| rev | 
   line source | 
| 
bsw/jbe@0
 | 
     1 Member = mondelefant.new_class()
 | 
| 
bsw/jbe@0
 | 
     2 Member.table = 'member'
 | 
| 
bsw/jbe@0
 | 
     3 
 | 
| 
bsw/jbe@0
 | 
     4 Member:add_reference{
 | 
| 
bsw@9
 | 
     5   mode          = "1m",
 | 
| 
bsw@9
 | 
     6   to            = "MemberHistory",
 | 
| 
bsw@9
 | 
     7   this_key      = 'id',
 | 
| 
bsw@9
 | 
     8   that_key      = 'member_id',
 | 
| 
bsw@9
 | 
     9   ref           = 'history_entries',
 | 
| 
bsw@9
 | 
    10   back_ref      = 'member'
 | 
| 
bsw@9
 | 
    11 }
 | 
| 
bsw@9
 | 
    12 
 | 
| 
bsw@9
 | 
    13 Member:add_reference{
 | 
| 
bsw/jbe@4
 | 
    14   mode          = '1m',
 | 
| 
bsw@2
 | 
    15   to            = "MemberImage",
 | 
| 
bsw@2
 | 
    16   this_key      = 'id',
 | 
| 
bsw@2
 | 
    17   that_key      = 'member_id',
 | 
| 
bsw/jbe@4
 | 
    18   ref           = 'images',
 | 
| 
bsw@2
 | 
    19   back_ref      = 'member'
 | 
| 
bsw@2
 | 
    20 }
 | 
| 
bsw@2
 | 
    21 
 | 
| 
bsw@2
 | 
    22 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
    23   mode          = '1m',
 | 
| 
bsw/jbe@0
 | 
    24   to            = "Contact",
 | 
| 
bsw/jbe@0
 | 
    25   this_key      = 'id',
 | 
| 
bsw/jbe@0
 | 
    26   that_key      = 'member_id',
 | 
| 
bsw/jbe@0
 | 
    27   ref           = 'contacts',
 | 
| 
bsw/jbe@0
 | 
    28   back_ref      = 'member',
 | 
| 
bsw/jbe@0
 | 
    29   default_order = '"other_member_id"'
 | 
| 
bsw/jbe@0
 | 
    30 }
 | 
| 
bsw/jbe@0
 | 
    31 
 | 
| 
bsw/jbe@0
 | 
    32 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
    33   mode          = '1m',
 | 
| 
bsw/jbe@0
 | 
    34   to            = "Contact",
 | 
| 
bsw/jbe@0
 | 
    35   this_key      = 'id',
 | 
| 
bsw/jbe@0
 | 
    36   that_key      = 'member_id',
 | 
| 
bsw/jbe@0
 | 
    37   ref           = 'foreign_contacts',
 | 
| 
bsw/jbe@0
 | 
    38   back_ref      = 'other_member',
 | 
| 
bsw/jbe@0
 | 
    39   default_order = '"member_id"'
 | 
| 
bsw/jbe@0
 | 
    40 }
 | 
| 
bsw/jbe@0
 | 
    41 
 | 
| 
bsw/jbe@0
 | 
    42 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
    43   mode          = '1m',
 | 
| 
bsw/jbe@0
 | 
    44   to            = "Session",
 | 
| 
bsw/jbe@0
 | 
    45   this_key      = 'id',
 | 
| 
bsw/jbe@0
 | 
    46   that_key      = 'member_id',
 | 
| 
bsw/jbe@0
 | 
    47   ref           = 'sessions',
 | 
| 
bsw/jbe@0
 | 
    48   back_ref      = 'member',
 | 
| 
bsw/jbe@0
 | 
    49   default_order = '"ident"'
 | 
| 
bsw/jbe@0
 | 
    50 }
 | 
| 
bsw/jbe@0
 | 
    51 
 | 
| 
bsw/jbe@0
 | 
    52 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
    53   mode          = '1m',
 | 
| 
bsw/jbe@0
 | 
    54   to            = "Draft",
 | 
| 
bsw/jbe@0
 | 
    55   this_key      = 'id',
 | 
| 
bsw/jbe@0
 | 
    56   that_key      = 'author_id',
 | 
| 
bsw/jbe@0
 | 
    57   ref           = 'drafts',
 | 
| 
bsw/jbe@0
 | 
    58   back_ref      = 'author',
 | 
| 
bsw/jbe@0
 | 
    59   default_order = '"id"'
 | 
| 
bsw/jbe@0
 | 
    60 }
 | 
| 
bsw/jbe@0
 | 
    61 
 | 
| 
bsw/jbe@0
 | 
    62 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
    63   mode          = '1m',
 | 
| 
bsw/jbe@0
 | 
    64   to            = "Suggestion",
 | 
| 
bsw/jbe@0
 | 
    65   this_key      = 'id',
 | 
| 
bsw/jbe@0
 | 
    66   that_key      = 'author_id',
 | 
| 
bsw/jbe@0
 | 
    67   ref           = 'suggestions',
 | 
| 
bsw/jbe@0
 | 
    68   back_ref      = 'author',
 | 
| 
bsw/jbe@0
 | 
    69   default_order = '"id"'
 | 
| 
bsw/jbe@0
 | 
    70 }
 | 
| 
bsw/jbe@0
 | 
    71 
 | 
| 
bsw/jbe@0
 | 
    72 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
    73   mode          = '1m',
 | 
| 
bsw/jbe@0
 | 
    74   to            = "Membership",
 | 
| 
bsw/jbe@0
 | 
    75   this_key      = 'id',
 | 
| 
bsw/jbe@0
 | 
    76   that_key      = 'member_id',
 | 
| 
bsw/jbe@0
 | 
    77   ref           = 'memberships',
 | 
| 
bsw/jbe@0
 | 
    78   back_ref      = 'member',
 | 
| 
bsw/jbe@0
 | 
    79   default_order = '"area_id"'
 | 
| 
bsw/jbe@0
 | 
    80 }
 | 
| 
bsw/jbe@0
 | 
    81 
 | 
| 
bsw/jbe@0
 | 
    82 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
    83   mode          = '1m',
 | 
| 
bsw/jbe@0
 | 
    84   to            = "Interest",
 | 
| 
bsw/jbe@0
 | 
    85   this_key      = 'id',
 | 
| 
bsw/jbe@0
 | 
    86   that_key      = 'member_id',
 | 
| 
bsw/jbe@0
 | 
    87   ref           = 'interests',
 | 
| 
bsw/jbe@0
 | 
    88   back_ref      = 'member',
 | 
| 
bsw/jbe@0
 | 
    89   default_order = '"id"'
 | 
| 
bsw/jbe@0
 | 
    90 }
 | 
| 
bsw/jbe@0
 | 
    91 
 | 
| 
bsw/jbe@0
 | 
    92 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
    93   mode          = '1m',
 | 
| 
bsw/jbe@0
 | 
    94   to            = "Initiator",
 | 
| 
bsw/jbe@0
 | 
    95   this_key      = 'id',
 | 
| 
bsw/jbe@0
 | 
    96   that_key      = 'member_id',
 | 
| 
bsw/jbe@0
 | 
    97   ref           = 'initiators',
 | 
| 
bsw@10
 | 
    98   back_ref      = 'member'
 | 
| 
bsw/jbe@0
 | 
    99 }
 | 
| 
bsw/jbe@0
 | 
   100 
 | 
| 
bsw/jbe@0
 | 
   101 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
   102   mode          = '1m',
 | 
| 
bsw/jbe@0
 | 
   103   to            = "Supporter",
 | 
| 
bsw/jbe@0
 | 
   104   this_key      = 'id',
 | 
| 
bsw/jbe@0
 | 
   105   that_key      = 'member_id',
 | 
| 
bsw/jbe@0
 | 
   106   ref           = 'supporters',
 | 
| 
bsw@2
 | 
   107   back_ref      = 'member'
 | 
| 
bsw/jbe@0
 | 
   108 }
 | 
| 
bsw/jbe@0
 | 
   109 
 | 
| 
bsw/jbe@0
 | 
   110 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
   111   mode          = '1m',
 | 
| 
bsw/jbe@0
 | 
   112   to            = "Opinion",
 | 
| 
bsw/jbe@0
 | 
   113   this_key      = 'id',
 | 
| 
bsw/jbe@0
 | 
   114   that_key      = 'member_id',
 | 
| 
bsw/jbe@0
 | 
   115   ref           = 'opinions',
 | 
| 
bsw/jbe@0
 | 
   116   back_ref      = 'member',
 | 
| 
bsw/jbe@0
 | 
   117   default_order = '"id"'
 | 
| 
bsw/jbe@0
 | 
   118 }
 | 
| 
bsw/jbe@0
 | 
   119 
 | 
| 
bsw/jbe@0
 | 
   120 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
   121   mode          = '1m',
 | 
| 
bsw/jbe@0
 | 
   122   to            = "Delegation",
 | 
| 
bsw/jbe@0
 | 
   123   this_key      = 'id',
 | 
| 
bsw/jbe@0
 | 
   124   that_key      = 'truster_id',
 | 
| 
bsw/jbe@0
 | 
   125   ref           = 'outgoing_delegations',
 | 
| 
bsw/jbe@0
 | 
   126   back_ref      = 'truster',
 | 
| 
bsw@1045
 | 
   127 --  default_order = '"id"'
 | 
| 
bsw/jbe@0
 | 
   128 }
 | 
| 
bsw/jbe@0
 | 
   129 
 | 
| 
bsw/jbe@0
 | 
   130 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
   131   mode          = '1m',
 | 
| 
bsw/jbe@0
 | 
   132   to            = "Delegation",
 | 
| 
bsw/jbe@0
 | 
   133   this_key      = 'id',
 | 
| 
bsw/jbe@0
 | 
   134   that_key      = 'trustee_id',
 | 
| 
bsw/jbe@0
 | 
   135   ref           = 'incoming_delegations',
 | 
| 
bsw/jbe@0
 | 
   136   back_ref      = 'trustee',
 | 
| 
bsw@1045
 | 
   137 --  default_order = '"id"'
 | 
| 
bsw/jbe@0
 | 
   138 }
 | 
| 
bsw/jbe@0
 | 
   139 
 | 
| 
bsw/jbe@0
 | 
   140 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
   141   mode          = '1m',
 | 
| 
bsw/jbe@0
 | 
   142   to            = "DirectVoter",
 | 
| 
bsw/jbe@0
 | 
   143   this_key      = 'id',
 | 
| 
bsw/jbe@0
 | 
   144   that_key      = 'member_id',
 | 
| 
bsw/jbe@0
 | 
   145   ref           = 'direct_voter',
 | 
| 
bsw/jbe@0
 | 
   146   back_ref      = 'member',
 | 
| 
bsw/jbe@0
 | 
   147   default_order = '"issue_id"'
 | 
| 
bsw/jbe@0
 | 
   148 }
 | 
| 
bsw/jbe@0
 | 
   149 
 | 
| 
bsw/jbe@0
 | 
   150 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
   151   mode          = '1m',
 | 
| 
bsw/jbe@0
 | 
   152   to            = "Vote",
 | 
| 
bsw/jbe@0
 | 
   153   this_key      = 'id',
 | 
| 
bsw/jbe@0
 | 
   154   that_key      = 'member_id',
 | 
| 
bsw/jbe@0
 | 
   155   ref           = 'vote',
 | 
| 
bsw/jbe@0
 | 
   156   back_ref      = 'member',
 | 
| 
bsw/jbe@0
 | 
   157   default_order = '"issue_id", "initiative_id"'
 | 
| 
bsw/jbe@0
 | 
   158 }
 | 
| 
bsw/jbe@0
 | 
   159 
 | 
| 
bsw/jbe@0
 | 
   160 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
   161   mode                  = 'mm',
 | 
| 
bsw/jbe@0
 | 
   162   to                    = "Member",
 | 
| 
bsw/jbe@0
 | 
   163   this_key              = 'id',
 | 
| 
bsw/jbe@0
 | 
   164   that_key              = 'id',
 | 
| 
bsw/jbe@0
 | 
   165   connected_by_table    = 'contact',
 | 
| 
bsw/jbe@0
 | 
   166   connected_by_this_key = 'member_id',
 | 
| 
bsw/jbe@0
 | 
   167   connected_by_that_key = 'other_member_id',
 | 
| 
bsw/jbe@0
 | 
   168   ref                   = 'saved_members',
 | 
| 
bsw/jbe@0
 | 
   169 }
 | 
| 
bsw/jbe@0
 | 
   170 
 | 
| 
bsw/jbe@0
 | 
   171 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
   172   mode                  = 'mm',
 | 
| 
bsw/jbe@0
 | 
   173   to                    = "Member",
 | 
| 
bsw/jbe@0
 | 
   174   this_key              = 'id',
 | 
| 
bsw/jbe@0
 | 
   175   that_key              = 'id',
 | 
| 
bsw/jbe@0
 | 
   176   connected_by_table    = 'contact',
 | 
| 
bsw/jbe@0
 | 
   177   connected_by_this_key = 'other_member_id',
 | 
| 
bsw/jbe@0
 | 
   178   connected_by_that_key = 'member_id',
 | 
| 
bsw/jbe@0
 | 
   179   ref                   = 'saved_by_members',
 | 
| 
bsw/jbe@0
 | 
   180 }
 | 
| 
bsw/jbe@0
 | 
   181 
 | 
| 
bsw/jbe@0
 | 
   182 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
   183   mode                  = 'mm',
 | 
| 
bsw@281
 | 
   184   to                    = "Unit",
 | 
| 
bsw@281
 | 
   185   this_key              = 'id',
 | 
| 
bsw@281
 | 
   186   that_key              = 'id',
 | 
| 
bsw@281
 | 
   187   connected_by_table    = 'privilege',
 | 
| 
bsw@281
 | 
   188   connected_by_this_key = 'member_id',
 | 
| 
bsw@281
 | 
   189   connected_by_that_key = 'unit_id',
 | 
| 
bsw@281
 | 
   190   ref                   = 'units'
 | 
| 
bsw@281
 | 
   191 }
 | 
| 
bsw@281
 | 
   192 
 | 
| 
bsw@281
 | 
   193 Member:add_reference{
 | 
| 
bsw@281
 | 
   194   mode                  = 'mm',
 | 
| 
bsw/jbe@0
 | 
   195   to                    = "Area",
 | 
| 
bsw/jbe@0
 | 
   196   this_key              = 'id',
 | 
| 
bsw/jbe@0
 | 
   197   that_key              = 'id',
 | 
| 
bsw/jbe@0
 | 
   198   connected_by_table    = 'membership',
 | 
| 
bsw/jbe@0
 | 
   199   connected_by_this_key = 'member_id',
 | 
| 
bsw/jbe@0
 | 
   200   connected_by_that_key = 'area_id',
 | 
| 
bsw/jbe@0
 | 
   201   ref                   = 'areas'
 | 
| 
bsw/jbe@0
 | 
   202 }
 | 
| 
bsw/jbe@0
 | 
   203 
 | 
| 
bsw/jbe@0
 | 
   204 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
   205   mode                  = 'mm',
 | 
| 
bsw/jbe@0
 | 
   206   to                    = "Issue",
 | 
| 
bsw/jbe@0
 | 
   207   this_key              = 'id',
 | 
| 
bsw/jbe@0
 | 
   208   that_key              = 'id',
 | 
| 
bsw/jbe@0
 | 
   209   connected_by_table    = 'interest',
 | 
| 
bsw/jbe@0
 | 
   210   connected_by_this_key = 'member_id',
 | 
| 
bsw/jbe@0
 | 
   211   connected_by_that_key = 'issue_id',
 | 
| 
bsw/jbe@0
 | 
   212   ref                   = 'issues'
 | 
| 
bsw/jbe@0
 | 
   213 }
 | 
| 
bsw/jbe@0
 | 
   214 
 | 
| 
bsw/jbe@0
 | 
   215 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
   216   mode                  = 'mm',
 | 
| 
bsw/jbe@0
 | 
   217   to                    = "Initiative",
 | 
| 
bsw/jbe@0
 | 
   218   this_key              = 'id',
 | 
| 
bsw/jbe@0
 | 
   219   that_key              = 'id',
 | 
| 
bsw/jbe@0
 | 
   220   connected_by_table    = 'initiator',
 | 
| 
bsw/jbe@0
 | 
   221   connected_by_this_key = 'member_id',
 | 
| 
bsw/jbe@0
 | 
   222   connected_by_that_key = 'initiative_id',
 | 
| 
bsw/jbe@0
 | 
   223   ref                   = 'initiated_initiatives'
 | 
| 
bsw/jbe@0
 | 
   224 }
 | 
| 
bsw/jbe@0
 | 
   225 
 | 
| 
bsw/jbe@0
 | 
   226 Member:add_reference{
 | 
| 
bsw/jbe@0
 | 
   227   mode                  = 'mm',
 | 
| 
bsw/jbe@0
 | 
   228   to                    = "Initiative",
 | 
| 
bsw/jbe@0
 | 
   229   this_key              = 'id',
 | 
| 
bsw/jbe@0
 | 
   230   that_key              = 'id',
 | 
| 
bsw/jbe@0
 | 
   231   connected_by_table    = 'supporter',
 | 
| 
bsw/jbe@0
 | 
   232   connected_by_this_key = 'member_id',
 | 
| 
bsw/jbe@0
 | 
   233   connected_by_that_key = 'initiative_id',
 | 
| 
bsw/jbe@0
 | 
   234   ref                   = 'supported_initiatives'
 | 
| 
bsw/jbe@0
 | 
   235 }
 | 
| 
bsw/jbe@0
 | 
   236 
 | 
| 
bsw@279
 | 
   237 model.has_rendered_content(Member, RenderedMemberStatement, "statement")
 | 
| 
bsw@279
 | 
   238 
 | 
| 
bsw@193
 | 
   239 function Member:build_selector(args)
 | 
| 
bsw@193
 | 
   240   local selector = self:new_selector()
 | 
| 
bsw@193
 | 
   241   if args.active ~= nil then
 | 
| 
bsw@193
 | 
   242     selector:add_where{ "member.active = ?", args.active }
 | 
| 
bsw@193
 | 
   243   end
 | 
| 
bsw@581
 | 
   244   if args.locked ~= nil then
 | 
| 
bsw@581
 | 
   245     selector:add_where{ "member.locked = ?", args.locked }
 | 
| 
bsw@581
 | 
   246   end
 | 
| 
bsw@199
 | 
   247   if args.is_contact_of_member_id then
 | 
| 
bsw@199
 | 
   248     selector:join("contact", "__model_member__contact", "member.id = __model_member__contact.other_member_id")
 | 
| 
bsw@199
 | 
   249     selector:add_where{ "__model_member__contact.member_id = ?", args.is_contact_of_member_id }
 | 
| 
bsw@199
 | 
   250   end
 | 
| 
bsw@297
 | 
   251   if args.voting_right_for_unit_id then
 | 
| 
bsw@299
 | 
   252     selector:join("privilege", "__model_member__privilege", { "member.id = __model_member__privilege.member_id AND __model_member__privilege.voting_right AND __model_member__privilege.unit_id = ?", args.voting_right_for_unit_id })
 | 
| 
bsw@297
 | 
   253   end
 | 
| 
bsw@581
 | 
   254   if args.admin_search then
 | 
| 
bsw@581
 | 
   255     local search_string = "%" .. args.admin_search .. "%"
 | 
| 
bsw@581
 | 
   256     selector:add_where{ "member.identification ILIKE ? OR member.name ILIKE ?", search_string, search_string }
 | 
| 
bsw@581
 | 
   257   end
 | 
| 
bsw@193
 | 
   258   if args.order then
 | 
| 
bsw@193
 | 
   259     if args.order == "id" then
 | 
| 
bsw@193
 | 
   260       selector:add_order_by("id")
 | 
| 
bsw@581
 | 
   261     elseif args.order == "identification" then
 | 
| 
bsw@581
 | 
   262       selector:add_order_by("identification")
 | 
| 
bsw@193
 | 
   263     elseif args.order == "name" then
 | 
| 
bsw@193
 | 
   264       selector:add_order_by("name")
 | 
| 
bsw@193
 | 
   265     else
 | 
| 
bsw@193
 | 
   266       error("invalid order")
 | 
| 
bsw@193
 | 
   267     end
 | 
| 
bsw@193
 | 
   268   end
 | 
| 
bsw@193
 | 
   269   return selector
 | 
| 
bsw@193
 | 
   270 end
 | 
| 
bsw@193
 | 
   271 
 | 
| 
bsw@929
 | 
   272 function Member:lockForReference()
 | 
| 
bsw@929
 | 
   273   self.get_db_conn().query("LOCK TABLE " .. self:get_qualified_table() .. " IN ROW SHARE MODE")
 | 
| 
bsw@929
 | 
   274 end
 | 
| 
bsw@929
 | 
   275 
 | 
| 
bsw/jbe@0
 | 
   276 function Member.object:set_password(password)
 | 
| 
bsw@865
 | 
   277   trace.disable()
 | 
| 
bsw@905
 | 
   278   
 | 
| 
bsw@905
 | 
   279   local hash_prefix
 | 
| 
bsw@905
 | 
   280   local salt_length
 | 
| 
bsw@905
 | 
   281 
 | 
| 
bsw@905
 | 
   282   local function rounds()
 | 
| 
bsw@905
 | 
   283     return multirand.integer(
 | 
| 
bsw@905
 | 
   284       config.password_hash_min_rounds,
 | 
| 
bsw@905
 | 
   285       config.password_hash_max_rounds
 | 
| 
bsw@905
 | 
   286     )
 | 
| 
bsw@905
 | 
   287   end
 | 
| 
bsw@905
 | 
   288       
 | 
| 
bsw@905
 | 
   289   if config.password_hash_algorithm == "crypt_md5" then
 | 
| 
bsw@905
 | 
   290     hash_prefix = "$1$" 
 | 
| 
bsw@905
 | 
   291     salt_length = 8
 | 
| 
bsw@905
 | 
   292     
 | 
| 
bsw@905
 | 
   293   elseif config.password_hash_algorithm == "crypt_sha256" then
 | 
| 
bsw@905
 | 
   294     hash_prefix = "$5$rounds=" .. rounds() .. "$"
 | 
| 
bsw@905
 | 
   295     salt_length = 16
 | 
| 
bsw@905
 | 
   296     
 | 
| 
bsw@905
 | 
   297   elseif config.password_hash_algorithm == "crypt_sha512" then
 | 
| 
bsw@905
 | 
   298     hash_prefix = "$6$rounds=" .. rounds() .. "$"
 | 
| 
bsw@905
 | 
   299     salt_length = 16
 | 
| 
bsw@905
 | 
   300     
 | 
| 
bsw@905
 | 
   301   else
 | 
| 
bsw@905
 | 
   302     error("Unknown hash algorithm selected in configuration")
 | 
| 
bsw@905
 | 
   303 
 | 
| 
bsw@905
 | 
   304   end
 | 
| 
bsw@906
 | 
   305   
 | 
| 
bsw@906
 | 
   306   hash_prefix = hash_prefix .. multirand.string(
 | 
| 
bsw@906
 | 
   307     salt_length,
 | 
| 
bsw@906
 | 
   308     "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz./"
 | 
| 
bsw@906
 | 
   309   )
 | 
| 
bsw@905
 | 
   310 
 | 
| 
bsw@906
 | 
   311   local hash = extos.crypt(password, hash_prefix)
 | 
| 
bsw@905
 | 
   312 
 | 
| 
bsw@905
 | 
   313   if not hash or hash:sub(1, #hash_prefix) ~= hash_prefix then
 | 
| 
bsw@905
 | 
   314     error("Password hashing algorithm failed")
 | 
| 
bsw@905
 | 
   315   end
 | 
| 
bsw@905
 | 
   316   
 | 
| 
bsw/jbe@0
 | 
   317   self.password = hash
 | 
| 
bsw/jbe@0
 | 
   318 end
 | 
| 
bsw/jbe@0
 | 
   319 
 | 
| 
bsw/jbe@0
 | 
   320 function Member.object:check_password(password)
 | 
| 
bsw/jbe@0
 | 
   321   if type(password) == "string" and type(self.password) == "string" then
 | 
| 
bsw@728
 | 
   322     return extos.crypt(password, self.password) == self.password
 | 
| 
bsw/jbe@0
 | 
   323   else
 | 
| 
bsw/jbe@0
 | 
   324     return false
 | 
| 
bsw/jbe@0
 | 
   325   end
 | 
| 
bsw/jbe@0
 | 
   326 end
 | 
| 
bsw/jbe@0
 | 
   327 
 | 
| 
bsw@905
 | 
   328 function Member.object_get:password_hash_needs_update()
 | 
| 
bsw@905
 | 
   329   
 | 
| 
bsw@905
 | 
   330   if self.password == nil then
 | 
| 
bsw@905
 | 
   331     return nil
 | 
| 
bsw@905
 | 
   332   end
 | 
| 
bsw@905
 | 
   333 
 | 
| 
bsw@905
 | 
   334   local function check_rounds(rounds)
 | 
| 
bsw@905
 | 
   335     if rounds then
 | 
| 
bsw@905
 | 
   336       rounds = tonumber(rounds)
 | 
| 
bsw@905
 | 
   337       if 
 | 
| 
bsw@905
 | 
   338         rounds >= config.password_hash_min_rounds and 
 | 
| 
bsw@905
 | 
   339         rounds <= config.password_hash_max_rounds
 | 
| 
bsw@905
 | 
   340       then
 | 
| 
bsw@905
 | 
   341         return false
 | 
| 
bsw@905
 | 
   342       end
 | 
| 
bsw@905
 | 
   343     end
 | 
| 
bsw@905
 | 
   344     return true
 | 
| 
bsw@905
 | 
   345   end
 | 
| 
bsw@905
 | 
   346   
 | 
| 
bsw@905
 | 
   347   if config.password_hash_algorithm == "crypt_md5" then
 | 
| 
bsw@905
 | 
   348 
 | 
| 
bsw@905
 | 
   349     return self.password:sub(1,3) ~= "$1$"
 | 
| 
bsw@905
 | 
   350     
 | 
| 
bsw@905
 | 
   351   elseif config.password_hash_algorithm == "crypt_sha256" then
 | 
| 
bsw@905
 | 
   352     
 | 
| 
bsw@905
 | 
   353     return check_rounds(self.password:match("^%$5%$rounds=([1-9][0-9]*)%$"))
 | 
| 
bsw@905
 | 
   354     
 | 
| 
bsw@905
 | 
   355   elseif config.password_hash_algorithm == "crypt_sha512" then
 | 
| 
bsw@905
 | 
   356 
 | 
| 
bsw@905
 | 
   357     return check_rounds(self.password:match("^%$6%$rounds=([1-9][0-9]*)%$"))
 | 
| 
bsw@905
 | 
   358 
 | 
| 
bsw@905
 | 
   359   else
 | 
| 
bsw@905
 | 
   360     error("Unknown hash algorithm selected in configuration")
 | 
| 
bsw@905
 | 
   361 
 | 
| 
bsw@905
 | 
   362   end
 | 
| 
bsw@905
 | 
   363   
 | 
| 
bsw@905
 | 
   364 end
 | 
| 
bsw@905
 | 
   365 
 | 
| 
bsw/jbe@0
 | 
   366 function Member.object_get:published_contacts()
 | 
| 
bsw/jbe@0
 | 
   367   return Member:new_selector()
 | 
| 
bsw/jbe@0
 | 
   368     :join('"contact"', nil, '"contact"."other_member_id" = "member"."id"')
 | 
| 
bsw/jbe@0
 | 
   369     :add_where{ '"contact"."member_id" = ?', self.id }
 | 
| 
bsw/jbe@0
 | 
   370     :add_where("public")
 | 
| 
bsw/jbe@0
 | 
   371     :exec()
 | 
| 
bsw/jbe@0
 | 
   372 end
 | 
| 
bsw/jbe@0
 | 
   373 
 | 
| 
bsw/jbe@0
 | 
   374 function Member:by_login_and_password(login, password)
 | 
| 
bsw/jbe@0
 | 
   375   local selector = self:new_selector()
 | 
| 
bsw@988
 | 
   376   selector:add_field({ "now() > COALESCE(last_delegation_check, activated) + ?::interval", config.check_delegations_interval_hard }, "needs_delegation_check_hard")
 | 
| 
bsw/jbe@5
 | 
   377   selector:add_where{'"login" = ?', login }
 | 
| 
bsw@203
 | 
   378   selector:add_where('NOT "locked"')
 | 
| 
bsw/jbe@0
 | 
   379   selector:optional_object_mode()
 | 
| 
bsw/jbe@0
 | 
   380   local member = selector:exec()
 | 
| 
bsw/jbe@0
 | 
   381   if member and member:check_password(password) then
 | 
| 
bsw/jbe@0
 | 
   382     return member
 | 
| 
bsw/jbe@0
 | 
   383   else
 | 
| 
bsw/jbe@0
 | 
   384     return nil
 | 
| 
bsw/jbe@0
 | 
   385   end
 | 
| 
bsw/jbe@0
 | 
   386 end
 | 
| 
bsw/jbe@0
 | 
   387 
 | 
| 
bsw/jbe@5
 | 
   388 function Member:by_login(login)
 | 
| 
bsw/jbe@5
 | 
   389   local selector = self:new_selector()
 | 
| 
bsw/jbe@5
 | 
   390   selector:add_where{'"login" = ?', login }
 | 
| 
bsw/jbe@5
 | 
   391   selector:optional_object_mode()
 | 
| 
bsw/jbe@5
 | 
   392   return selector:exec()
 | 
| 
bsw/jbe@5
 | 
   393 end
 | 
| 
bsw/jbe@5
 | 
   394 
 | 
| 
bsw/jbe@5
 | 
   395 function Member:by_name(name)
 | 
| 
bsw/jbe@5
 | 
   396   local selector = self:new_selector()
 | 
| 
bsw/jbe@5
 | 
   397   selector:add_where{'"name" = ?', name }
 | 
| 
bsw/jbe@5
 | 
   398   selector:optional_object_mode()
 | 
| 
bsw/jbe@5
 | 
   399   return selector:exec()
 | 
| 
bsw/jbe@5
 | 
   400 end
 | 
| 
bsw/jbe@5
 | 
   401 
 | 
| 
bsw@2
 | 
   402 function Member:get_search_selector(search_string)
 | 
| 
bsw/jbe@0
 | 
   403   return self:new_selector()
 | 
| 
bsw@2
 | 
   404     :add_field( {'"highlight"("member"."name", ?)', search_string }, "name_highlighted")
 | 
| 
bsw@2
 | 
   405     :add_where{ '"member"."text_search_data" @@ "text_search_query"(?)', search_string }
 | 
| 
bsw@362
 | 
   406     :add_where("activated NOTNULL AND active")
 | 
| 
bsw/jbe@0
 | 
   407 end
 | 
| 
bsw@2
 | 
   408 
 | 
| 
bsw@388
 | 
   409 function Member.object:send_invitation(template_file, subject)
 | 
| 
bsw@286
 | 
   410   trace.disable()
 | 
| 
bsw@286
 | 
   411   self.invite_code = multirand.string( 24, "23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz" )
 | 
| 
bsw@388
 | 
   412   self:save()
 | 
| 
bsw@388
 | 
   413   
 | 
| 
bsw@388
 | 
   414   local subject = subject
 | 
| 
bsw@388
 | 
   415   local content
 | 
| 
bsw@388
 | 
   416   
 | 
| 
bsw@388
 | 
   417   if template_file then
 | 
| 
bsw@388
 | 
   418     local fh = io.open(template_file, "r")
 | 
| 
bsw@388
 | 
   419     content = fh:read("*a")
 | 
| 
bsw@388
 | 
   420     content = (content:gsub("#{invite_code}", self.invite_code))
 | 
| 
bsw@388
 | 
   421   else
 | 
| 
bsw@388
 | 
   422     subject = config.mail_subject_prefix .. _"Invitation to LiquidFeedback"
 | 
| 
bsw@388
 | 
   423     content = slot.use_temporary(function()
 | 
| 
bsw@388
 | 
   424       slot.put(_"Hello\n\n")
 | 
| 
bsw@388
 | 
   425       slot.put(_"You are invited to LiquidFeedback. To register please click the following link:\n\n")
 | 
| 
bsw@388
 | 
   426       slot.put(request.get_absolute_baseurl() .. "index/register.html?invite=" .. self.invite_code .. "\n\n")
 | 
| 
bsw@388
 | 
   427       slot.put(_"If this link is not working, please open following url in your web browser:\n\n")
 | 
| 
bsw@388
 | 
   428       slot.put(request.get_absolute_baseurl() .. "index/register.html\n\n")
 | 
| 
bsw@388
 | 
   429       slot.put(_"On that page please enter the invite key:\n\n")
 | 
| 
bsw@388
 | 
   430       slot.put(self.invite_code .. "\n\n")
 | 
| 
bsw@388
 | 
   431     end)
 | 
| 
bsw@388
 | 
   432   end
 | 
| 
bsw@388
 | 
   433 
 | 
| 
bsw@286
 | 
   434   local success = net.send_mail{
 | 
| 
bsw@286
 | 
   435     envelope_from = config.mail_envelope_from,
 | 
| 
bsw@286
 | 
   436     from          = config.mail_from,
 | 
| 
bsw@286
 | 
   437     reply_to      = config.mail_reply_to,
 | 
| 
bsw@286
 | 
   438     to            = self.notify_email_unconfirmed or self.notify_email,
 | 
| 
bsw@388
 | 
   439     subject       = subject,
 | 
| 
bsw@286
 | 
   440     content_type  = "text/plain; charset=UTF-8",
 | 
| 
bsw@286
 | 
   441     content       = content
 | 
| 
bsw@286
 | 
   442   }
 | 
| 
bsw@286
 | 
   443   return success
 | 
| 
bsw/jbe@0
 | 
   444 end
 | 
| 
bsw@2
 | 
   445 
 | 
| 
bsw/jbe@6
 | 
   446 function Member.object:set_notify_email(notify_email)
 | 
| 
bsw@224
 | 
   447   trace.disable()
 | 
| 
bsw/jbe@6
 | 
   448   local expiry = db:query("SELECT now() + '7 days'::interval as expiry", "object").expiry
 | 
| 
bsw/jbe@6
 | 
   449   self.notify_email_unconfirmed = notify_email
 | 
| 
bsw/jbe@6
 | 
   450   self.notify_email_secret = multirand.string( 24, "23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz" )
 | 
| 
bsw/jbe@6
 | 
   451   self.notify_email_secret_expiry = expiry
 | 
| 
bsw/jbe@6
 | 
   452   local content = slot.use_temporary(function()
 | 
| 
bsw/jbe@6
 | 
   453     slot.put(_"Hello " .. self.name .. ",\n\n")
 | 
| 
bsw/jbe@6
 | 
   454     slot.put(_"Please confirm your email address by clicking the following link:\n\n")
 | 
| 
jbe@326
 | 
   455     slot.put(request.get_absolute_baseurl() .. "index/confirm_notify_email.html?secret=" .. self.notify_email_secret .. "\n\n")
 | 
| 
bsw/jbe@6
 | 
   456     slot.put(_"If this link is not working, please open following url in your web browser:\n\n")
 | 
| 
jbe@326
 | 
   457     slot.put(request.get_absolute_baseurl() .. "index/confirm_notify_email.html\n\n")
 | 
| 
bsw/jbe@6
 | 
   458     slot.put(_"On that page please enter the confirmation code:\n\n")
 | 
| 
bsw/jbe@6
 | 
   459     slot.put(self.notify_email_secret .. "\n\n")
 | 
| 
bsw/jbe@6
 | 
   460   end)
 | 
| 
bsw/jbe@6
 | 
   461   local success = net.send_mail{
 | 
| 
bsw/jbe@6
 | 
   462     envelope_from = config.mail_envelope_from,
 | 
| 
bsw/jbe@6
 | 
   463     from          = config.mail_from,
 | 
| 
bsw/jbe@6
 | 
   464     reply_to      = config.mail_reply_to,
 | 
| 
bsw/jbe@6
 | 
   465     to            = self.notify_email_unconfirmed,
 | 
| 
bsw/jbe@6
 | 
   466     subject       = config.mail_subject_prefix .. _"Email confirmation request",
 | 
| 
bsw/jbe@6
 | 
   467     content_type  = "text/plain; charset=UTF-8",
 | 
| 
bsw/jbe@6
 | 
   468     content       = content
 | 
| 
bsw/jbe@6
 | 
   469   }
 | 
| 
bsw@75
 | 
   470   if success then
 | 
| 
bsw@75
 | 
   471     local lock_expiry = db:query("SELECT now() + '1 hour'::interval AS lock_expiry", "object").lock_expiry
 | 
| 
bsw@75
 | 
   472     self.notify_email_lock_expiry = lock_expiry
 | 
| 
bsw@75
 | 
   473   end
 | 
| 
bsw@75
 | 
   474   self:save()
 | 
| 
bsw/jbe@6
 | 
   475   return success
 | 
| 
bsw/jbe@6
 | 
   476 end
 | 
| 
bsw@11
 | 
   477 
 | 
| 
bsw/jbe@19
 | 
   478 function Member.object:get_setting(key)
 | 
| 
bsw@79
 | 
   479   return Setting:by_pk(self.id, key)
 | 
| 
bsw/jbe@19
 | 
   480 end
 | 
| 
bsw/jbe@19
 | 
   481 
 | 
| 
bsw/jbe@19
 | 
   482 function Member.object:get_setting_value(key)
 | 
| 
bsw@79
 | 
   483   local setting = Setting:by_pk(self.id, key)
 | 
| 
bsw/jbe@19
 | 
   484   if setting then
 | 
| 
bsw/jbe@19
 | 
   485     return setting.value
 | 
| 
bsw/jbe@19
 | 
   486   end
 | 
| 
bsw@11
 | 
   487 end
 | 
| 
bsw@11
 | 
   488 
 | 
| 
bsw@11
 | 
   489 function Member.object:set_setting(key, value)
 | 
| 
bsw/jbe@19
 | 
   490   local setting = self:get_setting(key)
 | 
| 
bsw/jbe@19
 | 
   491   if not setting then
 | 
| 
bsw/jbe@19
 | 
   492     setting = Setting:new()
 | 
| 
bsw@79
 | 
   493     setting.member_id = self.id
 | 
| 
bsw/jbe@19
 | 
   494     setting.key = key
 | 
| 
bsw/jbe@19
 | 
   495   end
 | 
| 
bsw/jbe@19
 | 
   496   setting.value = value
 | 
| 
bsw/jbe@19
 | 
   497   setting:save()
 | 
| 
bsw@11
 | 
   498 end
 | 
| 
bsw@11
 | 
   499 
 | 
| 
bsw@11
 | 
   500 function Member.object:get_setting_maps_by_key(key)
 | 
| 
bsw@11
 | 
   501   return SettingMap:new_selector()
 | 
| 
bsw@11
 | 
   502     :add_where{ "member_id = ?", self.id }
 | 
| 
bsw@11
 | 
   503     :add_where{ "key = ?", key }
 | 
| 
bsw@11
 | 
   504     :add_order_by("subkey")
 | 
| 
bsw@11
 | 
   505     :exec()
 | 
| 
bsw@11
 | 
   506 end
 | 
| 
bsw@11
 | 
   507 
 | 
| 
bsw@11
 | 
   508 function Member.object:get_setting_map_by_key_and_subkey(key, subkey)
 | 
| 
bsw@11
 | 
   509   return SettingMap:new_selector()
 | 
| 
bsw@11
 | 
   510     :add_where{ "member_id = ?", self.id }
 | 
| 
bsw@11
 | 
   511     :add_where{ "key = ?", key }
 | 
| 
bsw@11
 | 
   512     :add_where{ "subkey = ?", subkey }
 | 
| 
bsw@11
 | 
   513     :add_order_by("subkey")
 | 
| 
bsw@11
 | 
   514     :optional_object_mode()
 | 
| 
bsw@11
 | 
   515     :exec()
 | 
| 
bsw@11
 | 
   516 end
 | 
| 
bsw@11
 | 
   517 
 | 
| 
bsw@11
 | 
   518 function Member.object:set_setting_map(key, subkey, value)
 | 
| 
poelzi@144
 | 
   519   setting_map = self:get_setting_map_by_key_and_subkey(key, subkey)
 | 
| 
poelzi@144
 | 
   520   if not setting_map then
 | 
| 
poelzi@144
 | 
   521     setting_map = SettingMap:new()
 | 
| 
poelzi@144
 | 
   522     setting_map.member_id = self.id
 | 
| 
poelzi@144
 | 
   523     setting_map.key = key
 | 
| 
poelzi@144
 | 
   524     setting_map.subkey = subkey
 | 
| 
poelzi@144
 | 
   525   end
 | 
| 
poelzi@144
 | 
   526   setting_map.value = value
 | 
| 
poelzi@144
 | 
   527   setting_map:save()
 | 
| 
bsw@11
 | 
   528 end
 | 
| 
bsw@75
 | 
   529 
 | 
| 
bsw@75
 | 
   530 function Member.object_get:notify_email_locked()
 | 
| 
bsw@75
 | 
   531   return(
 | 
| 
bsw@75
 | 
   532     Member:new_selector()
 | 
| 
bsw@75
 | 
   533       :add_where{ "id = ?", app.session.member.id }
 | 
| 
bsw@75
 | 
   534       :add_where("notify_email_lock_expiry > now()")
 | 
| 
bsw@75
 | 
   535       :count() == 1
 | 
| 
bsw@75
 | 
   536   )
 | 
| 
poelzi@134
 | 
   537 end
 | 
| 
poelzi@134
 | 
   538 
 | 
| 
bsw@273
 | 
   539 function Member.object_get:units_with_voting_right()
 | 
| 
bsw@273
 | 
   540   return(Unit:new_selector()
 | 
| 
bsw@273
 | 
   541     :join("privilege", nil, { "privilege.unit_id = unit.id AND privilege.member_id = ? AND privilege.voting_right", self.id })
 | 
| 
bsw@273
 | 
   542     :exec()
 | 
| 
bsw@273
 | 
   543   )
 | 
| 
bsw@273
 | 
   544 end
 | 
| 
bsw@273
 | 
   545 
 | 
| 
poelzi@134
 | 
   546 function Member.object:ui_field_text(args)
 | 
| 
poelzi@134
 | 
   547   args = args or {}
 | 
| 
bsw@813
 | 
   548   if app.session:has_access("authors_pseudonymous") then
 | 
| 
poelzi@134
 | 
   549     -- ugly workaround for getting html into a replaced string and to the user
 | 
| 
poelzi@134
 | 
   550     ui.container{label = args.label, label_attr={class="ui_field_label"}, content = function()
 | 
| 
poelzi@134
 | 
   551         slot.put(string.format('<span><a href="%s">%s</a></span>',
 | 
| 
poelzi@134
 | 
   552                                                 encode.url{
 | 
| 
poelzi@134
 | 
   553                                                   module    = "member",
 | 
| 
poelzi@134
 | 
   554                                                   view      = "show",
 | 
| 
poelzi@134
 | 
   555                                                   id        = self.id,
 | 
| 
poelzi@134
 | 
   556                                                 },
 | 
| 
poelzi@134
 | 
   557                                                 encode.html(self.name)))
 | 
| 
poelzi@134
 | 
   558       end
 | 
| 
poelzi@134
 | 
   559     }
 | 
| 
poelzi@134
 | 
   560   else
 | 
| 
poelzi@134
 | 
   561     ui.field.text{ label = args.label,      value = _"[not displayed public]" }
 | 
| 
poelzi@134
 | 
   562   end
 | 
| 
poelzi@134
 | 
   563 end
 | 
| 
bsw@281
 | 
   564 
 | 
| 
bsw@281
 | 
   565 function Member.object:has_voting_right_for_unit_id(unit_id)
 | 
| 
bsw@547
 | 
   566   if not self.__units_with_voting_right_hash then
 | 
| 
bsw@547
 | 
   567     local privileges = Privilege:new_selector()
 | 
| 
bsw@547
 | 
   568       :add_where{ "member_id = ?", self.id }
 | 
| 
bsw@547
 | 
   569       :add_where("voting_right")
 | 
| 
bsw@547
 | 
   570       :exec()
 | 
| 
bsw@547
 | 
   571     self.__units_with_voting_right_hash = {}
 | 
| 
bsw@551
 | 
   572     for i, privilege in ipairs(privileges) do
 | 
| 
bsw@551
 | 
   573       self.__units_with_voting_right_hash[privilege.unit_id] = true
 | 
| 
bsw@551
 | 
   574     end
 | 
| 
bsw@547
 | 
   575   end
 | 
| 
bsw@547
 | 
   576   return self.__units_with_voting_right_hash[unit_id] and true or false
 | 
| 
jbe@326
 | 
   577 end
 | 
| 
bsw@525
 | 
   578 
 | 
| 
bsw@894
 | 
   579 function Member.object:has_polling_right_for_unit_id(unit_id)
 | 
| 
bsw@894
 | 
   580   if not self.__units_with_polling_right_hash then
 | 
| 
bsw@894
 | 
   581     local privileges = Privilege:new_selector()
 | 
| 
bsw@894
 | 
   582       :add_where{ "member_id = ?", self.id }
 | 
| 
bsw@894
 | 
   583       :add_where("polling_right")
 | 
| 
bsw@894
 | 
   584       :exec()
 | 
| 
bsw@894
 | 
   585     self.__units_with_polling_right_hash = {}
 | 
| 
bsw@894
 | 
   586     for i, privilege in ipairs(privileges) do
 | 
| 
bsw@894
 | 
   587       self.__units_with_polling_right_hash[privilege.unit_id] = true
 | 
| 
bsw@894
 | 
   588     end
 | 
| 
bsw@894
 | 
   589   end
 | 
| 
bsw@894
 | 
   590   return self.__units_with_polling_right_hash[unit_id] and true or false
 | 
| 
bsw@894
 | 
   591 end
 | 
| 
bsw@894
 | 
   592 
 | 
| 
bsw@525
 | 
   593 function Member.object:get_delegatee_member(unit_id, area_id, issue_id)
 | 
| 
bsw@525
 | 
   594   local selector = Member:new_selector()
 | 
| 
bsw@525
 | 
   595   if unit_id then
 | 
| 
bsw@525
 | 
   596     selector:join("delegation", nil, { "delegation.trustee_id = member.id AND delegation.scope = 'unit' AND delegation.unit_id = ? AND delegation.truster_id = ?", unit_id, self.id })
 | 
| 
bsw@525
 | 
   597   end
 | 
| 
bsw@525
 | 
   598   selector:optional_object_mode()
 | 
| 
bsw@525
 | 
   599   return selector:exec()
 | 
| 
bsw@533
 | 
   600 end
 | 
| 
bsw@929
 | 
   601 
 |