fever.php 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572
  1. <?php
  2. declare(strict_types=1);
  3. /**
  4. * Fever API for FreshRSS
  5. * Version 0.1
  6. * Author: Kevin Papst / https://github.com/kevinpapst
  7. * Documentation: https://feedafever.com/api
  8. *
  9. * Inspired by:
  10. * TinyTinyRSS Fever API plugin @dasmurphy
  11. * See https://github.com/dasmurphy/tinytinyrss-fever-plugin
  12. */
  13. // ================================================================================================
  14. // BOOTSTRAP FreshRSS
  15. require(__DIR__ . '/../../constants.php');
  16. require(LIB_PATH . '/lib_rss.php'); //Includes class autoloader
  17. FreshRSS_Context::initSystem();
  18. // check if API is enabled globally
  19. if (!FreshRSS_Context::hasSystemConf() || !FreshRSS_Context::systemConf()->api_enabled) {
  20. Minz_Log::warning('Fever API: service unavailable!');
  21. Minz_Log::debug('Fever API: serviceUnavailable() ' . debugInfo(), API_LOG);
  22. header('HTTP/1.1 503 Service Unavailable');
  23. header('Content-Type: text/plain; charset=UTF-8');
  24. die('Service Unavailable!');
  25. }
  26. Minz_Session::init('FreshRSS', true);
  27. // ================================================================================================
  28. // <Debug>
  29. $ORIGINAL_INPUT = file_get_contents('php://input', false, null, 0, 1_048_576) ?: '';;
  30. function debugInfo(): string {
  31. if (function_exists('getallheaders')) {
  32. $ALL_HEADERS = getallheaders();
  33. } else { //nginx http://php.net/getallheaders#84262
  34. $ALL_HEADERS = [];
  35. foreach ($_SERVER as $name => $value) {
  36. if (str_starts_with($name, 'HTTP_')) {
  37. $ALL_HEADERS[str_replace(' ', '-', ucwords(strtolower(str_replace('_', ' ', substr($name, 5)))))] = $value;
  38. }
  39. }
  40. }
  41. global $ORIGINAL_INPUT;
  42. $log = sensitive_log([
  43. 'date' => date('c'),
  44. 'headers' => $ALL_HEADERS,
  45. '_SERVER' => $_SERVER,
  46. '_GET' => $_GET,
  47. '_POST' => $_POST,
  48. '_COOKIE' => $_COOKIE,
  49. 'INPUT' => $ORIGINAL_INPUT,
  50. ]);
  51. return print_r($log, true);
  52. }
  53. //Minz_Log::debug('----------------------------------------------------------------', API_LOG);
  54. //Minz_Log::debug(debugInfo(), API_LOG);
  55. // </Debug>
  56. final class FeverDAO extends Minz_ModelPdo
  57. {
  58. /**
  59. * @param array<string|int> $values
  60. * @param array<string,string|int> $bindArray
  61. */
  62. private function bindParamArray(string $prefix, array $values, array &$bindArray): string {
  63. $str = '';
  64. foreach ($values as $i => $iValue) {
  65. $str .= ':' . $prefix . $i . ',';
  66. $bindArray[$prefix . $i] = $iValue;
  67. }
  68. return rtrim($str, ',');
  69. }
  70. /**
  71. * @param array<string|int> $feed_ids
  72. * @param array<string> $entry_ids
  73. * @return FreshRSS_Entry[]
  74. */
  75. public function findEntries(array $feed_ids, array $entry_ids, string $max_id, string $since_id): array {
  76. $values = [];
  77. $order = '';
  78. $entryDAO = FreshRSS_Factory::createEntryDao();
  79. $sql = 'SELECT id, guid, title, author, '
  80. . ($entryDAO::isCompressed() ? 'UNCOMPRESS(content_bin) AS content' : 'content')
  81. . ', link, date, is_read, is_favorite, id_feed, attributes '
  82. . 'FROM `_entry` WHERE';
  83. if (!empty($entry_ids)) {
  84. $bindEntryIds = $this->bindParamArray('id', $entry_ids, $values);
  85. $sql .= " id IN($bindEntryIds)";
  86. } elseif ($max_id != '') {
  87. $sql .= ' id < :id';
  88. $values[':id'] = $max_id;
  89. $order = ' ORDER BY id DESC';
  90. } elseif ($since_id != '') {
  91. $sql .= ' id > :id';
  92. $values[':id'] = $since_id;
  93. $order = ' ORDER BY id ASC';
  94. } else {
  95. $sql .= ' 1=1';
  96. }
  97. if (!empty($feed_ids)) {
  98. $bindFeedIds = $this->bindParamArray('feed', $feed_ids, $values);
  99. $sql .= " AND id_feed IN($bindFeedIds)";
  100. }
  101. $sql .= $order;
  102. $sql .= ' LIMIT 50';
  103. $stm = $this->pdo->prepare($sql);
  104. if ($stm !== false && $stm->execute($values)) {
  105. $result = $stm->fetchAll(PDO::FETCH_ASSOC);
  106. $entries = [];
  107. foreach ($result as $dao) {
  108. $entries[] = FreshRSS_Entry::fromArray($dao);
  109. }
  110. return $entries;
  111. }
  112. return [];
  113. }
  114. }
  115. /**
  116. * Class FeverAPI
  117. */
  118. final class FeverAPI
  119. {
  120. public const API_LEVEL = 3;
  121. public const STATUS_OK = 1;
  122. public const STATUS_ERR = 0;
  123. private FreshRSS_EntryDAO $entryDAO;
  124. private FreshRSS_FeedDAO $feedDAO;
  125. /**
  126. * Authenticate the user
  127. *
  128. * API Password sent from client is the result of the md5 sum of
  129. * your FreshRSS "username:your-api-password" combination
  130. */
  131. private function authenticate(): bool {
  132. FreshRSS_Context::clearUserConf();
  133. Minz_User::change();
  134. $feverKey = empty($_POST['api_key']) ? '' : substr(trim($_POST['api_key']), 0, 128);
  135. if (ctype_xdigit($feverKey)) {
  136. $feverKey = strtolower($feverKey);
  137. $username = @file_get_contents(DATA_PATH . '/fever/.key-' . sha1(FreshRSS_Context::systemConf()->salt) . '-' . $feverKey . '.txt', false);
  138. if ($username != false) {
  139. $username = trim($username);
  140. FreshRSS_Context::initUser($username);
  141. if ($feverKey === FreshRSS_Context::userConf()->feverKey && FreshRSS_Context::userConf()->enabled) {
  142. Minz_Translate::init(FreshRSS_Context::userConf()->language);
  143. $this->entryDAO = FreshRSS_Factory::createEntryDao();
  144. $this->feedDAO = FreshRSS_Factory::createFeedDao();
  145. return true;
  146. } else {
  147. Minz_Translate::init();
  148. }
  149. Minz_Log::error('Fever API: Reset API password for user: ' . $username, API_LOG);
  150. Minz_Log::error('Fever API: Please reset your API password!');
  151. Minz_User::change();
  152. }
  153. Minz_Log::warning('Fever API: wrong credentials! ' . $feverKey, API_LOG);
  154. }
  155. return false;
  156. }
  157. public function isAuthenticatedApiUser(): bool {
  158. $this->authenticate();
  159. return FreshRSS_Context::hasUserConf();
  160. }
  161. /**
  162. * This does all the processing, since the fever api does not have a specific variable that specifies the operation
  163. * @return array<string,mixed>
  164. * @throws Exception
  165. */
  166. public function process(): array {
  167. $response_arr = [];
  168. if (!$this->isAuthenticatedApiUser()) {
  169. throw new Exception('No user given or user is not allowed to access API');
  170. }
  171. if (isset($_REQUEST['groups'])) {
  172. $response_arr['groups'] = $this->getGroups();
  173. $response_arr['feeds_groups'] = $this->getFeedsGroup();
  174. }
  175. if (isset($_REQUEST['feeds'])) {
  176. $response_arr['feeds'] = $this->getFeeds();
  177. $response_arr['feeds_groups'] = $this->getFeedsGroup();
  178. }
  179. if (isset($_REQUEST['favicons'])) {
  180. $response_arr['favicons'] = $this->getFavicons();
  181. }
  182. if (isset($_REQUEST['items'])) {
  183. $response_arr['total_items'] = $this->getTotalItems();
  184. $response_arr['items'] = $this->getItems();
  185. }
  186. if (isset($_REQUEST['links'])) {
  187. $response_arr['links'] = $this->getLinks();
  188. }
  189. if (isset($_REQUEST['unread_item_ids'])) {
  190. $response_arr['unread_item_ids'] = $this->getUnreadItemIds();
  191. }
  192. if (isset($_REQUEST['saved_item_ids'])) {
  193. $response_arr['saved_item_ids'] = $this->getSavedItemIds();
  194. }
  195. if (isset($_REQUEST['mark'], $_REQUEST['as'], $_REQUEST['id']) && ctype_digit($_REQUEST['id'])) {
  196. $id = (string)$_REQUEST['id'];
  197. $before = (int)($_REQUEST['before'] ?? '0');
  198. switch (strtolower($_REQUEST['mark'])) {
  199. case 'item':
  200. switch ($_REQUEST['as']) {
  201. case 'read':
  202. $this->setItemAsRead($id);
  203. break;
  204. case 'saved':
  205. $this->setItemAsSaved($id);
  206. break;
  207. case 'unread':
  208. $this->setItemAsUnread($id);
  209. break;
  210. case 'unsaved':
  211. $this->setItemAsUnsaved($id);
  212. break;
  213. }
  214. break;
  215. case 'feed':
  216. switch ($_REQUEST['as']) {
  217. case 'read':
  218. $this->setFeedAsRead((int)$id, $before);
  219. break;
  220. }
  221. break;
  222. case 'group':
  223. switch ($_REQUEST['as']) {
  224. case 'read':
  225. $this->setGroupAsRead((int)$id, $before);
  226. break;
  227. }
  228. break;
  229. }
  230. switch ($_REQUEST['as']) {
  231. case 'read':
  232. case 'unread':
  233. $response_arr['unread_item_ids'] = $this->getUnreadItemIds();
  234. break;
  235. case 'saved':
  236. case 'unsaved':
  237. $response_arr['saved_item_ids'] = $this->getSavedItemIds();
  238. break;
  239. }
  240. }
  241. return $response_arr;
  242. }
  243. /**
  244. * Returns the complete JSON, with 'api_version' and status as 'auth'.
  245. * @param array<string,mixed> $reply
  246. */
  247. public function wrap(int $status, array $reply = []): string {
  248. $arr = ['api_version' => self::API_LEVEL, 'auth' => $status];
  249. if ($status === self::STATUS_OK) {
  250. $arr['last_refreshed_on_time'] = $this->lastRefreshedOnTime();
  251. $arr = array_merge($arr, $reply);
  252. }
  253. return json_encode($arr) ?: '';
  254. }
  255. /**
  256. * every authenticated method includes last_refreshed_on_time
  257. */
  258. private function lastRefreshedOnTime(): int {
  259. $lastUpdate = 0;
  260. $entries = $this->feedDAO->listFeedsOrderUpdate(-1, 1);
  261. $feed = current($entries);
  262. if (!empty($feed)) {
  263. $lastUpdate = $feed->lastUpdate();
  264. }
  265. return $lastUpdate;
  266. }
  267. /** @return array<array<string,string|int>> */
  268. private function getFeeds(): array {
  269. $feeds = [];
  270. $myFeeds = $this->feedDAO->listFeeds();
  271. /** @var FreshRSS_Feed $feed */
  272. foreach ($myFeeds as $feed) {
  273. $feeds[] = [
  274. 'id' => $feed->id(),
  275. 'favicon_id' => $feed->id(),
  276. 'title' => escapeToUnicodeAlternative($feed->name(), true),
  277. 'url' => htmlspecialchars_decode($feed->url(), ENT_QUOTES),
  278. 'site_url' => htmlspecialchars_decode($feed->website(), ENT_QUOTES),
  279. 'is_spark' => 0,
  280. // unsupported
  281. 'last_updated_on_time' => $feed->lastUpdate(),
  282. ];
  283. }
  284. return $feeds;
  285. }
  286. /** @return array<array<string,int|string>> */
  287. private function getGroups(): array {
  288. $groups = [];
  289. $categoryDAO = FreshRSS_Factory::createCategoryDao();
  290. $categories = $categoryDAO->listCategories(false, false) ?: [];
  291. foreach ($categories as $category) {
  292. $groups[] = [
  293. 'id' => $category->id(),
  294. 'title' => escapeToUnicodeAlternative($category->name(), true)
  295. ];
  296. }
  297. return $groups;
  298. }
  299. /** @return array<array<string,int|string>> */
  300. private function getFavicons(): array {
  301. if (!FreshRSS_Context::hasSystemConf()) {
  302. return [];
  303. }
  304. require_once(LIB_PATH . '/favicons.php');
  305. $favicons = [];
  306. $salt = FreshRSS_Context::systemConf()->salt;
  307. $myFeeds = $this->feedDAO->listFeeds();
  308. foreach ($myFeeds as $feed) {
  309. $id = hash('crc32b', $salt . $feed->url());
  310. $filename = DATA_PATH . '/favicons/' . $id . '.ico';
  311. if (!file_exists($filename)) {
  312. continue;
  313. }
  314. $favicons[] = [
  315. 'id' => $feed->id(),
  316. 'data' => contentType($filename) . ';base64,' . base64_encode(file_get_contents($filename) ?: '')
  317. ];
  318. }
  319. return $favicons;
  320. }
  321. private function getTotalItems(): int {
  322. return $this->entryDAO->count();
  323. }
  324. /**
  325. * @return array<array<string,int|string>>
  326. */
  327. private function getFeedsGroup(): array {
  328. $groups = [];
  329. $ids = [];
  330. $myFeeds = $this->feedDAO->listFeeds();
  331. foreach ($myFeeds as $feed) {
  332. $ids[$feed->categoryId()][] = $feed->id();
  333. }
  334. foreach ($ids as $category => $feedIds) {
  335. $groups[] = [
  336. 'group_id' => $category,
  337. 'feed_ids' => implode(',', $feedIds)
  338. ];
  339. }
  340. return $groups;
  341. }
  342. /**
  343. * AFAIK there is no 'hot links' alternative in FreshRSS
  344. * @return array<string>
  345. */
  346. private function getLinks(): array {
  347. return [];
  348. }
  349. /**
  350. * @param array<numeric-string> $ids
  351. */
  352. private function entriesToIdList(array $ids = []): string {
  353. return implode(',', array_values($ids));
  354. }
  355. private function getUnreadItemIds(): string {
  356. $entries = $this->entryDAO->listIdsWhere('a', 0, FreshRSS_Entry::STATE_NOT_READ, 'ASC', 0) ?? [];
  357. return $this->entriesToIdList($entries);
  358. }
  359. private function getSavedItemIds(): string {
  360. $entries = $this->entryDAO->listIdsWhere('a', 0, FreshRSS_Entry::STATE_FAVORITE, 'ASC', 0) ?? [];
  361. return $this->entriesToIdList($entries);
  362. }
  363. /**
  364. * @param numeric-string $id
  365. */
  366. private function setItemAsRead(string $id): int|false {
  367. return $this->entryDAO->markRead($id, true);
  368. }
  369. /**
  370. * @param numeric-string $id
  371. */
  372. private function setItemAsUnread(string $id): int|false {
  373. return $this->entryDAO->markRead($id, false);
  374. }
  375. /**
  376. * @param numeric-string $id
  377. */
  378. private function setItemAsSaved(string $id): int|false {
  379. return $this->entryDAO->markFavorite($id, true);
  380. }
  381. /**
  382. * @param numeric-string $id
  383. */
  384. private function setItemAsUnsaved(string $id): int|false {
  385. return $this->entryDAO->markFavorite($id, false);
  386. }
  387. /** @return array<array<string,string|int>> */
  388. private function getItems(): array {
  389. $feed_ids = [];
  390. $entry_ids = [];
  391. $max_id = '';
  392. $since_id = '';
  393. if (isset($_REQUEST['feed_ids']) || isset($_REQUEST['group_ids'])) {
  394. if (isset($_REQUEST['feed_ids'])) {
  395. $feed_ids = explode(',', $_REQUEST['feed_ids']);
  396. }
  397. if (isset($_REQUEST['group_ids'])) {
  398. $categoryDAO = FreshRSS_Factory::createCategoryDao();
  399. $group_ids = explode(',', $_REQUEST['group_ids']);
  400. $feeds = [];
  401. foreach ($group_ids as $id) {
  402. $category = $categoryDAO->searchById((int)$id); //TODO: Transform to SQL query without loop! Consider FreshRSS_CategoryDAO::listCategories(true)
  403. if ($category == null) {
  404. continue;
  405. }
  406. foreach ($category->feeds() as $feed) {
  407. $feeds[] = $feed->id();
  408. }
  409. }
  410. $feed_ids = array_unique($feeds);
  411. }
  412. }
  413. if (isset($_REQUEST['max_id'])) {
  414. // use the max_id argument to request the previous $item_limit items
  415. $max_id = '' . $_REQUEST['max_id'];
  416. if (!ctype_digit($max_id)) {
  417. $max_id = '';
  418. }
  419. } elseif (isset($_REQUEST['with_ids'])) {
  420. $entry_ids = explode(',', $_REQUEST['with_ids']);
  421. } elseif (isset($_REQUEST['since_id'])) {
  422. // use the since_id argument to request the next $item_limit items
  423. $since_id = '' . $_REQUEST['since_id'];
  424. if (!ctype_digit($since_id)) {
  425. $since_id = '';
  426. }
  427. }
  428. $items = [];
  429. $feverDAO = new FeverDAO();
  430. $entries = $feverDAO->findEntries($feed_ids, $entry_ids, $max_id, $since_id);
  431. // Load list of extensions and enable the "system" ones.
  432. Minz_ExtensionManager::init();
  433. foreach ($entries as $item) {
  434. /** @var FreshRSS_Entry $entry */
  435. $entry = Minz_ExtensionManager::callHook('entry_before_display', $item);
  436. if ($entry == null) {
  437. continue;
  438. }
  439. $items[] = [
  440. 'id' => $entry->id(),
  441. 'feed_id' => $entry->feedId(),
  442. 'title' => escapeToUnicodeAlternative($entry->title(), false),
  443. 'author' => escapeToUnicodeAlternative(trim($entry->authors(true), '; '), false),
  444. 'html' => $entry->content(), 'url' => htmlspecialchars_decode($entry->link(), ENT_QUOTES),
  445. 'is_saved' => $entry->isFavorite() ? 1 : 0,
  446. 'is_read' => $entry->isRead() ? 1 : 0,
  447. 'created_on_time' => $entry->date(true),
  448. ];
  449. }
  450. return $items;
  451. }
  452. /**
  453. * TODO replace by a dynamic fetch for id <= $before timestamp
  454. * @return numeric-string
  455. */
  456. private function convertBeforeToId(int $beforeTimestamp): string {
  457. return $beforeTimestamp == 0 ? '0' : $beforeTimestamp . '000000';
  458. }
  459. private function setFeedAsRead(int $id, int $before): int|false {
  460. $before = $this->convertBeforeToId($before);
  461. return $this->entryDAO->markReadFeed($id, $before);
  462. }
  463. private function setGroupAsRead(int $id, int $before): int|false {
  464. $before = $this->convertBeforeToId($before);
  465. // special case to mark all items as read
  466. if ($id == 0) {
  467. return $this->entryDAO->markReadEntries($before);
  468. }
  469. return $this->entryDAO->markReadCat($id, $before);
  470. }
  471. }
  472. // ================================================================================================
  473. // refresh is not allowed yet, probably we find a way to support it later
  474. if (isset($_REQUEST['refresh'])) {
  475. Minz_Log::warning('Fever API: Refresh items - notImplemented()', API_LOG);
  476. header('HTTP/1.1 501 Not Implemented');
  477. header('Content-Type: text/plain; charset=UTF-8');
  478. die('Not Implemented!');
  479. }
  480. // Start the Fever API handling
  481. $handler = new FeverAPI();
  482. header('Content-Type: application/json; charset=UTF-8');
  483. if (!$handler->isAuthenticatedApiUser()) {
  484. echo $handler->wrap(FeverAPI::STATUS_ERR, []);
  485. } else {
  486. echo $handler->wrap(FeverAPI::STATUS_OK, $handler->process());
  487. }