aboutsummaryrefslogtreecommitdiff
path: root/IkiWiki/Plugin/smcvpostcomment.pm
blob: 40ffe816425722d89852bf37ee59479dbfe398f5 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
#!/usr/bin/perl
# Copyright © 2006-2008 Joey Hess <joey@ikiwiki.info>
# Copyright © 2008 Simon McVittie <http://smcv.pseudorandom.co.uk/>
# Licensed under the GNU GPL, version 2, or any later version published by the
# Free Software Foundation
package IkiWiki::Plugin::smcvpostcomment;

use warnings;
use strict;
use IkiWiki 2.00;

use constant PLUGIN => "smcvpostcomment";
use constant PREVIEW => "Preview";
use constant POST_COMMENT => "Post comment";
use constant CANCEL => "Cancel";

sub import { #{{{
	hook(type => "getsetup", id => PLUGIN,  call => \&getsetup);
	hook(type => "preprocess", id => PLUGIN, call => \&preprocess);
	hook(type => "sessioncgi", id => PLUGIN, call => \&sessioncgi);
	hook(type => "htmlize", id => "_".PLUGIN,
		call => \&IkiWiki::Plugin::mdwn::htmlize);
	IkiWiki::loadplugin("inline");
	IkiWiki::loadplugin("mdwn");
} # }}}

sub htmlize { # {{{
	eval { use IkiWiki::Plugin::mdwn; };
	error($@) if ($@);
	return IkiWiki::Plugin::mdwn::htmlize(@_)
} # }}}

sub getsetup () { #{{{
	return
		plugin => {
			safe => 1,
			rebuild => undef,
		},
} #}}}

# Somewhat based on IkiWiki::Plugin::inline blog posting support
sub preprocess (@) { #{{{
	my %params=@_;

	unless (length $config{cgiurl}) {
		error(sprintf (gettext("[[!%s plugin requires CGI enabled]]"),
			PLUGIN));
	}

	my $page = $params{page};
	$pagestate{$page}{PLUGIN()}{comments} = 1;
	$pagestate{$page}{PLUGIN()}{allowhtml} = IkiWiki::yesno($params{allowhtml});
	$pagestate{$page}{PLUGIN()}{allowdirectives} = IkiWiki::yesno($params{allowdirectives});
	$pagestate{$page}{PLUGIN()}{commit} = defined $params{commit}
		? IkiWiki::yesno($params{commit})
		: 1;

	my $formtemplate = IkiWiki::template(PLUGIN . "_embed.tmpl",
		blind_cache => 1);
	$formtemplate->param(cgiurl => $config{cgiurl});
	$formtemplate->param(page => $params{page});

	if ($params{preview}) {
		$formtemplate->param("disabled" =>
			gettext('not available during Preview'));
	}

	debug("page $params{page} => destpage $params{destpage}");

	my $posts = '';
	unless (defined $params{inline} && !IkiWiki::yesno($params{inline})) {
		eval { use IkiWiki::Plugin::inline; };
		error($@) if ($@);
		my @args = (
			pages => "internal($params{page}/_comment_*)",
			template => PLUGIN . "_display",
			show => 0,
			reverse => "yes",
			# special stuff passed through
			page => $params{page},
			destpage => $params{destpage},
			preview => $params{preview},
		);
		push @args, atom => $params{atom} if defined $params{atom};
		push @args, rss => $params{rss} if defined $params{rss};
		push @args, feeds => $params{feeds} if defined $params{feeds};
		push @args, feedshow => $params{feedshow} if defined $params{feedshow};
		push @args, timeformat => $params{timeformat} if defined $params{timeformat};
		push @args, feedonly => $params{feedonly} if defined $params{feedonly};
		$posts = "\n" . IkiWiki::preprocess_inline(@args);
	}

	return $formtemplate->output . $posts;
} # }}}

# FIXME: logic taken from editpage, should be common code?
sub getcgiuser ($) { # {{{
	my $session = shift;
	my $user = $session->param('name');
	$user = $ENV{REMOTE_ADDR} unless defined $user;
	debug("getcgiuser() -> $user");
	return $user;
} # }}}

# FIXME: logic adapted from recentchanges, should be common code?
sub linkuser ($) { # {{{
	my $user = shift;
	my $oiduser = eval { IkiWiki::openiduser($user) };

	if (defined $oiduser) {
		return ($user, $oiduser);
	}
	else {
		my $page = bestlink('', (length $config{userdir}
				? "$config{userdir}/"
				: "").$user);
		return (urlto($page, undef, 1), $user);
	}
} # }}}

# FIXME: taken from IkiWiki::Plugin::editpage, should be common?
sub checksessionexpiry ($$) { # {{{
	my $session = shift;
	my $sid = shift;

	if (defined $session->param("name")) {
		if (! defined $sid || $sid ne $session->id) {
			error(gettext("Your login session has expired."));
		}
	}
} # }}}

# Mostly cargo-culted from IkiWiki::plugin::editpage
sub sessioncgi ($$) { #{{{
	my $cgi=shift;
	my $session=shift;

	my $do = $cgi->param('do');
	return unless $do eq PLUGIN;

	IkiWiki::decode_cgi_utf8($cgi);

	eval q{use CGI::FormBuilder};
	error($@) if $@;

	my @buttons = (POST_COMMENT, PREVIEW, CANCEL);
	my $form = CGI::FormBuilder->new(
		fields => [qw{do sid page subject body}],
		charset => 'utf-8',
		method => 'POST',
		required => [qw{body}],
		javascript => 0,
		params => $cgi,
		action => $config{cgiurl},
		header => 0,
		table => 0,
		template => scalar IkiWiki::template_params(PLUGIN . '_form.tmpl'),
		# wtf does this do in editpage?
		wikiname => $config{wikiname},
	);

	IkiWiki::decode_form_utf8($form);
	IkiWiki::run_hooks(formbuilder_setup => sub {
			shift->(title => PLUGIN, form => $form, cgi => $cgi,
				session => $session, buttons => \@buttons);
		});
	IkiWiki::decode_form_utf8($form);

	$form->field(name => 'do', type => 'hidden');
	$form->field(name => 'sid', type => 'hidden', value => $session->id,
		force => 1);
	$form->field(name => 'page', type => 'hidden');
	$form->field(name => 'subject', type => 'text', size => 72);
	$form->field(name => 'body', type => 'textarea', rows => 5,
		cols => 80);

	# The untaint is OK (as in editpage) because we're about to pass
	# it to file_pruned anyway
	my $page = $form->field('page');
	$page = IkiWiki::possibly_foolish_untaint($page);
	if (!defined $page || !length $page ||
		IkiWiki::file_pruned($page, $config{srcdir})) {
		error(gettext("bad page name"));
	}

	my $allow_directives = $pagestate{$page}{PLUGIN()}{allowdirectives};
	my $allow_html = $pagestate{$page}{PLUGIN()}{allowdirectives};
	my $commit_comments = defined $pagestate{$page}{PLUGIN()}{commit}
		? $pagestate{$page}{PLUGIN()}{commit}
		: 1;

	# FIXME: is this right? Or should we be using the candidate subpage
	# (whatever that might mean) as the base URL?
	my $baseurl = urlto($page, undef, 1);

	$form->title(sprintf(gettext("commenting on %s"),
			IkiWiki::pagetitle($page)));

	$form->tmpl_param('helponformattinglink',
		htmllink($page, $page, 'ikiwiki/formatting',
			noimageinline => 1,
			linktext => 'FormattingHelp'),
			allowhtml => $allow_html,
			allowdirectives => $allow_directives);

	if (not exists $pagesources{$page}) {
		error(sprintf(gettext(
			"page '%s' doesn't exist, so you can't comment"),
			$page));
	}
	if (not $pagestate{$page}{PLUGIN()}{comments}) {
		error(sprintf(gettext(
			"comments are not enabled on page '%s'"),
			$page));
	}

	if ($form->submitted eq CANCEL) {
		# bounce back to the page they wanted to comment on, and exit.
		# CANCEL need not be considered in future
		IkiWiki::redirect($cgi, urlto($page, undef, 1));
		exit;
	}

	IkiWiki::check_canedit($page . "[" . PLUGIN . "]", $cgi, $session);

	my ($authorurl, $author) = linkuser(getcgiuser($session));

	my $body = $form->field('body') || '';
	$body =~ s/\r\n/\n/g;
	$body =~ s/\r/\n/g;
	$body = "\n" if $body !~ /\n$/;

	unless ($allow_directives) {
		# don't allow new-style directives at all
		$body =~ s/(^|[^\\])\[\[!/$1\\[[!/g;

		# don't allow [[ unless it begins an old-style
		# wikilink, if prefix_directives is off
		$body =~ s/(^|[^\\])\[\[(?![^\n\s\]+]\]\])/$1\\[[!/g
			unless $config{prefix_directives};
	}

	unless ($allow_html) {
		$body =~ s/&(\w|#)/&amp;$1/g;
		$body =~ s/</&lt;/g;
		$body =~ s/>/&gt;/g;
	}

	# In this template, the [[!meta]] directives should stay at the end,
	# so that they will override anything the user specifies. (For
	# instance, [[!meta author="I can fake the author"]]...)
	my $content_tmpl = template(PLUGIN . '_comment.tmpl');
	$content_tmpl->param(author => $author);
	$content_tmpl->param(authorurl => $authorurl);
	$content_tmpl->param(subject => $form->field('subject'));
	$content_tmpl->param(body => $body);

	my $content = $content_tmpl->output;

	# This is essentially a simplified version of editpage:
	# - the user does not control the page that's created, only the parent
	# - it's always a create operation, never an edit
	# - this means that conflicts should never happen
	# - this means that if they do, rocks fall and everyone dies

	if ($form->submitted eq PREVIEW) {
		# $fake is a location that has the same number of slashes
		# as the eventual location of this comment.
		my $fake = "$page/_" . PLUGIN . "hypothetical";
		my $preview = IkiWiki::htmlize($fake, $page, 'mdwn',
				IkiWiki::linkify($page, $page,
					IkiWiki::preprocess($page, $page,
						IkiWiki::filter($fake, $page,
							$content),
						0, 1)));
		IkiWiki::run_hooks(format => sub {
				$preview = shift->(page => $page,
					content => $preview);
			});

		my $template = template(PLUGIN . "_display.tmpl");
		$template->param(content => $preview);
		$template->param(title => $form->field('subject'));
		$template->param(ctime => displaytime(time));
		$template->param(author => $author);
		$template->param(authorurl => $authorurl);

		$form->tmpl_param(page_preview => $template->output);
	}
	else {
		$form->tmpl_param(page_preview => "");
	}

	if ($form->submitted eq POST_COMMENT && $form->validate) {
		# Let's get posting. We don't check_canedit here because
		# that somewhat defeats the point of this plugin.

		checksessionexpiry($session, $cgi->param('sid'));

		# FIXME: check that the wiki is locked right now, because
		# if it's not, there are mad race conditions!

		# FIXME: rather a simplistic way to make the comments...
		my $i = 0;
		my $file;
		do {
			$i++;
			$file = "$page/_comment_${i}._" . PLUGIN;
		} while (-e "$config{srcdir}/$file");

		# FIXME: could probably do some sort of graceful retry
		# if I could be bothered
		writefile($file, $config{srcdir}, $content);

		my $conflict;

		if ($config{rcs} and $commit_comments) {
			my $message = gettext("Added a comment");
			if (defined $form->field('subject') &&
				length $form->field('subject')) {
				$message .= ": ".$form->field('subject');
			}

			IkiWiki::rcs_add($file);
			IkiWiki::disable_commit_hook();
			$conflict = IkiWiki::rcs_commit_staged($message,
				$session->param('name'), $ENV{REMOTE_ADDR});
			IkiWiki::enable_commit_hook();
			IkiWiki::rcs_update();
		}

		# Now we need a refresh
		require IkiWiki::Render;
		IkiWiki::refresh();
		IkiWiki::saveindex();

		# this should never happen, unless a committer deliberately
		# breaks it or something
		error($conflict) if defined $conflict;

		# Bounce back to where we were, but defeat broken caches
		my $anticache = "?updated=$page/_comment_$i";
		IkiWiki::redirect($cgi, urlto($page, undef, 1).$anticache);
	}
	else {
		IkiWiki::showform ($form, \@buttons, $session, $cgi,
			forcebaseurl => $baseurl);
	}

	exit;
} #}}}

package IkiWiki::PageSpec;

sub match_smcvpostcomment ($$;@) {
	my $page = shift;
	my $glob = shift;

	unless ($page =~ s/\[smcvpostcomment\]$//) {
		return IkiWiki::FailReason->new("not posting a comment");
	}
	return match_glob($page, $glob);
}

1