]> git.mxchange.org Git - friendica.git/blobdiff - include/api.php
Removed Statusnet from the counting of contacts for scrape/noscrape
[friendica.git] / include / api.php
index a5bf161ccfe7be876b6503190bcdd0f7f6cde8e8..c8a313ce198e764187d505ca3d61c6f077001b3e 100644 (file)
                return false;
        }
 
+       function api_source() {
+               if (requestdata('source'))
+                       return (requestdata('source'));
+
+               // Support for known clients that doesn't send a source name
+               if (strstr($_SERVER['HTTP_USER_AGENT'], "Twidere"))
+                       return ("Twidere");
+
+               logger("Unrecognized user-agent ".$_SERVER['HTTP_USER_AGENT'], LOGGER_DEBUG);
+
+               return ("api");
+       }
+
        function api_date($str){
                //Wed May 23 06:01:13 +0000 2007
                return datetime_convert('UTC', 'UTC', $str, "D M d H:i:s +0000 Y" );
                }
 
                $user = $_SERVER['PHP_AUTH_USER'];
-               $encrypted = hash('whirlpool',trim($_SERVER['PHP_AUTH_PW']));
+               $password = $_SERVER['PHP_AUTH_PW'];
+               $encrypted = hash('whirlpool',trim($password));
 
 
                /**
                 *  next code from mod/auth.php. needs better solution
                 */
+               $record = null;
 
-               // process normal login request
-
-               $r = q("SELECT * FROM `user` WHERE ( `email` = '%s' OR `nickname` = '%s' )
-                       AND `password` = '%s' AND `blocked` = 0 AND `account_expired` = 0 AND `account_removed` = 0 AND `verified` = 1 LIMIT 1",
-                       dbesc(trim($user)),
-                       dbesc(trim($user)),
-                       dbesc($encrypted)
+               $addon_auth = array(
+                       'username' => trim($user), 
+                       'password' => trim($password),
+                       'authenticated' => 0,
+                       'user_record' => null
                );
-               if(count($r)){
-                       $record = $r[0];
-               } else {
+
+               /**
+                *
+                * A plugin indicates successful login by setting 'authenticated' to non-zero value and returning a user record
+                * Plugins should never set 'authenticated' except to indicate success - as hooks may be chained
+                * and later plugins should not interfere with an earlier one that succeeded.
+                *
+                */
+
+               call_hooks('authenticate', $addon_auth);
+
+               if(($addon_auth['authenticated']) && (count($addon_auth['user_record']))) {
+                       $record = $addon_auth['user_record'];
+               }
+               else {
+                       // process normal login request
+
+                       $r = q("SELECT * FROM `user` WHERE ( `email` = '%s' OR `nickname` = '%s' )
+                               AND `password` = '%s' AND `blocked` = 0 AND `account_expired` = 0 AND `account_removed` = 0 AND `verified` = 1 LIMIT 1",
+                               dbesc(trim($user)),
+                               dbesc(trim($user)),
+                               dbesc($encrypted)
+                       );
+                       if(count($r))
+                               $record = $r[0];
+               }
+
+               if((! $record) || (! count($record))) {
                        logger('API_login failure: ' . print_r($_SERVER,true), LOGGER_DEBUG);
                        header('WWW-Authenticate: Basic realm="Friendica"');
                        header('HTTP/1.0 401 Unauthorized');
 
                // preset
                $type="json";
-
                foreach ($API as $p=>$info){
                        if (strpos($a->query_string, $p)===0){
                                $called_api= explode("/",$p);
                                        case "json":
                                                header ("Content-Type: application/json");
                                                foreach($r as $rr)
-                                                       return json_encode($rr);
+                                                       $json = json_encode($rr);
+                                                       if ($_GET['callback'])
+                                                               $json = $_GET['callback']."(".$json.")";
+                                                       return $json;
                                                break;
                                        case "rss":
                                                header ("Content-Type: application/rss+xml");
        }
 
        function api_error(&$a, $type, $error) {
+               # TODO:  https://dev.twitter.com/overview/api/response-codes
                $r = "<status><error>".$error."</error><request>".$a->query_string."</request></status>";
                switch($type){
                        case "xml":
                        logger('api_statuses_update: no user');
                        return false;
                }
+
                $user_info = api_get_user($a);
 
                // convert $_POST array items to the form we use for web posts.
                if($parent)
                        $_REQUEST['type'] = 'net-comment';
                else {
+                       // Check for throttling (maximum posts per day, week and month)
+                       $throttle_day = get_config('system','throttle_limit_day');
+                       if ($throttle_day > 0) {
+                               $datefrom = date("Y-m-d H:i:s", time() - 24*60*60);
+
+                               $r = q("SELECT COUNT(*) AS `posts_day` FROM `item` WHERE `uid`=%d AND `wall`
+                                       AND `created` > '%s' AND `id` = `parent`",
+                                       intval(api_user()), dbesc($datefrom));
+
+                               if ($r)
+                                       $posts_day = $r[0]["posts_day"];
+                               else
+                                       $posts_day = 0;
+
+                               if ($posts_day > $throttle_day) {
+                                       logger('Daily posting limit reached for user '.api_user(), LOGGER_DEBUG);
+                                       die(api_error($a, $type, sprintf(t("Daily posting limit of %d posts reached. The post was rejected."), $throttle_day)));
+                               }
+                       }
+
+                       $throttle_week = get_config('system','throttle_limit_week');
+                       if ($throttle_week > 0) {
+                               $datefrom = date("Y-m-d H:i:s", time() - 24*60*60*7);
+
+                               $r = q("SELECT COUNT(*) AS `posts_week` FROM `item` WHERE `uid`=%d AND `wall`
+                                       AND `created` > '%s' AND `id` = `parent`",
+                                       intval(api_user()), dbesc($datefrom));
+
+                               if ($r)
+                                       $posts_week = $r[0]["posts_week"];
+                               else
+                                       $posts_week = 0;
+
+                               if ($posts_week > $throttle_week) {
+                                       logger('Weekly posting limit reached for user '.api_user(), LOGGER_DEBUG);
+                                       die(api_error($a, $type, sprintf(t("Weekly posting limit of %d posts reached. The post was rejected."), $throttle_week)));
+                               }
+                       }
+
+                       $throttle_month = get_config('system','throttle_limit_month');
+                       if ($throttle_month > 0) {
+                               $datefrom = date("Y-m-d H:i:s", time() - 24*60*60*30);
+
+                               $r = q("SELECT COUNT(*) AS `posts_month` FROM `item` WHERE `uid`=%d AND `wall`
+                                       AND `created` > '%s' AND `id` = `parent`",
+                                       intval(api_user()), dbesc($datefrom));
+
+                               if ($r)
+                                       $posts_month = $r[0]["posts_month"];
+                               else
+                                       $posts_month = 0;
+
+                               if ($posts_month > $throttle_month) {
+                                       logger('Monthly posting limit reached for user '.api_user(), LOGGER_DEBUG);
+                                       die(api_error($a, $type, sprintf(t("Monthly posting limit of %d posts reached. The post was rejected."), $throttle_month)));
+                               }
+                       }
+
                        $_REQUEST['type'] = 'wall';
                        if(x($_FILES,'media')) {
                                // upload the image if we have one
 
                $_REQUEST['api_source'] = true;
 
+               if (!x($_REQUEST, "source"))
+                       $_REQUEST["source"] = api_source();
+
                // call out normal post function
 
                require_once('mod/item.php');
                // get last public wall message
                $lastwall = q("SELECT `item`.*, `i`.`contact-id` as `reply_uid`, `i`.`author-link` AS `item-author`
                                FROM `item`, `item` as `i`
-                               WHERE `item`.`contact-id` = %d
+                               WHERE `item`.`contact-id` = %d AND `item`.`uid` = %d
                                        AND ((`item`.`author-link` IN ('%s', '%s')) OR (`item`.`owner-link` IN ('%s', '%s')))
                                        AND `i`.`id` = `item`.`parent`
                                        AND `item`.`type`!='activity'
                                ORDER BY `item`.`created` DESC
                                LIMIT 1",
                                intval($user_info['cid']),
+                               intval(api_user()),
                                dbesc($user_info['url']),
                                dbesc(normalise_link($user_info['url'])),
                                dbesc($user_info['url']),
                        $in_reply_to_status_id_str = NULL;
                        $in_reply_to_user_id_str = NULL;
                        $in_reply_to_screen_name = NULL;
-                       if ($lastwall['parent']!=$lastwall['id']) {
+                       if (intval($lastwall['parent']) != intval($lastwall['id'])) {
                                $in_reply_to_status_id= intval($lastwall['parent']);
                                $in_reply_to_status_id_str = (string) intval($lastwall['parent']);
 
                                }
                        }
 
+                       // There seems to be situation, where both fields are identical:
+                       // https://github.com/friendica/friendica/issues/1010
+                       // This is a bugfix for that.
+                       if (intval($in_reply_to_status_id) == intval($lastwall['id'])) {
+                               logger('api_status_show: this message should never appear: id: '.$lastwall['id'].' similar to reply-to: '.$in_reply_to_status_id, LOGGER_DEBUG);
+                               $in_reply_to_status_id = NULL;
+                               $in_reply_to_user_id = NULL;
+                               $in_reply_to_status_id_str = NULL;
+                               $in_reply_to_user_id_str = NULL;
+                               $in_reply_to_screen_name = NULL;
+                       }
+
+                       $converted = api_convert_item($item);
+
                        $status_info = array(
-                               'text' => trim(html2plain(bbcode(api_clean_plain_items($lastwall['body']), false, false, 2, true), 0)),
+                               'text' => $converted["text"],
                                'truncated' => false,
                                'created_at' => api_date($lastwall['created']),
                                'in_reply_to_status_id' => $in_reply_to_status_id,
                                'in_reply_to_user_id_str' => $in_reply_to_user_id_str,
                                'in_reply_to_screen_name' => $in_reply_to_screen_name,
                                'geo' => NULL,
-                               'favorited' => false,
-                               // attachments
+                               'favorited' => $lastwall['starred'] ? true : false,
                                'user' => $user_info,
-                               'statusnet_html'                => trim(bbcode($lastwall['body'], false, false)),
+                               'statusnet_html'                => $converted["html"],
                                'statusnet_conversation_id'     => $lastwall['parent'],
                        );
 
-                       if ($lastwall['title'] != "")
-                               $status_info['statusnet_html'] = "<h4>".bbcode($lastwall['title'])."</h4>\n".$status_info['statusnet_html'];
+                       if (count($converted["attachments"]) > 0)
+                               $status_info["attachments"] = $converted["attachments"];
 
-                       $entities = api_get_entitities($status_info['text'], $lastwall['body']);
-                       if (count($entities) > 0)
-                               $status_info['entities'] = $entities;
+                       if (count($converted["entities"]) > 0)
+                               $status_info["entities"] = $converted["entities"];
 
                        if (($lastwall['item_network'] != "") AND ($status["source"] == 'web'))
                                $status_info["source"] = network_to_name($lastwall['item_network']);
                                        }
                                }
                        }
+
+                       $converted = api_convert_item($item);
+
                        $user_info['status'] = array(
-                               'text' => trim(html2plain(bbcode(api_clean_plain_items($lastwall['body']), false, false, 2, true), 0)),
+                               'text' => $converted["text"],
                                'truncated' => false,
                                'created_at' => api_date($lastwall['created']),
                                'in_reply_to_status_id' => $in_reply_to_status_id,
                                'in_reply_to_user_id_str' => $in_reply_to_user_id_str,
                                'in_reply_to_screen_name' => $in_reply_to_screen_name,
                                'geo' => NULL,
-                               'favorited' => false,
-                               'statusnet_html'                => trim(bbcode($lastwall['body'], false, false)),
+                               'favorited' => $lastwall['starred'] ? true : false,
+                               'statusnet_html'                => $converted["html"],
                                'statusnet_conversation_id'     => $lastwall['parent'],
                        );
 
-                       if ($lastwall['title'] != "")
-                               $user_info['statusnet_html'] = "<h4>".bbcode($lastwall['title'])."</h4>\n".$user_info['statusnet_html'];
+                       if (count($converted["attachments"]) > 0)
+                               $user_info["status"]["attachments"] = $converted["attachments"];
 
-                       $entities = api_get_entitities($user_info['text'], $lastwall['body']);
-                       if (count($entities) > 0)
-                               $user_info['entities'] = $entities;
+                       if (count($converted["entities"]) > 0)
+                               $user_info["status"]["entities"] = $converted["entities"];
 
                        if (($lastwall['item_network'] != "") AND ($user_info["status"]["source"] == 'web'))
                                $user_info["status"]["source"] = network_to_name($lastwall['item_network']);
        }
        api_register_func('api/users/show','api_users_show');
 
+
+       function api_users_search(&$a, $type) {
+               $page = (x($_REQUEST,'page')?$_REQUEST['page']-1:0);
+
+               $userlist = array();
+
+               if (isset($_GET["q"])) {
+                       $r = q("SELECT id FROM unique_contacts WHERE name='%s'", dbesc($_GET["q"]));
+                       if (!count($r))
+                               $r = q("SELECT id FROM unique_contacts WHERE nick='%s'", dbesc($_GET["q"]));
+
+                       if (count($r)) {
+                               foreach ($r AS $user) {
+                                       $user_info = api_get_user($a, $user["id"]);
+                                       //echo print_r($user_info, true)."\n";
+                                       $userdata = api_apply_template("user", $type, array('user' => $user_info));
+                                       $userlist[] = $userdata["user"];
+                               }
+                               $userlist = array("users" => $userlist);
+                       } else
+                               die(api_error($a, $type, t("User not found.")));
+               } else
+                       die(api_error($a, $type, t("User not found.")));
+
+               return ($userlist);
+       }
+
+       api_register_func('api/users/search','api_users_search');
+
        /**
         *
         * http://developer.twitter.com/doc/get/statuses/home_timeline
 
                // We aren't going to try to figure out at the item, group, and page
                // level which items you've seen and which you haven't. If you're looking
-               // at the network timeline just mark everything seen. 
+               // at the network timeline just mark everything seen.
 
-               $r = q("UPDATE `item` SET `unseen` = 0 
+               $r = q("UPDATE `item` SET `unseen` = 0
                        WHERE `unseen` = 1 AND `uid` = %d",
                        //intval($user_info['uid'])
                        intval(api_user())
        api_register_func('api/statuses/public_timeline','api_statuses_public_timeline', true);
 
        /**
-        * 
+        *
         */
        function api_statuses_show(&$a, $type){
                if (api_user()===false) return false;
                        `contact`.`id` AS `cid`, `contact`.`uid` AS `contact-uid`
                        FROM `item`, `contact`
                        WHERE `item`.`visible` = 1 and `item`.`moderated` = 0 AND `item`.`deleted` = 0
-                       AND `contact`.`id` = `item`.`contact-id`
+                       AND `contact`.`id` = `item`.`contact-id` AND `item`.`uid` = %d AND `item`.`verb` = '%s'
                        AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
                        $sql_extra",
+                       intval(api_user()),
+                       dbesc(ACTIVITY_POST),
                        intval($id)
                );
 
                        $_REQUEST['type'] = 'wall';
                        $_REQUEST['api_source'] = true;
 
+                       if (!x($_REQUEST, "source"))
+                               $_REQUEST["source"] = api_source();
+
                        require_once('mod/item.php');
                        item_post($a);
                }
        api_register_func('api/statuses/destroy','api_statuses_destroy', true);
 
        /**
-        * 
+        *
         * http://developer.twitter.com/doc/get/statuses/mentions
-        * 
+        *
         */
        function api_statuses_mentions(&$a, $type){
                if (api_user()===false) return false;
                        AND `item`.`visible` = 1 and `item`.`moderated` = 0 AND `item`.`deleted` = 0
                        AND `contact`.`id` = `item`.`contact-id`
                        AND `contact`.`blocked` = 0 AND `contact`.`pending` = 0
-                       AND `item`.`parent` IN (SELECT `iid` from thread where uid = %d AND `mention`)
+                       AND `item`.`parent` IN (SELECT `iid` from thread where uid = %d AND `mention` AND !`ignored`)
                        $sql_extra
                        AND `item`.`id`>%d
                        ORDER BY `item`.`id` DESC LIMIT %d ,%d ",
        api_register_func('api/statuses/user_timeline','api_statuses_user_timeline', true);
 
 
+       /**
+        * Star/unstar an item
+        * param: id : id of the item
+        *
+        * api v1 : https://web.archive.org/web/20131019055350/https://dev.twitter.com/docs/api/1/post/favorites/create/%3Aid
+        */
+       function api_favorites_create_destroy(&$a, $type){
+               if (api_user()===false) return false;
+
+               # for versioned api.
+               # TODO: we need a better global soluton
+               $action_argv_id=2;
+               if ($a->argv[1]=="1.1") $action_argv_id=3;
+
+               if ($a->argc<=$action_argv_id) die(api_error($a, $type, t("Invalid request.")));
+               $action = str_replace(".".$type,"",$a->argv[$action_argv_id]);
+               if ($a->argc==$action_argv_id+2) {
+                       $itemid = intval($a->argv[$action_argv_id+1]);
+               } else {
+                       $itemid = intval($_REQUEST['id']);
+               }
+
+               $item = q("SELECT * FROM item WHERE id=%d AND uid=%d",
+                               $itemid, api_user());
+
+               if ($item===false || count($item)==0) die(api_error($a, $type, t("Invalid item.")));
+
+               switch($action){
+                       case "create":
+                               $item[0]['starred']=1;
+                               break;
+                       case "destroy":
+                               $item[0]['starred']=0;
+                               break;
+                       default:
+                               die(api_error($a, $type, t("Invalid action. ".$action)));
+               }
+               $r = q("UPDATE item SET starred=%d WHERE id=%d AND uid=%d",
+                               $item[0]['starred'], $itemid, api_user());
+
+               q("UPDATE thread SET starred=%d WHERE iid=%d AND uid=%d",
+                       $item[0]['starred'], $itemid, api_user());
+
+               if ($r===false) die(api_error($a, $type, t("DB error")));
+
+
+               $user_info = api_get_user($a);
+               $rets = api_format_items($item,$user_info);
+               $ret = $rets[0];
+
+               $data = array('$status' => $ret);
+               switch($type){
+                       case "atom":
+                       case "rss":
+                               $data = api_rss_extra($a, $data, $user_info);
+               }
+
+               return api_apply_template("status", $type, $data);
+       }
+
+       api_register_func('api/favorites/create', 'api_favorites_create_destroy', true);
+       api_register_func('api/favorites/destroy', 'api_favorites_create_destroy', true);
+
        function api_favorites(&$a, $type){
                global $called_api;
 
                                `contact`.`network`, `contact`.`thumb`, `contact`.`dfrn-id`, `contact`.`self`,
                                `contact`.`id` AS `cid`, `contact`.`uid` AS `contact-uid`
                                FROM `item`, `contact`
-                               WHERE `item`.`uid` = %d AND `verb` = '%s'
+                               WHERE `item`.`uid` = %d
                                AND `item`.`visible` = 1 and `item`.`moderated` = 0 AND `item`.`deleted` = 0
                                AND `item`.`starred` = 1
                                AND `contact`.`id` = `item`.`contact-id`
                                AND `item`.`id`>%d
                                ORDER BY `item`.`id` DESC LIMIT %d ,%d ",
                                intval(api_user()),
-                               dbesc(ACTIVITY_POST),
                                intval($since_id),
                                intval($start), intval($count)
                        );
 
        api_register_func('api/favorites','api_favorites', true);
 
+
+
+
        function api_format_as($a, $ret, $user_info) {
 
                $as = array();
                return $ret;
        }
 
-       function api_get_entitities($text, $bbcode) {
+       function api_convert_item($item) {
+
+               $body = $item['body'];
+               $attachments = api_get_attachments($body);
+
+               // Workaround for ostatus messages where the title is identically to the body
+               $html = bbcode(api_clean_plain_items($body), false, false, 2, true);
+               $statusbody = trim(html2plain($html, 0));
+
+               // handle data: images
+               $statusbody = api_format_items_embeded_images($item,$statusbody);
+
+               $statustitle = trim($item['title']);
+
+               if (($statustitle != '') and (strpos($statusbody, $statustitle) !== false))
+                       $statustext = trim($statusbody);
+               else
+                       $statustext = trim($statustitle."\n\n".$statusbody);
+
+               if (($item["network"] == NETWORK_FEED) and (strlen($statustext)> 1000))
+                       $statustext = substr($statustext, 0, 1000)."... \n".$item["plink"];
+
+               $statushtml = trim(bbcode($body, false, false));
+
+               if ($item['title'] != "")
+                       $statushtml = "<h4>".bbcode($item['title'])."</h4>\n".$statushtml;
+
+               $entities = api_get_entitities($statustext, $body);
+
+               return(array("text" => $statustext, "html" => $statushtml, "attachments" => $attachments, "entities" => $entities));
+       }
+
+       function api_get_attachments(&$body) {
+
+               $text = $body;
+               $text = preg_replace("/\[img\=([0-9]*)x([0-9]*)\](.*?)\[\/img\]/ism", '[img]$3[/img]', $text);
+
+               $URLSearchString = "^\[\]";
+               $ret = preg_match_all("/\[img\]([$URLSearchString]*)\[\/img\]/ism", $text, $images);
+
+               if (!$ret)
+                       return false;
+
+               require_once("include/Photo.php");
+
+               $attachments = array();
+
+               foreach ($images[1] AS $image) {
+                       $imagedata = get_photo_info($image);
+
+                       if ($imagedata)
+                               $attachments[] = array("url" => $image, "mimetype" => $imagedata["mime"], "size" => $imagedata["size"]);
+               }
+
+               if (strstr($_SERVER['HTTP_USER_AGENT'], "AndStatus"))
+                       foreach ($images[0] AS $orig)
+                               $body = str_replace($orig, "", $body);
+
+               return $attachments;
+       }
+
+       function api_get_entitities(&$text, $bbcode) {
                /*
                To-Do:
                * Links at the first character of the post
-               * different sizes of pictures
-               * caching picture data (using the id for that?) (See privacy_image_cache)
                */
 
+               $a = get_app();
+
                $include_entities = strtolower(x($_REQUEST,'include_entities')?$_REQUEST['include_entities']:"false");
 
-               if ($include_entities != "true")
+               if ($include_entities != "true") {
+                       require_once("mod/proxy.php");
+
+                       preg_match_all("/\[img](.*?)\[\/img\]/ism", $bbcode, $images);
+
+                       foreach ($images[1] AS $image) {
+                               $replace = proxy_url($image);
+                               $text = str_replace($image, $replace, $text);
+                       }
                        return array();
+               }
 
                $bbcode = bb_CleanPictureLinks($bbcode);
 
                                        '[url=https://www.youtube.com/watch?v=$1]https://www.youtube.com/watch?v=$1[/url]', $bbcode);
                $bbcode = preg_replace("/\[youtube\](.*?)\[\/youtube\]/ism",'[url=$1]$1[/url]',$bbcode);
 
-               $Text = preg_replace("/\[vimeo\]([0-9]+)(.*?)\[\/vimeo\]/ism",
+               $bbcode = preg_replace("/\[vimeo\]([0-9]+)(.*?)\[\/vimeo\]/ism",
                                        '[url=https://vimeo.com/$1]https://vimeo.com/$1[/url]', $bbcode);
                $bbcode = preg_replace("/\[vimeo\](.*?)\[\/vimeo\]/ism",'[url=$1]$1[/url]',$bbcode);
 
 
                        $start = iconv_strpos($text, $url, $offset, "UTF-8");
                        if (!($start === false)) {
-                               $redirects = 0;
-                               $img_str = fetch_url($url,true, $redirects, 10);
-                               $image = @imagecreatefromstring($img_str);
+                               require_once("include/Photo.php");
+                               $image = get_photo_info($url);
                                if ($image) {
+                                       // If image cache is activated, then use the following sizes:
+                                       // thumb  (150), small (340), medium (600) and large (1024)
+                                       if (!get_config("system", "proxy_disabled")) {
+                                               require_once("mod/proxy.php");
+                                               $media_url = proxy_url($url);
+
+                                               $sizes = array();
+                                               $scale = scale_image($image[0], $image[1], 150);
+                                               $sizes["thumb"] = array("w" => $scale["width"], "h" => $scale["height"], "resize" => "fit");
+
+                                               if (($image[0] > 150) OR ($image[1] > 150)) {
+                                                       $scale = scale_image($image[0], $image[1], 340);
+                                                       $sizes["small"] = array("w" => $scale["width"], "h" => $scale["height"], "resize" => "fit");
+                                               }
+
+                                               $scale = scale_image($image[0], $image[1], 600);
+                                               $sizes["medium"] = array("w" => $scale["width"], "h" => $scale["height"], "resize" => "fit");
+
+                                               if (($image[0] > 600) OR ($image[1] > 600)) {
+                                                       $scale = scale_image($image[0], $image[1], 1024);
+                                                       $sizes["large"] = array("w" => $scale["width"], "h" => $scale["height"], "resize" => "fit");
+                                               }
+                                       } else {
+                                               $media_url = $url;
+                                               $sizes["medium"] = array("w" => $image[0], "h" => $image[1], "resize" => "fit");
+                                       }
+
                                        $entities["media"][] = array(
                                                                "id" => $start+1,
                                                                "id_str" => (string)$start+1,
                                                                "indices" => array($start, $start+strlen($url)),
-                                                               "media_url" => $url,
-                                                               "media_url_https" => $url,
+                                                               "media_url" => normalise_link($media_url),
+                                                               "media_url_https" => $media_url,
                                                                "url" => $url,
                                                                "display_url" => $display_url,
                                                                "expanded_url" => $url,
                                                                "type" => "photo",
-                                                               "sizes" => array("medium" => array(
-                                                                                               "w" => imagesx($image),
-                                                                                               "h" => imagesy($image),
-                                                                                               "resize" => "fit")));
+                                                               "sizes" => $sizes);
                                }
                                $offset = $start + 1;
                        }
 
                return($entities);
        }
+       function api_format_items_embeded_images($item, $text){
+               $a = get_app();
+               $text = preg_replace_callback(
+                               "|data:image/([^;]+)[^=]+=*|m",
+                               function($match) use ($a, $item) {
+                                       return $a->get_baseurl()."/display/".$item['guid'];
+                               },
+                               $text);
+               return $text;
+       }
 
        function api_format_items($r,$user_info, $filter_user = false) {
 
                $ret = Array();
 
                foreach($r as $item) {
-                       api_share_as_retweet($a, api_user(), $item);
+                       api_share_as_retweet($item);
 
                        localize_item($item);
                        $status_user = api_item_get_user($a,$item);
                                $in_reply_to_status_id_str = NULL;
                        }
 
-                       // Workaround for ostatus messages where the title is identically to the body
-                       //$statusbody = trim(html2plain(bbcode(api_clean_plain_items($item['body']), false, false, 5, true), 0));
-                       $html = bbcode(api_clean_plain_items($item['body']), false, false, 2, true);
-                       $statusbody = trim(html2plain($html, 0));
-
-                       $statustitle = trim($item['title']);
-
-                       if (($statustitle != '') and (strpos($statusbody, $statustitle) !== false))
-                               $statustext = trim($statusbody);
-                       else
-                               $statustext = trim($statustitle."\n\n".$statusbody);
-
-                       if (($item["network"] == NETWORK_FEED) and (strlen($statustext)> 1000))
-                               $statustext = substr($statustext, 0, 1000)."... \n".$item["plink"];
+                       $converted = api_convert_item($item);
 
                        $status = array(
-                               'text'          => $statustext,
+                               'text'          => $converted["text"],
                                'truncated' => False,
                                'created_at'=> api_date($item['created']),
                                'in_reply_to_status_id' => $in_reply_to_status_id,
                                'in_reply_to_screen_name' => $in_reply_to_screen_name,
                                'geo' => NULL,
                                'favorited' => $item['starred'] ? true : false,
-                               //'attachments' => array(),
                                'user' =>  $status_user ,
                                //'entities' => NULL,
-                               'statusnet_html'                => trim(bbcode($item['body'], false, false)),
+                               'statusnet_html'                => $converted["html"],
                                'statusnet_conversation_id'     => $item['parent'],
                        );
 
-                       if ($item['title'] != "")
-                               $status['statusnet_html'] = "<h4>".bbcode($item['title'])."</h4>\n".$status['statusnet_html'];
+                       if (count($converted["attachments"]) > 0)
+                               $status["attachments"] = $converted["attachments"];
 
-                       $entities = api_get_entitities($status['text'], $item['body']);
-                       if (count($entities) > 0)
-                               $status['entities'] = $entities;
+                       if (count($converted["entities"]) > 0)
+                               $status["entities"] = $converted["entities"];
 
                        if (($item['item_network'] != "") AND ($status["source"] == 'web'))
                                $status["source"] = network_to_name($item['item_network']);
        function api_direct_messages_box(&$a, $type, $box) {
                if (api_user()===false) return false;
 
-               unset($_REQUEST["user_id"]);
-               unset($_GET["user_id"]);
-
-               unset($_REQUEST["screen_name"]);
-               unset($_GET["screen_name"]);
-
-               $user_info = api_get_user($a);
 
                // params
                $count = (x($_GET,'count')?$_GET['count']:20);
                $since_id = (x($_REQUEST,'since_id')?$_REQUEST['since_id']:0);
                $max_id = (x($_REQUEST,'max_id')?$_REQUEST['max_id']:0);
 
-               $start = $page*$count;
+               $user_id = (x($_REQUEST,'user_id')?$_REQUEST['user_id']:"");
+               $screen_name = (x($_REQUEST,'screen_name')?$_REQUEST['screen_name']:"");
+
+               //  caller user info
+               unset($_REQUEST["user_id"]);
+               unset($_GET["user_id"]);
 
+               unset($_REQUEST["screen_name"]);
+               unset($_GET["screen_name"]);
+
+               $user_info = api_get_user($a);
                //$profile_url = $a->get_baseurl() . '/profile/' . $a->user['nickname'];
                $profile_url = $user_info["url"];
 
+
+               // pagination
+               $start = $page*$count;
+
+               // filters
                if ($box=="sentbox") {
                        $sql_extra = "`mail`.`from-url`='".dbesc( $profile_url )."'";
                }
                if ($max_id > 0)
                        $sql_extra .= ' AND `mail`.`id` <= '.intval($max_id);
 
+               if ($user_id !="") {
+                       $sql_extra .= ' AND `mail`.`contact-id` = ' . intval($user_id);
+               }
+               elseif($screen_name !=""){
+                       $sql_extra .= " AND `contact`.`nick` = '" . dbesc($screen_name). "'";
+               }
+
                $r = q("SELECT `mail`.*, `contact`.`nurl` AS `contact-url` FROM `mail`,`contact` WHERE `mail`.`contact-id` = `contact`.`id` AND `mail`.`uid`=%d AND $sql_extra AND `mail`.`id` > %d ORDER BY `mail`.`id` DESC LIMIT %d,%d",
                                intval(api_user()),
                                intval($since_id),
                                intval($start), intval($count)
                );
 
+
                $ret = Array();
                foreach($r as $item) {
                        if ($box == "inbox" || $item['from-url'] != $profile_url){
                                $recipient = $user_info;
                                $sender = api_get_user($a,normalise_link($item['contact-url']));
                        }
-                       elseif ($box == "sentbox" || $item['from-url'] != $profile_url){
+                       elseif ($box == "sentbox" || $item['from-url'] == $profile_url){
                                $recipient = api_get_user($a,normalise_link($item['contact-url']));
                                $sender = $user_info;
 
                        }
-
                        $ret[]=api_format_messages($item, $recipient, $sender);
                }
 
        api_register_func('api/oauth/request_token', 'api_oauth_request_token', false);
        api_register_func('api/oauth/access_token', 'api_oauth_access_token', false);
 
-function api_share_as_retweet($a, $uid, &$item) {
+
+       function api_fr_photos_list(&$a,$type) {
+               if (api_user()===false) return false;
+               $r = q("select distinct `resource-id` from photo where uid = %d and album != 'Contact Photos' ",
+                       intval(local_user())
+               );
+               if($r) {
+                       $ret = array();
+                       foreach($r as $rr)
+                               $ret[] = $rr['resource-id'];
+                       header("Content-type: application/json");
+                       echo json_encode($ret);
+               }
+               killme();
+       }
+
+       function api_fr_photo_detail(&$a,$type) {
+               if (api_user()===false) return false;
+               if(! $_REQUEST['photo_id']) return false;
+               $scale = ((array_key_exists('scale',$_REQUEST)) ? intval($_REQUEST['scale']) : 0);
+               $r = q("select * from photo where uid = %d and `resource-id` = '%s' and scale = %d limit 1",
+                       intval(local_user()),
+                       dbesc($_REQUEST['photo_id']),
+                       intval($scale)
+               );
+               if($r) {
+                       header("Content-type: application/json");
+                       $r[0]['data'] = base64_encode($r[0]['data']);
+                       echo json_encode($r[0]);
+               }
+
+               killme();
+       }
+
+       api_register_func('api/friendica/photos/list', 'api_fr_photos_list', true);
+       api_register_func('api/friendica/photo', 'api_fr_photo_detail', true);
+
+
+
+function api_share_as_retweet(&$item) {
        $body = trim($item["body"]);
 
        // Skip if it isn't a pure repeated messages
@@ -2307,6 +2665,15 @@ function api_share_as_retweet($a, $uid, &$item) {
        if ($matches[1] != "")
                $avatar = $matches[1];
 
+       $link = "";
+       preg_match("/link='(.*?)'/ism", $attributes, $matches);
+       if ($matches[1] != "")
+               $link = $matches[1];
+
+       preg_match('/link="(.*?)"/ism', $attributes, $matches);
+       if ($matches[1] != "")
+               $link = $matches[1];
+
        $shared_body = preg_replace("/\[share(.*?)\]\s?(.*?)\s?\[\/share\]\s?/ism","$2",$body);
 
        if (($shared_body == "") OR ($profile == "") OR ($author == "") OR ($avatar == ""))
@@ -2316,6 +2683,7 @@ function api_share_as_retweet($a, $uid, &$item) {
        $item["author-name"] = $author;
        $item["author-link"] = $profile;
        $item["author-avatar"] = $avatar;
+       $item["plink"] = $link;
 
        return(true);
 
@@ -2473,9 +2841,6 @@ function api_best_nickname(&$contacts) {
 
 /*
 Not implemented by now:
-favorites
-favorites/create
-favorites/destroy
 statuses/retweets_of_me
 friendships/create
 friendships/destroy