Files
simple-nanoshare/routes/side/main.py
T
2025-10-25 14:54:00 +02:00

87 lines
3.4 KiB
Python

from my_modules.file_helper_functions import is_expired, verify_signed_url
from my_modules.decoratory.header import login_required
from my_modules.functions import get_ip
from my_modules.app.setup import LIMITER
from my_modules.app.logger import logger
from quart import Blueprint, request, session, Response, send_from_directory, render_template, abort, current_app
from datetime import datetime, timezone
side_main_bp = Blueprint('side_main', __name__)
@side_main_bp.route('/')
@LIMITER.limit("10 per minute;50 per hour")
async def index():
if session.get("user") is not None:
return await render_template("views/webpage/files/upload.htm")
return await render_template("views/webpage/index.htm")
@side_main_bp.route('/access')
@login_required
async def access_list(user):
access_data = await current_app.edgedb.get_all_access_of_user(user_id=user['sub'])
return await render_template("views/webpage/access/list.htm", access_logs=access_data)
@side_main_bp.route('/files')
@login_required
async def files_list(user):
files_data = await current_app.edgedb.get_files(current_datetime=datetime.now(timezone.utc), user_id=user['sub'])
return await render_template("views/webpage/files/list.htm", files=files_data)
@side_main_bp.route('/files/<path:file_id>/info')
@login_required
async def file_info(file_id, user):
files_data = await current_app.edgedb.get_files(user_id=user['sub'])
return await render_template("views/webpage/files/info.htm", files=files_data)
@side_main_bp.route('/files/<path:file_id>/edit')
@login_required
async def file_edit(file_id, user):
files_data = await current_app.edgedb.get_files(user_id=user['sub'])
return await render_template("views/webpage/files/edit.htm", files=files_data)
@side_main_bp.route("/-<file_id>")
@LIMITER.limit("10 per minute;500 per hour;")
async def serve_file(file_id: str):
file_data = await current_app.edgedb.get_file(file_id=file_id)
disable_logging = False
if not file_data:
abort(404)
user = session.get('user')
if user and user['sub'] == file_data['user_id']:
disable_logging = True
if is_expired(file_data.get("expires_at")):
if not disable_logging:
await current_app.edgedb.add_file_access(file_id=file_id, ip_address=get_ip(), user_agent=request.user_agent, status="expired", accessed_at=datetime.now(timezone.utc))
return Response("This file has expired.", status=410, headers={
"Cache-Control": "no-store",
"X-Content-Type-Options": "nosniff",
})
file_name = file_data.get("file_name")
content_type = file_data.get("content_type") or "application/octet-stream"
force_download = request.args.get("download") in {"1", "true", "yes"}
path = current_app.upload_folder / file_name
if not path.exists() or not path.is_file():
if not disable_logging:
await current_app.edgedb.add_file_access(file_id=file_id, ip_address=get_ip(), user_agent=request.user_agent, status="error", accessed_at=datetime.now(timezone.utc))
abort(404)
if not disable_logging:
await current_app.edgedb.add_file_access(file_id=file_id, ip_address=get_ip(), user_agent=request.user_agent, status="ok", accessed_at=datetime.now(timezone.utc))
return await send_from_directory(
directory=current_app.upload_folder,
file_name=file_name,
mimetype=content_type,
as_attachment=force_download,
attachment_filename=file_name,
conditional=True,
cache_timeout=60,
last_modified=path.stat().st_mtime
)