views.py 44 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280
  1. from django.shortcuts import render
  2. from django.http import HttpResponseRedirect
  3. from django.conf import settings
  4. from django.shortcuts import get_object_or_404
  5. from django.db.models import Q
  6. from django.contrib.auth.decorators import login_required
  7. from django.contrib import messages
  8. from django.template.defaultfilters import slugify
  9. from django.core.mail import EmailMessage
  10. from django.contrib.postgres.search import SearchQuery
  11. from rest_framework import permissions
  12. from rest_framework.views import APIView
  13. from rest_framework.response import Response
  14. from rest_framework.settings import api_settings
  15. from rest_framework.exceptions import PermissionDenied
  16. from rest_framework import status
  17. from rest_framework.parsers import (
  18. JSONParser,
  19. MultiPartParser,
  20. FileUploadParser,
  21. FormParser,
  22. )
  23. from celery.task.control import revoke
  24. from cms.permissions import IsAuthorizedToAdd, IsUserOrEditor
  25. from cms.permissions import user_allowed_to_upload
  26. from cms.custom_pagination import FastPaginationWithoutCount
  27. from actions.models import MediaAction, USER_MEDIA_ACTIONS
  28. from users.models import User
  29. from .helpers import produce_ffmpeg_commands, clean_query
  30. from .models import (
  31. Media,
  32. EncodeProfile,
  33. Encoding,
  34. Playlist,
  35. PlaylistMedia,
  36. Comment,
  37. Category,
  38. Tag,
  39. )
  40. from .forms import MediaForm, ContactForm, SubtitleForm
  41. from .tasks import save_user_action
  42. from .methods import (
  43. list_tasks,
  44. get_user_or_session,
  45. show_recommended_media,
  46. show_related_media,
  47. is_mediacms_editor,
  48. is_mediacms_manager,
  49. update_user_ratings,
  50. notify_user_on_comment,
  51. )
  52. from .serializers import (
  53. MediaSerializer,
  54. CategorySerializer,
  55. TagSerializer,
  56. SingleMediaSerializer,
  57. EncodeProfileSerializer,
  58. MediaSearchSerializer,
  59. PlaylistSerializer,
  60. PlaylistDetailSerializer,
  61. CommentSerializer,
  62. )
  63. from .stop_words import STOP_WORDS
  64. VALID_USER_ACTIONS = [action for action, name in USER_MEDIA_ACTIONS]
  65. def about(request):
  66. """About view"""
  67. context = {}
  68. return render(request, "cms/about.html", context)
  69. @login_required
  70. def add_subtitle(request):
  71. """Add subtitle view"""
  72. friendly_token = request.GET.get("m", "").strip()
  73. if not friendly_token:
  74. return HttpResponseRedirect("/")
  75. media = Media.objects.filter(friendly_token=friendly_token).first()
  76. if not media:
  77. return HttpResponseRedirect("/")
  78. if not (
  79. request.user == media.user
  80. or is_mediacms_editor(request.user)
  81. or is_mediacms_manager(request.user)
  82. ):
  83. return HttpResponseRedirect("/")
  84. if request.method == "POST":
  85. form = SubtitleForm(media, request.POST, request.FILES)
  86. if form.is_valid():
  87. subtitle = form.save()
  88. messages.add_message(request, messages.INFO, "Subtitle was added!")
  89. return HttpResponseRedirect(subtitle.media.get_absolute_url())
  90. else:
  91. form = SubtitleForm(media_item=media)
  92. return render(request, "cms/add_subtitle.html", {"form": form})
  93. def categories(request):
  94. """List categories view"""
  95. context = {}
  96. return render(request, "cms/categories.html", context)
  97. def contact(request):
  98. """Contact view"""
  99. context = {}
  100. if request.method == "GET":
  101. form = ContactForm(request.user)
  102. context["form"] = form
  103. else:
  104. form = ContactForm(request.user, request.POST)
  105. if form.is_valid():
  106. if request.user.is_authenticated:
  107. from_email = request.user.email
  108. name = request.user.name
  109. else:
  110. from_email = request.POST.get("from_email")
  111. name = request.POST.get("name")
  112. message = request.POST.get("message")
  113. title = "[{}] - Contact form message received".format(settings.PORTAL_NAME)
  114. msg = """
  115. You have received a message through the contact form\n
  116. Sender name: %s
  117. Sender email: %s\n
  118. \n %s
  119. """ % (
  120. name,
  121. from_email,
  122. message,
  123. )
  124. email = EmailMessage(
  125. title,
  126. msg,
  127. settings.DEFAULT_FROM_EMAIL,
  128. settings.ADMIN_EMAIL_LIST,
  129. reply_to=[from_email],
  130. )
  131. email.send(fail_silently=True)
  132. success_msg = "Message was sent! Thanks for contacting"
  133. context["success_msg"] = success_msg
  134. return render(request, "cms/contact.html", context)
  135. def history(request):
  136. """Show personal history view"""
  137. context = {}
  138. return render(request, "cms/history.html", context)
  139. @login_required
  140. def edit_media(request):
  141. """Edit a media view"""
  142. friendly_token = request.GET.get("m", "").strip()
  143. if not friendly_token:
  144. return HttpResponseRedirect("/")
  145. media = Media.objects.filter(friendly_token=friendly_token).first()
  146. if not media:
  147. return HttpResponseRedirect("/")
  148. if not (
  149. request.user == media.user
  150. or is_mediacms_editor(request.user)
  151. or is_mediacms_manager(request.user)
  152. ):
  153. return HttpResponseRedirect("/")
  154. if request.method == "POST":
  155. form = MediaForm(request.user, request.POST, request.FILES, instance=media)
  156. if form.is_valid():
  157. media = form.save()
  158. for tag in media.tags.all():
  159. media.tags.remove(tag)
  160. if form.cleaned_data.get("new_tags"):
  161. for tag in form.cleaned_data.get("new_tags").split(","):
  162. tag = slugify(tag)
  163. if tag:
  164. try:
  165. tag = Tag.objects.get(title=tag)
  166. except Tag.DoesNotExist:
  167. tag = Tag.objects.create(title=tag, user=request.user)
  168. if tag not in media.tags.all():
  169. media.tags.add(tag)
  170. messages.add_message(request, messages.INFO, "Media was edited!")
  171. return HttpResponseRedirect(media.get_absolute_url())
  172. else:
  173. form = MediaForm(request.user, instance=media)
  174. return render(
  175. request,
  176. "cms/edit_media.html",
  177. {"form": form, "add_subtitle_url": media.add_subtitle_url},
  178. )
  179. def embed_media(request):
  180. """Embed media view"""
  181. friendly_token = request.GET.get("m", "").strip()
  182. if not friendly_token:
  183. return HttpResponseRedirect("/")
  184. media = Media.objects.values("title").filter(friendly_token=friendly_token).first()
  185. if not media:
  186. return HttpResponseRedirect("/")
  187. user_or_session = get_user_or_session(request)
  188. context = {}
  189. context["media"] = friendly_token
  190. return render(request, "cms/embed.html", context)
  191. def featured_media(request):
  192. """List featured media view"""
  193. context = {}
  194. return render(request, "cms/featured-media.html", context)
  195. def index(request):
  196. """Index view"""
  197. context = {}
  198. return render(request, "cms/index.html", context)
  199. def latest_media(request):
  200. """List latest media view"""
  201. context = {}
  202. return render(request, "cms/latest-media.html", context)
  203. def liked_media(request):
  204. """List user's liked media view"""
  205. context = {}
  206. return render(request, "cms/liked_media.html", context)
  207. @login_required
  208. def manage_users(request):
  209. """List users management view"""
  210. context = {}
  211. return render(request, "cms/manage_users.html", context)
  212. @login_required
  213. def manage_media(request):
  214. """List media management view"""
  215. context = {}
  216. return render(request, "cms/manage_media.html", context)
  217. @login_required
  218. def manage_comments(request):
  219. """List comments management view"""
  220. context = {}
  221. return render(request, "cms/manage_comments.html", context)
  222. def members(request):
  223. """List members view"""
  224. context = {}
  225. return render(request, "cms/members.html", context)
  226. def recommended_media(request):
  227. """List recommended media view"""
  228. context = {}
  229. return render(request, "cms/recommended-media.html", context)
  230. def search(request):
  231. """Search view"""
  232. context = {}
  233. RSS_URL = f"/rss{request.environ['REQUEST_URI']}"
  234. context["RSS_URL"] = RSS_URL
  235. return render(request, "cms/search.html", context)
  236. def tags(request):
  237. """List tags view"""
  238. context = {}
  239. return render(request, "cms/tags.html", context)
  240. def tos(request):
  241. """Terms of service view"""
  242. context = {}
  243. return render(request, "cms/tos.html", context)
  244. def upload_media(request):
  245. """Upload media view"""
  246. from allauth.account.forms import LoginForm
  247. form = LoginForm()
  248. context = {}
  249. context["form"] = form
  250. context["can_add"] = user_allowed_to_upload(request)
  251. can_upload_exp = settings.CANNOT_ADD_MEDIA_MESSAGE
  252. context["can_upload_exp"] = can_upload_exp
  253. return render(request, "cms/add-media.html", context)
  254. def view_media(request):
  255. """View media view"""
  256. friendly_token = request.GET.get("m", "").strip()
  257. context = {}
  258. media = Media.objects.filter(friendly_token=friendly_token).first()
  259. if not media:
  260. context["media"] = None
  261. return render(request, "cms/media.html", context)
  262. user_or_session = get_user_or_session(request)
  263. save_user_action.delay(
  264. user_or_session, friendly_token=friendly_token, action="watch"
  265. )
  266. context = {}
  267. context["media"] = friendly_token
  268. context["media_object"] = media
  269. context["CAN_DELETE_MEDIA"] = False
  270. context["CAN_EDIT_MEDIA"] = False
  271. context["CAN_DELETE_COMMENTS"] = False
  272. if request.user.is_authenticated:
  273. if (
  274. (media.user.id == request.user.id)
  275. or is_mediacms_editor(request.user)
  276. or is_mediacms_manager(request.user)
  277. ):
  278. context["CAN_DELETE_MEDIA"] = True
  279. context["CAN_EDIT_MEDIA"] = True
  280. context["CAN_DELETE_COMMENTS"] = True
  281. return render(request, "cms/media.html", context)
  282. def view_playlist(request, friendly_token):
  283. """View playlist view"""
  284. try:
  285. playlist = Playlist.objects.get(friendly_token=friendly_token)
  286. except BaseException:
  287. playlist = None
  288. context = {}
  289. context["playlist"] = playlist
  290. return render(request, "cms/playlist.html", context)
  291. class MediaList(APIView):
  292. """Media listings views"""
  293. permission_classes = (IsAuthorizedToAdd,)
  294. parser_classes = (JSONParser, MultiPartParser, FormParser, FileUploadParser)
  295. def get(self, request, format=None):
  296. # Show media
  297. params = self.request.query_params
  298. show_param = params.get("show", "")
  299. author_param = params.get("author", "").strip()
  300. if author_param:
  301. user_queryset = User.objects.all()
  302. user = get_object_or_404(user_queryset, username=author_param)
  303. if show_param == "recommended":
  304. pagination_class = FastPaginationWithoutCount
  305. media = show_recommended_media(request, limit=50)
  306. else:
  307. pagination_class = api_settings.DEFAULT_PAGINATION_CLASS
  308. if author_param:
  309. # in case request.user is the user here, show
  310. # all media independant of state
  311. if self.request.user == user:
  312. basic_query = Q(user=user)
  313. else:
  314. basic_query = Q(listable=True, user=user)
  315. else:
  316. # base listings should show safe content
  317. basic_query = Q(listable=True)
  318. if show_param == "featured":
  319. media = Media.objects.filter(basic_query, featured=True)
  320. else:
  321. media = Media.objects.filter(basic_query).order_by("-add_date")
  322. paginator = pagination_class()
  323. if show_param != "recommended":
  324. media = media.prefetch_related("user")
  325. page = paginator.paginate_queryset(media, request)
  326. serializer = MediaSerializer(page, many=True, context={"request": request})
  327. return paginator.get_paginated_response(serializer.data)
  328. def post(self, request, format=None):
  329. # Add new media
  330. serializer = MediaSerializer(data=request.data, context={"request": request})
  331. if serializer.is_valid():
  332. media_file = request.data["media_file"]
  333. serializer.save(user=request.user, media_file=media_file)
  334. return Response(serializer.data, status=status.HTTP_201_CREATED)
  335. return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
  336. class MediaDetail(APIView):
  337. """
  338. Retrieve, update or delete a media instance.
  339. """
  340. permission_classes = (permissions.IsAuthenticatedOrReadOnly, IsUserOrEditor)
  341. parser_classes = (JSONParser, MultiPartParser, FormParser, FileUploadParser)
  342. def get_object(self, friendly_token, password=None):
  343. try:
  344. media = (
  345. Media.objects.select_related("user")
  346. .prefetch_related("encodings__profile")
  347. .get(friendly_token=friendly_token)
  348. )
  349. # this need be explicitly called, and will call
  350. # has_object_permission() after has_permission has succeeded
  351. self.check_object_permissions(self.request, media)
  352. if media.state == "private" and not (
  353. self.request.user == media.user or is_mediacms_editor(self.request.user)
  354. ):
  355. if (
  356. (not password)
  357. or (not media.password)
  358. or (password != media.password)
  359. ):
  360. return Response(
  361. {"detail": "media is private"},
  362. status=status.HTTP_401_UNAUTHORIZED,
  363. )
  364. return media
  365. except PermissionDenied:
  366. return Response(
  367. {"detail": "bad permissions"}, status=status.HTTP_401_UNAUTHORIZED
  368. )
  369. except BaseException:
  370. return Response(
  371. {"detail": "media file does not exist"},
  372. status=status.HTTP_400_BAD_REQUEST,
  373. )
  374. def get(self, request, friendly_token, format=None):
  375. # Get media details
  376. password = request.GET.get("password")
  377. media = self.get_object(friendly_token, password=password)
  378. if isinstance(media, Response):
  379. return media
  380. serializer = SingleMediaSerializer(media, context={"request": request})
  381. if media.state == "private":
  382. related_media = []
  383. else:
  384. related_media = show_related_media(media, request=request, limit=100)
  385. related_media_serializer = MediaSerializer(
  386. related_media, many=True, context={"request": request}
  387. )
  388. related_media = related_media_serializer.data
  389. ret = serializer.data
  390. # update rattings info with user specific ratings
  391. # eg user has already rated for this media
  392. # this only affects user rating and only if enabled
  393. if (
  394. settings.ALLOW_RATINGS
  395. and ret.get("ratings_info")
  396. and not request.user.is_anonymous
  397. ):
  398. ret["ratings_info"] = update_user_ratings(
  399. request.user, media, ret.get("ratings_info")
  400. )
  401. ret["related_media"] = related_media
  402. return Response(ret)
  403. def post(self, request, friendly_token, format=None):
  404. """superuser actions
  405. Available only to MediaCMS editors and managers
  406. Action is a POST variable, review and encode are implemented
  407. """
  408. media = self.get_object(friendly_token)
  409. if isinstance(media, Response):
  410. return media
  411. if not (is_mediacms_editor(request.user) or is_mediacms_manager(request.user)):
  412. return Response(
  413. {"detail": "not allowed"}, status=status.HTTP_400_BAD_REQUEST
  414. )
  415. action = request.data.get("type")
  416. profiles_list = request.data.get("encoding_profiles")
  417. result = request.data.get("result", True)
  418. if action == "encode":
  419. # Create encoding tasks for specific profiles
  420. valid_profiles = []
  421. if profiles_list:
  422. if isinstance(profiles_list, list):
  423. for p in profiles_list:
  424. p = EncodeProfile.objects.filter(id=p).first()
  425. if p:
  426. valid_profiles.append(p)
  427. elif isinstance(profiles_list, str):
  428. try:
  429. p = EncodeProfile.objects.filter(id=int(profiles_list)).first()
  430. valid_profiles.append(p)
  431. except ValueError:
  432. return Response(
  433. {
  434. "detail": "encoding_profiles must be int or list of ints of valid encode profiles"
  435. },
  436. status=status.HTTP_400_BAD_REQUEST,
  437. )
  438. media.encode(profiles=valid_profiles)
  439. return Response(
  440. {"detail": "media will be encoded"}, status=status.HTTP_201_CREATED
  441. )
  442. elif action == "review":
  443. if result:
  444. media.is_reviewed = True
  445. elif result == False:
  446. media.is_reviewed = False
  447. media.save(update_fields=["is_reviewed"])
  448. return Response(
  449. {"detail": "media reviewed set"}, status=status.HTTP_201_CREATED
  450. )
  451. return Response(
  452. {"detail": "not valid action or no action specified"},
  453. status=status.HTTP_400_BAD_REQUEST,
  454. )
  455. def put(self, request, friendly_token, format=None):
  456. # Update a media object
  457. media = self.get_object(friendly_token)
  458. if isinstance(media, Response):
  459. return media
  460. serializer = MediaSerializer(
  461. media, data=request.data, context={"request": request}
  462. )
  463. if serializer.is_valid():
  464. media_file = request.data["media_file"]
  465. serializer.save(user=request.user, media_file=media_file)
  466. return Response(serializer.data, status=status.HTTP_201_CREATED)
  467. return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
  468. def delete(self, request, friendly_token, format=None):
  469. # Delete a media object
  470. media = self.get_object(friendly_token)
  471. if isinstance(media, Response):
  472. return media
  473. media.delete()
  474. return Response(status=status.HTTP_204_NO_CONTENT)
  475. class MediaActions(APIView):
  476. """
  477. Retrieve, update or delete a media action instance.
  478. """
  479. permission_classes = (permissions.AllowAny,)
  480. parser_classes = (JSONParser,)
  481. def get_object(self, friendly_token):
  482. try:
  483. media = (
  484. Media.objects.select_related("user")
  485. .prefetch_related("encodings__profile")
  486. .get(friendly_token=friendly_token)
  487. )
  488. if media.state == "private" and self.request.user != media.user:
  489. return Response(
  490. {"detail": "media is private"}, status=status.HTTP_400_BAD_REQUEST
  491. )
  492. return media
  493. except PermissionDenied:
  494. return Response(
  495. {"detail": "bad permissions"}, status=status.HTTP_400_BAD_REQUEST
  496. )
  497. except BaseException:
  498. return Response(
  499. {"detail": "media file does not exist"},
  500. status=status.HTTP_400_BAD_REQUEST,
  501. )
  502. def get(self, request, friendly_token, format=None):
  503. # show date and reason for each time media was reported
  504. media = self.get_object(friendly_token)
  505. if isinstance(media, Response):
  506. return media
  507. ret = {}
  508. reported = MediaAction.objects.filter(media=media, action="report")
  509. ret["reported"] = []
  510. for rep in reported:
  511. item = {"reported_date": rep.action_date, "reason": rep.extra_info}
  512. ret["reported"].append(item)
  513. return Response(ret, status=status.HTTP_200_OK)
  514. def post(self, request, friendly_token, format=None):
  515. # perform like/dislike/report actions
  516. media = self.get_object(friendly_token)
  517. if isinstance(media, Response):
  518. return media
  519. action = request.data.get("type")
  520. extra = request.data.get("extra_info")
  521. if request.user.is_anonymous:
  522. # there is a list of allowed actions for
  523. # anonymous users, specified in settings
  524. if action not in settings.ALLOW_ANONYMOUS_ACTIONS:
  525. return Response(
  526. {"detail": "action allowed on logged in users only"},
  527. status=status.HTTP_400_BAD_REQUEST,
  528. )
  529. if action:
  530. user_or_session = get_user_or_session(request)
  531. save_user_action.delay(
  532. user_or_session,
  533. friendly_token=media.friendly_token,
  534. action=action,
  535. extra_info=extra,
  536. )
  537. return Response(
  538. {"detail": "action received"}, status=status.HTTP_201_CREATED
  539. )
  540. else:
  541. return Response(
  542. {"detail": "no action specified"}, status=status.HTTP_400_BAD_REQUEST
  543. )
  544. def delete(self, request, friendly_token, format=None):
  545. media = self.get_object(friendly_token)
  546. if isinstance(media, Response):
  547. return media
  548. if not request.user.is_superuser:
  549. return Response(
  550. {"detail": "not allowed"}, status=status.HTTP_400_BAD_REQUEST
  551. )
  552. action = request.data.get("type")
  553. if action:
  554. if action == "report": # delete reported actions
  555. MediaAction.objects.filter(media=media, action="report").delete()
  556. media.reported_times = 0
  557. media.save(update_fields=["reported_times"])
  558. return Response(
  559. {"detail": "reset reported times counter"},
  560. status=status.HTTP_201_CREATED,
  561. )
  562. else:
  563. return Response(
  564. {"detail": "no action specified"}, status=status.HTTP_400_BAD_REQUEST
  565. )
  566. class MediaSearch(APIView):
  567. """
  568. Retrieve results for searc
  569. Only GET is implemented here
  570. """
  571. parser_classes = (JSONParser,)
  572. def get(self, request, format=None):
  573. params = self.request.query_params
  574. query = params.get("q", "").strip().lower()
  575. category = params.get("c", "").strip()
  576. tag = params.get("t", "").strip()
  577. ordering = params.get("ordering", "").strip()
  578. sort_by = params.get("sort_by", "").strip()
  579. media_type = params.get("media_type", "").strip()
  580. author = params.get("author", "").strip()
  581. sort_by_options = ["title", "add_date", "edit_date", "views", "likes"]
  582. if sort_by not in sort_by_options:
  583. sort_by = "add_date"
  584. if ordering == "asc":
  585. ordering = ""
  586. else:
  587. ordering = "-"
  588. if media_type not in ["video", "image", "audio", "pdf"]:
  589. media_type = None
  590. if not (query or category or tag):
  591. ret = {}
  592. return Response(ret, status=status.HTTP_200_OK)
  593. media = Media.objects.filter(state="public", is_reviewed=True)
  594. if query:
  595. # move this processing to a prepare_query function
  596. query = clean_query(query)
  597. q_parts = [
  598. q_part.rstrip("y")
  599. for q_part in query.split()
  600. if q_part not in STOP_WORDS
  601. ]
  602. if q_parts:
  603. query = SearchQuery(q_parts[0] + ":*", search_type="raw")
  604. for part in q_parts[1:]:
  605. query &= SearchQuery(part + ":*", search_type="raw")
  606. else:
  607. query = None
  608. if query:
  609. media = media.filter(search=query)
  610. if tag:
  611. media = media.filter(tags__title=tag)
  612. if category:
  613. media = media.filter(category__title__contains=category)
  614. if media_type:
  615. media = media.filter(media_type=media_type)
  616. if author:
  617. media = media.filter(user__username=author)
  618. media = media.order_by(f"{ordering}{sort_by}")
  619. if self.request.query_params.get("show", "").strip() == "titles":
  620. media = media.values("title")[:40]
  621. return Response(media, status=status.HTTP_200_OK)
  622. else:
  623. media = media.prefetch_related("user")
  624. if category or tag:
  625. pagination_class = api_settings.DEFAULT_PAGINATION_CLASS
  626. else:
  627. # pagination_class = FastPaginationWithoutCount
  628. pagination_class = api_settings.DEFAULT_PAGINATION_CLASS
  629. paginator = pagination_class()
  630. page = paginator.paginate_queryset(media, request)
  631. serializer = MediaSearchSerializer(
  632. page, many=True, context={"request": request}
  633. )
  634. return paginator.get_paginated_response(serializer.data)
  635. class PlaylistList(APIView):
  636. """Playlists listings and creation views"""
  637. permission_classes = (permissions.IsAuthenticatedOrReadOnly, IsAuthorizedToAdd)
  638. parser_classes = (JSONParser, MultiPartParser, FormParser, FileUploadParser)
  639. def get(self, request, format=None):
  640. pagination_class = api_settings.DEFAULT_PAGINATION_CLASS
  641. paginator = pagination_class()
  642. playlists = Playlist.objects.filter().prefetch_related("user")
  643. if "author" in self.request.query_params:
  644. author = self.request.query_params["author"].strip()
  645. playlists = playlists.filter(user__username=author)
  646. page = paginator.paginate_queryset(playlists, request)
  647. serializer = PlaylistSerializer(page, many=True, context={"request": request})
  648. return paginator.get_paginated_response(serializer.data)
  649. def post(self, request, format=None):
  650. serializer = PlaylistSerializer(data=request.data, context={"request": request})
  651. if serializer.is_valid():
  652. serializer.save(user=request.user)
  653. return Response(serializer.data, status=status.HTTP_201_CREATED)
  654. return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
  655. class PlaylistDetail(APIView):
  656. """Playlist related views"""
  657. permission_classes = (permissions.IsAuthenticatedOrReadOnly, IsUserOrEditor)
  658. parser_classes = (JSONParser, MultiPartParser, FormParser, FileUploadParser)
  659. def get_playlist(self, friendly_token):
  660. try:
  661. playlist = Playlist.objects.get(friendly_token=friendly_token)
  662. self.check_object_permissions(self.request, playlist)
  663. return playlist
  664. except PermissionDenied:
  665. return Response(
  666. {"detail": "not enough permissions"}, status=status.HTTP_400_BAD_REQUEST
  667. )
  668. except BaseException:
  669. return Response(
  670. {"detail": "Playlist does not exist"},
  671. status=status.HTTP_400_BAD_REQUEST,
  672. )
  673. def get(self, request, friendly_token, format=None):
  674. playlist = self.get_playlist(friendly_token)
  675. if isinstance(playlist, Response):
  676. return playlist
  677. serializer = PlaylistDetailSerializer(playlist, context={"request": request})
  678. playlist_media = PlaylistMedia.objects.filter(
  679. playlist=playlist
  680. ).prefetch_related("media__user")
  681. playlist_media = [c.media for c in playlist_media]
  682. playlist_media_serializer = MediaSerializer(
  683. playlist_media, many=True, context={"request": request}
  684. )
  685. ret = serializer.data
  686. ret["playlist_media"] = playlist_media_serializer.data
  687. return Response(ret)
  688. def post(self, request, friendly_token, format=None):
  689. playlist = self.get_playlist(friendly_token)
  690. if isinstance(playlist, Response):
  691. return playlist
  692. serializer = PlaylistDetailSerializer(
  693. playlist, data=request.data, context={"request": request}
  694. )
  695. if serializer.is_valid():
  696. serializer.save(user=request.user)
  697. return Response(serializer.data, status=status.HTTP_201_CREATED)
  698. return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
  699. def put(self, request, friendly_token, format=None):
  700. playlist = self.get_playlist(friendly_token)
  701. if isinstance(playlist, Response):
  702. return playlist
  703. action = request.data.get("type")
  704. media_friendly_token = request.data.get("media_friendly_token")
  705. ordering = 0
  706. if request.data.get("ordering"):
  707. try:
  708. ordering = int(request.data.get("ordering"))
  709. except ValueError:
  710. pass
  711. if action in ["add", "remove", "ordering"]:
  712. media = Media.objects.filter(
  713. friendly_token=media_friendly_token, state="public", media_type="video"
  714. ).first()
  715. if media:
  716. if action == "add":
  717. media_in_playlist = PlaylistMedia.objects.filter(
  718. playlist=playlist
  719. ).count()
  720. if media_in_playlist >= settings.MAX_MEDIA_PER_PLAYLIST:
  721. return Response(
  722. {"detail": "max number of media for a Playlist reached"},
  723. status=status.HTTP_400_BAD_REQUEST,
  724. )
  725. else:
  726. obj, created = PlaylistMedia.objects.get_or_create(
  727. playlist=playlist,
  728. media=media,
  729. ordering=media_in_playlist + 1,
  730. )
  731. obj.save()
  732. return Response(
  733. {"detail": "media added to Playlist"},
  734. status=status.HTTP_201_CREATED,
  735. )
  736. elif action == "remove":
  737. PlaylistMedia.objects.filter(
  738. playlist=playlist, media=media
  739. ).delete()
  740. return Response(
  741. {"detail": "media removed from Playlist"},
  742. status=status.HTTP_201_CREATED,
  743. )
  744. elif action == "ordering":
  745. if ordering:
  746. playlist.set_ordering(media, ordering)
  747. return Response(
  748. {"detail": "new ordering set"},
  749. status=status.HTTP_201_CREATED,
  750. )
  751. else:
  752. return Response(
  753. {"detail": "media is not valid"}, status=status.HTTP_400_BAD_REQUEST
  754. )
  755. return Response(
  756. {"detail": "invalid or not specified action"},
  757. status=status.HTTP_400_BAD_REQUEST,
  758. )
  759. def delete(self, request, friendly_token, format=None):
  760. playlist = self.get_playlist(friendly_token)
  761. if isinstance(playlist, Response):
  762. return playlist
  763. playlist.delete()
  764. return Response(status=status.HTTP_204_NO_CONTENT)
  765. class EncodingDetail(APIView):
  766. """Experimental. This View is used by remote workers
  767. Needs heavy testing and documentation.
  768. """
  769. permission_classes = (permissions.IsAdminUser,)
  770. parser_classes = (JSONParser, MultiPartParser, FormParser, FileUploadParser)
  771. def post(self, request, encoding_id):
  772. ret = {}
  773. force = request.data.get("force", False)
  774. task_id = request.data.get("task_id", False)
  775. action = request.data.get("action", "")
  776. chunk = request.data.get("chunk", False)
  777. chunk_file_path = request.data.get("chunk_file_path", "")
  778. encoding_status = request.data.get("status", "")
  779. progress = request.data.get("progress", "")
  780. commands = request.data.get("commands", "")
  781. logs = request.data.get("logs", "")
  782. retries = request.data.get("retries", "")
  783. worker = request.data.get("worker", "")
  784. temp_file = request.data.get("temp_file", "")
  785. total_run_time = request.data.get("total_run_time", "")
  786. if action == "start":
  787. try:
  788. encoding = Encoding.objects.get(id=encoding_id)
  789. media = encoding.media
  790. profile = encoding.profile
  791. except BaseException:
  792. Encoding.objects.filter(id=encoding_id).delete()
  793. return Response({"status": "fail"}, status=status.HTTP_400_BAD_REQUEST)
  794. # TODO: break chunk True/False logic here
  795. if (
  796. Encoding.objects.filter(
  797. media=media,
  798. profile=profile,
  799. chunk=chunk,
  800. chunk_file_path=chunk_file_path,
  801. ).count()
  802. > 1
  803. and force == False
  804. ):
  805. Encoding.objects.filter(id=encoding_id).delete()
  806. return Response({"status": "fail"}, status=status.HTTP_400_BAD_REQUEST)
  807. else:
  808. Encoding.objects.filter(
  809. media=media,
  810. profile=profile,
  811. chunk=chunk,
  812. chunk_file_path=chunk_file_path,
  813. ).exclude(id=encoding.id).delete()
  814. encoding.status = "running"
  815. if task_id:
  816. encoding.task_id = task_id
  817. encoding.save()
  818. if chunk:
  819. original_media_path = chunk_file_path
  820. original_media_md5sum = encoding.md5sum
  821. original_media_url = (
  822. settings.SSL_FRONTEND_HOST + encoding.media_chunk_url
  823. )
  824. else:
  825. original_media_path = media.media_file.path
  826. original_media_md5sum = media.md5sum
  827. original_media_url = (
  828. settings.SSL_FRONTEND_HOST + media.original_media_url
  829. )
  830. ret["original_media_url"] = original_media_url
  831. ret["original_media_path"] = original_media_path
  832. ret["original_media_md5sum"] = original_media_md5sum
  833. # generating the commands here, and will replace these with temporary
  834. # files created on the remote server
  835. tf = "TEMP_FILE_REPLACE"
  836. tfpass = "TEMP_FPASS_FILE_REPLACE"
  837. ffmpeg_commands = produce_ffmpeg_commands(
  838. original_media_path,
  839. media.media_info,
  840. resolution=profile.resolution,
  841. codec=profile.codec,
  842. output_filename=tf,
  843. pass_file=tfpass,
  844. chunk=chunk,
  845. )
  846. if not ffmpeg_commands:
  847. encoding.delete()
  848. return Response({"status": "fail"}, status=status.HTTP_400_BAD_REQUEST)
  849. ret["duration"] = media.duration
  850. ret["ffmpeg_commands"] = ffmpeg_commands
  851. ret["profile_extension"] = profile.extension
  852. return Response(ret, status=status.HTTP_201_CREATED)
  853. elif action == "update_fields":
  854. try:
  855. encoding = Encoding.objects.get(id=encoding_id)
  856. except BaseException:
  857. return Response({"status": "fail"}, status=status.HTTP_400_BAD_REQUEST)
  858. to_update = ["size", "update_date"]
  859. if encoding_status:
  860. encoding.status = encoding_status
  861. to_update.append("status")
  862. if progress:
  863. encoding.progress = progress
  864. to_update.append("progress")
  865. if logs:
  866. encoding.logs = logs
  867. to_update.append("logs")
  868. if commands:
  869. encoding.commands = commands
  870. to_update.append("commands")
  871. if task_id:
  872. encoding.task_id = task_id
  873. to_update.append("task_id")
  874. if total_run_time:
  875. encoding.total_run_time = total_run_time
  876. to_update.append("total_run_time")
  877. if worker:
  878. encoding.worker = worker
  879. to_update.append("worker")
  880. if temp_file:
  881. encoding.temp_file = temp_file
  882. to_update.append("temp_file")
  883. if retries:
  884. encoding.retries = retries
  885. to_update.append("retries")
  886. try:
  887. encoding.save(update_fields=to_update)
  888. except BaseException:
  889. return Response({"status": "fail"}, status=status.HTTP_400_BAD_REQUEST)
  890. return Response({"status": "success"}, status=status.HTTP_201_CREATED)
  891. def put(self, request, encoding_id, format=None):
  892. encoding_file = request.data["file"]
  893. encoding = Encoding.objects.filter(id=encoding_id).first()
  894. if not encoding:
  895. return Response(
  896. {"detail": "encoding does not exist"},
  897. status=status.HTTP_400_BAD_REQUEST,
  898. )
  899. encoding.media_file = encoding_file
  900. encoding.save()
  901. return Response({"detail": "ok"}, status=status.HTTP_201_CREATED)
  902. class CommentList(APIView):
  903. permission_classes = (permissions.IsAuthenticatedOrReadOnly, IsAuthorizedToAdd)
  904. parser_classes = (JSONParser, MultiPartParser, FormParser, FileUploadParser)
  905. def get(self, request, format=None):
  906. pagination_class = api_settings.DEFAULT_PAGINATION_CLASS
  907. paginator = pagination_class()
  908. comments = Comment.objects.filter()
  909. comments = comments.prefetch_related("user")
  910. comments = comments.prefetch_related("media")
  911. params = self.request.query_params
  912. if "author" in params:
  913. author_param = params["author"].strip()
  914. user_queryset = User.objects.all()
  915. user = get_object_or_404(user_queryset, username=author_param)
  916. comments = comments.filter(user=user)
  917. page = paginator.paginate_queryset(comments, request)
  918. serializer = CommentSerializer(page, many=True, context={"request": request})
  919. return paginator.get_paginated_response(serializer.data)
  920. class CommentDetail(APIView):
  921. """Comments related views
  922. Listings of comments for a media (GET)
  923. Create comment (POST)
  924. Delete comment (DELETE)
  925. """
  926. permission_classes = (IsAuthorizedToAdd,)
  927. parser_classes = (JSONParser, MultiPartParser, FormParser, FileUploadParser)
  928. def get_object(self, friendly_token):
  929. try:
  930. media = Media.objects.select_related("user").get(
  931. friendly_token=friendly_token
  932. )
  933. self.check_object_permissions(self.request, media)
  934. if media.state == "private" and self.request.user != media.user:
  935. return Response(
  936. {"detail": "media is private"}, status=status.HTTP_400_BAD_REQUEST
  937. )
  938. return media
  939. except PermissionDenied:
  940. return Response(
  941. {"detail": "bad permissions"}, status=status.HTTP_400_BAD_REQUEST
  942. )
  943. except BaseException:
  944. return Response(
  945. {"detail": "media file does not exist"},
  946. status=status.HTTP_400_BAD_REQUEST,
  947. )
  948. def get(self, request, friendly_token):
  949. # list comments for a media
  950. media = self.get_object(friendly_token)
  951. if isinstance(media, Response):
  952. return media
  953. comments = media.comments.filter().prefetch_related("user")
  954. pagination_class = api_settings.DEFAULT_PAGINATION_CLASS
  955. paginator = pagination_class()
  956. page = paginator.paginate_queryset(comments, request)
  957. serializer = CommentSerializer(page, many=True, context={"request": request})
  958. return paginator.get_paginated_response(serializer.data)
  959. def delete(self, request, friendly_token, uid=None):
  960. """Delete a comment
  961. Administrators, MediaCMS editors and managers,
  962. media owner, and comment owners, can delete a comment
  963. """
  964. if uid:
  965. try:
  966. comment = Comment.objects.get(uid=uid)
  967. except BaseException:
  968. return Response(
  969. {"detail": "comment does not exist"},
  970. status=status.HTTP_400_BAD_REQUEST,
  971. )
  972. if (
  973. (comment.user == self.request.user)
  974. or comment.media.user == self.request.user
  975. or is_mediacms_editor(self.request.user)
  976. ):
  977. comment.delete()
  978. else:
  979. return Response(
  980. {"detail": "bad permissions"}, status=status.HTTP_400_BAD_REQUEST
  981. )
  982. return Response(status=status.HTTP_204_NO_CONTENT)
  983. def post(self, request, friendly_token):
  984. """Create a comment"""
  985. media = self.get_object(friendly_token)
  986. if isinstance(media, Response):
  987. return media
  988. if not media.enable_comments:
  989. return Response(
  990. {"detail": "comments not allowed here"},
  991. status=status.HTTP_400_BAD_REQUEST,
  992. )
  993. serializer = CommentSerializer(data=request.data, context={"request": request})
  994. if serializer.is_valid():
  995. serializer.save(user=request.user, media=media)
  996. if request.user != media.user:
  997. notify_user_on_comment(friendly_token=media.friendly_token)
  998. return Response(serializer.data, status=status.HTTP_201_CREATED)
  999. return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
  1000. class UserActions(APIView):
  1001. parser_classes = (JSONParser,)
  1002. def get(self, request, action):
  1003. media = []
  1004. if action in VALID_USER_ACTIONS:
  1005. if request.user.is_authenticated:
  1006. media = (
  1007. Media.objects.select_related("user")
  1008. .filter(
  1009. mediaactions__user=request.user, mediaactions__action=action
  1010. )
  1011. .order_by("-mediaactions__action_date")
  1012. )
  1013. elif request.session.session_key:
  1014. media = (
  1015. Media.objects.select_related("user")
  1016. .filter(
  1017. mediaactions__session_key=request.session.session_key,
  1018. mediaactions__action=action,
  1019. )
  1020. .order_by("-mediaactions__action_date")
  1021. )
  1022. pagination_class = api_settings.DEFAULT_PAGINATION_CLASS
  1023. paginator = pagination_class()
  1024. page = paginator.paginate_queryset(media, request)
  1025. serializer = MediaSerializer(page, many=True, context={"request": request})
  1026. return paginator.get_paginated_response(serializer.data)
  1027. class CategoryList(APIView):
  1028. """List categories"""
  1029. def get(self, request, format=None):
  1030. categories = Category.objects.filter().order_by("title")
  1031. serializer = CategorySerializer(
  1032. categories, many=True, context={"request": request}
  1033. )
  1034. ret = serializer.data
  1035. return Response(ret)
  1036. class TagList(APIView):
  1037. """List tags"""
  1038. def get(self, request, format=None):
  1039. tags = Tag.objects.filter().order_by("-media_count")
  1040. pagination_class = api_settings.DEFAULT_PAGINATION_CLASS
  1041. paginator = pagination_class()
  1042. page = paginator.paginate_queryset(tags, request)
  1043. serializer = TagSerializer(page, many=True, context={"request": request})
  1044. return paginator.get_paginated_response(serializer.data)
  1045. class EncodeProfileList(APIView):
  1046. """List encode profiles"""
  1047. def get(self, request, format=None):
  1048. profiles = EncodeProfile.objects.all()
  1049. serializer = EncodeProfileSerializer(
  1050. profiles, many=True, context={"request": request}
  1051. )
  1052. return Response(serializer.data)
  1053. class TasksList(APIView):
  1054. """List tasks"""
  1055. permission_classes = (permissions.IsAdminUser,)
  1056. def get(self, request, format=None):
  1057. ret = list_tasks()
  1058. return Response(ret)
  1059. class TaskDetail(APIView):
  1060. """Cancel a task"""
  1061. permission_classes = (permissions.IsAdminUser,)
  1062. def delete(self, request, uid, format=None):
  1063. revoke(uid, terminate=True)
  1064. return Response(status=status.HTTP_204_NO_CONTENT)