main.py 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468
  1. import datetime
  2. import os
  3. from flask import Flask, render_template, request, url_for
  4. from flask_login import login_user, current_user, LoginManager, logout_user, login_required
  5. from flask_wtf import CSRFProtect
  6. from flask_restful import abort
  7. from werkzeug.datastructures import CombinedMultiDict
  8. from werkzeug.utils import redirect
  9. from itsdangerous import URLSafeTimedSerializer, SignatureExpired
  10. from sqlalchemy import or_
  11. from json import loads
  12. from functions import check_password, mail, init_db_default, get_projects_data, get_user_data, save_project_logo, \
  13. overdue_quest_project
  14. from forms.edit_profile import EditProfileForm
  15. from forms.login import LoginForm
  16. from forms.find_project import FindProjectForm
  17. from forms.register import RegisterForm
  18. from forms.project import ProjectForm
  19. from forms.recovery import RecoveryForm, NewPasswordForm
  20. from forms.conf_delete_project import DeleteProjectForm
  21. from data.users import User
  22. from data.quests import Quests
  23. from data.files import Files
  24. from data.projects import Projects
  25. from data.staff_projects import StaffProjects
  26. from waitress import serve
  27. from data import db_session
  28. app = Flask(__name__)
  29. with open('incepted.config', 'r', encoding='utf-8') as file:
  30. file = file.read()
  31. file = loads(file)
  32. key = file["encrypt_key"]
  33. app.config['SECRET_KEY'] = key
  34. csrf = CSRFProtect(app)
  35. s = URLSafeTimedSerializer(key)
  36. login_manager = LoginManager()
  37. login_manager.init_app(app)
  38. @app.route('/')
  39. def base():
  40. if not current_user.is_authenticated:
  41. return render_template('main.html', title='Главная')
  42. else:
  43. return redirect('/projects')
  44. @app.route('/project/<int:id_project>/edit', methods=['GET', 'POST'])
  45. def edit_project(id_project):
  46. if current_user.is_authenticated:
  47. data_session = db_session.create_session()
  48. current_project = data_session.query(Projects).filter(Projects.id == id_project).first()
  49. if current_project:
  50. staff = data_session.query(StaffProjects).filter(StaffProjects.project == current_project.id).all()
  51. if current_user.id == current_project.creator or current_user.id in list(map(lambda x: x.user, staff)):
  52. list_users = list(
  53. map(lambda x: get_user_data(x), data_session.query(User).filter(User.id != current_user.id).all()))
  54. staff = list(map(lambda x: get_user_data(x), data_session.query(User).filter(
  55. User.id.in_(list(map(lambda x: x.user, staff)))).all())) if staff else []
  56. form = ProjectForm()
  57. if form.save.data:
  58. new_staff = []
  59. for i in list_users:
  60. if request.form.getlist(f"choose_{i['login']}") and i['id'] != current_user.id:
  61. new_staff.append(i)
  62. if i not in staff:
  63. new_staffer = StaffProjects(
  64. user=i['id'],
  65. project=current_project.id,
  66. role='user',
  67. permission=3
  68. )
  69. data_session.add(new_staffer)
  70. data_session.commit()
  71. if sorted(new_staff, key=lambda x: x['id']) != sorted(staff, key=lambda x: x['id']):
  72. for i in staff:
  73. if i not in new_staff:
  74. data_session.delete(data_session.query(StaffProjects).filter(
  75. StaffProjects.user == i['id'], StaffProjects.project == current_project.id).first())
  76. data_session.commit()
  77. if form.logo.data:
  78. current_project.photo = save_project_logo(form.logo.data)
  79. data_session.commit()
  80. current_project.name = form.name.data
  81. current_project.description = form.description.data
  82. data_session.commit()
  83. return redirect(f'/project/{current_project.id}')
  84. if form.del_photo.data:
  85. os.remove(current_project.photo)
  86. current_project.photo = 'static/images/none_project.png'
  87. data_session.commit()
  88. return redirect(f'/project/{current_project.id}/edit')
  89. form.name.data = current_project.name
  90. form.description.data = current_project.description
  91. return render_template('edit_project.html', title='Изменение проекта', form=form, list_users=list_users,
  92. staff=staff, project=current_project)
  93. else:
  94. abort(403)
  95. else:
  96. abort(404)
  97. else:
  98. return redirect('/login')
  99. @app.route('/project/<int:id_project>')
  100. def project(id_project):
  101. if current_user.is_authenticated:
  102. data_session = db_session.create_session()
  103. current_project = data_session.query(Projects).filter(Projects.id == id_project).first()
  104. if current_project:
  105. staff = data_session.query(StaffProjects).filter(StaffProjects.project == current_project.id).all()
  106. if current_user.id == current_project.creator or current_user.id in list(map(lambda x: x.user, staff)):
  107. staff = list(map(lambda x: get_user_data(x), data_session.query(User).filter(
  108. User.id.in_(list(map(lambda x: x.user, staff)))).all())) if staff else []
  109. quests = data_session.query(Quests).filter(Quests.project == current_project.id).all()
  110. if quests:
  111. quests.sort(key=lambda x: (x.realized, x.deadline))
  112. quests = list(map(lambda x: overdue_quest_project(x), quests))
  113. return render_template('project.html',
  114. project=current_project,
  115. title=current_project.name,
  116. staff=staff,
  117. quests=quests)
  118. else:
  119. abort(403)
  120. else:
  121. abort(404)
  122. else:
  123. return redirect('/login')
  124. @app.route('/recovery/confirmation/<token>', methods=['GET', 'POST'])
  125. def conf_recovery(token):
  126. try:
  127. user_email = s.loads(token, max_age=86400)
  128. data_session = db_session.create_session()
  129. user = data_session.query(User).filter(User.email == user_email).first()
  130. if user:
  131. form = NewPasswordForm()
  132. if form.validate_on_submit():
  133. if form.password.data != form.repeat_password.data:
  134. return render_template('recovery.html', title='Восстановление', form=form, recovery=0,
  135. message='Пароли не совпадают')
  136. status_password = check_password(form.password.data)
  137. if status_password != 'OK':
  138. return render_template('recovery.html', title='Восстановление', form=form, recovery=0,
  139. message=str(status_password))
  140. user.set_password(form.password.data)
  141. data_session.commit()
  142. mail(f'Для аккаунта {user.login}, успешно был обновлен пароль', user.email,
  143. 'Изменение пароля')
  144. return redirect('/login?message=Пароль обновлен')
  145. return render_template('recovery.html', title='Восстановление', form=form, recovery=0, message='')
  146. else:
  147. return redirect('/login?message=Пользователь не найден&danger=True')
  148. except SignatureExpired:
  149. return redirect('/login?message=Срок действия ссылки истек&danger=True')
  150. @app.route('/recovery', methods=['GET', 'POST'])
  151. def recovery():
  152. if not current_user.is_authenticated:
  153. form = RecoveryForm()
  154. if form.validate_on_submit():
  155. token = s.dumps(form.email.data)
  156. link_conf = url_for('conf_recovery', token=token, _external=True)
  157. mail(f'Для сбросы пароля пройдите по ссылке: {link_conf}', form.email.data,
  158. 'Восстановление доступа')
  159. return redirect('/login?message=Мы выслали ссылку для сброса вам на почту')
  160. return render_template('recovery.html', title='Восстановление пароля', form=form, recovery=True, message='')
  161. else:
  162. return redirect('/')
  163. @app.route('/project/<int:id_project>/delete', methods=['GET', 'POST'])
  164. def delete_project(id_project):
  165. if current_user.is_authenticated:
  166. data_session = db_session.create_session()
  167. project_del = data_session.query(Projects).filter(Projects.id == id_project).first()
  168. if project_del:
  169. if project_del.creator == current_user.id:
  170. form = DeleteProjectForm()
  171. if form.validate_on_submit():
  172. if form.conf.data != f'delete/{project_del.name}':
  173. return render_template('delete_project.html', title='Удаление проекта', form=form,
  174. project=project_del,
  175. message='Вы не правильно ввели фразу')
  176. staff = data_session.query(StaffProjects).filter(StaffProjects.project == id_project).all()
  177. for i in staff:
  178. data_session.delete(i)
  179. if 'none_project' not in project_del.photo:
  180. os.remove(project_del.photo)
  181. shutil.rmtree(f'static/app_files/all_projects/{str(project_del.id)}')
  182. data_session.delete(project_del)
  183. data_session.commit()
  184. return redirect('/projects')
  185. return render_template('delete_project.html', title='Удаление проекта', form=form, project=project_del,
  186. message='')
  187. else:
  188. abort(403)
  189. else:
  190. abort(404)
  191. else:
  192. return redirect('/login')
  193. @app.route('/user/<string:_login>', methods=['GET', 'POST'])
  194. def user_view(_login):
  195. if current_user.is_authenticated:
  196. data_session = db_session.create_session()
  197. user = data_session.query(User).filter(User.login == _login).first()
  198. if user:
  199. current_projects = data_session.query(Projects).filter(or_(Projects.creator == user.id, Projects.id.in_(
  200. list(map(lambda x: x[0], data_session.query(
  201. StaffProjects.project).filter(
  202. StaffProjects.user == user.id).all()))))).all()
  203. resp = list(map(lambda x: get_projects_data(x), current_projects))
  204. return render_template('user_view.html', title=user.name + ' ' + user.surname, user=user,
  205. list_projects=resp)
  206. else:
  207. abort(404)
  208. else:
  209. return redirect('/login')
  210. @app.route('/projects/new', methods=['GET', 'POST'])
  211. def new_project():
  212. if current_user.is_authenticated:
  213. form = ProjectForm()
  214. data_session = db_session.create_session()
  215. list_users = list(
  216. map(lambda x: get_user_data(x), data_session.query(User).filter(User.id != current_user.id).all()))
  217. if form.validate_on_submit():
  218. currnet_project = Projects(
  219. name=form.name.data,
  220. description=form.description.data,
  221. date_create=datetime.datetime.now(),
  222. creator=current_user.id
  223. )
  224. currnet_project.photo = save_project_logo(
  225. form.logo.data) if form.logo.data else 'static/images/none_project.png'
  226. data_session.add(currnet_project)
  227. data_session.flush()
  228. data_session.refresh(currnet_project)
  229. for i in list_users:
  230. if request.form.getlist(f"choose_{i['login']}") and i['id'] != current_user.id:
  231. new_staffer = StaffProjects(
  232. user=i['id'],
  233. project=currnet_project.id,
  234. role='user',
  235. permission=3
  236. )
  237. data_session.add(new_staffer)
  238. data_session.commit()
  239. os.mkdir(f'static/app_files/all_projects/{str(currnet_project.id)}')
  240. return redirect('/projects')
  241. return render_template('new_project.html', title='Новый проект', form=form, list_users=list_users)
  242. else:
  243. return redirect('/login')
  244. @app.route('/projects', methods=['GET', 'POST'])
  245. def projects():
  246. if current_user.is_authenticated:
  247. find = False
  248. form = FindProjectForm()
  249. data_session = db_session.create_session()
  250. resp = []
  251. current_projects = \
  252. data_session.query(Projects).filter(or_(Projects.creator == current_user.id,
  253. Projects.id.in_(
  254. list(map(lambda x: x[0],
  255. data_session.query(
  256. StaffProjects.project).filter(
  257. StaffProjects.user
  258. == current_user.id).all()))))).all()
  259. if form.validate_on_submit():
  260. new_resp = []
  261. for i in range(len(current_projects)):
  262. if str(form.project.data).lower().strip() in str(current_projects[i].name).lower().strip():
  263. new_resp.append(current_projects[i])
  264. current_projects = new_resp
  265. find = True
  266. resp = list(map(lambda x: get_projects_data(x), current_projects))
  267. return render_template('projects.html', title='Проекты', list_projects=resp, form=form, find=find)
  268. else:
  269. return redirect('/login')
  270. @app.route('/profile', methods=['GET', 'POST'])
  271. def profile():
  272. if current_user.is_authenticated:
  273. form = EditProfileForm(
  274. CombinedMultiDict((request.files, request.form)),
  275. email=current_user.email,
  276. name=current_user.name,
  277. surname=current_user.surname,
  278. about=current_user.about,
  279. birthday=current_user.birthday
  280. )
  281. if form.del_photo.data:
  282. data_session = db_session.create_session()
  283. user = data_session.query(User).filter(User.id == current_user.id).first()
  284. if not user:
  285. return render_template('profile.html', title='Профиль', form=form,
  286. message='Ошибка, пользователь ненайден')
  287. os.remove(current_user.photo)
  288. user.photo = 'static/images/none_logo.png'
  289. data_session.commit()
  290. if form.validate_on_submit():
  291. data_session = db_session.create_session()
  292. user = data_session.query(User).filter(User.id == current_user.id).first()
  293. if not user:
  294. return render_template('profile.html', title='Профиль', form=form,
  295. message='Ошибка, пользователь ненайден')
  296. if form.email.data != current_user.email:
  297. token = s.dumps(form.email.data)
  298. link_conf = url_for('confirmation', token=token, _external=True)
  299. mail(f'Для изменения почты пройдите по ссылке: {link_conf}', form.email.data,
  300. 'Изменение почты')
  301. user.activated = False
  302. user.email = form.email.data
  303. if form.photo.data:
  304. with open(f'static/app_files/user_logo/{current_user.login}.png', 'wb') as file:
  305. form.photo.data.save(file)
  306. user.photo = f'static/app_files/user_logo/{current_user.login}.png'
  307. user.name = form.name.data
  308. user.surname = form.surname.data
  309. user.about = form.about.data
  310. user.birthday = form.birthday.data
  311. data_session.commit()
  312. return redirect('/profile')
  313. return render_template('profile.html', title='Профиль', form=form, message='')
  314. else:
  315. return redirect('/login')
  316. @login_manager.user_loader
  317. def load_user(user_id):
  318. db_sess = db_session.create_session()
  319. return db_sess.query(User).get(user_id)
  320. @app.route('/login', methods=['GET', 'POST'])
  321. def login():
  322. if not current_user.is_authenticated:
  323. message = request.args.get('message') if request.args.get('message') else ''
  324. danger = request.args.get('danger') if request.args.get('danger') else False
  325. form = LoginForm()
  326. if form.validate_on_submit():
  327. data_session = db_session.create_session()
  328. user = data_session.query(User).filter(User.email == form.login.data).first()
  329. if not user:
  330. user = data_session.query(User).filter(User.login == form.login.data).first()
  331. if user and user.check_password(form.password.data):
  332. if user.activated:
  333. login_user(user, remember=form.remember_me.data)
  334. return redirect('/projects')
  335. else:
  336. return render_template('login.html',
  337. message="Ваша почта не подтверждена",
  338. danger=True,
  339. form=form)
  340. return render_template('login.html',
  341. message="Неправильный логин или пароль",
  342. danger=True,
  343. form=form)
  344. return render_template('login.html', title='Авторизация', form=form, message=message,
  345. danger=danger)
  346. else:
  347. return redirect('/projects')
  348. @app.route('/logout')
  349. @login_required
  350. def logout():
  351. logout_user()
  352. return redirect("/")
  353. @app.route('/register', methods=['GET', 'POST'])
  354. def register():
  355. if not current_user.is_authenticated:
  356. form = RegisterForm()
  357. if form.validate_on_submit():
  358. data_session = db_session.create_session()
  359. if data_session.query(User).filter(User.login == form.login.data).first():
  360. return render_template('register.html', form=form, message="Такой пользователь уже есть",
  361. title='Регистрация')
  362. if data_session.query(User).filter(User.email == form.email.data).first():
  363. return render_template('register.html', form=form, message="Такая почта уже есть", title='Регистрация')
  364. status_password = check_password(form.password.data)
  365. if status_password != 'OK':
  366. return render_template('register.html', form=form, message=status_password, title='Регистрация')
  367. user = User(
  368. email=form.email.data,
  369. name=form.name.data,
  370. login=form.login.data,
  371. activity=datetime.datetime.now(),
  372. data_reg=datetime.date.today(),
  373. photo='static/images/none_logo.png',
  374. role=1
  375. )
  376. user.set_password(form.password.data)
  377. data_session.add(user)
  378. data_session.commit()
  379. token = s.dumps(form.email.data)
  380. link_conf = url_for('confirmation', token=token, _external=True)
  381. mail(f'Для завершения регистрации пройдите по ссылке: {link_conf}', form.email.data,
  382. 'Подтверждение регистрации')
  383. return redirect('/login?message=Мы выслали ссылку для подтверждения почты')
  384. return render_template('register.html', form=form, message='', title='Регистрация')
  385. else:
  386. return redirect('/projects')
  387. @app.route('/confirmation/<token>')
  388. def confirmation(token):
  389. try:
  390. user_email = s.loads(token, max_age=86400)
  391. data_session = db_session.create_session()
  392. user = data_session.query(User).filter(User.email == user_email).first()
  393. if user:
  394. user.activated = True
  395. data_session.commit()
  396. return redirect('/login?message=Почта успешно подтверждена')
  397. else:
  398. return redirect('/login?message=Пользователь не найден&danger=True')
  399. except SignatureExpired:
  400. data_session = db_session.create_session()
  401. users = data_session.query(User).filter(
  402. User.activated == 0 and User.activated < datetime.datetime.now() - datetime.timedelta(days=1)).all()
  403. if users:
  404. list(map(lambda x: data_session.delete(x), users))
  405. data_session.commit()
  406. return redirect('/login?message=Срок действия ссылки истек, данные удалены&danger=True')
  407. @app.errorhandler(500)
  408. def internal_server_error(error):
  409. return render_template('page_error.html', title='Ошибка сервера', error='500', message='Технические шоколадки')
  410. @app.errorhandler(404)
  411. def page_not_found(error):
  412. return render_template('page_error.html', title='Страница не найдена', error='404', message='Страница не найдена')
  413. @app.errorhandler(403)
  414. def access_error(error):
  415. return render_template('page_error.html', title='Ошибка доступа', error='403', message='Доступ сюда запрещен')
  416. def main():
  417. db_path = 'db/incepted.db'
  418. db = os.path.exists(db_path)
  419. db_session.global_init(db_path)
  420. if not db:
  421. init_db_default()
  422. serve(app, host='0.0.0.0', port=5000)
  423. if __name__ == '__main__':
  424. main()