internal/httpd/mractions.go
287 lines · 9697 bytes
1package httpd
2
3import (
4 "fmt"
5 "net/http"
6 "net/url"
7 "strconv"
8 "strings"
9
10 "gitbay.org/gitbay/internal/control"
11 "gitbay.org/gitbay/internal/gitutil"
12 "gitbay.org/gitbay/internal/policy"
13 "gitbay.org/gitbay/internal/store"
14)
15
16// Merge request actions. Each one runs the control command the CLI runs,
17// so review rules, merge gates, and audit entries have a single
18// implementation; the browser only chooses arguments and shows the
19// result.
20
21// mrRedirect returns to the merge request, carrying a failure message the
22// page renders as a banner.
23func (s *Server) mrRedirect(w http.ResponseWriter, r *http.Request, msg string) {
24 dest := fmt.Sprintf("/%s/%s/mrs/%s",
25 r.PathValue("owner"), r.PathValue("repo"), r.PathValue("n"))
26 s.setFlash(w, msg)
27 http.Redirect(w, r, dest, http.StatusSeeOther)
28}
29
30// mrDiffRedirect returns to the diff view, where the thread controls are.
31func (s *Server) mrDiffRedirect(w http.ResponseWriter, r *http.Request, msg string) {
32 dest := fmt.Sprintf("/%s/%s/mrs/%s?view=diff",
33 r.PathValue("owner"), r.PathValue("repo"), r.PathValue("n"))
34 s.setFlash(w, msg)
35 http.Redirect(w, r, dest, http.StatusSeeOther)
36}
37
38// mrArgs builds "<verb> owner/name <n>" for the mr command family.
39func mrArgs(r *http.Request, verb string, extra ...string) []string {
40 repo := r.PathValue("owner") + "/" + r.PathValue("repo")
41 return append([]string{"mr", verb, repo, r.PathValue("n")}, extra...)
42}
43
44func (s *Server) mrReviewSubmit(w http.ResponseWriter, r *http.Request, u store.User) {
45 flag := map[string]string{
46 "approve": "--approve",
47 "request-changes": "--request-changes",
48 "comment": "--comment",
49 }[r.FormValue("verdict")]
50 if flag == "" {
51 s.mrRedirect(w, r, "pick approve, request changes, or comment")
52 return
53 }
54 _, msg, code := s.runControlCode(u, mrArgs(r, "review", flag))
55 s.done(w, r, code, msg, s.mrRedirect)
56}
57
58func (s *Server) mrReviewRequestSubmit(w http.ResponseWriter, r *http.Request, u store.User) {
59 args := append(fieldArgs("--add", r.FormValue("add")), fieldArgs("--remove", r.FormValue("remove"))...)
60 if len(args) == 0 {
61 s.mrRedirect(w, r, "name at least one person")
62 return
63 }
64 repo := r.PathValue("owner") + "/" + r.PathValue("repo")
65 _, msg, code := s.runControlCode(u, append([]string{"mr", "review", "request", repo, r.PathValue("n")}, args...))
66 s.done(w, r, code, msg, s.mrRedirect)
67}
68
69func (s *Server) mrLabelSubmit(w http.ResponseWriter, r *http.Request, u store.User) {
70 args := append(fieldArgs("--add", r.FormValue("add")), fieldArgs("--remove", r.FormValue("remove"))...)
71 if len(args) == 0 {
72 s.mrRedirect(w, r, "name at least one label")
73 return
74 }
75 _, msg, code := s.runControlCode(u, mrArgs(r, "label", args...))
76 s.done(w, r, code, msg, s.mrRedirect)
77}
78
79func (s *Server) mrMergeSubmit(w http.ResponseWriter, r *http.Request, u store.User) {
80 args := []string{}
81 if st := strings.TrimSpace(r.FormValue("strategy")); st != "" && st != "auto" {
82 args = append(args, "--strategy", st)
83 }
84 _, msg, code := s.runControlCode(u, mrArgs(r, "merge", args...))
85 s.done(w, r, code, msg, s.mrRedirect)
86}
87
88func (s *Server) mrCloseSubmit(w http.ResponseWriter, r *http.Request, u store.User) {
89 args := []string{}
90 if by := strings.TrimPrefix(strings.TrimSpace(r.FormValue("by")), "!"); by != "" {
91 if _, err := strconv.ParseInt(by, 10, 64); err != nil {
92 s.mrRedirect(w, r, "the superseding request is a number")
93 return
94 }
95 args = append(args, "--by", by)
96 }
97 _, msg, code := s.runControlCode(u, mrArgs(r, "close", args...))
98 s.done(w, r, code, msg, s.mrRedirect)
99}
100
101// mrDraftSubmit toggles the draft mark. The form says which way it is
102// going, so a stale page cannot flip the wrong one.
103func (s *Server) mrDraftSubmit(w http.ResponseWriter, r *http.Request, u store.User) {
104 verb := "ready"
105 if r.FormValue("draft") == "on" {
106 verb = "draft"
107 }
108 _, msg, code := s.runControlCode(u, mrArgs(r, verb))
109 s.done(w, r, code, msg, s.mrRedirect)
110}
111
112// mrDiffCommentSubmit opens a review thread on a diff line, or replies to
113// one. The body goes in on stdin: it is user prose, and argv is visible in
114// /proc.
115func (s *Server) mrDiffCommentSubmit(w http.ResponseWriter, r *http.Request, u store.User) {
116 body := strings.TrimSpace(r.FormValue("body"))
117 if body == "" {
118 s.mrDiffRedirect(w, r, "empty comment")
119 return
120 }
121 var extra []string
122 if reply := strings.TrimSpace(r.FormValue("reply")); reply != "" {
123 if _, err := strconv.ParseInt(reply, 10, 64); err != nil {
124 s.mrDiffRedirect(w, r, "bad thread id")
125 return
126 }
127 extra = []string{"--reply", reply}
128 } else {
129 path := strings.TrimSpace(r.FormValue("path"))
130 line := strings.TrimSpace(r.FormValue("line"))
131 if n, err := strconv.ParseInt(line, 10, 64); path == "" || err != nil || n < 1 {
132 s.mrDiffRedirect(w, r, "pick a line to comment on")
133 return
134 }
135 extra = []string{"--path", path, "--line", line}
136 if r.FormValue("side") == "old" {
137 extra = append(extra, "--old")
138 }
139 }
140 // "Add to review" holds the comment back until the verdict; "Comment"
141 // posts it now, which is what the form did before there was a choice.
142 if r.FormValue("pending") == "on" {
143 extra = append(extra, "--pending")
144 }
145 msg, code := s.runControlStdinCode(u, mrArgs(r, "diff-comment", append(extra, "--file", "-")...), body)
146 s.done(w, r, code, msg, s.mrDiffRedirect)
147}
148
149// mrRetargetSubmit moves the merge request onto another branch.
150func (s *Server) mrRetargetSubmit(w http.ResponseWriter, r *http.Request, u store.User) {
151 target := strings.TrimSpace(r.FormValue("target"))
152 if target == "" {
153 s.mrRedirect(w, r, "pick a branch to retarget onto")
154 return
155 }
156 _, msg, code := s.runControlCode(u, mrArgs(r, "retarget", target))
157 s.done(w, r, code, msg, s.mrRedirect)
158}
159
160// mrThreadSubmit resolves or reopens one review thread.
161func (s *Server) mrThreadSubmit(w http.ResponseWriter, r *http.Request, u store.User) {
162 verb := "resolve"
163 if r.FormValue("action") == "unresolve" {
164 verb = "unresolve"
165 }
166 id := strings.TrimSpace(r.FormValue("thread"))
167 if _, err := strconv.ParseInt(id, 10, 64); err != nil {
168 s.mrRedirect(w, r, "bad thread id")
169 return
170 }
171 _, msg, code := s.runControlCode(u, mrArgs(r, verb, id))
172 s.done(w, r, code, msg, s.mrRedirect)
173}
174
175// mrNewPage is the create form: branches to choose from, plus whatever
176// the last attempt had in it so a refusal does not lose the draft.
177type mrNewPage struct {
178 repoPage
179 Branches []gitutil.Ref
180 Sources []string
181 Source string
182 Target string
183 Title string
184 Body string
185 Format string
186 Notice string
187 Draft *draft
188}
189
190// mrSources lists the branches a merge request may be opened from, in the
191// form the command takes: this repository's branches by name, and those of
192// any fork of it the viewer can push to as "owner/name:branch".
193// Write is the filter because a contributor proposes from a fork they
194// own; the command still checks the source for itself (#168).
195func (s *Server) mrSources(u store.User, p repoPage) []string {
196 var out []string
197 branches, _ := gitutil.Refs(p.Dir, "heads")
198 for _, b := range branches {
199 out = append(out, b.Name)
200 }
201 if u.ID == 0 {
202 return out
203 }
204 forks, _ := s.st.ListForks(p.Repo.ID)
205 for _, f := range forks {
206 grant, _ := s.st.AccessRole(f.ID, u.ID)
207 if !policy.CanWrite(u, f, grant) {
208 continue
209 }
210 dir := control.RepoDir(s.cfg.Server.Root, f.OwnerName, f.Name)
211 refs, _ := gitutil.Refs(dir, "heads")
212 for _, b := range refs {
213 out = append(out, f.Path()+":"+b.Name)
214 }
215 }
216 return out
217}
218
219func (s *Server) mrCreateForm(w http.ResponseWriter, r *http.Request, u store.User) {
220 p, ok := s.repoFor(w, r, "")
221 if !ok {
222 return
223 }
224 p.Tab = "merge requests"
225 branches, _ := gitutil.Refs(p.Dir, "heads")
226 q := r.URL.Query()
227 target := q.Get("target")
228 if target == "" {
229 target = p.Repo.DefaultBranch
230 }
231 format := q.Get("format")
232 if format != "org" {
233 format = "md"
234 }
235 s.render(w, "mrnew.html", mrNewPage{
236 repoPage: p, Branches: branches, Sources: s.mrSources(u, p),
237 Source: q.Get("source"), Target: target,
238 Title: q.Get("title"), Body: q.Get("body"), Format: format, Notice: s.takeFlash(w, r),
239 })
240}
241
242func (s *Server) mrCreateSubmit(w http.ResponseWriter, r *http.Request, u store.User) {
243 p, ok := s.repoFor(w, r, "")
244 if !ok {
245 return
246 }
247 source := strings.TrimSpace(r.FormValue("source"))
248 target := strings.TrimSpace(r.FormValue("target"))
249 title := strings.TrimSpace(r.FormValue("title"))
250 body := strings.TrimSpace(r.FormValue("body"))
251 format := bodyFormat(r)
252
253 // Preview: the same page back with the draft intact, nothing opened.
254 if wantsPreview(r) {
255 p.Tab = "merge requests"
256 branches, _ := gitutil.Refs(p.Dir, "heads")
257 s.render(w, "mrnew.html", mrNewPage{
258 repoPage: p, Branches: branches, Sources: s.mrSources(u, p),
259 Source: source, Target: target, Title: title, Body: body, Format: format,
260 Draft: s.draftFor(r, p.Repo, "body", "body", format),
261 })
262 return
263 }
264
265 back := func(msg string) {
266 q := url.Values{"source": {source}, "target": {target}, "title": {title}, "body": {body}, "format": {format}}
267 s.setFlash(w, msg)
268 http.Redirect(w, r, fmt.Sprintf("/%s/mrs/new?%s", p.Repo.Path(), q.Encode()), http.StatusSeeOther)
269 }
270 if source == "" || title == "" {
271 back("pick a source branch and give the merge request a title")
272 return
273 }
274 argv := []string{"mr", "create", p.Repo.Path(), "--source", source, "--title", title, "--format", format}
275 if target != "" {
276 argv = append(argv, "--target", target)
277 }
278 if body != "" {
279 argv = append(argv, "--body", body)
280 }
281 var created control.MRCreated
282 if msg, ok := s.runControlInto(u, argv, &created); !ok {
283 back(msg)
284 return
285 }
286 http.Redirect(w, r, fmt.Sprintf("/%s/mrs/%d", p.Repo.Path(), created.Number), http.StatusSeeOther)
287}