2013-04-23 18:51:17 +02:00
|
|
|
from __future__ import absolute_import
|
2013-06-10 21:35:48 +02:00
|
|
|
from django.conf import settings
|
2013-04-23 18:51:17 +02:00
|
|
|
|
2012-10-17 04:07:35 +02:00
|
|
|
import hashlib
|
2013-07-29 23:03:31 +02:00
|
|
|
from zerver.lib.utils import make_safe_digest
|
2012-10-17 04:07:35 +02:00
|
|
|
|
|
|
|
def gravatar_hash(email):
|
|
|
|
"""Compute the Gravatar hash for an email address."""
|
2013-03-20 15:31:27 +01:00
|
|
|
# Non-ASCII characters aren't permitted by the currently active e-mail
|
|
|
|
# RFCs. However, the IETF has published https://tools.ietf.org/html/rfc4952,
|
|
|
|
# outlining internationalization of email addresses, and regardless if we
|
|
|
|
# typo an address or someone manages to give us a non-ASCII address, let's
|
|
|
|
# not error out on it.
|
|
|
|
return make_safe_digest(email.lower(), hashlib.md5)
|
2013-06-10 21:35:48 +02:00
|
|
|
|
|
|
|
def user_avatar_hash(email):
|
|
|
|
# Salting the user_key may be overkill, but it prevents us from
|
|
|
|
# basically mimicking Gravatar's hashing scheme, which could lead
|
|
|
|
# to some abuse scenarios like folks using us as a free Gravatar
|
|
|
|
# replacement.
|
|
|
|
user_key = email.lower() + settings.AVATAR_SALT
|
|
|
|
return make_safe_digest(user_key, hashlib.sha1)
|
|
|
|
|
|
|
|
def avatar_url(user_profile):
|
|
|
|
if user_profile.avatar_source == 'U':
|
|
|
|
bucket = settings.S3_AVATAR_BUCKET
|
|
|
|
hash_key = user_avatar_hash(user_profile.email)
|
|
|
|
# ?x=x allows templates to append additional parameters with &s
|
|
|
|
return "https://%s.s3.amazonaws.com/%s?x=x" % (bucket, hash_key)
|
|
|
|
else:
|
|
|
|
hash_key = gravatar_hash(user_profile.email)
|
|
|
|
return "https://secure.gravatar.com/avatar/%s?d=identicon" % (hash_key,)
|