from flask import flash, redirect, render_template, url_for from flask_login import login_required from . import admin from .forms import EditUserForm from .tables import AdminUserItem, AdminUserTable from .. import db from ..decorators import admin_required from ..models import Role, User from ..profile import tasks as profile_tasks import html @admin.route('/') @login_required @admin_required def index(): users = User.query.all() items = [AdminUserItem(u.username, u.email, u.role_id, u.confirmed, u.id) for u in users] # Convert table object to html string table = html.unescape(AdminUserTable(items).__html__()) # Add class "list" to tbody element. Needed for "List.js" table = table.replace('tbody', 'tbody class="list"', 1) return render_template('admin/index.html.j2', table=table, title='Administration tools') @admin.route('/user/') @login_required @admin_required def user(user_id): user = User.query.get_or_404(user_id) return render_template('admin/user.html.j2', title='Administration: User', user=user) @admin.route('/user//delete') @login_required @admin_required def delete_user(user_id): user = User.query.get_or_404(user_id) profile_tasks.delete_user(user_id) flash('User has been deleted!') return redirect(url_for('admin.index')) @admin.route('/user//edit', methods=['GET', 'POST']) @login_required @admin_required def edit_user(user_id): user = User.query.get_or_404(user_id) edit_user_form = EditUserForm(user=user) if edit_user_form.validate_on_submit(): user.email = edit_user_form.email.data user.username = edit_user_form.username.data user.confirmed = edit_user_form.confirmed.data user.role = Role.query.get(edit_user_form.role.data) db.session.add(user) db.session.commit() flash('The profile has been updated.') return redirect(url_for('admin.edit_user', user_id=user.id)) edit_user_form.email.data = user.email edit_user_form.username.data = user.username edit_user_form.confirmed.data = user.confirmed edit_user_form.role.data = user.role_id return render_template('admin/edit_user.html.j2', edit_user_form=edit_user_form, title='Administration: Edit user', user=user)