views.py 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531
  1. # -*- coding: utf-8 -*-
  2. from flask import request, redirect, url_for, abort, \
  3. render_template, flash, json, session, Response, Markup, \
  4. current_app, Blueprint
  5. from flask.ext.babel import gettext as _, get_locale
  6. from flask.ext.mail import Message
  7. from sqlalchemy.sql import func, asc
  8. import itsdangerous
  9. import docutils.core
  10. import ispformat.specs
  11. from datetime import datetime
  12. import locale
  13. locale.setlocale(locale.LC_ALL, '')
  14. from time import time
  15. import os.path
  16. from . import forms, utils
  17. from .constants import STEPS, STEPS_LABELS, LOCALES_FLAGS
  18. from . import db, cache, mail
  19. from .models import ISP, ISPWhoosh, CoveredArea, RegisteredOffice
  20. from .crawler import WebValidator, PrettyValidator
  21. from json import dumps
  22. ispdb = Blueprint('ispdb', __name__)
  23. @ispdb.route('/')
  24. def home():
  25. return render_template('index.html', active_button="home")
  26. @ispdb.route('/embed_map_cube/')
  27. def embed_map_cube():
  28. return render_template('embed_map.html')
  29. @ispdb.route('/isp/')
  30. def project_list():
  31. return render_template('project_list.html', projects=ISP.query.filter_by(is_disabled=False).order_by(asc(func.lower(ISP.name))))
  32. @ispdb.app_errorhandler(404)
  33. def page_not_found(e):
  34. return render_template('404.html'), 404
  35. @ispdb.app_errorhandler(500)
  36. def internal_error(e):
  37. return render_template('500.html'), 500
  38. # this needs to be cached
  39. @ispdb.route('/isp/map_data.json', methods=['GET'])
  40. def isp_map_data():
  41. isps = ISP.query.filter_by(is_disabled=False)
  42. data = []
  43. for isp in isps:
  44. d = dict(isp.json)
  45. for k in d.keys():
  46. if k not in ('name', 'shortname', 'coordinates'):
  47. del d[k]
  48. d['id'] = isp.id
  49. d['ffdn_member'] = isp.is_ffdn_member
  50. d['popup'] = render_template('map_popup.html', isp=isp)
  51. data.append(d)
  52. return Response(dumps(data), mimetype='application/json')
  53. # this needs to be cached
  54. @ispdb.route('/isp/map_data_cube.json', methods=['GET'])
  55. def isp_map_data_cube():
  56. isps = ISP.query.filter_by(is_disabled=False)
  57. data = []
  58. for isp in isps:
  59. d = dict(isp.json)
  60. for k in d.keys():
  61. if k not in ('name', 'shortname', 'coordinates'):
  62. del d[k]
  63. d['id'] = isp.id
  64. d['ffdn_member'] = isp.is_ffdn_member
  65. d['has_vpn'] = isp.has_technology("vpn")
  66. d['distribute_cube'] = isp.has_technology("cube")
  67. d['url'] = isp.json.get("website", "")
  68. d['popup'] = render_template('map_popup.html', isp=isp)
  69. data.append(d)
  70. return Response(json.dumps(data), mimetype='application/json')
  71. @ispdb.route('/isp/find_near.json', methods=['GET'])
  72. def isp_find_near():
  73. lat = request.args.get('lat')
  74. lon = request.args.get('lon')
  75. try:
  76. lat = float(lat)
  77. lon = float(lon)
  78. except (ValueError, TypeError):
  79. abort(400)
  80. q = CoveredArea.containing((lat, lon))\
  81. .options(db.joinedload('isp'))
  82. res = [[{
  83. 'isp_id': ca.isp_id,
  84. 'area': {
  85. 'id': ca.id,
  86. 'name': ca.name,
  87. }
  88. } for ca in q]]
  89. dst = RegisteredOffice.point.distance(db.func.MakePoint(lon, lat), 1).label('distance')
  90. q = db.session.query(RegisteredOffice, dst)\
  91. .options(db.joinedload('isp'))\
  92. .order_by('distance ASC')\
  93. .limit(2)
  94. res.append([{
  95. 'distance': d,
  96. 'isp_id': r.isp.id,
  97. } for r, d in q])
  98. return Response(json.dumps(res))
  99. @ispdb.route('/isp/<projectid>/covered_areas.json', methods=['GET'])
  100. def isp_covered_areas(projectid):
  101. p = ISP.query.filter_by(id=projectid, is_disabled=False)\
  102. .options(db.joinedload('covered_areas'),
  103. db.defer('covered_areas.area'),
  104. db.undefer('covered_areas.area_geojson'))\
  105. .scalar()
  106. if not p:
  107. abort(404)
  108. cas = []
  109. for ca in p.covered_areas:
  110. cas.append({
  111. 'id': ca.id,
  112. 'name': ca.name,
  113. 'area': json.loads(ca.area_geojson) if ca.area_geojson else None
  114. })
  115. return Response(json.dumps(cas), mimetype='application/json')
  116. @ispdb.route('/isp/<projectid>/')
  117. def project(projectid):
  118. p = ISP.query.filter_by(id=projectid, is_disabled=False).first()
  119. if not p:
  120. abort(404)
  121. return render_template('project_detail.html', json = json.dumps(p.json), project_row=p, project=p.json)
  122. @ispdb.route('/isp/<projectid>/edit', methods=['GET', 'POST'])
  123. def edit_project(projectid):
  124. MAX_TOKEN_AGE = 3600
  125. isp = ISP.query.filter_by(id=projectid, is_disabled=False).first_or_404()
  126. sess_token = session.get('edit_tokens', {}).get(isp.id)
  127. if 'token' in request.args:
  128. s = itsdangerous.URLSafeTimedSerializer(current_app.secret_key, salt='edit')
  129. try:
  130. r = s.loads(request.args['token'], max_age=MAX_TOKEN_AGE,
  131. return_timestamp=True)
  132. except:
  133. abort(403)
  134. if r[0] != isp.id:
  135. abort(403)
  136. tokens = session.setdefault('edit_tokens', {})
  137. session.modified = True # ITS A TARP
  138. tokens[r[0]] = r[1]
  139. # refresh page, without the token in the url
  140. return redirect(url_for('.edit_project', projectid=r[0]))
  141. elif (sess_token is None or (datetime.utcnow() - sess_token).total_seconds() > MAX_TOKEN_AGE):
  142. return redirect(url_for('.gen_edit_token', projectid=isp.id))
  143. form = forms.ProjectForm.edit_json(isp)
  144. if form.validate_on_submit():
  145. isp.name = form.name.data
  146. isp.shortname = form.shortname.data or None
  147. isp.json = form.to_json(isp.json)
  148. isp.tech_email = form.tech_email.data
  149. isp.json_url = None
  150. db.session.add(isp)
  151. db.session.commit()
  152. flash(_(u'Project modified'), 'info')
  153. return redirect(url_for('.project', projectid=isp.id))
  154. return render_template('edit_project_form.html', form=form, isp=isp)
  155. @ispdb.route('/isp/<projectid>/edit_json_url', methods=['GET', 'POST'])
  156. def edit_project_auto_update(projectid):
  157. MAX_TOKEN_AGE = 3600
  158. isp = ISP.query.filter_by(id=projectid, is_disabled=False).first_or_404()
  159. sess_token = session.get('edit_tokens', {}).get(isp.id)
  160. if 'token' in request.args:
  161. s = itsdangerous.URLSafeTimedSerializer(current_app.secret_key, salt='edit')
  162. try:
  163. r = s.loads(request.args['token'], max_age=MAX_TOKEN_AGE,
  164. return_timestamp=True)
  165. except:
  166. abort(403)
  167. if r[0] != isp.id:
  168. abort(403)
  169. tokens = session.setdefault('edit_tokens', {})
  170. session.modified = True # ITS A TARP
  171. tokens[r[0]] = r[1]
  172. # refresh page, without the token in the url
  173. return redirect(url_for('.edit_project', projectid=r[0]))
  174. elif (sess_token is None or (datetime.utcnow() - sess_token).total_seconds() > MAX_TOKEN_AGE):
  175. return redirect(url_for('.gen_edit_token', projectid=isp.id))
  176. form = forms.ProjectJSONForm(obj=isp)
  177. if form.validate_on_submit():
  178. isp.tech_email = form.tech_email.data
  179. url = utils.make_ispjson_url(form.json_url.data)
  180. isp.json_url = url
  181. db.session.add(isp)
  182. db.session.commit()
  183. flash(_(u'Project modified'), 'info')
  184. return redirect(url_for('.project', projectid=isp.id))
  185. return render_template('edit_project_json_form.html', form=form, isp=isp)
  186. @ispdb.route('/isp/<projectid>/gen_edit_token', methods=['GET', 'POST'])
  187. def gen_edit_token(projectid):
  188. isp = ISP.query.filter_by(id=projectid, is_disabled=False).first_or_404()
  189. form = forms.RequestEditToken()
  190. if form.validate_on_submit(): # validated
  191. if form.tech_email.data == isp.tech_email:
  192. s = itsdangerous.URLSafeTimedSerializer(current_app.secret_key, salt='edit')
  193. token = s.dumps(isp.id)
  194. msg = Message("Edit request of your ISP", sender=current_app.config['EMAIL_SENDER'])
  195. msg.body = """
  196. Hello,
  197. You are receiving this message because your are listed as technical contact for "%s" on the FFDN ISP database.
  198. Someone asked to edit your ISP's data in our database. If it's not you, please ignore this message.
  199. To proceed to the editing form, please click on the following link:
  200. %s?token=%s
  201. Note: the link is only valid for one hour from the moment we send you this email.
  202. Thanks,
  203. The FFDN ISP Database team
  204. https://db.ffdn.org
  205. """.strip() % (isp.complete_name,
  206. url_for('.edit_project', projectid=isp.id, _external=True),
  207. token)
  208. msg.add_recipient(isp.tech_email)
  209. mail.send(msg)
  210. # if the email provided is not the correct one, we still redirect
  211. flash(_(u'If you provided the correct email adress, '
  212. 'you must will receive a message shortly (check your spam folder)'), 'info')
  213. return redirect(url_for('.project', projectid=isp.id))
  214. return render_template('gen_edit_token.html', form=form)
  215. @ispdb.route('/add-a-project', methods=['GET'])
  216. def add_project():
  217. return render_template('add_project.html')
  218. @ispdb.route('/isp/create/form', methods=['GET', 'POST'])
  219. def create_project_form():
  220. form = forms.ProjectForm()
  221. if form.validate_on_submit():
  222. isp = ISP()
  223. isp.name = form.name.data
  224. isp.shortname = form.shortname.data or None
  225. isp.tech_email = form.tech_email.data
  226. isp.json = form.to_json(isp.json)
  227. db.session.add(isp)
  228. db.session.commit()
  229. flash(_(u'Project created'), 'info')
  230. return redirect(url_for('.project', projectid=isp.id))
  231. return render_template('add_project_form.html', form=form)
  232. @ispdb.route('/isp/create/validator', methods=['GET'])
  233. def json_url_validator():
  234. if 'form_json' not in session or \
  235. session['form_json'].get('validated', False):
  236. abort(403)
  237. v = session['form_json'].get('validator')
  238. if v is not None:
  239. if v > time() - 5:
  240. abort(429)
  241. else:
  242. session['form_json']['validator'] = time()
  243. validator = WebValidator(session._get_current_object(), 'form_json')
  244. return Response(utils.stream_with_ctx_and_exc(
  245. validator(session['form_json']['url'])
  246. ), mimetype="text/event-stream")
  247. @ispdb.route('/isp/create', methods=['GET', 'POST'])
  248. def create_project_json():
  249. form = forms.ProjectJSONForm()
  250. if form.validate_on_submit():
  251. url = utils.make_ispjson_url(form.json_url.data)
  252. session['form_json'] = {'url': url, 'tech_email': form.tech_email.data}
  253. return render_template('project_json_validator.html')
  254. return render_template('add_project_json_form.html', form=form)
  255. @ispdb.route('/isp/create/confirm', methods=['POST'])
  256. def create_project_json_confirm():
  257. if 'form_json' in session and session['form_json'].get('validated', False):
  258. if not forms.is_url_unique(session['form_json']['url']):
  259. abort(409)
  260. jdict = session['form_json']['jdict']
  261. isp = ISP()
  262. isp.name = jdict['name']
  263. if 'shortname' in jdict:
  264. isp.shortname = jdict['shortname']
  265. isp.json_url = session['form_json']['url']
  266. isp.json = jdict
  267. isp.tech_email = session['form_json']['tech_email']
  268. isp.last_update_attempt = session['form_json']['last_update']
  269. isp.last_update_success = session['form_json']['last_update']
  270. isp.next_update = session['form_json']['next_update']
  271. isp.cache_info = session['form_json']['cache_info']
  272. del session['form_json']
  273. db.session.add(isp)
  274. db.session.commit()
  275. flash(_(u'Project created'), 'info')
  276. return redirect(url_for('.project', projectid=isp.id))
  277. else:
  278. return redirect(url_for('.create_project_json'))
  279. @ispdb.route('/isp/reactivate-validator', methods=['GET'])
  280. def reactivate_validator():
  281. if 'form_reactivate' not in session or \
  282. session['form_reactivate'].get('validated', False):
  283. abort(403)
  284. p = ISP.query.get(session['form_reactivate']['isp_id'])
  285. if not p:
  286. abort(403)
  287. v = session['form_reactivate'].get('validator')
  288. if v is not None:
  289. if v > time() - 5:
  290. abort(429)
  291. else:
  292. session['form_reactivate']['validator'] = time()
  293. validator = PrettyValidator(session._get_current_object(), 'form_reactivate')
  294. return Response(utils.stream_with_ctx_and_exc(
  295. validator(p.json_url, p.cache_info or {})
  296. ), mimetype="text/event-stream")
  297. @ispdb.route('/isp/<projectid>/reactivate', methods=['GET', 'POST'])
  298. def reactivate_isp(projectid):
  299. """
  300. Allow to reactivate an ISP after it has been disabled
  301. because of problems with the JSON file.
  302. """
  303. p = ISP.query.filter(ISP.id == projectid, ISP.is_disabled == False,
  304. ISP.update_error_strike >= 3).first_or_404()
  305. if request.method == 'GET':
  306. key = request.args.get('key')
  307. try:
  308. s = itsdangerous.URLSafeSerializer(current_app.secret_key,
  309. salt='reactivate')
  310. d = s.loads(key)
  311. except Exception:
  312. abort(403)
  313. if (len(d) != 2 or d[0] != p.id or d[1] != str(p.last_update_attempt)):
  314. abort(403)
  315. session['form_reactivate'] = {'isp_id': p.id}
  316. return render_template('reactivate_validator.html', isp=p)
  317. else:
  318. if 'form_reactivate' not in session or \
  319. not session['form_reactivate'].get('validated', False):
  320. abort(409)
  321. p = ISP.query.get(session['form_reactivate']['isp_id'])
  322. p.json = session['form_reactivate']['jdict']
  323. p.cache_info = session['form_reactivate']['cache_info']
  324. p.last_update_attempt = session['form_reactivate']['last_update']
  325. p.last_update_success = p.last_update_attempt
  326. p.update_error_strike = 0
  327. db.session.add(p)
  328. db.session.commit()
  329. flash(_(u'Automatic updates activated'), 'info')
  330. return redirect(url_for('.project', projectid=p.id))
  331. @ispdb.route('/search', methods=['GET', 'POST'])
  332. def search():
  333. terms = request.args.get('q')
  334. if not terms:
  335. return redirect(url_for('.home'))
  336. res = ISPWhoosh.search(terms)
  337. return render_template('search_results.html', results=res, search_terms=terms)
  338. @ispdb.route('/format', methods=['GET'])
  339. def format():
  340. cache.clear()
  341. parts = cache.get('format-spec')
  342. if parts is None:
  343. spec = open(ispformat.specs.versions[0.2]).read()
  344. overrides = {
  345. 'initial_header_level': 3,
  346. }
  347. parts = docutils.core.publish_parts(
  348. spec,
  349. source_path=os.path.dirname(ispformat.specs.versions[0.2]),
  350. destination_path=None, writer_name='html',
  351. settings_overrides=overrides
  352. )
  353. cache.set('format-spec', parts, timeout=60 * 60 * 24)
  354. return render_template('format_spec.html', spec=Markup(parts['html_body']))
  355. @ispdb.route('/api/v1/', methods=['GET'])
  356. def api():
  357. return render_template('api.html')
  358. @ispdb.route('/humans.txt', methods=['GET'])
  359. def humans():
  360. import os.path
  361. authors_file = os.path.join(os.path.dirname(__file__), '../AUTHORS')
  362. return Response(open(authors_file), mimetype='text/plain; charset=utf-8')
  363. @ispdb.route('/site.js', methods=['GET'])
  364. def site_js():
  365. l = get_locale()
  366. js_i18n = cache.get('site_js_%s' % (l,))
  367. if not js_i18n:
  368. js_i18n = render_template('site.js')
  369. cache.set('site_js_%s' % (l,), js_i18n, timeout=60 * 60)
  370. r = Response(js_i18n, headers={
  371. 'Content-type': 'application/javascript',
  372. 'Cache-control': 'private, max-age=3600'
  373. })
  374. r.add_etag()
  375. r.make_conditional(request)
  376. return r
  377. @ispdb.route('/site_embed.js', methods=['GET'])
  378. def site_embed_js():
  379. l = get_locale()
  380. js_i18n = cache.get('site_embed_js_%s' % (l,))
  381. if not js_i18n:
  382. js_i18n = render_template('site_embed.js')
  383. cache.set('site_embed_js_%s' % (l,), js_i18n, timeout=60 * 60)
  384. r = Response(js_i18n, headers={
  385. 'Content-type': 'application/javascript',
  386. 'Cache-control': 'private, max-age=3600'
  387. })
  388. r.add_etag()
  389. r.make_conditional(request)
  390. return r
  391. @ispdb.route('/locale_selector', methods=['GET', 'POST'])
  392. def locale_selector():
  393. l = current_app.config['LANGUAGES']
  394. if request.method == 'POST' and request.form.get('locale') in l:
  395. resp = redirect(url_for('.home'))
  396. resp.set_cookie('locale', request.form['locale'])
  397. return resp
  398. return render_template('locale_selector.html', locales=(
  399. (code, LOCALES_FLAGS[code], name) for code, name in l.iteritems()
  400. ))
  401. #------
  402. # Filters
  403. @ispdb.app_template_filter('step_to_label')
  404. def step_to_label(step):
  405. if step:
  406. return u"<a href='#' data-toggle='tooltip' data-placement='right' title='" + STEPS[step] + "'><span class='badge badge-" + STEPS_LABELS[step] + "'>" + str(step) + "</span></a>"
  407. else:
  408. return u'-'
  409. @ispdb.app_template_filter('stepname')
  410. def stepname(step):
  411. return STEPS[step]
  412. @ispdb.app_template_filter('js_str')
  413. def json_filter(v):
  414. return Markup(json.dumps(unicode(v)))
  415. @ispdb.app_template_filter('locale_flag')
  416. def locale_flag(l):
  417. return LOCALES_FLAGS.get(str(l), '_unknown')
  418. @ispdb.app_template_global('current_locale')
  419. def current_locale():
  420. return get_locale()