECT * FROM `contact` WHERE `uid` = 0 AND `nurl` = '%s' LIMIT 1", dbesc(normalise_link($url)));
 
                        if ($r) {
+                               $network_name = network_to_name($r[0]['network'], $r[0]['url']);
+
                                // If no nick where given, extract it from the address
                                if (($r[0]['nick'] == "") OR ($r[0]['name'] == $r[0]['nick']))
                                        $r[0]['nick'] = api_get_nick($r[0]["url"]);
                                        'id_str' => (string) $r[0]["id"],
                                        'name' => $r[0]["name"],
                                        'screen_name' => (($r[0]['nick']) ? $r[0]['nick'] : $r[0]['name']),
-                                       'location' => NULL,
-                                       'description' => NULL,
+                                       'location' => ($r[0]["location"] != "") ? $r[0]["location"] : $network_name,
+                                       'description' => $r[0]["about"],
+                                       'profile_image_url' => $r[0]["micro"],
+                                       'profile_image_url_https' => $r[0]["micro"],
                                        'url' => $r[0]["url"],
                                        'protected' => false,
                                        'followers_count' => 0,
                                        'friends_count' => 0,
                                        'listed_count' => 0,
-                                       'created_at' => api_date(0),
+                                       'created_at' => api_date($r[0]["created"]),
                                        'favourites_count' => 0,
                                        'utc_offset' => 0,
                                        'time_zone' => 'UTC',
                                        'contributors_enabled' => false,
                                        'is_translator' => false,
                                        'is_translation_enabled' => false,
-                                       'profile_image_url' => $r[0]["avatar"],
-                                       'profile_image_url_https' => $r[0]["avatar"],
                                        'following' => false,
                                        'follow_request_sent' => false,
-                                       'notifications' => false,
                                        'statusnet_blocking' => false,
                                        'notifications' => false,
                                        'statusnet_profile_url' => $r[0]["url"],
                                        'uid' => 0,
-                                       'cid' => 0,
+                                       'cid' => get_contact($r[0]["url"], api_user(), true),
                                        'self' => 0,
-                                       'network' => '',
+                                       'network' => $r[0]["network"],
                                );
 
                                return $ret;
-                       } else
-                               die(api_error($a, $type, t("User not found.")));
-
+                       } else {
+                               throw new BadRequestException("User not found.");
+                       }
                }
 
                if($uinfo[0]['self']) {
+
+                       if ($uinfo[0]['network'] == "")
+                               $uinfo[0]['network'] = NETWORK_DFRN;
+
                        $usr = q("select * from user where uid = %d limit 1",
                                intval(api_user())
                        );
                                intval(api_user())
                        );
 
-                       //AND `allow_cid`='' AND `allow_gid`='' AND `deny_cid`='' AND `deny_gid`=''",
+                       // Counting is deactivated by now, due to performance issues
                        // count public wall messages
-                       $r = q("SELECT count(*) as `count` FROM `item`
-                                       WHERE  `uid` = %d
-                                       AND `type`='wall'",
-                                       intval($uinfo[0]['uid'])
-                       );
-                       $countitms = $r[0]['count'];
-               }
-               else {
-                       //AND `allow_cid`='' AND `allow_gid`='' AND `deny_cid`='' AND `deny_gid`=''",
-                       $r = q("SELECT count(*) as `count` FROM `item`
-                                       WHERE  `contact-id` = %d",
-                                       intval($uinfo[0]['id'])
-                       );
-                       $countitms = $r[0]['count'];
+                       //$r = q("SELECT COUNT(*) as `count` FROM `item` WHERE `uid` = %d AND `wall`",
+                       //              intval($uinfo[0]['uid'])
+                       //);
+                       //$countitms = $r[0]['count'];
+                       $countitms = 0;
+               } else {
+                       // Counting is deactivated by now, due to performance issues
+                       //$r = q("SELECT count(*) as `count` FROM `item`
+                       //              WHERE  `contact-id` = %d",
+                       //              intval($uinfo[0]['id'])
+                       //);
+                       //$countitms = $r[0]['count'];
+                       $countitms = 0;
                }
-
+/*
+               // Counting is deactivated by now, due to performance issues
                // count friends
                $r = q("SELECT count(*) as `count` FROM `contact`
                                WHERE  `uid` = %d AND `rel` IN ( %d, %d )
-                               AND `self`=0 AND `blocked`=0 AND `pending`=0 AND `hidden`=0",
+                               AND `self`=0 AND `blocked`=0 AND `hidden`=0",
                                intval($uinfo[0]['uid']),
                                intval(CONTACT_IS_SHARING),
                                intval(CONTACT_IS_FRIEND)
 
                $r = q("SELECT count(*) as `count` FROM `contact`
                                WHERE  `uid` = %d AND `rel` IN ( %d, %d )
-                               AND `self`=0 AND `blocked`=0 AND `pending`=0 AND `hidden`=0",
+                               AND `self`=0 AND `blocked`=0 AND `hidden`=0",
                                intval($uinfo[0]['uid']),
                                intval(CONTACT_IS_FOLLOWER),
                                intval(CONTACT_IS_FRIEND)
                        $countfollowers = 0;
                        $starred = 0;
                }
+*/
+               $countfriends = 0;
+               $countfollowers = 0;
+               $starred = 0;
 
                // Add a nick if it isn't present there
                if (($uinfo[0]['nick'] == "") OR ($uinfo[0]['name'] == $uinfo[0]['nick'])) {
                        $uinfo[0]['nick'] = api_get_nick($uinfo[0]["url"]);
                }
 
-               // Fetching unique id
-               $r = q("SELECT id FROM `unique_contacts` WHERE `url`='%s' LIMIT 1", dbesc(normalise_link($uinfo[0]['url'])));
-
-               // If not there, then add it
-               if (count($r) == 0) {
-                       q("INSERT INTO `unique_contacts` (`url`, `name`, `nick`, `avatar`) VALUES ('%s', '%s', '%s', '%s')",
-                               dbesc(normalise_link($uinfo[0]['url'])), dbesc($uinfo[0]['name']),dbesc($uinfo[0]['nick']), dbesc($uinfo[0]['micro']));
-
-                       $r = q("SELECT `id` FROM `unique_contacts` WHERE `url`='%s' LIMIT 1", dbesc(normalise_link($uinfo[0]['url'])));
-               }
-
                $network_name = network_to_name($uinfo[0]['network'], $uinfo[0]['url']);
 
+               $pcontact_id  = get_contact($uinfo[0]['url'], 0, true);
+
                $ret = Array(
-                       'id' => intval($r[0]['id']),
-                       'id_str' => (string) intval($r[0]['id']),
+                       'id' => intval($pcontact_id),
+                       'id_str' => (string) intval($pcontact_id),
                        'name' => (($uinfo[0]['name']) ? $uinfo[0]['name'] : $uinfo[0]['nick']),
                        'screen_name' => (($uinfo[0]['nick']) ? $uinfo[0]['nick'] : $uinfo[0]['name']),
                        'location' => ($usr) ? $usr[0]['default-location'] : $network_name,
                        'protected' => false,
                        'followers_count' => intval($countfollowers),
                        'friends_count' => intval($countfriends),
+                       'listed_count' => 0,
                        'created_at' => api_date($uinfo[0]['created']),
                        'favourites_count' => intval($starred),
                        'utc_offset' => "0",
                        'time_zone' => 'UTC',
+                       'geo_enabled' => false,
+                       'verified' => true,
                        'statuses_count' => intval($countitms),
+                       'lang' => '',
+                       'contributors_enabled' => false,
+                       'is_translator' => false,
+                       'is_translation_enabled' => false,
                        'following' => (($uinfo[0]['rel'] == CONTACT_IS_FOLLOWER) OR ($uinfo[0]['rel'] == CONTACT_IS_FRIEND)),
-                       'verified' => true,
+                       'follow_request_sent' => false,
                        'statusnet_blocking' => false,
                        'notifications' => false,
-                       //'statusnet_profile_url' => $a->get_baseurl()."/contacts/".$uinfo[0]['cid'],
+                       //'statusnet_profile_url' => App::get_baseurl()."/contacts/".$uinfo[0]['cid'],
                        'statusnet_profile_url' => $uinfo[0]['url'],
                        'uid' => intval($uinfo[0]['uid']),
                        'cid' => intval($uinfo[0]['cid']),
 
        }
 
+       /**
+        * @brief return api-formatted array for item's author and owner
+        *
+        * @param App $a
+        * @param array $item : item from db
+        * @return array(array:author, array:owner)
+        */
        function api_item_get_user(&$a, $item) {
 
-               $author = q("SELECT * FROM `unique_contacts` WHERE `url`='%s' LIMIT 1",
-                       dbesc(normalise_link($item['author-link'])));
+               $status_user = api_get_user($a, $item["author-link"]);
 
-               if (count($author) == 0) {
-                       q("INSERT INTO `unique_contacts` (`url`, `name`, `avatar`) VALUES ('%s', '%s', '%s')",
-                               dbesc(normalise_link($item["author-link"])), dbesc($item["author-name"]), dbesc($item["author-avatar"]));
-
-                       $author = q("SELECT `id` FROM `unique_contacts` WHERE `url`='%s' LIMIT 1",
-                               dbesc(normalise_link($item['author-link'])));
-               } else if ($item["author-link"].$item["author-name"] != $author[0]["url"].$author[0]["name"]) {
-                       $r = q("SELECT `id` FROM `unique_contacts` WHERE `name` = '%s' AND `avatar` = '%s' AND url = '%s'",
-                               dbesc($item["author-name"]), dbesc($item["author-avatar"]),
-                               dbesc(normalise_link($item["author-link"])));
+               $status_user["protected"] = (($item["allow_cid"] != "") OR
+                                               ($item["allow_gid"] != "") OR
+                                               ($item["deny_cid"] != "") OR
+                                               ($item["deny_gid"] != "") OR
+                                               $item["private"]);
 
-                       if (!$r)
-                               q("UPDATE `unique_contacts` SET `name` = '%s', `avatar` = '%s' WHERE `url` = '%s'",
-                                       dbesc($item["author-name"]), dbesc($item["author-avatar"]),
-                                       dbesc(normalise_link($item["author-link"])));
-               }
+               $owner_user = api_get_user($a, $item["owner-link"]);
 
-               $owner = q("SELECT `id` FROM `unique_contacts` WHERE `url`='%s' LIMIT 1",
-                       dbesc(normalise_link($item['owner-link'])));
+               return (array($status_user, $owner_user));
+       }
 
-               if (count($owner) == 0) {
-                       q("INSERT INTO `unique_contacts` (`url`, `name`, `avatar`) VALUES ('%s', '%s', '%s')",
-                               dbesc(normalise_link($item["owner-link"])), dbesc($item["owner-name"]), dbesc($item["owner-avatar"]));
+       /**
+        * @brief walks recursively through an array with the possibility to change value and key
+        *
+        * @param array $array The array to walk through
+        * @param string $callback The callback function
+        *
+        * @return array the transformed array
+        */
+       function api_walk_recursive(array &$array, callable $callback) {
 
-                       $owner = q("SELECT `id` FROM `unique_contacts` WHERE `url`='%s' LIMIT 1",
-                               dbesc(normalise_link($item['owner-link'])));
-               } else if ($item["owner-link"].$item["owner-name"] != $owner[0]["url"].$owner[0]["name"]) {
-                       $r = q("SELECT `id` FROM `unique_contacts` WHERE `name` = '%s' AND `avatar` = '%s' AND url = '%s'",
-                               dbesc($item["owner-name"]), dbesc($item["owner-avatar"]),
-                               dbesc(normalise_link($item["owner-link"])));
+               $new_array = array();
 
-                       if (!$r)
-                               q("UPDATE `unique_contacts` SET `name` = '%s', `avatar` = '%s' WHERE `url` = '%s'",
-                                       dbesc($item["owner-name"]), dbesc($item["owner-avatar"]),
-                                       dbesc(normalise_link($item["owner-link"])));
+               foreach ($array as $k => $v) {
+                       if (is_array($v)) {
+                               if ($callback($v, $k))
+                                       $new_array[$k] = api_walk_recursive($v, $callback);
+                       } else {
+                               if ($callback($v, $k))
+                                       $new_array[$k] = $v;
+                       }
                }
+               $array = $new_array;
 
-               // Comments in threads may appear as wall-to-wall postings.
-               // So only take the owner at the top posting.
-               if ($item["id"] == $item["parent"])
-                       $status_user = api_get_user($a,$item["owner-link"]);
-               else
-                       $status_user = api_get_user($a,$item["author-link"]);
+               return $array;
+       }
 
-               $status_user["protected"] = (($item["allow_cid"] != "") OR
-                                               ($item["allow_gid"] != "") OR
-                                               ($item["deny_cid"] != "") OR
-                                               ($item["deny_gid"] != "") OR
-                                               $item["private"]);
+       /**
+        * @brief Callback function to transform the array in an array that can be transformed in a XML file
+        *
+        * @param variant $item Array item value
+        * @param string $key Array key
+        *
+        * @return boolean Should the array item be deleted?
+        */
+       function api_reformat_xml(&$item, &$key) {
+               if (is_bool($item))
+                       $item = ($item ? "true" : "false");
+
+               if (substr($key, 0, 10) == "statusnet_")
+                       $key = "statusnet:".substr($key, 10);
+               elseif (substr($key, 0, 10) == "friendica_")
+                       $key = "friendica:".substr($key, 10);
+               //else
+               //      $key = "default:".$key;
 
-               return ($status_user);
+               return true;
        }
 
+       /**
+        * @brief Creates the XML from a JSON style array
+        *
+        * @param array $data JSON style array
+        * @param string $root_element Name of the root element
+        *
+        * @return string The XML data
+        */
+       function api_create_xml($data, $root_element) {
+               $childname = key($data);
+               $data2 = array_pop($data);
+               $key = key($data2);
+
+               $namespaces = array("" => "http://api.twitter.com",
+                                       "statusnet" => "http://status.net/schema/api/1/",
+                                       "friendica" => "http://friendi.ca/schema/api/1/",
+                                       "georss" => "http://www.georss.org/georss");
+
+               /// @todo Auto detection of needed namespaces
+               if (in_array($root_element, array("ok", "hash", "config", "version", "ids", "notes", "photos")))
+                       $namespaces = array();
+
+               if (is_array($data2))
+                       api_walk_recursive($data2, "api_reformat_xml");
+
+               if ($key == "0") {
+                       $data4 = array();
+                       $i = 1;
+
+                       foreach ($data2 AS $item)
+                               $data4[$i++.":".$childname] = $item;
+
+                       $data2 = $data4;
+               }
+
+               $data3 = array($root_element => $data2);
+
+               $ret = xml::from_array($data3, $xml, false, $namespaces);
+               return $ret;
+       }
 
        /**
-        *  load api $templatename for $type and replace $data array
+        * @brief Formats the data according to the data type
+        *
+        * @param string $root_element Name of the root element
+        * @param string $type Return type (atom, rss, xml, json)
+        * @param array $data JSON style array
+        *
+        * @return (string|object) XML data or JSON data
         */
-       function api_apply_template($templatename, $type, $data){
+       function api_format_data($root_element, $type, $data){
 
                $a = get_app();
 
                        case "atom":
                        case "rss":
                        case "xml":
-                               $data = array_xmlify($data);
-                               $tpl = get_markup_template("api_".$templatename."_".$type.".tpl");
-                               if(! $tpl) {
-                                       header ("Content-Type: text/xml");
-                                       echo '<?xml version="1.0" encoding="UTF-8"?>'."\n".'<status><error>not implemented</error></status>';
-                                       killme();
-                               }
-                               $ret = replace_macros($tpl, $data);
+                               $ret = api_create_xml($data, $root_element);
                                break;
                        case "json":
                                $ret = $data;
         * returns a 401 status code and an error message if not.
         * http://developer.twitter.com/doc/get/account/verify_credentials
         */
-       function api_account_verify_credentials(&$a, $type){
-               if (api_user()===false) return false;
+       function api_account_verify_credentials($type){
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
                unset($_REQUEST["user_id"]);
                unset($_GET["user_id"]);
 
                // - Adding last status
                if (!$skip_status) {
-                       $user_info["status"] = api_status_show($a,"raw");
+                       $user_info["status"] = api_status_show("raw");
                        if (!count($user_info["status"]))
                                unset($user_info["status"]);
                        else
                unset($user_info["uid"]);
                unset($user_info["self"]);
 
-               return api_apply_template("user", $type, array('$user' => $user_info));
+               return api_format_data("user", $type, array('user' => $user_info));
 
        }
        api_register_func('api/account/verify_credentials','api_account_verify_credentials', true);
        }
 
 /*Waitman Gobble Mod*/
-       function api_statuses_mediap(&$a, $type) {
+       function api_statuses_mediap($type) {
+
+               $a = get_app();
+
                if (api_user()===false) {
                        logger('api_statuses_update: no user');
-                       return false;
+                       throw new ForbiddenException();
                }
                $user_info = api_get_user($a);
 
 
                if((strpos($txt,'<') !== false) || (strpos($txt,'>') !== false)) {
 
-                       require_once('library/HTMLPurifier.auto.php');
-
                        $txt = html2bb_video($txt);
                        $config = HTMLPurifier_Config::createDefault();
                        $config->set('Cache.DefinitionImpl', null);
                item_post($a);
 
                // this should output the last post (the one we just posted).
-               return api_status_show($a,$type);
+               return api_status_show($type);
        }
-       api_register_func('api/statuses/mediap','api_statuses_mediap', true);
+       api_register_func('api/statuses/mediap','api_statuses_mediap', true, API_METHOD_POST);
 /*Waitman Gobble Mod*/
 
 
-       function api_statuses_update(&$a, $type) {
+       function api_statuses_update($type) {
+
+               $a = get_app();
+
                if (api_user()===false) {
                        logger('api_statuses_update: no user');
-                       return false;
+                       throw new ForbiddenException();
                }
 
                $user_info = api_get_user($a);
                if(requestdata('htmlstatus')) {
                        $txt = requestdata('htmlstatus');
                        if((strpos($txt,'<') !== false) || (strpos($txt,'>') !== false)) {
-
-                               require_once('library/HTMLPurifier.auto.php');
-
                                $txt = html2bb_video($txt);
 
                                $config = HTMLPurifier_Config::createDefault();
 
                                if ($posts_day > $throttle_day) {
                                        logger('Daily posting limit reached for user '.api_user(), LOGGER_DEBUG);
-                                       die(api_error($a, $type, sprintf(t("Daily posting limit of %d posts reached. The post was rejected."), $throttle_day)));
+                                       #die(api_error($type, sprintf(t("Daily posting limit of %d posts reached. The post was rejected."), $throttle_day)));
+                                       throw new TooManyRequestsException(sprintf(t("Daily posting limit of %d posts reached. The post was rejected."), $throttle_day));
                                }
                        }
 
 
                                if ($posts_week > $throttle_week) {
                                        logger('Weekly posting limit reached for user '.api_user(), LOGGER_DEBUG);
-                                       die(api_error($a, $type, sprintf(t("Weekly posting limit of %d posts reached. The post was rejected."), $throttle_week)));
+                                       #die(api_error($type, sprintf(t("Weekly posting limit of %d posts reached. The post was rejected."), $throttle_week)));
+                                       throw new TooManyRequestsException(sprintf(t("Weekly posting limit of %d posts reached. The post was rejected."), $throttle_week));
+
                                }
                        }
 
 
                                if ($posts_month > $throttle_month) {
                                        logger('Monthly posting limit reached for user '.api_user(), LOGGER_DEBUG);
-                                       die(api_error($a, $type, sprintf(t("Monthly posting limit of %d posts reached. The post was rejected."), $throttle_month)));
+                                       #die(api_error($type, sprintf(t("Monthly posting limit of %d posts reached. The post was rejected."), $throttle_month)));
+                                       throw new TooManyRequestsException(sprintf(t("Monthly posting limit of %d posts reached. The post was rejected."), $throttle_month));
                                }
                        }
 
                        if ($r) {
                                $phototypes = Photo::supportedTypes();
                                $ext = $phototypes[$r[0]['type']];
-                               $_REQUEST['body'] .= "\n\n".'[url='.$a->get_baseurl().'/photos/'.$r[0]['nickname'].'/image/'.$r[0]['resource-id'].']';
-                               $_REQUEST['body'] .= '[img]'.$a->get_baseurl()."/photo/".$r[0]['resource-id']."-".$r[0]['scale'].".".$ext."[/img][/url]";
+                               $_REQUEST['body'] .= "\n\n".'[url='.App::get_baseurl().'/photos/'.$r[0]['nickname'].'/image/'.$r[0]['resource-id'].']';
+                               $_REQUEST['body'] .= '[img]'.App::get_baseurl()."/photo/".$r[0]['resource-id']."-".$r[0]['scale'].".".$ext."[/img][/url]";
                        }
                }
 
                item_post($a);
 
                // this should output the last post (the one we just posted).
-               return api_status_show($a,$type);
+               return api_status_show($type);
        }
-       api_register_func('api/statuses/update','api_statuses_update', true);
-       api_register_func('api/statuses/update_with_media','api_statuses_update', true);
+       api_register_func('api/statuses/update','api_statuses_update', true, API_METHOD_POST);
+       api_register_func('api/statuses/update_with_media','api_statuses_update', true, API_METHOD_POST);
+
 
+       function api_media_upload($type) {
+
+               $a = get_app();
 
-       function api_media_upload(&$a, $type) {
                if (api_user()===false) {
                        logger('no user');
-                       return false;
+                       throw new ForbiddenException();
                }
 
                $user_info = api_get_user($a);
 
                if(!x($_FILES,'media')) {
                        // Output error
-                       return false;
+                       throw new BadRequestException("No media.");
                }
 
                $media = wall_upload_post($a, false);
                if(!$media) {
                        // Output error
-                       return false;
+                       throw new InternalServerErrorException();
                }
 
                $returndata = array();
 
                return array("media" => $returndata);
        }
+       api_register_func('api/media/upload','api_media_upload', true, API_METHOD_POST);
+
+       function api_status_show($type){
 
-       api_register_func('api/media/upload','api_media_upload', true);
+               $a = get_app();
 
-       function api_status_show(&$a, $type){
                $user_info = api_get_user($a);
 
                logger('api_status_show: user_info: '.print_r($user_info, true), LOGGER_DEBUG);
                        $privacy_sql = "";
 
                // get last public wall message
-               $lastwall = q("SELECT `item`.*, `i`.`contact-id` as `reply_uid`, `i`.`author-link` AS `item-author`
-                               FROM `item`, `item` as `i`
+               $lastwall = q("SELECT `item`.*
+                               FROM `item`
                                WHERE `item`.`contact-id` = %d AND `item`.`uid` = %d
                                        AND ((`item`.`author-link` IN ('%s', '%s')) OR (`item`.`owner-link` IN ('%s', '%s')))
-                                       AND `i`.`id` = `item`.`parent`
-                                       AND `item`.`type`!='activity' $privacy_sql
-                               ORDER BY `item`.`created` DESC
+                                       AND `item`.`type` != 'activity' $privacy_sql
+                               ORDER BY `item`.`id` DESC
                                LIMIT 1",
                                intval($user_info['cid']),
                                intval(api_user()),
                if (count($lastwall)>0){
                        $lastwall = $lastwall[0];
 
-                       $in_reply_to_status_id = NULL;
-                       $in_reply_to_user_id = NULL;
-                       $in_reply_to_status_id_str = NULL;
-                       $in_reply_to_user_id_str = NULL;
-                       $in_reply_to_screen_name = NULL;
-                       if (intval($lastwall['parent']) != intval($lastwall['id'])) {
-                               $in_reply_to_status_id= intval($lastwall['parent']);
-                               $in_reply_to_status_id_str = (string) intval($lastwall['parent']);
-
-                               $r = q("SELECT * FROM `unique_contacts` WHERE `url` = '%s'", dbesc(normalise_link($lastwall['item-author'])));
-                               if ($r) {
-                                       if ($r[0]['nick'] == "")
-                                               $r[0]['nick'] = api_get_nick($r[0]["url"]);
-
-                                       $in_reply_to_screen_name = (($r[0]['nick']) ? $r[0]['nick'] : $r[0]['name']);
-                                       $in_reply_to_user_id = intval($r[0]['id']);
-                                       $in_reply_to_user_id_str = (string) intval($r[0]['id']);
-                               }
-                       }
-
-                       // There seems to be situation, where both fields are identical:
-                       // https://github.com/friendica/friendica/issues/1010
-                       // This is a bugfix for that.
-                       if (intval($in_reply_to_status_id) == intval($lastwall['id'])) {
-                               logger('api_status_show: this message should never appear: id: '.$lastwall['id'].' similar to reply-to: '.$in_reply_to_status_id, LOGGER_DEBUG);
-                               $in_reply_to_status_id = NULL;
-                               $in_reply_to_user_id = NULL;
-                               $in_reply_to_status_id_str = NULL;
-                               $in_reply_to_user_id_str = NULL;
-                               $in_reply_to_screen_name = NULL;
-                       }
+                       $in_reply_to = api_in_reply_to($lastwall);
 
                        $converted = api_convert_item($lastwall);
 
+                       if ($type == "xml")
+                               $geo = "georss:point";
+                       else
+                               $geo = "geo";
+
                        $status_info = array(
                                'created_at' => api_date($lastwall['created']),
                                'id' => intval($lastwall['id']),
                                'text' => $converted["text"],
                                'source' => (($lastwall['app']) ? $lastwall['app'] : 'web'),
                                'truncated' => false,
-                               'in_reply_to_status_id' => $in_reply_to_status_id,
-                               'in_reply_to_status_id_str' => $in_reply_to_status_id_str,
-                               'in_reply_to_user_id' => $in_reply_to_user_id,
-                               'in_reply_to_user_id_str' => $in_reply_to_user_id_str,
-                               'in_reply_to_screen_name' => $in_reply_to_screen_name,
+                               'in_reply_to_status_id' => $in_reply_to['status_id'],
+                               'in_reply_to_status_id_str' => $in_reply_to['status_id_str'],
+                               'in_reply_to_user_id' => $in_reply_to['user_id'],
+                               'in_reply_to_user_id_str' => $in_reply_to['user_id_str'],
+                               'in_reply_to_screen_name' => $in_reply_to['screen_name'],
                                'user' => $user_info,
-                               'geo' => NULL,
+                               $geo => NULL,
                                'coordinates' => "",
                                'place' => "",
                                'contributors' => "",
                if ($type == "raw")
                        return($status_info);
 
-               return  api_apply_template("status", $type, array('$status' => $status_info));
+               return  api_format_data("statuses", $type, array('status' => $status_info));
 
        }
 
         * The author's most recent status will be returned inline.
         * http://developer.twitter.com/doc/get/users/show
         */
-       function api_users_show(&$a, $type){
-               $user_info = api_get_user($a);
+       function api_users_show($type){
+
+               $a = get_app();
 
+               $user_info = api_get_user($a);
                $lastwall = q("SELECT `item`.*
-                               FROM `item`, `contact`
+                               FROM `item`
+                               INNER JOIN `contact` ON `contact`.`id`=`item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
                                WHERE `item`.`uid` = %d AND `verb` = '%s' AND `item`.`contact-id` = %d
                                        AND ((`item`.`author-link` IN ('%s', '%s')) OR (`item`.`owner-link` IN ('%s', '%s')))
-                                       AND `contact`.`id`=`item`.`contact-id`
                                        AND `type`!='activity'
                                        AND `item`.`allow_cid`='' AND `item`.`allow_gid`='' AND `item`.`deny_cid`='' AND `item`.`deny_gid`=''
-                               ORDER BY `created` DESC
+                               ORDER BY `id` DESC
                                LIMIT 1",
                                intval(api_user()),
                                dbesc(ACTIVITY_POST),
                                dbesc($user_info['url']),
                                dbesc(normalise_link($user_info['url']))
                );
+
                if (count($lastwall)>0){
                        $lastwall = $lastwall[0];
 
-                       $in_reply_to_status_id = NULL;
-                       $in_reply_to_user_id = NULL;
-                       $in_reply_to_status_id_str = NULL;
-                       $in_reply_to_user_id_str = NULL;
-                       $in_reply_to_screen_name = NULL;
-                       if ($lastwall['parent']!=$lastwall['id']) {
-                               $reply = q("SELECT `item`.`id`, `item`.`contact-id` as `reply_uid`, `contact`.`nick` as `reply_author`, `item`.`author-link` AS `item-author`
-                                               FROM `item`,`contact` WHERE `contact`.`id`=`item`.`contact-id` AND `item`.`id` = %d", intval($lastwall['parent']));
-                               if (count($reply)>0) {
-                                       $in_reply_to_status_id = intval($lastwall['parent']);
-                                       $in_reply_to_status_id_str = (string) intval($lastwall['parent']);
-
-                                       $r = q("SELECT * FROM `unique_contacts` WHERE `url` = '%s'", dbesc(normalise_link($reply[0]['item-author'])));
-                                       if ($r) {
-                                               if ($r[0]['nick'] == "")
-                                                       $r[0]['nick'] = api_get_nick($r[0]["url"]);
-
-                                               $in_reply_to_screen_name = (($r[0]['nick']) ? $r[0]['nick'] : $r[0]['name']);
-                                               $in_reply_to_user_id = intval($r[0]['id']);
-                                               $in_reply_to_user_id_str = (string) intval($r[0]['id']);
-                                       }
-                               }
-                       }
+                       $in_reply_to = api_in_reply_to($lastwall);
 
                        $converted = api_convert_item($lastwall);
 
+                       if ($type == "xml")
+                               $geo = "georss:point";
+                       else
+                               $geo = "geo";
+
                        $user_info['status'] = array(
                                'text' => $converted["text"],
                                'truncated' => false,
                                'created_at' => api_date($lastwall['created']),
-                               'in_reply_to_status_id' => $in_reply_to_status_id,
-                               'in_reply_to_status_id_str' => $in_reply_to_status_id_str,
+                               'in_reply_to_status_id' => $in_reply_to['status_id'],
+                               'in_reply_to_status_id_str' => $in_reply_to['status_id_str'],
                                'source' => (($lastwall['app']) ? $lastwall['app'] : 'web'),
                                'id' => intval($lastwall['contact-id']),
                                'id_str' => (string) $lastwall['contact-id'],
-                               'in_reply_to_user_id' => $in_reply_to_user_id,
-                               'in_reply_to_user_id_str' => $in_reply_to_user_id_str,
-                               'in_reply_to_screen_name' => $in_reply_to_screen_name,
-                               'geo' => NULL,
+                               'in_reply_to_user_id' => $in_reply_to['user_id'],
+                               'in_reply_to_user_id_str' => $in_reply_to['user_id_str'],
+                               'in_reply_to_screen_name' => $in_reply_to['screen_name'],
+                               $geo => NULL,
                                'favorited' => $lastwall['starred'] ? true : false,
                                'statusnet_html'                => $converted["html"],
                                'statusnet_conversation_id'     => $lastwall['parent'],
                unset($user_info["uid"]);
                unset($user_info["self"]);
 
-               return  api_apply_template("user", $type, array('$user' => $user_info));
+               return  api_format_data("user", $type, array('user' => $user_info));
 
        }
        api_register_func('api/users/show','api_users_show');
 
 
-       function api_users_search(&$a, $type) {
+       function api_users_search($type) {
+
+               $a = get_app();
+
                $page = (x($_REQUEST,'page')?$_REQUEST['page']-1:0);
 
                $userlist = array();
 
                if (isset($_GET["q"])) {
-                       $r = q("SELECT id FROM `unique_contacts` WHERE `name`='%s'", dbesc($_GET["q"]));
+                       $r = q("SELECT id FROM `contact` WHERE `uid` = 0 AND `name` = '%s'", dbesc($_GET["q"]));
                        if (!count($r))
-                               $r = q("SELECT `id` FROM `unique_contacts` WHERE `nick`='%s'", dbesc($_GET["q"]));
+                               $r = q("SELECT `id` FROM `contact` WHERE `uid` = 0 AND `nick` = '%s'", dbesc($_GET["q"]));
 
                        if (count($r)) {
+                               $k = 0;
                                foreach ($r AS $user) {
-                                       $user_info = api_get_user($a, $user["id"]);
-                                       //echo print_r($user_info, true)."\n";
-                                       $userdata = api_apply_template("user", $type, array('user' => $user_info));
-                                       $userlist[] = $userdata["user"];
+                                       $user_info = api_get_user($a, $user["id"], "json");
+
+                                       if ($type == "xml")
+                                               $userlist[$k++.":user"] = $user_info;
+                                       else
+                                               $userlist[] = $user_info;
                                }
                                $userlist = array("users" => $userlist);
-                       } else
-                               die(api_error($a, $type, t("User not found.")));
-               } else
-                       die(api_error($a, $type, t("User not found.")));
-
-               return ($userlist);
+                       } else {
+                               throw new BadRequestException("User not found.");
+                       }
+               } else {
+                       throw new BadRequestException("User not found.");
+               }
+               return api_format_data("users", $type, $userlist);
        }
 
        api_register_func('api/users/search','api_users_search');
         * TODO: Optional parameters
         * TODO: Add reply info
         */
-       function api_statuses_home_timeline(&$a, $type){
-               if (api_user()===false) return false;
+       function api_statuses_home_timeline($type){
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
                unset($_REQUEST["user_id"]);
                unset($_GET["user_id"]);
                $user_info = api_get_user($a);
                // get last newtork messages
 
-
                // params
                $count = (x($_REQUEST,'count')?$_REQUEST['count']:20);
                $page = (x($_REQUEST,'page')?$_REQUEST['page']-1:0);
                if ($conversation_id > 0)
                        $sql_extra .= ' AND `item`.`parent` = '.intval($conversation_id);
 
-               $r = q("SELECT STRAIGHT_JOIN `item`.*, `item`.`id` AS `item_id`, `item`.`network` AS `item_network`,
+               $r = q("SELECT `item`.*, `item`.`id` AS `item_id`, `item`.`network` AS `item_network`,
                        `contact`.`name`, `contact`.`photo`, `contact`.`url`, `contact`.`rel`,
                        `contact`.`network`, `contact`.`thumb`, `contact`.`dfrn-id`, `contact`.`self`,
-                       `contact`.`id` AS `cid`, `contact`.`uid` AS `contact-uid`
-                       FROM `item`, `contact`
+                       `contact`.`id` AS `cid`
+                       FROM `item`
+                       STRAIGHT_JOIN `contact` ON `contact`.`id` = `item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
+                               AND NOT `contact`.`blocked`
                        WHERE `item`.`uid` = %d AND `verb` = '%s'
-                       AND `item`.`visible` = 1 and `item`.`moderated` = 0 AND `item`.`deleted` = 0
-                       AND `contact`.`id` = `item`.`contact-id`
-                       AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
+                       AND `item`.`visible` AND NOT `item`.`moderated` AND NOT `item`.`deleted`
                        $sql_extra
                        AND `item`.`id`>%d
                        ORDER BY `item`.`id` DESC LIMIT %d ,%d ",
                        intval($start), intval($count)
                );
 
-               $ret = api_format_items($r,$user_info);
+               $ret = api_format_items($r,$user_info, false, $type);
 
                // Set all posts from the query above to seen
                $idarray = array();
 
                $idlist = implode(",", $idarray);
 
-               if ($idlist != "")
-                       $r = q("UPDATE `item` SET `unseen` = 0 WHERE `unseen` AND `id` IN (%s)", $idlist);
+               if ($idlist != "") {
+                       $unseen = q("SELECT `id` FROM `item` WHERE `unseen` AND `id` IN (%s)", $idlist);
 
+                       if ($unseen)
+                               $r = q("UPDATE `item` SET `unseen` = 0 WHERE `unseen` AND `id` IN (%s)", $idlist);
+               }
 
-               $data = array('$statuses' => $ret);
+               $data = array('status' => $ret);
                switch($type){
                        case "atom":
                        case "rss":
                                $data = api_rss_extra($a, $data, $user_info);
                                break;
-                       case "as":
-                               $as = api_format_as($a, $ret, $user_info);
-                               $as['title'] = $a->config['sitename']." Home Timeline";
-                               $as['link']['url'] = $a->get_baseurl()."/".$user_info["screen_name"]."/all";
-                               return($as);
-                               break;
                }
 
-               return  api_apply_template("timeline", $type, $data);
+               return  api_format_data("statuses", $type, $data);
        }
        api_register_func('api/statuses/home_timeline','api_statuses_home_timeline', true);
        api_register_func('api/statuses/friends_timeline','api_statuses_home_timeline', true);
 
-       function api_statuses_public_timeline(&$a, $type){
-               if (api_user()===false) return false;
+       function api_statuses_public_timeline($type){
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
                $user_info = api_get_user($a);
                // get last newtork messages
                $r = q("SELECT `item`.*, `item`.`id` AS `item_id`, `item`.`network` AS `item_network`,
                        `contact`.`name`, `contact`.`photo`, `contact`.`url`, `contact`.`rel`,
                        `contact`.`network`, `contact`.`thumb`, `contact`.`self`, `contact`.`writable`,
-                       `contact`.`id` AS `cid`, `contact`.`uid` AS `contact-uid`,
+                       `contact`.`id` AS `cid`,
                        `user`.`nickname`, `user`.`hidewall`
-                       FROM `item` STRAIGHT_JOIN `contact` ON `contact`.`id` = `item`.`contact-id`
+                       FROM `item`
+                       STRAIGHT_JOIN `contact` ON `contact`.`id` = `item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
+                               AND NOT `contact`.`blocked`
                        STRAIGHT_JOIN `user` ON `user`.`uid` = `item`.`uid`
-                       WHERE `verb` = '%s' AND `item`.`visible` = 1 AND `item`.`deleted` = 0 and `item`.`moderated` = 0
+                               AND NOT `user`.`hidewall`
+                       WHERE `verb` = '%s' AND `item`.`visible` AND NOT `item`.`deleted` AND NOT `item`.`moderated`
                        AND `item`.`allow_cid` = ''  AND `item`.`allow_gid` = ''
                        AND `item`.`deny_cid`  = '' AND `item`.`deny_gid`  = ''
-                       AND `item`.`private` = 0 AND `item`.`wall` = 1 AND `user`.`hidewall` = 0
-                       AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
+                       AND NOT `item`.`private` AND `item`.`wall`
                        $sql_extra
                        AND `item`.`id`>%d
                        ORDER BY `item`.`id` DESC LIMIT %d, %d ",
                        intval($start),
                        intval($count));
 
-               $ret = api_format_items($r,$user_info);
+               $ret = api_format_items($r,$user_info, false, $type);
 
 
-               $data = array('$statuses' => $ret);
+               $data = array('status' => $ret);
                switch($type){
                        case "atom":
                        case "rss":
                                $data = api_rss_extra($a, $data, $user_info);
                                break;
-                       case "as":
-                               $as = api_format_as($a, $ret, $user_info);
-                               $as['title'] = $a->config['sitename']." Public Timeline";
-                               $as['link']['url'] = $a->get_baseurl()."/";
-                               return($as);
-                               break;
                }
 
-               return  api_apply_template("timeline", $type, $data);
+               return  api_format_data("statuses", $type, $data);
        }
        api_register_func('api/statuses/public_timeline','api_statuses_public_timeline', true);
 
        /**
         *
         */
-       function api_statuses_show(&$a, $type){
-               if (api_user()===false) return false;
+       function api_statuses_show($type){
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
                $user_info = api_get_user($a);
 
 
                $sql_extra = '';
                if ($conversation)
-                       $sql_extra .= " AND `item`.`parent` = %d ORDER BY `received` ASC ";
+                       $sql_extra .= " AND `item`.`parent` = %d ORDER BY `id` ASC ";
                else
                        $sql_extra .= " AND `item`.`id` = %d";
 
                $r = q("SELECT `item`.*, `item`.`id` AS `item_id`, `item`.`network` AS `item_network`,
                        `contact`.`name`, `contact`.`photo`, `contact`.`url`, `contact`.`rel`,
                        `contact`.`network`, `contact`.`thumb`, `contact`.`dfrn-id`, `contact`.`self`,
-                       `contact`.`id` AS `cid`, `contact`.`uid` AS `contact-uid`
-                       FROM `item`, `contact`
-                       WHERE `item`.`visible` = 1 and `item`.`moderated` = 0 AND `item`.`deleted` = 0
-                       AND `contact`.`id` = `item`.`contact-id` AND `item`.`uid` = %d AND `item`.`verb` = '%s'
-                       AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
+                       `contact`.`id` AS `cid`
+                       FROM `item`
+                       INNER JOIN `contact` ON `contact`.`id` = `item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
+                               AND NOT `contact`.`blocked`
+                       WHERE `item`.`visible` AND NOT `item`.`moderated` AND NOT `item`.`deleted`
+                       AND `item`.`uid` = %d AND `item`.`verb` = '%s'
                        $sql_extra",
                        intval(api_user()),
                        dbesc(ACTIVITY_POST),
                        intval($id)
                );
 
-               if (!$r)
-                       die(api_error($a, $type, t("There is no status with this id.")));
+               if (!$r) {
+                       throw new BadRequestException("There is no status with this id.");
+               }
 
-               $ret = api_format_items($r,$user_info);
+               $ret = api_format_items($r,$user_info, false, $type);
 
                if ($conversation) {
-                       $data = array('$statuses' => $ret);
-                       return api_apply_template("timeline", $type, $data);
+                       $data = array('status' => $ret);
+                       return api_format_data("statuses", $type, $data);
                } else {
-                       $data = array('$status' => $ret[0]);
-                       /*switch($type){
-                               case "atom":
-                               case "rss":
-                                       $data = api_rss_extra($a, $data, $user_info);
-                       }*/
-                       return  api_apply_template("status", $type, $data);
+                       $data = array('status' => $ret[0]);
+                       return  api_format_data("status", $type, $data);
                }
        }
        api_register_func('api/statuses/show','api_statuses_show', true);
        /**
         *
         */
-       function api_conversation_show(&$a, $type){
-               if (api_user()===false) return false;
+       function api_conversation_show($type){
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
                $user_info = api_get_user($a);
 
                if ($max_id > 0)
                        $sql_extra = ' AND `item`.`id` <= '.intval($max_id);
 
+               // Not sure why this query was so complicated. We should keep it here for a while,
+               // just to make sure that we really don't need it.
+               //      FROM `item` INNER JOIN (SELECT `uri`,`parent` FROM `item` WHERE `id` = %d) AS `temp1`
+               //      ON (`item`.`thr-parent` = `temp1`.`uri` AND `item`.`parent` = `temp1`.`parent`)
+
                $r = q("SELECT `item`.*, `item`.`id` AS `item_id`, `item`.`network` AS `item_network`,
                        `contact`.`name`, `contact`.`photo`, `contact`.`url`, `contact`.`rel`,
                        `contact`.`network`, `contact`.`thumb`, `contact`.`dfrn-id`, `contact`.`self`,
-                       `contact`.`id` AS `cid`, `contact`.`uid` AS `contact-uid`
-                       FROM `item` INNER JOIN (SELECT `uri`,`parent` FROM `item` WHERE `id` = %d) AS `temp1`
-                       ON (`item`.`thr-parent` = `temp1`.`uri` AND `item`.`parent` = `temp1`.`parent`), `contact`
-                       WHERE `item`.`visible` = 1 and `item`.`moderated` = 0 AND `item`.`deleted` = 0
-                       AND `item`.`uid` = %d AND `item`.`verb` = '%s' AND `contact`.`id` = `item`.`contact-id`
-                       AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
+                       `contact`.`id` AS `cid`
+                       FROM `item`
+                       STRAIGHT_JOIN `contact` ON `contact`.`id` = `item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
+                               AND NOT `contact`.`blocked`
+                       WHERE `item`.`parent` = %d AND `item`.`visible`
+                       AND NOT `item`.`moderated` AND NOT `item`.`deleted`
+                       AND `item`.`uid` = %d AND `item`.`verb` = '%s'
                        AND `item`.`id`>%d $sql_extra
                        ORDER BY `item`.`id` DESC LIMIT %d ,%d",
                        intval($id), intval(api_user()),
                );
 
                if (!$r)
-                       die(api_error($a, $type, t("There is no conversation with this id.")));
+                       throw new BadRequestException("There is no conversation with this id.");
 
-               $ret = api_format_items($r,$user_info);
+               $ret = api_format_items($r,$user_info, false, $type);
 
-               $data = array('$statuses' => $ret);
-               return api_apply_template("timeline", $type, $data);
+               $data = array('status' => $ret);
+               return api_format_data("statuses", $type, $data);
        }
        api_register_func('api/conversation/show','api_conversation_show', true);
+       api_register_func('api/statusnet/conversation','api_conversation_show', true);
 
 
        /**
         *
         */
-       function api_statuses_repeat(&$a, $type){
+       function api_statuses_repeat($type){
                global $called_api;
 
-               if (api_user()===false) return false;
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
                $user_info = api_get_user($a);
 
                $r = q("SELECT `item`.*, `item`.`id` AS `item_id`, `item`.`network` AS `item_network`, `contact`.`nick` as `reply_author`,
                        `contact`.`name`, `contact`.`photo` as `reply_photo`, `contact`.`url` as `reply_url`, `contact`.`rel`,
                        `contact`.`network`, `contact`.`thumb`, `contact`.`dfrn-id`, `contact`.`self`,
-                       `contact`.`id` AS `cid`, `contact`.`uid` AS `contact-uid`
-                       FROM `item`, `contact`
-                       WHERE `item`.`visible` = 1 and `item`.`moderated` = 0 AND `item`.`deleted` = 0
-                       AND `contact`.`id` = `item`.`contact-id`
-                       AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
+                       `contact`.`id` AS `cid`
+                       FROM `item`
+                       INNER JOIN `contact` ON `contact`.`id` = `item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
+                               AND NOT `contact`.`blocked`
+                       WHERE `item`.`visible` AND NOT `item`.`moderated` AND NOT `item`.`deleted`
+                       AND NOT `item`.`private` AND `item`.`allow_cid` = '' AND `item`.`allow`.`gid` = ''
+                       AND `item`.`deny_cid` = '' AND `item`.`deny_gid` = ''
                        $sql_extra
                        AND `item`.`id`=%d",
                        intval($id)
                                $_REQUEST["source"] = api_source();
 
                        item_post($a);
-               }
+               } else
+                       throw new ForbiddenException();
 
                // this should output the last post (the one we just posted).
                $called_api = null;
-               return(api_status_show($a,$type));
+               return(api_status_show($type));
        }
-       api_register_func('api/statuses/retweet','api_statuses_repeat', true);
+       api_register_func('api/statuses/retweet','api_statuses_repeat', true, API_METHOD_POST);
 
        /**
         *
         */
-       function api_statuses_destroy(&$a, $type){
-               if (api_user()===false) return false;
+       function api_statuses_destroy($type){
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
                $user_info = api_get_user($a);
 
 
                logger('API: api_statuses_destroy: '.$id);
 
-               $ret = api_statuses_show($a, $type);
+               $ret = api_statuses_show($type);
 
                drop_item($id, false);
 
                return($ret);
        }
-       api_register_func('api/statuses/destroy','api_statuses_destroy', true);
+       api_register_func('api/statuses/destroy','api_statuses_destroy', true, API_METHOD_DELETE);
 
        /**
         *
         * http://developer.twitter.com/doc/get/statuses/mentions
         *
         */
-       function api_statuses_mentions(&$a, $type){
-               if (api_user()===false) return false;
+       function api_statuses_mentions($type){
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
                unset($_REQUEST["user_id"]);
                unset($_GET["user_id"]);
                $start = $page*$count;
 
                // Ugly code - should be changed
-               $myurl = $a->get_baseurl() . '/profile/'. $a->user['nickname'];
+               $myurl = App::get_baseurl() . '/profile/'. $a->user['nickname'];
                $myurl = substr($myurl,strpos($myurl,'://')+3);
                //$myurl = str_replace(array('www.','.'),array('','\\.'),$myurl);
                $myurl = str_replace('www.','',$myurl);
                $r = q("SELECT `item`.*, `item`.`id` AS `item_id`, `item`.`network` AS `item_network`,
                        `contact`.`name`, `contact`.`photo`, `contact`.`url`, `contact`.`rel`,
                        `contact`.`network`, `contact`.`thumb`, `contact`.`dfrn-id`, `contact`.`self`,
-                       `contact`.`id` AS `cid`, `contact`.`uid` AS `contact-uid`
-                       FROM `item`, `contact`
+                       `contact`.`id` AS `cid`
+                       FROM `item` FORCE INDEX (`uid_id`)
+                       STRAIGHT_JOIN `contact` ON `contact`.`id` = `item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
+                               AND NOT `contact`.`blocked`
                        WHERE `item`.`uid` = %d AND `verb` = '%s'
                        AND NOT (`item`.`author-link` IN ('https://%s', 'http://%s'))
-                       AND `item`.`visible` = 1 and `item`.`moderated` = 0 AND `item`.`deleted` = 0
-                       AND `contact`.`id` = `item`.`contact-id`
-                       AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
-                       AND `item`.`parent` IN (SELECT `iid` from thread where uid = %d AND `mention` AND !`ignored`)
+                       AND `item`.`visible` AND NOT `item`.`moderated` AND NOT `item`.`deleted`
+                       AND `item`.`parent` IN (SELECT `iid` FROM `thread` WHERE `uid` = %d AND `mention` AND !`ignored`)
                        $sql_extra
                        AND `item`.`id`>%d
                        ORDER BY `item`.`id` DESC LIMIT %d ,%d ",
                        intval($start), intval($count)
                );
 
-               $ret = api_format_items($r,$user_info);
+               $ret = api_format_items($r,$user_info, false, $type);
 
 
-               $data = array('$statuses' => $ret);
+               $data = array('status' => $ret);
                switch($type){
                        case "atom":
                        case "rss":
                                $data = api_rss_extra($a, $data, $user_info);
                                break;
-                       case "as":
-                               $as = api_format_as($a, $ret, $user_info);
-                               $as["title"] = $a->config['sitename']." Mentions";
-                               $as['link']['url'] = $a->get_baseurl()."/";
-                               return($as);
-                               break;
                }
 
-               return  api_apply_template("timeline", $type, $data);
+               return  api_format_data("statuses", $type, $data);
        }
        api_register_func('api/statuses/mentions','api_statuses_mentions', true);
        api_register_func('api/statuses/replies','api_statuses_mentions', true);
 
 
-       function api_statuses_user_timeline(&$a, $type){
-               if (api_user()===false) return false;
+       function api_statuses_user_timeline($type){
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
                $user_info = api_get_user($a);
                // get last network messages
                $r = q("SELECT `item`.*, `item`.`id` AS `item_id`, `item`.`network` AS `item_network`,
                        `contact`.`name`, `contact`.`photo`, `contact`.`url`, `contact`.`rel`,
                        `contact`.`network`, `contact`.`thumb`, `contact`.`dfrn-id`, `contact`.`self`,
-                       `contact`.`id` AS `cid`, `contact`.`uid` AS `contact-uid`
-                       FROM `item`, `contact`
+                       `contact`.`id` AS `cid`
+                       FROM `item` FORCE INDEX (`uid_contactid_id`)
+                       STRAIGHT_JOIN `contact` ON `contact`.`id` = `item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
+                               AND NOT `contact`.`blocked`
                        WHERE `item`.`uid` = %d AND `verb` = '%s'
                        AND `item`.`contact-id` = %d
-                       AND `item`.`visible` = 1 and `item`.`moderated` = 0 AND `item`.`deleted` = 0
-                       AND `contact`.`id` = `item`.`contact-id`
-                       AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
+                       AND `item`.`visible` AND NOT `item`.`moderated` AND NOT `item`.`deleted`
                        $sql_extra
                        AND `item`.`id`>%d
                        ORDER BY `item`.`id` DESC LIMIT %d ,%d ",
                        intval($start), intval($count)
                );
 
-               $ret = api_format_items($r,$user_info, true);
+               $ret = api_format_items($r,$user_info, true, $type);
 
-               $data = array('$statuses' => $ret);
+               $data = array('status' => $ret);
                switch($type){
                        case "atom":
                        case "rss":
                                $data = api_rss_extra($a, $data, $user_info);
                }
 
-               return  api_apply_template("timeline", $type, $data);
+               return  api_format_data("statuses", $type, $data);
        }
-
        api_register_func('api/statuses/user_timeline','api_statuses_user_timeline', true);
 
 
         *
         * api v1 : https://web.archive.org/web/20131019055350/https://dev.twitter.com/docs/api/1/post/favorites/create/%3Aid
         */
-       function api_favorites_create_destroy(&$a, $type){
-               if (api_user()===false) return false;
+       function api_favorites_create_destroy($type){
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
-               # for versioned api.
-               # TODO: we need a better global soluton
+               // for versioned api.
+               /// @TODO We need a better global soluton
                $action_argv_id=2;
                if ($a->argv[1]=="1.1") $action_argv_id=3;
 
-               if ($a->argc<=$action_argv_id) die(api_error($a, $type, t("Invalid request.")));
+               if ($a->argc<=$action_argv_id) throw new BadRequestException("Invalid request.");
                $action = str_replace(".".$type,"",$a->argv[$action_argv_id]);
                if ($a->argc==$action_argv_id+2) {
                        $itemid = intval($a->argv[$action_argv_id+1]);
                $item = q("SELECT * FROM item WHERE id=%d AND uid=%d",
                                $itemid, api_user());
 
-               if ($item===false || count($item)==0) die(api_error($a, $type, t("Invalid item.")));
+               if ($item===false || count($item)==0)
+                       throw new BadRequestException("Invalid item.");
 
                switch($action){
                        case "create":
                                $item[0]['starred']=0;
                                break;
                        default:
-                               die(api_error($a, $type, t("Invalid action. ".$action)));
+                               throw new BadRequestException("Invalid action ".$action);
                }
                $r = q("UPDATE item SET starred=%d WHERE id=%d AND uid=%d",
                                $item[0]['starred'], $itemid, api_user());
                q("UPDATE thread SET starred=%d WHERE iid=%d AND uid=%d",
                        $item[0]['starred'], $itemid, api_user());
 
-               if ($r===false) die(api_error($a, $type, t("DB error")));
+               if ($r===false)
+                       throw InternalServerErrorException("DB error");
 
 
                $user_info = api_get_user($a);
-               $rets = api_format_items($item,$user_info);
+               $rets = api_format_items($item, $user_info, false, $type);
                $ret = $rets[0];
 
-               $data = array('$status' => $ret);
+               $data = array('status' => $ret);
                switch($type){
                        case "atom":
                        case "rss":
                                $data = api_rss_extra($a, $data, $user_info);
                }
 
-               return api_apply_template("status", $type, $data);
+               return api_format_data("status", $type, $data);
        }
+       api_register_func('api/favorites/create', 'api_favorites_create_destroy', true, API_METHOD_POST);
+       api_register_func('api/favorites/destroy', 'api_favorites_create_destroy', true, API_METHOD_DELETE);
 
-       api_register_func('api/favorites/create', 'api_favorites_create_destroy', true);
-       api_register_func('api/favorites/destroy', 'api_favorites_create_destroy', true);
-
-       function api_favorites(&$a, $type){
+       function api_favorites($type){
                global $called_api;
 
-               if (api_user()===false) return false;
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
                $called_api= array();
 
                        $r = q("SELECT `item`.*, `item`.`id` AS `item_id`, `item`.`network` AS `item_network`,
                                `contact`.`name`, `contact`.`photo`, `contact`.`url`, `contact`.`rel`,
                                `contact`.`network`, `contact`.`thumb`, `contact`.`dfrn-id`, `contact`.`self`,
-                               `contact`.`id` AS `cid`, `contact`.`uid` AS `contact-uid`
+                               `contact`.`id` AS `cid`
                                FROM `item`, `contact`
                                WHERE `item`.`uid` = %d
                                AND `item`.`visible` = 1 and `item`.`moderated` = 0 AND `item`.`deleted` = 0
                                AND `item`.`starred` = 1
                                AND `contact`.`id` = `item`.`contact-id`
-                               AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
+                               AND NOT `contact`.`blocked`
                                $sql_extra
                                AND `item`.`id`>%d
                                ORDER BY `item`.`id` DESC LIMIT %d ,%d ",
                                intval($start), intval($count)
                        );
 
-                       $ret = api_format_items($r,$user_info);
+                       $ret = api_format_items($r,$user_info, false, $type);
 
                }
 
-               $data = array('$statuses' => $ret);
+               $data = array('status' => $ret);
                switch($type){
                        case "atom":
                        case "rss":
                                $data = api_rss_extra($a, $data, $user_info);
                }
 
-               return  api_apply_template("timeline", $type, $data);
+               return  api_format_data("statuses", $type, $data);
        }
-
        api_register_func('api/favorites','api_favorites', true);
 
-
-
-
-       function api_format_as($a, $ret, $user_info) {
-
-               $as = array();
-               $as['title'] = $a->config['sitename']." Public Timeline";
-               $items = array();
-               foreach ($ret as $item) {
-                       $singleitem["actor"]["displayName"] = $item["user"]["name"];
-                       $singleitem["actor"]["id"] = $item["user"]["contact_url"];
-                       $avatar[0]["url"] = $item["user"]["profile_image_url"];
-                       $avatar[0]["rel"] = "avatar";
-                       $avatar[0]["type"] = "";
-                       $avatar[0]["width"] = 96;
-                       $avatar[0]["height"] = 96;
-                       $avatar[1]["url"] = $item["user"]["profile_image_url"];
-                       $avatar[1]["rel"] = "avatar";
-                       $avatar[1]["type"] = "";
-                       $avatar[1]["width"] = 48;
-                       $avatar[1]["height"] = 48;
-                       $avatar[2]["url"] = $item["user"]["profile_image_url"];
-                       $avatar[2]["rel"] = "avatar";
-                       $avatar[2]["type"] = "";
-                       $avatar[2]["width"] = 24;
-                       $avatar[2]["height"] = 24;
-                       $singleitem["actor"]["avatarLinks"] = $avatar;
-
-                       $singleitem["actor"]["image"]["url"] = $item["user"]["profile_image_url"];
-                       $singleitem["actor"]["image"]["rel"] = "avatar";
-                       $singleitem["actor"]["image"]["type"] = "";
-                       $singleitem["actor"]["image"]["width"] = 96;
-                       $singleitem["actor"]["image"]["height"] = 96;
-                       $singleitem["actor"]["type"] = "person";
-                       $singleitem["actor"]["url"] = $item["person"]["contact_url"];
-                       $singleitem["actor"]["statusnet:profile_info"]["local_id"] = $item["user"]["id"];
-                       $singleitem["actor"]["statusnet:profile_info"]["following"] = $item["user"]["following"] ? "true" : "false";
-                       $singleitem["actor"]["statusnet:profile_info"]["blocking"] = "false";
-                       $singleitem["actor"]["contact"]["preferredUsername"] = $item["user"]["screen_name"];
-                       $singleitem["actor"]["contact"]["displayName"] = $item["user"]["name"];
-                       $singleitem["actor"]["contact"]["addresses"] = "";
-
-                       $singleitem["body"] = $item["text"];
-                       $singleitem["object"]["displayName"] = $item["text"];
-                       $singleitem["object"]["id"] = $item["url"];
-                       $singleitem["object"]["type"] = "note";
-                       $singleitem["object"]["url"] = $item["url"];
-                       //$singleitem["context"] =;
-                       $singleitem["postedTime"] = date("c", strtotime($item["published"]));
-                       $singleitem["provider"]["objectType"] = "service";
-                       $singleitem["provider"]["displayName"] = "Test";
-                       $singleitem["provider"]["url"] = "http://test.tld";
-                       $singleitem["title"] = $item["text"];
-                       $singleitem["verb"] = "post";
-                       $singleitem["statusnet:notice_info"]["local_id"] = $item["id"];
-                       $singleitem["statusnet:notice_info"]["source"] = $item["source"];
-                       $singleitem["statusnet:notice_info"]["favorite"] = "false";
-                       $singleitem["statusnet:notice_info"]["repeated"] = "false";
-                       //$singleitem["original"] = $item;
-                       $items[] = $singleitem;
-               }
-               $as['items'] = $items;
-               $as['link']['url'] = $a->get_baseurl()."/".$user_info["screen_name"]."/all";
-               $as['link']['rel'] = "alternate";
-               $as['link']['type'] = "text/html";
-               return($as);
-       }
-
        function api_format_messages($item, $recipient, $sender) {
                // standard meta information
                $ret=Array(
                                'recipient_screen_name' => $recipient['screen_name'],
                                'sender'                => $sender,
                                'recipient'             => $recipient,
+                               'title'                 => "",
+                               'friendica_seen'        => $item['seen'],
+                               'friendica_parent_uri'  => $item['parent-uri'],
                );
 
                // "uid" and "self" are only needed for some internal stuff, so remove it from here
        }
 
        function api_convert_item($item) {
-
                $body = $item['body'];
                $attachments = api_get_attachments($body);
 
 
                $statushtml = trim(bbcode($body, false, false));
 
+               $search = array("<br>", "<blockquote>", "</blockquote>",
+                               "<h1>", "</h1>", "<h2>", "</h2>",
+                               "<h3>", "</h3>", "<h4>", "</h4>",
+                               "<h5>", "</h5>", "<h6>", "</h6>");
+               $replace = array("<br>\n", "\n<blockquote>", "</blockquote>\n",
+                               "\n<h1>", "</h1>\n", "\n<h2>", "</h2>\n",
+                               "\n<h3>", "</h3>\n", "\n<h4>", "</h4>\n",
+                               "\n<h5>", "</h5>\n", "\n<h6>", "</h6>\n");
+               $statushtml = str_replace($search, $replace, $statushtml);
+
                if ($item['title'] != "")
                        $statushtml = "<h4>".bbcode($item['title'])."</h4>\n".$statushtml;
 
                $entities = api_get_entitities($statustext, $body);
 
-               return(array("text" => $statustext, "html" => $statushtml, "attachments" => $attachments, "entities" => $entities));
+               return array(
+                       "text" => $statustext,
+                       "html" => $statushtml,
+                       "attachments" => $attachments,
+                       "entities" => $entities
+               );
        }
 
        function api_get_attachments(&$body) {
 
                return($entities);
        }
-       function api_format_items_embeded_images($item, $text){
-               $a = get_app();
+       function api_format_items_embeded_images(&$item, $text){
                $text = preg_replace_callback(
                                "|data:image/([^;]+)[^=]+=*|m",
-                               function($match) use ($a, $item) {
-                                       return $a->get_baseurl()."/display/".$item['guid'];
+                               function($match) use ($item) {
+                                       return App::get_baseurl()."/display/".$item['guid'];
                                },
                                $text);
                return $text;
        }
 
-       function api_format_items($r,$user_info, $filter_user = false) {
-
-               $a = get_app();
-               $ret = Array();
-
-               foreach($r as $item) {
-                       api_share_as_retweet($item);
 
-                       localize_item($item);
-                       $status_user = api_item_get_user($a,$item);
-
-                       // Look if the posts are matching if they should be filtered by user id
-                       if ($filter_user AND ($status_user["id"] != $user_info["id"]))
-                               continue;
+       /**
+        * @brief return <a href='url'>name</a> as array
+        *
+        * @param string $txt
+        * @return array
+        *                      name => 'name'
+        *                      'url => 'url'
+        */
+       function api_contactlink_to_array($txt) {
+               $match = array();
+               $r = preg_match_all('|<a href="([^"]*)">([^<]*)</a>|', $txt, $match);
+               if ($r && count($match)==3) {
+                       $res = array(
+                               'name' => $match[2],
+                               'url' => $match[1]
+                       );
+               } else {
+                       $res = array(
+                               'name' => $text,
+                               'url' => ""
+                       );
+               }
+               return $res;
+       }
 
-                       if ($item['thr-parent'] != $item['uri']) {
-                               $r = q("SELECT id FROM item WHERE uid=%d AND uri='%s' LIMIT 1",
-                                       intval(api_user()),
-                                       dbesc($item['thr-parent']));
-                               if ($r)
-                                       $in_reply_to_status_id = intval($r[0]['id']);
-                               else
-                                       $in_reply_to_status_id = intval($item['parent']);
 
-                               $in_reply_to_status_id_str = (string) intval($item['parent']);
+       /**
+        * @brief return likes, dislikes and attend status for item
+        *
+        * @param array $item
+        * @return array
+        *                      likes => int count
+        *                      dislikes => int count
+        */
+       function api_format_items_activities(&$item, $type = "json") {
+               $activities = array(
+                       'like' => array(),
+                       'dislike' => array(),
+                       'attendyes' => array(),
+                       'attendno' => array(),
+                       'attendmaybe' => array()
+               );
 
-                               $in_reply_to_screen_name = NULL;
-                               $in_reply_to_user_id = NULL;
-                               $in_reply_to_user_id_str = NULL;
+               $items = q('SELECT * FROM item
+                                       WHERE uid=%d AND `thr-parent`="%s" AND visible AND NOT deleted',
+                                       intval($item['uid']),
+                                       dbesc($item['uri']));
+
+               foreach ($items as $i){
+                       // not used as result should be structured like other user data
+                       //builtin_activity_puller($i, $activities);
+
+                       // get user data and add it to the array of the activity
+                       $user = api_get_user($a, $i['author-link']);
+                       switch($i['verb']) {
+                               case ACTIVITY_LIKE:
+                                       $activities['like'][] = $user;
+                                       break;
+                               case ACTIVITY_DISLIKE:
+                                       $activities['dislike'][] = $user;
+                                       break;
+                               case ACTIVITY_ATTEND:
+                                       $activities['attendyes'][] = $user;
+                                       break;
+                               case ACTIVITY_ATTENDNO:
+                                       $activities['attendno'][] = $user;
+                                       break;
+                               case ACTIVITY_ATTENDMAYBE:
+                                       $activities['attendmaybe'][] = $user;
+                                       break;
+                               default:
+                                       break;
+                       }
+               }
 
-                               $r = q("SELECT `author-link` FROM item WHERE uid=%d AND id=%d LIMIT 1",
-                                       intval(api_user()),
-                                       intval($in_reply_to_status_id));
-                               if ($r) {
-                                       $r = q("SELECT * FROM `unique_contacts` WHERE `url` = '%s'", dbesc(normalise_link($r[0]['author-link'])));
+               if ($type == "xml") {
+                       $xml_activities = array();
+                       foreach ($activities as $k => $v) {
+                               // change xml element from "like" to "friendica:like"
+                               $xml_activities["friendica:".$k] = $v;
+                               // add user data into xml output
+                               $k_user = 0;
+                               foreach ($v as $user)
+                                       $xml_activities["friendica:".$k][$k_user++.":user"] = $user;
+                       }
+                       $activities = $xml_activities;
+               }
 
-                                       if ($r) {
-                                               if ($r[0]['nick'] == "")
-                                                       $r[0]['nick'] = api_get_nick($r[0]["url"]);
+               return $activities;
 
-                                               $in_reply_to_screen_name = (($r[0]['nick']) ? $r[0]['nick'] : $r[0]['name']);
-                                               $in_reply_to_user_id = intval($r[0]['id']);
-                                               $in_reply_to_user_id_str = (string) intval($r[0]['id']);
-                                       }
-                               }
-                       } else {
-                               $in_reply_to_screen_name = NULL;
-                               $in_reply_to_user_id = NULL;
-                               $in_reply_to_status_id = NULL;
-                               $in_reply_to_user_id_str = NULL;
-                               $in_reply_to_status_id_str = NULL;
-                       }
+       }
+
+
+       /**
+        * @brief return data from profiles
+        *
+        * @param array $profile array containing data from db table 'profile'
+        * @param string $type Known types are 'atom', 'rss', 'xml' and 'json'
+        * @return array
+        */
+       function api_format_items_profiles(&$profile = null, $type = "json") {
+               if ($profile != null) {
+                       $profile = array('profile_id' => $profile['id'],
+                                                       'profile_name' => $profile['profile-name'],
+                                                       'is_default' => $profile['is-default'] ? true : false,
+                                                       'hide_friends'=> $profile['hide-friends'] ? true : false,
+                                                       'profile_photo' => $profile['photo'],
+                                                       'profile_thumb' => $profile['thumb'],
+                                                       'publish' => $profile['publish'] ? true : false,
+                                                       'net_publish' => $profile['net-publish'] ? true : false,
+                                                       'description' => $profile['pdesc'],
+                                                       'date_of_birth' => $profile['dob'],
+                                                       'address' => $profile['address'],
+                                                       'city' => $profile['locality'],
+                                                       'region' => $profile['region'],
+                                                       'postal_code' => $profile['postal-code'],
+                                                       'country' => $profile['country-name'],
+                                                       'hometown' => $profile['hometown'],
+                                                       'gender' => $profile['gender'],
+                                                       'marital' => $profile['marital'],
+                                                       'marital_with' => $profile['with'],
+                                                       'marital_since' => $profile['howlong'],
+                                                       'sexual' => $profile['sexual'],
+                                                       'politic' => $profile['politic'],
+                                                       'religion' => $profile['religion'],
+                                                       'public_keywords' => $profile['pub_keywords'],
+                                                       'private_keywords' => $profile['prv_keywords'],
+                                                       'likes' => bbcode(api_clean_plain_items($profile['likes']), false, false, 2, false),
+                                                       'dislikes' => bbcode(api_clean_plain_items($profile['dislikes']), false, false, 2, false),
+                                                       'about' => bbcode(api_clean_plain_items($profile['about']), false, false, 2, false),
+                                                       'music' => bbcode(api_clean_plain_items($profile['music']), false, false, 2, false),
+                                                       'book' => bbcode(api_clean_plain_items($profile['book']), false, false, 2, false),
+                                                       'tv' => bbcode(api_clean_plain_items($profile['tv']), false, false, 2, false),
+                                                       'film' => bbcode(api_clean_plain_items($profile['film']), false, false, 2, false),
+                                                       'interest' => bbcode(api_clean_plain_items($profile['interest']), false, false, 2, false),
+                                                       'romance' => bbcode(api_clean_plain_items($profile['romance']), false, false, 2, false),
+                                                       'work' => bbcode(api_clean_plain_items($profile['work']), false, false, 2, false),
+                                                       'education' => bbcode(api_clean_plain_items($profile['education']), false, false, 2, false),
+                                                       'social_networks' => bbcode(api_clean_plain_items($profile['contact']), false, false, 2, false),
+                                                       'homepage' => $profile['homepage'],
+                                                       'users' => null);
+                       return $profile;
+               } 
+       }
+
+       /**
+        * @brief format items to be returned by api
+        *
+        * @param array $r array of items
+        * @param array $user_info
+        * @param bool $filter_user filter items by $user_info
+        */
+       function api_format_items($r,$user_info, $filter_user = false, $type = "json") {
+
+               $a = get_app();
+
+               $ret = Array();
+
+               foreach($r as $item) {
+
+                       localize_item($item);
+                       list($status_user, $owner_user) = api_item_get_user($a,$item);
+
+                       // Look if the posts are matching if they should be filtered by user id
+                       if ($filter_user AND ($status_user["id"] != $user_info["id"]))
+                               continue;
+
+                       $in_reply_to = api_in_reply_to($item);
 
                        $converted = api_convert_item($item);
 
+                       if ($type == "xml")
+                               $geo = "georss:point";
+                       else
+                               $geo = "geo";
+
                        $status = array(
                                'text'          => $converted["text"],
                                'truncated' => False,
                                'created_at'=> api_date($item['created']),
-                               'in_reply_to_status_id' => $in_reply_to_status_id,
-                               'in_reply_to_status_id_str' => $in_reply_to_status_id_str,
+                               'in_reply_to_status_id' => $in_reply_to['status_id'],
+                               'in_reply_to_status_id_str' => $in_reply_to['status_id_str'],
                                'source'    => (($item['app']) ? $item['app'] : 'web'),
                                'id'            => intval($item['id']),
                                'id_str'        => (string) intval($item['id']),
-                               'in_reply_to_user_id' => $in_reply_to_user_id,
-                               'in_reply_to_user_id_str' => $in_reply_to_user_id_str,
-                               'in_reply_to_screen_name' => $in_reply_to_screen_name,
-                               'geo' => NULL,
+                               'in_reply_to_user_id' => $in_reply_to['user_id'],
+                               'in_reply_to_user_id_str' => $in_reply_to['user_id_str'],
+                               'in_reply_to_screen_name' => $in_reply_to['screen_name'],
+                               $geo => NULL,
                                'favorited' => $item['starred'] ? true : false,
                                'user' =>  $status_user ,
+                               'friendica_owner' => $owner_user,
                                //'entities' => NULL,
                                'statusnet_html'                => $converted["html"],
                                'statusnet_conversation_id'     => $item['parent'],
+                               'friendica_activities' => api_format_items_activities($item, $type),
                        );
 
                        if (count($converted["attachments"]) > 0)
 
                        // Retweets are only valid for top postings
                        // It doesn't work reliable with the link if its a feed
-                       $IsRetweet = ($item['owner-link'] != $item['author-link']);
-                       if ($IsRetweet)
-                               $IsRetweet = (($item['owner-name'] != $item['author-name']) OR ($item['owner-avatar'] != $item['author-avatar']));
+                       #$IsRetweet = ($item['owner-link'] != $item['author-link']);
+                       #if ($IsRetweet)
+                       #       $IsRetweet = (($item['owner-name'] != $item['author-name']) OR ($item['owner-avatar'] != $item['author-avatar']));
+
+
+                       if ($item["id"] == $item["parent"]) {
+                               $retweeted_item = api_share_as_retweet($item);
+                               if ($retweeted_item !== false) {
+                                       $retweeted_status = $status;
+                                       try {
+                                               $retweeted_status["user"] = api_get_user($a,$retweeted_item["author-link"]);
+                                       } catch( BadRequestException $e ) {
+                                               // user not found. should be found?
+                                               /// @todo check if the user should be always found
+                                               $retweeted_status["user"] = array();
+                                       }
 
-                       if ($IsRetweet AND ($item["id"] == $item["parent"])) {
-                               $retweeted_status = $status;
-                               $retweeted_status["user"] = api_get_user($a,$item["author-link"]);
+                                       $rt_converted = api_convert_item($retweeted_item);
 
-                               $status["retweeted_status"] = $retweeted_status;
+                                       $retweeted_status['text'] = $rt_converted["text"];
+                                       $retweeted_status['statusnet_html'] = $rt_converted["html"];
+                                       $retweeted_status['friendica_activities'] = api_format_items_activities($retweeted_item, $type);
+                                       $retweeted_status['created_at'] =  api_date($retweeted_item['created']);
+                                       $status['retweeted_status'] = $retweeted_status;
+                               }
                        }
 
                        // "uid" and "self" are only needed for some internal stuff, so remove it from here
                        if ($item["coord"] != "") {
                                $coords = explode(' ',$item["coord"]);
                                if (count($coords) == 2) {
-                                       $status["geo"] = array('type' => 'Point',
-                                                       'coordinates' => array((float) $coords[0],
-                                                                               (float) $coords[1]));
+                                       if ($type == "json")
+                                               $status["geo"] = array('type' => 'Point',
+                                                               'coordinates' => array((float) $coords[0],
+                                                                                       (float) $coords[1]));
+                                       else // Not sure if this is the official format - if someone founds a documentation we can check
+                                               $status["georss:point"] = $item["coord"];
                                }
                        }
-
                        $ret[] = $status;
                };
                return $ret;
        }
 
 
-       function api_account_rate_limit_status(&$a,$type) {
+       function api_account_rate_limit_status($type) {
 
-               $hash = array(
-                         'reset_time_in_seconds' => strtotime('now + 1 hour'),
-                         'remaining_hits' => (string) 150,
-                         'hourly_limit' => (string) 150,
-                         'reset_time' => api_date(datetime_convert('UTC','UTC','now + 1 hour',ATOM_TIME)),
-               );
                if ($type == "xml")
-                       $hash['resettime_in_seconds'] = $hash['reset_time_in_seconds'];
-
-               return api_apply_template('ratelimit', $type, array('$hash' => $hash));
+                       $hash = array(
+                                       'remaining-hits' => (string) 150,
+                                       '@attributes' => array("type" => "integer"),
+                                       'hourly-limit' => (string) 150,
+                                       '@attributes2' => array("type" => "integer"),
+                                       'reset-time' => datetime_convert('UTC','UTC','now + 1 hour',ATOM_TIME),
+                                       '@attributes3' => array("type" => "datetime"),
+                                       'reset_time_in_seconds' => strtotime('now + 1 hour'),
+                                       '@attributes4' => array("type" => "integer"),
+                               );
+               else
+                       $hash = array(
+                                       'reset_time_in_seconds' => strtotime('now + 1 hour'),
+                                       'remaining_hits' => (string) 150,
+                                       'hourly_limit' => (string) 150,
+                                       'reset_time' => api_date(datetime_convert('UTC','UTC','now + 1 hour',ATOM_TIME)),
+                               );
 
+               return api_format_data('hash', $type, array('hash' => $hash));
        }
        api_register_func('api/account/rate_limit_status','api_account_rate_limit_status',true);
 
-       function api_help_test(&$a,$type) {
-
+       function api_help_test($type) {
                if ($type == 'xml')
                        $ok = "true";
                else
                        $ok = "ok";
 
-               return api_apply_template('test', $type, array("$ok" => $ok));
-
+               return api_format_data('ok', $type, array("ok" => $ok));
        }
        api_register_func('api/help/test','api_help_test',false);
 
-       function api_lists(&$a,$type) {
-
+       function api_lists($type) {
                $ret = array();
-               return array($ret);
+               return api_format_data('lists', $type, array("lists_list" => $ret));
        }
        api_register_func('api/lists','api_lists',true);
 
-       function api_lists_list(&$a,$type) {
-
+       function api_lists_list($type) {
                $ret = array();
-               return array($ret);
+               return api_format_data('lists', $type, array("lists_list" => $ret));
        }
        api_register_func('api/lists/list','api_lists_list',true);
 
         *  This function is deprecated by Twitter
         *  returns: json, xml
         **/
-       function api_statuses_f(&$a, $type, $qtype) {
-               if (api_user()===false) return false;
+       function api_statuses_f($type, $qtype) {
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
                $user_info = api_get_user($a);
 
                if (x($_GET,'cursor') && $_GET['cursor']=='undefined'){
                if ($user_info['self'] == 0)
                        $sql_extra = " AND false ";
 
-               $r = q("SELECT `nurl` FROM `contact` WHERE `uid` = %d AND `self` = 0 AND `blocked` = 0 AND `pending` = 0 $sql_extra",
+               $r = q("SELECT `nurl` FROM `contact` WHERE `uid` = %d AND NOT `self` AND NOT `blocked` $sql_extra",
                        intval(api_user())
                );
 
                                $ret[] = $user;
                }
 
-               return array('$users' => $ret);
+               return array('user' => $ret);
 
        }
-       function api_statuses_friends(&$a, $type){
-               $data =  api_statuses_f($a,$type,"friends");
+       function api_statuses_friends($type){
+               $data =  api_statuses_f($type, "friends");
                if ($data===false) return false;
-               return  api_apply_template("friends", $type, $data);
+               return  api_format_data("users", $type, $data);
        }
-       function api_statuses_followers(&$a, $type){
-               $data = api_statuses_f($a,$type,"followers");
+       function api_statuses_followers($type){
+               $data = api_statuses_f($type, "followers");
                if ($data===false) return false;
-               return  api_apply_template("friends", $type, $data);
+               return  api_format_data("users", $type, $data);
        }
        api_register_func('api/statuses/friends','api_statuses_friends',true);
        api_register_func('api/statuses/followers','api_statuses_followers',true);
 
 
 
-       function api_statusnet_config(&$a,$type) {
+       function api_statusnet_config($type) {
+
+               $a = get_app();
+
                $name = $a->config['sitename'];
                $server = $a->get_hostname();
-               $logo = $a->get_baseurl() . '/images/friendica-64.png';
+               $logo = App::get_baseurl() . '/images/friendica-64.png';
                $email = $a->config['admin_email'];
                $closed = (($a->config['register_policy'] == REGISTER_CLOSED) ? 'true' : 'false');
                $private = (($a->config['system']['block_public']) ? 'true' : 'false');
                if($a->config['api_import_size'])
                        $texlimit = string($a->config['api_import_size']);
                $ssl = (($a->config['system']['have_ssl']) ? 'true' : 'false');
-               $sslserver = (($ssl === 'true') ? str_replace('http:','https:',$a->get_baseurl()) : '');
+               $sslserver = (($ssl === 'true') ? str_replace('http:','https:',App::get_baseurl()) : '');
 
                $config = array(
                        'site' => array('name' => $name,'server' => $server, 'theme' => 'default', 'path' => '',
                        ),
                );
 
-               return api_apply_template('config', $type, array('$config' => $config));
+               return api_format_data('config', $type, array('config' => $config));
 
        }
        api_register_func('api/statusnet/config','api_statusnet_config',false);
 
-       function api_statusnet_version(&$a,$type) {
-
+       function api_statusnet_version($type) {
                // liar
+               $fake_statusnet_version = "0.9.7";
 
-               if($type === 'xml') {
-                       header("Content-type: application/xml");
-                       echo '<?xml version="1.0" encoding="UTF-8"?>' . "\r\n" . '<version>0.9.7</version>' . "\r\n";
-                       killme();
-               }
-               elseif($type === 'json') {
-                       header("Content-type: application/json");
-                       echo '"0.9.7"';
-                       killme();
-               }
+               return api_format_data('version', $type, array('version' => $fake_statusnet_version));
        }
        api_register_func('api/statusnet/version','api_statusnet_version',false);
 
+       /**
+        * @todo use api_format_data() to return data
+        */
+       function api_ff_ids($type,$qtype) {
 
-       function api_ff_ids(&$a,$type,$qtype) {
-               if(! api_user())
-                       return false;
+               $a = get_app();
+
+               if(! api_user()) throw new ForbiddenException();
 
                $user_info = api_get_user($a);
 
 
                $stringify_ids = (x($_REQUEST,'stringify_ids')?$_REQUEST['stringify_ids']:false);
 
-               $r = q("SELECT `unique_contact`.`id` FROM contact, `unique_contacts` WHERE contact.nurl = unique_contacts.url AND `uid` = %d AND `self` = 0 AND `blocked` = 0 AND `pending` = 0 $sql_extra",
+               $r = q("SELECT `pcontact`.`id` FROM `contact`
+                               INNER JOIN `contact` AS `pcontact` ON `contact`.`nurl` = `pcontact`.`nurl` AND `pcontact`.`uid` = 0
+                               WHERE `contact`.`uid` = %s AND NOT `contact`.`self`",
                        intval(api_user())
                );
 
-               if(is_array($r)) {
+               if(!dbm::is_result($r))
+                       return;
 
-                       if($type === 'xml') {
-                               header("Content-type: application/xml");
-                               echo '<?xml version="1.0" encoding="UTF-8"?>' . "\r\n" . '<ids>' . "\r\n";
-                               foreach($r as $rr)
-                                       echo '<id>' . $rr['id'] . '</id>' . "\r\n";
-                               echo '</ids>' . "\r\n";
-                               killme();
-                       }
-                       elseif($type === 'json') {
-                               $ret = array();
-                               header("Content-type: application/json");
-                               foreach($r as $rr)
-                                       if ($stringify_ids)
-                                               $ret[] = $rr['id'];
-                                       else
-                                               $ret[] = intval($rr['id']);
+               $ids = array();
+               foreach($r as $rr)
+                       if ($stringify_ids)
+                               $ids[] = $rr['id'];
+                       else
+                               $ids[] = intval($rr['id']);
 
-                               echo json_encode($ret);
-                               killme();
-                       }
-               }
+               return api_format_data("ids", $type, array('id' => $ids));
        }
 
-       function api_friends_ids(&$a,$type) {
-               api_ff_ids($a,$type,'friends');
+       function api_friends_ids($type) {
+               return api_ff_ids($type,'friends');
        }
-       function api_followers_ids(&$a,$type) {
-               api_ff_ids($a,$type,'followers');
+       function api_followers_ids($type) {
+               return api_ff_ids($type,'followers');
        }
        api_register_func('api/friends/ids','api_friends_ids',true);
        api_register_func('api/followers/ids','api_followers_ids',true);
 
 
-       function api_direct_messages_new(&$a, $type) {
-               if (api_user()===false) return false;
+       function api_direct_messages_new($type) {
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
                if (!x($_POST, "text") OR (!x($_POST,"screen_name") AND !x($_POST,"user_id"))) return;
 
                        $ret = array("error"=>$id);
                }
 
-               $data = Array('$messages'=>$ret);
+               $data = Array('direct_message'=>$ret);
 
                switch($type){
                        case "atom":
                                $data = api_rss_extra($a, $data, $user_info);
                }
 
-               return  api_apply_template("direct_messages", $type, $data);
+               return  api_format_data("direct-messages", $type, $data);
 
        }
-       api_register_func('api/direct_messages/new','api_direct_messages_new',true);
+       api_register_func('api/direct_messages/new','api_direct_messages_new',true, API_METHOD_POST);
 
-       function api_direct_messages_box(&$a, $type, $box) {
-               if (api_user()===false) return false;
 
+       /**
+        * @brief delete a direct_message from mail table through api
+        *
+        * @param string $type Known types are 'atom', 'rss', 'xml' and 'json'
+        * @return string
+        */
+       function api_direct_messages_destroy($type){
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
+
+               // params
+               $user_info = api_get_user($a);
+               //required
+               $id = (x($_REQUEST,'id') ? $_REQUEST['id'] : 0);
+               // optional
+               $parenturi = (x($_REQUEST, 'friendica_parenturi') ? $_REQUEST['friendica_parenturi'] : "");
+               $verbose = (x($_GET,'friendica_verbose')?strtolower($_GET['friendica_verbose']):"false");
+               /// @todo optional parameter 'include_entities' from Twitter API not yet implemented
+
+               $uid = $user_info['uid'];
+               // error if no id or parenturi specified (for clients posting parent-uri as well)
+               if ($verbose == "true") {
+                       if ($id == 0 || $parenturi == "") {
+                               $answer = array('result' => 'error', 'message' => 'message id or parenturi not specified');
+                               return api_format_data("direct_messages_delete", $type, array('$result' => $answer));
+                       }
+               }
+
+               // BadRequestException if no id specified (for clients using Twitter API)
+               if ($id == 0) throw new BadRequestException('Message id not specified');
+
+               // add parent-uri to sql command if specified by calling app            
+               $sql_extra = ($parenturi != "" ? " AND `parent-uri` = '" . dbesc($parenturi) . "'" : "");
+
+               // get data of the specified message id
+               $r = q("SELECT `id` FROM `mail` WHERE `uid` = %d AND `id` = %d" . $sql_extra,
+                       intval($uid), 
+                       intval($id));
+       
+               // error message if specified id is not in database
+               if (!dbm::is_result($r)) {
+                       if ($verbose == "true") {
+                               $answer = array('result' => 'error', 'message' => 'message id not in database');
+                               return api_format_data("direct_messages_delete", $type, array('$result' => $answer));
+                       }
+                       /// @todo BadRequestException ok for Twitter API clients?
+                       throw new BadRequestException('message id not in database');
+               }
+
+               // delete message
+               $result = q("DELETE FROM `mail` WHERE `uid` = %d AND `id` = %d" . $sql_extra, 
+                       intval($uid), 
+                       intval($id));
+
+               if ($verbose == "true") {
+                       if ($result) {
+                               // return success
+                               $answer = array('result' => 'ok', 'message' => 'message deleted');
+                               return api_format_data("direct_message_delete", $type, array('$result' => $answer));
+                       }
+                       else {
+                               $answer = array('result' => 'error', 'message' => 'unknown error');
+                               return api_format_data("direct_messages_delete", $type, array('$result' => $answer));
+                       }
+               }
+               /// @todo return JSON data like Twitter API not yet implemented
+
+       }
+       api_register_func('api/direct_messages/destroy', 'api_direct_messages_destroy', true, API_METHOD_DELETE);
+
+
+       function api_direct_messages_box($type, $box, $verbose) {
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
                // params
                $count = (x($_GET,'count')?$_GET['count']:20);
                unset($_GET["screen_name"]);
 
                $user_info = api_get_user($a);
-               //$profile_url = $a->get_baseurl() . '/profile/' . $a->user['nickname'];
                $profile_url = $user_info["url"];
 
 
                                intval($since_id),
                                intval($start), intval($count)
                );
-
+               if ($verbose == "true") {
+                       // stop execution and return error message if no mails available
+                       if($r == null) {
+                               $answer = array('result' => 'error', 'message' => 'no mails available');
+                               return api_format_data("direct_messages_all", $type, array('$result' => $answer));
+                       }
+               }
 
                $ret = Array();
                foreach($r as $item) {
                }
 
 
-               $data = array('$messages' => $ret);
+               $data = array('direct_message' => $ret);
                switch($type){
                        case "atom":
                        case "rss":
                                $data = api_rss_extra($a, $data, $user_info);
                }
 
-               return  api_apply_template("direct_messages", $type, $data);
+               return  api_format_data("direct-messages", $type, $data);
 
        }
 
-       function api_direct_messages_sentbox(&$a, $type){
-               return api_direct_messages_box($a, $type, "sentbox");
+       function api_direct_messages_sentbox($type){
+               $verbose = (x($_GET,'friendica_verbose')?strtolower($_GET['friendica_verbose']):"false");
+               return api_direct_messages_box($type, "sentbox", $verbose);
        }
-       function api_direct_messages_inbox(&$a, $type){
-               return api_direct_messages_box($a, $type, "inbox");
+       function api_direct_messages_inbox($type){
+               $verbose = (x($_GET,'friendica_verbose')?strtolower($_GET['friendica_verbose']):"false");
+               return api_direct_messages_box($type, "inbox", $verbose);
        }
-       function api_direct_messages_all(&$a, $type){
-               return api_direct_messages_box($a, $type, "all");
+       function api_direct_messages_all($type){
+               $verbose = (x($_GET,'friendica_verbose')?strtolower($_GET['friendica_verbose']):"false");
+               return api_direct_messages_box($type, "all", $verbose);
        }
-       function api_direct_messages_conversation(&$a, $type){
-               return api_direct_messages_box($a, $type, "conversation");
+       function api_direct_messages_conversation($type){
+               $verbose = (x($_GET,'friendica_verbose')?strtolower($_GET['friendica_verbose']):"false");
+               return api_direct_messages_box($type, "conversation", $verbose);
        }
        api_register_func('api/direct_messages/conversation','api_direct_messages_conversation',true);
        api_register_func('api/direct_messages/all','api_direct_messages_all',true);
 
 
 
-       function api_oauth_request_token(&$a, $type){
+       function api_oauth_request_token($type){
                try{
                        $oauth = new FKOAuth1();
                        $r = $oauth->fetch_request_token(OAuthRequest::from_request());
                echo $r;
                killme();
        }
-       function api_oauth_access_token(&$a, $type){
+       function api_oauth_access_token($type){
                try{
                        $oauth = new FKOAuth1();
                        $r = $oauth->fetch_access_token(OAuthRequest::from_request());
        api_register_func('api/oauth/access_token', 'api_oauth_access_token', false);
 
 
-       function api_fr_photos_list(&$a,$type) {
-               if (api_user()===false) return false;
-               $r = q("select distinct `resource-id` from photo where uid = %d and album != 'Contact Photos' ",
+       function api_fr_photos_list($type) {
+               if (api_user()===false) throw new ForbiddenException();
+               $r = q("select `resource-id`, max(scale) as scale, album, filename, type from photo
+                               where uid = %d and album != 'Contact Photos' group by `resource-id`",
                        intval(local_user())
                );
+               $typetoext = array(
+               'image/jpeg' => 'jpg',
+               'image/png' => 'png',
+               'image/gif' => 'gif'
+               );
+               $data = array('photo'=>array());
                if($r) {
-                       $ret = array();
-                       foreach($r as $rr)
-                               $ret[] = $rr['resource-id'];
-                       header("Content-type: application/json");
-                       echo json_encode($ret);
+                       foreach($r as $rr) {
+                               $photo = array();
+                               $photo['id'] = $rr['resource-id'];
+                               $photo['album'] = $rr['album'];
+                               $photo['filename'] = $rr['filename'];
+                               $photo['type'] = $rr['type'];
+                               $thumb = App::get_baseurl()."/photo/".$rr['resource-id']."-".$rr['scale'].".".$typetoext[$rr['type']];
+
+                               if ($type == "xml")
+                                       $data['photo'][] = array("@attributes" => $photo, "1" => $thumb);
+                               else {
+                                       $photo['thumb'] = $thumb;
+                                       $data['photo'][] = $photo;
+                               }
+                       }
                }
-               killme();
+               return  api_format_data("photos", $type, $data);
        }
 
-       function api_fr_photo_detail(&$a,$type) {
-               if (api_user()===false) return false;
-               if(! $_REQUEST['photo_id']) return false;
-               $scale = ((array_key_exists('scale',$_REQUEST)) ? intval($_REQUEST['scale']) : 0);
-               $r = q("select * from photo where uid = %d and `resource-id` = '%s' and scale = %d limit 1",
+       function api_fr_photo_detail($type) {
+               if (api_user()===false) throw new ForbiddenException();
+               if(!x($_REQUEST,'photo_id')) throw new BadRequestException("No photo id.");
+
+               $scale = (x($_REQUEST, 'scale') ? intval($_REQUEST['scale']) : false);
+               $scale_sql = ($scale === false ? "" : sprintf("and scale=%d",intval($scale)));
+               $data_sql = ($scale === false ? "" : "data, ");
+
+               $r = q("select %s `resource-id`, `created`, `edited`, `title`, `desc`, `album`, `filename`,
+                                               `type`, `height`, `width`, `datasize`, `profile`, min(`scale`) as minscale, max(`scale`) as maxscale
+                               from photo where `uid` = %d and `resource-id` = '%s' %s group by `resource-id`",
+                       $data_sql,
                        intval(local_user()),
                        dbesc($_REQUEST['photo_id']),
-                       intval($scale)
+                       $scale_sql
                );
-               if($r) {
-                       header("Content-type: application/json");
-                       $r[0]['data'] = base64_encode($r[0]['data']);
-                       echo json_encode($r[0]);
+
+               $typetoext = array(
+               'image/jpeg' => 'jpg',
+               'image/png' => 'png',
+               'image/gif' => 'gif'
+               );
+
+               if ($r) {
+                       $data = array('photo' => $r[0]);
+                       $data['photo']['id'] = $data['photo']['resource-id'];
+                       if ($scale !== false) {
+                               $data['photo']['data'] = base64_encode($data['photo']['data']);
+                       } else {
+                               unset($data['photo']['datasize']); //needed only with scale param
+                       }
+                       if ($type == "xml") {
+                               $data['photo']['links'] = array();
+                               for ($k=intval($data['photo']['minscale']); $k<=intval($data['photo']['maxscale']); $k++)
+                                       $data['photo']['links'][$k.":link"]["@attributes"] = array("type" => $data['photo']['type'],
+                                                                                       "scale" => $k,
+                                                                                       "href" => App::get_baseurl()."/photo/".$data['photo']['resource-id']."-".$k.".".$typetoext[$data['photo']['type']]);
+                       } else {
+                               $data['photo']['link'] = array();
+                               for ($k=intval($data['photo']['minscale']); $k<=intval($data['photo']['maxscale']); $k++) {
+                                       $data['photo']['link'][$k] = App::get_baseurl()."/photo/".$data['photo']['resource-id']."-".$k.".".$typetoext[$data['photo']['type']];
+                               }
+                       }
+                       unset($data['photo']['resource-id']);
+                       unset($data['photo']['minscale']);
+                       unset($data['photo']['maxscale']);
+
+               } else {
+                       throw new NotFoundException();
                }
 
-               killme();
+               return api_format_data("photo_detail", $type, $data);
        }
 
        api_register_func('api/friendica/photos/list', 'api_fr_photos_list', true);
         *              c_url: url of remote contact to auth to
         *              url: string, url to redirect after auth
         */
-       function api_friendica_remoteauth(&$a) {
+       function api_friendica_remoteauth() {
                $url = ((x($_GET,'url')) ? $_GET['url'] : '');
                $c_url = ((x($_GET,'c_url')) ? $_GET['c_url'] : '');
 
                if ($url === '' || $c_url === '')
-                       die((api_error($a, 'json', "Wrong parameters")));
+                       throw new BadRequestException("Wrong parameters.");
 
                $c_url = normalise_link($c_url);
 
                );
 
                if ((! count($r)) || ($r[0]['network'] !== NETWORK_DFRN))
-                       die((api_error($a, 'json', "Unknown contact")));
+                       throw new BadRequestException("Unknown contact");
 
                $cid = $r[0]['id'];
 
        }
        api_register_func('api/friendica/remoteauth', 'api_friendica_remoteauth', true);
 
+       /**
+        * @brief Return the item shared, if the item contains only the [share] tag
+        *
+        * @param array $item Sharer item
+        * @return array Shared item or false if not a reshare
+        */
+       function api_share_as_retweet(&$item) {
+               $body = trim($item["body"]);
 
+               if (diaspora::is_reshare($body, false)===false) {
+                       return false;
+               }
 
-function api_share_as_retweet(&$item) {
-       $body = trim($item["body"]);
+               $attributes = preg_replace("/\[share(.*?)\]\s?(.*?)\s?\[\/share\]\s?/ism","$1",$body);
+               // Skip if there is no shared message in there
+               // we already checked this in diaspora::is_reshare()
+               // but better one more than one less...
+               if ($body == $attributes)
+                       return false;
 
-       // Skip if it isn't a pure repeated messages
-       // Does it start with a share?
-       if (strpos($body, "[share") > 0)
-               return(false);
 
-       // Does it end with a share?
-       if (strlen($body) > (strrpos($body, "[/share]") + 8))
-               return(false);
+               // build the fake reshared item
+               $reshared_item = $item;
 
-       $attributes = preg_replace("/\[share(.*?)\]\s?(.*?)\s?\[\/share\]\s?/ism","$1",$body);
-       // Skip if there is no shared message in there
-       if ($body == $attributes)
-               return(false);
+               $author = "";
+               preg_match("/author='(.*?)'/ism", $attributes, $matches);
+               if ($matches[1] != "")
+                       $author = html_entity_decode($matches[1],ENT_QUOTES,'UTF-8');
 
-       $author = "";
-       preg_match("/author='(.*?)'/ism", $attributes, $matches);
-       if ($matches[1] != "")
-               $author = html_entity_decode($matches[1],ENT_QUOTES,'UTF-8');
+               preg_match('/author="(.*?)"/ism', $attributes, $matches);
+               if ($matches[1] != "")
+                       $author = $matches[1];
 
-       preg_match('/author="(.*?)"/ism', $attributes, $matches);
-       if ($matches[1] != "")
-               $author = $matches[1];
+               $profile = "";
+               preg_match("/profile='(.*?)'/ism", $attributes, $matches);
+               if ($matches[1] != "")
+                       $profile = $matches[1];
 
-       $profile = "";
-       preg_match("/profile='(.*?)'/ism", $attributes, $matches);
-       if ($matches[1] != "")
-               $profile = $matches[1];
+               preg_match('/profile="(.*?)"/ism', $attributes, $matches);
+               if ($matches[1] != "")
+                       $profile = $matches[1];
 
-       preg_match('/profile="(.*?)"/ism', $attributes, $matches);
-       if ($matches[1] != "")
-               $profile = $matches[1];
+               $avatar = "";
+               preg_match("/avatar='(.*?)'/ism", $attributes, $matches);
+               if ($matches[1] != "")
+                       $avatar = $matches[1];
 
-       $avatar = "";
-       preg_match("/avatar='(.*?)'/ism", $attributes, $matches);
-       if ($matches[1] != "")
-               $avatar = $matches[1];
+               preg_match('/avatar="(.*?)"/ism', $attributes, $matches);
+               if ($matches[1] != "")
+                       $avatar = $matches[1];
 
-       preg_match('/avatar="(.*?)"/ism', $attributes, $matches);
-       if ($matches[1] != "")
-               $avatar = $matches[1];
+               $link = "";
+               preg_match("/link='(.*?)'/ism", $attributes, $matches);
+               if ($matches[1] != "")
+                       $link = $matches[1];
 
-       $link = "";
-       preg_match("/link='(.*?)'/ism", $attributes, $matches);
-       if ($matches[1] != "")
-               $link = $matches[1];
+               preg_match('/link="(.*?)"/ism', $attributes, $matches);
+               if ($matches[1] != "")
+                       $link = $matches[1];
 
-       preg_match('/link="(.*?)"/ism', $attributes, $matches);
-       if ($matches[1] != "")
-               $link = $matches[1];
+               $posted = "";
+               preg_match("/posted='(.*?)'/ism", $attributes, $matches);
+               if ($matches[1] != "")
+                       $posted= $matches[1];
 
-       $shared_body = preg_replace("/\[share(.*?)\]\s?(.*?)\s?\[\/share\]\s?/ism","$2",$body);
+               preg_match('/posted="(.*?)"/ism', $attributes, $matches);
+               if ($matches[1] != "")
+                       $posted = $matches[1];
 
-       if (($shared_body == "") OR ($profile == "") OR ($author == "") OR ($avatar == ""))
-               return(false);
+               $shared_body = preg_replace("/\[share(.*?)\]\s?(.*?)\s?\[\/share\]\s?/ism","$2",$body);
 
-       $item["body"] = $shared_body;
-       $item["author-name"] = $author;
-       $item["author-link"] = $profile;
-       $item["author-avatar"] = $avatar;
-       $item["plink"] = $link;
+               if (($shared_body == "") || ($profile == "") || ($author == "") || ($avatar == "") || ($posted == ""))
+                       return false;
 
-       return(true);
 
-}
 
-function api_get_nick($profile) {
-/* To-Do:
- - remove trailing junk from profile url
- - pump.io check has to check the website
-*/
+               $reshared_item["body"] = $shared_body;
+               $reshared_item["author-name"] = $author;
+               $reshared_item["author-link"] = $profile;
+               $reshared_item["author-avatar"] = $avatar;
+               $reshared_item["plink"] = $link;
+               $reshared_item["created"] = $posted;
+               $reshared_item["edited"] = $posted;
 
-       $nick = "";
+               return $reshared_item;
 
-       $r = q("SELECT `nick` FROM `gcontact` WHERE `nurl` = '%s'",
-               dbesc(normalise_link($profile)));
-       if ($r)
-               $nick = $r[0]["nick"];
+       }
+
+       function api_get_nick($profile) {
+               /* To-Do:
+                - remove trailing junk from profile url
+                - pump.io check has to check the website
+               */
+
+               $nick = "";
 
-       if (!$nick == "") {
                $r = q("SELECT `nick` FROM `contact` WHERE `uid` = 0 AND `nurl` = '%s'",
                        dbesc(normalise_link($profile)));
                if ($r)
                        $nick = $r[0]["nick"];
-       }
 
-       if (!$nick == "") {
-               $friendica = preg_replace("=https?://(.*)/profile/(.*)=ism", "$2", $profile);
-               if ($friendica != $profile)
-                       $nick = $friendica;
-       }
+               if (!$nick == "") {
+                       $r = q("SELECT `nick` FROM `contact` WHERE `uid` = 0 AND `nurl` = '%s'",
+                               dbesc(normalise_link($profile)));
+                       if ($r)
+                               $nick = $r[0]["nick"];
+               }
 
-       if (!$nick == "") {
-               $diaspora = preg_replace("=https?://(.*)/u/(.*)=ism", "$2", $profile);
-               if ($diaspora != $profile)
-                       $nick = $diaspora;
-       }
+               if (!$nick == "") {
+                       $friendica = preg_replace("=https?://(.*)/profile/(.*)=ism", "$2", $profile);
+                       if ($friendica != $profile)
+                               $nick = $friendica;
+               }
 
-       if (!$nick == "") {
-               $twitter = preg_replace("=https?://twitter.com/(.*)=ism", "$1", $profile);
-               if ($twitter != $profile)
-                       $nick = $twitter;
-       }
+               if (!$nick == "") {
+                       $diaspora = preg_replace("=https?://(.*)/u/(.*)=ism", "$2", $profile);
+                       if ($diaspora != $profile)
+                               $nick = $diaspora;
+               }
+
+               if (!$nick == "") {
+                       $twitter = preg_replace("=https?://twitter.com/(.*)=ism", "$1", $profile);
+                       if ($twitter != $profile)
+                               $nick = $twitter;
+               }
 
 
-       if (!$nick == "") {
-               $StatusnetHost = preg_replace("=https?://(.*)/user/(.*)=ism", "$1", $profile);
-               if ($StatusnetHost != $profile) {
-                       $StatusnetUser = preg_replace("=https?://(.*)/user/(.*)=ism", "$2", $profile);
-                       if ($StatusnetUser != $profile) {
-                               $UserData = fetch_url("http://".$StatusnetHost."/api/users/show.json?user_id=".$StatusnetUser);
-                               $user = json_decode($UserData);
-                               if ($user)
-                                       $nick = $user->screen_name;
+               if (!$nick == "") {
+                       $StatusnetHost = preg_replace("=https?://(.*)/user/(.*)=ism", "$1", $profile);
+                       if ($StatusnetHost != $profile) {
+                               $StatusnetUser = preg_replace("=https?://(.*)/user/(.*)=ism", "$2", $profile);
+                               if ($StatusnetUser != $profile) {
+                                       $UserData = fetch_url("http://".$StatusnetHost."/api/users/show.json?user_id=".$StatusnetUser);
+                                       $user = json_decode($UserData);
+                                       if ($user)
+                                               $nick = $user->screen_name;
+                               }
                        }
                }
-       }
 
-       // To-Do: look at the page if its really a pumpio site
-       //if (!$nick == "") {
-       //      $pumpio = preg_replace("=https?://(.*)/(.*)/=ism", "$2", $profile."/");
-       //      if ($pumpio != $profile)
-       //              $nick = $pumpio;
-               //      <div class="media" id="profile-block" data-profile-id="acct:kabniel@microca.st">
+               // To-Do: look at the page if its really a pumpio site
+               //if (!$nick == "") {
+               //      $pumpio = preg_replace("=https?://(.*)/(.*)/=ism", "$2", $profile."/");
+               //      if ($pumpio != $profile)
+               //              $nick = $pumpio;
+                       //      <div class="media" id="profile-block" data-profile-id="acct:kabniel@microca.st">
+
+               //}
 
-       //}
+               if ($nick != "")
+                       return($nick);
 
-       if ($nick != "") {
-               q("UPDATE `unique_contacts` SET `nick` = '%s' WHERE `nick` != '%s' AND url = '%s'",
-                       dbesc($nick), dbesc($nick), dbesc(normalise_link($profile)));
-               return($nick);
+               return(false);
        }
 
-       return(false);
-}
+       function api_in_reply_to($item) {
+               $in_reply_to = array();
 
-function api_clean_plain_items($Text) {
-       $include_entities = strtolower(x($_REQUEST,'include_entities')?$_REQUEST['include_entities']:"false");
+               $in_reply_to['status_id'] = NULL;
+               $in_reply_to['user_id'] = NULL;
+               $in_reply_to['status_id_str'] = NULL;
+               $in_reply_to['user_id_str'] = NULL;
+               $in_reply_to['screen_name'] = NULL;
 
-       $Text = bb_CleanPictureLinks($Text);
+               if (($item['thr-parent'] != $item['uri']) AND (intval($item['parent']) != intval($item['id']))) {
+                       $r = q("SELECT `id` FROM `item` WHERE `uid` = %d AND `uri` = '%s' LIMIT 1",
+                               intval($item['uid']),
+                               dbesc($item['thr-parent']));
 
-       $URLSearchString = "^\[\]";
+                       if (dbm::is_result($r)) {
+                               $in_reply_to['status_id'] = intval($r[0]['id']);
+                       } else {
+                               $in_reply_to['status_id'] = intval($item['parent']);
+                       }
 
-       $Text = preg_replace("/([!#@])\[url\=([$URLSearchString]*)\](.*?)\[\/url\]/ism",'$1$3',$Text);
+                       $in_reply_to['status_id_str'] = (string) intval($in_reply_to['status_id']);
 
-       if ($include_entities == "true") {
-               $Text = preg_replace("/\[url\=([$URLSearchString]*)\](.*?)\[\/url\]/ism",'[url=$1]$1[/url]',$Text);
-       }
+                       $r = q("SELECT `contact`.`nick`, `contact`.`name`, `contact`.`id`, `contact`.`url` FROM item
+                               STRAIGHT_JOIN `contact` ON `contact`.`id` = `item`.`author-id`
+                               WHERE `item`.`id` = %d LIMIT 1",
+                               intval($in_reply_to['status_id'])
+                       );
 
-       $Text = preg_replace_callback("((.*?)\[class=(.*?)\](.*?)\[\/class\])ism","api_cleanup_share",$Text);
-       return($Text);
-}
+                       if (dbm::is_result($r)) {
+                               if ($r[0]['nick'] == "") {
+                                       $r[0]['nick'] = api_get_nick($r[0]["url"]);
+                               }
 
-function api_cleanup_share($shared) {
-       if ($shared[2] != "type-link")
-               return($shared[0]);
+                               $in_reply_to['screen_name'] = (($r[0]['nick']) ? $r[0]['nick'] : $r[0]['name']);
+                               $in_reply_to['user_id'] = intval($r[0]['id']);
+                               $in_reply_to['user_id_str'] = (string) intval($r[0]['id']);
+                       }
 
-       if (!preg_match_all("/\[bookmark\=([^\]]*)\](.*?)\[\/bookmark\]/ism",$shared[3], $bookmark))
-               return($shared[0]);
+                       // There seems to be situation, where both fields are identical:
+                       // https://github.com/friendica/friendica/issues/1010
+                       // This is a bugfix for that.
+                       if (intval($in_reply_to['status_id']) == intval($item['id'])) {
+                               logger('this message should never appear: id: '.$item['id'].' similar to reply-to: '.$in_reply_to['status_id'], LOGGER_DEBUG);
+                               $in_reply_to['status_id'] = NULL;
+                               $in_reply_to['user_id'] = NULL;
+                               $in_reply_to['status_id_str'] = NULL;
+                               $in_reply_to['user_id_str'] = NULL;
+                               $in_reply_to['screen_name'] = NULL;
+                       }
+               }
 
-       $title = "";
-       $link = "";
+               return $in_reply_to;
+       }
 
-       if (isset($bookmark[2][0]))
-               $title = $bookmark[2][0];
+       function api_clean_plain_items($Text) {
+               $include_entities = strtolower(x($_REQUEST,'include_entities')?$_REQUEST['include_entities']:"false");
 
-       if (isset($bookmark[1][0]))
-               $link = $bookmark[1][0];
+               $Text = bb_CleanPictureLinks($Text);
+               $URLSearchString = "^\[\]";
 
-       if (strpos($shared[1],$title) !== false)
-               $title = "";
+               $Text = preg_replace("/([!#@])\[url\=([$URLSearchString]*)\](.*?)\[\/url\]/ism",'$1$3',$Text);
 
-       if (strpos($shared[1],$link) !== false)
-               $link = "";
+               if ($include_entities == "true") {
+                       $Text = preg_replace("/\[url\=([$URLSearchString]*)\](.*?)\[\/url\]/ism",'[url=$1]$1[/url]',$Text);
+               }
 
-       $text = trim($shared[1]);
+               // Simplify "attachment" element
+               $Text = api_clean_attachments($Text);
 
-       //if (strlen($text) < strlen($title))
-       if (($text == "") AND ($title != ""))
-               $text .= "\n\n".trim($title);
+               return($Text);
+       }
 
-       if ($link != "")
-               $text .= "\n".trim($link);
+       /**
+        * @brief Removes most sharing information for API text export
+        *
+        * @param string $body The original body
+        *
+        * @return string Cleaned body
+        */
+       function api_clean_attachments($body) {
+               $data = get_attachment_data($body);
 
-       return(trim($text));
-}
+               if (!$data)
+                       return $body;
 
-function api_best_nickname(&$contacts) {
-       $best_contact = array();
+               $body = "";
 
-       if (count($contact) == 0)
-               return;
+               if (isset($data["text"]))
+                       $body = $data["text"];
 
-       foreach ($contacts AS $contact)
-               if ($contact["network"] == "") {
-                       $contact["network"] = "dfrn";
-                       $best_contact = array($contact);
-               }
+               if (($body == "") AND (isset($data["title"])))
+                       $body = $data["title"];
 
-       if (sizeof($best_contact) == 0)
-               foreach ($contacts AS $contact)
-                       if ($contact["network"] == "dfrn")
-                               $best_contact = array($contact);
+               if (isset($data["url"]))
+                       $body .= "\n".$data["url"];
 
-       if (sizeof($best_contact) == 0)
-               foreach ($contacts AS $contact)
-                       if ($contact["network"] == "dspr")
-                               $best_contact = array($contact);
+               $body .= $data["after"];
 
-       if (sizeof($best_contact) == 0)
-               foreach ($contacts AS $contact)
-                       if ($contact["network"] == "stat")
-                               $best_contact = array($contact);
+               return $body;
+       }
 
-       if (sizeof($best_contact) == 0)
-               foreach ($contacts AS $contact)
-                       if ($contact["network"] == "pump")
-                               $best_contact = array($contact);
+       function api_best_nickname(&$contacts) {
+               $best_contact = array();
+
+               if (count($contact) == 0)
+                       return;
 
-       if (sizeof($best_contact) == 0)
                foreach ($contacts AS $contact)
-                       if ($contact["network"] == "twit")
+                       if ($contact["network"] == "") {
+                               $contact["network"] = "dfrn";
                                $best_contact = array($contact);
+                       }
 
-       if (sizeof($best_contact) == 1)
-               $contacts = $best_contact;
-       else
-               $contacts = array($contacts[0]);
-}
+               if (sizeof($best_contact) == 0)
+                       foreach ($contacts AS $contact)
+                               if ($contact["network"] == "dfrn")
+                                       $best_contact = array($contact);
+
+               if (sizeof($best_contact) == 0)
+                       foreach ($contacts AS $contact)
+                               if ($contact["network"] == "dspr")
+                                       $best_contact = array($contact);
+
+               if (sizeof($best_contact) == 0)
+                       foreach ($contacts AS $contact)
+                               if ($contact["network"] == "stat")
+                                       $best_contact = array($contact);
+
+               if (sizeof($best_contact) == 0)
+                       foreach ($contacts AS $contact)
+                               if ($contact["network"] == "pump")
+                                       $best_contact = array($contact);
+
+               if (sizeof($best_contact) == 0)
+                       foreach ($contacts AS $contact)
+                               if ($contact["network"] == "twit")
+                                       $best_contact = array($contact);
+
+               if (sizeof($best_contact) == 1)
+                       $contacts = $best_contact;
+               else
+                       $contacts = array($contacts[0]);
+       }
 
        // return all or a specified group of the user with the containing contacts
-       function api_friendica_group_show(&$a, $type) {
-               if (api_user()===false) return false;           
+       function api_friendica_group_show($type) {
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
                // params
                $user_info = api_get_user($a);
                $gid = (x($_REQUEST,'gid') ? $_REQUEST['gid'] : 0);
                $uid = $user_info['uid'];
-       
+
                // get data of the specified group id or all groups if not specified
                if ($gid != 0) {
                        $r = q("SELECT * FROM `group` WHERE `deleted` = 0 AND `uid` = %d AND `id` = %d",
-                               intval($uid), 
+                               intval($uid),
                                intval($gid));
                        // error message if specified gid is not in database
-                       if (count($r) == 0) 
-                               die(api_error($a, $type, 'gid not available'));
+                       if (count($r) == 0)
+                               throw new BadRequestException("gid not available");
                }
-               else 
+               else
                        $r = q("SELECT * FROM `group` WHERE `deleted` = 0 AND `uid` = %d",
                                intval($uid));
-               
+
                // loop through all groups and retrieve all members for adding data in the user array
                foreach ($r as $rr) {
                        $members = group_get_members($rr['id']);
                        $users = array();
-                       foreach ($members as $member) {
-                               $user = api_get_user($a, $member['nurl']);
-                               $users[] = $user;
+
+                       if ($type == "xml") {
+                               $user_element = "users";
+                               $k = 0;
+                               foreach ($members as $member) {
+                                       $user = api_get_user($a, $member['nurl']);
+                                       $users[$k++.":user"] = $user;
+                               }
+                       } else {
+                               $user_element = "user";
+                               foreach ($members as $member) {
+                                       $user = api_get_user($a, $member['nurl']);
+                                       $users[] = $user;
+                               }
                        }
-                       $grps[] = array('name' => $rr['name'], 'gid' => $rr['id'], 'user' => $users);
+                       $grps[] = array('name' => $rr['name'], 'gid' => $rr['id'], $user_element => $users);
                }
-               return api_apply_template("group_show", $type, array('$groups' => $grps));
+               return api_format_data("groups", $type, array('group' => $grps));
        }
        api_register_func('api/friendica/group_show', 'api_friendica_group_show', true);
 
 
        // delete the specified group of the user
-       function api_friendica_group_delete(&$a, $type) {
-               if (api_user()===false) return false;           
+       function api_friendica_group_delete($type) {
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
                // params
                $user_info = api_get_user($a);
                $gid = (x($_REQUEST,'gid') ? $_REQUEST['gid'] : 0);
                $name = (x($_REQUEST, 'name') ? $_REQUEST['name'] : "");
                $uid = $user_info['uid'];
-       
+
                // error if no gid specified
                if ($gid == 0 || $name == "")
-                       die(api_error($a, $type, 'gid or name not specified'));
+                       throw new BadRequestException('gid or name not specified');
 
                // get data of the specified group id
                $r = q("SELECT * FROM `group` WHERE `uid` = %d AND `id` = %d",
-                       intval($uid), 
+                       intval($uid),
                        intval($gid));
                // error message if specified gid is not in database
-               if (count($r) == 0) 
-                       die(api_error($a, $type, 'gid not available'));
+               if (count($r) == 0)
+                       throw new BadRequestException('gid not available');
 
                // get data of the specified group id and group name
                $rname = q("SELECT * FROM `group` WHERE `uid` = %d AND `id` = %d AND `name` = '%s'",
-                       intval($uid), 
+                       intval($uid),
                        intval($gid),
                        dbesc($name));
                // error message if specified gid is not in database
-               if (count($rname) == 0) 
-                       die(api_error($a, $type, 'wrong group name'));
+               if (count($rname) == 0)
+                       throw new BadRequestException('wrong group name');
 
                // delete group
                $ret = group_rmv($uid, $name);
                if ($ret) {
                        // return success
                        $success = array('success' => $ret, 'gid' => $gid, 'name' => $name, 'status' => 'deleted', 'wrong users' => array());
-                       return api_apply_template("group_delete", $type, array('$result' => $success));
+                       return api_format_data("group_delete", $type, array('result' => $success));
                }
                else
-                       die(api_error($a, $type, 'other API error'));
+                       throw new BadRequestException('other API error');
        }
-       api_register_func('api/friendica/group_delete', 'api_friendica_group_delete', true);
+       api_register_func('api/friendica/group_delete', 'api_friendica_group_delete', true, API_METHOD_DELETE);
 
 
-       // create the specified group with the posted array of contacts 
-       function api_friendica_group_create(&$a, $type) {
-               if (api_user()===false) return false;           
+       // create the specified group with the posted array of contacts
+       function api_friendica_group_create($type) {
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
 
                // params
                $user_info = api_get_user($a);
@@ -3128,38 +3622,38 @@ function api_best_nickname(&$contacts) {
 
                // error if no name specified
                if ($name == "")
-                       die(api_error($a, $type, 'group name not specified'));
+                       throw new BadRequestException('group name not specified');
 
                // get data of the specified group name
                $rname = q("SELECT * FROM `group` WHERE `uid` = %d AND `name` = '%s' AND `deleted` = 0",
-                       intval($uid), 
+                       intval($uid),
                        dbesc($name));
                // error message if specified group name already exists
-               if (count($rname) != 0) 
-                       die(api_error($a, $type, 'group name already exists'));
+               if (count($rname) != 0)
+                       throw new BadRequestException('group name already exists');
 
                // check if specified group name is a deleted group
                $rname = q("SELECT * FROM `group` WHERE `uid` = %d AND `name` = '%s' AND `deleted` = 1",
-                       intval($uid), 
+                       intval($uid),
                        dbesc($name));
                // error message if specified group name already exists
-               if (count($rname) != 0) 
+               if (count($rname) != 0)
                        $reactivate_group = true;
 
                // create group
                $ret = group_add($uid, $name);
-               if ($ret) 
+               if ($ret)
                        $gid = group_byname($uid, $name);
                else
-                       die(api_error($a, $type, 'other API error'));
-               
+                       throw new BadRequestException('other API error');
+
                // add members
                $erroraddinguser = false;
                $errorusers = array();
                foreach ($users as $user) {
                        $cid = $user['cid'];
                        // check if user really exists as contact
-                       $contact = q("SELECT * FROM `contact` WHERE `id` = %d AND `uid` = %d", 
+                       $contact = q("SELECT * FROM `contact` WHERE `id` = %d AND `uid` = %d",
                                intval($cid),
                                intval($uid));
                        if (count($contact))
@@ -3173,14 +3667,17 @@ function api_best_nickname(&$contacts) {
                // return success message incl. missing users in array
                $status = ($erroraddinguser ? "missing user" : ($reactivate_group ? "reactivated" : "ok"));
                $success = array('success' => true, 'gid' => $gid, 'name' => $name, 'status' => $status, 'wrong users' => $errorusers);
-               return api_apply_template("group_create", $type, array('result' => $success));          
+               return api_format_data("group_create", $type, array('result' => $success));
        }
-       api_register_func('api/friendica/group_create', 'api_friendica_group_create', true);
+       api_register_func('api/friendica/group_create', 'api_friendica_group_create', true, API_METHOD_POST);
+
+
+       // update the specified group with the posted array of contacts
+       function api_friendica_group_update($type) {
 
+               $a = get_app();
 
-       // update the specified group with the posted array of contacts 
-       function api_friendica_group_update(&$a, $type) {
-               if (api_user()===false) return false;           
+               if (api_user()===false) throw new ForbiddenException();
 
                // params
                $user_info = api_get_user($a);
@@ -3192,11 +3689,11 @@ function api_best_nickname(&$contacts) {
 
                // error if no name specified
                if ($name == "")
-                       die(api_error($a, $type, 'group name not specified'));
+                       throw new BadRequestException('group name not specified');
 
                // error if no gid specified
                if ($gid == "")
-                       die(api_error($a, $type, 'gid not specified'));
+                       throw new BadRequestException('gid not specified');
 
                // remove members
                $members = group_get_members($gid);
@@ -3216,7 +3713,7 @@ function api_best_nickname(&$contacts) {
                foreach ($users as $user) {
                        $cid = $user['cid'];
                        // check if user really exists as contact
-                       $contact = q("SELECT * FROM `contact` WHERE `id` = %d AND `uid` = %d", 
+                       $contact = q("SELECT * FROM `contact` WHERE `id` = %d AND `uid` = %d",
                                intval($cid),
                                intval($uid));
                        if (count($contact))
@@ -3226,13 +3723,289 @@ function api_best_nickname(&$contacts) {
                                $errorusers[] = $cid;
                        }
                }
-               
+
                // return success message incl. missing users in array
                $status = ($erroraddinguser ? "missing user" : "ok");
                $success = array('success' => true, 'gid' => $gid, 'name' => $name, 'status' => $status, 'wrong users' => $errorusers);
-               return api_apply_template("group_update", $type, array('result' => $success));          
+               return api_format_data("group_update", $type, array('result' => $success));
+       }
+       api_register_func('api/friendica/group_update', 'api_friendica_group_update', true, API_METHOD_POST);
+
+
+       function api_friendica_activity($type) {
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
+               $verb = strtolower($a->argv[3]);
+               $verb = preg_replace("|\..*$|", "", $verb);
+
+               $id = (x($_REQUEST, 'id') ? $_REQUEST['id'] : 0);
+
+               $res = do_like($id, $verb);
+
+               if ($res) {
+                       if ($type == "xml")
+                               $ok = "true";
+                       else
+                               $ok = "ok";
+                       return api_format_data('ok', $type, array('ok' => $ok));
+               } else {
+                       throw new BadRequestException('Error adding activity');
+               }
+
+       }
+       api_register_func('api/friendica/activity/like', 'api_friendica_activity', true, API_METHOD_POST);
+       api_register_func('api/friendica/activity/dislike', 'api_friendica_activity', true, API_METHOD_POST);
+       api_register_func('api/friendica/activity/attendyes', 'api_friendica_activity', true, API_METHOD_POST);
+       api_register_func('api/friendica/activity/attendno', 'api_friendica_activity', true, API_METHOD_POST);
+       api_register_func('api/friendica/activity/attendmaybe', 'api_friendica_activity', true, API_METHOD_POST);
+       api_register_func('api/friendica/activity/unlike', 'api_friendica_activity', true, API_METHOD_POST);
+       api_register_func('api/friendica/activity/undislike', 'api_friendica_activity', true, API_METHOD_POST);
+       api_register_func('api/friendica/activity/unattendyes', 'api_friendica_activity', true, API_METHOD_POST);
+       api_register_func('api/friendica/activity/unattendno', 'api_friendica_activity', true, API_METHOD_POST);
+       api_register_func('api/friendica/activity/unattendmaybe', 'api_friendica_activity', true, API_METHOD_POST);
+
+       /**
+        * @brief Returns notifications
+        *
+        * @param string $type Known types are 'atom', 'rss', 'xml' and 'json'
+        * @return string
+       */
+       function api_friendica_notification($type) {
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
+               if ($a->argc!==3) throw new BadRequestException("Invalid argument count");
+               $nm = new NotificationsManager();
+
+               $notes = $nm->getAll(array(), "+seen -date", 50);
+
+               if ($type == "xml") {
+                       $xmlnotes = array();
+                       foreach ($notes AS $note)
+                               $xmlnotes[] = array("@attributes" => $note);
+
+                       $notes = $xmlnotes;
+               }
+
+               return api_format_data("notes", $type, array('note' => $notes));
        }
-       api_register_func('api/friendica/group_update', 'api_friendica_group_update', true);
+
+       /**
+        * @brief Set notification as seen and returns associated item (if possible)
+        *
+        * POST request with 'id' param as notification id
+        *
+        * @param string $type Known types are 'atom', 'rss', 'xml' and 'json'
+        * @return string
+        */
+       function api_friendica_notification_seen($type){
+
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
+               if ($a->argc!==4) throw new BadRequestException("Invalid argument count");
+
+               $id = (x($_REQUEST, 'id') ? intval($_REQUEST['id']) : 0);
+
+               $nm = new NotificationsManager();
+               $note = $nm->getByID($id);
+               if (is_null($note)) throw new BadRequestException("Invalid argument");
+
+               $nm->setSeen($note);
+               if ($note['otype']=='item') {
+                       // would be really better with an ItemsManager and $im->getByID() :-P
+                       $r = q("SELECT * FROM `item` WHERE `id`=%d AND `uid`=%d",
+                               intval($note['iid']),
+                               intval(local_user())
+                       );
+                       if ($r!==false) {
+                               // we found the item, return it to the user
+                               $user_info = api_get_user($a);
+                               $ret = api_format_items($r,$user_info, false, $type);
+                               $data = array('status' => $ret);
+                               return api_format_data("status", $type, $data);
+                       }
+                       // the item can't be found, but we set the note as seen, so we count this as a success
+               }
+               return api_format_data('result', $type, array('result' => "success"));
+       }
+
+       api_register_func('api/friendica/notification/seen', 'api_friendica_notification_seen', true, API_METHOD_POST);
+       api_register_func('api/friendica/notification', 'api_friendica_notification', true, API_METHOD_GET);
+
+
+       /**
+        * @brief update a direct_message to seen state
+        *
+        * @param string $type Known types are 'atom', 'rss', 'xml' and 'json'
+        * @return string (success result=ok, error result=error with error message)
+        */
+       function api_friendica_direct_messages_setseen($type){
+               $a = get_app();
+               if (api_user()===false) throw new ForbiddenException();
+
+               // params
+               $user_info = api_get_user($a);
+               $uid = $user_info['uid'];
+               $id = (x($_REQUEST, 'id') ? $_REQUEST['id'] : 0);
+
+               // return error if id is zero
+               if ($id == "") {
+                       $answer = array('result' => 'error', 'message' => 'message id not specified');
+                       return api_format_data("direct_messages_setseen", $type, array('$result' => $answer));
+               }
+
+               // get data of the specified message id
+               $r = q("SELECT `id` FROM `mail` WHERE `id` = %d AND `uid` = %d",
+                       intval($id), 
+                       intval($uid));
+               // error message if specified id is not in database
+               if (!dbm::is_result($r)) {
+                       $answer = array('result' => 'error', 'message' => 'message id not in database');
+                       return api_format_data("direct_messages_setseen", $type, array('$result' => $answer));
+               }
+
+               // update seen indicator
+               $result = q("UPDATE `mail` SET `seen` = 1 WHERE `id` = %d AND `uid` = %d", 
+                       intval($id), 
+                       intval($uid));
+
+               if ($result) {
+                       // return success
+                       $answer = array('result' => 'ok', 'message' => 'message set to seen');
+                       return api_format_data("direct_message_setseen", $type, array('$result' => $answer));
+               } else {
+                       $answer = array('result' => 'error', 'message' => 'unknown error');
+                       return api_format_data("direct_messages_setseen", $type, array('$result' => $answer));
+               }
+       }
+       api_register_func('api/friendica/direct_messages_setseen', 'api_friendica_direct_messages_setseen', true);
+
+
+
+
+       /**
+        * @brief search for direct_messages containing a searchstring through api
+        *
+        * @param string $type Known types are 'atom', 'rss', 'xml' and 'json'
+        * @return string (success: success=true if found and search_result contains found messages
+        *                          success=false if nothing was found, search_result='nothing found',
+        *                 error: result=error with error message)
+        */
+       function api_friendica_direct_messages_search($type){
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
+
+               // params
+               $user_info = api_get_user($a);
+               $searchstring = (x($_REQUEST,'searchstring') ? $_REQUEST['searchstring'] : "");
+               $uid = $user_info['uid'];
+
+               // error if no searchstring specified
+               if ($searchstring == "") {
+                       $answer = array('result' => 'error', 'message' => 'searchstring not specified');
+                       return api_format_data("direct_messages_search", $type, array('$result' => $answer));
+               }
+
+               // get data for the specified searchstring
+               $r = q("SELECT `mail`.*, `contact`.`nurl` AS `contact-url` FROM `mail`,`contact` WHERE `mail`.`contact-id` = `contact`.`id` AND `mail`.`uid`=%d AND `body` LIKE '%s' ORDER BY `mail`.`id` DESC",
+                       intval($uid),
+                       dbesc('%'.$searchstring.'%')
+               );
+
+               $profile_url = $user_info["url"];
+               // message if nothing was found
+               if (count($r) == 0) 
+                       $success = array('success' => false, 'search_results' => 'nothing found');
+               else {
+                       $ret = Array();
+                       foreach($r as $item) {
+                               if ($box == "inbox" || $item['from-url'] != $profile_url){
+                                       $recipient = $user_info;
+                                       $sender = api_get_user($a,normalise_link($item['contact-url']));
+                               }
+                               elseif ($box == "sentbox" || $item['from-url'] == $profile_url){
+                                       $recipient = api_get_user($a,normalise_link($item['contact-url']));
+                                       $sender = $user_info;
+                               }
+                               $ret[]=api_format_messages($item, $recipient, $sender);
+                       }
+                       $success = array('success' => true, 'search_results' => $ret);
+               }
+
+               return api_format_data("direct_message_search", $type, array('$result' => $success));
+       }
+       api_register_func('api/friendica/direct_messages_search', 'api_friendica_direct_messages_search', true);
+
+
+       /**
+        * @brief return data of all the profiles a user has to the client
+        *
+        * @param string $type Known types are 'atom', 'rss', 'xml' and 'json'
+        * @return string
+        */
+       function api_friendica_profile_show($type){
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
+
+               // input params
+               $profileid = (x($_REQUEST,'profile_id') ? $_REQUEST['profile_id'] : 0);
+
+               // retrieve general information about profiles for user
+               $multi_profiles = feature_enabled(api_user(),'multi_profiles');
+               $directory = get_config('system', 'directory');
+
+// get data of the specified profile id or all profiles of the user if not specified
+               if ($profileid != 0) {
+                       $r = q("SELECT * FROM `profile` WHERE `uid` = %d AND `id` = %d",
+                               intval(api_user()),
+                               intval($profileid));
+                       // error message if specified gid is not in database
+                       if (count($r) == 0)
+                               throw new BadRequestException("profile_id not available");
+               }
+               else
+                       $r = q("SELECT * FROM `profile` WHERE `uid` = %d",
+                               intval(api_user()));
+
+               // loop through all returned profiles and retrieve data and users
+               $k = 0;
+               foreach ($r as $rr) {
+                       $profile = api_format_items_profiles($rr, $type);
+
+                       // select all users from contact table, loop and prepare standard return for user data
+                       $users = array();
+                       $r = q("SELECT `id`, `nurl` FROM `contact` WHERE `uid`= %d AND `profile-id` = %d",
+                               intval(api_user()),
+                               intval($rr['profile_id']));
+
+                       foreach ($r as $rr) {
+                               $user = api_get_user($a, $rr['nurl']);
+                               ($type == "xml") ? $users[$k++.":user"] = $user : $users[] = $user;
+                       }
+                       $profile['users'] = $users;
+
+                       // add prepared profile data to array for final return
+                       if ($type == "xml") {
+                               $profiles[$k++.":profile"] = $profile;
+                       } else {
+                               $profiles[] = $profile;
+                       }
+               }
+
+               // return settings, authenticated user and profiles data
+               $result = array('multi_profiles' => $multi_profiles ? true : false,
+                                               'global_dir' => $directory,
+                                               'friendica_owner' => api_get_user($a, intval(api_user())),
+                                               'profiles' => $profiles);
+               return api_format_data("friendica_profiles", $type, array('$result' => $result));
+       }
+       api_register_func('api/friendica/profile/show', 'api_friendica_profile_show', true, API_METHOD_GET);
 
 /*
 To.Do:
@@ -3245,7 +4018,7 @@ To.Do:
     [include_rts] => 1
     [include_reply_count] => true
     [include_descendent_reply_count] => true
-
+(?)
 
 
 Not implemented by now:
@@ -3259,6 +4032,9 @@ account/update_profile_background_image
 account/update_profile_image
 blocks/create
 blocks/destroy
+friendica/profile/update
+friendica/profile/create
+friendica/profile/delete
 
 Not implemented in status.net:
 statuses/retweeted_to_me