2
0

func.py 30 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910
  1. import email.mime.text
  2. import urllib.request
  3. import sqlite3
  4. import hashlib
  5. import smtplib
  6. import bcrypt
  7. import flask
  8. import json
  9. import html
  10. import sys
  11. import re
  12. import os
  13. try:
  14. import css_html_js_minify
  15. except:
  16. pass
  17. if sys.version_info < (3, 6):
  18. import sha3
  19. from set_mark.tool import *
  20. from mark import *
  21. def load_conn(data):
  22. global conn
  23. global curs
  24. conn = data
  25. curs = conn.cursor()
  26. load_conn2(data)
  27. def send_email(who, title, data):
  28. smtp = smtplib.SMTP_SSL('smtp.gmail.com', 465)
  29. try:
  30. curs.execute('select name, data from other where name = "g_email" or name = "g_pass"')
  31. rep_data = curs.fetchall()
  32. if rep_data:
  33. g_email = ''
  34. g_pass = ''
  35. for i in rep_data:
  36. if i[0] == 'g_email':
  37. g_email = i[1]
  38. else:
  39. g_pass = i[1]
  40. smtp.login(g_email, g_pass)
  41. msg = email.mime.text.MIMEText(data)
  42. msg['Subject'] = title
  43. smtp.sendmail(g_email, who, msg.as_string())
  44. smtp.quit()
  45. except:
  46. print('error : email login error')
  47. def easy_minify(data, tool = None):
  48. try:
  49. if not tool:
  50. data = css_html_js_minify.html_minify(data)
  51. else:
  52. if tool == 'css':
  53. data = css_html_js_minify.css_minify(data)
  54. elif tool == 'js':
  55. data = css_html_js_minify.js_minify(data)
  56. except:
  57. data = re.sub('\n +<', '\n<', data)
  58. data = re.sub('>(\n| )+<', '> <', data)
  59. return data
  60. def render_set(title = '', data = '', num = 0):
  61. if acl_check(title, 'render') == 1:
  62. return 'http request 401.3'
  63. else:
  64. return namumark(title, data, num)
  65. def captcha_get():
  66. data = ''
  67. if custom()[2] == 0:
  68. curs.execute('select data from other where name = "recaptcha"')
  69. recaptcha = curs.fetchall()
  70. if recaptcha and recaptcha[0][0] != '':
  71. curs.execute('select data from other where name = "sec_re"')
  72. sec_re = curs.fetchall()
  73. if sec_re and sec_re[0][0] != '':
  74. data += recaptcha[0][0] + '<hr>'
  75. return data
  76. def update():
  77. # v3.0.5 사용자 문서, 파일 문서, 분류 문서 영어화
  78. try:
  79. all_rep = [['사용자:', 'user:'], ['파일:', 'file:'], ['분류:', 'category:']]
  80. all_rep2 = ['data', 'history', 'acl', 'topic', 'back']
  81. test = 0
  82. for i in range(3):
  83. for j in range(6):
  84. if not j == 5:
  85. curs.execute('select title from ' + all_rep2[j] + ' where title like ?', [all_rep[i][0] + '%'])
  86. else:
  87. curs.execute('select link from back where link like ?', [all_rep[i][0] + '%'])
  88. user_rep = curs.fetchall()
  89. if user_rep:
  90. for user_rep2 in user_rep:
  91. test = 1
  92. first = re.sub('^' + all_rep[i][0], all_rep[i][1], user_rep2[0])
  93. if j == 0:
  94. curs.execute("update data set title = ? where title = ?", [first, user_rep2[0]])
  95. elif j == 1:
  96. curs.execute("update history set title = ? where title = ?", [first, user_rep2[0]])
  97. elif j == 2:
  98. curs.execute("update acl set title = ? where title = ?", [first, user_rep2[0]])
  99. elif j == 3:
  100. curs.execute("update topic set title = ? where title = ?", [first, user_rep2[0]])
  101. elif j == 4:
  102. curs.execute("update back set title = ? where title = ?", [first, user_rep2[0]])
  103. elif j == 5:
  104. curs.execute("update back set link = ? where link = ?", [first, user_rep2[0]])
  105. if test == 1:
  106. print('사용자 to user, 파일 to file, 분류 to category')
  107. except:
  108. pass
  109. # v3.0.8 rd, agreedis, stop 테이블 통합
  110. try:
  111. curs.execute("select title, sub, close from stop")
  112. for i in curs.fetchall():
  113. if i[2] == '':
  114. curs.execute("update rd set stop = 'S' where title = ? and sub = ?", [i[0], i[1]])
  115. else:
  116. curs.execute("update rd set stop = 'O' where title = ? and sub = ?", [i[0], i[1]])
  117. except:
  118. pass
  119. try:
  120. curs.execute("select title, sub from agreedis")
  121. for i in curs.fetchall():
  122. curs.execute("update rd set agree = 'O' where title = ? and sub = ?", [i[0], i[1]])
  123. except:
  124. pass
  125. try:
  126. curs.execute("drop table if exists stop")
  127. curs.execute("drop table if exists agreedis")
  128. except:
  129. pass
  130. def pw_encode(data, data2 = '', type_d = ''):
  131. if type_d == '':
  132. curs.execute('select data from other where name = "encode"')
  133. set_data = curs.fetchall()
  134. type_d = set_data[0][0]
  135. if type_d == 'sha256':
  136. return hashlib.sha256(bytes(data, 'utf-8')).hexdigest()
  137. elif type_d == 'sha3':
  138. if sys.version_info < (3, 6):
  139. return sha3.sha3_256(bytes(data, 'utf-8')).hexdigest()
  140. else:
  141. return hashlib.sha3_256(bytes(data, 'utf-8')).hexdigest()
  142. else:
  143. if data2 != '':
  144. salt_data = bytes(data2, 'utf-8')
  145. else:
  146. salt_data = bcrypt.gensalt(11)
  147. return bcrypt.hashpw(bytes(data, 'utf-8'), salt_data).decode()
  148. def pw_check(data, data2, type_d = 'no', id_d = ''):
  149. curs.execute('select data from other where name = "encode"')
  150. db_data = curs.fetchall()
  151. if type_d != 'no':
  152. if type_d == '':
  153. set_data = 'bcrypt'
  154. else:
  155. set_data = type_d
  156. else:
  157. set_data = db_data[0][0]
  158. if set_data in ['sha256', 'sha3']:
  159. data3 = pw_encode(data = data, type_d = set_data)
  160. if data3 == data2:
  161. re_data = 1
  162. else:
  163. re_data = 0
  164. else:
  165. if pw_encode(data, data2, 'bcrypt') == data2:
  166. re_data = 1
  167. else:
  168. re_data = 0
  169. if db_data[0][0] != set_data and re_data == 1 and id_d != '':
  170. curs.execute("update user set pw = ?, encode = ? where id = ?", [pw_encode(data), db_data[0][0], id_d])
  171. return re_data
  172. def captcha_post(re_data, num = 1):
  173. if num == 1:
  174. if custom()[2] == 0 and captcha_get() != '':
  175. curs.execute('select data from other where name = "sec_re"')
  176. sec_re = curs.fetchall()
  177. if sec_re and sec_re[0][0] != '':
  178. data = urllib.request.urlopen('https://www.google.com/recaptcha/api/siteverify?secret=' + sec_re[0][0] + '&response=' + re_data)
  179. if not data:
  180. return 0
  181. else:
  182. json_data = data.read().decode(data.headers.get_content_charset())
  183. json_data = json.loads(json_data)
  184. if data.getcode() == 200 and json_data['success'] == True:
  185. return 0
  186. else:
  187. return 1
  188. else:
  189. return 0
  190. else:
  191. return 0
  192. else:
  193. pass
  194. def load_lang(data, num = 2):
  195. if num == 1:
  196. curs.execute("select data from other where name = 'language'")
  197. rep_data = curs.fetchall()
  198. json_data = open(os.path.join('language', rep_data[0][0] + '.json'), 'rt', encoding='utf-8').read()
  199. lang = json.loads(json_data)
  200. if data in lang:
  201. return lang[data]
  202. else:
  203. return data + ' (missing)'
  204. else:
  205. curs.execute('select data from user_set where name = "lang" and id = ?', [ip_check()])
  206. rep_data = curs.fetchall()
  207. if rep_data:
  208. try:
  209. json_data = open(os.path.join('language', rep_data[0][0] + '.json'), 'rt', encoding='utf-8').read()
  210. lang = json.loads(json_data)
  211. except:
  212. return load_lang(data, 1)
  213. if data in lang:
  214. return lang[data]
  215. else:
  216. return load_lang(data, 1)
  217. else:
  218. return load_lang(data, 1)
  219. def load_oauth(provider):
  220. oauth_native = open('oauthsettings.json', encoding='utf-8').read()
  221. oauth = json.loads(oauth_native)
  222. return oauth[provider]
  223. def update_oauth(provider, target, content):
  224. oauth_native = open('oauthsettings.json', encoding='utf-8').read()
  225. oauth = json.loads(oauth_native)
  226. oauth[provider][target] = content
  227. with open('oauthsettings.json', 'w', encoding='utf-8') as f:
  228. json.dump(oauth, f)
  229. return 'Done'
  230. def ip_or_user(data):
  231. if re.search('(\.|:)', data):
  232. return 1
  233. else:
  234. return 0
  235. def edit_help_button():
  236. # https://stackoverflow.com/questions/11076975/insert-text-into-textarea-at-cursor-position-javascript
  237. js_data = '''
  238. <script>
  239. function insert_data(name, data) {
  240. if(document.selection) {
  241. document.getElementById(name).focus();
  242. sel = document.selection.createRange();
  243. sel.text = data;
  244. } else if(document.getElementById(name).selectionStart || document.getElementById(name).selectionStart == '0') {
  245. var startPos = document.getElementById(name).selectionStart;
  246. var endPos = document.getElementById(name).selectionEnd;
  247. document.getElementById(name).value = document.getElementById(name).value.substring(0, startPos) + data + document.getElementById(name).value.substring(endPos, document.getElementById(name).value.length);
  248. } else {
  249. document.getElementById(name).value += data;
  250. }
  251. }
  252. </script>
  253. '''
  254. insert_list = [['[[|]]', '[[|]]'], ['[*()]', '[*()]'], ['{{{#!}}}', '{{{#!}}}'], ['||<>||', '||<>||'], ["\\'\\'\\'", "\'\'\'"]]
  255. data = ''
  256. for insert_data in insert_list:
  257. data += '<a href="javascript:void(0);" onclick="insert_data(\'content\', \'' + insert_data[0] + '\');">(' + insert_data[1] + ')</a> '
  258. return [js_data, data + '<hr>']
  259. def ip_warring():
  260. if custom()[2] == 0:
  261. curs.execute('select data from other where name = "no_login_warring"')
  262. data = curs.fetchall()
  263. if data and data[0][0] != '':
  264. text_data = '<span>' + data[0][0] + '</span><hr>'
  265. else:
  266. text_data = '<span>' + load_lang('no_login_warring') + '</span><hr>'
  267. else:
  268. text_data = ''
  269. return text_data
  270. def skin_check():
  271. skin = './views/neo_yousoro/'
  272. curs.execute('select data from other where name = "skin"')
  273. skin_exist = curs.fetchall()
  274. if skin_exist and skin_exist[0][0] != '':
  275. if os.path.exists(os.path.abspath('./views/' + skin_exist[0][0] + '/index.html')) == 1:
  276. skin = './views/' + skin_exist[0][0] + '/'
  277. curs.execute('select data from user_set where name = "skin" and id = ?', [ip_check()])
  278. skin_exist = curs.fetchall()
  279. if skin_exist and skin_exist[0][0] != '':
  280. if os.path.exists(os.path.abspath('./views/' + skin_exist[0][0] + '/index.html')) == 1:
  281. skin = './views/' + skin_exist[0][0] + '/'
  282. return skin + 'index.html'
  283. def next_fix(link, num, page, end = 50):
  284. list_data = ''
  285. if num == 1:
  286. if len(page) == end:
  287. list_data += '<hr><a href="' + link + str(num + 1) + '">(' + load_lang('next') + ')</a>'
  288. elif len(page) != end:
  289. list_data += '<hr><a href="' + link + str(num - 1) + '">(' + load_lang('previous') + ')</a>'
  290. else:
  291. list_data += '<hr><a href="' + link + str(num - 1) + '">(' + load_lang('previous') + ')</a> <a href="' + link + str(num + 1) + '">(' + load_lang('next') + ')</a>'
  292. return list_data
  293. def other2(data):
  294. return data + ['']
  295. def wiki_set(num = 1):
  296. if num == 1:
  297. data_list = []
  298. curs.execute('select data from other where name = ?', ['name'])
  299. db_data = curs.fetchall()
  300. if db_data and db_data[0][0] != '':
  301. data_list += [db_data[0][0]]
  302. else:
  303. data_list += ['wiki']
  304. curs.execute('select data from other where name = "license"')
  305. db_data = curs.fetchall()
  306. if db_data and db_data[0][0] != '':
  307. data_list += [db_data[0][0]]
  308. else:
  309. data_list += ['CC 0']
  310. data_list += ['', '']
  311. curs.execute('select data from other where name = "logo"')
  312. db_data = curs.fetchall()
  313. if db_data and db_data[0][0] != '':
  314. data_list += [db_data[0][0]]
  315. else:
  316. data_list += [data_list[0]]
  317. curs.execute("select data from other where name = 'head'")
  318. db_data = curs.fetchall()
  319. if db_data and db_data[0][0] != '':
  320. data_list += [db_data[0][0]]
  321. else:
  322. data_list += ['']
  323. return data_list
  324. if num == 2:
  325. var_data = 'FrontPage'
  326. curs.execute('select data from other where name = "frontpage"')
  327. elif num == 3:
  328. var_data = '2'
  329. curs.execute('select data from other where name = "upload"')
  330. db_data = curs.fetchall()
  331. if db_data and db_data[0][0] != '':
  332. return db_data[0][0]
  333. else:
  334. return var_data
  335. def diff(seqm):
  336. output = []
  337. for opcode, a0, a1, b0, b1 in seqm.get_opcodes():
  338. if opcode == 'equal':
  339. output += [seqm.a[a0:a1]]
  340. elif opcode == 'insert':
  341. output += ["<span style='background:#CFC;'>" + seqm.b[b0:b1] + "</span>"]
  342. elif opcode == 'delete':
  343. output += ["<span style='background:#FDD;'>" + seqm.a[a0:a1] + "</span>"]
  344. elif opcode == 'replace':
  345. output += ["<span style='background:#FDD;'>" + seqm.a[a0:a1] + "</span>"]
  346. output += ["<span style='background:#CFC;'>" + seqm.b[b0:b1] + "</span>"]
  347. end = ''.join(output)
  348. end = end.replace('\r\n', '\n')
  349. sub = ''
  350. if not re.search('\n', end):
  351. end += '\n'
  352. num = 0
  353. left = 1
  354. while 1:
  355. data = re.search('((?:(?!\n).)*)\n', end)
  356. if data:
  357. data = data.groups()[0]
  358. left += 1
  359. if re.search('<span style=\'(?:(?:(?!\').)+)\'>', data):
  360. num += 1
  361. if re.search('<\/span>', data):
  362. num -= 1
  363. sub += str(left) + ' : ' + re.sub('(?P<in>(?:(?!\n).)*)\n', '\g<in>', data, 1) + '<br>'
  364. else:
  365. if re.search('<\/span>', data):
  366. num -= 1
  367. sub += str(left) + ' : ' + re.sub('(?P<in>(?:(?!\n).)*)\n', '\g<in>', data, 1) + '<br>'
  368. else:
  369. if num > 0:
  370. sub += str(left) + ' : ' + re.sub('(?P<in>.*)\n', '\g<in>', data, 1) + '<br>'
  371. end = re.sub('((?:(?!\n).)*)\n', '', end, 1)
  372. else:
  373. break
  374. return sub
  375. def admin_check(num = None, what = None):
  376. ip = ip_check()
  377. curs.execute("select acl from user where id = ?", [ip])
  378. user = curs.fetchall()
  379. if user:
  380. reset = 0
  381. while 1:
  382. if num == 1 and reset == 0:
  383. check = 'ban'
  384. elif num == 3 and reset == 0:
  385. check = 'toron'
  386. elif num == 4 and reset == 0:
  387. check = 'check'
  388. elif num == 5 and reset == 0:
  389. check = 'acl'
  390. elif num == 6 and reset == 0:
  391. check = 'hidel'
  392. elif num == 7 and reset == 0:
  393. check = 'give'
  394. else:
  395. check = 'owner'
  396. curs.execute('select name from alist where name = ? and acl = ?', [user[0][0], check])
  397. if curs.fetchall():
  398. if what:
  399. curs.execute("insert into re_admin (who, what, time) values (?, ?, ?)", [ip, what, get_time()])
  400. conn.commit()
  401. return 1
  402. else:
  403. if reset == 0:
  404. reset = 1
  405. else:
  406. break
  407. return 0
  408. def ip_pas(raw_ip):
  409. hide = 0
  410. if re.search("(\.|:)", raw_ip):
  411. if not re.search("^" + load_lang('tool', 1) + ":", raw_ip):
  412. curs.execute("select data from other where name = 'ip_view'")
  413. data = curs.fetchall()
  414. if data and data[0][0] != '':
  415. ip = '<span style="font-size: 75%;">' + hashlib.md5(bytes(raw_ip, 'utf-8')).hexdigest() + '</span>'
  416. if not admin_check('ban', None):
  417. hide = 1
  418. else:
  419. ip = raw_ip
  420. else:
  421. ip = raw_ip
  422. hide = 1
  423. else:
  424. curs.execute("select title from data where title = ?", ['user:' + raw_ip])
  425. if curs.fetchall():
  426. ip = '<a href="/w/' + url_pas('user:' + raw_ip) + '">' + raw_ip + '</a>'
  427. else:
  428. ip = '<a id="not_thing" href="/w/' + url_pas('user:' + raw_ip) + '">' + raw_ip + '</a>'
  429. if hide == 0:
  430. ip += ' <a href="/tool/' + url_pas(raw_ip) + '">(' + load_lang('tool') + ')</a>'
  431. return ip
  432. def custom():
  433. if 'head' in flask.session:
  434. user_head = flask.session['head']
  435. else:
  436. user_head = ''
  437. if 'state' in flask.session and flask.session['state'] == 1:
  438. curs.execute('select name from alarm where name = ? limit 1', [ip_check()])
  439. if curs.fetchall():
  440. user_icon = 2
  441. else:
  442. user_icon = 1
  443. else:
  444. user_icon = 0
  445. if user_icon != 0:
  446. curs.execute('select data from user_set where name = "email" and id = ?', [ip_check()])
  447. data = curs.fetchall()
  448. if data:
  449. email = data[0][0]
  450. else:
  451. email = ''
  452. else:
  453. email = ''
  454. if user_icon != 0:
  455. user_name = ip_check()
  456. else:
  457. user_name = load_lang('user')
  458. return ['', '', user_icon, user_head, email, user_name, load_lang(data = '', num = 2)]
  459. def load_skin(data = ''):
  460. div2 = ''
  461. system_file = ['main_css', 'easter_egg.html']
  462. if data == '':
  463. ip = ip_check()
  464. curs.execute('select data from user_set where name = "skin" and id = ?', [ip])
  465. data = curs.fetchall()
  466. for skin_data in os.listdir(os.path.abspath('views')):
  467. if not skin_data in system_file:
  468. if not data:
  469. curs.execute('select data from other where name = "skin"')
  470. sql_data = curs.fetchall()
  471. if sql_data and sql_data[0][0] == skin_data:
  472. div2 = '<option value="' + skin_data + '">' + skin_data + '</option>' + div2
  473. else:
  474. div2 += '<option value="' + skin_data + '">' + skin_data + '</option>'
  475. elif data[0][0] == skin_data:
  476. div2 = '<option value="' + skin_data + '">' + skin_data + '</option>' + div2
  477. else:
  478. div2 += '<option value="' + skin_data + '">' + skin_data + '</option>'
  479. else:
  480. for skin_data in os.listdir(os.path.abspath('views')):
  481. if not skin_data in system_file:
  482. if data == skin_data:
  483. div2 = '<option value="' + skin_data + '">' + skin_data + '</option>' + div2
  484. else:
  485. div2 += '<option value="' + skin_data + '">' + skin_data + '</option>'
  486. return div2
  487. def acl_check(name, tool = ''):
  488. ip = ip_check()
  489. if tool == 'render':
  490. curs.execute("select view from acl where title = ?", [name])
  491. acl_data = curs.fetchall()
  492. if acl_data:
  493. if acl_data[0][0] == 'user':
  494. if not user_data:
  495. return 1
  496. if acl_data[0][0] == 'admin':
  497. if not user_data:
  498. return 1
  499. if not admin_check(5, 'view (' + name + ')') == 1:
  500. return 1
  501. return 0
  502. else:
  503. if ban_check() == 1:
  504. return 1
  505. acl_c = re.search("^user:([^/]*)", name)
  506. if acl_c:
  507. acl_n = acl_c.groups()
  508. if admin_check(5, None) == 1:
  509. return 0
  510. curs.execute("select dec from acl where title = ?", ['user:' + acl_n[0]])
  511. acl_data = curs.fetchall()
  512. if acl_data:
  513. if acl_data[0][0] == 'all':
  514. return 0
  515. if acl_data[0][0] == 'user' and not re.search("(\.|:)", ip):
  516. return 0
  517. if ip != acl_n[0] or re.search("(\.|:)", ip):
  518. return 1
  519. if ip == acl_n[0] and not re.search("(\.|:)", ip) and not re.search("(\.|:)", acl_n[0]):
  520. return 0
  521. else:
  522. return 1
  523. file_c = re.search("^file:(.*)", name)
  524. if file_c and admin_check(5, 'edit (' + name + ')') != 1:
  525. return 1
  526. curs.execute("select acl from user where id = ?", [ip])
  527. user_data = curs.fetchall()
  528. curs.execute("select dec from acl where title = ?", [name])
  529. acl_data = curs.fetchall()
  530. if acl_data:
  531. if acl_data[0][0] == 'user':
  532. if not user_data:
  533. return 1
  534. if acl_data[0][0] == 'admin':
  535. if not user_data:
  536. return 1
  537. if not admin_check(5, 'edit (' + name + ')') == 1:
  538. return 1
  539. curs.execute('select data from other where name = "edit"')
  540. set_data = curs.fetchall()
  541. if set_data:
  542. if set_data[0][0] == 'login':
  543. if not user_data:
  544. return 1
  545. if set_data[0][0] == 'admin':
  546. if not user_data:
  547. return 1
  548. if not admin_check(5, None) == 1:
  549. return 1
  550. return 0
  551. def ban_check(ip = None, tool = None):
  552. if not ip:
  553. ip = ip_check()
  554. band = re.search("^([0-9]{1,3}\.[0-9]{1,3})", ip)
  555. if band:
  556. band_it = band.groups()[0]
  557. else:
  558. band_it = '-'
  559. curs.execute("select end, login from ban where block = ?", [band_it])
  560. band_d = curs.fetchall()
  561. curs.execute("select end, login from ban where block = ?", [ip])
  562. ban_d = curs.fetchall()
  563. data = band_d or ban_d
  564. if data and (data[0][0] == '' or data[0][0] > get_time()):
  565. if tool and tool == 'login':
  566. if data[0][1] == 'O':
  567. return 0
  568. return 1
  569. return 0
  570. def topic_check(name, sub):
  571. ip = ip_check()
  572. if ban_check() == 1:
  573. return 1
  574. curs.execute("select acl from user where id = ?", [ip])
  575. user_data = curs.fetchall()
  576. curs.execute('select data from other where name = "discussion"')
  577. acl_data = curs.fetchall()
  578. if acl_data:
  579. if acl_data[0][0] == 'login':
  580. if not user_data:
  581. return 1
  582. if acl_data[0][0] == 'admin':
  583. if not user_data:
  584. return 1
  585. if not admin_check(3, 'topic (' + name + ')') == 1:
  586. return 1
  587. curs.execute("select dis from acl where title = ?", [name])
  588. acl_data = curs.fetchall()
  589. if acl_data:
  590. if acl_data[0][0] == 'user':
  591. if not user_data:
  592. return 1
  593. if acl_data[0][0] == 'admin':
  594. if not user_data:
  595. return 1
  596. if not admin_check(3, 'topic (' + name + ')') == 1:
  597. return 1
  598. curs.execute("select title from rd where title = ? and sub = ? and not stop = ''", [name, sub])
  599. if curs.fetchall():
  600. if not admin_check(3, 'topic (' + name + ')') == 1:
  601. return 1
  602. return 0
  603. def ban_insert(name, end, why, login, blocker):
  604. now_time = get_time()
  605. if re.search("^([0-9]{1,3}\.[0-9]{1,3})$", name):
  606. band = 'O'
  607. else:
  608. band = ''
  609. curs.execute("select block from ban where block = ?", [name])
  610. if curs.fetchall():
  611. curs.execute("insert into rb (block, end, today, blocker, why, band) values (?, ?, ?, ?, ?, ?)", [name, load_lang('release', 1), now_time, blocker, '', band])
  612. curs.execute("delete from ban where block = ?", [name])
  613. else:
  614. if login != '':
  615. login = 'O'
  616. else:
  617. login = ''
  618. if end != '0':
  619. time = datetime.datetime.now()
  620. plus = datetime.timedelta(seconds = int(end))
  621. r_time = (time + plus).strftime("%Y-%m-%d %H:%M:%S")
  622. else:
  623. r_time = ''
  624. curs.execute("insert into rb (block, end, today, blocker, why, band) values (?, ?, ?, ?, ?, ?)", [name, r_time, now_time, blocker, why, band])
  625. curs.execute("insert into ban (block, end, why, band, login) values (?, ?, ?, ?, ?)", [name, r_time, why, band, login])
  626. conn.commit()
  627. def rd_plus(title, sub, date):
  628. curs.execute("select title from rd where title = ? and sub = ?", [title, sub])
  629. if curs.fetchall():
  630. curs.execute("update rd set date = ? where title = ? and sub = ?", [date, title, sub])
  631. else:
  632. curs.execute("insert into rd (title, sub, date) values (?, ?, ?)", [title, sub, date])
  633. def history_plus(title, data, date, ip, send, leng):
  634. curs.execute("select id from history where title = ? order by id + 0 desc limit 1", [title])
  635. id_data = curs.fetchall()
  636. curs.execute("insert into history (id, title, data, date, ip, send, leng, hide) values (?, ?, ?, ?, ?, ?, ?, '')", [str(int(id_data[0][0]) + 1) if id_data else '1', title, data, date, ip, send, leng])
  637. def leng_check(first, second):
  638. if first < second:
  639. all_plus = '+' + str(second - first)
  640. elif second < first:
  641. all_plus = '-' + str(first - second)
  642. else:
  643. all_plus = '0'
  644. return all_plus
  645. def edit_filter_do(data):
  646. if admin_check(1, 'edit_filter pass') != 1:
  647. curs.execute("select regex, sub from filter")
  648. for data_list in curs.fetchall():
  649. match = re.compile(data_list[0], re.I)
  650. if match.search(data):
  651. ban_insert(
  652. ip_check(),
  653. '0' if data_list[1] == 'X' else data_list[1],
  654. load_lang('edit', 1) + ' ' + load_lang('filter', 1),
  655. None,
  656. load_lang('tool', 1) + ':' + load_lang('edit', 1) + ' ' + load_lang('filter', 1)
  657. )
  658. return 1
  659. return 0
  660. def redirect(data):
  661. return flask.redirect(data)
  662. def re_error(data):
  663. conn.commit()
  664. if data == '/ban':
  665. ip = ip_check()
  666. end = '<li>' + load_lang('why') + ' : ' + load_lang('authority_error') + '</li>'
  667. if ban_check() == 1:
  668. curs.execute("select end, why from ban where block = ?", [ip])
  669. end_data = curs.fetchall()
  670. if not end_data:
  671. match = re.search("^([0-9]{1,3}\.[0-9]{1,3})", ip)
  672. if match:
  673. curs.execute("select end, why from ban where block = ?", [match.groups()[0]])
  674. end_data = curs.fetchall()
  675. if end_data:
  676. end = '<li>' + load_lang('state') + ' : ' + load_lang('ban') + '</li><li>'
  677. if end_data[0][0]:
  678. now = int(re.sub('(\-| |:)', '', get_time()))
  679. day = int(re.sub('(\-| |:)', '', end_data[0][0]))
  680. if now >= day:
  681. curs.execute("delete from ban where block = ?", [ip])
  682. conn.commit()
  683. end += '<script>location.reload();</script>'
  684. else:
  685. end += 'end : ' + end_data[0][0]
  686. else:
  687. end += load_lang('limitless')
  688. end += '</li>'
  689. if end_data[0][1] != '':
  690. end += '<li>' + load_lang('why') + ' : ' + end_data[0][1] + '</li>'
  691. return easy_minify(flask.render_template(skin_check(),
  692. imp = ['error', wiki_set(1), custom(), other2([0, 0])],
  693. data = '<h2>error</h2><ul>' + end + '</ul>',
  694. menu = 0
  695. ))
  696. else:
  697. error_data = re.search('\/error\/([0-9]+)', data)
  698. if error_data:
  699. num = int(error_data.groups()[0])
  700. if num == 1:
  701. data = load_lang('no_login_error')
  702. elif num == 2:
  703. data = load_lang('no_exist_user_error')
  704. elif num == 3:
  705. data = load_lang('authority_error')
  706. elif num == 4:
  707. data = load_lang('no_admin_block_error')
  708. elif num == 5:
  709. data = load_lang('skin_error')
  710. elif num == 6:
  711. data = load_lang('same_id_exist_error')
  712. elif num == 7:
  713. data = load_lang('long_id_error')
  714. elif num == 8:
  715. data = load_lang('id_char_error') + ' <a href="/name_filter">(' + load_lang('id') + ' ' + load_lang('filter') + ')</a>'
  716. elif num == 9:
  717. data = load_lang('file_exist_error')
  718. elif num == 10:
  719. data = load_lang('password_error')
  720. elif num == 13:
  721. data = load_lang('recaptcha_error')
  722. elif num == 14:
  723. data = load_lang('file_extension_error')
  724. elif num == 15:
  725. data = load_lang('edit_record_error')
  726. elif num == 16:
  727. data = load_lang('same_file_error')
  728. elif num == 17:
  729. data = load_lang('file_capacity_error') + ' ' + wiki_set(3)
  730. elif num == 19:
  731. data = load_lang('decument_exist_error')
  732. elif num == 20:
  733. data = load_lang('password_diffrent_error')
  734. elif num == 21:
  735. data = load_lang('edit_filter_error')
  736. elif num == 22:
  737. data = load_lang('file_name_error')
  738. else:
  739. data = '???'
  740. return easy_minify(flask.render_template(skin_check(),
  741. imp = ['error', wiki_set(1), custom(), other2([0, 0])],
  742. data = '<h2>error</h2><ul><li>' + data + '</li></ul>',
  743. menu = 0
  744. ))
  745. else:
  746. return redirect('/')