81 lines
2.9 KiB
Python
Executable file
81 lines
2.9 KiB
Python
Executable file
from oauth2_provider.oauth2_validators import OAuth2Validator
|
|
|
|
from django.contrib.auth import get_user_model
|
|
from oauth2_provider.settings import oauth2_settings
|
|
|
|
from apps.gooyal_oauth2.models import Resource
|
|
|
|
USER_MODEL = get_user_model()
|
|
|
|
|
|
class MultiGatewayOAuth2Validator(OAuth2Validator): # pylint: disable=w0223
|
|
def validate_user(self, username, password, client, request, *args, **kwargs):
|
|
auth_fields = getattr(request, 'auth_fields', 'username:password').split(':')
|
|
|
|
if len(auth_fields) != 2:
|
|
return False
|
|
|
|
user_field, pass_field = auth_fields
|
|
|
|
if user_field not in ['phone_number', 'username', 'email']:
|
|
return False
|
|
|
|
if pass_field not in ['password', 'otp']:
|
|
return False
|
|
|
|
if not username or not password:
|
|
return False
|
|
|
|
user = USER_MODEL.objects.filter(**{user_field:username}).first()
|
|
|
|
if not user:
|
|
return False
|
|
|
|
if not user.check_auth(pass_field, password):
|
|
return False
|
|
|
|
if user.is_active:
|
|
request.user = user
|
|
return True
|
|
|
|
return False
|
|
|
|
|
|
# class IntrospectOAuth2Validator(OAuth2Validator):
|
|
# def validate_bearer_token(self, token, scopes, request):
|
|
# """
|
|
# When users try to access resources, check that provided token is valid
|
|
# """
|
|
# if not token:
|
|
# return False
|
|
#
|
|
# introspection_url = oauth2_settings.RESOURCE_SERVER_INTROSPECTION_URL
|
|
# introspection_token = oauth2_settings.RESOURCE_SERVER_AUTH_TOKEN
|
|
# introspection_credentials = oauth2_settings.RESOURCE_SERVER_INTROSPECTION_CREDENTIALS
|
|
#
|
|
# try:
|
|
# access_token = AccessToken.objects.select_related("application", "user").get(token=token)
|
|
# except AccessToken.DoesNotExist:
|
|
# access_token = None
|
|
#
|
|
# # if there is no token or it's invalid then introspect the token if there's an external OAuth server
|
|
# if not access_token or not access_token.is_valid(scopes):
|
|
# if introspection_url and (introspection_token or introspection_credentials):
|
|
# access_token = self._get_token_from_authentication_server(
|
|
# token,
|
|
# introspection_url,
|
|
# introspection_token,
|
|
# introspection_credentials
|
|
# )
|
|
#
|
|
# if access_token and access_token.is_valid(scopes):
|
|
# request.client = access_token.application
|
|
# request.user = access_token.user or (access_token.application and access_token.application.user)
|
|
# request.scopes = scopes
|
|
#
|
|
# # this is needed by django rest framework
|
|
# request.access_token = access_token
|
|
# return True
|
|
# else:
|
|
# self._set_oauth2_error_on_request(request, access_token, scopes)
|
|
# return False
|