| 1 |
from django.contrib.auth import REDIRECT_FIELD_NAME |
|---|
| 2 |
from django.contrib.auth.decorators import login_required |
|---|
| 3 |
from django.contrib.auth.forms import AuthenticationForm |
|---|
| 4 |
from django.contrib.auth.forms import PasswordResetForm, PasswordChangeForm, AdminPasswordChangeForm |
|---|
| 5 |
from django.core.exceptions import PermissionDenied |
|---|
| 6 |
from django.shortcuts import render_to_response, get_object_or_404 |
|---|
| 7 |
from django.contrib.sites.models import Site, RequestSite |
|---|
| 8 |
from django.http import HttpResponseRedirect |
|---|
| 9 |
from django.template import RequestContext |
|---|
| 10 |
from django.utils.http import urlquote |
|---|
| 11 |
from django.utils.html import escape |
|---|
| 12 |
from django.utils.translation import ugettext as _ |
|---|
| 13 |
from django.contrib.auth.models import User |
|---|
| 14 |
import re |
|---|
| 15 |
|
|---|
| 16 |
def login(request, template_name='registration/login.html', redirect_field_name=REDIRECT_FIELD_NAME): |
|---|
| 17 |
"Displays the login form and handles the login action." |
|---|
| 18 |
redirect_to = request.REQUEST.get(redirect_field_name, '') |
|---|
| 19 |
if request.method == "POST": |
|---|
| 20 |
form = AuthenticationForm(data=request.POST) |
|---|
| 21 |
if form.is_valid(): |
|---|
| 22 |
# Light security check -- make sure redirect_to isn't garbage. |
|---|
| 23 |
if not redirect_to or '//' in redirect_to or ' ' in redirect_to: |
|---|
| 24 |
from django.conf import settings |
|---|
| 25 |
redirect_to = settings.LOGIN_REDIRECT_URL |
|---|
| 26 |
from django.contrib.auth import login |
|---|
| 27 |
login(request, form.get_user()) |
|---|
| 28 |
if request.session.test_cookie_worked(): |
|---|
| 29 |
request.session.delete_test_cookie() |
|---|
| 30 |
return HttpResponseRedirect(redirect_to) |
|---|
| 31 |
else: |
|---|
| 32 |
form = AuthenticationForm(request) |
|---|
| 33 |
request.session.set_test_cookie() |
|---|
| 34 |
if Site._meta.installed: |
|---|
| 35 |
current_site = Site.objects.get_current() |
|---|
| 36 |
else: |
|---|
| 37 |
current_site = RequestSite(request) |
|---|
| 38 |
return render_to_response(template_name, { |
|---|
| 39 |
'form': form, |
|---|
| 40 |
redirect_field_name: redirect_to, |
|---|
| 41 |
'site_name': current_site.name, |
|---|
| 42 |
}, context_instance=RequestContext(request)) |
|---|
| 43 |
|
|---|
| 44 |
def logout(request, next_page=None, template_name='registration/logged_out.html'): |
|---|
| 45 |
"Logs out the user and displays 'You are logged out' message." |
|---|
| 46 |
from django.contrib.auth import logout |
|---|
| 47 |
logout(request) |
|---|
| 48 |
if next_page is None: |
|---|
| 49 |
return render_to_response(template_name, {'title': _('Logged out')}, context_instance=RequestContext(request)) |
|---|
| 50 |
else: |
|---|
| 51 |
# Redirect to this page until the session has been cleared. |
|---|
| 52 |
return HttpResponseRedirect(next_page or request.path) |
|---|
| 53 |
|
|---|
| 54 |
def logout_then_login(request, login_url=None): |
|---|
| 55 |
"Logs out the user if he is logged in. Then redirects to the log-in page." |
|---|
| 56 |
if not login_url: |
|---|
| 57 |
from django.conf import settings |
|---|
| 58 |
login_url = settings.LOGIN_URL |
|---|
| 59 |
return logout(request, login_url) |
|---|
| 60 |
|
|---|
| 61 |
def redirect_to_login(next, login_url=None, redirect_field_name=REDIRECT_FIELD_NAME): |
|---|
| 62 |
"Redirects the user to the login page, passing the given 'next' page" |
|---|
| 63 |
if not login_url: |
|---|
| 64 |
from django.conf import settings |
|---|
| 65 |
login_url = settings.LOGIN_URL |
|---|
| 66 |
return HttpResponseRedirect('%s?%s=%s' % (login_url, urlquote(redirect_field_name), urlquote(next))) |
|---|
| 67 |
|
|---|
| 68 |
def password_reset(request, is_admin_site=False, template_name='registration/password_reset_form.html', |
|---|
| 69 |
email_template_name='registration/password_reset_email.html', |
|---|
| 70 |
password_reset_form=PasswordResetForm): |
|---|
| 71 |
if request.method == "POST": |
|---|
| 72 |
form = password_reset_form(request.POST) |
|---|
| 73 |
if form.is_valid(): |
|---|
| 74 |
if is_admin_site: |
|---|
| 75 |
form.save(domain_override=request.META['HTTP_HOST']) |
|---|
| 76 |
else: |
|---|
| 77 |
if Site._meta.installed: |
|---|
| 78 |
form.save(email_template_name=email_template_name) |
|---|
| 79 |
else: |
|---|
| 80 |
form.save(domain_override=RequestSite(request).domain, email_template_name=email_template_name) |
|---|
| 81 |
return HttpResponseRedirect('%sdone/' % request.path) |
|---|
| 82 |
else: |
|---|
| 83 |
form = password_reset_form() |
|---|
| 84 |
return render_to_response(template_name, { |
|---|
| 85 |
'form': form, |
|---|
| 86 |
}, context_instance=RequestContext(request)) |
|---|
| 87 |
|
|---|
| 88 |
def password_reset_done(request, template_name='registration/password_reset_done.html'): |
|---|
| 89 |
return render_to_response(template_name, context_instance=RequestContext(request)) |
|---|
| 90 |
|
|---|
| 91 |
def password_change(request, template_name='registration/password_change_form.html'): |
|---|
| 92 |
if request.method == "POST": |
|---|
| 93 |
form = PasswordChangeForm(request.user, request.POST) |
|---|
| 94 |
if form.is_valid(): |
|---|
| 95 |
form.save() |
|---|
| 96 |
return HttpResponseRedirect('%sdone/' % request.path) |
|---|
| 97 |
else: |
|---|
| 98 |
form = PasswordChangeForm(request.user) |
|---|
| 99 |
return render_to_response(template_name, { |
|---|
| 100 |
'form': form, |
|---|
| 101 |
}, context_instance=RequestContext(request)) |
|---|
| 102 |
password_change = login_required(password_change) |
|---|
| 103 |
|
|---|
| 104 |
def password_change_done(request, template_name='registration/password_change_done.html'): |
|---|
| 105 |
return render_to_response(template_name, context_instance=RequestContext(request)) |
|---|
| 106 |
|
|---|
| 107 |
# TODO: move to admin.py in the ModelAdmin |
|---|
| 108 |
def user_change_password(request, id): |
|---|
| 109 |
if not request.user.has_perm('auth.change_user'): |
|---|
| 110 |
raise PermissionDenied |
|---|
| 111 |
user = get_object_or_404(User, pk=id) |
|---|
| 112 |
if request.method == 'POST': |
|---|
| 113 |
form = AdminPasswordChangeForm(user, request.POST) |
|---|
| 114 |
if form.is_valid(): |
|---|
| 115 |
new_user = form.save() |
|---|
| 116 |
msg = _('Password changed successfully.') |
|---|
| 117 |
request.user.message_set.create(message=msg) |
|---|
| 118 |
return HttpResponseRedirect('..') |
|---|
| 119 |
else: |
|---|
| 120 |
form = AdminPasswordChangeForm(user) |
|---|
| 121 |
return render_to_response('admin/auth/user/change_password.html', { |
|---|
| 122 |
'title': _('Change password: %s') % escape(user.username), |
|---|
| 123 |
'form': form, |
|---|
| 124 |
'is_popup': '_popup' in request.REQUEST, |
|---|
| 125 |
'add': True, |
|---|
| 126 |
'change': False, |
|---|
| 127 |
'has_delete_permission': False, |
|---|
| 128 |
'has_change_permission': True, |
|---|
| 129 |
'has_absolute_url': False, |
|---|
| 130 |
'opts': User._meta, |
|---|
| 131 |
'original': user, |
|---|
| 132 |
'save_as': False, |
|---|
| 133 |
'show_save': True, |
|---|
| 134 |
'root_path': re.sub('auth/user/(\d+)/password/$', '', request.path), |
|---|
| 135 |
}, context_instance=RequestContext(request)) |
|---|