app.py 173 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658365936603661366236633664366536663667366836693670367136723673367436753676367736783679368036813682368336843685368636873688368936903691369236933694369536963697369836993700370137023703370437053706370737083709371037113712371337143715371637173718371937203721372237233724372537263727372837293730373137323733373437353736373737383739374037413742374337443745374637473748374937503751375237533754375537563757375837593760376137623763376437653766376737683769377037713772377337743775377637773778377937803781378237833784378537863787378837893790379137923793379437953796379737983799380038013802380338043805380638073808380938103811381238133814381538163817381838193820382138223823382438253826382738283829383038313832383338343835383638373838383938403841384238433844384538463847384838493850385138523853385438553856385738583859386038613862386338643865386638673868386938703871387238733874387538763877387838793880388138823883388438853886388738883889389038913892389338943895389638973898389939003901390239033904390539063907390839093910391139123913391439153916391739183919392039213922392339243925392639273928392939303931393239333934393539363937393839393940394139423943394439453946394739483949395039513952395339543955395639573958395939603961396239633964396539663967396839693970397139723973397439753976397739783979398039813982398339843985398639873988398939903991399239933994399539963997399839994000400140024003400440054006400740084009401040114012401340144015401640174018401940204021402240234024402540264027402840294030403140324033403440354036403740384039404040414042404340444045404640474048404940504051405240534054405540564057405840594060406140624063406440654066406740684069407040714072407340744075407640774078407940804081408240834084408540864087408840894090409140924093409440954096409740984099410041014102410341044105410641074108410941104111411241134114411541164117411841194120412141224123412441254126412741284129413041314132413341344135413641374138413941404141414241434144414541464147414841494150415141524153415441554156415741584159416041614162416341644165416641674168416941704171417241734174417541764177417841794180418141824183418441854186418741884189419041914192419341944195
  1. import werkzeug.routing
  2. import flask_compress
  3. import flask_reggie
  4. import tornado.ioloop
  5. import tornado.httpserver
  6. import tornado.wsgi
  7. import urllib.request
  8. import platform
  9. import zipfile
  10. import difflib
  11. import shutil
  12. import threading
  13. import logging
  14. import random
  15. import sys
  16. from func import *
  17. r_ver = 'v3.0.8-master-05'
  18. c_ver = ''.join(re.findall('[0-9]', r_ver))
  19. print('version : ' + r_ver)
  20. try:
  21. json_data = open('set.json').read()
  22. set_data = json.loads(json_data)
  23. except:
  24. while 1:
  25. print('db name : ', end = '')
  26. new_json = str(input())
  27. if new_json != '':
  28. with open('set.json', 'w') as f:
  29. f.write('{ "db" : "' + new_json + '" }')
  30. json_data = open('set.json').read()
  31. set_data = json.loads(json_data)
  32. break
  33. else:
  34. print('insert value')
  35. pass
  36. if os.path.exists(set_data['db'] + '.db'):
  37. setup_tool = 0
  38. else:
  39. setup_tool = 1
  40. conn = sqlite3.connect(set_data['db'] + '.db', check_same_thread = False)
  41. curs = conn.cursor()
  42. load_conn(conn)
  43. logging.basicConfig(level = logging.ERROR)
  44. app = flask.Flask(__name__, template_folder = './')
  45. app.config['JSON_AS_ASCII'] = False
  46. flask_reggie.Reggie(app)
  47. compress = flask_compress.Compress()
  48. # compress.init_app(app)
  49. class EverythingConverter(werkzeug.routing.PathConverter):
  50. regex = '.*?'
  51. app.jinja_env.filters['md5_replace'] = md5_replace
  52. app.jinja_env.filters['load_lang'] = load_lang
  53. app.url_map.converters['everything'] = EverythingConverter
  54. curs.execute('create table if not exists data(test text)')
  55. curs.execute('create table if not exists cache_data(test text)')
  56. curs.execute('create table if not exists history(test text)')
  57. curs.execute('create table if not exists rd(test text)')
  58. curs.execute('create table if not exists user(test text)')
  59. curs.execute('create table if not exists user_set(test text)')
  60. curs.execute('create table if not exists ban(test text)')
  61. curs.execute('create table if not exists topic(test text)')
  62. curs.execute('create table if not exists stop(test text)')
  63. curs.execute('create table if not exists rb(test text)')
  64. curs.execute('create table if not exists back(test text)')
  65. curs.execute('create table if not exists agreedis(test text)')
  66. curs.execute('create table if not exists custom(test text)')
  67. curs.execute('create table if not exists other(test text)')
  68. curs.execute('create table if not exists alist(test text)')
  69. curs.execute('create table if not exists re_admin(test text)')
  70. curs.execute('create table if not exists alarm(test text)')
  71. curs.execute('create table if not exists ua_d(test text)')
  72. curs.execute('create table if not exists filter(test text)')
  73. curs.execute('create table if not exists scan(test text)')
  74. curs.execute('create table if not exists acl(test text)')
  75. curs.execute('create table if not exists inter(test text)')
  76. curs.execute('create table if not exists html_filter(test text)')
  77. if setup_tool == 0:
  78. curs.execute('select data from other where name = "ver"')
  79. ver_set_data = curs.fetchall()
  80. if not ver_set_data:
  81. setup_tool = 1
  82. else:
  83. if c_ver > ver_set_data[0][0]:
  84. setup_tool = 1
  85. if setup_tool != 0:
  86. create_data = {}
  87. create_data['all_data'] = [
  88. 'data',
  89. 'cache_data',
  90. 'history',
  91. 'rd',
  92. 'user',
  93. 'user_set',
  94. 'ban',
  95. 'topic',
  96. 'stop',
  97. 'rb',
  98. 'back',
  99. 'agreedis',
  100. 'custom',
  101. 'other',
  102. 'alist',
  103. 're_admin',
  104. 'alarm',
  105. 'ua_d',
  106. 'filter',
  107. 'scan',
  108. 'acl',
  109. 'inter',
  110. 'html_filter'
  111. ]
  112. create_data['data'] = ['title', 'data']
  113. create_data['cache_data'] = ['title', 'data']
  114. create_data['history'] = ['id', 'title', 'data', 'date', 'ip', 'send', 'leng', 'hide', 'type']
  115. create_data['rd'] = ['title', 'sub', 'date', 'band']
  116. create_data['user'] = ['id', 'pw', 'acl', 'date', 'encode']
  117. create_data['user_set'] = ['name', 'id', 'data']
  118. create_data['ban'] = ['block', 'end', 'why', 'band', 'login']
  119. create_data['topic'] = ['id', 'title', 'sub', 'data', 'date', 'ip', 'block', 'top']
  120. create_data['stop'] = ['title', 'sub', 'close']
  121. create_data['rb'] = ['block', 'end', 'today', 'blocker', 'why', 'band']
  122. create_data['back'] = ['title', 'link', 'type']
  123. create_data['agreedis'] = ['title', 'sub']
  124. create_data['custom'] = ['user', 'css']
  125. create_data['other'] = ['name', 'data']
  126. create_data['alist'] = ['name', 'acl']
  127. create_data['re_admin'] = ['who', 'what', 'time']
  128. create_data['alarm'] = ['name', 'data', 'date']
  129. create_data['ua_d'] = ['name', 'ip', 'ua', 'today', 'sub']
  130. create_data['filter'] = ['name', 'regex', 'sub']
  131. create_data['scan'] = ['user', 'title']
  132. create_data['acl'] = ['title', 'dec', 'dis', 'view', 'why']
  133. create_data['inter'] = ['title', 'link']
  134. create_data['html_filter'] = ['html', 'kind']
  135. for create_table in create_data['all_data']:
  136. for create in create_data[create_table]:
  137. try:
  138. curs.execute('select ' + create + ' from ' + create_table + ' limit 1')
  139. except:
  140. curs.execute("alter table " + create_table + " add " + create + " text default ''")
  141. update()
  142. curs.execute('select name from alist where acl = "owner"')
  143. if not curs.fetchall():
  144. curs.execute('delete from alist where name = "owner"')
  145. curs.execute('insert into alist (name, acl) values ("owner", "owner")')
  146. if not os.path.exists('image'):
  147. os.makedirs('image')
  148. if not os.path.exists('views'):
  149. os.makedirs('views')
  150. if os.getenv('NAMU_PORT') != None:
  151. rep_port = os.getenv('NAMU_PORT')
  152. else:
  153. curs.execute('select data from other where name = "port"')
  154. rep_data = curs.fetchall()
  155. if not rep_data:
  156. while 1:
  157. print('port : ', end = '')
  158. rep_port = int(input())
  159. if rep_port:
  160. curs.execute('insert into other (name, data) values ("port", ?)', [rep_port])
  161. break
  162. else:
  163. pass
  164. else:
  165. rep_port = rep_data[0][0]
  166. print('port : ' + str(rep_port))
  167. try:
  168. if not os.path.exists('robots.txt'):
  169. curs.execute('select data from other where name = "robot"')
  170. robot_test = curs.fetchall()
  171. if robot_test:
  172. fw_test = open('./robots.txt', 'w')
  173. fw_test.write(re.sub('\r\n', '\n', robot_test[0][0]))
  174. fw_test.close()
  175. else:
  176. fw_test = open('./robots.txt', 'w')
  177. fw_test.write('User-agent: *\nDisallow: /\nAllow: /$\nAllow: /w/')
  178. fw_test.close()
  179. curs.execute('insert into other (name, data) values ("robot", "User-agent: *\nDisallow: /\nAllow: /$\nAllow: /w/")')
  180. print('robots.txt create')
  181. except:
  182. pass
  183. curs.execute('select data from other where name = "key"')
  184. rep_data = curs.fetchall()
  185. if not rep_data:
  186. rep_key = ''.join(random.choice("0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ") for i in range(16))
  187. if rep_key:
  188. curs.execute('insert into other (name, data) values ("key", ?)', [rep_key])
  189. else:
  190. rep_key = rep_data[0][0]
  191. support_language = ['ko-KR', 'en-US']
  192. curs.execute("select data from other where name = 'language'")
  193. rep_data = curs.fetchall()
  194. if not rep_data:
  195. if os.getenv('NAMU_LANG') != None:
  196. if os.getenv('NAMU_LANG') in support_language:
  197. curs.execute("insert into other (name, data) values ('language', ?)", [os.getenv('NAMU_LANG')])
  198. rep_language = os.getenv('NAMU_LANG')
  199. else:
  200. print('language ' + str(os.getenv('NAMU_LANG')) + ' is not supported!')
  201. rep_language = 'en-US'
  202. else:
  203. while 1:
  204. print('language [' + ', '.join(support_language) + '] : ', end = '')
  205. rep_language = str(input())
  206. if rep_language in support_language:
  207. curs.execute("insert into other (name, data) values ('language', ?)", [rep_language])
  208. break
  209. else:
  210. pass
  211. else:
  212. rep_language = rep_data[0][0]
  213. print('language : ' + str(rep_language))
  214. ask_this = [[['markup', 'markup'], ['namumark']], [['encryption method', 'encode'], ['sha256', 'bcrypt']]]
  215. for ask_data in ask_this:
  216. curs.execute('select data from other where name = ?', [ask_data[0][1]])
  217. rep_data = curs.fetchall()
  218. if not rep_data:
  219. while 1:
  220. print(ask_data[0][0] + ' [' + ', '.join(ask_data[1]) + '] : ', end = '')
  221. rep_mark = str(input())
  222. if rep_mark and rep_mark in ask_data[1]:
  223. curs.execute('insert into other (name, data) values (?, ?)', [ask_data[0][1], rep_mark])
  224. break
  225. else:
  226. pass
  227. else:
  228. rep_mark = rep_data[0][0]
  229. print(ask_data[0][1] + ' : ' + str(rep_mark))
  230. curs.execute('delete from other where name = "ver"')
  231. curs.execute('insert into other (name, data) values ("ver", ?)', [c_ver])
  232. def back_up():
  233. try:
  234. shutil.copyfile(set_data['db'] + '.db', 'back_' + set_data['db'] + '.db')
  235. print('back up : ok')
  236. except:
  237. print('back up : error')
  238. threading.Timer(60 * 60 * back_time, back_up).start()
  239. try:
  240. curs.execute('select data from other where name = "back_up"')
  241. back_up_time = curs.fetchall()
  242. back_time = int(back_up_time[0][0])
  243. except:
  244. back_time = 0
  245. if back_time != 0:
  246. print('back up state : ' + str(back_time) + ' hours interval')
  247. if __name__ == '__main__':
  248. back_up()
  249. else:
  250. print('back up state : turn off')
  251. conn.commit()
  252. @app.route('/del_alarm')
  253. def del_alarm():
  254. curs.execute("delete from alarm where name = ?", [ip_check()])
  255. conn.commit()
  256. return redirect('/alarm')
  257. @app.route('/alarm')
  258. def alarm():
  259. if custom()[2] == 0:
  260. return redirect('/login')
  261. data = '<ul>'
  262. curs.execute("select data, date from alarm where name = ? order by date desc", [ip_check()])
  263. data_list = curs.fetchall()
  264. if data_list:
  265. data = '<a href="/del_alarm">(' + load_lang('delete') + ')</a><hr>' + data
  266. for data_one in data_list:
  267. data += '<li>' + data_one[0] + ' (' + data_one[1] + ')</li>'
  268. else:
  269. data += '<li>-</li>'
  270. data += '</ul>'
  271. return easy_minify(flask.render_template(skin_check(),
  272. imp = [load_lang('alarm'), wiki_set(), custom(), other2([0, 0])],
  273. data = data,
  274. menu = [['user', load_lang('user')]]
  275. ))
  276. @app.route('/<regex("inter_wiki|(?:edit|email|name)_filter"):tools>')
  277. def inter_wiki(tools = None):
  278. div = ''
  279. admin = admin_check(None, None)
  280. if tools == 'inter_wiki':
  281. del_link = 'del_inter_wiki'
  282. plus_link = 'plus_inter_wiki'
  283. title = load_lang('interwiki') + ' ' + load_lang('list')
  284. div = ''
  285. curs.execute('select title, link from inter')
  286. elif tools == 'email_filter':
  287. del_link = 'del_email_filter'
  288. plus_link = 'plus_email_filter'
  289. title = 'email ' + load_lang('filter') + ' ' + load_lang('list')
  290. div = '''
  291. <ul>
  292. <li>gmail.com</li>
  293. <li>naver.com</li>
  294. <li>daum.net</li>
  295. <li>hanmail.net</li>
  296. </ul>
  297. '''
  298. curs.execute("select html from html_filter where kind = 'email'")
  299. else:
  300. del_link = 'del_edit_filter'
  301. plus_link = 'manager/9'
  302. title = load_lang('edit') + ' ' + load_lang('filter') + ' ' + load_lang('list')
  303. div = ''
  304. curs.execute("select name from filter")
  305. db_data = curs.fetchall()
  306. if db_data:
  307. div += '<ul>'
  308. for data in db_data:
  309. if tools == 'inter_wiki':
  310. div += '<li>' + data[0] + ' : <a id="out_link" href="' + data[1] + '">' + data[1] + '</a>'
  311. elif tools == 'edit_filter':
  312. div += '<li><a href="/plus_edit_filter/' + url_pas(data[0]) + '">' + data[0] + '</a>'
  313. else:
  314. div += '<li>' + data[0]
  315. if admin == 1:
  316. div += ' <a href="/' + del_link + '/' + url_pas(data[0]) + '">(' + load_lang('delete') + ')</a>'
  317. div += '</li>'
  318. div += '</ul>'
  319. if admin == 1:
  320. div += '<hr><a href="/' + plus_link + '">(' + load_lang('plus') + ')</a>'
  321. else:
  322. if admin == 1:
  323. div += '<a href="/' + plus_link + '">(' + load_lang('plus') + ')</a>'
  324. return easy_minify(flask.render_template(skin_check(),
  325. imp = [title, wiki_set(), custom(), other2([0, 0])],
  326. data = div,
  327. menu = [['other', load_lang('other')]]
  328. ))
  329. @app.route('/<regex("del_(?:inter_wiki|(?:edit|email|name)_filter)"):tools>/<name>')
  330. def del_inter(tools = None, name = None):
  331. if admin_check(None, tools) == 1:
  332. if tools == 'del_inter_wiki':
  333. curs.execute("delete from inter where title = ?", [name])
  334. elif tools == 'del_edit_filter':
  335. curs.execute("delete from filter where name = ?", [name])
  336. else:
  337. curs.execute("delete from html_filter where html = ? and kind = 'email'", [name])
  338. conn.commit()
  339. return redirect('/' + re.sub('^del_', '', tools))
  340. else:
  341. return re_error('/error/3')
  342. @app.route('/<regex("plus_(?:inter_wiki|(?:edit|email|name)_filter)"):tools>', methods=['POST', 'GET'])
  343. @app.route('/<regex("plus_edit_filter"):tools>/<name>', methods=['POST', 'GET'])
  344. def plus_inter(tools = None, name = None):
  345. if flask.request.method == 'POST':
  346. if tools == 'plus_inter_wiki':
  347. curs.execute('insert into inter (title, link) values (?, ?)', [flask.request.form.get('title', None), flask.request.form.get('link', None)])
  348. admin_check(None, 'inter_wiki_plus')
  349. elif tools == 'plus_edit_filter':
  350. if admin_check(1, 'edit_filter edit') != 1:
  351. return re_error('/error/3')
  352. if flask.request.form.get('limitless', '') != '':
  353. end = 'X'
  354. else:
  355. end = flask.request.form.get('second', 'X')
  356. curs.execute("select name from filter where name = ?", [name])
  357. if curs.fetchall():
  358. curs.execute("update filter set regex = ?, sub = ? where name = ?", [flask.request.form.get('content', 'test'), end, name])
  359. else:
  360. curs.execute("insert into filter (name, regex, sub) values (?, ?, ?)", [name, flask.request.form.get('content', 'test'), end])
  361. else:
  362. curs.execute('insert into html_filter (html, kind) values (?, "email")', [flask.request.form.get('title', None)])
  363. admin_check(None, 'email_filter edit')
  364. conn.commit()
  365. return redirect('/' + re.sub('^plus_', '', tools))
  366. else:
  367. if admin_check(1, None) != 1:
  368. stat = 'disabled'
  369. else:
  370. stat = ''
  371. if tools == 'plus_inter_wiki':
  372. title = load_lang('interwiki') + ' ' + load_lang('plus')
  373. form_data = '''
  374. <input placeholder="''' + load_lang('name') + '''" type="text" name="title">
  375. <hr>
  376. <input placeholder="link" type="text" name="link">
  377. '''
  378. elif tools == 'plus_edit_filter':
  379. curs.execute("select regex, sub from filter where name = ?", [name])
  380. exist = curs.fetchall()
  381. if exist:
  382. textarea = exist[0][0]
  383. if exist[0][1] == 'X':
  384. time_check = 'checked="checked"'
  385. time_data = ''
  386. else:
  387. time_check = ''
  388. time_data = exist[0][1]
  389. else:
  390. textarea = ''
  391. time_check = ''
  392. time_data = ''
  393. title = load_lang('edit') + ' ' + load_lang('filter') + ' ' + load_lang('plus')
  394. form_data = '''
  395. <input placeholder="''' + load_lang('second') + '''" name="second" type="text" value="''' + html.escape(time_data) + '''">
  396. <hr>
  397. <input ''' + stat + ''' type="checkbox" ''' + time_check + ''' name="limitless"> ''' + load_lang('limitless') + '''
  398. <hr>
  399. <input ''' + stat + ''' placeholder="''' + load_lang('regex') + '''" name="content" value="''' + html.escape(textarea) + '''" type="text">
  400. '''
  401. else:
  402. title = 'email ' + load_lang('filter') + ' ' + load_lang('plus')
  403. form_data = '<input placeholder="email" type="text" name="title">'
  404. return easy_minify(flask.render_template(skin_check(),
  405. imp = [title, wiki_set(), custom(), other2([0, 0])],
  406. data = '''
  407. <form method="post">
  408. ''' + form_data + '''
  409. <hr>
  410. <button ''' + stat + ''' type="submit">''' + load_lang('plus') + '''</button>
  411. </form>
  412. ''',
  413. menu = [['other', load_lang('other')], [re.sub('^plus_', '', tools), load_lang('list')]]
  414. ))
  415. @app.route('/setting')
  416. @app.route('/setting/<int:num>', methods=['POST', 'GET'])
  417. def setting(num = 0):
  418. if num != 0 and admin_check(None, None) != 1:
  419. return re_error('/ban')
  420. if num == 0:
  421. li_list = [load_lang('main'), load_lang('text') + ' ' + load_lang('setting'), load_lang('main') + ' head', 'robots.txt', 'google']
  422. x = 0
  423. li_data = ''
  424. for li in li_list:
  425. x += 1
  426. li_data += '<li><a href="/setting/' + str(x) + '">' + li + '</a></li>'
  427. return easy_minify(flask.render_template(skin_check(),
  428. imp = [load_lang('setting'), wiki_set(), custom(), other2([0, 0])],
  429. data = '<h2>' + load_lang('list') + '</h2><ul>' + li_data + '</ul>',
  430. menu = [['manager', load_lang('admin')]]
  431. ))
  432. elif num == 1:
  433. i_list = ['name', 'logo', 'frontpage', 'license', 'upload', 'skin', 'edit', 'reg', 'ip_view', 'back_up', 'port', 'key', 'update', 'email_have', 'discussion', 'encode']
  434. n_list = ['wiki', '', 'FrontPage', 'CC 0', '2', '', 'normal', '', '', '0', '3000', 'test', 'stable', '', 'normal', 'sha256']
  435. if flask.request.method == 'POST':
  436. i = 0
  437. for data in i_list:
  438. curs.execute("update other set data = ? where name = ?", [flask.request.form.get(data, n_list[i]), data])
  439. i += 1
  440. conn.commit()
  441. admin_check(None, 'edit_set')
  442. return redirect('/setting/1')
  443. else:
  444. d_list = []
  445. x = 0
  446. for i in i_list:
  447. curs.execute('select data from other where name = ?', [i])
  448. sql_d = curs.fetchall()
  449. if sql_d:
  450. d_list += [sql_d[0][0]]
  451. else:
  452. curs.execute('insert into other (name, data) values (?, ?)', [i, n_list[x]])
  453. d_list += [n_list[x]]
  454. x += 1
  455. conn.commit()
  456. div = ''
  457. acl_list = [[load_lang('subscriber'), 'login'], [load_lang('normal'), 'normal'], [load_lang('admin'), 'admin']]
  458. for i in acl_list:
  459. if i[1] == d_list[6]:
  460. div = '<option value="' + i[1] + '">' + i[0] + '</option>' + div
  461. else:
  462. div += '<option value="' + i[1] + '">' + i[0] + '</option>'
  463. div4 = ''
  464. for i in acl_list:
  465. if i[1] == d_list[14]:
  466. div4 = '<option value="' + i[1] + '">' + i[0] + '</option>' + div4
  467. else:
  468. div4 += '<option value="' + i[1] + '">' + i[0] + '</option>'
  469. ch_1 = ''
  470. if d_list[7]:
  471. ch_1 = 'checked="checked"'
  472. ch_2 = ''
  473. if d_list[8]:
  474. ch_2 = 'checked="checked"'
  475. ch_3 = ''
  476. if d_list[13]:
  477. ch_3 = 'checked="checked"'
  478. div2 = load_skin(d_list[5])
  479. div3 =''
  480. if d_list[12] == 'stable':
  481. div3 += '<option value="stable">stable</option>'
  482. div3 += '<option value="master">master</option>'
  483. else:
  484. div3 += '<option value="master">master</option>'
  485. div3 += '<option value="stable">stable</option>'
  486. div5 =''
  487. if d_list[15] == 'sha256':
  488. div5 += '<option value="sha256">sha256</option>'
  489. div5 += '<option value="bcrypt">bcrypt</option>'
  490. else:
  491. div5 += '<option value="bcrypt">bcrypt</option>'
  492. div5 += '<option value="sha256">sha256</option>'
  493. return easy_minify(flask.render_template(skin_check(),
  494. imp = [load_lang('main'), wiki_set(), custom(), other2([0, 0])],
  495. data = '''
  496. <form method="post">
  497. <span>''' + load_lang('name') + '''</span>
  498. <br>
  499. <br>
  500. <input placeholder="''' + load_lang('name') + '''" type="text" name="name" value="''' + html.escape(d_list[0]) + '''">
  501. <hr>
  502. <span>''' + load_lang('logo') + ''' (html)</span>
  503. <br>
  504. <br>
  505. <input placeholder="''' + load_lang('logo') + '''" type="text" name="logo" value="''' + html.escape(d_list[1]) + '''">
  506. <hr>
  507. <span>''' + load_lang('frontpage') + '''</span>
  508. <br>
  509. <br>
  510. <input placeholder="''' + load_lang('frontpage') + '''" type="text" name="frontpage" value="''' + html.escape(d_list[2]) + '''">
  511. <hr>
  512. <span>''' + load_lang('bottom') + ' ' + load_lang('text') + ''' (html)</span>
  513. <br>
  514. <br>
  515. <input placeholder="''' + load_lang('bottom') + ' ' + load_lang('text') + '''" type="text" name="license" value="''' + html.escape(d_list[3]) + '''">
  516. <hr>
  517. <span>''' + load_lang('max_file_size') + ''' [mb]</span>
  518. <br>
  519. <br>
  520. <input placeholder="''' + load_lang('max_file_size') + '''" type="text" name="upload" value="''' + html.escape(d_list[4]) + '''">
  521. <hr>
  522. <span>''' + load_lang('backup_interval') + ' [' + load_lang('hour') + '''] (off : 0) {restart}</span>
  523. <br>
  524. <br>
  525. <input placeholder="''' + load_lang('backup_interval') + '''" type="text" name="back_up" value="''' + html.escape(d_list[9]) + '''">
  526. <hr>
  527. <span>''' + load_lang('skin') + '''</span>
  528. <br>
  529. <br>
  530. <select name="skin">''' + div2 + '''</select>
  531. <hr>
  532. <span>''' + load_lang('default') + ''' acl</span>
  533. <br>
  534. <br>
  535. <select name="edit">''' + div + '''</select>
  536. <hr>
  537. <span>''' + load_lang('default') + ' ' + load_lang('discussion') + ''' acl</span>
  538. <br>
  539. <br>
  540. <select name="discussion">''' + div4 + '''</select>
  541. <hr>
  542. <input type="checkbox" name="reg" ''' + ch_1 + '''> ''' + load_lang('register') + ''' X
  543. <hr>
  544. <input type="checkbox" name="ip_view" ''' + ch_2 + '''> ip ''' + load_lang('hide') + '''
  545. <hr>
  546. <input type="checkbox" name="email_have" ''' + ch_3 + '''> must have email {<a href="/setting/5">must set google imap</a>}
  547. <hr>
  548. <span>''' + load_lang('port') + '''</span>
  549. <br>
  550. <br>
  551. <input placeholder="''' + load_lang('port') + '''" type="text" name="port" value="''' + html.escape(d_list[10]) + '''">
  552. <hr>
  553. <span>''' + load_lang('secret_key') + '''</span>
  554. <br>
  555. <br>
  556. <input placeholder="''' + load_lang('secret_key') + '''" type="password" name="key" value="''' + html.escape(d_list[11]) + '''">
  557. <hr>
  558. <span>''' + load_lang('update_branch') + '''</span>
  559. <br>
  560. <br>
  561. <select name="update">''' + div3 + '''</select>
  562. <hr>
  563. <span>encryption method</span>
  564. <br>
  565. <br>
  566. <select name="encode">''' + div5 + '''</select>
  567. <hr>
  568. <button id="save" type="submit">''' + load_lang('save') + '''</button>
  569. </form>
  570. ''',
  571. menu = [['setting', load_lang('setting')]]
  572. ))
  573. elif num == 2:
  574. if flask.request.method == 'POST':
  575. curs.execute("update other set data = ? where name = ?", [flask.request.form.get('contract', None), 'contract'])
  576. curs.execute("update other set data = ? where name = ?", [flask.request.form.get('no_login_warring', None), 'no_login_warring'])
  577. conn.commit()
  578. admin_check(None, 'edit_set')
  579. return redirect('/setting/2')
  580. else:
  581. i_list = ['contract', 'no_login_warring']
  582. n_list = ['', '']
  583. d_list = []
  584. x = 0
  585. for i in i_list:
  586. curs.execute('select data from other where name = ?', [i])
  587. sql_d = curs.fetchall()
  588. if sql_d:
  589. d_list += [sql_d[0][0]]
  590. else:
  591. curs.execute('insert into other (name, data) values (?, ?)', [i, n_list[x]])
  592. d_list += [n_list[x]]
  593. x += 1
  594. conn.commit()
  595. return easy_minify(flask.render_template(skin_check(),
  596. imp = [load_lang('text') + ' ' + load_lang('setting'), wiki_set(), custom(), other2([0, 0])],
  597. data = '''
  598. <form method="post">
  599. <span>''' + load_lang('register_text') + '''</span>
  600. <br>
  601. <br>
  602. <input placeholder="''' + load_lang('register_text') + '''" type="text" name="contract" value="''' + html.escape(d_list[0]) + '''">
  603. <hr>
  604. <span>''' + load_lang('non_login_alert') + '''</span>
  605. <br>
  606. <br>
  607. <input placeholder="''' + load_lang('non_login_alert') + '''" type="text" name="no_login_warring" value="''' + html.escape(d_list[1]) + '''">
  608. <hr>
  609. <button id="save" type="submit">''' + load_lang('save') + '''</button>
  610. </form>
  611. ''',
  612. menu = [['setting', load_lang('setting')]]
  613. ))
  614. elif num == 3:
  615. if flask.request.method == 'POST':
  616. curs.execute("select name from other where name = 'head'")
  617. if curs.fetchall():
  618. curs.execute("update other set data = ? where name = 'head'", [flask.request.form.get('content', None)])
  619. else:
  620. curs.execute("insert into other (name, data) values ('head', ?)", [flask.request.form.get('content', None)])
  621. conn.commit()
  622. admin_check(None, 'edit_set')
  623. return redirect('/setting/3')
  624. else:
  625. curs.execute("select data from other where name = 'head'")
  626. head = curs.fetchall()
  627. if head:
  628. data = head[0][0]
  629. else:
  630. data = ''
  631. return easy_minify(flask.render_template(skin_check(),
  632. imp = [load_lang('main') + ' head', wiki_set(), custom(), other2([0, 0])],
  633. data = '''
  634. <form method="post">
  635. <textarea rows="25" name="content">''' + html.escape(data) + '''</textarea>
  636. <hr>
  637. <button id="save" type="submit">''' + load_lang('save') + '''</button>
  638. </form>
  639. ''',
  640. menu = [['setting', load_lang('setting')]]
  641. ))
  642. elif num == 4:
  643. if flask.request.method == 'POST':
  644. curs.execute("select name from other where name = 'robot'")
  645. if curs.fetchall():
  646. curs.execute("update other set data = ? where name = 'robot'", [flask.request.form.get('content', None)])
  647. else:
  648. curs.execute("insert into other (name, data) values ('robot', ?)", [flask.request.form.get('content', None)])
  649. conn.commit()
  650. fw = open('./robots.txt', 'w')
  651. fw.write(re.sub('\r\n', '\n', flask.request.form.get('content', None)))
  652. fw.close()
  653. admin_check(None, 'edit_set')
  654. return redirect('/setting/4')
  655. else:
  656. curs.execute("select data from other where name = 'robot'")
  657. robot = curs.fetchall()
  658. if robot:
  659. data = robot[0][0]
  660. else:
  661. data = ''
  662. f = open('./robots.txt', 'r')
  663. lines = f.readlines()
  664. f.close()
  665. if not data or data == '':
  666. data = ''.join(lines)
  667. return easy_minify(flask.render_template(skin_check(),
  668. imp = ['robots.txt', wiki_set(), custom(), other2([0, 0])],
  669. data = '''
  670. <a href="/robots.txt">(view)</a>
  671. <hr>
  672. <form method="post">
  673. <textarea rows="25" name="content">''' + html.escape(data) + '''</textarea>
  674. <hr>
  675. <button id="save" type="submit">''' + load_lang('save') + '''</button>
  676. </form>
  677. ''',
  678. menu = [['setting', load_lang('setting')]]
  679. ))
  680. elif num == 5:
  681. i_list = ['recaptcha', 'sec_re', 'g_email', 'g_pass']
  682. if flask.request.method == 'POST':
  683. for data in i_list:
  684. curs.execute("update other set data = ? where name = ?", [flask.request.form.get(data, ''), data])
  685. conn.commit()
  686. admin_check(None, 'edit_set')
  687. return redirect('/setting/5')
  688. else:
  689. n_list = ['', '', '', '']
  690. d_list = []
  691. x = 0
  692. for i in i_list:
  693. curs.execute('select data from other where name = ?', [i])
  694. sql_d = curs.fetchall()
  695. if sql_d:
  696. d_list += [sql_d[0][0]]
  697. else:
  698. curs.execute('insert into other (name, data) values (?, ?)', [i, n_list[x]])
  699. d_list += [n_list[x]]
  700. x += 1
  701. conn.commit()
  702. return easy_minify(flask.render_template(skin_check(),
  703. imp = ['google', wiki_set(), custom(), other2([0, 0])],
  704. data = '''
  705. <form method="post">
  706. <h2><a href="https://www.google.com/recaptcha/admin">recaptcha</a></h2>
  707. <span>recaptcha (html)</span>
  708. <br>
  709. <br>
  710. <input placeholder="recaptcha (html)" type="text" name="recaptcha" value="''' + html.escape(d_list[0]) + '''">
  711. <hr>
  712. <span>recaptcha (secret key)</span>
  713. <br>
  714. <br>
  715. <input placeholder="recaptcha (secret key)" type="text" name="sec_re" value="''' + html.escape(d_list[1]) + '''">
  716. <hr>
  717. <h2><a href="https://support.google.com/mail/answer/7126229">google imap</a> {restart}</h1>
  718. <span>google email</span>
  719. <br>
  720. <br>
  721. <input placeholder="google email" type="text" name="g_email" value="''' + html.escape(d_list[2]) + '''">
  722. <hr>
  723. <span><a href="https://security.google.com/settings/security/apppasswords">google app password</a></span>
  724. <br>
  725. <br>
  726. <input placeholder="google app password" type="password" name="g_pass" value="''' + html.escape(d_list[3]) + '''">
  727. <hr>
  728. <button id="save" type="submit">''' + load_lang('save') + '''</button>
  729. </form>
  730. ''',
  731. menu = [['setting', load_lang('setting')]]
  732. ))
  733. else:
  734. return redirect('/')
  735. @app.route('/not_close_topic')
  736. def not_close_topic():
  737. div = '<ul>'
  738. curs.execute('select title, sub from rd order by date desc')
  739. n_list = curs.fetchall()
  740. for data in n_list:
  741. curs.execute('select * from stop where title = ? and sub = ? and close = "O"', [data[0], data[1]])
  742. is_close = curs.fetchall()
  743. if not is_close:
  744. div += '<li><a href="/topic/' + url_pas(data[0]) + '/sub/' + url_pas(data[1]) + '">' + data[0] + ' (' + data[1] + ')</a></li>'
  745. div += '</ul>'
  746. return easy_minify(flask.render_template(skin_check(),
  747. imp = [load_lang('open') + ' ' + load_lang('discussion') + ' ' + load_lang('list'), wiki_set(), custom(), other2([0, 0])],
  748. data = div,
  749. menu = [['manager', load_lang('admin')]]
  750. ))
  751. @app.route('/image/<name>')
  752. def image_view(name = None):
  753. if os.path.exists(os.path.join('image', name)):
  754. return flask.send_from_directory('./image', name)
  755. else:
  756. return redirect('/')
  757. @app.route('/acl_list')
  758. def acl_list():
  759. div = '''
  760. <table id="main_table_set">
  761. <tbody>
  762. <tr>
  763. <td id="main_table_width_quarter">''' + load_lang('document') + ' ' + load_lang('name') + '''</td>
  764. <td id="main_table_width_quarter">''' + load_lang('document') + ''' acl</td>
  765. <td id="main_table_width_quarter">''' + load_lang('discussion') + ''' acl</td>
  766. <td id="main_table_width_quarter">''' + load_lang('view') + ''' acl</td>
  767. '''
  768. curs.execute("select title, dec, dis, view, why from acl where dec = 'admin' or dec = 'user' or dis = 'admin' or dis = 'user' or view = 'admin' or view = 'user' order by title desc")
  769. list_data = curs.fetchall()
  770. for data in list_data:
  771. if not re.search('^user:', data[0]) and not re.search('^file:', data[0]):
  772. acl = []
  773. for i in range(1, 4):
  774. if data[i] == 'admin':
  775. acl += [load_lang('admin')]
  776. else:
  777. acl += [load_lang('subscriber')]
  778. div += '<tr><td><a href="/w/' + url_pas(data[0]) + '">' + data[0] + '</a></td><td>' + acl[0] + '</td><td>' + acl[1] + '</td><td>' + acl[2] + '</td></tr>'
  779. div += '</tbody></table>'
  780. return easy_minify(flask.render_template(skin_check(),
  781. imp = ['acl ' + load_lang('document') + ' ' + load_lang('list'), wiki_set(), custom(), other2([0, 0])],
  782. data = div,
  783. menu = [['other', load_lang('other')]]
  784. ))
  785. @app.route('/admin_plus/<name>', methods=['POST', 'GET'])
  786. def admin_plus(name = None):
  787. if flask.request.method == 'POST':
  788. if admin_check(None, 'admin_plus (' + name + ')') != 1:
  789. return re_error('/error/3')
  790. curs.execute("delete from alist where name = ?", [name])
  791. if flask.request.form.get('ban', 0) != 0:
  792. curs.execute("insert into alist (name, acl) values (?, 'ban')", [name])
  793. if flask.request.form.get('toron', 0) != 0:
  794. curs.execute("insert into alist (name, acl) values (?, 'toron')", [name])
  795. if flask.request.form.get('check', 0) != 0:
  796. curs.execute("insert into alist (name, acl) values (?, 'check')", [name])
  797. if flask.request.form.get('acl', 0) != 0:
  798. curs.execute("insert into alist (name, acl) values (?, 'acl')", [name])
  799. if flask.request.form.get('hidel', 0) != 0:
  800. curs.execute("insert into alist (name, acl) values (?, 'hidel')", [name])
  801. if flask.request.form.get('give', 0) != 0:
  802. curs.execute("insert into alist (name, acl) values (?, 'give')", [name])
  803. if flask.request.form.get('owner', 0) != 0:
  804. curs.execute("insert into alist (name, acl) values (?, 'owner')", [name])
  805. conn.commit()
  806. return redirect('/admin_plus/' + url_pas(name))
  807. else:
  808. data = '<ul>'
  809. exist_list = ['', '', '', '', '', '', '', '']
  810. curs.execute('select acl from alist where name = ?', [name])
  811. acl_list = curs.fetchall()
  812. for go in acl_list:
  813. if go[0] == 'ban':
  814. exist_list[0] = 'checked="checked"'
  815. elif go[0] == 'toron':
  816. exist_list[2] = 'checked="checked"'
  817. elif go[0] == 'check':
  818. exist_list[3] = 'checked="checked"'
  819. elif go[0] == 'acl':
  820. exist_list[4] = 'checked="checked"'
  821. elif go[0] == 'hidel':
  822. exist_list[5] = 'checked="checked"'
  823. elif go[0] == 'give':
  824. exist_list[6] = 'checked="checked"'
  825. elif go[0] == 'owner':
  826. exist_list[7] = 'checked="checked"'
  827. if admin_check(None, None) != 1:
  828. state = 'disabled'
  829. else:
  830. state = ''
  831. data += '<li><input type="checkbox" ' + state + ' name="ban" ' + exist_list[0] + '> ' + load_lang('ban') + '</li>'
  832. data += '<li><input type="checkbox" ' + state + ' name="toron" ' + exist_list[2] + '> ' + load_lang('discussion') + '</li>'
  833. data += '<li><input type="checkbox" ' + state + ' name="check" ' + exist_list[3] + '> ' + load_lang('user') + ' ' + load_lang('check') + '</li>'
  834. data += '<li><input type="checkbox" ' + state + ' name="acl" ' + exist_list[4] + '> ' + load_lang('document') + ' acl</li>'
  835. data += '<li><input type="checkbox" ' + state + ' name="hidel" ' + exist_list[5] + '> ' + load_lang('history') + ' ' + load_lang('hide') + '</li>'
  836. data += '<li><input type="checkbox" ' + state + ' name="give" ' + exist_list[6] + '> ' + load_lang('authority') + '</li>'
  837. data += '<li><input type="checkbox" ' + state + ' name="owner" ' + exist_list[7] + '> ' + load_lang('owner') + '</li></ul>'
  838. return easy_minify(flask.render_template(skin_check(),
  839. imp = [load_lang('admin_group') + ' ' + load_lang('plus'), wiki_set(), custom(), other2([0, 0])],
  840. data = '''
  841. <form method="post">
  842. ''' + data + '''
  843. <hr>
  844. <button id="save" ''' + state + ''' type="submit">''' + load_lang('save') + '''</button>
  845. </form>
  846. ''',
  847. menu = [['manager', load_lang('admin')]]
  848. ))
  849. @app.route('/admin_list')
  850. def admin_list():
  851. div = '<ul>'
  852. curs.execute("select id, acl, date from user where not acl = 'user' order by date desc")
  853. for data in curs.fetchall():
  854. name = ip_pas(data[0]) + ' <a href="/admin_plus/' + url_pas(data[1]) + '">(' + data[1] + ')</a>'
  855. if data[2] != '':
  856. name += '(' + data[2] + ')'
  857. div += '<li>' + name + '</li>'
  858. div += '</ul>'
  859. return easy_minify(flask.render_template(skin_check(),
  860. imp = [load_lang('admin') + ' ' + load_lang('list'), wiki_set(), custom(), other2([0, 0])],
  861. data = div,
  862. menu = [['other', load_lang('other')]]
  863. ))
  864. @app.route('/hidden/<everything:name>')
  865. def history_hidden(name = None):
  866. num = int(flask.request.args.get('num', 0))
  867. if admin_check(6, 'history_hidden (' + name + '#' + str(num) + ')') == 1:
  868. curs.execute("select title from history where title = ? and id = ? and hide = 'O'", [name, str(num)])
  869. if curs.fetchall():
  870. curs.execute("update history set hide = '' where title = ? and id = ?", [name, str(num)])
  871. else:
  872. curs.execute("update history set hide = 'O' where title = ? and id = ?", [name, str(num)])
  873. conn.commit()
  874. return redirect('/history/' + url_pas(name))
  875. @app.route('/user_log')
  876. def user_log():
  877. num = int(flask.request.args.get('num', 1))
  878. if num * 50 > 0:
  879. sql_num = num * 50 - 50
  880. else:
  881. sql_num = 0
  882. list_data = '<ul>'
  883. admin_one = admin_check(1, None)
  884. curs.execute("select id, date from user order by date desc limit ?, '50'", [str(sql_num)])
  885. user_list = curs.fetchall()
  886. for data in user_list:
  887. if admin_one == 1:
  888. curs.execute("select block from ban where block = ?", [data[0]])
  889. if curs.fetchall():
  890. ban_button = ' <a href="/ban/' + url_pas(data[0]) + '">(' + load_lang('release') + ')</a>'
  891. else:
  892. ban_button = ' <a href="/ban/' + url_pas(data[0]) + '">(' + load_lang('ban') + ')</a>'
  893. else:
  894. ban_button = ''
  895. list_data += '<li>' + ip_pas(data[0]) + ban_button
  896. if data[1] != '':
  897. list_data += ' (' + data[1] + ')'
  898. list_data += '</li>'
  899. if num == 1:
  900. curs.execute("select count(id) from user")
  901. user_count = curs.fetchall()
  902. if user_count:
  903. count = user_count[0][0]
  904. else:
  905. count = 0
  906. list_data += '</ul><hr><ul><li>all : ' + str(count) + '</li></ul>'
  907. list_data += next_fix('/user_log?num=', num, user_list)
  908. return easy_minify(flask.render_template(skin_check(),
  909. imp = [load_lang('recent') + ' ' + load_lang('subscriber'), wiki_set(), custom(), other2([0, 0])],
  910. data = list_data,
  911. menu = 0
  912. ))
  913. @app.route('/admin_log')
  914. def admin_log():
  915. num = int(flask.request.args.get('num', 1))
  916. if num * 50 > 0:
  917. sql_num = num * 50 - 50
  918. else:
  919. sql_num = 0
  920. list_data = '<ul>'
  921. curs.execute("select who, what, time from re_admin order by time desc limit ?, '50'", [str(sql_num)])
  922. get_list = curs.fetchall()
  923. for data in get_list:
  924. list_data += '<li>' + ip_pas(data[0]) + ' / ' + data[1] + ' / ' + data[2] + '</li>'
  925. list_data += '</ul>'
  926. list_data += next_fix('/admin_log?num=', num, get_list)
  927. return easy_minify(flask.render_template(skin_check(),
  928. imp = [load_lang('recent') + ' ' + load_lang('authority'), wiki_set(), custom(), other2([0, 0])],
  929. data = list_data,
  930. menu = 0
  931. ))
  932. @app.route('/give_log')
  933. def give_log():
  934. list_data = '<ul>'
  935. back = ''
  936. curs.execute("select distinct name from alist order by name asc")
  937. for data in curs.fetchall():
  938. if back != data[0]:
  939. back = data[0]
  940. list_data += '<li><a href="/admin_plus/' + url_pas(data[0]) + '">' + data[0] + '</a></li>'
  941. list_data += '</ul><hr><a href="/manager/8">(' + load_lang('create') + ')</a>'
  942. return easy_minify(flask.render_template(skin_check(),
  943. imp = [load_lang('admin_group') + ' ' + load_lang('list'), wiki_set(), custom(), other2([0, 0])],
  944. data = list_data,
  945. menu = [['other', load_lang('other')]]
  946. ))
  947. @app.route('/indexing')
  948. def indexing():
  949. if admin_check(None, 'indexing') != 1:
  950. return re_error('/error/3')
  951. curs.execute("select name from sqlite_master where type = 'index'")
  952. data = curs.fetchall()
  953. if data:
  954. for delete_index in data:
  955. print('delete : ' + delete_index[0])
  956. sql = 'drop index if exists ' + delete_index[0]
  957. try:
  958. curs.execute(sql)
  959. except:
  960. pass
  961. else:
  962. curs.execute("select name from sqlite_master where type in ('table', 'view') and name not like 'sqlite_%' union all select name from sqlite_temp_master where type in ('table', 'view') order by 1;")
  963. for table in curs.fetchall():
  964. curs.execute('select sql from sqlite_master where name = ?', [table[0]])
  965. cul = curs.fetchall()
  966. r_cul = re.findall('(?:([^ (]*) text)', str(cul[0]))
  967. for n_cul in r_cul:
  968. print('create : index_' + table[0] + '_' + n_cul)
  969. sql = 'create index index_' + table[0] + '_' + n_cul + ' on ' + table[0] + '(' + n_cul + ')'
  970. try:
  971. curs.execute(sql)
  972. except:
  973. pass
  974. conn.commit()
  975. return redirect('/')
  976. @app.route('/restart', methods=['POST', 'GET'])
  977. def restart():
  978. if admin_check(None, 'restart') != 1:
  979. return re_error('/error/3')
  980. if flask.request.method == 'POST':
  981. os.execl(sys.executable, sys.executable, *sys.argv)
  982. else:
  983. print('restart')
  984. return easy_minify(flask.render_template(skin_check(),
  985. imp = [load_lang('server') + ' ' + load_lang('restart'), wiki_set(), custom(), other2([0, 0])],
  986. data = '''
  987. <form method="post">
  988. <button type="submit">''' + load_lang('restart') + '''</button>
  989. </form>
  990. ''',
  991. menu = [['manager', load_lang('admin')]]
  992. ))
  993. @app.route('/update')
  994. def now_update():
  995. if admin_check(None, 'update') != 1:
  996. return re_error('/error/3')
  997. curs.execute('select data from other where name = "update"')
  998. up_data = curs.fetchall()
  999. if up_data:
  1000. up_data = up_data[0][0]
  1001. else:
  1002. up_data = 'stable'
  1003. if platform.system() == 'Linux':
  1004. print('update')
  1005. os.system('git remote rm origin')
  1006. os.system('git remote add origin https://github.com/2DU/opennamu.git')
  1007. ok = os.system('git fetch origin ' + up_data)
  1008. ok = os.system('git reset --hard origin/' + up_data)
  1009. if ok == 0:
  1010. return redirect('/restart')
  1011. else:
  1012. if platform.system() == 'Windows':
  1013. print('download')
  1014. urllib.request.urlretrieve('https://github.com/2DU/opennamu/archive/' + up_data + '.zip', 'update.zip')
  1015. print('zip extract')
  1016. zipfile.ZipFile('update.zip').extractall('')
  1017. print('move')
  1018. ok = os.system('xcopy /y /r opennamu-' + up_data + ' .')
  1019. if ok == 0:
  1020. print('remove')
  1021. os.system('rd /s /q opennamu-' + up_data)
  1022. os.system('del update.zip')
  1023. return redirect('/restart')
  1024. return easy_minify(flask.render_template(skin_check(),
  1025. imp = [load_lang('update'), wiki_set(), custom(), other2([0, 0])],
  1026. data = 'auto update is not support. <a href="https://github.com/2DU/opennamu">(github)</a>',
  1027. menu = [['manager/1', load_lang('admin')]]
  1028. ))
  1029. @app.route('/xref/<everything:name>')
  1030. def xref(name = None):
  1031. num = int(flask.request.args.get('num', 1))
  1032. if num * 50 > 0:
  1033. sql_num = num * 50 - 50
  1034. else:
  1035. sql_num = 0
  1036. div = '<ul>'
  1037. curs.execute("select link, type from back where title = ? and not type = 'cat' and not type = 'no' order by link asc limit ?, '50'", [name, str(sql_num)])
  1038. data_list = curs.fetchall()
  1039. for data in data_list:
  1040. div += '<li><a href="/w/' + url_pas(data[0]) + '">' + data[0] + '</a>'
  1041. if data[1]:
  1042. div += ' (' + data[1] + ')'
  1043. curs.execute("select title from back where title = ? and type = 'include'", [data[0]])
  1044. db_data = curs.fetchall()
  1045. if db_data:
  1046. div += ' <a id="inside" href="/xref/' + url_pas(data[0]) + '">(' + load_lang('backlink') + ')</a>'
  1047. div += '</li>'
  1048. div += '</ul>' + next_fix('/xref/' + url_pas(name) + '?num=', num, data_list)
  1049. return easy_minify(flask.render_template(skin_check(),
  1050. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('backlink') + ')', 0])],
  1051. data = div,
  1052. menu = [['w/' + url_pas(name), load_lang('document')]]
  1053. ))
  1054. @app.route('/please')
  1055. def please():
  1056. num = int(flask.request.args.get('num', 1))
  1057. if num * 50 > 0:
  1058. sql_num = num * 50 - 50
  1059. else:
  1060. sql_num = 0
  1061. div = '<ul>'
  1062. var = ''
  1063. curs.execute("select distinct title from back where type = 'no' order by title asc limit ?, '50'", [str(sql_num)])
  1064. data_list = curs.fetchall()
  1065. for data in data_list:
  1066. if var != data[0]:
  1067. div += '<li><a id="not_thing" href="/w/' + url_pas(data[0]) + '">' + data[0] + '</a></li>'
  1068. var = data[0]
  1069. div += '</ul>' + next_fix('/please?num=', num, data_list)
  1070. return easy_minify(flask.render_template(skin_check(),
  1071. imp = [load_lang('need') + ' ' + load_lang('document'), wiki_set(), custom(), other2([0, 0])],
  1072. data = div,
  1073. menu = [['other', load_lang('other')]]
  1074. ))
  1075. @app.route('/recent_discuss')
  1076. def recent_discuss():
  1077. div = ''
  1078. if flask.request.args.get('what', 'normal') == 'normal':
  1079. div += '<a href="/recent_discuss?what=close">(' + load_lang('close') + ')</a>'
  1080. m_sub = 0
  1081. else:
  1082. div += '<a href="/recent_discuss">(' + load_lang('open') + ')</a>'
  1083. m_sub = ' (' + load_lang('close') + ')'
  1084. div += '''
  1085. <hr>
  1086. <table id="main_table_set">
  1087. <tbody>
  1088. <tr>
  1089. <td id="main_table_width_half">''' + load_lang('discussion') + ' ' + load_lang('name') + '''</td>
  1090. <td id="main_table_width_half">''' + load_lang('time') + '''</td>
  1091. </tr>
  1092. '''
  1093. curs.execute("select title, sub, date from rd order by date desc limit 50")
  1094. for data in curs.fetchall():
  1095. title = html.escape(data[0])
  1096. sub = html.escape(data[1])
  1097. close = 0
  1098. if flask.request.args.get('what', 'normal') == 'normal':
  1099. curs.execute("select title from stop where title = ? and sub = ? and close = 'O'", [data[0], data[1]])
  1100. if curs.fetchall():
  1101. close = 1
  1102. else:
  1103. curs.execute("select title from stop where title = ? and sub = ? and close = 'O'", [data[0], data[1]])
  1104. if not curs.fetchall():
  1105. close = 1
  1106. if close == 0:
  1107. div += '<tr><td><a href="/topic/' + url_pas(data[0]) + '/sub/' + url_pas(data[1]) + '">' + title + '</a> (' + sub + ')</td><td>' + data[2] + '</td></tr>'
  1108. else:
  1109. div += '</tbody></table>'
  1110. return easy_minify(flask.render_template(skin_check(),
  1111. imp = [load_lang('recent') + ' ' + load_lang('discussion'), wiki_set(), custom(), other2([m_sub, 0])],
  1112. data = div,
  1113. menu = 0
  1114. ))
  1115. @app.route('/block_log')
  1116. @app.route('/block_log/<regex("ip|user|never_end|can_end|end|now|edit_filter"):tool2>')
  1117. @app.route('/<regex("block_user|block_admin"):tool>/<name>')
  1118. def block_log(name = None, tool = None, tool2 = None):
  1119. num = int(flask.request.args.get('num', 1))
  1120. if num * 50 > 0:
  1121. sql_num = num * 50 - 50
  1122. else:
  1123. sql_num = 0
  1124. div = '''
  1125. <table id="main_table_set">
  1126. <tbody>
  1127. <tr>
  1128. <td id="main_table_width">''' + load_lang('blocked') + '''</td>
  1129. <td id="main_table_width">''' + load_lang('admin') + '''</td>
  1130. <td id="main_table_width">''' + load_lang('period') + '''</td>
  1131. </tr>
  1132. '''
  1133. data_list = ''
  1134. if not name:
  1135. if not tool2:
  1136. div = '''
  1137. <a href="/manager/11">(''' + load_lang('blocked') + ''')</a> <a href="/manager/12">(''' + load_lang('admin') + ''')</a>
  1138. <hr>
  1139. <a href="/block_log/ip">(ip)</a> <a href="/block_log/user">(''' + load_lang('subscriber') + ')</a> <a href="/block_log/never_end">(' + load_lang('limitless') + ')</a> <a href="/block_log/can_end">(' + load_lang('period') + ')</a> <a href="/block_log/end">(' + load_lang('release') + ')</a> <a href="/block_log/now">(' + load_lang('now') + ')</a> <a href="/block_log/edit_filter">(' + load_lang('edit') + ' ' + load_lang('filter') + ''')</a>
  1140. <hr>
  1141. ''' + div
  1142. sub = 0
  1143. menu = 0
  1144. curs.execute("select why, block, blocker, end, today from rb order by today desc limit ?, '50'", [str(sql_num)])
  1145. else:
  1146. menu = [['block_log', load_lang('normal')]]
  1147. if tool2 == 'ip':
  1148. sub = ' (ip)'
  1149. curs.execute("select why, block, blocker, end, today from rb where (block like ? or block like ?) order by today desc limit ?, '50'", ['%.%', '%:%', str(sql_num)])
  1150. elif tool2 == 'user':
  1151. sub = ' (' + load_lang('subscriber') + ')'
  1152. curs.execute("select why, block, blocker, end, today from rb where not (block like ? or block like ?) order by today desc limit ?, '50'", ['%.%', '%:%', str(sql_num)])
  1153. elif tool2 == 'never_end':
  1154. sub = '(' + load_lang('limitless') + ')'
  1155. curs.execute("select why, block, blocker, end, today from rb where not end like ? and not end like ? order by today desc limit ?, '50'", ['%:%', '%' + load_lang('release', 1) + '%', str(sql_num)])
  1156. elif tool2 == 'end':
  1157. sub = '(' + load_lang('release') + ')'
  1158. curs.execute("select why, block, blocker, end, today from rb where end = ? order by today desc limit ?, '50'", [load_lang('release', 1), str(sql_num)])
  1159. elif tool2 == 'now':
  1160. sub = '(' + load_lang('now') + ')'
  1161. data_list = []
  1162. curs.execute("select block from ban where end > ? limit ?, '50'", [get_time(), str(sql_num)])
  1163. for in_data in curs.fetchall():
  1164. curs.execute("select why, block, blocker, end, today from rb where block = ? order by today desc limit 1", [in_data[0]])
  1165. data_list = [curs.fetchall()[0]] + data_list
  1166. elif tool2 == 'edit_filter':
  1167. sub = '(' + load_lang('edit') + ' ' + load_lang('filter') + ')'
  1168. curs.execute("select why, block, blocker, end, today from rb where blocker = ? order by today desc limit ?, '50'", [load_lang('tool', 1) + ':' + load_lang('edit', 1) + ' ' + load_lang('filter', 1), str(sql_num)])
  1169. else:
  1170. sub = '(' + load_lang('period') + ')'
  1171. curs.execute("select why, block, blocker, end, today from rb where end like ? order by today desc limit ?, '50'", ['%\-%', str(sql_num)])
  1172. else:
  1173. menu = [['block_log', load_lang('normal')]]
  1174. if tool == 'block_user':
  1175. sub = ' (' + load_lang('blocked') + ')'
  1176. curs.execute("select why, block, blocker, end, today from rb where block = ? order by today desc limit ?, '50'", [name, str(sql_num)])
  1177. else:
  1178. sub = ' (' + load_lang('admin') + ')'
  1179. curs.execute("select why, block, blocker, end, today from rb where blocker = ? order by today desc limit ?, '50'", [name, str(sql_num)])
  1180. if data_list == '':
  1181. data_list = curs.fetchall()
  1182. for data in data_list:
  1183. why = html.escape(data[0])
  1184. if why == '':
  1185. why = '<br>'
  1186. band = re.search("^([0-9]{1,3}\.[0-9]{1,3})$", data[1])
  1187. if band:
  1188. ip = data[1] + ' (' + load_lang('band') + ')'
  1189. else:
  1190. ip = ip_pas(data[1])
  1191. if data[3] != '':
  1192. end = data[3]
  1193. else:
  1194. end = load_lang('limitless') + ''
  1195. div += '''
  1196. <tr>
  1197. <td>''' + ip + '''</td>
  1198. <td>''' + ip_pas(data[2]) + '''</td>
  1199. <td>
  1200. start : ''' + data[4] + '''
  1201. <br>
  1202. end : ''' + end + '''
  1203. </td>
  1204. </tr>
  1205. <tr>
  1206. <td colspan="3">''' + why + '''</td>
  1207. </tr>
  1208. </tbody>
  1209. </table>
  1210. '''
  1211. if not name:
  1212. if not tool2:
  1213. div += next_fix('/block_log?num=', num, data_list)
  1214. else:
  1215. div += next_fix('/block_log/' + url_pas(tool2) + '?num=', num, data_list)
  1216. else:
  1217. div += next_fix('/' + url_pas(tool) + '/' + url_pas(name) + '?num=', num, data_list)
  1218. return easy_minify(flask.render_template(skin_check(),
  1219. imp = [load_lang('recent') + ' ' + load_lang('ban'), wiki_set(), custom(), other2([sub, 0])],
  1220. data = div,
  1221. menu = menu
  1222. ))
  1223. @app.route('/search', methods=['POST'])
  1224. def search():
  1225. return redirect('/search/' + url_pas(flask.request.form.get('search', None)))
  1226. @app.route('/goto', methods=['POST'])
  1227. def goto():
  1228. curs.execute("select title from data where title = ?", [flask.request.form.get('search', None)])
  1229. data = curs.fetchall()
  1230. if data:
  1231. return redirect('/w/' + url_pas(flask.request.form.get('search', None)))
  1232. else:
  1233. return redirect('/search/' + url_pas(flask.request.form.get('search', None)))
  1234. @app.route('/search/<everything:name>')
  1235. def deep_search(name = None):
  1236. num = int(flask.request.args.get('num', 1))
  1237. if num * 50 > 0:
  1238. sql_num = num * 50 - 50
  1239. else:
  1240. sql_num = 0
  1241. div = '<ul>'
  1242. div_plus = ''
  1243. test = ''
  1244. curs.execute("select title from data where title = ?", [name])
  1245. if curs.fetchall():
  1246. div = '<ul><li><a href="/w/' + url_pas(name) + '">' + name + '</a></li></ul><hr><ul>'
  1247. else:
  1248. div = '<ul><li><a id="not_thing" href="/w/' + url_pas(name) + '">' + name + '</a></li></ul><hr><ul>'
  1249. curs.execute("select distinct title, case when title like ? then '제목' else '내용' end from data where title like ? or data like ? order by case when title like ? then 1 else 2 end limit ?, '50'", ['%' + name + '%', '%' + name + '%', '%' + name + '%', '%' + name + '%', str(sql_num)])
  1250. all_list = curs.fetchall()
  1251. if all_list:
  1252. test = all_list[0][1]
  1253. for data in all_list:
  1254. if data[1] != test:
  1255. div_plus += '</ul><hr><ul>'
  1256. test = data[1]
  1257. div_plus += '<li><a href="/w/' + url_pas(data[0]) + '">' + data[0] + '</a> (' + data[1] + ')</li>'
  1258. else:
  1259. div += '<li>-</li>'
  1260. div += div_plus + '</ul>'
  1261. div += next_fix('/search/' + url_pas(name) + '?num=', num, all_list)
  1262. return easy_minify(flask.render_template(skin_check(),
  1263. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('search') + ')', 0])],
  1264. data = div,
  1265. menu = 0
  1266. ))
  1267. @app.route('/raw/<everything:name>')
  1268. @app.route('/topic/<everything:name>/sub/<sub_title>/raw/<int:num>')
  1269. def raw_view(name = None, sub_title = None, num = None):
  1270. v_name = name
  1271. sub = ' (' + load_lang('raw') + ')'
  1272. if not num:
  1273. num = flask.request.args.get('num', None)
  1274. if num:
  1275. num = int(num)
  1276. if not sub_title and num:
  1277. curs.execute("select title from history where title = ? and id = ? and hide = 'O'", [name, str(num)])
  1278. if curs.fetchall() and admin_check(6, None) != 1:
  1279. return re_error('/error/3')
  1280. curs.execute("select data from history where title = ? and id = ?", [name, str(num)])
  1281. sub += ' (' + str(num) + load_lang('version') + ')'
  1282. menu = [['history/' + url_pas(name), load_lang('history')]]
  1283. elif sub_title:
  1284. curs.execute("select data from topic where id = ? and title = ? and sub = ? and block = ''", [str(num), name, sub_title])
  1285. v_name = load_lang('discussion') + ' Raw'
  1286. sub = ' (' + str(num) + ')'
  1287. menu = [['topic/' + url_pas(name) + '/sub/' + url_pas(sub_title) + '#' + str(num), load_lang('discussion')], ['topic/' + url_pas(name) + '/sub/' + url_pas(sub_title) + '/admin/' + str(num), load_lang('tool')]]
  1288. else:
  1289. curs.execute("select data from data where title = ?", [name])
  1290. menu = [['w/' + url_pas(name), load_lang('document')]]
  1291. data = curs.fetchall()
  1292. if data:
  1293. p_data = html.escape(data[0][0])
  1294. p_data = '<textarea readonly rows="25">' + p_data + '</textarea>'
  1295. return easy_minify(flask.render_template(skin_check(),
  1296. imp = [v_name, wiki_set(), custom(), other2([sub, 0])],
  1297. data = p_data,
  1298. menu = menu
  1299. ))
  1300. else:
  1301. return redirect('/w/' + url_pas(name))
  1302. @app.route('/revert/<everything:name>', methods=['POST', 'GET'])
  1303. def revert(name = None):
  1304. num = int(flask.request.args.get('num', 0))
  1305. curs.execute("select title from history where title = ? and id = ? and hide = 'O'", [name, str(num)])
  1306. if curs.fetchall() and admin_check(6, None) != 1:
  1307. return re_error('/error/3')
  1308. if acl_check(name) == 1:
  1309. return re_error('/ban')
  1310. if flask.request.method == 'POST':
  1311. if captcha_post(flask.request.form.get('g-recaptcha-response', '')) == 1:
  1312. return re_error('/error/13')
  1313. else:
  1314. captcha_post('', 0)
  1315. curs.execute("select data from history where title = ? and id = ?", [name, str(num)])
  1316. data = curs.fetchall()
  1317. if data:
  1318. if edit_filter_do(data[0][0]) == 1:
  1319. return re_error('/error/21')
  1320. curs.execute("delete from back where link = ?", [name])
  1321. conn.commit()
  1322. if data:
  1323. curs.execute("select data from data where title = ?", [name])
  1324. data_old = curs.fetchall()
  1325. if data_old:
  1326. leng = leng_check(len(data_old[0][0]), len(data[0][0]))
  1327. curs.execute("update data set data = ? where title = ?", [data[0][0], name])
  1328. else:
  1329. leng = '+' + str(len(data[0][0]))
  1330. curs.execute("insert into data (title, data) values (?, ?)", [name, data[0][0]])
  1331. history_plus(
  1332. name,
  1333. data[0][0],
  1334. get_time(),
  1335. ip_check(),
  1336. flask.request.form.get('send', None) + ' (' + str(num) + load_lang('version', 1) + ')',
  1337. leng
  1338. )
  1339. render_set(
  1340. title = name,
  1341. data = data[0][0],
  1342. num = 1
  1343. )
  1344. conn.commit()
  1345. return redirect('/w/' + url_pas(name))
  1346. else:
  1347. curs.execute("select title from history where title = ? and id = ?", [name, str(num)])
  1348. if not curs.fetchall():
  1349. return redirect('/w/' + url_pas(name))
  1350. return easy_minify(flask.render_template(skin_check(),
  1351. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('revert') + ')', 0])],
  1352. data = '''
  1353. <form method="post">
  1354. <span>''' + flask.request.args.get('num', '0') + load_lang('version') + '''</span>
  1355. <hr>
  1356. ''' + ip_warring() + '''
  1357. <input placeholder="''' + load_lang('why') + '''" name="send" type="text">
  1358. <hr>
  1359. ''' + captcha_get() + '''
  1360. <button type="submit">''' + load_lang('revert') + '''</button>
  1361. </form>
  1362. ''',
  1363. menu = [['history/' + url_pas(name), load_lang('history')], ['recent_changes', load_lang('recent') + ' ' + load_lang('change')]]
  1364. ))
  1365. @app.route('/edit/<everything:name>', methods=['POST', 'GET'])
  1366. def edit(name = None):
  1367. ip = ip_check()
  1368. if acl_check(name) == 1:
  1369. return re_error('/ban')
  1370. if flask.request.method == 'POST':
  1371. if captcha_post(flask.request.form.get('g-recaptcha-response', '')) == 1:
  1372. return re_error('/error/13')
  1373. else:
  1374. captcha_post('', 0)
  1375. if len(flask.request.form.get('send', None)) > 500:
  1376. return re_error('/error/15')
  1377. if flask.request.form.get('otent', None) == flask.request.form.get('content', None):
  1378. return redirect('/w/' + url_pas(name))
  1379. if edit_filter_do(flask.request.form.get('content', '')) == 1:
  1380. return re_error('/error/21')
  1381. today = get_time()
  1382. content = savemark(flask.request.form.get('content', None))
  1383. curs.execute("select data from data where title = ?", [name])
  1384. old = curs.fetchall()
  1385. if old:
  1386. leng = leng_check(len(flask.request.form.get('otent', None)), len(content))
  1387. if flask.request.args.get('section', None):
  1388. content = old[0][0].replace(flask.request.form.get('otent', None), content)
  1389. curs.execute("update data set data = ? where title = ?", [content, name])
  1390. else:
  1391. leng = '+' + str(len(content))
  1392. curs.execute("insert into data (title, data) values (?, ?)", [name, content])
  1393. curs.execute("select user from scan where title = ?", [name])
  1394. for _ in curs.fetchall():
  1395. curs.execute("insert into alarm (name, data, date) values (?, ?, ?)", [ip, ip + ' - <a href="/w/' + url_pas(name) + '">' + name + '</a> (Edit)', today])
  1396. history_plus(
  1397. name,
  1398. content,
  1399. today,
  1400. ip,
  1401. flask.request.form.get('send', None),
  1402. leng
  1403. )
  1404. curs.execute("delete from back where link = ?", [name])
  1405. curs.execute("delete from back where title = ? and type = 'no'", [name])
  1406. render_set(
  1407. title = name,
  1408. data = content,
  1409. num = 1
  1410. )
  1411. conn.commit()
  1412. return redirect('/w/' + url_pas(name))
  1413. else:
  1414. curs.execute("select data from data where title = ?", [name])
  1415. new = curs.fetchall()
  1416. if new:
  1417. if flask.request.args.get('section', None):
  1418. test_data = '\n' + re.sub('\r\n', '\n', new[0][0]) + '\n'
  1419. section_data = re.findall('((?:={1,6}) ?(?:(?:(?!={1,6}\n).)+) ?={1,6}\n(?:(?:(?!(?:={1,6}) ?(?:(?:(?!={1,6}\n).)+) ?={1,6}\n).)*\n*)*)', test_data)
  1420. data = section_data[int(flask.request.args.get('section', None)) - 1]
  1421. else:
  1422. data = new[0][0]
  1423. else:
  1424. data = ''
  1425. data_old = data
  1426. if not flask.request.args.get('section', None):
  1427. get_name = '''
  1428. <a href="/manager/15?plus=''' + url_pas(name) + '">(' + load_lang('load') + ')</a> <a href="/edit_filter">(' + load_lang('edit') + ' ' + load_lang('filter') + ''')</a>
  1429. <hr>
  1430. '''
  1431. action = ''
  1432. else:
  1433. get_name = ''
  1434. action = '?section=' + flask.request.args.get('section', None)
  1435. if flask.request.args.get('plus', None):
  1436. curs.execute("select data from data where title = ?", [flask.request.args.get('plus', None)])
  1437. get_data = curs.fetchall()
  1438. if get_data:
  1439. data = get_data[0][0]
  1440. get_name = ''
  1441. js_data = edit_help_button()
  1442. return easy_minify(flask.render_template(skin_check(),
  1443. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('edit') + ')', 0])],
  1444. data = get_name + js_data[0] + '''
  1445. <form method="post" action="/edit/''' + url_pas(name) + action + '''">
  1446. ''' + js_data[1] + '''
  1447. <textarea id="content" rows="25" name="content">''' + html.escape(re.sub('\n$', '', data)) + '''</textarea>
  1448. <textarea style="display: none;" name="otent">''' + html.escape(re.sub('\n$', '', data_old)) + '''</textarea>
  1449. <hr>
  1450. <input placeholder="''' + load_lang('why') + '''" name="send" type="text">
  1451. <hr>
  1452. ''' + captcha_get() + ip_warring() + '''
  1453. <button id="save" type="submit">''' + load_lang('save') + '''</button>
  1454. <button id="preview" type="submit" formaction="/preview/''' + url_pas(name) + action + '">' + load_lang('preview') + '''</button>
  1455. </form>
  1456. ''',
  1457. menu = [['w/' + url_pas(name), load_lang('document')], ['delete/' + url_pas(name), load_lang('delete')], ['move/' + url_pas(name), load_lang('move')]]
  1458. ))
  1459. @app.route('/preview/<everything:name>', methods=['POST'])
  1460. def preview(name = None):
  1461. if acl_check(name) == 1:
  1462. return re_error('/ban')
  1463. new_data = re.sub('^\r\n', '', flask.request.form.get('content', None))
  1464. new_data = re.sub('\r\n$', '', new_data)
  1465. end_data = render_set(
  1466. title = name,
  1467. data = new_data
  1468. )
  1469. if flask.request.args.get('section', None):
  1470. action = '?section=' + flask.request.args.get('section', None)
  1471. else:
  1472. action = ''
  1473. js_data = edit_help_button()
  1474. return easy_minify(flask.render_template(skin_check(),
  1475. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('preview') + ')', 0])],
  1476. data = '<a href="/edit_filter">(' + load_lang('edit') + ' ' + load_lang('filter') + ')</a>' + js_data[0] + '''
  1477. <form method="post" action="/edit/''' + url_pas(name) + action + '''">
  1478. ''' + js_data[1] + '''
  1479. <textarea id="content" rows="25" name="content">''' + html.escape(flask.request.form.get('content', None)) + '''</textarea>
  1480. <textarea style="display: none;" name="otent">''' + html.escape(flask.request.form.get('otent', None)) + '''</textarea>
  1481. <hr>
  1482. <input placeholder="''' + load_lang('why') + '''" name="send" type="text">
  1483. <hr>
  1484. ''' + captcha_get() + '''
  1485. <button id="save" type="submit">''' + load_lang('save') + '''</button>
  1486. <button id="preview" type="submit" formaction="/preview/''' + url_pas(name) + action + '">' + load_lang('preview') + '''</button>
  1487. </form>
  1488. <hr>
  1489. ''' + end_data,
  1490. menu = [['w/' + url_pas(name), load_lang('document')]]
  1491. ))
  1492. @app.route('/delete/<everything:name>', methods=['POST', 'GET'])
  1493. def delete(name = None):
  1494. ip = ip_check()
  1495. if acl_check(name) == 1:
  1496. return re_error('/ban')
  1497. if flask.request.method == 'POST':
  1498. if captcha_post(flask.request.form.get('g-recaptcha-response', '')) == 1:
  1499. return re_error('/error/13')
  1500. else:
  1501. captcha_post('', 0)
  1502. curs.execute("select data from data where title = ?", [name])
  1503. data = curs.fetchall()
  1504. if data:
  1505. today = get_time()
  1506. leng = '-' + str(len(data[0][0]))
  1507. history_plus(
  1508. name,
  1509. '',
  1510. today,
  1511. ip,
  1512. flask.request.form.get('send', None) + ' (' + load_lang('delete', 1) + ')',
  1513. leng
  1514. )
  1515. curs.execute("select title, link from back where title = ? and not type = 'cat' and not type = 'no'", [name])
  1516. for data in curs.fetchall():
  1517. curs.execute("insert into back (title, link, type) values (?, ?, 'no')", [data[0], data[1]])
  1518. curs.execute("delete from back where link = ?", [name])
  1519. curs.execute("delete from data where title = ?", [name])
  1520. conn.commit()
  1521. return redirect('/w/' + url_pas(name))
  1522. else:
  1523. curs.execute("select title from data where title = ?", [name])
  1524. if not curs.fetchall():
  1525. return redirect('/w/' + url_pas(name))
  1526. return easy_minify(flask.render_template(skin_check(),
  1527. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('delete') + ')', 0])],
  1528. data = '''
  1529. <form method="post">
  1530. ''' + ip_warring() + '''
  1531. <input placeholder="''' + load_lang('why') + '''" name="send" type="text">
  1532. <hr>
  1533. ''' + captcha_get() + '''
  1534. <button type="submit">''' + load_lang('delete') + '''</button>
  1535. </form>
  1536. ''',
  1537. menu = [['w/' + url_pas(name), load_lang('document')]]
  1538. ))
  1539. @app.route('/move_data/<everything:name>')
  1540. def move_data(name = None):
  1541. data = '<ul>'
  1542. curs.execute("select send, date, ip from history where send like ? or send like ? order by date desc", ['%<a>' + name + '</a> ' + load_lang('move', 1) + ')%', '%(<a>' + name + '</a>%'])
  1543. for for_data in curs.fetchall():
  1544. match = re.findall('<a>((?:(?!<\/a>).)+)<\/a>', for_data[0])
  1545. send = re.sub('\([^\)]+\)$', '', for_data[0])
  1546. data += '<li><a href="/move_data/' + url_pas(match[0]) + '">' + match[0] + '</a> - <a href="/move_data/' + url_pas(match[1]) + '">' + match[1] + '</a>'
  1547. if re.search('^( *)+$', send):
  1548. data += ' / ' + for_data[2] + ' / ' + for_data[1] + '</li>'
  1549. else:
  1550. data += ' / ' + for_data[2] + ' / ' + for_data[1] + ' / ' + send + '</li>'
  1551. data += '</ul>'
  1552. return easy_minify(flask.render_template(skin_check(),
  1553. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('move') + ' ' + load_lang('history') + ')', 0])],
  1554. data = data,
  1555. menu = [['history/' + url_pas(name), load_lang('history')]]
  1556. ))
  1557. @app.route('/move/<everything:name>', methods=['POST', 'GET'])
  1558. def move(name = None):
  1559. if acl_check(name) == 1:
  1560. return re_error('/ban')
  1561. if flask.request.method == 'POST':
  1562. if captcha_post(flask.request.form.get('g-recaptcha-response', '')) == 1:
  1563. return re_error('/error/13')
  1564. else:
  1565. captcha_post('', 0)
  1566. curs.execute("select title from history where title = ?", [flask.request.form.get('title', None)])
  1567. if curs.fetchall():
  1568. if admin_check(None, 'merge documents') == 1:
  1569. curs.execute("select data from data where title = ?", [flask.request.form.get('title', None)])
  1570. data = curs.fetchall()
  1571. if data:
  1572. curs.execute("delete from data where title = ?", [flask.request.form.get('title', None)])
  1573. curs.execute("delete from back where link = ?", [flask.request.form.get('title', None)])
  1574. curs.execute("select data from data where title = ?", [name])
  1575. data = curs.fetchall()
  1576. if data:
  1577. curs.execute("update data set title = ? where title = ?", [flask.request.form.get('title', None), name])
  1578. curs.execute("update back set link = ? where link = ?", [flask.request.form.get('title', None), name])
  1579. data_in = data[0][0]
  1580. else:
  1581. data_in = ''
  1582. history_plus(
  1583. name,
  1584. data_in,
  1585. get_time(),
  1586. ip_check(),
  1587. flask.request.form.get('send', None) + ' (marge <a>' + name + '</a> - <a>' + flask.request.form.get('title', None) + '</a> ' + load_lang('move', 1) + ')',
  1588. '0'
  1589. )
  1590. curs.execute("update back set type = 'no' where title = ? and not type = 'cat' and not type = 'no'", [name])
  1591. curs.execute("delete from back where title = ? and not type = 'cat' and type = 'no'", [flask.request.form.get('title', None)])
  1592. curs.execute("select id from history where title = ? order by id + 0 desc limit 1", [flask.request.form.get('title', None)])
  1593. data = curs.fetchall()
  1594. num = data[0][0]
  1595. curs.execute("select id from history where title = ? order by id + 0 asc", [name])
  1596. data = curs.fetchall()
  1597. for move in data:
  1598. curs.execute("update history set title = ?, id = ? where title = ? and id = ?", [flask.request.form.get('title', None), str(int(num) + int(move[0])), name, move[0]])
  1599. conn.commit()
  1600. return redirect('/w/' + url_pas(flask.request.form.get('title', None)))
  1601. else:
  1602. return re_error('/error/19')
  1603. else:
  1604. curs.execute("select data from data where title = ?", [name])
  1605. data = curs.fetchall()
  1606. if data:
  1607. curs.execute("update data set title = ? where title = ?", [flask.request.form.get('title', None), name])
  1608. curs.execute("update back set link = ? where link = ?", [flask.request.form.get('title', None), name])
  1609. data_in = data[0][0]
  1610. else:
  1611. data_in = ''
  1612. history_plus(
  1613. name,
  1614. data_in,
  1615. get_time(),
  1616. ip_check(),
  1617. flask.request.form.get('send', None) + ' (<a>' + name + '</a> - <a>' + flask.request.form.get('title', None) + '</a> ' + load_lang('move', 1) + ')',
  1618. '0'
  1619. )
  1620. curs.execute("update back set type = 'no' where title = ? and not type = 'cat' and not type = 'no'", [name])
  1621. curs.execute("delete from back where title = ? and not type = 'cat' and type = 'no'", [flask.request.form.get('title', None)])
  1622. curs.execute("update history set title = ? where title = ?", [flask.request.form.get('title', None), name])
  1623. conn.commit()
  1624. return redirect('/w/' + url_pas(flask.request.form.get('title', None)))
  1625. else:
  1626. return easy_minify(flask.render_template(skin_check(),
  1627. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('move') + ')', 0])],
  1628. data = '''
  1629. <form method="post">
  1630. ''' + ip_warring() + '''
  1631. <input placeholder="''' + load_lang('document') + ' ' + load_lang('name') + '" value="' + name + '''" name="title" type="text">
  1632. <hr>
  1633. <input placeholder="''' + load_lang('why') + '''" name="send" type="text">
  1634. <hr>
  1635. ''' + captcha_get() + '''
  1636. <button type="submit">''' + load_lang('move') + '''</button>
  1637. </form>
  1638. ''',
  1639. menu = [['w/' + url_pas(name), load_lang('document')]]
  1640. ))
  1641. @app.route('/other')
  1642. def other():
  1643. return easy_minify(flask.render_template(skin_check(),
  1644. imp = [load_lang('other') + ' ' + load_lang('tool'), wiki_set(), custom(), other2([0, 0])],
  1645. data = '''
  1646. <h2>''' + load_lang('record') + '''</h2>
  1647. <ul>
  1648. <li><a href="/manager/6">''' + load_lang('edit') + '''</a></li>
  1649. <li><a href="/manager/7">''' + load_lang('discussion') + '''</a></li>
  1650. </ul>
  1651. <br>
  1652. <h2>''' + load_lang('list') + '''</h2>
  1653. <ul>
  1654. <li><a href="/admin_list">''' + load_lang('admin') + '''</a></li>
  1655. <li><a href="/give_log">''' + load_lang('admin_group') + '''</a></li>
  1656. <li><a href="/not_close_topic">''' + load_lang('open') + ' ' + load_lang('discussion') + '''</a></li>
  1657. <li><a href="/title_index">''' + load_lang('all') + ' ' + load_lang('document') + '''</a></li>
  1658. <li><a href="/acl_list">acl ''' + load_lang('document') + '''</a></li>
  1659. <li><a href="/please">''' + load_lang('need') + ' ' + load_lang('document') + '''</a></li>
  1660. </ul>
  1661. <br>
  1662. <h2>''' + load_lang('other') + '''</h2>
  1663. <ul>
  1664. <li><a href="/upload">''' + load_lang('upload') + '''</a></li>
  1665. <li><a href="/manager/10">''' + load_lang('document') + ' ' + load_lang('search') + '''</a></li>
  1666. </ul>
  1667. <br>
  1668. <h2>''' + load_lang('admin') + '''</h2>
  1669. <ul>
  1670. <li><a href="/manager/1">''' + load_lang('admin') + ' ' + load_lang('tool') + '''</a></li>
  1671. </ul>
  1672. <br>
  1673. <h2>''' + load_lang('normal_version') + '''</h2>
  1674. <ul>
  1675. <li>''' + load_lang('normal_version') + ' : <a id="out_link" href="https://github.com/2DU/opennamu/blob/master/version.md">' + r_ver + '''</a></li>
  1676. </ul>
  1677. ''',
  1678. menu = 0
  1679. ))
  1680. @app.route('/manager', methods=['POST', 'GET'])
  1681. @app.route('/manager/<int:num>', methods=['POST', 'GET'])
  1682. def manager(num = 1):
  1683. title_list = {
  1684. 0 : [load_lang('document') + ' ' + load_lang('name'), 'acl'],
  1685. 1 : [0, 'check'],
  1686. 2 : [0, 'ban'],
  1687. 3 : [0, 'admin'],
  1688. 4 : [0, 'record'],
  1689. 5 : [0, 'topic_record'],
  1690. 6 : [load_lang('name'), 'admin_plus'],
  1691. 7 : [load_lang('name'), 'plus_edit_filter'],
  1692. 8 : [load_lang('document') + ' ' + load_lang('name'), 'search'],
  1693. 9 : [0, 'block_user'],
  1694. 10 : [0, 'block_admin'],
  1695. 11 : [load_lang('document') + ' ' + load_lang('name'), 'watch_list'],
  1696. 12 : [load_lang('compare'), 'check'],
  1697. 13 : [load_lang('document') + ' ' + load_lang('name'), 'edit']
  1698. }
  1699. if num == 1:
  1700. return easy_minify(flask.render_template(skin_check(),
  1701. imp = [load_lang('admin') + ' ' + load_lang('tool'), wiki_set(), custom(), other2([0, 0])],
  1702. data = '''
  1703. <h2>''' + load_lang('admin') + '''</h2>
  1704. <ul>
  1705. <li><a href="/manager/2">''' + load_lang('document') + ''' acl</a></li>
  1706. <li><a href="/manager/3">''' + load_lang('user') + ' ' + load_lang('check') + '''</a></li>
  1707. <li><a href="/manager/4">''' + load_lang('user') + ' ' + load_lang('ban') + '''</a></li>
  1708. <li><a href="/manager/5">''' + load_lang('subscriber') + ' ' + load_lang('authority') + '''</a></li>
  1709. <li><a href="/edit_filter">''' + load_lang('edit') + ' ' + load_lang('filter') + '''</a></li>
  1710. </ul>
  1711. <br>
  1712. <h2>''' + load_lang('owner') + '''</h2>
  1713. <ul>
  1714. <li><a href="/manager/8">''' + load_lang('admin_group') + ' ' + load_lang('create') + '''</a></li>
  1715. <li><a href="/setting">''' + load_lang('setting') + ' ' + load_lang('edit') + '''</a></li>
  1716. <li><a href="/inter_wiki">''' + load_lang('interwiki') + '''</a></li>
  1717. <li><a href="/html_filter">html ''' + load_lang('filter') + '''</a></li>
  1718. <li><a href="/email_filter">email ''' + load_lang('filter') + '''</a></li>
  1719. </ul>
  1720. <br>
  1721. <h2>''' + load_lang('server') + '''</h2>
  1722. <ul>
  1723. <li><a href="/indexing">''' + load_lang('indexing') + ' (' + load_lang('create') + ' or ' + load_lang('delete') + ''')</a></li>
  1724. <li><a href="/restart">''' + load_lang('server') + ' ' + load_lang('restart') + '''</a></li>
  1725. <li><a href="/update">''' + load_lang('update') + '''</a></li>
  1726. </ul>
  1727. ''',
  1728. menu = [['other', load_lang('other')]]
  1729. ))
  1730. elif not num - 1 > len(title_list):
  1731. if flask.request.method == 'POST':
  1732. if flask.request.args.get('plus', None):
  1733. return redirect('/' + title_list[(num - 2)][1] + '/' + url_pas(flask.request.args.get('plus', None)) + '?plus=' + flask.request.form.get('name', None))
  1734. else:
  1735. return redirect('/' + title_list[(num - 2)][1] + '/' + url_pas(flask.request.form.get('name', None)))
  1736. else:
  1737. if title_list[(num - 2)][0] == 0:
  1738. placeholder = load_lang('user') + ' ' + load_lang('name')
  1739. else:
  1740. placeholder = title_list[(num - 2)][0]
  1741. return easy_minify(flask.render_template(skin_check(),
  1742. imp = ['Redirect', wiki_set(), custom(), other2([0, 0])],
  1743. data = '''
  1744. <form method="post">
  1745. <input placeholder="''' + placeholder + '''" name="name" type="text">
  1746. <hr>
  1747. <button type="submit">''' + load_lang('move') + '''</button>
  1748. </form>
  1749. ''',
  1750. menu = [['manager', load_lang('admin')]]
  1751. ))
  1752. else:
  1753. return redirect('/')
  1754. @app.route('/title_index')
  1755. def title_index():
  1756. page = int(flask.request.args.get('page', 1))
  1757. num = int(flask.request.args.get('num', 100))
  1758. if page * num > 0:
  1759. sql_num = page * num - num
  1760. else:
  1761. sql_num = 0
  1762. all_list = sql_num + 1
  1763. if num > 1000:
  1764. return re_error('/error/3')
  1765. data = '<a href="/title_index?num=250">(250)</a> <a href="/title_index?num=500">(500)</a> <a href="/title_index?num=1000">(1000)</a>'
  1766. curs.execute("select title from data order by title asc limit ?, ?", [str(sql_num), str(num)])
  1767. title_list = curs.fetchall()
  1768. if title_list:
  1769. data += '<hr><ul>'
  1770. for list_data in title_list:
  1771. data += '<li>' + str(all_list) + '. <a href="/w/' + url_pas(list_data[0]) + '">' + list_data[0] + '</a></li>'
  1772. all_list += 1
  1773. if page == 1:
  1774. count_end = []
  1775. curs.execute("select count(title) from data")
  1776. count = curs.fetchall()
  1777. if count:
  1778. count_end += [count[0][0]]
  1779. else:
  1780. count_end += [0]
  1781. sql_list = [load_lang('template', 1) + ':', 'category:', 'user:', 'file:']
  1782. for sql in sql_list:
  1783. curs.execute("select count(title) from data where title like ?", [sql + '%'])
  1784. count = curs.fetchall()
  1785. if count:
  1786. count_end += [count[0][0]]
  1787. else:
  1788. count_end += [0]
  1789. count_end += [count_end[0] - count_end[1] - count_end[2] - count_end[3] - count_end[4]]
  1790. data += '</ul><hr><ul><li>all : ' + str(count_end[0]) + '</li></ul><hr><ul>'
  1791. data += '<li>' + load_lang('template') + ' : ' + str(count_end[1]) + '</li>'
  1792. data += '<li>' + load_lang('category') + ' : ' + str(count_end[2]) + '</li>'
  1793. data += '<li>' + load_lang('user') + ' : ' + str(count_end[3]) + '</li>'
  1794. data += '<li>' + load_lang('file') + ' : ' + str(count_end[4]) + '</li>'
  1795. data += '<li>other : ' + str(count_end[5]) + '</li>'
  1796. data += '</ul>' + next_fix('/title_index?num=' + str(num) + '&page=', page, title_list, num)
  1797. sub = ' (' + str(num) + ')'
  1798. return easy_minify(flask.render_template(skin_check(),
  1799. imp = [load_lang('all') + ' ' + load_lang('document'), wiki_set(), custom(), other2([sub, 0])],
  1800. data = data,
  1801. menu = [['other', load_lang('other')]]
  1802. ))
  1803. @app.route('/topic/<everything:name>/sub/<sub>/b/<int:num>')
  1804. def topic_block(name = None, sub = None, num = None):
  1805. if admin_check(3, 'blind (' + name + ' - ' + sub + '#' + str(num) + ')') != 1:
  1806. return re_error('/error/3')
  1807. curs.execute("select block from topic where title = ? and sub = ? and id = ?", [name, sub, str(num)])
  1808. block = curs.fetchall()
  1809. if block:
  1810. if block[0][0] == 'O':
  1811. curs.execute("update topic set block = '' where title = ? and sub = ? and id = ?", [name, sub, str(num)])
  1812. else:
  1813. curs.execute("update topic set block = 'O' where title = ? and sub = ? and id = ?", [name, sub, str(num)])
  1814. rd_plus(name, sub, get_time())
  1815. conn.commit()
  1816. return redirect('/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '#' + str(num))
  1817. @app.route('/topic/<everything:name>/sub/<sub>/notice/<int:num>')
  1818. def topic_top(name = None, sub = None, num = None):
  1819. if admin_check(3, 'notice (' + name + ' - ' + sub + '#' + str(num) + ')') != 1:
  1820. return re_error('/error/3')
  1821. curs.execute("select title from topic where title = ? and sub = ? and id = ?", [name, sub, str(num)])
  1822. if curs.fetchall():
  1823. curs.execute("select top from topic where id = ? and title = ? and sub = ?", [str(num), name, sub])
  1824. top_data = curs.fetchall()
  1825. if top_data:
  1826. if top_data[0][0] == 'O':
  1827. curs.execute("update topic set top = '' where title = ? and sub = ? and id = ?", [name, sub, str(num)])
  1828. else:
  1829. curs.execute("update topic set top = 'O' where title = ? and sub = ? and id = ?", [name, sub, str(num)])
  1830. rd_plus(name, sub, get_time())
  1831. conn.commit()
  1832. return redirect('/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '#' + str(num))
  1833. @app.route('/topic/<everything:name>/sub/<sub>/tool/<regex("close|stop|agree"):tool>')
  1834. def topic_stop(name = None, sub = None, tool = None):
  1835. if tool == 'close':
  1836. set_list = [
  1837. 'O',
  1838. '',
  1839. load_lang('discussion', 1) + ' ' + load_lang('close', 1),
  1840. load_lang('discussion', 1) + ' ' + load_lang('open', 1)
  1841. ]
  1842. elif tool == 'stop':
  1843. set_list = [
  1844. '',
  1845. 'O',
  1846. load_lang('discussion', 1) + ' ' + load_lang('stop', 1),
  1847. load_lang('discussion', 1) + ' ' + load_lang('restart', 1)
  1848. ]
  1849. elif tool == 'agree':
  1850. pass
  1851. else:
  1852. return redirect('/topic/' + url_pas(name) + '/sub/' + url_pas(sub))
  1853. if admin_check(3, 'topic ' + tool + ' (' + name + ' - ' + sub + ')') != 1:
  1854. return re_error('/error/3')
  1855. ip = ip_check()
  1856. time = get_time()
  1857. curs.execute("select id from topic where title = ? and sub = ? order by id + 0 desc limit 1", [name, sub])
  1858. topic_check = curs.fetchall()
  1859. if topic_check:
  1860. if tool == 'agree':
  1861. curs.execute("select title from agreedis where title = ? and sub = ?", [name, sub])
  1862. if curs.fetchall():
  1863. curs.execute("insert into topic (id, title, sub, data, date, ip, block, top) values (?, ?, ?, '" + load_lang('agreement', 1) + " X', ?, ?, '', '1')", [str(int(topic_check[0][0]) + 1), name, sub, time, ip])
  1864. curs.execute("delete from agreedis where title = ? and sub = ?", [name, sub])
  1865. else:
  1866. curs.execute("insert into topic (id, title, sub, data, date, ip, block, top) values (?, ?, ?, '" + load_lang('agreement', 1) + " O', ?, ?, '', '1')", [str(int(topic_check[0][0]) + 1), name, sub, time, ip])
  1867. curs.execute("insert into agreedis (title, sub) values (?, ?)", [name, sub])
  1868. else:
  1869. curs.execute("select title from stop where title = ? and sub = ? and close = ?", [name, sub, set_list[0]])
  1870. if curs.fetchall():
  1871. curs.execute("insert into topic (id, title, sub, data, date, ip, block, top) values (?, ?, ?, ?, ?, ?, '', '1')", [str(int(topic_check[0][0]) + 1), name, sub, set_list[3], time, ip])
  1872. curs.execute("delete from stop where title = ? and sub = ? and close = ?", [name, sub, set_list[0]])
  1873. else:
  1874. curs.execute("insert into topic (id, title, sub, data, date, ip, block, top) values (?, ?, ?, ?, ?, ?, '', '1')", [str(int(topic_check[0][0]) + 1), name, sub, set_list[2], time, ip])
  1875. curs.execute("insert into stop (title, sub, close) values (?, ?, ?)", [name, sub, set_list[0]])
  1876. curs.execute("delete from stop where title = ? and sub = ? and close = ?", [name, sub, set_list[1]])
  1877. rd_plus(name, sub, time)
  1878. conn.commit()
  1879. return redirect('/topic/' + url_pas(name) + '/sub/' + url_pas(sub))
  1880. @app.route('/topic/<everything:name>/sub/<sub>/admin/<int:num>')
  1881. def topic_admin(name = None, sub = None, num = None):
  1882. curs.execute("select block, ip, date from topic where title = ? and sub = ? and id = ?", [name, sub, str(num)])
  1883. data = curs.fetchall()
  1884. if not data:
  1885. return redirect('/topic/' + url_pas(name) + '/sub/' + url_pas(sub))
  1886. ban = ''
  1887. if admin_check(3, None) == 1:
  1888. ban += '</ul><br><h2>' + load_lang('admin') + ' ' + load_lang('tool') + '</h2><ul>'
  1889. is_ban = '<li><a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/b/' + str(num) + '">'
  1890. if data[0][0] == 'O':
  1891. is_ban += load_lang('hide') + ' ' + load_lang('release')
  1892. else:
  1893. is_ban += load_lang('hide')
  1894. is_ban += '</a></li>'
  1895. is_ban += '<li><a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/notice/' + str(num) + '">'
  1896. curs.execute("select id from topic where title = ? and sub = ? and id = ? and top = 'O'", [name, sub, str(num)])
  1897. if curs.fetchall():
  1898. is_ban += load_lang('notice') + ' ' + load_lang('release')
  1899. else:
  1900. is_ban += load_lang('notice') + ''
  1901. is_ban += '</a></li></ul>'
  1902. ban += '<li><a href="/ban/' + url_pas(data[0][1]) + '">'
  1903. curs.execute("select end from ban where block = ?", [data[0][1]])
  1904. if curs.fetchall():
  1905. ban += load_lang('ban') + ' ' + load_lang('release')
  1906. else:
  1907. ban += load_lang('ban')
  1908. ban += '</a></li>' + is_ban
  1909. ban += '</ul><br><h2>' + load_lang('other') + ' ' + load_lang('tool') + '</h2><ul>'
  1910. ban += '<li><a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/raw/' + str(num) + '">raw</a></li>'
  1911. ban = '<li>' + load_lang('time') + ' : ' + data[0][2] + '</li>' + ban
  1912. if ip_or_user(data[0][1]) == 1:
  1913. ban = '<li>' + load_lang('writer') + ' : ' + data[0][1] + ' <a href="/record/' + url_pas(data[0][1]) + '">(' + load_lang('record') + ')</a></li>' + ban
  1914. else:
  1915. ban = '<li>' + load_lang('writer') + ' : <a href="/w/user:' + data[0][1] + '">' + data[0][1] + '</a> <a href="/record/' + url_pas(data[0][1]) + '">(' + load_lang('record') + ')</a></li>' + ban
  1916. ban = '<h2>' + load_lang('state') + '</h2><ul>' + ban
  1917. return easy_minify(flask.render_template(skin_check(),
  1918. imp = [load_lang('discussion') + ' ' + load_lang('tool'), wiki_set(), custom(), other2([' (' + str(num) + ')', 0])],
  1919. data = ban,
  1920. menu = [['topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '#' + str(num), load_lang('discussion')]]
  1921. ))
  1922. @app.route('/topic/<everything:name>/sub/<sub>', methods=['POST', 'GET'])
  1923. def topic(name = None, sub = None):
  1924. ban = topic_check(name, sub)
  1925. admin = admin_check(3, None)
  1926. if flask.request.method == 'POST':
  1927. if captcha_post(flask.request.form.get('g-recaptcha-response', '')) == 1:
  1928. return re_error('/error/13')
  1929. else:
  1930. captcha_post('', 0)
  1931. ip = ip_check()
  1932. today = get_time()
  1933. if ban == 1:
  1934. return re_error('/ban')
  1935. curs.execute("select id from topic where title = ? and sub = ? order by id + 0 desc limit 1", [name, sub])
  1936. old_num = curs.fetchall()
  1937. if old_num:
  1938. num = int(old_num[0][0]) + 1
  1939. else:
  1940. num = 1
  1941. match = re.search('^user:([^/]+)', name)
  1942. if match:
  1943. curs.execute('insert into alarm (name, data, date) values (?, ?, ?)', [match.groups()[0], ip + ' - <a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '">' + load_lang('user', 1) + ' ' + load_lang('discussion', 1) + '</a>', today])
  1944. data = re.sub('\[\[((?:분류|category):(?:(?:(?!\]\]).)*))\]\]', '[br]', flask.request.form.get('content', None))
  1945. for rd_data in re.findall("(?:#([0-9]+))", data):
  1946. curs.execute("select ip from topic where title = ? and sub = ? and id = ?", [name, sub, rd_data])
  1947. ip_data = curs.fetchall()
  1948. if ip_data and ip_or_user(ip_data[0][0]) == 0:
  1949. curs.execute('insert into alarm (name, data, date) values (?, ?, ?)', [ip_data[0][0], ip + ' - <a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '#' + str(num) + '">' + load_lang('discussion', 1) + '</a>', today])
  1950. data = re.sub("(?P<in>#(?:[0-9]+))", '[[\g<in>]]', data)
  1951. data = savemark(data)
  1952. rd_plus(name, sub, today)
  1953. curs.execute("insert into topic (id, title, sub, data, date, ip, block, top) values (?, ?, ?, ?, ?, ?, '', '')", [str(num), name, sub, data, today, ip])
  1954. conn.commit()
  1955. return redirect('/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '#reload')
  1956. else:
  1957. curs.execute("select title from stop where title = ? and sub = ? and close = 'O'", [name, sub])
  1958. close_data = curs.fetchall()
  1959. curs.execute("select title from stop where title = ? and sub = ? and close = ''", [name, sub])
  1960. stop_data = curs.fetchall()
  1961. curs.execute("select id from topic where title = ? and sub = ? limit 1", [name, sub])
  1962. topic_exist = curs.fetchall()
  1963. display = ''
  1964. all_data = ''
  1965. data = ''
  1966. number = 1
  1967. if admin == 1 and topic_exist:
  1968. if close_data:
  1969. all_data += '<a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/tool/close">(' + load_lang('open') + ')</a> '
  1970. else:
  1971. all_data += '<a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/tool/close">(' + load_lang('close') + ')</a> '
  1972. if stop_data:
  1973. all_data += '<a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/tool/stop">(' + load_lang('restart') + ')</a> '
  1974. else:
  1975. all_data += '<a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/tool/stop">(' + load_lang('stop') + ')</a> '
  1976. curs.execute("select title from agreedis where title = ? and sub = ?", [name, sub])
  1977. if curs.fetchall():
  1978. all_data += '<a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/tool/agree">(' + load_lang('release') + ')</a>'
  1979. else:
  1980. all_data += '<a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/tool/agree">(' + load_lang('agreement') + ')</a>'
  1981. all_data += '<hr>'
  1982. if (close_data or stop_data) and admin != 1:
  1983. display = 'display: none;'
  1984. curs.execute("select data, id, date, ip, block, top from topic where title = ? and sub = ? order by id + 0 asc", [name, sub])
  1985. topic = curs.fetchall()
  1986. curs.execute("select data, id, date, ip from topic where title = ? and sub = ? and top = 'O' order by id + 0 asc", [name, sub])
  1987. for topic_data in curs.fetchall():
  1988. who_plus = ''
  1989. curs.execute("select who from re_admin where what = ? order by time desc limit 1", ['notice (' + name + ' - ' + sub + '#' + topic_data[1] + ')'])
  1990. topic_data_top = curs.fetchall()
  1991. if topic_data_top:
  1992. who_plus += ' <span style="margin-right: 5px;">@' + topic_data_top[0][0] + ' </span>'
  1993. all_data += '<table id="toron"><tbody><tr><td id="toron_color_red">'
  1994. all_data += '<a href="#' + topic_data[1] + '">#' + topic_data[1] + '</a> ' + ip_pas(topic_data[3]) + who_plus + ' <span style="float: right;">' + topic_data[2] + '</span>'
  1995. all_data += '</td></tr><tr><td>' + render_set(data = topic_data[0]) + '</td></tr></tbody></table><br>'
  1996. for topic_data in topic:
  1997. user_write = topic_data[0]
  1998. if number == 1:
  1999. start = topic_data[3]
  2000. if topic_data[4] == 'O':
  2001. blind_data = 'id="toron_color_grey"'
  2002. if admin != 1:
  2003. curs.execute("select who from re_admin where what = ? order by time desc limit 1", ['blind (' + name + ' - ' + sub + '#' + str(number) + ')'])
  2004. who_blind = curs.fetchall()
  2005. if who_blind:
  2006. user_write = '[[user:' + who_blind[0][0] + ']] ' + load_lang('hide')
  2007. else:
  2008. user_write = load_lang('hide')
  2009. else:
  2010. blind_data = ''
  2011. user_write = render_set(data = user_write)
  2012. ip = ip_pas(topic_data[3])
  2013. curs.execute('select acl from user where id = ?', [topic_data[3]])
  2014. user_acl = curs.fetchall()
  2015. if user_acl and user_acl[0][0] != 'user':
  2016. ip += ' <a href="javascript:void(0);" title="' + load_lang('admin') + '">★</a>'
  2017. if admin == 1 or blind_data == '':
  2018. ip += ' <a href="/topic/' + url_pas(name) + '/sub/' + url_pas(sub) + '/admin/' + str(number) + '">(' + load_lang('tool') + ')</a>'
  2019. curs.execute("select end from ban where block = ?", [topic_data[3]])
  2020. if curs.fetchall():
  2021. ip += ' <a href="javascript:void(0);" title="' + load_lang('blocked') + '">†</a>'
  2022. if topic_data[5] == '1':
  2023. color = '_blue'
  2024. elif topic_data[3] == start:
  2025. color = '_green'
  2026. else:
  2027. color = ''
  2028. if user_write == '':
  2029. user_write = '<br>'
  2030. all_data += '''
  2031. <table id="toron">
  2032. <tbody>
  2033. <tr>
  2034. <td id="toron_color''' + color + '''">
  2035. <a href="javascript:void(0);" id="''' + str(number) + '">#' + str(number) + '</a> ' + ip + '''</span>
  2036. </td>
  2037. </tr>
  2038. <tr ''' + blind_data + '''>
  2039. <td>''' + user_write + '''</td>
  2040. </tr>
  2041. </tbody>
  2042. </table>
  2043. <br>
  2044. '''
  2045. number += 1
  2046. if ban != 1 or admin == 1:
  2047. data += '''
  2048. <div id="plus"></div>
  2049. <script type="text/javascript" src="/views/main_css/topic_reload.js"></script>
  2050. <script>topic_load("''' + name + '''", "''' + sub + '''");</script>
  2051. <a id="reload" href="javascript:void(0);" onclick="location.href.endsWith(\'#reload\')? location.reload(true):location.href=\'#reload\'">(''' + load_lang('reload') + ''')</a>
  2052. <form style="''' + display + '''" method="post">
  2053. <br>
  2054. <textarea style="height: 100px;" name="content"></textarea>
  2055. <hr>
  2056. ''' + captcha_get()
  2057. if display == '':
  2058. data += ip_warring()
  2059. data += '<button type="submit">' + load_lang('send') + '</button></form>'
  2060. return easy_minify(flask.render_template(skin_check(),
  2061. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('discussion') + ')', 0])],
  2062. data = '<h2 id="topic_top_title">' + sub + '</h2>' + all_data + data,
  2063. menu = [['topic/' + url_pas(name), load_lang('list')]]
  2064. ))
  2065. @app.route('/tool/<name>')
  2066. def user_tool(name = None):
  2067. data = '''
  2068. <h2>''' + load_lang('tool') + '''</h2>
  2069. <ul>
  2070. <li><a href="/record/''' + url_pas(name) + '''">''' + load_lang('record') + '''</li>
  2071. </ul>
  2072. '''
  2073. return easy_minify(flask.render_template(skin_check(),
  2074. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('tool') + ')', 0])],
  2075. data = data,
  2076. menu = [['topic/' + url_pas(name), load_lang('list')]]
  2077. ))
  2078. @app.route('/topic/<everything:name>', methods=['POST', 'GET'])
  2079. @app.route('/topic/<everything:name>/<regex("close|agree"):tool>', methods=['GET'])
  2080. def close_topic_list(name = None, tool = None):
  2081. div = ''
  2082. if flask.request.method == 'POST':
  2083. t_num = ''
  2084. while 1:
  2085. curs.execute("select title from topic where title = ? and sub = ? limit 1", [name, flask.request.form.get('topic', None) + t_num])
  2086. if curs.fetchall():
  2087. if t_num == '':
  2088. t_num = ' 2'
  2089. else:
  2090. t_num = ' ' + str(int(t_num.replace(' ', '')) + 1)
  2091. else:
  2092. break
  2093. return redirect('/topic/' + url_pas(name) + '/sub/' + url_pas(flask.request.form.get('topic', None) + t_num))
  2094. else:
  2095. plus = ''
  2096. menu = [['topic/' + url_pas(name), load_lang('list')]]
  2097. if tool == 'close':
  2098. curs.execute("select sub from stop where title = ? and close = 'O' order by sub asc", [name])
  2099. sub = load_lang('close') + ''
  2100. elif tool == 'agree':
  2101. curs.execute("select sub from agreedis where title = ? order by sub asc", [name])
  2102. sub = load_lang('agreement') + ''
  2103. else:
  2104. curs.execute("select sub from rd where title = ? order by date desc", [name])
  2105. sub = load_lang('discussion') + ' ' + load_lang('list')
  2106. menu = [['w/' + url_pas(name), load_lang('document')]]
  2107. plus = '''
  2108. <a href="/topic/''' + url_pas(name) + '''/close">(''' + load_lang('close') + ''')</a> <a href="/topic/''' + url_pas(name) + '''/agree">(''' + load_lang('agreement') + ''')</a>
  2109. <hr>
  2110. <input placeholder="''' + load_lang('discussion') + ' ' + load_lang('name') + '''" name="topic" type="text">
  2111. <hr>
  2112. <button type="submit">''' + load_lang('open') + '''</button>
  2113. '''
  2114. for data in curs.fetchall():
  2115. curs.execute("select data, date, ip, block from topic where title = ? and sub = ? and id = '1'", [name, data[0]])
  2116. if curs.fetchall():
  2117. it_p = 0
  2118. if sub == load_lang('discussion') + ' ' + load_lang('list'):
  2119. curs.execute("select title from stop where title = ? and sub = ? and close = 'O' order by sub asc", [name, data[0]])
  2120. if curs.fetchall():
  2121. it_p = 1
  2122. if it_p != 1:
  2123. div += '<h2><a href="/topic/' + url_pas(name) + '/sub/' + url_pas(data[0]) + '">' + data[0] + '</a></h2>'
  2124. if div == '':
  2125. plus = re.sub('^<br>', '', plus)
  2126. return easy_minify(flask.render_template(skin_check(),
  2127. imp = [name, wiki_set(), custom(), other2([' (' + sub + ')', 0])],
  2128. data = '<form method="post">' + div + plus + '</form>',
  2129. menu = menu
  2130. ))
  2131. @app.route('/login', methods=['POST', 'GET'])
  2132. def login():
  2133. if custom()[2] != 0:
  2134. return redirect('/user')
  2135. if ban_check(tool = 'login') == 1:
  2136. return re_error('/ban')
  2137. if flask.request.method == 'POST':
  2138. if captcha_post(flask.request.form.get('g-recaptcha-response', '')) == 1:
  2139. return re_error('/error/13')
  2140. else:
  2141. captcha_post('', 0)
  2142. ip = ip_check()
  2143. agent = flask.request.headers.get('User-Agent')
  2144. curs.execute("select pw, encode from user where id = ?", [flask.request.form.get('id', None)])
  2145. user = curs.fetchall()
  2146. if not user:
  2147. return re_error('/error/2')
  2148. pw_check_d = pw_check(
  2149. flask.request.form.get('pw', ''),
  2150. user[0][0],
  2151. user[0][1],
  2152. flask.request.form.get('id', None)
  2153. )
  2154. if pw_check_d != 1:
  2155. return re_error('/error/10')
  2156. flask.session['state'] = 1
  2157. flask.session['id'] = flask.request.form.get('id', None)
  2158. curs.execute("select css from custom where user = ?", [flask.request.form.get('id', None)])
  2159. css_data = curs.fetchall()
  2160. if css_data:
  2161. flask.session['head'] = css_data[0][0]
  2162. else:
  2163. flask.session['head'] = ''
  2164. curs.execute("insert into ua_d (name, ip, ua, today, sub) values (?, ?, ?, ?, '')", [flask.request.form.get('id', None), ip_check(1), agent, get_time()])
  2165. conn.commit()
  2166. return redirect('/user')
  2167. else:
  2168. return easy_minify(flask.render_template(skin_check(),
  2169. imp = [load_lang('login'), wiki_set(), custom(), other2([0, 0])],
  2170. data = '''
  2171. <form method="post">
  2172. <input placeholder="''' + load_lang('id') + '''" name="id" type="text">
  2173. <hr>
  2174. <input placeholder="''' + load_lang('password') + '''" name="pw" type="password">
  2175. <hr>
  2176. ''' + captcha_get() + '''
  2177. <button type="submit">''' + load_lang('login') + '''</button>
  2178. <hr>
  2179. <span>''' + load_lang('http_warring') + '''</span>
  2180. </form>
  2181. ''',
  2182. menu = [['user', load_lang('user')]]
  2183. ))
  2184. @app.route('/change', methods=['POST', 'GET'])
  2185. def change_password():
  2186. global support_language
  2187. if ban_check() == 1:
  2188. return re_error('/ban')
  2189. if custom()[2] == 0:
  2190. return redirect('/login')
  2191. ip = ip_check()
  2192. user_state = flask.request.args.get('user', 'ip')
  2193. if user_state == 'ip':
  2194. if flask.request.method == 'POST':
  2195. if flask.request.form.get('pw4', None) and flask.request.form.get('pw2', None):
  2196. if flask.request.form.get('pw2', None) != flask.request.form.get('pw3', None):
  2197. return re_error('/error/20')
  2198. curs.execute("select pw, encode from user where id = ?", [flask.session['id']])
  2199. user = curs.fetchall()
  2200. if not user:
  2201. return re_error('/error/2')
  2202. pw_check_d = pw_check(
  2203. flask.request.form.get('pw4', ''),
  2204. user[0][0],
  2205. user[0][1],
  2206. flask.request.form.get('id', None)
  2207. )
  2208. if pw_check_d != 1:
  2209. return re_error('/error/10')
  2210. hashed = pw_encode(flask.request.form.get('pw2', None))
  2211. curs.execute("update user set pw = ? where id = ?", [hashed, flask.session['id']])
  2212. auto_list = ['email', 'skin', 'lang']
  2213. for auto_data in auto_list:
  2214. curs.execute('select data from user_set where name = ? and id = ?', [auto_data, ip])
  2215. if curs.fetchall():
  2216. curs.execute("update user_set set data = ? where name = ? and id = ?", [flask.request.form.get(auto_data, ''), auto_data, ip])
  2217. else:
  2218. curs.execute("insert into user_set (name, id, data) values (?, ?, ?)", [auto_data, ip, flask.request.form.get(auto_data, '')])
  2219. conn.commit()
  2220. return redirect('/change')
  2221. else:
  2222. curs.execute('select data from user_set where name = "email" and id = ?', [ip])
  2223. data = curs.fetchall()
  2224. if data:
  2225. email = data[0][0]
  2226. else:
  2227. email = ''
  2228. div2 = load_skin()
  2229. div3 = ''
  2230. var_div3 = ''
  2231. curs.execute('select data from user_set where name = "lang" and id = ?', [ip])
  2232. data = curs.fetchall()
  2233. for lang_data in support_language:
  2234. if data and data[0][0] == lang_data:
  2235. div3 = '<option value="' + lang_data + '">' + lang_data + '</option>'
  2236. else:
  2237. var_div3 += '<option value="' + lang_data + '">' + lang_data + '</option>'
  2238. div3 += var_div3
  2239. return easy_minify(flask.render_template(skin_check(),
  2240. imp = [load_lang('user') + ' ' + load_lang('setting') + ' ' + load_lang('edit'), wiki_set(), custom(), other2([0, 0])],
  2241. data = '''
  2242. <form method="post">
  2243. <span>id : ''' + ip + '''</span>
  2244. <hr>
  2245. <input placeholder="''' + load_lang('now') + ' ' + load_lang('password') + '''" name="pw4" type="password">
  2246. <br>
  2247. <br>
  2248. <input placeholder="''' + load_lang('new') + ' ' + load_lang('password') + '''" name="pw2" type="password">
  2249. <br>
  2250. <br>
  2251. <input placeholder="''' + load_lang('password') + ' ' + load_lang('confirm') + '''" name="pw3" type="password">
  2252. <hr>
  2253. <span>''' + load_lang('user') + ' ' + load_lang('skin') + '''</span>
  2254. <br>
  2255. <br>
  2256. <select name="skin">''' + div2 + '''</select>
  2257. <hr>
  2258. <span>''' + load_lang('user') + ' ' + load_lang('language') + '''</span>
  2259. <br>
  2260. <br>
  2261. <select name="lang">''' + div3 + '''</select>
  2262. <hr>
  2263. <button type="submit">''' + load_lang('edit') + '''</button>
  2264. <hr>
  2265. <span>''' + load_lang('http_warring') + '''</span>
  2266. </form>
  2267. ''',
  2268. menu = [['user', load_lang('user')]]
  2269. ))
  2270. else:
  2271. pass
  2272. @app.route('/check/<name>')
  2273. def user_check(name = None):
  2274. curs.execute("select acl from user where id = ? or id = ?", [name, flask.request.args.get('plus', '-')])
  2275. user = curs.fetchall()
  2276. if user and user[0][0] != 'user':
  2277. if admin_check(None, None) != 1:
  2278. return re_error('/error/4')
  2279. if admin_check(4, 'check (' + name + ')') != 1:
  2280. return re_error('/error/3')
  2281. num = int(flask.request.args.get('num', 1))
  2282. if num * 50 > 0:
  2283. sql_num = num * 50 - 50
  2284. else:
  2285. sql_num = 0
  2286. if flask.request.args.get('plus', None):
  2287. end_check = 1
  2288. if ip_or_user(name) == 1:
  2289. if ip_or_user(flask.request.args.get('plus', None)) == 1:
  2290. curs.execute("select name, ip, ua, today from ua_d where ip = ? or ip = ? order by today desc limit ?, '50'", [name, flask.request.args.get('plus', None), sql_num])
  2291. else:
  2292. curs.execute("select name, ip, ua, today from ua_d where ip = ? or name = ? order by today desc limit ?, '50'", [name, flask.request.args.get('plus', None), sql_num])
  2293. else:
  2294. if ip_or_user(flask.request.args.get('plus', None)) == 1:
  2295. curs.execute("select name, ip, ua, today from ua_d where name = ? or ip = ? order by today desc limit ?, '50'", [name, flask.request.args.get('plus', None), sql_num])
  2296. else:
  2297. curs.execute("select name, ip, ua, today from ua_d where name = ? or name = ? order by today desc limit ?, '50'", [name, flask.request.args.get('plus', None), sql_num])
  2298. else:
  2299. end_check = 0
  2300. if ip_or_user(name) == 1:
  2301. curs.execute("select name, ip, ua, today from ua_d where ip = ? order by today desc limit ?, '50'", [name, sql_num])
  2302. else:
  2303. curs.execute("select name, ip, ua, today from ua_d where name = ? order by today desc limit ?, '50'", [name, sql_num])
  2304. record = curs.fetchall()
  2305. if record:
  2306. if not flask.request.args.get('plus', None):
  2307. div = '<a href="/manager/14?plus=' + url_pas(name) + '">(' + load_lang('compare') + ')</a> <a href="/easy_check/' + url_pas(name) + '">(' + load_lang('easy') + ')</a><hr>'
  2308. else:
  2309. div = '<a href="/check/' + url_pas(name) + '">(' + name + ')</a> <a href="/check/' + url_pas(flask.request.args.get('plus', None)) + '">(' + flask.request.args.get('plus', None) + ')</a><hr>'
  2310. div += '<table id="main_table_set"><tbody><tr>'
  2311. div += '<td id="main_table_width">' + load_lang('name') + '</td><td id="main_table_width">ip</td><td id="main_table_width">' + load_lang('time') + '</td></tr>'
  2312. for data in record:
  2313. if data[2]:
  2314. ua = data[2]
  2315. else:
  2316. ua = '<br>'
  2317. div += '<tr><td>' + ip_pas(data[0]) + '</td><td>' + ip_pas(data[1]) + '</td><td>' + data[3] + '</td></tr>'
  2318. div += '<tr><td colspan="3">' + ua + '</td></tr>'
  2319. div += '</tbody></table>'
  2320. else:
  2321. return re_error('/error/2')
  2322. if end_check == 1:
  2323. div += next_fix('/check/' + url_pas(name) + '?plus=' + flask.request.args.get('plus', None) + '&num=', num, record)
  2324. else:
  2325. div += next_fix('/check/' + url_pas(name) + '?num=', num, record)
  2326. return easy_minify(flask.render_template(skin_check(),
  2327. imp = [load_lang('check'), wiki_set(), custom(), other2([0, 0])],
  2328. data = div,
  2329. menu = [['manager', load_lang('admin')]]
  2330. ))
  2331. @app.route('/register', methods=['POST', 'GET'])
  2332. def register():
  2333. if ban_check() == 1:
  2334. return re_error('/ban')
  2335. if custom()[2] != 0:
  2336. return redirect('/user')
  2337. if not admin_check(None, None) == 1:
  2338. curs.execute('select data from other where name = "reg"')
  2339. set_d = curs.fetchall()
  2340. if set_d and set_d[0][0] == 'on':
  2341. return re_error('/ban')
  2342. if flask.request.method == 'POST':
  2343. if captcha_post(flask.request.form.get('g-recaptcha-response', '')) == 1:
  2344. return re_error('/error/13')
  2345. else:
  2346. captcha_post('', 0)
  2347. if flask.request.form.get('pw', None) != flask.request.form.get('pw2', None):
  2348. return re_error('/error/20')
  2349. if re.search('(?:[^A-Za-zㄱ-힣0-9 ])', flask.request.form.get('id', None)):
  2350. return re_error('/error/8')
  2351. if len(flask.request.form.get('id', None)) > 32:
  2352. return re_error('/error/7')
  2353. curs.execute("select id from user where id = ?", [flask.request.form.get('id', None)])
  2354. if curs.fetchall():
  2355. return re_error('/error/6')
  2356. hashed = pw_encode(flask.request.form.get('pw', None))
  2357. curs.execute('select data from other where name = "email_have"')
  2358. sql_data = curs.fetchall()
  2359. if sql_data and sql_data[0][0] != '':
  2360. flask.session['c_id'] = flask.request.form.get('id', None)
  2361. flask.session['c_pw'] = hashed
  2362. flask.session['c_key'] = ''.join(random.choice("0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ") for i in range(16))
  2363. return redirect('/need_email')
  2364. else:
  2365. curs.execute("select id from user limit 1")
  2366. if not curs.fetchall():
  2367. curs.execute("insert into user (id, pw, acl, date) values (?, ?, 'owner', ?)", [flask.request.form.get('id', None), hashed, get_time()])
  2368. first = 1
  2369. else:
  2370. curs.execute("insert into user (id, pw, acl, date) values (?, ?, 'user', ?)", [flask.request.form.get('id', None), hashed, get_time()])
  2371. first = 0
  2372. ip = ip_check()
  2373. agent = flask.request.headers.get('User-Agent')
  2374. curs.execute("insert into ua_d (name, ip, ua, today, sub) values (?, ?, ?, ?, '')", [flask.request.form.get('id', None), ip, agent, get_time()])
  2375. flask.session['state'] = 1
  2376. flask.session['id'] = flask.request.form.get('id', None)
  2377. flask.session['head'] = ''
  2378. conn.commit()
  2379. if first == 0:
  2380. return redirect('/change')
  2381. else:
  2382. return redirect('/setting')
  2383. else:
  2384. contract = ''
  2385. curs.execute('select data from other where name = "contract"')
  2386. data = curs.fetchall()
  2387. if data and data[0][0] != '':
  2388. contract = data[0][0] + '<hr>'
  2389. return easy_minify(flask.render_template(skin_check(),
  2390. imp = [load_lang('register'), wiki_set(), custom(), other2([0, 0])],
  2391. data = '''
  2392. <form method="post">
  2393. ''' + contract + '''
  2394. <input placeholder="''' + load_lang('id') + '''" name="id" type="text">
  2395. <hr>
  2396. <input placeholder="''' + load_lang('password') + '''" name="pw" type="password">
  2397. <hr>
  2398. <input placeholder="''' + load_lang('confirm') + '''" name="pw2" type="password">
  2399. <hr>
  2400. ''' + captcha_get() + '''
  2401. <button type="submit">''' + load_lang('register') + '''</button>
  2402. <hr>
  2403. <span>''' + load_lang('http_warring') + '''</span>
  2404. </form>
  2405. ''',
  2406. menu = [['user', load_lang('user')]]
  2407. ))
  2408. @app.route('/<regex("need_email|pass_find"):tool>', methods=['POST', 'GET'])
  2409. def need_email(tool = 'pass_find'):
  2410. if flask.request.method == 'POST':
  2411. if tool == 'need_email':
  2412. if 'c_id' in flask.session:
  2413. main_email = ['naver.com', 'gmail.com', 'daum.net', 'hanmail.net']
  2414. data = re.search('@([^@]+)$', flask.request.form.get('email', ''))
  2415. if data:
  2416. data = data.groups()[0]
  2417. curs.execute("select html from html_filter where html = ? and kind = 'email'", [data])
  2418. if curs.fetchall() or (data in main_email):
  2419. curs.execute('select id from user_set where name = "email" and data = ?', [flask.request.form.get('email', '')])
  2420. if curs.fetchall():
  2421. flask.session.pop('c_id', None)
  2422. flask.session.pop('c_pw', None)
  2423. flask.session.pop('c_key', None)
  2424. return redirect('/register')
  2425. else:
  2426. send_email(flask.request.form.get('email', ''), wiki_set()[0] + ' key', 'key : ' + flask.session['c_key'])
  2427. flask.session['c_email'] = flask.request.form.get('email', '')
  2428. return redirect('/check_key')
  2429. return redirect('/register')
  2430. else:
  2431. curs.execute("select id from user where id = ? and email = ?", [flask.request.form.get('id', ''), flask.request.form.get('email', '')])
  2432. if curs.fetchall():
  2433. flask.session['c_key'] = ''.join(random.choice("0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ") for i in range(16))
  2434. flask.session['c_id'] = flask.request.form.get('id', '')
  2435. send_email(flask.request.form.get('email', ''), wiki_set()[0] + ' ' + load_lang('password') + ' ' + load_lang('search') + ' key', 'key : ' + flask.session['c_key'])
  2436. return redirect('/check_pass_key')
  2437. else:
  2438. if tool == 'need_email':
  2439. return easy_minify(flask.render_template(skin_check(),
  2440. imp = ['email', wiki_set(), custom(), other2([0, 0])],
  2441. data = '''
  2442. <a href="/email_filter">(email ''' + load_lang('list') + ''')</a>
  2443. <hr>
  2444. <form method="post">
  2445. <input placeholder="email" name="email" type="text">
  2446. <hr>
  2447. <button type="submit">''' + load_lang('save') + '''</button>
  2448. </form>
  2449. ''',
  2450. menu = [['user', load_lang('user')]]
  2451. ))
  2452. else:
  2453. return easy_minify(flask.render_template(skin_check(),
  2454. imp = [load_lang('password') + ' ' + load_lang('search'), wiki_set(), custom(), other2([0, 0])],
  2455. data = '''
  2456. <form method="post">
  2457. <input placeholder="''' + load_lang('id') + '''" name="id" type="text">
  2458. <hr>
  2459. <input placeholder="email" name="email" type="text">
  2460. <hr>
  2461. <button type="submit">''' + load_lang('save') + '''</button>
  2462. </form>
  2463. ''',
  2464. menu = [['user', load_lang('user')]]
  2465. ))
  2466. @app.route('/<regex("check_key|check_pass_key"):tool>', methods=['POST', 'GET'])
  2467. def check_key(tool = 'check_pass_key'):
  2468. if flask.request.method == 'POST':
  2469. if tool == 'check_key':
  2470. if 'c_id' in flask.session and flask.session['c_key'] == flask.request.form.get('key', None):
  2471. curs.execute("select id from user limit 1")
  2472. if not curs.fetchall():
  2473. curs.execute("insert into user (id, pw, acl, date) values (?, ?, 'owner', ?)", [flask.session['c_id'], flask.session['c_pw'], get_time()])
  2474. first = 1
  2475. else:
  2476. curs.execute("insert into user (id, pw, acl, date) values (?, ?, 'user', ?)", [flask.session['c_id'], flask.session['c_pw'], get_time()])
  2477. first = 0
  2478. ip = ip_check()
  2479. agent = flask.request.headers.get('User-Agent')
  2480. curs.execute("insert into user_set (name, id, data) values ('email', ?, ?)", [flask.session['c_id'], flask.session['c_email']])
  2481. curs.execute("insert into ua_d (name, ip, ua, today, sub) values (?, ?, ?, ?, '')", [flask.session['c_id'], ip, agent, get_time()])
  2482. flask.session['state'] = 1
  2483. flask.session['id'] = flask.session['c_id']
  2484. flask.session['head'] = ''
  2485. conn.commit()
  2486. flask.session.pop('c_id', None)
  2487. flask.session.pop('c_pw', None)
  2488. flask.session.pop('c_key', None)
  2489. flask.session.pop('c_email', None)
  2490. if first == 0:
  2491. return redirect('/change')
  2492. else:
  2493. return redirect('/setting')
  2494. else:
  2495. flask.session.pop('c_id', None)
  2496. flask.session.pop('c_pw', None)
  2497. flask.session.pop('c_key', None)
  2498. flask.session.pop('c_email', None)
  2499. return redirect('/register')
  2500. else:
  2501. if 'c_id' in flask.session and flask.session['c_key'] == flask.request.form.get('key', None):
  2502. hashed = pw_encode(flask.session['c_key'])
  2503. curs.execute("update user set pw = ? where id = ?", [hashed, flask.session['c_id']])
  2504. d_id = flask.session['c_id']
  2505. pw = flask.session['c_key']
  2506. flask.session.pop('c_id', None)
  2507. flask.session.pop('c_key', None)
  2508. return easy_minify(flask.render_template(skin_check(),
  2509. imp = ['check', wiki_set(), custom(), other2([0, 0])],
  2510. data = '''
  2511. ''' + load_lang('id') + ' : ' + d_id + '''
  2512. <br>
  2513. ''' + load_lang('password') + ' : ' + pw + '''
  2514. ''',
  2515. menu = [['user', load_lang('user')]]
  2516. ))
  2517. else:
  2518. return redirect('/pass_find')
  2519. else:
  2520. return easy_minify(flask.render_template(skin_check(),
  2521. imp = ['check', wiki_set(), custom(), other2([0, 0])],
  2522. data = '''
  2523. <form method="post">
  2524. <input placeholder="key" name="key" type="text">
  2525. <hr>
  2526. <button type="submit">''' + load_lang('save') + '''</button>
  2527. </form>
  2528. ''',
  2529. menu = [['user', load_lang('user')]]
  2530. ))
  2531. @app.route('/logout')
  2532. def logout():
  2533. flask.session['state'] = 0
  2534. flask.session.pop('id', None)
  2535. return redirect('/user')
  2536. @app.route('/ban/<name>', methods=['POST', 'GET'])
  2537. def user_ban(name = None):
  2538. if ip_or_user(name) == 0:
  2539. curs.execute("select acl from user where id = ?", [name])
  2540. user = curs.fetchall()
  2541. if not user:
  2542. return re_error('/error/2')
  2543. if user and user[0][0] != 'user':
  2544. if admin_check(None, None) != 1:
  2545. return re_error('/error/4')
  2546. if ban_check(ip = ip_check(), tool = 'login') == 1:
  2547. return re_error('/ban')
  2548. if flask.request.method == 'POST':
  2549. if admin_check(1, 'ban (' + name + ')') != 1:
  2550. return re_error('/error/3')
  2551. if flask.request.form.get('limitless', '') == '':
  2552. end = flask.request.form.get('second', '0')
  2553. else:
  2554. end = '0'
  2555. ban_insert(name, end, flask.request.form.get('why', ''), flask.request.form.get('login', ''), ip_check())
  2556. return redirect('/ban/' + url_pas(name))
  2557. else:
  2558. if admin_check(1, None) != 1:
  2559. return re_error('/error/3')
  2560. curs.execute("select end, why from ban where block = ?", [name])
  2561. end = curs.fetchall()
  2562. if end:
  2563. now = load_lang('release')
  2564. if end[0][0] == '':
  2565. data = '<ul><li>' + load_lang('limitless') + ' ' + load_lang('ban') + '</li>'
  2566. else:
  2567. data = '<ul><li>' + load_lang('ban') + ' : ' + end[0][0] + '</li>'
  2568. curs.execute("select block from ban where block = ? and login = 'O'", [name])
  2569. if curs.fetchall():
  2570. data += '<li>' + load_lang('login') + ' ' + load_lang('able') + '</li>'
  2571. if end[0][1] != '':
  2572. data += '<li>' + load_lang('why') + ' : ' + end[0][1] + '</li></ul><hr>'
  2573. else:
  2574. data += '</ul><hr>'
  2575. else:
  2576. if re.search("^([0-9]{1,3}\.[0-9]{1,3})$", name):
  2577. now = load_lang('band') + ' ' + load_lang('ban')
  2578. else:
  2579. now = load_lang('ban')
  2580. if ip_or_user(name) == 1:
  2581. plus = '<input type="checkbox" name="login"> ' + load_lang('login') + ' ' + load_lang('able') + '<hr>'
  2582. else:
  2583. plus = ''
  2584. data = '<input placeholder="' + load_lang('second') + '" name="second" type="text"><hr><input type="checkbox" name="limitless"> ' + load_lang('limitless') + '<hr>'
  2585. data += '<input placeholder="' + load_lang('why') + '" name="why" type="text"><hr>' + plus
  2586. return easy_minify(flask.render_template(skin_check(),
  2587. imp = [name, wiki_set(), custom(), other2([' (' + now + ')', 0])],
  2588. data = '<form method="post">' + data + '<button type="submit">' + now + '</button></form>',
  2589. menu = [['manager', load_lang('admin')]]
  2590. ))
  2591. @app.route('/acl/<everything:name>', methods=['POST', 'GET'])
  2592. def acl(name = None):
  2593. check_ok = ''
  2594. if flask.request.method == 'POST':
  2595. check_data = 'acl (' + name + ')'
  2596. else:
  2597. check_data = None
  2598. user_data = re.search('^user:(.+)$', name)
  2599. if user_data:
  2600. if check_data and custom()[2] == 0:
  2601. return redirect('/login')
  2602. if user_data.groups()[0] != ip_check():
  2603. if admin_check(5, check_data) != 1:
  2604. if check_data:
  2605. return re_error('/error/3')
  2606. else:
  2607. check_ok = 'disabled'
  2608. else:
  2609. if admin_check(5, check_data) != 1:
  2610. if check_data:
  2611. return re_error('/error/3')
  2612. else:
  2613. check_ok = 'disabled'
  2614. if flask.request.method == 'POST':
  2615. curs.execute("select title from acl where title = ?", [name])
  2616. if curs.fetchall():
  2617. curs.execute("update acl set dec = ? where title = ?", [flask.request.form.get('dec', ''), name])
  2618. curs.execute("update acl set dis = ? where title = ?", [flask.request.form.get('dis', ''), name])
  2619. curs.execute("update acl set why = ? where title = ?", [flask.request.form.get('why', ''), name])
  2620. curs.execute("update acl set view = ? where title = ?", [flask.request.form.get('view', ''), name])
  2621. else:
  2622. curs.execute("insert into acl (title, dec, dis, why, view) values (?, ?, ?, ?, ?)", [name, flask.request.form.get('dec', ''), flask.request.form.get('dis', ''), flask.request.form.get('why', ''), flask.request.form.get('view', '')])
  2623. curs.execute("select title from acl where title = ? and dec = '' and dis = ''", [name])
  2624. if curs.fetchall():
  2625. curs.execute("delete from acl where title = ?", [name])
  2626. conn.commit()
  2627. return redirect('/acl/' + url_pas(name))
  2628. else:
  2629. data = '' + load_lang('document') + ' acl<br><br><select name="dec" ' + check_ok + '>'
  2630. if re.search('^user:', name):
  2631. acl_list = [['', load_lang('normal')], ['user', load_lang('subscriber')], ['all', load_lang('all')]]
  2632. else:
  2633. acl_list = [['', load_lang('normal')], ['user', load_lang('subscriber')], ['admin', load_lang('admin')]]
  2634. curs.execute("select dec from acl where title = ?", [name])
  2635. acl_data = curs.fetchall()
  2636. for data_list in acl_list:
  2637. if acl_data and acl_data[0][0] == data_list[0]:
  2638. check = 'selected="selected"'
  2639. else:
  2640. check = ''
  2641. data += '<option value="' + data_list[0] + '" ' + check + '>' + data_list[1] + '</option>'
  2642. data += '</select>'
  2643. if not re.search('^user:', name):
  2644. data += '<hr>' + load_lang('discussion') + ' acl<br><br><select name="dis" ' + check_ok + '>'
  2645. curs.execute("select dis, why, view from acl where title = ?", [name])
  2646. acl_data = curs.fetchall()
  2647. for data_list in acl_list:
  2648. if acl_data and acl_data[0][0] == data_list[0]:
  2649. check = 'selected="selected"'
  2650. else:
  2651. check = ''
  2652. data += '<option value="' + data_list[0] + '" ' + check + '>' + data_list[1] + '</option>'
  2653. data += '</select>'
  2654. data += '<hr>' + load_lang('view') + ' acl<br><br><select name="view" ' + check_ok + '>'
  2655. for data_list in acl_list:
  2656. if acl_data and acl_data[0][2] == data_list[0]:
  2657. check = 'selected="selected"'
  2658. else:
  2659. check = ''
  2660. data += '<option value="' + data_list[0] + '" ' + check + '>' + data_list[1] + '</option>'
  2661. data += '</select>'
  2662. if check_ok == '':
  2663. if acl_data:
  2664. data += '<hr><input value="' + html.escape(acl_data[0][1]) + '" placeholder="' + load_lang('why') + '" name="why" type="text" ' + check_ok + '>'
  2665. else:
  2666. data += '<hr><input placeholder="' + load_lang('why') + '" name="why" type="text" ' + check_ok + '>'
  2667. return easy_minify(flask.render_template(skin_check(),
  2668. imp = [name, wiki_set(), custom(), other2([' (acl)', 0])],
  2669. data = '''
  2670. <form method="post">
  2671. ''' + data + '''
  2672. <hr>
  2673. <button type="submit" ''' + check_ok + '''>acl ''' + load_lang('edit') + '''</button>
  2674. </form>
  2675. ''',
  2676. menu = [['w/' + url_pas(name), load_lang('document')], ['manager', load_lang('admin')]]
  2677. ))
  2678. @app.route('/admin/<name>', methods=['POST', 'GET'])
  2679. def user_admin(name = None):
  2680. owner = admin_check(None, None)
  2681. curs.execute("select acl from user where id = ?", [name])
  2682. user = curs.fetchall()
  2683. if not user:
  2684. return re_error('/error/2')
  2685. else:
  2686. if owner != 1:
  2687. curs.execute('select name from alist where name = ? and acl = "owner"', [user[0][0]])
  2688. if curs.fetchall():
  2689. return re_error('/error/3')
  2690. if ip_check() == name:
  2691. return re_error('/error/3')
  2692. if flask.request.method == 'POST':
  2693. if admin_check(7, 'admin (' + name + ')') != 1:
  2694. return re_error('/error/3')
  2695. if owner != 1:
  2696. curs.execute('select name from alist where name = ? and acl = "owner"', [flask.request.form.get('select', None)])
  2697. if curs.fetchall():
  2698. return re_error('/error/3')
  2699. if flask.request.form.get('select', None) == 'X':
  2700. curs.execute("update user set acl = 'user' where id = ?", [name])
  2701. else:
  2702. curs.execute("update user set acl = ? where id = ?", [flask.request.form.get('select', None), name])
  2703. conn.commit()
  2704. return redirect('/admin/' + url_pas(name))
  2705. else:
  2706. if admin_check(7, None) != 1:
  2707. return re_error('/error/3')
  2708. div = '<option value="X">X</option>'
  2709. curs.execute('select distinct name from alist order by name asc')
  2710. for data in curs.fetchall():
  2711. if user[0][0] == data[0]:
  2712. div += '<option value="' + data[0] + '" selected="selected">' + data[0] + '</option>'
  2713. else:
  2714. if owner != 1:
  2715. curs.execute('select name from alist where name = ? and acl = "owner"', [data[0]])
  2716. if not curs.fetchall():
  2717. div += '<option value="' + data[0] + '">' + data[0] + '</option>'
  2718. else:
  2719. div += '<option value="' + data[0] + '">' + data[0] + '</option>'
  2720. return easy_minify(flask.render_template(skin_check(),
  2721. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('authority') + ')', 0])],
  2722. data = '''
  2723. <form method="post">
  2724. <select name="select">''' + div + '''</select>
  2725. <hr>
  2726. <button type="submit">''' + load_lang('edit') + '''</button>
  2727. </form>
  2728. ''',
  2729. menu = [['manager', load_lang('admin')]]
  2730. ))
  2731. @app.route('/diff/<everything:name>')
  2732. def diff_data(name = None):
  2733. first = flask.request.args.get('first', '1')
  2734. second = flask.request.args.get('second', '1')
  2735. curs.execute("select data from history where id = ? and title = ?", [first, name])
  2736. first_raw_data = curs.fetchall()
  2737. if first_raw_data:
  2738. curs.execute("select data from history where id = ? and title = ?", [second, name])
  2739. second_raw_data = curs.fetchall()
  2740. if second_raw_data:
  2741. first_data = html.escape(first_raw_data[0][0])
  2742. second_data = html.escape(second_raw_data[0][0])
  2743. if first == second:
  2744. result = '-'
  2745. else:
  2746. diff_data = difflib.SequenceMatcher(None, first_data, second_data)
  2747. result = re.sub('\r', '', diff(diff_data))
  2748. return easy_minify(flask.render_template(skin_check(),
  2749. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('compare') + ')', 0])],
  2750. data = '<pre>' + result + '</pre>',
  2751. menu = [['history/' + url_pas(name), load_lang('history')]]
  2752. ))
  2753. return redirect('/history/' + url_pas(name))
  2754. @app.route('/down/<everything:name>')
  2755. def down(name = None):
  2756. div = '<ul>'
  2757. curs.execute("select title from data where title like ?", ['%' + name + '/%'])
  2758. for data in curs.fetchall():
  2759. div += '<li><a href="/w/' + url_pas(data[0]) + '">' + data[0] + '</a></li>'
  2760. div += '</ul>'
  2761. return easy_minify(flask.render_template(skin_check(),
  2762. imp = [name, wiki_set(), custom(), other2([' (' + load_lang('under') + ')', 0])],
  2763. data = div,
  2764. menu = [['w/' + url_pas(name), load_lang('document')]]
  2765. ))
  2766. @app.route('/w/<everything:name>')
  2767. def read_view(name = None):
  2768. data_none = 0
  2769. sub = ''
  2770. acl = ''
  2771. div = ''
  2772. num = flask.request.args.get('num', None)
  2773. if num:
  2774. num = int(num)
  2775. else:
  2776. if not flask.request.args.get('from', None):
  2777. curs.execute("select title from back where link = ? and type = 'redirect'", [name])
  2778. redirect_data = curs.fetchall()
  2779. if redirect_data:
  2780. return redirect('/w/' + redirect_data[0][0] + '?from=' + name)
  2781. curs.execute("select sub from rd where title = ? order by date desc", [name])
  2782. for data in curs.fetchall():
  2783. curs.execute("select title from stop where title = ? and sub = ? and close = 'O'", [name, data[0]])
  2784. if not curs.fetchall():
  2785. sub += ' (' + load_lang('discussion') + ')'
  2786. break
  2787. curs.execute("select link from back where title = ? and type = 'cat' order by link asc", [name])
  2788. curs.execute("select title from data where title like ?", ['%' + name + '/%'])
  2789. if curs.fetchall():
  2790. down = 1
  2791. else:
  2792. down = 0
  2793. m = re.search("^(.*)\/(.*)$", name)
  2794. if m:
  2795. uppage = m.groups()[0]
  2796. else:
  2797. uppage = 0
  2798. if re.search('^category:', name):
  2799. curs.execute("select link from back where title = ? and type = 'cat' order by link asc", [name])
  2800. back = curs.fetchall()
  2801. if back:
  2802. div = '<br><h2 id="cate_normal">' + load_lang('category') + '</h2><ul>'
  2803. u_div = ''
  2804. for data in back:
  2805. if re.search('^category:', data[0]):
  2806. u_div += '<li><a href="/w/' + url_pas(data[0]) + '">' + data[0] + '</a></li>'
  2807. else:
  2808. curs.execute("select title from back where title = ? and type = 'include'", [data[0]])
  2809. db_data = curs.fetchall()
  2810. if db_data:
  2811. div += '<li><a href="/w/' + url_pas(data[0]) + '">' + data[0] + '</a> <a id="inside" href="/xref/' + url_pas(data[0]) + '">(' + load_lang('backlink') + ')</a></li>'
  2812. else:
  2813. div += '<li><a href="/w/' + url_pas(data[0]) + '">' + data[0] + '</a></li>'
  2814. div += '</ul>'
  2815. if div == '<br><h2 id="cate_normal">' + load_lang('category') + '</h2><ul></ul>':
  2816. div = ''
  2817. if u_div != '':
  2818. div += '<br><h2 id="cate_under">' + load_lang('under') + ' ' + load_lang('category') + '</h2><ul>' + u_div + '</ul>'
  2819. if num:
  2820. curs.execute("select title from history where title = ? and id = ? and hide = 'O'", [name, str(num)])
  2821. if curs.fetchall() and admin_check(6, None) != 1:
  2822. return redirect('/history/' + url_pas(name))
  2823. curs.execute("select title, data from history where title = ? and id = ?", [name, str(num)])
  2824. else:
  2825. curs.execute("select title, data from data where title = ?", [name])
  2826. data = curs.fetchall()
  2827. if data:
  2828. else_data = data[0][1]
  2829. response_data = 200
  2830. else:
  2831. data_none = 1
  2832. response_data = 404
  2833. else_data = None
  2834. m = re.search("^user:([^/]*)", name)
  2835. if m:
  2836. g = m.groups()
  2837. curs.execute("select acl from user where id = ?", [g[0]])
  2838. test = curs.fetchall()
  2839. if test and test[0][0] != 'user':
  2840. acl = ' (' + load_lang('admin') + ')'
  2841. else:
  2842. if ban_check(g[0]) == 1:
  2843. sub += ' (' + load_lang('ban') + ')'
  2844. else:
  2845. acl = ''
  2846. curs.execute("select dec from acl where title = ?", [name])
  2847. data = curs.fetchall()
  2848. if data:
  2849. acl += ' (acl)'
  2850. if flask.request.args.get('from', None):
  2851. else_data = re.sub('^\r\n', '', else_data)
  2852. else_data = re.sub('\r\n$', '', else_data)
  2853. end_data = render_set(
  2854. title = name,
  2855. data = else_data
  2856. )
  2857. if end_data == 'http request 401.3':
  2858. response_data = 401
  2859. if num:
  2860. menu = [['history/' + url_pas(name), load_lang('history')]]
  2861. sub = ' (' + str(num) + load_lang('version') + ')'
  2862. acl = ''
  2863. r_date = 0
  2864. else:
  2865. if data_none == 1:
  2866. menu = [['edit/' + url_pas(name), load_lang('create')]]
  2867. else:
  2868. menu = [['edit/' + url_pas(name), load_lang('edit')]]
  2869. menu += [['topic/' + url_pas(name), load_lang('discussion')], ['history/' + url_pas(name), load_lang('history')], ['xref/' + url_pas(name), load_lang('backlink')], ['acl/' + url_pas(name), 'acl']]
  2870. if flask.request.args.get('from', None):
  2871. menu += [['w/' + url_pas(name), load_lang('pass')]]
  2872. end_data = '''
  2873. <div id="redirect">
  2874. <a href="/w/''' + url_pas(flask.request.args.get('from', None)) + '?from=' + url_pas(name) + '">' + flask.request.args.get('from', None) + '</a> - ' + name + '''
  2875. </div>
  2876. <br>''' + end_data
  2877. if uppage != 0:
  2878. menu += [['w/' + url_pas(uppage), load_lang('upper')]]
  2879. if down:
  2880. menu += [['down/' + url_pas(name), load_lang('under')]]
  2881. curs.execute("select date from history where title = ? order by date desc limit 1", [name])
  2882. date = curs.fetchall()
  2883. if date:
  2884. r_date = date[0][0]
  2885. else:
  2886. r_date = 0
  2887. div = end_data + div
  2888. return easy_minify(flask.render_template(skin_check(),
  2889. imp = [flask.request.args.get('show', name), wiki_set(), custom(), other2([sub + acl, r_date])],
  2890. data = div,
  2891. menu = menu
  2892. )), response_data
  2893. @app.route('/topic_record/<name>')
  2894. def user_topic_list(name = None):
  2895. num = int(flask.request.args.get('num', 1))
  2896. if num * 50 > 0:
  2897. sql_num = num * 50 - 50
  2898. else:
  2899. sql_num = 0
  2900. one_admin = admin_check(1, None)
  2901. div = '''
  2902. <table id="main_table_set">
  2903. <tbody>
  2904. <tr>
  2905. <td id="main_table_width">''' + load_lang('discussion') + ' ' + load_lang('name') + '''</td>
  2906. <td id="main_table_width">''' + load_lang('writer') + '''</td>
  2907. <td id="main_table_width">''' + load_lang('time') + '''</td>
  2908. </tr>
  2909. '''
  2910. curs.execute("select title, id, sub, ip, date from topic where ip = ? order by date desc limit ?, '50'", [name, str(sql_num)])
  2911. data_list = curs.fetchall()
  2912. for data in data_list:
  2913. title = html.escape(data[0])
  2914. sub = html.escape(data[2])
  2915. if one_admin == 1:
  2916. curs.execute("select * from ban where block = ?", [data[3]])
  2917. if curs.fetchall():
  2918. ban = ' <a href="/ban/' + url_pas(data[3]) + '">(' + load_lang('release') + ')</a>'
  2919. else:
  2920. ban = ' <a href="/ban/' + url_pas(data[3]) + '">(' + load_lang('ban') + ')</a>'
  2921. else:
  2922. ban = ''
  2923. div += '<tr><td><a href="/topic/' + url_pas(data[0]) + '/sub/' + url_pas(data[2]) + '#' + data[1] + '">' + title + '#' + data[1] + '</a> (' + sub + ')</td>'
  2924. div += '<td>' + ip_pas(data[3]) + ban + '</td><td>' + data[4] + '</td></tr>'
  2925. div += '</tbody></table>'
  2926. div += next_fix('/topic_record/' + url_pas(name) + '?num=', num, data_list)
  2927. curs.execute("select end from ban where block = ?", [name])
  2928. if curs.fetchall():
  2929. sub = ' (' + load_lang('ban') + ')'
  2930. else:
  2931. sub = 0
  2932. return easy_minify(flask.render_template(skin_check(),
  2933. imp = [load_lang('discussion') + ' ' + load_lang('record'), wiki_set(), custom(), other2([sub, 0])],
  2934. data = div,
  2935. menu = [['other', load_lang('other')], ['user', load_lang('user')], ['count/' + url_pas(name), load_lang('count')], ['record/' + url_pas(name), load_lang('record')]]
  2936. ))
  2937. @app.route('/recent_changes')
  2938. @app.route('/<regex("record"):tool>/<name>')
  2939. @app.route('/<regex("history"):tool>/<everything:name>', methods=['POST', 'GET'])
  2940. def recent_changes(name = None, tool = 'record'):
  2941. if flask.request.method == 'POST':
  2942. return redirect('/diff/' + url_pas(name) + '?first=' + flask.request.form.get('b', None) + '&second=' + flask.request.form.get('a', None))
  2943. else:
  2944. one_admin = admin_check(1, None)
  2945. six_admin = admin_check(6, None)
  2946. ban = ''
  2947. select = ''
  2948. what = flask.request.args.get('what', 'all')
  2949. div = '<table id="main_table_set"><tbody><tr>'
  2950. if name:
  2951. num = int(flask.request.args.get('num', 1))
  2952. if num * 50 > 0:
  2953. sql_num = num * 50 - 50
  2954. else:
  2955. sql_num = 0
  2956. if tool == 'history':
  2957. div += '''
  2958. <td id="main_table_width">''' + load_lang('version') + '''</td>
  2959. <td id="main_table_width">''' + load_lang('editor') + '''</td>
  2960. <td id="main_table_width">''' + load_lang('time') + '''</td></tr>
  2961. '''
  2962. curs.execute("select id, title, date, ip, send, leng from history where title = ? order by id + 0 desc limit ?, '50'", [name, str(sql_num)])
  2963. else:
  2964. div += '<td id="main_table_width">' + load_lang('document') + ' ' + load_lang('name') + '</td><td id="main_table_width">' + load_lang('editor') + '</td><td id="main_table_width">' + load_lang('time') + '</td></tr>'
  2965. if what == 'all':
  2966. div = '<a href="/record/' + url_pas(name) + '?what=revert">(' + load_lang('revert') + ')</a><hr>' + div
  2967. div = '<a href="/record/' + url_pas(name) + '?what=move">(' + load_lang('move') + ')</a> ' + div
  2968. div = '<a href="/record/' + url_pas(name) + '?what=delete">(' + load_lang('delete') + ')</a> ' + div
  2969. div = '<a href="/topic_record/' + url_pas(name) + '">(' + load_lang('discussion') + ')</a> ' + div
  2970. curs.execute("select id, title, date, ip, send, leng from history where ip = ? order by date desc limit ?, '50'", [name, str(sql_num)])
  2971. else:
  2972. if what == 'delete':
  2973. sql = '%(' + load_lang('delete', 1) + ')'
  2974. elif what == 'move':
  2975. sql = '%' + load_lang('move', 1) + ')'
  2976. elif what == 'revert':
  2977. sql = '%' + load_lang('version', 1) + ')'
  2978. else:
  2979. return redirect('/')
  2980. curs.execute("select id, title, date, ip, send, leng from history where ip = ? and send like ? order by date desc limit ?, 50", [name, sql, str(sql_num)])
  2981. else:
  2982. num = int(flask.request.args.get('num', 1))
  2983. if num * 50 > 0:
  2984. sql_num = num * 50 - 50
  2985. else:
  2986. sql_num = 0
  2987. div += '<td id="main_table_width">' + load_lang('document') + ' ' + load_lang('name') + '</td><td id="main_table_width">' + load_lang('editor') + '</td><td id="main_table_width">' + load_lang('time') + '</td></tr>'
  2988. if what == 'all':
  2989. div = '<a href="/recent_changes?what=revert">(' + load_lang('revert') + ')</a><hr>' + div
  2990. div = '<a href="/recent_changes?what=move">(' + load_lang('move') + ')</a> ' + div
  2991. div = '<a href="/recent_changes?what=delete">(' + load_lang('delete') + ')</a> ' + div
  2992. div = '<a href="/recent_discuss">(' + load_lang('discussion') + ')</a> <a href="/block_log">(' + load_lang('ban') + ')</a> <a href="/user_log">(' + load_lang('subscriber') + ')</a> <a href="/admin_log">(' + load_lang('authority') + ')</a><hr>' + div
  2993. curs.execute("select id, title, date, ip, send, leng from history where not title like 'user:%' order by date desc limit ?, 50", [str(sql_num)])
  2994. else:
  2995. if what == 'delete':
  2996. sql = '%(' + load_lang('delete', 1) + ')'
  2997. elif what == 'move':
  2998. sql = '%' + load_lang('move', 1) + ')'
  2999. elif what == 'revert':
  3000. sql = '%' + load_lang('version', 1) + ')'
  3001. else:
  3002. return redirect('/')
  3003. curs.execute("select id, title, date, ip, send, leng from history where send like ? and not title like 'user:%' order by date desc limit ?, 50", [sql, str(sql_num)])
  3004. data_list = curs.fetchall()
  3005. for data in data_list:
  3006. select += '<option value="' + data[0] + '">' + data[0] + '</option>'
  3007. send = '<br>'
  3008. if data[4]:
  3009. if not re.search("^(?: *)$", data[4]):
  3010. send = data[4]
  3011. if re.search("\+", data[5]):
  3012. leng = '<span style="color:green;">(' + data[5] + ')</span>'
  3013. elif re.search("\-", data[5]):
  3014. leng = '<span style="color:red;">(' + data[5] + ')</span>'
  3015. else:
  3016. leng = '<span style="color:gray;">(' + data[5] + ')</span>'
  3017. if one_admin == 1:
  3018. curs.execute("select block from ban where block = ?", [data[3]])
  3019. if curs.fetchall():
  3020. ban = ' <a href="/ban/' + url_pas(data[3]) + '">(' + load_lang('release') + ')</a>'
  3021. else:
  3022. ban = ' <a href="/ban/' + url_pas(data[3]) + '">(' + load_lang('ban') + ')</a>'
  3023. ip = ip_pas(data[3])
  3024. if int(data[0]) - 1 == 0:
  3025. revert = ''
  3026. else:
  3027. revert = '<a href="/diff/' + url_pas(data[1]) + '?first=' + str(int(data[0]) - 1) + '&second=' + data[0] + '">(' + load_lang('compare') + ')</a> <a href="/revert/' + url_pas(data[1]) + '?num=' + str(int(data[0]) - 1) + '">(' + load_lang('revert') + ')</a>'
  3028. style = ['', '']
  3029. date = data[2]
  3030. curs.execute("select title from history where title = ? and id = ? and hide = 'O'", [data[1], data[0]])
  3031. hide = curs.fetchall()
  3032. if six_admin == 1:
  3033. if hide:
  3034. hidden = ' <a href="/hidden/' + url_pas(data[1]) + '?num=' + data[0] + '">(' + load_lang('release') + ')'
  3035. style[0] = 'id="toron_color_grey"'
  3036. style[1] = 'id="toron_color_grey"'
  3037. if send == '<br>':
  3038. send = '(' + load_lang('hide') + ')'
  3039. else:
  3040. send += ' (' + load_lang('hide') + ')'
  3041. else:
  3042. hidden = ' <a href="/hidden/' + url_pas(data[1]) + '?num=' + data[0] + '">(' + load_lang('hide') + ')'
  3043. elif not hide:
  3044. hidden = ''
  3045. else:
  3046. ip = ''
  3047. hidden = ''
  3048. ban = ''
  3049. date = ''
  3050. send = '(' + load_lang('hide') + ')'
  3051. style[0] = 'style="display: none;"'
  3052. style[1] = 'id="toron_color_grey"'
  3053. if tool == 'history':
  3054. title = '<a href="/w/' + url_pas(name) + '?num=' + data[0] + '">' + data[0] + load_lang('version') + '</a> <a href="/raw/' + url_pas(name) + '?num=' + data[0] + '">(' + load_lang('raw') + ')</a> '
  3055. else:
  3056. title = '<a href="/w/' + url_pas(data[1]) + '">' + html.escape(data[1]) + '</a> <a href="/history/' + url_pas(data[1]) + '">(' + data[0] + load_lang('version') + ')</a> '
  3057. div += '<tr ' + style[0] + '><td>' + title + revert + ' ' + leng + '</td>'
  3058. div += '<td>' + ip + ban + hidden + '</td><td>' + date + '</td></tr><tr ' + style[1] + '><td colspan="3">' + send_parser(send) + '</td></tr>'
  3059. div += '</tbody></table>'
  3060. sub = ''
  3061. if name:
  3062. if tool == 'history':
  3063. div = '<form method="post"><select name="a">' + select + '</select> <select name="b">' + select + '</select> <button type="submit">' + load_lang('compare') + '</button></form><hr>' + div
  3064. title = name
  3065. sub += ' (' + load_lang('history') + ')'
  3066. menu = [['w/' + url_pas(name), load_lang('document')], ['raw/' + url_pas(name), 'raw'], ['move_data/' + url_pas(name), load_lang('move') + ' ' + load_lang('history')]]
  3067. div += next_fix('/history/' + url_pas(name) + '?num=', num, data_list)
  3068. else:
  3069. curs.execute("select end from ban where block = ?", [name])
  3070. if curs.fetchall():
  3071. sub += ' (' + load_lang('ban') + ')'
  3072. title = load_lang('edit') + ' ' + load_lang('record')
  3073. menu = [['other', load_lang('other')], ['user', load_lang('user')], ['count/' + url_pas(name), load_lang('count')]]
  3074. div += next_fix('/record/' + url_pas(name) + '/' + url_pas(what) + '?num=', num, data_list)
  3075. if what != 'all':
  3076. menu += [['record/' + url_pas(name), load_lang('normal')]]
  3077. else:
  3078. menu = 0
  3079. title = load_lang('recent') + ' ' + load_lang('change') + ''
  3080. if what != 'all':
  3081. menu = [['recent_changes', load_lang('normal')]]
  3082. div += next_fix('/recent_changes?num=', num, data_list)
  3083. if what == 'delete':
  3084. sub += ' (' + load_lang('delete') + ')'
  3085. elif what == 'move':
  3086. sub += ' (' + load_lang('move') + ')'
  3087. elif what == 'revert':
  3088. sub += ' (' + load_lang('revert') + ')'
  3089. if sub == '':
  3090. sub = 0
  3091. return easy_minify(flask.render_template(skin_check(),
  3092. imp = [title, wiki_set(), custom(), other2([sub, 0])],
  3093. data = div,
  3094. menu = menu
  3095. ))
  3096. @app.route('/upload', methods=['GET', 'POST'])
  3097. def upload():
  3098. if ban_check() == 1:
  3099. return re_error('/ban')
  3100. if flask.request.method == 'POST':
  3101. if captcha_post(flask.request.form.get('g-recaptcha-response', '')) == 1:
  3102. return re_error('/error/13')
  3103. else:
  3104. captcha_post('', 0)
  3105. data = flask.request.files.get('f_data', None)
  3106. if not data:
  3107. return re_error('/error/9')
  3108. if int(wiki_set(3)) * 1024 * 1024 < flask.request.content_length:
  3109. return re_error('/error/17')
  3110. value = os.path.splitext(data.filename)[1]
  3111. if not value in ['.jpeg', '.jpg', '.gif', '.png', '.webp', '.JPEG', '.JPG', '.GIF', '.PNG', '.WEBP']:
  3112. return re_error('/error/14')
  3113. if flask.request.form.get('f_name', None):
  3114. name = flask.request.form.get('f_name', None) + value
  3115. else:
  3116. name = data.filename
  3117. piece = os.path.splitext(name)
  3118. if re.search('[^ㄱ-힣0-9a-zA-Z_\- ]', piece[0]):
  3119. return re_error('/error/22')
  3120. e_data = sha224(piece[0]) + piece[1]
  3121. curs.execute("select title from data where title = ?", ['file:' + name])
  3122. if curs.fetchall():
  3123. return re_error('/error/16')
  3124. ip = ip_check()
  3125. if flask.request.form.get('f_lice', None):
  3126. lice = flask.request.form.get('f_lice', None)
  3127. else:
  3128. if custom()[2] == 0:
  3129. lice = ip + ' ' + load_lang('upload', 1)
  3130. else:
  3131. lice = '[[user:' + ip + ']] ' + load_lang('upload', 1)
  3132. if os.path.exists(os.path.join('image', e_data)):
  3133. os.remove(os.path.join('image', e_data))
  3134. data.save(os.path.join('image', e_data))
  3135. else:
  3136. data.save(os.path.join('image', e_data))
  3137. curs.execute("select title from data where title = ?", ['file:' + name])
  3138. if curs.fetchall():
  3139. curs.execute("delete from data where title = ?", ['file:' + name])
  3140. curs.execute("insert into data (title, data) values (?, ?)", ['file:' + name, '[[file:' + name + ']][br][br]{{{[[file:' + name + ']]}}}[br][br]' + lice])
  3141. curs.execute("insert into acl (title, dec, dis, why, view) values (?, 'admin', '', '', '')", ['file:' + name])
  3142. history_plus(
  3143. 'file:' + name, '[[file:' + name + ']][br][br]{{{[[file:' + name + ']]}}}[br][br]' + lice,
  3144. get_time(),
  3145. ip,
  3146. load_lang('upload', 1),
  3147. '0'
  3148. )
  3149. conn.commit()
  3150. return redirect('/w/file:' + name)
  3151. else:
  3152. return easy_minify(flask.render_template(skin_check(),
  3153. imp = [load_lang('upload'), wiki_set(), custom(), other2([0, 0])],
  3154. data = '''
  3155. <form method="post" enctype="multipart/form-data" accept-charset="utf8">
  3156. <input type="file" name="f_data">
  3157. <hr>
  3158. <input placeholder="''' + load_lang('name') + '''" name="f_name" type="text">
  3159. <hr>
  3160. <input placeholder="''' + load_lang('license') + '''" name="f_lice" type="text">
  3161. <hr>
  3162. ''' + captcha_get() + '''
  3163. <button id="save" type="submit">''' + load_lang('save') + '''</button>
  3164. </form>
  3165. ''',
  3166. menu = [['other', load_lang('other')]]
  3167. ))
  3168. @app.route('/user')
  3169. def user_info():
  3170. ip = ip_check()
  3171. curs.execute("select acl from user where id = ?", [ip])
  3172. data = curs.fetchall()
  3173. if ban_check() == 0:
  3174. if data:
  3175. if data[0][0] != 'user':
  3176. acl = data[0][0]
  3177. else:
  3178. acl = load_lang('subscriber')
  3179. else:
  3180. acl = load_lang('normal')
  3181. else:
  3182. acl = load_lang('ban')
  3183. match = re.search("^([0-9]{1,3}\.[0-9]{1,3})", ip)
  3184. if match:
  3185. match = match.groups()[0]
  3186. else:
  3187. match = '-'
  3188. curs.execute("select end, login, band from ban where block = ? or block = ?", [ip, match])
  3189. block_data = curs.fetchall()
  3190. if block_data:
  3191. if block_data[0][0] != '':
  3192. acl += ' (end : ' + block_data[0][0] + ')'
  3193. else:
  3194. acl += ' (' + load_lang('limitless') + ')'
  3195. if block_data[0][1] != '':
  3196. acl += ' (' + load_lang('login') + ' ' + load_lang('able') + ')'
  3197. if block_data[0][2] == 'O':
  3198. acl += ' (' + load_lang('band') + ')'
  3199. if custom()[2] != 0:
  3200. ip_user = '<a href="/w/user:' + ip + '">' + ip + '</a>'
  3201. plus = '''
  3202. <li><a href="/logout">''' + load_lang('logout') + '''</a></li>
  3203. <li><a href="/change">''' + load_lang('user') + ' ' + load_lang('setting') + ' ' + load_lang('edit') + '''</a></li>
  3204. '''
  3205. curs.execute('select name from alarm where name = ? limit 1', [ip_check()])
  3206. if curs.fetchall():
  3207. plus2 = '<li><a href="/alarm">' + load_lang('alarm') + ' (O)</a></li>'
  3208. else:
  3209. plus2 = '<li><a href="/alarm">' + load_lang('alarm') + '</a></li>'
  3210. plus2 += '<li><a href="/watch_list">' + load_lang('watchlist') + '</a></li>'
  3211. else:
  3212. ip_user = ip
  3213. plus = '''
  3214. <li><a href="/login">''' + load_lang('login') + '''</a></li>
  3215. <li><a href="/register">''' + load_lang('register') + '''</a></li>
  3216. '''
  3217. plus2 = ''
  3218. curs.execute("select data from other where name = 'email_have'")
  3219. test = curs.fetchall()
  3220. if test and test[0][0] != '':
  3221. plus += '<li><a href="/pass_find">' + load_lang('password') + ' ' + load_lang('search') + '</a></li>'
  3222. return easy_minify(flask.render_template(skin_check(),
  3223. imp = [load_lang('user') + ' ' + load_lang('tool'), wiki_set(), custom(), other2([0, 0])],
  3224. data = '''
  3225. <h2>''' + load_lang('state') + '''</h2>
  3226. <ul>
  3227. <li>''' + ip_user + ''' <a href="/record/''' + url_pas(ip) + '''">(''' + load_lang('record') + ''')</a></li>
  3228. <li>''' + load_lang('authority') + ''' : ''' + acl + '''</li>
  3229. </ul>
  3230. <br>
  3231. <h2>''' + load_lang('login') + '''</h2>
  3232. <ul>
  3233. ''' + plus + '''
  3234. </ul>
  3235. <br>
  3236. <h2>''' + load_lang('tool') + '''</h2>
  3237. <ul>
  3238. <li><a href="/acl/user:''' + url_pas(ip) + '">' + load_lang('user') + ' ' + load_lang('document') + ''' acl</a></li>
  3239. <li><a href="/custom_head">''' + load_lang('user') + ''' head</a></li>
  3240. </ul>
  3241. <br>
  3242. <h2>''' + load_lang('other') + '''</h2>
  3243. <ul>
  3244. ''' + plus2 + '''
  3245. <li>
  3246. <a href="/count">''' + load_lang('count') + '''</a>
  3247. </li>
  3248. </ul>
  3249. ''',
  3250. menu = 0
  3251. ))
  3252. @app.route('/watch_list')
  3253. def watch_list():
  3254. div = 'limit : 10<hr>'
  3255. if custom()[2] == 0:
  3256. return redirect('/login')
  3257. curs.execute("select title from scan where user = ?", [ip_check()])
  3258. data = curs.fetchall()
  3259. for data_list in data:
  3260. div += '<li><a href="/w/' + url_pas(data_list[0]) + '">' + data_list[0] + '</a> <a href="/watch_list/' + url_pas(data_list[0]) + '">(' + load_lang('delete') + ')</a></li>'
  3261. if data:
  3262. div = '<ul>' + div + '</ul><hr>'
  3263. div += '<a href="/manager/13">(' + load_lang('plus') + ')</a>'
  3264. return easy_minify(flask.render_template(skin_check(),
  3265. imp = [load_lang('watchlist') + ' ' + load_lang('list'), wiki_set(), custom(), other2([0, 0])],
  3266. data = div,
  3267. menu = [['manager', load_lang('admin')]]
  3268. ))
  3269. @app.route('/watch_list/<everything:name>')
  3270. def watch_list_name(name = None):
  3271. if custom()[2] == 0:
  3272. return redirect('/login')
  3273. ip = ip_check()
  3274. curs.execute("select count(title) from scan where user = ?", [ip])
  3275. count = curs.fetchall()
  3276. if count and count[0][0] > 9:
  3277. return redirect('/watch_list')
  3278. curs.execute("select title from scan where user = ? and title = ?", [ip, name])
  3279. if curs.fetchall():
  3280. curs.execute("delete from scan where user = ? and title = ?", [ip, name])
  3281. else:
  3282. curs.execute("insert into scan (user, title) values (?, ?)", [ip, name])
  3283. conn.commit()
  3284. return redirect('/watch_list')
  3285. @app.route('/custom_head', methods=['GET', 'POST'])
  3286. def custom_head_view():
  3287. ip = ip_check()
  3288. if flask.request.method == 'POST':
  3289. if custom()[2] != 0:
  3290. curs.execute("select user from custom where user = ?", [ip + ' (head)'])
  3291. if curs.fetchall():
  3292. curs.execute("update custom set css = ? where user = ?", [flask.request.form.get('content', None), ip + ' (head)'])
  3293. else:
  3294. curs.execute("insert into custom (user, css) values (?, ?)", [ip + ' (head)', flask.request.form.get('content', None)])
  3295. conn.commit()
  3296. flask.session['head'] = flask.request.form.get('content', None)
  3297. return redirect('/user')
  3298. else:
  3299. if custom()[2] != 0:
  3300. start = ''
  3301. curs.execute("select css from custom where user = ?", [ip + ' (head)'])
  3302. head_data = curs.fetchall()
  3303. if head_data:
  3304. data = head_data[0][0]
  3305. else:
  3306. data = ''
  3307. else:
  3308. start = '<span>' + load_lang('user_head_warring') + '</span><hr>'
  3309. if 'head' in flask.session:
  3310. data = flask.session['head']
  3311. else:
  3312. data = ''
  3313. start += '<span>&lt;style&gt;css&lt;/style&gt;<br>&lt;script&gt;js&lt;/script&gt;</span><hr>'
  3314. return easy_minify(flask.render_template(skin_check(),
  3315. imp = [load_lang('user') + ' head', wiki_set(), custom(), other2([0, 0])],
  3316. data = start + '''
  3317. <form method="post">
  3318. <textarea rows="25" cols="100" name="content">''' + data + '''</textarea>
  3319. <hr>
  3320. <button id="save" type="submit">''' + load_lang('save') + '''</button>
  3321. </form>
  3322. ''',
  3323. menu = [['user', load_lang('user')]]
  3324. ))
  3325. @app.route('/count')
  3326. @app.route('/count/<name>')
  3327. def count_edit(name = None):
  3328. if name == None:
  3329. that = ip_check()
  3330. else:
  3331. that = name
  3332. curs.execute("select count(title) from history where ip = ?", [that])
  3333. count = curs.fetchall()
  3334. if count:
  3335. data = count[0][0]
  3336. else:
  3337. data = 0
  3338. curs.execute("select count(title) from topic where ip = ?", [that])
  3339. count = curs.fetchall()
  3340. if count:
  3341. t_data = count[0][0]
  3342. else:
  3343. t_data = 0
  3344. return easy_minify(flask.render_template(skin_check(),
  3345. imp = [load_lang('count'), wiki_set(), custom(), other2([0, 0])],
  3346. data = '''
  3347. <ul>
  3348. <li><a href="/record/''' + url_pas(that) + '''">''' + load_lang('edit') + '''</a> : ''' + str(data) + '''</li>
  3349. <li><a href="/topic_record/''' + url_pas(that) + '''">''' + load_lang('discussion') + '''</a> : ''' + str(t_data) + '''</a></li>
  3350. </ul>
  3351. ''',
  3352. menu = [['user', load_lang('user')]]
  3353. ))
  3354. @app.route('/random')
  3355. def title_random():
  3356. curs.execute("select title from data order by random() limit 1")
  3357. data = curs.fetchall()
  3358. if data:
  3359. return redirect('/w/' + url_pas(data[0][0]))
  3360. else:
  3361. return redirect('/')
  3362. @app.route('/skin_set')
  3363. def skin_set():
  3364. return re_error('/error/5')
  3365. @app.route('/api/w/<everything:name>')
  3366. def api_w(name = ''):
  3367. curs.execute("select data from data where title = ?", [name])
  3368. data = curs.fetchall()
  3369. if data:
  3370. json_data = { "title" : name, "data" : render_set(data = data[0][0]) }
  3371. return flask.jsonify(json_data)
  3372. else:
  3373. return flask.jsonify({})
  3374. @app.route('/api/raw/<everything:name>')
  3375. def api_raw(name = ''):
  3376. curs.execute("select data from data where title = ?", [name])
  3377. data = curs.fetchall()
  3378. if data:
  3379. json_data = { "title" : name, "data" : data[0][0] }
  3380. return flask.jsonify(json_data)
  3381. else:
  3382. return flask.jsonify({})
  3383. @app.route('/api/topic/<everything:name>/sub/<sub>')
  3384. def api_topic_sub(name = '', sub = '', time = ''):
  3385. if flask.request.args.get('time', None):
  3386. curs.execute("select id, data, ip from topic where title = ? and sub = ? and date >= ? order by id + 0 asc", [name, sub, flask.request.args.get('time', None)])
  3387. else:
  3388. curs.execute("select id, data, ip from topic where title = ? and sub = ? order by id + 0 asc", [name, sub])
  3389. data = curs.fetchall()
  3390. if data:
  3391. json_data = {}
  3392. for i in data:
  3393. json_data[i[0]] = {
  3394. "data" : i[1],
  3395. "id" : i[2]
  3396. }
  3397. return flask.jsonify(json_data)
  3398. else:
  3399. return flask.jsonify({})
  3400. @app.route('/views/<everything:name>')
  3401. def views(name = None):
  3402. if re.search('\/', name):
  3403. m = re.search('^(.*)\/(.*)$', name)
  3404. if m:
  3405. n = m.groups()
  3406. plus = '/' + n[0]
  3407. rename = n[1]
  3408. else:
  3409. plus = ''
  3410. rename = name
  3411. else:
  3412. plus = ''
  3413. rename = name
  3414. m = re.search('\.(.+)$', name)
  3415. if m:
  3416. g = m.groups()
  3417. else:
  3418. g = ['']
  3419. if g == 'css':
  3420. return easy_minify(flask.send_from_directory('./views' + plus, rename))
  3421. elif g == 'js':
  3422. return easy_minify(flask.send_from_directory('./views' + plus, rename))
  3423. elif g == 'html':
  3424. return easy_minify(flask.send_from_directory('./views' + plus, rename))
  3425. else:
  3426. return flask.send_from_directory('./views' + plus, rename)
  3427. @app.route('/<data>')
  3428. def main_file(data = None):
  3429. if re.search('\.(txt|html)$', data):
  3430. return flask.send_from_directory('./', data)
  3431. else:
  3432. return redirect('/w/' + url_pas(wiki_set(2)))
  3433. @app.errorhandler(404)
  3434. def error_404(e):
  3435. return redirect('/w/' + url_pas(wiki_set(2)))
  3436. if __name__=="__main__":
  3437. app.secret_key = rep_key
  3438. http_server = tornado.httpserver.HTTPServer(tornado.wsgi.WSGIContainer(app))
  3439. http_server.listen(rep_port)
  3440. tornado.ioloop.IOLoop.instance().start()