--- loncom/interface/loncreatecourse.pm	2014/01/30 19:00:09	1.156
+++ loncom/interface/loncreatecourse.pm	2017/11/16 16:22:58	1.158.2.3.2.1
@@ -1,7 +1,7 @@
 # The LearningOnline Network
 # Create a course
 #
-# $Id: loncreatecourse.pm,v 1.156 2014/01/30 19:00:09 bisitz Exp $
+# $Id: loncreatecourse.pm,v 1.158.2.3.2.1 2017/11/16 16:22:58 raeburn Exp $
 #
 # Copyright Michigan State University Board of Trustees
 #
@@ -133,6 +133,8 @@ sub print_course_creation_page {
     } else {
         my $title_alert = &mt('A Community title is required');
         my $coord_alert = &mt('The username of the Coordinator is required');
+        &js_escape(\$title_alert);
+        &js_escape(\$coord_alert);
         $javascript_validations = qq|
 function validate(formname) {
     if (formname.title == '') {
@@ -158,7 +160,7 @@ function validate(formname) {
                     'snid' => "Section Numbers and corresponding LON-CAPA section IDs",
                     'csli' => "a comma separated list of institutional section numbers, each separated by a colon from the (optional) corresponding section ID to be used in LON-CAPA e.g., 001:1,002:2",
                     'crcs' => "Crosslisted courses",
-                    'cscs' => "a comma separated list of course sections crosslisted with the current course, with each entry including the institutional course section name followed by a colon and then the (optional) sectionID to be used in LON-CAPA, e.g., fs03ent231001:ent1,fs03bot231001:bot1,fs03zol231002:zol2",
+                    'cscs' => "a comma separated list of course sections crosslisted with the current course, with each entry including the institutional course section name followed by a colon and then the (optional) section ID to be used in LON-CAPA, e.g., fs03ent231001:ent1,fs03bot231001:bot1,fs03zol231002:zol2",
                     'ccre' => "Course credits",
                     'crcd' => "Create six character course identifier to share with students",
                     'cred' => "the number of institutional credits students will earn by completing this course",
@@ -185,7 +187,8 @@ function validate(formname) {
                     'oaas' => "Open all assessments",
                     'mssg' => "Messaging",
                     'scpf' => "Set course policy feedback to Course Coordinator",
-                    'scfc' => "Set content feedback to Course Coordinator",
+                    'scfc' => "Set resource content feedback to Course Coordinator",
+                    'scof' => "Set course content feedback to Course Coordinator",
                     'cmmn' => "Communication",
                     'dsrd' => "Disable student resource discussion",
                     'dsuc' => "Disable student use of chat rooms",
@@ -231,7 +234,8 @@ function validate(formname) {
         $lt{'navi'} = &mt('Community Contents');
         $lt{'cid'}  = &mt('Community ID');
         $lt{'scpf'} = &mt('Set community policy feedback to Coordinator');
-        $lt{'scfc'} = &mt('Set content feedback to Coordinator');
+        $lt{'scfc'} = &mt('Set resource content feedback to Coordinator');
+        $lt{'scof'} = &mt('Set community content feedback to Coordinator');
         $lt{'dsrd'} = &mt('Disable member resource discussion');
         $lt{'dsuc'} = &mt('Disable member use of chat rooms');
         $lt{'dads'} = &mt('Default Access Dates for Members');
@@ -460,6 +464,10 @@ END
                  .'<input type="checkbox" name="setcontent" checked="checked" />'
                  .&Apache::lonhtmlcommon::row_closure()
 
+                 .&Apache::lonhtmlcommon::row_title($lt{'scof'})
+                 .'<input type="checkbox" name="setcomment" checked="checked" />'
+                 .&Apache::lonhtmlcommon::row_closure()
+
                  .&Apache::lonhtmlcommon::row_headline()
                  .'<h3>'.$lt{'cmmn'}.'</h3>'
                  .&Apache::lonhtmlcommon::row_closure()
@@ -646,6 +654,7 @@ sub create_course {
                endaccess => $endaccess,
                setpolicy => $env{'form.setpolicy'},
                setcontent => $env{'form.setcontent'},
+               setcomment => $env{'form.setcomment'},
                reshome => $env{'form.reshome'},
                setkeys => $env{'form.setkeys'},
                keyauth => $env{'form.keyauth'},
@@ -732,7 +741,7 @@ sub create_course {
 }
 
 sub print_intro_page {
-    my ($r,$show_all_choices) = @_;
+    my ($r,$show_all_choices,$cancreate,$permission) = @_;
     my $start_page =
         &Apache::loncommon::start_page('Create a New Course or Community');
     my $crumbs = &Apache::lonhtmlcommon::breadcrumbs('Creation Options','Create_Course',undef,'Create_Courses');
@@ -741,6 +750,10 @@ sub print_intro_page {
     my $helplink=&Apache::loncommon::help_open_topic('Create_Course_Community',&mt('Help on Creating Courses and Communities'));
 
     # Create menu
+    my $approve = 'Display requests awaiting approval';
+    if ($permission->{'create'}) {
+        $approve = 'Approve or reject requests';
+    }
     my @menu;
     @menu =
        ({ categorytitle => 'Course/Community Creation',
@@ -748,7 +761,7 @@ sub print_intro_page {
           {
                linktext => 'Create a single course',
                url => '/adm/createcourse?phase=courseone',
-               permission => 1,
+               permission => $permission->{'create'},
                #help => '',
                icon => 'crsnew.png',
                linktitle => 'Create a new course by completing an online form.'
@@ -756,7 +769,7 @@ sub print_intro_page {
           {
                linktext => 'Create a single community',
                url => '/adm/createcourse?phase=groupone',
-               permission => $show_all_choices,
+               permission => $permission->{'create'} && $cancreate->{'Community'},
                #help => '',
                icon => 'crsnew.png',
                linktitle => 'Create a new collaborative community by completing an online form.'
@@ -764,7 +777,7 @@ sub print_intro_page {
           {
                linktext => 'Create courses/communities by uploading an attributes file',
                url => '/adm/createcourse?phase=batchone',
-               permission => 1,
+               permission => $permission->{'create'},
                help => 'Batch_Creation',
                icon => 'uplcrs.png',
                linktitle => 'Upload an attributes file containing specifications for one or more courses or communities in XML format.'
@@ -774,7 +787,7 @@ sub print_intro_page {
        { categorytitle => 'Course/Community Requests',
        items => [
            {
-               linktext => 'Approve or reject requests',
+               linktext => $approve,
                url => '/adm/createcourse?phase=requestdisplay',
                permission => $show_all_choices,
                #help => '',
@@ -835,43 +848,60 @@ sub upload_batchfile {
 
 sub process_batchfile {
     my $r = shift;
-    my $start_page =
-        &Apache::loncommon::start_page('Create a New Course or Community');
-    my $crumbs = &Apache::lonhtmlcommon::breadcrumbs('Creation Outcome','Create_Course',undef,'Create_Courses');
-    my $end_page =
-        &Apache::loncommon::end_page();
     my $defdom=$env{'request.role.domain'};
-    my $batchfilepath=&Apache::lonnet::userfileupload('coursecreatorxml',undef,
-                                                      'batchupload',undef,undef,
-                                                       undef,undef,$defdom);
-    my ($batchdir,$filename) = ($batchfilepath =~ m-^(.+)/pending/([^/]+)$-);
+    my $uname = $env{'user.name'};
+    my $udom = $env{'user.domain'};
+    my $dir = &LONCAPA::tempdir().'addcourse';
     my ($result,$logmsg);
-    if (-e "$batchfilepath") {
-        open(FILE,"<$batchfilepath");
-        my @buffer = <FILE>;
-        close(FILE);
-        if ((defined($filename)) && (defined($batchdir))) {
-            my @requests = ($filename);
-            my %courseids = ();
-            ($result,$logmsg) = &LONCAPA::batchcreatecourse::create_courses(
-                                        \@requests,\%courseids,'web',$defdom,
-                                        $env{'user.name'},$env{'user.domain'});
-            if ($result) {
-                if (!-e "$batchdir/processed") {
-                    mkdir("$batchdir/processed", 0755);
-                    open(FILE,">$batchdir/processed/$filename");
-                    print FILE @buffer;
+    if (($defdom =~ /^$match_domain$/) && ($uname =~ /^$match_username$/) && ($udom =~/^$match_domain$/)) {
+        my $batchfilepath=&Apache::lonnet::userfileupload('coursecreatorxml',undef,
+                                                          'batchupload',undef,undef,
+                                                          undef,undef,$defdom);
+        if ($batchfilepath =~ m{^(\Q$dir/$defdom/web/$uname\_$udom\E)/pending/([^/]+)$}) {
+            my ($batchdir,$filename) = ($1,$2);
+            if (-e "$batchfilepath") {
+                if (open(FILE,"<",$batchfilepath)) {
+                    my @buffer = <FILE>;
                     close(FILE);
-                    if (-e "$batchdir/processed/$filename") {
-                        unlink("$batchdir/pending/$filename");
+                    if ((defined($filename)) && (defined($batchdir))) {
+                        my @requests = ($filename);
+                        my %courseids = ();
+                        ($result,$logmsg) = &LONCAPA::batchcreatecourse::create_courses(
+                                                    \@requests,\%courseids,'web',$defdom,
+                                                    $uname,$udom);
+                        if (keys(%courseids) > 0) {
+                            if (!-e "$batchdir/processed") {
+                                mkdir("$batchdir/processed", 0755);
+                            }
+                            if (-d "$batchdir/processed") {
+                                if (open(FILE,">","$batchdir/processed/$filename")) {
+                                    print FILE @buffer;
+                                    close(FILE);
+                                }
+                            }
+                            if (-e "$batchdir/processed/$filename") {
+                                unlink("$batchdir/pending/$filename");
+                            }
+                        }
                     }
+                } else {
+                    $result = '<p class="LC_error">'.&mt('Could not open attributes file.').'<br />'.&mt('No courses created.').'</p>';
                 }
+            } else {
+                $result = '<p class="LC_error">'.&mt('No uploaded attributes file found.').'<br />'.&mt('No courses created.').'</p>';
             }
+        } else {
+            $result = '<p class="LC_error">'.&mt('Invalid path to attributes file.').'<br />'.&mt('No courses created.').'</p>';
         }
+    } else {
+        $result = '<p class="LC_error">'.&mt("Your username, domain, and/or your current role's domain are missing or contain invalid characters.").
+                  '<br />'.&mt('No courses created.').'</p>';
     }
-    $r->print($start_page.$crumbs.$logmsg.$result.'<br /><a href="/adm/createcourse">'.
-              &mt('Creation options menu').'</a>'.$end_page);
- 
+    $r->print(&Apache::loncommon::start_page('Create a New Course, Community or Placement Test').
+              &Apache::lonhtmlcommon::breadcrumbs('Creation Outcome','Create_Course',undef,'Create_Courses').
+              $logmsg.$result.'<br /><a href="/adm/createcourse">'.
+              &mt('Creation options menu').'</a>'.
+              &Apache::loncommon::end_page());
 }
 
 sub courserequestbrowser_javascript {
@@ -1245,6 +1275,20 @@ ENDJS
 
 }
 
+sub get_permission {
+    my ($dom) = @_;
+    my ($allowed,%permission);
+    if (&Apache::lonnet::allowed('ccc',$dom)) {
+        $allowed = 1;
+        %permission = (
+            create => 1,
+        );
+    } elsif (&Apache::lonnet::allowed('dcc',$dom)) {
+        $allowed = 1;
+    }
+    return ($allowed,\%permission);
+}
+
 # ===================================================================== Handler
 sub handler {
     my $r = shift;
@@ -1255,14 +1299,27 @@ sub handler {
        return OK;
     }
 
-    my $show_all_choices = 0;
-    my $primary_rev = &Apache::lonnet::get_server_loncaparev($env{'request.role.domain'});
-    if (($primary_rev ne 'refused') && ($primary_rev ne 'error') &&
-        ($primary_rev ne 'unknown_cmd') && ($primary_rev ne 'no_such_host')) {
-        $show_all_choices = 1;
-    }
+    my ($allowed,$permission) = &get_permission($env{'request.role.domain'});
+    if ($allowed) {
+        my $show_all_choices = 0;
+        my $primary_rev = &Apache::lonnet::get_server_loncaparev($env{'request.role.domain'});
+        my %cancreate = (
+                           Community => 0,
+                        );
+        if (($primary_rev ne 'refused') && ($primary_rev ne 'error') &&
+            ($primary_rev ne 'unknown_cmd') && ($primary_rev ne 'no_such_host')) {
+            $show_all_choices = 1;
+            my ($primary_major,$primary_minor) = split(/\./,$primary_rev);
+            foreach my $key (keys(%cancreate)) {
+                my ($needsmajor,$needsminor) =
+                    split(/\./,$Apache::lonnet::needsrelease{'course:crstype:'.$key});
+                unless (($needsmajor > $primary_major) ||
+                        (($needsmajor == $primary_major) && ($needsminor > $primary_minor))) {
+                    $cancreate{$key} = 1;
+                }
+            }
+        }
 
-    if (&Apache::lonnet::allowed('ccc',$env{'request.role.domain'})) {
        &Apache::loncommon::content_type($r,'text/html');
        $r->send_http_header;
 
@@ -1273,9 +1330,10 @@ sub handler {
           ({href=>"/adm/createcourse",
             text=>"Creation Options",
             faq=>79,bug=>'Dom Coord Interface',});
-       if (($env{'form.phase'} eq 'coursetwo') ||
-           (($env{'form.phase'} eq 'grouptwo') && 
-            ($show_all_choices))) { 
+       if (($permission->{'create'}) &&
+           (($env{'form.phase'} eq 'coursetwo') ||
+            (($env{'form.phase'} eq 'grouptwo') &&
+            ($cancreate{'Community'})))) {
            &Apache::lonhtmlcommon::add_breadcrumb
                  ({href=>"/adm/createcourse?phase=$env{'form.prevphase'}",
                    text=>&mt('[_1] Creation Settings',),
@@ -1285,21 +1343,24 @@ sub handler {
                    text=>"Creation Outcome",
                    faq=>9,bug=>'Dom Coord Interface',});
            &create_course($r);
-       } elsif (($env{'form.phase'} eq 'courseone') || 
-                (($env{'form.phase'} eq 'groupone') && 
-                ($show_all_choices))) {
+       } elsif (($permission->{'create'}) &&
+                (($env{'form.phase'} eq 'courseone') ||
+                 (($env{'form.phase'} eq 'groupone') &&
+                 ($cancreate{'Community'})))) {
            &Apache::lonhtmlcommon::add_breadcrumb
                  ({href=>"/adm/createcourse?phase=$env{'form.phase'}",
                    text=>&mt('[_1] Creation Settings',),
                    faq=>9,bug=>'Dom Coord Interface',});
 	   &print_course_creation_page($r);
-       } elsif ($env{'form.phase'} eq 'batchone') {
+       } elsif (($permission->{'create'}) &&
+                ($env{'form.phase'} eq 'batchone')) {
            &Apache::lonhtmlcommon::add_breadcrumb
                  ({href=>"/adm/createcourse?phase=$env{'form.phase'}",
                    text=>"Upload Description File",
                    faq=>9,bug=>'Dom Coord Interface',});
            &upload_batchfile($r);
-       } elsif ($env{'form.phase'} eq 'batchtwo') {
+       } elsif (($permission->{'create'}) &&
+                ($env{'form.phase'} eq 'batchtwo')) {
            &Apache::lonhtmlcommon::add_breadcrumb
                  ({href=>"/adm/createcourse?phase=$env{'form.prevphase'}",
                    text=>"Upload Description File",
@@ -1317,11 +1378,16 @@ sub handler {
            my $js = &courserequestbrowser_javascript();
            my $start_page=&Apache::loncommon::start_page('Display Requests',$js);
            my $crumbs = &Apache::lonhtmlcommon::breadcrumbs('Display Requests','Course_Requests',undef,'Course_Requests');
+           my $context = 'domain';
+           unless ($permission->{'create'}) {
+               $context = 'helpdesk';
+           }
            $r->print($start_page.$crumbs."\n".'<div>'.
                      &Apache::loncoursequeueadmin::display_queued_requests(
-                         'domain',$env{'request.role.domain'}).'</div>'.
+                         $context,$env{'request.role.domain'}).'</div>'.
                      &Apache::loncommon::end_page());
-       } elsif (($env{'form.phase'} eq 'requestchange') && ($show_all_choices)) {
+       } elsif (($permission->{'create'}) &&
+                ($env{'form.phase'} eq 'requestchange') && ($show_all_choices)) { 
            if ($env{'form.queue'} eq 'pending') {
                &Apache::lonhtmlcommon::add_breadcrumb
                    ({href=>"/adm/createcourse?phase=pendingdisplay",
@@ -1351,11 +1417,16 @@ sub handler {
            my $js = &courserequestbrowser_javascript();
            my $start_page=&Apache::loncommon::start_page('Display Pending Queue',$js);
            my $crumbs = &Apache::lonhtmlcommon::breadcrumbs('Display Pending Queue','Course_Requests',undef,'Course_Requests');
+           my $context = 'pending';
+           unless ($permission->{'create'}) {
+               $context = 'displaypending';
+           }
            $r->print($start_page.$crumbs."\n".'<div>'.
                      &Apache::loncoursequeueadmin::display_queued_requests(
-                         'pending',$env{'request.role.domain'}).'</div>'.
+                         $context,$env{'request.role.domain'}).'</div>'.
                      &Apache::loncommon::end_page());
-       } elsif (($env{'form.phase'} eq 'requestvalidation') && ($show_all_choices)) {
+       } elsif (($permission->{'create'}) &&
+                ($env{'form.phase'} eq 'requestvalidation') && ($show_all_choices)) { 
            my $js = &courserequestbrowser_javascript();
            &Apache::lonhtmlcommon::add_breadcrumb
                  ({href=>"/adm/createcourse?phase=pendingdisplay",
@@ -1382,7 +1453,7 @@ sub handler {
            &print_creation_logs($r);
            $r->print('</div>'.&Apache::loncommon::end_page());
        } else {
-           &print_intro_page($r,$show_all_choices);
+           &print_intro_page($r,$show_all_choices,\%cancreate,$permission);
        }
    } else {
       $env{'user.error.msg'}=