You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

forms.py 12KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347
  1. import string
  2. import random
  3. from django.contrib.auth.forms import AuthenticationForm
  4. from django.core.urlresolvers import reverse
  5. from django.utils.translation import ugettext_lazy as _
  6. from django.core.exceptions import ObjectDoesNotExist
  7. from django import forms
  8. from django.db.models import get_model
  9. from django.contrib.auth.models import User
  10. from django.contrib.auth import forms as auth_forms
  11. from django.conf import settings
  12. from django.core import validators
  13. from django.core.exceptions import ValidationError
  14. from django.utils.http import int_to_base36
  15. from django.contrib.sites.models import get_current_site
  16. from django.contrib.auth.tokens import default_token_generator
  17. from oscar.core.loading import get_profile_class, get_class
  18. Dispatcher = get_class('customer.utils', 'Dispatcher')
  19. CommunicationEventType = get_model('customer', 'communicationeventtype')
  20. ProductAlert = get_model('customer', 'ProductAlert')
  21. def generate_username():
  22. uname = ''.join([random.choice(string.letters + string.digits + '_') for i in range(30)])
  23. try:
  24. User.objects.get(username=uname)
  25. return generate_username()
  26. except User.DoesNotExist:
  27. return uname
  28. class PasswordResetForm(auth_forms.PasswordResetForm):
  29. communication_type_code = "PASSWORD_RESET"
  30. def save(self, domain_override=None,
  31. subject_template_name='registration/password_reset_subject.txt',
  32. email_template_name='registration/password_reset_email.html',
  33. use_https=False, token_generator=default_token_generator,
  34. from_email=None, request=None, **kwargs):
  35. """
  36. Generates a one-use only link for resetting password and sends to the
  37. user.
  38. """
  39. site = get_current_site(request)
  40. if domain_override is not None:
  41. site.domain = site.name = domain_override
  42. for user in self.users_cache:
  43. # Build reset url
  44. reset_url = "%s://%s%s" % (
  45. 'https' if use_https else 'http',
  46. site.domain,
  47. reverse('password-reset-confirm', kwargs={
  48. 'uidb36': int_to_base36(user.id),
  49. 'token': token_generator.make_token(user)}))
  50. ctx = {
  51. 'site': site,
  52. 'reset_url': reset_url}
  53. messages = CommunicationEventType.objects.get_and_render(
  54. code=self.communication_type_code, context=ctx)
  55. Dispatcher().dispatch_user_messages(user, messages)
  56. class EmailAuthenticationForm(AuthenticationForm):
  57. """
  58. Extends the standard django AuthenticationForm, to support 75 character
  59. usernames. 75 character usernames are needed to support the EmailOrUsername
  60. auth backend.
  61. """
  62. username = forms.EmailField(label=_('Email Address'))
  63. class CommonPasswordValidator(validators.BaseValidator):
  64. # See http://www.smartplanet.com/blog/business-brains/top-20-most-common-passwords-of-all-time-revealed-8216123456-8216princess-8216qwerty/4519
  65. forbidden_passwords = [
  66. 'password',
  67. '1234',
  68. '12345'
  69. '123456',
  70. '123456y',
  71. '123456789',
  72. 'iloveyou',
  73. 'princess',
  74. 'monkey',
  75. 'rockyou',
  76. 'babygirl',
  77. 'monkey',
  78. 'qwerty',
  79. '654321',
  80. 'dragon',
  81. 'pussy',
  82. 'baseball',
  83. 'football',
  84. 'letmein',
  85. 'monkey',
  86. '696969',
  87. 'abc123',
  88. 'qwe123',
  89. 'qweasd',
  90. 'mustang',
  91. 'michael',
  92. 'shadow',
  93. 'master',
  94. 'jennifer',
  95. '111111',
  96. '2000',
  97. 'jordan',
  98. 'superman'
  99. 'harley'
  100. ]
  101. message = _("Please choose a less common password")
  102. code = 'password'
  103. def __init__(self, password_file=None):
  104. self.limit_value = password_file
  105. def clean(self, value):
  106. return value.strip()
  107. def compare(self, value, limit):
  108. return value in self.forbidden_passwords
  109. def get_forbidden_passwords(self):
  110. if self.limit_value is None:
  111. return self.forbidden_passwords
  112. class EmailUserCreationForm(forms.ModelForm):
  113. email = forms.EmailField(label=_('Email Address'))
  114. password1 = forms.CharField(label=_('Password'), widget=forms.PasswordInput,
  115. validators=[validators.MinLengthValidator(6),
  116. CommonPasswordValidator()])
  117. password2 = forms.CharField(label=_('Confirm Password'), widget=forms.PasswordInput)
  118. class Meta:
  119. model = User
  120. fields = ('email',)
  121. def clean_email(self):
  122. email = self.cleaned_data['email'].lower()
  123. try:
  124. User.objects.get(email=email)
  125. except User.DoesNotExist:
  126. return email
  127. raise forms.ValidationError(_("A user with that email address already exists."))
  128. def clean_password2(self):
  129. password1 = self.cleaned_data.get('password1', '')
  130. password2 = self.cleaned_data.get('password2', '')
  131. if password1 != password2:
  132. raise forms.ValidationError(_("The two password fields didn't match."))
  133. return password2
  134. def save(self, commit=True):
  135. user = super(EmailUserCreationForm, self).save(commit=False)
  136. user.set_password(self.cleaned_data['password1'])
  137. user.username = generate_username()
  138. if commit:
  139. user.save()
  140. return user
  141. class SearchByDateRangeForm(forms.Form):
  142. date_from = forms.DateField(required=False, label="From")
  143. date_to = forms.DateField(required=False, label="To")
  144. def clean(self):
  145. if self.is_valid() and not self.cleaned_data['date_from'] and not self.cleaned_data['date_to']:
  146. raise forms.ValidationError(_("At least one date field is required."))
  147. return super(SearchByDateRangeForm, self).clean()
  148. def description(self):
  149. if not self.is_bound or not self.is_valid():
  150. return 'All orders'
  151. date_from = self.cleaned_data['date_from']
  152. date_to = self.cleaned_data['date_to']
  153. if date_from and date_to:
  154. return 'Orders placed between %s and %s' % (date_from, date_to)
  155. elif date_from and not date_to:
  156. return 'Orders placed since %s' % date_from
  157. elif not date_from and date_to:
  158. return 'Orders placed until %s' % date_to
  159. def get_filters(self):
  160. date_from = self.cleaned_data['date_from']
  161. date_to = self.cleaned_data['date_to']
  162. if date_from and date_to:
  163. return {'date_placed__range': [date_from, date_to]}
  164. elif date_from and not date_to:
  165. return {'date_placed__gt': date_from}
  166. elif not date_from and date_to:
  167. return {'date_placed__lt': date_to}
  168. return {}
  169. class CleanEmailMixin(object):
  170. def clean_email(self):
  171. """
  172. Make sure that the email address is aways unique as it is
  173. used instead of the username. This is necessary because the
  174. unique-ness of email addresses is *not* enforced on the model
  175. level in ``django.contrib.auth.models.User``.
  176. """
  177. email = self.cleaned_data['email']
  178. try:
  179. user = User.objects.get(email=email)
  180. except User.DoesNotExist:
  181. # this email address is unique so we don't have to worry
  182. # about it
  183. return email
  184. if self.instance and self.instance.id != user.id:
  185. raise ValidationError(
  186. _("A user with this email address already exists")
  187. )
  188. return email
  189. class UserForm(forms.ModelForm, CleanEmailMixin):
  190. def __init__(self, user, *args, **kwargs):
  191. self.user = user
  192. kwargs['instance'] = user
  193. super(UserForm, self).__init__(*args, **kwargs)
  194. class Meta:
  195. model = User
  196. exclude = ('username', 'password', 'is_staff', 'is_superuser',
  197. 'is_active', 'last_login', 'date_joined',
  198. 'user_permissions', 'groups')
  199. if hasattr(settings, 'AUTH_PROFILE_MODULE'):
  200. Profile = get_profile_class()
  201. class UserAndProfileForm(forms.ModelForm, CleanEmailMixin):
  202. first_name = forms.CharField(label=_('First name'), max_length=128)
  203. last_name = forms.CharField(label=_('Last name'), max_length=128)
  204. email = forms.EmailField(label=_('Email address'))
  205. # Fields from user model
  206. user_fields = ('first_name', 'last_name', 'email')
  207. def __init__(self, user, *args, **kwargs):
  208. self.user = user
  209. try:
  210. instance = user.get_profile()
  211. except ObjectDoesNotExist:
  212. # User has no profile, try a blank one
  213. instance = Profile(user=user)
  214. kwargs['instance'] = instance
  215. super(UserAndProfileForm, self).__init__(*args, **kwargs)
  216. # Add user fields
  217. self.fields['first_name'].initial = self.instance.user.first_name
  218. self.fields['last_name'].initial = self.instance.user.last_name
  219. self.fields['email'].initial = self.instance.user.email
  220. # Ensure user fields are above profile
  221. order = list(self.user_fields)
  222. for field_name in self.fields.keys():
  223. if field_name not in self.user_fields:
  224. order.append(field_name)
  225. self.fields.keyOrder = order
  226. class Meta:
  227. model = Profile
  228. exclude = ('user',)
  229. def save(self, *args, **kwargs):
  230. user = self.instance.user
  231. user.first_name = self.cleaned_data['first_name']
  232. user.last_name = self.cleaned_data['last_name']
  233. user.email = self.cleaned_data['email']
  234. user.save()
  235. return super(ProfileForm, self).save(*args,**kwargs)
  236. ProfileForm = UserAndProfileForm
  237. else:
  238. ProfileForm = UserForm
  239. class ProductAlertForm(forms.ModelForm):
  240. email = forms.EmailField(required=True, label=_(u'Send notification to'),
  241. widget=forms.TextInput(attrs={
  242. 'placeholder': _('Enter your email')
  243. }))
  244. def __init__(self, user, product, *args, **kwargs):
  245. self.user = user
  246. self.product = product
  247. super(ProductAlertForm, self).__init__(*args, **kwargs)
  248. # Only show email field to unauthenticated users
  249. if user and user.is_authenticated():
  250. self.fields['email'].widget = forms.HiddenInput()
  251. self.fields['email'].required = False
  252. def save(self, commit=True):
  253. alert = super(ProductAlertForm, self).save(commit=False)
  254. if self.user.is_authenticated():
  255. alert.user = self.user
  256. alert.product = self.product
  257. if commit:
  258. alert.save()
  259. return alert
  260. def clean(self):
  261. cleaned_data = self.cleaned_data
  262. email = cleaned_data.get('email')
  263. if email:
  264. try:
  265. ProductAlert.objects.get(
  266. product=self.product, email=email,
  267. status=ProductAlert.ACTIVE)
  268. except ProductAlert.DoesNotExist:
  269. pass
  270. else:
  271. raise forms.ValidationError(_(
  272. "There is already an active stock alert for %s") % email)
  273. elif self.user.is_authenticated():
  274. try:
  275. ProductAlert.objects.get(product=self.product,
  276. user=self.user,
  277. status=ProductAlert.ACTIVE)
  278. except ProductAlert.DoesNotExist:
  279. pass
  280. else:
  281. raise forms.ValidationError(_(
  282. "You already have an active alert for this product"))
  283. return cleaned_data
  284. class Meta:
  285. model = ProductAlert
  286. exclude = ('user', 'key',
  287. 'status', 'date_confirmed', 'date_cancelled', 'date_closed',
  288. 'product')