+ if params[:trace]
+ logger.info(params[:trace][:gpx_file].class.name)
+
+ if params[:trace][:gpx_file].respond_to?(:read)
+ begin
+ do_create(params[:trace][:gpx_file], params[:trace][:tagstring],
+ params[:trace][:description], params[:trace][:visibility])
+ rescue => ex
+ logger.debug ex
+ end
+
+ if @trace.id
+ flash[:notice] = t "trace.create.trace_uploaded"
+
+ if @user.traces.where(:inserted => false).count > 4
+ flash[:warning] = t "trace.trace_header.traces_waiting", :count => @user.traces.where(:inserted => false).count
+ end
+
+ redirect_to :action => :list, :display_name => @user.display_name
+ end
+ else
+ @trace = Trace.new(:name => "Dummy",
+ :tagstring => params[:trace][:tagstring],
+ :description => params[:trace][:description],
+ :visibility => params[:trace][:visibility],
+ :inserted => false, :user => @user,
+ :timestamp => Time.now.getutc)
+ @trace.valid?
+ @trace.errors.add(:gpx_file, "can't be blank")
+ end
+ else
+ @trace = Trace.new(:visibility => default_visibility)
+ end
+
+ @title = t "trace.create.upload_trace"
+ end
+
+ def data
+ trace = Trace.find(params[:id])
+
+ if trace.visible? && (trace.public? || (@user && @user == trace.user))
+ if Acl.no_trace_download(request.remote_ip)
+ render :text => "", :status => :forbidden
+ elsif request.format == Mime::XML
+ send_file(trace.xml_file, :filename => "#{trace.id}.xml", :type => request.format.to_s, :disposition => "attachment")
+ elsif request.format == Mime::GPX
+ send_file(trace.xml_file, :filename => "#{trace.id}.gpx", :type => request.format.to_s, :disposition => "attachment")
+ else
+ send_file(trace.trace_name, :filename => "#{trace.id}#{trace.extension_name}", :type => trace.mime_type, :disposition => "attachment")
+ end
+ else
+ render :text => "", :status => :not_found
+ end
+ rescue ActiveRecord::RecordNotFound
+ render :text => "", :status => :not_found
+ end
+
+ def edit
+ @trace = Trace.find(params[:id])
+
+ if !@trace.visible?
+ render :text => "", :status => :not_found
+ elsif @user.nil? || @trace.user != @user
+ render :text => "", :status => :forbidden
+ else
+ @title = t "trace.edit.title", :name => @trace.name
+
+ if params[:trace]
+ @trace.description = params[:trace][:description]
+ @trace.tagstring = params[:trace][:tagstring]
+ @trace.visibility = params[:trace][:visibility]
+ if @trace.save
+ redirect_to :action => "view", :display_name => @user.display_name
+ end
+ end
+ end
+ rescue ActiveRecord::RecordNotFound
+ render :text => "", :status => :not_found
+ end
+
+ def delete
+ trace = Trace.find(params[:id])
+
+ if !trace.visible?
+ render :text => "", :status => :not_found
+ elsif @user.nil? || trace.user != @user
+ render :text => "", :status => :forbidden
+ else
+ trace.visible = false
+ trace.save
+ flash[:notice] = t "trace.delete.scheduled_for_deletion"
+ redirect_to :action => :list, :display_name => @user.display_name
+ end
+ rescue ActiveRecord::RecordNotFound
+ render :text => "", :status => :not_found
+ end
+
+ def georss
+ @traces = Trace.visible_to_all.visible
+
+ if params[:display_name]
+ @traces = @traces.joins(:user).where(:users => { :display_name => params[:display_name] })
+ end
+
+ @traces = @traces.tagged(params[:tag]) if params[:tag]
+ @traces = @traces.order("timestamp DESC")
+ @traces = @traces.limit(20)
+ @traces = @traces.includes(:user)
+ end
+
+ def picture
+ trace = Trace.find(params[:id])
+
+ if trace.visible? && trace.inserted?
+ if trace.public? || (@user && @user == trace.user)
+ expires_in 7.days, :private => !trace.public?, :public => trace.public?
+ send_file(trace.large_picture_name, :filename => "#{trace.id}.gif", :type => "image/gif", :disposition => "inline")
+ else
+ render :text => "", :status => :forbidden
+ end
+ else
+ render :text => "", :status => :not_found
+ end
+ rescue ActiveRecord::RecordNotFound
+ render :text => "", :status => :not_found
+ end
+
+ def icon
+ trace = Trace.find(params[:id])
+
+ if trace.visible? && trace.inserted?
+ if trace.public? || (@user && @user == trace.user)
+ expires_in 7.days, :private => !trace.public?, :public => trace.public?
+ send_file(trace.icon_picture_name, :filename => "#{trace.id}_icon.gif", :type => "image/gif", :disposition => "inline")
+ else
+ render :text => "", :status => :forbidden
+ end
+ else
+ render :text => "", :status => :not_found
+ end
+ rescue ActiveRecord::RecordNotFound
+ render :text => "", :status => :not_found
+ end
+
+ def api_read
+ trace = Trace.visible.find(params[:id])
+
+ if trace.public? || trace.user == @user
+ render :text => trace.to_xml.to_s, :content_type => "text/xml"
+ else
+ render :text => "", :status => :forbidden
+ end
+ end
+
+ def api_update
+ trace = Trace.visible.find(params[:id])
+
+ if trace.user == @user
+ new_trace = Trace.from_xml(request.raw_post)
+
+ unless new_trace && new_trace.id == trace.id
+ fail OSM::APIBadUserInput.new("The id in the url (#{trace.id}) is not the same as provided in the xml (#{new_trace.id})")
+ end
+
+ trace.description = new_trace.description
+ trace.tags = new_trace.tags
+ trace.visibility = new_trace.visibility
+ trace.save!
+
+ render :text => "", :status => :ok
+ else
+ render :text => "", :status => :forbidden
+ end
+ end
+
+ def api_delete
+ trace = Trace.visible.find(params[:id])
+
+ if trace.user == @user
+ trace.visible = false
+ trace.save!
+
+ render :text => "", :status => :ok
+ else
+ render :text => "", :status => :forbidden
+ end
+ end
+
+ def api_data
+ trace = Trace.visible.find(params[:id])
+
+ if trace.public? || trace.user == @user
+ if request.format == Mime::XML
+ send_file(trace.xml_file, :filename => "#{trace.id}.xml", :type => request.format.to_s, :disposition => "attachment")
+ elsif request.format == Mime::GPX
+ send_file(trace.xml_file, :filename => "#{trace.id}.gpx", :type => request.format.to_s, :disposition => "attachment")
+ else
+ send_file(trace.trace_name, :filename => "#{trace.id}#{trace.extension_name}", :type => trace.mime_type, :disposition => "attachment")
+ end
+ else
+ render :text => "", :status => :forbidden
+ end
+ end
+
+ def api_create
+ tags = params[:tags] || ""
+ description = params[:description] || ""
+ visibility = params[:visibility]
+
+ if visibility.nil?
+ if params[:public] && params[:public].to_i.nonzero?
+ visibility = "public"
+ else
+ visibility = "private"
+ end
+ end
+
+ if params[:file].respond_to?(:read)
+ do_create(params[:file], tags, description, visibility)
+
+ if @trace.id
+ render :text => @trace.id.to_s, :content_type => "text/plain"
+ elsif @trace.valid?
+ render :text => "", :status => :internal_server_error
+ else
+ render :text => "", :status => :bad_request
+ end
+ else
+ render :text => "", :status => :bad_request
+ end
+ end
+
+ private
+
+ def do_create(file, tags, description, visibility)
+ # Sanitise the user's filename
+ name = file.original_filename.gsub(/[^a-zA-Z0-9.]/, "_")
+
+ # Get a temporary filename...