Add CSRF support (MediaWiki bug 23076)
[mw] / src / mw / clicommands.py
index 33c4177d0ceac2ec134fbc46dc669879e6abf636..a42bcfbab0107492d5f2c0b6acfac9d910228dc1 100644 (file)
@@ -16,7 +16,9 @@
 # with this program.  If not, see <http://www.gnu.org/licenses/>.
 ###
 
+import codecs
 import getpass
+import hashlib
 import mw.api
 import mw.metadir
 from optparse import OptionParser, OptionGroup
@@ -36,11 +38,6 @@ class CommandBase(object):
         self.parser = OptionParser(usage=usage, description=description)
         self.name = name
         self.metadir = mw.metadir.Metadir()
-        #global_options = OptionGroup(self.parser, "Global Options")
-        #global_options.add_option('-u', '--use-auth', action='store_true',
-        #                          dest='use_auth', help='force authentication '
-        #                          'even if not required')
-        #self.parser.add_option_group(global_options)
         self.shortcuts = []
 
     def main(self):
@@ -60,6 +57,16 @@ class CommandBase(object):
         if result['login']['result'] == 'Success':
             # cookies are saved to a file
             print 'Login successful! (yay)'
+        elif result['login']['result'] == 'NeedToken':
+            print'Login with token'
+            result = self.api.call({'action': 'login',
+                               'lgname': user,
+                               'lgpassword': passwd,
+                               'lgtoken': result['login']['token']})
+            if result['login']['result'] == 'Success':
+                print 'Login successful! (yay)'
+    else:
+        print 'Login failed: %s' % result['login']['result']
         else:
             print 'Login failed: %s' % result['login']['result']
 
@@ -171,16 +178,87 @@ class DiffCommand(CommandBase):
         for file in status:
             if status[file] == 'U':
                 print self.metadir.diff_rv_to_working(
-                    mw.api.filename_to_pagename(file[:-5])
-                ),
+                        mw.api.filename_to_pagename(file[:-5])),
 
 
 class CommitCommand(CommandBase):
 
     def __init__(self):
-        CommandBase.__init__(self, 'commit', 'commit changes to wiki')
+        usage = '[FILES]'
+        CommandBase.__init__(self, 'commit', 'commit changes to wiki', usage)
         self.shortcuts.append('ci')
+        self.parser.add_option('-m', '--message', dest='edit_summary',
+                               help='don\'t prompt for edit summary and '
+                               'use this instead')
+        self.parser.add_option('--bot', dest='bot', action='store_true',
+                               help='mark actions as a bot (won\'t affect '
+                               'anything if you don\'t have the bot right',
+                               default=False)
 
     def _do_command(self):
         self._die_if_no_init()
         self._api_setup()
+        status = self.metadir.working_dir_status(files=self.args)
+        nothing_to_commit = True
+        for file in status:
+            print '%s %s' % (status[file], file)
+            if status[file] in ['U']:
+                nothing_to_commit = False
+        if nothing_to_commit:
+            print 'nothing to commit'
+            sys.exit()
+        print
+        print 'WARNING: mw does not do collision detection yet.'
+        print 'Hit ^C now if you haven\'t double checked, otherwise hit Enter'
+        raw_input()
+        if self.options.edit_summary == None:
+            print 'Edit summary:',
+            edit_summary = raw_input()
+        else:
+            edit_summary = self.options.edit_summary
+        for file in status:
+            if status[file] in ['U']:
+                # get edit token
+                data = {
+                        'action': 'query',
+                        'prop': 'info',
+                        'intoken': 'edit',
+                        'titles': mw.api.filename_to_pagename(file[:-5]),
+                }
+                response = self.api.call(data)
+                pageid = response['query']['pages'].keys()[0]
+                edittoken = response['query']['pages'][pageid]['edittoken']
+                # FIXME use basetimestamp and starttimestamp
+                filename = os.path.join(self.metadir.root, file)
+                text = codecs.open(filename, 'r', 'utf-8').read()
+                text = text.encode('utf-8')
+                if text[-1] == '\n':
+                    text = text[:-1]
+                md5 = hashlib.md5()
+                md5.update(text)
+                textmd5 = md5.hexdigest()
+                data = {
+                        'action': 'edit',
+                        'title': mw.api.filename_to_pagename(file[:-5]),
+                        'token': edittoken,
+                        'text': text,
+                        'md5': textmd5,
+                        'summary': edit_summary,
+                }
+                if self.options.bot:
+                    data['bot'] = 'bot'
+                response = self.api.call(data)
+                if response['edit']['result'] == 'Success':
+                    data = {
+                            'action': 'query',
+                            'revids': response['edit']['newrevid'],
+                            'prop': 'info|revisions',
+                            'rvprop':
+                                    'ids|flags|timestamp|user|comment|content',
+                    }
+                    response = self.api.call(data)['query']['pages']
+                    self.metadir.pages_add_rv(int(pageid),
+                                              response[pageid]['revisions'][0])
+                else:
+                    print 'committing %s failed: %s' % \
+                            (file, response['edit']['result'])

Benjamin Mako Hill || Want to submit a patch?