etesync-server/django_etesync/views.py

477 lines
19 KiB
Python
Raw Normal View History

2020-02-19 18:53:43 +00:00
# Copyright © 2017 Tom Hacohen
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, version 3.
#
# This library is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
2020-02-19 12:55:56 +00:00
2020-05-14 10:43:49 +00:00
import json
2020-04-14 13:21:51 +00:00
from django.conf import settings
2020-02-26 12:21:14 +00:00
from django.contrib.auth import get_user_model
from django.db import transaction, IntegrityError
2020-04-16 14:14:03 +00:00
from django.db.models import Max
2020-04-14 13:21:51 +00:00
from django.http import HttpResponseBadRequest, HttpResponse, Http404
2020-02-19 18:53:43 +00:00
from django.shortcuts import get_object_or_404
from rest_framework import status
from rest_framework import viewsets
2020-02-20 11:56:16 +00:00
from rest_framework import parsers
from rest_framework.decorators import action as action_decorator
2020-02-19 18:53:43 +00:00
from rest_framework.response import Response
2020-05-14 10:43:49 +00:00
from rest_framework.authtoken.models import Token
import nacl.encoding
import nacl.signing
import nacl.secret
import nacl.hash
2020-02-19 18:53:43 +00:00
from . import app_settings
from .models import Collection, CollectionItem, CollectionItemRevision
2020-02-19 18:53:43 +00:00
from .serializers import (
2020-05-14 10:43:49 +00:00
b64encode,
AuthenticationSignupSerializer,
AuthenticationLoginChallengeSerializer,
AuthenticationLoginSerializer,
AuthenticationLoginInnerSerializer,
2020-02-19 18:53:43 +00:00
CollectionSerializer,
CollectionItemSerializer,
2020-05-19 08:20:02 +00:00
CollectionItemDepSerializer,
2020-02-20 20:41:39 +00:00
CollectionItemRevisionSerializer,
2020-05-14 14:19:18 +00:00
CollectionItemChunkSerializer,
UserSerializer,
2020-02-19 18:53:43 +00:00
)
User = get_user_model()
class BaseViewSet(viewsets.ModelViewSet):
authentication_classes = tuple(app_settings.API_AUTHENTICATORS)
permission_classes = tuple(app_settings.API_PERMISSIONS)
stoken_id_field = None
2020-02-19 18:53:43 +00:00
def get_serializer_class(self):
serializer_class = self.serializer_class
if self.request.method == 'PUT':
serializer_class = getattr(self, 'serializer_update_class', serializer_class)
return serializer_class
def get_collection_queryset(self, queryset=Collection.objects):
user = self.request.user
return queryset.filter(members__user=user)
2020-02-19 18:53:43 +00:00
def get_stoken_rev(self, request):
stoken = request.GET.get('stoken', None)
if stoken is not None:
return get_object_or_404(CollectionItemRevision.objects.all(), uid=stoken)
return None
def filter_by_stoken_and_limit(self, request, queryset):
limit = int(request.GET.get('limit', 50))
stoken_id_field = self.stoken_id_field + '__id'
stoken_rev = self.get_stoken_rev(request)
if stoken_rev is not None:
last_rev = get_object_or_404(CollectionItemRevision.objects.all(), uid=stoken_rev.uid)
filter_by = {stoken_id_field + '__gt': last_rev.id}
queryset = queryset.filter(**filter_by)
stoken = stoken_rev.uid
else:
stoken = None
new_stoken_id = queryset.aggregate(stoken_id=Max(stoken_id_field))['stoken_id']
new_stoken = CollectionItemRevision.objects.get(id=new_stoken_id).uid if new_stoken_id is not None else stoken
return queryset[:limit], new_stoken
2020-02-19 18:53:43 +00:00
class CollectionViewSet(BaseViewSet):
allowed_methods = ['GET', 'POST', 'DELETE']
permission_classes = BaseViewSet.permission_classes
queryset = Collection.objects.all()
serializer_class = CollectionSerializer
lookup_field = 'uid'
stoken_id_field = 'items__revisions'
2020-02-19 18:53:43 +00:00
def get_queryset(self, queryset=None):
if queryset is None:
queryset = type(self).queryset
2020-02-19 18:53:43 +00:00
return self.get_collection_queryset(queryset)
def get_serializer_context(self):
context = super().get_serializer_context()
inline = 'inline' in self.request.query_params
2020-04-15 13:47:31 +00:00
context.update({'request': self.request, 'inline': inline})
return context
2020-02-19 18:53:43 +00:00
def destroy(self, request, uid=None):
# FIXME: implement
return Response(status=status.HTTP_405_METHOD_NOT_ALLOWED)
2020-04-19 12:13:09 +00:00
def partial_update(self, request, uid=None):
return Response(status=status.HTTP_405_METHOD_NOT_ALLOWED)
2020-02-19 18:53:43 +00:00
def create(self, request, *args, **kwargs):
serializer = self.serializer_class(data=request.data, context=self.get_serializer_context())
2020-02-19 18:53:43 +00:00
if serializer.is_valid():
try:
serializer.save(owner=self.request.user)
2020-02-19 18:53:43 +00:00
except IntegrityError:
content = {'code': 'integrity_error'}
return Response(content, status=status.HTTP_400_BAD_REQUEST)
return Response({}, status=status.HTTP_201_CREATED)
return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
def list(self, request):
queryset = self.get_queryset()
queryset, new_stoken = self.filter_by_stoken_and_limit(request, queryset)
serializer = self.serializer_class(queryset, context=self.get_serializer_context(), many=True)
ret = {
'data': serializer.data,
}
return Response(ret, headers={'X-EteSync-SToken': new_stoken})
2020-02-19 18:53:43 +00:00
class CollectionItemViewSet(BaseViewSet):
allowed_methods = ['GET', 'POST', 'PUT']
2020-02-19 18:53:43 +00:00
permission_classes = BaseViewSet.permission_classes
queryset = CollectionItem.objects.all()
serializer_class = CollectionItemSerializer
lookup_field = 'uid'
stoken_id_field = 'revisions'
2020-02-19 18:53:43 +00:00
def get_queryset(self):
collection_uid = self.kwargs['collection_uid']
try:
collection = self.get_collection_queryset(Collection.objects).get(uid=collection_uid)
except Collection.DoesNotExist:
raise Http404("Collection does not exist")
2020-02-20 20:41:39 +00:00
# XXX Potentially add this for performance: .prefetch_related('revisions__chunks')
queryset = type(self).queryset.filter(collection__pk=collection.pk,
revisions__current=True,
revisions__deleted=False)
2020-02-19 18:53:43 +00:00
return queryset
def get_serializer_context(self):
context = super().get_serializer_context()
inline = 'inline' in self.request.query_params
2020-04-15 13:47:31 +00:00
context.update({'request': self.request, 'inline': inline})
return context
2020-02-19 18:53:43 +00:00
def create(self, request, collection_uid=None):
collection_object = get_object_or_404(self.get_collection_queryset(Collection.objects), uid=collection_uid)
2020-02-19 18:53:43 +00:00
# FIXME: change this to also support bulk update, or have another endpoint for that.
# See https://www.django-rest-framework.org/api-guide/serializers/#customizing-multiple-update
2020-02-19 18:53:43 +00:00
many = isinstance(request.data, list)
serializer = self.serializer_class(data=request.data, many=many)
2020-02-20 11:56:16 +00:00
if serializer.is_valid():
try:
serializer.save(collection=collection_object)
except IntegrityError:
content = {'code': 'integrity_error'}
return Response(content, status=status.HTTP_400_BAD_REQUEST)
return Response({}, status=status.HTTP_201_CREATED)
return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
def destroy(self, request, collection_uid=None, uid=None):
# We can't have destroy because we need to get data from the user (in the body) such as hmac.
2020-02-20 11:56:16 +00:00
return Response(status=status.HTTP_405_METHOD_NOT_ALLOWED)
def update(self, request, collection_uid=None, uid=None):
return Response(status=status.HTTP_405_METHOD_NOT_ALLOWED)
2020-02-20 11:56:16 +00:00
def partial_update(self, request, collection_uid=None, uid=None):
return Response(status=status.HTTP_405_METHOD_NOT_ALLOWED)
def list(self, request, collection_uid=None):
queryset = self.get_queryset()
2020-04-16 14:14:03 +00:00
queryset, new_stoken = self.filter_by_stoken_and_limit(request, queryset)
serializer = self.serializer_class(queryset, context=self.get_serializer_context(), many=True)
ret = {
'data': serializer.data,
}
return Response(ret, headers={'X-EteSync-SToken': new_stoken})
2020-02-20 14:35:20 +00:00
@action_decorator(detail=True, methods=['GET'])
2020-02-20 20:41:39 +00:00
def revision(self, request, collection_uid=None, uid=None):
2020-04-16 13:43:21 +00:00
# FIXME: need pagination support
col = get_object_or_404(self.get_collection_queryset(Collection.objects), uid=collection_uid)
2020-02-20 14:35:20 +00:00
col_it = get_object_or_404(col.items, uid=uid)
2020-02-20 20:41:39 +00:00
serializer = CollectionItemRevisionSerializer(col_it.revisions.order_by('-id'), many=True)
ret = {
'data': serializer.data,
}
return Response(ret)
2020-02-20 14:35:20 +00:00
@action_decorator(detail=False, methods=['POST'])
def bulk_get(self, request, collection_uid=None):
queryset = self.get_queryset()
if isinstance(request.data, list):
queryset = queryset.filter(uid__in=request.data)
2020-04-16 14:14:03 +00:00
queryset, new_stoken = self.filter_by_stoken_and_limit(request, queryset)
serializer = self.get_serializer_class()(queryset, context=self.get_serializer_context(), many=True)
ret = {
'data': serializer.data,
}
return Response(ret, headers={'X-EteSync-SToken': new_stoken})
@action_decorator(detail=False, methods=['POST'])
def batch(self, request, collection_uid=None):
# FIXME: different to transaction slightly
return self.transaction(request, collection_uid)
@action_decorator(detail=False, methods=['POST'])
def transaction(self, request, collection_uid=None):
stoken = request.GET.get('stoken', None)
collection_object = get_object_or_404(self.get_collection_queryset(Collection.objects), uid=collection_uid)
if stoken is not None and stoken != collection_object.stoken:
content = {'code': 'stale_stoken', 'detail': 'Stoken is too old'}
return Response(content, status=status.HTTP_400_BAD_REQUEST)
items = request.data.get('items')
deps = request.data.get('deps', None)
# FIXME: It should just be one serializer
serializer = self.get_serializer_class()(data=items, context=self.get_serializer_context(), many=True)
2020-05-19 08:20:02 +00:00
deps_serializer = CollectionItemDepSerializer(data=deps, context=self.get_serializer_context(), many=True)
ser_valid = serializer.is_valid()
deps_ser_valid = (deps is None or deps_serializer.is_valid())
if ser_valid and deps_ser_valid:
try:
with transaction.atomic():
collections = serializer.save(collection=collection_object)
except IntegrityError:
2020-05-19 08:20:02 +00:00
# FIXME: should return the items with a bad token (including deps) so we don't have to fetch them after
content = {'code': 'integrity_error'}
return Response(content, status=status.HTTP_400_BAD_REQUEST)
ret = {
"data": [collection.stoken for collection in collections],
}
return Response(ret, status=status.HTTP_200_OK)
return Response(
{
"items": serializer.errors,
"deps": deps_serializer.errors if deps is not None else [],
},
status=status.HTTP_400_BAD_REQUEST)
2020-02-20 11:56:16 +00:00
class CollectionItemChunkViewSet(viewsets.ViewSet):
allowed_methods = ['GET', 'POST']
parser_classes = (parsers.MultiPartParser, )
2020-02-20 11:56:16 +00:00
authentication_classes = BaseViewSet.authentication_classes
permission_classes = BaseViewSet.permission_classes
serializer_class = CollectionItemChunkSerializer
2020-02-20 11:56:16 +00:00
lookup_field = 'uid'
def get_collection_queryset(self, queryset=Collection.objects):
user = self.request.user
return queryset.filter(members__user=user)
def create(self, request, collection_uid=None, collection_item_uid=None):
col = get_object_or_404(self.get_collection_queryset(), uid=collection_uid)
col_it = get_object_or_404(col.items, uid=collection_item_uid)
2020-02-20 11:56:16 +00:00
serializer = self.serializer_class(data=request.data)
2020-02-19 18:53:43 +00:00
if serializer.is_valid():
try:
serializer.save(item=col_it)
2020-02-19 18:53:43 +00:00
except IntegrityError:
content = {'code': 'integrity_error'}
return Response(content, status=status.HTTP_400_BAD_REQUEST)
return Response({}, status=status.HTTP_201_CREATED)
return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
@action_decorator(detail=True, methods=['GET'])
def download(self, request, collection_uid=None, collection_item_uid=None, uid=None):
import os
from django.views.static import serve
col = get_object_or_404(self.get_collection_queryset(), uid=collection_uid)
col_it = get_object_or_404(col.items, uid=collection_item_uid)
chunk = get_object_or_404(col_it.chunks, uid=uid)
filename = chunk.chunkFile.path
dirname = os.path.dirname(filename)
basename = os.path.basename(filename)
# FIXME: DO NOT USE! Use django-send file or etc instead.
return serve(request, basename, dirname)
2020-04-14 13:21:51 +00:00
2020-05-14 10:43:49 +00:00
class AuthenticationViewSet(viewsets.ViewSet):
allowed_methods = ['POST']
def get_encryption_key(self, salt):
key = nacl.hash.blake2b(settings.SECRET_KEY.encode(), encoder=nacl.encoding.RawEncoder)
2020-05-15 09:44:10 +00:00
return nacl.hash.blake2b(b'', key=key, salt=salt[:nacl.hash.BLAKE2B_SALTBYTES], person=b'etesync-auth',
encoder=nacl.encoding.RawEncoder)
2020-05-14 10:43:49 +00:00
def get_queryset(self):
return User.objects.all()
2020-05-14 14:19:18 +00:00
def login_response_data(self, user):
return {
'token': Token.objects.get_or_create(user=user)[0].key,
'user': UserSerializer(user).data,
}
2020-05-14 10:43:49 +00:00
def list(self, request):
return Response(status=status.HTTP_405_METHOD_NOT_ALLOWED)
@action_decorator(detail=False, methods=['POST'])
def signup(self, request):
serializer = AuthenticationSignupSerializer(data=request.data)
if serializer.is_valid():
2020-05-14 14:19:18 +00:00
user = serializer.save()
2020-05-14 10:43:49 +00:00
2020-05-14 14:19:18 +00:00
data = self.login_response_data(user)
return Response(data, status=status.HTTP_201_CREATED)
2020-05-14 10:43:49 +00:00
return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
def get_login_user(self, serializer):
username = serializer.validated_data.get('username')
email = serializer.validated_data.get('email')
if username:
kwargs = {User.USERNAME_FIELD: username}
user = get_object_or_404(self.get_queryset(), **kwargs)
elif email:
kwargs = {User.EMAIL_FIELD: email}
user = get_object_or_404(self.get_queryset(), **kwargs)
return user
@action_decorator(detail=False, methods=['POST'])
def login_challenge(self, request):
from datetime import datetime
serializer = AuthenticationLoginChallengeSerializer(data=request.data)
if serializer.is_valid():
user = self.get_login_user(serializer)
salt = user.userinfo.salt
enc_key = self.get_encryption_key(salt)
box = nacl.secret.SecretBox(enc_key)
challenge_data = {
"timestamp": int(datetime.now().timestamp()),
"userId": user.id,
}
challenge = box.encrypt(json.dumps(
challenge_data, separators=(',', ':')).encode(), encoder=nacl.encoding.RawEncoder)
ret = {
"salt": b64encode(salt),
"challenge": b64encode(challenge),
2020-05-14 14:19:18 +00:00
"version": user.userinfo.version,
2020-05-14 10:43:49 +00:00
}
return Response(ret, status=status.HTTP_200_OK)
return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
@action_decorator(detail=False, methods=['POST'])
def login(self, request):
from datetime import datetime
outer_serializer = AuthenticationLoginSerializer(data=request.data)
if outer_serializer.is_valid():
response_raw = outer_serializer.validated_data['response']
response = json.loads(response_raw.decode())
signature = outer_serializer.validated_data['signature']
serializer = AuthenticationLoginInnerSerializer(data=response, context={'host': request.get_host()})
if serializer.is_valid():
user = self.get_login_user(serializer)
host = serializer.validated_data['host']
challenge = serializer.validated_data['challenge']
salt = user.userinfo.salt
enc_key = self.get_encryption_key(salt)
box = nacl.secret.SecretBox(enc_key)
challenge_data = json.loads(box.decrypt(challenge).decode())
now = int(datetime.now().timestamp())
if now - challenge_data['timestamp'] > app_settings.CHALLENGE_VALID_SECONDS:
content = {'code': 'challenge_expired', 'detail': 'Login challange has expired'}
return Response(content, status=status.HTTP_400_BAD_REQUEST)
elif challenge_data['userId'] != user.id:
content = {'code': 'wrong_user', 'detail': 'This challenge is for the wrong user'}
return Response(content, status=status.HTTP_400_BAD_REQUEST)
elif not settings.DEBUG and host != request.get_host():
detail = 'Found wrong host name. Got: "{}" expected: "{}"'.format(host, request.get_host())
content = {'code': 'wrong_host', 'detail': detail}
return Response(content, status=status.HTTP_400_BAD_REQUEST)
verify_key = nacl.signing.VerifyKey(user.userinfo.pubkey, encoder=nacl.encoding.RawEncoder)
verify_key.verify(response_raw, signature)
2020-05-14 14:19:18 +00:00
data = self.login_response_data(user)
return Response(data, status=status.HTTP_200_OK)
2020-05-14 10:43:49 +00:00
return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
@action_decorator(detail=False, methods=['POST'])
def logout(self, request):
# FIXME: expire the token - we need better token handling - using knox? Something else?
return Response({}, status=status.HTTP_200_OK)
2020-05-14 10:43:49 +00:00
class TestAuthenticationViewSet(viewsets.ViewSet):
authentication_classes = BaseViewSet.authentication_classes
permission_classes = BaseViewSet.permission_classes
2020-04-14 13:21:51 +00:00
allowed_methods = ['POST']
def list(self, request):
return Response(status=status.HTTP_405_METHOD_NOT_ALLOWED)
@action_decorator(detail=False, methods=['POST'])
def reset(self, request, *args, **kwargs):
2020-04-14 13:21:51 +00:00
# Only run when in DEBUG mode! It's only used for tests
if not settings.DEBUG:
return HttpResponseBadRequest("Only allowed in debug mode.")
# Only allow local users, for extra safety
if not getattr(request.user, User.EMAIL_FIELD).endswith('@localhost'):
2020-04-14 13:21:51 +00:00
return HttpResponseBadRequest("Endpoint not allowed for user.")
# Delete all of the journal data for this user for a clear test env
request.user.collection_set.all().delete()
# FIXME: also delete chunk files!!!
return HttpResponse()