canaille-globuzma/canaille/oidc/models.py

202 lines
5.7 KiB
Python
Raw Normal View History

2022-01-11 18:49:06 +00:00
import datetime
2024-04-07 14:39:05 +00:00
from typing import ClassVar
from typing import List
2022-01-11 18:49:06 +00:00
from authlib.oauth2.rfc6749 import AuthorizationCodeMixin
from authlib.oauth2.rfc6749 import ClientMixin
from authlib.oauth2.rfc6749 import TokenMixin
from authlib.oauth2.rfc6749 import util
from canaille.app import models
from canaille.backends import BaseBackend
2023-08-23 13:18:43 +00:00
from .basemodels import AuthorizationCode as BaseAuthorizationCode
from .basemodels import Client as BaseClient
from .basemodels import Consent as BaseConsent
from .basemodels import Token as BaseToken
class Client(BaseClient, ClientMixin):
2024-04-07 14:39:05 +00:00
client_info_attributes: ClassVar[List[str]] = [
"client_id",
"client_secret",
"client_id_issued_at",
"client_secret_expires_at",
]
2024-04-07 14:39:05 +00:00
client_metadata_attributes: ClassVar[List[str]] = [
"client_name",
"contacts",
"client_uri",
"redirect_uris",
"logo_uri",
"grant_types",
"response_types",
"scope",
"tos_uri",
"policy_uri",
"jwks_uri",
"jwk",
"token_endpoint_auth_method",
"software_id",
"software_version",
]
2022-01-11 18:49:06 +00:00
def get_client_id(self):
return self.client_id
2022-01-11 18:49:06 +00:00
def get_default_redirect_uri(self):
return self.redirect_uris[0]
2022-01-11 18:49:06 +00:00
def get_allowed_scope(self, scope):
2022-07-07 14:05:34 +00:00
return util.list_to_scope(
[scope_piece for scope_piece in self.scope if scope_piece in scope]
)
2022-01-11 18:49:06 +00:00
def check_redirect_uri(self, redirect_uri):
return redirect_uri in self.redirect_uris
2022-01-11 18:49:06 +00:00
def check_client_secret(self, client_secret):
2022-10-17 15:49:52 +00:00
return client_secret == self.client_secret
2022-01-11 18:49:06 +00:00
2022-04-10 14:00:51 +00:00
def check_endpoint_auth_method(self, method, endpoint):
if endpoint == "token":
return method == self.token_endpoint_auth_method
return True
2022-01-11 18:49:06 +00:00
def check_response_type(self, response_type):
2022-10-17 15:49:52 +00:00
return all(r in self.response_types for r in response_type.split(" "))
2022-01-11 18:49:06 +00:00
def check_grant_type(self, grant_type):
2022-10-17 15:49:52 +00:00
return grant_type in self.grant_types
2022-01-11 18:49:06 +00:00
@property
def client_info(self):
result = {
attribute_name: getattr(self, attribute_name)
for attribute_name in self.client_info_attributes
}
result["client_id_issued_at"] = int(
datetime.datetime.timestamp(result["client_id_issued_at"])
2022-01-11 18:49:06 +00:00
)
result["client_secret_expires_at"] = (
int(datetime.datetime.timestamp(result["client_secret_expires_at"]))
if result["client_secret_expires_at"]
else 0
)
return result
@property
def client_metadata(self):
metadata = {
attribute_name: getattr(self, attribute_name)
for attribute_name in self.client_metadata_attributes
}
2023-01-28 17:35:39 +00:00
metadata["scope"] = " ".join(metadata["scope"])
return metadata
2022-01-11 18:49:06 +00:00
def delete(self):
for consent in BaseBackend.instance.query(models.Consent, client=self):
consent.delete()
for code in BaseBackend.instance.query(models.AuthorizationCode, client=self):
code.delete()
for token in BaseBackend.instance.query(models.Token, client=self):
token.delete()
super().delete()
2022-01-11 18:49:06 +00:00
class AuthorizationCode(BaseAuthorizationCode, AuthorizationCodeMixin):
2022-01-11 18:49:06 +00:00
def get_redirect_uri(self):
return self.redirect_uri
2022-01-11 18:49:06 +00:00
def get_scope(self):
return self.scope
2022-01-11 18:49:06 +00:00
def get_nonce(self):
return self.nonce
2022-01-11 18:49:06 +00:00
def is_expired(self):
2023-03-17 23:38:56 +00:00
return self.issue_date + datetime.timedelta(
seconds=int(self.lifetime)
) < datetime.datetime.now(datetime.timezone.utc)
2022-01-11 18:49:06 +00:00
def get_auth_time(self):
2023-03-17 23:38:56 +00:00
return int(
(
self.issue_date
- datetime.datetime(1970, 1, 1, tzinfo=datetime.timezone.utc)
).total_seconds()
)
2022-01-11 18:49:06 +00:00
class Token(BaseToken, TokenMixin):
2022-01-11 18:49:06 +00:00
@property
def expire_date(self):
return self.issue_date + datetime.timedelta(seconds=int(self.lifetime))
2022-01-11 18:49:06 +00:00
@property
def revoked(self):
return bool(self.revokation_date)
2022-01-11 18:49:06 +00:00
def get_scope(self):
return " ".join(self.scope)
2022-01-11 18:49:06 +00:00
def get_issued_at(self):
2023-03-17 23:38:56 +00:00
return int(
(
self.issue_date
- datetime.datetime(1970, 1, 1, tzinfo=datetime.timezone.utc)
).total_seconds()
)
2022-01-11 18:49:06 +00:00
def get_expires_at(self):
issue_timestamp = (
2023-03-17 23:38:56 +00:00
self.issue_date
- datetime.datetime(1970, 1, 1, tzinfo=datetime.timezone.utc)
2022-01-11 18:49:06 +00:00
).total_seconds()
return int(issue_timestamp) + int(self.lifetime)
2022-01-11 18:49:06 +00:00
def is_refresh_token_active(self):
if self.revokation_date:
2022-01-11 18:49:06 +00:00
return False
2023-03-17 23:38:56 +00:00
return self.expire_date >= datetime.datetime.now(datetime.timezone.utc)
2022-01-11 18:49:06 +00:00
def is_expired(self):
2023-03-17 23:38:56 +00:00
return self.issue_date + datetime.timedelta(
seconds=int(self.lifetime)
) < datetime.datetime.now(datetime.timezone.utc)
2022-01-11 18:49:06 +00:00
2022-04-10 14:00:51 +00:00
def is_revoked(self):
return bool(self.revokation_date)
def check_client(self, client):
return client.client_id == self.client.client_id
2022-04-10 14:00:51 +00:00
2022-01-11 18:49:06 +00:00
class Consent(BaseConsent):
2023-02-14 17:43:43 +00:00
@property
def revoked(self):
return bool(self.revokation_date)
2022-01-11 18:49:06 +00:00
def revoke(self):
2023-03-17 23:38:56 +00:00
self.revokation_date = datetime.datetime.now(datetime.timezone.utc)
BaseBackend.instance.save(self)
2022-01-11 18:49:06 +00:00
tokens = BaseBackend.instance.query(
models.Token,
client=self.client,
subject=self.subject,
2022-01-11 18:49:06 +00:00
)
2023-02-14 17:43:43 +00:00
tokens = [token for token in tokens if not token.revoked]
2022-01-11 18:49:06 +00:00
for t in tokens:
t.revokation_date = self.revokation_date
BaseBackend.instance.save(t)
2023-02-14 17:43:43 +00:00
def restore(self):
self.revokation_date = None
BaseBackend.instance.save(self)