Show some speaker details if person is not logged in or is not the speaker
[cascardo/ema.git] / eventos / views.py
1 # -*- coding: utf-8 -*-
2 # Copyright (C) 2008 Lincoln de Sousa <lincoln@minaslivre.org>
3 #
4 # This program is free software; you can redistribute it and/or
5 # modify it under the terms of the GNU General Public License as
6 # published by the Free Software Foundation; either version 2 of the
7 # License, or (at your option) any later version.
8 #
9 # This program is distributed in the hope that it will be useful,
10 # but WITHOUT ANY WARRANTY; without even the implied warranty of
11 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
12 # General Public License for more details.
13 #
14 # You should have received a copy of the GNU General Public
15 # License along with this program; if not, write to the
16 # Free Software Foundation, Inc., 59 Temple Place - Suite 330,
17 # Boston, MA 02111-1307, USA.
18 from django.conf import settings
19 from django.http import HttpResponseRedirect, HttpResponseForbidden
20 from django.contrib.auth import authenticate, login as login_django, \
21     logout as logout_django
22 from django.contrib.auth.models import User, Group
23 from django.forms import HiddenInput, ModelForm
24 from django.shortcuts import render_to_response, get_object_or_404
25 from django.template import RequestContext, Context, loader
26 from eventos.models import Palestrante, Trabalho, TipoTrabalho, Trilha, Evento, Improve
27 from eventos.forms import RegisterSpeaker
28 from django.db.models import Q
29
30 forbidden = \
31     HttpResponseForbidden('<h2>You are not allowed to do this action.<h2>')
32
33 class SpeakerForm(ModelForm):
34     class Meta:
35         model = Palestrante
36         exclude = ('usuario',)
37
38 class TalkForm(ModelForm):
39     class Meta:
40         model = Trabalho
41
42 class ImproveForm(ModelForm):
43     class Meta:
44         model = Improve
45
46 def login(request):
47     """This is a function that will be used as a front-end to the
48     django's login system. It receives username and password fields
49     from a POST request and tries to login the user.
50
51     If login is successful, user will be redirected to the referer
52     address, otherwise will be redirected to /?login_failed.
53     """
54     username = request.POST['username']
55     password = request.POST['password']
56     user = authenticate(username=username, password=password)
57
58     if user is not None:
59         if user.is_active:
60             login_django(request, user)
61             try:
62                 request.session.delete_test_cookie()
63             except KeyError:
64                 pass
65             return HttpResponseRedirect('/')
66         else:
67             return HttpResponseRedirect('/?login_failed')
68     else:
69         return HttpResponseRedirect('/?login_failed')
70
71     request.session.set_test_cookie()
72     return HttpResponseRedirect(request.META.get('HTTP_REFERER', '/'))
73
74 def logout(request):
75     """Simple front-end to django's logout stuff. This function should
76     be mapped to an url and simply called without any parameter.
77     """
78     logout_django(request)
79     return HttpResponseRedirect('/')
80
81 def speaker_add(request):
82     """Adds a new speaker to the system.
83     """
84     uform = RegisterSpeaker(request.POST or None)
85
86     form = SpeakerForm(request.POST or None)
87
88     if request.POST and form.is_valid() and uform.is_valid():
89         cd = uform.cleaned_data
90         group = Group.objects.get_or_create(name='palestrantes')[0]
91
92         # creating the user that will be set as the user of the
93         # speaker.
94         user = User(username=cd['username'])
95         user.set_password(cd['password1'])
96         user.is_active = True
97         user.save()
98         user.groups.add(group)
99
100         # this commit=False is to avoid IntegritErrors, because at
101         # this point, the speaker doesn't have an user associated
102         # with it.
103         instance = form.save(commit=False)
104         instance.usuario = user
105         instance.save()
106         return HttpResponseRedirect('/')
107
108     c = {'form': form, 'uform': uform}
109     return render_to_response('eventos/speaker-add.html', Context(c),
110                               context_instance=RequestContext(request))
111
112 def speaker_details(request, lid):
113     """Shows a simple form containing all editable fields of a
114     speaker and gives the speaker the possibility to save them =)
115     """
116     speaker = get_object_or_404(Palestrante, pk=lid)
117     d = {'speaker' : speaker}
118     if not hasattr(request.user, 'palestrante_set'):
119         return render_to_response('eventos/speaker-details2.html', Context(d),
120                                   context_instance=RequestContext(request))
121
122     entity = request.user.palestrante_set.get()
123     if entity.id != int(lid):
124         return render_to_response('eventos/speaker-details2.html', Context(d),
125                                   context_instance=RequestContext(request))
126
127     form = SpeakerForm(request.POST or None, instance=entity)
128
129     if request.POST and form.is_valid():
130         form.save()
131
132     c = {'form': form}
133     return render_to_response('eventos/speaker-details.html', Context(c),
134                               context_instance=RequestContext(request))
135
136 def speaker_talks(request, lid):
137     """Lists all talks of a speaker (based on speaker id -- lid
138     parameter).
139     """
140     if not hasattr(request.user, 'palestrante_set'):
141         return forbidden
142
143     entity = request.user.palestrante_set.get()
144     if entity.id != int(lid):
145         return forbidden
146
147     talks = Trabalho.objects.filter(
148         Q(palestrante=entity) | Q(outros_palestrantes=entity) )
149
150     c = {'speaker': entity, 'talks': talks}
151     return render_to_response('eventos/talk-list.html', Context(c),
152                               context_instance=RequestContext(request))
153
154 def talk_details(request, tid):
155     """Shows a form to edit a talk
156     """
157     # If the user is not a speaker we should not try to show anything.
158     if not hasattr(request.user, 'palestrante_set'):
159         return forbidden
160
161     # Selected in settings.py (SITE_ID) variable, because an event can
162     # be linked with only one site.
163     event = Evento.objects.get(site__id__exact=settings.SITE_ID)
164
165     # building the form
166     entity = get_object_or_404(Trabalho, pk=tid)
167     form = TalkForm(request.POST or None, instance=entity)
168
169     # These fields should not be shown to the user.
170     form.fields['palestrante'].widget = HiddenInput()
171     form.fields['evento'].widget = HiddenInput()
172
173     # These fields are event specific
174     trilhas = Trilha.objects.filter(evento=event)
175     form.fields['trilha']._set_queryset(trilhas)
176
177     tipos = TipoTrabalho.objects.filter(evento=event)
178     form.fields['tipo']._set_queryset(tipos)
179
180     # hidding the owner in the other speakers list
181     other = Palestrante.objects.exclude(pk=entity.id)
182     form.fields['outros_palestrantes']._set_queryset(other)
183     if other.count() == 0:
184         # I need set the value to '', otherwise the wise django
185         # newforms will fill the field with the invalid string '[]'
186         form.fields['outros_palestrantes'].initial = ''
187         form.fields['outros_palestrantes'].widget = HiddenInput()
188
189     # avoiding smart people trying to se talks of other speakers.
190     speaker = request.user.palestrante_set.get()
191     if speaker.id != entity.palestrante.id \
192             and speaker not in entity.outros_palestrantes.all():
193         return forbidden
194
195     if request.POST and form.is_valid():
196         form.save()
197
198     c = {'form': form}
199     return render_to_response('eventos/talk-details.html', Context(c),
200                               context_instance=RequestContext(request))
201
202 def talk_delete(request, tid):
203     """Drops a talk but only if the logged in user is its owner.
204     """
205     if not hasattr(request.user, 'palestrante_set'):
206         return forbidden
207
208     entity = request.user.palestrante_set.get()
209     talk = Trabalho.objects.filter(pk=tid, palestrante=entity)
210     if not talk:
211         return forbidden
212
213     talk.delete()
214     return HttpResponseRedirect('/speaker/%d/talks/' % entity.id)
215
216 def talk_add(request):
217     """Shows a form to the speaker send a talk
218     """
219     if not hasattr(request.user, 'palestrante_set'):
220         return forbidden
221
222     # building the form
223     form = TalkForm(request.POST or None)
224
225     # These fields should not be shown to the user.
226
227     # Selected in settings.py (SITE_ID) variable, because an event can
228     # be linked with only one site.
229     entity = request.user.palestrante_set.get()
230     form.fields['palestrante'].widget = HiddenInput(attrs={'value' : entity.id})
231
232     event = Evento.objects.get(site__id__exact=settings.SITE_ID)
233     form.fields['evento'].widget = HiddenInput(attrs={'value' : event.id})
234
235     # These fields are event specific
236     trilhas = Trilha.objects.filter(evento=event)
237     form.fields['trilha']._set_queryset(trilhas)
238
239     tipos = TipoTrabalho.objects.filter(evento=event)
240     form.fields['tipo']._set_queryset(tipos)
241
242     # hidding the owner in the other speakers list
243     other = Palestrante.objects.exclude(pk=entity.id)
244     form.fields['outros_palestrantes']._set_queryset(other)
245     if other.count() == 0:
246         form.fields['outros_palestrantes'].widget = HiddenInput()
247
248     if request.POST and form.is_valid():
249         # validation
250         cleaned = form.cleaned_data
251         if cleaned['tipo'].evento.id != event.id:
252             return forbidden
253
254         if cleaned['trilha'].evento.id != event.id:
255             return forbidden
256
257         instance = form.save()
258         return HttpResponseRedirect('/speaker/%d/talks/' % entity.id)
259
260     c = {'form': form}
261     return render_to_response('eventos/talk-add.html', Context(c),
262                               context_instance=RequestContext(request))
263
264 def list_all_talks(request):
265     event = Evento.objects.get(site__id__exact=settings.SITE_ID)
266     trilhas = Trilha.objects.filter(evento=event)
267
268     improve = []
269     for t in trilhas:
270         talks = Trabalho.objects.filter(trilha=t)
271         aux = {'trilha':t.nome, 'talks':talks}
272         improve.append(aux)
273
274     c = {'improve': improve,}
275     return render_to_response('eventos/improve.html', Context(c),
276                               context_instance=RequestContext(request))
277
278 def talk_improve(request, tid):
279     if not hasattr(request.user, 'palestrante_set') and request.POST:
280         return forbidden
281
282     talk = get_object_or_404(Trabalho, pk=tid)
283     improve = Improve.objects.filter(trabalho=talk)
284
285     # building the form
286     form = ImproveForm(request.POST or None)
287     form.fields['trabalho'].widget = HiddenInput(attrs={'value':talk.id})
288     form.fields['usuario'].widget = HiddenInput(attrs={'value':request.user.id})
289
290     if request.POST and form.is_valid():
291         event = Evento.objects.get(site__id__exact=settings.SITE_ID)
292         # validation
293         cleaned = form.cleaned_data
294         if cleaned['trabalho'].evento.id != event.id:
295             return forbidden
296
297         instance = form.save()
298         return HttpResponseRedirect('/improve/%d/' % talk.id)
299
300     c = {'talk': talk, 'form': form, 'improve': improve}
301     return render_to_response('eventos/talk_improve.html', Context(c),
302                               context_instance=RequestContext(request))