aboutsummaryrefslogtreecommitdiff
path: root/gn3/auth/authentication/oauth2/resource_server.py
diff options
context:
space:
mode:
authorFrederick Muriuki Muriithi2022-12-28 14:39:29 +0300
committerFrederick Muriuki Muriithi2022-12-28 14:42:30 +0300
commit278d8db432378655b76f0ee4cbbc776d50928fdb (patch)
tree1726a53b5ea01942cdfea9e3382ce74397f7bdd9 /gn3/auth/authentication/oauth2/resource_server.py
parent4081d30cf8a41f876f8fab0c7a03d359bc438f94 (diff)
downloadgenenetwork3-278d8db432378655b76f0ee4cbbc776d50928fdb.tar.gz
auth: Add resource server and /user endpoint
Add a resource server with the validator for the bearer token to protect the resources endpoints. Add a protected `/user` endpoint that returns the user details for valid tokens. * gn3/auth/authentication/oauth2/resource_server.py: new file * gn3/auth/authentication/oauth2/views.py: add /user endpoint
Diffstat (limited to 'gn3/auth/authentication/oauth2/resource_server.py')
-rw-r--r--gn3/auth/authentication/oauth2/resource_server.py19
1 files changed, 19 insertions, 0 deletions
diff --git a/gn3/auth/authentication/oauth2/resource_server.py b/gn3/auth/authentication/oauth2/resource_server.py
new file mode 100644
index 0000000..885cbd8
--- /dev/null
+++ b/gn3/auth/authentication/oauth2/resource_server.py
@@ -0,0 +1,19 @@
+"""Protect the resources endpoints"""
+
+from flask import current_app as app
+from authlib.oauth2.rfc6750 import BearerTokenValidator as _BearerTokenValidator
+from authlib.integrations.flask_oauth2 import ResourceProtector, current_token
+
+from gn3.auth import db
+from gn3.auth.authentication.oauth2.models.oauth2token import token_by_access_token
+
+class BearerTokenValidator(_BearerTokenValidator):
+ """Extends `authlib.oauth2.rfc6750.BearerTokenValidator`"""
+ def authenticate_token(self, token_string: str):
+ with db.connection(app.config["AUTH_DB"]) as conn:
+ return token_by_access_token(conn, token_string).maybe(
+ None, lambda tok: tok)
+
+require_oauth = ResourceProtector()
+
+require_oauth.register_token_validator(BearerTokenValidator())