]> git.wh0rd.org - tt-rss.git/blame - classes/rpc.php
prevent absolutely useless 'exploit' (not really) while editing filters (closes ...
[tt-rss.git] / classes / rpc.php
CommitLineData
d5112468 1<?php
369dbc19 2class RPC extends Handler_Protected {
d5112468 3
8484ce22 4 function csrf_ignore($method) {
6c2637d9 5 $csrf_ignored = array("sanitycheck", "completelabels");
8484ce22
AD
6
7 return array_search($method, $csrf_ignored) !== false;
8 }
9
d5112468
AD
10 function setprofile() {
11 $id = db_escape_string($_REQUEST["id"]);
46da73c2 12
d5112468
AD
13 $_SESSION["profile"] = $id;
14 $_SESSION["prefs_cache"] = array();
15 }
16
17 function remprofiles() {
18 $ids = explode(",", db_escape_string(trim($_REQUEST["ids"])));
19
20 foreach ($ids as $id) {
21 if ($_SESSION["profile"] != $id) {
22 db_query($this->link, "DELETE FROM ttrss_settings_profiles WHERE id = '$id' AND
23 owner_uid = " . $_SESSION["uid"]);
24 }
25 }
26 }
27
28 // Silent
29 function addprofile() {
30 $title = db_escape_string(trim($_REQUEST["title"]));
31 if ($title) {
32 db_query($this->link, "BEGIN");
33
34 $result = db_query($this->link, "SELECT id FROM ttrss_settings_profiles
35 WHERE title = '$title' AND owner_uid = " . $_SESSION["uid"]);
36
37 if (db_num_rows($result) == 0) {
38
39 db_query($this->link, "INSERT INTO ttrss_settings_profiles (title, owner_uid)
40 VALUES ('$title', ".$_SESSION["uid"] .")");
41
42 $result = db_query($this->link, "SELECT id FROM ttrss_settings_profiles WHERE
43 title = '$title'");
44
45 if (db_num_rows($result) != 0) {
46 $profile_id = db_fetch_result($result, 0, "id");
47
48 if ($profile_id) {
49 initialize_user_prefs($this->link, $_SESSION["uid"], $profile_id);
50 }
51 }
52 }
53
54 db_query($this->link, "COMMIT");
55 }
56 }
57
58 // Silent
59 function saveprofile() {
60 $id = db_escape_string($_REQUEST["id"]);
61 $title = db_escape_string(trim($_REQUEST["value"]));
62
63 if ($id == 0) {
64 print __("Default profile");
65 return;
66 }
67
68 if ($title) {
69 db_query($this->link, "BEGIN");
70
71 $result = db_query($this->link, "SELECT id FROM ttrss_settings_profiles
72 WHERE title = '$title' AND owner_uid =" . $_SESSION["uid"]);
73
74 if (db_num_rows($result) == 0) {
75 db_query($this->link, "UPDATE ttrss_settings_profiles
76 SET title = '$title' WHERE id = '$id' AND
77 owner_uid = " . $_SESSION["uid"]);
78 print $title;
79 } else {
80 $result = db_query($this->link, "SELECT title FROM ttrss_settings_profiles
81 WHERE id = '$id' AND owner_uid =" . $_SESSION["uid"]);
82 print db_fetch_result($result, 0, "title");
83 }
84
85 db_query($this->link, "COMMIT");
86 }
87 }
88
89 // Silent
90 function remarchive() {
91 $ids = explode(",", db_escape_string($_REQUEST["ids"]));
92
93 foreach ($ids as $id) {
94 $result = db_query($this->link, "DELETE FROM ttrss_archived_feeds WHERE
95 (SELECT COUNT(*) FROM ttrss_user_entries
96 WHERE orig_feed_id = '$id') = 0 AND
97 id = '$id' AND owner_uid = ".$_SESSION["uid"]);
98
99 $rc = db_affected_rows($this->link, $result);
100 }
101 }
102
103 function addfeed() {
104 $feed = db_escape_string($_REQUEST['feed']);
105 $cat = db_escape_string($_REQUEST['cat']);
106 $login = db_escape_string($_REQUEST['login']);
107 $pass = db_escape_string($_REQUEST['pass']);
aa60999b 108 $need_auth = db_escape_string($_REQUEST['need_auth']) != "";
d5112468 109
aa60999b 110 $rc = subscribe_to_feed($this->link, $feed, $cat, $login, $pass, $need_auth);
d5112468
AD
111
112 print json_encode(array("result" => $rc));
113 }
114
d5112468
AD
115 function togglepref() {
116 $key = db_escape_string($_REQUEST["key"]);
117 set_pref($this->link, $key, !get_pref($this->link, $key));
118 $value = get_pref($this->link, $key);
119
120 print json_encode(array("param" =>$key, "value" => $value));
121 }
122
123 function setpref() {
0380cfa9 124 // set_pref escapes input, so no need to double escape it here
74eef4fc
AD
125 $key = $_REQUEST['key'];
126 $value = str_replace("\n", "<br/>", $_REQUEST['value']);
d5112468 127
7e431502 128 set_pref($this->link, $key, $value, $_SESSION['uid'], $key != 'USER_STYLESHEET');
d5112468
AD
129
130 print json_encode(array("param" =>$key, "value" => $value));
131 }
132
133 function mark() {
134 $mark = $_REQUEST["mark"];
135 $id = db_escape_string($_REQUEST["id"]);
136
137 if ($mark == "1") {
138 $mark = "true";
139 } else {
140 $mark = "false";
141 }
142
143 $result = db_query($this->link, "UPDATE ttrss_user_entries SET marked = $mark
144 WHERE ref_id = '$id' AND owner_uid = " . $_SESSION["uid"]);
145
146 print json_encode(array("message" => "UPDATE_COUNTERS"));
147 }
148
149 function delete() {
150 $ids = db_escape_string($_REQUEST["ids"]);
151
152 $result = db_query($this->link, "DELETE FROM ttrss_user_entries
153 WHERE ref_id IN ($ids) AND owner_uid = " . $_SESSION["uid"]);
154
155 print json_encode(array("message" => "UPDATE_COUNTERS"));
156 }
157
158 function unarchive() {
159 $ids = db_escape_string($_REQUEST["ids"]);
160
161 $result = db_query($this->link, "UPDATE ttrss_user_entries
162 SET feed_id = orig_feed_id, orig_feed_id = NULL
163 WHERE ref_id IN ($ids) AND owner_uid = " . $_SESSION["uid"]);
164
165 print json_encode(array("message" => "UPDATE_COUNTERS"));
166 }
167
168 function archive() {
169 $ids = explode(",", db_escape_string($_REQUEST["ids"]));
170
171 foreach ($ids as $id) {
87d7e850 172 $this->archive_article($this->link, $id, $_SESSION["uid"]);
d5112468
AD
173 }
174
175 print json_encode(array("message" => "UPDATE_COUNTERS"));
176 }
177
87d7e850
AD
178 private function archive_article($link, $id, $owner_uid) {
179 db_query($link, "BEGIN");
180
181 $result = db_query($link, "SELECT feed_id FROM ttrss_user_entries
182 WHERE ref_id = '$id' AND owner_uid = $owner_uid");
183
184 if (db_num_rows($result) != 0) {
185
186 /* prepare the archived table */
187
188 $feed_id = (int) db_fetch_result($result, 0, "feed_id");
189
190 if ($feed_id) {
191 $result = db_query($link, "SELECT id FROM ttrss_archived_feeds
192 WHERE id = '$feed_id'");
193
194 if (db_num_rows($result) == 0) {
195 db_query($link, "INSERT INTO ttrss_archived_feeds
196 (id, owner_uid, title, feed_url, site_url)
197 SELECT id, owner_uid, title, feed_url, site_url from ttrss_feeds
198 WHERE id = '$feed_id'");
199 }
200
201 db_query($link, "UPDATE ttrss_user_entries
202 SET orig_feed_id = feed_id, feed_id = NULL
203 WHERE ref_id = '$id' AND owner_uid = " . $_SESSION["uid"]);
204 }
205 }
206
207 db_query($link, "COMMIT");
208 }
209
d5112468
AD
210 function publ() {
211 $pub = $_REQUEST["pub"];
212 $id = db_escape_string($_REQUEST["id"]);
213 $note = trim(strip_tags(db_escape_string($_REQUEST["note"])));
214
215 if ($pub == "1") {
216 $pub = "true";
217 } else {
218 $pub = "false";
219 }
220
221 $result = db_query($this->link, "UPDATE ttrss_user_entries SET
46b78149 222 published = $pub, last_read = NOW()
d5112468
AD
223 WHERE ref_id = '$id' AND owner_uid = " . $_SESSION["uid"]);
224
225 $pubsub_result = false;
226
227 if (PUBSUBHUBBUB_HUB) {
228 $rss_link = get_self_url_prefix() .
229 "/public.php?op=rss&id=-2&key=" .
230 get_feed_access_key($this->link, -2, false);
231
232 $p = new Publisher(PUBSUBHUBBUB_HUB);
233
234 $pubsub_result = $p->publish_update($rss_link);
235 }
236
237 print json_encode(array("message" => "UPDATE_COUNTERS",
238 "pubsub_result" => $pubsub_result));
239 }
240
241 function getAllCounters() {
242 $last_article_id = (int) $_REQUEST["last_article_id"];
243
244 $reply = array();
245
5b55e9e2 246 if ($seq) $reply['seq'] = $seq;
d5112468 247
5b55e9e2
AD
248 if ($last_article_id != getLastArticleId($this->link)) {
249 $reply['counters'] = getAllCounters($this->link);
250 }
d5112468 251
5b55e9e2 252 $reply['runtime-info'] = make_runtime_info($this->link);
d5112468 253
5b55e9e2 254 print json_encode($reply);
d5112468
AD
255 }
256
257 /* GET["cmode"] = 0 - mark as read, 1 - as unread, 2 - toggle */
258 function catchupSelected() {
259 $ids = explode(",", db_escape_string($_REQUEST["ids"]));
260 $cmode = sprintf("%d", $_REQUEST["cmode"]);
261
262 catchupArticlesById($this->link, $ids, $cmode);
263
264 print json_encode(array("message" => "UPDATE_COUNTERS"));
265 }
266
267 function markSelected() {
268 $ids = explode(",", db_escape_string($_REQUEST["ids"]));
269 $cmode = sprintf("%d", $_REQUEST["cmode"]);
270
87d7e850 271 $this->markArticlesById($this->link, $ids, $cmode);
d5112468
AD
272
273 print json_encode(array("message" => "UPDATE_COUNTERS"));
274 }
275
276 function publishSelected() {
277 $ids = explode(",", db_escape_string($_REQUEST["ids"]));
278 $cmode = sprintf("%d", $_REQUEST["cmode"]);
279
87d7e850 280 $this->publishArticlesById($this->link, $ids, $cmode);
d5112468
AD
281
282 print json_encode(array("message" => "UPDATE_COUNTERS"));
283 }
284
285 function sanityCheck() {
286 $_SESSION["hasAudio"] = $_REQUEST["hasAudio"] === "true";
287
288 $reply = array();
289
290 $reply['error'] = sanity_check($this->link);
291
292 if ($reply['error']['code'] == 0) {
293 $reply['init-params'] = make_init_params($this->link);
294 $reply['runtime-info'] = make_runtime_info($this->link);
295 }
296
297 print json_encode($reply);
298 }
299
300 function setArticleTags() {
d5112468
AD
301
302 $id = db_escape_string($_REQUEST["id"]);
303
304 $tags_str = db_escape_string($_REQUEST["tags_str"]);
305 $tags = array_unique(trim_array(explode(",", $tags_str)));
306
307 db_query($this->link, "BEGIN");
308
309 $result = db_query($this->link, "SELECT int_id FROM ttrss_user_entries WHERE
310 ref_id = '$id' AND owner_uid = '".$_SESSION["uid"]."' LIMIT 1");
311
312 if (db_num_rows($result) == 1) {
313
314 $tags_to_cache = array();
315
316 $int_id = db_fetch_result($result, 0, "int_id");
317
318 db_query($this->link, "DELETE FROM ttrss_tags WHERE
319 post_int_id = $int_id AND owner_uid = '".$_SESSION["uid"]."'");
320
321 foreach ($tags as $tag) {
322 $tag = sanitize_tag($tag);
323
324 if (!tag_is_valid($tag)) {
325 continue;
326 }
327
328 if (preg_match("/^[0-9]*$/", $tag)) {
329 continue;
330 }
331
332 // print "<!-- $id : $int_id : $tag -->";
333
334 if ($tag != '') {
335 db_query($this->link, "INSERT INTO ttrss_tags
336 (post_int_id, owner_uid, tag_name) VALUES ('$int_id', '".$_SESSION["uid"]."', '$tag')");
337 }
338
339 array_push($tags_to_cache, $tag);
340 }
341
342 /* update tag cache */
343
344 sort($tags_to_cache);
345 $tags_str = join(",", $tags_to_cache);
346
347 db_query($this->link, "UPDATE ttrss_user_entries
348 SET tag_cache = '$tags_str' WHERE ref_id = '$id'
349 AND owner_uid = " . $_SESSION["uid"]);
350 }
351
352 db_query($this->link, "COMMIT");
353
d5112468
AD
354 $tags = get_article_tags($this->link, $id);
355 $tags_str = format_tags_string($tags, $id);
356 $tags_str_full = join(", ", $tags);
357
358 if (!$tags_str_full) $tags_str_full = __("no tags");
359
360 print json_encode(array("tags_str" => array("id" => $id,
361 "content" => $tags_str, "content_full" => $tags_str_full)));
362 }
363
364 function regenOPMLKey() {
87d7e850 365 $this->update_feed_access_key($this->link, 'OPML:Publish',
d5112468
AD
366 false, $_SESSION["uid"]);
367
50832719 368 $new_link = Opml::opml_publish_url($this->link);
d5112468
AD
369
370 print json_encode(array("link" => $new_link));
371 }
372
1b4d1a6b
AD
373 function completeLabels() {
374 $search = db_escape_string($_REQUEST["search"]);
375
376 $result = db_query($this->link, "SELECT DISTINCT caption FROM
377 ttrss_labels2
378 WHERE owner_uid = '".$_SESSION["uid"]."' AND
379 LOWER(caption) LIKE LOWER('$search%') ORDER BY caption
380 LIMIT 5");
381
382 print "<ul>";
383 while ($line = db_fetch_assoc($result)) {
384 print "<li>" . $line["caption"] . "</li>";
385 }
386 print "</ul>";
387 }
388
389
d5112468
AD
390 function completeTags() {
391 $search = db_escape_string($_REQUEST["search"]);
392
393 $result = db_query($this->link, "SELECT DISTINCT tag_name FROM ttrss_tags
394 WHERE owner_uid = '".$_SESSION["uid"]."' AND
395 tag_name LIKE '$search%' ORDER BY tag_name
396 LIMIT 10");
397
398 print "<ul>";
399 while ($line = db_fetch_assoc($result)) {
400 print "<li>" . $line["tag_name"] . "</li>";
401 }
402 print "</ul>";
403 }
404
405 function purge() {
406 $ids = explode(",", db_escape_string($_REQUEST["ids"]));
407 $days = sprintf("%d", $_REQUEST["days"]);
408
409 foreach ($ids as $id) {
410
411 $result = db_query($this->link, "SELECT id FROM ttrss_feeds WHERE
412 id = '$id' AND owner_uid = ".$_SESSION["uid"]);
413
414 if (db_num_rows($result) == 1) {
415 purge_feed($this->link, $id, $days);
416 }
417 }
418 }
419
420 function getArticles() {
421 $ids = explode(",", db_escape_string($_REQUEST["ids"]));
422 $articles = array();
423
424 foreach ($ids as $id) {
425 if ($id) {
426 array_push($articles, format_article($this->link, $id, 0, false));
427 }
428 }
429
430 print json_encode($articles);
431 }
432
433 function checkDate() {
434 $date = db_escape_string($_REQUEST["date"]);
435 $date_parsed = strtotime($date);
436
437 print json_encode(array("result" => (bool)$date_parsed,
438 "date" => date("c", $date_parsed)));
439 }
440
441 function assigntolabel() {
4fdb8759 442 return $this->labelops(true);
d5112468 443 }
46da73c2 444
d5112468 445 function removefromlabel() {
4fdb8759 446 return $this->labelops(false);
d5112468 447 }
46da73c2 448
d5112468
AD
449 function labelops($assign) {
450 $reply = array();
451
452 $ids = explode(",", db_escape_string($_REQUEST["ids"]));
453 $label_id = db_escape_string($_REQUEST["lid"]);
454
455 $label = db_escape_string(label_find_caption($this->link, $label_id,
456 $_SESSION["uid"]));
457
458 $reply["info-for-headlines"] = array();
459
460 if ($label) {
461
462 foreach ($ids as $id) {
463
464 if ($assign)
465 label_add_article($this->link, $id, $label, $_SESSION["uid"]);
466 else
467 label_remove_article($this->link, $id, $label, $_SESSION["uid"]);
468
469 $labels = get_article_labels($this->link, $id, $_SESSION["uid"]);
470
471 array_push($reply["info-for-headlines"],
472 array("id" => $id, "labels" => format_article_labels($labels, $id)));
473
474 }
475 }
476
477 $reply["message"] = "UPDATE_COUNTERS";
478
479 print json_encode($reply);
480 }
481
482 function updateFeedBrowser() {
483 $search = db_escape_string($_REQUEST["search"]);
484 $limit = db_escape_string($_REQUEST["limit"]);
485 $mode = (int) db_escape_string($_REQUEST["mode"]);
486
55c7f092
AD
487 require_once "feedbrowser.php";
488
d5112468
AD
489 print json_encode(array("content" =>
490 make_feed_browser($this->link, $search, $limit, $mode),
491 "mode" => $mode));
492 }
493
494 // Silent
495 function massSubscribe() {
496
497 $payload = json_decode($_REQUEST["payload"], false);
498 $mode = $_REQUEST["mode"];
499
500 if (!$payload || !is_array($payload)) return;
501
502 if ($mode == 1) {
503 foreach ($payload as $feed) {
504
505 $title = db_escape_string($feed[0]);
506 $feed_url = db_escape_string($feed[1]);
507
508 $result = db_query($this->link, "SELECT id FROM ttrss_feeds WHERE
509 feed_url = '$feed_url' AND owner_uid = " . $_SESSION["uid"]);
510
511 if (db_num_rows($result) == 0) {
512 $result = db_query($this->link, "INSERT INTO ttrss_feeds
513 (owner_uid,feed_url,title,cat_id,site_url)
514 VALUES ('".$_SESSION["uid"]."',
515 '$feed_url', '$title', NULL, '')");
516 }
517 }
518 } else if ($mode == 2) {
519 // feed archive
520 foreach ($payload as $id) {
521 $result = db_query($this->link, "SELECT * FROM ttrss_archived_feeds
522 WHERE id = '$id' AND owner_uid = " . $_SESSION["uid"]);
523
524 if (db_num_rows($result) != 0) {
525 $site_url = db_escape_string(db_fetch_result($result, 0, "site_url"));
526 $feed_url = db_escape_string(db_fetch_result($result, 0, "feed_url"));
527 $title = db_escape_string(db_fetch_result($result, 0, "title"));
528
529 $result = db_query($this->link, "SELECT id FROM ttrss_feeds WHERE
530 feed_url = '$feed_url' AND owner_uid = " . $_SESSION["uid"]);
531
532 if (db_num_rows($result) == 0) {
533 $result = db_query($this->link, "INSERT INTO ttrss_feeds
534 (owner_uid,feed_url,title,cat_id,site_url)
535 VALUES ('$id','".$_SESSION["uid"]."',
536 '$feed_url', '$title', NULL, '$site_url')");
537 }
538 }
539 }
540 }
541 }
542
d5112468
AD
543 function catchupFeed() {
544 $feed_id = db_escape_string($_REQUEST['feed_id']);
545 $is_cat = db_escape_string($_REQUEST['is_cat']) == "true";
184f5195 546 $max_id = (int) db_escape_string($_REQUEST['max_id']);
d5112468 547
184f5195 548 catchup_feed($this->link, $feed_id, $is_cat, false, $max_id);
d5112468
AD
549
550 print json_encode(array("message" => "UPDATE_COUNTERS"));
551 }
552
d5112468
AD
553 function quickAddCat() {
554 $cat = db_escape_string($_REQUEST["cat"]);
555
556 add_feed_category($this->link, $cat);
557
558 $result = db_query($this->link, "SELECT id FROM ttrss_feed_categories WHERE
559 title = '$cat' AND owner_uid = " . $_SESSION["uid"]);
560
561 if (db_num_rows($result) == 1) {
562 $id = db_fetch_result($result, 0, "id");
563 } else {
564 $id = 0;
565 }
566
567 print_feed_cat_select($this->link, "cat_id", $id);
568 }
569
570 function regenFeedKey() {
571 $feed_id = db_escape_string($_REQUEST['id']);
572 $is_cat = db_escape_string($_REQUEST['is_cat']) == "true";
573
87d7e850 574 $new_key = $this->update_feed_access_key($this->link, $feed_id, $is_cat);
d5112468
AD
575
576 print json_encode(array("link" => $new_key));
577 }
578
579 // Silent
580 function clearKeys() {
581 db_query($this->link, "DELETE FROM ttrss_access_keys WHERE
582 owner_uid = " . $_SESSION["uid"]);
583 }
584
585 // Silent
586 function clearArticleKeys() {
587 db_query($this->link, "UPDATE ttrss_user_entries SET uuid = '' WHERE
588 owner_uid = " . $_SESSION["uid"]);
589
590 return;
591 }
592
d5112468
AD
593 function verifyRegexp() {
594 $reg_exp = $_REQUEST["reg_exp"];
595
596 $status = @preg_match("/$reg_exp/i", "TEST") !== false;
597
598 print json_encode(array("status" => $status));
599 }
600
19c73507 601 /* function buttonPlugin() {
369dbc19 602 $pclass = "button_" . basename($_REQUEST['plugin']);
f9ac31d6
AD
603 $method = $_REQUEST['plugin_method'];
604
605 if (class_exists($pclass)) {
606 $plugin = new $pclass($this->link);
607 if (method_exists($plugin, $method)) {
608 return $plugin->$method();
609 }
d5112468 610 }
19c73507 611 } */
d5112468 612
d5112468
AD
613 function genHash() {
614 $hash = sha1(uniqid(rand(), true));
615
616 print json_encode(array("hash" => $hash));
617 }
33f0fdd0
AD
618
619 function batchAddFeeds() {
620 $cat_id = db_escape_string($_REQUEST['cat']);
621 $feeds = explode("\n", db_escape_string($_REQUEST['feeds']));
622 $login = db_escape_string($_REQUEST['login']);
623 $pass = db_escape_string($_REQUEST['pass']);
624 $need_auth = db_escape_string($_REQUEST['need_auth']) != "";
625
33f0fdd0
AD
626 foreach ($feeds as $feed) {
627 $feed = trim($feed);
628
629 if (validate_feed_url($feed)) {
630
631 db_query($this->link, "BEGIN");
632
33f0fdd0
AD
633 if ($cat_id == "0" || !$cat_id) {
634 $cat_qpart = "NULL";
635 } else {
636 $cat_qpart = "'$cat_id'";
637 }
638
639 $result = db_query($this->link,
640 "SELECT id FROM ttrss_feeds
641 WHERE feed_url = '$feed' AND owner_uid = ".$_SESSION["uid"]);
642
643 if (db_num_rows($result) == 0) {
644 $result = db_query($this->link,
645 "INSERT INTO ttrss_feeds
646 (owner_uid,feed_url,title,cat_id,auth_login,auth_pass,update_method)
647 VALUES ('".$_SESSION["uid"]."', '$feed',
19b3992b 648 '[Unknown]', $cat_qpart, '$login', '$pass', 0)");
33f0fdd0
AD
649 }
650
651 db_query($this->link, "COMMIT");
652 }
653 }
654 }
655
beb6ce27 656 function setScore() {
29064218 657 $ids = db_escape_string($_REQUEST['id']);
beb6ce27
AD
658 $score = (int)db_escape_string($_REQUEST['score']);
659
660 db_query($this->link, "UPDATE ttrss_user_entries SET
29064218 661 score = '$score' WHERE ref_id IN ($ids) AND owner_uid = " . $_SESSION["uid"]);
beb6ce27
AD
662
663 print json_encode(array("id" => $id,
664 "score_pic" => theme_image($link, get_score_pic($score))));
665 }
666
7d8f5657
AD
667 function setpanelmode() {
668 $wide = (int) $_REQUEST["wide"];
669
f03701fe
AD
670 setcookie("ttrss_widescreen", $wide,
671 time() + SESSION_COOKIE_LIFETIME);
7d8f5657
AD
672
673 print json_encode(array("wide" => $wide));
674 }
675
8b83bf5f
AD
676 function updaterandomfeed() {
677 // Test if the feed need a update (update interval exceded).
678 if (DB_TYPE == "pgsql") {
679 $update_limit_qpart = "AND ((
680 ttrss_feeds.update_interval = 0
681 AND ttrss_feeds.last_updated < NOW() - CAST((ttrss_user_prefs.value || ' minutes') AS INTERVAL)
682 ) OR (
683 ttrss_feeds.update_interval > 0
684 AND ttrss_feeds.last_updated < NOW() - CAST((ttrss_feeds.update_interval || ' minutes') AS INTERVAL)
685 ) OR ttrss_feeds.last_updated IS NULL
686 OR last_updated = '1970-01-01 00:00:00')";
687 } else {
688 $update_limit_qpart = "AND ((
689 ttrss_feeds.update_interval = 0
690 AND ttrss_feeds.last_updated < DATE_SUB(NOW(), INTERVAL CONVERT(ttrss_user_prefs.value, SIGNED INTEGER) MINUTE)
691 ) OR (
692 ttrss_feeds.update_interval > 0
693 AND ttrss_feeds.last_updated < DATE_SUB(NOW(), INTERVAL ttrss_feeds.update_interval MINUTE)
694 ) OR ttrss_feeds.last_updated IS NULL
695 OR last_updated = '1970-01-01 00:00:00')";
696 }
697
698 // Test if feed is currently being updated by another process.
699 if (DB_TYPE == "pgsql") {
700 $updstart_thresh_qpart = "AND (ttrss_feeds.last_update_started IS NULL OR ttrss_feeds.last_update_started < NOW() - INTERVAL '5 minutes')";
701 } else {
702 $updstart_thresh_qpart = "AND (ttrss_feeds.last_update_started IS NULL OR ttrss_feeds.last_update_started < DATE_SUB(NOW(), INTERVAL 5 MINUTE))";
703 }
704
705 $random_qpart = sql_random_function();
706
707 // We search for feed needing update.
708 $result = db_query($this->link, "SELECT ttrss_feeds.feed_url,ttrss_feeds.id
709 FROM
710 ttrss_feeds, ttrss_users, ttrss_user_prefs
711 WHERE
712 ttrss_feeds.owner_uid = ttrss_users.id
713 AND ttrss_users.id = ttrss_user_prefs.owner_uid
714 AND ttrss_user_prefs.pref_name = 'DEFAULT_UPDATE_INTERVAL'
715 AND ttrss_feeds.owner_uid = ".$_SESSION["uid"]."
716 $update_limit_qpart $updstart_thresh_qpart
717 ORDER BY $random_qpart LIMIT 30");
718
719 $feed_id = -1;
720
721 require_once "rssfuncs.php";
722
723 $num_updated = 0;
724
725 $tstart = time();
726
727 while ($line = db_fetch_assoc($result)) {
728 $feed_id = $line["id"];
729
6b1a4ecd 730 if (time() - $tstart < ini_get("max_execution_time") * 0.7) {
8b83bf5f
AD
731 update_rss_feed($this->link, $feed_id, true);
732 ++$num_updated;
733 } else {
734 break;
735 }
736 }
737
738 if ($num_updated > 0) {
739 print json_encode(array("message" => "UPDATE_COUNTERS",
740 "num_updated" => $num_updated));
741 } else {
742 print json_encode(array("message" => "NOTHING_TO_UPDATE"));
743 }
744
745 }
746
87d7e850
AD
747 function update_feed_access_key($link, $feed_id, $is_cat, $owner_uid = false) {
748 if (!$owner_uid) $owner_uid = $_SESSION["uid"];
749
750 $sql_is_cat = bool_to_sql_bool($is_cat);
751
752 $result = db_query($link, "SELECT access_key FROM ttrss_access_keys
753 WHERE feed_id = '$feed_id' AND is_cat = $sql_is_cat
754 AND owner_uid = " . $owner_uid);
755
756 if (db_num_rows($result) == 1) {
757 $key = db_escape_string(sha1(uniqid(rand(), true)));
758
759 db_query($link, "UPDATE ttrss_access_keys SET access_key = '$key'
760 WHERE feed_id = '$feed_id' AND is_cat = $sql_is_cat
761 AND owner_uid = " . $owner_uid);
762
763 return $key;
764
765 } else {
766 return get_feed_access_key($link, $feed_id, $is_cat, $owner_uid);
767 }
768 }
769
770 private function markArticlesById($link, $ids, $cmode) {
771
772 $tmp_ids = array();
773
774 foreach ($ids as $id) {
775 array_push($tmp_ids, "ref_id = '$id'");
776 }
777
778 $ids_qpart = join(" OR ", $tmp_ids);
779
780 if ($cmode == 0) {
781 db_query($link, "UPDATE ttrss_user_entries SET
782 marked = false,last_read = NOW()
783 WHERE ($ids_qpart) AND owner_uid = " . $_SESSION["uid"]);
784 } else if ($cmode == 1) {
785 db_query($link, "UPDATE ttrss_user_entries SET
786 marked = true
787 WHERE ($ids_qpart) AND owner_uid = " . $_SESSION["uid"]);
788 } else {
789 db_query($link, "UPDATE ttrss_user_entries SET
790 marked = NOT marked,last_read = NOW()
791 WHERE ($ids_qpart) AND owner_uid = " . $_SESSION["uid"]);
792 }
793 }
794
795 private function publishArticlesById($link, $ids, $cmode) {
796
797 $tmp_ids = array();
798
799 foreach ($ids as $id) {
800 array_push($tmp_ids, "ref_id = '$id'");
801 }
802
803 $ids_qpart = join(" OR ", $tmp_ids);
804
805 if ($cmode == 0) {
806 db_query($link, "UPDATE ttrss_user_entries SET
807 published = false,last_read = NOW()
808 WHERE ($ids_qpart) AND owner_uid = " . $_SESSION["uid"]);
809 } else if ($cmode == 1) {
810 db_query($link, "UPDATE ttrss_user_entries SET
811 published = true,last_read = NOW()
812 WHERE ($ids_qpart) AND owner_uid = " . $_SESSION["uid"]);
813 } else {
814 db_query($link, "UPDATE ttrss_user_entries SET
815 published = NOT published,last_read = NOW()
816 WHERE ($ids_qpart) AND owner_uid = " . $_SESSION["uid"]);
817 }
818
819 if (PUBSUBHUBBUB_HUB) {
820 $rss_link = get_self_url_prefix() .
821 "/public.php?op=rss&id=-2&key=" .
822 get_feed_access_key($link, -2, false);
823
824 $p = new Publisher(PUBSUBHUBBUB_HUB);
825
826 $pubsub_result = $p->publish_update($rss_link);
827 }
828 }
829
d5112468
AD
830}
831?>