web-only confirmation routine for vinyambar

This commit is contained in:
Enno Rehling 2002-04-02 22:06:43 +00:00
parent fa4a09ae99
commit 69b6570700
2 changed files with 142 additions and 11 deletions

View file

@ -82,6 +82,15 @@ def ShowInfo(custid, Password):
global Errors
db = MySQLdb.connect(db=dbname)
cursor = db.cursor()
query=("select firstname, lastname, email, address, city, country, phone, status "+
"from users "+
"where id="+str(custid)+" and password='"+Password+"' ")
results = cursor.execute(query)
if results != 0:
firstname, lastname, email, address, city, country, phone, status = cursor.fetchone()
if status=='WAITING':
cursor.execute("update users set status='CONFIRMED' where id="+str(custid))
cursor.execute("select max(date), max(id) from transactions")
lastdate, id = cursor.fetchone()
@ -90,16 +99,8 @@ def ShowInfo(custid, Password):
while nraces>0:
nraces = nraces - 1
races.append(cursor.fetchone())
query=("select firstname, lastname, email, address, city, country, phone, status "+
"from users "+
"where id="+str(custid)+" and password='"+Password+"' ")
#print query
results = cursor.execute(query);
if results != 0:
output = '<div align=center>Letzter Buchungstag: '+str(lastdate)[0:10]+'</div><form action="'+scripturl+'" method=post><div align=center><table bgcolor="#e0e0e0" width=80% border>\n'
firstname, lastname, email, address, city, country, phone, status = cursor.fetchone()
query = "SELECT sum(balance) from transactions where user="+str(custid)
transactions = cursor.execute(query)

View file

@ -0,0 +1,130 @@
#!/usr/bin/env python
import sys
import MySQLdb
import os
import cgi
import re
import string
import smtplib
from whrandom import choice
# specify the filename of the template file
scripturl="http://eressea.upb.de/~enno/cgi-bin/vinyambar-register.py"
HTMLTemplate = "vinyambar.html"
MailTemplate="register.mail"
DefaultTitle = "Vinyambar Anmeldung"
dbname = "vinyambar"
From = "accounts@vinyambar.de"
locale="de"
smtpserver = 'localhost'
db=None
# define a new function called Display
# it takes one parameter - a string to Display
def Display(Content, Title=DefaultTitle):
TemplateHandle = open(HTMLTemplate, "r") # open in read only mode
# read the entire file as a string
TemplateInput = TemplateHandle.read()
TemplateHandle.close() # close the file
# this defines an exception string in case our
# template file is messed up
BadTemplateException = "There was a problem with the HTML template."
SubResult = re.subn("<!-- INSERT TITLE HERE -->", Title, TemplateInput)
SubResult = re.subn("<!-- INSERT CONTENT HERE -->", Content, SubResult[0])
if SubResult[1] == 0:
raise BadTemplateException
print "Content-Type: text/html\n\n"
print SubResult[0]
return
def Send(email, custid, firstname, password, position):
TemplateHandle = open(MailTemplate+"."+locale, "r") # open in read only mode
# read the entire file as a string
TemplateInput = TemplateHandle.read()
TemplateHandle.close() # close the file
SubResult = re.subn("<FIRSTNAME>", firstname, TemplateInput)
SubResult = re.subn("<PASSWORD>", password, SubResult[0])
SubResult = re.subn("<POSITION>", str(int(position)), SubResult[0])
SubResult = re.subn("<CUSTID>", str(int(custid)), SubResult[0])
Msg="From: "+From+"\nTo: "+email+"\nSubject: Vinyambar Anmeldung\n\n"
Msg=Msg+SubResult[0]
server=smtplib.SMTP(smtpserver)
server.sendmail(From, email, Msg)
server.close()
return
def GetKey(Form, key):
if Form.has_key(key):
value=Form[key].value
if value!="":
return value
return None
def ValidEmail(email):
if string.find(email, "@")==-1:
return 0
elif string.find(email, " ")!=-1:
return 0
return 1
def genpasswd():
newpasswd=""
chars = string.letters + string.digits
for i in range(8):
newpasswd = newpasswd + choice(chars)
return newpasswd
Form = cgi.FieldStorage()
email=GetKey(Form, "email")
firstname=GetKey(Form, "firstname")
lastname=GetKey(Form, "lastname")
address=GetKey(Form, "address")
city=GetKey(Form, "city")
country=GetKey(Form, "country")
phone=GetKey(Form, "phone")
if (locale==None) or (lastname==None) or (firstname==None) or (address==None) or (city==None):
output="<p>Um Dich zu Vinyambar anzumelden musst Du das Formular vollständig ausfüllen.\n "
for key in Form.keys():
output=output+"<br>"+key+": "+Form[key].value+"\n"
Display(output)
elif ValidEmail(email)==0:
output="<p>Um Dich zu Vinyambar anzumelden musst Du eine gültige Email-Adresse angeben.\n "
Display(output)
else:
db=MySQLdb.connect(db=dbname)
cursor=db.cursor()
exist=cursor.execute("select id from users where email='"+email+"'")
if exist>0:
Display('<p>Du hast bereits einen Eintrag in der Datenbank.')
else:
password=genpasswd()
fields = "firstname, lastname, locale, email, address, city, status, password"
values = "'"+firstname+"', '"+lastname+"', '"+locale+"', '"+email+"', '"+address+"', '"+city+"', 'WAITING', '"+password+"'"
if phone!=None:
fields=fields+", phone"
values=values+", '"+phone+"'"
if country!=None:
fields=fields+", country"
values=values+", "+country+""
cursor.execute("insert into users ("+fields+") VALUES ("+values+")")
cursor.execute("SELECT LAST_INSERT_ID() from dual")
custid=cursor.fetchone()[0]
if os.environ.has_key('REMOTE_ADDR'):
ip=os.environ['REMOTE_ADDR']
cursor.execute("REPLACE userips (ip, user) VALUES ('"+ip+"', "+str(int(custid))+")")
cursor.execute("select count(*) from users where status='WAITING' or status='CONFIRMED'")
waiting=cursor.fetchone()[0]
Send(email, custid, firstname, password, waiting)
Display("<p>Deine Anmeldung wurde bearbeitet. Eine EMail mit Hinweisen ist unterwegs zu Dir.")
db.close()