X-Git-Url: https://git.auder.net/?a=blobdiff_plain;f=routes%2Fall.js;h=b2318135823d4d5a5b0956e76ab926003aa53410;hb=9a3c9f790aa28fd4708faefe41b4624173922c8e;hp=f3e184e608133d267c374f6b4c0360c1c8531690;hpb=da06a6eb0237123ce43fdb01cb06246b8b57f5e5;p=vchess.git diff --git a/routes/all.js b/routes/all.js index f3e184e6..b2318135 100644 --- a/routes/all.js +++ b/routes/all.js @@ -5,6 +5,33 @@ const sqlite3 = require('sqlite3');//.verbose(); const db = new sqlite3.Database('db/vchess.sqlite'); const sanitizeHtml = require('sanitize-html'); +const supportedLang = ["fr","en"]; +function selectLanguage(req, res) +{ + // If preferred language already set: + if (!!req.cookies["lang"]) + return req.cookies["lang"]; + + // Else: search and set it + const langString = req.headers["accept-language"]; + let langArray = langString + .replace(/;q=[0-9.]+/g, "") //priority + .replace(/-[A-Z]+/g, "") //region (skipped for now...) + .split(",") //may have some duplicates, but removal is too costly + let bestLang = "en"; //default: English + for (let lang of langArray) + { + if (supportedLang.includes(lang)) + { + bestLang = lang; + break; + } + } + // Cookie expires in 183 days (expressed in milliseconds) + res.cookie('lang', bestLang, { maxAge: 183*24*3600*1000 }); + return bestLang; +} + // Home router.get('/', function(req, res, next) { db.serialize(function() { @@ -13,7 +40,9 @@ router.get('/', function(req, res, next) { return next(err); res.render('index', { title: 'club', - variantArray: variants, //JSON.stringify(variants) + variantArray: variants, + lang: selectLanguage(req, res), + languages: supportedLang, }); }); }); @@ -28,6 +57,7 @@ router.get("/:vname([a-zA-Z0-9]+)", (req,res,next) => { return next(err); if (!variant || variant.length==0) return next(createError(404)); + // TODO (later...) get only n=100(?) most recent problems db.all("SELECT * FROM Problems WHERE variant='" + vname + "'", (err2,problems) => { if (!!err2) @@ -47,7 +77,8 @@ router.get("/:vname([a-zA-Z0-9]+)", (req,res,next) => { router.get("/rules/:variant([a-zA-Z0-9]+)", (req,res) => { if (!req.xhr) return res.json({errmsg: "Unauthorized access"}); - res.render("rules/" + req.params["variant"]); + const lang = selectLanguage(req, res); + res.render("rules/" + req.params["variant"] + "/" + lang); }); // Fetch 10 previous or next problems (AJAX) @@ -55,6 +86,9 @@ router.get("/problems/:variant([a-zA-Z0-9]+)", (req,res) => { if (!req.xhr) return res.json({errmsg: "Unauthorized access"}); // TODO: next or previous: in params + timedate (of current oldest or newest) + db.serialize(function() { + //TODO + }); }); // Upload a problem (AJAX) @@ -62,17 +96,20 @@ router.post("/problems/:variant([a-zA-Z0-9]+)", (req,res) => { if (!req.xhr) return res.json({errmsg: "Unauthorized access"}); const vname = req.params["variant"]; - - // TODO: get parameters and sanitize them - sanitizeHtml(req.body["fen"]); // [/a-z0-9 ]* - sanitizeHtml(req.body["instructions"]); + const timestamp = Date.now(); + // Sanitize them + const fen = req.body["fen"]; + if (!fen.match(/^[a-zA-Z0-9, /-]*$/)) + return res.json({errmsg: "Bad characters in FEN string"}); + const instructions = sanitizeHtml(req.body["instructions"]); + const solution = sanitizeHtml(req.body["solution"]); db.serialize(function() { - let stmt = db.prepare("INSERT INTO Problems VALUES (?,?,?,?,?)"); + let stmt = db.prepare("INSERT INTO Problems " + + "(added,variant,fen,instructions,solution) VALUES (?,?,?,?,?)"); stmt.run(timestamp, vname, fen, instructions, solution); stmt.finalize(); }); res.json({}); }); - module.exports = router;