mirror of
https://gitlab.com/allianceauth/allianceauth.git
synced 2025-07-11 13:30:17 +02:00
* Port to Django 1.10 Initial migrations for current states of all models. Requires faking to retain data. Removed all references to render_to_response, replacing with render shortcut. Same for HttpResponseRedirect to render shortcut. Corrected notification signal import to wait for app registry to finish loading. * Correct typos from render conversion * Modify models to suppress Django field warnings * Script for automatic database conversion - fakes initial migrations to preserve data Include LOGIN_URL setting * Correct context processor import typo * Removed pathfinder support. Current pathfinder versions require SSO, not APIs added to database. Conditionally load additional database definitions only if services are enabled. Prevents errors when running auth without creating all possible databases. * Condense context processors * Include Django 1.10 installation in migrate script Remove syncdb/evolve, replace with migrate for update script * Replaced member/blue perms with user state system Removed sigtracker Initial migrations for default perms and groups Removed perm bootstrapping on first run * Clean up services list * Remove fleet fittings page * Provide action feedback via django messaging Display unread notification count Correct left navbar alignment * Stop storing service passwords. Provide them one time upon activation or reset. Closes #177 * Add group sync buttons to admin site Allow searcing of AuthServicesInfo models Display user main character * Correct button CSS to remove underlines on hover * Added bulk actions to notifications Altered notification default ordering * Centralize API key validation. Remove unused error count on API key model. Restructure API key refresh task to queue all keys per user and await completion. Closes #350 * Example configuration files for supervisor. Copy to /etc/supervisor/conf.d and restart to take effect. Closes #521 Closes #266 * Pre-save receiver for member/blue state switching Removed is_blue field Added link to admin site * Remove all hardcoded URLs from views and templates Correct missing render arguments Closes #540 * Correct celeryd process directory * Migration to automatically set user states. Runs instead of waiting for next API refresh cycle. Should make the transition much easier. * Verify service accounts accessible to member state * Restructure project to remove unnecessary apps. (celerytask, util, portal, registraion apps) Added workarounds for python 3 compatibility. * Correct python2 compatibility * Check services against state being changed to * Python3 compatibility fixes * Relocate x2bool py3 fix * SSO integration for logging in to existing accounts. * Add missing url names for fleetup reverse * Sanitize groupnames before syncing. * Correct trailing slash preventing url resolution * Alter group name sanitization to allow periods and hyphens * Correct state check on pre_save model for corp/alliance group assignment * Remove sigtracker table from old dbs to allow user deletion * Include missing celery configuration * Teamspeak error handling * Prevent celery worker deadlock on async group result wait * Correct active navbar links for translated urls. Correct corp status url resolution for some links. Remove DiscordAuthToken model.
103 lines
3.9 KiB
Python
103 lines
3.9 KiB
Python
from __future__ import unicode_literals
|
|
import logging
|
|
import os
|
|
from django.db import connections
|
|
from passlib.hash import bcrypt
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
|
|
class Ips4Manager:
|
|
SQL_ADD_USER = r"INSERT INTO core_members (name, email, members_pass_hash, members_pass_salt, " \
|
|
r"member_group_id) VALUES (%s, %s, %s, %s, %s)"
|
|
SQL_GET_ID = r"SELECT member_id FROM core_members WHERE name = %s"
|
|
SQL_UPDATE_PASSWORD = r"UPDATE core_members SET members_pass_hash = %s, members_pass_salt = %s WHERE name = %s"
|
|
SQL_DEL_USER = r"DELETE FROM core_members WHERE member_id = %s"
|
|
|
|
MEMBER_GROUP_ID = 3
|
|
|
|
@staticmethod
|
|
def add_user(username, email):
|
|
logger.debug("Adding new IPS4 user %s" % username)
|
|
plain_password = Ips4Manager.__generate_random_pass()
|
|
hash = bcrypt.encrypt(plain_password, rounds=13)
|
|
hash_result = hash
|
|
rounds_striped = hash_result.strip('$2a$13$')
|
|
salt = rounds_striped[:22]
|
|
group = Ips4Manager.MEMBER_GROUP_ID
|
|
cursor = connections['ips4'].cursor()
|
|
cursor.execute(Ips4Manager.SQL_ADD_USER, [username, email, hash, salt, group])
|
|
member_id = Ips4Manager.get_user_id(username)
|
|
return username, plain_password, member_id
|
|
|
|
@staticmethod
|
|
def get_user_id(username):
|
|
cursor = connections['ips4'].cursor()
|
|
cursor.execute(Ips4Manager.SQL_GET_ID, [username])
|
|
row = cursor.fetchone()
|
|
if row is not None:
|
|
logger.debug("Got user id %s for username %s" % (row[0], username))
|
|
return row[0]
|
|
else:
|
|
logger.error("username %s not found. Unable to determine id." % username)
|
|
return None
|
|
|
|
@staticmethod
|
|
def __generate_random_pass():
|
|
return os.urandom(8).encode('hex')
|
|
|
|
@staticmethod
|
|
def delete_user(id):
|
|
logger.debug("Deleting IPS4 user id %s" % id)
|
|
try:
|
|
cursor = connections['ips4'].cursor()
|
|
cursor.execute(Ips4Manager.SQL_DEL_USER, [id])
|
|
logger.info("Deleted IPS4 user %s" % id)
|
|
return True
|
|
except:
|
|
logger.exception("Failed to delete IPS4 user id %s" % id)
|
|
return False
|
|
|
|
@staticmethod
|
|
def update_user_password(username):
|
|
logger.debug("Updating IPS4 user id %s password" % id)
|
|
if Ips4Manager.check_user(username):
|
|
plain_password = Ips4Manager.__generate_random_pass()
|
|
hash = bcrypt.encrypt(plain_password, rounds=13)
|
|
hash_result = hash
|
|
rounds_striped = hash_result.strip('$2a$13$')
|
|
salt = rounds_striped[:22]
|
|
cursor = connections['ips4'].cursor()
|
|
cursor.execute(Ips4Manager.SQL_UPDATE_PASSWORD, [hash, salt, username])
|
|
return plain_password
|
|
else:
|
|
logger.error("Unable to update ips4 user %s password" % username)
|
|
return ""
|
|
|
|
@staticmethod
|
|
def check_user(username):
|
|
logger.debug("Checking IPS4 username %s" % username)
|
|
cursor = connections['ips4'].cursor()
|
|
cursor.execute(Ips4Manager.SQL_GET_ID, [username])
|
|
row = cursor.fetchone()
|
|
if row:
|
|
logger.debug("Found user %s on IPS4" % username)
|
|
return True
|
|
logger.debug("User %s not found on IPS4" % username)
|
|
return False
|
|
|
|
@staticmethod
|
|
def update_custom_password(username, plain_password):
|
|
logger.debug("Updating IPS4 user id %s password" % id)
|
|
if Ips4Manager.check_user(username):
|
|
hash = bcrypt.encrypt(plain_password, rounds=13)
|
|
hash_result = hash
|
|
rounds_striped = hash_result.strip('$2a$13$')
|
|
salt = rounds_striped[:22]
|
|
cursor = connections['ips4'].cursor()
|
|
cursor.execute(Ips4Manager.SQL_UPDATE_PASSWORD, [hash, salt, username])
|
|
return plain_password
|
|
else:
|
|
logger.error("Unable to update ips4 user %s password" % username)
|
|
return ""
|