check for absolute paths
[ikiwiki] / IkiWiki / Plugin / rename.pm
1 #!/usr/bin/perl
2 package IkiWiki::Plugin::rename;
3
4 use warnings;
5 use strict;
6 use IkiWiki 2.00;
7
8 sub import { #{{{
9         hook(type => "formbuilder_setup", id => "rename", call => \&formbuilder_setup);
10         hook(type => "formbuilder", id => "rename", call => \&formbuilder);
11         hook(type => "sessioncgi", id => "rename", call => \&sessioncgi);
12
13 } # }}}
14
15 sub check_canrename ($$$$$$$) { #{{{
16         my $src=shift;
17         my $srcfile=shift;
18         my $dest=shift;
19         my $destfile=shift;
20         my $q=shift;
21         my $session=shift;
22         my $attachment=shift;
23
24         # Must be a known source file.
25         if (! exists $pagesources{$src}) {
26                 error(sprintf(gettext("%s does not exist"),
27                         htmllink("", "", $src, noimageinline => 1)));
28         }
29         
30         # Must exist on disk, and be a regular file.
31         if (! -e "$config{srcdir}/$srcfile") {
32                 error(sprintf(gettext("%s is not in the srcdir, so it cannot be renamed"), $srcfile));
33         }
34         elsif (-l "$config{srcdir}/$srcfile" && ! -f _) {
35                 error(sprintf(gettext("%s is not a file"), $srcfile));
36         }
37
38         # Must be editable.
39         IkiWiki::check_canedit($src, $q, $session);
40         if ($attachment) {
41                 IkiWiki::Plugin::attachment::check_canattach($session, $src, $srcfile);
42         }
43         
44         # Dest checks can be omitted by passing undef.
45         if (defined $dest) {
46                 if ($src eq $dest || $srcfile eq $destfile) {
47                         error(gettext("no change to the file name was specified"));
48                 }
49
50                 # Must be a legal filename, and not absolute.
51                 if (IkiWiki::file_pruned($destfile, $config{srcdir}) || 
52                     $destfile=~/^\//) {
53                         error(sprintf(gettext("illegal name")));
54                 }
55
56                 # Must not be a known source file.
57                 if (exists $pagesources{$dest}) {
58                         error(sprintf(gettext("%s already exists"),
59                                 htmllink("", "", $dest, noimageinline => 1)));
60                 }
61         
62                 # Must not exist on disk already.
63                 if (-l "$config{srcdir}/$destfile" || -e _) {
64                         error(sprintf(gettext("%s already exists on disk"), $destfile));
65                 }
66         
67                 # Must be editable.
68                 IkiWiki::check_canedit($dest, $q, $session);
69                 if ($attachment) {
70                         # Note that $srcfile is used here, not $destfile,
71                         # because it wants the current file, to check it.
72                         IkiWiki::Plugin::attachment::check_canattach($session, $dest, $srcfile);
73                 }
74         }
75 } #}}}
76
77 sub formbuilder_setup (@) { #{{{
78         my %params=@_;
79         my $form=$params{form};
80         my $q=$params{cgi};
81
82         if (defined $form->field("do") && $form->field("do") eq "edit") {
83                 # Rename button for the page, and also for attachments.
84                 push @{$params{buttons}}, "Rename";
85                 $form->tmpl_param("field-rename" => '<input name="_submit" type="submit" value="Rename Attachment" />');
86         }
87 } #}}}
88
89 sub rename_form ($$$) { #{{{ 
90         my $q=shift;
91         my $session=shift;
92         my $page=shift;
93
94         eval q{use CGI::FormBuilder};
95         error($@) if $@;
96         my $f = CGI::FormBuilder->new(
97                 name => "rename",
98                 title => sprintf(gettext("rename %s"), IkiWiki::pagetitle($page)),
99                 header => 0,
100                 charset => "utf-8",
101                 method => 'POST',
102                 javascript => 0,
103                 params => $q,
104                 action => $config{cgiurl},
105                 stylesheet => IkiWiki::baseurl()."style.css",
106                 fields => [qw{do page new_name attachment}],
107         );
108         
109         $f->field(name => "do", type => "hidden", value => "rename", force => 1);
110         $f->field(name => "page", type => "hidden", value => $page, force => 1);
111         $f->field(name => "new_name", value => IkiWiki::pagetitle($page), size => 60);
112         $f->field(name => "attachment", type => "hidden");
113
114         return $f, ["Rename", "Cancel"];
115 } #}}}
116
117 sub rename_start ($$$$) {
118         my $q=shift;
119         my $session=shift;
120         my $attachment=shift;
121         my $page=shift;
122
123         check_canrename($page, $pagesources{$page}, undef, undef,
124                 $q, $session, $attachment);
125
126         # Save current form state to allow returning to it later
127         # without losing any edits.
128         # (But don't save what button was submitted, to avoid
129         # looping back to here.)
130         # Note: "_submit" is CGI::FormBuilder internals.
131         $q->param(-name => "_submit", -value => "");
132         $session->param(postrename => scalar $q->Vars);
133         IkiWiki::cgi_savesession($session);
134         
135         my ($f, $buttons)=rename_form($q, $session, $page);
136         if (defined $attachment) {
137                 $f->field(name => "attachment", value => $attachment, force => 1);
138         }
139         
140         IkiWiki::showform($f, $buttons, $session, $q);
141         exit 0;
142 }
143
144 sub postrename ($;$) {
145         my $session=shift;
146         my $newname=shift;
147
148         # Load saved form state and return to edit form.
149         my $postrename=CGI->new($session->param("postrename"));
150         if (defined $newname) {
151                 # They renamed the page they were editing.
152                 # Tweak the edit form to be editing the new
153                 # page name, and redirect back to it.
154                 # (Deep evil here.)
155                 error("don't know how to redir back!"); ## FIXME
156         }
157         $session->clear("postrename");
158         IkiWiki::cgi_savesession($session);
159         IkiWiki::cgi($postrename, $session);
160 }
161
162 sub formbuilder (@) { #{{{
163         my %params=@_;
164         my $form=$params{form};
165
166         if (defined $form->field("do") && $form->field("do") eq "edit") {
167                 my $q=$params{cgi};
168                 my $session=$params{session};
169
170                 if ($form->submitted eq "Rename") {
171                         rename_start($q, $session, 0, $form->field("page"));
172                 }
173                 elsif ($form->submitted eq "Rename Attachment") {
174                         my @selected=$q->param("attachment_select");
175                         if (@selected > 1) {
176                                 error(gettext("Only one attachment can be renamed at a time."));
177                         }
178                         elsif (! @selected) {
179                                 error(gettext("Please select the attachment to rename."))
180                         }
181                         rename_start($q, $session, 1, $selected[0]);
182                 }
183         }
184 } #}}}
185
186 sub sessioncgi ($$) { #{{{
187         my $q=shift;
188
189         if ($q->param("do") eq 'rename') {
190                 my $session=shift;
191                 my ($form, $buttons)=rename_form($q, $session, $q->param("page"));
192                 IkiWiki::decode_form_utf8($form);
193
194                 if ($form->submitted eq 'Cancel') {
195                         postrename($session);
196                 }
197                 elsif ($form->submitted eq 'Rename' && $form->validate) {
198                         # These untaints are safe because of the checks
199                         # performed in check_canrename below.
200                         my $src=$q->param("page");
201                         my $srcfile=IkiWiki::possibly_foolish_untaint($pagesources{$src});
202                         my $dest=IkiWiki::possibly_foolish_untaint(IkiWiki::titlepage($q->param("new_name")));
203
204                         # The extension of dest is the same as src if it's
205                         # a page. If it's an extension, the extension is
206                         # already included.
207                         my $destfile=$dest;
208                         if (! $q->param("attachment")) {
209                                 my ($ext)=$srcfile=~/(\.[^.]+)$/;
210                                 $destfile.=$ext;
211                         }
212
213                         check_canrename($src, $srcfile, $dest, $destfile,
214                                 $q, $session, $q->param("attachment"));
215
216                         # Ensures that the dest directory exists and is ok.
217                         IkiWiki::prep_writefile($destfile, $config{srcdir});
218
219                         # Do rename, and update the wiki.
220                         require IkiWiki::Render;
221                         if ($config{rcs}) {
222                                 IkiWiki::disable_commit_hook();
223                                 IkiWiki::rcs_rename($srcfile, $destfile);
224                                 IkiWiki::rcs_commit_staged(gettext("rename $srcfile to $destfile"),
225                                         $session->param("name"), $ENV{REMOTE_ADDR});
226                                 IkiWiki::enable_commit_hook();
227                                 IkiWiki::rcs_update();
228                         }
229                         else {
230                                 if (! rename("$config{srcdir}/$srcfile", "$config{srcdir}/$destfile")) {
231                                         error("rename: $!");
232                                 }
233                         }
234                         IkiWiki::refresh();
235                         IkiWiki::saveindex();
236
237                         if ($q->param("attachment")) {
238                                 postrename($session);
239                         }
240                         else {
241                                 postrename($session, $dest);
242                         }
243                 }
244                 else {
245                         IkiWiki::showform($form, $buttons, $session, $q);
246                 }
247
248                 exit 0;
249         }
250 }
251
252 1