diff --git a/accounts/urls.py b/accounts/urls.py index 21ff5a0..2719555 100644 --- a/accounts/urls.py +++ b/accounts/urls.py @@ -36,7 +36,7 @@ urlpatterns = [ path('admin/', admin.site.urls), path('wallet/', include('apps.wallet.urls')), path('users/', include('apps.users.urls')), - path('', include('apps.superapp.urls')), + path('superapp/', include('apps.superapp.urls')), path('oauth2/', include('oauth2_provider.urls', namespace='oauth2_provider')), diff --git a/apps/superapp/serializers.py b/apps/superapp/serializers.py index a699c92..277499f 100755 --- a/apps/superapp/serializers.py +++ b/apps/superapp/serializers.py @@ -8,10 +8,12 @@ from .models import App class AppSerializer(serializers.ModelSerializer): class Meta: model = App - fields = ('title', - 'description', - 'order', - "logo", - "type", - 'url', - ) + fields = ( + 'uuid', + 'title', + 'description', + 'order', + "logo", + "type", + 'url', + ) diff --git a/apps/superapp/urls.py b/apps/superapp/urls.py index a715cbd..a08640f 100644 --- a/apps/superapp/urls.py +++ b/apps/superapp/urls.py @@ -1,10 +1,11 @@ from django.urls import path -from .views import AppListView, AppDetailView, AppListAPIView +from .views import AppListView, AppDetailView, AppListAPIView, AppDetailAPIView app_name = "superapp" urlpatterns = [ path('api/applications/', AppListAPIView.as_view(), name='app_list_api'), + path('api/applications/', AppDetailAPIView.as_view(), name='app_detail_api'), path('', AppListView.as_view(), name='app_list'), path('', AppDetailView.as_view(), name='app_detail'), ] \ No newline at end of file diff --git a/apps/superapp/views.py b/apps/superapp/views.py index 9b44226..a7693a5 100644 --- a/apps/superapp/views.py +++ b/apps/superapp/views.py @@ -34,3 +34,15 @@ class AppListAPIView(generics.ListAPIView): def get_queryset(self): return App.objects.all() + + +class AppDetailAPIView(generics.RetrieveAPIView): + permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements] + serializer_class = AppSerializer + lookup_field = 'uuid' + required_alternate_scopes = { + "GET": [['superapp.applications:retrieve']], + } + + def get_queryset(self): + return App.objects.all() diff --git a/client.py b/client.py index 677b4b1..77e5997 100644 --- a/client.py +++ b/client.py @@ -1,14 +1,15 @@ import json +import time + import requests OAUTH_CLIENT_ID = 'WNQzBFHxell95Px45veRncL2vIw6l90Q4Zr5yKuU' -'PFY1JXAb0c7H88GAsyzAYzSMWBR5R8QvSux7e0uCeeqGeUJj8yNvW4isZz6E7U0gUTTF5KRtuTZf59iztjfwZgto8rGe0czqMSarUhLHf8hYMotsJNRgQb98wvbFiHca' -# OAUTH_CLIENT_SECRET = 'pbkdf2_sha256$390000$A8ru6iwhcjU1wEgPL6n6b8$GOhCcrfqw4Xkw6USpuEL6esjmNgqJe1A8q1Ec2dLxhw=' OAUTH_CLIENT_SECRET = 'pbkdf2_sha256$390000$cu9a2xBKZzR5sLfcBNsRB6$UZ6MurBq8mfccWDdCCvNTCv3EyiAKSGkh51l2rlAYVk=' +# OAUTH_CLIENT_ID = 'zaKGaL7IpjRHzfzjbmcXIUAlPIPCf3ZNsqKuBh1t' +# OAUTH_CLIENT_ID = 'zaKGaL7IpjRHzfzjbmcXIUAlPIPCf3ZNsqKuBh1t' +# OAUTH_CLIENT_SECRET = 'pbkdf2_sha256$390000$wyByMVckbY9beSRc9ZXNBo$cN5f17TAV13FD+1ioRQ1ANnNOVCd31JJbIrmswxFxA4=' +# OAUTH_CLIENT_SECRET = 'pbkdf2_sha256$390000$aAYjehfEm4Jw8FWU1cV5so$OIzTz03dHupFypxfjm4wCBw/J86Bbd4RlmhpMrxo8Bo=' API_URI = 'https://accounts.mindplus-dev.ir' -# API_URI = 'https://accounts.gooyal.com' -# NOTIFICATION_URI = 'https://notifications.gooyal.com' -# NOTIFICATION_URI = 'http://127.0.0.1:8001' class ApiClient(): @@ -26,7 +27,6 @@ class ApiClient(): "grant_type": "password", "username": phone_number, "password": password, - # "scope": 'introspection', "scope": 'introspection education.course:retrieve superapp.applications:list accounts.account:request_ott accounts.profile:list accounts.profile:retrieve accounts.account:retrieve accounts.account:update accounts.profile:inquiry accounts.account:change_password wallet.transaction:list wallet.invoice:create wallet.transaction:retrieve wallet.invoice:pay wallet.invoice:receipt wallet.deposit:submit wallet.deposit:verify wallet.withdraw:submit wallet.withdraw:verify ', "auth_fields": 'phone_number:otp' } @@ -41,7 +41,7 @@ class ApiClient(): auth_data = response.json() if 'access_token' in auth_data: self.auth_data = auth_data - + print(auth_data) return auth_data def ott_login(self, token): @@ -68,6 +68,34 @@ class ApiClient(): return auth_data + def login_as_client_credentials(self): + access_token = self.auth_data.get('access_token') + expires_in = self.auth_data.get('expires_in') + created_at = self.auth_data.get('created_at') + + if access_token and expires_in > time.time() - created_at: + return self.auth_data + + data = { + "grant_type": 'client_credentials', + "scope": 'wallet.deposit:submit wallet.deposit:verify', + } + auth = (OAUTH_CLIENT_ID, OAUTH_CLIENT_SECRET) + + response = requests.post(f'{API_URI}/oauth2/token/', + data=data, + auth=auth) + + + auth_data = response.json() + print(auth_data) + if 'access_token' in auth_data: + auth_data['created_at'] = time.time() + self.auth_data = auth_data + + return auth_data + + def _request(self, url, data=None, files=None, method='get', with_auth=True, encode=True): if files: header = {} @@ -101,57 +129,6 @@ class ApiClient(): result = self._request(url=url, data=data, method=method, with_auth=False) return result - def get_account(self): - path = 'users/api/account/' - url = f'{API_URI}/{path}' - result = self._request(url=url) - return result - - def update_account(self, **kwargs): - path = 'users/api/account/' - url = f'{API_URI}/{path}' - data = {} - fields = ( - 'username', - "first_name", - "last_name", - 'name', - 'iban', - 'iban_card_number', - 'iban_account_number', - ) - for key, value in kwargs.items(): - if key in fields: - data.setdefault(key, value) - - avatar = kwargs.get('avatar') - if avatar: - files = {'avatar': avatar} - encode = False - else: - files = None - encode = True - - result = self._request(url=url, data=data, method='put', files=files, encode=encode) - return result - - def change_password(self, old_password, new_password, old_password_gateway='otp'): - path = 'users/api/change_password/' - url = f'{API_URI}/{path}' - data = {'old_password': old_password, - 'new_password': new_password, - 'old_password_gateway': old_password_gateway - } - - result = self._request(url=url, data=data, method='put') - return result - - def get_user_profile(self, code): - path = f'users/api/users/{code}/' - url = f'{API_URI}/{path}' - result = self._request(url=url) - return result - def get_application_list(self, page=None): path = 'api/applications/' if page: @@ -161,96 +138,34 @@ class ApiClient(): return self._request(url=url) - def get_transactions(self, page=None): - path = 'wallet/api/transactions/' - if page: - page = int(page) - path = f'{path}?page={page}' - url = f'{API_URI}/{path}' - - return self._request(url=url) - - def get_transaction(self, code): - path = f'transactions/{code}' - url = f'{API_URI}/{path}' - return self._request(url=url) - def get_course_list(self): - url = 'http://markaz:8002/api/courses/' + url = 'https://edu-srv.mindplus-dev.ir/api/courses/' return self._request(url=url) - # create user invoice - # def create_invoice(self, amount, delay, payer=None): - # data = { - # 'delay': delay, - # 'amount': amount - # } - # if payer: - # data.setdefault('payer', {'code': payer}) - # response = self._request('transactions/', method='post', data=data) - # return response and 'code' in response, response - - # create application invoice def get_application_token(self): path = 'users/api/request_ott/' + data = { + 'application': 'https://edu.mindplus-dev.ir' + } url = f'{API_URI}/{path}' - response = self._request(url, method='get') + response = self._request(url, method='POST',data=data) return response and 'code' in response, response - def create_invoice(self, amount, delay=0): - path = 'wallet/api/transactions/' + def update_account(self, first_name): + path = '/users/api/account/' + data = { + 'first_name': first_name + } url = f'{API_URI}/{path}' - data = { - 'delay': delay, - 'amount': amount - } - response = self._request(url, method='post', data=data) + response = self._request(url, method='PUT', data=data) return response and 'code' in response, response - def pay_invoice(self, code): - path = f'wallet/api/transactions/{code}/pay' - return self._request(path=path) - - def receipt_transaction(self, code): - path = f'transactions/{code}/receipt' - return self._request(path=path) - - def get_introspection(self): - path = 'oauth2/introspect/' - access_token = self.auth_data.get('access_token', '') - data = { - 'token': access_token, - } - return self._request(path=path, data=data) - - def notify(self): - data = { - 'phone_number': "+989106853582", - 'body': 'this is a test' - } - # data = json.dumps(data) - header = { - # "Content-Type": "application/json", - "charset": "utf-8" - } - access_token = self.auth_data.get('access_token', '') - # access_token = 'Px7WLUKoynua6qJq5IkIG8Fn5dPLXq' - header.setdefault("Authorization", f"Bearer {access_token}", ) - - response = requests.request('post', f'{NOTIFICATION_URI}/notifications/', headers=header, json=data) - try: - return response.json() - except: - return response.text - client = ApiClient('+989106853582') -client.request_otp() -client.otp_login('12345') -print(client.get_application_list()) -print(client.get_course_list()) -# print(client.get_application_token()) -# print(client.ott_login('abcdef12345')) - -# print(client.create_invoice(2000, 10)) -# print(client.pay_invoice('7967a76a-5de1-48b2-92ac-1b0f39f7223b')) +# print(client.login_as_client_credentials()) +print(client.request_otp()) +print(client.otp_login('12345')) +print(client.update_account('Sayyid Hamid')) +# ott = client.get_application_token()[1]['ott'] +# print(client.ott_login(ott)) +# print(ott)