diff options
author | Frederick Muriuki Muriithi | 2022-12-28 14:39:29 +0300 |
---|---|---|
committer | Frederick Muriuki Muriithi | 2022-12-28 14:42:30 +0300 |
commit | 278d8db432378655b76f0ee4cbbc776d50928fdb (patch) | |
tree | 1726a53b5ea01942cdfea9e3382ce74397f7bdd9 /gn3/auth/authentication/oauth2/resource_server.py | |
parent | 4081d30cf8a41f876f8fab0c7a03d359bc438f94 (diff) | |
download | genenetwork3-278d8db432378655b76f0ee4cbbc776d50928fdb.tar.gz |
auth: Add resource server and /user endpoint
Add a resource server with the validator for the bearer token to protect the
resources endpoints.
Add a protected `/user` endpoint that returns the user details for valid
tokens.
* gn3/auth/authentication/oauth2/resource_server.py: new file
* gn3/auth/authentication/oauth2/views.py: add /user endpoint
Diffstat (limited to 'gn3/auth/authentication/oauth2/resource_server.py')
-rw-r--r-- | gn3/auth/authentication/oauth2/resource_server.py | 19 |
1 files changed, 19 insertions, 0 deletions
diff --git a/gn3/auth/authentication/oauth2/resource_server.py b/gn3/auth/authentication/oauth2/resource_server.py new file mode 100644 index 0000000..885cbd8 --- /dev/null +++ b/gn3/auth/authentication/oauth2/resource_server.py @@ -0,0 +1,19 @@ +"""Protect the resources endpoints""" + +from flask import current_app as app +from authlib.oauth2.rfc6750 import BearerTokenValidator as _BearerTokenValidator +from authlib.integrations.flask_oauth2 import ResourceProtector, current_token + +from gn3.auth import db +from gn3.auth.authentication.oauth2.models.oauth2token import token_by_access_token + +class BearerTokenValidator(_BearerTokenValidator): + """Extends `authlib.oauth2.rfc6750.BearerTokenValidator`""" + def authenticate_token(self, token_string: str): + with db.connection(app.config["AUTH_DB"]) as conn: + return token_by_access_token(conn, token_string).maybe( + None, lambda tok: tok) + +require_oauth = ResourceProtector() + +require_oauth.register_token_validator(BearerTokenValidator()) |