views.py 9.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313
  1. import os
  2. import io
  3. import shutil
  4. import datetime
  5. from functools import wraps
  6. from nova import app, db, login_manager, fs, logic, memtar
  7. from nova.models import User, Dataset, Access
  8. from flask import (Response, render_template, request, flash, redirect,
  9. abort, url_for)
  10. from flask_login import login_required, login_user, logout_user, current_user
  11. from flask_wtf import Form
  12. from wtforms import StringField, BooleanField
  13. from wtforms.validators import DataRequired
  14. from itsdangerous import Signer
  15. def login_required(admin=False):
  16. def wrapper(func):
  17. @wraps(func)
  18. def decorated_view(*args, **kwargs):
  19. if not current_user.is_authenticated:
  20. return login_manager.unauthorized()
  21. if admin and not current_user.is_admin:
  22. return login_manager.unauthorized()
  23. return func(*args, **kwargs)
  24. return decorated_view
  25. return wrapper
  26. class LoginForm(Form):
  27. name = StringField('name', validators=[DataRequired()])
  28. password = StringField('password', validators=[DataRequired()])
  29. class SignupForm(Form):
  30. name = StringField('name', validators=[DataRequired()])
  31. fullname = StringField('fullname', validators=[DataRequired()])
  32. email = StringField('email', validators=[DataRequired()])
  33. password = StringField('password', validators=[DataRequired()])
  34. is_admin = BooleanField('is_admin')
  35. class CreateForm(Form):
  36. name = StringField('name', validators=[DataRequired()])
  37. @login_manager.user_loader
  38. def load_user(user_id):
  39. return db.session.query(User).filter(User.name == user_id).first()
  40. @app.route('/login', methods=['GET', 'POST'])
  41. def login():
  42. form = LoginForm()
  43. if form.validate_on_submit():
  44. user = db.session.query(User).filter(User.name == form.name.data).first()
  45. if user.password == form.password.data:
  46. login_user(user)
  47. flash('Logged in successfully')
  48. return redirect(url_for('index'))
  49. else:
  50. return abort(401)
  51. return render_template('user/login.html', form=form)
  52. @app.route('/logout')
  53. @login_required(admin=False)
  54. def logout():
  55. logout_user()
  56. return redirect(url_for('index'))
  57. @app.route('/')
  58. @login_required(admin=False)
  59. def index():
  60. result = db.session.query(Dataset, Access).\
  61. filter(Access.user == current_user).\
  62. filter(Access.dataset_id == Dataset.id).\
  63. all()
  64. datasets, accesses = zip(*result) if result else ([], [])
  65. shared = db.session.query(Dataset, Access).\
  66. filter(Access.user == current_user).\
  67. filter(Access.dataset_id == Dataset.id).\
  68. filter(Access.owner == False).\
  69. filter(Access.seen == False).\
  70. all()
  71. shared, shared_accesses = zip(*shared) if shared else ([], [])
  72. for access in shared_accesses:
  73. access.seen = True
  74. db.session.commit()
  75. # XXX: we should cache this and compute outside
  76. num_files, total_size = fs.get_statistics(datasets)
  77. return render_template('index.html', result=result, shared=shared, num_files=num_files, total_size=total_size)
  78. @app.route('/user/admin')
  79. @login_required(admin=True)
  80. def admin():
  81. users = db.session.query(User).all()
  82. return render_template('user/admin.html', users=users)
  83. @app.route('/user/settings')
  84. @login_required(admin=False)
  85. def settings():
  86. return render_template('user/settings.html')
  87. @app.route('/user/token/generate')
  88. @login_required(admin=False)
  89. def generate_token():
  90. time = datetime.datetime.utcnow()
  91. signer = Signer(current_user.password.hash + time.isoformat())
  92. current_user.token = signer.sign(str(current_user.id))
  93. current_user.token_time = time
  94. db.session.commit()
  95. return redirect(url_for('settings'))
  96. @app.route('/user/token/revoke')
  97. @login_required(admin=False)
  98. def revoke_token():
  99. signer = Signer(current_user.password.hash)
  100. current_user.token = None
  101. db.session.commit()
  102. return redirect(url_for('settings'))
  103. @app.route('/signup', methods=['GET', 'POST'])
  104. @login_required(admin=True)
  105. def signup():
  106. form = SignupForm()
  107. if form.validate_on_submit():
  108. user = User(name=form.name.data, fullname=form.fullname.data,
  109. email=form.email.data, password=form.password.data,
  110. is_admin=form.is_admin.data)
  111. db.session.add(user)
  112. db.session.commit()
  113. return redirect(url_for('admin'))
  114. return render_template('user/signup.html', form=form)
  115. @app.route('/create', methods=['GET', 'POST'])
  116. @login_required(admin=False)
  117. def create():
  118. form = CreateForm()
  119. if form.validate_on_submit():
  120. logic.create_dataset(form.name.data, current_user)
  121. return redirect(url_for('index'))
  122. return render_template('dataset/create.html', form=form)
  123. @app.route('/share/<int:dataset_id>')
  124. @app.route('/share/<int:dataset_id>/<int:user_id>')
  125. @login_required(admin=False)
  126. def share(dataset_id, user_id=None):
  127. if not user_id:
  128. users = db.session.query(User).filter(User.id != current_user.id).all()
  129. return render_template('dataset/share.html', users=users, dataset_id=dataset_id)
  130. user = db.session.query(User).filter(User.id == user_id).first()
  131. dataset = db.session.query(Dataset).filter(Dataset.id == dataset_id).first()
  132. access = Access(user=user, dataset=dataset, owner=False, writable=False)
  133. db.session.add(access)
  134. db.session.commit()
  135. return redirect(url_for('index'))
  136. def copytree(src, dst, symlinks=False, ignore=None):
  137. for item in os.listdir(src):
  138. s = os.path.join(src, item)
  139. d = os.path.join(dst, item)
  140. if os.path.isdir(s):
  141. copytree(s, d, symlinks, ignore)
  142. else:
  143. if not os.path.exists(d) or os.stat(s).st_mtime - os.stat(d).st_mtime > 1:
  144. shutil.copy2(s, d)
  145. def copy(dataset, parent):
  146. root = app.config['NOVA_ROOT_PATH']
  147. src = os.path.join(root, parent.path)
  148. dst = os.path.join(root, dataset.path)
  149. app.logger.info("Copy data from {} to {}".format(src, dst))
  150. copytree(src, dst)
  151. processors = {
  152. 'copy': copy
  153. }
  154. @app.route('/process/<int:dataset_id>')
  155. @app.route('/process/<int:dataset_id>/<process>', methods=['GET', 'POST'])
  156. @login_required(admin=False)
  157. def process(dataset_id, process=None):
  158. parent = db.session.query(Dataset).filter(Dataset.id == dataset_id).first()
  159. if not process:
  160. return render_template('dataset/process.html', dataset=parent)
  161. dataset = logic.create_dataset(request.form['name'], current_user, parent=parent)
  162. processors[process](dataset, parent)
  163. return redirect(url_for('index'))
  164. @app.route('/detail/<int:dataset_id>')
  165. @app.route('/detail/<int:dataset_id>/<path:path>')
  166. @login_required(admin=False)
  167. def detail(dataset_id=None, path=''):
  168. dataset = db.session.query(Dataset).\
  169. filter(Dataset.id == dataset_id).\
  170. filter(Access.user == current_user).\
  171. filter(Access.dataset_id == dataset_id).first()
  172. # FIXME: scream if no dataset found
  173. origin = []
  174. parent = dataset.parent[0] if dataset.parent else None
  175. while parent:
  176. origin.append(parent)
  177. parent = parent.parent[0] if parent.parent else None
  178. origin = origin[::-1]
  179. parts = path.split('/')
  180. subpaths = []
  181. for part in parts:
  182. if subpaths:
  183. subpaths.append((part, os.path.join(subpaths[-1][1], part)))
  184. else:
  185. subpaths.append((part, part))
  186. dirs = fs.get_dirs(dataset, path)
  187. files = fs.get_files(dataset, path)
  188. params = dict(dataset=dataset, path=path, subpaths=subpaths,
  189. files=files, dirs=dirs, origin=origin)
  190. return render_template('dataset/detail.html', **params)
  191. @app.route('/delete/<int:dataset_id>')
  192. @login_required(admin=False)
  193. def delete(dataset_id=None):
  194. result = db.session.query(Dataset, Access).\
  195. filter(Access.user == current_user).\
  196. filter(Access.dataset_id == dataset_id).first()
  197. dataset, access = result
  198. if dataset:
  199. db.session.delete(dataset)
  200. db.session.delete(access)
  201. db.session.commit()
  202. return redirect(url_for('index'))
  203. @app.route('/upload/<int:dataset_id>', methods=['POST'])
  204. def upload(dataset_id):
  205. user = logic.check_token(request.args.get('token'))
  206. dataset = db.session.query(Dataset).\
  207. filter(Access.user == user).\
  208. filter(Access.dataset_id == dataset_id).\
  209. filter(Dataset.id == dataset_id).first()
  210. f = io.BytesIO(request.data)
  211. memtar.extract_tar(f, os.path.join(app.config['NOVA_ROOT_PATH'], dataset.path))
  212. return ''
  213. @app.route('/clone/<int:dataset_id>')
  214. def clone(dataset_id):
  215. user = logic.check_token(request.args.get('token'))
  216. dataset = db.session.query(Dataset).\
  217. filter(Access.user == user).\
  218. filter(Access.dataset_id == dataset_id).\
  219. filter(Dataset.id == dataset_id).first()
  220. root = app.config['NOVA_ROOT_PATH']
  221. path = os.path.join(root, dataset.path)
  222. fileobj = memtar.create_tar(path)
  223. fileobj.seek(0)
  224. def generate():
  225. while True:
  226. data = fileobj.read(4096)
  227. if not data:
  228. break
  229. yield data
  230. return Response(generate(), mimetype='application/gzip')