# -*- coding: utf-8 -*- #all the imports from flask import Flask, request, session, g, redirect, url_for, render_template from functools import wraps import hashlib from pytz import timezone from docutils import core from docutils.writers.html4css1 import Writer from datetime import datetime import time from email import utils from bs4 import BeautifulSoup from flask_mail import Mail, Message import locale from sqlalchemy import create_engine, MetaData, Table, select, func from sqlalchemy.orm import scoped_session, sessionmaker locale.setlocale(locale.LC_ALL, 'fr_FR.UTF-8') engine = create_engine('sqlite:///famille.db', convert_unicode=True) db_session = scoped_session(sessionmaker(autocommit=False, autoflush=False, bind=engine)) def rstify(string): w = Writer() result = core.publish_parts(string, writer=w)['fragment'] return result # configuration app = Flask(__name__) app.config.from_envvar('CONF') mail = Mail(app) @app.template_filter('shortify') def shortify(string): soup = BeautifulSoup(string) try: return soup("p")[0].get_text()[:50] except IndexError: return string @app.template_filter('format_date') def format_date(date_object, formatstr=u"%a %d %b %Y à %Hh%M"): if not date_object: return "" formatstr = formatstr.encode("utf8") return date_object.replace(tzinfo=timezone('utc')). \ astimezone(timezone(session['timezone'])).strftime(formatstr).decode("utf8") @app.template_filter('format_ago') def format_ago(date_object, formatstr): if not date_object: return "" formatstr = formatstr.encode("utf8") readable = date_object.replace(tzinfo=timezone('utc')). \ astimezone(timezone(session['timezone'])).strftime(formatstr) iso_format = date_object.strftime('%Y-%m-%dT%H:%M:%SZ') return '{1}'.\ format(iso_format, readable).decode("utf8") @app.template_filter('format_rfc2822') def format_rfc2822(date_object): timestamp = time.mktime(date_object.timetuple()) return utils.formatdate(timestamp) @app.template_filter('pluralize') def pluralize(word, count, plural=None): if count == 0: return "Aucun {0}".format(word) elif count == 1: return "1 {0}".format(word) elif plural: return "{0} {1}".format(count, plural) else: return "{0} {1}s".format(count, word) def query_db(stmt, one=False): db = db_session() cur = db.execute(stmt) rv = cur.fetchone() if one else cur.fetchall() cur.close() return rv @app.teardown_appcontext def shutdown_session(exception=None): db_session.remove() def get_metadata(): return MetaData(bind=engine) def login_required(f): @wraps(f) def decorated_function(*args, **kwargs): if 'user_name' not in session: return redirect(url_for('login', next=request.url)) return f(*args, **kwargs) return decorated_function @app.route('/') @app.route('/news/') @login_required def list_news(): metadata = get_metadata() users = Table('users', metadata, autoload=True) news = Table('news', metadata, autoload=True) comments = Table('comments', metadata, autoload=True) stmt = select([news, users.c.user_name, func.count(comments.c.id).label('ncomments')]).\ select_from(news.outerjoin(users).outerjoin(comments, comments.c.news_id==news.c.id)).\ group_by(news.c.id).order_by(news.c.date.desc()) list_news = query_db(stmt) stmt = select([comments]).select_from(comments.outerjoin(users)).\ order_by(comments.c.date.desc()).limit(5) list_comments = query_db(stmt) stmt = select([users]).order_by(users.c.last_seen.desc()) list_users = query_db(stmt) return render_template("news/list.html", news=list_news, comments=list_comments, users=list_users) @app.route('/news/add/', methods=['GET', 'POST']) @login_required def add_news(): if request.method == 'POST': content = request.form['content'] content_cache = rstify(content) if 'Add' in request.form: metadata = get_metadata() users = Table('users', metadata, autoload=True) news = Table('news', metadata, autoload=True) comments = Table('comments', metadata, autoload=True) ins = news.insert().values(title = request.form['title'], content = content, content_cache = content_cache, user_id = session['user_id']) db = db_session() result = db.execute(ins) news_id = result.inserted_primary_key[0] db.commit() # send email #emails = query_db(db, "SELECT email from users where notify=1") emails = None #emails = [email["email"] for email in emails] if emails: message = Message(request.form['title'], sender="news.horel@gmail.com") message.html = content_cache url = url_for('show_news', news_id=news_id, _external=True) message.html += "

Vous pouvez "\ "Lire cette nouvelle sur le site de la famille.

".\ format(url) message.recipients = emails mail.send(message) return redirect(url_for('show_news', news_id=news_id)) else: news = {'content': content,'content_cache': content_cache, 'title': request.form['title']} return render_template("news/preview.html", news=news) elif request.method == 'GET': return render_template("news/add.html") @app.route('/news//', methods=['GET', 'POST']) @login_required def show_news(news_id): metadata = get_metadata() users = Table('users', metadata, autoload=True) news = Table('news', metadata, autoload=True) comments = Table('comments', metadata, autoload=True) stmt = select([news,users.c.user_name]).select_from(news.outerjoin(users)).\ where(news.c.id == news_id) news_content = query_db(stmt, True) if request.method == 'GET': stmt = select([comments, users.c.user_name]).\ select_from(comments.outerjoin(users)).\ where(comments.c.news_id == news_id).order_by(comments.c.date) list_comments = query_db(stmt) return render_template("news/show.html", news=news_content, comments=list_comments) elif request.method == 'POST': content = request.form['content'] ins = comments.insert().values(user_id=session['user_id'], content=content, news_id=news_id, content_cache = rstify(content)) db = db_session() db.execute(ins) db.commit() return redirect(url_for('show_news', news_id=news_id)) @app.route('/news//edit', methods=['GET', 'POST']) @login_required def edit_news(news_id): metadata = get_metadata() news = Table('news', metadata, autoload = True) if request.method == 'GET': stmt = select([news]).where(news.c.id = news_id) news = query_db(stmt, True) if news["user_id"] == session['user_id']: return render_template('news/add.html', news=news) elif request.method == 'POST': stmt = news.update().where(news.c.id = news_id).\ values(title = request.form['title'], content_cache = rstify(request.form['content']), content = request.form['content']) db = db_session() db.execute(stmt) db.commit() return redirect(url_for('show_news', news_id=news_id)) @app.route('/user//') @login_required def view_user(user_id): metadata = get_metadata() users = Table('users', metadata, autoload = True) stmt = select([users]).where(users.c.id = user_id) user = query_db(stmt, True) return render_template("user/show.html", user=user) @app.route('/user/edit/', methods=['GET', 'POST']) @login_required def edit_user(): db = get_db() if request.method == 'GET': user = query_db(db, 'SELECT * FROM users WHERE id= ?', (session['user_id'],), True) user = {k: user[k] for k in user.keys() if user[k]} return render_template("user/edit.html", user=user) elif request.method == 'POST': result = {} try: if request.form['password'] == request.form['password_confirm']: result['password'] = hashlib.md5(request.form['password']).hexdigest() else: error = u"Les deux mots de passe ne coïncident pas" return render_template("user/edit.html", user=request.form, error=error) except KeyError: pass args = tuple(request.form[key] for key in \ ['email', 'phone', 'birthday', 'nameday', 'address_line1', \ 'address_line2', 'address_city_line', 'timezone']) args += ("notify" in request.form, session['user_id']) sqlstr = "UPDATE users SET email= ?, phone=?, birthday=?, nameday=?," \ "address_line1=?, address_line2=?, address_city_line=?, timezone=?, notify=? " \ "where id=?" db.execute(sqlstr, args) db.commit() session["timezone"] = request.form["timezone"] return redirect(url_for('view_user', user_id=session['user_id'])) @app.route('/login/', methods=['GET', 'POST']) def login(): if 'user_name' in session: return redirect(url_for('list_news')) error = None if request.method == 'POST': metadata = get_metadata() users = Table('users', metadata, autoload=True) username = request.form['username'] password = hashlib.md5(request.form['password']).hexdigest() user = users.select(users.c.user_name == username).execute().fetchone() if user: if user['password'] == password: session['user_name'] = user['user_name'] session['user_id'] = user['id'] session['timezone'] = user['timezone'] or "UTC" stmt = users.update().where(users.c.id == user['id']).\ values(last_seen=datetime.utcnow()) db_session.execute(stmt) db_session.commit() return redirect(url_for('list_news')) else: error = u'Mot de passe incorrect' else: error = u'Utilisateur non enregistré' return render_template('login.html', error=error) @app.route('/logout/') @login_required def logout(): session.pop('user_name', None) session.pop('user_id', None) return redirect(url_for('login')) @app.route('/rss.xml') def rss(): db = get_db() news = query_db(db, "SELECT * FROM news LEFT JOIN users ON " "news.user_id=users.id ORDER BY news.date desc") return render_template('rss.xml', news=news) if __name__=="__main__": app.run()