]> WPIA git - gigi.git/blob - src/org/cacert/gigi/pages/admin/support/SupportUserDetailsPage.java
upd: enforce a more strict Form call pattern.
[gigi.git] / src / org / cacert / gigi / pages / admin / support / SupportUserDetailsPage.java
1 package org.cacert.gigi.pages.admin.support;
2
3 import java.io.IOException;
4 import java.util.HashMap;
5 import java.util.Map;
6
7 import javax.servlet.http.HttpServletRequest;
8 import javax.servlet.http.HttpServletResponse;
9
10 import org.cacert.gigi.dbObjects.Domain;
11 import org.cacert.gigi.dbObjects.EmailAddress;
12 import org.cacert.gigi.dbObjects.SupportedUser;
13 import org.cacert.gigi.dbObjects.User;
14 import org.cacert.gigi.localisation.Language;
15 import org.cacert.gigi.output.template.Form;
16 import org.cacert.gigi.output.template.Form.CSRFException;
17 import org.cacert.gigi.output.template.IterableDataset;
18 import org.cacert.gigi.pages.LoginPage;
19 import org.cacert.gigi.pages.ManagedMultiFormPage;
20 import org.cacert.gigi.util.AuthorizationContext;
21
22 public class SupportUserDetailsPage extends ManagedMultiFormPage {
23
24     public static final String PATH = "/support/user/";
25
26     public SupportUserDetailsPage() {
27         super("Support: User Details");
28     }
29
30     @Override
31     public void doGet(HttpServletRequest req, HttpServletResponse resp) throws IOException {
32         User user = getUser(req, resp);
33         if (user == null) {
34             return;
35         }
36         SupportedUser targetUser = new SupportedUser(user, getUser(req), LoginPage.getAuthorizationContext(req).getSupporterTicketId());
37         outputContents(req, resp, user, new SupportRevokeCertificatesForm(req, targetUser), new SupportUserDetailsForm(req, targetUser));
38     }
39
40     private User getUser(HttpServletRequest req, HttpServletResponse resp) throws IOException {
41         int id = -1;
42         if ( !req.getPathInfo().endsWith("/")) {
43             resp.sendError(404);
44             return null;
45         }
46         String[] idP = req.getPathInfo().split("/");
47         try {
48             id = Integer.parseInt(idP[idP.length - 1]);
49         } catch (NumberFormatException e) {
50             resp.sendError(404);
51             return null;
52         }
53         final User user = User.getById(id);
54         return user;
55     }
56
57     private void outputContents(HttpServletRequest req, HttpServletResponse resp, final User user, SupportRevokeCertificatesForm certificatesForm, SupportUserDetailsForm f) throws IOException {
58         HashMap<String, Object> vars = new HashMap<String, Object>();
59         vars.put("details", f);
60         final EmailAddress[] addrs = user.getEmails();
61         vars.put("emails", new IterableDataset() {
62
63             int i = 0;
64
65             @Override
66             public boolean next(Language l, Map<String, Object> vars) {
67                 for (; i < addrs.length;) {
68                     EmailAddress secAddress = addrs[i++];
69                     String address = secAddress.getAddress();
70                     if ( !address.equals(user.getEmail())) {
71                         vars.put("secmail", address);
72                         vars.put("status", l.getTranslation(secAddress.isVerified() ? "verified" : "not verified"));
73                         return true;
74                     }
75                 }
76                 return false;
77             }
78         });
79
80         final Domain[] doms = user.getDomains();
81         vars.put("domains", new IterableDataset() {
82
83             private int point = 0;
84
85             @Override
86             public boolean next(Language l, Map<String, Object> vars) {
87                 if (point >= doms.length) {
88                     return false;
89                 }
90                 Domain domain = doms[point];
91                 vars.put("domain", domain.getSuffix());
92                 vars.put("status", l.getTranslation(domain.isVerified() ? "verified" : "not verified"));
93                 point++;
94                 return true;
95             }
96         });
97
98         vars.put("certifrevoke", certificatesForm);
99         getDefaultTemplate().output(resp.getWriter(), getLanguage(req), vars);
100     }
101
102     @Override
103     public void doPost(HttpServletRequest req, HttpServletResponse resp) throws IOException {
104         User user = getUser(req, resp);
105         if (user == null) {
106             return;
107         }
108         if (Form.printFormErrors(req, resp.getWriter())) {
109             Form f = getForm(req);
110             SupportedUser targetUser = new SupportedUser(user, getUser(req), LoginPage.getAuthorizationContext(req).getSupporterTicketId());
111
112             if (f instanceof SupportUserDetailsForm) {
113                 outputContents(req, resp, user, new SupportRevokeCertificatesForm(req, targetUser), (SupportUserDetailsForm) f);
114             } else if (f instanceof SupportRevokeCertificatesForm) {
115                 outputContents(req, resp, user, (SupportRevokeCertificatesForm) f, new SupportUserDetailsForm(req, targetUser));
116             }
117         }
118
119     }
120
121     @Override
122     public boolean isPermitted(AuthorizationContext ac) {
123         return ac != null && ac.canSupport();
124     }
125
126     @Override
127     public Form getForm(HttpServletRequest req) throws CSRFException {
128         if (req.getParameter("revokeall") != null) {
129             return Form.getForm(req, SupportRevokeCertificatesForm.class);
130         } else if (req.getParameter("detailupdate") != null || req.getParameter("resetPass") != null || req.getParameter("removeGroup") != null || req.getParameter("addGroup") != null) {
131             return Form.getForm(req, SupportUserDetailsForm.class);
132         }
133         return null;
134     }
135 }