]> git.mxchange.org Git - friendica.git/blobdiff - mod/dfrn_request.php
Merge branch 'omigeot-master'
[friendica.git] / mod / dfrn_request.php
index 3c16e2560a14851aeb1637f44429e2473650c167..24c466bba5655e9533073ffe5d89d383e7ffb9cb 100644 (file)
@@ -1,18 +1,41 @@
 <?php
 
+/**
+ *
+ * Module: dfrn_request
+ *
+ * Purpose: Handles communication associated with the issuance of
+ * friend requests.
+ *
+ */
+
 if(! function_exists('dfrn_request_init')) {
 function dfrn_request_init(&$a) {
 
        if($a->argc > 1)
                $which = $a->argv[1];
 
-       require_once('mod/profile.php');
-       profile_init($a,$which);
-
+       profile_load($a,$which);
        return;
 }}
 
 
+/**
+ * Function: dfrn_request_post
+ *
+ * Purpose:
+ * Handles multiple scenarios.
+ *
+ * Scenario 1:
+ * Clicking 'submit' on a friend request page.
+ *
+ * Scenario 2:
+ * Following Scenario 1, we are brought back to our home site
+ * in order to link our friend request with our own server cell.
+ * After logging in, we click 'submit' to approve the linkage.
+ *
+ */
+
 if(! function_exists('dfrn_request_post')) {
 function dfrn_request_post(&$a) {
 
@@ -25,32 +48,47 @@ function dfrn_request_post(&$a) {
        } 
 
 
-       // We've introduced ourself to another cell, then have been returned to our own cell
-       // to confirm the request, and then we've clicked submit (perhaps after logging in). 
-       // That brings us here:
+       /**
+        *
+        * Scenario 2: We've introduced ourself to another cell, then have been returned to our own cell
+        * to confirm the request, and then we've clicked submit (perhaps after logging in). 
+        * That brings us here:
+        *
+        */
 
        if((x($_POST,'localconfirm')) && ($_POST['localconfirm'] == 1)) {
 
-               // Ensure this is a valid request
+               /**
+                * Ensure this is a valid request
+                */
+
                if(local_user() && ($a->user['nickname'] == $a->argv[1]) && (x($_POST,'dfrn_url'))) {
 
 
-                       $dfrn_url = notags(trim($_POST['dfrn_url']));
-                       $aes_allow = (((x($_POST,'aes_allow')) && ($_POST['aes_allow'] == 1)) ? 1 : 0);
+                       $dfrn_url    = notags(trim($_POST['dfrn_url']));
+                       $aes_allow   = (((x($_POST,'aes_allow')) && ($_POST['aes_allow'] == 1)) ? 1 : 0);
                        $confirm_key = ((x($_POST,'confirm_key')) ? $_POST['confirm_key'] : "");
 
                        $contact_record = null;
        
                        if(x($dfrn_url)) {
+
+                               /**
+                                * Lookup the contact based on their URL (which is the only unique thing we have at the moment)
+                                */
        
-                               $r = q("SELECT * FROM `contact` WHERE `uid` = %d AND `url` = '%s' LIMIT 1",
-                                       intval(get_uid()),
+                               $r = q("SELECT * FROM `contact` WHERE `uid` = %d AND `url` = '%s' AND `self` = 0 LIMIT 1",
+                                       intval(local_user()),
                                        dbesc($dfrn_url)
                                );
        
                                if(count($r)) {
                                        if(strlen($r[0]['dfrn-id'])) {
+
+                                               /**
+                                                * We don't need to be here. It has already happened.
+                                                */
+
                                                notice( t("This introduction has already been accepted.") . EOL );
                                                return;
                                        }
@@ -66,9 +104,12 @@ function dfrn_request_post(&$a) {
                                }
                                else {
        
+                                       /**
+                                        * Scrape the other site's profile page to pick up the dfrn links, key, fn, and photo
+                                        */
+
                                        require_once('Scrape.php');
        
-       
                                        $parms = scrape_dfrn($dfrn_url);
        
                                        if(! count($parms)) {
@@ -89,20 +130,26 @@ function dfrn_request_post(&$a) {
                                                }
                                        }
 
-
-
                                        $dfrn_request = $parms['dfrn-request'];
 
+                    /********* Escape the entire array ********/
+
                                        dbesc_array($parms);
 
+                                       /******************************************/
+
+                                       /**
+                                        * Create a contact record on our site for the other person
+                                        */
 
-                                       $r = q("INSERT INTO `contact` ( `uid`, `created`,`url`, `name`, `photo`, `site-pubkey`,
+                                       $r = q("INSERT INTO `contact` ( `uid`, `created`,`url`, `name`, `nick`, `photo`, `site-pubkey`,
                                                `request`, `confirm`, `notify`, `poll`, `aes_allow`) 
-                                               VALUES ( %d, '%s', '%s', '%s' , '%s', '%s', '%s', '%s', '%s', '%s', %d)",
-                                               intval(get_uid()),
+                                               VALUES ( %d, '%s', '%s', '%s' , '%s', '%s', '%s', '%s', '%s', '%s', '%s', %d)",
+                                               intval(local_user()),
                                                datetime_convert(),
                                                dbesc($dfrn_url),
                                                $parms['fn'],
+                                               $parms['nick'],
                                                $parms['photo'],
                                                $parms['key'],
                                                $parms['dfrn-request'],
@@ -117,14 +164,18 @@ function dfrn_request_post(&$a) {
                                        notice( t("Introduction complete.") . EOL);
                                }
 
-                               // Allow the blocked remote notification to complete
+                               /**
+                                * Allow the blocked remote notification to complete
+                                */
 
                                if(is_array($contact_record))
                                        $dfrn_request = $contact_record['request'];
 
                                if(strlen($dfrn_request) && strlen($confirm_key))
                                        $s = fetch_url($dfrn_request . '?confirm_key=' . $confirm_key);
-                                       // ignore reply
+                               
+                               // (ignore reply, nothing we can do it failed)
+
                                goaway($dfrn_url);
                                return; // NOTREACHED
 
@@ -139,40 +190,84 @@ function dfrn_request_post(&$a) {
                return; // NOTREACHED
        }
 
-       // Otherwise:
-
-       // We are the requestee. A person from a remote cell has made an introduction 
-       // on our profile web page and clicked submit. We will use their DFRN-URL to 
-       // figure out how to contact their cell.  
-
-       // Scrape the originating DFRN-URL for everything we need. Create a contact record
-       // and an introduction to show our user next time he/she logs in.
-       // Finally redirect back to the requestor so that their site can record the request.
-       // If our user (the requestee) later confirms this request, a record of it will need 
-       // to exist on the requestor's cell in order for the confirmation process to complete.. 
-
-       // It's possible that neither the requestor or the requestee are logged in at the moment,
-       // and the requestor does not yet have any credentials to the requestee profile.
-
-       // Who is the requestee? We've already loaded their profile which means their nickname should be
-       // in $a->argv[1] and we should have their complete info in $a->profile.
+       /**
+        * Otherwise:
+        * 
+        * Scenario 1:
+        * We are the requestee. A person from a remote cell has made an introduction 
+        * on our profile web page and clicked submit. We will use their DFRN-URL to 
+        * figure out how to contact their cell.  
+        *
+        * Scrape the originating DFRN-URL for everything we need. Create a contact record
+        * and an introduction to show our user next time he/she logs in.
+        * Finally redirect back to the requestor so that their site can record the request.
+        * If our user (the requestee) later confirms this request, a record of it will need 
+        * to exist on the requestor's cell in order for the confirmation process to complete.. 
+        *
+        * It's possible that neither the requestor or the requestee are logged in at the moment,
+        * and the requestor does not yet have any credentials to the requestee profile.
+        *
+        * Who is the requestee? We've already loaded their profile which means their nickname should be
+        * in $a->argv[1] and we should have their complete info in $a->profile.
+        *
+        */
 
        if(! (is_array($a->profile) && count($a->profile))) {
                notice( t('Profile unavailable.') . EOL);
                return;
        }
 
-       $nickname = $a->profile['nickname'];
-       $notify_flags = $a->profile['notify-flags'];
-       $uid = $a->profile['uid'];
-
+       $nickname       = $a->profile['nickname'];
+       $notify_flags   = $a->profile['notify-flags'];
+       $uid            = $a->profile['uid'];
+       $maxreq         = intval($a->profile['maxreq']);
        $contact_record = null;
-       $failed = false;
-       $parms = null;
+       $failed         = false;
+       $parms          = null;
 
 
        if( x($_POST,'dfrn_url')) {
 
+               /**
+                * Block friend request spam
+                */
+
+               if($maxreq) {
+                       $r = q("SELECT * FROM `intro` WHERE `datetime` > '%s' AND `uid` = %d",
+                               dbesc(datetime_convert('UTC','UTC','now - 24 hours')),
+                               intval($uid)
+                       );
+                       if(count($r) > $maxreq) {
+                               notice( $a->profile['name'] . t(' has received too many connection requests today.') . EOL);
+                               notice( t('Spam protection measures have been invoked.') . EOL);
+                               notice( t('Friends are advised to please try again in 24 hours.') . EOL);
+                               return;
+                       } 
+               }
+
+               /**
+                *
+                * Cleanup old introductions that remain blocked. 
+                * Also remove the contact record, but only if there is no existing relationship
+                *
+                */
+
+               $r = q("SELECT `intro`.*, `intro`.`id` AS `iid`, `contact`.`id` AS `cid`, `contact`.`rel` 
+                       FROM `intro` LEFT JOIN `contact` on `intro`.`contact-id` = `contact`.`id`
+                       WHERE `intro`.`blocked` = 1 AND `contact`.`self` = 0 AND `intro`.`datetime` < UTC_TIMESTAMP() - INTERVAL 30 MINUTE ");
+               if(count($r)) {
+                       foreach($r as $rr) {
+                               if(! $rr['rel']) {
+                                       q("DELETE FROM `contact` WHERE `id` = %d LIMIT 1",
+                                               intval($rr['cid'])
+                                       );
+                               }
+                               q("DELETE FROM `intro` WHERE `id` = %d LIMIT 1",
+                                       intval($rr['iid'])
+                               );
+                       }
+               }
+
                $url = trim($_POST['dfrn_url']);
                if(! strlen($url)) {
                        notice( t("Invalid locator") . EOL );
@@ -191,6 +286,8 @@ function dfrn_request_post(&$a) {
                        $network = 'dfrn';
                }
 
+               logger('dfrn_request: url: ' . $url);
+
                if(! strlen($url)) {
                        notice( t("Unable to resolve your name at the provided location.") . EOL);                      
                        return;
@@ -198,7 +295,7 @@ function dfrn_request_post(&$a) {
 
 
                if($network === 'dfrn') {
-                       $ret = q("SELECT * FROM `contact` WHERE `uid` = %d AND `url` = '%s' LIMIT 1", 
+                       $ret = q("SELECT * FROM `contact` WHERE `uid` = %d AND `url` = '%s' AND `self` = 0 LIMIT 1", 
                                intval($uid),
                                dbesc($url)
                        );
@@ -208,11 +305,16 @@ function dfrn_request_post(&$a) {
                                        notice( t('You have already introduced yourself here.') . EOL );
                                        return;
                                }
+                               elseif($ret[0]['rel'] == REL_BUD) {
+                                       notice( t('Apparently you are already friends with .') . $a->profile['name'] . EOL);
+                                       return;
+                               }
                                else {
                                        $contact_record = $ret[0];
                                        $parms = array('dfrn-request' => $ret[0]['request']);
                                }
                        }
+
                        $issued_id = random_string();
 
                        if(is_array($contact_record)) {
@@ -266,13 +368,14 @@ function dfrn_request_post(&$a) {
 
 
                                dbesc_array($parms);
-                               $r = q("INSERT INTO `contact` ( `uid`, `created`, `url`, `name`, `issued-id`, `photo`, `site-pubkey`,
+                               $r = q("INSERT INTO `contact` ( `uid`, `created`, `url`, `name`, `nick`, `issued-id`, `photo`, `site-pubkey`,
                                        `request`, `confirm`, `notify`, `poll` )
-                                       VALUES ( %d, '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s' )",
+                                       VALUES ( %d, '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s' )",
                                        intval($uid),
                                        datetime_convert(),
                                        $parms['url'],
                                        $parms['fn'],
+                                       $parms['nick'],
                                        $parms['issued-id'],
                                        $parms['photo'],
                                        $parms['key'],
@@ -314,8 +417,7 @@ function dfrn_request_post(&$a) {
                                );
                        }
        
-
-                       // This notice will only be seen by the requestor if  the requestor and requestee are on the same server.
+                       // This notice will only be seen by the requestor if the requestor and requestee are on the same server.
 
                        if(! $failed) 
                                notice( t('Your introduction has been sent.') . EOL );
@@ -336,14 +438,14 @@ function dfrn_request_post(&$a) {
                elseif($network === 'stat') {
                        
                        /**
-                       *
-                       * OStatus network
-                       * Check contact existence
-                       * Try and scrape together enough information to create a contact record, with us as REL_VIP
-                       * Substitute our user's feed URL into $url template
-                       * Send the subscriber home to subscribe
-                       *
-                       **/
+                        *
+                        * OStatus network
+                        * Check contact existence
+                        * Try and scrape together enough information to create a contact record, with us as REL_VIP
+                        * Substitute our user's feed URL into $url template
+                        * Send the subscriber home to subscribe
+                        *
+                        */
 
                        $url = str_replace('{uri}', $a->get_baseurl() . '/dfrn_poll/' . $nickname, $url);
                        goaway($url);
@@ -365,7 +467,6 @@ function dfrn_request_content(&$a) {
        if(($a->argc != 2) || (! count($a->profile)))
                return "";
 
-       $a->page['template'] = 'profile';
 
        // "Homecoming". Make sure we're logged in to this site as the correct user. Then offer a confirm button
        // to send us to the post section to record the introduction.
@@ -374,6 +475,12 @@ function dfrn_request_content(&$a) {
 
                if(! local_user()) {
                        notice( t("Please login to confirm introduction.") . EOL );
+
+                       /* setup the return URL to come back to this page if they use openid */
+
+                       $stripped = str_replace('q=','',$a->query_string);
+                       $_SESSION['return_url'] = trim($stripped,'/');
+
                        return login();
                }
 
@@ -417,9 +524,13 @@ function dfrn_request_content(&$a) {
                                WHERE `contact`.`id` = %d LIMIT 1",
                                intval($intro[0]['contact-id'])
                        );
-                       if(count($r)) {
 
-                               if($r[0]['notify-flags'] & NOTIFY_INTRO) {
+                       $auto_confirm = false;
+
+                       if(count($r)) {
+                               if($r[0]['page-flags'] != PAGE_NORMAL)
+                                       $auto_confirm = true;                           
+                               if(($r[0]['notify-flags'] & NOTIFY_INTRO) && (! $auto_confirm)) {
                                        $email_tpl = load_view_file('view/request_notify_eml.tpl');
                                        $email = replace_macros($email_tpl, array(
                                                '$requestor' => ((strlen(stripslashes($r[0]['name']))) ? stripslashes($r[0]['name']) : t('[Name Withheld]')),
@@ -431,25 +542,94 @@ function dfrn_request_content(&$a) {
                                        $res = mail($r[0]['email'], 
                                                t("Introduction received at ") . $a->config['sitename'],
                                                $email,
-                                               'From: ' . t('Administrator') . '@' . $_SERVER[SERVER_NAME] );
+                                               'From: ' . t('Administrator') . '@' . $_SERVER['SERVER_NAME'] );
                                        // This is a redundant notification - no point throwing errors if it fails.
                                }
+                               if($auto_confirm) {
+                                       require_once('mod/dfrn_confirm.php');
+                                       $handsfree = array(
+                                               'uid' => $r[0]['uid'],
+                                               'node' => $r[0]['nickname'],
+                                               'dfrn_id' => $r[0]['issued-id'],
+                                               'intro_id' => $intro[0]['id'],
+                                               'duplex' => (($r[0]['page-flags'] == PAGE_FREELOVE) ? 1 : 0)
+                                       );
+                                       dfrn_confirm_post($a,$handsfree);
+                               }
+
                        }
 
-                       $r = q("UPDATE `intro` SET `blocked` = 0 WHERE `hash` = '%s' LIMIT 1",
-                               dbesc($_GET['confirm_key'])
-                       );
+                       if(! $auto_confirm) {
 
+                               // If we are auto_confirming, this record will have already been nuked
+                               // in dfrn_confirm_post()
+
+                               $r = q("UPDATE `intro` SET `blocked` = 0 WHERE `hash` = '%s' LIMIT 1",
+                                       dbesc($_GET['confirm_key'])
+                               );
+                       }
                }
                killme();
                return; // NOTREACHED
        }
        else {
 
-               // Normal web request. Display our user's introduction form. 
+               /**
+                * Normal web request. Display our user's introduction form.
+                */
+               /**
+                * Try to auto-fill the profile address
+                */
+
+               if(local_user()) {
+                       if(strlen($a->path)) {
+                               $myaddr = $a->get_baseurl() . '/profile/' . $a->user['nickname'];
+                       }
+                       else {
+                               $myaddr = $a->user['nickname'] . '@' . substr($a->get_baseurl(), strpos($a->get_baseurl(),'://') + 3 );
+                       }
+               }
+               elseif(x($_GET,'addr')) {
+                       $myaddr = hex2bin($_GET['addr']);
+               }
+               else {
+                       /* $_GET variables are already urldecoded */ 
+                       $myaddr = ((x($_GET,'address')) ? $_GET['address'] : '');
+               }
 
-               $o = load_view_file("view/dfrn_request.tpl");
-               $o = replace_macros($o,array('$nickname' => $a->argv[1]));
+               /**
+                *
+                * The auto_request form only has the profile address
+                * because nobody is going to read the comments and 
+                * it doesn't matter if they know you or not.
+                *
+                */
+
+               if($a->profile['page-flags'] == PAGE_NORMAL)
+                       $tpl = load_view_file('view/dfrn_request.tpl');
+               else
+                       $tpl = load_view_file('view/auto_request.tpl');
+
+               $o .= replace_macros($tpl,array(
+                       '$header' => t('Friend/Connection Request'),
+                       '$pls_answer' => t('Please answer the following:'),
+                       '$does_know' => t('Does $name know you?'),
+                       '$yes' => t('Yes'),
+                       '$no' => t('No'),
+                       '$add_note' => t('Add a personal note:'),
+                       '$page_desc' => t('Please enter your profile address from one of the following supported social networks:'),
+                       '$friendika' => t('Friendika'),
+                       '$statusnet' => t('StatusNet/Federated Social Web'),
+                       '$private_net' => t("Private \x28secure\x29 network"),
+                       '$public_net' => t("Public \x28insecure\x29 network"),
+                       '$your_address' => t('Your profile address:'),
+                       '$submit' => t('Submit Request'),
+                       '$cancel' => t('Cancel'),
+                       '$nickname' => $a->argv[1],
+                       '$name' => $a->profile['name'],
+                       '$myaddr' => $myaddr
+               ));
                return $o;
        }