Files
skyview.astronomiemuseum.de/public/ajax/save_monthly_preview_to_joomla.php
T

271 lines
12 KiB
PHP

<?php
declare(strict_types=1);
session_start();
require_once __DIR__ . '/../auth_helpers.php';
header('Content-Type: application/json; charset=UTF-8');
function respondWithJoomlaPreviewResult(int $statusCode, array $payload): never
{
http_response_code($statusCode);
echo json_encode($payload, JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES);
exit;
}
if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
respondWithJoomlaPreviewResult(405, [
'success' => false,
'message' => 'Nur POST ist erlaubt.',
]);
}
if (!currentUserIsAdminLike()) {
respondWithJoomlaPreviewResult(403, [
'success' => false,
'message' => 'Für den Joomla-Export sind Administratorrechte erforderlich.',
]);
}
$sessionToken = isset($_SESSION['joomla_monthly_preview_token']) && is_string($_SESSION['joomla_monthly_preview_token'])
? $_SESSION['joomla_monthly_preview_token']
: '';
$submittedToken = isset($_POST['joomla_monthly_preview_token']) ? (string) $_POST['joomla_monthly_preview_token'] : '';
if ($sessionToken === '' || $submittedToken === '' || !hash_equals($sessionToken, $submittedToken)) {
respondWithJoomlaPreviewResult(403, [
'success' => false,
'message' => 'Sicherheitsprüfung fehlgeschlagen. Bitte die Seite neu laden und erneut versuchen.',
]);
}
$year = filter_input(INPUT_POST, 'year', FILTER_VALIDATE_INT);
$month = filter_input(INPUT_POST, 'month', FILTER_VALIDATE_INT);
$html = isset($_POST['html']) ? (string) $_POST['html'] : '';
if ($year === false || $year < 2000 || $year > 2100 || $month === false || $month < 1 || $month > 12) {
respondWithJoomlaPreviewResult(400, [
'success' => false,
'message' => 'Ungültiger Monat für den Joomla-Export.',
]);
}
if ($html === '' || strlen($html) > 14 * 1024 * 1024) {
respondWithJoomlaPreviewResult(400, [
'success' => false,
'message' => 'Der HTML-Inhalt fehlt oder ist zu groß.',
]);
}
$monthNames = [
1 => 'Januar', 2 => 'Februar', 3 => 'März', 4 => 'April',
5 => 'Mai', 6 => 'Juni', 7 => 'Juli', 8 => 'August',
9 => 'September', 10 => 'Oktober', 11 => 'November', 12 => 'Dezember',
];
$monthName = $monthNames[$month];
$title = sprintf('Monatsvorschau %s %d', $monthName, $year);
$aliasMonthNames = [
1 => 'januar', 2 => 'februar', 3 => 'maerz', 4 => 'april',
5 => 'mai', 6 => 'juni', 7 => 'juli', 8 => 'august',
9 => 'september', 10 => 'oktober', 11 => 'november', 12 => 'dezember',
];
$alias = sprintf('monatsvorschau-%s-%d', $aliasMonthNames[$month], $year);
$visibilityDate = (new DateTimeImmutable(sprintf('%04d-%02d-01 00:00:00', $year, $month), new DateTimeZone('Europe/Berlin')))
->modify('-5 days')
->format('Y-m-d H:i:s');
$joomlaImagesJson = json_encode([
'image_intro' => '', 'image_intro_alt' => '', 'float_intro' => '', 'image_intro_caption' => '',
'image_fulltext' => '', 'image_fulltext_alt' => '', 'float_fulltext' => '', 'image_fulltext_caption' => '',
], JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES) ?: '{}';
$joomlaUrlsJson = json_encode([
'urla' => '', 'urlatext' => '', 'targeta' => '', 'urlb' => '', 'urlbtext' => '', 'targetb' => '',
'urlc' => '', 'urlctext' => '', 'targetc' => '',
], JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES) ?: '{}';
$joomlaAttribsJson = json_encode([
'article_layout' => '', 'show_title' => '', 'link_titles' => '', 'show_tags' => '', 'show_intro' => '',
'info_block_position' => '', 'info_block_show_title' => '', 'show_category' => '', 'link_category' => '',
'show_parent_category' => '', 'link_parent_category' => '', 'show_author' => '', 'link_author' => '',
'show_create_date' => '', 'show_modify_date' => '', 'show_publish_date' => '', 'show_item_navigation' => '',
'show_hits' => '', 'show_noauth' => '', 'urls_position' => '', 'alternative_readmore' => '',
'article_page_title' => '', 'show_publishing_options' => '', 'show_article_options' => '',
'show_urls_images_backend' => '', 'show_urls_images_frontend' => '',
], JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES) ?: '{}';
$joomlaMetadataJson = json_encode([
'robots' => '', 'author' => '', 'rights' => '',
], JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES) ?: '{}';
try {
$dbConfig = require __DIR__ . '/../../config/observationtips_database.php';
$pdo = new PDO(
sprintf(
'mysql:host=%s;dbname=%s;charset=%s',
$dbConfig['host'],
$dbConfig['dbname'],
$dbConfig['charset'] ?? 'utf8mb4'
),
$dbConfig['user'],
$dbConfig['pass'],
[
PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
]
);
$pdo->beginTransaction();
try {
$existingStmt = $pdo->prepare(
'SELECT `id`, `asset_id`, `created`, `created_by` '
. 'FROM `astro_content` '
. 'WHERE `catid` = 59 AND `title` = :title '
. 'ORDER BY `id` DESC '
. 'LIMIT 1 '
. 'FOR UPDATE'
);
$existingStmt->execute([':title' => $title]);
$existingArticle = $existingStmt->fetch();
$articleId = 0;
if (is_array($existingArticle)) {
$updateStmt = $pdo->prepare(
'UPDATE `astro_content` '
. 'SET `alias` = :alias, `introtext` = :introtext, `fulltext` = \'\', `state` = 1, `created` = :created, '
. '`images` = :images, `urls` = :urls, `attribs` = :attribs, `metadata` = :metadata, '
. '`checked_out` = NULL, `checked_out_time` = NULL, '
. '`modified` = NOW(), `modified_by` = :modified_by, `publish_up` = :publish_up, '
. '`publish_down` = NULL, `version` = `version` + 1 '
. 'WHERE `id` = :id'
);
$updateStmt->execute([
':alias' => $alias,
':introtext' => $html,
':created' => $visibilityDate,
':images' => $joomlaImagesJson,
':urls' => $joomlaUrlsJson,
':attribs' => $joomlaAttribsJson,
':metadata' => $joomlaMetadataJson,
':modified_by' => (int) $existingArticle['created_by'],
':publish_up' => $visibilityDate,
':id' => (int) $existingArticle['id'],
]);
$articleId = (int) $existingArticle['id'];
$result = [
'success' => true,
'message' => sprintf('%s wurde in Joomla aktualisiert.', $title),
'action' => 'updated',
];
} else {
$authorStmt = $pdo->query(
'SELECT `created_by` FROM `astro_content` WHERE `catid` = 59 ORDER BY `id` DESC LIMIT 1'
);
$authorId = (int) $authorStmt->fetchColumn();
if ($authorId <= 0) {
// Kategorie 59 kann beim ersten Export noch leer sein.
// Monatsvorschauen werden dann mit dem festgelegten Joomla-
// Autor angelegt.
$authorId = 217;
}
$insertContentStmt = $pdo->prepare(
'INSERT INTO `astro_content` ('
. '`asset_id`, `title`, `alias`, `introtext`, `fulltext`, `state`, `catid`, `created`, `created_by`, '
. '`modified`, `modified_by`, `checked_out`, `checked_out_time`, `publish_up`, `publish_down`, '
. '`images`, `urls`, `attribs`, `version`, `ordering`, `metakey`, `metadesc`, `access`, `hits`, '
. '`metadata`, `featured`, `language`, `note` '
. ') VALUES (0, :title, :alias, :introtext, \'\', 1, 59, :created, :created_by, '
. 'NOW(), :modified_by, NULL, NULL, :publish_up, NULL, :images, :urls, :attribs, 1, 0, \'\', \'\', 1, 0, '
. ':metadata, 0, \'*\', \'\')'
);
$insertContentStmt->execute([
':title' => $title,
':alias' => $alias,
':introtext' => $html,
':created' => $visibilityDate,
':created_by' => $authorId,
':modified_by' => $authorId,
':publish_up' => $visibilityDate,
':images' => $joomlaImagesJson,
':urls' => $joomlaUrlsJson,
':attribs' => $joomlaAttribsJson,
':metadata' => $joomlaMetadataJson,
]);
$articleId = (int) $pdo->lastInsertId();
// Joomla speichert Artikelrechte als Knoten im Asset-Baum.
$categoryAssetStmt = $pdo->query(
'SELECT `id`, `rgt`, `level` FROM `astro_assets` WHERE `id` = 740 FOR UPDATE'
);
$categoryAsset = $categoryAssetStmt->fetch();
if (!is_array($categoryAsset)) {
throw new RuntimeException('Die Joomla-Kategorie für Monatsvorschauen wurde nicht gefunden.');
}
$newLeft = (int) $categoryAsset['rgt'];
$pdo->prepare('UPDATE `astro_assets` SET `rgt` = `rgt` + 2 WHERE `rgt` >= :position')
->execute([':position' => $newLeft]);
$pdo->prepare('UPDATE `astro_assets` SET `lft` = `lft` + 2 WHERE `lft` > :position')
->execute([':position' => $newLeft]);
$insertAssetStmt = $pdo->prepare(
'INSERT INTO `astro_assets` (`parent_id`, `lft`, `rgt`, `level`, `name`, `title`, `rules`) '
. 'VALUES (740, :lft, :rgt, :level, :name, :title, \'{}\')'
);
$insertAssetStmt->execute([
':lft' => $newLeft,
':rgt' => $newLeft + 1,
':level' => (int) $categoryAsset['level'] + 1,
':name' => 'com_content.article.' . $articleId,
':title' => $title,
]);
$pdo->prepare('UPDATE `astro_content` SET `asset_id` = :asset_id WHERE `id` = :id')
->execute([
':asset_id' => (int) $pdo->lastInsertId(),
':id' => $articleId,
]);
$result = [
'success' => true,
'message' => sprintf('%s wurde in Joomla angelegt.', $title),
'action' => 'created',
];
}
// Joomla 5 zeigt Artikel nur mit einer Workflow-Stufenzuordnung zuverlässig im Backend an.
$workflowStageStmt = $pdo->query(
'SELECT `id` FROM `astro_workflow_stages` '
. 'WHERE `workflow_id` = 1 AND `default` = 1 AND `published` = 1 '
. 'ORDER BY `id` ASC LIMIT 1'
);
$workflowStageId = (int) $workflowStageStmt->fetchColumn();
if ($workflowStageId <= 0) {
throw new RuntimeException('Die Joomla-Standard-Workflow-Stufe wurde nicht gefunden.');
}
$workflowAssociationStmt = $pdo->prepare(
'INSERT IGNORE INTO `astro_workflow_associations` (`item_id`, `stage_id`, `extension`) '
. 'VALUES (:item_id, :stage_id, \'com_content.article\')'
);
$workflowAssociationStmt->execute([
':item_id' => $articleId,
':stage_id' => $workflowStageId,
]);
$pdo->commit();
} catch (Throwable $e) {
if ($pdo->inTransaction()) {
$pdo->rollBack();
}
throw $e;
}
respondWithJoomlaPreviewResult(200, $result);
} catch (Throwable $e) {
error_log('Joomla-Monatsvorschau konnte nicht gespeichert werden: ' . $e->getMessage());
respondWithJoomlaPreviewResult(500, [
'success' => false,
'message' => 'Die Monatsvorschau konnte nicht in Joomla gespeichert werden.',
]);
}