summaryrefslogtreecommitdiff
path: root/jakob/dynamic/capabilities/comment-form.scm
blob: 958e9dc74520426c57804e940c7455f2c2c08e32 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
;;; Copyright © 2019 - 2023 Jakob L. Kreuze <zerodaysfordays@sdf.org>
;;;
;;; This program is free software; you can redistribute it and/or
;;; modify it under the terms of the GNU General Public License as
;;; published by the Free Software Foundation; either version 3 of the
;;; License, or (at your option) any later version.
;;;
;;; This program is distributed in the hope that it will be useful,
;;; but WITHOUT ANY WARRANTY; without even the implied warranty of
;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
;;; General Public License for more details.
;;;
;;; You should have received a copy of the GNU General Public License
;;; along with this program. If not, see
;;; <http://www.gnu.org/licenses/>.

(define-module (jakob dynamic capabilities comment-form)
  #:use-module (gcrypt base64)
  #:use-module (haunt html)
  #:use-module (ice-9 match)
  #:use-module (jakob builder blog)
  #:use-module (jakob dynamic captcha)
  #:use-module (jakob dynamic util)
  #:use-module (jakob theme)
  #:use-module (jakob utils sxml)
  #:use-module (json)
  #:use-module (srfi srfi-1)
  #:use-module (srfi srfi-11)
  #:use-module (web request)
  #:use-module (web response)
  #:use-module (web uri)
  #:export (render-static-comment-form
            render-dynamic-comment-form
            get-comment-form))

(define (render-comment-field)
  `(fieldset (@ (id "comment-content"))
    (legend "Comment")
    (label (@ (for "name") (class "required")) "Name:")
    (input (@ (type "text") (id "name") (name "name") (required #t)))
    (label (@ (for "email")) "Email:")
    (input (@ (type "text") (id "email") (name "email")))
    (label (@ (for "url")) "Webpage URL:")
    (input (@ (type "text") (id "url") (name "url")))
    (label (@ (for "subject")) "Subject:")
    (input (@ (type "text") (id "subject") (name "subject")))
    (label (@ (for "comment") (class "required")) "Comment :")
    (textarea (@ (id "coment") (name "comment")))
    (p "(*) Indicates a required field.")))

(define* (render-comment-captcha-field #:optional (captcha-id "") captcha-image
                                       #:key hidden)
  `(fieldset ,(if hidden
                  '(@ (id "comment-captcha") (hidden "#t"))
                  '(@ (id "comment-captcha")))
    (legend "Captcha")
    (div (@ (id "captcha-challenge-primary"))
     (label (@ (for "captcha")) "Please evaluate the following definite integral:")
     (img (@ (id "captcha-image")
             (src ,(if captcha-image
                       (format #f "data:image/jpeg;charset=utf-8;base64,~a"
                               (base64-encode captcha-image))
                       ""))))
     (input (@ (type "text") (id "captcha") (name "captcha") (size 24))))
    (button (@ (id "pow-trigger") (hidden #t))
            "Too hard? (Or unable to see the challenge?) Click here.")
    (input (@ (autocomplete "off") (type "text") (id "captcha-id") (name "captcha-id") (hidden #t) (value ,captcha-id)))
    (input (@ (autocomplete "off") (type "text") (id "captcha-alt") (name "captcha-alt") (hidden #t)))
    (input (@ (autocomplete "off") (type "text") (id "captcha-alt-id") (name "captcha-alt-id") (hidden #t)))
    (input (@ (type "submit") (id "submit-form") (value "Submit")))))

(define (render-static-comment-form slug captcha-id captcha-image)
  `(div (@ (id "comment-form"))
     (h1 "Comment form")
     (form (@ (id "comment-input") (action "/api/comment") (method "post"))
       (input (@ (type "text") (name "slug") (hidden #t) (value ,slug)))
       ,(render-comment-field)
       ,(render-comment-captcha-field captcha-id captcha-image))
     ,(script "proof-of-work.js")))

(define (render-dynamic-comment-form slug)
  `(div (@ (id "comment-form"))
     (h3 (@ (id "comment-form-header")) "Comment form")
     (form (@ (id "comment-input") (action "/api/comment") (method "post"))
       (input (@ (autocomplete "off")
                 (type "text")
                 (name "slug")
                 (hidden #t)
                 (value ,slug)))
       (input (@ (autocomplete "off")
                 (type "text")
                 (name "reply-to")
                 (id "reply-to")
                 (hidden #t)
                 (value "")))
       ,(render-comment-field)
       (fieldset (@ (id "captcha-trigger-block"))
        (legend "Captcha")
        (label "You need to complete a captcha to write a comment.")
        (button (@ (id "captcha-challenge-trigger"))
                "Click here to generate a captcha challenge"))
       ,(render-comment-captcha-field #:hidden #t))
     ,(script "dynamic-comment-form.js")
     ,(script "proof-of-work.js")))

(define (get-comment-form request body)
  (let-values (((captcha-id captcha-image) (new-captcha!)))
    (let* ((path-encoded (uri-path (request-uri request)))
           (path (split-and-decode-uri-path path-encoded))
           (slug (last path))
           (form (render-static-comment-form slug captcha-id captcha-image)))
      (values '((content-type . (text/html)))
              (sxml->html-string
               (theme #:content form #:title "Comment prompt"))))))