cgi-bin/loona.lua
author Timm S. Mueller <tmueller@neoscientists.org>
Fri, 16 Feb 2007 23:28:45 +0100
changeset 23 ebc5fbbd5996
parent 20 6ab0b2d1dec9
child 27 13aff038ba4c
permissions -rw-r--r--
Saving sections and switching profiles is now safe
tmueller@0
     1
tmueller@0
     2
--
tmueller@0
     3
--	loona - tiny CMS
tmueller@0
     4
--	Written by Timm S. Mueller <tmueller at neoscientists.org>
tmueller@0
     5
--	See copyright notice in COPYRIGHT
tmueller@0
     6
--
tmueller@0
     7
tmueller@0
     8
require "tek"
tmueller@0
     9
require "tek.cgi"
tmueller@0
    10
require "tek.cgi.request"
tmueller@0
    11
require "tek.cgi.request.args"
tmueller@0
    12
require "tek.cgi.header"
tmueller@0
    13
require "tek.cgi.session"
tmueller@0
    14
require "tek.posix"
tmueller@0
    15
require "tek.web"
tmueller@0
    16
require "tek.web.markup"
tmueller@0
    17
require "tek.util"
tmueller@0
    18
tmueller@23
    19
tmueller@0
    20
local boxed_G = { 
tmueller@0
    21
	string = string, table = table,
tmueller@0
    22
	assert = assert, collectgarbage = collectgarbage, dofile = dofile,
tmueller@0
    23
	error = error, getfenv = getfenv, getmetatable = getmetatable,
tmueller@0
    24
	ipairs = ipairs, load = load, loadfile = loadfile, loadstring = loadstring,
tmueller@0
    25
	next = next, pairs = pairs, pcall = pcall, print = print,
tmueller@0
    26
	rawequal = rawequal, rawget = rawget, rawset = rawset, require = require,
tmueller@0
    27
	select = select, setfenv = setfenv, setmetatable = setmetatable,
tmueller@0
    28
	tonumber = tonumber, tostring = tostring, type = type, unpack = unpack,
tmueller@0
    29
	xpcall = xpcall
tmueller@0
    30
}
tmueller@0
    31
tmueller@0
    32
local tek, table, string, assert, unpack, ipairs, pairs, type, require =
tmueller@0
    33
	tek, table, string, assert, unpack, ipairs, pairs, type, require
tmueller@0
    34
local setmetatable, setfenv, getfenv = setmetatable, setfenv, getfenv
tmueller@0
    35
local open, remove, rename, getenv, time =
tmueller@0
    36
	io.open, os.remove, os.rename, os.getenv, os.time
tmueller@0
    37
tmueller@0
    38
local sectionfname, langs, locale
tmueller@0
    39
tmueller@0
    40
tmueller@0
    41
module "loona"
tmueller@0
    42
tmueller@0
    43
tmueller@0
    44
_VERSION = 2
tmueller@0
    45
_REVISION = 0
tmueller@0
    46
tmueller@0
    47
tmueller@0
    48
out = tek.web.out
tmueller@0
    49
setheader = tek.web.setheader
tmueller@0
    50
cgi = tek.cgi
tmueller@0
    51
session = cgi.session
tmueller@0
    52
request = cgi.request
tmueller@0
    53
args = request.args
tmueller@0
    54
posix = tek.posix
tmueller@0
    55
encodeform = cgi.encodeform
tmueller@0
    56
loadhtml = tek.web.include.load
tmueller@0
    57
source = tek.source
tmueller@0
    58
domarkup = tek.web.markup.main
tmueller@0
    59
expire = tek.util.expire
tmueller@0
    60
tmueller@0
    61
tmueller@20
    62
local function dbmsg(msg, detail)
tmueller@20
    63
	return msg and msg .. 
tmueller@20
    64
		(detail and (config.debug == true and (" : " .. detail)) or "")
tmueller@20
    65
end
tmueller@20
    66
tmueller@20
    67
tmueller@0
    68
local function checkprofilename(c)
tmueller@20
    69
	assert(c:match("^%w+$") and c ~= "current", dbmsg(loc("INVALID_NAME"), c))
tmueller@0
    70
	return c
tmueller@0
    71
end
tmueller@0
    72
tmueller@0
    73
tmueller@0
    74
local function checksectionname(s)
tmueller@0
    75
	s = s or "main"
tmueller@20
    76
	assert(s:match("^[%w_]*%w+[%w_]*$"), dbmsg(loc("INVALID_NAME"), s))
tmueller@0
    77
	return s
tmueller@0
    78
end
tmueller@0
    79
tmueller@0
    80
tmueller@0
    81
local function deletedir(dst)
tmueller@0
    82
	for e in tek.util.readdir(dst) do
tmueller@0
    83
		local success, msg = remove(dst .. "/" .. e)
tmueller@20
    84
		assert(success, dbmsg("Error removing entry in profile", msg))
tmueller@0
    85
	end
tmueller@0
    86
	return remove(dst)
tmueller@0
    87
end
tmueller@0
    88
tmueller@0
    89
tmueller@0
    90
local function copyprofile(contentdir, lang, srcprofile, newprofile)
tmueller@0
    91
	local src = contentdir .. "/" .. srcprofile .. "_" .. lang
tmueller@20
    92
	assert(posix.stat(src, "mode") == "directory",
tmueller@20
    93
		dbmsg("Not a directory", src))
tmueller@0
    94
	local dst = contentdir .. "/" .. newprofile .. "_" .. lang
tmueller@0
    95
	local success, msg = posix.mkdir(dst)
tmueller@20
    96
	assert(success, dbmsg("Error creating profile directory", msg))
tmueller@0
    97
	for e in tek.util.readdir(src) do
tmueller@0
    98
		local ext = e:match("^[^.].*%.([^.]*)$")
tmueller@0
    99
		if ext ~= "LOCK" then
tmueller@0
   100
			local f = src .. "/" .. e
tmueller@0
   101
			if posix.stat(f, "mode") == "file" then
tmueller@0
   102
				success, msg = tek.copyfile(f, dst .. "/" .. e)
tmueller@20
   103
				assert(success, dbmsg("Error copying file", msg))
tmueller@0
   104
			end
tmueller@0
   105
		end
tmueller@0
   106
	end
tmueller@0
   107
end
tmueller@0
   108
tmueller@0
   109
tmueller@0
   110
local function publishprofile(contentdir, lang, profile)
tmueller@0
   111
	local newpath = contentdir .. "/current_" .. lang
tmueller@23
   112
	local tmppath = newpath .. "." .. session.sessionname
tmueller@23
   113
	local success, msg = posix.symlink(profile .. "_" .. lang, tmppath)
tmueller@20
   114
	assert(success, dbmsg("Cannot create symlink", msg))
tmueller@23
   115
	success, msg = rename(tmppath, newpath)
tmueller@23
   116
	assert(success, dbmsg("Cannot put symlink in place", msg))
tmueller@0
   117
end
tmueller@0
   118
tmueller@0
   119
tmueller@20
   120
local function lookupname(tab, val)
tmueller@0
   121
	if tab then
tmueller@0
   122
		for i, v in ipairs(tab) do
tmueller@20
   123
			if v.name == val then
tmueller@0
   124
				return i
tmueller@0
   125
			end
tmueller@0
   126
		end
tmueller@0
   127
	end
tmueller@0
   128
end
tmueller@0
   129
tmueller@0
   130
tmueller@20
   131
--	Index sections, determine accessibility and visibility in menu
tmueller@20
   132
tmueller@20
   133
local function indexsections(s)
tmueller@0
   134
	s = s or config.sections
tmueller@0
   135
	for _, e in ipairs(s) do
tmueller@0
   136
		if e.subs then
tmueller@20
   137
			indexsections(e.subs)
tmueller@0
   138
		end
tmueller@0
   139
		e.notvalid = (not secure and e.secure) or 
tmueller@0
   140
			(not authuser and e.secret) or nil
tmueller@0
   141
		e.notvisible = e.notvalid or not authuser and e.hidden or nil
tmueller@16
   142
		s[e.name] = e
tmueller@0
   143
	end
tmueller@0
   144
end
tmueller@0
   145
tmueller@0
   146
tmueller@20
   147
--	Decompose section path into a stack of sections, returning only up to
tmueller@0
   148
--	the last valid element in the path. additionally returns the table of
tmueller@0
   149
--	the last section path element (or the default section)
tmueller@0
   150
tmueller@0
   151
local function getsection(config, section, authuser, path, default)
tmueller@0
   152
	local tab = { { entries = config.sections, name = default } }
tmueller@0
   153
	local sections = config.sections
tmueller@0
   154
	local sectionpath
tmueller@0
   155
	(path or default):gsub("(%w+)/?", function(a)
tmueller@0
   156
		if sections then
tmueller@20
   157
			local s = sections[a]
tmueller@20
   158
			if s and not s.notvalid then
tmueller@20
   159
				sectionpath = s
tmueller@0
   160
				tab[#tab].name = a
tmueller@20
   161
				sections = s.subs
tmueller@0
   162
				if sections then
tmueller@0
   163
					table.insert(tab, { entries = sections })
tmueller@0
   164
				end
tmueller@0
   165
			else
tmueller@0
   166
				sections = nil -- stop.
tmueller@0
   167
			end
tmueller@0
   168
		end
tmueller@0
   169
	end)
tmueller@0
   170
	if not section and not sectionpath then
tmueller@20
   171
		sectionpath = config.sections[default]
tmueller@0
   172
		if sectionpath then
tmueller@0
   173
			table.insert(tab, { entries = sectionpath.subs })
tmueller@0
   174
		end
tmueller@0
   175
	end
tmueller@0
   176
	return tab, sectionpath
tmueller@0
   177
end
tmueller@0
   178
tmueller@0
   179
tmueller@0
   180
local function getpath(sections, delimiter)
tmueller@0
   181
	local t = { }
tmueller@0
   182
	for _, menu in ipairs(sections) do
tmueller@0
   183
		if menu.name then
tmueller@0
   184
			table.insert(t, menu.name)
tmueller@0
   185
		end
tmueller@0
   186
	end
tmueller@0
   187
	return table.concat(t, delimiter or "/")
tmueller@0
   188
end
tmueller@0
   189
tmueller@0
   190
tmueller@20
   191
--	Descending into the sections table alongside the current path,
tmueller@20
   192
--	return the filename to include, defaulting to its parent value
tmueller@20
   193
--	(or the default specified)
tmueller@0
   194
tmueller@20
   195
local function getsectionfile(sections, path, ext, default)
tmueller@20
   196
	local t, val = { }
tmueller@0
   197
	for _, menu in ipairs(sections) do
tmueller@20
   198
		if menu.entries and menu.entries[menu.name] then
tmueller@20
   199
			table.insert(t, menu.name)
tmueller@20
   200
			local fn = table.concat(t, "_") .. ext
tmueller@0
   201
			if posix.stat(path .. "/" .. fn, "mode") == "file" then
tmueller@0
   202
				val = fn
tmueller@0
   203
			end
tmueller@0
   204
		end
tmueller@0
   205
	end
tmueller@0
   206
	return val or default
tmueller@0
   207
end
tmueller@0
   208
tmueller@0
   209
tmueller@0
   210
local function deletenode(dir, fname)
tmueller@0
   211
	local fullname = dir .. "/" .. fname
tmueller@0
   212
	local success, msg = remove(fullname)
tmueller@0
   213
	if success then
tmueller@0
   214
		local pat = "^" .. 
tmueller@0
   215
			fname:gsub("%^%$%(%)%%%.%[%]%*%+%-%?", "%%%1") .. "%..*$"
tmueller@0
   216
		for e in tek.util.readdir(dir) do
tmueller@0
   217
			if e:match(pat) then
tmueller@0
   218
				remove(dir .. "/" .. e)
tmueller@0
   219
			end
tmueller@0
   220
		end
tmueller@0
   221
	end
tmueller@0
   222
	return success, msg
tmueller@0
   223
end
tmueller@0
   224
tmueller@0
   225
tmueller@20
   226
--	Add element to path
tmueller@0
   227
tmueller@20
   228
local function addtopath(tab, path, e)
tmueller@0
   229
	path:gsub("(%w+)/?", function(a)
tmueller@20
   230
		if tab then
tmueller@20
   231
			local s = tab[a]
tmueller@20
   232
			if s then
tmueller@20
   233
				if not s.subs then
tmueller@20
   234
					s.subs = { }
tmueller@0
   235
				end
tmueller@20
   236
				tab = s.subs
tmueller@0
   237
			else
tmueller@20
   238
				table.insert(tab, e)
tmueller@20
   239
				tab[a] = e
tmueller@20
   240
 				tab = nil -- stop
tmueller@0
   241
			end
tmueller@0
   242
		end
tmueller@0
   243
	end)
tmueller@0
   244
end
tmueller@0
   245
tmueller@0
   246
tmueller@20
   247
--	Remove element from path
tmueller@0
   248
tmueller@20
   249
local function rmpath(tab, path)
tmueller@20
   250
	local parent
tmueller@0
   251
	path:gsub("(%w+)/?", function(a)
tmueller@20
   252
		if tab then
tmueller@20
   253
			local idx = lookupname(tab, a)
tmueller@20
   254
			if idx then
tmueller@20
   255
				if tab[idx].subs then
tmueller@20
   256
					parent = tab[idx]
tmueller@20
   257
					tab = tab[idx].subs
tmueller@0
   258
				else
tmueller@20
   259
					table.remove(tab, idx)
tmueller@20
   260
					if #tab == 0 and parent then
tmueller@20
   261
						parent.subs = nil
tmueller@0
   262
					end
tmueller@20
   263
					tab = nil
tmueller@0
   264
				end
tmueller@0
   265
			end
tmueller@0
   266
		end
tmueller@0
   267
	end)
tmueller@0
   268
end
tmueller@0
   269
tmueller@0
   270
tmueller@0
   271
-------------------------------------------------------------------------------
tmueller@0
   272
tmueller@0
   273
tmueller@8
   274
--	Produce page title
tmueller@8
   275
tmueller@8
   276
function title()
tmueller@8
   277
	return section and (section.title or section.label or section.name) or ""
tmueller@8
   278
end
tmueller@8
   279
tmueller@8
   280
tmueller@0
   281
--	Return locale string
tmueller@0
   282
tmueller@0
   283
function loc(s)
tmueller@0
   284
	if not locale then
tmueller@0
   285
		for _, l in ipairs(langs) do
tmueller@0
   286
			locale = source(config.localedir .. "/" .. l)
tmueller@0
   287
			if locale then
tmueller@0
   288
				break
tmueller@0
   289
			end		
tmueller@0
   290
		end
tmueller@0
   291
	end
tmueller@14
   292
	return locale and encodeform(locale[s]) or 
tmueller@14
   293
		'nonlocalized message: "' .. s .. '"'
tmueller@0
   294
end
tmueller@0
   295
tmueller@0
   296
tmueller@0
   297
--	Find element in path
tmueller@0
   298
tmueller@0
   299
function checkpath(tab, path)
tmueller@0
   300
	local res, idx
tmueller@0
   301
	path:gsub("(%w+)/?", function(a)
tmueller@0
   302
		if tab then
tmueller@20
   303
			local i = lookupname(tab, a)
tmueller@0
   304
			if i then
tmueller@0
   305
				res, idx = tab, i
tmueller@0
   306
				tab = tab[i].subs
tmueller@0
   307
			else
tmueller@0
   308
				res, idx = nil, nil
tmueller@0
   309
			end
tmueller@0
   310
		end
tmueller@0
   311
	end)
tmueller@0
   312
	return res, idx
tmueller@0
   313
end
tmueller@0
   314
tmueller@0
   315
tmueller@0
   316
--	Run a site function snippet, with full error recovery
tmueller@0
   317
--	(also recovers from errors in error handling function)
tmueller@0
   318
tmueller@23
   319
function dosnippet(config, func, errfunc)
tmueller@0
   320
	local ret = { tek.catch(func) }
tmueller@0
   321
	if ret[1] == 0 or (errfunc and tek.catch(errfunc) == 0) then
tmueller@0
   322
		return unpack(ret)
tmueller@0
   323
	end
tmueller@0
   324
	out("<h2>Error</h2>")
tmueller@14
   325
	out("<h3>" .. (ret[2] or "") .. "</h3>")
tmueller@23
   326
	if config.debug == true then
tmueller@0
   327
		if type(ret[3]) == "string" then
tmueller@14
   328
			out("<p>" .. ret[3] .. "</p>")
tmueller@0
   329
		end
tmueller@0
   330
		if ret[4] and config.debug == true then
tmueller@14
   331
			out("<pre>" .. ret[4] .. "</pre>")
tmueller@0
   332
		end
tmueller@0
   333
	end
tmueller@0
   334
end	
tmueller@0
   335
tmueller@0
   336
tmueller@0
   337
function lockfile(newfile)
tmueller@0
   338
	return not session and true or 
tmueller@0
   339
		posix.symlink(session.filename, newfile .. ".LOCK")
tmueller@0
   340
end
tmueller@0
   341
tmueller@0
   342
tmueller@0
   343
function unlockfile(dstfile)
tmueller@0
   344
	return not session and true or remove(dstfile .. ".LOCK")
tmueller@0
   345
end
tmueller@0
   346
tmueller@0
   347
tmueller@0
   348
function savenode(dir, fname, content)
tmueller@0
   349
	fname = dir .. "/" .. fname
tmueller@0
   350
	local f, msg = open(fname, "wb")
tmueller@20
   351
	assert(f, dbmsg("Could not open file for writing", msg))
tmueller@0
   352
	f:write(content or "")
tmueller@0
   353
	f:close()
tmueller@0
   354
end
tmueller@0
   355
tmueller@23
   356
tmueller@20
   357
--	Run extension in a controlled environment
tmueller@0
   358
tmueller@0
   359
function include(fname, ...)
tmueller@20
   360
	assert(not fname:match("%W"), dbmsg(loc("INVALID_NAME"), fname))
tmueller@0
   361
	local fname2 = config.extdir .. "/" .. fname .. ".lua"
tmueller@0
   362
	local f, msg = open(fname2)
tmueller@20
   363
	assert(f, dbmsg("Cannot open file", msg))
tmueller@0
   364
	local parsed, msg = loadhtml(f, "loona.out", fname2)
tmueller@20
   365
	assert(parsed, dbmsg("Syntax error", msg))
tmueller@0
   366
 	local fenv = {
tmueller@0
   367
 		arg = arg,
tmueller@0
   368
 		loona = {
tmueller@0
   369
 			out = out,
tmueller@0
   370
 			setheader = setheader,
tmueller@0
   371
			hidden = hidden,
tmueller@15
   372
			link = link,
tmueller@0
   373
			elink = elink,
tmueller@0
   374
			href = href,
tmueller@0
   375
			checkpath = checkpath,
tmueller@0
   376
			authuser = authuser,
tmueller@0
   377
			document = document,
tmueller@0
   378
			contentdir = contentdir,
tmueller@0
   379
			profile = profile,
tmueller@0
   380
			pubprofile = pubprofile,
tmueller@0
   381
			lang = lang,
tmueller@0
   382
			secure = secure,
tmueller@0
   383
			config = config,
tmueller@0
   384
			session = session,
tmueller@0
   385
			sectionpath = sectionpath,
tmueller@0
   386
		}
tmueller@0
   387
	}
tmueller@0
   388
 	setmetatable(fenv, { __index = boxed_G }) -- boxed global environment
tmueller@0
   389
	setfenv(parsed, fenv)
tmueller@0
   390
	return parsed()
tmueller@0
   391
end
tmueller@0
   392
tmueller@0
   393
tmueller@0
   394
function href(section, ...)
tmueller@0
   395
	local target = cgi.document.Name
tmueller@0
   396
	target = section and target .. "/" .. section or target
tmueller@0
   397
	if session or args.profile and args.profile ~= pubprofile then
tmueller@0
   398
		return tek.web.gethref(target, "lang", "profile", "session",
tmueller@0
   399
			unpack(arg))
tmueller@0
   400
	end
tmueller@0
   401
	return tek.web.gethref(target, "lang", unpack(arg))
tmueller@0
   402
end
tmueller@0
   403
tmueller@0
   404
tmueller@0
   405
function link(section, text, ...) -- normal link
tmueller@0
   406
	return '<a href="' .. href(section, unpack(arg)) .. '">' ..
tmueller@0
   407
		(text or section) .. '</a>'
tmueller@0
   408
end
tmueller@0
   409
tmueller@0
   410
tmueller@15
   411
function uilink(section, text, ...) -- active link
tmueller@15
   412
	return '<a class="loonaUILink" href="' .. href(section, unpack(arg)) ..
tmueller@0
   413
		'">' .. (text or section) .. '</a>'
tmueller@0
   414
end
tmueller@0
   415
tmueller@0
   416
tmueller@0
   417
function elink(target, text) -- external link
tmueller@15
   418
	return '<a class="loonaExtLink" href="' .. target .. 
tmueller@0
   419
		'" onclick="void(window.open(this.href, \'\', \'\')); return false;">'
tmueller@0
   420
		.. (text or target) .. '</a>'
tmueller@0
   421
end
tmueller@0
   422
tmueller@0
   423
tmueller@0
   424
function hidden(name, value)
tmueller@0
   425
	return not value and "" or 
tmueller@0
   426
		'<input type="hidden" name="' .. name .. '" value="' .. value .. '" />'
tmueller@0
   427
end
tmueller@0
   428
tmueller@0
   429
tmueller@0
   430
function getprofiles(contentdir, lang)
tmueller@0
   431
	local t = { }
tmueller@0
   432
	for f in tek.util.readdir(contentdir) do
tmueller@0
   433
		if posix.lstat(contentdir .. "/" .. f, "mode") == "directory" then
tmueller@0
   434
			local e = f:match("^(%w+)_" .. lang .. "$")
tmueller@0
   435
 			if e then
tmueller@0
   436
	 			t[e] = e
tmueller@0
   437
 	 		end
tmueller@0
   438
		end
tmueller@0
   439
	end
tmueller@0
   440
	return t
tmueller@0
   441
end
tmueller@0
   442
tmueller@0
   443
tmueller@0
   444
-- Init
tmueller@0
   445
tmueller@0
   446
local function init()
tmueller@0
   447
	
tmueller@0
   448
	-- get list of languages, in order of preference
tmueller@0
   449
	
tmueller@0
   450
	langs = { args.lang and args.lang:match("^%w+$") }
tmueller@0
   451
	if config.browserlang == true then
tmueller@0
   452
		local s = getenv("HTTP_ACCEPT_LANGUAGE")
tmueller@0
   453
		while s do
tmueller@0
   454
			local l, r = s:match("^([%w.=]+)[,;](.*)$")
tmueller@0
   455
			l = l or s
tmueller@0
   456
			s = r
tmueller@0
   457
			if l:match("^%w+$") then
tmueller@0
   458
				table.insert(langs, l)
tmueller@0
   459
			end
tmueller@0
   460
		end
tmueller@0
   461
	end
tmueller@0
   462
	table.insert(langs, config.deflang)
tmueller@0
   463
	
tmueller@0
   464
	-- get list of possible profiles
tmueller@0
   465
	
tmueller@0
   466
	local profiles = { }
tmueller@0
   467
	for e in tek.util.readdir(config.contentdir) do
tmueller@0
   468
		profiles[e] = e
tmueller@0
   469
	end
tmueller@0
   470
	
tmueller@0
   471
	-- get pubprofile
tmueller@0
   472
	
tmueller@0
   473
	for _, lang in ipairs(langs) do
tmueller@0
   474
		local p = posix.readlink(config.contentdir .. "/current_" .. lang)
tmueller@0
   475
		p = p and p:match("^(%w+)_" .. lang .. "$")
tmueller@0
   476
		if p then
tmueller@0
   477
			pubprofile = p
tmueller@0
   478
			break
tmueller@0
   479
		end
tmueller@0
   480
	end
tmueller@0
   481
	
tmueller@0
   482
	-- get profile
tmueller@0
   483
	
tmueller@0
   484
	local checkprofile = authuser and args.profile or pubprofile or "default"
tmueller@0
   485
	for _, l in ipairs(langs) do
tmueller@0
   486
		if profiles[checkprofile .. "_" .. l] then
tmueller@0
   487
			profile = checkprofile
tmueller@0
   488
			lang = l
tmueller@0
   489
			break
tmueller@0
   490
		end
tmueller@0
   491
	end
tmueller@0
   492
	
tmueller@20
   493
	assert(profile and lang, "Invalid profile or language")
tmueller@0
   494
	
tmueller@0
   495
	-- write back language and profile into args
tmueller@0
   496
tmueller@0
   497
	args.lang = lang ~= config.deflang and lang or nil
tmueller@0
   498
	args.profile = profile
tmueller@0
   499
	
tmueller@0
   500
	-- determine content directory pathname and section filename
tmueller@0
   501
	
tmueller@0
   502
	contentdir = config.contentdir .. "/" .. profile .. "_" .. lang
tmueller@0
   503
	sectionfname = contentdir .. "/.sections"
tmueller@0
   504
	
tmueller@0
   505
	-- load sections
tmueller@0
   506
	
tmueller@0
   507
	config.sections = source(sectionfname)
tmueller@0
   508
	
tmueller@20
   509
	-- index sections, determine visibility in menu
tmueller@0
   510
	
tmueller@20
   511
	indexsections(config.sections)
tmueller@0
   512
	
tmueller@0
   513
	-- decompose section path, produce a stack of sections
tmueller@0
   514
	
tmueller@0
   515
	submenus, section = getsection(config, section, authuser, 
tmueller@0
   516
		cgi.document.VirtualPath or "", not authuser and config.defname)
tmueller@0
   517
tmueller@0
   518
	-- handle redirects if not logged on
tmueller@0
   519
	
tmueller@0
   520
	if not authuser and section and section.redirect then
tmueller@0
   521
		submenus, section = getsection(config, section, authuser, 
tmueller@0
   522
			section.redirect, not authuser and config.defname)
tmueller@0
   523
	end
tmueller@0
   524
			
tmueller@0
   525
	-- section path and document name (refined)
tmueller@0
   526
	
tmueller@0
   527
	sectionpath = getpath(submenus)
tmueller@0
   528
tmueller@0
   529
end
tmueller@0
   530
tmueller@0
   531
tmueller@20
   532
--	Handle state modifications (create/save/delete, profile management)
tmueller@0
   533
tmueller@0
   534
local function handlestate()
tmueller@23
   535
tmueller@0
   536
	if args.editkey == "main" then
tmueller@23
   537
		
tmueller@23
   538
		-- In main editable section:
tmueller@23
   539
		
tmueller@23
   540
		local save
tmueller@0
   541
		
tmueller@0
   542
		if args.actioncreate then
tmueller@23
   543
			-- Create new node
tmueller@0
   544
			local editname = args.editname:lower()
tmueller@20
   545
			assert(not editname:match("%W"),
tmueller@20
   546
				dbmsg(loc("INVALID_NAME"), editname))
tmueller@20
   547
			if not (section and (section.subs or section)[editname]) then
tmueller@20
   548
				local newpath = 
tmueller@20
   549
					(sectionpath and (sectionpath .. "/")) .. editname
tmueller@0
   550
				addtopath(config.sections, newpath, { name = editname,
tmueller@0
   551
					label = args.editlabel ~= "" and args.editlabel or nil,
tmueller@0
   552
					title = args.edittitle ~= "" and args.edittitle or nil,
tmueller@0
   553
					creator = authuser,
tmueller@20
   554
					creationdate = time() })
tmueller@23
   555
				save = true
tmueller@0
   556
			end
tmueller@20
   557
		
tmueller@0
   558
		elseif args.actionsave then
tmueller@23
   559
			-- Save node
tmueller@0
   560
			section.revisiondate = time()
tmueller@0
   561
			section.revisioner = authuser
tmueller@23
   562
			save = true
tmueller@20
   563
		
tmueller@0
   564
		elseif args.actiondelete then
tmueller@23
   565
			-- Delete node
tmueller@0
   566
			if not args.actionconfirm then
tmueller@20
   567
				useralert = {
tmueller@20
   568
					text = loc("ALERT_DELETE_NODE"),
tmueller@20
   569
					confirm =
tmueller@20
   570
						'<input type="submit" name="actiondelete" value="' .. 
tmueller@20
   571
						loc("DELETE") .. '" /> ' ..
tmueller@20
   572
						hidden("actionconfirm", "true")
tmueller@20
   573
				}
tmueller@0
   574
			else
tmueller@0
   575
				deletenode(contentdir, sectionpath:gsub("/", "_"))
tmueller@20
   576
				rmpath(config.sections, sectionpath)
tmueller@23
   577
				save = true
tmueller@0
   578
			end
tmueller@20
   579
		
tmueller@0
   580
		elseif args.actionsaveprops then
tmueller@23
   581
			-- Save properties
tmueller@0
   582
			section.hidden = args.editvisibility and true
tmueller@0
   583
			section.secret = args.editsecrecy and true
tmueller@0
   584
			section.secure = args.editsecure and true
tmueller@0
   585
			section.label = args.editlabel ~= "" and args.editlabel or nil
tmueller@0
   586
			section.title = args.edittitle ~= "" and args.edittitle or nil
tmueller@20
   587
			section.redirect =
tmueller@20
   588
				args.editredirect ~= "" and args.editredirect or nil
tmueller@23
   589
			save = true
tmueller@20
   590
		
tmueller@0
   591
		elseif args.actionup then
tmueller@23
   592
			-- Move node up
tmueller@0
   593
			local t, i = checkpath(config.sections, sectionpath)
tmueller@0
   594
			if t and i > 1 then
tmueller@0
   595
				local item = table.remove(t, i)
tmueller@0
   596
				table.insert(t, i - 1, item)
tmueller@23
   597
				save = true
tmueller@0
   598
			end
tmueller@20
   599
		
tmueller@0
   600
		elseif args.actiondown then
tmueller@23
   601
			-- Move node down
tmueller@0
   602
			local t, i = checkpath(config.sections, sectionpath)
tmueller@0
   603
			if t and i < #t then
tmueller@0
   604
				local item = table.remove(t, i)
tmueller@0
   605
				table.insert(t, i + 1, item)
tmueller@23
   606
				save = true
tmueller@0
   607
			end
tmueller@20
   608
		
tmueller@0
   609
		elseif args.actioncreateprofile and args.createprofile then
tmueller@23
   610
			-- Create profile
tmueller@0
   611
			local c = checkprofilename(args.createprofile:lower())
tmueller@0
   612
			if c == profile then
tmueller@0
   613
				useralert = { text = loc("ALERT_CANNOT_COPY_PROFILE_TO_SELF") }
tmueller@0
   614
			else
tmueller@0
   615
				local profiles = getprofiles(config.contentdir, lang)
tmueller@0
   616
				if profiles[c] and not args.actionconfirm then
tmueller@20
   617
					useralert = {
tmueller@20
   618
						text = c == pubprofile and 
tmueller@0
   619
							loc("ALERT_OVERWRITE_PUBLISHED_PROFILE") or
tmueller@0
   620
							loc("ALERT_OVERWRITE_EXISTING_PROFILE"),
tmueller@0
   621
						confirm =
tmueller@20
   622
							'<input type="submit" name="actioncreateprofile" value="' .. 
tmueller@20
   623
							loc("OVERWRITE") .. '" /> ' ..
tmueller@20
   624
							hidden("actionconfirm", "true") .. 
tmueller@20
   625
							hidden("createprofile", c)
tmueller@20
   626
					}
tmueller@0
   627
				else
tmueller@0
   628
					if profiles[c] then
tmueller@0
   629
						deletedir(config.contentdir .. "/" .. c .. "_" .. lang)
tmueller@0
   630
					end
tmueller@0
   631
					copyprofile(config.contentdir, lang, profile, c)
tmueller@0
   632
				end
tmueller@0
   633
			end
tmueller@20
   634
		
tmueller@0
   635
		elseif args.actiondeleteprofile and args.deleteprofile then
tmueller@23
   636
			-- Delete profile
tmueller@0
   637
			local c = checkprofilename(args.deleteprofile:lower())
tmueller@20
   638
			assert(c ~= pubprofile,
tmueller@20
   639
				dbmsg(loc("CANNOT_DELETE_PUBLISHED_PROFILE"), c))
tmueller@0
   640
			if args.actionconfirm then
tmueller@0
   641
				deletedir(config.contentdir .. "/" .. c .. "_" .. lang)
tmueller@0
   642
				profile = nil
tmueller@0
   643
				args.profile = nil
tmueller@23
   644
				init() -- get new sectionfname etc.
tmueller@23
   645
				save = true
tmueller@0
   646
			else
tmueller@20
   647
				useralert = { 
tmueller@20
   648
					text = loc("ALERT_DELETE_PROFILE"),
tmueller@20
   649
					confirm = 
tmueller@20
   650
						'<input type="submit" name="actiondeleteprofile" value="' .. 
tmueller@20
   651
						loc("DELETE") .. '" /> ' ..
tmueller@20
   652
						hidden("actionconfirm", "true") ..
tmueller@20
   653
						hidden("deleteprofile", c)
tmueller@20
   654
				}
tmueller@0
   655
			end
tmueller@20
   656
		
tmueller@0
   657
		elseif args.actionchangeprofile and args.changeprofile then
tmueller@23
   658
			-- Change profile
tmueller@0
   659
			local c = checkprofilename(args.changeprofile:lower())
tmueller@0
   660
			profile = c
tmueller@0
   661
			args.profile = c
tmueller@23
   662
			save = true
tmueller@20
   663
		
tmueller@0
   664
		elseif args.actionpublishprofile and args.publishprofile then
tmueller@23
   665
			-- Publish profile
tmueller@0
   666
			local c = checkprofilename(args.publishprofile:lower())
tmueller@0
   667
			if c ~= _publicprofile then
tmueller@0
   668
				if args.actionconfirm then
tmueller@0
   669
					publishprofile(config.contentdir, lang, c)
tmueller@23
   670
					save = true
tmueller@0
   671
				else
tmueller@20
   672
					useralert = {
tmueller@20
   673
						text = loc("ALERT_PUBLISH_PROFILE"),
tmueller@20
   674
						confirm =
tmueller@20
   675
							'<input type="submit" name="actionpublishprofile" value="' ..
tmueller@20
   676
							loc("PUBLISH") .. '" /> ' ..
tmueller@20
   677
							hidden("actionconfirm", "true") ..
tmueller@20
   678
							hidden("publishprofile", c)
tmueller@20
   679
					}
tmueller@20
   680
				end
tmueller@20
   681
			end
tmueller@0
   682
		end
tmueller@0
   683
		
tmueller@23
   684
		if save then
tmueller@23
   685
			-- Write sections atomically, reload
tmueller@23
   686
			local tempname = sectionfname .. "." .. session.sessionname
tmueller@0
   687
			local f, msg = open(tempname, "wb")
tmueller@20
   688
			assert(f, dbmsg("Error opening section file for writing", msg))
tmueller@0
   689
			tek.dump(config.sections, function(...)
tmueller@0
   690
				f:write(unpack(arg))
tmueller@0
   691
			end)
tmueller@0
   692
			f:close()
tmueller@0
   693
			local success, msg = rename(tempname, sectionfname)
tmueller@20
   694
			assert(success, dbmsg("Error renaming section file", msg))
tmueller@0
   695
			init()
tmueller@0
   696
		end
tmueller@0
   697
	
tmueller@0
   698
	elseif args.editkey and checksectionname(args.editkey) then
tmueller@0
   699
		if args.actiondelete then
tmueller@23
   700
			-- Delete node in secondary editable section:
tmueller@20
   701
			deletenode(contentdir,
tmueller@20
   702
				sectionpath:gsub("/", "_") .. "." .. args.editkey)
tmueller@0
   703
		end
tmueller@0
   704
	end
tmueller@0
   705
end
tmueller@0
   706
tmueller@0
   707
tmueller@23
   708
--	Load configuration
tmueller@0
   709
tmueller@0
   710
config = source("../etc/config.lua") or { }
tmueller@20
   711
config.passwdfile = posix.abspath(config.passwdfile or "../etc/passwd.lua")
tmueller@0
   712
config.sessiondir = posix.abspath(config.sessiondir or "../var/sessions")
tmueller@0
   713
config.extdir = posix.abspath(config.extdir or "../extensions")
tmueller@20
   714
config.contentdir = posix.abspath(config.contentdir or "../content")
tmueller@20
   715
config.localedir = posix.abspath(config.localedir or "../locale")
tmueller@0
   716
config.defname = config.defname or "home"
tmueller@0
   717
config.deflang = config.deflang or "en"
tmueller@20
   718
config.sessionmaxage = config.sessionmaxage or 600
tmueller@0
   719
config.secureport = config.secureport or 443
tmueller@0
   720
tmueller@20
   721
tmueller@0
   722
--	manage login and establish session
tmueller@0
   723
tmueller@0
   724
session.init(config.sessiondir, args.session, config.sessionmaxage)
tmueller@0
   725
if args.login then
tmueller@0
   726
	if args.login == "false" then
tmueller@0
   727
		session.delete()
tmueller@0
   728
		session = nil
tmueller@0
   729
	elseif args.password then
tmueller@0
   730
		local pwddb = source(config.passwdfile)
tmueller@0
   731
		local pwdentry = pwddb[args.login]
tmueller@0
   732
		if pwdentry and pwdentry.password == args.password then
tmueller@0
   733
			session.data.authuser = pwdentry.username
tmueller@0
   734
			session.data.id = session.id
tmueller@0
   735
		end
tmueller@0
   736
	end
tmueller@0
   737
end
tmueller@0
   738
tmueller@20
   739
secure = cgi.request.Port == config.secureport
tmueller@20
   740
authuser = session and session.data.authuser
tmueller@20
   741
tmueller@20
   742
if not authuser then
tmueller@0
   743
	session = nil
tmueller@0
   744
	args.session = nil
tmueller@0
   745
end
tmueller@0
   746
tmueller@23
   747
tmueller@20
   748
-- get lang, locale, profile, section
tmueller@0
   749
tmueller@0
   750
init()
tmueller@0
   751
if authuser then
tmueller@0
   752
	handlestate()
tmueller@0
   753
end
tmueller@0
   754
tmueller@23
   755
tmueller@0
   756
-- current document
tmueller@20
   757
tmueller@0
   758
document = cgi.document.Name
tmueller@0
   759
document = sectionpath and document .. "/" .. sectionpath
tmueller@0
   760
tmueller@23
   761
tmueller@0
   762
-- get content filename from section path
tmueller@20
   763
tmueller@0
   764
local fname = sectionpath:gsub("/", "_")
tmueller@0
   765
tmueller@23
   766
tmueller@0
   767
-- add links for creating new nodes
tmueller@20
   768
tmueller@0
   769
if authuser then
tmueller@20
   770
	local newent = { name = "new", 
tmueller@20
   771
		label = "[" .. loc("NEW") .. "]",
tmueller@20
   772
		action = "actionnew=true" }
tmueller@0
   773
	for _, s in ipairs(submenus) do
tmueller@20
   774
		table.insert(s.entries, newent)
tmueller@0
   775
	end
tmueller@0
   776
	if submenus[#submenus].name then
tmueller@20
   777
		table.insert(submenus, {
tmueller@20
   778
			name = "new", 
tmueller@20
   779
			entries = { [1] = newent }
tmueller@20
   780
		})
tmueller@0
   781
	end
tmueller@0
   782
end
tmueller@0
   783
tmueller@23
   784
tmueller@0
   785
--	create section function
tmueller@0
   786
tmueller@0
   787
local func, msg = loadhtml(open("loona/editable.lua"),
tmueller@0
   788
	"tek.web.out", "loona/editable.lua")
tmueller@0
   789
tmueller@20
   790
assert(func, dbmsg("Syntax error", msg))
tmueller@0
   791
tmueller@0
   792
local editable = func()
tmueller@0
   793
tmueller@0
   794
function body(name)
tmueller@0
   795
	name = checksectionname(name)
tmueller@0
   796
	if name == "main" then
tmueller@0
   797
		dosnippet(config, editable("main", contentdir, fname, fname))
tmueller@0
   798
	else
tmueller@0
   799
		local ext = "." .. name
tmueller@0
   800
		dosnippet(config, editable(name, contentdir,
tmueller@20
   801
			getsectionfile(submenus, contentdir, ext), fname .. ext))
tmueller@0
   802
	end
tmueller@0
   803
end
tmueller@0
   804
tmueller@23
   805
tmueller@0
   806
--	write back session state
tmueller@0
   807
tmueller@0
   808
if session then
tmueller@0
   809
	session.save()
tmueller@0
   810
end
tmueller@0
   811
tmueller@0
   812
tmueller@0
   813
-- do
tmueller@0
   814
-- 	local f = open("/tmp/foo", "wb")
tmueller@0
   815
-- 	tek.dump(config.sections, function(s)
tmueller@0
   816
-- 		f:write(s)
tmueller@0
   817
-- 	end)
tmueller@0
   818
-- end
tmueller@0
   819