aboutsummaryrefslogtreecommitdiff
path: root/src/java/com/juick/http/www/Settings.java
blob: 7ae0259df5c5356fa491e546069e8313bd4d3b7b (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
/*
 * Juick
 * Copyright (C) 2008-2013, Ugnich Anton
 *
 * This program is free software: you can redistribute it and/or modify
 * it under the terms of the GNU Affero General Public License as
 * published by the Free Software Foundation, either version 3 of the
 * License, or (at your option) any later version.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU Affero General Public License for more details.
 *
 * You should have received a copy of the GNU Affero General Public License
 * along with this program.  If not, see <http://www.gnu.org/licenses/>.
 */
package com.juick.http.www;

import java.io.IOException;
import java.io.PrintWriter;
import java.sql.Connection;
import java.sql.PreparedStatement;
import java.sql.SQLException;
import java.util.Locale;
import java.util.ResourceBundle;
import javax.servlet.ServletException;
import javax.servlet.http.Cookie;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

/**
 *
 * @author Ugnich Anton
 */
public class Settings {

    protected void doGet(Connection sql, HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
        com.juick.User visitor = Utils.getVisitorUser(sql, request);
        Locale locale = request.getLocale();
        ResourceBundle rb = ResourceBundle.getBundle("Login", locale);

        response.setContentType("text/html; charset=UTF-8");
        PrintWriter out = response.getWriter();
        try {
            PageTemplates.pageHead(out, rb.getString("Login"), "");
            PageTemplates.pageNavigation(out, locale, visitor, null);

            out.println("<div id=\"topwrapper\">");
            out.println("<div id=\"wrapper\">");
            out.println("<div id=\"content\">");
            out.println("<form action=\"/login\" method=\"post\">");
            out.println("<p>" + rb.getString("Username") + ": <input type=\"text\" name=\"username\"/></p>");
            out.println("<p>" + rb.getString("Password") + ": <input type=\"password\" name=\"password\"/></p>");
            out.println("<p><input type=\"submit\" value=\"    OK    \"/></p>");
            out.println("</form>");
            out.println("</div>");
            out.println("</div>");
            out.println("</div>"); // topwrapper

            PageTemplates.pageFooter(request, out, locale, visitor, false);
            PageTemplates.pageEnd(out);
        } finally {
            out.close();
        }
    }

    protected void doPost(Connection sql, HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
        String username = request.getParameter("username");
        String password = request.getParameter("password");
        if (username == null || password == null || username.length() > 32 || password.isEmpty()) {
            response.sendError(400);
            return;
        }

        int uid = com.juick.server.UserQueries.checkPassword(sql, username, password);
        if (uid > 0) {
            String hash = com.juick.server.UserQueries.getHashByUID(sql, uid);
            Cookie c = new Cookie("hash", hash);
            c.setDomain(".juick.com");
            c.setMaxAge(365 * 24 * 60 * 60);
            response.addCookie(c);


            if (uid > 0) {
                PreparedStatement stmt = null;
                try {
                    stmt = sql.prepareStatement("DELETE FROM logins WHERE user_id=?");
                    stmt.setInt(1, uid);
                    stmt.executeUpdate();
                } catch (SQLException e) {
                    System.err.println(e);
                } finally {
                    Utils.finishSQL(null, stmt);
                }
            }

            String referer = request.getHeader("Referer");
            if (referer != null && referer.startsWith("http://juick.com/") && !referer.equals("http://juick.com/login")) {
                response.sendRedirect(referer);
            } else {
                response.sendRedirect("/");
            }
        } else {
            response.sendError(403);
        }
    }
}