Implement osdf code to enable ssl
[optf/osdf.git] / osdfapp.py
index a2af0bf..b8afbf4 100755 (executable)
 OSDF Manager Main Flask Application
 """
 
+import json
+import ssl
 import sys
+import traceback
+from optparse import OptionParser
 from threading import Thread  # for scaling up, may need celery with RabbitMQ or redis
 
+import pydevd
 from flask import Flask, request, Response, g
+from requests import RequestException
+from schematics.exceptions import DataError
 
-import osdf
-import pydevd
-import json
-import osdf.adapters.policy.interface
-import osdf.config.credentials
-import osdf.config.loader
-import osdf.operation.error_handling
+import osdf.adapters.aaf.sms as sms
 import osdf.operation.responses
-import traceback
 from osdf.adapters.policy.interface import get_policies
+from osdf.adapters.policy.interface import upload_policy_models
 from osdf.config.base import osdf_config
+from osdf.logging.osdf_logging import MH, audit_log, error_log, debug_log
+from osdf.models.api.pciOptimizationRequest import PCIOptimizationAPI
+from osdf.models.api.placementRequest import PlacementAPI
+from osdf.operation.error_handling import request_exception_to_json_body, internal_error_message
+from osdf.operation.exceptions import BusinessException
+from osdf.operation.responses import osdf_response_for_request_accept as req_accept
+from osdf.optimizers.pciopt.pci_opt_processor import process_pci_optimation
 from osdf.optimizers.placementopt.conductor.remote_opt_processor import process_placement_opt
+from osdf.optimizers.routeopt.simple_route_opt import RouteOpt
+from osdf.utils import api_data_utils
 from osdf.webapp.appcontroller import auth_basic
-from optparse import OptionParser
-from osdf.operation.exceptions import BusinessException
-from osdf.operation.error_handling import request_exception_to_json_body, internal_error_message
-from requests import RequestException
-from schematics.exceptions import DataError
-from osdf.logging.osdf_logging import MH, audit_log, error_log
-from osdf.models.api.placementRequest import PlacementAPI
 
 ERROR_TEMPLATE = osdf.ERROR_TEMPLATE
 
 app = Flask(__name__)
 
-
-
 BAD_CLIENT_REQUEST_MESSAGE = 'Client sent an invalid request'
 
-# An exception explicitly raised due to some business rule
+
 @app.errorhandler(BusinessException)
 def handle_business_exception(e):
+    """An exception explicitly raised due to some business rule"""
     error_log.error("Synchronous error for request id {} {}".format(g.request_id, traceback.format_exc()))
     err_msg = ERROR_TEMPLATE.render(description=str(e))
     response = Response(err_msg, content_type='application/json; charset=utf-8')
     response.status_code = 400
     return response
 
-# Returns a detailed synchronous message to the calling client when osdf fails due to a remote call to another system
+
 @app.errorhandler(RequestException)
 def handle_request_exception(e):
+    """Returns a detailed synchronous message to the calling client
+    when osdf fails due to a remote call to another system"""
     error_log.error("Synchronous error for request id {} {}".format(g.request_id, traceback.format_exc()))
     err_msg = request_exception_to_json_body(e)
     response = Response(err_msg, content_type='application/json; charset=utf-8')
     response.status_code = 400
     return response
 
-# Returns a detailed message to the calling client when the initial synchronous message is invalid
+
 @app.errorhandler(DataError)
 def handle_data_error(e):
+    """Returns a detailed message to the calling client when the initial synchronous message is invalid"""
     error_log.error("Synchronous error for request id {} {}".format(g.request_id, traceback.format_exc()))
 
     body_dictionary = {
         "serviceException": {
             "text": BAD_CLIENT_REQUEST_MESSAGE,
-            "exceptionMessage": str(e.messages),
+            "exceptionMessage": str(e.errors),
             "errorType": "InvalidClientRequest"
         }
     }
@@ -91,9 +96,35 @@ def handle_data_error(e):
     return response
 
 
-@app.route("/osdf/api/v2/placement", methods=["POST"])
+@app.route("/api/oof/v1/healthcheck", methods=["GET"])
+def do_osdf_health_check():
+    """Simple health check"""
+    audit_log.info("A health check request is processed!")
+    return "OK"
+
+
+@app.route("/api/oof/loadmodels/v1", methods=["GET"])
+def do_osdf_load_policies():
+    audit_log.info("Uploading policy models")
+    """Upload policy models"""
+    response = upload_policy_models()
+    audit_log.info(response)
+    return "OK"
+
+
+@app.route("/api/oof/v1/placement", methods=["POST"])
 @auth_basic.login_required
 def do_placement_opt():
+    return placement_rest_api()
+
+
+@app.route("/api/oof/placement/v1", methods=["POST"])
+@auth_basic.login_required
+def do_placement_opt_common_versioning():
+    return placement_rest_api()
+
+
+def placement_rest_api():
     """Perform placement optimization after validating the request and fetching policies
     Make a call to the call-back URL with the output of the placement request.
     Note: Call to Conductor for placement optimization may have redirects, so account for them
@@ -102,26 +133,51 @@ def do_placement_opt():
     req_id = request_json['requestInfo']['requestId']
     g.request_id = req_id
     audit_log.info(MH.received_request(request.url, request.remote_addr, json.dumps(request_json)))
-
+    api_version_info = api_data_utils.retrieve_version_info(request, req_id)
     PlacementAPI(request_json).validate()
+    policies = get_policies(request_json, "placement")
+    audit_log.info(MH.new_worker_thread(req_id, "[for placement]"))
+    t = Thread(target=process_placement_opt, args=(request_json, policies, osdf_config))
+    t.start()
+    audit_log.info(MH.accepted_valid_request(req_id, request))
+    return req_accept(request_id=req_id,
+                      transaction_id=request_json['requestInfo']['transactionId'],
+                      version_info=api_version_info, request_status="accepted", status_message="")
+
 
-    # Currently policies are being used only during placement, so only fetch them if placement demands is not empty
-    policies = {}
+@app.route("/api/oof/v1/route", methods=["POST"])
+def do_route_calc():
+    """
+    Perform the basic route calculations and returnn the vpn-bindings
+    """
+    request_json = request.get_json()
+    audit_log.info("Calculate Route request received!")
+    return RouteOpt().getRoute(request_json)
 
-    if 'placementDemand' in request_json['placementInfo']['demandInfo']:
-        policies, prov_status = get_policies(request_json, "placement")
 
-    audit_log.info(MH.new_worker_thread(req_id, "[for placement]"))
-    t = Thread(target=process_placement_opt, args=(request_json, policies, osdf_config, prov_status))
+@app.route("/api/oof/v1/pci", methods=["POST"])
+@app.route("/api/oof/pci/v1", methods=["POST"])
+@auth_basic.login_required
+def do_pci_optimization():
+    request_json = request.get_json()
+    req_id = request_json['requestInfo']['requestId']
+    g.request_id = req_id
+    audit_log.info(MH.received_request(request.url, request.remote_addr, json.dumps(request_json)))
+    PCIOptimizationAPI(request_json).validate()
+    # disable policy retrieval
+    # policies = get_policies(request_json, "pciopt")
+    audit_log.info(MH.new_worker_thread(req_id, "[for pciopt]"))
+    t = Thread(target=process_pci_optimation, args=(request_json, osdf_config, None))
     t.start()
     audit_log.info(MH.accepted_valid_request(req_id, request))
-    return osdf.operation.responses.osdf_response_for_request_accept(
-        req_id=req_id, text="Accepted placement request. Response will be posted to callback URL")
+    return req_accept(request_id=req_id,
+                      transaction_id=request_json['requestInfo']['transactionId'],
+                      request_status="accepted", status_message="")
 
 
-# Returned when unexpected coding errors occur during initial synchronous processing
 @app.errorhandler(500)
 def internal_failure(error):
+    """Returned when unexpected coding errors occur during initial synchronous processing"""
     error_log.error("Synchronous error for request id {} {}".format(g.request_id, traceback.format_exc()))
     response = Response(internal_error_message, content_type='application/json; charset=utf-8')
     response.status_code = 500
@@ -129,36 +185,49 @@ def internal_failure(error):
 
 
 def get_options(argv):
-    program_version_string = '%%prog %s' % ("v1.0")
+    program_version_string = '%%prog %s' % "v1.0"
     program_longdesc = ""
     program_license = ""
 
     parser = OptionParser(version=program_version_string, epilog=program_longdesc, description=program_license)
     parser.add_option("-l", "--local", dest="local", help="run locally", action="store_true", default=False)
-    parser.add_option("-t", "--devtest", dest="devtest", help="run in dev/test environment", action="store_true", default=False)
+    parser.add_option("-t", "--devtest", dest="devtest", help="run in dev/test environment", action="store_true",
+                      default=False)
     parser.add_option("-d", "--debughost", dest="debughost", help="IP Address of host running debug server", default='')
     parser.add_option("-p", "--debugport", dest="debugport", help="Port number of debug server", type=int, default=5678)
-    (opts, args) = parser.parse_args(argv)
+    opts, args = parser.parse_args(argv)
 
-    if (opts.debughost != ''):
-        print('pydevd.settrace(%s, port=%s)' % (opts.debughost, opts.debugport))
+    if opts.debughost:
+        debug_log.debug('pydevd.settrace({}, port={})'.format(opts.debughost, opts.debugport))
         pydevd.settrace(opts.debughost, port=opts.debugport)
     return opts
 
 
+def build_ssl_context():
+    ssl_context = ssl.SSLContext(ssl.PROTOCOL_TLSv1_2)
+    ssl_context.set_ciphers('ECDHE-RSA-AES128-SHA256:EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH')
+    ssl_context.load_cert_chain(sys_conf['ssl_context'][0], sys_conf['ssl_context'][1])
+    return ssl_context
+
+
 if __name__ == "__main__":
 
     sys_conf = osdf_config['core']['osdf_system']
     ports = sys_conf['osdf_ports']
     internal_port, external_port = ports['internal'], ports['external']
-    ssl_context = tuple(sys_conf['ssl_context'])
-    local_host = "0.0.0.0"  # NOSONAR
 
+    local_host = sys_conf['osdf_ip_default']
     common_app_opts = dict(host=local_host, threaded=True, use_reloader=False)
 
+    ssl_opts = sys_conf.get('ssl_context')
+    if ssl_opts:
+        common_app_opts.update({'ssl_context': build_ssl_context()})
+
     opts = get_options(sys.argv)
-    if (not opts.local and not opts.devtest):  # normal deployment
-        app.run(port=internal_port, ssl_context=ssl_context, debug=False, **common_app_opts)
+    # Load secrets from SMS
+    sms.load_secrets()
+    if not opts.local and not opts.devtest:  # normal deployment
+        app.run(port=internal_port, debug=False, **common_app_opts)
     else:
         port = internal_port if opts.local else external_port
         app.run(port=port, debug=True, **common_app_opts)