sign in system pretty much
This commit is contained in:
@@ -1,4 +1,6 @@
|
||||
from flask import Flask, render_template, redirect, request, url_for
|
||||
from functools import wraps
|
||||
|
||||
from flask import Flask, render_template, redirect, request, url_for, session, flash
|
||||
from flask_sqlalchemy import SQLAlchemy
|
||||
from werkzeug.security import generate_password_hash, check_password_hash
|
||||
|
||||
@@ -19,6 +21,16 @@ with app.app_context():
|
||||
db.create_all()
|
||||
|
||||
|
||||
def login_required(view_func):
|
||||
@wraps(view_func)
|
||||
def wrapped(*args, **kwargs):
|
||||
if 'user_id' not in session:
|
||||
flash('Please sign in to view that page.')
|
||||
return redirect(url_for('signin'))
|
||||
return view_func(*args, **kwargs)
|
||||
return wrapped
|
||||
|
||||
|
||||
@app.route('/submit-form', methods=['POST'])
|
||||
def handle_submission():
|
||||
form_username = request.form.get('username')
|
||||
@@ -41,21 +53,21 @@ def handle_submission():
|
||||
|
||||
|
||||
@app.route('/users')
|
||||
@login_required
|
||||
def view_users():
|
||||
all_users = User.query.all()
|
||||
|
||||
|
||||
html_output = "<h2>Registered Accounts</h2><table border='1' cellpadding='10'>"
|
||||
html_output += "<tr><th>ID</th><th>Username</th><th>Email</th></tr>"
|
||||
|
||||
|
||||
for user in all_users:
|
||||
html_output += f"<tr><td>{user.id}</td><td>{user.username}</td><td>{user.email}</td><td>{user.password_hash}</td></tr>"
|
||||
|
||||
html_output += f"<tr><td>{user.id}</td><td>{user.username}</td><td>{user.email}</td></tr>"
|
||||
|
||||
html_output += "</table>"
|
||||
|
||||
|
||||
if not all_users:
|
||||
return "<h3>No accounts found in the database yet.</h3>"
|
||||
|
||||
|
||||
return html_output
|
||||
|
||||
|
||||
@@ -71,15 +83,36 @@ def bivariate():
|
||||
def about():
|
||||
return render_template('about.html')
|
||||
|
||||
@app.route('/signin')
|
||||
@app.route('/signin', methods=['GET', 'POST'])
|
||||
def signin():
|
||||
if request.method == 'POST':
|
||||
form_username = request.form.get('username')
|
||||
form_password = request.form.get('password')
|
||||
|
||||
user = User.query.filter_by(username=form_username).first()
|
||||
|
||||
if user is None or not check_password_hash(user.password_hash, form_password):
|
||||
flash('Incorrect username or password.')
|
||||
return render_template('signin.html'), 401
|
||||
|
||||
session['user_id'] = user.id
|
||||
session['username'] = user.username
|
||||
return redirect(url_for('home'))
|
||||
|
||||
return render_template('signin.html')
|
||||
|
||||
|
||||
@app.route('/logout')
|
||||
def logout():
|
||||
session.clear()
|
||||
return redirect(url_for('home'))
|
||||
|
||||
@app.route('/signup')
|
||||
def signup():
|
||||
return render_template('signup.html')
|
||||
|
||||
@app.route('/all_users')
|
||||
@login_required
|
||||
def all_users():
|
||||
return render_template('all_users.html')
|
||||
|
||||
|
||||
Reference in New Issue
Block a user