X-Git-Url: https://git.mxchange.org/?a=blobdiff_plain;f=mod%2Fbookmarklet.php;h=d9c2f52f821d0a449c7a24b116fd0f36358ae4dd;hb=9feab828c88dfdc0c66fef3269f6cdf0122d2840;hp=45c3d319073e4ce879aaca2cf011850fe1f31e95;hpb=2b35938e34da9327d32f0883eae525b85ccce88a;p=friendica.git
diff --git a/mod/bookmarklet.php b/mod/bookmarklet.php
index 45c3d31907..d9c2f52f82 100644
--- a/mod/bookmarklet.php
+++ b/mod/bookmarklet.php
@@ -4,10 +4,12 @@
*/
use Friendica\App;
-use Friendica\Core\Acl;
+use Friendica\Core\ACL;
+use Friendica\Core\Config;
use Friendica\Core\L10n;
use Friendica\Core\System;
use Friendica\Module\Login;
+use Friendica\Util\Strings;
require_once 'include/conversation.php';
require_once 'include/items.php';
@@ -21,14 +23,18 @@ function bookmarklet_content(App $a)
{
if (!local_user()) {
$o = '
' . L10n::t('Login') . '
';
- $o .= Login::form($a->query_string, $a->config['register_policy'] == REGISTER_CLOSED ? false : true);
+ $o .= Login::form($a->query_string, intval(Config::get('config', 'register_policy')) === REGISTER_CLOSED ? false : true);
return $o;
}
- $referer = normalise_link($_SERVER["HTTP_REFERER"]);
- $page = normalise_link(System::baseUrl() . "/bookmarklet");
+ $referer = Strings::normaliseLink(defaults($_SERVER, 'HTTP_REFERER', ''));
+ $page = Strings::normaliseLink(System::baseUrl() . "/bookmarklet");
if (!strstr($referer, $page)) {
+ if (empty($_REQUEST["url"])) {
+ System::httpExit(400, ["title" => L10n::t('Bad Request')]);
+ }
+
$content = add_page_info($_REQUEST["url"]);
$x = [
@@ -37,12 +43,12 @@ function bookmarklet_content(App $a)
'default_location' => $a->user['default-location'],
'nickname' => $a->user['nickname'],
'lockstate' => ((is_array($a->user) && ((strlen($a->user['allow_cid'])) || (strlen($a->user['allow_gid'])) || (strlen($a->user['deny_cid'])) || (strlen($a->user['deny_gid'])))) ? 'lock' : 'unlock'),
- 'default_perms' => Acl::getDefaultUserPermissions($a->user),
- 'acl' => populate_acl($a->user, true),
+ 'default_perms' => ACL::getDefaultUserPermissions($a->user),
+ 'acl' => ACL::getFullSelectorHTML($a->user, true),
'bang' => '',
'visitor' => 'block',
'profile_uid' => local_user(),
- 'title' => trim($_REQUEST["title"], "*"),
+ 'title' => trim(defaults($_REQUEST, 'title', ''), "*"),
'content' => $content
];
$o = status_editor($a, $x, 0, false);