# views/security_views.py from flask import Blueprint, render_template, redirect, request, flash, current_app from flask_security import current_user, login_required, login_user, logout_user from flask_security.utils import verify_and_update_password, get_message, do_flash, config_value from flask_security.forms import LoginForm from urllib.parse import urlparse import datetime as dt from common.models.user import User from common.utils.nginx_utils import prefixed_url_for security_bp = Blueprint('security_bp', __name__) @security_bp.before_request def log_before_request(): current_app.logger.debug(f"Before request (security_bp): {request.method} {request.url}") @security_bp.after_request def log_after_request(response): current_app.logger.debug(f"After request (security_bp): {request.method} {request.url} - Status: {response.status}") return response @security_bp.route('/login', methods=['GET', 'POST']) def login(): if current_user.is_authenticated: return redirect(prefixed_url_for('basic_bp.index')) form = LoginForm() if form.validate_on_submit(): current_app.logger.debug(f'Validating login form: {form.email.data}') user = User.query.filter_by(email=form.email.data).first() if user is None or not verify_and_update_password(form.password.data, user): flash('Invalid username or password') return redirect(prefixed_url_for('security_bp.login')) login_user(user, remember=form.remember.data) return redirect(prefixed_url_for('user_bp.tenant_overview')) return render_template('security/login_user.html', login_user_form=form) @security_bp.route('/logout', methods=['GET', 'POST']) @login_required def logout(): current_app.logger.debug('Logging out') logout_user() current_app.logger.debug('After Logout') return redirect(prefixed_url_for('basic_bp.index'))