From: Douglas Seifert Date: 2009-05-10T03:14:29+09:00 Subject: Re: CGI help --0015175770b2333a3c04697eb707 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit > > [jleggett@binford cgi-bin]$ cat classification.txt > Access Control,access,High,0,Medium,5,Low,10 > Authentication,auth,High,0,Medium,5,Low,10 > Confidentiality Impact,confi,High,10,Medium,5,Low,0 > Confidentiality modifier,confm,Employee Data,30,Customer > Data,20,System/network Data,10,application metadata,5,N/A,0 > integrity impact,integi,High,10,Medium,5,Low,0 > integrity modifier,integm,System/Application,30,Customer > Information,20,Employee Info,30,Individual Info,10,N/A,0 > Availability Impact,avail,High,10,medium,5,Low,0 > [jleggett@binford cgi-bin]$ > > OK, after figuring out how CGI works in ruby ... there are some problems with your original code: 1) cgi.body { cgi.h1 { TITLE } } The above will generate a body tag with a h1 tag and then close the body. I think you wanted to defer that closing brace until after the form was generated. 2) The block passed to the form method must evaluate to a string which will be the form's contents. Your block will evaluate to the return value of File.close (because this is the last statement executed by the block). close returns nil, which when coerced to a string would be "" (the empty string). Thus, your form will have no content. 3) popup_menu takes a String as the first argument which is the name of the select tag and then an arbitrary number of arguments representing the options. I think you want to use Arrays as the arguments because you want to specify an option value and option name. The code you wrote does not do that. It just passes a big string to popup_menu as a single argument. 4) You are mixing puts with generating strings inside the CGI tag method blocks. You need to make sure you don't use puts as it will corrupt the HTML generated by the script by outputting stuff you don't want output. I took a stab at correcting all these problems, and changed some minor things, but didn't really try to rubyfy the code: require "cgi" Filename = 'classification.txt' EMPTY_STRING = '' TITLE = 'Vulnerability Classification' cgi = CGI.new('html4') output = cgi.html do cgi.head { cgi.title { TITLE } } + cgi.body do cgi.h1 { TITLE } + cgi.form('post') do form_contents = "" if File.readable?(Filename) then # Use the version of File#open that takes a block. That # way you don't have to worry about closing the file after # you are done with it -- it will happen automatically when # the block is done executing File.open(Filename,"r") do |f| f.each_line do |l| # Need to use chomp! instead of plain chomp to # ensure l is actually changed. Otherwise, we just # create and throw away a new string l.chomp! inputs = l.split(',') form_contents << inputs[0] + ": " select_name = inputs[1] select_opts = [] 2.times { inputs.delete_at(0) } until inputs.empty? do select_opts << [inputs[1], inputs[0]] 2.times { inputs.delete_at(0) } end form_contents << cgi.popup_menu(select_name, *select_opts) + cgi.br end end end form_contents + cgi.submit end end end --0015175770b2333a3c04697eb707--