answers.py 8.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273
  1. from django import forms
  2. from django.core.exceptions import PermissionDenied
  3. from django.utils import timezone
  4. from django.utils.translation import ugettext_lazy as _, ungettext
  5. from misago.acl import algebra
  6. from misago.acl.decorators import return_boolean
  7. from misago.categories.models import Category, CategoryRole
  8. from misago.categories.permissions import get_categories_roles
  9. from misago.core.forms import YesNoSwitch
  10. from misago.threads.models import Post
  11. __all__nope = [
  12. 'allow_select_answer',
  13. 'can_select_answer',
  14. 'allow_remove_answer',
  15. 'can_remove_answer',
  16. ]
  17. class CategoryPermissionsForm(forms.Form):
  18. legend = _("Answers")
  19. can_set_answers = forms.TypedChoiceField(
  20. label=_("Can set answers"),
  21. coerce=int,
  22. initial=0,
  23. choices=[
  24. (0, _("No")),
  25. (1, _("Own threads")),
  26. (2, _("All threads")),
  27. ],
  28. )
  29. can_change_answers = forms.TypedChoiceField(
  30. label=_("Can change answers"),
  31. coerce=int,
  32. initial=0,
  33. choices=[
  34. (0, _("No")),
  35. (1, _("Own threads")),
  36. (2, _("All threads")),
  37. ],
  38. )
  39. answer_change_time = forms.IntegerField(
  40. label=_("Time limit for owned thread answer change, in minutes"),
  41. help_text=_("Enter 0 to don't limit time for changing own thread answer."),
  42. initial=0,
  43. min_value=0,
  44. )
  45. def change_permissions_form(role):
  46. if isinstance(role, CategoryRole):
  47. return CategoryPermissionsForm
  48. else:
  49. return None
  50. def build_acl(acl, roles, key_name):
  51. categories_roles = get_categories_roles(roles)
  52. categories = list(Category.objects.all_categories(include_root=True))
  53. for category in categories:
  54. category_acl = acl['categories'].get(category.pk, {'can_browse': 0})
  55. if category_acl['can_browse']:
  56. category_acl = acl['categories'][category.pk] = build_category_acl(
  57. category_acl, category, categories_roles, key_name
  58. )
  59. return acl
  60. def build_category_acl(acl, category, categories_roles, key_name):
  61. category_roles = categories_roles.get(category.pk, [])
  62. final_acl = {
  63. 'can_set_answers': 0,
  64. 'can_change_answers': 0,
  65. 'answer_change_time': 0,
  66. }
  67. final_acl.update(acl)
  68. algebra.sum_acls(
  69. final_acl,
  70. roles=category_roles,
  71. key=key_name,
  72. can_set_answers=algebra.greater,
  73. can_change_answers=algebra.greater,
  74. answer_change_time=algebra.greater_or_zero,
  75. )
  76. return final_acl
  77. def add_acl_to_post(user, post):
  78. post.acl.update({
  79. 'can_set_answer': can_set_answer(user, post),
  80. 'can_unset_answer': can_unset_answer(user, post),
  81. })
  82. def register_with(registry):
  83. registry.acl_annotator(Post, add_acl_to_post)
  84. def allow_set_answer(user, target):
  85. if user.is_anonymous:
  86. raise PermissionDenied(_("You have to sign in to set posts as answers."))
  87. if target.is_event:
  88. raise PermissionDenied(_("Events can't be set as answers."))
  89. category_acl = user.acl_cache['categories'].get(
  90. target.category_id, {
  91. 'can_set_answers': 0,
  92. }
  93. )
  94. if not category_acl['can_set_answers']:
  95. raise PermissionDenied(
  96. _(
  97. 'You don\'t have permission to set answers in the "%(category)s" category.'
  98. ) % {
  99. 'category': target.category,
  100. }
  101. )
  102. if category_acl['can_set_answers'] == 1 and target.thread.starter != user:
  103. raise PermissionDenied(
  104. _(
  105. "You dont't have permission to set this post as an answer "
  106. "because you are not the thread starter."
  107. )
  108. )
  109. if target.is_first_post:
  110. raise PermissionDenied(_("First post in a thread can't be set as an answer."))
  111. if target.is_hidden:
  112. raise PermissionDenied(_("Hidden posts can't be set as answers."))
  113. if target.is_unapproved:
  114. raise PermissionDenied(_("Unapproved posts can't be set as answers."))
  115. if target.is_answer:
  116. raise PermissionDenied(_("This post is already set as an answer."))
  117. if category_acl['can_set_answers'] == 1 and target.thread.answer_id:
  118. if not has_time_to_change_answer(user, target):
  119. raise PermissionDenied(
  120. ungettext(
  121. (
  122. "You don't have permission to change thread's answer that was set "
  123. "for more than %(minutes)s minute."),
  124. (
  125. "You don't have permission to change thread's answer that was set "
  126. "for more than %(minutes)s minutes."),
  127. category_acl['answer_change_time'],
  128. ) % {
  129. 'minutes': category_acl['answer_change_time'],
  130. }
  131. )
  132. if target.thread.answer_is_protected and not category_acl['can_protect_posts']:
  133. raise PermissionDenied(
  134. _(
  135. "You don't have permission to change this thread's answer because moderator "
  136. "has protected it."
  137. )
  138. )
  139. if not category_acl['can_close_threads']:
  140. if target.category.is_closed:
  141. raise PermissionDenied(
  142. _(
  143. 'You can\'t sets this post as an answer because it\'s category '
  144. '"%(category)s" is closed.'
  145. ) % {
  146. 'category': target.category,
  147. }
  148. )
  149. if target.thread.is_closed:
  150. raise PermissionDenied(
  151. _(
  152. "You can't set this post as an answer because it's thread is closed and you "
  153. "don't have permission to open it."
  154. )
  155. )
  156. if target.is_protected and not category_acl['can_protect_posts']:
  157. raise PermissionDenied(
  158. _("You can't sets this post as an answer because moderator has protected it.")
  159. )
  160. can_set_answer = return_boolean(allow_set_answer)
  161. def allow_unset_answer(user, target):
  162. if user.is_anonymous:
  163. raise PermissionDenied(_("You have to sign in to unset threads answers."))
  164. category_acl = user.acl_cache['categories'].get(
  165. target.category_id, {
  166. 'can_change_answers': 0,
  167. }
  168. )
  169. if not category_acl['can_change_answers']:
  170. raise PermissionDenied(
  171. _(
  172. 'You don\'t have permission to unset threads answers in the "%(category)s" '
  173. 'category.'
  174. ) % {
  175. 'category': target.category,
  176. }
  177. )
  178. if not target.is_answer:
  179. raise PermissionDenied(
  180. _(
  181. "You can't unset."
  182. )
  183. )
  184. if category_acl['can_change_answers'] == 1 and target.thread.starter != user:
  185. raise PermissionDenied(
  186. _(
  187. "You dont't have permission to unset this answer because "
  188. "you are not a thread starter."
  189. )
  190. )
  191. if not category_acl['can_close_threads']:
  192. if target.category.is_closed:
  193. raise PermissionDenied(
  194. _(
  195. 'You can\'t unset this answer because it\'s scategory "%(category)s" is closed.'
  196. ) % {
  197. 'category': target.category,
  198. }
  199. )
  200. if target.thread.is_closed:
  201. raise PermissionDenied(
  202. _(
  203. "You don't have permission to unset this answer because it's thread is closed "
  204. "and you don't have permission to open it."
  205. )
  206. )
  207. if target.is_protected and not category_acl['can_protect_posts']:
  208. raise PermissionDenied(
  209. _(
  210. "You don't have permission to unset this thread's answer because moderator has "
  211. "protected it."
  212. )
  213. )
  214. can_unset_answer = return_boolean(allow_unset_answer)
  215. def has_time_to_change_answer(user, target):
  216. category_acl = user.acl_cache['categories'].get(target.category_id, {})
  217. change_time = category_acl.get('answer_change_time', 0)
  218. if change_time:
  219. diff = timezone.now() - target.thread.answer_set_on
  220. diff_minutes = int(diff.total_seconds() / 60)
  221. return diff_minutes < change_time
  222. else:
  223. return True