Rietveld Code Review Tool
Help | Bug tracker | Discussion group | Source code

Delta Between Two Patch Sets: sitescripts/submit_email/web/submit_email.py

Issue 5177883412660224: Issue 2234 - Add a WSGI controller to collect email addresses for the Adblock Browser iOS launch (Closed)
Left Patch Set: Moved signing logic into submit_email module Created April 23, 2015, 4:29 p.m.
Right Patch Set: URL-encode language before inserting into URL Created April 28, 2015, 10:50 a.m.
Left:
Right:
Use n/p to move between diff chunks; N/P to move between comments.
Jump to:
Left: Side by side diff | Download
Right: Side by side diff | Download
« no previous file with change/comment | « sitescripts/submit_email/web/__init__.py ('k') | sitescripts/utils.py » ('j') | no next file with change/comment »
Toggle Intra-line Diffs ('i') | Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
LEFTRIGHT
1 # coding: utf-8 1 # coding: utf-8
2 2
3 # This file is part of the Adblock Plus web scripts, 3 # This file is part of the Adblock Plus web scripts,
4 # Copyright (C) 2006-2015 Eyeo GmbH 4 # Copyright (C) 2006-2015 Eyeo GmbH
5 # 5 #
6 # Adblock Plus is free software: you can redistribute it and/or modify 6 # Adblock Plus is free software: you can redistribute it and/or modify
7 # it under the terms of the GNU General Public License version 3 as 7 # it under the terms of the GNU General Public License version 3 as
8 # published by the Free Software Foundation. 8 # published by the Free Software Foundation.
9 # 9 #
10 # Adblock Plus is distributed in the hope that it will be useful, 10 # Adblock Plus is distributed in the hope that it will be useful,
11 # but WITHOUT ANY WARRANTY; without even the implied warranty of 11 # but WITHOUT ANY WARRANTY; without even the implied warranty of
12 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 12 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 # GNU General Public License for more details. 13 # GNU General Public License for more details.
14 # 14 #
15 # You should have received a copy of the GNU General Public License 15 # You should have received a copy of the GNU General Public License
16 # along with Adblock Plus. If not, see <http://www.gnu.org/licenses/>. 16 # along with Adblock Plus. If not, see <http://www.gnu.org/licenses/>.
17 17
18 import fcntl 18 import fcntl
19 import hmac 19 import hmac
20 import hashlib 20 import hashlib
21 import wsgiref.util 21 import wsgiref.util
22 from urlparse import parse_qs, urljoin 22 from urlparse import parse_qsl, urljoin
23 from urllib import urlencode 23 from urllib import urlencode, quote
24 24
25 from sitescripts.utils import get_config, sendMail, encode_email_address 25 from sitescripts.utils import get_config, sendMail, encode_email_address
26 from sitescripts.web import url_handler, form_handler 26 from sitescripts.web import url_handler, form_handler, send_simple_response
27 27
28 VERIFICATION_PATH = '/verifyEmail' 28 VERIFICATION_PATH = '/verifyEmail'
29 29
30 def sign(config, data): 30 def sign(config, data):
31 secret = config.get('submit_email', 'secret') 31 secret = config.get('submit_email', 'secret')
32 return hmac.new(secret, data, hashlib.sha1).hexdigest() 32 return hmac.new(secret, data, hashlib.sha1).hexdigest()
33 33
34 @url_handler('/submitEmail') 34 @url_handler('/submitEmail')
35 @form_handler 35 @form_handler
36 def submit_email(environ, start_response, data): 36 def submit_email(environ, start_response, data):
37 email = data.get('email', '').strip() 37 email = data.get('email', '').strip()
38 try: 38 try:
39 email = encode_email_address(email) 39 email = encode_email_address(email)
40 except ValueError: 40 except ValueError:
41 start_response('400 Bad Request', [('Content-Type', 'text/plain')]) 41 return send_simple_response(
42 return ['No valid email address given.'] 42 start_response, 400,
43 'Please enter a valid email address.'
44 )
43 45
44 config = get_config() 46 config = get_config()
47 params = [('email', email), ('signature', sign(config, email))]
48 lang = data.get('lang')
49 if lang:
50 params.append(('lang', lang))
51
45 sendMail( 52 sendMail(
46 config.get('submit_email', 'verification_email_template'), 53 config.get('submit_email', 'verification_email_template'),
47 { 54 {
48 'recipient': email, 55 'recipient': email,
49 'verification_url': '%s?%s' % ( 56 'verification_url': '%s?%s' % (
50 urljoin(wsgiref.util.application_uri(environ), VERIFICATION_PATH), 57 urljoin(wsgiref.util.application_uri(environ), VERIFICATION_PATH),
51 urlencode([('email', email), ('signature', sign(config, email))]) 58 urlencode(params)
52 ) 59 )
53 } 60 }
54 ) 61 )
55 62
56 start_response('200 OK', [('Content-Type', 'text/plain')]) 63 return send_simple_response(
57 return ["Thanks for your submission! You'll receive a verification email short ly."] 64 start_response, 200,
65 'A confirmation email has been sent. Please check '
66 'your email and click the confirmation link.'
67 )
58 68
59 @url_handler(VERIFICATION_PATH) 69 @url_handler(VERIFICATION_PATH)
60 def verify_email(environ, start_response): 70 def verify_email(environ, start_response):
61 config = get_config() 71 config = get_config()
72 params = dict(parse_qsl(environ.get('QUERY_STRING', '')))
62 73
63 params = parse_qs(environ.get('QUERY_STRING', '')) 74 email = params.get('email', '')
64 email = params.get('email', [''])[0] 75 signature = params.get('signature', '')
65 signature = params.get('signature', [''])[0] 76 if sign(config, email) != signature:
77 return send_simple_response(
78 start_response, 403,
79 'Invalid signature in verification request.'
80 )
66 81
67 if sign(config, email) == signature: 82 filename = config.get('submit_email', 'filename')
68 filename = config.get('submit_email', 'filename') 83 with open(filename, 'ab', 0) as file:
69 with open(filename, 'ab', 0) as file: 84 fcntl.lockf(file, fcntl.LOCK_EX)
70 fcntl.lockf(file, fcntl.LOCK_EX) 85 try:
71 try: 86 print >>file, email
72 print >>file, email 87 finally:
73 finally: 88 fcntl.lockf(file, fcntl.LOCK_UN)
74 fcntl.lockf(file, fcntl.LOCK_UN)
75 89
76 option = 'successful_verification_redirect_location' 90 location = config.get('submit_email', 'successful_verification_redirect_locati on')
77 else: 91 location = location.format(lang=quote(params.get('lang') or 'en', ''))
kzar 2015/04/28 11:13:42 Looks like a typo at the end there? ", ''"
Sebastian Noack 2015/04/28 11:31:25 The empty string at the end is the second argument
kzar 2015/04/28 11:33:41 Oh I see.
Sebastian Noack 2015/04/28 11:36:04 I meant (forward) slashes.
78 option = 'failed_verification_redirect_location' 92 start_response('303 See Other', [('Location', location)])
79
80 start_response('303 See Other', [('Location', config.get('submit_email', optio n))])
81 return [] 93 return []
LEFTRIGHT

Powered by Google App Engine
This is Rietveld