1 # -*- coding: utf-8 -*-
3 # portal/views.py: views for the portal application
4 # This file is part of the Manifold project.
7 # Jordan Augé <jordan.auge@lip6.fr>
8 # Mohammed Yasin Rahman <mohammed-yasin.rahman@lip6.fr>
9 # Loic Baron <loic.baron@lip6.fr>
10 # Copyright 2013, UPMC Sorbonne Universités / LIP6
12 # This program is free software; you can redistribute it and/or modify it under
13 # the terms of the GNU General Public License as published by the Free Software
14 # Foundation; either version 3, or (at your option) any later version.
16 # This program is distributed in the hope that it will be useful, but WITHOUT
17 # ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
18 # FOR A PARTICULAR PURPOSE. See the GNU General Public License for more
21 # You should have received a copy of the GNU General Public License along with
22 # this program; see the file COPYING. If not, write to the Free Software
23 # Foundation, 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
27 from django.http import HttpResponseRedirect, HttpResponse
28 from django.shortcuts import render
29 from django.template.loader import render_to_string
31 from unfold.loginrequired import FreeAccessView
32 from ui.topmenu import topmenu_items_live, the_user
34 from portal.event import Event
35 # presview is put in observation for now
36 #from plugins.pres_view import PresView
37 from plugins.raw import Raw
39 # these seem totally unused for now
40 #from portal.util import RegistrationView, ActivationView
42 from portal.models import PendingUser, PendingSlice
43 from portal.actions import get_requests
44 from manifoldapi.manifoldapi import execute_query
45 from manifold.core.query import Query
46 from unfold.page import Page
47 from theme import ThemeView
49 class ValidatePendingView(FreeAccessView, ThemeView):
50 template_name = "validate_pending.html"
52 def get_context_data(self, **kwargs):
53 # We might have slices on different registries with different user accounts
54 # We note that this portal could be specific to a given registry, to which we register users, but i'm not sure that simplifies things
55 # Different registries mean different identities, unless we identify via SFA HRN or have associated the user email to a single hrn
57 #messages.info(self.request, 'You have logged in')
58 page = Page(self.request)
60 ctx_my_authorities = {}
61 ctx_delegation_authorities = {}
62 ctx_sub_authorities = {}
66 # The user need to be logged in
67 if the_user(self.request):
68 # Who can a PI validate:
69 # His own authorities + those he has credentials for.
70 # In MySlice we need to look at credentials also.
73 # XXX This will have to be asynchroneous. Need to implement barriers,
74 # for now it will be sufficient to have it working statically
76 # get user_id to later on query accounts
77 # XXX Having real query plan on local tables would simplify all this
78 # XXX $user_email is still not available for local tables
79 #user_query = Query().get('local:user').filter_by('email', '==', '$user_email').select('user_id')
80 user_query = Query().get('local:user').filter_by('email', '==', the_user(self.request)).select('user_id')
81 user, = execute_query(self.request, user_query)
82 user_id = user['user_id']
84 # Query manifold to learn about available SFA platforms for more information
85 # In general we will at least have the portal
86 # For now we are considering all registries
89 sfa_platforms_query = Query().get('local:platform').filter_by('gateway_type', '==', 'sfa').select('platform_id', 'platform', 'auth_type')
90 sfa_platforms = execute_query(self.request, sfa_platforms_query)
91 for sfa_platform in sfa_platforms:
92 print "SFA PLATFORM > ", sfa_platform['platform']
93 if not 'auth_type' in sfa_platform:
95 auth = sfa_platform['auth_type']
96 if not auth in all_authorities:
97 all_authorities.append(auth)
98 platform_ids.append(sfa_platform['platform_id'])
100 print "W: Hardcoding platform myslice"
101 # There has been a tweak on how new platforms are referencing a
102 # so-called 'myslice' platform for storing authentication tokens.
103 # XXX This has to be removed in final versions.
104 myslice_platforms_query = Query().get('local:platform').filter_by('platform', '==', 'myslice').select('platform_id')
105 myslice_platforms = execute_query(self.request, myslice_platforms_query)
106 if myslice_platforms:
107 myslice_platform, = myslice_platforms
108 platform_ids.append(myslice_platform['platform_id'])
110 # We can check on which the user has authoritity credentials = PI rights
111 credential_authorities = set()
112 credential_authorities_expired = set()
114 # User account on these registries
115 user_accounts_query = Query.get('local:account').filter_by('user_id', '==', user_id).filter_by('platform_id', 'included', platform_ids).select('auth_type', 'config')
116 user_accounts = execute_query(self.request, user_accounts_query)
120 for user_account in user_accounts:
122 print "USER ACCOUNT", user_account
123 if user_account['auth_type'] == 'reference':
124 continue # we hardcoded the myslice platform...
126 config = json.loads(user_account['config'])
128 print "CONFIG KEYS", config.keys()
129 if 'authority_credentials' in config:
130 print "***", config['authority_credentials'].keys()
131 for authority_hrn, credential in config['authority_credentials'].items():
132 #if credential is not expired:
133 credential_authorities.add(authority_hrn)
135 # credential_authorities_expired.add(authority_hrn)
136 if 'delegated_authority_credentials' in config:
137 print "***", config['delegated_authority_credentials'].keys()
138 for authority_hrn, credential in config['delegated_authority_credentials'].items():
139 #if credential is not expired:
140 credential_authorities.add(authority_hrn)
142 # credential_authorities_expired.add(authority_hrn)
144 print 'credential_authorities =', credential_authorities
145 print 'credential_authorities_expired =', credential_authorities_expired
147 # # Using cache manifold-tables to get the list of authorities faster
148 # all_authorities_query = Query.get('authority').select('name', 'authority_hrn')
149 # all_authorities = execute_query(self.request, all_authorities_query)
151 # ** Where am I a PI **
152 # For this we need to ask SFA (of all authorities) = PI function
153 pi_authorities_query = Query.get('user').filter_by('user_hrn', '==', '$user_hrn').select('pi_authorities')
154 pi_authorities_tmp = execute_query(self.request, pi_authorities_query)
155 pi_authorities = set()
156 for pa in pi_authorities_tmp:
157 pi_authorities |= set(pa['pi_authorities'])
159 # # include all sub-authorities of the PI
160 # # if PI on ple, include all sub-auths ple.upmc, ple.inria and so on...
161 # pi_subauthorities = set()
162 # for authority in all_authorities:
163 # authority_hrn = authority['authority_hrn']
164 # for my_authority in pi_authorities:
165 # if authority_hrn.startswith(my_authority) and authority_hrn not in pi_subauthorities:
166 # pi_subauthorities.add(authority_hrn)
168 #print "pi_authorities =", pi_authorities
169 #print "pi_subauthorities =", pi_subauthorities
171 # My authorities + I have a credential
172 pi_credential_authorities = pi_authorities & credential_authorities
173 pi_no_credential_authorities = pi_authorities - credential_authorities - credential_authorities_expired
174 pi_expired_credential_authorities = pi_authorities & credential_authorities_expired
175 # Authorities I've been delegated PI rights
176 pi_delegation_credential_authorities = credential_authorities - pi_authorities
177 pi_delegation_expired_authorities = credential_authorities_expired - pi_authorities
179 #print "pi_credential_authorities =", pi_credential_authorities
180 #print "pi_no_credential_authorities =", pi_no_credential_authorities
181 #print "pi_expired_credential_authorities =", pi_expired_credential_authorities
182 #print "pi_delegation_credential_authorities = ", pi_delegation_credential_authorities
183 #print "pi_delegation_expired_authorities = ", pi_delegation_expired_authorities
185 # Summary intermediary
186 pi_my_authorities = pi_credential_authorities | pi_no_credential_authorities | pi_expired_credential_authorities
187 pi_delegation_authorities = pi_delegation_credential_authorities | pi_delegation_expired_authorities
190 #print "pi_my_authorities = ", pi_my_authorities
191 #print "pi_delegation_authorities = ", pi_delegation_authorities
192 #print "pi_subauthorities = ", pi_subauthorities
195 queried_pending_authorities = pi_my_authorities | pi_delegation_authorities #| pi_subauthorities
197 #print "queried_pending_authorities = ", queried_pending_authorities
199 # iterate on the requests and check if the authority matches a prefix startswith an authority on which the user is PI
200 requests = get_requests()
201 # requests = get_requests(queried_pending_authorities)
202 for request in requests:
203 auth_hrn = request['authority_hrn']
204 for my_auth in pi_my_authorities:
205 if auth_hrn.startswith(my_auth):
206 dest = ctx_my_authorities
207 request['allowed'] = 'allowed'
208 for my_auth in pi_delegation_authorities:
209 if auth_hrn.startswith(my_auth):
210 dest = ctx_delegation_authorities
211 request['allowed'] = 'allowed'
212 if auth_hrn in pi_expired_credential_authorities:
213 request['allowed'] = 'expired'
214 if 'allowed' not in request:
215 request['allowed'] = 'denied'
216 #print "authority for this request", auth_hrn
218 # if auth_hrn in pi_my_authorities:
219 # dest = ctx_my_authorities
221 # # define the css class
222 # if auth_hrn in pi_credential_authorities:
223 # request['allowed'] = 'allowed'
224 # elif auth_hrn in pi_expired_credential_authorities:
225 # request['allowed'] = 'expired'
226 # else: # pi_no_credential_authorities
227 # request['allowed'] = 'denied'
229 # elif auth_hrn in pi_delegation_authorities:
230 # dest = ctx_delegation_authorities
232 # if auth_hrn in pi_delegation_credential_authorities:
233 # request['allowed'] = 'allowed'
234 # else: # pi_delegation_expired_authorities
235 # request['allowed'] = 'expired'
237 # elif auth_hrn in pi_subauthorities:
238 # dest = ctx_sub_authorities
240 # if auth_hrn in pi_subauthorities:
241 # request['allowed'] = 'allowed'
242 # else: # pi_delegation_expired_authorities
243 # request['allowed'] = 'denied'
248 if not auth_hrn in dest:
250 dest[auth_hrn].append(request)
252 context = super(ValidatePendingView, self).get_context_data(**kwargs)
253 context['my_authorities'] = ctx_my_authorities
254 context['sub_authorities'] = ctx_sub_authorities
255 context['delegation_authorities'] = ctx_delegation_authorities
257 # XXX This is repeated in all pages
258 # more general variables expected in the template
259 context['title'] = 'Test view that combines various plugins'
260 # the menu items on the top
261 context['topmenu_items'] = topmenu_items_live('Validation', page)
262 # so we can sho who is logged
263 context['username'] = the_user(self.request)
265 context['theme'] = self.theme
266 # XXX We need to prepare the page for queries
267 #context.update(page.prelude_env())