Implement changes for API authentication and Swagger UI (#541)
* initial token-based-api login handler * add token schema and validation * initial import of pyro3d api code * basic Swagger spec support * Merge in working copy of API/Device.pm * Fix some error handling for API/Device.pm * Break out utility functions into separate file, to allow other api portions to use * Add NodeIP support. * Add nodeip plugin to config * remove double define of "plugin:" (#448) disclaimer: i did not test this is any way, came across it when looking for something else. * only AuthZ header for api use, and alway regen key on login * use RFC7235 * workaround for Swagger plugin weird response body * do not autodiscover swagger routes * code formatting only * move api util to utils area * initial full swagger spec for nodeip search * add api user role and fix api auth failure response * update version of swagger-ui to 3.20.3 * add more openapi defs * fixes to SQL and api spec * clean up subs * improvements to login/logout for API * make api logout work * add openapi tags to group operations * allow api params to be generated from DBIC schema spec * remove API calls for nodes and devices * remove some poor assumptions about api calls * tidy up * remove DDP * make login and logout similar * example of api call being handled by ajax call * make the branch authonly
This commit is contained in:
@@ -8,7 +8,7 @@ use App::Netdisco::Util::Device 'delete_device';
|
||||
|
||||
register_worker({ phase => 'check' }, sub {
|
||||
return Status->error('Missing device (-d).')
|
||||
unless defined shift->device;
|
||||
unless shift->device;
|
||||
return Status->done('Delete is able to run');
|
||||
});
|
||||
|
||||
|
||||
32
lib/App/Netdisco/Worker/Plugin/SetUserToken.pm
Normal file
32
lib/App/Netdisco/Worker/Plugin/SetUserToken.pm
Normal file
@@ -0,0 +1,32 @@
|
||||
package App::Netdisco::Worker::Plugin::SetUserToken;
|
||||
|
||||
use Dancer ':syntax';
|
||||
use Dancer::Plugin::DBIC 'schema';
|
||||
|
||||
use App::Netdisco::Worker::Plugin;
|
||||
use aliased 'App::Netdisco::Worker::Status';
|
||||
|
||||
register_worker({ phase => 'check' }, sub {
|
||||
return Status->error('Missing user (-e).')
|
||||
unless shift->extra;
|
||||
return Status->done('SetUserToken is able to run');
|
||||
});
|
||||
|
||||
register_worker({ phase => 'main' }, sub {
|
||||
my ($job, $workerconf) = @_;
|
||||
my $username = $job->extra;
|
||||
|
||||
my $user = schema('netdisco')->resultset('User')
|
||||
->find({ username => $username });
|
||||
|
||||
return Status->error("No such user")
|
||||
unless $user and $user->in_storage;
|
||||
|
||||
$user->update({ token_from => time, token => \'md5(random()::text)' })
|
||||
->discard_changes();
|
||||
|
||||
return Status->done(
|
||||
sprintf 'Set token for user %s: %s', $username, $user->token);
|
||||
});
|
||||
|
||||
true;
|
||||
Reference in New Issue
Block a user