1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
|
;;; Copyright © 2019 - 2023 Jakob L. Kreuze <zerodaysfordays@sdf.org>
;;;
;;; This program is free software; you can redistribute it and/or
;;; modify it under the terms of the GNU General Public License as
;;; published by the Free Software Foundation; either version 3 of the
;;; License, or (at your option) any later version.
;;;
;;; This program is distributed in the hope that it will be useful,
;;; but WITHOUT ANY WARRANTY; without even the implied warranty of
;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
;;; General Public License for more details.
;;;
;;; You should have received a copy of the GNU General Public License
;;; along with this program. If not, see
;;; <http://www.gnu.org/licenses/>.
(define-module (jakob dynamic capabilities comment-form)
#:use-module (gcrypt base64)
#:use-module (haunt html)
#:use-module (ice-9 match)
#:use-module (jakob builder blog)
#:use-module (jakob dynamic captcha)
#:use-module (jakob dynamic util)
#:use-module (jakob theme)
#:use-module (jakob utils sxml)
#:use-module (json)
#:use-module (srfi srfi-1)
#:use-module (srfi srfi-11)
#:use-module (web request)
#:use-module (web response)
#:use-module (web uri)
#:export (render-static-comment-form
render-dynamic-comment-form
get-comment-form))
(define (render-comment-field)
`(fieldset (@ (id "comment-content"))
(legend "Comment")
(label (@ (for "name") (class "required")) "Name:")
(input (@ (type "text") (id "name") (name "name") (required #t)))
(label (@ (for "email")) "Email:")
(input (@ (type "text") (id "email") (name "email")))
(label (@ (for "url")) "Webpage URL:")
(input (@ (type "text") (id "url") (name "url")))
(label (@ (for "subject")) "Subject:")
(input (@ (type "text") (id "subject") (name "subject")))
(label (@ (for "comment") (class "required")) "Comment :")
(textarea (@ (id "coment") (name "comment")))
(p "(*) Indicates a required field.")))
(define* (render-comment-captcha-field #:optional (captcha-id "") captcha-image
#:key hidden)
`(fieldset ,(if hidden
'(@ (id "comment-captcha") (hidden "#t"))
'(@ (id "comment-captcha")))
(legend "Captcha")
(div (@ (id "captcha-challenge-primary"))
(label (@ (for "captcha")) "Please evaluate the following definite integral:")
(img (@ (id "captcha-image")
(src ,(if captcha-image
(format #f "data:image/jpeg;charset=utf-8;base64,~a"
(base64-encode captcha-image))
""))))
(input (@ (type "text") (id "captcha") (name "captcha") (size 24))))
(button (@ (id "pow-trigger") (hidden #t))
"Too hard? (Or unable to see the challenge?) Click here.")
(input (@ (autocomplete "off") (type "text") (id "captcha-id") (name "captcha-id") (hidden #t) (value ,captcha-id)))
(input (@ (autocomplete "off") (type "text") (id "captcha-alt") (name "captcha-alt") (hidden #t)))
(input (@ (autocomplete "off") (type "text") (id "captcha-alt-id") (name "captcha-alt-id") (hidden #t)))
(input (@ (type "submit") (id "submit-form") (value "Submit")))))
(define (render-static-comment-form slug captcha-id captcha-image)
`(div (@ (id "comment-form"))
(h1 "Comment form")
(form (@ (id "comment-input") (action "/api/comment") (method "post"))
(input (@ (type "text") (name "slug") (hidden #t) (value ,slug)))
,(render-comment-field)
,(render-comment-captcha-field captcha-id captcha-image))
,(script "proof-of-work.js")))
(define (render-dynamic-comment-form slug)
`(div (@ (id "comment-form"))
(h3 (@ (id "comment-form-header")) "Comment form")
(form (@ (id "comment-input") (action "/api/comment") (method "post"))
(input (@ (autocomplete "off")
(type "text")
(name "slug")
(hidden #t)
(value ,slug)))
(input (@ (autocomplete "off")
(type "text")
(name "reply-to")
(id "reply-to")
(hidden #t)
(value "")))
,(render-comment-field)
(fieldset (@ (id "captcha-trigger-block"))
(legend "Captcha")
(label "You need to complete a captcha to write a comment.")
(button (@ (id "captcha-challenge-trigger"))
"Click here to generate a captcha challenge"))
,(render-comment-captcha-field #:hidden #t))
,(script "dynamic-comment-form.js")
,(script "proof-of-work.js")))
(define (get-comment-form request body)
(let-values (((captcha-id captcha-image) (new-captcha!)))
(let* ((path-encoded (uri-path (request-uri request)))
(path (split-and-decode-uri-path path-encoded))
(slug (last path))
(form (render-static-comment-form slug captcha-id captcha-image)))
(values '((content-type . (text/html)))
(sxml->html-string
(theme #:content form #:title "Comment prompt"))))))
|