package web
import (
"bytes"
"encoding/json"
"errors"
"html"
"io"
"mime/multipart"
"net/http"
"net/url"
"strconv"
"strings"
"github.com/google/uuid"
"github.com/gramanas/blogspace/internal/markdown"
"github.com/gramanas/blogspace/internal/store"
)
const filesPerPage = 50
// readUpload stores the file from a multipart field, returning nil if the
// field is empty. imagesOnly is for the design page, whose fields become theme
// image ids.
func (s *Server) readUpload(r *http.Request, field string, imagesOnly bool) (*store.File, error) {
if r.MultipartForm == nil {
return nil, nil
}
fhs := r.MultipartForm.File[field]
if len(fhs) == 0 {
return nil, nil
}
return s.storeUpload(r, fhs[0], imagesOnly)
}
func (s *Server) storeUpload(r *http.Request, fh *multipart.FileHeader, imagesOnly bool) (*store.File, error) {
limit := currentBlog(r).UploadLimit(s.cfg)
tooBig := errors.New(s.trf(r, "File is too large (max %s).", humanSize(limit)))
if fh.Size > limit {
return nil, tooBig
}
f, err := fh.Open()
if err != nil {
return nil, err
}
defer f.Close()
var buf bytes.Buffer
if _, err := io.CopyN(&buf, f, limit+1); err != nil && !errors.Is(err, io.EOF) {
return nil, err
}
if int64(buf.Len()) > limit {
return nil, tooBig
}
if buf.Len() == 0 {
return nil, errors.New(s.tr(r, "File is empty."))
}
name := cleanFilename(fh.Filename)
ct, kind := fileType(buf.Bytes(), name)
if imagesOnly && kind != "image" {
return nil, errors.New(s.tr(r, "Only PNG, JPEG, GIF, WebP and ICO images can be used here."))
}
return blogStore(r).CreateFile(r.Context(), name, ct, kind, buf.Bytes())
}
// fileMarkdown is the line the editor inserts: an image for images, a link
// for everything else.
func fileMarkdown(f *store.File) string {
text := strings.NewReplacer("]", "", "\n", " ").Replace(f.Filename)
open := "["
if f.Kind == "image" {
open = " + ")"
}
// fileHTML is fileMarkdown for content written in HTML mode.
func fileHTML(f *store.File) string {
name := html.EscapeString(f.Filename)
src := "/media/" + f.ID.String()
if f.Kind == "image" {
return `
`
}
return `` + name + ``
}
// appendFile is the no-JavaScript path of "Insert file": the file arrives
// with the form itself and is appended to the end of the text on save, in
// the text's format.
func appendFile(body string, f *store.File, format string) string {
if f == nil {
return body
}
line := fileMarkdown(f)
if format == store.FormatHTML {
line = fileHTML(f)
}
body = strings.TrimRight(body, "\n")
if body != "" {
body += "\n\n"
}
return body + line + "\n"
}
// renderBody is what a save stores for the blog to show: Markdown is rendered
// and sanitised, HTML goes out exactly as the blogger wrote it — the same
// owner's decision as the custom HTML module (see AGENTS.md).
func renderBody(format, src string) string {
if format == store.FormatHTML {
return src
}
return markdown.Render(src)
}
// ---- file library ----------------------------------------------------------
func (s *Server) handleFiles(w http.ResponseWriter, r *http.Request) {
q := r.URL.Query()
kind := q.Get("kind")
if _, ok := fileKindNames[kind]; !ok {
kind = ""
}
search := strings.TrimSpace(q.Get("q"))
if rs := []rune(search); len(rs) > 100 {
search = string(rs[:100])
}
n, _ := strconv.Atoi(q.Get("p"))
d, err := s.filesData(r, kind, search, n)
if err != nil {
s.serverError(w, err)
return
}
s.render(w, r, "dashboard/files.html", d)
}
// filesData is what files.html shows: the page of files matching the filter,
// the pager links and the library's usage.
func (s *Server) filesData(r *http.Request, kind, search string, n int) (map[string]any, error) {
bs := blogStore(r)
count, bytes, err := bs.FileUsage(r.Context())
if err != nil {
return nil, err
}
offset, page, _ := pageBounds(1<<30, filesPerPage, n)
files, total, err := bs.ListFiles(r.Context(), kind, search, filesPerPage, offset)
if err != nil {
return nil, err
}
// A page past the end (stale link, last file deleted) shows the last page instead.
if o, p, _ := pageBounds(total, filesPerPage, n); p != page {
offset, page = o, p
if files, _, err = bs.ListFiles(r.Context(), kind, search, filesPerPage, offset); err != nil {
return nil, err
}
}
_, _, last := pageBounds(total, filesPerPage, page)
link := func(p int) string {
v := url.Values{}
if kind != "" {
v.Set("kind", kind)
}
if search != "" {
v.Set("q", search)
}
if p > 1 {
v.Set("p", strconv.Itoa(p))
}
if len(v) == 0 {
return "/b/" + currentBlog(r).Subdomain + "/files"
}
return "/b/" + currentBlog(r).Subdomain + "/files?" + v.Encode()
}
return map[string]any{
"files": files, "kind": kind, "q": search, "kinds": fileKinds, "kindNames": fileKindNames,
"pageNum": page, "lastPage": last, "prevURL": link(page - 1), "nextURL": link(page + 1), "self": link(page),
"count": count, "bytes": bytes, "limit": humanSize(currentBlog(r).UploadLimit(s.cfg)),
}, nil
}
// handleFileUpload serves the Files page form (several files at once) and,
// when the client asks for JSON, the upload scripts (one file per request).
func (s *Server) handleFileUpload(w http.ResponseWriter, r *http.Request) {
blog := currentBlog(r)
var fhs []*multipart.FileHeader
if r.MultipartForm != nil {
fhs = r.MultipartForm.File["file"] // browsers repeat the field for
}
var msg string
var files []*store.File
switch {
case len(fhs) == 0:
msg = s.tr(r, "Choose a file first.")
case len(fhs) > maxUploadFiles:
msg = s.trf(r, "At most %d files at a time.", maxUploadFiles)
}
for _, fh := range fhs {
if msg != "" {
break
}
f, err := s.storeUpload(r, fh, false)
if err != nil {
msg = err.Error()
break
}
files = append(files, f)
}
if wantsJSON(r) {
if msg != "" {
writeJSON(w, http.StatusBadRequest, map[string]string{"error": msg})
return
}
f := files[0]
writeJSON(w, http.StatusOK, map[string]any{"id": f.ID.String(), "filename": f.Filename, "kind": f.Kind, "size": f.Size, "markdown": fileMarkdown(f), "html": fileHTML(f)})
return
}
if msg != "" {
d, err := s.filesData(r, "", "", 1)
if err != nil {
s.serverError(w, err)
return
}
d["error"] = msg
s.renderStatus(w, r, http.StatusBadRequest, "dashboard/files.html", d)
return
}
if len(files) == 1 {
redirectOK(w, r, "/b/"+blog.Subdomain+"/files", s.trf(r, "Uploaded %s.", files[0].Filename))
return
}
redirectOK(w, r, "/b/"+blog.Subdomain+"/files", s.trf(r, "Uploaded %d files.", len(files)))
}
func writeJSON(w http.ResponseWriter, status int, v any) {
w.Header().Set("Content-Type", "application/json")
w.Header().Set("X-Content-Type-Options", "nosniff")
w.WriteHeader(status)
_ = json.NewEncoder(w).Encode(v)
}
// filesBack is where rename/delete return to: the list page the form was on.
func filesBack(r *http.Request) string {
if back := safeNext(r.FormValue("back")); back != "" {
return back
}
return "/b/" + currentBlog(r).Subdomain + "/files"
}
func (s *Server) handleFileRename(w http.ResponseWriter, r *http.Request) {
id, err := uuid.Parse(r.PathValue("id"))
if err != nil {
http.NotFound(w, r)
return
}
name := cleanFilename(r.FormValue("filename"))
if err := blogStore(r).RenameFile(r.Context(), id, name); err != nil {
if errors.Is(err, store.ErrNotFound) {
http.NotFound(w, r)
return
}
s.serverError(w, err)
return
}
redirectOK(w, r, filesBack(r), s.trf(r, "Renamed to %s.", name))
}
func (s *Server) handleFileDelete(w http.ResponseWriter, r *http.Request) {
blog := currentBlog(r)
id, err := uuid.Parse(r.PathValue("id"))
if err != nil {
http.NotFound(w, r)
return
}
if err := blogStore(r).DeleteFile(r.Context(), id); err != nil {
s.serverError(w, err)
return
}
// Drop dangling references from the theme.
theme := ParseTheme(blog.ThemeJSON)
changed := false
for _, ref := range []*string{&theme.BgImage, &theme.HeaderImage, &theme.Favicon, &theme.Logo} {
if *ref == id.String() {
*ref, changed = "", true
}
}
if changed {
if err := blogStore(r).UpdateTheme(r.Context(), theme.JSON()); err != nil {
s.serverError(w, err)
return
}
}
redirectOK(w, r, filesBack(r), s.tr(r, "File deleted."))
}