diff options
Diffstat (limited to 'routes/push.php')
| -rw-r--r-- | routes/push.php | 50 |
1 files changed, 50 insertions, 0 deletions
diff --git a/routes/push.php b/routes/push.php new file mode 100644 index 0000000..6712fb4 --- /dev/null +++ b/routes/push.php @@ -0,0 +1,50 @@ +<?php + +use Digitigrade\HttpResponseStatus\BadRequest; +use Digitigrade\HttpResponseStatus\Forbidden; +use Digitigrade\HttpResponseStatus\Unauthorized; +use Digitigrade\Model\Actor; +use Digitigrade\Model\Instance; +use Digitigrade\Model\Note; +use Digitigrade\Router; + +Router::getInstance()->mount('/push', function (array $args) { + // receive incoming pushes + $instance = Instance::findByRequestHeaders(); + if ($instance == null) { + throw new Unauthorized('please identify yourself with a valid Authorization header!'); + } + if (!$instance->auth->inboundPushEnabled) { + throw new Forbidden('you are not permitted to push as i have not subscribed to you'); + } + + $body = file_get_contents('php://input'); + $obj = json_decode($body); + if ($obj === false) { + throw new BadRequest("request body doesn't look like valid json"); + } + if (!isset($obj->type, $obj->self)) { + throw new BadRequest('the object needs to have `type` and `self` properties'); + } + if (!str_starts_with($obj->self, 'https://')) { + throw new BadRequest('dodgy looking `self` uri!'); + } + if (hostname_from_uri($obj->self) != $instance->domain) { + throw new Forbidden('you may not push objects belonging to a different instance'); + } + + switch ($obj->type) { + case 'actor': + Actor::importFromReceivedObject($obj); + break; + case 'note': + Note::importFromReceivedObject($obj); + break; + case 'interaction': + case 'extension': + case 'tombstone': + throw new \RuntimeException('object type not yet implemented :('); + default: + throw new BadRequest('invalid object type'); + } +});
\ No newline at end of file |
