aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorFriendika <info@friendika.com>2011-07-06 19:07:43 -0700
committerFriendika <info@friendika.com>2011-07-06 19:07:43 -0700
commit474156b15ce8cc00b3c594b4668f2a658c283522 (patch)
tree27bb8ef2621970e23ed15a96774a9f1a7c53ac69
parent94ca19c016591430ccf2bb8b6a2a2f0239f9cb96 (diff)
downloadvolse-hubzilla-474156b15ce8cc00b3c594b4668f2a658c283522.tar.gz
volse-hubzilla-474156b15ce8cc00b3c594b4668f2a658c283522.tar.bz2
volse-hubzilla-474156b15ce8cc00b3c594b4668f2a658c283522.zip
remove insecure java_uploader, add some debugging to twitter plugin
-rw-r--r--addon/java_upload/java_upload.php103
-rw-r--r--addon/java_upload/jumploader_z.jarbin962772 -> 0 bytes
-rw-r--r--addon/twitter/twitter.php1
3 files changed, 1 insertions, 103 deletions
diff --git a/addon/java_upload/java_upload.php b/addon/java_upload/java_upload.php
deleted file mode 100644
index 09e321f0a..000000000
--- a/addon/java_upload/java_upload.php
+++ /dev/null
@@ -1,103 +0,0 @@
-<?php
-
-/**
- * Name: Java photo uploader
- * Description: WARNING: This module currently has privacy issues. The java package does not pass the permissions array intact and could lead to photos being seen by people that were excluded from seeing them.
- * Version: 1.0
- * Author: Mike Macgirvin <http://macgirvin.com/profile/mike>
- */
-
-/**
- *
- * Java photo uploader, uses Jumploader
- *
- * WARNING: This module currently has privacy issues.
- * The java package does not pass the permissions array intact and could lead to
- * photos being seen by people that were excluded from seeing them.
- *
- */
-
-
-function java_upload_install() {
- register_hook('photo_upload_form', 'addon/java_upload/java_upload.php', 'java_upload_form');
- register_hook('photo_post_init', 'addon/java_upload/java_upload.php', 'java_upload_post_init');
- register_hook('photo_post_end', 'addon/java_upload/java_upload.php', 'java_upload_post_end');
-}
-
-
-function java_upload_uninstall() {
- unregister_hook('photo_upload_form', 'addon/java_upload/java_upload.php', 'java_upload_form');
- unregister_hook('photo_post_init', 'addon/java_upload/java_upload.php', 'java_upload_post_init');
- unregister_hook('photo_post_end', 'addon/java_upload/java_upload.php', 'java_upload_post_end');
-}
-
-
-function java_upload_form(&$a,&$b) {
-
- $uploadurl = $b['post_url'];
- $sessid = session_id();
- $archive = $a->get_baseurl() . '/addon/java_upload/jumploader_z.jar';
- $filestext = t('Select files to upload: ');
-
- $nojava = t('Use the following controls only if the Java uploader [above] fails to launch.');
-
- $b['default_upload'] = true;
-
-
-$b['addon_text'] .= <<< EOT
-
- <div id="photos-upload-select-files-text">$filestext</div>
-
- <div id="photos_upload_applet_wrapper">
- <applet name="jumpLoaderApplet"
- code="jmaster.jumploader.app.JumpLoaderApplet.class"
- archive="$archive"
- width="700"
- height="600"
- mayscript >
- <param name="uc_uploadUrl" value="$uploadurl" />
- <param name="uc_uploadFormName" value="photos-upload-form" />
- <param name="gc_loggingLeveL" value="FATAL" />
- <param name="uc_fileParameterName" value="userfile" />
- <param name="uc_cookie" value="PHPSESSID=$sessid; path=/;" />
- <param name="vc_disableLocalFileSystem" value="false" />
- <param name="vc_uploadViewMenuBarVisible" value="false" />
- <param name="vc_mainViewFileListViewVisible" value="true" />
- <param name="vc_mainViewFileListViewHeightPercent" value="50" />
- <param name="vc_mainViewFileTreeViewVisible" value="true" />
- <param name="vc_mainViewFileTreeViewWidthPercent" value="35" />
- <param name="vc_lookAndFeel" value="system" />
-
- </applet>
-
- </div>
-
- <div id="photos-upload-no-java-message" >
- $nojava
- </div>
-
-EOT;
-
-}
-
-
-
-
-
-function java_upload_photo_post_init(&$a,&$b) {
-
- if($_POST['partitionCount'])
- $a->data['java_upload'] = true;
- else
- $a->data['java_upload'] = false;
-
-
-}
-
-
-function java_upload_photo_post_end(&$a,&$b) {
-
- if(x($a->data,'java_upload') && $a->data['java_upload'])
- killme();
-
-}
diff --git a/addon/java_upload/jumploader_z.jar b/addon/java_upload/jumploader_z.jar
deleted file mode 100644
index 30a85a33f..000000000
--- a/addon/java_upload/jumploader_z.jar
+++ /dev/null
Binary files differ
diff --git a/addon/twitter/twitter.php b/addon/twitter/twitter.php
index 183c71126..1dce9d2f6 100644
--- a/addon/twitter/twitter.php
+++ b/addon/twitter/twitter.php
@@ -216,6 +216,7 @@ function twitter_post_hook(&$a,&$b) {
$twitter_enable = (($twitter_post && x($_POST,'twitter_enable')) ? intval($_POST['twitter_enable']) : 0);
if($twitter_post && $twitter_enable) {
+ logger('Posting to Twitter', LOGGER_DEBUG);
require_once('library/twitteroauth.php');
require_once('include/bbcode.php');
$tweet = new TwitterOAuth($ckey,$csecret,$otoken,$osecret);