4 from sfa.util.faults import *
5 from sfa.util.method import Method
6 from sfa.util.parameter import Parameter, Mixed
7 from sfa.trust.auth import Auth
8 from sfa.util.sfaticket import SfaTicket
10 class get_ticket(Method):
12 Retrieve a ticket. This operation is currently implemented on PLC
13 only (see SFA, engineering decisions); it is not implemented on
16 The ticket is filled in with information from the PLC database. This
17 information includes resources, and attributes such as user keys and
20 @param cred credential string
21 @param name name of the slice to retrieve a ticket for
22 @param rspec resource specification dictionary
24 @return the string representation of a ticket object
27 interfaces = ['registry']
30 Parameter(str, "Credential string"),
31 Parameter(str, "Human readable name of slice to retrive a ticket for (hrn)"),
32 Parameter(str, "Resource specification (rspec)"),
33 Mixed(Parameter(str, "Request hash"),
34 Parameter(None, "Request hash not specified"))
37 returns = Parameter(str, "String represeneation of a ticket object")
39 def call(self, cred, hrn, rspec, request_hash=None):
40 self.api.auth.authenticateCred(cred, [cred, hrn, rspec], request_hash)
41 self.api.auth.check(cred, "getticket")
42 self.api.auth.verify_object_belongs_to_me(hrn)
43 self.api.auth.verify_object_permission(name)
45 # XXX much of this code looks like get_credential... are they so similar
46 # that they should be combined?
48 auth_hrn = self.api.auth.get_authority(hrn)
51 auth_info = self.api.auth.get_auth_info(auth_hrn)
53 table = self.api.auth.get_auth_table(auth_hrn)
54 record = table.resolve('slice', hrn)
56 object_gid = record.get_gid_object()
57 new_ticket = SfaTicket(subject = object_gid.get_subject())
58 new_ticket.set_gid_caller(self.client_gid)
59 new_ticket.set_gid_object(object_gid)
60 new_ticket.set_issuer(key=auth_info.get_pkey_object(), subject=auth_hrn)
61 new_ticket.set_pubkey(object_gid.get_pubkey())
63 self.api.fill_record_info(record)
65 (attributes, rspec) = self.api.record_to_slice_info(record)
67 new_ticket.set_attributes(attributes)
68 new_ticket.set_rspec(rspec)
70 new_ticket.set_parent(self.api.auth.hierarchy.get_auth_ticket(auth_hrn))
75 return new_ticket.save_to_string(save_parents=True)