app.py 57 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026
  1. from flask import Flask, request, session, render_template
  2. app = Flask(__name__)
  3. from urllib import parse
  4. import json
  5. import pymysql
  6. import time
  7. import re
  8. import bcrypt
  9. json_data=open('set.json').read()
  10. data = json.loads(json_data)
  11. conn = pymysql.connect(host = data['host'], user = data['user'], password = data['pw'], db = data['db'], charset = 'utf8')
  12. curs = conn.cursor(pymysql.cursors.DictCursor)
  13. app.secret_key = data['key']
  14. def namumark(title, data):
  15. data = '\n' + data + '\n'
  16. data = re.sub('<', '&lt;', data)
  17. data = re.sub('>', '&gt;', data)
  18. data = re.sub('"', '&quot;', data)
  19. data = re.sub("======\s?(?P<in>[^=]*)\s?======(?:\s+)?\n", '<h6>\g<in></h6>', data)
  20. data = re.sub("=====\s?(?P<in>[^=]*)\s?=====(?:\s+)?\n", '<h5>\g<in></h5>', data)
  21. data = re.sub("====\s?(?P<in>[^=]*)\s?====(?:\s+)?\n", '<h4>\g<in></h4>', data)
  22. data = re.sub("===\s?(?P<in>[^=]*)\s?===(?:\s+)?\n", '<h3>\g<in></h3>', data)
  23. data = re.sub("==\s?(?P<in>[^=]*)\s?==(?:\s+)?\n", '<h2>\g<in></h2>', data)
  24. data = re.sub("=\s?(?P<in>[^=]*)\s?=(?:\s+)?\n", '<h1>\g<in></h1>', data)
  25. data = re.sub("'''(?P<in>.+?)'''(?!')", '<b>\g<in></b>', data)
  26. data = re.sub("''(?P<in>.+?)''(?!')", '<i>\g<in></i>', data)
  27. data = re.sub('~~(?P<in>.+?)~~(?!~)', '<s>\g<in></s>', data)
  28. data = re.sub('--(?P<in>.+?)--(?!-)', '<s>\g<in></s>', data)
  29. data = re.sub('__(?P<in>.+?)__(?!_)', '<u>\g<in></u>', data)
  30. data = re.sub('\^\^(?P<in>.+?)\^\^(?!\^)', '<sup>\g<in></sup>', data)
  31. data = re.sub(',,(?P<in>.+?),,(?!,)', '<sub>\g<in></sub>', data)
  32. while True:
  33. p = re.compile("\[youtube\(((?:(?!,|\)\]).)*)(?:,\s)?(?:width=((?:(?!,|\)\]).)*))?(?:,\s)?(?:height=((?:(?!,|\)\]).)*))?(?:,\s)?(?:width=((?:(?!,|\)\]).)*))?\)\]", re.I)
  34. m = p.search(data)
  35. if(m):
  36. result = m.groups()
  37. if(result[1]):
  38. if(result[2]):
  39. width = result[1]
  40. height = result[2]
  41. else:
  42. width = result[1]
  43. height = '315'
  44. elif(result[2]):
  45. if(result[3]):
  46. height = result[2]
  47. width = result[3]
  48. else:
  49. height = result[2]
  50. width = '560'
  51. else:
  52. width = '560'
  53. height = '315'
  54. data = p.sub('<iframe width="' + width + '" height="' + height + '" src="https://www.youtube.com/embed/' + result[0] + '" frameborder="0" allowfullscreen></iframe>', data, 1)
  55. else:
  56. break
  57. while True:
  58. m = re.search("\[\[(((?!\]\]).)*)\]\]", data)
  59. if(m):
  60. result = m.groups()
  61. a = re.search("(((?!\|).)*)\|(.*)", result[0])
  62. if(a):
  63. results = a.groups()
  64. p = re.compile("^http(?:s)?:\/\/", re.I)
  65. b = p.search(results[0])
  66. if(b):
  67. data = re.sub('\[\[(((?!\]\]).)*)\]\]', '<a class="out_link" href="' + results[0] + '">' + results[2] + '</a>', data, 1)
  68. else:
  69. if(results[0] == title):
  70. data = re.sub('\[\[(((?!\]\]).)*)\]\]', '<b>' + results[2] + '</b>', data, 1)
  71. else:
  72. curs.execute("select * from data where title = '" + pymysql.escape_string(results[0]) + "'")
  73. rows = curs.fetchall()
  74. if(rows):
  75. data = re.sub('\[\[(((?!\]\]).)*)\]\]', '<a title="' + results[0] + '" href="/w/' + parse.quote(results[0]) + '">' + results[2] + '</a>', data, 1)
  76. else:
  77. data = re.sub('\[\[(((?!\]\]).)*)\]\]', '<a title="' + results[0] + '" class="not_thing" href="/w/' + parse.quote(results[0]) + '">' + results[2] + '</a>', data, 1)
  78. else:
  79. b = re.search("^[Hh][Tt][Tt][Pp]([Ss])?:\/\/", result[0])
  80. if(b):
  81. data = re.sub('\[\[(((?!\]\]).)*)\]\]', '<a class="out_link" href="' + result[0] + '">' + result[0] + '</a>', data, 1)
  82. else:
  83. if(result[0] == title):
  84. data = re.sub('\[\[(((?!\]\]).)*)\]\]', '<b>' + result[0] + '</b>', data, 1)
  85. else:
  86. curs.execute("select * from data where title = '" + pymysql.escape_string(result[0]) + "'")
  87. rows = curs.fetchall()
  88. if(rows):
  89. data = re.sub('\[\[(((?!\]\]).)*)\]\]', '<a href="/w/' + parse.quote(result[0]) + '">' + result[0] + '</a>', data, 1)
  90. else:
  91. data = re.sub('\[\[(((?!\]\]).)*)\]\]', '<a class="not_thing" href="/w/' + parse.quote(result[0]) + '">' + result[0] + '</a>', data, 1)
  92. else:
  93. break
  94. data = re.sub('\n', '<br>', data)
  95. return data
  96. def getip(request):
  97. if(session.get('Now') == True):
  98. ip = format(session['DREAMER'])
  99. else:
  100. if(request.headers.getlist("X-Forwarded-For")):
  101. ip = request.headers.getlist("X-Forwarded-For")[0]
  102. else:
  103. ip = request.remote_addr
  104. return ip
  105. def getcan(ip, name):
  106. curs.execute("select * from ban where block = '" + pymysql.escape_string(ip) + "'")
  107. rows = curs.fetchall()
  108. if(rows):
  109. return 1
  110. else:
  111. curs.execute("select * from data where title = '" + pymysql.escape_string(name) + "'")
  112. row = curs.fetchall()
  113. if(row):
  114. curs.execute("select * from user where id = '" + pymysql.escape_string(ip) + "'")
  115. rows = curs.fetchall()
  116. if(row[0]['acl'] == 'user'):
  117. if(rows):
  118. return 0
  119. else:
  120. return 1
  121. elif(row[0]['acl'] == 'admin'):
  122. if(rows):
  123. if(rows[0]['acl'] == 'admin' or rows[0]['acl'] == 'owner'):
  124. return 0
  125. else:
  126. return 1
  127. else:
  128. return 1
  129. else:
  130. return 0
  131. else:
  132. return 0
  133. def getban(ip):
  134. curs.execute("select * from ban where block = '" + pymysql.escape_string(ip) + "'")
  135. rows = curs.fetchall()
  136. if(rows):
  137. return 1
  138. else:
  139. return 0
  140. def getdiscuss(ip, name, sub):
  141. curs.execute("select * from ban where block = '" + pymysql.escape_string(ip) + "'")
  142. rows = curs.fetchall()
  143. if(rows):
  144. return 1
  145. else:
  146. curs.execute("select * from stop where title = '" + pymysql.escape_string(name) + "' and sub = '" + pymysql.escape_string(sub) + "'")
  147. rows = curs.fetchall()
  148. if(rows):
  149. return 1
  150. else:
  151. return 0
  152. def getnow():
  153. now = time.localtime()
  154. s = "%04d-%02d-%02d %02d:%02d:%02d" % (now.tm_year, now.tm_mon, now.tm_mday, now.tm_hour, now.tm_min, now.tm_sec)
  155. return s
  156. def recent(title, ip, today, send, leng):
  157. curs.execute("insert into rc (title, date, ip, send, leng, back) value ('" + pymysql.escape_string(title) + "', '" + today + "', '" + ip + "', '" + pymysql.escape_string(send) + "', '" + leng + "', '')")
  158. conn.commit()
  159. def discuss(title, sub, date):
  160. curs.execute("select * from rd where title = '" + pymysql.escape_string(title) + "' and sub = '" + pymysql.escape_string(sub) + "'")
  161. rows = curs.fetchall()
  162. if(rows):
  163. curs.execute("update rd set date = '" + pymysql.escape_string(date) + "' where title = '" + pymysql.escape_string(title) + "' and sub = '" + pymysql.escape_string(sub) + "'")
  164. else:
  165. curs.execute("insert into rd (title, sub, date) value ('" + pymysql.escape_string(title) + "', '" + pymysql.escape_string(sub) + "', '" + pymysql.escape_string(date) + "')")
  166. conn.commit()
  167. def history(title, data, date, ip, send, leng):
  168. curs.execute("select * from history where title = '" + pymysql.escape_string(title) + "' order by id+0 desc limit 1")
  169. rows = curs.fetchall()
  170. if(rows):
  171. number = int(rows[0]['id']) + 1
  172. curs.execute("insert into history (id, title, data, date, ip, send, leng) value ('" + str(number) + "', '" + pymysql.escape_string(title) + "', '" + pymysql.escape_string(data) + "', '" + date + "', '" + ip + "', '" + pymysql.escape_string(send) + "', '" + leng + "')")
  173. conn.commit()
  174. else:
  175. curs.execute("insert into history (id, title, data, date, ip, send, leng) value ('1', '" + pymysql.escape_string(title) + "', '" + pymysql.escape_string(data) + "', '" + date + "', '" + ip + "', '" + pymysql.escape_string(send) + "', '" + leng + "')")
  176. conn.commit()
  177. def getleng(existing, change):
  178. if(existing < change):
  179. leng = change - existing
  180. leng = '+' + str(leng)
  181. elif(change < existing):
  182. leng = existing - change
  183. leng = '-' + str(leng)
  184. else:
  185. leng = '0'
  186. return leng;
  187. @app.route('/')
  188. @app.route('/w/')
  189. def redirect():
  190. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(data['frontpage']) + '" />'
  191. @app.route('/recentchanges')
  192. def recentchanges():
  193. i = 0
  194. div = '<div>'
  195. curs.execute("select * from rc order by date desc limit 50")
  196. rows = curs.fetchall()
  197. if(rows):
  198. while True:
  199. try:
  200. a = rows[i]
  201. except:
  202. div = div + '</div>'
  203. break
  204. if(rows[i]['send']):
  205. send = rows[i]['send']
  206. send = re.sub('<', '&lt;', send)
  207. send = re.sub('>', '&gt;', send)
  208. send = re.sub('&lt;a href="\/w\/(?P<in>[^"]*)"&gt;(?P<out>[^&]*)&lt;\/a&gt;', '<a href="/w/\g<in>">\g<out></a>', send)
  209. else:
  210. send = '<br>'
  211. title = rows[i]['title']
  212. title = re.sub('<', '&lt;', title)
  213. title = re.sub('>', '&gt;', title)
  214. div = div + '<table style="width: 100%;"><tbody><tr><td style="text-align: center;width:33.33%;"><a href="/w/' + parse.quote(rows[i]['title']) + '">' + title + '</a> <a href="/history/' + parse.quote(rows[i]['title']) + '">(역사)</a> (' + rows[i]['leng'] + ')</td><td style="text-align: center;width:33.33%;">' + rows[i]['ip'] + '</td><td style="text-align: center;width:33.33%;">' + rows[i]['date'] + '</td></tr><tr><td colspan="3" style="text-align: center;width:100%;">' + send + '</td></tr></tbody></table>'
  215. i = i + 1
  216. return render_template('index.html', logo = data['name'], rows = div, tn = 3, title = '최근 변경내역')
  217. else:
  218. return render_template('index.html', logo = data['name'], rows = '', tn = 3, title = '최근 변경내역')
  219. @app.route('/recentdiscuss')
  220. def recentdiscuss():
  221. i = 0
  222. div = '<div>'
  223. curs.execute("select * from rd order by date desc limit 50")
  224. rows = curs.fetchall()
  225. if(rows):
  226. while True:
  227. try:
  228. a = rows[i]
  229. except:
  230. div = div + '</div>'
  231. break
  232. title = rows[i]['title']
  233. title = re.sub('<', '&lt;', title)
  234. title = re.sub('>', '&gt;', title)
  235. sub = rows[i]['sub']
  236. sub = re.sub('<', '&lt;', sub)
  237. sub = re.sub('>', '&gt;', sub)
  238. div = div + '<table style="width: 100%;"><tbody><tr><td style="text-align: center;width:50%;"><a href="/topic/' + parse.quote(rows[i]['title']) + '/sub/' + parse.quote(rows[i]['sub']) + '">' + title + '</a> (' + sub + ')</td><td style="text-align: center;width:50%;">' + rows[i]['date'] + '</td></tr></tbody></table>'
  239. i = i + 1
  240. return render_template('index.html', logo = data['name'], rows = div, tn = 12, title = '최근 토론내역')
  241. else:
  242. return render_template('index.html', logo = data['name'], rows = '', tn = 12, title = '최근 토론내역')
  243. @app.route('/history/<name>')
  244. def gethistory(name = None):
  245. i = 0
  246. div = '<div>'
  247. curs.execute("select * from history where title = '" + pymysql.escape_string(name) + "' order by date desc")
  248. rows = curs.fetchall()
  249. if(rows):
  250. while True:
  251. try:
  252. a = rows[i]
  253. except:
  254. div = div + '</div>'
  255. break
  256. if(rows[i]['send']):
  257. send = rows[i]['send']
  258. send = re.sub('<', '&lt;', send)
  259. send = re.sub('>', '&gt;', send)
  260. send = re.sub('&lt;a href="\/w\/(?P<in>[^"]*)"&gt;(?P<out>[^&]*)&lt;\/a&gt;', '<a href="/w/\g<in>">\g<out></a>', send)
  261. else:
  262. send = '<br>'
  263. div = div + '<table style="width: 100%;"><tbody><tr><td style="text-align: center;width:33.33%;">r' + rows[i]['id'] + '</a> <a href="/w/' + parse.quote(rows[i]['title']) + '/r/' + rows[i]['id'] + '">(w)</a> <a href="/w/' + parse.quote(rows[i]['title']) + '/raw/' + rows[i]['id'] + '">(Raw)</a> <a href="/revert/' + parse.quote(rows[i]['title']) + '/r/' + rows[i]['id'] + '">(되돌리기)</a> (' + rows[i]['leng'] + ')</td><td style="text-align: center;width:33.33%;">' + rows[i]['ip'] + '</td><td style="text-align: center;width:33.33%;">' + rows[i]['date'] + '</td></tr><tr><td colspan="3" style="text-align: center;width:100%;">' + send + '</td></tr></tbody></table>'
  264. i = i + 1
  265. return render_template('index.html', logo = data['name'], rows = div, tn = 5, title = name, page = parse.quote(name))
  266. else:
  267. return render_template('index.html', logo = data['name'], rows = '', tn = 5, title = name, page = parse.quote(name))
  268. @app.route('/search', methods=['POST', 'GET'])
  269. def search():
  270. if(request.method == 'POST'):
  271. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(request.form["search"]) + '" />'
  272. else:
  273. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(data['frontpage']) + '" />'
  274. @app.route('/w/<name>')
  275. def w(name = None):
  276. curs.execute("select * from data where title = '" + pymysql.escape_string(name) + "'")
  277. rows = curs.fetchall()
  278. if(rows):
  279. if(rows[0]['acl'] == 'admin'):
  280. acl = '(관리자)'
  281. elif(rows[0]['acl'] == 'user'):
  282. acl = '(유저)'
  283. else:
  284. acl = ''
  285. enddata = namumark(name, rows[0]['data'])
  286. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = enddata, license = data['license'], tn = 1, acl = acl)
  287. else:
  288. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = '<br>문서 없음', license = data['license'], tn = 1)
  289. @app.route('/w/<name>/redirect/<redirect>')
  290. def redirectw(name = None, redirect = None):
  291. curs.execute("select * from data where title = '" + pymysql.escape_string(name) + "'")
  292. rows = curs.fetchall()
  293. if(rows):
  294. enddata = namumark(name, rows[0]['data'])
  295. test = redirect
  296. redirect = re.sub('<', '&lt;', redirect)
  297. redirect = re.sub('>', '&gt;', redirect)
  298. redirect = re.sub('"', '&quot;', redirect)
  299. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = enddata, license = data['license'], tn = 1, redirect = '<a href="/w/' + parse.quote(test) + '">' + redirect + '</a>에서 넘어 왔습니다.')
  300. else:
  301. test = redirect
  302. redirect = re.sub('<', '&lt;', redirect)
  303. redirect = re.sub('>', '&gt;', redirect)
  304. redirect = re.sub('"', '&quot;', redirect)
  305. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = '<br>문서 없음', license = data['license'], tn = 1, redirect = '<a href="/w/' + parse.quote(test) + '">' + redirect + '</a>에서 넘어 왔습니다.')
  306. @app.route('/w/<name>/r/<number>')
  307. def rew(name = None, number = None):
  308. curs.execute("select * from history where title = '" + pymysql.escape_string(name) + "' and id = '" + number + "'")
  309. rows = curs.fetchall()
  310. if(rows):
  311. enddata = namumark(name, rows[0]['data'])
  312. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = enddata, license = data['license'], tn = 6)
  313. else:
  314. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = '<br>문서 없음', license = data['license'], tn = 6)
  315. @app.route('/w/<name>/raw/<number>')
  316. def reraw(name = None, number = None):
  317. curs.execute("select * from history where title = '" + pymysql.escape_string(name) + "' and id = '" + number + "'")
  318. rows = curs.fetchall()
  319. if(rows):
  320. enddata = re.sub("\n", '<br>', rows[0]['data'])
  321. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = enddata, license = data['license'])
  322. else:
  323. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = '<br>문서 없음', license = data['license'])
  324. @app.route('/raw/<name>')
  325. def raw(name = None):
  326. curs.execute("select * from data where title = '" + pymysql.escape_string(name) + "'")
  327. rows = curs.fetchall()
  328. if(rows):
  329. enddata = re.sub("\n", '<br>', rows[0]['data'])
  330. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = enddata, license = data['license'], tn = 7)
  331. else:
  332. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = '문서 없음', license = data['license'], tn = 7)
  333. @app.route('/revert/<name>/r/<number>', methods=['POST', 'GET'])
  334. def revert(name = None, number = None):
  335. if(request.method == 'POST'):
  336. curs.execute("select * from history where title = '" + pymysql.escape_string(name) + "' and id = '" + number + "'")
  337. rows = curs.fetchall()
  338. if(rows):
  339. ip = getip(request)
  340. can = getcan(ip, name)
  341. if(can == 1):
  342. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  343. else:
  344. today = getnow()
  345. curs.execute("select * from data where title = '" + pymysql.escape_string(name) + "'")
  346. row = curs.fetchall()
  347. if(row):
  348. leng = getleng(len(row[0]['data']), len(rows[0]['data']))
  349. curs.execute("update data set data = '" + pymysql.escape_string(rows[0]['data']) + "' where title = '" + pymysql.escape_string(name) + "'")
  350. conn.commit()
  351. else:
  352. leng = '+' + str(len(rows[0]['data']))
  353. curs.execute("insert into data (title, data, acl) value ('" + pymysql.escape_string(name) + "', '" + pymysql.escape_string(rows[0]['data']) + "', '')")
  354. conn.commit()
  355. recent(name, ip, today, '문서를 ' + number + '판으로 되돌렸습니다.', leng)
  356. history(name, rows[0]['data'], today, ip, '문서를 ' + number + '판으로 되돌렸습니다.', leng)
  357. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(name) + '" />'
  358. else:
  359. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(name) + '" />'
  360. else:
  361. ip = getip(request)
  362. can = getcan(ip, name)
  363. if(can == 1):
  364. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  365. else:
  366. curs.execute("select * from history where title = '" + pymysql.escape_string(name) + "' and id = '" + number + "'")
  367. rows = curs.fetchall()
  368. if(rows):
  369. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), r = parse.quote(number), tn = 13, plus = '정말 되돌리시겠습니까?')
  370. else:
  371. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(name) + '" />'
  372. @app.route('/edit/<name>', methods=['POST', 'GET'])
  373. def edit(name = None):
  374. if(request.method == 'POST'):
  375. curs.execute("select * from data where title = '" + pymysql.escape_string(name) + "'")
  376. rows = curs.fetchall()
  377. if(rows):
  378. ip = getip(request)
  379. can = getcan(ip, name)
  380. if(can == 1):
  381. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  382. else:
  383. today = getnow()
  384. leng = getleng(len(rows[0]['data']), len(request.form["content"]))
  385. recent(name, ip, today, request.form["send"], leng)
  386. history(name, request.form["content"], today, ip, request.form["send"], leng)
  387. curs.execute("update data set data = '" + pymysql.escape_string(request.form["content"]) + "' where title = '" + pymysql.escape_string(name) + "'")
  388. conn.commit()
  389. else:
  390. ip = getip(request)
  391. can = getcan(ip, name)
  392. if(can == 1):
  393. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  394. else:
  395. today = getnow()
  396. leng = '+' + str(len(request.form["content"]))
  397. recent(name, ip, today, request.form["send"], leng)
  398. history(name, request.form["content"], today, ip, request.form["send"], leng)
  399. curs.execute("insert into data (title, data, acl) value ('" + pymysql.escape_string(name) + "', '" + pymysql.escape_string(request.form["content"]) + "', '')")
  400. conn.commit()
  401. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(name) + '" />'
  402. else:
  403. ip = getip(request)
  404. can = getcan(ip, name)
  405. if(can == 1):
  406. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  407. else:
  408. curs.execute("select * from data where title = '" + pymysql.escape_string(name) + "'")
  409. rows = curs.fetchall()
  410. if(rows):
  411. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = rows[0]['data'], tn = 2)
  412. else:
  413. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = '', tn = 2)
  414. @app.route('/preview/<name>', methods=['POST'])
  415. def preview(name = None):
  416. ip = getip(request)
  417. can = getcan(ip, name)
  418. if(can == 1):
  419. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  420. else:
  421. enddata = namumark(name, request.form["content"])
  422. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = request.form["content"], tn = 2, preview = 1, enddata = enddata)
  423. @app.route('/delete/<name>', methods=['POST', 'GET'])
  424. def delete(name = None):
  425. if(request.method == 'POST'):
  426. curs.execute("select * from data where title = '" + pymysql.escape_string(name) + "'")
  427. rows = curs.fetchall()
  428. if(rows):
  429. ip = getip(request)
  430. can = getcan(ip, name)
  431. if(can == 1):
  432. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  433. else:
  434. today = getnow()
  435. leng = '-' + str(len(rows[0]['data']))
  436. recent(name, ip, today, '문서를 삭제 했습니다.', leng)
  437. history(name, '', today, ip, '문서를 삭제 했습니다.', leng)
  438. curs.execute("delete from data where title = '" + pymysql.escape_string(name) + "'")
  439. conn.commit()
  440. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(name) + '" />'
  441. else:
  442. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(name) + '" />'
  443. else:
  444. curs.execute("select * from data where title = '" + pymysql.escape_string(name) + "'")
  445. rows = curs.fetchall()
  446. if(rows):
  447. ip = getip(request)
  448. can = getcan(ip, name)
  449. if(can == 1):
  450. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  451. else:
  452. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), tn = 8, plus = '정말 삭제 하시겠습니까?')
  453. else:
  454. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(name) + '" />'
  455. @app.route('/move/<name>', methods=['POST', 'GET'])
  456. def move(name = None):
  457. if(request.method == 'POST'):
  458. curs.execute("select * from data where title = '" + pymysql.escape_string(name) + "'")
  459. rows = curs.fetchall()
  460. if(rows):
  461. ip = getip(request)
  462. can = getcan(ip, name)
  463. if(can == 1):
  464. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  465. else:
  466. today = getnow()
  467. leng = '0'
  468. curs.execute("select * from history where title = '" + pymysql.escape_string(request.form["title"]) + "'")
  469. row = curs.fetchall()
  470. if(row):
  471. return render_template('index.html', title = '이동 오류', logo = data['name'], data = '이동 하려는 곳에 문서가 이미 있습니다.')
  472. else:
  473. recent(name, ip, today, '문서를 <a href="/w/' + pymysql.escape_string(parse.quote(request.form["title"])) + '">' + pymysql.escape_string(request.form["title"]) + '</a> 문서로 이동 했습니다.', leng)
  474. history(name, rows[0]['data'], today, ip, '<a href="/w/' + pymysql.escape_string(parse.quote(name)) + '">' + pymysql.escape_string(name) + '</a> 문서를 <a href="/w/' + pymysql.escape_string(parse.quote(request.form["title"])) + '">' + pymysql.escape_string(request.form["title"]) + '</a> 문서로 이동 했습니다.', leng)
  475. curs.execute("update data set title = '" + pymysql.escape_string(request.form["title"]) + "' where title = '" + pymysql.escape_string(name) + "'")
  476. curs.execute("update history set title = '" + pymysql.escape_string(request.form["title"]) + "' where title = '" + pymysql.escape_string(name) + "'")
  477. conn.commit()
  478. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(request.form["title"]) + '" />'
  479. else:
  480. ip = getip(request)
  481. can = getcan(ip, name)
  482. if(can == 1):
  483. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  484. else:
  485. today = getnow()
  486. leng = '0'
  487. curs.execute("select * from history where title = '" + pymysql.escape_string(request.form["title"]) + "'")
  488. row = curs.fetchall()
  489. if(row):
  490. return render_template('index.html', title = '이동 오류', logo = data['name'], data = '이동 하려는 곳에 문서가 이미 있습니다.')
  491. else:
  492. recent(name, ip, today, '문서를 <a href="/w/' + pymysql.escape_string(parse.quote(request.form["title"])) + '">' + pymysql.escape_string(request.form["title"]) + '</a> 문서로 이동 했습니다.', leng)
  493. history(name, rows[0]['data'], today, ip, '<a href="/w/' + pymysql.escape_string(parse.quote(name)) + '">' + pymysql.escape_string(name) + '</a> 문서를 <a href="/w/' + pymysql.escape_string(parse.quote(request.form["title"])) + '">' + pymysql.escape_string(request.form["title"]) + '</a> 문서로 이동 했습니다.', leng)
  494. curs.execute("update history set title = '" + pymysql.escape_string(request.form["title"]) + "' where title = '" + pymysql.escape_string(name) + "'")
  495. conn.commit()
  496. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(request.form["title"]) + '" />'
  497. else:
  498. ip = getip(request)
  499. can = getcan(ip, name)
  500. if(can == 1):
  501. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  502. else:
  503. return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), tn = 9, plus = '정말 이동 하시겠습니까?')
  504. @app.route('/setup')
  505. def setup():
  506. curs.execute("create table if not exists data(title text not null, data longtext not null, acl text not null)")
  507. curs.execute("create table if not exists history(id text not null, title text not null, data longtext not null, date text not null, ip text not null, send text not null, leng text not null)")
  508. curs.execute("create table if not exists rc(title text not null, date text not null, ip text not null, send text not null, leng text not null, back text not null)")
  509. curs.execute("create table if not exists rd(title text not null, sub text not null, date text not null)")
  510. curs.execute("create table if not exists user(id text not null, pw text not null, acl text not null)")
  511. curs.execute("create table if not exists ban(block text not null, end text not null, why text not null, band text not null)")
  512. curs.execute("create table if not exists topic(id text not null, title text not null, sub text not null, data longtext not null, date text not null, ip text not null, block text not null)")
  513. curs.execute("create table if not exists stop(title text not null, sub text not null, close text not null)")
  514. return render_template('index.html', title = '설치 완료', logo = data['name'], data = '문제 없었음')
  515. @app.route('/other')
  516. def other():
  517. return render_template('index.html', title = '기타 메뉴', logo = data['name'], data = '<li><a href="/titleindex">모든 문서</a><li><a href="/grammar">문법 설명</a></li><li><a href="/version">버전</a></li>')
  518. @app.route('/titleindex')
  519. def titleindex():
  520. i = 0
  521. div = '<div>'
  522. curs.execute("select * from data")
  523. rows = curs.fetchall()
  524. if(rows):
  525. while True:
  526. try:
  527. a = rows[i]
  528. except:
  529. div = div + '</div>'
  530. break
  531. div = div + '<li><a href="/w/' + parse.quote(rows[i]['title']) + '">' + rows[i]['title'] + '</a></li>'
  532. i = i + 1
  533. return render_template('index.html', logo = data['name'], rows = div, tn = 4, title = '모든 문서')
  534. else:
  535. return render_template('index.html', logo = data['name'], rows = '', tn = 4, title = '모든 문서')
  536. @app.route('/topic/<name>', methods=['POST', 'GET'])
  537. def topic(name = None):
  538. if(request.method == 'POST'):
  539. return '<meta http-equiv="refresh" content="0;url=/topic/' + parse.quote(name) + '/sub/' + parse.quote(request.form["topic"]) + '" />'
  540. else:
  541. div = '<div>'
  542. i = 0
  543. curs.execute("select * from topic where title = '" + pymysql.escape_string(name) + "' order by sub asc")
  544. rows = curs.fetchall()
  545. while True:
  546. try:
  547. a = rows[i]
  548. except:
  549. div = div + '</div>'
  550. break
  551. if(i == 0):
  552. sub = rows[i]['sub']
  553. curs.execute("select * from stop where title = '" + pymysql.escape_string(name) + "' and sub = '" + pymysql.escape_string(sub) + "' and close = 'O'")
  554. row = curs.fetchall()
  555. if(not row):
  556. div = div + '<li><a href="/topic/' + parse.quote(name) + '/sub/' + parse.quote(rows[i]['sub']) + '">' + rows[i]['sub'] + '</a></li>'
  557. else:
  558. if(not sub == rows[i]['sub']):
  559. sub = rows[i]['sub']
  560. curs.execute("select * from stop where title = '" + pymysql.escape_string(name) + "' and sub = '" + pymysql.escape_string(sub) + "' and close = 'O'")
  561. row = curs.fetchall()
  562. if(not row):
  563. div = div + '<li><a href="/topic/' + parse.quote(name) + '/sub/' + parse.quote(rows[i]['sub']) + '">' + rows[i]['sub'] + '</a></li>'
  564. i = i + 1
  565. return render_template('index.html', title = name, page = parse.quote(name), logo = data['name'], plus = div, tn = 10, list = 1)
  566. @app.route('/topic/<name>/close')
  567. def topicstoplist(name = None):
  568. if(request.method == 'POST'):
  569. return '<meta http-equiv="refresh" content="0;url=/topic/' + parse.quote(name) + '/sub/' + parse.quote(request.form["topic"]) + '" />'
  570. else:
  571. div = '<div>'
  572. i = 0
  573. curs.execute("select * from stop where title = '" + pymysql.escape_string(name) + "' and close = 'O' order by sub asc")
  574. rows = curs.fetchall()
  575. while True:
  576. try:
  577. a = rows[i]
  578. except:
  579. div = div + '</div>'
  580. break
  581. if(i == 0):
  582. sub = rows[i]['sub']
  583. div = div + '<li><a href="/topic/' + parse.quote(name) + '/sub/' + parse.quote(rows[i]['sub']) + '">' + rows[i]['sub'] + '</a></li>'
  584. else:
  585. if(not sub == rows[i]['sub']):
  586. sub = rows[i]['sub']
  587. div = div + '<li><a href="/topic/' + parse.quote(name) + '/sub/' + parse.quote(rows[i]['sub']) + '">' + rows[i]['sub'] + '</a></li>'
  588. i = i + 1
  589. return render_template('index.html', title = name, page = parse.quote(name), logo = data['name'], plus = div, tn = 10)
  590. @app.route('/topic/<name>/sub/<sub>', methods=['POST', 'GET'])
  591. def sub(name = None, sub = None):
  592. if(request.method == 'POST'):
  593. curs.execute("select * from topic where title = '" + pymysql.escape_string(name) + "' and sub = '" + pymysql.escape_string(sub) + "' order by id+0 desc limit 1")
  594. rows = curs.fetchall()
  595. if(rows):
  596. number = int(rows[0]['id']) + 1
  597. else:
  598. number = 1
  599. ip = getip(request)
  600. ban = getdiscuss(ip, name, sub)
  601. if(ban == 1):
  602. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  603. else:
  604. curs.execute("select * from user where id = '" + pymysql.escape_string(ip) + "'")
  605. rows = curs.fetchall()
  606. if(rows):
  607. if(rows[0]['acl'] == 'owner' or rows[0]['acl'] == 'admin'):
  608. ip = ip + ' - Admin'
  609. today = getnow()
  610. discuss(name, sub, today)
  611. curs.execute("insert into topic (id, title, sub, data, date, ip, block) value ('" + str(number) + "', '" + pymysql.escape_string(name) + "', '" + pymysql.escape_string(sub) + "', '" + pymysql.escape_string(request.form["content"]) + "', '" + today + "', '" + ip + "', '')")
  612. conn.commit()
  613. return '<meta http-equiv="refresh" content="0;url=/topic/' + parse.quote(name) + '/sub/' + parse.quote(sub) + '" />'
  614. else:
  615. ip = getip(request)
  616. ban = getdiscuss(ip, name, sub)
  617. div = '<div>'
  618. i = 0
  619. curs.execute("select * from topic where title = '" + pymysql.escape_string(name) + "' and sub = '" + pymysql.escape_string(sub) + "' order by id+0 asc")
  620. rows = curs.fetchall()
  621. while True:
  622. try:
  623. a = rows[i]
  624. except:
  625. div = div + '</div>'
  626. break
  627. if(i == 0):
  628. start = rows[i]['ip']
  629. indata = rows[i]['data']
  630. indata = re.sub('<', '&lt;', indata)
  631. indata = re.sub('>', '&gt;', indata)
  632. indata = re.sub('"', '&quot;', indata)
  633. indata = re.sub('\n', '<br>', indata)
  634. if(rows[i]['block'] == 'O'):
  635. indata = '블라인드 되었습니다.'
  636. block = 'style="background: gainsboro;"'
  637. else:
  638. block = ''
  639. if(rows[i]['ip'] == start):
  640. j = i + 1
  641. div = div + '<table id="toron"><tbody><tr><td id="toroncolorgreen"><a href="javascript:void(0);" id="' + str(j) + '">#' + str(j) + '</a> ' + rows[i]['ip'] + ' <span style="float:right;">' + rows[i]['date'] + '</span></td></tr><tr><td ' + block + '>' + indata + '</td></tr></tbody></table><br>'
  642. else:
  643. j = i + 1
  644. div = div + '<table id="toron"><tbody><tr><td id="toroncolor"><a href="javascript:void(0);" id="' + str(j) + '">#' + str(j) + '</a> ' + rows[i]['ip'] + ' <span style="float:right;">' + rows[i]['date'] + '</span></td></tr><tr><td ' + block + '>' + indata + '</td></tr></tbody></table><br>'
  645. i = i + 1
  646. return render_template('index.html', title = name, page = parse.quote(name), suburl = parse.quote(sub), sub = sub, logo = data['name'], rows = div, tn = 11, ban = ban)
  647. @app.route('/topic/<name>/sub/<sub>/b/<number>')
  648. def blind(name = None, sub = None, number = None):
  649. if(session.get('Now') == True):
  650. ip = getip(request)
  651. curs.execute("select * from user where id = '" + pymysql.escape_string(ip) + "'")
  652. rows = curs.fetchall()
  653. if(rows):
  654. if(rows[0]['acl'] == 'owner' or rows[0]['acl'] == 'admin'):
  655. curs.execute("select * from topic where title = '" + pymysql.escape_string(name) + "' and sub = '" + pymysql.escape_string(sub) + "' and id = '" + number + "'")
  656. row = curs.fetchall()
  657. if(row):
  658. if(row[0]['block'] == 'O'):
  659. curs.execute("update topic set block = '' where title = '" + pymysql.escape_string(name) + "' and sub = '" + pymysql.escape_string(sub) + "' and id = '" + number + "'")
  660. else:
  661. curs.execute("update topic set block = 'O' where title = '" + pymysql.escape_string(name) + "' and sub = '" + pymysql.escape_string(sub) + "' and id = '" + number + "'")
  662. conn.commit()
  663. return '<meta http-equiv="refresh" content="0;url=/topic/' + name + '/sub/' + sub + '" />'
  664. else:
  665. return '<meta http-equiv="refresh" content="0;url=/topic/' + name + '/sub/' + sub + '" />'
  666. else:
  667. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '권한이 모자랍니다.')
  668. else:
  669. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '계정이 없습니다.')
  670. else:
  671. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '비 로그인 상태 입니다.')
  672. @app.route('/topic/<name>/sub/<sub>/stop')
  673. def topicstop(name = None, sub = None):
  674. if(session.get('Now') == True):
  675. ip = getip(request)
  676. curs.execute("select * from user where id = '" + pymysql.escape_string(ip) + "'")
  677. rows = curs.fetchall()
  678. if(rows):
  679. if(rows[0]['acl'] == 'owner' or rows[0]['acl'] == 'admin'):
  680. curs.execute("select * from topic where title = '" + pymysql.escape_string(name) + "' and sub = '" + pymysql.escape_string(sub) + "' order by id+0 desc limit 1")
  681. row = curs.fetchall()
  682. if(row):
  683. today = getnow()
  684. curs.execute("select * from stop where title = '" + pymysql.escape_string(name) + "' and sub = '" + pymysql.escape_string(sub) + "' and close = ''")
  685. rows = curs.fetchall()
  686. if(rows):
  687. curs.execute("insert into topic (id, title, sub, data, date, ip, block) value ('" + pymysql.escape_string(str(int(row[0]['id']) + 1)) + "', '" + pymysql.escape_string(name) + "', '" + pymysql.escape_string(sub) + "', 'Restart', '" + pymysql.escape_string(today) + "', '" + pymysql.escape_string(ip) + " - Restart', '')")
  688. curs.execute("delete from stop where title = '" + pymysql.escape_string(name) + "' and sub = '" + pymysql.escape_string(sub) + "' and close = ''")
  689. else:
  690. curs.execute("insert into topic (id, title, sub, data, date, ip, block) value ('" + pymysql.escape_string(str(int(row[0]['id']) + 1)) + "', '" + pymysql.escape_string(name) + "', '" + pymysql.escape_string(sub) + "', 'Stop', '" + pymysql.escape_string(today) + "', '" + pymysql.escape_string(ip) + " - Stop', '')")
  691. curs.execute("insert into stop (title, sub, close) value ('" + pymysql.escape_string(name) + "', '" + pymysql.escape_string(sub) + "', '')")
  692. conn.commit()
  693. return '<meta http-equiv="refresh" content="0;url=/topic/' + name + '/sub/' + sub + '" />'
  694. else:
  695. return '<meta http-equiv="refresh" content="0;url=/topic/' + name + '/sub/' + sub + '" />'
  696. else:
  697. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '권한이 모자랍니다.')
  698. else:
  699. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '계정이 없습니다.')
  700. else:
  701. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '비 로그인 상태 입니다.')
  702. @app.route('/topic/<name>/sub/<sub>/close')
  703. def topicclose(name = None, sub = None):
  704. if(session.get('Now') == True):
  705. ip = getip(request)
  706. curs.execute("select * from user where id = '" + pymysql.escape_string(ip) + "'")
  707. rows = curs.fetchall()
  708. if(rows):
  709. if(rows[0]['acl'] == 'owner' or rows[0]['acl'] == 'admin'):
  710. curs.execute("select * from topic where title = '" + pymysql.escape_string(name) + "' and sub = '" + pymysql.escape_string(sub) + "' order by id+0 desc limit 1")
  711. row = curs.fetchall()
  712. if(row):
  713. today = getnow()
  714. curs.execute("select * from stop where title = '" + pymysql.escape_string(name) + "' and sub = '" + pymysql.escape_string(sub) + "' and close = 'O'")
  715. rows = curs.fetchall()
  716. if(rows):
  717. curs.execute("insert into topic (id, title, sub, data, date, ip, block) value ('" + pymysql.escape_string(str(int(row[0]['id']) + 1)) + "', '" + pymysql.escape_string(name) + "', '" + pymysql.escape_string(sub) + "', 'Reopen', '" + pymysql.escape_string(today) + "', '" + pymysql.escape_string(ip) + " - Reopen', '')")
  718. curs.execute("delete from stop where title = '" + pymysql.escape_string(name) + "' and sub = '" + pymysql.escape_string(sub) + "' and close = 'O'")
  719. else:
  720. curs.execute("insert into topic (id, title, sub, data, date, ip, block) value ('" + pymysql.escape_string(str(int(row[0]['id']) + 1)) + "', '" + pymysql.escape_string(name) + "', '" + pymysql.escape_string(sub) + "', 'Close', '" + pymysql.escape_string(today) + "', '" + pymysql.escape_string(ip) + " - Close', '')")
  721. curs.execute("insert into stop (title, sub, close) value ('" + pymysql.escape_string(name) + "', '" + pymysql.escape_string(sub) + "', 'O')")
  722. conn.commit()
  723. return '<meta http-equiv="refresh" content="0;url=/topic/' + name + '/sub/' + sub + '" />'
  724. else:
  725. return '<meta http-equiv="refresh" content="0;url=/topic/' + name + '/sub/' + sub + '" />'
  726. else:
  727. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '권한이 모자랍니다.')
  728. else:
  729. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '계정이 없습니다.')
  730. else:
  731. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '비 로그인 상태 입니다.')
  732. @app.route('/login', methods=['POST', 'GET'])
  733. def login():
  734. if(request.method == 'POST'):
  735. ip = getip(request)
  736. ban = getban(ip)
  737. if(ban == 1):
  738. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  739. else:
  740. curs.execute("select * from user where id = '" + pymysql.escape_string(request.form["id"]) + "'")
  741. rows = curs.fetchall()
  742. if(rows):
  743. if(session.get('Now') == True):
  744. return render_template('index.html', title = '로그인 오류', logo = data['name'], data = '이미 로그인 되어 있습니다.')
  745. elif(bcrypt.checkpw(bytes(request.form["pw"], 'utf-8'), bytes(rows[0]['pw'], 'utf-8'))):
  746. session['Now'] = True
  747. session['DREAMER'] = request.form["id"]
  748. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(data['frontpage']) + '" />'
  749. else:
  750. return render_template('index.html', title = '로그인 오류', logo = data['name'], data = '비밀번호가 다릅니다.')
  751. else:
  752. return render_template('index.html', title = '로그인 오류', logo = data['name'], data = '없는 계정 입니다.')
  753. else:
  754. ip = getip(request)
  755. ban = getban(ip)
  756. if(ban == 1):
  757. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  758. else:
  759. if(session.get('Now') == True):
  760. return render_template('index.html', title = '로그인 오류', logo = data['name'], data = '이미 로그인 되어 있습니다.')
  761. else:
  762. return render_template('index.html', title = '로그인', enter = '로그인', logo = data['name'], tn = 15)
  763. @app.route('/register', methods=['POST', 'GET'])
  764. def register():
  765. if(request.method == 'POST'):
  766. ip = getip(request)
  767. ban = getban(ip)
  768. if(ban == 1):
  769. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  770. else:
  771. p = re.compile('(?:[^A-Za-zㄱ-힣0-9 ])')
  772. m = p.search(request.form["id"])
  773. if(m):
  774. return render_template('index.html', title = '회원가입 오류', logo = data['name'], data = '아이디에는 한글과 알파벳 공백만 허용 됩니다.')
  775. else:
  776. curs.execute("select * from user where id = '" + pymysql.escape_string(request.form["id"]) + "'")
  777. rows = curs.fetchall()
  778. if(rows):
  779. return render_template('index.html', title = '회원가입 오류', logo = data['name'], data = '동일한 아이디의 유저가 있습니다.')
  780. else:
  781. hashed = bcrypt.hashpw(bytes(request.form["pw"], 'utf-8'), bcrypt.gensalt())
  782. if(request.form["id"] == data['owner']):
  783. curs.execute("insert into user (id, pw, acl) value ('" + pymysql.escape_string(request.form["id"]) + "', '" + pymysql.escape_string(hashed.decode()) + "', 'owner')")
  784. else:
  785. curs.execute("insert into user (id, pw, acl) value ('" + pymysql.escape_string(request.form["id"]) + "', '" + pymysql.escape_string(hashed.decode()) + "', 'user')")
  786. conn.commit()
  787. return '<meta http-equiv="refresh" content="0;url=/login" />'
  788. else:
  789. ip = getip(request)
  790. ban = getban(ip)
  791. if(ban == 1):
  792. return '<meta http-equiv="refresh" content="0;url=/ban" />'
  793. else:
  794. return render_template('index.html', title = '회원가입', enter = '회원가입', logo = data['name'], tn = 15)
  795. @app.route('/logout')
  796. def logout():
  797. session['Now'] = False
  798. session.pop('DREAMER', None)
  799. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(data['frontpage']) + '" />'
  800. @app.route('/ban/<name>', methods=['POST', 'GET'])
  801. def ban(name = None):
  802. if(request.method == 'POST'):
  803. if(session.get('Now') == True):
  804. ip = getip(request)
  805. curs.execute("select * from user where id = '" + pymysql.escape_string(ip) + "'")
  806. rows = curs.fetchall()
  807. if(rows):
  808. if(rows[0]['acl'] == 'owner' or rows[0]['acl'] == 'admin'):
  809. curs.execute("select * from ban where block = '" + pymysql.escape_string(name) + "'")
  810. row = curs.fetchall()
  811. if(row):
  812. curs.execute("delete from ban where block = '" + pymysql.escape_string(name) + "'")
  813. else:
  814. curs.execute("insert into ban (block, end, why, band) value ('" + pymysql.escape_string(name) + "', '" + pymysql.escape_string(request.form["end"]) + "', '" + pymysql.escape_string(request.form["why"]) + "', '')")
  815. conn.commit()
  816. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(data['frontpage']) + '" />'
  817. else:
  818. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '권한이 모자랍니다.')
  819. else:
  820. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '계정이 없습니다.')
  821. else:
  822. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '비 로그인 상태 입니다.')
  823. else:
  824. if(session.get('Now') == True):
  825. ip = getip(request)
  826. curs.execute("select * from user where id = '" + pymysql.escape_string(ip) + "'")
  827. rows = curs.fetchall()
  828. if(rows):
  829. if(rows[0]['acl'] == 'owner' or rows[0]['acl'] == 'admin'):
  830. curs.execute("select * from ban where block = '" + pymysql.escape_string(name) + "'")
  831. row = curs.fetchall()
  832. if(row):
  833. now = '차단 해제'
  834. else:
  835. now = '차단'
  836. return render_template('index.html', title = name, page = parse.quote(name), logo = data['name'], tn = 16, now = now)
  837. else:
  838. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '권한이 모자랍니다.')
  839. else:
  840. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '계정이 없습니다.')
  841. else:
  842. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '비 로그인 상태 입니다.')
  843. @app.route('/acl/<name>', methods=['POST', 'GET'])
  844. def acl(name = None):
  845. if(request.method == 'POST'):
  846. if(session.get('Now') == True):
  847. ip = getip(request)
  848. curs.execute("select * from user where id = '" + pymysql.escape_string(ip) + "'")
  849. rows = curs.fetchall()
  850. if(rows):
  851. if(rows[0]['acl'] == 'owner' or rows[0]['acl'] == 'admin'):
  852. curs.execute("select * from data where title = '" + pymysql.escape_string(name) + "'")
  853. row = curs.fetchall()
  854. if(row):
  855. if(request.form["select"] == 'admin'):
  856. curs.execute("update data set acl = 'admin' where title = '" + pymysql.escape_string(name) + "'")
  857. elif(request.form["select"] == 'user'):
  858. curs.execute("update data set acl = 'user' where title = '" + pymysql.escape_string(name) + "'")
  859. else:
  860. curs.execute("update data set acl = '' where title = '" + pymysql.escape_string(name) + "'")
  861. conn.commit()
  862. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(name) + '" />'
  863. else:
  864. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '권한이 모자랍니다.')
  865. else:
  866. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '계정이 없습니다.')
  867. else:
  868. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '비 로그인 상태 입니다.')
  869. else:
  870. if(session.get('Now') == True):
  871. ip = getip(request)
  872. curs.execute("select * from user where id = '" + pymysql.escape_string(ip) + "'")
  873. rows = curs.fetchall()
  874. if(rows):
  875. if(rows[0]['acl'] == 'owner' or rows[0]['acl'] == 'admin'):
  876. curs.execute("select * from data where title = '" + pymysql.escape_string(name) + "'")
  877. row = curs.fetchall()
  878. if(row):
  879. if(row[0]['acl'] == 'admin'):
  880. now = '관리자만'
  881. elif(row[0]['acl'] == 'user'):
  882. now = '유저 이상'
  883. else:
  884. now = '일반'
  885. return render_template('index.html', title = name, page = parse.quote(name), logo = data['name'], tn = 19, now = '현재 ACL 상태는 ' + now)
  886. else:
  887. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(name) + '" />'
  888. else:
  889. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '권한이 모자랍니다.')
  890. else:
  891. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '계정이 없습니다.')
  892. else:
  893. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '비 로그인 상태 입니다.')
  894. @app.route('/admin/<name>', methods=['POST', 'GET'])
  895. def admin(name = None):
  896. if(request.method == 'POST'):
  897. if(session.get('Now') == True):
  898. ip = getip(request)
  899. curs.execute("select * from user where id = '" + pymysql.escape_string(ip) + "'")
  900. rows = curs.fetchall()
  901. if(rows):
  902. if(rows[0]['acl'] == 'owner' or rows[0]['acl'] == 'admin'):
  903. curs.execute("select * from user where id = '" + pymysql.escape_string(name) + "'")
  904. row = curs.fetchall()
  905. if(row):
  906. if(row[0]['acl'] == 'admin' or row[0]['acl'] == 'owner'):
  907. curs.execute("update user set acl = 'user' where id = '" + pymysql.escape_string(name) + "'")
  908. else:
  909. curs.execute("update user set acl = '" + pymysql.escape_string(request.form["select"]) + "' where id = '" + pymysql.escape_string(name) + "'")
  910. conn.commit()
  911. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(data['frontpage']) + '" />'
  912. else:
  913. return render_template('index.html', title = '사용자 오류', logo = data['name'], data = '계정이 없습니다.')
  914. else:
  915. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '권한이 모자랍니다.')
  916. else:
  917. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '계정이 없습니다.')
  918. else:
  919. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '비 로그인 상태 입니다.')
  920. else:
  921. if(session.get('Now') == True):
  922. ip = getip(request)
  923. curs.execute("select * from user where id = '" + pymysql.escape_string(ip) + "'")
  924. rows = curs.fetchall()
  925. if(rows):
  926. if(rows[0]['acl'] == 'owner'):
  927. curs.execute("select * from user where id = '" + pymysql.escape_string(name) + "'")
  928. row = curs.fetchall()
  929. if(row):
  930. if(row[0]['acl'] == 'admin' or row[0]['acl'] == 'owner'):
  931. now = '권한 해제'
  932. else:
  933. now = '권한 부여'
  934. return render_template('index.html', title = name, page = parse.quote(name), logo = data['name'], tn = 18, now = now)
  935. else:
  936. return render_template('index.html', title = '사용자 오류', logo = data['name'], data = '계정이 없습니다.')
  937. else:
  938. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '권한이 모자랍니다.')
  939. else:
  940. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '계정이 없습니다.')
  941. else:
  942. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '비 로그인 상태 입니다.')
  943. @app.route('/grammar')
  944. def grammar():
  945. return render_template('index.html', title = '문법 설명', logo = data['name'], tn = 17)
  946. @app.route('/ban')
  947. def aban():
  948. return render_template('index.html', title = '권한 오류', logo = data['name'], data = '현재 차단 상태거나 ACL이 맞지 않습니다.')
  949. @app.route('/version')
  950. def version():
  951. return render_template('index.html', title = '버전', logo = data['name'], tn = 14)
  952. @app.route('/user')
  953. def user():
  954. ip = getip(request)
  955. return render_template('index.html', title = '유저 메뉴', logo = data['name'], data = ip + '<br><br><li><a href="/login">로그인</a></li><li><a href="/logout">로그아웃</a></li><li><a href="/register">회원가입</a></li>')
  956. @app.route('/random')
  957. def random():
  958. curs.execute("select * from data order by rand() limit 1")
  959. rows = curs.fetchall()
  960. if(rows):
  961. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(rows[0]['title']) + '" />'
  962. else:
  963. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(data['frontpage']) + '" />'
  964. @app.errorhandler(404)
  965. def uncaughtError(error):
  966. return '<meta http-equiv="refresh" content="0;url=/w/' + parse.quote(data['frontpage']) + '" />'
  967. if __name__ == '__main__':
  968. app.run(host = '0.0.0.0', port = 3000)