aboutsummaryrefslogtreecommitdiffhomepage
path: root/routes/push.php
diff options
context:
space:
mode:
Diffstat (limited to 'routes/push.php')
-rw-r--r--routes/push.php50
1 files changed, 50 insertions, 0 deletions
diff --git a/routes/push.php b/routes/push.php
new file mode 100644
index 0000000..6712fb4
--- /dev/null
+++ b/routes/push.php
@@ -0,0 +1,50 @@
+<?php
+
+use Digitigrade\HttpResponseStatus\BadRequest;
+use Digitigrade\HttpResponseStatus\Forbidden;
+use Digitigrade\HttpResponseStatus\Unauthorized;
+use Digitigrade\Model\Actor;
+use Digitigrade\Model\Instance;
+use Digitigrade\Model\Note;
+use Digitigrade\Router;
+
+Router::getInstance()->mount('/push', function (array $args) {
+ // receive incoming pushes
+ $instance = Instance::findByRequestHeaders();
+ if ($instance == null) {
+ throw new Unauthorized('please identify yourself with a valid Authorization header!');
+ }
+ if (!$instance->auth->inboundPushEnabled) {
+ throw new Forbidden('you are not permitted to push as i have not subscribed to you');
+ }
+
+ $body = file_get_contents('php://input');
+ $obj = json_decode($body);
+ if ($obj === false) {
+ throw new BadRequest("request body doesn't look like valid json");
+ }
+ if (!isset($obj->type, $obj->self)) {
+ throw new BadRequest('the object needs to have `type` and `self` properties');
+ }
+ if (!str_starts_with($obj->self, 'https://')) {
+ throw new BadRequest('dodgy looking `self` uri!');
+ }
+ if (hostname_from_uri($obj->self) != $instance->domain) {
+ throw new Forbidden('you may not push objects belonging to a different instance');
+ }
+
+ switch ($obj->type) {
+ case 'actor':
+ Actor::importFromReceivedObject($obj);
+ break;
+ case 'note':
+ Note::importFromReceivedObject($obj);
+ break;
+ case 'interaction':
+ case 'extension':
+ case 'tombstone':
+ throw new \RuntimeException('object type not yet implemented :(');
+ default:
+ throw new BadRequest('invalid object type');
+ }
+}); \ No newline at end of file