Friendica Communications Platform (please note that this is a clone of the repository at github, issues are handled there) https://friendi.ca
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

424 lines
13 KiB

7 years ago
  1. <?php
  2. require_once('include/config.php');
  3. require_once('include/network.php');
  4. require_once('include/plugin.php');
  5. require_once('include/text.php');
  6. require_once('include/pgettext.php');
  7. require_once('include/datetime.php');
  8. require_once('include/enotify.php');
  9. function create_user($arr) {
  10. // Required: { username, nickname, email } or { openid_url }
  11. $a = get_app();
  12. $result = array('success' => false, 'user' => null, 'password' => '', 'message' => '');
  13. $using_invites = get_config('system','invitation_only');
  14. $num_invites = get_config('system','number_invites');
  15. $invite_id = ((x($arr,'invite_id')) ? notags(trim($arr['invite_id'])) : '');
  16. $username = ((x($arr,'username')) ? notags(trim($arr['username'])) : '');
  17. $nickname = ((x($arr,'nickname')) ? notags(trim($arr['nickname'])) : '');
  18. $email = ((x($arr,'email')) ? notags(trim($arr['email'])) : '');
  19. $openid_url = ((x($arr,'openid_url')) ? notags(trim($arr['openid_url'])) : '');
  20. $photo = ((x($arr,'photo')) ? notags(trim($arr['photo'])) : '');
  21. $password = ((x($arr,'password')) ? trim($arr['password']) : '');
  22. $password1 = ((x($arr,'password1')) ? trim($arr['password1']) : '');
  23. $confirm = ((x($arr,'confirm')) ? trim($arr['confirm']) : '');
  24. $blocked = ((x($arr,'blocked')) ? intval($arr['blocked']) : 0);
  25. $verified = ((x($arr,'verified')) ? intval($arr['verified']) : 0);
  26. $publish = ((x($arr,'profile_publish_reg') && intval($arr['profile_publish_reg'])) ? 1 : 0);
  27. $netpublish = ((strlen(get_config('system','directory'))) ? $publish : 0);
  28. if ($password1 != $confirm) {
  29. $result['message'] .= t('Passwords do not match. Password unchanged.') . EOL;
  30. return $result;
  31. } elseif ($password1 != "")
  32. $password = $password1;
  33. $tmp_str = $openid_url;
  34. if($using_invites) {
  35. if(! $invite_id) {
  36. $result['message'] .= t('An invitation is required.') . EOL;
  37. return $result;
  38. }
  39. $r = q("select * from register where `hash` = '%s' limit 1", dbesc($invite_id));
  40. if(! results($r)) {
  41. $result['message'] .= t('Invitation could not be verified.') . EOL;
  42. return $result;
  43. }
  44. }
  45. if((! x($username)) || (! x($email)) || (! x($nickname))) {
  46. if($openid_url) {
  47. if(! validate_url($tmp_str)) {
  48. $result['message'] .= t('Invalid OpenID url') . EOL;
  49. return $result;
  50. }
  51. $_SESSION['register'] = 1;
  52. $_SESSION['openid'] = $openid_url;
  53. require_once('library/openid.php');
  54. $openid = new LightOpenID;
  55. $openid->identity = $openid_url;
  56. $openid->returnUrl = $a->get_baseurl() . '/openid';
  57. $openid->required = array('namePerson/friendly', 'contact/email', 'namePerson');
  58. $openid->optional = array('namePerson/first','media/image/aspect11','media/image/default');
  59. try {
  60. $authurl = $openid->authUrl();
  61. } catch (Exception $e){
  62. $result['message'] .= t("We encountered a problem while logging in with the OpenID you provided. Please check the correct spelling of the ID."). EOL . EOL . t("The error message was:") . $e->getMessage() . EOL;
  63. return $result;
  64. }
  65. goaway($authurl);
  66. // NOTREACHED
  67. }
  68. notice( t('Please enter the required information.') . EOL );
  69. return;
  70. }
  71. if(! validate_url($tmp_str))
  72. $openid_url = '';
  73. $err = '';
  74. // collapse multiple spaces in name
  75. $username = preg_replace('/ +/',' ',$username);
  76. if(mb_strlen($username) > 48)
  77. $result['message'] .= t('Please use a shorter name.') . EOL;
  78. if(mb_strlen($username) < 3)
  79. $result['message'] .= t('Name too short.') . EOL;
  80. // I don't really like having this rule, but it cuts down
  81. // on the number of auto-registrations by Russian spammers
  82. // Using preg_match was completely unreliable, due to mixed UTF-8 regex support
  83. // $no_utf = get_config('system','no_utf');
  84. // $pat = (($no_utf) ? '/^[a-zA-Z]* [a-zA-Z]*$/' : '/^\p{L}* \p{L}*$/u' );
  85. // So now we are just looking for a space in the full name.
  86. $loose_reg = get_config('system','no_regfullname');
  87. if(! $loose_reg) {
  88. $username = mb_convert_case($username,MB_CASE_TITLE,'UTF-8');
  89. if(! strpos($username,' '))
  90. $result['message'] .= t("That doesn't appear to be your full \x28First Last\x29 name.") . EOL;
  91. }
  92. if(! allowed_email($email))
  93. $result['message'] .= t('Your email domain is not among those allowed on this site.') . EOL;
  94. if((! valid_email($email)) || (! validate_email($email)))
  95. $result['message'] .= t('Not a valid email address.') . EOL;
  96. // Disallow somebody creating an account using openid that uses the admin email address,
  97. // since openid bypasses email verification. We'll allow it if there is not yet an admin account.
  98. $adminlist = explode(",", str_replace(" ", "", strtolower($a->config['admin_email'])));
  99. //if((x($a->config,'admin_email')) && (strcasecmp($email,$a->config['admin_email']) == 0) && strlen($openid_url)) {
  100. if((x($a->config,'admin_email')) && in_array(strtolower($email), $adminlist) && strlen($openid_url)) {
  101. $r = q("SELECT * FROM `user` WHERE `email` = '%s' LIMIT 1",
  102. dbesc($email)
  103. );
  104. if(count($r))
  105. $result['message'] .= t('Cannot use that email.') . EOL;
  106. }
  107. $nickname = $arr['nickname'] = strtolower($nickname);
  108. if(! preg_match("/^[a-z0-9][a-z0-9\_]*$/",$nickname))
  109. $result['message'] .= t('Your "nickname" can only contain "a-z", "0-9" and "_".') . EOL;
  110. $r = q("SELECT `uid` FROM `user`
  111. WHERE `nickname` = '%s' LIMIT 1",
  112. dbesc($nickname)
  113. );
  114. if(count($r))
  115. $result['message'] .= t('Nickname is already registered. Please choose another.') . EOL;
  116. // Check deleted accounts that had this nickname. Doesn't matter to us,
  117. // but could be a security issue for federated platforms.
  118. $r = q("SELECT * FROM `userd`
  119. WHERE `username` = '%s' LIMIT 1",
  120. dbesc($nickname)
  121. );
  122. if(count($r))
  123. $result['message'] .= t('Nickname was once registered here and may not be re-used. Please choose another.') . EOL;
  124. if(strlen($result['message'])) {
  125. return $result;
  126. }
  127. $new_password = ((strlen($password)) ? $password : autoname(6) . mt_rand(100,9999));
  128. $new_password_encoded = hash('whirlpool',$new_password);
  129. $result['password'] = $new_password;
  130. require_once('include/crypto.php');
  131. $keys = new_keypair(4096);
  132. if($keys === false) {
  133. $result['message'] .= t('SERIOUS ERROR: Generation of security keys failed.') . EOL;
  134. return $result;
  135. }
  136. $default_service_class = get_config('system','default_service_class');
  137. if(! $default_service_class)
  138. $default_service_class = '';
  139. $prvkey = $keys['prvkey'];
  140. $pubkey = $keys['pubkey'];
  141. /**
  142. *
  143. * Create another keypair for signing/verifying
  144. * salmon protocol messages. We have to use a slightly
  145. * less robust key because this won't be using openssl
  146. * but the phpseclib. Since it is PHP interpreted code
  147. * it is not nearly as efficient, and the larger keys
  148. * will take several minutes each to process.
  149. *
  150. */
  151. $sres = new_keypair(512);
  152. $sprvkey = $sres['prvkey'];
  153. $spubkey = $sres['pubkey'];
  154. $r = q("INSERT INTO `user` ( `guid`, `username`, `password`, `email`, `openid`, `nickname`,
  155. `pubkey`, `prvkey`, `spubkey`, `sprvkey`, `register_date`, `verified`, `blocked`, `timezone`, `service_class`, `default-location` )
  156. VALUES ( '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', %d, %d, 'UTC', '%s', '' )",
  157. dbesc(generate_user_guid()),
  158. dbesc($username),
  159. dbesc($new_password_encoded),
  160. dbesc($email),
  161. dbesc($openid_url),
  162. dbesc($nickname),
  163. dbesc($pubkey),
  164. dbesc($prvkey),
  165. dbesc($spubkey),
  166. dbesc($sprvkey),
  167. dbesc(datetime_convert()),
  168. intval($verified),
  169. intval($blocked),
  170. dbesc($default_service_class)
  171. );
  172. if($r) {
  173. $r = q("SELECT * FROM `user`
  174. WHERE `username` = '%s' AND `password` = '%s' LIMIT 1",
  175. dbesc($username),
  176. dbesc($new_password_encoded)
  177. );
  178. if($r !== false && count($r)) {
  179. $u = $r[0];
  180. $newuid = intval($r[0]['uid']);
  181. }
  182. }
  183. else {
  184. $result['message'] .= t('An error occurred during registration. Please try again.') . EOL ;
  185. return $result;
  186. }
  187. /**
  188. * if somebody clicked submit twice very quickly, they could end up with two accounts
  189. * due to race condition. Remove this one.
  190. */
  191. $r = q("SELECT `uid` FROM `user`
  192. WHERE `nickname` = '%s' ",
  193. dbesc($nickname)
  194. );
  195. if((count($r) > 1) && $newuid) {
  196. $result['message'] .= t('Nickname is already registered. Please choose another.') . EOL;
  197. q("DELETE FROM `user` WHERE `uid` = %d",
  198. intval($newuid)
  199. );
  200. return $result;
  201. }
  202. if(x($newuid) !== false) {
  203. $r = q("INSERT INTO `profile` ( `uid`, `profile-name`, `is-default`, `name`, `photo`, `thumb`, `publish`, `net-publish` )
  204. VALUES ( %d, '%s', %d, '%s', '%s', '%s', %d, %d ) ",
  205. intval($newuid),
  206. t('default'),
  207. 1,
  208. dbesc($username),
  209. dbesc($a->get_baseurl() . "/photo/profile/{$newuid}.jpg"),
  210. dbesc($a->get_baseurl() . "/photo/avatar/{$newuid}.jpg"),
  211. intval($publish),
  212. intval($netpublish)
  213. );
  214. if($r === false) {
  215. $result['message'] .= t('An error occurred creating your default profile. Please try again.') . EOL;
  216. // Start fresh next time.
  217. $r = q("DELETE FROM `user` WHERE `uid` = %d",
  218. intval($newuid));
  219. return $result;
  220. }
  221. $r = q("INSERT INTO `contact` ( `uid`, `created`, `self`, `name`, `nick`, `photo`, `thumb`, `micro`, `blocked`, `pending`, `url`, `nurl`,
  222. `request`, `notify`, `poll`, `confirm`, `poco`, `name-date`, `uri-date`, `avatar-date`, `closeness` )
  223. VALUES ( %d, '%s', 1, '%s', '%s', '%s', '%s', '%s', 0, 0, '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', 0 ) ",
  224. intval($newuid),
  225. datetime_convert(),
  226. dbesc($username),
  227. dbesc($nickname),
  228. dbesc($a->get_baseurl() . "/photo/profile/{$newuid}.jpg"),
  229. dbesc($a->get_baseurl() . "/photo/avatar/{$newuid}.jpg"),
  230. dbesc($a->get_baseurl() . "/photo/micro/{$newuid}.jpg"),
  231. dbesc($a->get_baseurl() . "/profile/$nickname"),
  232. dbesc(normalise_link($a->get_baseurl() . "/profile/$nickname")),
  233. dbesc($a->get_baseurl() . "/dfrn_request/$nickname"),
  234. dbesc($a->get_baseurl() . "/dfrn_notify/$nickname"),
  235. dbesc($a->get_baseurl() . "/dfrn_poll/$nickname"),
  236. dbesc($a->get_baseurl() . "/dfrn_confirm/$nickname"),
  237. dbesc($a->get_baseurl() . "/poco/$nickname"),
  238. dbesc(datetime_convert()),
  239. dbesc(datetime_convert()),
  240. dbesc(datetime_convert())
  241. );
  242. // Create a group with no members. This allows somebody to use it
  243. // right away as a default group for new contacts.
  244. require_once('include/group.php');
  245. group_add($newuid, t('Friends'));
  246. $r = q("SELECT id FROM `group` WHERE uid = %d AND name = '%s'",
  247. intval($newuid),
  248. dbesc(t('Friends'))
  249. );
  250. if($r && count($r)) {
  251. $def_gid = $r[0]['id'];
  252. q("UPDATE user SET def_gid = %d WHERE uid = %d",
  253. intval($r[0]['id']),
  254. intval($newuid)
  255. );
  256. }
  257. if(get_config('system', 'newuser_private') && $def_gid) {
  258. q("UPDATE user SET allow_gid = '%s' WHERE uid = %d",
  259. dbesc("<" . $def_gid . ">"),
  260. intval($newuid)
  261. );
  262. }
  263. }
  264. // if we have no OpenID photo try to look up an avatar
  265. if(! strlen($photo))
  266. $photo = avatar_img($email);
  267. // unless there is no avatar-plugin loaded
  268. if(strlen($photo)) {
  269. require_once('include/Photo.php');
  270. $photo_failure = false;
  271. $filename = basename($photo);
  272. $img_str = fetch_url($photo,true);
  273. // guess mimetype from headers or filename
  274. $type = guess_image_type($photo,true);
  275. $img = new Photo($img_str, $type);
  276. if($img->is_valid()) {
  277. $img->scaleImageSquare(175);
  278. $hash = photo_new_resource();
  279. $r = $img->store($newuid, 0, $hash, $filename, t('Profile Photos'), 4 );
  280. if($r === false)
  281. $photo_failure = true;
  282. $img->scaleImage(80);
  283. $r = $img->store($newuid, 0, $hash, $filename, t('Profile Photos'), 5 );
  284. if($r === false)
  285. $photo_failure = true;
  286. $img->scaleImage(48);
  287. $r = $img->store($newuid, 0, $hash, $filename, t('Profile Photos'), 6 );
  288. if($r === false)
  289. $photo_failure = true;
  290. if(! $photo_failure) {
  291. q("UPDATE `photo` SET `profile` = 1 WHERE `resource-id` = '%s' ",
  292. dbesc($hash)
  293. );
  294. }
  295. }
  296. }
  297. call_hooks('register_account', $newuid);
  298. $result['success'] = true;
  299. $result['user'] = $u;
  300. return $result;
  301. }
  302. /*
  303. * send registration confirmation.
  304. * It's here as a function because the mail is sent
  305. * from different parts
  306. */
  307. function send_register_open_eml($email, $sitename, $siteurl, $username, $password){
  308. $preamble = deindent(t('
  309. Dear %1$s,
  310. Thank you for registering at %2$s. Your account has been created.
  311. '));
  312. $body = deindent(t('
  313. The login details are as follows:
  314. Site Location: %3$s
  315. Login Name: %1$s
  316. Password: %5$s
  317. You may change your password from your account "Settings" page after logging
  318. in.
  319. Please take a few moments to review the other account settings on that page.
  320. You may also wish to add some basic information to your default profile
  321. (on the "Profiles" page) so that other people can easily find you.
  322. We recommend setting your full name, adding a profile photo,
  323. adding some profile "keywords" (very useful in making new friends) - and
  324. perhaps what country you live in; if you do not wish to be more specific
  325. than that.
  326. We fully respect your right to privacy, and none of these items are necessary.
  327. If you are new and do not know anybody here, they may help
  328. you to make some new and interesting friends.
  329. Thank you and welcome to %2$s.'));
  330. $preamble = sprintf($preamble, $username, $sitename);
  331. $body = sprintf($body, $email, $sitename, $siteurl, $username, $password);
  332. return notification(array(
  333. 'type' => "SYSTEM_EMAIL",
  334. 'to_email' => $email,
  335. 'subject'=> sprintf( t('Registration details for %s'), $sitename),
  336. 'preamble'=> $preamble,
  337. 'body' => $body));
  338. }