You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436
  1. import string
  2. import urlparse
  3. import random
  4. from django import forms
  5. from django.conf import settings
  6. from django.contrib.auth import forms as auth_forms
  7. from django.contrib.auth.forms import AuthenticationForm
  8. from django.contrib.auth.tokens import default_token_generator
  9. from django.contrib.sites.models import get_current_site
  10. from django.core import validators
  11. from django.core.exceptions import ObjectDoesNotExist
  12. from django.core.exceptions import ValidationError
  13. from django.db.models import get_model
  14. from django.utils.translation import ugettext_lazy as _
  15. from oscar.core.loading import get_profile_class, get_class
  16. from oscar.core.compat import get_user_model
  17. from oscar.apps.customer.utils import get_password_reset_url, normalise_email
  18. Dispatcher = get_class('customer.utils', 'Dispatcher')
  19. CommunicationEventType = get_model('customer', 'communicationeventtype')
  20. ProductAlert = get_model('customer', 'ProductAlert')
  21. User = get_user_model()
  22. def generate_username():
  23. uname = ''.join([random.choice(string.letters + string.digits + '_')
  24. for i in range(30)])
  25. try:
  26. User.objects.get(username=uname)
  27. return generate_username()
  28. except User.DoesNotExist:
  29. return uname
  30. class PasswordResetForm(auth_forms.PasswordResetForm):
  31. """
  32. This form takes the same structure as its parent from django.contrib.auth
  33. """
  34. communication_type_code = "PASSWORD_RESET"
  35. def save(self, domain_override=None,
  36. subject_template_name='registration/password_reset_subject.txt',
  37. email_template_name='registration/password_reset_email.html',
  38. use_https=False, token_generator=default_token_generator,
  39. from_email=None, request=None, **kwargs):
  40. """
  41. Generates a one-use only link for resetting password and sends to the
  42. user.
  43. """
  44. site = get_current_site(request)
  45. if domain_override is not None:
  46. site.domain = site.name = domain_override
  47. email = self.cleaned_data['email']
  48. users = User._default_manager.filter(email__iexact=email)
  49. for user in users:
  50. # Build reset url
  51. reset_url = "%s://%s%s" % (
  52. 'https' if use_https else 'http',
  53. site.domain,
  54. get_password_reset_url(user))
  55. ctx = {
  56. 'user': user,
  57. 'site': site,
  58. 'reset_url': reset_url}
  59. messages = CommunicationEventType.objects.get_and_render(
  60. code=self.communication_type_code, context=ctx)
  61. Dispatcher().dispatch_user_messages(user, messages)
  62. class EmailAuthenticationForm(AuthenticationForm):
  63. """
  64. Extends the standard django AuthenticationForm, to support 75 character
  65. usernames. 75 character usernames are needed to support the EmailOrUsername
  66. auth backend.
  67. """
  68. username = forms.EmailField(label=_('Email Address'))
  69. redirect_url = forms.CharField(
  70. widget=forms.HiddenInput, required=False)
  71. def __init__(self, host, *args, **kwargs):
  72. self.host = host
  73. super(EmailAuthenticationForm, self).__init__(*args, **kwargs)
  74. def clean_redirect_url(self):
  75. url = self.cleaned_data['redirect_url'].strip()
  76. if not url:
  77. return settings.LOGIN_REDIRECT_URL
  78. host = urlparse.urlparse(url)[1]
  79. if host and host != self.host:
  80. return settings.LOGIN_REDIRECT_URL
  81. return url
  82. class CommonPasswordValidator(validators.BaseValidator):
  83. # See
  84. # http://www.smartplanet.com/blog/business-brains/top-20-most-common-passwords-of-all-time-revealed-8216123456-8216princess-8216qwerty/4519 # noqa
  85. forbidden_passwords = [
  86. 'password',
  87. '1234',
  88. '12345'
  89. '123456',
  90. '123456y',
  91. '123456789',
  92. 'iloveyou',
  93. 'princess',
  94. 'monkey',
  95. 'rockyou',
  96. 'babygirl',
  97. 'monkey',
  98. 'qwerty',
  99. '654321',
  100. 'dragon',
  101. 'pussy',
  102. 'baseball',
  103. 'football',
  104. 'letmein',
  105. 'monkey',
  106. '696969',
  107. 'abc123',
  108. 'qwe123',
  109. 'qweasd',
  110. 'mustang',
  111. 'michael',
  112. 'shadow',
  113. 'master',
  114. 'jennifer',
  115. '111111',
  116. '2000',
  117. 'jordan',
  118. 'superman'
  119. 'harley'
  120. ]
  121. message = _("Please choose a less common password")
  122. code = 'password'
  123. def __init__(self, password_file=None):
  124. self.limit_value = password_file
  125. def clean(self, value):
  126. return value.strip()
  127. def compare(self, value, limit):
  128. return value in self.forbidden_passwords
  129. def get_forbidden_passwords(self):
  130. if self.limit_value is None:
  131. return self.forbidden_passwords
  132. class EmailUserCreationForm(forms.ModelForm):
  133. email = forms.EmailField(label=_('Email address'))
  134. password1 = forms.CharField(
  135. label=_('Password'), widget=forms.PasswordInput,
  136. validators=[validators.MinLengthValidator(6),
  137. CommonPasswordValidator()])
  138. password2 = forms.CharField(
  139. label=_('Confirm password'), widget=forms.PasswordInput)
  140. redirect_url = forms.CharField(
  141. widget=forms.HiddenInput, required=False)
  142. class Meta:
  143. model = User
  144. fields = ('email',)
  145. def __init__(self, host=None, *args, **kwargs):
  146. self.host = host
  147. super(EmailUserCreationForm, self).__init__(*args, **kwargs)
  148. def clean_email(self):
  149. email = normalise_email(self.cleaned_data['email'])
  150. if User._default_manager.filter(email=email).exists():
  151. raise forms.ValidationError(
  152. _("A user with that email address already exists."))
  153. return email
  154. def clean_password2(self):
  155. password1 = self.cleaned_data.get('password1', '')
  156. password2 = self.cleaned_data.get('password2', '')
  157. if password1 != password2:
  158. raise forms.ValidationError(
  159. _("The two password fields didn't match."))
  160. return password2
  161. def clean_redirect_url(self):
  162. url = self.cleaned_data['redirect_url'].strip()
  163. if not url:
  164. return settings.LOGIN_REDIRECT_URL
  165. host = urlparse.urlparse(url)[1]
  166. if host and self.host and host != self.host:
  167. return settings.LOGIN_REDIRECT_URL
  168. return url
  169. def save(self, commit=True):
  170. user = super(EmailUserCreationForm, self).save(commit=False)
  171. user.set_password(self.cleaned_data['password1'])
  172. if 'username' in [f.name for f in User._meta.fields]:
  173. user.username = generate_username()
  174. if commit:
  175. user.save()
  176. return user
  177. class OrderSearchForm(forms.Form):
  178. date_from = forms.DateField(required=False, label=_("From"))
  179. date_to = forms.DateField(required=False, label=_("To"))
  180. order_number = forms.CharField(required=False, label=_("Order number"))
  181. def clean(self):
  182. if self.is_valid() and not any([self.cleaned_data['date_from'],
  183. self.cleaned_data['date_to'],
  184. self.cleaned_data['order_number']]):
  185. raise forms.ValidationError(_("At least one field is required."))
  186. return super(OrderSearchForm, self).clean()
  187. def description(self):
  188. """
  189. Uses the form's data to build a useful description of what orders
  190. are listed.
  191. """
  192. if not self.is_bound or not self.is_valid():
  193. return _('All orders')
  194. else:
  195. date_from = self.cleaned_data['date_from']
  196. date_to = self.cleaned_data['date_to']
  197. order_number = self.cleaned_data['order_number']
  198. return self._orders_description(date_from, date_to, order_number)
  199. def _orders_description(self, date_from, date_to, order_number):
  200. if date_from and date_to:
  201. if order_number:
  202. desc = _('Orders placed between %(date_from)s and '
  203. '%(date_to)s and order number containing '
  204. '%(order_number)s')
  205. else:
  206. desc = _('Orders placed between %(date_from)s and '
  207. '%(date_to)s')
  208. elif date_from:
  209. if order_number:
  210. desc = _('Orders placed since %(date_from)s and '
  211. 'order number containing %(order_number)s')
  212. else:
  213. desc = _('Orders placed since %(date_from)s')
  214. elif date_to:
  215. if order_number:
  216. desc = _('Orders placed until %(date_to)s and '
  217. 'order number containing %(order_number)s')
  218. else:
  219. desc = _('Orders placed until %(date_to)s')
  220. elif order_number:
  221. desc = _('Orders with order number containing %(order_number)s')
  222. else:
  223. return None
  224. params = {
  225. 'date_from': date_from,
  226. 'date_to': date_to,
  227. 'order_number': order_number,
  228. }
  229. return desc % params
  230. def get_filters(self):
  231. date_from = self.cleaned_data['date_from']
  232. date_to = self.cleaned_data['date_to']
  233. order_number = self.cleaned_data['order_number']
  234. kwargs = {}
  235. if date_from and date_to:
  236. kwargs['date_placed__range'] = [date_from, date_to]
  237. elif date_from and not date_to:
  238. kwargs['date_placed__gt'] = date_from
  239. elif not date_from and date_to:
  240. kwargs['date_placed__lt'] = date_to
  241. if order_number:
  242. kwargs['number__contains'] = order_number
  243. return kwargs
  244. class UserForm(forms.ModelForm):
  245. def __init__(self, user, *args, **kwargs):
  246. self.user = user
  247. kwargs['instance'] = user
  248. super(UserForm, self).__init__(*args, **kwargs)
  249. if 'email' in self.fields:
  250. self.fields['email'].required = True
  251. def clean_email(self):
  252. """
  253. Make sure that the email address is aways unique as it is
  254. used instead of the username. This is necessary because the
  255. unique-ness of email addresses is *not* enforced on the model
  256. level in ``django.contrib.auth.models.User``.
  257. """
  258. email = normalise_email(self.cleaned_data['email'])
  259. if User._default_manager.filter(
  260. email=email).exclude(id=self.user.id).exists():
  261. raise ValidationError(
  262. _("A user with this email address already exists"))
  263. return email
  264. class Meta:
  265. model = User
  266. exclude = ('username', 'password', 'is_staff', 'is_superuser',
  267. 'is_active', 'last_login', 'date_joined',
  268. 'user_permissions', 'groups')
  269. Profile = get_profile_class()
  270. if Profile:
  271. class UserAndProfileForm(forms.ModelForm):
  272. email = forms.EmailField(label=_('Email address'), required=True)
  273. def __init__(self, user, *args, **kwargs):
  274. self.user = user
  275. try:
  276. instance = Profile.objects.get(user=user)
  277. except ObjectDoesNotExist:
  278. # User has no profile, try a blank one
  279. instance = Profile(user=user)
  280. kwargs['instance'] = instance
  281. super(UserAndProfileForm, self).__init__(*args, **kwargs)
  282. # Get a list of profile fields to help with ordering later
  283. profile_field_names = self.fields.keys()
  284. del profile_field_names[profile_field_names.index('email')]
  285. self.fields['email'].initial = self.instance.user.email
  286. # Add user fields (we look for core user fields first)
  287. core_field_names = set([f.name for f in User._meta.fields])
  288. user_field_names = ['email']
  289. for field_name in ('first_name', 'last_name'):
  290. if field_name in core_field_names:
  291. user_field_names.append(field_name)
  292. user_field_names.extend(User._meta.additional_fields)
  293. # Store user fields so we know what to save later
  294. self.user_field_names = user_field_names
  295. # Add additional user fields
  296. additional_fields = forms.fields_for_model(
  297. User, fields=user_field_names)
  298. self.fields.update(additional_fields)
  299. # Set initial values
  300. for field_name in user_field_names:
  301. self.fields[field_name].initial = getattr(user, field_name)
  302. # Ensure order of fields is email, user fields then profile fields
  303. self.fields.keyOrder = user_field_names + profile_field_names
  304. class Meta:
  305. model = Profile
  306. exclude = ('user',)
  307. def clean_email(self):
  308. email = normalise_email(self.cleaned_data['email'])
  309. if User._default_manager.filter(
  310. email=email).exclude(id=self.user.id).exists():
  311. raise ValidationError(
  312. _("A user with this email address already exists"))
  313. return email
  314. def save(self, *args, **kwargs):
  315. user = self.instance.user
  316. # Save user also
  317. for field_name in self.user_field_names:
  318. setattr(user, field_name, self.cleaned_data[field_name])
  319. user.save()
  320. return super(ProfileForm, self).save(*args, **kwargs)
  321. ProfileForm = UserAndProfileForm
  322. else:
  323. ProfileForm = UserForm
  324. class ProductAlertForm(forms.ModelForm):
  325. email = forms.EmailField(required=True, label=_(u'Send notification to'),
  326. widget=forms.TextInput(attrs={
  327. 'placeholder': _('Enter your email')
  328. }))
  329. def __init__(self, user, product, *args, **kwargs):
  330. self.user = user
  331. self.product = product
  332. super(ProductAlertForm, self).__init__(*args, **kwargs)
  333. # Only show email field to unauthenticated users
  334. if user and user.is_authenticated():
  335. self.fields['email'].widget = forms.HiddenInput()
  336. self.fields['email'].required = False
  337. def save(self, commit=True):
  338. alert = super(ProductAlertForm, self).save(commit=False)
  339. if self.user.is_authenticated():
  340. alert.user = self.user
  341. alert.product = self.product
  342. if commit:
  343. alert.save()
  344. return alert
  345. def clean(self):
  346. cleaned_data = self.cleaned_data
  347. email = cleaned_data.get('email')
  348. if email:
  349. try:
  350. ProductAlert.objects.get(
  351. product=self.product, email=email,
  352. status=ProductAlert.ACTIVE)
  353. except ProductAlert.DoesNotExist:
  354. pass
  355. else:
  356. raise forms.ValidationError(_(
  357. "There is already an active stock alert for %s") % email)
  358. elif self.user.is_authenticated():
  359. try:
  360. ProductAlert.objects.get(product=self.product,
  361. user=self.user,
  362. status=ProductAlert.ACTIVE)
  363. except ProductAlert.DoesNotExist:
  364. pass
  365. else:
  366. raise forms.ValidationError(_(
  367. "You already have an active alert for this product"))
  368. return cleaned_data
  369. class Meta:
  370. model = ProductAlert
  371. exclude = ('user', 'key',
  372. 'status', 'date_confirmed', 'date_cancelled', 'date_closed',
  373. 'product')