views.py 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394
  1. # -*- coding: utf-8 -*-
  2. from flask import request, g, redirect, url_for, abort, \
  3. render_template, flash, json, session, Response, Markup
  4. from flask.ext.babel import gettext as _
  5. from flask.ext.mail import Message
  6. import itsdangerous
  7. import docutils.core
  8. import ispformat.specs
  9. from datetime import date, time, timedelta, datetime
  10. from urlparse import urlunsplit
  11. import locale
  12. locale.setlocale(locale.LC_ALL, '')
  13. from time import time
  14. import os.path
  15. from . import forms
  16. from .constants import *
  17. from . import app, db, cache, mail
  18. from .models import ISP, ISPWhoosh, CoveredArea, RegisteredOffice
  19. from .crawler import WebValidator, PrettyValidator
  20. @app.route('/')
  21. def home():
  22. return render_template('index.html', active_button="home")
  23. @app.route('/isp/')
  24. def project_list():
  25. return render_template('project_list.html', projects=ISP.query.filter_by(is_disabled=False))
  26. # this needs to be cached
  27. @app.route('/isp/map_data.json', methods=['GET'])
  28. def isp_map_data():
  29. isps=ISP.query.filter_by(is_disabled=False)
  30. data=[]
  31. for isp in isps:
  32. d=dict(isp.json)
  33. for k in d.keys():
  34. if k not in ('name', 'shortname', 'coordinates'):
  35. del d[k]
  36. d['id']=isp.id
  37. d['ffdn_member']=isp.is_ffdn_member
  38. d['popup']=render_template('map_popup.html', isp=isp)
  39. data.append(d)
  40. return Response(json.dumps(data), mimetype='application/json')
  41. @app.route('/isp/find_near.json', methods=['GET'])
  42. def isp_find_near():
  43. lat=request.args.get('lat')
  44. lon=request.args.get('lon')
  45. try:
  46. lat=float(lat)
  47. lon=float(lon)
  48. except (ValueError, TypeError):
  49. abort(400)
  50. q=CoveredArea.containing((lat,lon))\
  51. .options(db.joinedload('isp'))
  52. res=[[{
  53. 'isp_id': ca.isp_id,
  54. 'area': {
  55. 'id': ca.id,
  56. 'name': ca.name,
  57. }
  58. } for ca in q]]
  59. d=RegisteredOffice.point.distance(db.func.MakePoint(lon, lat), 1).label('distance')
  60. q=db.session.query(RegisteredOffice, d)\
  61. .options(db.joinedload('isp'))\
  62. .order_by('distance ASC')\
  63. .limit(2)
  64. res.append([{
  65. 'distance': d,
  66. 'isp_id': r.isp.id,
  67. } for r, d in q])
  68. return Response(json.dumps(res))
  69. @app.route('/isp/<projectid>/covered_areas.json', methods=['GET'])
  70. def isp_covered_areas(projectid):
  71. p=ISP.query.filter_by(id=projectid, is_disabled=False)\
  72. .options(db.joinedload('covered_areas'),
  73. db.defer('covered_areas.area'),
  74. db.undefer('covered_areas.area_geojson'))\
  75. .scalar()
  76. if not p:
  77. abort(404)
  78. cas=[]
  79. for ca in p.covered_areas:
  80. cas.append({
  81. 'id': ca.id,
  82. 'name': ca.name,
  83. 'area': json.loads(ca.area_geojson) if ca.area_geojson else None
  84. })
  85. return Response(json.dumps(cas), mimetype='application/json')
  86. @app.route('/isp/<projectid>/')
  87. def project(projectid):
  88. p=ISP.query.filter_by(id=projectid, is_disabled=False).first()
  89. if not p:
  90. abort(404)
  91. return render_template('project_detail.html', project_row=p, project=p.json)
  92. @app.route('/isp/<projectid>/edit', methods=['GET', 'POST'])
  93. def edit_project(projectid):
  94. MAX_TOKEN_AGE=3600
  95. isp=ISP.query.filter_by(id=projectid, is_disabled=False).first_or_404()
  96. sess_token=session.get('edit_tokens', {}).get(isp.id)
  97. if 'token' in request.args:
  98. print session
  99. s = itsdangerous.URLSafeTimedSerializer(app.secret_key, salt='edit')
  100. try:
  101. r = s.loads(request.args['token'], max_age=MAX_TOKEN_AGE,
  102. return_timestamp=True)
  103. except:
  104. abort(403)
  105. if r[0] != isp.id:
  106. abort(403)
  107. tokens = session.setdefault('edit_tokens', {})
  108. tokens[r[0]] = r[1]
  109. # refresh page, without the token in the url
  110. return redirect(url_for('edit_project', projectid=r[0]))
  111. elif (sess_token is None or (datetime.utcnow()-sess_token).total_seconds() > MAX_TOKEN_AGE):
  112. return redirect(url_for('gen_edit_token', projectid=isp.id))
  113. if isp.is_local:
  114. form = forms.ProjectForm.edit_json(isp)
  115. if form.validate_on_submit():
  116. isp.name = form.name.data
  117. isp.shortname = form.shortname.data or None
  118. isp.json = form.to_json(isp.json)
  119. isp.tech_email = form.tech_email.data
  120. db.session.add(isp)
  121. db.session.commit()
  122. flash(_(u'Project modified'), 'info')
  123. return redirect(url_for('project', projectid=isp.id))
  124. return render_template('edit_project_form.html', form=form)
  125. else:
  126. form = forms.ProjectJSONForm(obj=isp)
  127. if form.validate_on_submit():
  128. isp.tech_email = form.tech_email.data
  129. u = list(form.json_url.data)
  130. u[2]='/isp.json' # new path
  131. url=urlunsplit(u)
  132. isp.json_url = url
  133. db.session.add(isp)
  134. db.session.commit()
  135. flash(_(u'Project modified'), 'info')
  136. return redirect(url_for('project', projectid=isp.id))
  137. return render_template('edit_project_json_form.html', form=form)
  138. @app.route('/isp/<projectid>/gen_edit_token', methods=['GET', 'POST'])
  139. def gen_edit_token(projectid):
  140. isp=ISP.query.filter_by(id=projectid, is_disabled=False).first_or_404()
  141. form = forms.RequestEditToken()
  142. if form.validate_on_submit(): # validated
  143. if form.tech_email.data == isp.tech_email:
  144. s = itsdangerous.URLSafeTimedSerializer(app.secret_key, salt='edit')
  145. token = s.dumps(isp.id)
  146. msg = Message("Edit request of your ISP", sender=app.config['EMAIL_SENDER'])
  147. msg.body="""
  148. Hello,
  149. You are receiving this message because your are listed as technical contact for "%s" on the FFDN ISP database.
  150. Someone asked to edit your ISP's data in our database. If it's not you, please ignore this message.
  151. To proceed to the editing form, please click on the following link:
  152. %s?token=%s
  153. Note: the link is only valid for one hour from the moment we send you this email.
  154. Thanks,
  155. The FFDN ISP Database team
  156. https://db.ffdn.org
  157. """.strip() % (isp.complete_name,
  158. url_for('edit_project', projectid=isp.id, _external=True),
  159. token)
  160. msg.add_recipient(isp.tech_email)
  161. mail.send(msg)
  162. # if the email provided is not the correct one, we still redirect
  163. flash(_(u'If you provided the correct email adress, '
  164. 'you must will receive a message shortly (check your spam folder)'), 'info')
  165. return redirect(url_for('project', projectid=isp.id))
  166. return render_template('gen_edit_token.html', form=form)
  167. @app.route('/add-a-project', methods=['GET'])
  168. def add_project():
  169. return render_template('add_project.html')
  170. @app.route('/isp/create/form', methods=['GET', 'POST'])
  171. def create_project_form():
  172. form = forms.ProjectForm()
  173. if form.validate_on_submit():
  174. isp=ISP()
  175. isp.name = form.name.data
  176. isp.shortname = form.shortname.data or None
  177. isp.tech_email = form.tech_email.data
  178. isp.json=form.to_json(isp.json)
  179. db.session.add(isp)
  180. db.session.commit()
  181. flash(_(u'Project created'), 'info')
  182. return redirect(url_for('project', projectid=isp.id))
  183. return render_template('add_project_form.html', form=form)
  184. @app.route('/isp/create/validator', methods=['GET'])
  185. def json_url_validator():
  186. if 'form_json' not in session or \
  187. session['form_json'].get('validated', False):
  188. abort(403)
  189. v=session['form_json'].get('validator')
  190. if v is not None:
  191. if v > time()-5:
  192. abort(429)
  193. else:
  194. session['form_json']['validator']=time()
  195. validator=WebValidator(session._get_current_object(), 'form_json')
  196. return Response(validator(session['form_json']['url']),
  197. mimetype="text/event-stream")
  198. @app.route('/isp/create', methods=['GET', 'POST'])
  199. def create_project_json():
  200. form = forms.ProjectJSONForm()
  201. if form.validate_on_submit():
  202. u=list(form.json_url.data)
  203. u[2]='/isp.json' # new path
  204. url=urlunsplit(u)
  205. session['form_json'] = {'url': url, 'tech_email': form.tech_email.data}
  206. return render_template('project_json_validator.html')
  207. return render_template('add_project_json_form.html', form=form)
  208. @app.route('/isp/create/confirm', methods=['POST'])
  209. def create_project_json_confirm():
  210. if 'form_json' in session and session['form_json'].get('validated', False):
  211. if not forms.is_url_unique(session['form_json']['url']):
  212. abort(409)
  213. jdict=session['form_json']['jdict']
  214. isp=ISP()
  215. isp.name=jdict['name']
  216. if 'shortname' in jdict:
  217. isp.shortname=jdict['shortname']
  218. isp.json_url=session['form_json']['url']
  219. isp.json=jdict
  220. isp.tech_email=session['form_json']['tech_email']
  221. isp.last_update_success=session['form_json']['last_update']
  222. isp.next_update=session['form_json']['next_update']
  223. isp.cache_info=session['form_json']['cache_info']
  224. del session['form_json']
  225. db.session.add(isp)
  226. db.session.commit()
  227. flash(_(u'Project created'), 'info')
  228. return redirect(url_for('project', projectid=isp.id))
  229. else:
  230. return redirect(url_for('create_project_json'))
  231. @app.route('/isp/reactivate-validator', methods=['GET'])
  232. def reactivate_validator():
  233. if 'form_reactivate' not in session or \
  234. session['form_reactivate'].get('validated', False):
  235. abort(403)
  236. p=ISP.query.get(session['form_reactivate']['isp_id'])
  237. if not p:
  238. abort(403)
  239. v=session['form_reactivate'].get('validator')
  240. if v is not None:
  241. if v > time()-5:
  242. abort(429)
  243. else:
  244. session['form_reactivate']['validator']=time()
  245. validator=PrettyValidator(session._get_current_object(), 'form_reactivate')
  246. return Response(validator(p.json_url, p.cache_info or {}),
  247. mimetype="text/event-stream")
  248. @app.route('/isp/<projectid>/reactivate', methods=['GET', 'POST'])
  249. def reactivate_isp(projectid):
  250. """
  251. Allow to reactivate an ISP after it has been disabled
  252. because of problems with the JSON file.
  253. """
  254. p=ISP.query.filter(ISP.id==projectid, ISP.is_disabled==False,
  255. ISP.update_error_strike>=3).first_or_404()
  256. if request.method == 'GET':
  257. key = request.args.get('key')
  258. try:
  259. s=itsdangerous.URLSafeSerializer(app.secret_key,
  260. salt='reactivate')
  261. d=s.loads(key)
  262. except Exception as e:
  263. abort(403)
  264. if (len(d) != 2 or d[0] != p.id or
  265. d[1] != str(p.last_update_attempt)):
  266. abort(403)
  267. session['form_reactivate'] = {'isp_id': p.id}
  268. return render_template('reactivate_validator.html', isp=p)
  269. else:
  270. if 'form_reactivate' not in session or \
  271. not session['form_reactivate'].get('validated', False):
  272. abort(409)
  273. p=ISP.query.get(session['form_reactivate']['isp_id'])
  274. p.json=session['form_reactivate']['jdict']
  275. p.cache_info=session['form_reactivate']['cache_info']
  276. p.last_update_attempt=datetime.now()
  277. p.last_update_success=p.last_update_attempt
  278. db.session.add(p)
  279. db.session.commit()
  280. flash(_(u'Automatic updates activated'), 'info')
  281. return redirect(url_for('project', projectid=p.id))
  282. @app.route('/search', methods=['GET', 'POST'])
  283. def search():
  284. terms=request.args.get('q')
  285. if not terms:
  286. return redirect(url_for('home'))
  287. res=ISPWhoosh.search(terms)
  288. return render_template('search_results.html', results=res, search_terms=terms)
  289. @app.route('/format', methods=['GET'])
  290. def format():
  291. parts = cache.get('format-spec')
  292. if parts is None:
  293. spec=open(ispformat.specs.versions[0.1]).read()
  294. overrides = {
  295. 'initial_header_level' : 3,
  296. }
  297. parts = docutils.core.publish_parts(spec,
  298. source_path=os.path.dirname(ispformat.specs.versions[0.1]),
  299. destination_path=None, writer_name='html',
  300. settings_overrides=overrides)
  301. cache.set('format-spec', parts, timeout=60*60*24)
  302. return render_template('format_spec.html', spec=Markup(parts['html_body']))
  303. @app.route('/humans.txt', methods=['GET'])
  304. def humans():
  305. import os.path
  306. authors_file=os.path.join(os.path.dirname(__file__), '../AUTHORS')
  307. return Response(open(authors_file), mimetype='text/plain; charset=utf-8')
  308. #------
  309. # Filters
  310. @app.template_filter('step_to_label')
  311. def step_to_label(step):
  312. if step:
  313. return u"<a href='#' rel='tooltip' data-placement='right' title='" + STEPS[step] + "'><span class='badge badge-" + STEPS_LABELS[step] + "'>" + str(step) + "</span></a>"
  314. else:
  315. return u'-'
  316. @app.template_filter('stepname')
  317. def stepname(step):
  318. return STEPS[step]