forms.py 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468
  1. # -*- coding: utf-8 -*-
  2. """
  3. flaskbb.management.forms
  4. ~~~~~~~~~~~~~~~~~~~~~~~~
  5. It provides the forms that are needed for the management views.
  6. :copyright: (c) 2014 by the FlaskBB Team.
  7. :license: BSD, see LICENSE for more details.
  8. """
  9. from flask_wtf import FlaskForm
  10. from wtforms import (BooleanField, HiddenField, IntegerField, PasswordField,
  11. SelectField, StringField, SubmitField, TextAreaField)
  12. from wtforms.validators import (DataRequired, Optional, Email, regexp, Length,
  13. URL, ValidationError)
  14. from wtforms.ext.sqlalchemy.fields import (QuerySelectField,
  15. QuerySelectMultipleField)
  16. from sqlalchemy.orm.session import make_transient, make_transient_to_detached
  17. from flask_babelplus import lazy_gettext as _
  18. from flaskbb.utils.fields import BirthdayField
  19. from flaskbb.extensions import db
  20. from flaskbb.forum.models import Forum, Category
  21. from flaskbb.user.models import User, Group
  22. from flaskbb.utils.requirements import IsAtleastModerator
  23. from flask_allows import Permission
  24. USERNAME_RE = r'^[\w.+-]+$'
  25. is_username = regexp(USERNAME_RE,
  26. message=_("You can only use letters, numbers or dashes."))
  27. def selectable_forums():
  28. return Forum.query.order_by(Forum.position)
  29. def selectable_categories():
  30. return Category.query.order_by(Category.position)
  31. def selectable_groups():
  32. return Group.query.order_by(Group.id.asc()).all()
  33. def select_primary_group():
  34. return Group.query.filter(Group.guest != True).order_by(Group.id)
  35. class UserForm(FlaskForm):
  36. username = StringField(_("Username"), validators=[
  37. DataRequired(message=_("A valid username is required.")),
  38. is_username])
  39. email = StringField(_("Email address"), validators=[
  40. DataRequired(message=_("A valid email address is required.")),
  41. Email(message=_("Invalid email address."))])
  42. password = PasswordField("Password", validators=[
  43. DataRequired()])
  44. birthday = BirthdayField(_("Birthday"), format="%d %m %Y", validators=[
  45. Optional()])
  46. gender = SelectField(_("Gender"), default="None", choices=[
  47. ("None", ""),
  48. ("Male", _("Male")),
  49. ("Female", _("Female"))])
  50. location = StringField(_("Location"), validators=[
  51. Optional()])
  52. website = StringField(_("Website"), validators=[
  53. Optional(), URL()])
  54. avatar = StringField(_("Avatar"), validators=[
  55. Optional(), URL()])
  56. signature = TextAreaField(_("Forum signature"), validators=[
  57. Optional(), Length(min=0, max=250)])
  58. notes = TextAreaField(_("Notes"), validators=[
  59. Optional(), Length(min=0, max=5000)])
  60. activated = BooleanField(_("Is active?"), validators=[
  61. Optional()])
  62. primary_group = QuerySelectField(
  63. _("Primary group"),
  64. query_factory=select_primary_group,
  65. get_label="name")
  66. secondary_groups = QuerySelectMultipleField(
  67. _("Secondary groups"),
  68. # TODO: Template rendering errors "NoneType is not callable"
  69. # without this, figure out why.
  70. query_factory=select_primary_group,
  71. get_label="name")
  72. submit = SubmitField(_("Save"))
  73. def validate_username(self, field):
  74. if hasattr(self, "user"):
  75. user = User.query.filter(
  76. db.and_(
  77. User.username.like(field.data.lower()),
  78. db.not_(User.id == self.user.id)
  79. )
  80. ).first()
  81. else:
  82. user = User.query.filter(
  83. User.username.like(field.data.lower())
  84. ).first()
  85. if user:
  86. raise ValidationError(_("This username is already taken."))
  87. def validate_email(self, field):
  88. if hasattr(self, "user"):
  89. user = User.query.filter(
  90. db.and_(
  91. User.email.like(field.data.lower()),
  92. db.not_(User.id == self.user.id)
  93. )
  94. ).first()
  95. else:
  96. user = User.query.filter(
  97. User.email.like(field.data.lower())
  98. ).first()
  99. if user:
  100. raise ValidationError(_("This email address is already taken."))
  101. def save(self):
  102. data = self.data
  103. data.pop('submit', None)
  104. data.pop('csrf_token', None)
  105. user = User(**data)
  106. return user.save()
  107. class AddUserForm(UserForm):
  108. pass
  109. class EditUserForm(UserForm):
  110. password = PasswordField("Password", validators=[Optional()])
  111. def __init__(self, user, *args, **kwargs):
  112. self.user = user
  113. kwargs['obj'] = self.user
  114. UserForm.__init__(self, *args, **kwargs)
  115. class GroupForm(FlaskForm):
  116. name = StringField(_("Group name"), validators=[
  117. DataRequired(message=_("Please enter a name for the group."))])
  118. description = TextAreaField(_("Description"), validators=[
  119. Optional()])
  120. admin = BooleanField(
  121. _("Is 'Admin' group?"),
  122. description=_("With this option the group has access to "
  123. "the admin panel.")
  124. )
  125. super_mod = BooleanField(
  126. _("Is 'Super Moderator' group?"),
  127. description=_("Check this, if the users in this group are allowed to "
  128. "moderate every forum.")
  129. )
  130. mod = BooleanField(
  131. _("Is 'Moderator' group?"),
  132. description=_("Check this, if the users in this group are allowed to "
  133. "moderate specified forums.")
  134. )
  135. banned = BooleanField(
  136. _("Is 'Banned' group?"),
  137. description=_("Only one group of type 'Banned' is allowed.")
  138. )
  139. guest = BooleanField(
  140. _("Is 'Guest' group?"),
  141. description=_("Only one group of type 'Guest' is allowed.")
  142. )
  143. editpost = BooleanField(
  144. _("Can edit posts"),
  145. description=_("Check this, if the users in this group can edit posts.")
  146. )
  147. deletepost = BooleanField(
  148. _("Can delete posts"),
  149. description=_("Check this, if the users in this group can delete "
  150. "posts.")
  151. )
  152. deletetopic = BooleanField(
  153. _("Can delete topics"),
  154. description=_("Check this, if the users in this group can delete "
  155. "topics.")
  156. )
  157. posttopic = BooleanField(
  158. _("Can create topics"),
  159. description=_("Check this, if the users in this group can create "
  160. "topics.")
  161. )
  162. postreply = BooleanField(
  163. _("Can post replies"),
  164. description=_("Check this, if the users in this group can post "
  165. "replies.")
  166. )
  167. mod_edituser = BooleanField(
  168. _("Moderators can edit user profiles"),
  169. description=_("Allow moderators to edit another user's profile "
  170. "including password and email changes.")
  171. )
  172. mod_banuser = BooleanField(
  173. _("Moderators can ban users"),
  174. description=_("Allow moderators to ban other users.")
  175. )
  176. viewhidden = BooleanField(
  177. _("Can view hidden posts and topics"),
  178. description=_("Allows a user to view hidden posts and topics"),
  179. )
  180. makehidden = BooleanField(
  181. _("Can hide posts and topics"),
  182. description=_("Allows a user to hide posts and topics"),
  183. )
  184. submit = SubmitField(_("Save"))
  185. def validate_name(self, field):
  186. if hasattr(self, "group"):
  187. group = Group.query.filter(
  188. db.and_(
  189. Group.name.like(field.data.lower()),
  190. db.not_(Group.id == self.group.id)
  191. )
  192. ).first()
  193. else:
  194. group = Group.query.filter(
  195. Group.name.like(field.data.lower())
  196. ).first()
  197. if group:
  198. raise ValidationError(_("This group name is already taken."))
  199. def validate_banned(self, field):
  200. if hasattr(self, "group"):
  201. group = Group.query.filter(
  202. db.and_(
  203. Group.banned,
  204. db.not_(Group.id == self.group.id)
  205. )
  206. ).count()
  207. else:
  208. group = Group.query.filter_by(banned=True).count()
  209. if field.data and group > 0:
  210. raise ValidationError(_("There is already a group of type "
  211. "'Banned'."))
  212. def validate_guest(self, field):
  213. if hasattr(self, "group"):
  214. group = Group.query.filter(
  215. db.and_(
  216. Group.guest,
  217. db.not_(Group.id == self.group.id)
  218. )
  219. ).count()
  220. else:
  221. group = Group.query.filter_by(guest=True).count()
  222. if field.data and group > 0:
  223. raise ValidationError(_("There is already a group of type "
  224. "'Guest'."))
  225. def validate(self):
  226. if not super(GroupForm, self).validate():
  227. return False
  228. result = True
  229. permission_fields = (
  230. self.editpost, self.deletepost, self.deletetopic,
  231. self.posttopic, self.postreply, self.mod_edituser,
  232. self.mod_banuser, self.viewhidden, self.makehidden
  233. )
  234. group_fields = [
  235. self.admin, self.super_mod, self.mod, self.banned, self.guest
  236. ]
  237. # we do not allow to modify any guest permissions
  238. if self.guest.data:
  239. for field in permission_fields:
  240. if field.data:
  241. # if done in 'validate_guest' it would display this
  242. # warning on the fields
  243. field.errors.append(
  244. _("Can't assign any permissions to this group.")
  245. )
  246. result = False
  247. def save(self):
  248. data = self.data
  249. data.pop('submit', None)
  250. data.pop('csrf_token', None)
  251. group = Group(**data)
  252. return group.save()
  253. class EditGroupForm(GroupForm):
  254. def __init__(self, group, *args, **kwargs):
  255. self.group = group
  256. kwargs['obj'] = self.group
  257. GroupForm.__init__(self, *args, **kwargs)
  258. class AddGroupForm(GroupForm):
  259. pass
  260. class ForumForm(FlaskForm):
  261. title = StringField(
  262. _("Forum title"),
  263. validators=[DataRequired(message=_("Please enter a forum title."))]
  264. )
  265. description = TextAreaField(
  266. _("Description"),
  267. validators=[Optional()],
  268. description=_("You can format your description with Markdown.")
  269. )
  270. position = IntegerField(
  271. _("Position"),
  272. default=1,
  273. validators=[DataRequired(message=_("Please enter a position for the"
  274. "forum."))]
  275. )
  276. category = QuerySelectField(
  277. _("Category"),
  278. query_factory=selectable_categories,
  279. allow_blank=False,
  280. get_label="title",
  281. description=_("The category that contains this forum.")
  282. )
  283. external = StringField(
  284. _("External link"),
  285. validators=[Optional(), URL()],
  286. description=_("A link to a website i.e. 'http://flaskbb.org'.")
  287. )
  288. moderators = StringField(
  289. _("Moderators"),
  290. description=_("Comma separated usernames. Leave it blank if you do "
  291. "not want to set any moderators.")
  292. )
  293. show_moderators = BooleanField(
  294. _("Show moderators"),
  295. description=_("Do you want to show the moderators on the index page?")
  296. )
  297. locked = BooleanField(
  298. _("Locked?"),
  299. description=_("Disable new posts and topics in this forum.")
  300. )
  301. groups = QuerySelectMultipleField(
  302. _("Group access"),
  303. query_factory=selectable_groups,
  304. get_label="name",
  305. description=_("Select the groups that can access this forum.")
  306. )
  307. submit = SubmitField(_("Save"))
  308. def validate_external(self, field):
  309. if hasattr(self, "forum"):
  310. if self.forum.topics.count() > 0:
  311. raise ValidationError(_("You cannot convert a forum that "
  312. "contains topics into an "
  313. "external link."))
  314. def validate_show_moderators(self, field):
  315. if field.data and not self.moderators.data:
  316. raise ValidationError(_("You also need to specify some "
  317. "moderators."))
  318. def validate_moderators(self, field):
  319. approved_moderators = []
  320. if field.data:
  321. moderators = [mod.strip() for mod in field.data.split(',')]
  322. users = User.query.filter(User.username.in_(moderators))
  323. for user in users:
  324. if not Permission(IsAtleastModerator, identity=user):
  325. raise ValidationError(
  326. _("%(user)s is not in a moderators group.",
  327. user=user.username)
  328. )
  329. else:
  330. approved_moderators.append(user)
  331. field.data = approved_moderators
  332. def save(self):
  333. data = self.data
  334. # delete submit and csrf_token from data
  335. data.pop('submit', None)
  336. data.pop('csrf_token', None)
  337. forum = Forum(**data)
  338. return forum.save()
  339. class EditForumForm(ForumForm):
  340. id = HiddenField()
  341. def __init__(self, forum, *args, **kwargs):
  342. self.forum = forum
  343. kwargs['obj'] = self.forum
  344. ForumForm.__init__(self, *args, **kwargs)
  345. def save(self):
  346. data = self.data
  347. # delete submit and csrf_token from data
  348. data.pop('submit', None)
  349. data.pop('csrf_token', None)
  350. forum = Forum(**data)
  351. # flush SQLA info from created instance so that it can be merged
  352. make_transient(forum)
  353. make_transient_to_detached(forum)
  354. return forum.save()
  355. class AddForumForm(ForumForm):
  356. pass
  357. class CategoryForm(FlaskForm):
  358. title = StringField(_("Category title"), validators=[
  359. DataRequired(message=_("Please enter a category title."))])
  360. description = TextAreaField(
  361. _("Description"),
  362. validators=[Optional()],
  363. description=_("You can format your description with Markdown.")
  364. )
  365. position = IntegerField(
  366. _("Position"),
  367. default=1,
  368. validators=[DataRequired(message=_("Please enter a position for the "
  369. "category."))]
  370. )
  371. submit = SubmitField(_("Save"))
  372. def save(self):
  373. data = self.data
  374. # delete submit and csrf_token from data
  375. data.pop('submit', None)
  376. data.pop('csrf_token', None)
  377. category = Category(**data)
  378. return category.save()