Page move undo feature
[lhc/web/wiklou.git] / includes / SpecialMovepage.php
index 1db3b34..fc52580 100644 (file)
@@ -1,12 +1,23 @@
 <?php
+/**
+ *
+ * @package MediaWiki
+ * @subpackage SpecialPage
+ */
+
+/**
+ *
+ */
 require_once( "LinksUpdate.php" );
 
-function wfSpecialMovepage()
-{
+/**
+ * Constructor
+ */
+function wfSpecialMovepage() {
        global $wgUser, $wgOut, $wgRequest, $action, $wgOnlySysopMayMove;
 
        # check rights. We don't want newbies to move pages to prevents possible attack
-       if ( 0 == $wgUser->getID() or $wgUser->isBlocked() or ($wgOnlySysopMayMove and $wgUser->isNewbie())) {
+       if ( $wgUser->isAnon() or $wgUser->isBlocked() or ($wgOnlySysopMayMove and $wgUser->isNewbie())) {
                $wgOut->errorpage( "movenologin", "movenologintext" );
                return;
        }
@@ -18,73 +29,108 @@ function wfSpecialMovepage()
 
        $f = new MovePageForm();
 
-       if ( 'success' == $action ) { $f->showSuccess(); }
-       else if ( 'submit' == $action && $wgRequest->wasPosted() ) { $f->doSubmit(); }
-       else { $f->showForm( '' ); }
+       if ( 'success' == $action ) {
+               $f->showSuccess();
+       } else if ( 'submit' == $action && $wgRequest->wasPosted()
+               && $wgUser->matchEditToken( $wgRequest->getVal( 'wpEditToken' ) ) ) {
+               $f->doSubmit();
+       } else {
+               $f->showForm( '' );
+       }
 }
 
+/**
+ *
+ * @package MediaWiki
+ * @subpackage SpecialPage
+ */
 class MovePageForm {
-       var $oldTitle, $newTitle; # Text input
+       var $oldTitle, $newTitle, $reason; # Text input
+       var $moveTalk;
                
        function MovePageForm() {
                global $wgRequest;
                $this->oldTitle = $wgRequest->getText( 'wpOldTitle', $wgRequest->getVal( 'target' ) );
                $this->newTitle = $wgRequest->getText( 'wpNewTitle' );
+               $this->reason = $wgRequest->getText( 'wpReason' );
+               $this->moveTalk = $wgRequest->getBool( 'wpMovetalk', true );
        }
        
-       function showForm( $err )
-       {
+       function showForm( $err ) {
                global $wgOut, $wgUser, $wgLang;
 
                $wgOut->setPagetitle( wfMsg( 'movepage' ) );
 
-               if ( empty( $this->oldTitle ) ) {
+               if ( $this->oldTitle == '' ) {
                        $wgOut->errorpage( 'notargettitle', 'notargettext' );
                        return;
                }
+
+               $ot = Title::newFromURL( $this->oldTitle );
+               $oldTitle = $ot->getPrefixedText();
                
                $encOldTitle = htmlspecialchars( $this->oldTitle );
-               $encNewTitle = htmlspecialchars( $this->newTitle );
-               $ot = Title::newFromURL( $this->oldTitle );
-               $ott = $ot->getPrefixedText();
+               if( $this->newTitle == '' ) {
+                       # Show the current title as a default
+                       # when the form is first opened.
+                       $encNewTitle = $oldTitle;
+               } else {
+                       $encNewTitle = htmlspecialchars( $this->newTitle );
+               }
+               $encReason = htmlspecialchars( $this->reason );
 
                $wgOut->addWikiText( wfMsg( 'movepagetext' ) );
-               if ( ! Namespace::isTalk( $ot->getNamespace() ) ) {
+               if ( !$ot->isTalkPage() ) {
                        $wgOut->addWikiText( wfMsg( 'movepagetalktext' ) );
                }
 
-               $ma = wfMsg( 'movearticle' );
-               $newt = wfMsg( 'newtitle' );
-               $mpb = wfMsg( 'movepagebtn' );
+               $movearticle = wfMsg( 'movearticle' );
+               $newtitle = wfMsg( 'newtitle' );
+               $movepagebtn = wfMsg( 'movepagebtn' );
                $movetalk = wfMsg( 'movetalk' );
+               $movereason = wfMsg( 'movereason' );
 
                $titleObj = Title::makeTitle( NS_SPECIAL, 'Movepage' );
                $action = $titleObj->escapeLocalURL( 'action=submit' );
+               $token = htmlspecialchars( $wgUser->editToken() );
 
                if ( $err != '' ) {
                        $wgOut->setSubtitle( wfMsg( 'formerror' ) );
                        $wgOut->addHTML( '<p class="error">'.$err."</p>\n" );
                }
+
+               if ( $this->moveTalk ) {
+                       $moveTalkChecked = " checked='checked'";
+               } else {
+                       $moveTalkChecked = '';
+               }
+               
                $wgOut->addHTML( "
 <form id=\"movepage\" method=\"post\" action=\"{$action}\">
        <table border='0'>
                <tr>
-                       <td align='right'>{$ma}:</td>
-                       <td align='left'><strong>{$ott}</strong></td>
+                       <td align='right'>{$movearticle}:</td>
+                       <td align='left'><strong>{$oldTitle}</strong></td>
                </tr>
                <tr>
-                       <td align='right'>{$newt}:</td>
+                       <td align='right'>{$newtitle}:</td>
                        <td align='left'>
                                <input type='text' size='40' name=\"wpNewTitle\" value=\"{$encNewTitle}\" />
                                <input type='hidden' name=\"wpOldTitle\" value=\"{$encOldTitle}\" />
                        </td>
+               </tr>
+               <tr>
+                       <td align='right'>{$movereason}:</td>
+                       <td align='left'>
+                               <input type='text' size=40 name=\"wpReason\" value=\"{$encReason}\" />
+                       </td>
                </tr>" );
 
-               if ( ! Namespace::isTalk( $ot->getNamespace() ) ) {
+               if ( ! $ot->isTalkPage() ) {
                        $wgOut->addHTML( "
                <tr>
                        <td align='right'>
-                               <input type='checkbox' name=\"wpMovetalk\" checked='checked' value=\"1\" />
+                               <input type='checkbox' name=\"wpMovetalk\"{$moveTalkChecked} value=\"1\" />
                        </td>
                        <td>{$movetalk}</td>
                </tr>" );
@@ -93,16 +139,16 @@ class MovePageForm {
                <tr>
                        <td>&nbsp;</td>
                        <td align='left'>
-                               <input type='submit' name=\"wpMove\" value=\"{$mpb}\" />
+                               <input type='submit' name=\"wpMove\" value=\"{$movepagebtn}\" />
                        </td>
                </tr>
        </table>
+       <input type='hidden' name='wpEditToken' value=\"{$token}\" />
 </form>\n" );
 
        }
 
-       function doSubmit()
-       {
+       function doSubmit() {
                global $wgOut, $wgUser, $wgLang;
                global $wgDeferredUpdateList, $wgMessageCache;
                global  $wgUseSquid, $wgRequest;
@@ -110,23 +156,46 @@ class MovePageForm {
                
                # Variables beginning with 'o' for old article 'n' for new article
 
+               # Attempt to move the article
                $ot = Title::newFromText( $this->oldTitle );
                $nt = Title::newFromText( $this->newTitle );
 
-               $error = $ot->moveTo( $nt );
+               # don't allow moving to pages with # in
+               if ( !$nt || $nt->getFragment() != '' ) {
+                       $this->showForm( wfMsg( "badtitletext" ) );
+                       return;
+               }
+
+               $error = $ot->moveTo( $nt, true, $this->reason );
                if ( $error !== true ) {
                        $this->showForm( wfMsg( $error ) );
                        return;
                }
+
+               # Update counters if the article got moved into or out of NS_MAIN namespace
+               $ons = $ot->getNamespace();
+               $nns = $nt->getNamespace();
+               
+               # moved out of article namespace?
+               if ( $ons == NS_MAIN and $nns != NS_MAIN ) {
+                       $u = new SiteStatsUpdate( 0, 1, -1); # not viewed, edited, removing
+               }
+               # moved into article namespace?
+               elseif ( $ons != NS_MAIN and $nns == NS_MAIN ) {
+                       $u = new SiteStatsUpdate( 0, 1, +1 ); # not viewed, edited, adding
+               } else {
+                       $u = false;
+               }
+               if ( $u !== false ) {
+                       # save it for later update
+                       array_push( $wgDeferredUpdateList, $u );
+                       unset($u);
+               }
                
                # Move talk page if
                # (1) the checkbox says to,
                # (2) the namespaces are not themselves talk namespaces, and of course
                # (3) it exists.
-
-               $ons = $ot->getNamespace();
-               $nns = $nt->getNamespace();
-               
                if ( ( $wgRequest->getVal('wpMovetalk') == 1 ) &&
                     ( ! Namespace::isTalk( $ons ) ) &&
                     ( ! Namespace::isTalk( $nns ) ) ) {
@@ -141,7 +210,7 @@ class MovePageForm {
                        $ntt = Title::makeTitle( $nns, $nt->getDBkey() );
 
                        # Attempt the move
-                       $error = $ott->moveTo( $ntt );
+                       $error = $ott->moveTo( $ntt, true, $this->reason );
                        if ( $error === true ) {
                                $talkmoved = 1;
                        } else {
@@ -150,7 +219,6 @@ class MovePageForm {
                }
                
                # Give back result to user.
-               
                $titleObj = Title::makeTitle( NS_SPECIAL, 'Movepage' );
                $success = $titleObj->getFullURL( 
                  'action=success&oldtitle=' . wfUrlencode( $ot->getPrefixedText() ) .
@@ -160,9 +228,8 @@ class MovePageForm {
                $wgOut->redirect( $success );
        }
 
-       function showSuccess()
-       {
-               global $wgOut, $wgUser, $wgRequest;
+       function showSuccess() {
+               global $wgOut, $wgRequest, $wgRawHtml;
 
                $wgOut->setPagetitle( wfMsg( 'movepage' ) );
                $wgOut->setSubtitle( wfMsg( 'pagemovedsub' ) );
@@ -171,7 +238,12 @@ class MovePageForm {
                $talkmoved = $wgRequest->getVal('talkmoved');
 
                $text = wfMsg( 'pagemovedtext', $oldtitle, $newtitle );
+               
+               # Temporarily disable raw html wikitext option out of XSS paranoia
+               $marchingantofdoom = $wgRawHtml;
+               $wgRawHtml = false;
                $wgOut->addWikiText( $text );
+               $wgRawHtml = $marchingantofdoom;
 
                if ( $talkmoved == 1 ) {
                        $wgOut->addHTML( "\n<p>" . wfMsg( 'talkpagemoved' ) . "</p>\n" );
@@ -179,7 +251,7 @@ class MovePageForm {
                        $wgOut->addHTML( "\n<p><strong>" . wfMsg( 'talkexists' ) . "</strong></p>\n" );
                } else {
                        $ot = Title::newFromURL( $oldtitle );
-                       if ( ! Namespace::isTalk( $ot->getNamespace() ) ) {
+                       if ( ! $ot->isTalkPage() ) {
                                $wgOut->addHTML( "\n<p>" . wfMsg( 'talkpagenotmoved', wfMsg( $talkmoved ) ) . "</p>\n" );
                        }
                }