XmppPlugin.php 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472
  1. <?php
  2. // This file is part of GNU social - https://www.gnu.org/software/social
  3. //
  4. // GNU social is free software: you can redistribute it and/or modify
  5. // it under the terms of the GNU Affero General Public License as published by
  6. // the Free Software Foundation, either version 3 of the License, or
  7. // (at your option) any later version.
  8. //
  9. // GNU social is distributed in the hope that it will be useful,
  10. // but WITHOUT ANY WARRANTY; without even the implied warranty of
  11. // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  12. // GNU Affero General Public License for more details.
  13. //
  14. // You should have received a copy of the GNU Affero General Public License
  15. // along with GNU social. If not, see <http://www.gnu.org/licenses/>.
  16. /**
  17. * Send and receive notices using the XMPP network
  18. *
  19. * @category IM
  20. * @package GNUsocial
  21. * @author Evan Prodromou <evan@status.net>
  22. * @copyright 2009 StatusNet, Inc.
  23. * @license https://www.gnu.org/licenses/agpl.html GNU AGPL v3 or later
  24. */
  25. defined('GNUSOCIAL') || die();
  26. /**
  27. * Plugin for XMPP
  28. *
  29. * @category Plugin
  30. * @package GNUsocial
  31. * @author Evan Prodromou <evan@status.net>
  32. * @copyright 2009 StatusNet, Inc.
  33. * @license https://www.gnu.org/licenses/agpl.html GNU AGPL v3 or later
  34. */
  35. class XmppPlugin extends ImPlugin
  36. {
  37. const PLUGIN_VERSION = '2.0.0';
  38. public $server = null;
  39. public $port = 5222;
  40. public $user = 'update';
  41. public $resource = 'gnusocial';
  42. public $encryption = true;
  43. public $password = null;
  44. public $host = null; // only set if != server
  45. public $debug = false; // print extra debug info
  46. public $transport = 'xmpp';
  47. public function getDisplayName()
  48. {
  49. // TRANS: Plugin display name.
  50. return _m('XMPP/Jabber');
  51. }
  52. public function daemonScreenname()
  53. {
  54. $ret = $this->user . '@' . $this->server;
  55. if ($this->resource) {
  56. return $ret . '/' . $this->resource;
  57. } else {
  58. return $ret;
  59. }
  60. }
  61. public function validate($screenname)
  62. {
  63. return $this->validateBaseJid($screenname, common_config('email', 'check_domain'));
  64. }
  65. /**
  66. * Checks whether a string is a syntactically valid base Jabber ID (JID).
  67. * A base JID won't include a resource specifier on the end; since we
  68. * take it off when reading input we can't really use them reliably
  69. * to direct outgoing messages yet (sorry guys!)
  70. *
  71. * Note that a bare domain can be a valid JID.
  72. *
  73. * @param string $jid string to check
  74. * @param bool $check_domain whether we should validate that domain...
  75. *
  76. * @return boolean whether the string is a valid JID
  77. */
  78. protected function validateBaseJid($jid, $check_domain = false)
  79. {
  80. try {
  81. $parts = $this->splitJid($jid);
  82. if ($check_domain) {
  83. if (!$this->checkDomain($parts['domain'])) {
  84. return false;
  85. }
  86. }
  87. // missing; empty isn't kosher
  88. return is_null($parts['resource']);
  89. } catch (UnexpectedValueException $e) {
  90. return false;
  91. }
  92. }
  93. /**
  94. * Splits a Jabber ID (JID) into node, domain, and resource portions.
  95. *
  96. * Based on validation routine submitted by:
  97. * @param string $jid string to check
  98. *
  99. * @return array with "node", "domain", and "resource" indices
  100. * @throws UnexpectedValueException if input is not valid
  101. * @license Licensed under ISC-L, which is compatible with everything else that keeps the copyright notice intact.
  102. *
  103. * @copyright 2009 Patrick Georgi <patrick@georgi-clan.de>
  104. */
  105. protected function splitJid($jid)
  106. {
  107. $chars = [];
  108. /* the following definitions come from stringprep, Appendix C,
  109. which is used in its entirety by nodeprop, Chapter 5, "Prohibited Output" */
  110. // C.1.1 Latin-1 space characters
  111. $chars['1.1'] = "\x{20}";
  112. // C.1.2 Non-Latin-1 space characters
  113. $chars['1.2'] = "\x{a0}\x{1680}\x{2000}-\x{200b}\x{202f}\x{205f}\x{3000a}";
  114. // C.2.1 Latin-1 control characters
  115. $chars['2.1'] = "\x{00}-\x{1f}\x{7f}";
  116. // C.2.2 Non-Latin-1 control characters
  117. $chars['2.2'] = "\x{80}-\x{9f}\x{6dd}\x{70f}\x{180e}\x{200c}\x{200d}"
  118. . "\x{2028}\x{2029}\x{2060}-\x{2063}\x{206a}-\x{206f}\x{feff}"
  119. . "\x{fff9}-\x{fffc}\x{1d173}-\x{1d17a}";
  120. // C.3 - Private Use
  121. $chars['3'] = "\x{e000}-\x{f8ff}\x{f0000}-\x{ffffd}\x{100000}-\x{10fffd}";
  122. // C.4 - Non-character code points
  123. $chars['4'] = "\x{fdd0}-\x{fdef}\x{fffe}\x{ffff}\x{1fffe}\x{1ffff}"
  124. . "\x{2fffe}\x{2ffff}\x{3fffe}\x{3ffff}\x{4fffe}\x{4ffff}\x{5fffe}"
  125. . "\x{5ffff}\x{6fffe}\x{6ffff}\x{7fffe}\x{7ffff}\x{8fffe}\x{8ffff}"
  126. . "\x{9fffe}\x{9ffff}\x{afffe}\x{affff}\x{bfffe}\x{bffff}\x{cfffe}"
  127. . "\x{cffff}\x{dfffe}\x{dffff}\x{efffe}\x{effff}\x{ffffe}\x{fffff}"
  128. . "\x{10fffe}\x{10ffff}";
  129. // C.5 - Surrogate codes
  130. // We can't use preg_match to check this, fix below
  131. // $chars['5'] = "\x{d800}-\x{dfff}";
  132. // C.6 - Inappropriate for plain text
  133. $chars['6'] = "\x{fff9}-\x{fffd}";
  134. // C.7 - Inappropriate for canonical representation
  135. $chars['7'] = "\x{2ff0}-\x{2ffb}";
  136. // C.8 - Change display properties or are deprecated
  137. $chars['8'] = "\x{340}\x{341}\x{200e}\x{200f}\x{202a}-\x{202e}\x{206a}-\x{206f}";
  138. // C.9 - Tagging characters
  139. $chars['9'] = "\x{e0001}\x{e0020}-\x{e007f}";
  140. $nodeprep_chars = implode('', $chars);
  141. // Nodeprep forbids some more characters
  142. $nodeprep_chars .= "\x{22}\x{26}\x{27}\x{2f}\x{3a}\x{3c}\x{3e}\x{40}";
  143. // Resourceprep forbids all from stringprep, Appendix C, except for C.1.1
  144. $resprep_chars = implode('', array_slice($chars, 1));
  145. $parts = explode('/', $jid, 2);
  146. if (count($parts) > 1) {
  147. $resource = $parts[1];
  148. // if ($resource == '') then
  149. // Warning: empty resource isn't legit.
  150. // But if we're normalizing, we may as well take it...
  151. } else {
  152. $resource = null;
  153. }
  154. $node = explode("@", $parts[0]);
  155. if ((count($node) > 2) || (count($node) == 0)) {
  156. // TRANS: Exception thrown when using too many @ signs in a Jabber ID.
  157. throw new UnexpectedValueException(_m('Invalid JID: too many @s.'));
  158. } elseif (count($node) == 1) {
  159. $domain = $node[0];
  160. $node = null;
  161. } else {
  162. $domain = $node[1];
  163. $node = $node[0];
  164. if ($node == '') {
  165. // TRANS: Exception thrown when using @ sign not followed by a Jabber ID.
  166. throw new UnexpectedValueException(_m('Invalid JID: @ but no node'));
  167. }
  168. }
  169. if (!is_null($node)) {
  170. // Length limits per https://xmpp.org/rfcs/rfc3920.html#addressing
  171. if (mb_strlen($node, '8bit') > 1023) {
  172. // TRANS: Exception thrown when using too long a Jabber ID (>1023).
  173. throw new UnexpectedValueException(_m('Invalid JID: node too long.'));
  174. }
  175. // C5 - Surrogate codes is ensured by encoding check
  176. if (preg_match("/[{$nodeprep_chars}]/u", $node)
  177. || mb_detect_encoding($node, 'UTF-8', true) !== 'UTF-8') {
  178. // TRANS: Exception thrown when using an invalid Jabber ID.
  179. // TRANS: %s is the invalid Jabber ID.
  180. throw new UnexpectedValueException(sprintf(_m('Invalid JID node "%s".'), $node));
  181. }
  182. }
  183. if (mb_strlen($domain, '8bit') > 1023) {
  184. // TRANS: Exception thrown when using too long a Jabber domain (>1023).
  185. throw new UnexpectedValueException(_m('Invalid JID: domain too long.'));
  186. }
  187. if (!common_valid_domain($domain)) {
  188. // TRANS: Exception thrown when using an invalid Jabber domain name.
  189. // TRANS: %s is the invalid domain name.
  190. throw new UnexpectedValueException(sprintf(_m('Invalid JID domain name "%s".'), $domain));
  191. }
  192. if (!is_null($resource)) {
  193. if (mb_strlen($resource, '8bit') > 1023) {
  194. // TRANS: Exception thrown when using too long a resource (>1023).
  195. throw new UnexpectedValueException('Invalid JID: resource too long.');
  196. }
  197. if (preg_match("/[{$resprep_chars}]/u", $resource)) {
  198. // TRANS: Exception thrown when using an invalid Jabber resource.
  199. // TRANS: %s is the invalid resource.
  200. throw new UnexpectedValueException(sprintf(_m('Invalid JID resource "%s".'), $resource));
  201. }
  202. }
  203. return array('node' => is_null($node) ? null : mb_strtolower($node),
  204. 'domain' => is_null($domain) ? null : mb_strtolower($domain),
  205. 'resource' => $resource);
  206. }
  207. /**
  208. * Check if this domain's got some legit DNS record
  209. * @param $domain
  210. * @return bool
  211. */
  212. protected function checkDomain($domain)
  213. {
  214. if (checkdnsrr("_xmpp-server._tcp." . $domain, "SRV")) {
  215. return true;
  216. }
  217. if (checkdnsrr($domain, "ANY")) {
  218. return true;
  219. }
  220. return false;
  221. }
  222. public function onStartImDaemonIoManagers(&$classes)
  223. {
  224. parent::onStartImDaemonIoManagers($classes);
  225. $classes[] = new XmppManager($this); // handles pings/reconnects
  226. return true;
  227. }
  228. public function sendMessage($screenname, $body)
  229. {
  230. $this->queuedConnection()->message($screenname, $body, 'chat');
  231. }
  232. /**
  233. * Build a queue-proxied XMPP interface object. Any outgoing messages
  234. * will be run back through us for enqueing rather than sent directly.
  235. *
  236. * @return QueuedXMPP
  237. * @throws Exception if server settings are invalid.
  238. */
  239. public function queuedConnection()
  240. {
  241. if (!isset($this->server)) {
  242. // TRANS: Exception thrown when the plugin configuration is incorrect.
  243. throw new Exception(_m('You must specify a server in the configuration.'));
  244. }
  245. if (!isset($this->port)) {
  246. // TRANS: Exception thrown when the plugin configuration is incorrect.
  247. throw new Exception(_m('You must specify a port in the configuration.'));
  248. }
  249. if (!isset($this->user)) {
  250. // TRANS: Exception thrown when the plugin configuration is incorrect.
  251. throw new Exception(_m('You must specify a user in the configuration.'));
  252. }
  253. if (!isset($this->password)) {
  254. // TRANS: Exception thrown when the plugin configuration is incorrect.
  255. throw new Exception(_m('You must specify a password in the configuration.'));
  256. }
  257. return new QueuedXMPP(
  258. $this,
  259. ($this->host ?: $this->server),
  260. $this->port,
  261. $this->user,
  262. $this->password,
  263. $this->resource,
  264. $this->server,
  265. ($this->debug ? true : false),
  266. ($this->debug ? \XMPPHP\Log::LEVEL_VERBOSE : null)
  267. );
  268. }
  269. public function sendNotice($screenname, Notice $notice)
  270. {
  271. try {
  272. $msg = $this->formatNotice($notice);
  273. $entry = $this->format_entry($notice);
  274. } catch (Exception $e) {
  275. common_log(LOG_ERR, __METHOD__ . ": Discarding outgoing stanza because of exception: {$e->getMessage()}");
  276. return false; // return value of sendNotice is never actually used as of now
  277. }
  278. $this->queuedConnection()->message($screenname, $msg, 'chat', null, $entry);
  279. return true;
  280. }
  281. /**
  282. * extra information for XMPP messages, as defined by Twitter
  283. *
  284. * @param Notice $notice Notice being sent
  285. *
  286. * @return string Extra information (Atom, HTML, addresses) in string format
  287. */
  288. protected function format_entry(Notice $notice)
  289. {
  290. $profile = $notice->getProfile();
  291. $entry = $notice->asAtomEntry(true, true);
  292. $xs = new XMLStringer();
  293. $xs->elementStart('html', array('xmlns' => 'http://jabber.org/protocol/xhtml-im'));
  294. $xs->elementStart('body', array('xmlns' => 'http://www.w3.org/1999/xhtml'));
  295. $xs->element('a', array('href' => $profile->profileurl), $profile->nickname);
  296. try {
  297. $parent = $notice->getParent();
  298. $orig_profile = $parent->getProfile();
  299. $orig_profurl = $orig_profile->getUrl();
  300. $xs->text(" => ");
  301. $xs->element('a', array('href' => $orig_profurl), $orig_profile->nickname);
  302. $xs->text(": ");
  303. } catch (NoParentNoticeException $e) {
  304. $xs->text(": ");
  305. }
  306. // FIXME: Why do we replace \t with ''? is it just to make it pretty? shouldn't whitespace be handled well...?
  307. $xs->raw(str_replace("\t", "", $notice->getRendered()));
  308. $xs->text(" ");
  309. $xs->element(
  310. 'a',
  311. [
  312. 'href' => common_local_url(
  313. 'conversation',
  314. ['id' => $notice->conversation]
  315. ) . '#notice-' . $notice->id,
  316. ],
  317. // TRANS: Link description to notice in conversation.
  318. // TRANS: %s is a notice ID.
  319. sprintf(_m('[%u]'), $notice->id)
  320. );
  321. $xs->elementEnd('body');
  322. $xs->elementEnd('html');
  323. $html = $xs->getString();
  324. return $html . ' ' . $entry;
  325. }
  326. public function receiveRawMessage($pl)
  327. {
  328. $from = $this->normalize($pl['from']);
  329. if (is_null($from)) {
  330. $this->log(LOG_WARNING, 'Ignoring message from invalid JID: ' . $pl['xml']->toString());
  331. return true;
  332. }
  333. if ($pl['type'] !== 'chat') {
  334. $this->log(LOG_WARNING, "Ignoring message of type " . $pl['type'] . " from $from: " . $pl['xml']->toString());
  335. return true;
  336. }
  337. if (mb_strlen($pl['body']) == 0) {
  338. $this->log(LOG_WARNING, "Ignoring message with empty body from $from: " . $pl['xml']->toString());
  339. return true;
  340. }
  341. $this->handleIncoming($from, $pl['body']);
  342. return true;
  343. }
  344. /**
  345. * Normalizes a Jabber ID for comparison, dropping the resource component if any.
  346. *
  347. * @param string $jid JID to check
  348. * @return string an equivalent JID in normalized (lowercase) form
  349. */
  350. public function normalize($jid)
  351. {
  352. try {
  353. $parts = $this->splitJid($jid);
  354. if (!is_null($parts['node'])) {
  355. return $parts['node'] . '@' . $parts['domain'];
  356. } else {
  357. return $parts['domain'];
  358. }
  359. } catch (UnexpectedValueException $e) {
  360. return null;
  361. }
  362. }
  363. /**
  364. * Add XMPP plugin daemon to the list of daemon to start
  365. *
  366. * @param array $daemons the list of daemons to run
  367. *
  368. * @return boolean hook return
  369. */
  370. public function onGetValidDaemons(&$daemons)
  371. {
  372. if (isset($this->server) &&
  373. isset($this->port) &&
  374. isset($this->user) &&
  375. isset($this->password)) {
  376. array_push(
  377. $daemons,
  378. INSTALLDIR . '/scripts/imdaemon.php'
  379. );
  380. }
  381. return true;
  382. }
  383. /**
  384. * Plugin Nodeinfo information
  385. *
  386. * @param array $protocols
  387. * @return bool hook true
  388. */
  389. public function onNodeInfoProtocols(array &$protocols)
  390. {
  391. $protocols[] = "xmpp";
  392. return true;
  393. }
  394. public function onPluginVersion(array &$versions): bool
  395. {
  396. $versions[] = array('name' => 'XMPP',
  397. 'version' => self::PLUGIN_VERSION,
  398. 'author' => 'Craig Andrews, Evan Prodromou',
  399. 'homepage' => GNUSOCIAL_ENGINE_REPO_URL . 'tree/master/plugins/XMPP',
  400. 'rawdescription' =>
  401. // TRANS: Plugin description.
  402. _m('The XMPP plugin allows users to send and receive notices over the XMPP/Jabber network.'));
  403. return true;
  404. }
  405. /**
  406. * Checks whether a string is a syntactically valid Jabber ID (JID),
  407. * either with or without a resource.
  408. *
  409. * Note that a bare domain can be a valid JID.
  410. *
  411. * @param string $jid string to check
  412. * @param bool $check_domain whether we should validate that domain...
  413. *
  414. * @return boolean whether the string is a valid JID
  415. */
  416. protected function validateFullJid($jid, $check_domain = false)
  417. {
  418. try {
  419. $parts = $this->splitJid($jid);
  420. if ($check_domain) {
  421. if (!$this->checkDomain($parts['domain'])) {
  422. return false;
  423. }
  424. }
  425. return $parts['resource'] !== ''; // missing or present; empty ain't kosher
  426. } catch (UnexpectedValueException $e) {
  427. return false;
  428. }
  429. }
  430. }