#!/bin/sh

IP=$(uci -q get network.lan.ipaddr || echo "192.168.1.1")
IP="${IP%%/*}"

# Check if wizard is complete or password is set
wiz=$(uci -q get wizard.default.wizard_complete)
pass=$(awk -F: '/^root:/ {print $2}' /etc/shadow 2>/dev/null)
if [ "$wiz" = "1" ] || [ -n "$pass" ]; then
  # Trigger captive portal cleanup (once)
  if [ -f /tmp/captive-portal-active ]; then
    rm -f /tmp/captive-portal-active
    ( /etc/init.d/wizard reload ) &
  fi
  # Wizard done — respond as "no captive portal" to OS checks
  case "$REQUEST_URI" in
    */generate_204|*/gen_204|*/generate_204_204*|*/check_network_v2*)
      echo "Status: 204 No Content"
      echo ""
      exit 0
      ;;
    */hotspot-detect*|*/library/test/success*)
      echo "Content-Type: text/html"
      echo ""
      echo "<HTML><HEAD><TITLE>Success</TITLE></HEAD><BODY>Success</BODY></HTML>"
      exit 0
      ;;
    */connecttest.txt)
      echo "Content-Type: text/plain"
      echo ""
      echo "Microsoft Connect Test"
      exit 0
      ;;
    */ncsi.txt)
      echo "Content-Type: text/plain"
      echo ""
      echo "Microsoft NCSI"
      exit 0
      ;;
    */canonical.html|*/success.txt)
      echo "Content-Type: text/plain"
      echo ""
      echo "success"
      exit 0
      ;;
  esac
  # Non-captive request — normal 404
  echo "Status: 404 Not Found"
  echo "Content-Type: text/html"
  echo ""
  echo "<html><body><h1>404</h1></body></html>"
  exit 0
fi

# Direct request to router IP — normal 404
case "$HTTP_HOST" in
  "$IP"|"$IP:"*)
    echo "Status: 404 Not Found"
    echo "Content-Type: text/html"
    echo ""
    echo "<html><body><h1>404</h1></body></html>"
    exit 0
    ;;
esac

# Build wizard URL with session
build_wizard_url() {
  url="http://${IP}/luci-static/resources/wizard.html?v=1.4.0"
  sid=$(ubus call session login '{"username":"root","password":""}' 2>/dev/null | jsonfilter -e '@.ubus_rpc_session')
  [ -n "$sid" ] && url="${url}&sid=${sid}"
  echo "$url"
}

# OS/browser captive detection endpoints — 302 redirect
case "$REQUEST_URI" in
  */generate_204|*/gen_204)
    # Android / Chrome / ChromeOS
    echo "Status: 302 Found"
    echo "Location: $(build_wizard_url)"
    echo ""
    exit 0
    ;;
  */hotspot-detect*|*/library/test/success*)
    # Apple iOS / macOS
    echo "Status: 302 Found"
    echo "Location: $(build_wizard_url)"
    echo ""
    exit 0
    ;;
  */connecttest.txt|*/ncsi.txt)
    # Microsoft Windows NCSI check
    echo "Status: 302 Found"
    echo "Location: $(build_wizard_url)"
    echo ""
    exit 0
    ;;
  */canonical.html|*/success.txt)
    # Firefox / Brave
    echo "Status: 302 Found"
    echo "Location: $(build_wizard_url)"
    echo ""
    exit 0
    ;;
  */check_network_v2*|*/generate_204_204*)
    # Samsung / Xiaomi / Huawei / Vivo
    echo "Status: 302 Found"
    echo "Location: $(build_wizard_url)"
    echo ""
    exit 0
    ;;
esac

# Everything else — serve captive landing page
echo "Content-Type: text/html; charset=utf-8"
echo ""
wizard_url=$(build_wizard_url)
wizard_url_escaped=$(printf '%s' "$wizard_url" | sed 's/&/\\\&/g')
sed "s|WIZARD_URL|$wizard_url_escaped|g" /www/luci-static/resources/captive-redirect.html
