models.py 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519
  1. import hashlib
  2. import math
  3. from random import choice
  4. from path import path
  5. from django.conf import settings
  6. from django.contrib.auth.hashers import (
  7. check_password, make_password, is_password_usable, UNUSABLE_PASSWORD)
  8. from django.core.cache import cache, InvalidCacheBackendError
  9. from django.core.exceptions import ValidationError
  10. from django.core.mail import EmailMultiAlternatives
  11. from django.db import models
  12. from django.template import RequestContext
  13. from django.utils import timezone as tz_util
  14. from django.utils.translation import ugettext_lazy as _
  15. from misago.acl.builder import build_acl
  16. from misago.monitor.monitor import Monitor
  17. from misago.roles.models import Role
  18. from misago.settings.settings import Settings as DBSettings
  19. from misago.users.signals import delete_user_content, rename_user
  20. from misago.users.validators import validate_username, validate_password, validate_email
  21. from misago.utils import get_random_string, slugify
  22. from misago.utils.avatars import avatar_size
  23. class UserManager(models.Manager):
  24. """
  25. User Manager provides us with some additional methods for users
  26. """
  27. def get_blank_user(self):
  28. blank_user = User(
  29. join_date=tz_util.now(),
  30. join_ip='127.0.0.1'
  31. )
  32. return blank_user
  33. def resync_monitor(self, monitor):
  34. monitor['users'] = self.count()
  35. monitor['users_inactive'] = self.filter(activation__gt=0).count()
  36. last_user = self.latest('id')
  37. monitor['last_user'] = last_user.pk
  38. monitor['last_user_name'] = last_user.username
  39. monitor['last_user_slug'] = last_user.username_slug
  40. def create_user(self, username, email, password, timezone=False, ip='127.0.0.1', no_roles=False, activation=0, request=False):
  41. token = ''
  42. if activation > 0:
  43. token = get_random_string(12)
  44. try:
  45. db_settings = request.settings
  46. except AttributeError:
  47. db_settings = DBSettings()
  48. if timezone == False:
  49. timezone = db_settings['default_timezone']
  50. # Get first rank
  51. try:
  52. from misago.ranks.models import Rank
  53. default_rank = Rank.objects.filter(special=0).order_by('order')[0]
  54. except IndexError:
  55. default_rank = None
  56. # Store user in database
  57. new_user = User(
  58. last_sync=tz_util.now(),
  59. join_date=tz_util.now(),
  60. join_ip=ip,
  61. activation=activation,
  62. token=token,
  63. timezone=timezone,
  64. rank=default_rank,
  65. )
  66. new_user.set_username(username)
  67. new_user.set_email(email)
  68. new_user.set_password(password)
  69. new_user.full_clean()
  70. new_user.default_avatar(db_settings)
  71. new_user.save(force_insert=True)
  72. # Set user roles?
  73. if not no_roles:
  74. from misago.roles.models import Role
  75. new_user.roles.add(Role.objects.get(token='registered'))
  76. new_user.make_acl_key()
  77. new_user.save(force_update=True)
  78. # Load monitor
  79. try:
  80. monitor = request.monitor
  81. except AttributeError:
  82. monitor = Monitor()
  83. # Update forum stats
  84. if activation == 0:
  85. monitor['users'] = int(monitor['users']) + 1
  86. monitor['last_user'] = new_user.pk
  87. monitor['last_user_name'] = new_user.username
  88. monitor['last_user_slug'] = new_user.username_slug
  89. else:
  90. monitor['users_inactive'] = int(monitor['users_inactive']) + 1
  91. # Return new user
  92. return new_user
  93. def get_by_email(self, email):
  94. return self.get(email_hash=hashlib.md5(email).hexdigest())
  95. def filter_stats(self, start, end):
  96. return self.filter(join_date__gte=start).filter(join_date__lte=end)
  97. class User(models.Model):
  98. """
  99. Misago User model
  100. """
  101. username = models.CharField(max_length=255, validators=[validate_username])
  102. username_slug = models.SlugField(max_length=255, unique=True,
  103. error_messages={'unique': _("This user name is already in use by another user.")})
  104. email = models.EmailField(max_length=255, validators=[validate_email])
  105. email_hash = models.CharField(max_length=32, unique=True,
  106. error_messages={'unique': _("This email address is already in use by another user.")})
  107. password = models.CharField(max_length=255)
  108. password_date = models.DateTimeField()
  109. avatar_type = models.CharField(max_length=10, null=True, blank=True)
  110. avatar_image = models.CharField(max_length=255, null=True, blank=True)
  111. avatar_original = models.CharField(max_length=255, null=True, blank=True)
  112. avatar_temp = models.CharField(max_length=255, null=True, blank=True)
  113. signature = models.TextField(null=True, blank=True)
  114. signature_preparsed = models.TextField(null=True, blank=True)
  115. join_date = models.DateTimeField()
  116. join_ip = models.GenericIPAddressField()
  117. join_agent = models.TextField(null=True, blank=True)
  118. last_date = models.DateTimeField(null=True, blank=True)
  119. last_ip = models.GenericIPAddressField(null=True, blank=True)
  120. last_agent = models.TextField(null=True, blank=True)
  121. hide_activity = models.PositiveIntegerField(default=0)
  122. alert_ats = models.PositiveIntegerField(default=0)
  123. allow_pms = models.PositiveIntegerField(default=0)
  124. receive_newsletters = models.BooleanField(default=True)
  125. threads = models.PositiveIntegerField(default=0)
  126. posts = models.PositiveIntegerField(default=0)
  127. votes = models.PositiveIntegerField(default=0)
  128. karma_given_p = models.PositiveIntegerField(default=0)
  129. karma_given_n = models.PositiveIntegerField(default=0)
  130. karma_p = models.PositiveIntegerField(default=0)
  131. karma_n = models.PositiveIntegerField(default=0)
  132. following = models.PositiveIntegerField(default=0)
  133. followers = models.PositiveIntegerField(default=0)
  134. score = models.IntegerField(default=0, db_index=True)
  135. rank = models.ForeignKey('ranks.Rank', null=True, blank=True, on_delete=models.SET_NULL)
  136. last_sync = models.DateTimeField(null=True, blank=True)
  137. follows = models.ManyToManyField('self', related_name='follows_set', symmetrical=False)
  138. ignores = models.ManyToManyField('self', related_name='ignores_set', symmetrical=False)
  139. title = models.CharField(max_length=255, null=True, blank=True)
  140. last_post = models.DateTimeField(null=True, blank=True)
  141. last_search = models.DateTimeField(null=True, blank=True)
  142. alerts = models.PositiveIntegerField(default=0)
  143. alerts_date = models.DateTimeField(null=True, blank=True)
  144. activation = models.IntegerField(default=0)
  145. token = models.CharField(max_length=12, null=True, blank=True)
  146. avatar_ban = models.BooleanField(default=False)
  147. avatar_ban_reason_user = models.TextField(null=True, blank=True)
  148. avatar_ban_reason_admin = models.TextField(null=True, blank=True)
  149. signature_ban = models.BooleanField(default=False)
  150. signature_ban_reason_user = models.TextField(null=True, blank=True)
  151. signature_ban_reason_admin = models.TextField(null=True, blank=True)
  152. timezone = models.CharField(max_length=255, default='utc')
  153. roles = models.ManyToManyField('roles.Role')
  154. is_team = models.BooleanField(default=False, db_index=True)
  155. acl_key = models.CharField(max_length=12, null=True, blank=True)
  156. objects = UserManager()
  157. ACTIVATION_NONE = 0
  158. ACTIVATION_USER = 1
  159. ACTIVATION_ADMIN = 2
  160. ACTIVATION_CREDENTIALS = 3
  161. statistics_name = _('Users Registrations')
  162. def is_god(self):
  163. try:
  164. return self.is_god_cache
  165. except AttributeError:
  166. for user in settings.ADMINS:
  167. if user[1].lower() == self.email:
  168. self.is_god_cache = True
  169. return True
  170. self.is_god_cache = False
  171. return False
  172. def is_anonymous(self):
  173. return False
  174. def is_authenticated(self):
  175. return True
  176. def is_crawler(self):
  177. return False
  178. def is_protected(self):
  179. for role in self.roles.all():
  180. if role.protected:
  181. return True
  182. return False
  183. def lock_avatar(self):
  184. # Kill existing avatar and lock our ability to change it
  185. self.delete_avatar()
  186. self.avatar_ban = True
  187. # Pick new one from _locked gallery
  188. galleries = path(settings.STATICFILES_DIRS[0]).joinpath('avatars').joinpath('_locked')
  189. avatars_list = galleries.files('*.gif')
  190. avatars_list += galleries.files('*.jpg')
  191. avatars_list += galleries.files('*.jpeg')
  192. avatars_list += galleries.files('*.png')
  193. self.avatar_type = 'gallery'
  194. self.avatar_image = '/'.join(path(choice(avatars_list)).splitall()[-2:])
  195. def default_avatar(self, db_settings):
  196. if db_settings['default_avatar'] == 'gallery':
  197. try:
  198. avatars_list = []
  199. try:
  200. # First try, _default path
  201. galleries = path(settings.STATICFILES_DIRS[0]).joinpath('avatars').joinpath('_default')
  202. avatars_list += galleries.files('*.gif')
  203. avatars_list += galleries.files('*.jpg')
  204. avatars_list += galleries.files('*.jpeg')
  205. avatars_list += galleries.files('*.png')
  206. except Exception as e:
  207. pass
  208. # Second try, all paths
  209. if not avatars_list:
  210. avatars_list = []
  211. for directory in path(settings.STATICFILES_DIRS[0]).joinpath('avatars').dirs():
  212. if not directory[-7:] == '_locked' and not directory[-7:] == '_thumbs':
  213. avatars_list += directory.files('*.gif')
  214. avatars_list += directory.files('*.jpg')
  215. avatars_list += directory.files('*.jpeg')
  216. avatars_list += directory.files('*.png')
  217. if avatars_list:
  218. # Pick random avatar from list
  219. self.avatar_type = 'gallery'
  220. self.avatar_image = '/'.join(path(choice(avatars_list)).splitall()[-2:])
  221. return True
  222. except Exception as e:
  223. pass
  224. self.avatar_type = 'gravatar'
  225. self.avatar_image = None
  226. return True
  227. def delete_avatar_temp(self):
  228. if self.avatar_temp:
  229. try:
  230. av_file = path(settings.MEDIA_ROOT + 'avatars/' + self.avatar_temp)
  231. if not av_file.isdir():
  232. av_file.remove()
  233. except Exception:
  234. pass
  235. self.avatar_temp = None
  236. def delete_avatar_original(self):
  237. if self.avatar_original:
  238. try:
  239. av_file = path(settings.MEDIA_ROOT + 'avatars/' + self.avatar_original)
  240. if not av_file.isdir():
  241. av_file.remove()
  242. except Exception:
  243. pass
  244. self.avatar_original = None
  245. def delete_avatar_image(self):
  246. if self.avatar_image:
  247. for size in settings.AVATAR_SIZES[1:]:
  248. try:
  249. av_file = path(settings.MEDIA_ROOT + 'avatars/' + str(size) + '_' + self.avatar_image)
  250. if not av_file.isdir():
  251. av_file.remove()
  252. except Exception:
  253. pass
  254. try:
  255. av_file = path(settings.MEDIA_ROOT + 'avatars/' + self.avatar_image)
  256. if not av_file.isdir():
  257. av_file.remove()
  258. except Exception:
  259. pass
  260. self.avatar_image = None
  261. def delete_avatar(self):
  262. self.delete_avatar_temp()
  263. self.delete_avatar_original()
  264. self.delete_avatar_image()
  265. def delete_content(self):
  266. delete_user_content.send(sender=self)
  267. def delete(self, *args, **kwargs):
  268. self.delete_avatar()
  269. super(User, self).delete(*args, **kwargs)
  270. def set_username(self, username):
  271. self.username = username.strip()
  272. self.username_slug = slugify(username)
  273. if self.pk:
  274. rename_user.send(sender=self)
  275. def is_username_valid(self, e):
  276. try:
  277. raise ValidationError(e.message_dict['username'])
  278. except KeyError:
  279. pass
  280. try:
  281. raise ValidationError(e.message_dict['username_slug'])
  282. except KeyError:
  283. pass
  284. def is_email_valid(self, e):
  285. try:
  286. raise ValidationError(e.message_dict['email'])
  287. except KeyError:
  288. pass
  289. try:
  290. raise ValidationError(e.message_dict['email_hash'])
  291. except KeyError:
  292. pass
  293. def is_password_valid(self, e):
  294. try:
  295. raise ValidationError(e.message_dict['password'])
  296. except KeyError:
  297. pass
  298. def set_email(self, email):
  299. self.email = email.strip().lower()
  300. self.email_hash = hashlib.md5(self.email).hexdigest()
  301. def set_password(self, raw_password):
  302. self.password_date = tz_util.now()
  303. self.password = make_password(raw_password.strip())
  304. def set_last_visit(self, ip, agent, hidden=False):
  305. self.last_date = tz_util.now()
  306. self.last_ip = ip
  307. self.last_agent = agent
  308. self.last_hide = hidden
  309. def check_password(self, raw_password, mobile=False):
  310. """
  311. Returns a boolean of whether the raw_password was correct. Handles
  312. hashing formats behind the scenes.
  313. """
  314. def setter(raw_password):
  315. self.set_password(raw_password)
  316. self.save()
  317. # Is standard password allright?
  318. if check_password(raw_password, self.password, setter):
  319. return True
  320. # Check mobile password?
  321. if mobile:
  322. raw_password = raw_password[:1].lower() + raw_password[1:]
  323. else:
  324. password_reversed = u''
  325. for c in raw_password:
  326. r = c.upper()
  327. if r == c:
  328. r = c.lower()
  329. password_reversed += r
  330. raw_password = password_reversed
  331. return check_password(raw_password, self.password, setter)
  332. def is_following(self, user):
  333. try:
  334. return self.follows.filter(id=user.pk).count() > 0
  335. except AttributeError:
  336. return self.follows.filter(id=user).count() > 0
  337. def is_ignoring(self, user):
  338. try:
  339. return self.ignores.filter(id=user.pk).count() > 0
  340. except AttributeError:
  341. return self.ignores.filter(id=user).count() > 0
  342. def get_roles(self):
  343. return self.roles.all()
  344. def make_acl_key(self, force=False):
  345. if not force and self.acl_key:
  346. return self.acl_key
  347. roles_ids = []
  348. for role in self.roles.all():
  349. roles_ids.append(str(role.pk))
  350. self.acl_key = 'acl_%s' % hashlib.md5('_'.join(roles_ids)).hexdigest()[0:8]
  351. return self.acl_key
  352. def get_acl(self, request):
  353. try:
  354. acl = cache.get(self.acl_key)
  355. if acl.version != request.monitor.acl_version:
  356. raise InvalidCacheBackendError()
  357. except AttributeError, InvalidCacheBackendError:
  358. # build acl cache
  359. acl = build_acl(request, self.get_roles())
  360. cache.set(self.acl_key, acl, 2592000)
  361. return acl
  362. def get_avatar(self, size=None):
  363. image_size = avatar_size(size) if size else None
  364. # Get uploaded avatar
  365. if self.avatar_type == 'upload':
  366. image_prefix = '%s_' % image_size if image_size else ''
  367. return settings.MEDIA_URL + 'avatars/' + image_prefix + self.avatar_image
  368. # Get gallery avatar
  369. if self.avatar_type == 'gallery':
  370. image_prefix = '_thumbs/%s/' % image_size if image_size else ''
  371. return settings.STATIC_URL + 'avatars/' + image_prefix + self.avatar_image
  372. # No avatar found, get gravatar
  373. if not image_size:
  374. image_size = settings.AVATAR_SIZES[0]
  375. return 'http://www.gravatar.com/avatar/%s?s=%s' % (hashlib.md5(self.email).hexdigest(), image_size)
  376. def get_title(self):
  377. if self.title:
  378. return self.title
  379. if self.rank:
  380. return self.rank.title
  381. return None
  382. def get_style(self):
  383. if self.rank:
  384. return self.rank.style
  385. return ''
  386. def email_user(self, request, template, subject, context={}):
  387. templates = request.theme.get_email_templates(template)
  388. context = RequestContext(request, context)
  389. context['author'] = context['user']
  390. context['user'] = self
  391. # Set message recipient
  392. if settings.DEBUG and settings.CATCH_ALL_EMAIL_ADDRESS:
  393. recipient = settings.CATCH_ALL_EMAIL_ADDRESS
  394. else:
  395. recipient = self.email
  396. # Build and send message
  397. email = EmailMultiAlternatives(subject, templates[0].render(context), settings.EMAIL_HOST_USER, [recipient])
  398. email.attach_alternative(templates[1].render(context), "text/html")
  399. email.send()
  400. def get_activation(self):
  401. activations = ['none', 'user', 'admin', 'credentials']
  402. return activations[self.activation]
  403. def alert(self, message):
  404. from misago.alerts.models import Alert
  405. self.alerts += 1
  406. return Alert(user=self, message=message, date=tz_util.now())
  407. def get_date(self):
  408. return self.join_date
  409. def sync_user(self):
  410. pass
  411. class Guest(object):
  412. """
  413. Misago Guest dummy
  414. """
  415. id = -1
  416. pk = -1
  417. is_team = False
  418. def is_anonymous(self):
  419. return True
  420. def is_authenticated(self):
  421. return False
  422. def is_crawler(self):
  423. return False
  424. def get_roles(self):
  425. return Role.objects.filter(token='guest')
  426. def make_acl_key(self):
  427. return 'acl_guest'
  428. class Crawler(Guest):
  429. """
  430. Misago Crawler dummy
  431. """
  432. is_team = False
  433. def __init__(self, username):
  434. self.username = username
  435. def is_anonymous(self):
  436. return True
  437. def is_authenticated(self):
  438. return False
  439. def is_crawler(self):
  440. return True