Merge pull request #4285 from MrPetovan/task/3942-centralize-password-update
[friendica.git/.git] / mod / settings.php
1 <?php
2 /**
3  * @file mod/settings.php
4  */
5
6 use Friendica\App;
7 use Friendica\Content\Feature;
8 use Friendica\Content\Nav;
9 use Friendica\Core\Addon;
10 use Friendica\Core\Config;
11 use Friendica\Core\PConfig;
12 use Friendica\Core\System;
13 use Friendica\Core\Worker;
14 use Friendica\Database\DBM;
15 use Friendica\Model\GContact;
16 use Friendica\Model\Group;
17 use Friendica\Model\User;
18 use Friendica\Protocol\Email;
19
20 function get_theme_config_file($theme)
21 {
22         $a = get_app();
23         $base_theme = $a->theme_info['extends'];
24
25         if (file_exists("view/theme/$theme/config.php")) {
26                 return "view/theme/$theme/config.php";
27         }
28         if (file_exists("view/theme/$base_theme/config.php")) {
29                 return "view/theme/$base_theme/config.php";
30         }
31         return null;
32 }
33
34 function settings_init(App $a)
35 {
36         if (!local_user()) {
37                 notice(t('Permission denied.') . EOL);
38                 return;
39         }
40
41         // These lines provide the javascript needed by the acl selector
42
43         $tpl = get_markup_template('settings/head.tpl');
44         $a->page['htmlhead'] .= replace_macros($tpl,[
45                 '$ispublic' => t('everybody')
46         ]);
47
48         $tabs = [
49                 [
50                         'label' => t('Account'),
51                         'url'   => 'settings',
52                         'selected'      =>  (($a->argc == 1) && ($a->argv[0] === 'settings')?'active':''),
53                         'accesskey' => 'o',
54                 ],
55         ];
56
57         if (Feature::get()) {
58                 $tabs[] =       [
59                                         'label' => t('Additional features'),
60                                         'url'   => 'settings/features',
61                                         'selected'      => (($a->argc > 1) && ($a->argv[1] === 'features') ? 'active' : ''),
62                                         'accesskey' => 't',
63                                 ];
64         }
65
66         $tabs[] =       [
67                 'label' => t('Display'),
68                 'url'   => 'settings/display',
69                 'selected'      => (($a->argc > 1) && ($a->argv[1] === 'display')?'active':''),
70                 'accesskey' => 'i',
71         ];
72
73         $tabs[] =       [
74                 'label' => t('Social Networks'),
75                 'url'   => 'settings/connectors',
76                 'selected'      => (($a->argc > 1) && ($a->argv[1] === 'connectors')?'active':''),
77                 'accesskey' => 'w',
78         ];
79
80         $tabs[] =       [
81                 'label' => t('Addons'),
82                 'url'   => 'settings/addon',
83                 'selected'      => (($a->argc > 1) && ($a->argv[1] === 'addon')?'active':''),
84                 'accesskey' => 'l',
85         ];
86
87         $tabs[] =       [
88                 'label' => t('Delegations'),
89                 'url'   => 'delegate',
90                 'selected'      => (($a->argc == 1) && ($a->argv[0] === 'delegate')?'active':''),
91                 'accesskey' => 'd',
92         ];
93
94         $tabs[] =       [
95                 'label' => t('Connected apps'),
96                 'url' => 'settings/oauth',
97                 'selected' => (($a->argc > 1) && ($a->argv[1] === 'oauth')?'active':''),
98                 'accesskey' => 'b',
99         ];
100
101         $tabs[] =       [
102                 'label' => t('Export personal data'),
103                 'url' => 'uexport',
104                 'selected' => (($a->argc == 1) && ($a->argv[0] === 'uexport')?'active':''),
105                 'accesskey' => 'e',
106         ];
107
108         $tabs[] =       [
109                 'label' => t('Remove account'),
110                 'url' => 'removeme',
111                 'selected' => (($a->argc == 1) && ($a->argv[0] === 'removeme')?'active':''),
112                 'accesskey' => 'r',
113         ];
114
115
116         $tabtpl = get_markup_template("generic_links_widget.tpl");
117         $a->page['aside'] = replace_macros($tabtpl, [
118                 '$title' => t('Settings'),
119                 '$class' => 'settings-widget',
120                 '$items' => $tabs,
121         ]);
122
123 }
124
125 function settings_post(App $a)
126 {
127         if (!local_user()) {
128                 return;
129         }
130
131         if (x($_SESSION, 'submanage') && intval($_SESSION['submanage'])) {
132                 return;
133         }
134
135         if (count($a->user) && x($a->user, 'uid') && $a->user['uid'] != local_user()) {
136                 notice(t('Permission denied.') . EOL);
137                 return;
138         }
139
140         $old_page_flags = $a->user['page-flags'];
141
142         if (($a->argc > 1) && ($a->argv[1] === 'oauth') && x($_POST, 'remove')) {
143                 check_form_security_token_redirectOnErr('/settings/oauth', 'settings_oauth');
144
145                 $key = $_POST['remove'];
146                 q("DELETE FROM tokens WHERE id='%s' AND uid=%d",
147                         dbesc($key),
148                         local_user());
149                 goaway(System::baseUrl(true)."/settings/oauth/");
150                 return;
151         }
152
153         if (($a->argc > 2) && ($a->argv[1] === 'oauth')  && ($a->argv[2] === 'edit'||($a->argv[2] === 'add')) && x($_POST, 'submit')) {
154                 check_form_security_token_redirectOnErr('/settings/oauth', 'settings_oauth');
155
156                 $name     = defaults($_POST, 'name'    , '');
157                 $key      = defaults($_POST, 'key'     , '');
158                 $secret   = defaults($_POST, 'secret'  , '');
159                 $redirect = defaults($_POST, 'redirect', '');
160                 $icon     = defaults($_POST, 'icon'    , '');
161
162                 if ($name == "" || $key == "" || $secret == "") {
163                         notice(t("Missing some important data!"));
164                 } else {
165                         if ($_POST['submit']==t("Update")) {
166                                 q("UPDATE clients SET
167                                                         client_id='%s',
168                                                         pw='%s',
169                                                         name='%s',
170                                                         redirect_uri='%s',
171                                                         icon='%s',
172                                                         uid=%d
173                                                 WHERE client_id='%s'",
174                                         dbesc($key),
175                                         dbesc($secret),
176                                         dbesc($name),
177                                         dbesc($redirect),
178                                         dbesc($icon),
179                                         local_user(),
180                                         dbesc($key)
181                                 );
182                         } else {
183                                 q("INSERT INTO clients
184                                                         (client_id, pw, name, redirect_uri, icon, uid)
185                                                 VALUES ('%s', '%s', '%s', '%s', '%s',%d)",
186                                         dbesc($key),
187                                         dbesc($secret),
188                                         dbesc($name),
189                                         dbesc($redirect),
190                                         dbesc($icon),
191                                         local_user()
192                                 );
193                         }
194                 }
195                 goaway(System::baseUrl(true)."/settings/oauth/");
196                 return;
197         }
198
199         if (($a->argc > 1) && ($a->argv[1] == 'addon')) {
200                 check_form_security_token_redirectOnErr('/settings/addon', 'settings_addon');
201
202                 Addon::callHooks('addon_settings_post', $_POST);
203                 return;
204         }
205
206         if (($a->argc > 1) && ($a->argv[1] == 'connectors'))
207         {
208                 check_form_security_token_redirectOnErr('/settings/connectors', 'settings_connectors');
209
210                 if (x($_POST, 'general-submit')) {
211                         PConfig::set(local_user(), 'system', 'no_intelligent_shortening', intval($_POST['no_intelligent_shortening']));
212                         PConfig::set(local_user(), 'system', 'ostatus_autofriend', intval($_POST['snautofollow']));
213                         PConfig::set(local_user(), 'ostatus', 'default_group', $_POST['group-selection']);
214                         PConfig::set(local_user(), 'ostatus', 'legacy_contact', $_POST['legacy_contact']);
215                 } elseif (x($_POST, 'imap-submit')) {
216
217                         $mail_server       = ((x($_POST, 'mail_server')) ? $_POST['mail_server'] : '');
218                         $mail_port         = ((x($_POST, 'mail_port')) ? $_POST['mail_port'] : '');
219                         $mail_ssl          = ((x($_POST, 'mail_ssl')) ? strtolower(trim($_POST['mail_ssl'])) : '');
220                         $mail_user         = ((x($_POST, 'mail_user')) ? $_POST['mail_user'] : '');
221                         $mail_pass         = ((x($_POST, 'mail_pass')) ? trim($_POST['mail_pass']) : '');
222                         $mail_action       = ((x($_POST, 'mail_action')) ? trim($_POST['mail_action']) : '');
223                         $mail_movetofolder = ((x($_POST, 'mail_movetofolder')) ? trim($_POST['mail_movetofolder']) : '');
224                         $mail_replyto      = ((x($_POST, 'mail_replyto')) ? $_POST['mail_replyto'] : '');
225                         $mail_pubmail      = ((x($_POST, 'mail_pubmail')) ? $_POST['mail_pubmail'] : '');
226
227
228                         $mail_disabled = ((function_exists('imap_open') && (!Config::get('system', 'imap_disabled'))) ? 0 : 1);
229                         if (Config::get('system', 'dfrn_only')) {
230                                 $mail_disabled = 1;
231                         }
232
233                         if (!$mail_disabled) {
234                                 $failed = false;
235                                 $r = q("SELECT * FROM `mailacct` WHERE `uid` = %d LIMIT 1",
236                                         intval(local_user())
237                                 );
238                                 if (!DBM::is_result($r)) {
239                                         dba::insert('mailacct', ['uid' => local_user()]);
240                                 }
241                                 if (strlen($mail_pass)) {
242                                         $pass = '';
243                                         openssl_public_encrypt($mail_pass, $pass, $a->user['pubkey']);
244                                         dba::update('mailacct', ['pass' => bin2hex($pass)], ['uid' => local_user()]);
245                                 }
246                                 $r = q("UPDATE `mailacct` SET `server` = '%s', `port` = %d, `ssltype` = '%s', `user` = '%s',
247                                         `action` = %d, `movetofolder` = '%s',
248                                         `mailbox` = 'INBOX', `reply_to` = '%s', `pubmail` = %d WHERE `uid` = %d",
249                                         dbesc($mail_server),
250                                         intval($mail_port),
251                                         dbesc($mail_ssl),
252                                         dbesc($mail_user),
253                                         intval($mail_action),
254                                         dbesc($mail_movetofolder),
255                                         dbesc($mail_replyto),
256                                         intval($mail_pubmail),
257                                         intval(local_user())
258                                 );
259                                 logger("mail: updating mailaccount. Response: ".print_r($r, true));
260                                 $r = q("SELECT * FROM `mailacct` WHERE `uid` = %d LIMIT 1",
261                                         intval(local_user())
262                                 );
263                                 if (DBM::is_result($r)) {
264                                         $eacct = $r[0];
265                                         $mb = Email::constructMailboxName($eacct);
266
267                                         if (strlen($eacct['server'])) {
268                                                 $dcrpass = '';
269                                                 openssl_private_decrypt(hex2bin($eacct['pass']), $dcrpass, $a->user['prvkey']);
270                                                 $mbox = Email::connect($mb, $mail_user, $dcrpass);
271                                                 unset($dcrpass);
272                                                 if (!$mbox) {
273                                                         $failed = true;
274                                                         notice(t('Failed to connect with email account using the settings provided.') . EOL);
275                                                 }
276                                         }
277                                 }
278                                 if (!$failed) {
279                                         info(t('Email settings updated.') . EOL);
280                                 }
281                         }
282                 }
283
284                 Addon::callHooks('connector_settings_post', $_POST);
285                 return;
286         }
287
288         if (($a->argc > 1) && ($a->argv[1] === 'features')) {
289                 check_form_security_token_redirectOnErr('/settings/features', 'settings_features');
290                 foreach ($_POST as $k => $v) {
291                         if (strpos($k, 'feature_') === 0) {
292                                 PConfig::set(local_user(), 'feature', substr($k, 8), ((intval($v)) ? 1 : 0));
293                         }
294                 }
295                 info(t('Features updated') . EOL);
296                 return;
297         }
298
299         if (($a->argc > 1) && ($a->argv[1] === 'display')) {
300                 check_form_security_token_redirectOnErr('/settings/display', 'settings_display');
301
302                 $theme             = x($_POST, 'theme')             ? notags(trim($_POST['theme']))        : $a->user['theme'];
303                 $mobile_theme      = x($_POST, 'mobile_theme')      ? notags(trim($_POST['mobile_theme'])) : '';
304                 $nosmile           = x($_POST, 'nosmile')           ? intval($_POST['nosmile'])            : 0;
305                 $first_day_of_week = x($_POST, 'first_day_of_week') ? intval($_POST['first_day_of_week'])  : 0;
306                 $noinfo            = x($_POST, 'noinfo')            ? intval($_POST['noinfo'])             : 0;
307                 $infinite_scroll   = x($_POST, 'infinite_scroll')   ? intval($_POST['infinite_scroll'])    : 0;
308                 $no_auto_update    = x($_POST, 'no_auto_update')    ? intval($_POST['no_auto_update'])     : 0;
309                 $bandwidth_saver   = x($_POST, 'bandwidth_saver')   ? intval($_POST['bandwidth_saver'])    : 0;
310                 $smart_threading   = x($_POST, 'smart_threading')   ? intval($_POST['smart_threading'])    : 0;
311                 $nowarn_insecure   = x($_POST, 'nowarn_insecure')   ? intval($_POST['nowarn_insecure'])    : 0;
312                 $browser_update    = x($_POST, 'browser_update')    ? intval($_POST['browser_update'])     : 0;
313                 if ($browser_update != -1) {
314                         $browser_update = $browser_update * 1000;
315                         if ($browser_update < 10000) {
316                                 $browser_update = 10000;
317                         }
318                 }
319
320                 $itemspage_network = x($_POST, 'itemspage_network')  ? intval($_POST['itemspage_network'])  : 40;
321                 if ($itemspage_network > 100) {
322                         $itemspage_network = 100;
323                 }
324                 $itemspage_mobile_network = x($_POST, 'itemspage_mobile_network') ? intval($_POST['itemspage_mobile_network']) : 20;
325                 if ($itemspage_mobile_network > 100) {
326                         $itemspage_mobile_network = 100;
327                 }
328
329                 if ($mobile_theme !== '') {
330                         PConfig::set(local_user(), 'system', 'mobile_theme', $mobile_theme);
331                 }
332
333                 PConfig::set(local_user(), 'system', 'nowarn_insecure'         , $nowarn_insecure);
334                 PConfig::set(local_user(), 'system', 'update_interval'         , $browser_update);
335                 PConfig::set(local_user(), 'system', 'itemspage_network'       , $itemspage_network);
336                 PConfig::set(local_user(), 'system', 'itemspage_mobile_network', $itemspage_mobile_network);
337                 PConfig::set(local_user(), 'system', 'no_smilies'              , $nosmile);
338                 PConfig::set(local_user(), 'system', 'first_day_of_week'       , $first_day_of_week);
339                 PConfig::set(local_user(), 'system', 'ignore_info'             , $noinfo);
340                 PConfig::set(local_user(), 'system', 'infinite_scroll'         , $infinite_scroll);
341                 PConfig::set(local_user(), 'system', 'no_auto_update'          , $no_auto_update);
342                 PConfig::set(local_user(), 'system', 'bandwidth_saver'         , $bandwidth_saver);
343                 PConfig::set(local_user(), 'system', 'smart_threading'         , $smart_threading);
344
345                 if ($theme == $a->user['theme']) {
346                         // call theme_post only if theme has not been changed
347                         if (($themeconfigfile = get_theme_config_file($theme)) !== null) {
348                                 require_once $themeconfigfile;
349                                 theme_post($a);
350                         }
351                 }
352
353                 $r = q("UPDATE `user` SET `theme` = '%s' WHERE `uid` = %d",
354                                 dbesc($theme),
355                                 intval(local_user())
356                 );
357
358                 Addon::callHooks('display_settings_post', $_POST);
359                 goaway('settings/display');
360                 return; // NOTREACHED
361         }
362
363         check_form_security_token_redirectOnErr('/settings', 'settings');
364
365         if (x($_POST,'resend_relocate')) {
366                 Worker::add(PRIORITY_HIGH, 'Notifier', 'relocate', local_user());
367                 info(t("Relocate message has been send to your contacts"));
368                 goaway('settings');
369         }
370
371         Addon::callHooks('settings_post', $_POST);
372
373         if (x($_POST, 'password') || x($_POST, 'confirm')) {
374                 $newpass = $_POST['password'];
375                 $confirm = $_POST['confirm'];
376
377                 $err = false;
378                 if ($newpass != $confirm) {
379                         notice(t('Passwords do not match. Password unchanged.') . EOL);
380                         $err = true;
381                 }
382
383                 if (!x($newpass) || !x($confirm)) {
384                         notice(t('Empty passwords are not allowed. Password unchanged.') . EOL);
385                         $err = true;
386         }
387
388         //  check if the old password was supplied correctly before changing it to the new value
389         if (!User::authenticate(intval(local_user()), $_POST['opassword'])) {
390             notice(t('Wrong password.') . EOL);
391             $err = true;
392         }
393
394                 if (!$err) {
395                         $result = User::updatePassword(local_user(), $newpass);
396                         if (DBM::is_result($result)) {
397                                 info(t('Password changed.') . EOL);
398                         } else {
399                                 notice(t('Password update failed. Please try again.') . EOL);
400                         }
401                 }
402         }
403
404         $username         = ((x($_POST, 'username'))   ? notags(trim($_POST['username']))     : '');
405         $email            = ((x($_POST, 'email'))      ? notags(trim($_POST['email']))        : '');
406         $timezone         = ((x($_POST, 'timezone'))   ? notags(trim($_POST['timezone']))     : '');
407         $language         = ((x($_POST, 'language'))   ? notags(trim($_POST['language']))     : '');
408
409         $defloc           = ((x($_POST, 'defloc'))     ? notags(trim($_POST['defloc']))       : '');
410         $openid           = ((x($_POST, 'openid_url')) ? notags(trim($_POST['openid_url']))   : '');
411         $maxreq           = ((x($_POST, 'maxreq'))     ? intval($_POST['maxreq'])             : 0);
412         $expire           = ((x($_POST, 'expire'))     ? intval($_POST['expire'])             : 0);
413         $def_gid          = ((x($_POST, 'group-selection')) ? intval($_POST['group-selection']) : 0);
414
415
416         $expire_items     = ((x($_POST, 'expire_items')) ? intval($_POST['expire_items'])        : 0);
417         $expire_notes     = ((x($_POST, 'expire_notes')) ? intval($_POST['expire_notes'])        : 0);
418         $expire_starred   = ((x($_POST, 'expire_starred')) ? intval($_POST['expire_starred']) : 0);
419         $expire_photos    = ((x($_POST, 'expire_photos'))? intval($_POST['expire_photos'])       : 0);
420         $expire_network_only    = ((x($_POST, 'expire_network_only'))? intval($_POST['expire_network_only'])     : 0);
421
422         $allow_location   = (((x($_POST, 'allow_location')) && (intval($_POST['allow_location']) == 1)) ? 1: 0);
423         $publish          = (((x($_POST, 'profile_in_directory')) && (intval($_POST['profile_in_directory']) == 1)) ? 1: 0);
424         $net_publish      = (((x($_POST, 'profile_in_netdirectory')) && (intval($_POST['profile_in_netdirectory']) == 1)) ? 1: 0);
425         $old_visibility   = (((x($_POST, 'visibility')) && (intval($_POST['visibility']) == 1)) ? 1 : 0);
426         $account_type     = (((x($_POST, 'account-type')) && (intval($_POST['account-type']))) ? intval($_POST['account-type']) : 0);
427         $page_flags       = (((x($_POST, 'page-flags')) && (intval($_POST['page-flags']))) ? intval($_POST['page-flags']) : 0);
428         $blockwall        = (((x($_POST, 'blockwall')) && (intval($_POST['blockwall']) == 1)) ? 0: 1); // this setting is inverted!
429         $blocktags        = (((x($_POST, 'blocktags')) && (intval($_POST['blocktags']) == 1)) ? 0: 1); // this setting is inverted!
430         $unkmail          = (((x($_POST, 'unkmail')) && (intval($_POST['unkmail']) == 1)) ? 1: 0);
431         $cntunkmail       = ((x($_POST, 'cntunkmail')) ? intval($_POST['cntunkmail']) : 0);
432         $suggestme        = ((x($_POST, 'suggestme')) ? intval($_POST['suggestme'])  : 0);
433         $hide_friends     = (($_POST['hide-friends'] == 1) ? 1: 0);
434         $hidewall         = (($_POST['hidewall'] == 1) ? 1: 0);
435         $post_newfriend   = (($_POST['post_newfriend'] == 1) ? 1: 0);
436         $post_joingroup   = (($_POST['post_joingroup'] == 1) ? 1: 0);
437         $post_profilechange   = (($_POST['post_profilechange'] == 1) ? 1: 0);
438
439         $email_textonly   = (($_POST['email_textonly'] == 1) ? 1 : 0);
440         $detailed_notif   = (($_POST['detailed_notif'] == 1) ? 1 : 0);
441
442         $notify = 0;
443
444         if (x($_POST, 'notify1')) {
445                 $notify += intval($_POST['notify1']);
446         }
447         if (x($_POST, 'notify2')) {
448                 $notify += intval($_POST['notify2']);
449         }
450         if (x($_POST, 'notify3')) {
451                 $notify += intval($_POST['notify3']);
452         }
453         if (x($_POST, 'notify4')) {
454                 $notify += intval($_POST['notify4']);
455         }
456         if (x($_POST, 'notify5')) {
457                 $notify += intval($_POST['notify5']);
458         }
459         if (x($_POST, 'notify6')) {
460                 $notify += intval($_POST['notify6']);
461         }
462         if (x($_POST, 'notify7')) {
463                 $notify += intval($_POST['notify7']);
464         }
465         if (x($_POST, 'notify8')) {
466                 $notify += intval($_POST['notify8']);
467         }
468
469         // Adjust the page flag if the account type doesn't fit to the page flag.
470         if (($account_type == ACCOUNT_TYPE_PERSON) && !in_array($page_flags, [PAGE_NORMAL, PAGE_SOAPBOX, PAGE_FREELOVE])) {
471                 $page_flags = PAGE_NORMAL;
472         } elseif (($account_type == ACCOUNT_TYPE_ORGANISATION) && !in_array($page_flags, [PAGE_SOAPBOX])) {
473                 $page_flags = PAGE_SOAPBOX;
474         } elseif (($account_type == ACCOUNT_TYPE_NEWS) && !in_array($page_flags, [PAGE_SOAPBOX])) {
475                 $page_flags = PAGE_SOAPBOX;
476         } elseif (($account_type == ACCOUNT_TYPE_COMMUNITY) && !in_array($page_flags, [PAGE_COMMUNITY, PAGE_PRVGROUP])) {
477                 $page_flags = PAGE_COMMUNITY;
478         }
479
480         $email_changed = false;
481
482         $err = '';
483
484         $name_change = false;
485
486         if ($username != $a->user['username']) {
487                 $name_change = true;
488                 if (strlen($username) > 40) {
489                         $err .= t(' Please use a shorter name.');
490                 }
491                 if (strlen($username) < 3) {
492                         $err .= t(' Name too short.');
493                 }
494         }
495
496         if ($email != $a->user['email']) {
497                 $email_changed = true;
498                 //  check for the correct password
499                 if (!User::authenticate(intval(local_user()), $_POST['mpassword'])) {
500                         $err .= t('Wrong Password') . EOL;
501                         $email = $a->user['email'];
502                 }
503                 //  check the email is valid
504                 if (!valid_email($email)) {
505                         $err .= t('Invalid email.');
506                 }
507                 //  ensure new email is not the admin mail
508                 //if ((x($a->config, 'admin_email')) && (strcasecmp($email, $a->config['admin_email']) == 0)) {
509                 if (x($a->config, 'admin_email')) {
510                         $adminlist = explode(",", str_replace(" ", "", strtolower($a->config['admin_email'])));
511                         if (in_array(strtolower($email), $adminlist)) {
512                                 $err .= t('Cannot change to that email.');
513                                 $email = $a->user['email'];
514                         }
515                 }
516         }
517
518         if (strlen($err)) {
519                 notice($err . EOL);
520                 return;
521         }
522
523         if (($timezone != $a->user['timezone']) && strlen($timezone)) {
524                 date_default_timezone_set($timezone);
525         }
526
527         $str_group_allow   = perms2str($_POST['group_allow']);
528         $str_contact_allow = perms2str($_POST['contact_allow']);
529         $str_group_deny    = perms2str($_POST['group_deny']);
530         $str_contact_deny  = perms2str($_POST['contact_deny']);
531
532         $openidserver = $a->user['openidserver'];
533         //$openid = normalise_openid($openid);
534
535         // If openid has changed or if there's an openid but no openidserver, try and discover it.
536         if ($openid != $a->user['openid'] || (strlen($openid) && (!strlen($openidserver)))) {
537                 if (validate_url($openid)) {
538                         logger('updating openidserver');
539                         require_once 'library/openid.php';
540                         $open_id_obj = new LightOpenID;
541                         $open_id_obj->identity = $openid;
542                         $openidserver = $open_id_obj->discover($open_id_obj->identity);
543                 } else {
544                         $openidserver = '';
545                 }
546         }
547
548         PConfig::set(local_user(), 'expire', 'items', $expire_items);
549         PConfig::set(local_user(), 'expire', 'notes', $expire_notes);
550         PConfig::set(local_user(), 'expire', 'starred', $expire_starred);
551         PConfig::set(local_user(), 'expire', 'photos', $expire_photos);
552         PConfig::set(local_user(), 'expire', 'network_only', $expire_network_only);
553
554         PConfig::set(local_user(), 'system', 'suggestme', $suggestme);
555         PConfig::set(local_user(), 'system', 'post_newfriend', $post_newfriend);
556         PConfig::set(local_user(), 'system', 'post_joingroup', $post_joingroup);
557         PConfig::set(local_user(), 'system', 'post_profilechange', $post_profilechange);
558
559         PConfig::set(local_user(), 'system', 'email_textonly', $email_textonly);
560         PConfig::set(local_user(), 'system', 'detailed_notif', $detailed_notif);
561
562         if ($page_flags == PAGE_PRVGROUP) {
563                 $hidewall = 1;
564                 if (!$str_contact_allow && !$str_group_allow && !$str_contact_deny && !$str_group_deny) {
565                         if ($def_gid) {
566                                 info(t('Private forum has no privacy permissions. Using default privacy group.'). EOL);
567                                 $str_group_allow = '<' . $def_gid . '>';
568                         } else {
569                                 notice(t('Private forum has no privacy permissions and no default privacy group.') . EOL);
570                         }
571                 }
572         }
573
574
575         $r = q("UPDATE `user` SET `username` = '%s', `email` = '%s',
576                                 `openid` = '%s', `timezone` = '%s',
577                                 `allow_cid` = '%s', `allow_gid` = '%s', `deny_cid` = '%s', `deny_gid` = '%s',
578                                 `notify-flags` = %d, `page-flags` = %d, `account-type` = %d, `default-location` = '%s',
579                                 `allow_location` = %d, `maxreq` = %d, `expire` = %d, `openidserver` = '%s',
580                                 `def_gid` = %d, `blockwall` = %d, `hidewall` = %d, `blocktags` = %d,
581                                 `unkmail` = %d, `cntunkmail` = %d, `language` = '%s'
582                         WHERE `uid` = %d",
583                         dbesc($username),
584                         dbesc($email),
585                         dbesc($openid),
586                         dbesc($timezone),
587                         dbesc($str_contact_allow),
588                         dbesc($str_group_allow),
589                         dbesc($str_contact_deny),
590                         dbesc($str_group_deny),
591                         intval($notify),
592                         intval($page_flags),
593                         intval($account_type),
594                         dbesc($defloc),
595                         intval($allow_location),
596                         intval($maxreq),
597                         intval($expire),
598                         dbesc($openidserver),
599                         intval($def_gid),
600                         intval($blockwall),
601                         intval($hidewall),
602                         intval($blocktags),
603                         intval($unkmail),
604                         intval($cntunkmail),
605                         dbesc($language),
606                         intval(local_user())
607         );
608         if (DBM::is_result($r)) {
609                 info(t('Settings updated.') . EOL);
610         }
611
612         // clear session language
613         unset($_SESSION['language']);
614
615         $r = q("UPDATE `profile`
616                 SET `publish` = %d,
617                 `name` = '%s',
618                 `net-publish` = %d,
619                 `hide-friends` = %d
620                 WHERE `is-default` = 1 AND `uid` = %d",
621                 intval($publish),
622                 dbesc($username),
623                 intval($net_publish),
624                 intval($hide_friends),
625                 intval(local_user())
626         );
627
628
629         if ($name_change) {
630                 q("UPDATE `contact` SET `name` = '%s', `name-date` = '%s' WHERE `uid` = %d AND `self`",
631                         dbesc($username),
632                         dbesc(datetime_convert()),
633                         intval(local_user())
634                 );
635         }
636
637         if (($old_visibility != $net_publish) || ($page_flags != $old_page_flags)) {
638                 // Update global directory in background
639                 $url = $_SESSION['my_url'];
640                 if ($url && strlen(Config::get('system', 'directory'))) {
641                         Worker::add(PRIORITY_LOW, "Directory", $url);
642                 }
643         }
644
645         Worker::add(PRIORITY_LOW, 'ProfileUpdate', local_user());
646
647         // Update the global contact for the user
648         GContact::updateForUser(local_user());
649
650         goaway('settings');
651         return; // NOTREACHED
652 }
653
654
655 function settings_content(App $a)
656 {
657         $o = '';
658         Nav::setSelected('settings');
659
660         if (!local_user()) {
661                 //notice(t('Permission denied.') . EOL);
662                 return;
663         }
664
665         if (x($_SESSION, 'submanage') && intval($_SESSION['submanage'])) {
666                 notice(t('Permission denied.') . EOL);
667                 return;
668         }
669
670         if (($a->argc > 1) && ($a->argv[1] === 'oauth')) {
671                 if (($a->argc > 2) && ($a->argv[2] === 'add')) {
672                         $tpl = get_markup_template('settings/oauth_edit.tpl');
673                         $o .= replace_macros($tpl, [
674                                 '$form_security_token' => get_form_security_token("settings_oauth"),
675                                 '$title'        => t('Add application'),
676                                 '$submit'       => t('Save Settings'),
677                                 '$cancel'       => t('Cancel'),
678                                 '$name'         => ['name', t('Name'), '', ''],
679                                 '$key'          => ['key', t('Consumer Key'), '', ''],
680                                 '$secret'       => ['secret', t('Consumer Secret'), '', ''],
681                                 '$redirect'     => ['redirect', t('Redirect'), '', ''],
682                                 '$icon'         => ['icon', t('Icon url'), '', ''],
683                         ]);
684                         return $o;
685                 }
686
687                 if (($a->argc > 3) && ($a->argv[2] === 'edit')) {
688                         $r = q("SELECT * FROM clients WHERE client_id='%s' AND uid=%d",
689                                         dbesc($a->argv[3]),
690                                         local_user());
691
692                         if (!DBM::is_result($r)) {
693                                 notice(t("You can't edit this application."));
694                                 return;
695                         }
696                         $app = $r[0];
697
698                         $tpl = get_markup_template('settings/oauth_edit.tpl');
699                         $o .= replace_macros($tpl, [
700                                 '$form_security_token' => get_form_security_token("settings_oauth"),
701                                 '$title'        => t('Add application'),
702                                 '$submit'       => t('Update'),
703                                 '$cancel'       => t('Cancel'),
704                                 '$name'         => ['name', t('Name'), $app['name'] , ''],
705                                 '$key'          => ['key', t('Consumer Key'), $app['client_id'], ''],
706                                 '$secret'       => ['secret', t('Consumer Secret'), $app['pw'], ''],
707                                 '$redirect'     => ['redirect', t('Redirect'), $app['redirect_uri'], ''],
708                                 '$icon'         => ['icon', t('Icon url'), $app['icon'], ''],
709                         ]);
710                         return $o;
711                 }
712
713                 if (($a->argc > 3) && ($a->argv[2] === 'delete')) {
714                         check_form_security_token_redirectOnErr('/settings/oauth', 'settings_oauth', 't');
715
716                         q("DELETE FROM clients WHERE client_id='%s' AND uid=%d",
717                                         dbesc($a->argv[3]),
718                                         local_user());
719                         goaway(System::baseUrl(true)."/settings/oauth/");
720                         return;
721                 }
722
723                 /// @TODO validate result with DBM::is_result()
724                 $r = q("SELECT clients.*, tokens.id as oauth_token, (clients.uid=%d) AS my
725                                 FROM clients
726                                 LEFT JOIN tokens ON clients.client_id=tokens.client_id
727                                 WHERE clients.uid IN (%d, 0)",
728                                 local_user(),
729                                 local_user());
730
731
732                 $tpl = get_markup_template('settings/oauth.tpl');
733                 $o .= replace_macros($tpl, [
734                         '$form_security_token' => get_form_security_token("settings_oauth"),
735                         '$baseurl'      => System::baseUrl(true),
736                         '$title'        => t('Connected Apps'),
737                         '$add'          => t('Add application'),
738                         '$edit'         => t('Edit'),
739                         '$delete'               => t('Delete'),
740                         '$consumerkey' => t('Client key starts with'),
741                         '$noname'       => t('No name'),
742                         '$remove'       => t('Remove authorization'),
743                         '$apps'         => $r,
744                 ]);
745                 return $o;
746         }
747
748         if (($a->argc > 1) && ($a->argv[1] === 'addon')) {
749                 $settings_addons = "";
750
751                 $r = q("SELECT * FROM `hook` WHERE `hook` = 'addon_settings' ");
752                 if (!DBM::is_result($r)) {
753                         $settings_addons = t('No Addon settings configured');
754                 }
755
756                 Addon::callHooks('addon_settings', $settings_addons);
757
758
759                 $tpl = get_markup_template('settings/addons.tpl');
760                 $o .= replace_macros($tpl, [
761                         '$form_security_token' => get_form_security_token("settings_addon"),
762                         '$title'        => t('Addon Settings'),
763                         '$settings_addons' => $settings_addons
764                 ]);
765                 return $o;
766         }
767
768         if (($a->argc > 1) && ($a->argv[1] === 'features')) {
769
770                 $arr = [];
771                 $features = Feature::get();
772                 foreach ($features as $fname => $fdata) {
773                         $arr[$fname] = [];
774                         $arr[$fname][0] = $fdata[0];
775                         foreach (array_slice($fdata,1) as $f) {
776                                 $arr[$fname][1][] = ['feature_' .$f[0], $f[1],((intval(Feature::isEnabled(local_user(), $f[0]))) ? "1" : ''), $f[2],[t('Off'), t('On')]];
777                         }
778                 }
779
780                 $tpl = get_markup_template('settings/features.tpl');
781                 $o .= replace_macros($tpl, [
782                         '$form_security_token' => get_form_security_token("settings_features"),
783                         '$title'               => t('Additional Features'),
784                         '$features'            => $arr,
785                         '$submit'              => t('Save Settings'),
786                 ]);
787                 return $o;
788         }
789
790         if (($a->argc > 1) && ($a->argv[1] === 'connectors')) {
791                 $no_intelligent_shortening = intval(PConfig::get(local_user(), 'system', 'no_intelligent_shortening'));
792                 $ostatus_autofriend        = intval(PConfig::get(local_user(), 'system', 'ostatus_autofriend'));
793                 $default_group             = PConfig::get(local_user(), 'ostatus', 'default_group');
794                 $legacy_contact            = PConfig::get(local_user(), 'ostatus', 'legacy_contact');
795
796                 if (x($legacy_contact)) {
797                         /// @todo Isn't it supposed to be a goaway() call?
798                         $a->page['htmlhead'] = '<meta http-equiv="refresh" content="0; URL=' . System::baseUrl().'/ostatus_subscribe?url=' . urlencode($legacy_contact) . '">';
799                 }
800
801                 $settings_connectors = '';
802                 Addon::callHooks('connector_settings', $settings_connectors);
803
804                 if (is_site_admin()) {
805                         $diasp_enabled = t('Built-in support for %s connectivity is %s', t('Diaspora'), ((Config::get('system', 'diaspora_enabled')) ? t('enabled') : t('disabled')));
806                         $ostat_enabled = t('Built-in support for %s connectivity is %s', t('GNU Social (OStatus)'), ((Config::get('system', 'ostatus_disabled')) ? t('disabled') : t('enabled')));
807                 } else {
808                         $diasp_enabled = "";
809                         $ostat_enabled = "";
810                 }
811
812                 $mail_disabled = ((function_exists('imap_open') && (!Config::get('system', 'imap_disabled'))) ? 0 : 1);
813                 if (Config::get('system', 'dfrn_only')) {
814                         $mail_disabled = 1;
815                 }
816                 if (!$mail_disabled) {
817                         $r = q("SELECT * FROM `mailacct` WHERE `uid` = %d LIMIT 1",
818                                 local_user()
819                         );
820                 } else {
821                         $r = null;
822                 }
823
824                 $mail_server       = ((DBM::is_result($r)) ? $r[0]['server'] : '');
825                 $mail_port         = ((DBM::is_result($r) && intval($r[0]['port'])) ? intval($r[0]['port']) : '');
826                 $mail_ssl          = ((DBM::is_result($r)) ? $r[0]['ssltype'] : '');
827                 $mail_user         = ((DBM::is_result($r)) ? $r[0]['user'] : '');
828                 $mail_replyto      = ((DBM::is_result($r)) ? $r[0]['reply_to'] : '');
829                 $mail_pubmail      = ((DBM::is_result($r)) ? $r[0]['pubmail'] : 0);
830                 $mail_action       = ((DBM::is_result($r)) ? $r[0]['action'] : 0);
831                 $mail_movetofolder = ((DBM::is_result($r)) ? $r[0]['movetofolder'] : '');
832                 $mail_chk          = ((DBM::is_result($r)) ? $r[0]['last_check'] : NULL_DATE);
833
834
835                 $tpl = get_markup_template('settings/connectors.tpl');
836
837                 $mail_disabled_message = (($mail_disabled) ? t('Email access is disabled on this site.') : '');
838
839                 $o .= replace_macros($tpl, [
840                         '$form_security_token' => get_form_security_token("settings_connectors"),
841
842                         '$title'        => t('Social Networks'),
843
844                         '$diasp_enabled' => $diasp_enabled,
845                         '$ostat_enabled' => $ostat_enabled,
846
847                         '$general_settings' => t('General Social Media Settings'),
848                         '$no_intelligent_shortening' => ['no_intelligent_shortening', t('Disable intelligent shortening'), $no_intelligent_shortening, t('Normally the system tries to find the best link to add to shortened posts. If this option is enabled then every shortened post will always point to the original friendica post.')],
849                         '$ostatus_autofriend' => ['snautofollow', t('Automatically follow any GNU Social (OStatus) followers/mentioners'), $ostatus_autofriend, t('If you receive a message from an unknown OStatus user, this option decides what to do. If it is checked, a new contact will be created for every unknown user.')],
850                         '$default_group' => Group::displayGroupSelection(local_user(), $default_group, t("Default group for OStatus contacts")),
851                         '$legacy_contact' => ['legacy_contact', t('Your legacy GNU Social account'), $legacy_contact, t('If you enter your old GNU Social/Statusnet account name here (in the format user@domain.tld), your contacts will be added automatically. The field will be emptied when done.')],
852
853                         '$repair_ostatus_url' => System::baseUrl() . '/repair_ostatus',
854                         '$repair_ostatus_text' => t('Repair OStatus subscriptions'),
855
856                         '$settings_connectors' => $settings_connectors,
857
858                         '$h_imap' => t('Email/Mailbox Setup'),
859                         '$imap_desc' => t("If you wish to communicate with email contacts using this service \x28optional\x29, please specify how to connect to your mailbox."),
860                         '$imap_lastcheck' => ['imap_lastcheck', t('Last successful email check:'), $mail_chk, ''],
861                         '$mail_disabled' => $mail_disabled_message,
862                         '$mail_server'  => ['mail_server',  t('IMAP server name:'), $mail_server, ''],
863                         '$mail_port'    => ['mail_port',         t('IMAP port:'), $mail_port, ''],
864                         '$mail_ssl'             => ['mail_ssl',          t('Security:'), strtoupper($mail_ssl), '', ['notls'=>t('None'), 'TLS'=>'TLS', 'SSL'=>'SSL']],
865                         '$mail_user'    => ['mail_user',    t('Email login name:'), $mail_user, ''],
866                         '$mail_pass'    => ['mail_pass',         t('Email password:'), '', ''],
867                         '$mail_replyto' => ['mail_replyto', t('Reply-to address:'), $mail_replyto, 'Optional'],
868                         '$mail_pubmail' => ['mail_pubmail', t('Send public posts to all email contacts:'), $mail_pubmail, ''],
869                         '$mail_action'  => ['mail_action',       t('Action after import:'), $mail_action, '', [0=>t('None'), /*1=>t('Delete'),*/ 2=>t('Mark as seen'), 3=>t('Move to folder')]],
870                         '$mail_movetofolder'    => ['mail_movetofolder',         t('Move to folder:'), $mail_movetofolder, ''],
871                         '$submit' => t('Save Settings'),
872                 ]);
873
874                 Addon::callHooks('display_settings', $o);
875                 return $o;
876         }
877
878         /*
879          * DISPLAY SETTINGS
880          */
881         if (($a->argc > 1) && ($a->argv[1] === 'display')) {
882                 $default_theme = Config::get('system', 'theme');
883                 if (!$default_theme) {
884                         $default_theme = 'default';
885                 }
886                 $default_mobile_theme = Config::get('system', 'mobile-theme');
887                 if (!$default_mobile_theme) {
888                         $default_mobile_theme = 'none';
889                 }
890
891                 $allowed_themes_str = Config::get('system', 'allowed_themes');
892                 $allowed_themes_raw = explode(',', $allowed_themes_str);
893                 $allowed_themes = [];
894                 if (count($allowed_themes_raw)) {
895                         foreach ($allowed_themes_raw as $x) {
896                                 if (strlen(trim($x)) && is_dir("view/theme/$x")) {
897                                         $allowed_themes[] = trim($x);
898                                 }
899                         }
900                 }
901
902
903                 $themes = [];
904                 $mobile_themes = ["---" => t('No special theme for mobile devices')];
905                 if ($allowed_themes) {
906                         foreach ($allowed_themes as $theme) {
907                                 $is_experimental = file_exists('view/theme/' . $theme . '/experimental');
908                                 $is_unsupported  = file_exists('view/theme/' . $theme . '/unsupported');
909                                 $is_mobile       = file_exists('view/theme/' . $theme . '/mobile');
910                                 if (!$is_experimental || ($is_experimental && (Config::get('experimentals', 'exp_themes')==1 || is_null(Config::get('experimentals', 'exp_themes'))))) {
911                                         $theme_name = ucfirst($theme);
912                                         if ($is_unsupported) {
913                                                 $theme_name = t("%s - (Unsupported)", $theme_name);
914                                         } elseif ($is_experimental) {
915                                                 $theme_name = t("%s - (Experimental)", $theme_name);
916                                         }
917                                         if ($is_mobile) {
918                                                 $mobile_themes[$theme] = $theme_name;
919                                         } else {
920                                                 $themes[$theme] = $theme_name;
921                                         }
922                                 }
923                         }
924                 }
925                 $theme_selected        = defaults($_SESSION, 'theme'       , $default_theme);
926                 $mobile_theme_selected = defaults($_SESSION, 'mobile-theme', $default_mobile_theme);
927
928                 $nowarn_insecure = intval(PConfig::get(local_user(), 'system', 'nowarn_insecure'));
929
930                 $browser_update = intval(PConfig::get(local_user(), 'system', 'update_interval'));
931                 if (intval($browser_update) != -1) {
932                         $browser_update = (($browser_update == 0) ? 40 : $browser_update / 1000); // default if not set: 40 seconds
933                 }
934
935                 $itemspage_network = intval(PConfig::get(local_user(), 'system', 'itemspage_network'));
936                 $itemspage_network = (($itemspage_network > 0 && $itemspage_network < 101) ? $itemspage_network : 40); // default if not set: 40 items
937                 $itemspage_mobile_network = intval(PConfig::get(local_user(), 'system', 'itemspage_mobile_network'));
938                 $itemspage_mobile_network = (($itemspage_mobile_network > 0 && $itemspage_mobile_network < 101) ? $itemspage_mobile_network : 20); // default if not set: 20 items
939
940                 $nosmile = PConfig::get(local_user(), 'system', 'no_smilies', 0);
941                 $first_day_of_week = PConfig::get(local_user(), 'system', 'first_day_of_week', 0);
942                 $weekdays = [0 => t("Sunday"), 1 => t("Monday")];
943
944                 $noinfo = PConfig::get(local_user(), 'system', 'ignore_info', 0);
945                 $infinite_scroll = PConfig::get(local_user(), 'system', 'infinite_scroll', 0);
946                 $no_auto_update = PConfig::get(local_user(), 'system', 'no_auto_update', 0);
947                 $bandwidth_saver = PConfig::get(local_user(), 'system', 'bandwidth_saver', 0);
948                 $smart_threading = PConfig::get(local_user(), 'system', 'smart_threading', 0);
949
950                 $theme_config = "";
951                 if (($themeconfigfile = get_theme_config_file($theme_selected)) !== null) {
952                         require_once $themeconfigfile;
953                         $theme_config = theme_content($a);
954                 }
955
956                 $tpl = get_markup_template('settings/display.tpl');
957                 $o = replace_macros($tpl, [
958                         '$ptitle'       => t('Display Settings'),
959                         '$form_security_token' => get_form_security_token("settings_display"),
960                         '$submit'       => t('Save Settings'),
961                         '$baseurl' => System::baseUrl(true),
962                         '$uid' => local_user(),
963
964                         '$theme'        => ['theme', t('Display Theme:'), $theme_selected, '', $themes, true],
965                         '$mobile_theme' => ['mobile_theme', t('Mobile Theme:'), $mobile_theme_selected, '', $mobile_themes, false],
966                         '$nowarn_insecure' => ['nowarn_insecure',  t('Suppress warning of insecure networks'), $nowarn_insecure, t("Should the system suppress the warning that the current group contains members of networks that can't receive non public postings.")],
967                         '$ajaxint'   => ['browser_update',  t("Update browser every xx seconds"), $browser_update, t('Minimum of 10 seconds. Enter -1 to disable it.')],
968                         '$itemspage_network'   => ['itemspage_network',  t("Number of items to display per page:"), $itemspage_network, t('Maximum of 100 items')],
969                         '$itemspage_mobile_network'   => ['itemspage_mobile_network',  t("Number of items to display per page when viewed from mobile device:"), $itemspage_mobile_network, t('Maximum of 100 items')],
970                         '$nosmile'      => ['nosmile', t("Don't show emoticons"), $nosmile, ''],
971                         '$calendar_title' => t('Calendar'),
972                         '$first_day_of_week'    => ['first_day_of_week', t('Beginning of week:'), $first_day_of_week, '', $weekdays, false],
973                         '$noinfo'       => ['noinfo', t("Don't show notices"), $noinfo, ''],
974                         '$infinite_scroll'      => ['infinite_scroll', t("Infinite scroll"), $infinite_scroll, ''],
975                         '$no_auto_update'       => ['no_auto_update', t("Automatic updates only at the top of the network page"), $no_auto_update, t('When disabled, the network page is updated all the time, which could be confusing while reading.')],
976                         '$bandwidth_saver' => ['bandwidth_saver', t('Bandwith Saver Mode'), $bandwidth_saver, t('When enabled, embedded content is not displayed on automatic updates, they only show on page reload.')],
977                         '$smart_threading' => ['smart_threading', t('Smart Threading'), $smart_threading, t('When enabled, suppress extraneous thread indentation while keeping it where it matters. Only works if threading is available and enabled.')],
978
979                         '$d_tset' => t('General Theme Settings'),
980                         '$d_ctset' => t('Custom Theme Settings'),
981                         '$d_cset' => t('Content Settings'),
982                         'stitle' => t('Theme settings'),
983                         '$theme_config' => $theme_config,
984                 ]);
985
986                 $tpl = get_markup_template('settings/display_end.tpl');
987                 $a->page['end'] .= replace_macros($tpl, [
988                         '$theme'        => ['theme', t('Display Theme:'), $theme_selected, '', $themes]
989                 ]);
990
991                 return $o;
992         }
993
994
995         /*
996          * ACCOUNT SETTINGS
997          */
998
999         require_once('include/acl_selectors.php');
1000
1001         $profile = dba::selectFirst('profile', [], ['is-default' => true, 'uid' => local_user()]);
1002         if (!DBM::is_result($profile)) {
1003                 notice(t('Unable to find your profile. Please contact your admin.') . EOL);
1004                 return;
1005         }
1006
1007         $username   = $a->user['username'];
1008         $email      = $a->user['email'];
1009         $nickname   = $a->user['nickname'];
1010         $timezone   = $a->user['timezone'];
1011         $language   = $a->user['language'];
1012         $notify     = $a->user['notify-flags'];
1013         $defloc     = $a->user['default-location'];
1014         $openid     = $a->user['openid'];
1015         $maxreq     = $a->user['maxreq'];
1016         $expire     = ((intval($a->user['expire'])) ? $a->user['expire'] : '');
1017         $unkmail    = $a->user['unkmail'];
1018         $cntunkmail = $a->user['cntunkmail'];
1019
1020         $expire_items = PConfig::get(local_user(), 'expire', 'items', true);
1021         $expire_notes = PConfig::get(local_user(), 'expire', 'notes', true);
1022         $expire_starred = PConfig::get(local_user(), 'expire', 'starred', true);
1023         $expire_photos = PConfig::get(local_user(), 'expire', 'photos', false);
1024         $expire_network_only = PConfig::get(local_user(), 'expire', 'network_only', false);
1025         $suggestme = PConfig::get(local_user(), 'system', 'suggestme', false);
1026         $post_newfriend = PConfig::get(local_user(), 'system', 'post_newfriend', false);
1027         $post_joingroup = PConfig::get(local_user(), 'system', 'post_joingroup', false);
1028         $post_profilechange = PConfig::get(local_user(), 'system', 'post_profilechange', false);
1029
1030         // nowarn_insecure
1031
1032         if (!strlen($a->user['timezone'])) {
1033                 $timezone = date_default_timezone_get();
1034         }
1035
1036         // Set the account type to "Community" when the page is a community page but the account type doesn't fit
1037         // This is only happening on the first visit after the update
1038         if (in_array($a->user['page-flags'], [PAGE_COMMUNITY, PAGE_PRVGROUP]) &&
1039                 ($a->user['account-type'] != ACCOUNT_TYPE_COMMUNITY))
1040                 $a->user['account-type'] = ACCOUNT_TYPE_COMMUNITY;
1041
1042         $pageset_tpl = get_markup_template('settings/pagetypes.tpl');
1043
1044         $pagetype = replace_macros($pageset_tpl, [
1045                 '$account_types'        => t("Account Types"),
1046                 '$user'                 => t("Personal Page Subtypes"),
1047                 '$community'            => t("Community Forum Subtypes"),
1048                 '$account_type'         => $a->user['account-type'],
1049                 '$type_person'          => ACCOUNT_TYPE_PERSON,
1050                 '$type_organisation'    => ACCOUNT_TYPE_ORGANISATION,
1051                 '$type_news'            => ACCOUNT_TYPE_NEWS,
1052                 '$type_community'       => ACCOUNT_TYPE_COMMUNITY,
1053
1054                 '$account_person'       => ['account-type', t('Personal Page'), ACCOUNT_TYPE_PERSON,
1055                                                                         t('Account for a personal profile.'),
1056                                                                         ($a->user['account-type'] == ACCOUNT_TYPE_PERSON)],
1057
1058                 '$account_organisation' => ['account-type', t('Organisation Page'), ACCOUNT_TYPE_ORGANISATION,
1059                                                                         t('Account for an organisation that automatically approves contact requests as "Followers".'),
1060                                                                         ($a->user['account-type'] == ACCOUNT_TYPE_ORGANISATION)],
1061
1062                 '$account_news'         => ['account-type', t('News Page'), ACCOUNT_TYPE_NEWS,
1063                                                                         t('Account for a news reflector that automatically approves contact requests as "Followers".'),
1064                                                                         ($a->user['account-type'] == ACCOUNT_TYPE_NEWS)],
1065
1066                 '$account_community'    => ['account-type', t('Community Forum'), ACCOUNT_TYPE_COMMUNITY,
1067                                                                         t('Account for community discussions.'),
1068                                                                         ($a->user['account-type'] == ACCOUNT_TYPE_COMMUNITY)],
1069
1070                 '$page_normal'          => ['page-flags', t('Normal Account Page'), PAGE_NORMAL,
1071                                                                         t('Account for a regular personal profile that requires manual approval of "Friends" and "Followers".'),
1072                                                                         ($a->user['page-flags'] == PAGE_NORMAL)],
1073
1074                 '$page_soapbox'         => ['page-flags', t('Soapbox Page'), PAGE_SOAPBOX,
1075                                                                         t('Account for a public profile that automatically approves contact requests as "Followers".'),
1076                                                                         ($a->user['page-flags'] == PAGE_SOAPBOX)],
1077
1078                 '$page_community'       => ['page-flags', t('Public Forum'), PAGE_COMMUNITY,
1079                                                                         t('Automatically approves all contact requests.'),
1080                                                                         ($a->user['page-flags'] == PAGE_COMMUNITY)],
1081
1082                 '$page_freelove'        => ['page-flags', t('Automatic Friend Page'), PAGE_FREELOVE,
1083                                                                         t('Account for a popular profile that automatically approves contact requests as "Friends".'),
1084                                                                         ($a->user['page-flags'] == PAGE_FREELOVE)],
1085
1086                 '$page_prvgroup'        => ['page-flags', t('Private Forum [Experimental]'), PAGE_PRVGROUP,
1087                                                                         t('Requires manual approval of contact requests.'),
1088                                                                         ($a->user['page-flags'] == PAGE_PRVGROUP)],
1089
1090
1091         ]);
1092
1093         $noid = Config::get('system', 'no_openid');
1094
1095         if ($noid) {
1096                 $openid_field = false;
1097         } else {
1098                 $openid_field = ['openid_url', t('OpenID:'), $openid, t("\x28Optional\x29 Allow this OpenID to login to this account."), "", "", "url"];
1099         }
1100
1101         $opt_tpl = get_markup_template("field_yesno.tpl");
1102         if (Config::get('system', 'publish_all')) {
1103                 $profile_in_dir = '<input type="hidden" name="profile_in_directory" value="1" />';
1104         } else {
1105                 $profile_in_dir = replace_macros($opt_tpl, [
1106                         '$field' => ['profile_in_directory', t('Publish your default profile in your local site directory?'), $profile['publish'], t("Your profile may be visible in public."), [t('No'), t('Yes')]]
1107                 ]);
1108         }
1109
1110         if (strlen(Config::get('system', 'directory'))) {
1111                 $profile_in_net_dir = replace_macros($opt_tpl, [
1112                         '$field' => ['profile_in_netdirectory', t('Publish your default profile in the global social directory?'), $profile['net-publish'], '', [t('No'), t('Yes')]]
1113                 ]);
1114         } else {
1115                 $profile_in_net_dir = '';
1116         }
1117
1118         $hide_friends = replace_macros($opt_tpl, [
1119                 '$field' => ['hide-friends', t('Hide your contact/friend list from viewers of your default profile?'), $profile['hide-friends'], '', [t('No'), t('Yes')]],
1120         ]);
1121
1122         $hide_wall = replace_macros($opt_tpl, [
1123                 '$field' => ['hidewall', t('Hide your profile details from unknown viewers?'), $a->user['hidewall'], t("If enabled, posting public messages to Diaspora and other networks isn't possible."), [t('No'), t('Yes')]],
1124         ]);
1125
1126         $blockwall = replace_macros($opt_tpl, [
1127                 '$field' => ['blockwall', t('Allow friends to post to your profile page?'), (intval($a->user['blockwall']) ? '0' : '1'), '', [t('No'), t('Yes')]],
1128         ]);
1129
1130         $blocktags = replace_macros($opt_tpl, [
1131                 '$field' => ['blocktags', t('Allow friends to tag your posts?'), (intval($a->user['blocktags']) ? '0' : '1'), '', [t('No'), t('Yes')]],
1132         ]);
1133
1134         $suggestme = replace_macros($opt_tpl, [
1135                 '$field' => ['suggestme', t('Allow us to suggest you as a potential friend to new members?'), $suggestme, '', [t('No'), t('Yes')]],
1136         ]);
1137
1138         $unkmail = replace_macros($opt_tpl, [
1139                 '$field' => ['unkmail', t('Permit unknown people to send you private mail?'), $unkmail, '', [t('No'), t('Yes')]],
1140         ]);
1141
1142         if (!$profile['publish'] && !$profile['net-publish']) {
1143                 info(t('Profile is <strong>not published</strong>.') . EOL);
1144         }
1145
1146         $tpl_addr = get_markup_template('settings/nick_set.tpl');
1147
1148         $prof_addr = replace_macros($tpl_addr,[
1149                 '$desc' => t("Your Identity Address is <strong>'%s'</strong> or '%s'.", $nickname . '@' . $a->get_hostname() . $a->get_path(), System::baseUrl() . '/profile/' . $nickname),
1150                 '$basepath' => $a->get_hostname()
1151         ]);
1152
1153         $stpl = get_markup_template('settings/settings.tpl');
1154
1155         $expire_arr = [
1156                 'days' => ['expire',  t("Automatically expire posts after this many days:"), $expire, t('If empty, posts will not expire. Expired posts will be deleted')],
1157                 'advanced' => t('Advanced expiration settings'),
1158                 'label' => t('Advanced Expiration'),
1159                 'items' => ['expire_items',  t("Expire posts:"), $expire_items, '', [t('No'), t('Yes')]],
1160                 'notes' => ['expire_notes',  t("Expire personal notes:"), $expire_notes, '', [t('No'), t('Yes')]],
1161                 'starred' => ['expire_starred',  t("Expire starred posts:"), $expire_starred, '', [t('No'), t('Yes')]],
1162                 'photos' => ['expire_photos',  t("Expire photos:"), $expire_photos, '', [t('No'), t('Yes')]],
1163                 'network_only' => ['expire_network_only',  t("Only expire posts by others:"), $expire_network_only, '', [t('No'), t('Yes')]],
1164         ];
1165
1166         $group_select = Group::displayGroupSelection(local_user(), $a->user['def_gid']);
1167
1168         // Private/public post links for the non-JS ACL form
1169         $private_post = 1;
1170         if ($_REQUEST['public']) {
1171                 $private_post = 0;
1172         }
1173
1174         $query_str = $a->query_string;
1175         if (strpos($query_str, 'public=1') !== false) {
1176                 $query_str = str_replace(['?public=1', '&public=1'], ['', ''], $query_str);
1177         }
1178
1179         // I think $a->query_string may never have ? in it, but I could be wrong
1180         // It looks like it's from the index.php?q=[etc] rewrite that the web
1181         // server does, which converts any ? to &, e.g. suggest&ignore=61 for suggest?ignore=61
1182         if (strpos($query_str, '?') === false) {
1183                 $public_post_link = '?public=1';
1184         } else {
1185                 $public_post_link = '&public=1';
1186         }
1187
1188         /* Installed langs */
1189         $lang_choices = get_available_languages();
1190
1191         /// @TODO Fix indending (or so)
1192         $o .= replace_macros($stpl, [
1193                 '$ptitle'       => t('Account Settings'),
1194
1195                 '$submit'       => t('Save Settings'),
1196                 '$baseurl' => System::baseUrl(true),
1197                 '$uid' => local_user(),
1198                 '$form_security_token' => get_form_security_token("settings"),
1199                 '$nickname_block' => $prof_addr,
1200
1201                 '$h_pass'       => t('Password Settings'),
1202                 '$password1'=> ['password', t('New Password:'), '', ''],
1203                 '$password2'=> ['confirm', t('Confirm:'), '', t('Leave password fields blank unless changing')],
1204                 '$password3'=> ['opassword', t('Current Password:'), '', t('Your current password to confirm the changes')],
1205                 '$password4'=> ['mpassword', t('Password:'), '', t('Your current password to confirm the changes')],
1206                 '$oid_enable' => (!Config::get('system', 'no_openid')),
1207                 '$openid'       => $openid_field,
1208
1209                 '$h_basic'      => t('Basic Settings'),
1210                 '$username' => ['username',  t('Full Name:'), $username, ''],
1211                 '$email'        => ['email', t('Email Address:'), $email, '', '', '', 'email'],
1212                 '$timezone' => ['timezone_select' , t('Your Timezone:'), select_timezone($timezone), ''],
1213                 '$language' => ['language', t('Your Language:'), $language, t('Set the language we use to show you friendica interface and to send you emails'), $lang_choices],
1214                 '$defloc'       => ['defloc', t('Default Post Location:'), $defloc, ''],
1215                 '$allowloc' => ['allow_location', t('Use Browser Location:'), ($a->user['allow_location'] == 1), ''],
1216
1217
1218                 '$h_prv'        => t('Security and Privacy Settings'),
1219
1220                 '$maxreq'       => ['maxreq', t('Maximum Friend Requests/Day:'), $maxreq , t("\x28to prevent spam abuse\x29")],
1221                 '$permissions' => t('Default Post Permissions'),
1222                 '$permdesc' => t("\x28click to open/close\x29"),
1223                 '$visibility' => $profile['net-publish'],
1224                 '$aclselect' => populate_acl($a->user),
1225                 '$suggestme' => $suggestme,
1226                 '$blockwall'=> $blockwall, // array('blockwall', t('Allow friends to post to your profile page:'), !$blockwall, ''),
1227                 '$blocktags'=> $blocktags, // array('blocktags', t('Allow friends to tag your posts:'), !$blocktags, ''),
1228
1229                 // ACL permissions box
1230                 '$group_perms' => t('Show to Groups'),
1231                 '$contact_perms' => t('Show to Contacts'),
1232                 '$private' => t('Default Private Post'),
1233                 '$public' => t('Default Public Post'),
1234                 '$is_private' => $private_post,
1235                 '$return_path' => $query_str,
1236                 '$public_link' => $public_post_link,
1237                 '$settings_perms' => t('Default Permissions for New Posts'),
1238
1239                 '$group_select' => $group_select,
1240
1241
1242                 '$expire'       => $expire_arr,
1243
1244                 '$profile_in_dir' => $profile_in_dir,
1245                 '$profile_in_net_dir' => $profile_in_net_dir,
1246                 '$hide_friends' => $hide_friends,
1247                 '$hide_wall' => $hide_wall,
1248                 '$unkmail' => $unkmail,
1249                 '$cntunkmail'   => ['cntunkmail', t('Maximum private messages per day from unknown people:'), $cntunkmail , t("\x28to prevent spam abuse\x29")],
1250
1251
1252                 '$h_not'        => t('Notification Settings'),
1253                 '$activity_options' => t('By default post a status message when:'),
1254                 '$post_newfriend' => ['post_newfriend',  t('accepting a friend request'), $post_newfriend, ''],
1255                 '$post_joingroup' => ['post_joingroup',  t('joining a forum/community'), $post_joingroup, ''],
1256                 '$post_profilechange' => ['post_profilechange',  t('making an <em>interesting</em> profile change'), $post_profilechange, ''],
1257                 '$lbl_not'      => t('Send a notification email when:'),
1258                 '$notify1'      => ['notify1', t('You receive an introduction'), ($notify & NOTIFY_INTRO), NOTIFY_INTRO, ''],
1259                 '$notify2'      => ['notify2', t('Your introductions are confirmed'), ($notify & NOTIFY_CONFIRM), NOTIFY_CONFIRM, ''],
1260                 '$notify3'      => ['notify3', t('Someone writes on your profile wall'), ($notify & NOTIFY_WALL), NOTIFY_WALL, ''],
1261                 '$notify4'      => ['notify4', t('Someone writes a followup comment'), ($notify & NOTIFY_COMMENT), NOTIFY_COMMENT, ''],
1262                 '$notify5'      => ['notify5', t('You receive a private message'), ($notify & NOTIFY_MAIL), NOTIFY_MAIL, ''],
1263                 '$notify6'  => ['notify6', t('You receive a friend suggestion'), ($notify & NOTIFY_SUGGEST), NOTIFY_SUGGEST, ''],
1264                 '$notify7'  => ['notify7', t('You are tagged in a post'), ($notify & NOTIFY_TAGSELF), NOTIFY_TAGSELF, ''],
1265                 '$notify8'  => ['notify8', t('You are poked/prodded/etc. in a post'), ($notify & NOTIFY_POKE), NOTIFY_POKE, ''],
1266
1267                 '$desktop_notifications' => ['desktop_notifications', t('Activate desktop notifications') , false, t('Show desktop popup on new notifications')],
1268
1269                 '$email_textonly' => ['email_textonly', t('Text-only notification emails'),
1270                                                                         PConfig::get(local_user(), 'system', 'email_textonly'),
1271                                                                         t('Send text only notification emails, without the html part')],
1272
1273                 '$detailed_notif' => ['detailed_notif', t('Show detailled notifications'),
1274                                                                         PConfig::get(local_user(), 'system', 'detailed_notif'),
1275                                                                         t('Per default the notificiation are condensed to a single notification per item. When enabled, every notification is displayed.')],
1276
1277                 '$h_advn' => t('Advanced Account/Page Type Settings'),
1278                 '$h_descadvn' => t('Change the behaviour of this account for special situations'),
1279                 '$pagetype' => $pagetype,
1280
1281                 '$relocate' => t('Relocate'),
1282                 '$relocate_text' => t("If you have moved this profile from another server, and some of your contacts don't receive your updates, try pushing this button."),
1283                 '$relocate_button' => t("Resend relocate message to contacts"),
1284
1285         ]);
1286
1287         Addon::callHooks('settings_form', $o);
1288
1289         $o .= '</form>' . "\r\n";
1290
1291         return $o;
1292
1293 }