From 085762ec174eae1c519ec14db632f5ba197ed3c7 Mon Sep 17 00:00:00 2001 From: winter Date: Tue, 17 Dec 2024 18:39:18 +0000 Subject: hopefully implement push! again i can't really test this yet because i don't have two https instances that can talk to each other. soon i will set that up and test all these recent commits --- routes/push.php | 50 ++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 50 insertions(+) create mode 100644 routes/push.php (limited to 'routes/push.php') diff --git a/routes/push.php b/routes/push.php new file mode 100644 index 0000000..6712fb4 --- /dev/null +++ b/routes/push.php @@ -0,0 +1,50 @@ +mount('/push', function (array $args) { + // receive incoming pushes + $instance = Instance::findByRequestHeaders(); + if ($instance == null) { + throw new Unauthorized('please identify yourself with a valid Authorization header!'); + } + if (!$instance->auth->inboundPushEnabled) { + throw new Forbidden('you are not permitted to push as i have not subscribed to you'); + } + + $body = file_get_contents('php://input'); + $obj = json_decode($body); + if ($obj === false) { + throw new BadRequest("request body doesn't look like valid json"); + } + if (!isset($obj->type, $obj->self)) { + throw new BadRequest('the object needs to have `type` and `self` properties'); + } + if (!str_starts_with($obj->self, 'https://')) { + throw new BadRequest('dodgy looking `self` uri!'); + } + if (hostname_from_uri($obj->self) != $instance->domain) { + throw new Forbidden('you may not push objects belonging to a different instance'); + } + + switch ($obj->type) { + case 'actor': + Actor::importFromReceivedObject($obj); + break; + case 'note': + Note::importFromReceivedObject($obj); + break; + case 'interaction': + case 'extension': + case 'tombstone': + throw new \RuntimeException('object type not yet implemented :('); + default: + throw new BadRequest('invalid object type'); + } +}); \ No newline at end of file -- cgit v1.3