Ви не можете вибрати більше 25 тем Теми мають розпочинатися з літери або цифри, можуть містити дефіси (-) і не повинні перевищувати 35 символів.

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269
  1. /*
  2. * Copyright 2011 gitblit.com.
  3. *
  4. * Licensed under the Apache License, Version 2.0 (the "License");
  5. * you may not use this file except in compliance with the License.
  6. * You may obtain a copy of the License at
  7. *
  8. * http://www.apache.org/licenses/LICENSE-2.0
  9. *
  10. * Unless required by applicable law or agreed to in writing, software
  11. * distributed under the License is distributed on an "AS IS" BASIS,
  12. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  13. * See the License for the specific language governing permissions and
  14. * limitations under the License.
  15. */
  16. package com.gitblit.wicket.pages;
  17. import java.util.LinkedHashMap;
  18. import java.util.Map;
  19. import java.util.TimeZone;
  20. import javax.servlet.http.Cookie;
  21. import javax.servlet.http.HttpServletRequest;
  22. import org.apache.wicket.Application;
  23. import org.apache.wicket.MarkupContainer;
  24. import org.apache.wicket.PageParameters;
  25. import org.apache.wicket.RestartResponseAtInterceptPageException;
  26. import org.apache.wicket.RestartResponseException;
  27. import org.apache.wicket.markup.html.WebPage;
  28. import org.apache.wicket.markup.html.basic.Label;
  29. import org.apache.wicket.markup.html.link.BookmarkablePageLink;
  30. import org.apache.wicket.markup.html.link.ExternalLink;
  31. import org.apache.wicket.markup.html.panel.FeedbackPanel;
  32. import org.apache.wicket.markup.html.panel.Fragment;
  33. import org.apache.wicket.protocol.http.WebRequest;
  34. import org.apache.wicket.protocol.http.WebResponse;
  35. import org.apache.wicket.protocol.http.servlet.ServletWebRequest;
  36. import org.slf4j.Logger;
  37. import org.slf4j.LoggerFactory;
  38. import com.gitblit.Constants;
  39. import com.gitblit.Constants.AccessRestrictionType;
  40. import com.gitblit.Constants.FederationStrategy;
  41. import com.gitblit.GitBlit;
  42. import com.gitblit.Keys;
  43. import com.gitblit.models.RepositoryModel;
  44. import com.gitblit.models.UserModel;
  45. import com.gitblit.wicket.GitBlitWebSession;
  46. import com.gitblit.wicket.WicketUtils;
  47. import com.gitblit.wicket.panels.LinkPanel;
  48. public abstract class BasePage extends WebPage {
  49. private final Logger logger;
  50. public BasePage() {
  51. super();
  52. logger = LoggerFactory.getLogger(getClass());
  53. loginByCookie();
  54. }
  55. public BasePage(PageParameters params) {
  56. super(params);
  57. logger = LoggerFactory.getLogger(getClass());
  58. loginByCookie();
  59. }
  60. @Override
  61. protected void onBeforeRender() {
  62. if (GitBlit.isDebugMode()) {
  63. // strip Wicket tags in debug mode for jQuery DOM traversal
  64. Application.get().getMarkupSettings().setStripWicketTags(true);
  65. }
  66. super.onBeforeRender();
  67. }
  68. @Override
  69. protected void onAfterRender() {
  70. if (GitBlit.isDebugMode()) {
  71. // restore Wicket debug tags
  72. Application.get().getMarkupSettings().setStripWicketTags(false);
  73. }
  74. super.onAfterRender();
  75. }
  76. private void loginByCookie() {
  77. if (!GitBlit.getBoolean(Keys.web.allowCookieAuthentication, false)) {
  78. return;
  79. }
  80. UserModel user = null;
  81. // Grab cookie from Browser Session
  82. Cookie[] cookies = ((WebRequest) getRequestCycle().getRequest()).getCookies();
  83. if (cookies != null && cookies.length > 0) {
  84. user = GitBlit.self().authenticate(cookies);
  85. }
  86. // Login the user
  87. if (user != null) {
  88. // Set the user into the session
  89. GitBlitWebSession session = GitBlitWebSession.get();
  90. // issue 62: fix session fixation vulnerability
  91. session.replaceSession();
  92. session.setUser(user);
  93. // Set Cookie
  94. WebResponse response = (WebResponse) getRequestCycle().getResponse();
  95. GitBlit.self().setCookie(response, user);
  96. continueToOriginalDestination();
  97. }
  98. }
  99. protected void setupPage(String repositoryName, String pageName) {
  100. if (repositoryName != null && repositoryName.trim().length() > 0) {
  101. add(new Label("title", getServerName() + " - " + repositoryName));
  102. } else {
  103. add(new Label("title", getServerName()));
  104. }
  105. ExternalLink rootLink = new ExternalLink("rootLink", urlFor(RepositoriesPage.class, null).toString());
  106. WicketUtils.setHtmlTooltip(rootLink, GitBlit.getString(Keys.web.siteName, Constants.NAME));
  107. add(rootLink);
  108. // Feedback panel for info, warning, and non-fatal error messages
  109. add(new FeedbackPanel("feedback"));
  110. // footer
  111. if (GitBlit.getBoolean(Keys.web.authenticateViewPages, true)
  112. || GitBlit.getBoolean(Keys.web.authenticateAdminPages, true)) {
  113. UserFragment userFragment = new UserFragment("userPanel", "userFragment", BasePage.this);
  114. add(userFragment);
  115. } else {
  116. add(new Label("userPanel", ""));
  117. }
  118. add(new Label("gbVersion", "v" + Constants.VERSION));
  119. if (GitBlit.getBoolean(Keys.web.aggressiveHeapManagement, false)) {
  120. System.gc();
  121. }
  122. }
  123. protected Map<AccessRestrictionType, String> getAccessRestrictions() {
  124. Map<AccessRestrictionType, String> map = new LinkedHashMap<AccessRestrictionType, String>();
  125. for (AccessRestrictionType type : AccessRestrictionType.values()) {
  126. switch (type) {
  127. case NONE:
  128. map.put(type, getString("gb.notRestricted"));
  129. break;
  130. case PUSH:
  131. map.put(type, getString("gb.pushRestricted"));
  132. break;
  133. case CLONE:
  134. map.put(type, getString("gb.cloneRestricted"));
  135. break;
  136. case VIEW:
  137. map.put(type, getString("gb.viewRestricted"));
  138. break;
  139. }
  140. }
  141. return map;
  142. }
  143. protected Map<FederationStrategy, String> getFederationTypes() {
  144. Map<FederationStrategy, String> map = new LinkedHashMap<FederationStrategy, String>();
  145. for (FederationStrategy type : FederationStrategy.values()) {
  146. switch (type) {
  147. case EXCLUDE:
  148. map.put(type, getString("gb.excludeFromFederation"));
  149. break;
  150. case FEDERATE_THIS:
  151. map.put(type, getString("gb.federateThis"));
  152. break;
  153. case FEDERATE_ORIGIN:
  154. map.put(type, getString("gb.federateOrigin"));
  155. break;
  156. }
  157. }
  158. return map;
  159. }
  160. protected TimeZone getTimeZone() {
  161. return GitBlit.getBoolean(Keys.web.useClientTimezone, false) ? GitBlitWebSession.get()
  162. .getTimezone() : TimeZone.getDefault();
  163. }
  164. protected String getServerName() {
  165. ServletWebRequest servletWebRequest = (ServletWebRequest) getRequest();
  166. HttpServletRequest req = servletWebRequest.getHttpServletRequest();
  167. return req.getServerName();
  168. }
  169. protected String getRepositoryUrl(RepositoryModel repository) {
  170. StringBuilder sb = new StringBuilder();
  171. sb.append(WicketUtils.getGitblitURL(getRequestCycle().getRequest()));
  172. sb.append(Constants.GIT_PATH);
  173. sb.append(repository.name);
  174. // inject username into repository url if authentication is required
  175. if (repository.accessRestriction.exceeds(AccessRestrictionType.NONE)
  176. && GitBlitWebSession.get().isLoggedIn()) {
  177. String username = GitBlitWebSession.get().getUser().username;
  178. sb.insert(sb.indexOf("://") + 3, username + "@");
  179. }
  180. return sb.toString();
  181. }
  182. public void warn(String message, Throwable t) {
  183. logger.warn(message, t);
  184. }
  185. public void error(String message, boolean redirect) {
  186. logger.error(message);
  187. if (redirect) {
  188. GitBlitWebSession.get().cacheErrorMessage(message);
  189. throw new RestartResponseException(getApplication().getHomePage());
  190. } else {
  191. super.error(message);
  192. }
  193. }
  194. public void error(String message, Throwable t, boolean redirect) {
  195. logger.error(message, t);
  196. if (redirect) {
  197. GitBlitWebSession.get().cacheErrorMessage(message);
  198. throw new RestartResponseException(getApplication().getHomePage());
  199. } else {
  200. super.error(message);
  201. }
  202. }
  203. public void authenticationError(String message) {
  204. logger.error(message);
  205. if (GitBlitWebSession.get().isLoggedIn()) {
  206. error(message, true);
  207. } else {
  208. throw new RestartResponseAtInterceptPageException(RepositoriesPage.class);
  209. }
  210. }
  211. /**
  212. * Panel fragment for displaying login or logout/change_password links.
  213. *
  214. */
  215. static class UserFragment extends Fragment {
  216. private static final long serialVersionUID = 1L;
  217. public UserFragment(String id, String markupId, MarkupContainer markupProvider) {
  218. super(id, markupId, markupProvider);
  219. if (GitBlitWebSession.get().isLoggedIn()) {
  220. // username, logout, and change password
  221. add(new Label("username", GitBlitWebSession.get().getUser().toString() + ":"));
  222. add(new LinkPanel("loginLink", null, markupProvider.getString("gb.logout"),
  223. LogoutPage.class));
  224. // quick and dirty hack for showing a separator
  225. add(new Label("separator", "|"));
  226. add(new BookmarkablePageLink<Void>("changePasswordLink", ChangePasswordPage.class));
  227. } else {
  228. // login
  229. add(new Label("username").setVisible(false));
  230. add(new Label("loginLink").setVisible(false));
  231. add(new Label("separator").setVisible(false));
  232. add(new Label("changePasswordLink").setVisible(false));
  233. }
  234. }
  235. }
  236. }