users.py 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340
  1. from django.contrib import messages
  2. from django.contrib.auth import get_user_model, update_session_auth_hash
  3. from django.db import transaction
  4. from django.http import JsonResponse
  5. from django.shortcuts import redirect
  6. from django.utils.translation import ugettext_lazy as _
  7. from misago.admin.auth import start_admin_session
  8. from misago.admin.views import generic
  9. from misago.conf import settings
  10. from misago.core.mail import mail_users
  11. from misago.core.pgutils import batch_update
  12. from misago.forums.models import Forum
  13. from misago.threads.models import Thread
  14. from misago.users.avatars.dynamic import set_avatar as set_dynamic_avatar
  15. from misago.users.forms.admin import (StaffFlagUserFormFactory, NewUserForm,
  16. EditUserForm, SearchUsersForm,
  17. BanUsersForm)
  18. from misago.users.models import ACTIVATION_REQUIRED_NONE, User, Ban
  19. from misago.users.signatures import set_user_signature
  20. class UserAdmin(generic.AdminBaseMixin):
  21. root_link = 'misago:admin:users:accounts:index'
  22. templates_dir = 'misago/admin/users'
  23. def get_model(self):
  24. return get_user_model()
  25. def create_form_type(self, request, target):
  26. if request.user.is_superuser:
  27. add_staff_field = request.user.pk != target.id
  28. else:
  29. add_staff_field = False
  30. return StaffFlagUserFormFactory(
  31. self.Form, target, add_staff_field=add_staff_field)
  32. class UsersList(UserAdmin, generic.ListView):
  33. items_per_page = 24
  34. ordering = (
  35. ('-id', _("From newest")),
  36. ('id', _("From oldest")),
  37. ('slug', _("A to z")),
  38. ('-slug', _("Z to a")),
  39. ('posts', _("Biggest posters")),
  40. ('-posts', _("Smallest posters")),
  41. )
  42. selection_label = _('With users: 0')
  43. empty_selection_label = _('Select users')
  44. mass_actions = [
  45. {
  46. 'action': 'activate',
  47. 'name': _("Activate accounts"),
  48. 'icon': 'fa fa-check-square-o',
  49. },
  50. {
  51. 'action': 'ban',
  52. 'name': _("Ban users"),
  53. 'icon': 'fa fa-lock',
  54. },
  55. {
  56. 'action': 'delete_accounts',
  57. 'name': _("Delete accounts"),
  58. 'icon': 'fa fa-times-circle',
  59. 'confirmation': _("Are you sure you want "
  60. "to delete selected users?"),
  61. },
  62. {
  63. 'action': 'delete_all',
  64. 'name': _("Delete all"),
  65. 'icon': 'fa fa-eraser',
  66. 'confirmation': _("Are you sure you want to delete selected "
  67. "users? This will also delete all content "
  68. "associated with their accounts."),
  69. 'is_atomic': False,
  70. }
  71. ]
  72. def get_queryset(self):
  73. qs = super(UsersList, self).get_queryset()
  74. return qs.select_related('rank')
  75. def get_search_form(self, request):
  76. return SearchUsersForm
  77. def action_activate(self, request, users):
  78. inactive_users = []
  79. for user in users:
  80. if user.requires_activation:
  81. inactive_users.append(user)
  82. if not inactive_users:
  83. message = _("You have to select inactive users.")
  84. raise generic.MassActionError(message)
  85. else:
  86. activated_users_pks = [u.pk for u in inactive_users]
  87. queryset = User.objects.filter(pk__in=activated_users_pks)
  88. queryset.update(requires_activation=ACTIVATION_REQUIRED_NONE)
  89. mail_subject = _("Your account on %(forum_title)s "
  90. "forums has been activated")
  91. subject_formats = {'forum_title': settings.forum_name}
  92. mail_subject = mail_subject % subject_formats
  93. mail_subject = mail_subject
  94. mail_users(request, inactive_users, mail_subject,
  95. 'misago/emails/activation/by_admin')
  96. message = _("Selected users accounts have been activated.")
  97. messages.success(request, message)
  98. def action_ban(self, request, users):
  99. users = users.order_by('slug')
  100. for user in users:
  101. if user.is_superuser:
  102. message = _("%(user)s is super admin and can't be banned.")
  103. mesage = message % {'user': user.username}
  104. raise generic.MassActionError(mesage)
  105. form = BanUsersForm()
  106. if 'finalize' in request.POST:
  107. form = BanUsersForm(request.POST)
  108. if form.is_valid():
  109. for user in users:
  110. Ban.objects.create(
  111. banned_value=user.username,
  112. user_message=form.cleaned_data.get('user_message'),
  113. staff_message=form.cleaned_data.get('staff_message'),
  114. expires_on=form.cleaned_data.get('expires_on')
  115. )
  116. Ban.objects.invalidate_cache()
  117. message = _("Selected users have been banned.")
  118. messages.success(request, message)
  119. return None
  120. return self.render(
  121. request, template='misago/admin/users/ban.html', context={
  122. 'users': users,
  123. 'form': form,
  124. })
  125. def action_delete_accounts(self, request, users):
  126. for user in users:
  127. if user.is_staff or user.is_superuser:
  128. message = _("%(user)s is admin and can't be deleted.")
  129. mesage = message % {'user': user.username}
  130. raise generic.MassActionError(mesage)
  131. for user in users:
  132. user.delete()
  133. message = _("Selected users have been deleted.")
  134. messages.success(request, message)
  135. def action_delete_all(self, request, users):
  136. return self.render(
  137. request, template='misago/admin/users/delete.html', context={
  138. 'users': users,
  139. })
  140. for user in users:
  141. if user.is_staff or user.is_superuser:
  142. message = _("%(user)s is admin and can't be deleted.")
  143. mesage = message % {'user': user.username}
  144. raise generic.MassActionError(mesage)
  145. for user in users:
  146. user.delete(delete_content=True)
  147. message = _("Selected users and their content has been deleted.")
  148. messages.success(request, message)
  149. class NewUser(UserAdmin, generic.ModelFormView):
  150. Form = NewUserForm
  151. template = 'new.html'
  152. message_submit = _('New user "%(user)s" has been registered.')
  153. def handle_form(self, form, request, target):
  154. User = get_user_model()
  155. new_user = User.objects.create_user(
  156. form.cleaned_data['username'],
  157. form.cleaned_data['email'],
  158. form.cleaned_data['new_password'],
  159. title=form.cleaned_data['title'],
  160. rank=form.cleaned_data.get('rank'),
  161. joined_from_ip=request._misago_real_ip,
  162. set_default_avatar=True)
  163. if form.cleaned_data.get('staff_level'):
  164. new_user.staff_level = form.cleaned_data['staff_level']
  165. if form.cleaned_data.get('roles'):
  166. new_user.roles.add(*form.cleaned_data['roles'])
  167. new_user.update_acl_key()
  168. new_user.save()
  169. messages.success(
  170. request, self.message_submit % {'user': target.username})
  171. return redirect('misago:admin:users:accounts:edit',
  172. user_id=new_user.id)
  173. class EditUser(UserAdmin, generic.ModelFormView):
  174. Form = EditUserForm
  175. template = 'edit.html'
  176. message_submit = _('User "%(user)s" has been edited.')
  177. def real_dispatch(self, request, target):
  178. target.old_username = target.username
  179. target.old_is_avatar_locked = target.is_avatar_locked
  180. return super(EditUser, self).real_dispatch(request, target)
  181. def handle_form(self, form, request, target):
  182. target.username = target.old_username
  183. if target.username != form.cleaned_data.get('username'):
  184. target.set_username(form.cleaned_data.get('username'),
  185. changed_by=request.user)
  186. if form.cleaned_data.get('new_password'):
  187. target.set_password(form.cleaned_data['new_password'])
  188. if target.pk == request.user.pk:
  189. start_admin_session(request, target)
  190. update_session_auth_hash(request, target)
  191. if form.cleaned_data.get('email'):
  192. target.set_email(form.cleaned_data['email'])
  193. if target.pk == request.user.pk:
  194. start_admin_session(request, target)
  195. if form.cleaned_data.get('is_avatar_locked'):
  196. if not target.old_is_avatar_locked:
  197. set_dynamic_avatar(target)
  198. if 'staff_level' in form.cleaned_data:
  199. target.staff_level = form.cleaned_data['staff_level']
  200. target.rank = form.cleaned_data.get('rank')
  201. if form.cleaned_data.get('roles'):
  202. target.roles.add(*form.cleaned_data['roles'])
  203. set_user_signature(request, target, form.cleaned_data.get('signature'))
  204. target.update_acl_key()
  205. target.save()
  206. messages.success(
  207. request, self.message_submit % {'user': target.username})
  208. class DeletionStep(UserAdmin, generic.ButtonView):
  209. is_atomic = False
  210. def check_permissions(self, request, target):
  211. if not request.is_ajax():
  212. return _("This action can't be accessed directly")
  213. if target.is_staff or target.is_superuser:
  214. message = _("%(user)s is admin and can't be deleted.")
  215. return message % {'user': user.username}
  216. def execute_step(self, user):
  217. raise NotImplementedError("execute_step method should return dict "
  218. "with number of deleted_count and "
  219. "is_completed keys")
  220. def button_action(self, request, target):
  221. return JsonResponse(self.execute_step(target))
  222. class DeleteThreadsStep(DeletionStep):
  223. def execute_step(self, user):
  224. recount_forums = set()
  225. deleted_threads = 0
  226. is_completed = False
  227. for thread in user.thread_set.order_by('-id')[:50]:
  228. recount_forums.add(thread.forum_id)
  229. with transaction.atomic():
  230. thread.delete()
  231. deleted_threads += 1
  232. if recount_forums:
  233. for forum in Forum.objects.filter(id__in=recount_forums):
  234. forum.synchronize()
  235. forum.save()
  236. else:
  237. is_completed = True
  238. return {
  239. 'deleted_count': deleted_threads,
  240. 'is_completed': is_completed
  241. }
  242. class DeletePostsStep(DeletionStep):
  243. def execute_step(self, user):
  244. recount_forums = set()
  245. recount_threads = set()
  246. deleted_posts = 0
  247. is_completed = False
  248. for post in user.post_set.order_by('-id')[:50]:
  249. recount_forums.add(post.forum_id)
  250. recount_threads.add(post.thread_id)
  251. with transaction.atomic():
  252. post.delete()
  253. deleted_posts += 1
  254. if recount_forums:
  255. changed_threads_qs = Thread.objects.filter(id__in=recount_threads)
  256. for thread in batch_update(changed_threads_qs, 50):
  257. thread.synchronize()
  258. thread.save()
  259. for forum in Forum.objects.filter(id__in=recount_forums):
  260. forum.synchronize()
  261. forum.save()
  262. else:
  263. is_completed = True
  264. return {
  265. 'deleted_count': deleted_posts,
  266. 'is_completed': is_completed
  267. }
  268. class DeleteAccountStep(DeletionStep):
  269. def execute_step(self, user):
  270. user.delete(delete_content=True)
  271. return {'is_completed': True}