* Repaired all my b0rken COLOR tags
[citadel.git] / webcit / useredit.c
1 /*
2  * Administrative screen to add/change/delete user accounts
3  *
4  */
5
6
7 #include <ctype.h>
8 #include <stdlib.h>
9 #include <unistd.h>
10 #include <stdio.h>
11 #include <fcntl.h>
12 #include <signal.h>
13 #include <sys/types.h>
14 #include <sys/wait.h>
15 #include <sys/socket.h>
16 #include <sys/time.h>
17 #include <limits.h>
18 #include <netinet/in.h>
19 #include <netdb.h>
20 #include <string.h>
21 #include <pwd.h>
22 #include <errno.h>
23 #include <stdarg.h>
24 #include <pthread.h>
25 #include <signal.h>
26 #include "webcit.h"
27 #include "webserver.h"
28
29
30
31
32
33 void select_user_to_edit(char *message, char *preselect)
34 {
35         char buf[SIZ];
36         char username[SIZ];
37
38         output_headers(3);      /* No room banner on this screen */
39
40         if (message != NULL) wprintf(message);
41
42         wprintf("<TABLE WIDTH=100%% BORDER=0 BGCOLOR=\"#007700\"><TR><TD>");
43         wprintf("<SPAN CLASS=\"titlebar\">"
44                 "Add/change/delete user accounts"
45                 "</SPAN></TD></TR></TABLE>\n");
46
47         wprintf("<TABLE border=0 CELLSPACING=10><TR VALIGN=TOP>"
48                 "<TD>To edit an existing user account, select the user "
49                 "name from the list and click 'Edit'.<BR><BR>");
50         
51         wprintf("<CENTER><FORM METHOD=\"POST\" ACTION=\"/display_edituser\">\n");
52         wprintf("<SELECT NAME=\"username\" SIZE=10>\n");
53         serv_puts("LIST");
54         serv_gets(buf);
55         if (buf[0] == '1') {
56                 while (serv_gets(buf), strcmp(buf, "000")) {
57                         extract(username, buf, 0);
58                         wprintf("<OPTION");
59                         if (preselect != NULL)
60                            if (!strcasecmp(username, preselect))
61                               wprintf(" SELECTED");
62                         wprintf(">");
63                         escputs(username);
64                         wprintf("\n");
65                 }
66         }
67         wprintf("</SELECT><BR>\n");
68
69         wprintf("<input type=submit name=sc value=\"Edit configuration\">");
70         wprintf("<input type=submit name=sc value=\"Edit address book entry\">");
71         wprintf("</FORM></CENTER>\n");
72
73         wprintf("</TD><TD>"
74                 "To create a new user account, enter the desired "
75                 "user name in the box below and click 'Create'.<BR><BR>");
76
77         wprintf("<CENTER><FORM METHOD=\"POST\" ACTION=\"/create_user\">\n");
78         wprintf("New user: ");
79         wprintf("<input type=text name=username><BR>\n"
80                 "<input type=submit value=\"Create\">"
81                 "</FORM></CENTER>\n");
82
83         wprintf("</TD></TR></TABLE>\n");
84
85         wDumpContent(1);
86 }
87
88
89
90 /* 
91  * Locate the message number of a user's vCard in the current room
92  */
93 long locate_user_vcard(char *username, long usernum) {
94         char buf[SIZ];
95         long vcard_msgnum = (-1L);
96         char content_type[SIZ];
97         char partnum[SIZ];
98         int already_tried_creating_one = 0;
99
100         struct stuff_t {
101                 struct stuff_t *next;
102                 long msgnum;
103         };
104
105         struct stuff_t *stuff = NULL;
106         struct stuff_t *ptr;
107
108 TRYAGAIN:
109         /* Search for the user's vCard */
110         serv_puts("MSGS ALL");
111         serv_gets(buf);
112         if (buf[0] == '1') while (serv_gets(buf), strcmp(buf, "000")) {
113                 ptr = malloc(sizeof(struct stuff_t));
114                 ptr->msgnum = atol(buf);
115                 ptr->next = stuff;
116                 stuff = ptr;
117         }
118
119         /* Iterate through the message list looking for vCards */
120         while (stuff != NULL) {
121                 serv_printf("MSG0 %ld|2", stuff->msgnum);
122                 serv_gets(buf);
123                 if (buf[0]=='1') {
124                         while(serv_gets(buf), strcmp(buf, "000")) {
125                                 if (!strncasecmp(buf, "part=", 5)) {
126                                         extract(partnum, &buf[5], 2);
127                                         extract(content_type, &buf[5], 4);
128                                         if (!strcasecmp(content_type,
129                                            "text/x-vcard")) {
130                                                 vcard_msgnum = stuff->msgnum;
131                                         }
132                                 }
133                         }
134                 }
135
136                 ptr = stuff->next;
137                 free(stuff);
138                 stuff = ptr;
139         }
140
141         /* If there's no vcard, create one */
142         if (vcard_msgnum < 0) if (already_tried_creating_one == 0) {
143                 already_tried_creating_one = 1;
144                 serv_puts("ENT0 1|||4");
145                 serv_gets(buf);
146                 if (buf[0] == '4') {
147                         serv_puts("Content-type: text/x-vcard");
148                         serv_puts("");
149                         serv_puts("begin:vcard");
150                         serv_puts("end:vcard");
151                         serv_puts("000");
152                 }
153                 goto TRYAGAIN;
154         }
155
156         return(vcard_msgnum);
157 }
158
159
160 /* 
161  * Display the form for editing a user's address book entry
162  */
163 void display_edit_address_book_entry(char *username, long usernum) {
164         char roomname[SIZ];
165         char buf[SIZ];
166         char error_message[SIZ];
167         long vcard_msgnum = (-1L);
168
169         /* Locate the user's config room, creating it if necessary */
170         sprintf(roomname, "%010ld.%s", usernum, USERCONFIGROOM);
171         serv_printf("GOTO %s||1", roomname);
172         serv_gets(buf);
173         if (buf[0] != '2') {
174                 serv_printf("CRE8 1|%s|5|||1|", roomname);
175                 serv_gets(buf);
176                 serv_printf("GOTO %s||1", roomname);
177                 serv_gets(buf);
178                 if (buf[0] != '2') {
179                         sprintf(error_message,
180                                 "<IMG SRC=\"static/error.gif\" ALIGN=CENTER>"
181                                 "%s<BR><BR>\n", &buf[4]);
182                         select_user_to_edit(error_message, username);
183                         return;
184                 }
185         }
186
187         vcard_msgnum = locate_user_vcard(username, usernum);
188
189         if (vcard_msgnum < 0) {
190                 sprintf(error_message,
191                         "<IMG SRC=\"static/error.gif\" ALIGN=CENTER>"
192                         "Could not create/edit vCard"
193                         "<BR><BR>\n"
194                 );
195                 select_user_to_edit(error_message, username);
196                 return;
197         }
198
199         do_edit_vcard(vcard_msgnum, "1", "/select_user_to_edit");
200 }
201
202
203
204
205 /*
206  * Edit a user.  If supplied_username is null, look in the "username"
207  * web variable for the name of the user to edit.
208  */
209 void display_edituser(char *supplied_username) {
210         char buf[SIZ];
211         char error_message[SIZ];
212         time_t now;
213
214         char username[SIZ];
215         char password[SIZ];
216         unsigned int flags;
217         int timescalled;
218         int msgsposted;
219         int axlevel;
220         long usernum;
221         time_t lastcall;
222         int purgedays;
223         int i;
224
225         if (supplied_username != NULL) {
226                 strcpy(username, supplied_username);
227         }
228         else {
229                 strcpy(username, bstr("username") );
230         }
231
232         serv_printf("AGUP %s", username);
233         serv_gets(buf);
234         if (buf[0] != '2') {
235                 sprintf(error_message,
236                         "<IMG SRC=\"static/error.gif\" ALIGN=CENTER>"
237                         "%s<BR><BR>\n", &buf[4]);
238                 select_user_to_edit(error_message, username);
239                 return;
240         }
241
242         extract(username, &buf[4], 0);
243         extract(password, &buf[4], 1);
244         flags = extract_int(&buf[4], 2);
245         timescalled = extract_int(&buf[4], 3);
246         msgsposted = extract_int(&buf[4], 4);
247         axlevel = extract_int(&buf[4], 5);
248         usernum = extract_long(&buf[4], 6);
249         lastcall = extract_long(&buf[4], 7);
250         purgedays = extract_long(&buf[4], 8);
251
252         if (!strcmp(bstr("sc"), "Edit address book entry")) {
253                 display_edit_address_book_entry(username, usernum);
254                 return;
255         }
256
257         output_headers(3);      /* No room banner on this screen */
258         wprintf("<TABLE WIDTH=100%% BORDER=0 BGCOLOR=\"#007700\"><TR><TD>");
259         wprintf("<SPAN CLASS=\"titlebar\">"
260                 "Edit user account: ");
261         escputs(username);
262         wprintf("</SPAN></TD></TR></TABLE>\n");
263
264         wprintf("<FORM METHOD=\"POST\" ACTION=\"/edituser\">\n"
265                 "<INPUT TYPE=\"hidden\" NAME=\"username\" VALUE=\"");
266         escputs(username);
267         wprintf("\">\n");
268
269         wprintf("<INPUT TYPE=\"hidden\" NAME=\"flags\" VALUE=\"%d\">\n", flags);
270
271         wprintf("<CENTER><TABLE>");
272
273         wprintf("<TR><TD>Password</TD><TD>"
274                 "<INPUT TYPE=\"password\" NAME=\"password\" VALUE=\"");
275         escputs(password);
276         wprintf("\" MAXLENGTH=\"20\"></TD></TR>\n");
277
278         wprintf("<TR><TD>Times logged in</TD><TD>"
279                 "<INPUT TYPE=\"text\" NAME=\"timescalled\" VALUE=\"");
280         wprintf("%d", timescalled);
281         wprintf("\" MAXLENGTH=\"6\"></TD></TR>\n");
282
283         wprintf("<TR><TD>Messages posted</TD><TD>"
284                 "<INPUT TYPE=\"text\" NAME=\"msgsposted\" VALUE=\"");
285         wprintf("%d", msgsposted);
286         wprintf("\" MAXLENGTH=\"6\"></TD></TR>\n");
287
288         wprintf("<TR><TD>Access level</TD><TD>"
289                 "<SELECT NAME=\"axlevel\">\n");
290         for (i=0; i<7; ++i) {
291                 wprintf("<OPTION ");
292                 if (axlevel == i) {
293                         wprintf("SELECTED ");
294                 }
295                 wprintf("VALUE=\"%d\">%d - %s</OPTION>\n",
296                         i, i, axdefs[i]);
297         }
298         wprintf("</SELECT></TD></TR>\n");
299
300         wprintf("<TR><TD>User ID number</TD><TD>"
301                 "<INPUT TYPE=\"text\" NAME=\"usernum\" VALUE=\"");
302         wprintf("%ld", usernum);
303         wprintf("\" MAXLENGTH=\"7\"></TD></TR>\n");
304
305         now = time(NULL);
306         wprintf("<TR><TD>Date/time of last login</TD><TD>"
307                 "<SELECT NAME=\"lastcall\">\n");
308
309         wprintf("<OPTION SELECTED VALUE=\"%ld\">", lastcall);
310         escputs(asctime(localtime(&lastcall)));
311         wprintf("</OPTION>\n");
312
313         wprintf("<OPTION VALUE=\"%ld\">", now);
314         escputs(asctime(localtime(&now)));
315         wprintf("</OPTION>\n");
316
317         wprintf("</SELECT></TD></TR>");
318
319         wprintf("<TR><TD>Auto-purge after days</TD><TD>"
320                 "<INPUT TYPE=\"text\" NAME=\"purgedays\" VALUE=\"");
321         wprintf("%d", purgedays);
322         wprintf("\" MAXLENGTH=\"5\"></TD></TR>\n");
323
324         wprintf("</TABLE>\n");
325
326         wprintf("<INPUT type=\"submit\" NAME=\"action\" VALUE=\"OK\">\n"
327                 "<INPUT type=\"submit\" NAME=\"action\" VALUE=\"Cancel\">\n"
328                 "<BR><BR></FORM>\n");
329
330         wprintf("</CENTER>\n");
331
332         wDumpContent(1);
333
334 }
335
336
337
338 void edituser(void) {
339         char message[SIZ];
340         char buf[SIZ];
341
342         if (strcasecmp(bstr("action"), "OK")) {
343                 strcpy(message, "Edit user cancelled.");
344         }
345
346         else {
347
348                 serv_printf("ASUP %s|%s|%s|%s|%s|%s|%s|%s|%s|",
349                         bstr("username"),
350                         bstr("password"),
351                         bstr("flags"),
352                         bstr("timescalled"),
353                         bstr("msgsposted"),
354                         bstr("axlevel"),
355                         bstr("usernum"),
356                         bstr("lastcall"),
357                         bstr("purgedays")
358                 );
359                 serv_gets(buf);
360                 if (buf[0] != '2') {
361                         sprintf(message,
362                                 "<IMG SRC=\"static/error.gif\" ALIGN=CENTER>"
363                                 "%s<BR><BR>\n", &buf[4]);
364                 }
365                 else {
366                         strcpy(message, "");
367                 }
368         }
369
370         select_user_to_edit(message, bstr("username"));
371 }
372
373
374
375
376 void create_user(void) {
377         char buf[SIZ];
378         char error_message[SIZ];
379         char username[SIZ];
380
381         strcpy(username, bstr("username"));
382
383         serv_printf("CREU %s", username);
384         serv_gets(buf);
385
386         if (buf[0] == '2') {
387                 sprintf(error_message, "<b>User has been created.</b>");
388                 select_user_to_edit(error_message, username);
389         }
390         else {
391                 sprintf(error_message,
392                         "<IMG SRC=\"static/error.gif\" ALIGN=CENTER>"
393                         "%s<BR><BR>\n", &buf[4]);
394                 select_user_to_edit(error_message, NULL);
395         }
396
397 }
398