Upgrade to 4.0.10.
[usit-rt.git] / share / html / REST / 1.0 / ticket / comment
CommitLineData
84fb5b46
MKG
1%# BEGIN BPS TAGGED BLOCK {{{
2%#
3%# COPYRIGHT:
4%#
403d7b0b 5%# This software is Copyright (c) 1996-2013 Best Practical Solutions, LLC
84fb5b46
MKG
6%# <sales@bestpractical.com>
7%#
8%# (Except where explicitly superseded by other copyright notices)
9%#
10%#
11%# LICENSE:
12%#
13%# This work is made available to you under the terms of Version 2 of
14%# the GNU General Public License. A copy of that license should have
15%# been provided with this software, but in any event can be snarfed
16%# from www.gnu.org.
17%#
18%# This work is distributed in the hope that it will be useful, but
19%# WITHOUT ANY WARRANTY; without even the implied warranty of
20%# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
21%# General Public License for more details.
22%#
23%# You should have received a copy of the GNU General Public License
24%# along with this program; if not, write to the Free Software
25%# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
26%# 02110-1301 or visit their web page on the internet at
27%# http://www.gnu.org/licenses/old-licenses/gpl-2.0.html.
28%#
29%#
30%# CONTRIBUTION SUBMISSION POLICY:
31%#
32%# (The following paragraph is not intended to limit the rights granted
33%# to you to modify and distribute this software under the terms of
34%# the GNU General Public License and is only of importance to you if
35%# you choose to contribute your changes and enhancements to the
36%# community by submitting them to Best Practical Solutions, LLC.)
37%#
38%# By intentionally submitting any modifications, corrections or
39%# derivatives to this work, or any other work intended for use with
40%# Request Tracker, to Best Practical Solutions, LLC, you confirm that
41%# you are the copyright holder for those contributions and you grant
42%# Best Practical Solutions, LLC a nonexclusive, worldwide, irrevocable,
43%# royalty-free, perpetual, license to use, copy, create derivative
44%# works based on those contributions, and sublicense and distribute
45%# those contributions and any derivatives thereof.
46%#
47%# END BPS TAGGED BLOCK }}}
48%# REST/1.0/ticket/comment
49%#
50<%ARGS>
51$content
52</%ARGS>
53<%INIT>
54use MIME::Entity;
55use LWP::MediaTypes;
56use RT::Interface::REST;
57use File::Temp qw(tempfile);
58
59my $ticket = RT::Ticket->new($session{CurrentUser});
60my $object = $r->path_info;
61my $status = "200 Ok";
62my $output;
63my $action;
64
65# http://.../REST/1.0/ticket/1/comment
66my ($c, $o, $k, $e) = @{ form_parse($content)->[0] };
67if ($e || !$o) {
68 if (!$o) {
69 $output = "Empty form submitted.\n";
70 }
71 else {
72 $c = "# Syntax error.";
73 $output = form_compose([[$c, $o, $k, $e]]);
74 }
75 $status = "400 Bad Request";
76 goto OUTPUT;
77}
78
79$object =~ s#^/##;
80$object ||= $k->{Ticket};
81unless ($object =~ /^\d+/) {
82 $output = "Invalid ticket id: `$object'.\n";
83 $status = "400 Bad Request";
84 goto OUTPUT;
85}
86if ($k->{Ticket} && $object ne $k->{Ticket}) {
87 $output = "The submitted form and URL specify different tickets.\n";
88 $status = "400 Bad Request";
89 goto OUTPUT;
90}
91
92($action = $k->{Action}) =~ s/^(.)(.*)$/\U$1\L$2\E/;
93unless ($action =~ /^(?:Comment|Correspond)$/) {
94 $output = "Invalid action: `$action'.\n";
95 $status = "400 Bad Request";
96 goto OUTPUT;
97}
98
99my $text = $k->{Text};
100my @atts = @{ vsplit($k->{Attachment}) };
101
102if (!$k->{Text} && @atts == 0) {
103 $status = "400 Bad Request";
104 $output = "Empty comment with no attachments submitted.\n";
105 goto OUTPUT;
106}
107
108my $cgi = $m->cgi_object;
403d7b0b
MKG
109my $ent = MIME::Entity->build(
110 Type => "multipart/mixed",
111 'X-RT-Interface' => 'REST',
112);
84fb5b46
MKG
113$ent->attach(Data => $k->{Text}) if $k->{Text};
114
115my $i = 1;
116foreach my $att (@atts) {
117 local $/=undef;
118 my $file = $att;
119 $file =~ s#^.*[\\/]##;
120
121 my $fh = $cgi->upload("attachment_$i");
122 if ($fh) {
123 my $buf;
124 my ($w, $tmp) = tempfile();
125 my $info = $cgi->uploadInfo();
126
127 while (sysread($fh, $buf, 8192)) {
128 syswrite($w, $buf);
129 }
130
131 $ent->attach(
132 Path => $tmp,
133 Type => $info->{'Content-Type'} || guess_media_type($tmp),
134 Filename => $file,
135 Disposition => "attachment"
136 );
137 }
138 else {
139 $status = "400 Bad Request";
140 $output = "No attachment for $att.\n";
141 goto OUTPUT;
142 }
143
144 $i++;
145}
146
147$ticket->Load($object);
148unless ($ticket->Id) {
149 $output = "Couldn't load ticket id: `$object'.\n";
150 $status = "404 Ticket not found";
151 goto OUTPUT;
152}
153unless ($ticket->CurrentUserHasRight('ModifyTicket') ||
154 ($action eq "Comment" &&
155 $ticket->CurrentUserHasRight("CommentOnTicket")) ||
156 ($action eq "Correspond" &&
157 $ticket->CurrentUserHasRight("ReplyToTicket")))
158{
159 $output = "You are not allowed to $action on ticket $object.\n";
160 $status = "403 Permission denied";
161 goto OUTPUT;
162}
163
164my $cc = join ", ", @{ vsplit($k->{Cc}) };
165my $bcc = join ", ", @{ vsplit($k->{Bcc}) };
166my ($n, $s) = $ticket->$action(MIMEObj => $ent,
167 CcMessageTo => $cc,
168 BccMessageTo => $bcc,
169 TimeTaken => $k->{TimeWorked} || 0);
170$output = $s;
171if ($k->{Status}) {
172 my ($status_n, $status_s) = $ticket->SetStatus($k->{'Status'} );
173 $output .= "\n".$status_s;
174}
175
176OUTPUT:
177</%INIT>
178RT/<% $RT::VERSION %> <% $status %>
179
180<% $output |n %>