backend.py 3.2 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192
  1. #!/usr/bin/env python
  2. # Licensed to Cloudera, Inc. under one
  3. # or more contributor license agreements. See the NOTICE file
  4. # distributed with this work for additional information
  5. # regarding copyright ownership. Cloudera, Inc. licenses this file
  6. # to you under the Apache License, Version 2.0 (the
  7. # "License"); you may not use this file except in compliance
  8. # with the License. You may obtain a copy of the License at
  9. #
  10. # http://www.apache.org/licenses/LICENSE-2.0
  11. #
  12. # Unless required by applicable law or agreed to in writing, software
  13. # distributed under the License is distributed on an "AS IS" BASIS,
  14. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  15. # See the License for the specific language governing permissions and
  16. # limitations under the License.
  17. """
  18. See desktop/auth/backend.py
  19. """
  20. from __future__ import absolute_import
  21. import logging
  22. import sys
  23. from django.contrib.auth import logout as auth_logout
  24. from django.contrib.auth.models import User
  25. from django_openid_auth.auth import OpenIDBackend as _OpenIDBackend
  26. from desktop.auth.backend import rewrite_user
  27. from useradmin.models import get_profile, get_default_user_group, UserProfile
  28. from libopenid import metrics
  29. LOG = logging.getLogger(__name__)
  30. class OpenIDBackend(_OpenIDBackend):
  31. """
  32. Wrapper around openid backend.
  33. """
  34. @metrics.openid_authentication_time
  35. def authenticate(self, *args, **kwargs):
  36. return super(OpenIDBackend, self).authenticate(*args, **kwargs)
  37. def update_user_details(self, user, details, openid_response):
  38. # Do this check up here, because the auth call creates a django user upon first login per user
  39. is_super = False
  40. if not UserProfile.objects.filter(creation_method=str(UserProfile.CreationMethod.EXTERNAL)).exists():
  41. # If there are no external users already in the system, the first one will
  42. # become a superuser
  43. is_super = True
  44. elif User.objects.filter(username=user.username).exists():
  45. # If the user already exists, we shouldn't change its superuser
  46. # privileges. However, if there's a naming conflict with a non-external
  47. # user, we should do the safe thing and turn off superuser privs.
  48. user = User.objects.get(username=user.username)
  49. existing_profile = get_profile(user)
  50. if existing_profile.creation_method == str(UserProfile.CreationMethod.EXTERNAL):
  51. is_super = user.is_superuser
  52. super(OpenIDBackend, self).update_user_details(user, details, openid_response)
  53. if user is not None and user.is_active:
  54. profile = get_profile(user)
  55. profile.creation_method = UserProfile.CreationMethod.EXTERNAL
  56. profile.save()
  57. user.is_superuser = is_super
  58. user = rewrite_user(user)
  59. default_group = get_default_user_group()
  60. if default_group is not None:
  61. user.groups.add(default_group)
  62. user.save()
  63. def get_user(self, user_id):
  64. user = super(OpenIDBackend, self).get_user(user_id)
  65. user = rewrite_user(user)
  66. return user
  67. @classmethod
  68. def manages_passwords_externally(cls):
  69. return True
  70. @classmethod
  71. def is_first_login_ever(cls):
  72. """ Return true if no external user has ever logged in to Desktop yet. """
  73. return not UserProfile.objects.filter(creation_method=str(UserProfile.CreationMethod.EXTERNAL)).exists()