remove, rename: Add guards against XSRF attacks.
[ikiwiki] / IkiWiki / Plugin / rename.pm
1 #!/usr/bin/perl
2 package IkiWiki::Plugin::rename;
3
4 use warnings;
5 use strict;
6 use IkiWiki 3.00;
7
8 sub import {
9         hook(type => "getsetup", id => "rename", call => \&getsetup);
10         hook(type => "formbuilder_setup", id => "rename", call => \&formbuilder_setup);
11         hook(type => "formbuilder", id => "rename", call => \&formbuilder);
12         hook(type => "sessioncgi", id => "rename", call => \&sessioncgi);
13         hook(type => "rename", id => "rename", call => \&rename_subpages);
14 }
15
16 sub getsetup () {
17         return 
18                 plugin => {
19                         safe => 1,
20                         rebuild => 0,
21                         section => "web",
22                 },
23 }
24
25 sub check_canrename ($$$$$$) {
26         my $src=shift;
27         my $srcfile=shift;
28         my $dest=shift;
29         my $destfile=shift;
30         my $q=shift;
31         my $session=shift;
32
33         my $attachment=! defined pagetype($pagesources{$src});
34
35         # Must be a known source file.
36         if (! exists $pagesources{$src}) {
37                 error(sprintf(gettext("%s does not exist"),
38                         htmllink("", "", $src, noimageinline => 1)));
39         }
40         
41         # Must exist on disk, and be a regular file.
42         if (! -e "$config{srcdir}/$srcfile") {
43                 error(sprintf(gettext("%s is not in the srcdir, so it cannot be renamed"), $srcfile));
44         }
45         elsif (-l "$config{srcdir}/$srcfile" && ! -f _) {
46                 error(sprintf(gettext("%s is not a file"), $srcfile));
47         }
48
49         # Must be editable.
50         IkiWiki::check_canedit($src, $q, $session);
51         if ($attachment) {
52                 if (IkiWiki::Plugin::attachment->can("check_canattach")) {
53                         IkiWiki::Plugin::attachment::check_canattach($session, $src, "$config{srcdir}/$srcfile");
54                 }
55                 else {
56                         error("renaming of attachments is not allowed");
57                 }
58         }
59         
60         # Dest checks can be omitted by passing undef.
61         if (defined $dest) {
62                 if ($srcfile eq $destfile) {
63                         error(gettext("no change to the file name was specified"));
64                 }
65
66                 # Must be a legal filename.
67                 if (IkiWiki::file_pruned($destfile)) {
68                         error(sprintf(gettext("illegal name")));
69                 }
70
71                 # Must not be a known source file.
72                 if ($src ne $dest && exists $pagesources{$dest}) {
73                         error(sprintf(gettext("%s already exists"),
74                                 htmllink("", "", $dest, noimageinline => 1)));
75                 }
76         
77                 # Must not exist on disk already.
78                 if (-l "$config{srcdir}/$destfile" || -e _) {
79                         error(sprintf(gettext("%s already exists on disk"), $destfile));
80                 }
81         
82                 # Must be editable.
83                 IkiWiki::check_canedit($dest, $q, $session);
84                 if ($attachment) {
85                         # Note that $srcfile is used here, not $destfile,
86                         # because it wants the current file, to check it.
87                         IkiWiki::Plugin::attachment::check_canattach($session, $dest, "$config{srcdir}/$srcfile");
88                 }
89         }
90
91         my $canrename;
92         IkiWiki::run_hooks(canrename => sub {
93                 return if defined $canrename;
94                 my $ret=shift->(cgi => $q, session => $session,
95                         src => $src, srcfile => $srcfile,
96                         dest => $dest, destfile => $destfile);
97                 if (defined $ret) {
98                         if ($ret eq "") {
99                                 $canrename=1;
100                         }
101                         elsif (ref $ret eq 'CODE') {
102                                 $ret->();
103                                 $canrename=0;
104                         }
105                         elsif (defined $ret) {
106                                 error($ret);
107                                 $canrename=0;
108                         }
109                 }
110         });
111 }
112
113 sub rename_form ($$$) {
114         my $q=shift;
115         my $session=shift;
116         my $page=shift;
117
118         eval q{use CGI::FormBuilder};
119         error($@) if $@;
120         my $f = CGI::FormBuilder->new(
121                 name => "rename",
122                 title => sprintf(gettext("rename %s"), pagetitle($page)),
123                 header => 0,
124                 charset => "utf-8",
125                 method => 'POST',
126                 javascript => 0,
127                 params => $q,
128                 action => $config{cgiurl},
129                 stylesheet => 1,
130                 fields => [qw{do page new_name attachment}],
131         );
132         
133         $f->field(name => "do", type => "hidden", value => "rename", force => 1);
134         $f->field(name => "sid", type => "hidden", value => $session->id,
135                 force => 1);
136         $f->field(name => "page", type => "hidden", value => $page, force => 1);
137         $f->field(name => "new_name", value => pagetitle($page, 1), size => 60);
138         if (!$q->param("attachment")) {
139                 # insert the standard extensions
140                 my @page_types;
141                 if (exists $IkiWiki::hooks{htmlize}) {
142                         foreach my $key (grep { !/^_/ } keys %{$IkiWiki::hooks{htmlize}}) {
143                                 push @page_types, [$key, $IkiWiki::hooks{htmlize}{$key}{longname} || $key];
144                         }
145                 }
146                 @page_types=sort @page_types;
147         
148                 # make sure the current extension is in the list
149                 my ($ext) = $pagesources{$page}=~/\.([^.]+)$/;
150                 if (! $IkiWiki::hooks{htmlize}{$ext}) {
151                         unshift(@page_types, [$ext, $ext]);
152                 }
153         
154                 $f->field(name => "type", type => 'select',
155                         options => \@page_types,
156                         value => $ext, force => 1);
157                 
158                 foreach my $p (keys %pagesources) {
159                         if ($pagesources{$p}=~m/^\Q$page\E\//) {
160                                 $f->field(name => "subpages",
161                                         label => "",
162                                         type => "checkbox",
163                                         options => [ [ 1 => gettext("Also rename SubPages and attachments") ] ],
164                                         value => 1,
165                                         force => 1);
166                                 last;
167                         }
168                 }
169         }
170         $f->field(name => "attachment", type => "hidden");
171
172         return $f, ["Rename", "Cancel"];
173 }
174
175 sub rename_start ($$$$) {
176         my $q=shift;
177         my $session=shift;
178         my $attachment=shift;
179         my $page=shift;
180
181         check_canrename($page, $pagesources{$page}, undef, undef,
182                 $q, $session);
183
184         # Save current form state to allow returning to it later
185         # without losing any edits.
186         # (But don't save what button was submitted, to avoid
187         # looping back to here.)
188         # Note: "_submit" is CGI::FormBuilder internals.
189         $q->param(-name => "_submit", -value => "");
190         $session->param(postrename => scalar $q->Vars);
191         IkiWiki::cgi_savesession($session);
192         
193         if (defined $attachment) {
194                 $q->param(-name => "attachment", -value => $attachment);
195         }
196         my ($f, $buttons)=rename_form($q, $session, $page);
197         IkiWiki::showform($f, $buttons, $session, $q);
198         exit 0;
199 }
200
201 sub postrename ($;$$$) {
202         my $session=shift;
203         my $src=shift;
204         my $dest=shift;
205         my $attachment=shift;
206
207         # Load saved form state and return to edit page.
208         my $postrename=CGI->new($session->param("postrename"));
209         $session->clear("postrename");
210         IkiWiki::cgi_savesession($session);
211
212         if (defined $dest) {
213                 if (! $attachment) {
214                         # They renamed the page they were editing. This requires
215                         # fixups to the edit form state.
216                         # Tweak the edit form to be editing the new page.
217                         $postrename->param("page", $dest);
218                 }
219
220                 # Update edit form content to fix any links present
221                 # on it.
222                 $postrename->param("editcontent",
223                         renamepage_hook($dest, $src, $dest,
224                                  $postrename->param("editcontent")));
225
226                 # Get a new edit token; old was likely invalidated.
227                 $postrename->param("rcsinfo",
228                         IkiWiki::rcs_prepedit($pagesources{$dest}));
229         }
230
231         IkiWiki::cgi_editpage($postrename, $session);
232 }
233
234 sub formbuilder (@) {
235         my %params=@_;
236         my $form=$params{form};
237
238         if (defined $form->field("do") && ($form->field("do") eq "edit" ||
239             $form->field("do") eq "create")) {
240                 IkiWiki::decode_form_utf8($form);
241                 my $q=$params{cgi};
242                 my $session=$params{session};
243
244                 if ($form->submitted eq "Rename" && $form->field("do") eq "edit") {
245                         rename_start($q, $session, 0, $form->field("page"));
246                 }
247                 elsif ($form->submitted eq "Rename Attachment") {
248                         my @selected=map { Encode::decode_utf8($_) } $q->param("attachment_select");
249                         if (@selected > 1) {
250                                 error(gettext("Only one attachment can be renamed at a time."));
251                         }
252                         elsif (! @selected) {
253                                 error(gettext("Please select the attachment to rename."))
254                         }
255                         rename_start($q, $session, 1, $selected[0]);
256                 }
257         }
258 }
259
260 my $renamesummary;
261
262 sub formbuilder_setup (@) {
263         my %params=@_;
264         my $form=$params{form};
265         my $q=$params{cgi};
266
267         if (defined $form->field("do") && ($form->field("do") eq "edit" ||
268             $form->field("do") eq "create")) {
269                 # Rename button for the page, and also for attachments.
270                 push @{$params{buttons}}, "Rename" if $form->field("do") eq "edit";
271                 $form->tmpl_param("field-rename" => '<input name="_submit" type="submit" value="Rename Attachment" />');
272
273                 if (defined $renamesummary) {
274                         $form->tmpl_param(message => $renamesummary);
275                 }
276         }
277 }
278
279 sub sessioncgi ($$) {
280         my $q=shift;
281
282         if ($q->param("do") eq 'rename') {
283                 my $session=shift;
284                 my ($form, $buttons)=rename_form($q, $session, Encode::decode_utf8($q->param("page")));
285                 IkiWiki::decode_form_utf8($form);
286
287                 if ($form->submitted eq 'Cancel') {
288                         postrename($session);
289                 }
290                 elsif ($form->submitted eq 'Rename' && $form->validate) {
291                         IkiWiki::checksessionexpiry($q, $session, $q->param('sid'));
292
293                         # Queue of rename actions to perfom.
294                         my @torename;
295
296                         # These untaints are safe because of the checks
297                         # performed in check_canrename later.
298                         my $src=$form->field("page");
299                         my $srcfile=IkiWiki::possibly_foolish_untaint($pagesources{$src});
300                         my $dest=IkiWiki::possibly_foolish_untaint(titlepage($form->field("new_name")));
301                         my $destfile=$dest;
302                         if (! $q->param("attachment")) {
303                                 my $type=$q->param('type');
304                                 if (defined $type && length $type && $IkiWiki::hooks{htmlize}{$type}) {
305                                         $type=IkiWiki::possibly_foolish_untaint($type);
306                                 }
307                                 else {
308                                         my ($ext)=$srcfile=~/\.([^.]+)$/;
309                                         $type=$ext;
310                                 }
311                                 
312                                 $destfile=newpagefile($dest, $type);
313                         }
314                         push @torename, {
315                                 src => $src,
316                                 srcfile => $srcfile,
317                                 dest => $dest,
318                                 destfile => $destfile,
319                                 required => 1,
320                         };
321
322                         @torename=rename_hook(
323                                 torename => \@torename,
324                                 done => {},
325                                 cgi => $q,
326                                 session => $session,
327                         );
328
329                         require IkiWiki::Render;
330                         IkiWiki::disable_commit_hook() if $config{rcs};
331                         my %origpagesources=%pagesources;
332
333                         # First file renaming.
334                         foreach my $rename (@torename) {
335                                 if ($rename->{required}) {
336                                         do_rename($rename, $q, $session);
337                                 }
338                                 else {
339                                         eval {do_rename($rename, $q, $session)};
340                                         if ($@) {
341                                                 $rename->{error}=$@;
342                                                 next;
343                                         }
344                                 }
345
346                                 # Temporarily tweak pagesources to point to
347                                 # the renamed file, in case fixlinks needs
348                                 # to edit it.
349                                 $pagesources{$rename->{src}}=$rename->{destfile};
350                         }
351                         IkiWiki::rcs_commit_staged(
352                                 sprintf(gettext("rename %s to %s"), $srcfile, $destfile),
353                                 $session->param("name"), $ENV{REMOTE_ADDR}) if $config{rcs};
354
355                         # Then link fixups.
356                         foreach my $rename (@torename) {
357                                 next if $rename->{src} eq $rename->{dest};
358                                 next if $rename->{error};
359                                 foreach my $p (fixlinks($rename, $session)) {
360                                         # map old page names to new
361                                         foreach my $r (@torename) {
362                                                 next if $rename->{error};
363                                                 if ($r->{src} eq $p) {
364                                                         $p=$r->{dest};
365                                                         last;
366                                                 }
367                                         }
368                                         push @{$rename->{fixedlinks}}, $p;
369                                 }
370                         }
371
372                         # Then refresh.
373                         %pagesources=%origpagesources;
374                         if ($config{rcs}) {
375                                 IkiWiki::enable_commit_hook();
376                                 IkiWiki::rcs_update();
377                         }
378                         IkiWiki::refresh();
379                         IkiWiki::saveindex();
380
381                         # Find pages with remaining, broken links.
382                         foreach my $rename (@torename) {
383                                 next if $rename->{src} eq $rename->{dest};
384                                 
385                                 foreach my $page (keys %links) {
386                                         my $broken=0;
387                                         foreach my $link (@{$links{$page}}) {
388                                                 my $bestlink=bestlink($page, $link);
389                                                 if ($bestlink eq $rename->{src}) {
390                                                         push @{$rename->{brokenlinks}}, $page;
391                                                         last;
392                                                 }
393                                         }
394                                 }
395                         }
396
397                         # Generate a summary, that will be shown at the top
398                         # of the edit template.
399                         $renamesummary="";
400                         foreach my $rename (@torename) {
401                                 my $template=template("renamesummary.tmpl");
402                                 $template->param(src => $rename->{srcfile});
403                                 $template->param(dest => $rename->{destfile});
404                                 $template->param(error => $rename->{error});
405                                 if ($rename->{src} ne $rename->{dest}) {
406                                         $template->param(brokenlinks_checked => 1);
407                                         $template->param(brokenlinks => linklist($rename->{dest}, $rename->{brokenlinks}));
408                                         $template->param(fixedlinks => linklist($rename->{dest}, $rename->{fixedlinks}));
409                                 }
410                                 $renamesummary.=$template->output;
411                         }
412
413                         postrename($session, $src, $dest, $q->param("attachment"));
414                 }
415                 else {
416                         IkiWiki::showform($form, $buttons, $session, $q);
417                 }
418
419                 exit 0;
420         }
421 }
422
423 # Add subpages to the list of pages to be renamed, if needed.
424 sub rename_subpages (@) {
425         my %params = @_;
426
427         my %torename = %{$params{torename}};
428         my $q = $params{cgi};
429         my $src = $torename{src};
430         my $srcfile = $torename{src};
431         my $dest = $torename{dest};
432         my $destfile = $torename{dest};
433
434         return () unless ($q->param("subpages") && $src ne $dest);
435
436         my @ret;
437         foreach my $p (keys %pagesources) {
438                 next unless $pagesources{$p}=~m/^\Q$src\E\//;
439                 # If indexpages is enabled, the srcfile should not be confused
440                 # with a subpage.
441                 next if $pagesources{$p} eq $srcfile;
442
443                 my $d=$pagesources{$p};
444                 $d=~s/^\Q$src\E\//$dest\//;
445                 push @ret, {
446                         src => $p,
447                         srcfile => $pagesources{$p},
448                         dest => pagename($d),
449                         destfile => $d,
450                         required => 0,
451                 };
452         }
453         return @ret;
454 }
455
456 sub linklist {
457         # generates a list of links in a form suitable for FormBuilder
458         my $dest=shift;
459         my $list=shift;
460         # converts a list of pages into a list of links
461         # in a form suitable for FormBuilder.
462
463         [map {
464                 {
465                         page => htmllink($dest, $dest, $_,
466                                         noimageinline => 1,
467                                         linktext => pagetitle($_),
468                                 )
469                 }
470         } @{$list}]
471 }
472
473 sub renamepage_hook ($$$$) {
474         my ($page, $src, $dest, $content)=@_;
475
476         IkiWiki::run_hooks(renamepage => sub {
477                 $content=shift->(
478                         page => $page,
479                         oldpage => $src,
480                         newpage => $dest,
481                         content => $content,
482                 );
483         });
484
485         return $content;
486 }
487
488 sub rename_hook {
489         my %params = @_;
490
491         my @torename=@{$params{torename}};
492         my %done=%{$params{done}};
493         my $q=$params{cgi};
494         my $session=$params{session};
495
496         return () unless @torename;
497
498         my @nextset;
499         foreach my $torename (@torename) {
500                 unless (exists $done{$torename->{src}} && $done{$torename->{src}}) {
501                         IkiWiki::run_hooks(rename => sub {
502                                 push @nextset, shift->(
503                                         torename => $torename,
504                                         cgi => $q,
505                                         session => $session,
506                                 );
507                         });
508                         $done{$torename->{src}}=1;
509                 }
510         }
511
512         push @torename, rename_hook(
513                 torename => \@nextset,
514                 done => \%done,
515                 cgi => $q,
516                 session => $session,
517         );
518
519         # dedup
520         my %seen;
521         return grep { ! $seen{$_->{src}}++ } @torename;
522 }
523
524 sub do_rename ($$$) {
525         my $rename=shift;
526         my $q=shift;
527         my $session=shift;
528
529         # First, check if this rename is allowed.
530         check_canrename($rename->{src},
531                 $rename->{srcfile},
532                 $rename->{dest},
533                 $rename->{destfile},
534                 $q, $session);
535
536         # Ensure that the dest directory exists and is ok.
537         IkiWiki::prep_writefile($rename->{destfile}, $config{srcdir});
538
539         if ($config{rcs}) {
540                 IkiWiki::rcs_rename($rename->{srcfile}, $rename->{destfile});
541         }
542         else {
543                 if (! rename($config{srcdir}."/".$rename->{srcfile},
544                              $config{srcdir}."/".$rename->{destfile})) {
545                         error("rename: $!");
546                 }
547         }
548
549 }
550
551 sub fixlinks ($$$) {
552         my $rename=shift;
553         my $session=shift;
554
555         my @fixedlinks;
556
557         foreach my $page (keys %links) {
558                 my $needfix=0;
559                 foreach my $link (@{$links{$page}}) {
560                         my $bestlink=bestlink($page, $link);
561                         if ($bestlink eq $rename->{src}) {
562                                 $needfix=1;
563                                 last;
564                         }
565                 }
566                 if ($needfix) {
567                         my $file=$pagesources{$page};
568                         my $oldcontent=readfile($config{srcdir}."/".$file);
569                         my $content=renamepage_hook($page, $rename->{src}, $rename->{dest}, $oldcontent);
570                         if ($oldcontent ne $content) {
571                                 my $token=IkiWiki::rcs_prepedit($file);
572                                 eval { writefile($file, $config{srcdir}, $content) };
573                                 next if $@;
574                                 my $conflict=IkiWiki::rcs_commit(
575                                         $file,
576                                         sprintf(gettext("update for rename of %s to %s"), $rename->{srcfile}, $rename->{destfile}),
577                                         $token,
578                                         $session->param("name"), 
579                                         $ENV{REMOTE_ADDR}
580                                 );
581                                 push @fixedlinks, $page if ! defined $conflict;
582                         }
583                 }
584         }
585
586         return @fixedlinks;
587 }
588
589 1