2
0

app.py 148 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658
  1. import os
  2. import re
  3. for i_data in os.listdir("route"):
  4. f_src = re.search("(.+)\.py$", i_data)
  5. if f_src:
  6. f_src = f_src.groups()[0]
  7. exec("from route." + f_src + " import *")
  8. r_ver = 'v3.0.9-master-004'
  9. c_ver = '309001'
  10. print('Version : ' + r_ver)
  11. APPVAR = json.loads(open('data/app_variables.json', encoding='utf-8').read())
  12. # Start Data Migration Code
  13. '''
  14. 3.0.9-master-004 -> next release
  15. * Dockerizing
  16. * Add OAuth Provider: Discord
  17. '''
  18. if os.path.exists('image'):
  19. os.rename('image', APPVAR['PATH_DATA_IMAGES'])
  20. if os.path.exists('set.json'):
  21. os.rename('set.json', APPVAR['PATH_SET_JSON'])
  22. if os.path.exists('oauthsettings.json'):
  23. os.rename('oauthsettings.json', APPVAR['PATH_OAUTHSETTINGS'])
  24. try:
  25. load_oauth('discord')
  26. except KeyError:
  27. old_oauth_data = json.loads(open(APPVAR['PATH_OAUTHSETTINGS'], encoding='utf-8').read())
  28. if 'discord' not in old_oauth_data['_README']['support']:
  29. old_oauth_data['_README']['support'] += ['discord']
  30. old_oauth_data['discord'] = {}
  31. old_oauth_data['discord']['client_id'] = ''
  32. old_oauth_data['discord']['client_secret'] = ''
  33. with open(APPVAR['PATH_OAUTHSETTINGS'], 'w') as f:
  34. f.write(json.dumps(old_oauth_data, sort_keys=True, indent=4))
  35. # -> End Data Migration Code
  36. try:
  37. set_data = json.loads(open(APPVAR['PATH_SET_JSON']).read())
  38. except:
  39. if os.getenv('NAMU_DB') != None:
  40. set_data = { "db" : 'data/' + os.getenv('NAMU_DB') }
  41. else:
  42. print('DB\'s name (data) : ', end = '')
  43. new_json = str(input())
  44. if new_json == '':
  45. new_json = 'data'
  46. with open(APPVAR['PATH_SET_JSON'], 'w') as f:
  47. f.write('{ "db" : "data/' + new_json + '" }')
  48. set_data = json.loads(open(APPVAR['PATH_SET_JSON']).read())
  49. print('DB\'s name : ' + set_data['db'])
  50. if os.path.exists(set_data['db'] + '.db'):
  51. setup_tool = 0
  52. else:
  53. setup_tool = 1
  54. conn = sqlite3.connect(set_data['db'] + '.db', check_same_thread = False)
  55. curs = conn.cursor()
  56. load_conn(conn)
  57. logging.basicConfig(level = logging.ERROR)
  58. app = flask.Flask(__name__, template_folder = './')
  59. app.config['JSON_AS_ASCII'] = False
  60. flask_reggie.Reggie(app)
  61. compress = flask_compress.Compress()
  62. compress.init_app(app)
  63. class EverythingConverter(werkzeug.routing.PathConverter):
  64. regex = '.*?'
  65. app.jinja_env.filters['md5_replace'] = md5_replace
  66. app.jinja_env.filters['load_lang'] = load_lang
  67. app.url_map.converters['everything'] = EverythingConverter
  68. curs.execute('create table if not exists data(test text)')
  69. curs.execute('create table if not exists cache_data(test text)')
  70. curs.execute('create table if not exists history(test text)')
  71. curs.execute('create table if not exists rd(test text)')
  72. curs.execute('create table if not exists user(test text)')
  73. curs.execute('create table if not exists user_set(test text)')
  74. curs.execute('create table if not exists ban(test text)')
  75. curs.execute('create table if not exists topic(test text)')
  76. curs.execute('create table if not exists rb(test text)')
  77. curs.execute('create table if not exists back(test text)')
  78. curs.execute('create table if not exists custom(test text)')
  79. curs.execute('create table if not exists other(test text)')
  80. curs.execute('create table if not exists alist(test text)')
  81. curs.execute('create table if not exists re_admin(test text)')
  82. curs.execute('create table if not exists alarm(test text)')
  83. curs.execute('create table if not exists ua_d(test text)')
  84. curs.execute('create table if not exists filter(test text)')
  85. curs.execute('create table if not exists scan(test text)')
  86. curs.execute('create table if not exists acl(test text)')
  87. curs.execute('create table if not exists inter(test text)')
  88. curs.execute('create table if not exists html_filter(test text)')
  89. curs.execute('create table if not exists oauth_conn(test text)')
  90. if setup_tool == 0:
  91. curs.execute('select data from other where name = "ver"')
  92. ver_set_data = curs.fetchall()
  93. if not ver_set_data:
  94. setup_tool = 1
  95. else:
  96. if c_ver > ver_set_data[0][0]:
  97. setup_tool = 1
  98. if setup_tool != 0:
  99. create_data = {}
  100. create_data['all_data'] = [
  101. 'data',
  102. 'cache_data',
  103. 'history',
  104. 'rd',
  105. 'user',
  106. 'user_set',
  107. 'ban',
  108. 'topic',
  109. 'rb',
  110. 'back',
  111. 'custom',
  112. 'other',
  113. 'alist',
  114. 're_admin',
  115. 'alarm',
  116. 'ua_d',
  117. 'filter',
  118. 'scan',
  119. 'acl',
  120. 'inter',
  121. 'html_filter',
  122. 'oauth_conn'
  123. ]
  124. create_data['data'] = ['title', 'data']
  125. create_data['cache_data'] = ['title', 'data']
  126. create_data['history'] = ['id', 'title', 'data', 'date', 'ip', 'send', 'leng', 'hide', 'type']
  127. create_data['rd'] = ['title', 'sub', 'date', 'band', 'stop', 'agree']
  128. create_data['user'] = ['id', 'pw', 'acl', 'date', 'encode']
  129. create_data['user_set'] = ['name', 'id', 'data']
  130. create_data['ban'] = ['block', 'end', 'why', 'band', 'login']
  131. create_data['topic'] = ['id', 'title', 'sub', 'data', 'date', 'ip', 'block', 'top']
  132. create_data['rb'] = ['block', 'end', 'today', 'blocker', 'why', 'band']
  133. create_data['back'] = ['title', 'link', 'type']
  134. create_data['custom'] = ['user', 'css']
  135. create_data['other'] = ['name', 'data']
  136. create_data['alist'] = ['name', 'acl']
  137. create_data['re_admin'] = ['who', 'what', 'time']
  138. create_data['alarm'] = ['name', 'data', 'date']
  139. create_data['ua_d'] = ['name', 'ip', 'ua', 'today', 'sub']
  140. create_data['filter'] = ['name', 'regex', 'sub']
  141. create_data['scan'] = ['user', 'title']
  142. create_data['acl'] = ['title', 'dec', 'dis', 'view', 'why']
  143. create_data['inter'] = ['title', 'link']
  144. create_data['html_filter'] = ['html', 'kind']
  145. create_data['oauth_conn'] = ['provider', 'wiki_id', 'sns_id', 'name', 'picture']
  146. for create_table in create_data['all_data']:
  147. for create in create_data[create_table]:
  148. try:
  149. curs.execute('select ' + create + ' from ' + create_table + ' limit 1')
  150. except:
  151. curs.execute("alter table " + create_table + " add " + create + " text default ''")
  152. update()
  153. curs.execute('select name from alist where acl = "owner"')
  154. if not curs.fetchall():
  155. curs.execute('delete from alist where name = "owner"')
  156. curs.execute('insert into alist (name, acl) values ("owner", "owner")')
  157. if not os.path.exists(APPVAR['PATH_DATA_IMAGES']):
  158. os.makedirs(APPVAR['PATH_DATA_IMAGES'])
  159. if not os.path.exists('views'):
  160. os.makedirs('views')
  161. # ==========================
  162. import route.tool.init as server_init
  163. server_set_key = ['host', 'port', 'language', 'markup', 'encode']
  164. server_set = {}
  165. for i in range(len(server_set_key)):
  166. curs.execute('select data from other where name = ?', [server_set_key[i]])
  167. server_set_val = curs.fetchall()
  168. if not server_set_val:
  169. server_set_val = server_init.init(server_set_key[i])
  170. curs.execute('insert into other (name, data) values (?, ?)', [server_set_key[i], server_set_val])
  171. conn.commit()
  172. else:
  173. server_set_val = server_set_val[0][0]
  174. print(server_set_key[i] + ' : ' + server_set_val)
  175. server_set[server_set_key[i]] = server_set_val
  176. # ==========================
  177. try:
  178. if not os.path.exists('robots.txt'):
  179. curs.execute('select data from other where name = "robot"')
  180. robot_test = curs.fetchall()
  181. if robot_test:
  182. fw_test = open('./robots.txt', 'w')
  183. fw_test.write(re.sub('\r\n', '\n', robot_test[0][0]))
  184. fw_test.close()
  185. else:
  186. fw_test = open('./robots.txt', 'w')
  187. fw_test.write('User-agent: *\nDisallow: /\nAllow: /$\nAllow: /w/')
  188. fw_test.close()
  189. curs.execute('insert into other (name, data) values ("robot", "User-agent: *\nDisallow: /\nAllow: /$\nAllow: /w/")')
  190. print('Engine made robots.txt')
  191. except:
  192. pass
  193. curs.execute('select data from other where name = "key"')
  194. rep_data = curs.fetchall()
  195. if not rep_data:
  196. rep_key = ''.join(random.choice("0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ") for i in range(16))
  197. if rep_key:
  198. curs.execute('insert into other (name, data) values ("key", ?)', [rep_key])
  199. else:
  200. rep_key = rep_data[0][0]
  201. curs.execute('select data from other where name = "adsense"')
  202. adsense_result = curs.fetchall()
  203. if not adsense_result:
  204. curs.execute('insert into other (name, data) values ("adsense", "False")')
  205. curs.execute('insert into other (name, data) values ("adsense_code", "")')
  206. curs.execute('delete from other where name = "ver"')
  207. curs.execute('insert into other (name, data) values ("ver", ?)', [c_ver])
  208. def back_up():
  209. try:
  210. shutil.copyfile(set_data['db'] + '.db', 'back_' + set_data['db'] + '.db')
  211. print('Back up : OK')
  212. except:
  213. print('Back up : Error')
  214. threading.Timer(60 * 60 * back_time, back_up).start()
  215. try:
  216. curs.execute('select data from other where name = "back_up"')
  217. back_up_time = curs.fetchall()
  218. back_time = int(back_up_time[0][0])
  219. except:
  220. back_time = 0
  221. if back_time != 0:
  222. print('Back up state : ' + str(back_time) + ' hours')
  223. if __name__ == '__main__':
  224. back_up()
  225. else:
  226. print('Back up state : Turn off')
  227. conn.commit()
  228. @app.route('/del_alarm')
  229. def del_alarm():
  230. return del_alarm_2(conn)
  231. @app.route('/alarm')
  232. def alarm():
  233. return alarm_2(conn)
  234. @app.route('/<regex("inter_wiki|(?:edit|email|name)_filter"):tools>')
  235. def inter_wiki(tools = None):
  236. return inter_wiki_2(conn, tools)
  237. @app.route('/<regex("del_(?:inter_wiki|(?:edit|email|name)_filter)"):tools>/<name>')
  238. def del_inter(tools = None, name = None):
  239. return del_inter_2(conn, tools, name)
  240. @app.route('/<regex("plus_(?:inter_wiki|(?:edit|email|name)_filter)"):tools>', methods=['POST', 'GET'])
  241. @app.route('/<regex("plus_edit_filter"):tools>/<name>', methods=['POST', 'GET'])
  242. def plus_inter(tools = None, name = None):
  243. return plus_inter_2(conn, tools, name)
  244. @app.route('/setting')
  245. @app.route('/setting/<int:num>', methods=['POST', 'GET'])
  246. def setting(num = 0):
  247. return setting_2(conn, num)
  248. @app.route('/not_close_topic')
  249. def not_close_topic():
  250. return not_close_topic_2(conn)
  251. @app.route('/image/<name>')
  252. def image_view(name = None):
  253. return image_view_2(conn, name)
  254. @app.route('/acl_list')
  255. def acl_list():
  256. return acl_list_2(conn)
  257. @app.route('/admin_plus/<name>', methods=['POST', 'GET'])
  258. def admin_plus(name = None):
  259. return admin_plus_2(conn)
  260. @app.route('/admin_list')
  261. def admin_list():
  262. return admin_list_2(conn)
  263. @app.route('/hidden/<everything:name>')
  264. def history_hidden(name = None):
  265. return history_hidden_2(name)
  266. @app.route('/user_log')
  267. def user_log():
  268. return user_log_2(conn)
  269. @app.route('/admin_log')
  270. def admin_log():
  271. num = int(number_check(flask.request.args.get('num', '1')))
  272. if num * 50 > 0:
  273. sql_num = num * 50 - 50
  274. else:
  275. sql_num = 0
  276. list_data = '<ul>'
  277. curs.execute("select who, what, time from re_admin order by time desc limit ?, '50'", [str(sql_num)])
  278. get_list = curs.fetchall()
  279. for data in get_list:
  280. list_data += '<li>' + ip_pas(data[0]) + ' / ' + data[1] + ' / ' + data[2] + '</li>'
  281. list_data += '</ul>'
  282. list_data += next_fix('/admin_log?num=', num, get_list)
  283. return easy_minify(flask.render_template(skin_check(),
  284. imp = [load_lang('authority_use_list'), wiki_set(), custom(), other2([0, 0])],
  285. data = list_data,
  286. menu = [['other', load_lang('return')]]
  287. ))
  288. @app.route('/give_log')
  289. def give_log():
  290. list_data = '<ul>'
  291. back = ''
  292. curs.execute("select distinct name from alist order by name asc")
  293. for data in curs.fetchall():
  294. if back != data[0]:
  295. back = data[0]
  296. list_data += '<li><a href="/admin_plus/' + url_pas(data[0]) + '">' + data[0] + '</a></li>'
  297. list_data += '</ul><hr class=\"main_hr\"><a href="/manager/8">(' + load_lang('add') + ')</a>'
  298. return easy_minify(flask.render_template(skin_check(),
  299. imp = [load_lang('admin_group_list'), wiki_set(), custom(), other2([0, 0])],
  300. data = list_data,
  301. menu = [['other', load_lang('return')]]
  302. ))
  303. @app.route('/indexing', methods=['POST', 'GET'])
  304. def indexing():
  305. if admin_check() != 1:
  306. return re_error('/error/3')
  307. if flask.request.method == 'POST':
  308. admin_check(None, 'indexing')
  309. curs.execute("select name from sqlite_master where type = 'index'")
  310. data = curs.fetchall()
  311. if data:
  312. for delete_index in data:
  313. print('Delete : ' + delete_index[0])
  314. sql = 'drop index if exists ' + delete_index[0]
  315. try:
  316. curs.execute(sql)
  317. except:
  318. pass
  319. else:
  320. curs.execute("select name from sqlite_master where type in ('table', 'view') and name not like 'sqlite_%' union all select name from sqlite_temp_master where type in ('table', 'view') order by 1;")
  321. for table in curs.fetchall():
  322. curs.execute('select sql from sqlite_master where name = ?', [table[0]])
  323. cul = curs.fetchall()
  324. r_cul = re.findall('(?:([^ (]*) text)', str(cul[0]))
  325. for n_cul in r_cul:
  326. print('Create : index_' + table[0] + '_' + n_cul)
  327. sql = 'create index index_' + table[0] + '_' + n_cul + ' on ' + table[0] + '(' + n_cul + ')'
  328. try:
  329. curs.execute(sql)
  330. except:
  331. pass
  332. conn.commit()
  333. return redirect()
  334. else:
  335. curs.execute("select name from sqlite_master where type = 'index'")
  336. data = curs.fetchall()
  337. if data:
  338. b_data = load_lang('delete')
  339. else:
  340. b_data = load_lang('create')
  341. return easy_minify(flask.render_template(skin_check(),
  342. imp = [load_lang('indexing'), wiki_set(), custom(), other2([0, 0])],
  343. data = '''
  344. <form method="post">
  345. <button type="submit">''' + b_data + '''</button>
  346. </form>
  347. ''',
  348. menu = [['manager', load_lang('return')]]
  349. ))
  350. @app.route('/restart', methods=['POST', 'GET'])
  351. def restart():
  352. if admin_check(None, 'restart') != 1:
  353. return re_error('/error/3')
  354. if flask.request.method == 'POST':
  355. os.execl(sys.executable, sys.executable, *sys.argv)
  356. else:
  357. print('Restart')
  358. return easy_minify(flask.render_template(skin_check(),
  359. imp = [load_lang('wiki_restart'), wiki_set(), custom(), other2([0, 0])],
  360. data = '''
  361. <form method="post">
  362. <button type="submit">''' + load_lang('restart') + '''</button>
  363. </form>
  364. ''',
  365. menu = [['manager', load_lang('return')]]
  366. ))
  367. @app.route('/update')
  368. def now_update():
  369. if admin_check(None, 'update') != 1:
  370. return re_error('/error/3')
  371. curs.execute('select data from other where name = "update"')
  372. up_data = curs.fetchall()
  373. if up_data:
  374. up_data = up_data[0][0]
  375. else:
  376. up_data = 'stable'
  377. if platform.system() == 'Linux':
  378. print('Update')
  379. os.system('git remote rm origin')
  380. os.system('git remote add origin https://github.com/2DU/opennamu.git')
  381. ok = os.system('git fetch origin ' + up_data)
  382. ok = os.system('git reset --hard origin/' + up_data)
  383. if ok == 0:
  384. return redirect('/restart')
  385. else:
  386. if platform.system() == 'Windows':
  387. print('Update')
  388. urllib.request.urlretrieve('https://github.com/2DU/opennamu/archive/' + up_data + '.zip', 'update.zip')
  389. zipfile.ZipFile('update.zip').extractall('')
  390. ok = os.system('xcopy /y /r opennamu-' + up_data + ' .')
  391. if ok == 0:
  392. print('Remove')
  393. os.system('rd /s /q opennamu-' + up_data)
  394. os.system('del update.zip')
  395. return redirect('/restart')
  396. return easy_minify(flask.render_template(skin_check(),
  397. imp = [load_lang('update'), wiki_set(), custom(), other2([0, 0])],
  398. data = load_lang("update_error") + ' <a href="https://github.com/2DU/opennamu">(Github)</a>',
  399. menu = [['manager/1', load_lang('return')]]
  400. ))
  401. @app.route('/oauth_settings', methods=['GET', 'POST'])
  402. def oauth_settings():
  403. if admin_check(None, 'oauth_settings') != 1:
  404. return re_error('/error/3')
  405. if flask.request.method == 'POST':
  406. try:
  407. facebook_client_id = flask.request.form['facebook_client_id']
  408. facebook_client_secret = flask.request.form['facebook_client_secret']
  409. naver_client_id = flask.request.form['naver_client_id']
  410. naver_client_secret = flask.request.form['naver_client_secret']
  411. except:
  412. return easy_minify(flask.render_template(skin_check(),
  413. imp = [load_lang('inter_error'), wiki_set(), custom(), other2([0, 0])],
  414. data = '<h2>ie_no_data_required</h2>' + load_lang('ie_no_data_required'),
  415. menu = [['other', load_lang('return')]]
  416. ))
  417. with open(APPVAR['PATH_OAUTHSETTINGS'], 'r', encoding='utf-8') as f:
  418. legacy = json.loads(f.read())
  419. with open(APPVAR['PATH_OAUTHSETTINGS'], 'w', encoding='utf-8') as f:
  420. f.write("""
  421. {
  422. "_README" : {
  423. "en" : \"""" + legacy['_README']['en'] + """\",
  424. "ko" : \"""" + legacy['_README']['ko'] + """\",
  425. "support" : """ + str(legacy['_README']['support']).replace("'", '"') + """
  426. },
  427. "publish_url" : \"""" + legacy['publish_url'] + """\",
  428. "facebook" : {
  429. "client_id" : \"""" + facebook_client_id + """\",
  430. "client_secret" : \"""" + facebook_client_secret + """\"
  431. },
  432. "naver" : {
  433. "client_id" : \"""" + naver_client_id + """\",
  434. "client_secret" : \"""" + naver_client_secret + """\"
  435. }
  436. }
  437. """)
  438. return flask.redirect('/oauth_settings')
  439. oauth_supported = load_oauth('_README')['support']
  440. body_content = ''
  441. body_content += '''
  442. <script>
  443. function check_value (target) {
  444. target_box = document.getElementById(target.id + "_box");
  445. if (target.value !== "") {
  446. target_box.checked = true;
  447. } else {
  448. target_box.checked = false;
  449. }
  450. }
  451. </script>
  452. '''
  453. init_js = ''
  454. body_content += '<form method="post">'
  455. for i in range(len(oauth_supported)):
  456. oauth_data = load_oauth(oauth_supported[i])
  457. for j in range(2):
  458. if j == 0:
  459. load_target = 'id'
  460. elif j == 1:
  461. load_target = 'secret'
  462. init_js += 'check_value(document.getElementById("{}_client_{}"));'.format(oauth_supported[i], load_target)
  463. body_content += '''
  464. <input id="{}_client_{}_box" type="checkbox" disabled>
  465. <input placeholder="{}_client_{}" id="{}_client_{}" name="{}_client_{}" value="{}" type="text" onChange="check_value(this)" style="width: 80%;">
  466. <hr>
  467. '''.format(
  468. oauth_supported[i],
  469. load_target,
  470. oauth_supported[i],
  471. load_target,
  472. oauth_supported[i],
  473. load_target,
  474. oauth_supported[i],
  475. load_target,
  476. oauth_data['client_{}'.format(load_target)]
  477. )
  478. body_content += '<button id="save" type="submit">' + load_lang('save') + '</button></form>'
  479. body_content += '<script>' + init_js + '</script>'
  480. return easy_minify(flask.render_template(skin_check(),
  481. imp = [load_lang('oauth_setting'), wiki_set(), custom(), other2([0, 0])],
  482. data = body_content,
  483. menu = [['other', load_lang('return')]]
  484. ))
  485. @app.route('/adsense_settings', methods=['GET', 'POST'])
  486. def adsense_settings():
  487. if admin_check(None, 'adsense_settings') != 1:
  488. return re_error('/error/3')
  489. if flask.request.method == 'POST':
  490. try:
  491. adsense_enabled = flask.request.form.get('adsense_enabled')
  492. adsense_code = flask.request.form['adsense_code']
  493. except:
  494. return easy_minify(flask.render_template(skin_check(),
  495. imp = [load_lang('inter_error'), wiki_set(), custom(), other2([0, 0])],
  496. data = '<h2>ie_no_data_required</h2>' + load_lang('ie_no_data_required'),
  497. menu = [['other', load_lang('return')]]
  498. ))
  499. if adsense_enabled == 'on':
  500. curs.execute('update other set data = "True" where name = "adsense"')
  501. else:
  502. curs.execute('update other set data = "False" where name = "adsense"')
  503. curs.execute('update other set data = ? where name = "adsense_code"', [adsense_code])
  504. conn.commit()
  505. return redirect('/adsense_settings')
  506. body_content = ''
  507. curs.execute('select data from other where name = "adsense"')
  508. adsense_enabled = curs.fetchall()[0][0]
  509. curs.execute('select data from other where name = "adsense_code"')
  510. adsense_code = curs.fetchall()[0][0]
  511. template = '''
  512. <form action="" accept-charset="utf-8" method="post">
  513. <div class="form-check">
  514. <label class="form-check-label">
  515. <input class="form-check-input" name="adsense_enabled" type="checkbox" {}>
  516. {}
  517. </label>
  518. </div>
  519. <hr>
  520. <div class="form-group">
  521. <textarea class="form-control" id="adsense_code" name="adsense_code" rows="12">{}</textarea>
  522. </div>
  523. <button type="submit" value="publish">{}</button>
  524. </form>
  525. '''
  526. body_content += template.format(
  527. 'checked' if adsense_enabled == 'True' else template.format(''),
  528. load_lang('adsense_enable'),
  529. load_lang('save'),
  530. adsense_code
  531. )
  532. return easy_minify(flask.render_template(skin_check(),
  533. imp = [load_lang('adsense_setting'), wiki_set(), custom(), other2([0, 0])],
  534. data = body_content,
  535. menu = [['other', load_lang('return')]]
  536. ))
  537. @app.route('/xref/<everything:name>')
  538. def xref(name = None):
  539. num = int(number_check(flask.request.args.get('num', '1')))
  540. if num * 50 > 0:
  541. sql_num = num * 50 - 50
  542. else:
  543. sql_num = 0
  544. div = '<ul>'
  545. curs.execute("select link, type from back where title = ? and not type = 'cat' and not type = 'no' order by link asc limit ?, '50'", [name, str(sql_num)])
  546. data_list = curs.fetchall()
  547. for data in data_list:
  548. div += '<li><a href="/w/' + url_pas(data[0]) + '">' + data[0] + '</a>'
  549. if data[1]:
  550. div += ' (' + data[1] + ')'
  551. curs.execute("select title from back where title = ? and type = 'include'", [data[0]])
  552. db_data = curs.fetchall()
  553. if db_data:
  554. div += ' <a id="inside" href="/xref/' + url_pas(data[0]) + '">(' + load_lang('backlink') + ')</a>'
  555. div += '</li>'
  556. div += '</ul>' + next_fix('/xref/' + url_pas(name) + '?num=', num, data_list)
  557. return easy_minify(flask.render_template(skin_check(),
  558. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('backlink') + ')', 0])],
  559. data = div,
  560. menu = [['w/' + url_pas(name), load_lang('return')]]
  561. ))
  562. @app.route('/please')
  563. def please():
  564. num = int(number_check(flask.request.args.get('num', '1')))
  565. if num * 50 > 0:
  566. sql_num = num * 50 - 50
  567. else:
  568. sql_num = 0
  569. div = '<ul>'
  570. var = ''
  571. curs.execute("select distinct title from back where type = 'no' order by title asc limit ?, '50'", [str(sql_num)])
  572. data_list = curs.fetchall()
  573. for data in data_list:
  574. if var != data[0]:
  575. div += '<li><a id="not_thing" href="/w/' + url_pas(data[0]) + '">' + data[0] + '</a></li>'
  576. var = data[0]
  577. div += '</ul>' + next_fix('/please?num=', num, data_list)
  578. return easy_minify(flask.render_template(skin_check(),
  579. imp = [load_lang('need_document'), wiki_set(), custom(), other2([0, 0])],
  580. data = div,
  581. menu = [['other', load_lang('return')]]
  582. ))
  583. @app.route('/recent_discuss')
  584. def recent_discuss():
  585. div = ''
  586. if flask.request.args.get('what', 'normal') == 'normal':
  587. div += '<a href="/recent_discuss?what=close">(' + load_lang('close_discussion') + ')</a>'
  588. m_sub = 0
  589. else:
  590. div += '<a href="/recent_discuss">(' + load_lang('open_discussion') + ')</a>'
  591. m_sub = ' (' + load_lang('closed') + ')'
  592. div += '''
  593. <hr class=\"main_hr\">
  594. <table id="main_table_set">
  595. <tbody>
  596. <tr>
  597. <td id="main_table_width_half">''' + load_lang('discussion_name') + '''</td>
  598. <td id="main_table_width_half">''' + load_lang('time') + '''</td>
  599. </tr>
  600. '''
  601. if m_sub == 0:
  602. curs.execute("select title, sub, date from rd where not stop = 'O' order by date desc limit 50")
  603. else:
  604. curs.execute("select title, sub, date from rd where stop = 'O' order by date desc limit 50")
  605. for data in curs.fetchall():
  606. title = html.escape(data[0])
  607. sub = html.escape(data[1])
  608. div += '<tr><td><a href="/topic/' + url_pas(data[0]) + '/sub/' + url_pas(data[1]) + '">' + title + '</a> (' + sub + ')</td><td>' + data[2] + '</td></tr>'
  609. div += '</tbody></table>'
  610. return easy_minify(flask.render_template(skin_check(),
  611. imp = [load_lang('recent_discussion'), wiki_set(), custom(), other2([m_sub, 0])],
  612. data = div,
  613. menu = 0
  614. ))
  615. @app.route('/block_log')
  616. @app.route('/<regex("block_user|block_admin"):tool>/<name>')
  617. def block_log(name = None, tool = None):
  618. num = int(number_check(flask.request.args.get('num', '1')))
  619. if num * 50 > 0:
  620. sql_num = num * 50 - 50
  621. else:
  622. sql_num = 0
  623. div = '''
  624. <table id="main_table_set">
  625. <tbody>
  626. <tr>
  627. <td id="main_table_width">''' + load_lang('blocked') + '''</td>
  628. <td id="main_table_width">''' + load_lang('admin') + '''</td>
  629. <td id="main_table_width">''' + load_lang('period') + '''</td>
  630. </tr>
  631. '''
  632. data_list = ''
  633. if not name:
  634. div = '''
  635. <a href="/manager/11">(''' + load_lang('blocked') + ''')</a> <a href="/manager/12">(''' + load_lang('admin') + ''')</a>
  636. <hr class=\"main_hr\">
  637. ''' + div
  638. sub = 0
  639. menu = 0
  640. curs.execute("select why, block, blocker, end, today from rb order by today desc limit ?, '50'", [str(sql_num)])
  641. else:
  642. menu = [['block_log', load_lang('normal')]]
  643. if tool == 'block_user':
  644. sub = ' (' + load_lang('blocked') + ')'
  645. curs.execute("select why, block, blocker, end, today from rb where block = ? order by today desc limit ?, '50'", [name, str(sql_num)])
  646. else:
  647. sub = ' (' + load_lang('admin') + ')'
  648. curs.execute("select why, block, blocker, end, today from rb where blocker = ? order by today desc limit ?, '50'", [name, str(sql_num)])
  649. if data_list == '':
  650. data_list = curs.fetchall()
  651. for data in data_list:
  652. why = html.escape(data[0])
  653. if why == '':
  654. why = '<br>'
  655. band = re.search("^([0-9]{1,3}\.[0-9]{1,3})$", data[1])
  656. if band:
  657. ip = data[1] + ' (' + load_lang('range') + ')'
  658. else:
  659. ip = ip_pas(data[1])
  660. if data[3] != '':
  661. end = data[3]
  662. else:
  663. end = load_lang('limitless') + ''
  664. div += '''
  665. <tr>
  666. <td>''' + ip + '''</td>
  667. <td>''' + ip_pas(data[2]) + '''</td>
  668. <td>
  669. start : ''' + data[4] + '''
  670. <br>
  671. end : ''' + end + '''
  672. </td>
  673. </tr>
  674. <tr>
  675. <td colspan="3">''' + why + '''</td>
  676. </tr>
  677. '''
  678. div += '</tbody></table>'
  679. if not name:
  680. div += next_fix('/block_log?num=', num, data_list)
  681. else:
  682. div += next_fix('/' + url_pas(tool) + '/' + url_pas(name) + '?num=', num, data_list)
  683. return easy_minify(flask.render_template(skin_check(),
  684. imp = [load_lang('recent_ban'), wiki_set(), custom(), other2([sub, 0])],
  685. data = div,
  686. menu = menu
  687. ))
  688. @app.route('/search', methods=['POST'])
  689. def search():
  690. return redirect('/search/' + url_pas(flask.request.form.get('search', None)))
  691. @app.route('/goto', methods=['POST'])
  692. def goto():
  693. curs.execute("select title from data where title = ?", [flask.request.form.get('search', None)])
  694. data = curs.fetchall()
  695. if data:
  696. return redirect('/w/' + url_pas(flask.request.form.get('search', None)))
  697. else:
  698. return redirect('/search/' + url_pas(flask.request.form.get('search', None)))
  699. @app.route('/search/<everything:name>')
  700. def deep_search(name = None):
  701. if name == '':
  702. return redirect()
  703. num = int(number_check(flask.request.args.get('num', '1')))
  704. if num * 50 > 0:
  705. sql_num = num * 50 - 50
  706. else:
  707. sql_num = 0
  708. div = '<ul>'
  709. div_plus = ''
  710. test = ''
  711. curs.execute("select title from data where title = ?", [name])
  712. if curs.fetchall():
  713. link_id = ''
  714. else:
  715. link_id = 'id="not_thing"'
  716. div = '''
  717. <ul>
  718. <li>
  719. <a ''' + link_id + ' href="/w/' + url_pas(name) + '">' + name + '''</a>
  720. </li>
  721. </ul>
  722. <hr class=\"main_hr\">
  723. <ul>
  724. '''
  725. curs.execute("select distinct title, case when title like ? then '제목' else '내용' end from data where title like ? or data like ? order by case when title like ? then 1 else 2 end limit ?, '50'", ['%' + name + '%', '%' + name + '%', '%' + name + '%', '%' + name + '%', str(sql_num)])
  726. all_list = curs.fetchall()
  727. if all_list:
  728. test = all_list[0][1]
  729. for data in all_list:
  730. if data[1] != test:
  731. div_plus += '</ul><hr class=\"main_hr\"><ul>'
  732. test = data[1]
  733. div_plus += '<li><a href="/w/' + url_pas(data[0]) + '">' + data[0] + '</a> (' + data[1] + ')</li>'
  734. div += div_plus + '</ul>'
  735. div += next_fix('/search/' + url_pas(name) + '?num=', num, all_list)
  736. return easy_minify(flask.render_template(skin_check(),
  737. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('search') + ')', 0])],
  738. data = div,
  739. menu = 0
  740. ))
  741. @app.route('/raw/<everything:name>')
  742. @app.route('/topic/<everything:name>/sub/<sub_title>/raw/<int:num>')
  743. def raw_view(name = None, sub_title = None, num = None):
  744. v_name = name
  745. sub = ' (' + load_lang('raw') + ')'
  746. if not num:
  747. num = flask.request.args.get('num', None)
  748. if num:
  749. num = int(number_check(num))
  750. if not sub_title and num:
  751. curs.execute("select title from history where title = ? and id = ? and hide = 'O'", [name, str(num)])
  752. if curs.fetchall() and admin_check(6) != 1:
  753. return re_error('/error/3')
  754. curs.execute("select data from history where title = ? and id = ?", [name, str(num)])
  755. sub += ' (r' + str(num) + ')'
  756. menu = [['history/' + url_pas(name), load_lang('history')]]
  757. elif sub_title:
  758. curs.execute("select data from topic where id = ? and title = ? and sub = ? and block = ''", [str(num), name, sub_title])
  759. v_name = load_lang('discussion_raw')
  760. sub = ' (' + str(num) + ')'
  761. menu = [['topic/' + url_pas(name) + '/sub/' + url_pas(sub_title) + '#' + str(num), load_lang('discussion')], ['topic/' + url_pas(name) + '/sub/' + url_pas(sub_title) + '/admin/' + str(num), load_lang('return')]]
  762. else:
  763. curs.execute("select data from data where title = ?", [name])
  764. menu = [['w/' + url_pas(name), load_lang('return')]]
  765. data = curs.fetchall()
  766. if data:
  767. p_data = html.escape(data[0][0])
  768. p_data = '<textarea readonly rows="25">' + p_data + '</textarea>'
  769. return easy_minify(flask.render_template(skin_check(),
  770. imp = [v_name, wiki_set(), custom(), other2([sub, 0])],
  771. data = p_data,
  772. menu = menu
  773. ))
  774. else:
  775. return redirect('/w/' + url_pas(name))
  776. @app.route('/revert/<everything:name>', methods=['POST', 'GET'])
  777. def revert(name = None):
  778. num = int(number_check(flask.request.args.get('num', '1')))
  779. curs.execute("select title from history where title = ? and id = ? and hide = 'O'", [name, str(num)])
  780. if curs.fetchall() and admin_check(6) != 1:
  781. return re_error('/error/3')
  782. if acl_check(name) == 1:
  783. return re_error('/ban')
  784. if flask.request.method == 'POST':
  785. if captcha_post(flask.request.form.get('g-recaptcha-response', '')) == 1:
  786. return re_error('/error/13')
  787. else:
  788. captcha_post('', 0)
  789. curs.execute("select data from history where title = ? and id = ?", [name, str(num)])
  790. data = curs.fetchall()
  791. if data:
  792. if edit_filter_do(data[0][0]) == 1:
  793. return re_error('/error/21')
  794. curs.execute("delete from back where link = ?", [name])
  795. conn.commit()
  796. if data:
  797. curs.execute("select data from data where title = ?", [name])
  798. data_old = curs.fetchall()
  799. if data_old:
  800. leng = leng_check(len(data_old[0][0]), len(data[0][0]))
  801. curs.execute("update data set data = ? where title = ?", [data[0][0], name])
  802. else:
  803. leng = '+' + str(len(data[0][0]))
  804. curs.execute("insert into data (title, data) values (?, ?)", [name, data[0][0]])
  805. history_plus(
  806. name,
  807. data[0][0],
  808. get_time(),
  809. ip_check(),
  810. flask.request.form.get('send', None) + ' (r' + str(num) + ')',
  811. leng
  812. )
  813. render_set(
  814. title = name,
  815. data = data[0][0],
  816. num = 1
  817. )
  818. conn.commit()
  819. return redirect('/w/' + url_pas(name))
  820. else:
  821. curs.execute("select title from history where title = ? and id = ?", [name, str(num)])
  822. if not curs.fetchall():
  823. return redirect('/w/' + url_pas(name))
  824. return easy_minify(flask.render_template(skin_check(),
  825. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('revert') + ')', 0])],
  826. data = '''
  827. <form method="post">
  828. <span>r''' + flask.request.args.get('num', '0') + '''</span>
  829. <hr class=\"main_hr\">
  830. ''' + ip_warring() + '''
  831. <input placeholder="''' + load_lang('why') + '''" name="send" type="text">
  832. <hr class=\"main_hr\">
  833. ''' + captcha_get() + '''
  834. <button type="submit">''' + load_lang('revert') + '''</button>
  835. </form>
  836. ''',
  837. menu = [['history/' + url_pas(name), load_lang('history')], ['recent_changes', load_lang('recent_change')]]
  838. ))
  839. @app.route('/edit/<everything:name>', methods=['POST', 'GET'])
  840. def edit(name = None):
  841. ip = ip_check()
  842. if acl_check(name) == 1:
  843. return re_error('/ban')
  844. if flask.request.method == 'POST':
  845. if captcha_post(flask.request.form.get('g-recaptcha-response', '')) == 1:
  846. return re_error('/error/13')
  847. else:
  848. captcha_post('', 0)
  849. if len(flask.request.form.get('send', None)) > 500:
  850. return re_error('/error/15')
  851. if flask.request.form.get('otent', None) == flask.request.form.get('content', None):
  852. return redirect('/w/' + url_pas(name))
  853. if edit_filter_do(flask.request.form.get('content', '')) == 1:
  854. return re_error('/error/21')
  855. today = get_time()
  856. content = savemark(flask.request.form.get('content', None))
  857. curs.execute("select data from data where title = ?", [name])
  858. old = curs.fetchall()
  859. if old:
  860. leng = leng_check(len(flask.request.form.get('otent', None)), len(content))
  861. if flask.request.args.get('section', None):
  862. content = old[0][0].replace(flask.request.form.get('otent', None), content)
  863. curs.execute("update data set data = ? where title = ?", [content, name])
  864. else:
  865. leng = '+' + str(len(content))
  866. curs.execute("insert into data (title, data) values (?, ?)", [name, content])
  867. curs.execute("select user from scan where title = ?", [name])
  868. for _ in curs.fetchall():
  869. curs.execute("insert into alarm (name, data, date) values (?, ?, ?)", [ip, ip + ' - <a href="/w/' + url_pas(name) + '">' + name + '</a> (Edit)', today])
  870. history_plus(
  871. name,
  872. content,
  873. today,
  874. ip,
  875. flask.request.form.get('send', None),
  876. leng
  877. )
  878. curs.execute("delete from back where link = ?", [name])
  879. curs.execute("delete from back where title = ? and type = 'no'", [name])
  880. render_set(
  881. title = name,
  882. data = content,
  883. num = 1
  884. )
  885. conn.commit()
  886. return redirect('/w/' + url_pas(name))
  887. else:
  888. curs.execute("select data from data where title = ?", [name])
  889. new = curs.fetchall()
  890. if new:
  891. if flask.request.args.get('section', None):
  892. test_data = '\n' + re.sub('\r\n', '\n', new[0][0]) + '\n'
  893. section_data = re.findall('((?:={1,6}) ?(?:(?:(?!={1,6}\n).)+) ?={1,6}\n(?:(?:(?!(?:={1,6}) ?(?:(?:(?!={1,6}\n).)+) ?={1,6}\n).)*\n*)*)', test_data)
  894. data = section_data[int(flask.request.args.get('section', None)) - 1]
  895. else:
  896. data = new[0][0]
  897. else:
  898. data = ''
  899. data_old = data
  900. if not flask.request.args.get('section', None):
  901. get_name = '''
  902. <a href="/manager/15?plus=''' + url_pas(name) + '">(' + load_lang('load') + ')</a> <a href="/edit_filter">(' + load_lang('edit_filter_rule') + ''')</a>
  903. <hr class=\"main_hr\">
  904. '''
  905. action = ''
  906. else:
  907. get_name = ''
  908. action = '?section=' + flask.request.args.get('section', None)
  909. if flask.request.args.get('plus', None):
  910. curs.execute("select data from data where title = ?", [flask.request.args.get('plus', None)])
  911. get_data = curs.fetchall()
  912. if get_data:
  913. data = get_data[0][0]
  914. get_name = ''
  915. js_data = edit_help_button()
  916. return easy_minify(flask.render_template(skin_check(),
  917. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('edit') + ')', 0])],
  918. data = get_name + js_data[0] + '''
  919. <form method="post" action="/edit/''' + url_pas(name) + action + '''">
  920. ''' + js_data[1] + '''
  921. <textarea id="content" rows="25" name="content">''' + html.escape(re.sub('\n$', '', data)) + '''</textarea>
  922. <textarea style="display: none;" name="otent">''' + html.escape(re.sub('\n$', '', data_old)) + '''</textarea>
  923. <hr class=\"main_hr\">
  924. <input placeholder="''' + load_lang('why') + '''" name="send" type="text">
  925. <hr class=\"main_hr\">
  926. ''' + captcha_get() + ip_warring() + '''
  927. <button id="save" type="submit">''' + load_lang('save') + '''</button>
  928. <button id="preview" type="submit" formaction="/preview/''' + url_pas(name) + action + '">' + load_lang('preview') + '''</button>
  929. </form>
  930. ''',
  931. menu = [['w/' + url_pas(name), load_lang('return')], ['delete/' + url_pas(name), load_lang('delete')], ['move/' + url_pas(name), load_lang('move')]]
  932. ))
  933. @app.route('/preview/<everything:name>', methods=['POST'])
  934. def preview(name = None):
  935. if acl_check(name) == 1:
  936. return re_error('/ban')
  937. new_data = re.sub('^\r\n', '', flask.request.form.get('content', None))
  938. new_data = re.sub('\r\n$', '', new_data)
  939. end_data = render_set(
  940. title = name,
  941. data = new_data
  942. )
  943. if flask.request.args.get('section', None):
  944. action = '?section=' + flask.request.args.get('section', None)
  945. else:
  946. action = ''
  947. js_data = edit_help_button()
  948. return easy_minify(flask.render_template(skin_check(),
  949. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('preview') + ')', 0])],
  950. data = '<a href="/edit_filter">(' + load_lang('edit_filter_rule') + ')</a>' + js_data[0] + '''
  951. <form method="post" action="/edit/''' + url_pas(name) + action + '''">
  952. ''' + js_data[1] + '''
  953. <textarea id="content" rows="25" name="content">''' + html.escape(flask.request.form.get('content', None)) + '''</textarea>
  954. <textarea style="display: none;" name="otent">''' + html.escape(flask.request.form.get('otent', None)) + '''</textarea>
  955. <hr class=\"main_hr\">
  956. <input placeholder="''' + load_lang('why') + '''" name="send" type="text">
  957. <hr class=\"main_hr\">
  958. ''' + captcha_get() + '''
  959. <button id="save" type="submit">''' + load_lang('save') + '''</button>
  960. <button id="preview" type="submit" formaction="/preview/''' + url_pas(name) + action + '">' + load_lang('preview') + '''</button>
  961. </form>
  962. <hr class=\"main_hr\">
  963. ''' + end_data,
  964. menu = [['w/' + url_pas(name), load_lang('return')]]
  965. ))
  966. @app.route('/delete/<everything:name>', methods=['POST', 'GET'])
  967. def delete(name = None):
  968. return delete_2(conn, name)
  969. @app.route('/move/<everything:name>', methods=['POST', 'GET'])
  970. def move(name = None):
  971. if acl_check(name) == 1:
  972. return re_error('/ban')
  973. if flask.request.method == 'POST':
  974. if captcha_post(flask.request.form.get('g-recaptcha-response', '')) == 1:
  975. return re_error('/error/13')
  976. else:
  977. captcha_post('', 0)
  978. curs.execute("select title from history where title = ?", [flask.request.form.get('title', None)])
  979. if curs.fetchall():
  980. if admin_check(None, 'merge documents') == 1:
  981. curs.execute("select data from data where title = ?", [flask.request.form.get('title', None)])
  982. data = curs.fetchall()
  983. if data:
  984. curs.execute("delete from data where title = ?", [flask.request.form.get('title', None)])
  985. curs.execute("delete from back where link = ?", [flask.request.form.get('title', None)])
  986. curs.execute("select data from data where title = ?", [name])
  987. data = curs.fetchall()
  988. if data:
  989. curs.execute("update data set title = ? where title = ?", [flask.request.form.get('title', None), name])
  990. curs.execute("update back set link = ? where link = ?", [flask.request.form.get('title', None), name])
  991. data_in = data[0][0]
  992. else:
  993. data_in = ''
  994. history_plus(
  995. name,
  996. data_in,
  997. get_time(),
  998. ip_check(),
  999. flask.request.form.get('send', None) + ' (marge <a>' + name + '</a> - <a>' + flask.request.form.get('title', None) + '</a> move)',
  1000. '0'
  1001. )
  1002. curs.execute("update back set type = 'no' where title = ? and not type = 'cat' and not type = 'no'", [name])
  1003. curs.execute("delete from back where title = ? and not type = 'cat' and type = 'no'", [flask.request.form.get('title', None)])
  1004. curs.execute("select id from history where title = ? order by id + 0 desc limit 1", [flask.request.form.get('title', None)])
  1005. data = curs.fetchall()
  1006. num = data[0][0]
  1007. curs.execute("select id from history where title = ? order by id + 0 asc", [name])
  1008. data = curs.fetchall()
  1009. for move in data:
  1010. curs.execute("update history set title = ?, id = ? where title = ? and id = ?", [flask.request.form.get('title', None), str(int(num) + int(move[0])), name, move[0]])
  1011. conn.commit()
  1012. return redirect('/w/' + url_pas(flask.request.form.get('title', None)))
  1013. else:
  1014. return re_error('/error/19')
  1015. else:
  1016. curs.execute("select data from data where title = ?", [name])
  1017. data = curs.fetchall()
  1018. if data:
  1019. curs.execute("update data set title = ? where title = ?", [flask.request.form.get('title', None), name])
  1020. curs.execute("update back set link = ? where link = ?", [flask.request.form.get('title', None), name])
  1021. data_in = data[0][0]
  1022. else:
  1023. data_in = ''
  1024. history_plus(
  1025. name,
  1026. data_in,
  1027. get_time(),
  1028. ip_check(),
  1029. flask.request.form.get('send', None) + ' (<a>' + name + '</a> - <a>' + flask.request.form.get('title', None) + '</a> move)',
  1030. '0'
  1031. )
  1032. curs.execute("update back set type = 'no' where title = ? and not type = 'cat' and not type = 'no'", [name])
  1033. curs.execute("delete from back where title = ? and not type = 'cat' and type = 'no'", [flask.request.form.get('title', None)])
  1034. curs.execute("update history set title = ? where title = ?", [flask.request.form.get('title', None), name])
  1035. conn.commit()
  1036. return redirect('/w/' + url_pas(flask.request.form.get('title', None)))
  1037. else:
  1038. return easy_minify(flask.render_template(skin_check(),
  1039. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('move') + ')', 0])],
  1040. data = '''
  1041. <form method="post">
  1042. ''' + ip_warring() + '''
  1043. <input placeholder="''' + load_lang('document_name') + '" value="' + name + '''" name="title" type="text">
  1044. <hr class=\"main_hr\">
  1045. <input placeholder="''' + load_lang('why') + '''" name="send" type="text">
  1046. <hr class=\"main_hr\">
  1047. ''' + captcha_get() + '''
  1048. <button type="submit">''' + load_lang('move') + '''</button>
  1049. </form>
  1050. ''',
  1051. menu = [['w/' + url_pas(name), load_lang('return')]]
  1052. ))
  1053. @app.route('/other')
  1054. def other():
  1055. return easy_minify(flask.render_template(skin_check(),
  1056. imp = [load_lang('other_tool'), wiki_set(), custom(), other2([0, 0])],
  1057. data = '''
  1058. <h2>''' + load_lang('record') + '''</h2>
  1059. <ul>
  1060. <li><a href="/manager/6">''' + load_lang('edit_record') + '''</a></li>
  1061. <li><a href="/manager/7">''' + load_lang('discussion_record') + '''</a></li>
  1062. </ul>
  1063. <br>
  1064. <h2>''' + load_lang('list') + '''</h2>
  1065. <ul>
  1066. <li><a href="/admin_list">''' + load_lang('admin_list') + '''</a></li>
  1067. <li><a href="/give_log">''' + load_lang('admin_group_list') + '''</a></li>
  1068. <li><a href="/not_close_topic">''' + load_lang('open_discussion_list') + '''</a></li>
  1069. <li><a href="/title_index">''' + load_lang('all_document_list') + '''</a></li>
  1070. <li><a href="/acl_list">''' + load_lang('acl_document_list') + '''</a></li>
  1071. <li><a href="/please">''' + load_lang('need_document') + '''</a></li>
  1072. <li><a href="/block_log">''' + load_lang('recent_ban') + '''</a></li>
  1073. <li><a href="/user_log">''' + load_lang('member_list') + '''</a></li>
  1074. <li><a href="/admin_log">''' + load_lang('authority_use_list') + '''</a></li>
  1075. </ul>
  1076. <br>
  1077. <h2>''' + load_lang('other') + '''</h2>
  1078. <ul>
  1079. <li><a href="/upload">''' + load_lang('upload') + '''</a></li>
  1080. <li><a href="/manager/10">''' + load_lang('search') + '''</a></li>
  1081. </ul>
  1082. <br>
  1083. <h2>''' + load_lang('admin') + '''</h2>
  1084. <ul>
  1085. <li><a href="/manager/1">''' + load_lang('admin_tool') + '''</a></li>
  1086. </ul>
  1087. <br>
  1088. <h2>''' + load_lang('version') + '''</h2>
  1089. <ul>
  1090. <li>''' + load_lang('version') + ' : <a id="out_link" href="https://github.com/2DU/opennamu/blob/master/version.md">' + r_ver + '''</a></li>
  1091. </ul>
  1092. ''',
  1093. menu = 0
  1094. ))
  1095. @app.route('/manager', methods=['POST', 'GET'])
  1096. @app.route('/manager/<int:num>', methods=['POST', 'GET'])
  1097. def manager(num = 1):
  1098. title_list = {
  1099. 0 : [load_lang('document_name'), 'acl'],
  1100. 1 : [0, 'check'],
  1101. 2 : [0, 'ban'],
  1102. 3 : [0, 'admin'],
  1103. 4 : [0, 'record'],
  1104. 5 : [0, 'topic_record'],
  1105. 6 : [load_lang('name'), 'admin_plus'],
  1106. 7 : [load_lang('name'), 'plus_edit_filter'],
  1107. 8 : [load_lang('document_name'), 'search'],
  1108. 9 : [0, 'block_user'],
  1109. 10 : [0, 'block_admin'],
  1110. 11 : [load_lang('document_name'), 'watch_list'],
  1111. 12 : [load_lang('compare_target'), 'check'],
  1112. 13 : [load_lang('document_name'), 'edit']
  1113. }
  1114. if num == 1:
  1115. return easy_minify(flask.render_template(skin_check(),
  1116. imp = [load_lang('admin_tool'), wiki_set(), custom(), other2([0, 0])],
  1117. data = '''
  1118. <h2>''' + load_lang('admin') + '''</h2>
  1119. <ul>
  1120. <li><a href="/manager/2">''' + load_lang('acl_document_list') + '''</a></li>
  1121. <li><a href="/manager/3">''' + load_lang('check_user') + '''</a></li>
  1122. <li><a href="/manager/4">''' + load_lang('ban') + '''</a></li>
  1123. <li><a href="/manager/5">''' + load_lang('authorize') + '''</a></li>
  1124. <li><a href="/edit_filter">''' + load_lang('edit_filter_list') + '''</a></li>
  1125. </ul>
  1126. <br>
  1127. <h2>''' + load_lang('owner') + '''</h2>
  1128. <ul>
  1129. <li><a href="/manager/8">''' + load_lang('admin_group_add') + '''</a></li>
  1130. <li><a href="/setting">''' + load_lang('setting') + '''</a></li>
  1131. </ul>
  1132. <h3>''' + load_lang('filter') + '''</h3>
  1133. <ul>
  1134. <li><a href="/inter_wiki">''' + load_lang('interwiki_list') + '''</a></li>
  1135. <li><a href="/email_filter">''' + load_lang('email_filter_list') + '''</a></li>
  1136. <li><a href="/name_filter">''' + load_lang('id_filter_list') + '''</a></li>
  1137. </ul>
  1138. <br>
  1139. <h2>''' + load_lang('server') + '''</h2>
  1140. <ul>
  1141. <li><a href="/indexing">''' + load_lang('indexing') + '''</a></li>
  1142. <li><a href="/restart">''' + load_lang('wiki_restart') + '''</a></li>
  1143. <li><a href="/update">''' + load_lang('update') + '''</a></li>
  1144. <li><a href="/oauth_settings">''' + load_lang('oauth_setting') + '''</a></li>
  1145. <li><a href="/adsense_settings">''' + load_lang('adsense_setting') + '''</a></li>
  1146. </ul>
  1147. ''',
  1148. menu = [['other', load_lang('return')]]
  1149. ))
  1150. elif not num - 1 > len(title_list):
  1151. if flask.request.method == 'POST':
  1152. if flask.request.args.get('plus', None):
  1153. return redirect('/' + title_list[(num - 2)][1] + '/' + url_pas(flask.request.args.get('plus', None)) + '?plus=' + flask.request.form.get('name', None))
  1154. else:
  1155. return redirect('/' + title_list[(num - 2)][1] + '/' + url_pas(flask.request.form.get('name', None)))
  1156. else:
  1157. if title_list[(num - 2)][0] == 0:
  1158. placeholder = load_lang('user_name')
  1159. else:
  1160. placeholder = title_list[(num - 2)][0]
  1161. return easy_minify(flask.render_template(skin_check(),
  1162. imp = ['Redirect', wiki_set(), custom(), other2([0, 0])],
  1163. data = '''
  1164. <form method="post">
  1165. <input placeholder="''' + placeholder + '''" name="name" type="text">
  1166. <hr class=\"main_hr\">
  1167. <button type="submit">''' + load_lang('go') + '''</button>
  1168. </form>
  1169. ''',
  1170. menu = [['manager', load_lang('return')]]
  1171. ))
  1172. else:
  1173. return redirect()
  1174. @app.route('/title_index')
  1175. def title_index():
  1176. page = int(number_check(flask.request.args.get('page', '1')))
  1177. num = int(number_check(flask.request.args.get('num', '100')))
  1178. if page * num > 0:
  1179. sql_num = page * num - num
  1180. else:
  1181. sql_num = 0
  1182. all_list = sql_num + 1
  1183. if num > 1000:
  1184. return re_error('/error/3')
  1185. data = '<a href="/title_index?num=250">(250)</a> <a href="/title_index?num=500">(500)</a> <a href="/title_index?num=1000">(1000)</a>'
  1186. curs.execute("select title from data order by title asc limit ?, ?", [str(sql_num), str(num)])
  1187. title_list = curs.fetchall()
  1188. if title_list:
  1189. data += '<hr class=\"main_hr\"><ul>'
  1190. for list_data in title_list:
  1191. data += '<li>' + str(all_list) + '. <a href="/w/' + url_pas(list_data[0]) + '">' + list_data[0] + '</a></li>'
  1192. all_list += 1
  1193. if page == 1:
  1194. count_end = []
  1195. curs.execute("select count(title) from data")
  1196. count = curs.fetchall()
  1197. if count:
  1198. count_end += [count[0][0]]
  1199. else:
  1200. count_end += [0]
  1201. sql_list = [load_lang('template', 1).lower() + ':', 'category:', 'user:', 'file:']
  1202. for sql in sql_list:
  1203. curs.execute("select count(title) from data where title like ?", [sql + '%'])
  1204. count = curs.fetchall()
  1205. if count:
  1206. count_end += [count[0][0]]
  1207. else:
  1208. count_end += [0]
  1209. count_end += [count_end[0] - count_end[1] - count_end[2] - count_end[3] - count_end[4]]
  1210. data += '''
  1211. </ul>
  1212. <hr class=\"main_hr\">
  1213. <ul>
  1214. <li>all : ''' + str(count_end[0]) + '''</li>
  1215. </ul>
  1216. <hr class=\"main_hr\">
  1217. <ul>
  1218. <li>''' + load_lang('template') + ' : ' + str(count_end[1]) + '''</li>
  1219. <li>''' + load_lang('category') + ' : ' + str(count_end[2]) + '''</li>
  1220. <li>''' + load_lang('user') + ' : ' + str(count_end[3]) + '''</li>
  1221. <li>''' + load_lang('file') + ' : ' + str(count_end[4]) + '''</li>
  1222. <li>other : ''' + str(count_end[5]) + '''</li>
  1223. '''
  1224. data += '</ul>' + next_fix('/title_index?num=' + str(num) + '&page=', page, title_list, num)
  1225. sub = ' (' + str(num) + ')'
  1226. return easy_minify(flask.render_template(skin_check(),
  1227. imp = [load_lang('all_document_list'), wiki_set(), custom(), other2([sub, 0])],
  1228. data = data,
  1229. menu = [['other', load_lang('return')]]
  1230. ))
  1231. @app.route('/topic/<everything:name>/sub/<sub>/b/<int:num>')
  1232. def topic_block(name = None, sub = None, num = 1):
  1233. if admin_check(3, 'blind (' + name + ' - ' + sub + '#' + str(num) + ')') != 1:
  1234. return re_error('/error/3')
  1235. curs.execute("select block from topic where title = ? and sub = ? and id = ?", [name, sub, str(num)])
  1236. block = curs.fetchall()
  1237. if block:
  1238. if block[0][0] == 'O':
  1239. curs.execute("update topic set block = '' where title = ? and sub = ? and id = ?", [name, sub, str(num)])
  1240. else:
  1241. curs.execute("update topic set block = 'O' where title = ? and sub = ? and id = ?", [name, sub, str(num)])
  1242. rd_plus(name, sub, get_time())
  1243. conn.commit()
  1244. return redirect('/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '#' + str(num))
  1245. @app.route('/topic/<everything:name>/sub/<sub>/notice/<int:num>')
  1246. def topic_top(name = None, sub = None, num = 1):
  1247. if admin_check(3, 'notice (' + name + ' - ' + sub + '#' + str(num) + ')') != 1:
  1248. return re_error('/error/3')
  1249. curs.execute("select title from topic where title = ? and sub = ? and id = ?", [name, sub, str(num)])
  1250. if curs.fetchall():
  1251. curs.execute("select top from topic where id = ? and title = ? and sub = ?", [str(num), name, sub])
  1252. top_data = curs.fetchall()
  1253. if top_data:
  1254. if top_data[0][0] == 'O':
  1255. curs.execute("update topic set top = '' where title = ? and sub = ? and id = ?", [name, sub, str(num)])
  1256. else:
  1257. curs.execute("update topic set top = 'O' where title = ? and sub = ? and id = ?", [name, sub, str(num)])
  1258. rd_plus(name, sub, get_time())
  1259. conn.commit()
  1260. return redirect('/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '#' + str(num))
  1261. @app.route('/topic/<everything:name>/sub/<sub>/tool/<regex("close|stop|agree"):tool>')
  1262. def topic_stop(name = None, sub = None, tool = None):
  1263. if tool == 'close':
  1264. set_list = [
  1265. 'O',
  1266. 'S',
  1267. load_lang('close', 1),
  1268. load_lang('open', 1)
  1269. ]
  1270. elif tool == 'stop':
  1271. set_list = [
  1272. '',
  1273. 'O',
  1274. load_lang('stop', 1),
  1275. load_lang('restart', 1)
  1276. ]
  1277. elif tool == 'agree':
  1278. pass
  1279. else:
  1280. return redirect('/topic/' + url_pas(name) + '/sub/' + url_pas(sub))
  1281. if admin_check(3, 'topic ' + tool + ' (' + name + ' - ' + sub + ')') != 1:
  1282. return re_error('/error/3')
  1283. ip = ip_check()
  1284. time = get_time()
  1285. curs.execute("select id from topic where title = ? and sub = ? order by id + 0 desc limit 1", [name, sub])
  1286. topic_check = curs.fetchall()
  1287. if topic_check:
  1288. if tool == 'agree':
  1289. curs.execute("select title from rd where title = ? and sub = ? and agree = 'O'", [name, sub])
  1290. if curs.fetchall():
  1291. curs.execute("insert into topic (id, title, sub, data, date, ip, block, top) values (?, ?, ?, '" + load_lang('agreement', 1) + " X', ?, ?, '', '1')", [str(int(topic_check[0][0]) + 1), name, sub, time, ip])
  1292. curs.execute("update rd set agree = '' where title = ? and sub = ?", [name, sub])
  1293. else:
  1294. curs.execute("insert into topic (id, title, sub, data, date, ip, block, top) values (?, ?, ?, '" + load_lang('agreement', 1) + " O', ?, ?, '', '1')", [str(int(topic_check[0][0]) + 1), name, sub, time, ip])
  1295. curs.execute("update rd set agree = 'O' where title = ? and sub = ?", [name, sub])
  1296. else:
  1297. curs.execute("select title from rd where title = ? and sub = ? and stop = ?", [name, sub, set_list[0]])
  1298. if curs.fetchall():
  1299. curs.execute("insert into topic (id, title, sub, data, date, ip, block, top) values (?, ?, ?, ?, ?, ?, '', '1')", [str(int(topic_check[0][0]) + 1), name, sub, set_list[3], time, ip])
  1300. curs.execute("update rd set stop = '' where title = ? and sub = ?", [name, sub])
  1301. else:
  1302. curs.execute("insert into topic (id, title, sub, data, date, ip, block, top) values (?, ?, ?, ?, ?, ?, '', '1')", [str(int(topic_check[0][0]) + 1), name, sub, set_list[2], time, ip])
  1303. curs.execute("update rd set stop = ? where title = ? and sub = ?", [set_list[0], name, sub])
  1304. rd_plus(name, sub, time)
  1305. conn.commit()
  1306. return redirect('/topic/' + url_pas(name) + '/sub/' + url_pas(sub))
  1307. @app.route('/topic/<everything:name>/sub/<sub>/admin/<int:num>')
  1308. def topic_admin(name = None, sub = None, num = 1):
  1309. curs.execute("select block, ip, date from topic where title = ? and sub = ? and id = ?", [name, sub, str(num)])
  1310. data = curs.fetchall()
  1311. if not data:
  1312. return redirect('/topic/' + url_pas(name) + '/sub/' + url_pas(sub))
  1313. ban = ''
  1314. if admin_check(3) == 1:
  1315. ban += '''
  1316. </ul>
  1317. <br>
  1318. <h2>''' + load_lang('admin_tool') + '''</h2>
  1319. <ul>
  1320. '''
  1321. is_ban = '<li><a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/b/' + str(num) + '">'
  1322. if data[0][0] == 'O':
  1323. is_ban += load_lang('hide_release')
  1324. else:
  1325. is_ban += load_lang('hide')
  1326. is_ban += '''
  1327. </a>
  1328. </li>
  1329. <li>
  1330. <a href="/topic/''' + url_pas(name) + '/sub/' + url_pas(sub) + '/notice/' + str(num) + '''">
  1331. '''
  1332. curs.execute("select id from topic where title = ? and sub = ? and id = ? and top = 'O'", [name, sub, str(num)])
  1333. if curs.fetchall():
  1334. is_ban += load_lang('notice_release')
  1335. else:
  1336. is_ban += load_lang('notice') + ''
  1337. is_ban += '</a></li></ul>'
  1338. ban += '<li><a href="/ban/' + url_pas(data[0][1]) + '">'
  1339. curs.execute("select end from ban where block = ?", [data[0][1]])
  1340. if curs.fetchall():
  1341. ban += load_lang('ban_release')
  1342. else:
  1343. ban += load_lang('ban')
  1344. ban += '</a></li>' + is_ban
  1345. ban += '''
  1346. </ul>
  1347. <br>
  1348. <h2>''' + load_lang('other_tool') + '''</h2>
  1349. <ul>
  1350. <li>
  1351. <a href="/topic/''' + url_pas(name) + '/sub/' + url_pas(sub) + '/raw/' + str(num) + '''">raw</a>
  1352. </li>
  1353. '''
  1354. ban = '<li>' + load_lang('time') + ' : ' + data[0][2] + '</li>' + ban
  1355. if ip_or_user(data[0][1]) == 1:
  1356. ban = '<li>' + load_lang('writer') + ' : ' + data[0][1] + ' <a href="/record/' + url_pas(data[0][1]) + '">(' + load_lang('record') + ')</a></li>' + ban
  1357. else:
  1358. ban = '''
  1359. <li>
  1360. ''' + load_lang('writer') + ' : <a href="/w/user:' + data[0][1] + '">' + data[0][1] + '</a> <a href="/record/' + url_pas(data[0][1]) + '">(' + load_lang('record') + ''')</a>
  1361. </li>
  1362. ''' + ban
  1363. ban = '<h2>' + load_lang('state') + '</h2><ul>' + ban
  1364. return easy_minify(flask.render_template(skin_check(),
  1365. imp = [load_lang('discussion_tool'), wiki_set(), custom(), other2([' (' + str(num) + ')', 0])],
  1366. data = ban,
  1367. menu = [['topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '#' + str(num), load_lang('return')]]
  1368. ))
  1369. @app.route('/topic/<everything:name>/sub/<sub>', methods=['POST', 'GET'])
  1370. def topic(name = None, sub = None):
  1371. ban = topic_check(name, sub)
  1372. admin = admin_check(3)
  1373. if flask.request.method == 'POST':
  1374. if captcha_post(flask.request.form.get('g-recaptcha-response', '')) == 1:
  1375. return re_error('/error/13')
  1376. else:
  1377. captcha_post('', 0)
  1378. ip = ip_check()
  1379. today = get_time()
  1380. if ban == 1:
  1381. return re_error('/ban')
  1382. curs.execute("select id from topic where title = ? and sub = ? order by id + 0 desc limit 1", [name, sub])
  1383. old_num = curs.fetchall()
  1384. if old_num:
  1385. num = int(old_num[0][0]) + 1
  1386. else:
  1387. num = 1
  1388. match = re.search('^user:([^/]+)', name)
  1389. if match:
  1390. curs.execute('insert into alarm (name, data, date) values (?, ?, ?)', [match.groups()[0], ip + ' - <a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '">' + load_lang('user_discussion', 1) + '</a>', today])
  1391. data = re.sub('\[\[((?:분류|category):(?:(?:(?!\]\]).)*))\]\]', '[br]', flask.request.form.get('content', None))
  1392. for rd_data in re.findall("(?:#([0-9]+))", data):
  1393. curs.execute("select ip from topic where title = ? and sub = ? and id = ?", [name, sub, rd_data])
  1394. ip_data = curs.fetchall()
  1395. if ip_data and ip_or_user(ip_data[0][0]) == 0:
  1396. curs.execute('insert into alarm (name, data, date) values (?, ?, ?)', [ip_data[0][0], ip + ' - <a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '#' + str(num) + '">' + load_lang('discussion', 1) + '</a>', today])
  1397. data = re.sub("(?P<in>#(?:[0-9]+))", '[[\g<in>]]', data)
  1398. data = savemark(data)
  1399. rd_plus(name, sub, today)
  1400. curs.execute("insert into topic (id, title, sub, data, date, ip, block, top) values (?, ?, ?, ?, ?, ?, '', '')", [str(num), name, sub, data, today, ip])
  1401. conn.commit()
  1402. return redirect('/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '#reload')
  1403. else:
  1404. curs.execute("select title from rd where title = ? and sub = ? and stop = 'O'", [name, sub])
  1405. close_data = curs.fetchall()
  1406. curs.execute("select title from rd where title = ? and sub = ? and stop = 'S'", [name, sub])
  1407. stop_data = curs.fetchall()
  1408. curs.execute("select id from topic where title = ? and sub = ? limit 1", [name, sub])
  1409. topic_exist = curs.fetchall()
  1410. display = ''
  1411. all_data = ''
  1412. data = ''
  1413. number = 1
  1414. if admin == 1 and topic_exist:
  1415. if close_data:
  1416. all_data += '<a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/tool/close">(' + load_lang('open') + ')</a> '
  1417. else:
  1418. all_data += '<a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/tool/close">(' + load_lang('close') + ')</a> '
  1419. if stop_data:
  1420. all_data += '<a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/tool/stop">(' + load_lang('restart') + ')</a> '
  1421. else:
  1422. all_data += '<a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/tool/stop">(' + load_lang('stop') + ')</a> '
  1423. curs.execute("select title from rd where title = ? and sub = ? and agree = 'O'", [name, sub])
  1424. if curs.fetchall():
  1425. all_data += '<a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/tool/agree">(' + load_lang('destruction') + ')</a>'
  1426. else:
  1427. all_data += '<a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/tool/agree">(' + load_lang('agreement') + ')</a>'
  1428. all_data += '<hr class=\"main_hr\">'
  1429. if (close_data or stop_data) and admin != 1:
  1430. display = 'display: none;'
  1431. curs.execute("select data, id, date, ip, block, top from topic where title = ? and sub = ? order by id + 0 asc", [name, sub])
  1432. topic = curs.fetchall()
  1433. curs.execute("select data, id, date, ip from topic where title = ? and sub = ? and top = 'O' order by id + 0 asc", [name, sub])
  1434. for topic_data in curs.fetchall():
  1435. who_plus = ''
  1436. curs.execute("select who from re_admin where what = ? order by time desc limit 1", ['notice (' + name + ' - ' + sub + '#' + topic_data[1] + ')'])
  1437. topic_data_top = curs.fetchall()
  1438. if topic_data_top:
  1439. who_plus += ' <span style="margin-right: 5px;">@' + topic_data_top[0][0] + ' </span>'
  1440. all_data += '''
  1441. <table id="toron">
  1442. <tbody>
  1443. <tr>
  1444. <td id="toron_color_red">
  1445. <a href="#''' + topic_data[1] + '''">
  1446. #''' + topic_data[1] + '''
  1447. </a> ''' + ip_pas(topic_data[3]) + who_plus + ''' <span style="float: right;">''' + topic_data[2] + '''</span>
  1448. </td>
  1449. </tr>
  1450. <tr>
  1451. <td>''' + render_set(data = topic_data[0]) + '''</td>
  1452. </tr>
  1453. </tbody>
  1454. </table>
  1455. <br>
  1456. '''
  1457. for topic_data in topic:
  1458. user_write = topic_data[0]
  1459. if number == 1:
  1460. start = topic_data[3]
  1461. if topic_data[4] == 'O':
  1462. blind_data = 'id="toron_color_grey"'
  1463. if admin != 1:
  1464. curs.execute("select who from re_admin where what = ? order by time desc limit 1", ['blind (' + name + ' - ' + sub + '#' + str(number) + ')'])
  1465. who_blind = curs.fetchall()
  1466. if who_blind:
  1467. user_write = '[[user:' + who_blind[0][0] + ']] ' + load_lang('hide')
  1468. else:
  1469. user_write = load_lang('hide')
  1470. else:
  1471. blind_data = ''
  1472. user_write = render_set(data = user_write)
  1473. ip = ip_pas(topic_data[3])
  1474. curs.execute('select acl from user where id = ?', [topic_data[3]])
  1475. user_acl = curs.fetchall()
  1476. if user_acl and user_acl[0][0] != 'user':
  1477. ip += ' <a href="javascript:void(0);" title="' + load_lang('admin') + '">★</a>'
  1478. if admin == 1 or blind_data == '':
  1479. ip += ' <a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/admin/' + str(number) + '">(' + load_lang('discussion_tool') + ')</a>'
  1480. curs.execute("select end from ban where block = ?", [topic_data[3]])
  1481. if curs.fetchall():
  1482. ip += ' <a href="javascript:void(0);" title="' + load_lang('blocked') + '">†</a>'
  1483. if topic_data[5] == '1':
  1484. color = '_blue'
  1485. elif topic_data[3] == start:
  1486. color = '_green'
  1487. else:
  1488. color = ''
  1489. if user_write == '':
  1490. user_write = '<br>'
  1491. all_data += '''
  1492. <table id="toron">
  1493. <tbody>
  1494. <tr>
  1495. <td id="toron_color''' + color + '''">
  1496. <a href="javascript:void(0);" id="''' + str(number) + '">#' + str(number) + '</a> ' + ip + '''</span>
  1497. </td>
  1498. </tr>
  1499. <tr ''' + blind_data + '''>
  1500. <td>''' + user_write + '''</td>
  1501. </tr>
  1502. </tbody>
  1503. </table>
  1504. <br>
  1505. '''
  1506. number += 1
  1507. if ban != 1 or admin == 1:
  1508. data += '''
  1509. <div id="plus"></div>
  1510. <script type="text/javascript" src="/views/main_css/topic_reload.js"></script>
  1511. <script>topic_load("''' + name + '''", "''' + sub + '''");</script>
  1512. <a id="reload" href="javascript:void(0);" onclick="location.href.endsWith(\'#reload\')? location.reload(true):location.href=\'#reload\'">(''' + load_lang('reload') + ''')</a>
  1513. <form style="''' + display + '''" method="post">
  1514. <br>
  1515. <textarea style="height: 100px;" name="content"></textarea>
  1516. <hr class=\"main_hr\">
  1517. ''' + captcha_get()
  1518. if display == '':
  1519. data += ip_warring()
  1520. data += '''
  1521. <button type="submit">''' + load_lang('send') + '''</button>
  1522. </form>
  1523. '''
  1524. return easy_minify(flask.render_template(skin_check(),
  1525. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('discussion') + ')', 0])],
  1526. data = '<h2 id="topic_top_title">' + sub + '</h2>' + all_data + data,
  1527. menu = [['topic/' + url_pas(name), load_lang('list')]]
  1528. ))
  1529. @app.route('/tool/<name>')
  1530. def user_tool(name = None):
  1531. data = '''
  1532. <h2>''' + load_lang('tool') + '''</h2>
  1533. <ul>
  1534. <li><a href="/record/''' + url_pas(name) + '''">''' + load_lang('record') + '''</a></li>
  1535. </ul>
  1536. '''
  1537. if admin_check(1) == 1:
  1538. curs.execute("select block from ban where block = ?", [name])
  1539. if curs.fetchall():
  1540. ban_name = load_lang('ban_release')
  1541. else:
  1542. ban_name = load_lang('ban')
  1543. data += '''
  1544. <h2>''' + load_lang('admin') + '''</h2>
  1545. <ul>
  1546. <li><a href="/ban/''' + url_pas(name) + '''">''' + ban_name + '''</a></li>
  1547. <li><a href="/check/''' + url_pas(name) + '''">''' + load_lang('check') + '''</a></li>
  1548. </ul>
  1549. '''
  1550. return easy_minify(flask.render_template(skin_check(),
  1551. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('tool') + ')', 0])],
  1552. data = data,
  1553. menu = 0
  1554. ))
  1555. @app.route('/topic/<everything:name>', methods=['POST', 'GET'])
  1556. @app.route('/topic/<everything:name>/<regex("close|agree"):tool>', methods=['GET'])
  1557. def close_topic_list(name = None, tool = None):
  1558. div = ''
  1559. if flask.request.method == 'POST':
  1560. t_num = ''
  1561. while 1:
  1562. curs.execute("select title from topic where title = ? and sub = ? limit 1", [name, flask.request.form.get('topic', None) + t_num])
  1563. if curs.fetchall():
  1564. if t_num == '':
  1565. t_num = ' 2'
  1566. else:
  1567. t_num = ' ' + str(int(t_num.replace(' ', '')) + 1)
  1568. else:
  1569. break
  1570. return redirect('/topic/' + url_pas(name) + '/sub/' + url_pas(flask.request.form.get('topic', None) + t_num))
  1571. else:
  1572. plus = ''
  1573. menu = [['topic/' + url_pas(name), load_lang('return')]]
  1574. if tool == 'close':
  1575. curs.execute("select sub from rd where title = ? and stop = 'O' order by sub asc", [name])
  1576. sub = load_lang('close') + ''
  1577. elif tool == 'agree':
  1578. curs.execute("select sub from rd where title = ? and agree = 'O' order by sub asc", [name])
  1579. sub = load_lang('agreement') + ''
  1580. else:
  1581. curs.execute("select sub from rd where title = ? order by date desc", [name])
  1582. sub = load_lang('discussion_list')
  1583. menu = [['w/' + url_pas(name), load_lang('document')]]
  1584. plus = '''
  1585. <a href="/topic/''' + url_pas(name) + '''/close">(''' + load_lang('close') + ''')</a> <a href="/topic/''' + url_pas(name) + '''/agree">(''' + load_lang('agreement') + ''')</a>
  1586. <hr class=\"main_hr\">
  1587. <input placeholder="''' + load_lang('discussion_name') + '''" name="topic" type="text">
  1588. <hr class=\"main_hr\">
  1589. <button type="submit">''' + load_lang('go') + '''</button>
  1590. '''
  1591. for data in curs.fetchall():
  1592. curs.execute("select data, date, ip, block from topic where title = ? and sub = ? and id = '1'", [name, data[0]])
  1593. if curs.fetchall():
  1594. it_p = 0
  1595. if sub == load_lang('discussion_list'):
  1596. curs.execute("select title from rd where title = ? and sub = ? and stop = 'O' order by sub asc", [name, data[0]])
  1597. if curs.fetchall():
  1598. it_p = 1
  1599. if it_p != 1:
  1600. div += '<h2><a href="/topic/' + url_pas(name) + '/sub/' + url_pas(data[0]) + '">' + data[0] + '</a></h2>'
  1601. if div == '':
  1602. plus = re.sub('^<br>', '', plus)
  1603. return easy_minify(flask.render_template(skin_check(),
  1604. imp = [name, wiki_set(), custom(), other2([' (' + sub + ')', 0])],
  1605. data = '<form method="post">' + div + plus + '</form>',
  1606. menu = menu
  1607. ))
  1608. @app.route('/login', methods=['POST', 'GET'])
  1609. def login():
  1610. if custom()[2] != 0:
  1611. return redirect('/user')
  1612. if ban_check(tool = 'login') == 1:
  1613. return re_error('/ban')
  1614. if flask.request.method == 'POST':
  1615. if captcha_post(flask.request.form.get('g-recaptcha-response', '')) == 1:
  1616. return re_error('/error/13')
  1617. else:
  1618. captcha_post('', 0)
  1619. ip = ip_check()
  1620. agent = flask.request.headers.get('User-Agent')
  1621. curs.execute("select pw, encode from user where id = ?", [flask.request.form.get('id', None)])
  1622. user = curs.fetchall()
  1623. if not user:
  1624. return re_error('/error/2')
  1625. pw_check_d = pw_check(
  1626. flask.request.form.get('pw', ''),
  1627. user[0][0],
  1628. user[0][1],
  1629. flask.request.form.get('id', None)
  1630. )
  1631. if pw_check_d != 1:
  1632. return re_error('/error/10')
  1633. flask.session['state'] = 1
  1634. flask.session['id'] = flask.request.form.get('id', None)
  1635. curs.execute("select css from custom where user = ?", [flask.request.form.get('id', None)])
  1636. css_data = curs.fetchall()
  1637. if css_data:
  1638. flask.session['head'] = css_data[0][0]
  1639. else:
  1640. flask.session['head'] = ''
  1641. curs.execute("insert into ua_d (name, ip, ua, today, sub) values (?, ?, ?, ?, '')", [flask.request.form.get('id', None), ip_check(1), agent, get_time()])
  1642. conn.commit()
  1643. return redirect('/user')
  1644. else:
  1645. oauth_content = '<link rel="stylesheet" href="/views/main_css/oauth.css"><div class="oauth-wrapper"><ul class="oauth-list">'
  1646. oauth_supported = load_oauth('_README')['support']
  1647. for i in range(len(oauth_supported)):
  1648. oauth_data = load_oauth(oauth_supported[i])
  1649. if oauth_data['client_id'] != '' and oauth_data['client_secret'] != '':
  1650. oauth_content += '''
  1651. <li>
  1652. <a href="/oauth/{}/init">
  1653. <div class="oauth-btn oauth-btn-{}">
  1654. <div class="oauth-btn-logo oauth-btn-{}"></div>
  1655. {}
  1656. </div>
  1657. </a>
  1658. </li>
  1659. '''.format(
  1660. oauth_supported[i],
  1661. oauth_supported[i],
  1662. oauth_supported[i],
  1663. load_lang('oauth_signin_' + oauth_supported[i])
  1664. )
  1665. oauth_content += '</ul></div>'
  1666. return easy_minify(flask.render_template(skin_check(),
  1667. imp = [load_lang('login'), wiki_set(), custom(), other2([0, 0])],
  1668. data = '''
  1669. <form method="post">
  1670. <input placeholder="''' + load_lang('id') + '''" name="id" type="text">
  1671. <hr class=\"main_hr\">
  1672. <input placeholder="''' + load_lang('password') + '''" name="pw" type="password">
  1673. <hr class=\"main_hr\">
  1674. ''' + captcha_get() + '''
  1675. <button type="submit">''' + load_lang('login') + '''</button>
  1676. <hr class=\"main_hr\">
  1677. ''' + oauth_content + '''
  1678. <hr class=\"main_hr\">
  1679. <span>''' + load_lang('http_warring') + '''</span>
  1680. </form>
  1681. ''',
  1682. menu = [['user', load_lang('return')]]
  1683. ))
  1684. @app.route('/oauth/<regex("discord|naver|facebook"):platform>/<regex("init|callback"):func>', methods=['GET', 'POST'])
  1685. def login_oauth(platform = None, func = None):
  1686. publish_url = load_oauth('publish_url')
  1687. oauth_data = load_oauth(platform)
  1688. api_url = {}
  1689. data = {
  1690. 'client_id' : oauth_data['client_id'],
  1691. 'client_secret' : oauth_data['client_secret'],
  1692. 'redirect_uri' : publish_url + '/oauth/' + platform + '/callback',
  1693. 'state' : 'RAMDOMVALUE'
  1694. }
  1695. if platform == 'discord':
  1696. api_url['redirect'] = 'https://discordapp.com/api/oauth2/authorize'
  1697. api_url['token'] = 'https://discordapp.com/api/oauth2/token'
  1698. api_url['profile'] = 'https://discordapp.com/api/users/@me'
  1699. elif platform == 'naver':
  1700. api_url['redirect'] = 'https://nid.naver.com/oauth2.0/authorize'
  1701. api_url['token'] = 'https://nid.naver.com/oauth2.0/token'
  1702. api_url['profile'] = 'https://openapi.naver.com/v1/nid/me'
  1703. elif platform == 'facebook':
  1704. api_url['redirect'] = 'https://www.facebook.com/v3.1/dialog/oauth'
  1705. api_url['token'] = 'https://graph.facebook.com/v3.1/oauth/access_token'
  1706. api_url['profile'] = 'https://graph.facebook.com/me'
  1707. if func == 'init':
  1708. if oauth_data['client_id'] == '' or oauth_data['client_secret'] == '':
  1709. return easy_minify(flask.render_template(skin_check(),
  1710. imp = [load_lang('error'), wiki_set(), custom(), other2([0, 0])],
  1711. data = load_lang('oauth_disabled'),
  1712. menu = [['user', load_lang('return')]]
  1713. ))
  1714. elif publish_url == 'https://':
  1715. return easy_minify(flask.render_template(skin_check(),
  1716. imp = [load_lang('error'), wiki_set(), custom(), other2([0, 0])],
  1717. data = load_lang('oauth_settings_not_found'),
  1718. menu = [['user', load_lang('return')]]
  1719. ))
  1720. referrer_re = re.compile(r'(?P<host>^(https?):\/\/([^\/]+))\/(?P<refer>[^\/?]+)')
  1721. if flask.request.referrer != None:
  1722. referrer = referrer_re.search(flask.request.referrer)
  1723. if referrer.group('host') != load_oauth('publish_url'):
  1724. return redirect()
  1725. else:
  1726. flask.session['referrer'] = referrer.group('refer')
  1727. else:
  1728. return redirect()
  1729. flask.session['refer'] = flask.request.referrer
  1730. if platform == 'discord':
  1731. return redirect(api_url['redirect'] + '?client_id={}&redirect_uri={}&response_type=code&scope=identify'.format(
  1732. data['client_id'],
  1733. data['redirect_uri']
  1734. ))
  1735. elif platform == 'naver':
  1736. return redirect(api_url['redirect'] + '?response_type=code&client_id={}&redirect_uri={}&state={}'.format(
  1737. data['client_id'],
  1738. data['redirect_uri'],
  1739. data['state']
  1740. ))
  1741. elif platform == 'facebook':
  1742. return redirect(api_url['redirect'] + '?client_id={}&redirect_uri={}&state={}'.format(
  1743. data['client_id'],
  1744. data['redirect_uri'],
  1745. data['state']
  1746. ))
  1747. elif func == 'callback':
  1748. code = flask.request.args.get('code')
  1749. state = flask.request.args.get('state')
  1750. if code == None:
  1751. return easy_minify(flask.render_template(skin_check(),
  1752. imp = [load_lang('inter_error'), wiki_set(), custom(), other2([0, 0])],
  1753. data = '<h2>ie_wrong_callback</h2>' + load_lang('ie_wrong_callback'),
  1754. menu = [['user', load_lang('return')]]
  1755. ))
  1756. if platform == 'discord':
  1757. data = {
  1758. 'client_id' : data['client_id'],
  1759. 'client_secret' : data['client_secret'],
  1760. 'grant_type' : 'authorization_code',
  1761. 'redirect_uri' : data['redirect_uri'],
  1762. 'scope' : 'identify',
  1763. 'code' : code
  1764. }
  1765. headers = {
  1766. 'Content-Type': 'application/x-www-form-urlencoded',
  1767. 'User-Agent': 'Mozilla/5.0'
  1768. }
  1769. token_exchange = urllib.request.Request(
  1770. 'https://discordapp.com/api/oauth2/token',
  1771. data = bytes(urllib.parse.urlencode(data).encode()),
  1772. headers = headers
  1773. )
  1774. token_result = urllib.request.urlopen(token_exchange).read()
  1775. token_json = json.loads(token_result)
  1776. headers = {
  1777. 'User-Agent' : 'Mozilla/5.0',
  1778. 'Authorization' : 'Bearer ' + token_json['access_token']
  1779. }
  1780. profile_exchange = urllib.request.Request(
  1781. 'https://discordapp.com/api/users/@me',
  1782. headers = headers
  1783. )
  1784. profile_result = urllib.request.urlopen(profile_exchange).read().decode('utf-8')
  1785. profile_result_json = json.loads(profile_result)
  1786. stand_json = {
  1787. 'id' : profile_result_json['id'],
  1788. 'name' : profile_result_json['username'] + '#' + profile_result_json['discriminator'],
  1789. 'picture' : profile_result_json['avatar']
  1790. }
  1791. elif platform == 'naver':
  1792. token_access = api_url['token'] + '?grant_type=authorization_code&client_id={}&client_secret={}&code={}&state={}'.format(
  1793. data['client_id'],
  1794. data['client_secret'],
  1795. code,
  1796. state
  1797. )
  1798. token_result = urllib.request.urlopen(token_access).read().decode('utf-8')
  1799. token_result_json = json.loads(token_result)
  1800. headers = {
  1801. 'Authorization': 'Bearer {}'.format(token_result_json['access_token'])
  1802. }
  1803. profile_access = urllib.request.Request(api_url['profile'], headers = headers)
  1804. profile_result = urllib.request.urlopen(profile_access).read().decode('utf-8')
  1805. profile_result_json = json.loads(profile_result)
  1806. stand_json = {
  1807. 'id' : profile_result_json['response']['id'],
  1808. 'name' : profile_result_json['response']['name'],
  1809. 'picture' : profile_result_json['response']['profile_image']
  1810. }
  1811. elif platform == 'facebook':
  1812. token_access = api_url['token'] + '?client_id={}&redirect_uri={}&client_secret={}&code={}'.format(
  1813. data['client_id'],
  1814. data['redirect_uri'],
  1815. data['client_secret'],
  1816. code
  1817. )
  1818. token_result = urllib.request.urlopen(token_access).read().decode('utf-8')
  1819. token_result_json = json.loads(token_result)
  1820. profile_access = api_url['profile'] + '?fields=id,name,picture&access_token={}'.format(token_result_json['access_token'])
  1821. profile_result = urllib.request.urlopen(profile_access).read().decode('utf-8')
  1822. profile_result_json = json.loads(profile_result)
  1823. stand_json = {
  1824. 'id': profile_result_json['id'],
  1825. 'name': profile_result_json['name'],
  1826. 'picture': profile_result_json['picture']['data']['url']
  1827. }
  1828. if flask.session['referrer'][0:6] == 'change':
  1829. curs.execute('select * from oauth_conn where wiki_id = ? and provider = ?', [flask.session['id'], platform])
  1830. oauth_result = curs.fetchall()
  1831. if len(oauth_result) == 0:
  1832. curs.execute('insert into oauth_conn (provider, wiki_id, sns_id, name, picture) values(?, ?, ?, ?, ?)', [
  1833. platform,
  1834. flask.session['id'],
  1835. stand_json['id'],
  1836. stand_json['name'],
  1837. stand_json['picture']
  1838. ])
  1839. else:
  1840. curs.execute('update oauth_conn set name = ? picture = ? where wiki_id = ?', [stand_json['name'], stand_json['pricture'], flask.session['id']])
  1841. conn.commit()
  1842. elif flask.session['referrer'][0:5] == 'login':
  1843. curs.execute('select * from oauth_conn where provider = ? and sns_id = ?', [platform, stand_json['id']])
  1844. curs_result = curs.fetchall()
  1845. if len(curs_result) == 0:
  1846. return re_error('/error/2')
  1847. else:
  1848. flask.session['state'] = 1
  1849. flask.session['id'] = curs_result[0][2]
  1850. return redirect(flask.session['refer'])
  1851. @app.route('/change', methods=['POST', 'GET'])
  1852. def change_password():
  1853. support_language = server_init.server_set_var['language']['list']
  1854. if ban_check() == 1:
  1855. return re_error('/ban')
  1856. if custom()[2] == 0:
  1857. return redirect('/login')
  1858. ip = ip_check()
  1859. user_state = flask.request.args.get('user', 'ip')
  1860. if user_state == 'ip':
  1861. if flask.request.method == 'POST':
  1862. if flask.request.form.get('pw4', None) and flask.request.form.get('pw2', None):
  1863. if flask.request.form.get('pw2', None) != flask.request.form.get('pw3', None):
  1864. return re_error('/error/20')
  1865. curs.execute("select pw, encode from user where id = ?", [flask.session['id']])
  1866. user = curs.fetchall()
  1867. if not user:
  1868. return re_error('/error/2')
  1869. pw_check_d = pw_check(
  1870. flask.request.form.get('pw4', ''),
  1871. user[0][0],
  1872. user[0][1],
  1873. flask.request.form.get('id', None)
  1874. )
  1875. if pw_check_d != 1:
  1876. return re_error('/error/10')
  1877. hashed = pw_encode(flask.request.form.get('pw2', None))
  1878. curs.execute("update user set pw = ? where id = ?", [hashed, flask.session['id']])
  1879. auto_list = ['email', 'skin', 'lang']
  1880. for auto_data in auto_list:
  1881. curs.execute('select data from user_set where name = ? and id = ?', [auto_data, ip])
  1882. if curs.fetchall():
  1883. curs.execute("update user_set set data = ? where name = ? and id = ?", [flask.request.form.get(auto_data, ''), auto_data, ip])
  1884. else:
  1885. curs.execute("insert into user_set (name, id, data) values (?, ?, ?)", [auto_data, ip, flask.request.form.get(auto_data, '')])
  1886. conn.commit()
  1887. return redirect('/change')
  1888. else:
  1889. curs.execute('select data from user_set where name = "email" and id = ?', [ip])
  1890. data = curs.fetchall()
  1891. if data:
  1892. email = data[0][0]
  1893. else:
  1894. email = ''
  1895. div2 = load_skin()
  1896. div3 = ''
  1897. var_div3 = ''
  1898. curs.execute('select data from user_set where name = "lang" and id = ?', [flask.session['id']])
  1899. data = curs.fetchall()
  1900. for lang_data in support_language:
  1901. if data and data[0][0] == lang_data:
  1902. div3 = '<option value="' + lang_data + '">' + lang_data + '</option>'
  1903. else:
  1904. var_div3 += '<option value="' + lang_data + '">' + lang_data + '</option>'
  1905. div3 += var_div3
  1906. oauth_provider = load_oauth('_README')['support']
  1907. oauth_content = '<ul>'
  1908. for i in range(len(oauth_provider)):
  1909. curs.execute('select name, picture from oauth_conn where wiki_id = ? and provider = ?', [flask.session['id'], oauth_provider[i]])
  1910. oauth_data = curs.fetchall()
  1911. if len(oauth_data) == 1:
  1912. oauth_content += '<li>{} - {}</li>'.format(oauth_provider[i], load_lang('connection') + ' : <img src="{}" width="17px" height="17px">{}'.format(oauth_data[0][1], oauth_data[0][0]))
  1913. else:
  1914. oauth_content += '<li>{} - {}</li>'.format(oauth_provider[i], load_lang('connection') + ' : <a href="/oauth/{}/init">{}</a>'.format(oauth_provider[i], load_lang('connect')))
  1915. oauth_content += '</ul>'
  1916. return easy_minify(flask.render_template(skin_check(),
  1917. imp = [load_lang('user_setting'), wiki_set(), custom(), other2([0, 0])],
  1918. data = '''
  1919. <form method="post">
  1920. <span>id : ''' + ip + '''</span>
  1921. <hr class=\"main_hr\">
  1922. <input placeholder="''' + load_lang('now_password') + '''" name="pw4" type="password">
  1923. <hr class=\"main_hr\">
  1924. <input placeholder="''' + load_lang('new_password') + '''" name="pw2" type="password">
  1925. <hr class=\"main_hr\">
  1926. <input placeholder="''' + load_lang('password_confirm') + '''" name="pw3" type="password">
  1927. <hr class=\"main_hr\">
  1928. <span>''' + load_lang('skin') + '''</span>
  1929. <hr class=\"main_hr\">
  1930. <select name="skin">''' + div2 + '''</select>
  1931. <hr class=\"main_hr\">
  1932. <span>''' + load_lang('language') + '''</span>
  1933. <hr class=\"main_hr\">
  1934. <select name="lang">''' + div3 + '''</select>
  1935. <hr class=\"main_hr\">
  1936. <span>''' + load_lang('oauth_connection') + '''</span>
  1937. ''' + oauth_content + '''
  1938. <hr class=\"main_hr\">
  1939. <button type="submit">''' + load_lang('save') + '''</button>
  1940. <hr class=\"main_hr\">
  1941. <span>''' + load_lang('http_warring') + '''</span>
  1942. </form>
  1943. ''',
  1944. menu = [['user', load_lang('return')]]
  1945. ))
  1946. else:
  1947. pass
  1948. @app.route('/check/<name>')
  1949. def user_check(name = None):
  1950. curs.execute("select acl from user where id = ? or id = ?", [name, flask.request.args.get('plus', '-')])
  1951. user = curs.fetchall()
  1952. if user and user[0][0] != 'user':
  1953. if admin_check() != 1:
  1954. return re_error('/error/4')
  1955. if admin_check(4, 'check (' + name + ')') != 1:
  1956. return re_error('/error/3')
  1957. num = int(number_check(flask.request.args.get('num', '1')))
  1958. if num * 50 > 0:
  1959. sql_num = num * 50 - 50
  1960. else:
  1961. sql_num = 0
  1962. if flask.request.args.get('plus', None):
  1963. end_check = 1
  1964. if ip_or_user(name) == 1:
  1965. if ip_or_user(flask.request.args.get('plus', None)) == 1:
  1966. curs.execute("select name, ip, ua, today from ua_d where ip = ? or ip = ? order by today desc limit ?, '50'", [name, flask.request.args.get('plus', None), sql_num])
  1967. else:
  1968. curs.execute("select name, ip, ua, today from ua_d where ip = ? or name = ? order by today desc limit ?, '50'", [name, flask.request.args.get('plus', None), sql_num])
  1969. else:
  1970. if ip_or_user(flask.request.args.get('plus', None)) == 1:
  1971. curs.execute("select name, ip, ua, today from ua_d where name = ? or ip = ? order by today desc limit ?, '50'", [name, flask.request.args.get('plus', None), sql_num])
  1972. else:
  1973. curs.execute("select name, ip, ua, today from ua_d where name = ? or name = ? order by today desc limit ?, '50'", [name, flask.request.args.get('plus', None), sql_num])
  1974. else:
  1975. end_check = 0
  1976. if ip_or_user(name) == 1:
  1977. curs.execute("select name, ip, ua, today from ua_d where ip = ? order by today desc limit ?, '50'", [name, sql_num])
  1978. else:
  1979. curs.execute("select name, ip, ua, today from ua_d where name = ? order by today desc limit ?, '50'", [name, sql_num])
  1980. record = curs.fetchall()
  1981. if record:
  1982. if not flask.request.args.get('plus', None):
  1983. div = '<a href="/manager/14?plus=' + url_pas(name) + '">(' + load_lang('compare') + ')</a><hr class=\"main_hr\">'
  1984. else:
  1985. div = '<a href="/check/' + url_pas(name) + '">(' + name + ')</a> <a href="/check/' + url_pas(flask.request.args.get('plus', None)) + '">(' + flask.request.args.get('plus', None) + ')</a><hr class=\"main_hr\">'
  1986. div += '''
  1987. <table id="main_table_set">
  1988. <tbody>
  1989. <tr>
  1990. <td id="main_table_width">''' + load_lang('name') + '''</td>
  1991. <td id="main_table_width">ip</td>
  1992. <td id="main_table_width">''' + load_lang('time') + '''</td>
  1993. </tr>
  1994. '''
  1995. for data in record:
  1996. if data[2]:
  1997. ua = data[2]
  1998. else:
  1999. ua = '<br>'
  2000. div += '''
  2001. <tr>
  2002. <td>''' + ip_pas(data[0]) + '''</td>
  2003. <td>''' + ip_pas(data[1]) + '''</td>
  2004. <td>''' + data[3] + '''</td>
  2005. </tr>
  2006. <tr>
  2007. <td colspan="3">''' + ua + '''</td>
  2008. </tr>
  2009. '''
  2010. div += '''
  2011. </tbody>
  2012. </table>
  2013. '''
  2014. else:
  2015. return re_error('/error/2')
  2016. if end_check == 1:
  2017. div += next_fix('/check/' + url_pas(name) + '?plus=' + flask.request.args.get('plus', None) + '&num=', num, record)
  2018. else:
  2019. div += next_fix('/check/' + url_pas(name) + '?num=', num, record)
  2020. return easy_minify(flask.render_template(skin_check(),
  2021. imp = [load_lang('check'), wiki_set(), custom(), other2([0, 0])],
  2022. data = div,
  2023. menu = [['manager', load_lang('return')]]
  2024. ))
  2025. @app.route('/register', methods=['POST', 'GET'])
  2026. def register():
  2027. if ban_check() == 1:
  2028. return re_error('/ban')
  2029. if custom()[2] != 0:
  2030. return redirect('/user')
  2031. if not admin_check() == 1:
  2032. curs.execute('select data from other where name = "reg"')
  2033. set_d = curs.fetchall()
  2034. if set_d and set_d[0][0] == 'on':
  2035. return re_error('/ban')
  2036. if flask.request.method == 'POST':
  2037. if captcha_post(flask.request.form.get('g-recaptcha-response', '')) == 1:
  2038. return re_error('/error/13')
  2039. else:
  2040. captcha_post('', 0)
  2041. if flask.request.form.get('pw', None) != flask.request.form.get('pw2', None):
  2042. return re_error('/error/20')
  2043. if re.search('(?:[^A-Za-zㄱ-힣0-9 ])', flask.request.form.get('id', None)):
  2044. return re_error('/error/8')
  2045. curs.execute('select html from html_filter where kind = "name"')
  2046. set_d = curs.fetchall()
  2047. for i in set_d:
  2048. check_r = re.compile(i[0], re.I)
  2049. if check_r.search(flask.request.form.get('id', None)):
  2050. return re_error('/error/8')
  2051. if len(flask.request.form.get('id', None)) > 32:
  2052. return re_error('/error/7')
  2053. curs.execute("select id from user where id = ?", [flask.request.form.get('id', None)])
  2054. if curs.fetchall():
  2055. return re_error('/error/6')
  2056. hashed = pw_encode(flask.request.form.get('pw', None))
  2057. curs.execute('select data from other where name = "email_have"')
  2058. sql_data = curs.fetchall()
  2059. if sql_data and sql_data[0][0] != '':
  2060. flask.session['c_id'] = flask.request.form.get('id', None)
  2061. flask.session['c_pw'] = hashed
  2062. flask.session['c_key'] = ''.join(random.choice("0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ") for i in range(16))
  2063. return redirect('/need_email')
  2064. else:
  2065. curs.execute('select data from other where name = "encode"')
  2066. db_data = curs.fetchall()
  2067. curs.execute("select id from user limit 1")
  2068. if not curs.fetchall():
  2069. curs.execute("insert into user (id, pw, acl, date, encode) values (?, ?, 'owner', ?, ?)", [flask.request.form.get('id', None), hashed, get_time(), db_data[0][0]])
  2070. first = 1
  2071. else:
  2072. curs.execute("insert into user (id, pw, acl, date, encode) values (?, ?, 'user', ?, ?)", [flask.request.form.get('id', None), hashed, get_time(), db_data[0][0]])
  2073. first = 0
  2074. ip = ip_check()
  2075. agent = flask.request.headers.get('User-Agent')
  2076. curs.execute("insert into ua_d (name, ip, ua, today, sub) values (?, ?, ?, ?, '')", [flask.request.form.get('id', None), ip, agent, get_time()])
  2077. flask.session['state'] = 1
  2078. flask.session['id'] = flask.request.form.get('id', None)
  2079. flask.session['head'] = ''
  2080. conn.commit()
  2081. if first == 0:
  2082. return redirect('/change')
  2083. else:
  2084. return redirect('/setting')
  2085. else:
  2086. contract = ''
  2087. curs.execute('select data from other where name = "contract"')
  2088. data = curs.fetchall()
  2089. if data and data[0][0] != '':
  2090. contract = data[0][0] + '<hr class=\"main_hr\">'
  2091. return easy_minify(flask.render_template(skin_check(),
  2092. imp = [load_lang('register'), wiki_set(), custom(), other2([0, 0])],
  2093. data = '''
  2094. <form method="post">
  2095. ''' + contract + '''
  2096. <input placeholder="''' + load_lang('id') + '''" name="id" type="text">
  2097. <hr class=\"main_hr\">
  2098. <input placeholder="''' + load_lang('password') + '''" name="pw" type="password">
  2099. <hr class=\"main_hr\">
  2100. <input placeholder="''' + load_lang('password_confirm') + '''" name="pw2" type="password">
  2101. <hr class=\"main_hr\">
  2102. ''' + captcha_get() + '''
  2103. <button type="submit">''' + load_lang('save') + '''</button>
  2104. <hr class=\"main_hr\">
  2105. <span>''' + load_lang('http_warring') + '''</span>
  2106. </form>
  2107. ''',
  2108. menu = [['user', load_lang('return')]]
  2109. ))
  2110. @app.route('/<regex("need_email|pass_find"):tool>', methods=['POST', 'GET'])
  2111. def need_email(tool = 'pass_find'):
  2112. if flask.request.method == 'POST':
  2113. if tool == 'need_email':
  2114. if 'c_id' in flask.session:
  2115. main_email = ['naver.com', 'gmail.com', 'daum.net', 'hanmail.net', 'hanmail2.net']
  2116. data = re.search('@([^@]+)$', flask.request.form.get('email', ''))
  2117. if data:
  2118. data = data.groups()[0]
  2119. curs.execute("select html from html_filter where html = ? and kind = 'email'", [data])
  2120. if curs.fetchall() or (data in main_email):
  2121. curs.execute('select id from user_set where name = "email" and data = ?', [flask.request.form.get('email', '')])
  2122. if curs.fetchall():
  2123. flask.session.pop('c_id', None)
  2124. flask.session.pop('c_pw', None)
  2125. flask.session.pop('c_key', None)
  2126. return redirect('/register')
  2127. else:
  2128. send_email(flask.request.form.get('email', ''), wiki_set()[0] + ' key', 'key : ' + flask.session['c_key'])
  2129. flask.session['c_email'] = flask.request.form.get('email', '')
  2130. return redirect('/check_key')
  2131. return redirect('/register')
  2132. else:
  2133. curs.execute("select id from user where id = ? and email = ?", [flask.request.form.get('id', ''), flask.request.form.get('email', '')])
  2134. if curs.fetchall():
  2135. flask.session['c_key'] = ''.join(random.choice("0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ") for i in range(16))
  2136. flask.session['c_id'] = flask.request.form.get('id', '')
  2137. send_email(flask.request.form.get('email', ''), wiki_set()[0] + ' ' + load_lang('password_search') + ' key', 'key : ' + flask.session['c_key'])
  2138. return redirect('/check_pass_key')
  2139. else:
  2140. if tool == 'need_email':
  2141. return easy_minify(flask.render_template(skin_check(),
  2142. imp = [load_lang('email'), wiki_set(), custom(), other2([0, 0])],
  2143. data = '''
  2144. <a href="/email_filter">(''' + load_lang('email_filter_list') + ''')</a>
  2145. <hr class=\"main_hr\">
  2146. <form method="post">
  2147. <input placeholder="''' + load_lang('email') + '''" name="email" type="text">
  2148. <hr class=\"main_hr\">
  2149. <button type="submit">''' + load_lang('save') + '''</button>
  2150. </form>
  2151. ''',
  2152. menu = [['user', load_lang('return')]]
  2153. ))
  2154. else:
  2155. return easy_minify(flask.render_template(skin_check(),
  2156. imp = [load_lang('password_search'), wiki_set(), custom(), other2([0, 0])],
  2157. data = '''
  2158. <form method="post">
  2159. <input placeholder="''' + load_lang('id') + '''" name="id" type="text">
  2160. <hr class=\"main_hr\">
  2161. <input placeholder="email" name="email" type="text">
  2162. <hr class=\"main_hr\">
  2163. <button type="submit">''' + load_lang('save') + '''</button>
  2164. </form>
  2165. ''',
  2166. menu = [['user', load_lang('return')]]
  2167. ))
  2168. @app.route('/<regex("check_key|check_pass_key"):tool>', methods=['POST', 'GET'])
  2169. def check_key(tool = 'check_pass_key'):
  2170. if flask.request.method == 'POST':
  2171. if tool == 'check_key':
  2172. if 'c_id' in flask.session and flask.session['c_key'] == flask.request.form.get('key', None):
  2173. curs.execute('select data from other where name = "encode"')
  2174. db_data = curs.fetchall()
  2175. curs.execute("select id from user limit 1")
  2176. if not curs.fetchall():
  2177. curs.execute("insert into user (id, pw, acl, date, encode) values (?, ?, 'owner', ?)", [flask.session['c_id'], flask.session['c_pw'], get_time(), db_data[0][0]])
  2178. first = 1
  2179. else:
  2180. curs.execute("insert into user (id, pw, acl, date, encode) values (?, ?, 'user', ?)", [flask.session['c_id'], flask.session['c_pw'], get_time(), db_data[0][0]])
  2181. first = 0
  2182. ip = ip_check()
  2183. agent = flask.request.headers.get('User-Agent')
  2184. curs.execute("insert into user_set (name, id, data) values ('email', ?, ?)", [flask.session['c_id'], flask.session['c_email']])
  2185. curs.execute("insert into ua_d (name, ip, ua, today, sub) values (?, ?, ?, ?, '')", [flask.session['c_id'], ip, agent, get_time()])
  2186. flask.session['state'] = 1
  2187. flask.session['id'] = flask.session['c_id']
  2188. flask.session['head'] = ''
  2189. conn.commit()
  2190. flask.session.pop('c_id', None)
  2191. flask.session.pop('c_pw', None)
  2192. flask.session.pop('c_key', None)
  2193. flask.session.pop('c_email', None)
  2194. if first == 0:
  2195. return redirect('/change')
  2196. else:
  2197. return redirect('/setting')
  2198. else:
  2199. flask.session.pop('c_id', None)
  2200. flask.session.pop('c_pw', None)
  2201. flask.session.pop('c_key', None)
  2202. flask.session.pop('c_email', None)
  2203. return redirect('/register')
  2204. else:
  2205. if 'c_id' in flask.session and flask.session['c_key'] == flask.request.form.get('key', None):
  2206. hashed = pw_encode(flask.session['c_key'])
  2207. curs.execute("update user set pw = ? where id = ?", [hashed, flask.session['c_id']])
  2208. d_id = flask.session['c_id']
  2209. pw = flask.session['c_key']
  2210. flask.session.pop('c_id', None)
  2211. flask.session.pop('c_key', None)
  2212. return easy_minify(flask.render_template(skin_check(),
  2213. imp = ['check', wiki_set(), custom(), other2([0, 0])],
  2214. data = '''
  2215. ''' + load_lang('id') + ' : ' + d_id + '''
  2216. <br>
  2217. ''' + load_lang('password') + ' : ' + pw + '''
  2218. ''',
  2219. menu = [['user', load_lang('return')]]
  2220. ))
  2221. else:
  2222. return redirect('/pass_find')
  2223. else:
  2224. return easy_minify(flask.render_template(skin_check(),
  2225. imp = ['check', wiki_set(), custom(), other2([0, 0])],
  2226. data = '''
  2227. <form method="post">
  2228. <input placeholder="''' + load_lang('key') + '''" name="key" type="text">
  2229. <hr class=\"main_hr\">
  2230. <button type="submit">''' + load_lang('save') + '''</button>
  2231. </form>
  2232. ''',
  2233. menu = [['user', load_lang('return')]]
  2234. ))
  2235. @app.route('/logout')
  2236. def logout():
  2237. flask.session['state'] = 0
  2238. flask.session.pop('id', None)
  2239. return redirect('/user')
  2240. @app.route('/ban/<name>', methods=['POST', 'GET'])
  2241. def user_ban(name = None):
  2242. if ip_or_user(name) == 0:
  2243. curs.execute("select acl from user where id = ?", [name])
  2244. user = curs.fetchall()
  2245. if not user:
  2246. return re_error('/error/2')
  2247. if user and user[0][0] != 'user':
  2248. if admin_check() != 1:
  2249. return re_error('/error/4')
  2250. if ban_check(ip = ip_check(), tool = 'login') == 1:
  2251. return re_error('/ban')
  2252. if flask.request.method == 'POST':
  2253. if admin_check(1, 'ban (' + name + ')') != 1:
  2254. return re_error('/error/3')
  2255. if flask.request.form.get('limitless', '') == '':
  2256. end = flask.request.form.get('second', '0')
  2257. else:
  2258. end = '0'
  2259. ban_insert(name, end, flask.request.form.get('why', ''), flask.request.form.get('login', ''), ip_check())
  2260. return redirect('/ban/' + url_pas(name))
  2261. else:
  2262. if admin_check(1) != 1:
  2263. return re_error('/error/3')
  2264. curs.execute("select end, why from ban where block = ?", [name])
  2265. end = curs.fetchall()
  2266. if end:
  2267. now = load_lang('release')
  2268. if end[0][0] == '':
  2269. data = '<ul><li>' + load_lang('limitless') + '</li>'
  2270. else:
  2271. data = '<ul><li>' + load_lang('period') + ' : ' + end[0][0] + '</li>'
  2272. curs.execute("select block from ban where block = ? and login = 'O'", [name])
  2273. if curs.fetchall():
  2274. data += '<li>' + load_lang('login_able') + '</li>'
  2275. if end[0][1] != '':
  2276. data += '<li>' + load_lang('why') + ' : ' + end[0][1] + '</li></ul><hr class=\"main_hr\">'
  2277. else:
  2278. data += '</ul><hr class=\"main_hr\">'
  2279. else:
  2280. if re.search("^([0-9]{1,3}\.[0-9]{1,3})$", name):
  2281. now = load_lang('band_ban')
  2282. else:
  2283. now = load_lang('ban')
  2284. if ip_or_user(name) == 1:
  2285. plus = '<input type="checkbox" name="login"> ' + load_lang('login_able') + '<hr class=\"main_hr\">'
  2286. else:
  2287. plus = ''
  2288. data = '''
  2289. <input placeholder="''' + load_lang('second') + '''" name="second" type="text">
  2290. <hr class=\"main_hr\">
  2291. <input type="checkbox" name="limitless"> ''' + load_lang('limitless') + '''
  2292. <hr class=\"main_hr\">
  2293. <input placeholder="''' + load_lang('why') + '''" name="why" type="text">
  2294. <hr class=\"main_hr\">
  2295. ''' + plus
  2296. return easy_minify(flask.render_template(skin_check(),
  2297. imp = [name, wiki_set(), custom(), other2([' (' + now + ')', 0])],
  2298. data = '''
  2299. <form method="post">
  2300. ''' + data + '''
  2301. <button type="submit">''' + now + '''</button>
  2302. </form>
  2303. ''',
  2304. menu = [['manager', load_lang('return')]]
  2305. ))
  2306. @app.route('/acl/<everything:name>', methods=['POST', 'GET'])
  2307. def acl(name = None):
  2308. check_ok = ''
  2309. if flask.request.method == 'POST':
  2310. check_data = 'acl (' + name + ')'
  2311. else:
  2312. check_data = None
  2313. user_data = re.search('^user:(.+)$', name)
  2314. if user_data:
  2315. if check_data and custom()[2] == 0:
  2316. return redirect('/login')
  2317. if user_data.groups()[0] != ip_check():
  2318. if admin_check(5, check_data) != 1:
  2319. if check_data:
  2320. return re_error('/error/3')
  2321. else:
  2322. check_ok = 'disabled'
  2323. else:
  2324. if admin_check(5, check_data) != 1:
  2325. if check_data:
  2326. return re_error('/error/3')
  2327. else:
  2328. check_ok = 'disabled'
  2329. if flask.request.method == 'POST':
  2330. if flask.request.form.get('dec', '') != flask.request.form.get('view', ''):
  2331. dec = flask.request.form.get('view', '')
  2332. view = flask.request.form.get('view', '')
  2333. else:
  2334. dec = flask.request.form.get('dec', '')
  2335. view = flask.request.form.get('view', '')
  2336. curs.execute("select title from acl where title = ?", [name])
  2337. if curs.fetchall():
  2338. curs.execute("update acl set dec = ? where title = ?", [dec, name])
  2339. curs.execute("update acl set dis = ? where title = ?", [flask.request.form.get('dis', ''), name])
  2340. curs.execute("update acl set why = ? where title = ?", [flask.request.form.get('why', ''), name])
  2341. curs.execute("update acl set view = ? where title = ?", [view, name])
  2342. else:
  2343. curs.execute("insert into acl (title, dec, dis, why, view) values (?, ?, ?, ?, ?)", [name, dec, flask.request.form.get('dis', ''), flask.request.form.get('why', ''), view])
  2344. curs.execute("select title from acl where title = ? and dec = '' and dis = ''", [name])
  2345. if curs.fetchall():
  2346. curs.execute("delete from acl where title = ?", [name])
  2347. conn.commit()
  2348. return redirect('/acl/' + url_pas(name))
  2349. else:
  2350. data = '' + load_lang('document_acl') + '<br><br><select name="dec" ' + check_ok + '>'
  2351. if re.search('^user:', name):
  2352. acl_list = [['', load_lang('normal')], ['user', load_lang('member')], ['all', load_lang('all')]]
  2353. else:
  2354. acl_list = [['', load_lang('normal')], ['user', load_lang('member')], ['admin', load_lang('admin')]]
  2355. curs.execute("select dec from acl where title = ?", [name])
  2356. acl_data = curs.fetchall()
  2357. for data_list in acl_list:
  2358. if acl_data and acl_data[0][0] == data_list[0]:
  2359. check = 'selected="selected"'
  2360. else:
  2361. check = ''
  2362. data += '<option value="' + data_list[0] + '" ' + check + '>' + data_list[1] + '</option>'
  2363. data += '</select>'
  2364. if not re.search('^user:', name):
  2365. data += '<hr class=\"main_hr\">' + load_lang('discussion_acl') + '<br><br><select name="dis" ' + check_ok + '>'
  2366. curs.execute("select dis, why, view from acl where title = ?", [name])
  2367. acl_data = curs.fetchall()
  2368. for data_list in acl_list:
  2369. if acl_data and acl_data[0][0] == data_list[0]:
  2370. check = 'selected="selected"'
  2371. else:
  2372. check = ''
  2373. data += '<option value="' + data_list[0] + '" ' + check + '>' + data_list[1] + '</option>'
  2374. data += '</select>'
  2375. data += '<hr class=\"main_hr\">' + load_lang('view_acl') + '<br><br><select name="view" ' + check_ok + '>'
  2376. for data_list in acl_list:
  2377. if acl_data and acl_data[0][2] == data_list[0]:
  2378. check = 'selected="selected"'
  2379. else:
  2380. check = ''
  2381. data += '<option value="' + data_list[0] + '" ' + check + '>' + data_list[1] + '</option>'
  2382. data += '</select>'
  2383. if check_ok == '':
  2384. if acl_data:
  2385. data += '<hr class=\"main_hr\"><input value="' + html.escape(acl_data[0][1]) + '" placeholder="' + load_lang('why') + '" name="why" type="text" ' + check_ok + '>'
  2386. else:
  2387. data += '<hr class=\"main_hr\"><input placeholder="' + load_lang('why') + '" name="why" type="text" ' + check_ok + '>'
  2388. return easy_minify(flask.render_template(skin_check(),
  2389. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('acl') + ')', 0])],
  2390. data = '''
  2391. <form method="post">
  2392. ''' + data + '''
  2393. <hr class=\"main_hr\">
  2394. <button type="submit" ''' + check_ok + '''>''' + load_lang('save') + '''</button>
  2395. </form>
  2396. ''',
  2397. menu = [['w/' + url_pas(name), load_lang('document')], ['manager', load_lang('admin')]]
  2398. ))
  2399. @app.route('/admin/<name>', methods=['POST', 'GET'])
  2400. def user_admin(name = None):
  2401. owner = admin_check()
  2402. curs.execute("select acl from user where id = ?", [name])
  2403. user = curs.fetchall()
  2404. if not user:
  2405. return re_error('/error/2')
  2406. else:
  2407. if owner != 1:
  2408. curs.execute('select name from alist where name = ? and acl = "owner"', [user[0][0]])
  2409. if curs.fetchall():
  2410. return re_error('/error/3')
  2411. if ip_check() == name:
  2412. return re_error('/error/3')
  2413. if flask.request.method == 'POST':
  2414. if admin_check(7, 'admin (' + name + ')') != 1:
  2415. return re_error('/error/3')
  2416. if owner != 1:
  2417. curs.execute('select name from alist where name = ? and acl = "owner"', [flask.request.form.get('select', None)])
  2418. if curs.fetchall():
  2419. return re_error('/error/3')
  2420. if flask.request.form.get('select', None) == 'X':
  2421. curs.execute("update user set acl = 'user' where id = ?", [name])
  2422. else:
  2423. curs.execute("update user set acl = ? where id = ?", [flask.request.form.get('select', None), name])
  2424. conn.commit()
  2425. return redirect('/admin/' + url_pas(name))
  2426. else:
  2427. if admin_check(7) != 1:
  2428. return re_error('/error/3')
  2429. div = '<option value="X">X</option>'
  2430. curs.execute('select distinct name from alist order by name asc')
  2431. for data in curs.fetchall():
  2432. if user[0][0] == data[0]:
  2433. div += '<option value="' + data[0] + '" selected="selected">' + data[0] + '</option>'
  2434. else:
  2435. if owner != 1:
  2436. curs.execute('select name from alist where name = ? and acl = "owner"', [data[0]])
  2437. if not curs.fetchall():
  2438. div += '<option value="' + data[0] + '">' + data[0] + '</option>'
  2439. else:
  2440. div += '<option value="' + data[0] + '">' + data[0] + '</option>'
  2441. return easy_minify(flask.render_template(skin_check(),
  2442. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('authorize') + ')', 0])],
  2443. data = '''
  2444. <form method="post">
  2445. <select name="select">''' + div + '''</select>
  2446. <hr class=\"main_hr\">
  2447. <button type="submit">''' + load_lang('save') + '''</button>
  2448. </form>
  2449. ''',
  2450. menu = [['manager', load_lang('return')]]
  2451. ))
  2452. @app.route('/diff/<everything:name>')
  2453. def diff_data(name = None):
  2454. first = flask.request.args.get('first', '1')
  2455. second = flask.request.args.get('second', '1')
  2456. curs.execute("select data from history where id = ? and title = ?", [first, name])
  2457. first_raw_data = curs.fetchall()
  2458. if first_raw_data:
  2459. curs.execute("select data from history where id = ? and title = ?", [second, name])
  2460. second_raw_data = curs.fetchall()
  2461. if second_raw_data:
  2462. first_data = html.escape(first_raw_data[0][0])
  2463. second_data = html.escape(second_raw_data[0][0])
  2464. if first == second:
  2465. result = '-'
  2466. else:
  2467. diff_data = difflib.SequenceMatcher(None, first_data, second_data)
  2468. result = re.sub('\r', '', diff(diff_data))
  2469. return easy_minify(flask.render_template(skin_check(),
  2470. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('compare') + ')', 0])],
  2471. data = '<pre>' + result + '</pre>',
  2472. menu = [['history/' + url_pas(name), load_lang('return')]]
  2473. ))
  2474. return redirect('/history/' + url_pas(name))
  2475. @app.route('/down/<everything:name>')
  2476. def down(name = None):
  2477. div = '<ul>'
  2478. curs.execute("select title from data where title like ?", ['%' + name + '/%'])
  2479. for data in curs.fetchall():
  2480. div += '<li><a href="/w/' + url_pas(data[0]) + '">' + data[0] + '</a></li>'
  2481. div += '</ul>'
  2482. return easy_minify(flask.render_template(skin_check(),
  2483. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('sub') + ')', 0])],
  2484. data = div,
  2485. menu = [['w/' + url_pas(name), load_lang('return')]]
  2486. ))
  2487. @app.route('/w/<everything:name>')
  2488. def read_view(name = None):
  2489. return read_view_2(conn, name)
  2490. @app.route('/topic_record/<name>')
  2491. def user_topic_list(name = None):
  2492. num = int(number_check(flask.request.args.get('num', '1')))
  2493. if num * 50 > 0:
  2494. sql_num = num * 50 - 50
  2495. else:
  2496. sql_num = 0
  2497. one_admin = admin_check(1)
  2498. div = '''
  2499. <table id="main_table_set">
  2500. <tbody>
  2501. <tr>
  2502. <td id="main_table_width">''' + load_lang('discussion_name') + '''</td>
  2503. <td id="main_table_width">''' + load_lang('writer') + '''</td>
  2504. <td id="main_table_width">''' + load_lang('time') + '''</td>
  2505. </tr>
  2506. '''
  2507. curs.execute("select title, id, sub, ip, date from topic where ip = ? order by date desc limit ?, '50'", [name, str(sql_num)])
  2508. data_list = curs.fetchall()
  2509. for data in data_list:
  2510. title = html.escape(data[0])
  2511. sub = html.escape(data[2])
  2512. if one_admin == 1:
  2513. curs.execute("select * from ban where block = ?", [data[3]])
  2514. if curs.fetchall():
  2515. ban = ' <a href="/ban/' + url_pas(data[3]) + '">(' + load_lang('release') + ')</a>'
  2516. else:
  2517. ban = ' <a href="/ban/' + url_pas(data[3]) + '">(' + load_lang('ban') + ')</a>'
  2518. else:
  2519. ban = ''
  2520. div += '<tr><td><a href="/topic/' + url_pas(data[0]) + '/sub/' + url_pas(data[2]) + '#' + data[1] + '">' + title + '#' + data[1] + '</a> (' + sub + ')</td>'
  2521. div += '<td>' + ip_pas(data[3]) + ban + '</td><td>' + data[4] + '</td></tr>'
  2522. div += '</tbody></table>'
  2523. div += next_fix('/topic_record/' + url_pas(name) + '?num=', num, data_list)
  2524. curs.execute("select end from ban where block = ?", [name])
  2525. if curs.fetchall():
  2526. sub = ' (' + load_lang('blocked') + ')'
  2527. else:
  2528. sub = 0
  2529. return easy_minify(flask.render_template(skin_check(),
  2530. imp = [load_lang('discussion_record'), wiki_set(), custom(), other2([sub, 0])],
  2531. data = div,
  2532. menu = [['other', load_lang('other')], ['user', load_lang('user')], ['count/' + url_pas(name), load_lang('count')], ['record/' + url_pas(name), load_lang('record')]]
  2533. ))
  2534. @app.route('/recent_changes')
  2535. @app.route('/<regex("record"):tool>/<name>')
  2536. @app.route('/<regex("history"):tool>/<everything:name>', methods=['POST', 'GET'])
  2537. def recent_changes(name = None, tool = 'record'):
  2538. if flask.request.method == 'POST':
  2539. return redirect('/diff/' + url_pas(name) + '?first=' + flask.request.form.get('b', None) + '&second=' + flask.request.form.get('a', None))
  2540. else:
  2541. one_admin = admin_check(1)
  2542. six_admin = admin_check(6)
  2543. ban = ''
  2544. select = ''
  2545. div = '''
  2546. <table id="main_table_set">
  2547. <tbody>
  2548. <tr>
  2549. '''
  2550. if name:
  2551. num = int(number_check(flask.request.args.get('num', '1')))
  2552. if num * 50 > 0:
  2553. sql_num = num * 50 - 50
  2554. else:
  2555. sql_num = 0
  2556. if tool == 'history':
  2557. div += '''
  2558. <td id="main_table_width">''' + load_lang('version') + '''</td>
  2559. <td id="main_table_width">''' + load_lang('editor') + '''</td>
  2560. <td id="main_table_width">''' + load_lang('time') + '''</td></tr>
  2561. '''
  2562. curs.execute("select id, title, date, ip, send, leng from history where title = ? order by id + 0 desc limit ?, '50'", [name, str(sql_num)])
  2563. else:
  2564. div += '''
  2565. <td id="main_table_width">''' + load_lang('document_name') + '''</td>
  2566. <td id="main_table_width">''' + load_lang('editor') + '''</td>
  2567. <td id="main_table_width">''' + load_lang('time') + '''</td>
  2568. </tr>
  2569. '''
  2570. div = '<a href="/topic_record/' + url_pas(name) + '">(' + load_lang('discussion') + ')</a><hr class=\"main_hr\">' + div
  2571. curs.execute("select id, title, date, ip, send, leng from history where ip = ? order by date desc limit ?, '50'", [name, str(sql_num)])
  2572. else:
  2573. num = int(number_check(flask.request.args.get('num', '1')))
  2574. if num * 50 > 0:
  2575. sql_num = num * 50 - 50
  2576. else:
  2577. sql_num = 0
  2578. div += '''
  2579. <td id="main_table_width">''' + load_lang('document_name') + '''</td>
  2580. <td id="main_table_width">''' + load_lang('editor') + '''</td>
  2581. <td id="main_table_width">''' + load_lang('time') + '''</td>
  2582. </tr>
  2583. '''
  2584. curs.execute("select id, title, date, ip, send, leng from history where not title like 'user:%' order by date desc limit ?, 50", [str(sql_num)])
  2585. data_list = curs.fetchall()
  2586. for data in data_list:
  2587. select += '<option value="' + data[0] + '">' + data[0] + '</option>'
  2588. send = '<br>'
  2589. if data[4]:
  2590. if not re.search("^(?: *)$", data[4]):
  2591. send = data[4]
  2592. if re.search("\+", data[5]):
  2593. leng = '<span style="color:green;">(' + data[5] + ')</span>'
  2594. elif re.search("\-", data[5]):
  2595. leng = '<span style="color:red;">(' + data[5] + ')</span>'
  2596. else:
  2597. leng = '<span style="color:gray;">(' + data[5] + ')</span>'
  2598. ip = ip_pas(data[3])
  2599. if int(data[0]) - 1 == 0:
  2600. revert = ''
  2601. else:
  2602. revert = '<a href="/diff/' + url_pas(data[1]) + '?first=' + str(int(data[0]) - 1) + '&second=' + data[0] + '">(' + load_lang('compare') + ')</a> <a href="/revert/' + url_pas(data[1]) + '?num=' + str(int(data[0]) - 1) + '">(' + load_lang('revert') + ')</a>'
  2603. style = ['', '']
  2604. date = data[2]
  2605. curs.execute("select title from history where title = ? and id = ? and hide = 'O'", [data[1], data[0]])
  2606. hide = curs.fetchall()
  2607. if six_admin == 1:
  2608. if hide:
  2609. hidden = ' <a href="/hidden/' + url_pas(data[1]) + '?num=' + data[0] + '">(' + load_lang('hide_release') + ')'
  2610. style[0] = 'id="toron_color_grey"'
  2611. style[1] = 'id="toron_color_grey"'
  2612. if send == '<br>':
  2613. send = '(' + load_lang('hide') + ')'
  2614. else:
  2615. send += ' (' + load_lang('hide') + ')'
  2616. else:
  2617. hidden = ' <a href="/hidden/' + url_pas(data[1]) + '?num=' + data[0] + '">(' + load_lang('hide') + ')'
  2618. elif not hide:
  2619. hidden = ''
  2620. else:
  2621. ip = ''
  2622. hidden = ''
  2623. ban = ''
  2624. date = ''
  2625. send = '(' + load_lang('hide') + ')'
  2626. style[0] = 'style="display: none;"'
  2627. style[1] = 'id="toron_color_grey"'
  2628. if tool == 'history':
  2629. title = '<a href="/w/' + url_pas(name) + '?num=' + data[0] + '">r' + data[0] + '</a> <a href="/raw/' + url_pas(name) + '?num=' + data[0] + '">(' + load_lang('raw') + ')</a> '
  2630. else:
  2631. title = '<a href="/w/' + url_pas(data[1]) + '">' + html.escape(data[1]) + '</a> <a href="/history/' + url_pas(data[1]) + '">(r' + data[0] + ')</a> '
  2632. div += '''
  2633. <tr ''' + style[0] + '''>
  2634. <td>''' + title + revert + ' ' + leng + '''</td>
  2635. <td>''' + ip + ban + hidden + '''</td>
  2636. <td>''' + date + '''</td>
  2637. </tr>
  2638. <tr ''' + style[1] + '''>
  2639. <td colspan="3">''' + send_parser(send) + '''</td>
  2640. </tr>
  2641. '''
  2642. div += '''
  2643. </tbody>
  2644. </table>
  2645. '''
  2646. sub = ''
  2647. if name:
  2648. if tool == 'history':
  2649. div = '''
  2650. <form method="post">
  2651. <select name="a">''' + select + '''</select> <select name="b">''' + select + '''</select>
  2652. <button type="submit">''' + load_lang('compare') + '''</button>
  2653. </form>
  2654. <hr class=\"main_hr\">
  2655. ''' + div
  2656. title = name
  2657. sub += ' (' + load_lang('history') + ')'
  2658. menu = [['w/' + url_pas(name), load_lang('document')], ['raw/' + url_pas(name), 'raw']]
  2659. div += next_fix('/history/' + url_pas(name) + '?num=', num, data_list)
  2660. else:
  2661. curs.execute("select end from ban where block = ?", [name])
  2662. if curs.fetchall():
  2663. sub += ' (' + load_lang('blocked') + ')'
  2664. title = load_lang('edit_record')
  2665. menu = [['other', load_lang('other')], ['user', load_lang('user')], ['count/' + url_pas(name), load_lang('count')]]
  2666. div += next_fix('/record/' + url_pas(name) + '?num=', num, data_list)
  2667. else:
  2668. menu = 0
  2669. title = load_lang('recent_change')
  2670. div += next_fix('/recent_changes?num=', num, data_list)
  2671. if sub == '':
  2672. sub = 0
  2673. return easy_minify(flask.render_template(skin_check(),
  2674. imp = [title, wiki_set(), custom(), other2([sub, 0])],
  2675. data = div,
  2676. menu = menu
  2677. ))
  2678. @app.route('/upload', methods=['GET', 'POST'])
  2679. def upload():
  2680. if ban_check() == 1:
  2681. return re_error('/ban')
  2682. if flask.request.method == 'POST':
  2683. if captcha_post(flask.request.form.get('g-recaptcha-response', '')) == 1:
  2684. return re_error('/error/13')
  2685. else:
  2686. captcha_post('', 0)
  2687. data = flask.request.files.get('f_data', None)
  2688. if not data:
  2689. return re_error('/error/9')
  2690. if int(wiki_set(3)) * 1024 * 1024 < flask.request.content_length:
  2691. return re_error('/error/17')
  2692. value = os.path.splitext(data.filename)[1]
  2693. if not value in ['.jpeg', '.jpg', '.gif', '.png', '.webp', '.JPEG', '.JPG', '.GIF', '.PNG', '.WEBP']:
  2694. return re_error('/error/14')
  2695. if flask.request.form.get('f_name', None):
  2696. name = flask.request.form.get('f_name', None) + value
  2697. else:
  2698. name = data.filename
  2699. piece = os.path.splitext(name)
  2700. if re.search('[^ㄱ-힣0-9a-zA-Z_\- ]', piece[0]):
  2701. return re_error('/error/22')
  2702. e_data = sha224(piece[0]) + piece[1]
  2703. curs.execute("select title from data where title = ?", ['file:' + name])
  2704. if curs.fetchall():
  2705. return re_error('/error/16')
  2706. ip = ip_check()
  2707. if flask.request.form.get('f_lice', None):
  2708. lice = flask.request.form.get('f_lice', None)
  2709. else:
  2710. if custom()[2] == 0:
  2711. lice = ip
  2712. else:
  2713. lice = '[[user:' + ip + ']]'
  2714. if os.path.exists(os.path.join(APPVAR['PATH_DATA_IMAGES'], e_data)):
  2715. os.remove(os.path.join(APPVAR['PATH_DATA_IMAGES'], e_data))
  2716. data.save(os.path.join(APPVAR['PATH_DATA_IMAGES'], e_data))
  2717. else:
  2718. data.save(os.path.join(APPVAR['PATH_DATA_IMAGES'], e_data))
  2719. curs.execute("select title from data where title = ?", ['file:' + name])
  2720. if curs.fetchall():
  2721. curs.execute("delete from data where title = ?", ['file:' + name])
  2722. curs.execute("insert into data (title, data) values (?, ?)", ['file:' + name, '[[file:' + name + ']][br][br]{{{[[file:' + name + ']]}}}[br][br]' + lice])
  2723. curs.execute("insert into acl (title, dec, dis, why, view) values (?, 'admin', '', '', '')", ['file:' + name])
  2724. history_plus(
  2725. 'file:' + name, '[[file:' + name + ']][br][br]{{{[[file:' + name + ']]}}}[br][br]' + lice,
  2726. get_time(),
  2727. ip,
  2728. '(upload)',
  2729. '0'
  2730. )
  2731. conn.commit()
  2732. return redirect('/w/file:' + name)
  2733. else:
  2734. return easy_minify(flask.render_template(skin_check(),
  2735. imp = [load_lang('upload'), wiki_set(), custom(), other2([0, 0])],
  2736. data = '''
  2737. <form method="post" enctype="multipart/form-data" accept-charset="utf8">
  2738. <input type="file" name="f_data">
  2739. <hr class=\"main_hr\">
  2740. <input placeholder="''' + load_lang('name') + '''" name="f_name" type="text">
  2741. <hr class=\"main_hr\">
  2742. <input placeholder="''' + load_lang('license') + '''" name="f_lice" type="text">
  2743. <hr class=\"main_hr\">
  2744. ''' + captcha_get() + '''
  2745. <button id="save" type="submit">''' + load_lang('save') + '''</button>
  2746. </form>
  2747. ''',
  2748. menu = [['other', load_lang('return')]]
  2749. ))
  2750. @app.route('/user')
  2751. def user_info():
  2752. ip = ip_check()
  2753. curs.execute("select acl from user where id = ?", [ip])
  2754. data = curs.fetchall()
  2755. if ban_check() == 0:
  2756. if data:
  2757. if data[0][0] != 'user':
  2758. acl = data[0][0]
  2759. else:
  2760. acl = load_lang('member')
  2761. else:
  2762. acl = load_lang('normal')
  2763. else:
  2764. acl = load_lang('blocked')
  2765. match = re.search("^([0-9]{1,3}\.[0-9]{1,3})", ip)
  2766. if match:
  2767. match = match.groups()[0]
  2768. else:
  2769. match = '-'
  2770. curs.execute("select end, login, band from ban where block = ? or block = ?", [ip, match])
  2771. block_data = curs.fetchall()
  2772. if block_data:
  2773. if block_data[0][0] != '':
  2774. acl += ' (' + load_lang('period') + ' : ' + block_data[0][0] + ')'
  2775. else:
  2776. acl += ' (' + load_lang('limitless') + ')'
  2777. if block_data[0][1] != '':
  2778. acl += ' (' + load_lang('login_able') + ')'
  2779. if block_data[0][2] == 'O':
  2780. acl += ' (' + load_lang('band_blocked') + ')'
  2781. if custom()[2] != 0:
  2782. ip_user = '<a href="/w/user:' + ip + '">' + ip + '</a>'
  2783. plus = '''
  2784. <li><a href="/logout">''' + load_lang('logout') + '''</a></li>
  2785. <li><a href="/change">''' + load_lang('user_setting') + '''</a></li>
  2786. '''
  2787. curs.execute('select name from alarm where name = ? limit 1', [ip_check()])
  2788. if curs.fetchall():
  2789. plus2 = '<li><a href="/alarm">' + load_lang('alarm') + ' (O)</a></li>'
  2790. else:
  2791. plus2 = '<li><a href="/alarm">' + load_lang('alarm') + '</a></li>'
  2792. plus2 += '<li><a href="/watch_list">' + load_lang('watchlist') + '</a></li>'
  2793. plus3 = '<li><a href="/acl/user:' + url_pas(ip) + '">' + load_lang('user_document_acl') + '</a></li>'
  2794. else:
  2795. ip_user = ip
  2796. plus = '''
  2797. <li><a href="/login">''' + load_lang('login') + '''</a></li>
  2798. <li><a href="/register">''' + load_lang('register') + '''</a></li>
  2799. '''
  2800. plus2 = ''
  2801. plus3 = ''
  2802. curs.execute("select data from other where name = 'email_have'")
  2803. test = curs.fetchall()
  2804. if test and test[0][0] != '':
  2805. plus += '<li><a href="/pass_find">' + load_lang('password_search') + '</a></li>'
  2806. return easy_minify(flask.render_template(skin_check(),
  2807. imp = [load_lang('user') + ' ' + load_lang('tool'), wiki_set(), custom(), other2([0, 0])],
  2808. data = '''
  2809. <h2>''' + load_lang('state') + '''</h2>
  2810. <ul>
  2811. <li>''' + ip_user + ''' <a href="/record/''' + url_pas(ip) + '''">(''' + load_lang('record') + ''')</a></li>
  2812. <li>''' + load_lang('state') + ''' : ''' + acl + '''</li>
  2813. </ul>
  2814. <br>
  2815. <h2>''' + load_lang('login') + '''</h2>
  2816. <ul>
  2817. ''' + plus + '''
  2818. </ul>
  2819. <br>
  2820. <h2>''' + load_lang('tool') + '''</h2>
  2821. <ul>
  2822. ''' + plus3 + '''
  2823. <li><a href="/custom_head">''' + load_lang('user_head') + '''</a></li>
  2824. </ul>
  2825. <br>
  2826. <h2>''' + load_lang('other') + '''</h2>
  2827. <ul>
  2828. ''' + plus2 + '''
  2829. <li>
  2830. <a href="/count">''' + load_lang('count') + '''</a>
  2831. </li>
  2832. </ul>
  2833. ''',
  2834. menu = 0
  2835. ))
  2836. @app.route('/watch_list')
  2837. def watch_list():
  2838. div = 'limit : 10<hr class=\"main_hr\">'
  2839. if custom()[2] == 0:
  2840. return redirect('/login')
  2841. curs.execute("select title from scan where user = ?", [ip_check()])
  2842. data = curs.fetchall()
  2843. for data_list in data:
  2844. div += '<li><a href="/w/' + url_pas(data_list[0]) + '">' + data_list[0] + '</a> <a href="/watch_list/' + url_pas(data_list[0]) + '">(' + load_lang('delete') + ')</a></li>'
  2845. if data:
  2846. div = '<ul>' + div + '</ul><hr class=\"main_hr\">'
  2847. div += '<a href="/manager/13">(' + load_lang('add') + ')</a>'
  2848. return easy_minify(flask.render_template(skin_check(),
  2849. imp = [load_lang('watchlist'), wiki_set(), custom(), other2([0, 0])],
  2850. data = div,
  2851. menu = [['manager', load_lang('return')]]
  2852. ))
  2853. @app.route('/watch_list/<everything:name>')
  2854. def watch_list_name(name = None):
  2855. if custom()[2] == 0:
  2856. return redirect('/login')
  2857. ip = ip_check()
  2858. curs.execute("select count(title) from scan where user = ?", [ip])
  2859. count = curs.fetchall()
  2860. if count and count[0][0] > 9:
  2861. return redirect('/watch_list')
  2862. curs.execute("select title from scan where user = ? and title = ?", [ip, name])
  2863. if curs.fetchall():
  2864. curs.execute("delete from scan where user = ? and title = ?", [ip, name])
  2865. else:
  2866. curs.execute("insert into scan (user, title) values (?, ?)", [ip, name])
  2867. conn.commit()
  2868. return redirect('/watch_list')
  2869. @app.route('/custom_head', methods=['GET', 'POST'])
  2870. def custom_head_view():
  2871. ip = ip_check()
  2872. if flask.request.method == 'POST':
  2873. if custom()[2] != 0:
  2874. curs.execute("select user from custom where user = ?", [ip + ' (head)'])
  2875. if curs.fetchall():
  2876. curs.execute("update custom set css = ? where user = ?", [flask.request.form.get('content', None), ip + ' (head)'])
  2877. else:
  2878. curs.execute("insert into custom (user, css) values (?, ?)", [ip + ' (head)', flask.request.form.get('content', None)])
  2879. conn.commit()
  2880. flask.session['head'] = flask.request.form.get('content', None)
  2881. return redirect('/user')
  2882. else:
  2883. if custom()[2] != 0:
  2884. start = ''
  2885. curs.execute("select css from custom where user = ?", [ip + ' (head)'])
  2886. head_data = curs.fetchall()
  2887. if head_data:
  2888. data = head_data[0][0]
  2889. else:
  2890. data = ''
  2891. else:
  2892. start = '<span>' + load_lang('user_head_warring') + '</span><hr class=\"main_hr\">'
  2893. if 'head' in flask.session:
  2894. data = flask.session['head']
  2895. else:
  2896. data = ''
  2897. start += '<span>&lt;style&gt;css&lt;/style&gt;<br>&lt;script&gt;js&lt;/script&gt;</span><hr class=\"main_hr\">'
  2898. return easy_minify(flask.render_template(skin_check(),
  2899. imp = [load_lang(data = 'user_head', safe = 1), wiki_set(), custom(), other2([0, 0])],
  2900. data = start + '''
  2901. <form method="post">
  2902. <textarea rows="25" cols="100" name="content">''' + data + '''</textarea>
  2903. <hr class=\"main_hr\">
  2904. <button id="save" type="submit">''' + load_lang('save') + '''</button>
  2905. </form>
  2906. ''',
  2907. menu = [['user', load_lang('return')]]
  2908. ))
  2909. @app.route('/count')
  2910. @app.route('/count/<name>')
  2911. def count_edit(name = None):
  2912. if name == None:
  2913. that = ip_check()
  2914. else:
  2915. that = name
  2916. curs.execute("select count(title) from history where ip = ?", [that])
  2917. count = curs.fetchall()
  2918. if count:
  2919. data = count[0][0]
  2920. else:
  2921. data = 0
  2922. curs.execute("select count(title) from topic where ip = ?", [that])
  2923. count = curs.fetchall()
  2924. if count:
  2925. t_data = count[0][0]
  2926. else:
  2927. t_data = 0
  2928. return easy_minify(flask.render_template(skin_check(),
  2929. imp = [load_lang('count'), wiki_set(), custom(), other2([0, 0])],
  2930. data = '''
  2931. <ul>
  2932. <li><a href="/record/''' + url_pas(that) + '''">''' + load_lang('edit_record') + '''</a> : ''' + str(data) + '''</li>
  2933. <li><a href="/topic_record/''' + url_pas(that) + '''">''' + load_lang('discussion_record') + '''</a> : ''' + str(t_data) + '''</a></li>
  2934. </ul>
  2935. ''',
  2936. menu = [['user', load_lang('return')]]
  2937. ))
  2938. @app.route('/random')
  2939. def title_random():
  2940. curs.execute("select title from data order by random() limit 1")
  2941. data = curs.fetchall()
  2942. if data:
  2943. return redirect('/w/' + url_pas(data[0][0]))
  2944. else:
  2945. return redirect()
  2946. @app.route('/skin_set')
  2947. def skin_set():
  2948. return re_error('/error/5')
  2949. @app.route('/api/w/<everything:name>')
  2950. def api_w(name = ''):
  2951. curs.execute("select data from data where title = ?", [name])
  2952. data = curs.fetchall()
  2953. if data:
  2954. json_data = { "title" : name, "data" : render_set(title = name, data = data[0][0]) }
  2955. return flask.jsonify(json_data)
  2956. else:
  2957. return flask.jsonify({})
  2958. @app.route('/api/raw/<everything:name>')
  2959. def api_raw(name = ''):
  2960. curs.execute("select data from data where title = ?", [name])
  2961. data = curs.fetchall()
  2962. if data:
  2963. json_data = { "title" : name, "data" : render_set(title = name, data = data[0][0], s_data = 1) }
  2964. return flask.jsonify(json_data)
  2965. else:
  2966. return flask.jsonify({})
  2967. @app.route('/api/topic/<everything:name>/sub/<sub>')
  2968. def api_topic_sub(name = '', sub = '', time = ''):
  2969. if flask.request.args.get('time', None):
  2970. curs.execute("select id, data, ip from topic where title = ? and sub = ? and date >= ? order by id + 0 asc", [name, sub, flask.request.args.get('time', None)])
  2971. else:
  2972. curs.execute("select id, data, ip from topic where title = ? and sub = ? order by id + 0 asc", [name, sub])
  2973. data = curs.fetchall()
  2974. if data:
  2975. json_data = {}
  2976. for i in data:
  2977. json_data[i[0]] = {
  2978. "data" : i[1],
  2979. "id" : i[2]
  2980. }
  2981. return flask.jsonify(json_data)
  2982. else:
  2983. return flask.jsonify({})
  2984. @app.route('/views/<everything:name>')
  2985. def views(name = None):
  2986. if re.search('\/', name):
  2987. m = re.search('^(.*)\/(.*)$', name)
  2988. if m:
  2989. n = m.groups()
  2990. plus = '/' + n[0]
  2991. rename = n[1]
  2992. else:
  2993. plus = ''
  2994. rename = name
  2995. else:
  2996. plus = ''
  2997. rename = name
  2998. m = re.search('\.(.+)$', name)
  2999. if m:
  3000. g = m.groups()
  3001. else:
  3002. g = ['']
  3003. if g == 'css':
  3004. return easy_minify(flask.send_from_directory('./views' + plus, rename), 'css')
  3005. elif g == 'js':
  3006. return easy_minify(flask.send_from_directory('./views' + plus, rename), 'js')
  3007. elif g == 'html':
  3008. return easy_minify(flask.send_from_directory('./views' + plus, rename))
  3009. else:
  3010. return flask.send_from_directory('./views' + plus, rename)
  3011. @app.route('/<data>')
  3012. def main_file(data = None):
  3013. if re.search('\.txt$', data):
  3014. return flask.send_from_directory('./', data)
  3015. else:
  3016. return redirect('/w/' + url_pas(wiki_set(2)))
  3017. @app.errorhandler(404)
  3018. def error_404(e):
  3019. return redirect('/w/' + url_pas(wiki_set(2)))
  3020. if __name__=="__main__":
  3021. app.secret_key = rep_key
  3022. http_server = tornado.httpserver.HTTPServer(tornado.wsgi.WSGIContainer(app))
  3023. http_server.listen(server_set['port'], address=server_set['host'])
  3024. tornado.ioloop.IOLoop.instance().start()