users.py 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389
  1. from django.contrib import messages
  2. from django.contrib.auth import get_user_model, update_session_auth_hash
  3. from django.db import transaction
  4. from django.http import JsonResponse
  5. from django.shortcuts import redirect
  6. from django.utils.translation import ugettext_lazy as _
  7. from misago.admin.auth import start_admin_session
  8. from misago.admin.views import generic
  9. from misago.categories.models import Category
  10. from misago.conf import settings
  11. from misago.core.mail import mail_users
  12. from misago.core.pgutils import batch_update
  13. from misago.threads.models import Thread
  14. from misago.users.avatars.dynamic import set_avatar as set_dynamic_avatar
  15. from misago.users.forms.admin import (StaffFlagUserFormFactory, NewUserForm,
  16. EditUserForm, SearchUsersForm,
  17. BanUsersForm)
  18. from misago.users.models import ACTIVATION_REQUIRED_NONE, User, Ban
  19. from misago.users.models.ban import BAN_USERNAME, BAN_EMAIL, BAN_IP
  20. from misago.users.signatures import set_user_signature
  21. class UserAdmin(generic.AdminBaseMixin):
  22. root_link = 'misago:admin:users:accounts:index'
  23. templates_dir = 'misago/admin/users'
  24. def get_model(self):
  25. return get_user_model()
  26. def create_form_type(self, request, target):
  27. if request.user.is_superuser:
  28. add_staff_field = request.user.pk != target.id
  29. else:
  30. add_staff_field = False
  31. return StaffFlagUserFormFactory(
  32. self.Form, target, add_staff_field=add_staff_field)
  33. class UsersList(UserAdmin, generic.ListView):
  34. items_per_page = 24
  35. ordering = (
  36. ('-id', _("From newest")),
  37. ('id', _("From oldest")),
  38. ('slug', _("A to z")),
  39. ('-slug', _("Z to a")),
  40. ('posts', _("Biggest posters")),
  41. ('-posts', _("Smallest posters")),
  42. )
  43. selection_label = _('With users: 0')
  44. empty_selection_label = _('Select users')
  45. mass_actions = [
  46. {
  47. 'action': 'activate',
  48. 'name': _("Activate accounts"),
  49. 'icon': 'fa fa-check-square-o',
  50. },
  51. {
  52. 'action': 'ban',
  53. 'name': _("Ban users"),
  54. 'icon': 'fa fa-lock',
  55. },
  56. {
  57. 'action': 'delete_accounts',
  58. 'name': _("Delete accounts"),
  59. 'icon': 'fa fa-times-circle',
  60. 'confirmation': _("Are you sure you want "
  61. "to delete selected users?"),
  62. },
  63. {
  64. 'action': 'delete_all',
  65. 'name': _("Delete all"),
  66. 'icon': 'fa fa-eraser',
  67. 'confirmation': _("Are you sure you want to delete selected "
  68. "users? This will also delete all content "
  69. "associated with their accounts."),
  70. 'is_atomic': False,
  71. }
  72. ]
  73. def get_queryset(self):
  74. qs = super(UsersList, self).get_queryset()
  75. return qs.select_related('rank')
  76. def get_search_form(self, request):
  77. return SearchUsersForm
  78. def action_activate(self, request, users):
  79. inactive_users = []
  80. for user in users:
  81. if user.requires_activation:
  82. inactive_users.append(user)
  83. if not inactive_users:
  84. message = _("You have to select inactive users.")
  85. raise generic.MassActionError(message)
  86. else:
  87. activated_users_pks = [u.pk for u in inactive_users]
  88. queryset = User.objects.filter(pk__in=activated_users_pks)
  89. queryset.update(requires_activation=ACTIVATION_REQUIRED_NONE)
  90. mail_subject = _("Your account on %(forum_name)s "
  91. "forums has been activated")
  92. subject_formats = {'forum_name': settings.forum_name}
  93. mail_subject = mail_subject % subject_formats
  94. mail_subject = mail_subject
  95. mail_users(request, inactive_users, mail_subject,
  96. 'misago/emails/activation/by_admin')
  97. message = _("Selected users accounts have been activated.")
  98. messages.success(request, message)
  99. def action_ban(self, request, users):
  100. users = users.order_by('slug')
  101. for user in users:
  102. if user.is_superuser:
  103. message = _("%(user)s is super admin and can't be banned.")
  104. mesage = message % {'user': user.username}
  105. raise generic.MassActionError(mesage)
  106. form = BanUsersForm()
  107. if 'finalize' in request.POST:
  108. form = BanUsersForm(request.POST)
  109. if form.is_valid():
  110. cleaned_data = form.cleaned_data
  111. banned_values = []
  112. ban_kwargs = {
  113. 'user_message': cleaned_data.get('user_message'),
  114. 'staff_message': cleaned_data.get('staff_message'),
  115. 'expires_on': cleaned_data.get('expires_on')
  116. }
  117. for user in users:
  118. for ban in cleaned_data['ban_type']:
  119. if ban == 'usernames':
  120. check_type = BAN_USERNAME
  121. banned_value = user.username.lower()
  122. if ban == 'emails':
  123. check_type = BAN_EMAIL
  124. banned_value = user.email.lower()
  125. if ban == 'domains':
  126. check_type = BAN_EMAIL
  127. banned_value = user.email.lower()
  128. at_pos = banned_value.find('@')
  129. banned_value = '*%s' % banned_value[at_pos:]
  130. if ban == 'ip':
  131. check_type = BAN_IP
  132. banned_value = user.joined_from_ip
  133. if ban in ('ip_first', 'ip_two'):
  134. check_type = BAN_IP
  135. if ':' in user.joined_from_ip:
  136. ip_separator = ':'
  137. if '.' in user.joined_from_ip:
  138. ip_separator = '.'
  139. bits = user.joined_from_ip.split(ip_separator)
  140. if ban == 'ip_first':
  141. formats = (bits[0], ip_separator)
  142. if ban == 'ip_two':
  143. formats = (
  144. bits[0], ip_separator,
  145. bits[1], ip_separator
  146. )
  147. banned_value = '%s*' % (''.join(formats))
  148. if banned_value not in banned_values:
  149. ban_kwargs.update({
  150. 'check_type': check_type,
  151. 'banned_value': banned_value
  152. })
  153. Ban.objects.create(**ban_kwargs)
  154. banned_values.append(banned_value)
  155. Ban.objects.invalidate_cache()
  156. message = _("Selected users have been banned.")
  157. messages.success(request, message)
  158. return None
  159. return self.render(
  160. request, template='misago/admin/users/ban.html', context={
  161. 'users': users,
  162. 'form': form,
  163. })
  164. def action_delete_accounts(self, request, users):
  165. for user in users:
  166. if user.is_staff or user.is_superuser:
  167. message = _("%(user)s is admin and can't be deleted.")
  168. mesage = message % {'user': user.username}
  169. raise generic.MassActionError(mesage)
  170. for user in users:
  171. user.delete()
  172. message = _("Selected users have been deleted.")
  173. messages.success(request, message)
  174. def action_delete_all(self, request, users):
  175. return self.render(
  176. request, template='misago/admin/users/delete.html', context={
  177. 'users': users,
  178. })
  179. for user in users:
  180. if user.is_staff or user.is_superuser:
  181. message = _("%(user)s is admin and can't be deleted.")
  182. mesage = message % {'user': user.username}
  183. raise generic.MassActionError(mesage)
  184. for user in users:
  185. user.delete(delete_content=True)
  186. message = _("Selected users and their content has been deleted.")
  187. messages.success(request, message)
  188. class NewUser(UserAdmin, generic.ModelFormView):
  189. Form = NewUserForm
  190. template = 'new.html'
  191. message_submit = _('New user "%(user)s" has been registered.')
  192. def handle_form(self, form, request, target):
  193. User = get_user_model()
  194. new_user = User.objects.create_user(
  195. form.cleaned_data['username'],
  196. form.cleaned_data['email'],
  197. form.cleaned_data['new_password'],
  198. title=form.cleaned_data['title'],
  199. rank=form.cleaned_data.get('rank'),
  200. joined_from_ip=request.user_ip,
  201. set_default_avatar=True)
  202. if form.cleaned_data.get('staff_level'):
  203. new_user.staff_level = form.cleaned_data['staff_level']
  204. if form.cleaned_data.get('roles'):
  205. new_user.roles.add(*form.cleaned_data['roles'])
  206. new_user.update_acl_key()
  207. new_user.save()
  208. messages.success(
  209. request, self.message_submit % {'user': target.username})
  210. return redirect('misago:admin:users:accounts:edit',
  211. user_id=new_user.id)
  212. class EditUser(UserAdmin, generic.ModelFormView):
  213. Form = EditUserForm
  214. template = 'edit.html'
  215. message_submit = _('User "%(user)s" has been edited.')
  216. def real_dispatch(self, request, target):
  217. target.old_username = target.username
  218. target.old_is_avatar_locked = target.is_avatar_locked
  219. return super(EditUser, self).real_dispatch(request, target)
  220. def handle_form(self, form, request, target):
  221. target.username = target.old_username
  222. if target.username != form.cleaned_data.get('username'):
  223. target.set_username(form.cleaned_data.get('username'),
  224. changed_by=request.user)
  225. if form.cleaned_data.get('new_password'):
  226. target.set_password(form.cleaned_data['new_password'])
  227. if target.pk == request.user.pk:
  228. start_admin_session(request, target)
  229. update_session_auth_hash(request, target)
  230. if form.cleaned_data.get('email'):
  231. target.set_email(form.cleaned_data['email'])
  232. if target.pk == request.user.pk:
  233. start_admin_session(request, target)
  234. if form.cleaned_data.get('is_avatar_locked'):
  235. if not target.old_is_avatar_locked:
  236. set_dynamic_avatar(target)
  237. if 'staff_level' in form.cleaned_data:
  238. target.staff_level = form.cleaned_data['staff_level']
  239. target.rank = form.cleaned_data.get('rank')
  240. if form.cleaned_data.get('roles'):
  241. target.roles.add(*form.cleaned_data['roles'])
  242. set_user_signature(request, target, form.cleaned_data.get('signature'))
  243. target.update_acl_key()
  244. target.save()
  245. messages.success(
  246. request, self.message_submit % {'user': target.username})
  247. class DeletionStep(UserAdmin, generic.ButtonView):
  248. is_atomic = False
  249. def check_permissions(self, request, target):
  250. if not request.is_ajax():
  251. return _("This action can't be accessed directly")
  252. if target.is_staff or target.is_superuser:
  253. message = _("%(user)s is admin and can't be deleted.")
  254. return message % {'user': user.username}
  255. def execute_step(self, user):
  256. raise NotImplementedError("execute_step method should return dict "
  257. "with number of deleted_count and "
  258. "is_completed keys")
  259. def button_action(self, request, target):
  260. return JsonResponse(self.execute_step(target))
  261. class DeleteThreadsStep(DeletionStep):
  262. def execute_step(self, user):
  263. recount_categories = set()
  264. deleted_threads = 0
  265. is_completed = False
  266. for thread in user.thread_set.order_by('-id')[:50]:
  267. recount_categories.add(thread.category_id)
  268. with transaction.atomic():
  269. thread.delete()
  270. deleted_threads += 1
  271. if recount_categories:
  272. for category in Category.objects.filter(id__in=recount_categories):
  273. category.synchronize()
  274. category.save()
  275. else:
  276. is_completed = True
  277. return {
  278. 'deleted_count': deleted_threads,
  279. 'is_completed': is_completed
  280. }
  281. class DeletePostsStep(DeletionStep):
  282. def execute_step(self, user):
  283. recount_categories = set()
  284. recount_threads = set()
  285. deleted_posts = 0
  286. is_completed = False
  287. for post in user.post_set.order_by('-id')[:50]:
  288. recount_categories.add(post.category_id)
  289. recount_threads.add(post.thread_id)
  290. with transaction.atomic():
  291. post.delete()
  292. deleted_posts += 1
  293. if recount_categories:
  294. changed_threads_qs = Thread.objects.filter(id__in=recount_threads)
  295. for thread in batch_update(changed_threads_qs, 50):
  296. thread.synchronize()
  297. thread.save()
  298. for category in Category.objects.filter(id__in=recount_categories):
  299. category.synchronize()
  300. category.save()
  301. else:
  302. is_completed = True
  303. return {
  304. 'deleted_count': deleted_posts,
  305. 'is_completed': is_completed
  306. }
  307. class DeleteAccountStep(DeletionStep):
  308. def execute_step(self, user):
  309. user.delete(delete_content=True)
  310. return {'is_completed': True}