| OLD | NEW | 
|---|
| 1 # This file is part of the Adblock Plus web scripts, | 1 # This file is part of the Adblock Plus web scripts, | 
| 2 # Copyright (C) 2006-present eyeo GmbH | 2 # Copyright (C) 2006-present eyeo GmbH | 
| 3 # | 3 # | 
| 4 # Adblock Plus is free software: you can redistribute it and/or modify | 4 # Adblock Plus is free software: you can redistribute it and/or modify | 
| 5 # it under the terms of the GNU General Public License version 3 as | 5 # it under the terms of the GNU General Public License version 3 as | 
| 6 # published by the Free Software Foundation. | 6 # published by the Free Software Foundation. | 
| 7 # | 7 # | 
| 8 # Adblock Plus is distributed in the hope that it will be useful, | 8 # Adblock Plus is distributed in the hope that it will be useful, | 
| 9 # but WITHOUT ANY WARRANTY; without even the implied warranty of | 9 # but WITHOUT ANY WARRANTY; without even the implied warranty of | 
| 10 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the | 10 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the | 
| 11 # GNU General Public License for more details. | 11 # GNU General Public License for more details. | 
| 12 # | 12 # | 
| 13 # You should have received a copy of the GNU General Public License | 13 # You should have received a copy of the GNU General Public License | 
| 14 # along with Adblock Plus.  If not, see <http://www.gnu.org/licenses/>. | 14 # along with Adblock Plus.  If not, see <http://www.gnu.org/licenses/>. | 
| 15 | 15 | 
| 16 import re | 16 import re | 
| 17 import os |  | 
| 18 import sys |  | 
| 19 import random | 17 import random | 
| 20 from urlparse import parse_qsl | 18 from urlparse import parse_qsl | 
| 21 from sitescripts.utils import get_config, get_template, setupStderr | 19 from sitescripts.utils import get_config, get_template, setupStderr | 
| 22 from sitescripts.web import url_handler | 20 from sitescripts.web import url_handler | 
| 23 from sitescripts.reports.utils import calculateReportSecret, calculateReportSecr
    et_compat, getReport, saveReport, sendUpdateNotification, getUserId, updateUserU
    sefulness | 21 from sitescripts.reports.utils import (calculateReportSecret, | 
|  | 22                                        calculateReportSecret_compat, getReport, | 
|  | 23                                        saveReport, sendUpdateNotification, | 
|  | 24                                        getUserId, updateUserUsefulness) | 
| 24 | 25 | 
| 25 | 26 | 
| 26 @url_handler('/updateReport') | 27 @url_handler('/updateReport') | 
| 27 def handleRequest(environ, start_response): | 28 def handleRequest(environ, start_response): | 
|  | 29 | 
| 28     setupStderr(environ['wsgi.errors']) | 30     setupStderr(environ['wsgi.errors']) | 
| 29 | 31 | 
| 30     if environ['REQUEST_METHOD'].upper() != 'POST' or not environ.get('CONTENT_T
    YPE', '').startswith('application/x-www-form-urlencoded'): | 32     if environ['REQUEST_METHOD'].upper() != 'POST' or not environ.get('CONTENT_T
    YPE', '').startswith('application/x-www-form-urlencoded'): | 
| 31         return showError('Unsupported request method', start_response) | 33         return showError('Unsupported request method', start_response) | 
| 32 | 34 | 
| 33     try: | 35     try: | 
| 34         request_body_length = int(environ['CONTENT_LENGTH']) | 36         request_body_length = int(environ['CONTENT_LENGTH']) | 
| 35     except: | 37     except: | 
| 36         return showError('Invalid or missing Content-Length header', start_respo
    nse) | 38         return showError('Invalid or missing Content-Length header', start_respo
    nse) | 
| 37 | 39 | 
| 38     request_body = environ['wsgi.input'].read(request_body_length) | 40     request_body = environ['wsgi.input'].read(request_body_length) | 
| 39     params = {} | 41     params = {} | 
| 40     for key, value in parse_qsl(request_body): | 42     for key, value in parse_qsl(request_body): | 
| 41         params[key] = value.decode('utf-8') | 43         params[key] = value.decode('utf-8') | 
| 42 | 44 | 
| 43     guid = params.get('guid', '').lower() | 45     guid = params.get('guid', '').lower() | 
| 44     if not re.match(r'^[\da-f]{8}-[\da-f]{4}-[\da-f]{4}-[\da-f]{4}-[\da-f]{12}$'
    , guid): | 46     if not re.match(r'^[\da-f]{8}-[\da-f]{4}-[\da-f]{4}-[\da-f]{4}-[\da-f]{12}$'
    , guid): | 
| 45         return showError('Invalid or missing report GUID', start_response) | 47         return showError('Invalid or missing report GUID', start_response) | 
| 46 | 48 | 
| 47     reportData = getReport(guid) | 49     reportData = getReport(guid)  # WSGIAppError: OperationalError(2003, "Can't 
    connect to MySQL server on 'localhost' ([Errno 111] Connection refused)") | 
| 48 | 50 | 
| 49     if reportData == None: | 51     if reportData == None: | 
| 50         return showError('Report does not exist', start_response) | 52         return showError('Report does not exist', start_response) | 
| 51 | 53 | 
| 52     secret = calculateReportSecret(guid) | 54     secret = calculateReportSecret(guid) | 
| 53     if params.get('secret', '') != secret and params.get('secret', '') != calcul
    ateReportSecret_compat(guid): | 55     if params.get('secret', '') != secret and params.get('secret', '') != calcul
    ateReportSecret_compat(guid): | 
| 54         return showError('Wrong secret value', start_response) | 56         return showError('Wrong secret value', start_response) | 
| 55 | 57 | 
| 56     reportData['status'] = params.get('status', '') | 58     reportData['status'] = params.get('status', '') | 
| 57     if len(reportData['status']) > 1024: | 59     if len(reportData['status']) > 1024: | 
| 58         reportData['status'] = reportData['status'][:1024] | 60         reportData['status'] = reportData['status'][:1024] | 
| 59 | 61 | 
| 60     oldusefulness = reportData.get('usefulness', '0') | 62     oldusefulness = reportData.get('usefulness', '0') | 
| 61     reportData['usefulness'] = params.get('usefulness', '0') | 63     reportData['usefulness'] = params.get('usefulness', '0') | 
| 62     if 'email' in reportData: | 64     if 'email' in reportData: | 
| 63         updateUserUsefulness(getUserId(reportData['email']), reportData['usefuln
    ess'], oldusefulness) | 65         updateUserUsefulness(getUserId(reportData['email']), reportData['usefuln
    ess'], oldusefulness) | 
| 64 | 66 | 
| 65     saveReport(guid, reportData) | 67     saveReport(guid, reportData)  # WSGIAppError: OperationalError(2003, "Can't 
    connect to MySQL server on 'localhost' ([Errno 111] Connection refused)") | 
| 66 | 68 | 
| 67     if params.get('notify', '') and 'email' in reportData: | 69     if params.get('notify', '') and 'email' in reportData: | 
| 68         email = reportData['email'] | 70         email = reportData['email'] | 
| 69         email = re.sub(r' at ', r'@', email) | 71         email = re.sub(r' at ', r'@', email) | 
| 70         email = re.sub(r' dot ', r'.', email) | 72         email = re.sub(r' dot ', r'.', email) | 
| 71         if re.match(r'^[\w.%+-]+@[\w.%+-]+(\.[\w.%+-]+)+', email): | 73         if re.match(r'^[\w.%+-]+@[\w.%+-]+(\.[\w.%+-]+)+', email): | 
| 72             sendUpdateNotification({ | 74             sendUpdateNotification({ | 
| 73                 'email': email, | 75                 'email': email, | 
| 74                 'url': get_config().get('reports', 'urlRoot') + guid, | 76                 'url': get_config().get('reports', 'urlRoot') + guid, | 
| 75                 'status': reportData['status'], | 77                 'status': reportData['status'], | 
| 76             }) | 78             }) | 
| 77 | 79 | 
| 78     newURL = get_config().get('reports', 'urlRoot') + guid | 80     newURL = get_config().get('reports', 'urlRoot') + guid | 
| 79     newURL += '?updated=' + str(int(random.uniform(0, 10000))) | 81     newURL += '?updated=' + str(int(random.uniform(0, 10000))) | 
| 80     newURL += '#secret=' + secret | 82     newURL += '#secret=' + secret | 
| 81     start_response('302 Found', [('Location', newURL.encode('utf-8'))]) | 83     start_response('302 Found', [('Location', newURL.encode('utf-8'))]) | 
| 82     return [] | 84     return [] | 
| 83 | 85 | 
| 84 | 86 | 
| 85 def showError(message, start_response): | 87 def showError(message, start_response): | 
| 86     template = get_template(get_config().get('reports', 'errorTemplate')) | 88     template = get_template(get_config().get('reports', 'errorTemplate')) | 
| 87     start_response('400 Processing Error', [('Content-Type', 'application/xhtml+
    xml; charset=utf-8')]) | 89     start_response('400 Processing Error', [('Content-Type', 'application/xhtml+
    xml; charset=utf-8')]) | 
| 88     return [template.render({'message': message}).encode('utf-8')] | 90     return [template.render({'message': message}).encode('utf-8')] | 
| OLD | NEW | 
|---|