INTROSPECTION_USER_CREATE_METHOD in settings

This commit is contained in:
mahdavi 2020-10-26 11:56:06 +03:30
parent 7cb2de4338
commit f1cec16495
3 changed files with 55 additions and 45 deletions

View file

@ -1,10 +1,19 @@
from oauth2_provider.settings import OAuth2ProviderSettings, USER_SETTINGS, DEFAULTS, IMPORT_STRINGS, MANDATORY from oauth2_provider.settings import OAuth2ProviderSettings, USER_SETTINGS, DEFAULTS, IMPORT_STRINGS, MANDATORY
GOOYAL_DEFAULTS = { GOOYAL_DEFAULTS = {
# Resource Server with Token Introspection additions
"RESOURCE_SERVER_CLIENT_ID": None, "RESOURCE_SERVER_CLIENT_ID": None,
"RESOURCE_SERVER_CLIENT_SECRET": None "RESOURCE_SERVER_CLIENT_SECRET": None,
}
"INTROSPECTION_USER_CREATE_METHOD": None,
}
GOOYAL_IMPORT_STRINGS = ("INTROSPECTION_USER_CREATE_METHOD",)
GOOYAL_MANDATORY = ("INTROSPECTION_USER_CREATE_METHOD",)
DEFAULTS.update(GOOYAL_DEFAULTS) DEFAULTS.update(GOOYAL_DEFAULTS)
IMPORT_STRINGS = IMPORT_STRINGS + GOOYAL_IMPORT_STRINGS
MANDATORY = MANDATORY + GOOYAL_MANDATORY
oauth2_settings = OAuth2ProviderSettings(USER_SETTINGS, DEFAULTS, IMPORT_STRINGS, MANDATORY) oauth2_settings = OAuth2ProviderSettings(USER_SETTINGS, DEFAULTS, IMPORT_STRINGS, MANDATORY)

View file

@ -4,7 +4,6 @@ from datetime import datetime, timedelta
import requests import requests
import service_clients import service_clients
from django.conf import settings
from django.contrib.auth import get_user_model from django.contrib.auth import get_user_model
from django.utils.timezone import make_aware from django.utils.timezone import make_aware
from oauth2_provider.models import get_access_token_model from oauth2_provider.models import get_access_token_model
@ -17,6 +16,47 @@ AccessTokenModel = get_access_token_model()
UserModel = get_user_model() UserModel = get_user_model()
def get_user_profile(token, content):
# content = {
# "active": True,
# "scope": "read write email",
# "client_id": "J8NFmU4tJVgDxKaJFmXTWvaHO",
# "username": "aaronpk",
# "exp": 1437275311
# }
user_client = service_clients.Client(access_token=token,
scopes=content.get('scope', '').split(),
expires_in=100)
user_account = user_client.accounts.account()
if user_account.get('uuid'):
content.update(user_account)
# content = {'active': True, 'scope': 'ipg.payment:submit accounts.account:retrieve', 'exp': 1602619137,
# 'client_id': 'bd2hEGXytrqMjbFnplRyHJTeoW1vwKzCZJtH6ro0', 'username': '',
# 'uuid': '94255117-117c-4a9f-af50-35a6c47503ac', 'email': '', 'phone_number': '+989106853582',
# 'first_name': '', 'last_name': '', 'name': '', 'balance': 0,
# 'avatar': 'http://accounts.gooyal.com/media/avatars/1691899.jpg', 'iban': '', 'iban_verified': None}
user = UserModel.objects.filter(uuid=content['uuid']).first()
if user:
pass
else:
user = UserModel.objects.create_user(
**{UserModel.USERNAME_FIELD: content["username"]},
uuid=content['uuid'],
email=content['email'],
phone_number=content['phone_number'],
first_name=content['first_name'],
last_name=content['last_name'],
name=content['name'],
avatar=content['avatar']
)
return user, content
class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223 class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
def validate_user(self, username, password, client, request, *args, **kwargs): def validate_user(self, username, password, client, request, *args, **kwargs):
auth_fields = getattr(request, 'auth_fields', 'username:password').split(':') auth_fields = getattr(request, 'auth_fields', 'username:password').split(':')
@ -49,46 +89,6 @@ class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
return False return False
def _get_user_profile(self, token, content):
# content = {
# "active": True,
# "scope": "read write email",
# "client_id": "J8NFmU4tJVgDxKaJFmXTWvaHO",
# "username": "aaronpk",
# "exp": 1437275311
# }
user_client = service_clients.Client(access_token=token,
scopes=content.get('scope', '').split(),
expires_in=100)
user_account = user_client.accounts.account()
if user_account.get('uuid'):
content.update(user_account)
# content = {'active': True, 'scope': 'ipg.payment:submit accounts.account:retrieve', 'exp': 1602619137,
# 'client_id': 'bd2hEGXytrqMjbFnplRyHJTeoW1vwKzCZJtH6ro0', 'username': '',
# 'uuid': '94255117-117c-4a9f-af50-35a6c47503ac', 'email': '', 'phone_number': '+989106853582',
# 'first_name': '', 'last_name': '', 'name': '', 'balance': 0,
# 'avatar': 'http://accounts.gooyal.com/media/avatars/1691899.jpg', 'iban': '', 'iban_verified': None}
user = UserModel.objects.filter(uuid=content['uuid']).first()
if user:
pass
else:
user = UserModel.objects.create_user(
**{UserModel.USERNAME_FIELD: content["username"]},
uuid=content['uuid'],
email=content['email'],
phone_number=content['phone_number'],
first_name=content['first_name'],
last_name=content['last_name'],
name=content['name'],
avatar=content['avatar']
)
return user, content
def _get_token_from_gooyal_authentication_server( def _get_token_from_gooyal_authentication_server(
self, token, introspection_url, introspection_token, introspection_credentials, introspection_client_id, self, token, introspection_url, introspection_token, introspection_credentials, introspection_client_id,
introspection_client_secret introspection_client_secret
@ -154,7 +154,7 @@ class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
user = None user = None
if "active" in content and content["active"] is True: if "active" in content and content["active"] is True:
if "username" in content: if "username" in content:
user, content = self._get_user_profile(token, content) user, content = oauth2_settings.INTROSPECTION_USER_CREATE_METHOD(token, content)
max_caching_time = datetime.now() + timedelta( max_caching_time = datetime.now() + timedelta(
seconds=oauth2_settings.RESOURCE_SERVER_TOKEN_CACHING_SECONDS seconds=oauth2_settings.RESOURCE_SERVER_TOKEN_CACHING_SECONDS

View file

@ -69,7 +69,8 @@ OAUTH2_PROVIDER = {
'write': 'Write scope', 'write': 'Write scope',
'groups': 'Access to your groups', 'groups': 'Access to your groups',
'introspection': 'Introspect token scope'}, 'introspection': 'Introspect token scope'},
'OAUTH2_VALIDATOR_CLASS': 'apps.gooyal_oauth2.validators.OAuth2Validator' 'OAUTH2_VALIDATOR_CLASS': 'apps.gooyal_oauth2.validators.OAuth2Validator',
"INTROSPECTION_USER_CREATE_METHOD": 'apps.gooyal_oauth2.validators.get_user_profile',
} }
# GOOYAL_DYNAMIC_SCOPES # GOOYAL_DYNAMIC_SCOPES