xmlrpcs.inc 9.4 KB
Newer Older
Dries's avatar
   
Dries committed
1
<?php
2
// $Id$
Dries's avatar
   
Dries committed
3

4
5
6
7
8
/**
 * @file
 * Provides API for defining and handling XML-RPC requests.
 */

9
10
11
12
13
14
/**
 * The main entry point for XML-RPC requests.
 *
 * @param $callbacks
 *   Array of external XML-RPC method names with the callbacks they map to.
 */
15
16
function xmlrpc_server($callbacks) {
  $xmlrpc_server = new stdClass();
17
  // Define built-in XML-RPC method names
18
  $defaults = array(
19
      'system.multicall' => 'xmlrpc_server_multicall',
20
21
22
23
    array(
      'system.methodSignature',
      'xmlrpc_server_method_signature',
      array('array', 'string'),
24
      'Returns an array describing the return type and required parameters of a method.'
25
26
27
28
29
    ),
    array(
      'system.getCapabilities',
      'xmlrpc_server_get_capabilities',
      array('struct'),
30
      'Returns a struct describing the XML-RPC specifications supported by this server.'
31
32
33
34
35
    ),
    array(
      'system.listMethods',
      'xmlrpc_server_list_methods',
      array('array'),
36
      'Returns an array of available methods on this server.'),
37
38
39
40
    array(
      'system.methodHelp',
      'xmlrpc_server_method_help',
      array('string', 'string'),
41
      'Returns a documentation string for the specified method.')
42
  );
43
44
45
  // We build an array of all method names by combining the built-ins
  // with those defined by modules implementing the _xmlrpc hook.
  // Built-in methods are overridable.
46
  foreach (array_merge($defaults, (array) $callbacks) as $key => $callback) {
47
48
49
50
51
52
53
54
55
56
57
58
59
    // we could check for is_array($callback)
    if (is_int($key)) {
      $method = $callback[0];
      $xmlrpc_server->callbacks[$method] = $callback[1];
      $xmlrpc_server->signatures[$method] = $callback[2];
      $xmlrpc_server->help[$method] = $callback[3];
    }
    else {
      $xmlrpc_server->callbacks[$key] = $callback;
      $xmlrpc_server->signatures[$key] = '';
      $xmlrpc_server->help[$key] = '';
    }
  }
Dries's avatar
   
Dries committed
60

61
  $data = file_get_contents('php://input');
62
  if (!$data) {
63
    exit('XML-RPC server accepts POST requests only.');
Dries's avatar
   
Dries committed
64
  }
65
66
  $xmlrpc_server->message = xmlrpc_message($data);
  if (!xmlrpc_message_parse($xmlrpc_server->message)) {
67
    xmlrpc_server_error(-32700, t('Parse error. Request not well formed.'));
Dries's avatar
   
Dries committed
68
  }
69
  if ($xmlrpc_server->message->messagetype != 'methodCall') {
70
    xmlrpc_server_error(-32600, t('Server error. Invalid XML-RPC. Request must be a methodCall.'));
Dries's avatar
   
Dries committed
71
  }
72
73
74
  if (!isset($xmlrpc_server->message->params)) {
    $xmlrpc_server->message->params = array();
  }
75
  xmlrpc_server_set($xmlrpc_server);
76
  $result = xmlrpc_server_call($xmlrpc_server, $xmlrpc_server->message->methodname, $xmlrpc_server->message->params);
77

78
  if (is_object($result) && !empty($result->is_error)) {
79
    xmlrpc_server_error($result);
Dries's avatar
   
Dries committed
80
  }
81
82
83
84
85
86
87
  // Encode the result
  $r = xmlrpc_value($result);
  // Create the XML
  $xml = '
<methodResponse>
  <params>
  <param>
88
    <value>' .
89
    xmlrpc_value_get_xml($r)
90
    . '</value>
91
92
93
  </param>
  </params>
</methodResponse>
Dries's avatar
   
Dries committed
94

95
96
97
98
';
  // Send it
  xmlrpc_server_output($xml);
}
Dries's avatar
   
Dries committed
99

100
101
102
103
104
105
106
107
/**
 * Throw an XML-RPC error.
 *
 * @param $error
 *   an error object OR integer error code
 * @param $message
 *   description of error, used only if integer error code was passed
 */
108
function xmlrpc_server_error($error, $message = FALSE) {
109
110
  if ($message && !is_object($error)) {
    $error = xmlrpc_error($error, $message);
Dries's avatar
   
Dries committed
111
  }
112
  xmlrpc_server_output(xmlrpc_error_get_xml($error));
Dries's avatar
   
Dries committed
113
114
}

115
function xmlrpc_server_output($xml) {
116
  $xml = '<?xml version="1.0"?>' . "\n" . $xml;
117
118
  drupal_add_http_header('Content-Length', strlen($xml));
  drupal_add_http_header('Content-Type', 'text/xml');
119
  echo $xml;
120
  drupal_exit();
Dries's avatar
   
Dries committed
121
122
}

123
124
125
126
127
128
/**
 * Store a copy of the request temporarily.
 *
 * @param $xmlrpc_server
 *   Request object created by xmlrpc_server().
 */
129
130
131
132
function xmlrpc_server_set($xmlrpc_server = NULL) {
  static $server;
  if (!isset($server)) {
    $server = $xmlrpc_server;
Dries's avatar
   
Dries committed
133
  }
134
135
  return $server;
}
Dries's avatar
   
Dries committed
136

137
// Retrieve the stored request.
138
139
140
function xmlrpc_server_get() {
  return xmlrpc_server_set();
}
Dries's avatar
   
Dries committed
141

142
143
144
145
/**
 * Dispatch the request and any parameters to the appropriate handler.
 *
 * @param $xmlrpc_server
146
147
 *   Contains information about this XML-RPC server, the methods it provides,
 *   their signatures, etc.
148
149
150
151
152
 * @param $methodname
 *   The external XML-RPC method name, e.g. 'system.methodHelp'
 * @param $args
 *   Array containing any parameters that were sent along with the request.
 */
153
function xmlrpc_server_call($xmlrpc_server, $methodname, $args) {
154
  // Make sure parameters are in an array
155
156
  if ($args && !is_array($args)) {
    $args = array($args);
Dries's avatar
   
Dries committed
157
  }
158
  // Has this method been mapped to a Drupal function by us or by modules?
159
  if (!isset($xmlrpc_server->callbacks[$methodname])) {
160
    return xmlrpc_error(-32601, t('Server error. Requested method @methodname not specified.', array("@methodname" => $xmlrpc_server->message->methodname)));
161
162
163
  }
  $method = $xmlrpc_server->callbacks[$methodname];
  $signature = $xmlrpc_server->signatures[$methodname];
Dries's avatar
   
Dries committed
164

165
  // If the method has a signature, validate the request against the signature
166
  if (is_array($signature)) {
167
    $ok = TRUE;
168
169
170
    $return_type = array_shift($signature);
    // Check the number of arguments
    if (count($args) != count($signature)) {
171
      return xmlrpc_error(-32602, t('Server error. Wrong number of method parameters.'));
Dries's avatar
   
Dries committed
172
    }
173
174
175
176
177
178
179
    // Check the argument types
    foreach ($signature as $key => $type) {
      $arg = $args[$key];
      switch ($type) {
        case 'int':
        case 'i4':
          if (is_array($arg) || !is_int($arg)) {
180
            $ok = FALSE;
181
182
183
184
185
          }
          break;
        case 'base64':
        case 'string':
          if (!is_string($arg)) {
186
            $ok = FALSE;
187
188
189
          }
          break;
        case 'boolean':
190
191
          if ($arg !== FALSE && $arg !== TRUE) {
            $ok = FALSE;
192
193
194
195
196
          }
          break;
        case 'float':
        case 'double':
          if (!is_float($arg)) {
197
            $ok = FALSE;
198
199
200
201
202
          }
          break;
        case 'date':
        case 'dateTime.iso8601':
          if (!$arg->is_date) {
203
            $ok = FALSE;
204
205
          }
          break;
Dries's avatar
   
Dries committed
206
      }
207
      if (!$ok) {
208
        return xmlrpc_error(-32602, t('Server error. Invalid method parameters.'));
Dries's avatar
   
Dries committed
209
210
211
      }
    }
  }
212

213
  if (!function_exists($method)) {
214
    return xmlrpc_error(-32601, t('Server error. Requested function @method does not exist.', array("@method" => $method)));
215
  }
216
  // Call the mapped function
217
218
  return call_user_func_array($method, $args);
}
Dries's avatar
   
Dries committed
219

220
221
222
223
224
function xmlrpc_server_multicall($methodcalls) {
  // See http://www.xmlrpc.com/discuss/msgReader$1208
  $return = array();
  $xmlrpc_server = xmlrpc_server_get();
  foreach ($methodcalls as $call) {
225
    $ok = TRUE;
226
227
    if (!isset($call['methodName']) || !isset($call['params'])) {
      $result = xmlrpc_error(3, t('Invalid syntax for system.multicall.'));
228
      $ok = FALSE;
229
230
231
232
233
234
235
236
237
    }
    $method = $call['methodName'];
    $params = $call['params'];
    if ($method == 'system.multicall') {
      $result = xmlrpc_error(-32600, t('Recursive calls to system.multicall are forbidden.'));
    }
    elseif ($ok) {
      $result = xmlrpc_server_call($xmlrpc_server, $method, $params);
    }
238
    if (is_object($result) && !empty($result->is_error)) {
239
240
241
242
243
244
      $return[] = array(
        'faultCode' => $result->code,
        'faultString' => $result->message
      );
    }
    else {
245
      $return[] = array($result);
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
    }
  }
  return $return;
}


/**
 * XML-RPC method system.listMethods maps to this function.
 */
function xmlrpc_server_list_methods() {
  $xmlrpc_server = xmlrpc_server_get();
  return array_keys($xmlrpc_server->callbacks);
}

/**
 * XML-RPC method system.getCapabilities maps to this function.
262
263
 *
 * @see http://groups.yahoo.com/group/xml-rpc/message/2897
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
 */
function xmlrpc_server_get_capabilities() {
  return array(
    'xmlrpc' => array(
      'specUrl' => 'http://www.xmlrpc.com/spec',
      'specVersion' => 1
    ),
    'faults_interop' => array(
      'specUrl' => 'http://xmlrpc-epi.sourceforge.net/specs/rfc.fault_codes.php',
      'specVersion' => 20010516
    ),
    'system.multicall' => array(
      'specUrl' => 'http://www.xmlrpc.com/discuss/msgReader$1208',
      'specVersion' => 1
    ),
    'introspection' => array(
    'specUrl' => 'http://scripts.incutio.com/xmlrpc/introspection.html',
    'specVersion' => 1
    )
  );
}

/**
 * XML-RPC method system.methodSignature maps to this function.
 *
 * @param $methodname
 *   Name of method for which we return a method signature.
291
 * @return
292
293
294
295
296
297
298
 *   An array of types representing the method signature of the
 *   function that the methodname maps to. The methodSignature of
 *   this function is 'array', 'string' because it takes an array
 *   and returns a string.
 */
function xmlrpc_server_method_signature($methodname) {
  $xmlrpc_server = xmlrpc_server_get();
299
  if (!isset($xmlrpc_server->callbacks[$methodname])) {
300
    return xmlrpc_error(-32601, t('Server error. Requested method @methodname not specified.', array("@methodname" => $methodname)));
301
  }
302
  if (!is_array($xmlrpc_server->signatures[$methodname])) {
303
    return xmlrpc_error(-32601, t('Server error. Requested method @methodname signature not specified.', array("@methodname" => $methodname)));
304
  }
305
  // We array of types
306
307
  $return = array();
  foreach ($xmlrpc_server->signatures[$methodname] as $type) {
308
    $return[] = $type;
Dries's avatar
   
Dries committed
309
  }
310
311
312
  return $return;
}

313
314
315
316
317
318
/**
 * XML-RPC method system.methodHelp maps to this function.
 *
 * @param $method
 *   Name of method for which we return a help string.
 */
319
320
function xmlrpc_server_method_help($method) {
  $xmlrpc_server = xmlrpc_server_get();
321
  return $xmlrpc_server->help[$method];
322
}