annotate AuthTokenGenerator.py @ 2:4c6c8835fc5c

new version for new Annotator Auth API using PyJWT.
author casties
date Fri, 23 Mar 2012 17:50:06 +0100
parents c33668e282fa
children 17bbd5e80d15
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
0
c33668e282fa first checkin.
casties
parents:
diff changeset
1 from OFS.SimpleItem import SimpleItem
c33668e282fa first checkin.
casties
parents:
diff changeset
2 from Products.PageTemplates.PageTemplateFile import PageTemplateFile
c33668e282fa first checkin.
casties
parents:
diff changeset
3 from OFS.PropertyManager import PropertyManager
c33668e282fa first checkin.
casties
parents:
diff changeset
4
2
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
5 import logging
0
c33668e282fa first checkin.
casties
parents:
diff changeset
6 import datetime
2
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
7 import jwt
0
c33668e282fa first checkin.
casties
parents:
diff changeset
8
c33668e282fa first checkin.
casties
parents:
diff changeset
9
c33668e282fa first checkin.
casties
parents:
diff changeset
10 ZERO = datetime.timedelta(0)
c33668e282fa first checkin.
casties
parents:
diff changeset
11 class Utc(datetime.tzinfo):
c33668e282fa first checkin.
casties
parents:
diff changeset
12 def utcoffset(self, dt):
c33668e282fa first checkin.
casties
parents:
diff changeset
13 return ZERO
c33668e282fa first checkin.
casties
parents:
diff changeset
14
c33668e282fa first checkin.
casties
parents:
diff changeset
15 def tzname(self, dt):
c33668e282fa first checkin.
casties
parents:
diff changeset
16 return "UTC"
c33668e282fa first checkin.
casties
parents:
diff changeset
17
c33668e282fa first checkin.
casties
parents:
diff changeset
18 def dst(self, dt):
c33668e282fa first checkin.
casties
parents:
diff changeset
19 return ZERO
c33668e282fa first checkin.
casties
parents:
diff changeset
20 UTC = Utc()
c33668e282fa first checkin.
casties
parents:
diff changeset
21
c33668e282fa first checkin.
casties
parents:
diff changeset
22
c33668e282fa first checkin.
casties
parents:
diff changeset
23 class AuthTokenGenerator(SimpleItem, PropertyManager):
c33668e282fa first checkin.
casties
parents:
diff changeset
24 """Generator of auth tokens for OKFN Annotator"""
c33668e282fa first checkin.
casties
parents:
diff changeset
25
c33668e282fa first checkin.
casties
parents:
diff changeset
26 meta_type = 'AuthTokenGenerator'
2
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
27 _properties = ({'id':'consumer_key', 'type': 'string', 'mode': 'w'},
0
c33668e282fa first checkin.
casties
parents:
diff changeset
28 {'id':'consumer_secret', 'type': 'string', 'mode': 'w'},
c33668e282fa first checkin.
casties
parents:
diff changeset
29 )
c33668e282fa first checkin.
casties
parents:
diff changeset
30
c33668e282fa first checkin.
casties
parents:
diff changeset
31 manage_options = PropertyManager.manage_options + SimpleItem.manage_options
c33668e282fa first checkin.
casties
parents:
diff changeset
32
c33668e282fa first checkin.
casties
parents:
diff changeset
33 # Only change this if you're sure you know what you're doing
2
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
34 tokenTtl = 86400
0
c33668e282fa first checkin.
casties
parents:
diff changeset
35
c33668e282fa first checkin.
casties
parents:
diff changeset
36 def __init__(self, id, consumerKey=None, consumerSecret=None):
c33668e282fa first checkin.
casties
parents:
diff changeset
37 """init document viewer"""
2
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
38 self.id = id
0
c33668e282fa first checkin.
casties
parents:
diff changeset
39 self.consumer_key = consumerKey
c33668e282fa first checkin.
casties
parents:
diff changeset
40 self.consumer_secret = consumerSecret
c33668e282fa first checkin.
casties
parents:
diff changeset
41
c33668e282fa first checkin.
casties
parents:
diff changeset
42 def index_html(self, user='anonymous', password=None):
c33668e282fa first checkin.
casties
parents:
diff changeset
43 """returns authentication token for user"""
c33668e282fa first checkin.
casties
parents:
diff changeset
44 if self._token_allowed():
c33668e282fa first checkin.
casties
parents:
diff changeset
45 token = self._generate_token(user)
2
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
46 # set CORS headers
0
c33668e282fa first checkin.
casties
parents:
diff changeset
47 origin = self.REQUEST.getHeader("Origin", None)
c33668e282fa first checkin.
casties
parents:
diff changeset
48 if origin is not None:
c33668e282fa first checkin.
casties
parents:
diff changeset
49 self.REQUEST.RESPONSE.setHeader("Access-Control-Allow-Origin", origin)
c33668e282fa first checkin.
casties
parents:
diff changeset
50 else:
c33668e282fa first checkin.
casties
parents:
diff changeset
51 self.REQUEST.RESPONSE.setHeader("Access-Control-Allow-Origin", "*")
c33668e282fa first checkin.
casties
parents:
diff changeset
52
c33668e282fa first checkin.
casties
parents:
diff changeset
53 self.REQUEST.RESPONSE.setHeader("Access-Control-Allow-Credentials", "true")
2
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
54 logging.debug("token=%s"%token)
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
55 self.REQUEST.RESPONSE.setHeader("Content-Type", "text/plain")
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
56 return token
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
57 # send as JSON
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
58 #self.REQUEST.RESPONSE.setHeader("Content-Type", "application/json")
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
59 #json.dump(token, self.REQUEST.RESPONSE)
0
c33668e282fa first checkin.
casties
parents:
diff changeset
60 else:
c33668e282fa first checkin.
casties
parents:
diff changeset
61 self.REQUEST.RESPONSE.setStatus('Forbidden')
c33668e282fa first checkin.
casties
parents:
diff changeset
62 return "SORRY, NOT ALLOWED!"
c33668e282fa first checkin.
casties
parents:
diff changeset
63
c33668e282fa first checkin.
casties
parents:
diff changeset
64 def _token_allowed(self, user=None, password=None):
c33668e282fa first checkin.
casties
parents:
diff changeset
65 # here we should check the login
c33668e282fa first checkin.
casties
parents:
diff changeset
66 return True
c33668e282fa first checkin.
casties
parents:
diff changeset
67
c33668e282fa first checkin.
casties
parents:
diff changeset
68 def _generate_token(self, user_id):
c33668e282fa first checkin.
casties
parents:
diff changeset
69 #return JSON-token
2
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
70 issue_time = datetime.datetime.now(UTC).replace(microsecond=0)
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
71
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
72 return jwt.encode({
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
73 'consumerKey': self.consumer_key,
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
74 'userId': user_id,
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
75 'issuedAt': issue_time.isoformat(),
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
76 'ttl': self.tokenTtl
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
77 }, self.consumer_secret)
4c6c8835fc5c new version for new Annotator Auth API using PyJWT.
casties
parents: 0
diff changeset
78
0
c33668e282fa first checkin.
casties
parents:
diff changeset
79
c33668e282fa first checkin.
casties
parents:
diff changeset
80 def manage_addAuthTokenGeneratorForm(self):
c33668e282fa first checkin.
casties
parents:
diff changeset
81 """form for adding AuthTokenGenerator"""
c33668e282fa first checkin.
casties
parents:
diff changeset
82 pt = PageTemplateFile("zpt/manage_addAuthTokenGenerator", globals()).__of__(self)
c33668e282fa first checkin.
casties
parents:
diff changeset
83 return pt()
c33668e282fa first checkin.
casties
parents:
diff changeset
84
c33668e282fa first checkin.
casties
parents:
diff changeset
85 def manage_addAuthTokenGenerator(context, id, consumerKey=None, consumerSecret=None):
c33668e282fa first checkin.
casties
parents:
diff changeset
86 """ """
c33668e282fa first checkin.
casties
parents:
diff changeset
87 context._setObject(id, AuthTokenGenerator(id, consumerKey=consumerKey, consumerSecret=consumerSecret))
c33668e282fa first checkin.
casties
parents:
diff changeset
88 return "AuthTokenGenerator Installed: %s" % id