]> git.wh0rd.org - tt-rss.git/blobdiff - include/functions.php
force-cast some variables used in queries to integer
[tt-rss.git] / include / functions.php
index 526750574446b646fba26f72fa12357b8486573f..a9786e49b2a08c70cf143c923efa00d98457f396 100644 (file)
@@ -1,6 +1,6 @@
 <?php
        define('EXPECTED_CONFIG_VERSION', 26);
-       define('SCHEMA_VERSION', 130);
+       define('SCHEMA_VERSION', 133);
 
        define('LABEL_BASE_INDEX', -1024);
        define('PLUGIN_FEED_BASE_INDEX', -128);
 
        /**
         * Define a constant if not already defined
-        *
-        * @param string $name The constant name.
-        * @param mixed $value The constant value.
-        * @access public
-        * @return boolean True if defined successfully or not.
         */
        function define_default($name, $value) {
                defined($name) or define($name, $value);
        }
 
-       ///// Some defaults that you can override in config.php //////
+       /* Some tunables you can override in config.php using define(): */
 
        define_default('FEED_FETCH_TIMEOUT', 45);
        // How may seconds to wait for response when requesting feed from a site
        define_default('FILE_FETCH_CONNECT_TIMEOUT', 15);
        // How many seconds to wait for initial response from website when
        // fetching files from remote sites
+       define_default('DAEMON_UPDATE_LOGIN_LIMIT', 30);
+       // stop updating feeds if users haven't logged in for X days
+       define_default('DAEMON_FEED_LIMIT', 500);
+       // feed limit for one update batch
+       define_default('DAEMON_SLEEP_INTERVAL', 120);
+       // default sleep interval between feed updates (sec)
+       define_default('MIN_CACHE_FILE_SIZE', 1024);
+       // do not cache files smaller than that (bytes)
+       define_default('CACHE_MAX_DAYS', 7);
+       // max age in days for various automatically cached (temporary) files
+    define_default('MAX_CONDITIONAL_INTERVAL', 3600*12);
+    // max interval between forced unconditional updates for servers
+    // not complying with http if-modified-since (seconds)
+
+       /* tunables end here */
 
        if (DB_TYPE == "pgsql") {
                define('SUBSTRING_FOR_DATE', 'SUBSTRING_FOR_DATE');
 
        require_once 'db-prefs.php';
        require_once 'version.php';
-       require_once 'ccache.php';
-       require_once 'labels.php';
+       require_once 'controls.php';
 
        define('SELF_USER_AGENT', 'Tiny Tiny RSS/' . VERSION . ' (http://tt-rss.org/)');
        ini_set('user_agent', SELF_USER_AGENT);
 
-       require_once 'lib/pubsubhubbub/Publisher.php';
-
        $schema_version = false;
 
        function _debug_suppress($suppress) {
 
                if (!$purge_interval) $purge_interval = feed_purge_interval($feed_id);
 
-               $rows = -1;
+               $pdo = Db::pdo();
 
-               $result = db_query(
-                       "SELECT owner_uid FROM ttrss_feeds WHERE id = '$feed_id'");
+               $sth = $pdo->prepare("SELECT owner_uid FROM ttrss_feeds WHERE id = ?");
+               $sth->execute([$feed_id]);
 
                $owner_uid = false;
 
-               if (db_num_rows($result) == 1) {
-                       $owner_uid = db_fetch_result($result, 0, "owner_uid");
+               if ($row = $sth->fetch()) {
+                       $owner_uid = $row["owner_uid"];
                }
 
                if ($purge_interval == -1 || !$purge_interval) {
                        if ($owner_uid) {
-                               ccache_update($feed_id, $owner_uid);
+                               CCache::update($feed_id, $owner_uid);
                        }
                        return;
                }
                        $purge_interval = FORCE_ARTICLE_PURGE;
                }
 
-               if (!$purge_unread) $query_limit = " unread = false AND ";
+               if (!$purge_unread)
+                   $query_limit = " unread = false AND ";
+               else
+                   $query_limit = "";
+
+               $purge_interval = (int) $purge_interval;
 
                if (DB_TYPE == "pgsql") {
-                       $result = db_query("DELETE FROM ttrss_user_entries
+                       $sth = $pdo->prepare("DELETE FROM ttrss_user_entries
                                USING ttrss_entries
                                WHERE ttrss_entries.id = ref_id AND
                                marked = false AND
-                               feed_id = '$feed_id' AND
+                               feed_id = ? AND
                                $query_limit
                                ttrss_entries.date_updated < NOW() - INTERVAL '$purge_interval days'");
+                       $sth->execute([$feed_id]);
 
                } else {
-
-/*                     $result = db_query("DELETE FROM ttrss_user_entries WHERE
-                               marked = false AND feed_id = '$feed_id' AND
-                               (SELECT date_updated FROM ttrss_entries WHERE
-                                       id = ref_id) < DATE_SUB(NOW(), INTERVAL $purge_interval DAY)"); */
-
-                       $result = db_query("DELETE FROM ttrss_user_entries
+            $sth  = $pdo->prepare("DELETE FROM ttrss_user_entries
                                USING ttrss_user_entries, ttrss_entries
                                WHERE ttrss_entries.id = ref_id AND
                                marked = false AND
-                               feed_id = '$feed_id' AND
+                               feed_id = ? AND
                                $query_limit
                                ttrss_entries.date_updated < DATE_SUB(NOW(), INTERVAL $purge_interval DAY)");
+            $sth->execute([$feed_id]);
+
                }
 
-               $rows = db_affected_rows($result);
+               $rows = $sth->rowCount();
 
-               ccache_update($feed_id, $owner_uid);
+               CCache::update($feed_id, $owner_uid);
 
                if ($debug) {
                        _debug("Purged feed $feed_id ($purge_interval): deleted $rows articles");
 
        function feed_purge_interval($feed_id) {
 
-               $result = db_query("SELECT purge_interval, owner_uid FROM ttrss_feeds
-                       WHERE id = '$feed_id'");
+           $pdo = DB::pdo();
+
+               $sth = $pdo->prepare("SELECT purge_interval, owner_uid FROM ttrss_feeds
+                       WHERE id = ?");
+               $sth->execute([$feed_id]);
 
-               if (db_num_rows($result) == 1) {
-                       $purge_interval = db_fetch_result($result, 0, "purge_interval");
-                       $owner_uid = db_fetch_result($result, 0, "owner_uid");
+               if ($row = $sth->fetch()) {
+                       $purge_interval = $row["purge_interval"];
+                       $owner_uid = $row["owner_uid"];
 
                        if ($purge_interval == 0) $purge_interval = get_pref(
                                'PURGE_OLD_DAYS', $owner_uid);
                }
        }
 
-       function purge_orphans($do_output = false) {
-
-               // purge orphaned posts in main content table
-               $result = db_query("DELETE FROM ttrss_entries WHERE
-                       NOT EXISTS (SELECT ref_id FROM ttrss_user_entries WHERE ref_id = id)");
-
-               if ($do_output) {
-                       $rows = db_affected_rows($result);
-                       _debug("Purged $rows orphaned posts.");
-               }
-       }
-
-       function get_feed_update_interval($feed_id) {
-               $result = db_query("SELECT owner_uid, update_interval FROM
-                       ttrss_feeds WHERE id = '$feed_id'");
-
-               if (db_num_rows($result) == 1) {
-                       $update_interval = db_fetch_result($result, 0, "update_interval");
-                       $owner_uid = db_fetch_result($result, 0, "owner_uid");
-
-                       if ($update_interval != 0) {
-                               return $update_interval;
-                       } else {
-                               return get_pref('DEFAULT_UPDATE_INTERVAL', $owner_uid, false);
-                       }
-
-               } else {
-                       return -1;
-               }
-       }
-
        // TODO: multiple-argument way is deprecated, first parameter is a hash now
        function fetch_file_contents($options /* previously: 0: $url , 1: $type = false, 2: $login = false, 3: $pass = false,
                                4: $post_query = false, 5: $timeout = false, 6: $timestamp = 0, 7: $useragent = false*/) {
                global $fetch_last_error_code;
                global $fetch_last_error_content;
                global $fetch_last_content_type;
+               global $fetch_last_modified;
                global $fetch_curl_used;
 
                $fetch_last_error = false;
                $fetch_last_error_content = "";
                $fetch_last_content_type = "";
                $fetch_curl_used = false;
+               $fetch_last_modified = "";
 
                if (!is_array($options)) {
 
                        // falling back on compatibility shim
-                       $option_names = [ "url", "type", "login", "pass", "post_query", "timeout", "timestamp", "useragent" ];
+                       $option_names = [ "url", "type", "login", "pass", "post_query", "timeout", "last_modified", "useragent" ];
                        $tmp = [];
 
                        for ($i = 0; $i < func_num_args(); $i++) {
                $pass = isset($options["pass"]) ? $options["pass"] : false;
                $post_query = isset($options["post_query"]) ? $options["post_query"] : false;
                $timeout = isset($options["timeout"]) ? $options["timeout"] : false;
-               $timestamp = isset($options["timestamp"]) ? $options["timestamp"] : 0;
+               $last_modified = isset($options["last_modified"]) ? $options["last_modified"] : "";
                $useragent = isset($options["useragent"]) ? $options["useragent"] : false;
                $followlocation = isset($options["followlocation"]) ? $options["followlocation"] : true;
 
 
                        $ch = curl_init($url);
 
-                       if ($timestamp && !$post_query) {
+                       if ($last_modified && !$post_query) {
                                curl_setopt($ch, CURLOPT_HTTPHEADER,
-                                       array("If-Modified-Since: ".gmdate('D, d M Y H:i:s \G\M\T', $timestamp)));
+                                       array("If-Modified-Since: $last_modified"));
                        }
 
                        curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, $timeout ? $timeout : FILE_FETCH_CONNECT_TIMEOUT);
                        curl_setopt($ch, CURLOPT_MAXREDIRS, 20);
                        curl_setopt($ch, CURLOPT_BINARYTRANSFER, true);
                        curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
+                       curl_setopt($ch, CURLOPT_HEADER, true);
                        curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_ANY);
                        curl_setopt($ch, CURLOPT_USERAGENT, $useragent ? $useragent :
                                SELF_USER_AGENT);
                        if ($login && $pass)
                                curl_setopt($ch, CURLOPT_USERPWD, "$login:$pass");
 
-                       $contents = @curl_exec($ch);
+                       $ret = @curl_exec($ch);
+
+                       $headers_length = curl_getinfo($ch, CURLINFO_HEADER_SIZE);
+                       $headers = explode("\r\n", substr($ret, 0, $headers_length));
+                       $contents = substr($ret, $headers_length);
+
+                       foreach ($headers as $header) {
+                if (strstr($header, ": ") !== FALSE) {
+                    list ($key, $value) = explode(": ", $header);
+
+                    if (strtolower($key) == "last-modified") {
+                        $fetch_last_modified = $value;
+                    }
+                }
+
+                if (substr(strtolower($header), 0, 7) == 'http/1.') {
+                    $fetch_last_error_code = (int) substr($header, 9, 3);
+                    $fetch_last_error = $header;
+                }
+                       }
 
                        if (curl_errno($ch) === 23 || curl_errno($ch) === 61) {
                                curl_setopt($ch, CURLOPT_ENCODING, 'none');
                                $contents = @curl_exec($ch);
                        }
 
-                       if ($contents === false) {
-                               $fetch_last_error = curl_errno($ch) . " " . curl_error($ch);
-                               curl_close($ch);
-                               return false;
-                       }
-
                        $http_code = curl_getinfo($ch, CURLINFO_HTTP_CODE);
                        $fetch_last_content_type = curl_getinfo($ch, CURLINFO_CONTENT_TYPE);
 
                        $fetch_last_error_code = $http_code;
 
                        if ($http_code != 200 || $type && strpos($fetch_last_content_type, "$type") === false) {
+
                                if (curl_errno($ch) != 0) {
-                                       $fetch_last_error = curl_errno($ch) . " " . curl_error($ch);
-                               } else {
-                                       $fetch_last_error = "HTTP Code: $http_code";
+                                       $fetch_last_error .=  "; " . curl_errno($ch) . " " . curl_error($ch);
                                }
+
                                $fetch_last_error_content = $contents;
                                curl_close($ch);
                                return false;
                        }
 
+                       if (!$contents) {
+                               $fetch_last_error = curl_errno($ch) . " " . curl_error($ch);
+                               curl_close($ch);
+                               return false;
+                       }
+
                        curl_close($ch);
 
                        return $contents;
 
                        // TODO: should this support POST requests or not? idk
 
-                       if (!$post_query && $timestamp) {
+                       if (!$post_query && $last_modified) {
                                 $context = stream_context_create(array(
                                          'http' => array(
                                                        'method' => 'GET',
                                                    'ignore_errors' => true,
                                                    'timeout' => $timeout ? $timeout : FILE_FETCH_TIMEOUT,
                                                        'protocol_version'=> 1.1,
-                                                       'header' => "If-Modified-Since: ".gmdate("D, d M Y H:i:s \\G\\M\\T\r\n", $timestamp)
-                                         )));
+                                                       'header' => "If-Modified-Since: $last_modified\r\n")
+                                         ));
                        } else {
                                 $context = stream_context_create(array(
                                          'http' => array(
                        $data = @file_get_contents($url, false, $context);
 
                        if (isset($http_response_header) && is_array($http_response_header)) {
-                               foreach ($http_response_header as $h) {
-                                       if (substr(strtolower($h), 0, 13) == 'content-type:') {
-                                               $fetch_last_content_type = substr($h, 14);
-                                               // don't abort here b/c there might be more than one
-                                               // e.g. if we were being redirected -- last one is the right one
-                                       }
-
-                                       if (substr(strtolower($h), 0, 7) == 'http/1.') {
-                                               $fetch_last_error_code = (int) substr($h, 9, 3);
+                               foreach ($http_response_header as $header) {
+                                   if (strstr($header, ": ") !== FALSE) {
+                        list ($key, $value) = explode(": ", $header);
+
+                        $key = strtolower($key);
+
+                        if ($key == 'content-type') {
+                            $fetch_last_content_type = $value;
+                            // don't abort here b/c there might be more than one
+                            // e.g. if we were being redirected -- last one is the right one
+                        } else if ($key == 'last-modified') {
+                            $fetch_last_modified = $value;
+                        }
+                    }
+
+                                       if (substr(strtolower($header), 0, 7) == 'http/1.') {
+                                               $fetch_last_error_code = (int) substr($header, 9, 3);
+                                               $fetch_last_error = $header;
                                        }
                                }
                        }
                                $error = error_get_last();
 
                                if ($error['message'] != $old_error['message']) {
-                                       $fetch_last_error = $error["message"];
-                               } else {
-                                       $fetch_last_error = "HTTP Code: $fetch_last_error_code";
+                                       $fetch_last_error .= "; " . $error["message"];
                                }
 
                                $fetch_last_error_content = $data;
                        $doc->loadHTML($html);
                        $xpath = new DOMXPath($doc);
 
-                       $base = $xpath->query('/html/head/base');
+                       $base = $xpath->query('/html/head/base[@href]');
                        foreach ($base as $b) {
-                               $url = $b->getAttribute("href");
+                               $url = rewrite_relative_url($url, $b->getAttribute("href"));
                                break;
                        }
 
                return $favicon_url;
        } // function get_favicon_url
 
-       function check_feed_favicon($site_url, $feed) {
-#              print "FAVICON [$site_url]: $favicon_url\n";
-
-               $icon_file = ICONS_DIR . "/$feed.ico";
-
-               if (!file_exists($icon_file)) {
-                       $favicon_url = get_favicon_url($site_url);
-
-                       if ($favicon_url) {
-                               // Limiting to "image" type misses those served with text/plain
-                               $contents = fetch_file_contents($favicon_url); // , "image");
-
-                               if ($contents) {
-                                       // Crude image type matching.
-                                       // Patterns gleaned from the file(1) source code.
-                                       if (preg_match('/^\x00\x00\x01\x00/', $contents)) {
-                                               // 0       string  \000\000\001\000        MS Windows icon resource
-                                               //error_log("check_feed_favicon: favicon_url=$favicon_url isa MS Windows icon resource");
-                                       }
-                                       elseif (preg_match('/^GIF8/', $contents)) {
-                                               // 0       string          GIF8            GIF image data
-                                               //error_log("check_feed_favicon: favicon_url=$favicon_url isa GIF image");
-                                       }
-                                       elseif (preg_match('/^\x89PNG\x0d\x0a\x1a\x0a/', $contents)) {
-                                               // 0       string          \x89PNG\x0d\x0a\x1a\x0a         PNG image data
-                                               //error_log("check_feed_favicon: favicon_url=$favicon_url isa PNG image");
-                                       }
-                                       elseif (preg_match('/^\xff\xd8/', $contents)) {
-                                               // 0       beshort         0xffd8          JPEG image data
-                                               //error_log("check_feed_favicon: favicon_url=$favicon_url isa JPG image");
-                                       }
-                                       else {
-                                               //error_log("check_feed_favicon: favicon_url=$favicon_url isa UNKNOWN type");
-                                               $contents = "";
-                                       }
-                               }
-
-                               if ($contents) {
-                                       $fp = @fopen($icon_file, "w");
-
-                                       if ($fp) {
-                                               fwrite($fp, $contents);
-                                               fclose($fp);
-                                               chmod($icon_file, 0644);
-                                       }
-                               }
-                       }
-            return $icon_file;
-               }
-       }
-
-       function print_select($id, $default, $values, $attributes = "", $name = "") {
-               if (!$name) $name = $id;
-
-               print "<select name=\"$name\" id=\"$id\" $attributes>";
-               foreach ($values as $v) {
-                       if ($v == $default)
-                               $sel = "selected=\"1\"";
-                        else
-                               $sel = "";
-
-                       $v = trim($v);
-
-                       print "<option value=\"$v\" $sel>$v</option>";
-               }
-               print "</select>";
-       }
-
-       function print_select_hash($id, $default, $values, $attributes = "", $name = "") {
-               if (!$name) $name = $id;
-
-               print "<select name=\"$name\" id='$id' $attributes>";
-               foreach (array_keys($values) as $v) {
-                       if ($v == $default)
-                               $sel = 'selected="selected"';
-                        else
-                               $sel = "";
-
-                       $v = trim($v);
-
-                       print "<option $sel value=\"$v\">".$values[$v]."</option>";
-               }
-
-               print "</select>";
-       }
-
-       function print_hidden($name, $value) {
-               print "<input dojoType=\"dijit.form.TextBox\" style=\"display : none\" name=\"$name\" value=\"$value\">";
-       }
-
-       function print_checkbox($id, $checked, $value = "", $attributes = "") {
-               $checked_str = $checked ? "checked" : "";
-               $value_str = $value ? "value=\"$value\"" : "";
-
-               print "<input dojoType=\"dijit.form.CheckBox\" id=\"$id\" $value_str $checked_str $attributes name=\"$id\">";
-       }
-
-       function print_button($type, $value, $attributes = "") {
-               print "<p><button dojoType=\"dijit.form.Button\" $attributes type=\"$type\">$value</button>";
-       }
-
-       function print_radio($id, $default, $true_is, $values, $attributes = "") {
-               foreach ($values as $v) {
-
-                       if ($v == $default)
-                               $sel = "checked";
-                        else
-                               $sel = "";
-
-                       if ($v == $true_is) {
-                               $sel .= " value=\"1\"";
-                       } else {
-                               $sel .= " value=\"0\"";
-                       }
-
-                       print "<input class=\"noborder\" dojoType=\"dijit.form.RadioButton\"
-                               type=\"radio\" $sel $attributes name=\"$id\">&nbsp;$v&nbsp;";
-
-               }
-       }
-
        function initialize_user_prefs($uid, $profile = false) {
 
-               $uid = db_escape_string($uid);
+               if (get_schema_version() < 63) $profile_qpart = "";
 
-               if (!$profile) {
-                       $profile = "NULL";
-                       $profile_qpart = "AND profile IS NULL";
-               } else {
-                       $profile_qpart = "AND profile = '$profile'";
-               }
+        $pdo = DB::pdo();
+        $in_nested_tr = false;
 
-               if (get_schema_version() < 63) $profile_qpart = "";
+        try {
+                       $pdo->beginTransaction();
+               } catch (Exception $e) {
+               $in_nested_tr = true;
+               }
 
-               db_query("BEGIN");
+               $sth = $pdo->query("SELECT pref_name,def_value FROM ttrss_prefs");
 
-               $result = db_query("SELECT pref_name,def_value FROM ttrss_prefs");
+        $profile = $profile ? $profile : null;
 
-               $u_result = db_query("SELECT pref_name
-                       FROM ttrss_user_prefs WHERE owner_uid = '$uid' $profile_qpart");
+               $u_sth = $pdo->prepare("SELECT pref_name
+                       FROM ttrss_user_prefs WHERE owner_uid = :uid AND 
+                               (profile = :profile OR (:profile IS NULL AND profile IS NULL))");
+               $u_sth->execute([':uid' => $uid, ':profile' => $profile]);
 
                $active_prefs = array();
 
-               while ($line = db_fetch_assoc($u_result)) {
+               while ($line = $u_sth->fetch()) {
                        array_push($active_prefs, $line["pref_name"]);
                }
 
-               while ($line = db_fetch_assoc($result)) {
+               while ($line = $sth->fetch()) {
                        if (array_search($line["pref_name"], $active_prefs) === FALSE) {
 //                             print "adding " . $line["pref_name"] . "<br>";
 
-                               $line["def_value"] = db_escape_string($line["def_value"]);
-                               $line["pref_name"] = db_escape_string($line["pref_name"]);
-
                                if (get_schema_version() < 63) {
-                                       db_query("INSERT INTO ttrss_user_prefs
+                                       $i_sth = $pdo->prepare("INSERT INTO ttrss_user_prefs
                                                (owner_uid,pref_name,value) VALUES
-                                               ('$uid', '".$line["pref_name"]."','".$line["def_value"]."')");
+                                               (?, ?, ?)");
+                                       $i_sth->execute([$uid, $line["pref_name"], $line["def_value"]]);
 
                                } else {
-                                       db_query("INSERT INTO ttrss_user_prefs
+                                       $i_sth = $pdo->prepare("INSERT INTO ttrss_user_prefs
                                                (owner_uid,pref_name,value, profile) VALUES
-                                               ('$uid', '".$line["pref_name"]."','".$line["def_value"]."', $profile)");
+                                               (?, ?, ?, ?)");
+                    $i_sth->execute([$uid, $line["pref_name"], $line["def_value"], $profile]);
                                }
 
                        }
                }
 
-               db_query("COMMIT");
+               if (!$in_nested_tr) $pdo->commit();
 
        }
 
                                $_SESSION["uid"] = $user_id;
                                $_SESSION["version"] = VERSION_STATIC;
 
-                               $result = db_query("SELECT login,access_level,pwd_hash FROM ttrss_users
-                                       WHERE id = '$user_id'");
+                               $pdo = DB::pdo();
+                               $sth = $pdo->prepare("SELECT login,access_level,pwd_hash FROM ttrss_users
+                                       WHERE id = ?");
+                               $sth->execute([$user_id]);
+                               $row = $sth->fetch();
 
-                               $_SESSION["name"] = db_fetch_result($result, 0, "login");
-                               $_SESSION["access_level"] = db_fetch_result($result, 0, "access_level");
+                               $_SESSION["name"] = $row["login"];
+                               $_SESSION["access_level"] = $row["access_level"];
                                $_SESSION["csrf_token"] = uniqid_short();
 
-                               db_query("UPDATE ttrss_users SET last_login = NOW() WHERE id = " .
-                                       $_SESSION["uid"]);
+                               $usth = $pdo->prepare("UPDATE ttrss_users SET last_login = NOW() WHERE id = ?");
+                               $usth->execute([$user_id]);
 
                                $_SESSION["ip_address"] = $_SERVER["REMOTE_ADDR"];
                                $_SESSION["user_agent"] = sha1($_SERVER['HTTP_USER_AGENT']);
-                               $_SESSION["pwd_hash"] = db_fetch_result($result, 0, "pwd_hash");
+                               $_SESSION["pwd_hash"] = $row["pwd_hash"];
 
                                $_SESSION["last_version_check"] = time();
 
                }
        }
 
+       // this is used for user http parameters unless HTML code is actually needed
+       function clean($param) {
+               if (is_array($param)) {
+                       return array_map(strip_tags, $param);
+               } else if (is_string($param)) {
+                       return strip_tags($param);
+               } else {
+                       return $param;
+               }
+       }
+
        function make_password($length = 8) {
 
                $password = "";
 
        function initialize_user($uid) {
 
-               db_query("insert into ttrss_feeds (owner_uid,title,feed_url)
-                       values ('$uid', 'Tiny Tiny RSS: Forum',
+           $pdo = DB::pdo();
+
+               $sth = $pdo->prepare("insert into ttrss_feeds (owner_uid,title,feed_url)
+                       values (?, 'Tiny Tiny RSS: Forum',
                                'http://tt-rss.org/forum/rss.php')");
+               $sth->execute([$uid]);
        }
 
        function logout_user() {
        }
 
        function login_sequence() {
+        $pdo = Db::pdo();
+
                if (SINGLE_USER_MODE) {
                        @session_start();
                        authenticate_user("admin", null);
 
                        } else {
                                /* bump login timestamp */
-                               db_query("UPDATE ttrss_users SET last_login = NOW() WHERE id = " .
-                                       $_SESSION["uid"]);
+                               $sth = $pdo->prepare("UPDATE ttrss_users SET last_login = NOW() WHERE id = ?");
+                               $sth->execute([$_SESSION['uid']]);
+
                                $_SESSION["last_login_update"] = time();
                        }
 
 
                                /* cleanup ccache */
 
-                               db_query("DELETE FROM ttrss_counters_cache WHERE owner_uid = ".
-                                       $_SESSION["uid"] . " AND
+                               $sth = $pdo->prepare("DELETE FROM ttrss_counters_cache WHERE owner_uid = ? 
+                    AND
                                                (SELECT COUNT(id) FROM ttrss_feeds WHERE
                                                        ttrss_feeds.id = feed_id) = 0");
 
-                               db_query("DELETE FROM ttrss_cat_counters_cache WHERE owner_uid = ".
-                                       $_SESSION["uid"] . " AND
+                               $sth->execute([$_SESSION['uid']]);
+
+                               $sth = $pdo->prepare("DELETE FROM ttrss_cat_counters_cache WHERE owner_uid = ? 
+                    AND
                                                (SELECT COUNT(id) FROM ttrss_feed_categories WHERE
                                                        ttrss_feed_categories.id = feed_id) = 0");
 
+                $sth->execute([$_SESSION['uid']]);
                        }
 
                }
        }
 
        function sql_bool_to_bool($s) {
-               if ($s == "t" || $s == "1" || strtolower($s) == "true") {
-                       return true;
-               } else {
-                       return false;
-               }
+               return $s && ($s !== "f" && $s !== "false"); //no-op for PDO, backwards compat for legacy layer
        }
 
        function bool_to_sql_bool($s) {
-               if ($s) {
-                       return "true";
-               } else {
-                       return "false";
-               }
+               return $s ? 1 : 0;
        }
 
        // Session caching removed due to causing wrong redirects to upgrade
        function get_schema_version($nocache = false) {
                global $schema_version;
 
+               $pdo = DB::pdo();
+
                if (!$schema_version && !$nocache) {
-                       $result = db_query("SELECT schema_version FROM ttrss_version");
-                       $version = db_fetch_result($result, 0, "schema_version");
+                       $row = $pdo->query("SELECT schema_version FROM ttrss_version")->fetch();
+                       $version = $row["schema_version"];
                        $schema_version = $version;
                        return $version;
                } else {
                        $error_code = 5;
                }
 
-               if (DB_TYPE == "mysql") {
-                       $result = db_query("SELECT true", false);
-                       if (db_num_rows($result) != 1) {
-                               $error_code = 10;
-                       }
-               }
-
-               if (db_escape_string("testTEST") != "testTEST") {
-                       $error_code = 12;
-               }
-
                return array("code" => $error_code, "message" => $ERRORS[$error_code]);
        }
 
                }
        }
 
-       function catchup_feed($feed, $cat_view, $owner_uid = false, $max_id = false, $mode = 'all', $search = false) {
+       function getFeedUnread($feed, $is_cat = false) {
+               return Feeds::getFeedArticles($feed, $is_cat, true, $_SESSION["uid"]);
+       }
 
-               if (!$owner_uid) $owner_uid = $_SESSION['uid'];
+       function checkbox_to_sql_bool($val) {
+               return ($val == "on") ? 1 : 0;
+       }
 
-               // Todo: all this interval stuff needs some generic generator function
+       function uniqid_short() {
+               return uniqid(base_convert(rand(), 10, 36));
+       }
 
-               $date_qpart = "false";
-               $search_qpart = is_array($search) && $search[0] ? search_to_sql($search[0], $search[1])[0] : 'true';
+       function make_init_params() {
+               $params = array();
 
-               switch ($mode) {
-               case "1day":
-                       if (DB_TYPE == "pgsql") {
-                               $date_qpart = "date_entered < NOW() - INTERVAL '1 day' ";
-                       } else {
-                               $date_qpart = "date_entered < DATE_SUB(NOW(), INTERVAL 1 DAY) ";
-                       }
-                       break;
-               case "1week":
-                       if (DB_TYPE == "pgsql") {
-                               $date_qpart = "date_entered < NOW() - INTERVAL '1 week' ";
-                       } else {
-                               $date_qpart = "date_entered < DATE_SUB(NOW(), INTERVAL 1 WEEK) ";
-                       }
-                       break;
-               case "2week":
-                       if (DB_TYPE == "pgsql") {
-                               $date_qpart = "date_entered < NOW() - INTERVAL '2 week' ";
-                       } else {
-                               $date_qpart = "date_entered < DATE_SUB(NOW(), INTERVAL 2 WEEK) ";
-                       }
-                       break;
-               default:
-                       $date_qpart = "true";
+               foreach (array("ON_CATCHUP_SHOW_NEXT_FEED", "HIDE_READ_FEEDS",
+                                        "ENABLE_FEED_CATS", "FEEDS_SORT_BY_UNREAD", "CONFIRM_FEED_CATCHUP",
+                                        "CDM_AUTO_CATCHUP", "FRESH_ARTICLE_MAX_AGE",
+                                        "HIDE_READ_SHOWS_SPECIAL", "COMBINED_DISPLAY_MODE") as $param) {
+
+                       $params[strtolower($param)] = (int) get_pref($param);
                }
 
-               if (is_numeric($feed)) {
-                       if ($cat_view) {
+               $params["icons_url"] = ICONS_URL;
+               $params["cookie_lifetime"] = SESSION_COOKIE_LIFETIME;
+               $params["default_view_mode"] = get_pref("_DEFAULT_VIEW_MODE");
+               $params["default_view_limit"] = (int) get_pref("_DEFAULT_VIEW_LIMIT");
+               $params["default_view_order_by"] = get_pref("_DEFAULT_VIEW_ORDER_BY");
+               $params["bw_limit"] = (int) $_SESSION["bw_limit"];
+               $params["is_default_pw"] = Pref_Prefs::isdefaultpassword();
+               $params["label_base_index"] = (int) LABEL_BASE_INDEX;
 
-                               if ($feed >= 0) {
+               $theme = get_pref( "USER_CSS_THEME", false, false);
+               $params["theme"] = theme_valid("$theme") ? $theme : "";
 
-                                       if ($feed > 0) {
-                                               $children = getChildCategories($feed, $owner_uid);
-                                               array_push($children, $feed);
+               $params["plugins"] = implode(", ", PluginHost::getInstance()->get_plugin_names());
 
-                                               $children = join(",", $children);
+               $params["php_platform"] = PHP_OS;
+               $params["php_version"] = PHP_VERSION;
 
-                                               $cat_qpart = "cat_id IN ($children)";
-                                       } else {
-                                               $cat_qpart = "cat_id IS NULL";
-                                       }
+               $params["sanity_checksum"] = sha1(file_get_contents("include/sanity_check.php"));
 
-                                       db_query("UPDATE ttrss_user_entries
-                                               SET unread = false, last_read = NOW() WHERE ref_id IN
-                                                       (SELECT id FROM
-                                                               (SELECT DISTINCT id FROM ttrss_entries, ttrss_user_entries WHERE ref_id = id
-                                                                       AND owner_uid = $owner_uid AND unread = true AND feed_id IN
-                                                                               (SELECT id FROM ttrss_feeds WHERE $cat_qpart) AND $date_qpart AND $search_qpart) as tmp)");
+               $pdo = Db::pdo();
 
-                               } else if ($feed == -2) {
+               $sth = $pdo->prepare("SELECT MAX(id) AS mid, COUNT(*) AS nf FROM
+                               ttrss_feeds WHERE owner_uid = ?");
+               $sth->execute([$_SESSION['uid']]);
+               $row = $sth->fetch();
 
-                                       db_query("UPDATE ttrss_user_entries
-                                               SET unread = false,last_read = NOW() WHERE (SELECT COUNT(*)
-                                                       FROM ttrss_user_labels2, ttrss_entries WHERE article_id = ref_id AND id = ref_id AND $date_qpart AND $search_qpart) > 0
-                                                       AND unread = true AND owner_uid = $owner_uid");
-                               }
+               $max_feed_id = $row["mid"];
+               $num_feeds = $row["nf"];
 
-                       } else if ($feed > 0) {
+               $params["max_feed_id"] = (int) $max_feed_id;
+               $params["num_feeds"] = (int) $num_feeds;
 
-                               db_query("UPDATE ttrss_user_entries
-                                       SET unread = false, last_read = NOW() WHERE ref_id IN
-                                               (SELECT id FROM
-                                                       (SELECT DISTINCT id FROM ttrss_entries, ttrss_user_entries WHERE ref_id = id
-                                                               AND owner_uid = $owner_uid AND unread = true AND feed_id = $feed AND $date_qpart AND $search_qpart) as tmp)");
+               $params["hotkeys"] = get_hotkeys_map();
 
-                       } else if ($feed < 0 && $feed > LABEL_BASE_INDEX) { // special, like starred
+               $params["csrf_token"] = $_SESSION["csrf_token"];
+               $params["widescreen"] = (int) $_COOKIE["ttrss_widescreen"];
 
-                               if ($feed == -1) {
-                                       db_query("UPDATE ttrss_user_entries
-                                               SET unread = false, last_read = NOW() WHERE ref_id IN
-                                                       (SELECT id FROM
-                                                               (SELECT DISTINCT id FROM ttrss_entries, ttrss_user_entries WHERE ref_id = id
-                                                                       AND owner_uid = $owner_uid AND unread = true AND marked = true AND $date_qpart AND $search_qpart) as tmp)");
-                               }
+               $params['simple_update'] = defined('SIMPLE_UPDATE_MODE') && SIMPLE_UPDATE_MODE;
 
-                               if ($feed == -2) {
-                                       db_query("UPDATE ttrss_user_entries
-                                               SET unread = false, last_read = NOW() WHERE ref_id IN
-                                                       (SELECT id FROM
-                                                               (SELECT DISTINCT id FROM ttrss_entries, ttrss_user_entries WHERE ref_id = id
-                                                                       AND owner_uid = $owner_uid AND unread = true AND published = true AND $date_qpart AND $search_qpart) as tmp)");
-                               }
+               $params["icon_alert"] = base64_img("images/alert.png");
+               $params["icon_information"] = base64_img("images/information.png");
+               $params["icon_cross"] = base64_img("images/cross.png");
+               $params["icon_indicator_white"] = base64_img("images/indicator_white.gif");
 
-                               if ($feed == -3) {
+               $params["labels"] = Labels::get_all_labels($_SESSION["uid"]);
 
-                                       $intl = get_pref("FRESH_ARTICLE_MAX_AGE");
+               return $params;
+       }
 
-                                       if (DB_TYPE == "pgsql") {
-                                               $match_part = "date_entered > NOW() - INTERVAL '$intl hour' ";
-                                       } else {
-                                               $match_part = "date_entered > DATE_SUB(NOW(),
-                                                       INTERVAL $intl HOUR) ";
-                                       }
+       function get_hotkeys_info() {
+               $hotkeys = array(
+                       __("Navigation") => array(
+                               "next_feed" => __("Open next feed"),
+                               "prev_feed" => __("Open previous feed"),
+                               "next_article" => __("Open next article"),
+                               "prev_article" => __("Open previous article"),
+                               "next_article_noscroll" => __("Open next article (don't scroll long articles)"),
+                               "prev_article_noscroll" => __("Open previous article (don't scroll long articles)"),
+                               "next_article_noexpand" => __("Move to next article (don't expand or mark read)"),
+                               "prev_article_noexpand" => __("Move to previous article (don't expand or mark read)"),
+                               "search_dialog" => __("Show search dialog")),
+                       __("Article") => array(
+                               "toggle_mark" => __("Toggle starred"),
+                               "toggle_publ" => __("Toggle published"),
+                               "toggle_unread" => __("Toggle unread"),
+                               "edit_tags" => __("Edit tags"),
+                               "open_in_new_window" => __("Open in new window"),
+                               "catchup_below" => __("Mark below as read"),
+                               "catchup_above" => __("Mark above as read"),
+                               "article_scroll_down" => __("Scroll down"),
+                               "article_scroll_up" => __("Scroll up"),
+                               "select_article_cursor" => __("Select article under cursor"),
+                               "email_article" => __("Email article"),
+                               "close_article" => __("Close/collapse article"),
+                               "toggle_expand" => __("Toggle article expansion (combined mode)"),
+                               "toggle_widescreen" => __("Toggle widescreen mode"),
+                               "toggle_embed_original" => __("Toggle embed original")),
+                       __("Article selection") => array(
+                               "select_all" => __("Select all articles"),
+                               "select_unread" => __("Select unread"),
+                               "select_marked" => __("Select starred"),
+                               "select_published" => __("Select published"),
+                               "select_invert" => __("Invert selection"),
+                               "select_none" => __("Deselect everything")),
+                       __("Feed") => array(
+                               "feed_refresh" => __("Refresh current feed"),
+                               "feed_unhide_read" => __("Un/hide read feeds"),
+                               "feed_subscribe" => __("Subscribe to feed"),
+                               "feed_edit" => __("Edit feed"),
+                               "feed_catchup" => __("Mark as read"),
+                               "feed_reverse" => __("Reverse headlines"),
+                               "feed_toggle_vgroup" => __("Toggle headline grouping"),
+                               "feed_debug_update" => __("Debug feed update"),
+                               "feed_debug_viewfeed" => __("Debug viewfeed()"),
+                               "catchup_all" => __("Mark all feeds as read"),
+                               "cat_toggle_collapse" => __("Un/collapse current category"),
+                               "toggle_combined_mode" => __("Toggle combined mode"),
+                               "toggle_cdm_expanded" => __("Toggle auto expand in combined mode")),
+                       __("Go to") => array(
+                               "goto_all" => __("All articles"),
+                               "goto_fresh" => __("Fresh"),
+                               "goto_marked" => __("Starred"),
+                               "goto_published" => __("Published"),
+                               "goto_tagcloud" => __("Tag cloud"),
+                               "goto_prefs" => __("Preferences")),
+                       __("Other") => array(
+                               "create_label" => __("Create label"),
+                               "create_filter" => __("Create filter"),
+                               "collapse_sidebar" => __("Un/collapse sidebar"),
+                               "help_dialog" => __("Show help dialog"))
+               );
+
+               foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_HOTKEY_INFO) as $plugin) {
+                       $hotkeys = $plugin->hook_hotkey_info($hotkeys);
+               }
+
+               return $hotkeys;
+       }
 
-                                       db_query("UPDATE ttrss_user_entries
-                                               SET unread = false, last_read = NOW() WHERE ref_id IN
-                                                       (SELECT id FROM
-                                                               (SELECT DISTINCT id FROM ttrss_entries, ttrss_user_entries WHERE ref_id = id
-                                                                       AND owner_uid = $owner_uid AND score >= 0 AND unread = true AND $date_qpart AND $match_part AND $search_qpart) as tmp)");
-                               }
+       function get_hotkeys_map() {
+               $hotkeys = array(
+       //                      "navigation" => array(
+                       "k" => "next_feed",
+                       "j" => "prev_feed",
+                       "n" => "next_article",
+                       "p" => "prev_article",
+                       "(38)|up" => "prev_article",
+                       "(40)|down" => "next_article",
+       //                              "^(38)|Ctrl-up" => "prev_article_noscroll",
+       //                              "^(40)|Ctrl-down" => "next_article_noscroll",
+                       "(191)|/" => "search_dialog",
+       //                      "article" => array(
+                       "s" => "toggle_mark",
+                       "*s" => "toggle_publ",
+                       "u" => "toggle_unread",
+                       "*t" => "edit_tags",
+                       "o" => "open_in_new_window",
+                       "c p" => "catchup_below",
+                       "c n" => "catchup_above",
+                       "*n" => "article_scroll_down",
+                       "*p" => "article_scroll_up",
+                       "*(38)|Shift+up" => "article_scroll_up",
+                       "*(40)|Shift+down" => "article_scroll_down",
+                       "a *w" => "toggle_widescreen",
+                       "a e" => "toggle_embed_original",
+                       "e" => "email_article",
+                       "a q" => "close_article",
+       //                      "article_selection" => array(
+                       "a a" => "select_all",
+                       "a u" => "select_unread",
+                       "a *u" => "select_marked",
+                       "a p" => "select_published",
+                       "a i" => "select_invert",
+                       "a n" => "select_none",
+       //                      "feed" => array(
+                       "f r" => "feed_refresh",
+                       "f a" => "feed_unhide_read",
+                       "f s" => "feed_subscribe",
+                       "f e" => "feed_edit",
+                       "f q" => "feed_catchup",
+                       "f x" => "feed_reverse",
+                       "f g" => "feed_toggle_vgroup",
+                       "f *d" => "feed_debug_update",
+                       "f *g" => "feed_debug_viewfeed",
+                       "f *c" => "toggle_combined_mode",
+                       "f c" => "toggle_cdm_expanded",
+                       "*q" => "catchup_all",
+                       "x" => "cat_toggle_collapse",
+       //                      "goto" => array(
+                       "g a" => "goto_all",
+                       "g f" => "goto_fresh",
+                       "g s" => "goto_marked",
+                       "g p" => "goto_published",
+                       "g t" => "goto_tagcloud",
+                       "g *p" => "goto_prefs",
+       //                      "other" => array(
+                       "(9)|Tab" => "select_article_cursor", // tab
+                       "c l" => "create_label",
+                       "c f" => "create_filter",
+                       "c s" => "collapse_sidebar",
+                       "^(191)|Ctrl+/" => "help_dialog",
+               );
+
+               if (get_pref('COMBINED_DISPLAY_MODE')) {
+                       $hotkeys["^(38)|Ctrl-up"] = "prev_article_noscroll";
+                       $hotkeys["^(40)|Ctrl-down"] = "next_article_noscroll";
+               }
+
+               foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_HOTKEY_MAP) as $plugin) {
+                       $hotkeys = $plugin->hook_hotkey_map($hotkeys);
+               }
+
+               $prefixes = array();
+
+               foreach (array_keys($hotkeys) as $hotkey) {
+                       $pair = explode(" ", $hotkey, 2);
+
+                       if (count($pair) > 1 && !in_array($pair[0], $prefixes)) {
+                               array_push($prefixes, $pair[0]);
+                       }
+               }
 
-                               if ($feed == -4) {
-                                       db_query("UPDATE ttrss_user_entries
-                                               SET unread = false, last_read = NOW() WHERE ref_id IN
-                                                       (SELECT id FROM
-                                                               (SELECT DISTINCT id FROM ttrss_entries, ttrss_user_entries WHERE ref_id = id
-                                                                       AND owner_uid = $owner_uid AND unread = true AND $date_qpart AND $search_qpart) as tmp)");
-                               }
+               return array($prefixes, $hotkeys);
+       }
 
-                       } else if ($feed < LABEL_BASE_INDEX) { // label
+       function check_for_update() {
+               if (defined("GIT_VERSION_TIMESTAMP")) {
+                       $content = @fetch_file_contents(array("url" => "http://tt-rss.org/version.json", "timeout" => 5));
 
-                               $label_id = feed_to_label_id($feed);
+                       if ($content) {
+                               $content = json_decode($content, true);
 
-                               db_query("UPDATE ttrss_user_entries
-                                       SET unread = false, last_read = NOW() WHERE ref_id IN
-                                               (SELECT id FROM
-                                                       (SELECT DISTINCT ttrss_entries.id FROM ttrss_entries, ttrss_user_entries, ttrss_user_labels2 WHERE ref_id = id
-                                                               AND label_id = '$label_id' AND ref_id = article_id
-                                                               AND owner_uid = $owner_uid AND unread = true AND $date_qpart AND $search_qpart) as tmp)");
+                               if ($content && isset($content["changeset"])) {
+                                       if ((int)GIT_VERSION_TIMESTAMP < (int)$content["changeset"]["timestamp"] &&
+                                               GIT_VERSION_HEAD != $content["changeset"]["id"]) {
 
+                                               return $content["changeset"]["id"];
+                                       }
+                               }
                        }
+               }
+
+               return "";
+       }
+
+       function make_runtime_info($disable_update_check = false) {
+               $data = array();
+
+               $pdo = Db::pdo();
 
-                       ccache_update($feed, $owner_uid, $cat_view);
+               $sth = $pdo->prepare("SELECT MAX(id) AS mid, COUNT(*) AS nf FROM
+                               ttrss_feeds WHERE owner_uid = ?");
+               $sth->execute([$_SESSION['uid']]);
+               $row = $sth->fetch();
 
-               } else { // tag
-                       db_query("UPDATE ttrss_user_entries
-                               SET unread = false, last_read = NOW() WHERE ref_id IN
-                                       (SELECT id FROM
-                                               (SELECT DISTINCT ttrss_entries.id FROM ttrss_entries, ttrss_user_entries, ttrss_tags WHERE ref_id = ttrss_entries.id
-                                                       AND post_int_id = int_id AND tag_name = '$feed'
-                                                       AND ttrss_user_entries.owner_uid = $owner_uid AND unread = true AND $date_qpart AND $search_qpart) as tmp)");
+               $max_feed_id = $row['mid'];
+               $num_feeds = $row['nf'];
 
+               $data["max_feed_id"] = (int) $max_feed_id;
+               $data["num_feeds"] = (int) $num_feeds;
+
+               $data['last_article_id'] = Article::getLastArticleId();
+               $data['cdm_expanded'] = get_pref('CDM_EXPANDED');
+
+               $data['dep_ts'] = calculate_dep_timestamp();
+               $data['reload_on_ts_change'] = !defined('_NO_RELOAD_ON_TS_CHANGE');
+
+               $data["labels"] = Labels::get_all_labels($_SESSION["uid"]);
+
+               if (CHECK_FOR_UPDATES && !$disable_update_check && $_SESSION["last_version_check"] + 86400 + rand(-1000, 1000) < time()) {
+                       $update_result = @check_for_update();
+
+                       $data["update_result"] = $update_result;
+
+                       $_SESSION["last_version_check"] = time();
                }
-       }
 
-       function getAllCounters() {
-               $data = getGlobalCounters();
+               if (file_exists(LOCK_DIRECTORY . "/update_daemon.lock")) {
+
+                       $data['daemon_is_running'] = (int) file_is_locked("update_daemon.lock");
+
+                       if (time() - $_SESSION["daemon_stamp_check"] > 30) {
+
+                               $stamp = (int) @file_get_contents(LOCK_DIRECTORY . "/update_daemon.stamp");
+
+                               if ($stamp) {
+                                       $stamp_delta = time() - $stamp;
+
+                                       if ($stamp_delta > 1800) {
+                                               $stamp_check = 0;
+                                       } else {
+                                               $stamp_check = 1;
+                                               $_SESSION["daemon_stamp_check"] = time();
+                                       }
+
+                                       $data['daemon_stamp_ok'] = $stamp_check;
+
+                                       $stamp_fmt = date("Y.m.d, G:i", $stamp);
 
-               $data = array_merge($data, getVirtCounters());
-               $data = array_merge($data, getLabelCounters());
-               $data = array_merge($data, getFeedCounters());
-               $data = array_merge($data, getCategoryCounters());
+                                       $data['daemon_stamp'] = $stamp_fmt;
+                               }
+                       }
+               }
 
                return $data;
        }
 
-       function getCategoryTitle($cat_id) {
+       function search_to_sql($search, $search_language) {
 
-               if ($cat_id == -1) {
-                       return __("Special");
-               } else if ($cat_id == -2) {
-                       return __("Labels");
-               } else {
+               $keywords = str_getcsv(trim($search), " ");
+               $query_keywords = array();
+               $search_words = array();
+               $search_query_leftover = array();
 
-                       $result = db_query("SELECT title FROM ttrss_feed_categories WHERE
-                               id = '$cat_id'");
+               $pdo = Db::pdo();
+               
+               if ($search_language)
+                       $search_language = $pdo->quote(mb_strtolower($search_language));
+               else
+                       $search_language = "english";
 
-                       if (db_num_rows($result) == 1) {
-                               return db_fetch_result($result, 0, "title");
+               foreach ($keywords as $k) {
+                       if (strpos($k, "-") === 0) {
+                               $k = substr($k, 1);
+                               $not = "NOT";
                        } else {
-                               return __("Uncategorized");
+                               $not = "";
                        }
-               }
-       }
 
+                       $commandpair = explode(":", mb_strtolower($k), 2);
 
-       function getCategoryCounters() {
-               $ret_arr = array();
+                       switch ($commandpair[0]) {
+                               case "title":
+                                       if ($commandpair[1]) {
+                                               array_push($query_keywords, "($not (LOWER(ttrss_entries.title) LIKE ".
+                                                       $pdo->quote('%' . mb_strtolower($commandpair[1]) . '%') ."))");
+                                       } else {
+                                               array_push($query_keywords, "(UPPER(ttrss_entries.title) $not LIKE UPPER('%$k%')
+                                                               OR UPPER(ttrss_entries.content) $not LIKE UPPER(".$pdo->quote("%$k%")."))");
+                                               array_push($search_words, $k);
+                                       }
+                                       break;
+                               case "author":
+                                       if ($commandpair[1]) {
+                                               array_push($query_keywords, "($not (LOWER(author) LIKE ".
+                                                       $pdo->quote('%' . mb_strtolower($commandpair[1]) . '%')."))");
+                                       } else {
+                                               array_push($query_keywords, "(UPPER(ttrss_entries.title) $not LIKE UPPER('%$k%')
+                                                               OR UPPER(ttrss_entries.content) $not LIKE UPPER(".$pdo->quote("%$k%")."))");
+                                               array_push($search_words, $k);
+                                       }
+                                       break;
+                               case "note":
+                                       if ($commandpair[1]) {
+                                               if ($commandpair[1] == "true")
+                                                       array_push($query_keywords, "($not (note IS NOT NULL AND note != ''))");
+                                               else if ($commandpair[1] == "false")
+                                                       array_push($query_keywords, "($not (note IS NULL OR note = ''))");
+                                               else
+                                                       array_push($query_keywords, "($not (LOWER(note) LIKE ".
+                                                               $pdo->quote('%' . mb_strtolower($commandpair[1]) . '%')."))");
+                                       } else {
+                                               array_push($query_keywords, "(UPPER(ttrss_entries.title) $not LIKE UPPER(".$pdo->quote("%$k%").")
+                                                               OR UPPER(ttrss_entries.content) $not LIKE UPPER(".$pdo->quote("%$k%")."))");
+                                               if (!$not) array_push($search_words, $k);
+                                       }
+                                       break;
+                               case "star":
 
-               /* Labels category */
+                                       if ($commandpair[1]) {
+                                               if ($commandpair[1] == "true")
+                                                       array_push($query_keywords, "($not (marked = true))");
+                                               else
+                                                       array_push($query_keywords, "($not (marked = false))");
+                                       } else {
+                                               array_push($query_keywords, "(UPPER(ttrss_entries.title) $not LIKE UPPER(".$pdo->quote("%$k%").")
+                                                               OR UPPER(ttrss_entries.content) $not LIKE UPPER(".$pdo->quote("%$k%")."))");
+                                               if (!$not) array_push($search_words, $k);
+                                       }
+                                       break;
+                               case "pub":
+                                       if ($commandpair[1]) {
+                                               if ($commandpair[1] == "true")
+                                                       array_push($query_keywords, "($not (published = true))");
+                                               else
+                                                       array_push($query_keywords, "($not (published = false))");
 
-               $cv = array("id" => -2, "kind" => "cat",
-                       "counter" => getCategoryUnread(-2));
+                                       } else {
+                                               array_push($query_keywords, "(UPPER(ttrss_entries.title) $not LIKE UPPER('%$k%')
+                                                               OR UPPER(ttrss_entries.content) $not LIKE UPPER(".$pdo->quote("%$k%")."))");
+                                               if (!$not) array_push($search_words, $k);
+                                       }
+                                       break;
+                               case "unread":
+                                       if ($commandpair[1]) {
+                                               if ($commandpair[1] == "true")
+                                                       array_push($query_keywords, "($not (unread = true))");
+                                               else
+                                                       array_push($query_keywords, "($not (unread = false))");
 
-               array_push($ret_arr, $cv);
+                                       } else {
+                                               array_push($query_keywords, "(UPPER(ttrss_entries.title) $not LIKE UPPER(".$pdo->quote("%$k%").")
+                                                               OR UPPER(ttrss_entries.content) $not LIKE UPPER(".$pdo->quote("%$k%")."))");
+                                               if (!$not) array_push($search_words, $k);
+                                       }
+                                       break;
+                               default:
+                                       if (strpos($k, "@") === 0) {
 
-               $result = db_query("SELECT id AS cat_id, value AS unread,
-                       (SELECT COUNT(id) FROM ttrss_feed_categories AS c2
-                               WHERE c2.parent_cat = ttrss_feed_categories.id) AS num_children
-                       FROM ttrss_feed_categories, ttrss_cat_counters_cache
-                       WHERE ttrss_cat_counters_cache.feed_id = id AND
-                       ttrss_cat_counters_cache.owner_uid = ttrss_feed_categories.owner_uid AND
-                       ttrss_feed_categories.owner_uid = " . $_SESSION["uid"]);
+                                               $user_tz_string = get_pref('USER_TIMEZONE', $_SESSION['uid']);
+                                               $orig_ts = strtotime(substr($k, 1));
+                                               $k = date("Y-m-d", convert_timestamp($orig_ts, $user_tz_string, 'UTC'));
 
-               while ($line = db_fetch_assoc($result)) {
-                       $line["cat_id"] = (int) $line["cat_id"];
+                                               //$k = date("Y-m-d", strtotime(substr($k, 1)));
 
-                       if ($line["num_children"] > 0) {
-                               $child_counter = getCategoryChildrenUnread($line["cat_id"], $_SESSION["uid"]);
-                       } else {
-                               $child_counter = 0;
-                       }
+                                               array_push($query_keywords, "(".SUBSTRING_FOR_DATE."(updated,1,LENGTH('$k')) $not = '$k')");
+                                       } else {
 
-                       $cv = array("id" => $line["cat_id"], "kind" => "cat",
-                               "counter" => $line["unread"] + $child_counter);
+                                               if (DB_TYPE == "pgsql") {
+                                                       $k = mb_strtolower($k);
+                                                       array_push($search_query_leftover, $not ? "!$k" : $k);
+                                               } else {
+                                                       array_push($query_keywords, "(UPPER(ttrss_entries.title) $not LIKE UPPER(".$pdo->quote("%$k%").")
+                                                               OR UPPER(ttrss_entries.content) $not LIKE UPPER(".$pdo->quote("%$k%")."))");
+                                               }
 
-                       array_push($ret_arr, $cv);
+                                               if (!$not) array_push($search_words, $k);
+                                       }
+                       }
                }
 
-               /* Special case: NULL category doesn't actually exist in the DB */
+               if (count($search_query_leftover) > 0) {
+                       $search_query_leftover = $pdo->quote(implode(" & ", $search_query_leftover));
+
+                       if (DB_TYPE == "pgsql") {
+                               array_push($query_keywords,
+                                       "(tsvector_combined @@ to_tsquery($search_language, $search_query_leftover))");
+                       }
 
-               $cv = array("id" => 0, "kind" => "cat",
-                       "counter" => (int) ccache_find(0, $_SESSION["uid"], true));
+               }
 
-               array_push($ret_arr, $cv);
+               $search_query_part = implode("AND", $query_keywords);
 
-               return $ret_arr;
+               return array($search_query_part, $search_words);
        }
 
-       // only accepts real cats (>= 0)
-       function getCategoryChildrenUnread($cat, $owner_uid = false) {
-               if (!$owner_uid) $owner_uid = $_SESSION["uid"];
-
-               $result = db_query("SELECT id FROM ttrss_feed_categories WHERE parent_cat = '$cat'
-                               AND owner_uid = $owner_uid");
+       function iframe_whitelisted($entry) {
+               $whitelist = array("youtube.com", "youtu.be", "vimeo.com", "player.vimeo.com");
 
-               $unread = 0;
+               @$src = parse_url($entry->getAttribute("src"), PHP_URL_HOST);
 
-               while ($line = db_fetch_assoc($result)) {
-                       $unread += getCategoryUnread($line["id"], $owner_uid);
-                       $unread += getCategoryChildrenUnread($line["id"], $owner_uid);
+               if ($src) {
+                       foreach ($whitelist as $w) {
+                               if ($src == $w || $src == "www.$w")
+                                       return true;
+                       }
                }
 
-               return $unread;
+               return false;
        }
 
-       function getCategoryUnread($cat, $owner_uid = false) {
+       function sanitize($str, $force_remove_images = false, $owner = false, $site_url = false, $highlight_words = false, $article_id = false) {
+               if (!$owner) $owner = $_SESSION["uid"];
 
-               if (!$owner_uid) $owner_uid = $_SESSION["uid"];
+               $res = trim($str); if (!$res) return '';
 
-               if ($cat >= 0) {
+               $charset_hack = '<head>
+                               <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
+                       </head>';
 
-                       if ($cat != 0) {
-                               $cat_query = "cat_id = '$cat'";
-                       } else {
-                               $cat_query = "cat_id IS NULL";
-                       }
+               $res = trim($res); if (!$res) return '';
 
-                       $result = db_query("SELECT id FROM ttrss_feeds WHERE $cat_query
-                                       AND owner_uid = " . $owner_uid);
+               libxml_use_internal_errors(true);
 
-                       $cat_feeds = array();
-                       while ($line = db_fetch_assoc($result)) {
-                               array_push($cat_feeds, "feed_id = " . $line["id"]);
-                       }
+               $doc = new DOMDocument();
+               $doc->loadHTML($charset_hack . $res);
+               $xpath = new DOMXPath($doc);
 
-                       if (count($cat_feeds) == 0) return 0;
+               $rewrite_base_url = $site_url ? $site_url : get_self_url_prefix();
 
-                       $match_part = implode(" OR ", $cat_feeds);
+               $entries = $xpath->query('(//a[@href]|//img[@src]|//video/source[@src]|//audio/source[@src])');
 
-                       $result = db_query("SELECT COUNT(int_id) AS unread
-                               FROM ttrss_user_entries
-                               WHERE   unread = true AND ($match_part)
-                               AND owner_uid = " . $owner_uid);
+               foreach ($entries as $entry) {
 
-                       $unread = 0;
+                       if ($entry->hasAttribute('href')) {
+                               $entry->setAttribute('href',
+                                       rewrite_relative_url($rewrite_base_url, $entry->getAttribute('href')));
 
-                       # this needs to be rewritten
-                       while ($line = db_fetch_assoc($result)) {
-                               $unread += $line["unread"];
+                               $entry->setAttribute('rel', 'noopener noreferrer');
                        }
 
-                       return $unread;
-               } else if ($cat == -1) {
-                       return getFeedUnread(-1) + getFeedUnread(-2) + getFeedUnread(-3) + getFeedUnread(0);
-               } else if ($cat == -2) {
-
-                       $result = db_query("
-                               SELECT COUNT(unread) AS unread FROM
-                                       ttrss_user_entries, ttrss_user_labels2
-                               WHERE article_id = ref_id AND unread = true
-                                       AND ttrss_user_entries.owner_uid = '$owner_uid'");
+                       if ($entry->hasAttribute('src')) {
+                               $src = rewrite_relative_url($rewrite_base_url, $entry->getAttribute('src'));
+                               $cached_filename = CACHE_DIR . '/images/' . sha1($src);
 
-                       $unread = db_fetch_result($result, 0, "unread");
+                               if (file_exists($cached_filename)) {
 
-                       return $unread;
+                                       // this is strictly cosmetic
+                                       if ($entry->tagName == 'img') {
+                                               $suffix = ".png";
+                                       } else if ($entry->parentNode && $entry->parentNode->tagName == "video") {
+                                               $suffix = ".mp4";
+                                       } else if ($entry->parentNode && $entry->parentNode->tagName == "audio") {
+                                               $suffix = ".ogg";
+                                       } else {
+                                               $suffix = "";
+                                       }
 
-               }
-       }
+                                       $src = get_self_url_prefix() . '/public.php?op=cached_url&hash=' . sha1($src) . $suffix;
 
-       function getFeedUnread($feed, $is_cat = false) {
-               return getFeedArticles($feed, $is_cat, true, $_SESSION["uid"]);
-       }
+                                       if ($entry->hasAttribute('srcset')) {
+                                               $entry->removeAttribute('srcset');
+                                       }
 
-       function getLabelUnread($label_id, $owner_uid = false) {
-               if (!$owner_uid) $owner_uid = $_SESSION["uid"];
+                                       if ($entry->hasAttribute('sizes')) {
+                                               $entry->removeAttribute('sizes');
+                                       }
+                               }
 
-               $result = db_query("SELECT COUNT(ref_id) AS unread FROM ttrss_user_entries, ttrss_user_labels2
-                       WHERE owner_uid = '$owner_uid' AND unread = true AND label_id = '$label_id' AND article_id = ref_id");
+                               $entry->setAttribute('src', $src);
+                       }
 
-               if (db_num_rows($result) != 0) {
-                       return db_fetch_result($result, 0, "unread");
-               } else {
-                       return 0;
-               }
-       }
+                       if ($entry->nodeName == 'img') {
+                               $entry->setAttribute('referrerpolicy', 'no-referrer');
 
-       function getFeedArticles($feed, $is_cat = false, $unread_only = false,
-               $owner_uid = false) {
+                               if ($entry->hasAttribute('src')) {
+                                       $is_https_url = parse_url($entry->getAttribute('src'), PHP_URL_SCHEME) === 'https';
 
-               $n_feed = (int) $feed;
-               $need_entries = false;
+                                       if (is_prefix_https() && !$is_https_url) {
 
-               if (!$owner_uid) $owner_uid = $_SESSION["uid"];
+                                               if ($entry->hasAttribute('srcset')) {
+                                                       $entry->removeAttribute('srcset');
+                                               }
 
-               if ($unread_only) {
-                       $unread_qpart = "unread = true";
-               } else {
-                       $unread_qpart = "true";
-               }
+                                               if ($entry->hasAttribute('sizes')) {
+                                                       $entry->removeAttribute('sizes');
+                                               }
+                                       }
+                               }
 
-               if ($is_cat) {
-                       return getCategoryUnread($n_feed, $owner_uid);
-               } else if ($n_feed == -6) {
-                       return 0;
-               } else if ($feed != "0" && $n_feed == 0) {
+                               if (($owner && get_pref("STRIP_IMAGES", $owner)) ||
+                                       $force_remove_images || $_SESSION["bw_limit"]) {
 
-                       $feed = db_escape_string($feed);
+                                       $p = $doc->createElement('p');
 
-                       $result = db_query("SELECT SUM((SELECT COUNT(int_id)
-                               FROM ttrss_user_entries,ttrss_entries WHERE int_id = post_int_id
-                                       AND ref_id = id AND $unread_qpart)) AS count FROM ttrss_tags
-                               WHERE owner_uid = $owner_uid AND tag_name = '$feed'");
-                       return db_fetch_result($result, 0, "count");
+                                       $a = $doc->createElement('a');
+                                       $a->setAttribute('href', $entry->getAttribute('src'));
 
-               } else if ($n_feed == -1) {
-                       $match_part = "marked = true";
-               } else if ($n_feed == -2) {
-                       $match_part = "published = true";
-               } else if ($n_feed == -3) {
-                       $match_part = "unread = true AND score >= 0";
+                                       $a->appendChild(new DOMText($entry->getAttribute('src')));
+                                       $a->setAttribute('target', '_blank');
+                                       $a->setAttribute('rel', 'noopener noreferrer');
 
-                       $intl = get_pref("FRESH_ARTICLE_MAX_AGE", $owner_uid);
+                                       $p->appendChild($a);
 
-                       if (DB_TYPE == "pgsql") {
-                               $match_part .= " AND date_entered > NOW() - INTERVAL '$intl hour' ";
-                       } else {
-                               $match_part .= " AND date_entered > DATE_SUB(NOW(), INTERVAL $intl HOUR) ";
+                                       $entry->parentNode->replaceChild($p, $entry);
+                               }
                        }
 
-                       $need_entries = true;
+                       if (strtolower($entry->nodeName) == "a") {
+                               $entry->setAttribute("target", "_blank");
+                               $entry->setAttribute("rel", "noopener noreferrer");
+                       }
+               }
 
-               } else if ($n_feed == -4) {
-                       $match_part = "true";
-               } else if ($n_feed >= 0) {
+               $entries = $xpath->query('//iframe');
+               foreach ($entries as $entry) {
+                       if (!iframe_whitelisted($entry)) {
+                               $entry->setAttribute('sandbox', 'allow-scripts');
+                       } else {
+                               if (is_prefix_https()) {
+                                       $entry->setAttribute("src",
+                                               str_replace("http://", "https://",
+                                                       $entry->getAttribute("src")));
+                               }
+                       }
+               }
 
-                       if ($n_feed != 0) {
-                               $match_part = "feed_id = '$n_feed'";
+               $allowed_elements = array('a', 'address', 'acronym', 'audio', 'article', 'aside',
+                       'b', 'bdi', 'bdo', 'big', 'blockquote', 'body', 'br',
+                       'caption', 'cite', 'center', 'code', 'col', 'colgroup',
+                       'data', 'dd', 'del', 'details', 'description', 'dfn', 'div', 'dl', 'font',
+                       'dt', 'em', 'footer', 'figure', 'figcaption',
+                       'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'header', 'hr', 'html', 'i',
+                       'img', 'ins', 'kbd', 'li', 'main', 'mark', 'nav', 'noscript',
+                       'ol', 'p', 'pre', 'q', 'ruby', 'rp', 'rt', 's', 'samp', 'section',
+                       'small', 'source', 'span', 'strike', 'strong', 'sub', 'summary',
+                       'sup', 'table', 'tbody', 'td', 'tfoot', 'th', 'thead', 'time',
+                       'tr', 'track', 'tt', 'u', 'ul', 'var', 'wbr', 'video', 'xml:namespace' );
+
+               if ($_SESSION['hasSandbox']) $allowed_elements[] = 'iframe';
+
+               $disallowed_attributes = array('id', 'style', 'class');
+
+               foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_SANITIZE) as $plugin) {
+                       $retval = $plugin->hook_sanitize($doc, $site_url, $allowed_elements, $disallowed_attributes, $article_id);
+                       if (is_array($retval)) {
+                               $doc = $retval[0];
+                               $allowed_elements = $retval[1];
+                               $disallowed_attributes = $retval[2];
                        } else {
-                               $match_part = "feed_id IS NULL";
+                               $doc = $retval;
                        }
+               }
 
-               } else if ($feed < LABEL_BASE_INDEX) {
+               $doc->removeChild($doc->firstChild); //remove doctype
+               $doc = strip_harmful_tags($doc, $allowed_elements, $disallowed_attributes);
 
-                       $label_id = feed_to_label_id($feed);
+               if ($highlight_words) {
+                       foreach ($highlight_words as $word) {
 
-                       return getLabelUnread($label_id, $owner_uid);
+                               // http://stackoverflow.com/questions/4081372/highlight-keywords-in-a-paragraph
 
+                               $elements = $xpath->query("//*/text()");
+
+                               foreach ($elements as $child) {
+
+                                       $fragment = $doc->createDocumentFragment();
+                                       $text = $child->textContent;
+
+                                       while (($pos = mb_stripos($text, $word)) !== false) {
+                                               $fragment->appendChild(new DomText(mb_substr($text, 0, $pos)));
+                                               $word = mb_substr($text, $pos, mb_strlen($word));
+                                               $highlight = $doc->createElement('span');
+                                               $highlight->appendChild(new DomText($word));
+                                               $highlight->setAttribute('class', 'highlight');
+                                               $fragment->appendChild($highlight);
+                                               $text = mb_substr($text, $pos + mb_strlen($word));
+                                       }
+
+                                       if (!empty($text)) $fragment->appendChild(new DomText($text));
+
+                                       $child->parentNode->replaceChild($fragment, $child);
+                               }
+                       }
                }
 
-               if ($match_part) {
+               $res = $doc->saveHTML();
 
-                       if ($need_entries) {
-                               $from_qpart = "ttrss_user_entries,ttrss_entries";
-                               $from_where = "ttrss_entries.id = ttrss_user_entries.ref_id AND";
-                       } else {
-                               $from_qpart = "ttrss_user_entries";
-                               $from_where = "";
+               /* strip everything outside of <body>...</body> */
+
+               $res_frag = array();
+               if (preg_match('/<body>(.*)<\/body>/is', $res, $res_frag)) {
+                       return $res_frag[1];
+               } else {
+                       return $res;
+               }
+       }
+
+       function strip_harmful_tags($doc, $allowed_elements, $disallowed_attributes) {
+               $xpath = new DOMXPath($doc);
+               $entries = $xpath->query('//*');
+
+               foreach ($entries as $entry) {
+                       if (!in_array($entry->nodeName, $allowed_elements)) {
+                               $entry->parentNode->removeChild($entry);
                        }
 
-                       $query = "SELECT count(int_id) AS unread
-                               FROM $from_qpart WHERE
-                               $unread_qpart AND $from_where ($match_part) AND ttrss_user_entries.owner_uid = $owner_uid";
+                       if ($entry->hasAttributes()) {
+                               $attrs_to_remove = array();
 
-                       //echo "[$feed/$query]\n";
+                               foreach ($entry->attributes as $attr) {
 
-                       $result = db_query($query);
+                                       if (strpos($attr->nodeName, 'on') === 0) {
+                                               array_push($attrs_to_remove, $attr);
+                                       }
 
-               } else {
+                                       if ($attr->nodeName == 'href' && stripos($attr->value, 'javascript:') === 0) {
+                                               array_push($attrs_to_remove, $attr);
+                                       }
+
+                                       if (in_array($attr->nodeName, $disallowed_attributes)) {
+                                               array_push($attrs_to_remove, $attr);
+                                       }
+                               }
 
-                       $result = db_query("SELECT COUNT(post_int_id) AS unread
-                               FROM ttrss_tags,ttrss_user_entries,ttrss_entries
-                               WHERE tag_name = '$feed' AND post_int_id = int_id AND ref_id = ttrss_entries.id
-                               AND $unread_qpart AND ttrss_tags.owner_uid = " . $owner_uid);
+                               foreach ($attrs_to_remove as $attr) {
+                                       $entry->removeAttributeNode($attr);
+                               }
+                       }
                }
 
-               $unread = db_fetch_result($result, 0, "unread");
+               return $doc;
+       }
+
+       function trim_array($array) {
+               $tmp = $array;
+               array_walk($tmp, 'trim');
+               return $tmp;
+       }
+
+       function tag_is_valid($tag) {
+               if ($tag == '') return false;
+               if (is_numeric($tag)) return false;
+               if (mb_strlen($tag) > 250) return false;
+
+               if (!$tag) return false;
+
+               return true;
+       }
+
+       function render_login_form() {
+               header('Cache-Control: public');
+
+               require_once "login_form.php";
+               exit;
+       }
+
+       function T_sprintf() {
+               $args = func_get_args();
+               return vsprintf(__(array_shift($args)), $args);
+       }
 
-               return $unread;
+       function print_checkpoint($n, $s) {
+               $ts = microtime(true);
+               echo sprintf("<!-- CP[$n] %.4f seconds -->\n", $ts - $s);
+               return $ts;
        }
 
-       function getGlobalUnread($user_id = false) {
+       function sanitize_tag($tag) {
+               $tag = trim($tag);
+
+               $tag = mb_strtolower($tag, 'utf-8');
 
-               if (!$user_id) {
-                       $user_id = $_SESSION["uid"];
+               $tag = preg_replace('/[,\'\"\+\>\<]/', "", $tag);
+
+               if (DB_TYPE == "mysql") {
+                       $tag = preg_replace('/[\x{10000}-\x{10FFFF}]/u', "\xEF\xBF\xBD", $tag);
                }
 
-               $result = db_query("SELECT SUM(value) AS c_id FROM ttrss_counters_cache
-                       WHERE owner_uid = '$user_id' AND feed_id > 0");
+               return $tag;
+       }
 
-               $c_id = db_fetch_result($result, 0, "c_id");
+       function is_server_https() {
+               return (!empty($_SERVER['HTTPS']) && ($_SERVER['HTTPS'] != 'off')) || $_SERVER['HTTP_X_FORWARDED_PROTO'] == 'https';
+       }
 
-               return $c_id;
+       function is_prefix_https() {
+               return parse_url(SELF_URL_PATH, PHP_URL_SCHEME) == 'https';
        }
 
-       function getGlobalCounters($global_unread = -1) {
-               $ret_arr = array();
+       // this returns SELF_URL_PATH sans ending slash
+       function get_self_url_prefix() {
+               if (strrpos(SELF_URL_PATH, "/") === strlen(SELF_URL_PATH)-1) {
+                       return substr(SELF_URL_PATH, 0, strlen(SELF_URL_PATH)-1);
+               } else {
+                       return SELF_URL_PATH;
+               }
+       }
 
-               if ($global_unread == -1) {
-                       $global_unread = getGlobalUnread();
+       function encrypt_password($pass, $salt = '', $mode2 = false) {
+               if ($salt && $mode2) {
+                       return "MODE2:" . hash('sha256', $salt . $pass);
+               } else if ($salt) {
+                       return "SHA1X:" . sha1("$salt:$pass");
+               } else {
+                       return "SHA1:" . sha1($pass);
                }
+       } // function encrypt_password
 
-               $cv = array("id" => "global-unread",
-                       "counter" => (int) $global_unread);
+       function load_filters($feed_id, $owner_uid) {
+               $filters = array();
 
-               array_push($ret_arr, $cv);
+               $feed_id = (int) $feed_id;
+               $cat_id = (int)Feeds::getFeedCategory($feed_id);
 
-               $result = db_query("SELECT COUNT(id) AS fn FROM
-                       ttrss_feeds WHERE owner_uid = " . $_SESSION["uid"]);
+               if ($cat_id == 0)
+                       $null_cat_qpart = "cat_id IS NULL OR";
+               else
+                       $null_cat_qpart = "";
 
-               $subscribed_feeds = db_fetch_result($result, 0, "fn");
+               $pdo = Db::pdo();
 
-               $cv = array("id" => "subscribed-feeds",
-                       "counter" => (int) $subscribed_feeds);
+               $sth = $pdo->prepare("SELECT * FROM ttrss_filters2 WHERE
+                               owner_uid = ? AND enabled = true ORDER BY order_id, title");
+               $sth->execute([$owner_uid]);
 
-               array_push($ret_arr, $cv);
+               $check_cats = array_merge(
+                       Feeds::getParentCategories($cat_id, $owner_uid),
+                       [$cat_id]);
 
-               return $ret_arr;
-       }
+               $check_cats_str = join(",", $check_cats);
+               $check_cats_fullids = array_map(function($a) { return "CAT:$a"; }, $check_cats);
 
-       function getVirtCounters() {
+               while ($line = $sth->fetch()) {
+                       $filter_id = $line["id"];
 
-               $ret_arr = array();
+            $match_any_rule = sql_bool_to_bool($line["match_any_rule"]);
 
-               for ($i = 0; $i >= -4; $i--) {
+                       $sth2 = $pdo->prepare("SELECT
+                                       r.reg_exp, r.inverse, r.feed_id, r.cat_id, r.cat_filter, r.match_on, t.name AS type_name
+                                       FROM ttrss_filters2_rules AS r,
+                                       ttrss_filter_types AS t
+                                       WHERE
+                                           (match_on IS NOT NULL OR
+                                                 (($null_cat_qpart (cat_id IS NULL AND cat_filter = false) OR cat_id IN ($check_cats_str)) AND
+                                                 (feed_id IS NULL OR feed_id = ?))) AND
+                                               filter_type = t.id AND filter_id = ?");
+                       $sth2->execute([$feed_id, $filter_id]);
 
-                       $count = getFeedUnread($i);
+                       $rules = array();
+                       $actions = array();
 
-                       if ($i == 0 || $i == -1 || $i == -2)
-                               $auxctr = getFeedArticles($i, false);
-                       else
-                               $auxctr = 0;
+                       while ($rule_line = $sth2->fetch()) {
+       #                               print_r($rule_line);
 
-                       $cv = array("id" => $i,
-                               "counter" => (int) $count,
-                               "auxcounter" => (int) $auxctr);
+                if ($rule_line["match_on"]) {
+                    $match_on = json_decode($rule_line["match_on"], true);
 
-//                     if (get_pref('EXTENDED_FEEDLIST'))
-//                             $cv["xmsg"] = getFeedArticles($i)." ".__("total");
+                    if (in_array("0", $match_on) || in_array($feed_id, $match_on) || count(array_intersect($check_cats_fullids, $match_on)) > 0) {
 
-                       array_push($ret_arr, $cv);
-               }
+                        $rule = array();
+                        $rule["reg_exp"] = $rule_line["reg_exp"];
+                        $rule["type"] = $rule_line["type_name"];
+                        $rule["inverse"] = sql_bool_to_bool($rule_line["inverse"]);
+
+                        array_push($rules, $rule);
+                    } else if (!$match_any_rule) {
+                        // this filter contains a rule that doesn't match to this feed/category combination
+                        // thus filter has to be rejected
+
+                        $rules = [];
+                        break;
+                    }
 
-               $feeds = PluginHost::getInstance()->get_feeds(-1);
+                } else {
 
-               if (is_array($feeds)) {
-                       foreach ($feeds as $feed) {
-                               $cv = array("id" => PluginHost::pfeed_to_feed_id($feed['id']),
-                                       "counter" => $feed['sender']->get_unread($feed['id']));
+                    $rule = array();
+                    $rule["reg_exp"] = $rule_line["reg_exp"];
+                    $rule["type"] = $rule_line["type_name"];
+                    $rule["inverse"] = sql_bool_to_bool($rule_line["inverse"]);
 
-                               if (method_exists($feed['sender'], 'get_total'))
-                                       $cv["auxcounter"] = $feed['sender']->get_total($feed['id']);
+                    array_push($rules, $rule);
+                }
+                       }
 
-                               array_push($ret_arr, $cv);
+                       if (count($rules) > 0) {
+                $sth2 = $pdo->prepare("SELECT a.action_param,t.name AS type_name
+                        FROM ttrss_filters2_actions AS a,
+                        ttrss_filter_actions AS t
+                        WHERE
+                            action_id = t.id AND filter_id = ?");
+                $sth2->execute([$filter_id]);
+
+                while ($action_line = $sth2->fetch()) {
+                    #                          print_r($action_line);
+
+                    $action = array();
+                    $action["type"] = $action_line["type_name"];
+                    $action["param"] = $action_line["action_param"];
+
+                    array_push($actions, $action);
+                }
+            }
+
+                       $filter = array();
+                       $filter["match_any_rule"] = sql_bool_to_bool($line["match_any_rule"]);
+                       $filter["inverse"] = sql_bool_to_bool($line["inverse"]);
+                       $filter["rules"] = $rules;
+                       $filter["actions"] = $actions;
+
+                       if (count($rules) > 0 && count($actions) > 0) {
+                               array_push($filters, $filter);
                        }
                }
 
-               return $ret_arr;
+               return $filters;
        }
 
-       function getLabelCounters($descriptions = false) {
+       function get_score_pic($score) {
+               if ($score > 100) {
+                       return "score_high.png";
+               } else if ($score > 0) {
+                       return "score_half_high.png";
+               } else if ($score < -100) {
+                       return "score_low.png";
+               } else if ($score < 0) {
+                       return "score_half_low.png";
+               } else {
+                       return "score_neutral.png";
+               }
+       }
 
-               $ret_arr = array();
+       function init_plugins() {
+               PluginHost::getInstance()->load(PLUGINS, PluginHost::KIND_ALL);
 
-               $owner_uid = $_SESSION["uid"];
+               return true;
+       }
+
+       function add_feed_category($feed_cat, $parent_cat_id = false) {
+
+               if (!$feed_cat) return false;
+
+               $feed_cat = mb_substr($feed_cat, 0, 250);
+               if (!$parent_cat_id) $parent_cat_id = null;
 
-               $result = db_query("SELECT id,caption,SUM(CASE WHEN u1.unread = true THEN 1 ELSE 0 END) AS unread, COUNT(u1.unread) AS total
-                       FROM ttrss_labels2 LEFT JOIN ttrss_user_labels2 ON
-                               (ttrss_labels2.id = label_id)
-                               LEFT JOIN ttrss_user_entries AS u1 ON u1.ref_id = article_id
-                               WHERE ttrss_labels2.owner_uid = $owner_uid AND u1.owner_uid = $owner_uid
-                               GROUP BY ttrss_labels2.id,
-                                       ttrss_labels2.caption");
+               $pdo = Db::pdo();
+               $tr_in_progress = false;
+
+               try {
+                       $pdo->beginTransaction();
+               } catch (Exception $e) {
+                       $tr_in_progress = true;
+               }
 
-               while ($line = db_fetch_assoc($result)) {
+               $sth = $pdo->prepare("SELECT id FROM ttrss_feed_categories
+                               WHERE (parent_cat = :parent OR (:parent IS NULL AND parent_cat IS NULL)) 
+                               AND title = :title AND owner_uid = :uid");
+               $sth->execute([':parent' => $parent_cat_id, ':title' => $feed_cat, ':uid' => $_SESSION['uid']]);
 
-                       $id = label_to_feed_id($line["id"]);
+               if (!$sth->fetch()) {
 
-                       $cv = array("id" => $id,
-                               "counter" => (int) $line["unread"],
-                               "auxcounter" => (int) $line["total"]);
+                       $sth = $pdo->prepare("INSERT INTO ttrss_feed_categories (owner_uid,title,parent_cat)
+                                       VALUES (?, ?, ?)");
+                       $sth->execute([$_SESSION['uid'], $feed_cat, $parent_cat_id]);
 
-                       if ($descriptions)
-                               $cv["description"] = $line["caption"];
+                       if (!$tr_in_progress) $pdo->commit();
 
-                       array_push($ret_arr, $cv);
+                       return true;
                }
 
-               return $ret_arr;
+        $pdo->commit();
+
+               return false;
        }
 
-       function getFeedCounters($active_feed = false) {
+       /**
+        * Fixes incomplete URLs by prepending "http://".
+        * Also replaces feed:// with http://, and
+        * prepends a trailing slash if the url is a domain name only.
+        *
+        * @param string $url Possibly incomplete URL
+        *
+        * @return string Fixed URL.
+        */
+       function fix_url($url) {
 
-               $ret_arr = array();
+               // support schema-less urls
+               if (strpos($url, '//') === 0) {
+                       $url = 'https:' . $url;
+               }
 
-               $query = "SELECT ttrss_feeds.id,
-                               ttrss_feeds.title,
-                               ".SUBSTRING_FOR_DATE."(ttrss_feeds.last_updated,1,19) AS last_updated,
-                               last_error, value AS count
-                       FROM ttrss_feeds, ttrss_counters_cache
-                       WHERE ttrss_feeds.owner_uid = ".$_SESSION["uid"]."
-                               AND ttrss_counters_cache.owner_uid = ttrss_feeds.owner_uid
-                               AND ttrss_counters_cache.feed_id = id";
+               if (strpos($url, '://') === false) {
+                       $url = 'http://' . $url;
+               } else if (substr($url, 0, 5) == 'feed:') {
+                       $url = 'http:' . substr($url, 5);
+               }
 
-               $result = db_query($query);
+               //prepend slash if the URL has no slash in it
+               // "http://www.example" -> "http://www.example/"
+               if (strpos($url, '/', strpos($url, ':') + 3) === false) {
+                       $url .= '/';
+               }
 
-               while ($line = db_fetch_assoc($result)) {
+               //convert IDNA hostname to punycode if possible
+               if (function_exists("idn_to_ascii")) {
+                       $parts = parse_url($url);
+                       if (mb_detect_encoding($parts['host']) != 'ASCII')
+                       {
+                               $parts['host'] = idn_to_ascii($parts['host']);
+                               $url = build_url($parts);
+                       }
+               }
 
-                       $id = $line["id"];
-                       $count = $line["count"];
-                       $last_error = htmlspecialchars($line["last_error"]);
+               if ($url != "http:///")
+                       return $url;
+               else
+                       return '';
+       }
 
-                       $last_updated = make_local_datetime($line['last_updated'], false);
+       function validate_feed_url($url) {
+               $parts = parse_url($url);
 
-                       $has_img = feed_has_icon($id);
+               return ($parts['scheme'] == 'http' || $parts['scheme'] == 'feed' || $parts['scheme'] == 'https');
 
-                       if (date('Y') - date('Y', strtotime($line['last_updated'])) > 2)
-                               $last_updated = '';
+       }
 
-                       $cv = array("id" => $id,
-                               "updated" => $last_updated,
-                               "counter" => (int) $count,
-                               "has_img" => (int) $has_img);
+       /* function save_email_address($email) {
+               // FIXME: implement persistent storage of emails
 
-                       if ($last_error)
-                               $cv["error"] = $last_error;
+               if (!$_SESSION['stored_emails'])
+                       $_SESSION['stored_emails'] = array();
 
-//                     if (get_pref('EXTENDED_FEEDLIST'))
-//                             $cv["xmsg"] = getFeedArticles($id)." ".__("total");
+               if (!in_array($email, $_SESSION['stored_emails']))
+                       array_push($_SESSION['stored_emails'], $email);
+       } */
 
-                       if ($active_feed && $id == $active_feed)
-                               $cv["title"] = truncate_string($line["title"], 30);
 
-                       array_push($ret_arr, $cv);
+       function get_feed_access_key($feed_id, $is_cat, $owner_uid = false) {
 
+               if (!$owner_uid) $owner_uid = $_SESSION["uid"];
+
+               $is_cat = bool_to_sql_bool($is_cat);
+
+               $pdo = Db::pdo();
+
+               $sth = $pdo->prepare("SELECT access_key FROM ttrss_access_keys
+                               WHERE feed_id = ? AND is_cat = ?
+                               AND owner_uid = ?");
+               $sth->execute([$feed_id, (int)$is_cat, $owner_uid]);
+
+               if ($row = $sth->fetch()) {
+                       return $row["access_key"];
+               } else {
+                       $key = uniqid_short();
+
+                       $sth = $pdo->prepare("INSERT INTO ttrss_access_keys
+                                       (access_key, feed_id, is_cat, owner_uid)
+                                       VALUES (?, ?, ?, ?)");
+
+                       $sth->execute([$key, $feed_id, (int)$is_cat, $owner_uid]);
+
+                       return $key;
                }
+       }
+
+       function get_feeds_from_html($url, $content)
+       {
+               $url     = fix_url($url);
+               $baseUrl = substr($url, 0, strrpos($url, '/') + 1);
+
+               libxml_use_internal_errors(true);
+
+               $doc = new DOMDocument();
+               $doc->loadHTML($content);
+               $xpath = new DOMXPath($doc);
+               $entries = $xpath->query('/html/head/link[@rel="alternate" and '.
+                       '(contains(@type,"rss") or contains(@type,"atom"))]|/html/head/link[@rel="feed"]');
+               $feedUrls = array();
+               foreach ($entries as $entry) {
+                       if ($entry->hasAttribute('href')) {
+                               $title = $entry->getAttribute('title');
+                               if ($title == '') {
+                                       $title = $entry->getAttribute('type');
+                               }
+                               $feedUrl = rewrite_relative_url(
+                                       $baseUrl, $entry->getAttribute('href')
+                               );
+                               $feedUrls[$feedUrl] = $title;
+                       }
+               }
+               return $feedUrls;
+       }
 
-               return $ret_arr;
+       function is_html($content) {
+               return preg_match("/<html|DOCTYPE html/i", substr($content, 0, 100)) !== 0;
        }
 
-       function get_pgsql_version() {
-               $result = db_query("SELECT version() AS version");
-               $version = explode(" ", db_fetch_result($result, 0, "version"));
-               return $version[1];
+       function url_is_html($url, $login = false, $pass = false) {
+               return is_html(fetch_file_contents($url, false, $login, $pass));
+       }
+
+       function build_url($parts) {
+               return $parts['scheme'] . "://" . $parts['host'] . $parts['path'];
+       }
+
+       function cleanup_url_path($path) {
+               $path = str_replace("/./", "/", $path);
+               $path = str_replace("//", "/", $path);
+
+               return $path;
        }
 
        /**
-        * @return array (code => Status code, message => error message if available)
+        * Converts a (possibly) relative URL to a absolute one.
+        *
+        * @param string $url     Base URL (i.e. from where the document is)
+        * @param string $rel_url Possibly relative URL in the document
         *
-        *                 0 - OK, Feed already exists
-        *                 1 - OK, Feed added
-        *                 2 - Invalid URL
-        *                 3 - URL content is HTML, no feeds available
-        *                 4 - URL content is HTML which contains multiple feeds.
-        *                     Here you should call extractfeedurls in rpc-backend
-        *                     to get all possible feeds.
-        *                 5 - Couldn't download the URL content.
-        *                 6 - Content is an invalid XML.
+        * @return string Absolute URL
         */
-       function subscribe_to_feed($url, $cat_id = 0,
-                       $auth_login = '', $auth_pass = '') {
+       function rewrite_relative_url($url, $rel_url) {
+               if (strpos($rel_url, "://") !== false) {
+                       return $rel_url;
+               } else if (strpos($rel_url, "//") === 0) {
+                       # protocol-relative URL (rare but they exist)
+                       return $rel_url;
+               } else if (preg_match("/^[a-z]+:/i", $rel_url)) {
+                       # magnet:, feed:, etc
+                       return $rel_url;
+               } else if (strpos($rel_url, "/") === 0) {
+                       $parts = parse_url($url);
+                       $parts['path'] = $rel_url;
+                       $parts['path'] = cleanup_url_path($parts['path']);
+
+                       return build_url($parts);
 
-               global $fetch_last_error;
-               global $fetch_last_error_content;
-               global $fetch_last_error_code;
+               } else {
+                       $parts = parse_url($url);
+                       if (!isset($parts['path'])) {
+                               $parts['path'] = '/';
+                       }
+                       $dir = $parts['path'];
+                       if (substr($dir, -1) !== '/') {
+                               $dir = dirname($parts['path']);
+                               $dir !== '/' && $dir .= '/';
+                       }
+                       $parts['path'] = $dir . $rel_url;
+                       $parts['path'] = cleanup_url_path($parts['path']);
 
-               require_once "include/rssfuncs.php";
+                       return build_url($parts);
+               }
+       }
 
-               $url = fix_url($url);
+       function cleanup_tags($days = 14, $limit = 1000) {
 
-               if (!$url || !validate_feed_url($url)) return array("code" => 2);
+           $days = (int) $days;
 
-               $contents = @fetch_file_contents($url, false, $auth_login, $auth_pass);
+               if (DB_TYPE == "pgsql") {
+                       $interval_query = "date_updated < NOW() - INTERVAL '$days days'";
+               } else if (DB_TYPE == "mysql") {
+                       $interval_query = "date_updated < DATE_SUB(NOW(), INTERVAL $days DAY)";
+               }
 
-               if (!$contents) {
-                       if (preg_match("/cloudflare\.com/", $fetch_last_error_content)) {
-                               $fetch_last_error .= " (feed behind Cloudflare)";
-                       }
+               $tags_deleted = 0;
 
-                       return array("code" => 5, "message" => $fetch_last_error);
-               }
+        $pdo = Db::pdo();
 
-               foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_SUBSCRIBE_FEED) as $plugin) {
-                       $contents = $plugin->hook_subscribe_feed($contents, $url, $auth_login, $auth_pass);
-               }
+        while ($limit > 0) {
+                       $limit_part = 500;
+
+                       $sth = $pdo->prepare("SELECT ttrss_tags.id AS id
+                                       FROM ttrss_tags, ttrss_user_entries, ttrss_entries
+                                       WHERE post_int_id = int_id AND $interval_query AND
+                                       ref_id = ttrss_entries.id AND tag_cache != '' LIMIT ?");
+                       $sth->execute([$limit]);
 
-               if (is_html($contents)) {
-                       $feedUrls = get_feeds_from_html($url, $contents);
+                       $ids = array();
 
-                       if (count($feedUrls) == 0) {
-                               return array("code" => 3);
-                       } else if (count($feedUrls) > 1) {
-                               return array("code" => 4, "feeds" => $feedUrls);
+                       while ($line = $sth->fetch()) {
+                               array_push($ids, $line['id']);
                        }
-                       //use feed url as new URL
-                       $url = key($feedUrls);
+
+                       if (count($ids) > 0) {
+                               $ids = join(",", $ids);
+
+                               $usth = $pdo->query("DELETE FROM ttrss_tags WHERE id IN ($ids)");
+                               $tags_deleted = $usth->rowCount();
+                       } else {
+                               break;
+                       }
+
+                       $limit -= $limit_part;
                }
 
-               if ($cat_id == "0" || !$cat_id) {
-                       $cat_qpart = "NULL";
-               } else {
-                       $cat_qpart = "'$cat_id'";
+               return $tags_deleted;
+       }
+
+       function print_user_stylesheet() {
+               $value = get_pref('USER_STYLESHEET');
+
+               if ($value) {
+                       print "<style type=\"text/css\">";
+                       print str_replace("<br/>", "\n", $value);
+                       print "</style>";
                }
 
-               $result = db_query(
-                       "SELECT id FROM ttrss_feeds
-                       WHERE feed_url = '$url' AND owner_uid = ".$_SESSION["uid"]);
+       }
+
+       function filter_to_sql($filter, $owner_uid) {
+               $query = array();
+
+               $pdo = Db::pdo();
+
+               if (DB_TYPE == "pgsql")
+                       $reg_qpart = "~";
+               else
+                       $reg_qpart = "REGEXP";
+
+               foreach ($filter["rules"] AS $rule) {
+                       $rule['reg_exp'] = str_replace('/', '\/', $rule["reg_exp"]);
+                       $regexp_valid = preg_match('/' . $rule['reg_exp'] . '/',
+                                       $rule['reg_exp']) !== FALSE;
+
+                       if ($regexp_valid) {
+
+                               $rule['reg_exp'] = $pdo->quote($rule['reg_exp']);
+
+                               switch ($rule["type"]) {
+                                       case "title":
+                                               $qpart = "LOWER(ttrss_entries.title) $reg_qpart LOWER('".
+                                                       $rule['reg_exp'] . "')";
+                                               break;
+                                       case "content":
+                                               $qpart = "LOWER(ttrss_entries.content) $reg_qpart LOWER('".
+                                                       $rule['reg_exp'] . "')";
+                                               break;
+                                       case "both":
+                                               $qpart = "LOWER(ttrss_entries.title) $reg_qpart LOWER('".
+                                                       $rule['reg_exp'] . "') OR LOWER(" .
+                                                       "ttrss_entries.content) $reg_qpart LOWER('" . $rule['reg_exp'] . "')";
+                                               break;
+                                       case "tag":
+                                               $qpart = "LOWER(ttrss_user_entries.tag_cache) $reg_qpart LOWER('".
+                                                       $rule['reg_exp'] . "')";
+                                               break;
+                                       case "link":
+                                               $qpart = "LOWER(ttrss_entries.link) $reg_qpart LOWER('".
+                                                       $rule['reg_exp'] . "')";
+                                               break;
+                                       case "author":
+                                               $qpart = "LOWER(ttrss_entries.author) $reg_qpart LOWER('".
+                                                       $rule['reg_exp'] . "')";
+                                               break;
+                               }
+
+                               if (isset($rule['inverse'])) $qpart = "NOT ($qpart)";
+
+                               if (isset($rule["feed_id"]) && $rule["feed_id"] > 0) {
+                                       $qpart .= " AND feed_id = " . $pdo->quote($rule["feed_id"]);
+                               }
 
-               $auth_pass_encrypted = 'false';
-               $auth_pass = db_escape_string($auth_pass);
+                               if (isset($rule["cat_id"])) {
 
-               if (db_num_rows($result) == 0) {
-                       $result = db_query(
-                               "INSERT INTO ttrss_feeds
-                                       (owner_uid,feed_url,title,cat_id, auth_login,auth_pass,update_method,auth_pass_encrypted)
-                               VALUES ('".$_SESSION["uid"]."', '$url',
-                               '[Unknown]', $cat_qpart, '$auth_login', '$auth_pass', 0, $auth_pass_encrypted)");
+                                       if ($rule["cat_id"] > 0) {
+                                               $children = Feeds::getChildCategories($rule["cat_id"], $owner_uid);
+                                               array_push($children, $rule["cat_id"]);
+                                               $children = array_map("intval", $children);
 
-                       $result = db_query(
-                               "SELECT id FROM ttrss_feeds WHERE feed_url = '$url'
-                                       AND owner_uid = " . $_SESSION["uid"]);
+                                               $children = join(",", $children);
+
+                                               $cat_qpart = "cat_id IN ($children)";
+                                       } else {
+                                               $cat_qpart = "cat_id IS NULL";
+                                       }
+
+                                       $qpart .= " AND $cat_qpart";
+                               }
 
-                       $feed_id = db_fetch_result($result, 0, "id");
+                               $qpart .= " AND feed_id IS NOT NULL";
+
+                               array_push($query, "($qpart)");
 
-                       if ($feed_id) {
-                               set_basic_feed_info($feed_id);
                        }
+               }
 
-                       return array("code" => 1, "feed_id" => (int) $feed_id);
+               if (count($query) > 0) {
+                       $fullquery = "(" . join($filter["match_any_rule"] ? "OR" : "AND", $query) . ")";
                } else {
-                       return array("code" => 0, "feed_id" => (int) db_fetch_result($result, 0, "id"));
+                       $fullquery = "(false)";
                }
-       }
 
-       function print_feed_select($id, $default_id = "",
-               $attributes = "", $include_all_feeds = true,
-               $root_id = false, $nest_level = 0) {
+               if ($filter['inverse']) $fullquery = "(NOT $fullquery)";
 
-               if (!$root_id) {
-                       print "<select id=\"$id\" name=\"$id\" $attributes>";
-                       if ($include_all_feeds) {
-                               $is_selected = ("0" == $default_id) ? "selected=\"1\"" : "";
-                               print "<option $is_selected value=\"0\">".__('All feeds')."</option>";
-                       }
+               return $fullquery;
+       }
+
+       if (!function_exists('gzdecode')) {
+               function gzdecode($string) { // no support for 2nd argument
+                       return file_get_contents('compress.zlib://data:who/cares;base64,'.
+                               base64_encode($string));
                }
+       }
 
-               if (get_pref('ENABLE_FEED_CATS')) {
+       function get_random_bytes($length) {
+               if (function_exists('openssl_random_pseudo_bytes')) {
+                       return openssl_random_pseudo_bytes($length);
+               } else {
+                       $output = "";
 
-                       if ($root_id)
-                               $parent_qpart = "parent_cat = '$root_id'";
-                       else
-                               $parent_qpart = "parent_cat IS NULL";
+                       for ($i = 0; $i < $length; $i++)
+                               $output .= chr(mt_rand(0, 255));
 
-                       $result = db_query("SELECT id,title,
-                               (SELECT COUNT(id) FROM ttrss_feed_categories AS c2 WHERE
-                                       c2.parent_cat = ttrss_feed_categories.id) AS num_children
-                               FROM ttrss_feed_categories
-                               WHERE owner_uid = ".$_SESSION["uid"]." AND $parent_qpart ORDER BY title");
+                       return $output;
+               }
+       }
 
-                       while ($line = db_fetch_assoc($result)) {
+       function read_stdin() {
+               $fp = fopen("php://stdin", "r");
 
-                               for ($i = 0; $i < $nest_level; $i++)
-                                       $line["title"] = " - " . $line["title"];
+               if ($fp) {
+                       $line = trim(fgets($fp));
+                       fclose($fp);
+                       return $line;
+               }
 
-                               $is_selected = ("CAT:".$line["id"] == $default_id) ? "selected=\"1\"" : "";
+               return null;
+       }
 
-                               printf("<option $is_selected value='CAT:%d'>%s</option>",
-                                       $line["id"], htmlspecialchars($line["title"]));
+       function implements_interface($class, $interface) {
+               return in_array($interface, class_implements($class));
+       }
 
-                               if ($line["num_children"] > 0)
-                                       print_feed_select($id, $default_id, $attributes,
-                                               $include_all_feeds, $line["id"], $nest_level+1);
+       function get_minified_js($files) {
+               require_once 'lib/jshrink/Minifier.php';
 
-                               $feed_result = db_query("SELECT id,title FROM ttrss_feeds
-                                       WHERE cat_id = '".$line["id"]."' AND owner_uid = ".$_SESSION["uid"] . " ORDER BY title");
+               $rv = '';
 
-                               while ($fline = db_fetch_assoc($feed_result)) {
-                                       $is_selected = ($fline["id"] == $default_id) ? "selected=\"1\"" : "";
+               foreach ($files as $js) {
+                       if (!isset($_GET['debug'])) {
+                               $cached_file = CACHE_DIR . "/js/".basename($js);
 
-                                       $fline["title"] = " + " . $fline["title"];
+                               if (file_exists($cached_file) && is_readable($cached_file) && filemtime($cached_file) >= filemtime("js/$js")) {
 
-                                       for ($i = 0; $i < $nest_level; $i++)
-                                               $fline["title"] = " - " . $fline["title"];
+                                       list($header, $contents) = explode("\n", file_get_contents($cached_file), 2);
 
-                                       printf("<option $is_selected value='%d'>%s</option>",
-                                               $fline["id"], htmlspecialchars($fline["title"]));
+                                       if ($header && $contents) {
+                                               list($htag, $hversion) = explode(":", $header);
+
+                                               if ($htag == "tt-rss" && $hversion == VERSION) {
+                                                       $rv .= $contents;
+                                                       continue;
+                                               }
+                                       }
                                }
+
+                               $minified = JShrink\Minifier::minify(file_get_contents("js/$js"));
+                               file_put_contents($cached_file, "tt-rss:" . VERSION . "\n" . $minified);
+                               $rv .= $minified;
+
+                       } else {
+                               $rv .= file_get_contents("js/$js"); // no cache in debug mode
                        }
+               }
+
+               return $rv;
+       }
+
+       function calculate_dep_timestamp() {
+               $files = array_merge(glob("js/*.js"), glob("css/*.css"));
 
-                       if (!$root_id) {
-                               $default_is_cat = ($default_id == "CAT:0");
-                               $is_selected = $default_is_cat ? "selected=\"1\"" : "";
+               $max_ts = -1;
 
-                               printf("<option $is_selected value='CAT:0'>%s</option>",
-                                       __("Uncategorized"));
+               foreach ($files as $file) {
+                       if (filemtime($file) > $max_ts) $max_ts = filemtime($file);
+               }
 
-                               $feed_result = db_query("SELECT id,title FROM ttrss_feeds
-                                       WHERE cat_id IS NULL AND owner_uid = ".$_SESSION["uid"] . " ORDER BY title");
+               return $max_ts;
+       }
 
-                               while ($fline = db_fetch_assoc($feed_result)) {
-                                       $is_selected = ($fline["id"] == $default_id && !$default_is_cat) ? "selected=\"1\"" : "";
+       function T_js_decl($s1, $s2) {
+               if ($s1 && $s2) {
+                       $s1 = preg_replace("/\n/", "", $s1);
+                       $s2 = preg_replace("/\n/", "", $s2);
+
+                       $s1 = preg_replace("/\"/", "\\\"", $s1);
+                       $s2 = preg_replace("/\"/", "\\\"", $s2);
+
+                       return "T_messages[\"$s1\"] = \"$s2\";\n";
+               }
+       }
 
-                                       $fline["title"] = " + " . $fline["title"];
+       function init_js_translations() {
 
-                                       for ($i = 0; $i < $nest_level; $i++)
-                                               $fline["title"] = " - " . $fline["title"];
+               print 'var T_messages = new Object();
 
-                                       printf("<option $is_selected value='%d'>%s</option>",
-                                               $fline["id"], htmlspecialchars($fline["title"]));
+                       function __(msg) {
+                               if (T_messages[msg]) {
+                                       return T_messages[msg];
+                               } else {
+                                       return msg;
                                }
                        }
 
-               } else {
-                       $result = db_query("SELECT id,title FROM ttrss_feeds
-                               WHERE owner_uid = ".$_SESSION["uid"]." ORDER BY title");
-
-                       while ($line = db_fetch_assoc($result)) {
+                       function ngettext(msg1, msg2, n) {
+                               return __((parseInt(n) > 1) ? msg2 : msg1);
+                       }';
 
-                               $is_selected = ($line["id"] == $default_id) ? "selected=\"1\"" : "";
+               $l10n = _get_reader();
 
-                               printf("<option $is_selected value='%d'>%s</option>",
-                                       $line["id"], htmlspecialchars($line["title"]));
+               for ($i = 0; $i < $l10n->total; $i++) {
+                       $orig = $l10n->get_original_string($i);
+                       if(strpos($orig, "\000") !== FALSE) { // Plural forms
+                               $key = explode(chr(0), $orig);
+                               print T_js_decl($key[0], _ngettext($key[0], $key[1], 1)); // Singular
+                               print T_js_decl($key[1], _ngettext($key[0], $key[1], 2)); // Plural
+                       } else {
+                               $translation = __($orig);
+                               print T_js_decl($orig, $translation);
                        }
                }
+       }
 
-               if (!$root_id) {
-                       print "</select>";
-               }
+       function get_theme_path($theme) {
+               if ($theme == "default.php")
+                       return "css/default.css";
+
+               $check = "themes/$theme";
+               if (file_exists($check)) return $check;
+
+               $check = "themes.local/$theme";
+               if (file_exists($check)) return $check;
        }
 
-       function print_feed_cat_select($id, $default_id,
-               $attributes, $include_all_cats = true, $root_id = false, $nest_level = 0) {
+       function theme_valid($theme) {
+               $bundled_themes = [ "default.php", "night.css", "compact.css" ];
+
+               if (in_array($theme, $bundled_themes)) return true;
+
+               $file = "themes/" . basename($theme);
+
+               if (!file_exists($file)) $file = "themes.local/" . basename($theme);
 
-                       if (!$root_id) {
-                                       print "<select id=\"$id\" name=\"$id\" default=\"$default_id\" $attributes>";
+               if (file_exists($file) && is_readable($file)) {
+                       $fh = fopen($file, "r");
+
+                       if ($fh) {
+                               $header = fgets($fh);
+                               fclose($fh);
+
+                               return strpos($header, "supports-version:" . VERSION_STATIC) !== FALSE;
                        }
+               }
 
-                       if ($root_id)
-                               $parent_qpart = "parent_cat = '$root_id'";
-                       else
-                               $parent_qpart = "parent_cat IS NULL";
+               return false;
+       }
 
-                       $result = db_query("SELECT id,title,
-                               (SELECT COUNT(id) FROM ttrss_feed_categories AS c2 WHERE
-                                       c2.parent_cat = ttrss_feed_categories.id) AS num_children
-                               FROM ttrss_feed_categories
-                               WHERE owner_uid = ".$_SESSION["uid"]." AND $parent_qpart ORDER BY title");
+       /**
+        * @SuppressWarnings(unused)
+        */
+       function error_json($code) {
+               require_once "errors.php";
 
-                       while ($line = db_fetch_assoc($result)) {
-                               if ($line["id"] == $default_id) {
-                                       $is_selected = "selected=\"1\"";
-                               } else {
-                                       $is_selected = "";
-                               }
+               @$message = $ERRORS[$code];
 
-                               for ($i = 0; $i < $nest_level; $i++)
-                                       $line["title"] = " - " . $line["title"];
+               return json_encode(array("error" =>
+                       array("code" => $code, "message" => $message)));
 
-                               if ($line["title"])
-                                       printf("<option $is_selected value='%d'>%s</option>",
-                                               $line["id"], htmlspecialchars($line["title"]));
+       }
 
-                               if ($line["num_children"] > 0)
-                                       print_feed_cat_select($id, $default_id, $attributes,
-                                               $include_all_cats, $line["id"], $nest_level+1);
-                       }
+       /*function abs_to_rel_path($dir) {
+               $tmp = str_replace(dirname(__DIR__), "", $dir);
 
-                       if (!$root_id) {
-                               if ($include_all_cats) {
-                                       if (db_num_rows($result) > 0) {
-                                               print "<option disabled=\"1\">--------</option>";
-                                       }
+               if (strlen($tmp) > 0 && substr($tmp, 0, 1) == "/") $tmp = substr($tmp, 1);
 
-                                       if ($default_id == 0) {
-                                               $is_selected = "selected=\"1\"";
-                                       } else {
-                                               $is_selected = "";
-                                       }
+               return $tmp;
+       }*/
 
-                                       print "<option $is_selected value=\"0\">".__('Uncategorized')."</option>";
-                               }
-                               print "</select>";
-                       }
-               }
+       function get_upload_error_message($code) {
 
-       function checkbox_to_sql_bool($val) {
-               return ($val == "on") ? "true" : "false";
-       }
-
-       function getFeedCatTitle($id) {
-               if ($id == -1) {
-                       return __("Special");
-               } else if ($id < LABEL_BASE_INDEX) {
-                       return __("Labels");
-               } else if ($id > 0) {
-                       $result = db_query("SELECT ttrss_feed_categories.title
-                               FROM ttrss_feeds, ttrss_feed_categories WHERE ttrss_feeds.id = '$id' AND
-                                       cat_id = ttrss_feed_categories.id");
-                       if (db_num_rows($result) == 1) {
-                               return db_fetch_result($result, 0, "title");
-                       } else {
-                               return __("Uncategorized");
-                       }
+               $errors = array(
+                       0 => __('There is no error, the file uploaded with success'),
+                       1 => __('The uploaded file exceeds the upload_max_filesize directive in php.ini'),
+                       2 => __('The uploaded file exceeds the MAX_FILE_SIZE directive that was specified in the HTML form'),
+                       3 => __('The uploaded file was only partially uploaded'),
+                       4 => __('No file was uploaded'),
+                       6 => __('Missing a temporary folder'),
+                       7 => __('Failed to write file to disk.'),
+                       8 => __('A PHP extension stopped the file upload.'),
+               );
+
+               return $errors[$code];
+       }
+
+       function base64_img($filename) {
+               if (file_exists($filename)) {
+                       $ext = pathinfo($filename, PATHINFO_EXTENSION);
+
+                       return "data:image/$ext;base64," . base64_encode(file_get_contents($filename));
                } else {
-                       return "getFeedCatTitle($id) failed";
-               }
-
-       }
-
-       function getFeedIcon($id) {
-               switch ($id) {
-               case 0:
-                       return "images/archive.png";
-                       break;
-               case -1:
-                       return "images/star.png";
-                       break;
-               case -2:
-                       return "images/feed.png";
-                       break;
-               case -3:
-                       return "images/fresh.png";
-                       break;
-               case -4:
-                       return "images/folder.png";
-                       break;
-               case -6:
-                       return "images/time.png";
-                       break;
-               default:
-                       if ($id < LABEL_BASE_INDEX) {
-                               return "images/label.png";
-                       } else {
-                               if (file_exists(ICONS_DIR . "/$id.ico"))
-                                       return ICONS_URL . "/$id.ico";
-                       }
-                       break;
+                       return "";
                }
-
-               return false;
        }
 
-       function getFeedTitle($id, $cat = false) {
-               if ($cat) {
-                       return getCategoryTitle($id);
-               } else if ($id == -1) {
-                       return __("Starred articles");
-               } else if ($id == -2) {
-                       return __("Published articles");
-               } else if ($id == -3) {
-                       return __("Fresh articles");
-               } else if ($id == -4) {
-                       return __("All articles");
-               } else if ($id === 0 || $id === "0") {
-                       return __("Archived articles");
-               } else if ($id == -6) {
-                       return __("Recently read");
-               } else if ($id < LABEL_BASE_INDEX) {
-                       $label_id = feed_to_label_id($id);
-                       $result = db_query("SELECT caption FROM ttrss_labels2 WHERE id = '$label_id'");
-                       if (db_num_rows($result) == 1) {
-                               return db_fetch_result($result, 0, "caption");
-                       } else {
-                               return "Unknown label ($label_id)";
-                       }
+       /*      this is essentially a wrapper for readfile() which allows plugins to hook
+               output with httpd-specific "fast" implementation i.e. X-Sendfile or whatever else
 
-               } else if (is_numeric($id) && $id > 0) {
-                       $result = db_query("SELECT title FROM ttrss_feeds WHERE id = '$id'");
-                       if (db_num_rows($result) == 1) {
-                               return db_fetch_result($result, 0, "title");
-                       } else {
-                               return "Unknown feed ($id)";
+               hook function should return true if request was handled (or at least attempted to)
+
+               note that this can be called without user context so the plugin to handle this
+               should be loaded systemwide in config.php */
+       function send_local_file($filename) {
+               if (file_exists($filename)) {
+                       $tmppluginhost = new PluginHost();
+
+                       $tmppluginhost->load(PLUGINS, PluginHost::KIND_SYSTEM);
+                       $tmppluginhost->load_data();
+
+                       foreach ($tmppluginhost->get_hooks(PluginHost::HOOK_SEND_LOCAL_FILE) as $plugin) {
+                               if ($plugin->hook_send_local_file($filename)) return true;
                        }
+
+                       $mimetype = mime_content_type($filename);
+                       header("Content-type: $mimetype");
+
+                       $stamp = gmdate("D, d M Y H:i:s", filemtime($filename)) . " GMT";
+                       header("Last-Modified: $stamp", true);
+
+                       return readfile($filename);
                } else {
-                       return $id;
+                       return false;
                }
        }
 
-       function uniqid_short() {
-               return uniqid(base_convert(rand(), 10, 36));
+       function check_mysql_tables() {
+               $pdo = Db::pdo();
+
+               $sth = $pdo->prepare("SELECT engine, table_name FROM information_schema.tables WHERE
+                       table_schema = ? AND table_name LIKE 'ttrss_%' AND engine != 'InnoDB'");
+               $sth->execute([DB_NAME]);
+
+               $bad_tables = [];
+
+               while ($line = $sth->fetch()) {
+                       array_push($bad_tables, $line);
+               }
+
+               return $bad_tables;
        }
 
-       // TODO: less dumb splitting
-       require_once "functions2.php";
+       function validate_field($string, $allowed, $default = "") {
+               if (in_array($string, $allowed))
+                       return $string;
+               else
+                       return $default;
+       }
 
-?>
+    function arr_qmarks($arr) {
+        return str_repeat('?,', count($arr) - 1) . '?';
+    }