## OpenCA - Command
## (c) 1998-2001 by Massimiliano Pala and OpenCA Group
##
##   File Name: search
##       Brief: Search Items
## Description: Search Items ad list results found
##  Parameters: dataType, viewFrom, rows

sub cmdSearch {

## Reserved variables
my ( $page, $certData, $sheet );

## We need some parameters to generate the list because of
## we do not want to generate a list of ALL issued certificates
## so get the numer of results we should give away, then the
## starting serial number.
my $from     = $query->param( 'viewFrom' );
my $matched  = $query->param( 'rows'     );
my $dataType = $query->param( 'dataType' );
my $parName  = $query->param( 'name'     );
my $parVal   = $query->param( 'value'    );
my $pcounter = $query->param( 'pcounter' );
my $server   = getRequired ( 'CgiServerType' );

## Get required parameters ( return only the value string )
my $sheet    = getRequired( 'baseSearchlist' );
my $maxItems = getRequired( 'MaxReturnedItems' );
my $uptime   = $tools->getDate();

my $f1    = "<FONT COLOR=\"#EF7000\">";
my $f2    = "<FONT SIZE=+0 COLOR=\"#CCCCDD\">";
my $f3    = "<FONT COLOR=\"#FFFFFF\">";
my $ef    = "</FONT>";

my $title = gettext ("<FONT COLOR=#EF7000>S</FONT>earch <FONT COLOR=#EF7000>R</FONT>esults</FONT>")."<BR>";

generalError (gettext ("Permission denied! It is not allowed to search for other objects than certificates on this server."))
    if ($dataType !~ /CERTIFICATE/ and $server !~ /^(RA|CA|LDAP)$/);

if( $dataType =~ /CERTIFICATE/ ) {
   $title .= "${f2}".gettext ("Certificates Search")."${ef}";
} elsif ( $dataType =~ /REQUEST/ ) {
   $title .= "${f2}".gettext ("Requests Search")."${ef}";
} elsif ( $dataType =~ /REQUEST/ ) {
   $title .= "${f2}".gettext ("Certificate Revocation Requests Search")."${ef}";
} else {
   $title .= "${f2}".gettext ("Unknown Search")."${ef}";
}   

my @cols;

## Get the base Page ( got in $page variable )
if( not $page = $query->getFile( "$sheet" ) ) {
	configError ( i18nGettext ("File not Found : __SHEET__", "__SHEET__", $sheet) );
};

if( $dataType =~ /CERTIFICATE/ ) {
	push( @cols, gettext("Serial"), gettext("Common Name"), gettext("Email") );
} elsif ( $dataType =~ /REQUEST/ ) {
	push( @cols, gettext("Serial"), gettext("Common Name"), gettext("Email") );
} elsif ( $dataType =~ /CRR/ ) {
	push( @cols, gettext("Serial"), gettext("Common Name"), gettext("Email") );
} else {
	configError( i18nGettext("Datatype __DATATYPE__ not supported!", "__DATATYPE__", $dataType) );
}

if (not $pcounter)
{
    $parVal =~ s/([^\\])\*/${1}%/g;
    $parVal =~ s/^\*/%/;
    @itemsList = $db->searchItems( DATATYPE => $dataType, 
                                   $parName => $parVal );
} else {
    my %para;
    $para{DATATYPE} = $dataType;
    ## 10 is for DoS-defence
    for (my $i=1; $i<=$pcounter and $i <= 10; $i++)
    {
        my $h = $query->param ("value_$i");
        $h =~ s/([^\\])\*/${1}%/g;
        $h =~ s/^\*/%/;
        $para{$query->param ("name_$i")} = $h;
    }
    @itemsList = $db->searchItems (%para);
}

generalError (gettext ("The search in the database failed.").
              "<br>".$db->errval(),
              $db->errno())
    if ($db->errno());

if ( not $matched ) { $matched  = $#itemsList; };

$table  = $query->buildRefs( ELEMENTS=>$matched, MAXITEMS=>$maxItems  );
$table .= $query->startTable( 	COLS=>[ @cols ],
				WIDTH=>"100%",
				TITLE_BGCOLOR=>"#DDCCFF" );

## Process all Files
foreach $item ( @itemsList ) {
	my ( $lnk, $cmd, $key, $mySer, $myCN, $myEmail, $serCol );

	$key     = $item->getSerial();

	$mySer   = ( $item->getSerial() or "<CENTER>".gettext("n/a")."</CENTER>");
	$myCN    = ( $item->getParsed()->{DN_HASH}->{CN}[0] or "<CENTER>".gettext("n/a")."</CENTER>" );
	$myEmail = ( $item->getParsed()->{EMAILADDRESS} or "<CENTER>".gettext("n/a")."</CENTER>" );

	if( $dataType =~ /CERTIFICATE/ ) {
		$cmd = "viewCert";
	} elsif ( $dataType =~ /REQUEST/ ) {
		$cmd = "viewCSR";
	} elsif ( $dataType =~ /CRR/ ) {
		$cmd = "viewCRR";
	} else {
		$cmd = "$dataType";
	}

	$lnk = new CGI({ cmd=>"$cmd", dataType=>$dataType, key=>$key });
	$serCol = $lnk->a( {-href=>$lnk->self_url()}, "$mySer" );
	$table .= $query->addTableLine( DATA =>[ $serCol, $myCN, $myEmail ]);
}

## Close the Table
$table .= $query->endTable();
$table .= getCopyRight();

## Substitute the Variables in the $page
$page = $query->subVar( $page, '@UPTIME@', $uptime );
$page = $query->subVar( $page, '@TABLE@', $table );
$page = $query->subVar( $page, '@TITLE@', $title );

print "$page";

}

1;

