paul@12 | 1 | # -*- coding: iso-8859-1 -*- |
paul@12 | 2 | """ |
paul@12 | 3 | MoinMoin - SendMessage Action |
paul@12 | 4 | |
paul@16 | 5 | @copyright: 2012, 2013 by Paul Boddie <paul@boddie.org.uk> |
paul@12 | 6 | @license: GNU GPL (v2 or later), see COPYING.txt for details. |
paul@12 | 7 | """ |
paul@12 | 8 | |
paul@21 | 9 | from MoinMoin.action import ActionBase, AttachFile |
paul@21 | 10 | from MoinMoin.formatter import text_html |
paul@12 | 11 | from MoinMoin.log import getLogger |
paul@27 | 12 | from MoinMoin.Page import Page |
paul@21 | 13 | from MoinMoin import config |
paul@12 | 14 | from MoinMessage import GPG, MoinMessageError, Message, sendMessage |
paul@12 | 15 | from MoinSupport import * |
paul@37 | 16 | from MoinMoin.wikiutil import escape, MimeType, parseQueryString, \ |
paul@37 | 17 | taintfilename, getInterwikiHomePage |
paul@21 | 18 | |
paul@21 | 19 | from email.mime.image import MIMEImage |
paul@21 | 20 | from email.mime.multipart import MIMEMultipart |
paul@12 | 21 | from email.mime.text import MIMEText |
paul@40 | 22 | from os.path import abspath, exists, join |
paul@21 | 23 | import urllib |
paul@12 | 24 | |
paul@40 | 25 | try: |
paul@40 | 26 | from MoinMoin.web import static |
paul@40 | 27 | htdocs = abspath(join(static.__file__, "htdocs")) |
paul@40 | 28 | except ImportError: |
paul@40 | 29 | htdocs = None |
paul@40 | 30 | |
paul@12 | 31 | Dependencies = [] |
paul@12 | 32 | |
paul@40 | 33 | def get_htdocs(request): |
paul@40 | 34 | |
paul@40 | 35 | "Use the 'request' to find the htdocs directory." |
paul@40 | 36 | |
paul@40 | 37 | global htdocs |
paul@40 | 38 | |
paul@40 | 39 | if not htdocs: |
paul@40 | 40 | htdocs_in_cfg = getattr(request.cfg, "moinmessage_static_files", None) |
paul@40 | 41 | if htdocs_in_cfg and exists(htdocs_in_cfg): |
paul@40 | 42 | htdocs = htdocs_in_cfg |
paul@40 | 43 | return htdocs |
paul@40 | 44 | htdocs_in_data = abspath(join(request.cfg.data_dir, "../htdocs")) |
paul@40 | 45 | if exists(htdocs_in_data): |
paul@40 | 46 | htdocs = htdocs_in_data |
paul@40 | 47 | return htdocs |
paul@40 | 48 | |
paul@40 | 49 | return htdocs |
paul@40 | 50 | |
paul@12 | 51 | class SendMessage(ActionBase, ActionSupport): |
paul@12 | 52 | |
paul@12 | 53 | "An action that can send a message to another site." |
paul@12 | 54 | |
paul@12 | 55 | def get_form_html(self, buttons_html): |
paul@12 | 56 | |
paul@12 | 57 | "Present an interface for message sending." |
paul@12 | 58 | |
paul@12 | 59 | _ = self._ |
paul@12 | 60 | request = self.request |
paul@12 | 61 | form = self.get_form() |
paul@12 | 62 | |
paul@12 | 63 | message = form.get("message", [""])[0] |
paul@12 | 64 | recipient = form.get("recipient", [""])[0] |
paul@25 | 65 | preview = form.get("preview") |
paul@26 | 66 | queue = form.get("queue") |
paul@12 | 67 | |
paul@12 | 68 | # Get a list of potential recipients. |
paul@12 | 69 | |
paul@12 | 70 | recipients = self.get_recipients() |
paul@12 | 71 | |
paul@12 | 72 | # Prepare the recipients list, selecting the specified recipients. |
paul@12 | 73 | |
paul@12 | 74 | recipients_list = [] |
paul@12 | 75 | |
paul@12 | 76 | if recipients: |
paul@12 | 77 | recipients_list += self.get_option_list(recipient, recipients) or [] |
paul@12 | 78 | |
paul@12 | 79 | recipients_list.sort() |
paul@12 | 80 | |
paul@21 | 81 | # Prepare any preview. |
paul@21 | 82 | |
paul@21 | 83 | request.formatter.setPage(self.page) |
paul@22 | 84 | preview_output = preview and formatText(message, request, request.formatter, inhibit_p=False) or "" |
paul@21 | 85 | |
paul@12 | 86 | # Fill in the fields and labels. |
paul@12 | 87 | |
paul@12 | 88 | d = { |
paul@12 | 89 | "buttons_html" : buttons_html, |
paul@25 | 90 | "recipient_label" : escape(_("Recipient")), |
paul@12 | 91 | "recipients_list" : "\n".join(recipients_list), |
paul@25 | 92 | "message_label" : escape(_("Message text")), |
paul@21 | 93 | "message_default" : escape(message), |
paul@25 | 94 | "preview_label" : escattr(_("Preview message")), |
paul@21 | 95 | "preview_output" : preview_output, |
paul@26 | 96 | "queue_label" : escape(_("Queue message for sending")), |
paul@26 | 97 | "queue_checked" : queue and 'checked="checked" ' or "", |
paul@12 | 98 | } |
paul@12 | 99 | |
paul@12 | 100 | # Prepare the output HTML. |
paul@12 | 101 | |
paul@12 | 102 | html = ''' |
paul@12 | 103 | <table> |
paul@12 | 104 | <tr> |
paul@12 | 105 | <td class="label"><label>%(recipient_label)s</label></td> |
paul@12 | 106 | <td> |
paul@12 | 107 | <select name="recipient"> |
paul@12 | 108 | %(recipients_list)s |
paul@12 | 109 | </select> |
paul@12 | 110 | </td> |
paul@12 | 111 | </tr> |
paul@12 | 112 | <tr> |
paul@12 | 113 | <td class="label"><label>%(message_label)s</label></td> |
paul@21 | 114 | <td> |
paul@21 | 115 | <textarea name="message" cols="60" rows="10">%(message_default)s</textarea> |
paul@12 | 116 | </td> |
paul@12 | 117 | </tr> |
paul@12 | 118 | <tr> |
paul@12 | 119 | <td></td> |
paul@21 | 120 | <td class="buttons"> |
paul@21 | 121 | <input name="preview" type="submit" value="%(preview_label)s" /> |
paul@21 | 122 | </td> |
paul@21 | 123 | </tr> |
paul@21 | 124 | <tr> |
paul@21 | 125 | <td></td> |
paul@21 | 126 | <td class="moinmessage-preview"> |
paul@21 | 127 | %(preview_output)s |
paul@21 | 128 | </td> |
paul@21 | 129 | </tr> |
paul@21 | 130 | <tr> |
paul@26 | 131 | <td class="label"><label>%(queue_label)s</label></td> |
paul@26 | 132 | <td> |
paul@26 | 133 | <input name="queue" type="checkbox" value="true" %(queue_checked)s/> |
paul@26 | 134 | </td> |
paul@26 | 135 | <tr> |
paul@21 | 136 | <td></td> |
paul@21 | 137 | <td class="buttons"> |
paul@12 | 138 | %(buttons_html)s |
paul@12 | 139 | </td> |
paul@12 | 140 | </tr> |
paul@12 | 141 | </table>''' % d |
paul@12 | 142 | |
paul@12 | 143 | return html |
paul@12 | 144 | |
paul@12 | 145 | def do_action(self): |
paul@12 | 146 | |
paul@12 | 147 | "Attempt to send the message." |
paul@12 | 148 | |
paul@12 | 149 | _ = self._ |
paul@12 | 150 | request = self.request |
paul@12 | 151 | form = self.get_form() |
paul@12 | 152 | |
paul@12 | 153 | text = form.get("message", [None])[0] |
paul@12 | 154 | recipient = form.get("recipient", [None])[0] |
paul@26 | 155 | queue = form.get("queue") |
paul@12 | 156 | |
paul@12 | 157 | if not text: |
paul@12 | 158 | return 0, _("A message must be given.") |
paul@12 | 159 | |
paul@12 | 160 | if not recipient: |
paul@12 | 161 | return 0, _("A recipient must be given.") |
paul@12 | 162 | |
paul@12 | 163 | homedir = self.get_homedir() |
paul@12 | 164 | if not homedir: |
paul@12 | 165 | return 0, _("MoinMessage has not been set up: a GPG homedir is not defined.") |
paul@12 | 166 | |
paul@12 | 167 | gpg = GPG(homedir) |
paul@12 | 168 | |
paul@12 | 169 | # Construct a message from the request. |
paul@12 | 170 | |
paul@12 | 171 | message = Message() |
paul@21 | 172 | |
paul@21 | 173 | container = MIMEMultipart("related") |
paul@21 | 174 | container["Update-Action"] = "store" |
paul@26 | 175 | container["To"] = recipient |
paul@21 | 176 | |
paul@21 | 177 | # Add the message body and any attachments. |
paul@21 | 178 | |
paul@21 | 179 | fmt = OutgoingHTMLFormatter(request) |
paul@21 | 180 | fmt.setPage(request.page) |
paul@23 | 181 | body = formatText(text, request, fmt, inhibit_p=False) |
paul@21 | 182 | |
paul@21 | 183 | container.attach(MIMEText(body, "html")) |
paul@21 | 184 | |
paul@40 | 185 | for pos, (path, filename) in enumerate(fmt.attachments): |
paul@21 | 186 | |
paul@21 | 187 | # Obtain the attachment content. |
paul@21 | 188 | |
paul@21 | 189 | f = open(path, "rb") |
paul@21 | 190 | try: |
paul@21 | 191 | body = f.read() |
paul@21 | 192 | finally: |
paul@21 | 193 | f.close() |
paul@21 | 194 | |
paul@21 | 195 | # Determine the attachment type. |
paul@21 | 196 | |
paul@21 | 197 | mimetype = MimeType(filename=filename) |
paul@21 | 198 | |
paul@21 | 199 | # NOTE: Support a limited set of explicit part types for now. |
paul@21 | 200 | |
paul@21 | 201 | if mimetype.major == "image": |
paul@21 | 202 | part = MIMEImage(body, mimetype.minor, **mimetype.params) |
paul@21 | 203 | elif mimetype.major == "text": |
paul@21 | 204 | part = MIMEText(body, mimetype.minor, mimetype.charset, **mimetype.params) |
paul@21 | 205 | else: |
paul@21 | 206 | part = MIMEApplication(body, mimetype.minor, **mimetype.params) |
paul@21 | 207 | |
paul@21 | 208 | # Label the attachment and include it in the message. |
paul@21 | 209 | |
paul@21 | 210 | part["Content-ID"] = "attachment%d" % pos |
paul@21 | 211 | container.attach(part) |
paul@21 | 212 | |
paul@21 | 213 | message.add_update(container) |
paul@12 | 214 | |
paul@12 | 215 | # Get the sender details for signing messages. |
paul@12 | 216 | # This is not the same as the details for authenticating users in the |
paul@12 | 217 | # PostMessage action since the fingerprints refer to public keys. |
paul@12 | 218 | |
paul@21 | 219 | signing_users = self.get_signing_users() |
paul@12 | 220 | signer = signing_users and signing_users.get(request.user.name) |
paul@12 | 221 | |
paul@12 | 222 | # Get the recipient details. |
paul@12 | 223 | |
paul@12 | 224 | recipients = self.get_recipients() |
paul@12 | 225 | if not recipients: |
paul@12 | 226 | return 0, _("No recipients page is defined for MoinMessage.") |
paul@12 | 227 | |
paul@12 | 228 | recipient_details = recipients.get(recipient) |
paul@12 | 229 | if not recipient_details: |
paul@12 | 230 | return 0, _("The specified recipient is not present in the list of known contacts.") |
paul@12 | 231 | |
paul@27 | 232 | parameters = parseDictEntry(recipient_details, ("fingerprint",)) |
paul@27 | 233 | |
paul@27 | 234 | if not parameters.has_key("page") and not parameters.has_key("url"): |
paul@27 | 235 | return 0, _("The recipient details are missing a location for sent messages.") |
paul@27 | 236 | |
paul@27 | 237 | if parameters.has_key("url") and not parameters.has_key("fingerprint"): |
paul@27 | 238 | return 0, _("The recipient details are missing a fingerprint for sending messages.") |
paul@12 | 239 | |
paul@12 | 240 | # Sign, encrypt and send the message. |
paul@12 | 241 | |
paul@26 | 242 | message = message.get_payload() |
paul@26 | 243 | |
paul@27 | 244 | if not queue and parameters.has_key("url"): |
paul@26 | 245 | try: |
paul@26 | 246 | if signer: |
paul@26 | 247 | message = gpg.signMessage(message, signer) |
paul@12 | 248 | |
paul@27 | 249 | message = gpg.encryptMessage(message, parameters["fingerprint"]) |
paul@27 | 250 | sendMessage(message, parameters["url"]) |
paul@26 | 251 | |
paul@26 | 252 | except MoinMessageError, exc: |
paul@39 | 253 | return 0, "%s: %s" % (_("The message could not be prepared and sent"), exc) |
paul@12 | 254 | |
paul@27 | 255 | # Or queue the message on the specified page. |
paul@27 | 256 | |
paul@27 | 257 | elif parameters.has_key("page"): |
paul@27 | 258 | page = Page(request, parameters["page"]) |
paul@27 | 259 | outbox = ItemStore(page, "messages", "message-locks") |
paul@27 | 260 | outbox.append(message.as_string()) |
paul@27 | 261 | |
paul@27 | 262 | # Or queue the message in a special outbox. |
paul@26 | 263 | |
paul@26 | 264 | else: |
paul@26 | 265 | outbox = ItemStore(request.page, "outgoing-messages", "outgoing-message-locks") |
paul@26 | 266 | outbox.append(message.as_string()) |
paul@12 | 267 | |
paul@31 | 268 | return 1, _("Message sent!") |
paul@12 | 269 | |
paul@12 | 270 | def get_homedir(self): |
paul@12 | 271 | |
paul@12 | 272 | "Locate the GPG home directory." |
paul@12 | 273 | |
paul@12 | 274 | return getattr(self.request.cfg, "moinmessage_gpg_homedir") |
paul@12 | 275 | |
paul@12 | 276 | def get_recipients(self): |
paul@37 | 277 | |
paul@37 | 278 | """ |
paul@37 | 279 | Return the recipients dictionary by first obtaining the page in which it |
paul@37 | 280 | is stored. This page may either be a subpage of the user's home page, if |
paul@37 | 281 | stored on this wiki, or it may be relative to the site root. |
paul@37 | 282 | |
paul@37 | 283 | The name of the subpage is defined by the configuration setting |
paul@37 | 284 | 'moinmessage_gpg_recipients_page', which if absent is set to |
paul@37 | 285 | "MoinMessageRecipientsDict". |
paul@37 | 286 | """ |
paul@37 | 287 | |
paul@37 | 288 | request = self.request |
paul@37 | 289 | |
paul@37 | 290 | subpage = getattr(request.cfg, "moinmessage_gpg_recipients_page", "MoinMessageRecipientsDict") |
paul@37 | 291 | homedetails = getInterwikiHomePage(request) |
paul@37 | 292 | |
paul@37 | 293 | if homedetails: |
paul@37 | 294 | homewiki, homepage = homedetails |
paul@37 | 295 | if homewiki == "Self": |
paul@37 | 296 | recipients = getWikiDict("%s/%s" % (homepage, subpage), request) |
paul@37 | 297 | if recipients: |
paul@37 | 298 | return recipients |
paul@37 | 299 | |
paul@37 | 300 | return getWikiDict(subpage, request) |
paul@21 | 301 | |
paul@21 | 302 | def get_signing_users(self): |
paul@21 | 303 | return getWikiDict( |
paul@21 | 304 | getattr(self.request.cfg, "moinmessage_gpg_signing_users_page", "MoinMessageSigningUserDict"), |
paul@21 | 305 | self.request) |
paul@21 | 306 | |
paul@21 | 307 | # Special message formatters. |
paul@21 | 308 | |
paul@21 | 309 | def unquoteWikinameURL(url, charset=config.charset): |
paul@21 | 310 | |
paul@21 | 311 | """ |
paul@21 | 312 | The inverse of wikiutil.quoteWikinameURL, returning the page name referenced |
paul@21 | 313 | by the given 'url', with the page name assumed to be encoded using the given |
paul@21 | 314 | 'charset' (or default charset if omitted). |
paul@21 | 315 | """ |
paul@21 | 316 | |
paul@21 | 317 | return unicode(urllib.unquote(url), encoding=charset) |
paul@21 | 318 | |
paul@21 | 319 | def getAttachmentFromURL(url, request): |
paul@21 | 320 | |
paul@21 | 321 | """ |
paul@40 | 322 | Return a (full path, attachment filename) tuple for the attachment |
paul@21 | 323 | referenced by the given 'url', using the 'request' to interpret the |
paul@21 | 324 | structure of 'url'. |
paul@21 | 325 | |
paul@21 | 326 | If 'url' does not refer to an attachment on this wiki, None is returned. |
paul@21 | 327 | """ |
paul@21 | 328 | |
paul@40 | 329 | # Detect static resources. |
paul@40 | 330 | |
paul@40 | 331 | htdocs_dir = get_htdocs(request) |
paul@40 | 332 | |
paul@40 | 333 | if htdocs_dir: |
paul@40 | 334 | prefix = request.cfg.url_prefix_static |
paul@40 | 335 | |
paul@40 | 336 | # Normalise the |
paul@40 | 337 | |
paul@40 | 338 | if not prefix.endswith("/"): |
paul@40 | 339 | prefix += "/" |
paul@40 | 340 | |
paul@40 | 341 | if url.startswith(prefix): |
paul@40 | 342 | filename = url[len(prefix):] |
paul@40 | 343 | |
paul@40 | 344 | # Obtain the resource path. |
paul@40 | 345 | |
paul@40 | 346 | path = abspath(join(htdocs_dir, filename)) |
paul@40 | 347 | |
paul@40 | 348 | if exists(path): |
paul@40 | 349 | return path, taintfilename(filename) |
paul@40 | 350 | |
paul@40 | 351 | # Detect attachments and other resources. |
paul@40 | 352 | |
paul@21 | 353 | script = request.getScriptname() |
paul@39 | 354 | |
paul@39 | 355 | # Normalise the URL. |
paul@39 | 356 | |
paul@39 | 357 | if not script.endswith("/"): |
paul@39 | 358 | script += "/" |
paul@39 | 359 | |
paul@39 | 360 | # Reject URLs outside the wiki. |
paul@39 | 361 | |
paul@21 | 362 | if not url.startswith(script): |
paul@21 | 363 | return None |
paul@21 | 364 | |
paul@21 | 365 | path = url[len(script):].lstrip("/") |
paul@21 | 366 | try: |
paul@21 | 367 | qpagename, qs = path.split("?", 1) |
paul@21 | 368 | except ValueError: |
paul@21 | 369 | qpagename = path |
paul@21 | 370 | qs = None |
paul@21 | 371 | |
paul@21 | 372 | pagename = unquoteWikinameURL(qpagename) |
paul@21 | 373 | qs = qs and parseQueryString(qs) or {} |
paul@40 | 374 | |
paul@40 | 375 | filename = qs.get("target") or qs.get("drawing") |
paul@40 | 376 | filename = taintfilename(filename) |
paul@40 | 377 | |
paul@40 | 378 | # Obtain the attachment path. |
paul@40 | 379 | |
paul@40 | 380 | path = AttachFile.getFilename(request, pagename, filename) |
paul@40 | 381 | return path, filename |
paul@21 | 382 | |
paul@21 | 383 | class OutgoingHTMLFormatter(text_html.Formatter): |
paul@21 | 384 | |
paul@21 | 385 | """ |
paul@21 | 386 | Handle outgoing HTML content by identifying attachments and rewriting their |
paul@21 | 387 | locations. References to bundled attachments are done using RFC 2111: |
paul@21 | 388 | |
paul@21 | 389 | https://tools.ietf.org/html/rfc2111 |
paul@21 | 390 | |
paul@21 | 391 | Messages employing references between parts are meant to comply with RFC |
paul@21 | 392 | 2387: |
paul@21 | 393 | |
paul@21 | 394 | https://tools.ietf.org/html/rfc2387 |
paul@21 | 395 | """ |
paul@21 | 396 | |
paul@21 | 397 | def __init__(self, request, **kw): |
paul@21 | 398 | text_html.Formatter.__init__(self, request, **kw) |
paul@21 | 399 | self.attachments = [] |
paul@21 | 400 | |
paul@21 | 401 | def add_attachment(self, location): |
paul@21 | 402 | details = getAttachmentFromURL(location, self.request) |
paul@21 | 403 | if details: |
paul@21 | 404 | pos = len(self.attachments) |
paul@21 | 405 | self.attachments.append(details) |
paul@21 | 406 | return "cid:attachment%d" % pos |
paul@21 | 407 | else: |
paul@21 | 408 | return None |
paul@21 | 409 | |
paul@21 | 410 | def image(self, src=None, **kw): |
paul@21 | 411 | src = src or kw.get("src") |
paul@21 | 412 | ref = src and self.add_attachment(src) |
paul@21 | 413 | return text_html.Formatter.image(self, ref or src, **kw) |
paul@21 | 414 | |
paul@21 | 415 | def transclusion(self, on, **kw): |
paul@21 | 416 | if on: |
paul@21 | 417 | data = kw.get("data") |
paul@21 | 418 | kw["data"] = data and self.add_attachment(data) |
paul@21 | 419 | return text_html.Formatter.transclusion(self, on, **kw) |
paul@12 | 420 | |
paul@12 | 421 | # Action function. |
paul@12 | 422 | |
paul@12 | 423 | def execute(pagename, request): |
paul@12 | 424 | SendMessage(pagename, request).render() |
paul@12 | 425 | |
paul@12 | 426 | # vim: tabstop=4 expandtab shiftwidth=4 |