Ajoute 4 mécanismes moteur manquants pour le thème sécurité incendie : étiquette, carte, image SVG inline, bouton avec pièce jointe
Contenu et mécanisme uniquement, aucun style ajouté (voir consigne du 24/09/2026) : deux nouveaux kinds de contenu (badge/carte, rendu en div brutes sans CSS), un mode SVG inline pour l'image (svg_markup, nettoyé par un nouveau sanitizer allow-list avant chaque rendu) et un fichier téléchargeable joignable à un bouton (upload/download routes, stockage sous db.support_dir). Le futur système de templates portera l'habillage visuel de ces éléments. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
e7c6ed7159
commit
a34bcf4159
@@ -8,9 +8,11 @@ from . import ( # noqa: F401 - enregistre les routes definies dans chaque modul
|
||||
document_edit,
|
||||
document_element_add,
|
||||
document_element_delete,
|
||||
document_element_download_attachment,
|
||||
document_element_move,
|
||||
document_element_move_to_page,
|
||||
document_element_update,
|
||||
document_element_upload_attachment,
|
||||
document_new,
|
||||
document_page_add,
|
||||
document_page_delete,
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
import os
|
||||
|
||||
from flask import send_from_directory
|
||||
from werkzeug.exceptions import NotFound
|
||||
from werkzeug.wrappers import Response
|
||||
|
||||
import db
|
||||
import document_engine
|
||||
from core.flask_app import app
|
||||
|
||||
|
||||
@app.route("/document/<slug>/elements/<int:element_id>/download-attachment")
|
||||
def document_element_download_attachment(slug: str, element_id: int) -> Response:
|
||||
"""Sert le fichier joint à un bouton (voir
|
||||
document_element_upload_attachment.py) sous son nom d'origine
|
||||
(`download_name`), jamais sous son nom de stockage anonymisé
|
||||
(`attachment_stored_name`, un UUID)."""
|
||||
element = document_engine.get_document_element(slug, element_id)
|
||||
if element is None:
|
||||
raise NotFound
|
||||
stored_name = str(element["attributes"].get("attachment_stored_name", ""))
|
||||
original_filename = str(element["attributes"].get("attachment_filename", ""))
|
||||
if not stored_name:
|
||||
raise NotFound
|
||||
return send_from_directory(
|
||||
os.path.join(db.support_dir(slug), "attachments"),
|
||||
stored_name,
|
||||
as_attachment=True,
|
||||
download_name=original_filename or stored_name,
|
||||
)
|
||||
@@ -0,0 +1,54 @@
|
||||
import os
|
||||
import uuid
|
||||
from typing import Any
|
||||
|
||||
from flask import jsonify, request
|
||||
from werkzeug.wrappers import Response
|
||||
|
||||
import db
|
||||
import document_engine
|
||||
from core.flask_app import app
|
||||
|
||||
|
||||
@app.route("/document/<slug>/elements/<int:element_id>/upload-attachment", methods=["POST"])
|
||||
def document_element_upload_attachment(slug: str, element_id: int) -> Response | tuple[Response, int]:
|
||||
"""Joint un fichier téléchargeable à un bouton (voir _render_button,
|
||||
document_engine/rendering/render_document_element.py) — mirroir de
|
||||
routes/uploads/upload_file.py côté jeu, mais stocké sous le dossier du
|
||||
SUPPORT (db.support_dir) et réservé au kind "bouton" (un fichier joint
|
||||
n'a de sens que pour déclencher un téléchargement au clic)."""
|
||||
element = document_engine.get_document_element(slug, element_id)
|
||||
if element is None:
|
||||
return jsonify({"error": "élément introuvable"}), 404
|
||||
if element["kind"] != "bouton":
|
||||
return jsonify({"error": "seul un bouton peut recevoir un fichier joint"}), 400
|
||||
f = request.files.get("file")
|
||||
if not f or not f.filename:
|
||||
return jsonify({"error": "Aucun fichier reçu"}), 400
|
||||
original_filename = f.filename
|
||||
ext = "".join(c for c in os.path.splitext(original_filename)[1].lower() if c.isalnum() or c == ".")[:10]
|
||||
stored_name = uuid.uuid4().hex + ext
|
||||
attachments_dir = os.path.join(db.support_dir(slug), "attachments")
|
||||
os.makedirs(attachments_dir, exist_ok=True)
|
||||
f.save(os.path.join(attachments_dir, stored_name))
|
||||
|
||||
attributes = {
|
||||
**element["attributes"],
|
||||
"attachment_stored_name": stored_name,
|
||||
"attachment_filename": original_filename,
|
||||
}
|
||||
document_engine.update_document_element_attributes(slug, element_id, attributes)
|
||||
element = db.assert_not_none(
|
||||
document_engine.get_document_element(slug, element_id),
|
||||
"element_id verifie present juste au-dessus, aucune suppression concurrente possible entre-temps ici",
|
||||
)
|
||||
elements_by_parent: dict[int | None, list[dict[str, Any]]] = {}
|
||||
for el in document_engine.list_document_elements(slug, element["page_id"]):
|
||||
elements_by_parent.setdefault(el["parent_id"], []).append(el)
|
||||
return jsonify(
|
||||
{
|
||||
"ok": True,
|
||||
"attributes": element["attributes"],
|
||||
"rendered_html": document_engine.render_document_element(element, elements_by_parent),
|
||||
}
|
||||
)
|
||||
Reference in New Issue
Block a user