X-Git-Url: https://git.mdrn.pl/django-cas-provider.git/blobdiff_plain/b012d252975d36d17a2368bd0ee79088a2407bb0..refs/heads/master:/cas_provider/models.py?ds=inline diff --git a/cas_provider/models.py b/cas_provider/models.py index 5d09912..8e05337 100644 --- a/cas_provider/models.py +++ b/cas_provider/models.py @@ -1,41 +1,95 @@ -from django.db import models -from django.contrib.auth.models import User from django.conf import settings -from django.core.urlresolvers import get_callable +from django.db import models +from django.utils.translation import gettext_lazy as _ +from random import Random +import string +from urllib.parse import urlencode, urlparse, parse_qs, ParseResult -from cas_provider.etree import etree, register_namespace, ElementRoot -class ServiceTicket(models.Model): - user = models.ForeignKey(User) - service = models.URLField(verify_exists=False) - ticket = models.CharField(max_length=256) - created = models.DateTimeField(auto_now=True) - - def __unicode__(self): - return "%s (%s) - %s" % (self.user.username, self.service, self.created) - -class LoginTicket(models.Model): - ticket = models.CharField(max_length=32) - created = models.DateTimeField(auto_now=True) - +__all__ = ['ServiceTicket', 'LoginTicket', 'ProxyGrantingTicket', 'ProxyTicket', 'ProxyGrantingTicketIOU'] + +class BaseTicket(models.Model): + ticket = models.CharField(_('ticket'), max_length=32) + created = models.DateTimeField(_('created'), auto_now=True) + + class Meta: + abstract = True + + def __init__(self, *args, **kwargs): + super(BaseTicket, self).__init__(*args, **kwargs) + if not self.ticket: + self.ticket = self._generate_ticket() + def __unicode__(self): - return "%s - %s" % (self.ticket, self.created) - -CAS_URI = 'http://www.yale.edu/tp/cas' -register_namespace('cas', CAS_URI) -CAS = '{%s}' % CAS_URI - -def auth_success_response(user): - attrs = {} - if settings.CAS_CUSTOM_ATTRIBUTES_CALLBACK: - callback = get_callable(settings.CAS_CUSTOM_ATTRIBUTES_CALLBACK) - attrs = callback(user) - - response = ElementRoot(CAS + 'serviceResponse') - auth_success = etree.SubElement(response, CAS + 'authenticationSuccess') - username = etree.SubElement(auth_success, CAS + 'user') - username.text = user.username - for name, value in attrs.items(): - element = etree.SubElement(auth_success, name) - element.text = value - return unicode(etree.tostring(response, encoding='utf-8'), 'utf-8') + return self.ticket + + def _generate_ticket(self, length=ticket.max_length, chars=string.ascii_letters + string.digits): + """ Generates a random string of the requested length. Used for creation of tickets. """ + return "%s-%s" % (self.prefix, ''.join(Random().sample(chars, length - (len(self.prefix) + 1)))) + + +class ServiceTicket(BaseTicket): + user = models.ForeignKey(settings.AUTH_USER_MODEL, verbose_name=_('user'), on_delete=models.CASCADE) + service = models.URLField(_('service'), max_length=2048) + + prefix = 'ST' + + class Meta: + verbose_name = _('Service Ticket') + verbose_name_plural = _('Service Tickets') + + def get_redirect_url(self): + parsed = urlparse(self.service) + query = parse_qs(parsed.query) + query['ticket'] = [self.ticket] + query = [((k, v) if len(v) > 1 else (k, v[0])) for k, v in query.items()] + parsed = ParseResult(parsed.scheme, parsed.netloc, + parsed.path, parsed.params, + urlencode(query), parsed.fragment) + return parsed.geturl() + + +class LoginTicket(BaseTicket): + prefix = 'LT' + + class Meta: + verbose_name = _('Login Ticket') + verbose_name_plural = _('Login Tickets') + + +class ProxyGrantingTicket(BaseTicket): + user = models.ForeignKey(settings.AUTH_USER_MODEL, verbose_name=_('user'), on_delete=models.CASCADE) + service = models.URLField(_('service'), null=True) + pgt = models.ForeignKey('self', null=True, on_delete=models.CASCADE) + pgtiou = models.CharField(max_length=256, verbose_name=_('PGTiou')) + prefix = 'PGT' + + def __init__(self, *args, **kwargs): + super(ProxyGrantingTicket, self).__init__(*args, **kwargs) + if not self.pgtiou: + self.pgtiou = "PGTIOU-%s" % (''.join(Random().sample(string.ascii_letters + string.digits, 50))) + + class Meta: + verbose_name = _('Proxy Granting Ticket') + verbose_name_plural = _('Proxy Granting Tickets') + + +class ProxyTicket(ServiceTicket): + proxyGrantingTicket = models.ForeignKey(ProxyGrantingTicket, verbose_name=_('Proxy Granting Ticket'), on_delete=models.CASCADE) + + prefix = 'PT' + + class Meta: + verbose_name = _('Proxy Ticket') + verbose_name_plural = _('Proxy Tickets') + + +class ProxyGrantingTicketIOU(BaseTicket): + proxyGrantingTicket = models.ForeignKey(ProxyGrantingTicket, verbose_name=_('Proxy Granting Ticket'), on_delete=models.CASCADE) + + prefix = 'PGTIOU' + + class Meta: + verbose_name = _('Proxy Granting Ticket IOU') + verbose_name_plural = _('Proxy Granting Tickets IOU') +