Merge ssh://github.com/web2py/web2py
This commit is contained in:
@@ -1 +1 @@
|
|||||||
Version 2.6.0-development+timestamp.2013.07.23.02.04.35
|
Version 2.6.0-development+timestamp.2013.07.27.06.46.34
|
||||||
|
|||||||
@@ -32,7 +32,8 @@ except:
|
|||||||
|
|
||||||
if request.env.http_x_forwarded_for or request.is_https:
|
if request.env.http_x_forwarded_for or request.is_https:
|
||||||
session.secure()
|
session.secure()
|
||||||
elif (remote_addr not in hosts) and (remote_addr != "127.0.0.1"):
|
elif (remote_addr not in hosts) and (remote_addr != "127.0.0.1") and \
|
||||||
|
(request.function != 'manage'):
|
||||||
raise HTTP(200, T('appadmin is disabled because insecure channel'))
|
raise HTTP(200, T('appadmin is disabled because insecure channel'))
|
||||||
|
|
||||||
if request.function == 'manage':
|
if request.function == 'manage':
|
||||||
|
|||||||
@@ -32,7 +32,8 @@ except:
|
|||||||
|
|
||||||
if request.env.http_x_forwarded_for or request.is_https:
|
if request.env.http_x_forwarded_for or request.is_https:
|
||||||
session.secure()
|
session.secure()
|
||||||
elif (remote_addr not in hosts) and (remote_addr != "127.0.0.1"):
|
elif (remote_addr not in hosts) and (remote_addr != "127.0.0.1") and \
|
||||||
|
(request.function != 'manage'):
|
||||||
raise HTTP(200, T('appadmin is disabled because insecure channel'))
|
raise HTTP(200, T('appadmin is disabled because insecure channel'))
|
||||||
|
|
||||||
if request.function == 'manage':
|
if request.function == 'manage':
|
||||||
|
|||||||
@@ -32,7 +32,8 @@ except:
|
|||||||
|
|
||||||
if request.env.http_x_forwarded_for or request.is_https:
|
if request.env.http_x_forwarded_for or request.is_https:
|
||||||
session.secure()
|
session.secure()
|
||||||
elif (remote_addr not in hosts) and (remote_addr != "127.0.0.1"):
|
elif (remote_addr not in hosts) and (remote_addr != "127.0.0.1") and \
|
||||||
|
(request.function != 'manage'):
|
||||||
raise HTTP(200, T('appadmin is disabled because insecure channel'))
|
raise HTTP(200, T('appadmin is disabled because insecure channel'))
|
||||||
|
|
||||||
if request.function == 'manage':
|
if request.function == 'manage':
|
||||||
|
|||||||
+3
-4
File diff suppressed because one or more lines are too long
+9
-2
@@ -679,6 +679,11 @@ class BaseAdapter(ConnectionPool):
|
|||||||
'big-reference': 'BIGINT REFERENCES %(foreign_key)s ON DELETE %(on_delete_action)s',
|
'big-reference': 'BIGINT REFERENCES %(foreign_key)s ON DELETE %(on_delete_action)s',
|
||||||
}
|
}
|
||||||
|
|
||||||
|
def isOperationalError(self,exception):
|
||||||
|
if not hasattr(self.driver, "OperationalError"):
|
||||||
|
return None
|
||||||
|
return isinstance(exception, self.driver.OperationalError)
|
||||||
|
|
||||||
def id_query(self, table):
|
def id_query(self, table):
|
||||||
return table._id != None
|
return table._id != None
|
||||||
|
|
||||||
@@ -4324,7 +4329,9 @@ class DatabaseStoredFile:
|
|||||||
try:
|
try:
|
||||||
if db.executesql(query):
|
if db.executesql(query):
|
||||||
return True
|
return True
|
||||||
except Exception:
|
except Exception, e:
|
||||||
|
if not db._adapter.isOperationalError(e):
|
||||||
|
raise
|
||||||
# no web2py_filesystem found?
|
# no web2py_filesystem found?
|
||||||
tb = traceback.format_exc()
|
tb = traceback.format_exc()
|
||||||
LOGGER.error("Could not retrieve %s\n%s" % (filename, tb))
|
LOGGER.error("Could not retrieve %s\n%s" % (filename, tb))
|
||||||
@@ -5457,7 +5464,7 @@ class MongoDBAdapter(NoSQLAdapter):
|
|||||||
else:
|
else:
|
||||||
mongosort_list.append((f, 1))
|
mongosort_list.append((f, 1))
|
||||||
if limitby:
|
if limitby:
|
||||||
limitby_skip, limitby_limit = limitby
|
limitby_skip, limitby_limit = limitby[0], int(limitby[1])
|
||||||
else:
|
else:
|
||||||
limitby_skip = limitby_limit = 0
|
limitby_skip = limitby_limit = 0
|
||||||
|
|
||||||
|
|||||||
@@ -27,6 +27,7 @@ defined_status = {
|
|||||||
307: 'TEMPORARY REDIRECT',
|
307: 'TEMPORARY REDIRECT',
|
||||||
400: 'BAD REQUEST',
|
400: 'BAD REQUEST',
|
||||||
401: 'UNAUTHORIZED',
|
401: 'UNAUTHORIZED',
|
||||||
|
402: 'PAYMENT REQUIRED',
|
||||||
403: 'FORBIDDEN',
|
403: 'FORBIDDEN',
|
||||||
404: 'NOT FOUND',
|
404: 'NOT FOUND',
|
||||||
405: 'METHOD NOT ALLOWED',
|
405: 'METHOD NOT ALLOWED',
|
||||||
@@ -79,6 +80,8 @@ class HTTP(Exception):
|
|||||||
headers = self.headers
|
headers = self.headers
|
||||||
if status in defined_status:
|
if status in defined_status:
|
||||||
status = '%d %s' % (status, defined_status[status])
|
status = '%d %s' % (status, defined_status[status])
|
||||||
|
elif isinstance(status, int):
|
||||||
|
status = '%d UNKNOWN ERROR' % status
|
||||||
else:
|
else:
|
||||||
status = str(status)
|
status = str(status)
|
||||||
if not regex_status.match(status):
|
if not regex_status.match(status):
|
||||||
|
|||||||
+4
-1
@@ -172,7 +172,10 @@ def copystream_progress(request, chunk_size=10 ** 5):
|
|||||||
size = int(env.content_length)
|
size = int(env.content_length)
|
||||||
except ValueError:
|
except ValueError:
|
||||||
raise HTTP(400, "Invalid Content-Length header")
|
raise HTTP(400, "Invalid Content-Length header")
|
||||||
dest = tempfile.NamedTemporaryFile()
|
try: # Android requires this
|
||||||
|
dest = tempfile.NamedTemporaryFile()
|
||||||
|
except NotImplementedError: # and GAE this
|
||||||
|
dest = tempfile.TemporaryFile()
|
||||||
if not 'X-Progress-ID' in request.vars:
|
if not 'X-Progress-ID' in request.vars:
|
||||||
copystream(source, dest, size, chunk_size)
|
copystream(source, dest, size, chunk_size)
|
||||||
return dest
|
return dest
|
||||||
|
|||||||
+22
-31
@@ -2618,39 +2618,30 @@ class SQLFORM(FORM):
|
|||||||
for rfield in table._referenced_by:
|
for rfield in table._referenced_by:
|
||||||
check[rfield.tablename] = \
|
check[rfield.tablename] = \
|
||||||
check.get(rfield.tablename, []) + [rfield.name]
|
check.get(rfield.tablename, []) + [rfield.name]
|
||||||
|
if linked_tables is None:
|
||||||
|
linked_tables = db.tables()
|
||||||
if isinstance(linked_tables, dict):
|
if isinstance(linked_tables, dict):
|
||||||
for tbl in linked_tables.keys():
|
linked_tables = linked_tables.get(table._tablename,[])
|
||||||
tb = db[tbl]
|
if linked_tables:
|
||||||
if isinstance(linked_tables[tbl], list):
|
for item in linked_tables:
|
||||||
if len(linked_tables[tbl]) > 1:
|
tb = None
|
||||||
t = T('%s(%s)' %(tbl, fld))
|
if isinstance(item,Table) and item._tablename in check:
|
||||||
else:
|
tablename = item._tablename
|
||||||
t = T(tb._plural)
|
linked_fieldnames = check[tablename]
|
||||||
for fld in linked_tables[tbl]:
|
td = item
|
||||||
if fld not in db[tbl].fields:
|
elif isinstance(item,str) and item in check:
|
||||||
raise ValueError('Field %s not in table' %fld)
|
tablename = item
|
||||||
args0 = tbl + '.' + fld
|
linked_fieldnames = check[item]
|
||||||
links.append(
|
tb = db[item]
|
||||||
lambda row, t=t, nargs=nargs, args0=args0:
|
elif isinstance(item,Field) and item.name in check.get(item._tablename,[]):
|
||||||
A(SPAN(t), _class=trap_class(), _href=url(
|
tablename = item._tablename
|
||||||
args=[args0, row[id_field_name]])))
|
linked_fieldnames = [item.name]
|
||||||
|
tb = item.table
|
||||||
else:
|
else:
|
||||||
t = T(tb._plural)
|
linked_fieldnames = []
|
||||||
fld = linked_tables[tbl]
|
if tb:
|
||||||
if fld not in db[tbl].fields:
|
multiple_links = len(linked_fieldnames) > 1
|
||||||
raise ValueError('Field %s not in table' %fld)
|
for fieldname in linked_fieldnames:
|
||||||
args0 = tbl + '.' + fld
|
|
||||||
links.append(
|
|
||||||
lambda row, t=t, nargs=nargs, args0=args0:
|
|
||||||
A(SPAN(t), _class=trap_class(), _href=url(
|
|
||||||
args=[args0, row[id_field_name]])))
|
|
||||||
else:
|
|
||||||
for tablename in sorted(check):
|
|
||||||
linked_fieldnames = check[tablename]
|
|
||||||
tb = db[tablename]
|
|
||||||
multiple_links = len(linked_fieldnames) > 1
|
|
||||||
for fieldname in linked_fieldnames:
|
|
||||||
if linked_tables is None or tablename in linked_tables:
|
|
||||||
t = T(tb._plural) if not multiple_links else \
|
t = T(tb._plural) if not multiple_links else \
|
||||||
T(tb._plural + '(' + fieldname + ')')
|
T(tb._plural + '(' + fieldname + ')')
|
||||||
args0 = tablename + '.' + fieldname
|
args0 = tablename + '.' + fieldname
|
||||||
|
|||||||
+11
-6
@@ -893,6 +893,7 @@ class Auth(object):
|
|||||||
on_failed_authentication=lambda x: redirect(x),
|
on_failed_authentication=lambda x: redirect(x),
|
||||||
formstyle="table3cols",
|
formstyle="table3cols",
|
||||||
label_separator=": ",
|
label_separator=": ",
|
||||||
|
logging_enabled = True,
|
||||||
allow_delete_accounts=False,
|
allow_delete_accounts=False,
|
||||||
password_field='password',
|
password_field='password',
|
||||||
table_user_name='auth_user',
|
table_user_name='auth_user',
|
||||||
@@ -969,7 +970,6 @@ class Auth(object):
|
|||||||
new_password='New password',
|
new_password='New password',
|
||||||
old_password='Old password',
|
old_password='Old password',
|
||||||
group_description='Group uniquely assigned to user %(id)s',
|
group_description='Group uniquely assigned to user %(id)s',
|
||||||
logging_enabled = True,
|
|
||||||
register_log='User %(id)s Registered',
|
register_log='User %(id)s Registered',
|
||||||
login_log='User %(id)s Logged-in',
|
login_log='User %(id)s Logged-in',
|
||||||
login_failed_log=None,
|
login_failed_log=None,
|
||||||
@@ -1750,7 +1750,7 @@ class Auth(object):
|
|||||||
user_id = None # user unknown
|
user_id = None # user unknown
|
||||||
vars = vars or {}
|
vars = vars or {}
|
||||||
# log messages should not be translated
|
# log messages should not be translated
|
||||||
if type(descrption).__name__ == 'lazyT':
|
if type(description).__name__ == 'lazyT':
|
||||||
description = description.m
|
description = description.m
|
||||||
self.table_event().insert(
|
self.table_event().insert(
|
||||||
description=str(description % vars),
|
description=str(description % vars),
|
||||||
@@ -2048,10 +2048,15 @@ class Auth(object):
|
|||||||
if next is DEFAULT:
|
if next is DEFAULT:
|
||||||
# important for security
|
# important for security
|
||||||
next = self.settings.login_next
|
next = self.settings.login_next
|
||||||
if self.next:
|
user_next = self.next
|
||||||
host = self.next.split('//',1)[-1].split('/')[0]
|
if user_next:
|
||||||
if host in self.settings.cas_domains:
|
external = user_next.split('://')
|
||||||
next = self.next
|
if external[0].lower() in ['http', 'https', 'ftp']:
|
||||||
|
host_next = user_next.split('//', 1)[-1].split('/')[0]
|
||||||
|
if host_next in self.settings.cas_domains:
|
||||||
|
next = user_next
|
||||||
|
else:
|
||||||
|
next = user_next
|
||||||
if onvalidation is DEFAULT:
|
if onvalidation is DEFAULT:
|
||||||
onvalidation = self.settings.login_onvalidation
|
onvalidation = self.settings.login_onvalidation
|
||||||
if onaccept is DEFAULT:
|
if onaccept is DEFAULT:
|
||||||
|
|||||||
Reference in New Issue
Block a user