summaryrefslogtreecommitdiff
path: root/actions/deletenotice.php
blob: ba348c5faf4f5bf2be2cf6fc99aef8b11e9a30db (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
<?php
/*
 * Laconica - a distributed open-source microblogging tool
 * Copyright (C) 2008, Controlez-Vous, Inc.
 *
 * This program is free software: you can redistribute it and/or modify
 * it under the terms of the GNU Affero General Public License as published by
 * the Free Software Foundation, either version 3 of the License, or
 * (at your option) any later version.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU Affero General Public License for more details.
 *
 * You should have received a copy of the GNU Affero General Public License
 * along with this program.  If not, see <http://www.gnu.org/licenses/>.
 */

if (!defined('LACONICA')) { exit(1); }

require_once(INSTALLDIR.'/lib/deleteaction.php');

class DeletenoticeAction extends DeleteAction {
    function handle($args) {
        parent::handle($args);
        # XXX: Ajax!

        if ($_SERVER['REQUEST_METHOD'] == 'POST') {
            $this->delete_notice();
        } else if ($_SERVER['REQUEST_METHOD'] == 'GET') {
            $this->show_form();
        }
    }

    function get_instructions() {
        return _('You are about to permanently delete a notice.  Once this is done, it cannot be undone.');
    }

    function get_title() {
        return _('Delete notice');
    }

    function show_form($error=NULL) {
        $user = common_current_user();

        common_show_header($this->get_title(), array($this, 'show_header'), $error,
                           array($this, 'show_top'));
        common_element_start('form', array('id' => 'notice_delete_form',
                                   'method' => 'post',
                                   'action' => common_local_url('deletenotice')));
        common_hidden('token', common_session_token());
        common_hidden('notice', $this->trimmed('notice'));
        common_element_start('p');
        common_element('span', array('id' => 'confirmation_text'), _('Are you sure you want to delete this notice?'));

        common_element('input', array('id' => 'submit_no',
                          'name' => 'submit',
                          'type' => 'submit',
                          'value' => _('No')));
        common_element('input', array('id' => 'submit_yes',
                          'name' => 'submit',
                          'type' => 'submit',
                          'value' => _('Yes')));
        common_element_end('p');
        common_element_end('form');
        common_show_footer();
    }

    function delete_notice() {
        # CSRF protection
        $token = $this->trimmed('token');
        if (!$token || $token != common_session_token()) {
            $this->show_form(_('There was a problem with your session token. Try again, please.'));
            return;
        }
        $url = common_get_returnto();
        $confirmed = $this->trimmed('submit');
        if ($confirmed == _('Yes')) {
            $user = common_current_user();
            $notice_id = $this->trimmed('notice');
            $notice = Notice::staticGet($notice_id);
            $replies = new Reply;
            $replies->get('notice_id', $notice_id);

            common_dequeue_notice($notice);
            if (common_config('memcached', 'enabled')) {
                $notice->blowSubsCache();
            }
            $replies->delete();
            $notice->delete();
        } else {
            if ($url) {
                common_set_returnto(NULL);
            } else {
                $url = common_local_url('public');
            }
        }
        common_redirect($url);
    }
}