a56a53d8cf60e333ea4ce1ade9de9cbaf6c48dbf
[optf/osdf.git] / osdf / webapp / appcontroller.py
1 # -------------------------------------------------------------------------
2 #   Copyright (c) 2015-2017 AT&T Intellectual Property
3 #
4 #   Licensed under the Apache License, Version 2.0 (the "License");
5 #   you may not use this file except in compliance with the License.
6 #   You may obtain a copy of the License at
7 #
8 #       http://www.apache.org/licenses/LICENSE-2.0
9 #
10 #   Unless required by applicable law or agreed to in writing, software
11 #   distributed under the License is distributed on an "AS IS" BASIS,
12 #   WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 #   See the License for the specific language governing permissions and
14 #   limitations under the License.
15 #
16 # -------------------------------------------------------------------------
17 #
18
19 from flask import request
20 from flask_httpauth import HTTPBasicAuth
21 from flask import Response
22 import json
23 import osdf
24 from osdf.config.base import http_basic_auth_credentials
25 from osdf.adapters.aaf import aaf_authentication as aaf_auth
26
27 auth_basic = HTTPBasicAuth()
28
29 error_body = {
30     "serviceException": {
31         "text": "Unauthorized, check username and password"
32     }
33 }
34
35 unauthorized_message = json.dumps(error_body)
36
37 @auth_basic.get_password
38 def get_pw(username):
39     end_point = request.url.split('/')[-1]
40     auth_group = osdf.end_point_auth_mapping.get(end_point)
41     return http_basic_auth_credentials[auth_group].get(username) if auth_group else None
42
43 @auth_basic.error_handler
44 def auth_error():
45     response = Response(unauthorized_message, content_type='application/json; charset=utf-8')
46     response.headers.add('content-length', len(unauthorized_message))
47     response.status_code = 401
48     return response
49
50
51 @auth_basic.verify_password
52 def verify_pw(username, password):
53     is_aaf_enabled = osdf.deployment.get('is_aaf_enabled', False)
54     if is_aaf_enabled:
55         return aaf_auth.authenticate(username, password)
56     else:
57         pw = get_pw(username)
58         return pw == password
59     return False