2 # Copyright (C) 2018 rubenwardy
4 # This program is free software: you can redistribute it and/or modify
5 # it under the terms of the GNU General Public License as published by
6 # the Free Software Foundation, either version 3 of the License, or
7 # (at your option) any later version.
9 # This program is distributed in the hope that it will be useful,
10 # but WITHOUT ANY WARRANTY; without even the implied warranty of
11 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 # GNU General Public License for more details.
14 # You should have received a copy of the GNU General Public License
15 # along with this program. If not, see <https://www.gnu.org/licenses/>.
18 from flask import render_template, abort, request, redirect, url_for, flash
19 from flask_user import current_user
20 import flask_menu as menu
24 from app.models import *
25 from app.querybuilder import QueryBuilder
26 from app.tasks.importtasks import importRepoScreenshot, updateMetaFromRelease
27 from app.rediscache import has_key, set_key
28 from app.utils import *
30 from flask_wtf import FlaskForm
32 from wtforms.validators import *
33 from wtforms.ext.sqlalchemy.fields import QuerySelectField, QuerySelectMultipleField
34 from sqlalchemy import or_, func
35 from sqlalchemy.orm import joinedload, subqueryload
37 from celery import uuid
40 @menu.register_menu(bp, ".mods", "Mods", order=11, endpoint_arguments_constructor=lambda: { 'type': 'mod' })
41 @menu.register_menu(bp, ".games", "Games", order=12, endpoint_arguments_constructor=lambda: { 'type': 'game' })
42 @menu.register_menu(bp, ".txp", "Texture Packs", order=13, endpoint_arguments_constructor=lambda: { 'type': 'txp' })
43 @menu.register_menu(bp, ".random", "Random", order=14, endpoint_arguments_constructor=lambda: { 'random': '1', 'lucky': '1' })
44 @bp.route("/packages/")
46 qb = QueryBuilder(request.args)
47 query = qb.buildPackageQuery()
50 query = query.options( \
51 joinedload(Package.license), \
52 joinedload(Package.media_license), \
53 subqueryload(Package.tags))
55 ip = request.headers.get("X-Forwarded-For") or request.remote_addr
56 if ip is not None and not is_user_bot():
60 key = "tag/{}/{}".format(ip, tag.name)
63 Tag.query.filter_by(id=tag.id).update({
64 "views": Tag.views + 1
71 package = query.first()
73 return redirect(package.getDetailsURL())
75 topic = qb.buildTopicQuery().first()
76 if qb.search and topic:
77 return redirect("https://forum.minetest.net/viewtopic.php?t=" + str(topic.topic_id))
79 page = get_int_or_abort(request.args.get("page"), 1)
80 num = min(40, get_int_or_abort(request.args.get("n"), 100))
81 query = query.paginate(page, num, True)
83 search = request.args.get("q")
84 type_name = request.args.get("type")
88 authors = User.query \
89 .filter(or_(*[func.lower(User.username) == name.lower().strip() for name in search.split(" ")])) \
92 authors = [(author.username, search.lower().replace(author.username.lower(), "")) for author in authors]
95 if qb.search and not query.has_next:
96 qb.show_discarded = True
97 topics = qb.buildTopicQuery().all()
99 tags = db.session.query(func.count(Tags.c.tag_id), Tag) \
100 .select_from(Tag).outerjoin(Tags).group_by(Tag.id).order_by(db.asc(Tag.title)).all()
102 selected_tags = set(qb.tags)
104 return render_template("packages/list.html", \
105 title=title, packages=query.items, pagination=query, \
106 query=search, tags=tags, selected_tags=selected_tags, type=type_name, \
107 authors=authors, packages_count=query.total, topics=topics)
110 def getReleases(package):
111 if package.checkPerm(current_user, Permission.MAKE_RELEASE):
112 return package.releases.limit(5)
114 return package.releases.filter_by(approved=True).limit(5)
117 @bp.route("/packages/<author>/<name>/")
121 if package.type == PackageType.MOD:
122 alternatives = Package.query \
123 .filter_by(name=package.name, type=PackageType.MOD, soft_deleted=False) \
124 .filter(Package.id != package.id) \
125 .order_by(db.desc(Package.score)) \
129 show_similar_topics = current_user == package.author or \
130 package.checkPerm(current_user, Permission.APPROVE_NEW)
132 similar_topics = None if not show_similar_topics else \
134 .filter_by(name=package.name) \
135 .filter(ForumTopic.topic_id != package.forums) \
136 .filter(~ db.exists().where(Package.forums==ForumTopic.topic_id)) \
137 .order_by(db.asc(ForumTopic.name), db.asc(ForumTopic.title)) \
140 releases = getReleases(package)
141 requests = [r for r in package.requests if r.status == 0]
143 review_thread = package.review_thread
144 if review_thread is not None and not review_thread.checkPerm(current_user, Permission.SEE_THREAD):
148 topic_error_lvl = "warning"
149 if not package.approved and package.forums is not None:
151 if Package.query.filter_by(forums=package.forums, soft_deleted=False).count() > 1:
152 errors.append("<b>Error: Another package already uses this forum topic!</b>")
153 topic_error_lvl = "danger"
155 topic = ForumTopic.query.get(package.forums)
156 if topic is not None:
157 if topic.author != package.author:
158 errors.append("<b>Error: Forum topic author doesn't match package author.</b>")
159 topic_error_lvl = "danger"
162 errors.append("Warning: Forum topic is in WIP section, make sure package meets playability standards.")
163 elif package.type != PackageType.TXP:
164 errors.append("Warning: Forum topic not found. This may happen if the topic has only just been created.")
166 topic_error = "<br />".join(errors)
169 threads = Thread.query.filter_by(package_id=package.id, review_id=None)
170 if not current_user.is_authenticated:
171 threads = threads.filter_by(private=False)
172 elif not current_user.rank.atLeast(UserRank.EDITOR) and not current_user == package.author:
173 threads = threads.filter(or_(Thread.private == False, Thread.author == current_user))
175 has_review = current_user.is_authenticated and PackageReview.query.filter_by(package=package, author=current_user).count() > 0
177 return render_template("packages/view.html", \
178 package=package, releases=releases, requests=requests, \
179 alternatives=alternatives, similar_topics=similar_topics, \
180 review_thread=review_thread, topic_error=topic_error, topic_error_lvl=topic_error_lvl, \
181 threads=threads.all(), has_review=has_review)
184 @bp.route("/packages/<author>/<name>/download/")
186 def download(package):
187 release = package.getDownloadRelease()
190 if "application/zip" in request.accept_mimetypes and \
191 not "text/html" in request.accept_mimetypes:
194 flash("No download available.", "danger")
195 return redirect(package.getDetailsURL())
197 return redirect(release.getDownloadURL(), code=302)
200 class PackageForm(FlaskForm):
201 name = StringField("Name (Technical)", [InputRequired(), Length(1, 100), Regexp("^[a-z0-9_]+$", 0, "Lower case letters (a-z), digits (0-9), and underscores (_) only")])
202 title = StringField("Title (Human-readable)", [InputRequired(), Length(3, 100)])
203 short_desc = StringField("Short Description (Plaintext)", [InputRequired(), Length(1,200)])
204 desc = TextAreaField("Long Description (Markdown)", [Optional(), Length(0,10000)])
205 type = SelectField("Type", [InputRequired()], choices=PackageType.choices(), coerce=PackageType.coerce, default=PackageType.MOD)
206 license = QuerySelectField("License", [DataRequired()], allow_blank=True, query_factory=lambda: License.query.order_by(db.asc(License.name)), get_pk=lambda a: a.id, get_label=lambda a: a.name)
207 media_license = QuerySelectField("Media License", [DataRequired()], allow_blank=True, query_factory=lambda: License.query.order_by(db.asc(License.name)), get_pk=lambda a: a.id, get_label=lambda a: a.name)
208 provides_str = StringField("Provides (mods included in package)", [Optional()])
209 tags = QuerySelectMultipleField('Tags', query_factory=lambda: Tag.query.order_by(db.asc(Tag.name)), get_pk=lambda a: a.id, get_label=lambda a: a.title)
210 content_warnings = QuerySelectMultipleField('Content Warnings', query_factory=lambda: ContentWarning.query.order_by(db.asc(ContentWarning.name)), get_pk=lambda a: a.id, get_label=lambda a: a.title)
211 harddep_str = StringField("Hard Dependencies", [Optional()])
212 softdep_str = StringField("Soft Dependencies", [Optional()])
213 repo = StringField("VCS Repository URL", [Optional(), URL()], filters = [lambda x: x or None])
214 website = StringField("Website URL", [Optional(), URL()], filters = [lambda x: x or None])
215 issueTracker = StringField("Issue Tracker URL", [Optional(), URL()], filters = [lambda x: x or None])
216 forums = IntegerField("Forum Topic ID", [Optional(), NumberRange(0,999999)])
217 submit = SubmitField("Save")
220 @bp.route("/packages/new/", methods=["GET", "POST"])
221 @bp.route("/packages/<author>/<name>/edit/", methods=["GET", "POST"])
223 def create_edit(author=None, name=None):
227 form = PackageForm(formdata=request.form)
228 author = request.args.get("author")
229 if author is None or author == current_user.username:
230 author = current_user
232 author = User.query.filter_by(username=author).first()
234 flash("Unable to find that user", "danger")
235 return redirect(url_for("packages.create_edit"))
237 if not author.checkPerm(current_user, Permission.CHANGE_AUTHOR):
238 flash("Permission denied", "danger")
239 return redirect(url_for("packages.create_edit"))
242 package = getPackageByInfo(author, name)
243 if not package.checkPerm(current_user, Permission.EDIT_PACKAGE):
244 return redirect(package.getDetailsURL())
246 author = package.author
248 form = PackageForm(formdata=request.form, obj=package)
250 # Initial form class from post data and default data
251 if request.method == "GET":
253 form.name.data = request.args.get("bname")
254 form.title.data = request.args.get("title")
255 form.repo.data = request.args.get("repo")
256 form.forums.data = request.args.get("forums")
257 form.license.data = None
258 form.media_license.data = None
260 form.harddep_str.data = ",".join([str(x) for x in package.getSortedHardDependencies() ])
261 form.softdep_str.data = ",".join([str(x) for x in package.getSortedOptionalDependencies() ])
262 form.provides_str.data = MetaPackage.ListToSpec(package.provides)
263 form.tags.data = list(package.tags)
264 form.content_warnings.data = list(package.content_warnings)
266 if request.method == "POST" and form.validate():
269 package = Package.query.filter_by(name=form["name"].data, author_id=author.id).first()
270 if package is not None:
271 if package.soft_deleted:
272 Package.query.filter_by(name=form["name"].data, author_id=author.id).delete()
274 flash("Package already exists!", "danger")
275 return redirect(url_for("packages.create_edit"))
278 package.author = author
279 package.maintainers.append(author)
282 elif package.approved and package.name != form.name.data and \
283 not package.checkPerm(current_user, Permission.CHANGE_NAME):
284 flash("Unable to change package name", "danger")
285 return redirect(url_for("packages.create_edit", author=author, name=name))
288 msg = "Edited {}".format(package.title)
290 addNotification(package.maintainers, current_user,
291 msg, package.getDetailsURL(), package)
293 severity = AuditSeverity.NORMAL if current_user in package.maintainers else AuditSeverity.EDITOR
294 addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
296 form.populate_obj(package) # copy to row
298 if package.type== PackageType.TXP:
299 package.license = package.media_license
302 package.provides.clear()
303 mpackages = MetaPackage.SpecToList(form.provides_str.data, mpackage_cache)
305 package.provides.append(m)
307 Dependency.query.filter_by(depender=package).delete()
308 deps = Dependency.SpecToList(package, form.harddep_str.data, mpackage_cache)
313 deps = Dependency.SpecToList(package, form.softdep_str.data, mpackage_cache)
318 if wasNew and package.type == PackageType.MOD and not package.name in mpackage_cache:
319 m = MetaPackage.GetOrCreate(package.name, mpackage_cache)
320 package.provides.append(m)
323 for tag in form.tags.raw_data:
324 package.tags.append(Tag.query.get(tag))
326 package.content_warnings.clear()
327 for warning in form.content_warnings.raw_data:
328 package.content_warnings.append(ContentWarning.query.get(warning))
330 db.session.commit() # save
332 next_url = package.getDetailsURL()
333 if wasNew and package.repo is not None:
334 task = importRepoScreenshot.delay(package.id)
335 next_url = url_for("tasks.check", id=task.id, r=next_url)
337 if wasNew and ("WTFPL" in package.license.name or "WTFPL" in package.media_license.name):
338 next_url = url_for("flatpage", path="help/wtfpl", r=next_url)
340 return redirect(next_url)
342 package_query = Package.query.filter_by(approved=True, soft_deleted=False)
343 if package is not None:
344 package_query = package_query.filter(Package.id != package.id)
346 enableWizard = name is None and request.method != "POST"
347 return render_template("packages/create_edit.html", package=package, \
348 form=form, author=author, enable_wizard=enableWizard, \
349 packages=package_query.all(), \
350 mpackages=MetaPackage.query.order_by(db.asc(MetaPackage.name)).all())
352 @bp.route("/packages/<author>/<name>/approve/", methods=["POST"])
355 def approve(package):
356 if not package.checkPerm(current_user, Permission.APPROVE_NEW):
357 flash("You don't have permission to do that.", "danger")
359 elif package.approved:
360 flash("Package has already been approved", "danger")
363 package.approved = True
365 screenshots = PackageScreenshot.query.filter_by(package=package, approved=False).all()
366 for s in screenshots:
369 msg = "Approved {}".format(package.title)
370 addNotification(package.maintainers, current_user, msg, package.getDetailsURL(), package)
371 severity = AuditSeverity.NORMAL if current_user == package.author else AuditSeverity.EDITOR
372 addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
375 return redirect(package.getDetailsURL())
378 @bp.route("/packages/<author>/<name>/remove/", methods=["GET", "POST"])
382 if request.method == "GET":
383 return render_template("packages/remove.html", package=package)
385 if "delete" in request.form:
386 if not package.checkPerm(current_user, Permission.DELETE_PACKAGE):
387 flash("You don't have permission to do that.", "danger")
388 return redirect(package.getDetailsURL())
390 package.soft_deleted = True
392 url = url_for("users.profile", username=package.author.username)
393 msg = "Deleted {}".format(package.title)
394 addNotification(package.maintainers, current_user, msg, url, package)
395 addAuditLog(AuditSeverity.EDITOR, current_user, msg, url)
398 flash("Deleted package", "success")
401 elif "unapprove" in request.form:
402 if not package.checkPerm(current_user, Permission.UNAPPROVE_PACKAGE):
403 flash("You don't have permission to do that.", "danger")
404 return redirect(package.getDetailsURL())
406 package.approved = False
408 msg = "Unapproved {}".format(package.title)
409 addNotification(package.maintainers, current_user, msg, package.getDetailsURL(), package)
410 addAuditLog(AuditSeverity.EDITOR, current_user, msg, package.getDetailsURL(), package)
414 flash("Unapproved package", "success")
416 return redirect(package.getDetailsURL())
422 class PackageMaintainersForm(FlaskForm):
423 maintainers_str = StringField("Maintainers (Comma-separated)", [Optional()])
424 submit = SubmitField("Save")
427 @bp.route("/packages/<author>/<name>/edit-maintainers/", methods=["GET", "POST"])
430 def edit_maintainers(package):
431 if not package.checkPerm(current_user, Permission.EDIT_MAINTAINERS):
432 flash("You do not have permission to edit maintainers", "danger")
433 return redirect(package.getDetailsURL())
435 form = PackageMaintainersForm(formdata=request.form)
436 if request.method == "GET":
437 form.maintainers_str.data = ", ".join([ x.username for x in package.maintainers if x != package.author ])
439 if request.method == "POST" and form.validate():
440 usernames = [x.strip().lower() for x in form.maintainers_str.data.split(",")]
441 users = User.query.filter(func.lower(User.username).in_(usernames)).all()
444 if not user in package.maintainers:
445 addNotification(user, current_user,
446 "Added you as a maintainer of {}".format(package.title), package.getDetailsURL(), package)
448 for user in package.maintainers:
449 if user != package.author and not user in users:
450 addNotification(user, current_user,
451 "Removed you as a maintainer of {}".format(package.title), package.getDetailsURL(), package)
453 package.maintainers.clear()
454 package.maintainers.extend(users)
455 if package.author not in package.maintainers:
456 package.maintainers.append(package.author)
458 msg = "Edited {} maintainers".format(package.title)
459 addNotification(package.author, current_user, msg, package.getDetailsURL(), package)
460 severity = AuditSeverity.NORMAL if current_user == package.author else AuditSeverity.MODERATION
461 addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
465 return redirect(package.getDetailsURL())
467 users = User.query.filter(User.rank >= UserRank.NEW_MEMBER).order_by(db.asc(User.username)).all()
469 return render_template("packages/edit_maintainers.html", \
470 package=package, form=form, users=users)
473 @bp.route("/packages/<author>/<name>/remove-self-maintainer/", methods=["POST"])
476 def remove_self_maintainers(package):
477 if not current_user in package.maintainers:
478 flash("You are not a maintainer", "danger")
480 elif current_user == package.author:
481 flash("Package owners cannot remove themselves as maintainers", "danger")
484 package.maintainers.remove(current_user)
486 addNotification(package.author, current_user,
487 "Removed themself as a maintainer of {}".format(package.title), package.getDetailsURL(), package)
491 return redirect(package.getDetailsURL())
494 @bp.route("/packages/<author>/<name>/import-meta/", methods=["POST"])
497 def update_from_release(package):
498 if not package.checkPerm(current_user, Permission.REIMPORT_META):
499 flash("You don't have permission to reimport meta", "danger")
500 return redirect(package.getDetailsURL())
502 release = package.releases.first()
504 flash("Release needed", "danger")
505 return redirect(package.getDetailsURL())
507 msg = "Updated meta from latest release"
508 addNotification(package.maintainers, current_user,
509 msg, package.getDetailsURL(), package)
510 severity = AuditSeverity.NORMAL if current_user in package.maintainers else AuditSeverity.EDITOR
511 addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
516 zippath = release.url.replace("/uploads/", app.config["UPLOAD_DIR"])
517 updateMetaFromRelease.apply_async((release.id, zippath), task_id=task_id)
519 return redirect(url_for("tasks.check", id=task_id, r=package.getEditURL()))