.gitattributes vendored Normal file
View File

@ -0,0 +1,38 @@
# Set default behavior
* text=auto eol=lf
# Ensure sources are processed
*.conf text
*.css text
*.html text diff=html
*.js text
*.md text
*.php text diff=php
Dockerfile text
# Do not alter images nor minified scripts nor fonts
*.ico binary
*.jpg binary
*.png binary
*.svg binary
*.otf binary
*.eot binary
*.woff binary
*.woff2 binary
*.ttf binary
*.min.css binary
*.min.js binary
# Exclude from Git archives
.gitattributes export-ignore
.github export-ignore
.gitignore export-ignore
.travis.yml export-ignore
doc/**/*.json export-ignore
doc/**/*.md export-ignore
docker/ export-ignore
Doxyfile export-ignore
Makefile export-ignore
mkdocs.yml export-ignore
phpunit.xml export-ignore
tests/ export-ignore

.github/mailmap vendored Normal file
View File

@ -0,0 +1,15 @@
ArthurHoaro <>
Florian Eula <> feula
Florian Eula <> <>
Nicolas Danelon <> nicolasm
Nicolas Danelon <> <>
Nicolas Danelon <> <>
Nicolas Danelon <> <>
Sébastien Sauvage <>
Timo Van Neerden <>
Timo Van Neerden <> lehollandaisvolant <>
VirtualTam <> <>
VirtualTam <> <>
VirtualTam <> <>
Willi Eggeling <> <>
Willi Eggeling <> <>

.gitignore vendored
View File

@ -1,4 +1,4 @@
# Ignore data/, tmp/, cache/ and pagecache/
# Shaarli runtime resources
@ -7,4 +7,31 @@ pagecache
# Eclipse project files
# Raintpl generated pages
# 3rd-party dependencies
# Release archives
# Development and test resources
# User plugin configuration
# HTML documentation
# 3rd party themes

.htaccess Normal file
View File

@ -0,0 +1,4 @@
RewriteEngine On
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule ^ index.php [QSA,L]

.travis.yml Normal file
View File

@ -0,0 +1,19 @@
sudo: false
dist: trusty
language: php
- $HOME/.composer/cache
- 7.1
- 7.0
- 5.6
- 5.5
- composer self-update
- composer install --prefer-dist
- locale -a
- make clean
- make check_permissions
- make all_tests

1094 Normal file

File diff suppressed because it is too large Load Diff

78 Normal file
View File

@ -0,0 +1,78 @@
## Contributing to Shaarli (community repository)
### Bugs and feature requests
**Reporting bugs, feature requests: issues management**
You can look through existing bugs/requests and help reporting them [here](
Constructive input/experience reports/helping other users is welcome.
The general guideline of the fork is to keep Shaarli simple (project and code maintenance, and features-wise), while providing customization capabilities (plugin system, making more settings configurable).
Check the [milestones]( to see what issues have priority.
* The issues list should preferably contain **only tasks that can be actioned immediately**. Anyone should be able to open the issues list, pick one and start working on it immediately.
* If you have a clear idea of a **feature you expect, or have a specific bug/defect to report**, [search the issues list, both open and closed]( to check if it has been discussed, and comment on the appropriate issue. If you can't find one, please open a [new issue](
* **General discussions** fit in #44 so that we don't follow a slope where users and contributors have to track 90 "maybe" items in the bug tracker. Separate issues about clear, separate steps can be opened after discussion.
* You can also join instant discussion at, or via IRC as described [here](
### Documentation
The [official documentation]( is generated from [Markdown]( documents in the `doc/md/` directory. HTML documentation is generated using [Mkdocs]( [Read the Docs]( provides hosting for the online documentation.
To edit the documentation, please edit the appropriate `doc/md/*.md` files (and optionally `make htmlpages` to preview changes to HTML files). Then submit your changes as a Pull Request. Have a look at the MkDocs documentation and configuration file `mkdocs.yml` if you need to add/remove/rename/reorder pages.
### Translations
Currently Shaarli has no translation/internationalization/localization system available and is single-language. You can help by proposing an i18n system (issue
### Beta testing
You can help testing Shaarli releases by immediately upgrading your installation after a [new version has been releases](
All current development happens in [Pull Requests]( You can test proposed patches by cloning the Shaarli repo, adding the Pull Request branch and `git checkout` to it. You can also merge multiple Pull Requests to a testing branch.
git clone
git remote add pull-request-25 owner/cool-new-feature
git remote add pull-request-26 anotherowner/bugfix
git remote update
git checkout -b testing
git merge cool-new-feature
git merge bugfix
Or see [Checkout Github Pull Requests locally](
Please report any problem you might find.
### Contributing code
#### Adding your own changes
* Pick or open an issue
* Fork the Shaarli repository on github
* `git clone` your fork
* starting from branch ` master`, switch to a new branch (eg. `git checkout -b my-awesome-feature`)
* edit the required files (from the Github web interface or your text editor)
* add and commit your changes with a meaningful commit message (eg `Cool new feature, fixes issue #1001`)
* run unit tests against your patched version, see [Running unit tests](
* Open your fork in the Github web interface and click the "Compare and Pull Request" button, enter required info and submit your Pull Request.
All changes you will do on the `my-awesome-feature` in the future will be added to your Pull Request. Don't work directly on the master branch, don't do unrelated work on your `my-awesome-feature` branch.
#### Contributing to an existing Pull Request
#### Useful links
If you are not familiar with Git or Github, here are a few links to set you on track:
* - 10 minutes Github workflow interactive tutorial
* - A Git cheatsheet
* - Helps you understand some basic Git concepts visually
* - Git tutorials
* - Git workflows
* - The official Git book, multiple languages
* - Git tutorials
* - Guide to Git
* - medium to advanced Git docs/tips/blog/articles
* - Participating in Open Source

View File

@ -1,16 +1,67 @@
Shaarli is distributed under the zlib/libpng License:
Files: *
License: zlib/libpng
Copyright: (c) 2011-2015 Sébastien SAUVAGE <>
(c) 2011-2017 The Shaarli Community, see AUTHORS
Copyright (c) 2011 Sébastien SAUVAGE (
Files: inc/reset.css
License: BSD (
Copyright: (c) 2010, Yahoo! Inc.
Files: images/calendar.png, images/edit_icon.png, images/feed-icon-14x14.png, images/private.png, images/private_16x16.png, images/private_16x16_active.png, images/tag_blue.png
License: CC-BY (
Copyright: (c) 2014 Yusuke Kamiyamane
Files: images/delete_icon.png
License: CC-BY (
Copyright: (c) 2014 Designmodo
Files: images/floral_left.png, images/floral_right.png, images/squiggle.png, images/squiggle_closing.png
Licence: Public Domain
Files: images/Paper_texture_v5_by_bashcorpo_w1000.jpg
Licence: Public Domain
Files: images/logo.png
License: zlib/libpng
Copyright: (c) 2011-2014 idleman
Files: inc/blazy*.js
License: MIT License (
Copyright: (C) Bjoern Klinggaard - @bklinggaard -
Files: inc/rain.tpl.class.php
Copyright: 2011-2012, Federico Ulfo <>
2011-2012, The Rain Team <>
License: LGPL-3+ (
Files: inc/awesomplete*
License: MIT License (
Copyright: (C) 2015 Lea Verou -
Files: plugins/wallabag/wallabag.png
License: MIT License (
Copyright: (C) 2015 Nicolas Lœuillet -
Files: tpl/default/sad_star.png
License: MIT License (
Copyright: (C) 2015 kalvn -
This software is provided 'as-is', without any express or implied warranty.
In no event will the authors be held liable for any damages arising from
the use of this software.
Permission is granted to anyone to use this software for any purpose,
including commercial applications, and to alter it and redistribute it
including commercial applications, and to alter it and redistribute it
freely, subject to the following restrictions:
1. The origin of this software must not be misrepresented; you must not
1. The origin of this software must not be misrepresented; you must not
claim that you wrote the original software. If you use this software
in a product, an acknowledgment in the product documentation would
be appreciated but is not required.
@ -19,3 +70,721 @@ freely, subject to the following restrictions:
not be misrepresented as being the original software.
3. This notice may not be removed or altered from any source distribution.
Doxyfile Normal file

File diff suppressed because it is too large Load Diff

Makefile Normal file
View File

@ -0,0 +1,215 @@
# The personal, minimalist, super-fast, database free, bookmarking service.
# Makefile for PHP code analysis & testing, documentation and release generation
# Prerequisites:
# - install Composer, either:
# - from your distro's package manager;
# - from the official website (;
# - install/update test dependencies:
# $ composer install # 1st setup
# $ composer update
# - install Xdebug for PHPUnit code coverage reports:
# - see
# - enable in php.ini
BIN = vendor/bin
PHP_SOURCE = index.php application tests plugins
PHP_COMMA_SOURCE = index.php,application,tests,plugins
all: static_analysis_summary check_permissions test
# Docker test adapter
# Shaarli sources and vendored libraries are copied from a shared volume
# to a user-owned directory to enable running tests as a non-root user.
rsync -az /shaarli/ ~/shaarli/
cd ~/shaarli && make $*
# Concise status of the project
# These targets are non-blocking: || exit 0
static_analysis_summary: code_sniffer_source copy_paste mess_detector_summary
# PHP_CodeSniffer
# Detects PHP syntax errors
# Documentation (usage, output formatting):
# -
# -
code_sniffer: code_sniffer_full
### - errors filtered by coding standard: PEAR, PSR1, PSR2, Zend...
@$(BIN)/phpcs $(PHP_SOURCE) --report-full --report-width=200 --standard=$*
### - errors by Git author
@$(BIN)/phpcs $(PHP_SOURCE) --report-gitblame
### - all errors/warnings
@$(BIN)/phpcs $(PHP_SOURCE) --report-full --report-width=200
### - errors grouped by kind
@$(BIN)/phpcs $(PHP_SOURCE) --report-source || exit 0
# PHP Copy/Paste Detector
# Detects code redundancy
# Documentation:
@echo "-----------------------"
@echo "-----------------------"
@$(BIN)/phpcpd $(PHP_SOURCE) || exit 0
# PHP Mess Detector
# Detects PHP syntax errors, sorted by category
# Rules documentation:
MESS_DETECTOR_RULES = cleancode,codesize,controversial,design,naming,unusedcode
@echo "-----------------"
@echo "-----------------"
### - all warnings
mess_detector: mess_title
@$(BIN)/phpmd $(PHP_COMMA_SOURCE) text $(MESS_DETECTOR_RULES) | sed 's_.*\/__'
### - all warnings + HTML output contains links to PHPMD's documentation
--reportfile phpmd.html || exit 0
### - warnings grouped by message, sorted by descending frequency order
mess_detector_grouped: mess_title
| cut -f 2 | sort | uniq -c | sort -nr
### - summary: number of warnings by rule set
mess_detector_summary: mess_title
@for rule in $$(echo $(MESS_DETECTOR_RULES) | tr ',' ' '); do \
warnings=$$($(BIN)/phpmd $(PHP_COMMA_SOURCE) text $$rule | wc -l); \
printf "$$warnings\t$$rule\n"; \
# Checks source file & script permissions
@echo "----------------------"
@echo "Check file permissions"
@echo "----------------------"
@for file in `git ls-files`; do \
if [ -x $$file ]; then \
errors=true; \
echo "$${file} is executable"; \
fi \
done; [ -z $$errors ] || false
# PHPUnit
# Runs unitary and functional tests
# Generates an HTML coverage report if Xdebug is enabled
# See phpunit.xml for configuration
@echo "-------"
@echo "PHPUNIT"
@echo "-------"
@mkdir -p sandbox coverage
@$(BIN)/phpunit --coverage-php coverage/main.cov --testsuite unit-tests
@UT_LOCALE=$*.utf8 \
$(BIN)/phpunit \
--coverage-php coverage/$(firstword $(subst _, ,$*)).cov \
--bootstrap tests/languages/bootstrap.php \
--testsuite language-$(firstword $(subst _, ,$*))
all_tests: test locale_test_de_DE locale_test_en_US locale_test_fr_FR
@$(BIN)/phpcov merge --html coverage coverage
@# --text doesn't work with phpunit 4.* (v5 requires PHP 5.6)
@#$(BIN)/phpcov merge --text coverage/txt coverage
# Custom release archive generation
# For each tagged revision, GitHub provides tar and zip archives that correspond
# to the output of git-archive
# These targets produce similar archives, featuring 3rd-party dependencies
# to ease deployment on shared hosting.
ARCHIVE_VERSION := shaarli-$$(git describe)-full
release_archive: release_tar release_zip
### download 3rd-party PHP libraries
composer_dependencies: clean
composer install --no-dev --prefer-dist
find vendor/ -name ".git" -type d -exec rm -rf {} +
### generate a release tarball and include 3rd-party dependencies
release_tar: composer_dependencies htmldoc
git archive --prefix=$(ARCHIVE_PREFIX) -o $(ARCHIVE_VERSION).tar HEAD
tar rvf $(ARCHIVE_VERSION).tar --transform "s|^vendor|$(ARCHIVE_PREFIX)vendor|" vendor/
tar rvf $(ARCHIVE_VERSION).tar --transform "s|^doc/html|$(ARCHIVE_PREFIX)doc/html|" doc/html/
### generate a release zip and include 3rd-party dependencies
release_zip: composer_dependencies htmldoc
git archive --prefix=$(ARCHIVE_PREFIX) -o $(ARCHIVE_VERSION).zip -9 HEAD
mkdir -p $(ARCHIVE_PREFIX)/{doc,vendor}
rsync -a doc/html/ $(ARCHIVE_PREFIX)doc/html/
rsync -a vendor/ $(ARCHIVE_PREFIX)vendor/
zip -r $(ARCHIVE_VERSION).zip $(ARCHIVE_PREFIX)vendor/
# Targets for repository and documentation maintenance
### remove all unversioned files
@git clean -df
@rm -rf sandbox
### generate the AUTHORS file from Git commit information
@cp .github/mailmap .mailmap
@git shortlog -sne > AUTHORS
@rm .mailmap
### generate Doxygen documentation
doxygen: clean
@rm -rf doxygen
@( cat Doxyfile ; echo "PROJECT_NUMBER=`git describe`" ) | doxygen -
### generate HTML documentation from Markdown pages with MkDocs
python3 -m venv venv/
bash -c 'source venv/bin/activate; \
pip install mkdocs; \
mkdocs build'
find doc/html/ -type f -exec chmod a-x '{}' \;
rm -r venv

View File

@ -1,95 +1,37 @@
![Shaarli logo](
![Shaarli logo](doc/md/images/doc-logo.png)
Shaarli, the personal, minimalist, super-fast, no-database delicious clone.
The personal, minimalist, super-fast, database free, bookmarking service.
You want to share the links you discover ? Shaarli is a minimalist delicious clone you can install on your own website.
It is designed to be personal (single-user), fast and handy.
_Do you want to share the links you discover?_
_Shaarli is a minimalist link sharing service that you can install on your own server._
_It is designed to be personal (single-user), fast and handy._
[![Join the chat at](](
[![Docker repository](](
* Minimalist design (simple is beautiful)
* **FAST**
* Dead-simple installation: Drop the files, open the page. No database required.
* Easy to use: Single button in your browser to bookmark a page
* Save url, title, description (unlimited size). Classify links with tags (with autocomplete)
* Tag renaming, merging and deletion.
* Automatic thumbnails for various services (imgur,, flickr, youtube, vimeo, dailymotion…)
* Automatic conversion of URLs to clickable links in descriptions. Support for http/ftp/file/apt/magnet protocols.
* Save links as public or private
* 1-clic access to your private links/notes
* Browse links by page, filter by tag or use the full text search engine
* Permalinks (with QR-Code) for easy reference
* RSS and ATOM feeds (which can be filtered by tag or text search)
* Tag cloud
* Picture wall (which can be filtered by tag or text search)
* “Links of the day” Newspaper-like digest, browsable by day.
* “Daily” RSS feed: Get each day a digest of all new links.
* [PubSubHubbub]( protocol support
* Easy backup (Data stored in a single file)
* Compact storage (1320 links stored in 299 ko)
* Mobile browsers support
* Also works with javascript disabled
* Can import/export Netscape bookmarks (for import/export from/to Firefox, Opera, Chrome, Delicious…)
* Brute force protected login form
* Protected against [XSRF](, session cookie hijacking.
* Automatic removal of annoying FeedBurner/Google FeedProxy parameters in URL (?utm_source…)
* Shaarli is a bookmarking application, but you can use it for micro-blogging (like Twitter), a pastebin, an online notepad, a snippet repository, etc.
* You will be automatically notified by a discreet popup if a new version is available
* Pages are easy to customize (using CSS and simple RainTPL templates)
## Quickstart
More information on the project page:
- [Documentation](
- [Change log](
- [Bugs/Feature requests/Discussion](
![my Shaarli logo](
### Demo
myShaarli Features :
You can use this [public demo instance of Shaarli](
It runs the latest development version of Shaarli and is updated/reset daily.
* Markdown support (web+RSS+Atom)
* Define external thumbnailer
* Add favicon
* Better configuration page
* Template support
* Add extra field for origin of link
* New default theme
* Add link to (qwertygc
* myShaali can use Firefox social API (Marsup
* myShaali can post original article to Wallabag (v1/v2)(nodiscc
* myShaali implement OpenSearch (ArthurHoaro
* Few small fix
* You can upgrade original Shaarli to myShaarli without lost your data
* You can define url origin of update
* Change date/time format
Login: `demo`; Password: `demo`
More information on the project page:
### License
Requires php 5.1
Shaarli is distributed under the zlib/libpng License:
Copyright (c) 2011 Sébastien SAUVAGE (
This software is provided 'as-is', without any express or implied warranty.
In no event will the authors be held liable for any damages arising from
the use of this software.
Permission is granted to anyone to use this software for any purpose,
including commercial applications, and to alter it and redistribute it
freely, subject to the following restrictions:
1. The origin of this software must not be misrepresented; you must not
claim that you wrote the original software. If you use this software
in a product, an acknowledgment in the product documentation would
be appreciated but is not required.
2. Altered source versions must be plainly marked as such, and must
not be misrepresented as being the original software.
3. This notice may not be removed or altered from any source distribution.
Shaarli is [Free Software]( See [COPYING](COPYING) for a detail of the contributors and licenses for each individual component.

application/.htaccess Normal file
View File

@ -0,0 +1,13 @@
<IfModule version_module>
<IfVersion >= 2.4>
Require all denied
<IfVersion < 2.4>
Allow from none
Deny from all
<IfModule !version_module>
Require all denied

View File

@ -0,0 +1,239 @@
* Shaarli (application) utilities
class ApplicationUtils
* @var string File containing the current version
public static $VERSION_FILE = 'shaarli_version.php';
private static $GIT_URL = '';
private static $GIT_BRANCHES = array('latest', 'stable');
private static $VERSION_START_TAG = '<?php /* ';
private static $VERSION_END_TAG = ' */ ?>';
* Gets the latest version code from the Git repository
* The code is read from the raw content of the version file on the Git server.
* @param string $url URL to reach to get the latest version.
* @param int $timeout Timeout to check the URL (in seconds).
* @return mixed the version code from the repository if available, else 'false'
public static function getLatestGitVersionCode($url, $timeout=2)
list($headers, $data) = get_http_response($url, $timeout);
if (strpos($headers[0], '200 OK') === false) {
error_log('Failed to retrieve ' . $url);
return false;
return $data;
* Retrieve the version from a remote URL or a file.
* @param string $remote URL or file to fetch.
* @param int $timeout For URLs fetching.
* @return bool|string The version or false if it couldn't be retrieved.
public static function getVersion($remote, $timeout = 2)
if (startsWith($remote, 'http')) {
if (($data = static::getLatestGitVersionCode($remote, $timeout)) === false) {
return false;
} else {
if (! is_file($remote)) {
return false;
$data = file_get_contents($remote);
return str_replace(
array('', '', ''),
* Checks if a new Shaarli version has been published on the Git repository
* Updates checks are run periodically, according to the following criteria:
* - the update checks are enabled (install, global config);
* - the user is logged in (or this is an open instance);
* - the last check is older than a given interval;
* - the check is non-blocking if the HTTPS connection to Git fails;
* - in case of failure, the update file's modification date is updated,
* to avoid intempestive connection attempts.
* @param string $currentVersion the current version code
* @param string $updateFile the file where to store the latest version code
* @param int $checkInterval the minimum interval between update checks (in seconds
* @param bool $enableCheck whether to check for new versions
* @param bool $isLoggedIn whether the user is logged in
* @param string $branch check update for the given branch
* @throws Exception an invalid branch has been set for update checks
* @return mixed the new version code if available and greater, else 'false'
public static function checkUpdate($currentVersion,
// Do not check versions for visitors
// Do not check if the user doesn't want to
// Do not check with dev version
if (! $isLoggedIn || empty($enableCheck) || $currentVersion === 'dev') {
return false;
if (is_file($updateFile) && (filemtime($updateFile) > time() - $checkInterval)) {
// Shaarli has checked for updates recently - skip HTTP query
$latestKnownVersion = file_get_contents($updateFile);
if (version_compare($latestKnownVersion, $currentVersion) == 1) {
return $latestKnownVersion;
return false;
if (! in_array($branch, self::$GIT_BRANCHES)) {
throw new Exception(
'Invalid branch selected for updates: "' . $branch . '"'
// Late Static Binding allows overriding within tests
// See
$latestVersion = static::getVersion(
self::$GIT_URL . '/' . $branch . '/' . self::$VERSION_FILE
if (! $latestVersion) {
// Only update the file's modification date
file_put_contents($updateFile, $currentVersion);
return false;
// Update the file's content and modification date
file_put_contents($updateFile, $latestVersion);
if (version_compare($latestVersion, $currentVersion) == 1) {
return $latestVersion;
return false;
* Checks the PHP version to ensure Shaarli can run
* @param string $minVersion minimum PHP required version
* @param string $curVersion current PHP version (use PHP_VERSION)
* @throws Exception the PHP version is not supported
public static function checkPHPVersion($minVersion, $curVersion)
if (version_compare($curVersion, $minVersion) < 0) {
throw new Exception(
'Your PHP version is obsolete!'
.' Shaarli requires at least PHP '.$minVersion.', and thus cannot run.'
.' Your PHP version has known security vulnerabilities and should be'
.' updated as soon as possible.'
* Checks Shaarli has the proper access permissions to its resources
* @param ConfigManager $conf Configuration Manager instance.
* @return array A list of the detected configuration issues
public static function checkResourcePermissions($conf)
$errors = array();
$rainTplDir = rtrim($conf->get('resource.raintpl_tpl'), '/');
// Check script and template directories are readable
foreach (array(
) as $path) {
if (! is_readable(realpath($path))) {
$errors[] = '"'.$path.'" directory is not readable';
// Check cache and data directories are readable and writable
foreach (array(
) as $path) {
if (! is_readable(realpath($path))) {
$errors[] = '"'.$path.'" directory is not readable';
if (! is_writable(realpath($path))) {
$errors[] = '"'.$path.'" directory is not writable';
// Check configuration files are readable and writable
foreach (array(
) as $path) {
if (! is_file(realpath($path))) {
# the file may not exist yet
if (! is_readable(realpath($path))) {
$errors[] = '"'.$path.'" file is not readable';
if (! is_writable(realpath($path))) {
$errors[] = '"'.$path.'" file is not writable';
return $errors;
* Returns a salted hash representing the current Shaarli version.
* Useful for assets browser cache.
* @param string $currentVersion of Shaarli
* @param string $salt User personal salt, also used for the authentication
* @return string version hash
public static function getVersionHash($currentVersion, $salt)
return hash_hmac('sha256', $currentVersion, $salt);

application/Base64Url.php Normal file
View File

@ -0,0 +1,34 @@
namespace Shaarli;
* URL-safe Base64 operations
* @see
class Base64Url
* Base64Url-encodes data
* @param string $data Data to encode
* @return string Base64Url-encoded data
public static function encode($data) {
return rtrim(strtr(base64_encode($data), '+/', '-_'), '=');
* Decodes Base64Url-encoded data
* @param string $data Data to decode
* @return string Decoded data
public static function decode($data) {
return base64_decode(str_pad(strtr($data, '-_', '+/'), strlen($data) % 4, '=', STR_PAD_RIGHT));

application/Cache.php Normal file
View File

@ -0,0 +1,38 @@
* Cache utilities
* Purges all cached pages
* @param string $pageCacheDir page cache directory
* @return mixed an error string if the directory is missing
function purgeCachedPages($pageCacheDir)
if (! is_dir($pageCacheDir)) {
$error = 'Cannot purge '.$pageCacheDir.': no directory';
return $error;
array_map('unlink', glob($pageCacheDir.'/*.cache'));
* Invalidates caches when the database is changed or the user logs out.
* @param string $pageCacheDir page cache directory
function invalidateCaches($pageCacheDir)
// Purge cache attached to session.
if (isset($_SESSION['tags'])) {
// Purge page cache shared by sessions.

View File

@ -0,0 +1,59 @@
* Simple cache system, mainly for the RSS/ATOM feeds
class CachedPage
// Directory containing page caches
private $cacheDir;
// Should this URL be cached (boolean)?
private $shouldBeCached;
// Name of the cache file for this URL
private $filename;
* Creates a new CachedPage
* @param string $cacheDir page cache directory
* @param string $url page URL
* @param bool $shouldBeCached whether this page needs to be cached
public function __construct($cacheDir, $url, $shouldBeCached)
// TODO: check write access to the cache directory
$this->cacheDir = $cacheDir;
$this->filename = $this->cacheDir.'/'.sha1($url).'.cache';
$this->shouldBeCached = $shouldBeCached;
* Returns the cached version of a page, if it exists and should be cached
* @return string a cached version of the page if it exists, null otherwise
public function cachedVersion()
if (!$this->shouldBeCached) {
return null;
if (is_file($this->filename)) {
return file_get_contents($this->filename);
return null;
* Puts a page in the cache
* @param string $pageContent XML content to cache
public function cache($pageContent)
if (!$this->shouldBeCached) {
file_put_contents($this->filename, $pageContent);

application/FeedBuilder.php Normal file
View File

@ -0,0 +1,296 @@
* FeedBuilder class.
* Used to build ATOM and RSS feeds data.
class FeedBuilder
* @var string Constant: RSS feed type.
public static $FEED_RSS = 'rss';
* @var string Constant: ATOM feed type.
public static $FEED_ATOM = 'atom';
* @var string Default language if the locale isn't set.
public static $DEFAULT_LANGUAGE = 'en-en';
* @var int Number of links to display in a feed by default.
public static $DEFAULT_NB_LINKS = 50;
* @var LinkDB instance.
protected $linkDB;
* @var string RSS or ATOM feed.
protected $feedType;
* @var array $_SERVER.
protected $serverInfo;
* @var array $_GET.
protected $userInput;
* @var boolean True if the user is currently logged in, false otherwise.
protected $isLoggedIn;
* @var boolean Use permalinks instead of direct links if true.
protected $usePermalinks;
* @var boolean true to hide dates in feeds.
protected $hideDates;
* @var string server locale.
protected $locale;
* @var DateTime Latest item date.
protected $latestDate;
* Feed constructor.
* @param LinkDB $linkDB LinkDB instance.
* @param string $feedType Type of feed.
* @param array $serverInfo $_SERVER.
* @param array $userInput $_GET.
* @param boolean $isLoggedIn True if the user is currently logged in, false otherwise.
public function __construct($linkDB, $feedType, $serverInfo, $userInput, $isLoggedIn)
$this->linkDB = $linkDB;
$this->feedType = $feedType;
$this->serverInfo = $serverInfo;
$this->userInput = $userInput;
$this->isLoggedIn = $isLoggedIn;
* Build data for feed templates.
* @return array Formatted data for feeds templates.
public function buildData()
// Search for untagged links
if (isset($this->userInput['searchtags']) && empty($this->userInput['searchtags'])) {
$this->userInput['searchtags'] = false;
// Optionally filter the results:
$linksToDisplay = $this->linkDB->filterSearch($this->userInput);
$nblinksToDisplay = $this->getNbLinks(count($linksToDisplay));
// Can't use array_keys() because $link is a LinkDB instance and not a real array.
$keys = array();
foreach ($linksToDisplay as $key => $value) {
$keys[] = $key;
$pageaddr = escape(index_url($this->serverInfo));
$linkDisplayed = array();
for ($i = 0; $i < $nblinksToDisplay && $i < count($keys); $i++) {
$linkDisplayed[$keys[$i]] = $this->buildItem($linksToDisplay[$keys[$i]], $pageaddr);
$data['language'] = $this->getTypeLanguage();
$data['last_update'] = $this->getLatestDateFormatted();
$data['show_dates'] = !$this->hideDates || $this->isLoggedIn;
// Remove leading slash from REQUEST_URI.
$data['self_link'] = escape(server_url($this->serverInfo))
. escape($this->serverInfo['REQUEST_URI']);
$data['index_url'] = $pageaddr;
$data['usepermalinks'] = $this->usePermalinks === true;
$data['links'] = $linkDisplayed;
return $data;
* Build a feed item (one per shaare).
* @param array $link Single link array extracted from LinkDB.
* @param string $pageaddr Index URL.
* @return array Link array with feed attributes.
protected function buildItem($link, $pageaddr)
$link['guid'] = $pageaddr .'?'. $link['shorturl'];
// Check for both signs of a note: starting with ? and 7 chars long.
if ($link['url'][0] === '?' && strlen($link['url']) === 7) {
$link['url'] = $pageaddr . $link['url'];
if ($this->usePermalinks === true) {
$permalink = '<a href="'. $link['url'] .'" title="Direct link">Direct link</a>';
} else {
$permalink = '<a href="'. $link['guid'] .'" title="Permalink">Permalink</a>';
$link['description'] = format_description($link['description'], '', $pageaddr);
$link['description'] .= PHP_EOL .'<br>&#8212; '. $permalink;
$pubDate = $link['created'];
$link['pub_iso_date'] = $this->getIsoDate($pubDate);
// atom:entry elements MUST contain exactly one atom:updated element.
if (!empty($link['updated'])) {
$upDate = $link['updated'];
$link['up_iso_date'] = $this->getIsoDate($upDate, DateTime::ATOM);
} else {
$link['up_iso_date'] = $this->getIsoDate($pubDate, DateTime::ATOM);;
// Save the more recent item.
if (empty($this->latestDate) || $this->latestDate < $pubDate) {
$this->latestDate = $pubDate;
if (!empty($upDate) && $this->latestDate < $upDate) {
$this->latestDate = $upDate;
$taglist = array_filter(explode(' ', $link['tags']), 'strlen');
uasort($taglist, 'strcasecmp');
$link['taglist'] = $taglist;
return $link;
* Set this to true to use permalinks instead of direct links.
* @param boolean $usePermalinks true to force permalinks.
public function setUsePermalinks($usePermalinks)
$this->usePermalinks = $usePermalinks;
* Set this to true to hide timestamps in feeds.
* @param boolean $hideDates true to enable.
public function setHideDates($hideDates)
$this->hideDates = $hideDates;
* Set the locale. Used to show feed language.
* @param string $locale The locale (eg. 'fr_FR.UTF8').
public function setLocale($locale)
$this->locale = strtolower($locale);
* Get the language according to the feed type, based on the locale:
* - RSS format: en-us (default: 'en-en').
* - ATOM format: fr (default: 'en').
* @return string The language.
public function getTypeLanguage()
// Use the locale do define the language, if available.
if (! empty($this->locale) && preg_match('/^\w{2}[_\-]\w{2}/', $this->locale)) {
$length = ($this->feedType == self::$FEED_RSS) ? 5 : 2;
return str_replace('_', '-', substr($this->locale, 0, $length));
return ($this->feedType == self::$FEED_RSS) ? 'en-en' : 'en';
* Format the latest item date found according to the feed type.
* Return an empty string if invalid DateTime is passed.
* @return string Formatted date.
protected function getLatestDateFormatted()
if (empty($this->latestDate) || !$this->latestDate instanceof DateTime) {
return '';
$type = ($this->feedType == self::$FEED_RSS) ? DateTime::RSS : DateTime::ATOM;
return $this->latestDate->format($type);
* Get ISO date from DateTime according to feed type.
* @param DateTime $date Date to format.
* @param string|bool $format Force format.
* @return string Formatted date.
protected function getIsoDate(DateTime $date, $format = false)
if ($format !== false) {
return $date->format($format);
if ($this->feedType == self::$FEED_RSS) {
return $date->format(DateTime::RSS);
return $date->format(DateTime::ATOM);
* Returns the number of link to display according to 'nb' user input parameter.
* If 'nb' not set or invalid, default value: $DEFAULT_NB_LINKS.
* If 'nb' is set to 'all', display all filtered links (max parameter).
* @param int $max maximum number of links to display.
* @return int number of links to display.
public function getNbLinks($max)
if (empty($this->userInput['nb'])) {
return self::$DEFAULT_NB_LINKS;
if ($this->userInput['nb'] == 'all') {
return $max;
$intNb = intval($this->userInput['nb']);
if (! is_int($intNb) || $intNb == 0) {
return self::$DEFAULT_NB_LINKS;
return $intNb;

application/FileUtils.php Normal file
View File

@ -0,0 +1,82 @@
require_once 'exceptions/IOException.php';
* Class FileUtils
* Utility class for file manipulation.
class FileUtils
* @var string
protected static $phpPrefix = '<?php /* ';
* @var string
protected static $phpSuffix = ' */ ?>';
* Write data into a file (Shaarli database format).
* The data is stored in a PHP file, as a comment, in compressed base64 format.
* The file will be created if it doesn't exist.
* @param string $file File path.
* @param mixed $content Content to write.
* @return int|bool Number of bytes written or false if it fails.
* @throws IOException The destination file can't be written.
public static function writeFlatDB($file, $content)
if (is_file($file) && !is_writeable($file)) {
// The datastore exists but is not writeable
throw new IOException($file);
} else if (!is_file($file) && !is_writeable(dirname($file))) {
// The datastore does not exist and its parent directory is not writeable
throw new IOException(dirname($file));
return file_put_contents(
* Read data from a file containing Shaarli database format content.
* If the file isn't readable or doesn't exist, default data will be returned.
* @param string $file File path.
* @param mixed $default The default value to return if the file isn't readable.
* @return mixed The content unserialized, or default if the file isn't readable, or false if it fails.
public static function readFlatDB($file, $default = null)
// Note that gzinflate is faster than gzuncompress.
// See:
if (! is_readable($file)) {
return $default;
$data = file_get_contents($file);
if ($data == '') {
return $default;
return unserialize(
substr($data, strlen(self::$phpPrefix), -strlen(self::$phpSuffix))

application/History.php Normal file
View File

@ -0,0 +1,200 @@
* Class History
* Handle the history file tracing events in Shaarli.
* The history is stored as JSON in a file set by 'resource.history' setting.
* Available data:
* - event: event key
* - datetime: event date, in ISO8601 format.
* - id: event item identifier (currently only link IDs).
* Available event keys:
* - CREATED: new link
* - UPDATED: link updated
* - DELETED: link deleted
* - SETTINGS: the settings have been updated through the UI.
* Note: new events are put at the beginning of the file and history array.
class History
* @var string Action key: a new link has been created.
* @var string Action key: a link has been updated.
* @var string Action key: a link has been deleted.
* @var string Action key: settings have been updated.
* @var string History file path.
protected $historyFilePath;
* @var array History data.
protected $history;
* @var int History retention time in seconds (1 month).
protected $retentionTime = 2678400;
* History constructor.
* @param string $historyFilePath History file path.
* @param int $retentionTime History content rentention time in seconds.
* @throws Exception if something goes wrong.
public function __construct($historyFilePath, $retentionTime = null)
$this->historyFilePath = $historyFilePath;
if ($retentionTime !== null) {
$this->retentionTime = $retentionTime;
* Initialize: read history file.
* Allow lazy loading (don't read the file if it isn't necessary).
protected function initialize()
* Add Event: new link.
* @param array $link Link data.
public function addLink($link)
$this->addEvent(self::CREATED, $link['id']);
* Add Event: update existing link.
* @param array $link Link data.
public function updateLink($link)
$this->addEvent(self::UPDATED, $link['id']);
* Add Event: delete existing link.
* @param array $link Link data.
public function deleteLink($link)
$this->addEvent(self::DELETED, $link['id']);
* Add Event: settings updated.
public function updateSettings()
* Save a new event and write it in the history file.
* @param string $status Event key, should be defined as constant.
* @param mixed $id Event item identifier (e.g. link ID).
protected function addEvent($status, $id = null)
if ($this->history === null) {
$item = [
'event' => $status,
'datetime' => new DateTime(),
'id' => $id !== null ? $id : '',
$this->history = array_merge([$item], $this->history);
* Check that the history file is writable.
* Create the file if it doesn't exist.
* @throws Exception if it isn't writable.
protected function check()
if (! is_file($this->historyFilePath)) {
FileUtils::writeFlatDB($this->historyFilePath, []);
if (! is_writable($this->historyFilePath)) {
throw new Exception('History file isn\'t readable or writable');
* Read JSON history file.
protected function read()
$this->history = FileUtils::readFlatDB($this->historyFilePath, []);
if ($this->history === false) {
throw new Exception('Could not parse history file');
* Write JSON history file and delete old entries.
protected function write()
$comparaison = new DateTime('-'. $this->retentionTime . ' seconds');
foreach ($this->history as $key => $value) {
if ($value['datetime'] < $comparaison) {
FileUtils::writeFlatDB($this->historyFilePath, array_values($this->history));
* Get the History.
* @return array
public function getHistory()
if ($this->history === null) {
return $this->history;

application/HttpUtils.php Normal file
View File

@ -0,0 +1,431 @@
* GET an HTTP URL to retrieve its content
* Uses the cURL library or a fallback method
* @param string $url URL to get (http://...)
* @param int $timeout network timeout (in seconds)
* @param int $maxBytes maximum downloaded bytes (default: 4 MiB)
* @return array HTTP response headers, downloaded content
* Output format:
* [0] = associative array containing HTTP response headers
* [1] = URL content (downloaded data)
* Example:
* list($headers, $data) = get_http_response('');
* if (strpos($headers[0], '200 OK') !== false) {
* echo 'Data type: '.htmlspecialchars($headers['Content-Type']);
* } else {
* echo 'There was an error: '.htmlspecialchars($headers[0]);
* }
* @see
* @see
* @see
* @see
* @see
* @see
* @see
function get_http_response($url, $timeout = 30, $maxBytes = 4194304)
$urlObj = new Url($url);
$cleanUrl = $urlObj->idnToAscii();
if (!filter_var($cleanUrl, FILTER_VALIDATE_URL) || !$urlObj->isHttp()) {
return array(array(0 => 'Invalid HTTP Url'), false);
$userAgent =
'Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:45.0)'
. ' Gecko/20100101 Firefox/45.0';
$acceptLanguage =
substr(setlocale(LC_COLLATE, 0), 0, 2) . ',en-US;q=0.7,en;q=0.3';
$maxRedirs = 3;
if (!function_exists('curl_init')) {
return get_http_response_fallback(
$ch = curl_init($cleanUrl);
if ($ch === false) {
return array(array(0 => 'curl_init() error'), false);
// General cURL settings
curl_setopt($ch, CURLOPT_AUTOREFERER, true);
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true);
curl_setopt($ch, CURLOPT_HEADER, true);
array('Accept-Language: ' . $acceptLanguage)
curl_setopt($ch, CURLOPT_MAXREDIRS, $maxRedirs);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_TIMEOUT, $timeout);
curl_setopt($ch, CURLOPT_USERAGENT, $userAgent);
// Max download size management
curl_setopt($ch, CURLOPT_BUFFERSIZE, 1024);
curl_setopt($ch, CURLOPT_NOPROGRESS, false);
function($arg0, $arg1, $arg2, $arg3, $arg4 = 0) use ($maxBytes)
if (version_compare(phpversion(), '5.5', '<')) {
// PHP version lower than 5.5
// Callback has 4 arguments
$downloaded = $arg1;
} else {
// Callback has 5 arguments
$downloaded = $arg2;
// Non-zero return stops downloading
return ($downloaded > $maxBytes) ? 1 : 0;
$response = curl_exec($ch);
$errorNo = curl_errno($ch);
$errorStr = curl_error($ch);
$headSize = curl_getinfo($ch, CURLINFO_HEADER_SIZE);
if ($response === false) {
* Workaround to match fallback method behaviour
* Removing this would require updating
* GetHttpUrlTest::testGetInvalidRemoteUrl()
return array(false, false);
return array(array(0 => 'curl_exec() error: ' . $errorStr), false);
// Formatting output like the fallback method
$rawHeaders = substr($response, 0, $headSize);
// Keep only headers from latest redirection
$rawHeadersArrayRedirs = explode("\r\n\r\n", trim($rawHeaders));
$rawHeadersLastRedir = end($rawHeadersArrayRedirs);
$content = substr($response, $headSize);
$headers = array();
foreach (preg_split('~[\r\n]+~', $rawHeadersLastRedir) as $line) {
if (empty($line) || ctype_space($line)) {
$splitLine = explode(': ', $line, 2);
if (count($splitLine) > 1) {
$key = $splitLine[0];
$value = $splitLine[1];
if (array_key_exists($key, $headers)) {
if (!is_array($headers[$key])) {
$headers[$key] = array(0 => $headers[$key]);
$headers[$key][] = $value;
} else {
$headers[$key] = $value;
} else {
$headers[] = $splitLine[0];
return array($headers, $content);
* GET an HTTP URL to retrieve its content (fallback method)
* @param string $cleanUrl URL to get (http://... valid and in ASCII form)
* @param int $timeout network timeout (in seconds)
* @param int $maxBytes maximum downloaded bytes
* @param string $userAgent "User-Agent" header
* @param string $acceptLanguage "Accept-Language" header
* @param int $maxRedr maximum amount of redirections followed
* @return array HTTP response headers, downloaded content
* Output format:
* [0] = associative array containing HTTP response headers
* [1] = URL content (downloaded data)
* @see
* @see
* @see
function get_http_response_fallback(
) {
$options = array(
'http' => array(
'method' => 'GET',
'timeout' => $timeout,
'user_agent' => $userAgent,
'header' => "Accept: */*\r\n"
. 'Accept-Language: ' . $acceptLanguage
list($headers, $finalUrl) = get_redirected_headers($cleanUrl, $maxRedr);
if (! $headers || strpos($headers[0], '200 OK') === false) {
$options['http']['request_fulluri'] = true;
list($headers, $finalUrl) = get_redirected_headers($cleanUrl, $maxRedr);
if (! $headers) {
return array($headers, false);
try {
// TODO: catch Exception in calling code (thumbnailer)
$context = stream_context_create($options);
$content = file_get_contents($finalUrl, false, $context, -1, $maxBytes);
} catch (Exception $exc) {
return array(array(0 => 'HTTP Error'), $exc->getMessage());
return array($headers, $content);
* Retrieve HTTP headers, following n redirections (temporary and permanent ones).
* @param string $url initial URL to reach.
* @param int $redirectionLimit max redirection follow.
* @return array HTTP headers, or false if it failed.
function get_redirected_headers($url, $redirectionLimit = 3)
$headers = get_headers($url, 1);
if (!empty($headers['location']) && empty($headers['Location'])) {
$headers['Location'] = $headers['location'];
// Headers found, redirection found, and limit not reached.
if ($redirectionLimit-- > 0
&& !empty($headers)
&& (strpos($headers[0], '301') !== false || strpos($headers[0], '302') !== false)
&& !empty($headers['Location'])) {
$redirection = is_array($headers['Location']) ? end($headers['Location']) : $headers['Location'];
if ($redirection != $url) {
$redirection = getAbsoluteUrl($url, $redirection);
return get_redirected_headers($redirection, $redirectionLimit);
return array($headers, $url);
* Get an absolute URL from a complete one, and another absolute/relative URL.
* @param string $originalUrl The original complete URL.
* @param string $newUrl The new one, absolute or relative.
* @return string Final URL:
* - $newUrl if it was already an absolute URL.
* - if it was relative, absolute URL from $originalUrl path.
function getAbsoluteUrl($originalUrl, $newUrl)
$newScheme = parse_url($newUrl, PHP_URL_SCHEME);
// Already an absolute URL.
if (!empty($newScheme)) {
return $newUrl;
$parts = parse_url($originalUrl);
$final = $parts['scheme'] .'://'. $parts['host'];
$final .= (!empty($parts['port'])) ? $parts['port'] : '';
$final .= '/';
if ($newUrl[0] != '/') {
$final .= substr(ltrim($parts['path'], '/'), 0, strrpos($parts['path'], '/'));
$final .= ltrim($newUrl, '/');
return $final;
* Returns the server's base URL: scheme://domain.tld[:port]
* @param array $server the $_SERVER array
* @return string the server's base URL
* @see
* @see
* @see
* @see
function server_url($server)
$scheme = 'http';
$port = '';
// Shaarli is served behind a proxy
if (isset($server['HTTP_X_FORWARDED_PROTO'])) {
// Keep forwarded scheme
if (strpos($server['HTTP_X_FORWARDED_PROTO'], ',') !== false) {
$schemes = explode(',', $server['HTTP_X_FORWARDED_PROTO']);
$scheme = trim($schemes[0]);
} else {
$scheme = $server['HTTP_X_FORWARDED_PROTO'];
if (isset($server['HTTP_X_FORWARDED_PORT'])) {
// Keep forwarded port
if (strpos($server['HTTP_X_FORWARDED_PORT'], ',') !== false) {
$ports = explode(',', $server['HTTP_X_FORWARDED_PORT']);
$port = trim($ports[0]);
} else {
$port = $server['HTTP_X_FORWARDED_PORT'];
if (($scheme == 'http' && $port != '80')
|| ($scheme == 'https' && $port != '443')
) {
$port = ':' . $port;
} else {
$port = '';
if (isset($server['HTTP_X_FORWARDED_HOST'])) {
// Keep forwarded host
if (strpos($server['HTTP_X_FORWARDED_HOST'], ',') !== false) {
$hosts = explode(',', $server['HTTP_X_FORWARDED_HOST']);
$host = trim($hosts[0]);
} else {
$host = $server['HTTP_X_FORWARDED_HOST'];
} else {
$host = $server['SERVER_NAME'];
return $scheme.'://'.$host.$port;
// SSL detection
if ((! empty($server['HTTPS']) && strtolower($server['HTTPS']) == 'on')
|| (isset($server['SERVER_PORT']) && $server['SERVER_PORT'] == '443')) {
$scheme = 'https';
// Do not append standard port values
if (($scheme == 'http' && $server['SERVER_PORT'] != '80')
|| ($scheme == 'https' && $server['SERVER_PORT'] != '443')) {
$port = ':'.$server['SERVER_PORT'];
return $scheme.'://'.$server['SERVER_NAME'].$port;
* Returns the absolute URL of the current script, without the query
* If the resource is "index.php", then it is removed (for better-looking URLs)
* @param array $server the $_SERVER array
* @return string the absolute URL of the current script, without the query
function index_url($server)
$scriptname = $server['SCRIPT_NAME'];
if (endsWith($scriptname, 'index.php')) {
$scriptname = substr($scriptname, 0, -9);
return server_url($server) . $scriptname;
* Returns the absolute URL of the current script, with the query
* If the resource is "index.php", then it is removed (for better-looking URLs)
* @param array $server the $_SERVER array
* @return string the absolute URL of the current script, with the query
function page_url($server)
if (! empty($server['QUERY_STRING'])) {
return index_url($server).'?'.$server['QUERY_STRING'];
return index_url($server);
* Retrieve the initial IP forwarded by the reverse proxy.
* Inspired from:
* @param array $server $_SERVER array which contains HTTP headers.
* @param array $trustedIps List of trusted IP from the configuration.
* @return string|bool The forwarded IP, or false if none could be extracted.
function getIpAddressFromProxy($server, $trustedIps)
$forwardedIpHeader = 'HTTP_X_FORWARDED_FOR';
if (empty($server[$forwardedIpHeader])) {
return false;
$ips = preg_split('/\s*,\s*/', $server[$forwardedIpHeader]);
$ips = array_diff($ips, $trustedIps);
if (empty($ips)) {
return false;
return array_pop($ips);
* Returns true if Shaarli's currently browsed in HTTPS.
* Supports reverse proxies (if the headers are correctly set).
* @param array $server $_SERVER.
* @return bool true if HTTPS, false otherwise.
function is_https($server)
if (isset($server['HTTP_X_FORWARDED_PORT'])) {
// Keep forwarded port
if (strpos($server['HTTP_X_FORWARDED_PORT'], ',') !== false) {
$ports = explode(',', $server['HTTP_X_FORWARDED_PORT']);
$port = trim($ports[0]);
} else {
$port = $server['HTTP_X_FORWARDED_PORT'];
if ($port == '443') {
return true;
return ! empty($server['HTTPS']);

application/Languages.php Normal file
View File

@ -0,0 +1,21 @@
* Wrapper function for translation which match the API
* of gettext()/_() and ngettext().
* Not doing translation for now.
* @param string $text Text to translate.
* @param string $nText The plural message ID.
* @param int $nb The number of items for plural forms.
* @return String Text translated.
function t($text, $nText = '', $nb = 0) {
if (empty($nText)) {
return $text;
$actualForm = $nb > 1 ? $nText : $text;
return sprintf($actualForm, $nb);

application/LinkDB.php Normal file
View File

@ -0,0 +1,567 @@
* Data storage for links.
* This object behaves like an associative array.
* Example:
* $myLinks = new LinkDB();
* echo $myLinks[350]['title'];
* foreach ($myLinks as $link)
* echo $link['title'].' at url '.$link['url'].'; description:'.$link['description'];
* Available keys:
* - id: primary key, incremental integer identifier (persistent)
* - description: description of the entry
* - created: creation date of this entry, DateTime object.
* - updated: last modification date of this entry, DateTime object.
* - private: Is this link private? 0=no, other value=yes
* - tags: tags attached to this entry (separated by spaces)
* - title Title of the link
* - url URL of the link. Used for displayable links (no redirector, relative, etc.).
* Can be absolute or relative.
* Relative URLs are permalinks (e.g.'?m-ukcw')
* - real_url Absolute processed URL.
* - shorturl Permalink smallhash
* Implements 3 interfaces:
* - ArrayAccess: behaves like an associative array;
* - Countable: there is a count() method;
* - Iterator: usable in foreach () loops.
* ID mechanism:
* ArrayAccess is implemented in a way that will allow to access a link
* with the unique identifier ID directly with $link[ID].
* Note that it's not the real key of the link array attribute.
* This mechanism is in place to have persistent link IDs,
* even though the internal array is reordered by date.
* Example:
* - DB: link #1 (2010-01-01) link #2 (2016-01-01)
* - Order: #2 #1
* - Import links containing: link #3 (2013-01-01)
* - New DB: link #1 (2010-01-01) link #2 (2016-01-01) link #3 (2013-01-01)
* - Real order: #2 #3 #1
class LinkDB implements Iterator, Countable, ArrayAccess
// Links are stored as a PHP serialized string
private $datastore;
// Link date storage format
const LINK_DATE_FORMAT = 'Ymd_His';
// List of links (associative array)
// - key: link date (e.g. "20110823_124546"),
// - value: associative array (keys: title, description...)
private $links;
// List of all recorded URLs (key=url, value=link offset)
// for fast reserve search (url-->link offset)
private $urls;
* @var array List of all links IDS mapped with their array offset.
* Map: id->offset.
protected $ids;
// List of offset keys (for the Iterator interface implementation)
private $keys;
// Position in the $this->keys array (for the Iterator interface)
private $position;
// Is the user logged in? (used to filter private links)
private $loggedIn;
// Hide public links
private $hidePublicLinks;
// link redirector set in user settings.
private $redirector;
* Set this to `true` to urlencode link behind redirector link, `false` to leave it untouched.
* Example:
* needs clean URL while needs urlencoded URL.
* @var boolean $redirectorEncode parameter: true or false
private $redirectorEncode;
* Creates a new LinkDB
* Checks if the datastore exists; else, attempts to create a dummy one.
* @param string $datastore datastore file path.
* @param boolean $isLoggedIn is the user logged in?
* @param boolean $hidePublicLinks if true all links are private.
* @param string $redirector link redirector set in user settings.
* @param boolean $redirectorEncode Enable urlencode on redirected urls (default: true).
public function __construct(
$redirector = '',
$redirectorEncode = true
$this->datastore = $datastore;
$this->loggedIn = $isLoggedIn;
$this->hidePublicLinks = $hidePublicLinks;
$this->redirector = $redirector;
$this->redirectorEncode = $redirectorEncode === true;
* Countable - Counts elements of an object
public function count()
return count($this->links);
* ArrayAccess - Assigns a value to the specified offset
public function offsetSet($offset, $value)
// TODO: use exceptions instead of "die"
if (!$this->loggedIn) {
die('You are not authorized to add a link.');
if (!isset($value['id']) || empty($value['url'])) {
die('Internal Error: A link should always have an id and URL.');
if (($offset !== null && ! is_int($offset)) || ! is_int($value['id'])) {
die('You must specify an integer as a key.');
if ($offset !== null && $offset !== $value['id']) {
die('Array offset and link ID must be equal.');
// If the link exists, we reuse the real offset, otherwise new entry
$existing = $this->getLinkOffset($offset);
if ($existing !== null) {
$offset = $existing;
} else {
$offset = count($this->links);
$this->links[$offset] = $value;
$this->urls[$value['url']] = $offset;
$this->ids[$value['id']] = $offset;
* ArrayAccess - Whether or not an offset exists
public function offsetExists($offset)
return array_key_exists($this->getLinkOffset($offset), $this->links);
* ArrayAccess - Unsets an offset
public function offsetUnset($offset)
if (!$this->loggedIn) {
// TODO: raise an exception
die('You are not authorized to delete a link.');
$realOffset = $this->getLinkOffset($offset);
$url = $this->links[$realOffset]['url'];
* ArrayAccess - Returns the value at specified offset
public function offsetGet($offset)
$realOffset = $this->getLinkOffset($offset);
return isset($this->links[$realOffset]) ? $this->links[$realOffset] : null;
* Iterator - Returns the current element
public function current()
return $this[$this->keys[$this->position]];
* Iterator - Returns the key of the current element
public function key()
return $this->keys[$this->position];
* Iterator - Moves forward to next element
public function next()
* Iterator - Rewinds the Iterator to the first element
* Entries are sorted by date (latest first)
public function rewind()
$this->keys = array_keys($this->ids);
$this->position = 0;
* Iterator - Checks if current position is valid
public function valid()
return isset($this->keys[$this->position]);
* Checks if the DB directory and file exist
* If no DB file is found, creates a dummy DB.
private function check()
if (file_exists($this->datastore)) {
// Create a dummy database for example
$this->links = array();
$link = array(
'id' => 1,
'title'=>' Shaarli: the personal, minimalist, super-fast, no-database delicious clone',
'description'=>'Welcome to Shaarli! This is your first public bookmark. To edit or delete me, you must first login.
To learn how to use Shaarli, consult the link "Help/documentation" at the bottom of this page.
You use the community supported version of the original Shaarli project, by Sebastien Sauvage.',
'created'=> new DateTime(),
'tags'=>'opensource software'
$link['shorturl'] = link_small_hash($link['created'], $link['id']);
$this->links[1] = $link;
$link = array(
'id' => 0,
'title'=>'My secret stuff... -',
'description'=>'Shhhh! I\'m a private link only YOU can see. You can delete me too.',
'created'=> new DateTime('1 minute ago'),
$link['shorturl'] = link_small_hash($link['created'], $link['id']);
$this->links[0] = $link;
// Write database to disk
* Reads database from disk to memory
private function read()
// Public links are hidden and user not logged in => nothing to show
if ($this->hidePublicLinks && !$this->loggedIn) {
$this->links = array();
$this->links = FileUtils::readFlatDB($this->datastore, []);
$toremove = array();
foreach ($this->links as $key => &$link) {
if (! $this->loggedIn && $link['private'] != 0) {
// Transition for not upgraded databases.
$toremove[] = $key;
// Sanitize data fields.
// Remove private tags if the user is not logged in.
if (! $this->loggedIn) {
$link['tags'] = preg_replace('/(^|\s+)\.[^($|\s)]+\s*/', ' ', $link['tags']);
// Do not use the redirector for internal links (Shaarli note URL starting with a '?').
if (!empty($this->redirector) && !startsWith($link['url'], '?')) {
$link['real_url'] = $this->redirector;
if ($this->redirectorEncode) {
$link['real_url'] .= urlencode(unescape($link['url']));
} else {
$link['real_url'] .= $link['url'];
else {
$link['real_url'] = $link['url'];
// To be able to load links before running the update, and prepare the update
if (! isset($link['created'])) {
$link['id'] = $link['linkdate'];
$link['created'] = DateTime::createFromFormat(self::LINK_DATE_FORMAT, $link['linkdate']);
if (! empty($link['updated'])) {
$link['updated'] = DateTime::createFromFormat(self::LINK_DATE_FORMAT, $link['updated']);
$link['shorturl'] = smallHash($link['linkdate']);
// If user is not logged in, filter private links.
foreach ($toremove as $offset) {
* Saves the database from memory to disk
* @throws IOException the datastore is not writable
private function write()
FileUtils::writeFlatDB($this->datastore, $this->links);
* Saves the database from memory to disk
* @param string $pageCacheDir page cache directory
public function save($pageCacheDir)
if (!$this->loggedIn) {
// TODO: raise an Exception instead
die('You are not authorized to change the database.');
* Returns the link for a given URL, or False if it does not exist.
* @param string $url URL to search for
* @return mixed the existing link if it exists, else 'false'
public function getLinkFromUrl($url)
if (isset($this->urls[$url])) {
return $this->links[$this->urls[$url]];
return false;
* Returns the shaare corresponding to a smallHash.
* @param string $request QUERY_STRING server parameter.
* @return array $filtered array containing permalink data.
* @throws LinkNotFoundException if the smallhash is malformed or doesn't match any link.
public function filterHash($request)
$request = substr($request, 0, 6);
$linkFilter = new LinkFilter($this->links);
return $linkFilter->filter(LinkFilter::$FILTER_HASH, $request);
* Returns the list of articles for a given day.
* @param string $request day to filter. Format: YYYYMMDD.
* @return array list of shaare found.
public function filterDay($request) {
$linkFilter = new LinkFilter($this->links);
return $linkFilter->filter(LinkFilter::$FILTER_DAY, $request);
* Filter links according to search parameters.
* @param array $filterRequest Search request content. Supported keys:
* - searchtags: list of tags
* - searchterm: term search
* @param bool $casesensitive Optional: Perform case sensitive filter
* @param string $visibility return only all/private/public links
* @param string $untaggedonly return only untagged links
* @return array filtered links, all links if no suitable filter was provided.
public function filterSearch($filterRequest = array(), $casesensitive = false, $visibility = 'all', $untaggedonly = false)
// Filter link database according to parameters.
$searchtags = isset($filterRequest['searchtags']) ? escape($filterRequest['searchtags']) : '';
$searchterm = isset($filterRequest['searchterm']) ? escape($filterRequest['searchterm']) : '';
// Search tags + fullsearch - blank string parameter will return all links.
$type = LinkFilter::$FILTER_TAG | LinkFilter::$FILTER_TEXT; // == "vuotext"
$request = [$searchtags, $searchterm];
$linkFilter = new LinkFilter($this);
return $linkFilter->filter($type, $request, $casesensitive, $visibility, $untaggedonly);
* Returns the list tags appearing in the links with the given tags
* @param $filteringTags: tags selecting the links to consider
* @param $visibility: process only all/private/public links
* @return: a tag=>linksCount array
public function linksCountPerTag($filteringTags = [], $visibility = 'all')
$links = empty($filteringTags) ? $this->links : $this->filterSearch(['searchtags' => $filteringTags], false, $visibility);
$tags = array();
$caseMapping = array();
foreach ($links as $link) {
foreach (preg_split('/\s+/', $link['tags'], 0, PREG_SPLIT_NO_EMPTY) as $tag) {
if (empty($tag)) {
// The first case found will be displayed.
if (!isset($caseMapping[strtolower($tag)])) {
$caseMapping[strtolower($tag)] = $tag;
$tags[$caseMapping[strtolower($tag)]] = 0;
// Sort tags by usage (most used tag first)
return $tags;
* Rename or delete a tag across all links.
* @param string $from Tag to rename
* @param string $to New tag. If none is provided, the from tag will be deleted
* @return array|bool List of altered links or false on error
public function renameTag($from, $to)
if (empty($from)) {
return false;
$delete = empty($to);
// True for case-sensitive tag search.
$linksToAlter = $this->filterSearch(['searchtags' => $from], true);
foreach($linksToAlter as $key => &$value)
$tags = preg_split('/\s+/', trim($value['tags']));
if (($pos = array_search($from, $tags)) !== false) {
if ($delete) {
unset($tags[$pos]); // Remove tag.
} else {
$tags[$pos] = trim($to);
$value['tags'] = trim(implode(' ', array_unique($tags)));
$this[$value['id']] = $value;
return $linksToAlter;
* Returns the list of days containing articles (oldest first)
* Output: An array containing days (in format YYYYMMDD).
public function days()
$linkDays = array();
foreach ($this->links as $link) {
$linkDays[$link['created']->format('Ymd')] = 0;
$linkDays = array_keys($linkDays);
return $linkDays;
* Reorder links by creation date (newest first).
* Also update the urls and ids mapping arrays.
* @param string $order ASC|DESC
public function reorder($order = 'DESC')
$order = $order === 'ASC' ? -1 : 1;
// Reorder array by dates.
usort($this->links, function($a, $b) use ($order) {
return $a['created'] < $b['created'] ? 1 * $order : -1 * $order;
$this->urls = array();
$this->ids = array();
foreach ($this->links as $key => $link) {
$this->urls[$link['url']] = $key;
$this->ids[$link['id']] = $key;
* Return the next key for link creation.
* E.g. If the last ID is 597, the next will be 598.
* @return int next ID.
public function getNextId()
if (!empty($this->ids)) {
return max(array_keys($this->ids)) + 1;
return 0;
* Returns a link offset in links array from its unique ID.
* @param int $id Persistent ID of a link.
* @return int Real offset in local array, or null if doesn't exist.
protected function getLinkOffset($id)
if (isset($this->ids[$id])) {
return $this->ids[$id];
return null;

application/LinkFilter.php Normal file
View File

@ -0,0 +1,448 @@
* Class LinkFilter.
* Perform search and filter operation on link data list.
class LinkFilter
* @var string permalinks.
public static $FILTER_HASH = 'permalink';
* @var string text search.
public static $FILTER_TEXT = 'fulltext';
* @var string tag filter.
public static $FILTER_TAG = 'tags';
* @var string filter by day.
public static $FILTER_DAY = 'FILTER_DAY';
* @var string Allowed characters for hashtags (regex syntax).
public static $HASHTAG_CHARS = '\p{Pc}\p{N}\p{L}\p{Mn}';
* @var LinkDB all available links.
private $links;
* @param LinkDB $links initialization.
public function __construct($links)
$this->links = $links;
* Filter links according to parameters.
* @param string $type Type of filter (eg. tags, permalink, etc.).
* @param mixed $request Filter content.
* @param bool $casesensitive Optional: Perform case sensitive filter if true.
* @param string $visibility Optional: return only all/private/public links
* @param string $untaggedonly Optional: return only untagged links. Applies only if $type includes FILTER_TAG
* @return array filtered link list.
public function filter($type, $request, $casesensitive = false, $visibility = 'all', $untaggedonly = false)
if (! in_array($visibility, ['all', 'public', 'private'])) {
$visibility = 'all';
switch($type) {
case self::$FILTER_HASH:
return $this->filterSmallHash($request);
case self::$FILTER_TAG | self::$FILTER_TEXT: // == "vuotext"
$noRequest = empty($request) || (empty($request[0]) && empty($request[1]));
if ($noRequest) {
if ($untaggedonly) {
return $this->filterUntagged($visibility);
return $this->noFilter($visibility);
if ($untaggedonly) {
$filtered = $this->filterUntagged($visibility);
} else {
$filtered = $this->links;
if (!empty($request[0])) {
$filtered = (new LinkFilter($filtered))->filterTags($request[0], $casesensitive, $visibility);
if (!empty($request[1])) {
$filtered = (new LinkFilter($filtered))->filterFulltext($request[1], $visibility);
return $filtered;
case self::$FILTER_TEXT:
return $this->filterFulltext($request, $visibility);
case self::$FILTER_TAG:
if ($untaggedonly) {
return $this->filterUntagged($visibility);
} else {
return $this->filterTags($request, $casesensitive, $visibility);
case self::$FILTER_DAY:
return $this->filterDay($request);
return $this->noFilter($visibility);
* Unknown filter, but handle private only.
* @param string $visibility Optional: return only all/private/public links
* @return array filtered links.
private function noFilter($visibility = 'all')
if ($visibility === 'all') {
return $this->links;
$out = array();
foreach ($this->links as $key => $value) {
if ($value['private'] && $visibility === 'private') {
$out[$key] = $value;
} else if (! $value['private'] && $visibility === 'public') {
$out[$key] = $value;
return $out;
* Returns the shaare corresponding to a smallHash.
* @param string $smallHash permalink hash.
* @return array $filtered array containing permalink data.
* @throws LinkNotFoundException if the smallhash doesn't match any link.
private function filterSmallHash($smallHash)
$filtered = array();
foreach ($this->links as $key => $l) {
if ($smallHash == $l['shorturl']) {
// Yes, this is ugly and slow
$filtered[$key] = $l;
return $filtered;
if (empty($filtered)) {
throw new LinkNotFoundException();
return $filtered;
* Returns the list of links corresponding to a full-text search
* Searches:
* - in the URLs, title and description;
* - are case-insensitive;
* - terms surrounded by quotes " are exact terms search.
* - terms starting with a dash - are excluded (except exact terms).
* Example:
* print_r($mydb->filterFulltext('hollandais'));
* mb_convert_case($val, MB_CASE_LOWER, 'UTF-8')
* - allows to perform searches on Unicode text
* - see for examples
* @param string $searchterms search query.
* @param string $visibility Optional: return only all/private/public links.
* @return array search results.
private function filterFulltext($searchterms, $visibility = 'all')
if (empty($searchterms)) {
return $this->noFilter($visibility);
$filtered = array();
$search = mb_convert_case(html_entity_decode($searchterms), MB_CASE_LOWER, 'UTF-8');
$exactRegex = '/"([^"]+)"/';
// Retrieve exact search terms.
preg_match_all($exactRegex, $search, $exactSearch);
$exactSearch = array_values(array_filter($exactSearch[1]));
// Remove exact search terms to get AND terms search.
$explodedSearchAnd = explode(' ', trim(preg_replace($exactRegex, '', $search)));
$explodedSearchAnd = array_values(array_filter($explodedSearchAnd));
// Filter excluding terms and update andSearch.
$excludeSearch = array();
$andSearch = array();
foreach ($explodedSearchAnd as $needle) {
if ($needle[0] == '-' && strlen($needle) > 1) {
$excludeSearch[] = substr($needle, 1);
} else {
$andSearch[] = $needle;
$keys = array('title', 'description', 'url', 'tags');
// Iterate over every stored link.
foreach ($this->links as $id => $link) {
// ignore non private links when 'privatonly' is on.
if ($visibility !== 'all') {
if (! $link['private'] && $visibility === 'private') {
} else if ($link['private'] && $visibility === 'public') {
// Concatenate link fields to search across fields.
// Adds a '\' separator for exact search terms.
$content = '';
foreach ($keys as $key) {
$content .= mb_convert_case($link[$key], MB_CASE_LOWER, 'UTF-8') . '\\';
// Be optimistic
$found = true;
// First, we look for exact term search
for ($i = 0; $i < count($exactSearch) && $found; $i++) {
$found = strpos($content, $exactSearch[$i]) !== false;
// Iterate over keywords, if keyword is not found,
// no need to check for the others. We want all or nothing.
for ($i = 0; $i < count($andSearch) && $found; $i++) {
$found = strpos($content, $andSearch[$i]) !== false;
// Exclude terms.
for ($i = 0; $i < count($excludeSearch) && $found; $i++) {
$found = strpos($content, $excludeSearch[$i]) === false;
if ($found) {
$filtered[$id] = $link;
return $filtered;
* generate a regex fragment out of a tag
* @param string $tag to to generate regexs from. may start with '-' to negate, contain '*' as wildcard
* @return string generated regex fragment
private static function tag2regex($tag)
$len = strlen($tag);
if(!$len || $tag === "-" || $tag === "*"){
// nothing to search, return empty regex
return '';
if($tag[0] === "-") {
// query is negated
$i = 1; // use offset to start after '-' character
$regex = '(?!'; // create negative lookahead
} else {
$i = 0; // start at first character
$regex = '(?='; // use positive lookahead
$regex .= '.*(?:^| )'; // before tag may only be a space or the beginning
// iterate over string, separating it into placeholder and content
for(; $i < $len; $i++){
if($tag[$i] === '*'){
// placeholder found
$regex .= '[^ ]*?';
} else {
// regular characters
$offset = strpos($tag, '*', $i);
if($offset === false){
// no placeholder found, set offset to end of string
$offset = $len;
// subtract one, as we want to get before the placeholder or end of string
$offset -= 1;
// we got a tag name that we want to search for. escape any regex characters to prevent conflicts.
$regex .= preg_quote(substr($tag, $i, $offset - $i + 1), '/');
// move $i on
$i = $offset;
$regex .= '(?:$| ))'; // after the tag may only be a space or the end
return $regex;
* Returns the list of links associated with a given list of tags
* You can specify one or more tags, separated by space or a comma, e.g.
* print_r($mydb->filterTags('linux programming'));
* @param string $tags list of tags separated by commas or blank spaces.
* @param bool $casesensitive ignore case if false.
* @param string $visibility Optional: return only all/private/public links.
* @return array filtered links.
public function filterTags($tags, $casesensitive = false, $visibility = 'all')
// get single tags (we may get passed an array, even though the docs say different)
$inputTags = $tags;
if(!is_array($tags)) {
// we got an input string, split tags
$inputTags = preg_split('/(?:\s+)|,/', $inputTags, -1, PREG_SPLIT_NO_EMPTY);
// no input tags
return $this->noFilter($visibility);
// build regex from all tags
$re = '/^' . implode(array_map("self::tag2regex", $inputTags)) . '.*$/';
if(!$casesensitive) {
// make regex case insensitive
$re .= 'i';
// create resulting array
$filtered = array();
// iterate over each link
foreach ($this->links as $key => $link) {
// check level of visibility
// ignore non private links when 'privateonly' is on.
if ($visibility !== 'all') {
if (! $link['private'] && $visibility === 'private') {
} else if ($link['private'] && $visibility === 'public') {
$search = $link['tags']; // build search string, start with tags of current link
if(strlen(trim($link['description'])) && strpos($link['description'], '#') !== false){
// description given and at least one possible tag found
$descTags = array();
// find all tags in the form of #tag in the description
'/(?<![' . self::$HASHTAG_CHARS . '])#([' . self::$HASHTAG_CHARS . ']+?)\b/sm',
// there were some tags in the description, add them to the search string
$search .= ' ' . implode(' ', $descTags[1]);
// match regular expression with search string
if(!preg_match($re, $search)){
// this entry does _not_ match our regex
$filtered[$key] = $link;
return $filtered;
* Return only links without any tag.
* @param string $visibility return only all/private/public links.
* @return array filtered links.
public function filterUntagged($visibility)
$filtered = [];
foreach ($this->links as $key => $link) {
if ($visibility !== 'all') {
if (! $link['private'] && $visibility === 'private') {
} else if ($link['private'] && $visibility === 'public') {
if (empty(trim($link['tags']))) {
$filtered[$key] = $link;
return $filtered;
* Returns the list of articles for a given day, chronologically sorted
* Day must be in the form 'YYYYMMDD' (e.g. '20120125'), e.g.
* print_r($mydb->filterDay('20120125'));
* @param string $day day to filter.
* @return array all link matching given day.
* @throws Exception if date format is invalid.
public function filterDay($day)
if (! checkDateFormat('Ymd', $day)) {
throw new Exception('Invalid date format');
$filtered = array();
foreach ($this->links as $key => $l) {
if ($l['created']->format('Ymd') == $day) {
$filtered[$key] = $l;
// sort by date ASC
return array_reverse($filtered, true);
* Convert a list of tags (str) to an array. Also
* - handle case sensitivity.
* - accepts spaces commas as separator.
* @param string $tags string containing a list of tags.
* @param bool $casesensitive will convert everything to lowercase if false.
* @return array filtered tags string.
public static function tagsStrToArray($tags, $casesensitive)
// We use UTF-8 conversion to handle various graphemes (i.e. cyrillic, or greek)
$tagsOut = $casesensitive ? $tags : mb_convert_case($tags, MB_CASE_LOWER, 'UTF-8');
$tagsOut = str_replace(',', ' ', $tagsOut);
return preg_split('/\s+/', $tagsOut, -1, PREG_SPLIT_NO_EMPTY);
class LinkNotFoundException extends Exception
protected $message = 'The link you are trying to reach does not exist or has been deleted.';

@ -0,0 +1,186 @
* Extract title from an HTML document.
* @param string $html HTML content where to look for a title.
* @return bool|string Extracted title if found, false otherwise.
function html_extract_title($html)
if (preg_match('!<title.*?>(.*?)</title>!is', $html, $matches)) {
return trim(str_replace("\n", '', $matches[1]));
return false;
* Determine charset from downloaded page.
* Priority:
* 1. HTTP headers (Content type).
* 2. HTML content page (tag <meta charset>).
* 3. Use a default charset (default: UTF-8).
* @param array $headers HTTP headers array.
* @param string $htmlContent HTML content where to look for charset.
* @param string $defaultCharset Default charset to apply if other methods failed.
* @return string Determined charset.
function get_charset($headers, $htmlContent, $defaultCharset = 'utf-8')
if ($charset = headers_extract_charset($headers)) {
return $charset;
if ($charset = html_extract_charset($htmlContent)) {
return $charset;
return $defaultCharset;
* Extract charset from HTTP headers if it's defined.
* @param array $headers HTTP headers array.
* @return bool|string Charset string if found (lowercase), false otherwise.
function headers_extract_charset($headers)
if (! empty($headers['Content-Type']) && strpos($headers['Content-Type'], 'charset=') !== false) {
preg_match('/charset="?([^; ]+)/i', $headers['Content-Type'], $match);
if (! empty($match[1])) {
return strtolower(trim($match[1]));
return false;
* Extract charset HTML content (tag <meta charset>).
* @param string $html HTML content where to look for charset.
* @return bool|string Charset string if found, false otherwise.
function html_extract_charset($html)
// Get encoding specified in HTML header.
preg_match('#<meta .*charset=["\']?([^";\'>/]+)["\']? */?>#Usi', $html, $enc);
if (!empty($enc[1])) {
return strtolower($enc[1]);
return false;
* Count private links in given linklist.
* @param array|Countable $links Linklist.
* @return int Number of private links.
function count_private($links)
$cpt = 0;
foreach ($links as $link) {
if ($link['private']) {
$cpt += 1;
return $cpt;
* In a string, converts URLs to clickable links.
* @param string $text input string.
* @param string $redirector if a redirector is set, use it to gerenate links.
* @return string returns $text with all links converted to HTML links.
* @see Function inspired from
function text2clickable($text, $redirector = '')
$regex = '!(((?:https?|ftp|file)://|apt:|magnet:)\S+[a-z0-9\(\)]/?)!si';
if (empty($redirector)) {
return preg_replace($regex, '<a href="$1">$1</a>', $text);
// Redirector is set, urlencode the final URL.
return preg_replace_callback(
function ($matches) use ($redirector) {
return '<a href="' . $redirector . urlencode($matches[1]) .'">'. $matches[1] .'</a>';
* Auto-link hashtags.
* @param string $description Given description.
* @param string $indexUrl Root URL.
* @return string Description with auto-linked hashtags.
function hashtag_autolink($description, $indexUrl = '')
* To support unicode:
* \p{Pc} - to match underscore
* \p{N} - numeric character in any script
* \p{L} - letter from any language
* \p{Mn} - any non marking space (accents, umlauts, etc)
$regex = '/(^|\s)#([\p{Pc}\p{N}\p{L}\p{Mn}]+)/mui';
$replacement = '$1<a href="'. $indexUrl .'?addtag=$2" title="Hashtag $2">#$2</a>';
return preg_replace($regex, $replacement, $description);
* This function inserts &nbsp; where relevant so that multiple spaces are properly displayed in HTML
* even in the absence of <pre> (This is used in description to keep text formatting).
* @param string $text input text.
* @return string formatted text.
function space2nbsp($text)
return preg_replace('/(^| ) /m', '$1&nbsp;', $text);
* Format Shaarli's description
* @param string $description shaare's description.
* @param string $redirector if a redirector is set, use it to gerenate links.
* @param string $indexUrl URL to Shaarli's index.
* @return string formatted description.
function format_description($description, $redirector = '', $indexUrl = '') {
return nl2br(space2nbsp(hashtag_autolink(text2clickable($description, $redirector), $indexUrl)));
* Generate a small hash for a link.
* @param DateTime $date Link creation date.
* @param int $id Link ID.
* @return string the small hash generated from link data.
function link_small_hash($date, $id)
return smallHash($date->format(LinkDB::LINK_DATE_FORMAT) . $id);

View File

@ -0,0 +1,211 @
use Psr\Log\LogLevel;
use Shaarli\Config\ConfigManager;
use Shaarli\NetscapeBookmarkParser\NetscapeBookmarkParser;
use Katzgrau\KLogger\Logger;
* Utilities to import and export bookmarks using the Netscape format
* TODO: Not static, use a container.
class NetscapeBookmarkUtils
* Filters links and adds Netscape-formatted fields
* Added fields:
* - timestamp link addition date, using the Unix epoch format
* - taglist comma-separated tag list
* @param LinkDB $linkDb Link datastore
* @param string $selection Which links to export: (all|private|public)
* @param bool $prependNoteUrl Prepend note permalinks with the server's URL
* @param string $indexUrl Absolute URL of the Shaarli index page
* @throws Exception Invalid export selection
* @return array The links to be exported, with additional fields
public static function filterAndFormat($linkDb, $selection, $prependNoteUrl, $indexUrl)
// see tpl/export.html for possible values
if (! in_array($selection, array('all', 'public', 'private'))) {
throw new Exception('Invalid export selection: "'.$selection.'"');
$bookmarkLinks = array();
foreach ($linkDb as $link) {
if ($link['private'] != 0 && $selection == 'public') {
if ($link['private'] == 0 && $selection == 'private') {
$date = $link['created'];
$link['timestamp'] = $date->getTimestamp();
$link['taglist'] = str_replace(' ', ',', $link['tags']);
if (startsWith($link['url'], '?') && $prependNoteUrl) {
$link['url'] = $indexUrl . $link['url'];
$bookmarkLinks[] = $link;
return $bookmarkLinks;
* Generates an import status summary
* @param string $filename name of the file to import
* @param int $filesize size of the file to import
* @param int $importCount how many links were imported
* @param int $overwriteCount how many links were overwritten
* @param int $skipCount how many links were skipped
* @return string Summary of the bookmark import status
private static function importStatus(
$status = 'File '.$filename.' ('.$filesize.' bytes) ';
if ($importCount == 0 && $overwriteCount == 0 && $skipCount == 0) {
$status .= 'has an unknown file format. Nothing was imported.';
} else {
$status .= 'was successfully processed: '.$importCount.' links imported, ';
$status .= $overwriteCount.' links overwritten, ';
$status .= $skipCount.' links skipped.';
return $status;
* Imports Web bookmarks from an uploaded Netscape bookmark dump
* @param array $post Server $_POST parameters
* @param array $files Server $_FILES parameters
* @param LinkDB $linkDb Loaded LinkDB instance
* @param ConfigManager $conf instance
* @param History $history History instance
* @return string Summary of the bookmark import status
public static function import($post, $files, $linkDb, $conf, $history)
$filename = $files['filetoupload']['name'];
$filesize = $files['filetoupload']['size'];
$data = file_get_contents($files['filetoupload']['tmp_name']);
if (strpos($data, '<!DOCTYPE NETSCAPE-Bookmark-file-1>') === false) {
return self::importStatus($filename, $filesize);
// Overwrite existing links?
$overwrite = ! empty($post['overwrite']);
// Add tags to all imported links?
if (empty($post['default_tags'])) {
$defaultTags = array();
} else {
$defaultTags = preg_split(
// links are imported as public by default
$defaultPrivacy = 0;
$parser = new NetscapeBookmarkParser(
true, // nested tag support
$defaultTags, // additional user-specified tags
strval(1 - $defaultPrivacy), // defaultPub = 1 - defaultPrivacy
$conf->get('resource.data_dir') // log path, will be overridden
$logger = new Logger(
! $conf->get('dev.debug') ? LogLevel::INFO : LogLevel::DEBUG,
'prefix' => 'import.',
'extension' => 'log',
$bookmarks = $parser->parseString($data);
$importCount = 0;
$overwriteCount = 0;
$skipCount = 0;
foreach ($bookmarks as $bkm) {
$private = $defaultPrivacy;
if (empty($post['privacy']) || $post['privacy'] == 'default') {
// use value from the imported file
$private = $bkm['pub'] == '1' ? 0 : 1;
} else if ($post['privacy'] == 'private') {
// all imported links are private
$private = 1;
} else if ($post['privacy'] == 'public') {
// all imported links are public
$private = 0;
$newLink = array(
'title' => $bkm['title'],
'url' => $bkm['uri'],
'description' => $bkm['note'],
'private' => $private,
'tags' => $bkm['tags']
$existingLink = $linkDb->getLinkFromUrl($bkm['uri']);
if ($existingLink !== false) {
if ($overwrite === false) {
// Do not overwrite an existing link
// Overwrite an existing link, keep its date
$newLink['id'] = $existingLink['id'];
$newLink['created'] = $existingLink['created'];
$newLink['updated'] = new DateTime();
$newLink['shorturl'] = $existingLink['shorturl'];
$linkDb[$existingLink['id']] = $newLink;
// Add a new link - @ used for UNIX timestamps
$newLinkDate = new DateTime('@'.strval($bkm['time']));
$newLinkDate->setTimezone(new DateTimeZone(date_default_timezone_get()));
$newLink['created'] = $newLinkDate;
$newLink['id'] = $linkDb->getNextId();
$newLink['shorturl'] = link_small_hash($newLink['created'], $newLink['id']);
$linkDb[$newLink['id']] = $newLink;
return self::importStatus(

@ -0,0 +1,168 @
use Shaarli\Config\ConfigManager;
* This class is in charge of building the final page.
* (This is basically a wrapper around RainTPL which pre-fills some fields.)
* $p = new PageBuilder();
* $p->assign('myfield','myvalue');
* $p->renderPage('mytemplate');
class PageBuilder
* @var RainTPL RainTPL instance.
private $tpl;
* @var ConfigManager $conf Configuration Manager instance.
protected $conf;
* @var LinkDB $linkDB instance.
protected $linkDB;
* PageBuilder constructor.
* $tpl is initialized at false for lazy loading.
* @param ConfigManager $conf Configuration Manager instance (reference).
* @param LinkDB $linkDB instance.
public function __construct(&$conf, $linkDB = null)
$this->tpl = false;
$this->conf = $conf;
$this->linkDB = $linkDB;
* Initialize all default tpl tags.
private function initialize()
$this->tpl = new RainTPL();
try {
$version = ApplicationUtils::checkUpdate(
$this->tpl->assign('newVersion', escape($version));
$this->tpl->assign('versionError', '');
} catch (Exception $exc) {
logm($this->conf->get('resource.log'), $_SERVER['REMOTE_ADDR'], $exc->getMessage());
$this->tpl->assign('newVersion', '');
$this->tpl->assign('versionError', escape($exc->getMessage()));
$this->tpl->assign('feedurl', escape(index_url($_SERVER)));
$searchcrits = ''; // Search criteria
if (!empty($_GET['searchtags'])) {
$searchcrits .= '&searchtags=' . urlencode($_GET['searchtags']);
if (!empty($_GET['searchterm'])) {
$searchcrits .= '&searchterm=' . urlencode($_GET['searchterm']);
$this->tpl->assign('searchcrits', $searchcrits);
$this->tpl->assign('source', index_url($_SERVER));
$this->tpl->assign('version', SHAARLI_VERSION);
ApplicationUtils::getVersionHash(SHAARLI_VERSION, $this->conf->get('credentials.salt'))
$this->tpl->assign('scripturl', index_url($_SERVER));
@ -0,0 +1,242 @
if ($this->conf->exists('general.header_link')) {
$this->tpl->assign('titleLink', $this->conf->get('general.header_link'));
$this->tpl->assign('shaarlititle', $this->conf->get('general.title', 'Shaarli'));
$this->tpl->assign('openshaarli', $this->conf->get('security.open_shaarli', false));
$this->tpl->assign('showatom', $this->conf->get('feed.show_atom', true));
$this->tpl->assign('feed_type', $this->conf->get('feed.show_atom', true) !== false ? 'atom' : 'rss');
$this->tpl->assign('hide_timestamps', $this->conf->get('privacy.hide_timestamps', false));
$this->tpl->assign('token', getToken($this->conf));
if ($this->linkDB !== null) {
$this->tpl->assign('tags', $this->linkDB->linksCountPerTag());
// To be removed with a proper theme configuration.
$this->tpl->assign('conf', $this->conf);
* The following assign() method is basically the same as RainTPL (except lazy loading)
* @param string $placeholder Template placeholder.
* @param mixed $value Value to assign.
public function assign($placeholder, $value)
if ($this->tpl === false) {
$this->tpl->assign($placeholder, $value);
* Assign an array of data to the template builder.
* @param array $data Data to assign.
* @return false if invalid data.
public function assignAll($data)
if ($this->tpl === false) {
if (empty($data) || !is_array($data)){
return false;
foreach ($data as $key => $value) {
$this->assign($key, $value);
return true;
* Render a specific page (using a template file).
* e.g. $pb->renderPage('picwall');
* @param string $page Template filename (without extension).
public function renderPage($page)
if ($this->tpl === false) {
* Render a 404 page (uses the template : tpl/404.tpl)
* usage : $PAGE->render404('The link was deleted')
* @param string $message A messate to display what is not found
public function render404($message = 'The page you are trying to reach does not exist or has been deleted.')
header($_SERVER['SERVER_PROTOCOL'] . ' 404 Not Found');
$this->tpl->assign('error_message', $message);

View File

@ -0,0 +1,242 @
* Class PluginManager
* Use to manage, load and execute plugins.
class PluginManager
* List of authorized plugins from configuration file.
* @var array $authorizedPlugins
private $authorizedPlugins;
* List of loaded plugins.
* @var array $loadedPlugins
private $loadedPlugins = array();
* @var ConfigManager Configuration Manager instance.
protected $conf;
* @var array List of plugin errors.
protected $errors;
* Plugins subdirectory.
* @var string $PLUGINS_PATH
public static $PLUGINS_PATH = 'plugins';
* Plugins meta files extension.
* @var string $META_EXT
public static $META_EXT = 'meta';
* Constructor.
* @param ConfigManager $conf Configuration Manager instance.
public function __construct(&$conf)
$this->conf = $conf;
$this->errors = array();
* Load plugins listed in $authorizedPlugins.
* @param array $authorizedPlugins Names of plugin authorized to be loaded.
* @return void
public function load($authorizedPlugins)
$this->authorizedPlugins = $authorizedPlugins;
$dirs = glob(self::$PLUGINS_PATH . '/*', GLOB_ONLYDIR);
$dirnames = array_map('basename', $dirs);
foreach ($this->authorizedPlugins as $plugin) {
$index = array_search($plugin, $dirnames);
// plugin authorized, but its folder isn't listed
if ($index === false) {
try {
$this->loadPlugin($dirs[$index], $plugin);
catch (PluginFileNotFoundException $e) {
* Execute all plugins registered hook.
* @param string $hook name of the hook to trigger.
* @param array $data list of data to manipulate passed by reference.
* @param array $params additional parameters such as page target.
* @return void
public function executeHooks($hook, &$data, $params = array())
if (!empty($params['target'])) {
$data['_PAGE_'] = $params['target'];
if (isset($params['loggedin'])) {
$data['_LOGGEDIN_'] = $params['loggedin'];
foreach ($this->loadedPlugins as $plugin) {
$hookFunction = $this->buildHookName($hook, $plugin);
if (function_exists($hookFunction)) {
$data = call_user_func($hookFunction, $data, $this->conf);
* Load a single plugin from its files.
* Call the init function if it exists, and collect errors.
* Add them in $loadedPlugins if successful.
* @param string $dir plugin's directory.
* @param string $pluginName plugin's name.
* @return void
* @throws PluginFileNotFoundException - plugin files not found.
private function loadPlugin($dir, $pluginName)
if (!is_dir($dir)) {
throw new PluginFileNotFoundException($pluginName);
$pluginFilePath = $dir . '/' . $pluginName . '.php';
if (!is_file($pluginFilePath)) {
throw new PluginFileNotFoundException($pluginName);
$conf = $this->conf;
include_once $pluginFilePath;
$initFunction = $pluginName . '_init';
if (function_exists($initFunction)) {
$errors = call_user_func($initFunction, $this->conf);
if (!empty($errors)) {
$this->errors = array_merge($this->errors, $errors);
$this->loadedPlugins[] = $pluginName;
* Construct normalize hook name for a specific plugin.
* Format:
* hook_<plugin_name>_<hook_name>
* @param string $hook hook name.
* @param string $pluginName plugin name.
* @return string - plugin's hook name.
public function buildHookName($hook, $pluginName)
return 'hook_' . $pluginName . '_' . $hook;
* Retrieve plugins metadata from *.meta (INI) files into an array.
* Metadata contains:
* - plugin description [description]
* - parameters split with ';' [parameters]
* Respects plugins order from settings.
* @return array plugins metadata.
public function getPluginsMeta()
$metaData = array();
$dirs = glob(self::$PLUGINS_PATH . '/*', GLOB_ONLYDIR | GLOB_MARK);
// Browse all plugin directories.
foreach ($dirs as $pluginDir) {
$plugin = basename($pluginDir);
$metaFile = $pluginDir . $plugin . '.' . self::$META_EXT;
if (!is_file($metaFile) || !is_readable($metaFile)) {
$metaData[$plugin] = parse_ini_file($metaFile);
$metaData[$plugin]['order'] = array_search($plugin, $this->authorizedPlugins);
// Read parameters and format them into an array.
if (isset($metaData[$plugin]['parameters'])) {
$params = explode(';', $metaData[$plugin]['parameters']);
} else {
$params = array();
$metaData[$plugin]['parameters'] = array();
foreach ($params as $param) {
if (empty($param)) {
$metaData[$plugin]['parameters'][$param]['value'] = '';
// Optional parameter description in parameter.PARAM_NAME=
if (isset($metaData[$plugin]['parameter.'. $param])) {
$metaData[$plugin]['parameters'][$param]['desc'] = $metaData[$plugin]['parameter.'. $param];
return $metaData;
* Return the list of encountered errors.
* @return array List of errors (empty array if none exists).
public function getErrors()
return $this->errors;
* Class PluginFileNotFoundException
* Raise when plugin files can't be found.
class PluginFileNotFoundException extends Exception
* Construct exception with plugin name.
* Generate message.
* @param string $pluginName name of the plugin not found
public function __construct($pluginName)
$this->message = 'Plugin "'. $pluginName .'" files not found.';

@ -0,0 +1,159 @
* Class Router
* (only displayable pages here)
class Router
public static $PAGE_LOGIN = 'login';
public static $PAGE_PICWALL = 'picwall';
public static $PAGE_TAGCLOUD = 'tagcloud';
public static $PAGE_TAGLIST = 'taglist';
public static $PAGE_DAILY = 'daily';
public static $PAGE_FEED_ATOM = 'atom';
public static $PAGE_FEED_RSS = 'rss';
public static $PAGE_TOOLS = 'tools';
public static $PAGE_CHANGEPASSWORD = 'changepasswd';
public static $PAGE_CONFIGURE = 'configure';
public static $PAGE_CHANGETAG = 'changetag';
public static $PAGE_ADDLINK = 'addlink';
public static $PAGE_EDITLINK = 'edit_link';
public static $PAGE_DELETELINK = 'delete_link';
public static $PAGE_EXPORT = 'export';
public static $PAGE_IMPORT = 'import';
public static $PAGE_OPENSEARCH = 'opensearch';
public static $PAGE_LINKLIST = 'linklist';
public static $PAGE_PLUGINSADMIN = 'pluginadmin';
public static $PAGE_SAVE_PLUGINSADMIN = 'save_pluginadmin';
public static $GET_TOKEN = 'token';
* Reproducing renderPage() if hell, to avoid regression.
* This highlights how bad this needs to be rewrite,
* but let's focus on plugins for now.
* @param string $query $_SERVER['QUERY_STRING'].
* @param array $get $_SERVER['GET'].
* @param bool $loggedIn true if authenticated user.
* @return string page found.
public static function findPage($query, $get, $loggedIn)
$loggedIn = ($loggedIn === true) ? true : false;
if (empty($query) && !isset($get['edit_link']) && !isset($get['post'])) {
return self::$PAGE_LINKLIST;
if (startsWith($query, 'do='. self::$PAGE_LOGIN) && $loggedIn === false) {
return self::$PAGE_LOGIN;
if (startsWith($query, 'do='. self::$PAGE_PICWALL)) {
return self::$PAGE_PICWALL;
if (startsWith($query, 'do='. self::$PAGE_TAGCLOUD)) {
return self::$PAGE_TAGCLOUD;
if (startsWith($query, 'do='. self::$PAGE_TAGLIST)) {
return self::$PAGE_TAGLIST;
if (startsWith($query, 'do='. self::$PAGE_OPENSEARCH)) {
return self::$PAGE_OPENSEARCH;
if (startsWith($query, 'do='. self::$PAGE_DAILY)) {
return self::$PAGE_DAILY;
if (startsWith($query, 'do='. self::$PAGE_FEED_ATOM)) {
return self::$PAGE_FEED_ATOM;
if (startsWith($query, 'do='. self::$PAGE_FEED_RSS)) {
return self::$PAGE_FEED_RSS;
// At this point, only loggedin pages.
if (!$loggedIn) {
return self::$PAGE_LINKLIST;
if (startsWith($query, 'do='. self::$PAGE_TOOLS)) {
return self::$PAGE_TOOLS;
if (startsWith($query, 'do='. self::$PAGE_CHANGEPASSWORD)) {
if (startsWith($query, 'do='. self::$PAGE_CONFIGURE)) {
return self::$PAGE_CONFIGURE;
if (startsWith($query, 'do='. self::$PAGE_CHANGETAG)) {
return self::$PAGE_CHANGETAG;
if (startsWith($query, 'do='. self::$PAGE_ADDLINK)) {
return self::$PAGE_ADDLINK;
if (isset($get['edit_link']) || isset($get['post'])) {
return self::$PAGE_EDITLINK;
if (isset($get['delete_link'])) {
return self::$PAGE_DELETELINK;
if (startsWith($query, 'do='. self::$PAGE_EXPORT)) {
return self::$PAGE_EXPORT;
if (startsWith($query, 'do='. self::$PAGE_IMPORT)) {
return self::$PAGE_IMPORT;
if (startsWith($query, 'do='. self::$PAGE_PLUGINSADMIN)) {
return self::$PAGE_PLUGINSADMIN;
if (startsWith($query, 'do='. self::$PAGE_SAVE_PLUGINSADMIN)) {
if (startsWith($query, 'do='. self::$GET_TOKEN)) {
return self::$GET_TOKEN;
return self::$PAGE_LINKLIST;

@ -0,0 +1,34 @
* Class ThemeUtils
* Utility functions related to theme management.
* @package Shaarli
class ThemeUtils
* Get a list of available themes.
* It will return the name of any directory present in the template folder.
* @param string $tplDir Templates main directory.
* @return array List of theme names.
public static function getThemes($tplDir)
$tplDir = rtrim($tplDir, '/');
$allTheme = glob($tplDir.'/*', GLOB_ONLYDIR);
$themes = [];
foreach ($allTheme as $value) {
$themes[] = str_replace($tplDir.'/', '', $value);
return $themes;

@ -0,0 +1,91 @
* Generates a list of available timezone continents and cities.
* Two distinct array based on available timezones
* and the one selected in the settings:
* - (0) continents:
* + list of available continents
* + special key 'selected' containing the value of the selected timezone's continent
* - (1) cities:
* + list of available cities associated with their continent
* + special key 'selected' containing the value of the selected timezone's city (without the continent)
* Example:
* [
* [
* 'America',
* 'Europe',
* 'selected' => 'Europe',
* ],
* [
* ['continent' => 'America', 'city' => 'Toronto'],
* ['continent' => 'Europe', 'city' => 'Paris'],
* 'selected' => 'Paris',
* ],
* ];
* Notes:
* - 'UTC/UTC' is mapped to 'UTC' to form a valid option
* - a few timezone cities includes the country/state, such as Argentina/Buenos_Aires
* - these arrays are designed to build timezone selects in template files with any HTML structure
* @param array $installedTimeZones List of installed timezones as string
* @param string $preselectedTimezone preselected timezone (optional)
* @return array[] continents and cities
function generateTimeZoneData($installedTimeZones, $preselectedTimezone = '')
if ($preselectedTimezone == 'UTC') {
$pcity = $pcontinent = 'UTC';
} else {
// Try to split the provided timezone
$spos = strpos($preselectedTimezone, '/');
$pcontinent = substr($preselectedTimezone, 0, $spos);
$pcity = substr($preselectedTimezone, $spos+1);
$continents = [];
$cities = [];
foreach ($installedTimeZones as $tz) {
if ($tz == 'UTC') {
$tz = 'UTC/UTC';
$spos = strpos($tz, '/');
// Ignore invalid timezones
if ($spos === false) {
$continent = substr($tz, 0, $spos);
$city = substr($tz, $spos+1);
$cities[] = ['continent' => $continent, 'city' => $city];
$continents[$continent] = true;
$continents = array_keys($continents);
$continents['selected'] = $pcontinent;
$cities['selected'] = $pcity;
return [$continents, $cities];
* Tells if a continent/city pair form a valid timezone
* Note: 'UTC/UTC' is mapped to 'UTC'
* @param string $continent the timezone continent
* @param string $city the timezone city
* @return bool whether continent/city is a valid timezone
function isTimeZoneValid($continent, $city)
return in_array(

@ -0,0 +1,532 @
use Shaarli\Config\ConfigJson;
use Shaarli\Config\ConfigPhp;
use Shaarli\Config\ConfigManager;
* Class Updater.
* Used to update stuff when a new Shaarli's version is reached.
* Update methods are ran only once, and the stored in a JSON file.
class Updater
* @var array Updates which are already done.
protected $doneUpdates;
* @var LinkDB instance.
protected $linkDB;
* @var ConfigManager $conf Configuration Manager instance.
protected $conf;
* @var bool True if the user is logged in, false otherwise.
protected $isLoggedIn;
* @var ReflectionMethod[] List of current class methods.
protected $methods;
* Object constructor.
* @param array $doneUpdates Updates which are already done.
* @param LinkDB $linkDB LinkDB instance.
* @param ConfigManager $conf Configuration Manager instance.
* @param boolean $isLoggedIn True if the user is logged in.
public function __construct($doneUpdates, $linkDB, $conf, $isLoggedIn)
$this->doneUpdates = $doneUpdates;
$this->linkDB = $linkDB;
$this->conf = $conf;
$this->isLoggedIn = $isLoggedIn;
// Retrieve all update methods.
$class = new ReflectionClass($this);
$this->methods = $class->getMethods();
* Run all new updates.
* Update methods have to start with 'updateMethod' and return true (on success).
* @return array An array containing ran updates.
* @throws UpdaterException If something went wrong.
public function update()
$updatesRan = array();
// If the user isn't logged in, exit without updating.
if ($this->isLoggedIn !== true) {
return $updatesRan;
if ($this->methods === null) {
throw new UpdaterException('Couldn\'t retrieve Updater class methods.');
foreach ($this->methods as $method) {
// Not an update method or already done, pass.
if (! startsWith($method->getName(), 'updateMethod')
|| in_array($method->getName(), $this->doneUpdates)
) {
try {
$res = $method->invoke($this);
// Update method must return true to be considered processed.
if ($res === true) {
$updatesRan[] = $method->getName();
} catch (Exception $e) {
throw new UpdaterException($method, $e);
$this->doneUpdates = array_merge($this->doneUpdates, $updatesRan);
return $updatesRan;
* @return array Updates methods already processed.
public function getDoneUpdates()
return $this->doneUpdates;
* Move deprecated options.php to config.php.
* Milestone 0.9 (old versioning) - shaarli/Shaarli#41:
* options.php is not supported anymore.
public function updateMethodMergeDeprecatedConfigFile()
if (is_file($this->conf->get('resource.data_dir') . '/options.php')) {
include $this->conf->get('resource.data_dir') . '/options.php';
// Load GLOBALS into config
$allowedKeys = array_merge(ConfigPhp::$ROOT_KEYS);
$allowedKeys[] = 'config';
foreach ($GLOBALS as $key => $value) {
if (in_array($key, $allowedKeys)) {
$this->conf->set($key, $value);
return true;
* Move old configuration in PHP to the new config system in JSON format.
* Will rename 'config.php' into '' and create 'config.json.php'.
* It will also convert legacy setting keys to the new ones.
public function updateMethodConfigToJson()
// JSON config already exists, nothing to do.
if ($this->conf->getConfigIO() instanceof ConfigJson) {
return true;
$configPhp = new ConfigPhp();
$configJson = new ConfigJson();
$oldConfig = $configPhp->read($this->conf->getConfigFile() . '.php');
rename($this->conf->getConfigFileExt(), $this->conf->getConfigFile() . '.save.php');
$legacyMap = array_flip(ConfigPhp::$LEGACY_KEYS_MAPPING);
foreach (ConfigPhp::$ROOT_KEYS as $key) {
$this->conf->set($legacyMap[$key], $oldConfig[$key]);
// Set sub config keys (config and plugins)
$subConfig = array('config', 'plugins');
foreach ($subConfig as $sub) {
foreach ($oldConfig[$sub] as $key => $value) {
if (isset($legacyMap[$sub .'.'. $key])) {
$configKey = $legacyMap[$sub .'.'. $key];
} else {
$configKey = $sub .'.'. $key;
$this->conf->set($configKey, $value);
return true;
} catch (IOException $e) {
return false;
* Escape settings which have been manually escaped in every request in previous versions:
* - general.title
* - general.header_link
* - redirector.url
* @return bool true if the update is successful, false otherwise.
public function updateMethodEscapeUnescapedConfig()
try {
$this->conf->set('general.title', escape($this->conf->get('general.title')));
$this->conf->set('general.header_link', escape($this->conf->get('general.header_link')));
$this->conf->set('redirector.url', escape($this->conf->get('redirector.url')));
} catch (Exception $e) {
return false;
return true;
* Update the database to use the new ID system, which replaces linkdate primary keys.
* Also, creation and update dates are now DateTime objects (done by LinkDB).
* Since this update is very sensitve (changing the whole database), the datastore will be
* automatically backed up into the file datastore.<datetime>.php.
* LinkDB also adds the field 'shorturl' with the precedent format (linkdate smallhash),
* which will be saved by this method.
* @return bool true if the update is successful, false otherwise.
public function updateMethodDatastoreIds()
// up to date database
if (isset($this->linkDB[0])) {
return true;
$save = $this->conf->get('resource.data_dir') .'/datastore.'. date('YmdHis') .'.php';
copy($this->conf->get('resource.datastore'), $save);
$links = array();
foreach ($this->linkDB as $offset => $value) {
$links[] = $value;
$links = array_reverse($links);
$cpt = 0;
foreach ($links as $l) {
$l['id'] = $cpt;
$this->linkDB[$cpt++] = $l;
return true;
* Rename tags starting with a '-' to work with tag exclusion search.
public function updateMethodRenameDashTags()
$linklist = $this->linkDB->filterSearch();
foreach ($linklist as $key => $link) {
$link['tags'] = preg_replace('/(^| )\-/', '$1', $link['tags']);
$link['tags'] = implode(' ', array_unique(LinkFilter::tagsStrToArray($link['tags'], true)));
$this->linkDB[$key] = $link;
return true;
* Initialize API settings:
* - api.enabled: true
* - api.secret: generated secret
public function updateMethodApiSettings()
if ($this->conf->exists('api.secret')) {
return true;
$this->conf->set('api.enabled', true);
return true;
* New setting: theme name. If the default theme is used, nothing to do.
* If the user uses a custom theme, raintpl_tpl dir is updated to the parent directory,
* and the current theme is set as default in the theme setting.
* @return bool true if the update is successful, false otherwise.
public function updateMethodDefaultTheme()
// raintpl_tpl isn't the root template directory anymore.
// We run the update only if this folder still contains the template files.
$tplDir = $this->conf->get('resource.raintpl_tpl');
$tplFile = $tplDir . '/linklist.html';
if (! file_exists($tplFile)) {
return true;
$parent = dirname($tplDir);
$this->conf->set('resource.raintpl_tpl', $parent);
$this->conf->set('resource.theme', trim(str_replace($parent, '', $tplDir), '/'));
// Dependency injection gore
RainTPL::$tpl_dir = $tplDir;
return true;
* Move the file to inc/user.css to data/user.css.
* Note: Due to hardcoded paths, it's not unit testable. But one line of code should be fine.
* @return bool true if the update is successful, false otherwise.
public function updateMethodMoveUserCss()
if (! is_file('inc/user.css')) {
return true;
return rename('inc/user.css', 'data/user.css');
* * `markdown_escape` is a new setting, set to true as default.
* If the markdown plugin was already enabled, escaping is disabled to avoid
* breaking existing entries.
public function updateMethodEscapeMarkdown()
if ($this->conf->exists('security.markdown_escape')) {
return true;
if (in_array('markdown', $this->conf->get('general.enabled_plugins'))) {
$this->conf->set('security.markdown_escape', false);
} else {
$this->conf->set('security.markdown_escape', true);
return true;
* Add 'http://' to Piwik URL the setting is set.
* @return bool true if the update is successful, false otherwise.
public function updateMethodPiwikUrl()
if (! $this->conf->exists('plugins.PIWIK_URL') || startsWith($this->conf->get('plugins.PIWIK_URL'), 'http')) {
return true;
$this->conf->set('plugins.PIWIK_URL', 'http://'. $this->conf->get('plugins.PIWIK_URL'));
return true;
* Use ATOM feed as default.
public function updateMethodAtomDefault()
if (!$this->conf->exists('feed.show_atom') || $this->conf->get('feed.show_atom') === true) {
return true;
$this->conf->set('feed.show_atom', true);
return true;
* Update updates.check_updates_branch setting.
* If the current major version digit matches the latest branch
* major version digit, we set the branch to `latest`,
* otherwise we'll check updates on the `stable` branch.
* No update required for the dev version.
* Note: due to hardcoded URL and lack of dependency injection, this is not unit testable.
* FIXME! This needs to be removed when we switch to first digit major version
* instead of the second one since the versionning process will change.
public function updateMethodCheckUpdateRemoteBranch()
if (SHAARLI_VERSION === 'dev' || $this->conf->get('updates.check_updates_branch') === 'latest') {
return true;
// Get latest branch major version digit
$latestVersion = ApplicationUtils::getLatestGitVersionCode(
if (preg_match('/(\d+)\.\d+$/', $latestVersion, $matches) === false) {
return false;
$latestMajor = $matches[1];
// Get current major version digit
preg_match('/(\d+)\.\d+$/', SHAARLI_VERSION, $matches);
$currentMajor = $matches[1];
if ($currentMajor === $latestMajor) {
$branch = 'latest';
} else {
$branch = 'stable';
$this->conf->set('updates.check_updates_branch', $branch);
return true;
* Reset history store file due to date format change.
public function updateMethodResetHistoryFile()
if (is_file($this->conf->get('resource.history'))) {
return true;
* Class UpdaterException.
class UpdaterException extends Exception
* @var string Method where the error occurred.
protected $method;
* @var Exception The parent exception.
protected $previous;
* Constructor.
* @param string $message Force the error message if set.
* @param string $method Method where the error occurred.
* @param Exception|bool $previous Parent exception.
public function __construct($message = '', $method = '', $previous = false)
$this->method = $method;
$this->previous = $previous;
$this->message = $this->buildMessage($message);
* Build the exception error message.
* @param string $message Optional given error message.
* @return string The built error message.
private function buildMessage($message)
$out = '';
if (! empty($message)) {
$out .= $message . PHP_EOL;
if (! empty($this->method)) {
$out .= 'An error occurred while running the update '. $this->method . PHP_EOL;
if (! empty($this->previous)) {
$out .= ' '. $this->previous->getMessage();
return $out;
* Read the updates file, and return already done updates.
* @param string $updatesFilepath Updates file path.
* @return array Already done update methods.
function read_updates_file($updatesFilepath)
if (! empty($updatesFilepath) && is_file($updatesFilepath)) {
$content = file_get_contents($updatesFilepath);
if (! empty($content)) {
return explode(';', $content);
return array();
* Write updates file.
* @param string $updatesFilepath Updates file path.
* @param array $updates Updates array to write.
* @throws Exception Couldn't write version number.
function write_updates_file($updatesFilepath, $updates)
if (empty($updatesFilepath)) {
throw new Exception('Updates file path is not set, can\'t write updates.');
$res = file_put_contents($updatesFilepath, implode(';', $updates));
if ($res === false) {
throw new Exception('Unable to write updates in '. $updatesFilepath . '.');

@ -0,0 +1,299 @
* Converts an array-represented URL to a string
* Source:
* @see
* @param array $parsedUrl an array-represented URL
* @return string the string representation of the URL
function unparse_url($parsedUrl)
$scheme = isset($parsedUrl['scheme']) ? $parsedUrl['scheme'].'://' : '';
$host = isset($parsedUrl['host']) ? $parsedUrl['host'] : '';
$port = isset($parsedUrl['port']) ? ':'.$parsedUrl['port'] : '';
$user = isset($parsedUrl['user']) ? $parsedUrl['user'] : '';
$pass = isset($parsedUrl['pass']) ? ':'.$parsedUrl['pass'] : '';
$pass = ($user || $pass) ? "$pass@" : '';
$path = isset($parsedUrl['path']) ? $parsedUrl['path'] : '';
$query = isset($parsedUrl['query']) ? '?'.$parsedUrl['query'] : '';
$fragment = isset($parsedUrl['fragment']) ? '#'.$parsedUrl['fragment'] : '';
return "$scheme$user$pass$host$port$path$query$fragment";
* Removes undesired query parameters and fragments
* @param string url Url to be cleaned
* @return string the string representation of this URL after cleanup
function cleanup_url($url)
$obj_url = new Url($url);
return $obj_url->cleanup();
* Get URL scheme.
* @param string url Url for which the scheme is requested
* @return mixed the URL scheme or false if none is provided.
function get_url_scheme($url)
$obj_url = new Url($url);
return $obj_url->getScheme();
* Adds a trailing slash at the end of URL if necessary.
* @param string $url URL to check/edit.
* @return string $url URL with a end trailing slash.
function add_trailing_slash($url)
return $url . (!endsWith($url, '/') ? '/' : '');
* Replace not whitelisted protocols by 'http://' from given URL.
* @param string $url URL to clean
* @param array $protocols List of allowed protocols (aside from http(s)).
* @return string URL with allowed protocol
function whitelist_protocols($url, $protocols)
if (startsWith($url, '?') || startsWith($url, '/')) {
return $url;
$protocols = array_merge(['http', 'https'], $protocols);
$protocol = preg_match('#^(\w+):/?/?#', $url, $match);
// Protocol not allowed: we remove it and replace it with http
if ($protocol === 1 && ! in_array($match[1], $protocols)) {
$url = str_replace($match[0], 'http://', $url);
} else if ($protocol !== 1) {
$url = 'http://' . $url;
return $url;
* URL representation and cleanup utilities
* Form
* scheme://[username:password@]host[:port][/path][?query][#fragment]
* Examples
* http://username:password@hostname:9090/path?arg1=value1&arg2=value2#anchor
* https://h2.g2/faq/?vendor=hitchhiker&item=guide&dest=galaxy#answer
* @see
class Url
private static $annoyingQueryParams = array(
// Facebook
// Google Analytics & FeedProxy
// ATInternet
// Other
private static $annoyingFragments = array(
// ATInternet
// Misc.
* URL parts represented as an array
* @see
protected $parts;
* Parses a string containing a URL
* @param string $url a string containing a URL
public function __construct($url)
$url = self::cleanupUnparsedUrl(trim($url));
$this->parts = parse_url($url);
if (!empty($url) && empty($this->parts['scheme'])) {
$this->parts['scheme'] = 'http';
* Clean up URL before it's parsed.
* ie. handle urlencode, url prefixes, etc.
* @param string $url URL to clean.
* @return string cleaned URL.
protected static function cleanupUnparsedUrl($url)
return self::removeFirefoxAboutReader($url);
* Remove Firefox Reader prefix if it's present.
* @param string $input url
* @return string cleaned url
protected static function removeFirefoxAboutReader($input)
$firefoxPrefix = 'about://reader?url=';
if (startsWith($input, $firefoxPrefix)) {
return urldecode(ltrim($input, $firefoxPrefix));
return $input;
* Returns a string representation of this URL
public function toString()
return unparse_url($this->parts);
* Removes undesired query parameters
protected function cleanupQuery()
if (! isset($this->parts['query'])) {
$queryParams = explode('&', $this->parts['query']);
foreach (self::$annoyingQueryParams as $annoying) {
foreach ($queryParams as $param) {
if (startsWith($param, $annoying)) {
$queryParams = array_diff($queryParams, array($param));
if (count($queryParams) == 0) {
$this->parts['query'] = implode('&', $queryParams);
* Removes undesired fragments
protected function cleanupFragment()
if (! isset($this->parts['fragment'])) {
foreach (self::$annoyingFragments as $annoying) {
if (startsWith($this->parts['fragment'], $annoying)) {
* Removes undesired query parameters and fragments
* @return string the string representation of this URL after cleanup
public function cleanup()
return $this->toString();
* Converts an URL with an International Domain Name host to a ASCII one.
* This requires PHP-intl. If it's not available, just returns this->cleanup().
* @return string converted cleaned up URL.
public function idnToAscii()
$out = $this->cleanup();
if (! function_exists('idn_to_ascii') || ! isset($this->parts['host'])) {
return $out;
$asciiHost = idn_to_ascii($this->parts['host']);
return str_replace($this->parts['host'], $asciiHost, $out);
* Get URL scheme.
* @return string the URL scheme or false if none is provided.
public function getScheme() {
if (!isset($this->parts['scheme'])) {
return false;
return $this->parts['scheme'];
* Get URL host.
* @return string the URL host or false if none is provided.
public function getHost() {
if (empty($this->parts['host'])) {
return false;
return $this->parts['host'];
* Test if the Url is an HTTP one.
* @return true is HTTP, false otherwise.
public function isHttp() {
return strpos(strtolower($this->parts['scheme']), 'http') !== false;

@ -0,0 +1,472 @
* Shaarli utilities
* Logs a message to a text file
* The log format is compatible with fail2ban.
* @param string $logFile where to write the logs
* @param string $clientIp the client's remote IPv4/IPv6 address
* @param string $message the message to log
function logm($logFile, $clientIp, $message)
date('Y/m/d H:i:s').' - '.$clientIp.' - '.strval($message).PHP_EOL,
* Returns the small hash of a string, using RFC 4648 base64url format
* Small hashes:
* - are unique (well, as unique as crc32, at last)
* - are always 6 characters long.
* - only use the following characters: a-z A-Z 0-9 - _ @
* - are NOT cryptographically secure (they CAN be forged)
* In Shaarli, they are used as a tinyurl-like link to individual entries,
* built once with the combination of the date and item ID.
* e.g. smallHash('20111006_131924' . 142) --> eaWxtQ
* @warning before v0.8.1, smallhashes were built only with the date,
* and their value has been preserved.
* @param string $text Create a hash from this text.
* @return string generated small hash.
function smallHash($text)
$t = rtrim(base64_encode(hash('crc32', $text, true)), '=');
return strtr($t, '+/', '-_');
* Tells if a string start with a substring
* @param string $haystack Given string.
* @param string $needle String to search at the beginning of $haystack.
* @param bool $case Case sensitive.
* @return bool True if $haystack starts with $needle.
function startsWith($haystack, $needle, $case = true)
if ($case) {
return (strcmp(substr($haystack, 0, strlen($needle)), $needle) === 0);
return (strcasecmp(substr($haystack, 0, strlen($needle)), $needle) === 0);
* Tells if a string ends with a substring
* @param string $haystack Given string.
* @param string $needle String to search at the end of $haystack.
* @param bool $case Case sensitive.
* @return bool True if $haystack ends with $needle.
function endsWith($haystack, $needle, $case = true)
if ($case) {
return (strcmp(substr($haystack, strlen($haystack) - strlen($needle)), $needle) === 0);
return (strcasecmp(substr($haystack, strlen($haystack) - strlen($needle)), $needle) === 0);
* Htmlspecialchars wrapper
* Support multidimensional array of strings.
* @param mixed $input Data to escape: a single string or an array of strings.
* @return string escaped.
function escape($input)
if (is_bool($input)) {
return $input;
if (is_array($input)) {
$out = array();
foreach($input as $key => $value) {
$out[$key] = escape($value);
return $out;
return htmlspecialchars($input, ENT_COMPAT, 'UTF-8', false);
* Reverse the escape function.
* @param string $str the string to unescape.
* @return string unescaped string.
function unescape($str)
return htmlspecialchars_decode($str);
* Sanitize link before rendering.
* @param array $link Link to escape.
function sanitizeLink(&$link)
$link['url'] = escape($link['url']); // useful?
$link['title'] = escape($link['title']);
$link['description'] = escape($link['description']);
$link['tags'] = escape($link['tags']);
* Checks if a string represents a valid date
* @param string $format The expected DateTime format of the string
* @param string $string A string-formatted date
* @return bool whether the string is a valid date
* @see
* @see
function checkDateFormat($format, $string)
$date = DateTime::createFromFormat($format, $string);
return $date && $date->format($string) == $string;
* Generate a header location from HTTP_REFERER.
* Make sure the referer is Shaarli itself and prevent redirection loop.
* @param string $referer - HTTP_REFERER.
* @param string $host - Server HOST.
* @param array $loopTerms - Contains list of term to prevent redirection loop.
* @return string $referer - final referer.
function generateLocation($referer, $host, $loopTerms = array())
$finalReferer = '?';
// No referer if it contains any value in $loopCriteria.
foreach ($loopTerms as $value) {
if (strpos($referer, $value) !== false) {
return $finalReferer;
// Remove port from HTTP_HOST
if ($pos = strpos($host, ':')) {
$host = substr($host, 0, $pos);
$refererHost = parse_url($referer, PHP_URL_HOST);
if (!empty($referer) && (strpos($refererHost, $host) !== false || startsWith('?', $refererHost))) {
$finalReferer = $referer;
return $finalReferer;
* Validate session ID to prevent Full Path Disclosure.
* See #298.
* The session ID's format depends on the hash algorithm set in PHP settings
* @param string $sessionId Session ID
* @return true if valid, false otherwise.
* @see
* @see
function is_session_id_valid($sessionId)
if (empty($sessionId)) {
return false;
if (!$sessionId) {
return false;
if (!preg_match('/^[a-zA-Z0-9,-]{2,128}$/', $sessionId)) {
return false;
return true;
* Sniff browser language to set the locale automatically.
* Note that is may not work on your server if the corresponding locale is not installed.
* @param string $headerLocale Locale send in HTTP headers (e.g. "fr,fr-fr;q=0.8,en;q=0.5,en-us;q=0.3").
function autoLocale($headerLocale)
// Default if browser does not send HTTP_ACCEPT_LANGUAGE
$locales = array('en_US', 'en_US.utf8', 'en_US.UTF-8');
if (! empty($headerLocale)) {
if (preg_match_all('/([a-z]{2,3})[-_]?([a-z]{2})?,?/i', $headerLocale, $matches, PREG_SET_ORDER)) {
$attempts = [];
foreach ($matches as $match) {
$first = [strtolower($match[1]), strtoupper($match[1])];
$separators = ['_', '-'];
$encodings = ['utf8', 'UTF-8'];
if (!empty($match[2])) {
$second = [strtoupper($match[2]), strtolower($match[2])];
$items = [$first, $separators, $second, ['.'], $encodings];
} else {
$items = [$first, $separators, $first, ['.'], $encodings];
$attempts = array_merge($attempts, iterator_to_array(cartesian_product_generator($items)));
if (! empty($attempts)) {
$locales = array_merge(array_map('implode', $attempts), $locales);
setlocale(LC_ALL, $locales);
* Build a Generator object representing the cartesian product from given $items.
* Example:
* [['a'], ['b', 'c']]
* will generate:
* [
* ['a', 'b'],
* ['a', 'c'],
* ]
* @param array $items array of array of string
* @return Generator representing the cartesian product of given array.
* @see
function cartesian_product_generator($items)
if (empty($items)) {
yield [];
$subArray = array_pop($items);
if (empty($subArray)) {
foreach (cartesian_product_generator($items) as $item) {
foreach ($subArray as $value) {
yield $item + [count($item) => $value];
* Generates a default API secret.
* Note that the random-ish methods used in this function are predictable,
* which makes them NOT suitable for crypto.
* BUT the random string is salted with the salt and hashed with the username.
* It makes the generated API secret secured enough for Shaarli.
* PHP 7 provides random_int(), designed for cryptography.
* More info:
* @param string $username Shaarli login username
* @param string $salt Shaarli password hash salt
* @return string|bool Generated API secret, 12 char length.
* Or false if invalid parameters are provided (which will make the API unusable).
function generate_api_secret($username, $salt)
if (empty($username) || empty($salt)) {
return false;
return str_shuffle(substr(hash_hmac('sha512', uniqid($salt), $username), 10, 12));
* Trim string, replace sequences of whitespaces by a single space.
* PHP equivalent to `normalize-space` XSLT function.
* @param string $string Input string.
* @return mixed Normalized string.
function normalize_spaces($string)
return preg_replace('/\s{2,}/', ' ', trim($string));
* Format the date according to the locale.
* Requires php-intl to display international datetimes,
* otherwise default format '%c' will be returned.
* @param DateTime $date to format.
* @param bool $time Displays time if true.
* @param bool $intl Use international format if true.
* @return bool|string Formatted date, or false if the input is invalid.
function format_date($date, $time = true, $intl = true)
if (! $date instanceof DateTime) {
return false;
if (! $intl || ! class_exists('IntlDateFormatter')) {
$format = $time ? '%c' : '%x';
return strftime($format, $date->getTimestamp());
$formatter = new IntlDateFormatter(
setlocale(LC_TIME, 0),
$time ? IntlDateFormatter::LONG : IntlDateFormatter::NONE
return $formatter->format($date);
* Check if the input is an integer, no matter its real type.
* PHP is a bit messy regarding this:
* - is_int returns false if the input is a string
* - ctype_digit returns false if the input is an integer or negative
* @param mixed $input value
* @return bool true if the input is an integer, false otherwise
function is_integer_mixed($input)
if (is_array($input) || is_bool($input) || is_object($input)) {
return false;
$input = strval($input);
return ctype_digit($input) || (startsWith($input, '-') && ctype_digit(substr($input, 1)));
* Convert post_max_size/upload_max_filesize (e.g. '16M') parameters to bytes.
* @param string $val Size expressed in string.
* @return int Size expressed in bytes.
function return_bytes($val)
if (is_integer_mixed($val) || $val === '0' || empty($val)) {
return $val;
$val = trim($val);
$last = strtolower($val[strlen($val)-1]);
$val = intval(substr($val, 0, -1));
switch($last) {
case 'g': $val *= 1024;
case 'm': $val *= 1024;
case 'k': $val *= 1024;
return $val;
* Return a human readable size from bytes.
* @param int $bytes value
* @return string Human readable size
function human_bytes($bytes)
if ($bytes === '') {
return t('Setting not set');
if (! is_integer_mixed($bytes)) {
return $bytes;
$bytes = intval($bytes);
if ($bytes === 0) {
return t('Unlimited');
$units = [t('B'), t('kiB'), t('MiB'), t('GiB')];
for ($i = 0; $i < count($units) && $bytes >= 1024; ++$i) {
$bytes /= 1024;
return round($bytes) . $units[$i];
* Try to determine max file size for uploads (POST).
* Returns an integer (in bytes) or formatted depending on $format.
* @param mixed $limitPost post_max_size PHP setting
* @param mixed $limitUpload upload_max_filesize PHP setting
* @param bool $format Format max upload size to human readable size
* @return int|string max upload file size
function get_max_upload_size($limitPost, $limitUpload, $format = true)
$size1 = return_bytes($limitPost);
$size2 = return_bytes($limitUpload);
// Return the smaller of two:
$maxsize = min($size1, $size2);
return $format ? human_bytes($maxsize) : $maxsize;
* Sort the given array alphabetically using php-intl if available.
* Case sensitive.
* Note: doesn't support multidimensional arrays
* @param array $data Input array, passed by reference
* @param bool $reverse Reverse sort if set to true
* @param bool $byKeys Sort the array by keys if set to true, by value otherwise.
function alphabetical_sort(&$data, $reverse = false, $byKeys = false)
$callback = function($a, $b) use ($reverse) {
// Collator is part of PHP intl.
if (class_exists('Collator')) {
$collator = new Collator(setlocale(LC_COLLATE, 0));
if (!intl_is_failure(intl_get_error_code())) {
return $collator->compare($a, $b) * ($reverse ? -1 : 1);
return strcasecmp($a, $b) * ($reverse ? -1 : 1);
if ($byKeys) {
uksort($data, $callback);
} else {
usort($data, $callback);

@ -0,0 +1,138 @
use Shaarli\Api\Exceptions\ApiException;
use Shaarli\Api\Exceptions\ApiAuthorizationException;
use Shaarli\Config\ConfigManager;
use Slim\Container;
use Slim\Http\Request;
use Slim\Http\Response;
* Class ApiMiddleware
* This will be called before accessing any API Controller.
* Its role is to make sure that the API is enabled, configured, and to validate the JWT token.
* If the request is validated, the controller is called, otherwise a JSON error response is returned.
* @package Api
class ApiMiddleware
* @var int JWT token validity in seconds (9 min).
public static $TOKEN_DURATION = 540;
* @var Container: contains conf, plugins, etc.
protected $container;
* @var ConfigManager instance.
protected $conf;
* ApiMiddleware constructor.
* @param Container $container instance.
public function __construct($container)
$this->container = $container;
$this->conf = $this->container->get('conf');
* Middleware execution:
* - check the API request
* - execute the controller
* - return the response
* @param Request $request Slim request
* @param Response $response Slim response
* @param callable $next Next action
* @return Response response.
public function __invoke($request, $response, $next)
try {
$response = $next($request, $response);
} catch(ApiException $e) {
$e->setDebug($this->conf->get('dev.debug', false));
$response = $e->getApiResponse();
return $response;
* Check the request validity (HTTP method, request value, etc.),
* that the API is enabled, and the JWT token validity.
* @param Request $request Slim request
* @throws ApiAuthorizationException The API is disabled or the token is invalid.
protected function checkRequest($request)
if (! $this->conf->get('api.enabled', true)) {
throw new ApiAuthorizationException('API is disabled');
* Check that the JWT token is set and valid.
* The API secret setting must be set.
* @param Request $request Slim request
* @throws ApiAuthorizationException The token couldn't be validated.
protected function checkToken($request) {
if (! $request->hasHeader('Authorization')) {
throw new ApiAuthorizationException('JWT token not provided');
if (empty($this->conf->get('api.secret'))) {
throw new ApiAuthorizationException('Token secret must be set in Shaarli\'s administration');
$authorization = $request->getHeaderLine('Authorization');
if (! preg_match('/^Bearer (.*)/i', $authorization, $matches)) {
throw new ApiAuthorizationException('Invalid JWT header');
ApiUtils::validateJwtToken($matches[1], $this->conf->get('api.secret'));
* Instantiate a new LinkDB including private links,
* and load in the Slim container.
* FIXME! LinkDB could use a refactoring to avoid this trick.
* @param ConfigManager $conf instance.
protected function setLinkDb($conf)
$linkDb = new \LinkDB(
$this->container['db'] = $linkDb;

@ -0,0 +1,137 @
use Shaarli\Base64Url;
use Shaarli\Api\Exceptions\ApiAuthorizationException;
* REST API utilities
class ApiUtils
* Validates a JWT token authenticity.
* @param string $token JWT token extracted from the headers.
* @param string $secret API secret set in the settings.
* @throws ApiAuthorizationException the token is not valid.
public static function validateJwtToken($token, $secret)
$parts = explode('.', $token);
if (count($parts) != 3 || strlen($parts[0]) == 0 || strlen($parts[1]) == 0) {
throw new ApiAuthorizationException('Malformed JWT token');
$genSign = Base64Url::encode(hash_hmac('sha512', $parts[0] .'.'. $parts[1], $secret, true));
if ($parts[2] != $genSign) {
throw new ApiAuthorizationException('Invalid JWT signature');
$header = json_decode(Base64Url::decode($parts[0]));
if ($header === null) {
throw new ApiAuthorizationException('Invalid JWT header');
$payload = json_decode(Base64Url::decode($parts[1]));
if ($payload === null) {
throw new ApiAuthorizationException('Invalid JWT payload');
if (empty($payload->iat)
|| $payload->iat > time()
|| time() - $payload->iat > ApiMiddleware::$TOKEN_DURATION
) {
throw new ApiAuthorizationException('Invalid JWT issued time');
* Format a Link for the REST API.
* @param array $link Link data read from the datastore.
* @param string $indexUrl Shaarli's index URL (used for relative URL).
* @return array Link data formatted for the REST API.
public static function formatLink($link, $indexUrl)
$out['id'] = $link['id'];
// Not an internal link
if ($link['url'][0] != '?') {
$out['url'] = $link['url'];
} else {
$out['url'] = $indexUrl . $link['url'];
$out['shorturl'] = $link['shorturl'];
$out['title'] = $link['title'];
$out['description'] = $link['description'];
$out['tags'] = preg_split('/\s+/', $link['tags'], -1, PREG_SPLIT_NO_EMPTY);
$out['private'] = $link['private'] == true;
$out['created'] = $link['created']->format(\DateTime::ATOM);
if (! empty($link['updated'])) {
$out['updated'] = $link['updated']->format(\DateTime::ATOM);
} else {
$out['updated'] = '';
return $out;
* Convert a link given through a request, to a valid link for LinkDB.
* If no URL is provided, it will generate a local note URL.
* If no title is provided, it will use the URL as title.
* @param array $input Request Link.
* @param bool $defaultPrivate Request Link.
* @return array Formatted link.
public static function buildLinkFromRequest($input, $defaultPrivate)
$input['url'] = ! empty($input['url']) ? cleanup_url($input['url']) : '';
if (isset($input['private'])) {
$private = filter_var($input['private'], FILTER_VALIDATE_BOOLEAN);
} else {
$private = $defaultPrivate;
$link = [
'title' => ! empty($input['title']) ? $input['title'] : $input['url'],
'url' => $input['url'],
'description' => ! empty($input['description']) ? $input['description'] : '',
'tags' => ! empty($input['tags']) ? implode(' ', $input['tags']) : '',
'private' => $private,
'created' => new \DateTime(),
return $link;
* Update link fields using an updated link object.
* @param array $oldLink data
* @param array $newLink data
* @return array $oldLink updated with $newLink values
public static function updateLink($oldLink, $newLink)
foreach (['title', 'url', 'description', 'tags', 'private'] as $field) {
$oldLink[$field] = $newLink[$field];
$oldLink['updated'] = new \DateTime();
if (empty($oldLink['url'])) {
$oldLink['url'] = '?' . $oldLink['shorturl'];
if (empty($oldLink['title'])) {
$oldLink['title'] = $oldLink['url'];
return $oldLink;

@ -0,0 +1,71 @
use Shaarli\Config\ConfigManager;
use \Slim\Container;
* Abstract Class ApiController
* Defines REST API Controller dependencies injected from the container.
* @package Api\Controllers
abstract class ApiController
* @var Container
protected $ci;
* @var ConfigManager
protected $conf;
* @var \LinkDB
protected $linkDb;
* @var \History
protected $history;
* @var int|null JSON style option.
protected $jsonStyle;
* ApiController constructor.
* Note: enabling debug mode displays JSON with readable formatting.
* @param Container $ci Slim container.
public function __construct(Container $ci)
$this->ci = $ci;
$this->conf = $ci->get('conf');
$this->linkDb = $ci->get('db');
$this->history = $ci->get('history');
if ($this->conf->get('dev.debug', false)) {
$this->jsonStyle = JSON_PRETTY_PRINT;
} else {
$this->jsonStyle = null;
* Get the container.
* @return Container
public function getCi()
return $this->ci;

@ -0,0 +1,70 @
use Shaarli\Api\Exceptions\ApiBadParametersException;
use Slim\Http\Request;
use Slim\Http\Response;
* Class History
* REST API Controller: /history
* @package Shaarli\Api\Controllers
class History extends ApiController
* Service providing operation regarding Shaarli datastore and settings.
* @param Request $request Slim request.
* @param Response $response Slim response.
* @return Response response.
* @throws ApiBadParametersException Invalid parameters.
public function getHistory($request, $response)
$history = $this->history->getHistory();
// Return history operations from the {offset}th, starting from {since}.
$since = \DateTime::createFromFormat(\DateTime::ATOM, $request->getParam('since'));
$offset = $request->getParam('offset');
if (empty($offset)) {
$offset = 0;
else if (ctype_digit($offset)) {
$offset = (int) $offset;
} else {
throw new ApiBadParametersException('Invalid offset');
// limit parameter is either a number of links or 'all' for everything.
$limit = $request->getParam('limit');
if (empty($limit)) {
$limit = count($history);
} else if (ctype_digit($limit)) {
$limit = (int) $limit;
} else {
throw new ApiBadParametersException('Invalid limit');
$out = [];
$i = 0;
foreach ($history as $entry) {
if ((! empty($since) && $entry['datetime'] <= $since) || count($out) >= $limit) {
if (++$i > $offset) {
$out[$i] = $entry;
$out[$i]['datetime'] = $out[$i]['datetime']->format(\DateTime::ATOM);
$out = array_values($out);
return $response->withJson($out, 200, $this->jsonStyle);

@ -0,0 +1,42 @
use Slim\Http\Request;
use Slim\Http\Response;
* Class Info
* REST API Controller: /info
* @package Api\Controllers
* @see
class Info extends ApiController
* Service providing various information about Shaarli instance.
* @param Request $request Slim request.
* @param Response $response Slim response.
* @return Response response.
public function getInfo($request, $response)
$info = [
'global_counter' => count($this->linkDb),
'private_counter' => count_private($this->linkDb),
'settings' => array(
'title' => $this->conf->get('general.title', 'Shaarli'),
'header_link' => $this->conf->get('general.header_link', '?'),
'timezone' => $this->conf->get('general.timezone', 'UTC'),
'enabled_plugins' => $this->conf->get('general.enabled_plugins', []),
'default_private_links' => $this->conf->get('privacy.default_private_links', false),
return $response->withJson($info, 200, $this->jsonStyle);

@ -0,0 +1,217 @
use Shaarli\Api\ApiUtils;
use Shaarli\Api\Exceptions\ApiBadParametersException;
use Shaarli\Api\Exceptions\ApiLinkNotFoundException;
use Slim\Http\Request;
use Slim\Http\Response;
* Class Links
* REST API Controller: all services related to links collection.
* @package Api\Controllers
* @see
class Links extends ApiController
* @var int Number of links returned if no limit is provided.
public static $DEFAULT_LIMIT = 20;
* Retrieve a list of links, allowing different filters.
* @param Request $request Slim request.
* @param Response $response Slim response.
* @return Response response.
* @throws ApiBadParametersException Invalid parameters.
public function getLinks($request, $response)
$private = $request->getParam('visibility');
$links = $this->linkDb->filterSearch(
'searchtags' => $request->getParam('searchtags', ''),
'searchterm' => $request->getParam('searchterm', ''),
// Return links from the {offset}th link, starting from 0.
$offset = $request->getParam('offset');
if (! empty($offset) && ! ctype_digit($offset)) {
throw new ApiBadParametersException('Invalid offset');
$offset = ! empty($offset) ? intval($offset) : 0;
if ($offset > count($links)) {
return $response->withJson([], 200, $this->jsonStyle);
// limit parameter is either a number of links or 'all' for everything.
$limit = $request->getParam('limit');
if (empty($limit)) {
$limit = self::$DEFAULT_LIMIT;
} else if (ctype_digit($limit)) {
$limit = intval($limit);
} else if ($limit === 'all') {
$limit = count($links);
} else {
throw new ApiBadParametersException('Invalid limit');
// 'environment' is set by Slim and encapsulate $_SERVER.
$index = index_url($this->ci['environment']);
$out = [];
$cpt = 0;
foreach ($links as $link) {
if (count($out) >= $limit) {
if ($cpt++ >= $offset) {
$out[] = ApiUtils::formatLink($link, $index);
return $response->withJson($out, 200, $this->jsonStyle);
* Return a single formatted link by its ID.
* @param Request $request Slim request.
* @param Response $response Slim response.
* @param array $args Path parameters. including the ID.
* @return Response containing the link array.
* @throws ApiLinkNotFoundException generating a 404 error.
public function getLink($request, $response, $args)
if (!isset($this->linkDb[$args['id']])) {
throw new ApiLinkNotFoundException();
$index = index_url($this->ci['environment']);
$out = ApiUtils::formatLink($this->linkDb[$args['id']], $index);
return $response->withJson($out, 200, $this->jsonStyle);
* Creates a new link from posted request body.
* @param Request $request Slim request.
* @param Response $response Slim response.
* @return Response response.
public function postLink($request, $response)
$data = $request->getParsedBody();
$link = ApiUtils::buildLinkFromRequest($data, $this->conf->get('privacy.default_private_links'));
// duplicate by URL, return 409 Conflict
if (! empty($link['url']) && ! empty($dup = $this->linkDb->getLinkFromUrl($link['url']))) {
return $response->withJson(
ApiUtils::formatLink($dup, index_url($this->ci['environment'])),
$link['id'] = $this->linkDb->getNextId();
$link['shorturl'] = link_small_hash($link['created'], $link['id']);
// note: general relative URL
if (empty($link['url'])) {
$link['url'] = '?' . $link['shorturl'];
if (empty($link['title'])) {
$link['title'] = $link['url'];
$this->linkDb[$link['id']] = $link;
$out = ApiUtils::formatLink($link, index_url($this->ci['environment']));
$redirect = $this->ci->router->relativePathFor('getLink', ['id' => $link['id']]);
return $response->withAddedHeader('Location', $redirect)
->withJson($out, 201, $this->jsonStyle);
* Updates an existing link from posted request body.
* @param Request $request Slim request.
* @param Response $response Slim response.
* @param array $args Path parameters. including the ID.
* @return Response response.
* @throws ApiLinkNotFoundException generating a 404 error.
public function putLink($request, $response, $args)
if (! isset($this->linkDb[$args['id']])) {
throw new ApiLinkNotFoundException();
$index = index_url($this->ci['environment']);
$data = $request->getParsedBody();
$requestLink = ApiUtils::buildLinkFromRequest($data, $this->conf->get('privacy.default_private_links'));
// duplicate URL on a different link, return 409 Conflict
if (! empty($requestLink['url'])
&& ! empty($dup = $this->linkDb->getLinkFromUrl($requestLink['url']))
&& $dup['id'] != $args['id']
) {
return $response->withJson(
ApiUtils::formatLink($dup, $index),
$responseLink = $this->linkDb[$args['id']];
$responseLink = ApiUtils::updateLink($responseLink, $requestLink);
$this->linkDb[$responseLink['id']] = $responseLink;
$out = ApiUtils::formatLink($responseLink, $index);
return $response->withJson($out, 200, $this->jsonStyle);
* Delete an existing link by its ID.
* @param Request $request Slim request.
* @param Response $response Slim response.
* @param array $args Path parameters. including the ID.
* @return Response response.
* @throws ApiLinkNotFoundException generating a 404 error.
public function deleteLink($request, $response, $args)
if (! isset($this->linkDb[$args['id']])) {
throw new ApiLinkNotFoundException();
$link = $this->linkDb[$args['id']];
unset($this->linkDb[(int) $args['id']]);
return $response->withStatus(204);

@ -0,0 +1,34 @
* Class ApiAuthorizationException
* Request not authorized, return a 401 HTTP code.
class ApiAuthorizationException extends ApiException
* {@inheritdoc}
public function getApiResponse()
$this->setMessage('Not authorized');
return $this->buildApiResponse(401);
* Set the exception message.
* We only return a generic error message in production mode to avoid giving
* to much security information.
* @param $message string the exception message.
public function setMessage($message)
$original = $this->debug === true ? ': '. $this->getMessage() : '';
$this->message = $message . $original;

@ -0,0 +1,19 @
* Class ApiBadParametersException
* Invalid request exception, return a 400 HTTP code.
class ApiBadParametersException extends ApiException
* {@inheritdoc}
public function getApiResponse()
return $this->buildApiResponse(400);

@ -0,0 +1,77 @
use Slim\Http\Response;
* Abstract class ApiException
* Parent Exception related to the API, able to generate a valid Response (ResponseInterface).
* Also can include various information in debug mode.
abstract class ApiException extends \Exception {
* @var Response instance from Slim.
protected $response;
* @var bool Debug mode enabled/disabled.
protected $debug;
* Build the final response.
* @return Response Final response to give.
public abstract function getApiResponse();
* Creates ApiResponse body.
* In production mode, it will only return the exception message,
* but in dev mode, it includes additional information in an array.
* @return array|string response body
protected function getApiResponseBody() {
if ($this->debug !== true) {
return $this->getMessage();
return [
'message' => $this->getMessage(),
'stacktrace' => get_class($this) .': '. $this->getTraceAsString()
* Build the Response object to return.
* @param int $code HTTP status.
* @return Response with status + body.
protected function buildApiResponse($code)
$style = $this->debug ? JSON_PRETTY_PRINT : null;
return $this->response->withJson($this->getApiResponseBody(), $code, $style);
* @param Response $response
public function setResponse($response)
$this->response = $response;
* @param bool $debug
public function setDebug($debug)
$this->debug = $debug;

@ -0,0 +1,19 @
* Class ApiInternalException
* Generic exception, return a 500 HTTP code.
class ApiInternalException extends ApiException
* @inheritdoc
public function getApiResponse()
return $this->buildApiResponse(500);

@ -0,0 +1,32 @
use Slim\Http\Response;
* Class ApiLinkNotFoundException
* Link selected by ID couldn't be found, results in a 404 error.
* @package Shaarli\Api\Exceptions
class ApiLinkNotFoundException extends ApiException
* ApiLinkNotFoundException constructor.
public function __construct()
$this->message = 'Link not found';
* {@inheritdoc}
public function getApiResponse()
return $this->buildApiResponse(404);

@ -0,0 +1,34 @
* Interface ConfigIO
* This describes how Config types should store their configuration.
interface ConfigIO
* Read configuration.
* @param string $filepath Config file absolute path.
* @return array All configuration in an array.
public function read($filepath);
* Write configuration.
* @param string $filepath Config file absolute path.
* @param array $conf All configuration in an array.
public function write($filepath, $conf);
* Get config file extension according to config type.
* @return string Config file extension.
public function getExtension();

@ -0,0 +1,85 @
* Class ConfigJson (ConfigIO implementation)
* Handle Shaarli's JSON configuration file.
class ConfigJson implements ConfigIO
* @inheritdoc
public function read($filepath)
if (! is_readable($filepath)) {
return array();
$data = file_get_contents($filepath);
$data = str_replace(self::getPhpHeaders(), '', $data);
$data = str_replace(self::getPhpSuffix(), '', $data);
$data = json_decode($data, true);
if ($data === null) {
$errorCode = json_last_error();
$error = 'An error occurred while parsing JSON configuration file ('. $filepath .'): error code #';
$error .= $errorCode. '<br>➜ <code>' . json_last_error_msg() .'</code>';
if ($errorCode === JSON_ERROR_SYNTAX) {
$error .= '<br>Please check your JSON syntax (without PHP comment tags) using a JSON lint tool such as ';
$error .= '<a href=""></a>.';
throw new \Exception($error);
return $data;
* @inheritdoc
public function write($filepath, $conf)
// JSON_PRETTY_PRINT is available from PHP 5.4.
$print = defined('JSON_PRETTY_PRINT') ? JSON_PRETTY_PRINT : 0;
$data = self::getPhpHeaders() . json_encode($conf, $print) . self::getPhpSuffix();
if (!file_put_contents($filepath, $data)) {
throw new \IOException(
'Shaarli could not create the config file.
Please make sure Shaarli has the right to write in the folder is it installed in.'
* @inheritdoc
public function getExtension()
return '.json.php';
* The JSON data is wrapped in a PHP file for security purpose.
* This way, even if the file is accessible, credentials and configuration won't be exposed.
* Note: this isn't a static field because concatenation isn't supported in field declaration before PHP 5.6.
* @return string PHP start tag and comment tag.
public static function getPhpHeaders()
return '<?php /*'. PHP_EOL;
* Get PHP comment closing tags.
* Static method for consistency with getPhpHeaders.
* @return string PHP comment closing.
public static function getPhpSuffix()
return PHP_EOL . '*/ ?>';

@ -0,0 +1,373 @
use Shaarli\Config\Exception\MissingFieldConfigException;
use Shaarli\Config\Exception\UnauthorizedConfigException;
* Class ConfigManager
* Manages all Shaarli's settings.
* See the documentation for more information on settings:
* - doc/md/
* -
class ConfigManager
* @var string Flag telling a setting is not found.
protected static $NOT_FOUND = 'NOT_FOUND';
public static $DEFAULT_PLUGINS = array('qrcode');
* @var string Config folder.
protected $configFile;
* @var array Loaded config array.
protected $loadedConfig;
* @var ConfigIO implementation instance.
protected $configIO;
* Constructor.
* @param string $configFile Configuration file path without extension.
public function __construct($configFile = 'data/config')
$this->configFile = $configFile;
* Reset the ConfigManager instance.
public function reset()
* Rebuild the loaded config array from config files.
public function reload()
* Initialize the ConfigIO and loaded the conf.
protected function initialize()
if (file_exists($this->configFile . '.php')) {
$this->configIO = new ConfigPhp();
} else {
$this->configIO = new ConfigJson();
* Load configuration in the ConfigurationManager.
protected function load()
try {
$this->loadedConfig = $this->configIO->read($this->getConfigFileExt());
} catch (\Exception $e) {
* Get a setting.
* Supports nested settings with dot separated keys.
* Eg. 'config.stuff.option' will find $conf[config][stuff][option],
* or in JSON:
* { "config": { "stuff": {"option": "mysetting" } } } }
* @param string $setting Asked setting, keys separated with dots.
* @param string $default Default value if not found.
* @return mixed Found setting, or the default value.
public function get($setting, $default = '')
// During the ConfigIO transition, map legacy settings to the new ones.
if ($this->configIO instanceof ConfigPhp && isset(ConfigPhp::$LEGACY_KEYS_MAPPING[$setting])) {
$setting = ConfigPhp::$LEGACY_KEYS_MAPPING[$setting];
$settings = explode('.', $setting);
$value = self::getConfig($settings, $this->loadedConfig);
if ($value === self::$NOT_FOUND) {
return $default;
return $value;
* Set a setting, and eventually write it.
* Supports nested settings with dot separated keys.
* @param string $setting Asked setting, keys separated with dots.
* @param string $value Value to set.
* @param bool $write Write the new setting in the config file, default false.
* @param bool $isLoggedIn User login state, default false.
* @throws \Exception Invalid
public function set($setting, $value, $write = false, $isLoggedIn = false)
if (empty($setting) || ! is_string($setting)) {
throw new \Exception('Invalid setting key parameter. String expected, got: '. gettype($setting));
// During the ConfigIO transition, map legacy settings to the new ones.
if ($this->configIO instanceof ConfigPhp && isset(ConfigPhp::$LEGACY_KEYS_MAPPING[$setting])) {
$setting = ConfigPhp::$LEGACY_KEYS_MAPPING[$setting];
$settings = explode('.', $setting);
self::setConfig($settings, $value, $this->loadedConfig);
if ($write) {
* Check if a settings exists.
* Supports nested settings with dot separated keys.
* @param string $setting Asked setting, keys separated with dots.
* @return bool true if the setting exists, false otherwise.
public function exists($setting)
// During the ConfigIO transition, map legacy settings to the new ones.
if ($this->configIO instanceof ConfigPhp && isset(ConfigPhp::$LEGACY_KEYS_MAPPING[$setting])) {
$setting = ConfigPhp::$LEGACY_KEYS_MAPPING[$setting];
$settings = explode('.', $setting);
$value = self::getConfig($settings, $this->loadedConfig);
if ($value === self::$NOT_FOUND) {
return false;
return true;
* Call the config writer.
* @param bool $isLoggedIn User login state.
* @return bool True if the configuration has been successfully written, false otherwise.
* @throws MissingFieldConfigException: a mandatory field has not been provided in $conf.
* @throws UnauthorizedConfigException: user is not authorize to change configuration.
* @throws \IOException: an error occurred while writing the new config file.
public function write($isLoggedIn)
// These fields are required in configuration.
$mandatoryFields = array(
// Only logged in user can alter config.
if (is_file($this->getConfigFileExt()) && !$isLoggedIn) {
throw new UnauthorizedConfigException();
// Check that all mandatory fields are provided in $conf.
foreach ($mandatoryFields as $field) {
if (! $this->exists($field)) {
throw new MissingFieldConfigException($field);
return $this->configIO->write($this->getConfigFileExt(), $this->loadedConfig);
* Set the config file path (without extension).
* @param string $configFile File path.
public function setConfigFile($configFile)
$this->configFile = $configFile;
* Return the configuration file path (without extension).
* @return string Config path.
public function getConfigFile()
return $this->configFile;
* Get the configuration file path with its extension.
* @return string Config file path.
public function getConfigFileExt()
return $this->configFile . $this->configIO->getExtension();
* Recursive function which find asked setting in the loaded config.
* @param array $settings Ordered array which contains keys to find.
* @param array $conf Loaded settings, then sub-array.
* @return mixed Found setting or NOT_FOUND flag.
protected static function getConfig($settings, $conf)
if (!is_array($settings) || count($settings) == 0) {
return self::$NOT_FOUND;
$setting = array_shift($settings);
if (!isset($conf[$setting])) {
return self::$NOT_FOUND;
if (count($settings) > 0) {
return self::getConfig($settings, $conf[$setting]);
return $conf[$setting];
* Recursive function which find asked setting in the loaded config.
* @param array $settings Ordered array which contains keys to find.
* @param mixed $value
* @param array $conf Loaded settings, then sub-array.
* @return mixed Found setting or NOT_FOUND flag.
protected static function setConfig($settings, $value, &$conf)
if (!is_array($settings) || count($settings) == 0) {
return self::$NOT_FOUND;
$setting = array_shift($settings);
if (count($settings) > 0) {
return self::setConfig($settings, $value, $conf[$setting]);
$conf[$setting] = $value;
* Set a bunch of default values allowing Shaarli to start without a config file.
protected function setDefaultValues()
$this->setEmpty('resource.data_dir', 'data');
$this->setEmpty('resource.config', 'data/config.php');
$this->setEmpty('resource.datastore', 'data/datastore.php');
$this->setEmpty('resource.ban_file', 'data/ipbans.php');
$this->setEmpty('resource.updates', 'data/updates.txt');
$this->setEmpty('resource.log', 'data/log.txt');
$this->setEmpty('resource.update_check', 'data/lastupdatecheck.txt');
$this->setEmpty('resource.history', 'data/history.php');
$this->setEmpty('resource.raintpl_tpl', 'tpl/');
$this->setEmpty('resource.theme', 'default');
$this->setEmpty('resource.raintpl_tmp', 'tmp/');
$this->setEmpty('resource.thumbnails_cache', 'cache');
$this->setEmpty('resource.page_cache', 'pagecache');
$this->setEmpty('security.ban_after', 4);
$this->setEmpty('security.ban_duration', 1800);
$this->setEmpty('security.session_protection_disabled', false);
$this->setEmpty('security.open_shaarli', false);
$this->setEmpty('security.allowed_protocols', ['ftp', 'ftps', 'magnet']);
$this->setEmpty('general.header_link', '?');
$this->setEmpty('general.links_per_page', 20);
$this->setEmpty('general.enabled_plugins', self::$DEFAULT_PLUGINS);
$this->setEmpty('general.default_note_title', 'Note: ');
$this->setEmpty('updates.check_updates', false);
$this->setEmpty('updates.check_updates_branch', 'stable');
$this->setEmpty('updates.check_updates_interval', 86400);
$this->setEmpty('feed.rss_permalinks', true);
$this->setEmpty('feed.show_atom', true);
$this->setEmpty('privacy.default_private_links', false);
$this->setEmpty('privacy.hide_public_links', false);
$this->setEmpty('privacy.force_login', false);
$this->setEmpty('privacy.hide_timestamps', false);
// default state of the 'remember me' checkbox of the login form
$this->setEmpty('privacy.remember_user_default', true);
$this->setEmpty('thumbnail.enable_thumbnails', true);
$this->setEmpty('thumbnail.enable_localcache', true);
$this->setEmpty('redirector.url', '');
$this->setEmpty('redirector.encode_url', true);
$this->setEmpty('plugins', array());
* Set only if the setting does not exists.
* @param string $key Setting key.
* @param mixed $value Setting value.
public function setEmpty($key, $value)
if (! $this->exists($key)) {
$this->set($key, $value);
* @return ConfigIO
public function getConfigIO()
return $this->configIO;
* @param ConfigIO $configIO
public function setConfigIO($configIO)
$this->configIO = $configIO;

namespace Shaarli\Config;
* Class ConfigPhp (ConfigIO implementation)
* Handle Shaarli's legacy PHP configuration file.
* Note: this is only designed to support the transition to JSON configuration.
class ConfigPhp implements ConfigIO
* @var array List of config key without group.
public static $ROOT_KEYS = array(
* Map legacy config keys with the new ones.
* If ConfigPhp is used, getting <newkey> will actually look for <legacykey>.
* The Updater will use this array to transform keys when switching to JSON.
* @var array current key => legacy key.
public static $LEGACY_KEYS_MAPPING = array(
'credentials.login' => 'login',
'credentials.hash' => 'hash',
'credentials.salt' => 'salt',
'resource.data_dir' => 'config.DATADIR',
'resource.config' => 'config.CONFIG_FILE',
'resource.datastore' => 'config.DATASTORE',
'resource.updates' => 'config.UPDATES_FILE',
'resource.log' => 'config.LOG_FILE',
'resource.update_check' => 'config.UPDATECHECK_FILENAME',
'resource.raintpl_tpl' => 'config.RAINTPL_TPL',
'resource.theme' => 'config.theme',
'resource.raintpl_tmp' => 'config.RAINTPL_TMP',
'resource.thumbnails_cache' => 'config.CACHEDIR',
'resource.page_cache' => 'config.PAGECACHE',
'resource.ban_file' => 'config.IPBANS_FILENAME',
'security.session_protection_disabled' => 'disablesessionprotection',
'security.ban_after' => 'config.BAN_AFTER',
'security.ban_duration' => 'config.BAN_DURATION',
'general.title' => 'title',
'general.timezone' => 'timezone',
'general.header_link' => 'titleLink',
'updates.check_updates' => 'config.ENABLE_UPDATECHECK',
'updates.check_updates_branch' => 'config.UPDATECHECK_BRANCH',
'updates.check_updates_interval' => 'config.UPDATECHECK_INTERVAL',
'privacy.default_private_links' => 'privateLinkByDefault',
'feed.rss_permalinks' => 'config.ENABLE_RSS_PERMALINKS',
'general.links_per_page' => 'config.LINKS_PER_PAGE',
'thumbnail.enable_thumbnails' => 'config.ENABLE_THUMBNAILS',
'thumbnail.enable_localcache' => 'config.ENABLE_LOCALCACHE',
'general.enabled_plugins' => 'config.ENABLED_PLUGINS',
'redirector.url' => 'redirector',
'redirector.encode_url' => 'config.REDIRECTOR_URLENCODE',
'feed.show_atom' => 'config.SHOW_ATOM',
'privacy.hide_public_links' => 'config.HIDE_PUBLIC_LINKS',
'privacy.hide_timestamps' => 'config.HIDE_TIMESTAMPS',
'security.open_shaarli' => 'config.OPEN_SHAARLI',
public function read($filepath)
if (! file_exists($filepath) || ! is_readable($filepath)) {
return array();
include $filepath;
$out = array();
foreach (self::$ROOT_KEYS as $key) {
$out[$key] = $GLOBALS[$key];
$out['config'] = $GLOBALS['config'];
$out['plugins'] = !empty($GLOBALS['plugins']) ? $GLOBALS['plugins'] : array();
return $out;
public function write($filepath, $conf)
$configStr = '<?php '. PHP_EOL;
foreach (self::$ROOT_KEYS as $key) {
if (isset($conf[$key])) {
$configStr .= '$GLOBALS[\'' . $key . '\'] = ' . var_export($conf[$key], true) . ';' . PHP_EOL;
// Store all $conf['config']
foreach ($conf['config'] as $key => $value) {
$configStr .= '$GLOBALS[\'config\'][\''. $key .'\'] = '.var_export($conf['config'][$key], true).';'. PHP_EOL;
if (isset($conf['plugins'])) {
foreach ($conf['plugins'] as $key => $value) {
$configStr .= '$GLOBALS[\'plugins\'][\''. $key .'\'] = '.var_export($conf['plugins'][$key], true).';'. PHP_EOL;
if (!file_put_contents($filepath, $configStr)
|| strcmp(file_get_contents($filepath), $configStr) != 0
) {
throw new \IOException(
'Shaarli could not create the config file.
Please make sure Shaarli has the right to write in the folder is it installed in.'
public function getExtension()
return '.php';

View File

@ -0,0 +1,113 @@
use Shaarli\Config\Exception\PluginConfigOrderException;
* Plugin configuration helper functions.
* Note: no access to configuration files here.
* Process plugin administration form data and save it in an array.
* @param array $formData Data sent by the plugin admin form.
* @return array New list of enabled plugin, ordered.
* @throws PluginConfigOrderException Plugins can't be sorted because their order is invalid.
function save_plugin_config($formData)
// Make sure there are no duplicates in orders.
if (!validate_plugin_order($formData)) {
throw new PluginConfigOrderException();
$plugins = array();
$newEnabledPlugins = array();
foreach ($formData as $key => $data) {
if (startsWith($key, 'order')) {
// If there is no order, it means a disabled plugin has been enabled.
if (isset($formData['order_' . $key])) {
$plugins[(int) $formData['order_' . $key]] = $key;
else {
$newEnabledPlugins[] = $key;
// New enabled plugins will be added at the end of order.
$plugins = array_merge($plugins, $newEnabledPlugins);
// Sort plugins by order.
if (!ksort($plugins)) {
throw new PluginConfigOrderException();
$finalPlugins = array();
// Make plugins order continuous.
foreach ($plugins as $plugin) {
$finalPlugins[] = $plugin;
return $finalPlugins;
* Validate plugin array submitted.
* Will fail if there is duplicate orders value.
* @param array $formData Data from submitted form.
* @return bool true if ok, false otherwise.
function validate_plugin_order($formData)
$orders = array();
foreach ($formData as $key => $value) {
// No duplicate order allowed.
if (in_array($value, $orders)) {
return false;
if (startsWith($key, 'order')) {
$orders[] = $value;
return true;
* Affect plugin parameters values from the ConfigManager into plugins array.
* @param mixed $plugins Plugins array:
* $plugins[<plugin_name>]['parameters'][<param_name>] = [
* 'value' => <value>,
* 'desc' => <description>
* ]
* @param mixed $conf Plugins configuration.
* @return mixed Updated $plugins array.
function load_plugin_parameter_values($plugins, $conf)
$out = $plugins;
foreach ($plugins as $name => $plugin) {
if (empty($plugin['parameters'])) {
foreach ($plugin['parameters'] as $key => $param) {
if (!empty($conf[$key])) {
$out[$name]['parameters'][$key]['value'] = $conf[$key];
return $out;

namespace Shaarli\Config\Exception;
* Exception used if a mandatory field is missing in given configuration.
class MissingFieldConfigException extends \Exception
public $field;
* Construct exception.
* @param string $field field name missing.
public function __construct($field)
$this->field = $field;
$this->message = 'Configuration value is required for '. $this->field;

namespace Shaarli\Config\Exception;
* Exception used if an error occur while saving plugin configuration.
class PluginConfigOrderException extends \Exception
* Construct exception.
public function __construct()
$this->message = 'An error occurred while trying to save plugins loading order.';

namespace Shaarli\Config\Exception;
* Exception used if an unauthorized attempt to edit configuration has been made.
class UnauthorizedConfigException extends \Exception
* Construct exception.
public function __construct()
$this->message = 'You are not authorized to alter config.';

* Exception class thrown when a filesystem access failure happens
class IOException extends Exception
private $path;
* Construct a new IOException
* @param string $path path to the resource that cannot be accessed
* @param string $message Custom exception message.
public function __construct($path, $message = '')
$this->path = $path;
$this->message = empty($message) ? 'Error accessing' : $message;
$this->message .= ' "' . $this->path .'"';

<IfModule version_module>
<IfVersion >= 2.4>
Require all denied
<IfVersion < 2.4>
Allow from none
Deny from all
<IfModule !version_module>
Require all denied

"name": "shaarli/shaarli",
"description": "The personal, minimalist, super-fast, database-free bookmarking service",
"type": "project",
"license": "MIT",
"homepage": "",
"support": {
"issues": "",
"wiki": ""
"keywords": ["bookmark", "link", "share", "web"],
"config": {
"platform": {
"php": "5.5.38"
"require": {
"php": ">=5.5",
"shaarli/netscape-bookmark-parser": "^2.0",
"erusev/parsedown": "1.6",
"slim/slim": "^3.0",
"pubsubhubbub/publisher": "dev-master"
"require-dev": {
"phpmd/phpmd" : "@stable",
"phpunit/phpunit": "4.8.*",
"sebastian/phpcpd": "*",
"squizlabs/php_codesniffer": "2.*",
"phpunit/phpcov": "*"
"autoload": {
"psr-4": {
"Shaarli\\": "application",
"Shaarli\\Api\\": "application/api/",
"Shaarli\\Api\\Controllers\\": "application/api/controllers",
"Shaarli\\Api\\Exceptions\\": "application/api/exceptions",
"Shaarli\\Config\\": "application/config/",
"Shaarli\\Config\\Exception\\": "application/config/exception"

<IfModule version_module>
<IfVersion >= 2.4>
Require all denied
<IfVersion < 2.4>
Allow from none
Deny from all
<IfModule !version_module>
Require all denied

## CSS
- Yahoo UI [CSS Reset](
- resets default CSS properties for all HTML elements (overriding browsers' default values)
- ensures custom CSS stylessheets will provide the same results on all browsers
## Javascript
- [Awesomeplete]( ([GitHub]( - autocompletion in input forms
- [bLazy]( ([GitHub]( - lazy loading for thumbnails
- [qr.js]( ([GitHub]( - QR code generation
## PHP
- [shaarli/netscape-bookmark-parser]( - Netscape bookmark parser
- [RainTPL]( - HTML templating for PHP

## Backup and restore the datastore file
Backup the file `data/datastore.php` (by FTP or SSH). Restore by putting the file back in place.
Example command:
rsync -avzP datastore-$(date +%Y-%m-%d_%H%M).php
## Export links as...
To export links as an HTML file, under _Tools > Export_, choose:
- _Export all_ to export both public and private links
- _Export public_ to export public links only
- _Export private_ to export private links only
Restore by using the `Import` feature.
- This can be done using the [shaarchiver]( tool.
Example command:
./ --url= --username=myusername --password=mysupersecretpassword --download-dir=./ --type=all
## Import links from...
### Diigo
If you export your bookmark from Diigo, make sure you use the Delicious export, not the Netscape export. (Their Netscape export is broken, and they don't seem to be interested in fixing it.)
### Mister Wong
See [this issue]( for import tweaks.
### SemanticScuttle
To correctly import the tags from a [SemanticScuttle]( HTML export, edit the HTML file before importing and replace all occurences of `tags=` (lowercase) to `TAGS=` (uppercase).
### Scuttle
Shaarli cannot import data directly from [Scuttle](
However, you can use the third-party [scuttle-to-shaarli](
tool to export the Scuttle database to the Netscape HTML format compatible with the Shaarli importer.
## Import Shaarli links to Firefox
- Export your Shaarli links as described above.
- For compatibility reasons, check `Prepend note permalinks with this Shaarli instance's URL (useful to import bookmarks in a web browser)`
- In Firefox, open the bookmark manager (not the sidebar! `Bookmarks menu > Show all bookmarks` or `Ctrl+Shift+B`)
- Select `Import and Backup > Import bookmarks in HTML format`
Your bookmarks will be imported in Firefox, ready to use, with tags and descriptions retained. "Self" (notes) shaares will still point to the Shaarli instance you exported them from, but the note text can be viewed directly in the bookmark properties inside your browser. Depending on the number of bookmarks, the import can take some time.
You may be interested in these Firefox addons to manage links imported from Shaarli
- [Bookmark Deduplicator]( - provides an easy way to deduplicate your bookmarks
- [TagSieve]( - browse your bookmarks by their tags

@ -0,0 +1,29 @@
## Add the sharing button (_bookmarklet_) to your browser
- Open your Shaarli and `Login`
- Click the `Tools` button in the top bar
- Drag the **`✚Shaare link` button**, and drop it to your browser's bookmarks bar.
_This bookmarklet button is compatible with Firefox, Opera, Chrome and Safari. Under Opera, you can't drag'n drop the button: You have to right-click on it and add a bookmark to your personal toolbar._
## Share links using the _bookmarklet_
- When you are visiting a webpage you would like to share with Shaarli, click the _bookmarklet_ you just added.
- A window opens.
- You can freely edit title, description, tags... to find it later using the text search or tag filtering.
- You will be able to edit this link later using the ![]( edit button.
- You can also check the “Private” box so that the link is saved but only visible to you.
- Click `Save`.**Voilà! Your link is now shared.**
## Troubleshooting: The bookmarklet doesn't work with a few websites (e.g.
Websites which enforce Content Security Policy (CSP), such as, disallow usage of bookmarklets. Unfortunatly, there is nothing Shaarli can do about it.
See [#196](
There is an open bug for both Firefox and Chromium:

## Plain text search
Use the `Search text` field to search in _any_ of the fields of all links (Title, URL, Description...)
**Exclude text/tags:** Use the `-` operator before a word or tag (example `-uninteresting`) to prevent entries containing (or tagged) `uninteresting` from showing up in the search results.
**Exact text search:** Use double-quotes (example `"exact search"`) to search for the exact expression.
Both exclude patterns and exact searches can be combined with normal searches (example `"exact search" term otherterm -notthis "very exact" stuff -notagain`)
## Tags search
Use the `Filter by tags` field to restrict displayed links to entries tagged with one or multiple tags (use space to separate tags).
**Hidden tags:** Tags starting with a dot `.` (example `.secret`) are private. They can only be seen and searched when logged in.
Alternatively you can use the `Tag cloud` to discover all tags and click on any of them to display related links.
To search for links that are not tagged, enter `""` in the tag search field.
## Filtering RSS feeds/Picture wall
RSS feeds can also be restricted to only return items matching a text/tag search: see [RSS feeds](RSS feeds).

_Unofficial but related work on Shaarli. If you maintain one of these,
please get in touch with us to help us find a way to adapt your work to our fork._
## Community
- [Liens en vrac de sebsauvage]( - the original Shaarli
- [A large list of Shaarlis](
- [A list of working Shaarli aggregators](
- [A list of some known Shaarlis](
- [Adieu Delicious, Diigo et StumbleUpon. Salut Shaarli ! -]( (fr) _16/09/2011 - the original post about Shaarli_
- [Original ideas/fixme/TODO page](
- [Original discussion page]( (fr)
- [Original revisions history](
- []( - Unofficial, unsupported (old fork) hosted Shaarlis provider, courtesy of [DMeloni](
### Articles and social media discussions
- 2016-09-22 - Hacker News -
- 2015-08-15 - Reddit - [Question about migrating from WordPress to Shaarli.](
- 2015-06-22 - Hacker News -
- 2015-05-12 - Reddit - [shaarli - Self hosted Bookmarking / Delicious (PHP, MySQL)](
See [REST API](REST-API) for a list of official and community clients.
- [autosave]( by [@kalvn]( Automatically saves data when editing a link to avoid any loss in case of crash or unexpected shutdown.
- [Code Coloration]( by [@ArthurHoaro]( client side code syntax highlighter.
- [Disqus]( by [@kalvn]( Adds Disqus comment system to your Shaarli.
- [emojione]( by [@NerosTie]( Add colorful emojis to your Shaarli.
- [google analytics]( by [@ericjuden]( Adds Google Analytics tracking support
- [launch]( - Launch Plugin is a plugin designed to enhance and customize Launch Theme for Shaarli.
- [related]( by [@ilesinge]( - Show related links based on the number of identical tags.
- [social]( by [@alexisju]( share links to social networks.
- [shaarli2twitter]( by [@ArthurHoaro]( - Automatically tweet your shared links from Shaarli
See [Theming](Theming) for a list of community-contributed themes, and an installation guide.
- [tt-rss-shaarli]( - [Tiny-Tiny RSS]( plugin that adds support for sharing articles with Shaarli
- [octopress-shaarli]( - Octopress plugin to retrieve Shaarli links on the sidebar
- [Scuttle to Shaarli]( - Import bookmarks from Scuttle
- [ShaarliOS]( iOS share extension - see [#308]( for some promo codes,
- [Shaarli for Android]( - Android application that adds Shaarli as a sharing provider
- [Shaarlier for Android]( - Android application to simply add links directly into your Shaarli
- [shaarchiver]( - Archive your Shaarli bookmarks and their content
- [shaarli-river]( - An aggregator for shaarlis with many features
- [Shaarlo]( - An aggregator for shaarlis with many features (a very popular running instance among French shaarliers: [](
- [Shaarlimages]( - An image-oriented aggregator for Shaarlis
- [mknexen/shaarli-api]( - A REST API for Shaarli
- [Self dead link]( - Detect dead links on shaarli. This version use the database of shaarli. [Another version](, can be used for other shaarli instances (but is more resource consuming).
- [Bookmark Archiver]( - Save an archived copy of all websites starred using browser bookmarks/Shaarli/Delicious/Instapaper/ Outputs browseable html.
See the [bookmarks & link sharing](
section on [awesome-selfhosted](

## Local development
A [`Makefile`]( is available to perform project-related operations:
- Documentation - generate a local HTML copy of the GitHub wiki
- [Static analysis](Static analysis) - check that the code is compliant to PHP conventions
- [Unit tests](Unit tests) - ensure there are no regressions introduced by new commits
## Automatic builds
[Travis CI]( is a Continuous Integration build server, that runs a build:
- each time a commit is merged to the mainline (`master` branch)
- each time a Pull Request is submitted or updated
A build is composed of several jobs: one for each supported PHP version (see [Server requirements](Server requirements)).
Each build job:
- updates Composer
- installs 3rd-party test dependencies with Composer
- runs [Unit tests](Unit tests)
After all jobs have finished, Travis returns the results to GitHub:
- a status icon represents the result for the `master` branch: [![](](
- Pull Requests are updated with the Travis result
- Green: all tests have passed
- Red: some tests failed
- Orange: tests are pending

Please have a look at the following pages:
- [Contributing to Shaarli](
- [Static analysis](Static analysis) - patches should try to stick to the [PHP Standard Recommendations]( (PSR), especially:
- [PSR-1]( - Basic Coding Standard
- [PSR-2]( - Coding Style Guide
- [Unit tests](Unit tests)
- [GnuPG signature](GnuPG signature) for tags/releases

index.php # Main program
application/ # Shaarli classes
├── LinkDB.php
└── Utils.php
tests/ # Shaarli unitary & functional tests
├── LinkDBTest.php
├── utils # utilities to ease testing
│ └── ReferenceLinkDB.php
└── UtilsTest.php
COPYING # Shaarli license
inc/ # static assets and 3rd party libraries
├── awesomplete.* # tags autocompletion library
├── blazy.* # picture wall lazy image loading library
├── shaarli.css, reset.css # Shaarli stylesheet.
├── qr.* # qr code generation library
└──rain.tpl.class.php # RainTPL templating library
tpl/ # RainTPL templates for Shaarli. They are used to build the pages.
images/ # Images and icons used in Shaarli
data/ # data storage: bookmark database, configuration, logs, banlist…
├── config.php # Shaarli configuration (login, password, timezone, title…)
├── datastore.php # Your link database (compressed).
├── ipban.php # IP address ban system data
├── lastupdatecheck.txt # Update check timestamp file
└──log.txt # login/IPban log.
cache/ # thumbnails cache
# This directory is automatically created. You can erase it anytime you want.
tmp/ # Temporary directory for compiled RainTPL templates.
# This directory is automatically created. You can erase it anytime you want.

Also, please make sure your server meets the [requirements](Server-requirements)
and is properly [configured](Server-configuration).
Several releases are available:
- by downloading full release archives including all dependencies
- by downloading Github archives
- by cloning the Git repository
## Latest release (recommended)
### Download as an archive
Get the latest released version from the [releases]( page.
**Download our *shaarli-full* archive** to include dependencies.
The current latest released version is `v0.9.1`
Or in command lines:
$ wget
$ unzip
$ mv Shaarli /path/to/shaarli/
In most cases, download Shaarli from the [releases]( page. Cloning using `git` or downloading Github branches as zip files requires additional steps (see below).|
### Using git
$ mkdir -p /path/to/shaarli && cd /path/to/shaarli/
$ git clone -b v0.9 .
$ composer install --no-dev --prefer-dist
## Stable version
The stable version has been experienced by Shaarli users, and will receive security updates.
### Download as an archive
As a .zip archive:
$ wget
$ unzip
$ mv Shaarli-stable /path/to/shaarli/
As a .tar.gz archive :
$ wget
$ tar xvf stable.tar.gz
$ mv Shaarli-stable /path/to/shaarli/
### Clone with Git
[Composer]( is required to build a functional Shaarli installation when pulling from git.
$ git clone -b stable /path/to/shaarli/
# install/update third-party dependencies
$ cd /path/to/shaarli/
$ composer install --no-dev --prefer-dist
## Development version (mainline)
_Use at your own risk!_
To get the latest changes from the `master` branch:
# clone the repository
$ git clone -b master /path/to/shaarli/
# install/update third-party dependencies
$ cd /path/to/shaarli
$ composer install --no-dev --prefer-dist
## Finish Installation
Once Shaarli is downloaded and files have been placed at the correct location, open it this location your favorite browser.
![install screenshot](
Setup your Shaarli installation, and it's ready to use!
## Updating Shaarli
See [Upgrade and Migration](Upgrade-and-migration)

doc/md/ Normal file
View File

### Why use Shaarli and not Delicious/Diigo ?
With Shaarli:
- The data is yours: It's hosted on your server.
- Never fear of having your data locked-in.
- Never fear to have your data sold to third party.
- Your private links are not hosted on a third party server.
- You are not tracked by browser addons (like Diigo does)
- You can change the look and feel of the pages if you want.
- You can change the behaviour of the program.
- It's magnitude faster than most bookmarking services.
### What does Shaarli mean?
Shaarli stands for _shaaring_ your _links_.
### My Shaarli is broken!
First of all, ensure that both the [web server](Server-configuration) and [Shaarli](Shaarli-configuration) are correctly configured, and that your installation is [supported](Server-requirements).
If everything looks right but the issue(s) remain(s), please:
- take a look at the [troubleshooting](Troubleshooting) section
- come [chat with us]( on Gitter, we'll be happy to help ;-)
- browse active [issues]( and [Pull Requests](
- if you find one that is related to the issue, feel free to comment and provide additional details (host/Shaarli setup)
- else, [open a new issue](, and provide information about the problem:
- _what happens?_ - display glitches, invalid data, security flaws...
- _what is your configuration?_ - OS, server version, activated extensions, web browser...
- _is it reproducible?_
### Why not use a real database? Files are slow!
Does browsing [this page]( feel slow? Try browsing older pages, too.
It's not slow at all, is it? And don't forget the database contains more than 16000 links, and it's on a shared host, with 32000 visitors/day for my website alone. And it's still damn fast. Why?
The data file is only 3.7 Mb. It's read 99% of the time, and is probably already in the operation system disk cache. So generating a page involves no I/O at all most of the time.

Shaarli is intended:
- to share, comment and save interesting links and news
- to bookmark useful/frequent personal links (as private links) and share them between computers
- as a minimal blog/microblog/writing platform (no character limit)
- as a read-it-later list (for example items tagged `readlater`)
- to draft and save articles/ideas
- to keep code snippets
- to keep notes and documentation
- as a shared clipboard between machines
- as a todo list
- to store playlists (e.g. with the `music` or `video` tags)
- to keep extracts/comments from webpages that may disappear
- to keep track of ongoing discussions (for example items tagged `discussion`)
- [to feed RSS aggregators]( (planets) with specific tags
- to feed other social networks, blogs... using RSS feeds and external services (, ...)
### Using Shaarli as a blog, notepad, pastebin...
- Go to your Shaarli setup and log in
- Click the `Add Link` button
- To share text only, do not enter any URL in the corresponding input field and click `Add Link`
- Pick a title and enter your article, or note, in the description field; add a few tags; optionally check `Private` then click `Save`
- Voilà! Your article is now published (privately if you selected that option) and accessible using its permalink.

- Open your Shaarli and `Login`
- Click the `Tools` button in the top bar
- Click the `✚Add to Firefox social` button and accept the activation.
### Sharing links using Firefox share
- Add the sharing service as described above
- When you are visiting a webpage you would like to share with Shaarli,
click the Firefox _Share_ button [images/firefoxshare.png](images/firefoxshare.png)
- You can edit your link before and after saving, just like the bookmarklet above.
_Your Shaarli instance must be hosted on an HTTPS (SSL/TLS secure connection)
enabled server for Firefox Share to work. Firefox Share will not work over
plain HTTP connections._

### PGP and GPG
[Gnu Privacy Guard]( (GnuPG) is an Open Source implementation of the
[Pretty Good Privacy](
(OpenPGP) specification. Its main purposes are digital authentication, signature and encryption.
It is often used by the [FLOSS]( community to verify:
- Linux package signatures: Debian [SecureApt](, ArchLinux [Master
- [SCM]( releases & maintainer identity
### Trust
To quote Phil Pennock (the author of the [SKS]( key server -
> You MUST understand that presence of data in the keyserver (pools) in no way connotes trust. Anyone can generate a key, with any name or email address, and upload it. All security and trust comes from evaluating security at the “object level”, via PGP Web-Of-Trust signatures. This keyserver makes it possible to retrieve keys, looking them up via various indices, but the collection of keys in this public pool is KNOWN to contain malicious and fraudulent keys. It is the common expectation of server operators that users understand this and use software which, like all known common OpenPGP implementations, evaluates trust accordingly. This expectation is so common that it is not normally explicitly stated.
Trust can be gained by having your key signed by other people (and signing their key back, too :) ), for instance during [key signing parties](, see:
- [The Keysigning party HOWTO](
- [Web of trust](
## Generate a GPG key
- [Generating a GPG key for Git tagging]( (StackOverflow)
- [Generating a GPG key]( (GitHub)
### gpg - provide identity information
$ gpg --gen-key
gpg (GnuPG) 2.1.6; Copyright (C) 2015 Free Software Foundation, Inc.
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
Note: Use "gpg2 --full-gen-key" for a full featured key generation dialog.
GnuPG needs to construct a user ID to identify your key.
Real name: Marvin the Paranoid Android
Email address:
You selected this USER-ID:
"Marvin the Paranoid Android <>"
Change (N)ame, (E)mail, or (O)kay/(Q)uit? o
We need to generate a lot of random bytes. It is a good idea to perform
some other action (type on the keyboard, move the mouse, utilize the
disks) during the prime generation; this gives the random number
generator a better chance to gain enough entropy.
### gpg - entropy interlude
At this point, you will:
- be prompted for a secure password to protect your key (the input method will depend on your Desktop Environment and configuration)
- be asked to use your machine's input devices (mouse, keyboard, etc.) to generate random entropy; this step _may take some time_
### gpg - key creation confirmation
gpg: key A9D53A3E marked as ultimately trusted
public and secret key created and signed.
gpg: checking the trustdb
gpg: 3 marginal(s) needed, 1 complete(s) needed, PGP trust model
gpg: depth: 0 valid: 2 signed: 0 trust: 0-, 0q, 0n, 0m, 0f, 2u
pub rsa2048/A9D53A3E 2015-07-31
Key fingerprint = AF2A 5381 E54B 2FD2 14C4 A9A3 0E35 ACA4 A9D5 3A3E
uid [ultimate] Marvin the Paranoid Android <>
sub rsa2048/8C0EACF1 2015-07-31
### gpg - submit your public key to a PGP server (Optional)
``` bash
$ gpg --keyserver --send-keys A9D53A3E
gpg: sending key A9D53A3E to hkp server
## Create and push a GPG-signed tag
See [Release Shaarli](Release Shaarli).

[**I am a template designer: ** Guide for template designers](#guide-for-template-designer)
## Developer API
### What can I do with plugins?
The plugin system let you:
- insert content into specific places across templates.
- alter data before templates rendering.
- alter data before saving new links.
### How can I create a plugin for Shaarli?
First, chose a plugin name, such as `demo_plugin`.
Under `plugin` folder, create a folder named with your plugin name. Then create a <plugin_name>.php file in that folder.
You should have the following tree view:
| index.php
| plugins/
|---| demo_plugin/
| |---| demo_plugin.php
### Plugin initialization
At the beginning of Shaarli execution, all enabled plugins are loaded. At this point, the plugin system looks for an `init()` function to execute and run it if it exists. This function must be named this way, and takes the `ConfigManager` as parameter.
This function can be used to create initial data, load default settings, etc. But also to set *plugin errors*. If the initialization function returns an array of strings, they will be understand as errors, and displayed in the header to logged in users.
### Understanding hooks
A plugin is a set of functions. Each function will be triggered by the plugin system at certain point in Shaarli execution.
These functions need to be named with this pattern:
hook_<plugin_name>_<hook_name>($data, $conf)
- data: see [$data section](
- conf: the `ConfigManager` instance.
For example, if my plugin want to add data to the header, this function is needed:
If this function is declared, and the plugin enabled, it will be called every time Shaarli is rendering the header.
### Plugin's data
#### Parameters
Every hook function has a `$data` parameter. Its content differs for each hooks.
**This parameter needs to be returned every time**, otherwise data is lost.
return $data;
#### Filling templates placeholder
Template placeholders are displayed in template in specific places.
RainTPL displays every element contained in the placeholder's array. These element can be added by plugins.
For example, let's add a value in the placeholder `top_placeholder` which is displayed at the top of my page:
$data['top_placeholder'][] = 'My content';
# OR
array_push($data['top_placeholder'], 'My', 'content');
return $data;
#### Data manipulation
When a page is displayed, every variable send to the template engine is passed to plugins before that in `$data`.
The data contained by this array can be altered before template rendering.
For exemple, in linklist, it is possible to alter every title:
// mind the reference if you want $data to be altered
foreach ($data['links'] as &$value) {
// String reverse every title.
$value['title'] = strrev($value['title']);
return $data;
### Metadata
Every plugin needs a `<plugin_name>.meta` file, which is in fact an `.ini` file (`KEY="VALUE"`), to be listed in plugin administration.
Each file contain two keys:
- `description`: plugin description
- `parameters`: user parameter names, separated by a `;`.
- `parameter.<PARAMETER_NAME>`: add a text description the specified parameter.
> Note: In PHP, `parse_ini_file()` seems to want strings to be between by quotes `"` in the ini file.
### It's not working!
Use `demo_plugin` as a functional example. It covers most of the plugin system features.
If it's still not working, please [open an issue](
### Hooks
| Hooks | Description |
| ------------- |:-------------:|
| [render_header](#render_header) | Allow plugin to add content in page headers. |
| [render_includes](#render_includes) | Allow plugin to include their own CSS files. |
| [render_footer](#render_footer) | Allow plugin to add content in page footer and include their own JS files. |
| [render_linklist](#render_linklist) | It allows to add content at the begining and end of the page, after every link displayed and to alter link data. |
| [render_editlink](#render_editlink) | Allow to add fields in the form, or display elements. |
| [render_tools](#render_tools) | Allow to add content at the end of the page. |
| [render_picwall](#render_picwall) | Allow to add content at the top and bottom of the page. |
| [render_tagcloud](#render_tagcloud) | Allow to add content at the top and bottom of the page, and after all tags. |
| [render_taglist](#render_taglist) | Allow to add content at the top and bottom of the page, and after all tags. |
| [render_daily](#render_daily) | Allow to add content at the top and bottom of the page, the bottom of each link and to alter data. |
| [render_feed](#render_feed) | Allow to do add tags in RSS and ATOM feeds. |
| [save_link](#save_link) | Allow to alter the link being saved in the datastore. |
| [delete_link](#delete_link) | Allow to do an action before a link is deleted from the datastore. |
#### render_header
Triggered on every page.
Allow plugin to add content in page headers.
##### Data
`$data` is an array containing:
- `_PAGE_`: current target page (eg: `linklist`, `picwall`, etc.).
- `_LOGGEDIN_`: true if user is logged in, false otherwise.
##### Template placeholders
Items can be displayed in templates by adding an entry in `$data['<placeholder>']` array.
List of placeholders:
- `buttons_toolbar`: after the list of buttons in the header.
- `fields_toolbar`: after search fields in the header.
> Note: This will only be called in linklist.
#### render_includes
Triggered on every page.
Allow plugin to include their own CSS files.
##### Data
`$data` is an array containing:
- `_PAGE_`: current target page (eg: `linklist`, `picwall`, etc.).
- `_LOGGEDIN_`: true if user is logged in, false otherwise.
##### Template placeholders
Items can be displayed in templates by adding an entry in `$data['<placeholder>']` array.
List of placeholders:
- `css_files`: called after loading default CSS.
> Note: only add the path of the CSS file. E.g: `plugins/demo_plugin/custom_demo.css`.
#### render_footer
Triggered on every page.
Allow plugin to add content in page footer and include their own JS files.
##### Data
`$data` is an array containing:
- `_PAGE_`: current target page (eg: `linklist`, `picwall`, etc.).
- `_LOGGEDIN_`: true if user is logged in, false otherwise.
##### Template placeholders
Items can be displayed in templates by adding an entry in `$data['<placeholder>']` array.
List of placeholders:
- `text`: called after the end of the footer text.
- `endofpage`: called at the end of the page.
- `js_files`: called at the end of the page, to include custom JS scripts.
> Note: only add the path of the JS file. E.g: `plugins/demo_plugin/custom_demo.js`.
#### render_linklist
Triggered when `linklist` is displayed (list of links, permalink, search, tag filtered, etc.).
It allows to add content at the begining and end of the page, after every link displayed and to alter link data.
##### Data
`$data` is an array containing:
- `_LOGGEDIN_`: true if user is logged in, false otherwise.
- All templates data, including links.
##### Template placeholders
Items can be displayed in templates by adding an entry in `$data['<placeholder>']` array.
List of placeholders:
- `action_plugin`: next to the button "private only" at the top and bottom of the page.
- `link_plugin`: for every link, between permalink and link URL.
- `plugin_start_zone`: before displaying the template content.
- `plugin_end_zone`: after displaying the template content.
#### render_editlink
Triggered when the link edition form is displayed.
Allow to add fields in the form, or display elements.
##### Data
`$data` is an array containing:
- All templates data.
##### Template placeholders
Items can be displayed in templates by adding an entry in `$data['<placeholder>']` array.
List of placeholders:
- `edit_link_plugin`: after tags field.
#### render_tools
Triggered when the "tools" page is displayed.
Allow to add content at the end of the page.
##### Data
`$data` is an array containing:
- All templates data.
##### Template placeholders
Items can be displayed in templates by adding an entry in `$data['<placeholder>']` array.
List of placeholders:
- `tools_plugin`: at the end of the page.
#### render_picwall
Triggered when picwall is displayed.
Allow to add content at the top and bottom of the page.
##### Data
`$data` is an array containing:
- `_LOGGEDIN_`: true if user is logged in, false otherwise.
- All templates data.
##### Template placeholders
Items can be displayed in templates by adding an entry in `$data['<placeholder>']` array.
List of placeholders:
- `plugin_start_zone`: before displaying the template content.
- `plugin_end_zone`: after displaying the template content.
#### render_tagcloud
Triggered when tagcloud is displayed.
Allow to add content at the top and bottom of the page.
##### Data
`$data` is an array containing:
- `_LOGGEDIN_`: true if user is logged in, false otherwise.
- All templates data.
##### Template placeholders
Items can be displayed in templates by adding an entry in `$data['<placeholder>']` array.
List of placeholders:
- `plugin_start_zone`: before displaying the template content.
- `plugin_end_zone`: after displaying the template content.
For each tag, the following placeholder can be used:
- `tag_plugin`: after each tag
#### render_taglist
Triggered when taglist is displayed.
Allow to add content at the top and bottom of the page.
##### Data
`$data` is an array containing:
- `_LOGGEDIN_`: true if user is logged in, false otherwise.
- All templates data.
##### Template placeholders
Items can be displayed in templates by adding an entry in `$data['<placeholder>']` array.
List of placeholders:
- `plugin_start_zone`: before displaying the template content.
- `plugin_end_zone`: after displaying the template content.
For each tag, the following placeholder can be used:
- `tag_plugin`: after each tag
#### render_daily
Triggered when tagcloud is displayed.
Allow to add content at the top and bottom of the page, the bottom of each link and to alter data.
##### Data
`$data` is an array containing:
- `_LOGGEDIN_`: true if user is logged in, false otherwise.
- All templates data, including links.
##### Template placeholders
Items can be displayed in templates by adding an entry in `$data['<placeholder>']` array.
List of placeholders:
- `link_plugin`: used at bottom of each link.
- `plugin_start_zone`: before displaying the template content.
- `plugin_end_zone`: after displaying the template content.
#### render_feed
Triggered when the ATOM or RSS feed is displayed.
Allow to add tags in the feed, either in the header or for each items. Items (links) can also be altered before being rendered.
##### Data
`$data` is an array containing:
- `_LOGGEDIN_`: true if user is logged in, false otherwise.
- `_PAGE_`: containing either `rss` or `atom`.
- All templates data, including links.
##### Template placeholders
Tags can be added in feeds by adding an entry in `$data['<placeholder>']` array.
List of placeholders:
- `feed_plugins_header`: used as a header tag in the feed.
For each links:
- `feed_plugins`: additional tag for every link entry.
#### save_link
Triggered when a link is save (new link or edit).
Allow to alter the link being saved in the datastore.
##### Data
`$data` is an array containing the link being saved:
- id
- title
- url
- shorturl
- description
- private
- tags
- created
- updated
#### delete_link
Triggered when a link is deleted.
Allow to execute any action before the link is actually removed from the datastore
##### Data
`$data` is an array containing the link being saved:
- id
- title
- url
- shorturl
- description
- private
- tags
- created
- updated
## Guide for template designer
### Plugin administration
Your theme must include a plugin administration page: `pluginsadmin.html`.
> Note: repo's template link needs to be added when the PR is merged.
Use the default one as an example.
Aside from classic RainTPL loops, plugins order is handle by JavaScript. You can just include `plugin_admin.js`, only if:
- you're using a table.
- you call orderUp() and orderUp() onclick on arrows.
- you add data-line and data-order to your rows.
Otherwise, you can use your own JS as long as this field is send by the form:
<input type="hidden" name="order_{$key}" value="{$counter}">
### Placeholder system
In order to make plugins work with every custom themes, you need to add variable placeholder in your templates.
It's a RainTPL loop like this:
You should enable `demo_plugin` for testing purpose, since it uses every placeholder available.
### List of placeholders
At the end of the menu:
At the end of file, before clearing floating blocks:
{if="!empty($plugin_errors) && isLoggedIn()"}
<ul class="errors">
At the end of the file:
<link type="text/css" rel="stylesheet" href="{$value}#"/>
At the end of your footer notes:
At the end of file:
<script src="{$value}#"></script>
After search fields:
Before displaying the link list (after paging):
For every links (icons):
Before end paging:
After the "private only" icon:
After tags field:
After the last tool:
<div id="plugin_zone_start_picwall" class="plugin_zone">
<div id="plugin_zone_end_picwall" class="plugin_zone">
<div id="plugin_zone_start_tagcloud" class="plugin_zone">
<div id="plugin_zone_end_tagcloud" class="plugin_zone">
<div id="plugin_zone_start_picwall" class="plugin_zone">
After every link:
<div class="dailyEntryFooter">
<div id="plugin_zone_end_picwall" class="plugin_zone">
**feed.atom.xml** and **feed.rss.xml**:
In headers tags section:
After each entry:

There is a bunch of plugins shipped with Shaarli, where there is nothing to do to install them.
If you want to install a third party plugin:
- Download it.
- Put it in the `plugins` directory in Shaarli's installation folder.
- Make sure you put it correctly:
| index.php
| plugins/
|---| custom_plugin/
| |---| custom_plugin.php
| |---| ...
* Make sure your webserver can read and write the files in your plugin folder.
## Plugin configuration
In Shaarli's administration page (`Tools` link), go to `Plugin administration`.
Here you can enable and disable all plugins available, and configure them.
![administration screenshot](
## Plugin order
In the plugin administration page, you can move enabled plugins to the top or bottom of the list. The first plugins in the list will be processed first.
This is important in case plugins are depending on each other. Read plugins README details for more information.
**Use case**: The (non existent) plugin `shaares_footer` adds a footer to every shaare in Markdown syntax. It needs to be processed *before* (higher in the list) the Markdown plugin. Otherwise its syntax won't be translated in HTML.
## File mode
Enabled plugin are stored in your `config.php` parameters file, under the `array`:
You can edit them manually here.
$GLOBALS['config']['ENABLED_PLUGINS'] = array(
### Plugin usage
#### Official plugins
Usage of each plugin is documented in it's README file:
* `addlink-toolbar`: Adds the addlink input on the linklist page
* `archiveorg`: For each link, add an icon
* [`markdown`]( Render shaare description with Markdown syntax.
* [`playvideos`]( Add a button in the toolbar allowing to watch all videos.
* `qrcode`: For each link, add a QRCode icon.
* [`wallabag`]( For each link, add a Wallabag icon to save it in your instance.
#### Third party plugins
See [Community & related software](

See the [REST API documentation](
for a list of available endpoints and parameters.
Please ensure that your server meets the [requirements](Server-requirements)
and is properly [configured](Server-configuration):
- URL rewriting is enabled (see specific Apache and Nginx sections)
- the server's timezone is properly defined
- the server's clock is synchronized with
The host where the API client is invoked should also be synchronized with NTP,
see [token expiration](#payload).
## Authentication
All requests to Shaarli's API must include a JWT token to verify their authenticity.
This token has to be included as an HTTP header called `Authentication: Bearer <jwt token>`.
JWT resources :
- []( (including a list of client per language).
- RFC :
- HackerNews thread:
### Shaarli JWT Token
JWT tokens are composed by three parts, separated by a dot `.` and encoded in base64:
#### Header
Shaarli only allow one hash algorithm, so the header will always be the same:
"typ": "JWT",
"alg": "HS512"
Encoded in base64, it gives:
#### Payload
**Token expiration**
To avoid infinite token validity, JWT tokens must include their creation date
in UNIX timestamp format (timezone independent - UTC) under the key `iat` (issued at).
This token will be valid during **9 minutes**.
"iat": 1468663519
See [RFC reference](
#### Signature
The signature authenticate the token validity. It contains the base64 of the header and the body, separated by a dot `.`, hashed in SHA512 with the API secret available in Shaarli administration page.
Signature example with PHP:
$content = base64_encode($header) . '.' . base64_encode($payload);
$signature = hash_hmac('sha512', $content, $secret);
## Clients and examples
### Android, Java, Kotlin
- [Android client example with Kotlin](
by [Braincoke](
### Javascript, NodeJS
- [shaarli-client](
([source code](
by [laBecasse](
### PHP
This example uses the [PHP cURL]( library.
$baseUrl = '';
$secret = 'thats_my_api_secret';
function base64url_encode($data) {
return rtrim(strtr(base64_encode($data), '+/', '-_'), '=');
function generateToken($secret) {
$header = base64url_encode('{
"typ": "JWT",
"alg": "HS512"
$payload = base64url_encode('{
"iat": '. time() .'
$signature = base64url_encode(hash_hmac('sha512', $header .'.'. $payload , $secret, true));
return $header . '.' . $payload . '.' . $signature;
function getInfo($baseUrl, $secret) {
$token = generateToken($secret);
$endpoint = rtrim($baseUrl, '/') . '/api/v1/info';
$headers = [
'Content-Type: text/plain; charset=UTF-8',
'Authorization: Bearer ' . $token,
$ch = curl_init($endpoint);
curl_setopt($ch, CURLOPT_HTTPHEADER, $headers);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_AUTOREFERER, 1);
curl_setopt($ch, CURLOPT_FRESH_CONNECT, 1);
$result = curl_exec($ch);
return $result;
var_dump(getInfo($baseUrl, $secret));
### Python
See the reference API client:
- [Documentation]( on ReadTheDocs
- [python-shaarli-client]( on Github

Feeds are available in ATOM with `?do=atom` and RSS with `do=RSS`.
- You can use `permalinks` in the feed URL to get permalink to Shaares instead of direct link to shaared URL.
- E.G. `https://my.shaarli.domain/?do=atom&permalinks`.
- You can use `nb` parameter in the feed URL to specify the number of Shaares you want in a feed (default if not specified: `50`). The keyword `all` is available if you want everything.
- `https://my.shaarli.domain/?do=atom&permalinks&nb=42`
- `https://my.shaarli.domain/?do=atom&permalinks&nb=all`
### RSS Feeds or Picture Wall for a specific search/tag
It is possible to filter RSS/ATOM feeds and Picture Wall on a Shaarli to **only display results of a specific search, or for a specific tag**.
For example, if you want to subscribe only to links tagged `photography`:
- Go to the desired Shaarli instance.
- Search for the `photography` tag in the _Filter by tag_ box. Links tagged `photography` are displayed.
- Click on the `RSS Feed` button.
- You are presented with an RSS feed showing only these links. Subscribe to it to receive only updates with this tag.
- The same method **also works for a full-text search** (_Search_ box) **and for the Picture Wall** (want to only see pictures about `nature`?)
- You can also build the URLs manually:
- `https://my.shaarli.domain/?do=rss&searchtags=nature`
- `https://my.shaarli.domain/links/?do=picwall&searchterm=poney`
![](images/rss-filter-1.png) ![](images/rss-filter-2.png)

## Prerequisites
This guide assumes that you have:
- a GPG key matching your GitHub authentication credentials
- i.e., the email address identified by the GPG key is the same as the one in your `~/.gitconfig`
- a GitHub fork of Shaarli
- a local clone of your Shaarli fork, with the following remotes:
- `origin` pointing to your GitHub fork
- `upstream` pointing to the main Shaarli repository
- The [venv]( Python 3 module needs to be installed for HTML documentation generation.
## GitHub release draft and ``
See for changelog formatting.
### GitHub release draft
GitHub allows drafting the release note for the upcoming release, from the [Releases]( page. This way, the release note can be drafted while contributions are merged to `master`.
### ``
This file should contain the same information as the release note draft for the upcoming version.
Update it to:
- add new entries (additions, fixes, etc.)
- mark the current version as released by setting its date and link
- add a new section for the future unreleased version
$ cd /path/to/shaarli
$ nano
## [vX.Y.Z]( - YYYY-MM-DD
## Increment the version code, update docs, create and push a signed tag
### Update the list of Git contributors
$ make authors
$ git commit -s -m "Update AUTHORS"
### Create and merge a Pull Request
This one is pretty straightforward ;-)
### Bump Shaarli version to v0.x branch
$ git checkout master
$ git fetch upstream
$ git pull upstream master
# IF the branch doesn't exists
$ git checkout -b v0.5
# OR if the branch already exists
$ git checkout v0.5
$ git rebase upstream/master
# Bump shaarli version from dev to 0.5.0, **without the `v`**
$ vim shaarli_version.php
$ git add shaarli_version
$ git commit -s -m "Bump Shaarli version to v0.5.0"
$ git push upstream v0.5
### Create and push a signed tag
# update your local copy
$ git checkout v0.5
$ git fetch upstream
$ git push --tags upstream
### Verify a signed tag
[`v0.5.0`]( is the first GPG-signed tag pushed on the Community Shaarli.
Let's have a look at its signature!
$ cd /path/to/shaarli
$ git fetch upstream
# get the SHA1 reference of the tag
$ git show-ref tags/v0.5.0
f7762cf803f03f5caf4b8078359a63783d0090c1 refs/tags/v0.5.0
# verify the tag signature information
$ git verify-tag f7762cf803f03f5caf4b8078359a63783d0090c1
gpg: Signature made Thu 30 Jul 2015 11:46:34 CEST using RSA key ID 4100DF6F
gpg: Good signature from "VirtualTam <>" [ultimate]
## Publish the GitHub release
### Update release badges
Update `` so version badges display and point to the newly released Shaarli version(s), in the `master` branch.
### Create a GitHub release from a Git tag
From the previously drafted release:
- edit the release notes (if needed)
- specify the appropriate Git tag
- publish the release
- profit!
### Generate and upload all-in-one release archives
Users with a shared hosting may have:
- no SSH access
- no possibility to install PHP packages or server extensions
- no possibility to run scripts
To ease Shaarli installations, it is possible to generate and upload additional release archives,
that will contain Shaarli code plus all required third-party libraries.
**From the `v0.5` branch:**
$ make release_archive
This will create the following archives:
- `shaarli-vX.Y.Z-full.tar`
- ``
The archives need to be manually uploaded on the previously created GitHub release.
### Update `stable` and `latest` branches
$ git checkout latest
# latest release
$ git merge v0.5.0
# fix eventual conflicts
$ make test
$ git push upstream latest
$ git checkout stable
# latest previous major
$ git merge v0.4.5
# fix eventual conflicts
$ make test
$ git push upstream stable

- Shaarli relies on `HTTP_REFERER` for some functions (like redirects and clicking on tags). If you have disabled or masqueraded `HTTP_REFERER` in your browser, some features of Shaarli may not work
## Server and sessions
- Directories are protected using `.htaccess` files
- Forms are protected against XSRF (Cross-site requests forgery):
- Forms which act on data (save,delete…) contain a token generated by the server.
- Any posted form which does not contain a valid token is rejected.
- Any token can only be used once.
- Tokens are attached to the session and cannot be reused in another session.
- Sessions automatically expire after 60 minutes.
- Sessions are protected against hijacking: the session ID cannot be used from a different IP address.
## Shaarli datastore and configuration
- The password is salted, hashed and stored in the data subdirectory, in a PHP file, and protected by htaccess. Even if the webserver does not support htaccess, the hash is not readable by URL. Even if the .php file is stolen, the password cannot deduced from the hash. The salt prevents rainbow-tables attacks.
- Links are stored as an associative array which is serialized, compressed (with deflate), base64-encoded and saved as a comment in a `.php` file.
- Even if the server does not support `.htaccess` files, the data file will still not be readable by URL.
- The database looks like this:
<?php /* zP1ZjxxJtiYIvvevEPJ2lDOaLrZv7o...
...ka7gaco/Z+TFXM2i7BlfMf8qxpaSSYfKlvqv/x8= */ ?>
- Small hashes are used to make a link to an entry in Shaarli. They are unique. In fact, the date of the items (eg. `20110923_150523`) is hashed with CRC32, then converted to base64 and some characters are replaced. They are always 6 characters longs and use only `A-Z a-z 0-9 - _` and `@`.

- [Nginx](#nginx)
## Prerequisites
### Shaarli
- Shaarli is installed in a directory readable/writeable by the user
- the correct read/write permissions have been granted to the web server _user and/or group_
- for HTTPS / SSL:
- a key pair (public, private) and a certificate have been generated
- the appropriate server SSL extension is installed and active
### HTTPS, TLS and self-signed certificates
Related guides:
- [How to Create Self-Signed SSL Certificates with OpenSSL](
- [How do I create my own Certificate Authority?](
- Generate a self-signed certificate (will trigger browser warnings) with apache2:
`make-ssl-cert generate-default-snakeoil --force-overwrite` will create `/etc/ssl/certs/ssl-cert-snakeoil.pem` and `/etc/ssl/private/ssl-cert-snakeoil.key`
### Proxies
If Shaarli is served behind a proxy (i.e. there is a proxy server between clients and the web server hosting Shaarli), please refer to the proxy server documentation for proper configuration. In particular, you have to ensure that the following server variables are properly set:
- `X-Forwarded-Proto`
- `X-Forwarded-Host`
- `X-Forwarded-For`
See also [proxy-related]( issues.
## Apache
### Minimal
<VirtualHost *:80>
DocumentRoot /absolute/path/to/shaarli/
### Debug - Log all the things!
This configuration will log both Apache and PHP errors, which may prove useful to identify server configuration errors.
- [Apache/PHP - error log per VirtualHost]( (StackOverflow)
- [PHP: php_value vs php_admin_value and the use of php_flag explained](
<VirtualHost *:80>
DocumentRoot /absolute/path/to/shaarli/
LogLevel warn
ErrorLog /var/log/apache2/shaarli-error.log
CustomLog /var/log/apache2/shaarli-access.log combined
php_flag log_errors on
php_flag display_errors on
php_value error_reporting 2147483647
php_value error_log /var/log/apache2/shaarli-php-error.log
### Standard - Keep access and error logs
<VirtualHost *:80>
DocumentRoot /absolute/path/to/shaarli/
LogLevel warn
ErrorLog /var/log/apache2/shaarli-error.log
CustomLog /var/log/apache2/shaarli-access.log combined
### Paranoid - Redirect HTTP (:80) to HTTPS (:443)
See [Server-side TLS]( (Mozilla).
<VirtualHost *:443>
DocumentRoot /absolute/path/to/shaarli/
SSLEngine on
SSLCertificateFile /absolute/path/to/the/website/certificate.pem
SSLCertificateKeyFile /absolute/path/to/the/website/key.key
<Directory /absolute/path/to/shaarli/>
AllowOverride All
Options Indexes FollowSymLinks MultiViews
Order allow,deny
allow from all
LogLevel warn
ErrorLog /var/log/apache2/shaarli-error.log
CustomLog /var/log/apache2/shaarli-access.log combined
<VirtualHost *:80>
Redirect 301 /
Shaarli use `.htaccess` Apache files to deny access to files that shouldn't be directly accessed (datastore, config, etc.). You need the directive `AllowOverride All` in your virtual host configuration for them to work.
**Warning**: If you use Apache 2.2 or lower, you need [mod_version]( to be installed and enabled.
Apache module `mod_rewrite` **must** be enabled to use the REST API. URL rewriting rules for the Slim microframework are stated in the root `.htaccess` file.
## LightHttpd
## Nginx
### Foreword
Nginx does not natively interpret PHP scripts; to this effect, we will run a [FastCGI]( service, to which Nginx's FastCGI module will proxy all requests to PHP resources.
Required packages:
- [nginx](
- [php-fpm]( - PHP FastCGI Process Manager
Official documentation:
- [Beginner's guide](
- [ngx_http_fastcgi_module](
- [Pitfalls](
Community resources:
- [Server-side TLS (Nginx)]( (Mozilla)
- [PHP configuration examples]( (Karl Blessing)
### Common setup
Once Nginx and PHP-FPM are installed, we need to ensure:
- Nginx and PHP-FPM are running using the _same user and group_
- both these user and group have
- `read` permissions for Shaarli resources
- `execute` permissions for Shaarli directories _AND_ their parent directories
On a production server:
- `user:group` will likely be `http:http`, `www:www` or `www-data:www-data`
- files will be located under `/var/www`, `/var/http` or `/usr/share/nginx`
On a development server:
- files may be located in a user's home directory
- in this case, make sure both Nginx and PHP-FPM are running as the local user/group!
For all following configuration examples, this user/group pair will be used:
- `user:group = john:users`,
which corresponds to the following service configuration:
; /etc/php/php-fpm.conf
user = john
group = users
listen.owner = john = users
# /etc/nginx/nginx.conf
user john users;
http {
### (Optional) Increase the maximum file upload size
Some bookmark dumps generated by web browsers can be _huge_ due to the presence of Base64-encoded images and favicons, as well as extra verbosity when nesting links in (sub-)folders.
To increase upload size, you will need to modify both nginx and PHP configuration:
# /etc/nginx/nginx.conf
http {
client_max_body_size 10m;
# /etc/php5/fpm/php.ini
post_max_size = 10M
upload_max_filesize = 10M
### Minimal
_WARNING: Use for development only!_
user john users;
worker_processes 1;
events {
worker_connections 1024;
http {
include mime.types;
default_type application/octet-stream;
keepalive_timeout 20;
index index.html index.php;
server {
listen 80;
server_name localhost;
root /home/john/web;
access_log /var/log/nginx/access.log;
error_log /var/log/nginx/error.log;
location /shaarli/ {
try_files $uri /shaarli/index.php$is_args$args;
access_log /var/log/nginx/shaarli.access.log;
error_log /var/log/nginx/shaarli.error.log;
location ~ (index)\.php$ {
try_files $uri =404;
fastcgi_split_path_info ^(.+\.php)(/.+)$;
fastcgi_pass unix:/var/run/php-fpm/php-fpm.sock;
fastcgi_index index.php;
include fastcgi.conf;
### Modular
The previous setup is sufficient for development purposes, but has several major caveats:
- every content that does not match the PHP rule will be sent to client browsers:
- dotfiles - in our case, `.htaccess`
- temporary files, e.g. Vim or Emacs files: `index.php~`
- asset / static resource caching is not optimized
- if serving several PHP sites, there will be a lot of duplication: `location /shaarli/`, `location /mysite/`, etc.
To solve this, we will split Nginx configuration in several parts, that will be included when needed:
# /etc/nginx/deny.conf
location ~ /\. {
# deny access to dotfiles
access_log off;
log_not_found off;
deny all;
location ~ ~$ {
# deny access to temp editor files, e.g. "script.php~"
access_log off;
log_not_found off;
deny all;
# /etc/nginx/php.conf
location ~ (index)\.php$ {
# Slim - split URL path into (script_filename, path_info)
try_files $uri =404;
fastcgi_split_path_info ^(.+\.php)(/.+)$;
# filter and proxy PHP requests to PHP-FPM
fastcgi_pass unix:/var/run/php-fpm/php-fpm.sock;
fastcgi_index index.php;
include fastcgi.conf;
location ~ \.php$ {
# deny access to all other PHP scripts
deny all;
# /etc/nginx/static_assets.conf
location ~* \.(?:ico|css|js|gif|jpe?g|png)$ {
expires max;
add_header Pragma public;
add_header Cache-Control "public, must-revalidate, proxy-revalidate";
# /etc/nginx/nginx.conf
http {
root /home/john/web;
access_log /var/log/nginx/access.log;
error_log /var/log/nginx/error.log;
server {
# virtual host for a first domain
listen 80;
location /shaarli/ {
# Slim - rewrite URLs
try_files $uri /shaarli/index.php$is_args$args;
access_log /var/log/nginx/shaarli.access.log;
error_log /var/log/nginx/shaarli.error.log;
location = /shaarli/favicon.ico {
# serve the Shaarli favicon from its custom location
alias /var/www/shaarli/images/favicon.ico;
include deny.conf;
include static_assets.conf;
include php.conf;
server {
# virtual host for a second domain
listen 80;
location /minigal/ {
access_log /var/log/nginx/minigal.access.log;
error_log /var/log/nginx/minigal.error.log;
include deny.conf;
include static_assets.conf;
include php.conf;
### Redirect HTTP to HTTPS
Assuming you have generated a (self-signed) key and certificate, and they are
located under `/home/john/ssl/localhost.{key,crt}`, it is pretty straightforward
to set an HTTP (:80) to HTTPS (:443) redirection to force SSL/TLS usage.
# /etc/nginx/nginx.conf
http {
index index.html index.php;
root /home/john/web;
access_log /var/log/nginx/access.log;
error_log /var/log/nginx/error.log;
server {
listen 80;
server_name localhost;
return 301 https://localhost$request_uri;
server {
listen 443 ssl;
server_name localhost;
ssl_certificate /home/john/ssl/localhost.crt;
ssl_certificate_key /home/john/ssl/localhost.key;
location /shaarli/ {
# Slim - rewrite URLs
try_files $uri /index.php$is_args$args;
access_log /var/log/nginx/shaarli.access.log;
error_log /var/log/nginx/shaarli.error.log;
location = /shaarli/favicon.ico {
# serve the Shaarli favicon from its custom location
alias /var/www/shaarli/images/favicon.ico;
include deny.conf;
include static_assets.conf;
include php.conf;

- [PHP: Supported versions](
- [PHP: Unsupported versions]( _(EOL - End Of Life)_
- [PHP 7 Changelog](
- [PHP 5 Changelog](
- [PHP: Bugs](
### Supported versions
Version | Status | Shaarli compatibility
7.1 | Supported (v0.9.x) | Yes
7.0 | Supported | Yes
5.6 | Supported | Yes
5.5 | EOL: 2016-07-10 | Yes
5.4 | EOL: 2015-09-14 | Yes (up to Shaarli 0.8.x)
5.3 | EOL: 2014-08-14 | Yes (up to Shaarli 0.8.x)
See also:
- [Travis configuration](
### Dependency management
Starting with Shaarli `v0.8.x`, [Composer]( is used to resolve,
download and install third-party PHP dependencies.
Library | Required? | Usage
[`shaarli/netscape-bookmark-parser`]( | All | Import bookmarks from Netscape files
[`erusev/parsedown`]( | All | Parse MarkDown syntax for the MarkDown plugin
[`slim/slim`]( | All | Handle routes and middleware for the REST API
### Extensions
Extension | Required? | Usage
[`openssl`]( | All | OpenSSL, HTTPS
[`php-mbstring`]( | CentOS, Fedora, RHEL, Windows | multibyte (Unicode) string support
[`php-gd`]( | optional | thumbnail resizing
[`php-intl`]( | optional | localized text sorting (e.g. `e->è->f`)
[`php-curl`]( | optional | using cURL for fetching webpages and thumbnails in a more robust way

PHP settings are defined in:
- a main configuration file, usually found under `/etc/php5/php.ini`; some distributions provide different configuration environments, e.g.
- `/etc/php5/php.ini` - used when running console scripts
- `/etc/php5/apache2/php.ini` - used when a client requests PHP resources from Apache
- `/etc/php5/php-fpm.conf` - used when PHP requests are proxied to PHP-FPM
- additional configuration files/entries, depending on the installed/enabled extensions:
- `/etc/php/conf.d/xdebug.ini`
### Locate .ini files
#### Console environment
$ php --ini
Configuration File (php.ini) Path: /etc/php
Loaded Configuration File: /etc/php/php.ini
Scan for additional .ini files in: /etc/php/conf.d
Additional .ini files parsed: /etc/php/conf.d/xdebug.ini
#### Server environment
- create a `phpinfo.php` script located in a path supported by the web server, e.g.
- Apache (with user dirs enabled): `/home/myself/public_html/phpinfo.php`
- `/var/www/test/phpinfo.php`
- make sure the script is readable by the web server user/group (usually, `www`, `www-data` or `httpd`)
- access the script from a web browser
- look at the _Loaded Configuration File_ and _Scan this dir for additional .ini files_ entries
<?php phpinfo(); ?>
## fail2ban
`fail2ban` is an intrusion prevention framework that reads server (Apache, SSH, etc.) and uses `iptables` profiles to block brute-force attempts:
- [Official website](
- [Source code](
### Read Shaarli logs to ban IPs
Example configuration:
- allow 3 login attempts per IP address
- after 3 failures, permanently ban the corresponding IP adddress
enabled = true
port = https,http
filter = shaarli-auth
logpath = /var/www/path/to/shaarli/data/log.txt
maxretry = 3
bantime = -1
before = common.conf
failregex = \s-\s<HOST>\s-\sLogin failed for user.*$
ignoreregex =
## Robots - Restricting search engines and web crawler traffic
Creating a `robots.txt` with the following contents at the root of your Shaarli installation will prevent _honest_ web crawlers from indexing each and every link and Daily page from a Shaarli instance, thus getting rid of a certain amount of unsollicited network traffic.
User-agent: *
Disallow: /

Once your Shaarli instance is installed, the file `data/config.json.php` is generated:
* it contains all settings in JSON format, and can be edited to customize values
* it defines which [plugins](Plugin-System) are enabled[](.html)
* its values override those defined in `index.php`
* it is wrap in a PHP comment to prevent anyone accessing it, regardless of server configuration
## File and directory permissions
The server process running Shaarli must have:
- `read` access to the following resources:
- PHP scripts: `index.php`, `application/*.php`, `plugins/*.php`
- 3rd party PHP and Javascript libraries: `inc/*.php`, `inc/*.js`
- static assets:
- CSS stylesheets: `inc/*.css`
- `images/*`
- RainTPL templates: `tpl/*.html`
- `read`, `write` and `execution` access to the following directories:
- `cache` - thumbnail cache
- `data` - link data store, configuration options
- `pagecache` - Atom/RSS feed cache
- `tmp` - RainTPL page cache
On a Linux distribution:
- the web server user will likely be `www` or `http` (for Apache2)
- it will be a member of a group of the same name: `www:www`, `http:http`
- to give it access to Shaarli, either:
- unzip Shaarli in the default web server location (usually `/var/www/`) and set the web server user as the owner
- put users in the same group as the web server, and set the appropriate access rights
- if you have a domain / subdomain to serve Shaarli, [configure the server](Server-configuration) accordingly[](.html)
## Configuration
In `data/config.json.php`.
See also [Plugin System](Plugin-System.html).
### Credentials
_These settings should not be edited_
- **login**: Login username.
- **hash**: Generated password hash.
- **salt**: Password salt.
### General
- **title**: Shaarli's instance title.
- **header_link**: Link to the homepage.
- **links_per_page**: Number of shaares displayed per page.
- **timezone**: See [the list of supported timezones](
- **enabled_plugins**: List of enabled plugins.
- **default_note_title**: Default title of a new note.
### Security
- **session_protection_disabled**: Disable session cookie hijacking protection (not recommended).
It might be useful if your IP adress often changes.
- **ban_after**: Failed login attempts before being IP banned.
- **ban_duration**: IP ban duration in seconds.
- **open_shaarli**: Anyone can add a new link while logged out if enabled.
- **trusted_proxies**: List of trusted IP which won't be banned after failed login attemps. Useful if Shaarli is behind a reverse proxy.
- **allowed_protocols**: List of allowed protocols in shaare URLs or markdown-rendered descriptions. Useful if you want to store `javascript:` links (bookmarklets) in Shaarli (default: `["ftp", "ftps", "magnet"]`).
### Resources
- **data_dir**: Data directory.
- **datastore**: Shaarli's links database file path.
- **history**: Shaarli's operation history file path.
- **updates**: File path for the ran updates file.
- **log**: Log file path.
- **update_check**: Last update check file path.
- **raintpl_tpl**: Templates directory.
- **raintpl_tmp**: Template engine cache directory.
- **thumbnails_cache**: Thumbnails cache directory.
- **page_cache**: Shaarli's internal cache directory.
- **ban_file**: Banned IP file path.
### Updates
- **check_updates**: Enable or disable update check to the git repository.
- **check_updates_branch**: Git branch used to check updates (e.g. `stable` or `master`).
- **check_updates_interval**: Look for new version every N seconds (default: every day).
### Privacy
- **default_private_links**: Check the private checkbox by default for every new link.
- **hide_public_links**: All links are hidden while logged out.
- **force_login**: if **hide_public_links** and this are set to `true`, all anonymous users are redirected to the login page.
- **hide_timestamps**: Timestamps are hidden.
- **remember_user_default**: Default state of the login page's *remember me* checkbox
- `true`: checked by default, `false`: unchecked by default
### Feed
- **rss_permalinks**: Enable this to redirect RSS links to Shaarli's permalinks instead of shaared URL.
- **show_atom**: Display ATOM feed button.
### Thumbnail
- **enable_thumbnails**: Enable or disable thumbnail display.
- **enable_localcache**: Enable or disable local cache.
### Redirector
- **url**: Redirector URL, such as ``.
- **encode_url**: Enable this if the redirector needs encoded URL to work properly.
## Configuration file example
<?php /*
"credentials": {
"login": "<login>",
"hash": "<password hash>",
"salt": "<password salt>"
"security": {
"ban_after": 4,
"session_protection_disabled": false,
"ban_duration": 1800,
"trusted_proxies": [
"allowed_protocols": [
"resources": {
"data_dir": "data",
"config": "data\/config.php",
"datastore": "data\/datastore.php",
"ban_file": "data\/ipbans.php",
"updates": "data\/updates.txt",
"log": "data\/log.txt",
"update_check": "data\/lastupdatecheck.txt",
"raintpl_tmp": "tmp\/",
"raintpl_tpl": "tpl\/",
"thumbnails_cache": "cache",
"page_cache": "pagecache"
"general": {
"check_updates": true,
"rss_permalinks": true,
"links_per_page": 20,
"default_private_links": true,
"enable_thumbnails": true,
"enable_localcache": true,
"check_updates_branch": "stable",
"check_updates_interval": 86400,
"enabled_plugins": [
"timezone": "Europe\/Paris",
"title": "My Shaarli",
"header_link": "?"
"extras": {
"show_atom": false,
"hide_public_links": false,
"hide_timestamps": false,
"open_shaarli": false,
"redirector": "",
"redirector_encode_url": false
"general": {
"header_link": "?",
"links_per_page": 20,
"enabled_plugins": [
"timezone": "Europe\/Paris",
"title": "My Shaarli"
"updates": {
"check_updates": true,
"check_updates_branch": "stable",
"check_updates_interval": 86400
"feed": {
"rss_permalinks": true,
"show_atom": false
"privacy": {
"default_private_links": true,
"hide_public_links": false,
"force_login": false,
"hide_timestamps": false,
"remember_user_default": true
"thumbnail": {
"enable_thumbnails": true,
"enable_localcache": true
"redirector": {
"url": "",
"encode_url": false
"plugins": {
} ?>
## Additional configuration
The `playvideos` plugin may require that you adapt your server's
[Content Security Policy](
configuration to work properly.

This topic is currently being discussed here:
- [Fix coding style (static analysis)]( (#95)
- [Continuous Integration tools & features]( (#130)
### Usage
Static analysis tools can be installed with Composer, and used through Shaarli's [Makefile](
For an overview of the available features, see:
- [Code quality: Makefile to run static code checkers]( (#124)
- [Run PHPCS against different coding standards]( (#276)

There are two ways of customizing how Shaarli looks:
1. by using a custom CSS to override Shaarli's CSS
2. by using a full theme that provides its own RainTPL templates, CSS and Javascript resources
## Custom CSS
Shaarli's appearance can be modified by adding CSS rules to:
- Shaarli < `v0.9.0`: `inc/user.css`
- Shaarli >= `v0.9.0`: `data/user.css`
This file allows overriding rules defined in the template CSS files (only add changed rules), or define a whole new theme.
**Note**: Do not edit `tpl/default/css/shaarli.css`! Your changes would be overridden when updating Shaarli.
See also [Download CSS styles from an OPML list](Download CSS styles from an OPML list)
## Themes
- find a theme you'd like to install
- copy or clone the theme folder under `tpl/<a_sweet_theme>`
- enable the theme:
- Shaarli < `v0.9.0`: edit `data/config.json.php` and set the value of `raintpl_tpl` to the new theme name:
`"raintpl_tpl": "tpl\/my-template\/"`
- Shaarli >= `v0.9.0`: select the theme through the _Tools_ page
## Community CSS & themes
### Custom CSS
- [mrjovanovic/serious-theme-shaarli]( - A serious theme for Shaarli
- [shaarli/shaarli-themes](
### Themes
- [AkibaTech/Shaarli Superhero Theme]( - A template/theme for Shaarli
- [alexisju/albinomouse-template]( - A full template for Shaarli
- [ArthurHoaro/shaarli-launch]( - Customizable Shaarli theme
- [dhoko/ShaarliTemplate]( - A template/theme for Shaarli
- [kalvn/shaarli-blocks]( - A template/theme for Shaarli
- [kalvn/Shaarli-Material]( - A theme (template) based on Google's Material Design for Shaarli, the superfast delicious clone
- [ManufacturaInd/shaarli-2004licious-theme]( - A template/theme as a humble homage to the early looks of the site
### Shaarli forks
- [misterair/Limonade]( - A fork of (legacy) Shaarli with a new template
- [vivienhaese/shaarlitheme]( - A Shaarli fork meant to be run in an openshift instance
## Example installation: AlbinoMouse theme
With the following configuration:
- Apache 2 / PHP 5.6
- user sites are enabled, e.g. `/home/user/public_html/somedir` is served as `http://localhost/~user/somedir`
- `http` is the name of the Apache user
$ cd ~/public_html
# clone repositories
$ git clone shaarli
$ pushd shaarli/tpl
$ git clone
$ popd
# set access rights for Apache
$ chgrp -R http shaarli
$ chmod g+rwx shaarli shaarli/cache shaarli/data shaarli/pagecache shaarli/tmp
Get config written:
- go to the freshly installed site
- fill the install form
- log in to Shaarli
Edit Shaarli's [configuration](Shaarli-configuration):
# the file should be owned by Apache, thus not writeable => sudo
$ sudo sed -i s=tpl=tpl/albinomouse-template=g shaarli/data/config.php

## Browser
### Redirection issues (HTTP Referer)
Depending on its configuration and installed plugins, the browser may remove or alter (spoof) HTTP referers, thus preventing Shaarli from properly redirecting between pages.
- [HTTP referer]( (Wikipedia)
- [Improve online privacy by controlling referrer information](
- [Better security, privacy and anonymity in Firefox](
### Firefox HTTP Referer options
HTTP settings are available by browsing `about:config`, here are the available settings and their values.
`network.http.sendRefererHeader` - determines when to send the Referer HTTP header
- `0`: Never send the referring URL
- not recommended, may break some sites
- `1`: Send only on clicked links
- `2` (default): Send for links and images
`network.http.referer.XOriginPolicy` - Cross-domain origin policy
- `0` (default): Always send
- `1`: Send if base domains match
- `2`: Send if hosts match
`network.http.referer.spoofSource` - Referer spoofing (~faking)
- `false` (default): real referer
- `true`: spoof referer (use target URI as referer)
- known to break some functionality in Shaarli
`network.http.referer.trimmingPolicy` - trim the URI not to send a full Referer
- `0`: (default): send full URI
- `1`: scheme+host+port+path
- `2`: scheme+host+port
### Firefox, localhost and redirections
`localhost` is not a proper Fully Qualified Domain Name (FQDN); if Firefox has
been set up to spoof referers, or only accept requests from the same base domain/host,
Shaarli redirections will not work properly.
To solve this, assign a local domain to your host, e.g.
``` localhost desktop localhost.lan
::1 localhost desktop localhost.lan
and browse Shaarli at http://localhost.lan/.
Related threads:
- [What is localhost.localdomain for?](
- [Stop returning to the first page after editing a bookmark from another page](
## Login
### I forgot my password!
Delete the file `data/config.php` and display the page again. You will be asked for a new login/password.
### I'm locked out - Login bruteforce protection
Login form is protected against brute force attacks: 4 failed logins will ban the IP address from login for 30 minutes. Banned IPs can still browse links.
To remove the current IP bans, delete the file `data/ipbans.php`
### List of all login attempts
The file `data/log.txt` shows all logins (successful or failed) and bans/lifted bans.
Search for `failed` in this file to look for unauthorized login attempts.
## Hosting problems
### Old PHP versions
On ****: now supports php 5.6.x([link](
and so support now the tag autocompletion but you have to do the following.
At the root of your webspace create a `sessions` directory and a `.htaccess` file containing:
<IfDefine Free>
php56 1
- If you have an error such as: `Parse error: syntax error, unexpected '=', expecting '(' in /links/index.php on line xxx`, it means that your host is using php4, not php5. Shaarli requires php 5.1. Try changing the file extension to `.php5`
- On **1and1** : If you add the link from the page (and not from the bookmarklet), Shaarli will no be able to get the title of the page. You will have to enter it manually. (Because they have disabled the ability to download a file through HTTP).
- If you have the error `Warning: file_get_contents() [function.file-get-contents]: URL file-access is disabled in the server configuration in /…/index.php on line xxx`, it means that your host has disabled the ability to fetch a file by HTTP in the php config (Typically in 1and1 hosting). Bad host. Change host. Or comment the following lines:
//list($status,$headers,$data) = getHTTP($url,4); // Short timeout to keep the application responsive.
// FIXME: Decode charset according to charset specified in either 1) HTTP response headers or 2) <head> in html
//if (strpos($status,'200 OK')) $title=html_extract_title($data);
- On hosts which forbid outgoing HTTP requests (such as, some thumbnails will not work.
- On **lost-oasis**, RSS doesn't work correctly, because of this message at the begining of the RSS/ATOM feed : `<? // tout ce qui est charge ici (generalement des includes et require) est charge en permanence. ?>`. To fix this, remove this message from `php-include/prepend.php`
### Dates are not properly formatted
Shaarli tries to sniff the language of the browser (using HTTP_ACCEPT_LANGUAGE headers) and choose a date format accordingly. But Shaarli can only use the date formats (and more generaly speaking, the locales) provided by the webserver. So even if you have a browser in French, you may end up with dates in US format (it's the case on :-( )
### Problems on CentOS servers
On **CentOS**/RedHat derivatives, you may need to install the `php-mbstring` package.
### My session expires! I can't stay logged in
This can be caused by several things:
- Your php installation may not have a proper directory setup for session files. (eg. on you need to create a `session` directory on the root of your website.) You may need to create the session directory of set it up.
- Most hosts regularly clean the temporary and session directories. Your host may be cleaning those directories too aggressively (eg.OVH hosts), forcing an expire of the session. You may want to set the session directory in your web root. (eg. Create the `sessions` subdirectory and add `ini_set('session.save_path', $_SERVER['DOCUMENT_ROOT'].'/../sessions');`. Make sure this directory is not browsable !)
- If your IP address changes during surfing, Shaarli will force expire your session for security reasons (to prevent session cookie hijacking). This can happen when surfing from WiFi or 3G (you may have switched WiFi/3G access point), or in some corporate/university proxies which use load balancing (and may have proxies with several external IP addresses).
- Some browser addons may interfer with HTTP headers (ipfuck/ipflood/GreaseMonkey…). Try disabling those.
- You may be using OperaTurbo or OperaMini, which use their own proxies which may change from time to time.
- If you have another application on the same webserver where Shaarli is installed, these application may forcefully expire php sessions.
## Sessions do not seem to work correctly on your server
Follow the instructions in the error message. Make sure you are accessing shaarli via a direct IP address or a proper hostname. If you have **no dots** in the hostname (e.g. `localhost` or `http://my-webserver/shaarli/`), some browsers will not store cookies at all (this respects the [HTTP cookie specification](
### pubsubhubbub support
Download [publisher.php]( at the root of your Shaarli installation and set `$GLOBALS['config']['PUBSUBHUB_URL']` in your `config.php`

- [Docker 101](docker/
- [Docker resources](docker/
- [Unit tests](
### Docker test images
Test Dockerfiles are located under `docker/tests/<distribution>/Dockerfile`,
and can be used to build Docker images to run Shaarli test suites under common
Linux environments.
Dockerfiles are provided for the following environments:
- `alpine36` - [Alpine 3.6](
- `debian8` - [Debian 8 Jessie]( (oldstable)
- `debian9` - [Debian 9 Stretch]( (stable)
- `ubuntu16` - [Ubuntu 16.04 Xenial Xerus]( (LTS)
What's behind the curtains:
- each image provides:
- a base Linux OS
- Shaarli PHP dependencies (OS packages)
- test PHP dependencies (OS packages)
- Composer
- the local workspace is mapped to the container's `/shaarli/` directory,
- the files are rsync'd to so tests are run using a standard Linux user account
(running tests as `root` would bypass permission checks and may hide issues)
- the tests are run inside the container.
### Building test images
# build the Debian 9 Docker image
$ cd /path/to/shaarli
$ cd docker/test/debian9
$ docker build -t shaarli-test:debian9 .
### Running tests
$ cd /path/to/shaarli
# install/update 3rd-party test dependencies
$ composer install --prefer-dist
# run tests using the freshly built image
$ docker run -v $PWD:/shaarli shaarli-test:debian9 docker_test
# run the full test campaign
$ docker run -v $PWD:/shaarli shaarli-test:debian9 docker_all_tests

The framework used is [PHPUnit](; it can be installed with [Composer](, which is a dependency management tool.
Regarding Composer, you can either use:
- a system-wide version, e.g. installed through your distro's package manager
- a local version, downloadable [here](
#### Sample usage
# system-wide version
$ composer install
$ composer update
# local version
$ php composer.phar self-update
$ php composer.phar install
$ php composer.phar update
#### Install Shaarli dev dependencies
$ cd /path/to/shaarli
$ composer update
#### Install and enable Xdebug to generate PHPUnit coverage reports
For Debian-based distros:
$ aptitude install php5-xdebug
For ArchLinux:
$ pacman -S xdebug
Then add the following line to `/etc/php/php.ini`:
#### Run unit tests
Successful test suite:
$ make test
PHPUnit 4.6.9 by Sebastian Bergmann and contributors.
Configuration read from /home/virtualtam/public_html/shaarli/phpunit.xml
Time: 759 ms, Memory: 8.25Mb
OK (36 tests, 65 assertions)
Test suite with failures and errors:
$ make test
PHPUnit 4.6.9 by Sebastian Bergmann and contributors.
Configuration read from /home/virtualtam/public_html/shaarli/phpunit.xml
Time: 802 ms, Memory: 8.25Mb
There was 1 error:
1) LinkDBTest::testConstructLoggedIn
Missing argument 2 for LinkDB::__construct(), called in /home/virtualtam/public_html/shaarli/tests/Link\
DBTest.php on line 79 and defined
There were 2 failures:
1) LinkDBTest::testCheckDBNew
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
2) LinkDBTest::testCheckDBLoad
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
Tests: 36, Assertions: 63, Errors: 1, Failures: 2.
#### Test results and coverage
By default, PHPUnit will run all suitable tests found under the `tests` directory.
Each test has 3 possible outcomes:
- `.` - success
- `F` - failure: the test was run but its results are invalid
- the code does not behave as expected
- dependencies to external elements: globals, session, cache...
- `E` - error: something went wrong and the tested code has crashed
- typos in the code, or in the test code
- dependencies to missing external elements
If Xdebug has been installed and activated, two coverage reports will be generated:
- a summary in the console
- a detailed HTML report with metrics for tested code
- to open it in a web browser: `firefox coverage/index.html &`
### Executing specific tests
To run all tests annotated with `@group WIP`:
$ vendor/bin/phpunit --group WIP tests/

View File

@ -0,0 +1,197 @@
## Preparation
### Note your current version
If anything goes wrong, it's important for us to know which version you're upgrading from.
The current version is present in the `version.php` file.
### Backup your data
Shaarli stores all user data under the `data` directory:
- `data/config.php` - main configuration file
- `data/datastore.php` - bookmarked links
- `data/ipbans.php` - banned IP addresses
- `data/updates.txt` - contains all automatic update to the configuration and datastore files already run
See [Shaarli configuration](Shaarli configuration) for more information about Shaarli resources.
It is recommended to backup this repository _before_ starting updating/upgrading Shaarli:
- users with SSH access: copy or archive the directory to a temporary location
- users with FTP access: download a local copy of your Shaarli installation using your favourite client
### Migrating data from a previous installation
As all user data is kept under `data`, this is the only directory you need to worry about when migrating to a new installation, which corresponds to the following steps:
- backup the `data` directory
- install or update Shaarli:
- fresh installation - see [Download and installation](Download and installation)
- update - see the following sections
- check or restore the `data` directory
## Recommended : Upgrading from release archives
All tagged revisions can be downloaded as tarballs or ZIP archives from the [releases]( page.
We recommend that you use the latest release tarball with the `-full` suffix. It contains the dependencies, please read [Download and installation](Download and installation) for `git` complete instructions.
Once downloaded, extract the archive locally and update your remote installation (e.g. via FTP) -be sure you keep the content of the `data` directory!
After upgrading, access your fresh Shaarli installation from a web browser; the configuration and data store will then be automatically updated, and new settings added to `data/config.json.php` (see [Shaarli configuration](Shaarli configuration) for more details).
## Upgrading with Git
### Updating a community Shaarli
If you have installed Shaarli from the [community Git repository](Download#clone-with-git-recommended), simply [pull new changes]( from your local clone:
$ cd /path/to/shaarli
$ git pull
* branch master -> FETCH_HEAD
Updating ebd67c6..521f0e6
application/Url.php | 1 +
shaarli_version.php | 2 +-
tests/Url/UrlTest.php | 1 +
3 files changed, 3 insertions(+), 1 deletion(-)
Shaarli >= `v0.8.x`: install/update third-party PHP dependencies using [Composer](
$ composer install --no-dev
Loading composer repositories with package information
Updating dependencies
- Installing shaarli/netscape-bookmark-parser (v1.0.1)
Downloading: 100%
### Migrating and upgrading from Sebsauvage's repository
If you have installed Shaarli from [Sebsauvage's original Git repository](, you can use [Git remotes]( to update your working copy.
The following guide assumes that:
- you have a basic knowledge of Git [branching]( and [remote repositories](
- the default remote is named `origin` and points to Sebsauvage's repository
- the current branch is `master`
- if you have personal branches containing customizations, you will need to [rebase them]( after the upgrade; beware though, a lot of changes have been made since the community fork has been created, so things are very likely to break!
- the working copy is clean:
- no versioned file has been locally modified
- no untracked files are present
#### Step 0: show repository information
$ cd /path/to/shaarli
$ git remote -v
origin (fetch)
origin (push)
$ git branch -vv
* master 029f75f [origin/master] Update
$ git status
On branch master
Your branch is up-to-date with 'origin/master'.
nothing to commit, working directory clean
#### Step 1: update Git remotes
$ git remote rename origin sebsauvage
$ git remote -v
sebsauvage (fetch)
sebsauvage (push)
$ git remote add origin
$ git fetch origin
remote: Counting objects: 3015, done.
remote: Compressing objects: 100% (19/19), done.
remote: Total 3015 (delta 446), reused 457 (delta 446), pack-reused 2550
Receiving objects: 100% (3015/3015), 2.59 MiB | 918.00 KiB/s, done.
Resolving deltas: 100% (1899/1899), completed with 48 local objects.
* [new branch] master -> origin/master
* [new branch] stable -> origin/stable
* [new tag] v0.6.4 -> v0.6.4
* [new tag] v0.7.0 -> v0.7.0
#### Step 2: use the stable community branch
$ git checkout origin/stable -b stable
Branch stable set up to track remote branch stable from origin.
Switched to a new branch 'stable'
$ git branch -vv
master 029f75f [sebsauvage/master] Update
* stable 890afc3 [origin/stable] Merge pull request #509 from ArthurHoaro/v0.6.5
Shaarli >= `v0.8.x`: install/update third-party PHP dependencies using [Composer](
$ composer install --no-dev
Loading composer repositories with package information
Updating dependencies
- Installing shaarli/netscape-bookmark-parser (v1.0.1)
Downloading: 100%
Optionally, you can delete information related to the legacy version:
$ git branch -D master
Deleted branch master (was 029f75f).
$ git remote remove sebsauvage
$ git remote -v
origin (fetch)
origin (push)
$ git gc
Counting objects: 3317, done.
Delta compression using up to 8 threads.
Compressing objects: 100% (1237/1237), done.
Writing objects: 100% (3317/3317), done.
Total 3317 (delta 2050), reused 3301 (delta 2034)to
#### Step 3: configuration
After migrating, access your fresh Shaarli installation from a web browser; the configuration will then be automatically updated, and new settings added to `data/config.php` (see [Shaarli configuration](Shaarli configuration) for more details).
## Troubleshooting
If the solutions provided here don't work, please open an issue specifying which version you're upgrading from and to.
### You must specify an integer as a key
In `v0.8.1` we changed how link keys are handled (from timestamps to incremental integers).
Take a look at `data/updates.txt` content.
#### `updates.txt` contains `updateMethodDatastoreIds`
Try to delete it and refresh your page while being logged in.
#### `updates.txt` doesn't exist or doesn't contain `updateMethodDatastoreIds`
1. Create `data/updates.txt` if it doesn't exist
2. Paste this string in the update file `;updateMethodRenameDashTags;`
3. Login to Shaarli
4. Delete the update file
5. Refresh

To display the array representing the data saved in `data/datastore.php`, use the following snippet:
$data = "tZNdb9MwFIb... <Commented content inside datastore.php>";
$out = unserialize(gzinflate(base64_decode($data)));
echo "<pre>"; // Pretty printing is love, pretty printing is life
echo "</pre>";
This will output the internal representation of the datastore, "unobfuscated" (if this can really be considered obfuscation).
Alternatively, you can transform to JSON format (and pretty-print if you have `jq` installed):
php -r 'print(json_encode(unserialize(gzinflate(base64_decode(preg_replace("!.*/\* (.+) \*/.*!", "$1", file_get_contents("data/datastore.php")))))));' | jq .
### Changing the timestamp for a shaare
- Look for `<input type="hidden" name="lf_linkdate" value="{$link.linkdate}">` in `tpl/editlink.tpl` (line 14)
- Replace `type="hidden"` with `type="text"` from this line
- A new date/time field becomes available in the edit/new link dialog.
- You can set the timestamp manually by entering it in the format `YYYMMDD_HHMMS`.
### See also
- [Add a new custom field to shaares (example patch)](
- [Download CSS styles for shaarlis listed in an opml file](
- [Copy an existing Shaarli installation over SSH, and serve it locally](
- [Create multiple Shaarli instances, generate an HTML index of them](

The `master` branch is the development branch. Any new change MUST go through this branch using Pull Requests.
- This branch shouldn't be used for production as it isn't necessary stable.
- 3rd party aren't required to be compatible with the latest changes.
- Official plugins, themes and libraries (contained within Shaarli organization repos) must be compatible with the master branch.
- The version in this branch is always `dev`.
## `v0.x` branch
This `v0.x` branch, points to the latest `v0.x.y` release.
When a new version is released, it might contains a major bug which isn't detected right away. For example, a new PHP version is released, containing backward compatibility issue which doesn't work with Shaarli.
In this case, the issue is fixed in the `master` branch, and the fix is backported the to the `v0.x` branch. Then a new release is made from the `v0.x` branch.
This workflow allow us to fix any major bug detected, without having to release bleeding edge feature too soon.
## `latest` branch
This branch point the latest release. It recommended to use it to get the latest tested changes.
## `stable` branch
The `stable` branch doesn't contain any major bug, and is one major digit version behind the latest release.
For example, the current latest release is `v0.8.3`, the stable branch is an alias to the latest `v0.7.x` release. When the `v0.9.0` version will be released, the stable will move to the latest `v0.8.x` release.
- Shaarli release pace isn't fast, and the stable branch might be a few months behind the latest release.
## Releases
Releases are always made from the latest `v0.x` branch.
Note that for every release, we manually generate a tarball which contains all Shaarli dependencies, making Shaarli's installation only one step.
## Advices on 3rd party git repos workflow
### Versioning
Any time a new Shaarli release is published, you should publish a new release of your repo if the changes affected you since the latest release (take a look at the [changelog]( (*Draft* means not released yet) and the commit log (like [`tpl` folder]( for themes)). You can either:
- use the Shaarli version number, with your repo version. For example, if Shaarli `v0.8.3` is released, publish a `v0.8.3-1` release, where `v0.8.3` states Shaarli compatibility and `-1` is your own version digit for the current Shaarli version.
- use your own versioning scheme, and state Shaarli compatibility in the release description.
Using this, any user will be able to pick the release matching his own Shaarli version.
### Major bugfix backport releases
To be able to support backported fixes, it recommended to use our workflow:
# In master, fix the major bug
git commit -m "Katastrophe"
git push origin master
# Get your commit hash
git log --format="%H" -n 1
# Create a new branch from your latest release, let's say v0.8.2-1 (the tag name)
git checkout -b katastrophe v0.8.2-1
# Backport the fix commit to your brand new branch
git cherry-pick <fix commit hash>
git push origin katastrophe
# Then you just have to make a new release from the `katastrophe` branch tagged `v0.8.3-1`

Install [Docker](, by following the instructions relevant
to your OS / distribution, and start the service.
### Search an image on [DockerHub](
$ docker search debian
ubuntu Ubuntu is a Debian-based Linux operating s... 2065 [OK]
debian Debian is a Linux distribution that's comp... 603 [OK]
google/debian 47 [OK]
### Show available tags for a repository
$ curl | python -m json.tool
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 1283 0 1283 0 0 433 0 --:--:-- 0:00:02 --:--:-- 433
Sample output:
"layer": "85a02782",
"name": "stretch"
"layer": "59abecbc",
"name": "testing"
"layer": "bf0fd686",
"name": "unstable"
"layer": "60c52dbe",
"name": "wheezy"
"layer": "c5b806fe",
"name": "wheezy-backports"
### Pull an image from DockerHub
$ docker pull repository[:tag]
$ docker pull debian:wheezy
wheezy: Pulling from debian
4c8cbfd2973e: Pull complete
60c52dbe9d91: Pull complete
Digest: sha256:c584131da2ac1948aa3e66468a4424b6aea2f33acba7cec0b631bdb56254c4fe
Status: Downloaded newer image for debian:wheezy
Docker re-uses layers already downloaded. In other words if you have images based on Alpine or some Ubuntu version for example, those can share disk space.
### Start a container
A container is an instance created from an image, that can be run and that keeps running until its main process exits. Or until the user stops the container.
The simplest way to start a container from image is ``docker run``. It also pulls the image for you if it is not locally available. For more advanced use, refer to ``docker create``.
Stopped containers are not destroyed, unless you specify ``--rm``. To view all created, running and stopped containers, enter:
$ docker ps -a
Some containers may be designed or configured to be restarted, others are not. Also remember both network ports and volumes of a container are created on start, and not editable later.
### Access a running container
A running container is accessible using ``docker exec``, or ``docker copy``. You can use ``exec`` to start a root shell in the Shaarli container:
$ docker exec -ti <container-name-or-id> bash
Note the names and ID's of containers are listed in ``docker ps``. You can even type only one or two letters of the ID, given they are unique.
Access can also be through one or more network ports, or disk volumes. Both are specified on and fixed on ``docker create`` or ``run``.
You can view the console output of the main container process too:
$ docker logs -f <container-name-or-id>
### Docker disk use
Trying out different images can fill some gigabytes of disk quickly. Besides images, the docker volumes usually take up most disk space.
If you care only about trying out docker and not about what is running or saved, the following commands should help you out quickly if you run low on disk space:
$ docker rmi -f $(docker images -aq) # remove or mark all images for disposal
$ docker volume rm $(docker volume ls -q) # remove all volumes
### Systemd config
Systemd is the process manager of choice on Debian-based distributions. Once you have a ``docker`` service installed, you can use the following steps to set up Shaarli to run on system start.
systemctl enable /etc/systemd/system/docker.shaarli.service
systemctl start docker.shaarli
systemctl status docker.*
journalctl -f # inspect system log if needed
You will need sudo or a root terminal to perform some or all of the steps above. Here are the contents for the service file:
Description=Shaarli Bookmark Manager Container
# Put any environment you want in an included file, like $host- or $domainname in this example
# It's just an example..
ExecStart=/usr/bin/docker run \
-p 28010:80 \
--name ${hostname}-shaarli \
--hostname shaarli.${domainname} \
-v /srv/docker-volumes-local/shaarli-data:/var/www/shaarli/data:rw \
-v /etc/localtime:/etc/localtime:ro \
ExecStop=/usr/bin/docker rm -f ${hostname}-shaarli

- [Where are Docker images stored?](
- [Dockerfile reference](
- [Dockerfile best practices](
- [Volumes](
### DockerHub
- [Repositories](
- [Teams and organizations](
- [GitHub automated build](
### Service management
- [Using supervisord](
- [Nginx in the foreground](
- [supervisord](

## Nginx

View File

@ -0,0 +1,71 @@
## Get and run a Shaarli image
### DockerHub repository
The images can be found in the [`shaarli/shaarli`](
### Available image tags
- `latest`: master branch (tarball release)
- `stable`: stable branch (tarball release)
All images rely on:
- [Debian 8 Jessie](
- [PHP5-FPM](
- [Nginx](
### Download from DockerHub
$ docker pull shaarli/shaarli
latest: Pulling from shaarli/shaarli
32716d9fcddb: Pull complete
84899d045435: Pull complete
4b6ad7444763: Pull complete
e0345ef7a3e0: Pull complete
5c1dd344094f: Pull complete
6422305a200b: Pull complete
7d63f861dbef: Pull complete
3eb97210645c: Pull complete
869319d746ff: Already exists
869319d746ff: Pulling fs layer
902b87aaaec9: Already exists
Digest: sha256:f836b4627b958b3f83f59c332f22f02fcd495ace3056f2be2c4912bd8704cc98
Status: Downloaded newer image for shaarli/shaarli:latest
### Create and start a new container from the image
# map the host's :8000 port to the container's :80 port
$ docker create -p 8000:80 shaarli/shaarli
# launch the container in the background
$ docker start d40b7af693d678958adedfb88f87d6ea0237186c23de5c4102a55a8fcb499101
# list active containers
$ docker ps
d40b7af693d6 shaarli/shaarli /usr/bin/supervisor 15 seconds ago Up 4 seconds>80/tcp backstabbing_galileo
### Stop and destroy a container
$ docker stop backstabbing_galileo # those docker guys are really rude to physicists!
# check the container is stopped
$ docker ps
# list ALL containers
$ docker ps -a
d40b7af693d6 shaarli/shaarli /usr/bin/supervisor 5 minutes ago Exited (0) 48 seconds ago backstabbing_galileo
# destroy the container
$ docker rm backstabbing_galileo # let's put an end to these barbarian practices
$ docker ps -a

Width:  |  Height:  |  Size: 19 KiB

doc/md/images/doc-logo.svg Normal file
Binary file not shown.


Width:  |  Height:  |  Size: 757 B

Binary file not shown.


Width:  |  Height:  |  Size: 18 KiB

Binary file not shown.


Width:  |  Height:  |  Size: 15 KiB

doc/md/ Normal file
For general info, read the [README](
If you have any questions or ideas, please join the [chat]( (also reachable via [IRC](, post them in our [general discussion]( or read the current [issues](
If you've found a bug, please create a [new issue](
If you would like a feature added to Shaarli, check the issues labeled [`feature`](, [`enhancement`](, and [`plugin`](
_Note: This documentation is available online at, and locally in the `doc/html/` directory of your Shaarli installation._
[![Join the chat at](](
[![Docker repository](](
### Demo
You can use this [public demo instance of Shaarli](
It runs the latest development version of Shaarli and is updated/reset daily.
Login: `demo`; Password: `demo`
Docker users can start a personal instance from an [autobuild image]( For example to start a temporary Shaarli at ``localhost:8000``, and keep session data (config, storage):
MY_SHAARLI_VOLUME=$(cd /path/to/shaarli/data/ && pwd -P)
docker run -ti --rm \
-p 8000:80 \
-v $MY_SHAARLI_VOLUME:/var/www/shaarli/data \
A brief guide on getting starting using docker is given in [Docker 101](docker/docker-101).
To learn more about user data and how to keep it across versions, please see [Upgrade and Migration](Upgrade-and-migration) documentation.
## Features
### Interface
- minimalist design (simple is beautiful)
- ATOM and RSS feeds
- views:
- paginated link list
- tag cloud
- picture wall: image and video thumbnails
- daily: newspaper-like daily digest
- daily RSS feed
- permalinks for easy reference
- links can be public or private
- extensible through [plugins](
### Tag, view and search your links!
- add a custom title and description to archived links
- add tags to classify and search links
- features tag autocompletion, renaming, merging and deletion
- full-text and tag search
### Easy setup
- dead-simple installation: drop the files, open the page
- links are stored in a file
- compact storage
- no database required
- easy backup: simply copy the datastore file
- import and export links as Netscape bookmarks
### Accessibility
- Firefox bookmarlet to share links in one click
- support for mobile browsers
- works with Javascript disabled
- easy page customization through HTML/CSS/RainTPL
### Security
- bruteforce-proof login form
- protected against [XSRF](
and session cookie hijacking
### Goodies
- thumbnail generation for images and video services:
dailymotion, flickr, imageshack, imgur, vimeo, xkcd, youtube...
- lazy-loading with [bLazy](
- [PubSubHubbub]( protocol support
- URL cleanup: automatic removal of `?utm_source=...`, `fb=...`
- discreet pop-up notification when a new release is available
Easily extensible by any client using the REST API exposed by Shaarli.
See the [API documentation](
### Other usages
Though Shaarli is primarily a bookmarking application, it can serve other purposes
(see [Features](Features)):
- micro-blogging
- pastebin
- online notepad
- snippet archive
## About
### Shaarli community fork
This friendly fork is maintained by the Shaarli community at
This is a community fork of the original [Shaarli]( project by [Sébastien Sauvage](
The original project is currently unmaintained, and the developer [has informed us](
that he would have no time to work on Shaarli in the near future.
The Shaarli community has carried on the work to provide
[many patches](
for [bug fixes and enhancements](
in this repository, and will keep maintaining the project for the foreseeable future, while keeping Shaarli simple and efficient.
### Contributing
If you'd like to help, please:
- have a look at the open [issues](
and [pull requests](
- feel free to report bugs (feedback is much appreciated)
- suggest new features and improvements to both code and [documentation](
- propose solutions to existing problems
- submit pull requests :-)
### License
Shaarli is [Free Software]( See [COPYING](COPYING) for a detail of the contributors and licenses for each individual component.

Some files were not shown because too many files have changed in this diff Show More