auth.py 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290
  1. from flask import Blueprint, render_template, redirect, flash, url_for, request, abort, current_app, g
  2. from flask_login import login_required, login_user, current_user, logout_user
  3. from flask_wtf import FlaskForm
  4. from wtforms import StringField, PasswordField, BooleanField, SubmitField, ValidationError
  5. from wtforms.validators import DataRequired, Length, EqualTo
  6. import app
  7. from object.user import User, load_user_by_email
  8. from send_email import send_msg
  9. auth = Blueprint("auth", __name__)
  10. class LoginForm(FlaskForm):
  11. email = StringField("邮箱", validators=[DataRequired(), Length(1, 32)])
  12. passwd = PasswordField("密码", validators=[DataRequired(), Length(8, 32)])
  13. remember = BooleanField("记住我")
  14. submit = SubmitField("登录")
  15. class RegisterForm(FlaskForm):
  16. email = StringField("邮箱", validators=[DataRequired(), Length(1, 32)])
  17. passwd = PasswordField("密码", validators=[DataRequired(),
  18. EqualTo("passwd_again", message="两次输入密码不相同"),
  19. Length(8, 32)])
  20. passwd_again = PasswordField("重复密码", validators=[DataRequired()])
  21. submit = SubmitField("注册")
  22. def validate_email(self, field):
  23. if load_user_by_email(field.data) is not None:
  24. raise ValidationError("邮箱已被注册")
  25. class ChangePasswdForm(FlaskForm):
  26. old_passwd = PasswordField("旧密码", validators=[DataRequired()])
  27. passwd = PasswordField("新密码", validators=[DataRequired(),
  28. EqualTo("passwd_again", message="两次输入密码不相同"),
  29. Length(8, 32)])
  30. passwd_again = PasswordField("重复密码", validators=[DataRequired()])
  31. submit = SubmitField("修改密码")
  32. class DeleteUserForm(FlaskForm):
  33. email = StringField("邮箱", validators=[DataRequired(), Length(1, 32)])
  34. submit = SubmitField("删除用户")
  35. def validate_email(self, field):
  36. if load_user_by_email(field.data) is None:
  37. raise ValidationError("邮箱用户不存在")
  38. class CreateRoleForm(FlaskForm):
  39. name = StringField("角色名称", validators=[DataRequired(), Length(1, 20)])
  40. authority = StringField("权限", validators=[Length(0, 100)])
  41. submit = SubmitField("创建角色")
  42. class DeleteRoleForm(FlaskForm):
  43. name = StringField("角色名称", validators=[DataRequired(), Length(1, 20)])
  44. submit = SubmitField("删除角色")
  45. class SetRoleForm(FlaskForm):
  46. email = StringField("邮箱", validators=[DataRequired(), Length(1, 32)])
  47. name = StringField("角色名称", validators=[DataRequired(), Length(1, 20)])
  48. submit = SubmitField("设置角色")
  49. @auth.route('/yours')
  50. @login_required
  51. def yours_page():
  52. msg_count, comment_count, blog_count = current_user.count_info()
  53. app.HBlogFlask.print_load_page_log("user info")
  54. return render_template("auth/yours.html", msg_count=msg_count, comment_count=comment_count, blog_count=blog_count)
  55. @auth.route('/login', methods=["GET", "POST"])
  56. def login_page():
  57. if current_user.is_authenticated:
  58. app.HBlogFlask.print_user_not_allow_opt_log("login")
  59. return redirect(url_for("auth.yours_page"))
  60. form = LoginForm()
  61. if form.validate_on_submit():
  62. user = load_user_by_email(form.email.data)
  63. if user is not None and user.check_passwd(form.passwd.data):
  64. login_user(user, form.remember.data)
  65. next_page = request.args.get("next")
  66. if next_page is None or not next_page.startswith('/'):
  67. next_page = url_for('base.index_page')
  68. flash("登陆成功")
  69. app.HBlogFlask.print_user_opt_success_log(f"login {form.email.data}")
  70. return redirect(next_page)
  71. flash("账号或密码错误")
  72. app.HBlogFlask.print_user_opt_fail_log(f"login {form.email.data}")
  73. return redirect(url_for("auth.login_page"))
  74. app.HBlogFlask.print_load_page_log("user login")
  75. return render_template("auth/login.html", form=form)
  76. @auth.route('/register', methods=["GET", "POST"])
  77. def register_page():
  78. if current_user.is_authenticated:
  79. app.HBlogFlask.print_user_not_allow_opt_log("register")
  80. return redirect(url_for("auth.yours_page"))
  81. form = RegisterForm()
  82. if form.validate_on_submit():
  83. token = User.creat_token(form.email.data, form.passwd.data)
  84. register_url = url_for("auth.confirm_page", token=token, _external=True)
  85. hblog: app.Hblog = current_app
  86. send_msg("注册确认", hblog.mail, form.email.data, "register", register_url=register_url)
  87. flash("注册提交成功, 请进入邮箱点击确认注册链接")
  88. app.HBlogFlask.print_import_user_opt_success_log(f"register {form.email.data}")
  89. return redirect(url_for("base.index_page"))
  90. app.HBlogFlask.print_load_page_log("user register")
  91. return render_template("auth/register.html", RegisterForm=form)
  92. @auth.route('/confirm')
  93. def confirm_page():
  94. token = request.args.get("token", None)
  95. if token is None:
  96. app.HBlogFlask.print_user_opt_fail_log(f"Confirm (bad token)")
  97. abort(404)
  98. return
  99. token = User.load_token(token)
  100. if token is None:
  101. app.HBlogFlask.print_user_opt_fail_log(f"Confirm (bad token)")
  102. abort(404)
  103. return
  104. if load_user_by_email(token[0]) is not None:
  105. app.HBlogFlask.print_user_opt_fail_log(f"Confirm (bad token)")
  106. abort(404)
  107. return
  108. User(token[0], token[1], None, None).create()
  109. current_app.logger.info(f"{token[0]} confirm success")
  110. app.HBlogFlask.print_import_user_opt_success_log(f"confirm {token[0]}")
  111. flash(f"用户{token[0]}认证完成")
  112. return redirect(url_for("base.index_page"))
  113. @auth.route('/logout')
  114. @login_required
  115. def logout_page():
  116. app.HBlogFlask.print_import_user_opt_success_log(f"logout")
  117. logout_user()
  118. flash("退出登录成功")
  119. return redirect(url_for("base.index_page"))
  120. @auth.route('/passwd', methods=['GET', 'POST'])
  121. @login_required
  122. def change_passwd_page():
  123. form = ChangePasswdForm()
  124. if form.validate_on_submit():
  125. if not current_user.check_passwd(form.old_passwd.data):
  126. app.HBlogFlask.print_user_opt_fail_log("change passwd (old passwd error)")
  127. flash("旧密码错误")
  128. return redirect(url_for("auth.change_passwd_page"))
  129. if current_user.change_passwd(form.passwd.data):
  130. app.HBlogFlask.print_user_opt_success_log(f"change passwd")
  131. flash("密码修改成功")
  132. else:
  133. app.HBlogFlask.print_user_opt_error_log(f"change passwd")
  134. flash("密码修改失败")
  135. return redirect(url_for("auth.yours_page"))
  136. app.HBlogFlask.print_load_page_log("user change passwd")
  137. return render_template("auth/passwd.html", ChangePasswdForm=form)
  138. @auth.route('/delete', methods=['GET', 'POST'])
  139. @login_required
  140. def delete_user_page():
  141. if not current_user.check_role("DeleteUser"):
  142. app.HBlogFlask.print_user_not_allow_opt_log("delete user")
  143. abort(403)
  144. return
  145. form = DeleteUserForm()
  146. if form.validate_on_submit():
  147. user = load_user_by_email(form.email.data)
  148. if user is None:
  149. app.HBlogFlask.print_sys_opt_fail_log(f"delete user {form.email.data}")
  150. abort(404)
  151. return
  152. if user.delete():
  153. app.HBlogFlask.print_sys_opt_success_log(f"{current_user.email} delete user {form.email.data} success")
  154. flash("用户删除成功")
  155. else:
  156. app.HBlogFlask.print_sys_opt_fail_log(f"{current_user.email} delete user {form.email.data} fail")
  157. flash("用户删除失败")
  158. return redirect(url_for("auth.delete_user_page"))
  159. app.HBlogFlask.print_load_page_log("delete user")
  160. return render_template("auth/delete.html", DeleteUserForm=form)
  161. @auth.route('/role', methods=['GET'])
  162. @login_required
  163. def role_page():
  164. if not current_user.check_role("ConfigureSystem"):
  165. app.HBlogFlask.print_user_not_allow_opt_log("load role setting")
  166. abort(403)
  167. return
  168. app.HBlogFlask.print_load_page_log("role setting")
  169. return render_template("auth/role.html",
  170. CreateRoleForm=CreateRoleForm(),
  171. DeleteRoleForm=DeleteRoleForm(),
  172. SetRoleForm=SetRoleForm())
  173. @auth.route('/role-create', methods=['POST'])
  174. @login_required
  175. def role_create_page():
  176. form = CreateRoleForm()
  177. if form.validate_on_submit():
  178. if not current_user.check_role("ConfigureSystem"):
  179. app.HBlogFlask.print_user_not_allow_opt_log("create role")
  180. abort(403)
  181. return
  182. if User.create_role(form.name.data, form.authority.data.replace(" ", "").split(";")):
  183. app.HBlogFlask.print_sys_opt_success_log(f"Create role success: {form.name.data}")
  184. flash("角色创建成功")
  185. else:
  186. app.HBlogFlask.print_sys_opt_success_log(f"Create role fail: {form.name.data}")
  187. flash("角色创建失败")
  188. return redirect(url_for("auth.role_page"))
  189. abort(404)
  190. return
  191. @auth.route('/role-delete', methods=['POST'])
  192. @login_required
  193. def role_delete_page():
  194. form = DeleteRoleForm()
  195. if form.validate_on_submit():
  196. if not current_user.check_role("ConfigureSystem"):
  197. app.HBlogFlask.print_user_not_allow_opt_log("delete role")
  198. abort(403)
  199. return
  200. if User.delete_role(form.name.data):
  201. app.HBlogFlask.print_sys_opt_success_log(f"Delete role success: {form.name.data}")
  202. flash("角色删除成功")
  203. else:
  204. app.HBlogFlask.print_sys_opt_fail_log(f"Delete role fail: {form.name.data}")
  205. flash("角色删除失败")
  206. return redirect(url_for("auth.role_page"))
  207. abort(404)
  208. return
  209. @auth.route('/role-set', methods=['POST'])
  210. @login_required
  211. def role_set_page():
  212. form = SetRoleForm()
  213. if form.validate_on_submit():
  214. if not current_user.check_role("ConfigureSystem"):
  215. app.HBlogFlask.print_user_not_allow_opt_log("assign user a role")
  216. abort(403)
  217. return
  218. user = load_user_by_email(form.email.data)
  219. if user is not None:
  220. if user.set_user_role(form.name.data):
  221. app.HBlogFlask.print_sys_opt_success_log(f"Role assign {form.email.data} -> {form.name.data}")
  222. flash("角色设置成功")
  223. else:
  224. app.HBlogFlask.print_sys_opt_fail_log(f"Role assign {form.email.data} -> {form.name.data}")
  225. flash("角色设置失败")
  226. else:
  227. app.HBlogFlask.print_sys_opt_fail_log(f"Role assign (bad email) {form.email.data} -> {form.name.data}")
  228. flash("邮箱未注册")
  229. return redirect(url_for("auth.role_page"))
  230. abort(404)
  231. return
  232. @auth.context_processor
  233. def inject_base():
  234. return {"top_nav": ["", "", "", "", "", "active"]}