nopaque/web/app/admin/views.py

69 lines
2.4 KiB
Python
Raw Normal View History

from flask import flash, redirect, render_template, url_for
2019-09-23 16:25:26 +02:00
from flask_login import login_required
from . import admin
2019-11-15 14:01:36 +01:00
from .forms import EditUserForm
2019-11-15 12:57:01 +01:00
from .tables import AdminUserItem, AdminUserTable
2020-03-27 12:06:11 +01:00
from .. import db
from ..decorators import admin_required
from ..models import Role, User
from ..profile import tasks as profile_tasks
2020-06-10 15:10:23 +02:00
import html
2019-11-15 12:51:53 +01:00
@admin.route('/')
@login_required
@admin_required
2019-11-15 12:51:53 +01:00
def index():
2019-11-15 11:45:04 +01:00
users = User.query.all()
2019-09-23 16:25:26 +02:00
items = [AdminUserItem(u.username, u.email, u.role_id, u.confirmed, u.id)
for u in users]
# Convert table object to html string
2020-06-10 15:10:23 +02:00
table = html.unescape(AdminUserTable(items).__html__())
2019-09-23 16:25:26 +02:00
# Add class "list" to tbody element. Needed for "List.js"
table = table.replace('tbody', 'tbody class="list"', 1)
2019-11-15 12:51:53 +01:00
return render_template('admin/index.html.j2', table=table,
title='Administration tools')
2019-11-15 11:45:04 +01:00
@admin.route('/user/<int:user_id>')
@login_required
@admin_required
2019-11-15 11:45:04 +01:00
def user(user_id):
user = User.query.get_or_404(user_id)
2019-11-15 12:51:53 +01:00
return render_template('admin/user.html.j2', title='Administration: User',
2019-11-15 11:45:04 +01:00
user=user)
2019-11-15 11:45:04 +01:00
@admin.route('/user/<int:user_id>/delete')
@login_required
@admin_required
2019-11-15 11:45:04 +01:00
def delete_user(user_id):
user = User.query.get_or_404(user_id)
profile_tasks.delete_user(user_id)
2019-11-15 11:45:04 +01:00
flash('User has been deleted!')
2019-11-15 12:51:53 +01:00
return redirect(url_for('admin.index'))
2019-11-15 11:45:04 +01:00
@admin.route('/user/<int:user_id>/edit', methods=['GET', 'POST'])
@login_required
@admin_required
2019-11-15 11:45:04 +01:00
def edit_user(user_id):
user = User.query.get_or_404(user_id)
2019-11-15 14:01:36 +01:00
edit_user_form = EditUserForm(user=user)
if edit_user_form.validate_on_submit():
user.email = edit_user_form.email.data
user.username = edit_user_form.username.data
user.confirmed = edit_user_form.confirmed.data
user.role = Role.query.get(edit_user_form.role.data)
db.session.add(user)
db.session.commit()
flash('The profile has been updated.')
2019-11-15 11:45:04 +01:00
return redirect(url_for('admin.edit_user', user_id=user.id))
2020-02-18 15:22:48 +01:00
edit_user_form.email.data = user.email
edit_user_form.username.data = user.username
edit_user_form.confirmed.data = user.confirmed
edit_user_form.role.data = user.role_id
2019-11-15 14:01:36 +01:00
return render_template('admin/edit_user.html.j2',
edit_user_form=edit_user_form,
2019-11-15 12:51:53 +01:00
title='Administration: Edit user', user=user)