]> git.mxchange.org Git - friendica.git/blobdiff - src/Module/Xrd.php
Some removed escapeTags calls
[friendica.git] / src / Module / Xrd.php
index 38ce151ff87e9eb0f827836042c8eb103775d576..66404f4567d30b06887620af5a7dadbd79168044 100644 (file)
@@ -1,4 +1,23 @@
 <?php
+/**
+ * @copyright Copyright (C) 2010-2021, the Friendica project
+ *
+ * @license GNU AGPL version 3 or any later version
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU Affero General Public License as
+ * published by the Free Software Foundation, either version 3 of the
+ * License, or (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+ * GNU Affero General Public License for more details.
+ *
+ * You should have received a copy of the GNU Affero General Public License
+ * along with this program.  If not, see <https://www.gnu.org/licenses/>.
+ *
+ */
 
 namespace Friendica\Module;
 
@@ -6,27 +25,27 @@ use Friendica\BaseModule;
 use Friendica\Core\Hook;
 use Friendica\Core\Renderer;
 use Friendica\Core\System;
+use Friendica\DI;
+use Friendica\Model\Photo;
 use Friendica\Model\User;
+use Friendica\Protocol\ActivityNamespace;
 use Friendica\Protocol\Salmon;
-use Friendica\Util\Strings;
 
 /**
  * Prints responses to /.well-known/webfinger  or /xrd requests
  */
 class Xrd extends BaseModule
 {
-       public static function rawContent()
+       public static function rawContent(array $parameters = [])
        {
-               $app = self::getApp();
-
                // @TODO: Replace with parameter from router
-               if ($app->argv[0] == 'xrd') {
+               if (DI::args()->getArgv()[0] == 'xrd') {
                        if (empty($_GET['uri'])) {
                                return;
                        }
 
-                       $uri = urldecode(Strings::escapeTags(trim($_GET['uri'])));
-                       if (defaults($_SERVER, 'HTTP_ACCEPT', '') == 'application/jrd+json') {
+                       $uri = urldecode(trim($_GET['uri']));
+                       if (strpos($_SERVER['HTTP_ACCEPT'] ?? '', 'application/jrd+json') !== false)  {
                                $mode = 'json';
                        } else {
                                $mode = 'xml';
@@ -36,8 +55,8 @@ class Xrd extends BaseModule
                                return;
                        }
 
-                       $uri = urldecode(Strings::escapeTags(trim($_GET['resource'])));
-                       if (defaults($_SERVER, 'HTTP_ACCEPT', '') == 'application/xrd+xml') {
+                       $uri = urldecode(trim($_GET['resource']));
+                       if (strpos($_SERVER['HTTP_ACCEPT'] ?? '', 'application/xrd+xml') !== false)  {
                                $mode = 'xml';
                        } else {
                                $mode = 'json';
@@ -55,73 +74,128 @@ class Xrd extends BaseModule
                        $name = substr($local, 0, strpos($local, '@'));
                }
 
-               $user = User::getByNickname($name);
+               if ($name == User::getActorName()) {
+                       $owner = User::getSystemAccount();
+                       if (empty($owner)) {
+                               throw new \Friendica\Network\HTTPException\NotFoundException();
+                       }
+                       self::printSystemJSON($owner);
+               } else {
+                       $user = User::getByNickname($name);
+                       if (empty($user)) {
+                               throw new \Friendica\Network\HTTPException\NotFoundException();
+                       }
 
-               if (empty($user)) {
-                       System::httpExit(404);
-               }
+                       $owner = User::getOwnerDataById($user['uid']);
+                       if (empty($owner)) {
+                               DI::logger()->warning('No owner data for user id', ['uri' => $uri, 'name' => $name, 'user' => $user]);
+                               throw new \Friendica\Network\HTTPException\NotFoundException();
+                       }
 
-               $profileURL = $app->getBaseURL() . '/profile/' . $user['nickname'];
-               $alias = str_replace('/profile/', '/~', $profileURL);
+                       $alias = str_replace('/profile/', '/~', $owner['url']);
 
-               $addr = 'acct:' . $user['nickname'] . '@' . $app->getHostName();
-               if ($app->getURLPath()) {
-                       $addr .= '/' . $app->getURLPath();
+                       $avatar = Photo::selectFirst(['type'], ['uid' => $owner['uid'], 'profile' => true]);
+               }
+
+               if (empty($avatar)) {
+                       $avatar = ['type' => 'image/jpeg'];
                }
 
                if ($mode == 'xml') {
-                       self::printXML($addr, $alias, $profileURL, $app->getBaseURL(), $user);
+                       self::printXML($alias, DI::baseUrl()->get(), $user, $owner, $avatar);
                } else {
-                       self::printJSON($addr, $alias, $profileURL, $app->getBaseURL(), $user);
+                       self::printJSON($alias, DI::baseUrl()->get(), $owner, $avatar);
                }
        }
 
-       private static function printJSON($uri, $alias, $orofileURL, $baseURL, $user)
+       private static function printSystemJSON(array $owner)
        {
-               $salmon_key = Salmon::salmonKey($user['spubkey']);
-
+               $json = [
+                       'subject' => 'acct:' . $owner['addr'],
+                       'aliases' => [$owner['url']],
+                       'links'   => [
+                               [
+                                       'rel'  => 'http://webfinger.net/rel/profile-page',
+                                       'type' => 'text/html',
+                                       'href' => $owner['url'],
+                               ],
+                               [
+                                       'rel'  => 'self',
+                                       'type' => 'application/activity+json',
+                                       'href' => $owner['url'],
+                               ],
+                               [
+                                       'rel'      => 'http://ostatus.org/schema/1.0/subscribe',
+                                       'template' => DI::baseUrl()->get() . '/follow?url={uri}',
+                               ],
+                               [
+                                       'rel'  => ActivityNamespace::FEED,
+                                       'type' => 'application/atom+xml',
+                                       'href' => $owner['poll'] ?? DI::baseUrl()->get(),
+                               ],
+                               [
+                                       'rel'  => 'salmon',
+                                       'href' => DI::baseUrl()->get() . '/salmon/' . $owner['nickname'],
+                               ],
+                               [
+                                       'rel'  => 'http://microformats.org/profile/hcard',
+                                       'type' => 'text/html',
+                                       'href' => DI::baseUrl()->get() . '/hcard/' . $owner['nickname'],
+                               ],
+                               [
+                                       'rel'  => 'http://joindiaspora.com/seed_location',
+                                       'type' => 'text/html',
+                                       'href' => DI::baseUrl()->get(),
+                               ],
+                       ]
+               ];
                header('Access-Control-Allow-Origin: *');
-               header('Content-type: application/json; charset=utf-8');
+               System::jsonExit($json, 'application/jrd+json; charset=utf-8');
+       }
+
+       private static function printJSON($alias, $baseURL, $owner, $avatar)
+       {
+               $salmon_key = Salmon::salmonKey($owner['spubkey']);
 
                $json = [
-                       'subject' => $uri,
+                       'subject' => 'acct:' . $owner['addr'],
                        'aliases' => [
                                $alias,
-                               $orofileURL,
+                               $owner['url'],
                        ],
                        'links'   => [
                                [
-                                       'rel'  => NAMESPACE_DFRN,
-                                       'href' => $orofileURL,
+                                       'rel'  => ActivityNamespace::DFRN ,
+                                       'href' => $owner['url'],
                                ],
                                [
-                                       'rel'  => NAMESPACE_FEED,
+                                       'rel'  => ActivityNamespace::FEED,
                                        'type' => 'application/atom+xml',
-                                       'href' => $baseURL . '/dfrn_poll/' . $user['nickname'],
+                                       'href' => $owner['poll'],
                                ],
                                [
                                        'rel'  => 'http://webfinger.net/rel/profile-page',
                                        'type' => 'text/html',
-                                       'href' => $orofileURL,
+                                       'href' => $owner['url'],
                                ],
                                [
                                        'rel'  => 'self',
                                        'type' => 'application/activity+json',
-                                       'href' => $orofileURL,
+                                       'href' => $owner['url'],
                                ],
                                [
                                        'rel'  => 'http://microformats.org/profile/hcard',
                                        'type' => 'text/html',
-                                       'href' => $baseURL . '/hcard/' . $user['nickname'],
+                                       'href' => $baseURL . '/hcard/' . $owner['nickname'],
                                ],
                                [
-                                       'rel'  => NAMESPACE_POCO,
-                                       'href' => $baseURL . '/poco/' . $user['nickname'],
+                                       'rel'  => ActivityNamespace::POCO,
+                                       'href' => $owner['poco'],
                                ],
                                [
                                        'rel'  => 'http://webfinger.net/rel/avatar',
-                                       'type' => 'image/jpeg',
-                                       'href' => $baseURL . '/photo/profile/' . $user['uid'] . '.jpg',
+                                       'type' => $avatar['type'],
+                                       'href' => User::getAvatarUrl($owner),
                                ],
                                [
                                        'rel'  => 'http://joindiaspora.com/seed_location',
@@ -130,15 +204,15 @@ class Xrd extends BaseModule
                                ],
                                [
                                        'rel'  => 'salmon',
-                                       'href' => $baseURL . '/salmon/' . $user['nickname'],
+                                       'href' => $baseURL . '/salmon/' . $owner['nickname'],
                                ],
                                [
                                        'rel'  => 'http://salmon-protocol.org/ns/salmon-replies',
-                                       'href' => $baseURL . '/salmon/' . $user['nickname'],
+                                       'href' => $baseURL . '/salmon/' . $owner['nickname'],
                                ],
                                [
                                        'rel'  => 'http://salmon-protocol.org/ns/salmon-mention',
-                                       'href' => $baseURL . '/salmon/' . $user['nickname'] . '/mention',
+                                       'href' => $baseURL . '/salmon/' . $owner['nickname'] . '/mention',
                                ],
                                [
                                        'rel'      => 'http://ostatus.org/schema/1.0/subscribe',
@@ -156,13 +230,13 @@ class Xrd extends BaseModule
                        ],
                ];
 
-               echo json_encode($json);
-               exit();
+               header('Access-Control-Allow-Origin: *');
+               System::jsonExit($json, 'application/jrd+json; charset=utf-8');
        }
 
-       private static function printXML($uri, $alias, $profileURL, $baseURL, $user)
+       private static function printXML($alias, $baseURL, $user, $owner, $avatar)
        {
-               $salmon_key = Salmon::salmonKey($user['spubkey']);
+               $salmon_key = Salmon::salmonKey($owner['spubkey']);
 
                header('Access-Control-Allow-Origin: *');
                header('Content-type: text/xml');
@@ -170,17 +244,17 @@ class Xrd extends BaseModule
                $tpl = Renderer::getMarkupTemplate('xrd_person.tpl');
 
                $o = Renderer::replaceMacros($tpl, [
-                       '$nick'        => $user['nickname'],
-                       '$accturi'     => $uri,
+                       '$nick'        => $owner['nickname'],
+                       '$accturi'     => 'acct:' . $owner['addr'],
                        '$alias'       => $alias,
-                       '$profile_url' => $profileURL,
-                       '$hcard_url'   => $baseURL . '/hcard/' . $user['nickname'],
-                       '$atom'        => $baseURL . '/dfrn_poll/' . $user['nickname'],
-                       '$poco_url'    => $baseURL . '/poco/' . $user['nickname'],
-                       '$photo'       => $baseURL . '/photo/profile/' . $user['uid'] . '.jpg',
-                       '$baseurl'     => $baseURL,
-                       '$salmon'      => $baseURL . '/salmon/' . $user['nickname'],
-                       '$salmen'      => $baseURL . '/salmon/' . $user['nickname'] . '/mention',
+                       '$profile_url' => $owner['url'],
+                       '$hcard_url'   => $baseURL . '/hcard/' . $owner['nickname'],
+                       '$atom'        => $owner['poll'],
+                       '$poco_url'    => $owner['poco'],
+                       '$photo'       => User::getAvatarUrl($owner),
+                       '$type'        => $avatar['type'],
+                       '$salmon'      => $baseURL . '/salmon/' . $owner['nickname'],
+                       '$salmen'      => $baseURL . '/salmon/' . $owner['nickname'] . '/mention',
                        '$subscribe'   => $baseURL . '/follow?url={uri}',
                        '$openwebauth' => $baseURL . '/owa',
                        '$modexp'      => 'data:application/magic-public-key,' . $salmon_key