]> WPIA git - gigi.git/blobdiff - src/org/cacert/gigi/pages/orga/CreateOrgForm.java
upd: use a more strict pattern for handling forms
[gigi.git] / src / org / cacert / gigi / pages / orga / CreateOrgForm.java
index 32a9ceb7033ebba4a602f729372714ab8c13d813..086b3059cc591a6ca8bf66278039b379261cfdb2 100644 (file)
@@ -7,8 +7,11 @@ import javax.servlet.http.HttpServletRequest;
 
 import org.cacert.gigi.GigiApiException;
 import org.cacert.gigi.dbObjects.Organisation;
+import org.cacert.gigi.email.EmailProvider;
 import org.cacert.gigi.localisation.Language;
+import org.cacert.gigi.output.CountrySelector;
 import org.cacert.gigi.output.template.Form;
+import org.cacert.gigi.output.template.SprintfCommand;
 import org.cacert.gigi.output.template.Template;
 import org.cacert.gigi.pages.LoginPage;
 
@@ -20,45 +23,101 @@ public class CreateOrgForm extends Form {
 
     private String o = "";
 
-    private String c = "";
-
     private String st = "";
 
     private String l = "";
 
     private String email = "";
 
+    private String optionalName = "";
+
+    private String postalAddress = "";
+
     private boolean isEdit = false;
 
+    private CountrySelector cs;
+
     public CreateOrgForm(HttpServletRequest hsr) {
         super(hsr);
+        cs = new CountrySelector("C", false);
     }
 
     public CreateOrgForm(HttpServletRequest hsr, Organisation t) {
-        super(hsr);
+        this(hsr);
         isEdit = true;
         result = t;
         o = t.getName();
-        c = t.getState();
+
+        cs = new CountrySelector("C", false, t.getState());
+
         st = t.getProvince();
         l = t.getCity();
         email = t.getContactEmail();
+        optionalName = t.getOptionalName();
+        postalAddress = t.getPostalAddress();
     }
 
     @Override
-    public boolean submit(PrintWriter out, HttpServletRequest req) throws GigiApiException {
-        o = req.getParameter("O");
-        c = req.getParameter("C");
-        st = req.getParameter("ST");
-        l = req.getParameter("L");
-        email = req.getParameter("contact");
-        if (result != null) {
-            result.update(o, c, st, l, email);
+    public boolean submit(HttpServletRequest req) throws GigiApiException {
+        String action = req.getParameter("action");
+        if (action == null) {
+            return false;
+        }
+
+        if (action.equals("new")) {
+            checkCertData(req);
+            checkOrganisationData(req);
+            Organisation ne = new Organisation(o, cs.getCountry(), st, l, email, optionalName, postalAddress, LoginPage.getUser(req));
+            result = ne;
+            return true;
+        } else if (action.equals("updateOrganisationData")) {
+            checkOrganisationData(req);
+            result.updateOrgData(email, optionalName, postalAddress);
+            return true;
+        } else if (action.equals("updateCertificateData")) {
+            checkCertData(req);
+            result.updateCertData(o, cs.getCountry(), st, l);
             return true;
         }
-        Organisation ne = new Organisation(o, c, st, l, email, LoginPage.getUser(req));
-        result = ne;
-        return true;
+
+        return false;
+    }
+
+    private void checkOrganisationData(HttpServletRequest req) throws GigiApiException {
+        email = extractParam(req, "contact");
+        optionalName = extractParam(req, "optionalName");
+        postalAddress = extractParam(req, "postalAddress");
+        if ( !EmailProvider.isValidMailAddress(email)) {
+            throw new GigiApiException("Contact email is not a valid email address");
+        }
+    }
+
+    private void checkCertData(HttpServletRequest req) throws GigiApiException {
+        o = extractParam(req, "O");
+        st = extractParam(req, "ST");
+        l = extractParam(req, "L");
+
+        if (o.length() > 64 || o.length() < 1) {
+            throw new GigiApiException(SprintfCommand.createSimple("{0} not given or longer than {1} characters", "Organisation name", 64));
+        }
+
+        cs.update(req);
+
+        if (st.length() > 128 || st.length() < 1) {
+            throw new GigiApiException(SprintfCommand.createSimple("{0} not given or longer than {1} characters", "State/county", 128));
+        }
+
+        if (l.length() > 128 || l.length() < 1) {
+            throw new GigiApiException(SprintfCommand.createSimple("{0} not given or longer than {1} characters", "Town/suburb", 128));
+        }
+    }
+
+    private String extractParam(HttpServletRequest req, String name) {
+        String parameter = req.getParameter(name);
+        if (parameter == null) {
+            return "";
+        }
+        return parameter.trim();
     }
 
     public Organisation getResult() {
@@ -68,10 +127,13 @@ public class CreateOrgForm extends Form {
     @Override
     protected void outputContent(PrintWriter out, Language l, Map<String, Object> vars) {
         vars.put("O", o);
-        vars.put("C", c);
+        vars.put("C", cs);
         vars.put("ST", st);
         vars.put("L", this.l);
         vars.put("email", email);
+        vars.put("optionalName", optionalName);
+        vars.put("postalAddress", postalAddress);
+        vars.put("countryCode", cs);
         if (isEdit) {
             vars.put("edit", true);
         }