views.py 4.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116
  1. from account.decorators import login_required
  2. from file.models import File
  3. from django.http import FileResponse
  4. from django.utils.http import urlquote
  5. from folder.models import Folder
  6. from .judgement_function import judge_filepath
  7. from account.models import get_user
  8. from utils.debug import debug_view
  9. from utils.http import make_json_response
  10. from utils.permission import can_delete
  11. from utils.crypto import secure_transport
  12. from utils.crypto import get_file_encrypt_cipher
  13. import base64
  14. # Create your views here.
  15. @secure_transport
  16. @debug_view(template_name='upload_file.html')
  17. @login_required
  18. def upload_file(request):
  19. data = request.POST
  20. user = get_user(request)
  21. key = data.get('key', '')
  22. if key:
  23. file_b64 = data.get('file_b64')
  24. if not file_b64:
  25. return make_json_response(code=400, error='文件不存在')
  26. file_name = data.get('file_name')
  27. else:
  28. try:
  29. file_obj = request.FILES.get('file')
  30. except:
  31. return make_json_response(code=400, error='文件不存在')
  32. file_name = file_obj.name
  33. file_type = judge_filepath(file_name.split('.')[-1].lower()) if '.' in file_name else ''
  34. father_folder_id = data.get('father_folder_id')
  35. try:
  36. folder = Folder.objects.get(folder_id=father_folder_id)
  37. except:
  38. return make_json_response(code=402, error='文件夹不存在')
  39. if not folder.check_permission(user=user):
  40. return make_json_response(code=404, error='没有上传文件的权限')
  41. file = File.objects.create(file_name=file_name,
  42. father_folder=folder,
  43. file_type=file_type,
  44. owner=user,
  45. group=folder.group,
  46. key=key)
  47. try:
  48. file_path = file.get_path()
  49. with open(file_path, 'wb+') as f:
  50. if key:
  51. file_bytes = base64.b64decode(file_b64)
  52. enc_file_bytes = get_file_encrypt_cipher().encrypt(file_bytes)
  53. f.write(enc_file_bytes)
  54. else:
  55. for chunk in file_obj.chunks():
  56. f.write(chunk)
  57. except Exception as e:
  58. file.delete()
  59. return make_json_response(code=500, error='文件保存失败')
  60. return make_json_response()
  61. @secure_transport
  62. # @debug_view('file_id')
  63. @login_required
  64. def download_file(request):
  65. user = get_user(request)
  66. file_id = request.POST.get('file_id')
  67. try:
  68. file = File.objects.get(file_id=file_id)
  69. except:
  70. return make_json_response(code=402, error='文件不存在')
  71. if not file.father_folder.check_permission(user=user):
  72. return make_json_response(code=404, error='没有下载文件的权限')
  73. try:
  74. file_path = file.get_path()
  75. f = open(file_path, 'rb')
  76. except:
  77. return make_json_response(code=500, error='文件读取失败')
  78. if file.key:
  79. try:
  80. enc_file_bytes = f.read()
  81. file_bytes = get_file_encrypt_cipher().decrypt(enc_file_bytes)
  82. file_b64 = base64.b64encode(file_bytes).decode()
  83. f.close()
  84. except:
  85. return make_json_response(code=500, error='文件读取失败')
  86. return make_json_response(file_b64=file_b64, **file.to_json())
  87. else:
  88. file_name = file.file_name
  89. response = FileResponse(f)
  90. response['Content-Type'] = 'application/octet-stream'
  91. response['Content-Disposition'] = 'attachment;filename={}'.format(urlquote(file_name))
  92. return response
  93. @secure_transport
  94. # @debug_view('file_id')
  95. @login_required
  96. def delete_file(request):
  97. data = request.POST
  98. user = get_user(request)
  99. file_id = data.get('file_id')
  100. try:
  101. file = File.objects.get(file_id=file_id)
  102. except:
  103. return make_json_response(code=402, error='文件不存在')
  104. if not can_delete(user=user, f=file):
  105. return make_json_response(code=404, error='没有删除文件的权限')
  106. file.delete()
  107. return make_json_response()