mirror of
https://github.com/chanzuckerberg/cellxgene.git
synced 2026-10-02 08:08:11 +08:00
add oauth authentication (#1681)
* add oauth authentication Add support for OAuth2. Change the interface to AuthTypeBase - better handling of config parameters - add a complete_setup function for additional setup steps Added a function wrapper to enforce authentication for the routes that require authenticaiton. * change fsspec requirement fsspec 0.8.0 breaks our tests it imports a module that is does not require.
This commit is contained in:
+23
-8
@@ -139,6 +139,18 @@ def get_data_adaptor(url_dataroot=None, dataset=None):
|
||||
return cache_manager.data_adaptor(dataset_key, datapath, config)
|
||||
|
||||
|
||||
def requires_authentication(func):
|
||||
@wraps(func)
|
||||
def wrapped_function(self, *args, **kwargs):
|
||||
auth = current_app.auth
|
||||
if auth.is_user_authenticated():
|
||||
return func(self, *args, **kwargs)
|
||||
else:
|
||||
return make_response("not authenticated", HTTPStatus.UNAUTHORIZED)
|
||||
|
||||
return wrapped_function
|
||||
|
||||
|
||||
def rest_get_data_adaptor(func):
|
||||
@wraps(func)
|
||||
def wrapped_function(self, dataset=None):
|
||||
@@ -164,11 +176,11 @@ def dataroot_test_index():
|
||||
server_config = config.server_config
|
||||
|
||||
auth = server_config.auth
|
||||
if auth.is_valid():
|
||||
if server_config.auth.is_authenticated():
|
||||
data += f"<p>Logged in as {auth.get_userid()} / {auth.get_username()}</p>"
|
||||
if auth.is_valid_authentication_type():
|
||||
if server_config.auth.is_user_authenticated():
|
||||
data += f"<p>Logged in as {auth.get_user_id()} / {auth.get_user_name()} / {auth.get_user_email()}</p>"
|
||||
if auth.requires_client_login():
|
||||
if server_config.auth.is_authenticated():
|
||||
if server_config.auth.is_user_authenticated():
|
||||
data += "<p><a href='/logout'>Logout</a></p>"
|
||||
else:
|
||||
data += "<p><a href='/login'>Login</a></p>"
|
||||
@@ -237,6 +249,7 @@ class AnnotationsObsAPI(DatasetResource):
|
||||
def get(self, data_adaptor):
|
||||
return common_rest.annotations_obs_get(request, data_adaptor)
|
||||
|
||||
@requires_authentication
|
||||
@cache_control(no_store=True)
|
||||
@rest_get_data_adaptor
|
||||
def put(self, data_adaptor):
|
||||
@@ -357,9 +370,11 @@ class Server:
|
||||
resources = get_api_resources(bp_api)
|
||||
self.app.register_blueprint(resources.blueprint)
|
||||
|
||||
self.app.auth = server_config.auth
|
||||
if self.app.auth.requires_client_login():
|
||||
self.app.auth.add_url_rules(self.app)
|
||||
|
||||
self.app.matrix_data_cache_manager = server_config.matrix_data_cache_manager
|
||||
self.app.app_config = app_config
|
||||
|
||||
auth = server_config.auth
|
||||
self.app.auth = auth
|
||||
if auth.requires_client_login():
|
||||
auth.add_url_rules(self.app)
|
||||
auth.complete_setup(self.app)
|
||||
|
||||
Reference in New Issue
Block a user