More cleanup & formatting
[dylansserver.git] / index.php
index f15b999..5598679 100644 (file)
--- a/index.php
+++ b/index.php
@@ -34,7 +34,10 @@ abstract class cms {
       return 'index';
        } else if (isset($_GET['project'])) {
       return 'project';
+       } else if (isset($_GET['challenge'])) {
+      return 'captcha';
        }
+
   }
 
   public function query() {
@@ -55,7 +58,7 @@ abstract class cms {
        call_user_func_array("mysqli_stmt_bind_result", $fields);
        $i = 0;
        while ($statement->fetch()) {
-         foreach ($row as $key1=>$value1) $return[$i][$key1] = $value1;
+         foreach ($row as $key=>$value) $return[$i][$key] = $value;
          $i++;
        }
        $statement->free_result();
@@ -66,8 +69,14 @@ abstract class cms {
                                                                $home_link = "/") {
     $scripts = "";
        $stylesheets = "<link href=\"/includes/style.css\" rel=\"stylesheet\" type=\"text/css\">";
-       if (cms::determine_type() == "index") { $scripts = "<script type=\"text/javascript\" src=\"/includes/all.js\">";
+       if ($this->determine_type() == "index") {
+         $scripts = "<script type=\"text/javascript\" src=\"/includes/all.js\">";
          $home_link = "http://validator.w3.org/unicorn/check?ucn_uri=dylanstestserver.com&amp;ucn_task=conformance#";
+       } else if ($this->determine_type() == 'note') {
+         $scripts = "<script type=\"text/javascript\" src=\"http://www.google.com/recaptcha/api/js/recaptcha_ajax.js\"></script>";
+         $scripts .= "<script type=\"text/javascript\" src=\"/includes/jquery-core.js\"></script>";
+         $scripts .= "<script type=\"text/javascript\" src=\"/includes/jquery-all-components.js\"></script>";
+         $scripts .= "<script type=\"text/javascript\" src=\"/includes/ajax.js\"></script>";
        }
   echo <<<END_OF_HEAD
 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
@@ -296,6 +305,7 @@ class note extends cms {
 
   private $id;
   private $comments_enabled = false;
+  private $failed_captcha;
   public $url;
   public $title;
   public $year_posted;
@@ -334,6 +344,9 @@ class note extends cms {
        $result = $this->db->query($sql);
        $result = $result->fetch_array();
        $this->number_of_comments = $result[0];
+       if (isset($_GET['verify'])) {
+         $this->verify();
+       }
   }
 
   public function display() {
@@ -348,23 +361,27 @@ class note extends cms {
   }
 
   private function verify() {
-    require_once('includes/recaptchalib.php');
-       echo "<br>";
-    $resp = recaptcha_check_answer ($this->recaptcha_privatekey,
-                                                                   $_SERVER["REMOTE_ADDR"],
-                                                                   $_POST["recaptcha_challenge_field"],
-                                                                   $_POST["recaptcha_response_field"]);
-    if (!$resp->is_valid) {
-      echo "<span style=\"color:red;border:1px solid black;padding:15px;\">sorry, reCAPTCHA said you're not human.</span><br><br><br>";
-    } else {
+    if (!isset($_POST['captcha'])) {
+      require_once('includes/recaptchalib.php');
+         echo "<br>";
+      $resp = recaptcha_check_answer ($this->recaptcha_privatekey,
+                                                                     $_SERVER["REMOTE_ADDR"],
+                                                                     $_POST["recaptcha_challenge_field"],
+                                                                     $_POST["recaptcha_response_field"]);
+      if (!$resp->is_valid) {
+           $this->failed_captcha = true;
+         }
+    }
+       if (isset($_POST['captcha']) || $resp->is_valid) {
          $sql = ("INSERT INTO comments (date_posted, author,
                                email, text, note)
                                VALUES(NOW(), ?, ?, ?, ?)");
          $stmt = $this->db->prepare($sql);
          // Checks are needed here (no blank text,
          // and a default author / email need to be set
+         // for no-javascript users.
          $stmt->bind_param('ssss',
-                                               htmlspecialchars($_POST['author']),
+                                               htmlspecialchars($_POST['name']),
                                                htmlspecialchars($_POST['email']),
                                                htmlspecialchars($_POST['text']),
                                                $this->id);
@@ -419,59 +436,79 @@ END_OF_NAVIGATION;
          $author = $entry['author'];
          $email = $entry['email'];
          $text = htmlspecialchars($entry['text']);
+         if ($email == '') {
+           $head = "<h3>$author</h3>";
+         } else {
+           $head = "<h3><a href='mailto:$email'>$author</a></h3>";
+         }
          echo <<<END_OF_COMMENT
-         <h3><a href="mailto:$email">$author</a></h3>
+         <div class='comment'>
+         $head
          $text
-         <br>
-         <br>
+         </div>
 END_OF_COMMENT;
          }
        echo "</div>";
   }
 
   private function display_comment_form() {
+    $publickey = $this->recaptcha_publickey;
     echo <<<END_CAPTCHA_STYLE
 <script type="text/javascript">
-var RecaptchaOptions = {
-   theme : 'custom',
-   custom_theme_widget: 'recaptcha_widget'
-   };
+Recaptcha.create("$publickey",
+   "recaptcha_div", 
+   {
+     theme : 'custom',
+     custom_theme_widget: 'recaptcha_widget',
+     callback: Recaptcha.focus_response_field
+   });
 </script>
 END_CAPTCHA_STYLE;
     require_once('includes/recaptchalib.php');
-       // Trailing slash is necessary for reloads to work
     $url = $this->url . "verify";
-       echo "<form method=\"post\" action=\"$url\">";
-       echo  <<<FORM
-       <div id="comment">
-
-<h3>comment:</h3>
-<textarea rows="10" cols="70" name=text></textarea>
-<h3>name:</h3>
-<input type=text name=author>
-<h3>email:</h3>
-<input type=text name=email><br>
-<nowiki>
-
-<div id="recaptcha_widget"> 
-<h3 class="recaptcha_only_if_image"><b>what's this say</b>?</h3>
-<h3 class="recaptcha_only_if_audio"><b>enter the numbers you hear</b>:</h3>
-<span style="font-size:80%;">(<a href="javascript:Recaptcha.reload()">another</a>/<span class="recaptcha_only_if_image"><a href="javascript:Recaptcha.switch_type('audio')">audio</a></span>/<span class="recaptcha_only_if_audio"><a href="javascript:Recaptcha.switch_type('image')">Get an image CAPTCHA</a></span><a href="javascript:Recaptcha.showhelp()">help</a>)</span><br><br>
-  <input type="text" id="recaptcha_response_field" name="recaptcha_response_field" />
-  <br><br>
-  <div style="float:right;position:relative;width:100px;"><div id="recaptcha_image"></div></div>
-  <br><br><br><br>
-</div>
-FORM;
-       echo recaptcha_get_html($this->recaptcha_publickey);
-       if (isset($_GET['verify'])) {
-         $this->verify();
-       }
-       echo  <<<END_OF_FORM
-       <input class="submit" type="submit" value="comment">
-       </form>
-       </div>
+       echo "<form id=\"comment_form\"  method=\"post\" action=\"$url\">";
+       echo <<<END_OF_FORM
+    <div id="comment">
+      <h3>comment:</h3>
+      <textarea rows="10" cols="70" name="text" id="comment_text"></textarea>
+      <h3>name:</h3>
+      <input type=text name="name" id="comment_name">
+      <h3>email:</h3>
+      <input type=text name="email" id="comment_email"><br>
+  
+      <nowiki>
+      <div id="recaptcha_widget"> 
+        <h3 class="recaptcha_only_if_image"><b>what's this say</b>?</h3>
+        <h3 class="recaptcha_only_if_audio"><b>enter the numbers you hear</b>:</h3>
+        <span style="font-size:80%;">
+             ( <a href="javascript:Recaptcha.reload()">another</a> /
+          <span class="recaptcha_only_if_image"><a href="javascript:Recaptcha.switch_type('audio')">audio</a></span> /
+          <span class="recaptcha_only_if_audio"><a href="javascript:Recaptcha.switch_type('image')">Get an image CAPTCHA</a></span><a href="javascript:Recaptcha.showhelp()">help</a> )
+           </span>
+        <br><br>
+        <input type="text" id="recaptcha_response_field" name="recaptcha_response_field" />
+        <br><br>
+        <div style="float:right;position:relative;width:100px;">
+             <div id="recaptcha_image"></div>
+           </div>
+        <br><br><br><br>
+      </div>
+END_OF_FORM;
+    echo recaptcha_get_html($this->recaptcha_publickey); 
+    if ($this->failed_captcha) {
+    echo <<<END_OF_FORM
+        <span style='font-weight:bold;font-family:sans-serif;color:red;margin-top:15px;'>reCAPTCHA said you're not human,</span>
+        <input id="submit" class="submit" type="submit" value="try again?">
+        </form>
+      </div>
+END_OF_FORM;
+    } else {
+         echo <<<END_OF_FORM
+      <input id="submit" class="submit" type="submit" value="post comment">
+      </form>
+      </div>
 END_OF_FORM;
+    }
   }
 }
 
@@ -570,6 +607,19 @@ class notFound extends Exception {
        }
 }
 
+class captcha extends cms {
+       public function display() {
+         $challenge = $_GET['challenge'];
+         $response = $_GET['response'];
+         $remoteip = $_SERVER['REMOTE_ADDR'];
+      $curl = curl_init('http://api-verify.recaptcha.net/verify?');
+      curl_setopt ($curl, CURLOPT_POST, 4);
+      curl_setopt ($curl, CURLOPT_POSTFIELDS, "privatekey=$this->recaptcha_privatekey&remoteip=$remoteip&challenge=$challenge&response=$response");
+         $result = curl_exec ($curl);
+         curl_close ($curl);
+       }
+}
+
 ## now actually do something:
 switch (cms::determine_type()) {
   case "index":
@@ -596,6 +646,10 @@ switch (cms::determine_type()) {
     $archive = new archive;
        $archive->display();
        break;
+  case "captcha":
+    $captcha = new captcha;
+       $captcha->display();
+       break;
 }
 
 ?>