Rietveld Code Review Tool
Help | Bug tracker | Discussion group | Source code

Delta Between Two Patch Sets: sitescripts/submit_email/web/submit_email.py

Issue 5177883412660224: Issue 2234 - Add a WSGI controller to collect email addresses for the Adblock Browser iOS launch (Closed)
Left Patch Set: Refactored Created April 24, 2015, 2:16 p.m.
Right Patch Set: URL-encode language before inserting into URL Created April 28, 2015, 10:50 a.m.
Left:
Right:
Use n/p to move between diff chunks; N/P to move between comments.
Jump to:
Left: Side by side diff | Download
Right: Side by side diff | Download
« no previous file with change/comment | « sitescripts/submit_email/web/__init__.py ('k') | sitescripts/utils.py » ('j') | no next file with change/comment »
Toggle Intra-line Diffs ('i') | Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
LEFTRIGHT
1 # coding: utf-8 1 # coding: utf-8
2 2
3 # This file is part of the Adblock Plus web scripts, 3 # This file is part of the Adblock Plus web scripts,
4 # Copyright (C) 2006-2015 Eyeo GmbH 4 # Copyright (C) 2006-2015 Eyeo GmbH
5 # 5 #
6 # Adblock Plus is free software: you can redistribute it and/or modify 6 # Adblock Plus is free software: you can redistribute it and/or modify
7 # it under the terms of the GNU General Public License version 3 as 7 # it under the terms of the GNU General Public License version 3 as
8 # published by the Free Software Foundation. 8 # published by the Free Software Foundation.
9 # 9 #
10 # Adblock Plus is distributed in the hope that it will be useful, 10 # Adblock Plus is distributed in the hope that it will be useful,
11 # but WITHOUT ANY WARRANTY; without even the implied warranty of 11 # but WITHOUT ANY WARRANTY; without even the implied warranty of
12 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 12 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 # GNU General Public License for more details. 13 # GNU General Public License for more details.
14 # 14 #
15 # You should have received a copy of the GNU General Public License 15 # You should have received a copy of the GNU General Public License
16 # along with Adblock Plus. If not, see <http://www.gnu.org/licenses/>. 16 # along with Adblock Plus. If not, see <http://www.gnu.org/licenses/>.
17 17
18 import fcntl 18 import fcntl
19 import hmac 19 import hmac
20 import hashlib 20 import hashlib
21 import wsgiref.util 21 import wsgiref.util
22 from urlparse import parse_qs, urljoin 22 from urlparse import parse_qsl, urljoin
23 from urllib import urlencode 23 from urllib import urlencode, quote
24 24
25 from sitescripts.utils import get_config, sendMail, encode_email_address 25 from sitescripts.utils import get_config, sendMail, encode_email_address
26 from sitescripts.web import url_handler, form_handler, send_simple_response 26 from sitescripts.web import url_handler, form_handler, send_simple_response
27 27
28 VERIFICATION_PATH = '/verifyEmail' 28 VERIFICATION_PATH = '/verifyEmail'
29 29
30 def sign(config, data): 30 def sign(config, data):
31 secret = config.get('submit_email', 'secret') 31 secret = config.get('submit_email', 'secret')
32 return hmac.new(secret, data, hashlib.sha1).hexdigest() 32 return hmac.new(secret, data, hashlib.sha1).hexdigest()
33 33
34 @url_handler('/submitEmail') 34 @url_handler('/submitEmail')
35 @form_handler 35 @form_handler
36 def submit_email(environ, start_response, data): 36 def submit_email(environ, start_response, data):
37 email = data.get('email', '').strip() 37 email = data.get('email', '').strip()
38 try: 38 try:
39 email = encode_email_address(email) 39 email = encode_email_address(email)
40 except ValueError: 40 except ValueError:
41 return send_simple_response(start_response, 400, 'Please enter a valid email address.') 41 return send_simple_response(
Wladimir Palant 2015/04/24 22:50:48 Nit: Move the last parameter to the next line?
42 start_response, 400,
43 'Please enter a valid email address.'
44 )
42 45
43 config = get_config() 46 config = get_config()
47 params = [('email', email), ('signature', sign(config, email))]
48 lang = data.get('lang')
49 if lang:
50 params.append(('lang', lang))
51
44 sendMail( 52 sendMail(
45 config.get('submit_email', 'verification_email_template'), 53 config.get('submit_email', 'verification_email_template'),
46 { 54 {
47 'recipient': email, 55 'recipient': email,
48 'verification_url': '%s?%s' % ( 56 'verification_url': '%s?%s' % (
49 urljoin(wsgiref.util.application_uri(environ), VERIFICATION_PATH), 57 urljoin(wsgiref.util.application_uri(environ), VERIFICATION_PATH),
50 urlencode([('email', email), ('signature', sign(config, email))]) 58 urlencode(params)
51 ) 59 )
52 } 60 }
53 ) 61 )
54 62
55 return send_simple_response(start_response, 200, 'A confirmation email has ' 63 return send_simple_response(
56 'been sent. Please check ' 64 start_response, 200,
57 'your email and click the ' 65 'A confirmation email has been sent. Please check '
58 'confirmation link.') 66 'your email and click the confirmation link.'
Wladimir Palant 2015/04/24 22:50:48 Nit: Move the last parameter to the next line and
Sebastian Noack 2015/04/27 13:39:10 I actually like it as it is. I certainly dislike s
67 )
59 68
60 @url_handler(VERIFICATION_PATH) 69 @url_handler(VERIFICATION_PATH)
61 def verify_email(environ, start_response): 70 def verify_email(environ, start_response):
62 config = get_config() 71 config = get_config()
72 params = dict(parse_qsl(environ.get('QUERY_STRING', '')))
63 73
64 params = parse_qs(environ.get('QUERY_STRING', '')) 74 email = params.get('email', '')
65 email = params.get('email', [''])[0] 75 signature = params.get('signature', '')
66 signature = params.get('signature', [''])[0]
67
68 if sign(config, email) != signature: 76 if sign(config, email) != signature:
69 return send_simple_response(start_response, 403, 'Invalid signature in ' 77 return send_simple_response(
70 'verification request.') 78 start_response, 403,
79 'Invalid signature in verification request.'
80 )
71 81
72 filename = config.get('submit_email', 'filename') 82 filename = config.get('submit_email', 'filename')
73 with open(filename, 'ab', 0) as file: 83 with open(filename, 'ab', 0) as file:
74 fcntl.lockf(file, fcntl.LOCK_EX) 84 fcntl.lockf(file, fcntl.LOCK_EX)
75 try: 85 try:
76 print >>file, email 86 print >>file, email
77 finally: 87 finally:
78 fcntl.lockf(file, fcntl.LOCK_UN) 88 fcntl.lockf(file, fcntl.LOCK_UN)
79 89
80 location = config.get('submit_email', 'successful_verification_redirect_locati on') 90 location = config.get('submit_email', 'successful_verification_redirect_locati on')
91 location = location.format(lang=quote(params.get('lang') or 'en', ''))
kzar 2015/04/28 11:13:42 Looks like a typo at the end there? ", ''"
Sebastian Noack 2015/04/28 11:31:25 The empty string at the end is the second argument
kzar 2015/04/28 11:33:41 Oh I see.
Sebastian Noack 2015/04/28 11:36:04 I meant (forward) slashes.
81 start_response('303 See Other', [('Location', location)]) 92 start_response('303 See Other', [('Location', location)])
82 return [] 93 return []
LEFTRIGHT

Powered by Google App Engine
This is Rietveld