X-Git-Url: https://git.mxchange.org/?a=blobdiff_plain;f=mod%2Fpubsub.php;h=cae346493f4be64db27dd089ff1b5ac2103b3ce5;hb=221a659abeaf3bda3cefd88c80d1b7814f168f3e;hp=028b2ba95e6021aa443f6f85fb4fc6fbcaad9d42;hpb=32ee4ca4b1df1a98625ec363de25dd9ca014a1b6;p=friendica.git diff --git a/mod/pubsub.php b/mod/pubsub.php index 028b2ba95e..cae346493f 100644 --- a/mod/pubsub.php +++ b/mod/pubsub.php @@ -1,162 +1,157 @@ . + * + */ use Friendica\App; -use Friendica\Database\DBM; +use Friendica\Core\Logger; +use Friendica\Core\Protocol; +use Friendica\Database\DBA; +use Friendica\DI; +use Friendica\Model\Contact; use Friendica\Protocol\OStatus; +use Friendica\Util\Strings; +use Friendica\Util\Network; +use Friendica\Core\System; -function hub_return($valid,$body) { - +function hub_return($valid, $body) +{ if ($valid) { - header($_SERVER["SERVER_PROTOCOL"] . ' 200 ' . 'OK'); echo $body; - killme(); } else { - header($_SERVER["SERVER_PROTOCOL"] . ' 404 ' . 'Not Found'); - killme(); + throw new \Friendica\Network\HTTPException\NotFoundException(); } - - // NOTREACHED + exit(); } // when receiving an XML feed, always return OK -function hub_post_return() { - - header($_SERVER["SERVER_PROTOCOL"] . ' 200 ' . 'OK'); - killme(); - +function hub_post_return() +{ + throw new \Friendica\Network\HTTPException\OKException(); } - - -function pubsub_init(App $a) { - - $nick = (($a->argc > 1) ? notags(trim($a->argv[1])) : ''); +function pubsub_init(App $a) +{ + $nick = (($a->argc > 1) ? Strings::escapeTags(trim($a->argv[1])) : ''); $contact_id = (($a->argc > 2) ? intval($a->argv[2]) : 0 ); if ($_SERVER['REQUEST_METHOD'] === 'GET') { - $hub_mode = ((x($_GET,'hub_mode')) ? notags(trim($_GET['hub_mode'])) : ''); - $hub_topic = ((x($_GET,'hub_topic')) ? notags(trim($_GET['hub_topic'])) : ''); - $hub_challenge = ((x($_GET,'hub_challenge')) ? notags(trim($_GET['hub_challenge'])) : ''); - $hub_lease = ((x($_GET,'hub_lease_seconds')) ? notags(trim($_GET['hub_lease_seconds'])) : ''); - $hub_verify = ((x($_GET,'hub_verify_token')) ? notags(trim($_GET['hub_verify_token'])) : ''); + $hub_mode = Strings::escapeTags(trim($_GET['hub_mode'] ?? '')); + $hub_topic = Strings::escapeTags(trim($_GET['hub_topic'] ?? '')); + $hub_challenge = Strings::escapeTags(trim($_GET['hub_challenge'] ?? '')); + $hub_verify = Strings::escapeTags(trim($_GET['hub_verify_token'] ?? '')); - logger('pubsub: Subscription from ' . $_SERVER['REMOTE_ADDR'] . ' Mode: ' . $hub_mode . ' Nick: ' . $nick); - logger('pubsub: data: ' . print_r($_GET,true), LOGGER_DATA); + Logger::log('Subscription from ' . $_SERVER['REMOTE_ADDR'] . ' Mode: ' . $hub_mode . ' Nick: ' . $nick); + Logger::log('Data: ' . print_r($_GET,true), Logger::DATA); $subscribe = (($hub_mode === 'subscribe') ? 1 : 0); - $r = q("SELECT * FROM `user` WHERE `nickname` = '%s' AND `account_expired` = 0 AND `account_removed` = 0 LIMIT 1", - dbesc($nick) - ); - if (!DBM::is_result($r)) { - logger('pubsub: local account not found: ' . $nick); + $owner = DBA::selectFirst('user', ['uid'], ['nickname' => $nick, 'account_expired' => false, 'account_removed' => false]); + if (!DBA::isResult($owner)) { + Logger::log('Local account not found: ' . $nick); hub_return(false, ''); } + $condition = ['uid' => $owner['uid'], 'id' => $contact_id, 'blocked' => false, 'pending' => false]; - $owner = $r[0]; - - $sql_extra = ((strlen($hub_verify)) ? sprintf(" AND `hub-verify` = '%s' ", dbesc($hub_verify)) : ''); + if (!empty($hub_verify)) { + $condition['hub-verify'] = $hub_verify; + } - $r = q("SELECT * FROM `contact` WHERE `id` = %d AND `uid` = %d - AND `blocked` = 0 AND `pending` = 0 $sql_extra LIMIT 1", - intval($contact_id), - intval($owner['uid']) - ); - if (!DBM::is_result($r)) { - logger('pubsub: contact '.$contact_id.' not found.'); + $contact = DBA::selectFirst('contact', ['id', 'poll'], $condition); + if (!DBA::isResult($contact)) { + Logger::log('Contact ' . $contact_id . ' not found.'); hub_return(false, ''); } - if ($hub_topic) { - if (!link_compare($hub_topic,$r[0]['poll'])) { - logger('pubsub: hub topic ' . $hub_topic . ' != ' . $r[0]['poll']); - // should abort but let's humour them. - } + if (!empty($hub_topic) && !Strings::compareLink($hub_topic, $contact['poll'])) { + Logger::log('Hub topic ' . $hub_topic . ' != ' . $contact['poll']); + hub_return(false, ''); } - $contact = $r[0]; - // We must initiate an unsubscribe request with a verify_token. // Don't allow outsiders to unsubscribe us. - if ($hub_mode === 'unsubscribe') { - if (!strlen($hub_verify)) { - logger('pubsub: bogus unsubscribe'); - hub_return(false, ''); - } - logger('pubsub: unsubscribe success'); + if (($hub_mode === 'unsubscribe') && empty($hub_verify)) { + Logger::log('Bogus unsubscribe'); + hub_return(false, ''); } - if ($hub_mode) { - dba::update('contact', ['subhub' => $subscribe], ['id' => $contact['id']]); + if (!empty($hub_mode)) { + DBA::update('contact', ['subhub' => $subscribe], ['id' => $contact['id']]); + Logger::log($hub_mode . ' success for contact ' . $contact_id . '.'); } hub_return(true, $hub_challenge); } } -require_once('include/security.php'); - -function pubsub_post(App $a) { +function pubsub_post(App $a) +{ + $xml = Network::postdata(); - $xml = file_get_contents('php://input'); + Logger::log('Feed arrived from ' . $_SERVER['REMOTE_ADDR'] . ' for ' . DI::args()->getCommand() . ' with user-agent: ' . $_SERVER['HTTP_USER_AGENT']); + Logger::log('Data: ' . $xml, Logger::DATA); - logger('pubsub: feed arrived from ' . $_SERVER['REMOTE_ADDR'] . ' for ' . $a->cmd ); - logger('pubsub: user-agent: ' . $_SERVER['HTTP_USER_AGENT'] ); - logger('pubsub: data: ' . $xml, LOGGER_DATA); - - $nick = (($a->argc > 1) ? notags(trim($a->argv[1])) : ''); + $nick = (($a->argc > 1) ? Strings::escapeTags(trim($a->argv[1])) : ''); $contact_id = (($a->argc > 2) ? intval($a->argv[2]) : 0 ); - $r = q("SELECT * FROM `user` WHERE `nickname` = '%s' AND `account_expired` = 0 AND `account_removed` = 0 LIMIT 1", - dbesc($nick) - ); - if (!DBM::is_result($r)) { + $importer = DBA::selectFirst('user', [], ['nickname' => $nick, 'account_expired' => false, 'account_removed' => false]); + if (!DBA::isResult($importer)) { hub_post_return(); } - $importer = $r[0]; - - $r = q("SELECT * FROM `contact` WHERE `subhub` AND `id` = %d AND `uid` = %d - AND (`rel` = %d OR `rel` = %d OR network = '%s') AND NOT `blocked` LIMIT 1", - intval($contact_id), - intval($importer['uid']), - intval(CONTACT_IS_SHARING), - intval(CONTACT_IS_FRIEND), - dbesc(NETWORK_FEED) - ); + $condition = ['id' => $contact_id, 'uid' => $importer['uid'], 'subhub' => true, 'blocked' => false]; + $contact = DBA::selectFirst('contact', [], $condition); - if (!DBM::is_result($r)) { + if (!DBA::isResult($contact)) { $author = OStatus::salmonAuthor($xml, $importer); if (!empty($author['contact-id'])) { - $contact = dba::selectFirst('contact', [], ['id' => $author['contact-id']]); - if (!in_array($contact['rel'], [CONTACT_IS_SHARING, CONTACT_IS_FRIEND]) && ($contact['network'] != NETWORK_FEED)) { - logger('Contact ' . $author['contact-id'] . ' is not expected to share with us - ignored.'); - hub_post_return(); - } - logger('pubsub: no contact record for "'.$nick.' ('.$contact_id.')" - using '.$author['contact-id'].' instead.'); + $condition = ['id' => $author['contact-id'], 'uid' => $importer['uid'], 'subhub' => true, 'blocked' => false]; + $contact = DBA::selectFirst('contact', [], $condition); + Logger::log('No record for ' . $nick .' with contact id ' . $contact_id . ' - using '.$author['contact-id'].' instead.'); + } + if (!DBA::isResult($contact)) { + Logger::log('Contact ' . $author["author-link"] . ' (' . $contact_id . ') for user ' . $nick . " wasn't found - ignored. XML: " . $xml); + hub_post_return(); } - } else { - $contact = $r[0]; } - // we have no way to match Diaspora guid's with atom post id's and could get duplicates. - // we'll assume that direct delivery is robust (and this is a bad assumption, but the duplicates are messy). - - if ($r[0]['network'] === NETWORK_DIASPORA) { + if (!in_array($contact['rel'], [Contact::SHARING, Contact::FRIEND]) && ($contact['network'] != Protocol::FEED)) { + Logger::log('Contact ' . $contact['id'] . ' is not expected to share with us - ignored.'); hub_post_return(); } - $feedhub = ''; - require_once('include/items.php'); - - consume_feed($xml,$importer,$contact,$feedhub,1,1); + // We import feeds from OStatus, Friendica and ATOM/RSS. + /// @todo Check if Friendica posts really arrive here - otherwise we can discard some stuff + if (!in_array($contact['network'], [Protocol::OSTATUS, Protocol::DFRN, Protocol::FEED])) { + hub_post_return(); + } - // do it a second time so that any children find their parents. + Logger::log('Import item for ' . $nick . ' from ' . $contact['nick'] . ' (' . $contact['id'] . ')'); + $feedhub = ''; + consume_feed($xml, $importer, $contact, $feedhub); - consume_feed($xml,$importer,$contact,$feedhub,1,2); + // do it a second time for DFRN so that any children find their parents. + if ($contact['network'] === Protocol::DFRN) { + consume_feed($xml, $importer, $contact, $feedhub); + } hub_post_return(); - }