users.py 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432
  1. from django.contrib import messages
  2. from django.contrib.auth import get_user_model, update_session_auth_hash
  3. from django.db import transaction
  4. from django.http import JsonResponse
  5. from django.shortcuts import redirect
  6. from django.utils.translation import gettext_lazy as _
  7. from misago.acl.useracl import get_user_acl
  8. from misago.admin.auth import start_admin_session
  9. from misago.admin.views import generic
  10. from misago.categories.models import Category
  11. from misago.core.mail import mail_users
  12. from misago.core.pgutils import chunk_queryset
  13. from misago.threads.models import Thread
  14. from misago.users.avatars.dynamic import set_avatar as set_dynamic_avatar
  15. from misago.users.datadownloads import (
  16. request_user_data_download,
  17. user_has_data_download_request,
  18. )
  19. from misago.users.forms.admin import (
  20. BanUsersForm,
  21. EditUserForm,
  22. EditUserFormFactory,
  23. NewUserForm,
  24. create_search_users_form,
  25. )
  26. from misago.users.models import Ban
  27. from misago.users.profilefields import profilefields
  28. from misago.users.setupnewuser import setup_new_user
  29. from misago.users.signatures import set_user_signature
  30. User = get_user_model()
  31. class UserAdmin(generic.AdminBaseMixin):
  32. root_link = "misago:admin:users:accounts:index"
  33. templates_dir = "misago/admin/users"
  34. model = User
  35. def create_form_type(self, request, target):
  36. add_is_active_fields = False
  37. add_admin_fields = False
  38. if not target.is_deleting_account:
  39. if not target.is_staff:
  40. add_is_active_fields = True
  41. elif request.user.is_superuser:
  42. add_is_active_fields = request.user.pk != target.pk
  43. if request.user.is_superuser:
  44. add_admin_fields = request.user.pk != target.pk
  45. return EditUserFormFactory(
  46. self.form,
  47. target,
  48. add_is_active_fields=add_is_active_fields,
  49. add_admin_fields=add_admin_fields,
  50. )
  51. class UsersList(UserAdmin, generic.ListView):
  52. items_per_page = 24
  53. ordering = [
  54. ("-id", _("From newest")),
  55. ("id", _("From oldest")),
  56. ("slug", _("A to z")),
  57. ("-slug", _("Z to a")),
  58. ("posts", _("Biggest posters")),
  59. ("-posts", _("Smallest posters")),
  60. ]
  61. selection_label = _("With users: 0")
  62. empty_selection_label = _("Select users")
  63. mass_actions = [
  64. {
  65. "action": "activate",
  66. "name": _("Activate accounts"),
  67. "icon": "fa fa-check-square-o",
  68. },
  69. {"action": "ban", "name": _("Ban users"), "icon": "fa fa-lock"},
  70. {
  71. "action": "request_data_download",
  72. "name": _("Request data download"),
  73. "icon": "fa fa-download",
  74. },
  75. {
  76. "action": "delete_accounts",
  77. "name": _("Delete accounts"),
  78. "icon": "fa fa-times-circle",
  79. "confirmation": _("Are you sure you want to delete selected users?"),
  80. },
  81. {
  82. "action": "delete_all",
  83. "name": _("Delete all"),
  84. "icon": "fa fa-eraser",
  85. "confirmation": _(
  86. "Are you sure you want to delete selected users? "
  87. "This will also delete all content associated with their accounts."
  88. ),
  89. "is_atomic": False,
  90. },
  91. ]
  92. def get_queryset(self):
  93. qs = super().get_queryset()
  94. return qs.select_related("rank")
  95. def get_search_form(self, request):
  96. return create_search_users_form()
  97. def action_activate(self, request, users):
  98. inactive_users = []
  99. for user in users:
  100. if user.requires_activation:
  101. inactive_users.append(user)
  102. if not inactive_users:
  103. message = _("You have to select inactive users.")
  104. raise generic.MassActionError(message)
  105. else:
  106. activated_users_pks = [u.pk for u in inactive_users]
  107. queryset = User.objects.filter(pk__in=activated_users_pks)
  108. queryset.update(requires_activation=User.ACTIVATION_NONE)
  109. subject = _("Your account on %(forum_name)s forums has been activated")
  110. mail_subject = subject % {"forum_name": request.settings.forum_name}
  111. mail_users(
  112. inactive_users,
  113. mail_subject,
  114. "misago/emails/activation/by_admin",
  115. context={"settings": request.settings},
  116. )
  117. messages.success(request, _("Selected users accounts have been activated."))
  118. def action_ban(self, request, users):
  119. users = users.order_by("slug")
  120. for user in users:
  121. if user.is_superuser:
  122. message = _("%(user)s is super admin and can't be banned.")
  123. mesage = message % {"user": user.username}
  124. raise generic.MassActionError(mesage)
  125. form = BanUsersForm(users=users)
  126. if "finalize" in request.POST:
  127. form = BanUsersForm(request.POST, users=users)
  128. if form.is_valid():
  129. cleaned_data = form.cleaned_data
  130. banned_values = []
  131. ban_kwargs = {
  132. "user_message": cleaned_data.get("user_message"),
  133. "staff_message": cleaned_data.get("staff_message"),
  134. "expires_on": cleaned_data.get("expires_on"),
  135. }
  136. for user in users:
  137. for ban in cleaned_data["ban_type"]:
  138. banned_value = None
  139. if ban == "usernames":
  140. check_type = Ban.USERNAME
  141. banned_value = user.username.lower()
  142. if ban == "emails":
  143. check_type = Ban.EMAIL
  144. banned_value = user.email.lower()
  145. if ban == "domains":
  146. check_type = Ban.EMAIL
  147. banned_value = user.email.lower()
  148. at_pos = banned_value.find("@")
  149. banned_value = "*%s" % banned_value[at_pos:]
  150. if ban == "ip" and user.joined_from_ip:
  151. check_type = Ban.IP
  152. banned_value = user.joined_from_ip
  153. if ban in ("ip_first", "ip_two") and user.joined_from_ip:
  154. check_type = Ban.IP
  155. if ":" in user.joined_from_ip:
  156. ip_separator = ":"
  157. if "." in user.joined_from_ip:
  158. ip_separator = "."
  159. bits = user.joined_from_ip.split(ip_separator)
  160. if ban == "ip_first":
  161. formats = (bits[0], ip_separator)
  162. if ban == "ip_two":
  163. formats = (bits[0], ip_separator, bits[1], ip_separator)
  164. banned_value = "%s*" % ("".join(formats))
  165. if banned_value and banned_value not in banned_values:
  166. ban_kwargs.update(
  167. {"check_type": check_type, "banned_value": banned_value}
  168. )
  169. Ban.objects.create(**ban_kwargs)
  170. banned_values.append(banned_value)
  171. Ban.objects.invalidate_cache()
  172. messages.success(request, _("Selected users have been banned."))
  173. return None
  174. return self.render(
  175. request,
  176. template="misago/admin/users/ban.html",
  177. context={"users": users, "form": form},
  178. )
  179. def action_request_data_download(self, request, users):
  180. for user in users:
  181. if not user_has_data_download_request(user):
  182. request_user_data_download(user, requester=request.user)
  183. messages.success(
  184. request, _("Data download requests have been placed for selected users.")
  185. )
  186. def action_delete_accounts(self, request, users):
  187. for user in users:
  188. if user == request.user:
  189. raise generic.MassActionError(_("You can't delete yourself."))
  190. if user.is_staff or user.is_superuser:
  191. message = _("%(user)s is admin and can't be deleted.") % {
  192. "user": user.username
  193. }
  194. raise generic.MassActionError(message)
  195. for user in users:
  196. user.delete()
  197. messages.success(request, _("Selected users have been deleted."))
  198. def action_delete_all(self, request, users):
  199. for user in users:
  200. if user == request.user:
  201. raise generic.MassActionError(_("You can't delete yourself."))
  202. if user.is_staff or user.is_superuser:
  203. message = _("%(user)s is admin and can't be deleted.") % {
  204. "user": user.username
  205. }
  206. raise generic.MassActionError(message)
  207. return self.render(
  208. request, template="misago/admin/users/delete.html", context={"users": users}
  209. )
  210. class NewUser(UserAdmin, generic.ModelFormView):
  211. form = NewUserForm
  212. template = "new.html"
  213. message_submit = _('New user "%(user)s" has been registered.')
  214. def initialize_form(self, form, request, target):
  215. if request.method == "POST":
  216. return form(request.POST, request.FILES, instance=target, request=request)
  217. else:
  218. return form(instance=target, request=request)
  219. def handle_form(self, form, request, target):
  220. new_user = User.objects.create_user(
  221. form.cleaned_data["username"],
  222. form.cleaned_data["email"],
  223. form.cleaned_data["new_password"],
  224. title=form.cleaned_data["title"],
  225. rank=form.cleaned_data.get("rank"),
  226. joined_from_ip=request.user_ip,
  227. )
  228. if form.cleaned_data.get("staff_level"):
  229. new_user.staff_level = form.cleaned_data["staff_level"]
  230. if form.cleaned_data.get("roles"):
  231. new_user.roles.add(*form.cleaned_data["roles"])
  232. new_user.update_acl_key()
  233. setup_new_user(request.settings, new_user)
  234. messages.success(request, self.message_submit % {"user": target.username})
  235. return redirect("misago:admin:users:accounts:edit", pk=new_user.pk)
  236. class EditUser(UserAdmin, generic.ModelFormView):
  237. form = EditUserForm
  238. template = "edit.html"
  239. message_submit = _('User "%(user)s" has been edited.')
  240. def real_dispatch(self, request, target):
  241. target.old_username = target.username
  242. target.old_is_avatar_locked = target.is_avatar_locked
  243. return super().real_dispatch(request, target)
  244. def initialize_form(self, form, request, target):
  245. if request.method == "POST":
  246. return form(request.POST, request.FILES, instance=target, request=request)
  247. else:
  248. return form(instance=target, request=request)
  249. def handle_form(self, form, request, target):
  250. target.username = target.old_username
  251. if target.username != form.cleaned_data.get("username"):
  252. target.set_username(
  253. form.cleaned_data.get("username"), changed_by=request.user
  254. )
  255. if form.cleaned_data.get("new_password"):
  256. target.set_password(form.cleaned_data["new_password"])
  257. if target.pk == request.user.pk:
  258. start_admin_session(request, target)
  259. update_session_auth_hash(request, target)
  260. if form.cleaned_data.get("email"):
  261. target.set_email(form.cleaned_data["email"])
  262. if target.pk == request.user.pk:
  263. start_admin_session(request, target)
  264. if form.cleaned_data.get("is_avatar_locked"):
  265. if not target.old_is_avatar_locked:
  266. set_dynamic_avatar(target)
  267. if "is_staff" in form.fields and "is_superuser" in form.fields:
  268. target.is_staff = form.cleaned_data.get("is_staff")
  269. target.is_superuser = form.cleaned_data.get("is_superuser")
  270. if "is_active" in form.fields and "is_active_staff_message" in form.fields:
  271. target.is_active = form.cleaned_data.get("is_active")
  272. target.is_active_staff_message = form.cleaned_data.get(
  273. "is_active_staff_message"
  274. )
  275. target.rank = form.cleaned_data.get("rank")
  276. target.roles.clear()
  277. target.roles.add(*form.cleaned_data["roles"])
  278. target_acl = get_user_acl(target, request.cache_versions)
  279. set_user_signature(
  280. request, target, target_acl, form.cleaned_data.get("signature")
  281. )
  282. profilefields.update_user_profile_fields(request, target, form)
  283. target.update_acl_key()
  284. target.save()
  285. messages.success(request, self.message_submit % {"user": target.username})
  286. class DeletionStep(UserAdmin, generic.ButtonView):
  287. is_atomic = False
  288. def check_permissions(self, request, target):
  289. if not request.is_ajax():
  290. return _("This action can't be accessed directly.")
  291. if target == request.user:
  292. return _("You can't delete yourself.")
  293. if target.is_staff or target.is_superuser:
  294. return _("%(user)s is admin and can't be deleted.") % {
  295. "user": target.username
  296. }
  297. def execute_step(self, user):
  298. raise NotImplementedError(
  299. "execute_step method should return dict with "
  300. "number of deleted_count and is_completed keys"
  301. )
  302. def button_action(self, request, target):
  303. return JsonResponse(self.execute_step(target))
  304. class DeleteThreadsStep(DeletionStep):
  305. def execute_step(self, user):
  306. recount_categories = set()
  307. deleted_threads = 0
  308. is_completed = False
  309. for thread in user.thread_set.order_by("-id")[:50]:
  310. recount_categories.add(thread.category_id)
  311. with transaction.atomic():
  312. thread.delete()
  313. deleted_threads += 1
  314. if recount_categories:
  315. for category in Category.objects.filter(id__in=recount_categories):
  316. category.synchronize()
  317. category.save()
  318. else:
  319. is_completed = True
  320. return {"deleted_count": deleted_threads, "is_completed": is_completed}
  321. class DeletePostsStep(DeletionStep):
  322. def execute_step(self, user):
  323. recount_categories = set()
  324. recount_threads = set()
  325. deleted_posts = 0
  326. is_completed = False
  327. for post in user.post_set.order_by("-id")[:50]:
  328. recount_categories.add(post.category_id)
  329. recount_threads.add(post.thread_id)
  330. with transaction.atomic():
  331. post.delete()
  332. deleted_posts += 1
  333. if recount_categories:
  334. changed_threads_qs = Thread.objects.filter(id__in=recount_threads)
  335. for thread in chunk_queryset(changed_threads_qs, 50):
  336. thread.synchronize()
  337. thread.save()
  338. for category in Category.objects.filter(id__in=recount_categories):
  339. category.synchronize()
  340. category.save()
  341. else:
  342. is_completed = True
  343. return {"deleted_count": deleted_posts, "is_completed": is_completed}
  344. class DeleteAccountStep(DeletionStep):
  345. def execute_step(self, user):
  346. user.delete(delete_content=True)
  347. return {"is_completed": True}