]> scripts.mit.edu Git - autoinstallsdev/mediawiki.git/blob - includes/api/ApiQueryDeletedrevs.php
MediaWiki 1.30.2
[autoinstallsdev/mediawiki.git] / includes / api / ApiQueryDeletedrevs.php
1 <?php
2 /**
3  *
4  *
5  * Created on Jul 2, 2007
6  *
7  * Copyright © 2007 Roan Kattouw "<Firstname>.<Lastname>@gmail.com"
8  *
9  * This program is free software; you can redistribute it and/or modify
10  * it under the terms of the GNU General Public License as published by
11  * the Free Software Foundation; either version 2 of the License, or
12  * (at your option) any later version.
13  *
14  * This program is distributed in the hope that it will be useful,
15  * but WITHOUT ANY WARRANTY; without even the implied warranty of
16  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17  * GNU General Public License for more details.
18  *
19  * You should have received a copy of the GNU General Public License along
20  * with this program; if not, write to the Free Software Foundation, Inc.,
21  * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
22  * http://www.gnu.org/copyleft/gpl.html
23  *
24  * @file
25  */
26
27 /**
28  * Query module to enumerate all deleted revisions.
29  *
30  * @ingroup API
31  * @deprecated since 1.25
32  */
33 class ApiQueryDeletedrevs extends ApiQueryBase {
34
35         public function __construct( ApiQuery $query, $moduleName ) {
36                 parent::__construct( $query, $moduleName, 'dr' );
37         }
38
39         public function execute() {
40                 // Before doing anything at all, let's check permissions
41                 $this->checkUserRightsAny( 'deletedhistory' );
42
43                 $this->addDeprecation( 'apiwarn-deprecation-deletedrevs', 'action=query&list=deletedrevs' );
44
45                 $user = $this->getUser();
46                 $db = $this->getDB();
47                 $commentStore = new CommentStore( 'ar_comment' );
48                 $params = $this->extractRequestParams( false );
49                 $prop = array_flip( $params['prop'] );
50                 $fld_parentid = isset( $prop['parentid'] );
51                 $fld_revid = isset( $prop['revid'] );
52                 $fld_user = isset( $prop['user'] );
53                 $fld_userid = isset( $prop['userid'] );
54                 $fld_comment = isset( $prop['comment'] );
55                 $fld_parsedcomment = isset( $prop['parsedcomment'] );
56                 $fld_minor = isset( $prop['minor'] );
57                 $fld_len = isset( $prop['len'] );
58                 $fld_sha1 = isset( $prop['sha1'] );
59                 $fld_content = isset( $prop['content'] );
60                 $fld_token = isset( $prop['token'] );
61                 $fld_tags = isset( $prop['tags'] );
62
63                 if ( isset( $prop['token'] ) ) {
64                         $p = $this->getModulePrefix();
65                 }
66
67                 // If we're in a mode that breaks the same-origin policy, no tokens can
68                 // be obtained
69                 if ( $this->lacksSameOriginSecurity() ) {
70                         $fld_token = false;
71                 }
72
73                 // If user can't undelete, no tokens
74                 if ( !$user->isAllowed( 'undelete' ) ) {
75                         $fld_token = false;
76                 }
77
78                 $result = $this->getResult();
79                 $pageSet = $this->getPageSet();
80                 $titles = $pageSet->getTitles();
81
82                 // This module operates in three modes:
83                 // 'revs': List deleted revs for certain titles (1)
84                 // 'user': List deleted revs by a certain user (2)
85                 // 'all': List all deleted revs in NS (3)
86                 $mode = 'all';
87                 if ( count( $titles ) > 0 ) {
88                         $mode = 'revs';
89                 } elseif ( !is_null( $params['user'] ) ) {
90                         $mode = 'user';
91                 }
92
93                 if ( $mode == 'revs' || $mode == 'user' ) {
94                         // Ignore namespace and unique due to inability to know whether they were purposely set
95                         foreach ( [ 'from', 'to', 'prefix', /*'namespace', 'unique'*/ ] as $p ) {
96                                 if ( !is_null( $params[$p] ) ) {
97                                         $this->dieWithError( [ 'apierror-deletedrevs-param-not-1-2', $p ], 'badparams' );
98                                 }
99                         }
100                 } else {
101                         foreach ( [ 'start', 'end' ] as $p ) {
102                                 if ( !is_null( $params[$p] ) ) {
103                                         $this->dieWithError( [ 'apierror-deletedrevs-param-not-3', $p ], 'badparams' );
104                                 }
105                         }
106                 }
107
108                 if ( !is_null( $params['user'] ) && !is_null( $params['excludeuser'] ) ) {
109                         $this->dieWithError( 'user and excludeuser cannot be used together', 'badparams' );
110                 }
111
112                 $this->addTables( 'archive' );
113                 $this->addFields( [ 'ar_title', 'ar_namespace', 'ar_timestamp', 'ar_deleted', 'ar_id' ] );
114
115                 $this->addFieldsIf( 'ar_parent_id', $fld_parentid );
116                 $this->addFieldsIf( 'ar_rev_id', $fld_revid );
117                 $this->addFieldsIf( 'ar_user_text', $fld_user );
118                 $this->addFieldsIf( 'ar_user', $fld_userid );
119                 $this->addFieldsIf( 'ar_minor_edit', $fld_minor );
120                 $this->addFieldsIf( 'ar_len', $fld_len );
121                 $this->addFieldsIf( 'ar_sha1', $fld_sha1 );
122
123                 if ( $fld_comment || $fld_parsedcomment ) {
124                         $commentQuery = $commentStore->getJoin();
125                         $this->addTables( $commentQuery['tables'] );
126                         $this->addFields( $commentQuery['fields'] );
127                         $this->addJoinConds( $commentQuery['joins'] );
128                 }
129
130                 if ( $fld_tags ) {
131                         $this->addTables( 'tag_summary' );
132                         $this->addJoinConds(
133                                 [ 'tag_summary' => [ 'LEFT JOIN', [ 'ar_rev_id=ts_rev_id' ] ] ]
134                         );
135                         $this->addFields( 'ts_tags' );
136                 }
137
138                 if ( !is_null( $params['tag'] ) ) {
139                         $this->addTables( 'change_tag' );
140                         $this->addJoinConds(
141                                 [ 'change_tag' => [ 'INNER JOIN', [ 'ar_rev_id=ct_rev_id' ] ] ]
142                         );
143                         $this->addWhereFld( 'ct_tag', $params['tag'] );
144                 }
145
146                 if ( $fld_content ) {
147                         // Modern MediaWiki has the content for deleted revs in the 'text'
148                         // table using fields old_text and old_flags. But revisions deleted
149                         // pre-1.5 store the content in the 'archive' table directly using
150                         // fields ar_text and ar_flags, and no corresponding 'text' row. So
151                         // we have to LEFT JOIN and fetch all four fields, plus ar_text_id
152                         // to be able to tell the difference.
153                         $this->addTables( 'text' );
154                         $this->addJoinConds(
155                                 [ 'text' => [ 'LEFT JOIN', [ 'ar_text_id=old_id' ] ] ]
156                         );
157                         $this->addFields( [ 'ar_text', 'ar_flags', 'ar_text_id', 'old_text', 'old_flags' ] );
158
159                         // This also means stricter restrictions
160                         $this->checkUserRightsAny( [ 'deletedtext', 'undelete' ] );
161                 }
162                 // Check limits
163                 $userMax = $fld_content ? ApiBase::LIMIT_SML1 : ApiBase::LIMIT_BIG1;
164                 $botMax = $fld_content ? ApiBase::LIMIT_SML2 : ApiBase::LIMIT_BIG2;
165
166                 $limit = $params['limit'];
167
168                 if ( $limit == 'max' ) {
169                         $limit = $this->getMain()->canApiHighLimits() ? $botMax : $userMax;
170                         $this->getResult()->addParsedLimit( $this->getModuleName(), $limit );
171                 }
172
173                 $this->validateLimit( 'limit', $limit, 1, $userMax, $botMax );
174
175                 if ( $fld_token ) {
176                         // Undelete tokens are identical for all pages, so we cache one here
177                         $token = $user->getEditToken( '', $this->getMain()->getRequest() );
178                 }
179
180                 $dir = $params['dir'];
181
182                 // We need a custom WHERE clause that matches all titles.
183                 if ( $mode == 'revs' ) {
184                         $lb = new LinkBatch( $titles );
185                         $where = $lb->constructSet( 'ar', $db );
186                         $this->addWhere( $where );
187                 } elseif ( $mode == 'all' ) {
188                         $this->addWhereFld( 'ar_namespace', $params['namespace'] );
189
190                         $from = $params['from'] === null
191                                 ? null
192                                 : $this->titlePartToKey( $params['from'], $params['namespace'] );
193                         $to = $params['to'] === null
194                                 ? null
195                                 : $this->titlePartToKey( $params['to'], $params['namespace'] );
196                         $this->addWhereRange( 'ar_title', $dir, $from, $to );
197
198                         if ( isset( $params['prefix'] ) ) {
199                                 $this->addWhere( 'ar_title' . $db->buildLike(
200                                         $this->titlePartToKey( $params['prefix'], $params['namespace'] ),
201                                         $db->anyString() ) );
202                         }
203                 }
204
205                 if ( !is_null( $params['user'] ) ) {
206                         $this->addWhereFld( 'ar_user_text', $params['user'] );
207                 } elseif ( !is_null( $params['excludeuser'] ) ) {
208                         $this->addWhere( 'ar_user_text != ' .
209                                 $db->addQuotes( $params['excludeuser'] ) );
210                 }
211
212                 if ( !is_null( $params['user'] ) || !is_null( $params['excludeuser'] ) ) {
213                         // Paranoia: avoid brute force searches (T19342)
214                         // (shouldn't be able to get here without 'deletedhistory', but
215                         // check it again just in case)
216                         if ( !$user->isAllowed( 'deletedhistory' ) ) {
217                                 $bitmask = Revision::DELETED_USER;
218                         } elseif ( !$user->isAllowedAny( 'suppressrevision', 'viewsuppressed' ) ) {
219                                 $bitmask = Revision::DELETED_USER | Revision::DELETED_RESTRICTED;
220                         } else {
221                                 $bitmask = 0;
222                         }
223                         if ( $bitmask ) {
224                                 $this->addWhere( $db->bitAnd( 'ar_deleted', $bitmask ) . " != $bitmask" );
225                         }
226                 }
227
228                 if ( !is_null( $params['continue'] ) ) {
229                         $cont = explode( '|', $params['continue'] );
230                         $op = ( $dir == 'newer' ? '>' : '<' );
231                         if ( $mode == 'all' || $mode == 'revs' ) {
232                                 $this->dieContinueUsageIf( count( $cont ) != 4 );
233                                 $ns = intval( $cont[0] );
234                                 $this->dieContinueUsageIf( strval( $ns ) !== $cont[0] );
235                                 $title = $db->addQuotes( $cont[1] );
236                                 $ts = $db->addQuotes( $db->timestamp( $cont[2] ) );
237                                 $ar_id = (int)$cont[3];
238                                 $this->dieContinueUsageIf( strval( $ar_id ) !== $cont[3] );
239                                 $this->addWhere( "ar_namespace $op $ns OR " .
240                                         "(ar_namespace = $ns AND " .
241                                         "(ar_title $op $title OR " .
242                                         "(ar_title = $title AND " .
243                                         "(ar_timestamp $op $ts OR " .
244                                         "(ar_timestamp = $ts AND " .
245                                         "ar_id $op= $ar_id)))))" );
246                         } else {
247                                 $this->dieContinueUsageIf( count( $cont ) != 2 );
248                                 $ts = $db->addQuotes( $db->timestamp( $cont[0] ) );
249                                 $ar_id = (int)$cont[1];
250                                 $this->dieContinueUsageIf( strval( $ar_id ) !== $cont[1] );
251                                 $this->addWhere( "ar_timestamp $op $ts OR " .
252                                         "(ar_timestamp = $ts AND " .
253                                         "ar_id $op= $ar_id)" );
254                         }
255                 }
256
257                 $this->addOption( 'LIMIT', $limit + 1 );
258                 $this->addOption(
259                         'USE INDEX',
260                         [ 'archive' => ( $mode == 'user' ? 'ar_usertext_timestamp' : 'name_title_timestamp' ) ]
261                 );
262                 if ( $mode == 'all' ) {
263                         if ( $params['unique'] ) {
264                                 // @todo Does this work on non-MySQL?
265                                 $this->addOption( 'GROUP BY', 'ar_title' );
266                         } else {
267                                 $sort = ( $dir == 'newer' ? '' : ' DESC' );
268                                 $this->addOption( 'ORDER BY', [
269                                         'ar_title' . $sort,
270                                         'ar_timestamp' . $sort,
271                                         'ar_id' . $sort,
272                                 ] );
273                         }
274                 } else {
275                         if ( $mode == 'revs' ) {
276                                 // Sort by ns and title in the same order as timestamp for efficiency
277                                 $this->addWhereRange( 'ar_namespace', $dir, null, null );
278                                 $this->addWhereRange( 'ar_title', $dir, null, null );
279                         }
280                         $this->addTimestampWhereRange( 'ar_timestamp', $dir, $params['start'], $params['end'] );
281                         // Include in ORDER BY for uniqueness
282                         $this->addWhereRange( 'ar_id', $dir, null, null );
283                 }
284                 $res = $this->select( __METHOD__ );
285                 $pageMap = []; // Maps ns&title to (fake) pageid
286                 $count = 0;
287                 $newPageID = 0;
288                 foreach ( $res as $row ) {
289                         if ( ++$count > $limit ) {
290                                 // We've had enough
291                                 if ( $mode == 'all' || $mode == 'revs' ) {
292                                         $this->setContinueEnumParameter( 'continue',
293                                                 "$row->ar_namespace|$row->ar_title|$row->ar_timestamp|$row->ar_id"
294                                         );
295                                 } else {
296                                         $this->setContinueEnumParameter( 'continue', "$row->ar_timestamp|$row->ar_id" );
297                                 }
298                                 break;
299                         }
300
301                         $rev = [];
302                         $anyHidden = false;
303
304                         $rev['timestamp'] = wfTimestamp( TS_ISO_8601, $row->ar_timestamp );
305                         if ( $fld_revid ) {
306                                 $rev['revid'] = intval( $row->ar_rev_id );
307                         }
308                         if ( $fld_parentid && !is_null( $row->ar_parent_id ) ) {
309                                 $rev['parentid'] = intval( $row->ar_parent_id );
310                         }
311                         if ( $fld_user || $fld_userid ) {
312                                 if ( $row->ar_deleted & Revision::DELETED_USER ) {
313                                         $rev['userhidden'] = true;
314                                         $anyHidden = true;
315                                 }
316                                 if ( Revision::userCanBitfield( $row->ar_deleted, Revision::DELETED_USER, $user ) ) {
317                                         if ( $fld_user ) {
318                                                 $rev['user'] = $row->ar_user_text;
319                                         }
320                                         if ( $fld_userid ) {
321                                                 $rev['userid'] = (int)$row->ar_user;
322                                         }
323                                 }
324                         }
325
326                         if ( $fld_comment || $fld_parsedcomment ) {
327                                 if ( $row->ar_deleted & Revision::DELETED_COMMENT ) {
328                                         $rev['commenthidden'] = true;
329                                         $anyHidden = true;
330                                 }
331                                 if ( Revision::userCanBitfield( $row->ar_deleted, Revision::DELETED_COMMENT, $user ) ) {
332                                         $comment = $commentStore->getComment( $row )->text;
333                                         if ( $fld_comment ) {
334                                                 $rev['comment'] = $comment;
335                                         }
336                                         if ( $fld_parsedcomment ) {
337                                                 $title = Title::makeTitle( $row->ar_namespace, $row->ar_title );
338                                                 $rev['parsedcomment'] = Linker::formatComment( $comment, $title );
339                                         }
340                                 }
341                         }
342
343                         if ( $fld_minor ) {
344                                 $rev['minor'] = $row->ar_minor_edit == 1;
345                         }
346                         if ( $fld_len ) {
347                                 $rev['len'] = $row->ar_len;
348                         }
349                         if ( $fld_sha1 ) {
350                                 if ( $row->ar_deleted & Revision::DELETED_TEXT ) {
351                                         $rev['sha1hidden'] = true;
352                                         $anyHidden = true;
353                                 }
354                                 if ( Revision::userCanBitfield( $row->ar_deleted, Revision::DELETED_TEXT, $user ) ) {
355                                         if ( $row->ar_sha1 != '' ) {
356                                                 $rev['sha1'] = Wikimedia\base_convert( $row->ar_sha1, 36, 16, 40 );
357                                         } else {
358                                                 $rev['sha1'] = '';
359                                         }
360                                 }
361                         }
362                         if ( $fld_content ) {
363                                 if ( $row->ar_deleted & Revision::DELETED_TEXT ) {
364                                         $rev['texthidden'] = true;
365                                         $anyHidden = true;
366                                 }
367                                 if ( Revision::userCanBitfield( $row->ar_deleted, Revision::DELETED_TEXT, $user ) ) {
368                                         if ( isset( $row->ar_text ) && !$row->ar_text_id ) {
369                                                 // Pre-1.5 ar_text row (if condition from Revision::newFromArchiveRow)
370                                                 ApiResult::setContentValue( $rev, 'text', Revision::getRevisionText( $row, 'ar_' ) );
371                                         } else {
372                                                 ApiResult::setContentValue( $rev, 'text', Revision::getRevisionText( $row ) );
373                                         }
374                                 }
375                         }
376
377                         if ( $fld_tags ) {
378                                 if ( $row->ts_tags ) {
379                                         $tags = explode( ',', $row->ts_tags );
380                                         ApiResult::setIndexedTagName( $tags, 'tag' );
381                                         $rev['tags'] = $tags;
382                                 } else {
383                                         $rev['tags'] = [];
384                                 }
385                         }
386
387                         if ( $anyHidden && ( $row->ar_deleted & Revision::DELETED_RESTRICTED ) ) {
388                                 $rev['suppressed'] = true;
389                         }
390
391                         if ( !isset( $pageMap[$row->ar_namespace][$row->ar_title] ) ) {
392                                 $pageID = $newPageID++;
393                                 $pageMap[$row->ar_namespace][$row->ar_title] = $pageID;
394                                 $a['revisions'] = [ $rev ];
395                                 ApiResult::setIndexedTagName( $a['revisions'], 'rev' );
396                                 $title = Title::makeTitle( $row->ar_namespace, $row->ar_title );
397                                 ApiQueryBase::addTitleInfo( $a, $title );
398                                 if ( $fld_token ) {
399                                         $a['token'] = $token;
400                                 }
401                                 $fit = $result->addValue( [ 'query', $this->getModuleName() ], $pageID, $a );
402                         } else {
403                                 $pageID = $pageMap[$row->ar_namespace][$row->ar_title];
404                                 $fit = $result->addValue(
405                                         [ 'query', $this->getModuleName(), $pageID, 'revisions' ],
406                                         null, $rev );
407                         }
408                         if ( !$fit ) {
409                                 if ( $mode == 'all' || $mode == 'revs' ) {
410                                         $this->setContinueEnumParameter( 'continue',
411                                                 "$row->ar_namespace|$row->ar_title|$row->ar_timestamp|$row->ar_id"
412                                         );
413                                 } else {
414                                         $this->setContinueEnumParameter( 'continue', "$row->ar_timestamp|$row->ar_id" );
415                                 }
416                                 break;
417                         }
418                 }
419                 $result->addIndexedTagName( [ 'query', $this->getModuleName() ], 'page' );
420         }
421
422         public function isDeprecated() {
423                 return true;
424         }
425
426         public function getAllowedParams() {
427                 return [
428                         'start' => [
429                                 ApiBase::PARAM_TYPE => 'timestamp',
430                                 ApiBase::PARAM_HELP_MSG_INFO => [ [ 'modes', 1, 2 ] ],
431                         ],
432                         'end' => [
433                                 ApiBase::PARAM_TYPE => 'timestamp',
434                                 ApiBase::PARAM_HELP_MSG_INFO => [ [ 'modes', 1, 2 ] ],
435                         ],
436                         'dir' => [
437                                 ApiBase::PARAM_TYPE => [
438                                         'newer',
439                                         'older'
440                                 ],
441                                 ApiBase::PARAM_DFLT => 'older',
442                                 ApiBase::PARAM_HELP_MSG => 'api-help-param-direction',
443                                 ApiBase::PARAM_HELP_MSG_INFO => [ [ 'modes', 1, 3 ] ],
444                         ],
445                         'from' => [
446                                 ApiBase::PARAM_HELP_MSG_INFO => [ [ 'modes', 3 ] ],
447                         ],
448                         'to' => [
449                                 ApiBase::PARAM_HELP_MSG_INFO => [ [ 'modes', 3 ] ],
450                         ],
451                         'prefix' => [
452                                 ApiBase::PARAM_HELP_MSG_INFO => [ [ 'modes', 3 ] ],
453                         ],
454                         'unique' => [
455                                 ApiBase::PARAM_DFLT => false,
456                                 ApiBase::PARAM_HELP_MSG_INFO => [ [ 'modes', 3 ] ],
457                         ],
458                         'namespace' => [
459                                 ApiBase::PARAM_TYPE => 'namespace',
460                                 ApiBase::PARAM_DFLT => NS_MAIN,
461                                 ApiBase::PARAM_HELP_MSG_INFO => [ [ 'modes', 3 ] ],
462                         ],
463                         'tag' => null,
464                         'user' => [
465                                 ApiBase::PARAM_TYPE => 'user'
466                         ],
467                         'excludeuser' => [
468                                 ApiBase::PARAM_TYPE => 'user'
469                         ],
470                         'prop' => [
471                                 ApiBase::PARAM_DFLT => 'user|comment',
472                                 ApiBase::PARAM_TYPE => [
473                                         'revid',
474                                         'parentid',
475                                         'user',
476                                         'userid',
477                                         'comment',
478                                         'parsedcomment',
479                                         'minor',
480                                         'len',
481                                         'sha1',
482                                         'content',
483                                         'token',
484                                         'tags'
485                                 ],
486                                 ApiBase::PARAM_ISMULTI => true
487                         ],
488                         'limit' => [
489                                 ApiBase::PARAM_DFLT => 10,
490                                 ApiBase::PARAM_TYPE => 'limit',
491                                 ApiBase::PARAM_MIN => 1,
492                                 ApiBase::PARAM_MAX => ApiBase::LIMIT_BIG1,
493                                 ApiBase::PARAM_MAX2 => ApiBase::LIMIT_BIG2
494                         ],
495                         'continue' => [
496                                 ApiBase::PARAM_HELP_MSG => 'api-help-param-continue',
497                         ],
498                 ];
499         }
500
501         protected function getExamplesMessages() {
502                 return [
503                         'action=query&list=deletedrevs&titles=Main%20Page|Talk:Main%20Page&' .
504                                 'drprop=user|comment|content'
505                                 => 'apihelp-query+deletedrevs-example-mode1',
506                         'action=query&list=deletedrevs&druser=Bob&drlimit=50'
507                                 => 'apihelp-query+deletedrevs-example-mode2',
508                         'action=query&list=deletedrevs&drdir=newer&drlimit=50'
509                                 => 'apihelp-query+deletedrevs-example-mode3-main',
510                         'action=query&list=deletedrevs&drdir=newer&drlimit=50&drnamespace=1&drunique='
511                                 => 'apihelp-query+deletedrevs-example-mode3-talk',
512                 ];
513         }
514
515         public function getHelpUrls() {
516                 return 'https://www.mediawiki.org/wiki/Special:MyLanguage/API:Deletedrevs';
517         }
518 }