added request_hash argument. authenticate the credential using request_hash
[sfa.git] / sfa / methods / list.py
1 ### $Id$
2 ### $URL$
3
4 from sfa.util.faults import *
5 from sfa.util.method import Method
6 from sfa.util.parameter import Parameter, Mixed
7 from sfa.trust.auth import Auth
8 from sfa.util.record import GeniRecord
9 from sfa.util.genitable import GeniTable
10 from sfa.server.registry import Registries
11 from sfa.util.prefixTree import prefixTree
12 from sfa.trust.credential import Credential
13
14 class list(Method):
15     """
16     List the records in an authority. 
17
18     @param cred credential string specifying the rights of the caller
19     @param hrn human readable name of authority to list
20     @return list of record dictionaries         
21     """
22     interfaces = ['registry']
23     
24     accepts = [
25         Parameter(str, "Credential string"),
26         Parameter(str, "Human readable name (hrn)"),
27         Parameter(str, "Request hash")
28         ]
29
30     returns = [GeniRecord]
31     
32     def call(self, cred, hrn, request_hash, caller_cred=None):
33         self.api.auth.authenticateCred(cred, [cred, hrn], request_hash)
34         self.api.auth.check(cred, 'list')
35         if caller_cred==None:
36             caller_cred=cred
37
38         #log the call
39         self.api.logger.info("interface: %s\tcaller-hrn: %s\ttarget-hrn: %s\tmethod-name: %s"%(self.api.interface, Credential(string=caller_cred).get_gid_caller().get_hrn(), hrn, self.name))
40         records = []
41
42         # load all know registry names into a prefix tree and attempt to find
43         # the longest matching prefix  
44         registries = Registries(self.api)
45         hrns = registries.keys()
46         tree = prefixTree()
47         tree.load(hrns)
48         registry_hrn = tree.best_match(hrn)
49
50         #if there was no match then this record belongs to an unknow registry
51         if not registry_hrn:
52             raise MissingAuthority(hrn)
53         
54         # if the best match (longest matching hrn) is not the local registry,
55         # forward the request
56         if registry_hrn != self.api.hrn:
57             credential = self.api.getCredential()
58             try:
59                 record_list = registries[registry_hrn].list(credential, hrn, caller_cred=caller_cred)
60                 records = [record.as_dict() for record in record_list]
61                 if records:
62                     return records
63             except:
64                 pass
65
66         # if we still havnt found the record yet, try the local registry
67         if not self.api.auth.hierarchy.auth_exists(hrn):
68             raise MissingAuthority(hrn)
69         
70         table = GeniTable()
71         records = table.find({'authority': hrn})
72         
73         return records