extract user creation from validation
This commit is contained in:
parent
571cb2323a
commit
7cb2de4338
1 changed files with 66 additions and 34 deletions
|
|
@ -17,7 +17,6 @@ AccessTokenModel = get_access_token_model()
|
||||||
UserModel = get_user_model()
|
UserModel = get_user_model()
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
|
class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
|
||||||
def validate_user(self, username, password, client, request, *args, **kwargs):
|
def validate_user(self, username, password, client, request, *args, **kwargs):
|
||||||
auth_fields = getattr(request, 'auth_fields', 'username:password').split(':')
|
auth_fields = getattr(request, 'auth_fields', 'username:password').split(':')
|
||||||
|
|
@ -50,18 +49,45 @@ class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
|
||||||
|
|
||||||
return False
|
return False
|
||||||
|
|
||||||
def _create_user(self, content):
|
def _get_user_profile(self, token, content):
|
||||||
content = {'active': True, 'scope': 'ipg.payment:submit accounts.account:retrieve', 'exp': 1602619137,
|
# content = {
|
||||||
'client_id': 'bd2hEGXytrqMjbFnplRyHJTeoW1vwKzCZJtH6ro0', 'username': '',
|
# "active": True,
|
||||||
'uuid': '94255117-117c-4a9f-af50-35a6c47503ac', 'email': '', 'phone_number': '+989106853582',
|
# "scope": "read write email",
|
||||||
'first_name': '', 'last_name': '', 'name': '', 'balance': 0,
|
# "client_id": "J8NFmU4tJVgDxKaJFmXTWvaHO",
|
||||||
'avatar': 'http://accounts.gooyal.com/media/avatars/1691899.jpg', 'iban': '', 'iban_verified': None}
|
# "username": "aaronpk",
|
||||||
|
# "exp": 1437275311
|
||||||
|
# }
|
||||||
|
|
||||||
# TODO: create user?
|
user_client = service_clients.Client(access_token=token,
|
||||||
# user, _created = UserModel.objects.get_or_create(
|
scopes=content.get('scope', '').split(),
|
||||||
# **{UserModel.USERNAME_FIELD: content["username"]}
|
expires_in=100)
|
||||||
# )
|
|
||||||
return None
|
user_account = user_client.accounts.account()
|
||||||
|
if user_account.get('uuid'):
|
||||||
|
content.update(user_account)
|
||||||
|
|
||||||
|
# content = {'active': True, 'scope': 'ipg.payment:submit accounts.account:retrieve', 'exp': 1602619137,
|
||||||
|
# 'client_id': 'bd2hEGXytrqMjbFnplRyHJTeoW1vwKzCZJtH6ro0', 'username': '',
|
||||||
|
# 'uuid': '94255117-117c-4a9f-af50-35a6c47503ac', 'email': '', 'phone_number': '+989106853582',
|
||||||
|
# 'first_name': '', 'last_name': '', 'name': '', 'balance': 0,
|
||||||
|
# 'avatar': 'http://accounts.gooyal.com/media/avatars/1691899.jpg', 'iban': '', 'iban_verified': None}
|
||||||
|
|
||||||
|
user = UserModel.objects.filter(uuid=content['uuid']).first()
|
||||||
|
if user:
|
||||||
|
pass
|
||||||
|
|
||||||
|
else:
|
||||||
|
user = UserModel.objects.create_user(
|
||||||
|
**{UserModel.USERNAME_FIELD: content["username"]},
|
||||||
|
uuid=content['uuid'],
|
||||||
|
email=content['email'],
|
||||||
|
phone_number=content['phone_number'],
|
||||||
|
first_name=content['first_name'],
|
||||||
|
last_name=content['last_name'],
|
||||||
|
name=content['name'],
|
||||||
|
avatar=content['avatar']
|
||||||
|
)
|
||||||
|
return user, content
|
||||||
|
|
||||||
def _get_token_from_gooyal_authentication_server(
|
def _get_token_from_gooyal_authentication_server(
|
||||||
self, token, introspection_url, introspection_token, introspection_credentials, introspection_client_id,
|
self, token, introspection_url, introspection_token, introspection_credentials, introspection_client_id,
|
||||||
|
|
@ -84,6 +110,7 @@ class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
|
||||||
"""
|
"""
|
||||||
|
|
||||||
headers = None
|
headers = None
|
||||||
|
response = None
|
||||||
if introspection_token:
|
if introspection_token:
|
||||||
headers = {"Authorization": "Bearer {}".format(introspection_token)}
|
headers = {"Authorization": "Bearer {}".format(introspection_token)}
|
||||||
try:
|
try:
|
||||||
|
|
@ -127,12 +154,7 @@ class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
|
||||||
user = None
|
user = None
|
||||||
if "active" in content and content["active"] is True:
|
if "active" in content and content["active"] is True:
|
||||||
if "username" in content:
|
if "username" in content:
|
||||||
user_client = service_clients.Client(access_token=token,
|
user, content = self._get_user_profile(token, content)
|
||||||
scopes=content.get('scope','').split(),
|
|
||||||
expires_in=100)
|
|
||||||
user_account = user_client.accounts.account()
|
|
||||||
content.update(user_account)
|
|
||||||
user = self._create_user(content)
|
|
||||||
|
|
||||||
max_caching_time = datetime.now() + timedelta(
|
max_caching_time = datetime.now() + timedelta(
|
||||||
seconds=oauth2_settings.RESOURCE_SERVER_TOKEN_CACHING_SECONDS
|
seconds=oauth2_settings.RESOURCE_SERVER_TOKEN_CACHING_SECONDS
|
||||||
|
|
@ -148,22 +170,32 @@ class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
|
||||||
scope = content.get("scope", "")
|
scope = content.get("scope", "")
|
||||||
expires = make_aware(expires)
|
expires = make_aware(expires)
|
||||||
|
|
||||||
try:
|
access_token, _created = AccessTokenModel.objects.update_or_create(
|
||||||
access_token = AccessTokenModel.objects.select_related("application", "user").get(token=token)
|
|
||||||
except AccessTokenModel.DoesNotExist:
|
|
||||||
access_token = AccessTokenModel.objects.create(
|
|
||||||
user=user,
|
|
||||||
token=token,
|
token=token,
|
||||||
application=None,
|
defaults={
|
||||||
scope=scope,
|
"user": user,
|
||||||
expires=expires,
|
"application": None,
|
||||||
detail=content
|
"scope": scope,
|
||||||
)
|
"expires": expires,
|
||||||
else:
|
"detail": content,
|
||||||
access_token.expires = expires
|
})
|
||||||
access_token.scope = scope
|
|
||||||
access_token.detail = content
|
# try:
|
||||||
access_token.save()
|
# access_token = AccessTokenModel.objects.select_related("application", "user").get(token=token)
|
||||||
|
# except AccessTokenModel.DoesNotExist:
|
||||||
|
# access_token = AccessTokenModel.objects.create(
|
||||||
|
# user=user,
|
||||||
|
# token=token,
|
||||||
|
# application=None,
|
||||||
|
# scope=scope,
|
||||||
|
# expires=expires,
|
||||||
|
# detail=content
|
||||||
|
# )
|
||||||
|
# else:
|
||||||
|
# access_token.expires = expires
|
||||||
|
# access_token.scope = scope
|
||||||
|
# access_token.detail = content
|
||||||
|
# access_token.save()
|
||||||
|
|
||||||
return access_token
|
return access_token
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue