aboutsummaryrefslogtreecommitdiffhomepage
path: root/routes/push.php
blob: 2420f67bd8c46124918e583de83d68cc7c539dd4 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
<?php

use Digitigrade\HttpResponseStatus\BadRequest;
use Digitigrade\HttpResponseStatus\Forbidden;
use Digitigrade\HttpResponseStatus\Unauthorized;
use Digitigrade\Job\ProcessIncomingPush;
use Digitigrade\Job\ProcessIncomingSimplePush;
use Digitigrade\Model\Instance;
use Digitigrade\Router;

Router::getInstance()->mount('/push', function (array $args) {
    // receive incoming pushes
    $instance = Instance::findByRequestHeaders();
    if ($instance == null) {
        throw new Unauthorized('please identify yourself with a valid Authorization header!');
    }
    if (!$instance->auth->inboundPushEnabled) {
        throw new Forbidden('you are not permitted to push as i have not subscribed to you');
    }

    $body = file_get_contents('php://input');
    $obj = json_decode($body);
    if ($obj === null) {
        throw new BadRequest("request body doesn't look like valid json");
    }
    if (!isset($obj->type, $obj->self)) {
        throw new BadRequest('the object needs to have `type` and `self` properties');
    }
    if (!str_starts_with($obj->self, 'https://')) {
        throw new BadRequest('dodgy looking `self` uri!');
    }
    if (hostname_from_uri($obj->self) != $instance->domain) {
        throw new Forbidden('you may not push objects belonging to a different instance');
    }
    if (!in_array($obj->type, ['actor', 'note', 'interaction', 'extension', 'tombstone'])) {
        throw new BadRequest('invalid object type!');
    }

    (new ProcessIncomingPush($obj))->submit();
});

Router::getInstance()->mount('/push/simple', function (array $args) {
    // receive incoming simple pushes
    $uri = file_get_contents('php://input');
    if (!str_starts_with($uri, 'https://')) {
        throw new BadRequest('dodgy looking uri!');
    }

    // FIXME: use a proper rate limit system
    sleep(5);
    // and only add the job if the client actually waited for the delay time
    if (!connection_aborted()) {
        // submit it for later, to reduce abuse, theoretically
        (new ProcessIncomingSimplePush($uri))->submitDelayed(60);
    }
});