X-Git-Url: https://git.mdrn.pl/django-cas-provider.git/blobdiff_plain/93472270e0bb9c9b3d3c54e99e9f13e4d272b367..9cd57bfa9544aa6793e6cf5a678590b4cad83986:/cas_provider/views.py diff --git a/cas_provider/views.py b/cas_provider/views.py index 41d02fd..b2e54f2 100644 --- a/cas_provider/views.py +++ b/cas_provider/views.py @@ -11,11 +11,28 @@ from models import ServiceTicket, LoginTicket __all__ = ['login', 'validate', 'logout', 'service_validate'] +INVALID_TICKET = 1 +INVALID_SERVICE = 2 +INVALID_REQUEST = 3 + +ERROR_MESSAGES = ( + (INVALID_TICKET, u'The provided ticket is invalid.'), + (INVALID_SERVICE, u'Service is invalid'), + (INVALID_REQUEST, u'Not all required parameters were sent.'), +) + + def login(request, template_name='cas/login.html', \ - success_redirect=getattr(settings, 'LOGIN_REDIRECT_URL', '/accounts/')): + success_redirect=settings.LOGIN_REDIRECT_URL, + warn_template_name='cas/warn.html'): service = request.GET.get('service', None) if request.user.is_authenticated(): if service is not None: + if request.GET.get('warn', False): + return render_to_response(warn_template_name, { + 'service': service, + 'warn': False + }, context_instance=RequestContext(request)) ticket = ServiceTicket.objects.create(service=service, user=request.user) return HttpResponseRedirect(ticket.get_redirect_url()) else: @@ -50,16 +67,17 @@ def validate(request): ticket = ServiceTicket.objects.get(ticket=ticket_string) username = ticket.user.username ticket.delete() - return HttpResponse("yes\r\n%s\r\n" % username) + return HttpResponse("yes\n%s\n" % username) except: pass - return HttpResponse("no\r\n\r\n") + return HttpResponse("no\n\n") def logout(request, template_name='cas/logout.html'): url = request.GET.get('url', None) auth_logout(request) - return render_to_response(template_name, {'url': url}, context_instance=RequestContext(request)) + return render_to_response(template_name, {'url': url}, \ + context_instance=RequestContext(request)) def service_validate(request): @@ -67,29 +85,36 @@ def service_validate(request): service = request.GET.get('service', None) ticket_string = request.GET.get('ticket', None) if service is None or ticket_string is None: - return _cas2_error_response(u'INVALID_REQUEST', u'Not all required parameters were sent.') + return _cas2_error_response(INVALID_REQUEST) try: ticket = ServiceTicket.objects.get(ticket=ticket_string) except ServiceTicket.DoesNotExist: - return _cas2_error_response(u'INVALID_TICKET', u'The provided ticket is invalid.') + return _cas2_error_response(INVALID_TICKET) if settings.CAS_CHECK_SERVICE and ticket.service != service: ticket.delete() - return _cas2_error_response('INVALID_SERVICE', u'Service is invalid') + return _cas2_error_response(INVALID_SERVICE) username = ticket.user.username ticket.delete() + return _cas2_sucess_response(username) + + +def _cas2_error_response(code): + return HttpResponse(u'''' + + %(message)s + + ''' % { + 'code': code, + 'message': dict(ERROR_MESSAGES).get(code) + }, mimetype='text/xml') + + +def _cas2_sucess_response(username): return HttpResponse(u''' %(username)s ''' % {'username': username}, mimetype='text/xml') - - -def _cas2_error_response(code, message): - return HttpResponse(u'''' - - %s - - ''', mimetype='text/xml')