from oauth2_provider.oauth2_validators import OAuth2Validator from django.contrib.auth import get_user_model from oauth2_provider.settings import oauth2_settings from apps.gooyal_oauth2.models import Resource USER_MODEL = get_user_model() class MultiGatewayOAuth2Validator(OAuth2Validator): # pylint: disable=w0223 def validate_user(self, username, password, client, request, *args, **kwargs): auth_fields = getattr(request, 'auth_fields', 'username:password').split(':') if len(auth_fields) != 2: return False user_field, pass_field = auth_fields if user_field not in ['phone_number', 'username', 'email']: return False if pass_field not in ['password', 'otp']: return False if not username or not password: return False user = USER_MODEL.objects.filter(**{user_field:username}).first() if not user: return False if not user.check_auth(pass_field, password): return False if user.is_active: request.user = user return True return False class IntrospectOAuth2Validator(OAuth2Validator): def validate_bearer_token(self, token, scopes, request): """ When users try to access resources, check that provided token is valid """ if not token: return False introspection_url = oauth2_settings.RESOURCE_SERVER_INTROSPECTION_URL introspection_token = oauth2_settings.RESOURCE_SERVER_AUTH_TOKEN introspection_credentials = oauth2_settings.RESOURCE_SERVER_INTROSPECTION_CREDENTIALS try: access_token = Resource.objects.select_related("user").get(token=token) except Resource.DoesNotExist: access_token = None # if there is no token or it's invalid then introspect the token if there's an external OAuth server if not access_token or not access_token.is_valid(scopes): if introspection_url and (introspection_token or introspection_credentials): access_token = self._get_token_from_authentication_server( token, introspection_url, introspection_token, introspection_credentials ) if access_token and access_token.is_valid(scopes): request.client = access_token.application request.user = access_token.user request.scopes = scopes # this is needed by django rest framework request.access_token = access_token return True else: self._set_oauth2_error_on_request(request, access_token, scopes) return False