Merge branch 'onelab' of ssh://git.onelab.eu/git/myslice into onelab
[myslice.git] / rest / sfa_api.py
1 import os
2 import json
3 import ConfigParser 
4 import datetime
5 from time                           import mktime
6 import time
7 import xmltodict
8
9 from django.shortcuts               import render_to_response
10 from django.http                    import HttpResponse,QueryDict
11
12 from sfa.trust.certificate          import Keypair, Certificate
13 from sfa.client.sfaserverproxy      import SfaServerProxy
14 from manifold.gateways.sfa.proxy    import SFAProxy
15 from sfa.client.return_value        import ReturnValue
16 from sfa.util.xrn                   import Xrn, get_leaf, get_authority, hrn_to_urn, urn_to_hrn
17
18 from manifold.core.query            import Query
19
20 from manifoldapi.manifoldapi        import execute_admin_query
21
22 from unfold.loginrequired           import LoginRequiredView
23
24 from myslice.settings               import logger, config
25
26 from repoze.lru                     import lru_cache
27 from rest.json_encoder              import MyEncoder
28
29 import uuid
30 def unique_call_id(): return uuid.uuid4().urn
31
32 def dispatch(request, method):
33
34     hrn = None
35     urn = None
36     object_type = None
37     rspec = None
38     output_format = None
39     recursive = False
40     # Have to be hashable for lru_cache
41     options   = frozenset() # dict()
42     platforms = frozenset() # list()
43
44     results = dict()
45     display = None
46
47     if request.method == 'POST':
48         req_items = request.POST
49     elif request.method == 'GET':
50         req_items = request.GET
51
52     logger.debug("dispatch got = %s" % req_items.dict())
53     #t = dict(req_items.iterlists())
54     #rspec = req_items.getlist('rspec')
55     #logger.debug("dispatch got = %s" % t)
56
57     platforms = req_items.getlist('platform[]')
58     for k in req_items.dict():
59         logger.debug("key = %s - value = %s" % (k,req_items.get(k)))
60         if k == 'rspec':
61             rspec = req_items.get(k)
62         if k == 'options':
63             options = req_items.get(k)
64         if k == 'output_format':
65             output_format = req_items.get(k)
66         if k == 'hrn':
67             hrn = req_items.get(k)
68         if k == 'urn':
69             urn = req_items.get(k)
70         if k == 'type':
71             object_type = req_items.get(k)
72         if k == 'recursive':
73             if v == '1':
74                 recursive = True
75             else:
76                 recursive = False
77         if k == 'display':
78             display = req_items.get(k)
79
80     if rspec is not None:
81         try:
82             rspec = json.loads(rspec)
83         except Exception,e:
84             logger.debug("rspec type = %s" % type(rspec))
85         if type(rspec) is dict:
86             rspec = xmltodict.unparse(rspec)
87
88     start_time = time.time()
89     results = sfa_client(request, method, hrn=hrn, urn=urn, object_type=object_type, rspec=rspec, recursive=recursive, options=options, platforms=platforms, output_format=output_format, admin=False)
90     logger.debug("EXEC TIME - sfa_client() - %s sec." % (time.time() - start_time))
91     if display == 'table':
92         return render_to_response('table-default.html', {'data' : data, 'fields' : columns, 'id' : '@component_id', 'options' : None})
93     else:
94         return HttpResponse(json.dumps(results, cls=MyEncoder), content_type="application/json")
95
96 def get_user_account(request, user_email, platform_name):
97     """
98     Returns the user configuration for a given platform.
99     This function does not resolve references.
100     """
101     user_query  = Query().get('local:user').filter_by('email', '==', user_email).select('user_id')
102     user_details = execute_admin_query(request, user_query)
103     platform_query  = Query().get('local:platform').filter_by('platform', '==', platform_name).select('platform_id')
104     platform_details = execute_admin_query(request, platform_query)
105
106     account_query  = Query().get('local:account').filter_by('platform_id','==',platform_details[0]['platform_id']).filter_by('user_id', '==', user_details[0]['user_id']).select('user_id','platform_id','auth_type','config')
107     accounts = execute_admin_query(request, account_query)
108
109     if not accounts:
110         raise Exception, "this account does not exist"
111
112     if accounts[0]['auth_type'] == 'reference':
113         pf = json.loads(accounts[0]['config'])['reference_platform']
114         return get_user_account(request, user_email, pf)
115
116     return accounts[0]
117
118 #@lru_cache(100)
119 def sfa_client(request, method, hrn=None, urn=None, object_type=None, rspec=None, recursive=False, options=None, platforms=None, output_format=None, admin=False):
120
121     Config = ConfigParser.ConfigParser()
122     monitor_file = os.path.abspath(os.path.dirname(__file__) + '/../myslice/monitor.ini')
123     Config.read(monitor_file)
124
125     if admin:
126         user_email, admin_password = config.manifold_admin_user_password()
127     else:
128         #logger.debug(request.session['user']['email'])
129         user_email = request.session['user']['email']
130
131     results = dict()
132
133     if hrn is None:
134         hrn = ''
135     if urn is None:
136         urn = ''
137     if object_type is None:
138         object_type = ''
139     if rspec is None:
140         rspec = ''
141     else:
142         logger.debug("RSPEC = %s" % rspec)
143     if recursive is None:
144         recursive = False
145     if options is None:
146         options  = dict()
147     if platforms is None:
148         platforms = list()
149
150     if method not in ['GetVersion','ListResources']:
151         try:
152             if not hrn:
153                 hrn = urn_to_hrn(urn)
154             else:
155                 urn = hrn_to_urn(hrn, object_type) 
156         except Exception,e:
157             logger.error(e)
158             raise Exception, "Provide urn OR hrn + type as parameters of method %s" % method
159
160     if len(platforms)==0:
161         platforms = get_platforms(request)
162         #platforms.append('myslice')
163     #results = {'method':method,'platforms':platforms,'rspec':rspec,'options':options}
164
165     result = []
166     dict_result = {}
167     data = []
168     columns = []
169     api_options = {}
170     api_options['list_leases'] = 'all'
171     server_am = False
172     for pf in platforms:
173         platform = get_platform_config(request, pf)
174         if 'rspec_type' in platform and 'rspec_version' in platform:
175             api_options['geni_rspec_version'] = {'type': platform['rspec_type'],'version': platform['rspec_version']}
176         else:
177             api_options['geni_rspec_version'] = {'type': 'GENI', 'version': '3'}
178         if 'sm' in platform and len(platform['sm']) > 0:
179             server_am = True
180             server_url = platform['sm']
181         if 'rm' in platform and len(platform['rm']) > 0:
182             server_am = False
183             server_url = platform['rm']
184         if 'registry' in platform and len(platform['registry']) > 0:
185             server_am = False
186             server_url = platform['registry']
187     
188         if not Config.has_option('monitor', 'cert') :
189              #return HttpResponse(json.dumps({'error' : '-1'}), content_type="application/json")
190              return {'error' : '-1', 'msg': 'monitor.ini has no cert configured'}
191
192         cert = os.path.abspath(Config.get('monitor', 'cert'))
193         if not os.path.isfile(cert) :
194              #return HttpResponse(json.dumps({'error' : '-1'}), content_type="application/json")
195              return {'error' : '-1', 'msg': 'check cert file at %s'%cert}
196
197         if not Config.has_option('monitor', 'pkey') :
198              #return HttpResponse(json.dumps({'error' : '-2'}), content_type="application/json")
199              return {'error' : '-2'}
200
201         pkey = os.path.abspath(Config.get('monitor', 'pkey'))
202         if not os.path.isfile(pkey) :
203              #return HttpResponse(json.dumps({'error' : '-2'}), content_type="application/json")
204              return {'error' : '-2'}
205  
206         server = SfaServerProxy(server_url, pkey, cert, verbose=False)#, timeout=5)
207         #server = SFAProxy(server_url, pkey, cert)
208         #if 'geni_rspec_version' in api_options:
209         #    # GetVersion to know if the AM supports the requested version
210         #    # if not ask for the default GENI v3
211         #    start_time = time.time()
212         #    result = server.GetVersion()
213         #    logger.debug("EXEC TIME - GetVersion() - %s sec." % (time.time() - start_time))
214         #    if 'geni_ad_rspec_versions' in result['value']:
215         #        for v in result['value']['geni_ad_rspec_versions']:
216         #            if v['type'] == api_options['geni_rspec_version']:
217         #                api_options['geni_rspec_version'] = {'type': api_options['geni_rspec_version']}
218         #                break
219         #            else:
220         #                api_options['geni_rspec_version'] = {'type': 'GENI', 'version': '3'}
221         #else:
222         #    api_options['geni_rspec_version'] = {'type': 'GENI', 'version': '3'}
223
224         try:
225             # Get user config from Manifold
226             user_config = get_user_config(request, user_email, pf)
227             if 'delegated_user_credential' in user_config:
228                 logger.debug('delegated_user_credential')
229                 user_cred = user_config['delegated_user_credential']
230             elif 'user_credential' in user_config:
231                 logger.debug('user_credential')
232                 user_cred = user_config['user_credential']
233             else:
234                 logger.error("no user credentials for user = ", user_email)
235                 user_cred = {}
236
237             if object_type:
238                 if 'delegated_%s_credentials'%object_type in user_config:
239                     logger.debug('delegated_%s_credentials'%object_type)
240                     for obj_name, cred in user_config['delegated_%s_credentials'%object_type].items():
241                         if obj_name == hrn:
242                             object_cred = cred
243                 elif '%s_credentials'%object_type in user_config:
244                     logger.debug('%s_credentials'%object_type)
245                     for obj_name, cred in user_config['%s_credentials'%object_type].items():
246                         if obj_name == hrn:
247                             object_cred = cred
248                 else:
249                     logger.error("no credentials for object")
250                     logger.error(object_type)
251                     logger.error(object_name)
252                     object_cred = {}
253
254             # Both AM & Registry
255             if method == "GetVersion": 
256                 start_time = time.time()
257                 result = server.GetVersion()
258                 logger.debug("EXEC TIME - GetVersion() - %s sec." % (time.time() - start_time))
259             else:
260                 # AM API Calls
261                 if server_am:
262                     if method == "ListResources":
263                         start_time = time.time()
264                         result = server.ListResources([user_cred], api_options)
265                         logger.debug("EXEC TIME - ListResources() - %s sec." % (time.time() - start_time))
266                         dict_result = xmltodict.parse(result['value'])
267                         result['parsed'] = dict_result
268                         if isinstance(dict_result['rspec']['node'], list):
269                             columns.extend(dict_result['rspec']['node'][0].keys())
270                         else:
271                             columns.extend(dict_result['rspec']['node'].keys())
272
273                     elif method == "Describe":
274                         start_time = time.time()
275                         version = server.GetVersion()
276                         logger.debug("EXEC TIME - GetVersion() - %s sec." % (time.time() - start_time))
277                         logger.debug(version['geni_api'])
278                         # if GetVersion = v2
279                         if version['geni_api'] == 2:
280                             # ListResources(slice_hrn)
281                             api_options['geni_slice_urn'] = urn
282                             result = server.ListResources([object_cred], api_options)
283                             logger.debug(result)
284                             dict_result = xmltodict.parse(result['value'])
285                         # else GetVersion = v3
286                         else:
287                             result = server.Describe([urn] ,[object_cred], api_options)
288                             if isinstance(result, dict):
289                                 if result['value'] != 0:
290                                     dict_result = xmltodict.parse(result['value']['geni_rspec'])
291
292                         result['parsed'] = dict_result
293                         if 'rspec' in dict_result and 'node' in dict_result['rspec']:
294                             if isinstance(dict_result['rspec']['node'], list):
295                                 columns.extend(dict_result['rspec']['node'][0].keys())
296                             else:
297                                 columns.extend(dict_result['rspec']['node'].keys())
298
299                     elif method == 'Renew':
300                         # Renew till 1 month from now
301                         d = datetime.datetime.utcnow() + datetime.timedelta(365/12)
302                         date = d.isoformat("T") + "Z"
303                         result = server.Renew([urn] ,[object_cred], date, api_options)
304                     elif method == 'Delete':
305                         result = server.Delete([urn] ,[object_cred], api_options)
306                     elif method == 'Allocate':
307                         api_options['call_id']    = unique_call_id()
308                         # List of users comes from the Registry
309                         users = get_users_in_slice(request, hrn)
310                         api_options['sfa_users']  = users
311                         api_options['geni_users'] = users
312                         # if GetVersion = v2
313                         version = server.GetVersion()
314                         if version['geni_api'] == 2:
315                             result = server.CreateSliver([urn] ,[object_cred], rspec, api_options)
316                         # else GetVersion = v3
317                         else:
318                             result = server.Allocate(urn ,[object_cred], rspec, api_options)
319                     elif method == 'Provision':
320                         # if GetVersion = v2
321                         # Nothing it is not supported by v2 AMs
322                         version = server.GetVersion()
323                         # List of users comes from the Registry
324                         users = get_users_in_slice(request, hrn)
325                         api_options['sfa_users']  = users
326                         api_options['geni_users'] = users
327                         if version['geni_api'] == 3:
328                             api_options['call_id']    = unique_call_id()
329                             result = server.Provision([urn] ,[object_cred], api_options)
330                     elif method == 'Status':
331                         result = server.Status([urn] ,[object_cred], api_options)
332                     elif method == 'PerformOperationalAction':
333                         # if GetVersion = v2
334                         # Nothing it is not supported by v2 AMs
335                         version = server.GetVersion()
336                         if version['geni_api'] == 3:
337                             result = server.PerformOperationalAction([urn] ,[object_cred], action, api_options)
338                     elif method == 'Shutdown':
339                         result = server.Shutdown(urn ,[object_cred], api_options)
340                     else:
341                         #return HttpResponse(json.dumps({'error' : '-3','msg':'method not supported by AM'}), content_type="application/json")
342                         logger.debug('method %s not handled by AM' % method)
343                         result = []
344
345                 # Registry API Calls 
346                 else:
347                     record_dict = {'urn': urn, 'hrn': hrn, 'type': object_type}
348                     if method == "List":
349                         # hrn is required
350                         api_options['recursive'] = recursive
351                         result = server.List(hrn, user_cred, api_options)
352                         if object_type:
353                             result = filter_records(object_type, result)
354                     elif method == "Resolve":
355                         # hrn is required
356                         # details can be True or False
357                         api_options['details']=True
358                         result = server.Resolve(hrn, user_cred, api_options)
359                         if object_type:
360                             result = filter_records(object_type, result)
361                     elif method == "Register":
362                         # record_dict must be crafted
363                         # auth_cred must be selected in the list of auth_creds from user's account
364                         result = server.Register(record_dict, auth_cred)
365                     elif method == "Update":
366                         # record_dict must be crafted
367                         # object_cred must be selected in the list of creds for the object type
368                         # from user's account
369                         result = server.Update(record_dict, object_cred)
370                     elif method == "Remove":
371                         # hrn is required
372                         # auth_cred must be selected in the list of auth_creds from user's account
373                         # object_type is required
374                         result = server.Remove(hrn, auth_cred, object_type)
375                     else:
376                         #return HttpResponse(json.dumps({'error' : '-3','msg':'method not supported by Registry'}), content_type="application/json")
377                         logger.debug('method %s not handled by Registry' % method)
378                         result = []
379             if output_format is not None:
380                 if 'value' in result:
381                     # TODO Python Caching 
382                     # to avoid translating the same RSpec in the same format several times
383                     start_time = time.time()
384                     result = translate(result['value'],output_format)
385                     logger.debug("EXEC TIME - translate() - %s sec." % (time.time() - start_time))
386
387             results[pf] = result
388             if dict_result:
389                 if 'rspec' in dict_result and 'node' in dict_result['rspec']:
390                     if isinstance(dict_result['rspec']['node'], list):
391                         data = data + dict_result['rspec']['node']
392                     else:
393                         data.append(dict_result['rspec']['node'])
394         except Exception,e:
395             import traceback
396             logger.error(traceback.format_exc())
397             logger.error(e)
398             results[pf] = {'error':'-3', 'result':result,'error_msg': str(e)}
399
400     results['columns'] = columns
401     return results
402
403 @lru_cache(100)
404 def translate(rspec, output_format):
405     import urllib
406     import urllib2
407
408     values = {'content' : rspec}
409     url = 'https://demo.fiteagle.org/omnweb/convert/to/' + output_format
410     data = urllib.urlencode(values)
411     req = urllib2.Request(url, data)
412     response = urllib2.urlopen(req)
413     return response.read()
414
415 def rename(self,key,new_key):
416     ind = self._keys.index(key)  #get the index of old key, O(N) operation
417     self._keys[ind] = new_key    #replace old key with new key in self._keys
418     self[new_key] = self[key]    #add the new key, this is added at the end of self._keys
419     self._keys.pop(-1)           #pop the last item in self._keys
420
421 def get_users_in_slice(request, slice_hrn):
422     # select users.user_hrn, users.user_email, users.keys  
423     # from myslice:slice 
424     # where slice_hrn=='onelab.upmc.r2d2.slice1'
425     users_query  = Query().get('myslice:slice').filter_by('slice_hrn', '==', slice_hrn).select('users.user_hrn', 'users.user_urn', 'users.user_email','users.keys')
426     users = execute_admin_query(request, users_query)
427     rmap = {'user_urn':'urn','user_email':'email','user_hrn':'hrn'}
428     res = list()
429     for u in users[0]['users']:
430         r_user = dict()
431         for k,v in u.items():
432             if k in rmap.keys():
433                 r_user[rmap[k]] = v
434             else:
435                 r_user[k]=v
436         res.append(r_user)
437     return res
438
439 def get_user_config(request, user_email, platform_name):
440     account = get_user_account(request, user_email, platform_name)
441     return json.loads(account['config']) if account['config'] else {}
442
443 def get_platforms(request):
444     ret = list()
445     platform_query  = Query().get('local:platform').filter_by('gateway_type', '==', 'sfa').filter_by('disabled','==',0).select('platform')
446     platforms = execute_admin_query(request, platform_query)
447
448     for p in platforms:
449         ret.append(p['platform'])
450     return ret
451
452 def get_platform_config(request, platform_name):
453     platform_query  = Query().get('local:platform').filter_by('platform', '==', platform_name).select('platform', 'config')
454     platforms = execute_admin_query(request, platform_query)
455
456     return json.loads(platforms[0]['config']) if platforms[0]['config'] else {}
457
458 def filter_records(type, records):
459     filtered_records = []
460     for record in records:
461         if (record['type'] == type) or (type == "all"):
462             filtered_records.append(record)
463     return filtered_records