]> git.wh0rd.org - tt-rss.git/blobdiff - classes/api.php
api: getHeadlines: add configurable excerpt_length (bump api version)
[tt-rss.git] / classes / api.php
index 74464821f5c19a40746bdfe98673b54b757f9fa3..3c5d084087ba592ef39b9656688ee0830403f78f 100644 (file)
@@ -2,7 +2,7 @@
 
 class API extends Handler {
 
-       const API_LEVEL  = 4;
+       const API_LEVEL  = 11;
 
        const STATUS_OK  = 0;
        const STATUS_ERR = 1;
@@ -14,12 +14,12 @@ class API extends Handler {
                        header("Content-Type: text/json");
 
                        if (!$_SESSION["uid"] && $method != "login" && $method != "isloggedin") {
-                               print $this->wrap(self::STATUS_ERR, array("error" => 'NOT_LOGGED_IN'));
+                               $this->wrap(self::STATUS_ERR, array("error" => 'NOT_LOGGED_IN'));
                                return false;
                        }
 
-                       if ($_SESSION["uid"] && $method != "logout" && !get_pref($this->link, 'ENABLE_API_ACCESS')) {
-                               print $this->wrap(self::STATUS_ERR, array("error" => 'API_DISABLED'));
+                       if ($_SESSION["uid"] && $method != "logout" && !get_pref('ENABLE_API_ACCESS')) {
+                               $this->wrap(self::STATUS_ERR, array("error" => 'API_DISABLED'));
                                return false;
                        }
 
@@ -38,90 +38,95 @@ class API extends Handler {
 
        function getVersion() {
                $rv = array("version" => VERSION);
-               print $this->wrap(self::STATUS_OK, $rv);
+               $this->wrap(self::STATUS_OK, $rv);
        }
 
        function getApiLevel() {
                $rv = array("level" => self::API_LEVEL);
-               print $this->wrap(self::STATUS_OK, $rv);
+               $this->wrap(self::STATUS_OK, $rv);
        }
 
        function login() {
-               $login = db_escape_string($_REQUEST["user"]);
+               @session_destroy();
+               @session_start();
+
+               $login = $this->dbh->escape_string($_REQUEST["user"]);
                $password = $_REQUEST["password"];
                $password_base64 = base64_decode($_REQUEST["password"]);
 
                if (SINGLE_USER_MODE) $login = "admin";
 
-               $result = db_query($this->link, "SELECT id FROM ttrss_users WHERE login = '$login'");
+               $result = $this->dbh->query("SELECT id FROM ttrss_users WHERE login = '$login'");
 
-               if (db_num_rows($result) != 0) {
-                       $uid = db_fetch_result($result, 0, "id");
+               if ($this->dbh->num_rows($result) != 0) {
+                       $uid = $this->dbh->fetch_result($result, 0, "id");
                } else {
                        $uid = 0;
                }
 
                if (!$uid) {
-                       print $this->wrap(self::STATUS_ERR, array("error" => "LOGIN_ERROR"));
+                       $this->wrap(self::STATUS_ERR, array("error" => "LOGIN_ERROR"));
                        return;
                }
 
-               if (get_pref($this->link, "ENABLE_API_ACCESS", $uid)) {
-                       if (authenticate_user($this->link, $login, $password)) {               // try login with normal password
-                               print $this->wrap(self::STATUS_OK, array("session_id" => session_id(),
+               if (get_pref("ENABLE_API_ACCESS", $uid)) {
+                       if (authenticate_user($login, $password)) {               // try login with normal password
+                               $this->wrap(self::STATUS_OK, array("session_id" => session_id(),
                                        "api_level" => self::API_LEVEL));
-                       } else if (authenticate_user($this->link, $login, $password_base64)) { // else try with base64_decoded password
-                               print $this->wrap(self::STATUS_OK,      array("session_id" => session_id(),
+                       } else if (authenticate_user($login, $password_base64)) { // else try with base64_decoded password
+                               $this->wrap(self::STATUS_OK,    array("session_id" => session_id(),
                                        "api_level" => self::API_LEVEL));
                        } else {                                                         // else we are not logged in
-                               print $this->wrap(self::STATUS_ERR, array("error" => "LOGIN_ERROR"));
+                               user_error("Failed login attempt for $login from {$_SERVER['REMOTE_ADDR']}", E_USER_WARNING);
+                               $this->wrap(self::STATUS_ERR, array("error" => "LOGIN_ERROR"));
                        }
                } else {
-                       print $this->wrap(self::STATUS_ERR, array("error" => "API_DISABLED"));
+                       $this->wrap(self::STATUS_ERR, array("error" => "API_DISABLED"));
                }
 
        }
 
        function logout() {
                logout_user();
-               print $this->wrap(self::STATUS_OK, array("status" => "OK"));
+               $this->wrap(self::STATUS_OK, array("status" => "OK"));
        }
 
        function isLoggedIn() {
-               print $this->wrap(self::STATUS_OK, array("status" => $_SESSION["uid"] != ''));
+               $this->wrap(self::STATUS_OK, array("status" => $_SESSION["uid"] != ''));
        }
 
        function getUnread() {
-               $feed_id = db_escape_string($_REQUEST["feed_id"]);
-               $is_cat = db_escape_string($_REQUEST["is_cat"]);
+               $feed_id = $this->dbh->escape_string($_REQUEST["feed_id"]);
+               $is_cat = $this->dbh->escape_string($_REQUEST["is_cat"]);
 
                if ($feed_id) {
-                       print $this->wrap(self::STATUS_OK, array("unread" => getFeedUnread($this->link, $feed_id, $is_cat)));
+                       $this->wrap(self::STATUS_OK, array("unread" => getFeedUnread($feed_id, $is_cat)));
                } else {
-                       print $this->wrap(self::STATUS_OK, array("unread" => getGlobalUnread($this->link)));
+                       $this->wrap(self::STATUS_OK, array("unread" => getGlobalUnread()));
                }
        }
 
        /* Method added for ttrss-reader for Android */
        function getCounters() {
-               print $this->wrap(self::STATUS_OK, getAllCounters($this->link));
+               $this->wrap(self::STATUS_OK, getAllCounters());
        }
 
        function getFeeds() {
-               $cat_id = db_escape_string($_REQUEST["cat_id"]);
+               $cat_id = $this->dbh->escape_string($_REQUEST["cat_id"]);
                $unread_only = sql_bool_to_bool($_REQUEST["unread_only"]);
-               $limit = (int) db_escape_string($_REQUEST["limit"]);
-               $offset = (int) db_escape_string($_REQUEST["offset"]);
+               $limit = (int) $this->dbh->escape_string($_REQUEST["limit"]);
+               $offset = (int) $this->dbh->escape_string($_REQUEST["offset"]);
                $include_nested = sql_bool_to_bool($_REQUEST["include_nested"]);
 
-               $feeds = $this->api_get_feeds($this->link, $cat_id, $unread_only, $limit, $offset, $include_nested);
+               $feeds = $this->api_get_feeds($cat_id, $unread_only, $limit, $offset, $include_nested);
 
-               print $this->wrap(self::STATUS_OK, $feeds);
+               $this->wrap(self::STATUS_OK, $feeds);
        }
 
        function getCategories() {
                $unread_only = sql_bool_to_bool($_REQUEST["unread_only"]);
                $enable_nested = sql_bool_to_bool($_REQUEST["enable_nested"]);
+               $include_empty = sql_bool_to_bool($_REQUEST['include_empty']);
 
                // TODO do not return empty categories, return Uncategorized and standard virtual cats
 
@@ -130,22 +135,25 @@ class API extends Handler {
                else
                        $nested_qpart = "true";
 
-               $result = db_query($this->link, "SELECT
+               $result = $this->dbh->query("SELECT
                                id, title, order_id, (SELECT COUNT(id) FROM
                                ttrss_feeds WHERE
-                               ttrss_feed_categories.id IS NOT NULL AND cat_id = ttrss_feed_categories.id) AS num_feeds
+                               ttrss_feed_categories.id IS NOT NULL AND cat_id = ttrss_feed_categories.id) AS num_feeds,
+                       (SELECT COUNT(id) FROM
+                               ttrss_feed_categories AS c2 WHERE
+                               c2.parent_cat = ttrss_feed_categories.id) AS num_cats
                        FROM ttrss_feed_categories
                        WHERE $nested_qpart AND owner_uid = " .
                        $_SESSION["uid"]);
 
                $cats = array();
 
-               while ($line = db_fetch_assoc($result)) {
-                       if ($line["num_feeds"] > 0) {
-                               $unread = getFeedUnread($this->link, $line["id"], true);
+               while ($line = $this->dbh->fetch_assoc($result)) {
+                       if ($include_empty || $line["num_feeds"] > 0 || $line["num_cats"] > 0) {
+                               $unread = getFeedUnread($line["id"], true);
 
                                if ($enable_nested)
-                                       $unread += getCategoryChildrenUnread($this->link, $line["id"]);
+                                       $unread += getCategoryChildrenUnread($line["id"]);
 
                                if ($unread || !$unread_only) {
                                        array_push($cats, array("id" => $line["id"],
@@ -158,60 +166,80 @@ class API extends Handler {
                }
 
                foreach (array(-2,-1,0) as $cat_id) {
-                       $unread = getFeedUnread($this->link, $cat_id, true);
+                       if ($include_empty || !$this->isCategoryEmpty($cat_id)) {
+                               $unread = getFeedUnread($cat_id, true);
 
-                       if ($unread || !$unread_only) {
-                               array_push($cats, array("id" => $cat_id,
-                                       "title" => getCategoryTitle($this->link, $cat_id),
-                                       "unread" => $unread));
+                               if ($unread || !$unread_only) {
+                                       array_push($cats, array("id" => $cat_id,
+                                               "title" => getCategoryTitle($cat_id),
+                                               "unread" => $unread));
+                               }
                        }
                }
 
-               print $this->wrap(self::STATUS_OK, $cats);
+               $this->wrap(self::STATUS_OK, $cats);
        }
 
        function getHeadlines() {
-               $feed_id = db_escape_string($_REQUEST["feed_id"]);
+               $feed_id = $this->dbh->escape_string($_REQUEST["feed_id"]);
                if ($feed_id != "") {
 
-                       $limit = (int)db_escape_string($_REQUEST["limit"]);
+                       $limit = (int)$this->dbh->escape_string($_REQUEST["limit"]);
 
-                       if (!$limit || $limit >= 60) $limit = 60;
+                       if (!$limit || $limit >= 200) $limit = 200;
 
-                       $offset = (int)db_escape_string($_REQUEST["skip"]);
-                       $filter = db_escape_string($_REQUEST["filter"]);
+                       $offset = (int)$this->dbh->escape_string($_REQUEST["skip"]);
+                       $filter = $this->dbh->escape_string($_REQUEST["filter"]);
                        $is_cat = sql_bool_to_bool($_REQUEST["is_cat"]);
                        $show_excerpt = sql_bool_to_bool($_REQUEST["show_excerpt"]);
                        $show_content = sql_bool_to_bool($_REQUEST["show_content"]);
                        /* all_articles, unread, adaptive, marked, updated */
-                       $view_mode = db_escape_string($_REQUEST["view_mode"]);
+                       $view_mode = $this->dbh->escape_string($_REQUEST["view_mode"]);
                        $include_attachments = sql_bool_to_bool($_REQUEST["include_attachments"]);
-                       $since_id = (int)db_escape_string($_REQUEST["since_id"]);
+                       $since_id = (int)$this->dbh->escape_string($_REQUEST["since_id"]);
                        $include_nested = sql_bool_to_bool($_REQUEST["include_nested"]);
-                       $sanitize_content = true;
+                       $sanitize_content = !isset($_REQUEST["sanitize"]) ||
+                               sql_bool_to_bool($_REQUEST["sanitize"]);
+                       $force_update = sql_bool_to_bool($_REQUEST["force_update"]);
+                       $has_sandbox = sql_bool_to_bool($_REQUEST["has_sandbox"]);
+                       $excerpt_length = (int)$this->dbh->escape_string($_REQUEST["excerpt_length"]);
+
+                       $_SESSION['hasSandbox'] = $has_sandbox;
+
+                       $override_order = false;
+                       switch ($_REQUEST["order_by"]) {
+                               case "title":
+                                       $override_order = "ttrss_entries.title";
+                                       break;
+                               case "date_reverse":
+                                       $override_order = "score DESC, date_entered, updated";
+                                       break;
+                               case "feed_dates":
+                                       $override_order = "updated DESC";
+                                       break;
+                       }
 
                        /* do not rely on params below */
 
-                       $search = db_escape_string($_REQUEST["search"]);
-                       $search_mode = db_escape_string($_REQUEST["search_mode"]);
-                       $match_on = db_escape_string($_REQUEST["match_on"]);
+                       $search = $this->dbh->escape_string($_REQUEST["search"]);
+                       $search_mode = $this->dbh->escape_string($_REQUEST["search_mode"]);
 
-                       $headlines = $this->api_get_headlines($this->link, $feed_id, $limit, $offset,
-                               $filter, $is_cat, $show_excerpt, $show_content, $view_mode, false,
-                               $include_attachments, $since_id, $search, $search_mode, $match_on,
-                               $include_nested, $sanitize_content);
+                       $headlines = $this->api_get_headlines($feed_id, $limit, $offset,
+                               $filter, $is_cat, $show_excerpt, $show_content, $view_mode, $override_order,
+                               $include_attachments, $since_id, $search, $search_mode,
+                               $include_nested, $sanitize_content, $force_update, $excerpt_length);
 
-                       print $this->wrap(self::STATUS_OK, $headlines);
+                       $this->wrap(self::STATUS_OK, $headlines);
                } else {
-                       print $this->wrap(self::STATUS_ERR, array("error" => 'INCORRECT_USAGE'));
+                       $this->wrap(self::STATUS_ERR, array("error" => 'INCORRECT_USAGE'));
                }
        }
 
        function updateArticle() {
-               $article_ids = array_filter(explode(",", db_escape_string($_REQUEST["article_ids"])), is_numeric);
-               $mode = (int) db_escape_string($_REQUEST["mode"]);
-               $data = db_escape_string($_REQUEST["data"]);
-               $field_raw = (int)db_escape_string($_REQUEST["field"]);
+               $article_ids = array_filter(explode(",", $this->dbh->escape_string($_REQUEST["article_ids"])), is_numeric);
+               $mode = (int) $this->dbh->escape_string($_REQUEST["mode"]);
+               $data = $this->dbh->escape_string($_REQUEST["data"]);
+               $field_raw = (int)$this->dbh->escape_string($_REQUEST["field"]);
 
                $field = "";
                $set_to = "";
@@ -251,16 +279,16 @@ class API extends Handler {
 
                        $article_ids = join(", ", $article_ids);
 
-                       $result = db_query($this->link, "UPDATE ttrss_user_entries SET $field = $set_to $additional_fields WHERE ref_id IN ($article_ids) AND owner_uid = " . $_SESSION["uid"]);
+                       $result = $this->dbh->query("UPDATE ttrss_user_entries SET $field = $set_to $additional_fields WHERE ref_id IN ($article_ids) AND owner_uid = " . $_SESSION["uid"]);
 
-                       $num_updated = db_affected_rows($this->link, $result);
+                       $num_updated = $this->dbh->affected_rows($result);
 
                        if ($num_updated > 0 && $field == "unread") {
-                               $result = db_query($this->link, "SELECT DISTINCT feed_id FROM ttrss_user_entries
+                               $result = $this->dbh->query("SELECT DISTINCT feed_id FROM ttrss_user_entries
                                        WHERE ref_id IN ($article_ids)");
 
-                               while ($line = db_fetch_assoc($result)) {
-                                       ccache_update($this->link, $line["feed_id"], $_SESSION["uid"]);
+                               while ($line = $this->dbh->fetch_assoc($result)) {
+                                       ccache_update($line["feed_id"], $_SESSION["uid"]);
                                }
                        }
 
@@ -268,67 +296,80 @@ class API extends Handler {
                                if (PUBSUBHUBBUB_HUB) {
                                        $rss_link = get_self_url_prefix() .
                                                "/public.php?op=rss&id=-2&key=" .
-                                               get_feed_access_key($this->link, -2, false);
+                                               get_feed_access_key(-2, false);
 
                                        $p = new Publisher(PUBSUBHUBBUB_HUB);
                                        $pubsub_result = $p->publish_update($rss_link);
                                }
                        }
 
-                       print $this->wrap(self::STATUS_OK, array("status" => "OK",
+                       $this->wrap(self::STATUS_OK, array("status" => "OK",
                                "updated" => $num_updated));
 
                } else {
-                       print $this->wrap(self::STATUS_ERR, array("error" => 'INCORRECT_USAGE'));
+                       $this->wrap(self::STATUS_ERR, array("error" => 'INCORRECT_USAGE'));
                }
 
        }
 
        function getArticle() {
 
-               $article_id = join(",", array_filter(explode(",", db_escape_string($_REQUEST["article_id"])), is_numeric));
+               $article_id = join(",", array_filter(explode(",", $this->dbh->escape_string($_REQUEST["article_id"])), is_numeric));
 
-               $query = "SELECT id,title,link,content,cached_content,feed_id,comments,int_id,
-                       marked,unread,published,
-                       ".SUBSTRING_FOR_DATE."(updated,1,16) as updated,
-                       author
-                       FROM ttrss_entries,ttrss_user_entries
-                       WHERE   id IN ($article_id) AND ref_id = id AND owner_uid = " .
-                               $_SESSION["uid"] ;
+               if ($article_id) {
 
-               $result = db_query($this->link, $query);
+                       $query = "SELECT id,title,link,content,feed_id,comments,int_id,
+                               marked,unread,published,score,note,lang,
+                               ".SUBSTRING_FOR_DATE."(updated,1,16) as updated,
+                               author,(SELECT title FROM ttrss_feeds WHERE id = feed_id) AS feed_title
+                               FROM ttrss_entries,ttrss_user_entries
+                               WHERE   id IN ($article_id) AND ref_id = id AND owner_uid = " .
+                                       $_SESSION["uid"] ;
 
-               $articles = array();
+                       $result = $this->dbh->query($query);
 
-               if (db_num_rows($result) != 0) {
+                       $articles = array();
 
-                       while ($line = db_fetch_assoc($result)) {
+                       if ($this->dbh->num_rows($result) != 0) {
 
-                               $attachments = get_article_enclosures($this->link, $line['id']);
-
-                               $article = array(
-                                       "id" => $line["id"],
-                                       "title" => $line["title"],
-                                       "link" => $line["link"],
-                                       "labels" => get_article_labels($this->link, $line['id']),
-                                       "unread" => sql_bool_to_bool($line["unread"]),
-                                       "marked" => sql_bool_to_bool($line["marked"]),
-                                       "published" => sql_bool_to_bool($line["published"]),
-                                       "comments" => $line["comments"],
-                                       "author" => $line["author"],
-                                       "updated" => (int) strtotime($line["updated"]),
-                                       "content" => $line["cached_content"] != "" ? $line["cached_content"] : $line["content"],
-                                       "feed_id" => $line["feed_id"],
-                                       "attachments" => $attachments
-                               );
-
-                               array_push($articles, $article);
+                               while ($line = $this->dbh->fetch_assoc($result)) {
 
-                       }
-               }
+                                       $attachments = get_article_enclosures($line['id']);
+
+                                       $article = array(
+                                               "id" => $line["id"],
+                                               "title" => $line["title"],
+                                               "link" => $line["link"],
+                                               "labels" => get_article_labels($line['id']),
+                                               "unread" => sql_bool_to_bool($line["unread"]),
+                                               "marked" => sql_bool_to_bool($line["marked"]),
+                                               "published" => sql_bool_to_bool($line["published"]),
+                                               "comments" => $line["comments"],
+                                               "author" => $line["author"],
+                                               "updated" => (int) strtotime($line["updated"]),
+                                               "content" => $line["content"],
+                                               "feed_id" => $line["feed_id"],
+                                               "attachments" => $attachments,
+                                               "score" => (int)$line["score"],
+                                               "feed_title" => $line["feed_title"],
+                                               "note" => $line["note"],
+                                               "lang" => $line["lang"]
+                                       );
+
+                                       foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_RENDER_ARTICLE_API) as $p) {
+                                               $article = $p->hook_render_article_api(array("article" => $article));
+                                       }
 
-               print $this->wrap(self::STATUS_OK, $articles);
 
+                                       array_push($articles, $article);
+
+                               }
+                       }
+
+                       $this->wrap(self::STATUS_OK, $articles);
+               } else {
+                       $this->wrap(self::STATUS_ERR, array("error" => 'INCORRECT_USAGE'));
+               }
        }
 
        function getConfig() {
@@ -338,84 +379,86 @@ class API extends Handler {
 
                $config["daemon_is_running"] = file_is_locked("update_daemon.lock");
 
-               $result = db_query($this->link, "SELECT COUNT(*) AS cf FROM
+               $result = $this->dbh->query("SELECT COUNT(*) AS cf FROM
                        ttrss_feeds WHERE owner_uid = " . $_SESSION["uid"]);
 
-               $num_feeds = db_fetch_result($result, 0, "cf");
+               $num_feeds = $this->dbh->fetch_result($result, 0, "cf");
 
                $config["num_feeds"] = (int)$num_feeds;
 
-               print $this->wrap(self::STATUS_OK, $config);
+               $this->wrap(self::STATUS_OK, $config);
        }
 
        function updateFeed() {
-               $feed_id = db_escape_string($_REQUEST["feed_id"]);
+               require_once "include/rssfuncs.php";
 
-               update_rss_feed($this->link, $feed_id, true);
+               $feed_id = (int) $this->dbh->escape_string($_REQUEST["feed_id"]);
 
-               print $this->wrap(self::STATUS_OK, array("status" => "OK"));
+               update_rss_feed($feed_id, true);
+
+               $this->wrap(self::STATUS_OK, array("status" => "OK"));
        }
 
        function catchupFeed() {
-               $feed_id = db_escape_string($_REQUEST["feed_id"]);
-               $is_cat = db_escape_string($_REQUEST["is_cat"]);
+               $feed_id = $this->dbh->escape_string($_REQUEST["feed_id"]);
+               $is_cat = $this->dbh->escape_string($_REQUEST["is_cat"]);
 
-               catchup_feed($this->link, $feed_id, $is_cat);
+               catchup_feed($feed_id, $is_cat);
 
-               print $this->wrap(self::STATUS_OK, array("status" => "OK"));
+               $this->wrap(self::STATUS_OK, array("status" => "OK"));
        }
 
        function getPref() {
-               $pref_name = db_escape_string($_REQUEST["pref_name"]);
+               $pref_name = $this->dbh->escape_string($_REQUEST["pref_name"]);
 
-               print $this->wrap(self::STATUS_OK, array("value" => get_pref($this->link, $pref_name)));
+               $this->wrap(self::STATUS_OK, array("value" => get_pref($pref_name)));
        }
 
        function getLabels() {
-               //$article_ids = array_filter(explode(",", db_escape_string($_REQUEST["article_ids"])), is_numeric);
+               //$article_ids = array_filter(explode(",", $this->dbh->escape_string($_REQUEST["article_ids"])), is_numeric);
 
                $article_id = (int)$_REQUEST['article_id'];
 
                $rv = array();
 
-               $result = db_query($this->link, "SELECT id, caption, fg_color, bg_color
+               $result = $this->dbh->query("SELECT id, caption, fg_color, bg_color
                        FROM ttrss_labels2
                        WHERE owner_uid = '".$_SESSION['uid']."' ORDER BY caption");
 
                if ($article_id)
-                       $article_labels = get_article_labels($this->link, $article_id);
+                       $article_labels = get_article_labels($article_id);
                else
                        $article_labels = array();
 
-               while ($line = db_fetch_assoc($result)) {
+               while ($line = $this->dbh->fetch_assoc($result)) {
 
                        $checked = false;
                        foreach ($article_labels as $al) {
-                               if ($al[0] == $line['id']) {
+                               if (feed_to_label_id($al[0]) == $line['id']) {
                                        $checked = true;
                                        break;
                                }
                        }
 
                        array_push($rv, array(
-                               "id" => (int)$line['id'],
+                               "id" => (int)label_to_feed_id($line['id']),
                                "caption" => $line['caption'],
                                "fg_color" => $line['fg_color'],
                                "bg_color" => $line['bg_color'],
                                "checked" => $checked));
                }
 
-               print $this->wrap(self::STATUS_OK, $rv);
+               $this->wrap(self::STATUS_OK, $rv);
        }
 
        function setArticleLabel() {
 
-               $article_ids = array_filter(explode(",", db_escape_string($_REQUEST["article_ids"])), is_numeric);
-               $label_id = (int) db_escape_string($_REQUEST['label_id']);
-               $assign = (bool) db_escape_string($_REQUEST['assign']) == "true";
+               $article_ids = array_filter(explode(",", $this->dbh->escape_string($_REQUEST["article_ids"])), is_numeric);
+               $label_id = (int) $this->dbh->escape_string($_REQUEST['label_id']);
+               $assign = (bool) $this->dbh->escape_string($_REQUEST['assign']) == "true";
 
-               $label = db_escape_string(label_find_caption($this->link,
-                       $label_id, $_SESSION["uid"]));
+               $label = $this->dbh->escape_string(label_find_caption(
+                       feed_to_label_id($label_id), $_SESSION["uid"]));
 
                $num_updated = 0;
 
@@ -424,44 +467,53 @@ class API extends Handler {
                        foreach ($article_ids as $id) {
 
                                if ($assign)
-                                       label_add_article($this->link, $id, $label, $_SESSION["uid"]);
+                                       label_add_article($id, $label, $_SESSION["uid"]);
                                else
-                                       label_remove_article($this->link, $id, $label, $_SESSION["uid"]);
+                                       label_remove_article($id, $label, $_SESSION["uid"]);
 
                                ++$num_updated;
 
                        }
                }
 
-               print $this->wrap(self::STATUS_OK, array("status" => "OK",
+               $this->wrap(self::STATUS_OK, array("status" => "OK",
                        "updated" => $num_updated));
 
        }
 
-       function index() {
-               print $this->wrap(self::STATUS_ERR, array("error" => 'UNKNOWN_METHOD'));
+       function index($method) {
+               $plugin = PluginHost::getInstance()->get_api_method(strtolower($method));
+
+               if ($plugin && method_exists($plugin, $method)) {
+                       $reply = $plugin->$method();
+
+                       $this->wrap($reply[0], $reply[1]);
+
+               } else {
+                       $this->wrap(self::STATUS_ERR, array("error" => 'UNKNOWN_METHOD', "method" => $method));
+               }
        }
 
        function shareToPublished() {
-               $title = db_escape_string(strip_tags($_REQUEST["title"]));
-               $url = db_escape_string(strip_tags($_REQUEST["url"]));
-               $content = db_escape_string(strip_tags($_REQUEST["content"]));
+               $title = $this->dbh->escape_string(strip_tags($_REQUEST["title"]));
+               $url = $this->dbh->escape_string(strip_tags($_REQUEST["url"]));
+               $content = $this->dbh->escape_string(strip_tags($_REQUEST["content"]));
 
-               if (Article::create_published_article($this->link, $title, $url, $content, "", $_SESSION["uid"])) {
-                       print $this->wrap(self::STATUS_OK, array("status" => 'OK'));
+               if (Article::create_published_article($title, $url, $content, "", $_SESSION["uid"])) {
+                       $this->wrap(self::STATUS_OK, array("status" => 'OK'));
                } else {
-                       print $this->wrap(self::STATUS_ERR, array("error" => 'Publishing failed'));
+                       $this->wrap(self::STATUS_ERR, array("error" => 'Publishing failed'));
                }
        }
 
-       static function api_get_feeds($link, $cat_id, $unread_only, $limit, $offset, $include_nested = false) {
+       static function api_get_feeds($cat_id, $unread_only, $limit, $offset, $include_nested = false) {
 
                        $feeds = array();
 
                        /* Labels */
 
                        if ($cat_id == -4 || $cat_id == -2) {
-                               $counters = getLabelCounters($link, true);
+                               $counters = getLabelCounters(true);
 
                                foreach (array_values($counters) as $cv) {
 
@@ -470,7 +522,7 @@ class API extends Handler {
                                        if ($unread || !$unread_only) {
 
                                                $row = array(
-                                                               "id" => $cv["id"],
+                                                               "id" => (int) $cv["id"],
                                                                "title" => $cv["description"],
                                                                "unread" => $cv["counter"],
                                                                "cat_id" => -2,
@@ -485,10 +537,10 @@ class API extends Handler {
 
                        if ($cat_id == -4 || $cat_id == -1) {
                                foreach (array(-1, -2, -3, -4, -6, 0) as $i) {
-                                       $unread = getFeedUnread($link, $i);
+                                       $unread = getFeedUnread($i);
 
                                        if ($unread || !$unread_only) {
-                                               $title = getFeedTitle($link, $i);
+                                               $title = getFeedTitle($i);
 
                                                $row = array(
                                                                "id" => $i,
@@ -505,18 +557,18 @@ class API extends Handler {
                        /* Child cats */
 
                        if ($include_nested && $cat_id) {
-                               $result = db_query($link, "SELECT
+                               $result = db_query("SELECT
                                        id, title FROM ttrss_feed_categories
                                        WHERE parent_cat = '$cat_id' AND owner_uid = " . $_SESSION["uid"] .
                                " ORDER BY id, title");
 
                                while ($line = db_fetch_assoc($result)) {
-                                       $unread = getFeedUnread($link, $line["id"], true) +
-                                               getCategoryChildrenUnread($link, $line["id"]);
+                                       $unread = getFeedUnread($line["id"], true) +
+                                               getCategoryChildrenUnread($line["id"]);
 
                                        if ($unread || !$unread_only) {
                                                $row = array(
-                                                               "id" => $line["id"],
+                                                               "id" => (int) $line["id"],
                                                                "title" => $line["title"],
                                                                "unread" => $unread,
                                                                "is_cat" => true,
@@ -535,7 +587,7 @@ class API extends Handler {
                        }
 
                        if ($cat_id == -4 || $cat_id == -3) {
-                               $result = db_query($link, "SELECT
+                               $result = db_query("SELECT
                                        id, feed_url, cat_id, title, order_id, ".
                                                SUBSTRING_FOR_DATE."(last_updated,1,19) AS last_updated
                                                FROM ttrss_feeds WHERE owner_uid = " . $_SESSION["uid"] .
@@ -547,7 +599,7 @@ class API extends Handler {
                                else
                                        $cat_qpart = "cat_id IS NULL";
 
-                               $result = db_query($link, "SELECT
+                               $result = db_query("SELECT
                                        id, feed_url, cat_id, title, order_id, ".
                                                SUBSTRING_FOR_DATE."(last_updated,1,19) AS last_updated
                                                FROM ttrss_feeds WHERE
@@ -557,7 +609,7 @@ class API extends Handler {
 
                        while ($line = db_fetch_assoc($result)) {
 
-                               $unread = getFeedUnread($link, $line["id"]);
+                               $unread = getFeedUnread($line["id"]);
 
                                $has_icon = feed_has_icon($line['id']);
 
@@ -581,14 +633,35 @@ class API extends Handler {
                return $feeds;
        }
 
-       static function api_get_headlines($link, $feed_id, $limit, $offset,
+       static function api_get_headlines($feed_id, $limit, $offset,
                                $filter, $is_cat, $show_excerpt, $show_content, $view_mode, $order,
                                $include_attachments, $since_id,
-                               $search = "", $search_mode = "", $match_on = "",
-                               $include_nested = false, $sanitize_content = true) {
+                               $search = "", $search_mode = "",
+                               $include_nested = false, $sanitize_content = true, $force_update = false, $excerpt_length = 100) {
+
+                       if ($force_update && $feed_id > 0 && is_numeric($feed_id)) {
+                               // Update the feed if required with some basic flood control
+
+                               $result = db_query(
+                                       "SELECT cache_images,".SUBSTRING_FOR_DATE."(last_updated,1,19) AS last_updated
+                                               FROM ttrss_feeds WHERE id = '$feed_id'");
 
-                       $qfh_ret = queryFeedHeadlines($link, $feed_id, $limit,
-                               $view_mode, $is_cat, $search, $search_mode, $match_on,
+                               if (db_num_rows($result) != 0) {
+                                       $last_updated = strtotime(db_fetch_result($result, 0, "last_updated"));
+                                       $cache_images = sql_bool_to_bool(db_fetch_result($result, 0, "cache_images"));
+
+                                       if (!$cache_images && time() - $last_updated > 120) {
+                                               include "rssfuncs.php";
+                                               update_rss_feed($feed_id, true, true);
+                                       } else {
+                                               db_query("UPDATE ttrss_feeds SET last_updated = '1970-01-01', last_update_started = '1970-01-01'
+                                                       WHERE id = '$feed_id'");
+                                       }
+                               }
+                       }
+
+                       $qfh_ret = queryFeedHeadlines($feed_id, $limit,
+                               $view_mode, $is_cat, $search, $search_mode,
                                $order, $offset, 0, false, $since_id, $include_nested);
 
                        $result = $qfh_ret[0];
@@ -597,14 +670,34 @@ class API extends Handler {
                        $headlines = array();
 
                        while ($line = db_fetch_assoc($result)) {
+                               $line["content_preview"] = truncate_string(strip_tags($line["content"]), $excerpt_length);
+                               foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_QUERY_HEADLINES) as $p) {
+                                       $line = $p->hook_query_headlines($line, $excerpt_length, true);
+                               }
+
                                $is_updated = ($line["last_read"] == "" &&
                                        ($line["unread"] != "t" && $line["unread"] != "1"));
 
                                $tags = explode(",", $line["tag_cache"]);
-                               $labels = json_decode($line["label_cache"], true);
 
-                               //if (!$tags) $tags = get_article_tags($link, $line["id"]);
-                               //if (!$labels) $labels = get_article_labels($link, $line["id"]);
+                               $label_cache = $line["label_cache"];
+                               $labels = false;
+
+                               if ($label_cache) {
+                                       $label_cache = json_decode($label_cache, true);
+
+                                       if ($label_cache) {
+                                               if ($label_cache["no-labels"] == 1)
+                                                       $labels = array();
+                                               else
+                                                       $labels = $label_cache;
+                                       }
+                               }
+
+                               if (!is_array($labels)) $labels = get_article_labels($line["id"]);
+
+                               //if (!$tags) $tags = get_article_tags($line["id"]);
+                               //if (!$labels) $labels = get_article_labels($line["id"]);
 
                                $headline_row = array(
                                                "id" => (int)$line["id"],
@@ -619,26 +712,22 @@ class API extends Handler {
                                                "tags" => $tags,
                                        );
 
-                                       if ($include_attachments)
-                                               $headline_row['attachments'] = get_article_enclosures($link,
-                                                       $line['id']);
+                               if ($include_attachments)
+                                       $headline_row['attachments'] = get_article_enclosures(
+                                               $line['id']);
 
-                               if ($show_excerpt) {
-                                       $excerpt = truncate_string(strip_tags($line["content_preview"]), 100);
-                                       $headline_row["excerpt"] = $excerpt;
-                               }
+                               if ($show_excerpt)
+                                       $headline_row["excerpt"] = $line["content_preview"];
 
                                if ($show_content) {
 
-                                       if ($line["cached_content"] != "") {
-                                               $line["content_preview"] =& $line["cached_content"];
-                                       }
-
                                        if ($sanitize_content) {
-                                               $headline_row["content"] = sanitize($link,
-                                                       $line["content_preview"], false, false, $line["site_url"]);
+                                               $headline_row["content"] = sanitize(
+                                                       $line["content"],
+                                                       sql_bool_to_bool($line['hide_images']),
+                                                       false, $line["site_url"], false, $line["id"]);
                                        } else {
-                                               $headline_row["content"] = $line["content_preview"];
+                                               $headline_row["content"] = $line["content"];
                                        }
                                }
 
@@ -647,19 +736,98 @@ class API extends Handler {
 
                                $headline_row["labels"] = $labels;
 
-                               $headline_row["feed_title"] = $line["feed_title"];
+                               $headline_row["feed_title"] = $line["feed_title"] ? $line["feed_title"] :
+                                       $feed_title;
 
                                $headline_row["comments_count"] = (int)$line["num_comments"];
                                $headline_row["comments_link"] = $line["comments"];
 
                                $headline_row["always_display_attachments"] = sql_bool_to_bool($line["always_display_enclosures"]);
 
+                               $headline_row["author"] = $line["author"];
+
+                               $headline_row["score"] = (int)$line["score"];
+                               $headline_row["note"] = $line["note"];
+                               $headline_row["lang"] = $line["lang"];
+
+                               foreach (PluginHost::getInstance()->get_hooks(PluginHost::HOOK_RENDER_ARTICLE_API) as $p) {
+                                       $headline_row = $p->hook_render_article_api(array("headline" => $headline_row));
+                               }
+
                                array_push($headlines, $headline_row);
                        }
 
                        return $headlines;
        }
 
+       function unsubscribeFeed() {
+               $feed_id = (int) $this->dbh->escape_string($_REQUEST["feed_id"]);
+
+               $result = $this->dbh->query("SELECT id FROM ttrss_feeds WHERE
+                       id = '$feed_id' AND owner_uid = ".$_SESSION["uid"]);
+
+               if ($this->dbh->num_rows($result) != 0) {
+                       Pref_Feeds::remove_feed($feed_id, $_SESSION["uid"]);
+                       $this->wrap(self::STATUS_OK, array("status" => "OK"));
+               } else {
+                       $this->wrap(self::STATUS_ERR, array("error" => "FEED_NOT_FOUND"));
+               }
+       }
+
+       function subscribeToFeed() {
+               $feed_url = $this->dbh->escape_string($_REQUEST["feed_url"]);
+               $category_id = (int) $this->dbh->escape_string($_REQUEST["category_id"]);
+               $login = $this->dbh->escape_string($_REQUEST["login"]);
+               $password = $this->dbh->escape_string($_REQUEST["password"]);
+
+               if ($feed_url) {
+                       $rc = subscribe_to_feed($feed_url, $category_id, $login, $password);
+
+                       $this->wrap(self::STATUS_OK, array("status" => $rc));
+               } else {
+                       $this->wrap(self::STATUS_ERR, array("error" => 'INCORRECT_USAGE'));
+               }
+       }
+
+       function getFeedTree() {
+               $include_empty = sql_bool_to_bool($_REQUEST['include_empty']);
+
+               $pf = new Pref_Feeds($_REQUEST);
+
+               $_REQUEST['mode'] = 2;
+               $_REQUEST['force_show_empty'] = $include_empty;
+
+               if ($pf){
+                       $data = $pf->makefeedtree();
+                       $this->wrap(self::STATUS_OK, array("categories" => $data));
+               } else {
+                       $this->wrap(self::STATUS_ERR, array("error" =>
+                               'UNABLE_TO_INSTANTIATE_OBJECT'));
+               }
+
+       }
+
+       // only works for labels or uncategorized for the time being
+       private function isCategoryEmpty($id) {
+
+               if ($id == -2) {
+                       $result = $this->dbh->query("SELECT COUNT(*) AS count FROM ttrss_labels2
+                               WHERE owner_uid = " . $_SESSION["uid"]);
+
+                       return $this->dbh->fetch_result($result, 0, "count") == 0;
+
+               } else if ($id == 0) {
+                       $result = $this->dbh->query("SELECT COUNT(*) AS count FROM ttrss_feeds
+                               WHERE cat_id IS NULL AND owner_uid = " . $_SESSION["uid"]);
+
+                       return $this->dbh->fetch_result($result, 0, "count") == 0;
+
+               }
+
+               return false;
+       }
+
+
 }
 
 ?>