sign in system pretty much

This commit is contained in:
ralphi3
2026-06-18 13:48:25 +12:00
parent eda37b8ad1
commit 723c60fa22
6 changed files with 85 additions and 18 deletions
+41 -8
View File
@@ -1,4 +1,6 @@
from flask import Flask, render_template, redirect, request, url_for
from functools import wraps
from flask import Flask, render_template, redirect, request, url_for, session, flash
from flask_sqlalchemy import SQLAlchemy
from werkzeug.security import generate_password_hash, check_password_hash
@@ -19,6 +21,16 @@ with app.app_context():
db.create_all()
def login_required(view_func):
@wraps(view_func)
def wrapped(*args, **kwargs):
if 'user_id' not in session:
flash('Please sign in to view that page.')
return redirect(url_for('signin'))
return view_func(*args, **kwargs)
return wrapped
@app.route('/submit-form', methods=['POST'])
def handle_submission():
form_username = request.form.get('username')
@@ -41,21 +53,21 @@ def handle_submission():
@app.route('/users')
@login_required
def view_users():
all_users = User.query.all()
html_output = "<h2>Registered Accounts</h2><table border='1' cellpadding='10'>"
html_output += "<tr><th>ID</th><th>Username</th><th>Email</th></tr>"
for user in all_users:
html_output += f"<tr><td>{user.id}</td><td>{user.username}</td><td>{user.email}</td><td>{user.password_hash}</td></tr>"
html_output += f"<tr><td>{user.id}</td><td>{user.username}</td><td>{user.email}</td></tr>"
html_output += "</table>"
if not all_users:
return "<h3>No accounts found in the database yet.</h3>"
return html_output
@@ -71,15 +83,36 @@ def bivariate():
def about():
return render_template('about.html')
@app.route('/signin')
@app.route('/signin', methods=['GET', 'POST'])
def signin():
if request.method == 'POST':
form_username = request.form.get('username')
form_password = request.form.get('password')
user = User.query.filter_by(username=form_username).first()
if user is None or not check_password_hash(user.password_hash, form_password):
flash('Incorrect username or password.')
return render_template('signin.html'), 401
session['user_id'] = user.id
session['username'] = user.username
return redirect(url_for('home'))
return render_template('signin.html')
@app.route('/logout')
def logout():
session.clear()
return redirect(url_for('home'))
@app.route('/signup')
def signup():
return render_template('signup.html')
@app.route('/all_users')
@login_required
def all_users():
return render_template('all_users.html')