|
@@ -3,8 +3,10 @@ require_once "utils.php";
|
3
|
3
|
|
4
|
4
|
function check_token()
|
5
|
5
|
{
|
6
|
|
- if (!check_table_field("Authorization", "tokens", "token"))
|
|
6
|
+ $token = check_table_field("Authorization", "tokens", "token");
|
|
7
|
+ if ($token === false)
|
7
|
8
|
error(401, "Invalid token");
|
|
9
|
+ return $token;
|
8
|
10
|
}
|
9
|
11
|
|
10
|
12
|
function status_confirm($id)
|
|
@@ -14,8 +16,29 @@ function status_confirm($id)
|
14
|
16
|
|
15
|
17
|
function status_create()
|
16
|
18
|
{
|
17
|
|
- check_token();
|
|
19
|
+ $token = check_token();
|
18
|
20
|
$status = get_post("status");
|
|
21
|
+ if (strlen($status) < 10)
|
|
22
|
+ error(422, "Status too short");
|
|
23
|
+ $latitude = get_post("latitude", false);
|
|
24
|
+ $longitude = get_post("longitude", false);
|
|
25
|
+ $u = database_exec("SELECT `id`, `username` FROM users WHERE `id` = ".
|
|
26
|
+ "(SELECT `user` FROM tokens WHERE `token` = :token)",
|
|
27
|
+ array(":token" => $token))->fetch();
|
|
28
|
+ database_exec("INSERT INTO status (`status`, `user`) VALUES(:status, :user)",
|
|
29
|
+ array(":status" => $status, ":user" => $u["id"]));
|
|
30
|
+ $s = database_exec("SELECT * FROM status WHERE id = :id",
|
|
31
|
+ array(":id" => database_get()->lastInsertId()))->fetch();
|
|
32
|
+ echo json_encode(array("status" => $s["status"],
|
|
33
|
+ "creation_date" => $s['date'],
|
|
34
|
+ /*"nb_confirm_up" => intval($s["up"]),
|
|
35
|
+ "nb_confirm_down" => intval($s["down"]),*/
|
|
36
|
+ "latitude" => $s["latitude"] === null ? null : floatval($s["latitude"]),
|
|
37
|
+ "longitude" => $s["longitude"] === null ? null : floatval($s["longitude"]),
|
|
38
|
+ "media_url" => $s["media"],
|
|
39
|
+ "id" => $s["id"],
|
|
40
|
+ "user_id" => $u["id"]
|
|
41
|
+ ));
|
19
|
42
|
}
|
20
|
43
|
|
21
|
44
|
function status_feed()
|