formsets.py 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579
  1. from django.core.exceptions import ValidationError
  2. from django.forms import Form
  3. from django.forms.fields import BooleanField, IntegerField
  4. from django.forms.renderers import get_default_renderer
  5. from django.forms.utils import ErrorList, RenderableFormMixin
  6. from django.forms.widgets import CheckboxInput, HiddenInput, NumberInput
  7. from django.utils.functional import cached_property
  8. from django.utils.translation import gettext_lazy as _
  9. from django.utils.translation import ngettext_lazy
  10. __all__ = ("BaseFormSet", "formset_factory", "all_valid")
  11. # special field names
  12. TOTAL_FORM_COUNT = "TOTAL_FORMS"
  13. INITIAL_FORM_COUNT = "INITIAL_FORMS"
  14. MIN_NUM_FORM_COUNT = "MIN_NUM_FORMS"
  15. MAX_NUM_FORM_COUNT = "MAX_NUM_FORMS"
  16. ORDERING_FIELD_NAME = "ORDER"
  17. DELETION_FIELD_NAME = "DELETE"
  18. # default minimum number of forms in a formset
  19. DEFAULT_MIN_NUM = 0
  20. # default maximum number of forms in a formset, to prevent memory exhaustion
  21. DEFAULT_MAX_NUM = 1000
  22. class ManagementForm(Form):
  23. """
  24. Keep track of how many form instances are displayed on the page. If adding
  25. new forms via JavaScript, you should increment the count field of this form
  26. as well.
  27. """
  28. TOTAL_FORMS = IntegerField(widget=HiddenInput)
  29. INITIAL_FORMS = IntegerField(widget=HiddenInput)
  30. # MIN_NUM_FORM_COUNT and MAX_NUM_FORM_COUNT are output with the rest of the
  31. # management form, but only for the convenience of client-side code. The
  32. # POST value of them returned from the client is not checked.
  33. MIN_NUM_FORMS = IntegerField(required=False, widget=HiddenInput)
  34. MAX_NUM_FORMS = IntegerField(required=False, widget=HiddenInput)
  35. def clean(self):
  36. cleaned_data = super().clean()
  37. # When the management form is invalid, we don't know how many forms
  38. # were submitted.
  39. cleaned_data.setdefault(TOTAL_FORM_COUNT, 0)
  40. cleaned_data.setdefault(INITIAL_FORM_COUNT, 0)
  41. return cleaned_data
  42. class BaseFormSet(RenderableFormMixin):
  43. """
  44. A collection of instances of the same Form class.
  45. """
  46. deletion_widget = CheckboxInput
  47. ordering_widget = NumberInput
  48. default_error_messages = {
  49. "missing_management_form": _(
  50. "ManagementForm data is missing or has been tampered with. Missing fields: "
  51. "%(field_names)s. You may need to file a bug report if the issue persists."
  52. ),
  53. "too_many_forms": ngettext_lazy(
  54. "Please submit at most %(num)d form.",
  55. "Please submit at most %(num)d forms.",
  56. "num",
  57. ),
  58. "too_few_forms": ngettext_lazy(
  59. "Please submit at least %(num)d form.",
  60. "Please submit at least %(num)d forms.",
  61. "num",
  62. ),
  63. }
  64. template_name_div = "django/forms/formsets/div.html"
  65. template_name_p = "django/forms/formsets/p.html"
  66. template_name_table = "django/forms/formsets/table.html"
  67. template_name_ul = "django/forms/formsets/ul.html"
  68. def __init__(
  69. self,
  70. data=None,
  71. files=None,
  72. auto_id="id_%s",
  73. prefix=None,
  74. initial=None,
  75. error_class=ErrorList,
  76. form_kwargs=None,
  77. error_messages=None,
  78. ):
  79. self.is_bound = data is not None or files is not None
  80. self.prefix = prefix or self.get_default_prefix()
  81. self.auto_id = auto_id
  82. self.data = data or {}
  83. self.files = files or {}
  84. self.initial = initial
  85. self.form_kwargs = form_kwargs or {}
  86. self.error_class = error_class
  87. self._errors = None
  88. self._non_form_errors = None
  89. self.form_renderer = self.renderer
  90. self.renderer = self.renderer or get_default_renderer()
  91. messages = {}
  92. for cls in reversed(type(self).__mro__):
  93. messages.update(getattr(cls, "default_error_messages", {}))
  94. if error_messages is not None:
  95. messages.update(error_messages)
  96. self.error_messages = messages
  97. def __iter__(self):
  98. """Yield the forms in the order they should be rendered."""
  99. return iter(self.forms)
  100. def __getitem__(self, index):
  101. """Return the form at the given index, based on the rendering order."""
  102. return self.forms[index]
  103. def __len__(self):
  104. return len(self.forms)
  105. def __bool__(self):
  106. """
  107. Return True since all formsets have a management form which is not
  108. included in the length.
  109. """
  110. return True
  111. def __repr__(self):
  112. if self._errors is None:
  113. is_valid = "Unknown"
  114. else:
  115. is_valid = (
  116. self.is_bound
  117. and not self._non_form_errors
  118. and not any(form_errors for form_errors in self._errors)
  119. )
  120. return "<%s: bound=%s valid=%s total_forms=%s>" % (
  121. self.__class__.__qualname__,
  122. self.is_bound,
  123. is_valid,
  124. self.total_form_count(),
  125. )
  126. @cached_property
  127. def management_form(self):
  128. """Return the ManagementForm instance for this FormSet."""
  129. if self.is_bound:
  130. form = ManagementForm(
  131. self.data,
  132. auto_id=self.auto_id,
  133. prefix=self.prefix,
  134. renderer=self.renderer,
  135. )
  136. form.full_clean()
  137. else:
  138. form = ManagementForm(
  139. auto_id=self.auto_id,
  140. prefix=self.prefix,
  141. initial={
  142. TOTAL_FORM_COUNT: self.total_form_count(),
  143. INITIAL_FORM_COUNT: self.initial_form_count(),
  144. MIN_NUM_FORM_COUNT: self.min_num,
  145. MAX_NUM_FORM_COUNT: self.max_num,
  146. },
  147. renderer=self.renderer,
  148. )
  149. return form
  150. def total_form_count(self):
  151. """Return the total number of forms in this FormSet."""
  152. if self.is_bound:
  153. # return absolute_max if it is lower than the actual total form
  154. # count in the data; this is DoS protection to prevent clients
  155. # from forcing the server to instantiate arbitrary numbers of
  156. # forms
  157. return min(
  158. self.management_form.cleaned_data[TOTAL_FORM_COUNT], self.absolute_max
  159. )
  160. else:
  161. initial_forms = self.initial_form_count()
  162. total_forms = max(initial_forms, self.min_num) + self.extra
  163. # Allow all existing related objects/inlines to be displayed,
  164. # but don't allow extra beyond max_num.
  165. if initial_forms > self.max_num >= 0:
  166. total_forms = initial_forms
  167. elif total_forms > self.max_num >= 0:
  168. total_forms = self.max_num
  169. return total_forms
  170. def initial_form_count(self):
  171. """Return the number of forms that are required in this FormSet."""
  172. if self.is_bound:
  173. return self.management_form.cleaned_data[INITIAL_FORM_COUNT]
  174. else:
  175. # Use the length of the initial data if it's there, 0 otherwise.
  176. initial_forms = len(self.initial) if self.initial else 0
  177. return initial_forms
  178. @cached_property
  179. def forms(self):
  180. """Instantiate forms at first property access."""
  181. # DoS protection is included in total_form_count()
  182. return [
  183. self._construct_form(i, **self.get_form_kwargs(i))
  184. for i in range(self.total_form_count())
  185. ]
  186. def get_form_kwargs(self, index):
  187. """
  188. Return additional keyword arguments for each individual formset form.
  189. index will be None if the form being constructed is a new empty
  190. form.
  191. """
  192. return self.form_kwargs.copy()
  193. def _construct_form(self, i, **kwargs):
  194. """Instantiate and return the i-th form instance in a formset."""
  195. defaults = {
  196. "auto_id": self.auto_id,
  197. "prefix": self.add_prefix(i),
  198. "error_class": self.error_class,
  199. # Don't render the HTML 'required' attribute as it may cause
  200. # incorrect validation for extra, optional, and deleted
  201. # forms in the formset.
  202. "use_required_attribute": False,
  203. "renderer": self.form_renderer,
  204. }
  205. if self.is_bound:
  206. defaults["data"] = self.data
  207. defaults["files"] = self.files
  208. if self.initial and "initial" not in kwargs:
  209. try:
  210. defaults["initial"] = self.initial[i]
  211. except IndexError:
  212. pass
  213. # Allow extra forms to be empty, unless they're part of
  214. # the minimum forms.
  215. if i >= self.initial_form_count() and i >= self.min_num:
  216. defaults["empty_permitted"] = True
  217. defaults.update(kwargs)
  218. form = self.form(**defaults)
  219. self.add_fields(form, i)
  220. return form
  221. @property
  222. def initial_forms(self):
  223. """Return a list of all the initial forms in this formset."""
  224. return self.forms[: self.initial_form_count()]
  225. @property
  226. def extra_forms(self):
  227. """Return a list of all the extra forms in this formset."""
  228. return self.forms[self.initial_form_count() :]
  229. @property
  230. def empty_form(self):
  231. form_kwargs = {
  232. **self.get_form_kwargs(None),
  233. "auto_id": self.auto_id,
  234. "prefix": self.add_prefix("__prefix__"),
  235. "empty_permitted": True,
  236. "use_required_attribute": False,
  237. "renderer": self.form_renderer,
  238. }
  239. form = self.form(**form_kwargs)
  240. self.add_fields(form, None)
  241. return form
  242. @property
  243. def cleaned_data(self):
  244. """
  245. Return a list of form.cleaned_data dicts for every form in self.forms.
  246. """
  247. if not self.is_valid():
  248. raise AttributeError(
  249. "'%s' object has no attribute 'cleaned_data'" % self.__class__.__name__
  250. )
  251. return [form.cleaned_data for form in self.forms]
  252. @property
  253. def deleted_forms(self):
  254. """Return a list of forms that have been marked for deletion."""
  255. if not self.is_valid() or not self.can_delete:
  256. return []
  257. # construct _deleted_form_indexes which is just a list of form indexes
  258. # that have had their deletion widget set to True
  259. if not hasattr(self, "_deleted_form_indexes"):
  260. self._deleted_form_indexes = []
  261. for i, form in enumerate(self.forms):
  262. # if this is an extra form and hasn't changed, don't consider it
  263. if i >= self.initial_form_count() and not form.has_changed():
  264. continue
  265. if self._should_delete_form(form):
  266. self._deleted_form_indexes.append(i)
  267. return [self.forms[i] for i in self._deleted_form_indexes]
  268. @property
  269. def ordered_forms(self):
  270. """
  271. Return a list of form in the order specified by the incoming data.
  272. Raise an AttributeError if ordering is not allowed.
  273. """
  274. if not self.is_valid() or not self.can_order:
  275. raise AttributeError(
  276. "'%s' object has no attribute 'ordered_forms'" % self.__class__.__name__
  277. )
  278. # Construct _ordering, which is a list of (form_index, order_field_value)
  279. # tuples. After constructing this list, we'll sort it by order_field_value
  280. # so we have a way to get to the form indexes in the order specified
  281. # by the form data.
  282. if not hasattr(self, "_ordering"):
  283. self._ordering = []
  284. for i, form in enumerate(self.forms):
  285. # if this is an extra form and hasn't changed, don't consider it
  286. if i >= self.initial_form_count() and not form.has_changed():
  287. continue
  288. # don't add data marked for deletion to self.ordered_data
  289. if self.can_delete and self._should_delete_form(form):
  290. continue
  291. self._ordering.append((i, form.cleaned_data[ORDERING_FIELD_NAME]))
  292. # After we're done populating self._ordering, sort it.
  293. # A sort function to order things numerically ascending, but
  294. # None should be sorted below anything else. Allowing None as
  295. # a comparison value makes it so we can leave ordering fields
  296. # blank.
  297. def compare_ordering_key(k):
  298. if k[1] is None:
  299. return (1, 0) # +infinity, larger than any number
  300. return (0, k[1])
  301. self._ordering.sort(key=compare_ordering_key)
  302. # Return a list of form.cleaned_data dicts in the order specified by
  303. # the form data.
  304. return [self.forms[i[0]] for i in self._ordering]
  305. @classmethod
  306. def get_default_prefix(cls):
  307. return "form"
  308. @classmethod
  309. def get_deletion_widget(cls):
  310. return cls.deletion_widget
  311. @classmethod
  312. def get_ordering_widget(cls):
  313. return cls.ordering_widget
  314. def non_form_errors(self):
  315. """
  316. Return an ErrorList of errors that aren't associated with a particular
  317. form -- i.e., from formset.clean(). Return an empty ErrorList if there
  318. are none.
  319. """
  320. if self._non_form_errors is None:
  321. self.full_clean()
  322. return self._non_form_errors
  323. @property
  324. def errors(self):
  325. """Return a list of form.errors for every form in self.forms."""
  326. if self._errors is None:
  327. self.full_clean()
  328. return self._errors
  329. def total_error_count(self):
  330. """Return the number of errors across all forms in the formset."""
  331. return len(self.non_form_errors()) + sum(
  332. len(form_errors) for form_errors in self.errors
  333. )
  334. def _should_delete_form(self, form):
  335. """Return whether or not the form was marked for deletion."""
  336. return form.cleaned_data.get(DELETION_FIELD_NAME, False)
  337. def is_valid(self):
  338. """Return True if every form in self.forms is valid."""
  339. if not self.is_bound:
  340. return False
  341. # Accessing errors triggers a full clean the first time only.
  342. self.errors
  343. # List comprehension ensures is_valid() is called for all forms.
  344. # Forms due to be deleted shouldn't cause the formset to be invalid.
  345. forms_valid = all(
  346. [
  347. form.is_valid()
  348. for form in self.forms
  349. if not (self.can_delete and self._should_delete_form(form))
  350. ]
  351. )
  352. return forms_valid and not self.non_form_errors()
  353. def full_clean(self):
  354. """
  355. Clean all of self.data and populate self._errors and
  356. self._non_form_errors.
  357. """
  358. self._errors = []
  359. self._non_form_errors = self.error_class(
  360. error_class="nonform", renderer=self.renderer
  361. )
  362. empty_forms_count = 0
  363. if not self.is_bound: # Stop further processing.
  364. return
  365. if not self.management_form.is_valid():
  366. error = ValidationError(
  367. self.error_messages["missing_management_form"],
  368. params={
  369. "field_names": ", ".join(
  370. self.management_form.add_prefix(field_name)
  371. for field_name in self.management_form.errors
  372. ),
  373. },
  374. code="missing_management_form",
  375. )
  376. self._non_form_errors.append(error)
  377. for i, form in enumerate(self.forms):
  378. # Empty forms are unchanged forms beyond those with initial data.
  379. if not form.has_changed() and i >= self.initial_form_count():
  380. empty_forms_count += 1
  381. # Accessing errors calls full_clean() if necessary.
  382. # _should_delete_form() requires cleaned_data.
  383. form_errors = form.errors
  384. if self.can_delete and self._should_delete_form(form):
  385. continue
  386. self._errors.append(form_errors)
  387. try:
  388. if (
  389. self.validate_max
  390. and self.total_form_count() - len(self.deleted_forms) > self.max_num
  391. ) or self.management_form.cleaned_data[
  392. TOTAL_FORM_COUNT
  393. ] > self.absolute_max:
  394. raise ValidationError(
  395. self.error_messages["too_many_forms"] % {"num": self.max_num},
  396. code="too_many_forms",
  397. )
  398. if (
  399. self.validate_min
  400. and self.total_form_count()
  401. - len(self.deleted_forms)
  402. - empty_forms_count
  403. < self.min_num
  404. ):
  405. raise ValidationError(
  406. self.error_messages["too_few_forms"] % {"num": self.min_num},
  407. code="too_few_forms",
  408. )
  409. # Give self.clean() a chance to do cross-form validation.
  410. self.clean()
  411. except ValidationError as e:
  412. self._non_form_errors = self.error_class(
  413. e.error_list,
  414. error_class="nonform",
  415. renderer=self.renderer,
  416. )
  417. def clean(self):
  418. """
  419. Hook for doing any extra formset-wide cleaning after Form.clean() has
  420. been called on every form. Any ValidationError raised by this method
  421. will not be associated with a particular form; it will be accessible
  422. via formset.non_form_errors()
  423. """
  424. pass
  425. def has_changed(self):
  426. """Return True if data in any form differs from initial."""
  427. return any(form.has_changed() for form in self)
  428. def add_fields(self, form, index):
  429. """A hook for adding extra fields on to each form instance."""
  430. initial_form_count = self.initial_form_count()
  431. if self.can_order:
  432. # Only pre-fill the ordering field for initial forms.
  433. if index is not None and index < initial_form_count:
  434. form.fields[ORDERING_FIELD_NAME] = IntegerField(
  435. label=_("Order"),
  436. initial=index + 1,
  437. required=False,
  438. widget=self.get_ordering_widget(),
  439. )
  440. else:
  441. form.fields[ORDERING_FIELD_NAME] = IntegerField(
  442. label=_("Order"),
  443. required=False,
  444. widget=self.get_ordering_widget(),
  445. )
  446. if self.can_delete and (
  447. self.can_delete_extra or (index is not None and index < initial_form_count)
  448. ):
  449. form.fields[DELETION_FIELD_NAME] = BooleanField(
  450. label=_("Delete"),
  451. required=False,
  452. widget=self.get_deletion_widget(),
  453. )
  454. def add_prefix(self, index):
  455. return "%s-%s" % (self.prefix, index)
  456. def is_multipart(self):
  457. """
  458. Return True if the formset needs to be multipart, i.e. it
  459. has FileInput, or False otherwise.
  460. """
  461. if self.forms:
  462. return self.forms[0].is_multipart()
  463. else:
  464. return self.empty_form.is_multipart()
  465. @property
  466. def media(self):
  467. # All the forms on a FormSet are the same, so you only need to
  468. # interrogate the first form for media.
  469. if self.forms:
  470. return self.forms[0].media
  471. else:
  472. return self.empty_form.media
  473. @property
  474. def template_name(self):
  475. return self.renderer.formset_template_name
  476. def get_context(self):
  477. return {"formset": self}
  478. def formset_factory(
  479. form,
  480. formset=BaseFormSet,
  481. extra=1,
  482. can_order=False,
  483. can_delete=False,
  484. max_num=None,
  485. validate_max=False,
  486. min_num=None,
  487. validate_min=False,
  488. absolute_max=None,
  489. can_delete_extra=True,
  490. renderer=None,
  491. ):
  492. """Return a FormSet for the given form class."""
  493. if min_num is None:
  494. min_num = DEFAULT_MIN_NUM
  495. if max_num is None:
  496. max_num = DEFAULT_MAX_NUM
  497. # absolute_max is a hard limit on forms instantiated, to prevent
  498. # memory-exhaustion attacks. Default to max_num + DEFAULT_MAX_NUM
  499. # (which is 2 * DEFAULT_MAX_NUM if max_num is None in the first place).
  500. if absolute_max is None:
  501. absolute_max = max_num + DEFAULT_MAX_NUM
  502. if max_num > absolute_max:
  503. raise ValueError("'absolute_max' must be greater or equal to 'max_num'.")
  504. attrs = {
  505. "form": form,
  506. "extra": extra,
  507. "can_order": can_order,
  508. "can_delete": can_delete,
  509. "can_delete_extra": can_delete_extra,
  510. "min_num": min_num,
  511. "max_num": max_num,
  512. "absolute_max": absolute_max,
  513. "validate_min": validate_min,
  514. "validate_max": validate_max,
  515. "renderer": renderer,
  516. }
  517. return type(form.__name__ + "FormSet", (formset,), attrs)
  518. def all_valid(formsets):
  519. """Validate every formset and return True if all are valid."""
  520. # List comprehension ensures is_valid() is called for all formsets.
  521. return all([formset.is_valid() for formset in formsets])