]> ToastFreeware Gitweb - philipp/winterrodeln/wradmin.git/blob - wradmin/__init__.py
Prepare to restrict access to administrators
[philipp/winterrodeln/wradmin.git] / wradmin / __init__.py
1 from flask import Flask, send_from_directory, abort, g, render_template, request, redirect, url_for, flash, \
2     session, current_app
3 from sqlalchemy.engine import create_engine
4 import wradmin.model
5 import wradmin.template_helper
6 from wradmin.controllers.rodelbahn import RodelbahnController
7 from wradmin.controllers.gasthaus import GasthausController
8 from wradmin.controllers.bericht import BerichtController
9 from wradmin.controllers.coordtool import CoordtoolController
10 from wradmin.auth import password_is_correct
11 from wradmin.auth.forms import LoginForm
12 from flask_login import LoginManager, current_user, login_required, login_user, logout_user
13 from flask_principal import Principal, Permission, RoleNeed, identity_changed, identity_loaded, Identity, \
14     AnonymousIdentity, UserNeed
15
16
17 app = Flask(__name__)
18 app.config.from_envvar('WRADMIN_SETTINGS')
19 wradmin.model.init_model(create_engine(app.config['DATABASE_URI']))
20 app.jinja_env.globals.update(h=wradmin.template_helper.PylonsHelper())
21 login_manager = LoginManager(app)
22 login_manager.login_view = "login"
23 principals = Principal(app)
24 admin_permission = Permission(RoleNeed('admin'))
25
26
27 @app.before_request
28 def _before_request():
29     g.user = current_user
30
31
32 @app.teardown_appcontext
33 def remove_db_session(error):
34     """Removes the database session at the end of the request."""
35     wradmin.model.meta.Session.remove()
36
37
38 @app.route("/")
39 def index():
40     return render_template('index.html')
41
42
43 @app.route("/rodelbahn/list")
44 @login_required
45 def rodelbahn_list():
46     return RodelbahnController().list()
47
48
49 @app.route("/rodelbahn/view/<int:id>")
50 @admin_permission.require()
51 def rodelbahn_view(id):
52     return RodelbahnController().view(id)
53
54
55 @app.route("/rodelbahn/update")
56 @admin_permission.require()
57 def rodelbahn_update():
58     return RodelbahnController().update()
59
60
61 @app.route("/rodelbahn/update_regioncache")
62 @login_required
63 def rodelbahn_update_regioncache():
64     return RodelbahnController().update_regioncache()
65
66
67 @app.route("/rodelbahn/update_mapcache")
68 @login_required
69 def rodelbahn_update_mapcache():
70     return RodelbahnController().update_mapcache()
71
72
73 @app.route("/bericht/list")
74 @admin_permission.require()
75 def bericht_list():
76     return BerichtController().list()
77
78
79 @app.route("/bericht/view/<int:id>")
80 @admin_permission.require()
81 def bericht_view(id):
82     return BerichtController().view(id)
83
84
85 @app.route("/bericht/change_date_invalid/<int:id>", methods=['POST'])
86 @admin_permission.require()
87 def bericht_change_date_invalid(id):
88     return BerichtController().change_date_invalid(id)
89
90
91 @app.route("/bericht/update_reportcache")
92 @login_required
93 def bericht_update_reportcache():
94     return BerichtController().update_reportcache()
95
96
97 @app.route("/gasthaus/list")
98 @login_required
99 def gasthaus_list():
100     return GasthausController().list()
101
102
103 @app.route("/gasthaus/view/<int:id>")
104 @login_required
105 def gasthaus_view(id):
106     return GasthausController().view(id)
107
108
109 @app.route("/gasthaus/update")
110 @login_required
111 def gasthaus_update():
112     return GasthausController().update()
113
114
115 @app.route("/coordtool/index")
116 @login_required
117 def coordtool_index():
118     return CoordtoolController().index()
119
120
121 @app.route("/coordtool/convert", methods=['POST'])
122 @login_required
123 def coordtool_convert():
124     return CoordtoolController().convert()
125
126
127 @app.route("/login", methods=['GET', 'POST'])
128 def login():
129     form = LoginForm()
130     if form.validate_on_submit():
131         user = wradmin.model.meta.Session.query(wradmin.model.MwUser).filter_by(user_name=form.user_name.data).first()
132         if user is not None and password_is_correct(form.password.data, user.user_password.decode()):
133             login_user(user, form.remember_me.data)
134             identity_changed.send(current_app._get_current_object(), identity=Identity(user.get_id()))
135             next = request.args.get('next')
136             if next is None or not next.startswith('/'):
137                 next = url_for('index')
138             flash('Sie sind nun angemeldet.')
139             return redirect(next)
140         flash('Ungülter Benutzername oder ungültiges Passwort.')
141     return render_template('auth/login.html', form=form)
142
143
144 @app.route("/logout")
145 def logout():
146     logout_user()
147     for key in ('identity.name', 'identity.auth_type'):
148         session.pop(key, None)
149     identity_changed.send(current_app._get_current_object(), identity=AnonymousIdentity())
150     flash('Sie wurden ausgeloggt.')
151     return redirect(url_for('index'))
152
153
154 @login_manager.user_loader
155 def user_loader(user_id):
156     return wradmin.model.meta.Session.query(wradmin.model.MwUser).get(user_id)
157
158
159 @identity_loaded.connect_via(app)
160 def on_identity_loaded(sender, identity):
161     identity.user = current_user
162     user_id = current_user.get_id()
163     if user_id is not None:
164         identity.provides.add(UserNeed(user_id))
165         if current_user.user_name == b'Philipp':
166             identity.provides.add(RoleNeed('admin'))