]>
Commit | Line | Data |
---|---|---|
1 | <?php | |
2 | class Handler_Public extends Handler { | |
3 | ||
4 | private function generate_syndicated_feed($owner_uid, $feed, $is_cat, | |
5 | $limit, $offset, $search, | |
6 | $view_mode = false, $format = 'atom', $order = false, $orig_guid = false, $start_ts = false) { | |
7 | ||
8 | require_once "lib/MiniTemplator.class.php"; | |
9 | ||
10 | $note_style = "background-color : #fff7d5; | |
11 | border-width : 1px; ". | |
12 | "padding : 5px; border-style : dashed; border-color : #e7d796;". | |
13 | "margin-bottom : 1em; color : #9a8c59;"; | |
14 | ||
15 | if (!$limit) $limit = 60; | |
16 | ||
17 | $date_sort_field = "date_entered DESC, updated DESC"; | |
18 | $date_check_field = "date_entered"; | |
19 | ||
20 | if ($feed == -2 && !$is_cat) { | |
21 | $date_sort_field = "last_published DESC"; | |
22 | $date_check_field = "last_published"; | |
23 | } else if ($feed == -1 && !$is_cat) { | |
24 | $date_sort_field = "last_marked DESC"; | |
25 | $date_check_field = "last_marked"; | |
26 | } | |
27 | ||
28 | switch ($order) { | |
29 | case "title": | |
30 | $date_sort_field = "ttrss_entries.title"; | |
31 | break; | |
32 | case "date_reverse": | |
33 | $date_sort_field = "date_entered, updated"; | |
34 | break; | |
35 | case "feed_dates": | |
36 | $date_sort_field = "updated DESC"; | |
37 | break; | |
38 | } | |
39 | ||
40 | /*$qfh_ret = queryFeedHeadlines($feed, | |
41 | 1, $view_mode, $is_cat, $search, false, | |
42 | $date_sort_field, $offset, $owner_uid, | |
43 | false, 0, true, true, false, false, $start_ts);*/ | |
44 | ||
45 | //function queryFeedHeadlines($feed, | |
46 | // $limit, $view_mode, $cat_view, $search, $search_mode, | |
47 | // $override_order = false, $offset = 0, $owner_uid = 0, | |
48 | // $filter = false, $since_id = 0, $include_children = false, $ignore_vfeed_group = false, $override_strategy = false, $override_vfeed = false, $start_ts = false, $check_top_id = false) { | |
49 | ||
50 | $params = array( | |
51 | "owner_uid" => $owner_uid, | |
52 | "feed" => $feed, | |
53 | "limit" => 1, | |
54 | "view_mode" => $view_mode, | |
55 | "cat_view" => $is_cat, | |
56 | "search" => $search, | |
57 | "override_order" => $date_sort_field, | |
58 | "include_children" => true, | |
59 | "ignore_vfeed_group" => true, | |
60 | "offset" => $offset, | |
61 | "start_ts" => $start_ts | |
62 | ); | |
63 | ||
64 | $qfh_ret = queryFeedHeadlines($params); | |
65 | ||
66 | $result = $qfh_ret[0]; | |
67 | ||
68 | if ($this->dbh->num_rows($result) != 0) { | |
69 | ||
70 | $ts = strtotime($this->dbh->fetch_result($result, 0, $date_check_field)); | |
71 | ||
72 | if (isset($_SERVER['HTTP_IF_MODIFIED_SINCE']) && | |
73 | strtotime($_SERVER['HTTP_IF_MODIFIED_SINCE']) >= $ts) { | |
74 | header('HTTP/1.0 304 Not Modified'); | |
75 | return; | |
76 | } | |
77 | ||
78 | $last_modified = gmdate("D, d M Y H:i:s", $ts) . " GMT"; | |
79 | header("Last-Modified: $last_modified", true); | |
80 | } | |
81 | ||
82 | /*$qfh_ret = queryFeedHeadlines($feed, | |
83 | $limit, $view_mode, $is_cat, $search, false, | |
84 | $date_sort_field, $offset, $owner_uid, | |
85 | false, 0, true, true, false, false, $start_ts);*/ | |
86 | ||
87 | $params = array( | |
88 | "owner_uid" => $owner_uid, | |
89 | "feed" => $feed, | |
90 | "limit" => $limit, | |
91 | "view_mode" => $view_mode, | |
92 | "cat_view" => $is_cat, | |
93 | "search" => $search, | |
94 | "override_order" => $date_sort_field, | |
95 | "include_children" => true, | |
96 | "ignore_vfeed_group" => true, | |
97 | "offset" => $offset, | |
98 | "start_ts" => $start_ts | |
99 | ); | |
100 | ||
101 | $qfh_ret = queryFeedHeadlines($params); | |
102 | ||
103 | $result = $qfh_ret[0]; | |
104 | $feed_title = htmlspecialchars($qfh_ret[1]); | |
105 | $feed_site_url = $qfh_ret[2]; | |
106 | /* $last_error = $qfh_ret[3]; */ | |
107 | ||
108 | $feed_self_url = get_self_url_prefix() . | |
109 | "/public.php?op=rss&id=$feed&key=" . | |
110 | get_feed_access_key($feed, false, $owner_uid); | |
111 | ||
112 | if (!$feed_site_url) $feed_site_url = get_self_url_prefix(); | |
113 | ||
114 | if ($format == 'atom') { | |
115 | $tpl = new MiniTemplator; | |
116 | ||
117 | $tpl->readTemplateFromFile("templates/generated_feed.txt"); | |
118 | ||
119 | $tpl->setVariable('FEED_TITLE', $feed_title, true); | |
120 | $tpl->setVariable('VERSION', VERSION, true); | |
121 | $tpl->setVariable('FEED_URL', htmlspecialchars($feed_self_url), true); | |
122 | ||
123 | if (PUBSUBHUBBUB_HUB && $feed == -2) { | |
124 | $tpl->setVariable('HUB_URL', htmlspecialchars(PUBSUBHUBBUB_HUB), true); | |
125 | $tpl->addBlock('feed_hub'); | |
126 | } | |
127 | ||
128 | $tpl->setVariable('SELF_URL', htmlspecialchars(get_self_url_prefix()), true); | |
129 | while ($line = $this->dbh->fetch_assoc($result)) { | |
130 | ||
131 | $line["content_preview"] = truncate_string(strip_tags($line["content"]), 100, '...'); | |
132 | ||
133 | foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_QUERY_HEADLINES) as $p) { | |
134 | $line = $p->hook_query_headlines($line); | |
135 | } | |
136 | ||
137 | foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_ARTICLE_EXPORT_FEED) as $p) { | |
138 | $line = $p->hook_article_export_feed($line, $feed, $is_cat); | |
139 | } | |
140 | ||
141 | $tpl->setVariable('ARTICLE_ID', | |
142 | htmlspecialchars($orig_guid ? $line['link'] : | |
143 | $this->make_article_tag_uri($line['id'], $line['date_entered'])), true); | |
144 | $tpl->setVariable('ARTICLE_LINK', htmlspecialchars($line['link']), true); | |
145 | $tpl->setVariable('ARTICLE_TITLE', htmlspecialchars($line['title']), true); | |
146 | $tpl->setVariable('ARTICLE_EXCERPT', $line["content_preview"], true); | |
147 | ||
148 | $content = sanitize($line["content"], false, $owner_uid, | |
149 | $feed_site_url, false, $line["id"]); | |
150 | ||
151 | if ($line['note']) { | |
152 | $content = "<div style=\"$note_style\">Article note: " . $line['note'] . "</div>" . | |
153 | $content; | |
154 | $tpl->setVariable('ARTICLE_NOTE', htmlspecialchars($line['note']), true); | |
155 | } | |
156 | ||
157 | $tpl->setVariable('ARTICLE_CONTENT', $content, true); | |
158 | ||
159 | $tpl->setVariable('ARTICLE_UPDATED_ATOM', | |
160 | date('c', strtotime($line["updated"])), true); | |
161 | $tpl->setVariable('ARTICLE_UPDATED_RFC822', | |
162 | date(DATE_RFC822, strtotime($line["updated"])), true); | |
163 | ||
164 | $tpl->setVariable('ARTICLE_AUTHOR', htmlspecialchars($line['author']), true); | |
165 | ||
166 | $tpl->setVariable('ARTICLE_SOURCE_LINK', htmlspecialchars($line['site_url'] ? $line["site_url"] : get_self_url_prefix()), true); | |
167 | $tpl->setVariable('ARTICLE_SOURCE_TITLE', htmlspecialchars($line['feed_title'] ? $line['feed_title'] : $feed_title), true); | |
168 | ||
169 | $tags = get_article_tags($line["id"], $owner_uid); | |
170 | ||
171 | foreach ($tags as $tag) { | |
172 | $tpl->setVariable('ARTICLE_CATEGORY', htmlspecialchars($tag), true); | |
173 | $tpl->addBlock('category'); | |
174 | } | |
175 | ||
176 | $enclosures = get_article_enclosures($line["id"]); | |
177 | ||
178 | foreach ($enclosures as $e) { | |
179 | $type = htmlspecialchars($e['content_type']); | |
180 | $url = htmlspecialchars($e['content_url']); | |
181 | $length = $e['duration'] ? $e['duration'] : 1; | |
182 | ||
183 | $tpl->setVariable('ARTICLE_ENCLOSURE_URL', $url, true); | |
184 | $tpl->setVariable('ARTICLE_ENCLOSURE_TYPE', $type, true); | |
185 | $tpl->setVariable('ARTICLE_ENCLOSURE_LENGTH', $length, true); | |
186 | ||
187 | $tpl->addBlock('enclosure'); | |
188 | } | |
189 | ||
190 | $tpl->addBlock('entry'); | |
191 | } | |
192 | ||
193 | $tmp = ""; | |
194 | ||
195 | $tpl->addBlock('feed'); | |
196 | $tpl->generateOutputToString($tmp); | |
197 | ||
198 | if (@!$_REQUEST["noxml"]) { | |
199 | header("Content-Type: text/xml; charset=utf-8"); | |
200 | } else { | |
201 | header("Content-Type: text/plain; charset=utf-8"); | |
202 | } | |
203 | ||
204 | print $tmp; | |
205 | } else if ($format == 'json') { | |
206 | ||
207 | $feed = array(); | |
208 | ||
209 | $feed['title'] = $feed_title; | |
210 | $feed['version'] = VERSION; | |
211 | $feed['feed_url'] = $feed_self_url; | |
212 | ||
213 | if (PUBSUBHUBBUB_HUB && $feed == -2) { | |
214 | $feed['hub_url'] = PUBSUBHUBBUB_HUB; | |
215 | } | |
216 | ||
217 | $feed['self_url'] = get_self_url_prefix(); | |
218 | ||
219 | $feed['articles'] = array(); | |
220 | ||
221 | while ($line = $this->dbh->fetch_assoc($result)) { | |
222 | ||
223 | $line["content_preview"] = truncate_string(strip_tags($line["content_preview"]), 100, '...'); | |
224 | ||
225 | foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_QUERY_HEADLINES) as $p) { | |
226 | $line = $p->hook_query_headlines($line, 100); | |
227 | } | |
228 | ||
229 | foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_ARTICLE_EXPORT_FEED) as $p) { | |
230 | $line = $p->hook_article_export_feed($line, $feed, $is_cat); | |
231 | } | |
232 | ||
233 | $article = array(); | |
234 | ||
235 | $article['id'] = $line['link']; | |
236 | $article['link'] = $line['link']; | |
237 | $article['title'] = $line['title']; | |
238 | $article['excerpt'] = $line["content_preview"]; | |
239 | $article['content'] = sanitize($line["content"], false, $owner_uid, $feed_site_url, false, $line["id"]); | |
240 | $article['updated'] = date('c', strtotime($line["updated"])); | |
241 | ||
242 | if ($line['note']) $article['note'] = $line['note']; | |
243 | if ($article['author']) $article['author'] = $line['author']; | |
244 | ||
245 | $tags = get_article_tags($line["id"], $owner_uid); | |
246 | ||
247 | if (count($tags) > 0) { | |
248 | $article['tags'] = array(); | |
249 | ||
250 | foreach ($tags as $tag) { | |
251 | array_push($article['tags'], $tag); | |
252 | } | |
253 | } | |
254 | ||
255 | $enclosures = get_article_enclosures($line["id"]); | |
256 | ||
257 | if (count($enclosures) > 0) { | |
258 | $article['enclosures'] = array(); | |
259 | ||
260 | foreach ($enclosures as $e) { | |
261 | $type = $e['content_type']; | |
262 | $url = $e['content_url']; | |
263 | $length = $e['duration']; | |
264 | ||
265 | array_push($article['enclosures'], array("url" => $url, "type" => $type, "length" => $length)); | |
266 | } | |
267 | } | |
268 | ||
269 | array_push($feed['articles'], $article); | |
270 | } | |
271 | ||
272 | header("Content-Type: text/json; charset=utf-8"); | |
273 | print json_encode($feed); | |
274 | ||
275 | } else { | |
276 | header("Content-Type: text/plain; charset=utf-8"); | |
277 | print json_encode(array("error" => array("message" => "Unknown format"))); | |
278 | } | |
279 | } | |
280 | ||
281 | function getUnread() { | |
282 | $login = $this->dbh->escape_string($_REQUEST["login"]); | |
283 | $fresh = $_REQUEST["fresh"] == "1"; | |
284 | ||
285 | $result = $this->dbh->query("SELECT id FROM ttrss_users WHERE login = '$login'"); | |
286 | ||
287 | if ($this->dbh->num_rows($result) == 1) { | |
288 | $uid = $this->dbh->fetch_result($result, 0, "id"); | |
289 | ||
290 | print getGlobalUnread($uid); | |
291 | ||
292 | if ($fresh) { | |
293 | print ";"; | |
294 | print getFeedArticles(-3, false, true, $uid); | |
295 | } | |
296 | ||
297 | } else { | |
298 | print "-1;User not found"; | |
299 | } | |
300 | ||
301 | } | |
302 | ||
303 | function getProfiles() { | |
304 | $login = $this->dbh->escape_string($_REQUEST["login"]); | |
305 | ||
306 | $result = $this->dbh->query("SELECT ttrss_settings_profiles.* FROM ttrss_settings_profiles,ttrss_users | |
307 | WHERE ttrss_users.id = ttrss_settings_profiles.owner_uid AND login = '$login' ORDER BY title"); | |
308 | ||
309 | print "<select dojoType='dijit.form.Select' style='width : 220px; margin : 0px' name='profile'>"; | |
310 | ||
311 | print "<option value='0'>" . __("Default profile") . "</option>"; | |
312 | ||
313 | while ($line = $this->dbh->fetch_assoc($result)) { | |
314 | $id = $line["id"]; | |
315 | $title = $line["title"]; | |
316 | ||
317 | print "<option value='$id'>$title</option>"; | |
318 | } | |
319 | ||
320 | print "</select>"; | |
321 | } | |
322 | ||
323 | function pubsub() { | |
324 | $mode = $this->dbh->escape_string($_REQUEST['hub_mode']); | |
325 | if (!$mode) $mode = $this->dbh->escape_string($_REQUEST['hub.mode']); | |
326 | ||
327 | $feed_id = (int) $this->dbh->escape_string($_REQUEST['id']); | |
328 | $feed_url = $this->dbh->escape_string($_REQUEST['hub_topic']); | |
329 | ||
330 | if (!$feed_url) $feed_url = $this->dbh->escape_string($_REQUEST['hub.topic']); | |
331 | ||
332 | if (!PUBSUBHUBBUB_ENABLED) { | |
333 | header('HTTP/1.0 404 Not Found'); | |
334 | echo "404 Not found (Disabled by server)"; | |
335 | return; | |
336 | } | |
337 | ||
338 | // TODO: implement hub_verifytoken checking | |
339 | // TODO: store requested rel=self or whatever for verification | |
340 | // (may be different from stored feed url) e.g. http://url/ or http://url | |
341 | ||
342 | $result = $this->dbh->query("SELECT feed_url FROM ttrss_feeds | |
343 | WHERE id = '$feed_id'"); | |
344 | ||
345 | if ($this->dbh->num_rows($result) != 0) { | |
346 | ||
347 | $check_feed_url = $this->dbh->fetch_result($result, 0, "feed_url"); | |
348 | ||
349 | // ignore url checking for the time being | |
350 | if ($check_feed_url && (true || $check_feed_url == $feed_url || !$feed_url)) { | |
351 | if ($mode == "subscribe") { | |
352 | ||
353 | $this->dbh->query("UPDATE ttrss_feeds SET pubsub_state = 2 | |
354 | WHERE id = '$feed_id'"); | |
355 | ||
356 | print $_REQUEST['hub_challenge']; | |
357 | return; | |
358 | ||
359 | } else if ($mode == "unsubscribe") { | |
360 | ||
361 | $this->dbh->query("UPDATE ttrss_feeds SET pubsub_state = 0 | |
362 | WHERE id = '$feed_id'"); | |
363 | ||
364 | print $_REQUEST['hub_challenge']; | |
365 | return; | |
366 | ||
367 | } else if (!$mode) { | |
368 | ||
369 | // Received update ping, schedule feed update. | |
370 | //update_rss_feed($feed_id, true, true); | |
371 | ||
372 | $this->dbh->query("UPDATE ttrss_feeds SET | |
373 | last_update_started = '1970-01-01', | |
374 | last_updated = '1970-01-01' WHERE id = '$feed_id'"); | |
375 | ||
376 | } | |
377 | } else { | |
378 | header('HTTP/1.0 404 Not Found'); | |
379 | echo "404 Not found (URL check failed)"; | |
380 | } | |
381 | } else { | |
382 | header('HTTP/1.0 404 Not Found'); | |
383 | echo "404 Not found (Feed not found)"; | |
384 | } | |
385 | ||
386 | } | |
387 | ||
388 | function logout() { | |
389 | logout_user(); | |
390 | header("Location: index.php"); | |
391 | } | |
392 | ||
393 | function share() { | |
394 | $uuid = $this->dbh->escape_string($_REQUEST["key"]); | |
395 | ||
396 | $result = $this->dbh->query("SELECT ref_id, owner_uid FROM ttrss_user_entries WHERE | |
397 | uuid = '$uuid'"); | |
398 | ||
399 | if ($this->dbh->num_rows($result) != 0) { | |
400 | header("Content-Type: text/html"); | |
401 | ||
402 | $id = $this->dbh->fetch_result($result, 0, "ref_id"); | |
403 | $owner_uid = $this->dbh->fetch_result($result, 0, "owner_uid"); | |
404 | ||
405 | $article = format_article($id, false, true, $owner_uid); | |
406 | ||
407 | print_r($article['content']); | |
408 | ||
409 | } else { | |
410 | print "Article not found."; | |
411 | } | |
412 | ||
413 | } | |
414 | ||
415 | function rss() { | |
416 | $feed = $this->dbh->escape_string($_REQUEST["id"]); | |
417 | $key = $this->dbh->escape_string($_REQUEST["key"]); | |
418 | $is_cat = sql_bool_to_bool($_REQUEST["is_cat"]); | |
419 | $limit = (int)$this->dbh->escape_string($_REQUEST["limit"]); | |
420 | $offset = (int)$this->dbh->escape_string($_REQUEST["offset"]); | |
421 | ||
422 | $search = $this->dbh->escape_string($_REQUEST["q"]); | |
423 | $view_mode = $this->dbh->escape_string($_REQUEST["view-mode"]); | |
424 | $order = $this->dbh->escape_string($_REQUEST["order"]); | |
425 | $start_ts = $this->dbh->escape_string($_REQUEST["ts"]); | |
426 | ||
427 | $format = $this->dbh->escape_string($_REQUEST['format']); | |
428 | $orig_guid = sql_bool_to_bool($_REQUEST["orig_guid"]); | |
429 | ||
430 | if (!$format) $format = 'atom'; | |
431 | ||
432 | if (SINGLE_USER_MODE) { | |
433 | authenticate_user("admin", null); | |
434 | } | |
435 | ||
436 | $owner_id = false; | |
437 | ||
438 | if ($key) { | |
439 | $result = $this->dbh->query("SELECT owner_uid FROM | |
440 | ttrss_access_keys WHERE access_key = '$key' AND feed_id = '$feed'"); | |
441 | ||
442 | if ($this->dbh->num_rows($result) == 1) | |
443 | $owner_id = $this->dbh->fetch_result($result, 0, "owner_uid"); | |
444 | } | |
445 | ||
446 | if ($owner_id) { | |
447 | $this->generate_syndicated_feed($owner_id, $feed, $is_cat, $limit, | |
448 | $offset, $search, $view_mode, $format, $order, $orig_guid, $start_ts); | |
449 | } else { | |
450 | header('HTTP/1.1 403 Forbidden'); | |
451 | } | |
452 | } | |
453 | ||
454 | function updateTask() { | |
455 | PluginHost::getInstance()->run_hooks(PluginHost::HOOK_UPDATE_TASK, "hook_update_task", false); | |
456 | } | |
457 | ||
458 | function housekeepingTask() { | |
459 | PluginHost::getInstance()->run_hooks(PluginHost::HOOK_HOUSE_KEEPING, "hook_house_keeping", false); | |
460 | } | |
461 | ||
462 | function globalUpdateFeeds() { | |
463 | RPC::updaterandomfeed_real($this->dbh); | |
464 | ||
465 | PluginHost::getInstance()->run_hooks(PluginHost::HOOK_UPDATE_TASK, "hook_update_task", false); | |
466 | } | |
467 | ||
468 | function sharepopup() { | |
469 | if (SINGLE_USER_MODE) { | |
470 | login_sequence(); | |
471 | } | |
472 | ||
473 | header('Content-Type: text/html; charset=utf-8'); | |
474 | print "<html><head><title>Tiny Tiny RSS</title> | |
475 | <link rel=\"shortcut icon\" type=\"image/png\" href=\"images/favicon.png\"> | |
476 | <link rel=\"icon\" type=\"image/png\" sizes=\"72x72\" href=\"images/favicon-72px.png\">"; | |
477 | ||
478 | echo stylesheet_tag("css/utility.css"); | |
479 | echo stylesheet_tag("css/dijit.css"); | |
480 | echo javascript_tag("lib/prototype.js"); | |
481 | echo javascript_tag("lib/scriptaculous/scriptaculous.js?load=effects,controls"); | |
482 | print "<meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\"/> | |
483 | </head><body id='sharepopup'>"; | |
484 | ||
485 | $action = $_REQUEST["action"]; | |
486 | ||
487 | if ($_SESSION["uid"]) { | |
488 | ||
489 | if ($action == 'share') { | |
490 | ||
491 | $title = $this->dbh->escape_string(strip_tags($_REQUEST["title"])); | |
492 | $url = $this->dbh->escape_string(strip_tags($_REQUEST["url"])); | |
493 | $content = $this->dbh->escape_string(strip_tags($_REQUEST["content"])); | |
494 | $labels = $this->dbh->escape_string(strip_tags($_REQUEST["labels"])); | |
495 | ||
496 | Article::create_published_article($title, $url, $content, $labels, | |
497 | $_SESSION["uid"]); | |
498 | ||
499 | print "<script type='text/javascript'>"; | |
500 | print "window.close();"; | |
501 | print "</script>"; | |
502 | ||
503 | } else { | |
504 | $title = htmlspecialchars($_REQUEST["title"]); | |
505 | $url = htmlspecialchars($_REQUEST["url"]); | |
506 | ||
507 | ?> | |
508 | ||
509 | <table height='100%' width='100%'><tr><td colspan='2'> | |
510 | <h1><?php echo __("Share with Tiny Tiny RSS") ?></h1> | |
511 | </td></tr> | |
512 | ||
513 | <form id='share_form' name='share_form'> | |
514 | ||
515 | <input type="hidden" name="op" value="sharepopup"> | |
516 | <input type="hidden" name="action" value="share"> | |
517 | ||
518 | <tr><td align='right'><?php echo __("Title:") ?></td> | |
519 | <td width='80%'><input name='title' value="<?php echo $title ?>"></td></tr> | |
520 | <tr><td align='right'><?php echo __("URL:") ?></td> | |
521 | <td><input name='url' value="<?php echo $url ?>"></td></tr> | |
522 | <tr><td align='right'><?php echo __("Content:") ?></td> | |
523 | <td><input name='content' value=""></td></tr> | |
524 | <tr><td align='right'><?php echo __("Labels:") ?></td> | |
525 | <td><input name='labels' id="labels_value" | |
526 | placeholder='Alpha, Beta, Gamma' value=""> | |
527 | </td></tr> | |
528 | ||
529 | <tr><td> | |
530 | <div class="autocomplete" id="labels_choices" | |
531 | style="display : block"></div></td></tr> | |
532 | ||
533 | <script type='text/javascript'>document.forms[0].title.focus();</script> | |
534 | ||
535 | <script type='text/javascript'> | |
536 | new Ajax.Autocompleter('labels_value', 'labels_choices', | |
537 | "backend.php?op=rpc&method=completeLabels", | |
538 | { tokens: ',', paramName: "search" }); | |
539 | </script> | |
540 | ||
541 | <tr><td colspan='2'> | |
542 | <div style='float : right' class='insensitive-small'> | |
543 | <?php echo __("Shared article will appear in the Published feed.") ?> | |
544 | </div> | |
545 | <button type="submit"><?php echo __('Share') ?></button> | |
546 | <button onclick="return window.close()"><?php echo __('Cancel') ?></button> | |
547 | </td> | |
548 | ||
549 | </form> | |
550 | </td></tr></table> | |
551 | </body></html> | |
552 | <?php | |
553 | ||
554 | } | |
555 | ||
556 | } else { | |
557 | ||
558 | $return = urlencode($_SERVER["REQUEST_URI"]) | |
559 | ?> | |
560 | ||
561 | <form action="public.php?return=<?php echo $return ?>" | |
562 | method="POST" id="loginForm" name="loginForm"> | |
563 | ||
564 | <input type="hidden" name="op" value="login"> | |
565 | ||
566 | <table height='100%' width='100%'><tr><td colspan='2'> | |
567 | <h1><?php echo __("Not logged in") ?></h1></td></tr> | |
568 | ||
569 | <tr><td align="right"><?php echo __("Login:") ?></td> | |
570 | <td align="right"><input name="login" | |
571 | value="<?php echo $_SESSION["fake_login"] ?>"></td></tr> | |
572 | <tr><td align="right"><?php echo __("Password:") ?></td> | |
573 | <td align="right"><input type="password" name="password" | |
574 | value="<?php echo $_SESSION["fake_password"] ?>"></td></tr> | |
575 | <tr><td colspan='2'> | |
576 | <button type="submit"> | |
577 | <?php echo __('Log in') ?></button> | |
578 | ||
579 | <button onclick="return window.close()"> | |
580 | <?php echo __('Cancel') ?></button> | |
581 | </td></tr> | |
582 | </table> | |
583 | ||
584 | </form> | |
585 | <?php | |
586 | } | |
587 | } | |
588 | ||
589 | function login() { | |
590 | if (!SINGLE_USER_MODE) { | |
591 | ||
592 | $login = $this->dbh->escape_string($_POST["login"]); | |
593 | $password = $_POST["password"]; | |
594 | $remember_me = $_POST["remember_me"]; | |
595 | ||
596 | if ($remember_me) { | |
597 | session_set_cookie_params(SESSION_COOKIE_LIFETIME); | |
598 | } else { | |
599 | session_set_cookie_params(0); | |
600 | } | |
601 | ||
602 | @session_start(); | |
603 | ||
604 | if (authenticate_user($login, $password)) { | |
605 | $_POST["password"] = ""; | |
606 | ||
607 | if (get_schema_version() >= 120) { | |
608 | $_SESSION["language"] = get_pref("USER_LANGUAGE", $_SESSION["uid"]); | |
609 | } | |
610 | ||
611 | $_SESSION["ref_schema_version"] = get_schema_version(true); | |
612 | $_SESSION["bw_limit"] = !!$_POST["bw_limit"]; | |
613 | ||
614 | if ($_POST["profile"]) { | |
615 | ||
616 | $profile = $this->dbh->escape_string($_POST["profile"]); | |
617 | ||
618 | $result = $this->dbh->query("SELECT id FROM ttrss_settings_profiles | |
619 | WHERE id = '$profile' AND owner_uid = " . $_SESSION["uid"]); | |
620 | ||
621 | if ($this->dbh->num_rows($result) != 0) { | |
622 | $_SESSION["profile"] = $profile; | |
623 | } | |
624 | } | |
625 | } else { | |
626 | $_SESSION["login_error_msg"] = __("Incorrect username or password"); | |
627 | user_error("Failed login attempt for $login from {$_SERVER['REMOTE_ADDR']}", E_USER_WARNING); | |
628 | } | |
629 | ||
630 | if ($_REQUEST['return']) { | |
631 | header("Location: " . $_REQUEST['return']); | |
632 | } else { | |
633 | header("Location: " . SELF_URL_PATH); | |
634 | } | |
635 | } | |
636 | } | |
637 | ||
638 | /* function subtest() { | |
639 | header("Content-type: text/plain; charset=utf-8"); | |
640 | ||
641 | $url = $_REQUEST["url"]; | |
642 | ||
643 | print "$url\n\n"; | |
644 | ||
645 | ||
646 | print_r(get_feeds_from_html($url, fetch_file_contents($url))); | |
647 | ||
648 | } */ | |
649 | ||
650 | function subscribe() { | |
651 | if (SINGLE_USER_MODE) { | |
652 | login_sequence(); | |
653 | } | |
654 | ||
655 | if ($_SESSION["uid"]) { | |
656 | ||
657 | $feed_url = $this->dbh->escape_string(trim($_REQUEST["feed_url"])); | |
658 | ||
659 | header('Content-Type: text/html; charset=utf-8'); | |
660 | print "<html> | |
661 | <head> | |
662 | <title>Tiny Tiny RSS</title> | |
663 | <link rel=\"stylesheet\" type=\"text/css\" href=\"css/utility.css\"> | |
664 | <meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\"/> | |
665 | <link rel=\"shortcut icon\" type=\"image/png\" href=\"images/favicon.png\"> | |
666 | <link rel=\"icon\" type=\"image/png\" sizes=\"72x72\" href=\"images/favicon-72px.png\"> | |
667 | ||
668 | </head> | |
669 | <body> | |
670 | <img class=\"floatingLogo\" src=\"images/logo_small.png\" | |
671 | alt=\"Tiny Tiny RSS\"/> | |
672 | <h1>".__("Subscribe to feed...")."</h1><div class='content'>"; | |
673 | ||
674 | $rc = subscribe_to_feed($feed_url); | |
675 | ||
676 | switch ($rc['code']) { | |
677 | case 0: | |
678 | print_warning(T_sprintf("Already subscribed to <b>%s</b>.", $feed_url)); | |
679 | break; | |
680 | case 1: | |
681 | print_notice(T_sprintf("Subscribed to <b>%s</b>.", $feed_url)); | |
682 | break; | |
683 | case 2: | |
684 | print_error(T_sprintf("Could not subscribe to <b>%s</b>.", $feed_url)); | |
685 | break; | |
686 | case 3: | |
687 | print_error(T_sprintf("No feeds found in <b>%s</b>.", $feed_url)); | |
688 | break; | |
689 | case 4: | |
690 | print_notice(__("Multiple feed URLs found.")); | |
691 | $feed_urls = $rc["feeds"]; | |
692 | break; | |
693 | case 5: | |
694 | print_error(T_sprintf("Could not subscribe to <b>%s</b>.<br>Can't download the Feed URL.", $feed_url)); | |
695 | break; | |
696 | } | |
697 | ||
698 | if ($feed_urls) { | |
699 | ||
700 | print "<form action=\"public.php\">"; | |
701 | print "<input type=\"hidden\" name=\"op\" value=\"subscribe\">"; | |
702 | ||
703 | print "<select name=\"feed_url\">"; | |
704 | ||
705 | foreach ($feed_urls as $url => $name) { | |
706 | $url = htmlspecialchars($url); | |
707 | $name = htmlspecialchars($name); | |
708 | ||
709 | print "<option value=\"$url\">$name</option>"; | |
710 | } | |
711 | ||
712 | print "<input type=\"submit\" value=\"".__("Subscribe to selected feed"). | |
713 | "\">"; | |
714 | ||
715 | print "</form>"; | |
716 | } | |
717 | ||
718 | $tp_uri = get_self_url_prefix() . "/prefs.php"; | |
719 | $tt_uri = get_self_url_prefix(); | |
720 | ||
721 | if ($rc['code'] <= 2){ | |
722 | $result = $this->dbh->query("SELECT id FROM ttrss_feeds WHERE | |
723 | feed_url = '$feed_url' AND owner_uid = " . $_SESSION["uid"]); | |
724 | ||
725 | $feed_id = $this->dbh->fetch_result($result, 0, "id"); | |
726 | } else { | |
727 | $feed_id = 0; | |
728 | } | |
729 | print "<p>"; | |
730 | ||
731 | if ($feed_id) { | |
732 | print "<form method=\"GET\" style='display: inline' | |
733 | action=\"$tp_uri\"> | |
734 | <input type=\"hidden\" name=\"tab\" value=\"feedConfig\"> | |
735 | <input type=\"hidden\" name=\"method\" value=\"editFeed\"> | |
736 | <input type=\"hidden\" name=\"methodparam\" value=\"$feed_id\"> | |
737 | <input type=\"submit\" value=\"".__("Edit subscription options")."\"> | |
738 | </form>"; | |
739 | } | |
740 | ||
741 | print "<form style='display: inline' method=\"GET\" action=\"$tt_uri\"> | |
742 | <input type=\"submit\" value=\"".__("Return to Tiny Tiny RSS")."\"> | |
743 | </form></p>"; | |
744 | ||
745 | print "</div></body></html>"; | |
746 | ||
747 | } else { | |
748 | render_login_form(); | |
749 | } | |
750 | } | |
751 | ||
752 | function index() { | |
753 | header("Content-Type: text/plain"); | |
754 | print error_json(13); | |
755 | } | |
756 | ||
757 | function forgotpass() { | |
758 | startup_gettext(); | |
759 | ||
760 | @$hash = $_REQUEST["hash"]; | |
761 | ||
762 | header('Content-Type: text/html; charset=utf-8'); | |
763 | print "<html><head><title>Tiny Tiny RSS</title> | |
764 | <link rel=\"shortcut icon\" type=\"image/png\" href=\"images/favicon.png\"> | |
765 | <link rel=\"icon\" type=\"image/png\" sizes=\"72x72\" href=\"images/favicon-72px.png\">"; | |
766 | ||
767 | echo stylesheet_tag("css/utility.css"); | |
768 | echo javascript_tag("lib/prototype.js"); | |
769 | ||
770 | print "<meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\"/> | |
771 | </head><body id='forgotpass'>"; | |
772 | ||
773 | print '<div class="floatingLogo"><img src="images/logo_small.png"></div>'; | |
774 | print "<h1>".__("Password recovery")."</h1>"; | |
775 | print "<div class='content'>"; | |
776 | ||
777 | @$method = $_POST['method']; | |
778 | ||
779 | if ($hash) { | |
780 | $login = $_REQUEST["login"]; | |
781 | ||
782 | if ($login) { | |
783 | $result = $this->dbh->query("SELECT id, resetpass_token FROM ttrss_users | |
784 | WHERE login = '$login'"); | |
785 | ||
786 | if ($this->dbh->num_rows($result) != 0) { | |
787 | $id = $this->dbh->fetch_result($result, 0, "id"); | |
788 | $resetpass_token_full = $this->dbh->fetch_result($result, 0, "resetpass_token"); | |
789 | list($timestamp, $resetpass_token) = explode(":", $resetpass_token_full); | |
790 | ||
791 | if ($timestamp && $resetpass_token && | |
792 | $timestamp >= time() - 15*60*60 && | |
793 | $resetpass_token == $hash) { | |
794 | ||
795 | $result = $this->dbh->query("UPDATE ttrss_users SET resetpass_token = NULL | |
796 | WHERE id = $id"); | |
797 | ||
798 | Pref_Users::resetUserPassword($id, true); | |
799 | ||
800 | print "<p>"."Completed."."</p>"; | |
801 | ||
802 | } else { | |
803 | print_error("Some of the information provided is missing or incorrect."); | |
804 | } | |
805 | } else { | |
806 | print_error("Some of the information provided is missing or incorrect."); | |
807 | } | |
808 | } else { | |
809 | print_error("Some of the information provided is missing or incorrect."); | |
810 | } | |
811 | ||
812 | print "<form method=\"GET\" action=\"index.php\"> | |
813 | <input type=\"submit\" value=\"".__("Return to Tiny Tiny RSS")."\"> | |
814 | </form>"; | |
815 | ||
816 | } else if (!$method) { | |
817 | print_notice(__("You will need to provide valid account name and email. A password reset link will be sent to your email address.")); | |
818 | ||
819 | print "<form method='POST' action='public.php'>"; | |
820 | print "<input type='hidden' name='method' value='do'>"; | |
821 | print "<input type='hidden' name='op' value='forgotpass'>"; | |
822 | ||
823 | print "<fieldset>"; | |
824 | print "<label>".__("Login:")."</label>"; | |
825 | print "<input type='text' name='login' value='' required>"; | |
826 | print "</fieldset>"; | |
827 | ||
828 | print "<fieldset>"; | |
829 | print "<label>".__("Email:")."</label>"; | |
830 | print "<input type='email' name='email' value='' required>"; | |
831 | print "</fieldset>"; | |
832 | ||
833 | print "<fieldset>"; | |
834 | print "<label>".__("How much is two plus two:")."</label>"; | |
835 | print "<input type='text' name='test' value='' required>"; | |
836 | print "</fieldset>"; | |
837 | ||
838 | print "<p/>"; | |
839 | print "<button type='submit'>".__("Reset password")."</button>"; | |
840 | ||
841 | print "</form>"; | |
842 | } else if ($method == 'do') { | |
843 | ||
844 | $login = $this->dbh->escape_string($_POST["login"]); | |
845 | $email = $this->dbh->escape_string($_POST["email"]); | |
846 | $test = $this->dbh->escape_string($_POST["test"]); | |
847 | ||
848 | if (($test != 4 && $test != 'four') || !$email || !$login) { | |
849 | print_error(__('Some of the required form parameters are missing or incorrect.')); | |
850 | ||
851 | print "<form method=\"GET\" action=\"public.php\"> | |
852 | <input type=\"hidden\" name=\"op\" value=\"forgotpass\"> | |
853 | <input type=\"submit\" value=\"".__("Go back")."\"> | |
854 | </form>"; | |
855 | ||
856 | } else { | |
857 | ||
858 | print_notice("Password reset instructions are being sent to your email address."); | |
859 | ||
860 | $result = $this->dbh->query("SELECT id FROM ttrss_users | |
861 | WHERE login = '$login' AND email = '$email'"); | |
862 | ||
863 | if ($this->dbh->num_rows($result) != 0) { | |
864 | $id = $this->dbh->fetch_result($result, 0, "id"); | |
865 | ||
866 | if ($id) { | |
867 | $resetpass_token = sha1(get_random_bytes(128)); | |
868 | $resetpass_link = get_self_url_prefix() . "/public.php?op=forgotpass&hash=" . $resetpass_token . | |
869 | "&login=" . urlencode($login); | |
870 | ||
871 | require_once 'classes/ttrssmailer.php'; | |
872 | require_once "lib/MiniTemplator.class.php"; | |
873 | ||
874 | $tpl = new MiniTemplator; | |
875 | ||
876 | $tpl->readTemplateFromFile("templates/resetpass_link_template.txt"); | |
877 | ||
878 | $tpl->setVariable('LOGIN', $login); | |
879 | $tpl->setVariable('RESETPASS_LINK', $resetpass_link); | |
880 | ||
881 | $tpl->addBlock('message'); | |
882 | ||
883 | $message = ""; | |
884 | ||
885 | $tpl->generateOutputToString($message); | |
886 | ||
887 | $mail = new ttrssMailer(); | |
888 | ||
889 | $rc = $mail->quickMail($email, $login, | |
890 | __("[tt-rss] Password reset request"), | |
891 | $message, false); | |
892 | ||
893 | if (!$rc) print_error($mail->ErrorInfo); | |
894 | ||
895 | $resetpass_token_full = $this->dbh->escape_string(time() . ":" . $resetpass_token); | |
896 | ||
897 | $result = $this->dbh->query("UPDATE ttrss_users | |
898 | SET resetpass_token = '$resetpass_token_full' | |
899 | WHERE login = '$login' AND email = '$email'"); | |
900 | ||
901 | //Pref_Users::resetUserPassword($id, false); | |
902 | ||
903 | print "<p>"; | |
904 | ||
905 | print "<p>"."Completed."."</p>"; | |
906 | } else { | |
907 | print_error("User ID not found."); | |
908 | } | |
909 | ||
910 | print "<form method=\"GET\" action=\"index.php\"> | |
911 | <input type=\"submit\" value=\"".__("Return to Tiny Tiny RSS")."\"> | |
912 | </form>"; | |
913 | ||
914 | } else { | |
915 | print_error(__("Sorry, login and email combination not found.")); | |
916 | ||
917 | print "<form method=\"GET\" action=\"public.php\"> | |
918 | <input type=\"hidden\" name=\"op\" value=\"forgotpass\"> | |
919 | <input type=\"submit\" value=\"".__("Go back")."\"> | |
920 | </form>"; | |
921 | ||
922 | } | |
923 | } | |
924 | ||
925 | } | |
926 | ||
927 | print "</div>"; | |
928 | print "</body>"; | |
929 | print "</html>"; | |
930 | ||
931 | } | |
932 | ||
933 | function dbupdate() { | |
934 | startup_gettext(); | |
935 | ||
936 | if (!SINGLE_USER_MODE && $_SESSION["access_level"] < 10) { | |
937 | $_SESSION["login_error_msg"] = __("Your access level is insufficient to run this script."); | |
938 | render_login_form(); | |
939 | exit; | |
940 | } | |
941 | ||
942 | ?><html> | |
943 | <head> | |
944 | <title>Database Updater</title> | |
945 | <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/> | |
946 | <link rel="stylesheet" type="text/css" href="css/utility.css"/> | |
947 | <link rel=\"shortcut icon\" type=\"image/png\" href=\"images/favicon.png\"> | |
948 | <link rel=\"icon\" type=\"image/png\" sizes=\"72x72\" href=\"images/favicon-72px.png\"> | |
949 | </head> | |
950 | <style type="text/css"> | |
951 | span.ok { color : #009000; font-weight : bold; } | |
952 | span.err { color : #ff0000; font-weight : bold; } | |
953 | </style> | |
954 | <body> | |
955 | <script type='text/javascript'> | |
956 | function confirmOP() { | |
957 | return confirm("Update the database?"); | |
958 | } | |
959 | </script> | |
960 | ||
961 | <div class="floatingLogo"><img src="images/logo_small.png"></div> | |
962 | ||
963 | <h1><?php echo __("Database Updater") ?></h1> | |
964 | ||
965 | <div class="content"> | |
966 | ||
967 | <?php | |
968 | @$op = $_REQUEST["subop"]; | |
969 | $updater = new DbUpdater(Db::get(), DB_TYPE, SCHEMA_VERSION); | |
970 | ||
971 | if ($op == "performupdate") { | |
972 | if ($updater->isUpdateRequired()) { | |
973 | ||
974 | print "<h2>Performing updates</h2>"; | |
975 | ||
976 | print "<h3>Updating to schema version " . SCHEMA_VERSION . "</h3>"; | |
977 | ||
978 | print "<ul>"; | |
979 | ||
980 | for ($i = $updater->getSchemaVersion() + 1; $i <= SCHEMA_VERSION; $i++) { | |
981 | print "<li>Performing update up to version $i..."; | |
982 | ||
983 | $result = $updater->performUpdateTo($i); | |
984 | ||
985 | if (!$result) { | |
986 | print "<span class='err'>FAILED!</span></li></ul>"; | |
987 | ||
988 | print_warning("One of the updates failed. Either retry the process or perform updates manually."); | |
989 | print "<p><form method=\"GET\" action=\"index.php\"> | |
990 | <input type=\"submit\" value=\"".__("Return to Tiny Tiny RSS")."\"> | |
991 | </form>"; | |
992 | ||
993 | break; | |
994 | } else { | |
995 | print "<span class='ok'>OK!</span></li>"; | |
996 | } | |
997 | } | |
998 | ||
999 | print "</ul>"; | |
1000 | ||
1001 | print_notice("Your Tiny Tiny RSS database is now updated to the latest version."); | |
1002 | ||
1003 | print "<p><form method=\"GET\" action=\"index.php\"> | |
1004 | <input type=\"submit\" value=\"".__("Return to Tiny Tiny RSS")."\"> | |
1005 | </form>"; | |
1006 | ||
1007 | } else { | |
1008 | print "<h2>Your database is up to date.</h2>"; | |
1009 | ||
1010 | print "<p><form method=\"GET\" action=\"index.php\"> | |
1011 | <input type=\"submit\" value=\"".__("Return to Tiny Tiny RSS")."\"> | |
1012 | </form>"; | |
1013 | } | |
1014 | } else { | |
1015 | if ($updater->isUpdateRequired()) { | |
1016 | ||
1017 | print "<h2>Database update required</h2>"; | |
1018 | ||
1019 | print_notice("<h4>". | |
1020 | sprintf("Your Tiny Tiny RSS database needs update to the latest version: %d to %d.", | |
1021 | $updater->getSchemaVersion(), SCHEMA_VERSION). | |
1022 | "</h4>"); | |
1023 | ||
1024 | print_warning("Please backup your database before proceeding."); | |
1025 | ||
1026 | print "<form method='POST'> | |
1027 | <input type='hidden' name='subop' value='performupdate'> | |
1028 | <input type='submit' onclick='return confirmOP()' value='".__("Perform updates")."'> | |
1029 | </form>"; | |
1030 | ||
1031 | } else { | |
1032 | ||
1033 | print_notice("Tiny Tiny RSS database is up to date."); | |
1034 | ||
1035 | print "<p><form method=\"GET\" action=\"index.php\"> | |
1036 | <input type=\"submit\" value=\"".__("Return to Tiny Tiny RSS")."\"> | |
1037 | </form>"; | |
1038 | ||
1039 | } | |
1040 | } | |
1041 | ?> | |
1042 | ||
1043 | </div> | |
1044 | </body> | |
1045 | </html> | |
1046 | <?php | |
1047 | } | |
1048 | ||
1049 | function cached_image() { | |
1050 | @$hash = basename($_GET['hash']); | |
1051 | ||
1052 | if ($hash) { | |
1053 | ||
1054 | $filename = CACHE_DIR . '/images/' . $hash . '.png'; | |
1055 | ||
1056 | if (file_exists($filename)) { | |
1057 | /* See if we can use X-Sendfile */ | |
1058 | $xsendfile = false; | |
1059 | if (function_exists('apache_get_modules') && | |
1060 | array_search('mod_xsendfile', apache_get_modules())) | |
1061 | $xsendfile = true; | |
1062 | ||
1063 | if ($xsendfile) { | |
1064 | header("X-Sendfile: $filename"); | |
1065 | header("Content-type: application/octet-stream"); | |
1066 | header('Content-Disposition: attachment; filename="' . basename($filename) . '"'); | |
1067 | } else { | |
1068 | header("Content-type: image/png"); | |
1069 | $stamp = gmdate("D, d M Y H:i:s", filemtime($filename)). " GMT"; | |
1070 | header("Last-Modified: $stamp", true); | |
1071 | readfile($filename); | |
1072 | } | |
1073 | } else { | |
1074 | header($_SERVER["SERVER_PROTOCOL"]." 404 Not Found"); | |
1075 | echo "File not found."; | |
1076 | } | |
1077 | } | |
1078 | } | |
1079 | ||
1080 | private function make_article_tag_uri($id, $timestamp) { | |
1081 | ||
1082 | $timestamp = date("Y-m-d", strtotime($timestamp)); | |
1083 | ||
1084 | return "tag:" . parse_url(get_self_url_prefix(), PHP_URL_HOST) . ",$timestamp:/$id"; | |
1085 | } | |
1086 | } | |
1087 | ?> |