We are no longer offering accounts on this server. Consider https://gitlab.freedesktop.org/ as a place to host projects.

subscribe.php 5.11 KB
Newer Older
Evan Prodromou's avatar
Evan Prodromou committed
1
<?php
2
/**
3
 * StatusNet - the distributed open-source microblogging tool
4 5 6
 * Copyright (C) 2008-2010, StatusNet, Inc.
 *
 * Subscription action.
Evan Prodromou's avatar
Evan Prodromou committed
7
 *
Evan Prodromou's avatar
Evan Prodromou committed
8 9 10 11
 * This program is free software: you can redistribute it and/or modify
 * it under the terms of the GNU Affero General Public License as published by
 * the Free Software Foundation, either version 3 of the License, or
 * (at your option) any later version.
Evan Prodromou's avatar
Evan Prodromou committed
12
 *
Evan Prodromou's avatar
Evan Prodromou committed
13 14 15 16
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU Affero General Public License for more details.
Evan Prodromou's avatar
Evan Prodromou committed
17
 *
Evan Prodromou's avatar
Evan Prodromou committed
18 19
 * You should have received a copy of the GNU Affero General Public License
 * along with this program.  If not, see <http://www.gnu.org/licenses/>.
20 21 22 23 24 25 26 27 28
 *
 * PHP version 5
 *
 * @category  Action
 * @package   StatusNet
 * @author    Evan Prodromou <evan@status.net>
 * @copyright 2008-2010 StatusNet, Inc.
 * @license   http://www.fsf.org/licensing/licenses/agpl-3.0.html AGPLv3
 * @link      http://status.net/
Evan Prodromou's avatar
Evan Prodromou committed
29 30
 */

31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55
if (!defined('STATUSNET')) {
    exit(1);
}

/**
 * Subscription action
 *
 * Subscribing to a profile. Does not work for OMB 0.1 remote subscriptions,
 * but may work for other remote subscription protocols, like OStatus.
 *
 * Takes parameters:
 *
 *    - subscribeto: a profile ID
 *    - token: session token to prevent CSRF attacks
 *    - ajax: boolean; whether to return Ajax or full-browser results
 *
 * Only works if the current user is logged in.
 *
 * @category  Action
 * @package   StatusNet
 * @author    Evan Prodromou <evan@status.net>
 * @copyright 2008-2010 StatusNet, Inc.
 * @license   http://www.fsf.org/licensing/licenses/agpl-3.0.html AGPLv3
 * @link      http://status.net/
 */
56 57
class SubscribeAction extends Action
{
58 59
    var $user;
    var $other;
60

61 62 63 64 65 66 67 68 69 70
    /**
     * Check pre-requisites and instantiate attributes
     *
     * @param Array $args array of arguments (URL, GET, POST)
     *
     * @return boolean success flag
     */
    function prepare($args)
    {
        parent::prepare($args);
Evan Prodromou's avatar
Evan Prodromou committed
71

72
        // Only allow POST requests
73

74
        if ($_SERVER['REQUEST_METHOD'] != 'POST') {
75 76
            // TRANS: Client error displayed trying to perform any request method other than POST.
            // TRANS: Do not translate POST.
77 78
            $this->clientError(_('This action only accepts POST requests.'));
            return false;
79
        }
80

81
        // CSRF protection
82

83
        $token = $this->trimmed('token');
84

85
        if (!$token || $token != common_session_token()) {
86
            // TRANS: Client error displayed when the session token is not okay.
87 88 89 90 91 92 93 94 95 96
            $this->clientError(_('There was a problem with your session token.'.
                                 ' Try again, please.'));
            return false;
        }

        // Only for logged-in users

        $this->user = common_current_user();

        if (empty($this->user)) {
97
            // TRANS: Error message displayed when trying to perform an action that requires a logged in user.
98 99
            $this->clientError(_('Not logged in.'));
            return false;
100
        }
101

102 103
        // Profile to subscribe to

104
        $other_id = $this->arg('subscribeto');
105

106
        $this->other = Profile::staticGet('id', $other_id);
107

108
        if (empty($this->other)) {
109
            // TRANS: Client error displayed trying to subscribe to a non-existing profile.
110 111
            $this->clientError(_('No such profile.'));
            return false;
112 113
        }

114 115 116 117
        // OMB 0.1 doesn't have a mechanism for local-server-
        // originated subscription.

        $omb01 = Remote_profile::staticGet('id', $other_id);
Evan Prodromou's avatar
Evan Prodromou committed
118

119
        if (!empty($omb01)) {
120
            // TRANS: Client error displayed trying to subscribe to an OMB 0.1 remote profile.
121 122 123
            $this->clientError(_('You cannot subscribe to an OMB 0.1'.
                                 ' remote profile with this action.'));
            return false;
124
        }
millette's avatar
millette committed
125

126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141
        return true;
    }

    /**
     * Handle request
     *
     * Does the subscription and returns results.
     *
     * @param Array $args unused.
     *
     * @return void
     */
    function handle($args)
    {
        // Throws exception on error

Brion Vibber's avatar
Brion Vibber committed
142 143
        $sub = Subscription::start($this->user->getProfile(),
                                   $this->other);
144

145
        if ($this->boolean('ajax')) {
146
            $this->startHTML('text/xml;charset=utf-8');
147
            $this->elementStart('head');
148
            // TRANS: Page title when subscription succeeded.
149 150 151
            $this->element('title', null, _('Subscribed'));
            $this->elementEnd('head');
            $this->elementStart('body');
Brion Vibber's avatar
Brion Vibber committed
152 153 154 155 156 157
            if ($sub instanceof Subscription) {
                $form = new UnsubscribeForm($this, $this->other);
            } else {
                $form = new CancelSubscriptionForm($this, $this->other);
            }
            $form->show();
158 159
            $this->elementEnd('body');
            $this->elementEnd('html');
160
        } else {
161 162 163
            $url = common_local_url('subscriptions',
                                    array('nickname' => $this->user->nickname));
            common_redirect($url, 303);
millette's avatar
millette committed
164
        }
165
    }
millette's avatar
millette committed
166
}