2018-01-11 12:10:27 +00:00
|
|
|
# -*- coding: utf-8 -*-
|
|
|
|
#
|
2019-05-20 04:30:55 +00:00
|
|
|
import time
|
2018-01-11 12:10:27 +00:00
|
|
|
from rest_framework import permissions
|
2018-11-23 02:25:35 +00:00
|
|
|
from django.conf import settings
|
2021-04-25 08:22:38 +00:00
|
|
|
from common.exceptions import MFAVerifyRequired
|
2018-07-20 10:42:01 +00:00
|
|
|
|
2018-01-11 12:10:27 +00:00
|
|
|
|
|
|
|
class IsValidUser(permissions.IsAuthenticated, permissions.BasePermission):
|
|
|
|
"""Allows access to valid user, is active and not expired"""
|
|
|
|
|
|
|
|
def has_permission(self, request, view):
|
|
|
|
return super(IsValidUser, self).has_permission(request, view) \
|
2021-10-20 09:56:59 +00:00
|
|
|
and request.user.is_valid
|
2018-01-11 12:10:27 +00:00
|
|
|
|
|
|
|
|
2022-02-17 12:13:31 +00:00
|
|
|
class OnlySuperUser(IsValidUser):
|
2018-07-25 03:21:12 +00:00
|
|
|
def has_permission(self, request, view):
|
2022-02-17 12:13:31 +00:00
|
|
|
return super().has_permission(request, view) \
|
2018-07-25 03:21:12 +00:00
|
|
|
and request.user.is_superuser
|
|
|
|
|
|
|
|
|
2018-11-23 02:25:35 +00:00
|
|
|
class WithBootstrapToken(permissions.BasePermission):
|
|
|
|
def has_permission(self, request, view):
|
|
|
|
authorization = request.META.get('HTTP_AUTHORIZATION', '')
|
|
|
|
if not authorization:
|
|
|
|
return False
|
|
|
|
request_bootstrap_token = authorization.split()[-1]
|
|
|
|
return settings.BOOTSTRAP_TOKEN == request_bootstrap_token
|
2019-06-19 02:47:26 +00:00
|
|
|
|
|
|
|
|
2019-06-24 12:39:45 +00:00
|
|
|
class NeedMFAVerify(permissions.BasePermission):
|
|
|
|
def has_permission(self, request, view):
|
2021-07-27 08:06:00 +00:00
|
|
|
if not settings.SECURITY_VIEW_AUTH_NEED_MFA:
|
|
|
|
return True
|
|
|
|
|
2019-06-24 12:39:45 +00:00
|
|
|
mfa_verify_time = request.session.get('MFA_VERIFY_TIME', 0)
|
|
|
|
if time.time() - mfa_verify_time < settings.SECURITY_MFA_VERIFY_TTL:
|
|
|
|
return True
|
2021-04-25 08:22:38 +00:00
|
|
|
raise MFAVerifyRequired()
|
2019-07-02 06:17:56 +00:00
|
|
|
|
|
|
|
|
2020-08-19 05:49:59 +00:00
|
|
|
class IsObjectOwner(IsValidUser):
|
|
|
|
def has_object_permission(self, request, view, obj):
|
|
|
|
return (super().has_object_permission(request, view, obj) and
|
|
|
|
request.user == getattr(obj, 'user', None))
|