2020-12-02 10:09:08 +02:00
|
|
|
#!/usr/bin/env python
|
|
|
|
#
|
|
|
|
# Copyright (C) 2020 GNS3 Technologies Inc.
|
|
|
|
#
|
|
|
|
# This program is free software: you can redistribute it and/or modify
|
|
|
|
# it under the terms of the GNU General Public License as published by
|
|
|
|
# the Free Software Foundation, either version 3 of the License, or
|
|
|
|
# (at your option) any later version.
|
|
|
|
#
|
|
|
|
# This program is distributed in the hope that it will be useful,
|
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
# GNU General Public License for more details.
|
|
|
|
#
|
|
|
|
# You should have received a copy of the GNU General Public License
|
|
|
|
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
|
|
|
|
"""
|
|
|
|
API routes for users.
|
|
|
|
"""
|
|
|
|
|
|
|
|
from fastapi import APIRouter, Depends, HTTPException, status
|
2020-12-07 08:22:36 +02:00
|
|
|
from fastapi.security import OAuth2PasswordRequestForm
|
2020-12-02 10:09:08 +02:00
|
|
|
from uuid import UUID
|
|
|
|
from typing import List
|
|
|
|
|
|
|
|
from gns3server import schemas
|
2020-12-16 09:54:21 +02:00
|
|
|
from gns3server.controller.controller_error import (
|
|
|
|
ControllerBadRequestError,
|
|
|
|
ControllerNotFoundError,
|
|
|
|
ControllerUnauthorizedError
|
|
|
|
)
|
|
|
|
|
2020-12-02 10:09:08 +02:00
|
|
|
from gns3server.db.repositories.users import UsersRepository
|
|
|
|
from gns3server.services import auth_service
|
|
|
|
|
|
|
|
from .dependencies.authentication import get_current_active_user
|
2020-12-07 08:22:36 +02:00
|
|
|
from .dependencies.database import get_repository
|
2020-12-02 10:09:08 +02:00
|
|
|
|
|
|
|
import logging
|
|
|
|
log = logging.getLogger(__name__)
|
|
|
|
|
|
|
|
router = APIRouter()
|
|
|
|
|
|
|
|
|
|
|
|
@router.get("", response_model=List[schemas.User])
|
2021-04-05 07:51:41 +03:00
|
|
|
async def get_users(users_repo: UsersRepository = Depends(get_repository(UsersRepository))) -> List[schemas.User]:
|
2020-12-02 10:09:08 +02:00
|
|
|
"""
|
|
|
|
Get all users.
|
|
|
|
"""
|
|
|
|
|
2021-04-05 07:51:41 +03:00
|
|
|
return await users_repo.get_users()
|
2020-12-02 10:09:08 +02:00
|
|
|
|
|
|
|
|
|
|
|
@router.post("", response_model=schemas.User, status_code=status.HTTP_201_CREATED)
|
2020-12-07 08:22:36 +02:00
|
|
|
async def create_user(
|
2021-04-05 07:51:41 +03:00
|
|
|
user_create: schemas.UserCreate,
|
|
|
|
users_repo: UsersRepository = Depends(get_repository(UsersRepository))
|
2020-12-07 08:22:36 +02:00
|
|
|
) -> schemas.User:
|
2020-12-02 10:09:08 +02:00
|
|
|
"""
|
|
|
|
Create a new user.
|
|
|
|
"""
|
|
|
|
|
2021-04-05 07:51:41 +03:00
|
|
|
if await users_repo.get_user_by_username(user_create.username):
|
|
|
|
raise ControllerBadRequestError(f"Username '{user_create.username}' is already registered")
|
2020-12-02 10:09:08 +02:00
|
|
|
|
2021-04-05 07:51:41 +03:00
|
|
|
if user_create.email and await users_repo.get_user_by_email(user_create.email):
|
|
|
|
raise ControllerBadRequestError(f"Email '{user_create.email}' is already registered")
|
2020-12-02 10:09:08 +02:00
|
|
|
|
2021-04-05 07:51:41 +03:00
|
|
|
return await users_repo.create_user(user_create)
|
2020-12-02 10:09:08 +02:00
|
|
|
|
|
|
|
|
|
|
|
@router.get("/{user_id}", response_model=schemas.User)
|
2020-12-07 08:22:36 +02:00
|
|
|
async def get_user(
|
|
|
|
user_id: UUID,
|
2021-04-05 07:51:41 +03:00
|
|
|
users_repo: UsersRepository = Depends(get_repository(UsersRepository))
|
2020-12-07 08:22:36 +02:00
|
|
|
) -> schemas.User:
|
2020-12-02 10:09:08 +02:00
|
|
|
"""
|
|
|
|
Get an user.
|
|
|
|
"""
|
|
|
|
|
2021-04-05 07:51:41 +03:00
|
|
|
user = await users_repo.get_user(user_id)
|
2020-12-02 10:09:08 +02:00
|
|
|
if not user:
|
|
|
|
raise ControllerNotFoundError(f"User '{user_id}' not found")
|
|
|
|
return user
|
|
|
|
|
|
|
|
|
|
|
|
@router.put("/{user_id}", response_model=schemas.User)
|
2020-12-07 08:22:36 +02:00
|
|
|
async def update_user(
|
|
|
|
user_id: UUID,
|
2021-04-05 07:51:41 +03:00
|
|
|
user_update: schemas.UserUpdate,
|
|
|
|
users_repo: UsersRepository = Depends(get_repository(UsersRepository))
|
2020-12-07 08:22:36 +02:00
|
|
|
) -> schemas.User:
|
2020-12-02 10:09:08 +02:00
|
|
|
"""
|
|
|
|
Update an user.
|
|
|
|
"""
|
|
|
|
|
2021-04-05 07:51:41 +03:00
|
|
|
user = await users_repo.update_user(user_id, user_update)
|
2020-12-02 10:09:08 +02:00
|
|
|
if not user:
|
|
|
|
raise ControllerNotFoundError(f"User '{user_id}' not found")
|
|
|
|
return user
|
|
|
|
|
|
|
|
|
|
|
|
@router.delete("/{user_id}", status_code=status.HTTP_204_NO_CONTENT)
|
2020-12-16 09:54:21 +02:00
|
|
|
async def delete_user(
|
|
|
|
user_id: UUID,
|
2021-04-05 07:51:41 +03:00
|
|
|
users_repo: UsersRepository = Depends(get_repository(UsersRepository)),
|
2020-12-16 09:54:21 +02:00
|
|
|
current_user: schemas.User = Depends(get_current_active_user)
|
|
|
|
) -> None:
|
2020-12-02 10:09:08 +02:00
|
|
|
"""
|
|
|
|
Delete an user.
|
|
|
|
"""
|
|
|
|
|
2020-12-16 09:54:21 +02:00
|
|
|
if current_user.is_superuser:
|
|
|
|
raise ControllerUnauthorizedError("The super user cannot be deleted")
|
|
|
|
|
2021-04-05 07:51:41 +03:00
|
|
|
success = await users_repo.delete_user(user_id)
|
2020-12-02 10:09:08 +02:00
|
|
|
if not success:
|
|
|
|
raise ControllerNotFoundError(f"User '{user_id}' not found")
|
|
|
|
|
|
|
|
|
|
|
|
@router.post("/login", response_model=schemas.Token)
|
2020-12-07 08:22:36 +02:00
|
|
|
async def login(
|
2021-04-05 07:51:41 +03:00
|
|
|
users_repo: UsersRepository = Depends(get_repository(UsersRepository)),
|
2020-12-07 08:22:36 +02:00
|
|
|
form_data: OAuth2PasswordRequestForm = Depends()
|
|
|
|
) -> schemas.Token:
|
2020-12-02 10:09:08 +02:00
|
|
|
"""
|
|
|
|
User login.
|
|
|
|
"""
|
|
|
|
|
2021-04-05 07:51:41 +03:00
|
|
|
user = await users_repo.authenticate_user(username=form_data.username, password=form_data.password)
|
2020-12-02 10:09:08 +02:00
|
|
|
if not user:
|
|
|
|
raise HTTPException(status_code=status.HTTP_401_UNAUTHORIZED,
|
|
|
|
detail="Authentication was unsuccessful.",
|
|
|
|
headers={"WWW-Authenticate": "Bearer"})
|
|
|
|
|
|
|
|
token = schemas.Token(access_token=auth_service.create_access_token(user.username), token_type="bearer")
|
|
|
|
return token
|
|
|
|
|
|
|
|
|
|
|
|
@router.get("/users/me/", response_model=schemas.User)
|
|
|
|
async def get_current_active_user(current_user: schemas.User = Depends(get_current_active_user)) -> schemas.User:
|
|
|
|
"""
|
|
|
|
Get the current active user.
|
|
|
|
"""
|
|
|
|
|
|
|
|
return current_user
|