correct the id attribute of the profile
[statusnet:evans-mainline.git] / lib / omb.php
1 <?php
2 /*
3  * Laconica - a distributed open-source microblogging tool
4  * Copyright (C) 2008, Controlez-Vous, Inc.
5  *
6  * This program is free software: you can redistribute it and/or modify
7  * it under the terms of the GNU Affero General Public License as published by
8  * the Free Software Foundation, either version 3 of the License, or
9  * (at your option) any later version.
10  *
11  * This program is distributed in the hope that it will be useful,
12  * but WITHOUT ANY WARRANTY; without even the implied warranty of
13  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  * GNU Affero General Public License for more details.
15  *
16  * You should have received a copy of the GNU Affero General Public License
17  * along with this program.  If not, see <http://www.gnu.org/licenses/>.
18  */
19
20 if (!defined('LACONICA')) { exit(1); }
21
22 require_once('OAuth.php');
23 require_once(INSTALLDIR.'/lib/oauthstore.php');
24
25 require_once(INSTALLDIR.'/classes/Consumer.php');
26 require_once(INSTALLDIR.'/classes/Nonce.php');
27 require_once(INSTALLDIR.'/classes/Token.php');
28
29 require_once('Auth/Yadis/Yadis.php');
30
31 define('OAUTH_NAMESPACE', 'http://oauth.net/core/1.0/');
32 define('OMB_NAMESPACE', 'http://openmicroblogging.org/protocol/0.1');
33 define('OMB_VERSION_01', 'http://openmicroblogging.org/protocol/0.1');
34 define('OAUTH_DISCOVERY', 'http://oauth.net/discovery/1.0');
35
36 define('OMB_ENDPOINT_UPDATEPROFILE', OMB_NAMESPACE.'/updateProfile');
37 define('OMB_ENDPOINT_POSTNOTICE', OMB_NAMESPACE.'/postNotice');
38 define('OAUTH_ENDPOINT_REQUEST', OAUTH_NAMESPACE.'endpoint/request');
39 define('OAUTH_ENDPOINT_AUTHORIZE', OAUTH_NAMESPACE.'endpoint/authorize');
40 define('OAUTH_ENDPOINT_ACCESS', OAUTH_NAMESPACE.'endpoint/access');
41 define('OAUTH_ENDPOINT_RESOURCE', OAUTH_NAMESPACE.'endpoint/resource');
42 define('OAUTH_AUTH_HEADER', OAUTH_NAMESPACE.'parameters/auth-header');
43 define('OAUTH_POST_BODY', OAUTH_NAMESPACE.'parameters/post-body');
44 define('OAUTH_HMAC_SHA1', OAUTH_NAMESPACE.'signature/HMAC-SHA1');
45
46 function omb_oauth_consumer() {
47         static $con = NULL;
48         if (!$con) {
49                 $con = new OAuthConsumer(common_root_url(), '');
50         }
51         return $con;
52 }
53
54 function omb_oauth_server() {
55         static $server = null;
56         if (!$server) {
57                 $server = new OAuthServer(omb_oauth_datastore());
58                 $server->add_signature_method(omb_hmac_sha1());
59         }
60         return $server;
61 }
62
63 function omb_oauth_datastore() {
64         static $store = NULL;
65         if (!$store) {
66                 $store = new LaconicaOAuthDataStore();
67         }
68         return $store;
69 }
70
71 function omb_hmac_sha1() {
72         static $hmac_method = NULL;
73         if (!$hmac_method) {
74                 $hmac_method = new OAuthSignatureMethod_HMAC_SHA1();
75         }
76         return $hmac_method;
77 }
78
79 function omb_get_services($xrd, $type) {
80         return $xrd->services(array(omb_service_filter($type)));
81 }
82
83 function omb_service_filter($type) {
84         return create_function('$s',
85                                                    'return omb_match_service($s, \''.$type.'\');');
86 }
87
88 function omb_match_service($service, $type) {
89         return in_array($type, $service->getTypes());
90 }
91
92 function omb_service_uri($service) {
93         if (!$service) {
94                 return NULL;
95         }
96         $uris = $service->getURIs();
97         if (!$uris) {
98                 return NULL;
99         }
100         return $uris[0];
101 }
102
103 function omb_local_id($service) {
104         if (!$service) {
105                 return NULL;
106         }
107         $els = $service->getElements('xrd:LocalID');
108         if (!$els) {
109                 return NULL;
110         }
111         $el = $els[0];
112         return $service->parser->content($el);
113 }
114
115 function omb_broadcast_remote_subscribers($notice) {
116         # First, get remote users subscribed to this profile
117         # XXX: use a join here rather than looping through results
118         $sub = new Subscription();
119         $sub->subscribed = $notice->profile_id;
120         if ($sub->find()) {
121                 $posted = array();
122                 while ($sub->fetch()) {
123                         $rp = Remote_profile::staticGet('id', $sub->subscriber);
124                         if ($rp) {
125                                 if (!$posted[$rp->postnoticeurl]) {
126                                         if (omb_post_notice($notice, $rp, $sub)) {
127                                                 $posted[$rp->postnoticeurl] = TRUE;
128                                         }
129                                 }
130                         }
131                 }
132         }
133 }
134
135 function omb_post_notice($notice, $remote_profile, $subscription) {
136         global $config; # for license URL
137         $user = User::staticGet('id', $notice->profile_id);
138         $con = omb_oauth_consumer();
139         $token = new OAuthToken($subscription->token, $subscription->secret);
140         $url = $remote_profile->postnoticeurl;
141         $parsed = parse_url($url);
142         $params = array();
143         parse_str($parsed['query'], $params);
144         $req = OAuthRequest::from_consumer_and_token($con, $token,
145                                                                                                  "POST", $url, $params);
146         $req->set_parameter('omb_version', OMB_VERSION_01);
147         $req->set_parameter('omb_listenee', $user->uri);
148         $req->set_parameter('omb_notice', $notice->uri);
149         $req->set_parameter('omb_notice_content', $notice->content);
150         $req->set_parameter('omb_notice_url', common_local_url('shownotice',
151                                                                                                                    array('notice' =>
152                                                                                                                                  $notice->id)));
153         $req->set_parameter('omb_notice_license', $config['license']['url']);
154         
155         $req->sign_request(omb_hmac_sha1(), $con, $token);
156
157         # We re-use this tool's fetcher, since it's pretty good
158
159         $fetcher = Auth_Yadis_Yadis::getHTTPFetcher();
160
161         $result = $fetcher->post($req->get_normalized_http_url(),
162                                                          $req->to_postdata());
163
164         common_debug('Got HTTP result "'.print_r($result,TRUE).'"', __FILE__);
165         
166         if ($result->status == 403) { # not authorized, don't send again
167                 common_debug('403 result, deleting subscription', __FILE__);
168                 $subscription->delete();
169                 return false;
170         } else if ($result->status != 200) {
171                 common_debug('Error status '.$result->status, __FILE__);                
172                 return false;
173         } else { # success!
174                 parse_str($result->body, $return);
175                 if ($return['omb_version'] == OMB_VERSION_01) {
176                         return true;
177                 } else {
178                         return false;
179                 }
180         }
181 }
182
183 function omb_broadcast_profile($profile) {
184         # First, get remote users subscribed to this profile
185         # XXX: use a join here rather than looping through results
186         $sub = new Subscription();
187         $sub->subscribed = $notice->profile_id;
188         if ($sub->find()) {
189                 $updated = array();
190                 while ($sub->fetch()) {
191                         $rp = Remote_profile::staticGet('id', $sub->subscriber);
192                         if ($rp) {
193                                 if (!$updated[$rp->updateprofileurl]) {
194                                         if (omb_update_profile($profile, $rp, $sub)) {
195                                                 $updated[$rp->updateprofileurl] = TRUE;
196                                         }
197                                 }
198                         }
199                 }
200         }
201 }
202
203 function omb_update_profile($profile, $remote_profile, $subscription) {
204         global $config; # for license URL
205         $user = User::staticGet($profile->id);
206         $con = omb_oauth_consumer();
207         $token = new OAuthToken($subscription->token, $subscription->secret);
208         $url = $remote_profile->updateprofileurl;
209         $parsed = parse_url($url);
210         $params = array();
211         parse_str($parsed['query'], $params);
212         $req = OAuthRequest::from_consumer_and_token($con, $token,
213                                                                                                  "POST", $url, $params);
214         $req->set_parameter('omb_version', OMB_VERSION_01);
215         $req->set_parameter('omb_listenee', $user->uri);
216         $req->set_parameter('omb_listenee_profile', common_profile_url($profile->nickname));
217         $req->set_parameter('omb_listenee_nickname', $profile->nickname);
218         
219         # We use blanks to force emptying any existing values in these optional fields
220         
221         $req->set_parameter('omb_listenee_fullname',
222                                                 ($profile->fullname) ? $profile->fullname : '');
223         $req->set_parameter('omb_listenee_homepage', 
224                                                 ($profile->homepage) ? $profile->homepage : '');
225         $req->set_parameter('omb_listenee_bio', 
226                                                 ($profile->bio) ? $profile->bio : '');
227         $req->set_parameter('omb_listenee_location',
228                                                 ($profile->location) ? $profile->location : '');
229         
230         $avatar = $profile->getAvatar(AVATAR_PROFILE_SIZE);
231         $req->set_parameter('omb_listenee_avatar', 
232                                                 ($avatar) ? $avatar->url : '');
233         
234         $req->sign_request(omb_hmac_sha1(), $con, $token);
235
236         # We re-use this tool's fetcher, since it's pretty good
237
238         $fetcher = Auth_Yadis_Yadis::getHTTPFetcher();
239
240         common_debug('request URL = '.$req->get_normalized_http_url(), __FILE__);
241         common_debug('postdata = '.$req->to_postdata(), __FILE__);
242         $result = $fetcher->post($req->get_normalized_http_url(),
243                                                          $req->to_postdata());
244
245         common_debug('Got HTTP result "'.print_r($result,TRUE).'"', __FILE__);
246         
247         if ($result->status == 403) { # not authorized, don't send again
248                 common_debug('403 result, deleting subscription', __FILE__);
249                 $subscription->delete();
250                 return false;
251         } else if ($result->status != 200) {
252                 common_debug('Error status '.$result->status, __FILE__);                
253                 return false;
254         } else { # success!
255                 parse_str($result->body, $return);
256                 if ($return['omb_version'] == OMB_VERSION_01) {
257                         return true;
258                 } else {
259                         return false;
260                 }
261         }
262 }