views.py 4.6 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798
  1. from django.core.urlresolvers import reverse
  2. from django.shortcuts import redirect
  3. from django.template import RequestContext
  4. from django.utils import timezone
  5. from django.utils.translation import ugettext as _
  6. from misago.admin import site
  7. from misago.banning.decorators import block_banned
  8. from misago.forms.layouts import FormLayout
  9. from misago.messages import Message
  10. from misago.security import get_random_string
  11. import misago.security.auth as auth
  12. from misago.security.auth import AuthException, auth_admin, auth_forum, sign_user_in
  13. from misago.security.decorators import *
  14. from misago.security.models import SignInAttempt
  15. from misago.sessions.models import Token
  16. from forms import SignInForm
  17. @block_banned
  18. @block_authenticated
  19. @block_jammed
  20. def signin(request):
  21. message = request.messages.get_message('security')
  22. if request.method == 'POST':
  23. form = SignInForm(
  24. request.POST,
  25. show_remember_me=not request.firewall.admin and request.settings['remember_me_allow'],
  26. request=request
  27. )
  28. if form.is_valid():
  29. try:
  30. # Configure correct auth and redirect links
  31. if request.firewall.admin:
  32. auth_method = auth_admin
  33. success_redirect = reverse(site.get_admin_index())
  34. else:
  35. auth_method = auth_forum
  36. success_redirect = reverse('index')
  37. # Authenticate user
  38. user = auth_method(
  39. request,
  40. form.cleaned_data['user_email'],
  41. form.cleaned_data['user_password'],
  42. )
  43. sign_user_in(request, user)
  44. remember_me_token = False
  45. if not request.firewall.admin and request.settings['remember_me_allow'] and form.cleaned_data['user_remember_me']:
  46. remember_me_token = get_random_string(42)
  47. remember_me = Token(
  48. id=remember_me_token,
  49. user=user,
  50. created=timezone.now(),
  51. accessed=timezone.now(),
  52. )
  53. remember_me.save()
  54. if remember_me_token:
  55. request.cookie_jar.set('TOKEN', remember_me_token, True)
  56. request.messages.set_flash(Message(request, 'security/signed_in', extra={'user': user}), 'success', 'security')
  57. return redirect(success_redirect)
  58. except AuthException as e:
  59. message = Message(request, e.type, extra={'user':e.user, 'ban':e.ban})
  60. message.type = 'error'
  61. # If not in Admin, register failed attempt
  62. if not request.firewall.admin and e.type == auth.CREDENTIALS:
  63. SignInAttempt.objects.register_attempt(request.session.get_ip(request))
  64. # Have we jammed our account?
  65. if SignInAttempt.objects.is_jammed(request.settings, request.session.get_ip(request)):
  66. request.jam.expires = timezone.now()
  67. return redirect(reverse('sign_in'))
  68. else:
  69. message = Message(request, form.non_field_errors()[0])
  70. message.type = 'error'
  71. else:
  72. form = SignInForm(
  73. show_remember_me=not request.firewall.admin and request.settings['remember_me_allow'],
  74. request=request
  75. )
  76. return request.theme.render_to_response('signin.html',
  77. {
  78. 'message': message,
  79. 'form': FormLayout(form),
  80. 'hide_signin': True,
  81. },
  82. context_instance=RequestContext(request));
  83. @block_guest
  84. @check_csrf
  85. def signout(request):
  86. user = request.user
  87. request.session.sign_out(request)
  88. request.messages.set_flash(Message(request, 'security/signed_out', extra={'user': user}), 'info', 'security')
  89. if request.firewall.admin:
  90. return redirect(reverse(site.get_admin_index()))
  91. return redirect(reverse('index'))