]> git.lizzy.rs Git - cheatdb.git/blob - app/blueprints/packages/packages.py
Allow all users to delete their packages
[cheatdb.git] / app / blueprints / packages / packages.py
1 # ContentDB
2 # Copyright (C) 2018  rubenwardy
3 #
4 # This program is free software: you can redistribute it and/or modify
5 # it under the terms of the GNU General Public License as published by
6 # the Free Software Foundation, either version 3 of the License, or
7 # (at your option) any later version.
8 #
9 # This program is distributed in the hope that it will be useful,
10 # but WITHOUT ANY WARRANTY; without even the implied warranty of
11 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12 # GNU General Public License for more details.
13 #
14 # You should have received a copy of the GNU General Public License
15 # along with this program.  If not, see <https://www.gnu.org/licenses/>.
16
17
18 from flask import render_template, abort, request, redirect, url_for, flash
19 from flask_user import current_user
20 import flask_menu as menu
21
22 from . import bp
23
24 from app.models import *
25 from app.querybuilder import QueryBuilder
26 from app.tasks.importtasks import importRepoScreenshot, updateMetaFromRelease
27 from app.rediscache import has_key, set_key
28 from app.utils import *
29
30 from flask_wtf import FlaskForm
31 from wtforms import *
32 from wtforms.validators import *
33 from wtforms.ext.sqlalchemy.fields import QuerySelectField, QuerySelectMultipleField
34 from sqlalchemy import or_, func
35 from sqlalchemy.orm import joinedload, subqueryload
36 from urllib.parse import quote as urlescape
37
38 from celery import uuid
39
40
41 @menu.register_menu(bp, ".mods", "Mods", order=11, endpoint_arguments_constructor=lambda: { 'type': 'mod' })
42 @menu.register_menu(bp, ".games", "Games", order=12, endpoint_arguments_constructor=lambda: { 'type': 'game' })
43 @menu.register_menu(bp, ".txp", "Texture Packs", order=13, endpoint_arguments_constructor=lambda: { 'type': 'txp' })
44 @menu.register_menu(bp, ".random", "Random", order=14, endpoint_arguments_constructor=lambda: { 'random': '1', 'lucky': '1' })
45 @bp.route("/packages/")
46 def list_all():
47         qb    = QueryBuilder(request.args)
48         query = qb.buildPackageQuery()
49         title = qb.title
50
51         query = query.options( \
52                         joinedload(Package.license), \
53                         joinedload(Package.media_license), \
54                         subqueryload(Package.tags))
55
56         ip = request.headers.get("X-Forwarded-For") or request.remote_addr
57         if ip is not None and not is_user_bot():
58                 edited = False
59                 for tag in qb.tags:
60                         edited = True
61                         key = "tag/{}/{}".format(ip, tag.name)
62                         if not has_key(key):
63                                 set_key(key, "true")
64                                 Tag.query.filter_by(id=tag.id).update({
65                                                 "views": Tag.views + 1
66                                         })
67
68                 if edited:
69                         db.session.commit()
70
71         if qb.lucky:
72                 package = query.first()
73                 if package:
74                         return redirect(package.getDetailsURL())
75
76                 topic = qb.buildTopicQuery().first()
77                 if qb.search and topic:
78                         return redirect("https://forum.minetest.net/viewtopic.php?t=" + str(topic.topic_id))
79
80         page  = get_int_or_abort(request.args.get("page"), 1)
81         num   = min(40, get_int_or_abort(request.args.get("n"), 100))
82         query = query.paginate(page, num, True)
83
84         search = request.args.get("q")
85         type_name = request.args.get("type")
86
87         authors = []
88         if search:
89                 authors = User.query \
90                         .filter(or_(*[func.lower(User.username) == name.lower().strip() for name in search.split(" ")])) \
91                         .all()
92
93                 authors = [(author.username, search.lower().replace(author.username.lower(), "")) for author in authors]
94
95         topics = None
96         if qb.search and not query.has_next:
97                 qb.show_discarded = True
98                 topics = qb.buildTopicQuery().all()
99
100         tags_query = db.session.query(func.count(Tags.c.tag_id), Tag) \
101                 .select_from(Tag).join(Tags).join(Package).group_by(Tag.id).order_by(db.asc(Tag.title))
102         tags = qb.filterPackageQuery(tags_query).all()
103
104         selected_tags = set(qb.tags)
105
106         return render_template("packages/list.html", \
107                         title=title, packages=query.items, pagination=query, \
108                         query=search, tags=tags, selected_tags=selected_tags, type=type_name, \
109                         authors=authors, packages_count=query.total, topics=topics)
110
111
112 def getReleases(package):
113         if package.checkPerm(current_user, Permission.MAKE_RELEASE):
114                 return package.releases.limit(5)
115         else:
116                 return package.releases.filter_by(approved=True).limit(5)
117
118
119 @bp.route("/packages/<author>/<name>/")
120 @is_package_page
121 def view(package):
122         alternatives = None
123         if package.type == PackageType.MOD:
124                 alternatives = Package.query \
125                         .filter_by(name=package.name, type=PackageType.MOD) \
126                         .filter(Package.id != package.id, Package.state!=PackageState.DELETED) \
127                         .order_by(db.desc(Package.score)) \
128                         .all()
129
130
131         show_similar_topics = current_user == package.author or \
132                         package.checkPerm(current_user, Permission.APPROVE_NEW)
133
134         similar_topics = None if not show_similar_topics else \
135                         ForumTopic.query \
136                                 .filter_by(name=package.name) \
137                                 .filter(ForumTopic.topic_id != package.forums) \
138                                 .filter(~ db.exists().where(Package.forums==ForumTopic.topic_id)) \
139                                 .order_by(db.asc(ForumTopic.name), db.asc(ForumTopic.title)) \
140                                 .all()
141
142         releases = getReleases(package)
143         requests = [r for r in package.requests if r.status == 0]
144
145         review_thread = package.review_thread
146         if review_thread is not None and not review_thread.checkPerm(current_user, Permission.SEE_THREAD):
147                 review_thread = None
148
149         topic_error = None
150         topic_error_lvl = "warning"
151         if package.state != PackageState.APPROVED and package.forums is not None:
152                 errors = []
153                 if Package.query.filter(Package.forums==package.forums, Package.state!=PackageState.DELETED).count() > 1:
154                         errors.append("<b>Error: Another package already uses this forum topic!</b>")
155                         topic_error_lvl = "danger"
156
157                 topic = ForumTopic.query.get(package.forums)
158                 if topic is not None:
159                         if topic.author != package.author:
160                                 errors.append("<b>Error: Forum topic author doesn't match package author.</b>")
161                                 topic_error_lvl = "danger"
162
163                         if topic.wip:
164                                 errors.append("Warning: Forum topic is in WIP section, make sure package meets playability standards.")
165                 elif package.type != PackageType.TXP:
166                         errors.append("Warning: Forum topic not found. This may happen if the topic has only just been created.")
167
168                 topic_error = "<br />".join(errors)
169
170
171         threads = Thread.query.filter_by(package_id=package.id, review_id=None)
172         if not current_user.is_authenticated:
173                 threads = threads.filter_by(private=False)
174         elif not current_user.rank.atLeast(UserRank.EDITOR) and not current_user == package.author:
175                 threads = threads.filter(or_(Thread.private == False, Thread.author == current_user))
176
177         has_review = current_user.is_authenticated and PackageReview.query.filter_by(package=package, author=current_user).count() > 0
178
179         return render_template("packages/view.html", \
180                         package=package, releases=releases, requests=requests, \
181                         alternatives=alternatives, similar_topics=similar_topics, \
182                         review_thread=review_thread, topic_error=topic_error, topic_error_lvl=topic_error_lvl, \
183                         threads=threads.all(), has_review=has_review)
184
185
186 @bp.route("/packages/<author>/<name>/shields/<type>/")
187 @is_package_page
188 def shield(package, type):
189         if type == "title":
190                 url = "https://img.shields.io/badge/ContentDB-{}-{}" \
191                         .format(urlescape(package.title), urlescape("#375a7f"))
192         elif type == "downloads":
193                 #api_url = abs_url_for("api.package", author=package.author.username, name=package.name)
194                 api_url = "https://content.minetest.net" + url_for("api.package", author=package.author.username, name=package.name)
195                 url = "https://img.shields.io/badge/dynamic/json?color={}&label=ContentDB&query=downloads&suffix=+downloads&url={}" \
196                         .format(urlescape("#375a7f"), urlescape(api_url))
197         else:
198                 abort(404)
199
200         return redirect(url)
201
202
203
204 @bp.route("/packages/<author>/<name>/download/")
205 @is_package_page
206 def download(package):
207         release = package.getDownloadRelease()
208
209         if release is None:
210                 if "application/zip" in request.accept_mimetypes and \
211                                 not "text/html" in request.accept_mimetypes:
212                         return "", 204
213                 else:
214                         flash("No download available.", "danger")
215                         return redirect(package.getDetailsURL())
216         else:
217                 return redirect(release.getDownloadURL(), code=302)
218
219
220 def makeLabel(obj):
221         if obj.description:
222                 return "{}: {}".format(obj.title, obj.description)
223         else:
224                 return obj.title
225
226 class PackageForm(FlaskForm):
227         name             = StringField("Name (Technical)", [InputRequired(), Length(1, 100), Regexp("^[a-z0-9_]+$", 0, "Lower case letters (a-z), digits (0-9), and underscores (_) only")])
228         title            = StringField("Title (Human-readable)", [InputRequired(), Length(3, 100)])
229         short_desc       = StringField("Short Description (Plaintext)", [InputRequired(), Length(1,200)])
230         desc             = TextAreaField("Long Description (Markdown)", [Optional(), Length(0,10000)])
231         type             = SelectField("Type", [InputRequired()], choices=PackageType.choices(), coerce=PackageType.coerce, default=PackageType.MOD)
232         license          = QuerySelectField("License", [DataRequired()], allow_blank=True, query_factory=lambda: License.query.order_by(db.asc(License.name)), get_pk=lambda a: a.id, get_label=lambda a: a.name)
233         media_license    = QuerySelectField("Media License", [DataRequired()], allow_blank=True, query_factory=lambda: License.query.order_by(db.asc(License.name)), get_pk=lambda a: a.id, get_label=lambda a: a.name)
234         tags             = QuerySelectMultipleField('Tags', query_factory=lambda: Tag.query.order_by(db.asc(Tag.name)), get_pk=lambda a: a.id, get_label=makeLabel)
235         content_warnings = QuerySelectMultipleField('Content Warnings', query_factory=lambda: ContentWarning.query.order_by(db.asc(ContentWarning.name)), get_pk=lambda a: a.id, get_label=makeLabel)
236         # harddep_str      = StringField("Hard Dependencies", [Optional()])
237         # softdep_str      = StringField("Soft Dependencies", [Optional()])
238         repo             = StringField("VCS Repository URL", [Optional(), URL()], filters = [lambda x: x or None])
239         website          = StringField("Website URL", [Optional(), URL()], filters = [lambda x: x or None])
240         issueTracker     = StringField("Issue Tracker URL", [Optional(), URL()], filters = [lambda x: x or None])
241         forums           = IntegerField("Forum Topic ID", [Optional(), NumberRange(0,999999)])
242         submit           = SubmitField("Save")
243
244
245 @bp.route("/packages/new/", methods=["GET", "POST"])
246 @bp.route("/packages/<author>/<name>/edit/", methods=["GET", "POST"])
247 @login_required
248 def create_edit(author=None, name=None):
249         package = None
250         form = None
251         if author is None:
252                 form = PackageForm(formdata=request.form)
253                 author = request.args.get("author")
254                 if author is None or author == current_user.username:
255                         author = current_user
256                 else:
257                         author = User.query.filter_by(username=author).first()
258                         if author is None:
259                                 flash("Unable to find that user", "danger")
260                                 return redirect(url_for("packages.create_edit"))
261
262                         if not author.checkPerm(current_user, Permission.CHANGE_AUTHOR):
263                                 flash("Permission denied", "danger")
264                                 return redirect(url_for("packages.create_edit"))
265
266         else:
267                 package = getPackageByInfo(author, name)
268                 if package is None:
269                         abort(404)
270                 if not package.checkPerm(current_user, Permission.EDIT_PACKAGE):
271                         return redirect(package.getDetailsURL())
272
273                 author = package.author
274
275                 form = PackageForm(formdata=request.form, obj=package)
276
277         # Initial form class from post data and default data
278         if request.method == "GET":
279                 if package is None:
280                         form.name.data   = request.args.get("bname")
281                         form.title.data  = request.args.get("title")
282                         form.repo.data   = request.args.get("repo")
283                         form.forums.data = request.args.get("forums")
284                         form.license.data = None
285                         form.media_license.data = None
286                 else:
287                         # form.harddep_str.data  = ",".join([str(x) for x in package.getSortedHardDependencies() ])
288                         # form.softdep_str.data  = ",".join([str(x) for x in package.getSortedOptionalDependencies() ])
289                         form.tags.data         = list(package.tags)
290                         form.content_warnings.data = list(package.content_warnings)
291
292         if request.method == "POST" and form.validate():
293                 wasNew = False
294                 if not package:
295                         package = Package.query.filter_by(name=form["name"].data, author_id=author.id).first()
296                         if package is not None:
297                                 if package.state == PackageState.READY_FOR_REVIEW:
298                                         Package.query.filter_by(name=form["name"].data, author_id=author.id).delete()
299                                 else:
300                                         flash("Package already exists!", "danger")
301                                         return redirect(url_for("packages.create_edit"))
302
303                         package = Package()
304                         package.author = author
305                         package.maintainers.append(author)
306                         wasNew = True
307
308                 elif package.name != form.name.data and not package.checkPerm(current_user, Permission.CHANGE_NAME):
309                         flash("Unable to change package name", "danger")
310                         return redirect(url_for("packages.create_edit", author=author, name=name))
311
312                 else:
313                         msg = "Edited {}".format(package.title)
314
315                         addNotification(package.maintainers, current_user,
316                                         msg, package.getDetailsURL(), package)
317
318                         severity = AuditSeverity.NORMAL if current_user in package.maintainers else AuditSeverity.EDITOR
319                         addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
320
321                 form.populate_obj(package) # copy to row
322
323                 if package.type == PackageType.TXP:
324                         package.license = package.media_license
325
326                 # Dependency.query.filter_by(depender=package).delete()
327                 # deps = Dependency.SpecToList(package, form.harddep_str.data, mpackage_cache)
328                 # for dep in deps:
329                 #       dep.optional = False
330                 #       db.session.add(dep)
331
332                 # deps = Dependency.SpecToList(package, form.softdep_str.data, mpackage_cache)
333                 # for dep in deps:
334                 #       dep.optional = True
335                 #       db.session.add(dep)
336
337                 if wasNew and package.type == PackageType.MOD:
338                         m = MetaPackage.GetOrCreate(package.name, {})
339                         package.provides.append(m)
340
341                 package.tags.clear()
342                 for tag in form.tags.raw_data:
343                         package.tags.append(Tag.query.get(tag))
344
345                 package.content_warnings.clear()
346                 for warning in form.content_warnings.raw_data:
347                         package.content_warnings.append(ContentWarning.query.get(warning))
348
349                 db.session.commit() # save
350
351                 next_url = package.getDetailsURL()
352                 if wasNew and package.repo is not None:
353                         task = importRepoScreenshot.delay(package.id)
354                         next_url = url_for("tasks.check", id=task.id, r=next_url)
355
356                 if wasNew and ("WTFPL" in package.license.name or "WTFPL" in package.media_license.name):
357                         next_url = url_for("flatpage", path="help/wtfpl", r=next_url)
358
359                 return redirect(next_url)
360
361         package_query = Package.query.filter_by(state=PackageState.APPROVED)
362         if package is not None:
363                 package_query = package_query.filter(Package.id != package.id)
364
365         enableWizard = name is None and request.method != "POST"
366         return render_template("packages/create_edit.html", package=package, \
367                         form=form, author=author, enable_wizard=enableWizard, \
368                         packages=package_query.all(), \
369                         mpackages=MetaPackage.query.order_by(db.asc(MetaPackage.name)).all())
370
371
372 @bp.route("/packages/<author>/<name>/state/", methods=["POST"])
373 @login_required
374 @is_package_page
375 def move_to_state(package):
376         state = PackageState.get(request.args.get("state"))
377         if state is None:
378                 abort(400)
379
380         if not package.canMoveToState(current_user, state):
381                 flash("You don't have permission to do that", "danger")
382                 return redirect(package.getDetailsURL())
383
384         package.state = state
385         msg = "Marked {} as {}".format(package.title, state.value)
386
387         if state == PackageState.APPROVED:
388                 if not package.approved_at:
389                         package.approved_at = datetime.datetime.now()
390
391                 screenshots = PackageScreenshot.query.filter_by(package=package, approved=False).all()
392                 for s in screenshots:
393                         s.approved = True
394
395                 msg = "Approved {}".format(package.title)
396
397         addNotification(package.maintainers, current_user, msg, package.getDetailsURL(), package)
398         severity = AuditSeverity.NORMAL if current_user in package.maintainers else AuditSeverity.EDITOR
399         addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
400
401         db.session.commit()
402
403         if package.state == PackageState.CHANGES_NEEDED:
404                 flash("Please comment what changes are needed in the review thread", "warning")
405                 if package.review_thread:
406                         return redirect(package.review_thread.getViewURL())
407                 else:
408                         return redirect(url_for('threads.new', pid=package.id, title='Package approval comments'))
409
410         return redirect(package.getDetailsURL())
411
412
413 @bp.route("/packages/<author>/<name>/remove/", methods=["GET", "POST"])
414 @login_required
415 @is_package_page
416 def remove(package):
417         if request.method == "GET":
418                 return render_template("packages/remove.html", package=package)
419
420         if "delete" in request.form:
421                 if not package.checkPerm(current_user, Permission.DELETE_PACKAGE):
422                         flash("You don't have permission to do that.", "danger")
423                         return redirect(package.getDetailsURL())
424
425                 package.state = PackageState.DELETED
426
427                 url = url_for("users.profile", username=package.author.username)
428                 msg = "Deleted {}".format(package.title)
429                 addNotification(package.maintainers, current_user, msg, url, package)
430                 addAuditLog(AuditSeverity.EDITOR, current_user, msg, url)
431                 db.session.commit()
432
433                 flash("Deleted package", "success")
434
435                 return redirect(url)
436         elif "unapprove" in request.form:
437                 if not package.checkPerm(current_user, Permission.UNAPPROVE_PACKAGE):
438                         flash("You don't have permission to do that.", "danger")
439                         return redirect(package.getDetailsURL())
440
441                 package.state = PackageState.WIP
442
443                 msg = "Unapproved {}".format(package.title)
444                 addNotification(package.maintainers, current_user, msg, package.getDetailsURL(), package)
445                 addAuditLog(AuditSeverity.EDITOR, current_user, msg, package.getDetailsURL(), package)
446
447                 db.session.commit()
448
449                 flash("Unapproved package", "success")
450
451                 return redirect(package.getDetailsURL())
452         else:
453                 abort(400)
454
455
456
457 class PackageMaintainersForm(FlaskForm):
458         maintainers_str  = StringField("Maintainers (Comma-separated)", [Optional()])
459         submit        = SubmitField("Save")
460
461
462 @bp.route("/packages/<author>/<name>/edit-maintainers/", methods=["GET", "POST"])
463 @login_required
464 @is_package_page
465 def edit_maintainers(package):
466         if not package.checkPerm(current_user, Permission.EDIT_MAINTAINERS):
467                 flash("You do not have permission to edit maintainers", "danger")
468                 return redirect(package.getDetailsURL())
469
470         form = PackageMaintainersForm(formdata=request.form)
471         if request.method == "GET":
472                 form.maintainers_str.data = ", ".join([ x.username for x in package.maintainers if x != package.author ])
473
474         if request.method == "POST" and form.validate():
475                 usernames = [x.strip().lower() for x in form.maintainers_str.data.split(",")]
476                 users = User.query.filter(func.lower(User.username).in_(usernames)).all()
477
478                 for user in users:
479                         if not user in package.maintainers:
480                                 addNotification(user, current_user,
481                                                 "Added you as a maintainer of {}".format(package.title), package.getDetailsURL(), package)
482
483                 for user in package.maintainers:
484                         if user != package.author and not user in users:
485                                 addNotification(user, current_user,
486                                                 "Removed you as a maintainer of {}".format(package.title), package.getDetailsURL(), package)
487
488                 package.maintainers.clear()
489                 package.maintainers.extend(users)
490                 if package.author not in package.maintainers:
491                         package.maintainers.append(package.author)
492
493                 msg = "Edited {} maintainers".format(package.title)
494                 addNotification(package.author, current_user, msg, package.getDetailsURL(), package)
495                 severity = AuditSeverity.NORMAL if current_user == package.author else AuditSeverity.MODERATION
496                 addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
497
498                 db.session.commit()
499
500                 return redirect(package.getDetailsURL())
501
502         users = User.query.filter(User.rank >= UserRank.NEW_MEMBER).order_by(db.asc(User.username)).all()
503
504         return render_template("packages/edit_maintainers.html", \
505                         package=package, form=form, users=users)
506
507
508 @bp.route("/packages/<author>/<name>/remove-self-maintainer/", methods=["POST"])
509 @login_required
510 @is_package_page
511 def remove_self_maintainers(package):
512         if not current_user in package.maintainers:
513                 flash("You are not a maintainer", "danger")
514
515         elif current_user == package.author:
516                 flash("Package owners cannot remove themselves as maintainers", "danger")
517
518         else:
519                 package.maintainers.remove(current_user)
520
521                 addNotification(package.author, current_user,
522                                 "Removed themself as a maintainer of {}".format(package.title), package.getDetailsURL(), package)
523
524                 db.session.commit()
525
526         return redirect(package.getDetailsURL())
527
528
529 @bp.route("/packages/<author>/<name>/import-meta/", methods=["POST"])
530 @login_required
531 @is_package_page
532 def update_from_release(package):
533         if not package.checkPerm(current_user, Permission.REIMPORT_META):
534                 flash("You don't have permission to reimport meta", "danger")
535                 return redirect(package.getDetailsURL())
536
537         release = package.releases.first()
538         if not release:
539                 flash("Release needed", "danger")
540                 return redirect(package.getDetailsURL())
541
542         msg = "Updated meta from latest release"
543         addNotification(package.maintainers, current_user,
544                         msg, package.getDetailsURL(), package)
545         severity = AuditSeverity.NORMAL if current_user in package.maintainers else AuditSeverity.EDITOR
546         addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
547
548         db.session.commit()
549
550         task_id = uuid()
551         zippath = release.url.replace("/uploads/", app.config["UPLOAD_DIR"])
552         updateMetaFromRelease.apply_async((release.id, zippath), task_id=task_id)
553
554         return redirect(url_for("tasks.check", id=task_id, r=package.getEditURL()))