<?php
+/**
+ * @copyright Copyright (C) 2020, Friendica
+ *
+ * @license GNU AGPL version 3 or any later version
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU Affero General Public License as
+ * published by the Free Software Foundation, either version 3 of the
+ * License, or (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU Affero General Public License for more details.
+ *
+ * You should have received a copy of the GNU Affero General Public License
+ * along with this program. If not, see <https://www.gnu.org/licenses/>.
+ *
+ */
use Friendica\App;
use Friendica\Core\Logger;
use Friendica\Core\Protocol;
use Friendica\Database\DBA;
+use Friendica\DI;
use Friendica\Model\Contact;
use Friendica\Protocol\OStatus;
-
-require_once 'include/items.php';
+use Friendica\Util\Strings;
+use Friendica\Util\Network;
+use Friendica\Core\System;
function hub_return($valid, $body)
{
if ($valid) {
- header($_SERVER["SERVER_PROTOCOL"] . ' 200 OK');
echo $body;
} else {
- header($_SERVER["SERVER_PROTOCOL"] . ' 404 Not Found');
+ throw new \Friendica\Network\HTTPException\NotFoundException();
}
- killme();
+ exit();
}
// when receiving an XML feed, always return OK
function hub_post_return()
{
- header($_SERVER["SERVER_PROTOCOL"] . ' 200 OK');
- killme();
+ throw new \Friendica\Network\HTTPException\OKException();
}
function pubsub_init(App $a)
{
- $nick = (($a->argc > 1) ? notags(trim($a->argv[1])) : '');
+ $nick = (($a->argc > 1) ? Strings::escapeTags(trim($a->argv[1])) : '');
$contact_id = (($a->argc > 2) ? intval($a->argv[2]) : 0 );
if ($_SERVER['REQUEST_METHOD'] === 'GET') {
- $hub_mode = notags(trim(defaults($_GET, 'hub_mode', '')));
- $hub_topic = notags(trim(defaults($_GET, 'hub_topic', '')));
- $hub_challenge = notags(trim(defaults($_GET, 'hub_challenge', '')));
- $hub_lease = notags(trim(defaults($_GET, 'hub_lease_seconds', '')));
- $hub_verify = notags(trim(defaults($_GET, 'hub_verify_token', '')));
+ $hub_mode = Strings::escapeTags(trim($_GET['hub_mode'] ?? ''));
+ $hub_topic = Strings::escapeTags(trim($_GET['hub_topic'] ?? ''));
+ $hub_challenge = Strings::escapeTags(trim($_GET['hub_challenge'] ?? ''));
+ $hub_verify = Strings::escapeTags(trim($_GET['hub_verify_token'] ?? ''));
Logger::log('Subscription from ' . $_SERVER['REMOTE_ADDR'] . ' Mode: ' . $hub_mode . ' Nick: ' . $nick);
Logger::log('Data: ' . print_r($_GET,true), Logger::DATA);
hub_return(false, '');
}
- if (!empty($hub_topic) && !link_compare($hub_topic, $contact['poll'])) {
+ if (!empty($hub_topic) && !Strings::compareLink($hub_topic, $contact['poll'])) {
Logger::log('Hub topic ' . $hub_topic . ' != ' . $contact['poll']);
hub_return(false, '');
}
function pubsub_post(App $a)
{
- $xml = file_get_contents('php://input');
+ $xml = Network::postdata();
- Logger::log('Feed arrived from ' . $_SERVER['REMOTE_ADDR'] . ' for ' . $a->cmd . ' with user-agent: ' . $_SERVER['HTTP_USER_AGENT']);
+ Logger::log('Feed arrived from ' . $_SERVER['REMOTE_ADDR'] . ' for ' . DI::args()->getCommand() . ' with user-agent: ' . $_SERVER['HTTP_USER_AGENT']);
Logger::log('Data: ' . $xml, Logger::DATA);
- $nick = (($a->argc > 1) ? notags(trim($a->argv[1])) : '');
+ $nick = (($a->argc > 1) ? Strings::escapeTags(trim($a->argv[1])) : '');
$contact_id = (($a->argc > 2) ? intval($a->argv[2]) : 0 );
$importer = DBA::selectFirst('user', [], ['nickname' => $nick, 'account_expired' => false, 'account_removed' => false]);