Ver Fonte

Better enforce feed limits (#9357)

E.g. when added from API
Fix https://github.com/FreshRSS/FreshRSS/issues/8822#issuecomment-5781019651
Alexandre Alapetite há 15 horas atrás
pai
commit
a8e5e6300b

+ 20 - 5
app/Controllers/feedController.php

@@ -37,6 +37,13 @@ class FreshRSS_feed_Controller extends FreshRSS_ActionController {
 	 */
 	 */
 	public static function addFeed(string $url, string $title = '', int $cat_id = 0, string $new_cat_name = '',
 	public static function addFeed(string $url, string $title = '', int $cat_id = 0, string $new_cat_name = '',
 		string $http_auth = '', array $attributes = [], int $kind = FreshRSS_Feed::KIND_RSS): FreshRSS_Feed {
 		string $http_auth = '', array $attributes = [], int $kind = FreshRSS_Feed::KIND_RSS): FreshRSS_Feed {
+		$limits = FreshRSS_Context::systemConf()->limits;
+		$feedDAO = FreshRSS_Factory::createFeedDao();
+		if ($limits['max_feeds'] > 0 && $feedDAO->count() >= $limits['max_feeds']) {
+			Minz_Log::warning(_t('feedback.sub.feed.over_max', $limits['max_feeds']));
+			throw new FreshRSS_FeedNotAdded_Exception($url);
+		}
+
 		FreshRSS_UserDAO::touch();
 		FreshRSS_UserDAO::touch();
 		if (function_exists('set_time_limit')) {
 		if (function_exists('set_time_limit')) {
 			@set_time_limit(300);
 			@set_time_limit(300);
@@ -58,9 +65,13 @@ class FreshRSS_feed_Controller extends FreshRSS_ActionController {
 			$cat = $catDAO->searchById($cat_id);
 			$cat = $catDAO->searchById($cat_id);
 		}
 		}
 		if ($cat === null && $new_cat_name != '') {
 		if ($cat === null && $new_cat_name != '') {
-			$new_cat_id = $catDAO->addCategory(['name' => $new_cat_name]);
-			$cat_id = $new_cat_id > 0 ? $new_cat_id : $cat_id;
-			$cat = $catDAO->searchById($cat_id);
+			if ($limits['max_categories'] > 0 && $catDAO->count() >= $limits['max_categories']) {
+				Minz_Log::warning(_t('feedback.sub.category.over_max', $limits['max_categories']));
+			} else {
+				$new_cat_id = $catDAO->addCategory(['name' => $new_cat_name]);
+				$cat_id = $new_cat_id > 0 ? $new_cat_id : $cat_id;
+				$cat = $catDAO->searchById($cat_id);
+			}
 		}
 		}
 		if ($cat === null) {
 		if ($cat === null) {
 			$catDAO->checkDefault();
 			$catDAO->checkDefault();
@@ -92,7 +103,6 @@ class FreshRSS_feed_Controller extends FreshRSS_ActionController {
 				break;
 				break;
 		}
 		}
 
 
-		$feedDAO = FreshRSS_Factory::createFeedDao();
 		if ($feedDAO->searchByUrl($feed->url()) !== null) {
 		if ($feedDAO->searchByUrl($feed->url()) !== null) {
 			throw new FreshRSS_AlreadySubscribed_Exception($url, $feed->name());
 			throw new FreshRSS_AlreadySubscribed_Exception($url, $feed->name());
 		}
 		}
@@ -1070,7 +1080,12 @@ class FreshRSS_feed_Controller extends FreshRSS_ActionController {
 			$cat_id = $cat === null ? 0 : $cat->id();
 			$cat_id = $cat === null ? 0 : $cat->id();
 		}
 		}
 		if ($cat_id <= 1 && $new_cat_name != '') {
 		if ($cat_id <= 1 && $new_cat_name != '') {
-			$cat_id = $catDAO->addCategory(['name' => $new_cat_name]);
+			$limits = FreshRSS_Context::systemConf()->limits;
+			if ($limits['max_categories'] > 0 && $catDAO->count() >= $limits['max_categories']) {
+				Minz_Log::warning(_t('feedback.sub.category.over_max', $limits['max_categories']));
+			} else {
+				$cat_id = $catDAO->addCategory(['name' => $new_cat_name]) ?: $cat_id;
+			}
 		}
 		}
 		if ($cat_id <= 1) {
 		if ($cat_id <= 1) {
 			$catDAO->checkDefault();
 			$catDAO->checkDefault();

+ 12 - 1
app/Controllers/importExportController.php

@@ -711,7 +711,18 @@ class FreshRSS_importExport_Controller extends FreshRSS_ActionController {
 		$cat_name = Minz_Helper::htmlspecialchars_utf8(trim($origin['category'] ?? ''));
 		$cat_name = Minz_Helper::htmlspecialchars_utf8(trim($origin['category'] ?? ''));
 		if ($cat_name !== '') {
 		if ($cat_name !== '') {
 			$new_cat = $this->categoryDAO->searchByName($cat_name);
 			$new_cat = $this->categoryDAO->searchByName($cat_name);
-			$cat_id = $new_cat?->id() ?: $this->categoryDAO->addCategory(['name' => $cat_name]) ?: FreshRSS_CategoryDAO::DEFAULTCATEGORYID;
+			$cat_id = $new_cat?->id() ?: 0;
+			if ($cat_id === 0) {
+				$limits = FreshRSS_Context::systemConf()->limits;
+				if ($limits['max_categories'] > 0 && $this->categoryDAO->count() >= $limits['max_categories']) {
+					Minz_Log::warning(_t('feedback.sub.category.over_max', $limits['max_categories']));
+				} else {
+					$cat_id = $this->categoryDAO->addCategory(['name' => $cat_name]) ?: 0;
+				}
+			}
+			if ($cat_id === 0) {
+				$cat_id = FreshRSS_CategoryDAO::DEFAULTCATEGORYID;
+			}
 		}
 		}
 
 
 		try {
 		try {

+ 6 - 1
p/api/greader.php

@@ -421,7 +421,12 @@ final class GReaderAPI {
 				$cat = $categoryDAO->searchByName($c_name);
 				$cat = $categoryDAO->searchByName($c_name);
 				$addCatId = $cat === null ? 0 : $cat->id();
 				$addCatId = $cat === null ? 0 : $cat->id();
 				if ($addCatId === 0) {
 				if ($addCatId === 0) {
-					$addCatId = $categoryDAO->addCategory(['name' => $c_name]) ?: FreshRSS_CategoryDAO::DEFAULTCATEGORYID;
+					$limits = FreshRSS_Context::systemConf()->limits;
+					if ($limits['max_categories'] > 0 && $categoryDAO->count() >= $limits['max_categories']) {
+						Minz_Log::warning(_t('feedback.sub.category.over_max', $limits['max_categories']), API_LOG);
+					} else {
+						$addCatId = $categoryDAO->addCategory(['name' => $c_name]) ?: FreshRSS_CategoryDAO::DEFAULTCATEGORYID;
+					}
 				}
 				}
 			}
 			}
 		} elseif (str_starts_with($remove, 'user/-/label/')) {
 		} elseif (str_starts_with($remove, 'user/-/label/')) {