X-Git-Url: https://git.immae.eu/?a=blobdiff_plain;ds=sidebyside;f=index.php;h=4627438e523bf16a68530ac1d34d0790a271e9c2;hb=c4ad3d4f061d05a01db25aa54dda830ba776792d;hp=030fdfa3132512694773831e5af19f1475c60683;hpb=c70ff64a61d62cc8d35a62f30596ecc2a3c578a3;p=github%2Fshaarli%2FShaarli.git diff --git a/index.php b/index.php index 030fdfa3..4627438e 100644 --- a/index.php +++ b/index.php @@ -61,30 +61,13 @@ require_once 'application/TimeZone.php'; require_once 'application/Utils.php'; use Shaarli\ApplicationUtils; -use Shaarli\Bookmark\Bookmark; -use Shaarli\Bookmark\BookmarkFileService; -use Shaarli\Bookmark\BookmarkFilter; -use Shaarli\Bookmark\BookmarkServiceInterface; -use Shaarli\Bookmark\Exception\BookmarkNotFoundException; use Shaarli\Config\ConfigManager; use Shaarli\Container\ContainerBuilder; -use Shaarli\Feed\CachedPage; -use Shaarli\Feed\FeedBuilder; -use Shaarli\Formatter\BookmarkMarkdownFormatter; -use Shaarli\Formatter\FormatterFactory; -use Shaarli\History; use Shaarli\Languages; -use Shaarli\Netscape\NetscapeBookmarkUtils; use Shaarli\Plugin\PluginManager; -use Shaarli\Render\PageBuilder; -use Shaarli\Render\PageCacheManager; -use Shaarli\Render\ThemeUtils; -use Shaarli\Router; +use Shaarli\Security\CookieManager; use Shaarli\Security\LoginManager; use Shaarli\Security\SessionManager; -use Shaarli\Thumbnailer; -use Shaarli\Updater\Updater; -use Shaarli\Updater\UpdaterUtils; use Slim\App; // Ensure the PHP version is supported @@ -133,13 +116,14 @@ if ($conf->get('dev.debug', false)) { // See all errors (for debugging only) error_reporting(-1); - set_error_handler(function($errno, $errstr, $errfile, $errline, array $errcontext) { + set_error_handler(function ($errno, $errstr, $errfile, $errline, array $errcontext) { throw new ErrorException($errstr, 0, $errno, $errfile, $errline); }); } -$sessionManager = new SessionManager($_SESSION, $conf); -$loginManager = new LoginManager($conf, $sessionManager); +$sessionManager = new SessionManager($_SESSION, $conf, session_save_path()); +$cookieManager = new CookieManager($_COOKIE); +$loginManager = new LoginManager($conf, $sessionManager, $cookieManager); $loginManager->generateStaySignedInToken($_SERVER['REMOTE_ADDR']); $clientIpId = client_ip_id($_SERVER); @@ -173,42 +157,7 @@ header("Cache-Control: no-store, no-cache, must-revalidate"); header("Cache-Control: post-check=0, pre-check=0", false); header("Pragma: no-cache"); -if (! is_file($conf->getConfigFileExt())) { - // Ensure Shaarli has proper access to its resources - $errors = ApplicationUtils::checkResourcePermissions($conf); - - if ($errors != array()) { - $message = '

'. t('Insufficient permissions:') .'

'; - - header('Content-Type: text/html; charset=utf-8'); - echo $message; - exit; - } - - // Display the installation form if no existing config is found - install($conf, $sessionManager, $loginManager); -} - -$loginManager->checkLoginState($_COOKIE, $clientIpId); - -/** - * Adapter function to ensure compatibility with third-party templates - * - * @see https://github.com/shaarli/Shaarli/pull/1086 - * - * @return bool true when the user is logged in, false otherwise - */ -function isLoggedIn() -{ - global $loginManager; - return $loginManager->isLoggedIn(); -} - +$loginManager->checkLoginState($clientIpId); // ------------------------------------------------------------------------------------------ // Process login form: Check if login/password is correct. @@ -234,7 +183,7 @@ if (isset($_POST['login'])) { $expirationTime = $sessionManager->extendSession(); setcookie( - $loginManager::$STAY_SIGNED_IN_COOKIE, + CookieManager::STAY_SIGNED_IN, $loginManager->getStaySignedInToken(), $expirationTime, WEB_PATH @@ -300,717 +249,11 @@ if (!isset($_SESSION['tokens'])) { $_SESSION['tokens']=array(); // Token are attached to the session. } -/** - * Renders the linklist - * - * @param pageBuilder $PAGE pageBuilder instance. - * @param BookmarkServiceInterface $linkDb instance. - * @param ConfigManager $conf Configuration Manager instance. - * @param PluginManager $pluginManager Plugin Manager instance. - */ -function showLinkList($PAGE, $linkDb, $conf, $pluginManager, $loginManager) -{ - buildLinkList($PAGE, $linkDb, $conf, $pluginManager, $loginManager); - $PAGE->renderPage('linklist'); -} - -/** - * Render HTML page (according to URL parameters and user rights) - * - * @param ConfigManager $conf Configuration Manager instance. - * @param PluginManager $pluginManager Plugin Manager instance, - * @param BookmarkServiceInterface $bookmarkService - * @param History $history instance - * @param SessionManager $sessionManager SessionManager instance - * @param LoginManager $loginManager LoginManager instance - */ -function renderPage($conf, $pluginManager, $bookmarkService, $history, $sessionManager, $loginManager) -{ - $pageCacheManager = new PageCacheManager($conf->get('resource.page_cache'), $loginManager->isLoggedIn()); - $updater = new Updater( - UpdaterUtils::read_updates_file($conf->get('resource.updates')), - $bookmarkService, - $conf, - $loginManager->isLoggedIn() - ); - try { - $newUpdates = $updater->update(); - if (! empty($newUpdates)) { - UpdaterUtils::write_updates_file( - $conf->get('resource.updates'), - $updater->getDoneUpdates() - ); - - $pageCacheManager->invalidateCaches(); - } - } catch (Exception $e) { - die($e->getMessage()); - } - - $PAGE = new PageBuilder($conf, $_SESSION, $bookmarkService, $sessionManager->generateToken(), $loginManager->isLoggedIn()); - $PAGE->assign('linkcount', $bookmarkService->count(BookmarkFilter::$ALL)); - $PAGE->assign('privateLinkcount', $bookmarkService->count(BookmarkFilter::$PRIVATE)); - $PAGE->assign('plugin_errors', $pluginManager->getErrors()); - - // Determine which page will be rendered. - $query = (isset($_SERVER['QUERY_STRING'])) ? $_SERVER['QUERY_STRING'] : ''; - $targetPage = Router::findPage($query, $_GET, $loginManager->isLoggedIn()); - - if (// if the user isn't logged in - !$loginManager->isLoggedIn() && - // and Shaarli doesn't have public content... - $conf->get('privacy.hide_public_links') && - // and is configured to enforce the login - $conf->get('privacy.force_login') && - // and the current page isn't already the login page - $targetPage !== Router::$PAGE_LOGIN && - // and the user is not requesting a feed (which would lead to a different content-type as expected) - $targetPage !== Router::$PAGE_FEED_ATOM && - $targetPage !== Router::$PAGE_FEED_RSS - ) { - // force current page to be the login page - $targetPage = Router::$PAGE_LOGIN; - } - - // Call plugin hooks for header, footer and includes, specifying which page will be rendered. - // Then assign generated data to RainTPL. - $common_hooks = array( - 'includes', - 'header', - 'footer', - ); - - foreach ($common_hooks as $name) { - $plugin_data = array(); - $pluginManager->executeHooks( - 'render_' . $name, - $plugin_data, - array( - 'target' => $targetPage, - 'loggedin' => $loginManager->isLoggedIn() - ) - ); - $PAGE->assign('plugins_' . $name, $plugin_data); - } - - // -------- Display login form. - if ($targetPage == Router::$PAGE_LOGIN) { - header('Location: ./login'); - exit; - } - // -------- User wants to logout. - if (isset($_SERVER['QUERY_STRING']) && startsWith($_SERVER['QUERY_STRING'], 'do=logout')) { - header('Location: ./logout'); - exit; - } - - // -------- Picture wall - if ($targetPage == Router::$PAGE_PICWALL) { - header('Location: ./picture-wall'); - exit; - } - - // -------- Tag cloud - if ($targetPage == Router::$PAGE_TAGCLOUD) { - header('Location: ./tags/cloud'); - exit; - } - - // -------- Tag list - if ($targetPage == Router::$PAGE_TAGLIST) { - header('Location: ./tags/list'); - exit; - } - - // Daily page. - if ($targetPage == Router::$PAGE_DAILY) { - $dayParam = !empty($_GET['day']) ? '?day=' . escape($_GET['day']) : ''; - header('Location: ./daily'. $dayParam); - exit; - } - - // ATOM and RSS feed. - if ($targetPage == Router::$PAGE_FEED_ATOM || $targetPage == Router::$PAGE_FEED_RSS) { - $feedType = $targetPage == Router::$PAGE_FEED_RSS ? FeedBuilder::$FEED_RSS : FeedBuilder::$FEED_ATOM; - - header('Location: ./feed/'. $feedType .'?'. http_build_query($_GET)); - exit; - } - - // Display opensearch plugin (XML) - if ($targetPage == Router::$PAGE_OPENSEARCH) { - header('Location: ./open-search'); - exit; - } - - // -------- User clicks on a tag in a link: The tag is added to the list of searched tags (searchtags=...) - if (isset($_GET['addtag'])) { - header('Location: ./add-tag/'. $_GET['addtag']); - exit; - } - - // -------- User clicks on a tag in result count: Remove the tag from the list of searched tags (searchtags=...) - if (isset($_GET['removetag'])) { - header('Location: ./remove-tag/'. $_GET['removetag']); - exit; - } - - // -------- User wants to change the number of bookmarks per page (linksperpage=...) - if (isset($_GET['linksperpage'])) { - header('Location: ./links-per-page?nb='. $_GET['linksperpage']); - exit; - } - - // -------- User wants to see only private bookmarks (toggle) - if (isset($_GET['visibility'])) { - header('Location: ./visibility/'. $_GET['visibility']); - exit; - } - - // -------- User wants to see only untagged bookmarks (toggle) - if (isset($_GET['untaggedonly'])) { - header('Location: ./untagged-only'); - exit; - } - - // -------- Handle other actions allowed for non-logged in users: - if (!$loginManager->isLoggedIn()) { - // User tries to post new link but is not logged in: - // Show login screen, then redirect to ?post=... - if (isset($_GET['post'])) { - header( // Redirect to login page, then back to post link. - 'Location: ./login?post='.urlencode($_GET['post']). - (!empty($_GET['title'])?'&title='.urlencode($_GET['title']):''). - (!empty($_GET['description'])?'&description='.urlencode($_GET['description']):''). - (!empty($_GET['tags'])?'&tags='.urlencode($_GET['tags']):''). - (!empty($_GET['source'])?'&source='.urlencode($_GET['source']):'') - ); - exit; - } - - showLinkList($PAGE, $bookmarkService, $conf, $pluginManager, $loginManager); - if (isset($_GET['edit_link'])) { - header('Location: ./login?edit_link='. escape($_GET['edit_link'])); - exit; - } - - exit; // Never remove this one! All operations below are reserved for logged in user. - } - - // -------- All other functions are reserved for the registered user: - - // TODO: Remove legacy admin route redirections. We'll only keep public URL. - - // -------- Display the Tools menu if requested (import/export/bookmarklet...) - if ($targetPage == Router::$PAGE_TOOLS) { - header('Location: ./admin/tools'); - exit; - } - - // -------- User wants to change his/her password. - if ($targetPage == Router::$PAGE_CHANGEPASSWORD) { - header('Location: ./admin/password'); - exit; - } - - // -------- User wants to change configuration - if ($targetPage == Router::$PAGE_CONFIGURE) { - header('Location: ./admin/configure'); - exit; - } - - // -------- User wants to rename a tag or delete it - if ($targetPage == Router::$PAGE_CHANGETAG) { - header('Location: ./admin/tags'); - exit; - } - - // -------- User wants to add a link without using the bookmarklet: Show form. - if ($targetPage == Router::$PAGE_ADDLINK) { - header('Location: ./admin/shaare'); - exit; - } - - // -------- User clicked the "Save" button when editing a link: Save link to database. - if (isset($_POST['save_edit'])) { - // This route is no longer supported in legacy mode - header('Location: ./'); - exit; - } - - // -------- User clicked the "Delete" button when editing a link: Delete link from database. - if ($targetPage == Router::$PAGE_DELETELINK) { - $ids = $_GET['lf_linkdate'] ?? ''; - $token = $_GET['token'] ?? ''; - - header('Location: ./admin/shaare/delete?id=' . $ids . '&token=' . $token); - exit; - } - - // -------- User clicked either "Set public" or "Set private" bulk operation - if ($targetPage == Router::$PAGE_CHANGE_VISIBILITY) { - header('Location: ./admin/shaare/visibility?id=' . $_GET['token']); - exit; - } - - // -------- User clicked the "EDIT" button on a link: Display link edit form. - if (isset($_GET['edit_link'])) { - $id = (int) escape($_GET['edit_link']); - header('Location: ./admin/shaare/' . $id); - exit; - } - - // -------- User want to post a new link: Display link edit form. - if (isset($_GET['post'])) { - header('Location: ./admin/shaare?' . http_build_query($_GET)); - exit; - } - - if ($targetPage == Router::$PAGE_PINLINK) { - // This route is no longer supported in legacy mode - header('Location: ./'); - exit; - } - - if ($targetPage == Router::$PAGE_EXPORT) { - header('Location: ./admin/export'); - exit; - } - - if ($targetPage == Router::$PAGE_IMPORT) { - // Upload a Netscape bookmark dump to import its contents - - if (! isset($_POST['token']) || ! isset($_FILES['filetoupload'])) { - // Show import dialog - $PAGE->assign( - 'maxfilesize', - get_max_upload_size( - ini_get('post_max_size'), - ini_get('upload_max_filesize'), - false - ) - ); - $PAGE->assign( - 'maxfilesizeHuman', - get_max_upload_size( - ini_get('post_max_size'), - ini_get('upload_max_filesize'), - true - ) - ); - $PAGE->assign('pagetitle', t('Import') .' - '. $conf->get('general.title', 'Shaarli')); - $PAGE->renderPage('import'); - exit; - } - - // Import bookmarks from an uploaded file - if (isset($_FILES['filetoupload']['size']) && $_FILES['filetoupload']['size'] == 0) { - // The file is too big or some form field may be missing. - $msg = sprintf( - t( - 'The file you are trying to upload is probably bigger than what this webserver can accept' - .' (%s). Please upload in smaller chunks.' - ), - get_max_upload_size(ini_get('post_max_size'), ini_get('upload_max_filesize')) - ); - echo ''; - exit; - } - if (! $sessionManager->checkToken($_POST['token'])) { - die('Wrong token.'); - } - $netscapeBookmarkUtils = new NetscapeBookmarkUtils($bookmarkService, $conf, $history); - $status = $netscapeBookmarkUtils->import($_POST, $_FILES); - echo ''; - exit; - } - - // Plugin administration page - if ($targetPage == Router::$PAGE_PLUGINSADMIN) { - $pluginMeta = $pluginManager->getPluginsMeta(); - - // Split plugins into 2 arrays: ordered enabled plugins and disabled. - $enabledPlugins = array_filter($pluginMeta, function ($v) { - return $v['order'] !== false; - }); - // Load parameters. - $enabledPlugins = load_plugin_parameter_values($enabledPlugins, $conf->get('plugins', array())); - uasort( - $enabledPlugins, - function ($a, $b) { - return $a['order'] - $b['order']; - } - ); - $disabledPlugins = array_filter($pluginMeta, function ($v) { - return $v['order'] === false; - }); - - $PAGE->assign('enabledPlugins', $enabledPlugins); - $PAGE->assign('disabledPlugins', $disabledPlugins); - $PAGE->assign('pagetitle', t('Plugin administration') .' - '. $conf->get('general.title', 'Shaarli')); - $PAGE->renderPage('pluginsadmin'); - exit; - } - - // Plugin administration form action - if ($targetPage == Router::$PAGE_SAVE_PLUGINSADMIN) { - try { - if (isset($_POST['parameters_form'])) { - $pluginManager->executeHooks('save_plugin_parameters', $_POST); - unset($_POST['parameters_form']); - foreach ($_POST as $param => $value) { - $conf->set('plugins.'. $param, escape($value)); - } - } else { - $conf->set('general.enabled_plugins', save_plugin_config($_POST)); - } - $conf->write($loginManager->isLoggedIn()); - $history->updateSettings(); - } catch (Exception $e) { - error_log( - 'ERROR while saving plugin configuration:.' . PHP_EOL . - $e->getMessage() - ); - - // TODO: do not handle exceptions/errors in JS. - echo ''; - exit; - } - header('Location: ./?do='. Router::$PAGE_PLUGINSADMIN); - exit; - } - - // Get a fresh token - if ($targetPage == Router::$GET_TOKEN) { - header('Content-Type:text/plain'); - echo $sessionManager->generateToken(); - exit; - } - - // -------- Thumbnails Update - if ($targetPage == Router::$PAGE_THUMBS_UPDATE) { - $ids = []; - foreach ($bookmarkService->search() as $bookmark) { - // A note or not HTTP(S) - if ($bookmark->isNote() || ! startsWith(strtolower($bookmark->getUrl()), 'http')) { - continue; - } - $ids[] = $bookmark->getId(); - } - $PAGE->assign('ids', $ids); - $PAGE->assign('pagetitle', t('Thumbnails update') .' - '. $conf->get('general.title', 'Shaarli')); - $PAGE->renderPage('thumbnails'); - exit; - } - - // -------- Single Thumbnail Update - if ($targetPage == Router::$AJAX_THUMB_UPDATE) { - if (! isset($_POST['id']) || ! ctype_digit($_POST['id'])) { - http_response_code(400); - exit; - } - $id = (int) $_POST['id']; - if (! $bookmarkService->exists($id)) { - http_response_code(404); - exit; - } - $thumbnailer = new Thumbnailer($conf); - $bookmark = $bookmarkService->get($id); - $bookmark->setThumbnail($thumbnailer->get($bookmark->getUrl())); - $bookmarkService->set($bookmark); - - $factory = new FormatterFactory($conf, $loginManager->isLoggedIn()); - echo json_encode($factory->getFormatter('raw')->format($bookmark)); - exit; - } - - // -------- Otherwise, simply display search form and bookmarks: - showLinkList($PAGE, $bookmarkService, $conf, $pluginManager, $loginManager); - exit; -} - -/** - * Template for the list of bookmarks (