X-Git-Url: http://git.cascardo.info/?p=cascardo%2Fipsilon.git;a=blobdiff_plain;f=ipsilon%2Futil%2Fpage.py;h=e1cecb94dcc2847811eefa0db34d8403e8dfe2e6;hp=09299616ee71af383e6659e4dbd3e41d09659df2;hb=cfe24fa3dc15d87f3ace944a2d62a0f4c5ee496c;hpb=d6ffbfe04bc6b6370e3aa112e7bdd7183a851a94 diff --git a/ipsilon/util/page.py b/ipsilon/util/page.py index 0929961..e1cecb9 100644 --- a/ipsilon/util/page.py +++ b/ipsilon/util/page.py @@ -1,22 +1,7 @@ -# Copyright (C) 2013 Simo Sorce -# -# see file 'COPYING' for use and warranty information -# -# This program is free software; you can redistribute it and/or modify -# it under the terms of the GNU General Public License as published by -# the Free Software Foundation, either version 3 of the License, or -# (at your option) any later version. -# -# This program is distributed in the hope that it will be useful, -# but WITHOUT ANY WARRANTY; without even the implied warranty of -# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -# GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public License -# along with this program. If not, see . +# Copyright (C) 2013 Ipsilon project Contributors, for license see COPYING import cherrypy -from ipsilon.util.log import Log +from ipsilon.util.endpoint import Endpoint from ipsilon.util.user import UserSession from ipsilon.util.trans import Transaction from urllib import unquote @@ -40,17 +25,25 @@ def admin_protect(fn): return check -class Page(Log): +class Page(Endpoint): def __init__(self, site, form=False): + super(Page, self).__init__(site) if 'template_env' not in site: raise ValueError('Missing template environment') self._site = site self.basepath = cherrypy.config.get('base.mount', "") self.user = None self._is_form_page = form - self.default_headers = dict() self.auth_protect = False + def get_url(self): + return cherrypy.url(relative=False) + + def instance_base_url(self): + url = self.get_url() + s = urlparse(unquote(url)) + return '%s://%s%s' % (s.scheme, s.netloc, self.basepath) + def _check_referer(self, referer, url): r = urlparse(unquote(referer)) u = urlparse(unquote(url)) @@ -63,7 +56,6 @@ class Page(Log): return False def __call__(self, *args, **kwargs): - # pylint: disable=star-args cherrypy.response.headers.update(self.default_headers) self.user = UserSession().get_user() @@ -77,20 +69,20 @@ class Page(Log): return op(*args[1:], **kwargs) else: if self._is_form_page: - self._debug("method: %s" % cherrypy.request.method) + self.debug("method: %s" % cherrypy.request.method) op = getattr(self, cherrypy.request.method, None) if callable(op): # Basic CSRF protection if cherrypy.request.method != 'GET': - url = cherrypy.url(relative=False) + url = self.get_url() if 'referer' not in cherrypy.request.headers: - self._debug("Missing referer in %s request to %s" - % (cherrypy.request.method, url)) + self.debug("Missing referer in %s request to %s" + % (cherrypy.request.method, url)) raise cherrypy.HTTPError(403) referer = cherrypy.request.headers['referer'] if not self._check_referer(referer, url): - self._debug("Wrong referer %s in request to %s" - % (referer, url)) + self.debug("Wrong referer %s in request to %s" + % (referer, url)) raise cherrypy.HTTPError(403) return op(*args, **kwargs) else: @@ -108,7 +100,6 @@ class Page(Log): return model def _template(self, *args, **kwargs): - # pylint: disable=star-args t = self._site['template_env'].get_template(args[0]) m = self._template_model() m.update(kwargs) @@ -129,9 +120,17 @@ class Page(Log): # Try with kwargs first tid = t.find_tid(kwargs) if not tid: - # If no TID yet See if we have it in a referer + # If no TID yet See if we have it in a referer or in the + # environment in the REDIRECT_URL + url = None if 'referer' in cherrypy.request.headers: - r = urlparse(unquote(cherrypy.request.headers['referer'])) + url = cherrypy.request.headers['referer'] + r = urlparse(unquote(url)) + if r.query: + tid = t.find_tid(parse_qs(r.query)) + if not tid and 'REQUEST_URI' in cherrypy.request.wsgi_environ: + url = cherrypy.request.wsgi_environ['REQUEST_URI'] + r = urlparse(unquote(url)) if r.query: tid = t.find_tid(parse_qs(r.query)) if not tid: