From 8c8a7e7cb61df8d35b3634a77f7545b878fca29b Mon Sep 17 00:00:00 2001 From: Casey Peel Date: Tue, 26 Aug 2025 16:22:51 -0700 Subject: [PATCH 1/2] Remove the sitemap We're locking down the project pages which makes the sitemap no longer useful. --- SETUP/apache2.conf.example | 6 -- SETUP/ci/check_require_login.php | 1 - SETUP/tests/smoketests/pageload_smoketest.py | 1 - sitemap.php | 87 -------------------- 4 files changed, 95 deletions(-) delete mode 100644 sitemap.php diff --git a/SETUP/apache2.conf.example b/SETUP/apache2.conf.example index 73c8cc8b70..d0ad907e08 100644 --- a/SETUP/apache2.conf.example +++ b/SETUP/apache2.conf.example @@ -26,12 +26,6 @@ ErrorLog ${APACHE_LOG_DIR}/error.log - - # make the sitemap work with an .xml extension - RewriteEngine On - RewriteRule ^(.*)sitemap\.xml$ $1sitemap.php [R,L] - - # Possible values include: debug, info, notice, warn, error, crit, # alert, emerg. LogLevel warn diff --git a/SETUP/ci/check_require_login.php b/SETUP/ci/check_require_login.php index 725981e517..79659fad62 100755 --- a/SETUP/ci/check_require_login.php +++ b/SETUP/ci/check_require_login.php @@ -10,7 +10,6 @@ // Base website "index.php", "credits.php", - "sitemap.php", "project.php", "list_etexts.php", "locale/debug_ui_language.php", diff --git a/SETUP/tests/smoketests/pageload_smoketest.py b/SETUP/tests/smoketests/pageload_smoketest.py index 8668a9892e..984c5d684e 100755 --- a/SETUP/tests/smoketests/pageload_smoketest.py +++ b/SETUP/tests/smoketests/pageload_smoketest.py @@ -25,7 +25,6 @@ {'path': 'list_etexts.php?x=g'}, {'path': 'list_etexts.php?x=s'}, {'path': 'list_etexts.php?x=b'}, - {'path': 'sitemap.php'}, ] BASE_TESTS = [ diff --git a/sitemap.php b/sitemap.php deleted file mode 100644 index 2a634e0e6f..0000000000 --- a/sitemap.php +++ /dev/null @@ -1,87 +0,0 @@ - "monthly", -]; - -header('Content-type: application/xml; charset=utf-8'); - -// see https://en.wikipedia.org/wiki/Sitemaps#File_format -echo << - - - XML_HEADER; - -// sitemaps are limited to 50k URLs, so we need to keep track of how many -// we output and stop when we get to that number -$MAX_URLS = 50000; -$url_count = 0; - -foreach ($fixed_pages as $page => $frequency) { - if ($url_count >= $MAX_URLS) { - break; - } - - $url = "$code_url/$page"; - $lastmod = date("Y-m-d", filemtime("$code_dir/$page")); - echo << - $url - $lastmod - $frequency - 1.0 - - - URL; - $url_count += 1; -} - -// now project pages - -// Order the projects in the order they go through the system. This is only -// relevant if there are more than 50k of them, in which case we drop off -// projects on the tail end (deleted projects get dropped first, posted ones -// get dropped second, etc). -$order_by = sql_collator_for_project_state("state"); -$sql = " - SELECT projectid, modifieddate - FROM projects - ORDER BY $order_by -"; -$result = DPDatabase::query($sql); -while ($row = mysqli_fetch_assoc($result)) { - if ($url_count >= $MAX_URLS) { - break; - } - - // skip entries with no modifieddate - $modified_date = (int)$row["modifieddate"]; - if ($modified_date == 0) { - continue; - } - - $url = "$code_url/project.php?id=" . $row["projectid"]; - $lastmod = date("Y-m-d", $modified_date); - - echo << - $url - $lastmod - 0.5 - - - URL; - $url_count += 1; -} - -echo << - - XML_FOOTER; From 05277904673ea6729816cbeb10104c79d311062e Mon Sep 17 00:00:00 2001 From: Casey Peel Date: Tue, 26 Aug 2025 16:39:17 -0700 Subject: [PATCH 2/2] Require authentication to view project pages --- SETUP/ci/check_require_login.php | 1 - pinc/list_projects.inc | 4 +- project.php | 259 ++++++++++++++----------------- 3 files changed, 117 insertions(+), 147 deletions(-) diff --git a/SETUP/ci/check_require_login.php b/SETUP/ci/check_require_login.php index 79659fad62..b365d59192 100755 --- a/SETUP/ci/check_require_login.php +++ b/SETUP/ci/check_require_login.php @@ -10,7 +10,6 @@ // Base website "index.php", "credits.php", - "project.php", "list_etexts.php", "locale/debug_ui_language.php", // RSS feeds diff --git a/pinc/list_projects.inc b/pinc/list_projects.inc index 5a5c121d5b..3569646363 100644 --- a/pinc/list_projects.inc +++ b/pinc/list_projects.inc @@ -69,6 +69,8 @@ function list_projects(string $metal, string $order_clause, string $url_base, in $group_clause = ""; } + $is_user_logged_in = User::is_logged_in(); + // first get the number of projects, we cache this value for an hour // so it might be a bit out of sync with the full listing, but it means // we don't have to do this query twice @@ -163,7 +165,7 @@ function list_projects(string $metal, string $order_clause, string $url_base, in // Counter // Title echo ""; - if (is_null($postednum)) { + if ($is_user_logged_in && is_null($postednum)) { echo "" . html_safe($title) . ""; } else { echo html_safe($title); diff --git a/project.php b/project.php index fb1906047b..53cebd79e5 100644 --- a/project.php +++ b/project.php @@ -21,7 +21,9 @@ include_once($relPath.'daily_page_limit.inc'); // get_dpl_count_for_user_in_round include_once($relPath.'special_colors.inc'); // load_special_days -// If the requestor is not logged in, we refer to them as a "guest". +// This page originally allowed unauthenticated users and showed them a limited +// set of information but now we require users to be authenticated. +require_login(); // XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX @@ -49,7 +51,7 @@ $title = $project->nameofwork; -if (User::is_logged_in() && $mark_bookmark !== null) { +if ($mark_bookmark !== null) { upi_set_bookmark($pguser, $project->projectid, $mark_bookmark); } @@ -86,24 +88,12 @@ maybe_output_new_proofer_project_message($project); -if (!User::is_logged_in()) { - // Guests see a reduced version of the project page. - - [$top_blurb, $bottom_blurb] = decide_blurbs(); - do_blurb_box($top_blurb); - do_project_info_table(); - do_blurb_box($bottom_blurb); - - echo "
\n"; - return; -} else { - upi_set_t_latest_home_visit( - $pguser, - $project->projectid, - time(), - $project->PPer_is_current_user or $project->PPVer_is_current_user - ); -} +upi_set_t_latest_home_visit( + $pguser, + $project->projectid, + time(), + $project->PPer_is_current_user or $project->PPVer_is_current_user +); if ($detail_level == 1) { do_expected_state(); @@ -483,21 +473,18 @@ function do_project_info_table(): void echo_row_a(_("Image Source"), $project->image_source_name, true); } - // We choose not to show guests anything involving users' names. - if (User::is_logged_in()) { - echo_row_a(_("Project Manager"), $project->username, true); + echo_row_a(_("Project Manager"), $project->username, true); - if ($project->PPer) { - echo_row_a(_("Post Processor"), $project->PPer, true); - } - - if ($project->PPVer) { - echo_row_a(_("PP Verifier"), $project->PPVer, true); - } + if ($project->PPer) { + echo_row_a(_("Post Processor"), $project->PPer, true); + } - echo_row_a(_("Credits line so far"), $project->credits_line, true); + if ($project->PPVer) { + echo_row_a(_("PP Verifier"), $project->PPVer, true); } + echo_row_a(_("Credits line so far"), $project->credits_line, true); + // ------------------------------------------------------------------------- // Current activity @@ -529,37 +516,34 @@ function do_project_info_table(): void // ------------------------------------------------------------------------- - // We choose not to show guests the word lists. - if (User::is_logged_in()) { - $good_bad = [ - 'good' => _("Good Words"), - 'bad' => _("Bad Words"), - ]; + $good_bad = [ + 'good' => _("Good Words"), + 'bad' => _("Bad Words"), + ]; - $links = ''; - foreach ($good_bad as $gb => $label) { - $f = get_project_word_file($projectid, $gb); - if ($f->size > 0) { - $links .= new_window_link($f->abs_url, $label); - $links .= " - " . _("Last modified") . ": " . icu_date_template("long+time", $f->mod_time); - } else { - $links .= $label . " " . _("(empty)"); - } - $links .= "
"; + $links = ''; + foreach ($good_bad as $gb => $label) { + $f = get_project_word_file($projectid, $gb); + if ($f->size > 0) { + $links .= new_window_link($f->abs_url, $label); + $links .= " - " . _("Last modified") . ": " . icu_date_template("long+time", $f->mod_time); + } else { + $links .= $label . " " . _("(empty)"); } + $links .= "
"; + } - echo_row_a(_("Word Lists"), $links); + echo_row_a(_("Word Lists"), $links); - if ($project->pages_table_exists && !$project->is_utf8) { - echo_row_a(_("Encoding"), "" . _("Project table is not UTF-8.") . ""); - } + if ($project->pages_table_exists && !$project->is_utf8) { + echo_row_a(_("Encoding"), "" . _("Project table is not UTF-8.") . ""); + } - $project_charsuites = []; - foreach ($project->get_charsuites() as $charsuite) { - $project_charsuites[] = "" . html_safe($charsuite->title) . ""; - } - echo_row_a(_("Character Suites"), implode(", ", $project_charsuites)); + $project_charsuites = []; + foreach ($project->get_charsuites() as $charsuite) { + $project_charsuites[] = "" . html_safe($charsuite->title) . ""; } + echo_row_a(_("Character Suites"), implode(", ", $project_charsuites)); // ------------------------------------------------------------------------- @@ -586,84 +570,73 @@ function do_project_info_table(): void echo_row_a(_("Last Forum Post"), $last_post_date, true); } - // If the topic is only visible to logged-in users, - // there's little point showing guests the link to it. - if (User::is_logged_in()) { - if (($state == PROJ_DELETE) && ($topic_id == "")) { - echo_row_a(_("Forum"), _("The project has been deleted, and no discussion exists."), true); + if (($state == PROJ_DELETE) && ($topic_id == "")) { + echo_row_a(_("Forum"), _("The project has been deleted, and no discussion exists."), true); + } else { + if ($topic_id == "") { + $blurb = html_safe(_("Start a discussion about this project")); + $url = "$code_url/tools/proofers/project_topic.php?project=$projectid"; + echo_row_a(_("Forum"), "$blurb"); } else { - if ($topic_id == "") { - $blurb = html_safe(_("Start a discussion about this project")); - $url = "$code_url/tools/proofers/project_topic.php?project=$projectid"; - echo_row_a(_("Forum"), "$blurb"); + $details = get_topic_details($topic_id); + if ($details) { + $replies = sprintf(_("(%d replies)"), $details['num_replies']); } else { - $details = get_topic_details($topic_id); - if ($details) { - $replies = sprintf(_("(%d replies)"), $details['num_replies']); - } else { - $replies = ''; - } - $blurb = html_safe(_("Discuss this project")); - $url = get_url_to_view_topic($topic_id); - echo_row_a(_("Forum"), "$blurb $replies"); + $replies = ''; } + $blurb = html_safe(_("Discuss this project")); + $url = get_url_to_view_topic($topic_id); + echo_row_a(_("Forum"), "$blurb $replies"); } } // ------------------------------------------------------------------------- - // For now, we say that guests can't see page details or page browser - if (User::is_logged_in()) { - - if ($detail_level >= 4) { - // We'll call do_page_table later, so we don't need the "Page Detail" link. - } else { - $detail = ""; - if ($project->pages_table_exists) { - $url = "$code_url/tools/project_manager/page_detail.php?project=$projectid&show_image_size=0"; - $blurb = html_safe(_("Images, Pages Proofread, & Differences")); - $url2 = "$url&select_by_user"; - $blurb2 = html_safe(_("Just my pages")); - $detail = "$blurb ($blurb2)"; - if ($project->has_entered_formatting_round()) { - $url3 = "$code_url/tools/project_manager/page_compare.php?project=$projectid"; - $blurb3 = html_safe(_("Compare without formatting")); - $detail .= "
$blurb3"; - } - } else { - $detail = $project->pages_table_missing_reason(); + if ($detail_level >= 4) { + // We'll call do_page_table later, so we don't need the "Page Detail" link. + } else { + $detail = ""; + if ($project->pages_table_exists) { + $url = "$code_url/tools/project_manager/page_detail.php?project=$projectid&show_image_size=0"; + $blurb = html_safe(_("Images, Pages Proofread, & Differences")); + $url2 = "$url&select_by_user"; + $blurb2 = html_safe(_("Just my pages")); + $detail = "$blurb ($blurb2)"; + if ($project->has_entered_formatting_round()) { + $url3 = "$code_url/tools/project_manager/page_compare.php?project=$projectid"; + $blurb3 = html_safe(_("Compare without formatting")); + $detail .= "
$blurb3"; } - echo_row_a(_("Page Detail"), $detail); + } else { + $detail = $project->pages_table_missing_reason(); } + echo_row_a(_("Page Detail"), $detail); + } + + if ($detail_level >= 3 && $project->pages_table_exists) { + $pages = $project->get_page_names_from_db(); + $imageparam = $pages ? ("&imagefile=" . $pages[0]) : ""; + // get the first page image + $url = "$code_url/tools/page_browser.php?project=$projectid$imageparam"; + $images_url = "$url&mode=image"; + $text_url = "$url&mode=text"; + $both_url = "$url&mode=imageText"; + $blurb = sprintf( + _("Browse page: images · texts · both"), + $images_url, + $text_url, + $both_url + ); - if ($detail_level >= 3 && $project->pages_table_exists) { - $pages = $project->get_page_names_from_db(); - $imageparam = $pages ? ("&imagefile=" . $pages[0]) : ""; - // get the first page image - $url = "$code_url/tools/page_browser.php?project=$projectid$imageparam"; - $images_url = "$url&mode=image"; - $text_url = "$url&mode=text"; - $both_url = "$url&mode=imageText"; - $blurb = sprintf( - _("Browse page: images · texts · both"), - $images_url, - $text_url, - $both_url - ); - - echo_row_a(_("Page Browser"), $blurb); - } + echo_row_a(_("Page Browser"), $blurb); } // ------------------------------------------------------------------------- // Personal data with respect to this project - // If you're not logged in, we certainly can't show your personal data. - if (User::is_logged_in()) { - if ($round && $detail_level > 1) { - recentlyproofed(0); - recentlyproofed(1); - } + if ($round && $detail_level > 1) { + recentlyproofed(0); + recentlyproofed(1); } // ------------------------------------------------------------------------- @@ -672,7 +645,7 @@ function do_project_info_table(): void $postcomments = get_formatted_postcomments($project->projectid); - if (User::is_logged_in() && $postcomments != '') { + if ($postcomments != '') { if ($available_for_SR) { $class = 'sr-instructions'; echo_row_b(_("Instructions for Smooth Reading"), '', $class); @@ -696,39 +669,35 @@ function do_project_info_table(): void // -------- - // For now, we suppress Project Comments for guests. - // (They might be confused by the instructions for proofreaders.) - if (User::is_logged_in()) { - $comments = $project->comments; + $comments = $project->comments; - // insert e.g. templates and biographies - $comments = parse_project_comments($project); + // insert e.g. templates and biographies + $comments = parse_project_comments($project); - if ($comments == '') { - // Put in *something*, otherwise it'll probably look odd. - $comments = ' '; - } + if ($comments == '') { + // Put in *something*, otherwise it'll probably look odd. + $comments = ' '; + } - if ($round) { - $a = sprintf( - _("The Guidelines give detailed instructions for working in this round."), - get_faq_url($round->document) - ); - $b = _('The instructions below are particular to this project, and take precedence over those guidelines.'); + if ($round) { + $a = sprintf( + _("The Guidelines give detailed instructions for working in this round."), + get_faq_url($round->document) + ); + $b = _('The instructions below are particular to this project, and take precedence over those guidelines.'); - $time_str = icu_date_template("long+time", $project->t_last_change_comments); - $c = "(" . _("Last modified") . ": " . $time_str . ")"; + $time_str = icu_date_template("long+time", $project->t_last_change_comments); + $c = "(" . _("Last modified") . ": " . $time_str . ")"; - $comments_blurb = "$a
$b
$c"; - } else { - $comments_blurb = ""; - } + $comments_blurb = "$a
$b
$c"; + } else { + $comments_blurb = ""; + } - $class = 'project-comments'; - echo_row_b("" . _("Project Comments") . "", $comments_blurb, $class); + $class = 'project-comments'; + echo_row_b("" . _("Project Comments") . "", $comments_blurb, $class); - echo_row_c($comments); - } + echo_row_c($comments); // -------------------------------------------------------------------------