Normalize use of form security tokens in Admin modules
[friendica.git/.git] / src / Module / Admin / Users.php
1 <?php
2 /**
3  * @copyright Copyright (C) 2020, Friendica
4  *
5  * @license GNU AGPL version 3 or any later version
6  *
7  * This program is free software: you can redistribute it and/or modify
8  * it under the terms of the GNU Affero General Public License as
9  * published by the Free Software Foundation, either version 3 of the
10  * License, or (at your option) any later version.
11  *
12  * This program is distributed in the hope that it will be useful,
13  * but WITHOUT ANY WARRANTY; without even the implied warranty of
14  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
15  * GNU Affero General Public License for more details.
16  *
17  * You should have received a copy of the GNU Affero General Public License
18  * along with this program.  If not, see <https://www.gnu.org/licenses/>.
19  *
20  */
21
22 namespace Friendica\Module\Admin;
23
24 use Friendica\Content\Pager;
25 use Friendica\Core\Renderer;
26 use Friendica\Database\DBA;
27 use Friendica\DI;
28 use Friendica\Model\Register;
29 use Friendica\Model\User;
30 use Friendica\Module\BaseAdmin;
31 use Friendica\Util\Temporal;
32
33 class Users extends BaseAdmin
34 {
35         public static function post(array $parameters = [])
36         {
37                 parent::post($parameters);
38
39                 self::checkFormSecurityTokenRedirectOnError('/admin/users', 'admin_users');
40
41                 $pending     = $_POST['pending']           ?? [];
42                 $users       = $_POST['user']              ?? [];
43                 $nu_name     = $_POST['new_user_name']     ?? '';
44                 $nu_nickname = $_POST['new_user_nickname'] ?? '';
45                 $nu_email    = $_POST['new_user_email']    ?? '';
46                 $nu_language = DI::config()->get('system', 'language');
47
48                 if ($nu_name !== '' && $nu_email !== '' && $nu_nickname !== '') {
49                         try {
50                                 User::createMinimal($nu_name, $nu_email, $nu_nickname, $nu_language);
51                         } catch (\Exception $ex) {
52                                 notice($ex->getMessage());
53                                 return;
54                         }
55                 }
56
57                 if (!empty($_POST['page_users_block'])) {
58                         foreach ($users as $uid) {
59                                 User::block($uid);
60                         }
61                         notice(DI::l10n()->tt('%s user blocked', '%s users blocked', count($users)));
62                 }
63
64                 if (!empty($_POST['page_users_unblock'])) {
65                         foreach ($users as $uid) {
66                                 User::block($uid, false);
67                         }
68                         notice(DI::l10n()->tt('%s user unblocked', '%s users unblocked', count($users)));
69                 }
70
71                 if (!empty($_POST['page_users_delete'])) {
72                         foreach ($users as $uid) {
73                                 if (local_user() != $uid) {
74                                         User::remove($uid);
75                                 } else {
76                                         notice(DI::l10n()->t('You can\'t remove yourself'));
77                                 }
78                         }
79
80                         notice(DI::l10n()->tt('%s user deleted', '%s users deleted', count($users)));
81                 }
82
83                 if (!empty($_POST['page_users_approve'])) {
84                         foreach ($pending as $hash) {
85                                 User::allow($hash);
86                         }
87                         notice(DI::l10n()->tt('%s user approved', '%s users approved', count($pending)));
88                 }
89
90                 if (!empty($_POST['page_users_deny'])) {
91                         foreach ($pending as $hash) {
92                                 User::deny($hash);
93                         }
94                         notice(DI::l10n()->tt('%s registration revoked', '%s registrations revoked', count($pending)));
95                 }
96
97                 DI::baseUrl()->redirect('admin/users');
98         }
99
100         public static function content(array $parameters = [])
101         {
102                 parent::content($parameters);
103
104                 $action = $parameters['action'] ?? '';
105                 $uid = $parameters['uid'] ?? 0;
106
107                 if ($uid) {
108                         $user = User::getById($uid, ['username', 'blocked']);
109                         if (!DBA::isResult($user)) {
110                                 notice('User not found' . EOL);
111                                 DI::baseUrl()->redirect('admin/users');
112                                 return ''; // NOTREACHED
113                         }
114                 }
115
116                 switch ($action) {
117                         case 'delete':
118                                 if (local_user() != $uid) {
119                                         self::checkFormSecurityTokenRedirectOnError('/admin/users', 'admin_users', 't');
120                                         // delete user
121                                         User::remove($uid);
122
123                                         notice(DI::l10n()->t('User "%s" deleted', $user['username']));
124                                 } else {
125                                         notice(DI::l10n()->t('You can\'t remove yourself'));
126                                 }
127                                 break;
128                         case 'block':
129                                 self::checkFormSecurityTokenRedirectOnError('/admin/users', 'admin_users', 't');
130                                 User::block($uid);
131                                 notice(DI::l10n()->t('User "%s" blocked', $user['username']));
132                                 break;
133                         case 'unblock':
134                                 self::checkFormSecurityTokenRedirectOnError('/admin/users', 'admin_users', 't');
135                                 User::block($uid, false);
136                                 notice(DI::l10n()->t('User "%s" unblocked', $user['username']));
137                                 break;
138                         case 'allow':
139                                 self::checkFormSecurityTokenRedirectOnError('/admin/users', 'admin_users', 't');
140                                 User::allow(Register::getPendingForUser($uid)['hash'] ?? '');
141                                 notice(DI::l10n()->t('Account approved.'));
142                                 break;
143                         case 'deny':
144                                 self::checkFormSecurityTokenRedirectOnError('/admin/users', 'admin_users', 't');
145                                 User::deny(Register::getPendingForUser($uid)['hash'] ?? '');
146                                 notice(DI::l10n()->t('Registration revoked'));
147                                 break;
148                         default:
149                                 /* get pending */
150                                 $pending = Register::getPending();
151
152                                 $pager = new Pager(DI::l10n(), DI::args()->getQueryString(), 100);
153
154                                 $valid_orders = [
155                                         'name',
156                                         'email',
157                                         'register_date',
158                                         'login_date',
159                                         'last-item',
160                                         'page-flags'
161                                 ];
162
163                                 $order = 'name';
164                                 $order_direction = '+';
165                                 if (!empty($_GET['o'])) {
166                                         $new_order = $_GET['o'];
167                                         if ($new_order[0] === '-') {
168                                                 $order_direction = '-';
169                                                 $new_order = substr($new_order, 1);
170                                         }
171
172                                         if (in_array($new_order, $valid_orders)) {
173                                                 $order = $new_order;
174                                         }
175                                 }
176
177                                 $users = User::getList($pager->getStart(), $pager->getItemsPerPage(), 'all', $order, ($order_direction == '-'));
178
179                                 $adminlist = explode(',', str_replace(' ', '', DI::config()->get('config', 'admin_email')));
180                                 $_setup_users = function ($e) use ($adminlist) {
181                                         $page_types = [
182                                                 User::PAGE_FLAGS_NORMAL    => DI::l10n()->t('Normal Account Page'),
183                                                 User::PAGE_FLAGS_SOAPBOX   => DI::l10n()->t('Soapbox Page'),
184                                                 User::PAGE_FLAGS_COMMUNITY => DI::l10n()->t('Public Forum'),
185                                                 User::PAGE_FLAGS_FREELOVE  => DI::l10n()->t('Automatic Friend Page'),
186                                                 User::PAGE_FLAGS_PRVGROUP  => DI::l10n()->t('Private Forum')
187                                         ];
188                                         $account_types = [
189                                                 User::ACCOUNT_TYPE_PERSON       => DI::l10n()->t('Personal Page'),
190                                                 User::ACCOUNT_TYPE_ORGANISATION => DI::l10n()->t('Organisation Page'),
191                                                 User::ACCOUNT_TYPE_NEWS         => DI::l10n()->t('News Page'),
192                                                 User::ACCOUNT_TYPE_COMMUNITY    => DI::l10n()->t('Community Forum'),
193                                                 User::ACCOUNT_TYPE_RELAY        => DI::l10n()->t('Relay'),
194                                         ];
195
196                                         $e['page_flags_raw'] = $e['page-flags'];
197                                         $e['page-flags'] = $page_types[$e['page-flags']];
198
199                                         $e['account_type_raw'] = ($e['page_flags_raw'] == 0) ? $e['account-type'] : -1;
200                                         $e['account-type'] = ($e['page_flags_raw'] == 0) ? $account_types[$e['account-type']] : '';
201
202                                         $e['register_date'] = Temporal::getRelativeDate($e['register_date']);
203                                         $e['login_date'] = Temporal::getRelativeDate($e['login_date']);
204                                         $e['lastitem_date'] = Temporal::getRelativeDate($e['last-item']);
205                                         $e['is_admin'] = in_array($e['email'], $adminlist);
206                                         $e['is_deletable'] = (intval($e['uid']) != local_user());
207                                         $e['deleted'] = ($e['account_removed'] ? Temporal::getRelativeDate($e['account_expires_on']) : False);
208
209                                         return $e;
210                                 };
211
212                                 $tmp_users = array_map($_setup_users, $users);
213
214                                 // Get rid of dashes in key names, Smarty3 can't handle them
215                                 // and extracting deleted users
216
217                                 $deleted = [];
218                                 $users = [];
219                                 foreach ($tmp_users as $user) {
220                                         foreach ($user as $k => $v) {
221                                                 $newkey = str_replace('-', '_', $k);
222                                                 $user[$newkey] = $v;
223                                         }
224
225                                         if ($user['deleted']) {
226                                                 $deleted[] = $user;
227                                         } else {
228                                                 $users[] = $user;
229                                         }
230                                 }
231
232                                 $th_users = array_map(null, [DI::l10n()->t('Name'), DI::l10n()->t('Email'), DI::l10n()->t('Register date'), DI::l10n()->t('Last login'), DI::l10n()->t('Last public item'), DI::l10n()->t('Type')], $valid_orders);
233
234                                 $t = Renderer::getMarkupTemplate('admin/users.tpl');
235                                 $o = Renderer::replaceMacros($t, [
236                                         // strings //
237                                         '$title' => DI::l10n()->t('Administration'),
238                                         '$page' => DI::l10n()->t('Users'),
239                                         '$submit' => DI::l10n()->t('Add User'),
240                                         '$select_all' => DI::l10n()->t('select all'),
241                                         '$h_pending' => DI::l10n()->t('User registrations waiting for confirm'),
242                                         '$h_deleted' => DI::l10n()->t('User waiting for permanent deletion'),
243                                         '$th_pending' => [DI::l10n()->t('Request date'), DI::l10n()->t('Name'), DI::l10n()->t('Email')],
244                                         '$no_pending' => DI::l10n()->t('No registrations.'),
245                                         '$pendingnotetext' => DI::l10n()->t('Note from the user'),
246                                         '$approve' => DI::l10n()->t('Approve'),
247                                         '$deny' => DI::l10n()->t('Deny'),
248                                         '$delete' => DI::l10n()->t('Delete'),
249                                         '$block' => DI::l10n()->t('Block'),
250                                         '$blocked' => DI::l10n()->t('User blocked'),
251                                         '$unblock' => DI::l10n()->t('Unblock'),
252                                         '$siteadmin' => DI::l10n()->t('Site admin'),
253                                         '$accountexpired' => DI::l10n()->t('Account expired'),
254
255                                         '$h_users' => DI::l10n()->t('Users'),
256                                         '$h_newuser' => DI::l10n()->t('New User'),
257                                         '$th_deleted' => [DI::l10n()->t('Name'), DI::l10n()->t('Email'), DI::l10n()->t('Register date'), DI::l10n()->t('Last login'), DI::l10n()->t('Last public item'), DI::l10n()->t('Permanent deletion')],
258                                         '$th_users' => $th_users,
259                                         '$order_users' => $order,
260                                         '$order_direction_users' => $order_direction,
261
262                                         '$confirm_delete_multi' => DI::l10n()->t('Selected users will be deleted!\n\nEverything these users had posted on this site will be permanently deleted!\n\nAre you sure?'),
263                                         '$confirm_delete' => DI::l10n()->t('The user {0} will be deleted!\n\nEverything this user has posted on this site will be permanently deleted!\n\nAre you sure?'),
264
265                                         '$form_security_token' => self::getFormSecurityToken('admin_users'),
266
267                                         // values //
268                                         '$baseurl' => DI::baseUrl()->get(true),
269
270                                         '$pending' => $pending,
271                                         'deleted' => $deleted,
272                                         '$users' => $users,
273                                         '$newusername' => ['new_user_name', DI::l10n()->t('Name'), '', DI::l10n()->t('Name of the new user.')],
274                                         '$newusernickname' => ['new_user_nickname', DI::l10n()->t('Nickname'), '', DI::l10n()->t('Nickname of the new user.')],
275                                         '$newuseremail' => ['new_user_email', DI::l10n()->t('Email'), '', DI::l10n()->t('Email address of the new user.'), '', '', 'email'],
276                                 ]);
277
278                                 $o .= $pager->renderFull(DBA::count('user'));
279
280                                 return $o;
281                 }
282
283                 DI::baseUrl()->redirect('admin/users');
284                 return '';
285         }
286 }