]> git.mxchange.org Git - friendica.git/blobdiff - include/api.php
Merge branch '3.5rc' of https://github.com/friendica/friendica into 3.5rc
[friendica.git] / include / api.php
index ddc5813d50e714d4eaca037d967f9f07e6291bdd..a380845ed18d6be3c97a53450f58293957628d08 100644 (file)
@@ -92,7 +92,7 @@
         *
         * Register a function to be the endpont for defined API path.
         *
-        * @param string $path API URL path, relative to $a->get_baseurl()
+        * @param string $path API URL path, relative to App::get_baseurl()
         * @param string $func Function name to call on path request
         * @param bool $auth API need logged user
         * @param string $method
                else {
                        // process normal login request
 
-                       $r = q("SELECT * FROM `user` WHERE ( `email` = '%s' OR `nickname` = '%s' )
-                               AND `password` = '%s' AND `blocked` = 0 AND `account_expired` = 0 AND `account_removed` = 0 AND `verified` = 1 LIMIT 1",
+                       $r = q("SELECT * FROM `user` WHERE (`email` = '%s' OR `nickname` = '%s')
+                               AND `password` = '%s' AND NOT `blocked` AND NOT `account_expired` AND NOT `account_removed` AND `verified` LIMIT 1",
                                dbesc(trim($user)),
                                dbesc(trim($user)),
                                dbesc($encrypted)
                        throw new UnauthorizedException("This API requires login");
                }
 
-               authenticate_success($record); $_SESSION["allow_api"] = true;
+               authenticate_success($record);
+
+               $_SESSION["allow_api"] = true;
 
                call_hooks('logged_in', $a->user);
 
                                        logger('API parameters: ' . print_r($_REQUEST,true));
 
                                        $stamp =  microtime(true);
-                                       $r = call_user_func($info['func'], $a, $type);
+                                       $r = call_user_func($info['func'], $type);
                                        $duration = (float)(microtime(true)-$stamp);
                                        logger("API call duration: ".round($duration, 2)."\t".$a->query_string, LOGGER_DEBUG);
 
                                        switch($type){
                                                case "xml":
                                                        header ("Content-Type: text/xml");
-
-                                                       if (substr($r, 0, 5) == "<?xml")
-                                                               return $r;
-
-                                                       $r = mb_convert_encoding($r, "UTF-8",mb_detect_encoding($r));
-                                                       return '<?xml version="1.0" encoding="UTF-8"?>'."\n".$r;
+                                                       return $r;
                                                        break;
                                                case "json":
                                                        header ("Content-Type: application/json");
                        throw new NotImplementedException();
                } catch (HTTPException $e) {
                        header("HTTP/1.1 {$e->httpcode} {$e->httpdesc}");
-                       return api_error($a, $type, $e);
+                       return api_error($type, $e);
                }
        }
 
        /**
         * @brief Format API error string
         *
-        * @param Api $a
         * @param string $type Return type (xml, json, rss, as)
         * @param HTTPException $error Error object
         * @return strin error message formatted as $type
         */
-       function api_error(&$a, $type, $e) {
+       function api_error($type, $e) {
+
+               $a = get_app();
+
                $error = ($e->getMessage()!==""?$e->getMessage():$e->httpdesc);
                # TODO:  https://dev.twitter.com/overview/api/response-codes
-               $xmlstr = "<status><error>{$error}</error><code>{$e->httpcode} {$e->httpdesc}</code><request>{$a->query_string}</request></status>";
+
+               $error = array("error" => $error,
+                               "code" => $e->httpcode." ".$e->httpdesc,
+                               "request" => $a->query_string);
+
+               $ret = api_format_data('status', $type, array('status' => $error));
+
                switch($type){
                        case "xml":
                                header ("Content-Type: text/xml");
-                               return '<?xml version="1.0" encoding="UTF-8"?>'."\n".$xmlstr;
+                               return $ret;
                                break;
                        case "json":
                                header ("Content-Type: application/json");
-                               return json_encode(array(
-                                       'error' => $error,
-                                       'request' => $a->query_string,
-                                       'code' => $e->httpcode." ".$e->httpdesc
-                               ));
+                               return json_encode($ret);
                                break;
                        case "rss":
                                header ("Content-Type: application/rss+xml");
-                               return '<?xml version="1.0" encoding="UTF-8"?>'."\n".$xmlstr;
+                               return $ret;
                                break;
                        case "atom":
                                header ("Content-Type: application/atom+xml");
-                               return '<?xml version="1.0" encoding="UTF-8"?>'."\n".$xmlstr;
+                               return $ret;
                                break;
                }
        }
                $arr['$user'] = $user_info;
                $arr['$rss'] = array(
                        'alternate' => $user_info['url'],
-                       'self' => $a->get_baseurl(). "/". $a->query_string,
-                       'base' => $a->get_baseurl(),
+                       'self' => App::get_baseurl(). "/". $a->query_string,
+                       'base' => App::get_baseurl(),
                        'updated' => api_date(null),
                        'atom_updated' => datetime_convert('UTC','UTC','now',ATOM_TIME),
                        'language' => $user_info['language'],
-                       'logo'  => $a->get_baseurl()."/images/friendica-32.png",
+                       'logo'  => App::get_baseurl()."/images/friendica-32.png",
                );
 
                return $arr;
                                return False;
                        } else {
                                $user = $_SESSION['uid'];
-                               $extra_query = "AND `contact`.`uid` = %d AND `contact`.`self` = 1 ";
+                               $extra_query = "AND `contact`.`uid` = %d AND `contact`.`self` ";
                        }
 
                }
                                        'notifications' => false,
                                        'statusnet_profile_url' => $r[0]["url"],
                                        'uid' => 0,
-                                       'cid' => 0,
+                                       'cid' => get_contact($r[0]["url"], api_user()),
                                        'self' => 0,
                                        'network' => $r[0]["network"],
                                );
                }
 
                if($uinfo[0]['self']) {
+
+                       if ($uinfo[0]['network'] == "")
+                               $uinfo[0]['network'] = NETWORK_DFRN;
+
                        $usr = q("select * from user where uid = %d limit 1",
                                intval(api_user())
                        );
                        'verified' => true,
                        'statusnet_blocking' => false,
                        'notifications' => false,
-                       //'statusnet_profile_url' => $a->get_baseurl()."/contacts/".$uinfo[0]['cid'],
+                       //'statusnet_profile_url' => App::get_baseurl()."/contacts/".$uinfo[0]['cid'],
                        'statusnet_profile_url' => $uinfo[0]['url'],
                        'uid' => intval($uinfo[0]['uid']),
                        'cid' => intval($uinfo[0]['cid']),
                return (array($status_user, $owner_user));
        }
 
-
-       /**
-        * @brief transform $data array in xml without a template
-        *
-        * @param array $data
-        * @return string xml string
-        */
-       function api_array_to_xml($data, $ename="") {
-               $attrs="";
-               $childs="";
-               if (count($data)==1 && !is_array($data[array_keys($data)[0]])) {
-                       $ename = array_keys($data)[0];
-                       $ename = trim($ename,'$');
-                       $v = $data[$ename];
-                       return "<$ename>$v</$ename>";
-               }
-               foreach($data as $k=>$v) {
-                       $k=trim($k,'$');
-                       if (!is_array($v)) {
-                               $attrs .= sprintf('%s="%s" ', $k, $v);
-                       } else {
-                               if (is_numeric($k)) $k=trim($ename,'s');
-                               $childs.=api_array_to_xml($v, $k);
-                       }
-               }
-               $res = $childs;
-               if ($ename!="") $res = "<$ename $attrs>$res</$ename>";
-               return $res;
-       }
-
-
        /**
         * @brief walks recursively through an array with the possibility to change value and key
         *
                        $key = "statusnet:".substr($key, 10);
                elseif (substr($key, 0, 10) == "friendica_")
                        $key = "friendica:".substr($key, 10);
-               elseif (in_array($key, array("like", "dislike", "attendyes", "attendno", "attendmaybe")))
-                       $key = "friendica:".$key;
+               //else
+               //      $key = "default:".$key;
 
-               return (!in_array($key, array("attachments", "friendica:activities", "coordinates")));
+               return true;
        }
 
        /**
         * @brief Creates the XML from a JSON style array
         *
         * @param array $data JSON style array
-        * @param string $template Name of the root element
+        * @param string $root_element Name of the root element
         *
-        * @return boolean string The XML data
+        * @return string The XML data
         */
        function api_create_xml($data, $root_element) {
-
                $childname = key($data);
                $data2 = array_pop($data);
                $key = key($data2);
 
-               $namespaces = array("statusnet" => "http://status.net/schema/api/1/",
-                                       "friendica" => "http://friendi.ca/schema/api/1/");
+               $namespaces = array("" => "http://api.twitter.com",
+                                       "statusnet" => "http://status.net/schema/api/1/",
+                                       "friendica" => "http://friendi.ca/schema/api/1/",
+                                       "georss" => "http://www.georss.org/georss");
 
                /// @todo Auto detection of needed namespaces
                if (in_array($root_element, array("ok", "hash", "config", "version", "ids", "notes", "photos")))
                }
 
                $data3 = array($root_element => $data2);
+
                $ret = xml::from_array($data3, $xml, false, $namespaces);
                return $ret;
        }
 
        /**
-        *  load api $templatename for $type and replace $data array
+        * @brief Formats the data according to the data type
+        *
+        * @param string $root_element Name of the root element
+        * @param string $type Return type (atom, rss, xml, json)
+        * @param array $data JSON style array
+        *
+        * @return (string|object) XML data or JSON data
         */
-       function api_apply_template($templatename, $type, $data){
+       function api_format_data($root_element, $type, $data){
 
                $a = get_app();
 
                        case "atom":
                        case "rss":
                        case "xml":
-                               $ret = api_create_xml($data, $templatename);
-                               break;
-
-                               $data = array_xmlify($data);
-                               if ($templatename==="<auto>") {
-                                       $ret = api_array_to_xml($data);
-                               } else {
-                                       $tpl = get_markup_template("api_".$templatename."_".$type.".tpl");
-                                       if(! $tpl) {
-                                               header ("Content-Type: text/xml");
-                                               echo '<?xml version="1.0" encoding="UTF-8"?>'."\n".'<status><error>not implemented</error></status>';
-                                               killme();
-                                       }
-                                       $ret = replace_macros($tpl, $data);
-                               }
+                               $ret = api_create_xml($data, $root_element);
                                break;
                        case "json":
                                $ret = $data;
         * returns a 401 status code and an error message if not.
         * http://developer.twitter.com/doc/get/account/verify_credentials
         */
-       function api_account_verify_credentials(&$a, $type){
+       function api_account_verify_credentials($type){
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                unset($_REQUEST["user_id"]);
 
                // - Adding last status
                if (!$skip_status) {
-                       $user_info["status"] = api_status_show($a,"raw");
+                       $user_info["status"] = api_status_show("raw");
                        if (!count($user_info["status"]))
                                unset($user_info["status"]);
                        else
                unset($user_info["uid"]);
                unset($user_info["self"]);
 
-               return api_apply_template("user", $type, array('user' => $user_info));
+               return api_format_data("user", $type, array('user' => $user_info));
 
        }
        api_register_func('api/account/verify_credentials','api_account_verify_credentials', true);
        }
 
 /*Waitman Gobble Mod*/
-       function api_statuses_mediap(&$a, $type) {
+       function api_statuses_mediap($type) {
+
+               $a = get_app();
+
                if (api_user()===false) {
                        logger('api_statuses_update: no user');
                        throw new ForbiddenException();
                item_post($a);
 
                // this should output the last post (the one we just posted).
-               return api_status_show($a,$type);
+               return api_status_show($type);
        }
        api_register_func('api/statuses/mediap','api_statuses_mediap', true, API_METHOD_POST);
 /*Waitman Gobble Mod*/
 
 
-       function api_statuses_update(&$a, $type) {
+       function api_statuses_update($type) {
+
+               $a = get_app();
+
                if (api_user()===false) {
                        logger('api_statuses_update: no user');
                        throw new ForbiddenException();
 
                                if ($posts_day > $throttle_day) {
                                        logger('Daily posting limit reached for user '.api_user(), LOGGER_DEBUG);
-                                       #die(api_error($a, $type, sprintf(t("Daily posting limit of %d posts reached. The post was rejected."), $throttle_day)));
+                                       #die(api_error($type, sprintf(t("Daily posting limit of %d posts reached. The post was rejected."), $throttle_day)));
                                        throw new TooManyRequestsException(sprintf(t("Daily posting limit of %d posts reached. The post was rejected."), $throttle_day));
                                }
                        }
 
                                if ($posts_week > $throttle_week) {
                                        logger('Weekly posting limit reached for user '.api_user(), LOGGER_DEBUG);
-                                       #die(api_error($a, $type, sprintf(t("Weekly posting limit of %d posts reached. The post was rejected."), $throttle_week)));
+                                       #die(api_error($type, sprintf(t("Weekly posting limit of %d posts reached. The post was rejected."), $throttle_week)));
                                        throw new TooManyRequestsException(sprintf(t("Weekly posting limit of %d posts reached. The post was rejected."), $throttle_week));
 
                                }
 
                                if ($posts_month > $throttle_month) {
                                        logger('Monthly posting limit reached for user '.api_user(), LOGGER_DEBUG);
-                                       #die(api_error($a, $type, sprintf(t("Monthly posting limit of %d posts reached. The post was rejected."), $throttle_month)));
+                                       #die(api_error($type, sprintf(t("Monthly posting limit of %d posts reached. The post was rejected."), $throttle_month)));
                                        throw new TooManyRequestsException(sprintf(t("Monthly posting limit of %d posts reached. The post was rejected."), $throttle_month));
                                }
                        }
                        if ($r) {
                                $phototypes = Photo::supportedTypes();
                                $ext = $phototypes[$r[0]['type']];
-                               $_REQUEST['body'] .= "\n\n".'[url='.$a->get_baseurl().'/photos/'.$r[0]['nickname'].'/image/'.$r[0]['resource-id'].']';
-                               $_REQUEST['body'] .= '[img]'.$a->get_baseurl()."/photo/".$r[0]['resource-id']."-".$r[0]['scale'].".".$ext."[/img][/url]";
+                               $_REQUEST['body'] .= "\n\n".'[url='.App::get_baseurl().'/photos/'.$r[0]['nickname'].'/image/'.$r[0]['resource-id'].']';
+                               $_REQUEST['body'] .= '[img]'.App::get_baseurl()."/photo/".$r[0]['resource-id']."-".$r[0]['scale'].".".$ext."[/img][/url]";
                        }
                }
 
                item_post($a);
 
                // this should output the last post (the one we just posted).
-               return api_status_show($a,$type);
+               return api_status_show($type);
        }
        api_register_func('api/statuses/update','api_statuses_update', true, API_METHOD_POST);
        api_register_func('api/statuses/update_with_media','api_statuses_update', true, API_METHOD_POST);
 
 
-       function api_media_upload(&$a, $type) {
+       function api_media_upload($type) {
+
+               $a = get_app();
+
                if (api_user()===false) {
                        logger('no user');
                        throw new ForbiddenException();
        }
        api_register_func('api/media/upload','api_media_upload', true, API_METHOD_POST);
 
-       function api_status_show(&$a, $type){
+       function api_status_show($type){
+
+               $a = get_app();
+
                $user_info = api_get_user($a);
 
                logger('api_status_show: user_info: '.print_r($user_info, true), LOGGER_DEBUG);
                                        AND ((`item`.`author-link` IN ('%s', '%s')) OR (`item`.`owner-link` IN ('%s', '%s')))
                                        AND `i`.`id` = `item`.`parent`
                                        AND `item`.`type`!='activity' $privacy_sql
-                               ORDER BY `item`.`created` DESC
+                               ORDER BY `item`.`id` DESC
                                LIMIT 1",
                                intval($user_info['cid']),
                                intval(api_user()),
 
                        $converted = api_convert_item($lastwall);
 
+                       if ($type == "xml")
+                               $geo = "georss:point";
+                       else
+                               $geo = "geo";
+
                        $status_info = array(
                                'created_at' => api_date($lastwall['created']),
                                'id' => intval($lastwall['id']),
                                'in_reply_to_user_id_str' => $in_reply_to_user_id_str,
                                'in_reply_to_screen_name' => $in_reply_to_screen_name,
                                'user' => $user_info,
-                               'geo' => NULL,
+                               $geo => NULL,
                                'coordinates' => "",
                                'place' => "",
                                'contributors' => "",
                if ($type == "raw")
                        return($status_info);
 
-               return  api_apply_template("statuses", $type, array('status' => $status_info));
+               return  api_format_data("statuses", $type, array('status' => $status_info));
 
        }
 
         * The author's most recent status will be returned inline.
         * http://developer.twitter.com/doc/get/users/show
         */
-       function api_users_show(&$a, $type){
-               $user_info = api_get_user($a);
+       function api_users_show($type){
 
+               $a = get_app();
+
+               $user_info = api_get_user($a);
                $lastwall = q("SELECT `item`.*
-                               FROM `item`, `contact`
+                               FROM `item`
+                               INNER JOIN `contact` ON `contact`.`id`=`item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
                                WHERE `item`.`uid` = %d AND `verb` = '%s' AND `item`.`contact-id` = %d
                                        AND ((`item`.`author-link` IN ('%s', '%s')) OR (`item`.`owner-link` IN ('%s', '%s')))
-                                       AND `contact`.`id`=`item`.`contact-id`
                                        AND `type`!='activity'
                                        AND `item`.`allow_cid`='' AND `item`.`allow_gid`='' AND `item`.`deny_cid`='' AND `item`.`deny_gid`=''
-                               ORDER BY `created` DESC
+                               ORDER BY `id` DESC
                                LIMIT 1",
                                intval(api_user()),
                                dbesc(ACTIVITY_POST),
                                dbesc($user_info['url']),
                                dbesc(normalise_link($user_info['url']))
                );
+
                if (count($lastwall)>0){
                        $lastwall = $lastwall[0];
 
 
                        $converted = api_convert_item($lastwall);
 
+                       if ($type == "xml")
+                               $geo = "georss:point";
+                       else
+                               $geo = "geo";
+
                        $user_info['status'] = array(
                                'text' => $converted["text"],
                                'truncated' => false,
                                'in_reply_to_user_id' => $in_reply_to_user_id,
                                'in_reply_to_user_id_str' => $in_reply_to_user_id_str,
                                'in_reply_to_screen_name' => $in_reply_to_screen_name,
-                               'geo' => NULL,
+                               $geo => NULL,
                                'favorited' => $lastwall['starred'] ? true : false,
                                'statusnet_html'                => $converted["html"],
                                'statusnet_conversation_id'     => $lastwall['parent'],
                unset($user_info["uid"]);
                unset($user_info["self"]);
 
-               return  api_apply_template("user", $type, array('user' => $user_info));
+               return  api_format_data("user", $type, array('user' => $user_info));
 
        }
        api_register_func('api/users/show','api_users_show');
 
 
-       function api_users_search(&$a, $type) {
+       function api_users_search($type) {
+
+               $a = get_app();
+
                $page = (x($_REQUEST,'page')?$_REQUEST['page']-1:0);
 
                $userlist = array();
                                $r = q("SELECT `id` FROM `gcontact` WHERE `nick`='%s'", dbesc($_GET["q"]));
 
                        if (count($r)) {
+                               $k = 0;
                                foreach ($r AS $user) {
-                                       $user_info = api_get_user($a, $user["id"]);
-                                       //echo print_r($user_info, true)."\n";
-                                       $userdata = api_apply_template("user", $type, array('users' => $user_info));
-                                       $userlist[] = $userdata["user"];
+                                       $user_info = api_get_user($a, $user["id"], "json");
+
+                                       if ($type == "xml")
+                                               $userlist[$k++.":user"] = $user_info;
+                                       else
+                                               $userlist[] = $user_info;
                                }
                                $userlist = array("users" => $userlist);
                        } else {
                } else {
                        throw new BadRequestException("User not found.");
                }
-               return ($userlist);
+               return api_format_data("users", $type, $userlist);
        }
 
        api_register_func('api/users/search','api_users_search');
         * TODO: Optional parameters
         * TODO: Add reply info
         */
-       function api_statuses_home_timeline(&$a, $type){
+       function api_statuses_home_timeline($type){
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                unset($_REQUEST["user_id"]);
                if ($conversation_id > 0)
                        $sql_extra .= ' AND `item`.`parent` = '.intval($conversation_id);
 
-               $r = q("SELECT STRAIGHT_JOIN `item`.*, `item`.`id` AS `item_id`, `item`.`network` AS `item_network`,
+               $r = q("SELECT `item`.*, `item`.`id` AS `item_id`, `item`.`network` AS `item_network`,
                        `contact`.`name`, `contact`.`photo`, `contact`.`url`, `contact`.`rel`,
                        `contact`.`network`, `contact`.`thumb`, `contact`.`dfrn-id`, `contact`.`self`,
                        `contact`.`id` AS `cid`
-                       FROM `item`, `contact`
+                       FROM `item`
+                       STRAIGHT_JOIN `contact` ON `contact`.`id` = `item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
+                               AND NOT `contact`.`blocked` AND NOT `contact`.`pending`
                        WHERE `item`.`uid` = %d AND `verb` = '%s'
-                       AND `item`.`visible` = 1 and `item`.`moderated` = 0 AND `item`.`deleted` = 0
-                       AND `contact`.`id` = `item`.`contact-id`
-                       AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
+                       AND `item`.`visible` AND NOT `item`.`moderated` AND NOT `item`.`deleted`
                        $sql_extra
                        AND `item`.`id`>%d
                        ORDER BY `item`.`id` DESC LIMIT %d ,%d ",
                        intval($start), intval($count)
                );
 
-               $ret = api_format_items($r,$user_info);
+               $ret = api_format_items($r,$user_info, false, $type);
 
                // Set all posts from the query above to seen
                $idarray = array();
                                break;
                }
 
-               return  api_apply_template("statuses", $type, $data);
+               return  api_format_data("statuses", $type, $data);
        }
        api_register_func('api/statuses/home_timeline','api_statuses_home_timeline', true);
        api_register_func('api/statuses/friends_timeline','api_statuses_home_timeline', true);
 
-       function api_statuses_public_timeline(&$a, $type){
+       function api_statuses_public_timeline($type){
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                $user_info = api_get_user($a);
                        `contact`.`network`, `contact`.`thumb`, `contact`.`self`, `contact`.`writable`,
                        `contact`.`id` AS `cid`,
                        `user`.`nickname`, `user`.`hidewall`
-                       FROM `item` STRAIGHT_JOIN `contact` ON `contact`.`id` = `item`.`contact-id`
+                       FROM `item`
+                       STRAIGHT_JOIN `contact` ON `contact`.`id` = `item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
+                               AND NOT `contact`.`blocked` AND NOT `contact`.`pending`
                        STRAIGHT_JOIN `user` ON `user`.`uid` = `item`.`uid`
-                       WHERE `verb` = '%s' AND `item`.`visible` = 1 AND `item`.`deleted` = 0 and `item`.`moderated` = 0
+                               AND NOT `user`.`hidewall`
+                       WHERE `verb` = '%s' AND `item`.`visible` AND NOT `item`.`deleted` AND NOT `item`.`moderated`
                        AND `item`.`allow_cid` = ''  AND `item`.`allow_gid` = ''
                        AND `item`.`deny_cid`  = '' AND `item`.`deny_gid`  = ''
-                       AND `item`.`private` = 0 AND `item`.`wall` = 1 AND `user`.`hidewall` = 0
-                       AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
+                       AND NOT `item`.`private` AND `item`.`wall`
                        $sql_extra
                        AND `item`.`id`>%d
                        ORDER BY `item`.`id` DESC LIMIT %d, %d ",
                        intval($start),
                        intval($count));
 
-               $ret = api_format_items($r,$user_info);
+               $ret = api_format_items($r,$user_info, false, $type);
 
 
                $data = array('status' => $ret);
                                break;
                }
 
-               return  api_apply_template("statuses", $type, $data);
+               return  api_format_data("statuses", $type, $data);
        }
        api_register_func('api/statuses/public_timeline','api_statuses_public_timeline', true);
 
        /**
         *
         */
-       function api_statuses_show(&$a, $type){
+       function api_statuses_show($type){
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                $user_info = api_get_user($a);
 
                $sql_extra = '';
                if ($conversation)
-                       $sql_extra .= " AND `item`.`parent` = %d ORDER BY `received` ASC ";
+                       $sql_extra .= " AND `item`.`parent` = %d ORDER BY `id` ASC ";
                else
                        $sql_extra .= " AND `item`.`id` = %d";
 
                        `contact`.`name`, `contact`.`photo`, `contact`.`url`, `contact`.`rel`,
                        `contact`.`network`, `contact`.`thumb`, `contact`.`dfrn-id`, `contact`.`self`,
                        `contact`.`id` AS `cid`
-                       FROM `item`, `contact`
-                       WHERE `item`.`visible` = 1 and `item`.`moderated` = 0 AND `item`.`deleted` = 0
-                       AND `contact`.`id` = `item`.`contact-id` AND `item`.`uid` = %d AND `item`.`verb` = '%s'
-                       AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
+                       FROM `item`
+                       INNER JOIN `contact` ON `contact`.`id` = `item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
+                               AND NOT `contact`.`blocked` AND NOT `contact`.`pending`
+                       WHERE `item`.`visible` AND NOT `item`.`moderated` AND NOT `item`.`deleted`
+                       AND `item`.`uid` = %d AND `item`.`verb` = '%s'
                        $sql_extra",
                        intval(api_user()),
                        dbesc(ACTIVITY_POST),
                        throw new BadRequestException("There is no status with this id.");
                }
 
-               $ret = api_format_items($r,$user_info);
+               $ret = api_format_items($r,$user_info, false, $type);
 
                if ($conversation) {
                        $data = array('status' => $ret);
-                       return api_apply_template("statuses", $type, $data);
+                       return api_format_data("statuses", $type, $data);
                } else {
                        $data = array('status' => $ret[0]);
-                       return  api_apply_template("status", $type, $data);
+                       return  api_format_data("status", $type, $data);
                }
        }
        api_register_func('api/statuses/show','api_statuses_show', true);
        /**
         *
         */
-       function api_conversation_show(&$a, $type){
+       function api_conversation_show($type){
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                $user_info = api_get_user($a);
                        `contact`.`network`, `contact`.`thumb`, `contact`.`dfrn-id`, `contact`.`self`,
                        `contact`.`id` AS `cid`
                        FROM `item`
-                       INNER JOIN `contact` ON `contact`.`id` = `item`.`contact-id`
+                       STRAIGHT_JOIN `contact` ON `contact`.`id` = `item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
+                               AND NOT `contact`.`blocked` AND NOT `contact`.`pending`
                        WHERE `item`.`parent` = %d AND `item`.`visible`
                        AND NOT `item`.`moderated` AND NOT `item`.`deleted`
                        AND `item`.`uid` = %d AND `item`.`verb` = '%s'
-                       AND NOT `contact`.`blocked` AND NOT `contact`.`pending`
                        AND `item`.`id`>%d $sql_extra
                        ORDER BY `item`.`id` DESC LIMIT %d ,%d",
                        intval($id), intval(api_user()),
                if (!$r)
                        throw new BadRequestException("There is no conversation with this id.");
 
-               $ret = api_format_items($r,$user_info);
+               $ret = api_format_items($r,$user_info, false, $type);
 
                $data = array('status' => $ret);
-               return api_apply_template("statuses", $type, $data);
+               return api_format_data("statuses", $type, $data);
        }
        api_register_func('api/conversation/show','api_conversation_show', true);
        api_register_func('api/statusnet/conversation','api_conversation_show', true);
        /**
         *
         */
-       function api_statuses_repeat(&$a, $type){
+       function api_statuses_repeat($type){
                global $called_api;
 
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                $user_info = api_get_user($a);
                        `contact`.`name`, `contact`.`photo` as `reply_photo`, `contact`.`url` as `reply_url`, `contact`.`rel`,
                        `contact`.`network`, `contact`.`thumb`, `contact`.`dfrn-id`, `contact`.`self`,
                        `contact`.`id` AS `cid`
-                       FROM `item`, `contact`
-                       WHERE `item`.`visible` = 1 and `item`.`moderated` = 0 AND `item`.`deleted` = 0
-                       AND `contact`.`id` = `item`.`contact-id`
-                       AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
+                       FROM `item`
+                       INNER JOIN `contact` ON `contact`.`id` = `item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
+                               AND NOT `contact`.`blocked` AND NOT `contact`.`pending`
+                       WHERE `item`.`visible` AND NOT `item`.`moderated` AND NOT `item`.`deleted`
                        AND NOT `item`.`private` AND `item`.`allow_cid` = '' AND `item`.`allow`.`gid` = ''
                        AND `item`.`deny_cid` = '' AND `item`.`deny_gid` = ''
                        $sql_extra
 
                // this should output the last post (the one we just posted).
                $called_api = null;
-               return(api_status_show($a,$type));
+               return(api_status_show($type));
        }
        api_register_func('api/statuses/retweet','api_statuses_repeat', true, API_METHOD_POST);
 
        /**
         *
         */
-       function api_statuses_destroy(&$a, $type){
+       function api_statuses_destroy($type){
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                $user_info = api_get_user($a);
 
                logger('API: api_statuses_destroy: '.$id);
 
-               $ret = api_statuses_show($a, $type);
+               $ret = api_statuses_show($type);
 
                drop_item($id, false);
 
         * http://developer.twitter.com/doc/get/statuses/mentions
         *
         */
-       function api_statuses_mentions(&$a, $type){
+       function api_statuses_mentions($type){
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                unset($_REQUEST["user_id"]);
                $start = $page*$count;
 
                // Ugly code - should be changed
-               $myurl = $a->get_baseurl() . '/profile/'. $a->user['nickname'];
+               $myurl = App::get_baseurl() . '/profile/'. $a->user['nickname'];
                $myurl = substr($myurl,strpos($myurl,'://')+3);
                //$myurl = str_replace(array('www.','.'),array('','\\.'),$myurl);
                $myurl = str_replace('www.','',$myurl);
                        `contact`.`name`, `contact`.`photo`, `contact`.`url`, `contact`.`rel`,
                        `contact`.`network`, `contact`.`thumb`, `contact`.`dfrn-id`, `contact`.`self`,
                        `contact`.`id` AS `cid`
-                       FROM `item`  FORCE INDEX (`uid_id`), `contact`
+                       FROM `item` FORCE INDEX (`uid_id`)
+                       STRAIGHT_JOIN `contact` ON `contact`.`id` = `item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
+                               AND NOT `contact`.`blocked` AND NOT `contact`.`pending`
                        WHERE `item`.`uid` = %d AND `verb` = '%s'
                        AND NOT (`item`.`author-link` IN ('https://%s', 'http://%s'))
                        AND `item`.`visible` AND NOT `item`.`moderated` AND NOT `item`.`deleted`
-                       AND `contact`.`id` = `item`.`contact-id`
-                       AND NOT `contact`.`blocked` AND NOT `contact`.`pending`
                        AND `item`.`parent` IN (SELECT `iid` FROM `thread` WHERE `uid` = %d AND `mention` AND !`ignored`)
                        $sql_extra
                        AND `item`.`id`>%d
                        intval($start), intval($count)
                );
 
-               $ret = api_format_items($r,$user_info);
+               $ret = api_format_items($r,$user_info, false, $type);
 
 
                $data = array('status' => $ret);
                                break;
                }
 
-               return  api_apply_template("statuses", $type, $data);
+               return  api_format_data("statuses", $type, $data);
        }
        api_register_func('api/statuses/mentions','api_statuses_mentions', true);
        api_register_func('api/statuses/replies','api_statuses_mentions', true);
 
 
-       function api_statuses_user_timeline(&$a, $type){
+       function api_statuses_user_timeline($type){
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                $user_info = api_get_user($a);
                        `contact`.`name`, `contact`.`photo`, `contact`.`url`, `contact`.`rel`,
                        `contact`.`network`, `contact`.`thumb`, `contact`.`dfrn-id`, `contact`.`self`,
                        `contact`.`id` AS `cid`
-                       FROM `item`
-                       INNER JOIN `contact` ON `contact`.`id` = `item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
+                       FROM `item` FORCE INDEX (`uid_contactid_id`)
+                       STRAIGHT_JOIN `contact` ON `contact`.`id` = `item`.`contact-id` AND `contact`.`uid` = `item`.`uid`
                                AND NOT `contact`.`blocked` AND NOT `contact`.`pending`
                        WHERE `item`.`uid` = %d AND `verb` = '%s'
                        AND `item`.`contact-id` = %d
                        intval($start), intval($count)
                );
 
-               $ret = api_format_items($r,$user_info, true);
+               $ret = api_format_items($r,$user_info, true, $type);
 
                $data = array('status' => $ret);
                switch($type){
                                $data = api_rss_extra($a, $data, $user_info);
                }
 
-               return  api_apply_template("statuses", $type, $data);
+               return  api_format_data("statuses", $type, $data);
        }
        api_register_func('api/statuses/user_timeline','api_statuses_user_timeline', true);
 
         *
         * api v1 : https://web.archive.org/web/20131019055350/https://dev.twitter.com/docs/api/1/post/favorites/create/%3Aid
         */
-       function api_favorites_create_destroy(&$a, $type){
+       function api_favorites_create_destroy($type){
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                // for versioned api.
 
 
                $user_info = api_get_user($a);
-               $rets = api_format_items($item,$user_info);
+               $rets = api_format_items($item, $user_info, false, $type);
                $ret = $rets[0];
 
                $data = array('status' => $ret);
                                $data = api_rss_extra($a, $data, $user_info);
                }
 
-               return api_apply_template("status", $type, $data);
+               return api_format_data("status", $type, $data);
        }
        api_register_func('api/favorites/create', 'api_favorites_create_destroy', true, API_METHOD_POST);
        api_register_func('api/favorites/destroy', 'api_favorites_create_destroy', true, API_METHOD_DELETE);
 
-       function api_favorites(&$a, $type){
+       function api_favorites($type){
                global $called_api;
 
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                $called_api= array();
                                intval($start), intval($count)
                        );
 
-                       $ret = api_format_items($r,$user_info);
+                       $ret = api_format_items($r,$user_info, false, $type);
 
                }
 
                                $data = api_rss_extra($a, $data, $user_info);
                }
 
-               return  api_apply_template("statuses", $type, $data);
+               return  api_format_data("statuses", $type, $data);
        }
        api_register_func('api/favorites','api_favorites', true);
 
                                'recipient_screen_name' => $recipient['screen_name'],
                                'sender'                => $sender,
                                'recipient'             => $recipient,
+                               'title'                 => "",
+                               'friendica_seen'        => $item['seen'],
+                               'friendica_parent_uri'  => $item['parent-uri'],
                );
 
                // "uid" and "self" are only needed for some internal stuff, so remove it from here
                return($entities);
        }
        function api_format_items_embeded_images(&$item, $text){
-               $a = get_app();
                $text = preg_replace_callback(
                                "|data:image/([^;]+)[^=]+=*|m",
-                               function($match) use ($a, $item) {
-                                       return $a->get_baseurl()."/display/".$item['guid'];
+                               function($match) use ($item) {
+                                       return App::get_baseurl()."/display/".$item['guid'];
                                },
                                $text);
                return $text;
         *                      likes => int count
         *                      dislikes => int count
         */
-       function api_format_items_activities(&$item) {
+       function api_format_items_activities(&$item, $type = "json") {
                $activities = array(
                        'like' => array(),
                        'dislike' => array(),
                        builtin_activity_puller($i, $activities);
                }
 
+               if ($type == "xml") {
+                       $xml_activities = array();
+                       foreach ($activities as $k => $v)
+                               $xml_activities["friendica:".$k] = $v;
+
+                       $activities = $xml_activities;
+               }
+
                $res = array();
                $uri = $item['uri']."-l";
                foreach($activities as $k => $v) {
-                       $res[$k] = ( x($v,$uri) ? array_map("api_contactlink_to_array", $v[$uri]) : array() );
+                       $res[$k] = (x($v,$uri)?count($v[$uri]):0);
+                       #$res[$k] = ( x($v,$uri) ? array_map("api_contactlink_to_array", $v[$uri]) : array() );
                }
-
                return $res;
        }
 
         * @param array $user_info
         * @param bool $filter_user filter items by $user_info
         */
-       function api_format_items($r,$user_info, $filter_user = false) {
+       function api_format_items($r,$user_info, $filter_user = false, $type = "json") {
 
                $a = get_app();
+
                $ret = Array();
 
                foreach($r as $item) {
 
                        $converted = api_convert_item($item);
 
+                       if ($type == "xml")
+                               $geo = "georss:point";
+                       else
+                               $geo = "geo";
+
                        $status = array(
                                'text'          => $converted["text"],
                                'truncated' => False,
                                'in_reply_to_user_id' => $in_reply_to_user_id,
                                'in_reply_to_user_id_str' => $in_reply_to_user_id_str,
                                'in_reply_to_screen_name' => $in_reply_to_screen_name,
-                               'geo' => NULL,
+                               $geo => NULL,
                                'favorited' => $item['starred'] ? true : false,
                                'user' =>  $status_user ,
                                'friendica_owner' => $owner_user,
                                //'entities' => NULL,
                                'statusnet_html'                => $converted["html"],
                                'statusnet_conversation_id'     => $item['parent'],
-                               'friendica_activities' => api_format_items_activities($item),
+                               'friendica_activities' => api_format_items_activities($item, $type),
                        );
 
                        if (count($converted["attachments"]) > 0)
 
                                        $retweeted_status['text'] = $rt_converted["text"];
                                        $retweeted_status['statusnet_html'] = $rt_converted["html"];
-                                       $retweeted_status['friendica_activities'] = api_format_items_activities($retweeted_item);
+                                       $retweeted_status['friendica_activities'] = api_format_items_activities($retweeted_item, $type);
                                        $retweeted_status['created_at'] =  api_date($retweeted_item['created']);
                                        $status['retweeted_status'] = $retweeted_status;
                                }
                        if ($item["coord"] != "") {
                                $coords = explode(' ',$item["coord"]);
                                if (count($coords) == 2) {
-                                       $status["geo"] = array('type' => 'Point',
-                                                       'coordinates' => array((float) $coords[0],
-                                                                               (float) $coords[1]));
+                                       if ($type == "json")
+                                               $status["geo"] = array('type' => 'Point',
+                                                               'coordinates' => array((float) $coords[0],
+                                                                                       (float) $coords[1]));
+                                       else // Not sure if this is the official format - if someone founds a documentation we can check
+                                               $status["georss:point"] = $item["coord"];
                                }
                        }
-
                        $ret[] = $status;
                };
                return $ret;
        }
 
 
-       function api_account_rate_limit_status(&$a,$type) {
+       function api_account_rate_limit_status($type) {
 
-               if ($type == "json")
-                       $hash = array(
-                                       'reset_time_in_seconds' => strtotime('now + 1 hour'),
-                                       'remaining_hits' => (string) 150,
-                                       'hourly_limit' => (string) 150,
-                                       'reset_time' => api_date(datetime_convert('UTC','UTC','now + 1 hour',ATOM_TIME)),
-                               );
-               else
+               if ($type == "xml")
                        $hash = array(
                                        'remaining-hits' => (string) 150,
                                        '@attributes' => array("type" => "integer"),
                                        'reset_time_in_seconds' => strtotime('now + 1 hour'),
                                        '@attributes4' => array("type" => "integer"),
                                );
+               else
+                       $hash = array(
+                                       'reset_time_in_seconds' => strtotime('now + 1 hour'),
+                                       'remaining_hits' => (string) 150,
+                                       'hourly_limit' => (string) 150,
+                                       'reset_time' => api_date(datetime_convert('UTC','UTC','now + 1 hour',ATOM_TIME)),
+                               );
 
-               return api_apply_template('hash', $type, array('hash' => $hash));
+               return api_format_data('hash', $type, array('hash' => $hash));
        }
        api_register_func('api/account/rate_limit_status','api_account_rate_limit_status',true);
 
-       function api_help_test(&$a,$type) {
+       function api_help_test($type) {
                if ($type == 'xml')
                        $ok = "true";
                else
                        $ok = "ok";
 
-               return api_apply_template('ok', $type, array("ok" => $ok));
+               return api_format_data('ok', $type, array("ok" => $ok));
        }
        api_register_func('api/help/test','api_help_test',false);
 
-       function api_lists(&$a,$type) {
+       function api_lists($type) {
                $ret = array();
-               return api_apply_template('lists', $type, array("lists_list" => $ret));
+               return api_format_data('lists', $type, array("lists_list" => $ret));
        }
        api_register_func('api/lists','api_lists',true);
 
-       function api_lists_list(&$a,$type) {
+       function api_lists_list($type) {
                $ret = array();
-               return api_apply_template('lists', $type, array("lists_list" => $ret));
+               return api_format_data('lists', $type, array("lists_list" => $ret));
        }
        api_register_func('api/lists/list','api_lists_list',true);
 
         *  This function is deprecated by Twitter
         *  returns: json, xml
         **/
-       function api_statuses_f(&$a, $type, $qtype) {
+       function api_statuses_f($type, $qtype) {
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
                $user_info = api_get_user($a);
 
                return array('user' => $ret);
 
        }
-       function api_statuses_friends(&$a, $type){
-               $data =  api_statuses_f($a,$type,"friends");
+       function api_statuses_friends($type){
+               $data =  api_statuses_f($type, "friends");
                if ($data===false) return false;
-               return  api_apply_template("users", $type, $data);
+               return  api_format_data("users", $type, $data);
        }
-       function api_statuses_followers(&$a, $type){
-               $data = api_statuses_f($a,$type,"followers");
+       function api_statuses_followers($type){
+               $data = api_statuses_f($type, "followers");
                if ($data===false) return false;
-               return  api_apply_template("users", $type, $data);
+               return  api_format_data("users", $type, $data);
        }
        api_register_func('api/statuses/friends','api_statuses_friends',true);
        api_register_func('api/statuses/followers','api_statuses_followers',true);
 
 
 
-       function api_statusnet_config(&$a,$type) {
+       function api_statusnet_config($type) {
+
+               $a = get_app();
+
                $name = $a->config['sitename'];
                $server = $a->get_hostname();
-               $logo = $a->get_baseurl() . '/images/friendica-64.png';
+               $logo = App::get_baseurl() . '/images/friendica-64.png';
                $email = $a->config['admin_email'];
                $closed = (($a->config['register_policy'] == REGISTER_CLOSED) ? 'true' : 'false');
                $private = (($a->config['system']['block_public']) ? 'true' : 'false');
                if($a->config['api_import_size'])
                        $texlimit = string($a->config['api_import_size']);
                $ssl = (($a->config['system']['have_ssl']) ? 'true' : 'false');
-               $sslserver = (($ssl === 'true') ? str_replace('http:','https:',$a->get_baseurl()) : '');
+               $sslserver = (($ssl === 'true') ? str_replace('http:','https:',App::get_baseurl()) : '');
 
                $config = array(
                        'site' => array('name' => $name,'server' => $server, 'theme' => 'default', 'path' => '',
                        ),
                );
 
-               return api_apply_template('config', $type, array('config' => $config));
+               return api_format_data('config', $type, array('config' => $config));
 
        }
        api_register_func('api/statusnet/config','api_statusnet_config',false);
 
-       function api_statusnet_version(&$a,$type) {
+       function api_statusnet_version($type) {
                // liar
                $fake_statusnet_version = "0.9.7";
 
-               return api_apply_template('version', $type, array('version' => $fake_statusnet_version));
+               return api_format_data('version', $type, array('version' => $fake_statusnet_version));
        }
        api_register_func('api/statusnet/version','api_statusnet_version',false);
 
        /**
-        * @todo use api_apply_template() to return data
+        * @todo use api_format_data() to return data
         */
-       function api_ff_ids(&$a,$type,$qtype) {
+       function api_ff_ids($type,$qtype) {
+
+               $a = get_app();
+
                if(! api_user()) throw new ForbiddenException();
 
                $user_info = api_get_user($a);
                        else
                                $ids[] = intval($rr['id']);
 
-               return api_apply_template("ids", $type, array('id' => $ids));
+               return api_format_data("ids", $type, array('id' => $ids));
        }
 
-       function api_friends_ids(&$a,$type) {
-               return api_ff_ids($a,$type,'friends');
+       function api_friends_ids($type) {
+               return api_ff_ids($type,'friends');
        }
-       function api_followers_ids(&$a,$type) {
-               return api_ff_ids($a,$type,'followers');
+       function api_followers_ids($type) {
+               return api_ff_ids($type,'followers');
        }
        api_register_func('api/friends/ids','api_friends_ids',true);
        api_register_func('api/followers/ids','api_followers_ids',true);
 
 
-       function api_direct_messages_new(&$a, $type) {
+       function api_direct_messages_new($type) {
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                if (!x($_POST, "text") OR (!x($_POST,"screen_name") AND !x($_POST,"user_id"))) return;
                                $data = api_rss_extra($a, $data, $user_info);
                }
 
-               return  api_apply_template("direct-messages", $type, $data);
+               return  api_format_data("direct-messages", $type, $data);
 
        }
        api_register_func('api/direct_messages/new','api_direct_messages_new',true, API_METHOD_POST);
 
-       function api_direct_messages_box(&$a, $type, $box) {
+
+       /**
+        * @brief delete a direct_message from mail table through api
+        *
+        * @param string $type Known types are 'atom', 'rss', 'xml' and 'json'
+        * @return string 
+        */
+       function api_direct_messages_destroy($type){
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
+
+               // params
+               $user_info = api_get_user($a);
+               //required
+               $id = (x($_REQUEST,'id') ? $_REQUEST['id'] : 0);
+               // optional
+               $parenturi = (x($_REQUEST, 'friendica_parenturi') ? $_REQUEST['friendica_parenturi'] : "");
+               $verbose = (x($_GET,'friendica_verbose')?strtolower($_GET['friendica_verbose']):"false");
+               /// @todo optional parameter 'include_entities' from Twitter API not yet implemented
+
+               $uid = $user_info['uid'];
+               // error if no id or parenturi specified (for clients posting parent-uri as well)
+               if ($verbose == "true") {
+                       if ($id == 0 || $parenturi == "") {
+                               $answer = array('result' => 'error', 'message' => 'message id or parenturi not specified');
+                               return api_format_data("direct_messages_delete", $type, array('$result' => $answer));
+                       }
+               }
+
+               // BadRequestException if no id specified (for clients using Twitter API)
+               if ($id == 0) throw new BadRequestException('Message id not specified');
+
+               // add parent-uri to sql command if specified by calling app            
+               $sql_extra = ($parenturi != "" ? " AND `parent-uri` = '" . dbesc($parenturi) . "'" : "");
+
+               // get data of the specified message id
+               $r = q("SELECT `id` FROM `mail` WHERE `uid` = %d AND `id` = %d" . $sql_extra,
+                       intval($uid), 
+                       intval($id));
+       
+               // error message if specified id is not in database
+               if (!dbm::is_result($r)) {
+                       if ($verbose == "true") {
+                               $answer = array('result' => 'error', 'message' => 'message id not in database');
+                               return api_format_data("direct_messages_delete", $type, array('$result' => $answer));
+                       }
+                       /// @todo BadRequestException ok for Twitter API clients?
+                       throw new BadRequestException('message id not in database');
+               }
+
+               // delete message
+               $result = q("DELETE FROM `mail` WHERE `uid` = %d AND `id` = %d" . $sql_extra, 
+                       intval($uid), 
+                       intval($id));
+
+               if ($verbose == "true") {
+                       if ($result) {
+                               // return success
+                               $answer = array('result' => 'ok', 'message' => 'message deleted');
+                               return api_format_data("direct_message_delete", $type, array('$result' => $answer));
+                       }
+                       else {
+                               $answer = array('result' => 'error', 'message' => 'unknown error');
+                               return api_format_data("direct_messages_delete", $type, array('$result' => $answer));
+                       }
+               }
+               /// @todo return JSON data like Twitter API not yet implemented
+
+       }
+       api_register_func('api/direct_messages/destroy', 'api_direct_messages_destroy', true, API_METHOD_DELETE);
+
+
+       function api_direct_messages_box($type, $box, $verbose) {
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                // params
                unset($_GET["screen_name"]);
 
                $user_info = api_get_user($a);
-               //$profile_url = $a->get_baseurl() . '/profile/' . $a->user['nickname'];
                $profile_url = $user_info["url"];
 
 
                                intval($since_id),
                                intval($start), intval($count)
                );
-
+               if ($verbose == "true") {
+                       // stop execution and return error message if no mails available
+                       if($r == null) {
+                               $answer = array('result' => 'error', 'message' => 'no mails available');
+                               return api_format_data("direct_messages_all", $type, array('$result' => $answer));
+                       }
+               }
 
                $ret = Array();
                foreach($r as $item) {
                                $data = api_rss_extra($a, $data, $user_info);
                }
 
-               return  api_apply_template("direct-messages", $type, $data);
+               return  api_format_data("direct-messages", $type, $data);
 
        }
 
-       function api_direct_messages_sentbox(&$a, $type){
-               return api_direct_messages_box($a, $type, "sentbox");
+       function api_direct_messages_sentbox($type){
+               $verbose = (x($_GET,'friendica_verbose')?strtolower($_GET['friendica_verbose']):"false");
+               return api_direct_messages_box($type, "sentbox", $verbose);
        }
-       function api_direct_messages_inbox(&$a, $type){
-               return api_direct_messages_box($a, $type, "inbox");
+       function api_direct_messages_inbox($type){
+               $verbose = (x($_GET,'friendica_verbose')?strtolower($_GET['friendica_verbose']):"false");
+               return api_direct_messages_box($type, "inbox", $verbose);
        }
-       function api_direct_messages_all(&$a, $type){
-               return api_direct_messages_box($a, $type, "all");
+       function api_direct_messages_all($type){
+               $verbose = (x($_GET,'friendica_verbose')?strtolower($_GET['friendica_verbose']):"false");
+               return api_direct_messages_box($type, "all", $verbose);
        }
-       function api_direct_messages_conversation(&$a, $type){
-               return api_direct_messages_box($a, $type, "conversation");
+       function api_direct_messages_conversation($type){
+               $verbose = (x($_GET,'friendica_verbose')?strtolower($_GET['friendica_verbose']):"false");
+               return api_direct_messages_box($type, "conversation", $verbose);
        }
        api_register_func('api/direct_messages/conversation','api_direct_messages_conversation',true);
        api_register_func('api/direct_messages/all','api_direct_messages_all',true);
 
 
 
-       function api_oauth_request_token(&$a, $type){
+       function api_oauth_request_token($type){
                try{
                        $oauth = new FKOAuth1();
                        $r = $oauth->fetch_request_token(OAuthRequest::from_request());
                echo $r;
                killme();
        }
-       function api_oauth_access_token(&$a, $type){
+       function api_oauth_access_token($type){
                try{
                        $oauth = new FKOAuth1();
                        $r = $oauth->fetch_access_token(OAuthRequest::from_request());
        api_register_func('api/oauth/access_token', 'api_oauth_access_token', false);
 
 
-       function api_fr_photos_list(&$a,$type) {
+       function api_fr_photos_list($type) {
                if (api_user()===false) throw new ForbiddenException();
                $r = q("select `resource-id`, max(scale) as scale, album, filename, type from photo
                                where uid = %d and album != 'Contact Photos' group by `resource-id`",
                                $photo['album'] = $rr['album'];
                                $photo['filename'] = $rr['filename'];
                                $photo['type'] = $rr['type'];
-                               $thumb = $a->get_baseurl()."/photo/".$rr['resource-id']."-".$rr['scale'].".".$typetoext[$rr['type']];
+                               $thumb = App::get_baseurl()."/photo/".$rr['resource-id']."-".$rr['scale'].".".$typetoext[$rr['type']];
 
-                               if ($type == "json") {
+                               if ($type == "xml")
+                                       $data['photo'][] = array("@attributes" => $photo, "1" => $thumb);
+                               else {
                                        $photo['thumb'] = $thumb;
                                        $data['photo'][] = $photo;
-                               } else {
-                                       $data['photo'][] = array("@attributes" => $photo, "1" => $thumb);
                                }
                        }
                }
-               return  api_apply_template("photos", $type, $data);
+               return  api_format_data("photos", $type, $data);
        }
 
-       function api_fr_photo_detail(&$a,$type) {
+       function api_fr_photo_detail($type) {
                if (api_user()===false) throw new ForbiddenException();
                if(!x($_REQUEST,'photo_id')) throw new BadRequestException("No photo id.");
 
 
                if ($r) {
                        $data = array('photo' => $r[0]);
+                       $data['photo']['id'] = $data['photo']['resource-id'];
                        if ($scale !== false) {
                                $data['photo']['data'] = base64_encode($data['photo']['data']);
                        } else {
                                unset($data['photo']['datasize']); //needed only with scale param
                        }
-                       $data['photo']['link'] = array();
-                       for($k=intval($data['photo']['minscale']); $k<=intval($data['photo']['maxscale']); $k++) {
-                               $data['photo']['link'][$k] = $a->get_baseurl()."/photo/".$data['photo']['resource-id']."-".$k.".".$typetoext[$data['photo']['type']];
+                       if ($type == "xml") {
+                               $data['photo']['links'] = array();
+                               for ($k=intval($data['photo']['minscale']); $k<=intval($data['photo']['maxscale']); $k++)
+                                       $data['photo']['links'][$k.":link"]["@attributes"] = array("type" => $data['photo']['type'],
+                                                                                       "scale" => $k,
+                                                                                       "href" => App::get_baseurl()."/photo/".$data['photo']['resource-id']."-".$k.".".$typetoext[$data['photo']['type']]);
+                       } else {
+                               $data['photo']['link'] = array();
+                               for ($k=intval($data['photo']['minscale']); $k<=intval($data['photo']['maxscale']); $k++) {
+                                       $data['photo']['link'][$k] = App::get_baseurl()."/photo/".$data['photo']['resource-id']."-".$k.".".$typetoext[$data['photo']['type']];
+                               }
                        }
-                       $data['photo']['id'] = $data['photo']['resource-id'];
                        unset($data['photo']['resource-id']);
                        unset($data['photo']['minscale']);
                        unset($data['photo']['maxscale']);
                        throw new NotFoundException();
                }
 
-               return api_apply_template("photo_detail", $type, $data);
+               return api_format_data("photo_detail", $type, $data);
        }
 
        api_register_func('api/friendica/photos/list', 'api_fr_photos_list', true);
         *              c_url: url of remote contact to auth to
         *              url: string, url to redirect after auth
         */
-       function api_friendica_remoteauth(&$a) {
+       function api_friendica_remoteauth() {
                $url = ((x($_GET,'url')) ? $_GET['url'] : '');
                $c_url = ((x($_GET,'c_url')) ? $_GET['c_url'] : '');
 
        }
 
        // return all or a specified group of the user with the containing contacts
-       function api_friendica_group_show(&$a, $type) {
+       function api_friendica_group_show($type) {
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                // params
                foreach ($r as $rr) {
                        $members = group_get_members($rr['id']);
                        $users = array();
-                       foreach ($members as $member) {
-                               $user = api_get_user($a, $member['nurl']);
-                               $users[] = $user;
+
+                       if ($type == "xml") {
+                               $user_element = "users";
+                               $k = 0;
+                               foreach ($members as $member) {
+                                       $user = api_get_user($a, $member['nurl']);
+                                       $users[$k++.":user"] = $user;
+                               }
+                       } else {
+                               $user_element = "user";
+                               foreach ($members as $member) {
+                                       $user = api_get_user($a, $member['nurl']);
+                                       $users[] = $user;
+                               }
                        }
-                       $grps[] = array('name' => $rr['name'], 'gid' => $rr['id'], 'user' => $users);
+                       $grps[] = array('name' => $rr['name'], 'gid' => $rr['id'], $user_element => $users);
                }
-               return api_apply_template("group_show", $type, array('groups' => $grps));
+               return api_format_data("groups", $type, array('group' => $grps));
        }
        api_register_func('api/friendica/group_show', 'api_friendica_group_show', true);
 
 
        // delete the specified group of the user
-       function api_friendica_group_delete(&$a, $type) {
+       function api_friendica_group_delete($type) {
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                // params
                if ($ret) {
                        // return success
                        $success = array('success' => $ret, 'gid' => $gid, 'name' => $name, 'status' => 'deleted', 'wrong users' => array());
-                       return api_apply_template("group_delete", $type, array('result' => $success));
+                       return api_format_data("group_delete", $type, array('result' => $success));
                }
                else
                        throw new BadRequestException('other API error');
 
 
        // create the specified group with the posted array of contacts
-       function api_friendica_group_create(&$a, $type) {
+       function api_friendica_group_create($type) {
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                // params
                // return success message incl. missing users in array
                $status = ($erroraddinguser ? "missing user" : ($reactivate_group ? "reactivated" : "ok"));
                $success = array('success' => true, 'gid' => $gid, 'name' => $name, 'status' => $status, 'wrong users' => $errorusers);
-               return api_apply_template("group_create", $type, array('result' => $success));
+               return api_format_data("group_create", $type, array('result' => $success));
        }
        api_register_func('api/friendica/group_create', 'api_friendica_group_create', true, API_METHOD_POST);
 
 
        // update the specified group with the posted array of contacts
-       function api_friendica_group_update(&$a, $type) {
+       function api_friendica_group_update($type) {
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
 
                // params
                // return success message incl. missing users in array
                $status = ($erroraddinguser ? "missing user" : "ok");
                $success = array('success' => true, 'gid' => $gid, 'name' => $name, 'status' => $status, 'wrong users' => $errorusers);
-               return api_apply_template("group_update", $type, array('result' => $success));
+               return api_format_data("group_update", $type, array('result' => $success));
        }
        api_register_func('api/friendica/group_update', 'api_friendica_group_update', true, API_METHOD_POST);
 
 
-       function api_friendica_activity(&$a, $type) {
+       function api_friendica_activity($type) {
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
                $verb = strtolower($a->argv[3]);
                $verb = preg_replace("|\..*$|", "", $verb);
                $res = do_like($id, $verb);
 
                if ($res) {
-                       if ($type == 'xml')
+                       if ($type == "xml")
                                $ok = "true";
                        else
                                $ok = "ok";
-                       return api_apply_template('test', $type, array('ok' => $ok));
+                       return api_format_data('ok', $type, array('ok' => $ok));
                } else {
                        throw new BadRequestException('Error adding activity');
                }
        /**
         * @brief Returns notifications
         *
-        * @param App $a
         * @param string $type Known types are 'atom', 'rss', 'xml' and 'json'
         * @return string
        */
-       function api_friendica_notification(&$a, $type) {
+       function api_friendica_notification($type) {
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
                if ($a->argc!==3) throw new BadRequestException("Invalid argument count");
                $nm = new NotificationsManager();
                        $notes = $xmlnotes;
                }
 
-               return api_apply_template("notes", $type, array('note' => $notes));
+               return api_format_data("notes", $type, array('note' => $notes));
        }
 
        /**
         *
         * POST request with 'id' param as notification id
         *
-        * @param App $a
         * @param string $type Known types are 'atom', 'rss', 'xml' and 'json'
         * @return string
         */
-       function api_friendica_notification_seen(&$a, $type){
+       function api_friendica_notification_seen($type){
+
+               $a = get_app();
+
                if (api_user()===false) throw new ForbiddenException();
                if ($a->argc!==4) throw new BadRequestException("Invalid argument count");
 
                        if ($r!==false) {
                                // we found the item, return it to the user
                                $user_info = api_get_user($a);
-                               $ret = api_format_items($r,$user_info);
-                               $data = array('statuses' => $ret);
-                               return api_apply_template("timeline", $type, $data);
+                               $ret = api_format_items($r,$user_info, false, $type);
+                               $data = array('status' => $ret);
+                               return api_format_data("status", $type, $data);
                        }
                        // the item can't be found, but we set the note as seen, so we count this as a success
                }
-               return api_apply_template('<auto>', $type, array('status' => "success"));
+               return api_format_data('result', $type, array('result' => "success"));
        }
 
        api_register_func('api/friendica/notification/seen', 'api_friendica_notification_seen', true, API_METHOD_POST);
        api_register_func('api/friendica/notification', 'api_friendica_notification', true, API_METHOD_GET);
 
 
+       /**
+        * @brief update a direct_message to seen state
+        *
+        * @param string $type Known types are 'atom', 'rss', 'xml' and 'json'
+        * @return string (success result=ok, error result=error with error message)
+        */
+       function api_friendica_direct_messages_setseen($type){
+               $a = get_app();
+               if (api_user()===false) throw new ForbiddenException();
+
+               // params
+               $user_info = api_get_user($a);
+               $uid = $user_info['uid'];
+               $id = (x($_REQUEST, 'id') ? $_REQUEST['id'] : 0);
+
+               // return error if id is zero
+               if ($id == "") {
+                       $answer = array('result' => 'error', 'message' => 'message id not specified');
+                       return api_format_data("direct_messages_setseen", $type, array('$result' => $answer));
+               }
+
+               // get data of the specified message id
+               $r = q("SELECT `id` FROM `mail` WHERE `id` = %d AND `uid` = %d",
+                       intval($id), 
+                       intval($uid));
+               // error message if specified id is not in database
+               if (!dbm::is_result($r)) {
+                       $answer = array('result' => 'error', 'message' => 'message id not in database');
+                       return api_format_data("direct_messages_setseen", $type, array('$result' => $answer));
+               }
+
+               // update seen indicator
+               $result = q("UPDATE `mail` SET `seen` = 1 WHERE `id` = %d AND `uid` = %d", 
+                       intval($id), 
+                       intval($uid));
+
+               if ($result) {
+                       // return success
+                       $answer = array('result' => 'ok', 'message' => 'message set to seen');
+                       return api_format_data("direct_message_setseen", $type, array('$result' => $answer));
+               } else {
+                       $answer = array('result' => 'error', 'message' => 'unknown error');
+                       return api_format_data("direct_messages_setseen", $type, array('$result' => $answer));
+               }
+       }
+       api_register_func('api/friendica/direct_messages_setseen', 'api_friendica_direct_messages_setseen', true);
+
+
+
+
+       /**
+        * @brief search for direct_messages containing a searchstring through api
+        *
+        * @param string $type Known types are 'atom', 'rss', 'xml' and 'json'
+        * @return string (success: success=true if found and search_result contains found messages
+        *                          success=false if nothing was found, search_result='nothing found',
+        *                 error: result=error with error message)
+        */
+       function api_friendica_direct_messages_search($type){
+               $a = get_app();
+
+               if (api_user()===false) throw new ForbiddenException();
+
+               // params
+               $user_info = api_get_user($a);
+               $searchstring = (x($_REQUEST,'searchstring') ? $_REQUEST['searchstring'] : "");
+               $uid = $user_info['uid'];
+       
+               // error if no searchstring specified
+               if ($searchstring == "") {
+                       $answer = array('result' => 'error', 'message' => 'searchstring not specified');
+                       return api_format_data("direct_messages_search", $type, array('$result' => $answer));
+               }
+
+               // get data for the specified searchstring
+               $r = q("SELECT `mail`.*, `contact`.`nurl` AS `contact-url` FROM `mail`,`contact` WHERE `mail`.`contact-id` = `contact`.`id` AND `mail`.`uid`=%d AND `body` LIKE '%s' ORDER BY `mail`.`id` DESC",
+                       intval($uid),
+                       dbesc('%'.$searchstring.'%')
+               );
+
+               $profile_url = $user_info["url"];
+               // message if nothing was found
+               if (count($r) == 0) 
+                       $success = array('success' => false, 'search_results' => 'nothing found');
+               else {
+                       $ret = Array();
+                       foreach($r as $item) {
+                               if ($box == "inbox" || $item['from-url'] != $profile_url){
+                                       $recipient = $user_info;
+                                       $sender = api_get_user($a,normalise_link($item['contact-url']));
+                               }
+                               elseif ($box == "sentbox" || $item['from-url'] == $profile_url){
+                                       $recipient = api_get_user($a,normalise_link($item['contact-url']));
+                                       $sender = $user_info;
+                               }
+                               $ret[]=api_format_messages($item, $recipient, $sender);
+                       }
+                       $success = array('success' => true, 'search_results' => $ret);
+               }
+
+               return api_format_data("direct_message_search", $type, array('$result' => $success));
+       }
+       api_register_func('api/friendica/direct_messages_search', 'api_friendica_direct_messages_search', true);
+
+
 /*
 To.Do:
     [pagename] => api/1.1/statuses/lookup.json