uuid in introspection
This commit is contained in:
parent
b37d1a64f5
commit
61878794a6
4 changed files with 122 additions and 4 deletions
|
|
@ -33,9 +33,7 @@ urlpatterns = [
|
|||
|
||||
path('admin/', admin.site.urls),
|
||||
path('users/', include('apps.users.urls')),
|
||||
path('oauth2/', include('oauth2_provider.urls', namespace='oauth2_provider')),
|
||||
|
||||
|
||||
path('oauth2/', include('apps.gooyal_oauth2.urls', namespace='gooyal_oauth2')),
|
||||
]
|
||||
|
||||
urlpatterns += static(settings.MEDIA_URL, document_root=settings.MEDIA_ROOT)
|
||||
|
|
|
|||
|
|
@ -17,7 +17,7 @@ def register_scopes(app_config, verbosity=2, interactive=True, **kwargs):
|
|||
|
||||
The signal is connected in ``apps.py``.
|
||||
"""
|
||||
# Register any scopes in the oauth2_provider settings
|
||||
# Register any scopes in the oauth2_provider settings
|
||||
for name, description in oauth2_settings.SCOPES.items():
|
||||
Scope.register(
|
||||
name,
|
||||
|
|
|
|||
49
apps/gooyal_oauth2/urls.py
Normal file
49
apps/gooyal_oauth2/urls.py
Normal file
|
|
@ -0,0 +1,49 @@
|
|||
from django.urls import re_path
|
||||
|
||||
from oauth2_provider import views
|
||||
from .views.introspect import IntrospectTokenView
|
||||
|
||||
app_name = "oauth2_provider"
|
||||
|
||||
|
||||
base_urlpatterns = [
|
||||
re_path(r"^authorize/$", views.AuthorizationView.as_view(), name="authorize"),
|
||||
re_path(r"^token/$", views.TokenView.as_view(), name="token"),
|
||||
re_path(r"^revoke_token/$", views.RevokeTokenView.as_view(), name="revoke-token"),
|
||||
re_path(r"^introspect/$", IntrospectTokenView.as_view(), name="introspect"),
|
||||
]
|
||||
|
||||
|
||||
management_urlpatterns = [
|
||||
# Application management views
|
||||
re_path(r"^applications/$", views.ApplicationList.as_view(), name="list"),
|
||||
re_path(r"^applications/register/$", views.ApplicationRegistration.as_view(), name="register"),
|
||||
re_path(r"^applications/(?P<pk>[\w-]+)/$", views.ApplicationDetail.as_view(), name="detail"),
|
||||
re_path(r"^applications/(?P<pk>[\w-]+)/delete/$", views.ApplicationDelete.as_view(), name="delete"),
|
||||
re_path(r"^applications/(?P<pk>[\w-]+)/update/$", views.ApplicationUpdate.as_view(), name="update"),
|
||||
# Token management views
|
||||
re_path(r"^authorized_tokens/$", views.AuthorizedTokensListView.as_view(), name="authorized-token-list"),
|
||||
re_path(
|
||||
r"^authorized_tokens/(?P<pk>[\w-]+)/delete/$",
|
||||
views.AuthorizedTokenDeleteView.as_view(),
|
||||
name="authorized-token-delete",
|
||||
),
|
||||
]
|
||||
|
||||
oidc_urlpatterns = [
|
||||
# .well-known/openid-configuration/ is deprecated
|
||||
# https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderConfig
|
||||
# does not specify a trailing slash
|
||||
# Support for trailing slash shall be removed in a future release.
|
||||
re_path(
|
||||
r"^\.well-known/openid-configuration/?$",
|
||||
views.ConnectDiscoveryInfoView.as_view(),
|
||||
name="oidc-connect-discovery-info",
|
||||
),
|
||||
re_path(r"^\.well-known/jwks.json$", views.JwksInfoView.as_view(), name="jwks-info"),
|
||||
re_path(r"^userinfo/$", views.UserInfoView.as_view(), name="user-info"),
|
||||
re_path(r"^logout/$", views.RPInitiatedLogoutView.as_view(), name="rp-initiated-logout"),
|
||||
]
|
||||
|
||||
|
||||
urlpatterns = base_urlpatterns + management_urlpatterns + oidc_urlpatterns
|
||||
71
apps/gooyal_oauth2/views/introspect.py
Normal file
71
apps/gooyal_oauth2/views/introspect.py
Normal file
|
|
@ -0,0 +1,71 @@
|
|||
import calendar
|
||||
|
||||
from django.core.exceptions import ObjectDoesNotExist
|
||||
from django.http import JsonResponse
|
||||
from django.utils.decorators import method_decorator
|
||||
from django.views.decorators.csrf import csrf_exempt
|
||||
|
||||
from oauth2_provider.models import get_access_token_model
|
||||
from oauth2_provider.views.generic import ClientProtectedScopedResourceView
|
||||
|
||||
|
||||
@method_decorator(csrf_exempt, name="dispatch")
|
||||
class IntrospectTokenView(ClientProtectedScopedResourceView):
|
||||
"""
|
||||
Implements an endpoint for token introspection based
|
||||
on RFC 7662 https://rfc-editor.org/rfc/rfc7662.html
|
||||
|
||||
To access this view the request must pass a OAuth2 Bearer Token
|
||||
which is allowed to access the scope `introspection`.
|
||||
"""
|
||||
|
||||
required_scopes = ["introspection"]
|
||||
|
||||
@staticmethod
|
||||
def get_token_response(token_value=None):
|
||||
try:
|
||||
token = (
|
||||
get_access_token_model().objects.select_related("user", "application").get(token=token_value)
|
||||
)
|
||||
except ObjectDoesNotExist:
|
||||
return JsonResponse({"active": False}, status=200)
|
||||
else:
|
||||
if token.is_valid():
|
||||
data = {
|
||||
"active": True,
|
||||
"scope": token.scope,
|
||||
"exp": int(calendar.timegm(token.expires.timetuple())),
|
||||
}
|
||||
if token.application:
|
||||
data["client_id"] = token.application.client_id
|
||||
if token.user:
|
||||
|
||||
# NOTICE: i pass uuid instead of username
|
||||
data["username"] = token.user.pk
|
||||
return JsonResponse(data)
|
||||
else:
|
||||
return JsonResponse({"active": False}, status=200)
|
||||
|
||||
def get(self, request, *args, **kwargs):
|
||||
"""
|
||||
Get the token from the URL parameters.
|
||||
URL: https://example.com/introspect?token=mF_9.B5f-4.1JqM
|
||||
|
||||
:param request:
|
||||
:param args:
|
||||
:param kwargs:
|
||||
:return:
|
||||
"""
|
||||
return self.get_token_response(request.GET.get("token", None))
|
||||
|
||||
def post(self, request, *args, **kwargs):
|
||||
"""
|
||||
Get the token from the body form parameters.
|
||||
Body: token=mF_9.B5f-4.1JqM
|
||||
|
||||
:param request:
|
||||
:param args:
|
||||
:param kwargs:
|
||||
:return:
|
||||
"""
|
||||
return self.get_token_response(request.POST.get("token", None))
|
||||
Loading…
Add table
Reference in a new issue