Exemple #1
0
    def login(request):
        """
        Log a user in. Creates an access_token using a persona
        assertion and the client secret. Sets this access token as a cookie.
        'target_url' based as a GET parameter determines where the user is
        redirected.
        """

        target_url = request.POST.get('target_url')
        assertion = request.POST.get('Assertion')
        postdata = {
            'Assertion': assertion,
            'ClientSecret':settings.CLIENT_SECRET
        }

        url = build_url(request.get_host(), ['auth'])
        try:
            response = requests.post(url, data=postdata, headers={})
        except RequestException:
            return ErrorView.server_error(request)
        access_token = response.json()['data']
        if access_token is None:
            return ErrorView.server_error(request)

        response = HttpResponseRedirect(target_url if target_url != '' else '/')
        expires = datetime.datetime.fromtimestamp(2 ** 31 - 1)
        response.set_cookie('access_token', access_token, expires=expires, httponly=True)
        return response
Exemple #2
0
    def logout(request):
        """
        Log a user out.

        Issues a DELETE request to the backend for the user's access_token, and
        issues a delete cookie header in response to clear the user's
        access_token cookie.
        """

        response = redirect('/')
        if request.COOKIES.has_key('access_token'):
            response.set_cookie('access_token',
                                '',
                                expires="Thu, 01 Jan 1970 00:00:00 GMT")
            url = build_url(request.get_host(), ['auth', request.access_token])
            try:
                requests.post(url,
                              params={
                                  'method': 'DELETE',
                                  'access_token': request.access_token
                              })
            except RequestException:
                return ErrorView.server_error(request)

        return response
Exemple #3
0
def csv(request, event_id):
    """
    Downloads a CSV file containing event attendees.
    """
    return redirect(
        build_url(request.get_host(), ["events", "%s", "attendeescsv"]) %
        (event_id, ) + "?access_token=" + request.access_token, )
Exemple #4
0
    def login(request):
        """
        Log a user in using auth0

        Creates an access_token using an auth0 code and state.

        Sets this access token as a cookie.

        'target_url' based as a GET parameter determines where the user is
        redirected.
        """

        code = request.GET.get('code')
        state = request.GET.get('state')
        target_url = request.GET.get('target_url')

        postdata = {
            'Code': code,
            'State': state,
            'ClientSecret': settings.CLIENT_SECRET
        }

        url = build_url(request.get_host(), ['auth0'])
        try:
            response = requests.post(url, data=postdata, headers={})
        except RequestException:
            return ErrorView.server_error(request)

        access_token = response.json()['data']
        if access_token is None or access_token == '':
            return ErrorView.server_error(request)

        if target_url is None or target_url == '':
            target_url = state

        if target_url is None or target_url == '':
            target_url = '/'

        # Add cachebuster as the unauth'd page may be very aggressively cached
        pr = urlparse(target_url)
        qs = parse_qs(pr[4])
        qs.update({'cachebuster': id_generator()})
        target_url = urlunparse(
            (pr[0], pr[1], pr[2], pr[3], urlencode(qs), pr[5]))

        # Redirect and set cookie
        resp = HttpResponseRedirect(target_url)
        expires = datetime.datetime.fromtimestamp(2**31 - 1)
        resp.set_cookie('access_token',
                        access_token,
                        expires=expires,
                        httponly=True)

        return resp
Exemple #5
0
 def testEmptyFragments(self):
     url = build_url((BuildURLTests.subdomain_key + settings.API_DOMAIN_NAME), [])
     assert (
         url
         == settings.API_SCHEME
         + BuildURLTests.subdomain_key
         + settings.API_DOMAIN_NAME
         + "/"
         + settings.API_PATH
         + "/"
         + settings.API_VERSION
     )
Exemple #6
0
def csv(request, event_id):
    """
    Downloads a CSV file containing event attendees.
    """
    return redirect(
        build_url(
            request.get_host(),
            ["events", "%s", "attendeescsv"]
        ) % (
            event_id,
        ) + "?access_token=" + request.access_token,
    )
Exemple #7
0
 def testIntFragment(self):
     url = build_url((BuildURLTests.subdomain_key + settings.API_DOMAIN_NAME), [1, 2, 3])
     assert (
         url
         == settings.API_SCHEME
         + BuildURLTests.subdomain_key
         + settings.API_DOMAIN_NAME
         + "/"
         + settings.API_PATH
         + "/"
         + settings.API_VERSION
         + "/1/2/3"
     )
Exemple #8
0
 def testWithNoSeparator(self):
     url = build_url((BuildURLTests.subdomain_key + settings.API_DOMAIN_NAME), ["resource", "1", "extra"])
     assert (
         url
         == settings.API_SCHEME
         + BuildURLTests.subdomain_key
         + settings.API_DOMAIN_NAME
         + "/"
         + settings.API_PATH
         + "/"
         + settings.API_VERSION
         + "/resource/1/extra"
     )
Exemple #9
0
    def login(request):
        """
        Log a user in using auth0

        Creates an access_token using an auth0 code and state.

        Sets this access token as a cookie.

        'target_url' based as a GET parameter determines where the user is
        redirected.
        """

        code = request.GET.get('code')
        state = request.GET.get('state')
        target_url = request.GET.get('target_url')

        postdata = {
            'Code': code,
            'State': state,
            'ClientSecret': settings.CLIENT_SECRET
        }

        url = build_url(request.get_host(), ['auth0'])
        try:
            response = requests.post(url, data=postdata, headers={})
        except RequestException:
            return ErrorView.server_error(request)

        access_token = response.json()['data']
        if access_token is None or access_token == '':
            return ErrorView.server_error(request)

        if target_url is None or target_url == '':
            target_url = state

        if target_url is None or target_url == '':
            target_url = '/'

        # Add cachebuster as the unauth'd page may be very aggressively cached
        pr = urlparse(target_url)
        qs = parse_qs(pr[4])
        qs.update({'cachebuster': id_generator()})
        target_url = urlunparse((pr[0], pr[1], pr[2], pr[3], urlencode(qs), pr[5]))

        # Redirect and set cookie
        resp = HttpResponseRedirect(target_url)
        expires = datetime.datetime.fromtimestamp(2 ** 31 - 1)
        resp.set_cookie('access_token', access_token, expires=expires, httponly=True)
       
        return resp
Exemple #10
0
    def logout(request):
        """
        Log a user out. Issues a DELETE request to the backend for the
        user's access_token, and issues a delete cookie header in response to
        clear the user's access_token cookie.
        """

        response = redirect('/')
        if request.COOKIES.has_key('access_token'):
            response.set_cookie('access_token', '', expires="Thu, 01 Jan 1970 00:00:00 GMT")
            url = build_url(request.get_host(), ['auth', request.access_token])
            try:
                requests.post(url, params={'method': 'DELETE', 'access_token': request.access_token})
            except RequestException:
                return ErrorView.server_error(request)

        return response
Exemple #11
0
    def login(request):
        """
        Log a user in using Persona.

        Creates an access_token using a persona assertion and the client secret.

        Sets this access token as a cookie.

        'target_url' based as a GET parameter determines where the user is
        redirected.
        """

        target_url = request.POST.get('target_url')
        assertion = request.POST.get('Assertion')
        postdata = {
            'Assertion': assertion,
            'ClientSecret': settings.CLIENT_SECRET
        }

        url = build_url(request.get_host(), ['auth'])
        try:
            response = requests.post(url, data=postdata, headers={})
        except RequestException:
            return ErrorView.server_error(request)

        access_token = response.json()['data']
        if access_token is None or access_token == '':
            return ErrorView.server_error(request)

        if target_url is None or target_url == '':
            target_url = '/'

        response = HttpResponseRedirect(target_url)
        expires = datetime.datetime.fromtimestamp(2**31 - 1)
        response.set_cookie('access_token',
                            access_token,
                            expires=expires,
                            httponly=True)
        return response
Exemple #12
0
 def testFailCustomDomains(self):
     with self.assertRaises(APIException):
         build_url((BuildURLTests.subdomain_key + 'example.org'),
                   ['resource', '1', 'ex/tra'])
Exemple #13
0
 def testFailCustomDomains(self):
     with self.assertRaises(APIException):
         build_url((BuildURLTests.subdomain_key + "example.org"), ["resource", "1", "ex/tra"])
Exemple #14
0
 def testFailCustomDomains(self):
     with self.assertRaises(APIException):
         build_url((BuildURLTests.subdomain_key + 'example.org'), ['resource', '1', 'ex/tra'])
Exemple #15
0
 def testInvalidFragment(self):
     with self.assertRaises(AssertionError):
         build_url((BuildURLTests.subdomain_key + settings.API_DOMAIN_NAME), ['resource', '1', 'ex/tra'])
Exemple #16
0
 def testWithNoSeparator(self):
     url = build_url((BuildURLTests.subdomain_key + settings.API_DOMAIN_NAME), ['resource', '1', 'extra'])
     assert url == settings.API_SCHEME + BuildURLTests.subdomain_key +\
                   settings.API_DOMAIN_NAME + '/' + settings.API_PATH + '/' + settings.API_VERSION + '/resource/1/extra'
Exemple #17
0
 def testInvalidFragment(self):
     with self.assertRaises(AssertionError):
         build_url((BuildURLTests.subdomain_key + settings.API_DOMAIN_NAME),
                   ['resource', '1', 'ex/tra'])
Exemple #18
0
 def testIntFragment(self):
     url = build_url(
         (BuildURLTests.subdomain_key + settings.API_DOMAIN_NAME),
         [1, 2, 3])
     assert url == settings.API_SCHEME + BuildURLTests.subdomain_key +\
                   settings.API_DOMAIN_NAME + '/' + settings.API_PATH + '/' + settings.API_VERSION + '/1/2/3'
Exemple #19
0
 def testEmptyFragments(self):
     url = build_url(
         (BuildURLTests.subdomain_key + settings.API_DOMAIN_NAME), [])
     assert url == settings.API_SCHEME + BuildURLTests.subdomain_key +\
                   settings.API_DOMAIN_NAME + '/' + settings.API_PATH + '/' + settings.API_VERSION
Exemple #20
0
 def testWithNoSeparator(self):
     url = build_url(
         (BuildURLTests.subdomain_key + settings.API_DOMAIN_NAME),
         ['resource', '1', 'extra'])
     assert url == settings.API_SCHEME + BuildURLTests.subdomain_key +\
                   settings.API_DOMAIN_NAME + '/' + settings.API_PATH + '/' + settings.API_VERSION + '/resource/1/extra'