2020-01-26 13:19:35 +00:00
|
|
|
<?php declare(strict_types=1);
|
2014-01-15 23:28:40 +02:00
|
|
|
|
2013-11-29 01:09:05 +02:00
|
|
|
|
|
|
|
class _SafeOuroborosImage
|
|
|
|
{
|
|
|
|
/**
|
|
|
|
* Author
|
|
|
|
*/
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Post author
|
|
|
|
* @var string
|
|
|
|
*/
|
|
|
|
public $author = '';
|
|
|
|
/**
|
|
|
|
* Post author user ID
|
|
|
|
* @var integer
|
|
|
|
*/
|
|
|
|
public $creator_id = null;
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Image
|
|
|
|
*/
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Image height
|
|
|
|
* @var integer
|
|
|
|
*/
|
|
|
|
public $height = null;
|
|
|
|
/**
|
|
|
|
* Image width
|
|
|
|
* @var integer
|
|
|
|
*/
|
|
|
|
public $width = null;
|
2017-03-08 23:52:31 -08:00
|
|
|
/**
|
|
|
|
* File extension
|
|
|
|
* @var string
|
|
|
|
*/
|
|
|
|
public $file_ext = '';
|
2013-11-29 01:09:05 +02:00
|
|
|
/**
|
|
|
|
* File Size in bytes
|
|
|
|
* @var integer
|
|
|
|
*/
|
|
|
|
public $file_size = null;
|
|
|
|
/**
|
|
|
|
* URL to the static file
|
|
|
|
* @var string
|
|
|
|
*/
|
|
|
|
public $file_url = '';
|
|
|
|
/**
|
|
|
|
* File MD5 hash
|
|
|
|
* @var string
|
|
|
|
*/
|
|
|
|
public $md5 = '';
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Post Meta
|
|
|
|
*/
|
|
|
|
|
|
|
|
/**
|
|
|
|
* (Unknown) Change
|
|
|
|
* @var integer
|
|
|
|
*/
|
|
|
|
public $change = null;
|
|
|
|
/**
|
|
|
|
* Timestamp for post creation
|
|
|
|
* @var integer
|
|
|
|
*/
|
|
|
|
public $created_at = null;
|
|
|
|
/**
|
|
|
|
* Post ID
|
|
|
|
* @var integer
|
|
|
|
*/
|
|
|
|
public $id = null;
|
|
|
|
/**
|
|
|
|
* Parent post ID
|
|
|
|
* @var integer
|
|
|
|
*/
|
|
|
|
public $parent_id = null;
|
|
|
|
/**
|
|
|
|
* Post content rating
|
|
|
|
* @var string
|
|
|
|
*/
|
|
|
|
public $rating = 'q';
|
|
|
|
/**
|
|
|
|
* Post score
|
|
|
|
* @var integer
|
|
|
|
*/
|
|
|
|
public $score = 1;
|
|
|
|
/**
|
|
|
|
* Post source
|
|
|
|
* @var string
|
|
|
|
*/
|
|
|
|
public $source = '';
|
|
|
|
/**
|
|
|
|
* Post status
|
|
|
|
* @var string
|
|
|
|
*/
|
|
|
|
public $status = '';
|
|
|
|
/**
|
|
|
|
* Post tags
|
|
|
|
* @var string
|
|
|
|
*/
|
2015-01-05 13:47:53 +02:00
|
|
|
public $tags = 'tagme';
|
2013-11-29 01:09:05 +02:00
|
|
|
/**
|
|
|
|
* Flag if the post has child posts
|
|
|
|
* @var bool
|
|
|
|
*/
|
|
|
|
public $has_children = false;
|
|
|
|
/**
|
|
|
|
* Flag if the post has comments
|
|
|
|
* @var bool
|
|
|
|
*/
|
|
|
|
public $has_comments = false;
|
|
|
|
/**
|
|
|
|
* Flag if the post has notes
|
|
|
|
* @var bool
|
|
|
|
*/
|
|
|
|
public $has_notes = false;
|
|
|
|
/**
|
|
|
|
* Post description
|
|
|
|
* @var string
|
|
|
|
*/
|
|
|
|
public $description = '';
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Thumbnail
|
|
|
|
*/
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Thumbnail Height
|
|
|
|
* @var integer
|
|
|
|
*/
|
|
|
|
public $preview_height = null;
|
|
|
|
/**
|
|
|
|
* Thumbnail URL
|
|
|
|
* @var string
|
|
|
|
*/
|
|
|
|
public $preview_url = '';
|
|
|
|
/**
|
|
|
|
* Thumbnail Width
|
|
|
|
* @var integer
|
|
|
|
*/
|
|
|
|
public $preview_width = null;
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Downscaled Image
|
|
|
|
*/
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Downscaled image height
|
|
|
|
* @var integer
|
|
|
|
*/
|
|
|
|
public $sample_height = null;
|
|
|
|
/**
|
|
|
|
* Downscaled image
|
|
|
|
* @var string
|
|
|
|
*/
|
|
|
|
public $sample_url = '';
|
|
|
|
/**
|
|
|
|
* Downscaled image
|
|
|
|
* @var integer
|
|
|
|
*/
|
|
|
|
public $sample_width = null;
|
|
|
|
|
2017-03-08 23:52:31 -08:00
|
|
|
public function __construct(Image $img)
|
2013-11-29 01:09:05 +02:00
|
|
|
{
|
|
|
|
global $config;
|
|
|
|
// author
|
|
|
|
$author = $img->get_owner();
|
|
|
|
$this->author = $author->name;
|
|
|
|
$this->creator_id = intval($author->id);
|
|
|
|
|
|
|
|
// file
|
|
|
|
$this->height = intval($img->height);
|
|
|
|
$this->width = intval($img->width);
|
|
|
|
$this->file_ext = $img->ext;
|
|
|
|
$this->file_size = intval($img->filesize);
|
|
|
|
$this->file_url = make_http($img->get_image_link());
|
|
|
|
$this->md5 = $img->hash;
|
|
|
|
|
|
|
|
// meta
|
|
|
|
$this->change = intval($img->id); //DaFug is this even supposed to do? ChangeID?
|
|
|
|
// Should be JSON specific, just strip this when converting to XML
|
2019-05-28 17:59:38 +01:00
|
|
|
$this->created_at = ['n' => 123456789, 's' => strtotime($img->posted), 'json_class' => 'Time'];
|
2013-11-29 01:09:05 +02:00
|
|
|
$this->id = intval($img->id);
|
|
|
|
$this->parent_id = null;
|
2019-08-07 14:53:59 -05:00
|
|
|
|
|
|
|
if (Extension::is_enabled(RatingsInfo::KEY)!== false) {
|
|
|
|
// 'u' is not a "valid" rating
|
|
|
|
if ($img->rating == 's' || $img->rating == 'q' || $img->rating == 'e') {
|
|
|
|
$this->rating = $img->rating;
|
2013-11-29 01:09:05 +02:00
|
|
|
}
|
|
|
|
}
|
2019-08-07 14:53:59 -05:00
|
|
|
if (Extension::is_enabled(NumericScoreInfo::KEY)!== false) {
|
|
|
|
$this->score = $img->numeric_score;
|
|
|
|
}
|
|
|
|
|
2013-11-29 01:09:05 +02:00
|
|
|
$this->source = $img->source;
|
|
|
|
$this->status = 'active'; //not supported in Shimmie... yet
|
|
|
|
$this->tags = $img->get_tag_list();
|
|
|
|
$this->has_children = false;
|
|
|
|
$this->has_comments = false;
|
|
|
|
$this->has_notes = false;
|
|
|
|
|
|
|
|
// thumb
|
2019-06-18 13:45:59 -05:00
|
|
|
$this->preview_height = $config->get_int(ImageConfig::THUMB_HEIGHT);
|
|
|
|
$this->preview_width = $config->get_int(ImageConfig::THUMB_WIDTH);
|
2013-11-29 01:09:05 +02:00
|
|
|
$this->preview_url = make_http($img->get_thumb_link());
|
|
|
|
|
|
|
|
// sample (use the full image here)
|
|
|
|
$this->sample_height = intval($img->height);
|
|
|
|
$this->sample_width = intval($img->width);
|
|
|
|
$this->sample_url = make_http($img->get_image_link());
|
|
|
|
}
|
|
|
|
}
|
2014-01-15 23:28:40 +02:00
|
|
|
|
|
|
|
class OuroborosPost extends _SafeOuroborosImage
|
|
|
|
{
|
2013-12-03 00:45:07 +02:00
|
|
|
/**
|
|
|
|
* Multipart File
|
|
|
|
* @var array
|
|
|
|
*/
|
2019-05-28 17:59:38 +01:00
|
|
|
public $file = [];
|
2013-12-03 00:45:07 +02:00
|
|
|
|
|
|
|
/**
|
|
|
|
* Create with rating locked
|
|
|
|
* @var bool
|
|
|
|
*/
|
|
|
|
public $is_rating_locked = false;
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Create with notes locked
|
|
|
|
* @var bool
|
|
|
|
*/
|
|
|
|
public $is_note_locked = false;
|
|
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Initialize an OuroborosPost for creation
|
|
|
|
* Mainly just acts as a wrapper and validation layer
|
2020-03-13 09:23:54 +00:00
|
|
|
* @noinspection PhpMissingParentConstructorInspection
|
2013-12-03 00:45:07 +02:00
|
|
|
*/
|
2019-05-28 17:31:20 +01:00
|
|
|
public function __construct(array $post, string $md5 = '')
|
2014-01-15 23:28:40 +02:00
|
|
|
{
|
2013-12-03 00:45:07 +02:00
|
|
|
if (array_key_exists('tags', $post)) {
|
2016-07-30 22:11:49 +01:00
|
|
|
// implode(explode()) to resolve aliases and sanitise
|
|
|
|
$this->tags = Tag::implode(Tag::explode(urldecode($post['tags'])));
|
2013-12-03 00:45:07 +02:00
|
|
|
}
|
|
|
|
if (array_key_exists('file', $post)) {
|
2013-12-03 05:51:55 +02:00
|
|
|
if (!is_null($post['file'])) {
|
|
|
|
assert(is_array($post['file']));
|
|
|
|
assert(array_key_exists('tmp_name', $post['file']));
|
|
|
|
assert(array_key_exists('name', $post['file']));
|
|
|
|
$this->file = $post['file'];
|
|
|
|
}
|
2013-12-03 00:45:07 +02:00
|
|
|
}
|
|
|
|
if (array_key_exists('rating', $post)) {
|
|
|
|
assert(
|
|
|
|
$post['rating'] == 's' ||
|
|
|
|
$post['rating'] == 'q' ||
|
|
|
|
$post['rating'] == 'e'
|
|
|
|
);
|
|
|
|
$this->rating = $post['rating'];
|
|
|
|
}
|
|
|
|
if (array_key_exists('source', $post)) {
|
2015-01-05 13:47:53 +02:00
|
|
|
$this->file_url = filter_var(
|
|
|
|
urldecode($post['source']),
|
|
|
|
FILTER_SANITIZE_URL
|
|
|
|
);
|
2013-12-03 00:45:07 +02:00
|
|
|
}
|
|
|
|
if (array_key_exists('sourceurl', $post)) {
|
2015-01-05 13:47:53 +02:00
|
|
|
$this->source = filter_var(
|
|
|
|
urldecode($post['sourceurl']),
|
|
|
|
FILTER_SANITIZE_URL
|
|
|
|
);
|
2013-12-03 00:45:07 +02:00
|
|
|
}
|
|
|
|
if (array_key_exists('description', $post)) {
|
2015-01-05 13:47:53 +02:00
|
|
|
$this->description = filter_var(
|
|
|
|
$post['description'],
|
|
|
|
FILTER_SANITIZE_STRING
|
|
|
|
);
|
2013-12-03 00:45:07 +02:00
|
|
|
}
|
|
|
|
if (array_key_exists('is_rating_locked', $post)) {
|
2015-01-05 13:47:53 +02:00
|
|
|
assert(
|
|
|
|
$post['is_rating_locked'] == 'true' ||
|
|
|
|
$post['is_rating_locked'] == 'false' ||
|
|
|
|
$post['is_rating_locked'] == '1' ||
|
|
|
|
$post['is_rating_locked'] == '0'
|
|
|
|
);
|
2013-12-03 00:45:07 +02:00
|
|
|
$this->is_rating_locked = $post['is_rating_locked'];
|
|
|
|
}
|
|
|
|
if (array_key_exists('is_note_locked', $post)) {
|
2015-01-05 13:47:53 +02:00
|
|
|
assert(
|
|
|
|
$post['is_note_locked'] == 'true' ||
|
|
|
|
$post['is_note_locked'] == 'false' ||
|
|
|
|
$post['is_note_locked'] == '1' ||
|
|
|
|
$post['is_note_locked'] == '0'
|
|
|
|
);
|
2013-12-03 00:45:07 +02:00
|
|
|
$this->is_note_locked = $post['is_note_locked'];
|
|
|
|
}
|
|
|
|
if (array_key_exists('parent_id', $post)) {
|
2015-01-05 13:47:53 +02:00
|
|
|
$this->parent_id = filter_var(
|
|
|
|
$post['parent_id'],
|
|
|
|
FILTER_SANITIZE_NUMBER_INT
|
|
|
|
);
|
2013-12-03 00:45:07 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2014-01-15 23:28:40 +02:00
|
|
|
|
2013-11-29 01:09:05 +02:00
|
|
|
class _SafeOuroborosTag
|
|
|
|
{
|
|
|
|
public $ambiguous = false;
|
|
|
|
public $count = 0;
|
|
|
|
public $id = 0;
|
|
|
|
public $name = '';
|
|
|
|
public $type = 0;
|
|
|
|
|
2017-03-08 23:52:31 -08:00
|
|
|
public function __construct(array $tag)
|
2013-11-29 01:09:05 +02:00
|
|
|
{
|
|
|
|
$this->count = $tag['count'];
|
|
|
|
$this->id = $tag['id'];
|
|
|
|
$this->name = $tag['tag'];
|
|
|
|
}
|
|
|
|
}
|
2014-01-15 23:28:40 +02:00
|
|
|
|
2013-11-29 01:09:05 +02:00
|
|
|
class OuroborosAPI extends Extension
|
|
|
|
{
|
|
|
|
private $event;
|
2013-12-03 00:45:07 +02:00
|
|
|
private $type;
|
2015-01-05 13:47:53 +02:00
|
|
|
|
2013-12-03 00:45:07 +02:00
|
|
|
const HEADER_HTTP_200 = 'OK';
|
|
|
|
const MSG_HTTP_200 = 'Request was successful';
|
|
|
|
|
|
|
|
const HEADER_HTTP_403 = 'Forbidden';
|
|
|
|
const MSG_HTTP_403 = 'Access denied';
|
|
|
|
|
|
|
|
const HEADER_HTTP_404 = 'Not found';
|
|
|
|
const MSG_HTTP_404 = 'Not found';
|
|
|
|
|
|
|
|
const HEADER_HTTP_418 = 'I\'m a teapot';
|
|
|
|
const MSG_HTTP_418 = 'Short and stout';
|
|
|
|
|
|
|
|
const HEADER_HTTP_420 = 'Invalid Record';
|
|
|
|
const MSG_HTTP_420 = 'Record could not be saved';
|
|
|
|
|
|
|
|
const HEADER_HTTP_421 = 'User Throttled';
|
|
|
|
const MSG_HTTP_421 = 'User is throttled, try again later';
|
|
|
|
|
|
|
|
const HEADER_HTTP_422 = 'Locked';
|
|
|
|
const MSG_HTTP_422 = 'The resource is locked and cannot be modified';
|
|
|
|
|
|
|
|
const HEADER_HTTP_423 = 'Already Exists';
|
|
|
|
const MSG_HTTP_423 = 'Resource already exists';
|
|
|
|
|
|
|
|
const HEADER_HTTP_424 = 'Invalid Parameters';
|
|
|
|
const MSG_HTTP_424 = 'The given parameters were invalid';
|
|
|
|
|
|
|
|
const HEADER_HTTP_500 = 'Internal Server Error';
|
|
|
|
const MSG_HTTP_500 = 'Some unknown error occurred on the server';
|
|
|
|
|
|
|
|
const HEADER_HTTP_503 = 'Service Unavailable';
|
|
|
|
const MSG_HTTP_503 = 'Server cannot currently handle the request, try again later';
|
2013-11-29 01:09:05 +02:00
|
|
|
|
|
|
|
const ERROR_POST_CREATE_MD5 = 'MD5 mismatch';
|
|
|
|
const ERROR_POST_CREATE_DUPE = 'Duplicate';
|
2015-01-05 13:47:53 +02:00
|
|
|
const OK_POST_CREATE_UPDATE = 'Updated';
|
2013-11-29 01:09:05 +02:00
|
|
|
|
|
|
|
public function onPageRequest(PageRequestEvent $event)
|
|
|
|
{
|
2015-09-12 11:43:28 +01:00
|
|
|
global $page, $user;
|
2013-11-29 01:09:05 +02:00
|
|
|
|
|
|
|
if (preg_match("%\.(xml|json)$%", implode('/', $event->args), $matches) === 1) {
|
|
|
|
$this->event = $event;
|
2013-12-03 00:45:07 +02:00
|
|
|
$this->type = $matches[1];
|
|
|
|
if ($this->type == 'json') {
|
2013-11-29 01:09:05 +02:00
|
|
|
$page->set_type('application/json; charset=utf-8');
|
2014-01-15 23:28:40 +02:00
|
|
|
} elseif ($this->type == 'xml') {
|
2013-12-03 00:45:07 +02:00
|
|
|
$page->set_type('text/xml; charset=utf-8');
|
2013-11-29 01:09:05 +02:00
|
|
|
}
|
2019-06-18 20:58:28 -05:00
|
|
|
$page->set_mode(PageMode::DATA);
|
2013-12-03 00:45:07 +02:00
|
|
|
$this->tryAuth();
|
2013-11-29 01:09:05 +02:00
|
|
|
|
|
|
|
if ($event->page_matches('post')) {
|
|
|
|
if ($this->match('create')) {
|
|
|
|
// Create
|
2019-07-09 09:10:21 -05:00
|
|
|
if ($user->can(Permissions::CREATE_IMAGE)) {
|
2013-12-03 01:07:27 +02:00
|
|
|
$md5 = !empty($_REQUEST['md5']) ? filter_var($_REQUEST['md5'], FILTER_SANITIZE_STRING) : null;
|
2015-01-05 13:47:53 +02:00
|
|
|
$this->postCreate(new OuroborosPost($_REQUEST['post']), $md5);
|
2014-01-15 23:28:40 +02:00
|
|
|
} else {
|
2013-12-03 01:07:27 +02:00
|
|
|
$this->sendResponse(403, 'You cannot create new posts');
|
|
|
|
}
|
2014-01-15 23:28:40 +02:00
|
|
|
} elseif ($this->match('update')) {
|
2020-01-26 16:38:13 +00:00
|
|
|
throw new SCoreException("update not implemented");
|
2014-01-15 23:28:40 +02:00
|
|
|
} elseif ($this->match('show')) {
|
2013-11-29 01:09:05 +02:00
|
|
|
// Show
|
2013-12-03 00:45:07 +02:00
|
|
|
$id = !empty($_REQUEST['id']) ? filter_var($_REQUEST['id'], FILTER_SANITIZE_NUMBER_INT) : null;
|
|
|
|
$this->postShow($id);
|
2014-01-15 23:28:40 +02:00
|
|
|
} elseif ($this->match('index') || $this->match('list')) {
|
2013-11-29 01:09:05 +02:00
|
|
|
// List
|
2014-01-15 23:28:40 +02:00
|
|
|
$limit = !empty($_REQUEST['limit']) ? intval(
|
|
|
|
filter_var($_REQUEST['limit'], FILTER_SANITIZE_NUMBER_INT)
|
|
|
|
) : 45;
|
|
|
|
$p = !empty($_REQUEST['page']) ? intval(
|
|
|
|
filter_var($_REQUEST['page'], FILTER_SANITIZE_NUMBER_INT)
|
|
|
|
) : 1;
|
2019-05-28 17:59:38 +01:00
|
|
|
$tags = !empty($_REQUEST['tags']) ? filter_var($_REQUEST['tags'], FILTER_SANITIZE_STRING) : [];
|
2020-01-26 13:19:35 +00:00
|
|
|
if (is_string($tags)) {
|
2013-11-29 01:09:05 +02:00
|
|
|
$tags = Tag::explode($tags);
|
|
|
|
}
|
2013-12-03 00:45:07 +02:00
|
|
|
$this->postIndex($limit, $p, $tags);
|
2013-11-29 01:09:05 +02:00
|
|
|
}
|
2014-01-15 23:28:40 +02:00
|
|
|
} elseif ($event->page_matches('tag')) {
|
2013-11-29 01:09:05 +02:00
|
|
|
if ($this->match('index') || $this->match('list')) {
|
2014-01-15 23:28:40 +02:00
|
|
|
$limit = !empty($_REQUEST['limit']) ? intval(
|
|
|
|
filter_var($_REQUEST['limit'], FILTER_SANITIZE_NUMBER_INT)
|
|
|
|
) : 50;
|
|
|
|
$p = !empty($_REQUEST['page']) ? intval(
|
|
|
|
filter_var($_REQUEST['page'], FILTER_SANITIZE_NUMBER_INT)
|
|
|
|
) : 1;
|
|
|
|
$order = (!empty($_REQUEST['order']) && ($_REQUEST['order'] == 'date' || $_REQUEST['order'] == 'count' || $_REQUEST['order'] == 'name')) ? filter_var(
|
|
|
|
$_REQUEST['order'],
|
|
|
|
FILTER_SANITIZE_STRING
|
|
|
|
) : 'date';
|
|
|
|
$id = !empty($_REQUEST['id']) ? intval(
|
|
|
|
filter_var($_REQUEST['id'], FILTER_SANITIZE_NUMBER_INT)
|
|
|
|
) : null;
|
|
|
|
$after_id = !empty($_REQUEST['after_id']) ? intval(
|
|
|
|
filter_var($_REQUEST['after_id'], FILTER_SANITIZE_NUMBER_INT)
|
|
|
|
) : null;
|
2013-11-29 01:09:05 +02:00
|
|
|
$name = !empty($_REQUEST['name']) ? filter_var($_REQUEST['name'], FILTER_SANITIZE_STRING) : '';
|
2014-01-15 23:28:40 +02:00
|
|
|
$name_pattern = !empty($_REQUEST['name_pattern']) ? filter_var(
|
|
|
|
$_REQUEST['name_pattern'],
|
|
|
|
FILTER_SANITIZE_STRING
|
|
|
|
) : '';
|
2013-12-03 00:45:07 +02:00
|
|
|
$this->tagIndex($limit, $p, $order, $id, $after_id, $name, $name_pattern);
|
|
|
|
}
|
|
|
|
}
|
2014-01-15 23:28:40 +02:00
|
|
|
} elseif ($event->page_matches('post/show')) {
|
2019-06-18 20:58:28 -05:00
|
|
|
$page->set_mode(PageMode::REDIRECT);
|
2014-01-15 23:28:40 +02:00
|
|
|
$page->set_redirect(make_link(str_replace('post/show', 'post/view', implode('/', $event->args))));
|
|
|
|
$page->display();
|
|
|
|
die();
|
2013-12-03 00:45:07 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Post
|
|
|
|
*/
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Wrapper for post creation
|
|
|
|
*/
|
2020-01-26 13:19:35 +00:00
|
|
|
protected function postCreate(OuroborosPost $post, ?string $md5 = '')
|
2014-01-15 23:28:40 +02:00
|
|
|
{
|
2015-09-12 11:43:28 +01:00
|
|
|
global $config;
|
2019-06-18 13:45:59 -05:00
|
|
|
$handler = $config->get_string(ImageConfig::UPLOAD_COLLISION_HANDLER);
|
|
|
|
if (!empty($md5) && !($handler == ImageConfig::COLLISION_MERGE)) {
|
2013-12-03 00:45:07 +02:00
|
|
|
$img = Image::by_hash($md5);
|
|
|
|
if (!is_null($img)) {
|
|
|
|
$this->sendResponse(420, self::ERROR_POST_CREATE_DUPE);
|
2014-01-15 23:28:40 +02:00
|
|
|
return;
|
2013-12-03 00:45:07 +02:00
|
|
|
}
|
|
|
|
}
|
2019-05-28 17:59:38 +01:00
|
|
|
$meta = [];
|
2017-05-13 18:01:31 -07:00
|
|
|
$meta['tags'] = is_array($post->tags) ? $post->tags : Tag::explode($post->tags);
|
2013-12-03 00:45:07 +02:00
|
|
|
$meta['source'] = $post->source;
|
2019-08-07 14:53:59 -05:00
|
|
|
if (Extension::is_enabled(RatingsInfo::KEY)!== false) {
|
|
|
|
$meta['rating'] = $post->rating;
|
2013-12-03 00:45:07 +02:00
|
|
|
}
|
|
|
|
// Check where we should try for the file
|
2014-01-15 23:28:40 +02:00
|
|
|
if (empty($post->file) && !empty($post->file_url) && filter_var(
|
2019-05-28 17:59:38 +01:00
|
|
|
$post->file_url,
|
|
|
|
FILTER_VALIDATE_URL
|
2019-11-02 19:57:34 +00:00
|
|
|
) !== false
|
2014-01-15 23:28:40 +02:00
|
|
|
) {
|
2013-12-03 00:45:07 +02:00
|
|
|
// Transload from source
|
2014-01-15 23:28:40 +02:00
|
|
|
$meta['file'] = tempnam('/tmp', 'shimmie_transload_' . $config->get_string('transload_engine'));
|
2013-12-03 00:45:07 +02:00
|
|
|
$meta['filename'] = basename($post->file_url);
|
2014-01-15 23:28:40 +02:00
|
|
|
if (!transload($post->file_url, $meta['file'])) {
|
|
|
|
$this->sendResponse(500, 'Transloading failed');
|
|
|
|
return;
|
2013-12-03 00:45:07 +02:00
|
|
|
}
|
|
|
|
$meta['hash'] = md5_file($meta['file']);
|
2014-01-15 23:28:40 +02:00
|
|
|
} else {
|
2013-12-03 00:45:07 +02:00
|
|
|
// Use file
|
|
|
|
$meta['file'] = $post->file['tmp_name'];
|
|
|
|
$meta['filename'] = $post->file['name'];
|
|
|
|
$meta['hash'] = md5_file($meta['file']);
|
|
|
|
}
|
|
|
|
if (!empty($md5) && $md5 !== $meta['hash']) {
|
|
|
|
$this->sendResponse(420, self::ERROR_POST_CREATE_MD5);
|
2014-01-15 23:28:40 +02:00
|
|
|
return;
|
2013-12-03 00:45:07 +02:00
|
|
|
}
|
|
|
|
if (!empty($meta['hash'])) {
|
|
|
|
$img = Image::by_hash($meta['hash']);
|
|
|
|
if (!is_null($img)) {
|
2019-06-18 13:45:59 -05:00
|
|
|
$handler = $config->get_string(ImageConfig::UPLOAD_COLLISION_HANDLER);
|
|
|
|
if ($handler == ImageConfig::COLLISION_MERGE) {
|
2017-05-13 23:18:47 -07:00
|
|
|
$postTags = is_array($post->tags) ? $post->tags : Tag::explode($post->tags);
|
|
|
|
$merged = array_merge($postTags, $img->get_tag_array());
|
2015-01-05 13:47:53 +02:00
|
|
|
send_event(new TagSetEvent($img, $merged));
|
|
|
|
|
|
|
|
// This is really the only thing besides tags we should care
|
2019-05-28 17:59:38 +01:00
|
|
|
if (isset($meta['source'])) {
|
2015-01-05 13:47:53 +02:00
|
|
|
send_event(new SourceSetEvent($img, $meta['source']));
|
|
|
|
}
|
|
|
|
$this->sendResponse(200, self::OK_POST_CREATE_UPDATE . ' ID: ' . $img->id);
|
|
|
|
return;
|
2019-05-28 17:59:38 +01:00
|
|
|
} else {
|
2015-01-05 13:47:53 +02:00
|
|
|
$this->sendResponse(420, self::ERROR_POST_CREATE_DUPE);
|
|
|
|
return;
|
|
|
|
}
|
2013-12-03 00:45:07 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
$meta['extension'] = pathinfo($meta['filename'], PATHINFO_EXTENSION);
|
|
|
|
try {
|
|
|
|
$upload = new DataUploadEvent($meta['file'], $meta);
|
|
|
|
send_event($upload);
|
|
|
|
$image = Image::by_hash($meta['hash']);
|
|
|
|
if (!is_null($image)) {
|
2014-01-15 23:28:40 +02:00
|
|
|
$this->sendResponse(200, make_link('post/view/' . $image->id), true);
|
|
|
|
return;
|
|
|
|
} else {
|
2013-12-03 00:45:07 +02:00
|
|
|
// Fail, unsupported file?
|
|
|
|
$this->sendResponse(500, 'Unknown error');
|
2014-01-15 23:28:40 +02:00
|
|
|
return;
|
2013-12-03 00:45:07 +02:00
|
|
|
}
|
|
|
|
} catch (UploadException $e) {
|
|
|
|
// Cleanup in case shit hit the fan
|
|
|
|
$this->sendResponse(500, $e->getMessage());
|
2014-01-15 23:28:40 +02:00
|
|
|
return;
|
2013-12-03 00:45:07 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Wrapper for getting a single post
|
|
|
|
*/
|
2019-05-28 17:31:20 +01:00
|
|
|
protected function postShow(int $id = null)
|
2014-01-15 23:28:40 +02:00
|
|
|
{
|
2013-12-03 00:45:07 +02:00
|
|
|
if (!is_null($id)) {
|
2015-01-05 13:47:53 +02:00
|
|
|
$post = new _SafeOuroborosImage(Image::by_id($id));
|
2019-05-29 18:23:29 +01:00
|
|
|
$this->sendData('post', [$post]);
|
2015-01-05 13:47:53 +02:00
|
|
|
} else {
|
|
|
|
$this->sendResponse(424, 'ID is mandatory');
|
|
|
|
}
|
|
|
|
}
|
2013-12-03 00:45:07 +02:00
|
|
|
|
|
|
|
/**
|
|
|
|
* Wrapper for getting a list of posts
|
2019-05-28 17:31:20 +01:00
|
|
|
* #param string[] $tags
|
2013-12-03 00:45:07 +02:00
|
|
|
*/
|
2019-05-28 17:31:20 +01:00
|
|
|
protected function postIndex(int $limit, int $page, array $tags)
|
2014-01-15 23:28:40 +02:00
|
|
|
{
|
|
|
|
$start = ($page - 1) * $limit;
|
2013-12-03 00:45:07 +02:00
|
|
|
$results = Image::find_images(max($start, 0), min($limit, 100), $tags);
|
2019-05-28 17:59:38 +01:00
|
|
|
$posts = [];
|
2013-12-03 00:45:07 +02:00
|
|
|
foreach ($results as $img) {
|
|
|
|
if (!is_object($img)) {
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
$posts[] = new _SafeOuroborosImage($img);
|
|
|
|
}
|
|
|
|
$this->sendData('post', $posts, max($start, 0));
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Tag
|
|
|
|
*/
|
|
|
|
|
2019-05-28 17:31:20 +01:00
|
|
|
protected function tagIndex(int $limit, int $page, string $order, int $id, int $after_id, string $name, string $name_pattern)
|
2014-01-15 23:28:40 +02:00
|
|
|
{
|
2013-12-03 00:45:07 +02:00
|
|
|
global $database, $config;
|
2014-01-15 23:28:40 +02:00
|
|
|
$start = ($page - 1) * $limit;
|
2013-12-03 00:45:07 +02:00
|
|
|
switch ($order) {
|
|
|
|
case 'name':
|
2014-01-15 23:28:40 +02:00
|
|
|
$tag_data = $database->get_col(
|
2020-02-01 22:44:50 +00:00
|
|
|
"
|
|
|
|
SELECT DISTINCT
|
|
|
|
id, LOWER(substr(tag, 1, 1)), count
|
|
|
|
FROM tags
|
|
|
|
WHERE count >= :tags_min
|
|
|
|
ORDER BY LOWER(substr(tag, 1, 1)) LIMIT :start, :max_items
|
|
|
|
",
|
2019-07-13 21:18:45 -05:00
|
|
|
['tags_min' => $config->get_int(TagListConfig::TAGS_MIN), 'start' => $start, 'max_items' => $limit]
|
2014-01-15 23:28:40 +02:00
|
|
|
);
|
2013-12-03 00:45:07 +02:00
|
|
|
break;
|
|
|
|
case 'count':
|
2019-10-02 11:23:57 +01:00
|
|
|
default:
|
2014-01-15 23:28:40 +02:00
|
|
|
$tag_data = $database->get_all(
|
|
|
|
"
|
|
|
|
SELECT id, tag, count
|
|
|
|
FROM tags
|
|
|
|
WHERE count >= :tags_min
|
|
|
|
ORDER BY count DESC, tag ASC LIMIT :start, :max_items
|
|
|
|
",
|
2019-07-13 21:18:45 -05:00
|
|
|
['tags_min' => $config->get_int(TagListConfig::TAGS_MIN), 'start' => $start, 'max_items' => $limit]
|
2014-01-15 23:28:40 +02:00
|
|
|
);
|
2013-12-03 00:45:07 +02:00
|
|
|
break;
|
|
|
|
}
|
2019-05-28 17:59:38 +01:00
|
|
|
$tags = [];
|
2013-12-03 00:45:07 +02:00
|
|
|
foreach ($tag_data as $tag) {
|
|
|
|
if (!is_array($tag)) {
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
$tags[] = new _SafeOuroborosTag($tag);
|
|
|
|
}
|
|
|
|
$this->sendData('tag', $tags, $start);
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Utility methods
|
|
|
|
*/
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Sends a simple {success,reason} message to browser
|
|
|
|
*/
|
2019-05-28 17:31:20 +01:00
|
|
|
private function sendResponse(int $code = 200, string $reason = '', bool $location = false)
|
2014-01-15 23:28:40 +02:00
|
|
|
{
|
2013-12-03 00:45:07 +02:00
|
|
|
global $page;
|
|
|
|
if ($code == 200) {
|
|
|
|
$success = true;
|
2014-01-15 23:28:40 +02:00
|
|
|
} else {
|
2013-12-03 00:45:07 +02:00
|
|
|
$success = false;
|
|
|
|
}
|
|
|
|
if (empty($reason)) {
|
|
|
|
if (defined("self::MSG_HTTP_{$code}")) {
|
|
|
|
$reason = constant("self::MSG_HTTP_{$code}");
|
2014-01-15 23:28:40 +02:00
|
|
|
} else {
|
2013-12-03 00:45:07 +02:00
|
|
|
$reason = self::MSG_HTTP_418;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if ($code != 200) {
|
|
|
|
$proto = $_SERVER['SERVER_PROTOCOL'];
|
|
|
|
if (defined("self::HEADER_HTTP_{$code}")) {
|
|
|
|
$header = constant("self::HEADER_HTTP_{$code}");
|
2014-01-15 23:28:40 +02:00
|
|
|
} else {
|
2013-12-03 00:45:07 +02:00
|
|
|
// I'm a teapot!
|
|
|
|
$code = 418;
|
|
|
|
$header = self::HEADER_HTTP_418;
|
|
|
|
}
|
|
|
|
header("{$proto} {$code} {$header}", true);
|
|
|
|
}
|
2019-05-28 17:59:38 +01:00
|
|
|
$response = ['success' => $success, 'reason' => $reason];
|
2013-12-03 00:45:07 +02:00
|
|
|
if ($this->type == 'json') {
|
|
|
|
if ($location !== false) {
|
|
|
|
$response['location'] = $response['reason'];
|
|
|
|
unset($response['reason']);
|
|
|
|
}
|
|
|
|
$response = json_encode($response);
|
2014-01-15 23:28:40 +02:00
|
|
|
} elseif ($this->type == 'xml') {
|
2013-12-03 00:45:07 +02:00
|
|
|
// Seriously, XML sucks...
|
|
|
|
$xml = new XMLWriter();
|
|
|
|
$xml->openMemory();
|
|
|
|
$xml->startDocument('1.0', 'utf-8');
|
|
|
|
$xml->startElement('response');
|
|
|
|
$xml->writeAttribute('success', var_export($success, true));
|
|
|
|
if ($location !== false) {
|
|
|
|
$xml->writeAttribute('location', $reason);
|
2014-01-15 23:28:40 +02:00
|
|
|
} else {
|
2013-12-03 00:45:07 +02:00
|
|
|
$xml->writeAttribute('reason', $reason);
|
|
|
|
}
|
|
|
|
$xml->endElement();
|
|
|
|
$xml->endDocument();
|
|
|
|
$response = $xml->outputMemory(true);
|
|
|
|
unset($xml);
|
|
|
|
}
|
|
|
|
$page->set_data($response);
|
|
|
|
}
|
|
|
|
|
2019-05-28 17:59:38 +01:00
|
|
|
private function sendData(string $type = '', array $data = [], int $offset = 0)
|
2014-01-15 23:28:40 +02:00
|
|
|
{
|
2013-12-03 00:45:07 +02:00
|
|
|
global $page;
|
|
|
|
$response = '';
|
|
|
|
if ($this->type == 'json') {
|
|
|
|
$response = json_encode($data);
|
2014-01-15 23:28:40 +02:00
|
|
|
} elseif ($this->type == 'xml') {
|
2013-12-03 00:45:07 +02:00
|
|
|
$xml = new XMLWriter();
|
|
|
|
$xml->openMemory();
|
|
|
|
$xml->startDocument('1.0', 'utf-8');
|
|
|
|
if (array_key_exists(0, $data)) {
|
2014-01-15 23:28:40 +02:00
|
|
|
$xml->startElement($type . 's');
|
2013-12-03 00:45:07 +02:00
|
|
|
if ($type == 'post') {
|
|
|
|
$xml->writeAttribute('count', count($data));
|
|
|
|
$xml->writeAttribute('offset', $offset);
|
|
|
|
}
|
|
|
|
if ($type == 'tag') {
|
|
|
|
$xml->writeAttribute('type', 'array');
|
2013-11-29 01:09:05 +02:00
|
|
|
}
|
2013-12-03 00:45:07 +02:00
|
|
|
foreach ($data as $item) {
|
|
|
|
$this->createItemXML($xml, $type, $item);
|
|
|
|
}
|
|
|
|
$xml->endElement();
|
2014-01-15 23:28:40 +02:00
|
|
|
} else {
|
2013-12-03 00:45:07 +02:00
|
|
|
$this->createItemXML($xml, $type, $data);
|
2013-11-29 01:09:05 +02:00
|
|
|
}
|
2013-12-03 00:45:07 +02:00
|
|
|
$xml->endDocument();
|
|
|
|
$response = $xml->outputMemory(true);
|
|
|
|
unset($xml);
|
2013-11-29 01:09:05 +02:00
|
|
|
}
|
2013-12-03 00:45:07 +02:00
|
|
|
$page->set_data($response);
|
2013-11-29 01:09:05 +02:00
|
|
|
}
|
|
|
|
|
2019-05-28 17:31:20 +01:00
|
|
|
private function createItemXML(XMLWriter &$xml, string $type, $item)
|
2014-01-15 23:28:40 +02:00
|
|
|
{
|
2013-12-03 00:45:07 +02:00
|
|
|
$xml->startElement($type);
|
|
|
|
foreach ($item as $key => $val) {
|
|
|
|
if ($key == 'created_at' && $type == 'post') {
|
|
|
|
$xml->writeAttribute($key, $val['s']);
|
2014-01-15 23:28:40 +02:00
|
|
|
} else {
|
2013-12-03 00:45:07 +02:00
|
|
|
if (is_bool($val)) {
|
|
|
|
$val = $val ? 'true' : 'false';
|
|
|
|
}
|
|
|
|
$xml->writeAttribute($key, $val);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
$xml->endElement();
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Try to figure who is uploading
|
|
|
|
*
|
|
|
|
* Currently checks for either user & session in request or cookies
|
|
|
|
* and initializes a global User
|
|
|
|
*/
|
2014-01-15 23:28:40 +02:00
|
|
|
private function tryAuth()
|
|
|
|
{
|
2013-12-03 00:45:07 +02:00
|
|
|
global $config, $user;
|
|
|
|
|
|
|
|
if (isset($_REQUEST['user']) && isset($_REQUEST['session'])) {
|
|
|
|
//Auth by session data from query
|
|
|
|
$name = $_REQUEST['user'];
|
|
|
|
$session = $_REQUEST['session'];
|
|
|
|
$duser = User::by_session($name, $session);
|
|
|
|
if (!is_null($duser)) {
|
|
|
|
$user = $duser;
|
2014-01-15 23:28:40 +02:00
|
|
|
} else {
|
2013-12-03 00:45:07 +02:00
|
|
|
$user = User::by_id($config->get_int("anon_id", 0));
|
|
|
|
}
|
2019-07-04 12:48:33 -05:00
|
|
|
send_event(new UserLoginEvent($user));
|
2014-01-15 23:28:40 +02:00
|
|
|
} elseif (isset($_COOKIE[$config->get_string('cookie_prefix', 'shm') . '_' . 'session']) &&
|
|
|
|
isset($_COOKIE[$config->get_string('cookie_prefix', 'shm') . '_' . 'user'])
|
2013-12-03 00:45:07 +02:00
|
|
|
) {
|
|
|
|
//Auth by session data from cookies
|
2014-01-15 23:28:40 +02:00
|
|
|
$session = $_COOKIE[$config->get_string('cookie_prefix', 'shm') . '_' . 'session'];
|
|
|
|
$user = $_COOKIE[$config->get_string('cookie_prefix', 'shm') . '_' . 'user'];
|
2013-12-03 00:45:07 +02:00
|
|
|
$duser = User::by_session($user, $session);
|
|
|
|
if (!is_null($duser)) {
|
|
|
|
$user = $duser;
|
2014-01-15 23:28:40 +02:00
|
|
|
} else {
|
2013-12-03 00:45:07 +02:00
|
|
|
$user = User::by_id($config->get_int("anon_id", 0));
|
|
|
|
}
|
2019-07-04 12:48:33 -05:00
|
|
|
send_event(new UserLoginEvent($user));
|
2013-12-03 00:45:07 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Helper for matching API methods from event
|
|
|
|
*/
|
2019-05-28 17:31:20 +01:00
|
|
|
private function match(string $page): bool
|
2014-01-15 23:28:40 +02:00
|
|
|
{
|
2013-11-29 01:09:05 +02:00
|
|
|
return (preg_match("%{$page}\.(xml|json)$%", implode('/', $this->event->args), $matches) === 1);
|
|
|
|
}
|
|
|
|
}
|