cgi-bin/loona.lua
author Timm S. Mueller <tmueller@neoscientists.org>
Thu, 08 Mar 2007 00:14:00 +0100
changeset 124 326b29cf2a7c
parent 122 5da9f669cd06
child 129 99b3008f0c77
permissions -rw-r--r--
[New] links now created dynamically; added saveindex()
tmueller@0
     1
tmueller@0
     2
--
tmueller@0
     3
--	loona - tiny CMS
tmueller@0
     4
--	Written by Timm S. Mueller <tmueller at neoscientists.org>
tmueller@0
     5
--	See copyright notice in COPYRIGHT
tmueller@0
     6
--
tmueller@0
     7
tmueller@68
     8
local tek = require "tek"
tmueller@68
     9
local cgi = require "tek.cgi"
tmueller@68
    10
local posix = require "tek.posix"
tmueller@0
    11
require "tek.cgi.request"
tmueller@0
    12
require "tek.cgi.request.args"
tmueller@0
    13
require "tek.cgi.session"
tmueller@0
    14
require "tek.web"
tmueller@0
    15
require "tek.web.markup"
tmueller@0
    16
require "tek.util"
tmueller@0
    17
tmueller@23
    18
tmueller@0
    19
local boxed_G = { 
tmueller@0
    20
	string = string, table = table,
tmueller@0
    21
	assert = assert, collectgarbage = collectgarbage, dofile = dofile,
tmueller@0
    22
	error = error, getfenv = getfenv, getmetatable = getmetatable,
tmueller@0
    23
	ipairs = ipairs, load = load, loadfile = loadfile, loadstring = loadstring,
tmueller@0
    24
	next = next, pairs = pairs, pcall = pcall, print = print,
tmueller@0
    25
	rawequal = rawequal, rawget = rawget, rawset = rawset, require = require,
tmueller@0
    26
	select = select, setfenv = setfenv, setmetatable = setmetatable,
tmueller@0
    27
	tonumber = tonumber, tostring = tostring, type = type, unpack = unpack,
tmueller@0
    28
	xpcall = xpcall
tmueller@0
    29
}
tmueller@0
    30
tmueller@68
    31
local table, string, assert, unpack, ipairs, pairs, type, require =
tmueller@68
    32
	table, string, assert, unpack, ipairs, pairs, type, require
tmueller@0
    33
local setmetatable, setfenv, getfenv = setmetatable, setfenv, getfenv
tmueller@0
    34
local open, remove, rename, getenv, time =
tmueller@0
    35
	io.open, os.remove, os.rename, os.getenv, os.time
tmueller@0
    36
tmueller@68
    37
local sectionfname, langs, docname
tmueller@0
    38
tmueller@0
    39
tmueller@0
    40
module "loona"
tmueller@0
    41
tmueller@0
    42
tmueller@0
    43
_VERSION = 2
tmueller@80
    44
_REVISION = 2
tmueller@0
    45
tmueller@0
    46
tmueller@0
    47
out = tek.web.out
tmueller@0
    48
setheader = tek.web.setheader
tmueller@0
    49
session = cgi.session
tmueller@0
    50
request = cgi.request
tmueller@0
    51
args = request.args
tmueller@0
    52
encodeform = cgi.encodeform
tmueller@0
    53
loadhtml = tek.web.include.load
tmueller@0
    54
source = tek.source
tmueller@0
    55
domarkup = tek.web.markup.main
tmueller@0
    56
expire = tek.util.expire
tmueller@0
    57
tmueller@0
    58
tmueller@20
    59
local function dbmsg(msg, detail)
tmueller@80
    60
	return (msg and detail and config.debug) and
tmueller@47
    61
		("%s : %s"):format(msg, detail) or msg
tmueller@20
    62
end
tmueller@20
    63
tmueller@20
    64
tmueller@0
    65
local function checkprofilename(c)
tmueller@47
    66
	assert(c:match("^%w+$") and c ~= "current",
tmueller@47
    67
		dbmsg("Invalid profile name", c))
tmueller@0
    68
	return c
tmueller@0
    69
end
tmueller@0
    70
tmueller@0
    71
tmueller@47
    72
local function checkbodyname(s)
tmueller@0
    73
	s = s or "main"
tmueller@47
    74
	assert(s:match("^[%w_]*%w+[%w_]*$"), dbmsg("Invalid body name", s))
tmueller@0
    75
	return s
tmueller@0
    76
end
tmueller@0
    77
tmueller@0
    78
tmueller@0
    79
local function deletedir(dst)
tmueller@0
    80
	for e in tek.util.readdir(dst) do
tmueller@47
    81
 		local success, msg = remove(dst .. "/" .. e)
tmueller@20
    82
		assert(success, dbmsg("Error removing entry in profile", msg))
tmueller@0
    83
	end
tmueller@0
    84
	return remove(dst)
tmueller@0
    85
end
tmueller@0
    86
tmueller@0
    87
tmueller@0
    88
local function copyprofile(contentdir, lang, srcprofile, newprofile)
tmueller@68
    89
	local src = ("%s/%s_%s"):format(contentdir, srcprofile, lang)
tmueller@20
    90
	assert(posix.stat(src, "mode") == "directory",
tmueller@20
    91
		dbmsg("Not a directory", src))
tmueller@68
    92
	local dst = ("%s/%s_%s"):format(contentdir, newprofile, lang)
tmueller@0
    93
	local success, msg = posix.mkdir(dst)
tmueller@20
    94
	assert(success, dbmsg("Error creating profile directory", msg))
tmueller@0
    95
	for e in tek.util.readdir(src) do
tmueller@0
    96
		local ext = e:match("^[^.].*%.([^.]*)$")
tmueller@0
    97
		if ext ~= "LOCK" then
tmueller@0
    98
			local f = src .. "/" .. e
tmueller@0
    99
			if posix.stat(f, "mode") == "file" then
tmueller@0
   100
				success, msg = tek.copyfile(f, dst .. "/" .. e)
tmueller@20
   101
				assert(success, dbmsg("Error copying file", msg))
tmueller@0
   102
			end
tmueller@0
   103
		end
tmueller@0
   104
	end
tmueller@0
   105
end
tmueller@0
   106
tmueller@0
   107
tmueller@0
   108
local function publishprofile(contentdir, lang, profile)
tmueller@68
   109
	local newpath = ("%s/current_%s"):format(contentdir, lang)
tmueller@68
   110
	local tmppath = newpath .. "." .. session.name
tmueller@23
   111
	local success, msg = posix.symlink(profile .. "_" .. lang, tmppath)
tmueller@20
   112
	assert(success, dbmsg("Cannot create symlink", msg))
tmueller@23
   113
	success, msg = rename(tmppath, newpath)
tmueller@23
   114
	assert(success, dbmsg("Cannot put symlink in place", msg))
tmueller@0
   115
end
tmueller@0
   116
tmueller@0
   117
tmueller@20
   118
local function lookupname(tab, val)
tmueller@0
   119
	if tab then
tmueller@0
   120
		for i, v in ipairs(tab) do
tmueller@20
   121
			if v.name == val then
tmueller@0
   122
				return i
tmueller@0
   123
			end
tmueller@0
   124
		end
tmueller@0
   125
	end
tmueller@0
   126
end
tmueller@0
   127
tmueller@0
   128
tmueller@20
   129
--	Index sections, determine accessibility and visibility in menu
tmueller@20
   130
tmueller@20
   131
local function indexsections(s)
tmueller@0
   132
	for _, e in ipairs(s) do
tmueller@0
   133
		if e.subs then
tmueller@20
   134
			indexsections(e.subs)
tmueller@0
   135
		end
tmueller@0
   136
		e.notvalid = (not secure and e.secure) or 
tmueller@0
   137
			(not authuser and e.secret) or nil
tmueller@0
   138
		e.notvisible = e.notvalid or not authuser and e.hidden or nil
tmueller@16
   139
		s[e.name] = e
tmueller@0
   140
	end
tmueller@0
   141
end
tmueller@0
   142
tmueller@0
   143
tmueller@20
   144
--	Decompose section path into a stack of sections, returning only up to
tmueller@0
   145
--	the last valid element in the path. additionally returns the table of
tmueller@0
   146
--	the last section path element (or the default section)
tmueller@0
   147
tmueller@27
   148
local function getsection(section, authuser, path, default)
tmueller@27
   149
	local tab = { { entries = sections, name = default } }
tmueller@27
   150
	local ss = sections
tmueller@0
   151
	local sectionpath
tmueller@0
   152
	(path or default):gsub("(%w+)/?", function(a)
tmueller@27
   153
		if ss then
tmueller@27
   154
			local s = ss[a]
tmueller@20
   155
			if s and not s.notvalid then
tmueller@20
   156
				sectionpath = s
tmueller@0
   157
				tab[#tab].name = a
tmueller@27
   158
				ss = s.subs
tmueller@27
   159
				if ss then
tmueller@27
   160
					table.insert(tab, { entries = ss })
tmueller@0
   161
				end
tmueller@0
   162
			else
tmueller@27
   163
				ss = nil -- stop.
tmueller@0
   164
			end
tmueller@0
   165
		end
tmueller@0
   166
	end)
tmueller@0
   167
	if not section and not sectionpath then
tmueller@27
   168
		sectionpath = sections[default]
tmueller@0
   169
		if sectionpath then
tmueller@0
   170
			table.insert(tab, { entries = sectionpath.subs })
tmueller@0
   171
		end
tmueller@0
   172
	end
tmueller@0
   173
	return tab, sectionpath
tmueller@0
   174
end
tmueller@0
   175
tmueller@0
   176
tmueller@27
   177
local function getpath(menus, delimiter)
tmueller@0
   178
	local t = { }
tmueller@27
   179
	for _, menu in ipairs(menus) do
tmueller@0
   180
		if menu.name then
tmueller@0
   181
			table.insert(t, menu.name)
tmueller@0
   182
		end
tmueller@0
   183
	end
tmueller@0
   184
	return table.concat(t, delimiter or "/")
tmueller@0
   185
end
tmueller@0
   186
tmueller@0
   187
tmueller@20
   188
--	Descending into the sections table alongside the current path,
tmueller@20
   189
--	return the filename to include, defaulting to its parent value
tmueller@20
   190
--	(or the default specified)
tmueller@0
   191
tmueller@27
   192
local function getsectionfile(menus, path, ext, default)
tmueller@20
   193
	local t, val = { }
tmueller@27
   194
	for _, menu in ipairs(menus) do
tmueller@20
   195
		if menu.entries and menu.entries[menu.name] then
tmueller@20
   196
			table.insert(t, menu.name)
tmueller@20
   197
			local fn = table.concat(t, "_") .. ext
tmueller@0
   198
			if posix.stat(path .. "/" .. fn, "mode") == "file" then
tmueller@0
   199
				val = fn
tmueller@0
   200
			end
tmueller@0
   201
		end
tmueller@0
   202
	end
tmueller@0
   203
	return val or default
tmueller@0
   204
end
tmueller@0
   205
tmueller@0
   206
tmueller@45
   207
local function deletesection(dir, fname)
tmueller@0
   208
	local fullname = dir .. "/" .. fname
tmueller@0
   209
	local success, msg = remove(fullname)
tmueller@0
   210
	if success then
tmueller@0
   211
		local pat = "^" .. 
tmueller@0
   212
			fname:gsub("%^%$%(%)%%%.%[%]%*%+%-%?", "%%%1") .. "%..*$"
tmueller@0
   213
		for e in tek.util.readdir(dir) do
tmueller@0
   214
			if e:match(pat) then
tmueller@0
   215
				remove(dir .. "/" .. e)
tmueller@0
   216
			end
tmueller@0
   217
		end
tmueller@0
   218
	end
tmueller@0
   219
	return success, msg
tmueller@0
   220
end
tmueller@0
   221
tmueller@0
   222
tmueller@20
   223
--	Add element to path
tmueller@0
   224
tmueller@20
   225
local function addtopath(tab, path, e)
tmueller@0
   226
	path:gsub("(%w+)/?", function(a)
tmueller@20
   227
		if tab then
tmueller@20
   228
			local s = tab[a]
tmueller@20
   229
			if s then
tmueller@20
   230
				if not s.subs then
tmueller@20
   231
					s.subs = { }
tmueller@0
   232
				end
tmueller@20
   233
				tab = s.subs
tmueller@0
   234
			else
tmueller@20
   235
				table.insert(tab, e)
tmueller@20
   236
				tab[a] = e
tmueller@20
   237
 				tab = nil -- stop
tmueller@0
   238
			end
tmueller@0
   239
		end
tmueller@0
   240
	end)
tmueller@0
   241
end
tmueller@0
   242
tmueller@0
   243
tmueller@20
   244
--	Remove element from path
tmueller@0
   245
tmueller@20
   246
local function rmpath(tab, path)
tmueller@20
   247
	local parent
tmueller@0
   248
	path:gsub("(%w+)/?", function(a)
tmueller@20
   249
		if tab then
tmueller@20
   250
			local idx = lookupname(tab, a)
tmueller@20
   251
			if idx then
tmueller@20
   252
				if tab[idx].subs then
tmueller@20
   253
					parent = tab[idx]
tmueller@20
   254
					tab = tab[idx].subs
tmueller@0
   255
				else
tmueller@20
   256
					table.remove(tab, idx)
tmueller@43
   257
					tab[a] = nil
tmueller@20
   258
					if #tab == 0 and parent then
tmueller@20
   259
						parent.subs = nil
tmueller@0
   260
					end
tmueller@20
   261
					tab = nil
tmueller@0
   262
				end
tmueller@0
   263
			end
tmueller@0
   264
		end
tmueller@0
   265
	end)
tmueller@0
   266
end
tmueller@0
   267
tmueller@0
   268
tmueller@0
   269
-------------------------------------------------------------------------------
tmueller@0
   270
tmueller@0
   271
tmueller@8
   272
--	Produce page title
tmueller@8
   273
tmueller@8
   274
function title()
tmueller@8
   275
	return section and (section.title or section.label or section.name) or ""
tmueller@8
   276
end
tmueller@8
   277
tmueller@8
   278
tmueller@47
   279
--	Create proxy for on-demand loading of locale strings
tmueller@0
   280
tmueller@47
   281
locale = { }
tmueller@47
   282
local locmt = { }
tmueller@47
   283
locmt.__index = function(_, key)
tmueller@47
   284
	for _, l in ipairs(langs) do
tmueller@47
   285
		locmt.__locale = source(config.localedir .. "/" .. l)
tmueller@47
   286
		if locmt.__locale then
tmueller@47
   287
			break
tmueller@0
   288
		end
tmueller@0
   289
	end
tmueller@121
   290
	locmt.__index = function(tab, key)
tmueller@121
   291
		return locmt.__locale[key] or key
tmueller@121
   292
	end
tmueller@121
   293
	return locmt.__locale[key] or key
tmueller@0
   294
end
tmueller@47
   295
setmetatable(locale, locmt)
tmueller@0
   296
tmueller@0
   297
tmueller@0
   298
--	Find element in path
tmueller@0
   299
tmueller@0
   300
function checkpath(tab, path)
tmueller@0
   301
	local res, idx
tmueller@0
   302
	path:gsub("(%w+)/?", function(a)
tmueller@0
   303
		if tab then
tmueller@20
   304
			local i = lookupname(tab, a)
tmueller@0
   305
			if i then
tmueller@0
   306
				res, idx = tab, i
tmueller@0
   307
				tab = tab[i].subs
tmueller@0
   308
			else
tmueller@0
   309
				res, idx = nil, nil
tmueller@0
   310
			end
tmueller@0
   311
		end
tmueller@0
   312
	end)
tmueller@0
   313
	return res, idx
tmueller@0
   314
end
tmueller@0
   315
tmueller@0
   316
tmueller@0
   317
--	Run a site function snippet, with full error recovery
tmueller@0
   318
--	(also recovers from errors in error handling function)
tmueller@0
   319
tmueller@23
   320
function dosnippet(config, func, errfunc)
tmueller@0
   321
	local ret = { tek.catch(func) }
tmueller@0
   322
	if ret[1] == 0 or (errfunc and tek.catch(errfunc) == 0) then
tmueller@0
   323
		return unpack(ret)
tmueller@0
   324
	end
tmueller@0
   325
	out("<h2>Error</h2>")
tmueller@68
   326
	out("<h3>" .. cgi.encodeform(ret[2] or "") .. "</h3>")
tmueller@80
   327
	if config.debug then
tmueller@0
   328
		if type(ret[3]) == "string" then
tmueller@68
   329
			out("<p>" .. cgi.encodeform(ret[3]) .. "</p>")
tmueller@0
   330
		end
tmueller@80
   331
		if ret[4] and config.debug then
tmueller@68
   332
			out("<pre>" .. cgi.encodeform(ret[4]) .. "</pre>")
tmueller@0
   333
		end
tmueller@0
   334
	end
tmueller@0
   335
end	
tmueller@0
   336
tmueller@0
   337
tmueller@0
   338
function lockfile(newfile)
tmueller@0
   339
	return not session and true or 
tmueller@0
   340
		posix.symlink(session.filename, newfile .. ".LOCK")
tmueller@0
   341
end
tmueller@0
   342
tmueller@0
   343
tmueller@0
   344
function unlockfile(dstfile)
tmueller@0
   345
	return not session and true or remove(dstfile .. ".LOCK")
tmueller@0
   346
end
tmueller@0
   347
tmueller@0
   348
tmueller@124
   349
function saveindex()
tmueller@124
   350
	local tempname = sectionfname .. "." .. session.name
tmueller@124
   351
	local f, msg = open(tempname, "wb")
tmueller@124
   352
	assert(f, dbmsg("Error opening section file for writing", msg))
tmueller@124
   353
	tek.dump(sections, function(...)
tmueller@124
   354
		f:write(unpack(arg))
tmueller@124
   355
	end)
tmueller@124
   356
	f:close()
tmueller@124
   357
	local success, msg = rename(tempname, sectionfname)
tmueller@124
   358
	assert(success, dbmsg("Error renaming section file", msg))
tmueller@124
   359
end
tmueller@124
   360
tmueller@124
   361
tmueller@45
   362
function savesection(dir, fname, content)
tmueller@0
   363
	fname = dir .. "/" .. fname
tmueller@0
   364
	local f, msg = open(fname, "wb")
tmueller@20
   365
	assert(f, dbmsg("Could not open file for writing", msg))
tmueller@0
   366
	f:write(content or "")
tmueller@0
   367
	f:close()
tmueller@0
   368
end
tmueller@0
   369
tmueller@23
   370
tmueller@20
   371
--	Run extension in a controlled environment
tmueller@0
   372
tmueller@0
   373
function include(fname, ...)
tmueller@47
   374
	assert(not fname:match("%W"), dbmsg("Invalid include name", fname))
tmueller@47
   375
	local fname2 = ("%s/%s.lua"):format(config.extdir, fname)
tmueller@0
   376
	local f, msg = open(fname2)
tmueller@20
   377
	assert(f, dbmsg("Cannot open file", msg))
tmueller@0
   378
	local parsed, msg = loadhtml(f, "loona.out", fname2)
tmueller@20
   379
	assert(parsed, dbmsg("Syntax error", msg))
tmueller@0
   380
 	local fenv = {
tmueller@0
   381
 		arg = arg,
tmueller@0
   382
 		loona = {
tmueller@0
   383
 			out = out,
tmueller@0
   384
 			setheader = setheader,
tmueller@0
   385
			hidden = hidden,
tmueller@15
   386
			link = link,
tmueller@0
   387
			elink = elink,
tmueller@68
   388
			plink = plink,
tmueller@0
   389
			href = href,
tmueller@0
   390
			checkpath = checkpath,
tmueller@0
   391
			authuser = authuser,
tmueller@0
   392
			document = document,
tmueller@0
   393
			contentdir = contentdir,
tmueller@0
   394
			profile = profile,
tmueller@0
   395
			pubprofile = pubprofile,
tmueller@0
   396
			lang = lang,
tmueller@47
   397
			locale = locale,
tmueller@0
   398
			secure = secure,
tmueller@0
   399
			config = config,
tmueller@27
   400
			sectionpath = sectionpath,
tmueller@27
   401
			sections = sections,
tmueller@0
   402
			session = session,
tmueller@104
   403
			loginfailed = loginfailed
tmueller@0
   404
		}
tmueller@0
   405
	}
tmueller@0
   406
 	setmetatable(fenv, { __index = boxed_G }) -- boxed global environment
tmueller@0
   407
	setfenv(parsed, fenv)
tmueller@0
   408
	return parsed()
tmueller@0
   409
end
tmueller@0
   410
tmueller@0
   411
tmueller@68
   412
--	produce link target, propagate lang, profile, session
tmueller@68
   413
tmueller@0
   414
function href(section, ...)
tmueller@68
   415
	local target = section and docname .. "/" .. section or docname
tmueller@68
   416
	if session or profile ~= pubprofile then
tmueller@68
   417
		return tek.web.gethref(target, { "profile", "session", "lang", 
tmueller@68
   418
			unpack(arg) })
tmueller@0
   419
	end
tmueller@68
   420
	return tek.web.gethref(target, { "lang", unpack(arg) })
tmueller@0
   421
end
tmueller@0
   422
tmueller@68
   423
local function ilink(target, text, extra)
tmueller@68
   424
	return ('<a href="%s"%s>%s</a>'):format(target, extra or "", text)
tmueller@0
   425
end
tmueller@0
   426
tmueller@68
   427
--	internal link, propagation of lang, profile, session
tmueller@0
   428
tmueller@68
   429
function link(section, text, ...)
tmueller@83
   430
	return ilink(href(section, unpack(arg)), text or section)
tmueller@0
   431
end
tmueller@0
   432
tmueller@68
   433
--	external link (opens in a new window), no argument propagation
tmueller@0
   434
tmueller@68
   435
function elink(target, text)
tmueller@122
   436
	return ilink(target, text or target, not config.extlinksamewindow and
tmueller@83
   437
		' class="extlink" onclick="void(window.open(this.href, \'\', \'\')); return false;"')
tmueller@0
   438
end
tmueller@0
   439
tmueller@68
   440
--	plain link, no argument propagation
tmueller@68
   441
tmueller@68
   442
function plink(section, text, ...)
tmueller@68
   443
	return ilink(tek.web.gethref(section, arg), text or section)
tmueller@68
   444
end
tmueller@68
   445
tmueller@68
   446
--	user interface link, propagation of lang, profile, session
tmueller@68
   447
tmueller@68
   448
function uilink(section, text, ...)
tmueller@83
   449
	return ilink(href(section, unpack(arg)), text or section)
tmueller@68
   450
end
tmueller@68
   451
tmueller@68
   452
--	produce a hidden input value in forms
tmueller@0
   453
tmueller@0
   454
function hidden(name, value)
tmueller@68
   455
	return not value and "" or
tmueller@68
   456
		('<input type="hidden" name="%s" value="%s" />'):format(name, value)
tmueller@0
   457
end
tmueller@0
   458
tmueller@0
   459
tmueller@0
   460
function getprofiles(contentdir, lang)
tmueller@0
   461
	local t = { }
tmueller@0
   462
	for f in tek.util.readdir(contentdir) do
tmueller@0
   463
		if posix.lstat(contentdir .. "/" .. f, "mode") == "directory" then
tmueller@0
   464
			local e = f:match("^(%w+)_" .. lang .. "$")
tmueller@0
   465
 			if e then
tmueller@0
   466
	 			t[e] = e
tmueller@0
   467
 	 		end
tmueller@0
   468
		end
tmueller@0
   469
	end
tmueller@0
   470
	return t
tmueller@0
   471
end
tmueller@0
   472
tmueller@0
   473
tmueller@80
   474
--	Functions to produce a hierarchical navigation menu
tmueller@80
   475
tmueller@124
   476
local newent = { name = "new", label = "[+]",
tmueller@124
   477
	action="actionnew=true" }
tmueller@124
   478
tmueller@80
   479
local function rmenu(level, linkf, path)
tmueller@124
   480
	local sub = (authuser and level == #submenus + 1) and
tmueller@124
   481
		{ name = "new", entries = { }} or submenus[level]
tmueller@124
   482
 	if sub and sub.entries then
tmueller@80
   483
		local visible = { }
tmueller@80
   484
		for _, e in ipairs(sub.entries) do
tmueller@80
   485
			if not e.notvisible then
tmueller@80
   486
				table.insert(visible, e)
tmueller@80
   487
			end
tmueller@80
   488
		end
tmueller@124
   489
		if authuser then
tmueller@124
   490
			table.insert(visible, newent)
tmueller@124
   491
		end
tmueller@80
   492
		if #visible > 0 then
tmueller@87
   493
			out('<ul id="menulevel' .. level .. '">\n')
tmueller@80
   494
			for _, e in ipairs(visible) do
tmueller@80
   495
				local label = encodeform(e.label or e.name)
tmueller@80
   496
				local newpath = path and path .. "/" .. e.name or e.name
tmueller@80
   497
				local active = (e.name == sub.name)
tmueller@87
   498
				out('<li>\n')
tmueller@80
   499
				linkf(newpath, label, active, e.action)
tmueller@80
   500
				if active then
tmueller@80
   501
					rmenu(level + 1, linkf, newpath)
tmueller@80
   502
				end
tmueller@87
   503
				out('</li>\n')
tmueller@80
   504
			end
tmueller@87
   505
			out('</ul>\n')
tmueller@80
   506
		end
tmueller@80
   507
	end
tmueller@80
   508
end
tmueller@80
   509
tmueller@87
   510
local function menulink(path, label, active, ...)
tmueller@87
   511
	out(('<a %shref="%s">%s</a>\n'):format(active and 'class="active" ' or "",
tmueller@87
   512
		href(path, unpack(arg)), label))
tmueller@80
   513
end
tmueller@80
   514
tmueller@80
   515
function menu(level, linkf)
tmueller@87
   516
	rmenu(level or 1, linkf or menulink)
tmueller@80
   517
end
tmueller@80
   518
tmueller@80
   519
tmueller@0
   520
-- Init
tmueller@0
   521
tmueller@0
   522
local function init()
tmueller@0
   523
	
tmueller@0
   524
	-- get list of languages, in order of preference
tmueller@0
   525
	
tmueller@0
   526
	langs = { args.lang and args.lang:match("^%w+$") }
tmueller@80
   527
	if config.browserlang then
tmueller@0
   528
		local s = getenv("HTTP_ACCEPT_LANGUAGE")
tmueller@0
   529
		while s do
tmueller@0
   530
			local l, r = s:match("^([%w.=]+)[,;](.*)$")
tmueller@0
   531
			l = l or s
tmueller@0
   532
			s = r
tmueller@0
   533
			if l:match("^%w+$") then
tmueller@0
   534
				table.insert(langs, l)
tmueller@0
   535
			end
tmueller@0
   536
		end
tmueller@0
   537
	end
tmueller@0
   538
	table.insert(langs, config.deflang)
tmueller@0
   539
	
tmueller@0
   540
	-- get list of possible profiles
tmueller@0
   541
	
tmueller@0
   542
	local profiles = { }
tmueller@0
   543
	for e in tek.util.readdir(config.contentdir) do
tmueller@0
   544
		profiles[e] = e
tmueller@0
   545
	end
tmueller@0
   546
	
tmueller@0
   547
	-- get pubprofile
tmueller@0
   548
	
tmueller@0
   549
	for _, lang in ipairs(langs) do
tmueller@0
   550
		local p = posix.readlink(config.contentdir .. "/current_" .. lang)
tmueller@0
   551
		p = p and p:match("^(%w+)_" .. lang .. "$")
tmueller@0
   552
		if p then
tmueller@0
   553
			pubprofile = p
tmueller@0
   554
			break
tmueller@0
   555
		end
tmueller@0
   556
	end
tmueller@0
   557
	
tmueller@0
   558
	-- get profile
tmueller@0
   559
	
tmueller@0
   560
	local checkprofile = authuser and args.profile or pubprofile or "default"
tmueller@0
   561
	for _, l in ipairs(langs) do
tmueller@0
   562
		if profiles[checkprofile .. "_" .. l] then
tmueller@0
   563
			profile = checkprofile
tmueller@0
   564
			lang = l
tmueller@0
   565
			break
tmueller@0
   566
		end
tmueller@0
   567
	end
tmueller@0
   568
	
tmueller@20
   569
	assert(profile and lang, "Invalid profile or language")
tmueller@0
   570
	
tmueller@47
   571
	
tmueller@47
   572
	-- Write back language and profile
tmueller@0
   573
tmueller@0
   574
	args.lang = lang ~= config.deflang and lang or nil
tmueller@0
   575
	args.profile = profile
tmueller@0
   576
	
tmueller@47
   577
	
tmueller@0
   578
	-- determine content directory pathname and section filename
tmueller@0
   579
	
tmueller@68
   580
	contentdir = ("%s/%s_%s"):format(config.contentdir, profile, lang)
tmueller@68
   581
 	sectionfname = contentdir .. "/.sections"
tmueller@0
   582
	
tmueller@0
   583
	-- load sections
tmueller@0
   584
	
tmueller@68
   585
 	sections = source(sectionfname)
tmueller@0
   586
	
tmueller@20
   587
	-- index sections, determine visibility in menu
tmueller@0
   588
	
tmueller@27
   589
	indexsections(sections)
tmueller@0
   590
	
tmueller@0
   591
	-- decompose section path, produce a stack of sections
tmueller@0
   592
	
tmueller@27
   593
	submenus, section = getsection(section, authuser, 
tmueller@0
   594
		cgi.document.VirtualPath or "", not authuser and config.defname)
tmueller@0
   595
tmueller@0
   596
	-- handle redirects if not logged on
tmueller@0
   597
	
tmueller@0
   598
	if not authuser and section and section.redirect then
tmueller@27
   599
		submenus, section = getsection(section, authuser, 
tmueller@0
   600
			section.redirect, not authuser and config.defname)
tmueller@0
   601
	end
tmueller@0
   602
			
tmueller@0
   603
	-- section path and document name (refined)
tmueller@0
   604
	
tmueller@0
   605
	sectionpath = getpath(submenus)
tmueller@77
   606
	sectionname = getpath(submenus, "_")
tmueller@0
   607
tmueller@0
   608
end
tmueller@0
   609
tmueller@0
   610
tmueller@20
   611
--	Handle state modifications (create/save/delete, profile management)
tmueller@0
   612
tmueller@0
   613
local function handlestate()
tmueller@23
   614
tmueller@0
   615
	if args.editkey == "main" then
tmueller@23
   616
		
tmueller@23
   617
		-- In main editable section:
tmueller@23
   618
		
tmueller@23
   619
		local save
tmueller@0
   620
		
tmueller@0
   621
		if args.actioncreate then
tmueller@45
   622
			-- Create new section
tmueller@0
   623
			local editname = args.editname:lower()
tmueller@20
   624
			assert(not editname:match("%W"),
tmueller@47
   625
				dbmsg("Invalid section name", editname))
tmueller@20
   626
			if not (section and (section.subs or section)[editname]) then
tmueller@20
   627
				local newpath = 
tmueller@20
   628
					(sectionpath and (sectionpath .. "/")) .. editname
tmueller@27
   629
				addtopath(sections, newpath, { name = editname,
tmueller@0
   630
					label = args.editlabel ~= "" and args.editlabel or nil,
tmueller@0
   631
					title = args.edittitle ~= "" and args.edittitle or nil,
tmueller@43
   632
					redirect = args.editredirect ~= "" and args.editredirect or nil,
tmueller@43
   633
					hidden = args.editvisibility and true,
tmueller@43
   634
					secret = args.editsecrecy and true,
tmueller@43
   635
					secure = args.editsecure and true,
tmueller@0
   636
					creator = authuser,
tmueller@20
   637
					creationdate = time() })
tmueller@23
   638
				save = true
tmueller@0
   639
			end
tmueller@20
   640
		
tmueller@0
   641
		elseif args.actionsave then
tmueller@45
   642
			-- Save section
tmueller@0
   643
			section.revisiondate = time()
tmueller@0
   644
			section.revisioner = authuser
tmueller@23
   645
			save = true
tmueller@20
   646
		
tmueller@0
   647
		elseif args.actiondelete then
tmueller@45
   648
			-- Delete section
tmueller@0
   649
			if not args.actionconfirm then
tmueller@20
   650
				useralert = {
tmueller@119
   651
					text = profile == pubprofile and
tmueller@119
   652
						locale.ALERT_DELETE_SECTION_IN_PUBLISHED_PROFILE or
tmueller@119
   653
						locale.ALERT_DELETE_SECTION,
tmueller@20
   654
					confirm =
tmueller@20
   655
						'<input type="submit" name="actiondelete" value="' .. 
tmueller@47
   656
						locale.DELETE .. '" /> ' ..
tmueller@20
   657
						hidden("actionconfirm", "true")
tmueller@20
   658
				}
tmueller@0
   659
			else
tmueller@77
   660
				deletesection(contentdir, sectionname)
tmueller@27
   661
				rmpath(sections, sectionpath)
tmueller@23
   662
				save = true
tmueller@0
   663
			end
tmueller@20
   664
		
tmueller@0
   665
		elseif args.actionsaveprops then
tmueller@23
   666
			-- Save properties
tmueller@0
   667
			section.hidden = args.editvisibility and true
tmueller@0
   668
			section.secret = args.editsecrecy and true
tmueller@0
   669
			section.secure = args.editsecure and true
tmueller@0
   670
			section.label = args.editlabel ~= "" and args.editlabel or nil
tmueller@0
   671
			section.title = args.edittitle ~= "" and args.edittitle or nil
tmueller@20
   672
			section.redirect =
tmueller@20
   673
				args.editredirect ~= "" and args.editredirect or nil
tmueller@23
   674
			save = true
tmueller@20
   675
		
tmueller@0
   676
		elseif args.actionup then
tmueller@45
   677
			-- Move section up
tmueller@27
   678
			local t, i = checkpath(sections, sectionpath)
tmueller@0
   679
			if t and i > 1 then
tmueller@115
   680
				if profile == pubprofile and not args.actionconfirm then
tmueller@115
   681
					useralert = {
tmueller@115
   682
						text = locale.ALERT_MOVE_SECTION_IN_PUBLISHED_PROFILE,
tmueller@115
   683
						confirm =
tmueller@115
   684
							'<input type="submit" name="actionup" value="' .. 
tmueller@115
   685
							locale.MOVE .. '" /> ' ..
tmueller@115
   686
							hidden("actionconfirm", "true")
tmueller@115
   687
					}
tmueller@115
   688
				else
tmueller@115
   689
					local item = table.remove(t, i)
tmueller@115
   690
					table.insert(t, i - 1, item)
tmueller@115
   691
					save = true
tmueller@115
   692
				end
tmueller@0
   693
			end
tmueller@20
   694
		
tmueller@0
   695
		elseif args.actiondown then
tmueller@45
   696
			-- Move section down
tmueller@27
   697
			local t, i = checkpath(sections, sectionpath)
tmueller@0
   698
			if t and i < #t then
tmueller@115
   699
				if profile == pubprofile and not args.actionconfirm then
tmueller@115
   700
					useralert = {
tmueller@115
   701
						text = locale.ALERT_MOVE_SECTION_IN_PUBLISHED_PROFILE,
tmueller@115
   702
						confirm =
tmueller@115
   703
							'<input type="submit" name="actiondown" value="' .. 
tmueller@115
   704
							locale.MOVE .. '" /> ' ..
tmueller@115
   705
							hidden("actionconfirm", "true")
tmueller@115
   706
					}
tmueller@115
   707
				else
tmueller@115
   708
					local item = table.remove(t, i)
tmueller@115
   709
					table.insert(t, i + 1, item)
tmueller@115
   710
					save = true
tmueller@115
   711
				end
tmueller@0
   712
			end
tmueller@20
   713
		
tmueller@0
   714
		elseif args.actioncreateprofile and args.createprofile then
tmueller@23
   715
			-- Create profile
tmueller@0
   716
			local c = checkprofilename(args.createprofile:lower())
tmueller@0
   717
			if c == profile then
tmueller@47
   718
				useralert = { text = locale.ALERT_CANNOT_COPY_PROFILE_TO_SELF }
tmueller@0
   719
			else
tmueller@0
   720
				local profiles = getprofiles(config.contentdir, lang)
tmueller@0
   721
				if profiles[c] and not args.actionconfirm then
tmueller@20
   722
					useralert = {
tmueller@20
   723
						text = c == pubprofile and 
tmueller@47
   724
							locale.ALERT_OVERWRITE_PUBLISHED_PROFILE or
tmueller@47
   725
							locale.ALERT_OVERWRITE_EXISTING_PROFILE,
tmueller@0
   726
						confirm =
tmueller@20
   727
							'<input type="submit" name="actioncreateprofile" value="' .. 
tmueller@47
   728
							locale.OVERWRITE .. '" /> ' ..
tmueller@20
   729
							hidden("actionconfirm", "true") .. 
tmueller@20
   730
							hidden("createprofile", c)
tmueller@20
   731
					}
tmueller@0
   732
				else
tmueller@0
   733
					if profiles[c] then
tmueller@0
   734
						deletedir(config.contentdir .. "/" .. c .. "_" .. lang)
tmueller@0
   735
					end
tmueller@0
   736
					copyprofile(config.contentdir, lang, profile, c)
tmueller@0
   737
				end
tmueller@0
   738
			end
tmueller@20
   739
		
tmueller@0
   740
		elseif args.actiondeleteprofile and args.deleteprofile then
tmueller@23
   741
			-- Delete profile
tmueller@0
   742
			local c = checkprofilename(args.deleteprofile:lower())
tmueller@47
   743
			assert(c ~= pubprofile, dbmsg("Cannot delete published profile", c))
tmueller@0
   744
			if args.actionconfirm then
tmueller@0
   745
				deletedir(config.contentdir .. "/" .. c .. "_" .. lang)
tmueller@0
   746
				profile = nil
tmueller@0
   747
				args.profile = nil
tmueller@68
   748
				init()
tmueller@23
   749
				save = true
tmueller@0
   750
			else
tmueller@20
   751
				useralert = { 
tmueller@47
   752
					text = locale.ALERT_DELETE_PROFILE,
tmueller@20
   753
					confirm = 
tmueller@20
   754
						'<input type="submit" name="actiondeleteprofile" value="' .. 
tmueller@47
   755
						locale.DELETE .. '" /> ' ..
tmueller@20
   756
						hidden("actionconfirm", "true") ..
tmueller@20
   757
						hidden("deleteprofile", c)
tmueller@20
   758
				}
tmueller@0
   759
			end
tmueller@20
   760
		
tmueller@0
   761
		elseif args.actionchangeprofile and args.changeprofile then
tmueller@23
   762
			-- Change profile
tmueller@0
   763
			local c = checkprofilename(args.changeprofile:lower())
tmueller@0
   764
			profile = c
tmueller@0
   765
			args.profile = c
tmueller@23
   766
			save = true
tmueller@20
   767
		
tmueller@0
   768
		elseif args.actionpublishprofile and args.publishprofile then
tmueller@23
   769
			-- Publish profile
tmueller@0
   770
			local c = checkprofilename(args.publishprofile:lower())
tmueller@0
   771
			if c ~= _publicprofile then
tmueller@0
   772
				if args.actionconfirm then
tmueller@0
   773
					publishprofile(config.contentdir, lang, c)
tmueller@23
   774
					save = true
tmueller@0
   775
				else
tmueller@20
   776
					useralert = {
tmueller@47
   777
						text = locale.ALERT_PUBLISH_PROFILE,
tmueller@20
   778
						confirm =
tmueller@20
   779
							'<input type="submit" name="actionpublishprofile" value="' ..
tmueller@47
   780
							locale.PUBLISH .. '" /> ' ..
tmueller@20
   781
							hidden("actionconfirm", "true") ..
tmueller@20
   782
							hidden("publishprofile", c)
tmueller@20
   783
					}
tmueller@20
   784
				end
tmueller@20
   785
			end
tmueller@0
   786
		end
tmueller@0
   787
		
tmueller@23
   788
		if save then
tmueller@124
   789
			saveindex()
tmueller@0
   790
			init()
tmueller@0
   791
		end
tmueller@0
   792
	
tmueller@47
   793
	elseif args.editkey and checkbodyname(args.editkey) then
tmueller@0
   794
		if args.actiondelete then
tmueller@45
   795
			-- Delete section in secondary editable body:
tmueller@77
   796
			deletesection(contentdir, sectionname .. "." .. args.editkey)
tmueller@0
   797
		end
tmueller@0
   798
	end
tmueller@0
   799
end
tmueller@0
   800
tmueller@0
   801
tmueller@80
   802
--	Load/create configuration
tmueller@0
   803
tmueller@0
   804
config = source("../etc/config.lua") or { }
tmueller@80
   805
tmueller@80
   806
config.defname = config.defname or "home"
tmueller@80
   807
config.deflang = config.deflang or "en"
tmueller@80
   808
config.sessionmaxage = config.sessionmaxage or 600
tmueller@80
   809
config.secureport = config.secureport or 443
tmueller@80
   810
tmueller@80
   811
--	Check paths and make them absolute
tmueller@80
   812
tmueller@20
   813
config.passwdfile = posix.abspath(config.passwdfile or "../etc/passwd.lua")
tmueller@0
   814
config.sessiondir = posix.abspath(config.sessiondir or "../var/sessions")
tmueller@0
   815
config.extdir = posix.abspath(config.extdir or "../extensions")
tmueller@20
   816
config.contentdir = posix.abspath(config.contentdir or "../content")
tmueller@20
   817
config.localedir = posix.abspath(config.localedir or "../locale")
tmueller@0
   818
tmueller@80
   819
--	Manage login and establish session
tmueller@0
   820
tmueller@0
   821
session.init(config.sessiondir, args.session, config.sessionmaxage)
tmueller@0
   822
if args.login then
tmueller@0
   823
	if args.login == "false" then
tmueller@0
   824
		session.delete()
tmueller@0
   825
		session = nil
tmueller@0
   826
	elseif args.password then
tmueller@104
   827
		loginfailed = true
tmueller@0
   828
		local pwddb = source(config.passwdfile)
tmueller@0
   829
		local pwdentry = pwddb[args.login]
tmueller@0
   830
		if pwdentry and pwdentry.password == args.password then
tmueller@0
   831
			session.data.authuser = pwdentry.username
tmueller@0
   832
			session.data.id = session.id
tmueller@104
   833
			loginfailed = nil
tmueller@0
   834
		end
tmueller@0
   835
	end
tmueller@0
   836
end
tmueller@0
   837
tmueller@68
   838
secure = request.Port == config.secureport
tmueller@20
   839
authuser = session and session.data.authuser
tmueller@20
   840
tmueller@20
   841
if not authuser then
tmueller@0
   842
	session = nil
tmueller@0
   843
	args.session = nil
tmueller@0
   844
end
tmueller@0
   845
tmueller@23
   846
tmueller@80
   847
--	get lang, locale, profile, section
tmueller@0
   848
tmueller@0
   849
init()
tmueller@0
   850
if authuser then
tmueller@80
   851
	-- handle state modifications
tmueller@0
   852
	handlestate()
tmueller@0
   853
end
tmueller@0
   854
tmueller@23
   855
tmueller@80
   856
--	current document
tmueller@80
   857
tmueller@80
   858
docname = cgi.document.Name
tmueller@80
   859
document = docname .. "/" .. sectionpath
tmueller@80
   860
tmueller@80
   861
tmueller@0
   862
--	create section function
tmueller@0
   863
tmueller@0
   864
local func, msg = loadhtml(open("loona/editable.lua"),
tmueller@0
   865
	"tek.web.out", "loona/editable.lua")
tmueller@0
   866
tmueller@20
   867
assert(func, dbmsg("Syntax error", msg))
tmueller@0
   868
tmueller@0
   869
local editable = func()
tmueller@0
   870
tmueller@0
   871
function body(name)
tmueller@47
   872
	name = checkbodyname(name)
tmueller@0
   873
	if name == "main" then
tmueller@80
   874
		dosnippet(config, editable("main", contentdir, sectionname, sectionname))
tmueller@0
   875
	else
tmueller@0
   876
		local ext = "." .. name
tmueller@0
   877
		dosnippet(config, editable(name, contentdir,
tmueller@77
   878
			getsectionfile(submenus, contentdir, ext), sectionname .. ext))
tmueller@0
   879
	end
tmueller@0
   880
end
tmueller@0
   881
tmueller@23
   882
tmueller@0
   883
--	write back session state
tmueller@0
   884
tmueller@0
   885
if session then
tmueller@0
   886
	session.save()
tmueller@0
   887
end