1 package org.cacert.gigi.pages.main;
3 import java.io.InputStreamReader;
4 import java.io.PrintWriter;
5 import java.io.UnsupportedEncodingException;
6 import java.sql.PreparedStatement;
7 import java.sql.ResultSet;
8 import java.sql.SQLException;
10 import java.util.HashMap;
12 import javax.servlet.ServletRequest;
13 import javax.servlet.http.HttpServletRequest;
15 import org.cacert.gigi.Language;
16 import org.cacert.gigi.User;
17 import org.cacert.gigi.database.DatabaseConnection;
18 import org.cacert.gigi.output.DateSelector;
19 import org.cacert.gigi.output.Template;
20 import org.cacert.gigi.pages.Page;
21 import org.cacert.gigi.util.HTMLEncoder;
24 User buildup = new User();
28 boolean general = true, country = true, regional = true, radius = true;
31 t = new Template(new InputStreamReader(
32 Signup.class.getResourceAsStream("Signup.templ"), "UTF-8"));
33 } catch (UnsupportedEncodingException e) {
39 buildup.setSuffix("");
41 buildup.setDob(new Date(0));
43 DateSelector myDoB = new DateSelector("day", "month", "year");
45 public void writeForm(PrintWriter out, Language l) {
46 HashMap<String, Object> vars = new HashMap<String, Object>();
47 vars.put("fname", HTMLEncoder.encodeHTML(buildup.getFname()));
48 vars.put("mname", HTMLEncoder.encodeHTML(buildup.getMname()));
49 vars.put("lname", HTMLEncoder.encodeHTML(buildup.getLname()));
50 vars.put("suffix", HTMLEncoder.encodeHTML(buildup.getSuffix()));
51 vars.put("dob", myDoB);
52 vars.put("email", HTMLEncoder.encodeHTML(buildup.getEmail()));
53 vars.put("general", general ? " checked=\"checked\"" : "");
54 vars.put("country", country ? " checked=\"checked\"" : "");
55 vars.put("regional", regional ? " checked=\"checked\"" : "");
56 vars.put("radius", radius ? " checked=\"checked\"" : "");
60 l.getTranslation("Help on Names %sin the wiki%s"),
61 "<a href=\"//wiki.cacert.org/FAQ/HowToEnterNamesInJoinForm\" target=\"_blank\">",
63 t.output(out, l, vars);
65 private void update(HttpServletRequest r) {
66 if (r.getParameter("fname") != null) {
67 buildup.setFname(r.getParameter("fname"));
69 if (r.getParameter("lname") != null) {
70 buildup.setLname(r.getParameter("lname"));
72 if (r.getParameter("mname") != null) {
73 buildup.setMname(r.getParameter("mname"));
75 if (r.getParameter("suffix") != null) {
76 buildup.setSuffix(r.getParameter("suffix"));
78 if (r.getParameter("email") != null) {
79 buildup.setEmail(r.getParameter("email"));
81 general = "1".equals(r.getParameter("general"));
82 country = "1".equals(r.getParameter("country"));
83 regional = "1".equals(r.getParameter("regional"));
84 radius = "1".equals(r.getParameter("radius"));
88 public boolean submit(PrintWriter out, HttpServletRequest req) {
90 boolean failed = false;
91 out.println("<div class='formError'>");
92 if (buildup.getFname().equals("") || buildup.getLname().equals("")) {
93 outputError(out, req, "First and/or last names were blank.");
96 if (!myDoB.isValid()) {
97 outputError(out, req, "Invalid date of birth");
100 if (!"1".equals(req.getParameter("cca_agree"))) {
101 outputError(out, req,
102 "You have to agree to the CAcert Community agreement.");
105 if (buildup.getEmail().equals("")) {
106 outputError(out, req, "Email Address was blank");
109 String pw1 = req.getParameter("pword1");
110 String pw2 = req.getParameter("pword2");
111 if (pw1 == null || pw1.equals("")) {
112 outputError(out, req, "Pass Phrases were blank");
114 } else if (!pw1.equals(pw2)) {
115 outputError(out, req, "Pass Phrases don't match");
118 // TODO check password strength
120 out.println("</div>");
124 PreparedStatement q1 = DatabaseConnection.getInstance().prepare(
125 "select * from `email` where `email`=? and `deleted`=0");
126 PreparedStatement q2 = DatabaseConnection.getInstance().prepare(
127 "select * from `users` where `email`=? and `deleted`=0");
128 q1.setString(1, buildup.getEmail());
129 q2.setString(1, buildup.getEmail());
130 ResultSet r1 = q1.executeQuery();
131 ResultSet r2 = q2.executeQuery();
132 if (r1.next() || r2.next()) {
133 outputError(out, req,
134 "This email address is currently valid in the system.");
139 PreparedStatement q3 = DatabaseConnection
142 "select `domain` from `baddomains` where `domain`=RIGHT(?, LENGTH(`domain`))");
143 q3.setString(1, buildup.getEmail());
145 ResultSet r3 = q3.executeQuery();
147 String domain = r3.getString(1);
149 out.print(String.format(
151 "We don't allow signups from people using email addresses from %s"),
153 out.println("</div>");
157 } catch (SQLException e) {
161 // TODO fast-check mail
163 out.println("</div>");
167 // TODO start getting to work
170 private void outputError(PrintWriter out, ServletRequest req, String text) {
172 out.print(Page.translate(req, text));
173 out.println("</div>");