subscriptionController.php 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426
  1. <?php
  2. declare(strict_types=1);
  3. /**
  4. * Controller to handle subscription actions.
  5. */
  6. class FreshRSS_subscription_Controller extends FreshRSS_ActionController {
  7. /**
  8. * This action is called before every other action in that class. It is
  9. * the common boilerplate for every action. It is triggered by the
  10. * underlying framework.
  11. */
  12. #[\Override]
  13. public function firstAction(): void {
  14. if (!FreshRSS_Auth::hasAccess()) {
  15. Minz_Error::error(403);
  16. }
  17. $catDAO = FreshRSS_Factory::createCategoryDao();
  18. $catDAO->checkDefault();
  19. $this->view->categories = $catDAO->listSortedCategories(prePopulateFeeds: false, details: true);
  20. $signalError = false;
  21. foreach ($this->view->categories as $cat) {
  22. $feeds = $cat->feeds();
  23. foreach ($feeds as $feed) {
  24. if ($feed->inError()) {
  25. $signalError = true;
  26. }
  27. }
  28. if ($signalError) {
  29. break;
  30. }
  31. }
  32. $this->view->signalError = $signalError;
  33. }
  34. /**
  35. * This action handles the main subscription page
  36. *
  37. * It displays categories and associated feeds.
  38. */
  39. public function indexAction(): void {
  40. FreshRSS_View::appendScript(Minz_Url::display('/scripts/category.js?' . @filemtime(PUBLIC_PATH . '/scripts/category.js')));
  41. FreshRSS_View::appendScript(Minz_Url::display('/scripts/feed.js?' . @filemtime(PUBLIC_PATH . '/scripts/feed.js')));
  42. FreshRSS_View::prependTitle(_t('sub.title') . ' · ');
  43. $this->_csp([
  44. 'default-src' => "'self'",
  45. 'frame-ancestors' => FreshRSS_Context::systemConf()->attributeString('csp.frame-ancestors') ?? "'none'",
  46. 'img-src' => "'self' blob:",
  47. ]);
  48. $this->view->onlyFeedsWithError = Minz_Request::paramBoolean('error');
  49. $id = Minz_Request::paramInt('id');
  50. $this->view->displaySlider = false;
  51. if ($id !== 0) {
  52. $type = Minz_Request::paramString('type');
  53. $this->view->displaySlider = true;
  54. switch ($type) {
  55. case 'category':
  56. $categoryDAO = FreshRSS_Factory::createCategoryDao();
  57. $this->view->category = $categoryDAO->searchById($id);
  58. break;
  59. default:
  60. $feedDAO = FreshRSS_Factory::createFeedDao();
  61. $this->view->feed = $feedDAO->searchById($id) ?? FreshRSS_Feed::default();
  62. break;
  63. }
  64. }
  65. }
  66. /**
  67. * This action handles the feed configuration page.
  68. *
  69. * It displays the feed configuration page.
  70. * If this action is reached through a POST request, it stores all new
  71. * configuration values then sends a notification to the user.
  72. *
  73. * The options available on the page are:
  74. * - name
  75. * - description
  76. * - website URL
  77. * - feed URL
  78. * - category id (default: default category id)
  79. * - CSS path to article on website
  80. * - favicon
  81. * - display in main stream (default: 0)
  82. * - HTTP authentication
  83. * - number of article to retain (default: -2)
  84. * - refresh frequency (default: 0)
  85. * Default values are empty strings unless specified.
  86. */
  87. public function feedAction(): void {
  88. if (Minz_Request::paramBoolean('ajax')) {
  89. $this->view->_layout(null);
  90. } else {
  91. FreshRSS_View::appendScript(Minz_Url::display('/scripts/feed.js?' . @filemtime(PUBLIC_PATH . '/scripts/feed.js')));
  92. }
  93. $id = Minz_Request::paramInt('id');
  94. if ($id === 0) {
  95. Minz_Error::error(400);
  96. return;
  97. }
  98. $feedDAO = FreshRSS_Factory::createFeedDao();
  99. $feed = $feedDAO->searchById($id);
  100. if ($feed === null) {
  101. Minz_Error::error(404);
  102. return;
  103. }
  104. $this->view->feed = $feed;
  105. FreshRSS_View::prependTitle($feed->name() . ' · ' . _t('sub.title.feed_management') . ' · ');
  106. $this->_csp([
  107. 'default-src' => "'self'",
  108. 'frame-ancestors' => FreshRSS_Context::systemConf()->attributeString('csp.frame-ancestors') ?? "'none'",
  109. 'img-src' => "'self' blob:",
  110. ]);
  111. if (Minz_Request::isPost()) {
  112. $unicityCriteria = Minz_Request::paramString('unicityCriteria');
  113. if (in_array($unicityCriteria, ['id', '', null], strict: true)) {
  114. $unicityCriteria = null;
  115. }
  116. if ($unicityCriteria === null && $feed->attributeBoolean('hasBadGuids')) { // Legacy
  117. $unicityCriteria = 'link';
  118. }
  119. $feed->_attribute('hasBadGuids', null); // Remove legacy
  120. $feed->_attribute('unicityCriteria', $unicityCriteria);
  121. $feed->_attribute('unicityCriteriaForced', Minz_Request::paramBoolean('unicityCriteriaForced') ? true : null);
  122. $user = Minz_Request::paramString('http_user_feed' . $id);
  123. $pass = Minz_Request::paramString('http_pass_feed' . $id);
  124. $httpAuth = '';
  125. if ($user !== '' && $pass !== '') { //TODO: Sanitize
  126. $httpAuth = $user . ':' . $pass;
  127. }
  128. $feed->_ttl(Minz_Request::paramInt('ttl') ?: FreshRSS_Feed::TTL_DEFAULT);
  129. $feed->_mute(Minz_Request::paramBoolean('mute'));
  130. $feed->_attribute('read_upon_gone', Minz_Request::paramTernary('read_upon_gone'));
  131. $feed->_attribute('mark_updated_article_unread', Minz_Request::paramTernary('mark_updated_article_unread'));
  132. $feed->_attribute('read_upon_reception', Minz_Request::paramTernary('read_upon_reception'));
  133. $feed->_attribute('clear_cache', Minz_Request::paramTernary('clear_cache'));
  134. $keep_max_n_unread = Minz_Request::paramTernary('keep_max_n_unread') === true ? Minz_Request::paramInt('keep_max_n_unread') : null;
  135. $feed->_attribute('keep_max_n_unread', $keep_max_n_unread >= 0 ? $keep_max_n_unread : null);
  136. $read_when_same_title_in_feed = Minz_Request::paramString('read_when_same_title_in_feed');
  137. if ($read_when_same_title_in_feed === '') {
  138. $read_when_same_title_in_feed = null;
  139. } else {
  140. $read_when_same_title_in_feed = (int)$read_when_same_title_in_feed;
  141. if ($read_when_same_title_in_feed <= 0) {
  142. $read_when_same_title_in_feed = false;
  143. }
  144. }
  145. $feed->_attribute('read_when_same_title_in_feed', $read_when_same_title_in_feed);
  146. $cookie = Minz_Request::paramString('curl_params_cookie', plaintext: true);
  147. $cookie_file = Minz_Request::paramBoolean('curl_params_cookiefile');
  148. $max_redirs = Minz_Request::paramInt('curl_params_redirects');
  149. $useragent = Minz_Request::paramString('curl_params_useragent', plaintext: true);
  150. $proxy_address = Minz_Request::paramString('curl_params', plaintext: true);
  151. $proxy_type = Minz_Request::paramIntNull('proxy_type');
  152. $request_method = Minz_Request::paramString('curl_method', plaintext: true);
  153. $request_fields = Minz_Request::paramString('curl_fields', plaintext: true);
  154. $headers = Minz_Request::paramTextToArray('http_headers', plaintext: true);
  155. $opts = [];
  156. if ($proxy_type !== null) {
  157. $opts[CURLOPT_PROXYTYPE] = $proxy_type;
  158. }
  159. if ($proxy_address !== '') {
  160. $opts[CURLOPT_PROXY] = $proxy_address;
  161. }
  162. if ($cookie !== '') {
  163. $opts[CURLOPT_COOKIE] = $cookie;
  164. }
  165. if ($cookie_file) {
  166. // Pass empty cookie file name to enable the libcurl cookie engine
  167. // without reading any existing cookie data.
  168. $opts[CURLOPT_COOKIEFILE] = '';
  169. }
  170. if ($max_redirs != 0) {
  171. $opts[CURLOPT_MAXREDIRS] = $max_redirs;
  172. $opts[CURLOPT_FOLLOWLOCATION] = 1;
  173. }
  174. if ($useragent !== '') {
  175. $opts[CURLOPT_USERAGENT] = $useragent;
  176. }
  177. if ($request_method === 'POST') {
  178. $opts[CURLOPT_POST] = true;
  179. if ($request_fields !== '') {
  180. $opts[CURLOPT_POSTFIELDS] = $request_fields;
  181. if (json_decode($request_fields, true) !== null) {
  182. $opts[CURLOPT_HTTPHEADER] = ['Content-Type: application/json'];
  183. }
  184. }
  185. }
  186. $headers = array_filter($headers, fn(string $header): bool => trim($header) !== '');
  187. if (!empty($headers)) {
  188. $opts[CURLOPT_HTTPHEADER] = array_merge($headers, $opts[CURLOPT_HTTPHEADER] ?? []);
  189. $opts[CURLOPT_HTTPHEADER] = array_unique($opts[CURLOPT_HTTPHEADER]);
  190. }
  191. $feed->_attribute('curl_params', empty($opts) ? null : $opts);
  192. $feed->_attribute('content_action', Minz_Request::paramString('content_action', true) ?: 'replace');
  193. $feed->_attribute('ssl_verify', Minz_Request::paramTernary('ssl_verify'));
  194. $timeout = Minz_Request::paramInt('timeout');
  195. $feed->_attribute('timeout', $timeout > 0 ? $timeout : null);
  196. if (Minz_Request::paramBoolean('use_default_purge_options')) {
  197. $feed->_attribute('archiving', null);
  198. } else {
  199. if (Minz_Request::paramBoolean('enable_keep_max')) {
  200. $keepMax = Minz_Request::paramInt('keep_max') ?: FreshRSS_Feed::ARCHIVING_RETENTION_COUNT_LIMIT;
  201. } else {
  202. $keepMax = false;
  203. }
  204. if (Minz_Request::paramBoolean('enable_keep_period')) {
  205. $keepPeriod = FreshRSS_Feed::ARCHIVING_RETENTION_PERIOD;
  206. if (is_numeric(Minz_Request::paramString('keep_period_count')) && preg_match('/^PT?1[YMWDH]$/', Minz_Request::paramString('keep_period_unit'))) {
  207. $keepPeriod = str_replace('1', Minz_Request::paramString('keep_period_count'), Minz_Request::paramString('keep_period_unit'));
  208. }
  209. } else {
  210. $keepPeriod = false;
  211. }
  212. $feed->_attribute('archiving', [
  213. 'keep_period' => $keepPeriod,
  214. 'keep_max' => $keepMax,
  215. 'keep_min' => Minz_Request::paramInt('keep_min'),
  216. 'keep_favourites' => Minz_Request::paramBoolean('keep_favourites'),
  217. 'keep_labels' => Minz_Request::paramBoolean('keep_labels'),
  218. 'keep_unreads' => Minz_Request::paramBoolean('keep_unreads'),
  219. ]);
  220. }
  221. $feed->_filtersAction('read', Minz_Request::paramTextToArray('filteractions_read'));
  222. $feed->_kind(Minz_Request::paramInt('feed_kind') ?: FreshRSS_Feed::KIND_RSS);
  223. if ($feed->kind() === FreshRSS_Feed::KIND_HTML_XPATH || $feed->kind() === FreshRSS_Feed::KIND_XML_XPATH) {
  224. $xPathSettings = [];
  225. if (Minz_Request::paramString('xPathItem') != '')
  226. $xPathSettings['item'] = Minz_Request::paramString('xPathItem', true);
  227. if (Minz_Request::paramString('xPathItemTitle') != '')
  228. $xPathSettings['itemTitle'] = Minz_Request::paramString('xPathItemTitle', true);
  229. if (Minz_Request::paramString('xPathItemContent') != '')
  230. $xPathSettings['itemContent'] = Minz_Request::paramString('xPathItemContent', true);
  231. if (Minz_Request::paramString('xPathItemUri') != '')
  232. $xPathSettings['itemUri'] = Minz_Request::paramString('xPathItemUri', true);
  233. if (Minz_Request::paramString('xPathItemAuthor') != '')
  234. $xPathSettings['itemAuthor'] = Minz_Request::paramString('xPathItemAuthor', true);
  235. if (Minz_Request::paramString('xPathItemTimestamp') != '')
  236. $xPathSettings['itemTimestamp'] = Minz_Request::paramString('xPathItemTimestamp', true);
  237. if (Minz_Request::paramString('xPathItemTimeFormat') != '')
  238. $xPathSettings['itemTimeFormat'] = Minz_Request::paramString('xPathItemTimeFormat', true);
  239. if (Minz_Request::paramString('xPathItemThumbnail') != '')
  240. $xPathSettings['itemThumbnail'] = Minz_Request::paramString('xPathItemThumbnail', true);
  241. if (Minz_Request::paramString('xPathItemCategories') != '')
  242. $xPathSettings['itemCategories'] = Minz_Request::paramString('xPathItemCategories', true);
  243. if (Minz_Request::paramString('xPathItemUid') != '')
  244. $xPathSettings['itemUid'] = Minz_Request::paramString('xPathItemUid', true);
  245. if (!empty($xPathSettings))
  246. $feed->_attribute('xpath', $xPathSettings);
  247. } elseif ($feed->kind() === FreshRSS_Feed::KIND_JSON_DOTNOTATION || $feed->kind() === FreshRSS_Feed::KIND_HTML_XPATH_JSON_DOTNOTATION) {
  248. $jsonSettings = [];
  249. if (Minz_Request::paramString('jsonFeedTitle') !== '') {
  250. $jsonSettings['feedTitle'] = Minz_Request::paramString('jsonFeedTitle', true);
  251. }
  252. if (Minz_Request::paramString('jsonItem') !== '') {
  253. $jsonSettings['item'] = Minz_Request::paramString('jsonItem', true);
  254. }
  255. if (Minz_Request::paramString('jsonItemTitle') !== '') {
  256. $jsonSettings['itemTitle'] = Minz_Request::paramString('jsonItemTitle', true);
  257. }
  258. if (Minz_Request::paramString('jsonItemContent') !== '') {
  259. $jsonSettings['itemContent'] = Minz_Request::paramString('jsonItemContent', true);
  260. }
  261. if (Minz_Request::paramString('jsonItemUri') !== '') {
  262. $jsonSettings['itemUri'] = Minz_Request::paramString('jsonItemUri', true);
  263. }
  264. if (Minz_Request::paramString('jsonItemAuthor') !== '') {
  265. $jsonSettings['itemAuthor'] = Minz_Request::paramString('jsonItemAuthor', true);
  266. }
  267. if (Minz_Request::paramString('jsonItemTimestamp') !== '') {
  268. $jsonSettings['itemTimestamp'] = Minz_Request::paramString('jsonItemTimestamp', true);
  269. }
  270. if (Minz_Request::paramString('jsonItemTimeFormat') !== '') {
  271. $jsonSettings['itemTimeFormat'] = Minz_Request::paramString('jsonItemTimeFormat', true);
  272. }
  273. if (Minz_Request::paramString('jsonItemThumbnail') !== '') {
  274. $jsonSettings['itemThumbnail'] = Minz_Request::paramString('jsonItemThumbnail', true);
  275. }
  276. if (Minz_Request::paramString('jsonItemCategories') !== '') {
  277. $jsonSettings['itemCategories'] = Minz_Request::paramString('jsonItemCategories', true);
  278. }
  279. if (Minz_Request::paramString('jsonItemUid') !== '') {
  280. $jsonSettings['itemUid'] = Minz_Request::paramString('jsonItemUid', true);
  281. }
  282. if (!empty($jsonSettings)) {
  283. $feed->_attribute('json_dotnotation', $jsonSettings);
  284. }
  285. if (Minz_Request::paramString('xPathToJson', plaintext: true) !== '') {
  286. $feed->_attribute('xPathToJson', Minz_Request::paramString('xPathToJson', plaintext: true));
  287. }
  288. }
  289. $conditions = Minz_Request::paramTextToArray('path_entries_conditions', plaintext: true);
  290. $conditions = array_filter($conditions, fn(string $condition): bool => trim($condition) !== '');
  291. $feed->_attribute('path_entries_conditions', empty($conditions) ? null : $conditions);
  292. $feed->_attribute('path_entries_filter', Minz_Request::paramString('path_entries_filter', true));
  293. // @phpstan-ignore offsetAccess.nonOffsetAccessible
  294. $favicon_path = isset($_FILES['newFavicon']) ? $_FILES['newFavicon']['tmp_name'] : '';
  295. // @phpstan-ignore offsetAccess.nonOffsetAccessible
  296. $favicon_size = isset($_FILES['newFavicon']) ? $_FILES['newFavicon']['size'] : 0;
  297. $favicon_uploaded = $favicon_path !== '';
  298. $resetFavicon = Minz_Request::paramBoolean('resetFavicon');
  299. if ($resetFavicon) {
  300. $feed->resetCustomFavicon();
  301. }
  302. $values = [
  303. 'name' => Minz_Request::paramString('name'),
  304. 'kind' => $feed->kind(),
  305. 'description' => sanitizeHTML(Minz_Request::paramString('description', true)),
  306. 'website' => checkUrl(Minz_Request::paramString('website')) ?: '',
  307. 'url' => checkUrl(Minz_Request::paramString('url')) ?: '',
  308. 'category' => Minz_Request::paramInt('category'),
  309. 'pathEntries' => Minz_Request::paramString('path_entries'),
  310. 'priority' => Minz_Request::paramTernary('priority') === null ? FreshRSS_Feed::PRIORITY_MAIN_STREAM : Minz_Request::paramInt('priority'),
  311. 'httpAuth' => $httpAuth,
  312. 'ttl' => $feed->ttl(true),
  313. 'attributes' => $feed->attributes(),
  314. ];
  315. invalidateHttpCache();
  316. $from = Minz_Request::paramString('from');
  317. switch ($from) {
  318. case 'stats':
  319. $url_redirect = ['c' => 'stats', 'a' => 'idle', 'params' => ['id' => $id, 'from' => 'stats']];
  320. break;
  321. case 'normal':
  322. case 'reader':
  323. $get = Minz_Request::paramString('get');
  324. if ($get !== '') {
  325. $url_redirect = ['c' => 'index', 'a' => $from, 'params' => ['get' => $get]];
  326. } else {
  327. $url_redirect = ['c' => 'index', 'a' => $from];
  328. }
  329. break;
  330. default:
  331. $url_redirect = ['c' => 'subscription', 'params' => ['id' => $id]];
  332. }
  333. if ($favicon_uploaded && !$resetFavicon) {
  334. $max_size = FreshRSS_Context::systemConf()->limits['max_favicon_upload_size'];
  335. if ($favicon_size > $max_size) {
  336. Minz_Request::bad(_t('feedback.sub.feed.favicon.too_large', format_bytes($max_size)), $url_redirect);
  337. return;
  338. }
  339. try {
  340. $feed->setCustomFavicon(tmpPath: is_string($favicon_path) ? $favicon_path : '', values: $values);
  341. } catch (FreshRSS_UnsupportedImageFormat_Exception $_) {
  342. Minz_Request::bad(_t('feedback.sub.feed.favicon.unsupported_format'), $url_redirect);
  343. return;
  344. } catch (FreshRSS_Feed_Exception $_) {
  345. Minz_Request::bad(_t('feedback.sub.feed.error'), $url_redirect);
  346. return;
  347. }
  348. Minz_Request::good(
  349. _t('feedback.sub.feed.updated'),
  350. $url_redirect,
  351. showNotification: FreshRSS_Context::userConf()->good_notification_timeout > 0
  352. );
  353. } elseif ($values['url'] != '' && $feedDAO->updateFeed($id, $values) !== false) {
  354. $feed->_categoryId($values['category']);
  355. // update url and website values for faviconPrepare
  356. $feed->_url($values['url'], false);
  357. $feed->_website($values['website'], false);
  358. $feed->faviconPrepare();
  359. Minz_Request::good(
  360. _t('feedback.sub.feed.updated'),
  361. $url_redirect,
  362. showNotification: FreshRSS_Context::userConf()->good_notification_timeout > 0
  363. );
  364. } else {
  365. if ($values['url'] == '') {
  366. Minz_Log::warning('Invalid feed URL!');
  367. }
  368. Minz_Request::bad(_t('feedback.sub.feed.error'), $url_redirect);
  369. }
  370. }
  371. }
  372. /**
  373. * This action displays the bookmarklet page.
  374. */
  375. public function bookmarkletAction(): void {
  376. FreshRSS_View::prependTitle(_t('sub.title.subscription_tools') . ' . ');
  377. }
  378. /**
  379. * This action displays the page to add a new feed
  380. */
  381. public function addAction(): void {
  382. FreshRSS_View::appendScript(Minz_Url::display('/scripts/feed.js?' . @filemtime(PUBLIC_PATH . '/scripts/feed.js')));
  383. FreshRSS_View::prependTitle(_t('sub.title.add') . ' . ');
  384. }
  385. }