logic.py 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289
  1. # Site Back-End Logic
  2. from hmac import new
  3. from flask import Blueprint, render_template, request, flash, redirect, url_for, make_response
  4. from flask_login import login_user, login_required, logout_user, current_user
  5. from werkzeug.security import generate_password_hash, check_password_hash
  6. from argon2 import PasswordHasher
  7. from .models import User, Message
  8. from . import db
  9. import string, secrets
  10. from flask_wtf import FlaskForm
  11. from wtforms import StringField, SubmitField, PasswordField, FileField, IntegerField, RadioField, TextAreaField
  12. from wtforms.validators import DataRequired
  13. logic = Blueprint('logic', __name__)
  14. # WTForm Classes
  15. class DescForm(FlaskForm):
  16. # declare form field, required input, placeholder and validate data
  17. description = TextAreaField(validators=[DataRequired()])
  18. submit = SubmitField('Update your Description')
  19. class PasswdForm(FlaskForm):
  20. passwd_1 = PasswordField('Edit Password', validators=[DataRequired()])
  21. passwd_2 = PasswordField('Confirm Password', validators=[DataRequired()])
  22. submit = SubmitField('Update Password')
  23. class MsgForm(FlaskForm):
  24. msg = TextAreaField(validators=[DataRequired()])
  25. submit = SubmitField('Send')
  26. class LoginForm(FlaskForm):
  27. email = StringField(validators=[DataRequired()])
  28. passwd = PasswordField(validators=[DataRequired()])
  29. submit = SubmitField('Login')
  30. class RegForm(FlaskForm):
  31. email = StringField(validators=[DataRequired()])
  32. passwd_1 = PasswordField(validators=[DataRequired()])
  33. passwd_2 = PasswordField(validators=[DataRequired()])
  34. firstname = StringField(validators=[DataRequired()])
  35. lastname = StringField(validators=[DataRequired()])
  36. age = IntegerField(validators=[DataRequired()])
  37. gender = RadioField('Gender', choices=[('M', 'Male'),('F', 'Female')], validators=[DataRequired()])
  38. submit = SubmitField('Register')
  39. @logic.route('/', methods=['GET', 'POST'])
  40. @login_required
  41. def profile():
  42. form_1 = DescForm()
  43. form_2 = PasswdForm()
  44. ph = PasswordHasher()
  45. # WTForm Validation Checks
  46. if form_1.validate_on_submit():
  47. new_desc = form_1.description.data
  48. form_1.description.data = ''
  49. new_desc_dbcall = User.query.filter_by(id=current_user.id).first()
  50. new_desc_dbcall.description = new_desc
  51. db.session.commit()
  52. flash('Hooray! A new description!', category='success')
  53. elif form_2.validate_on_submit():
  54. passwd_1 = form_2.passwd_1.data
  55. passwd_2 = form_2.passwd_2.data
  56. form_2.passwd_1.data = ''
  57. form_2.passwd_2.data = ''
  58. if passwd_1 == passwd_2:
  59. if len(passwd_2) >= 12:
  60. npasswd = ph.hash(passwd_con)
  61. new_passwd_dbcall = User.query.filter_by(id=current_user.id).first()
  62. new_passwd_dbcall.password = npasswd
  63. db.session.commit()
  64. flash('Nice! Updated your password!', category='success')
  65. else:
  66. flash('Password must be equal or longer than 12 characters!', category='error')
  67. else:
  68. flash('Oh no! Your passwords must match!', category='error')
  69. # DB Insertions
  70. if request.method == "POST":
  71. new_pic = request.files.get('profilepic_upload')
  72. if new_pic:
  73. # generate random filename for uploaded file
  74. alphanumeric = string.ascii_letters + string.digits
  75. ralphanum = ''.join(secrets.choice(alphanumeric) for i in range(16))
  76. new_pic_dbcall = User.query.filter_by(id=current_user.id).first()
  77. if '.png' in new_pic.filename:
  78. new_pic.save(f'app/static/uploads/{ralphanum}.png')
  79. new_pic_dbcall.profile_image = f'{ralphanum}.png'
  80. elif '.jpg' in new_pic.filename or 'jpeg' in new_pic.filename:
  81. new_pic.save(f'app/static/uploads/{ralphanum}.jpeg')
  82. new_pic_dbcall.profile_image = f'{ralphanum}.jpeg'
  83. db.session.commit()
  84. response = make_response(render_template("profile.html", user = current_user, form1 = form_1, form2= form_2))
  85. response.headers['Content-Security-Policy'] = "default-src 'self'"
  86. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  87. response.headers['X-Content-Type-Options'] = 'nosniff'
  88. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  89. return response
  90. @logic.route('/matchbook', methods=['GET', 'POST'])
  91. @login_required
  92. def matchbook():
  93. all_users = User.query.all()
  94. if request.method == 'POST':
  95. recipient_id = request.form.get('message_recipient')
  96. fdbcall = User.query.filter_by(id=current_user.id).first()
  97. fdbcall.focus = recipient_id
  98. db.session.commit()
  99. response = make_response(redirect(url_for('logic.messaging')))
  100. response.headers['Content-Security-Policy'] = "default-src 'self'"
  101. return response
  102. response = make_response(render_template("matchbook.html", user=current_user, userlist=all_users))
  103. response.headers['Content-Security-Policy'] = "default-src 'self'"
  104. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  105. response.headers['X-Content-Type-Options'] = 'nosniff'
  106. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  107. return response
  108. @logic.route('/messaging', methods=['GET', 'POST'])
  109. @login_required
  110. def messaging():
  111. recipient_id = current_user.focus
  112. recipient = User.query.filter_by(id=recipient_id).first()
  113. sent_history = Message.query.filter_by(sender=current_user.id, recipient=recipient.id).all()
  114. recv_history = Message.query.filter_by(sender=recipient.id, recipient=current_user.id).all()
  115. joint_history = sent_history + recv_history
  116. joint_history.sort(key=lambda x: x.id) # add reverse=True for descending
  117. form = MsgForm()
  118. if form.validate_on_submit():
  119. message = form.msg.data
  120. form.msg.data = ''
  121. new_msg_dbcall = Message(sender=current_user.id, recipient=recipient.id, message=message)
  122. db.session.add(new_msg_dbcall)
  123. db.session.commit()
  124. response = make_response(redirect(url_for('logic.messaging')))
  125. response.headers['Content-Security-Policy'] = "default-src 'self'"
  126. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  127. response.headers['X-Content-Type-Options'] = 'nosniff'
  128. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  129. return response
  130. response = make_response(render_template(
  131. "messaging.html",
  132. user = current_user,
  133. recipient = recipient,
  134. msg_hist = joint_history,
  135. form = form
  136. ))
  137. response.headers['Content-Security-Policy'] = "default-src 'self'"
  138. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  139. response.headers['X-Content-Type-Options'] = 'nosniff'
  140. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  141. return response
  142. @logic.route('/login', methods=['GET', 'POST'])
  143. def login():
  144. form = LoginForm()
  145. ph = PasswordHasher()
  146. if form.validate_on_submit():
  147. email = form.email.data
  148. form.email.data = ''
  149. challenge_passwd = form.passwd.data
  150. form.passwd.data = ''
  151. user = User.query.filter_by(email=email).first()
  152. if user:
  153. if ph.verify(user.password, challenge_passwd):
  154. flash('Successful Login!', category='success')
  155. login_user(user, remember=True)
  156. return redirect(url_for('logic.profile'))
  157. else:
  158. flash('Unsucessful Login!', category='error')
  159. else:
  160. flash('Unsucessful Login!', category='error')
  161. response = make_response (render_template(
  162. "login.html",
  163. user = current_user,
  164. form = form
  165. ))
  166. response.headers['Content-Security-Policy'] = "default-src 'self'"
  167. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  168. response.headers['X-Content-Type-Options'] = 'nosniff'
  169. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  170. return response
  171. @logic.route('/logout')
  172. @login_required
  173. def logout():
  174. logout_user()
  175. response = make_response(redirect(url_for('logic.login')))
  176. response.headers['Content-Security-Policy'] = "default-src 'self'"
  177. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  178. response.headers['X-Content-Type-Options'] = 'nosniff'
  179. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  180. return response
  181. # Signup Route
  182. @logic.route('/register', methods=['GET', 'POST'])
  183. def register():
  184. pass_list = list()
  185. ph = PasswordHasher()
  186. form = RegForm()
  187. if form.validate_on_submit():
  188. email = form.email.data
  189. firstname = form.firstname.data
  190. lastname = form.lastname.data
  191. age = form.age.data
  192. gender = form.gender.data
  193. passwd_1 = form.passwd_1.data
  194. passwd_2 = form.passwd_2.data
  195. # Basic User Input Checks
  196. email_check = User.query.filter_by(email=email).first()
  197. if len(email) < 1:
  198. flash('Your Email must be longer than 0 characters.', category='error')
  199. elif email_check:
  200. flash('This Email is already taken', category='error')
  201. else:
  202. pass_list.append('p')
  203. if len(firstname) < 1:
  204. flash('First name must be something', category='error')
  205. else:
  206. pass_list.append('p')
  207. if len(lastname) < 1:
  208. flash('Last name must be something', category='error')
  209. else:
  210. pass_list.append('p')
  211. if gender == 'M' or gender == 'F':
  212. pass_list.append('p')
  213. else:
  214. flash('Gender must be either M or F!', category='error')
  215. if len(passwd_1) < 12 or len(passwd_2) < 12:
  216. flash('Your Password must be longer than or equal to 12 characters.', category='error')
  217. else:
  218. if passwd_1 != passwd_2:
  219. flash('Your Passwords must match!', category='error')
  220. else:
  221. if len(pass_list) == 4:
  222. npasswd = ph.hash(passwd_2)
  223. new_user = User(email=email, firstname=firstname, lastname=lastname, age=age, gender=gender, password=npasswd)
  224. db.session.add(new_user)
  225. db.session.commit()
  226. flash('Account Registration Successful!', category='success')
  227. response = make_response(redirect(url_for('logic.profile')))
  228. response.headers['Content-Security-Policy'] = "default-src 'self'"
  229. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  230. response.headers['X-Content-Type-Options'] = 'nosniff'
  231. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  232. return response
  233. else:
  234. flash('Registration Failed', category='error')
  235. response = make_response(render_template("register.html", user = current_user, form = form))
  236. response.headers['Content-Security-Policy'] = "default-src 'self'"
  237. response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains'
  238. response.headers['X-Content-Type-Options'] = 'nosniff'
  239. response.headers['X-Frame-Options'] = 'SAMEORIGIN'
  240. return response