(* COCANWIKI - a wiki written in Objective CAML.
* Written by Richard W.M. Jones <rich@merjis.com>.
* Copyright (C) 2004 Merjis Ltd.
- * $Id: cocanwiki.ml,v 1.1 2004/10/21 11:42:05 rich Exp $
+ * $Id: cocanwiki.ml,v 1.7 2005/11/21 15:28:36 rich Exp $
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
open Cocanwiki_ok
open Cocanwiki_strings
-module Pool = DbiPool (Dbi_postgres)
+module Pool = DbiPool (Dbi_postgresql)
(* This function is used to grab a database handle. It's used in a couple
* of very special places, and is not for general consumption.
type permissions_t = CanView | CanEdit | CanManageUsers | CanManageContacts
| CanManageSite | CanEditGlobalCSS | CanImportMail
+(* User preferences and other settings (some cannot be changed by the user). *)
+type prefs_t = {
+ email : string option; (* Email address. *)
+ email_notify : bool; (* Email notification. *)
+}
+
(* The "user object". *)
type user_t = Anonymous (* Not logged in. *)
- | User of int * string * permissions_t list
- (* Userid, name, permissions. *)
+ | User of int * string * permissions_t list * prefs_t
+ (* Userid, name, perms, prefs. *)
let test_permission {edit_anon = edit_anon; view_anon = view_anon} perm user =
if perm = CanEdit && edit_anon then true
else if perm = CanView && view_anon then true
else match user with
Anonymous -> false
- | User (_, _, perms) -> List.mem perm perms
+ | User (_, _, perms, _) -> List.mem perm perms
let can_edit host = test_permission host CanEdit
let can_manage_users host = test_permission host CanManageUsers
*)
let hostid, hostname, canonical_hostname, edit_anon, view_anon =
let hostname = try Request.hostname r
- with Not_found -> failwith "No ``Host:'' header in request" in
+ with Not_found ->
+ error ~back_button:true
+ ~title:"Browser problem" q
+ ("Your browser didn't send a \"Host\" header as part of " ^
+ "the HTTP request. Unfortunately this web server cannot " ^
+ "handle HTTP requests without a \"Host\" header.");
+ return () in
let hostname = String.lowercase hostname in
let sth =
| _ -> assert false)
with
Not_found ->
- failwith ("Hostname ``" ^ hostname ^ "'' not found in " ^
- "the hosts/hostnames tables in the database.") in
+ error ~back_button:true
+ ~title:"Unknown website" q
+ ("No website called \"" ^ hostname ^ "\" can be found. " ^
+ "If you are the administrator of this site, check that " ^
+ "the hostname is listed in the \"hostnames\" table " ^
+ "in the database.");
+ return () in
(* Create the host object. *)
let host = { hostname = hostname;
*)
if q#param_exists "cookie" then (
let value = q#param "cookie" in
- let cookie = Cookie.cookie ~name:"auth" ~value ~path:"/" () in
- Table.set (Request.headers_out r) "Set-Cookie" cookie#as_string;
+ let cookie = Cookie.cookie "auth" value ~path:"/" in
+ Table.set (Request.headers_out r) "Set-Cookie" cookie#to_string;
value
) else (
(* Normal cookie, from the headers. *)
dbh#prepare_cached
"select u.id, u.name, u.can_edit, u.can_manage_users,
u.can_manage_contacts, u.can_manage_site,
- u.can_edit_global_css, u.can_import_mail
+ u.can_edit_global_css, u.can_import_mail,
+ u.email, u.email_notify
from usercookies uc, users u
where uc.cookie = ? and uc.userid = u.id and u.hostid = ?" in
sth#execute [`String cookie; `Int hostid];
[ `Int userid; `String name;
`Bool can_edit; `Bool can_manage_users;
`Bool can_manage_contacts; `Bool can_manage_site;
- `Bool can_edit_global_css; `Bool can_import_mail ] ->
+ `Bool can_edit_global_css; `Bool can_import_mail;
+ (`Null | `String _) as email; `Bool email_notify ] ->
(* Every logged in user can view. *)
let perms = [CanView] in
let perms =
let perms =
if can_import_mail then CanImportMail :: perms
else perms in
- User (userid, name, perms)
+ (* Preferences. *)
+ let email =
+ match email with
+ `Null -> None
+ | `String email -> Some email in
+ let prefs = { email = email;
+ email_notify = email_notify; } in
+ User (userid, name, perms, prefs)
| _ -> assert false)
with
Not_found -> Anonymous
(* Call the actual CGI script. *)
run r q dbh hostid host user
) else (
- if user = Anonymous then
- q#redirect ("http://" ^ hostname ^ "/_login")
- else
+ if user = Anonymous then (
+ (* Not logged in and no permission to do the requested action,
+ * so redirect to the login script. If possible set the
+ * redirect parameter so that we return to the right URL.
+ *)
+ let redirect =
+ try
+ (* If we passed through mod_rewrite, then it saved the
+ * unmodified original URL in a subprocess environment
+ * variable called SCRIPT_URL:
+ *)
+ let tbl = Request.subprocess_env r in
+ Some (Table.get tbl "SCRIPT_URL")
+ with
+ Not_found ->
+ try
+ (* Otherwise try the ordinary uri field in request_rec. *)
+ Some (Request.uri r)
+ with Not_found ->
+ None in
+
+ let url =
+ "http://" ^ hostname ^ "/_login" ^
+ match redirect with
+ | None -> ""
+ | Some url -> "?redirect=" ^ Cgi_escape.escape_url url in
+ q#redirect url
+ ) else
error ~back_button:true
~title:"Access denied"
q "You do not have permission to access this part of the site."