aboutsummaryrefslogtreecommitdiffstats
path: root/includes/api/ApiEntryPoint.php
blob: 1f854a881075546f5b72be9b7a2f4b61a1c8d885 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
<?php
/**
 * Entry point implementation for all %Action API queries, handled by ApiMain
 * and ApiBase subclasses.
 *
 * @see /api.php The corresponding HTTP entry point.
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published by
 * the Free Software Foundation; either version 2 of the License, or
 * (at your option) any later version.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License along
 * with this program; if not, write to the Free Software Foundation, Inc.,
 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
 * http://www.gnu.org/copyleft/gpl.html
 *
 * @file
 * @ingroup entrypoint
 * @ingroup API
 */

namespace MediaWiki\Api;

use LogicException;
use MediaWiki\Context\RequestContext;
use MediaWiki\EntryPointEnvironment;
use MediaWiki\HookContainer\HookRunner;
use MediaWiki\MediaWikiEntryPoint;
use MediaWiki\MediaWikiServices;
use MediaWiki\Title\Title;
use Throwable;

/**
 * Implementation of the API entry point, for web browser navigations, usually via an
 * Action or SpecialPage subclass.
 *
 * This is used by bots to fetch content and information about the wiki,
 * its pages, and its users. See <https://www.mediawiki.org/wiki/API> for more
 * information.
 *
 * @see /api.php The corresponding HTTP entry point.
 * @internal
 */
class ApiEntryPoint extends MediaWikiEntryPoint {

	public function __construct(
		RequestContext $context,
		EntryPointEnvironment $environment,
		MediaWikiServices $services
	) {
		parent::__construct(
			$context,
			$environment,
			$services
		);
	}

	/**
	 * Overwritten to narrow the return type to RequestContext
	 */
	protected function getContext(): RequestContext {
		/** @var RequestContext $context */
		$context = parent::getContext();

		// @phan-suppress-next-line PhanTypeMismatchReturnSuperType see $context in the constructor
		return $context;
	}

	/**
	 * Executes a request to the action API.
	 *
	 * It begins by constructing a new ApiMain using the parameter passed to it
	 * as an argument in the URL ('?action='). It then invokes "execute()" on the
	 * ApiMain object instance, which produces output in the format specified in
	 * the URL.
	 */
	protected function execute() {
		// phpcs:ignore MediaWiki.Usage.DeprecatedGlobalVariables.Deprecated$wgTitle
		global $wgTitle;

		$context = $this->getContext();
		$request = $this->getRequest();

		$services = $this->getServiceContainer();

		// PATH_INFO can be used for stupid things. We don't support it for api.php at
		// all, so error out if it's present. (T128209)
		$pathInfo = $this->environment->getServerInfo( 'PATH_INFO', '' );
		if ( $pathInfo != '' ) {
			$correctUrl = wfAppendQuery(
				wfScript( 'api' ),
				$request->getQueryValuesOnly()
			);
			$correctUrl = (string)$services->getUrlUtils()->expand(
				$correctUrl,
				PROTO_CANONICAL
			);
			$this->header(
				"Location: $correctUrl",
				true,
				301
			);
			$this->print(
				'This endpoint does not support "path info", i.e. extra text ' .
				'between "api.php" and the "?". Remove any such text and try again.'
			);
			$this->exit( 1 );
		}

		// Set a dummy $wgTitle, because $wgTitle == null breaks various things
		// In a perfect world this wouldn't be necessary
		$wgTitle = Title::makeTitle(
			NS_SPECIAL,
			'Badtitle/dummy title for API calls set in api.php'
		);

		// RequestContext will read from $wgTitle, but it will also whine about it.
		// In a perfect world this wouldn't be necessary either.
		$context->setTitle( $wgTitle );

		try {
			// Construct an ApiMain with the arguments passed via the URL. What we get back
			// is some form of an ApiMain, possibly even one that produces an error message,
			// but we don't care here, as that is handled by the constructor.
			$processor = new ApiMain(
				$context,
				true,
				false
			);

			// Last chance hook before executing the API
			( new HookRunner( $services->getHookContainer() ) )->onApiBeforeMain( $processor );
			if ( !$processor instanceof ApiMain ) {
				throw new LogicException(
					'ApiBeforeMain hook set $processor to a non-ApiMain class'
				);
			}
		} catch ( Throwable $e ) {
			// Crap. Try to report the exception in API format to be friendly to clients.
			ApiMain::handleApiBeforeMainException( $e );
			$processor = false;
		}

		// Process data & print results
		if ( $processor ) {
			$processor->execute();
		}
	}
}