auth.py 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285
  1. from flask import Blueprint, render_template, redirect, flash, url_for, request, abort, current_app
  2. from flask_login import login_required, login_user, current_user, logout_user
  3. from flask_wtf import FlaskForm
  4. from wtforms import StringField, PasswordField, BooleanField, SelectMultipleField, SelectField, SubmitField, ValidationError
  5. from wtforms.validators import DataRequired
  6. import app
  7. from object.user import User, load_user_by_email
  8. from send_email import send_msg
  9. auth = Blueprint("auth", __name__)
  10. class LoginForm(FlaskForm):
  11. email = StringField("邮箱", validators=[DataRequired()])
  12. passwd = PasswordField("密码", validators=[DataRequired()])
  13. remember = BooleanField("记住我")
  14. submit = SubmitField("登录")
  15. class RegisterForm(FlaskForm):
  16. email = StringField("邮箱", validators=[DataRequired()])
  17. passwd = PasswordField("密码", validators=[DataRequired()])
  18. passwd_again = PasswordField("重复密码", validators=[DataRequired()])
  19. submit = SubmitField("注册")
  20. def validate_email(self, field):
  21. if load_user_by_email(field.data) is not None:
  22. raise ValidationError("邮箱已被注册")
  23. class ChangePasswdForm(FlaskForm):
  24. old_passwd = PasswordField("旧密码", validators=[DataRequired()])
  25. passwd = PasswordField("新密码", validators=[DataRequired()])
  26. passwd_again = PasswordField("重复密码", validators=[DataRequired()])
  27. submit = SubmitField("修改密码")
  28. class DeleteUserForm(FlaskForm):
  29. email = StringField("邮箱", validators=[DataRequired()])
  30. submit = SubmitField("删除用户")
  31. def validate_email(self, field):
  32. if load_user_by_email(field.data) is None:
  33. raise ValidationError("邮箱用户不存在")
  34. class CreateRoleForm(FlaskForm):
  35. name = StringField("角色名称", validators=[DataRequired()])
  36. authority = SelectMultipleField("权限", coerce=str, choices=User.RoleAuthorize)
  37. submit = SubmitField("创建角色")
  38. class DeleteRoleForm(FlaskForm):
  39. name = SelectField("角色名称", validators=[DataRequired()], coerce=int)
  40. submit = SubmitField("删除角色")
  41. def __init__(self):
  42. super(DeleteRoleForm, self).__init__()
  43. self.name.choices = [(i[0], i[1]) for i in User.get_role_list()]
  44. class SetRoleForm(FlaskForm):
  45. email = StringField("邮箱", validators=[DataRequired()])
  46. name = SelectField("角色名称", validators=[DataRequired()], coerce=int)
  47. submit = SubmitField("设置角色")
  48. def __init__(self):
  49. super(SetRoleForm, self).__init__()
  50. self.name.choices = [(i[0], i[1]) for i in User.get_role_list()]
  51. @auth.route('/yours')
  52. @login_required
  53. def yours_page():
  54. msg_count, comment_count, blog_count = current_user.count_info()
  55. app.HBlogFlask.print_load_page_log("user info")
  56. return render_template("auth/yours.html", msg_count=msg_count, comment_count=comment_count, blog_count=blog_count)
  57. @auth.route('/login', methods=["GET", "POST"])
  58. def login_page():
  59. if current_user.is_authenticated:
  60. app.HBlogFlask.print_user_not_allow_opt_log("login")
  61. return redirect(url_for("auth.yours_page"))
  62. form = LoginForm()
  63. if form.validate_on_submit():
  64. user = load_user_by_email(form.email.data)
  65. if user is not None and user.check_passwd(form.passwd.data):
  66. login_user(user, form.remember.data)
  67. next_page = request.args.get("next")
  68. if next_page is None or not next_page.startswith('/'):
  69. next_page = url_for('base.index_page')
  70. flash("登陆成功")
  71. app.HBlogFlask.print_user_opt_success_log(f"login {form.email.data}")
  72. return redirect(next_page)
  73. flash("账号或密码错误")
  74. app.HBlogFlask.print_user_opt_fail_log(f"login {form.email.data}")
  75. return redirect(url_for("auth.login_page"))
  76. app.HBlogFlask.print_load_page_log("user login")
  77. return render_template("auth/login.html", form=form)
  78. @auth.route('/register', methods=["GET", "POST"])
  79. def register_page():
  80. if current_user.is_authenticated:
  81. app.HBlogFlask.print_user_not_allow_opt_log("register")
  82. return redirect(url_for("auth.yours_page"))
  83. form = RegisterForm()
  84. if form.validate_on_submit():
  85. email = form.email.data
  86. passwd = form.passwd.data
  87. if len(email) > 20:
  88. flash("邮箱太长了")
  89. return redirect(url_for("auth.register_page"))
  90. elif not 8 < len(passwd) < 32:
  91. flash("请输入8-12位密码")
  92. return redirect(url_for("auth.register_page"))
  93. elif passwd != form.passwd_again.data:
  94. flash("两次输入的密码不一致")
  95. return redirect(url_for("auth.register_page"))
  96. token = User.creat_token(form.email.data, form.passwd.data)
  97. register_url = url_for("auth.confirm_page", token=token, _external=True)
  98. hblog: app.Hblog = current_app
  99. send_msg("注册确认", hblog.mail, form.email.data, "register", register_url=register_url)
  100. flash("注册提交成功, 请进入邮箱点击确认注册链接")
  101. app.HBlogFlask.print_import_user_opt_success_log(f"register {form.email.data}")
  102. return redirect(url_for("base.index_page"))
  103. app.HBlogFlask.print_load_page_log("user register")
  104. return render_template("auth/register.html", RegisterForm=form)
  105. @auth.route('/confirm')
  106. def confirm_page():
  107. token = request.args.get("token", None)
  108. if token is None:
  109. app.HBlogFlask.print_user_opt_fail_log(f"Confirm (bad token)")
  110. abort(404)
  111. return
  112. token = User.load_token(token)
  113. if token is None:
  114. app.HBlogFlask.print_user_opt_fail_log(f"Confirm (bad token)")
  115. abort(404)
  116. return
  117. if load_user_by_email(token[0]) is not None:
  118. app.HBlogFlask.print_user_opt_fail_log(f"Confirm (bad token)")
  119. abort(404)
  120. return
  121. User(token[0], token[1], None, None).create()
  122. current_app.logger.info(f"{token[0]} confirm success")
  123. app.HBlogFlask.print_import_user_opt_success_log(f"confirm {token[0]}")
  124. flash(f"用户{token[0]}认证完成")
  125. return redirect(url_for("base.index_page"))
  126. @auth.route('/logout')
  127. @login_required
  128. def logout_page():
  129. app.HBlogFlask.print_import_user_opt_success_log(f"logout")
  130. logout_user()
  131. flash("退出登录成功")
  132. return redirect(url_for("base.index_page"))
  133. @auth.route('/passwd', methods=['GET', 'POST'])
  134. @login_required
  135. def change_passwd_page():
  136. form = ChangePasswdForm()
  137. if form.validate_on_submit():
  138. passwd = form.passwd.data
  139. if not 8 < passwd < 32:
  140. flash("请输入8-32位密码")
  141. return redirect(url_for("auth.change_passwd_page"))
  142. elif passwd != form.passwd_again.data:
  143. flash("两次输入的密码不一致")
  144. return redirect(url_for("auth.change_passwd_page"))
  145. elif not current_user.check_passwd(form.old_passwd.data):
  146. app.HBlogFlask.print_user_opt_fail_log("change passwd (old passwd error)")
  147. flash("旧密码错误")
  148. return redirect(url_for("auth.change_passwd_page"))
  149. if current_user.change_passwd(passwd):
  150. app.HBlogFlask.print_user_opt_success_log(f"change passwd")
  151. flash("密码修改成功")
  152. else:
  153. app.HBlogFlask.print_user_opt_error_log(f"change passwd")
  154. flash("密码修改失败")
  155. return redirect(url_for("auth.yours_page"))
  156. app.HBlogFlask.print_load_page_log("user change passwd")
  157. return render_template("auth/passwd.html", ChangePasswdForm=form)
  158. @auth.route('/delete', methods=['GET', 'POST'])
  159. @login_required
  160. @app.role_required("DeleteUser", "delete user")
  161. def delete_user_page():
  162. form = DeleteUserForm()
  163. if form.validate_on_submit():
  164. user = load_user_by_email(form.email.data)
  165. if user is None:
  166. app.HBlogFlask.print_sys_opt_fail_log(f"delete user {form.email.data}")
  167. abort(404)
  168. return
  169. if user.delete():
  170. app.HBlogFlask.print_sys_opt_success_log(f"{current_user.email} delete user {form.email.data} success")
  171. flash("用户删除成功")
  172. else:
  173. app.HBlogFlask.print_sys_opt_fail_log(f"{current_user.email} delete user {form.email.data} fail")
  174. flash("用户删除失败")
  175. return redirect(url_for("auth.delete_user_page"))
  176. app.HBlogFlask.print_load_page_log("delete user")
  177. return render_template("auth/delete.html", DeleteUserForm=form)
  178. @auth.route('/role', methods=['GET'])
  179. @login_required
  180. @app.role_required("ConfigureSystem", "load role setting")
  181. def role_page():
  182. app.HBlogFlask.print_load_page_log("role setting")
  183. return render_template("auth/role.html",
  184. CreateRoleForm=CreateRoleForm(),
  185. DeleteRoleForm=DeleteRoleForm(),
  186. SetRoleForm=SetRoleForm())
  187. @auth.route('/role-create', methods=['POST'])
  188. @login_required
  189. @app.form_required(CreateRoleForm, "create role")
  190. @app.role_required("ConfigureSystem", "create role")
  191. def role_create_page(form: CreateRoleForm):
  192. name = form.name.data
  193. if len(name) > 10:
  194. flash("角色名字太长")
  195. else:
  196. if User.create_role(name, form.authority.data):
  197. app.HBlogFlask.print_sys_opt_success_log(f"Create role success: {name}")
  198. flash("角色创建成功")
  199. else:
  200. app.HBlogFlask.print_sys_opt_success_log(f"Create role fail: {name}")
  201. flash("角色创建失败")
  202. return redirect(url_for("auth.role_page"))
  203. @auth.route('/role-delete', methods=['POST'])
  204. @login_required
  205. @app.form_required(DeleteRoleForm, "delete role")
  206. @app.role_required("ConfigureSystem", "delete role")
  207. def role_delete_page(form: DeleteRoleForm):
  208. if User.delete_role(form.name.data):
  209. app.HBlogFlask.print_sys_opt_success_log(f"Delete role success: {form.name.data}")
  210. flash("角色删除成功")
  211. else:
  212. app.HBlogFlask.print_sys_opt_fail_log(f"Delete role fail: {form.name.data}")
  213. flash("角色删除失败")
  214. return redirect(url_for("auth.role_page"))
  215. @auth.route('/role-set', methods=['POST'])
  216. @login_required
  217. @app.form_required(SetRoleForm, "assign user a role")
  218. @app.role_required("ConfigureSystem", "assign user a role")
  219. def role_set_page(form: SetRoleForm):
  220. user = load_user_by_email(form.email.data)
  221. if user is not None:
  222. if user.set_user_role(form.name.data):
  223. app.HBlogFlask.print_sys_opt_success_log(f"Role assign {form.email.data} -> {form.name.data}")
  224. flash("角色设置成功")
  225. else:
  226. app.HBlogFlask.print_sys_opt_fail_log(f"Role assign {form.email.data} -> {form.name.data}")
  227. flash("角色设置失败")
  228. else:
  229. app.HBlogFlask.print_sys_opt_fail_log(f"Role assign (bad email) {form.email.data} -> {form.name.data}")
  230. flash("邮箱未注册")
  231. return redirect(url_for("auth.role_page"))
  232. @auth.context_processor
  233. def inject_base():
  234. return {"top_nav": ["", "", "", "", "", "active"]}