xref: /webtrees/app/Http/RequestHandlers/ContactAction.php (revision 9f9acdbc09170c04c1e150c36ee57d49027e314a)
1<?php
2
3/**
4 * webtrees: online genealogy
5 * Copyright (C) 2019 webtrees development team
6 * This program is free software: you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation, either version 3 of the License, or
9 * (at your option) any later version.
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program. If not, see <http://www.gnu.org/licenses/>.
16 */
17
18declare(strict_types=1);
19
20namespace Fisharebest\Webtrees\Http\RequestHandlers;
21
22use Fisharebest\Webtrees\Exceptions\HttpAccessDeniedException;
23use Fisharebest\Webtrees\Exceptions\HttpNotFoundException;
24use Fisharebest\Webtrees\FlashMessages;
25use Fisharebest\Webtrees\GuestUser;
26use Fisharebest\Webtrees\Http\ViewResponseTrait;
27use Fisharebest\Webtrees\I18N;
28use Fisharebest\Webtrees\Services\CaptchaService;
29use Fisharebest\Webtrees\Services\EmailService;
30use Fisharebest\Webtrees\Services\MessageService;
31use Fisharebest\Webtrees\Services\UserService;
32use Fisharebest\Webtrees\Tree;
33use Psr\Http\Message\ResponseInterface;
34use Psr\Http\Message\ServerRequestInterface;
35use Psr\Http\Server\RequestHandlerInterface;
36
37use function assert;
38use function e;
39use function in_array;
40use function preg_match;
41use function preg_quote;
42use function redirect;
43use function route;
44
45/**
46 * Send a message from a visitor.
47 */
48class ContactAction implements RequestHandlerInterface
49{
50    use ViewResponseTrait;
51
52    /** @var CaptchaService */
53    private $captcha_service;
54
55    /** @var EmailService */
56    private $email_service;
57
58    /** @var MessageService */
59    private $message_service;
60
61    /** @var UserService */
62    private $user_service;
63
64    /**
65     * MessagePage constructor.
66     *
67     * @param CaptchaService $captcha_service
68     * @param EmailService   $email_service
69     * @param MessageService $message_service
70     * @param UserService    $user_service
71     */
72    public function __construct(
73        CaptchaService $captcha_service,
74        EmailService $email_service,
75        MessageService $message_service,
76        UserService $user_service
77    ) {
78        $this->captcha_service = $captcha_service;
79        $this->email_service   = $email_service;
80        $this->user_service    = $user_service;
81        $this->message_service = $message_service;
82    }
83
84    /**
85     * @param ServerRequestInterface $request
86     *
87     * @return ResponseInterface
88     */
89    public function handle(ServerRequestInterface $request): ResponseInterface
90    {
91        $tree = $request->getAttribute('tree');
92        assert($tree instanceof Tree);
93
94        $params     = (array) $request->getParsedBody();
95        $body       = $params['body'];
96        $from_email = $params['from_email'];
97        $from_name  = $params['from_name'];
98        $subject    = $params['subject'];
99        $to         = $params['to'];
100        $url        = $params['url'];
101        $ip         = $request->getAttribute('client-ip');
102        $to_user    = $this->user_service->findByUserName($to);
103
104        if ($to_user === null) {
105            throw new HttpNotFoundException();
106        }
107
108        if (!in_array($to_user, $this->message_service->validContacts($tree), false)) {
109            throw new HttpAccessDeniedException('Invalid contact user id');
110        }
111
112        $errors = $body === '' || $subject === '' || $from_email === '' || $from_name === '';
113
114        if ($this->captcha_service->isRobot($request)) {
115            FlashMessages::addMessage(I18N::translate('Please try again.'), 'danger');
116            $errors = true;
117        }
118
119        if (!$this->email_service->isValidEmail($from_email)) {
120            FlashMessages::addMessage(I18N::translate('Please enter a valid email address.'), 'danger');
121            $errors = true;
122        }
123
124        $base_url = $request->getAttribute('base_url');
125
126        if (preg_match('/(?!' . preg_quote($base_url, '/') . ')(((?:ftp|http|https):\/\/)[a-zA-Z0-9.-]+)/', $subject . $body, $match)) {
127            FlashMessages::addMessage(I18N::translate('You are not allowed to send messages that contain external links.') . ' ' . /* I18N: e.g. ‘You should delete the “http://” from “http://www.example.com” and try again.’ */
128                I18N::translate('You should delete the “%1$s” from “%2$s” and try again.', $match[2], $match[1]), 'danger');
129            $errors = true;
130        }
131
132        if ($errors) {
133            return redirect(route(ContactPage::class, [
134                'body'       => $body,
135                'from_email' => $from_email,
136                'from_name'  => $from_name,
137                'subject'    => $subject,
138                'to'         => $to,
139                'tree'       => $tree->name(),
140                'url'        => $url,
141            ]));
142        }
143
144        $sender = new GuestUser($from_email, $from_name);
145
146        if ($this->message_service->deliverMessage($sender, $to_user, $subject, $body, $url, $ip)) {
147            FlashMessages::addMessage(I18N::translate('The message was successfully sent to %s.', e($to_user->realName())), 'success');
148
149            $url = $url ?: route(TreePage::class, ['tree' => $tree->name()]);
150
151            return redirect($url);
152        }
153
154        FlashMessages::addMessage(I18N::translate('The message was not sent.'), 'danger');
155
156        $redirect_url = route(ContactPage::class, [
157            'body'       => $body,
158            'from_email' => $from_email,
159            'from_name'  => $from_name,
160            'subject'    => $subject,
161            'to'         => $to,
162            'tree'       => $tree->name(),
163            'url'        => $url,
164        ]);
165
166        return redirect($redirect_url);
167    }
168}
169