diff --git a/apps/gooyal_oauth2/validators.py b/apps/gooyal_oauth2/validators.py index 002eacd..6d62e83 100755 --- a/apps/gooyal_oauth2/validators.py +++ b/apps/gooyal_oauth2/validators.py @@ -9,35 +9,26 @@ USER_MODEL = get_user_model() class MultiGatewayOAuth2Validator(OAuth2Validator): # pylint: disable=w0223 - """ Primarily extend the functionality of token generation """ - def validate_user(self, username, password, client, request, *args, **kwargs): - """ Here, you would be able to access the MOBILE/ OTP fields - which you will be sending in the request.post body. """ - # otp = request.otp - # mobile = request.mobile - # user = AppropriateModel.objects.get(otp=otp, mobile=mobile) auth_fields = getattr(request, 'auth_fields', 'username:password').split(':') - user_field = auth_fields[0] - pass_field = auth_fields[1] - user = None - if user_field == 'phone_number': - user = USER_MODEL.objects.get( - phone_number=username - ) + if len(auth_fields) != 2: + return False - elif user_field == 'username': - user = USER_MODEL.objects.get( - username=username - ) + user_field, pass_field = auth_fields - elif user_field == 'email': - user = USER_MODEL.objects.get( - email=username - ) + if user_field not in ['phone_number', 'username', 'email']: + return False - if user is None: + if pass_field not in ['password', 'otp']: + return False + + if not username or not password: + return False + + user = USER_MODEL.objects.filter(**{user_field:username}).first() + + if not user: return False if not user.check_auth(pass_field, password):