. */ /** * @package ApiLoggerPlugin * @maintainer Brion Vibber */ if (!defined('STATUSNET')) { exit(1); } class ApiLoggerPlugin extends Plugin { // Lower this to do random sampling of API requests rather than all. // 0.1 will check about 10% of hits, etc. public $frequency = 1.0; function onArgsInitialize($args) { if (isset($args['action'])) { $action = strtolower($args['action']); if (substr($action, 0, 3) == 'api') { if ($this->frequency < 1.0 && $this->frequency > 0.0) { $max = mt_getrandmax(); $n = mt_rand() / $max; if ($n > $this->frequency) { return true; } } $uri = $_SERVER['REQUEST_URI']; $method = $_SERVER['REQUEST_METHOD']; $ssl = empty($_SERVER['HTTPS']) ? 'no' : 'yes'; $cookie = empty($_SERVER['HTTP_COOKIE']) ? 'no' : 'yes'; $etag = empty($_SERVER['HTTP_IF_MATCH']) ? 'no' : 'yes'; $last = empty($_SERVER['HTTP_IF_MODIFIED_SINCE']) ? 'no' : 'yes'; $auth = empty($_SERVER['HTTP_AUTHORIZATION']) ? 'no' : 'yes'; if ($auth == 'no' && function_exists('apache_request_headers')) { // Sometimes Authorization doesn't make it into $_SERVER. // Probably someone thought it was scary. $headers = apache_request_headers(); if (isset($headers['Authorization'])) { $auth = 'yes'; } } $agent = empty($_SERVER['HTTP_USER_AGENT']) ? 'no' : $_SERVER['HTTP_USER_AGENT']; $query = (strpos($uri, '?') === false) ? 'no' : 'yes'; if ($query == 'yes') { if (preg_match('/\?since_id=\d+$/', $uri)) { $query = 'since_id'; } } common_log(LOG_INFO, "STATLOG action:$action method:$method ssl:$ssl query:$query cookie:$cookie auth:$auth ifmatch:$etag ifmod:$last agent:$agent"); } } return true; } function onPluginVersion(&$versions) { $versions[] = array('name' => 'ApiLogger', 'version' => STATUSNET_VERSION, 'author' => 'Brion Vibber', 'homepage' => 'http://status.net/wiki/Plugin:ApiLogger', 'rawdescription' => // TRANS: Plugin description. _m('Logging of API requests.')); return true; } }