This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include
, or for example
via PHP's auto-loading mechanism.
These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
1 | <?php |
||
2 | /** |
||
3 | * Elgg friends library. |
||
4 | * Provides the UI for friends. Includes access collections since they are based |
||
5 | * on friends relationships. |
||
6 | * |
||
7 | * @package Elgg.Core |
||
8 | * @subpackage Friends |
||
9 | */ |
||
10 | |||
11 | /** |
||
12 | * Init friends library |
||
13 | * |
||
14 | * @access private |
||
15 | */ |
||
16 | function _elgg_friends_init() { |
||
17 | elgg_register_action('friends/add'); |
||
18 | elgg_register_action('friends/remove'); |
||
19 | |||
20 | elgg_register_action('friends/collections/add'); |
||
21 | elgg_register_action('friends/collections/delete'); |
||
22 | elgg_register_action('friends/collections/edit'); |
||
23 | |||
24 | elgg_register_page_handler('friends', '_elgg_friends_page_handler'); |
||
25 | elgg_register_page_handler('friendsof', '_elgg_friends_page_handler'); |
||
26 | elgg_register_page_handler('collections', '_elgg_collections_page_handler'); |
||
27 | |||
28 | elgg_register_widget_type('friends', elgg_echo('friends'), elgg_echo('friends:widget:description')); |
||
29 | |||
30 | elgg_register_event_handler('pagesetup', 'system', '_elgg_friends_page_setup'); |
||
31 | elgg_register_event_handler('pagesetup', 'system', '_elgg_setup_collections_menu'); |
||
32 | elgg_register_plugin_hook_handler('register', 'menu:user_hover', '_elgg_friends_setup_user_hover_menu'); |
||
33 | elgg_register_event_handler('create', 'friend', '_elgg_send_friend_notification'); |
||
34 | } |
||
35 | |||
36 | /** |
||
37 | * Register some menu items for friends UI |
||
38 | * @access private |
||
39 | */ |
||
40 | function _elgg_friends_page_setup() { |
||
41 | $owner = elgg_get_page_owner_entity(); |
||
42 | $viewer = elgg_get_logged_in_user_entity(); |
||
43 | |||
44 | if ($owner) { |
||
45 | $params = array( |
||
46 | 'name' => 'friends', |
||
47 | 'text' => elgg_echo('friends'), |
||
48 | 'href' => 'friends/' . $owner->username, |
||
49 | 'contexts' => array('friends') |
||
50 | ); |
||
51 | elgg_register_menu_item('page', $params); |
||
52 | |||
53 | $params = array( |
||
54 | 'name' => 'friends:of', |
||
55 | 'text' => elgg_echo('friends:of'), |
||
56 | 'href' => 'friendsof/' . $owner->username, |
||
57 | 'contexts' => array('friends') |
||
58 | ); |
||
59 | elgg_register_menu_item('page', $params); |
||
60 | } |
||
61 | |||
62 | // topbar |
||
63 | if ($viewer) { |
||
64 | elgg_register_menu_item('topbar', array( |
||
65 | 'name' => 'friends', |
||
66 | 'href' => "friends/{$viewer->username}", |
||
67 | 'text' => elgg_view_icon('users'), |
||
68 | 'title' => elgg_echo('friends'), |
||
69 | 'priority' => 300, |
||
70 | )); |
||
71 | } |
||
72 | } |
||
73 | |||
74 | /** |
||
75 | * Adds friending to user hover menu |
||
76 | * |
||
77 | * @access private |
||
78 | */ |
||
79 | function _elgg_friends_setup_user_hover_menu($hook, $type, $return, $params) { |
||
80 | $user = $params['entity']; |
||
81 | /* @var \ElggUser $user */ |
||
82 | |||
83 | View Code Duplication | if (elgg_is_logged_in()) { |
|
84 | if (elgg_get_logged_in_user_guid() != $user->guid) { |
||
85 | $isFriend = $user->isFriend(); |
||
86 | |||
87 | // Always emit both to make it super easy to toggle with ajax |
||
88 | $return[] = \ElggMenuItem::factory(array( |
||
89 | 'name' => 'remove_friend', |
||
90 | 'href' => elgg_add_action_tokens_to_url("action/friends/remove?friend={$user->guid}"), |
||
91 | 'text' => elgg_echo('friend:remove'), |
||
92 | 'section' => 'action', |
||
93 | 'item_class' => $isFriend ? '' : 'hidden', |
||
94 | )); |
||
95 | |||
96 | $return[] = \ElggMenuItem::factory(array( |
||
97 | 'name' => 'add_friend', |
||
98 | 'href' => elgg_add_action_tokens_to_url("action/friends/add?friend={$user->guid}"), |
||
99 | 'text' => elgg_echo('friend:add'), |
||
100 | 'section' => 'action', |
||
101 | 'item_class' => $isFriend ? 'hidden' : '', |
||
102 | )); |
||
103 | } |
||
104 | } |
||
105 | |||
106 | return $return; |
||
107 | } |
||
108 | |||
109 | /** |
||
110 | * Page handler for friends-related pages |
||
111 | * |
||
112 | * @param array $segments URL segments |
||
113 | * @param string $handler The first segment in URL used for routing |
||
114 | * |
||
115 | * @return bool |
||
116 | * @access private |
||
117 | */ |
||
118 | function _elgg_friends_page_handler($segments, $handler) { |
||
119 | elgg_set_context('friends'); |
||
120 | |||
121 | View Code Duplication | if (isset($segments[0]) && $user = get_user_by_username($segments[0])) { |
|
122 | elgg_set_page_owner_guid($user->getGUID()); |
||
123 | } |
||
124 | |||
125 | if (!elgg_get_page_owner_guid()) { |
||
126 | return false; |
||
127 | } |
||
128 | |||
129 | switch ($handler) { |
||
130 | case 'friends': |
||
131 | require_once(dirname(dirname(dirname(__FILE__))) . "/pages/friends/index.php"); |
||
132 | break; |
||
133 | case 'friendsof': |
||
134 | require_once(dirname(dirname(dirname(__FILE__))) . "/pages/friends/of.php"); |
||
135 | break; |
||
136 | default: |
||
137 | return false; |
||
138 | } |
||
139 | return true; |
||
140 | } |
||
141 | |||
142 | /** |
||
143 | * Page handler for friends collections |
||
144 | * |
||
145 | * @param array $page_elements Page elements |
||
146 | * |
||
147 | * @return bool |
||
148 | * @access private |
||
149 | */ |
||
150 | function _elgg_collections_page_handler($page_elements) { |
||
151 | elgg_set_context('friends'); |
||
152 | $base = elgg_get_config('path'); |
||
153 | if (isset($page_elements[0])) { |
||
154 | switch ($page_elements[0]) { |
||
155 | case 'add': |
||
156 | elgg_set_page_owner_guid(elgg_get_logged_in_user_guid()); |
||
157 | |||
158 | require_once "{$base}pages/friends/collections/add.php"; |
||
159 | return true; |
||
160 | break; |
||
0 ignored issues
–
show
|
|||
161 | case 'owner': |
||
162 | $user = get_user_by_username($page_elements[1]); |
||
163 | if ($user) { |
||
164 | elgg_set_page_owner_guid($user->getGUID()); |
||
165 | |||
166 | require_once "{$base}pages/friends/collections/view.php"; |
||
167 | return true; |
||
168 | } |
||
169 | break; |
||
170 | } |
||
171 | } |
||
172 | return false; |
||
173 | } |
||
174 | |||
175 | /** |
||
176 | * Adds collection sidebar menu items |
||
177 | * |
||
178 | * @return void |
||
179 | * @access private |
||
180 | */ |
||
181 | function _elgg_setup_collections_menu() { |
||
182 | |||
183 | if (elgg_is_logged_in() && elgg_get_logged_in_user_guid() == elgg_get_page_owner_guid()) { |
||
184 | $user = elgg_get_page_owner_entity(); |
||
185 | |||
186 | elgg_register_menu_item('page', array( |
||
187 | 'name' => 'friends:view:collections', |
||
188 | 'text' => elgg_echo('friends:collections'), |
||
189 | 'href' => "collections/owner/$user->username", |
||
190 | 'contexts' => array('friends') |
||
191 | )); |
||
192 | } |
||
193 | } |
||
194 | |||
195 | /** |
||
196 | * Notify user that someone has friended them |
||
197 | * |
||
198 | * @param string $event Event name |
||
199 | * @param string $type Object type |
||
200 | * @param \ElggRelationship $object Object |
||
201 | * |
||
202 | * @return bool |
||
203 | * @access private |
||
204 | */ |
||
205 | function _elgg_send_friend_notification($event, $type, $object) { |
||
206 | $user_one = get_entity($object->guid_one); |
||
207 | /* @var \ElggUser $user_one */ |
||
208 | |||
209 | $user_two = get_entity($object->guid_two); |
||
210 | /* @var ElggUser $user_two */ |
||
211 | |||
212 | // Notification subject |
||
213 | $subject = elgg_echo('friend:newfriend:subject', array( |
||
214 | $user_one->name |
||
215 | ), $user_two->language); |
||
216 | |||
217 | // Notification body |
||
218 | $body = elgg_echo("friend:newfriend:body", array( |
||
219 | $user_one->name, |
||
220 | $user_one->getURL() |
||
221 | ), $user_two->language); |
||
222 | |||
223 | // Notification params |
||
224 | $params = [ |
||
225 | 'action' => 'add_friend', |
||
226 | 'object' => $user_one, |
||
227 | ]; |
||
228 | |||
229 | return notify_user($user_two->guid, $object->guid_one, $subject, $body, $params); |
||
230 | } |
||
231 | |||
232 | return function(\Elgg\EventsService $events, \Elgg\HooksRegistrationService $hooks) { |
||
233 | $events->registerHandler('init', 'system', '_elgg_friends_init'); |
||
234 | }; |
||
235 |
The break statement is not necessary if it is preceded for example by a return statement:
If you would like to keep this construct to be consistent with other case statements, you can safely mark this issue as a false-positive.