define('SQL_BACKUP006', 'RENAME TABLE `%1$scategory` TO `%1$scategory006`, `%1$sfeed` TO `%1$sfeed006`, `%1$sentry` TO `%1$sentry006`;');
define('SQL_SHOW_COLUMNS_UPDATEv006', 'SHOW columns FROM `%1$sentry006` LIKE "id2";');
define('SQL_UPDATEv006', '
ALTER TABLE `%1$scategory006` ADD id2 SMALLINT;
SET @i = 0;
UPDATE `%1$scategory006` SET id2=(@i:=@i+1) ORDER BY id;
ALTER TABLE `%1$sfeed006` ADD id2 SMALLINT, ADD category2 SMALLINT;
SET @i = 0;
UPDATE `%1$sfeed006` SET id2=(@i:=@i+1) ORDER BY name;
UPDATE `%1$sfeed006` f
INNER JOIN `%1$scategory006` c ON f.category = c.id
SET f.category2 = c.id2;
INSERT IGNORE INTO `%2$scategory` (name)
SELECT name
FROM `%1$scategory006`
ORDER BY id2;
INSERT IGNORE INTO `%2$sfeed` (url, category, name, website, description, priority, pathEntries, httpAuth, keep_history)
SELECT url, category2, name, website, description, priority, pathEntries, httpAuth, IF(keep_history = 1, -1, -2)
FROM `%1$sfeed006`
ORDER BY id2;
ALTER TABLE `%1$sentry006` ADD id2 bigint;
UPDATE `%1$sentry006` SET id2 = ((date * 1000000) + (rand() * 100000000));
INSERT IGNORE INTO `%2$sentry` (id, guid, title, author, link, date, is_read, is_favorite, id_feed, tags)
SELECT e0.id2, e0.guid, e0.title, e0.author, e0.link, e0.date, e0.is_read, e0.is_favorite, f0.id2, e0.tags
FROM `%1$sentry006` e0
INNER JOIN `%1$sfeed006` f0 ON e0.id_feed = f0.id;
');
define('SQL_CONVERT_SELECTv006', '
SELECT e0.id2, e0.content
FROM `%1$sentry006` e0
INNER JOIN `%2$sentry` e1 ON e0.id2 = e1.id
WHERE e1.content_bin IS NULL');
define('SQL_CONVERT_UPDATEv006', 'UPDATE `%1$sentry` SET '
. (isset($_SESSION['bd_type']) && $_SESSION['bd_type'] === 'mysql' ? 'content_bin=COMPRESS(?)' : 'content=?')
. ' WHERE id=?;');
define('SQL_DROP_BACKUPv006', 'DROP TABLE IF EXISTS `%1$sentry006`, `%1$sfeed006`, `%1$scategory006`;');
define('SQL_UPDATE_CACHED_VALUES', '
UPDATE `%1$sfeed` f
INNER JOIN (
SELECT e.id_feed,
COUNT(CASE WHEN e.is_read = 0 THEN 1 END) AS nbUnreads,
COUNT(e.id) AS nbEntries
FROM `%1$sentry` e
GROUP BY e.id_feed
) x ON x.id_feed=f.id
SET f.cache_nbEntries=x.nbEntries, f.cache_nbUnreads=x.nbUnreads
');
define('SQL_UPDATE_HISTORYv007b', 'UPDATE `%1$sfeed` SET keep_history = CASE WHEN keep_history = 0 THEN -2 WHEN keep_history = 1 THEN -1 ELSE keep_history END;');
define('SQL_GET_FEEDS', 'SELECT id, url, website FROM `%1$sfeed`;');
//
// gestion internationalisation
$translates = array ();
$actual = 'en';
function initTranslate () {
global $translates;
global $actual;
$actual = isset($_SESSION['language']) ? $_SESSION['language'] : getBetterLanguage('en');
$file = APP_PATH . '/i18n/' . $actual . '.php';
if (file_exists($file)) {
$translates = array_merge($translates, include($file));
}
$file = APP_PATH . '/i18n/install.' . $actual . '.php';
if (file_exists($file)) {
$translates = array_merge($translates, include($file));
}
}
function getBetterLanguage ($fallback) {
$available = availableLanguages ();
$accept = $_SERVER['HTTP_ACCEPT_LANGUAGE'];
$language = strtolower (substr ($accept, 0, 2));
if (isset ($available[$language])) {
return $language;
} else {
return $fallback;
}
}
function availableLanguages () {
return array (
'en' => 'English',
'fr' => 'Français'
);
}
function _t ($key) {
global $translates;
$translate = $key;
if (isset ($translates[$key])) {
$translate = $translates[$key];
}
$args = func_get_args ();
unset($args[0]);
return vsprintf ($translate, $args);
}
/*** SAUVEGARDES ***/
function saveLanguage () {
if (!empty ($_POST)) {
if (!isset ($_POST['language'])) {
return false;
}
$_SESSION['language'] = $_POST['language'];
header ('Location: index.php?step=1');
}
}
function saveStep2 () {
if (!empty ($_POST)) {
if (empty ($_POST['title']) ||
empty ($_POST['old_entries']) ||
empty ($_POST['auth_type']) ||
empty ($_POST['default_user'])) {
return false;
}
$_SESSION['salt'] = sha1(uniqid(mt_rand(), true).implode('', stat(__FILE__)));
$_SESSION['title'] = substr(trim($_POST['title']), 0, 25);
$_SESSION['old_entries'] = $_POST['old_entries'];
if ((!ctype_digit($_SESSION['old_entries'])) || ($_SESSION['old_entries'] < 1)) {
$_SESSION['old_entries'] = 3;
}
$_SESSION['mail_login'] = filter_var($_POST['mail_login'], FILTER_VALIDATE_EMAIL);
$_SESSION['default_user'] = substr(preg_replace('/[^a-zA-Z0-9]/', '', $_POST['default_user']), 0, 16);
$_SESSION['auth_type'] = $_POST['auth_type'];
if (!empty($_POST['passwordPlain'])) {
if (!function_exists('password_hash')) {
include_once(LIB_PATH . '/password_compat.php');
}
$passwordHash = password_hash($_POST['passwordPlain'], PASSWORD_BCRYPT, array('cost' => BCRYPT_COST));
$passwordHash = preg_replace('/^\$2[xy]\$/', '\$2a\$', $passwordHash); //Compatibility with bcrypt.js
$_SESSION['passwordHash'] = $passwordHash;
}
$token = '';
if ($_SESSION['mail_login']) {
$token = sha1($_SESSION['salt'] . $_SESSION['mail_login']);
}
$config_array = array (
'language' => $_SESSION['language'],
'theme' => $_SESSION['theme'],
'old_entries' => $_SESSION['old_entries'],
'mail_login' => $_SESSION['mail_login'],
'passwordHash' => $_SESSION['passwordHash'],
'token' => $token,
);
$configPath = DATA_PATH . '/' . $_SESSION['default_user'] . '_user.php';
@unlink($configPath); //To avoid access-rights problems
file_put_contents($configPath, " array(
'environment' => empty($_SESSION['environment']) ? 'production' : $_SESSION['environment'],
'salt' => $_SESSION['salt'],
'base_url' => '',
'title' => $_SESSION['title'],
'default_user' => $_SESSION['default_user'],
'allow_anonymous' => isset($_SESSION['allow_anonymous']) ? $_SESSION['allow_anonymous'] : false,
'allow_anonymous_refresh' => isset($_SESSION['allow_anonymous_refresh']) ? $_SESSION['allow_anonymous_refresh'] : false,
'auth_type' => $_SESSION['auth_type'],
'api_enabled' => isset($_SESSION['api_enabled']) ? $_SESSION['api_enabled'] : false,
'unsafe_autologin_enabled' => isset($_SESSION['unsafe_autologin_enabled']) ? $_SESSION['unsafe_autologin_enabled'] : false,
),
'db' => array(
'type' => $_SESSION['bd_type'],
'host' => $_SESSION['bd_host'],
'user' => $_SESSION['bd_user'],
'password' => $_SESSION['bd_password'],
'base' => $_SESSION['bd_base'],
'prefix' => $_SESSION['bd_prefix'],
),
);
@unlink(DATA_PATH . '/config.php'); //To avoid access-rights problems
file_put_contents(DATA_PATH . '/config.php', " 'SET NAMES utf8',
);
break;
case 'sqlite':
return false; //No update for SQLite needed so far
default:
return false;
}
$c = new PDO($str, $_SESSION['bd_user'], $_SESSION['bd_password'], $driver_options);
$stm = $c->prepare(SQL_SHOW_TABLES);
$stm->execute();
$res = $stm->fetchAll(PDO::FETCH_COLUMN, 0);
if (!in_array($_SESSION['bd_prefix'] . 'entry006', $res)) {
return false;
}
$sql = sprintf(SQL_SHOW_COLUMNS_UPDATEv006, $_SESSION['bd_prefix']);
$stm = $c->prepare($sql);
$stm->execute();
$res = $stm->fetchAll(PDO::FETCH_COLUMN, 0);
if (!in_array('id2', $res)) {
if (!$perform) {
return true;
}
$sql = sprintf(SQL_UPDATEv006, $_SESSION['bd_prefix'], $_SESSION['bd_prefix_user']);
$stm = $c->prepare($sql, array(PDO::ATTR_EMULATE_PREPARES => true));
$stm->execute();
}
$sql = sprintf(SQL_CONVERT_SELECTv006, $_SESSION['bd_prefix'], $_SESSION['bd_prefix_user']);
if (!$perform) {
$sql .= ' LIMIT 1';
}
$stm = $c->prepare($sql);
$stm->execute();
if (!$perform) {
$res = $stm->fetchAll(PDO::FETCH_COLUMN, 0);
return count($res) > 0;
} else {
@set_time_limit(300);
}
$c2 = new PDO($str, $_SESSION['bd_user'], $_SESSION['bd_password'], $driver_options);
$sql = sprintf(SQL_CONVERT_UPDATEv006, $_SESSION['bd_prefix_user']);
$stm2 = $c2->prepare($sql);
while ($row = $stm->fetch(PDO::FETCH_ASSOC)) {
$id = $row['id2'];
$content = unserialize(gzinflate(base64_decode($row['content'])));
$stm2->execute(array($content, $id));
}
return true;
} catch (PDOException $e) {
return false;
}
return false;
}
function newPdo() {
switch ($_SESSION['bd_type']) {
case 'mysql':
$str = 'mysql:host=' . $_SESSION['bd_host'] . ';dbname=' . $_SESSION['bd_base'];
$driver_options = array(
PDO::MYSQL_ATTR_INIT_COMMAND => 'SET NAMES utf8',
);
break;
case 'sqlite':
$str = 'sqlite:' . DATA_PATH . '/' . $_SESSION['default_user'] . '.sqlite';
$driver_options = array(
PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
);
break;
default:
return false;
}
return new PDO($str, $_SESSION['bd_user'], $_SESSION['bd_password'], $driver_options);
}
function postUpdate() {
$c = newPdo();
if ($_SESSION['bd_type'] !== 'sqlite') { //No update for SQLite needed yet
$sql = sprintf(SQL_UPDATE_HISTORYv007b, $_SESSION['bd_prefix_user']);
$stm = $c->prepare($sql);
$stm->execute();
$sql = sprintf(SQL_UPDATE_CACHED_VALUES, $_SESSION['bd_prefix_user']);
$stm = $c->prepare($sql);
$stm->execute();
}
//