external resource introspection
This commit is contained in:
parent
56ebabad7f
commit
b6b9e0d9c2
4 changed files with 46 additions and 5 deletions
|
|
@ -7,9 +7,8 @@ from django.contrib.admin.sites import NotRegistered
|
||||||
|
|
||||||
from oauth2_provider.admin import ApplicationAdmin
|
from oauth2_provider.admin import ApplicationAdmin
|
||||||
|
|
||||||
from .models import Application
|
from .models import Application, Resource, Scope
|
||||||
from .forms import ApplicationForm
|
from .forms import ApplicationForm
|
||||||
from .models import Scope
|
|
||||||
|
|
||||||
|
|
||||||
# The restricted application is registered by Django OAuth Toolkit, but we want
|
# The restricted application is registered by Django OAuth Toolkit, but we want
|
||||||
|
|
@ -20,10 +19,15 @@ except NotRegistered:
|
||||||
pass
|
pass
|
||||||
|
|
||||||
@admin.register(Application)
|
@admin.register(Application)
|
||||||
class RestrictedApplicationAdmin(ApplicationAdmin):
|
class ApplicationAdmin(ApplicationAdmin):
|
||||||
form = ApplicationForm
|
form = ApplicationForm
|
||||||
|
|
||||||
|
|
||||||
|
@admin.register(Resource)
|
||||||
|
class ResourceAdmin(admin.ModelAdmin):
|
||||||
|
list_display = ("token", "user", "expires")
|
||||||
|
|
||||||
|
|
||||||
@admin.register(Scope)
|
@admin.register(Scope)
|
||||||
class ScopeAdmin(admin.ModelAdmin):
|
class ScopeAdmin(admin.ModelAdmin):
|
||||||
list_display = ('name', 'description', 'is_default')
|
list_display = ('name', 'description', 'is_default')
|
||||||
|
|
|
||||||
37
apps/gooyal_oauth2/migrations/0003_auto_20200611_0828.py
Normal file
37
apps/gooyal_oauth2/migrations/0003_auto_20200611_0828.py
Normal file
|
|
@ -0,0 +1,37 @@
|
||||||
|
# Generated by Django 3.0.6 on 2020-06-11 08:28
|
||||||
|
|
||||||
|
from django.conf import settings
|
||||||
|
from django.db import migrations, models
|
||||||
|
import django.db.models.deletion
|
||||||
|
import uuid
|
||||||
|
|
||||||
|
|
||||||
|
class Migration(migrations.Migration):
|
||||||
|
|
||||||
|
dependencies = [
|
||||||
|
migrations.swappable_dependency(settings.AUTH_USER_MODEL),
|
||||||
|
('gooyal_oauth2', '0002_scope'),
|
||||||
|
]
|
||||||
|
|
||||||
|
operations = [
|
||||||
|
migrations.AlterField(
|
||||||
|
model_name='application',
|
||||||
|
name='user',
|
||||||
|
field=models.ForeignKey(blank=True, null=True, on_delete=django.db.models.deletion.CASCADE, related_name='gooyal_oauth2_application', to=settings.AUTH_USER_MODEL),
|
||||||
|
),
|
||||||
|
migrations.CreateModel(
|
||||||
|
name='Resource',
|
||||||
|
fields=[
|
||||||
|
('created', models.DateTimeField(auto_now_add=True)),
|
||||||
|
('updated', models.DateTimeField(auto_now=True)),
|
||||||
|
('uuid', models.UUIDField(db_index=True, default=uuid.uuid4, editable=False, primary_key=True, serialize=False, unique=True)),
|
||||||
|
('name', models.CharField(blank=True, max_length=255)),
|
||||||
|
('expires', models.DateTimeField()),
|
||||||
|
('token', models.CharField(max_length=255, unique=True)),
|
||||||
|
('user', models.ForeignKey(blank=True, null=True, on_delete=django.db.models.deletion.CASCADE, related_name='resources', to=settings.AUTH_USER_MODEL)),
|
||||||
|
],
|
||||||
|
options={
|
||||||
|
'abstract': False,
|
||||||
|
},
|
||||||
|
),
|
||||||
|
]
|
||||||
|
|
@ -63,7 +63,7 @@ class IntrospectOAuth2Validator(OAuth2Validator):
|
||||||
introspection_credentials = oauth2_settings.RESOURCE_SERVER_INTROSPECTION_CREDENTIALS
|
introspection_credentials = oauth2_settings.RESOURCE_SERVER_INTROSPECTION_CREDENTIALS
|
||||||
|
|
||||||
try:
|
try:
|
||||||
access_token = Resource.objects.select_related("application", "user").get(token=token)
|
access_token = Resource.objects.select_related("user").get(token=token)
|
||||||
except Resource.DoesNotExist:
|
except Resource.DoesNotExist:
|
||||||
access_token = None
|
access_token = None
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -47,7 +47,7 @@ def protected_resource(scopes=None):
|
||||||
|
|
||||||
@require_http_methods(['GET', 'POST'])
|
@require_http_methods(['GET', 'POST'])
|
||||||
@csrf_exempt
|
@csrf_exempt
|
||||||
@protected_resource(scopes=[settings.INTROSPECT_SCOPE])
|
@protected_resource(scopes=['introspection'])
|
||||||
def introspect_token(request):
|
def introspect_token(request):
|
||||||
"""
|
"""
|
||||||
Version of the introspection view protected by a regular scope instead of
|
Version of the introspection view protected by a regular scope instead of
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue