0b3007097f77effca18e427b2171051f979c1048
[ikiwiki.git] / IkiWiki / Plugin / comments.pm
1 #!/usr/bin/perl
2 # Copyright © 2006-2008 Joey Hess <joey@ikiwiki.info>
3 # Copyright © 2008 Simon McVittie <http://smcv.pseudorandom.co.uk/>
4 # Licensed under the GNU GPL, version 2, or any later version published by the
5 # Free Software Foundation
6 package IkiWiki::Plugin::comments;
7
8 use warnings;
9 use strict;
10 use IkiWiki 2.00;
11 use Encode;
12 use POSIX qw(strftime);
13
14 use constant PREVIEW => "Preview";
15 use constant POST_COMMENT => "Post comment";
16 use constant CANCEL => "Cancel";
17
18 my $postcomment;
19
20 sub import {
21         hook(type => "checkconfig", id => 'comments',  call => \&checkconfig);
22         hook(type => "getsetup", id => 'comments',  call => \&getsetup);
23         hook(type => "preprocess", id => '_comment', call => \&preprocess);
24         hook(type => "sessioncgi", id => 'comment', call => \&sessioncgi);
25         hook(type => "htmlize", id => "_comment", call => \&htmlize);
26         hook(type => "pagetemplate", id => "comments", call => \&pagetemplate);
27         hook(type => "cgi", id => "comments", call => \&linkcgi);
28         IkiWiki::loadplugin("inline");
29 }
30
31 sub getsetup () {
32         return
33                 plugin => {
34                         safe => 1,
35                         rebuild => 1,
36                 },
37                 comments_pagespec => {
38                         type => 'pagespec',
39                         example => 'blog/* and *!/Discussion',
40                         description => 'PageSpec of pages where comments are allowed',
41                         link => 'ikiwiki/PageSpec',
42                         safe => 1,
43                         rebuild => 1,
44                 },
45                 comments_closed_pagespec => {
46                         type => 'pagespec',
47                         example => 'blog/controversial or blog/flamewar',
48                         description => 'PageSpec of pages where posting new comments is not allowed',
49                         link => 'ikiwiki/PageSpec',
50                         safe => 1,
51                         rebuild => 1,
52                 },
53                 comments_pagename => {
54                         type => 'string',
55                         default => 'comment_',
56                         description => 'Base name for comments, e.g. "comment_" for pages like "sandbox/comment_12"',
57                         safe => 0, # manual page moving required
58                         rebuild => undef,
59                 },
60                 comments_allowdirectives => {
61                         type => 'boolean',
62                         example => 0,
63                         description => 'Interpret directives in comments?',
64                         safe => 1,
65                         rebuild => 0,
66                 },
67                 comments_allowauthor => {
68                         type => 'boolean',
69                         example => 0,
70                         description => 'Allow anonymous commenters to set an author name?',
71                         safe => 1,
72                         rebuild => 0,
73                 },
74                 comments_commit => {
75                         type => 'boolean',
76                         example => 1,
77                         description => 'commit comments to the VCS',
78                         # old uncommitted comments are likely to cause
79                         # confusion if this is changed
80                         safe => 0,
81                         rebuild => 0,
82                 },
83 }
84
85 sub checkconfig () {
86         $config{comments_commit} = 1
87                 unless defined $config{comments_commit};
88         $config{comments_pagespec} = ''
89                 unless defined $config{comments_pagespec};
90         $config{comments_closed_pagespec} = ''
91                 unless defined $config{comments_closed_pagespec};
92         $config{comments_pagename} = 'comment_'
93                 unless defined $config{comments_pagename};
94 }
95
96 sub htmlize {
97         my %params = @_;
98         return $params{content};
99 }
100
101 # FIXME: copied verbatim from meta
102 sub safeurl ($) {
103         my $url=shift;
104         if (exists $IkiWiki::Plugin::htmlscrubber::{safe_url_regexp} &&
105             defined $IkiWiki::Plugin::htmlscrubber::safe_url_regexp) {
106                 return $url=~/$IkiWiki::Plugin::htmlscrubber::safe_url_regexp/;
107         }
108         else {
109                 return 1;
110         }
111 }
112
113 sub preprocess {
114         my %params = @_;
115         my $page = $params{page};
116
117         my $format = $params{format};
118         if (defined $format && ! exists $IkiWiki::hooks{htmlize}{$format}) {
119                 error(sprintf(gettext("unsupported page format %s"), $format));
120         }
121
122         my $content = $params{content};
123         if (! defined $content) {
124                 error(gettext("comment must have content"));
125         }
126         $content =~ s/\\"/"/g;
127
128         $content = IkiWiki::filter($page, $params{destpage}, $content);
129
130         if ($config{comments_allowdirectives}) {
131                 $content = IkiWiki::preprocess($page, $params{destpage},
132                         $content);
133         }
134
135         # no need to bother with htmlize if it's just HTML
136         $content = IkiWiki::htmlize($page, $params{destpage}, $format,
137                 $content) if defined $format;
138
139         IkiWiki::run_hooks(sanitize => sub {
140                 $content = shift->(
141                         page => $page,
142                         destpage => $params{destpage},
143                         content => $content,
144                 );
145         });
146
147         # set metadata, possibly overriding [[!meta]] directives from the
148         # comment itself
149
150         my $commentuser;
151         my $commentip;
152         my $commentauthor;
153         my $commentauthorurl;
154
155         if (defined $params{username}) {
156                 $commentuser = $params{username};
157                 ($commentauthorurl, $commentauthor) =
158                         linkuser($params{username});
159         }
160         else {
161                 if (defined $params{ip}) {
162                         $commentip = $params{ip};
163                 }
164                 $commentauthor = gettext("Anonymous");
165         }
166
167         $pagestate{$page}{comments}{commentuser} = $commentuser;
168         $pagestate{$page}{comments}{commentip} = $commentip;
169         $pagestate{$page}{comments}{commentauthor} = $commentauthor;
170         $pagestate{$page}{comments}{commentauthorurl} = $commentauthorurl;
171         if (! defined $pagestate{$page}{meta}{author}) {
172                 $pagestate{$page}{meta}{author} = $commentauthor;
173         }
174         if (! defined $pagestate{$page}{meta}{authorurl}) {
175                 $pagestate{$page}{meta}{authorurl} = $commentauthorurl;
176         }
177
178         if ($config{comments_allowauthor}) {
179                 if (defined $params{claimedauthor}) {
180                         $pagestate{$page}{meta}{author} = $params{claimedauthor};
181                 }
182
183                 if (defined $params{url} and safeurl($params{url})) {
184                         $pagestate{$page}{meta}{authorurl} = $params{url};
185                 }
186         }
187         else {
188                 $pagestate{$page}{meta}{author} = $commentauthor;
189                 $pagestate{$page}{meta}{authorurl} = $commentauthorurl;
190         }
191
192         if (defined $params{subject}) {
193                 $pagestate{$page}{meta}{title} = $params{subject};
194         }
195
196         my $baseurl = urlto($params{destpage}, undef, 1);
197         my $anchor = "";
198         if ($params{page} =~ m/\/(\Q$config{comments_pagename}\E\d+)$/) {
199                 $anchor = $1;
200         }
201         $pagestate{$page}{meta}{permalink} = "${baseurl}#${anchor}";
202
203         eval q{use Date::Parse};
204         if (! $@) {
205                 my $time = str2time($params{date});
206                 $IkiWiki::pagectime{$page} = $time if defined $time;
207         }
208
209         # FIXME: hard-coded HTML (although it's just to set an ID)
210         return "<div id=\"$anchor\">$content</div>" if $anchor;
211         return $content;
212 }
213
214 # This is exactly the same as recentchanges_link :-(
215 sub linkcgi ($) {
216         my $cgi=shift;
217         if (defined $cgi->param('do') && $cgi->param('do') eq "commenter") {
218
219                 my $page=decode_utf8($cgi->param("page"));
220                 if (! defined $page) {
221                         error("missing page parameter");
222                 }
223
224                 IkiWiki::loadindex();
225
226                 my $link=bestlink("", $page);
227                 if (! length $link) {
228                         print "Content-type: text/html\n\n";
229                         print IkiWiki::misctemplate(gettext(gettext("missing page")),
230                                 "<p>".
231                                 sprintf(gettext("The page %s does not exist."),
232                                         htmllink("", "", $page)).
233                                 "</p>");
234                 }
235                 else {
236                         IkiWiki::redirect($cgi, urlto($link, undef, 1));
237                 }
238
239                 exit;
240         }
241 }
242
243 # FIXME: basically the same logic as recentchanges
244 # returns (author URL, pretty-printed version)
245 sub linkuser ($) {
246         my $user = shift;
247         my $oiduser = eval { IkiWiki::openiduser($user) };
248
249         if (defined $oiduser) {
250                 return ($user, $oiduser);
251         }
252         # FIXME: it'd be good to avoid having such a link for anonymous
253         # posts
254         else {
255                 return (IkiWiki::cgiurl(
256                                 do => 'commenter',
257                                 page => (length $config{userdir}
258                                         ? "$config{userdir}/$user"
259                                         : "$user")
260                         ), $user);
261         }
262 }
263
264 # Mostly cargo-culted from IkiWiki::plugin::editpage
265 sub sessioncgi ($$) {
266         my $cgi=shift;
267         my $session=shift;
268
269         my $do = $cgi->param('do');
270         return unless $do eq 'comment';
271
272         IkiWiki::decode_cgi_utf8($cgi);
273
274         eval q{use CGI::FormBuilder};
275         error($@) if $@;
276
277         my @buttons = (POST_COMMENT, PREVIEW, CANCEL);
278         my $form = CGI::FormBuilder->new(
279                 fields => [qw{do sid page subject editcontent type author url}],
280                 charset => 'utf-8',
281                 method => 'POST',
282                 required => [qw{editcontent}],
283                 javascript => 0,
284                 params => $cgi,
285                 action => $config{cgiurl},
286                 header => 0,
287                 table => 0,
288                 template => scalar IkiWiki::template_params('comments_form.tmpl'),
289                 # wtf does this do in editpage?
290                 wikiname => $config{wikiname},
291         );
292
293         IkiWiki::decode_form_utf8($form);
294         IkiWiki::run_hooks(formbuilder_setup => sub {
295                         shift->(title => "comment", form => $form, cgi => $cgi,
296                                 session => $session, buttons => \@buttons);
297                 });
298         IkiWiki::decode_form_utf8($form);
299
300         my $type = $form->param('type');
301         if (defined $type && length $type && $IkiWiki::hooks{htmlize}{$type}) {
302                 $type = IkiWiki::possibly_foolish_untaint($type);
303         }
304         else {
305                 $type = $config{default_pageext};
306         }
307         my @page_types;
308         if (exists $IkiWiki::hooks{htmlize}) {
309                 @page_types = grep { ! /^_/ } keys %{$IkiWiki::hooks{htmlize}};
310         }
311
312         $form->field(name => 'do', type => 'hidden');
313         $form->field(name => 'sid', type => 'hidden', value => $session->id,
314                 force => 1);
315         $form->field(name => 'page', type => 'hidden');
316         $form->field(name => 'subject', type => 'text', size => 72);
317         $form->field(name => 'editcontent', type => 'textarea', rows => 10);
318         $form->field(name => "type", value => $type, force => 1,
319                 type => 'select', options => \@page_types);
320
321         $form->tmpl_param(username => $session->param('name'));
322
323         if ($config{comments_allowauthor} and
324             ! defined $session->param('name')) {
325                 $form->tmpl_param(allowauthor => 1);
326                 $form->field(name => 'author', type => 'text', size => '40');
327                 $form->field(name => 'url', type => 'text', size => '40');
328         }
329         else {
330                 $form->tmpl_param(allowauthor => 0);
331                 $form->field(name => 'author', type => 'hidden', value => '',
332                         force => 1);
333                 $form->field(name => 'url', type => 'hidden', value => '',
334                         force => 1);
335         }
336
337         # The untaint is OK (as in editpage) because we're about to pass
338         # it to file_pruned anyway
339         my $page = $form->field('page');
340         $page = IkiWiki::possibly_foolish_untaint($page);
341         if (! defined $page || ! length $page ||
342                 IkiWiki::file_pruned($page, $config{srcdir})) {
343                 error(gettext("bad page name"));
344         }
345
346         # FIXME: is this right? Or should we be using the candidate subpage
347         # (whatever that might mean) as the base URL?
348         my $baseurl = urlto($page, undef, 1);
349
350         $form->title(sprintf(gettext("commenting on %s"),
351                         IkiWiki::pagetitle($page)));
352
353         $form->tmpl_param('helponformattinglink',
354                 htmllink($page, $page, 'ikiwiki/formatting',
355                         noimageinline => 1,
356                         linktext => 'FormattingHelp'),
357                         allowdirectives => $config{allow_directives});
358
359         if ($form->submitted eq CANCEL) {
360                 # bounce back to the page they wanted to comment on, and exit.
361                 # CANCEL need not be considered in future
362                 IkiWiki::redirect($cgi, urlto($page, undef, 1));
363                 exit;
364         }
365
366         if (not exists $pagesources{$page}) {
367                 error(sprintf(gettext(
368                         "page '%s' doesn't exist, so you can't comment"),
369                         $page));
370         }
371
372         if (pagespec_match($page, $config{comments_closed_pagespec},
373                 location => $page)) {
374                 error(sprintf(gettext(
375                         "comments on page '%s' are closed"),
376                         $page));
377         }
378
379         # Set a flag to indicate that we're posting a comment,
380         # so that postcomment() can tell it should match.
381         $postcomment=1;
382         IkiWiki::check_canedit($page, $cgi, $session);
383         $postcomment=0;
384
385         # FIXME: rather a simplistic way to make the comments...
386         my $i = 0;
387         my $file;
388         my $location;
389         do {
390                 $i++;
391                 $location = "$page/$config{comments_pagename}$i";
392         } while (-e "$config{srcdir}/$location._comment");
393
394         my $content = "[[!_comment format=$type\n";
395
396         # FIXME: handling of double quotes probably wrong?
397         if (defined $session->param('name')) {
398                 my $username = $session->param('name');
399                 $username =~ s/"/&quot;/g;
400                 $content .= " username=\"$username\"\n";
401         }
402         elsif (defined $ENV{REMOTE_ADDR}) {
403                 my $ip = $ENV{REMOTE_ADDR};
404                 if ($ip =~ m/^([.0-9]+)$/) {
405                         $content .= " ip=\"$1\"\n";
406                 }
407         }
408
409         if ($config{comments_allowauthor}) {
410                 my $author = $form->field('author');
411                 if (length $author) {
412                         $author =~ s/"/&quot;/g;
413                         $content .= " claimedauthor=\"$author\"\n";
414                 }
415                 my $url = $form->field('url');
416                 if (length $url) {
417                         $url =~ s/"/&quot;/g;
418                         $content .= " url=\"$url\"\n";
419                 }
420         }
421
422         my $subject = $form->field('subject');
423         if (length $subject) {
424                 $subject =~ s/"/&quot;/g;
425                 $content .= " subject=\"$subject\"\n";
426         }
427
428         $content .= " date=\"" . decode_utf8(strftime('%Y-%m-%dT%H:%M:%SZ', gmtime)) . "\"\n";
429
430         my $editcontent = $form->field('editcontent') || '';
431         $editcontent =~ s/\r\n/\n/g;
432         $editcontent =~ s/\r/\n/g;
433         $editcontent =~ s/"/\\"/g;
434         $content .= " content=\"\"\"\n$editcontent\n\"\"\"]]\n";
435
436         # This is essentially a simplified version of editpage:
437         # - the user does not control the page that's created, only the parent
438         # - it's always a create operation, never an edit
439         # - this means that conflicts should never happen
440         # - this means that if they do, rocks fall and everyone dies
441
442         if ($form->submitted eq PREVIEW) {
443                 my $preview = IkiWiki::htmlize($location, $page, '_comment',
444                                 IkiWiki::linkify($page, $page,
445                                         IkiWiki::preprocess($page, $page,
446                                                 IkiWiki::filter($location,
447                                                         $page, $content),
448                                                 0, 1)));
449                 IkiWiki::run_hooks(format => sub {
450                                 $preview = shift->(page => $page,
451                                         content => $preview);
452                         });
453
454                 my $template = template("comments_display.tmpl");
455                 $template->param(content => $preview);
456                 $template->param(title => $form->field('subject'));
457                 $template->param(ctime => displaytime(time));
458
459                 $form->tmpl_param(page_preview => $template->output);
460         }
461         else {
462                 $form->tmpl_param(page_preview => "");
463         }
464
465         if ($form->submitted eq POST_COMMENT && $form->validate) {
466                 my $file = "$location._comment";
467
468                 IkiWiki::checksessionexpiry($cgi, $session);
469
470                 # FIXME: could probably do some sort of graceful retry
471                 # on error? Would require significant unwinding though
472                 writefile($file, $config{srcdir}, $content);
473
474                 my $conflict;
475
476                 if ($config{rcs} and $config{comments_commit}) {
477                         my $message = gettext("Added a comment");
478                         if (defined $form->field('subject') &&
479                                 length $form->field('subject')) {
480                                 $message = sprintf(
481                                         gettext("Added a comment: %s"),
482                                         $form->field('subject'));
483                         }
484
485                         IkiWiki::rcs_add($file);
486                         IkiWiki::disable_commit_hook();
487                         $conflict = IkiWiki::rcs_commit_staged($message,
488                                 $session->param('name'), $ENV{REMOTE_ADDR});
489                         IkiWiki::enable_commit_hook();
490                         IkiWiki::rcs_update();
491                 }
492
493                 # Now we need a refresh
494                 require IkiWiki::Render;
495                 IkiWiki::refresh();
496                 IkiWiki::saveindex();
497
498                 # this should never happen, unless a committer deliberately
499                 # breaks it or something
500                 error($conflict) if defined $conflict;
501
502                 # Bounce back to where we were, but defeat broken caches
503                 my $anticache = "?updated=$page/$config{comments_pagename}$i";
504                 IkiWiki::redirect($cgi, urlto($page, undef, 1).$anticache);
505         }
506         else {
507                 IkiWiki::showform ($form, \@buttons, $session, $cgi,
508                         forcebaseurl => $baseurl);
509         }
510
511         exit;
512 }
513
514 sub pagetemplate (@) {
515         my %params = @_;
516
517         my $page = $params{page};
518         my $template = $params{template};
519
520         if ($template->query(name => 'comments')) {
521                 my $comments = undef;
522
523                 my $open = 0;
524                 my $shown = 0;
525                 if (pagespec_match($page,
526                                 $config{comments_pagespec},
527                                 location => $page)) {
528                         $shown = 1;
529                         $open = length $config{cgiurl} > 0;
530                 }
531
532                 if (pagespec_match($page, "*/$config{comments_pagename}*",
533                                 location => $page)) {
534                         $shown = 0;
535                         $open = 0;
536                 }
537                 if (length $config{comments_closed_pagespec} &&
538                     pagespec_match($page, $config{comments_closed_pagespec},
539                                 location => $page)) {
540                         $shown = 0;
541                         $open = 0;
542                 }
543
544                 if ($shown) {
545                         $comments = IkiWiki::preprocess_inline(
546                                 pages => "internal($page/$config{comments_pagename}*)",
547                                 template => 'comments_display',
548                                 show => 0,
549                                 reverse => 'yes',
550                                 page => $page,
551                                 destpage => $params{destpage},
552                                 feedfile => 'comments',
553                                 emptyfeeds => 'no',
554                         );
555                 }
556
557                 if (defined $comments && length $comments) {
558                         $template->param(comments => $comments);
559                 }
560
561                 if ($open) {
562                         my $commenturl = IkiWiki::cgiurl(do => 'comment',
563                                 page => $page);
564                         $template->param(commenturl => $commenturl);
565                 }
566         }
567
568         if ($template->query(name => 'commentuser')) {
569                 $template->param(commentuser =>
570                         $pagestate{$page}{comments}{commentuser});
571         }
572
573         if ($template->query(name => 'commentip')) {
574                 $template->param(commentip =>
575                         $pagestate{$page}{comments}{commentip});
576         }
577
578         if ($template->query(name => 'commentauthor')) {
579                 $template->param(commentauthor =>
580                         $pagestate{$page}{comments}{commentauthor});
581         }
582
583         if ($template->query(name => 'commentauthorurl')) {
584                 $template->param(commentauthorurl =>
585                         $pagestate{$page}{comments}{commentauthorurl});
586         }
587 }
588
589 package IkiWiki::PageSpec;
590
591 sub match_postcomment ($$;@) {
592         my $page = shift;
593         my $glob = shift;
594
595         if (! $postcomment) {
596                 return IkiWiki::FailReason->new("not posting a comment");
597         }
598         return match_glob($page, $glob);
599 }
600
601 1