diff options
| author | winter | 2024-12-19 20:59:18 +0000 |
|---|---|---|
| committer | winter | 2024-12-19 20:59:18 +0000 |
| commit | 72b07245f44c73ed41bfcca2465a9ee34426a922 (patch) | |
| tree | 57372703100ad792c95c665a568aabe8a763bfdf /misc/get_remote_object_authenticated.php | |
| parent | 1e070a7a0097c74f8ac30678d39267f19c76f9f6 (diff) | |
implement follow relationships (untested)
does NOT implement the actual behaviour behind follows (receiving posts and such)
Diffstat (limited to 'misc/get_remote_object_authenticated.php')
| -rw-r--r-- | misc/get_remote_object_authenticated.php | 50 |
1 files changed, 0 insertions, 50 deletions
diff --git a/misc/get_remote_object_authenticated.php b/misc/get_remote_object_authenticated.php deleted file mode 100644 index 9f2db43..0000000 --- a/misc/get_remote_object_authenticated.php +++ /dev/null @@ -1,50 +0,0 @@ -<?php - -use Digitigrade\GlobalConfig; -use Digitigrade\Model\Instance; - -/** - * Makes an HTTPS request to a remote instance, using the corresponding outbound auth token (if any) - * @param string $uri - * @param bool $dontLookUpInstance if true, will skip looking up the Instance, and consequently the auth token - * @param string $method HTTP verb - * @return false|string the response data, or false if it failed - */ -function get_remote_object_authenticated(string $uri, bool $dontLookUpInstance = false, string $method = 'GET'): false|string { - if (!str_starts_with($uri, 'https://')) - return false; - - $remoteHost = hostname_from_uri($uri); - if ($remoteHost == GlobalConfig::getInstance()->getCanonicalHost()) { - // refuse to fetch objects from ourself. that's silly - return false; - } - - $instance = null; - if (!$dontLookUpInstance) { - $instance = Instance::findByHostname($remoteHost); - } - - if (!isset($instance->auth->outboundToken) || $instance->auth->outboundToken == null) { - // hopefully we can make the request anyway? - $context = stream_context_create(['http' => ['method' => $method]]); - $resp = file_get_contents($uri); - // $http_response_header just poofs into existence . - // i don't like this api. i should probably use curl instead. hmm - // TODO: use curl instead of file_get_contents - if (str_contains($http_response_header[0], '401') || str_contains($http_response_header[0], '403')) { - // we can't authenticate right now because it's asynchronous - // so i'm choosing to begin the auth process now and return false in the hopes that - // this request will be retried later - $instance?->beginOutboundAuth(); - return false; - } - return $resp; - } - - $context = stream_context_create(['http' => [ - 'method' => $method, - 'header' => 'Authorization: Bearer ' . $instance->auth->outboundToken - ]]); - return file_get_contents($uri, context: $context); -}
\ No newline at end of file |
