# -*- coding: utf-8 -*- import sqlite3 #all the imports from flask import Flask, request, session, g, redirect, url_for, \ abort, render_template, flash, _app_ctx_stack from functools import wraps import hashlib from docutils import core from docutils.writers.html4css1 import Writer from datetime import datetime from bs4 import BeautifulSoup def rstify(string): w = Writer() result = core.publish_parts(string, writer=w)['fragment'] return result # configuration app = Flask(__name__) app.config.from_envvar('CONF') @app.template_filter('shortify') def shortify(string): soup = BeautifulSoup(string) return soup("p")[0].get_text()[:50] @app.template_filter('format_date') def format_date(datetime_string, format=u"%a %d %b %Y à %Hh%M".encode("utf8")): if not datetime_string: return "" return datetime.strptime(datetime_string[:-1], "%Y-%m-%dT%H:%M:%S").strftime(format).decode("utf8") @app.template_filter('pluralize') def pluralize(word, count, plural=None): if count == 0: return "Aucun {0}".format(word) elif count == 1: return "1 {0}".format(word) elif plural: return "{0} {1}".format(count, plural) else: return "{0} {1}s".format(count, word) def query_db(query, args=(), one=False): cur = g.db.execute(query, args) rv = cur.fetchone() if one else cur.fetchall() cur.close() return rv @app.before_request def before_request(): conn = sqlite3.connect(app.config['DATABASE']) conn.row_factory = sqlite3.Row g.db = conn @app.teardown_appcontext def close_db_connection(exception): """Closes the database again at the end of the request.""" g.db.close() def login_required(f): @wraps(f) def decorated_function(*args, **kwargs): if 'user_name' not in session: return redirect(url_for('login', next=request.url)) return f(*args, **kwargs) return decorated_function @app.route('/') @app.route('/news/') @login_required def list_news(): news = query_db("SELECT news.*, users.user_name, count(comments.id) as ncomments FROM news " "LEFT JOIN users ON news.user_id = users.id " "LEFT JOIN comments ON news.id=comments.news_id GROUP BY news.id " "ORDER BY news.date DESC") comments = query_db("SELECT * from comments LEFT JOIN users " "ON comments.user_id = users.id ORDER BY date DESC LIMIT 5") users = query_db("SELECT * from users ORDER BY last_seen DESC") return render_template("news/list.html", news=news, comments=comments, users=users) @app.route('/news/add/', methods=['GET', 'POST']) @login_required def add_news(): if request.method == 'POST': content = request.form['content'] content_cache = rstify(content) cur = g.db.execute("INSERT INTO news " "('title', 'content', 'user_id', 'content_cache') " "VALUES (?, ?, ?, ?)", (request.form['title'], content, session['user_id'], content_cache)) news_id = cur.lastrowid g.db.commit() return redirect(url_for('show_news', news_id=news_id)) elif request.method == 'GET': return render_template("news/add.html") @app.route('/news//', methods=['GET', 'POST']) @login_required def show_news(news_id): news = query_db("SELECT * FROM news LEFT JOIN users ON news.user_id = users.id " "WHERE news.id = ?", (news_id,), True) if request.method == 'GET': comments = query_db("SELECT * FROM comments LEFT JOIN users " "ON comments.user_id = users.id " "WHERE comments.news_id = ? " "ORDER BY date DESC", (news_id,)) return render_template("news/show.html", news=news, comments=comments) elif request.method == 'POST': user_id = session['user_id'] content = request.form['content'] content_cache = rstify(content) g.db.execute("INSERT INTO comments " "('user_id', 'content', 'news_id', 'content_cache') " "VALUES (?, ?, ?, ?)", (user_id, content, news_id, content_cache)) g.db.commit() return redirect(url_for('show_news', news_id=news_id)) @app.route('/news//edit', methods=['GET', 'POST']) @login_required def edit_news(news_id): if request.method == 'GET': news = query_db("SELECT * from news WHERE news.id = ?", (news_id,), True) if news["user_id"] == session['user_id']: return render_template('news/add.html', news=news) elif request.method == 'POST': title = request.form['title'] content = request.form['content'] content_cache = rstify(content) g.db.execute("UPDATE news SET 'title'=?, 'content'=?, 'content_cache'=? " "WHERE news.id =?", (title, content, content_cache, news_id)) g.db.commit() return redirect(url_for('show_news', news_id=news_id)) @app.route('/user//') @login_required def view_user(user_id): user = query_db('SELECT * FROM users WHERE id= ?', (session['user_id'],), True) return render_template("user/show.html", user=user) @app.route('/user/edit/', methods=['GET', 'POST']) @login_required def edit_user(): if request.method == 'GET': user = query_db('SELECT * FROM users WHERE id= ?', (session['user_id'],), True) user = {k: user[k] for k in user.keys() if user[k]} return render_template("user/edit.html", user=user) elif request.method == 'POST': result = {} try: if request.form['password'] == request.form['password_confirm']: result['password'] = hashlib.md5(request.form['password']).hexdigest() else: error = u"Les deux mots de passe ne coïncident pas" return render_template("user/edit.html", user=request.form, error=error) except KeyError: pass result["notify"] = 1 if "notify" in request.form else 0 for key in ['email', 'phone', 'birthday', 'nameday', 'address_line1', 'address_line2', 'address_city_line']: result[key] = request.form[key].encode("utf8") set_string = ",".join("'{0}'='{1}'".format(key, value) for key,value in result.iteritems()) print set_string g.db.execute("UPDATE users SET {} where id=?".format(set_string), (session['user_id'],)) g.db.commit() return redirect(url_for('view_user', user_id=session['user_id'])) @app.route('/login/', methods=['GET', 'POST']) def login(): if 'user_name' in session: return redirect(url_for('list_news')) error = None if request.method == 'POST': username = request.form['username'] password = hashlib.md5(request.form['password']).hexdigest(); user = query_db('select * from users where user_name = ?', (username,), True) if user: if user['password'] == password: session['user_name'] = user['user_name'] session['user_id'] = user['id'] g.db.execute("UPDATE users SET last_seen=? WHERE id=?", (datetime.utcnow().strftime("%Y-%m-%dT%H:%M:%SZ"), session['user_id'])) g.db.commit() return redirect(url_for('list_news')) else: error = u'Mot de passe incorrect' else: error = u'Utilisateur non enregistré' return render_template('login.html', error=error) @app.route('/logout/') @login_required def logout(): session.pop('user_name', None) session.pop('user_id', None) return redirect(url_for('login')) if __name__=="__main__": app.run()