func.py 37 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145
  1. import os
  2. import sys
  3. import platform
  4. for i in range(0, 2):
  5. try:
  6. import werkzeug.routing
  7. import werkzeug.debug
  8. import flask_compress
  9. import flask_reggie
  10. import tornado.ioloop
  11. import tornado.httpserver
  12. import tornado.wsgi
  13. import urllib.request
  14. import email.mime.text
  15. import sqlite3
  16. import pymysql
  17. import hashlib
  18. import smtplib
  19. import bcrypt
  20. import zipfile
  21. import difflib
  22. import shutil
  23. import threading
  24. import logging
  25. import random
  26. import flask
  27. import json
  28. import html
  29. import re
  30. if sys.version_info < (3, 6):
  31. import sha3
  32. from .set_mark.tool import *
  33. from .mark import *
  34. except ImportError as e:
  35. if i == 0:
  36. print(e)
  37. print('----')
  38. if platform.system() == 'Linux':
  39. ok = os.system('python3 -m pip install --user -r requirements.txt')
  40. if ok == 0:
  41. print('----')
  42. os.execl(sys.executable, sys.executable, *sys.argv)
  43. else:
  44. raise
  45. elif platform.system() == 'Windows':
  46. ok = os.system('python -m pip install --user -r requirements.txt')
  47. if ok == 0:
  48. print('----')
  49. os.execl(sys.executable, sys.executable, *sys.argv)
  50. else:
  51. raise
  52. else:
  53. print('----')
  54. print(e)
  55. raise
  56. else:
  57. print('----')
  58. print(e)
  59. raise
  60. app_var = json.loads(open('data/app_var.json', encoding='utf-8').read())
  61. def load_conn(data):
  62. global conn
  63. global curs
  64. conn = data
  65. curs = conn.cursor()
  66. load_conn2(data)
  67. def send_email(who, title, data):
  68. smtp = smtplib.SMTP_SSL('smtp.gmail.com', 465)
  69. try:
  70. curs.execute('select name, data from other where name = "g_email" or name = "g_pass"')
  71. rep_data = curs.fetchall()
  72. if rep_data:
  73. g_email = ''
  74. g_pass = ''
  75. for i in rep_data:
  76. if i[0] == 'g_email':
  77. g_email = i[1]
  78. else:
  79. g_pass = i[1]
  80. smtp.login(g_email, g_pass)
  81. msg = email.mime.text.MIMEText(data)
  82. msg['Subject'] = title
  83. smtp.sendmail(g_email, who, msg.as_string())
  84. smtp.quit()
  85. except:
  86. print('----')
  87. print('Error : Email send error')
  88. def last_change(data):
  89. json_address = re.sub("(((?!\.|\/).)+)\.html$", "set.json", skin_check())
  90. try:
  91. json_data = json.loads(open(json_address).read())
  92. except:
  93. json_data = 0
  94. if json_data != 0:
  95. for j_data in json_data:
  96. if "class" in json_data[j_data]:
  97. if "require" in json_data[j_data]:
  98. re_data = re.compile("<((?:" + j_data + ")( (?:(?!>).)*)?)>")
  99. s_data = re_data.findall(data)
  100. for i_data in s_data:
  101. e_data = 0
  102. for j_i_data in json_data[j_data]["require"]:
  103. re_data_2 = re.compile("( |^)" + j_i_data + " *= *[\'\"]" + json_data[j_data]["require"][j_i_data] + "[\'\"]")
  104. if not re_data_2.search(i_data[1]):
  105. re_data_2 = re.compile("( |^)" + j_i_data + "=" + json_data[j_data]["require"][j_i_data] + "(?: |$)")
  106. if not re_data_2.search(i_data[1]):
  107. e_data = 1
  108. break
  109. if e_data == 0:
  110. re_data_3 = re.compile("<" + i_data[0] + ">")
  111. data = re_data_3.sub("<" + i_data[0] + " class=\"" + json_data[j_data]["class"] + "\">", data)
  112. else:
  113. re_data = re.compile("<(?P<in>" + j_data + "(?: (?:(?!>).)*)?)>")
  114. data = re_data.sub("<\g<in> class=\"" + json_data[j_data]["class"] + "\">", data)
  115. return data
  116. def easy_minify(data, tool = None):
  117. return last_change(data)
  118. def render_set(title = '', data = '', num = 0, s_data = 0, include = None):
  119. if acl_check(title, 'render') == 1:
  120. return 'HTTP Request 401.3'
  121. elif s_data == 1:
  122. return data
  123. else:
  124. if data != None:
  125. return namumark(title, data, num, include)
  126. else:
  127. return 'HTTP Request 404'
  128. def captcha_get():
  129. data = ''
  130. if ip_or_user() != 0:
  131. curs.execute('select data from other where name = "recaptcha"')
  132. recaptcha = curs.fetchall()
  133. if recaptcha and recaptcha[0][0] != '':
  134. curs.execute('select data from other where name = "sec_re"')
  135. sec_re = curs.fetchall()
  136. if sec_re and sec_re[0][0] != '':
  137. data += recaptcha[0][0] + '<hr class=\"main_hr\">'
  138. return data
  139. def update():
  140. #v3.1.2
  141. try:
  142. curs.execute('select title, dec from acl where dec != ""')
  143. db_data = curs.fetchall()
  144. for i in db_data:
  145. curs.execute("update acl set decu = ? where title = ?", [i[1], i[0]])
  146. print('Fix table acl column dec to decu')
  147. print('----')
  148. except:
  149. pass
  150. conn.commit()
  151. def pw_encode(data, data2 = '', type_d = ''):
  152. if type_d == '':
  153. curs.execute('select data from other where name = "encode"')
  154. set_data = curs.fetchall()
  155. type_d = set_data[0][0]
  156. if type_d == 'sha256':
  157. return hashlib.sha256(bytes(data, 'utf-8')).hexdigest()
  158. elif type_d == 'sha3':
  159. if sys.version_info < (3, 6):
  160. return sha3.sha3_256(bytes(data, 'utf-8')).hexdigest()
  161. else:
  162. return hashlib.sha3_256(bytes(data, 'utf-8')).hexdigest()
  163. else:
  164. if data2 != '':
  165. salt_data = bytes(data2, 'utf-8')
  166. else:
  167. salt_data = bcrypt.gensalt(11)
  168. return bcrypt.hashpw(bytes(data, 'utf-8'), salt_data).decode()
  169. def pw_check(data, data2, type_d = 'no', id_d = ''):
  170. curs.execute('select data from other where name = "encode"')
  171. db_data = curs.fetchall()
  172. if type_d != 'no':
  173. if type_d == '':
  174. set_data = 'bcrypt'
  175. else:
  176. set_data = type_d
  177. else:
  178. set_data = db_data[0][0]
  179. while 1:
  180. if set_data in ['sha256', 'sha3']:
  181. data3 = pw_encode(data = data, type_d = set_data)
  182. if data3 == data2:
  183. re_data = 1
  184. else:
  185. re_data = 0
  186. break
  187. else:
  188. try:
  189. if pw_encode(data, data2, 'bcrypt') == data2:
  190. re_data = 1
  191. else:
  192. re_data = 0
  193. break
  194. except:
  195. set_data = db_data[0][0]
  196. if db_data[0][0] != set_data and re_data == 1 and id_d != '':
  197. curs.execute("update user set pw = ?, encode = ? where id = ?", [pw_encode(data), db_data[0][0], id_d])
  198. return re_data
  199. def captcha_post(re_data, num = 1):
  200. if num == 1:
  201. if ip_or_user() != 0 and captcha_get() != '':
  202. curs.execute('select data from other where name = "sec_re"')
  203. sec_re = curs.fetchall()
  204. if sec_re and sec_re[0][0] != '':
  205. try:
  206. data = urllib.request.urlopen('https://www.google.com/recaptcha/api/siteverify?secret=' + sec_re[0][0] + '&response=' + re_data)
  207. except:
  208. pass
  209. if data and data.getcode() == 200:
  210. json_data = json.loads(data.read().decode(data.headers.get_content_charset()))
  211. if json_data['success'] == True:
  212. return 0
  213. else:
  214. return 1
  215. else:
  216. return 0
  217. else:
  218. return 0
  219. else:
  220. return 0
  221. else:
  222. pass
  223. def load_lang(data, num = 2, safe = 0):
  224. if num == 1:
  225. curs.execute("select data from other where name = 'language'")
  226. rep_data = curs.fetchall()
  227. json_data = open(os.path.join('language', rep_data[0][0] + '.json'), 'rt', encoding='utf-8').read()
  228. lang = json.loads(json_data)
  229. if data in lang:
  230. if safe == 1:
  231. return lang[data]
  232. else:
  233. return html.escape(lang[data])
  234. else:
  235. return html.escape(data + ' (M)')
  236. else:
  237. curs.execute('select data from user_set where name = "lang" and id = ?', [ip_check()])
  238. rep_data = curs.fetchall()
  239. if rep_data:
  240. try:
  241. json_data = open(os.path.join('language', rep_data[0][0] + '.json'), 'rt', encoding='utf-8').read()
  242. lang = json.loads(json_data)
  243. except:
  244. return load_lang(data, 1, safe)
  245. if data in lang:
  246. if safe == 1:
  247. return lang[data]
  248. else:
  249. return html.escape(lang[data])
  250. else:
  251. return load_lang(data, 1, safe)
  252. else:
  253. return load_lang(data, 1, safe)
  254. def load_oauth(provider):
  255. oauth = json.loads(open(app_var['path_oauth_setting'], encoding='utf-8').read())
  256. return oauth[provider]
  257. def update_oauth(provider, target, content):
  258. oauth = json.loads(open(app_var['path_oauth_setting'], encoding='utf-8').read())
  259. oauth[provider][target] = content
  260. with open(app_var['path_oauth_setting'], 'w') as f:
  261. f.write(json.dumps(oauth, sort_keys=True, indent=4))
  262. return 'Done'
  263. def ip_or_user(data = ''):
  264. if data == '':
  265. data = ip_check()
  266. if re.search('(\.|:)', data):
  267. return 1
  268. else:
  269. return 0
  270. def edit_button():
  271. insert_list = []
  272. curs.execute("select html, plus from html_filter where kind = 'edit_top'")
  273. db_data = curs.fetchall()
  274. for get_data in db_data:
  275. insert_list += [[get_data[1], get_data[0]]]
  276. data = ''
  277. for insert_data in insert_list:
  278. data += '<a href="javascript:do_insert_data(\'content\', \'' + insert_data[0] + '\')">(' + insert_data[1] + ')</a> '
  279. if admin_check() == 1:
  280. data += (' ' if data != '' else '') + '<a href="/edit_top">(' + load_lang('add') + ')</a>'
  281. return data + '<hr class=\"main_hr\">'
  282. def ip_warring():
  283. if ip_or_user() != 0:
  284. curs.execute('select data from other where name = "no_login_warring"')
  285. data = curs.fetchall()
  286. if data and data[0][0] != '':
  287. text_data = '<span>' + data[0][0] + '</span><hr class=\"main_hr\">'
  288. else:
  289. text_data = '<span>' + load_lang('no_login_warring') + '</span><hr class=\"main_hr\">'
  290. else:
  291. text_data = ''
  292. return text_data
  293. def skin_check(set_n = 0):
  294. skin = 'marisa'
  295. curs.execute('select data from other where name = "skin"')
  296. skin_exist = curs.fetchall()
  297. if skin_exist and skin_exist[0][0] != '':
  298. if os.path.exists(os.path.abspath('./views/' + skin_exist[0][0] + '/index.html')) == 1:
  299. skin = skin_exist[0][0]
  300. curs.execute('select data from user_set where name = "skin" and id = ?', [ip_check()])
  301. skin_exist = curs.fetchall()
  302. if skin_exist and skin_exist[0][0] != '':
  303. if os.path.exists(os.path.abspath('./views/' + skin_exist[0][0] + '/index.html')) == 1:
  304. skin = skin_exist[0][0]
  305. if set_n == 0:
  306. return './views/' + skin + '/index.html'
  307. else:
  308. return skin
  309. def next_fix(link, num, page, end = 50):
  310. list_data = ''
  311. if num == 1:
  312. if len(page) == end:
  313. list_data += '<hr class=\"main_hr\"><a href="' + link + str(num + 1) + '">(' + load_lang('next') + ')</a>'
  314. elif len(page) != end:
  315. list_data += '<hr class=\"main_hr\"><a href="' + link + str(num - 1) + '">(' + load_lang('previous') + ')</a>'
  316. else:
  317. list_data += '<hr class=\"main_hr\"><a href="' + link + str(num - 1) + '">(' + load_lang('previous') + ')</a> <a href="' + link + str(num + 1) + '">(' + load_lang('next') + ')</a>'
  318. return list_data
  319. def other2(data):
  320. req_list = ''
  321. css_filter = {
  322. 'main.css' : '2'
  323. }
  324. for i_data in os.listdir(os.path.join("views", "main_css", "css")):
  325. if i_data in css_filter:
  326. req_list += '<link rel="stylesheet" href="/views/main_css/css/' + i_data + '?ver=' + css_filter[i_data] + '">'
  327. else:
  328. req_list += '<link rel="stylesheet" href="/views/main_css/css/' + i_data + '?ver=1">'
  329. js_filter = {
  330. 'load_include.js' : '2',
  331. 'render_html.js' : '2',
  332. 'do_open_foot.js' : '4',
  333. 'topic_main_load.js' : '2',
  334. 'topic_plus_load.js' : '2',
  335. 'do_stop_exit.js' : '2'
  336. }
  337. for i_data in os.listdir(os.path.join("views", "main_css", "js")):
  338. if i_data in js_filter:
  339. req_list += '<script src="/views/main_css/js/' + i_data + '?ver=' + js_filter[i_data] + '"></script>'
  340. else:
  341. req_list += '<script src="/views/main_css/js/' + i_data + '?ver=1"></script>'
  342. data += ['', '''
  343. <link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/9.12.0/styles/default.min.css">
  344. <link rel="stylesheet"
  345. href="https://cdn.jsdelivr.net/npm/katex@0.10.1/dist/katex.min.css"
  346. integrity="sha384-dbVIfZGuN1Yq7/1Ocstc1lUEm+AT+/rCkibIcC/OmWo5f0EA48Vf8CytHzGrSwbQ"
  347. crossorigin="anonymous">
  348. <script src="https://cdn.jsdelivr.net/npm/katex@0.10.1/dist/katex.min.js"
  349. integrity="sha384-2BKqo+exmr9su6dir+qCw08N2ZKRucY4PrGQPPWU1A7FtlCGjmEGFqXCv5nyM5Ij"
  350. crossorigin="anonymous"></script>
  351. <script src="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/9.12.0/highlight.min.js"></script>
  352. ''' + req_list]
  353. return data
  354. def cut_100(data):
  355. data = re.sub('<(((?!>).)*)>', ' ', data)
  356. data = re.sub('\n', ' ', data)
  357. data = re.sub('^ +', '', data)
  358. data = re.sub(' +$', '', data)
  359. data = re.sub(' {2,}', ' ', data)
  360. return data[0:100] + '...'
  361. def wiki_set(num = 1):
  362. if num == 1:
  363. data_list = []
  364. curs.execute('select data from other where name = ?', ['name'])
  365. db_data = curs.fetchall()
  366. if db_data and db_data[0][0] != '':
  367. data_list += [db_data[0][0]]
  368. else:
  369. data_list += ['Wiki']
  370. curs.execute('select data from other where name = "license"')
  371. db_data = curs.fetchall()
  372. if db_data and db_data[0][0] != '':
  373. data_list += [db_data[0][0]]
  374. else:
  375. data_list += ['CC 0']
  376. data_list += ['', '']
  377. curs.execute('select data from other where name = "logo"')
  378. db_data = curs.fetchall()
  379. if db_data and db_data[0][0] != '':
  380. data_list += [db_data[0][0]]
  381. else:
  382. data_list += [data_list[0]]
  383. curs.execute("select data from other where name = 'head' and coverage = ?", [skin_check(1)])
  384. db_data = curs.fetchall()
  385. if db_data and db_data[0][0] != '':
  386. if len(re.findall('<', db_data[0][0])) % 2 != 1:
  387. data_list += [db_data[0][0]]
  388. else:
  389. data_list += ['']
  390. else:
  391. curs.execute("select data from other where name = 'head' and coverage = ''")
  392. db_data = curs.fetchall()
  393. if db_data and db_data[0][0] != '':
  394. if len(re.findall('<', db_data[0][0])) % 2 != 1:
  395. data_list += [db_data[0][0]]
  396. else:
  397. data_list += ['']
  398. else:
  399. data_list += ['']
  400. return data_list
  401. if num == 2:
  402. var_data = 'FrontPage'
  403. curs.execute('select data from other where name = "frontpage"')
  404. elif num == 3:
  405. var_data = '2'
  406. curs.execute('select data from other where name = "upload"')
  407. db_data = curs.fetchall()
  408. if db_data and db_data[0][0] != '':
  409. return db_data[0][0]
  410. else:
  411. return var_data
  412. def diff(seqm):
  413. output = []
  414. for opcode, a0, a1, b0, b1 in seqm.get_opcodes():
  415. if opcode == 'equal':
  416. output += [seqm.a[a0:a1]]
  417. elif opcode == 'insert':
  418. output += ["<span style='background:#CFC;'>" + seqm.b[b0:b1] + "</span>"]
  419. elif opcode == 'delete':
  420. output += ["<span style='background:#FDD;'>" + seqm.a[a0:a1] + "</span>"]
  421. elif opcode == 'replace':
  422. output += ["<span style='background:#FDD;'>" + seqm.a[a0:a1] + "</span>"]
  423. output += ["<span style='background:#CFC;'>" + seqm.b[b0:b1] + "</span>"]
  424. end = ''.join(output)
  425. end = end.replace('\r\n', '\n')
  426. sub = ''
  427. if not re.search('\n$', end):
  428. end += '\n'
  429. num = 0
  430. left = 1
  431. while 1:
  432. data = re.search('((?:(?!\n).)*)\n', end)
  433. if data:
  434. data = data.groups()[0]
  435. left += 1
  436. if re.search('<span style=\'(?:(?:(?!\').)+)\'>', data):
  437. num += 1
  438. if re.search('<\/span>', data):
  439. num -= 1
  440. sub += str(left) + ' : ' + re.sub('(?P<in>(?:(?!\n).)*)\n', '\g<in>', data, 1) + '<br>'
  441. else:
  442. if re.search('<\/span>', data):
  443. num -= 1
  444. sub += str(left) + ' : ' + re.sub('(?P<in>(?:(?!\n).)*)\n', '\g<in>', data, 1) + '<br>'
  445. else:
  446. if num > 0:
  447. sub += str(left) + ' : ' + re.sub('(?P<in>.*)\n', '\g<in>', data, 1) + '<br>'
  448. end = re.sub('((?:(?!\n).)*)\n', '', end, 1)
  449. else:
  450. break
  451. return sub
  452. def admin_check(num = None, what = None, name = ''):
  453. if name == '':
  454. ip = ip_check()
  455. else:
  456. ip = name
  457. curs.execute("select acl from user where id = ?", [ip])
  458. user = curs.fetchall()
  459. if user:
  460. reset = 0
  461. back_num = num
  462. while 1:
  463. if num == 1:
  464. check = 'ban'
  465. elif num == 2:
  466. check = 'nothing'
  467. elif num == 3:
  468. check = 'toron'
  469. elif num == 4:
  470. check = 'check'
  471. elif num == 5:
  472. check = 'acl'
  473. elif num == 6:
  474. check = 'hidel'
  475. elif num == 7:
  476. check = 'give'
  477. else:
  478. check = 'owner'
  479. curs.execute('select name from alist where name = ? and acl = ?', [user[0][0], check])
  480. if curs.fetchall():
  481. if what:
  482. curs.execute("insert into re_admin (who, what, time) values (?, ?, ?)", [ip, what, get_time()])
  483. conn.commit()
  484. return 1
  485. else:
  486. if back_num == 'all':
  487. if num == 'all':
  488. num = 1
  489. elif num != 8:
  490. num += 1
  491. else:
  492. break
  493. elif num:
  494. num = None
  495. else:
  496. break
  497. return 0
  498. def ip_pas(raw_ip):
  499. hide = 0
  500. if ip_or_user(raw_ip) != 0:
  501. curs.execute("select data from other where name = 'ip_view'")
  502. data = curs.fetchall()
  503. if data and data[0][0] != '':
  504. ip = re.sub('((?:(?!\.).)+)$', 'xxx', raw_ip)
  505. if not admin_check(1):
  506. hide = 1
  507. else:
  508. ip = raw_ip
  509. else:
  510. curs.execute("select title from data where title = ?", ['user:' + raw_ip])
  511. if curs.fetchall():
  512. ip = '<a href="/w/' + url_pas('user:' + raw_ip) + '">' + raw_ip + '</a>'
  513. else:
  514. ip = '<a id="not_thing" href="/w/' + url_pas('user:' + raw_ip) + '">' + raw_ip + '</a>'
  515. if admin_check('all', None, raw_ip) == 1:
  516. ip = '<b>' + ip + '</b>'
  517. if ban_check(raw_ip) == 1:
  518. ip = '<s>' + ip + '</s>'
  519. if hide == 0:
  520. ip += ' <a href="/tool/' + url_pas(raw_ip) + '">(' + load_lang('tool') + ')</a>'
  521. return ip
  522. def custom():
  523. if 'head' in flask.session:
  524. if len(re.findall('<', flask.session['head'])) % 2 != 1:
  525. user_head = flask.session['head']
  526. else:
  527. user_head = ''
  528. else:
  529. user_head = ''
  530. ip = ip_check()
  531. if ip_or_user(ip) == 0:
  532. user_icon = 1
  533. else:
  534. user_icon = 0
  535. if user_icon != 0:
  536. curs.execute('select data from user_set where name = "email" and id = ?', [ip])
  537. data = curs.fetchall()
  538. if data:
  539. email = data[0][0]
  540. else:
  541. email = ''
  542. else:
  543. email = ''
  544. if user_icon != 0:
  545. user_name = ip
  546. else:
  547. user_name = load_lang('user')
  548. if admin_check('all') == 1:
  549. user_admin = '1'
  550. curs.execute("select acl from user where id = ?", [ip])
  551. user_acl = curs.fetchall()
  552. user_acl_list = []
  553. curs.execute('select acl from alist where name = ?', [user_acl[0][0]])
  554. user_acl = curs.fetchall()
  555. for i in user_acl:
  556. user_acl_list += [i[0]]
  557. if user_acl != []:
  558. user_acl_list = user_acl_list
  559. else:
  560. user_acl_list = '0'
  561. else:
  562. user_admin = '0'
  563. user_acl_list = '0'
  564. if ban_check() == 1:
  565. user_ban = '1'
  566. else:
  567. user_ban = '0'
  568. if user_icon == 1:
  569. curs.execute("select count(name) from alarm where name = ?", [ip])
  570. count = curs.fetchall()
  571. if count:
  572. user_notice = str(count[0][0])
  573. else:
  574. user_notice = '0'
  575. else:
  576. user_notice = '0'
  577. return ['', '', user_icon, user_head, email, user_name, user_admin, user_ban, user_notice, user_acl_list]
  578. def load_skin(data = '', set_n = 0):
  579. div2 = ''
  580. div3 = []
  581. system_file = ['main_css', 'easter_egg.html']
  582. if data == '':
  583. ip = ip_check()
  584. curs.execute('select data from user_set where name = "skin" and id = ?', [ip])
  585. data = curs.fetchall()
  586. if not data:
  587. curs.execute('select data from other where name = "skin"')
  588. data = curs.fetchall()
  589. if not data:
  590. data = [['marisa']]
  591. if set_n == 0:
  592. for skin_data in os.listdir(os.path.abspath('views')):
  593. if not skin_data in system_file:
  594. if data[0][0] == skin_data:
  595. div2 = '<option value="' + skin_data + '">' + skin_data + '</option>' + div2
  596. else:
  597. div2 += '<option value="' + skin_data + '">' + skin_data + '</option>'
  598. else:
  599. div2 = []
  600. for skin_data in os.listdir(os.path.abspath('views')):
  601. if not skin_data in system_file:
  602. if data[0][0] == skin_data:
  603. div2 = [skin_data] + div2
  604. else:
  605. div2 += [skin_data]
  606. else:
  607. if set_n == 0:
  608. for skin_data in os.listdir(os.path.abspath('views')):
  609. if not skin_data in system_file:
  610. if data == skin_data:
  611. div2 = '<option value="' + skin_data + '">' + skin_data + '</option>' + div2
  612. else:
  613. div2 += '<option value="' + skin_data + '">' + skin_data + '</option>'
  614. else:
  615. div2 = []
  616. for skin_data in os.listdir(os.path.abspath('views')):
  617. if not skin_data in system_file:
  618. if data == skin_data:
  619. div2 = [skin_data] + div2
  620. else:
  621. div2 += [skin_data]
  622. return div2
  623. def acl_check(name = 'test', tool = '', sub = 'test'):
  624. ip = ip_check()
  625. if ban_check() == 1:
  626. return 1
  627. if tool != 'topic' and tool != 'render':
  628. acl_c = re.search("^user:((?:(?!\/).)*)", name)
  629. if acl_c:
  630. acl_n = acl_c.groups()
  631. if admin_check(5) == 1:
  632. return 0
  633. curs.execute("select decu from acl where title = ?", ['user:' + acl_n[0]])
  634. acl_data = curs.fetchall()
  635. if acl_data:
  636. if acl_data[0][0] == 'all':
  637. return 0
  638. if acl_data[0][0] == 'user' and not re.search("(\.|:)", ip):
  639. return 0
  640. if ip != acl_n[0] or re.search("(\.|:)", ip):
  641. return 1
  642. if ip == acl_n[0] and not re.search("(\.|:)", ip) and not re.search("(\.|:)", acl_n[0]):
  643. return 0
  644. else:
  645. return 1
  646. if re.search("^file:", name) and admin_check(None, 'file edit (' + name + ')') != 1:
  647. return 1
  648. if tool == '':
  649. end = 3
  650. elif tool == 'topic':
  651. end = 2
  652. else:
  653. end = 1
  654. for i in range(0, end):
  655. if tool == '':
  656. if i == 0:
  657. curs.execute("select decu from acl where title = ?", [name])
  658. acl_data = curs.fetchall()
  659. elif i == 1:
  660. curs.execute('select data from other where name = "edit"')
  661. acl_data = curs.fetchall()
  662. else:
  663. curs.execute("select view from acl where title = ?", [name])
  664. acl_data = curs.fetchall()
  665. num = 5
  666. elif tool == 'topic':
  667. if i == 0:
  668. curs.execute("select dis from acl where title = ?", [name])
  669. acl_data = curs.fetchall()
  670. else:
  671. curs.execute('select data from other where name = "discussion"')
  672. acl_data = curs.fetchall()
  673. num = 3
  674. else:
  675. curs.execute("select view from acl where title = ?", [name])
  676. acl_data = curs.fetchall()
  677. num = 5
  678. if acl_data and acl_data[0][0] != 'normal':
  679. if acl_data[0][0] == 'user':
  680. if ip_or_user(ip) == 1:
  681. return 1
  682. if acl_data[0][0] == 'admin':
  683. if ip_or_user(ip) == 1:
  684. return 1
  685. if admin_check(num) != 1:
  686. return 1
  687. if acl_data[0][0] == '50_edit':
  688. if ip_or_user(ip) == 1:
  689. return 1
  690. if admin_check(num) != 1:
  691. curs.execute("select count(title) from history where ip = ?", [ip])
  692. count = curs.fetchall()
  693. if count:
  694. count = count[0][0]
  695. else:
  696. count = 0
  697. if count < 50:
  698. return 1
  699. if acl_data[0][0] == 'email':
  700. if ip_or_user(ip) == 1:
  701. return 1
  702. if admin_check(num) != 1:
  703. curs.execute("select data from user_set where id = ? and name = 'email'", [ip])
  704. email = curs.fetchall()
  705. if not email:
  706. return 1
  707. if acl_data[0][0] == 'owner':
  708. if admin_check() != 1:
  709. return 1
  710. if tool == 'topic':
  711. curs.execute("select title from rd where title = ? and sub = ? and not stop = ''", [name, sub])
  712. if curs.fetchall():
  713. if admin_check(3, 'topic (' + name + ')') != 1:
  714. return 1
  715. return 0
  716. def ban_check(ip = None, tool = None):
  717. if not ip:
  718. ip = ip_check()
  719. band = re.search("^([0-9]{1,3}\.[0-9]{1,3})", ip)
  720. if band:
  721. band_it = band.groups()[0]
  722. else:
  723. band_it = '-'
  724. curs.execute("delete from ban where (end < ? and end like '2%')", [get_time()])
  725. conn.commit()
  726. curs.execute("select login, block from ban where ((end > ? and end like '2%') or end = '') and band = 'regex'", [get_time()])
  727. regex_d = curs.fetchall()
  728. for test_r in regex_d:
  729. g_regex = re.compile(test_r[1])
  730. if g_regex.search(ip):
  731. if tool and tool == 'login':
  732. if test_r[0] != 'O':
  733. return 1
  734. else:
  735. return 1
  736. curs.execute("select login from ban where ((end > ? and end like '2%') or end = '') and block = ? and band = 'O'", [get_time(), band_it])
  737. band_d = curs.fetchall()
  738. if band_d:
  739. if tool and tool == 'login':
  740. if band_d[0][0] != 'O':
  741. return 1
  742. else:
  743. return 1
  744. curs.execute("select login from ban where ((end > ? and end like '2%') or end = '') and block = ? and band = ''", [get_time(), ip])
  745. ban_d = curs.fetchall()
  746. if ban_d:
  747. if tool and tool == 'login':
  748. if ban_d[0][0] != 'O':
  749. return 1
  750. else:
  751. return 1
  752. return 0
  753. def topic_check(name, sub):
  754. return acl_check(name, 'topic', sub)
  755. def ban_insert(name, end, why, login, blocker, type_d = None):
  756. now_time = get_time()
  757. if type_d:
  758. band = type_d
  759. else:
  760. if re.search("^([0-9]{1,3}\.[0-9]{1,3})$", name):
  761. band = 'O'
  762. else:
  763. band = ''
  764. curs.execute("delete from ban where (end < ? and end like '2%')", [get_time()])
  765. curs.execute("select block from ban where ((end > ? and end like '2%') or end = '') and block = ? and band = ?", [get_time(), name, band])
  766. if curs.fetchall():
  767. curs.execute("insert into rb (block, end, today, blocker, why, band) values (?, ?, ?, ?, ?, ?)", [
  768. name,
  769. 'release',
  770. now_time,
  771. blocker,
  772. '',
  773. band
  774. ])
  775. curs.execute("delete from ban where block = ? and band = ?", [name, band])
  776. else:
  777. if login != '':
  778. login = 'O'
  779. else:
  780. login = ''
  781. if end != '0':
  782. end = int(number_check(end))
  783. time = datetime.datetime.now()
  784. plus = datetime.timedelta(seconds = end)
  785. r_time = (time + plus).strftime("%Y-%m-%d %H:%M:%S")
  786. else:
  787. r_time = ''
  788. curs.execute("insert into rb (block, end, today, blocker, why, band) values (?, ?, ?, ?, ?, ?)", [name, r_time, now_time, blocker, why, band])
  789. curs.execute("insert into ban (block, end, why, band, login) values (?, ?, ?, ?, ?)", [name, r_time, why, band, login])
  790. conn.commit()
  791. def rd_plus(title, sub, date):
  792. curs.execute("select title from rd where title = ? and sub = ?", [title, sub])
  793. if curs.fetchall():
  794. curs.execute("update rd set date = ? where title = ? and sub = ?", [date, title, sub])
  795. else:
  796. curs.execute("insert into rd (title, sub, date) values (?, ?, ?)", [title, sub, date])
  797. conn.commit()
  798. def history_plus(title, data, date, ip, send, leng, t_check = ''):
  799. curs.execute("select id from history where title = ? order by id + 0 desc limit 1", [title])
  800. id_data = curs.fetchall()
  801. send = re.sub('\(|\)|<|>', '', send)
  802. if len(send) > 128:
  803. send = send[:128]
  804. if t_check != '':
  805. send += ' (' + t_check + ')'
  806. curs.execute("insert into history (id, title, data, date, ip, send, leng, hide) values (?, ?, ?, ?, ?, ?, ?, '')", [
  807. str(int(id_data[0][0]) + 1) if id_data else '1',
  808. title,
  809. data,
  810. date,
  811. ip,
  812. send,
  813. leng
  814. ])
  815. def leng_check(first, second):
  816. if first < second:
  817. all_plus = '+' + str(second - first)
  818. elif second < first:
  819. all_plus = '-' + str(first - second)
  820. else:
  821. all_plus = '0'
  822. return all_plus
  823. def number_check(data):
  824. try:
  825. int(data)
  826. return data
  827. except:
  828. return '1'
  829. def edit_filter_do(data):
  830. if admin_check(1) != 1:
  831. curs.execute("select regex, sub from filter where regex != ''")
  832. for data_list in curs.fetchall():
  833. match = re.compile(data_list[0], re.I)
  834. if match.search(data):
  835. ban_insert(
  836. ip_check(),
  837. '0' if data_list[1] == 'X' else data_list[1],
  838. 'edit filter',
  839. None,
  840. 'tool:edit filter'
  841. )
  842. return 1
  843. return 0
  844. def redirect(data = '/'):
  845. return flask.redirect(data)
  846. def re_error(data):
  847. conn.commit()
  848. if data == '/ban':
  849. ip = ip_check()
  850. end = '<li>' + load_lang('why') + ' : ' + load_lang('authority_error') + '</li>'
  851. if ban_check() == 1:
  852. end = '<li>' + load_lang('state') + ' : ' + load_lang('ban') + '</li>'
  853. ok_sign = 1
  854. band = re.search("^([0-9]{1,3}\.[0-9]{1,3})", ip)
  855. if band:
  856. band_it = band.groups()[0]
  857. else:
  858. band_it = '-'
  859. curs.execute("delete from ban where (end < ? and end like '2%')", [get_time()])
  860. conn.commit()
  861. curs.execute("select login, block, end from ban where ((end > ? and end like '2%') or end = '') and band = 'regex'", [get_time()])
  862. regex_d = curs.fetchall()
  863. for test_r in regex_d:
  864. g_regex = re.compile(test_r[1])
  865. if g_regex.search(ip):
  866. end += '<li>' + load_lang('type') + ' : regex ban</li>'
  867. end += '<li>' + load_lang('end') + ' : ' + (test_r[2] if test_r[2] != '' else load_lang('limitless')) + '</li>'
  868. if test_r[0] == 'O':
  869. end += '<li>' + load_lang('login_able') + ' (' + load_lang('not_sure') + ')</li>'
  870. end += '<hr class=\"main_hr\">'
  871. curs.execute("select login, end from ban where ((end > ? and end like '2%') or end = '') and block = ?", [get_time(), band_it])
  872. band_d = curs.fetchall()
  873. if band_d:
  874. end += '<li>' + load_lang('type') + ' : band ban</li>'
  875. end += '<li>' + load_lang('end') + ' : ' + (band_d[0][1] if band_d[0][1] != '' else load_lang('limitless')) + '</li>'
  876. if band_d[0][0] == 'O':
  877. end += '<li>' + load_lang('login_able') + ' (' + load_lang('not_sure') + ')</li>'
  878. end += '<hr class=\"main_hr\">'
  879. curs.execute("select login, end from ban where ((end > ? and end like '2%') or end = '') and block = ?", [get_time(), ip])
  880. ban_d = curs.fetchall()
  881. if ban_d:
  882. end += '<li>' + load_lang('type') + ' : ban</li>'
  883. end += '<li>' + load_lang('end') + ' : ' + (ban_d[0][1] if ban_d[0][1] != '' else load_lang('limitless')) + '</li>'
  884. if ban_d[0][0] == 'O':
  885. end += '<li>' + load_lang('login_able') + ' (' + load_lang('not_sure') + ')</li>'
  886. end += '<hr class=\"main_hr\">'
  887. return easy_minify(flask.render_template(skin_check(),
  888. imp = [load_lang('error'), wiki_set(1), custom(), other2([0, 0])],
  889. data = '<h2>' + load_lang('error') + '</h2><ul>' + end + '</ul>',
  890. menu = 0
  891. ))
  892. else:
  893. error_data = re.search('\/error\/([0-9]+)', data)
  894. if error_data:
  895. num = int(error_data.groups()[0])
  896. if num == 1:
  897. data = load_lang('no_login_error')
  898. elif num == 2:
  899. data = load_lang('no_exist_user_error')
  900. elif num == 3:
  901. data = load_lang('authority_error')
  902. elif num == 4:
  903. data = load_lang('no_admin_block_error')
  904. elif num == 5:
  905. data = load_lang('skin_error')
  906. elif num == 6:
  907. data = load_lang('same_id_exist_error')
  908. elif num == 7:
  909. data = load_lang('long_id_error')
  910. elif num == 8:
  911. data = load_lang('id_char_error') + ' <a href="/name_filter">(' + load_lang('id') + ' ' + load_lang('filter') + ')</a>'
  912. elif num == 9:
  913. data = load_lang('file_exist_error')
  914. elif num == 10:
  915. data = load_lang('password_error')
  916. elif num == 11:
  917. data = load_lang('topic_long_error')
  918. elif num == 12:
  919. data = load_lang('email_error')
  920. elif num == 13:
  921. data = load_lang('recaptcha_error')
  922. elif num == 14:
  923. data = load_lang('file_extension_error')
  924. elif num == 15:
  925. data = load_lang('edit_record_error')
  926. elif num == 16:
  927. data = load_lang('same_file_error')
  928. elif num == 17:
  929. data = load_lang('file_capacity_error') + ' ' + wiki_set(3)
  930. elif num == 19:
  931. data = load_lang('decument_exist_error')
  932. elif num == 20:
  933. data = load_lang('password_diffrent_error')
  934. elif num == 21:
  935. data = load_lang('edit_filter_error')
  936. elif num == 22:
  937. data = load_lang('file_name_error')
  938. elif num == 23:
  939. data = load_lang('regex_error')
  940. else:
  941. data = '???'
  942. if num == 5:
  943. return easy_minify(flask.render_template(skin_check(),
  944. imp = [load_lang('skin_set'), wiki_set(1), custom(), other2([0, 0])],
  945. data = '<div id="main_skin_set"><h2>' + load_lang('error') + '</h2><ul><li>' + data + '</li></ul></div>',
  946. menu = 0
  947. ))
  948. else:
  949. return easy_minify(flask.render_template(skin_check(),
  950. imp = [load_lang('error'), wiki_set(1), custom(), other2([0, 0])],
  951. data = '<h2>' + load_lang('error') + '</h2><ul><li>' + data + '</li></ul>',
  952. menu = 0
  953. )), 401
  954. else:
  955. return redirect('/')