]> git.wh0rd.org - tt-rss.git/blame - api/index.php
api: forbid login when api is disabled
[tt-rss.git] / api / index.php
CommitLineData
378a548c
AD
1<?php
2
3 /* This is experimental JSON-based API. It has to be manually enabled:
4 *
5 * Add define('_JSON_API_ENABLED', true) to config.php
6 */
7
8 error_reporting(E_ERROR | E_PARSE);
9
10 require_once "../config.php";
11
12 require_once "../db.php";
13 require_once "../db-prefs.php";
14 require_once "../functions.php";
15
16 if (!defined('_JSON_API_ENABLED')) {
17 print json_encode(array("error" => "API_DISABLED"));
18 return;
19 }
20
21 $link = db_connect(DB_HOST, DB_USER, DB_PASS, DB_NAME);
22
23 $session_expire = SESSION_EXPIRE_TIME; //seconds
24 $session_name = (!defined('TTRSS_SESSION_NAME')) ? "ttrss_sid_api" : TTRSS_SESSION_NAME . "_api";
25
26 session_start();
27
28 if (!$link) {
29 if (DB_TYPE == "mysql") {
30 print mysql_error();
31 }
32 // PG seems to display its own errors just fine by default.
33 return;
34 }
35
36 init_connection($link);
37
38 $op = db_escape_string($_REQUEST["op"]);
39
40// header("Content-Type: application/json");
41
42 if (!$_SESSION["uid"] && $op != "login" && $op != "isLoggedIn") {
43 print json_encode(array("error" => 'NOT_LOGGED_IN'));
44 return;
45 }
46
3a216db4 47 if ($_SESSION["uid"] && $op != "logout" && !get_pref($link, 'ENABLE_API_ACCESS')) {
378a548c
AD
48 print json_encode(array("error" => 'API_DISABLED'));
49 return;
3a216db4 50 }
378a548c
AD
51
52 switch ($op) {
53 case "getVersion":
54 $rv = array("version" => VERSION);
55 print json_encode($rv);
56 break;
57 case "login":
58 $login = db_escape_string($_REQUEST["user"]);
59 $password = db_escape_string($_REQUEST["password"]);
60
4cdd0d7c
AD
61 if (get_pref($link, "ENABLE_API_ACCESS", $login)) {
62 if (authenticate_user($link, $login, $password)) {
63 print json_encode(array("uid" => $_SESSION["uid"]));
64 } else {
65 print json_encode(array("error" => "LOGIN_ERROR"));
66 }
378a548c 67 } else {
4cdd0d7c
AD
68 logout_user();
69 print json_encode(array("error" => "API_DISABLED"));
378a548c
AD
70 }
71
72 break;
73 case "logout":
74 logout_user();
75 print json_encode(array("uid" => 0));
76 break;
77 case "isLoggedIn":
78 print json_encode(array("status" => $_SESSION["uid"] != ''));
79 break;
03e5f9eb
AD
80 case "getUnread":
81 $feed_id = db_escape_string($_REQUEST["feed_id"]);
82 $is_cat = db_escape_string($_REQUEST["is_cat"]);
83
84 if ($feed_id) {
85 print json_encode(array("unread" => getFeedUnread($link, $feed_id, $is_cat)));
86 } else {
87 print json_encode(array("unread" => getGlobalUnread($link)));
88 }
89 break;
378a548c
AD
90 case "getFeeds":
91 $cat_id = db_escape_string($_REQUEST["cat_id"]);
92 $unread_only = (bool)db_escape_string($_REQUEST["unread_only"]);
93
94 if (!$cat_id) {
95 $result = db_query($link, "SELECT
96 id, feed_url, cat_id, title, ".
97 SUBSTRING_FOR_DATE."(last_updated,1,19) AS last_updated
98 FROM ttrss_feeds WHERE owner_uid = " . $_SESSION["uid"]);
99 } else {
100 $result = db_query($link, "SELECT
101 id, feed_url, cat_id, title, ".
102 SUBSTRING_FOR_DATE."(last_updated,1,19) AS last_updated
103 FROM ttrss_feeds WHERE
104 cat_id = '$cat_id' AND owner_uid = " . $_SESSION["uid"]);
105 }
106
107 $feeds = array();
108
109 while ($line = db_fetch_assoc($result)) {
110
111 $unread = getFeedUnread($link, $line["id"]);
112
113 if ($unread || !$unread_only) {
114
7e2b7e46 115 $row = array(
378a548c
AD
116 "feed_url" => $line["feed_url"],
117 "title" => $line["title"],
118 "id" => (int)$line["id"],
119 "unread" => (int)$unread,
120 "cat_id" => (int)$line["cat_id"],
121 "last_updated" => strtotime($line["last_updated"])
122 );
123
7e2b7e46
AD
124 array_push($feeds, $row);
125 }
126 }
127
53aff642
AD
128 /* Labels */
129
130 if (!$cat_id || $cat_id == -2) {
7e2b7e46
AD
131 $counters = getLabelCounters($link, false, true);
132
133 foreach (array_keys($counters) as $id) {
134
135 $unread = $counters[$id]["counter"];
136
137 if ($unread || !$unread_only) {
138
139 $row = array(
140 "id" => $id,
141 "title" => $counters[$id]["description"],
142 "unread" => $counters[$id]["counter"],
53aff642 143 "cat_id" => -2,
7e2b7e46
AD
144 );
145
146 array_push($feeds, $row);
147 }
378a548c
AD
148 }
149 }
150
53aff642
AD
151 /* Virtual feeds */
152
153 if (!$cat_id || $cat_id == -1) {
154 foreach (array(-1, -2, -3, -4) as $i) {
155 $unread = getFeedUnread($link, $i);
156
157 if ($unread || !$unread_only) {
158 $title = getFeedTitle($link, $i);
159
160 $row = array(
161 "id" => $i,
162 "title" => $title,
163 "unread" => $unread,
164 "cat_id" => -1,
165 );
166 array_push($feeds, $row);
167 }
168
169 }
170 }
171
378a548c
AD
172 print json_encode($feeds);
173
174 break;
175 case "getCategories":
730c97c7
AD
176 $unread_only = (bool)db_escape_string($_REQUEST["unread_only"]);
177
378a548c
AD
178 $result = db_query($link, "SELECT
179 id, title FROM ttrss_feed_categories
180 WHERE owner_uid = " .
181 $_SESSION["uid"]);
182
183 $cats = array();
184
185 while ($line = db_fetch_assoc($result)) {
186 $unread = getFeedUnread($link, $line["id"], true);
730c97c7
AD
187
188 if ($unread || !$unread_only) {
f1c2b672
AD
189 array_push($cats, array("id" => $line["id"],
190 "title" => $line["title"],
191 "unread" => $unread));
730c97c7 192 }
378a548c
AD
193 }
194
195 print json_encode($cats);
196 break;
197 case "getHeadlines":
198 $feed_id = db_escape_string($_REQUEST["feed_id"]);
199 $limit = (int)db_escape_string($_REQUEST["limit"]);
200 $filter = db_escape_string($_REQUEST["filter"]);
201 $is_cat = (bool)db_escape_string($_REQUEST["is_cat"]);
202 $show_except = (bool)db_escape_string($_REQUEST["show_excerpt"]);
203
204 /* do not rely on params below */
205
206 $search = db_escape_string($_REQUEST["search"]);
207 $search_mode = db_escape_string($_REQUEST["search_mode"]);
208 $match_on = db_escape_string($_REQUEST["match_on"]);
209
210 $qfh_ret = queryFeedHeadlines($link, $feed_id, $limit,
211 $view_mode, $is_cat, $search, $search_mode, $match_on);
212
213 $result = $qfh_ret[0];
214 $feed_title = $qfh_ret[1];
215
216 $headlines = array();
217
218 while ($line = db_fetch_assoc($result)) {
219 $is_updated = ($line["last_read"] == "" &&
220 ($line["unread"] != "t" && $line["unread"] != "1"));
221
222 $headline_row = array(
223 "id" => (int)$line["id"],
224 "unread" => sql_bool_to_bool($line["unread"]),
225 "marked" => sql_bool_to_bool($line["marked"]),
226 "updated" => strtotime($line["updated"]),
227 "is_updated" => $is_updated,
228 "title" => $line["title"],
229 "feed_id" => $line["feed_id"],
230 );
231
232 if ($show_except) $headline_row["excerpt"] = $line["content_preview"];
233
234 array_push($headlines, $headline_row);
235 }
236
237 print json_encode($headlines);
238
730c97c7 239 break;
1c3fffbb
AD
240 case "updateArticle":
241 $article_id = (int) db_escape_string($_GET["article_id"]);
242 $mode = (int) db_escape_string($_REQUEST["mode"]);
243 $field_raw = (int)db_escape_string($_REQUEST["field"]);
244
245 $field = "";
246 $set_to = "";
247
248 switch ($field_raw) {
249 case 0:
250 $field = "marked";
251 break;
252 case 1:
253 $field = "published";
254 break;
255 case 2:
256 $field = "unread";
257 break;
258 };
259
260 switch ($mode) {
261 case 1:
262 $set_to = "true";
263 break;
264 case 0:
265 $set_to = "false";
266 break;
267 case 2:
268 $set_to = "NOT $field";
269 break;
270 }
271
272 if ($field && $set_to) {
273 if ($field == "unread") {
274 $result = db_query($link, "UPDATE ttrss_user_entries SET $field = $set_to,
275 last_read = NOW()
276 WHERE ref_id = '$article_id' AND owner_uid = " . $_SESSION["uid"]);
277 } else {
278 $result = db_query($link, "UPDATE ttrss_user_entries SET $field = $set_to
279 WHERE ref_id = '$article_id' AND owner_uid = " . $_SESSION["uid"]);
280 }
281 }
282
283 break;
284
730c97c7
AD
285 case "getArticle":
286
287 $article_id = (int)db_escape_string($_REQUEST["article_id"]);
288
289 $query = "SELECT title,link,content,feed_id,comments,int_id,
1c3fffbb 290 marked,unread,published,
730c97c7
AD
291 ".SUBSTRING_FOR_DATE."(updated,1,16) as updated,
292 author
293 FROM ttrss_entries,ttrss_user_entries
294 WHERE id = '$article_id' AND ref_id = id AND owner_uid = " .
295 $_SESSION["uid"] ;
296
297 $result = db_query($link, $query);
298
299 $article = array();
300
301 if (db_num_rows($result) != 0) {
302 $line = db_fetch_assoc($result);
303
304 $article = array(
305 "title" => $line["title"],
306 "link" => $line["link"],
53aff642 307 "labels" => get_article_labels($link, $article_id),
730c97c7
AD
308 "unread" => sql_bool_to_bool($line["unread"]),
309 "marked" => sql_bool_to_bool($line["marked"]),
1c3fffbb 310 "published" => sql_bool_to_bool($line["published"]),
730c97c7
AD
311 "comments" => $line["comments"],
312 "author" => $line["author"],
313 "updated" => strtotime($line["updated"]),
314 "content" => $line["content"],
315 "feed_id" => $line["feed_id"],
316 );
317 }
318
319 print json_encode($article);
320
378a548c
AD
321 break;
322 }
323
324 db_close($link);
325
326?>