forms.py 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422
  1. # -*- coding: utf-8 -*-
  2. """
  3. flaskbb.management.forms
  4. ~~~~~~~~~~~~~~~~~~~~~~~~
  5. It provides the forms that are needed for the management views.
  6. :copyright: (c) 2014 by the FlaskBB Team.
  7. :license: BSD, see LICENSE for more details.
  8. """
  9. from flask_wtf import FlaskForm
  10. from wtforms import (BooleanField, HiddenField, IntegerField, PasswordField,
  11. SelectField, StringField, SubmitField, TextAreaField)
  12. from wtforms.validators import (DataRequired, Optional, Email, regexp, Length,
  13. URL, ValidationError)
  14. from wtforms.ext.sqlalchemy.fields import (QuerySelectField,
  15. QuerySelectMultipleField)
  16. from sqlalchemy.orm.session import make_transient, make_transient_to_detached
  17. from flask_babelplus import lazy_gettext as _
  18. from flaskbb.utils.fields import BirthdayField
  19. from flaskbb.utils.widgets import SelectBirthdayWidget
  20. from flaskbb.extensions import db
  21. from flaskbb.forum.models import Forum, Category
  22. from flaskbb.user.models import User, Group
  23. from flaskbb.utils.requirements import IsAtleastModerator
  24. from flask_allows import Permission
  25. USERNAME_RE = r'^[\w.+-]+$'
  26. is_username = regexp(USERNAME_RE,
  27. message=_("You can only use letters, numbers or dashes."))
  28. def selectable_forums():
  29. return Forum.query.order_by(Forum.position)
  30. def selectable_categories():
  31. return Category.query.order_by(Category.position)
  32. def selectable_groups():
  33. return Group.query.order_by(Group.id.asc()).all()
  34. def select_primary_group():
  35. return Group.query.filter(Group.guest != True).order_by(Group.id)
  36. class UserForm(FlaskForm):
  37. username = StringField(_("Username"), validators=[
  38. DataRequired(message=_("A valid username is required.")),
  39. is_username])
  40. email = StringField(_("Email address"), validators=[
  41. DataRequired(message=_("A valid email address is required.")),
  42. Email(message=_("Invalid email address."))])
  43. password = PasswordField("Password", validators=[
  44. Optional()])
  45. birthday = BirthdayField(_("Birthday"), format="%d %m %Y",
  46. widget=SelectBirthdayWidget(),
  47. validators=[Optional()])
  48. gender = SelectField(_("Gender"), default="None", choices=[
  49. ("None", ""),
  50. ("Male", _("Male")),
  51. ("Female", _("Female"))])
  52. location = StringField(_("Location"), validators=[
  53. Optional()])
  54. website = StringField(_("Website"), validators=[
  55. Optional(), URL()])
  56. avatar = StringField(_("Avatar"), validators=[
  57. Optional(), URL()])
  58. signature = TextAreaField(_("Forum signature"), validators=[
  59. Optional(), Length(min=0, max=250)])
  60. notes = TextAreaField(_("Notes"), validators=[
  61. Optional(), Length(min=0, max=5000)])
  62. activated = BooleanField(_("Is active?"), validators=[
  63. Optional()])
  64. primary_group = QuerySelectField(
  65. _("Primary group"),
  66. query_factory=select_primary_group,
  67. get_label="name")
  68. secondary_groups = QuerySelectMultipleField(
  69. _("Secondary groups"),
  70. # TODO: Template rendering errors "NoneType is not callable"
  71. # without this, figure out why.
  72. query_factory=select_primary_group,
  73. get_label="name")
  74. submit = SubmitField(_("Save"))
  75. def validate_username(self, field):
  76. if hasattr(self, "user"):
  77. user = User.query.filter(
  78. db.and_(
  79. User.username.like(field.data),
  80. db.not_(User.id == self.user.id)
  81. )
  82. ).first()
  83. else:
  84. user = User.query.filter(User.username.like(field.data)).first()
  85. if user:
  86. raise ValidationError(_("This username is already taken."))
  87. def validate_email(self, field):
  88. if hasattr(self, "user"):
  89. user = User.query.filter(
  90. db.and_(
  91. User.email.like(field.data),
  92. db.not_(User.id == self.user.id)
  93. )
  94. ).first()
  95. else:
  96. user = User.query.filter(User.email.like(field.data)).first()
  97. if user:
  98. raise ValidationError(_("This email address is already taken."))
  99. def save(self):
  100. data = self.data
  101. data.pop('submit', None)
  102. user = User(**data)
  103. return user.save()
  104. class AddUserForm(UserForm):
  105. pass
  106. class EditUserForm(UserForm):
  107. def __init__(self, user, *args, **kwargs):
  108. self.user = user
  109. kwargs['obj'] = self.user
  110. UserForm.__init__(self, *args, **kwargs)
  111. class GroupForm(FlaskForm):
  112. name = StringField(_("Group name"), validators=[
  113. DataRequired(message=_("Please enter a name for the group."))])
  114. description = TextAreaField(_("Description"), validators=[
  115. Optional()])
  116. admin = BooleanField(
  117. _("Is 'Admin' group?"),
  118. description=_("With this option the group has access to "
  119. "the admin panel.")
  120. )
  121. super_mod = BooleanField(
  122. _("Is 'Super Moderator' group?"),
  123. description=_("Check this, if the users in this group are allowed to "
  124. "moderate every forum.")
  125. )
  126. mod = BooleanField(
  127. _("Is 'Moderator' group?"),
  128. description=_("Check this, if the users in this group are allowed to "
  129. "moderate specified forums.")
  130. )
  131. banned = BooleanField(
  132. _("Is 'Banned' group?"),
  133. description=_("Only one group of type 'Banned' is allowed.")
  134. )
  135. guest = BooleanField(
  136. _("Is 'Guest' group?"),
  137. description=_("Only one group of type 'Guest' is allowed.")
  138. )
  139. editpost = BooleanField(
  140. _("Can edit posts"),
  141. description=_("Check this, if the users in this group can edit posts.")
  142. )
  143. deletepost = BooleanField(
  144. _("Can delete posts"),
  145. description=_("Check this, if the users in this group can delete "
  146. "posts.")
  147. )
  148. deletetopic = BooleanField(
  149. _("Can delete topics"),
  150. description=_("Check this, if the users in this group can delete "
  151. "topics.")
  152. )
  153. posttopic = BooleanField(
  154. _("Can create topics"),
  155. description=_("Check this, if the users in this group can create "
  156. "topics.")
  157. )
  158. postreply = BooleanField(
  159. _("Can post replies"),
  160. description=_("Check this, if the users in this group can post "
  161. "replies.")
  162. )
  163. mod_edituser = BooleanField(
  164. _("Moderators can edit user profiles"),
  165. description=_("Allow moderators to edit another user's profile "
  166. "including password and email changes.")
  167. )
  168. mod_banuser = BooleanField(
  169. _("Moderators can ban users"),
  170. description=_("Allow moderators to ban other users.")
  171. )
  172. submit = SubmitField(_("Save"))
  173. def validate_name(self, field):
  174. if hasattr(self, "group"):
  175. group = Group.query.filter(
  176. db.and_(
  177. Group.name.like(field.data),
  178. db.not_(Group.id == self.group.id)
  179. )
  180. ).first()
  181. else:
  182. group = Group.query.filter(Group.name.like(field.data)).first()
  183. if group:
  184. raise ValidationError(_("This group name is already taken."))
  185. def validate_banned(self, field):
  186. if hasattr(self, "group"):
  187. group = Group.query.filter(
  188. db.and_(
  189. Group.banned,
  190. db.not_(Group.id == self.group.id)
  191. )
  192. ).count()
  193. else:
  194. group = Group.query.filter_by(banned=True).count()
  195. if field.data and group > 0:
  196. raise ValidationError(_("There is already a group of type "
  197. "'Banned'."))
  198. def validate_guest(self, field):
  199. if hasattr(self, "group"):
  200. group = Group.query.filter(
  201. db.and_(
  202. Group.guest,
  203. db.not_(Group.id == self.group.id)
  204. )
  205. ).count()
  206. else:
  207. group = Group.query.filter_by(guest=True).count()
  208. if field.data and group > 0:
  209. raise ValidationError(_("There is already a group of type "
  210. "'Guest'."))
  211. def save(self):
  212. data = self.data
  213. data.pop('submit', None)
  214. group = Group(**data)
  215. return group.save()
  216. class EditGroupForm(GroupForm):
  217. def __init__(self, group, *args, **kwargs):
  218. self.group = group
  219. kwargs['obj'] = self.group
  220. GroupForm.__init__(self, *args, **kwargs)
  221. class AddGroupForm(GroupForm):
  222. pass
  223. class ForumForm(FlaskForm):
  224. title = StringField(
  225. _("Forum title"),
  226. validators=[DataRequired(message=_("Please enter a forum title."))]
  227. )
  228. description = TextAreaField(
  229. _("Description"),
  230. validators=[Optional()],
  231. description=_("You can format your description with Markdown.")
  232. )
  233. position = IntegerField(
  234. _("Position"),
  235. default=1,
  236. validators=[DataRequired(message=_("Please enter a position for the"
  237. "forum."))]
  238. )
  239. category = QuerySelectField(
  240. _("Category"),
  241. query_factory=selectable_categories,
  242. allow_blank=False,
  243. get_label="title",
  244. description=_("The category that contains this forum.")
  245. )
  246. external = StringField(
  247. _("External link"),
  248. validators=[Optional(), URL()],
  249. description=_("A link to a website i.e. 'http://flaskbb.org'.")
  250. )
  251. moderators = StringField(
  252. _("Moderators"),
  253. description=_("Comma separated usernames. Leave it blank if you do "
  254. "not want to set any moderators.")
  255. )
  256. show_moderators = BooleanField(
  257. _("Show moderators"),
  258. description=_("Do you want to show the moderators on the index page?")
  259. )
  260. locked = BooleanField(
  261. _("Locked?"),
  262. description=_("Disable new posts and topics in this forum.")
  263. )
  264. groups = QuerySelectMultipleField(
  265. _("Group access"),
  266. query_factory=selectable_groups,
  267. get_label="name",
  268. description=_("Select the groups that can access this forum.")
  269. )
  270. submit = SubmitField(_("Save"))
  271. def validate_external(self, field):
  272. if hasattr(self, "forum"):
  273. if self.forum.topics.count() > 0:
  274. raise ValidationError(_("You cannot convert a forum that "
  275. "contains topics into an "
  276. "external link."))
  277. def validate_show_moderators(self, field):
  278. if field.data and not self.moderators.data:
  279. raise ValidationError(_("You also need to specify some "
  280. "moderators."))
  281. def validate_moderators(self, field):
  282. approved_moderators = []
  283. if field.data:
  284. moderators = [mod.strip() for mod in field.data.split(',')]
  285. users = User.query.filter(User.username.in_(moderators))
  286. for user in users:
  287. if not Permission(IsAtleastModerator, identity=user):
  288. raise ValidationError(
  289. _("%(user)s is not in a moderators group.",
  290. user=user.username)
  291. )
  292. else:
  293. approved_moderators.append(user)
  294. field.data = approved_moderators
  295. def save(self):
  296. data = self.data
  297. # remove the button
  298. data.pop('submit', None)
  299. forum = Forum(**data)
  300. return forum.save()
  301. class EditForumForm(ForumForm):
  302. id = HiddenField()
  303. def __init__(self, forum, *args, **kwargs):
  304. self.forum = forum
  305. kwargs['obj'] = self.forum
  306. ForumForm.__init__(self, *args, **kwargs)
  307. def save(self):
  308. data = self.data
  309. # remove the button
  310. data.pop('submit', None)
  311. forum = Forum(**data)
  312. # flush SQLA info from created instance so that it can be merged
  313. make_transient(forum)
  314. make_transient_to_detached(forum)
  315. return forum.save()
  316. class AddForumForm(ForumForm):
  317. pass
  318. class CategoryForm(FlaskForm):
  319. title = StringField(_("Category title"), validators=[
  320. DataRequired(message=_("Please enter a category title."))])
  321. description = TextAreaField(
  322. _("Description"),
  323. validators=[Optional()],
  324. description=_("You can format your description with Markdown.")
  325. )
  326. position = IntegerField(
  327. _("Position"),
  328. default=1,
  329. validators=[DataRequired(message=_("Please enter a position for the "
  330. "category."))]
  331. )
  332. submit = SubmitField(_("Save"))
  333. def save(self):
  334. data = self.data
  335. data.pop('submit', None)
  336. category = Category(**data)
  337. return category.save()