Files
notifications-admin/app/__init__.py
T

668 lines
22 KiB
Python
Raw Normal View History

2015-11-24 09:40:14 +00:00
import os
import urllib
from datetime import datetime, timedelta, timezone
2016-10-19 11:54:51 +01:00
from time import monotonic
import itertools
2016-10-19 11:54:51 +01:00
import ago
from itsdangerous import BadSignature
from flask import (
session,
render_template,
make_response,
current_app,
request,
g,
url_for,
flash
2017-10-18 14:51:26 +01:00
)
2015-11-24 09:40:14 +00:00
from flask._compat import string_types
2017-05-04 11:28:45 +01:00
from flask.globals import _lookup_req_object, _request_ctx_stack
from flask_login import LoginManager, current_user
from flask_wtf import CSRFProtect
2017-07-26 11:01:24 +01:00
from flask_wtf.csrf import CSRFError
2016-04-21 09:30:33 +01:00
from functools import partial
from notifications_python_client.errors import HTTPError
2017-11-14 14:38:26 +00:00
from notifications_utils import logging, request_helper, formatters
from notifications_utils.clients.antivirus.antivirus_client import AntivirusClient
2018-04-24 17:37:15 +01:00
from notifications_utils.clients.zendesk.zendesk_client import ZendeskClient
2016-12-01 17:21:06 +00:00
from notifications_utils.clients.statsd.statsd_client import StatsdClient
2017-06-06 12:57:55 +01:00
from notifications_utils.recipients import (
validate_phone_number,
InvalidPhoneError,
format_phone_number_human_readable,
)
2017-03-27 16:39:46 +01:00
from notifications_utils.formatters import formatted_list
2018-05-25 10:18:39 +01:00
from notifications_utils.sanitise_text import SanitiseASCII
2018-11-26 14:43:42 +00:00
from notifications_utils.timezones import utc_string_to_aware_gmt_datetime
2018-06-22 17:36:58 +01:00
from werkzeug.exceptions import abort, HTTPException as WerkzeugHTTPException
2016-04-21 09:30:33 +01:00
from werkzeug.local import LocalProxy
2017-10-18 14:51:26 +01:00
from app import proxy_fix
2017-11-06 13:07:21 +00:00
from app.config import configs
2018-10-26 15:39:32 +01:00
from app.asset_fingerprinter import asset_fingerprinter
2018-10-26 15:58:44 +01:00
from app.models.service import Service
from app.models.user import AnonymousUser
2018-06-12 16:17:20 +01:00
from app.navigation import (
CaseworkNavigation,
HeaderNavigation,
MainNavigation,
OrgNavigation
)
2018-10-26 15:39:32 +01:00
from app.notify_client.service_api_client import service_api_client
from app.notify_client.api_key_api_client import api_key_api_client
from app.notify_client.invite_api_client import invite_api_client
from app.notify_client.job_api_client import job_api_client
from app.notify_client.notification_api_client import notification_api_client
from app.notify_client.status_api_client import status_api_client
from app.notify_client.template_statistics_api_client import template_statistics_client
from app.notify_client.user_api_client import user_api_client
from app.notify_client.events_api_client import events_api_client
from app.notify_client.provider_client import provider_client
from app.notify_client.email_branding_client import email_branding_client
from app.notify_client.organisations_api_client import organisations_client
from app.notify_client.org_invite_api_client import org_invite_api_client
from app.notify_client.letter_jobs_client import letter_jobs_client
from app.notify_client.inbound_number_client import inbound_number_client
from app.notify_client.billing_api_client import billing_api_client
from app.notify_client.complaint_api_client import complaint_api_client
from app.notify_client.platform_stats_api_client import platform_stats_api_client
2018-11-01 15:33:09 +00:00
from app.notify_client.template_folder_api_client import template_folder_api_client
2017-11-06 13:07:21 +00:00
from app.commands import setup_commands
from app.utils import get_logo_cdn_domain, id_safe
login_manager = LoginManager()
csrf = CSRFProtect()
antivirus_client = AntivirusClient()
statsd_client = StatsdClient()
zendesk_client = ZendeskClient()
# The current service attached to the request stack.
def _get_current_service():
return _lookup_req_object('service')
current_service = LocalProxy(_get_current_service)
2018-02-13 14:49:03 +00:00
# The current organisation attached to the request stack.
current_organisation = LocalProxy(partial(_lookup_req_object, 'organisation'))
2015-11-20 16:22:44 +00:00
navigation = {
2018-06-12 16:17:20 +01:00
'casework_navigation': CaseworkNavigation(),
'main_navigation': MainNavigation(),
'header_navigation': HeaderNavigation(),
'org_navigation': OrgNavigation(),
}
2018-04-25 10:24:32 +01:00
2018-02-14 13:08:44 +00:00
2017-11-06 13:07:21 +00:00
def create_app(application):
setup_commands(application)
2015-11-20 16:22:44 +00:00
2017-01-09 19:14:04 +00:00
notify_environment = os.environ['NOTIFY_ENVIRONMENT']
2016-12-08 16:50:37 +00:00
application.config.from_object(configs[notify_environment])
2018-11-29 13:06:10 +00:00
asset_fingerprinter._asset_root = application.config['ASSET_PATH']
init_app(application)
antivirus_client.init_app(application)
2016-12-01 17:21:06 +00:00
statsd_client.init_app(application)
2018-04-24 17:37:15 +01:00
zendesk_client.init_app(application)
2016-12-01 17:21:06 +00:00
logging.init_app(application, statsd_client)
csrf.init_app(application)
2017-11-14 14:38:26 +00:00
request_helper.init_app(application)
service_api_client.init_app(application)
2016-01-19 22:47:42 +00:00
user_api_client.init_app(application)
2016-01-20 17:32:55 +00:00
api_key_api_client.init_app(application)
2016-01-29 10:27:23 +00:00
job_api_client.init_app(application)
2016-03-02 15:37:35 +00:00
notification_api_client.init_app(application)
2016-01-29 14:41:07 +00:00
status_api_client.init_app(application)
invite_api_client.init_app(application)
2018-02-19 16:53:29 +00:00
org_invite_api_client.init_app(application)
template_statistics_client.init_app(application)
events_api_client.init_app(application)
2016-05-11 09:43:55 +01:00
provider_client.init_app(application)
2018-02-07 10:30:49 +00:00
email_branding_client.init_app(application)
2018-02-08 12:18:37 +00:00
organisations_client.init_app(application)
2017-04-11 10:59:50 +01:00
letter_jobs_client.init_app(application)
2017-08-08 10:24:54 +01:00
inbound_number_client.init_app(application)
billing_api_client.init_app(application)
complaint_api_client.init_app(application)
2018-06-28 10:28:57 +01:00
platform_stats_api_client.init_app(application)
2018-11-01 15:33:09 +00:00
template_folder_api_client.init_app(application)
2016-01-15 15:15:35 +00:00
login_manager.init_app(application)
2016-01-06 17:17:02 +00:00
login_manager.login_view = 'main.sign_in'
login_manager.login_message_category = 'default'
2016-12-14 14:07:08 +00:00
login_manager.session_protection = None
2017-02-17 14:06:09 +00:00
login_manager.anonymous_user = AnonymousUser
2015-11-24 09:40:14 +00:00
2015-11-20 16:33:11 +00:00
from app.main import main as main_blueprint
2015-11-20 16:22:44 +00:00
application.register_blueprint(main_blueprint)
2016-01-11 14:54:23 +00:00
from .status import status as status_blueprint
application.register_blueprint(status_blueprint)
2015-11-30 14:32:58 +00:00
proxy_fix.init_app(application)
2017-11-06 13:07:21 +00:00
add_template_filters(application)
2016-04-21 09:30:33 +01:00
2016-01-07 15:48:29 +00:00
register_errorhandlers(application)
2016-01-07 13:58:38 +00:00
setup_event_handlers()
2015-11-24 09:40:14 +00:00
def init_app(application):
2017-11-06 13:07:21 +00:00
application.after_request(useful_headers_after_request)
application.after_request(save_service_or_org_after_request)
2017-11-06 13:07:21 +00:00
application.before_request(load_service_before_request)
application.before_request(load_organisation_before_request)
application.before_request(request_helper.check_proxy_header_before_request)
2017-11-06 13:07:21 +00:00
@application.before_request
def make_session_permanent():
# this is dumb. You'd think, given that there's `config['PERMANENT_SESSION_LIFETIME']`, that you'd enable
# permanent sessions in the config too - but no, you have to declare it for each request.
# https://stackoverflow.com/questions/34118093/flask-permanent-session-where-to-define-them
# session.permanent is also, helpfully, a way of saying that the session isn't permanent - in that, it will
# expire on its own, as opposed to being controlled by the browser's session. Because session is a proxy, it's
# only accessible from within a request context, so we need to set this before every request :rolls_eyes:
session.permanent = True
2017-11-06 13:07:21 +00:00
@application.context_processor
def _attach_current_service():
return {'current_service': current_service}
2018-02-13 14:49:03 +00:00
@application.context_processor
def _attach_current_organisation():
return {'current_org': current_organisation}
@application.context_processor
def _attach_current_user():
return{'current_user': current_user}
2018-04-24 12:48:05 +01:00
@application.context_processor
def _nav_selected():
return navigation
2018-04-24 12:48:05 +01:00
@application.before_request
def record_start_time():
g.start = monotonic()
2016-12-01 17:21:06 +00:00
g.endpoint = request.endpoint
@application.context_processor
2015-12-15 08:20:25 +00:00
def inject_global_template_variables():
2016-02-01 14:46:12 +00:00
return {
'asset_path': application.config['ASSET_PATH'],
'header_colour': application.config['HEADER_COLOUR'],
2016-02-10 15:47:00 +00:00
'asset_url': asset_fingerprinter.get_url
2016-02-01 14:46:12 +00:00
}
2015-12-15 08:20:25 +00:00
2015-11-24 09:40:14 +00:00
def convert_to_boolean(value):
if isinstance(value, string_types):
if value.lower() in ['t', 'true', 'on', 'yes', '1']:
return True
elif value.lower() in ['f', 'false', 'off', 'no', '0']:
return False
return value
def linkable_name(value):
return urllib.parse.quote_plus(value)
2016-05-17 14:00:40 +01:00
def format_datetime(date):
2016-08-26 08:06:28 +01:00
return '{} at {}'.format(
format_date(date),
format_time(date)
)
def format_datetime_24h(date):
return '{} at {}'.format(
format_date(date),
format_time_24h(date),
2016-08-26 08:06:28 +01:00
)
2016-01-21 12:28:05 +00:00
def format_datetime_normal(date):
2016-08-26 08:06:28 +01:00
return '{} at {}'.format(
format_date_normal(date),
format_time(date)
)
def format_datetime_short(date):
2016-08-26 08:06:28 +01:00
return '{} at {}'.format(
format_date_short(date),
format_time(date)
)
def format_datetime_relative(date):
return '{} at {}'.format(
get_human_day(date),
format_time(date)
)
def format_datetime_numeric(date):
return '{} {}'.format(
format_date_numeric(date),
format_time_24h(date),
)
def format_date_numeric(date):
2018-11-26 14:43:42 +00:00
return utc_string_to_aware_gmt_datetime(date).strftime('%Y-%m-%d')
def format_time_24h(date):
2018-11-26 14:43:42 +00:00
return utc_string_to_aware_gmt_datetime(date).strftime('%H:%M')
def get_human_day(time):
2017-05-24 13:19:31 +01:00
# Add 1 minute to transform 00:00 into midnight today instead of midnight tomorrow
2018-11-26 14:43:42 +00:00
date = (utc_string_to_aware_gmt_datetime(time) - timedelta(minutes=1)).date()
if date == (datetime.utcnow() + timedelta(days=1)).date():
return 'tomorrow'
if date == datetime.utcnow().date():
2017-05-24 13:19:31 +01:00
return 'today'
if date == (datetime.utcnow() - timedelta(days=1)).date():
2017-05-24 13:19:31 +01:00
return 'yesterday'
return _format_datetime_short(date)
2016-03-02 16:15:15 +00:00
def format_time(date):
2016-08-26 08:06:28 +01:00
return {
'12:00AM': 'Midnight',
'12:00PM': 'Midday'
}.get(
2018-11-26 14:43:42 +00:00
utc_string_to_aware_gmt_datetime(date).strftime('%-I:%M%p'),
utc_string_to_aware_gmt_datetime(date).strftime('%-I:%M%p')
2016-08-26 08:06:28 +01:00
).lower()
2016-03-02 16:15:15 +00:00
def format_date(date):
2018-11-26 14:43:42 +00:00
return utc_string_to_aware_gmt_datetime(date).strftime('%A %d %B %Y')
def format_date_normal(date):
2018-11-26 14:43:42 +00:00
return utc_string_to_aware_gmt_datetime(date).strftime('%d %B %Y').lstrip('0')
def format_date_short(date):
2018-11-26 14:43:42 +00:00
return _format_datetime_short(utc_string_to_aware_gmt_datetime(date))
def _format_datetime_short(datetime):
return datetime.strftime('%d %B').lstrip('0')
def format_delta(date):
2017-04-06 11:03:05 +01:00
delta = (
datetime.now(timezone.utc)
) - (
2018-11-26 14:43:42 +00:00
utc_string_to_aware_gmt_datetime(date)
2017-04-06 11:03:05 +01:00
)
if delta < timedelta(seconds=30):
return "just now"
2017-06-26 15:41:08 +01:00
if delta < timedelta(seconds=60):
return "in the last minute"
return ago.human(
2017-04-06 11:03:05 +01:00
delta,
future_tense='{} from now', # No-one should ever see this
past_tense='{} ago',
precision=1
)
2016-02-17 15:49:07 +00:00
def valid_phone_number(phone_number):
try:
validate_phone_number(phone_number)
return True
except InvalidPhoneError:
return False
def format_notification_type(notification_type):
return {
'email': 'Email',
'sms': 'SMS',
'letter': 'Letter'
}[notification_type]
2016-06-07 16:35:03 +01:00
def format_notification_status(status, template_type):
return {
'email': {
'failed': 'Failed',
'technical-failure': 'Technical failure',
'temporary-failure': 'Inbox not accepting messages right now',
'permanent-failure': 'Email address doesnt exist',
2016-06-07 16:35:03 +01:00
'delivered': 'Delivered',
'sending': 'Sending',
2017-04-27 16:02:49 +01:00
'created': 'Sending',
'sent': 'Delivered'
2016-06-07 16:35:03 +01:00
},
'sms': {
'failed': 'Failed',
'technical-failure': 'Technical failure',
'temporary-failure': 'Phone not accepting messages right now',
'permanent-failure': 'Phone number doesnt exist',
2016-06-07 16:35:03 +01:00
'delivered': 'Delivered',
'sending': 'Sending',
2017-04-27 16:02:49 +01:00
'created': 'Sending',
2018-09-11 13:46:33 +01:00
'pending': 'Sending',
2017-04-27 16:02:49 +01:00
'sent': 'Sent internationally'
},
'letter': {
'failed': '',
'technical-failure': 'Technical failure',
'temporary-failure': '',
'permanent-failure': '',
'delivered': '',
'received': '',
'accepted': '',
'sending': '',
'created': '',
'sent': '',
'pending-virus-check': '',
'virus-scan-failed': 'Virus detected',
'returned-letter': '',
'cancelled': '',
'validation-failed': 'Validation failed',
2016-06-07 16:35:03 +01:00
}
}[template_type].get(status, status)
2016-09-09 15:57:05 +01:00
def format_notification_status_as_time(status, created, updated):
2018-09-11 13:46:33 +01:00
return dict.fromkeys(
{'created', 'pending', 'sending'}, ' since {}'.format(created)
).get(status, updated)
def format_notification_status_as_field_status(status, notification_type):
2016-06-09 10:15:37 +01:00
return {
'letter': {
'failed': 'error',
'technical-failure': 'error',
'temporary-failure': 'error',
'permanent-failure': 'error',
'delivered': None,
'sent': None,
'sending': None,
'created': None,
'accepted': None,
'pending-virus-check': None,
'virus-scan-failed': 'error',
'returned-letter': None,
2018-12-04 15:07:20 +00:00
'cancelled': 'error',
}
}.get(
notification_type,
{
'failed': 'error',
'technical-failure': 'error',
'temporary-failure': 'error',
'permanent-failure': 'error',
'delivered': None,
'sent': None,
'sending': 'default',
2018-09-11 13:46:33 +01:00
'created': 'default',
'pending': 'default',
}
).get(status, 'error')
2016-06-09 10:15:37 +01:00
2018-10-11 10:54:39 +01:00
def format_notification_status_as_url(status, notification_type):
if notification_type == 'letter':
return None
2017-08-30 15:28:55 +01:00
url = partial(url_for, "main.using_notify")
return {
'technical-failure': url(_anchor='technical-failure'),
'temporary-failure': url(_anchor='not-accepting-messages'),
'permanent-failure': url(_anchor='does-not-exist')
}.get(status)
2017-03-02 15:56:28 +00:00
def nl2br(value):
return formatters.nl2br(value) if value else ''
2016-03-30 09:58:10 +01:00
@login_manager.user_loader
def load_user(user_id):
return user_api_client.get_user(user_id)
def load_service_before_request():
if '/static/' in request.url:
2017-05-04 11:28:45 +01:00
_request_ctx_stack.top.service = None
return
2016-04-13 16:19:34 +01:00
if _request_ctx_stack.top is not None:
_request_ctx_stack.top.service = None
if request.view_args:
service_id = request.view_args.get('service_id', session.get('service_id'))
else:
service_id = session.get('service_id')
if service_id:
try:
_request_ctx_stack.top.service = Service(
service_api_client.get_service(service_id)['data']
)
except HTTPError as exc:
# if service id isn't real, then 404 rather than 500ing later because we expect service to be set
if exc.status_code == 404:
abort(404)
else:
raise
def load_organisation_before_request():
if '/static/' in request.url:
_request_ctx_stack.top.organisation = None
return
if _request_ctx_stack.top is not None:
_request_ctx_stack.top.organisation = None
if request.view_args:
org_id = request.view_args.get('org_id')
if org_id:
try:
_request_ctx_stack.top.organisation = organisations_client.get_organisation(org_id)
except HTTPError as exc:
# if org id isn't real, then 404 rather than 500ing later because we expect org to be set
if exc.status_code == 404:
abort(404)
else:
raise
def save_service_or_org_after_request(response):
# Only save the current session if the request is 200
service_id = request.view_args.get('service_id', None) if request.view_args else None
organisation_id = request.view_args.get('org_id', None) if request.view_args else None
if response.status_code == 200:
if service_id:
session['service_id'] = service_id
session['organisation_id'] = None
elif organisation_id:
session['service_id'] = None
session['organisation_id'] = organisation_id
return response
# https://www.owasp.org/index.php/List_of_useful_HTTP_headers
2016-01-07 13:58:38 +00:00
def useful_headers_after_request(response):
response.headers.add('X-Frame-Options', 'deny')
response.headers.add('X-Content-Type-Options', 'nosniff')
response.headers.add('X-XSS-Protection', '1; mode=block')
2016-07-05 07:12:21 +01:00
response.headers.add('Content-Security-Policy', (
"default-src 'self' {asset_domain} 'unsafe-inline';"
"script-src 'self' {asset_domain} *.google-analytics.com 'unsafe-inline' 'unsafe-eval' data:;"
2017-11-06 10:25:30 +00:00
"connect-src 'self' *.google-analytics.com;"
2016-07-05 07:12:21 +01:00
"object-src 'self';"
"font-src 'self' {asset_domain} data:;"
"img-src 'self' {asset_domain} *.google-analytics.com *.notifications.service.gov.uk {logo_domain} data:;"
2018-11-29 11:29:52 +00:00
"frame-src 'self' www.youtube.com;".format(
2018-11-29 12:07:48 +00:00
asset_domain=current_app.config['ASSET_DOMAIN'],
logo_domain=get_logo_cdn_domain(),
2018-11-29 11:29:52 +00:00
)
2016-07-05 07:12:21 +01:00
))
2016-02-02 14:02:10 +00:00
if 'Cache-Control' in response.headers:
del response.headers['Cache-Control']
response.headers.add(
'Cache-Control', 'no-store, no-cache, private, must-revalidate')
2018-05-25 10:18:39 +01:00
for key, value in response.headers:
response.headers[key] = SanitiseASCII.encode(value)
2016-01-07 13:58:38 +00:00
return response
2016-01-07 15:48:29 +00:00
2016-01-07 15:55:55 +00:00
def register_errorhandlers(application): # noqa (C901 too complex)
def _error_response(error_code):
resp = make_response(render_template("error/{0}.html".format(error_code)), error_code)
return useful_headers_after_request(resp)
@application.errorhandler(HTTPError)
def render_http_error(error):
2018-03-08 16:10:17 +00:00
application.logger.warning("API {} failed with status {} message {}".format(
2016-07-21 17:32:28 +01:00
error.response.url if error.response else 'unknown',
2016-07-19 13:53:27 +01:00
error.status_code,
error.message
))
2016-03-11 10:16:06 +00:00
error_code = error.status_code
if error_code == 400:
if isinstance(error.message, str):
msg = [error.message]
else:
msg = list(itertools.chain(*[error.message[x] for x in error.message.keys()]))
resp = make_response(render_template("error/400.html", message=msg))
return useful_headers_after_request(resp)
2018-03-08 16:10:17 +00:00
elif error_code not in [401, 404, 403, 410]:
# probably a 500 or 503
application.logger.exception("API {} failed with status {} message {}".format(
error.response.url if error.response else 'unknown',
error.status_code,
error.message
))
error_code = 500
return _error_response(error_code)
2016-10-10 11:36:12 +01:00
2018-05-30 13:50:29 +01:00
@application.errorhandler(400)
def handle_400(error):
return _error_response(400)
2016-10-10 11:36:12 +01:00
@application.errorhandler(410)
def handle_gone(error):
return _error_response(410)
2018-03-08 17:49:08 +00:00
@application.errorhandler(413)
def handle_payload_too_large(error):
return _error_response(413)
@application.errorhandler(404)
def handle_not_found(error):
return _error_response(404)
@application.errorhandler(403)
def handle_not_authorized(error):
return _error_response(403)
@application.errorhandler(401)
def handle_no_permissions(error):
return _error_response(401)
@application.errorhandler(BadSignature)
def handle_bad_token(error):
# if someone has a malformed token
flash('Theres something wrong with the link youve used.')
return _error_response(404)
@application.errorhandler(CSRFError)
def handle_csrf(reason):
application.logger.warning('csrf.error_message: {}'.format(reason))
if 'user_id' not in session:
application.logger.warning(
u'csrf.session_expired: Redirecting user to log in page'
)
return application.login_manager.unauthorized()
application.logger.warning(
u'csrf.invalid_token: Aborting request, user_id: {user_id}',
extra={'user_id': session['user_id']})
resp = make_response(render_template(
"error/400.html",
message=['Something went wrong, please go back and try again.']
), 400)
return useful_headers_after_request(resp)
2018-06-22 17:36:58 +01:00
@application.errorhandler(405)
def handle_405(error):
resp = make_response(render_template(
"error/400.html",
message=['Something went wrong, please go back and try again.']
), 405)
return useful_headers_after_request(resp)
@application.errorhandler(WerkzeugHTTPException)
def handle_http_error(error):
if error.code == 301:
# RequestRedirect exception
return error
return _error_response(error.code)
2018-02-12 16:02:33 +00:00
@application.errorhandler(500)
@application.errorhandler(Exception)
def handle_bad_request(error):
current_app.logger.exception(error)
# We want the Flask in browser stacktrace
if current_app.config.get('DEBUG', None):
raise error
return _error_response(500)
def setup_event_handlers():
2017-07-26 11:02:57 +01:00
from flask_login import user_logged_in
2017-02-23 16:43:09 +00:00
from app.event_handlers import on_user_logged_in
user_logged_in.connect(on_user_logged_in)
2017-11-06 13:07:21 +00:00
def add_template_filters(application):
2017-11-09 15:54:49 +00:00
for fn in [
format_datetime,
format_datetime_24h,
format_datetime_normal,
format_datetime_short,
format_time,
valid_phone_number,
linkable_name,
format_date,
format_date_normal,
format_date_short,
format_datetime_relative,
format_delta,
format_notification_status,
format_notification_type,
2017-11-09 15:54:49 +00:00
format_notification_status_as_time,
format_notification_status_as_field_status,
format_notification_status_as_url,
formatted_list,
nl2br,
format_phone_number_human_readable,
id_safe,
2017-11-09 15:54:49 +00:00
]:
application.add_template_filter(fn)