]> git.lizzy.rs Git - cheatdb.git/blob - app/blueprints/packages/packages.py
464449b54ee0c83f87a4f5f80c3e5b8ee072a4be
[cheatdb.git] / app / blueprints / packages / packages.py
1 # Content DB
2 # Copyright (C) 2018  rubenwardy
3 #
4 # This program is free software: you can redistribute it and/or modify
5 # it under the terms of the GNU General Public License as published by
6 # the Free Software Foundation, either version 3 of the License, or
7 # (at your option) any later version.
8 #
9 # This program is distributed in the hope that it will be useful,
10 # but WITHOUT ANY WARRANTY; without even the implied warranty of
11 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12 # GNU General Public License for more details.
13 #
14 # You should have received a copy of the GNU General Public License
15 # along with this program.  If not, see <https://www.gnu.org/licenses/>.
16
17
18 from flask import render_template, abort, request, redirect, url_for, flash
19 from flask_user import current_user
20 import flask_menu as menu
21
22 from . import bp
23
24 from app.models import *
25 from app.querybuilder import QueryBuilder
26 from app.tasks.importtasks import importRepoScreenshot, updateMetaFromRelease
27 from app.utils import *
28
29 from flask_wtf import FlaskForm
30 from wtforms import *
31 from wtforms.validators import *
32 from wtforms.ext.sqlalchemy.fields import QuerySelectField, QuerySelectMultipleField
33 from sqlalchemy import or_, func
34 from sqlalchemy.orm import joinedload, subqueryload
35
36 from celery import uuid
37
38
39 @menu.register_menu(bp, ".mods", "Mods", order=11, endpoint_arguments_constructor=lambda: { 'type': 'mod' })
40 @menu.register_menu(bp, ".games", "Games", order=12, endpoint_arguments_constructor=lambda: { 'type': 'game' })
41 @menu.register_menu(bp, ".txp", "Texture Packs", order=13, endpoint_arguments_constructor=lambda: { 'type': 'txp' })
42 @menu.register_menu(bp, ".random", "Random", order=14, endpoint_arguments_constructor=lambda: { 'random': '1', 'lucky': '1' })
43 @bp.route("/packages/")
44 def list_all():
45         qb    = QueryBuilder(request.args)
46         query = qb.buildPackageQuery()
47         title = qb.title
48
49         query = query.options( \
50                         joinedload(Package.license), \
51                         joinedload(Package.media_license), \
52                         subqueryload(Package.tags))
53
54         if qb.lucky:
55                 package = query.first()
56                 if package:
57                         return redirect(package.getDetailsURL())
58
59                 topic = qb.buildTopicQuery().first()
60                 if qb.search and topic:
61                         return redirect("https://forum.minetest.net/viewtopic.php?t=" + str(topic.topic_id))
62
63         page  = get_int_or_abort(request.args.get("page"), 1)
64         num   = min(40, get_int_or_abort(request.args.get("n"), 100))
65         query = query.paginate(page, num, True)
66
67         search = request.args.get("q")
68         type_name = request.args.get("type")
69
70         authors = []
71         if search:
72                 authors = User.query \
73                         .filter(or_(*[func.lower(User.username) == name.lower().strip() for name in search.split(" ")])) \
74                         .all()
75
76                 authors = [(author.username, search.lower().replace(author.username.lower(), "")) for author in authors]
77
78         topics = None
79         if qb.search and not query.has_next:
80                 qb.show_discarded = True
81                 topics = qb.buildTopicQuery().all()
82
83         def url_builder(page):
84                 args = dict(request.args)
85                 args["page"] = page
86                 return url_for("packages.list_all", **args)
87
88         tags = Tag.query.all()
89         return render_template("packages/list.html", \
90                         title=title, packages=query.items, topics=topics, \
91                         query=search, tags=tags, type=type_name, \
92                         authors=authors, packages_count=query.total, \
93                         pagination=query, url_builder=url_builder)
94
95
96 def getReleases(package):
97         if package.checkPerm(current_user, Permission.MAKE_RELEASE):
98                 return package.releases.limit(5)
99         else:
100                 return package.releases.filter_by(approved=True).limit(5)
101
102
103 @bp.route("/packages/<author>/<name>/")
104 @is_package_page
105 def view(package):
106         alternatives = None
107         if package.type == PackageType.MOD:
108                 alternatives = Package.query \
109                         .filter_by(name=package.name, type=PackageType.MOD, soft_deleted=False) \
110                         .filter(Package.id != package.id) \
111                         .order_by(db.desc(Package.score)) \
112                         .all()
113
114
115         show_similar_topics = current_user == package.author or \
116                         package.checkPerm(current_user, Permission.APPROVE_NEW)
117
118         similar_topics = None if not show_similar_topics else \
119                         ForumTopic.query \
120                                 .filter_by(name=package.name) \
121                                 .filter(ForumTopic.topic_id != package.forums) \
122                                 .filter(~ db.exists().where(Package.forums==ForumTopic.topic_id)) \
123                                 .order_by(db.asc(ForumTopic.name), db.asc(ForumTopic.title)) \
124                                 .all()
125
126         releases = getReleases(package)
127         requests = [r for r in package.requests if r.status == 0]
128
129         review_thread = package.review_thread
130         if review_thread is not None and not review_thread.checkPerm(current_user, Permission.SEE_THREAD):
131                 review_thread = None
132
133         topic_error = None
134         topic_error_lvl = "warning"
135         if not package.approved and package.forums is not None:
136                 errors = []
137                 if Package.query.filter_by(forums=package.forums, soft_deleted=False).count() > 1:
138                         errors.append("<b>Error: Another package already uses this forum topic!</b>")
139                         topic_error_lvl = "danger"
140
141                 topic = ForumTopic.query.get(package.forums)
142                 if topic is not None:
143                         if topic.author != package.author:
144                                 errors.append("<b>Error: Forum topic author doesn't match package author.</b>")
145                                 topic_error_lvl = "danger"
146
147                         if topic.wip:
148                                 errors.append("Warning: Forum topic is in WIP section, make sure package meets playability standards.")
149                 elif package.type != PackageType.TXP:
150                         errors.append("Warning: Forum topic not found. This may happen if the topic has only just been created.")
151
152                 topic_error = "<br />".join(errors)
153
154
155         threads = Thread.query.filter_by(package_id=package.id, review_id=None)
156         if not current_user.is_authenticated:
157                 threads = threads.filter_by(private=False)
158         elif not current_user.rank.atLeast(UserRank.EDITOR) and not current_user == package.author:
159                 threads = threads.filter(or_(Thread.private == False, Thread.author == current_user))
160
161         has_review = current_user.is_authenticated and PackageReview.query.filter_by(package=package, author=current_user).count() > 0
162
163         return render_template("packages/view.html", \
164                         package=package, releases=releases, requests=requests, \
165                         alternatives=alternatives, similar_topics=similar_topics, \
166                         review_thread=review_thread, topic_error=topic_error, topic_error_lvl=topic_error_lvl, \
167                         threads=threads.all(), has_review=has_review)
168
169
170 @bp.route("/packages/<author>/<name>/download/")
171 @is_package_page
172 def download(package):
173         release = package.getDownloadRelease()
174
175         if release is None:
176                 if "application/zip" in request.accept_mimetypes and \
177                                 not "text/html" in request.accept_mimetypes:
178                         return "", 204
179                 else:
180                         flash("No download available.", "danger")
181                         return redirect(package.getDetailsURL())
182         else:
183                 return redirect(release.getDownloadURL(), code=302)
184
185
186 class PackageForm(FlaskForm):
187         name          = StringField("Name (Technical)", [InputRequired(), Length(1, 100), Regexp("^[a-z0-9_]+$", 0, "Lower case letters (a-z), digits (0-9), and underscores (_) only")])
188         title         = StringField("Title (Human-readable)", [InputRequired(), Length(3, 100)])
189         short_desc     = StringField("Short Description (Plaintext)", [InputRequired(), Length(1,200)])
190         desc          = TextAreaField("Long Description (Markdown)", [Optional(), Length(0,10000)])
191         type          = SelectField("Type", [InputRequired()], choices=PackageType.choices(), coerce=PackageType.coerce, default=PackageType.MOD)
192         license       = QuerySelectField("License", [DataRequired()], allow_blank=True, query_factory=lambda: License.query.order_by(db.asc(License.name)), get_pk=lambda a: a.id, get_label=lambda a: a.name)
193         media_license = QuerySelectField("Media License", [DataRequired()], allow_blank=True, query_factory=lambda: License.query.order_by(db.asc(License.name)), get_pk=lambda a: a.id, get_label=lambda a: a.name)
194         provides_str  = StringField("Provides (mods included in package)", [Optional()])
195         tags          = QuerySelectMultipleField('Tags', query_factory=lambda: Tag.query.order_by(db.asc(Tag.name)), get_pk=lambda a: a.id, get_label=lambda a: a.title)
196         harddep_str   = StringField("Hard Dependencies", [Optional()])
197         softdep_str   = StringField("Soft Dependencies", [Optional()])
198         repo          = StringField("VCS Repository URL", [Optional(), URL()], filters = [lambda x: x or None])
199         website       = StringField("Website URL", [Optional(), URL()], filters = [lambda x: x or None])
200         issueTracker  = StringField("Issue Tracker URL", [Optional(), URL()], filters = [lambda x: x or None])
201         forums        = IntegerField("Forum Topic ID", [Optional(), NumberRange(0,999999)])
202         submit        = SubmitField("Save")
203
204 @bp.route("/packages/new/", methods=["GET", "POST"])
205 @bp.route("/packages/<author>/<name>/edit/", methods=["GET", "POST"])
206 @login_required
207 def create_edit(author=None, name=None):
208         package = None
209         form = None
210         if author is None:
211                 form = PackageForm(formdata=request.form)
212                 author = request.args.get("author")
213                 if author is None or author == current_user.username:
214                         author = current_user
215                 else:
216                         author = User.query.filter_by(username=author).first()
217                         if author is None:
218                                 flash("Unable to find that user", "danger")
219                                 return redirect(url_for("packages.create_edit"))
220
221                         if not author.checkPerm(current_user, Permission.CHANGE_AUTHOR):
222                                 flash("Permission denied", "danger")
223                                 return redirect(url_for("packages.create_edit"))
224
225         else:
226                 package = getPackageByInfo(author, name)
227                 if not package.checkPerm(current_user, Permission.EDIT_PACKAGE):
228                         return redirect(package.getDetailsURL())
229
230                 author = package.author
231
232                 form = PackageForm(formdata=request.form, obj=package)
233
234         # Initial form class from post data and default data
235         if request.method == "GET":
236                 if package is None:
237                         form.name.data   = request.args.get("bname")
238                         form.title.data  = request.args.get("title")
239                         form.repo.data   = request.args.get("repo")
240                         form.forums.data = request.args.get("forums")
241                         form.license.data = None
242                         form.media_license.data = None
243                 else:
244                         form.harddep_str.data  = ",".join([str(x) for x in package.getSortedHardDependencies() ])
245                         form.softdep_str.data  = ",".join([str(x) for x in package.getSortedOptionalDependencies() ])
246                         form.provides_str.data = MetaPackage.ListToSpec(package.provides)
247                         form.tags.data         = list(package.tags)
248
249         if request.method == "POST" and form.validate():
250                 wasNew = False
251                 if not package:
252                         package = Package.query.filter_by(name=form["name"].data, author_id=author.id).first()
253                         if package is not None:
254                                 if package.soft_deleted:
255                                         Package.query.filter_by(name=form["name"].data, author_id=author.id).delete()
256                                 else:
257                                         flash("Package already exists!", "danger")
258                                         return redirect(url_for("packages.create_edit"))
259
260                         package = Package()
261                         package.author = author
262                         package.maintainers.append(author)
263                         wasNew = True
264
265                 elif package.approved and package.name != form.name.data and \
266                                 not package.checkPerm(current_user, Permission.CHANGE_NAME):
267                         flash("Unable to change package name", "danger")
268                         return redirect(url_for("packages.create_edit", author=author, name=name))
269
270                 else:
271                         msg = "Edited {}".format(package.title)
272
273                         addNotification(package.maintainers, current_user,
274                                         msg, package.getDetailsURL(), package)
275
276                         severity = AuditSeverity.NORMAL if current_user in package.maintainers else AuditSeverity.EDITOR
277                         addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
278
279                 form.populate_obj(package) # copy to row
280
281                 if package.type== PackageType.TXP:
282                         package.license = package.media_license
283
284                 mpackage_cache = {}
285                 package.provides.clear()
286                 mpackages = MetaPackage.SpecToList(form.provides_str.data, mpackage_cache)
287                 for m in mpackages:
288                         package.provides.append(m)
289
290                 Dependency.query.filter_by(depender=package).delete()
291                 deps = Dependency.SpecToList(package, form.harddep_str.data, mpackage_cache)
292                 for dep in deps:
293                         dep.optional = False
294                         db.session.add(dep)
295
296                 deps = Dependency.SpecToList(package, form.softdep_str.data, mpackage_cache)
297                 for dep in deps:
298                         dep.optional = True
299                         db.session.add(dep)
300
301                 if wasNew and package.type == PackageType.MOD and not package.name in mpackage_cache:
302                         m = MetaPackage.GetOrCreate(package.name, mpackage_cache)
303                         package.provides.append(m)
304
305                 package.tags.clear()
306                 for tag in form.tags.raw_data:
307                         package.tags.append(Tag.query.get(tag))
308
309                 db.session.commit() # save
310
311                 next_url = package.getDetailsURL()
312                 if wasNew and package.repo is not None:
313                         task = importRepoScreenshot.delay(package.id)
314                         next_url = url_for("tasks.check", id=task.id, r=next_url)
315
316                 if wasNew and ("WTFPL" in package.license.name or "WTFPL" in package.media_license.name):
317                         next_url = url_for("flatpage", path="help/wtfpl", r=next_url)
318
319                 return redirect(next_url)
320
321         package_query = Package.query.filter_by(approved=True, soft_deleted=False)
322         if package is not None:
323                 package_query = package_query.filter(Package.id != package.id)
324
325         enableWizard = name is None and request.method != "POST"
326         return render_template("packages/create_edit.html", package=package, \
327                         form=form, author=author, enable_wizard=enableWizard, \
328                         packages=package_query.all(), \
329                         mpackages=MetaPackage.query.order_by(db.asc(MetaPackage.name)).all())
330
331 @bp.route("/packages/<author>/<name>/approve/", methods=["POST"])
332 @login_required
333 @is_package_page
334 def approve(package):
335         if not package.checkPerm(current_user, Permission.APPROVE_NEW):
336                 flash("You don't have permission to do that.", "danger")
337
338         elif package.approved:
339                 flash("Package has already been approved", "danger")
340
341         else:
342                 package.approved = True
343
344                 screenshots = PackageScreenshot.query.filter_by(package=package, approved=False).all()
345                 for s in screenshots:
346                         s.approved = True
347
348                 msg = "Approved {}".format(package.title)
349                 addNotification(package.maintainers, current_user, msg, package.getDetailsURL(), package)
350                 severity = AuditSeverity.NORMAL if current_user == package.author else AuditSeverity.EDITOR
351                 addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
352                 db.session.commit()
353
354         return redirect(package.getDetailsURL())
355
356
357 @bp.route("/packages/<author>/<name>/remove/", methods=["GET", "POST"])
358 @login_required
359 @is_package_page
360 def remove(package):
361         if request.method == "GET":
362                 return render_template("packages/remove.html", package=package)
363
364         if "delete" in request.form:
365                 if not package.checkPerm(current_user, Permission.DELETE_PACKAGE):
366                         flash("You don't have permission to do that.", "danger")
367                         return redirect(package.getDetailsURL())
368
369                 package.soft_deleted = True
370
371                 url = url_for("users.profile", username=package.author.username)
372                 msg = "Deleted {}".format(package.title)
373                 addNotification(package.maintainers, current_user, msg, url, package)
374                 addAuditLog(AuditSeverity.EDITOR, current_user, msg, url)
375                 db.session.commit()
376
377                 flash("Deleted package", "success")
378
379                 return redirect(url)
380         elif "unapprove" in request.form:
381                 if not package.checkPerm(current_user, Permission.UNAPPROVE_PACKAGE):
382                         flash("You don't have permission to do that.", "danger")
383                         return redirect(package.getDetailsURL())
384
385                 package.approved = False
386
387                 msg = "Unapproved {}".format(package.title)
388                 addNotification(package.maintainers, current_user, msg, package.getDetailsURL(), package)
389                 addAuditLog(AuditSeverity.EDITOR, current_user, msg, package.getDetailsURL(), package)
390
391                 db.session.commit()
392
393                 flash("Unapproved package", "success")
394
395                 return redirect(package.getDetailsURL())
396         else:
397                 abort(400)
398
399
400
401 class PackageMaintainersForm(FlaskForm):
402         maintainers_str  = StringField("Maintainers (Comma-separated)", [Optional()])
403         submit        = SubmitField("Save")
404
405
406 @bp.route("/packages/<author>/<name>/edit-maintainers/", methods=["GET", "POST"])
407 @login_required
408 @is_package_page
409 def edit_maintainers(package):
410         if not package.checkPerm(current_user, Permission.EDIT_MAINTAINERS):
411                 flash("You do not have permission to edit maintainers", "danger")
412                 return redirect(package.getDetailsURL())
413
414         form = PackageMaintainersForm(formdata=request.form)
415         if request.method == "GET":
416                 form.maintainers_str.data = ", ".join([ x.username for x in package.maintainers if x != package.author ])
417
418         if request.method == "POST" and form.validate():
419                 usernames = [x.strip().lower() for x in form.maintainers_str.data.split(",")]
420                 users = User.query.filter(func.lower(User.username).in_(usernames)).all()
421
422                 for user in users:
423                         if not user in package.maintainers:
424                                 addNotification(user, current_user,
425                                                 "Added you as a maintainer of {}".format(package.title), package.getDetailsURL(), package)
426
427                 for user in package.maintainers:
428                         if user != package.author and not user in users:
429                                 addNotification(user, current_user,
430                                                 "Removed you as a maintainer of {}".format(package.title), package.getDetailsURL(), package)
431
432                 package.maintainers.clear()
433                 package.maintainers.extend(users)
434                 if package.author not in package.maintainers:
435                         package.maintainers.append(package.author)
436
437                 msg = "Edited {} maintainers".format(package.title)
438                 addNotification(package.author, current_user, msg, package.getDetailsURL(), package)
439                 severity = AuditSeverity.NORMAL if current_user == package.author else AuditSeverity.MODERATION
440                 addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
441
442                 db.session.commit()
443
444                 return redirect(package.getDetailsURL())
445
446         users = User.query.filter(User.rank >= UserRank.NEW_MEMBER).order_by(db.asc(User.username)).all()
447
448         return render_template("packages/edit_maintainers.html", \
449                         package=package, form=form, users=users)
450
451
452 @bp.route("/packages/<author>/<name>/remove-self-maintainer/", methods=["POST"])
453 @login_required
454 @is_package_page
455 def remove_self_maintainers(package):
456         if not current_user in package.maintainers:
457                 flash("You are not a maintainer", "danger")
458
459         elif current_user == package.author:
460                 flash("Package owners cannot remove themselves as maintainers", "danger")
461
462         else:
463                 package.maintainers.remove(current_user)
464
465                 addNotification(package.author, current_user,
466                                 "Removed themself as a maintainer of {}".format(package.title), package.getDetailsURL(), package)
467
468                 db.session.commit()
469
470         return redirect(package.getDetailsURL())
471
472
473 @bp.route("/packages/<author>/<name>/import-meta/", methods=["POST"])
474 @login_required
475 @is_package_page
476 def update_from_release(package):
477         if not package.checkPerm(current_user, Permission.REIMPORT_META):
478                 flash("You don't have permission to reimport meta", "danger")
479                 return redirect(package.getDetailsURL())
480
481         release = package.releases.first()
482         if not release:
483                 flash("Release needed", "danger")
484                 return redirect(package.getDetailsURL())
485
486         msg = "Updated meta from latest release"
487         addNotification(package.maintainers, current_user,
488                         msg, package.getDetailsURL(), package)
489         severity = AuditSeverity.NORMAL if current_user in package.maintainers else AuditSeverity.EDITOR
490         addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
491
492         db.session.commit()
493
494         task_id = uuid()
495         zippath = release.url.replace("/uploads/", app.config["UPLOAD_DIR"])
496         updateMetaFromRelease.apply_async((release.id, zippath), task_id=task_id)
497
498         return redirect(url_for("tasks.check", id=task_id, r=package.getEditURL()))