WTForms是一個支持多個web框架的form組件,主要用於對用戶請求數據進行驗證。html
pip3 install wtforms
from flask import Flask, request, render_template, redirect from wtforms import Form from wtforms import widgets from wtforms import validators from wtforms.fields import simple app = Flask(__name__) class MyValidators(object): """自定義驗證規則""" def __init__(self,message): self.message = message def __call__(self, form, field): black_list = ["shabi", "傻逼"] print("用戶輸入的信息:", field.data) if field.data not in black_list: return None raise validators.ValidationError(self.message) class LoginForm(Form): username = simple.StringField( label="帳號", validators=[ MyValidators(message="用戶名非法"), # 自定義驗證規則 validators.DataRequired(message="用戶名不能爲空"), validators.Length(min=2, max=8, message="用戶名長度必須大於%(min)d且小於%(max)d") ], widget=widgets.TextInput(), # TextInput(input_type="test") render_kw={"placeholder": "請輸入帳號"} ) password = simple.PasswordField( label="密碼", validators=[ validators.DataRequired(message="密碼不能爲空"), validators.Length(min=6, message="用戶名長度必須大於%(min)d"), validators.Regexp(regex="\d+", message="密碼必須是數字") # validators.Regexp(regex="^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[$@$!%*?&])[A-Za-z\d$@$!%*?&]{8,}", # message="密碼至少8個字符,至少1個大寫字母,1個小寫字母,1個數字和1個特殊字符") ], widget=widgets.PasswordInput(), render_kw={"placeholder": "請輸入密碼"} ) @app.route("/login", methods=["GET", "POST"]) def login(): if request.method == "GET": form = LoginForm() return render_template("login.html", form=form) form = LoginForm(formdata=request.form) if form.validate(): # 經過驗證 print(form.data) return redirect("https://www.cnblogs.com/believepd/") else: print(form.errors) return render_template("login.html", form=form) if __name__ == "__main__": app.run()
<!DOCTYPE html> <html lang="zh-cn"> <head> <meta charset="UTF-8"> <title>Title</title> </head> <body> <form method="post" novalidate> <div>{{ form.username.label }}{{ form.username }}{{ form.username.errors[0] }}</div> <div>{{ form.password.label }}{{ form.password }}{{ form.password.errors[0] }}</div> <div><input type="submit" value="登陸"></div> </form> </body> </html>
from flask import Flask, request, render_template from wtforms import Form from wtforms import widgets from wtforms import validators from wtforms.fields import core from wtforms.fields import html5 from wtforms.fields import simple app = Flask(__name__) class RegisterForm(Form): username = simple.StringField( label="帳號", validators=[ validators.DataRequired(message="帳號不能爲空") ], widget=widgets.TextInput(), render_kw={"class": "c1"}, default="pd" # 默認值 ) password = simple.PasswordField( label="密碼", validators=[ validators.DataRequired(message="密碼不能爲空") ], widget=widgets.PasswordInput(), render_kw={"class": "c2"} ) password_confirm = simple.PasswordField( label="重複密碼", validators=[ validators.DataRequired(message="重複密碼不能爲空"), validators.EqualTo("password", message="兩次密碼輸入不一致") ], widget=widgets.PasswordInput(), render_kw={"class": "c3"} ) email = html5.EmailField( label="郵箱", validators=[ validators.DataRequired(message="郵箱不能爲空"), validators.Email(message="郵箱格式錯誤") ], widget=widgets.TextInput(input_type="email"), render_kw={"class": "c4"} ) gender = core.RadioField( label="性別", choices=( (1, "男"), (2, "女") ), coerce=int ) city = core.SelectField( label="城市", choices=( ("BJ", "北京"), ("SH", "上海"), ("GZ", "廣州") ) ) hobby = core.SelectMultipleField( label="愛好", choices=( (1, "籃球"), (2, "足球") ), coerce=int ) favor = core.SelectMultipleField( label="喜愛", choices=( (1, "籃球"), (2, "足球"), ), widget=widgets.ListWidget(prefix_label=False), option_widget=widgets.CheckboxInput(), coerce=int, default=[1, 2] ) def __init__(self, *args, **kwargs): """用於從數據庫取出的數據是實時的""" super(RegisterForm, self).__init__(*args, **kwargs) self.favor.choices = ((1, "籃球"), (2, "足球"), (3, "羽毛球")) # self.favor.choices = 從數據庫取到的數據 def validate_password_confirm(self, field): """ 自定義password_confirm字段規則,例如:與password字段是否一致 """ # 最開始初始化時,self.data中已經有全部的值 if field.data != self.data["password"]: # raise validators.ValidationError("密碼不一致") # 繼續後續驗證 raise validators.StopValidation("密碼不一致") # 再也不繼續後續驗證 # {"password_confirm": ["兩次密碼輸入不一致", "密碼不一致"]} @app.route("/register", methods=["GET", "POST"]) def register(): if request.method == "GET": form = RegisterForm(data={"gender": 1}) return render_template("register.html", form=form) form = RegisterForm(formdata=request.form) if form.validate(): print(form.data) return "註冊成功" else: print(form.errors) return render_template("register.html", form=form) if __name__ == "__main__": app.run()from flask import Flask, request, render_template from wtforms import Form from wtforms import widgets from wtforms import validators from wtforms.fields import core from wtforms.fields import html5 from wtforms.fields import simple app = Flask(__name__) class RegisterForm(Form): username = simple.StringField( label="帳號", validators=[ validators.DataRequired(message="帳號不能爲空") ], widget=widgets.TextInput(), render_kw={"class": "c1"}, default="pd" # 默認值 ) password = simple.PasswordField( label="密碼", validators=[ validators.DataRequired(message="密碼不能爲空") ], widget=widgets.PasswordInput(), render_kw={"class": "c2"} ) password_confirm = simple.PasswordField( label="重複密碼", validators=[ validators.DataRequired(message="重複密碼不能爲空"), validators.EqualTo("password", message="兩次密碼輸入不一致") ], widget=widgets.PasswordInput(), render_kw={"class": "c3"} ) email = html5.EmailField( label="郵箱", validators=[ validators.DataRequired(message="郵箱不能爲空"), validators.Email(message="郵箱格式錯誤") ], widget=widgets.TextInput(input_type="email"), render_kw={"class": "c4"} ) gender = core.RadioField( label="性別", choices=( (1, "男"), (2, "女") ), coerce=int ) city = core.SelectField( label="城市", choices=( ("BJ", "北京"), ("SH", "上海"), ("GZ", "廣州") ) ) hobby = core.SelectMultipleField( label="愛好", choices=( (1, "籃球"), (2, "足球") ), coerce=int ) favor = core.SelectMultipleField( label="喜愛", choices=( (1, "籃球"), (2, "足球"), ), widget=widgets.ListWidget(prefix_label=False), option_widget=widgets.CheckboxInput(), coerce=int, default=[1, 2] ) def __init__(self, *args, **kwargs): """用於從數據庫取出的數據是實時的""" super(RegisterForm, self).__init__(*args, **kwargs) self.favor.choices = ((1, "籃球"), (2, "足球"), (3, "羽毛球")) # self.favor.choices = 從數據庫取到的數據 def validate_password_confirm(self, field): """ 鉤子函數 自定義password_confirm字段規則,例如:與password字段是否一致 """ # 最開始初始化時,self.data中已經有全部的值 if field.data != self.data["password"]: # raise validators.ValidationError("密碼不一致") # 繼續後續驗證 raise validators.StopValidation("密碼不一致") # 再也不繼續後續驗證 # {"password_confirm": ["兩次密碼輸入不一致", "密碼不一致"]} @app.route("/register", methods=["GET", "POST"]) def register(): if request.method == "GET": form = RegisterForm(data={"gender": 1}) return render_template("register.html", form=form) form = RegisterForm(formdata=request.form) if form.validate(): print(form.data) return "註冊成功" else: print(form.errors) return render_template("register.html", form=form) if __name__ == "__main__": app.run()
<!DOCTYPE html> <html lang="zh-cn"> <head> <meta charset="UTF-8"> <title>Title</title> </head> <body> <form method="post" novalidate> {% for field in form %} <div>{{ field.label }}{{ field }}{{ field.errors[0] }}</div> {% endfor %} <div><input type="submit" value="註冊"></div> </form> </body> </html>
import hashlib from flask import Flask, request, render_template, redirect from wtforms import Form from wtforms.fields import simple from wtforms.csrf.core import CSRF app = Flask(__name__) class MyCSRF(CSRF): """ Generate a CSRF token based on the user"s IP. I am probably not very secure, so don"t use me. """ def setup_form(self, form): self.csrf_context = form.meta.csrf_context() self.csrf_secret = form.meta.csrf_secret return super(MyCSRF, self).setup_form(form) def generate_csrf_token(self, csrf_token): gid = self.csrf_secret + self.csrf_context token = hashlib.md5(gid.encode("utf-8")).hexdigest() return token def validate_csrf_token(self, form, field): # print(field.data, field.current_token) if field.data != field.current_token: raise ValueError("Invalid CSRF") class LoginForm(Form): username = simple.StringField(label="帳號") password = simple.PasswordField(label="密碼") class Meta: ########## CSRF ########## # 是否自動生成CSRF標籤 csrf = True # 生成CSRF標籤name csrf_field_name = "csrf_token" # 自動生成標籤的值,加密用的csrf_secret csrf_secret = "aa" # 自動生成標籤的值,加密用的csrf_context csrf_context = lambda x: request.url # 生成和比較csrf標籤 csrf_class = MyCSRF ########## i18n ########## # 是否支持本地化 # locales = False locales = ("zh", "en") # 是否對本地化進行緩存 cache_translations = True # 保存本地化緩存信息的字段 translations_cache = {} @app.route("/login", methods=["GET", "POST"]) def login(): if request.method == "GET": form = LoginForm() return render_template("login.html", form=form) form = LoginForm(formdata=request.form) if form.validate(): print(form.data) return redirect("https://www.cnblogs.com/believepd/") else: print(form.errors) return render_template("login.html", form=form) if __name__ == "__main__": app.run()
morehtml5