INTROSPECTION_USER_CREATE_METHOD in settings
This commit is contained in:
parent
7cb2de4338
commit
f1cec16495
3 changed files with 55 additions and 45 deletions
|
|
@ -1,10 +1,19 @@
|
||||||
from oauth2_provider.settings import OAuth2ProviderSettings, USER_SETTINGS, DEFAULTS, IMPORT_STRINGS, MANDATORY
|
from oauth2_provider.settings import OAuth2ProviderSettings, USER_SETTINGS, DEFAULTS, IMPORT_STRINGS, MANDATORY
|
||||||
|
|
||||||
GOOYAL_DEFAULTS = {
|
GOOYAL_DEFAULTS = {
|
||||||
|
# Resource Server with Token Introspection additions
|
||||||
"RESOURCE_SERVER_CLIENT_ID": None,
|
"RESOURCE_SERVER_CLIENT_ID": None,
|
||||||
"RESOURCE_SERVER_CLIENT_SECRET": None
|
"RESOURCE_SERVER_CLIENT_SECRET": None,
|
||||||
}
|
|
||||||
|
"INTROSPECTION_USER_CREATE_METHOD": None,
|
||||||
|
}
|
||||||
|
|
||||||
|
GOOYAL_IMPORT_STRINGS = ("INTROSPECTION_USER_CREATE_METHOD",)
|
||||||
|
|
||||||
|
GOOYAL_MANDATORY = ("INTROSPECTION_USER_CREATE_METHOD",)
|
||||||
|
|
||||||
DEFAULTS.update(GOOYAL_DEFAULTS)
|
DEFAULTS.update(GOOYAL_DEFAULTS)
|
||||||
|
IMPORT_STRINGS = IMPORT_STRINGS + GOOYAL_IMPORT_STRINGS
|
||||||
|
MANDATORY = MANDATORY + GOOYAL_MANDATORY
|
||||||
|
|
||||||
oauth2_settings = OAuth2ProviderSettings(USER_SETTINGS, DEFAULTS, IMPORT_STRINGS, MANDATORY)
|
oauth2_settings = OAuth2ProviderSettings(USER_SETTINGS, DEFAULTS, IMPORT_STRINGS, MANDATORY)
|
||||||
|
|
|
||||||
|
|
@ -4,7 +4,6 @@ from datetime import datetime, timedelta
|
||||||
|
|
||||||
import requests
|
import requests
|
||||||
import service_clients
|
import service_clients
|
||||||
from django.conf import settings
|
|
||||||
from django.contrib.auth import get_user_model
|
from django.contrib.auth import get_user_model
|
||||||
from django.utils.timezone import make_aware
|
from django.utils.timezone import make_aware
|
||||||
from oauth2_provider.models import get_access_token_model
|
from oauth2_provider.models import get_access_token_model
|
||||||
|
|
@ -17,39 +16,7 @@ AccessTokenModel = get_access_token_model()
|
||||||
UserModel = get_user_model()
|
UserModel = get_user_model()
|
||||||
|
|
||||||
|
|
||||||
class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
|
def get_user_profile(token, content):
|
||||||
def validate_user(self, username, password, client, request, *args, **kwargs):
|
|
||||||
auth_fields = getattr(request, 'auth_fields', 'username:password').split(':')
|
|
||||||
|
|
||||||
if len(auth_fields) != 2:
|
|
||||||
return False
|
|
||||||
|
|
||||||
user_field, pass_field = auth_fields
|
|
||||||
|
|
||||||
if user_field not in ['phone_number', 'username', 'email']:
|
|
||||||
return False
|
|
||||||
|
|
||||||
if pass_field not in ['password', 'otp']:
|
|
||||||
return False
|
|
||||||
|
|
||||||
if not username or not password:
|
|
||||||
return False
|
|
||||||
|
|
||||||
user = UserModel.objects.filter(**{user_field: username}).first()
|
|
||||||
|
|
||||||
if not user:
|
|
||||||
return False
|
|
||||||
|
|
||||||
if not user.check_auth(pass_field, password):
|
|
||||||
return False
|
|
||||||
|
|
||||||
if user.is_active:
|
|
||||||
request.user = user
|
|
||||||
return True
|
|
||||||
|
|
||||||
return False
|
|
||||||
|
|
||||||
def _get_user_profile(self, token, content):
|
|
||||||
# content = {
|
# content = {
|
||||||
# "active": True,
|
# "active": True,
|
||||||
# "scope": "read write email",
|
# "scope": "read write email",
|
||||||
|
|
@ -89,6 +56,39 @@ class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
|
||||||
)
|
)
|
||||||
return user, content
|
return user, content
|
||||||
|
|
||||||
|
|
||||||
|
class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
|
||||||
|
def validate_user(self, username, password, client, request, *args, **kwargs):
|
||||||
|
auth_fields = getattr(request, 'auth_fields', 'username:password').split(':')
|
||||||
|
|
||||||
|
if len(auth_fields) != 2:
|
||||||
|
return False
|
||||||
|
|
||||||
|
user_field, pass_field = auth_fields
|
||||||
|
|
||||||
|
if user_field not in ['phone_number', 'username', 'email']:
|
||||||
|
return False
|
||||||
|
|
||||||
|
if pass_field not in ['password', 'otp']:
|
||||||
|
return False
|
||||||
|
|
||||||
|
if not username or not password:
|
||||||
|
return False
|
||||||
|
|
||||||
|
user = UserModel.objects.filter(**{user_field: username}).first()
|
||||||
|
|
||||||
|
if not user:
|
||||||
|
return False
|
||||||
|
|
||||||
|
if not user.check_auth(pass_field, password):
|
||||||
|
return False
|
||||||
|
|
||||||
|
if user.is_active:
|
||||||
|
request.user = user
|
||||||
|
return True
|
||||||
|
|
||||||
|
return False
|
||||||
|
|
||||||
def _get_token_from_gooyal_authentication_server(
|
def _get_token_from_gooyal_authentication_server(
|
||||||
self, token, introspection_url, introspection_token, introspection_credentials, introspection_client_id,
|
self, token, introspection_url, introspection_token, introspection_credentials, introspection_client_id,
|
||||||
introspection_client_secret
|
introspection_client_secret
|
||||||
|
|
@ -154,7 +154,7 @@ class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
|
||||||
user = None
|
user = None
|
||||||
if "active" in content and content["active"] is True:
|
if "active" in content and content["active"] is True:
|
||||||
if "username" in content:
|
if "username" in content:
|
||||||
user, content = self._get_user_profile(token, content)
|
user, content = oauth2_settings.INTROSPECTION_USER_CREATE_METHOD(token, content)
|
||||||
|
|
||||||
max_caching_time = datetime.now() + timedelta(
|
max_caching_time = datetime.now() + timedelta(
|
||||||
seconds=oauth2_settings.RESOURCE_SERVER_TOKEN_CACHING_SECONDS
|
seconds=oauth2_settings.RESOURCE_SERVER_TOKEN_CACHING_SECONDS
|
||||||
|
|
|
||||||
|
|
@ -69,7 +69,8 @@ OAUTH2_PROVIDER = {
|
||||||
'write': 'Write scope',
|
'write': 'Write scope',
|
||||||
'groups': 'Access to your groups',
|
'groups': 'Access to your groups',
|
||||||
'introspection': 'Introspect token scope'},
|
'introspection': 'Introspect token scope'},
|
||||||
'OAUTH2_VALIDATOR_CLASS': 'apps.gooyal_oauth2.validators.OAuth2Validator'
|
'OAUTH2_VALIDATOR_CLASS': 'apps.gooyal_oauth2.validators.OAuth2Validator',
|
||||||
|
"INTROSPECTION_USER_CREATE_METHOD": 'apps.gooyal_oauth2.validators.get_user_profile',
|
||||||
}
|
}
|
||||||
|
|
||||||
# GOOYAL_DYNAMIC_SCOPES
|
# GOOYAL_DYNAMIC_SCOPES
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue