--- loncom/interface/Attic/lonspreadsheet.pm	2002/11/22 19:21:59	1.149
+++ loncom/interface/Attic/lonspreadsheet.pm	2002/12/05 15:31:05	1.155
@@ -1,5 +1,5 @@
 #
-# $Id: lonspreadsheet.pm,v 1.149 2002/11/22 19:21:59 matthew Exp $
+# $Id: lonspreadsheet.pm,v 1.155 2002/12/05 15:31:05 matthew Exp $
 #
 # Copyright Michigan State University Board of Trustees
 #
@@ -62,6 +62,7 @@ use Safe;
 use Safe::Hole;
 use Opcode;
 use GDBM_File;
+use HTML::Entities();
 use HTML::TokeParser;
 use Spreadsheet::WriteExcel;
 
@@ -965,11 +966,9 @@ sub templaterow {
 	     'N','O','P','Q','R','S','T','U','V','W','X','Y','Z',
 	     'a','b','c','d','e','f','g','h','i','j','k','l','m',
 	     'n','o','p','q','r','s','t','u','v','w','x','y','z') {
-        my $fm=$sheet->{'f'}->{'template_'.$_};
-        $fm=~s/[\'\"]/\&\#34;/g;
         push(@cols,{ name    => 'template_'.$_,
-                     formula => $fm,
-                     value   => $fm });
+                     formula => $sheet->{'f'}->{'template_'.$_},
+                     value   => $sheet->{'f'}->{'template_'.$_} });
     }
     return ($rowlabel,@cols);
 }
@@ -982,7 +981,11 @@ sub outrowassess {
     if ($n) {
         my ($usy,$ufn)=split(/__&&&\__/,$sheet->{'f'}->{'A'.$n});
         if (exists($sheet->{'rowlabel'}->{$usy})) {
-            $rowlabel = $sheet->{'rowlabel'}->{$usy};
+            # This is dumb, but we need the information when we output
+            # the html version of the studentcalc spreadsheet for the
+            # links to the assesscalc sheets.
+            $rowlabel = $sheet->{'rowlabel'}->{$usy}.':'.
+                &Apache::lonnet::escape($ufn);
         } else { 
             $rowlabel = '';
         }
@@ -993,10 +996,8 @@ sub outrowassess {
 	     'N','O','P','Q','R','S','T','U','V','W','X','Y','Z',
 	     'a','b','c','d','e','f','g','h','i','j','k','l','m',
 	     'n','o','p','q','r','s','t','u','v','w','x','y','z') {
-        my $fm=$sheet->{'f'}->{$_.$n};
-        $fm=~s/[\'\"]/\&\#34;/g;
         push(@cols,{ name    => $_.$n,
-                     formula => $fm,
+                     formula => $sheet->{'f'}->{$_.$n},
                      value   => $sheet->{'values'}->{$_.$n}});
     }
     return ($rowlabel,@cols);
@@ -1019,10 +1020,8 @@ sub outrow {
 	     'N','O','P','Q','R','S','T','U','V','W','X','Y','Z',
 	     'a','b','c','d','e','f','g','h','i','j','k','l','m',
 	     'n','o','p','q','r','s','t','u','v','w','x','y','z') {
-        my $fm=$sheet->{'f'}->{$_.$n};
-        $fm=~s/[\'\"]/\&\#34;/g;
         push(@cols,{ name    => $_.$n,
-                     formula => $fm,
+                     formula => $sheet->{'f'}->{$_.$n},
                      value   => $sheet->{'values'}->{$_.$n}});
     }
     return ($rowlabel,@cols);
@@ -1203,9 +1202,13 @@ sub sort_indicies {
         my @sortby2=(undef);
         # Skip row 0
         for (my $row=1;$row<=$sheet->{'maxrow'};$row++) {
-            my (undef,$symb,$uname,$udom,$mapid,$resid,$title) = 
-                split(':',$sheet->{'rowlabel'}->{$sheet->{'f'}->{'A'.$row}});
-            $symb = &Apache::lonnet::unescape($symb);
+            my ($key,undef) = split(/__&&&\__/,$sheet->{'f'}->{'A'.$row});
+            my $rowlabel = $sheet->{'rowlabel'}->{$key};
+            my (undef,$symb,$mapid,$resid,$title,$ufn) = 
+                split(':',$rowlabel);
+            $ufn   = &Apache::lonnet::unescape($ufn);
+            $symb  = &Apache::lonnet::unescape($symb);
+            $title = &Apache::lonnet::unescape($title);
             my ($sequence) = ($symb =~ /\/([^\/]*\.sequence)/);
             if ($sequence eq '') {
                 $sequence = $symb;
@@ -1253,25 +1256,35 @@ sub html_editable_cell {
         if ($formula ne '') {
             $value = '<i>undefined value</i>';
         }
-    }
-    if ($value =~ /^\s*$/ ) {
+    } elsif ($value =~ /^\s*$/ ) {
         $value = '<font color="'.$bgcolor.'">#</font>';
+    } else {
+        $value = &HTML::Entities::encode($value);
     }
+    # Make the formula safe for outputting
+    $formula =~ s/\'/\"/g;
+    # The formula will be parsed by the browser *twice* before being 
+    # displayed to the user for editing.
+    $formula = &HTML::Entities::encode(&HTML::Entities::encode($formula));
+    # Escape newlines so they make it into the edit window
     $formula =~ s/\n/\\n/gs;
-    $result .= '<a href="javascript:celledit(\''.
-        $name.'\',\''.$formula.'\');">'.$value.'</a>';
+    # Glue everything together
+    $result .= "<a href=\"javascript:celledit(\'".
+        $name."','".$formula."');\">".$value."</a>";
     return $result;
 }
 
 sub html_uneditable_cell {
     my ($cell,$bgcolor) = @_;
     my $value = (defined($cell) ? $cell->{'value'} : '');
+    $value = &HTML::Entities::encode($value);
     return '&nbsp;'.$value.'&nbsp;';
 }
 
 sub outsheet_html  {
     my ($sheet,$r) = @_;
     my ($num_uneditable,$realm,$row_type);
+    my $requester_is_student = ($ENV{'request.role'} =~ /^st\./);
     if ($sheet->{'sheettype'} eq 'assesscalc') {
         $num_uneditable = 1;
         $realm = 'Assessment';
@@ -1316,34 +1329,39 @@ END
     ####################################
     # Print out template row
     ####################################
-    my ($rowlabel,@rowdata) = &get_row($sheet,'-');
-    my $row_html = '<tr><td>'.&format_html_rowlabel($sheet,$rowlabel).'</td>';
-    my $num_cols_output = 0;
-    foreach my $cell (@rowdata) {
-        if ($num_cols_output++ < $num_uneditable) {
-            $row_html .= '<td bgcolor="#FFDDDD">';
-            $row_html .= &html_uneditable_cell($cell,'#FFDDDD');
-        } else {
-            $row_html .= '<td bgcolor="#EOFFDD">';
-            $row_html .= &html_editable_cell($cell,'#E0FFDD');
+    my ($num_cols_output,$row_html,$rowlabel,@rowdata);
+    
+    if (! $requester_is_student) {
+        ($rowlabel,@rowdata) = &get_row($sheet,'-');
+        $row_html = '<tr><td>'.&format_html_rowlabel($sheet,$rowlabel).'</td>';
+        $num_cols_output = 0;
+        foreach my $cell (@rowdata) {
+            if ($requester_is_student || 
+                $num_cols_output++ < $num_uneditable) {
+                $row_html .= '<td bgcolor="#FFDDDD">';
+                $row_html .= &html_uneditable_cell($cell,'#FFDDDD');
+            } else {
+                $row_html .= '<td bgcolor="#EOFFDD">';
+                $row_html .= &html_editable_cell($cell,'#E0FFDD');
+            }
+            $row_html .= '</td>';
         }
-        $row_html .= '</td>';
+        $row_html.= "</tr>\n";
+        $r->print($row_html);
     }
-    $row_html.= "</tr>\n";
-    $r->print($row_html);
     ####################################
     # Print out summary/export row
     ####################################
-    my ($rowlabel,@rowdata) = &get_row($sheet,'0');
-    $row_html = '<tr><td>'.&format_html_rowlabel($sheet,$rowlabel).'</td>';
+    ($rowlabel,@rowdata) = &get_row($sheet,'0');
+    $row_html = '<tr><td>'.&format_html_rowlabel($sheet,'Summary').'</td>';
     $num_cols_output = 0;
     foreach my $cell (@rowdata) {
-        if ($num_cols_output++ < 26) {
+        if ($num_cols_output++ < 26 && ! $requester_is_student) {
             $row_html .= '<td bgcolor="#CCCCFF">';
             $row_html .= &html_editable_cell($cell,'#CCCCFF');
         } else {
             $row_html .= '<td bgcolor="#DDCCFF">';
-            $row_html .= &html_uneditable_cell(undef,'#CCCCFF');
+            $row_html .= &html_uneditable_cell($cell,'#CCCCFF');
         }
         $row_html .= '</td>';
     }
@@ -1383,18 +1401,21 @@ END
         if ($sheet->{'sheettype'} eq 'classcalc') {
             $row_html.='<td>'.&format_html_rowlabel($sheet,$rowlabel).'</td>';
             # Output links for each student?
-            # Nope, that is already done for us in format_html_rowlabel (for now)
+            # Nope, that is already done for us in format_html_rowlabel 
+            # (for now)
         } elsif ($sheet->{'sheettype'} eq 'studentcalc') {
+            my $ufn = (split(/:/,$rowlabel))[5];
             $row_html.='<td>'.&format_html_rowlabel($sheet,$rowlabel);
             $row_html.= '<br>'.
                 '<select name="sel_'.$rownum.'" '.
                     'onChange="changesheet('.$rownum.')">'.
                         '<option name="default">Default</option>';
+
             foreach (@{$sheet->{'othersheets'}}) {
                 $row_html.='<option name="'.$_.'"';
-                #if ($ufn eq $_) {
-                #    $row_html.=' selected';
-                #}
+                if ($ufn eq $_) {
+                    $row_html.=' selected';
+                }
                 $row_html.='>'.$_.'</option>';
             }
             $row_html.='</select></td>';
@@ -1417,7 +1438,7 @@ END
             $bgcolor='#FFDDDD' if ($shown_cells < $num_uneditable);
             #
             $row_html.='<td bgcolor='.$bgcolor.'>';
-            if ($shown_cells < $num_uneditable) {
+            if ($requester_is_student || $shown_cells < $num_uneditable) {
                 $row_html .= &html_uneditable_cell($cell,$bgcolor);
             } else {
                 $row_html .= &html_editable_cell($cell,$bgcolor);
@@ -1898,9 +1919,16 @@ sub writesheet {
                                           $cdom,$cnum);
             if ($reply eq 'ok') {
                 if ($makedef) { 
-                    return &Apache::lonnet::put('environment',
-                                  {'spreadsheet_default_'.$stype => $fn },
-                                                $cdom,$cnum);
+                    $reply = &Apache::lonnet::put('environment',
+                                    {'spreadsheet_default_'.$stype => $fn },
+                                                  $cdom,$cnum);
+                    if ($reply eq 'ok' && 
+                        ($sheet->{'sheettype'} eq 'studentcalc' ||
+                         $sheet->{'sheettype'} eq 'assesscalc')) {
+                        # Expire the spreadsheets of the other students.
+                        &Apache::lonnet::expirespread('','','studentcalc','');
+                    }
+                    return $reply;
                 } 
                 return $reply;
             } 
@@ -1923,7 +1951,10 @@ sub tmpwrite {
     $fn=$tmpdir.$fn.'.tmp';
     my $fh;
     if ($fh=Apache::File->new('>'.$fn)) {
-	print $fh join("\n",&getformulas($sheet));
+        my %f = &getformulas($sheet);
+        while( my ($cell,$formula) = each(%f)) {
+            print $fh &Apache::lonnet::escape($cell)."=".&Apache::lonnet::escape($formula)."\n";
+        }
     }
 }
 
@@ -1939,32 +1970,36 @@ sub tmpread {
     my %fo=();
     my $countrows=0;
     if ($fh=Apache::File->new($fn)) {
-        my $name;
-        while ($name=<$fh>) {
-	    chomp($name);
-            my $value=<$fh>;
-            chomp($value);
-            $fo{$name}=$value;
-            if ($name=~/^A(\d+)$/) {
-		if ($1>$countrows) {
-		    $countrows=$1;
-                }
-            }
-        }
-    }
+        while (<$fh>) {
+	    chomp;
+            my ($cell,$formula) = split(/=/);
+            $cell    = &Apache::lonnet::unescape($cell);
+            $formula = &Apache::lonnet::unescape($formula);
+            $fo{$cell} = $formula;
+        }
+    }
+#            chomp($value);
+#            $fo{$name}=$value;
+#            if ($name=~/^A(\d+)$/) {
+#		if ($1>$countrows) {
+#		    $countrows=$1;
+#                }
+#            }
+#        }
+#    }
     if ($nform eq 'changesheet') {
         $fo{'A'.$nfield}=(split(/__&&&\__/,$fo{'A'.$nfield}))[0];
         unless ($ENV{'form.sel_'.$nfield} eq 'Default') {
 	    $fo{'A'.$nfield}.='__&&&__'.$ENV{'form.sel_'.$nfield};
         }
-    } elsif ($nfield eq 'insertrow') {
-        $countrows++;
-        my $newrow=substr('000000'.$countrows,-7);
-        if ($nform eq 'top') {
-	    $fo{'A'.$countrows}='--- '.$newrow;
-        } else {
-            $fo{'A'.$countrows}='~~~ '.$newrow;
-        }
+#    } elsif ($nfield eq 'insertrow') {
+#        $countrows++;
+#        my $newrow=substr('000000'.$countrows,-7);
+#        if ($nform eq 'top') {
+#	    $fo{'A'.$countrows}='--- '.$newrow;
+#        } else {
+#            $fo{'A'.$countrows}='~~~ '.$newrow;
+#        }
     } else {
        if ($nfield) { $fo{$nfield}=$nform; }
     }
@@ -2058,11 +2093,15 @@ sub format_html_rowlabel {
     my ($type,$labeldata) = split(':',$rowlabel,2);
     my $result = '';
     if ($type eq 'symb') {
-        my ($symb,$mapid,$resid,$title) = split(':',$labeldata);
-        $symb = &Apache::lonnet::unescape($symb);
+        my ($symb,$mapid,$resid,$title,$ufn) = split(':',$labeldata);
+        $ufn   = 'default' if (!defined($ufn) || $ufn eq '');
+        $ufn   = &Apache::lonnet::unescape($ufn);
+        $symb  = &Apache::lonnet::unescape($symb);
+        $title = &Apache::lonnet::unescape($title);
         $result = '<a href="/adm/assesscalc?usymb='.$symb.
             '&uname='.$sheet->{'uname'}.'&udom='.$sheet->{'udom'}.
-                '&mapid='.$mapid.'&resid='.$resid.'">'.$title.'</a>';
+                '&ufn='.$ufn.
+                    '&mapid='.$mapid.'&resid='.$resid.'">'.$title.'</a>';
     } elsif ($type eq 'student') {
         my ($sname,$sdom,$fullname,$section,$id) = split(':',$labeldata);
         if ($fullname =~ /^\s*$/) {
@@ -2086,8 +2125,10 @@ sub format_csv_rowlabel {
     my ($type,$labeldata) = split(':',$rowlabel,2);
     my $result = '';
     if ($type eq 'symb') {
-        my ($symb,$mapid,$resid,$title) = split(':',$labeldata);
-        $symb = &Apache::lonnet::unescape($symb);
+        my ($symb,$mapid,$resid,$title,$ufn) = split(':',$labeldata);
+        $ufn   = &Apache::lonnet::unescape($ufn);
+        $symb  = &Apache::lonnet::unescape($symb);
+        $title = &Apache::lonnet::unescape($title);
         $result = $title;
     } elsif ($type eq 'student') {
         my ($sname,$sdom,$fullname,$section,$id) = split(':',$labeldata);
@@ -2108,8 +2149,10 @@ sub format_excel_rowlabel {
     my ($type,$labeldata) = split(':',$rowlabel,2);
     my $result = '';
     if ($type eq 'symb') {
-        my ($symb,$mapid,$resid,$title) = split(':',$labeldata);
-        $symb = &Apache::lonnet::unescape($symb);
+        my ($symb,$mapid,$resid,$title,$ufn) = split(':',$labeldata);
+        $ufn   = &Apache::lonnet::unescape($ufn);
+        $symb  = &Apache::lonnet::unescape($symb);
+        $title = &Apache::lonnet::unescape($title);
         $result = $title;
     } elsif ($type eq 'student') {
         my ($sname,$sdom,$fullname,$section,$id) = split(':',$labeldata);
@@ -2217,10 +2260,11 @@ sub get_student_rowlabels {
             return 'Could not access course data';
         }
         #
-        my %assesslist;
+        my %assesslist = ();
         foreach ('Feedback','Evaluation','Tutoring','Discussion') {
             my $symb = '_'.lc($_);
-            $assesslist{$symb} = join(':',('symb',$symb,0,0,$_));
+            $assesslist{$symb} = join(':',('symb',$symb,0,0,
+                                           &Apache::lonnet::escape($_)));
         }
         #
         while (my ($key,$srcf) = each(%course_db)) {
@@ -2232,8 +2276,9 @@ sub get_student_rowlabels {
                 my $symb=
                     &Apache::lonnet::declutter($course_db{'map_id_'.$mapid}).
                         '___'.$resid.'___'.&Apache::lonnet::declutter($srcf);
-                $assesslist{$symb}='symb:'.&Apache::lonnet::escape($symb).':'
-                    .$mapid.':'.$resid.':'.$course_db{'title_'.$id};
+                $assesslist{$symb} ='symb:'.&Apache::lonnet::escape($symb).':'
+                    .$mapid.':'.$resid.':'.
+                        &Apache::lonnet::escape($course_db{'title_'.$id});
             }
         }
         untie(%course_db);
@@ -2332,10 +2377,6 @@ sub updatestudentassesssheet {
                  ($formula =~ /^(~~~|---)/) )) {
             $f{$_}='!!! Obsolete';
             $changed=1;
-        } elsif ($ufn) {
-            # I do not think this works any more
-            $sheet->{'rowlabel'}->{$usy}
-                =~s/assesscalc\?usymb\=/assesscalc\?ufn\=$ufn&\usymb\=/;
         }
     }
     # New and unknown keys
@@ -2676,7 +2717,7 @@ sub forcedrecalc {
             &checkthis($uname.':'.$udom.':assesscalc:'.$map,$time) ||
             &checkthis($uname.':'.$udom.':assesscalc:'.$usymb,$time)) {
             return 1;
-        } 
+        }
     } else {
         if (&checkthis('::studentcalc:',$time) || 
             &checkthis($uname.':'.$udom.':studentcalc:',$time)) {
@@ -2697,6 +2738,7 @@ sub exportsheet {
     $udom  = $udom  || $sheet->{'udom'};
     $stype = $stype || $sheet->{'sheettype'};
     my @exportarr=();
+    # This handles the assessment sheets for '_feedback', etc
     if (defined($usymb) && ($usymb=~/^\_(\w+)/) && 
         (!defined($fn) || $fn eq '')) {
         $fn='default_'.$1;
@@ -2942,11 +2984,16 @@ sub handler {
         delete $ENV{'form.unewformula'} if (exists($ENV{'form.unewformula'}));
     }
     #
-    # Clean up symb and spreadsheet filename
+    # Look for special assessment spreadsheets - '_feedback', etc.
     #
-    if (($ENV{'form.usymb'}=~/^\_(\w+)/) && (!$ENV{'form.ufn'})) {
+    if (($ENV{'form.usymb'}=~/^\_(\w+)/) && (!$ENV{'form.ufn'} || 
+                                             $ENV{'form.ufn'} eq '' || 
+                                             $ENV{'form.ufn'} eq 'default')) {
         $ENV{'form.ufn'}='default_'.$1;
     }
+    if (!$ENV{'form.ufn'} || $ENV{'form.ufn'} eq 'default') {
+        $ENV{'form.ufn'}='course_default_'.$sheettype;
+    }
     #
     # Interactive loading of specific sheet?
     #
@@ -2988,6 +3035,8 @@ sub handler {
 
     function celledit(cellname,cellformula) {
         var edit_text = '';
+        // cellformula may contain less-than and greater-than symbols, so
+        // we need to escape them?  
         edit_text +='<html><head><title>Cell Edit Window</title></head><body>';
         edit_text += '<form name="editwinform">';
         edit_text += '<center><h3>Cell '+cellname+'</h3>';
@@ -3081,8 +3130,9 @@ ENDSCRIPT
     if ($ENV{'form.unewfield'}) {
         $r->print('<h2>Modified Workcopy</h2>');
         $ENV{'form.unewformula'}=~s/\'/\"/g;
-        $r->print('<p>New formula: '.$ENV{'form.unewfield'}.'='.
-                  $ENV{'form.unewformula'}.'<p>');
+        $r->print('<p>Cell '.$ENV{'form.unewfield'}.' = <pre>');
+        $r->print(&HTML::Entities::encode($ENV{'form.unewformula'}).
+                  '</pre></p>');
         $sheet->{'filename'} = $ENV{'form.ufn'};
         &tmpread($sheet,$ENV{'form.unewfield'},$ENV{'form.unewformula'});
     } elsif ($ENV{'form.saveas'}) {
@@ -3221,13 +3271,18 @@ ENDSCRIPT
         } 
         $r->print('>'.$mode.'</option>'."\n");
     }
-    if ($sheet->{'sheettype'} eq 'classcalc') {
-        $r->print('<option value="recursive excel"');
-        if ($ENV{'form.output'} eq 'recursive excel') {
-            $r->print(' selected ');
-        } 
-        $r->print(">Multi-Sheet Excel</option>\n");
-    }
+#
+#    Mulit-sheet excel takes too long and does not work at all for large
+#    classes.  Future inclusion of this option may be possible with the
+#    Spreadsheet::WriteExcel::Big and speed improvements.
+#
+#    if ($sheet->{'sheettype'} eq 'classcalc') {
+#        $r->print('<option value="recursive excel"');
+#        if ($ENV{'form.output'} eq 'recursive excel') {
+#            $r->print(' selected ');
+#        } 
+#        $r->print(">Multi-Sheet Excel</option>\n");
+#    }
     $r->print("</select>\n");
     #
     if ($sheet->{'sheettype'} eq 'classcalc') {
@@ -3253,3 +3308,5 @@ ENDSCRIPT
 
 1;
 __END__
+
+