]> git.wh0rd.org - tt-rss.git/blobdiff - backend.php
http user auth, password changer in preferences
[tt-rss.git] / backend.php
index 2ed2f926640ac9a4b7e0e90d7ec7b986ee91b18f..ed8ab6c1889ef213fcd88cc386e973eb6a28159f 100644 (file)
@@ -1,17 +1,25 @@
 <?
-       define(SCHEMA_VERSION, 2);
+       session_start();
 
-       $op = $_GET["op"];
+       if (!$_SESSION["uid"]) { exit; }
 
-       if ($op == "rpc") {
-               header("Content-Type: application/xml");
-       }
+       define(SCHEMA_VERSION, 2);
 
        require_once "config.php";
        require_once "db.php";
+       require_once "db-prefs.php";
        require_once "functions.php";
        require_once "magpierss/rss_fetch.inc";
 
+//     $_SESSION["uid"] = PLACEHOLDER_UID; // FIXME: placeholder
+//     $_SESSION["name"] = PLACEHOLDER_NAME;
+
+       $op = $_REQUEST["op"];
+
+       if ($op == "rpc" || $op == "updateAllFeeds") {
+               header("Content-Type: application/xml");
+       }
+
        $script_started = getmicrotime();
 
        $link = db_connect(DB_HOST, DB_USER, DB_PASS, DB_NAME); 
@@ -46,7 +54,7 @@
 
        function getGlobalCounters($link) {
                $result = db_query($link, "SELECT count(id) as c_id FROM ttrss_entries
-                       WHERE unread = true");
+                       WHERE unread = true AND owner_uid = " . $_SESSION["uid"]);
                $c_id = db_fetch_result($result, 0, "c_id");
                print "<counter id='global-unread' counter='$c_id'/>";
        }
        function getTagCounters($link) {
                $result = db_query($link, "SELECT tag_name,count(ttrss_entries.id) AS count
                        FROM ttrss_tags,ttrss_entries WHERE
+                       ttrss_tags.owner_uid = ".$_SESSION["uid"]." AND
                        post_id = ttrss_entries.id AND unread = true GROUP BY tag_name 
                UNION
-                       select tag_name,0 as count FROM ttrss_tags");
+                       select tag_name,0 as count FROM ttrss_tags
+                       WHERE ttrss_tags.owner_uid = ".$_SESSION["uid"]);
 
                $tags = array();
 
        function getLabelCounters($link) {
 
                $result = db_query($link, "SELECT count(id) as count FROM ttrss_entries
-                       WHERE marked = true AND unread = true");
+                       WHERE marked = true AND unread = true AND owner_uid = ".$_SESSION["uid"]);
 
                $count = db_fetch_result($result, 0, "count");
 
                print "<label id=\"-1\" counter=\"$count\"/>";
 
-               $result = db_query($link, "SELECT id,sql_exp,description FROM
-                       ttrss_labels ORDER by description");
+               $result = db_query($link, "SELECT owner_uid,id,sql_exp,description FROM
+                       ttrss_labels WHERE owner_uid = ".$_SESSION["uid"]." ORDER by description");
        
                while ($line = db_fetch_assoc($result)) {
 
        
                $result = db_query($link, "SELECT 
                                count(id) as count FROM ttrss_entries
-                       WHERE feed_id = '$id'   AND unread = true");
+                       WHERE feed_id = '$id' AND unread = true");
        
                        $count = db_fetch_result($result, 0, "count");
                        
                $result = db_query($link, "SELECT id,
                        (SELECT count(id) FROM ttrss_entries WHERE feed_id = ttrss_feeds.id 
                                AND unread = true) as count
-                       FROM ttrss_feeds");
+                       FROM ttrss_feeds WHERE owner_uid = ".$_SESSION["uid"]);
        
                while ($line = db_fetch_assoc($result)) {
                
 
                print "<html><head>
                        <title>Tiny Tiny RSS : Feedlist</title>
-                       <link rel=\"stylesheet\" href=\"tt-rss.css\" type=\"text/css\">
-                       <script type=\"text/javascript\" src=\"functions.js\"></script>
+                       <link rel=\"stylesheet\" href=\"tt-rss.css\" type=\"text/css\">";
+
+               if (get_pref($link, 'USE_COMPACT_STYLESHEET')) {
+                       print "<link rel=\"stylesheet\" type=\"text/css\" 
+                               href=\"tt-rss_compact.css\"/>";
+               } else {
+                       print "<link title=\"Compact Stylesheet\" rel=\"alternate stylesheet\" 
+                                       type=\"text/css\" href=\"tt-rss_compact.css\"/>";
+               }
+
+               print "<script type=\"text/javascript\" src=\"functions.js\"></script>
                        <script type=\"text/javascript\" src=\"feedlist.js\"></script>
                        <meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\">
                        </head><body onload=\"init()\">";
 
                print "<ul class=\"feedList\" id=\"feedList\">";
 
+               $owner_uid = $_SESSION["uid"];
+
                if (!$tags) {
 
                        /* virtual feeds */
 
                        $result = db_query($link, "SELECT count(id) as num_starred 
-                               FROM ttrss_entries WHERE marked = true AND unread = true");
+                               FROM ttrss_entries WHERE marked = true AND unread = true AND owner_uid = '$owner_uid'");
                        $num_starred = db_fetch_result($result, 0, "num_starred");
 
                        $class = "virt";
                        if ($num_starred > 0) $class .= "Unread";
 
                        printFeedEntry(-1, $class, "Starred articles", $num_starred, 
-                               "images/mark_set.png");
+                               "images/mark_set.png", $link);
 
-                       if (ENABLE_LABELS) {
+                       if (get_pref($link, 'ENABLE_LABELS')) {
        
                                $result = db_query($link, "SELECT id,sql_exp,description FROM
-                                       ttrss_labels ORDER by description");
+                                       ttrss_labels WHERE owner_uid = '$owner_uid' ORDER by description");
                
                                if (db_num_rows($result) > 0) {
                                        print "<li><hr></li>";
                                        error_reporting (E_ERROR | E_WARNING | E_PARSE);
        
                                        printFeedEntry(-$line["id"]-11, 
-                                               $class, $line["description"], $count, "images/label.png");
+                                               $class, $line["description"], $count, "images/label.png", $link);
                
                                }
                        }
                                        WHERE feed_id = ttrss_feeds.id) AS total,
                                (SELECT count(id) FROM ttrss_entries
                                        WHERE feed_id = ttrss_feeds.id AND unread = true) as unread
-                               FROM ttrss_feeds ORDER BY title");                      
+                               FROM ttrss_feeds WHERE owner_uid = '$owner_uid' ORDER BY title");                       
        
                        $actid = $_GET["actid"];
        
        
                                $total_unread += $unread;
        
-                               printFeedEntry($feed_id, $class, $feed, $unread, "icons/$feed_id.ico");
+                               printFeedEntry($feed_id, $class, $feed, $unread, "icons/$feed_id.ico", $link);
        
                                ++$lnum;
                        }
 
                        $result = db_query($link, "SELECT tag_name,count(ttrss_entries.id) AS count
                                FROM ttrss_tags,ttrss_entries WHERE
-                               post_id = ttrss_entries.id AND unread = true GROUP BY tag_name 
+                               post_id = ttrss_entries.id AND unread = true 
+                               AND ttrss_tags.owner_uid = '$owner_uid' GROUP BY tag_name                               
                        UNION
-                               select tag_name,0 as count FROM ttrss_tags");
+                               select tag_name,0 as count FROM ttrss_tags WHERE owner_uid = '$owner_uid'");
        
                        $tags = array();
        
                                        $class .= "Unread";
                                }
        
-                               printFeedEntry($tag, $class, $tag, $unread, "images/tag.png");
+                               printFeedEntry($tag, $class, $tag, $unread, "images/tag.png", $link);
        
                        } 
 
                }
 
                if (db_num_rows($result) == 0) {
-                       print "<li>No tags to display.</li>";
+                       print "<li>No tags/feeds to display.</li>";
                }
 
                print "</ul>";
                if ($addheader) {
                        print "<html><head>
                                <title>Tiny Tiny RSS : Feed $feed</title>
-                               <link rel=\"stylesheet\" href=\"tt-rss.css\" type=\"text/css\">
-                               <meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\">
+                               <link rel=\"stylesheet\" href=\"tt-rss.css\" type=\"text/css\">";
+
+                       if (get_pref($link, 'USE_COMPACT_STYLESHEET')) {
+                               print "<link rel=\"stylesheet\" 
+                                               type=\"text/css\" href=\"tt-rss_compact.css\"/>";
+
+                       } else {
+                               print "<link title=\"Compact Stylesheet\" rel=\"alternate stylesheet\" 
+                                               type=\"text/css\" href=\"tt-rss_compact.css\"/>";
+                       }
+                       print "<meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\">  
                                <script type=\"text/javascript\" src=\"functions.js\"></script>
                                <script type=\"text/javascript\" src=\"viewfeed.js\"></script>
                                </head><body onload='init()'>";
                        $feed_title = db_escape_string($_GET["t"]);
                        $feed_link = db_escape_string($_GET["l"]);
                        $upd_intl = db_escape_string($_GET["ui"]);
+                       $purge_intl = db_escape_string($_GET["pi"]);
                        $feed_id = $_GET["id"];
 
                        if (strtoupper($upd_intl) == "DEFAULT")
                                $upd_intl = 0;
 
+                       if (strtoupper($purge_intl) == "DEFAULT")
+                               $purge_intl = 0;
+
+                       if (strtoupper($purge_intl) == "DISABLED")
+                               $purge_intl = -1;
+
                        $result = db_query($link, "UPDATE ttrss_feeds SET 
                                title = '$feed_title', feed_url = '$feed_link',
-                               update_interval = '$upd_intl' WHERE id = '$feed_id'");                  
+                               update_interval = '$upd_intl',
+                               purge_interval = '$purge_intl' 
+                               WHERE id = '$feed_id'");                        
 
                }
 
 
                                foreach ($ids as $id) {
                                        db_query($link, "DELETE FROM ttrss_feeds WHERE id = '$id'");
+
+                                       $icons_dir = get_pref($link, 'ICONS_DIR');
                                        
-                                       if (file_exists(ICONS_DIR . "/$id.ico")) {
-                                               unlink(ICONS_DIR . "/$id.ico");
+                                       if (file_exists($icons_dir . "/$id.ico")) {
+                                               unlink($icons_dir . "/$id.ico");
                                        }
                                }
                        }
                                $feed_link = db_escape_string($_GET["link"]);
                                        
                                $result = db_query($link,
-                                       "INSERT INTO ttrss_feeds (feed_url,title) VALUES ('$feed_link', '')");
+                                       "INSERT INTO ttrss_feeds (owner_uid,feed_url,title) VALUES ('".$_SESSION["uid"]."', '$feed_link', '')");
 
                                $result = db_query($link,
                                        "SELECT id FROM ttrss_feeds WHERE feed_url = '$feed_link'");
 
                $result = db_query($link, "SELECT 
                                id,title,feed_url,substring(last_updated,1,16) as last_updated,
-                               update_interval
+                               update_interval,purge_interval
                        FROM 
-                               ttrss_feeds ORDER by title");
+                               ttrss_feeds WHERE owner_uid = '".$_SESSION["uid"]."' ORDER by title");
 
                print "<p><table width=\"100%\" class=\"prefFeedList\" id=\"prefFeedList\">";
                print "<tr class=\"title\">
-                                       <td>&nbsp;</td><td>Select</td><td width=\"40%\">Title</td>
-                                       <td width=\"30%\">Link</td><td width=\"10%\">Update Interval</td>
+                                       <td>&nbsp;</td><td>Select</td><td width=\"30%\">Title</td>
+                                       <td width=\"30%\">Link</td>
+                                       <td width=\"10%\">Update Interval</td>
+                                       <td width=\"10%\">Purge Days</td>
                                        <td>Last updated</td></tr>";
                
                $lnum = 0;
 
                        print "<tr class=\"$class\" id=\"FEEDR-$feed_id\">";
 
-                       $icon_file = ICONS_DIR . "/$feed_id.ico";
+                       $icon_file = get_pref($link, 'ICONS_DIR') . "/$feed_id.ico";
 
                        if (file_exists($icon_file) && filesize($icon_file) > 0) {
                                        $feed_icon = "<img width=\"16\" height=\"16\"
-                                               src=\"" . ICONS_URL . "/$feed_id.ico\">";
+                                               src=\"" . get_pref($link, 'ICONS_URL') . "/$feed_id.ico\">";
                        } else {
                                $feed_icon = "&nbsp;";
                        }
                                type=\"checkbox\" id=\"FRCHK-".$line["id"]."\"></td>";
 
                                print "<td><a href=\"javascript:editFeed($feed_id);\">" . 
-                                       $edit_title . "</td>";          
+                                       $edit_title . "</a></td>";              
                                print "<td><a href=\"javascript:editFeed($feed_id);\">" . 
-                                       $edit_link . "</td>";           
+                                       $edit_link . "</a></td>";               
 
                                if ($line["update_interval"] == "0")
                                        $line["update_interval"] = "Default";
 
-                               print "<td>" . $line["update_interval"] . "</td>";
+                               print "<td><a href=\"javascript:editFeed($feed_id);\">" . 
+                                       $line["update_interval"] . "</a></td>";
+
+                               if ($line["purge_interval"] == "0")
+                                       $line["purge_interval"] = "Default";
+
+                               if ($line["purge_interval"] < 0)
+                                       $line["purge_interval"] = "Disabled";
 
+                               print "<td><a href=\"javascript:editFeed($feed_id);\">" . 
+                                       $line["purge_interval"] . "</a></td>";
 
                        } else if ($feed_id != $edit_feed_id) {
 
 
                                print "<td>" . $line["update_interval"] . "</td>";
 
+                               if ($line["purge_interval"] == "0")
+                                       $line["purge_interval"] = "Default";
+
+                               if ($line["purge_interval"] < 0)
+                                       $line["purge_interval"] = "Disabled";
+
+                               print "<td>" . $line["purge_interval"] . "</td>";
+
                        } else {
 
                                print "<td><input disabled=\"true\" type=\"checkbox\"></td>";
                                print "<td><input id=\"iedit_title\" value=\"$edit_title\"></td>";
                                print "<td><input id=\"iedit_link\" value=\"$edit_link\"></td>";
                                print "<td><input id=\"iedit_updintl\" value=\"".$line["update_interval"]."\"></td>";
+                               print "<td><input id=\"iedit_purgintl\" value=\"".$line["purge_interval"]."\"></td>";
                                        
                        }
 
                        <input type=\"submit\" class=\"button\" 
                                onclick=\"javascript:removeSelectedFeeds()\" value=\"Remove\">";
                                
-                       if (ENABLE_PREFS_CATCHUP_UNCATCHUP) {
+                       if (get_pref($link, 'ENABLE_PREFS_CATCHUP_UNCATCHUP')) {
                                print "
                                <input type=\"submit\" class=\"button\" 
                                        onclick=\"javascript:readSelectedFeeds()\" value=\"Mark as read\">
                                $match = db_escape_string($_GET["match"]);
                                        
                                $result = db_query($link,
-                                       "INSERT INTO ttrss_filters (reg_exp,filter_type) VALUES 
+                                       "INSERT INTO ttrss_filters (reg_exp,filter_type,owner_uid) VALUES 
                                                ('$regexp', (SELECT id FROM ttrss_filter_types WHERE
-                                                       description = '$match'))");
+                                                       description = '$match'),'".$_SESSION["uid"]."')");
                        } 
                }
 
                                (SELECT description FROM ttrss_filter_types 
                                        WHERE id = filter_type) as filter_type_descr
                        FROM 
-                               ttrss_filters ORDER by reg_exp");
+                               ttrss_filters
+                       WHERE
+                               owner_uid = ".$_SESSION["uid"]."
+                       ORDER by reg_exp");
 
                print "<p><table width=\"100%\" class=\"prefFilterList\" id=\"prefFilterList\">";
 
                                $exp = $_GET["exp"];
                                        
                                $result = db_query($link,
-                                       "INSERT INTO ttrss_labels (sql_exp,description) 
-                                               VALUES ('$exp', '$exp')");
+                                       "INSERT INTO ttrss_labels (sql_exp,description,owner_uid
+                                               VALUES ('$exp', '$exp', '".$_SESSION["uid"]."')");
                        } 
                }
 
                $result = db_query($link, "SELECT 
                                id,sql_exp,description
                        FROM 
-                               ttrss_labels ORDER by description");
+                               ttrss_labels 
+                       WHERE 
+                               owner_uid = ".$_SESSION["uid"]."
+                       ORDER by description");
 
                print "<p><table width=\"100%\" class=\"prefLabelList\" id=\"prefLabelList\">";
 
 
        }
 
+       if ($op == "updateAllFeeds") {
+               update_all_feeds($link, true);                  
+
+               print "<rpc-reply>";
+               getLabelCounters($link);
+               getFeedCounters($link);
+               getTagCounters($link);
+               getGlobalCounters($link);
+               print "</rpc-reply>";
+
+       }
+
+       if ($op == "pref-prefs") {
+
+               $subop = $_REQUEST["subop"];
+
+               if ($subop == "Save configuration") {
+
+                       if (WEB_DEMO_MODE) return;
+
+                       foreach (array_keys($_POST) as $pref_name) {
+                       
+                               $pref_name = db_escape_string($pref_name);
+                               $value = db_escape_string($_POST[$pref_name]);
+
+                               $result = db_query($link, "SELECT type_name 
+                                       FROM ttrss_prefs,ttrss_prefs_types 
+                                       WHERE pref_name = '$pref_name' AND type_id = ttrss_prefs_types.id");
+
+                               if (db_num_rows($result) > 0) {
+
+                                       $type_name = db_fetch_result($result, 0, "type_name");
+
+//                                     print "$pref_name : $type_name : $value<br>";
+
+                                       if ($type_name == "bool") {
+                                               if ($value == "1") {
+                                                       $value = "true";
+                                               } else {
+                                                       $value = "false";
+                                               }
+                                       } else if ($type_name == "integer") {
+                                               $value = sprintf("%d", $value);
+                                       }
+
+//                                     print "$pref_name : $type_name : $value<br>";
+
+                                       db_query($link, "UPDATE ttrss_user_prefs SET value = '$value' 
+                                               WHERE pref_name = '$pref_name' AND owner_uid = ".$_SESSION["uid"]);
+
+                               }
+
+                               header("Location: prefs.php");
+
+                       }
+
+               } else if ($subop == "getHelp") {
+
+                       $pref_name = db_escape_string($_GET["pn"]);
+
+                       $result = db_query($link, "SELECT help_text FROM ttrss_prefs
+                               WHERE pref_name = '$pref_name'");
+
+                       if (db_num_rows($result) > 0) {
+                               $help_text = db_fetch_result($result, 0, "help_text");
+                               print $help_text;
+                       } else {
+                               print "Unknown option: $pref_name";
+                       }
+
+               } else if ($subop == "Change password") {
+
+                       if (WEB_DEMO_MODE) return;
+
+                       $old_pw = $_POST["OLD_PASSWORD"];
+                       $new_pw = $_POST["OLD_PASSWORD"];
+
+                       $old_pw_hash = 'SHA1:' . sha1($_POST["OLD_PASSWORD"]);
+                       $new_pw_hash = 'SHA1:' . sha1($_POST["NEW_PASSWORD"]);
+
+                       $active_uid = $_SESSION["uid"];
+
+                       if ($old_pw && $new_pw) {
+
+                               $login = db_escape_string($_SERVER['PHP_AUTH_USER']);
+
+                               $result = db_query($link, "SELECT id FROM ttrss_users WHERE 
+                                       id = '$active_uid' AND (pwd_hash = '$old_pw' OR 
+                                               pwd_hash = '$old_pw_hash')");
+
+                               if (db_num_rows($result) == 1) {
+                                       db_query($link, "UPDATE ttrss_users SET pwd_hash = '$new_pw_hash' 
+                                               WHERE id = '$active_uid'");                             
+                               }
+                       }
+
+                       header("Location: prefs.php");
+       
+               } else if ($subop == "Reset to defaults") {
+
+                       if (WEB_DEMO_MODE) return;
+
+                       db_query($link,"UPDATE ttrss_user_prefs 
+                               SET value = ttrss_prefs.def_value 
+                               WHERE owner_uid = '".$_SESSION["uid"]."' AND
+                               ttrss_prefs.pref_name = ttrss_user_prefs.pref_name");
+
+                       header("Location: prefs.php");
+
+               } else {
+
+                       print "<form action=\"backend.php\" method=\"POST\">";
+
+                       print "<table width=\"100%\" class=\"prefPrefsList\">";
+                       print "<tr><td colspan='3'><h3>Authentication</h3></tr></td>";
+
+                       print "<tr><td width=\"40%\">Old password</td>";
+                       print "<td><input class=\"editbox\" type=\"password\"
+                               name=\"OLD_PASSWORD\"></td></tr>";
+
+                       print "<tr><td width=\"40%\">New password</td>";
+                       
+                       print "<td><input class=\"editbox\" type=\"password\"
+                               name=\"NEW_PASSWORD\"></td></tr>";
+
+                       print "</table>";
+
+                       print "<input type=\"hidden\" name=\"op\" value=\"pref-prefs\">";
+
+                       print "<p><input class=\"button\" type=\"submit\" 
+                               value=\"Change password\" name=\"subop\">";
+
+                       print "</form>";
+
+                       $result = db_query($link, "SELECT 
+                               ttrss_user_prefs.pref_name,short_desc,help_text,value,type_name,
+                               section_name,def_value
+                               FROM ttrss_prefs,ttrss_prefs_types,ttrss_prefs_sections,ttrss_user_prefs
+                               WHERE type_id = ttrss_prefs_types.id AND 
+                                       section_id = ttrss_prefs_sections.id AND
+                                       ttrss_user_prefs.pref_name = ttrss_prefs.pref_name
+                               ORDER BY section_id,short_desc");
+
+                       print "<form action=\"backend.php\" method=\"POST\">";
+
+                       $lnum = 0;
+
+                       $active_section = "";
+       
+                       while ($line = db_fetch_assoc($result)) {
+
+                               if ($active_section != $line["section_name"]) {
+
+                                       if ($active_section != "") {
+                                               print "</table>";
+                                       }
+
+                                       print "<p><table width=\"100%\" class=\"prefPrefsList\">";
+                               
+                                       $active_section = $line["section_name"];                                
+                                       
+                                       print "<tr><td colspan=\"3\"><h3>$active_section</h3></td></tr>";
+//                                     print "<tr class=\"title\">
+//                                             <td width=\"25%\">Option</td><td>Value</td></tr>";
+
+                                       $lnum = 0;
+                               }
+
+//                             $class = ($lnum % 2) ? "even" : "odd";
+
+                               print "<tr>";
+
+                               $type_name = $line["type_name"];
+                               $pref_name = $line["pref_name"];
+                               $value = $line["value"];
+                               $def_value = $line["def_value"];
+                               $help_text = $line["help_text"];
+
+                               print "<td width=\"40%\" id=\"$pref_name\">" . $line["short_desc"];
+
+                               if ($help_text) print "<div class=\"prefHelp\">$help_text</div>";
+                               
+                               print "</td>";
+
+                               print "<td>";
+
+                               if ($type_name == "bool") {
+//                                     print_select($pref_name, $value, array("true", "false"));
+
+                                       if ($value == "true") {
+                                               $value = "Yes";
+                                       } else {
+                                               $value = "No";
+                                       }
+
+                                       print_radio($pref_name, $value, array("Yes", "No"));
+                       
+                               } else {
+                                       print "<input class=\"editbox\" name=\"$pref_name\" value=\"$value\">";
+                               }
+
+                               print "</td>";
+
+                               print "</tr>";
+
+                               $lnum++;
+                       }
+
+                       print "</table>";
+
+                       print "<input type=\"hidden\" name=\"op\" value=\"pref-prefs\">";
+
+                       print "<p><input class=\"button\" type=\"submit\" 
+                               name=\"subop\" value=\"Save configuration\">";
+                               
+                       print "&nbsp;<input class=\"button\" type=\"submit\" 
+                               name=\"subop\" value=\"Reset to defaults\"></p>";
+
+                       print "</form>";
+
+               }
+
+       }
+
        db_close($link);
 ?>