Friendica Communications Platform (please note that this is a clone of the repository at github, issues are handled there) https://friendi.ca
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

416 lines
13 KiB

  1. <?php
  2. require_once('include/config.php');
  3. require_once('include/network.php');
  4. require_once('include/plugin.php');
  5. require_once('include/text.php');
  6. require_once('include/pgettext.php');
  7. require_once('include/datetime.php');
  8. require_once('include/enotify.php');
  9. function create_user($arr) {
  10. // Required: { username, nickname, email } or { openid_url }
  11. $a = get_app();
  12. $result = array('success' => false, 'user' => null, 'password' => '', 'message' => '');
  13. $using_invites = get_config('system','invitation_only');
  14. $num_invites = get_config('system','number_invites');
  15. $invite_id = ((x($arr,'invite_id')) ? notags(trim($arr['invite_id'])) : '');
  16. $username = ((x($arr,'username')) ? notags(trim($arr['username'])) : '');
  17. $nickname = ((x($arr,'nickname')) ? notags(trim($arr['nickname'])) : '');
  18. $email = ((x($arr,'email')) ? notags(trim($arr['email'])) : '');
  19. $openid_url = ((x($arr,'openid_url')) ? notags(trim($arr['openid_url'])) : '');
  20. $photo = ((x($arr,'photo')) ? notags(trim($arr['photo'])) : '');
  21. $password = ((x($arr,'password')) ? trim($arr['password']) : '');
  22. $blocked = ((x($arr,'blocked')) ? intval($arr['blocked']) : 0);
  23. $verified = ((x($arr,'verified')) ? intval($arr['verified']) : 0);
  24. $publish = ((x($arr,'profile_publish_reg') && intval($arr['profile_publish_reg'])) ? 1 : 0);
  25. $netpublish = ((strlen(get_config('system','directory_submit_url'))) ? $publish : 0);
  26. $tmp_str = $openid_url;
  27. if($using_invites) {
  28. if(! $invite_id) {
  29. $result['message'] .= t('An invitation is required.') . EOL;
  30. return $result;
  31. }
  32. $r = q("select * from register where `hash` = '%s' limit 1", dbesc($invite_id));
  33. if(! results($r)) {
  34. $result['message'] .= t('Invitation could not be verified.') . EOL;
  35. return $result;
  36. }
  37. }
  38. if((! x($username)) || (! x($email)) || (! x($nickname))) {
  39. if($openid_url) {
  40. if(! validate_url($tmp_str)) {
  41. $result['message'] .= t('Invalid OpenID url') . EOL;
  42. return $result;
  43. }
  44. $_SESSION['register'] = 1;
  45. $_SESSION['openid'] = $openid_url;
  46. require_once('library/openid.php');
  47. $openid = new LightOpenID;
  48. $openid->identity = $openid_url;
  49. $openid->returnUrl = $a->get_baseurl() . '/openid';
  50. $openid->required = array('namePerson/friendly', 'contact/email', 'namePerson');
  51. $openid->optional = array('namePerson/first','media/image/aspect11','media/image/default');
  52. try {
  53. $authurl = $openid->authUrl();
  54. } catch (Exception $e){
  55. $result['message'] .= t("We encountered a problem while logging in with the OpenID you provided. Please check the correct spelling of the ID."). EOL . EOL . t("The error message was:") . $e->getMessage() . EOL;
  56. return $result;
  57. }
  58. goaway($authurl);
  59. // NOTREACHED
  60. }
  61. notice( t('Please enter the required information.') . EOL );
  62. return;
  63. }
  64. if(! validate_url($tmp_str))
  65. $openid_url = '';
  66. $err = '';
  67. // collapse multiple spaces in name
  68. $username = preg_replace('/ +/',' ',$username);
  69. if(mb_strlen($username) > 48)
  70. $result['message'] .= t('Please use a shorter name.') . EOL;
  71. if(mb_strlen($username) < 3)
  72. $result['message'] .= t('Name too short.') . EOL;
  73. // I don't really like having this rule, but it cuts down
  74. // on the number of auto-registrations by Russian spammers
  75. // Using preg_match was completely unreliable, due to mixed UTF-8 regex support
  76. // $no_utf = get_config('system','no_utf');
  77. // $pat = (($no_utf) ? '/^[a-zA-Z]* [a-zA-Z]*$/' : '/^\p{L}* \p{L}*$/u' );
  78. // So now we are just looking for a space in the full name.
  79. $loose_reg = get_config('system','no_regfullname');
  80. if(! $loose_reg) {
  81. $username = mb_convert_case($username,MB_CASE_TITLE,'UTF-8');
  82. if(! strpos($username,' '))
  83. $result['message'] .= t("That doesn't appear to be your full \x28First Last\x29 name.") . EOL;
  84. }
  85. if(! allowed_email($email))
  86. $result['message'] .= t('Your email domain is not among those allowed on this site.') . EOL;
  87. if((! valid_email($email)) || (! validate_email($email)))
  88. $result['message'] .= t('Not a valid email address.') . EOL;
  89. // Disallow somebody creating an account using openid that uses the admin email address,
  90. // since openid bypasses email verification. We'll allow it if there is not yet an admin account.
  91. $adminlist = explode(",", str_replace(" ", "", strtolower($a->config['admin_email'])));
  92. //if((x($a->config,'admin_email')) && (strcasecmp($email,$a->config['admin_email']) == 0) && strlen($openid_url)) {
  93. if((x($a->config,'admin_email')) && in_array(strtolower($email), $adminlist) && strlen($openid_url)) {
  94. $r = q("SELECT * FROM `user` WHERE `email` = '%s' LIMIT 1",
  95. dbesc($email)
  96. );
  97. if(count($r))
  98. $result['message'] .= t('Cannot use that email.') . EOL;
  99. }
  100. $nickname = $arr['nickname'] = strtolower($nickname);
  101. if(! preg_match("/^[a-z][a-z0-9\-\_]*$/",$nickname))
  102. $result['message'] .= t('Your "nickname" can only contain "a-z", "0-9", "-", and "_", and must also begin with a letter.') . EOL;
  103. $r = q("SELECT `uid` FROM `user`
  104. WHERE `nickname` = '%s' LIMIT 1",
  105. dbesc($nickname)
  106. );
  107. if(count($r))
  108. $result['message'] .= t('Nickname is already registered. Please choose another.') . EOL;
  109. // Check deleted accounts that had this nickname. Doesn't matter to us,
  110. // but could be a security issue for federated platforms.
  111. $r = q("SELECT * FROM `userd`
  112. WHERE `username` = '%s' LIMIT 1",
  113. dbesc($nickname)
  114. );
  115. if(count($r))
  116. $result['message'] .= t('Nickname was once registered here and may not be re-used. Please choose another.') . EOL;
  117. if(strlen($result['message'])) {
  118. return $result;
  119. }
  120. $new_password = ((strlen($password)) ? $password : autoname(6) . mt_rand(100,9999));
  121. $new_password_encoded = hash('whirlpool',$new_password);
  122. $result['password'] = $new_password;
  123. require_once('include/crypto.php');
  124. $keys = new_keypair(4096);
  125. if($keys === false) {
  126. $result['message'] .= t('SERIOUS ERROR: Generation of security keys failed.') . EOL;
  127. return $result;
  128. }
  129. $default_service_class = get_config('system','default_service_class');
  130. if(! $default_service_class)
  131. $default_service_class = '';
  132. $prvkey = $keys['prvkey'];
  133. $pubkey = $keys['pubkey'];
  134. /**
  135. *
  136. * Create another keypair for signing/verifying
  137. * salmon protocol messages. We have to use a slightly
  138. * less robust key because this won't be using openssl
  139. * but the phpseclib. Since it is PHP interpreted code
  140. * it is not nearly as efficient, and the larger keys
  141. * will take several minutes each to process.
  142. *
  143. */
  144. $sres = new_keypair(512);
  145. $sprvkey = $sres['prvkey'];
  146. $spubkey = $sres['pubkey'];
  147. $r = q("INSERT INTO `user` ( `guid`, `username`, `password`, `email`, `openid`, `nickname`,
  148. `pubkey`, `prvkey`, `spubkey`, `sprvkey`, `register_date`, `verified`, `blocked`, `timezone`, `service_class` )
  149. VALUES ( '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', %d, %d, 'UTC', '%s' )",
  150. dbesc(generate_user_guid()),
  151. dbesc($username),
  152. dbesc($new_password_encoded),
  153. dbesc($email),
  154. dbesc($openid_url),
  155. dbesc($nickname),
  156. dbesc($pubkey),
  157. dbesc($prvkey),
  158. dbesc($spubkey),
  159. dbesc($sprvkey),
  160. dbesc(datetime_convert()),
  161. intval($verified),
  162. intval($blocked),
  163. dbesc($default_service_class)
  164. );
  165. if($r) {
  166. $r = q("SELECT * FROM `user`
  167. WHERE `username` = '%s' AND `password` = '%s' LIMIT 1",
  168. dbesc($username),
  169. dbesc($new_password_encoded)
  170. );
  171. if($r !== false && count($r)) {
  172. $u = $r[0];
  173. $newuid = intval($r[0]['uid']);
  174. }
  175. }
  176. else {
  177. $result['message'] .= t('An error occurred during registration. Please try again.') . EOL ;
  178. return $result;
  179. }
  180. /**
  181. * if somebody clicked submit twice very quickly, they could end up with two accounts
  182. * due to race condition. Remove this one.
  183. */
  184. $r = q("SELECT `uid` FROM `user`
  185. WHERE `nickname` = '%s' ",
  186. dbesc($nickname)
  187. );
  188. if((count($r) > 1) && $newuid) {
  189. $result['message'] .= t('Nickname is already registered. Please choose another.') . EOL;
  190. q("DELETE FROM `user` WHERE `uid` = %d",
  191. intval($newuid)
  192. );
  193. return $result;
  194. }
  195. if(x($newuid) !== false) {
  196. $r = q("INSERT INTO `profile` ( `uid`, `profile-name`, `is-default`, `name`, `photo`, `thumb`, `publish`, `net-publish` )
  197. VALUES ( %d, '%s', %d, '%s', '%s', '%s', %d, %d ) ",
  198. intval($newuid),
  199. t('default'),
  200. 1,
  201. dbesc($username),
  202. dbesc($a->get_baseurl() . "/photo/profile/{$newuid}.jpg"),
  203. dbesc($a->get_baseurl() . "/photo/avatar/{$newuid}.jpg"),
  204. intval($publish),
  205. intval($netpublish)
  206. );
  207. if($r === false) {
  208. $result['message'] .= t('An error occurred creating your default profile. Please try again.') . EOL;
  209. // Start fresh next time.
  210. $r = q("DELETE FROM `user` WHERE `uid` = %d",
  211. intval($newuid));
  212. return $result;
  213. }
  214. $r = q("INSERT INTO `contact` ( `uid`, `created`, `self`, `name`, `nick`, `photo`, `thumb`, `micro`, `blocked`, `pending`, `url`, `nurl`,
  215. `request`, `notify`, `poll`, `confirm`, `poco`, `name-date`, `uri-date`, `avatar-date`, `closeness` )
  216. VALUES ( %d, '%s', 1, '%s', '%s', '%s', '%s', '%s', 0, 0, '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', '%s', 0 ) ",
  217. intval($newuid),
  218. datetime_convert(),
  219. dbesc($username),
  220. dbesc($nickname),
  221. dbesc($a->get_baseurl() . "/photo/profile/{$newuid}.jpg"),
  222. dbesc($a->get_baseurl() . "/photo/avatar/{$newuid}.jpg"),
  223. dbesc($a->get_baseurl() . "/photo/micro/{$newuid}.jpg"),
  224. dbesc($a->get_baseurl() . "/profile/$nickname"),
  225. dbesc(normalise_link($a->get_baseurl() . "/profile/$nickname")),
  226. dbesc($a->get_baseurl() . "/dfrn_request/$nickname"),
  227. dbesc($a->get_baseurl() . "/dfrn_notify/$nickname"),
  228. dbesc($a->get_baseurl() . "/dfrn_poll/$nickname"),
  229. dbesc($a->get_baseurl() . "/dfrn_confirm/$nickname"),
  230. dbesc($a->get_baseurl() . "/poco/$nickname"),
  231. dbesc(datetime_convert()),
  232. dbesc(datetime_convert()),
  233. dbesc(datetime_convert())
  234. );
  235. // Create a group with no members. This allows somebody to use it
  236. // right away as a default group for new contacts.
  237. require_once('include/group.php');
  238. group_add($newuid, t('Friends'));
  239. $r = q("SELECT id FROM `group` WHERE uid = %d AND name = '%s'",
  240. intval($newuid),
  241. dbesc(t('Friends'))
  242. );
  243. if($r && count($r)) {
  244. $def_gid = $r[0]['id'];
  245. q("UPDATE user SET def_gid = %d WHERE uid = %d",
  246. intval($r[0]['id']),
  247. intval($newuid)
  248. );
  249. }
  250. if(get_config('system', 'newuser_private') && $def_gid) {
  251. q("UPDATE user SET allow_gid = '%s' WHERE uid = %d",
  252. dbesc("<" . $def_gid . ">"),
  253. intval($newuid)
  254. );
  255. }
  256. }
  257. // if we have no OpenID photo try to look up an avatar
  258. if(! strlen($photo))
  259. $photo = avatar_img($email);
  260. // unless there is no avatar-plugin loaded
  261. if(strlen($photo)) {
  262. require_once('include/Photo.php');
  263. $photo_failure = false;
  264. $filename = basename($photo);
  265. $img_str = fetch_url($photo,true);
  266. // guess mimetype from headers or filename
  267. $type = guess_image_type($photo,true);
  268. $img = new Photo($img_str, $type);
  269. if($img->is_valid()) {
  270. $img->scaleImageSquare(175);
  271. $hash = photo_new_resource();
  272. $r = $img->store($newuid, 0, $hash, $filename, t('Profile Photos'), 4 );
  273. if($r === false)
  274. $photo_failure = true;
  275. $img->scaleImage(80);
  276. $r = $img->store($newuid, 0, $hash, $filename, t('Profile Photos'), 5 );
  277. if($r === false)
  278. $photo_failure = true;
  279. $img->scaleImage(48);
  280. $r = $img->store($newuid, 0, $hash, $filename, t('Profile Photos'), 6 );
  281. if($r === false)
  282. $photo_failure = true;
  283. if(! $photo_failure) {
  284. q("UPDATE `photo` SET `profile` = 1 WHERE `resource-id` = '%s' ",
  285. dbesc($hash)
  286. );
  287. }
  288. }
  289. }
  290. call_hooks('register_account', $newuid);
  291. $result['success'] = true;
  292. $result['user'] = $u;
  293. return $result;
  294. }
  295. /*
  296. * send registration confirmation.
  297. * It's here as a function because the mail is sent
  298. * from different parts
  299. */
  300. function send_register_open_eml($email, $sitename, $siteurl, $username, $password){
  301. $preamble = deindent(t('
  302. Dear %1$s,
  303. Thank you for registering at %2$s. Your account has been created.
  304. '));
  305. $body = deindent(t('
  306. The login details are as follows:
  307. Site Location: %3$s
  308. Login Name: %1$s
  309. Password: %5$s
  310. You may change your password from your account "Settings" page after logging
  311. in.
  312. Please take a few moments to review the other account settings on that page.
  313. You may also wish to add some basic information to your default profile
  314. (on the "Profiles" page) so that other people can easily find you.
  315. We recommend setting your full name, adding a profile photo,
  316. adding some profile "keywords" (very useful in making new friends) - and
  317. perhaps what country you live in; if you do not wish to be more specific
  318. than that.
  319. We fully respect your right to privacy, and none of these items are necessary.
  320. If you are new and do not know anybody here, they may help
  321. you to make some new and interesting friends.
  322. Thank you and welcome to %2$s.'));
  323. $preamble = sprintf($preamble, $username, $sitename);
  324. $body = sprintf($body, $email, $sitename, $siteurl, $username, $password);
  325. return notification(array(
  326. 'type' => "SYSTEM_EMAIL",
  327. 'to_email' => $email,
  328. 'subject'=> sprintf( t('Registration details for %s'), $sitename),
  329. 'preamble'=> $preamble,
  330. 'body' => $body));
  331. }