usermodel.py 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540
  1. import hashlib
  2. import math
  3. from random import choice
  4. from path import path
  5. from django.conf import settings
  6. from django.contrib.auth.hashers import (
  7. check_password, make_password, is_password_usable, UNUSABLE_PASSWORD)
  8. from django.core.cache import cache, InvalidCacheBackendError
  9. from django.core.exceptions import ValidationError
  10. from django.core.mail import EmailMultiAlternatives
  11. from django.db import models
  12. from django.template import RequestContext
  13. from django.utils import timezone as tz_util
  14. from django.utils.translation import ugettext_lazy as _
  15. from misago.acl.builder import build_acl
  16. from misago.monitor import Monitor
  17. from misago.dbsettings import DBSettings
  18. from misago.signals import delete_user_content, rename_user
  19. from misago.utils.avatars import avatar_size
  20. from misago.utils.strings import random_string, slugify
  21. from misago.validators import validate_username, validate_password, validate_email
  22. class UserManager(models.Manager):
  23. """
  24. User Manager provides us with some additional methods for users
  25. """
  26. def get_blank_user(self):
  27. blank_user = User(
  28. join_date=tz_util.now(),
  29. join_ip='127.0.0.1'
  30. )
  31. return blank_user
  32. def resync_monitor(self, monitor):
  33. monitor['users'] = self.filter(activation=0).count()
  34. monitor['users_inactive'] = self.filter(activation__gt=0).count()
  35. last_user = self.filter(activation=0).latest('id')
  36. monitor['last_user'] = last_user.pk
  37. monitor['last_user_name'] = last_user.username
  38. monitor['last_user_slug'] = last_user.username_slug
  39. def create_user(self, username, email, password, timezone=False, ip='127.0.0.1', agent='', no_roles=False, activation=0, request=False):
  40. token = ''
  41. if activation > 0:
  42. token = random_string(12)
  43. try:
  44. db_settings = request.settings
  45. except AttributeError:
  46. db_settings = DBSettings()
  47. if timezone == False:
  48. timezone = db_settings['default_timezone']
  49. # Get first rank
  50. try:
  51. from misago.models import Rank
  52. default_rank = Rank.objects.filter(special=0).order_by('order')[0]
  53. except IndexError:
  54. default_rank = None
  55. # Store user in database
  56. new_user = User(
  57. last_sync=tz_util.now(),
  58. join_date=tz_util.now(),
  59. join_ip=ip,
  60. join_agent=agent,
  61. activation=activation,
  62. token=token,
  63. timezone=timezone,
  64. rank=default_rank,
  65. subscribe_start=db_settings['subscribe_start'],
  66. subscribe_reply=db_settings['subscribe_reply'],
  67. )
  68. validate_username(username, db_settings)
  69. validate_password(password, db_settings)
  70. new_user.set_username(username)
  71. new_user.set_email(email)
  72. new_user.set_password(password)
  73. new_user.full_clean()
  74. new_user.default_avatar(db_settings)
  75. new_user.save(force_insert=True)
  76. # Set user roles?
  77. if not no_roles:
  78. from misago.models import Role
  79. new_user.roles.add(Role.objects.get(_special='registered'))
  80. new_user.make_acl_key()
  81. new_user.save(force_update=True)
  82. # Load monitor
  83. try:
  84. monitor = request.monitor
  85. except AttributeError:
  86. monitor = Monitor()
  87. # Update forum stats
  88. if activation == 0:
  89. monitor['users'] = int(monitor['users']) + 1
  90. monitor['last_user'] = new_user.pk
  91. monitor['last_user_name'] = new_user.username
  92. monitor['last_user_slug'] = new_user.username_slug
  93. else:
  94. monitor['users_inactive'] = int(monitor['users_inactive']) + 1
  95. # Return new user
  96. return new_user
  97. def get_by_email(self, email):
  98. return self.get(email_hash=hashlib.md5(email).hexdigest())
  99. def filter_stats(self, start, end):
  100. return self.filter(join_date__gte=start).filter(join_date__lte=end)
  101. class User(models.Model):
  102. """
  103. Misago User model
  104. """
  105. username = models.CharField(max_length=255)
  106. username_slug = models.SlugField(max_length=255, unique=True,
  107. error_messages={'unique': _("This user name is already in use by another user.")})
  108. email = models.EmailField(max_length=255, validators=[validate_email])
  109. email_hash = models.CharField(max_length=32, unique=True,
  110. error_messages={'unique': _("This email address is already in use by another user.")})
  111. password = models.CharField(max_length=255)
  112. password_date = models.DateTimeField()
  113. avatar_type = models.CharField(max_length=10, null=True, blank=True)
  114. avatar_image = models.CharField(max_length=255, null=True, blank=True)
  115. avatar_original = models.CharField(max_length=255, null=True, blank=True)
  116. avatar_temp = models.CharField(max_length=255, null=True, blank=True)
  117. signature = models.TextField(null=True, blank=True)
  118. signature_preparsed = models.TextField(null=True, blank=True)
  119. join_date = models.DateTimeField()
  120. join_ip = models.GenericIPAddressField()
  121. join_agent = models.TextField(null=True, blank=True)
  122. last_date = models.DateTimeField(null=True, blank=True)
  123. last_ip = models.GenericIPAddressField(null=True, blank=True)
  124. last_agent = models.TextField(null=True, blank=True)
  125. hide_activity = models.PositiveIntegerField(default=0)
  126. allow_pms = models.PositiveIntegerField(default=0)
  127. subscribe_start = models.PositiveIntegerField(default=0)
  128. subscribe_reply = models.PositiveIntegerField(default=0)
  129. receive_newsletters = models.BooleanField(default=True)
  130. threads = models.PositiveIntegerField(default=0)
  131. posts = models.PositiveIntegerField(default=0)
  132. votes = models.PositiveIntegerField(default=0)
  133. karma_given_p = models.PositiveIntegerField(default=0)
  134. karma_given_n = models.PositiveIntegerField(default=0)
  135. karma_p = models.PositiveIntegerField(default=0)
  136. karma_n = models.PositiveIntegerField(default=0)
  137. following = models.PositiveIntegerField(default=0)
  138. followers = models.PositiveIntegerField(default=0)
  139. score = models.IntegerField(default=0)
  140. ranking = models.PositiveIntegerField(default=0)
  141. rank = models.ForeignKey('Rank', null=True, blank=True, on_delete=models.SET_NULL)
  142. last_sync = models.DateTimeField(null=True, blank=True)
  143. follows = models.ManyToManyField('self', related_name='follows_set', symmetrical=False)
  144. ignores = models.ManyToManyField('self', related_name='ignores_set', symmetrical=False)
  145. title = models.CharField(max_length=255, null=True, blank=True)
  146. last_post = models.DateTimeField(null=True, blank=True)
  147. last_search = models.DateTimeField(null=True, blank=True)
  148. alerts = models.PositiveIntegerField(default=0)
  149. alerts_date = models.DateTimeField(null=True, blank=True)
  150. activation = models.IntegerField(default=0)
  151. token = models.CharField(max_length=12, null=True, blank=True)
  152. avatar_ban = models.BooleanField(default=False)
  153. avatar_ban_reason_user = models.TextField(null=True, blank=True)
  154. avatar_ban_reason_admin = models.TextField(null=True, blank=True)
  155. signature_ban = models.BooleanField(default=False)
  156. signature_ban_reason_user = models.TextField(null=True, blank=True)
  157. signature_ban_reason_admin = models.TextField(null=True, blank=True)
  158. timezone = models.CharField(max_length=255, default='utc')
  159. roles = models.ManyToManyField('Role')
  160. is_team = models.BooleanField(default=False)
  161. acl_key = models.CharField(max_length=12, null=True, blank=True)
  162. objects = UserManager()
  163. ACTIVATION_NONE = 0
  164. ACTIVATION_USER = 1
  165. ACTIVATION_ADMIN = 2
  166. ACTIVATION_CREDENTIALS = 3
  167. statistics_name = _('Users Registrations')
  168. class Meta:
  169. app_label = 'misago'
  170. def is_god(self):
  171. try:
  172. return self.is_god_cache
  173. except AttributeError:
  174. for user in settings.ADMINS:
  175. if user[1].lower() == self.email:
  176. self.is_god_cache = True
  177. return True
  178. self.is_god_cache = False
  179. return False
  180. def is_anonymous(self):
  181. return False
  182. def is_authenticated(self):
  183. return True
  184. def is_crawler(self):
  185. return False
  186. def is_protected(self):
  187. for role in self.roles.all():
  188. if role.protected:
  189. return True
  190. return False
  191. def lock_avatar(self):
  192. # Kill existing avatar and lock our ability to change it
  193. self.delete_avatar()
  194. self.avatar_ban = True
  195. # Pick new one from _locked gallery
  196. galleries = path(settings.STATICFILES_DIRS[0]).joinpath('avatars').joinpath('_locked')
  197. avatars_list = galleries.files('*.gif')
  198. avatars_list += galleries.files('*.jpg')
  199. avatars_list += galleries.files('*.jpeg')
  200. avatars_list += galleries.files('*.png')
  201. self.avatar_type = 'gallery'
  202. self.avatar_image = '/'.join(path(choice(avatars_list)).splitall()[-2:])
  203. def default_avatar(self, db_settings):
  204. if db_settings['default_avatar'] == 'gallery':
  205. try:
  206. avatars_list = []
  207. try:
  208. # First try, _default path
  209. galleries = path(settings.STATICFILES_DIRS[0]).joinpath('avatars').joinpath('_default')
  210. avatars_list += galleries.files('*.gif')
  211. avatars_list += galleries.files('*.jpg')
  212. avatars_list += galleries.files('*.jpeg')
  213. avatars_list += galleries.files('*.png')
  214. except Exception as e:
  215. pass
  216. # Second try, all paths
  217. if not avatars_list:
  218. avatars_list = []
  219. for directory in path(settings.STATICFILES_DIRS[0]).joinpath('avatars').dirs():
  220. if not directory[-7:] == '_locked' and not directory[-7:] == '_thumbs':
  221. avatars_list += directory.files('*.gif')
  222. avatars_list += directory.files('*.jpg')
  223. avatars_list += directory.files('*.jpeg')
  224. avatars_list += directory.files('*.png')
  225. if avatars_list:
  226. # Pick random avatar from list
  227. self.avatar_type = 'gallery'
  228. self.avatar_image = '/'.join(path(choice(avatars_list)).splitall()[-2:])
  229. return True
  230. except Exception as e:
  231. pass
  232. self.avatar_type = 'gravatar'
  233. self.avatar_image = None
  234. return True
  235. def delete_avatar_temp(self):
  236. if self.avatar_temp:
  237. try:
  238. av_file = path(settings.MEDIA_ROOT + 'avatars/' + self.avatar_temp)
  239. if not av_file.isdir():
  240. av_file.remove()
  241. except Exception:
  242. pass
  243. self.avatar_temp = None
  244. def delete_avatar_original(self):
  245. if self.avatar_original:
  246. try:
  247. av_file = path(settings.MEDIA_ROOT + 'avatars/' + self.avatar_original)
  248. if not av_file.isdir():
  249. av_file.remove()
  250. except Exception:
  251. pass
  252. self.avatar_original = None
  253. def delete_avatar_image(self):
  254. if self.avatar_image:
  255. for size in settings.AVATAR_SIZES[1:]:
  256. try:
  257. av_file = path(settings.MEDIA_ROOT + 'avatars/' + str(size) + '_' + self.avatar_image)
  258. if not av_file.isdir():
  259. av_file.remove()
  260. except Exception:
  261. pass
  262. try:
  263. av_file = path(settings.MEDIA_ROOT + 'avatars/' + self.avatar_image)
  264. if not av_file.isdir():
  265. av_file.remove()
  266. except Exception:
  267. pass
  268. self.avatar_image = None
  269. def delete_avatar(self):
  270. self.delete_avatar_temp()
  271. self.delete_avatar_original()
  272. self.delete_avatar_image()
  273. def delete_content(self):
  274. delete_user_content.send(sender=self)
  275. def delete(self, *args, **kwargs):
  276. self.delete_avatar()
  277. super(User, self).delete(*args, **kwargs)
  278. def set_username(self, username):
  279. self.username = username.strip()
  280. self.username_slug = slugify(username)
  281. def sync_username(self):
  282. print 'SYNCING NAME CACHES!'
  283. rename_user.send(sender=self)
  284. def is_username_valid(self, e):
  285. try:
  286. raise ValidationError(e.message_dict['username'])
  287. except KeyError:
  288. pass
  289. try:
  290. raise ValidationError(e.message_dict['username_slug'])
  291. except KeyError:
  292. pass
  293. def is_email_valid(self, e):
  294. try:
  295. raise ValidationError(e.message_dict['email'])
  296. except KeyError:
  297. pass
  298. try:
  299. raise ValidationError(e.message_dict['email_hash'])
  300. except KeyError:
  301. pass
  302. def is_password_valid(self, e):
  303. try:
  304. raise ValidationError(e.message_dict['password'])
  305. except KeyError:
  306. pass
  307. def set_email(self, email):
  308. self.email = email.strip().lower()
  309. self.email_hash = hashlib.md5(self.email).hexdigest()
  310. def set_password(self, raw_password):
  311. self.password_date = tz_util.now()
  312. self.password = make_password(raw_password.strip())
  313. def set_last_visit(self, ip, agent, hidden=False):
  314. self.last_date = tz_util.now()
  315. self.last_ip = ip
  316. self.last_agent = agent
  317. self.last_hide = hidden
  318. def check_password(self, raw_password, mobile=False):
  319. """
  320. Returns a boolean of whether the raw_password was correct. Handles
  321. hashing formats behind the scenes.
  322. """
  323. def setter(raw_password):
  324. self.set_password(raw_password)
  325. self.save()
  326. # Is standard password allright?
  327. if check_password(raw_password, self.password, setter):
  328. return True
  329. # Check mobile password?
  330. if mobile:
  331. raw_password = raw_password[:1].lower() + raw_password[1:]
  332. else:
  333. password_reversed = u''
  334. for c in raw_password:
  335. r = c.upper()
  336. if r == c:
  337. r = c.lower()
  338. password_reversed += r
  339. raw_password = password_reversed
  340. return check_password(raw_password, self.password, setter)
  341. def is_following(self, user):
  342. try:
  343. return self.follows.filter(id=user.pk).count() > 0
  344. except AttributeError:
  345. return self.follows.filter(id=user).count() > 0
  346. def is_ignoring(self, user):
  347. try:
  348. return self.ignores.filter(id=user.pk).count() > 0
  349. except AttributeError:
  350. return self.ignores.filter(id=user).count() > 0
  351. def ignored_users(self):
  352. return [item['id'] for item in self.ignores.values('id')]
  353. def get_roles(self):
  354. return self.roles.all()
  355. def make_acl_key(self, force=False):
  356. if not force and self.acl_key:
  357. return self.acl_key
  358. roles_ids = []
  359. for role in self.roles.all():
  360. roles_ids.append(str(role.pk))
  361. self.acl_key = 'acl_%s' % hashlib.md5('_'.join(roles_ids)).hexdigest()[0:8]
  362. return self.acl_key
  363. def acl(self, request):
  364. try:
  365. acl = cache.get(self.acl_key)
  366. if acl.version != request.monitor.acl_version:
  367. raise InvalidCacheBackendError()
  368. except AttributeError, InvalidCacheBackendError:
  369. # build acl cache
  370. acl = build_acl(request, self.get_roles())
  371. cache.set(self.acl_key, acl, 2592000)
  372. return acl
  373. def get_avatar(self, size=None):
  374. image_size = avatar_size(size) if size else None
  375. # Get uploaded avatar
  376. if self.avatar_type == 'upload':
  377. image_prefix = '%s_' % image_size if image_size else ''
  378. return settings.MEDIA_URL + 'avatars/' + image_prefix + self.avatar_image
  379. # Get gallery avatar
  380. if self.avatar_type == 'gallery':
  381. image_prefix = '_thumbs/%s/' % image_size if image_size else ''
  382. return settings.STATIC_URL + 'avatars/' + image_prefix + self.avatar_image
  383. # No avatar found, get gravatar
  384. if not image_size:
  385. image_size = settings.AVATAR_SIZES[0]
  386. return 'http://www.gravatar.com/avatar/%s?s=%s' % (hashlib.md5(self.email).hexdigest(), image_size)
  387. def get_ranking(self):
  388. if not self.ranking:
  389. self.ranking = User.objects.filter(score__gt=self.score).count() + 1
  390. self.save(force_update=True)
  391. return self.ranking
  392. def get_title(self):
  393. if self.title:
  394. return self.title
  395. if self.rank:
  396. return self.rank.title
  397. return None
  398. def get_style(self):
  399. if self.rank:
  400. return self.rank.style
  401. return ''
  402. def email_user(self, request, template, subject, context={}):
  403. templates = request.theme.get_email_templates(template)
  404. context = RequestContext(request, context)
  405. context['author'] = context['user']
  406. context['user'] = self
  407. # Set message recipient
  408. if settings.DEBUG and settings.CATCH_ALL_EMAIL_ADDRESS:
  409. recipient = settings.CATCH_ALL_EMAIL_ADDRESS
  410. else:
  411. recipient = self.email
  412. # Build and send message
  413. email = EmailMultiAlternatives(subject, templates[0].render(context), settings.EMAIL_HOST_USER, [recipient])
  414. email.attach_alternative(templates[1].render(context), "text/html")
  415. email.send()
  416. def get_activation(self):
  417. activations = ['none', 'user', 'admin', 'credentials']
  418. return activations[self.activation]
  419. def alert(self, message):
  420. from misago.models import Alert
  421. self.alerts += 1
  422. return Alert(user=self, message=message, date=tz_util.now())
  423. def get_date(self):
  424. return self.join_date
  425. def sync_user(self):
  426. pass
  427. class Guest(object):
  428. """
  429. Misago Guest dummy
  430. """
  431. id = -1
  432. pk = -1
  433. is_team = False
  434. def is_anonymous(self):
  435. return True
  436. def is_authenticated(self):
  437. return False
  438. def is_crawler(self):
  439. return False
  440. def get_roles(self):
  441. from misago.models import Role
  442. return Role.objects.filter(_special='guest')
  443. def make_acl_key(self):
  444. return 'acl_guest'
  445. class Crawler(Guest):
  446. """
  447. Misago Crawler dummy
  448. """
  449. is_team = False
  450. def __init__(self, username):
  451. self.username = username
  452. def is_anonymous(self):
  453. return True
  454. def is_authenticated(self):
  455. return False
  456. def is_crawler(self):
  457. return True