Friendica Communications Platform (please note that this is a clone of the repository at github, issues are handled there) https://friendi.ca
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

473 lines
15 KiB

7 years ago
  1. <?php
  2. require_once('include/config.php');
  3. require_once('include/network.php');
  4. require_once('include/plugin.php');
  5. require_once('include/text.php');
  6. require_once('include/pgettext.php');
  7. require_once('include/datetime.php');
  8. require_once('include/enotify.php');
  9. function create_user($arr) {
  10. // Required: { username, nickname, email } or { openid_url }
  11. $a = get_app();
  12. $result = array('success' => false, 'user' => null, 'password' => '', 'message' => '');
  13. $using_invites = get_config('system','invitation_only');
  14. $num_invites = get_config('system','number_invites');
  15. $invite_id = ((x($arr,'invite_id')) ? notags(trim($arr['invite_id'])) : '');
  16. $username = ((x($arr,'username')) ? notags(trim($arr['username'])) : '');
  17. $nickname = ((x($arr,'nickname')) ? notags(trim($arr['nickname'])) : '');
  18. $email = ((x($arr,'email')) ? notags(trim($arr['email'])) : '');
  19. $openid_url = ((x($arr,'openid_url')) ? notags(trim($arr['openid_url'])) : '');
  20. $photo = ((x($arr,'photo')) ? notags(trim($arr['photo'])) : '');
  21. $password = ((x($arr,'password')) ? trim($arr['password']) : '');
  22. $password1 = ((x($arr,'password1')) ? trim($arr['password1']) : '');
  23. $confirm = ((x($arr,'confirm')) ? trim($arr['confirm']) : '');
  24. $blocked = ((x($arr,'blocked')) ? intval($arr['blocked']) : 0);
  25. $verified = ((x($arr,'verified')) ? intval($arr['verified']) : 0);
  26. $publish = ((x($arr,'profile_publish_reg') && intval($arr['profile_publish_reg'])) ? 1 : 0);
  27. $netpublish = ((strlen(get_config('system','directory'))) ? $publish : 0);
  28. if ($password1 != $confirm) {
  29. $result['message'] .= t('Passwords do not match. Password unchanged.') . EOL;
  30. return $result;
  31. } elseif ($password1 != "")
  32. $password = $password1;
  33. $tmp_str = $openid_url;
  34. if($using_invites) {
  35. if(! $invite_id) {
  36. $result['message'] .= t('An invitation is required.') . EOL;
  37. return $result;
  38. }
  39. $r = q("SELECT * FROM `register` WHERE `hash` = '%s' LIMIT 1", dbesc($invite_id));
  40. if(! results($r)) {
  41. $result['message'] .= t('Invitation could not be verified.') . EOL;
  42. return $result;
  43. }
  44. }
  45. if((! x($username)) || (! x($email)) || (! x($nickname))) {
  46. if($openid_url) {
  47. if(! validate_url($tmp_str)) {
  48. $result['message'] .= t('Invalid OpenID url') . EOL;
  49. return $result;
  50. }
  51. $_SESSION['register'] = 1;
  52. $_SESSION['openid'] = $openid_url;
  53. require_once('library/openid.php');
  54. $openid = new LightOpenID;
  55. $openid->identity = $openid_url;
  56. $openid->returnUrl = z_root() . '/openid';
  57. $openid->required = array('namePerson/friendly', 'contact/email', 'namePerson');
  58. $openid->optional = array('namePerson/first','media/image/aspect11','media/image/default');
  59. try {
  60. $authurl = $openid->authUrl();
  61. } catch (Exception $e){
  62. $result['message'] .= t("We encountered a problem while logging in with the OpenID you provided. Please check the correct spelling of the ID."). EOL . EOL . t("The error message was:") . $e->getMessage() . EOL;
  63. return $result;
  64. }
  65. goaway($authurl);
  66. // NOTREACHED
  67. }
  68. notice( t('Please enter the required information.') . EOL );
  69. return;
  70. }
  71. if(! validate_url($tmp_str))
  72. $openid_url = '';
  73. $err = '';
  74. // collapse multiple spaces in name
  75. $username = preg_replace('/ +/',' ',$username);
  76. if(mb_strlen($username) > 48)
  77. $result['message'] .= t('Please use a shorter name.') . EOL;
  78. if(mb_strlen($username) < 3)
  79. $result['message'] .= t('Name too short.') . EOL;
  80. // I don't really like having this rule, but it cuts down
  81. // on the number of auto-registrations by Russian spammers
  82. // Using preg_match was completely unreliable, due to mixed UTF-8 regex support
  83. // $no_utf = get_config('system','no_utf');
  84. // $pat = (($no_utf) ? '/^[a-zA-Z]* [a-zA-Z]*$/' : '/^\p{L}* \p{L}*$/u' );
  85. // So now we are just looking for a space in the full name.
  86. $loose_reg = get_config('system','no_regfullname');
  87. if(! $loose_reg) {
  88. $username = mb_convert_case($username,MB_CASE_TITLE,'UTF-8');
  89. if(! strpos($username,' '))
  90. $result['message'] .= t("That doesn't appear to be your full \x28First Last\x29 name.") . EOL;
  91. }
  92. if(! allowed_email($email))
  93. $result['message'] .= t('Your email domain is not among those allowed on this site.') . EOL;
  94. if((! valid_email($email)) || (! validate_email($email)))
  95. $result['message'] .= t('Not a valid email address.') . EOL;
  96. // Disallow somebody creating an account using openid that uses the admin email address,
  97. // since openid bypasses email verification. We'll allow it if there is not yet an admin account.
  98. $adminlist = explode(",", str_replace(" ", "", strtolower($a->config['admin_email'])));
  99. //if((x($a->config,'admin_email')) && (strcasecmp($email,$a->config['admin_email']) == 0) && strlen($openid_url)) {
  100. if((x($a->config,'admin_email')) && in_array(strtolower($email), $adminlist) && strlen($openid_url)) {
  101. $r = q("SELECT * FROM `user` WHERE `email` = '%s' LIMIT 1",
  102. dbesc($email)
  103. );
  104. if (dbm::is_result($r))
  105. $result['message'] .= t('Cannot use that email.') . EOL;
  106. }
  107. $nickname = $arr['nickname'] = strtolower($nickname);
  108. if(! preg_match("/^[a-z0-9][a-z0-9\_]*$/",$nickname))
  109. $result['message'] .= t('Your "nickname" can only contain "a-z", "0-9" and "_".') . EOL;
  110. $r = q("SELECT `uid` FROM `user`
  111. WHERE `nickname` = '%s' LIMIT 1",
  112. dbesc($nickname)
  113. );
  114. if (dbm::is_result($r))
  115. $result['message'] .= t('Nickname is already registered. Please choose another.') . EOL;
  116. // Check deleted accounts that had this nickname. Doesn't matter to us,
  117. // but could be a security issue for federated platforms.
  118. $r = q("SELECT * FROM `userd`
  119. WHERE `username` = '%s' LIMIT 1",
  120. dbesc($nickname)
  121. );
  122. if (dbm::is_result($r))
  123. $result['message'] .= t('Nickname was once registered here and may not be re-used. Please choose another.') . EOL;
  124. if(strlen($result['message'])) {
  125. return $result;
  126. }
  127. $new_password = ((strlen($password)) ? $password : autoname(6) . mt_rand(100,9999));
  128. $new_password_encoded = hash('whirlpool',$new_password);
  129. $result['password'] = $new_password;
  130. require_once('include/crypto.php');
  131. $keys = new_keypair(4096);
  132. if($keys === false) {
  133. $result['message'] .= t('SERIOUS ERROR: Generation of security keys failed.') . EOL;
  134. return $result;
  135. }
  136. $default_service_class = get_config('system','default_service_class');
  137. if(! $default_service_class)
  138. $default_service_class = '';
  139. $prvkey = $keys['prvkey'];
  140. $pubkey = $keys['pubkey'];
  141. /**
  142. *
  143. * Create another keypair for signing/verifying
  144. * salmon protocol messages. We have to use a slightly
  145. * less robust key because this won't be using openssl
  146. * but the phpseclib. Since it is PHP interpreted code
  147. * it is not nearly as efficient, and the larger keys
  148. * will take several minutes each to process.
  149. *
  150. */
  151. $sres = new_keypair(512);
  152. $sprvkey = $sres['prvkey'];
  153. $spubkey = $sres['pubkey'];
  154. $r = q("INSERT INTO `user` ( `guid`, `username`, `password`, `email`, `openid`, `nickname`,
  155. `pubkey`, `prvkey`, `spubkey`, `sprvkey`, `register_date`, `verified`, `blocked`, `timezone`, `service_class`, `default-location` )
  156. VALUES ( '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', %d, %d, 'UTC', '%s', '' )",
  157. dbesc(generate_user_guid()),
  158. dbesc($username),
  159. dbesc($new_password_encoded),
  160. dbesc($email),
  161. dbesc($openid_url),
  162. dbesc($nickname),
  163. dbesc($pubkey),
  164. dbesc($prvkey),
  165. dbesc($spubkey),
  166. dbesc($sprvkey),
  167. dbesc(datetime_convert()),
  168. intval($verified),
  169. intval($blocked),
  170. dbesc($default_service_class)
  171. );
  172. if($r) {
  173. $r = q("SELECT * FROM `user`
  174. WHERE `username` = '%s' AND `password` = '%s' LIMIT 1",
  175. dbesc($username),
  176. dbesc($new_password_encoded)
  177. );
  178. if (dbm::is_result($r)) {
  179. $u = $r[0];
  180. $newuid = intval($r[0]['uid']);
  181. }
  182. }
  183. else {
  184. $result['message'] .= t('An error occurred during registration. Please try again.') . EOL ;
  185. return $result;
  186. }
  187. /**
  188. * if somebody clicked submit twice very quickly, they could end up with two accounts
  189. * due to race condition. Remove this one.
  190. */
  191. $r = q("SELECT `uid` FROM `user`
  192. WHERE `nickname` = '%s' ",
  193. dbesc($nickname)
  194. );
  195. if ((dbm::is_result($r)) && (count($r) > 1) && $newuid) {
  196. $result['message'] .= t('Nickname is already registered. Please choose another.') . EOL;
  197. q("DELETE FROM `user` WHERE `uid` = %d",
  198. intval($newuid)
  199. );
  200. return $result;
  201. }
  202. if(x($newuid) !== false) {
  203. $r = q("INSERT INTO `profile` ( `uid`, `profile-name`, `is-default`, `name`, `photo`, `thumb`, `publish`, `net-publish` )
  204. VALUES ( %d, '%s', %d, '%s', '%s', '%s', %d, %d ) ",
  205. intval($newuid),
  206. t('default'),
  207. 1,
  208. dbesc($username),
  209. dbesc(z_root() . "/photo/profile/{$newuid}.jpg"),
  210. dbesc(z_root() . "/photo/avatar/{$newuid}.jpg"),
  211. intval($publish),
  212. intval($netpublish)
  213. );
  214. if($r === false) {
  215. $result['message'] .= t('An error occurred creating your default profile. Please try again.') . EOL;
  216. // Start fresh next time.
  217. $r = q("DELETE FROM `user` WHERE `uid` = %d",
  218. intval($newuid));
  219. return $result;
  220. }
  221. // Create the self contact
  222. user_create_self_contact($newuid);
  223. // Create a group with no members. This allows somebody to use it
  224. // right away as a default group for new contacts.
  225. require_once('include/group.php');
  226. group_add($newuid, t('Friends'));
  227. $r = q("SELECT `id` FROM `group` WHERE `uid` = %d AND `name` = '%s'",
  228. intval($newuid),
  229. dbesc(t('Friends'))
  230. );
  231. if (dbm::is_result($r)) {
  232. $def_gid = $r[0]['id'];
  233. q("UPDATE `user` SET `def_gid` = %d WHERE `uid` = %d",
  234. intval($r[0]['id']),
  235. intval($newuid)
  236. );
  237. }
  238. if(get_config('system', 'newuser_private') && $def_gid) {
  239. q("UPDATE `user` SET `allow_gid` = '%s' WHERE `uid` = %d",
  240. dbesc("<" . $def_gid . ">"),
  241. intval($newuid)
  242. );
  243. }
  244. }
  245. // if we have no OpenID photo try to look up an avatar
  246. if(! strlen($photo))
  247. $photo = avatar_img($email);
  248. // unless there is no avatar-plugin loaded
  249. if(strlen($photo)) {
  250. require_once('include/Photo.php');
  251. $photo_failure = false;
  252. $filename = basename($photo);
  253. $img_str = fetch_url($photo,true);
  254. // guess mimetype from headers or filename
  255. $type = guess_image_type($photo,true);
  256. $img = new Photo($img_str, $type);
  257. if($img->is_valid()) {
  258. $img->scaleImageSquare(175);
  259. $hash = photo_new_resource();
  260. $r = $img->store($newuid, 0, $hash, $filename, t('Profile Photos'), 4 );
  261. if($r === false)
  262. $photo_failure = true;
  263. $img->scaleImage(80);
  264. $r = $img->store($newuid, 0, $hash, $filename, t('Profile Photos'), 5 );
  265. if($r === false)
  266. $photo_failure = true;
  267. $img->scaleImage(48);
  268. $r = $img->store($newuid, 0, $hash, $filename, t('Profile Photos'), 6 );
  269. if($r === false)
  270. $photo_failure = true;
  271. if(! $photo_failure) {
  272. q("UPDATE `photo` SET `profile` = 1 WHERE `resource-id` = '%s' ",
  273. dbesc($hash)
  274. );
  275. }
  276. }
  277. }
  278. call_hooks('register_account', $newuid);
  279. $result['success'] = true;
  280. $result['user'] = $u;
  281. return $result;
  282. }
  283. /**
  284. * @brief create the "self" contact from data from the user table
  285. *
  286. * @param integer $uid
  287. */
  288. function user_create_self_contact($uid) {
  289. // Only create the entry if it doesn't exist yet
  290. $r = q("SELECT `id` FROM `contact` WHERE `uid` = %d AND `self`", intval($uid));
  291. if (dbm::is_result($r)) {
  292. return;
  293. }
  294. $r = q("SELECT `uid`, `username`, `nickname` FROM `user` WHERE `uid` = %d", intval($uid));
  295. if (!dbm::is_result($r)) {
  296. return;
  297. }
  298. $user = $r[0];
  299. q("INSERT INTO `contact` (`uid`, `created`, `self`, `name`, `nick`, `photo`, `thumb`, `micro`, `blocked`, `pending`, `url`, `nurl`,
  300. `addr`, `request`, `notify`, `poll`, `confirm`, `poco`, `name-date`, `uri-date`, `avatar-date`, `closeness`)
  301. VALUES (%d, '%s', 1, '%s', '%s', '%s', '%s', '%s', 0, 0, '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', 0)",
  302. intval($user['uid']),
  303. datetime_convert(),
  304. dbesc($user['username']),
  305. dbesc($user['nickname']),
  306. dbesc(z_root()."/photo/profile/".$user['uid'].".jpg"),
  307. dbesc(z_root()."/photo/avatar/".$user['uid'].".jpg"),
  308. dbesc(z_root()."/photo/micro/".$user['uid'].".jpg"),
  309. dbesc(z_root()."/profile/".$user['nickname']),
  310. dbesc(normalise_link(z_root()."/profile/".$user['nickname'])),
  311. dbesc($user['nickname'].'@'.substr(z_root(), strpos(z_root(),'://') + 3)),
  312. dbesc(z_root()."/dfrn_request/".$user['nickname']),
  313. dbesc(z_root()."/dfrn_notify/".$user['nickname']),
  314. dbesc(z_root()."/dfrn_poll/".$user['nickname']),
  315. dbesc(z_root()."/dfrn_confirm/".$user['nickname']),
  316. dbesc(z_root()."/poco/".$user['nickname']),
  317. dbesc(datetime_convert()),
  318. dbesc(datetime_convert()),
  319. dbesc(datetime_convert())
  320. );
  321. }
  322. /**
  323. * @brief send registration confiŕmation with the intormation that reg is pending
  324. *
  325. * @param string $email
  326. * @param string $sitename
  327. * @param string $username
  328. * @return NULL|boolean from notification() and email() inherited
  329. */
  330. function send_register_pending_eml($email, $sitename, $username) {
  331. $body = deindent(t('
  332. Dear %1$s,
  333. Thank you for registering at %2$s. Your account is pending for approval by the administrator.
  334. '));
  335. $body = sprintf($body, $username, $sitename);
  336. return notification(array(
  337. 'type' => "SYSTEM_EMAIL",
  338. 'to_email' => $email,
  339. 'subject'=> sprintf( t('Registration at %s'), $sitename),
  340. 'body' => $body));
  341. }
  342. /*
  343. * send registration confirmation.
  344. * It's here as a function because the mail is sent
  345. * from different parts
  346. */
  347. function send_register_open_eml($email, $sitename, $siteurl, $username, $password){
  348. $preamble = deindent(t('
  349. Dear %1$s,
  350. Thank you for registering at %2$s. Your account has been created.
  351. '));
  352. $body = deindent(t('
  353. The login details are as follows:
  354. Site Location: %3$s
  355. Login Name: %1$s
  356. Password: %5$s
  357. You may change your password from your account "Settings" page after logging
  358. in.
  359. Please take a few moments to review the other account settings on that page.
  360. You may also wish to add some basic information to your default profile
  361. (on the "Profiles" page) so that other people can easily find you.
  362. We recommend setting your full name, adding a profile photo,
  363. adding some profile "keywords" (very useful in making new friends) - and
  364. perhaps what country you live in; if you do not wish to be more specific
  365. than that.
  366. We fully respect your right to privacy, and none of these items are necessary.
  367. If you are new and do not know anybody here, they may help
  368. you to make some new and interesting friends.
  369. Thank you and welcome to %2$s.'));
  370. $preamble = sprintf($preamble, $username, $sitename);
  371. $body = sprintf($body, $email, $sitename, $siteurl, $username, $password);
  372. return notification(array(
  373. 'type' => "SYSTEM_EMAIL",
  374. 'to_email' => $email,
  375. 'subject'=> sprintf( t('Registration details for %s'), $sitename),
  376. 'preamble'=> $preamble,
  377. 'body' => $body));
  378. }