Exemple #1
0
def load_logged_in_user():
    user_id = session.get('user_id')

    if user_id is None:
        g.user = None
    else:
        g.user = get_db().execute('SELECT * FROM users WHERE id = ?',
                                  (user_id, )).fetchone()
Exemple #2
0
def get_card(id, check_author=True):
    card = get_db().execute(
        'SELECT c.id, front, back, created_at, user_id, username'
        ' FROM cards c JOIN users u ON c.user_id = u.id'
        ' WHERE c.id = ?', (id, )).fetchone()

    if card is None:
        abort(404, "Card id {0} doesn't exist.".format(id))

    if check_author and card['user_id'] != g.user['id']:
        abort(403)

    return card
Exemple #3
0
def create():
    if request.method == 'POST':
        front = request.form['front']
        back = request.form['back']
        error = None

        if not front:
            error = 'Front is required.'

        if error is not None:
            flash(error)
        else:
            db = get_db()
            db.execute(
                'INSERT INTO cards (front, back, user_id)'
                ' VALUES (?, ?, ?)', (front, back, g.user['id']))
            db.commit()
            return redirect(url_for('cards.index'))

    return render_template('cards/create.html')
Exemple #4
0
def update(id):
    card = get_card(id)

    if request.method == 'POST':
        front = request.form['front']
        back = request.form['back']
        error = None

        if not front:
            error = 'Front is required.'

        if error is not None:
            flash(error)
        else:
            db = get_db()
            db.execute('UPDATE card SET front = ?, back = ?'
                       ' WHERE id = ?', (front, back, id))
            db.commit()
            return redirect(url_for('cards.index'))

    return render_template('cards/update.html', card=card)
Exemple #5
0
def login():
    if request.method == 'POST':
        username = request.form['username']
        password = request.form['password']
        db = get_db()
        error = None
        user = db.execute('SELECT * FROM users WHERE username = ?',
                          (username, )).fetchone()

        if user is None:
            error = 'Incorrect username.'
        elif not check_password_hash(user['password'], password):
            error = 'Incorrect password.'

        if error is None:
            session.clear()
            session['user_id'] = user['id']
            return redirect(url_for('index'))

        flash(error)

    return render_template('auth/login.html')
Exemple #6
0
def register():
    if request.method == 'POST':
        username = request.form['username']
        password = request.form['password']
        db = get_db()
        error = None

        if not username:
            error = 'Username is required.'
        elif not password:
            error = 'Password is required.'
        elif db.execute('SELECT id FROM users WHERE username = ?',
                        (username, )).fetchone() is not None:
            error = 'User {} is already registered.'.format(username)

        if error is None:
            db.execute('INSERT INTO users (username, password) VALUES (?, ?)',
                       (username, generate_password_hash(password)))
            db.commit()
            return redirect(url_for('auth.login'))

            flash(error)

    return render_template('auth/register.html')
Exemple #7
0
def delete(id):
    get_card(id)
    db = get_db()
    db.execute('DELETE FROM cards WHERE id = ?', (id, ))
    db.commit()
    return redirect(url_for('cards.index'))
Exemple #8
0
def index():
    db = get_db()
    cards = db.execute('SELECT * FROM cards WHERE user_id=?',
                       (g.user['id'])).fetchall()
    return render_template('cards/index.html', cards=cards)