fix account suspension logic, aest' fixes, add ability to suspend user from admin panel, 0.4.0 feature freeze

This commit is contained in:
Yusur 2025-07-20 22:12:49 +02:00
parent e7912ad88c
commit 99b816562c
8 changed files with 58 additions and 8 deletions

View file

@ -12,8 +12,9 @@
- Moderators (and admins) have now access to mod tools - Moderators (and admins) have now access to mod tools
+ Allowed operations: change display name, description, restriction status, and exile (guild-local ban) members + Allowed operations: change display name, description, restriction status, and exile (guild-local ban) members
+ Site administrators and guild owners can add moderators + Site administrators and guild owners can add moderators
- Administrators can claim ownership of abandoned guilds
- Guilds can have restricted posting/commenting now. Unmoderated guilds always have. - Guilds can have restricted posting/commenting now. Unmoderated guilds always have.
- Administrators can claim ownership of abandoned guilds
- Admins can now suspend users from admin panel
- Implemented guild subscriptions (not as in $$$, yes as in the follow button) - Implemented guild subscriptions (not as in $$$, yes as in the follow button)
- Minimum karma requirement for creating a guild is now configurable via env variable `FREAK_CREATE_GUILD_THRESHOLD` (previously hardcoded at 15) - Minimum karma requirement for creating a guild is now configurable via env variable `FREAK_CREATE_GUILD_THRESHOLD` (previously hardcoded at 15)
- Users can now set their display name, biography and color theme in `/settings` - Users can now set their display name, biography and color theme in `/settings`

View file

@ -54,7 +54,7 @@ post_report_reasons = [
REPORT_REASON_STRINGS = { **{x.num_code: x.description for x in post_report_reasons}, **{x.code: x.description for x in post_report_reasons} } REPORT_REASON_STRINGS = { **{x.num_code: x.description for x in post_report_reasons}, **{x.code: x.description for x in post_report_reasons} }
REPORT_REASONS = {x.code: x.num_code for x in post_report_reasons} REPORT_REASONS: dict[str, int] = {x.code: x.num_code for x in post_report_reasons}
REPORT_TARGET_POST = 1 REPORT_TARGET_POST = 1
REPORT_TARGET_COMMENT = 2 REPORT_TARGET_COMMENT = 2
@ -175,7 +175,13 @@ class User(Base):
@property @property
def is_disabled(self): def is_disabled(self):
return (self.banned_at is not None and (self.banned_until is None or self.banned_until <= datetime.datetime.now())) or self.is_disabled_by_user now = datetime.datetime.now()
return (
# suspended
(self.banned_at is not None and (self.banned_until is None or self.banned_until >= now)) or
# self-disabled
self.is_disabled_by_user
)
@property @property
def is_active(self): def is_active(self):

View file

@ -310,6 +310,12 @@ button, [type="submit"], [type="reset"], [type="button"]
&[disabled] &[disabled]
opacity: .5 opacity: .5
cursor: not-allowed cursor: not-allowed
border: var(--border)
color: var(--border)
&.primary[disabled]
color: var(--background)
background-color: var(--border)
&:first-child &:first-child
margin-inline-start: 0 margin-inline-start: 0

View file

@ -2,7 +2,7 @@
{% from "macros/title.html" import title_tag with context %} {% from "macros/title.html" import title_tag with context %}
{% block title %} {% block title %}
<title>{{ title_tag('X _ X') }}</title> {{ title_tag('X _ X') }}
{% endblock %} {% endblock %}
{% block body %} {% block body %}

View file

@ -2,7 +2,7 @@
{% from "macros/title.html" import title_tag with context %} {% from "macros/title.html" import title_tag with context %}
{% block title %} {% block title %}
<title>{{ title_tag('O _ O') }}</title> {{ title_tag('O _ O') }}
{% endblock %} {% endblock %}
{% block body %} {% block body %}

View file

@ -2,7 +2,7 @@
{% from "macros/title.html" import title_tag with context %} {% from "macros/title.html" import title_tag with context %}
{% block title %} {% block title %}
<title>{{ title_tag('O _ O') }}</title> {{ title_tag('O _ O') }}
{% endblock %} {% endblock %}
{% block body %} {% block body %}

View file

@ -24,7 +24,23 @@
{% endif %} {% endif %}
<!-- quick actions --> <!-- quick actions -->
<h3>Quick Actions</h3>
<form method="POST"> <form method="POST">
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}" />
<select name="reason">
<option selected value="0">(Select a reason)</option>
<option value="100">Multiple violations</option>
{% for k, v in report_reasons.items() %}
<option value="{{ k }}">{{ v }}</option>
{% endfor %}
</select>
<br />
{% if u.banned_at %}
<button type="submit" name="do" value="unsuspend">Remove suspension</button>
{% else %}
<button type="submit" name="do" value="suspend">Suspend</button>
<button type="submit" name="do" value="to_3d">Time-out (3 days)</button>
{% endif %}
</form> </form>
<h3>Strikes</h3> <h3>Strikes</h3>

View file

@ -10,10 +10,12 @@ from markupsafe import Markup
from sqlalchemy import insert, select, update from sqlalchemy import insert, select, update
from suou import additem, not_implemented from suou import additem, not_implemented
from ..models import REPORT_REASON_STRINGS, REPORT_TARGET_COMMENT, REPORT_TARGET_POST, REPORT_UPDATE_COMPLETE, REPORT_UPDATE_ON_HOLD, REPORT_UPDATE_REJECTED, Comment, Post, PostReport, User, UserStrike, db from ..models import REPORT_REASON_STRINGS, REPORT_REASONS, REPORT_TARGET_COMMENT, REPORT_TARGET_POST, REPORT_UPDATE_COMPLETE, REPORT_UPDATE_ON_HOLD, REPORT_UPDATE_REJECTED, Comment, Post, PostReport, User, UserStrike, db
bp = Blueprint('admin', __name__) bp = Blueprint('admin', __name__)
current_user: User
## TODO make admin interface ## TODO make admin interface
def admin_required(func: Callable): def admin_required(func: Callable):
@ -191,7 +193,26 @@ def user_detail(id: int):
if u is None: if u is None:
abort(404) abort(404)
if request.method == 'POST': if request.method == 'POST':
abort(501) action = request.form['do']
if action == 'suspend':
u.banned_at = datetime.datetime.now()
u.banned_by_id = current_user.id
u.banned_reason = REPORT_REASONS.get(request.form.get('reason'), 0)
db.session.commit()
elif action == 'unsuspend':
u.banned_at = None
u.banned_by_id = None
u.banned_until = None
u.banned_reason = None
db.session.commit()
elif action == 'to_3d':
u.banned_at = datetime.datetime.now()
u.banned_until = datetime.datetime.now() + datetime.timedelta(days=3)
u.banned_by_id = current_user.id
u.banned_reason = REPORT_REASONS.get(request.form.get('reason'), 0)
db.session.commit()
else:
abort(400)
strikes = db.session.execute(select(UserStrike).where(UserStrike.user_id == id).order_by(UserStrike.id.desc())).scalars() strikes = db.session.execute(select(UserStrike).where(UserStrike.user_id == id).order_by(UserStrike.id.desc())).scalars()
return render_template('admin/admin_user_detail.html', u=u, return render_template('admin/admin_user_detail.html', u=u,
report_reasons=REPORT_REASON_STRINGS, account_status_string=colorized_account_status_string, strikes=strikes) report_reasons=REPORT_REASON_STRINGS, account_status_string=colorized_account_status_string, strikes=strikes)