1
0

InvitationResponseController.php 5.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204
  1. <?php
  2. declare(strict_types=1);
  3. /**
  4. * SPDX-FileCopyrightText: 2018 Nextcloud GmbH and Nextcloud contributors
  5. * SPDX-License-Identifier: AGPL-3.0-or-later
  6. */
  7. namespace OCA\DAV\Controller;
  8. use OCA\DAV\CalDAV\InvitationResponse\InvitationResponseServer;
  9. use OCP\AppFramework\Controller;
  10. use OCP\AppFramework\Http\Attribute\NoCSRFRequired;
  11. use OCP\AppFramework\Http\Attribute\OpenAPI;
  12. use OCP\AppFramework\Http\Attribute\PublicPage;
  13. use OCP\AppFramework\Http\TemplateResponse;
  14. use OCP\AppFramework\Utility\ITimeFactory;
  15. use OCP\IDBConnection;
  16. use OCP\IRequest;
  17. use Sabre\VObject\ITip\Message;
  18. use Sabre\VObject\Reader;
  19. #[OpenAPI(scope: OpenAPI::SCOPE_IGNORE)]
  20. class InvitationResponseController extends Controller {
  21. /**
  22. * InvitationResponseController constructor.
  23. *
  24. * @param string $appName
  25. * @param IRequest $request
  26. * @param IDBConnection $db
  27. * @param ITimeFactory $timeFactory
  28. * @param InvitationResponseServer $responseServer
  29. */
  30. public function __construct(
  31. string $appName,
  32. IRequest $request,
  33. private IDBConnection $db,
  34. private ITimeFactory $timeFactory,
  35. private InvitationResponseServer $responseServer,
  36. ) {
  37. parent::__construct($appName, $request);
  38. // Don't run `$server->exec()`, because we just need access to the
  39. // fully initialized schedule plugin, but we don't want Sabre/DAV
  40. // to actually handle and reply to the request
  41. }
  42. /**
  43. * @param string $token
  44. * @return TemplateResponse
  45. */
  46. #[PublicPage]
  47. #[NoCSRFRequired]
  48. public function accept(string $token):TemplateResponse {
  49. $row = $this->getTokenInformation($token);
  50. if (!$row) {
  51. return new TemplateResponse($this->appName, 'schedule-response-error', [], 'guest');
  52. }
  53. $iTipMessage = $this->buildITipResponse($row, 'ACCEPTED');
  54. $this->responseServer->handleITipMessage($iTipMessage);
  55. if ($iTipMessage->getScheduleStatus() === '1.2') {
  56. return new TemplateResponse($this->appName, 'schedule-response-success', [], 'guest');
  57. }
  58. return new TemplateResponse($this->appName, 'schedule-response-error', [
  59. 'organizer' => $row['organizer'],
  60. ], 'guest');
  61. }
  62. /**
  63. * @param string $token
  64. * @return TemplateResponse
  65. */
  66. #[PublicPage]
  67. #[NoCSRFRequired]
  68. public function decline(string $token):TemplateResponse {
  69. $row = $this->getTokenInformation($token);
  70. if (!$row) {
  71. return new TemplateResponse($this->appName, 'schedule-response-error', [], 'guest');
  72. }
  73. $iTipMessage = $this->buildITipResponse($row, 'DECLINED');
  74. $this->responseServer->handleITipMessage($iTipMessage);
  75. if ($iTipMessage->getScheduleStatus() === '1.2') {
  76. return new TemplateResponse($this->appName, 'schedule-response-success', [], 'guest');
  77. }
  78. return new TemplateResponse($this->appName, 'schedule-response-error', [
  79. 'organizer' => $row['organizer'],
  80. ], 'guest');
  81. }
  82. /**
  83. * @param string $token
  84. * @return TemplateResponse
  85. */
  86. #[PublicPage]
  87. #[NoCSRFRequired]
  88. public function options(string $token):TemplateResponse {
  89. return new TemplateResponse($this->appName, 'schedule-response-options', [
  90. 'token' => $token
  91. ], 'guest');
  92. }
  93. /**
  94. * @param string $token
  95. *
  96. * @return TemplateResponse
  97. */
  98. #[PublicPage]
  99. #[NoCSRFRequired]
  100. public function processMoreOptionsResult(string $token):TemplateResponse {
  101. $partstat = $this->request->getParam('partStat');
  102. $row = $this->getTokenInformation($token);
  103. if (!$row || !\in_array($partstat, ['ACCEPTED', 'DECLINED', 'TENTATIVE'])) {
  104. return new TemplateResponse($this->appName, 'schedule-response-error', [], 'guest');
  105. }
  106. $iTipMessage = $this->buildITipResponse($row, $partstat);
  107. $this->responseServer->handleITipMessage($iTipMessage);
  108. if ($iTipMessage->getScheduleStatus() === '1.2') {
  109. return new TemplateResponse($this->appName, 'schedule-response-success', [], 'guest');
  110. }
  111. return new TemplateResponse($this->appName, 'schedule-response-error', [
  112. 'organizer' => $row['organizer'],
  113. ], 'guest');
  114. }
  115. /**
  116. * @param string $token
  117. * @return array|null
  118. */
  119. private function getTokenInformation(string $token) {
  120. $query = $this->db->getQueryBuilder();
  121. $query->select('*')
  122. ->from('calendar_invitations')
  123. ->where($query->expr()->eq('token', $query->createNamedParameter($token)));
  124. $stmt = $query->executeQuery();
  125. $row = $stmt->fetch(\PDO::FETCH_ASSOC);
  126. $stmt->closeCursor();
  127. if (!$row) {
  128. return null;
  129. }
  130. $currentTime = $this->timeFactory->getTime();
  131. if (((int)$row['expiration']) < $currentTime) {
  132. return null;
  133. }
  134. return $row;
  135. }
  136. /**
  137. * @param array $row
  138. * @param string $partStat participation status of attendee - SEE RFC 5545
  139. * @param int|null $guests
  140. * @param string|null $comment
  141. * @return Message
  142. */
  143. private function buildITipResponse(array $row, string $partStat):Message {
  144. $iTipMessage = new Message();
  145. $iTipMessage->uid = $row['uid'];
  146. $iTipMessage->component = 'VEVENT';
  147. $iTipMessage->method = 'REPLY';
  148. $iTipMessage->sequence = $row['sequence'];
  149. $iTipMessage->sender = $row['attendee'];
  150. if ($this->responseServer->isExternalAttendee($row['attendee'])) {
  151. $iTipMessage->recipient = $row['organizer'];
  152. } else {
  153. $iTipMessage->recipient = $row['attendee'];
  154. }
  155. $message = <<<EOF
  156. BEGIN:VCALENDAR
  157. PRODID:-//Nextcloud/Nextcloud CalDAV Server//EN
  158. METHOD:REPLY
  159. VERSION:2.0
  160. BEGIN:VEVENT
  161. ATTENDEE;PARTSTAT=%s:%s
  162. ORGANIZER:%s
  163. UID:%s
  164. SEQUENCE:%s
  165. REQUEST-STATUS:2.0;Success
  166. %sEND:VEVENT
  167. END:VCALENDAR
  168. EOF;
  169. $vObject = Reader::read(vsprintf($message, [
  170. $partStat, $row['attendee'], $row['organizer'],
  171. $row['uid'], $row['sequence'] ?? 0, $row['recurrenceid'] ?? ''
  172. ]));
  173. $vEvent = $vObject->{'VEVENT'};
  174. $vEvent->DTSTAMP = date('Ymd\\THis\\Z', $this->timeFactory->getTime());
  175. $iTipMessage->message = $vObject;
  176. return $iTipMessage;
  177. }
  178. }