create.py 3.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118
  1. from django.contrib.auth import authenticate, get_user_model, login
  2. from django.core.exceptions import PermissionDenied
  3. from django.utils.translation import ugettext as _
  4. from django.views.decorators.csrf import csrf_protect
  5. from rest_framework import status
  6. from rest_framework.response import Response
  7. from misago.conf import settings
  8. from misago.core import forms
  9. from misago.core.mail import mail_user
  10. from ... import captcha
  11. from ...bans import ban_ip
  12. from ...forms.register import RegisterForm
  13. from ...models import ACTIVATION_REQUIRED_ADMIN, ACTIVATION_REQUIRED_USER
  14. from ...serializers import AuthenticatedUserSerializer
  15. from ...tokens import make_activation_token
  16. from ...validators import validate_new_registration
  17. @csrf_protect
  18. def create_endpoint(request):
  19. if settings.account_activation == 'closed':
  20. raise PermissionDenied(_("New users registrations are currently closed."))
  21. form = RegisterForm(request.data)
  22. try:
  23. captcha.test_request(request)
  24. except forms.ValidationError as e:
  25. form.add_error('captcha', e)
  26. if not form.is_valid():
  27. return Response(form.errors, status=status.HTTP_400_BAD_REQUEST)
  28. try:
  29. validate_new_registration(
  30. request.user_ip,
  31. form.cleaned_data['username'],
  32. form.cleaned_data['email'])
  33. except PermissionDenied:
  34. staff_message = _("This ban was automatically imposed on "
  35. "%(date)s due to denied registration attempt.")
  36. message_formats = {'date': date_format(timezone.now())}
  37. staff_message = staff_message % message_formats
  38. ban_ip(
  39. request.user_ip,
  40. staff_message=staff_message,
  41. length={'days': 14}
  42. )
  43. raise PermissionDenied(
  44. _("Your IP address is banned from registering on this site."))
  45. activation_kwargs = {}
  46. if settings.account_activation == 'user':
  47. activation_kwargs = {
  48. 'requires_activation': ACTIVATION_REQUIRED_USER
  49. }
  50. elif settings.account_activation == 'admin':
  51. activation_kwargs = {
  52. 'requires_activation': ACTIVATION_REQUIRED_ADMIN
  53. }
  54. User = get_user_model()
  55. new_user = User.objects.create_user(
  56. form.cleaned_data['username'],
  57. form.cleaned_data['email'],
  58. form.cleaned_data['password'],
  59. joined_from_ip=request.user_ip,
  60. set_default_avatar=True,
  61. **activation_kwargs
  62. )
  63. mail_subject = _("Welcome on %(forum_name)s forums!")
  64. mail_subject = mail_subject % {'forum_name': settings.forum_name}
  65. if settings.account_activation == 'none':
  66. authenticated_user = authenticate(
  67. username=new_user.email,
  68. password=form.cleaned_data['password'])
  69. login(request, authenticated_user)
  70. mail_user(request, new_user, mail_subject,
  71. 'misago/emails/register/complete')
  72. return Response({
  73. 'activation': 'active',
  74. 'username': new_user.username,
  75. 'email': new_user.email
  76. })
  77. else:
  78. activation_token = make_activation_token(new_user)
  79. activation_by_admin = new_user.requires_activation_by_admin
  80. activation_by_user = new_user.requires_activation_by_user
  81. mail_user(
  82. request, new_user, mail_subject,
  83. 'misago/emails/register/inactive',
  84. {
  85. 'activation_token': activation_token,
  86. 'activation_by_admin': activation_by_admin,
  87. 'activation_by_user': activation_by_user,
  88. })
  89. if activation_by_admin:
  90. activation_method = 'admin'
  91. else:
  92. activation_method = 'user'
  93. return Response({
  94. 'activation': activation_method,
  95. 'username': new_user.username,
  96. 'email': new_user.email
  97. })