summaryrefslogtreecommitdiff
path: root/src/meetingtools/apps/auth/views.py
blob: 8da9a31477cee3325a7db49369e108815e8c07ea (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
'''
Created on Jul 5, 2010

@author: leifj
'''
from django.http import HttpResponseRedirect
from django.contrib.auth.models import User, Group
import datetime
from django.views.decorators.cache import never_cache
import logging
from meetingtools.apps.userprofile.models import UserProfile
from meetingtools.multiresponse import redirect_to, make_response_dict
from meetingtools.ac import ac_api_client, ac_api
from django.shortcuts import render_to_response
from django.contrib import auth
from django_co_connector.models import co_import_from_request, add_member,\
    remove_member
from meetingtools.apps.cluster.models import acc_for_user

def meta(request,attr):
    v = request.META.get(attr)
    if not v:
        return None
    values = filter(lambda x: x != "(null)",v.split(";"))
    return values;

def meta1(request,attr):
    v = meta(request,attr)
    if v:
        return str(v[0]).decode('utf-8')
    else:
        return None

def _localpart(a):
    if hasattr(a,'name'):
        a = a.name
    if '@' in a:
        (lp,dp) = a.split('@')
        a = lp
    return a

def _is_member_or_employee_old(affiliations):
    lpa = map(_localpart,affiliations)
    return 'student' in lpa or 'staff' in lpa or ('member' in lpa and not 'student' in lpa)

def _is_member_or_employee(user):
    lpa = map(_localpart,user.groups.all())
    return 'student' in lpa or 'staff' in lpa or ('member' in lpa and not 'student' in lpa)

@never_cache
def logout(request):
    auth.logout(request)
    return HttpResponseRedirect('/Shibboleth.sso/Logout')

@never_cache
def login(request):
    return render_to_response('apps/auth/login.html',make_response_dict(request,{'next': request.REQUEST.get("next")}));

def join_group(group,**kwargs):
    user = kwargs['user']
    acc = acc_for_user(user)
    connect_api = ac_api(acc)    
    principal = connect_api.find_principal("login", user.username, "user")
    if principal:
        gp = connect_api.find_group(group.name)
        if gp:
            connect_api.add_member(principal.get('principal-id'),gp.get('principal-id'))
    
            
def leave_group(group,**kwargs):
    user = kwargs['user']
    acc = acc_for_user(user)
    connect_api = ac_api(acc)
    
    principal = connect_api.find_principal("login", user.username, "user")
    if principal:
        gp = connect_api.find_group(group.name)
        if gp:
            connect_api.remove_member(principal.get('principal-id'),gp.get('principal-id'))

add_member.connect(join_group,sender=Group)
remove_member.connect(leave_group,sender=Group)

def accounts_login_federated(request):
    if request.user.is_authenticated():
        profile,created = UserProfile.objects.get_or_create(user=request.user)
        if created:
            profile.identifier = request.user.username
            profile.user = request.user
            profile.save()        
        
        update = False
        fn = meta1(request,'givenName')
        ln = meta1(request,'sn')
        cn = meta1(request,'cn')
        if not cn:
            cn = meta1(request,'displayName')
        logging.debug("cn=%s" % cn)
        if not cn and fn and ln:
            cn = "%s %s" % (fn,ln)
        if not cn:
            cn = profile.identifier
            
        mail = meta1(request,'mail')
        
        idp = meta1(request,'Shib-Identity-Provider')
        
        for attrib_name, meta_value in (('display_name',cn),('email',mail),('idp',idp)):
            attrib_value = getattr(profile, attrib_name)
            if meta_value and not attrib_value:
                setattr(profile,attrib_name,meta_value)
                update = True
                
        if request.user.password == "":
            request.user.password = "(not used for federated logins)"
            update = True
            
        if update:
            request.user.save()
        
        # Allow auto_now to kick in for the lastupdated field
        #profile.lastupdated = datetime.datetime.now()    
        profile.save()

        acc = acc_for_user(request.user)
        connect_api = ac_api_client(request, acc)
        # make sure the principal is created before shooting off 
        principal = connect_api.find_or_create_principal("login", request.user.username, "user", 
                                                         {'type': "user",
                                                          'has-children': "0",
                                                          'first-name':fn,
                                                          'last-name':ln,
                                                          'email':mail,
                                                          'send-email': 0,
                                                          'login':request.user.username,
                                                          'ext-login':request.user.username})
        
        
        
        co_import_from_request(request)
        
        member_or_employee = _is_member_or_employee(request.user)
        for gn in ('live-admins','seminar-admins'):
            group = connect_api.find_builtin(gn)
            if group:
                connect_api.add_remove_member(principal.get('principal-id'),group.get('principal-id'),member_or_employee)
        
        #(lp,domain) = uid.split('@')
        #for a in ('student','employee','member'):
        #    affiliation = "%s@%s" % (a,domain)
        #    group = connect_api.find_or_create_principal('name',affiliation,'group',{'type': 'group','has-children':'1','name': affiliation})
        #    member = affiliation in affiliations
        #    connect_api.add_remove_member(principal.get('principal-id'),group.get('principal-id'),member)
            
        #for e in epe:
        #    group = connect_api.find_or_create_principal('name',e,'group',{'type': 'group','has-children':'1','name': e})
        #    if group:
        #        connect_api.add_remove_member(principal.get('principal-id'),group.get('principal-id'),True)
            
        next = request.session.get("after_login_redirect", None)
        if not next and request.GET.has_key('next'):
            next = request.GET['next']
        if next is not None:
            return redirect_to(next)
    else:
        pass
    return redirect_to("/")