From 94a8e3f25f7f671f23a9aec88f28322053dcfe23 Mon Sep 17 00:00:00 2001 From: mahdavi Date: Thu, 13 Aug 2020 06:49:29 +0430 Subject: [PATCH] application have to have user --- apps/gooyal_oauth2/models.py | 49 ++++++++++++++++++-------------- apps/gooyal_oauth2/validators.py | 3 +- gooyal_accounts/settings.py | 1 - 3 files changed, 28 insertions(+), 25 deletions(-) diff --git a/apps/gooyal_oauth2/models.py b/apps/gooyal_oauth2/models.py index 279cc59..5f6ab72 100644 --- a/apps/gooyal_oauth2/models.py +++ b/apps/gooyal_oauth2/models.py @@ -17,6 +17,11 @@ class Application(AbstractApplication): Application model for use with Django OAuth Toolkit that allows the scopes available to an application to be restricted on a per-application basis. """ + user = models.ForeignKey( + settings.AUTH_USER_MODEL, + related_name="%(app_label)s_%(class)s", + on_delete=models.PROTECT + ) allowed_scope = models.TextField(blank=True) @property @@ -29,6 +34,28 @@ class Application(AbstractApplication): return app_scopes.intersection(all_scopes) +class Resource(AbstractAccessToken): + source_refresh_token = None + id = None + application = None + + uuid = models.UUIDField(primary_key=True, editable=False, default=uuid.uuid4, unique=True, db_index=True) + name = models.CharField(max_length=255, blank=True) + + user = models.ForeignKey( + settings.AUTH_USER_MODEL, on_delete=models.CASCADE, blank=True, null=True, + related_name="resources" + ) + expires = models.DateTimeField() + token = models.CharField(max_length=255, unique=True, ) # introspect token + + scope = 'introspection' + scopes = {'introspection': 'Introspect token scope'} + + def allow_scopes(self, scopes): + return scopes == [self.scope] + + class Scope(models.Model): """ Django model for an OAuth scope. @@ -99,28 +126,6 @@ class Scope(models.Model): return True -class Resource(AbstractAccessToken): - source_refresh_token = None - id = None - application = None - - uuid = models.UUIDField(primary_key=True, editable=False, default=uuid.uuid4, unique=True, db_index=True) - name = models.CharField(max_length=255, blank=True) - - user = models.ForeignKey( - settings.AUTH_USER_MODEL, on_delete=models.CASCADE, blank=True, null=True, - related_name="resources" - ) - expires = models.DateTimeField() - token = models.CharField(max_length=255, unique=True, ) # introspect token - - scope = 'introspection' - scopes = {'introspection': 'Introspect token scope'} - - def allow_scopes(self, scopes): - return scopes == [self.scope] - - class Grant(AbstractGrant): application = models.ForeignKey( oauth2_settings.APPLICATION_MODEL, on_delete=models.CASCADE, related_name='grants' diff --git a/apps/gooyal_oauth2/validators.py b/apps/gooyal_oauth2/validators.py index 6d62e83..a27a18c 100755 --- a/apps/gooyal_oauth2/validators.py +++ b/apps/gooyal_oauth2/validators.py @@ -70,7 +70,7 @@ class IntrospectOAuth2Validator(OAuth2Validator): if access_token and access_token.is_valid(scopes): request.client = access_token.application - request.user = access_token.user + request.user = access_token.user or (access_token.application and access_token.application.user) request.scopes = scopes # this is needed by django rest framework @@ -79,4 +79,3 @@ class IntrospectOAuth2Validator(OAuth2Validator): else: self._set_oauth2_error_on_request(request, access_token, scopes) return False - diff --git a/gooyal_accounts/settings.py b/gooyal_accounts/settings.py index d1c9c1b..b5caa01 100644 --- a/gooyal_accounts/settings.py +++ b/gooyal_accounts/settings.py @@ -74,7 +74,6 @@ OAUTH2_PROVIDER = { # GOOYAL_DYNAMIC_SCOPES RESOURCE_SERVER_REGISTER_SCOPE_URL = None -INTROSPECT_SCOPE = None REGISTER_SCOPE_SCOPE = None REST_FRAMEWORK = {