]> git.wh0rd.org - tt-rss.git/blobdiff - classes/api.php
prevent frontend updating of feeds on view if open_basedir is set to prevent plugins...
[tt-rss.git] / classes / api.php
index e9ffc63dd10e579a5420b99e0deab34aa1c66179..9be04cff93cd0fb882b102ef2e38009587ec1dd2 100644 (file)
@@ -2,7 +2,7 @@
 
 class API extends Handler {
 
-       const API_LEVEL  = 7;
+       const API_LEVEL  = 13;
 
        const STATUS_OK  = 0;
        const STATUS_ERR = 1;
@@ -77,6 +77,7 @@ class API extends Handler {
                                $this->wrap(self::STATUS_OK,    array("session_id" => session_id(),
                                        "api_level" => self::API_LEVEL));
                        } else {                                                         // else we are not logged in
+                               user_error("Failed login attempt for $login from {$_SERVER['REMOTE_ADDR']}", E_USER_WARNING);
                                $this->wrap(self::STATUS_ERR, array("error" => "LOGIN_ERROR"));
                        }
                } else {
@@ -183,6 +184,8 @@ class API extends Handler {
                $feed_id = $this->dbh->escape_string($_REQUEST["feed_id"]);
                if ($feed_id != "") {
 
+                       if (is_numeric($feed_id)) $feed_id = (int) $feed_id;
+
                        $limit = (int)$this->dbh->escape_string($_REQUEST["limit"]);
 
                        if (!$limit || $limit >= 200) $limit = 200;
@@ -199,11 +202,24 @@ class API extends Handler {
                        $include_nested = sql_bool_to_bool($_REQUEST["include_nested"]);
                        $sanitize_content = !isset($_REQUEST["sanitize"]) ||
                                sql_bool_to_bool($_REQUEST["sanitize"]);
+                       $force_update = sql_bool_to_bool($_REQUEST["force_update"]);
+                       $has_sandbox = sql_bool_to_bool($_REQUEST["has_sandbox"]);
+                       $excerpt_length = (int)$this->dbh->escape_string($_REQUEST["excerpt_length"]);
+                       $check_first_id = (int)$this->dbh->escape_string($_REQUEST["check_first_id"]);
+                       $include_header = sql_bool_to_bool($_REQUEST["include_header"]);
+
+                       $_SESSION['hasSandbox'] = $has_sandbox;
+
+                       $skip_first_id_check = false;
 
                        $override_order = false;
                        switch ($_REQUEST["order_by"]) {
+                               case "title":
+                                       $override_order = "ttrss_entries.title";
+                                       break;
                                case "date_reverse":
                                        $override_order = "score DESC, date_entered, updated";
+                                       $skip_first_id_check = true;
                                        break;
                                case "feed_dates":
                                        $override_order = "updated DESC";
@@ -213,14 +229,17 @@ class API extends Handler {
                        /* do not rely on params below */
 
                        $search = $this->dbh->escape_string($_REQUEST["search"]);
-                       $search_mode = $this->dbh->escape_string($_REQUEST["search_mode"]);
 
-                       $headlines = $this->api_get_headlines($feed_id, $limit, $offset,
+                       list($headlines, $headlines_header) = $this->api_get_headlines($feed_id, $limit, $offset,
                                $filter, $is_cat, $show_excerpt, $show_content, $view_mode, $override_order,
-                               $include_attachments, $since_id, $search, $search_mode,
-                               $include_nested, $sanitize_content);
+                               $include_attachments, $since_id, $search,
+                               $include_nested, $sanitize_content, $force_update, $excerpt_length, $check_first_id, $skip_first_id_check);
 
-                       $this->wrap(self::STATUS_OK, $headlines);
+                       if ($include_header) {
+                               $this->wrap(self::STATUS_OK, array($headlines_header, $headlines));
+                       } else {
+                               $this->wrap(self::STATUS_OK, $headlines);
+                       }
                } else {
                        $this->wrap(self::STATUS_ERR, array("error" => 'INCORRECT_USAGE'));
                }
@@ -306,13 +325,17 @@ class API extends Handler {
        function getArticle() {
 
                $article_id = join(",", array_filter(explode(",", $this->dbh->escape_string($_REQUEST["article_id"])), is_numeric));
+               $sanitize_content = !isset($_REQUEST["sanitize"]) ||
+                       sql_bool_to_bool($_REQUEST["sanitize"]);
 
                if ($article_id) {
 
                        $query = "SELECT id,title,link,content,feed_id,comments,int_id,
-                               marked,unread,published,score,
+                               marked,unread,published,score,note,lang,
                                ".SUBSTRING_FOR_DATE."(updated,1,16) as updated,
-                               author,(SELECT title FROM ttrss_feeds WHERE id = feed_id) AS feed_title
+                               author,(SELECT title FROM ttrss_feeds WHERE id = feed_id) AS feed_title,
+                               (SELECT site_url FROM ttrss_feeds WHERE id = feed_id) AS site_url,
+                               (SELECT hide_images FROM ttrss_feeds WHERE id = feed_id) AS hide_images
                                FROM ttrss_entries,ttrss_user_entries
                                WHERE   id IN ($article_id) AND ref_id = id AND owner_uid = " .
                                        $_SESSION["uid"] ;
@@ -338,13 +361,23 @@ class API extends Handler {
                                                "comments" => $line["comments"],
                                                "author" => $line["author"],
                                                "updated" => (int) strtotime($line["updated"]),
-                                               "content" => $line["content"],
                                                "feed_id" => $line["feed_id"],
                                                "attachments" => $attachments,
                                                "score" => (int)$line["score"],
-                                               "feed_title" => $line["feed_title"]
+                                               "feed_title" => $line["feed_title"],
+                                               "note" => $line["note"],
+                                               "lang" => $line["lang"]
                                        );
 
+                                       if ($sanitize_content) {
+                                               $article["content"] = sanitize(
+                                                       $line["content"],
+                                                       sql_bool_to_bool($line['hide_images']),
+                                                       false, $line["site_url"], false, $line["id"]);
+                                       } else {
+                                               $article["content"] = $line["content"];
+                                       }
+
                                        foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_RENDER_ARTICLE_API) as $p) {
                                                $article = $p->hook_render_article_api(array("article" => $article));
                                        }
@@ -383,7 +416,9 @@ class API extends Handler {
 
                $feed_id = (int) $this->dbh->escape_string($_REQUEST["feed_id"]);
 
-               update_rss_feed($feed_id, true);
+               if (!ini_get("open_basedir")) {
+                       update_rss_feed($feed_id, true);
+               }
 
                $this->wrap(self::STATUS_OK, array("status" => "OK"));
        }
@@ -423,7 +458,7 @@ class API extends Handler {
 
                        $checked = false;
                        foreach ($article_labels as $al) {
-                               if ($al[0] == $line['id']) {
+                               if (feed_to_label_id($al[0]) == $line['id']) {
                                        $checked = true;
                                        break;
                                }
@@ -447,7 +482,7 @@ class API extends Handler {
                $assign = (bool) $this->dbh->escape_string($_REQUEST['assign']) == "true";
 
                $label = $this->dbh->escape_string(label_find_caption(
-                       $label_id, $_SESSION["uid"]));
+                       feed_to_label_id($label_id), $_SESSION["uid"]));
 
                $num_updated = 0;
 
@@ -511,7 +546,7 @@ class API extends Handler {
                                        if ($unread || !$unread_only) {
 
                                                $row = array(
-                                                               "id" => $cv["id"],
+                                                               "id" => (int) $cv["id"],
                                                                "title" => $cv["description"],
                                                                "unread" => $cv["counter"],
                                                                "cat_id" => -2,
@@ -557,7 +592,7 @@ class API extends Handler {
 
                                        if ($unread || !$unread_only) {
                                                $row = array(
-                                                               "id" => $line["id"],
+                                                               "id" => (int) $line["id"],
                                                                "title" => $line["title"],
                                                                "unread" => $unread,
                                                                "is_cat" => true,
@@ -625,39 +660,103 @@ class API extends Handler {
        static function api_get_headlines($feed_id, $limit, $offset,
                                $filter, $is_cat, $show_excerpt, $show_content, $view_mode, $order,
                                $include_attachments, $since_id,
-                               $search = "", $search_mode = "",
-                               $include_nested = false, $sanitize_content = true) {
+                               $search = "", $include_nested = false, $sanitize_content = true,
+                               $force_update = false, $excerpt_length = 100, $check_first_id = false, $skip_first_id_check = false) {
+
+                       if ($force_update && $feed_id > 0 && is_numeric($feed_id)) {
+                               // Update the feed if required with some basic flood control
+
+                               $result = db_query(
+                                       "SELECT cache_images,".SUBSTRING_FOR_DATE."(last_updated,1,19) AS last_updated
+                                               FROM ttrss_feeds WHERE id = '$feed_id'");
+
+                               if (db_num_rows($result) != 0) {
+                                       $last_updated = strtotime(db_fetch_result($result, 0, "last_updated"));
+                                       $cache_images = sql_bool_to_bool(db_fetch_result($result, 0, "cache_images"));
+
+                                       if (!$cache_images && time() - $last_updated > 120) {
+                                               include "rssfuncs.php";
+                                               update_rss_feed($feed_id, true, true);
+                                       } else {
+                                               db_query("UPDATE ttrss_feeds SET last_updated = '1970-01-01', last_update_started = '1970-01-01'
+                                                       WHERE id = '$feed_id'");
+                                       }
+                               }
+                       }
 
-                       $qfh_ret = queryFeedHeadlines($feed_id, $limit,
-                               $view_mode, $is_cat, $search, $search_mode,
-                               $order, $offset, 0, false, $since_id, $include_nested);
+                       /*$qfh_ret = queryFeedHeadlines($feed_id, $limit,
+                               $view_mode, $is_cat, $search, false,
+                               $order, $offset, 0, false, $since_id, $include_nested);*/
+
+                       //function queryFeedHeadlines($feed, $limit,
+                       // $view_mode, $cat_view, $search, $search_mode,
+                       // $override_order = false, $offset = 0, $owner_uid = 0, $filter = false, $since_id = 0, $include_children = false,
+                       // $ignore_vfeed_group = false, $override_strategy = false, $override_vfeed = false, $start_ts = false, $check_top_id = false) {
+
+                       $params = array(
+                               "feed" => $feed_id,
+                               "limit" => $limit,
+                               "view_mode" => $view_mode,
+                               "cat_view" => $is_cat,
+                               "search" => $search,
+                               "override_order" => $order,
+                               "offset" => $offset,
+                               "since_id" => $since_id,
+                               "include_children" => $include_nested,
+                               "check_first_id" => $check_first_id,
+                               "skip_first_id_check" => $skip_first_id_check
+                       );
+
+                       $qfh_ret = queryFeedHeadlines($params);
 
                        $result = $qfh_ret[0];
                        $feed_title = $qfh_ret[1];
+                       $first_id = $qfh_ret[6];
 
                        $headlines = array();
 
-                       while ($line = db_fetch_assoc($result)) {
-                               $line["content_preview"] = truncate_string(strip_tags($line["content_preview"]), 100);
-                               foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_QUERY_HEADLINES) as $p) {
-                                       $line = $p->hook_query_headlines($line, 100, true);
-                               }
+                       $headlines_header = array(
+                               'id' => $feed_id,
+                               'first_id' => $first_id,
+                               'is_cat' => $is_cat);
+
+                       if (!is_numeric($result)) {
+                               while ($line = db_fetch_assoc($result)) {
+                                       $line["content_preview"] = truncate_string(strip_tags($line["content"]), $excerpt_length);
+                                       foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_QUERY_HEADLINES) as $p) {
+                                               $line = $p->hook_query_headlines($line, $excerpt_length, true);
+                                       }
 
-                               $is_updated = ($line["last_read"] == "" &&
-                                       ($line["unread"] != "t" && $line["unread"] != "1"));
+                                       $is_updated = ($line["last_read"] == "" &&
+                                               ($line["unread"] != "t" && $line["unread"] != "1"));
+
+                                       $tags = explode(",", $line["tag_cache"]);
+
+                                       $label_cache = $line["label_cache"];
+                                       $labels = false;
+
+                                       if ($label_cache) {
+                                               $label_cache = json_decode($label_cache, true);
+
+                                               if ($label_cache) {
+                                                       if ($label_cache["no-labels"] == 1)
+                                                               $labels = array();
+                                                       else
+                                                               $labels = $label_cache;
+                                               }
+                                       }
 
-                               $tags = explode(",", $line["tag_cache"]);
-                               $labels = json_decode($line["label_cache"], true);
+                                       if (!is_array($labels)) $labels = get_article_labels($line["id"]);
 
-                               //if (!$tags) $tags = get_article_tags($line["id"]);
-                               //if (!$labels) $labels = get_article_labels($line["id"]);
+                                       //if (!$tags) $tags = get_article_tags($line["id"]);
+                                       //if (!$labels) $labels = get_article_labels($line["id"]);
 
-                               $headline_row = array(
+                                       $headline_row = array(
                                                "id" => (int)$line["id"],
                                                "unread" => sql_bool_to_bool($line["unread"]),
                                                "marked" => sql_bool_to_bool($line["marked"]),
                                                "published" => sql_bool_to_bool($line["published"]),
-                                               "updated" => (int) strtotime($line["updated"]),
+                                               "updated" => (int)strtotime($line["updated"]),
                                                "is_updated" => $is_updated,
                                                "title" => $line["title"],
                                                "link" => $line["link"],
@@ -665,50 +764,55 @@ class API extends Handler {
                                                "tags" => $tags,
                                        );
 
-                               if ($include_attachments)
-                                       $headline_row['attachments'] = get_article_enclosures(
-                                               $line['id']);
+                                       if ($include_attachments)
+                                               $headline_row['attachments'] = get_article_enclosures(
+                                                       $line['id']);
 
-                               if (!$show_excerpt)
-                                       $headline_row["excerpt"] = $line["content_preview"];
+                                       if ($show_excerpt)
+                                               $headline_row["excerpt"] = $line["content_preview"];
 
-                               if ($show_content) {
+                                       if ($show_content) {
 
-                                       if ($sanitize_content) {
-                                               $headline_row["content"] = sanitize(
-                                                       $line["content"],
-                                                       sql_bool_to_bool($line['hide_images']),
-                                                       false, $line["site_url"]);
-                                       } else {
-                                               $headline_row["content"] = $line["content"];
+                                               if ($sanitize_content) {
+                                                       $headline_row["content"] = sanitize(
+                                                               $line["content"],
+                                                               sql_bool_to_bool($line['hide_images']),
+                                                               false, $line["site_url"], false, $line["id"]);
+                                               } else {
+                                                       $headline_row["content"] = $line["content"];
+                                               }
                                        }
-                               }
 
-                               // unify label output to ease parsing
-                               if ($labels["no-labels"] == 1) $labels = array();
+                                       // unify label output to ease parsing
+                                       if ($labels["no-labels"] == 1) $labels = array();
 
-                               $headline_row["labels"] = $labels;
+                                       $headline_row["labels"] = $labels;
 
-                               $headline_row["feed_title"] = $line["feed_title"] ? $line["feed_title"] :
-                                       $feed_title;
+                                       $headline_row["feed_title"] = $line["feed_title"] ? $line["feed_title"] :
+                                               $feed_title;
 
-                               $headline_row["comments_count"] = (int)$line["num_comments"];
-                               $headline_row["comments_link"] = $line["comments"];
+                                       $headline_row["comments_count"] = (int)$line["num_comments"];
+                                       $headline_row["comments_link"] = $line["comments"];
 
-                               $headline_row["always_display_attachments"] = sql_bool_to_bool($line["always_display_enclosures"]);
+                                       $headline_row["always_display_attachments"] = sql_bool_to_bool($line["always_display_enclosures"]);
 
-                               $headline_row["author"] = $line["author"];
+                                       $headline_row["author"] = $line["author"];
 
-                               $headline_row["score"] = (int)$line["score"];
+                                       $headline_row["score"] = (int)$line["score"];
+                                       $headline_row["note"] = $line["note"];
+                                       $headline_row["lang"] = $line["lang"];
 
-                               foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_RENDER_ARTICLE_API) as $p) {
-                                       $headline_row = $p->hook_render_article_api(array("headline" => $headline_row));
-                               }
+                                       foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_RENDER_ARTICLE_API) as $p) {
+                                               $headline_row = $p->hook_render_article_api(array("headline" => $headline_row));
+                                       }
 
-                               array_push($headlines, $headline_row);
+                                       array_push($headlines, $headline_row);
+                               }
+                       } else if (is_numeric($result) && $result == -1) {
+                               $headlines_header['first_id_changed'] = true;
                        }
 
-                       return $headlines;
+                       return array($headlines, $headlines_header);
        }
 
        function unsubscribeFeed() {