""" AUTHOR: Khushal P Soonderji DATE: Saturday, 21st Dec., 2024 OBJECTIVE: To receive authorization requests for various stockbrokers like Zerodha. REFERENCES: N/A DOWNLOADS: N/A NOTES: N/A """ # ***************************************************************************************************************** # ***** **** # *** IMPORT *** # ***** **** # ***************************************************************************************************************** # To make sibling directories accessible for imports: import sys sys.path.append(".") sys.path.append("..") # For using Quart: from quart import Blueprint, current_app, request # My utils: from utils_v2.string import json from utils_v2.api.codes import StatusCodes, HttpCodes from utils_v2.api.response import ResponseModel from utils_v2.api.async_quart import ( set_api_version, read_input, get_session_info, log_request_to_mongo, log_chain_to_mongo, should_not_be_under_maintenance, only_whitelisted_ips, limit_rate, validate_input, handle_cancelled_request ) # Common: from shared import constants # Data Models: from models.core.auth_token import CoreAuthTokenModel from models.api.finstitutions.trading.auth.oauth import ( TradingAuthRequestHeaders, TradingAuthRequestData ) # For asynchronous activities: import asyncio # ***************************************************************************************************************** # ***** **** # *** MACROS / ONE-TIME INIT *** # ***** **** # ***************************************************************************************************************** # Related to Quart: trading_oauth_request_bp = Blueprint("trading_oauth", __name__) # ***************************************************************************************************************** # ***** **** # *** VARIABLES *** # ***** **** # ***************************************************************************************************************** # --- Nothing Yet # ***************************************************************************************************************** # ***** **** # *** FUNCTIONS *** # ***** **** # ***************************************************************************************************************** @trading_oauth_request_bp.record_once def init(blueprint_setup_state): # This gets called when the blueprint is registered. # Consider this to be a one-time setup for the whole blueprint: pass # --------------------------------------------------------------------------------------------------------------------- @trading_oauth_request_bp.route("", methods = ["GET", "POST"]) @set_api_version(api_version = "1.0.0") @read_input(sanitize_headers = False, sanitize_data = False) @get_session_info(key = "X-Session-Token", session_coro = "get_session") @log_request_to_mongo( attr_name = "logs_mongo", project = constants.PROJECT_NAME, log_type = constants.MODULE_NAME, operation = "tradingOAuthUrlReqApi", log_input = True, log_output = True, sensitive_keys = ["sessionToken", "X-Session-Token"] ) @log_chain_to_mongo(attr_name = "logs_mongo") @should_not_be_under_maintenance(attr_name = "is_under_maintenance") @validate_input( header_validator = lambda x: TradingAuthRequestHeaders(**x).model_dump(), data_validator = lambda x: TradingAuthRequestData(**x) ) @handle_cancelled_request() async def request_oauth_authorization_url( inbound_headers: dict | TradingAuthRequestHeaders = None, inbound_data: dict | TradingAuthRequestData = None, inbound_files: dict = None, **kwargs ): """ Use this when requesting access to someone's trading account (like Zerodha). We generate a URL here which must be opened by the user (typically in a separate tab), and the user must then grant access to his account directly on the broker's site. The broker will then hit you with a callback URL when the user approves the request. :param inbound_headers: auto-extracted by the decorators. :param inbound_data: auto-extracted by the decorators. :param inbound_files: auto-extracted by the decorators. :param kwargs: Any number of extra inputs supplied by the decorators. :return: A standard response structure. """ # ┏┓ # ┃┃┏┓┏┓┏┓┏┓┏┓┏┏┓┏┏ # ┣┛┛ ┗ ┣┛┛ ┗┛┗┗ ┛┛ # ┛ # If the session token is invalid/expired: if kwargs.get("session_info") is None: return ResponseModel( status_code = StatusCodes.FAILED, http_code = HttpCodes.UNAUTHORIZED ) # Start by assuming failure: success = False auth_url = None # ┏┓ ┏┓ ┏┳┓ ┓• # ┣ ┏┓┏┓ ┃┃┏┓┏┓┏┓┏┓ ┃ ┏┓┏┓┏┫┓┏┓┏┓ # ┻ ┗┛┛ ┣┛┗┻┣┛┗ ┛ ┻ ┛ ┗┻┗┻┗┛┗┗┫ # ┛ ┛ # This is an internal paper-trading account. # It won't need daily logins for usage. if inbound_data.client == "paperTrading": # Immediately save the details against that token id: success = await current_app.paper_trading_controller.set_token_direct( sql_conn = current_app.sql_writer, mongo_data_conn = current_app.data_mongo, auth_token = CoreAuthTokenModel( serviceType = "stockTrading", client = inbound_data.client, authType = "auth", user = kwargs["session_info"], clientUserId = { "username": inbound_data.auth.username, "perTrade": inbound_data.get("perTrade", 0), "perCrore": inbound_data.get("perCrore", 0), "perLot": inbound_data.get("perLot", 0) }, auth = inbound_data.auth.model_dump(), status = "active", syncFreq = None ), token_notes = { "username": inbound_data.auth.username }, display_name = inbound_data.auth.username, display_picture = None, session_token = inbound_headers["X-Session-Token"] ) # Check if things were successful: if not success: auth_url = None # ┏┓ ┏┓ ┓┓ ┓┏┓• # ┣ ┏┓┏┓ ┏┛┏┓┏┓┏┓┏┫┣┓┏┓ ┃┫ ┓╋┏┓ # ┻ ┗┛┛ ┗┛┗ ┛ ┗┛┗┻┛┗┗┻ ┛┗┛┗┗┗ # PLANNED FLOW FOR ZERODHA-KITE: # Step 01.: (One time) The user will go to the integrations page and add his API Key and API Secret there. We store # these values without verification. # Step 02.: (Daily) The user will go to the investments tab and click on his Zerodha account, which will give him # a URL that will take him to Zerodha's official site to log in. When he logs in, Zerodha will hit our # callback URL and give us the authentication details. if inbound_data.client == "zerodhaKite": # Prepare the inputs: auth_url = await current_app.zerodha_kite_controller.get_authorization_url(api_key = inbound_data.auth.apiKey) # Immediately save the details against that token id: success = await current_app.zerodha_kite_controller.set_token_direct( sql_conn = current_app.sql_writer, mongo_data_conn = current_app.data_mongo, auth_token = CoreAuthTokenModel( serviceType = "stockTrading", client = inbound_data.client, authType = "oauth", user = kwargs["session_info"], clientUserId = { "userId": inbound_data.auth.userId, "apiKey": inbound_data.auth.apiKey }, auth = inbound_data.auth.model_dump(), status = "active", syncFreq = None ), token_notes = { "userId": inbound_data.auth.userId, "apiKey": inbound_data.auth.apiKey, "authUrl": auth_url }, display_name = inbound_data.auth.userId, display_picture = None, session_token = inbound_headers["X-Session-Token"] ) # Check if things were successful: if not success: auth_url = None # ┏┓ ┳┏┓┳┏┓┳ ┳┓ # ┣ ┏┓┏┓ ┃┃ ┃┃ ┃ ┣┫┏┓┏┓┏┓┓┏┓ # ┻ ┗┛┛ ┻┗┛┻┗┛┻ ┻┛┛ ┗ ┗ ┗┗ # PLANNED FLOW FOR ICICI-BREEZE: # Step 01.: (One time) The user will go to the integrations page and add his Client User ID, API Key, and API Secret # there. We store these values without verification. # Step 02.: (Daily) The user will go to the investments tab and click on his Breeze account, which will give him a # URL that will take him to ICICI's official site to log in. When he logs in, ICICI will hit our callback # URL and give us the authentication details. if inbound_data.client == "iciciBreeze": # Prepare the inputs: auth_url = await current_app.icici_breeze_controller.get_authorization_url(api_key = inbound_data.auth.apiKey) # Immediately save the details against that token id: success = await current_app.icici_breeze_controller.set_token_direct( sql_conn = current_app.sql_writer, mongo_data_conn = current_app.data_mongo, auth_token = CoreAuthTokenModel( serviceType = "stockTrading", client = inbound_data.client, authType = "oauth", user = kwargs["session_info"], clientUserId = { "userId": inbound_data.auth.userId, "apiKey": inbound_data.auth.apiKey }, auth = inbound_data.auth.model_dump(), status = "active", syncFreq = None ), token_notes = { "userId": inbound_data.auth.userId, "apiKey": inbound_data.auth.apiKey, "authUrl": auth_url }, display_name = inbound_data.auth.userId, display_picture = None, session_token = inbound_headers["X-Session-Token"] ) # Check if things were successful: if not success: auth_url = None # ┳┓ # ┣┫┏┓┏┏┓┏┓┏┓┏┏┓ # ┛┗┗ ┛┣┛┗┛┛┗┛┗ # ┛ # Done here: return ResponseModel( status_code = StatusCodes.OK if success else StatusCodes.FAILED, http_code = HttpCodes.SUCCESS if success else HttpCodes.INTERNAL_SERVER_ERROR, data = { "client": inbound_data.client, "authorizationUrl": auth_url } ) # --------------------------------------------------------------------------------------------------------------------- @trading_oauth_request_bp.route("/update", methods = ["GET", "POST"]) @set_api_version(api_version = "1.0.0") @read_input(sanitize_headers = False, sanitize_data = False) @get_session_info(key = "X-Session-Token", session_coro = "get_session") @log_request_to_mongo( attr_name = "logs_mongo", project = constants.PROJECT_NAME, log_type = constants.MODULE_NAME, operation = "tradingOAuthUrlReqApi", log_input = True, log_output = True, sensitive_keys = ["sessionToken", "X-Session-Token"] ) @log_chain_to_mongo(attr_name = "logs_mongo") @should_not_be_under_maintenance(attr_name = "is_under_maintenance") @validate_input( header_validator = lambda x: TradingAuthRequestHeaders(**x).model_dump(), data_validator = lambda x: TradingAuthRequestData(**x) ) @handle_cancelled_request() async def request_oauth_authorization_update_url( inbound_headers: dict | TradingAuthRequestHeaders = None, inbound_data: dict | TradingAuthRequestData = None, inbound_files: dict = None, **kwargs ): """ Use this when requesting access to someone's trading account (like Zerodha). We generate a URL here which must be opened by the user (typically in a separate tab), and the user must then grant access to his account directly on the broker's site. The broker will then hit you with a callback URL when the user approves the request. :param inbound_headers: auto-extracted by the decorators. :param inbound_data: auto-extracted by the decorators. :param inbound_files: auto-extracted by the decorators. :param kwargs: Any number of extra inputs supplied by the decorators. :return: A standard response structure. """ # ┏┓ # ┃┃┏┓┏┓┏┓┏┓┏┓┏┏┓┏┏ # ┣┛┛ ┗ ┣┛┛ ┗┛┗┗ ┛┛ # ┛ # If the session token is invalid/expired: if kwargs.get("session_info") is None: return ResponseModel( status_code = StatusCodes.FAILED, http_code = HttpCodes.UNAUTHORIZED ) # Start by assuming failure: success = False auth_url = None # ┏┓ ┏┓ ┏┳┓ ┓• # ┣ ┏┓┏┓ ┃┃┏┓┏┓┏┓┏┓ ┃ ┏┓┏┓┏┫┓┏┓┏┓ # ┻ ┗┛┛ ┣┛┗┻┣┛┗ ┛ ┻ ┛ ┗┻┗┻┗┛┗┗┫ # ┛ ┛ # This is an internal paper-trading account. # It won't need daily logins for usage. if inbound_data.client == "paperTrading": # Immediately save the details against that token id: success = await current_app.paper_trading_controller.set_token( sql_conn = current_app.sql_writer, mongo_data_conn = current_app.data_mongo, token_key=inbound_data.get("tokenKey"), auth_token = CoreAuthTokenModel( serviceType = "stockTrading", client = inbound_data.client, authType = "auth", user = kwargs["session_info"], clientUserId = { "username": inbound_data.auth.username, }, auth = inbound_data.auth.model_dump(), status = "active", syncFreq = None ), token_notes = { "username": inbound_data.auth.username, "perTrade": inbound_data.get("perTrade", 0), "perCrore": inbound_data.get("perCrore", 0), "perLot": inbound_data.get("perLot", 0) }, display_name = inbound_data.auth.username, display_picture = None, session_token = inbound_headers["X-Session-Token"] ) print(success) # Check if things were successful: if not success: auth_url = None # ┏┓ ┏┓ ┓┓ ┓┏┓• # ┣ ┏┓┏┓ ┏┛┏┓┏┓┏┓┏┫┣┓┏┓ ┃┫ ┓╋┏┓ # ┻ ┗┛┛ ┗┛┗ ┛ ┗┛┗┻┛┗┗┻ ┛┗┛┗┗┗ # PLANNED FLOW FOR ZERODHA-KITE: # Step 01.: (One time) The user will go to the integrations page and add his API Key and API Secret there. We store # these values without verification. # Step 02.: (Daily) The user will go to the investments tab and click on his Zerodha account, which will give him # a URL that will take him to Zerodha's official site to log in. When he logs in, Zerodha will hit our # callback URL and give us the authentication details. if inbound_data.client == "zerodhaKite": # Prepare the inputs: auth_url = await current_app.zerodha_kite_controller.get_authorization_url(api_key = inbound_data.auth.apiKey) # Immediately save the details against that token id: success = await current_app.zerodha_kite_controller.set_token_direct( sql_conn = current_app.sql_writer, mongo_data_conn = current_app.data_mongo, auth_token = CoreAuthTokenModel( serviceType = "stockTrading", client = inbound_data.client, authType = "oauth", user = kwargs["session_info"], clientUserId = { "userId": inbound_data.auth.userId, "apiKey": inbound_data.auth.apiKey }, auth = inbound_data.auth.model_dump(), status = "active", syncFreq = None ), token_notes = { "userId": inbound_data.auth.userId, "apiKey": inbound_data.auth.apiKey, "authUrl": auth_url }, display_name = inbound_data.auth.userId, display_picture = None, session_token = inbound_headers["X-Session-Token"] ) # Check if things were successful: if not success: auth_url = None # ┏┓ ┳┏┓┳┏┓┳ ┳┓ # ┣ ┏┓┏┓ ┃┃ ┃┃ ┃ ┣┫┏┓┏┓┏┓┓┏┓ # ┻ ┗┛┛ ┻┗┛┻┗┛┻ ┻┛┛ ┗ ┗ ┗┗ # PLANNED FLOW FOR ICICI-BREEZE: # Step 01.: (One time) The user will go to the integrations page and add his Client User ID, API Key, and API Secret # there. We store these values without verification. # Step 02.: (Daily) The user will go to the investments tab and click on his Breeze account, which will give him a # URL that will take him to ICICI's official site to log in. When he logs in, ICICI will hit our callback # URL and give us the authentication details. if inbound_data.client == "iciciBreeze": # Prepare the inputs: auth_url = await current_app.icici_breeze_controller.get_authorization_url(api_key = inbound_data.auth.apiKey) # Immediately save the details against that token id: success = await current_app.icici_breeze_controller.set_token_direct( sql_conn = current_app.sql_writer, mongo_data_conn = current_app.data_mongo, auth_token = CoreAuthTokenModel( serviceType = "stockTrading", client = inbound_data.client, authType = "oauth", user = kwargs["session_info"], clientUserId = { "userId": inbound_data.auth.userId, "apiKey": inbound_data.auth.apiKey }, auth = inbound_data.auth.model_dump(), status = "active", syncFreq = None ), token_notes = { "userId": inbound_data.auth.userId, "apiKey": inbound_data.auth.apiKey, "authUrl": auth_url }, display_name = inbound_data.auth.userId, display_picture = None, session_token = inbound_headers["X-Session-Token"] ) # Check if things were successful: if not success: auth_url = None # ┳┓ # ┣┫┏┓┏┏┓┏┓┏┓┏┏┓ # ┛┗┗ ┛┣┛┗┛┛┗┛┗ # ┛ # Done here: return ResponseModel( status_code = StatusCodes.OK if success else StatusCodes.FAILED, http_code = HttpCodes.SUCCESS if success else HttpCodes.INTERNAL_SERVER_ERROR, data = { "client": inbound_data.client, "authorizationUrl": auth_url } ) # ***************************************************************************************************************** # ***** **** # *** MAIN PROGRAM *** # ***** **** # ***************************************************************************************************************** if __name__ == "__main__": pass