Files
notifications-api/app/organization/invite_rest.py

163 lines
5.6 KiB
Python
Raw Normal View History

2021-03-10 13:55:06 +00:00
from flask import Blueprint, current_app, jsonify, request
from itsdangerous import BadData, SignatureExpired
from notifications_utils.url_safe_token import check_token, generate_token
2018-02-16 10:56:12 +00:00
from app.config import QueueNames
from app.dao.invited_org_user_dao import (
get_invited_org_user as dao_get_invited_org_user,
)
from app.dao.invited_org_user_dao import (
get_invited_org_user_by_id,
2023-07-10 11:06:29 -07:00
get_invited_org_users_for_organization,
2021-03-10 13:55:06 +00:00
save_invited_org_user,
2018-02-16 10:56:12 +00:00
)
from app.dao.templates_dao import dao_get_template_by_id
from app.errors import InvalidRequest, register_errors
2023-07-10 11:06:29 -07:00
from app.models import EMAIL_TYPE, KEY_TYPE_NORMAL, InvitedOrganizationUser
2021-03-10 13:55:06 +00:00
from app.notifications.process_notifications import (
persist_notification,
send_notification_to_queue,
)
2023-07-10 11:06:29 -07:00
from app.organization.organization_schema import (
2018-02-19 15:03:36 +00:00
post_create_invited_org_user_status_schema,
2021-03-10 13:55:06 +00:00
post_update_invited_org_user_status_schema,
2018-02-19 15:03:36 +00:00
)
2021-03-10 13:55:06 +00:00
from app.schema_validation import validate
2018-02-16 10:56:12 +00:00
2023-08-29 14:54:30 -07:00
organization_invite_blueprint = Blueprint("organization_invite", __name__)
2018-02-16 10:56:12 +00:00
2023-07-10 11:06:29 -07:00
register_errors(organization_invite_blueprint)
2018-02-16 10:56:12 +00:00
2023-08-29 14:54:30 -07:00
@organization_invite_blueprint.route(
"/organization/<uuid:organization_id>/invite", methods=["POST"]
)
2023-07-10 11:06:29 -07:00
def invite_user_to_org(organization_id):
2018-02-19 15:03:36 +00:00
data = request.get_json()
validate(data, post_create_invited_org_user_status_schema)
2018-02-16 10:56:12 +00:00
2023-07-10 11:06:29 -07:00
invited_org_user = InvitedOrganizationUser(
2023-08-29 14:54:30 -07:00
email_address=data["email_address"],
invited_by_id=data["invited_by"],
organization_id=organization_id,
2018-02-16 10:56:12 +00:00
)
save_invited_org_user(invited_org_user)
2023-08-29 14:54:30 -07:00
template = dao_get_template_by_id(
current_app.config["ORGANIZATION_INVITATION_EMAIL_TEMPLATE_ID"]
)
2018-02-16 10:56:12 +00:00
2024-01-22 10:55:09 -08:00
personalisation = {
"user_name": (
"The GOV.UK Notify team"
if invited_org_user.invited_by.platform_admin
else invited_org_user.invited_by.name
),
"organization_name": invited_org_user.organization.name,
"url": invited_org_user_url(
invited_org_user.id,
data.get("invite_link_host"),
),
}
2018-02-16 10:56:12 +00:00
saved_notification = persist_notification(
template_id=template.id,
template_version=template.version,
recipient=invited_org_user.email_address,
service=template.service,
2024-01-22 10:55:09 -08:00
personalisation={},
2018-02-16 10:56:12 +00:00
notification_type=EMAIL_TYPE,
api_key_id=None,
key_type=KEY_TYPE_NORMAL,
2023-08-29 14:54:30 -07:00
reply_to_text=invited_org_user.invited_by.email_address,
2018-02-16 10:56:12 +00:00
)
2024-01-22 10:55:09 -08:00
saved_notification.personalisation = personalisation
2018-02-16 10:56:12 +00:00
2023-08-25 12:09:00 -07:00
send_notification_to_queue(saved_notification, queue=QueueNames.NOTIFY)
2018-02-16 10:56:12 +00:00
return jsonify(data=invited_org_user.serialize()), 201
2023-08-29 14:54:30 -07:00
@organization_invite_blueprint.route(
"/organization/<uuid:organization_id>/invite", methods=["GET"]
)
2023-07-10 11:06:29 -07:00
def get_invited_org_users_by_organization(organization_id):
invited_org_users = get_invited_org_users_for_organization(organization_id)
2018-02-16 10:56:12 +00:00
return jsonify(data=[x.serialize() for x in invited_org_users]), 200
2023-07-10 11:06:29 -07:00
@organization_invite_blueprint.route(
2023-08-29 14:54:30 -07:00
"/organization/<uuid:organization_id>/invite/<invited_org_user_id>", methods=["GET"]
)
2023-07-10 11:06:29 -07:00
def get_invited_org_user_by_organization(organization_id, invited_org_user_id):
invited_org_user = dao_get_invited_org_user(organization_id, invited_org_user_id)
return jsonify(data=invited_org_user.serialize()), 200
2023-07-10 11:06:29 -07:00
@organization_invite_blueprint.route(
2023-08-29 14:54:30 -07:00
"/organization/<uuid:organization_id>/invite/<invited_org_user_id>",
methods=["POST"],
)
2023-07-10 11:06:29 -07:00
def update_org_invite_status(organization_id, invited_org_user_id):
2023-08-29 14:54:30 -07:00
fetched = dao_get_invited_org_user(
organization_id=organization_id, invited_org_user_id=invited_org_user_id
)
2018-02-16 10:56:12 +00:00
2018-02-19 15:03:36 +00:00
data = request.get_json()
validate(data, post_update_invited_org_user_status_schema)
2023-08-29 14:54:30 -07:00
fetched.status = data["status"]
2018-02-19 15:03:36 +00:00
save_invited_org_user(fetched)
2018-02-16 10:56:12 +00:00
return jsonify(data=fetched.serialize()), 200
def invited_org_user_url(invited_org_user_id, invite_link_host=None):
token = generate_token(
str(invited_org_user_id),
2023-08-29 14:54:30 -07:00
current_app.config["SECRET_KEY"],
current_app.config["DANGEROUS_SALT"],
2018-02-16 10:56:12 +00:00
)
if invite_link_host is None:
2023-08-29 14:54:30 -07:00
invite_link_host = current_app.config["ADMIN_BASE_URL"]
2018-02-16 10:56:12 +00:00
2023-08-29 14:54:30 -07:00
return "{0}/organization-invitation/{1}".format(invite_link_host, token)
2023-08-29 14:54:30 -07:00
@organization_invite_blueprint.route(
"/invite/organization/<uuid:invited_org_user_id>", methods=["GET"]
)
def get_invited_org_user(invited_org_user_id):
invited_user = get_invited_org_user_by_id(invited_org_user_id)
return jsonify(data=invited_user.serialize()), 200
2023-08-29 14:54:30 -07:00
@organization_invite_blueprint.route("/invite/organization/<token>", methods=["GET"])
@organization_invite_blueprint.route(
"/invite/organization/check/<token>", methods=["GET"]
)
def validate_invitation_token(token):
2023-08-29 14:54:30 -07:00
max_age_seconds = 60 * 60 * 24 * current_app.config["INVITATION_EXPIRATION_DAYS"]
try:
2023-08-29 14:54:30 -07:00
invited_user_id = check_token(
token,
current_app.config["SECRET_KEY"],
current_app.config["DANGEROUS_SALT"],
max_age_seconds,
)
except SignatureExpired:
2023-08-29 14:54:30 -07:00
errors = {
"invitation": "Your invitation to GOV.UK Notify has expired. "
"Please ask the person that invited you to send you another one"
}
raise InvalidRequest(errors, status_code=400)
except BadData:
2023-08-29 14:54:30 -07:00
errors = {
"invitation": "Somethings wrong with this link. Make sure youve copied the whole thing."
}
raise InvalidRequest(errors, status_code=400)
invited_user = get_invited_org_user_by_id(invited_user_id)
return jsonify(data=invited_user.serialize()), 200