login.py
169 lines
| 6.2 KiB
| text/x-python
|
PythonLexer
r861 | # -*- coding: utf-8 -*- | |||
""" | ||||
rhodecode.controllers.login | ||||
~~~~~~~~~~~~~~~~~~~~~~~~~~~ | ||||
Login controller for rhodeocode | ||||
r1203 | ||||
r861 | :created_on: Apr 22, 2010 | |||
:author: marcink | ||||
r1824 | :copyright: (C) 2010-2012 Marcin Kuzminski <marcin@python-works.com> | |||
r861 | :license: GPLv3, see COPYING for more details. | |||
""" | ||||
r1206 | # This program is free software: you can redistribute it and/or modify | |||
# it under the terms of the GNU General Public License as published by | ||||
# the Free Software Foundation, either version 3 of the License, or | ||||
# (at your option) any later version. | ||||
r1203 | # | |||
r547 | # This program is distributed in the hope that it will be useful, | |||
# but WITHOUT ANY WARRANTY; without even the implied warranty of | ||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||||
# GNU General Public License for more details. | ||||
r1203 | # | |||
r547 | # You should have received a copy of the GNU General Public License | |||
r1206 | # along with this program. If not, see <http://www.gnu.org/licenses/>. | |||
r547 | ||||
r861 | import logging | |||
import formencode | ||||
r547 | from formencode import htmlfill | |||
r861 | ||||
from pylons.i18n.translation import _ | ||||
from pylons.controllers.util import abort, redirect | ||||
r547 | from pylons import request, response, session, tmpl_context as c, url | |||
r861 | ||||
import rhodecode.lib.helpers as h | ||||
r547 | from rhodecode.lib.auth import AuthUser, HasPermissionAnyDecorator | |||
from rhodecode.lib.base import BaseController, render | ||||
r1400 | from rhodecode.model.db import User | |||
r547 | from rhodecode.model.forms import LoginForm, RegisterForm, PasswordResetForm | |||
r629 | from rhodecode.model.user import UserModel | |||
r1731 | from rhodecode.model.meta import Session | |||
r861 | ||||
r547 | ||||
log = logging.getLogger(__name__) | ||||
r1212 | ||||
r547 | class LoginController(BaseController): | |||
def __before__(self): | ||||
super(LoginController, self).__before__() | ||||
def index(self): | ||||
r1628 | # redirect if already logged in | |||
r547 | c.came_from = request.GET.get('came_from', None) | |||
r636 | ||||
r1121 | if self.rhodecode_user.is_authenticated \ | |||
and self.rhodecode_user.username != 'default': | ||||
r673 | ||||
r636 | return redirect(url('home')) | |||
r547 | if request.POST: | |||
r1718 | # import Login Form validator class | |||
r547 | login_form = LoginForm() | |||
try: | ||||
c.form_result = login_form.to_python(dict(request.POST)) | ||||
r1628 | # form checks for username/password, now we're authenticated | |||
r547 | username = c.form_result['username'] | |||
r1530 | user = User.get_by_username(username, case_insensitive=True) | |||
r1117 | auth_user = AuthUser(user.user_id) | |||
auth_user.set_authenticated() | ||||
r1718 | cs = auth_user.get_cookie_store() | |||
session['rhodecode_user'] = cs | ||||
Matt Zuba
|
r1802 | # If they want to be remembered, update the cookie | ||
if c.form_result['remember'] is not False: | ||||
session.cookie_expires = False | ||||
r2045 | session._set_cookie_values() | |||
Matt Zuba
|
r1802 | session._update_cookie_out() | ||
r547 | session.save() | |||
r636 | ||||
r1718 | log.info('user %s is now authenticated and stored in ' | |||
'session, session attrs %s' % (username, cs)) | ||||
r547 | user.update_lastlogin() | |||
r1749 | Session.commit() | |||
r1818 | ||||
r547 | if c.came_from: | |||
return redirect(c.came_from) | ||||
else: | ||||
r636 | return redirect(url('home')) | |||
r564 | except formencode.Invalid, errors: | |||
r547 | return htmlfill.render( | |||
render('/login.html'), | ||||
defaults=errors.value, | ||||
errors=errors.error_dict or {}, | ||||
prefix_error=False, | ||||
encoding="UTF-8") | ||||
r636 | ||||
r547 | return render('/login.html') | |||
r636 | ||||
r547 | @HasPermissionAnyDecorator('hg.admin', 'hg.register.auto_activate', | |||
'hg.register.manual_activate') | ||||
def register(self): | ||||
c.auto_active = False | ||||
r1530 | for perm in User.get_by_username('default').user_perms: | |||
r547 | if perm.permission.permission_name == 'hg.register.auto_activate': | |||
c.auto_active = True | ||||
break | ||||
r636 | ||||
r547 | if request.POST: | |||
r636 | ||||
r547 | register_form = RegisterForm()() | |||
try: | ||||
form_result = register_form.to_python(dict(request.POST)) | ||||
form_result['active'] = c.auto_active | ||||
r1749 | UserModel().create_registration(form_result) | |||
r549 | h.flash(_('You have successfully registered into rhodecode'), | |||
r636 | category='success') | |||
r1749 | Session.commit() | |||
r547 | return redirect(url('login_home')) | |||
r636 | ||||
r564 | except formencode.Invalid, errors: | |||
r547 | return htmlfill.render( | |||
render('/register.html'), | ||||
defaults=errors.value, | ||||
errors=errors.error_dict or {}, | ||||
prefix_error=False, | ||||
encoding="UTF-8") | ||||
r636 | ||||
r547 | return render('/register.html') | |||
def password_reset(self): | ||||
if request.POST: | ||||
password_reset_form = PasswordResetForm()() | ||||
try: | ||||
form_result = password_reset_form.to_python(dict(request.POST)) | ||||
r1749 | UserModel().reset_password_link(form_result) | |||
r1417 | h.flash(_('Your password reset link was sent'), | |||
r636 | category='success') | |||
r547 | return redirect(url('login_home')) | |||
r636 | ||||
r564 | except formencode.Invalid, errors: | |||
r547 | return htmlfill.render( | |||
render('/password_reset.html'), | ||||
defaults=errors.value, | ||||
errors=errors.error_dict or {}, | ||||
prefix_error=False, | ||||
encoding="UTF-8") | ||||
r636 | ||||
r547 | return render('/password_reset.html') | |||
r636 | ||||
r1417 | def password_reset_confirmation(self): | |||
if request.GET and request.GET.get('key'): | ||||
try: | ||||
user = User.get_by_api_key(request.GET.get('key')) | ||||
data = dict(email=user.email) | ||||
r1749 | UserModel().reset_password(data) | |||
r1417 | h.flash(_('Your password reset was successful, ' | |||
'new password has been sent to your email'), | ||||
category='success') | ||||
except Exception, e: | ||||
log.error(e) | ||||
return redirect(url('reset_password')) | ||||
return redirect(url('login_home')) | ||||
r547 | def logout(self): | |||
Matt Zuba
|
r1802 | session.delete() | ||
log.info('Logging out and deleting session for user') | ||||
r636 | redirect(url('home')) | |||