-
Notifications
You must be signed in to change notification settings - Fork 1
/
crimemap.py
83 lines (69 loc) · 1.98 KB
/
crimemap.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
# -*- coding: utf-8 -*-
import db_config
import json
import datetime
import dateparser
import string
from flask import Flask
from flask import render_template
from flask import request
if db_config.test:
from mockdbhelper import MockDBHelper as DBHelper
else:
from dbhelper import DBHelper
app = Flask(__name__)
DB = DBHelper()
categories = ['mugging','break-in']
@app.route("/")
def home(error_message=None):
crimes = DB.get_all_crimes()
crimes = json.dumps(crimes)
return render_template("home.html",
crimes=crimes,
categories=categories,
error_message=error_message)
@app.route("/add", methods=["POST"])
def add():
try:
data = request.form.get("userinput")
DB.add_input(data)
except Exception as e:
print e
return home()
@app.route("/clear")
def clear():
try:
DB.clear_all()
except Exception as e:
print e
return home()
@app.route("/submitcrime", methods=['POST'])
def submitcrime():
category = request.form.get("category")
if category not in categories:
return home()
date = format_date(request.form.get("date"))
if not date:
return home("Invalid date. please use yyyy-mm-dd format")
try:
latitude = float(request.form.get("latitude"))
longitude = float(request.form.get("longitude"))
except ValueError as ve:
print ve
return home()
description = sanitize_string(request.form.get("description"))
DB.add_crime(category, date, latitude, longitude, description)
return home()
# helper to validate date
def format_date(userdate):
date = dateparser.parse(userdate)
try:
return datetime.datetime.strftime(date, "%Y-%m-%d")
except TypeError:
return None
# XSS protection
def sanitize_string(userinput):
whitelist = string.letters + string.digits + " !?$.,;:-'()&"
return filter(lambda x: x in whitelist, userinput)
if __name__ == '__main__':
app.run(port=5000, debug=True)