]> git.mxchange.org Git - quix0rs-gnu-social.git/blobdiff - lib/profileaction.php
XSS vulnerability when remote-subscribing
[quix0rs-gnu-social.git] / lib / profileaction.php
index f36f099c712b2947b438aa1129e6e0ddcf21029e..bdcd575b6b6b946cb5fa2ce2390960b4b60cd0f9 100644 (file)
  * @link      http://status.net/
  */
 
-if (!defined('STATUSNET') && !defined('LACONICA')) {
-    exit(1);
-}
-
-require_once INSTALLDIR.'/lib/profileminilist.php';
-require_once INSTALLDIR.'/lib/groupminilist.php';
+if (!defined('GNUSOCIAL')) { exit(1); }
 
 /**
  * Profile action common superclass
@@ -46,56 +41,70 @@ require_once INSTALLDIR.'/lib/groupminilist.php';
  * @license  http://www.fsf.org/licensing/licenses/agpl-3.0.html GNU Affero General Public License version 3.0
  * @link     http://status.net/
  */
-class ProfileAction extends Action
+abstract class ProfileAction extends ManagedAction
 {
     var $page    = null;
-    var $profile = null;
     var $tag     = null;
 
-    function prepare($args)
-    {
-        parent::prepare($args);
+    protected $target  = null;    // Profile that we're showing
 
-        $nickname_arg = $this->arg('nickname');
+    protected function doPreparation()
+    {
+        // showstream requires a nickname
+        $nickname_arg = $this->trimmed('nickname');
         $nickname     = common_canonical_nickname($nickname_arg);
 
         // Permanent redirect on non-canonical nickname
-
         if ($nickname_arg != $nickname) {
             $args = array('nickname' => $nickname);
             if ($this->arg('page') && $this->arg('page') != 1) {
                 $args['page'] = $this->arg['page'];
             }
-            common_redirect(common_local_url($this->trimmed('action'), $args), 301);
-            return false;
+            common_redirect(common_local_url($this->getActionName(), $args), 301);
         }
 
-        $this->user = User::getKV('nickname', $nickname);
+        try {
+            $user = User::getByNickname($nickname);
+        } catch (NoSuchUserException $e) {
+            $group = Local_group::getKV('nickname', $nickname);
+            if ($group instanceof Local_group) {
+                common_redirect($group->getProfile()->getUrl());
+            }
 
-        if (!$this->user) {
-            // TRANS: Client error displayed when calling a profile action without specifying a user.
-            $this->clientError(_('No such user.'), 404);
-            return false;
+            // No user nor group found, throw the NoSuchUserException again
+            throw $e;
         }
 
-        $this->profile = $this->user->getProfile();
-
-        if (!$this->profile) {
-            // TRANS: Error message displayed when referring to a user without a profile.
-            $this->serverError(_('User has no profile.'));
-            return false;
-        }
+        $this->target = $user->getProfile();
+    }
 
-        $user = common_current_user();
+    protected function prepare(array $args=array())
+    {
+        // this will call ->doPreparation() which child classes use to set $this->target
+        parent::prepare($args);
 
-        if ($this->profile->hasRole(Profile_role::SILENCED) &&
-            (empty($user) || !$user->hasRight(Right::SILENCEUSER))) {
+        if ($this->target->hasRole(Profile_role::SILENCED)
+                && (!$this->scoped instanceof Profile || !$this->scoped->hasRight(Right::SILENCEUSER))) {
             throw new ClientException(_('This profile has been silenced by site moderators'), 403);
         }
 
         $this->tag = $this->trimmed('tag');
         $this->page = ($this->arg('page')) ? ($this->arg('page')+0) : 1;
         common_set_returnto($this->selfUrl());
+
+        return true;
+    }
+
+    public function getTarget()
+    {
+        if (!$this->target instanceof Profile) {
+            throw new ServerException('No target profile in ProfileAction class');
+        }
+        return $this->target;
+    }
+
+    function isReadOnly($args)
+    {
         return true;
     }
 
@@ -118,7 +127,7 @@ class ProfileAction extends Action
     private function statsSectionLink($actionClass, $title, $cssClass='')
     {
         $this->element('a', array('href' => common_local_url($actionClass,
-                                                             array('nickname' => $this->profile->nickname)),
+                                                             array('nickname' => $this->target->getNickname())),
                                   'class' => $cssClass),
                        $title);
     }
@@ -132,11 +141,11 @@ class ProfileAction extends Action
             // TRANS: H2 text for user subscription statistics.
             $this->statsSectionLink('subscriptions', _('Following'));
             $this->text(' ');
-            $this->text($this->profile->subscriptionCount());
+            $this->text($this->target->subscriptionCount());
             $this->elementEnd('h2');
         
             try {
-                $profile = $this->profile->getSubscribed(0, PROFILES_PER_MINILIST + 1);
+                $profile = $this->target->getSubscribed(0, PROFILES_PER_MINILIST + 1);
                 $pml = new ProfileMiniList($profile, $this);
                 $pml->show();
             } catch (NoResultException $e) {
@@ -160,11 +169,11 @@ class ProfileAction extends Action
             // TRANS: H2 text for user subscriber statistics.
             $this->statsSectionLink('subscribers', _('Followers'));
             $this->text(' ');
-            $this->text($this->profile->subscriberCount());
+            $this->text($this->target->subscriberCount());
             $this->elementEnd('h2');
 
             try {
-                $profile = $this->profile->getSubscribers(0, PROFILES_PER_MINILIST + 1);
+                $profile = $this->target->getSubscribers(0, PROFILES_PER_MINILIST + 1);
                 $sml = new SubscribersMiniList($profile, $this);
                 $sml->show();
             } catch (NoResultException $e) {
@@ -180,8 +189,8 @@ class ProfileAction extends Action
 
     function showStatistics()
     {
-        $notice_count = $this->profile->noticeCount();
-        $age_days     = (time() - strtotime($this->profile->created)) / 86400;
+        $notice_count = $this->target->noticeCount();
+        $age_days     = (time() - strtotime($this->target->created)) / 86400;
         if ($age_days < 1) {
             // Rather than extrapolating out to a bajillion...
             $age_days = 1;
@@ -194,7 +203,7 @@ class ProfileAction extends Action
         // TRANS: H2 text for user statistics.
         $this->element('h2', null, _('Statistics'));
 
-        $profile = $this->profile;
+        $profile = $this->target;
         $actionParams = array('nickname' => $profile->nickname);
         $stats = array(
             array(
@@ -249,7 +258,7 @@ class ProfileAction extends Action
 
     function showGroups()
     {
-        $groups = $this->profile->getGroups(0, GROUPS_PER_MINILIST + 1);
+        $groups = $this->target->getGroups(0, GROUPS_PER_MINILIST + 1);
 
         $this->elementStart('div', array('id' => 'entity_groups',
                                          'class' => 'section'));
@@ -258,16 +267,15 @@ class ProfileAction extends Action
             // TRANS: H2 text for user group membership statistics.
             $this->statsSectionLink('usergroups', _('Groups'));
             $this->text(' ');
-            $this->text($this->profile->getGroups(0, null)->N);
+            $this->text($this->target->getGroupCount());
             $this->elementEnd('h2');
 
-            if ($groups) {
-                $gml = new GroupMiniList($groups, $this->profile, $this);
+            if ($groups instanceof User_group) {
+                $gml = new GroupMiniList($groups, $this->target, $this);
                 $cnt = $gml->show();
-                if ($cnt == 0) {
-                    // TRANS: Text for user user group membership statistics if user is not a member of any group.
-                    $this->element('p', null, _('(None)'));
-                }
+            } else {
+                // TRANS: Text for user user group membership statistics if user is not a member of any group.
+                $this->element('p', null, _('(None)'));
             }
 
             Event::handle('EndShowGroupsMiniList', array($this));
@@ -277,9 +285,7 @@ class ProfileAction extends Action
 
     function showLists()
     {
-        $cur = common_current_user();
-
-        $lists = $this->profile->getLists($cur);
+        $lists = $this->target->getLists($this->scoped);
 
         if ($lists->N > 0) {
             $this->elementStart('div', array('id' => 'entity_lists',
@@ -288,7 +294,7 @@ class ProfileAction extends Action
             if (Event::handle('StartShowListsMiniList', array($this))) {
 
                 $url = common_local_url('peopletagsbyuser',
-                                        array('nickname' => $this->profile->nickname));
+                                        array('nickname' => $this->target->getNickname()));
 
                 $this->elementStart('h2');
                 $this->element('a',
@@ -309,7 +315,7 @@ class ProfileAction extends Action
                         $url = $lists->mainpage;
                     } else {
                         $url = common_local_url('showprofiletag',
-                                                array('tagger' => $this->profile->nickname,
+                                                array('nickname' => $this->target->getNickname(),
                                                       'tag'    => $lists->tag));
                     }
                     if (!$first) {