Merge stable changes to next-stable.

This commit is contained in:
Nate Coraor
2014-12-03 13:30:44 -05:00
9 changed files with 125 additions and 166 deletions
+77 -66
View File
@@ -28,7 +28,7 @@ from galaxy.web.base.controller import CreatesUsersMixin
from galaxy.web.base.controller import CreatesApiKeysMixin
from galaxy.web.form_builder import CheckboxField
from galaxy.web.form_builder import build_select_field
from galaxy.web.framework.helpers import time_ago, grids
from galaxy.web.framework.helpers import time_ago, grids, escape
from datetime import datetime, timedelta
from galaxy.util import hash_util, biostar
@@ -164,7 +164,7 @@ class User( BaseUIController, UsesFormDefinitionsMixin, CreatesUsersMixin, Creat
user_openid.provider = openid_provider
if trans.user:
if user_openid.user and user_openid.user.id != trans.user.id:
message = "The OpenID <strong>%s</strong> is already associated with another Galaxy account, <strong>%s</strong>. Please disassociate it from that account before attempting to associate it with a new account." % ( display_identifier, user_openid.user.email )
message = "The OpenID <strong>%s</strong> is already associated with another Galaxy account, <strong>%s</strong>. Please disassociate it from that account before attempting to associate it with a new account." % ( escape( display_identifier ), escape( user_openid.user.email ) )
if not trans.user.active and trans.app.config.user_activation_on: # Account activation is ON and the user is INACTIVE.
if ( trans.app.config.activation_grace_period != 0 ): # grace period is ON
if self.is_outside_grace_period( trans, trans.user.create_time ): # User is outside the grace period. Login is disabled and he will have the activation email resent.
@@ -179,23 +179,23 @@ class User( BaseUIController, UsesFormDefinitionsMixin, CreatesUsersMixin, Creat
user_openid.session = trans.galaxy_session
if not openid_provider_obj.never_associate_with_user:
if not auto_associate and ( user_openid.user and user_openid.user.id == trans.user.id ):
message = "The OpenID <strong>%s</strong> is already associated with your Galaxy account, <strong>%s</strong>." % ( display_identifier, trans.user.email )
message = "The OpenID <strong>%s</strong> is already associated with your Galaxy account, <strong>%s</strong>." % ( escape( display_identifier ), escape( trans.user.email ) )
status = "warning"
else:
message = "The OpenID <strong>%s</strong> has been associated with your Galaxy account, <strong>%s</strong>." % ( display_identifier, trans.user.email )
message = "The OpenID <strong>%s</strong> has been associated with your Galaxy account, <strong>%s</strong>." % ( escape( display_identifier ), escape( trans.user.email ) )
status = "done"
user_openid.user = trans.user
trans.sa_session.add( user_openid )
trans.sa_session.flush()
trans.log_event( "User associated OpenID: %s" % display_identifier )
else:
message = "The OpenID <strong>%s</strong> cannot be used to log into your Galaxy account, but any post authentication actions have been performed." % ( openid_provider_obj.name )
message = "The OpenID <strong>%s</strong> cannot be used to log into your Galaxy account, but any post authentication actions have been performed." % escape( openid_provider_obj.name )
status = "info"
openid_provider_obj.post_authentication( trans, trans.app.openid_manager, info )
if redirect:
message = '%s<br>Click <a href="%s"><strong>here</strong></a> to return to the page you were previously viewing.' % ( message, redirect )
message = '%s<br>Click <a href="%s"><strong>here</strong></a> to return to the page you were previously viewing.' % ( message, escape( self.__get_redirect_url( redirect ) ) )
if redirect and status != "error":
return trans.response.send_redirect( redirect )
return trans.response.send_redirect( self.__get_redirect_url( redirect ) )
return trans.response.send_redirect( url_for( controller='user',
action='openid_manage',
use_panels=True,
@@ -208,6 +208,7 @@ class User( BaseUIController, UsesFormDefinitionsMixin, CreatesUsersMixin, Creat
openid_provider_obj.post_authentication( trans, trans.app.openid_manager, info )
if not redirect:
redirect = url_for( '/' )
redirect = self.__get_redirect_url( redirect )
return trans.response.send_redirect( redirect )
trans.sa_session.add( user_openid )
trans.sa_session.flush()
@@ -448,18 +449,9 @@ class User( BaseUIController, UsesFormDefinitionsMixin, CreatesUsersMixin, Creat
@web.expose
def login( self, trans, refresh_frames=[], **kwd ):
"""Handle Galaxy login"""
redirect = kwd.get( 'redirect', trans.request.referer ).strip()
root_url = url_for( '/', qualified=True )
# Always start with redirect_url being empty.
redirect_url = ''
# Compare urls, to prevent a redirect from pointing (directly)
# outside of galaxy or to enter a logout/login loop.
if not util.compare_urls( root_url, redirect, compare_path=False ) or util.compare_urls( url_for( controller='user', action='logout', qualified=True ), redirect ):
redirect = root_url
if kwd.get( 'noredirect', False ):
# The referrer is explicitly asking not to redirect.
redirect = ''
'''Handle Galaxy Log in'''
redirect = self.__get_redirect_url( kwd.get( 'redirect', trans.request.referer ).strip() )
redirect_url = '' # always start with redirect_url being empty
use_panels = util.string_as_bool( kwd.get( 'use_panels', False ) )
message = kwd.get( 'message', '' )
status = kwd.get( 'status', 'done' )
@@ -910,7 +902,7 @@ class User( BaseUIController, UsesFormDefinitionsMixin, CreatesUsersMixin, Creat
username = util.restore_text( params.get( 'username', '' ) )
if not username:
username = user.username
message = util.restore_text( params.get( 'message', '' ) )
message = escape( util.restore_text( params.get( 'message', '' ) ) )
status = params.get( 'status', 'done' )
if trans.webapp.name == 'galaxy':
user_type_form_definition = self.__get_user_type_form_definition( trans, user=user, **kwd )
@@ -1119,8 +1111,8 @@ class User( BaseUIController, UsesFormDefinitionsMixin, CreatesUsersMixin, Creat
"""Reset the user's password. Send an email with the new password."""
if trans.app.config.smtp_server is None:
return trans.show_error_message( "Mail is not configured for this Galaxy instance. Please contact your local Galaxy administrator." )
message = util.sanitize_text( util.restore_text( kwd.get( 'message', '' ) ) )
status = 'done'
message = util.sanitize_text(util.restore_text( kwd.get( 'message', '' ) ))
status = kwd.get( 'status', 'done' )
if kwd.get( 'reset_password_button', False ):
reset_user = trans.sa_session.query( trans.app.model.User ).filter( trans.app.model.User.table.c.email == email ).first()
user = trans.get_user()
@@ -1146,7 +1138,7 @@ class User( BaseUIController, UsesFormDefinitionsMixin, CreatesUsersMixin, Creat
trans.sa_session.add( reset_user )
trans.sa_session.flush()
trans.log_event( "User reset password: %s" % email )
message = "Password has been reset and emailed to: %s. <a href='%s'>Click here</a> to return to the login form." % ( email, web.url_for( controller='user', action='login', noredirect='true' ) )
message = "Password has been reset and emailed to: %s. <a href='%s'>Click here</a> to return to the login form." % ( escape( email ), web.url_for( controller='user', action='login', noredirect='true' ) )
except Exception, e:
message = 'Failed to reset password: %s' % str( e )
status = 'error'
@@ -1370,17 +1362,20 @@ class User( BaseUIController, UsesFormDefinitionsMixin, CreatesUsersMixin, Creat
# User not logged in, history group must be only public
return trans.show_error_message( "You must be logged in to change your default permitted actions." )
@web.require_login( "to add addresses" )
@web.expose
def new_address( self, trans, cntrller, **kwd ):
params = util.Params( kwd )
message = util.restore_text( params.get( 'message', '' ) )
status = params.get( 'status', 'done' )
is_admin = cntrller == 'admin' and trans.user_is_admin()
user_id = params.get( 'user_id', False )
if not user_id:
# User must be logged in to create a new address
return trans.show_error_message( "You must be logged in to create a new address." )
user = trans.sa_session.query( trans.app.model.User ).get( trans.security.decode_id( user_id ) )
user_id = params.get( 'id', False )
if is_admin:
if not user_id:
return trans.show_error_message( "You must specify a user to add a new address to." )
user = trans.sa_session.query( trans.app.model.User ).get( trans.security.decode_id( user_id ) )
else:
user = trans.user
short_desc = util.restore_text( params.get( 'short_desc', '' ) )
name = util.restore_text( params.get( 'name', '' ) )
institution = util.restore_text( params.get( 'institution', '' ) )
@@ -1431,10 +1426,10 @@ class User( BaseUIController, UsesFormDefinitionsMixin, CreatesUsersMixin, Creat
phone=phone )
trans.sa_session.add( user_address )
trans.sa_session.flush()
message = 'Address (%s) has been added' % user_address.desc
message = 'Address (%s) has been added' % escape( user_address.desc )
new_kwd = dict( message=message, status=status )
if is_admin:
new_kwd[ 'user_id' ] = trans.security.encode_id( user.id )
new_kwd[ 'id' ] = trans.security.encode_id( user.id )
return trans.response.send_redirect( web.url_for( controller='user',
action='manage_user_info',
cntrller=cntrller,
@@ -1452,24 +1447,29 @@ class User( BaseUIController, UsesFormDefinitionsMixin, CreatesUsersMixin, Creat
postal_code=postal_code,
country=country,
phone=phone,
message=message,
message=escape(message),
status=status )
@web.require_login( "to edit addresses" )
@web.expose
def edit_address( self, trans, cntrller, **kwd ):
params = util.Params( kwd )
message = util.restore_text( params.get( 'message', '' ) )
status = params.get( 'status', 'done' )
is_admin = cntrller == 'admin' and trans.user_is_admin()
user_id = params.get( 'user_id', False )
if not user_id:
# User must be logged in to create a new address
return trans.show_error_message( "You must be logged in to create a new address." )
user = trans.sa_session.query( trans.app.model.User ).get( trans.security.decode_id( user_id ) )
user_id = params.get( 'id', False )
if is_admin:
if not user_id:
return trans.show_error_message( "You must specify a user to add a new address to." )
user = trans.sa_session.query( trans.app.model.User ).get( trans.security.decode_id( user_id ) )
else:
user = trans.user
address_id = params.get( 'address_id', None )
if not address_id:
return trans.show_error_message( "No address id received for editing." )
return trans.show_error_message( "Invalid address id." )
address_obj = trans.sa_session.query( trans.app.model.UserAddress ).get( trans.security.decode_id( address_id ) )
if address_obj.user_id != user.id:
return trans.show_error_message( "Invalid address id." )
if params.get( 'edit_address_button', False ):
short_desc = util.restore_text( params.get( 'short_desc', '' ) )
name = util.restore_text( params.get( 'name', '' ) )
@@ -1517,10 +1517,10 @@ class User( BaseUIController, UsesFormDefinitionsMixin, CreatesUsersMixin, Creat
address_obj.phone = phone
trans.sa_session.add( address_obj )
trans.sa_session.flush()
message = 'Address (%s) has been updated.' % address_obj.desc
message = 'Address (%s) has been updated.' % escape( address_obj.desc )
new_kwd = dict( message=message, status=status )
if is_admin:
new_kwd[ 'user_id' ] = trans.security.encode_id( user.id )
new_kwd[ 'id' ] = trans.security.encode_id( user.id )
return trans.response.send_redirect( web.url_for( controller='user',
action='manage_user_info',
cntrller=cntrller,
@@ -1530,45 +1530,44 @@ class User( BaseUIController, UsesFormDefinitionsMixin, CreatesUsersMixin, Creat
cntrller=cntrller,
user=user,
address_obj=address_obj,
message=message,
message=escape( message ),
status=status )
@web.require_login( "to delete addresses" )
@web.expose
def delete_address( self, trans, cntrller, address_id=None, user_id=None ):
def delete_address( self, trans, cntrller, address_id=None, **kwd ):
return self.__delete_undelete_address( trans, cntrller, 'delete', address_id=address_id, **kwd )
@web.require_login( "to undelete addresses" )
@web.expose
def undelete_address( self, trans, cntrller, address_id=None, **kwd ):
return self.__delete_undelete_address( trans, cntrller, 'undelete', address_id=address_id, **kwd )
def __delete_undelete_address( self, trans, cntrller, op, address_id=None, **kwd ):
is_admin = cntrller == 'admin' and trans.user_is_admin()
user_id = kwd.get( 'id', False )
if is_admin:
if not user_id:
return trans.show_error_message( "You must specify a user to %s an address from." % op )
user = trans.sa_session.query( trans.app.model.User ).get( trans.security.decode_id( user_id ) )
else:
user = trans.user
try:
user_address = trans.sa_session.query( trans.app.model.UserAddress ).get( trans.security.decode_id( address_id ) )
except:
message = 'Invalid address is (%s)' % address_id
status = 'error'
return trans.show_error_message( "Invalid address id." )
if user_address:
user_address.deleted = True
if user_address.user_id != user.id:
return trans.show_error_message( "Invalid address id." )
user_address.deleted = True if op == 'delete' else False
trans.sa_session.add( user_address )
trans.sa_session.flush()
message = 'Address (%s) deleted' % user_address.desc
message = 'Address (%s) %sd' % ( escape( user_address.desc ), op )
status = 'done'
return trans.response.send_redirect( web.url_for( controller='user',
action='manage_user_info',
cntrller=cntrller,
user_id=user_id,
message=message,
status=status ) )
@web.expose
def undelete_address( self, trans, cntrller, address_id=None, user_id=None ):
try:
user_address = trans.sa_session.query( trans.app.model.UserAddress ).get( trans.security.decode_id( address_id ) )
except:
message = 'Invalid address is (%s)' % address_id
status = 'error'
if user_address:
user_address.deleted = False
trans.sa_session.flush()
message = 'Address (%s) undeleted' % user_address.desc
status = 'done'
return trans.response.send_redirect( web.url_for( controller='user',
action='manage_user_info',
cntrller=cntrller,
user_id=user_id,
id=trans.security.encode_id( user.id ),
message=message,
status=status ) )
@@ -1728,7 +1727,7 @@ class User( BaseUIController, UsesFormDefinitionsMixin, CreatesUsersMixin, Creat
@web.require_login()
def api_keys( self, trans, cntrller, **kwd ):
params = util.Params( kwd )
message = util.restore_text( params.get( 'message', '' ) )
message = escape( util.restore_text( params.get( 'message', '' ) ) )
status = params.get( 'status', 'done' )
if params.get( 'new_api_key_button', False ):
self.create_api_key( trans, trans.user )
@@ -1740,6 +1739,18 @@ class User( BaseUIController, UsesFormDefinitionsMixin, CreatesUsersMixin, Creat
message=message,
status=status )
def __get_redirect_url( self, redirect ):
root_url = url_for( '/', qualified=True )
redirect_url = '' # always start with redirect_url being empty
# compare urls, to prevent a redirect from pointing (directly) outside of galaxy
# or to enter a logout/login loop
if not util.compare_urls( root_url, redirect, compare_path=False ) or util.compare_urls( url_for( controller='user', action='logout', qualified=True ), redirect ):
log.warning('Redirect URL is outside of Galaxy, will redirect to Galaxy root instead: %s', redirect)
redirect = root_url
elif util.compare_urls( url_for( controller='user', action='logout', qualified=True ), redirect ):
redirect = root_url
return redirect
# ===== Methods for building SelectFields ================================
def __build_user_type_fd_id_select_field( self, trans, selected_value ):
# Get all the user information forms
@@ -3,12 +3,11 @@ Contains the user interface in the Universe class
"""
import logging
import pprint
from galaxy import web
from galaxy import util, model
from galaxy.web.base.controller import BaseUIController, UsesFormDefinitionsMixin
from galaxy.web.framework.helpers import time_ago, grids
from galaxy.web.framework.helpers import time_ago, grids, escape
from inspect import getmembers
@@ -21,65 +20,46 @@ require_login_template = """
<p/>
"""
class UserOpenIDGrid( grids.Grid ):
use_panels = False
title = "OpenIDs linked to your account"
model_class = model.UserOpenID
template = '/user/openid_manage.mako'
default_filter = { "openid" : "All" }
default_sort_key = "-create_time"
columns = [
grids.TextColumn( "OpenID URL", key="openid", link=( lambda x: dict( action='openid_auth', login_button="Login", openid_url=x.openid if not x.provider else '', openid_provider=x.provider, auto_associate=True ) ) ),
grids.GridColumn( "Created", key="create_time", format=time_ago ),
]
operations = [
grids.GridOperation( "Delete", async_compatible=True ),
]
def build_initial_query( self, trans, **kwd ):
return trans.sa_session.query( self.model_class ).filter( self.model_class.user_id == trans.user.id )
# FIXME: This controller is using unencoded IDs, but I am not going to address
# this now since it is admin-side and should be reimplemented in the API
# anyway.
class User( BaseUIController, UsesFormDefinitionsMixin ):
user_openid_grid = UserOpenIDGrid()
installed_len_files = None
@web.expose
@web.require_login()
@web.require_admin
def index( self, trans, cntrller, **kwd ):
return trans.fill_template( 'webapps/galaxy/user/list_users.mako', action='all_users', cntrller=cntrller )
@web.expose
@web.require_login()
@web.require_admin
def admin_api_keys( self, trans, cntrller, uid, **kwd ):
params = util.Params( kwd )
message = util.restore_text( params.get( 'message', '' ) )
message = escape( util.restore_text( params.get( 'message', '' ) ) )
status = params.get( 'status', 'done' )
uid = params.get('uid', uid)
pprint.pprint(uid)
if params.get( 'new_api_key_button', False ):
new_key = trans.app.model.APIKeys()
new_key.user_id = uid
new_key.key = trans.app.security.get_new_guid()
trans.sa_session.add( new_key )
trans.sa_session.flush()
message = "Generated a new web API key"
message = "A new web API key has been generated for (%s)" % escape( new_key.user.email )
status = "done"
return trans.fill_template( 'webapps/galaxy/user/ok_admin_api_keys.mako',
cntrller=cntrller,
message=message,
status=status )
return trans.response.send_redirect( web.url_for( controller='userskeys',
action='all_users',
cntrller=cntrller,
message=message,
status=status ) )
@web.expose
@web.require_login()
@web.require_admin
def all_users( self, trans, cntrller="userskeys", **kwd ):
params = util.Params( kwd )
message = util.restore_text( params.get( 'message', '' ) )
message = escape( util.restore_text( params.get( 'message', '' ) ) )
status = params.get( 'status', 'done' )
users = []
for user in trans.sa_session.query( trans.app.model.User ) \
+11 -11
View File
@@ -10,17 +10,17 @@
<ul class="manage-table-actions">
<li>
<a class="action-button" href="${h.url_for( controller='user', action='manage_user_info', cntrller=cntrller, user_id=trans.security.encode_id( user.id) )}">Manage user information</a>
<a class="action-button" href="${h.url_for( controller='user', action='manage_user_info', cntrller=cntrller, id=trans.security.encode_id( user.id) )}">Manage user information</a>
</li>
</ul>
<div class="toolForm">
<div class="toolFormTitle">Edit address</div>
<div class="toolFormBody">
<form name="login_info" id="login_info" action="${h.url_for( controller='user', action='edit_address', cntrller=cntrller, address_id=trans.security.encode_id( address_obj.id ), user_id=trans.security.encode_id( user.id ) )}" method="post" >
<form name="login_info" id="login_info" action="${h.url_for( controller='user', action='edit_address', cntrller=cntrller, address_id=trans.security.encode_id( address_obj.id ), id=trans.security.encode_id( user.id ) )}" method="post" >
<div class="form-row">
<label>Short Description:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="short_desc" value="${address_obj.desc}" size="40">
<input type="text" name="short_desc" value="${address_obj.desc | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -28,7 +28,7 @@
<div class="form-row">
<label>Name:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="name" value="${address_obj.name}" size="40">
<input type="text" name="name" value="${address_obj.name | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -36,7 +36,7 @@
<div class="form-row">
<label>Institution:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="institution" value="${address_obj.institution}" size="40">
<input type="text" name="institution" value="${address_obj.institution | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -44,7 +44,7 @@
<div class="form-row">
<label>Address:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="address" value="${address_obj.address}" size="40">
<input type="text" name="address" value="${address_obj.address | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -52,7 +52,7 @@
<div class="form-row">
<label>City:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="city" value="${address_obj.city}" size="40">
<input type="text" name="city" value="${address_obj.city | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -60,7 +60,7 @@
<div class="form-row">
<label>State/Province/Region:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="state" value="${address_obj.state}" size="40">
<input type="text" name="state" value="${address_obj.state | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -68,7 +68,7 @@
<div class="form-row">
<label>Postal Code:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="postal_code" value="${address_obj.postal_code}" size="40">
<input type="text" name="postal_code" value="${address_obj.postal_code | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -76,7 +76,7 @@
<div class="form-row">
<label>Country:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="country" value="${address_obj.country}" size="40">
<input type="text" name="country" value="${address_obj.country | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -84,7 +84,7 @@
<div class="form-row">
<label>Phone:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="phone" value="${address_obj.phone}" size="40">
<input type="text" name="phone" value="${address_obj.phone | h}" size="40">
</div>
<div style="clear: both"></div>
</div>
-5
View File
@@ -1,9 +1,4 @@
<%inherit file="/base.mako"/>
<%namespace file="/message.mako" import="render_msg" />
%if message:
${render_msg( message, status )}
%endif
%if trans.user:
<h2>${_('User preferences')}</h2>
+5 -5
View File
@@ -90,7 +90,7 @@
<div class="toolFormTitle">Login Information</div>
<div class="form-row">
<label>Email address:</label>
<input type="text" id ="email_input" name="email" value="${email}" size="40"/>
<input type="text" id ="email_input" name="email" value="${email | h}" size="40"/>
<div class="toolParamHelp" style="clear: both;">
If you change your email address you will receive an activation link in the new mailbox and you have to activate your account by visiting it.
</div>
@@ -99,13 +99,13 @@
<label>Public name:</label>
%if t.webapp.name == 'tool_shed':
%if user.active_repositories:
<input type="hidden" name="username" value="${username}"/>
${username}
<input type="hidden" name="username" value="${username | h}"/>
${username | h}
<div class="toolParamHelp" style="clear: both;">
You cannot change your public name after you have created a repository in this tool shed.
</div>
%else:
<input type="text" name="username" size="40" value="${username}"/>
<input type="text" name="username" size="40" value="${username | h}"/>
<div class="toolParamHelp" style="clear: both;">
Your public name provides a means of identifying you publicly within this tool shed. Public
names must be at least four characters in length and contain only lower-case letters, numbers,
@@ -114,7 +114,7 @@
</div>
%endif
%else:
<input type="text" id="name_input" name="username" size="40" value="${username}"/>
<input type="text" id="name_input" name="username" size="40" value="${username | h}"/>
<div class="toolParamHelp" style="clear: both;">
Your public name is an optional identifier that will be used to generate addresses for information
you share publicly. Public names must be at least four characters in length and contain only lower-case
+11 -11
View File
@@ -10,18 +10,18 @@
<ul class="manage-table-actions">
<li>
<a class="action-button" href="${h.url_for( controller='user', action='manage_user_info', cntrller=cntrller, user_id=trans.security.encode_id( user.id) )}">
<a class="action-button" href="${h.url_for( controller='user', action='manage_user_info', cntrller=cntrller, id=trans.security.encode_id( user.id) )}">
<span>Manage User Information</span></a>
</li>
</ul>
<div class="toolForm">
<div class="toolFormTitle">Add new address</div>
<div class="toolFormBody">
<form name="login_info" id="login_info" action="${h.url_for( controller='user', action='new_address', cntrller=cntrller, user_id=trans.security.encode_id( user.id ) )}" method="post" >
<form name="login_info" id="login_info" action="${h.url_for( controller='user', action='new_address', cntrller=cntrller, id=trans.security.encode_id( user.id ) )}" method="post" >
<div class="form-row">
<label>Short Description:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="short_desc" value="${short_desc}" size="40">
<input type="text" name="short_desc" value="${short_desc | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -29,7 +29,7 @@
<div class="form-row">
<label>Name:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="name" value="${name}" size="40">
<input type="text" name="name" value="${name | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -37,7 +37,7 @@
<div class="form-row">
<label>Institution:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="institution" value="${institution}" size="40">
<input type="text" name="institution" value="${institution | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -45,7 +45,7 @@
<div class="form-row">
<label>Address:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="address" value="${address}" size="40">
<input type="text" name="address" value="${address | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -53,7 +53,7 @@
<div class="form-row">
<label>City:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="city" value="${city}" size="40">
<input type="text" name="city" value="${city | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -61,7 +61,7 @@
<div class="form-row">
<label>State/Province/Region:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="state" value="${state}" size="40">
<input type="text" name="state" value="${state | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -69,7 +69,7 @@
<div class="form-row">
<label>Postal Code:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="postal_code" value="${postal_code}" size="40">
<input type="text" name="postal_code" value="${postal_code | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -77,7 +77,7 @@
<div class="form-row">
<label>Country:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="country" value="${country}" size="40">
<input type="text" name="country" value="${country | h}" size="40">
</div>
<div class="toolParamHelp" style="clear: both;">Required</div>
<div style="clear: both"></div>
@@ -85,7 +85,7 @@
<div class="form-row">
<label>Phone:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="phone" value="${phone}" size="40">
<input type="text" name="phone" value="${phone | h}" size="40">
</div>
<div style="clear: both"></div>
</div>
@@ -1,4 +1,5 @@
<%inherit file="/base.mako"/>
<%namespace file="/message.mako" import="render_msg" />
%if message:
${render_msg( message, status )}
@@ -42,7 +42,7 @@ ${render_user_info()}
<p/>
<div class="toolForm">
<form name="user_addresses" id="user_addresses" action="${h.url_for( controller='user', action='new_address', cntrller=cntrller, user_id=trans.security.encode_id( user.id ) )}" method="post" >
<form name="user_addresses" id="user_addresses" action="${h.url_for( controller='user', action='new_address', cntrller=cntrller, id=trans.security.encode_id( user.id ) )}" method="post" >
<div class="toolFormTitle">User Addresses</div>
<div class="toolFormBody">
%if user.addresses:
@@ -53,9 +53,9 @@ ${render_user_info()}
<span>|</span>
%endif
%if show_filter == filter:
<span class="filter"><a href="${h.url_for( controller='user', action='manage_user_info', cntrller=cntrller, show_filter=filter, user_id=trans.security.encode_id( user.id ) )}"><b>${filter}</b></a></span>
<span class="filter"><a href="${h.url_for( controller='user', action='manage_user_info', cntrller=cntrller, show_filter=filter, id=trans.security.encode_id( user.id ) )}"><b>${filter}</b></a></span>
%else:
<span class="filter"><a href="${h.url_for( controller='user', action='manage_user_info', cntrller=cntrller, show_filter=filter, user_id=trans.security.encode_id( user.id ) )}">${filter}</a></span>
<span class="filter"><a href="${h.url_for( controller='user', action='manage_user_info', cntrller=cntrller, show_filter=filter, id=trans.security.encode_id( user.id ) )}">${filter}</a></span>
%endif
%endfor
</div>
@@ -73,10 +73,10 @@ ${render_user_info()}
<ul class="manage-table-actions">
<li>
%if not address.deleted:
<a class="action-button" href="${h.url_for( controller='user', action='edit_address', cntrller=cntrller, address_id=trans.security.encode_id( address.id ), user_id=trans.security.encode_id( user.id ) )}">Edit</a>
<a class="action-button" href="${h.url_for( controller='user', action='delete_address', cntrller=cntrller, address_id=trans.security.encode_id( address.id ), user_id=trans.security.encode_id( user.id ) )}">Delete</a>
<a class="action-button" href="${h.url_for( controller='user', action='edit_address', cntrller=cntrller, address_id=trans.security.encode_id( address.id ), id=trans.security.encode_id( user.id ) )}">Edit</a>
<a class="action-button" href="${h.url_for( controller='user', action='delete_address', cntrller=cntrller, address_id=trans.security.encode_id( address.id ), id=trans.security.encode_id( user.id ) )}">Delete</a>
%else:
<a class="action-button" href="${h.url_for( controller='user', action='undelete_address', cntrller=cntrller, address_id=trans.security.encode_id( address.id ), user_id=trans.security.encode_id( user.id ) )}">Undelete</a>
<a class="action-button" href="${h.url_for( controller='user', action='undelete_address', cntrller=cntrller, address_id=trans.security.encode_id( address.id ), id=trans.security.encode_id( user.id ) )}">Undelete</a>
%endif
</li>
</ul>
@@ -1,28 +0,0 @@
<%inherit file="/base.mako"/>
<%namespace file="/message.mako" import="render_msg" />
<br/><br/>
<ul class="manage-table-actions">
<li>
<a class="action-button" href="${h.url_for( controller='userskeys', action='all_users', cntrller=cntrller )}">List users API keys</a>
</li>
</ul>
%if message:
${render_msg( message, status )}
%endif
<div>
<div style="clear: both;">
SUCCESS. A new API key has been generated.
</div>
<div style="clear: both;">
An API key will allow you to access Galaxy via its web
API (documentation forthcoming). Please note that
<strong>this key acts as an alternate means to access
your account, and should be treated with the same care
as your login password</strong>.
</div>
</div>