users.py 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400
  1. from django.contrib import messages
  2. from django.contrib.auth import get_user_model, update_session_auth_hash
  3. from django.db import transaction
  4. from django.http import JsonResponse
  5. from django.shortcuts import redirect
  6. from django.utils.translation import ugettext_lazy as _
  7. from misago.admin.auth import start_admin_session
  8. from misago.admin.views import generic
  9. from misago.categories.models import Category
  10. from misago.conf import settings
  11. from misago.core.mail import mail_users
  12. from misago.core.pgutils import batch_update
  13. from misago.threads.models import Thread
  14. from misago.users.avatars.dynamic import set_avatar as set_dynamic_avatar
  15. from misago.users.forms.admin import (
  16. BanUsersForm, EditUserForm, EditUserFormFactory, NewUserForm, SearchUsersForm)
  17. from misago.users.models import Ban
  18. from misago.users.signatures import set_user_signature
  19. UserModel = get_user_model()
  20. class UserAdmin(generic.AdminBaseMixin):
  21. root_link = 'misago:admin:users:accounts:index'
  22. templates_dir = 'misago/admin/users'
  23. model = UserModel
  24. def create_form_type(self, request, target):
  25. add_is_active_fields = False
  26. add_admin_fields = False
  27. if target.is_staff:
  28. if request.user.is_superuser:
  29. add_is_active_fields = request.user.pk != target.pk
  30. else:
  31. add_is_active_fields = True
  32. if request.user.is_superuser:
  33. add_admin_fields = request.user.pk != target.pk
  34. return EditUserFormFactory(
  35. self.form, target,
  36. add_is_active_fields=add_is_active_fields,
  37. add_admin_fields=add_admin_fields,
  38. )
  39. class UsersList(UserAdmin, generic.ListView):
  40. items_per_page = 24
  41. ordering = (
  42. ('-id', _("From newest")),
  43. ('id', _("From oldest")),
  44. ('slug', _("A to z")),
  45. ('-slug', _("Z to a")),
  46. ('posts', _("Biggest posters")),
  47. ('-posts', _("Smallest posters")),
  48. )
  49. selection_label = _('With users: 0')
  50. empty_selection_label = _('Select users')
  51. mass_actions = [
  52. {
  53. 'action': 'activate',
  54. 'name': _("Activate accounts"),
  55. 'icon': 'fa fa-check-square-o',
  56. },
  57. {
  58. 'action': 'ban',
  59. 'name': _("Ban users"),
  60. 'icon': 'fa fa-lock',
  61. },
  62. {
  63. 'action': 'delete_accounts',
  64. 'name': _("Delete accounts"),
  65. 'icon': 'fa fa-times-circle',
  66. 'confirmation': _("Are you sure you want to delete selected users?"),
  67. },
  68. {
  69. 'action': 'delete_all',
  70. 'name': _("Delete all"),
  71. 'icon': 'fa fa-eraser',
  72. 'confirmation': _("Are you sure you want to delete selected "
  73. "users? This will also delete all content "
  74. "associated with their accounts."),
  75. 'is_atomic': False,
  76. }
  77. ]
  78. def get_queryset(self):
  79. qs = super(UsersList, self).get_queryset()
  80. return qs.select_related('rank')
  81. def get_search_form(self, request):
  82. return SearchUsersForm
  83. def action_activate(self, request, users):
  84. inactive_users = []
  85. for user in users:
  86. if user.requires_activation:
  87. inactive_users.append(user)
  88. if not inactive_users:
  89. message = _("You have to select inactive users.")
  90. raise generic.MassActionError(message)
  91. else:
  92. activated_users_pks = [u.pk for u in inactive_users]
  93. queryset = UserModel.objects.filter(pk__in=activated_users_pks)
  94. queryset.update(requires_activation=UserModel.ACTIVATION_NONE)
  95. subject = _("Your account on %(forum_name)s forums has been activated")
  96. mail_subject = subject % {
  97. 'forum_name': settings.forum_name
  98. }
  99. mail_users(request, inactive_users, mail_subject,
  100. 'misago/emails/activation/by_admin')
  101. message = _("Selected users accounts have been activated.")
  102. messages.success(request, message)
  103. def action_ban(self, request, users):
  104. users = users.order_by('slug')
  105. for user in users:
  106. if user.is_superuser:
  107. message = _("%(user)s is super admin and can't be banned.")
  108. mesage = message % {'user': user.username}
  109. raise generic.MassActionError(mesage)
  110. form = BanUsersForm()
  111. if 'finalize' in request.POST:
  112. form = BanUsersForm(request.POST)
  113. if form.is_valid():
  114. cleaned_data = form.cleaned_data
  115. banned_values = []
  116. ban_kwargs = {
  117. 'user_message': cleaned_data.get('user_message'),
  118. 'staff_message': cleaned_data.get('staff_message'),
  119. 'expires_on': cleaned_data.get('expires_on')
  120. }
  121. for user in users:
  122. for ban in cleaned_data['ban_type']:
  123. if ban == 'usernames':
  124. check_type = Ban.USERNAME
  125. banned_value = user.username.lower()
  126. if ban == 'emails':
  127. check_type = Ban.EMAIL
  128. banned_value = user.email.lower()
  129. if ban == 'domains':
  130. check_type = Ban.EMAIL
  131. banned_value = user.email.lower()
  132. at_pos = banned_value.find('@')
  133. banned_value = '*%s' % banned_value[at_pos:]
  134. if ban == 'ip':
  135. check_type = Ban.IP
  136. banned_value = user.joined_from_ip
  137. if ban in ('ip_first', 'ip_two'):
  138. check_type = Ban.IP
  139. if ':' in user.joined_from_ip:
  140. ip_separator = ':'
  141. if '.' in user.joined_from_ip:
  142. ip_separator = '.'
  143. bits = user.joined_from_ip.split(ip_separator)
  144. if ban == 'ip_first':
  145. formats = (bits[0], ip_separator)
  146. if ban == 'ip_two':
  147. formats = (
  148. bits[0], ip_separator,
  149. bits[1], ip_separator
  150. )
  151. banned_value = '%s*' % (''.join(formats))
  152. if banned_value not in banned_values:
  153. ban_kwargs.update({
  154. 'check_type': check_type,
  155. 'banned_value': banned_value
  156. })
  157. Ban.objects.create(**ban_kwargs)
  158. banned_values.append(banned_value)
  159. Ban.objects.invalidate_cache()
  160. message = _("Selected users have been banned.")
  161. messages.success(request, message)
  162. return None
  163. return self.render(
  164. request, template='misago/admin/users/ban.html', context={
  165. 'users': users,
  166. 'form': form,
  167. })
  168. def action_delete_accounts(self, request, users):
  169. for user in users:
  170. if user.is_staff or user.is_superuser:
  171. message = _("%(user)s is admin and can't be deleted.")
  172. mesage = message % {'user': user.username}
  173. raise generic.MassActionError(mesage)
  174. for user in users:
  175. user.delete()
  176. message = _("Selected users have been deleted.")
  177. messages.success(request, message)
  178. def action_delete_all(self, request, users):
  179. for user in users:
  180. if user.is_staff or user.is_superuser:
  181. message = _("%(user)s is admin and can't be deleted.")
  182. mesage = message % {'user': user.username}
  183. raise generic.MassActionError(mesage)
  184. for user in users:
  185. user.delete(delete_content=True)
  186. message = _("Selected users and their content has been deleted.")
  187. messages.success(request, message)
  188. return self.render(
  189. request,
  190. template='misago/admin/users/delete.html',
  191. context={
  192. 'users': users,
  193. }
  194. )
  195. class NewUser(UserAdmin, generic.ModelFormView):
  196. form = NewUserForm
  197. template = 'new.html'
  198. message_submit = _('New user "%(user)s" has been registered.')
  199. def handle_form(self, form, request, target):
  200. new_user = UserModel.objects.create_user(
  201. form.cleaned_data['username'],
  202. form.cleaned_data['email'],
  203. form.cleaned_data['new_password'],
  204. title=form.cleaned_data['title'],
  205. rank=form.cleaned_data.get('rank'),
  206. joined_from_ip=request.user_ip,
  207. set_default_avatar=True
  208. )
  209. if form.cleaned_data.get('staff_level'):
  210. new_user.staff_level = form.cleaned_data['staff_level']
  211. if form.cleaned_data.get('roles'):
  212. new_user.roles.add(*form.cleaned_data['roles'])
  213. new_user.update_acl_key()
  214. new_user.save()
  215. messages.success(
  216. request, self.message_submit % {'user': target.username})
  217. return redirect('misago:admin:users:accounts:edit', pk=new_user.pk)
  218. class EditUser(UserAdmin, generic.ModelFormView):
  219. form = EditUserForm
  220. template = 'edit.html'
  221. message_submit = _('User "%(user)s" has been edited.')
  222. def real_dispatch(self, request, target):
  223. target.old_username = target.username
  224. target.old_is_avatar_locked = target.is_avatar_locked
  225. return super(EditUser, self).real_dispatch(request, target)
  226. def handle_form(self, form, request, target):
  227. target.username = target.old_username
  228. if target.username != form.cleaned_data.get('username'):
  229. target.set_username(
  230. form.cleaned_data.get('username'), changed_by=request.user)
  231. if form.cleaned_data.get('new_password'):
  232. target.set_password(form.cleaned_data['new_password'])
  233. if target.pk == request.user.pk:
  234. start_admin_session(request, target)
  235. update_session_auth_hash(request, target)
  236. if form.cleaned_data.get('email'):
  237. target.set_email(form.cleaned_data['email'])
  238. if target.pk == request.user.pk:
  239. start_admin_session(request, target)
  240. if form.cleaned_data.get('is_avatar_locked'):
  241. if not target.old_is_avatar_locked:
  242. set_dynamic_avatar(target)
  243. if 'is_staff' in form.fields and 'is_superuser' in form.fields:
  244. target.is_staff = form.cleaned_data.get('is_staff')
  245. target.is_superuser = form.cleaned_data.get('is_superuser')
  246. if 'is_active' in form.fields and 'is_active_staff_message' in form.fields:
  247. target.is_active = form.cleaned_data.get('is_active')
  248. target.is_active_staff_message = form.cleaned_data.get('is_active_staff_message')
  249. target.rank = form.cleaned_data.get('rank')
  250. target.roles.clear()
  251. target.roles.add(*form.cleaned_data['roles'])
  252. set_user_signature(request, target, form.cleaned_data.get('signature'))
  253. target.update_acl_key()
  254. target.save()
  255. messages.success(
  256. request, self.message_submit % {'user': target.username})
  257. class DeletionStep(UserAdmin, generic.ButtonView):
  258. is_atomic = False
  259. def check_permissions(self, request, target):
  260. if not request.is_ajax():
  261. return _("This action can't be accessed directly")
  262. if target.is_staff or target.is_superuser:
  263. return _("%(user)s is admin and can't be deleted.") % {'user': target.username}
  264. def execute_step(self, user):
  265. raise NotImplementedError(
  266. "execute_step method should return dict with number of deleted_count and is_completed keys")
  267. def button_action(self, request, target):
  268. return JsonResponse(self.execute_step(target))
  269. class DeleteThreadsStep(DeletionStep):
  270. def execute_step(self, user):
  271. recount_categories = set()
  272. deleted_threads = 0
  273. is_completed = False
  274. for thread in user.thread_set.order_by('-id')[:50]:
  275. recount_categories.add(thread.category_id)
  276. with transaction.atomic():
  277. thread.delete()
  278. deleted_threads += 1
  279. if recount_categories:
  280. for category in Category.objects.filter(id__in=recount_categories):
  281. category.synchronize()
  282. category.save()
  283. else:
  284. is_completed = True
  285. return {
  286. 'deleted_count': deleted_threads,
  287. 'is_completed': is_completed
  288. }
  289. class DeletePostsStep(DeletionStep):
  290. def execute_step(self, user):
  291. recount_categories = set()
  292. recount_threads = set()
  293. deleted_posts = 0
  294. is_completed = False
  295. for post in user.post_set.order_by('-id')[:50]:
  296. recount_categories.add(post.category_id)
  297. recount_threads.add(post.thread_id)
  298. with transaction.atomic():
  299. post.delete()
  300. deleted_posts += 1
  301. if recount_categories:
  302. changed_threads_qs = Thread.objects.filter(id__in=recount_threads)
  303. for thread in batch_update(changed_threads_qs, 50):
  304. thread.synchronize()
  305. thread.save()
  306. for category in Category.objects.filter(id__in=recount_categories):
  307. category.synchronize()
  308. category.save()
  309. else:
  310. is_completed = True
  311. return {
  312. 'deleted_count': deleted_posts,
  313. 'is_completed': is_completed
  314. }
  315. class DeleteAccountStep(DeletionStep):
  316. def execute_step(self, user):
  317. user.delete(delete_content=True)
  318. return {'is_completed': True}