users.py 8.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242
  1. from django.contrib import messages
  2. from django.contrib.auth import get_user_model, update_session_auth_hash
  3. from django.shortcuts import redirect
  4. from django.utils.translation import ugettext_lazy as _
  5. from misago.admin.auth import start_admin_session
  6. from misago.admin.views import generic
  7. from misago.conf import settings
  8. from misago.core.mail import mail_users
  9. from misago.users.avatars.dynamic import set_avatar as set_dynamic_avatar
  10. from misago.users.forms.admin import (StaffFlagUserFormFactory, NewUserForm,
  11. EditUserForm, SearchUsersForm,
  12. BanUsersForm)
  13. from misago.users.models import ACTIVATION_REQUIRED_NONE, User, Ban
  14. from misago.users.signatures import set_user_signature
  15. class UserAdmin(generic.AdminBaseMixin):
  16. root_link = 'misago:admin:users:accounts:index'
  17. templates_dir = 'misago/admin/users'
  18. def get_model(self):
  19. return get_user_model()
  20. def create_form_type(self, request, target):
  21. if request.user.is_superuser:
  22. add_staff_field = request.user.pk != target.id
  23. else:
  24. add_staff_field = False
  25. return StaffFlagUserFormFactory(
  26. self.Form, target, add_staff_field=add_staff_field)
  27. class UsersList(UserAdmin, generic.ListView):
  28. items_per_page = 24
  29. ordering = (
  30. ('-id', _("From newest")),
  31. ('id', _("From oldest")),
  32. ('slug', _("A to z")),
  33. ('-slug', _("Z to a")),
  34. ('posts', _("Biggest posters")),
  35. ('-posts', _("Smallest posters")),
  36. )
  37. selection_label = _('With users: 0')
  38. empty_selection_label = _('Select users')
  39. mass_actions = [
  40. {
  41. 'action': 'activate',
  42. 'name': _("Activate accounts"),
  43. 'icon': 'fa fa-check-square-o',
  44. },
  45. {
  46. 'action': 'ban',
  47. 'name': _("Ban users"),
  48. 'icon': 'fa fa-lock',
  49. },
  50. {
  51. 'action': 'delete_accounts',
  52. 'name': _("Delete accounts"),
  53. 'icon': 'fa fa-times-circle',
  54. 'confirmation': _("Are you sure you want "
  55. "to delete selected users?"),
  56. },
  57. {
  58. 'action': 'delete_all',
  59. 'name': _("Delete all"),
  60. 'icon': 'fa fa-eraser',
  61. 'confirmation': _("Are you sure you want to delete selected "
  62. "users? This will also delete all content "
  63. "associated with their accounts."),
  64. }
  65. ]
  66. def get_queryset(self):
  67. qs = super(UsersList, self).get_queryset()
  68. return qs.select_related('rank')
  69. def get_search_form(self, request):
  70. return SearchUsersForm
  71. def action_activate(self, request, users):
  72. inactive_users = []
  73. for user in users:
  74. if user.requires_activation:
  75. inactive_users.append(user)
  76. if not inactive_users:
  77. message = _("You have to select inactive users.")
  78. raise generic.MassActionError(message)
  79. else:
  80. activated_users_pks = [u.pk for u in inactive_users]
  81. queryset = User.objects.filter(pk__in=activated_users_pks)
  82. queryset.update(requires_activation=ACTIVATION_REQUIRED_NONE)
  83. mail_subject = _("Your account on %(forum_title)s "
  84. "forums has been activated")
  85. subject_formats = {'forum_title': settings.forum_name}
  86. mail_subject = mail_subject % subject_formats
  87. mail_subject = mail_subject
  88. mail_users(request, inactive_users, mail_subject,
  89. 'misago/emails/activation/by_admin')
  90. message = _("Selected users accounts have been activated.")
  91. messages.success(request, message)
  92. def action_ban(self, request, users):
  93. users = users.order_by('slug')
  94. for user in users:
  95. if user.is_superuser:
  96. message = _("%(user)s is super admin and can't be banned.")
  97. mesage = message % {'user': user.username}
  98. raise generic.MassActionError(mesage)
  99. form = BanUsersForm()
  100. if 'finalize' in request.POST:
  101. form = BanUsersForm(request.POST)
  102. if form.is_valid():
  103. for user in users:
  104. Ban.objects.create(
  105. banned_value=user.username,
  106. user_message=form.cleaned_data.get('user_message'),
  107. staff_message=form.cleaned_data.get('staff_message'),
  108. valid_until=form.cleaned_data.get('valid_until')
  109. )
  110. Ban.objects.invalidate_cache()
  111. message = _("Selected users have been banned.")
  112. messages.success(request, message)
  113. return None
  114. return self.render(
  115. request, template='misago/admin/users/ban_users.html', context={
  116. 'users': users,
  117. 'form': form,
  118. })
  119. def action_delete_accounts(self, request, users):
  120. for user in users:
  121. if user.is_staff or user.is_superuser:
  122. message = _("%(user)s is admin and can't be deleted.")
  123. mesage = message % {'user': user.username}
  124. raise generic.MassActionError(mesage)
  125. for user in users:
  126. user.delete()
  127. message = _("Selected users have been deleted.")
  128. messages.success(request, message)
  129. def action_delete_all(self, request, users):
  130. for user in users:
  131. if user.is_staff or user.is_superuser:
  132. message = _("%(user)s is admin and can't be deleted.")
  133. mesage = message % {'user': user.username}
  134. raise generic.MassActionError(mesage)
  135. for user in users:
  136. user.delete(delete_content=True)
  137. message = _("Selected users and their content has been deleted.")
  138. messages.success(request, message)
  139. class NewUser(UserAdmin, generic.ModelFormView):
  140. Form = NewUserForm
  141. template = 'new.html'
  142. message_submit = _('New user "%s" has been registered.')
  143. def handle_form(self, form, request, target):
  144. User = get_user_model()
  145. new_user = User.objects.create_user(
  146. form.cleaned_data['username'],
  147. form.cleaned_data['email'],
  148. form.cleaned_data['new_password'],
  149. title=form.cleaned_data['title'],
  150. rank=form.cleaned_data.get('rank'),
  151. joined_from_ip=request._misago_real_ip,
  152. set_default_avatar=True)
  153. if form.cleaned_data.get('staff_level'):
  154. new_user.staff_level = form.cleaned_data['staff_level']
  155. if form.cleaned_data.get('roles'):
  156. new_user.roles.add(*form.cleaned_data['roles'])
  157. new_user.update_acl_key()
  158. new_user.save()
  159. messages.success(request, self.message_submit % target.username)
  160. return redirect('misago:admin:users:accounts:edit',
  161. user_id=new_user.id)
  162. class EditUser(UserAdmin, generic.ModelFormView):
  163. Form = EditUserForm
  164. template = 'edit.html'
  165. message_submit = _('User "%s" has been edited.')
  166. def real_dispatch(self, request, target):
  167. target.old_username = target.username
  168. target.old_is_avatar_locked = target.is_avatar_locked
  169. return super(EditUser, self).real_dispatch(request, target)
  170. def handle_form(self, form, request, target):
  171. target.username = target.old_username
  172. if target.username != form.cleaned_data.get('username'):
  173. target.set_username(form.cleaned_data.get('username'),
  174. changed_by=request.user)
  175. if form.cleaned_data.get('new_password'):
  176. target.set_password(form.cleaned_data['new_password'])
  177. if target.pk == request.user.pk:
  178. start_admin_session(request, target)
  179. update_session_auth_hash(request, target)
  180. if form.cleaned_data.get('email'):
  181. target.set_email(form.cleaned_data['email'])
  182. if target.pk == request.user.pk:
  183. start_admin_session(request, target)
  184. if form.cleaned_data.get('is_avatar_locked'):
  185. if not target.old_is_avatar_locked:
  186. set_dynamic_avatar(target)
  187. if 'staff_level' in form.cleaned_data:
  188. target.staff_level = form.cleaned_data['staff_level']
  189. target.rank = form.cleaned_data.get('rank')
  190. if form.cleaned_data.get('roles'):
  191. target.roles.add(*form.cleaned_data['roles'])
  192. set_user_signature(target, form.cleaned_data.get('signature'))
  193. target.update_acl_key()
  194. target.save()
  195. messages.success(request, self.message_submit % target.username)