2011-07-19 10:17:58 -04:00
< ? php
2018-02-25 19:45:04 -05:00
2011-07-19 10:17:58 -04:00
/* ACL selector json backend */
2012-06-05 23:33:11 -04:00
2017-04-30 00:07:00 -04:00
use Friendica\App ;
2018-02-25 19:45:04 -05:00
use Friendica\Content\Widget ;
2018-03-02 18:41:24 -05:00
use Friendica\Core\ACL ;
2018-12-26 01:06:24 -05:00
use Friendica\Core\Hook ;
2018-10-29 17:20:46 -04:00
use Friendica\Core\Logger ;
2018-08-11 16:40:44 -04:00
use Friendica\Core\Protocol ;
2018-07-20 08:19:26 -04:00
use Friendica\Database\DBA ;
2018-02-25 19:45:04 -05:00
use Friendica\Model\Contact ;
2018-06-12 05:05:36 -04:00
use Friendica\Model\Item ;
2018-07-30 22:06:22 -04:00
use Friendica\Util\Proxy as ProxyUtils ;
2018-11-08 10:14:37 -05:00
use Friendica\Util\Strings ;
2017-04-30 00:07:00 -04:00
2018-02-25 19:45:04 -05:00
function acl_content ( App $a )
{
if ( ! local_user ()) {
return '' ;
}
2018-02-25 20:24:46 -05:00
$start = defaults ( $_REQUEST , 'start' , 0 );
$count = defaults ( $_REQUEST , 'count' , 100 );
$search = defaults ( $_REQUEST , 'search' , '' );
$type = defaults ( $_REQUEST , 'type' , '' );
2018-02-25 19:45:04 -05:00
$conv_id = defaults ( $_REQUEST , 'conversation' , null );
// For use with jquery.textcomplete for private mail completion
2018-02-25 20:24:46 -05:00
if ( ! empty ( $_REQUEST [ 'query' ])) {
2018-02-25 19:45:04 -05:00
if ( ! $type ) {
$type = 'm' ;
}
$search = $_REQUEST [ 'query' ];
}
2018-12-30 15:42:56 -05:00
Logger :: info ( 'ACL {action} - {subaction}' , [ 'module' => 'acl' , 'action' => 'content' , 'subaction' => 'search' , 'search' => $search , 'type' => $type , 'conversation' => $conv_id ]);
2018-02-25 19:45:04 -05:00
if ( $search != '' ) {
2018-07-21 09:10:13 -04:00
$sql_extra = " AND `name` LIKE '%% " . DBA :: escape ( $search ) . " %%' " ;
$sql_extra2 = " AND (`attag` LIKE '%% " . DBA :: escape ( $search ) . " %%' OR `name` LIKE '%% " . DBA :: escape ( $search ) . " %%' OR `nick` LIKE '%% " . DBA :: escape ( $search ) . " %%') " ;
2018-02-25 19:45:04 -05:00
} else {
/// @TODO Avoid these needless else blocks by putting variable-initialization atop of if()
$sql_extra = $sql_extra2 = '' ;
}
// count groups and contacts
2018-02-25 20:24:46 -05:00
$group_count = 0 ;
2018-02-25 19:45:04 -05:00
if ( $type == '' || $type == 'g' ) {
2019-01-12 08:28:14 -05:00
$r = q ( " SELECT COUNT(*) AS g FROM `group` WHERE NOT `deleted` AND `uid` = %d $sql_extra " ,
2018-02-25 19:45:04 -05:00
intval ( local_user ())
);
$group_count = ( int ) $r [ 0 ][ 'g' ];
}
$sql_extra2 .= ' ' . Widget :: unavailableNetworks ();
2018-02-25 20:24:46 -05:00
$contact_count = 0 ;
2018-02-25 19:45:04 -05:00
if ( $type == '' || $type == 'c' ) {
// autocomplete for editor mentions
$r = q ( " SELECT COUNT(*) AS c FROM `contact`
2019-01-12 08:28:14 -05:00
WHERE `uid` = % d AND NOT `self` AND NOT `deleted`
2018-02-25 19:45:04 -05:00
AND NOT `blocked` AND NOT `pending` AND NOT `archive`
AND `notify` != '' $sql_extra2 " ,
intval ( local_user ())
);
$contact_count = ( int ) $r [ 0 ][ 'c' ];
} elseif ( $type == 'f' ) {
// autocomplete for editor mentions of forums
$r = q ( " SELECT COUNT(*) AS c FROM `contact`
2019-01-12 08:28:14 -05:00
WHERE `uid` = % d AND NOT `self` AND NOT `deleted`
2018-02-25 19:45:04 -05:00
AND NOT `blocked` AND NOT `pending` AND NOT `archive`
AND ( `forum` OR `prv` )
AND `notify` != '' $sql_extra2 " ,
intval ( local_user ())
);
$contact_count = ( int ) $r [ 0 ][ 'c' ];
} elseif ( $type == 'm' ) {
// autocomplete for Private Messages
$r = q ( " SELECT COUNT(*) AS c FROM `contact`
2019-01-12 08:28:14 -05:00
WHERE `uid` = % d AND NOT `self` AND NOT `deleted`
2018-02-25 19:45:04 -05:00
AND NOT `blocked` AND NOT `pending` AND NOT `archive`
2018-10-05 23:17:44 -04:00
AND `network` IN ( '%s' , '%s' , '%s' ) $sql_extra2 " ,
2018-02-25 19:45:04 -05:00
intval ( local_user ()),
2018-10-05 23:17:44 -04:00
DBA :: escape ( Protocol :: ACTIVITYPUB ),
2018-08-11 16:40:44 -04:00
DBA :: escape ( Protocol :: DFRN ),
DBA :: escape ( Protocol :: DIASPORA )
2018-02-25 19:45:04 -05:00
);
$contact_count = ( int ) $r [ 0 ][ 'c' ];
} elseif ( $type == 'a' ) {
// autocomplete for Contacts
$r = q ( " SELECT COUNT(*) AS c FROM `contact`
WHERE `uid` = % d AND NOT `self`
2019-01-12 08:28:14 -05:00
AND NOT `pending` AND NOT `deleted` $sql_extra2 " ,
2018-02-25 19:45:04 -05:00
intval ( local_user ())
);
$contact_count = ( int ) $r [ 0 ][ 'c' ];
}
$tot = $group_count + $contact_count ;
$groups = [];
$contacts = [];
if ( $type == '' || $type == 'g' ) {
/// @todo We should cache this query.
// This can be done when we can delete cache entries via wildcard
$r = q ( " SELECT `group`.`id`, `group`.`name`, GROUP_CONCAT(DISTINCT `group_member`.`contact-id` SEPARATOR ',') AS uids
FROM `group`
INNER JOIN `group_member` ON `group_member` . `gid` = `group` . `id`
WHERE NOT `group` . `deleted` AND `group` . `uid` = % d
$sql_extra
GROUP BY `group` . `name` , `group` . `id`
ORDER BY `group` . `name`
LIMIT % d , % d " ,
intval ( local_user ()),
intval ( $start ),
intval ( $count )
);
2016-02-07 09:11:34 -05:00
2018-02-25 19:45:04 -05:00
foreach ( $r as $g ) {
$groups [] = [
2018-02-25 20:24:46 -05:00
'type' => 'g' ,
2018-02-25 19:45:04 -05:00
'photo' => 'images/twopeople.png' ,
2018-11-25 14:48:26 -05:00
'name' => htmlspecialchars ( $g [ 'name' ]),
2018-02-25 20:24:46 -05:00
'id' => intval ( $g [ 'id' ]),
'uids' => array_map ( 'intval' , explode ( ',' , $g [ 'uids' ])),
'link' => '' ,
2018-02-25 19:45:04 -05:00
'forum' => '0'
];
}
if (( count ( $groups ) > 0 ) && ( $search == '' )) {
$groups [] = [ 'separator' => true ];
}
}
2016-02-07 09:11:34 -05:00
2018-02-25 20:24:46 -05:00
$r = [];
2018-02-25 19:45:04 -05:00
if ( $type == '' ) {
$r = q ( " SELECT `id`, `name`, `nick`, `micro`, `network`, `url`, `attag`, `addr`, `forum`, `prv`, (`prv` OR `forum`) AS `frm` FROM `contact`
2019-01-12 08:28:14 -05:00
WHERE `uid` = % d AND NOT `self` AND NOT `deleted` AND NOT `blocked` AND NOT `pending` AND NOT `archive` AND `notify` != ''
2019-07-20 13:34:08 -04:00
AND NOT ( `network` IN ( '%s' , '%s' ))
2018-02-25 20:24:46 -05:00
$sql_extra2
ORDER BY `name` ASC " ,
2018-02-25 19:45:04 -05:00
intval ( local_user ()),
2018-08-11 16:40:44 -04:00
DBA :: escape ( Protocol :: OSTATUS ),
DBA :: escape ( Protocol :: STATUSNET )
2018-02-25 19:45:04 -05:00
);
} elseif ( $type == 'c' ) {
$r = q ( " SELECT `id`, `name`, `nick`, `micro`, `network`, `url`, `attag`, `addr`, `forum`, `prv` FROM `contact`
2019-01-12 08:28:14 -05:00
WHERE `uid` = % d AND NOT `self` AND NOT `deleted` AND NOT `blocked` AND NOT `pending` AND NOT `archive` AND `notify` != ''
2019-07-20 13:34:08 -04:00
AND NOT ( `network` IN ( '%s' ))
2018-02-25 20:24:46 -05:00
$sql_extra2
ORDER BY `name` ASC " ,
2018-02-25 19:45:04 -05:00
intval ( local_user ()),
2018-08-11 16:40:44 -04:00
DBA :: escape ( Protocol :: STATUSNET )
2018-02-25 19:45:04 -05:00
);
} elseif ( $type == 'f' ) {
$r = q ( " SELECT `id`, `name`, `nick`, `micro`, `network`, `url`, `attag`, `addr`, `forum`, `prv` FROM `contact`
2019-01-12 08:28:14 -05:00
WHERE `uid` = % d AND NOT `self` AND NOT `deleted` AND NOT `blocked` AND NOT `pending` AND NOT `archive` AND `notify` != ''
2019-07-20 13:34:08 -04:00
AND NOT ( `network` IN ( '%s' ))
2018-02-25 20:24:46 -05:00
AND ( `forum` OR `prv` )
$sql_extra2
ORDER BY `name` ASC " ,
2018-02-25 19:45:04 -05:00
intval ( local_user ()),
2018-08-11 16:40:44 -04:00
DBA :: escape ( Protocol :: STATUSNET )
2018-02-25 19:45:04 -05:00
);
} elseif ( $type == 'm' ) {
$r = q ( " SELECT `id`, `name`, `nick`, `micro`, `network`, `url`, `attag`, `addr` FROM `contact`
2019-01-12 08:28:14 -05:00
WHERE `uid` = % d AND NOT `self` AND NOT `deleted` AND NOT `blocked` AND NOT `pending` AND NOT `archive`
2019-07-20 13:34:08 -04:00
AND `network` IN ( '%s' , '%s' , '%s' )
2018-02-25 20:24:46 -05:00
$sql_extra2
ORDER BY `name` ASC " ,
2018-02-25 19:45:04 -05:00
intval ( local_user ()),
2018-10-05 23:17:44 -04:00
DBA :: escape ( Protocol :: ACTIVITYPUB ),
2018-08-11 16:40:44 -04:00
DBA :: escape ( Protocol :: DFRN ),
DBA :: escape ( Protocol :: DIASPORA )
2018-02-25 19:45:04 -05:00
);
} elseif ( $type == 'a' ) {
$r = q ( " SELECT `id`, `name`, `nick`, `micro`, `network`, `url`, `attag`, `addr`, `forum`, `prv` FROM `contact`
2019-07-20 13:34:08 -04:00
WHERE `uid` = % d AND NOT `deleted` AND NOT `pending` AND NOT `archive`
2018-02-25 20:24:46 -05:00
$sql_extra2
ORDER BY `name` ASC " ,
2018-02-25 19:45:04 -05:00
intval ( local_user ())
);
} elseif ( $type == 'x' ) {
// autocomplete for global contact search (e.g. navbar search)
2018-11-09 13:29:42 -05:00
$search = Strings :: escapeTags ( trim ( $_REQUEST [ 'search' ]));
2018-02-25 20:04:30 -05:00
$mode = $_REQUEST [ 'smode' ];
2019-09-13 20:06:57 -04:00
$page = $_REQUEST [ 'page' ] ? ? 1 ;
2018-02-25 20:04:30 -05:00
2019-09-13 20:06:57 -04:00
$r = ACL :: contactAutocomplete ( $search , $mode , $page );
2018-02-25 20:04:30 -05:00
2018-02-25 19:45:04 -05:00
$contacts = [];
foreach ( $r as $g ) {
$contacts [] = [
2018-07-30 22:06:22 -04:00
'photo' => ProxyUtils :: proxifyUrl ( $g [ 'photo' ], false , ProxyUtils :: SIZE_MICRO ),
2018-11-25 14:48:26 -05:00
'name' => htmlspecialchars ( $g [ 'name' ]),
2018-02-25 20:24:46 -05:00
'nick' => defaults ( $g , 'addr' , $g [ 'url' ]),
2018-02-25 19:45:04 -05:00
'network' => $g [ 'network' ],
'link' => $g [ 'url' ],
2018-02-25 20:24:46 -05:00
'forum' => ! empty ( $g [ 'community' ]) ? 1 : 0 ,
2018-02-25 19:45:04 -05:00
];
}
$o = [
'start' => $start ,
'count' => $count ,
'items' => $contacts ,
];
echo json_encode ( $o );
2018-02-25 20:24:46 -05:00
exit ;
2018-02-25 19:45:04 -05:00
}
2018-07-21 08:46:04 -04:00
if ( DBA :: isResult ( $r )) {
2018-02-25 19:45:04 -05:00
$forums = [];
foreach ( $r as $g ) {
$entry = [
'type' => 'c' ,
2018-07-30 22:06:22 -04:00
'photo' => ProxyUtils :: proxifyUrl ( $g [ 'micro' ], false , ProxyUtils :: SIZE_MICRO ),
2018-11-25 14:48:26 -05:00
'name' => htmlspecialchars ( $g [ 'name' ]),
2018-02-25 19:45:04 -05:00
'id' => intval ( $g [ 'id' ]),
'network' => $g [ 'network' ],
'link' => $g [ 'url' ],
2018-02-25 20:24:46 -05:00
'nick' => htmlentities ( defaults ( $g , 'attag' , $g [ 'nick' ])),
'addr' => htmlentities ( defaults ( $g , 'addr' , $g [ 'url' ])),
'forum' => ! empty ( $g [ 'forum' ]) || ! empty ( $g [ 'prv' ]) ? 1 : 0 ,
2018-02-25 19:45:04 -05:00
];
if ( $entry [ 'forum' ]) {
$forums [] = $entry ;
} else {
$contacts [] = $entry ;
}
}
if ( count ( $forums ) > 0 ) {
if ( $search == '' ) {
$forums [] = [ 'separator' => true ];
}
$contacts = array_merge ( $forums , $contacts );
}
}
$items = array_merge ( $groups , $contacts );
if ( $conv_id ) {
2018-03-12 08:15:59 -04:00
// In multi threaded posts the conv_id is not the parent of the whole thread
2018-07-07 14:14:16 -04:00
$parent_item = Item :: selectFirst ([ 'parent' ], [ 'id' => $conv_id ]);
2018-07-21 08:46:04 -04:00
if ( DBA :: isResult ( $parent_item )) {
2018-03-12 08:15:59 -04:00
$conv_id = $parent_item [ 'parent' ];
}
2018-02-25 19:45:04 -05:00
/*
* if $conv_id is set , get unknown contacts in thread
* but first get known contacts url to filter them out
*/
$known_contacts = array_map ( function ( $i ) {
2018-06-12 05:05:36 -04:00
return $i [ 'link' ];
2018-02-25 19:45:04 -05:00
}, $contacts );
$unknown_contacts = [];
2018-06-12 05:05:36 -04:00
$condition = [ " `parent` = ? " , $conv_id ];
$params = [ 'order' => [ 'author-name' => true ]];
2018-06-17 13:05:17 -04:00
$authors = Item :: selectForUser ( local_user (), [ 'author-link' ], $condition , $params );
2018-06-12 05:05:36 -04:00
$item_authors = [];
2018-06-24 06:48:29 -04:00
while ( $author = Item :: fetch ( $authors )) {
2018-06-12 05:05:36 -04:00
$item_authors [ $author [ 'author-link' ]] = $author [ 'author-link' ];
}
2018-07-20 08:19:26 -04:00
DBA :: close ( $authors );
2018-06-12 05:05:36 -04:00
foreach ( $item_authors as $author ) {
if ( in_array ( $author , $known_contacts )) {
continue ;
}
$contact = Contact :: getDetailsByURL ( $author );
if ( count ( $contact ) > 0 ) {
$unknown_contacts [] = [
'type' => 'c' ,
2018-07-30 22:06:22 -04:00
'photo' => ProxyUtils :: proxifyUrl ( $contact [ 'micro' ], false , ProxyUtils :: SIZE_MICRO ),
2018-11-25 14:48:26 -05:00
'name' => htmlspecialchars ( $contact [ 'name' ]),
2018-06-12 05:05:36 -04:00
'id' => intval ( $contact [ 'cid' ]),
'network' => $contact [ 'network' ],
'link' => $contact [ 'url' ],
'nick' => htmlentities ( defaults ( $contact , 'nick' , $contact [ 'addr' ])),
'addr' => htmlentities ( defaults ( $contact , 'addr' , $contact [ 'url' ])),
'forum' => $contact [ 'forum' ]
];
2018-02-25 19:45:04 -05:00
}
}
$items = array_merge ( $items , $unknown_contacts );
$tot += count ( $unknown_contacts );
}
$results = [
'tot' => $tot ,
'start' => $start ,
'count' => $count ,
'groups' => $groups ,
'contacts' => $contacts ,
'items' => $items ,
'type' => $type ,
'search' => $search ,
];
2018-12-26 01:06:24 -05:00
Hook :: callAll ( 'acl_lookup_end' , $results );
2018-02-25 19:45:04 -05:00
$o = [
2018-02-25 20:24:46 -05:00
'tot' => $results [ 'tot' ],
2018-02-25 19:45:04 -05:00
'start' => $results [ 'start' ],
'count' => $results [ 'count' ],
'items' => $results [ 'items' ],
];
echo json_encode ( $o );
2018-02-25 20:24:46 -05:00
exit ;
2018-02-25 19:45:04 -05:00
}