server_controller.py 9.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235
  1. import uuid
  2. from datetime import timedelta, datetime
  3. from math import ceil, floor
  4. from bottle import request
  5. from passlib.hash import sha256_crypt
  6. import model
  7. from connection import check_missing_attributes, BadRequest, Forbidden
  8. def missing_attributes(attributes):
  9. for attr in attributes:
  10. if attr not in request.json or request.json[attr] == '' or request.json[attr] is None:
  11. if str(attr) == 'session_id':
  12. return 'You are not signed in.'
  13. return 'Missing value for attribute ' + str(attr)
  14. if str(attr) == 'session_id':
  15. if not model.valid_session_id(request.json['session_id']):
  16. return 'You are not signed in.'
  17. return False
  18. def login(json_request):
  19. check_missing_attributes(json_request, ['username', 'password'])
  20. username = request.json['username']
  21. password = request.json['password']
  22. session_id = model.login(username, password)
  23. if session_id:
  24. return {'session_id': session_id}
  25. else:
  26. return Forbidden('Invalid login data')
  27. def depot(json_request):
  28. check_missing_attributes(json_request, ['session_id'])
  29. user_id = model.get_user_id_by_session_id(request.json['session_id'])
  30. return {'data': model.get_user_ownership(user_id),
  31. 'own_wealth': model.user_wealth(user_id)}
  32. def register(json_request):
  33. check_missing_attributes(json_request, ['username', 'password'])
  34. username = request.json['username'].strip()
  35. if username == '':
  36. return BadRequest('Username can not be empty.')
  37. if model.user_exists(username):
  38. return BadRequest('User already exists.')
  39. game_key = ''
  40. if 'game_key' in request.json:
  41. game_key = request.json['game_key'].strip().upper()
  42. if game_key != '' and not model.valid_key(game_key):
  43. return BadRequest('Game key is not valid.')
  44. if model.register(username, request.json['password'], game_key):
  45. return {'message': "successfully registered user"}
  46. else:
  47. return BadRequest('Registration not successful')
  48. def activate_key(json_request):
  49. check_missing_attributes(json_request, ['key', 'session_id'])
  50. if model.valid_key(request.json['key']):
  51. user_id = model.get_user_id_by_session_id(request.json['session_id'])
  52. model.activate_key(request.json['key'], user_id)
  53. return {'message': "successfully activated key"}
  54. else:
  55. return BadRequest('Invalid key.')
  56. def order(json_request):
  57. check_missing_attributes(json_request, ['buy', 'session_id', 'amount', 'ownable', 'time_until_expiration'])
  58. if not model.ownable_name_exists(request.json['ownable']):
  59. return BadRequest('This kind of object can not be ordered.')
  60. buy = request.json['buy']
  61. sell = not buy
  62. if not isinstance(buy, bool):
  63. return BadRequest('`buy` must be a boolean')
  64. session_id = request.json['session_id']
  65. amount = request.json['amount']
  66. try:
  67. amount = int(amount)
  68. except ValueError:
  69. return BadRequest('Invalid amount.')
  70. if amount < 0:
  71. return BadRequest('You can not order a negative amount.')
  72. if amount < 1:
  73. return BadRequest('The minimum order size is 1.')
  74. ownable_name = request.json['ownable']
  75. time_until_expiration = float(request.json['time_until_expiration'])
  76. if time_until_expiration < 0:
  77. return BadRequest('Invalid expiration time.')
  78. ownable_id = model.ownable_id_by_name(ownable_name)
  79. user_id = model.get_user_id_by_session_id(session_id)
  80. model.own(user_id, ownable_name)
  81. ownership_id = model.get_ownership_id(ownable_id, user_id)
  82. try:
  83. if request.json['limit'] == '':
  84. limit = None
  85. elif request.json['limit'] is None:
  86. limit = None
  87. else:
  88. if buy:
  89. limit = floor(float(request.json['limit']) * 10000) / 10000
  90. else:
  91. limit = ceil(float(request.json['limit']) * 10000) / 10000
  92. except ValueError: # for example when float fails
  93. return BadRequest('Invalid limit.')
  94. except KeyError: # for example when limit was not specified
  95. limit = None
  96. if limit < 0:
  97. return BadRequest('Limit must not be negative.')
  98. try:
  99. if request.json['stop_loss'] == '':
  100. stop_loss = None
  101. elif request.json['stop_loss'] is None:
  102. stop_loss = None
  103. else:
  104. stop_loss = 'stop_loss' in request.json and request.json['stop_loss']
  105. if stop_loss is not None and limit is None:
  106. return BadRequest('Can only set stop-loss for limit orders')
  107. except KeyError: # for example when stop_loss was not specified
  108. stop_loss = None
  109. if sell:
  110. if not model.user_has_at_least_available(amount, user_id, ownable_id):
  111. return BadRequest('You can not sell more than you own.')
  112. try:
  113. expiry = datetime.strptime(model.current_db_time(), '%Y-%m-%d %H:%M:%S') + \
  114. timedelta(minutes=time_until_expiration)
  115. except OverflowError:
  116. return BadRequest('The expiration time is too far in the future.')
  117. model.place_order(buy, ownership_id, limit, stop_loss, amount, expiry)
  118. return {'message': "Order placed."}
  119. def gift(json_request):
  120. check_missing_attributes(json_request, ['session_id', 'amount', 'object_name', 'username'])
  121. if not model.ownable_name_exists(request.json['object_name']):
  122. return BadRequest('This kind of object can not be given away.')
  123. if request.json['username'] == 'bank' or not model.user_exists(request.json['username']):
  124. return BadRequest('There is no user with this name.')
  125. try:
  126. amount = float(request.json['amount'])
  127. except ValueError:
  128. return BadRequest('Invalid amount.')
  129. ownable_id = model.ownable_id_by_name(request.json['object_name'])
  130. sender_id = model.get_user_id_by_session_id(request.json['session_id'])
  131. if model.available_amount(sender_id, ownable_id) == 0:
  132. return BadRequest('You do not own any of these.')
  133. if not model.user_has_at_least_available(amount, sender_id, ownable_id):
  134. # for example if you have a 1.23532143213 Kollar and want to give them all away
  135. amount = model.available_amount(sender_id, ownable_id)
  136. recipient_id = model.get_user_id_by_name(request.json['username'])
  137. model.send_ownable(sender_id,
  138. recipient_id,
  139. ownable_id,
  140. amount)
  141. return {'message': "Gift sent."}
  142. def orders(json_request):
  143. check_missing_attributes(json_request, ['session_id'])
  144. data = model.get_user_orders(model.get_user_id_by_session_id(request.json['session_id']))
  145. return {'data': data}
  146. def orders_on(json_request):
  147. check_missing_attributes(json_request, ['session_id', 'ownable'])
  148. if not model.ownable_name_exists(request.json['ownable']):
  149. return BadRequest('This kind of object can not be ordered.')
  150. user_id = model.get_user_id_by_session_id(request.json['session_id'])
  151. ownable_id = model.ownable_id_by_name(request.json['ownable'])
  152. data = model.get_ownable_orders(user_id, ownable_id)
  153. return {'data': data}
  154. def old_orders(json_request):
  155. check_missing_attributes(json_request, ['session_id', 'include_canceled', 'include_executed', 'limit'])
  156. include_executed = request.json['include_executed']
  157. include_canceled = request.json['include_canceled']
  158. user_id = model.get_user_id_by_session_id(request.json['session_id'])
  159. limit = request.json['limit']
  160. data = model.get_old_orders(user_id, include_executed, include_canceled, limit)
  161. return {'data': data}
  162. def cancel_order(json_request):
  163. check_missing_attributes(json_request, ['session_id', 'order_id'])
  164. if not model.user_has_order_with_id(request.json['session_id'], request.json['order_id']):
  165. return BadRequest('You do not have an order with that number.')
  166. model.delete_order(request.json['order_id'], 'Canceled')
  167. return {'message': "Successfully deleted order"}
  168. def change_password(json_request):
  169. check_missing_attributes(json_request, ['session_id', 'password'])
  170. salt = str(uuid.uuid4())
  171. hashed_password = sha256_crypt.encrypt(request.json['password'] + salt)
  172. model.change_password(request.json['session_id'], hashed_password, salt)
  173. model.sign_out_user(request.json['session_id'])
  174. return {'message': "Successfully changed password"}
  175. def news(_json_request):
  176. return {'data': model.news()}
  177. def tradables(_json_request):
  178. return {'data': model.ownables()}
  179. def trades(json_request):
  180. check_missing_attributes(json_request, ['session_id', 'limit'])
  181. return {'data': model.trades(model.get_user_id_by_session_id(request.json['session_id']), request.json['limit'])}
  182. def trades_on(json_request):
  183. check_missing_attributes(json_request, ['session_id', 'ownable', 'limit'])
  184. if not model.ownable_name_exists(request.json['ownable']):
  185. return BadRequest('This kind of object can not have transactions.')
  186. return {'data': model.trades_on(model.ownable_id_by_name(request.json['ownable']), request.json['limit'])}
  187. def leaderboard(_json_request):
  188. return {'data': model.leaderboard()}