]> git.wh0rd.org - tt-rss.git/blobdiff - api/index.php
api: fix wrong sql syntax in getFeeds
[tt-rss.git] / api / index.php
index 90ca5405c582cf6dbb0f0abb798433585cad610b..8e6400a008b0f3cc5ae020fb7e84c081be1c761a 100644 (file)
@@ -1,10 +1,4 @@
 <?php
-
-       /* This is experimental JSON-based API. It has to be manually enabled:
-        * 
-        * Add define('_JSON_API_ENABLED', true) to config.php
-        */
-
        error_reporting(E_ERROR | E_PARSE);
 
        require_once "../config.php";
        require_once "../db-prefs.php";
        require_once "../functions.php";
 
-       if (!defined('_JSON_API_ENABLED')) {
-               print json_encode(array("error" => "API_DISABLED"));
-               return;
-       }
-
        $link = db_connect(DB_HOST, DB_USER, DB_PASS, DB_NAME); 
 
        $session_expire = SESSION_EXPIRE_TIME; //seconds
        $session_name = (!defined('TTRSS_SESSION_NAME')) ? "ttrss_sid_api" : TTRSS_SESSION_NAME . "_api";
 
+       session_name($session_name);
+
+       if ($_REQUEST["sid"]) {
+               session_id($_REQUEST["sid"]);
+       }
+
        session_start();
 
        if (!$link) {
                        $login = db_escape_string($_REQUEST["user"]);
                        $password = db_escape_string($_REQUEST["password"]);
 
-                       if (authenticate_user($link, $login, $password)) {
-                               print json_encode(array("uid" => $_SESSION["uid"]));
+                       $result = db_query($link, "SELECT id FROM ttrss_users WHERE login = '$login'");
+
+                       if (db_num_rows($result) != 0) {
+                               $uid = db_fetch_result($result, 0, "id");
+                       } else {
+                               $uid = 0;
+                       }
+
+                       if (get_pref($link, "ENABLE_API_ACCESS", $uid)) {
+                               if (authenticate_user($link, $login, $password)) {
+                                       print json_encode(array("session_id" => session_id()));
+                               } else {
+                                       print json_encode(array("error" => "LOGIN_ERROR"));
+                               }
                        } else {
-                               print json_encode(array("error" => "LOGIN_ERROR"));
+                               print json_encode(array("error" => "API_DISABLED"));
                        }
 
                        break;
                case "logout":
                        logout_user();
-                       print json_encode(array("uid" => 0));
+                       print json_encode(array("status" => "OK"));
                        break;
                case "isLoggedIn":
                        print json_encode(array("status" => $_SESSION["uid"] != ''));
                        } else {
                                print json_encode(array("unread" => getGlobalUnread($link)));
                        }
+                       break;
+               case "getCounters":
+
+                       /* TODO */
+
                        break;
                case "getFeeds":
                        $cat_id = db_escape_string($_REQUEST["cat_id"]);
                        $unread_only = (bool)db_escape_string($_REQUEST["unread_only"]);
+                       $limit = (int) db_escape_string($_REQUEST["limit"]);
+                       $offset = (int) db_escape_string($_REQUEST["offset"]);
+
+                       if ($limit) {
+                               $limit_qpart = "LIMIT $limit OFFSET $offset";
+                       } else {
+                               $limit_qpart = "";
+                       }
 
                        if (!$cat_id) {
                                $result = db_query($link, "SELECT 
                                        id, feed_url, cat_id, title, ".
                                                SUBSTRING_FOR_DATE."(last_updated,1,19) AS last_updated
-                                               FROM ttrss_feeds WHERE owner_uid = " . $_SESSION["uid"]);
+                                               FROM ttrss_feeds WHERE owner_uid = " . $_SESSION["uid"] . 
+                                               " ORDER BY cat_id, title " . $limit_qpart);
                        } else {
                                $result = db_query($link, "SELECT 
                                        id, feed_url, cat_id, title, ".
                                                SUBSTRING_FOR_DATE."(last_updated,1,19) AS last_updated
                                                FROM ttrss_feeds WHERE 
-                                                       cat_id = '$cat_id' AND owner_uid = " . $_SESSION["uid"]);
+                                               cat_id = '$cat_id' AND owner_uid = " . $_SESSION["uid"] . 
+                                               " ORDER BY cat_id, title " . $limit_qpart);
                        }
 
                        $feeds = array();
 
                                $unread = getFeedUnread($link, $line["id"]);
 
+                               $icon_path = "../" . ICONS_DIR . "/" . $line["id"] . ".ico";
+                               $has_icon = file_exists($icon_path) && filesize($icon_path) > 0;
+
                                if ($unread || !$unread_only) {
 
                                        $row = array(
                                                        "title" => $line["title"],
                                                        "id" => (int)$line["id"],
                                                        "unread" => (int)$unread,
+                                                       "has_icon" => $has_icon,
                                                        "cat_id" => (int)$line["cat_id"],
                                                        "last_updated" => strtotime($line["last_updated"])
                                                );
                        /* Labels */
 
                        if (!$cat_id || $cat_id == -2) {
-                               $counters = getLabelCounters($link, false, true);
+                               $counters = getLabelCounters($link, true);
 
                                foreach (array_keys($counters) as $id) {
 
                        /* Virtual feeds */
 
                        if (!$cat_id || $cat_id == -1) {
-                               foreach (array(-1, -2, -3, -4) as $i) {
+                               foreach (array(-1, -2, -3, -4, 0) as $i) {
                                        $unread = getFeedUnread($link, $i);
 
                                        if ($unread || !$unread_only) {
                case "getHeadlines":
                        $feed_id = db_escape_string($_REQUEST["feed_id"]);
                        $limit = (int)db_escape_string($_REQUEST["limit"]);
+                       $offset = (int)db_escape_string($_REQUEST["skip"]);
                        $filter = db_escape_string($_REQUEST["filter"]);
                        $is_cat = (bool)db_escape_string($_REQUEST["is_cat"]);
-                       $show_except = (bool)db_escape_string($_REQUEST["show_excerpt"]);
+                       $show_excerpt = (bool)db_escape_string($_REQUEST["show_excerpt"]);
+                       $show_content = (bool)db_escape_string($_REQUEST["show_content"]);
+                       /* all_articles, unread, adaptive, marked, updated */
+                       $view_mode = db_escape_string($_REQUEST["view_mode"]);
 
                        /* do not rely on params below */
 
                        $match_on = db_escape_string($_REQUEST["match_on"]);
                        
                        $qfh_ret = queryFeedHeadlines($link, $feed_id, $limit, 
-                               $view_mode, $is_cat, $search, $search_mode, $match_on);
+                               $view_mode, $is_cat, $search, $search_mode, $match_on,
+                               false, $offset);
 
                        $result = $qfh_ret[0];
                        $feed_title = $qfh_ret[1];
                                                "updated" => strtotime($line["updated"]),
                                                "is_updated" => $is_updated,
                                                "title" => $line["title"],
+                                               "link" => $line["link"],
                                                "feed_id" => $line["feed_id"],
                                        );
 
-                               if ($show_except) $headline_row["excerpt"] = $line["content_preview"];
-                       
+                               if ($show_excerpt) {
+                                       $excerpt = truncate_string(strip_tags($line["content_preview"]), 100);
+                                       $headline_row["excerpt"] = $excerpt;
+                               }
+
+                               if ($show_content) {
+                                       $headline_row["content"] = $line["content_preview"];
+                               }
+
                                array_push($headlines, $headline_row);
                        }
 
 
                        break;
                case "updateArticle":
-                       $article_id = (int) db_escape_string($_GET["article_id"]);
+                       $article_ids = split(",", db_escape_string($_REQUEST["article_ids"]));
                        $mode = (int) db_escape_string($_REQUEST["mode"]);
                        $field_raw = (int)db_escape_string($_REQUEST["field"]);
 
                                        break;
                        }
 
-                       if ($field && $set_to) {
+                       if ($field && $set_to && count($article_ids) > 0) {
+
+                               $article_ids = join(", ", $article_ids);
+
                                if ($field == "unread") {
                                        $result = db_query($link, "UPDATE ttrss_user_entries SET $field = $set_to,
                                                last_read = NOW()
-                                               WHERE ref_id = '$article_id' AND owner_uid = " . $_SESSION["uid"]);
+                                               WHERE ref_id IN ($article_ids) AND owner_uid = " . $_SESSION["uid"]);
                                } else {
                                        $result = db_query($link, "UPDATE ttrss_user_entries SET $field = $set_to
-                                               WHERE ref_id = '$article_id' AND owner_uid = " . $_SESSION["uid"]);
+                                               WHERE ref_id IN ($article_ids) AND owner_uid = " . $_SESSION["uid"]);
                                }
                        }
 
                        print json_encode($article);
 
                        break;
+               case "getConfig":
+                       $config = array(
+                               "icons_dir" => ICONS_DIR,
+                               "icons_url" => ICONS_URL);
+
+                       if (ENABLE_UPDATE_DAEMON) {
+                               $config["daemon_is_running"] = file_is_locked("update_daemon.lock");
+                       }
+
+                       $result = db_query($link, "SELECT COUNT(*) AS cf FROM
+                               ttrss_feeds WHERE owner_uid = " . $_SESSION["uid"]);
+
+                       $num_feeds = db_fetch_result($result, 0, "cf");
+
+                       $config["num_feeds"] = (int)$num_feeds;
+       
+                       print json_encode($config);
+
+                       break;
+
+               case "updateFeed":
+                       $feed_id = db_escape_string($_REQUEST["feed_id"]);
+
+                       update_rss_feed($link, $feed_id, true);
+
+                       print json_encode(array("status" => "OK"));
+
+                       break;
+
+               case "getPref":
+                       $pref_name = db_escape_string($_REQUEST["pref_name"]);
+                       print json_encode(array("value" => get_pref($link, $pref_name)));
+                       break;
+
+               default:
+                       print json_encode(array("error" => 'UNKNOWN_METHOD'));
+                       break;
+
        }
 
        db_close($link);