logic.py 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278
  1. # Site Back-End Logic
  2. from hmac import new
  3. from flask import Blueprint, render_template, request, flash, redirect, url_for, make_response
  4. from flask_login import login_user, login_required, logout_user, current_user
  5. from werkzeug.security import generate_password_hash, check_password_hash
  6. from .models import User, Message
  7. from . import db
  8. import string, secrets
  9. from flask_wtf import FlaskForm
  10. from wtforms import StringField, SubmitField, PasswordField, FileField, IntegerField, RadioField, TextAreaField
  11. from wtforms.validators import DataRequired
  12. logic = Blueprint('logic', __name__)
  13. # WTForm Classes
  14. class DescForm(FlaskForm):
  15. # declare form field, required input, placeholder and validate data
  16. description = TextAreaField(validators=[DataRequired()])
  17. submit = SubmitField('Update your Description')
  18. class PasswdForm(FlaskForm):
  19. passwd_1 = PasswordField('Edit Password', validators=[DataRequired()])
  20. passwd_2 = PasswordField('Confirm Password', validators=[DataRequired()])
  21. submit = SubmitField('Update Password')
  22. class MsgForm(FlaskForm):
  23. msg = TextAreaField(validators=[DataRequired()])
  24. submit = SubmitField('Send')
  25. class LoginForm(FlaskForm):
  26. email = StringField(validators=[DataRequired()])
  27. passwd = PasswordField(validators=[DataRequired()])
  28. submit = SubmitField('Login')
  29. class RegForm(FlaskForm):
  30. email = StringField(validators=[DataRequired()])
  31. passwd_1 = PasswordField(validators=[DataRequired()])
  32. passwd_2 = PasswordField(validators=[DataRequired()])
  33. firstname = StringField(validators=[DataRequired()])
  34. lastname = StringField(validators=[DataRequired()])
  35. age = IntegerField(validators=[DataRequired()])
  36. gender = RadioField('Gender', choices=[('M', 'Male'),('F', 'Female')], validators=[DataRequired()])
  37. submit = SubmitField('Register')
  38. @logic.route('/', methods=['GET', 'POST'])
  39. @login_required
  40. def profile():
  41. form_1 = DescForm()
  42. form_2 = PasswdForm()
  43. # WTForm Validation Checks
  44. if form_1.validate_on_submit():
  45. new_desc = form_1.description.data
  46. form_1.description.data = ''
  47. new_desc_dbcall = User.query.filter_by(id=current_user.id).first()
  48. new_desc_dbcall.description = new_desc
  49. db.session.commit()
  50. flash('Hooray! A new description!', category='success')
  51. elif form_2.validate_on_submit():
  52. passwd_1 = form_2.passwd_1.data
  53. passwd_2 = form_2.passwd_2.data
  54. form_2.passwd_1.data = ''
  55. form_2.passwd_2.data = ''
  56. if passwd_1 == passwd_2:
  57. new_passwd_dbcall = User.query.filter_by(id=current_user.id).first()
  58. new_passwd_dbcall.password = generate_password_hash(passwd_2, method='sha256')
  59. db.session.commit()
  60. flash('Nice! Updated your password!', category='success')
  61. else:
  62. flash('Oh no! Your passwords must match!', category='error')
  63. # DB Insertions
  64. if request.method == "POST":
  65. new_pic = request.files.get('profilepic_upload')
  66. if new_pic:
  67. # generate random filename for uploaded file
  68. alphanumeric = string.ascii_letters + string.digits
  69. ralphanum = ''.join(secrets.choice(alphanumeric) for i in range(16))
  70. new_pic_dbcall = User.query.filter_by(id=current_user.id).first()
  71. if '.png' in new_pic.filename:
  72. new_pic.save(f'app/static/uploads/{ralphanum}.png')
  73. new_pic_dbcall.profile_image = f'{ralphanum}.png'
  74. elif '.jpg' in new_pic.filename or 'jpeg' in new_pic.filename:
  75. new_pic.save(f'app/static/uploads/{ralphanum}.jpeg')
  76. new_pic_dbcall.profile_image = f'{ralphanum}.jpeg'
  77. db.session.commit()
  78. response = make_response(render_template("profile.html", user = current_user, form1 = form_1, form2= form_2))
  79. response.headers['Content-Security-Policy'] = "default-src 'self'"
  80. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  81. response.headers['X-Content-Type-Options'] = 'nosniff'
  82. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  83. return response
  84. @logic.route('/matchbook', methods=['GET', 'POST'])
  85. @login_required
  86. def matchbook():
  87. all_users = User.query.all()
  88. if request.method == 'POST':
  89. recipient_id = request.form.get('message_recipient')
  90. fdbcall = User.query.filter_by(id=current_user.id).first()
  91. fdbcall.focus = recipient_id
  92. db.session.commit()
  93. response = make_response(redirect(url_for('logic.messaging')))
  94. response.headers['Content-Security-Policy'] = "default-src 'self'"
  95. return response
  96. response = make_response(render_template("matchbook.html", user=current_user, userlist=all_users))
  97. response.headers['Content-Security-Policy'] = "default-src 'self'"
  98. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  99. response.headers['X-Content-Type-Options'] = 'nosniff'
  100. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  101. return response
  102. @logic.route('/messaging', methods=['GET', 'POST'])
  103. @login_required
  104. def messaging():
  105. recipient_id = current_user.focus
  106. recipient = User.query.filter_by(id=recipient_id).first()
  107. sent_history = Message.query.filter_by(sender=current_user.id, recipient=recipient.id).all()
  108. recv_history = Message.query.filter_by(sender=recipient.id, recipient=current_user.id).all()
  109. joint_history = sent_history + recv_history
  110. joint_history.sort(key=lambda x: x.id) # add reverse=True for descending
  111. form = MsgForm()
  112. if form.validate_on_submit():
  113. message = form.msg.data
  114. form.msg.data = ''
  115. new_msg_dbcall = Message(sender=current_user.id, recipient=recipient.id, message=message)
  116. db.session.add(new_msg_dbcall)
  117. db.session.commit()
  118. response = make_response(redirect(url_for('logic.messaging')))
  119. response.headers['Content-Security-Policy'] = "default-src 'self'"
  120. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  121. response.headers['X-Content-Type-Options'] = 'nosniff'
  122. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  123. return response
  124. response = make_response(render_template(
  125. "messaging.html",
  126. user = current_user,
  127. recipient = recipient,
  128. msg_hist = joint_history,
  129. form = form
  130. ))
  131. response.headers['Content-Security-Policy'] = "default-src 'self'"
  132. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  133. response.headers['X-Content-Type-Options'] = 'nosniff'
  134. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  135. return response
  136. @logic.route('/login', methods=['GET', 'POST'])
  137. def login():
  138. form = LoginForm()
  139. if form.validate_on_submit():
  140. email = form.email.data
  141. form.email.data = ''
  142. challenge_passwd = form.passwd.data
  143. form.passwd.data = ''
  144. user = User.query.filter_by(email=email).first()
  145. if user:
  146. if check_password_hash(user.password, challenge_passwd):
  147. flash('Successful Login!', category='success')
  148. login_user(user, remember=True)
  149. return redirect(url_for('logic.profile'))
  150. else:
  151. flash('Unsucessful Login!', category='error')
  152. else:
  153. flash('Unsucessful Login!', category='error')
  154. response = make_response (render_template(
  155. "login.html",
  156. user = current_user,
  157. form = form
  158. ))
  159. response.headers['Content-Security-Policy'] = "default-src 'self'"
  160. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  161. response.headers['X-Content-Type-Options'] = 'nosniff'
  162. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  163. return response
  164. @logic.route('/logout')
  165. @login_required
  166. def logout():
  167. logout_user()
  168. response = make_response(redirect(url_for('logic.login')))
  169. response.headers['Content-Security-Policy'] = "default-src 'self'"
  170. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  171. response.headers['X-Content-Type-Options'] = 'nosniff'
  172. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  173. return response
  174. # Signup Route
  175. @logic.route('/register', methods=['GET', 'POST'])
  176. def register():
  177. pass_list = list()
  178. form = RegForm()
  179. if form.validate_on_submit():
  180. email = form.email.data
  181. firstname = form.firstname.data
  182. lastname = form.lastname.data
  183. age = form.age.data
  184. gender = form.gender.data
  185. passwd_1 = form.passwd_1.data
  186. passwd_2 = form.passwd_2.data
  187. # Basic User Input Checks
  188. email_check = User.query.filter_by(email=email).first()
  189. if len(email) < 1:
  190. flash('Your Email must be longer than 0 characters.', category='error')
  191. elif email_check:
  192. flash('This Email is already taken', category='error')
  193. else:
  194. pass_list.append('p')
  195. if len(firstname) < 1:
  196. flash('First name must be something', category='error')
  197. else:
  198. pass_list.append('p')
  199. if len(lastname) < 1:
  200. flash('Last name must be something', category='error')
  201. else:
  202. pass_list.append('p')
  203. if gender == 'M' or gender == 'F':
  204. pass_list.append('p')
  205. else:
  206. flash('Gender must be either M or F!', category='error')
  207. if len(passwd_1) < 8 or len(passwd_2) < 8:
  208. flash('Your Password must be longer than or equal to 8 characters.', category='error')
  209. else:
  210. if passwd_1 != passwd_2:
  211. flash('Your Passwords must match!', category='error')
  212. else:
  213. if len(pass_list) == 4:
  214. new_user = User(email=email, firstname=firstname, lastname=lastname, age=age, gender=gender, password=generate_password_hash(passwd_2, method='sha256'))
  215. db.session.add(new_user)
  216. db.session.commit()
  217. flash('Account Registration Successful!', category='success')
  218. response = make_response(redirect(url_for('logic.profile')))
  219. response.headers['Content-Security-Policy'] = "default-src 'self'"
  220. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  221. response.headers['X-Content-Type-Options'] = 'nosniff'
  222. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  223. return response
  224. else:
  225. flash('Registration Failed', category='error')
  226. response = make_response(render_template("register.html", user = current_user, form = form))
  227. response.headers['Content-Security-Policy'] = "default-src 'self'"
  228. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  229. response.headers['X-Content-Type-Options'] = 'nosniff'
  230. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  231. return response