fix csrf in contact forms
[wolnelektury.git] / src / contact / views.py
1 # -*- coding: utf-8 -*-
2 from urllib import unquote
3
4 from django.contrib.auth.decorators import permission_required
5 from django.http import Http404
6 from django.shortcuts import get_object_or_404, redirect, render
7 from fnpdjango.utils.views import serve_file
8 from honeypot.decorators import check_honeypot
9
10 from .forms import contact_forms
11 from .models import Attachment, Contact
12
13
14 @check_honeypot
15 def form(request, form_tag, force_enabled=False):
16     try:
17         form_class = contact_forms[form_tag]
18     except KeyError:
19         raise Http404
20     if (getattr(form_class, 'disabled', False) and
21             not (force_enabled and request.user.is_superuser)):
22         template = getattr(form_class, 'disabled_template', None)
23         if template:
24             return render(request, template, {'title': form_class.form_title})
25         raise Http404
26     if request.method == 'POST':
27         form = form_class(request.POST, request.FILES)
28     else:
29         form = form_class(initial=request.GET)
30     formset_classes = getattr(form, 'form_formsets', {})
31     if request.method == 'POST':
32         formsets = {
33             prefix: formset_class(request.POST, request.FILES, prefix=prefix)
34             for prefix, formset_class in formset_classes.iteritems()}
35         if form.is_valid() and all(formset.is_valid() for formset in formsets.itervalues()):
36             contact = form.save(request, formsets.values())
37             if form.result_page:
38                 return redirect('contact_results', contact.id, contact.digest())
39             else:
40                 return redirect('contact_thanks', form_tag)
41     else:
42         formsets = {prefix: formset_class(prefix=prefix) for prefix, formset_class in formset_classes.iteritems()}
43
44     return render(
45         request, ['contact/%s/form.html' % form_tag, 'contact/form.html'],
46         {'form': form, 'formsets': formsets}
47     )
48
49
50 def thanks(request, form_tag):
51     try:
52         form_class = contact_forms[form_tag]
53     except KeyError:
54         raise Http404
55
56     return render(
57         request, ['contact/%s/thanks.html' % form_tag, 'contact/thanks.html'],
58         {'base_template': getattr(form_class, 'base_template', None)})
59
60
61 def results(request, contact_id, digest):
62     contact = get_object_or_404(Contact, id=contact_id)
63     if digest != contact.digest():
64         raise Http404
65     try:
66         form_class = contact_forms[contact.form_tag]
67     except KeyError:
68         raise Http404
69
70     return render(
71         request, 'contact/%s/results.html' % contact.form_tag,
72         {
73             'results': form_class.results(contact),
74             'base_template': getattr(form_class, 'base_template', None),
75         }
76     )
77
78
79 @permission_required('contact.change_attachment')
80 def attachment(request, contact_id, tag):
81     attachment = get_object_or_404(Attachment, contact_id=contact_id, tag=tag)
82     attachment_url = unquote(attachment.file.url)
83     return serve_file(attachment_url)