UserManger.py 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505
  1. import os
  2. import traceback
  3. import boto3
  4. import botocore
  5. from botocore import client
  6. import simplejson as json
  7. from django.http import HttpResponse
  8. from django.utils.decorators import method_decorator
  9. from django.views.decorators.csrf import csrf_exempt
  10. from django.views.generic import TemplateView, View
  11. from Ansjer.cn_config.config_test import REGION_NAME2
  12. from Ansjer.config import BASE_DIR, ACCESS_KEY_ID, SECRET_ACCESS_KEY, REGION_NAME, AVATAR_BUCKET, CONFIG_INFO, \
  13. CONFIG_CN, CONFIG_TEST, LOGGER
  14. from Ansjer.config import SERVER_DOMAIN
  15. from Model.models import Role, Device_User, UserOauth2Model, UserExModel, CountryLanguageModel, LanguageModel, App_Info, \
  16. IcloudUseDetails, CountryModel
  17. from Object.ContentSecurityObject import ContentSecurity
  18. from Object.RedisObject import RedisObject
  19. from Object.ResponseObject import ResponseObject
  20. from Object.TokenObject import TokenObject
  21. from Service.CommonService import CommonService
  22. from Service.ModelService import ModelService
  23. class showUserMoreView(TemplateView):
  24. @method_decorator(csrf_exempt)
  25. def dispatch(self, *args, **kwargs):
  26. return super(showUserMoreView, self).dispatch(*args, **kwargs)
  27. def post(self, request, *args, **kwargs):
  28. request.encoding = 'utf-8'
  29. return self.validation(request.POST)
  30. def get(self, request, *args, **kwargs):
  31. request.encoding = 'gb2312'
  32. return self.validation(request.GET)
  33. def validation(self, request_dict):
  34. response = ResponseObject()
  35. token = request_dict.get('token', None)
  36. lang = request_dict.get('lang', 'en')
  37. app_bundle_id = request_dict.get('app_bundle_id', None)
  38. tko = TokenObject(token)
  39. response.lang = tko.lang
  40. if tko.code != 0:
  41. return response.json(tko.code)
  42. user_id = tko.userID
  43. if not user_id:
  44. return response.json(104)
  45. return self.show_user_more(user_id, lang, app_bundle_id, response)
  46. @staticmethod
  47. def show_user_more(user_id, lang, app_bundle_id, response):
  48. """
  49. 获取用户完整信息
  50. @param user_id: 用户id
  51. @param lang: 语言
  52. @param app_bundle_id: app包id
  53. @param response: 响应
  54. @return: response
  55. """
  56. device_user_qs = Device_User.objects.filter(userID=user_id)
  57. if not device_user_qs.exists():
  58. return response.json(104)
  59. try:
  60. sqlDict = CommonService.qs_to_dict(device_user_qs)
  61. for k, v in enumerate(sqlDict["datas"]):
  62. sqlDict['datas'][k]['fields'].pop('password')
  63. userIconPath = sqlDict['datas'][k]['fields']['userIconPath']
  64. region_status = sqlDict['datas'][k]['fields']['region_status']
  65. if userIconPath:
  66. if userIconPath.find('static/') != -1:
  67. userIconPath = userIconPath.replace('static/', '').replace('\\', '/')
  68. userIconUrl = SERVER_DOMAIN + 'account/getAvatar/' + userIconPath
  69. sqlDict['datas'][k]['fields']['userIconUrl'] = userIconUrl
  70. # 判断用户是否开通云盘
  71. icloud_user_qs = IcloudUseDetails.objects.filter(user_id=user_id)
  72. v['fields']['is_cloudDrive'] = 1 if icloud_user_qs.exists() else 0
  73. # 确认地区字段
  74. sqlDict['datas'][k]['fields']['region_status'] = 1 if region_status else 0
  75. if len(v['fields']['role']):
  76. roleName = ModelService.getRole(rid=v['fields']['role'][0])
  77. sqlDict["datas"][k]['fields']['rolename'] = roleName
  78. # 根据region_country的值返回api和region数据
  79. sqlDict["datas"][k]['fields']['api'] = ''
  80. sqlDict['datas'][k]['fields']['region'] = ''
  81. region_country = sqlDict["datas"][k]['fields']['region_country']
  82. if region_country != 0:
  83. # api数据
  84. country_qs = CountryLanguageModel.objects.filter(country_id=region_country).values(
  85. 'country__region__api', 'country__region__zosi_api', 'country__region__loocam_api')
  86. sqlDict["datas"][k]['fields']['api'] = country_qs[0]['country__region__api']
  87. if region_country == 1: # 中国返回美洲域名
  88. sqlDict["datas"][k]['fields']['api'] = 'https://www.dvema.com/'
  89. # 根据app_bundle_id返回对应域名
  90. if app_bundle_id:
  91. # 查询app名
  92. app_inf_qs = App_Info.objects.filter(appBundleId=app_bundle_id).values('appName')
  93. if app_inf_qs.exists():
  94. app_name = app_inf_qs[0]['appName']
  95. if 'Zosi' in app_name:
  96. sqlDict['datas'][k]['fields']['api'] = country_qs[0]['country__region__zosi_api']
  97. if region_country == 1:
  98. sqlDict['datas'][k]['fields']['api'] = 'https://api.zositech2.com/'
  99. elif 'Loocam' in app_name:
  100. sqlDict['datas'][k]['fields']['api'] = country_qs[0]['country__region__loocam_api']
  101. if region_country == 1:
  102. sqlDict['datas'][k]['fields']['api'] = 'https://api.loocam2.com/'
  103. # region数据
  104. region_country = sqlDict['datas'][k]['fields']['region_country']
  105. language_qs = LanguageModel.objects.filter(lang=lang).values('id')
  106. region_qs = CountryLanguageModel.objects.filter(country_id=region_country,
  107. language_id=language_qs[0]['id']). \
  108. values('country_name')
  109. sqlDict['datas'][k]['fields']['region'] = region_qs[0]['country_name'] if region_qs.exists() else ''
  110. # 夏令时标识
  111. country_qs = CountryModel.objects.filter(id=region_country).values('DST')
  112. sqlDict['datas'][k]['fields']['DST_AREA'] = country_qs[0]['DST'] if country_qs.exists() else 0
  113. # 增加oauth2关联数据
  114. ua_qs = UserOauth2Model.objects.filter(userID_id=user_id).values_list('authType', flat=True)
  115. sqlDict['oauth2'] = list(ua_qs)
  116. return response.json(0, sqlDict)
  117. except Exception as e:
  118. return response.json(500, 'error_line:{}, error_msg:{}'.format(e.__traceback__.tb_lineno, repr(e)))
  119. class perfectUserInfoView(TemplateView):
  120. # 完善个人信息
  121. @method_decorator(csrf_exempt)
  122. def dispatch(self, *args, **kwargs):
  123. return super(perfectUserInfoView, self).dispatch(*args, **kwargs)
  124. def post(self, request, *args, **kwargs):
  125. request.encoding = 'utf-8'
  126. userContent = request.POST.get('content', None)
  127. userIcon = request.FILES.get('userIcon', None)
  128. token = request.POST.get('token', None)
  129. return self.ValidationError(token, userContent, userIcon)
  130. def get(self, request, *args, **kwargs):
  131. request.encoding = 'gb2312'
  132. userContent = request.GET.get('content', None)
  133. userIcon = request.FILES.get('userIcon', None)
  134. token = request.GET.get('token', None)
  135. return self.ValidationError(token, userContent, userIcon)
  136. def ValidationError(self, token, userContent, userIcon):
  137. response = ResponseObject()
  138. tko = TokenObject(token)
  139. response.lang = tko.lang
  140. if tko.code != 0:
  141. return response.json(tko.code)
  142. userID = tko.userID
  143. if not userID:
  144. return response.json(309)
  145. userIconPath = ''
  146. if userIcon:
  147. # 上传头像到aws s3
  148. aws_s3_client = boto3.client(
  149. 's3',
  150. region_name=REGION_NAME,
  151. aws_access_key_id=ACCESS_KEY_ID,
  152. aws_secret_access_key=SECRET_ACCESS_KEY,
  153. config=botocore.client.Config(signature_version='s3v4'),
  154. )
  155. Key = userID + '/' + userIcon.name
  156. aws_s3_client.put_object(Bucket=AVATAR_BUCKET, Key=Key, Body=userIcon)
  157. userIconPath = userID + '/' + userIcon.name
  158. # 测试/国内服,验证头像是否合规
  159. if CONFIG_INFO == CONFIG_CN or CONFIG_INFO == CONFIG_TEST:
  160. # 测试服头像地区为us-west-1
  161. if CONFIG_INFO == CONFIG_TEST:
  162. aws_s3_client = boto3.client(
  163. 's3',
  164. region_name=REGION_NAME2,
  165. aws_access_key_id=ACCESS_KEY_ID,
  166. aws_secret_access_key=SECRET_ACCESS_KEY,
  167. config=botocore.client.Config(signature_version='s3v4'),
  168. )
  169. params = {'Bucket': AVATAR_BUCKET, 'Key': Key}
  170. image_url = aws_s3_client.generate_presigned_url('get_object', Params=params)
  171. service = 'profilePhotoCheck'
  172. LOGGER.info('头像链接:{}'.format(image_url))
  173. service_dict = {'imageUrl': image_url}
  174. service_parameters = json.dumps(service_dict)
  175. legal = ContentSecurity().image_review(service, service_parameters)
  176. if not legal:
  177. return response.json(106)
  178. if userContent:
  179. dataValid = json.loads(userContent)
  180. if 'userID' and 'password' and 'is_superuser' in dataValid.keys():
  181. return response.json(444)
  182. if not userIconPath and not userContent:
  183. return response.json(444)
  184. elif not userIconPath and userContent:
  185. return self.perfectUserInfoUpdate(userID, response, userContent=userContent)
  186. elif userIconPath and not userContent:
  187. return self.perfectUserInfoUpdate(userID, response, userIconPath=userIconPath)
  188. else:
  189. return self.perfectUserInfoUpdate(userID, response, userIconPath=userIconPath, userContent=userContent)
  190. def perfectUserInfoUpdate(slef, userID, response, **kwargs):
  191. """
  192. :param username:
  193. :param userContent:
  194. :param args:
  195. :param kwargs:
  196. :return:
  197. """
  198. User = Device_User.objects.filter(userID=userID)
  199. if not User.exists():
  200. return response.json(104)
  201. userIconPath = kwargs.get('userIconPath', None)
  202. userContent = kwargs.get('userContent', None)
  203. userIconUrl = ""
  204. if userIconPath:
  205. userIconUrl = SERVER_DOMAIN + 'account/getAvatar/' + userIconPath
  206. if userContent:
  207. try:
  208. UserData = json.loads(userContent)
  209. except Exception as e:
  210. return response.json(444, repr(e))
  211. # 测试/国内服,验证昵称是否合规
  212. if CONFIG_INFO == CONFIG_CN or CONFIG_INFO == CONFIG_TEST:
  213. nickname = UserData.get('NickName')
  214. if nickname:
  215. service = 'nickname_detection'
  216. service_dict = {'content': nickname}
  217. service_parameters = json.dumps(service_dict)
  218. legal = ContentSecurity().text_review(service, service_parameters)
  219. if not legal:
  220. return response.json(108)
  221. try:
  222. if userIconPath and userContent:
  223. User.update(userIconPath=userIconPath, userIconUrl=userIconUrl, **UserData)
  224. elif not userIconPath and userContent:
  225. User.update(**UserData)
  226. elif userIconPath and not userContent:
  227. User.update(userIconPath=userIconPath, userIconUrl=userIconUrl)
  228. except Exception as e:
  229. return response.json(117, repr(e))
  230. else:
  231. res = CommonService.qs_to_dict(User)
  232. for k, v in enumerate(res["datas"]):
  233. res['datas'][k]['fields'].pop('password')
  234. userIconPath = res['datas'][k]['fields']['userIconPath']
  235. region_status = res['datas'][k]['fields']['region_status']
  236. if region_status is True:
  237. res['datas'][k]['fields']['region_status'] = 1
  238. else:
  239. res['datas'][k]['fields']['region_status'] = 0
  240. if userIconPath and userIconUrl != '':
  241. res['datas'][k]['fields']['userIconUrl'] = userIconUrl
  242. return response.json(0, res)
  243. class getAvatarView(TemplateView):
  244. @method_decorator(csrf_exempt)
  245. def dispatch(self, *args, **kwargs):
  246. return super(getAvatarView, self).dispatch(*args, **kwargs)
  247. def post(self, request, *args, **kwargs):
  248. request.encoding = 'utf-8'
  249. filePath = kwargs.get('filePath', '')
  250. filePath.encode(encoding='utf-8', errors='strict')
  251. return self.getAvatar(filePath)
  252. def get(self, request, *args, **kwargs):
  253. request.encoding = 'utf-8'
  254. filePath = kwargs.get('filePath', '')
  255. filePath.encode(encoding='utf-8', errors='strict')
  256. return self.getAvatar(filePath)
  257. def getAvatar(self, filePath):
  258. response = ResponseObject()
  259. if not filePath:
  260. return response.json(800)
  261. if filePath == 'User/default.png' or filePath == 'User/defaultUser.png':
  262. # 使用默认头像
  263. try:
  264. aws_s3_client = boto3.client(
  265. 's3',
  266. region_name=REGION_NAME,
  267. aws_access_key_id=ACCESS_KEY_ID,
  268. aws_secret_access_key=SECRET_ACCESS_KEY,
  269. config=botocore.client.Config(signature_version='s3v4'),
  270. )
  271. get_object_response = aws_s3_client.get_object(Bucket=AVATAR_BUCKET, Key='default/default.png')
  272. return HttpResponse(get_object_response['Body'], content_type="image/jpeg")
  273. except Exception as e:
  274. print(e)
  275. return response.json(500, 'error_line:{}, error_msg:{}'.format(e.__traceback__.tb_lineno, repr(e)))
  276. fullPath = os.path.join(BASE_DIR, "static", filePath).replace('\\', '/')
  277. if os.path.isfile(fullPath):
  278. try:
  279. imageData = open(fullPath, 'rb').read()
  280. return HttpResponse(imageData, content_type="image/jpeg")
  281. except Exception as e:
  282. return response.json(906, repr(e))
  283. else:
  284. try:
  285. aws_s3_client = boto3.client(
  286. 's3',
  287. region_name=REGION_NAME,
  288. aws_access_key_id=ACCESS_KEY_ID,
  289. aws_secret_access_key=SECRET_ACCESS_KEY,
  290. config=botocore.client.Config(signature_version='s3v4'),
  291. )
  292. get_object_response = aws_s3_client.get_object(Bucket=AVATAR_BUCKET, Key=filePath)
  293. return HttpResponse(get_object_response['Body'], content_type="image/jpeg")
  294. except Exception as e:
  295. return response.json(906, repr(e))
  296. @csrf_exempt
  297. def delUserInterface(request):
  298. response = ResponseObject()
  299. if request.method == 'POST':
  300. request_dict = request.POST
  301. elif request.method == 'GET':
  302. request_dict = request.GET
  303. else:
  304. return response.json(404)
  305. token = request_dict.get('token', None)
  306. delUserID = request_dict.get('delUserID', None)
  307. if not token or not delUserID:
  308. return response.json(444, 'token,delUserID')
  309. tko = TokenObject(token)
  310. response.lang = tko.lang
  311. if tko.code != 0:
  312. return response.json(tko.code)
  313. userID = tko.userID
  314. if not userID:
  315. return response.json(309)
  316. userValid = Device_User.objects.filter(userID=userID)
  317. if not userValid.exists():
  318. return response.json(104)
  319. own_perm = ModelService.check_perm(userID=userID, permID=10)
  320. if own_perm is not True:
  321. return response.json(404)
  322. delUser = Device_User.objects.filter(userID=delUserID)
  323. if not delUser.exists():
  324. return response.json(104)
  325. delUser.delete()
  326. return response.json(0)
  327. @csrf_exempt
  328. def showAllUserInterface(request):
  329. response = ResponseObject()
  330. if request.method == 'POST':
  331. request_dict = request.POST
  332. elif request.method == 'GET':
  333. request_dict = request.GET
  334. else:
  335. return response.json(404)
  336. token = request_dict.get('token', None)
  337. type = request_dict.get('type', None)
  338. tko = TokenObject(token)
  339. response.lang = tko.lang
  340. if tko.code != 0:
  341. return response.json(tko.code)
  342. userID = tko.userID
  343. if not userID:
  344. return response.json(104)
  345. if type == 'PC':
  346. line = int(request.POST.get('line', None))
  347. page = int(request.POST.get('page', None))
  348. userValid = Device_User.objects.filter(userID=userID).order_by('-data_joined')
  349. if not userValid:
  350. return response.json(104)
  351. # 管理员查询
  352. own_permission = ModelService.check_perm(userID=userID, permID=30)
  353. if own_permission is not True:
  354. return response.json(404)
  355. device_user_queryset = Device_User.objects.all()
  356. device_user_count = device_user_queryset.count()
  357. device_user_res = device_user_queryset.order_by('-data_joined')[(page - 1) * line:page * line]
  358. sqlDict = CommonService.qs_to_dict(device_user_res)
  359. redisObj = RedisObject(db=3)
  360. for k, v in enumerate(sqlDict["datas"]):
  361. if len(v['fields']['role']) > 0:
  362. role_query_set = Role.objects.get(rid=v['fields']['role'][0])
  363. sqlDict["datas"][k]['fields']['role'].append(role_query_set.roleName)
  364. if redisObj.get_data(key=v['pk']):
  365. sqlDict["datas"][k]['fields']['online'] = True
  366. else:
  367. sqlDict["datas"][k]['fields']['online'] = False
  368. ue = UserExModel.objects.filter(userID=sqlDict["datas"][k]['pk'])
  369. if ue.exists():
  370. sqlDict["datas"][k]['fields']['appBundleId'] = ue[0].appBundleId
  371. else:
  372. sqlDict["datas"][k]['fields']['appBundleId'] = ''
  373. sqlDict['count'] = device_user_count
  374. return response.json(0, sqlDict)
  375. else:
  376. own_permission = ModelService.check_perm(userID=userID, permID=30)
  377. if own_permission is not True:
  378. return response.json(404)
  379. qs = Device_User.objects.all().order_by('-data_joined')
  380. res = CommonService.qs_to_dict(qs)
  381. return response.json(0, res)
  382. class setUserValidView(View):
  383. @method_decorator(csrf_exempt)
  384. def dispatch(self, *args, **kwargs):
  385. return super(setUserValidView, self).dispatch(*args, **kwargs)
  386. def post(self, request, *args, **kwargs):
  387. request.encoding = 'utf-8'
  388. request_dict = request.POST
  389. return self.setUserValid(request_dict)
  390. def get(self, request, *args, **kwargs):
  391. request.encoding = 'utf-8'
  392. request_dict = request.GET
  393. return self.setUserValid(request_dict)
  394. def setUserValid(self, request_dict):
  395. token = request_dict.get('token', None)
  396. eUserID = request_dict.get('userID', None)
  397. isValid = request_dict.get('isValid', None)
  398. rid = request_dict.get('rid', None)
  399. response = ResponseObject()
  400. tko = TokenObject(token)
  401. response.lang = tko.lang
  402. if tko.code != 0:
  403. return response.json(tko.code)
  404. superID = tko.userID
  405. own_perm = ModelService.check_perm(userID=superID, permID=50)
  406. if own_perm is True or superID != None and superID != eUserID:
  407. if rid == None:
  408. return self.UserValidUpdate(superID, eUserID, isValid, response)
  409. else:
  410. return self.UserValidUpdatePC(superID, eUserID, isValid, rid, response)
  411. else:
  412. return response.json(444, 'superID or userID')
  413. def UserValidUpdatePC(self, superID, eUserID, isValid, rid, response):
  414. super = Device_User.objects.filter(userID=superID)
  415. eUser = Device_User.objects.filter(userID=eUserID)
  416. if not super.exists() or not eUser.exists():
  417. return response.json(104)
  418. own_permission = ModelService.check_perm(userID=superID, permID=50)
  419. if own_permission is True:
  420. try:
  421. eUser.update(user_isValid=isValid)
  422. device_user_query_set = Device_User.objects.get(userID=eUserID)
  423. if device_user_query_set.role.all():
  424. device_user_query_set.role.set([rid])
  425. else:
  426. role_user_query_set = Role.objects.get(rid=rid)
  427. device_user_query_set.role.add(role_user_query_set)
  428. except Exception as e:
  429. errorInfo = traceback.format_exc()
  430. print('更新数据库错误:%s' % errorInfo)
  431. return response.json(177, repr(e))
  432. else:
  433. return response.json(0)
  434. else:
  435. return response.json(404)
  436. def UserValidUpdate(self, superID, eUserID, isValid, response):
  437. super = Device_User.objects.filter(userID=superID)
  438. eUser = Device_User.objects.filter(userID=eUserID)
  439. if not super.exists():
  440. return response.json(104)
  441. if not eUser.exists():
  442. return response.json(104)
  443. if super[0].is_superuser != 100 or super[0].is_superuser == eUser[0].is_superuser:
  444. return response.json(404)
  445. try:
  446. eUser.update(user_isValid=isValid)
  447. except Exception as e:
  448. errorInfo = traceback.format_exc()
  449. print('更新数据库错误: %s' % errorInfo)
  450. return response.json(177, repr(e))
  451. return response.json(0)
  452. @csrf_exempt
  453. def success(request):
  454. return HttpResponse(status=200)