From a2638c2e82ee0dce32f4e5190e71449194380e34 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C3=81lvaro=20Arranz?= Date: Thu, 4 Oct 2018 23:47:41 +0200 Subject: [PATCH 1/3] Improve support for KeyRock v7 and remove support for KeyRock v5 --- src/wirecloud/fiware/social_auth_backend.py | 19 ++----- src/wirecloud/fiware/tests/social_backend.py | 60 +++++++++++--------- 2 files changed, 37 insertions(+), 42 deletions(-) diff --git a/src/wirecloud/fiware/social_auth_backend.py b/src/wirecloud/fiware/social_auth_backend.py index cfc9975f61..2ce32552da 100644 --- a/src/wirecloud/fiware/social_auth_backend.py +++ b/src/wirecloud/fiware/social_auth_backend.py @@ -61,7 +61,9 @@ def create_organizations(strategy, backend, user, response, *args, **kwargs): social = None if social is None: - org_name = Organization.objects.search_available_name(organization['displayName']) + # KeyRock v6 uses displayName instead of name + organization_name = organization["name"] if "name" in organization else organization['displayName'] + org_name = Organization.objects.search_available_name(organization_name) org = Organization.objects.create_organization(org_name) social = UserSocialAuth.objects.create(user=org, uid=organization['id']) @@ -123,7 +125,7 @@ def get_user_details(self, response): 'first_name': first_name, 'last_name': last_name, 'is_superuser': superuser, - 'is_staff': superuser + 'is_staff': superuser, } def request_user_info(self, access_token): @@ -133,17 +135,6 @@ def request_user_info(self, access_token): def user_data(self, access_token, *args, **kwargs): data = self.request_user_info(access_token) - # Newer versions of the FIWARE IdM provides and id field with the - # username of the user. Older versions use actorId as identifier, but - # also provides a nickName field. We use nickName because it is also - # unique and provides a better way for migrating to newer versions - # of KeyRock. Store the appropiated field in username to simplify - # the rest of the code - data['username'] = data['nickName'] if 'nickName' in data else data['id'] - - # Something similar happens with Organizations, previous versions of the - # IdM used to provide an actorId, unify this behaviour... - for organization in data['organizations']: - organization["id"] = organization['actorId'] if 'actorId' in organization else organization['id'] + data['username'] = data.get('username') if "username" in data else data.get('id') return data diff --git a/src/wirecloud/fiware/tests/social_backend.py b/src/wirecloud/fiware/tests/social_backend.py index c88fdd99be..c837a9c5f7 100644 --- a/src/wirecloud/fiware/tests/social_backend.py +++ b/src/wirecloud/fiware/tests/social_backend.py @@ -46,25 +46,24 @@ class TestSocialAuthBackend(WirecloudTestCase, TestCase): populate = False use_search_indexes = False + # KeyRock v6 OLD_RESPONSE = { - "schemas": ["urn:scim:schemas:core:2.0:User"], - "id": 1, - "actorId": 1, - "nickName": "demo", + "id": "demo", + "username": "demo", "displayName": "Demo user", "email": "demo@fiware.org", - "roles": [{"id": 1, "name": "Manager"}, {"id": 7, "name": "Ticket manager"}], + "roles": [{"id": "1", "name": "Manager"}, {"id": "7", "name": "Ticket manager"}], "organizations": [{ - "id": 1, - "actorId": 2, + "id": "00000000000000000000000000000001", "displayName": "Universidad Politecnica de Madrid", "roles": [{"id": 14, "name": "Admin"}] }] } - NEW_RESPONSE = { + OLD_RESPONSE_NO_LAST_NAME = { "id": "demo", - "displayName": "Demo user", + "username": "demo", + "displayName": "Demo", "email": "demo@fiware.org", "roles": [{"id": "1", "name": "Manager"}, {"id": "7", "name": "Ticket manager"}], "organizations": [{ @@ -74,21 +73,26 @@ class TestSocialAuthBackend(WirecloudTestCase, TestCase): }] } - RESPONSE_NO_LAST_NAME = { - "id": "demo", + # KeyRock v7 + NEW_RESPONSE = { + "id": "8b0127d8-38f7-4428-b22d-31bd80bba510", + "displayName": "", "username": "demo", - "displayName": "Demo", "email": "demo@fiware.org", - "roles": [{"id": "1", "name": "Manager"}, {"id": "7", "name": "Ticket manager"}], + "roles": [{"id": "4a923351-b767-4fef-bc92-4a4fa996e88e", "name": "Manager"}, {"id": "4a92as51-b54d-4fef-bc92-4a4fa996e88e", "name": "Ticket manager"}], "organizations": [{ - "id": "00000000000000000000000000000001", - "displayName": "Universidad Politecnica de Madrid", - "roles": [{"id": 14, "name": "Admin"}] + "id": "04ac28b2-54c7-46a7-a606-c62fdc4f1513", + "name": "Mi organization", + "description":"dafsdf", + "website": None, + "roles":[{"id": "4a923351-b767-4fef-bc92-4a4fa996e88e", "name":"one_role"}] }] } USER_DATA = {"username": "demo", "email": "demo@fiware.org", "fullname": "Demo user", "first_name": "Demo", "last_name": "user", "is_superuser": False, "is_staff": False} + NEW_USER_DATA = {"username": "demo", "email": "demo@fiware.org", "fullname": "", "first_name": "", "last_name": "", "is_superuser": False, "is_staff": False} USER_DATA_ADMIN = {"username": "demo", "email": "demo@fiware.org", "fullname": "Demo user", "first_name": "Demo", "last_name": "user", "is_superuser": True, "is_staff": True} + NEW_USER_DATA_ADMIN = {"username": "demo", "email": "demo@fiware.org", "fullname": "", "first_name": "", "last_name": "", "is_superuser": True, "is_staff": True} USER_DATA_NO_LAST_NAME = {"username": "demo", "email": "demo@fiware.org", "fullname": "Demo", "first_name": "Demo", "last_name": "", "is_superuser": False, "is_staff": False} def setUp(self): @@ -129,7 +133,7 @@ def test_get_user_data_old_version(self): self.assertIn('username', data) self.assertEqual(data['username'], 'demo') self.assertIn('id', data['organizations'][0]) - self.assertEqual(data['organizations'][0]['id'], 2) + self.assertEqual(data['organizations'][0]['id'], "00000000000000000000000000000001") def test_get_user_data_new_version(self): @@ -139,7 +143,7 @@ def test_get_user_data_new_version(self): self.assertIn('username', data) self.assertEqual(data['username'], 'demo') self.assertIn('id', data['organizations'][0]) - self.assertEqual(data['organizations'][0]['id'], "00000000000000000000000000000001") + self.assertEqual(data['organizations'][0]['id'], "04ac28b2-54c7-46a7-a606-c62fdc4f1513") def test_get_user_data_invalid_response(self): @@ -165,18 +169,25 @@ def test_get_user_details_old_version(self): def test_get_user_details_old_version_admin(self): response = deepcopy(self.OLD_RESPONSE) - response['roles'][0]['name'] = 'admin' + response['roles'][0]['name'] = 'Admin' data = self.instance.get_user_details(response) self.assertEqual(data, self.USER_DATA_ADMIN) + def test_get_user_details_old_version_no_last_name(self): + + response = deepcopy(self.OLD_RESPONSE_NO_LAST_NAME) + data = self.instance.get_user_details(response) + + self.assertEqual(data, self.USER_DATA_NO_LAST_NAME) + def test_get_user_details_new_version(self): response = deepcopy(self.NEW_RESPONSE) response['username'] = 'demo' data = self.instance.get_user_details(response) - self.assertEqual(data, self.USER_DATA) + self.assertEqual(data, self.NEW_USER_DATA) def test_get_user_details_new_version_admin(self): @@ -184,14 +195,7 @@ def test_get_user_details_new_version_admin(self): response['roles'][0]['name'] = 'Admin' data = self.instance.get_user_details(response) - self.assertEqual(data, self.USER_DATA_ADMIN) - - def test_get_user_details_no_last_name(self): - - response = deepcopy(self.RESPONSE_NO_LAST_NAME) - data = self.instance.get_user_details(response) - - self.assertEqual(data, self.USER_DATA_NO_LAST_NAME) + self.assertEqual(data, self.NEW_USER_DATA_ADMIN) def test_request_user_info(self): From 5b66135aae4ac4095581981db5c2553a7cf047ee Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C3=81lvaro=20Arranz?= Date: Thu, 4 Oct 2018 23:50:58 +0200 Subject: [PATCH 2/3] Document WireCloud only supports keyrock v6 and v7 --- docs/installation_guide.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/installation_guide.md b/docs/installation_guide.md index f85b2991f1..2b46335b9c 100644 --- a/docs/installation_guide.md +++ b/docs/installation_guide.md @@ -815,7 +815,7 @@ for more information about how to install and configure such a NGSI proxy. ### Integration with the IdM GE -Create a new Application using the IdM server that is going to be linked (for example: `https://account.lab.fiware.org`). See the [KeyRock's User and Programmers Guide] for more information about how to create such an Application. Redirect URI must be: `http(s)://${wirecloud_server}/complete/fiware/`. Take note of the *Client ID* and the *Client Secret* values (those values are available in the Application details page, inside the *OAuth2 Credentials* section) as they are going to be used later. +The first thing to take into account is that this version of WireCloud is compatible with KeyRock v6 and KeyRock v7. To enable this integration, the first step is creating a new Application using the IdM server that is going to be used (for example: `https://account.lab.fiware.org`). See the [KeyRock's User and Programmers Guide] for more information about how to create such an Application. Redirect URI must be: `http(s)://${wirecloud_server}/complete/fiware/`. Take note of the *Client ID* and the *Client Secret* values (those values are available in the Application details page, inside the *OAuth2 Credentials* section) as they are going to be used later. On the WireCloud instance: From a8947459dea9136c1f68b95cc3a5c370ef4b9656 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C3=81lvaro=20Arranz?= Date: Wed, 10 Oct 2018 11:11:02 +0200 Subject: [PATCH 3/3] Complete social_auth_backend coverage --- src/wirecloud/fiware/social_auth_backend.py | 2 + src/wirecloud/fiware/tests/social_backend.py | 43 ++++++++++++++++++++ 2 files changed, 45 insertions(+) diff --git a/src/wirecloud/fiware/social_auth_backend.py b/src/wirecloud/fiware/social_auth_backend.py index 2ce32552da..c7505e8068 100644 --- a/src/wirecloud/fiware/social_auth_backend.py +++ b/src/wirecloud/fiware/social_auth_backend.py @@ -32,6 +32,8 @@ field, check OAuthBackend class for details on how to extend it. """ +from __future__ import unicode_literals + import base64 import time from six.moves.urllib.parse import urljoin diff --git a/src/wirecloud/fiware/tests/social_backend.py b/src/wirecloud/fiware/tests/social_backend.py index c837a9c5f7..425514c276 100644 --- a/src/wirecloud/fiware/tests/social_backend.py +++ b/src/wirecloud/fiware/tests/social_backend.py @@ -35,6 +35,20 @@ class BasicClass(object): def __init__(self): pass + def extra_data(self, user, uid, response, details=None, *args, **kwargs): + return { + "access_token": "access_token", + "refresh_token": "refresh_token", + "expires_in": 3600 + } + + def refresh_token(self, token, *args, **kwargs): + return { + "access_token": "new_access_token", + "refresh_token": "new_refresh_token", + "expires_in": 3600 + } + @classmethod def get_key_and_secret(cls): return ('client', 'secret') @@ -158,6 +172,20 @@ def test_auth_headers(self): self.assertIn('Basic ', headers['Authorization']) self.assertEqual(headers['Authorization'], 'Basic Y2xpZW50OnNlY3JldA==') + @patch("wirecloud.fiware.social_auth_backend.time.time") + def test_extra_data(self, time_mock): + + time_mock.return_value = 10000 + + data = self.instance.extra_data("user", "uid", "response") + + self.assertEqual(data, { + "access_token": "access_token", + "refresh_token": "refresh_token", + "expires_in": 3600, + "expires_on": 13600 + }) + def test_get_user_details_old_version(self): response = deepcopy(self.OLD_RESPONSE) @@ -197,6 +225,21 @@ def test_get_user_details_new_version_admin(self): self.assertEqual(data, self.NEW_USER_DATA_ADMIN) + @patch("wirecloud.fiware.social_auth_backend.time.time") + def test_refresh_token_normalizes_token_expiration_time(self, time_mock): + + time_mock.return_value = 10000 + + data = self.instance.refresh_token("old_access_token") + + self.assertEqual(data, { + "access_token": "new_access_token", + "refresh_token": "new_refresh_token", + "expires_in": 3600, + "expires_on": 13600, + "openstack_token": None + }) + def test_request_user_info(self): self.instance.request = Mock()