authentik/passbook/core/auth/view.py

132 lines
5.8 KiB
Python
Raw Normal View History

2018-12-13 17:02:08 +00:00
"""passbook multi-factor authentication engine"""
from logging import getLogger
from django.contrib.auth import login
from django.contrib.auth.mixins import UserPassesTestMixin
2018-12-13 17:02:08 +00:00
from django.shortcuts import get_object_or_404, redirect, reverse
from django.views.generic import View
2018-12-13 17:02:08 +00:00
2019-02-16 08:52:37 +00:00
from passbook.core.models import Factor, User
from passbook.core.views.utils import PermissionDeniedView
from passbook.lib.utils.reflection import class_to_path, path_to_class
2018-12-13 17:02:08 +00:00
LOGGER = getLogger(__name__)
2019-02-16 08:52:37 +00:00
class AuthenticationView(UserPassesTestMixin, View):
2018-12-13 17:02:08 +00:00
"""Wizard-like Multi-factor authenticator"""
SESSION_FACTOR = 'passbook_factor'
SESSION_PENDING_FACTORS = 'passbook_pending_factors'
SESSION_PENDING_USER = 'passbook_pending_user'
SESSION_USER_BACKEND = 'passbook_user_backend'
2018-12-13 17:02:08 +00:00
pending_user = None
pending_factors = []
_current_factor = None
# Allow only not authenticated users to login
def test_func(self):
return self.request.user.is_authenticated is False
def handle_no_permission(self):
2019-02-16 08:52:37 +00:00
# Function from UserPassesTestMixin
if 'next' in self.request.GET:
return redirect(self.request.GET.get('next'))
return redirect(reverse('passbook_core:overview'))
2018-12-13 17:02:08 +00:00
def dispatch(self, request, *args, **kwargs):
# Extract pending user from session (only remember uid)
2019-02-16 08:52:37 +00:00
if AuthenticationView.SESSION_PENDING_USER in request.session:
2018-12-13 17:02:08 +00:00
self.pending_user = get_object_or_404(
2019-02-16 08:52:37 +00:00
User, id=self.request.session[AuthenticationView.SESSION_PENDING_USER])
2018-12-13 17:02:08 +00:00
else:
# No Pending user, redirect to login screen
return redirect(reverse('passbook_core:auth-login'))
2018-12-13 17:02:08 +00:00
# Write pending factors to session
2019-02-16 08:52:37 +00:00
if AuthenticationView.SESSION_PENDING_FACTORS in request.session:
self.pending_factors = request.session[AuthenticationView.SESSION_PENDING_FACTORS]
2018-12-13 17:02:08 +00:00
else:
2019-02-16 08:52:37 +00:00
# Get an initial list of factors which are currently enabled
2019-02-16 09:24:31 +00:00
# and apply to the current user. We check policies here and block the request
2019-02-16 08:52:37 +00:00
_all_factors = Factor.objects.filter(enabled=True)
self.pending_factors = []
for factor in _all_factors:
if factor.passes(self.pending_user):
2019-02-16 10:13:00 +00:00
self.pending_factors.append(factor.type)
# Read and instantiate factor from session
factor_class = None
2019-02-16 08:52:37 +00:00
if AuthenticationView.SESSION_FACTOR not in request.session:
2019-02-16 10:13:00 +00:00
# Case when no factors apply to user, return error denied
if not self.pending_factors:
return self.user_invalid()
factor_class = self.pending_factors[0]
else:
2019-02-16 08:52:37 +00:00
factor_class = request.session[AuthenticationView.SESSION_FACTOR]
# Instantiate Next Factor and pass request
factor = path_to_class(factor_class)
2018-12-13 17:02:08 +00:00
self._current_factor = factor(self)
2019-02-21 15:06:57 +00:00
self._current_factor.pending_user = self.pending_user
2018-12-13 17:02:08 +00:00
self._current_factor.request = request
return super().dispatch(request, *args, **kwargs)
def get(self, request, *args, **kwargs):
"""pass get request to current factor"""
LOGGER.debug("Passing GET to %s", class_to_path(self._current_factor.__class__))
2018-12-13 17:02:08 +00:00
return self._current_factor.get(request, *args, **kwargs)
def post(self, request, *args, **kwargs):
"""pass post request to current factor"""
LOGGER.debug("Passing POST to %s", class_to_path(self._current_factor.__class__))
2018-12-13 17:02:08 +00:00
return self._current_factor.post(request, *args, **kwargs)
def user_ok(self):
"""Redirect to next Factor"""
LOGGER.debug("Factor %s passed", class_to_path(self._current_factor.__class__))
# Remove passed factor from pending factors
if class_to_path(self._current_factor.__class__) in self.pending_factors:
self.pending_factors.remove(class_to_path(self._current_factor.__class__))
2018-12-13 17:02:08 +00:00
next_factor = None
if self.pending_factors:
next_factor = self.pending_factors.pop()
2019-02-16 08:52:37 +00:00
self.request.session[AuthenticationView.SESSION_PENDING_FACTORS] = \
2018-12-13 17:02:08 +00:00
self.pending_factors
2019-02-16 08:52:37 +00:00
self.request.session[AuthenticationView.SESSION_FACTOR] = next_factor
LOGGER.debug("Rendering Factor is %s", next_factor)
2019-02-21 15:06:57 +00:00
# return redirect(reverse('passbook_core:auth-process', kwargs={'factor': next_factor}))
return redirect(reverse('passbook_core:auth-process'))
2018-12-13 17:02:08 +00:00
# User passed all factors
LOGGER.debug("User passed all factors, logging in")
return self._user_passed()
2018-12-13 17:02:08 +00:00
def user_invalid(self):
"""Show error message, user cannot login.
This should only be shown if user authenticated successfully, but is disabled/locked/etc"""
2018-12-13 17:02:08 +00:00
LOGGER.debug("User invalid")
2019-02-21 15:06:57 +00:00
self._cleanup()
2019-02-16 08:52:37 +00:00
return redirect(reverse('passbook_core:auth-denied'))
def _user_passed(self):
"""User Successfully passed all factors"""
# user = authenticate(request=self.request, )
2019-02-16 08:52:37 +00:00
backend = self.request.session[AuthenticationView.SESSION_USER_BACKEND]
login(self.request, self.pending_user, backend=backend)
LOGGER.debug("Logged in user %s", self.pending_user)
# Cleanup
self._cleanup()
2019-02-16 10:13:00 +00:00
# TODO: ?next=...
return redirect(reverse('passbook_core:overview'))
def _cleanup(self):
"""Remove temporary data from session"""
session_keys = ['SESSION_FACTOR', 'SESSION_PENDING_FACTORS',
'SESSION_PENDING_USER', 'SESSION_USER_BACKEND', ]
for key in session_keys:
if key in self.request.session:
del self.request.session[key]
LOGGER.debug("Cleaned up sessions")
2019-02-16 09:54:15 +00:00
class FactorPermissionDeniedView(PermissionDeniedView):
"""User could not be authenticated"""