Merge branch 'onelab' of ssh://git.onelab.eu/git/myslice into onelab
[myslice.git] / rest / sfa_api.py
1 import os
2 import json
3 import ConfigParser 
4 import datetime
5 from time                           import mktime
6 import time
7 import xmltodict
8
9 from django.shortcuts               import render_to_response
10 from django.http                    import HttpResponse,QueryDict
11
12 from sfa.trust.certificate          import Keypair, Certificate
13 from sfa.client.sfaserverproxy      import SfaServerProxy
14 from manifold.gateways.sfa.proxy    import SFAProxy
15 from sfa.client.return_value        import ReturnValue
16 from sfa.util.xrn                   import Xrn, get_leaf, get_authority, hrn_to_urn, urn_to_hrn
17
18 from manifold.core.query            import Query
19
20 from manifoldapi.manifoldapi        import execute_admin_query
21
22 from unfold.loginrequired           import LoginRequiredView
23
24 from myslice.settings               import logger, config
25
26 from repoze.lru                     import lru_cache
27 from rest.json_encoder              import MyEncoder
28
29 import uuid
30 def unique_call_id(): return uuid.uuid4().urn
31
32 def dispatch(request, method):
33
34     hrn = None
35     urn = None
36     object_type = None
37     rspec = None
38     output_format = None
39     recursive = False
40     # Have to be hashable for lru_cache
41     options   = frozenset() # dict()
42     platforms = frozenset() # list()
43
44     results = dict()
45     display = None
46
47     if request.method == 'POST':
48         req_items = request.POST
49     elif request.method == 'GET':
50         req_items = request.GET
51
52     logger.debug("dispatch got = %s" % req_items.dict())
53     #t = dict(req_items.iterlists())
54     #rspec = req_items.getlist('rspec')
55     #logger.debug("dispatch got = %s" % t)
56
57     platforms = req_items.getlist('platform[]')
58     for k in req_items.dict():
59         logger.debug("key = %s - value = %s" % (k,req_items.get(k)))
60         if k == 'rspec':
61             rspec = req_items.get(k)
62         if k == 'options':
63             options = req_items.get(k)
64         if k == 'output_format':
65             output_format = req_items.get(k)
66         if k == 'hrn':
67             hrn = req_items.get(k)
68         if k == 'urn':
69             urn = req_items.get(k)
70         if k == 'type':
71             object_type = req_items.get(k)
72         if k == 'recursive':
73             if v == '1':
74                 recursive = True
75             else:
76                 recursive = False
77         if k == 'display':
78             display = req_items.get(k)
79
80     if rspec is not None:
81         try:
82             rspec = json.loads(rspec)
83         except Exception,e:
84             logger.debug("rspec type = %s" % type(rspec))
85         if type(rspec) is dict:
86             rspec = xmltodict.unparse(rspec)
87
88     start_time = time.time()
89     results = sfa_client(request, method, hrn=hrn, urn=urn, object_type=object_type, rspec=rspec, recursive=recursive, options=options, platforms=platforms, output_format=output_format, admin=False)
90     logger.debug("EXEC TIME - sfa_client() - %s sec." % (time.time() - start_time))
91     if display == 'table':
92         return render_to_response('table-default.html', {'data' : data, 'fields' : columns, 'id' : '@component_id', 'options' : None})
93     else:
94         return HttpResponse(json.dumps(results, cls=MyEncoder), content_type="application/json")
95
96 def get_user_account(request, user_email, platform_name):
97     """
98     Returns the user configuration for a given platform.
99     This function does not resolve references.
100     """
101     user_query  = Query().get('local:user').filter_by('email', '==', user_email).select('user_id')
102     user_details = execute_admin_query(request, user_query)
103     platform_query  = Query().get('local:platform').filter_by('platform', '==', platform_name).select('platform_id')
104     platform_details = execute_admin_query(request, platform_query)
105
106     account_query  = Query().get('local:account').filter_by('platform_id','==',platform_details[0]['platform_id']).filter_by('user_id', '==', user_details[0]['user_id']).select('user_id','platform_id','auth_type','config')
107     accounts = execute_admin_query(request, account_query)
108
109     if not accounts:
110         raise Exception, "this account does not exist"
111
112     if accounts[0]['auth_type'] == 'reference':
113         pf = json.loads(accounts[0]['config'])['reference_platform']
114         return get_user_account(request, user_email, pf)
115
116     return accounts[0]
117
118 #@lru_cache(100)
119 def sfa_client(request, method, hrn=None, urn=None, object_type=None, rspec=None, recursive=False, options=None, platforms=None, output_format=None, admin=False):
120
121     Config = ConfigParser.ConfigParser()
122     monitor_file = os.path.abspath(os.path.dirname(__file__) + '/../myslice/monitor.ini')
123     Config.read(monitor_file)
124
125     if admin:
126         user_email, admin_password = config.manifold_admin_user_password()
127     else:
128         #logger.debug(request.session['user']['email'])
129         user_email = request.session['user']['email']
130
131     results = dict()
132
133     if hrn is None:
134         hrn = ''
135     if urn is None:
136         urn = ''
137     if object_type is None:
138         object_type = ''
139     if rspec is None:
140         rspec = ''
141     else:
142         logger.debug("RSPEC = %s" % rspec)
143     if recursive is None:
144         recursive = False
145     if options is None:
146         options  = dict()
147     if platforms is None:
148         platforms = list()
149
150     if method not in ['GetVersion','ListResources']:
151         try:
152             if not hrn:
153                 hrn = urn_to_hrn(urn)
154             else:
155                 urn = hrn_to_urn(hrn, object_type) 
156         except Exception,e:
157             logger.error(e)
158             raise Exception, "Provide urn OR hrn + type as parameters of method %s" % method
159
160     if len(platforms)==0:
161         platforms = get_platforms(request)
162         #platforms.append('myslice')
163     #results = {'method':method,'platforms':platforms,'rspec':rspec,'options':options}
164
165     result = []
166     dict_result = {}
167     data = []
168     columns = []
169     api_options = {}
170     api_options['list_leases'] = 'all'
171     server_am = False
172     for pf in platforms:
173         platform = get_platform_config(request, pf)
174         if 'rspec_type' in platform and 'rspec_version' in platform:
175             api_options['geni_rspec_version'] = {'type': platform['rspec_type'],'version': platform['rspec_version']}
176         else:
177             api_options['geni_rspec_version'] = {'type': 'GENI', 'version': '3'}
178         if 'sm' in platform and len(platform['sm']) > 0:
179             server_am = True
180             server_url = platform['sm']
181         if 'rm' in platform and len(platform['rm']) > 0:
182             server_am = False
183             server_url = platform['rm']
184         if 'registry' in platform and len(platform['registry']) > 0:
185             server_am = False
186             server_url = platform['registry']
187     
188         if not Config.has_option('monitor', 'cert') :
189              #return HttpResponse(json.dumps({'error' : '-1'}), content_type="application/json")
190              return {'error' : '-1', 'msg': 'monitor.ini has no cert configured'}
191
192         cert = os.path.abspath(Config.get('monitor', 'cert'))
193         if not os.path.isfile(cert) :
194              #return HttpResponse(json.dumps({'error' : '-1'}), content_type="application/json")
195              return {'error' : '-1', 'msg': 'check cert file at %s'%cert}
196
197         if not Config.has_option('monitor', 'pkey') :
198              #return HttpResponse(json.dumps({'error' : '-2'}), content_type="application/json")
199              return {'error' : '-2'}
200
201         pkey = os.path.abspath(Config.get('monitor', 'pkey'))
202         if not os.path.isfile(pkey) :
203              #return HttpResponse(json.dumps({'error' : '-2'}), content_type="application/json")
204              return {'error' : '-2'}
205  
206         server = SfaServerProxy(server_url, pkey, cert)
207         #server = SFAProxy(server_url, pkey, cert)
208         if 'geni_rspec_version' in options:
209             # GetVersion to know if the AM supports the requested version
210             # if not ask for the default GENI v3
211             start_time = time.time()
212             result = server.GetVersion()
213             logger.debug("EXEC TIME - GetVersion() - %s sec." % (time.time() - start_time))
214             if 'geni_ad_rspec_versions' in result['value']:
215                 for v in result['value']['geni_ad_rspec_versions']:
216                     if v['type'] == options['geni_rspec_version']:
217                         api_options['geni_rspec_version'] = {'type': options['geni_rspec_version']}
218                         break
219                     else:
220                         api_options['geni_rspec_version'] = {'type': 'GENI', 'version': '3'}
221         else:
222             api_options['geni_rspec_version'] = {'type': 'GENI', 'version': '3'}
223
224         try:
225             # Get user config from Manifold
226             user_config = get_user_config(request, user_email, pf)
227             if 'delegated_user_credential' in user_config:
228                 logger.debug('delegated_user_credential')
229                 user_cred = user_config['delegated_user_credential']
230             elif 'user_credential' in user_config:
231                 logger.debug('user_credential')
232                 user_cred = user_config['user_credential']
233             else:
234                 logger.error("no user credentials for user = ", user_email)
235                 user_cred = {}
236
237             if object_type:
238                 if 'delegated_%s_credentials'%object_type in user_config:
239                     logger.debug('delegated_%s_credentials'%object_type)
240                     for obj_name, cred in user_config['delegated_%s_credentials'%object_type].items():
241                         if obj_name == hrn:
242                             object_cred = cred
243                 elif '%s_credentials'%object_type in user_config:
244                     logger.debug('%s_credentials'%object_type)
245                     for obj_name, cred in user_config['%s_credentials'%object_type].items():
246                         if obj_name == hrn:
247                             object_cred = cred
248                 else:
249                     logger.error("no credentials for object")
250                     logger.error(object_type)
251                     logger.error(object_name)
252                     object_cred = {}
253
254             # Both AM & Registry
255             if method == "GetVersion": 
256                 start_time = time.time()
257                 result = server.GetVersion()
258                 logger.debug("EXEC TIME - GetVersion() - %s sec." % (time.time() - start_time))
259             else:
260                 # AM API Calls
261                 if server_am:
262                     if method == "ListResources":
263                         logger.debug(api_options)
264                         #logger.debug(user_cred)
265                         start_time = time.time()
266                         result = server.ListResources([user_cred], api_options)
267                         logger.debug("EXEC TIME - ListResources() - %s sec." % (time.time() - start_time))
268                         #logger.debug(result)
269                         dict_result = xmltodict.parse(result['value'])
270                         result['parsed'] = dict_result
271                         if isinstance(dict_result['rspec']['node'], list):
272                             columns.extend(dict_result['rspec']['node'][0].keys())
273                         else:
274                             columns.extend(dict_result['rspec']['node'].keys())
275
276                     elif method == "Describe":
277                         start_time = time.time()
278                         version = server.GetVersion()
279                         logger.debug("EXEC TIME - GetVersion() - %s sec." % (time.time() - start_time))
280                         logger.debug(version['geni_api'])
281                         # if GetVersion = v2
282                         if version['geni_api'] == 2:
283                             # ListResources(slice_hrn)
284                             api_options['geni_slice_urn'] = urn
285                             result = server.ListResources([object_cred], api_options)
286                             dict_result = xmltodict.parse(result['value'])
287                         # else GetVersion = v3
288                         else:
289                             result = server.Describe([urn] ,[object_cred], api_options)
290                             if isinstance(result, dict):
291                                 if result['value'] != 0:
292                                     dict_result = xmltodict.parse(result['value']['geni_rspec'])
293
294                         result['parsed'] = dict_result
295                         if 'rspec' in dict_result and 'node' in dict_result['rspec']:
296                             if isinstance(dict_result['rspec']['node'], list):
297                                 columns.extend(dict_result['rspec']['node'][0].keys())
298                             else:
299                                 columns.extend(dict_result['rspec']['node'].keys())
300
301                     elif method == 'Renew':
302                         # Renew till 1 month from now
303                         d = datetime.datetime.utcnow() + datetime.timedelta(365/12)
304                         date = d.isoformat("T") + "Z"
305                         result = server.Renew([urn] ,[object_cred], date, api_options)
306                     elif method == 'Delete':
307                         result = server.Delete([urn] ,[object_cred], api_options)
308                     elif method == 'Allocate':
309                         api_options['call_id']    = unique_call_id()
310                         # List of users comes from the Registry
311                         users = get_users_in_slice(request, hrn)
312                         api_options['sfa_users']  = users
313                         api_options['geni_users'] = users
314                         # if GetVersion = v2
315                         version = server.GetVersion()
316                         if version['geni_api'] == 2:
317                             result = server.CreateSliver([urn] ,[object_cred], rspec, api_options)
318                         # else GetVersion = v3
319                         else:
320                             result = server.Allocate(urn ,[object_cred], rspec, api_options)
321                     elif method == 'Provision':
322                         # if GetVersion = v2
323                         # Nothing it is not supported by v2 AMs
324                         version = server.GetVersion()
325                         # List of users comes from the Registry
326                         users = get_users_in_slice(request, hrn)
327                         api_options['sfa_users']  = users
328                         api_options['geni_users'] = users
329                         if version['geni_api'] == 3:
330                             api_options['call_id']    = unique_call_id()
331                             result = server.Provision([urn] ,[object_cred], api_options)
332                     elif method == 'Status':
333                         result = server.Status([urn] ,[object_cred], api_options)
334                     elif method == 'PerformOperationalAction':
335                         # if GetVersion = v2
336                         # Nothing it is not supported by v2 AMs
337                         version = server.GetVersion()
338                         if version['geni_api'] == 3:
339                             result = server.PerformOperationalAction([urn] ,[object_cred], action, api_options)
340                     elif method == 'Shutdown':
341                         result = server.Shutdown(urn ,[object_cred], api_options)
342                     else:
343                         #return HttpResponse(json.dumps({'error' : '-3','msg':'method not supported by AM'}), content_type="application/json")
344                         logger.debug('method %s not handled by AM' % method)
345                         result = []
346
347                 # Registry API Calls 
348                 else:
349                     record_dict = {'urn': urn, 'hrn': hrn, 'type': object_type}
350                     if method == "List":
351                         # hrn is required
352                         api_options['recursive'] = recursive
353                         result = server.List(hrn, user_cred, api_options)
354                         if object_type:
355                             result = filter_records(object_type, result)
356                     elif method == "Resolve":
357                         # hrn is required
358                         # details can be True or False
359                         api_options['details']=True
360                         result = server.Resolve(hrn, user_cred, api_options)
361                         if object_type:
362                             result = filter_records(object_type, result)
363                     elif method == "Register":
364                         # record_dict must be crafted
365                         # auth_cred must be selected in the list of auth_creds from user's account
366                         result = server.Register(record_dict, auth_cred)
367                     elif method == "Update":
368                         # record_dict must be crafted
369                         # object_cred must be selected in the list of creds for the object type
370                         # from user's account
371                         result = server.Update(record_dict, object_cred)
372                     elif method == "Remove":
373                         # hrn is required
374                         # auth_cred must be selected in the list of auth_creds from user's account
375                         # object_type is required
376                         result = server.Remove(hrn, auth_cred, object_type)
377                     else:
378                         #return HttpResponse(json.dumps({'error' : '-3','msg':'method not supported by Registry'}), content_type="application/json")
379                         logger.debug('method %s not handled by Registry' % method)
380                         result = []
381             if output_format is not None:
382                 logger.debug("result = " % result)
383                 if 'value' in result:
384                     # TODO Python Caching 
385                     # to avoid translating the same RSpec in the same format several times
386                     start_time = time.time()
387                     result = translate(result['value'],output_format)
388                     logger.debug("EXEC TIME - translate() - %s sec." % (time.time() - start_time))
389
390             results[pf] = result
391             if dict_result:
392                 if 'rspec' in dict_result and 'node' in dict_result['rspec']:
393                     if isinstance(dict_result['rspec']['node'], list):
394                         data = data + dict_result['rspec']['node']
395                     else:
396                         data.append(dict_result['rspec']['node'])
397         except Exception,e:
398             import traceback
399             logger.error(traceback.format_exc())
400             logger.error(e)
401             results[pf] = {'error':'-3', 'result':result,'error_msg': str(e)}
402
403     results['columns'] = columns
404     return results
405
406 @lru_cache(100)
407 def translate(rspec, output_format):
408     import urllib
409     import urllib2
410
411     values = {'content' : rspec}
412     url = 'https://demo.fiteagle.org/omnweb/convert/to/' + output_format
413     data = urllib.urlencode(values)
414     req = urllib2.Request(url, data)
415     response = urllib2.urlopen(req)
416     return response.read()
417
418 def rename(self,key,new_key):
419     ind = self._keys.index(key)  #get the index of old key, O(N) operation
420     self._keys[ind] = new_key    #replace old key with new key in self._keys
421     self[new_key] = self[key]    #add the new key, this is added at the end of self._keys
422     self._keys.pop(-1)           #pop the last item in self._keys
423
424 def get_users_in_slice(request, slice_hrn):
425     # select users.user_hrn, users.user_email, users.keys  
426     # from myslice:slice 
427     # where slice_hrn=='onelab.upmc.r2d2.slice1'
428     users_query  = Query().get('myslice:slice').filter_by('slice_hrn', '==', slice_hrn).select('users.user_hrn', 'users.user_urn', 'users.user_email','users.keys')
429     users = execute_admin_query(request, users_query)
430     rmap = {'user_urn':'urn','user_email':'email','user_hrn':'hrn'}
431     res = list()
432     for u in users[0]['users']:
433         r_user = dict()
434         for k,v in u.items():
435             if k in rmap.keys():
436                 r_user[rmap[k]] = v
437             else:
438                 r_user[k]=v
439         res.append(r_user)
440     return res
441
442 def get_user_config(request, user_email, platform_name):
443     account = get_user_account(request, user_email, platform_name)
444     return json.loads(account['config']) if account['config'] else {}
445
446 def get_platforms(request):
447     ret = list()
448     platform_query  = Query().get('local:platform').filter_by('gateway_type', '==', 'sfa').filter_by('disabled','==',0).select('platform')
449     platforms = execute_admin_query(request, platform_query)
450
451     for p in platforms:
452         ret.append(p['platform'])
453     return ret
454
455 def get_platform_config(request, platform_name):
456     platform_query  = Query().get('local:platform').filter_by('platform', '==', platform_name).select('platform', 'config')
457     platforms = execute_admin_query(request, platform_query)
458
459     return json.loads(platforms[0]['config']) if platforms[0]['config'] else {}
460
461 def filter_records(type, records):
462     filtered_records = []
463     for record in records:
464         if (record['type'] == type) or (type == "all"):
465             filtered_records.append(record)
466     return filtered_records