]> git.lizzy.rs Git - cheatdb.git/blob - app/blueprints/packages/packages.py
f8124ea754164b1fb9ae34536678b797171cc0dd
[cheatdb.git] / app / blueprints / packages / packages.py
1 # ContentDB
2 # Copyright (C) 2018  rubenwardy
3 #
4 # This program is free software: you can redistribute it and/or modify
5 # it under the terms of the GNU General Public License as published by
6 # the Free Software Foundation, either version 3 of the License, or
7 # (at your option) any later version.
8 #
9 # This program is distributed in the hope that it will be useful,
10 # but WITHOUT ANY WARRANTY; without even the implied warranty of
11 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12 # GNU General Public License for more details.
13 #
14 # You should have received a copy of the GNU General Public License
15 # along with this program.  If not, see <https://www.gnu.org/licenses/>.
16
17
18 from flask import render_template, abort, request, redirect, url_for, flash
19 from flask_user import current_user
20 import flask_menu as menu
21
22 from . import bp
23
24 from app.models import *
25 from app.querybuilder import QueryBuilder
26 from app.tasks.importtasks import importRepoScreenshot, updateMetaFromRelease
27 from app.rediscache import has_key, set_key
28 from app.utils import *
29
30 from flask_wtf import FlaskForm
31 from wtforms import *
32 from wtforms.validators import *
33 from wtforms.ext.sqlalchemy.fields import QuerySelectField, QuerySelectMultipleField
34 from sqlalchemy import or_, func
35 from sqlalchemy.orm import joinedload, subqueryload
36
37 from celery import uuid
38
39
40 @menu.register_menu(bp, ".mods", "Mods", order=11, endpoint_arguments_constructor=lambda: { 'type': 'mod' })
41 @menu.register_menu(bp, ".games", "Games", order=12, endpoint_arguments_constructor=lambda: { 'type': 'game' })
42 @menu.register_menu(bp, ".txp", "Texture Packs", order=13, endpoint_arguments_constructor=lambda: { 'type': 'txp' })
43 @menu.register_menu(bp, ".random", "Random", order=14, endpoint_arguments_constructor=lambda: { 'random': '1', 'lucky': '1' })
44 @bp.route("/packages/")
45 def list_all():
46         qb    = QueryBuilder(request.args)
47         query = qb.buildPackageQuery()
48         title = qb.title
49
50         query = query.options( \
51                         joinedload(Package.license), \
52                         joinedload(Package.media_license), \
53                         subqueryload(Package.tags))
54
55         ip = request.headers.get("X-Forwarded-For") or request.remote_addr
56         if ip is not None and not is_user_bot():
57                 edited = False
58                 for tag in qb.tags:
59                         edited = True
60                         key = "tag/{}/{}".format(ip, tag.name)
61                         if not has_key(key):
62                                 set_key(key, "true")
63                                 Tag.query.filter_by(id=tag.id).update({
64                                                 "views": Tag.views + 1
65                                         })
66
67                 if edited:
68                         db.session.commit()
69
70         if qb.lucky:
71                 package = query.first()
72                 if package:
73                         return redirect(package.getDetailsURL())
74
75                 topic = qb.buildTopicQuery().first()
76                 if qb.search and topic:
77                         return redirect("https://forum.minetest.net/viewtopic.php?t=" + str(topic.topic_id))
78
79         page  = get_int_or_abort(request.args.get("page"), 1)
80         num   = min(40, get_int_or_abort(request.args.get("n"), 100))
81         query = query.paginate(page, num, True)
82
83         search = request.args.get("q")
84         type_name = request.args.get("type")
85
86         authors = []
87         if search:
88                 authors = User.query \
89                         .filter(or_(*[func.lower(User.username) == name.lower().strip() for name in search.split(" ")])) \
90                         .all()
91
92                 authors = [(author.username, search.lower().replace(author.username.lower(), "")) for author in authors]
93
94         topics = None
95         if qb.search and not query.has_next:
96                 qb.show_discarded = True
97                 topics = qb.buildTopicQuery().all()
98
99         tags = db.session.query(func.count(Tags.c.tag_id), Tag) \
100                 .select_from(Tag).outerjoin(Tags).group_by(Tag.id).order_by(db.asc(Tag.title)).all()
101
102         selected_tags = set(qb.tags)
103
104         return render_template("packages/list.html", \
105                         title=title, packages=query.items, pagination=query, \
106                         query=search, tags=tags, selected_tags=selected_tags, type=type_name, \
107                         authors=authors, packages_count=query.total, topics=topics)
108
109
110 def getReleases(package):
111         if package.checkPerm(current_user, Permission.MAKE_RELEASE):
112                 return package.releases.limit(5)
113         else:
114                 return package.releases.filter_by(approved=True).limit(5)
115
116
117 @bp.route("/packages/<author>/<name>/")
118 @is_package_page
119 def view(package):
120         alternatives = None
121         if package.type == PackageType.MOD:
122                 alternatives = Package.query \
123                         .filter_by(name=package.name, type=PackageType.MOD, soft_deleted=False) \
124                         .filter(Package.id != package.id) \
125                         .order_by(db.desc(Package.score)) \
126                         .all()
127
128
129         show_similar_topics = current_user == package.author or \
130                         package.checkPerm(current_user, Permission.APPROVE_NEW)
131
132         similar_topics = None if not show_similar_topics else \
133                         ForumTopic.query \
134                                 .filter_by(name=package.name) \
135                                 .filter(ForumTopic.topic_id != package.forums) \
136                                 .filter(~ db.exists().where(Package.forums==ForumTopic.topic_id)) \
137                                 .order_by(db.asc(ForumTopic.name), db.asc(ForumTopic.title)) \
138                                 .all()
139
140         releases = getReleases(package)
141         requests = [r for r in package.requests if r.status == 0]
142
143         review_thread = package.review_thread
144         if review_thread is not None and not review_thread.checkPerm(current_user, Permission.SEE_THREAD):
145                 review_thread = None
146
147         topic_error = None
148         topic_error_lvl = "warning"
149         if not package.approved and package.forums is not None:
150                 errors = []
151                 if Package.query.filter_by(forums=package.forums, soft_deleted=False).count() > 1:
152                         errors.append("<b>Error: Another package already uses this forum topic!</b>")
153                         topic_error_lvl = "danger"
154
155                 topic = ForumTopic.query.get(package.forums)
156                 if topic is not None:
157                         if topic.author != package.author:
158                                 errors.append("<b>Error: Forum topic author doesn't match package author.</b>")
159                                 topic_error_lvl = "danger"
160
161                         if topic.wip:
162                                 errors.append("Warning: Forum topic is in WIP section, make sure package meets playability standards.")
163                 elif package.type != PackageType.TXP:
164                         errors.append("Warning: Forum topic not found. This may happen if the topic has only just been created.")
165
166                 topic_error = "<br />".join(errors)
167
168
169         threads = Thread.query.filter_by(package_id=package.id, review_id=None)
170         if not current_user.is_authenticated:
171                 threads = threads.filter_by(private=False)
172         elif not current_user.rank.atLeast(UserRank.EDITOR) and not current_user == package.author:
173                 threads = threads.filter(or_(Thread.private == False, Thread.author == current_user))
174
175         has_review = current_user.is_authenticated and PackageReview.query.filter_by(package=package, author=current_user).count() > 0
176
177         return render_template("packages/view.html", \
178                         package=package, releases=releases, requests=requests, \
179                         alternatives=alternatives, similar_topics=similar_topics, \
180                         review_thread=review_thread, topic_error=topic_error, topic_error_lvl=topic_error_lvl, \
181                         threads=threads.all(), has_review=has_review)
182
183
184 @bp.route("/packages/<author>/<name>/download/")
185 @is_package_page
186 def download(package):
187         release = package.getDownloadRelease()
188
189         if release is None:
190                 if "application/zip" in request.accept_mimetypes and \
191                                 not "text/html" in request.accept_mimetypes:
192                         return "", 204
193                 else:
194                         flash("No download available.", "danger")
195                         return redirect(package.getDetailsURL())
196         else:
197                 return redirect(release.getDownloadURL(), code=302)
198
199
200 def makeLabel(obj):
201         if obj.description:
202                 return "{}: {}".format(obj.title, obj.description)
203         else:
204                 return obj.title
205
206 class PackageForm(FlaskForm):
207         name             = StringField("Name (Technical)", [InputRequired(), Length(1, 100), Regexp("^[a-z0-9_]+$", 0, "Lower case letters (a-z), digits (0-9), and underscores (_) only")])
208         title            = StringField("Title (Human-readable)", [InputRequired(), Length(3, 100)])
209         short_desc       = StringField("Short Description (Plaintext)", [InputRequired(), Length(1,200)])
210         desc             = TextAreaField("Long Description (Markdown)", [Optional(), Length(0,10000)])
211         type             = SelectField("Type", [InputRequired()], choices=PackageType.choices(), coerce=PackageType.coerce, default=PackageType.MOD)
212         license          = QuerySelectField("License", [DataRequired()], allow_blank=True, query_factory=lambda: License.query.order_by(db.asc(License.name)), get_pk=lambda a: a.id, get_label=lambda a: a.name)
213         media_license    = QuerySelectField("Media License", [DataRequired()], allow_blank=True, query_factory=lambda: License.query.order_by(db.asc(License.name)), get_pk=lambda a: a.id, get_label=lambda a: a.name)
214         provides_str     = StringField("Provides (mods included in package)", [Optional()])
215         tags             = QuerySelectMultipleField('Tags', query_factory=lambda: Tag.query.order_by(db.asc(Tag.name)), get_pk=lambda a: a.id, get_label=makeLabel)
216         content_warnings = QuerySelectMultipleField('Content Warnings', query_factory=lambda: ContentWarning.query.order_by(db.asc(ContentWarning.name)), get_pk=lambda a: a.id, get_label=makeLabel)
217         harddep_str      = StringField("Hard Dependencies", [Optional()])
218         softdep_str      = StringField("Soft Dependencies", [Optional()])
219         repo             = StringField("VCS Repository URL", [Optional(), URL()], filters = [lambda x: x or None])
220         website          = StringField("Website URL", [Optional(), URL()], filters = [lambda x: x or None])
221         issueTracker     = StringField("Issue Tracker URL", [Optional(), URL()], filters = [lambda x: x or None])
222         forums           = IntegerField("Forum Topic ID", [Optional(), NumberRange(0,999999)])
223         submit           = SubmitField("Save")
224
225
226 @bp.route("/packages/new/", methods=["GET", "POST"])
227 @bp.route("/packages/<author>/<name>/edit/", methods=["GET", "POST"])
228 @login_required
229 def create_edit(author=None, name=None):
230         package = None
231         form = None
232         if author is None:
233                 form = PackageForm(formdata=request.form)
234                 author = request.args.get("author")
235                 if author is None or author == current_user.username:
236                         author = current_user
237                 else:
238                         author = User.query.filter_by(username=author).first()
239                         if author is None:
240                                 flash("Unable to find that user", "danger")
241                                 return redirect(url_for("packages.create_edit"))
242
243                         if not author.checkPerm(current_user, Permission.CHANGE_AUTHOR):
244                                 flash("Permission denied", "danger")
245                                 return redirect(url_for("packages.create_edit"))
246
247         else:
248                 package = getPackageByInfo(author, name)
249                 if not package.checkPerm(current_user, Permission.EDIT_PACKAGE):
250                         return redirect(package.getDetailsURL())
251
252                 author = package.author
253
254                 form = PackageForm(formdata=request.form, obj=package)
255
256         # Initial form class from post data and default data
257         if request.method == "GET":
258                 if package is None:
259                         form.name.data   = request.args.get("bname")
260                         form.title.data  = request.args.get("title")
261                         form.repo.data   = request.args.get("repo")
262                         form.forums.data = request.args.get("forums")
263                         form.license.data = None
264                         form.media_license.data = None
265                 else:
266                         form.harddep_str.data  = ",".join([str(x) for x in package.getSortedHardDependencies() ])
267                         form.softdep_str.data  = ",".join([str(x) for x in package.getSortedOptionalDependencies() ])
268                         form.provides_str.data = MetaPackage.ListToSpec(package.provides)
269                         form.tags.data         = list(package.tags)
270                         form.content_warnings.data = list(package.content_warnings)
271
272         if request.method == "POST" and form.validate():
273                 wasNew = False
274                 if not package:
275                         package = Package.query.filter_by(name=form["name"].data, author_id=author.id).first()
276                         if package is not None:
277                                 if package.soft_deleted:
278                                         Package.query.filter_by(name=form["name"].data, author_id=author.id).delete()
279                                 else:
280                                         flash("Package already exists!", "danger")
281                                         return redirect(url_for("packages.create_edit"))
282
283                         package = Package()
284                         package.author = author
285                         package.maintainers.append(author)
286                         wasNew = True
287
288                 elif package.approved and package.name != form.name.data and \
289                                 not package.checkPerm(current_user, Permission.CHANGE_NAME):
290                         flash("Unable to change package name", "danger")
291                         return redirect(url_for("packages.create_edit", author=author, name=name))
292
293                 else:
294                         msg = "Edited {}".format(package.title)
295
296                         addNotification(package.maintainers, current_user,
297                                         msg, package.getDetailsURL(), package)
298
299                         severity = AuditSeverity.NORMAL if current_user in package.maintainers else AuditSeverity.EDITOR
300                         addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
301
302                 form.populate_obj(package) # copy to row
303
304                 if package.type == PackageType.TXP:
305                         package.license = package.media_license
306
307                 mpackage_cache = {}
308                 package.provides.clear()
309                 mpackages = MetaPackage.SpecToList(form.provides_str.data, mpackage_cache)
310                 for m in mpackages:
311                         package.provides.append(m)
312
313                 Dependency.query.filter_by(depender=package).delete()
314                 deps = Dependency.SpecToList(package, form.harddep_str.data, mpackage_cache)
315                 for dep in deps:
316                         dep.optional = False
317                         db.session.add(dep)
318
319                 deps = Dependency.SpecToList(package, form.softdep_str.data, mpackage_cache)
320                 for dep in deps:
321                         dep.optional = True
322                         db.session.add(dep)
323
324                 if wasNew and package.type == PackageType.MOD and not package.name in mpackage_cache:
325                         m = MetaPackage.GetOrCreate(package.name, mpackage_cache)
326                         package.provides.append(m)
327
328                 package.tags.clear()
329                 for tag in form.tags.raw_data:
330                         package.tags.append(Tag.query.get(tag))
331
332                 package.content_warnings.clear()
333                 for warning in form.content_warnings.raw_data:
334                         package.content_warnings.append(ContentWarning.query.get(warning))
335
336                 db.session.commit() # save
337
338                 next_url = package.getDetailsURL()
339                 if wasNew and package.repo is not None:
340                         task = importRepoScreenshot.delay(package.id)
341                         next_url = url_for("tasks.check", id=task.id, r=next_url)
342
343                 if wasNew and ("WTFPL" in package.license.name or "WTFPL" in package.media_license.name):
344                         next_url = url_for("flatpage", path="help/wtfpl", r=next_url)
345
346                 return redirect(next_url)
347
348         package_query = Package.query.filter_by(approved=True, soft_deleted=False)
349         if package is not None:
350                 package_query = package_query.filter(Package.id != package.id)
351
352         enableWizard = name is None and request.method != "POST"
353         return render_template("packages/create_edit.html", package=package, \
354                         form=form, author=author, enable_wizard=enableWizard, \
355                         packages=package_query.all(), \
356                         mpackages=MetaPackage.query.order_by(db.asc(MetaPackage.name)).all())
357
358 @bp.route("/packages/<author>/<name>/approve/", methods=["POST"])
359 @login_required
360 @is_package_page
361 def approve(package):
362         if not package.checkPerm(current_user, Permission.APPROVE_NEW):
363                 flash("You don't have permission to do that.", "danger")
364
365         elif package.approved:
366                 flash("Package has already been approved", "danger")
367
368         else:
369                 package.approved = True
370                 if not package.approved_at:
371                         package.approved_at = datetime.datetime.now()
372
373                 screenshots = PackageScreenshot.query.filter_by(package=package, approved=False).all()
374                 for s in screenshots:
375                         s.approved = True
376
377                 msg = "Approved {}".format(package.title)
378                 addNotification(package.maintainers, current_user, msg, package.getDetailsURL(), package)
379                 severity = AuditSeverity.NORMAL if current_user == package.author else AuditSeverity.EDITOR
380                 addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
381                 db.session.commit()
382
383         return redirect(package.getDetailsURL())
384
385
386 @bp.route("/packages/<author>/<name>/remove/", methods=["GET", "POST"])
387 @login_required
388 @is_package_page
389 def remove(package):
390         if request.method == "GET":
391                 return render_template("packages/remove.html", package=package)
392
393         if "delete" in request.form:
394                 if not package.checkPerm(current_user, Permission.DELETE_PACKAGE):
395                         flash("You don't have permission to do that.", "danger")
396                         return redirect(package.getDetailsURL())
397
398                 package.soft_deleted = True
399
400                 url = url_for("users.profile", username=package.author.username)
401                 msg = "Deleted {}".format(package.title)
402                 addNotification(package.maintainers, current_user, msg, url, package)
403                 addAuditLog(AuditSeverity.EDITOR, current_user, msg, url)
404                 db.session.commit()
405
406                 flash("Deleted package", "success")
407
408                 return redirect(url)
409         elif "unapprove" in request.form:
410                 if not package.checkPerm(current_user, Permission.UNAPPROVE_PACKAGE):
411                         flash("You don't have permission to do that.", "danger")
412                         return redirect(package.getDetailsURL())
413
414                 package.approved = False
415
416                 msg = "Unapproved {}".format(package.title)
417                 addNotification(package.maintainers, current_user, msg, package.getDetailsURL(), package)
418                 addAuditLog(AuditSeverity.EDITOR, current_user, msg, package.getDetailsURL(), package)
419
420                 db.session.commit()
421
422                 flash("Unapproved package", "success")
423
424                 return redirect(package.getDetailsURL())
425         else:
426                 abort(400)
427
428
429
430 class PackageMaintainersForm(FlaskForm):
431         maintainers_str  = StringField("Maintainers (Comma-separated)", [Optional()])
432         submit        = SubmitField("Save")
433
434
435 @bp.route("/packages/<author>/<name>/edit-maintainers/", methods=["GET", "POST"])
436 @login_required
437 @is_package_page
438 def edit_maintainers(package):
439         if not package.checkPerm(current_user, Permission.EDIT_MAINTAINERS):
440                 flash("You do not have permission to edit maintainers", "danger")
441                 return redirect(package.getDetailsURL())
442
443         form = PackageMaintainersForm(formdata=request.form)
444         if request.method == "GET":
445                 form.maintainers_str.data = ", ".join([ x.username for x in package.maintainers if x != package.author ])
446
447         if request.method == "POST" and form.validate():
448                 usernames = [x.strip().lower() for x in form.maintainers_str.data.split(",")]
449                 users = User.query.filter(func.lower(User.username).in_(usernames)).all()
450
451                 for user in users:
452                         if not user in package.maintainers:
453                                 addNotification(user, current_user,
454                                                 "Added you as a maintainer of {}".format(package.title), package.getDetailsURL(), package)
455
456                 for user in package.maintainers:
457                         if user != package.author and not user in users:
458                                 addNotification(user, current_user,
459                                                 "Removed you as a maintainer of {}".format(package.title), package.getDetailsURL(), package)
460
461                 package.maintainers.clear()
462                 package.maintainers.extend(users)
463                 if package.author not in package.maintainers:
464                         package.maintainers.append(package.author)
465
466                 msg = "Edited {} maintainers".format(package.title)
467                 addNotification(package.author, current_user, msg, package.getDetailsURL(), package)
468                 severity = AuditSeverity.NORMAL if current_user == package.author else AuditSeverity.MODERATION
469                 addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
470
471                 db.session.commit()
472
473                 return redirect(package.getDetailsURL())
474
475         users = User.query.filter(User.rank >= UserRank.NEW_MEMBER).order_by(db.asc(User.username)).all()
476
477         return render_template("packages/edit_maintainers.html", \
478                         package=package, form=form, users=users)
479
480
481 @bp.route("/packages/<author>/<name>/remove-self-maintainer/", methods=["POST"])
482 @login_required
483 @is_package_page
484 def remove_self_maintainers(package):
485         if not current_user in package.maintainers:
486                 flash("You are not a maintainer", "danger")
487
488         elif current_user == package.author:
489                 flash("Package owners cannot remove themselves as maintainers", "danger")
490
491         else:
492                 package.maintainers.remove(current_user)
493
494                 addNotification(package.author, current_user,
495                                 "Removed themself as a maintainer of {}".format(package.title), package.getDetailsURL(), package)
496
497                 db.session.commit()
498
499         return redirect(package.getDetailsURL())
500
501
502 @bp.route("/packages/<author>/<name>/import-meta/", methods=["POST"])
503 @login_required
504 @is_package_page
505 def update_from_release(package):
506         if not package.checkPerm(current_user, Permission.REIMPORT_META):
507                 flash("You don't have permission to reimport meta", "danger")
508                 return redirect(package.getDetailsURL())
509
510         release = package.releases.first()
511         if not release:
512                 flash("Release needed", "danger")
513                 return redirect(package.getDetailsURL())
514
515         msg = "Updated meta from latest release"
516         addNotification(package.maintainers, current_user,
517                         msg, package.getDetailsURL(), package)
518         severity = AuditSeverity.NORMAL if current_user in package.maintainers else AuditSeverity.EDITOR
519         addAuditLog(severity, current_user, msg, package.getDetailsURL(), package)
520
521         db.session.commit()
522
523         task_id = uuid()
524         zippath = release.url.replace("/uploads/", app.config["UPLOAD_DIR"])
525         updateMetaFromRelease.apply_async((release.id, zippath), task_id=task_id)
526
527         return redirect(url_for("tasks.check", id=task_id, r=package.getEditURL()))