friendica/boot.php

642 lines
17 KiB
PHP
Raw Normal View History

2010-07-01 23:48:07 +00:00
<?php
/**
* @copyright Copyright (C) 2020, Friendica
*
* @license GNU AGPL version 3 or any later version
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, either version 3 of the
* License, or (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*
2015-12-24 00:31:17 +00:00
* Friendica is a communications platform for integrated social communications
* utilising decentralised communications and linkage to several indie social
* projects - as well as popular mainstream providers.
*
2015-12-24 00:31:17 +00:00
* Our mission is to free our friends and families from the clutches of
* data-harvesting corporations, and pave the way to a future where social
* communications are free and open and flow between alternate providers as
* easily as email does today.
*/
2010-07-01 23:48:07 +00:00
use Friendica\Core\Protocol;
2019-02-05 21:30:18 +00:00
use Friendica\Core\System;
use Friendica\Database\DBA;
use Friendica\DI;
use Friendica\Model\Contact;
2020-02-05 21:31:08 +00:00
use Friendica\Model\Notify;
2019-02-03 21:22:04 +00:00
use Friendica\Util\BasePath;
use Friendica\Util\DateTimeFormat;
define('FRIENDICA_PLATFORM', 'Friendica');
2020-03-30 12:35:49 +00:00
define('FRIENDICA_CODENAME', 'Red Hot Poker');
2020-07-12 18:50:27 +00:00
define('FRIENDICA_VERSION', '2020.09-dev');
define('DFRN_PROTOCOL_VERSION', '2.23');
2017-12-14 21:13:02 +00:00
define('NEW_UPDATE_ROUTINE_VERSION', 1170);
/**
2020-01-19 06:05:23 +00:00
* Constant with a HTML line break.
*
* Contains a HTML line break (br) element and a real carriage return with line
* feed for the source.
* This can be used in HTML and JavaScript where needed a line break.
*/
define('EOL', "<br />\r\n");
2011-08-17 03:05:02 +00:00
/**
2020-01-19 06:05:23 +00:00
* Image storage quality.
*
* Lower numbers save space at cost of image detail.
* For ease of upgrade, please do not change here. Set system.jpegquality = n in config/local.config.php,
* where n is between 1 and 100, and with very poor results below about 50
*/
define('JPEG_QUALITY', 100);
2017-05-03 02:42:29 +00:00
2012-06-07 15:42:13 +00:00
/**
* system.png_quality = n where is between 0 (uncompressed) to 9
2012-06-07 15:42:13 +00:00
*/
define('PNG_QUALITY', 8);
2012-06-07 15:42:13 +00:00
/**
* An alternate way of limiting picture upload sizes. Specify the maximum pixel
* length that pictures are allowed to be (for non-square pictures, it will apply
* to the longest side). Pictures longer than this length will be resized to be
* this length (on the longest side, the other side will be scaled appropriately).
* Modify this value using
*
* 'system' => [
* 'max_image_length' => 'n',
* ...
* ],
*
* in config/local.config.php
*
* If you don't want to set a maximum length, set to -1. The default value is
* defined by 'MAX_IMAGE_LENGTH' below.
*/
define('MAX_IMAGE_LENGTH', -1);
/**
* Not yet used
*/
define('DEFAULT_DB_ENGINE', 'InnoDB');
/** @deprecated since version 2019.03, please use \Friendica\Module\Register::CLOSED instead */
define('REGISTER_CLOSED', \Friendica\Module\Register::CLOSED);
/** @deprecated since version 2019.03, please use \Friendica\Module\Register::APPROVE instead */
define('REGISTER_APPROVE', \Friendica\Module\Register::APPROVE);
/** @deprecated since version 2019.03, please use \Friendica\Module\Register::OPEN instead */
define('REGISTER_OPEN', \Friendica\Module\Register::OPEN);
/**
* @name CP
*
* Type of the community page
* @{
*/
define('CP_NO_INTERNAL_COMMUNITY', -2);
define('CP_NO_COMMUNITY_PAGE', -1);
define('CP_USERS_ON_SERVER', 0);
define('CP_GLOBAL_COMMUNITY', 1);
define('CP_USERS_AND_GLOBAL', 2);
/**
* @}
*/
/**
2012-03-29 02:56:14 +00:00
* These numbers are used in stored permissions
* and existing allocations MUST NEVER BE CHANGED
* OR RE-ASSIGNED! You may only add to them.
*/
$netgroup_ids = [
Protocol::DFRN => (-1),
Protocol::ZOT => (-2),
Protocol::OSTATUS => (-3),
Protocol::FEED => (-4),
Protocol::DIASPORA => (-5),
Protocol::MAIL => (-6),
Protocol::FACEBOOK => (-8),
Protocol::LINKEDIN => (-9),
Protocol::XMPP => (-10),
Protocol::MYSPACE => (-11),
Protocol::GPLUS => (-12),
Protocol::PUMPIO => (-13),
Protocol::TWITTER => (-14),
Protocol::DIASPORA2 => (-15),
Protocol::STATUSNET => (-16),
Protocol::NEWS => (-18),
Protocol::ICALENDAR => (-19),
Protocol::PNUT => (-20),
Protocol::PHANTOM => (-127),
];
2012-03-29 02:56:14 +00:00
2010-12-10 12:04:35 +00:00
/**
* Maximum number of "people who like (or don't like) this" that we will list by name
*/
define('MAX_LIKERS', 75);
2010-10-13 00:11:06 +00:00
2020-02-05 21:27:04 +00:00
/**
* @name Notify
*
* Email notification options
* @{
*/
2020-02-05 21:27:47 +00:00
/** @deprecated since 2020.03, use Notify\Type::INTRO instead */
2020-02-05 21:31:08 +00:00
define('NOTIFY_INTRO', Notify\Type::INTRO);
2020-02-05 21:27:47 +00:00
/** @deprecated since 2020.03, use Notify\Type::CONFIRM instead */
2020-02-05 21:31:08 +00:00
define('NOTIFY_CONFIRM', Notify\Type::CONFIRM);
2020-02-05 21:27:47 +00:00
/** @deprecated since 2020.03, use Notify\Type::WALL instead */
2020-02-05 21:31:08 +00:00
define('NOTIFY_WALL', Notify\Type::WALL);
2020-02-05 21:27:47 +00:00
/** @deprecated since 2020.03, use Notify\Type::COMMENT instead */
2020-02-05 21:31:08 +00:00
define('NOTIFY_COMMENT', Notify\Type::COMMENT);
2020-02-05 21:27:47 +00:00
/** @deprecated since 2020.03, use Notify\Type::MAIL instead */
2020-02-05 21:31:08 +00:00
define('NOTIFY_MAIL', Notify\Type::MAIL);
2020-02-05 21:27:47 +00:00
/** @deprecated since 2020.03, use Notify\Type::SUGGEST instead */
2020-02-05 21:31:08 +00:00
define('NOTIFY_SUGGEST', Notify\Type::SUGGEST);
2020-02-05 21:27:47 +00:00
/** @deprecated since 2020.03, use Notify\Type::PROFILE instead */
2020-02-05 21:31:08 +00:00
define('NOTIFY_PROFILE', Notify\Type::PROFILE);
2020-02-05 21:27:47 +00:00
/** @deprecated since 2020.03, use Notify\Type::TAG_SELF instead */
2020-02-05 21:31:08 +00:00
define('NOTIFY_TAGSELF', Notify\Type::TAG_SELF);
2020-02-05 21:27:47 +00:00
/** @deprecated since 2020.03, use Notify\Type::TAG_SHARE instead */
2020-02-05 21:31:08 +00:00
define('NOTIFY_TAGSHARE', Notify\Type::TAG_SHARE);
2020-02-05 21:27:47 +00:00
/** @deprecated since 2020.03, use Notify\Type::POKE instead */
2020-02-05 21:31:08 +00:00
define('NOTIFY_POKE', Notify\Type::POKE);
2020-02-05 21:27:47 +00:00
/** @deprecated since 2020.03, use Notify\Type::SHARE instead */
2020-02-05 21:31:08 +00:00
define('NOTIFY_SHARE', Notify\Type::SHARE);
2020-02-05 21:27:04 +00:00
/** @deprecated since 2020.12, use Notify\Type::SYSTEM instead */
2020-02-05 21:31:08 +00:00
define('NOTIFY_SYSTEM', Notify\Type::SYSTEM);
2020-02-05 21:27:04 +00:00
/* @}*/
2010-12-10 12:04:35 +00:00
/**
* @name Gravity
*
* Item weight for query ordering
* @{
2010-12-10 12:04:35 +00:00
*/
define('GRAVITY_PARENT', 0);
2018-06-27 18:09:33 +00:00
define('GRAVITY_ACTIVITY', 3);
define('GRAVITY_COMMENT', 6);
2018-06-27 18:09:33 +00:00
define('GRAVITY_UNKNOWN', 9);
/* @}*/
/**
* @name Priority
*
* Process priority for the worker
* @{
*/
define('PRIORITY_UNDEFINED', 0);
define('PRIORITY_CRITICAL', 10);
define('PRIORITY_HIGH', 20);
define('PRIORITY_MEDIUM', 30);
define('PRIORITY_LOW', 40);
define('PRIORITY_NEGLIGIBLE', 50);
/* @}*/
/**
* @name Social Relay settings
*
* See here: https://github.com/jaywink/social-relay
* and here: https://wiki.diasporafoundation.org/Relay_servers_for_public_posts
* @{
*/
define('SR_SCOPE_NONE', '');
define('SR_SCOPE_ALL', 'all');
define('SR_SCOPE_TAGS', 'tags');
/* @}*/
2010-09-09 03:14:17 +00:00
// Normally this constant is defined - but not if "pcntl" isn't installed
2017-03-19 08:04:04 +00:00
if (!defined("SIGTERM")) {
define("SIGTERM", 15);
2017-03-19 08:04:04 +00:00
}
2017-05-03 02:42:29 +00:00
/**
* Depending on the PHP version this constant does exist - or not.
* See here: http://php.net/manual/en/curl.constants.php#117928
*/
if (!defined('CURLE_OPERATION_TIMEDOUT')) {
define('CURLE_OPERATION_TIMEDOUT', CURLE_OPERATION_TIMEOUTED);
}
2010-11-24 07:42:45 +00:00
2015-12-24 00:31:17 +00:00
/**
2020-01-19 06:05:23 +00:00
* Returns the user id of locally logged in user or false.
*
2015-12-24 00:31:17 +00:00
* @return int|bool user id or false
*/
function local_user()
{
if (!empty($_SESSION['authenticated']) && !empty($_SESSION['uid'])) {
2015-12-24 00:31:17 +00:00
return intval($_SESSION['uid']);
}
2015-12-24 00:31:17 +00:00
return false;
}
2010-07-01 23:48:07 +00:00
/**
2020-01-19 06:05:23 +00:00
* Returns the public contact id of logged in user or false.
*
* @return int|bool public contact id or false
*/
function public_contact()
{
static $public_contact_id = false;
if (!$public_contact_id && !empty($_SESSION['authenticated'])) {
if (!empty($_SESSION['my_address'])) {
// Local user
$public_contact_id = intval(Contact::getIdForURL($_SESSION['my_address'], 0, false));
} elseif (!empty($_SESSION['visitor_home'])) {
// Remote user
$public_contact_id = intval(Contact::getIdForURL($_SESSION['visitor_home'], 0, false));
}
} elseif (empty($_SESSION['authenticated'])) {
$public_contact_id = false;
}
return $public_contact_id;
}
2015-12-24 00:31:17 +00:00
/**
2020-01-19 06:05:23 +00:00
* Returns contact id of authenticated site visitor or false
*
2015-12-24 00:31:17 +00:00
* @return int|bool visitor_id or false
*/
2019-09-28 09:59:08 +00:00
function remote_user()
{
2019-09-23 22:13:20 +00:00
if (empty($_SESSION['authenticated'])) {
return false;
}
2019-09-28 09:59:08 +00:00
if (!empty($_SESSION['visitor_id'])) {
2015-12-24 00:31:17 +00:00
return intval($_SESSION['visitor_id']);
}
2019-09-23 22:13:20 +00:00
2015-12-24 00:31:17 +00:00
return false;
}
2010-07-01 23:48:07 +00:00
2015-12-24 00:31:17 +00:00
/**
2020-01-19 06:05:23 +00:00
* Show an error message to user.
2015-12-24 00:31:17 +00:00
*
* This function save text in session, to be shown to the user at next page load
*
* @param string $s - Text of notice
*/
function notice($s)
{
if (empty($_SESSION)) {
return;
}
2020-01-04 22:42:01 +00:00
$a = DI::app();
if (empty($_SESSION['sysmsg'])) {
$_SESSION['sysmsg'] = [];
}
if ($a->interactive) {
2015-12-24 00:31:17 +00:00
$_SESSION['sysmsg'][] = $s;
}
}
2015-12-24 00:31:17 +00:00
/**
2020-01-19 06:05:23 +00:00
* Show an info message to user.
2015-12-24 00:31:17 +00:00
*
* This function save text in session, to be shown to the user at next page load
*
* @param string $s - Text of notice
*/
function info($s)
{
2020-01-04 22:42:01 +00:00
$a = DI::app();
if (empty($_SESSION['sysmsg_info'])) {
$_SESSION['sysmsg_info'] = [];
}
if ($a->interactive) {
2015-12-24 00:31:17 +00:00
$_SESSION['sysmsg_info'][] = $s;
}
2015-12-24 00:31:17 +00:00
}
function feed_birthday($uid, $tz)
{
2015-12-24 00:31:17 +00:00
/**
* Determine the next birthday, but only if the birthday is published
* in the default profile. We _could_ also look for a private profile that the
* recipient can see, but somebody could get mad at us if they start getting
* public birthday greetings when they haven't made this info public.
*
* Assuming we are able to publish this info, we are then going to convert
* the start time from the owner's timezone to UTC.
*
* This will potentially solve the problem found with some social networks
* where birthdays are converted to the viewer's timezone and salutations from
* elsewhere in the world show up on the wrong day. We will convert it to the
* viewer's timezone also, but first we are going to convert it from the birthday
* person's timezone to GMT - so the viewer may find the birthday starting at
* 6:00PM the day before, but that will correspond to midnight to the birthday person.
*/
$birthday = '';
2017-05-03 02:42:29 +00:00
if (!strlen($tz)) {
2015-12-24 00:31:17 +00:00
$tz = 'UTC';
}
$profile = DBA::selectFirst('profile', ['dob'], ['uid' => $uid]);
if (DBA::isResult($profile)) {
$tmp_dob = substr($profile['dob'], 5);
if (intval($tmp_dob)) {
$y = DateTimeFormat::timezoneNow($tz, 'Y');
2015-12-24 00:31:17 +00:00
$bd = $y . '-' . $tmp_dob . ' 00:00';
$t_dob = strtotime($bd);
$now = strtotime(DateTimeFormat::timezoneNow($tz));
if ($t_dob < $now) {
2015-12-24 00:31:17 +00:00
$bd = $y + 1 . '-' . $tmp_dob . ' 00:00';
}
$birthday = DateTimeFormat::convert($bd, 'UTC', $tz, DateTimeFormat::ATOM);
2011-02-07 06:41:07 +00:00
}
}
2015-12-24 00:31:17 +00:00
return $birthday;
}
2011-02-08 01:06:04 +00:00
2015-12-24 00:31:17 +00:00
/**
2020-01-19 06:05:23 +00:00
* Check if current user has admin role.
2015-12-24 00:31:17 +00:00
*
* @return bool true if user is an admin
*/
function is_site_admin()
{
2020-01-04 22:42:01 +00:00
$a = DI::app();
$admin_email = DI::config()->get('config', 'admin_email');
$adminlist = explode(',', str_replace(' ', '', $admin_email));
return local_user() && $admin_email && in_array($a->user['email'] ?? '', $adminlist);
}
function explode_querystring($query)
{
$arg_st = strpos($query, '?');
if ($arg_st !== false) {
$base = substr($query, 0, $arg_st);
$arg_st += 1;
} else {
$base = '';
$arg_st = 0;
}
$args = explode('&', substr($query, $arg_st));
foreach ($args as $k => $arg) {
/// @TODO really compare type-safe here?
if ($arg === '') {
unset($args[$k]);
}
}
$args = array_values($args);
if (!$base) {
$base = $args[0];
unset($args[0]);
$args = array_values($args);
}
return [
'base' => $base,
'args' => $args,
];
}
2012-09-13 03:35:51 +00:00
/**
2017-05-03 02:42:29 +00:00
* Returns the complete URL of the current page, e.g.: http(s)://something.com/network
*
* Taken from http://webcheatsheet.com/php/get_current_page_url.php
*/
function curPageURL()
{
2012-09-13 03:35:51 +00:00
$pageURL = 'http';
if (!empty($_SERVER["HTTPS"]) && ($_SERVER["HTTPS"] == "on")) {
$pageURL .= "s";
}
2012-09-13 03:35:51 +00:00
$pageURL .= "://";
2012-09-13 03:35:51 +00:00
if ($_SERVER["SERVER_PORT"] != "80" && $_SERVER["SERVER_PORT"] != "443") {
2017-05-03 02:42:29 +00:00
$pageURL .= $_SERVER["SERVER_NAME"] . ":" . $_SERVER["SERVER_PORT"] . $_SERVER["REQUEST_URI"];
2012-09-13 03:35:51 +00:00
} else {
2017-05-03 02:42:29 +00:00
$pageURL .= $_SERVER["SERVER_NAME"] . $_SERVER["REQUEST_URI"];
2012-09-13 03:35:51 +00:00
}
return $pageURL;
}
function get_temppath()
{
$temppath = DI::config()->get("system", "temppath");
2017-07-08 15:25:13 +00:00
2019-02-05 21:30:18 +00:00
if (($temppath != "") && System::isDirectoryUsable($temppath)) {
2017-07-08 15:25:13 +00:00
// We have a temp path and it is usable
2019-02-03 21:22:04 +00:00
return BasePath::getRealPath($temppath);
2017-07-08 15:25:13 +00:00
}
// We don't have a working preconfigured temp path, so we take the system path.
$temppath = sys_get_temp_dir();
// Check if it is usable
2019-02-05 21:30:18 +00:00
if (($temppath != "") && System::isDirectoryUsable($temppath)) {
// Always store the real path, not the path through symlinks
2019-02-03 21:22:04 +00:00
$temppath = BasePath::getRealPath($temppath);
2017-07-08 15:25:13 +00:00
// To avoid any interferences with other systems we create our own directory
$new_temppath = $temppath . "/" . DI::baseUrl()->getHostname();
2017-07-08 15:25:13 +00:00
if (!is_dir($new_temppath)) {
/// @TODO There is a mkdir()+chmod() upwards, maybe generalize this (+ configurable) into a function/method?
mkdir($new_temppath);
}
2019-02-05 21:30:18 +00:00
if (System::isDirectoryUsable($new_temppath)) {
2017-07-08 15:25:13 +00:00
// The new path is usable, we are happy
DI::config()->set("system", "temppath", $new_temppath);
2017-07-08 15:25:13 +00:00
return $new_temppath;
} else {
// We can't create a subdirectory, strange.
// But the directory seems to work, so we use it but don't store it.
return $temppath;
}
}
// Reaching this point means that the operating system is configured badly.
return '';
}
function get_cachefile($file, $writemode = true)
{
$cache = get_itemcachepath();
2012-11-16 23:50:39 +00:00
2017-05-03 02:42:29 +00:00
if ((!$cache) || (!is_dir($cache))) {
return "";
}
2012-11-16 23:50:39 +00:00
$subfolder = $cache . "/" . substr($file, 0, 2);
2012-11-16 23:50:39 +00:00
$cachepath = $subfolder . "/" . $file;
2012-11-16 23:50:39 +00:00
if ($writemode) {
if (!is_dir($subfolder)) {
mkdir($subfolder);
chmod($subfolder, 0777);
}
}
return $cachepath;
2012-11-16 23:50:39 +00:00
}
function clear_cache($basepath = "", $path = "")
{
2012-11-16 23:50:39 +00:00
if ($path == "") {
$basepath = get_itemcachepath();
2012-11-16 23:50:39 +00:00
$path = $basepath;
}
if (($path == "") || (!is_dir($path))) {
2012-11-16 23:50:39 +00:00
return;
}
2012-11-16 23:50:39 +00:00
if (substr(realpath($path), 0, strlen($basepath)) != $basepath) {
2012-11-16 23:50:39 +00:00
return;
}
2012-11-16 23:50:39 +00:00
$cachetime = (int) DI::config()->get('system', 'itemcache_duration');
if ($cachetime == 0) {
2012-11-16 23:50:39 +00:00
$cachetime = 86400;
}
2012-11-16 23:50:39 +00:00
2017-05-03 02:42:29 +00:00
if (is_writable($path)) {
if ($dh = opendir($path)) {
while (($file = readdir($dh)) !== false) {
2017-05-03 02:42:29 +00:00
$fullpath = $path . "/" . $file;
2017-06-09 01:03:44 +00:00
if ((filetype($fullpath) == "dir") && ($file != ".") && ($file != "..")) {
clear_cache($basepath, $fullpath);
}
2017-06-09 01:03:44 +00:00
if ((filetype($fullpath) == "file") && (filectime($fullpath) < (time() - $cachetime))) {
unlink($fullpath);
}
}
closedir($dh);
2012-11-16 23:50:39 +00:00
}
}
2012-11-16 23:50:39 +00:00
}
function get_itemcachepath()
{
// Checking, if the cache is deactivated
$cachetime = (int) DI::config()->get('system', 'itemcache_duration');
if ($cachetime < 0) {
return "";
}
$itemcache = DI::config()->get('system', 'itemcache');
2019-02-05 21:30:18 +00:00
if (($itemcache != "") && System::isDirectoryUsable($itemcache)) {
2019-02-03 21:22:04 +00:00
return BasePath::getRealPath($itemcache);
}
$temppath = get_temppath();
if ($temppath != "") {
2017-05-03 02:42:29 +00:00
$itemcache = $temppath . "/itemcache";
if (!file_exists($itemcache) && !is_dir($itemcache)) {
mkdir($itemcache);
}
2019-02-05 21:30:18 +00:00
if (System::isDirectoryUsable($itemcache)) {
DI::config()->set("system", "itemcache", $itemcache);
2017-02-19 08:23:21 +00:00
return $itemcache;
}
}
return "";
}
2016-12-01 22:50:07 +00:00
/**
2020-01-19 06:05:23 +00:00
* Returns the path where spool files are stored
2016-12-01 22:50:07 +00:00
*
* @return string Spool path
*/
function get_spoolpath()
{
$spoolpath = DI::config()->get('system', 'spoolpath');
2019-02-05 21:30:18 +00:00
if (($spoolpath != "") && System::isDirectoryUsable($spoolpath)) {
2017-02-19 08:23:21 +00:00
// We have a spool path and it is usable
return $spoolpath;
2016-12-01 22:50:07 +00:00
}
2016-12-01 13:50:26 +00:00
2017-02-19 08:23:21 +00:00
// We don't have a working preconfigured spool path, so we take the temp path.
2016-12-01 13:50:26 +00:00
$temppath = get_temppath();
if ($temppath != "") {
2017-02-19 08:23:21 +00:00
// To avoid any interferences with other systems we create our own directory
2017-05-03 02:42:29 +00:00
$spoolpath = $temppath . "/spool";
2016-12-01 22:50:07 +00:00
if (!is_dir($spoolpath)) {
2016-12-01 13:50:26 +00:00
mkdir($spoolpath);
2016-12-01 22:50:07 +00:00
}
2016-12-01 13:50:26 +00:00
2019-02-05 21:30:18 +00:00
if (System::isDirectoryUsable($spoolpath)) {
2017-02-19 08:23:21 +00:00
// The new path is usable, we are happy
DI::config()->set("system", "spoolpath", $spoolpath);
2017-02-19 08:23:21 +00:00
return $spoolpath;
} else {
// We can't create a subdirectory, strange.
// But the directory seems to work, so we use it but don't store it.
return $temppath;
2016-12-01 13:50:26 +00:00
}
}
2017-02-19 08:23:21 +00:00
// Reaching this point means that the operating system is configured badly.
2016-12-01 13:50:26 +00:00
return "";
}
if (!function_exists('exif_imagetype')) {
function exif_imagetype($file)
{
$size = getimagesize($file);
return $size[2];
}
}
2015-09-13 16:47:10 +00:00
function validate_include(&$file)
{
2015-09-13 16:47:10 +00:00
$orig_file = $file;
$file = realpath($file);
if (strpos($file, getcwd()) !== 0) {
2015-09-13 16:47:10 +00:00
return false;
}
2015-09-13 16:47:10 +00:00
2017-05-03 02:42:29 +00:00
$file = str_replace(getcwd() . "/", "", $file, $count);
if ($count != 1) {
2015-09-13 16:47:10 +00:00
return false;
}
2015-09-13 16:47:10 +00:00
if ($orig_file !== $file) {
2015-09-13 16:47:10 +00:00
return false;
}
2015-09-13 16:47:10 +00:00
$valid = false;
if (strpos($file, "include/") === 0) {
2015-09-13 16:47:10 +00:00
$valid = true;
}
2015-09-13 16:47:10 +00:00
if (strpos($file, "addon/") === 0) {
2015-09-13 16:47:10 +00:00
$valid = true;
}
2015-09-13 16:47:10 +00:00
// Simply return flag
return $valid;
2015-09-13 16:47:10 +00:00
}