mirror of
https://github.com/AxioDL/axiodl-www.git
synced 2026-07-11 06:19:06 -07:00
Implement reCAPTCHA
This commit is contained in:
@@ -9,14 +9,23 @@
|
||||
<div class="card-header bg-dark text-light">
|
||||
<div class="card-title"><h2 class="card-title">Log in</h2></div>
|
||||
</div>
|
||||
<form method="post">
|
||||
<div class="card-body bg-light border-dark">
|
||||
<form method="post" novalidate>
|
||||
|
||||
{% csrf_token %}
|
||||
<input type="hidden" name="next" value="{{ next }}">
|
||||
{% include 'includes/form.html' %}
|
||||
<script src='https://www.google.com/recaptcha/api.js'></script>
|
||||
<div class="form-group g-recaptcha"
|
||||
data-sitekey="{{ GOOGLE_RECAPTCHA_SITE_KEY }}"></div>
|
||||
{% if messages %}
|
||||
{% for message in messages %}
|
||||
{{ message }}
|
||||
{% endfor %}
|
||||
{% endif %}
|
||||
<button type="submit" class="btn btn-primary btn-block">Log in</button>
|
||||
</form>
|
||||
</div>
|
||||
</form>
|
||||
<div class="card-footer text-muted text-center">
|
||||
New to AxioDL? <a href="{% url 'signup' %}">Sign up</a>
|
||||
</div>
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
<div class="card-title"><h2 class="card-title">Sign up</h2></div>
|
||||
</div>
|
||||
|
||||
<form method="post" novalidate>
|
||||
<form method="post">
|
||||
<div class="card-body bg-light border-dark">
|
||||
<h3>*Denotes required fields</h3>
|
||||
{% csrf_token %}
|
||||
@@ -100,7 +100,15 @@
|
||||
{{ form.profile.use_gravatar.help_text|safe }}
|
||||
</small>
|
||||
{% endif %}
|
||||
<script src='https://www.google.com/recaptcha/api.js'></script>
|
||||
</div>
|
||||
<div class="form-group g-recaptcha"
|
||||
data-sitekey="{{ GOOGLE_RECAPTCHA_SITE_KEY }}"></div>
|
||||
{% if messages %}
|
||||
{% for message in messages %}
|
||||
{{ message }}
|
||||
{% endfor %}
|
||||
{% endif %}
|
||||
<button type="submit" class="btn btn-primary btn-block">Create an account</button>
|
||||
</div>
|
||||
</form>
|
||||
|
||||
+4
-4
@@ -1,11 +1,11 @@
|
||||
from django.conf.urls import url, include
|
||||
from django.contrib.auth import views as auth_views
|
||||
|
||||
from .views import UserUpdateView, gitlab_auth, UserSignupView
|
||||
from core.templatetags.check_recaptcha import check_recaptcha
|
||||
from .views import UserUpdateView, gitlab_auth, UserSignupView, UserLoginView
|
||||
|
||||
urlpatterns = [
|
||||
url(r'^signup/$', UserSignupView.as_view(), name='signup'),
|
||||
url(r'^login/$', auth_views.LoginView.as_view(template_name='login.html'), name='login'),
|
||||
url(r'^signup/$', check_recaptcha(UserSignupView.as_view()), name='signup'),
|
||||
url(r'^login/$', check_recaptcha(UserLoginView.as_view()), name='login'),
|
||||
url(r'^logout/$', auth_views.LogoutView.as_view(), name='logout'),
|
||||
url(r'^reset/$',
|
||||
auth_views.PasswordResetView.as_view(
|
||||
|
||||
+20
-2
@@ -1,11 +1,14 @@
|
||||
from django.contrib.auth import login as auth_login
|
||||
from django.contrib.auth import get_user_model
|
||||
from django.contrib.auth.views import LoginView
|
||||
from django.contrib.auth.forms import AuthenticationForm
|
||||
from django.contrib.auth.decorators import login_required
|
||||
from django.urls import reverse_lazy
|
||||
from django.utils.decorators import method_decorator
|
||||
from django.views.generic import UpdateView, CreateView
|
||||
from django.utils.http import urlencode
|
||||
from django.shortcuts import render, redirect
|
||||
from .forms import UserSignUpForm, ProfileForm, UserCreationMultiForm
|
||||
import hashlib
|
||||
from .forms import ProfileForm, UserCreationMultiForm
|
||||
from .models import Profile
|
||||
|
||||
|
||||
@@ -32,12 +35,27 @@ class UserSignupView(CreateView):
|
||||
template_name = 'signup.html'
|
||||
|
||||
def form_valid(self, form):
|
||||
if self.request.recaptcha_is_valid:
|
||||
# We need to save the user before we can save the profile
|
||||
user = form['user'].save()
|
||||
profile = form['profile'].save(commit=False)
|
||||
profile.user = user
|
||||
profile.save()
|
||||
return redirect(self.get_success_url())
|
||||
return render(self.request, self.template_name, self.get_context_data())
|
||||
|
||||
|
||||
class UserLoginView(LoginView):
|
||||
form_class = AuthenticationForm
|
||||
success_url = reverse_lazy('home')
|
||||
template_name = 'login.html'
|
||||
|
||||
def form_valid(self, form):
|
||||
if self.request.recaptcha_is_valid:
|
||||
form.save()
|
||||
return redirect(self.get_success_url())
|
||||
|
||||
return render(self.request, self.template_name, self.get_context_data())
|
||||
|
||||
|
||||
@method_decorator(login_required, name='dispatch')
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
from django.conf import settings
|
||||
|
||||
|
||||
def recaptcha_site_key(request):
|
||||
return {'GOOGLE_RECAPTCHA_SITE_KEY': settings.GOOGLE_RECAPTCHA_SITE_KEY}
|
||||
+2
-1
@@ -10,7 +10,7 @@ For the full list of settings and their values, see
|
||||
https://docs.djangoproject.com/en/2.2/ref/settings/
|
||||
"""
|
||||
from django.utils.translation import ugettext_lazy as _
|
||||
from .sitesettings import configuration
|
||||
from .sitesettings import configuration, GOOGLE_RECAPTCHA_SECRET_KEY, GOOGLE_RECAPTCHA_SITE_KEY
|
||||
import os
|
||||
|
||||
# Build paths inside the project like this: os.path.join(BASE_DIR, ...)
|
||||
@@ -80,6 +80,7 @@ TEMPLATES = [
|
||||
'django.template.context_processors.request',
|
||||
'django.contrib.auth.context_processors.auth',
|
||||
'django.contrib.messages.context_processors.messages',
|
||||
'axiodl.context_processors.recaptcha_site_key',
|
||||
],
|
||||
'libraries': {
|
||||
'site_configuration': 'axiodl.templatetags.site_configuration',
|
||||
|
||||
@@ -13,3 +13,7 @@ def lock_site(locked=False):
|
||||
|
||||
def is_site_locked():
|
||||
return configuration.locked
|
||||
|
||||
|
||||
GOOGLE_RECAPTCHA_SITE_KEY='6LeIxAcTAAAAAJcZVRqyHh71UMIEGNQ_MXjiZKhI' # Google Test key - Replace immediately with your key
|
||||
GOOGLE_RECAPTCHA_SECRET_KEY='6LeIxAcTAAAAAGG-vFI1TnRWxMZNFuojJ4WifJWe' # Google Test key - Replace immediately with your key
|
||||
|
||||
@@ -17,7 +17,7 @@
|
||||
<form method="post" novalidate>
|
||||
{% csrf_token %}
|
||||
{% include 'includes/form.html' %}
|
||||
<button type="submit" class="btn btn-success btn-block">Create</button>
|
||||
<button type="submit" class="btn btn-sm btn-success btn-block btn-outline-light">Create</button>
|
||||
</form>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -0,0 +1,27 @@
|
||||
from django.conf import settings
|
||||
from django.contrib import messages
|
||||
|
||||
import requests
|
||||
|
||||
|
||||
def check_recaptcha(function):
|
||||
def wrap(request, *args, **kwargs):
|
||||
request.recaptcha_is_valid = None
|
||||
if request.method == 'POST':
|
||||
recaptcha_response = request.POST.get('g-recaptcha-response')
|
||||
data = {
|
||||
'secret': settings.GOOGLE_RECAPTCHA_SECRET_KEY,
|
||||
'response': recaptcha_response
|
||||
}
|
||||
r = requests.post('https://www.google.com/recaptcha/api/siteverify', data=data)
|
||||
result = r.json()
|
||||
if result['success']:
|
||||
request.recaptcha_is_valid = True
|
||||
else:
|
||||
request.recaptcha_is_valid = False
|
||||
messages.error(request, 'Invalid reCAPTCHA. Please try again.')
|
||||
return function(request, *args, **kwargs)
|
||||
|
||||
wrap.__doc__ = function.__doc__
|
||||
wrap.__name__ = function.__name__
|
||||
return wrap
|
||||
Reference in New Issue
Block a user