XMLRPC Vote Casting Validation:
authorJohn Dong <jdong@mit.edu>
Fri, 17 Aug 2007 00:20:16 +0000 (20:20 -0400)
committerJohn Dong <jdong@mit.edu>
Fri, 17 Aug 2007 00:20:16 +0000 (20:20 -0400)
  * Can only vote for candidate_id's within the current election
  * Can only rank each candidate once
  * Must rank all candidates

TODO
app/models/selectricity_service.rb

diff --git a/TODO b/TODO
index dbac0f6d66007bf545cfbd969cd7a3aa4644af2f..be982eeb0f2e80459948cc28269d7a197049e975 100644 (file)
--- a/TODO
+++ b/TODO
@@ -1,3 +1,2 @@
 Known bugs or issues:
 
-* Validate XMLRPC data, particularly creating quickvotes
index 3f0a3bf7442ba12deb8d9d96ae5944af272085dc..4075f6401fa40f889f16be53ac80fc7b17398d57 100644 (file)
@@ -5,6 +5,12 @@ class SelectricityService < ActionWebService::Base
   def cast_quickvote(election_name, voter_id, vote_list)
     election = QuickVote.ident_to_quickvote election_name
     if election
+      candidates=election.candidates.collect { |c| c.id }
+      vote_list[0].each do |vote|
+        raise ArgumentError.new "Invalid Candidate ID #{vote}" unless candidates.index(vote)
+      end
+      raise ArgumentError.new "You must rank all candidates" unless candidates.length <= vote_list[0].length
+      raise ArgumentError.new "Please rank each candidate only once" if vote_list[0].uniq!
       voter = QuickVoter.new
       voter.election = election
       voter.ipaddress = "XMLRPC Request"

Benjamin Mako Hill || Want to submit a patch?