summaryrefslogtreecommitdiff
path: root/api/index.php
blob: 6b00711419491cfdfd9d2b8b9fd37bf9c6dc9b0b (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
<?php
	error_reporting(E_ERROR | E_PARSE);

	require_once "../config.php";

	set_include_path(__DIR__ . PATH_SEPARATOR .
		dirname(__DIR__) . PATH_SEPARATOR .
		dirname(__DIR__) . "/include" . PATH_SEPARATOR .
  		get_include_path());

	chdir("..");

	define('TTRSS_SESSION_NAME', 'ttrss_api_sid');
	define('NO_SESSION_AUTOSTART', true);

	require_once "autoload.php";
	require_once "db-prefs.php";
	require_once "functions.php";
	require_once "sessions.php";

	ini_set('session.use_cookies', "0");
	ini_set("session.gc_maxlifetime", "86400");

	ob_start();

	$input = file_get_contents("php://input");

	if (defined('_API_DEBUG_HTTP_ENABLED') && _API_DEBUG_HTTP_ENABLED) {
		// Override $_REQUEST with JSON-encoded data if available
		// fallback on HTTP parameters
		if ($input) {
			$input = json_decode($input, true);
			if ($input) $_REQUEST = $input;
		}
	} else {
		// Accept JSON only
		$input = json_decode((string)$input, true);
		$_REQUEST = $input;
	}

	if (!empty($_REQUEST["sid"])) {
		session_id($_REQUEST["sid"]);
		@session_start();
	} else if (defined('_API_DEBUG_HTTP_ENABLED')) {
		@session_start();
	}

	startup_gettext();

	if (!init_plugins()) return;

	if (!empty($_SESSION["uid"])) {
		if (!\Sessions\validate_session()) {
			header("Content-Type: text/json");

			print json_encode(array("seq" => -1,
				"status" => 1,
				"content" => array("error" => "NOT_LOGGED_IN")));

			return;
		}

		UserHelper::load_user_plugins($_SESSION["uid"]);
	}

	$method = strtolower($_REQUEST["op"]);

	$handler = new API($_REQUEST);

	if ($handler->before($method)) {
		if ($method && method_exists($handler, $method)) {
			$handler->$method();
		} else /* if (method_exists($handler, 'index')) */ {
			$handler->index($method);
		}
		$handler->after();
	}

	header("Api-Content-Length: " . ob_get_length());

	ob_end_flush();