annotate src/login.html.luan @ 14:7d0c96408abf

restrict name
author Franklin Schmidt <fschmidt@gmail.com>
date Mon, 04 Jul 2022 17:04:14 -0600
parents 9166f6a14021
children a1db5223ced1
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
3
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
1 local Luan = require "luan:Luan.luan"
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
2 local error = Luan.error
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
3 local String = require "luan:String.luan"
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
4 local trim = String.trim or error()
14
7d0c96408abf restrict name
Franklin Schmidt <fschmidt@gmail.com>
parents: 6
diff changeset
5 local matches = String.matches or error()
3
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
6 local Html = require "luan:Html.luan"
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
7 local url_encode = Html.url_encode or error()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
8 local Io = require "luan:Io.luan"
4
a17e400ddaa1 add email
Franklin Schmidt <fschmidt@gmail.com>
parents: 3
diff changeset
9 local output_of = Io.output_of or error()
3
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
10 local Http = require "luan:http/Http.luan"
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
11 local Shared = require "site:/lib/Shared.luan"
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
12 local head = Shared.head or error()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
13 local header = Shared.header or error()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
14 local footer = Shared.footer or error()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
15 local base_url = Shared.base_url or error()
6
9166f6a14021 add email api
Franklin Schmidt <fschmidt@gmail.com>
parents: 4
diff changeset
16 local call_mail_api = Shared.call_mail_api or error()
3
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
17 local Forum = require "site:/lib/Forum.luan"
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
18 local forum_title = Forum.title or error()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
19 local User = require "site:/lib/User.luan"
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
20 local Db = require "site:/lib/Db.luan"
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
21 local run_in_transaction = Db.run_in_transaction or error()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
22
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
23
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
24 local function get_user(email,password)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
25 local user = User.get_by_email(email)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
26 user or error "email not found"
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
27 user.password == password or error "wrong password"
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
28 return user
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
29 end
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
30
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
31 local function login(user)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
32 Http.response.set_persistent_cookie("user",user.name)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
33 Http.response.set_persistent_cookie("password",user.password)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
34 Http.request.cookies.user = user.name
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
35 Http.request.cookies.password = user.password
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
36 end
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
37
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
38 local function register_form(user,name,error_message)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
39 if error_message ~= nil then %>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
40 <p error>Error: <%= error_message %></p>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
41 <% end %>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
42 <form>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
43 <input type="hidden" name="email" value="<%= user.email %>" >
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
44 <input type="hidden" name="password" value="<%= user.password %>" >
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
45 <label>User name for <%= user.email %></label>
14
7d0c96408abf restrict name
Franklin Schmidt <fschmidt@gmail.com>
parents: 6
diff changeset
46 <input type="text" name="name" value="<%= name or "" %>" autofocus required pattern="[a-zA-Z0-9_-]+">
3
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
47 <input type="submit" value="Register">
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
48 </form>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
49 <%
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
50 end
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
51
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
52 local function page(contents)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
53 Io.stdout = Http.response.text_writer()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
54 %>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
55 <!doctype html>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
56 <html>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
57 <head>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
58 <% head() %>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
59 <title><%=forum_title%> - Login or Register</title>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
60 </head>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
61 <body>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
62 <% header() %>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
63 <div content>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
64 <h1>Login or Register</h1>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
65 <%
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
66 contents()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
67 %>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
68 </div>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
69 <% footer() %>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
70 </body>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
71 </html>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
72 <%
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
73 end
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
74
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
75 return function()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
76 local email = Http.request.parameters.email
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
77 local password = Http.request.parameters.password
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
78 local name = Http.request.parameters.name
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
79 if email == nil then
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
80 page(function()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
81 %>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
82 <form>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
83 <label>Email address</label>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
84 <input type="email" name="email" autofocus required>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
85 <input type="submit" value="Login or Register">
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
86 </form>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
87 <%
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
88 end)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
89 elseif password == nil then
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
90 local user = User.get_or_create_by_email(email)
6
9166f6a14021 add email api
Franklin Schmidt <fschmidt@gmail.com>
parents: 4
diff changeset
91 local result = call_mail_api( "login_email", {
9166f6a14021 add email api
Franklin Schmidt <fschmidt@gmail.com>
parents: 4
diff changeset
92 base_url = base_url()
9166f6a14021 add email api
Franklin Schmidt <fschmidt@gmail.com>
parents: 4
diff changeset
93 from = forum_title.." <support@freedit.org>"
9166f6a14021 add email api
Franklin Schmidt <fschmidt@gmail.com>
parents: 4
diff changeset
94 email = user.email
9166f6a14021 add email api
Franklin Schmidt <fschmidt@gmail.com>
parents: 4
diff changeset
95 password = user.password
9166f6a14021 add email api
Franklin Schmidt <fschmidt@gmail.com>
parents: 4
diff changeset
96 } )
9166f6a14021 add email api
Franklin Schmidt <fschmidt@gmail.com>
parents: 4
diff changeset
97 result.okay or error(result.error)
3
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
98 page(function()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
99 %>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
100 <p>We have sent you an email. Please check your email to login or register.</p>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
101 <%
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
102 end)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
103 elseif name == nil then
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
104 local user = get_user(email,password)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
105 if user.name == nil then
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
106 page(function()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
107 register_form(user)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
108 end)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
109 else
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
110 login(user)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
111 page(function()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
112 %>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
113 <p>You are now logged in.</p>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
114 <%
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
115 end)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
116 end
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
117 else
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
118 name = trim(name)
14
7d0c96408abf restrict name
Franklin Schmidt <fschmidt@gmail.com>
parents: 6
diff changeset
119 matches( name, "^[a-zA-Z0-9_-]+$" ) or error "invalid name"
3
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
120 local error_message = nil
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
121 local user
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
122 run_in_transaction( function()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
123 user = get_user(email,password)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
124 if user.name ~= name and User.get_by_name(name) ~= nil then
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
125 error_message = "Name already in use"
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
126 else
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
127 user.name = name
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
128 user.save()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
129 end
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
130 end )
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
131 if error_message ~= nil then
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
132 page(function()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
133 register_form(user,name,error_message)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
134 end)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
135 else
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
136 login(user)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
137 page(function()
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
138 %>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
139 <p>You are now registered.</p>
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
140 <%
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
141 end)
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
142 end
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
143 end
Franklin Schmidt <fschmidt@gmail.com>
parents:
diff changeset
144 end