2
0

view_acl.py 9.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194
  1. from .tool.func import *
  2. def view_acl(name):
  3. with get_db_connect() as conn:
  4. curs = conn.cursor()
  5. check_ok = ''
  6. user_page = 0
  7. ip = ip_check()
  8. if flask.request.method == 'POST':
  9. check_data = 'document_set (' + name + ')'
  10. else:
  11. check_data = None
  12. user_data = re.search(r'^user:(.+)$', name)
  13. if user_data:
  14. if check_data and ip_or_user(ip) != 0:
  15. return redirect('/login')
  16. if user_data.group(1) != ip:
  17. if admin_check(5) != 1:
  18. if check_data:
  19. return re_error('/error/3')
  20. else:
  21. check_ok = 'disabled'
  22. else:
  23. user_page = 1
  24. else:
  25. if admin_check(5) != 1:
  26. if check_data:
  27. return re_error('/error/3')
  28. else:
  29. check_ok = 'disabled'
  30. if flask.request.method == 'POST':
  31. acl_data = ['decu', 'document_edit_acl', 'document_move_acl', 'document_delete_acl', 'dis', 'view', 'why']
  32. for i in acl_data:
  33. form_data = flask.request.form.get(i, '')
  34. curs.execute(db_change("delete from acl where title = ? and type = ?"), [name, i])
  35. curs.execute(db_change("insert into acl (title, data, type) values (?, ?, ?)"), [name, form_data, i])
  36. curs.execute(db_change("delete from data_set where doc_name = ? and doc_rev = ? and set_name = 'acl_date'"), [name, i])
  37. time_limit = flask.request.form.get(i + '_date', '')
  38. if re.search(r'^[0-9]{4}-[0-9]{2}-[0-9]{2}$', time_limit):
  39. curs.execute(db_change("insert into data_set (doc_name, doc_rev, set_name, set_data) values (?, ?, 'acl_date', ?)"), [name, i, time_limit])
  40. all_d = ''
  41. for i in acl_data[:-1]:
  42. if flask.request.form.get(i, '') == '':
  43. all_d += 'normal'
  44. if i != 'view':
  45. all_d += ' | '
  46. else:
  47. all_d += flask.request.form.get(i, '')
  48. if i != 'view':
  49. all_d += ' | '
  50. markup_data = flask.request.form.get('document_markup', '')
  51. curs.execute(db_change("select set_data from data_set where doc_name = ? and set_name = 'document_markup'"), [name])
  52. db_data = curs.fetchall()
  53. curs.execute(db_change("delete from data_set where doc_name = ? and set_name = 'document_markup'"), [name])
  54. curs.execute(db_change("insert into data_set (doc_name, doc_rev, set_name, set_data) values (?, '', 'document_markup', ?)"), [name, markup_data])
  55. if not db_data or db_data[0][0] != markup_data:
  56. curs.execute(db_change("select data from data where title = ?"), [name])
  57. db_data_2 = curs.fetchall()
  58. if db_data_2:
  59. render_set(
  60. doc_name = name,
  61. doc_data = db_data_2[0][0],
  62. data_type = 'backlink'
  63. )
  64. markup_data = markup_data if markup_data != '' else 'normal'
  65. if user_page == 1:
  66. admin_check(5, check_data + ' (' + all_d + ')' + ' (' + markup_data + ')')
  67. conn.commit()
  68. return redirect('/acl/' + url_pas(name))
  69. else:
  70. data = '<h2>' + load_lang('acl') + '</h2>'
  71. acl_list = get_acl_list('user') if re.search(r'^user:', name) else get_acl_list()
  72. if not re.search(r'^user:', name):
  73. acl_get_list = [
  74. [load_lang('view_acl'), 'view', '3'],
  75. [load_lang('document_acl'), 'decu', '4'],
  76. [load_lang('document_edit_acl'), 'document_edit_acl', '5'],
  77. [load_lang('document_move_acl'), 'document_move_acl', '5'],
  78. [load_lang('document_delete_acl'), 'document_delete_acl', '5'],
  79. [load_lang('discussion_acl'), 'dis', '3'],
  80. ]
  81. else:
  82. acl_get_list = [
  83. [load_lang('document_acl'), 'decu', '2']
  84. ]
  85. for i in acl_get_list:
  86. data += '' + \
  87. '<h' + i[2] + '>' + i[0] + '</h' + i[2] + '>' + \
  88. '<hr class="main_hr">' + \
  89. '<select name="' + i[1] + '" ' + check_ok + '>' + \
  90. ''
  91. curs.execute(db_change("select data from acl where title = ? and type = ?"), [name, i[1]])
  92. acl_data = curs.fetchall()
  93. for data_list in acl_list:
  94. check = 'selected="selected"' if acl_data and acl_data[0][0] == data_list else ''
  95. data += '<option value="' + data_list + '" ' + check + '>' + (data_list if data_list != '' else 'normal') + '</option>'
  96. data += '</select>'
  97. data += '<hr class="main_hr">'
  98. date_value = ''
  99. curs.execute(db_change("select set_data from data_set where doc_name = ? and doc_rev = ? and set_name = 'acl_date'"), [name, i[1]])
  100. db_data = curs.fetchall()
  101. if db_data:
  102. date_value = db_data[0][0]
  103. data += '<input type="date" ' + check_ok + ' value="' + date_value + '" name="' + i[1] + '_date" pattern="\\d{4}-\\d{2}-\\d{2}">'
  104. data += '<hr class="main_hr">'
  105. curs.execute(db_change("select data from acl where title = ? and type = ?"), [name, 'why'])
  106. acl_data = curs.fetchall()
  107. acl_why = html.escape(acl_data[0][0]) if acl_data else ''
  108. data += '' + \
  109. '<h3>' + load_lang('why') + '</h3>' + \
  110. '<input value="' + acl_why + '" ' + check_ok + ' placeholder="' + load_lang('why') + '" name="why" ' + check_ok + '>' + \
  111. '<hr class="main_hr">' + \
  112. ''
  113. data += '''
  114. <h3>''' + load_lang('explanation') + '''</h3>
  115. <span id="exp"></span>
  116. <ul class="opennamu_ul">
  117. <li>normal : ''' + load_lang('unset') + '''</li>
  118. <li>admin : ''' + load_lang('admin_acl') + '''</li>
  119. <li>user : ''' + load_lang('member_acl') + '''</li>
  120. <li>50_edit : ''' + load_lang('50_edit_acl') + '''</li>
  121. <li>all : ''' + load_lang('all_acl') + '''</li>
  122. <li>email : ''' + load_lang('email_acl') + '''</li>
  123. <li>owner : ''' + load_lang('owner_acl') + '''</li>
  124. <li>ban : ''' + load_lang('ban_acl') + '''</li>
  125. <li>before : ''' + load_lang('before_acl') + '''</li>
  126. <li>30_day : ''' + load_lang('30_day_acl') + '''</li>
  127. <li>ban_admin : ''' + load_lang('ban_admin_acl') + '''</li>
  128. <li>not_all : ''' + load_lang('not_all_acl') + '''</li>
  129. <li>90_day : ''' + load_lang('90_day_acl') + '''</li>
  130. </ul>
  131. <hr class="main_hr">
  132. <h2>''' + load_lang('markup') + '''</h2>
  133. '''
  134. curs.execute(db_change("select set_data from data_set where doc_name = ? and set_name = 'document_markup'"), [name])
  135. db_data = curs.fetchall()
  136. markup_load = db_data[0][0] if db_data and db_data[0][0] != '' else ''
  137. markup_list = ['normal'] + get_init_set_list('markup')['list']
  138. markup_html = ''
  139. for for_a in markup_list:
  140. if markup_load == for_a:
  141. markup_html = '<option value="' + (for_a if for_a != 'normal' else '') + '">' + for_a + '</option>' + markup_html
  142. else:
  143. markup_html += '<option value="' + (for_a if for_a != 'normal' else '') + '">' + for_a + '</option>'
  144. markup_html = '<select name="document_markup" ' + check_ok + '>' + markup_html + '</select>'
  145. data += markup_html
  146. data += '<hr class="main_hr">'
  147. return easy_minify(flask.render_template(skin_check(),
  148. imp = [name, wiki_set(), wiki_custom(), wiki_css(['(' + load_lang('acl') + ')', 0])],
  149. data = '''
  150. <form method="post">
  151. <a href="/setting/acl">(''' + load_lang('main_acl_setting') + ''')</a>
  152. <hr class="main_hr">
  153. ''' + render_simple_set(data) + '''
  154. <button type="submit" ''' + check_ok + '''>''' + load_lang('save') + '''</button>
  155. </form>
  156. ''',
  157. menu = [
  158. ['w/' + url_pas(name), load_lang('return')],
  159. ['manager', load_lang('admin')],
  160. ['list/admin/auth_use_page/1/' + url_pas('acl (' + name + ')'), load_lang('acl_record')]
  161. ]
  162. ))