register.py 5.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144
  1. from django.contrib import messages
  2. from django.contrib.auth import authenticate, get_user_model, login
  3. from django.core.exceptions import PermissionDenied
  4. from django.http import Http404
  5. from django.shortcuts import get_object_or_404, redirect, render
  6. from django.utils import timezone
  7. from django.utils.formats import date_format
  8. from django.utils.translation import ugettext as _
  9. from django.views.decorators.cache import never_cache
  10. from django.views.decorators.debug import sensitive_post_parameters
  11. from misago.conf import settings
  12. from misago.core.mail import mail_user
  13. from misago.users.bans import ban_ip
  14. from misago.users.decorators import deny_authenticated, deny_banned_ips
  15. from misago.users.forms.register import RegisterForm
  16. from misago.users.models import (ACTIVATION_REQUIRED_USER,
  17. ACTIVATION_REQUIRED_ADMIN)
  18. from misago.users.tokens import make_activation_token
  19. from misago.users.validators import validate_new_registration
  20. def register_decorator(f):
  21. def decorator(request):
  22. if settings.account_activation == 'disabled':
  23. return register_disabled(request)
  24. else:
  25. return f(request)
  26. return decorator
  27. @sensitive_post_parameters("email", "password")
  28. @never_cache
  29. @deny_authenticated
  30. @deny_banned_ips
  31. @register_decorator
  32. def register(request):
  33. SecuredForm = add_captcha_to_form(RegisterForm, request)
  34. form = SecuredForm()
  35. if request.method == 'POST':
  36. form = SecuredForm(request.POST)
  37. if form.is_valid():
  38. try:
  39. validate_new_registration(
  40. request.user.ip,
  41. form.cleaned_data['username'],
  42. form.cleaned_data['email'])
  43. except PermissionDenied as e:
  44. staff_message = _("This ban was automatically imposed on "
  45. "%(date)s due to denied register attempt.")
  46. message_formats = {'date': date_format(timezone.now())}
  47. staff_message = staff_message % message_formats
  48. ban_ip(request.user.ip,
  49. staff_message=staff_message,
  50. length={'days': 1})
  51. raise e
  52. activation_kwargs = {}
  53. if settings.account_activation == 'user':
  54. activation_kwargs = {
  55. 'requires_activation': ACTIVATION_REQUIRED_USER
  56. }
  57. elif settings.account_activation == 'admin':
  58. activation_kwargs = {
  59. 'requires_activation': ACTIVATION_REQUIRED_ADMIN
  60. }
  61. User = get_user_model()
  62. new_user = User.objects.create_user(form.cleaned_data['username'],
  63. form.cleaned_data['email'],
  64. form.cleaned_data['password'],
  65. set_default_avatar=True,
  66. **activation_kwargs)
  67. mail_subject = _("Welcome on %(forum_title)s forums!")
  68. mail_subject = mail_subject % {'forum_title': settings.forum_name}
  69. if settings.account_activation == 'none':
  70. authenticated_user = authenticate(
  71. username=new_user.email,
  72. password=form.cleaned_data['password'])
  73. login(request, authenticated_user)
  74. welcome_message = _("Welcome aboard, %(user)s!")
  75. welcome_message = welcome_message % {'user': new_user.username}
  76. messages.success(request, welcome_message)
  77. mail_user(request, new_user, mail_subject,
  78. 'misago/emails/register/complete')
  79. return redirect(settings.LOGIN_REDIRECT_URL)
  80. else:
  81. activation_token = make_activation_token(new_user)
  82. activation_by_admin = new_user.requires_activation_by_admin
  83. activation_by_user = new_user.requires_activation_by_user
  84. mail_user(
  85. request, new_user, mail_subject,
  86. 'misago/emails/register/inactive',
  87. {
  88. 'activation_token': activation_token,
  89. 'activation_by_admin': activation_by_admin,
  90. 'activation_by_user': activation_by_user,
  91. })
  92. request.session['registered_user'] = new_user.pk
  93. return redirect('misago:register_completed')
  94. return render(request, 'misago/register/form.html', {'form': form})
  95. def register_disabled(request):
  96. return render(request, 'misago/register/disabled.html')
  97. def register_completed(request):
  98. """
  99. If user needs to activate his account, we display him page with message
  100. """
  101. registered_user_pk = request.session.get('registered_user')
  102. if not registered_user_pk:
  103. raise Http404()
  104. registered_user = get_object_or_404(get_user_model().objects,
  105. pk=registered_user_pk)
  106. if not registered_user.requires_activation:
  107. return redirect('misago:index')
  108. activation_by_admin = registered_user.requires_activation_by_admin
  109. activation_by_user = registered_user.requires_activation_by_user
  110. return render(
  111. request,
  112. 'misago/register/completed.html',
  113. {
  114. 'activation_by_admin': activation_by_admin,
  115. 'activation_by_user': activation_by_user,
  116. 'registered_user': registered_user,
  117. })