users.py 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445
  1. from django.contrib import messages
  2. from django.contrib.auth import get_user_model, update_session_auth_hash
  3. from django.db import transaction
  4. from django.http import JsonResponse
  5. from django.shortcuts import redirect
  6. from django.utils.translation import gettext_lazy as _
  7. from misago.acl.useracl import get_user_acl
  8. from misago.admin.auth import start_admin_session
  9. from misago.admin.views import generic
  10. from misago.categories.models import Category
  11. from misago.core.mail import mail_users
  12. from misago.core.pgutils import chunk_queryset
  13. from misago.threads.models import Thread
  14. from misago.users.avatars.dynamic import set_avatar as set_dynamic_avatar
  15. from misago.users.datadownloads import (
  16. request_user_data_download, user_has_data_download_request
  17. )
  18. from misago.users.forms.admin import (
  19. BanUsersForm, EditUserForm, EditUserFormFactory, NewUserForm,
  20. create_search_users_form
  21. )
  22. from misago.users.models import Ban
  23. from misago.users.profilefields import profilefields
  24. from misago.users.setupnewuser import setup_new_user
  25. from misago.users.signatures import set_user_signature
  26. User = get_user_model()
  27. class UserAdmin(generic.AdminBaseMixin):
  28. root_link = 'misago:admin:users:accounts:index'
  29. templates_dir = 'misago/admin/users'
  30. model = User
  31. def create_form_type(self, request, target):
  32. add_is_active_fields = False
  33. add_admin_fields = False
  34. if not target.is_deleting_account:
  35. if not target.is_staff:
  36. add_is_active_fields = True
  37. elif request.user.is_superuser:
  38. add_is_active_fields = request.user.pk != target.pk
  39. if request.user.is_superuser:
  40. add_admin_fields = request.user.pk != target.pk
  41. return EditUserFormFactory(
  42. self.form,
  43. target,
  44. add_is_active_fields=add_is_active_fields,
  45. add_admin_fields=add_admin_fields,
  46. )
  47. class UsersList(UserAdmin, generic.ListView):
  48. items_per_page = 24
  49. ordering = [
  50. ('-id', _("From newest")),
  51. ('id', _("From oldest")),
  52. ('slug', _("A to z")),
  53. ('-slug', _("Z to a")),
  54. ('posts', _("Biggest posters")),
  55. ('-posts', _("Smallest posters")),
  56. ]
  57. selection_label = _('With users: 0')
  58. empty_selection_label = _('Select users')
  59. mass_actions = [
  60. {
  61. 'action': 'activate',
  62. 'name': _("Activate accounts"),
  63. 'icon': 'fa fa-check-square-o',
  64. },
  65. {
  66. 'action': 'ban',
  67. 'name': _("Ban users"),
  68. 'icon': 'fa fa-lock',
  69. },
  70. {
  71. 'action': 'request_data_download',
  72. 'name': _("Request data download"),
  73. 'icon': 'fa fa-download',
  74. },
  75. {
  76. 'action': 'delete_accounts',
  77. 'name': _("Delete accounts"),
  78. 'icon': 'fa fa-times-circle',
  79. 'confirmation': _("Are you sure you want to delete selected users?"),
  80. },
  81. {
  82. 'action': 'delete_all',
  83. 'name': _("Delete all"),
  84. 'icon': 'fa fa-eraser',
  85. 'confirmation': _(
  86. "Are you sure you want to delete selected users? "
  87. "This will also delete all content associated with their accounts."
  88. ),
  89. 'is_atomic': False,
  90. },
  91. ]
  92. def get_queryset(self):
  93. qs = super().get_queryset()
  94. return qs.select_related('rank')
  95. def get_search_form(self, request):
  96. return create_search_users_form()
  97. def action_activate(self, request, users):
  98. inactive_users = []
  99. for user in users:
  100. if user.requires_activation:
  101. inactive_users.append(user)
  102. if not inactive_users:
  103. message = _("You have to select inactive users.")
  104. raise generic.MassActionError(message)
  105. else:
  106. activated_users_pks = [u.pk for u in inactive_users]
  107. queryset = User.objects.filter(pk__in=activated_users_pks)
  108. queryset.update(requires_activation=User.ACTIVATION_NONE)
  109. subject = _("Your account on %(forum_name)s forums has been activated")
  110. mail_subject = subject % {'forum_name': request.settings.forum_name}
  111. mail_users(
  112. inactive_users,
  113. mail_subject,
  114. 'misago/emails/activation/by_admin',
  115. context={"settings": request.settings},
  116. )
  117. messages.success(request, _("Selected users accounts have been activated."))
  118. def action_ban(self, request, users):
  119. users = users.order_by('slug')
  120. for user in users:
  121. if user.is_superuser:
  122. message = _("%(user)s is super admin and can't be banned.")
  123. mesage = message % {'user': user.username}
  124. raise generic.MassActionError(mesage)
  125. form = BanUsersForm(users=users)
  126. if 'finalize' in request.POST:
  127. form = BanUsersForm(request.POST, users=users)
  128. if form.is_valid():
  129. cleaned_data = form.cleaned_data
  130. banned_values = []
  131. ban_kwargs = {
  132. 'user_message': cleaned_data.get('user_message'),
  133. 'staff_message': cleaned_data.get('staff_message'),
  134. 'expires_on': cleaned_data.get('expires_on'),
  135. }
  136. for user in users:
  137. for ban in cleaned_data['ban_type']:
  138. banned_value = None
  139. if ban == 'usernames':
  140. check_type = Ban.USERNAME
  141. banned_value = user.username.lower()
  142. if ban == 'emails':
  143. check_type = Ban.EMAIL
  144. banned_value = user.email.lower()
  145. if ban == 'domains':
  146. check_type = Ban.EMAIL
  147. banned_value = user.email.lower()
  148. at_pos = banned_value.find('@')
  149. banned_value = '*%s' % banned_value[at_pos:]
  150. if ban == 'ip' and user.joined_from_ip:
  151. check_type = Ban.IP
  152. banned_value = user.joined_from_ip
  153. if ban in ('ip_first', 'ip_two') and user.joined_from_ip:
  154. check_type = Ban.IP
  155. if ':' in user.joined_from_ip:
  156. ip_separator = ':'
  157. if '.' in user.joined_from_ip:
  158. ip_separator = '.'
  159. bits = user.joined_from_ip.split(ip_separator)
  160. if ban == 'ip_first':
  161. formats = (bits[0], ip_separator)
  162. if ban == 'ip_two':
  163. formats = (bits[0], ip_separator, bits[1], ip_separator)
  164. banned_value = '%s*' % (''.join(formats))
  165. if banned_value and banned_value not in banned_values:
  166. ban_kwargs.update({
  167. 'check_type': check_type,
  168. 'banned_value': banned_value,
  169. })
  170. Ban.objects.create(**ban_kwargs)
  171. banned_values.append(banned_value)
  172. Ban.objects.invalidate_cache()
  173. messages.success(request, _("Selected users have been banned."))
  174. return None
  175. return self.render(
  176. request,
  177. template='misago/admin/users/ban.html',
  178. context={
  179. 'users': users,
  180. 'form': form,
  181. }
  182. )
  183. def action_request_data_download(self, request, users):
  184. for user in users:
  185. if not user_has_data_download_request(user):
  186. request_user_data_download(user, requester=request.user)
  187. messages.success(
  188. request, _("Data download requests have been placed for selected users."))
  189. def action_delete_accounts(self, request, users):
  190. for user in users:
  191. if user == request.user:
  192. raise generic.MassActionError(_("You can't delete yourself."))
  193. if user.is_staff or user.is_superuser:
  194. message = _("%(user)s is admin and can't be deleted.") % {'user': user.username}
  195. raise generic.MassActionError(message)
  196. for user in users:
  197. user.delete()
  198. messages.success(request, _("Selected users have been deleted."))
  199. def action_delete_all(self, request, users):
  200. for user in users:
  201. if user == request.user:
  202. raise generic.MassActionError(_("You can't delete yourself."))
  203. if user.is_staff or user.is_superuser:
  204. message = _("%(user)s is admin and can't be deleted.") % {'user': user.username}
  205. raise generic.MassActionError(message)
  206. return self.render(
  207. request,
  208. template='misago/admin/users/delete.html',
  209. context={
  210. 'users': users,
  211. },
  212. )
  213. class NewUser(UserAdmin, generic.ModelFormView):
  214. form = NewUserForm
  215. template = 'new.html'
  216. message_submit = _('New user "%(user)s" has been registered.')
  217. def initialize_form(self, form, request, target):
  218. if request.method == 'POST':
  219. return form(
  220. request.POST,
  221. request.FILES,
  222. instance=target,
  223. request=request,
  224. )
  225. else:
  226. return form(instance=target, request=request)
  227. def handle_form(self, form, request, target):
  228. new_user = User.objects.create_user(
  229. form.cleaned_data['username'],
  230. form.cleaned_data['email'],
  231. form.cleaned_data['new_password'],
  232. title=form.cleaned_data['title'],
  233. rank=form.cleaned_data.get('rank'),
  234. joined_from_ip=request.user_ip,
  235. )
  236. if form.cleaned_data.get('staff_level'):
  237. new_user.staff_level = form.cleaned_data['staff_level']
  238. if form.cleaned_data.get('roles'):
  239. new_user.roles.add(*form.cleaned_data['roles'])
  240. new_user.update_acl_key()
  241. setup_new_user(request.settings, new_user)
  242. messages.success(request, self.message_submit % {'user': target.username})
  243. return redirect('misago:admin:users:accounts:edit', pk=new_user.pk)
  244. class EditUser(UserAdmin, generic.ModelFormView):
  245. form = EditUserForm
  246. template = 'edit.html'
  247. message_submit = _('User "%(user)s" has been edited.')
  248. def real_dispatch(self, request, target):
  249. target.old_username = target.username
  250. target.old_is_avatar_locked = target.is_avatar_locked
  251. return super().real_dispatch(request, target)
  252. def initialize_form(self, form, request, target):
  253. if request.method == 'POST':
  254. return form(
  255. request.POST,
  256. request.FILES,
  257. instance=target,
  258. request=request,
  259. )
  260. else:
  261. return form(instance=target, request=request)
  262. def handle_form(self, form, request, target):
  263. target.username = target.old_username
  264. if target.username != form.cleaned_data.get('username'):
  265. target.set_username(form.cleaned_data.get('username'), changed_by=request.user)
  266. if form.cleaned_data.get('new_password'):
  267. target.set_password(form.cleaned_data['new_password'])
  268. if target.pk == request.user.pk:
  269. start_admin_session(request, target)
  270. update_session_auth_hash(request, target)
  271. if form.cleaned_data.get('email'):
  272. target.set_email(form.cleaned_data['email'])
  273. if target.pk == request.user.pk:
  274. start_admin_session(request, target)
  275. if form.cleaned_data.get('is_avatar_locked'):
  276. if not target.old_is_avatar_locked:
  277. set_dynamic_avatar(target)
  278. if 'is_staff' in form.fields and 'is_superuser' in form.fields:
  279. target.is_staff = form.cleaned_data.get('is_staff')
  280. target.is_superuser = form.cleaned_data.get('is_superuser')
  281. if 'is_active' in form.fields and 'is_active_staff_message' in form.fields:
  282. target.is_active = form.cleaned_data.get('is_active')
  283. target.is_active_staff_message = form.cleaned_data.get('is_active_staff_message')
  284. target.rank = form.cleaned_data.get('rank')
  285. target.roles.clear()
  286. target.roles.add(*form.cleaned_data['roles'])
  287. target_acl = get_user_acl(target, request.cache_versions)
  288. set_user_signature(
  289. request, target, target_acl, form.cleaned_data.get('signature')
  290. )
  291. profilefields.update_user_profile_fields(request, target, form)
  292. target.update_acl_key()
  293. target.save()
  294. messages.success(request, self.message_submit % {'user': target.username})
  295. class DeletionStep(UserAdmin, generic.ButtonView):
  296. is_atomic = False
  297. def check_permissions(self, request, target):
  298. if not request.is_ajax():
  299. return _("This action can't be accessed directly.")
  300. if target == request.user:
  301. return _("You can't delete yourself.")
  302. if target.is_staff or target.is_superuser:
  303. return _("%(user)s is admin and can't be deleted.") % {'user': target.username}
  304. def execute_step(self, user):
  305. raise NotImplementedError(
  306. "execute_step method should return dict with "
  307. "number of deleted_count and is_completed keys"
  308. )
  309. def button_action(self, request, target):
  310. return JsonResponse(self.execute_step(target))
  311. class DeleteThreadsStep(DeletionStep):
  312. def execute_step(self, user):
  313. recount_categories = set()
  314. deleted_threads = 0
  315. is_completed = False
  316. for thread in user.thread_set.order_by('-id')[:50]:
  317. recount_categories.add(thread.category_id)
  318. with transaction.atomic():
  319. thread.delete()
  320. deleted_threads += 1
  321. if recount_categories:
  322. for category in Category.objects.filter(id__in=recount_categories):
  323. category.synchronize()
  324. category.save()
  325. else:
  326. is_completed = True
  327. return {
  328. 'deleted_count': deleted_threads,
  329. 'is_completed': is_completed,
  330. }
  331. class DeletePostsStep(DeletionStep):
  332. def execute_step(self, user):
  333. recount_categories = set()
  334. recount_threads = set()
  335. deleted_posts = 0
  336. is_completed = False
  337. for post in user.post_set.order_by('-id')[:50]:
  338. recount_categories.add(post.category_id)
  339. recount_threads.add(post.thread_id)
  340. with transaction.atomic():
  341. post.delete()
  342. deleted_posts += 1
  343. if recount_categories:
  344. changed_threads_qs = Thread.objects.filter(id__in=recount_threads)
  345. for thread in chunk_queryset(changed_threads_qs, 50):
  346. thread.synchronize()
  347. thread.save()
  348. for category in Category.objects.filter(id__in=recount_categories):
  349. category.synchronize()
  350. category.save()
  351. else:
  352. is_completed = True
  353. return {
  354. 'deleted_count': deleted_posts,
  355. 'is_completed': is_completed,
  356. }
  357. class DeleteAccountStep(DeletionStep):
  358. def execute_step(self, user):
  359. user.delete(delete_content=True)
  360. return {'is_completed': True}