/* * Juick * Copyright (C) 2008-2013, Ugnich Anton * * This program is free software: you can redistribute it and/or modify * it under the terms of the GNU Affero General Public License as * published by the Free Software Foundation, either version 3 of the * License, or (at your option) any later version. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU Affero General Public License for more details. * * You should have received a copy of the GNU Affero General Public License * along with this program. If not, see . */ package com.juick.http.www; import com.juick.server.UserQueries; import java.io.IOException; import java.io.PrintWriter; import java.sql.Connection; import java.sql.PreparedStatement; import java.sql.ResultSet; import java.sql.SQLException; import javax.servlet.ServletException; import javax.servlet.http.Cookie; import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpServletResponse; /** * * @author Ugnich Anton */ public class SignUp { protected void doGet(Connection sql, HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException { com.juick.User visitor = Utils.getVisitorUser(sql, request, response); String type = request.getParameter("type"); String hash = request.getParameter("hash"); if (type == null || type.isEmpty() || hash == null || hash.isEmpty() || hash.length() > 36 || !type.matches("^[a-zA-Z0-9\\-]+$") || !hash.matches("^[a-zA-Z0-9\\-]+$")) { response.sendError(HttpServletResponse.SC_BAD_REQUEST); return; } String account = null; if (type.equals("fb")) { account = getFacebookNameByHash(sql, hash); } else if (type.equals("vk")) { account = getVKNameByHash(sql, hash); } else if (type.equals("xmpp")) { account = getJIDByHash(sql, hash); } if (account == null) { response.sendError(HttpServletResponse.SC_BAD_REQUEST); return; } response.setContentType("text/html; charset=UTF-8"); PrintWriter out = response.getWriter(); try { PageTemplates.pageHead(out, "Новый пользователь", ""); PageTemplates.pageNavigation(out, visitor, null); out.println("
"); out.print("

"); if (type.charAt(0) == 'f') { out.print("\"Facebook\"/"); } else if (type.charAt(0) == 'v') { out.print("\"VKontakte\"/"); } else if (type.charAt(0) == 'x') { out.print("\"XMPP\"/"); } out.println(account + "

"); out.println("

Связать с существующим аккаунтом Juick

"); out.println("
"); out.println(""); out.println(""); out.println(""); if (visitor != null) { out.println(""); } else { out.println("

Имя пользователя:

"); out.println("

Пароль:

"); out.println("

"); } out.println("
"); out.println("
"); out.println("

Создать новый аккаунт Juick

"); out.println("
"); out.println(""); out.println(""); out.println(""); out.println("

Имя пользователя:
(От 2-х до 16-и латинских символов и/или цифр, дефис)

"); out.println("

Пароль:
(от 6-и до 32-х символов)

"); out.println("

"); out.println("
"); out.println("
"); PageTemplates.pageFooter(request, out, visitor, false); PageTemplates.pageEnd(out); } finally { out.close(); } } protected void doPost(Connection sql, HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException { com.juick.User visitor = Utils.getVisitorUser(sql, request, response); int uid = 0; String type = request.getParameter("type"); String hash = request.getParameter("hash"); if (type == null || type.isEmpty() || hash == null || hash.isEmpty() || hash.length() > 36 || !type.matches("^[a-zA-Z0-9\\-]+$") || !hash.matches("^[a-zA-Z0-9\\-]+$")) { response.sendError(HttpServletResponse.SC_BAD_REQUEST); return; } String action = request.getParameter("action"); if (action.charAt(0) == 'l') { if (visitor == null) { String username = request.getParameter("username"); String password = request.getParameter("password"); if (username == null || password == null || username.length() > 32 || password.isEmpty()) { response.sendError(HttpServletResponse.SC_BAD_REQUEST); return; } uid = com.juick.server.UserQueries.checkPassword(sql, username, password); } else { uid = visitor.UID; } if (uid <= 0) { response.sendError(HttpServletResponse.SC_FORBIDDEN); return; } if (!(type.charAt(0) == 'f' && setFacebookUser(sql, hash, uid)) && !(type.charAt(0) == 'v' && setVKUser(sql, hash, uid)) && !(type.charAt(0) == 'x' && setJIDUser(sql, hash, uid))) { response.sendError(HttpServletResponse.SC_INTERNAL_SERVER_ERROR); return; } } else { // Create new account String username = request.getParameter("username"); String password = request.getParameter("password"); if (username == null || password == null || username.length() < 2 || username.length() > 16 || !username.matches("^[a-zA-Z0-9\\-]+$") || password.length() < 6 || password.length() > 32) { response.sendError(HttpServletResponse.SC_BAD_REQUEST); return; } // CHECK USERNAME uid = UserQueries.createUser(sql, username, password); if (uid <= 0) { response.sendError(HttpServletResponse.SC_INTERNAL_SERVER_ERROR); return; } if (!(type.charAt(0) == 'f' && setFacebookUser(sql, hash, uid)) && !(type.charAt(0) == 'v' && setVKUser(sql, hash, uid)) && !(type.charAt(0) == 'x' && setJIDUser(sql, hash, uid))) { response.sendError(HttpServletResponse.SC_INTERNAL_SERVER_ERROR); return; } int ref = 0; String sRef = Utils.getCookie(request, "ref"); if (sRef != null) { try { ref = Integer.parseInt(sRef); } catch (Exception e) { } } if (ref > 0) { setUserRef(sql, uid, ref); } visitor = null; } if (visitor == null) { hash = com.juick.server.UserQueries.getHashByUID(sql, uid); Cookie c = new Cookie("hash", hash); c.setMaxAge(365 * 24 * 60 * 60); response.addCookie(c); } response.sendRedirect("/"); } private boolean setUserRef(Connection sql, int uid, int ref) { boolean ret = false; PreparedStatement stmt = null; try { stmt = sql.prepareStatement("INSERT INTO users_refs(user_id,ref) VALUES (?,?)"); stmt.setInt(1, uid); stmt.setInt(2, ref); stmt.executeUpdate(); ret = true; } catch (SQLException e) { System.err.println(e); } finally { Utils.finishSQL(null, stmt); } return ret; } private String getFacebookNameByHash(Connection sql, String hash) { String ret = null; PreparedStatement stmt = null; ResultSet rs = null; try { stmt = sql.prepareStatement("SELECT fb_name,fb_link FROM facebook WHERE loginhash=?"); stmt.setString(1, hash); rs = stmt.executeQuery(); if (rs.first()) { ret = "" + rs.getString(1) + ""; } } catch (SQLException e) { System.err.println(e); } finally { Utils.finishSQL(rs, stmt); } return ret; } private boolean setFacebookUser(Connection sql, String hash, int uid) { boolean ret = false; PreparedStatement stmt = null; try { stmt = sql.prepareStatement("UPDATE facebook SET user_id=?,loginhash=NULL WHERE loginhash=?"); stmt.setInt(1, uid); stmt.setString(2, hash); stmt.executeUpdate(); ret = true; } catch (SQLException e) { System.err.println(e); } finally { Utils.finishSQL(null, stmt); } return ret; } private String getVKNameByHash(Connection sql, String hash) { String ret = null; PreparedStatement stmt = null; ResultSet rs = null; try { stmt = sql.prepareStatement("SELECT vk_name,vk_link FROM vk WHERE loginhash=?"); stmt.setString(1, hash); rs = stmt.executeQuery(); if (rs.first()) { ret = "" + rs.getString(1) + ""; } } catch (SQLException e) { System.err.println(e); } finally { Utils.finishSQL(rs, stmt); } return ret; } private boolean setVKUser(Connection sql, String hash, int uid) { boolean ret = false; PreparedStatement stmt = null; try { stmt = sql.prepareStatement("UPDATE vk SET user_id=?,loginhash=NULL WHERE loginhash=?"); stmt.setInt(1, uid); stmt.setString(2, hash); stmt.executeUpdate(); ret = true; } catch (SQLException e) { System.err.println(e); } finally { Utils.finishSQL(null, stmt); } return ret; } private String getJIDByHash(Connection sql, String hash) { String ret = null; PreparedStatement stmt = null; ResultSet rs = null; try { stmt = sql.prepareStatement("SELECT jid FROM jids WHERE loginhash=?"); stmt.setString(1, hash); rs = stmt.executeQuery(); if (rs.first()) { ret = rs.getString(1); } } catch (SQLException e) { System.err.println(e); } finally { Utils.finishSQL(rs, stmt); } return ret; } private boolean setJIDUser(Connection sql, String hash, int uid) { boolean ret = false; PreparedStatement stmt = null; try { stmt = sql.prepareStatement("UPDATE jids SET user_id=?,loginhash=NULL WHERE loginhash=?"); stmt.setInt(1, uid); stmt.setString(2, hash); stmt.executeUpdate(); ret = true; } catch (SQLException e) { System.err.println(e); } finally { Utils.finishSQL(null, stmt); } return ret; } }