]> git.mxchange.org Git - friendica.git/blobdiff - mod/poco.php
Merge pull request #7988 from friendica/MrPetovan-notice
[friendica.git] / mod / poco.php
index c5c5ef4c835548d901b08cad10001623509eeaf8..2ed871285b76586b38e30eb63def4c6d49816cb9 100644 (file)
@@ -3,45 +3,56 @@
 // See here for a documentation for portable contacts:
 // https://web.archive.org/web/20160405005550/http://portablecontacts.net/draft-spec.html
 
+
 use Friendica\App;
+use Friendica\Content\Text\BBCode;
+use Friendica\Core\Cache;
 use Friendica\Core\Config;
-use Friendica\Database\DBM;
+use Friendica\Core\Logger;
+use Friendica\Core\Protocol;
+use Friendica\Core\Renderer;
+use Friendica\Core\System;
+use Friendica\Database\DBA;
+use Friendica\Protocol\PortableContact;
+use Friendica\Util\DateTimeFormat;
+use Friendica\Util\Strings;
+use Friendica\Util\XML;
 
 function poco_init(App $a) {
        $system_mode = false;
 
        if (intval(Config::get('system', 'block_public')) || (Config::get('system', 'block_local_dir'))) {
-               http_status_exit(401);
+               throw new \Friendica\Network\HTTPException\ForbiddenException();
        }
 
        if ($a->argc > 1) {
-               $user = notags(trim($a->argv[1]));
+               $nickname = Strings::escapeTags(trim($a->argv[1]));
        }
-       if (! x($user)) {
+       if (empty($nickname)) {
                $c = q("SELECT * FROM `pconfig` WHERE `cat` = 'system' AND `k` = 'suggestme' AND `v` = 1");
-               if (! DBM::is_result($c)) {
-                       http_status_exit(401);
+               if (!DBA::isResult($c)) {
+                       throw new \Friendica\Network\HTTPException\ForbiddenException();
                }
                $system_mode = true;
        }
 
-       $format = (($_GET['format']) ? $_GET['format'] : 'json');
+       $format = ($_GET['format'] ?? '') ?: 'json';
 
        $justme = false;
        $global = false;
 
        if ($a->argc > 1 && $a->argv[1] === '@server') {
-               require_once 'include/socgraph.php';
                // List of all servers that this server knows
-               $ret = poco_serverlist();
+               $ret = PortableContact::serverlist();
                header('Content-type: application/json');
                echo json_encode($ret);
-               killme();
+               exit();
        }
+
        if ($a->argc > 1 && $a->argv[1] === '@global') {
                // List of all profiles that this server recently had data from
                $global = true;
-               $update_limit = date("Y-m-d H:i:s", time() - 30 * 86400);
+               $update_limit = date(DateTimeFormat::MYSQL, time() - 30 * 86400);
        }
        if ($a->argc > 2 && $a->argv[2] === '@me') {
                $justme = true;
@@ -59,10 +70,10 @@ function poco_init(App $a) {
        if (! $system_mode && ! $global) {
                $users = q("SELECT `user`.*,`profile`.`hide-friends` from user left join profile on `user`.`uid` = `profile`.`uid`
                        where `user`.`nickname` = '%s' and `profile`.`is-default` = 1 limit 1",
-                       dbesc($user)
+                       DBA::escape($nickname)
                );
-               if (! DBM::is_result($users) || $users[0]['hidewall'] || $users[0]['hide-friends']) {
-                       http_status_exit(404);
+               if (! DBA::isResult($users) || $users[0]['hidewall'] || $users[0]['hide-friends']) {
+                       throw new \Friendica\Network\HTTPException\NotFoundException();
                }
 
                $user = $users[0];
@@ -70,22 +81,22 @@ function poco_init(App $a) {
 
        if ($justme) {
                $sql_extra = " AND `contact`.`self` = 1 ";
+       } else {
+               $sql_extra = "";
        }
-//     else
-//             $sql_extra = " AND `contact`.`self` = 0 ";
 
-       if ($cid) {
+       if (!empty($cid)) {
                $sql_extra = sprintf(" AND `contact`.`id` = %d ", intval($cid));
        }
-       if (x($_GET, 'updatedSince')) {
-               $update_limit = date("Y-m-d H:i:s", strtotime($_GET['updatedSince']));
+       if (!empty($_GET['updatedSince'])) {
+               $update_limit = date(DateTimeFormat::MYSQL, strtotime($_GET['updatedSince']));
        }
        if ($global) {
                $contacts = q("SELECT count(*) AS `total` FROM `gcontact` WHERE `updated` >= '%s' AND `updated` >= `last_failure` AND NOT `hide` AND `network` IN ('%s', '%s', '%s')",
-                       dbesc($update_limit),
-                       dbesc(NETWORK_DFRN),
-                       dbesc(NETWORK_DIASPORA),
-                       dbesc(NETWORK_OSTATUS)
+                       DBA::escape($update_limit),
+                       DBA::escape(Protocol::DFRN),
+                       DBA::escape(Protocol::DIASPORA),
+                       DBA::escape(Protocol::OSTATUS)
                );
        } elseif ($system_mode) {
                $contacts = q("SELECT count(*) AS `total` FROM `contact` WHERE `self` = 1
@@ -95,36 +106,37 @@ function poco_init(App $a) {
                        AND (`success_update` >= `failure_update` OR `last-item` >= `failure_update`)
                        AND `network` IN ('%s', '%s', '%s', '%s') $sql_extra",
                        intval($user['uid']),
-                       dbesc(NETWORK_DFRN),
-                       dbesc(NETWORK_DIASPORA),
-                       dbesc(NETWORK_OSTATUS),
-                       dbesc(NETWORK_STATUSNET)
+                       DBA::escape(Protocol::DFRN),
+                       DBA::escape(Protocol::DIASPORA),
+                       DBA::escape(Protocol::OSTATUS),
+                       DBA::escape(Protocol::STATUSNET)
                );
        }
-       if (DBM::is_result($contacts)) {
+       if (DBA::isResult($contacts)) {
                $totalResults = intval($contacts[0]['total']);
        } else {
                $totalResults = 0;
        }
-       $startIndex = intval($_GET['startIndex']);
-       if (! $startIndex) {
+       if (!empty($_GET['startIndex'])) {
+               $startIndex = intval($_GET['startIndex']);
+       } else {
                $startIndex = 0;
        }
-       $itemsPerPage = ((x($_GET, 'count') && intval($_GET['count'])) ? intval($_GET['count']) : $totalResults);
+       $itemsPerPage = ((!empty($_GET['count'])) ? intval($_GET['count']) : $totalResults);
 
        if ($global) {
-               logger("Start global query", LOGGER_DEBUG);
+               Logger::log("Start global query", Logger::DEBUG);
                $contacts = q("SELECT * FROM `gcontact` WHERE `updated` > '%s' AND NOT `hide` AND `network` IN ('%s', '%s', '%s') AND `updated` > `last_failure`
                        ORDER BY `updated` DESC LIMIT %d, %d",
-                       dbesc($update_limit),
-                       dbesc(NETWORK_DFRN),
-                       dbesc(NETWORK_DIASPORA),
-                       dbesc(NETWORK_OSTATUS),
+                       DBA::escape($update_limit),
+                       DBA::escape(Protocol::DFRN),
+                       DBA::escape(Protocol::DIASPORA),
+                       DBA::escape(Protocol::OSTATUS),
                        intval($startIndex),
                        intval($itemsPerPage)
                );
        } elseif ($system_mode) {
-               logger("Start system mode query", LOGGER_DEBUG);
+               Logger::log("Start system mode query", Logger::DEBUG);
                $contacts = q("SELECT `contact`.*, `profile`.`about` AS `pabout`, `profile`.`locality` AS `plocation`, `profile`.`pub_keywords`,
                                `profile`.`gender` AS `pgender`, `profile`.`address` AS `paddress`, `profile`.`region` AS `pregion`,
                                `profile`.`postal-code` AS `ppostalcode`, `profile`.`country-name` AS `pcountry`, `user`.`account-type`
@@ -136,38 +148,38 @@ function poco_init(App $a) {
                        intval($itemsPerPage)
                );
        } else {
-               logger("Start query for user " . $user['nickname'], LOGGER_DEBUG);
+               Logger::log("Start query for user " . $user['nickname'], Logger::DEBUG);
                $contacts = q("SELECT * FROM `contact` WHERE `uid` = %d AND `blocked` = 0 AND `pending` = 0 AND `hidden` = 0 AND `archive` = 0
                        AND (`success_update` >= `failure_update` OR `last-item` >= `failure_update`)
                        AND `network` IN ('%s', '%s', '%s', '%s') $sql_extra LIMIT %d, %d",
                        intval($user['uid']),
-                       dbesc(NETWORK_DFRN),
-                       dbesc(NETWORK_DIASPORA),
-                       dbesc(NETWORK_OSTATUS),
-                       dbesc(NETWORK_STATUSNET),
+                       DBA::escape(Protocol::DFRN),
+                       DBA::escape(Protocol::DIASPORA),
+                       DBA::escape(Protocol::OSTATUS),
+                       DBA::escape(Protocol::STATUSNET),
                        intval($startIndex),
                        intval($itemsPerPage)
                );
        }
-       logger("Query done", LOGGER_DEBUG);
+       Logger::log("Query done", Logger::DEBUG);
 
-       $ret = array();
-       if (x($_GET, 'sorted')) {
+       $ret = [];
+       if (!empty($_GET['sorted'])) {
                $ret['sorted'] = false;
        }
-       if (x($_GET, 'filtered')) {
+       if (!empty($_GET['filtered'])) {
                $ret['filtered'] = false;
        }
-       if (x($_GET, 'updatedSince') && ! $global) {
+       if (!empty($_GET['updatedSince']) && ! $global) {
                $ret['updatedSince'] = false;
        }
        $ret['startIndex']   = (int) $startIndex;
        $ret['itemsPerPage'] = (int) $itemsPerPage;
        $ret['totalResults'] = (int) $totalResults;
-       $ret['entry']        = array();
+       $ret['entry']        = [];
 
 
-       $fields_ret = array(
+       $fields_ret = [
                'id' => false,
                'displayName' => false,
                'urls' => false,
@@ -182,9 +194,9 @@ function poco_init(App $a) {
                'address' => false,
                'contactType' => false,
                'generation' => false
-       );
+       ];
 
-       if ((! x($_GET, 'fields')) || ($_GET['fields'] === '@all')) {
+       if (empty($_GET['fields']) || ($_GET['fields'] === '@all')) {
                foreach ($fields_ret as $k => $v) {
                        $fields_ret[$k] = true;
                }
@@ -196,8 +208,12 @@ function poco_init(App $a) {
        }
 
        if (is_array($contacts)) {
-               if (DBM::is_result($contacts)) {
+               if (DBA::isResult($contacts)) {
                        foreach ($contacts as $contact) {
+                               if (!isset($contact['updated'])) {
+                                       $contact['updated'] = '';
+                               }
+
                                if (! isset($contact['generation'])) {
                                        if ($global) {
                                                $contact['generation'] = 3;
@@ -241,19 +257,18 @@ function poco_init(App $a) {
                                }
                                $about = Cache::get("about:" . $contact['updated'] . ":" . $contact['nurl']);
                                if (is_null($about)) {
-                                       require_once 'include/bbcode.php';
-                                       $about = bbcode($contact['about'], false, false);
+                                       $about = BBCode::convert($contact['about'], false);
                                        Cache::set("about:" . $contact['updated'] . ":" . $contact['nurl'], $about);
                                }
 
                                // Non connected persons can only see the keywords of a Diaspora account
-                               if ($contact['network'] == NETWORK_DIASPORA) {
+                               if ($contact['network'] == Protocol::DIASPORA) {
                                        $contact['location'] = "";
                                        $about = "";
                                        $contact['gender'] = "";
                                }
 
-                               $entry = array();
+                               $entry = [];
                                if ($fields_ret['id']) {
                                        $entry['id'] = (int)$contact['id'];
                                }
@@ -273,9 +288,9 @@ function poco_init(App $a) {
                                        $entry['generation'] = (int)$contact['generation'];
                                }
                                if ($fields_ret['urls']) {
-                                       $entry['urls'] = array(array('value' => $contact['url'], 'type' => 'profile'));
-                                       if ($contact['addr'] && ($contact['network'] !== NETWORK_MAIL)) {
-                                               $entry['urls'][] = array('value' => 'acct:' . $contact['addr'], 'type' => 'webfinger');
+                                       $entry['urls'] = [['value' => $contact['url'], 'type' => 'profile']];
+                                       if ($contact['addr'] && ($contact['network'] !== Protocol::MAIL)) {
+                                               $entry['urls'][] = ['value' => 'acct:' . $contact['addr'], 'type' => 'webfinger'];
                                        }
                                }
                                if ($fields_ret['preferredUsername']) {
@@ -300,22 +315,22 @@ function poco_init(App $a) {
                                        $entry['updated'] = date("c", strtotime($entry['updated']));
                                }
                                if ($fields_ret['photos']) {
-                                       $entry['photos'] = array(array('value' => $contact['photo'], 'type' => 'profile'));
+                                       $entry['photos'] = [['value' => $contact['photo'], 'type' => 'profile']];
                                }
                                if ($fields_ret['network']) {
                                        $entry['network'] = $contact['network'];
-                                       if ($entry['network'] == NETWORK_STATUSNET) {
-                                               $entry['network'] = NETWORK_OSTATUS;
+                                       if ($entry['network'] == Protocol::STATUSNET) {
+                                               $entry['network'] = Protocol::OSTATUS;
                                        }
                                        if (($entry['network'] == "") && ($contact['self'])) {
-                                               $entry['network'] = NETWORK_DFRN;
+                                               $entry['network'] = Protocol::DFRN;
                                        }
                                }
                                if ($fields_ret['tags']) {
                                        $tags = str_replace(",", " ", $contact['keywords']);
                                        $tags = explode(" ", $tags);
 
-                                       $cleaned = array();
+                                       $cleaned = [];
                                        foreach ($tags as $tag) {
                                                $tag = trim(strtolower($tag));
                                                if ($tag != "") {
@@ -323,10 +338,10 @@ function poco_init(App $a) {
                                                }
                                        }
 
-                                       $entry['tags'] = array($cleaned);
+                                       $entry['tags'] = [$cleaned];
                                }
                                if ($fields_ret['address']) {
-                                       $entry['address'] = array();
+                                       $entry['address'] = [];
 
                                        // Deactivated. It just reveals too much data. (Although its from the default profile)
                                        //if (isset($rr['paddress']))
@@ -353,23 +368,24 @@ function poco_init(App $a) {
                                $ret['entry'][] = $entry;
                        }
                } else {
-                       $ret['entry'][] = array();
+                       $ret['entry'][] = [];
                }
        } else {
-               http_status_exit(500);
+               throw new \Friendica\Network\HTTPException\InternalServerErrorException();
        }
-       logger("End of poco", LOGGER_DEBUG);
+
+       Logger::log("End of poco", Logger::DEBUG);
 
        if ($format === 'xml') {
                header('Content-type: text/xml');
-               echo replace_macros(get_markup_template('poco_xml.tpl'), array_xmlify(array('$response' => $ret)));
-               killme();
+               echo Renderer::replaceMacros(Renderer::getMarkupTemplate('poco_xml.tpl'), XML::arrayEscape(['$response' => $ret]));
+               exit();
        }
        if ($format === 'json') {
                header('Content-type: application/json');
                echo json_encode($ret);
-               killme();
+               exit();
        } else {
-               http_status_exit(500);
+               throw new \Friendica\Network\HTTPException\InternalServerErrorException();
        }
 }