202 lines
7.0 KiB
Python
202 lines
7.0 KiB
Python
"""
|
|
|
|
AUTHOR:
|
|
|
|
Khushal P Soonderji
|
|
|
|
DATE:
|
|
|
|
Wednesday, 19th Feb., 2025.
|
|
|
|
OBJECTIVE:
|
|
|
|
To perform a login from an ISP's device like a MikroTik.
|
|
|
|
REFERENCES:
|
|
|
|
N/A
|
|
|
|
DOWNLOADS:
|
|
|
|
N/A
|
|
|
|
NOTES:
|
|
|
|
N/A
|
|
|
|
"""
|
|
|
|
|
|
# *****************************************************************************************************************
|
|
# ***** ****
|
|
# *** IMPORT ***
|
|
# ***** ****
|
|
# *****************************************************************************************************************
|
|
|
|
|
|
# To make sibling directories accessible for imports:
|
|
import sys
|
|
sys.path.append(".")
|
|
sys.path.append("..")
|
|
|
|
# For using Quart:
|
|
from quart import Blueprint, current_app, request
|
|
|
|
# My utils:
|
|
from utils_v2.string import json
|
|
from utils_v2.api.codes import StatusCodes, HttpCodes
|
|
from utils_v2.api.response import ResponseModel
|
|
from utils_v2.api.async_quart import (
|
|
set_api_version,
|
|
read_input,
|
|
get_session_info,
|
|
log_request_to_mongo,
|
|
log_chain_to_mongo,
|
|
should_not_be_under_maintenance,
|
|
only_whitelisted_ips,
|
|
limit_rate,
|
|
validate_input,
|
|
handle_cancelled_request
|
|
)
|
|
|
|
# Common:
|
|
from shared import constants
|
|
|
|
# Data Models:
|
|
from models.core.user import CoreUserInfoModel
|
|
from models.api.common.isp.user_login import ISPUserLoginRequestHeaders, ISPUserLoginRequestData
|
|
|
|
# Helpers:
|
|
from api.helpers.user import token_check
|
|
|
|
# To work with MongoDB:
|
|
from bson import ObjectId
|
|
|
|
# To generate UUIDs:
|
|
import uuid
|
|
|
|
# For asynchronous activities:
|
|
import asyncio
|
|
|
|
|
|
# *****************************************************************************************************************
|
|
# ***** ****
|
|
# *** MACROS / ONE-TIME INIT ***
|
|
# ***** ****
|
|
# *****************************************************************************************************************
|
|
|
|
|
|
# Related to Quart:
|
|
isp_user_login_bp = Blueprint("isp_user_login", __name__)
|
|
|
|
|
|
# *****************************************************************************************************************
|
|
# ***** ****
|
|
# *** VARIABLES ***
|
|
# ***** ****
|
|
# *****************************************************************************************************************
|
|
|
|
|
|
# --- Nothing Yet
|
|
|
|
|
|
# *****************************************************************************************************************
|
|
# ***** ****
|
|
# *** FUNCTIONS ***
|
|
# ***** ****
|
|
# *****************************************************************************************************************
|
|
|
|
|
|
@isp_user_login_bp.record_once
|
|
def init(blueprint_setup_state):
|
|
|
|
# This gets called when the blueprint is registered.
|
|
# Consider this to be a one-time setup for the whole blueprint:
|
|
pass
|
|
|
|
|
|
# ---------------------------------------------------------------------------------------------------------------------
|
|
|
|
|
|
@isp_user_login_bp.route("/login", methods = ["POST"])
|
|
@set_api_version(api_version = "1.0.0")
|
|
@read_input(sanitize_headers = False, sanitize_data = False)
|
|
@get_session_info(key = "X-Session-Token", session_coro = "get_session")
|
|
@log_request_to_mongo(
|
|
attr_name = "logs_mongo",
|
|
project = constants.PROJECT_NAME,
|
|
log_type = constants.MODULE_NAME,
|
|
operation = "ispUsrLoginApi",
|
|
log_input = True,
|
|
log_output = True,
|
|
sensitive_keys = ["sessionToken", "X-Session-Token", "tokenKey"]
|
|
)
|
|
@log_chain_to_mongo(attr_name = "logs_mongo")
|
|
@should_not_be_under_maintenance(attr_name = "is_under_maintenance")
|
|
@validate_input(
|
|
header_validator = lambda x: ISPUserLoginRequestHeaders(**x).model_dump(),
|
|
data_validator = lambda x: ISPUserLoginRequestData(**x)
|
|
)
|
|
@handle_cancelled_request()
|
|
async def disable_auth_token(
|
|
inbound_headers: dict | ISPUserLoginRequestHeaders = None,
|
|
inbound_data: dict | ISPUserLoginRequestData = None,
|
|
inbound_files: dict = None,
|
|
**kwargs
|
|
):
|
|
|
|
"""
|
|
Use this for allowing an ISP's customer to login.
|
|
:param inbound_headers: auto-extracted by the decorators.
|
|
:param inbound_data: auto-extracted by the decorators.
|
|
:param inbound_files: auto-extracted by the decorators.
|
|
:param kwargs: Any number of extra inputs supplied by the decorators.
|
|
:return: A standard response structure.
|
|
"""
|
|
|
|
# ┏┓ ┓ ┏┓┓ ┓
|
|
# ┣┫┓┏╋┣┓ ┃ ┣┓┏┓┏┃┏
|
|
# ┛┗┗┻┗┛┗ ┗┛┛┗┗ ┗┛┗
|
|
|
|
# If the session token is invalid/expired:
|
|
if kwargs.get("session_info") is None:
|
|
return constants.API_RESPONSE_UNAUTHORIZED
|
|
|
|
# Get the user's info:
|
|
user_info = CoreUserInfoModel(**kwargs.get("session_info"))
|
|
|
|
# The user requesting this action needs to be an "Owner":
|
|
if user_info.role.strip().lower() != "owner":
|
|
return ResponseModel(
|
|
status_code = StatusCodes.FAILED,
|
|
http_code = HttpCodes.UNAUTHORIZED,
|
|
message = "Only owners can perform this action."
|
|
)
|
|
|
|
# ┏┓ ┳┳┓ • ┓┏
|
|
# ┗┓┏┓┏┳┓┏┓ ┃┃┃┏┓┏┓┓┏ ┣┫┏┓┏┓┏┓
|
|
# ┗┛┗┛┛┗┗┗ ┛ ┗┗┻┗┫┗┗ ┛┗┗ ┛ ┗
|
|
# ┛
|
|
|
|
# Gili-gili chhoo:
|
|
pass
|
|
|
|
# Done here:
|
|
return ResponseModel(
|
|
status_code = StatusCodes.FAILED,
|
|
http_code = HttpCodes.NOT_IMPLEMENTED,
|
|
data = None
|
|
)
|
|
|
|
|
|
# *****************************************************************************************************************
|
|
# ***** ****
|
|
# *** MAIN PROGRAM ***
|
|
# ***** ****
|
|
# *****************************************************************************************************************
|
|
|
|
|
|
if __name__ == "__main__":
|
|
|
|
pass
|