@login_required\r
def edit_user(request, id):\r
user = get_object_or_404(User, id=id)\r
- if request.user != user:\r
- raise Http404\r
+ if not (request.user.is_superuser or request.user == user):\r
+ return HttpResponseForbidden()\r
if request.method == "POST":\r
form = EditUserForm(user, request.POST)\r
if form.is_valid():\r
else:\r
form = EditUserForm(user)\r
return render_to_response('users/edit.html', {\r
+ 'user': user,\r
'form' : form,\r
'gravatar_faq_url' : reverse('faq') + '#gravatar',\r
}, context_instance=RequestContext(request))\r
\r
\r
+@login_required\r
+def user_powers(request, id, action, status):\r
+ if not request.user.is_superuser:\r
+ return HttpResponseForbidden()\r
+\r
+ user = get_object_or_404(User, id=id)\r
+ new_state = action == 'grant'\r
+\r
+ if status == 'super':\r
+ user.is_superuser = new_state\r
+ elif status == 'staff':\r
+ user.is_staff = new_state\r
+ else:\r
+ raise Http404()\r
+\r
+ user.save() \r
+ return HttpResponseRedirect(user.get_profile_url())\r
+\r
\r
def user_view(template, tab_name, tab_description, page_title, private=False):\r
def decorator(fn):\r
def decorated(request, id, slug=None):\r
user = get_object_or_404(User, id=id)\r
- if private and not user == request.user:\r
+ if private and not (user == request.user or request.user.is_superuser):\r
return HttpResponseForbidden()\r
context = fn(request, user)\r
+\r
+ rev_page_title = user.username + " - " + page_title\r
+\r
context.update({\r
"tab_name" : tab_name,\r
"tab_description" : tab_description,\r
- "page_title" : page_title,\r
+ "page_title" : rev_page_title,\r
+ "can_view_private": (user == request.user) or request.user.is_superuser\r
})\r
return render_to_response(template, context, context_instance=RequestContext(request))\r
return decorated\r
return decorator\r
\r
\r
-@user_view('users/stats.html', 'stats', _('user profile'), _('user profile overview'))\r
+@user_view('users/stats.html', 'stats', _('user profile'), _('user overview'))\r
def user_stats(request, user):\r
questions = Question.objects.filter(author=user, deleted=None).order_by('-added_at')\r
answers = Answer.objects.filter(author=user, deleted=None).order_by('-added_at')\r
"total_awards" : len(awards),\r
}\r
\r
-@user_view('users/recent.html', 'recent', _('recent user activity'), _('profile - recent activity'))\r
+@user_view('users/recent.html', 'recent', _('recent user activity'), _('recent activity'))\r
def user_recent(request, user):\r
activities = user.actions.exclude(action_type__in=("voteup", "votedown", "voteupcomment", "flag")).order_by('-action_date')[:USERS_PAGE_SIZE]\r
\r
return {"view_user" : user, "activities" : activities}\r
\r
\r
-@user_view('users/votes.html', 'votes', _('user vote record'), _('profile - votes'), True)\r
+@user_view('users/votes.html', 'votes', _('user vote record'), _('votes'), True)\r
def user_votes(request, user):\r
- votes = user.votes.filter(node__deleted=None).order_by('-voted_at')[:USERS_PAGE_SIZE]\r
+ votes = user.votes.filter(node__deleted=None, node__node_type__in=("question", "answer")).order_by('-voted_at')[:USERS_PAGE_SIZE]\r
\r
return {"view_user" : user, "votes" : votes}\r
\r
\r
-@user_view('users/reputation.html', 'reputation', _('user reputation in the community'), _('profile - user reputation'))\r
+@user_view('users/reputation.html', 'reputation', _('user reputation in the community'), _('user reputation'))\r
def user_reputation(request, user):\r
rep = list(user.reputes.order_by('date'))\r
values = [r.value for r in rep]\r
\r
return {"view_user": user, "reputation": reversed(rep), "graph_data": graph_data}\r
\r
-@user_view('users/questions.html', 'favorites', _('favorite questions'), _('profile - favorite questions'))\r
+@user_view('users/questions.html', 'favorites', _('favorite questions'), _('favorite questions'))\r
def user_favorites(request, user):\r
favorites = FavoriteAction.objects.filter(user=user)\r
\r
return {"favorites" : favorites, "view_user" : user}\r
\r
-@user_view('users/subscriptions.html', 'subscriptions', _('subscription settings'), _('profile - subscriptions'), True)\r
+@user_view('users/subscriptions.html', 'subscriptions', _('subscription settings'), _('subscriptions'), True)\r
def user_subscriptions(request, user):\r
if request.method == 'POST':\r
form = SubscriptionSettingsForm(request.POST)\r