rpc.php 24 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874
  1. <?php
  2. class RPC extends Handler_Protected {
  3. function csrf_ignore($method) {
  4. $csrf_ignored = array("sanitycheck", "completelabels");
  5. return array_search($method, $csrf_ignored) !== false;
  6. }
  7. function setprofile() {
  8. $id = db_escape_string($this->link, $_REQUEST["id"]);
  9. $_SESSION["profile"] = $id;
  10. $_SESSION["prefs_cache"] = array();
  11. }
  12. function remprofiles() {
  13. $ids = explode(",", db_escape_string($this->link, trim($_REQUEST["ids"])));
  14. foreach ($ids as $id) {
  15. if ($_SESSION["profile"] != $id) {
  16. db_query($this->link, "DELETE FROM ttrss_settings_profiles WHERE id = '$id' AND
  17. owner_uid = " . $_SESSION["uid"]);
  18. }
  19. }
  20. }
  21. // Silent
  22. function addprofile() {
  23. $title = db_escape_string($this->link, trim($_REQUEST["title"]));
  24. if ($title) {
  25. db_query($this->link, "BEGIN");
  26. $result = db_query($this->link, "SELECT id FROM ttrss_settings_profiles
  27. WHERE title = '$title' AND owner_uid = " . $_SESSION["uid"]);
  28. if (db_num_rows($result) == 0) {
  29. db_query($this->link, "INSERT INTO ttrss_settings_profiles (title, owner_uid)
  30. VALUES ('$title', ".$_SESSION["uid"] .")");
  31. $result = db_query($this->link, "SELECT id FROM ttrss_settings_profiles WHERE
  32. title = '$title'");
  33. if (db_num_rows($result) != 0) {
  34. $profile_id = db_fetch_result($result, 0, "id");
  35. if ($profile_id) {
  36. initialize_user_prefs($this->link, $_SESSION["uid"], $profile_id);
  37. }
  38. }
  39. }
  40. db_query($this->link, "COMMIT");
  41. }
  42. }
  43. // Silent
  44. function saveprofile() {
  45. $id = db_escape_string($this->link, $_REQUEST["id"]);
  46. $title = db_escape_string($this->link, trim($_REQUEST["value"]));
  47. if ($id == 0) {
  48. print __("Default profile");
  49. return;
  50. }
  51. if ($title) {
  52. db_query($this->link, "BEGIN");
  53. $result = db_query($this->link, "SELECT id FROM ttrss_settings_profiles
  54. WHERE title = '$title' AND owner_uid =" . $_SESSION["uid"]);
  55. if (db_num_rows($result) == 0) {
  56. db_query($this->link, "UPDATE ttrss_settings_profiles
  57. SET title = '$title' WHERE id = '$id' AND
  58. owner_uid = " . $_SESSION["uid"]);
  59. print $title;
  60. } else {
  61. $result = db_query($this->link, "SELECT title FROM ttrss_settings_profiles
  62. WHERE id = '$id' AND owner_uid =" . $_SESSION["uid"]);
  63. print db_fetch_result($result, 0, "title");
  64. }
  65. db_query($this->link, "COMMIT");
  66. }
  67. }
  68. // Silent
  69. function remarchive() {
  70. $ids = explode(",", db_escape_string($this->link, $_REQUEST["ids"]));
  71. foreach ($ids as $id) {
  72. $result = db_query($this->link, "DELETE FROM ttrss_archived_feeds WHERE
  73. (SELECT COUNT(*) FROM ttrss_user_entries
  74. WHERE orig_feed_id = '$id') = 0 AND
  75. id = '$id' AND owner_uid = ".$_SESSION["uid"]);
  76. $rc = db_affected_rows($this->link, $result);
  77. }
  78. }
  79. function addfeed() {
  80. $feed = db_escape_string($this->link, $_REQUEST['feed']);
  81. $cat = db_escape_string($this->link, $_REQUEST['cat']);
  82. $login = db_escape_string($this->link, $_REQUEST['login']);
  83. $pass = db_escape_string($this->link, $_REQUEST['pass']);
  84. $rc = subscribe_to_feed($this->link, $feed, $cat, $login, $pass);
  85. print json_encode(array("result" => $rc));
  86. }
  87. function togglepref() {
  88. $key = db_escape_string($this->link, $_REQUEST["key"]);
  89. set_pref($this->link, $key, !get_pref($this->link, $key));
  90. $value = get_pref($this->link, $key);
  91. print json_encode(array("param" =>$key, "value" => $value));
  92. }
  93. function setpref() {
  94. // set_pref escapes input, so no need to double escape it here
  95. $key = $_REQUEST['key'];
  96. $value = str_replace("\n", "<br/>", $_REQUEST['value']);
  97. set_pref($this->link, $key, $value, $_SESSION['uid'], $key != 'USER_STYLESHEET');
  98. print json_encode(array("param" =>$key, "value" => $value));
  99. }
  100. function mark() {
  101. $mark = $_REQUEST["mark"];
  102. $id = db_escape_string($this->link, $_REQUEST["id"]);
  103. if ($mark == "1") {
  104. $mark = "true";
  105. } else {
  106. $mark = "false";
  107. }
  108. $result = db_query($this->link, "UPDATE ttrss_user_entries SET marked = $mark,
  109. last_marked = NOW()
  110. WHERE ref_id = '$id' AND owner_uid = " . $_SESSION["uid"]);
  111. print json_encode(array("message" => "UPDATE_COUNTERS"));
  112. }
  113. function delete() {
  114. $ids = db_escape_string($this->link, $_REQUEST["ids"]);
  115. $result = db_query($this->link, "DELETE FROM ttrss_user_entries
  116. WHERE ref_id IN ($ids) AND owner_uid = " . $_SESSION["uid"]);
  117. print json_encode(array("message" => "UPDATE_COUNTERS"));
  118. }
  119. function unarchive() {
  120. $ids = db_escape_string($this->link, $_REQUEST["ids"]);
  121. $result = db_query($this->link, "UPDATE ttrss_user_entries
  122. SET feed_id = orig_feed_id, orig_feed_id = NULL
  123. WHERE ref_id IN ($ids) AND owner_uid = " . $_SESSION["uid"]);
  124. print json_encode(array("message" => "UPDATE_COUNTERS"));
  125. }
  126. function archive() {
  127. $ids = explode(",", db_escape_string($this->link, $_REQUEST["ids"]));
  128. foreach ($ids as $id) {
  129. $this->archive_article($this->link, $id, $_SESSION["uid"]);
  130. }
  131. print json_encode(array("message" => "UPDATE_COUNTERS"));
  132. }
  133. private function archive_article($link, $id, $owner_uid) {
  134. db_query($link, "BEGIN");
  135. $result = db_query($link, "SELECT feed_id FROM ttrss_user_entries
  136. WHERE ref_id = '$id' AND owner_uid = $owner_uid");
  137. if (db_num_rows($result) != 0) {
  138. /* prepare the archived table */
  139. $feed_id = (int) db_fetch_result($result, 0, "feed_id");
  140. if ($feed_id) {
  141. $result = db_query($link, "SELECT id FROM ttrss_archived_feeds
  142. WHERE id = '$feed_id'");
  143. if (db_num_rows($result) == 0) {
  144. db_query($link, "INSERT INTO ttrss_archived_feeds
  145. (id, owner_uid, title, feed_url, site_url)
  146. SELECT id, owner_uid, title, feed_url, site_url from ttrss_feeds
  147. WHERE id = '$feed_id'");
  148. }
  149. db_query($link, "UPDATE ttrss_user_entries
  150. SET orig_feed_id = feed_id, feed_id = NULL
  151. WHERE ref_id = '$id' AND owner_uid = " . $_SESSION["uid"]);
  152. }
  153. }
  154. db_query($link, "COMMIT");
  155. }
  156. function publ() {
  157. $pub = $_REQUEST["pub"];
  158. $id = db_escape_string($this->link, $_REQUEST["id"]);
  159. $note = trim(strip_tags(db_escape_string($this->link, $_REQUEST["note"])));
  160. if ($pub == "1") {
  161. $pub = "true";
  162. } else {
  163. $pub = "false";
  164. }
  165. $result = db_query($this->link, "UPDATE ttrss_user_entries SET
  166. published = $pub, last_published = NOW()
  167. WHERE ref_id = '$id' AND owner_uid = " . $_SESSION["uid"]);
  168. $pubsub_result = false;
  169. if (PUBSUBHUBBUB_HUB) {
  170. $rss_link = get_self_url_prefix() .
  171. "/public.php?op=rss&id=-2&key=" .
  172. get_feed_access_key($this->link, -2, false);
  173. $p = new Publisher(PUBSUBHUBBUB_HUB);
  174. $pubsub_result = $p->publish_update($rss_link);
  175. }
  176. print json_encode(array("message" => "UPDATE_COUNTERS",
  177. "pubsub_result" => $pubsub_result));
  178. }
  179. function getAllCounters() {
  180. $last_article_id = (int) $_REQUEST["last_article_id"];
  181. $reply = array();
  182. if ($seq) $reply['seq'] = $seq;
  183. if ($last_article_id != getLastArticleId($this->link)) {
  184. $reply['counters'] = getAllCounters($this->link);
  185. }
  186. $reply['runtime-info'] = make_runtime_info($this->link);
  187. print json_encode($reply);
  188. }
  189. /* GET["cmode"] = 0 - mark as read, 1 - as unread, 2 - toggle */
  190. function catchupSelected() {
  191. $ids = explode(",", db_escape_string($this->link, $_REQUEST["ids"]));
  192. $cmode = sprintf("%d", $_REQUEST["cmode"]);
  193. catchupArticlesById($this->link, $ids, $cmode);
  194. print json_encode(array("message" => "UPDATE_COUNTERS"));
  195. }
  196. function markSelected() {
  197. $ids = explode(",", db_escape_string($this->link, $_REQUEST["ids"]));
  198. $cmode = sprintf("%d", $_REQUEST["cmode"]);
  199. $this->markArticlesById($this->link, $ids, $cmode);
  200. print json_encode(array("message" => "UPDATE_COUNTERS"));
  201. }
  202. function publishSelected() {
  203. $ids = explode(",", db_escape_string($this->link, $_REQUEST["ids"]));
  204. $cmode = sprintf("%d", $_REQUEST["cmode"]);
  205. $this->publishArticlesById($this->link, $ids, $cmode);
  206. print json_encode(array("message" => "UPDATE_COUNTERS"));
  207. }
  208. function sanityCheck() {
  209. $_SESSION["hasAudio"] = $_REQUEST["hasAudio"] === "true";
  210. $_SESSION["hasSandbox"] = $_REQUEST["hasSandbox"] === "true";
  211. $reply = array();
  212. $reply['error'] = sanity_check($this->link);
  213. if ($reply['error']['code'] == 0) {
  214. $reply['init-params'] = make_init_params($this->link);
  215. $reply['runtime-info'] = make_runtime_info($this->link);
  216. }
  217. print json_encode($reply);
  218. }
  219. function setArticleTags() {
  220. $id = db_escape_string($this->link, $_REQUEST["id"]);
  221. $tags_str = db_escape_string($this->link, $_REQUEST["tags_str"]);
  222. $tags = array_unique(trim_array(explode(",", $tags_str)));
  223. db_query($this->link, "BEGIN");
  224. $result = db_query($this->link, "SELECT int_id FROM ttrss_user_entries WHERE
  225. ref_id = '$id' AND owner_uid = '".$_SESSION["uid"]."' LIMIT 1");
  226. if (db_num_rows($result) == 1) {
  227. $tags_to_cache = array();
  228. $int_id = db_fetch_result($result, 0, "int_id");
  229. db_query($this->link, "DELETE FROM ttrss_tags WHERE
  230. post_int_id = $int_id AND owner_uid = '".$_SESSION["uid"]."'");
  231. foreach ($tags as $tag) {
  232. $tag = sanitize_tag($tag);
  233. if (!tag_is_valid($tag)) {
  234. continue;
  235. }
  236. if (preg_match("/^[0-9]*$/", $tag)) {
  237. continue;
  238. }
  239. // print "<!-- $id : $int_id : $tag -->";
  240. if ($tag != '') {
  241. db_query($this->link, "INSERT INTO ttrss_tags
  242. (post_int_id, owner_uid, tag_name) VALUES ('$int_id', '".$_SESSION["uid"]."', '$tag')");
  243. }
  244. array_push($tags_to_cache, $tag);
  245. }
  246. /* update tag cache */
  247. sort($tags_to_cache);
  248. $tags_str = join(",", $tags_to_cache);
  249. db_query($this->link, "UPDATE ttrss_user_entries
  250. SET tag_cache = '$tags_str' WHERE ref_id = '$id'
  251. AND owner_uid = " . $_SESSION["uid"]);
  252. }
  253. db_query($this->link, "COMMIT");
  254. $tags = get_article_tags($this->link, $id);
  255. $tags_str = format_tags_string($tags, $id);
  256. $tags_str_full = join(", ", $tags);
  257. if (!$tags_str_full) $tags_str_full = __("no tags");
  258. print json_encode(array("tags_str" => array("id" => $id,
  259. "content" => $tags_str, "content_full" => $tags_str_full)));
  260. }
  261. function regenOPMLKey() {
  262. $this->update_feed_access_key($this->link, 'OPML:Publish',
  263. false, $_SESSION["uid"]);
  264. $new_link = Opml::opml_publish_url($this->link);
  265. print json_encode(array("link" => $new_link));
  266. }
  267. function completeLabels() {
  268. $search = db_escape_string($this->link, $_REQUEST["search"]);
  269. $result = db_query($this->link, "SELECT DISTINCT caption FROM
  270. ttrss_labels2
  271. WHERE owner_uid = '".$_SESSION["uid"]."' AND
  272. LOWER(caption) LIKE LOWER('$search%') ORDER BY caption
  273. LIMIT 5");
  274. print "<ul>";
  275. while ($line = db_fetch_assoc($result)) {
  276. print "<li>" . $line["caption"] . "</li>";
  277. }
  278. print "</ul>";
  279. }
  280. function completeTags() {
  281. $search = db_escape_string($this->link, $_REQUEST["search"]);
  282. $result = db_query($this->link, "SELECT DISTINCT tag_name FROM ttrss_tags
  283. WHERE owner_uid = '".$_SESSION["uid"]."' AND
  284. tag_name LIKE '$search%' ORDER BY tag_name
  285. LIMIT 10");
  286. print "<ul>";
  287. while ($line = db_fetch_assoc($result)) {
  288. print "<li>" . $line["tag_name"] . "</li>";
  289. }
  290. print "</ul>";
  291. }
  292. function purge() {
  293. $ids = explode(",", db_escape_string($this->link, $_REQUEST["ids"]));
  294. $days = sprintf("%d", $_REQUEST["days"]);
  295. foreach ($ids as $id) {
  296. $result = db_query($this->link, "SELECT id FROM ttrss_feeds WHERE
  297. id = '$id' AND owner_uid = ".$_SESSION["uid"]);
  298. if (db_num_rows($result) == 1) {
  299. purge_feed($this->link, $id, $days);
  300. }
  301. }
  302. }
  303. function getArticles() {
  304. $ids = explode(",", db_escape_string($this->link, $_REQUEST["ids"]));
  305. $articles = array();
  306. foreach ($ids as $id) {
  307. if ($id) {
  308. array_push($articles, format_article($this->link, $id, 0, false));
  309. }
  310. }
  311. print json_encode($articles);
  312. }
  313. function checkDate() {
  314. $date = db_escape_string($this->link, $_REQUEST["date"]);
  315. $date_parsed = strtotime($date);
  316. print json_encode(array("result" => (bool)$date_parsed,
  317. "date" => date("c", $date_parsed)));
  318. }
  319. function assigntolabel() {
  320. return $this->labelops(true);
  321. }
  322. function removefromlabel() {
  323. return $this->labelops(false);
  324. }
  325. function labelops($assign) {
  326. $reply = array();
  327. $ids = explode(",", db_escape_string($this->link, $_REQUEST["ids"]));
  328. $label_id = db_escape_string($this->link, $_REQUEST["lid"]);
  329. $label = db_escape_string($this->link, label_find_caption($this->link, $label_id,
  330. $_SESSION["uid"]));
  331. $reply["info-for-headlines"] = array();
  332. if ($label) {
  333. foreach ($ids as $id) {
  334. if ($assign)
  335. label_add_article($this->link, $id, $label, $_SESSION["uid"]);
  336. else
  337. label_remove_article($this->link, $id, $label, $_SESSION["uid"]);
  338. $labels = get_article_labels($this->link, $id, $_SESSION["uid"]);
  339. array_push($reply["info-for-headlines"],
  340. array("id" => $id, "labels" => format_article_labels($labels, $id)));
  341. }
  342. }
  343. $reply["message"] = "UPDATE_COUNTERS";
  344. print json_encode($reply);
  345. }
  346. function updateFeedBrowser() {
  347. $search = db_escape_string($this->link, $_REQUEST["search"]);
  348. $limit = db_escape_string($this->link, $_REQUEST["limit"]);
  349. $mode = (int) db_escape_string($this->link, $_REQUEST["mode"]);
  350. require_once "feedbrowser.php";
  351. print json_encode(array("content" =>
  352. make_feed_browser($this->link, $search, $limit, $mode),
  353. "mode" => $mode));
  354. }
  355. // Silent
  356. function massSubscribe() {
  357. $payload = json_decode($_REQUEST["payload"], false);
  358. $mode = $_REQUEST["mode"];
  359. if (!$payload || !is_array($payload)) return;
  360. if ($mode == 1) {
  361. foreach ($payload as $feed) {
  362. $title = db_escape_string($this->link, $feed[0]);
  363. $feed_url = db_escape_string($this->link, $feed[1]);
  364. $result = db_query($this->link, "SELECT id FROM ttrss_feeds WHERE
  365. feed_url = '$feed_url' AND owner_uid = " . $_SESSION["uid"]);
  366. if (db_num_rows($result) == 0) {
  367. $result = db_query($this->link, "INSERT INTO ttrss_feeds
  368. (owner_uid,feed_url,title,cat_id,site_url)
  369. VALUES ('".$_SESSION["uid"]."',
  370. '$feed_url', '$title', NULL, '')");
  371. }
  372. }
  373. } else if ($mode == 2) {
  374. // feed archive
  375. foreach ($payload as $id) {
  376. $result = db_query($this->link, "SELECT * FROM ttrss_archived_feeds
  377. WHERE id = '$id' AND owner_uid = " . $_SESSION["uid"]);
  378. if (db_num_rows($result) != 0) {
  379. $site_url = db_escape_string($this->link, db_fetch_result($result, 0, "site_url"));
  380. $feed_url = db_escape_string($this->link, db_fetch_result($result, 0, "feed_url"));
  381. $title = db_escape_string($this->link, db_fetch_result($result, 0, "title"));
  382. $result = db_query($this->link, "SELECT id FROM ttrss_feeds WHERE
  383. feed_url = '$feed_url' AND owner_uid = " . $_SESSION["uid"]);
  384. if (db_num_rows($result) == 0) {
  385. $result = db_query($this->link, "INSERT INTO ttrss_feeds
  386. (owner_uid,feed_url,title,cat_id,site_url)
  387. VALUES ('$id','".$_SESSION["uid"]."',
  388. '$feed_url', '$title', NULL, '$site_url')");
  389. }
  390. }
  391. }
  392. }
  393. }
  394. function catchupFeed() {
  395. $feed_id = db_escape_string($this->link, $_REQUEST['feed_id']);
  396. $is_cat = db_escape_string($this->link, $_REQUEST['is_cat']) == "true";
  397. $max_id = (int) db_escape_string($this->link, $_REQUEST['max_id']);
  398. catchup_feed($this->link, $feed_id, $is_cat, false, $max_id);
  399. print json_encode(array("message" => "UPDATE_COUNTERS"));
  400. }
  401. function quickAddCat() {
  402. $cat = db_escape_string($this->link, $_REQUEST["cat"]);
  403. add_feed_category($this->link, $cat);
  404. $result = db_query($this->link, "SELECT id FROM ttrss_feed_categories WHERE
  405. title = '$cat' AND owner_uid = " . $_SESSION["uid"]);
  406. if (db_num_rows($result) == 1) {
  407. $id = db_fetch_result($result, 0, "id");
  408. } else {
  409. $id = 0;
  410. }
  411. print_feed_cat_select($this->link, "cat_id", $id);
  412. }
  413. function regenFeedKey() {
  414. $feed_id = db_escape_string($this->link, $_REQUEST['id']);
  415. $is_cat = db_escape_string($this->link, $_REQUEST['is_cat']) == "true";
  416. $new_key = $this->update_feed_access_key($this->link, $feed_id, $is_cat);
  417. print json_encode(array("link" => $new_key));
  418. }
  419. // Silent
  420. function clearKeys() {
  421. db_query($this->link, "DELETE FROM ttrss_access_keys WHERE
  422. owner_uid = " . $_SESSION["uid"]);
  423. }
  424. // Silent
  425. function clearArticleKeys() {
  426. db_query($this->link, "UPDATE ttrss_user_entries SET uuid = '' WHERE
  427. owner_uid = " . $_SESSION["uid"]);
  428. return;
  429. }
  430. function verifyRegexp() {
  431. $reg_exp = $_REQUEST["reg_exp"];
  432. $status = @preg_match("/$reg_exp/i", "TEST") !== false;
  433. print json_encode(array("status" => $status));
  434. }
  435. /* function buttonPlugin() {
  436. $pclass = "button_" . basename($_REQUEST['plugin']);
  437. $method = $_REQUEST['plugin_method'];
  438. if (class_exists($pclass)) {
  439. $plugin = new $pclass($this->link);
  440. if (method_exists($plugin, $method)) {
  441. return $plugin->$method();
  442. }
  443. }
  444. } */
  445. function genHash() {
  446. $hash = sha1(uniqid(rand(), true));
  447. print json_encode(array("hash" => $hash));
  448. }
  449. function batchAddFeeds() {
  450. $cat_id = db_escape_string($this->link, $_REQUEST['cat']);
  451. $feeds = explode("\n", db_escape_string($this->link, $_REQUEST['feeds']));
  452. $login = db_escape_string($this->link, $_REQUEST['login']);
  453. $pass = db_escape_string($this->link, $_REQUEST['pass']);
  454. foreach ($feeds as $feed) {
  455. $feed = trim($feed);
  456. if (validate_feed_url($feed)) {
  457. db_query($this->link, "BEGIN");
  458. if ($cat_id == "0" || !$cat_id) {
  459. $cat_qpart = "NULL";
  460. } else {
  461. $cat_qpart = "'$cat_id'";
  462. }
  463. $result = db_query($this->link,
  464. "SELECT id FROM ttrss_feeds
  465. WHERE feed_url = '$feed' AND owner_uid = ".$_SESSION["uid"]);
  466. if (db_num_rows($result) == 0) {
  467. $result = db_query($this->link,
  468. "INSERT INTO ttrss_feeds
  469. (owner_uid,feed_url,title,cat_id,auth_login,auth_pass,update_method)
  470. VALUES ('".$_SESSION["uid"]."', '$feed',
  471. '[Unknown]', $cat_qpart, '$login', '$pass', 0)");
  472. }
  473. db_query($this->link, "COMMIT");
  474. }
  475. }
  476. }
  477. function setScore() {
  478. $ids = db_escape_string($this->link, $_REQUEST['id']);
  479. $score = (int)db_escape_string($this->link, $_REQUEST['score']);
  480. db_query($this->link, "UPDATE ttrss_user_entries SET
  481. score = '$score' WHERE ref_id IN ($ids) AND owner_uid = " . $_SESSION["uid"]);
  482. print json_encode(array("id" => $id,
  483. "score_pic" => get_score_pic($score)));
  484. }
  485. function setpanelmode() {
  486. $wide = (int) $_REQUEST["wide"];
  487. setcookie("ttrss_widescreen", $wide,
  488. time() + SESSION_COOKIE_LIFETIME);
  489. print json_encode(array("wide" => $wide));
  490. }
  491. function updaterandomfeed() {
  492. // Test if the feed need a update (update interval exceded).
  493. if (DB_TYPE == "pgsql") {
  494. $update_limit_qpart = "AND ((
  495. ttrss_feeds.update_interval = 0
  496. AND ttrss_feeds.last_updated < NOW() - CAST((ttrss_user_prefs.value || ' minutes') AS INTERVAL)
  497. ) OR (
  498. ttrss_feeds.update_interval > 0
  499. AND ttrss_feeds.last_updated < NOW() - CAST((ttrss_feeds.update_interval || ' minutes') AS INTERVAL)
  500. ) OR ttrss_feeds.last_updated IS NULL
  501. OR last_updated = '1970-01-01 00:00:00')";
  502. } else {
  503. $update_limit_qpart = "AND ((
  504. ttrss_feeds.update_interval = 0
  505. AND ttrss_feeds.last_updated < DATE_SUB(NOW(), INTERVAL CONVERT(ttrss_user_prefs.value, SIGNED INTEGER) MINUTE)
  506. ) OR (
  507. ttrss_feeds.update_interval > 0
  508. AND ttrss_feeds.last_updated < DATE_SUB(NOW(), INTERVAL ttrss_feeds.update_interval MINUTE)
  509. ) OR ttrss_feeds.last_updated IS NULL
  510. OR last_updated = '1970-01-01 00:00:00')";
  511. }
  512. // Test if feed is currently being updated by another process.
  513. if (DB_TYPE == "pgsql") {
  514. $updstart_thresh_qpart = "AND (ttrss_feeds.last_update_started IS NULL OR ttrss_feeds.last_update_started < NOW() - INTERVAL '5 minutes')";
  515. } else {
  516. $updstart_thresh_qpart = "AND (ttrss_feeds.last_update_started IS NULL OR ttrss_feeds.last_update_started < DATE_SUB(NOW(), INTERVAL 5 MINUTE))";
  517. }
  518. $random_qpart = sql_random_function();
  519. // We search for feed needing update.
  520. $result = db_query($this->link, "SELECT ttrss_feeds.feed_url,ttrss_feeds.id
  521. FROM
  522. ttrss_feeds, ttrss_users, ttrss_user_prefs
  523. WHERE
  524. ttrss_feeds.owner_uid = ttrss_users.id
  525. AND ttrss_users.id = ttrss_user_prefs.owner_uid
  526. AND ttrss_user_prefs.pref_name = 'DEFAULT_UPDATE_INTERVAL'
  527. AND ttrss_feeds.owner_uid = ".$_SESSION["uid"]."
  528. $update_limit_qpart $updstart_thresh_qpart
  529. ORDER BY $random_qpart LIMIT 30");
  530. $feed_id = -1;
  531. require_once "rssfuncs.php";
  532. $num_updated = 0;
  533. $tstart = time();
  534. while ($line = db_fetch_assoc($result)) {
  535. $feed_id = $line["id"];
  536. if (time() - $tstart < ini_get("max_execution_time") * 0.7) {
  537. update_rss_feed($this->link, $feed_id, true);
  538. ++$num_updated;
  539. } else {
  540. break;
  541. }
  542. }
  543. if ($num_updated > 0) {
  544. print json_encode(array("message" => "UPDATE_COUNTERS",
  545. "num_updated" => $num_updated));
  546. } else {
  547. print json_encode(array("message" => "NOTHING_TO_UPDATE"));
  548. }
  549. }
  550. function update_feed_access_key($link, $feed_id, $is_cat, $owner_uid = false) {
  551. if (!$owner_uid) $owner_uid = $_SESSION["uid"];
  552. $sql_is_cat = bool_to_sql_bool($is_cat);
  553. $result = db_query($link, "SELECT access_key FROM ttrss_access_keys
  554. WHERE feed_id = '$feed_id' AND is_cat = $sql_is_cat
  555. AND owner_uid = " . $owner_uid);
  556. if (db_num_rows($result) == 1) {
  557. $key = db_escape_string($this->link, sha1(uniqid(rand(), true)));
  558. db_query($link, "UPDATE ttrss_access_keys SET access_key = '$key'
  559. WHERE feed_id = '$feed_id' AND is_cat = $sql_is_cat
  560. AND owner_uid = " . $owner_uid);
  561. return $key;
  562. } else {
  563. return get_feed_access_key($link, $feed_id, $is_cat, $owner_uid);
  564. }
  565. }
  566. private function markArticlesById($link, $ids, $cmode) {
  567. $tmp_ids = array();
  568. foreach ($ids as $id) {
  569. array_push($tmp_ids, "ref_id = '$id'");
  570. }
  571. $ids_qpart = join(" OR ", $tmp_ids);
  572. if ($cmode == 0) {
  573. db_query($link, "UPDATE ttrss_user_entries SET
  574. marked = false, last_marked = NOW()
  575. WHERE ($ids_qpart) AND owner_uid = " . $_SESSION["uid"]);
  576. } else if ($cmode == 1) {
  577. db_query($link, "UPDATE ttrss_user_entries SET
  578. marked = true, last_marked = NOW()
  579. WHERE ($ids_qpart) AND owner_uid = " . $_SESSION["uid"]);
  580. } else {
  581. db_query($link, "UPDATE ttrss_user_entries SET
  582. marked = NOT marked,last_marked = NOW()
  583. WHERE ($ids_qpart) AND owner_uid = " . $_SESSION["uid"]);
  584. }
  585. }
  586. private function publishArticlesById($link, $ids, $cmode) {
  587. $tmp_ids = array();
  588. foreach ($ids as $id) {
  589. array_push($tmp_ids, "ref_id = '$id'");
  590. }
  591. $ids_qpart = join(" OR ", $tmp_ids);
  592. if ($cmode == 0) {
  593. db_query($link, "UPDATE ttrss_user_entries SET
  594. published = false,last_published = NOW()
  595. WHERE ($ids_qpart) AND owner_uid = " . $_SESSION["uid"]);
  596. } else if ($cmode == 1) {
  597. db_query($link, "UPDATE ttrss_user_entries SET
  598. published = true,last_published = NOW()
  599. WHERE ($ids_qpart) AND owner_uid = " . $_SESSION["uid"]);
  600. } else {
  601. db_query($link, "UPDATE ttrss_user_entries SET
  602. published = NOT published,last_published = NOW()
  603. WHERE ($ids_qpart) AND owner_uid = " . $_SESSION["uid"]);
  604. }
  605. if (PUBSUBHUBBUB_HUB) {
  606. $rss_link = get_self_url_prefix() .
  607. "/public.php?op=rss&id=-2&key=" .
  608. get_feed_access_key($link, -2, false);
  609. $p = new Publisher(PUBSUBHUBBUB_HUB);
  610. $pubsub_result = $p->publish_update($rss_link);
  611. }
  612. }
  613. function getlinktitlebyid() {
  614. $id = db_escape_string($this->link, $_REQUEST['id']);
  615. $result = db_query($this->link, "SELECT link, title FROM ttrss_entries, ttrss_user_entries
  616. WHERE ref_id = '$id' AND ref_id = id AND owner_uid = ". $_SESSION["uid"]);
  617. if (db_num_rows($result) != 0) {
  618. $link = db_fetch_result($result, 0, "link");
  619. $title = db_fetch_result($result, 0, "title");
  620. echo json_encode(array("link" => $link, "title" => $title));
  621. } else {
  622. echo json_encode(array("error" => "ARTICLE_NOT_FOUND"));
  623. }
  624. }
  625. function cdmArticlePreview() {
  626. $id = db_escape_string($this->link, $_REQUEST['id']);
  627. $result = db_query($this->link, "SELECT link,
  628. ttrss_entries.title, content, feed_url
  629. FROM
  630. ttrss_entries, ttrss_user_entries
  631. LEFT JOIN ttrss_feeds ON (ttrss_user_entries.feed_id = ttrss_feeds.id)
  632. WHERE ref_id = '$id' AND ref_id = ttrss_entries.id AND
  633. ttrss_user_entries.owner_uid = ". $_SESSION["uid"]);
  634. if (db_num_rows($result) != 0) {
  635. $link = db_fetch_result($result, 0, "link");
  636. $title = db_fetch_result($result, 0, "title");
  637. $feed_url = db_fetch_result($result, 0, "feed_url");
  638. $content = sanitize($this->link,
  639. db_fetch_result($result, 0, "content"), false, false, $feed_url);
  640. print "<div class='content'>".$content."</content>";
  641. } else {
  642. print "Article not found.";
  643. }
  644. }
  645. }
  646. ?>