util.py 3.36 KB
Newer Older
Antony Chazapis's avatar
Antony Chazapis committed
1
# Copyright 2011-2012 GRNET S.A. All rights reserved.
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
# 
# Redistribution and use in source and binary forms, with or
# without modification, are permitted provided that the following
# conditions are met:
# 
#   1. Redistributions of source code must retain the above
#      copyright notice, this list of conditions and the following
#      disclaimer.
# 
#   2. Redistributions in binary form must reproduce the above
#      copyright notice, this list of conditions and the following
#      disclaimer in the documentation and/or other materials
#      provided with the distribution.
# 
# THIS SOFTWARE IS PROVIDED BY GRNET S.A. ``AS IS'' AND ANY EXPRESS
# OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
# WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
# PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL GRNET S.A OR
# CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
# SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
# LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
# USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
# AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
# LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN
# ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
# POSSIBILITY OF SUCH DAMAGE.
# 
# The views and conclusions contained in the software and
# documentation are those of the authors and should not be
# interpreted as representing official policies, either expressed
# or implied, of GRNET S.A.

import datetime

from urlparse import urlsplit, urlunsplit
from urllib import quote

from django.http import HttpResponse
from django.utils.http import urlencode
from django.core.urlresolvers import reverse
Sofia Papagiannaki's avatar
Sofia Papagiannaki committed
42
from django.conf import settings
Sofia Papagiannaki's avatar
Sofia Papagiannaki committed
43
from django.contrib.auth import login
44

Sofia Papagiannaki's avatar
Sofia Papagiannaki committed
45
def prepare_response(request, user, next='', renew=False, skip_login=False):
46
47
48
49
50
51
    """Return the unique username and the token
       as 'X-Auth-User' and 'X-Auth-Token' headers,
       or redirect to the URL provided in 'next'
       with the 'user' and 'token' as parameters.
       
       Reissue the token even if it has not yet
52
53
       expired, if the 'renew' parameter is present
       or user has not a valid token.
54
55
    """
    
56
57
58
    renew = renew or (not user.auth_token)
    renew = renew or (user.auth_token_expires and user.auth_token_expires < datetime.datetime.now())
    if renew:
59
60
        user.renew_token()
        user.save()
61
    
62
63
64
    if next:
        # TODO: Avoid redirect loops.
        parts = list(urlsplit(next))
Sofia Papagiannaki's avatar
Sofia Papagiannaki committed
65
        if not parts[1] or (parts[1] and request.get_host() != parts[1]):
66
            parts[3] = urlencode({'user': user.username, 'token': user.auth_token})
67
68
            next = urlunsplit(parts)
    
Sofia Papagiannaki's avatar
Sofia Papagiannaki committed
69
    if settings.FORCE_PROFILE_UPDATE and not user.is_verified and not user.is_superuser:
70
71
72
        params = ''
        if next:
            params = '?' + urlencode({'next': next})
Sofia Papagiannaki's avatar
Sofia Papagiannaki committed
73
74
75
        next = reverse('astakos.im.views.edit_profile') + params
    
    # user login
Sofia Papagiannaki's avatar
Sofia Papagiannaki committed
76
77
    if not skip_login:
        login(request, user)
78
79
80
    
    response = HttpResponse()
    if not next:
Sofia Papagiannaki's avatar
Sofia Papagiannaki committed
81
        response['X-Auth-User'] = user.username
82
83
        response['X-Auth-Token'] = user.auth_token
        response.content = user.username + '\n' + user.auth_token + '\n'
84
85
86
87
88
        response.status_code = 200
    else:
        response['Location'] = next
        response.status_code = 302
    return response