]> WPIA git - gigi.git/blobdiff - src/org/cacert/gigi/pages/Verify.java
add: prevent supporters from modifying their own accounts via support
[gigi.git] / src / org / cacert / gigi / pages / Verify.java
index cdcf490fa01cb58d29d497b0e1c15055d65c310c..2a5950e91e23e586329cec5446f3f0707bcca228 100644 (file)
@@ -2,6 +2,7 @@ package org.cacert.gigi.pages;
 
 import java.io.IOException;
 import java.io.PrintWriter;
+import java.util.Arrays;
 import java.util.HashMap;
 import java.util.Map;
 
@@ -14,9 +15,14 @@ import org.cacert.gigi.dbObjects.EmailAddress;
 import org.cacert.gigi.dbObjects.Verifyable;
 import org.cacert.gigi.localisation.Language;
 import org.cacert.gigi.output.template.Form;
+import org.cacert.gigi.output.template.SprintfCommand;
 
 public class Verify extends Page {
 
+    private static final SprintfCommand emailAddressVerified = new SprintfCommand("Email address {0} verified", Arrays.asList("${subject}"));
+
+    private static final SprintfCommand domainVerified = new SprintfCommand("Domain {0} verified", Arrays.asList("${subject}"));
+
     private class VerificationForm extends Form {
 
         private String hash;
@@ -27,24 +33,32 @@ public class Verify extends Page {
 
         private Verifyable target;
 
+        String subject;
+
         public VerificationForm(HttpServletRequest hsr) {
             super(hsr, PATH);
             hash = hsr.getParameter("hash");
             type = hsr.getParameter("type");
             id = hsr.getParameter("id");
             if ("email".equals(type)) {
-                target = EmailAddress.getById(Integer.parseInt(id));
-            } else if ("domain".equals("type")) {
-                target = Domain.getById(Integer.parseInt(id));
+                EmailAddress addr = EmailAddress.getById(Integer.parseInt(id));
+                subject = addr.getAddress();
+                target = addr;
+            } else if ("domain".equals(type)) {
+                Domain domain = Domain.getById(Integer.parseInt(id));
+                subject = domain.getSuffix();
+                target = domain;
             }
         }
 
         @Override
         public boolean submit(PrintWriter out, HttpServletRequest req) throws GigiApiException {
+            HashMap<String, Object> data = new HashMap<>();
+            data.put("subject", subject);
             if ("email".equals(type)) {
                 try {
                     target.verify(hash);
-                    out.println("Email verification completed.");
+                    emailAddressVerified.output(out, getLanguage(req), data);
                 } catch (IllegalArgumentException e) {
                     out.println(translate(req, "The email address is invalid."));
                 } catch (GigiApiException e) {
@@ -53,7 +67,7 @@ public class Verify extends Page {
             } else if ("domain".equals(type)) {
                 try {
                     target.verify(hash);
-                    out.println("Domain verification completed.");
+                    domainVerified.output(out, getLanguage(req), data);
                 } catch (IllegalArgumentException e) {
                     out.println(translate(req, "The domain is invalid."));
                 } catch (GigiApiException e) {
@@ -68,11 +82,8 @@ public class Verify extends Page {
             vars.put("hash", hash);
             vars.put("id", id);
             vars.put("type", type);
-            if (target instanceof EmailAddress) {
-                vars.put("subject", ((EmailAddress) target).getAddress());
-            } else if (target instanceof Domain) {
-                vars.put("subject", ((Domain) target).getSuffix());
-            }
+
+            vars.put("subject", subject);
             getDefaultTemplate().output(out, l, vars);
         }
     }
@@ -90,11 +101,7 @@ public class Verify extends Page {
 
     @Override
     public void doPost(HttpServletRequest req, HttpServletResponse resp) throws IOException {
-        try {
-            if (Form.getForm(req, VerificationForm.class).submit(resp.getWriter(), req)) {
-            }
-        } catch (GigiApiException e) {
-            e.format(resp.getWriter(), getLanguage(req));
+        if (Form.getForm(req, VerificationForm.class).submitProtected(resp.getWriter(), req)) {
         }
     }