utils.py 4.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173
  1. from datetime import datetime, timedelta
  2. from django.conf import settings
  3. from django.core.exceptions import PermissionDenied
  4. from django.http import Http404
  5. from django.urls import resolve, reverse
  6. from django.utils import html, timezone
  7. from django.utils.encoding import force_text
  8. from django.utils.module_loading import import_string
  9. MISAGO_SLUGIFY = getattr(settings, "MISAGO_SLUGIFY", "misago.core.slugify.default")
  10. slugify = import_string(MISAGO_SLUGIFY)
  11. def format_plaintext_for_html(string):
  12. return html.linebreaks(html.urlize(html.escape(string)))
  13. def encode_json_html(string):
  14. return string.replace("<", r"\u003C")
  15. ISO8601_FORMATS = ("%Y-%m-%dT%H:%M:%S", "%Y-%m-%dT%H:%M:%S.%f")
  16. def parse_iso8601_string(value):
  17. """turns ISO 8601 string into datetime object"""
  18. value = force_text(value, strings_only=True).rstrip("Z")
  19. for format in ISO8601_FORMATS:
  20. try:
  21. parsed_value = datetime.strptime(value, format)
  22. break
  23. except ValueError:
  24. try:
  25. parsed_value = datetime.strptime(value[:-6], format)
  26. break
  27. except ValueError:
  28. pass
  29. else:
  30. raise ValueError("failed to hydrate the %s timestamp" % value)
  31. offset_str = value[-6:]
  32. if offset_str and offset_str[0] in ("-", "+"):
  33. tz_offset = timedelta(hours=int(offset_str[1:3]), minutes=int(offset_str[4:6]))
  34. tz_offset = tz_offset.seconds // 60
  35. if offset_str[0] == "-":
  36. tz_offset *= -1
  37. else:
  38. tz_offset = 0
  39. tz_correction = timezone.get_fixed_timezone(tz_offset)
  40. return timezone.make_aware(parsed_value, tz_correction)
  41. def hide_post_parameters(request):
  42. """
  43. Mark request as having sensitive parameters
  44. We can't use decorator because of DRF uses custom HttpRequest
  45. that is incompatibile with Django's decorator
  46. """
  47. request.sensitive_post_parameters = "__ALL__"
  48. def clean_return_path(request):
  49. """return path utility that returns return path from referer or POST"""
  50. if request.method == "POST" and "return_path" in request.POST:
  51. return _get_return_path_from_post(request)
  52. else:
  53. return _get_return_path_from_referer(request)
  54. def _get_return_path_from_post(request):
  55. return_path = request.POST.get("return_path")
  56. try:
  57. if not return_path:
  58. raise ValueError()
  59. if not return_path.startswith("/"):
  60. raise ValueError()
  61. resolve(return_path)
  62. return return_path
  63. except (Http404, ValueError):
  64. return None
  65. def _get_return_path_from_referer(request):
  66. referer = request.META.get("HTTP_REFERER")
  67. try:
  68. if not referer:
  69. raise ValueError()
  70. if not referer.startswith(request.scheme):
  71. raise ValueError()
  72. referer = referer[len(request.scheme) + 3 :]
  73. if not referer.startswith(request.META["HTTP_HOST"]):
  74. raise ValueError()
  75. referer = referer[len(request.META["HTTP_HOST"].rstrip("/")) :]
  76. if not referer.startswith("/"):
  77. raise ValueError()
  78. resolve(referer)
  79. return referer
  80. except (Http404, KeyError, ValueError):
  81. return None
  82. def is_request_to_misago(request):
  83. try:
  84. return request._request_to_misago
  85. except AttributeError:
  86. request._request_to_misago = _is_request_path_under_misago(request)
  87. return request._request_to_misago
  88. def _is_request_path_under_misago(request):
  89. # We are assuming that forum_index link is root of all Misago links
  90. forum_index = reverse("misago:index")
  91. path = request.path
  92. if len(forum_index) > len(path):
  93. return False
  94. return path[: len(forum_index)] == forum_index
  95. def is_referer_local(request):
  96. referer = request.META.get("HTTP_REFERER")
  97. if not referer:
  98. return False
  99. if not referer.startswith(request.scheme):
  100. return False
  101. referer = referer[len(request.scheme) + 3 :]
  102. if not referer.startswith(request.META["HTTP_HOST"]):
  103. return False
  104. referer = referer[len(request.META["HTTP_HOST"].rstrip("/")) :]
  105. if not referer.startswith("/"):
  106. return False
  107. return True
  108. def get_exception_message(exception=None, default_message=None):
  109. if not exception:
  110. return default_message
  111. try:
  112. return exception.args[0]
  113. except IndexError:
  114. return default_message
  115. def clean_ids_list(ids_list, error_message):
  116. try:
  117. return list(map(int, ids_list))
  118. except (ValueError, TypeError):
  119. raise PermissionDenied(error_message)
  120. def get_host_from_address(address):
  121. if not address:
  122. return None
  123. if address.lower().startswith("https://"):
  124. address = address[8:]
  125. if address.lower().startswith("http://"):
  126. address = address[7:]
  127. if address[0] == "/":
  128. address = address.lstrip("/")
  129. if "/" in address:
  130. address = address.split("/")[0] or address
  131. if ":" in address:
  132. address = address.split(":")[0] or address
  133. return address