utils.py 4.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157
  1. from datetime import datetime, timedelta
  2. from django.conf import settings
  3. from django.core.exceptions import PermissionDenied
  4. from django.http import Http404
  5. from django.urls import resolve, reverse
  6. from django.utils import html, timezone
  7. from django.utils.encoding import force_text
  8. from django.utils.module_loading import import_string
  9. ANONYMOUS_IP = '0.0.0.0'
  10. MISAGO_SLUGIFY = getattr(settings, 'MISAGO_SLUGIFY', 'misago.core.slugify.default')
  11. slugify = import_string(MISAGO_SLUGIFY)
  12. def format_plaintext_for_html(string):
  13. return html.linebreaks(html.urlize(html.escape(string)))
  14. def encode_json_html(string):
  15. return string.replace('<', r'\u003C')
  16. ISO8601_FORMATS = ("%Y-%m-%dT%H:%M:%S", "%Y-%m-%dT%H:%M:%S.%f", )
  17. def parse_iso8601_string(value):
  18. """turns ISO 8601 string into datetime object"""
  19. value = force_text(value, strings_only=True).rstrip('Z')
  20. for format in ISO8601_FORMATS:
  21. try:
  22. parsed_value = datetime.strptime(value, format)
  23. break
  24. except ValueError:
  25. try:
  26. parsed_value = datetime.strptime(value[:-6], format)
  27. break
  28. except ValueError:
  29. pass
  30. else:
  31. raise ValueError('failed to hydrate the %s timestamp' % value)
  32. offset_str = value[-6:]
  33. if offset_str and offset_str[0] in ('-', '+'):
  34. tz_offset = timedelta(hours=int(offset_str[1:3]), minutes=int(offset_str[4:6]))
  35. tz_offset = tz_offset.seconds // 60
  36. if offset_str[0] == '-':
  37. tz_offset *= -1
  38. else:
  39. tz_offset = 0
  40. tz_correction = timezone.get_fixed_timezone(tz_offset)
  41. return timezone.make_aware(parsed_value, tz_correction)
  42. def hide_post_parameters(request):
  43. """
  44. Mark request as having sensitive parameters
  45. We can't use decorator because of DRF uses custom HttpRequest
  46. that is incompatibile with Django's decorator
  47. """
  48. request.sensitive_post_parameters = '__ALL__'
  49. def clean_return_path(request):
  50. """return path utility that returns return path from referer or POST"""
  51. if request.method == 'POST' and 'return_path' in request.POST:
  52. return _get_return_path_from_post(request)
  53. else:
  54. return _get_return_path_from_referer(request)
  55. def _get_return_path_from_post(request):
  56. return_path = request.POST.get('return_path')
  57. try:
  58. if not return_path:
  59. raise ValueError()
  60. if not return_path.startswith('/'):
  61. raise ValueError()
  62. resolve(return_path)
  63. return return_path
  64. except (Http404, ValueError):
  65. return None
  66. def _get_return_path_from_referer(request):
  67. referer = request.META.get('HTTP_REFERER')
  68. try:
  69. if not referer:
  70. raise ValueError()
  71. if not referer.startswith(request.scheme):
  72. raise ValueError()
  73. referer = referer[len(request.scheme) + 3:]
  74. if not referer.startswith(request.META['HTTP_HOST']):
  75. raise ValueError()
  76. referer = referer[len(request.META['HTTP_HOST'].rstrip('/')):]
  77. if not referer.startswith('/'):
  78. raise ValueError()
  79. resolve(referer)
  80. return referer
  81. except (Http404, KeyError, ValueError):
  82. return None
  83. def is_request_to_misago(request):
  84. try:
  85. return request._request_to_misago
  86. except AttributeError:
  87. request._request_to_misago = _is_request_path_under_misago(request)
  88. return request._request_to_misago
  89. def _is_request_path_under_misago(request):
  90. # We are assuming that forum_index link is root of all Misago links
  91. forum_index = reverse('misago:index')
  92. path = request.path
  93. if len(forum_index) > len(path):
  94. return False
  95. return path[:len(forum_index)] == forum_index
  96. def is_referer_local(request):
  97. referer = request.META.get('HTTP_REFERER')
  98. if not referer:
  99. return False
  100. if not referer.startswith(request.scheme):
  101. return False
  102. referer = referer[len(request.scheme) + 3:]
  103. if not referer.startswith(request.META['HTTP_HOST']):
  104. return False
  105. referer = referer[len(request.META['HTTP_HOST'].rstrip('/')):]
  106. if not referer.startswith('/'):
  107. return False
  108. return True
  109. def get_exception_message(exception=None, default_message=None):
  110. if not exception:
  111. return default_message
  112. try:
  113. return exception.args[0]
  114. except IndexError:
  115. return default_message
  116. def clean_ids_list(ids_list, error_message):
  117. try:
  118. return list(map(int, ids_list))
  119. except (ValueError, TypeError):
  120. raise PermissionDenied(error_message)