From 009671090f996dc18ec1b7407b70e3648582b4c0 Mon Sep 17 00:00:00 2001 From: Matt Wright Date: Thu, 16 Aug 2012 18:20:42 -0400 Subject: [PATCH] Clean up and bug improvements --- flask_security/confirmable.py | 4 +-- flask_security/core.py | 2 +- flask_security/decorators.py | 2 +- flask_security/recoverable.py | 2 +- flask_security/views.py | 49 +++++++++++++++++++++-------------- 5 files changed, 35 insertions(+), 24 deletions(-) diff --git a/flask_security/confirmable.py b/flask_security/confirmable.py index c2c1d29..85b2e5d 100644 --- a/flask_security/confirmable.py +++ b/flask_security/confirmable.py @@ -73,7 +73,7 @@ def confirm_by_token(token): user = _datastore.find_user(id=data[0]) if user.confirmed_at: - raise ConfirmationError(get_message('ALREADY_CONFIRMED')) + raise ConfirmationError(get_message('ALREADY_CONFIRMED')[0]) user.confirmed_at = datetime.utcnow() _datastore._save_model(user) @@ -91,7 +91,7 @@ def confirm_by_token(token): raise ConfirmationError(msg, user=user) except BadSignature: - raise ConfirmationError(get_message('INVALID_CONFIRMATION_TOKEN')) + raise ConfirmationError(get_message('INVALID_CONFIRMATION_TOKEN')[0]) def reset_confirmation_token(user): diff --git a/flask_security/core.py b/flask_security/core.py index 64cdc0c..735b0dd 100644 --- a/flask_security/core.py +++ b/flask_security/core.py @@ -342,7 +342,7 @@ class AuthenticationProvider(object): raise exceptions.BadCredentialsError('Specified user does not exist.') if requires_confirmation(user): - raise exceptions.BadCredentialsError('Email requires confirmation.') + raise exceptions.ConfirmationError('Email requires confirmation.') # compare passwords if verify_password(password, user.password, diff --git a/flask_security/decorators.py b/flask_security/decorators.py index 5b766ca..9b3d7e3 100644 --- a/flask_security/decorators.py +++ b/flask_security/decorators.py @@ -43,7 +43,7 @@ def _get_unauthorized_response(text=None, headers=None): def _get_unauthorized_view(): cv = utils.get_url(utils.config_value('UNAUTHORIZED_VIEW')) - utils.do_flash(utils.get_message('UNAUTHORIZED')) + utils.do_flash(*utils.get_message('UNAUTHORIZED')) return redirect(cv or request.referrer or '/') diff --git a/flask_security/recoverable.py b/flask_security/recoverable.py index 25e6d63..15e34b6 100644 --- a/flask_security/recoverable.py +++ b/flask_security/recoverable.py @@ -98,7 +98,7 @@ def reset_by_token(token, password): user=_datastore.find_user(id=data[0])) except BadSignature: - raise ResetPasswordError(get_message('INVALID_RESET_PASSWORD_TOKEN')) + raise ResetPasswordError(get_message('INVALID_RESET_PASSWORD_TOKEN')[0]) def reset_password_reset_token(user): diff --git a/flask_security/views.py b/flask_security/views.py index 555a15a..f55f3b0 100644 --- a/flask_security/views.py +++ b/flask_security/views.py @@ -67,6 +67,7 @@ def _json_auth_error(msg): def authenticate(): """View function which handles an authentication request.""" + confirm_url = None form_data = MultiDict(request.json) if request.json else request.form form = LoginForm(form_data) @@ -81,6 +82,10 @@ def authenticate(): raise BadCredentialsError(get_message('DISABLED_ACCOUNT')[0]) + except ConfirmationError, e: + msg = str(e) + confirm_url = url_for_security('send_confirmation') + except BadCredentialsError, e: msg = str(e) @@ -91,11 +96,15 @@ def authenticate(): do_flash(msg, 'error') - return redirect(request.referrer or url_for_security('login')) + return redirect(request.referrer or + confirm_url or + url_for_security('login')) @anonymous_user_required def login(): + """View function for login view""" + form = PasswordlessLoginForm() if _security.passwordless else LoginForm() template = 'send_login' if _security.passwordless else 'login' return render_template('security/%s.html' % template, login_form=form) @@ -144,6 +153,7 @@ def register(): @anonymous_user_required def send_login(): + """View function that sends login instructions for passwordless login""" form = PasswordlessLoginForm() user = _datastore.find_user(**form.to_dict()) @@ -159,16 +169,16 @@ def send_login(): @anonymous_user_required def token_login(token): + """View function that handles passwordless login via a token""" + try: user, next = login_by_token(token) except PasswordlessLoginError, e: - msg, cat = str(e), 'error' - if e.user: send_login_instructions(e.user, e.next) - do_flash(msg, cat) + do_flash(str(e), 'error') return redirect(request.referrer or url_for_security('login')) @@ -179,6 +189,8 @@ def token_login(token): @anonymous_user_required def send_confirmation(): + """View function which sends confirmation instructions.""" + form = ResendConfirmationForm(csrf_enabled=not app.testing) if form.validate_on_submit(): @@ -188,9 +200,7 @@ def send_confirmation(): _logger.debug('%s request confirmation instructions' % user) - msg, cat = get_message('CONFIRMATION_REQUEST', email=user.email) - - do_flash(msg, cat) + do_flash(*get_message('CONFIRMATION_REQUEST', email=user.email)) return render_template('security/send_confirmation.html', reset_confirmation_form=form) @@ -198,19 +208,20 @@ def send_confirmation(): def confirm_email(token): """View function which handles a email confirmation request.""" + try: user = confirm_by_token(token) _logger.debug('%s confirmed their email' % user) except ConfirmationError, e: - msg, cat = str(e), 'error' + msg = (str(e), 'error') - _logger.debug('Confirmation error: ' + msg) + _logger.debug('Confirmation error: ' + msg[0]) if e.user: reset_confirmation_token(e.user) - do_flash(msg, cat) + do_flash(*msg) return redirect(get_url(_security.confirm_error_view) or url_for_security('send_confirmation')) @@ -236,9 +247,7 @@ def forgot_password(): _logger.debug('%s requested to reset their password' % user) - msg, cat = get_message('PASSWORD_RESET_REQUEST', email=user.email) - - do_flash(msg, cat) + do_flash(*get_message('PASSWORD_RESET_REQUEST', email=user.email)) return redirect(get_url(_security.post_forgot_view)) @@ -270,18 +279,18 @@ def reset_password(token): get_url(_security.post_login_view)) except ResetPasswordError, e: - msg, cat = str(e), 'error' + msg = (str(e), 'error') - _logger.debug('Password reset error: ' + msg) + _logger.debug('Password reset error: ' + msg[0]) if e.user: reset_password_reset_token(e.user) - msg, cat = get_message('PASSWORD_RESET_EXPIRED', - within=_security.reset_password_within, - email=e.user.email) + msg = get_message('PASSWORD_RESET_EXPIRED', + within=_security.reset_password_within, + email=e.user.email) - do_flash(msg, cat) + do_flash(*msg) return render_template('security/reset_password.html', reset_password_form=form, @@ -289,6 +298,8 @@ def reset_password(token): def create_blueprint(app, name, import_name, **kwargs): + """Creates the security extension blueprint""" + bp = Blueprint(name, import_name, **kwargs) if config_value('PASSWORDLESS', app=app):