Compare commits

...

7 Commits

3 changed files with 46 additions and 42 deletions
+20 -21
View File
@@ -18,7 +18,6 @@ Features:
""" """
from flask import Flask, render_template, request, redirect, url_for, session, flash, send_from_directory, get_flashed_messages, jsonify, Response, make_response, send_file, abort from flask import Flask, render_template, request, redirect, url_for, session, flash, send_from_directory, get_flashed_messages, jsonify, Response, make_response, send_file, abort
from flask_wtf.csrf import CSRFProtect
from werkzeug.utils import secure_filename from werkzeug.utils import secure_filename
from werkzeug.middleware.proxy_fix import ProxyFix from werkzeug.middleware.proxy_fix import ProxyFix
from werkzeug.exceptions import HTTPException from werkzeug.exceptions import HTTPException
@@ -116,7 +115,6 @@ app.config['PREFERRED_URL_SCHEME'] = 'https' if app.config['SESSION_COOKIE_SECUR
# app.config['QR_CODE_FOLDER'] = cfg.QR_CODE_FOLDER # QR Code storage deactivated # app.config['QR_CODE_FOLDER'] = cfg.QR_CODE_FOLDER # QR Code storage deactivated
app.wsgi_app = ProxyFix(app.wsgi_app, x_for=1, x_proto=1, x_host=1, x_port=1) app.wsgi_app = ProxyFix(app.wsgi_app, x_for=1, x_proto=1, x_host=1, x_port=1)
app.register_blueprint(terminplaner_bp, url_prefix='/terminplaner') app.register_blueprint(terminplaner_bp, url_prefix='/terminplaner')
csrf = CSRFProtect(app)
"""--------------------------------------------------------------Path Init-------------------------------------------------------""" """--------------------------------------------------------------Path Init-------------------------------------------------------"""
@@ -3607,24 +3605,25 @@ def api_item_detail(item_id):
borrows_html = '' borrows_html = ''
if borrow_records: if borrow_records:
rows = [] rows = []
for rec in borrow_records: while len(rows) < 3:
user_raw = rec.get('User') for rec in borrow_records:
try: user_raw = rec.get('User')
user = decrypt_text(user_raw) if user_raw is not None else '' try:
except Exception: user = decrypt_text(user_raw) if user_raw is not None else ''
user = user_raw except Exception:
status = rec.get('Status', '') user = user_raw
start = fmt_dt(rec.get('Start')) status = rec.get('Status', '')
end = fmt_dt(rec.get('End')) start = fmt_dt(rec.get('Start'))
notes = html.escape(str(rec.get('Notes') or '')) end = fmt_dt(rec.get('End'))
notes = html.escape(str(rec.get('Notes') or ''))
rows.append(
f"<li><strong>{html.escape(str(user or '-'))}</strong> — " rows.append(
f"{html.escape(str(status))}" f"<li><strong>{html.escape(str(user or '-'))}</strong>"
f"{html.escape(str(start))} {html.escape(str(end))}" f"{html.escape(str(status))} "
f"{('' + notes) if notes else ''}</li>" f"{html.escape(str(start))}{html.escape(str(end))}"
) f"{('' + notes) if notes else ''}</li>"
borrows_html = f"<h3>Ausleihhistorie</h3><ul>{''.join(rows)}</ul>" )
borrows_html = f"<h3>Ausleihhistorie</h3><ul>{''.join(rows)}</ul>"
detail_html = f""" detail_html = f"""
<h2>{html.escape(str(item.get('Name', 'Untitled')))}</h2> <h2>{html.escape(str(item.get('Name', 'Untitled')))}</h2>
@@ -7914,7 +7913,7 @@ def register():
return redirect(url_for('login')) return redirect(url_for('login'))
if request.method == 'POST': if request.method == 'POST':
password = request.form.get('password', '') password = request.form['password']
name = (request.form.get('name') or '').strip() name = (request.form.get('name') or '').strip()
last_name = (request.form.get('last-name') or '').strip() last_name = (request.form.get('last-name') or '').strip()
+24 -15
View File
@@ -1375,8 +1375,10 @@
<li><a class="dropdown-item" href="{{ url_for('library_loans_admin') }}">Ausleihen / Defekte Items</a></li> <li><a class="dropdown-item" href="{{ url_for('library_loans_admin') }}">Ausleihen / Defekte Items</a></li>
{% endif %} {% endif %}
{% if student_cards_module_enabled %} {% if student_cards_module_enabled %}
{% if current_permissions.actions.get('can_manage_users', False) %}
<li><a class="dropdown-item" href="{{ url_for('student_cards_admin') }}">Bibliotheksausweis</a></li> <li><a class="dropdown-item" href="{{ url_for('student_cards_admin') }}">Bibliotheksausweis</a></li>
{% endif %} {% endif %}
{% endif %}
{% if current_permissions.pages.get('admin_school_settings', False) %} {% if current_permissions.pages.get('admin_school_settings', False) %}
<li><a class="dropdown-item" href="{{ url_for('admin_school_settings') }}">Schulstammdaten</a></li> <li><a class="dropdown-item" href="{{ url_for('admin_school_settings') }}">Schulstammdaten</a></li>
{% endif %} {% endif %}
@@ -1619,11 +1621,10 @@
<div id="cookie-banner" role="dialog" aria-live="polite" aria-label="Cookie-Hinweis"> <div id="cookie-banner" role="dialog" aria-live="polite" aria-label="Cookie-Hinweis">
<div class="cb-inner"> <div class="cb-inner">
<div class="cb-text"> <div class="cb-text">
Wir verwenden technisch notwendige Cookies, um Ihre Sitzung zu verwalten und die Anwendung bereitzustellen. Bitte akzeptieren Sie Cookies, um fortzufahren. Wir verwenden ausschließlich technisch notwendige Cookies, um Ihre Sitzung zu verwalten und die Anwendung bereitzustellen. Bitte bestätigen Sie dies, um fortzufahren.
</div> </div>
<div class="cb-actions"> <div class="cb-actions">
<button class="btn-decline" id="cookie-decline">Ablehnen</button> <button class="btn-accept" id="cookie-accept">Notwendige Cookies akzeptieren</button>
<button class="btn-accept" id="cookie-accept">Akzeptieren</button>
</div> </div>
</div> </div>
</div> </div>
@@ -1728,31 +1729,39 @@
(function(){ (function(){
function getCookie(name){ function getCookie(name){
const v = document.cookie.split(';').map(s=>s.trim()); const v = document.cookie.split(';').map(s=>s.trim());
for(const c of v){ if(c.startsWith(name+'=')) return decodeURIComponent(c.split('=')[1]); } for(const c of v){
if(c.startsWith(name+'=')) return decodeURIComponent(c.split('=')[1]);
}
return null; return null;
} }
function setCookie(name, value, days){ function setCookie(name, value, days){
const d = new Date(); d.setTime(d.getTime() + (days*24*60*60*1000)); const d = new Date();
d.setTime(d.getTime() + (days*24*60*60*1000));
document.cookie = name + '=' + encodeURIComponent(value) + ';expires=' + d.toUTCString() + ';path=/;SameSite=Lax'; document.cookie = name + '=' + encodeURIComponent(value) + ';expires=' + d.toUTCString() + ';path=/;SameSite=Lax';
} }
function showBanner(){ var el = document.getElementById('cookie-banner'); if(el) el.style.display = 'block'; }
function hideBanner(){ var el = document.getElementById('cookie-banner'); if(el) el.style.display = 'none'; }
// If not decided yet, show banner and block app until decision function showBanner(){
var el = document.getElementById('cookie-banner');
if(el) el.style.display = 'block';
}
function hideBanner(){
var el = document.getElementById('cookie-banner');
if(el) el.style.display = 'none';
}
// Prüfen, ob der Nutzer bereits zugestimmt hat
const consent = getCookie('cookie_consent'); const consent = getCookie('cookie_consent');
if(!consent){ if(!consent){
showBanner(); showBanner();
// Optionally blur content until consent
document.body.style.filter = 'none';
} }
// Nur noch der Akzeptieren-Button für vitale Cookies ist vorhanden
document.getElementById('cookie-accept')?.addEventListener('click', function(){ document.getElementById('cookie-accept')?.addEventListener('click', function(){
setCookie('cookie_consent','accepted',365); setCookie('cookie_consent', 'vital_accepted', 365);
hideBanner(); hideBanner();
}); });
document.getElementById('cookie-decline')?.addEventListener('click', function(){
setCookie('cookie_consent','declined',365);
window.location.href = 'https://www.ecosia.org/';
});
const username = {{ (session['username'] if 'username' in session else '')|tojson }}; const username = {{ (session['username'] if 'username' in session else '')|tojson }};
const isTutorialPage = window.location.pathname === {{ url_for('tutorial_page')|tojson }}; const isTutorialPage = window.location.pathname === {{ url_for('tutorial_page')|tojson }};
+2 -6
View File
@@ -25,9 +25,6 @@
<div class="content"> <div class="content">
<div class="form-card"> <div class="form-card">
<form method="POST" action="{{ url_for('register') }}"> <form method="POST" action="{{ url_for('register') }}">
<!-- CSRF-Schutz (Zwingend erforderlich für POST) -->
<input type="hidden" name="csrf_token" value="{{ csrf_token }}">
<div class="form-group"> <div class="form-group">
<label for="name">Vorname</label> <label for="name">Vorname</label>
@@ -65,17 +62,16 @@
<div class="input-container"> <div class="input-container">
<span class="input-icon">🔒</span> <span class="input-icon">🔒</span>
<!-- HTML5 Pattern blockiert unsichere Passwörter vor dem Absenden --> <!-- HTML5 Pattern blockiert unsichere Passwörter vor dem Absenden -->
<input type="password" <input
id="password" id="password"
name="password" name="password"
placeholder="Geben Sie ein sicheres Passwort ein" placeholder="Geben Sie ein sicheres Passwort ein"
required required
pattern="(?=.*\d)(?=.*[a-z])(?=.*[A-Z])(?=.*[^a-zA-Z0-9]).{12,}"> pattern="(?=.*\d)(?=.*[a-z])(?=.*[A-Z])(?=.*[^a-zA-Z0-9]).{12,}">
</div> </div>
<button type="button" class="btn-secondary" id="toggle-pw-btn" onclick="togglePasswordVisibility()" title="Passwort anzeigen/verbergen">👁️</button>
</div> </div>
<div class="pw-actions"> <div class="pw-actions">
<button type="button" class="btn-secondary" onclick="generateSecurePassword()">🎲 Automatisches Passwort generieren</button> <button type="button" class="btn-secondary" onclick="generateSecurePassword()">Passwort generieren</button>
</div> </div>
</div> </div>