# -*- coding: utf-8 -*- import sqlite3 #all the imports from flask import Flask, request, session, g, redirect, url_for, \ abort, render_template, flash, _app_ctx_stack from functools import wraps import hashlib from pytz import timezone import pytz from docutils import core from docutils.writers.html4css1 import Writer from datetime import datetime import time from email import utils from bs4 import BeautifulSoup from flask_mail import Mail, Message import locale locale.setlocale(locale.LC_ALL, 'fr_FR.UTF-8') def rstify(string): w = Writer() result = core.publish_parts(string, writer=w)['fragment'] return result # configuration app = Flask(__name__) app.config.from_envvar('CONF') mail = Mail(app) @app.template_filter('shortify') def shortify(string): soup = BeautifulSoup(string) try: return soup("p")[0].get_text()[:50] except IndexError: return string @app.template_filter('format_date') def format_date(date_object, format=u"%a %d %b %Y à %Hh%M"): if not date_object: return "" format = format.encode("utf8") return date_object.replace(tzinfo=timezone('utc')). \ astimezone(timezone(session['timezone'])).strftime(format).decode("utf8") @app.template_filter('format_ago') def format_ago(date_object, format): if not date_object: return "" format = format.encode("utf8") readable = date_object.replace(tzinfo=timezone('utc')). \ astimezone(timezone(session['timezone'])).strftime(format) iso_format = date_object.strftime('%Y-%m-%dT%H:%M:%SZ') return '{1}'. \ format(iso_format, readable).decode("utf8") @app.template_filter('format_rfc2822') def format_rfc2822(date_object): timestamp = time.mktime(date_object.timetuple()) return utils.formatdate(timestamp) @app.template_filter('pluralize') def pluralize(word, count, plural=None): if count == 0: return "Aucun {0}".format(word) elif count == 1: return "1 {0}".format(word) elif plural: return "{0} {1}".format(count, plural) else: return "{0} {1}s".format(count, word) def query_db(query, args=(), one=False): cur = g.db.execute(query, args) rv = cur.fetchone() if one else cur.fetchall() cur.close() return rv @app.before_request def before_request(): conn = sqlite3.connect(app.config['DATABASE'], detect_types=sqlite3.PARSE_DECLTYPES) conn.row_factory = sqlite3.Row g.db = conn g.timezone = pytz.common_timezones @app.teardown_appcontext def close_db_connection(exception): """Closes the database again at the end of the request.""" g.db.close() def login_required(f): @wraps(f) def decorated_function(*args, **kwargs): if 'user_name' not in session: return redirect(url_for('login', next=request.url)) return f(*args, **kwargs) return decorated_function @app.route('/') @app.route('/news/') @login_required def list_news(): news = query_db("SELECT news.*, users.user_name, count(comments.id) as ncomments FROM news " "LEFT JOIN users ON news.user_id = users.id " "LEFT JOIN comments ON news.id=comments.news_id GROUP BY news.id " "ORDER BY news.date DESC") comments = query_db("SELECT * from comments LEFT JOIN users " "ON comments.user_id = users.id ORDER BY date DESC LIMIT 5") users = query_db("SELECT * from users ORDER BY last_seen DESC") return render_template("news/list.html", news=news, comments=comments, users=users) @app.route('/news/add/', methods=['GET', 'POST']) @login_required def add_news(): if request.method == 'POST': content = request.form['content'] content_cache = rstify(content) if 'Add' in request.form: cur = g.db.execute("INSERT INTO news " "('title', 'content', 'user_id', 'content_cache') " "VALUES (?, ?, ?, ?)", (request.form['title'], content, session['user_id'], content_cache)) news_id = cur.lastrowid g.db.commit() # send email emails = query_db("SELECT email from users where notify=1") emails = [email["email"] for email in emails] if emails: message = Message(request.form['title'], sender="news.horel@gmail.com") message.html = content_cache url = url_for('show_news', news_id=news_id, _external=True) message.html += "

Vous pouvez "\ "Lire cette nouvelle sur le site de la famille.

".\ format(url) message.recipients = emails mail.send(message) return redirect(url_for('show_news', news_id=news_id)) else: news = {'content': content,'content_cache': content_cache, 'title': request.form['title']} return render_template("news/preview.html", news=news) elif request.method == 'GET': return render_template("news/add.html") @app.route('/news//', methods=['GET', 'POST']) @login_required def show_news(news_id): news = query_db("SELECT * FROM news LEFT JOIN users " "ON news.user_id = users.id " "WHERE news.id = ?", (news_id,), True) if request.method == 'GET': comments = query_db("SELECT * FROM comments LEFT JOIN users " "ON comments.user_id = users.id " "WHERE comments.news_id = ? " "ORDER BY date", (news_id,)) return render_template("news/show.html", news=news, comments=comments) elif request.method == 'POST': user_id = session['user_id'] content = request.form['content'] content_cache = rstify(content) g.db.execute("INSERT INTO comments " "('user_id', 'content', 'news_id', 'content_cache') " "VALUES (?, ?, ?, ?)", (user_id, content, news_id, content_cache)) g.db.commit() return redirect(url_for('show_news', news_id=news_id)) @app.route('/news//edit', methods=['GET', 'POST']) @login_required def edit_news(news_id): if request.method == 'GET': news = query_db("SELECT * from news WHERE news.id = ?", (news_id,), True) if news["user_id"] == session['user_id']: return render_template('news/add.html', news=news) elif request.method == 'POST': title = request.form['title'] content = request.form['content'] content_cache = rstify(content) g.db.execute("UPDATE news SET 'title'=?, 'content'=?, 'content_cache'=? " "WHERE news.id =?", (title, content, content_cache, news_id)) g.db.commit() return redirect(url_for('show_news', news_id=news_id)) @app.route('/user//') @login_required def view_user(user_id): user = query_db('SELECT * FROM users WHERE id= ?', (user_id,), True) return render_template("user/show.html", user=user) @app.route('/user/edit/', methods=['GET', 'POST']) @login_required def edit_user(): if request.method == 'GET': user = query_db('SELECT * FROM users WHERE id= ?', (session['user_id'],), True) user = {k: user[k] for k in user.keys() if user[k]} return render_template("user/edit.html", user=user) elif request.method == 'POST': result = {} try: if request.form['password'] == request.form['password_confirm']: result['password'] = hashlib.md5(request.form['password']).hexdigest() else: error = u"Les deux mots de passe ne coïncident pas" return render_template("user/edit.html", user=request.form, error=error) except KeyError: pass args = tuple(request.form[key] for key in \ ['email', 'phone', 'birthday', 'nameday', 'address_line1', \ 'address_line2', 'address_city_line', 'timezone']) args += ("notify" in request.form, session['user_id']) sqlstr = "UPDATE users SET email= ?, phone=?, birthday=?, nameday=?," \ "address_line1=?, address_line2=?, address_city_line=?, timezone=?, notify=? " \ "where id=?" g.db.execute(sqlstr, args) g.db.commit() session["timezone"] = request.form["timezone"] return redirect(url_for('view_user', user_id=session['user_id'])) @app.route('/login/', methods=['GET', 'POST']) def login(): if 'user_name' in session: return redirect(url_for('list_news')) error = None if request.method == 'POST': username = request.form['username'] password = hashlib.md5(request.form['password']).hexdigest(); user = query_db('select * from users where user_name = ?', (username,), True) if user: if user['password'] == password: session['user_name'] = user['user_name'] session['user_id'] = user['id'] session['timezone'] = user['timezone'] or "UTC" g.db.execute("UPDATE users SET last_seen=? WHERE id=?", (datetime.utcnow(),session['user_id'])) g.db.commit() return redirect(url_for('list_news')) else: error = u'Mot de passe incorrect' else: error = u'Utilisateur non enregistré' return render_template('login.html', error=error) @app.route('/logout/') @login_required def logout(): session.pop('user_name', None) session.pop('user_id', None) return redirect(url_for('login')) @app.route('/rss.xml') def rss(): news = query_db("SELECT * FROM news LEFT JOIN users ON " "news.user_id=users.id ORDER BY news.date desc") return render_template('rss.xml', news=news) if __name__=="__main__": app.run()