2
0

func.py 38 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153
  1. import os
  2. import sys
  3. import platform
  4. for i in range(0, 2):
  5. try:
  6. import werkzeug.routing
  7. import flask_compress
  8. import flask_reggie
  9. import tornado.ioloop
  10. import tornado.httpserver
  11. import tornado.wsgi
  12. import urllib.request
  13. import email.mime.text
  14. import sqlite3
  15. import hashlib
  16. import smtplib
  17. import bcrypt
  18. import zipfile
  19. import difflib
  20. import shutil
  21. import request
  22. import threading
  23. import logging
  24. import random
  25. import flask
  26. import json
  27. import html
  28. import re
  29. try:
  30. import css_html_js_minify
  31. except:
  32. pass
  33. if sys.version_info < (3, 6):
  34. import sha3
  35. from .set_mark.tool import *
  36. from .mark import *
  37. except ImportError as e:
  38. if i == 0:
  39. if platform.system() == 'Linux':
  40. ok = os.system('python3 -m pip install --user -r requirements.txt')
  41. if ok == 0:
  42. os.execl(sys.executable, sys.executable, *sys.argv)
  43. else:
  44. raise
  45. elif platform.system() == 'Windows':
  46. ok = os.system('python -m pip install --user -r requirements.txt')
  47. if ok == 0:
  48. os.execl(sys.executable, sys.executable, *sys.argv)
  49. else:
  50. raise
  51. else:
  52. print('----')
  53. print(e)
  54. raise
  55. else:
  56. print('----')
  57. print(e)
  58. raise
  59. app_var = json.loads(open('data/app_variables.json', encoding='utf-8').read())
  60. def load_conn(data):
  61. global conn
  62. global curs
  63. conn = data
  64. curs = conn.cursor()
  65. load_conn2(data)
  66. def send_email(who, title, data):
  67. smtp = smtplib.SMTP_SSL('smtp.gmail.com', 465)
  68. try:
  69. curs.execute('select name, data from other where name = "g_email" or name = "g_pass"')
  70. rep_data = curs.fetchall()
  71. if rep_data:
  72. g_email = ''
  73. g_pass = ''
  74. for i in rep_data:
  75. if i[0] == 'g_email':
  76. g_email = i[1]
  77. else:
  78. g_pass = i[1]
  79. smtp.login(g_email, g_pass)
  80. msg = email.mime.text.MIMEText(data)
  81. msg['Subject'] = title
  82. smtp.sendmail(g_email, who, msg.as_string())
  83. smtp.quit()
  84. except:
  85. print('----')
  86. print('Error : Email send error')
  87. def last_change(data):
  88. json_address = re.sub("(((?!\.|\/).)+)\.html$", "set.json", skin_check())
  89. try:
  90. json_data = json.loads(open(json_address).read())
  91. except:
  92. json_data = 0
  93. if json_data != 0:
  94. for j_data in json_data:
  95. if "class" in json_data[j_data]:
  96. if "require" in json_data[j_data]:
  97. re_data = re.compile("<((?:" + j_data + ")( (?:(?!>).)*)?)>")
  98. s_data = re_data.findall(data)
  99. for i_data in s_data:
  100. e_data = 0
  101. for j_i_data in json_data[j_data]["require"]:
  102. re_data_2 = re.compile("( |^)" + j_i_data + " *= *[\'\"]" + json_data[j_data]["require"][j_i_data] + "[\'\"]")
  103. if not re_data_2.search(i_data[1]):
  104. re_data_2 = re.compile("( |^)" + j_i_data + "=" + json_data[j_data]["require"][j_i_data] + "(?: |$)")
  105. if not re_data_2.search(i_data[1]):
  106. e_data = 1
  107. break
  108. if e_data == 0:
  109. re_data_3 = re.compile("<" + i_data[0] + ">")
  110. data = re_data_3.sub("<" + i_data[0] + " class=\"" + json_data[j_data]["class"] + "\">", data)
  111. else:
  112. re_data = re.compile("<(?P<in>" + j_data + "(?: (?:(?!>).)*)?)>")
  113. data = re_data.sub("<\g<in> class=\"" + json_data[j_data]["class"] + "\">", data)
  114. return data
  115. def easy_minify(data, tool = None):
  116. try:
  117. if not tool:
  118. data = css_html_js_minify.html_minify(data)
  119. else:
  120. if tool == 'css':
  121. data = css_html_js_minify.css_minify(data)
  122. elif tool == 'js':
  123. data = css_html_js_minify.js_minify(data)
  124. except:
  125. data = re.sub('\n +<', '\n<', data)
  126. data = re.sub('>(\n| )+<', '> <', data)
  127. return last_change(data)
  128. def render_set(title = '', data = '', num = 0, s_data = 0):
  129. if acl_check(title, 'render') == 1:
  130. return 'HTTP Request 401.3'
  131. elif s_data == 1:
  132. return data
  133. else:
  134. return namumark(title, data, num)
  135. def captcha_get():
  136. data = ''
  137. if custom()[2] == 0:
  138. curs.execute('select data from other where name = "recaptcha"')
  139. recaptcha = curs.fetchall()
  140. if recaptcha and recaptcha[0][0] != '':
  141. curs.execute('select data from other where name = "sec_re"')
  142. sec_re = curs.fetchall()
  143. if sec_re and sec_re[0][0] != '':
  144. data += recaptcha[0][0] + '<hr class=\"main_hr\">'
  145. return data
  146. def update():
  147. # v3.0.8 rd, agreedis, stop 테이블 통합
  148. try:
  149. curs.execute("select title, sub, close from stop")
  150. for i in curs.fetchall():
  151. if i[2] == '':
  152. curs.execute("update rd set stop = 'S' where title = ? and sub = ?", [i[0], i[1]])
  153. else:
  154. curs.execute("update rd set stop = 'O' where title = ? and sub = ?", [i[0], i[1]])
  155. except:
  156. pass
  157. try:
  158. curs.execute("select title, sub from agreedis")
  159. for i in curs.fetchall():
  160. curs.execute("update rd set agree = 'O' where title = ? and sub = ?", [i[0], i[1]])
  161. except:
  162. pass
  163. try:
  164. curs.execute("drop table if exists stop")
  165. curs.execute("drop table if exists agreedis")
  166. except:
  167. pass
  168. # Start : Data Migration Code
  169. app_var = json.loads(open(os.path.abspath('./data/app_variables.json'), encoding='utf-8').read())
  170. if os.path.exists('image'):
  171. os.rename('image', app_var['path_data_image'])
  172. if os.path.exists('oauthsettings.json'):
  173. os.rename('oauthsettings.json', app_var['path_oauth_setting'])
  174. try:
  175. load_oauth('discord')
  176. except KeyError:
  177. old_oauth_data = json.loads(open(app_var['path_oauth_setting'], encoding='utf-8').read())
  178. if 'discord' not in old_oauth_data['_README']['support']:
  179. old_oauth_data['_README']['support'] += ['discord']
  180. old_oauth_data['discord'] = {}
  181. old_oauth_data['discord']['client_id'] = ''
  182. old_oauth_data['discord']['client_secret'] = ''
  183. with open(app_var['path_oauth_setting'], 'w') as f:
  184. f.write(json.dumps(old_oauth_data, sort_keys = True, indent = 4))
  185. # End
  186. def pw_encode(data, data2 = '', type_d = ''):
  187. if type_d == '':
  188. curs.execute('select data from other where name = "encode"')
  189. set_data = curs.fetchall()
  190. type_d = set_data[0][0]
  191. if type_d == 'sha256':
  192. return hashlib.sha256(bytes(data, 'utf-8')).hexdigest()
  193. elif type_d == 'sha3':
  194. if sys.version_info < (3, 6):
  195. return sha3.sha3_256(bytes(data, 'utf-8')).hexdigest()
  196. else:
  197. return hashlib.sha3_256(bytes(data, 'utf-8')).hexdigest()
  198. else:
  199. if data2 != '':
  200. salt_data = bytes(data2, 'utf-8')
  201. else:
  202. salt_data = bcrypt.gensalt(11)
  203. return bcrypt.hashpw(bytes(data, 'utf-8'), salt_data).decode()
  204. def pw_check(data, data2, type_d = 'no', id_d = ''):
  205. curs.execute('select data from other where name = "encode"')
  206. db_data = curs.fetchall()
  207. if type_d != 'no':
  208. if type_d == '':
  209. set_data = 'bcrypt'
  210. else:
  211. set_data = type_d
  212. else:
  213. set_data = db_data[0][0]
  214. while 1:
  215. if set_data in ['sha256', 'sha3']:
  216. data3 = pw_encode(data = data, type_d = set_data)
  217. if data3 == data2:
  218. re_data = 1
  219. else:
  220. re_data = 0
  221. break
  222. else:
  223. try:
  224. if pw_encode(data, data2, 'bcrypt') == data2:
  225. re_data = 1
  226. else:
  227. re_data = 0
  228. break
  229. except:
  230. set_data = db_data[0][0]
  231. if db_data[0][0] != set_data and re_data == 1 and id_d != '':
  232. curs.execute("update user set pw = ?, encode = ? where id = ?", [pw_encode(data), db_data[0][0], id_d])
  233. return re_data
  234. def captcha_post(re_data, num = 1):
  235. if num == 1:
  236. if custom()[2] == 0 and captcha_get() != '':
  237. curs.execute('select data from other where name = "sec_re"')
  238. sec_re = curs.fetchall()
  239. if sec_re and sec_re[0][0] != '':
  240. try:
  241. data = urllib.request.urlopen('https://www.google.com/recaptcha/api/siteverify?secret=' + sec_re[0][0] + '&response=' + re_data)
  242. except:
  243. pass
  244. if data and data.getcode() == 200:
  245. json_data = json.loads(data.read().decode(data.headers.get_content_charset()))
  246. if json_data['success'] == True:
  247. return 0
  248. else:
  249. return 1
  250. else:
  251. return 0
  252. else:
  253. return 0
  254. else:
  255. return 0
  256. else:
  257. pass
  258. def load_lang(data, num = 2, safe = 0):
  259. if num == 1:
  260. curs.execute("select data from other where name = 'language'")
  261. rep_data = curs.fetchall()
  262. json_data = open(os.path.join('language', rep_data[0][0] + '.json'), 'rt', encoding='utf-8').read()
  263. lang = json.loads(json_data)
  264. if data in lang:
  265. if safe == 1:
  266. return lang[data]
  267. else:
  268. return html.escape(lang[data])
  269. else:
  270. return html.escape(data + ' (M)')
  271. else:
  272. curs.execute('select data from user_set where name = "lang" and id = ?', [ip_check()])
  273. rep_data = curs.fetchall()
  274. if rep_data:
  275. try:
  276. json_data = open(os.path.join('language', rep_data[0][0] + '.json'), 'rt', encoding='utf-8').read()
  277. lang = json.loads(json_data)
  278. except:
  279. return load_lang(data, 1, safe)
  280. if data in lang:
  281. if safe == 1:
  282. return lang[data]
  283. else:
  284. return html.escape(lang[data])
  285. else:
  286. return load_lang(data, 1, safe)
  287. else:
  288. return load_lang(data, 1, safe)
  289. def load_oauth(provider):
  290. oauth = json.loads(open(app_var['path_oauth_setting'], encoding='utf-8').read())
  291. return oauth[provider]
  292. def update_oauth(provider, target, content):
  293. oauth = json.loads(open(app_var['path_oauth_setting'], encoding='utf-8').read())
  294. oauth[provider][target] = content
  295. with open(app_var['path_oauth_setting'], 'w') as f:
  296. f.write(json.dumps(oauth, sort_keys=True, indent=4))
  297. return 'Done'
  298. def ip_or_user(data):
  299. if re.search('(\.|:)', data):
  300. return 1
  301. else:
  302. return 0
  303. def edit_button():
  304. insert_list = [
  305. ['[[|]]', '[[|]]'],
  306. ['[*()]', '[*()]'],
  307. ['{{{#!}}}', '{{{#!}}}'],
  308. ['||<>||', '||<>||'],
  309. ["\\'\\'\\'", "\'\'\'"]
  310. ]
  311. data = ''
  312. for insert_data in insert_list:
  313. data += '<a href="javascript:insert_data(\'content\', \'' + insert_data[0] + '\')">(' + insert_data[1] + ')</a> '
  314. return data + '<hr class=\"main_hr\">'
  315. def ip_warring():
  316. if custom()[2] == 0:
  317. curs.execute('select data from other where name = "no_login_warring"')
  318. data = curs.fetchall()
  319. if data and data[0][0] != '':
  320. text_data = '<span>' + data[0][0] + '</span><hr class=\"main_hr\">'
  321. else:
  322. text_data = '<span>' + load_lang('no_login_warring') + '</span><hr class=\"main_hr\">'
  323. else:
  324. text_data = ''
  325. return text_data
  326. def skin_check(set_n = 0):
  327. skin = 'neo_yousoro'
  328. curs.execute('select data from other where name = "skin"')
  329. skin_exist = curs.fetchall()
  330. if skin_exist and skin_exist[0][0] != '':
  331. if os.path.exists(os.path.abspath('./views/' + skin_exist[0][0] + '/index.html')) == 1:
  332. skin = skin_exist[0][0]
  333. curs.execute('select data from user_set where name = "skin" and id = ?', [ip_check()])
  334. skin_exist = curs.fetchall()
  335. if skin_exist and skin_exist[0][0] != '':
  336. if os.path.exists(os.path.abspath('./views/' + skin_exist[0][0] + '/index.html')) == 1:
  337. skin = skin_exist[0][0]
  338. if set_n == 0:
  339. return './views/' + skin + '/index.html'
  340. else:
  341. return skin
  342. def next_fix(link, num, page, end = 50):
  343. list_data = ''
  344. if num == 1:
  345. if len(page) == end:
  346. list_data += '<hr class=\"main_hr\"><a href="' + link + str(num + 1) + '">(' + load_lang('next') + ')</a>'
  347. elif len(page) != end:
  348. list_data += '<hr class=\"main_hr\"><a href="' + link + str(num - 1) + '">(' + load_lang('previous') + ')</a>'
  349. else:
  350. list_data += '<hr class=\"main_hr\"><a href="' + link + str(num - 1) + '">(' + load_lang('previous') + ')</a> <a href="' + link + str(num + 1) + '">(' + load_lang('next') + ')</a>'
  351. return list_data
  352. def other2(data):
  353. req_list = ''
  354. for i_data in os.listdir(os.path.join("views", "main_css", "css")):
  355. req_list += '<link rel="stylesheet" href="/views/main_css/css/' + i_data + '">'
  356. for i_data in os.listdir(os.path.join("views", "main_css", "js")):
  357. req_list += '<script src="/views/main_css/js/' + i_data + '"></script>'
  358. data += ['', '''
  359. <link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/9.12.0/styles/default.min.css">
  360. <link rel="stylesheet"
  361. href="https://cdn.jsdelivr.net/npm/katex@0.10.1/dist/katex.min.css"
  362. integrity="sha384-dbVIfZGuN1Yq7/1Ocstc1lUEm+AT+/rCkibIcC/OmWo5f0EA48Vf8CytHzGrSwbQ"
  363. crossorigin="anonymous">
  364. <script src="https://cdn.jsdelivr.net/npm/katex@0.10.1/dist/katex.min.js"
  365. integrity="sha384-2BKqo+exmr9su6dir+qCw08N2ZKRucY4PrGQPPWU1A7FtlCGjmEGFqXCv5nyM5Ij"
  366. crossorigin="anonymous"></script>
  367. <script src="//cdnjs.cloudflare.com/ajax/libs/highlight.js/9.12.0/highlight.min.js"></script>
  368. ''' + req_list]
  369. return data
  370. def cut_100(data):
  371. return re.sub('<(((?!>).)*)>', '', data)[0:100] + '...'
  372. def wiki_set(num = 1):
  373. if num == 1:
  374. data_list = []
  375. curs.execute('select data from other where name = ?', ['name'])
  376. db_data = curs.fetchall()
  377. if db_data and db_data[0][0] != '':
  378. data_list += [db_data[0][0]]
  379. else:
  380. data_list += ['Wiki']
  381. curs.execute('select data from other where name = "license"')
  382. db_data = curs.fetchall()
  383. if db_data and db_data[0][0] != '':
  384. data_list += [db_data[0][0]]
  385. else:
  386. data_list += ['CC 0']
  387. data_list += ['', '']
  388. curs.execute('select data from other where name = "logo"')
  389. db_data = curs.fetchall()
  390. if db_data and db_data[0][0] != '':
  391. data_list += [db_data[0][0]]
  392. else:
  393. data_list += [data_list[0]]
  394. curs.execute("select data from other where name = 'head' and coverage = ?", [skin_check(1)])
  395. db_data = curs.fetchall()
  396. if db_data and db_data[0][0] != '':
  397. data_list += [db_data[0][0]]
  398. else:
  399. curs.execute("select data from other where name = 'head' and coverage = ''")
  400. db_data = curs.fetchall()
  401. if db_data and db_data[0][0] != '':
  402. data_list += [db_data[0][0]]
  403. else:
  404. data_list += ['']
  405. return data_list
  406. if num == 2:
  407. var_data = 'FrontPage'
  408. curs.execute('select data from other where name = "frontpage"')
  409. elif num == 3:
  410. var_data = '2'
  411. curs.execute('select data from other where name = "upload"')
  412. db_data = curs.fetchall()
  413. if db_data and db_data[0][0] != '':
  414. return db_data[0][0]
  415. else:
  416. return var_data
  417. def diff(seqm):
  418. output = []
  419. for opcode, a0, a1, b0, b1 in seqm.get_opcodes():
  420. if opcode == 'equal':
  421. output += [seqm.a[a0:a1]]
  422. elif opcode == 'insert':
  423. output += ["<span style='background:#CFC;'>" + seqm.b[b0:b1] + "</span>"]
  424. elif opcode == 'delete':
  425. output += ["<span style='background:#FDD;'>" + seqm.a[a0:a1] + "</span>"]
  426. elif opcode == 'replace':
  427. output += ["<span style='background:#FDD;'>" + seqm.a[a0:a1] + "</span>"]
  428. output += ["<span style='background:#CFC;'>" + seqm.b[b0:b1] + "</span>"]
  429. end = ''.join(output)
  430. end = end.replace('\r\n', '\n')
  431. sub = ''
  432. if not re.search('\n$', end):
  433. end += '\n'
  434. num = 0
  435. left = 1
  436. while 1:
  437. data = re.search('((?:(?!\n).)*)\n', end)
  438. if data:
  439. data = data.groups()[0]
  440. left += 1
  441. if re.search('<span style=\'(?:(?:(?!\').)+)\'>', data):
  442. num += 1
  443. if re.search('<\/span>', data):
  444. num -= 1
  445. sub += str(left) + ' : ' + re.sub('(?P<in>(?:(?!\n).)*)\n', '\g<in>', data, 1) + '<br>'
  446. else:
  447. if re.search('<\/span>', data):
  448. num -= 1
  449. sub += str(left) + ' : ' + re.sub('(?P<in>(?:(?!\n).)*)\n', '\g<in>', data, 1) + '<br>'
  450. else:
  451. if num > 0:
  452. sub += str(left) + ' : ' + re.sub('(?P<in>.*)\n', '\g<in>', data, 1) + '<br>'
  453. end = re.sub('((?:(?!\n).)*)\n', '', end, 1)
  454. else:
  455. break
  456. return sub
  457. def admin_check(num = None, what = None):
  458. ip = ip_check()
  459. curs.execute("select acl from user where id = ?", [ip])
  460. user = curs.fetchall()
  461. if user:
  462. reset = 0
  463. while 1:
  464. if num == 1 and reset == 0:
  465. check = 'ban'
  466. elif num == 3 and reset == 0:
  467. check = 'toron'
  468. elif num == 4 and reset == 0:
  469. check = 'check'
  470. elif num == 5 and reset == 0:
  471. check = 'acl'
  472. elif num == 6 and reset == 0:
  473. check = 'hidel'
  474. elif num == 7 and reset == 0:
  475. check = 'give'
  476. else:
  477. check = 'owner'
  478. curs.execute('select name from alist where name = ? and acl = ?', [user[0][0], check])
  479. if curs.fetchall():
  480. if what:
  481. curs.execute("insert into re_admin (who, what, time) values (?, ?, ?)", [ip, what, get_time()])
  482. conn.commit()
  483. return 1
  484. else:
  485. if reset == 0:
  486. reset = 1
  487. else:
  488. break
  489. return 0
  490. def ip_pas(raw_ip):
  491. hide = 0
  492. if re.search("(\.|:)", raw_ip):
  493. curs.execute("select data from other where name = 'ip_view'")
  494. data = curs.fetchall()
  495. if data and data[0][0] != '':
  496. ip = '<span style="font-size: 75%;">' + hashlib.md5(bytes(raw_ip, 'utf-8')).hexdigest() + '</span>'
  497. if not admin_check(1):
  498. hide = 1
  499. else:
  500. ip = raw_ip
  501. else:
  502. curs.execute("select title from data where title = ?", ['user:' + raw_ip])
  503. if curs.fetchall():
  504. ip = '<a href="/w/' + url_pas('user:' + raw_ip) + '">' + raw_ip + '</a>'
  505. else:
  506. ip = '<a id="not_thing" href="/w/' + url_pas('user:' + raw_ip) + '">' + raw_ip + '</a>'
  507. if hide == 0:
  508. ip += ' <a href="/tool/' + url_pas(raw_ip) + '">(' + load_lang('tool') + ')</a>'
  509. return ip
  510. def custom():
  511. if 'head' in flask.session:
  512. user_head = flask.session['head']
  513. else:
  514. user_head = ''
  515. ip = ip_check()
  516. if ip_or_user(ip) == 0:
  517. curs.execute('select name from alarm where name = ? limit 1', [ip])
  518. if curs.fetchall():
  519. user_icon = 2
  520. else:
  521. user_icon = 1
  522. else:
  523. user_icon = 0
  524. if user_icon != 0:
  525. curs.execute('select data from user_set where name = "email" and id = ?', [ip])
  526. data = curs.fetchall()
  527. if data:
  528. email = data[0][0]
  529. else:
  530. email = ''
  531. else:
  532. email = ''
  533. if user_icon != 0:
  534. user_name = ip
  535. else:
  536. user_name = load_lang('user')
  537. return ['', '', user_icon, user_head, email, user_name]
  538. def load_skin(data = '', set_n = 0):
  539. div2 = ''
  540. div3 = []
  541. system_file = ['main_css', 'easter_egg.html']
  542. if data == '':
  543. ip = ip_check()
  544. curs.execute('select data from user_set where name = "skin" and id = ?', [ip])
  545. data = curs.fetchall()
  546. if not data:
  547. curs.execute('select data from other where name = "skin"')
  548. data = curs.fetchall()
  549. if not data:
  550. data = [['neo_yousoro']]
  551. if set_n == 0:
  552. for skin_data in os.listdir(os.path.abspath('views')):
  553. if not skin_data in system_file:
  554. if data[0][0] == skin_data:
  555. div2 = '<option value="' + skin_data + '">' + skin_data + '</option>' + div2
  556. else:
  557. div2 += '<option value="' + skin_data + '">' + skin_data + '</option>'
  558. else:
  559. div2 = []
  560. for skin_data in os.listdir(os.path.abspath('views')):
  561. if not skin_data in system_file:
  562. if data[0][0] == skin_data:
  563. div2 = [skin_data] + div2
  564. else:
  565. div2 += [skin_data]
  566. else:
  567. if set_n == 0:
  568. for skin_data in os.listdir(os.path.abspath('views')):
  569. if not skin_data in system_file:
  570. if data == skin_data:
  571. div2 = '<option value="' + skin_data + '">' + skin_data + '</option>' + div2
  572. else:
  573. div2 += '<option value="' + skin_data + '">' + skin_data + '</option>'
  574. else:
  575. div2 = []
  576. for skin_data in os.listdir(os.path.abspath('views')):
  577. if not skin_data in system_file:
  578. if data == skin_data:
  579. div2 = [skin_data] + div2
  580. else:
  581. div2 += [skin_data]
  582. return div2
  583. def acl_check(name, tool = ''):
  584. ip = ip_check()
  585. if tool == 'render':
  586. curs.execute("select view from acl where title = ?", [name])
  587. acl_data = curs.fetchall()
  588. if acl_data:
  589. if acl_data[0][0] == 'user':
  590. if ip_or_user(ip) == 1:
  591. return 1
  592. if acl_data[0][0] == '50_edit':
  593. if ip_or_user(ip) == 1:
  594. return 1
  595. if admin_check(5, 'view (' + name + ')') != 1:
  596. curs.execute("select count(title) from history where ip = ?", [ip])
  597. count = curs.fetchall()
  598. if count:
  599. count = count[0][0]
  600. else:
  601. count = 0
  602. if count < 50:
  603. return 1
  604. if acl_data[0][0] == 'admin':
  605. if ip_or_user(ip) == 1:
  606. return 1
  607. if admin_check(5, 'view (' + name + ')') != 1:
  608. return 1
  609. return 0
  610. else:
  611. if ban_check() == 1:
  612. return 1
  613. acl_c = re.search("^user:((?:(?!\/).)*)", name)
  614. if acl_c:
  615. acl_n = acl_c.groups()
  616. if admin_check(5) == 1:
  617. return 0
  618. curs.execute("select dec from acl where title = ?", ['user:' + acl_n[0]])
  619. acl_data = curs.fetchall()
  620. if acl_data:
  621. if acl_data[0][0] == 'all':
  622. return 0
  623. if acl_data[0][0] == 'user' and not re.search("(\.|:)", ip):
  624. return 0
  625. if ip != acl_n[0] or re.search("(\.|:)", ip):
  626. return 1
  627. if ip == acl_n[0] and not re.search("(\.|:)", ip) and not re.search("(\.|:)", acl_n[0]):
  628. return 0
  629. else:
  630. return 1
  631. if re.search("^file:", name) and admin_check(None, 'file edit (' + name + ')') != 1:
  632. return 1
  633. curs.execute("select dec from acl where title = ?", [name])
  634. acl_data = curs.fetchall()
  635. if acl_data:
  636. if acl_data[0][0] == 'user':
  637. if ip_or_user(ip) == 1:
  638. return 1
  639. if acl_data[0][0] == 'admin':
  640. if ip_or_user(ip) == 1:
  641. return 1
  642. if admin_check(5, 'topic send (' + name + ')') != 1:
  643. return 1
  644. if acl_data[0][0] == '50_edit':
  645. if ip_or_user(ip) == 1:
  646. return 1
  647. if admin_check(5, 'topic send (' + name + ')') != 1:
  648. curs.execute("select count(title) from history where ip = ?", [ip])
  649. count = curs.fetchall()
  650. if count:
  651. count = count[0][0]
  652. else:
  653. count = 0
  654. if count < 50:
  655. return 1
  656. curs.execute('select data from other where name = "edit"')
  657. set_data = curs.fetchall()
  658. if set_data:
  659. if set_data[0][0] == 'login':
  660. if ip_or_user(ip) == 1:
  661. return 1
  662. if set_data[0][0] == 'admin':
  663. if ip_or_user(ip) == 1:
  664. return 1
  665. if admin_check(5, 'edit (' + name + ')') != 1:
  666. return 1
  667. if set_data[0][0] == '50_edit':
  668. if ip_or_user(ip) == 1:
  669. return 1
  670. if admin_check(5, 'edit (' + name + ')') != 1:
  671. curs.execute("select count(title) from history where ip = ?", [ip])
  672. count = curs.fetchall()
  673. if count:
  674. count = count[0][0]
  675. else:
  676. count = 0
  677. if count < 50:
  678. return 1
  679. return 0
  680. def ban_check(ip = None, tool = None):
  681. if not ip:
  682. ip = ip_check()
  683. band = re.search("^([0-9]{1,3}\.[0-9]{1,3})", ip)
  684. if band:
  685. band_it = band.groups()[0]
  686. else:
  687. band_it = '-'
  688. curs.execute("delete from ban where (end < ? and end like '2%')", [get_time()])
  689. conn.commit()
  690. curs.execute("select login, block from ban where ((end > ? and end like '2%') or end = '') and band = 'regex'", [get_time()])
  691. regex_d = curs.fetchall()
  692. for test_r in regex_d:
  693. g_regex = re.compile(test_r[1])
  694. if g_regex.search(ip):
  695. if tool and tool == 'login':
  696. if test_r[0] != 'O':
  697. return 1
  698. else:
  699. return 1
  700. curs.execute("select login from ban where ((end > ? and end like '2%') or end = '') and block = ? and band = 'O'", [get_time(), band_it])
  701. band_d = curs.fetchall()
  702. if band_d:
  703. if tool and tool == 'login':
  704. if data[0][0] != 'O':
  705. return 1
  706. else:
  707. return 1
  708. curs.execute("select login from ban where ((end > ? and end like '2%') or end = '') and block = ? and band = ''", [get_time(), ip])
  709. ban_d = curs.fetchall()
  710. if ban_d:
  711. if tool and tool == 'login':
  712. if data[0][0] != 'O':
  713. return 1
  714. else:
  715. return 1
  716. return 0
  717. def topic_check(name, sub):
  718. ip = ip_check()
  719. if ban_check() == 1:
  720. return 1
  721. curs.execute('select data from other where name = "discussion"')
  722. acl_data = curs.fetchall()
  723. if acl_data:
  724. if acl_data[0][0] == 'login':
  725. if ip_or_user(ip) == 1:
  726. return 1
  727. if acl_data[0][0] == 'admin':
  728. if ip_or_user(ip) == 1:
  729. return 1
  730. if admin_check(3, 'topic (' + name + ')') != 1:
  731. return 1
  732. curs.execute("select dis from acl where title = ?", [name])
  733. acl_data = curs.fetchall()
  734. if acl_data:
  735. if acl_data[0][0] == 'user':
  736. if ip_or_user(ip) == 1:
  737. return 1
  738. if acl_data[0][0] == '50_edit':
  739. if ip_or_user(ip) == 1:
  740. return 1
  741. if admin_check(3, 'topic (' + name + ')') != 1:
  742. curs.execute("select count(title) from history where ip = ?", [ip])
  743. count = curs.fetchall()
  744. if count:
  745. count = count[0][0]
  746. else:
  747. count = 0
  748. if count < 50:
  749. return 1
  750. if acl_data[0][0] == 'admin':
  751. if ip_or_user(ip) == 1:
  752. return 1
  753. if admin_check(3, 'topic (' + name + ')') != 1:
  754. return 1
  755. curs.execute("select title from rd where title = ? and sub = ? and not stop = ''", [name, sub])
  756. if curs.fetchall():
  757. if admin_check(3, 'topic (' + name + ')') != 1:
  758. return 1
  759. return 0
  760. def ban_insert(name, end, why, login, blocker, type_d = None):
  761. now_time = get_time()
  762. if type_d:
  763. band = type_d
  764. else:
  765. if re.search("^([0-9]{1,3}\.[0-9]{1,3})$", name):
  766. band = 'O'
  767. else:
  768. band = ''
  769. curs.execute("delete from ban where (end < ? and end like '2%')", [get_time()])
  770. curs.execute("select block from ban where ((end > ? and end like '2%') or end = '') and block = ? and band = ?", [get_time(), name, band])
  771. if curs.fetchall():
  772. curs.execute("insert into rb (block, end, today, blocker, why, band) values (?, ?, ?, ?, ?, ?)", [
  773. name,
  774. 'release',
  775. now_time,
  776. blocker,
  777. '',
  778. band
  779. ])
  780. curs.execute("delete from ban where block = ? and band = ?", [name, band])
  781. else:
  782. if login != '':
  783. login = 'O'
  784. else:
  785. login = ''
  786. if end != '0':
  787. end = int(number_check(end))
  788. time = datetime.datetime.now()
  789. plus = datetime.timedelta(seconds = end)
  790. r_time = (time + plus).strftime("%Y-%m-%d %H:%M:%S")
  791. else:
  792. r_time = ''
  793. curs.execute("insert into rb (block, end, today, blocker, why, band) values (?, ?, ?, ?, ?, ?)", [name, r_time, now_time, blocker, why, band])
  794. curs.execute("insert into ban (block, end, why, band, login) values (?, ?, ?, ?, ?)", [name, r_time, why, band, login])
  795. conn.commit()
  796. def rd_plus(title, sub, date):
  797. curs.execute("select title from rd where title = ? and sub = ?", [title, sub])
  798. if curs.fetchall():
  799. curs.execute("update rd set date = ? where title = ? and sub = ?", [date, title, sub])
  800. else:
  801. curs.execute("insert into rd (title, sub, date) values (?, ?, ?)", [title, sub, date])
  802. def history_plus(title, data, date, ip, send, leng, t_check = ''):
  803. curs.execute("select id from history where title = ? order by id + 0 desc limit 1", [title])
  804. id_data = curs.fetchall()
  805. send = re.sub('\(|\)|<|>', '', send)
  806. if len(send) > 128:
  807. send = send[:128]
  808. if t_check != '':
  809. send += ' (' + t_check + ')'
  810. curs.execute("insert into history (id, title, data, date, ip, send, leng, hide) values (?, ?, ?, ?, ?, ?, ?, '')", [
  811. str(int(id_data[0][0]) + 1) if id_data else '1',
  812. title,
  813. data,
  814. date,
  815. ip,
  816. send,
  817. leng
  818. ])
  819. def leng_check(first, second):
  820. if first < second:
  821. all_plus = '+' + str(second - first)
  822. elif second < first:
  823. all_plus = '-' + str(first - second)
  824. else:
  825. all_plus = '0'
  826. return all_plus
  827. def number_check(data):
  828. if not data:
  829. return '1'
  830. else:
  831. if re.search('[^0-9]', data):
  832. return '1'
  833. else:
  834. return data
  835. def edit_filter_do(data):
  836. if admin_check(1, 'edit_filter pass') != 1:
  837. curs.execute("select regex, sub from filter")
  838. for data_list in curs.fetchall():
  839. match = re.compile(data_list[0], re.I)
  840. if match.search(data):
  841. ban_insert(
  842. ip_check(),
  843. '0' if data_list[1] == 'X' else data_list[1],
  844. 'edit filter',
  845. None,
  846. 'tool:edit filter'
  847. )
  848. return 1
  849. return 0
  850. def redirect(data = '/'):
  851. return flask.redirect(data)
  852. def re_error(data):
  853. conn.commit()
  854. if data == '/ban':
  855. ip = ip_check()
  856. end = '<li>' + load_lang('why') + ' : ' + load_lang('authority_error') + '</li>'
  857. if ban_check() == 1:
  858. end = '<li>' + load_lang('state') + ' : ' + load_lang('ban') + '</li>'
  859. ok_sign = 1
  860. band = re.search("^([0-9]{1,3}\.[0-9]{1,3})", ip)
  861. if band:
  862. band_it = band.groups()[0]
  863. else:
  864. band_it = '-'
  865. curs.execute("delete from ban where (end < ? and end like '2%')", [get_time()])
  866. conn.commit()
  867. curs.execute("select login, block, end from ban where ((end > ? and end like '2%') or end = '') and band = 'regex'", [get_time()])
  868. regex_d = curs.fetchall()
  869. for test_r in regex_d:
  870. g_regex = re.compile(test_r[1])
  871. if g_regex.search(ip):
  872. end += '<li>' + load_lang('type') + ' : regex ban</li>'
  873. end += '<li>' + load_lang('end') + ' : ' + test_r[2] + '</li>'
  874. if test_r[0] != 'O':
  875. end += '<li>' + load_lang('login_able') + ' (' + load_lang('not_sure') + ')</li>'
  876. end += '<hr class=\"main_hr\">'
  877. curs.execute("select login, end from ban where ((end > ? and end like '2%') or end = '') and block = ?", [get_time(), band_it])
  878. band_d = curs.fetchall()
  879. if band_d:
  880. end += '<li>' + load_lang('type') + ' : band ban</li>'
  881. end += '<li>' + load_lang('end') + ' : ' + band_d[0][1] + '</li>'
  882. if data[0][0] != 'O':
  883. end += '<li>' + load_lang('login_able') + ' (' + load_lang('not_sure') + ')</li>'
  884. end += '<hr class=\"main_hr\">'
  885. curs.execute("select login, end from ban where ((end > ? and end like '2%') or end = '') and block = ?", [get_time(), ip])
  886. ban_d = curs.fetchall()
  887. if ban_d:
  888. end += '<li>' + load_lang('type') + ' : ban</li>'
  889. end += '<li>' + load_lang('end') + ' : ' + ban_d[0][1] + '</li>'
  890. if data[0][0] != 'O':
  891. end += '<li>' + load_lang('login_able') + ' (' + load_lang('not_sure') + ')</li>'
  892. end += '<hr class=\"main_hr\">'
  893. return easy_minify(flask.render_template(skin_check(),
  894. imp = [load_lang('error'), wiki_set(1), custom(), other2([0, 0])],
  895. data = '<h2>' + load_lang('error') + '</h2><ul>' + end + '</ul>',
  896. menu = 0
  897. ))
  898. else:
  899. error_data = re.search('\/error\/([0-9]+)', data)
  900. if error_data:
  901. num = int(error_data.groups()[0])
  902. if num == 1:
  903. data = load_lang('no_login_error')
  904. elif num == 2:
  905. data = load_lang('no_exist_user_error')
  906. elif num == 3:
  907. data = load_lang('authority_error')
  908. elif num == 4:
  909. data = load_lang('no_admin_block_error')
  910. elif num == 6:
  911. data = load_lang('same_id_exist_error')
  912. elif num == 7:
  913. data = load_lang('long_id_error')
  914. elif num == 8:
  915. data = load_lang('id_char_error') + ' <a href="/name_filter">(' + load_lang('id') + ' ' + load_lang('filter') + ')</a>'
  916. elif num == 9:
  917. data = load_lang('file_exist_error')
  918. elif num == 10:
  919. data = load_lang('password_error')
  920. elif num == 11:
  921. data = load_lang('topic_long_error')
  922. elif num == 12:
  923. data = load_lang('email_error')
  924. elif num == 13:
  925. data = load_lang('recaptcha_error')
  926. elif num == 14:
  927. data = load_lang('file_extension_error')
  928. elif num == 15:
  929. data = load_lang('edit_record_error')
  930. elif num == 16:
  931. data = load_lang('same_file_error')
  932. elif num == 17:
  933. data = load_lang('file_capacity_error') + ' ' + wiki_set(3)
  934. elif num == 19:
  935. data = load_lang('decument_exist_error')
  936. elif num == 20:
  937. data = load_lang('password_diffrent_error')
  938. elif num == 21:
  939. data = load_lang('edit_filter_error')
  940. elif num == 22:
  941. data = load_lang('file_name_error')
  942. elif num == 23:
  943. data = load_lang('regex_error')
  944. else:
  945. data = '???'
  946. return easy_minify(flask.render_template(skin_check(),
  947. imp = [load_lang('error'), wiki_set(1), custom(), other2([0, 0])],
  948. data = '<h2>' + load_lang('error') + '</h2><ul><li>' + data + '</li></ul>',
  949. menu = 0
  950. ))
  951. else:
  952. return redirect('/')