summaryrefslogtreecommitdiff
path: root/IkiWiki/Plugin/editpage.pm
blob: f44e4f857b60ad7d3d56065f27979f1d07e71563 (plain)
  1. #!/usr/bin/perl
  2. package IkiWiki::Plugin::editpage;
  3. use warnings;
  4. use strict;
  5. use IkiWiki;
  6. use open qw{:utf8 :std};
  7. sub import { #{{{
  8. hook(type => "getsetup", id => "editpage", call => \&getsetup);
  9. hook(type => "refresh", id => "editpage", call => \&refresh);
  10. hook(type => "sessioncgi", id => "editpage", call => \&IkiWiki::cgi_editpage);
  11. } # }}}
  12. sub getsetup () { #{{{
  13. return
  14. plugin => {
  15. safe => 1,
  16. rebuild => 1,
  17. },
  18. } #}}}
  19. sub refresh () {
  20. if (exists $wikistate{editpage} && exists $wikistate{editpage}{previews}) {
  21. # Expire old preview files after one hour.
  22. my $expire=time - (60 * 60);
  23. my @previews;
  24. foreach my $file (@{$wikistate{editpage}{previews}}) {
  25. my $mtime=(stat("$config{destdir}/$file"))[9];
  26. if (defined $mtime && $mtime <= $expire) {
  27. # Avoid deleting a preview that was later saved.
  28. my $delete=1;
  29. foreach my $page (keys %renderedfiles) {
  30. if (grep { $_ eq $file } @{$renderedfiles{$page}}) {
  31. $delete=0;
  32. }
  33. }
  34. if ($delete) {
  35. debug(sprintf(gettext("removing old preview %s"), $file));
  36. IkiWiki::prune("$config{destdir}/$file");
  37. }
  38. }
  39. elsif (defined $mtime) {
  40. push @previews, $file;
  41. }
  42. }
  43. $wikistate{editpage}{previews}=\@previews;
  44. }
  45. }
  46. # Back to ikiwiki namespace for the rest, this code is very much
  47. # internal to ikiwiki even though it's separated into a plugin,
  48. # and other plugins use the functions below.
  49. package IkiWiki;
  50. sub check_canedit ($$$;$) { #{{{
  51. my $page=shift;
  52. my $q=shift;
  53. my $session=shift;
  54. my $nonfatal=shift;
  55. my $canedit;
  56. run_hooks(canedit => sub {
  57. return if defined $canedit;
  58. my $ret=shift->($page, $q, $session);
  59. if (defined $ret) {
  60. if ($ret eq "") {
  61. $canedit=1;
  62. }
  63. elsif (ref $ret eq 'CODE') {
  64. $ret->() unless $nonfatal;
  65. $canedit=0;
  66. }
  67. elsif (defined $ret) {
  68. error($ret) unless $nonfatal;
  69. $canedit=0;
  70. }
  71. }
  72. });
  73. return $canedit;
  74. } #}}}
  75. sub cgi_editpage ($$) { #{{{
  76. my $q=shift;
  77. my $session=shift;
  78. my $do=$q->param('do');
  79. return unless $do eq 'create' || $do eq 'edit';
  80. decode_cgi_utf8($q);
  81. my @fields=qw(do rcsinfo subpage from page type editcontent comments);
  82. my @buttons=("Save Page", "Preview", "Cancel");
  83. eval q{use CGI::FormBuilder};
  84. error($@) if $@;
  85. my $form = CGI::FormBuilder->new(
  86. fields => \@fields,
  87. charset => "utf-8",
  88. method => 'POST',
  89. required => [qw{editcontent}],
  90. javascript => 0,
  91. params => $q,
  92. action => $config{cgiurl},
  93. header => 0,
  94. table => 0,
  95. template => scalar template_params("editpage.tmpl"),
  96. wikiname => $config{wikiname},
  97. );
  98. decode_form_utf8($form);
  99. run_hooks(formbuilder_setup => sub {
  100. shift->(form => $form, cgi => $q, session => $session,
  101. buttons => \@buttons);
  102. });
  103. decode_form_utf8($form);
  104. # This untaint is safe because we check file_pruned and
  105. # wiki_file_regexp.
  106. my ($page)=$form->field('page')=~/$config{wiki_file_regexp}/;
  107. $page=possibly_foolish_untaint($page);
  108. my $absolute=($page =~ s#^/+##);
  109. if (! defined $page || ! length $page ||
  110. file_pruned($page, $config{srcdir})) {
  111. error("bad page name");
  112. }
  113. my $baseurl = urlto($page, undef, 1);
  114. my $from;
  115. if (defined $form->field('from')) {
  116. ($from)=$form->field('from')=~/$config{wiki_file_regexp}/;
  117. }
  118. my $file;
  119. my $type;
  120. if (exists $pagesources{$page} && $form->field("do") ne "create") {
  121. $file=$pagesources{$page};
  122. $type=pagetype($file);
  123. if (! defined $type || $type=~/^_/) {
  124. error(sprintf(gettext("%s is not an editable page"), $page));
  125. }
  126. if (! $form->submitted) {
  127. $form->field(name => "rcsinfo",
  128. value => rcs_prepedit($file), force => 1);
  129. }
  130. $form->field(name => "editcontent", validate => '/.*/');
  131. }
  132. else {
  133. $type=$form->param('type');
  134. if (defined $type && length $type && $hooks{htmlize}{$type}) {
  135. $type=possibly_foolish_untaint($type);
  136. }
  137. elsif (defined $from && exists $pagesources{$from}) {
  138. # favor the type of linking page
  139. $type=pagetype($pagesources{$from});
  140. }
  141. $type=$config{default_pageext} unless defined $type;
  142. if (! $config{indexpages}) {
  143. $file=$page.".".$type;
  144. }
  145. else {
  146. $file=$page."/index.".$type;
  147. }
  148. if (! $form->submitted) {
  149. $form->field(name => "rcsinfo", value => "", force => 1);
  150. }
  151. $form->field(name => "editcontent", validate => '/.+/');
  152. }
  153. $form->field(name => "do", type => 'hidden');
  154. $form->field(name => "sid", type => "hidden", value => $session->id,
  155. force => 1);
  156. $form->field(name => "from", type => 'hidden');
  157. $form->field(name => "rcsinfo", type => 'hidden');
  158. $form->field(name => "subpage", type => 'hidden');
  159. $form->field(name => "page", value => $page, force => 1);
  160. $form->field(name => "type", value => $type, force => 1);
  161. $form->field(name => "comments", type => "text", size => 80);
  162. $form->field(name => "editcontent", type => "textarea", rows => 20,
  163. cols => 80);
  164. $form->tmpl_param("can_commit", $config{rcs});
  165. $form->tmpl_param("indexlink", indexlink());
  166. $form->tmpl_param("helponformattinglink",
  167. htmllink($page, $page, "ikiwiki/formatting",
  168. noimageinline => 1,
  169. linktext => "FormattingHelp"));
  170. if ($form->submitted eq "Cancel") {
  171. if ($form->field("do") eq "create" && defined $from) {
  172. redirect($q, urlto($from, undef, 1));
  173. }
  174. elsif ($form->field("do") eq "create") {
  175. redirect($q, $config{url});
  176. }
  177. else {
  178. redirect($q, urlto($page, undef, 1));
  179. }
  180. exit;
  181. }
  182. elsif ($form->submitted eq "Preview") {
  183. my $new=not exists $pagesources{$page};
  184. if ($new) {
  185. # temporarily record its type
  186. $pagesources{$page}=$page.".".$type;
  187. }
  188. my %wasrendered=map { $_ => 1 } @{$renderedfiles{$page}};
  189. my $content=$form->field('editcontent');
  190. run_hooks(editcontent => sub {
  191. $content=shift->(
  192. content => $content,
  193. page => $page,
  194. cgi => $q,
  195. session => $session,
  196. );
  197. });
  198. my $preview=htmlize($page, $page, $type,
  199. linkify($page, $page,
  200. preprocess($page, $page,
  201. filter($page, $page, $content), 0, 1)));
  202. run_hooks(format => sub {
  203. $preview=shift->(
  204. page => $page,
  205. content => $preview,
  206. );
  207. });
  208. $form->tmpl_param("page_preview", $preview);
  209. if ($new) {
  210. delete $pagesources{$page};
  211. }
  212. # Previewing may have created files on disk.
  213. # Keep a list of these to be deleted later.
  214. my %previews = map { $_ => 1 } @{$wikistate{editpage}{previews}};
  215. foreach my $f (@{$renderedfiles{$page}}) {
  216. $previews{$f}=1 unless $wasrendered{$f};
  217. }
  218. @{$wikistate{editpage}{previews}} = keys %previews;
  219. $renderedfiles{$page}=[keys %wasrendered];
  220. saveindex();
  221. }
  222. elsif ($form->submitted eq "Save Page") {
  223. $form->tmpl_param("page_preview", "");
  224. }
  225. if ($form->submitted ne "Save Page" || ! $form->validate) {
  226. if ($form->field("do") eq "create") {
  227. my @page_locs;
  228. my $best_loc;
  229. if (! defined $from || ! length $from ||
  230. $from ne $form->field('from') ||
  231. file_pruned($from, $config{srcdir}) ||
  232. $from=~/^\// ||
  233. $absolute ||
  234. $form->submitted eq "Preview") {
  235. @page_locs=$best_loc=$page;
  236. }
  237. else {
  238. my $dir=$from."/";
  239. $dir=~s![^/]+/+$!!;
  240. if ((defined $form->field('subpage') && length $form->field('subpage')) ||
  241. $page eq gettext('discussion')) {
  242. $best_loc="$from/$page";
  243. }
  244. else {
  245. $best_loc=$dir.$page;
  246. }
  247. push @page_locs, $dir.$page;
  248. push @page_locs, "$from/$page";
  249. while (length $dir) {
  250. $dir=~s![^/]+/+$!!;
  251. push @page_locs, $dir.$page;
  252. }
  253. push @page_locs, "$config{userdir}/$page"
  254. if length $config{userdir};
  255. }
  256. @page_locs = grep {
  257. ! exists $pagecase{lc $_}
  258. } @page_locs;
  259. if (! @page_locs) {
  260. # hmm, someone else made the page in the
  261. # meantime?
  262. if ($form->submitted eq "Preview") {
  263. # let them go ahead with the edit
  264. # and resolve the conflict at save
  265. # time
  266. @page_locs=$page;
  267. }
  268. else {
  269. redirect($q, urlto($page, undef, 1));
  270. exit;
  271. }
  272. }
  273. my @editable_locs = grep {
  274. check_canedit($_, $q, $session, 1)
  275. } @page_locs;
  276. if (! @editable_locs) {
  277. # let it throw an error this time
  278. map { check_canedit($_, $q, $session) } @page_locs;
  279. }
  280. my @page_types;
  281. if (exists $hooks{htmlize}) {
  282. @page_types=grep { !/^_/ }
  283. keys %{$hooks{htmlize}};
  284. }
  285. $form->tmpl_param("page_select", 1);
  286. $form->field(name => "page", type => 'select',
  287. options => [ map { [ $_, pagetitle($_, 1) ] } @editable_locs ],
  288. value => $best_loc);
  289. $form->field(name => "type", type => 'select',
  290. options => \@page_types);
  291. $form->title(sprintf(gettext("creating %s"), pagetitle($page)));
  292. }
  293. elsif ($form->field("do") eq "edit") {
  294. check_canedit($page, $q, $session);
  295. if (! defined $form->field('editcontent') ||
  296. ! length $form->field('editcontent')) {
  297. my $content="";
  298. if (exists $pagesources{$page}) {
  299. $content=readfile(srcfile($pagesources{$page}));
  300. $content=~s/\n/\r\n/g;
  301. }
  302. $form->field(name => "editcontent", value => $content,
  303. force => 1);
  304. }
  305. $form->tmpl_param("page_select", 0);
  306. $form->field(name => "page", type => 'hidden');
  307. $form->field(name => "type", type => 'hidden');
  308. $form->title(sprintf(gettext("editing %s"), pagetitle($page)));
  309. }
  310. showform($form, \@buttons, $session, $q, forcebaseurl => $baseurl);
  311. }
  312. else {
  313. # save page
  314. check_canedit($page, $q, $session);
  315. # The session id is stored on the form and checked to
  316. # guard against CSRF. But only if the user is logged in,
  317. # as anonok can allow anonymous edits.
  318. if (defined $session->param("name")) {
  319. my $sid=$q->param('sid');
  320. if (! defined $sid || $sid ne $session->id) {
  321. error(gettext("Your login session has expired."));
  322. }
  323. }
  324. my $exists=-e "$config{srcdir}/$file";
  325. if ($form->field("do") ne "create" && ! $exists &&
  326. ! defined srcfile($file, 1)) {
  327. $form->tmpl_param("message", template("editpagegone.tmpl")->output);
  328. $form->field(name => "do", value => "create", force => 1);
  329. $form->tmpl_param("page_select", 0);
  330. $form->field(name => "page", type => 'hidden');
  331. $form->field(name => "type", type => 'hidden');
  332. $form->title(sprintf(gettext("editing %s"), $page));
  333. showform($form, \@buttons, $session, $q, forcebaseurl => $baseurl);
  334. exit;
  335. }
  336. elsif ($form->field("do") eq "create" && $exists) {
  337. $form->tmpl_param("message", template("editcreationconflict.tmpl")->output);
  338. $form->field(name => "do", value => "edit", force => 1);
  339. $form->tmpl_param("page_select", 0);
  340. $form->field(name => "page", type => 'hidden');
  341. $form->field(name => "type", type => 'hidden');
  342. $form->title(sprintf(gettext("editing %s"), $page));
  343. $form->field("editcontent",
  344. value => readfile("$config{srcdir}/$file").
  345. "\n\n\n".$form->field("editcontent"),
  346. force => 1);
  347. showform($form, \@buttons, $session, $q, forcebaseurl => $baseurl);
  348. exit;
  349. }
  350. my $content=$form->field('editcontent');
  351. run_hooks(editcontent => sub {
  352. $content=shift->(
  353. content => $content,
  354. page => $page,
  355. cgi => $q,
  356. session => $session,
  357. );
  358. });
  359. $content=~s/\r\n/\n/g;
  360. $content=~s/\r/\n/g;
  361. $content.="\n" if $content !~ /\n$/;
  362. $config{cgi}=0; # avoid cgi error message
  363. eval { writefile($file, $config{srcdir}, $content) };
  364. $config{cgi}=1;
  365. if ($@) {
  366. $form->field(name => "rcsinfo", value => rcs_prepedit($file),
  367. force => 1);
  368. my $mtemplate=template("editfailedsave.tmpl");
  369. $mtemplate->param(error_message => $@);
  370. $form->tmpl_param("message", $mtemplate->output);
  371. $form->field("editcontent", value => $content, force => 1);
  372. $form->tmpl_param("page_select", 0);
  373. $form->field(name => "page", type => 'hidden');
  374. $form->field(name => "type", type => 'hidden');
  375. $form->title(sprintf(gettext("editing %s"), $page));
  376. showform($form, \@buttons, $session, $q,
  377. forcebaseurl => $baseurl);
  378. exit;
  379. }
  380. my $conflict;
  381. if ($config{rcs}) {
  382. my $message="";
  383. if (defined $form->field('comments') &&
  384. length $form->field('comments')) {
  385. $message=$form->field('comments');
  386. }
  387. if (! $exists) {
  388. rcs_add($file);
  389. }
  390. # Prevent deadlock with post-commit hook by
  391. # signaling to it that it should not try to
  392. # do anything.
  393. disable_commit_hook();
  394. $conflict=rcs_commit($file, $message,
  395. $form->field("rcsinfo"),
  396. $session->param("name"), $ENV{REMOTE_ADDR});
  397. enable_commit_hook();
  398. rcs_update();
  399. }
  400. # Refresh even if there was a conflict, since other changes
  401. # may have been committed while the post-commit hook was
  402. # disabled.
  403. require IkiWiki::Render;
  404. refresh();
  405. saveindex();
  406. if (defined $conflict) {
  407. $form->field(name => "rcsinfo", value => rcs_prepedit($file),
  408. force => 1);
  409. $form->tmpl_param("message", template("editconflict.tmpl")->output);
  410. $form->field("editcontent", value => $conflict, force => 1);
  411. $form->field("do", "edit", force => 1);
  412. $form->tmpl_param("page_select", 0);
  413. $form->field(name => "page", type => 'hidden');
  414. $form->field(name => "type", type => 'hidden');
  415. $form->title(sprintf(gettext("editing %s"), $page));
  416. showform($form, \@buttons, $session, $q,
  417. forcebaseurl => $baseurl);
  418. }
  419. else {
  420. # The trailing question mark tries to avoid broken
  421. # caches and get the most recent version of the page.
  422. redirect($q, urlto($page, undef, 1)."?updated");
  423. }
  424. }
  425. exit;
  426. } #}}}
  427. 1