views.py 3.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596
  1. from account.decorators import login_required
  2. from file.models import File
  3. from django.http import FileResponse, JsonResponse, HttpResponse
  4. from django.utils import timezone
  5. from folder.models import Folder
  6. from .judgement_function import judge_filepath, format_size
  7. from django.utils.http import urlquote
  8. import os
  9. from account.models import get_user
  10. from utils.debug import debug_view
  11. from utils.http import make_json_response
  12. from utils.permission import can_delete
  13. from utils.crypto import secure_transport
  14. BASE_DIR = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
  15. # Create your views here.
  16. @secure_transport
  17. # @debug_view(template_name='upload_file.html')
  18. @login_required
  19. def upload_file(request):
  20. data = request.POST
  21. user = get_user(request)
  22. try:
  23. file_obj = request.FILES.get('file')
  24. except:
  25. return make_json_response(code=400, error='文件不存在')
  26. update_time = timezone.now().strftime("%Y-%m-%d %H:%M:%S")
  27. file_size = file_obj.size
  28. file_name = file_obj.name
  29. file_type = judge_filepath(file_name.split('.')[-1].lower()) if '.' in file_name else ''
  30. father_folder_id = data.get('father_folder_id')
  31. try:
  32. folder = Folder.objects.get(folder_id=father_folder_id)
  33. except:
  34. return make_json_response(code=402, error='文件夹不存在')
  35. if not folder.check_permission(user=user):
  36. return make_json_response(code=404, error='没有上传文件的权限')
  37. file = File.objects.create(file_name=file_name,
  38. father_folder=folder,
  39. update_time=update_time,
  40. file_size=file_size,
  41. file_type=file_type,
  42. owner=user,
  43. group=folder.group)
  44. # TODO: 文件hash
  45. try:
  46. file_dir = BASE_DIR + '/' + str(file.file_id)
  47. with open(file_dir, 'wb+') as f:
  48. for chunk in file_obj.chunks():
  49. f.write(chunk)
  50. except:
  51. file.delete()
  52. return make_json_response(code=500, error='文件保存失败')
  53. return make_json_response()
  54. @secure_transport
  55. # @debug_view('file_id')
  56. @login_required
  57. def download_file(request):
  58. user = get_user(request)
  59. file_id = request.POST.get('file_id')
  60. try:
  61. file = File.objects.get(file_id=file_id)
  62. except:
  63. return make_json_response(code=402, error='文件不存在')
  64. if not file.father_folder.check_permission(user=user):
  65. return make_json_response(code=404, error='没有下载文件的权限')
  66. file_name = file.file_name
  67. file_dir = BASE_DIR + '/' + str(file.file_id)
  68. file = open(file_dir, 'rb')
  69. response = FileResponse(file)
  70. response['Content-Type'] = 'application/octet-stream'
  71. response['Content-Disposition'] = 'attachment;filename={}'.format(urlquote(file_name))
  72. return response
  73. @secure_transport
  74. # @debug_view('file_id')
  75. @login_required
  76. def delete_file(request):
  77. data = request.POST
  78. user = get_user(request)
  79. file_id = data.get('file_id')
  80. try:
  81. file = File.objects.get(file_id=file_id)
  82. except:
  83. return make_json_response(code=402, error='文件不存在')
  84. if not can_delete(user=user, f=file):
  85. return make_json_response(code=404, error='没有删除文件的权限')
  86. file.delete()
  87. return make_json_response()