Compare commits

...

97 Commits

Author SHA1 Message Date
Steven Reilly
8ac605fcb1 Revert "Production deploy 5/10/2024" 2024-05-14 13:57:14 -04:00
Steven Reilly
faf6170b67 Merge pull request #980 from GSA/main
Production deploy 5/10/2024
2024-05-10 12:22:41 -04:00
Carlo Costino
10eaf9b433 Merge pull request #977 from GSA/dependabot/pip/boto3-1.34.101
Bump boto3 from 1.34.94 to 1.34.101
2024-05-08 21:26:56 -04:00
dependabot[bot]
4577a6d06b Bump boto3 from 1.34.94 to 1.34.101
Bumps [boto3](https://github.com/boto/boto3) from 1.34.94 to 1.34.101.
- [Release notes](https://github.com/boto/boto3/releases)
- [Changelog](https://github.com/boto/boto3/blob/develop/CHANGELOG.rst)
- [Commits](https://github.com/boto/boto3/compare/1.34.94...1.34.101)

---
updated-dependencies:
- dependency-name: boto3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-05-09 01:19:29 +00:00
Carlo Costino
1acf9a2ed0 Merge pull request #976 from GSA/dependabot/pip/botocore-1.34.101
Bump botocore from 1.34.100 to 1.34.101
2024-05-08 21:16:39 -04:00
dependabot[bot]
39985e4d6e Bump botocore from 1.34.100 to 1.34.101
Bumps [botocore](https://github.com/boto/botocore) from 1.34.100 to 1.34.101.
- [Changelog](https://github.com/boto/botocore/blob/develop/CHANGELOG.rst)
- [Commits](https://github.com/boto/botocore/compare/1.34.100...1.34.101)

---
updated-dependencies:
- dependency-name: botocore
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-05-09 01:05:24 +00:00
Carlo Costino
72ca2f3744 Merge pull request #974 from GSA/dependabot/pip/faker-25.1.0
Bump faker from 24.14.1 to 25.1.0
2024-05-08 21:03:34 -04:00
dependabot[bot]
44fd437295 Bump faker from 24.14.1 to 25.1.0
Bumps [faker](https://github.com/joke2k/faker) from 24.14.1 to 25.1.0.
- [Release notes](https://github.com/joke2k/faker/releases)
- [Changelog](https://github.com/joke2k/faker/blob/master/CHANGELOG.md)
- [Commits](https://github.com/joke2k/faker/compare/v24.14.1...v25.1.0)

---
updated-dependencies:
- dependency-name: faker
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-05-08 21:45:07 +00:00
Carlo Costino
ec0e18ff35 Merge pull request #969 from GSA/dependabot/pip/botocore-1.34.100
Bump botocore from 1.34.99 to 1.34.100
2024-05-08 10:38:24 -04:00
dependabot[bot]
f21acb74ef Bump botocore from 1.34.99 to 1.34.100
Bumps [botocore](https://github.com/boto/botocore) from 1.34.99 to 1.34.100.
- [Changelog](https://github.com/boto/botocore/blob/develop/CHANGELOG.rst)
- [Commits](https://github.com/boto/botocore/compare/1.34.99...1.34.100)

---
updated-dependencies:
- dependency-name: botocore
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-05-08 14:04:49 +00:00
Carlo Costino
38228c585f Merge pull request #970 from GSA/dependabot/pip/exceptiongroup-1.2.1
Bump exceptiongroup from 1.2.0 to 1.2.1
2024-05-08 10:02:26 -04:00
dependabot[bot]
eb3c71ff6e Bump exceptiongroup from 1.2.0 to 1.2.1
Bumps [exceptiongroup](https://github.com/agronholm/exceptiongroup) from 1.2.0 to 1.2.1.
- [Release notes](https://github.com/agronholm/exceptiongroup/releases)
- [Changelog](https://github.com/agronholm/exceptiongroup/blob/main/CHANGES.rst)
- [Commits](https://github.com/agronholm/exceptiongroup/compare/1.2.0...1.2.1)

---
updated-dependencies:
- dependency-name: exceptiongroup
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-05-08 13:54:51 +00:00
Carlo Costino
3ae8b81dc3 Merge pull request #971 from GSA/dependabot/pip/python-dotenv-1.0.1
Bump python-dotenv from 1.0.0 to 1.0.1
2024-05-08 09:51:53 -04:00
Carlo Costino
7a1c49b7c7 Merge pull request #968 from GSA/dependabot/pip/cloudfoundry-client-1.37.1
Bump cloudfoundry-client from 1.36.0 to 1.37.1
2024-05-07 17:16:58 -04:00
dependabot[bot]
9f5b388c08 Bump python-dotenv from 1.0.0 to 1.0.1
Bumps [python-dotenv](https://github.com/theskumar/python-dotenv) from 1.0.0 to 1.0.1.
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.0.0...v1.0.1)

---
updated-dependencies:
- dependency-name: python-dotenv
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-05-07 21:14:46 +00:00
dependabot[bot]
01081c64b4 Bump cloudfoundry-client from 1.36.0 to 1.37.1
Bumps [cloudfoundry-client](https://github.com/antechrestos/cf-python-client) from 1.36.0 to 1.37.1.
- [Commits](https://github.com/antechrestos/cf-python-client/compare/v1.36.0...v1.37.1)

---
updated-dependencies:
- dependency-name: cloudfoundry-client
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-05-07 21:07:48 +00:00
Carlo Costino
43c066e541 Merge pull request #961 from GSA/dependabot/pip/packaging-24.0
Bump packaging from 23.2 to 24.0
2024-05-07 12:58:55 -04:00
dependabot[bot]
5cd76eacdb Bump packaging from 23.2 to 24.0
Bumps [packaging](https://github.com/pypa/packaging) from 23.2 to 24.0.
- [Release notes](https://github.com/pypa/packaging/releases)
- [Changelog](https://github.com/pypa/packaging/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pypa/packaging/compare/23.2...24.0)

---
updated-dependencies:
- dependency-name: packaging
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-05-07 14:24:33 +00:00
Carlo Costino
075f35d123 Merge pull request #963 from GSA/dependabot/pip/botocore-1.34.99
Bump botocore from 1.34.94 to 1.34.99
2024-05-07 10:21:35 -04:00
dependabot[bot]
fa07e32c5b Bump botocore from 1.34.94 to 1.34.99
Bumps [botocore](https://github.com/boto/botocore) from 1.34.94 to 1.34.99.
- [Changelog](https://github.com/boto/botocore/blob/develop/CHANGELOG.rst)
- [Commits](https://github.com/boto/botocore/compare/1.34.94...1.34.99)

---
updated-dependencies:
- dependency-name: botocore
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-05-07 13:55:53 +00:00
Carlo Costino
b2ac7537f0 Merge pull request #962 from GSA/dependabot/pip/moto-5.0.6
Bump moto from 5.0.5 to 5.0.6
2024-05-07 09:53:16 -04:00
Carlo Costino
79f43fe6e1 Merge pull request #965 from GSA/dependabot/pip/pip-audit-2.7.3
Bump pip-audit from 2.7.2 to 2.7.3
2024-05-06 18:08:00 -04:00
dependabot[bot]
6f6b74e26e Bump pip-audit from 2.7.2 to 2.7.3
Bumps [pip-audit](https://github.com/pypa/pip-audit) from 2.7.2 to 2.7.3.
- [Release notes](https://github.com/pypa/pip-audit/releases)
- [Changelog](https://github.com/pypa/pip-audit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/pypa/pip-audit/compare/v2.7.2...v2.7.3)

---
updated-dependencies:
- dependency-name: pip-audit
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-05-06 21:54:33 +00:00
dependabot[bot]
dee50eacff Bump moto from 5.0.5 to 5.0.6
Bumps [moto](https://github.com/getmoto/moto) from 5.0.5 to 5.0.6.
- [Release notes](https://github.com/getmoto/moto/releases)
- [Changelog](https://github.com/getmoto/moto/blob/master/CHANGELOG.md)
- [Commits](https://github.com/getmoto/moto/compare/5.0.5...5.0.6)

---
updated-dependencies:
- dependency-name: moto
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-05-06 21:52:45 +00:00
Carlo Costino
8f7c2930cd Merge pull request #959 from GSA/dependabot/pip/werkzeug-3.0.3
Bump werkzeug from 3.0.2 to 3.0.3
2024-05-06 13:12:08 -04:00
dependabot[bot]
017bb63f87 Bump werkzeug from 3.0.2 to 3.0.3
Bumps [werkzeug](https://github.com/pallets/werkzeug) from 3.0.2 to 3.0.3.
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](https://github.com/pallets/werkzeug/compare/3.0.2...3.0.3)

---
updated-dependencies:
- dependency-name: werkzeug
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-05-06 15:33:18 +00:00
Carlo Costino
cec16a6434 Merge pull request #958 from GSA/dependabot/pip/jinja2-3.1.4
Bump jinja2 from 3.1.3 to 3.1.4
2024-05-06 11:29:27 -04:00
dependabot[bot]
c221514936 Bump jinja2 from 3.1.3 to 3.1.4
Bumps [jinja2](https://github.com/pallets/jinja) from 3.1.3 to 3.1.4.
- [Release notes](https://github.com/pallets/jinja/releases)
- [Changelog](https://github.com/pallets/jinja/blob/main/CHANGES.rst)
- [Commits](https://github.com/pallets/jinja/compare/3.1.3...3.1.4)

---
updated-dependencies:
- dependency-name: jinja2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-05-06 14:33:35 +00:00
Carlo Costino
1e04ecca18 Merge pull request #901 from GSA/notify-api-869
flask upgrade
2024-05-06 10:31:49 -04:00
Carlo Costino
ac898b6ea3 Update marshmallow based on Dependabot
Signed-off-by: Carlo Costino <carlo.costino@gsa.gov>
2024-05-01 18:04:29 -04:00
Carlo Costino
a5c67da7a6 Update poetry.lock file for jsonschema
Signed-off-by: Carlo Costino <carlo.costino@gsa.gov>
2024-05-01 09:18:33 -04:00
Carlo Costino
f8a2c7e9e4 Update jsonschema from Dependabot
Signed-off-by: Carlo Costino <carlo.costino@gsa.gov>
2024-05-01 09:16:12 -04:00
Carlo Costino
bd9df68067 Merge branch 'main' into notify-api-869 2024-04-30 14:57:07 -04:00
Carlo Costino
acc577c272 Merge pull request #941 from GSA/1270-update-email-content
1270 update email content
2024-04-30 14:55:44 -04:00
Carlo Costino
ac82ae6f9f Updated utils to 0.5.1 release in prep for Flask upgrade
Signed-off-by: Carlo Costino <carlo.costino@gsa.gov>
2024-04-29 15:41:44 -04:00
Carlo Costino
a0d772385b Merge branch 'main' into notify-api-869 2024-04-29 15:40:05 -04:00
Steven Reilly
3e2ad6ba0d Merge pull request #949 from GSA/main
4/26/2024 Production Deploy
2024-04-26 15:32:47 -04:00
Carlo Costino
87d0ae29f5 Merge pull request #945 from GSA/fix_service_invites
fix service invites
2024-04-25 16:58:16 -04:00
Kenneth Kehl
bd80ef16ba code review feedback 2024-04-25 13:21:26 -07:00
Kenneth Kehl
f1f2f728af cleanup 2024-04-24 14:06:43 -07:00
Kenneth Kehl
a2518b8229 fix service invites 2024-04-24 10:51:47 -07:00
Carlo Costino
21c5e09f8b Merge pull request #928 from GSA/jskinne3-upgrade-cloudgov-module
Upgrade terraform-cloudgov module
2024-04-23 18:05:29 -04:00
Carlo Costino
701025fa46 Merge pull request #923 from GSA/jskinne3-upgrade-terraform-version
Upgrade terraform version to match CI/CD
2024-04-23 17:53:45 -04:00
Carlo Costino
4b72c35961 Merge pull request #922 from GSA/jskinne3-updgrade-cloudfoundary-0.53.1
Upgrade cloudfoundry from 0.53.0 to 0.53.1 everywhere
2024-04-23 16:40:34 -04:00
samathad2023
c7eba2ba50 latest version urllib3 2024-04-23 09:38:27 -07:00
Jonathan Bobel
fb8ab7ed23 1270 - Email content updates 2024-04-22 13:14:09 -04:00
Carlo Costino
e3a1fe34ee Merge pull request #940 from GSA/notify-admin-1447
api to return service invite info
2024-04-22 12:25:26 -04:00
Jonathan Bobel
50b5eae8e2 Merge branch 'main' of https://github.com/GSA/notifications-api into 1270-update-email-content 2024-04-22 12:07:51 -04:00
Kenneth Kehl
13b03bbfe4 fix test 2024-04-22 07:32:10 -07:00
Kenneth Kehl
49352a4be1 add tests 2024-04-19 15:19:11 -07:00
Kenneth Kehl
44c8d74250 don't do a json.dumps before sending 2024-04-19 14:11:05 -07:00
Kenneth Kehl
56c73d9898 api to return service invite info 2024-04-19 14:02:38 -07:00
Carlo Costino
b7c244c653 Merge pull request #938 from GSA/notify-admin-1447
use raw_get and raw_set for better debug of redis
2024-04-19 13:41:31 -04:00
Kenneth Kehl
c02f32a263 use raw_set and raw_get, fix tests 2024-04-19 10:33:26 -07:00
Kenneth Kehl
075ac1f3d3 use raw_get and raw_set for better debug of redis 2024-04-19 10:12:27 -07:00
Carlo Costino
e460e967bb Merge pull request #936 from GSA/notify-admin-1447
Add debug statements for why we can't add user to a service on staging
2024-04-19 12:38:43 -04:00
Kenneth Kehl
1ae239cdb8 fix flake8 2024-04-19 09:27:58 -07:00
Kenneth Kehl
234ca3cc9e merge from main 2024-04-19 09:14:55 -07:00
Kenneth Kehl
751e8ab077 more debug 2024-04-19 09:14:36 -07:00
Carlo Costino
8e198ae1ee Merge pull request #935 from GSA/main
04/18/2024 Production Deploy
2024-04-18 17:00:00 -04:00
Carlo Costino
5e498830d2 Merge pull request #929 from GSA/main
04/17/2024 Production Deploy
2024-04-17 15:46:22 -04:00
John Skiles Skinner
6a20f2c426 Upgrade terraform-cloudgov module from 0.7.1 to 0.9.1 in 2 modules 2024-04-17 11:47:39 -07:00
John Skiles Skinner
dbfb1e2379 Accommodate the version of Terraform that CI/CD expects 2024-04-15 17:52:40 -07:00
John Skiles Skinner
4b904c69c2 One more troubleshooting item 2024-04-15 17:32:34 -07:00
John Skiles Skinner
13061ce939 Update README about the -m flag when creating a SpaceDeployer 2024-04-15 17:25:04 -07:00
John Skiles Skinner
dc6379bae7 Update version of Terraform installed in the main README 2024-04-15 16:51:32 -07:00
John Skiles Skinner
99716f39e6 Upgrade minimum Terraform version in each providers.tf file 2024-04-15 16:43:35 -07:00
John Skiles Skinner
6608e3672e Upgrade cloudfoundry from 0.53.0 to 0.53.1 everywhere 2024-04-15 12:08:41 -07:00
Steven Reilly
946a7461f4 Merge pull request #908 from GSA/main
Production deploy for 4/9/24
2024-04-09 12:19:25 -04:00
samathad2023
85b12f63f9 flask from 3.0.2 to 3.0.3 2024-04-08 12:17:30 -07:00
samathad2023
6c216a88d7 flask upgrade dependencies 2024-04-04 16:18:57 -07:00
Carlo Costino
f1d190d235 Merge pull request #892 from GSA/main
Prod deploy - 4/3/24
2024-04-03 15:45:33 -04:00
Steven Reilly
d9bb94ff42 Merge pull request #877 from GSA/main
API Production Deploy - 3/28/2024
2024-04-03 11:31:28 -04:00
Jonathan Bobel
a65465b282 Merge branch 'main' of https://github.com/GSA/notifications-api into 1270-update-email-content 2024-03-25 14:27:07 -04:00
Steven Reilly
3387e2a0be Merge pull request #859 from GSA/main
API Production Deploy - 3/19/2024
2024-03-19 13:24:31 -04:00
Steven Reilly
ffddf478ee Merge pull request #846 from GSA/main
API Production Deploy 3/14/2023
2024-03-14 11:10:12 -04:00
Steven Reilly
895d08615a Merge pull request #834 from GSA/main
Production Deploy 3/6/2024
2024-03-06 09:23:54 -05:00
Steven Reilly
1add55bc91 Merge pull request #821 from GSA/main
2/27/2024 Production Deployment
2024-02-28 09:43:26 -05:00
Steven Reilly
57b6058605 Merge pull request #807 from GSA/main
Production Deploy 2/20/2024
2024-02-20 16:00:49 -05:00
Carlo Costino
837832ddf4 Merge pull request #795 from GSA/main
Production deploy 2/8/24
2024-02-09 09:37:37 -05:00
Steven Reilly
1ca6070269 Merge pull request #786 from GSA/main
One-off API Production Deploy to fix CSV parsing issue - 02-02-2024
2024-02-02 10:23:09 -05:00
Carlo Costino
ec388f95f2 Merge pull request #777 from GSA/main
CSV error handling prod deploy
2024-01-31 11:37:54 -05:00
Carlo Costino
7f36b6c3a1 Merge pull request #775 from GSA/main
CSV debug prod deploy
2024-01-31 10:44:08 -05:00
Carlo Costino
f29929e2ab Merge pull request #772 from GSA/main
Production deploy 1/30/24
2024-01-30 16:52:12 -05:00
Carlo Costino
32c5f8e035 Merge pull request #766 from GSA/main
Production deploy 1/29/24
2024-01-30 08:27:08 -05:00
Steven Reilly
078d31f55a Merge pull request #677 from GSA/main
Production deploy 12/13/23
2023-12-13 14:27:58 -05:00
Carlo Costino
e6df534d69 Merge pull request #643 from GSA/main
Prod deploy 11/30/2023
2023-11-30 15:50:39 -05:00
Steven Reilly
60a444b858 Merge pull request #635 from GSA/main
Production deploy 11/28/23
2023-11-29 15:20:27 -05:00
Steven Reilly
cdb8654e5e Merge pull request #552 from GSA/main
Production deploy 10/31/23
2023-11-01 14:26:15 -04:00
Carlo Costino
36f2e84a5f Merge pull request #526 from GSA/main
Production deploy 10/2/2023
2023-10-05 13:25:34 -04:00
Steven Reilly
eab34e0f52 Merge pull request #508 from GSA/main
Production deploy 9/26/23
2023-09-26 16:47:09 -04:00
Carlo Costino
5e53f0607a Merge pull request #503 from GSA/main
Production deploy 9/25/23
2023-09-25 17:43:57 -04:00
Steven Reilly
da0734bf3f Merge pull request #496 from GSA/main
Production deploy 9/22/23
2023-09-22 13:14:49 -04:00
Steven Reilly
e9e9b8a34a Merge pull request #480 from GSA/main
Production deploy 9/18/23, part 3
2023-09-18 13:59:28 -04:00
Steven Reilly
2f20d78c97 Merge pull request #478 from GSA/main
Production deploy 9/18/23, part 2
2023-09-18 12:43:31 -04:00
Steven Reilly
3f899ec78b Merge pull request #475 from GSA/main
Production deploy 9/18/23
2023-09-18 11:34:14 -04:00
Steven Reilly
4702b454fc Merge pull request #447 from GSA/main
Production deploy 8/29/23
2023-08-29 21:08:35 -04:00
18 changed files with 94 additions and 61 deletions

View File

@@ -141,11 +141,10 @@ Terraform installations. This is great, but you still need to install Terraform
itself, which can be done with this command:
```sh
tfenv install latest:^1.4.0
tfenv install "latest:^1.7"
tfenv use 1.7.x # x = the patch version installed
```
_NOTE: This project currently uses the latest `1.4.x release of Terraform._
#### Python Installation
Now we're going to install a tool to help us manage Python versions and

View File

@@ -89,14 +89,6 @@ def invite_user_to_org(organization_id):
ex=1800,
)
# This is for the login.gov path, note 24 hour expiry to match
# The expiration of invitations.
redis_key = f"organization-invite-{invited_org_user.email_address}"
redis_store.set(
redis_key,
organization_id,
ex=3600 * 24,
)
send_notification_to_queue(saved_notification, queue=QueueNames.NOTIFY)
return jsonify(data=invited_org_user.serialize()), 201

View File

@@ -102,7 +102,7 @@ from app.service.service_senders_schema import (
)
from app.service.utils import get_guest_list_objects
from app.user.users_schema import post_set_permissions_schema
from app.utils import get_prev_next_pagination_links
from app.utils import get_prev_next_pagination_links, hilite
service_blueprint = Blueprint("service", __name__)
@@ -314,7 +314,9 @@ def get_users_for_service(service_id):
def add_user_to_service(service_id, user_id):
service = dao_fetch_service_by_id(service_id)
user = get_user_by_id(user_id=user_id)
# TODO REMOVE DEBUG
print(hilite(f"GOING TO ADD {user.name} to service {service.name}"))
# END DEBUG
if user in service.users:
error = "User id: {} already part of service id: {}".format(user_id, service_id)
raise InvalidRequest(error, status_code=400)
@@ -329,6 +331,10 @@ def add_user_to_service(service_id, user_id):
folder_permissions = data.get("folder_permissions", [])
dao_add_user_to_service(service, user, permissions, folder_permissions)
# TODO REMOVE DEBUG
print(hilite(f"ADDED {user.name} to service {service.name}"))
# END DEBUG
data = service_schema.dump(service)
return jsonify(data=data), 201

View File

@@ -1,3 +1,4 @@
import base64
import json
import os
from datetime import datetime
@@ -25,6 +26,7 @@ from app.notifications.process_notifications import (
send_notification_to_queue,
)
from app.schemas import invited_user_schema
from app.utils import hilite
service_invite = Blueprint("service_invite", __name__)
@@ -32,6 +34,10 @@ register_errors(service_invite)
def _create_service_invite(invited_user, invite_link_host):
# TODO REMOVE DEBUG
print(hilite("ENTER _create_service_invite"))
# END DEBUG
template_id = current_app.config["INVITATION_EMAIL_TEMPLATE_ID"]
template = dao_get_template_by_id(template_id)
@@ -43,9 +49,25 @@ def _create_service_invite(invited_user, invite_link_host):
current_app.config["SECRET_KEY"],
current_app.config["DANGEROUS_SALT"],
)
# The raw permissions are in the form "a,b,c,d"
# but need to be in the form ["a", "b", "c", "d"]
data = {}
permissions = invited_user.permissions
permissions = permissions.split(",")
data["from_user_id"] = (str(invited_user.from_user.id))
data["service_id"] = str(invited_user.service.id)
data["permissions"] = permissions
data["folder_permissions"] = invited_user.folder_permissions
data["invited_user_id"] = str(invited_user.id)
data["invited_user_email"] = invited_user.email_address
url = os.environ["LOGIN_DOT_GOV_REGISTRATION_URL"]
url = url.replace("NONCE", token)
url = url.replace("STATE", token)
user_data_url_safe = get_user_data_url_safe(data)
url = url.replace("STATE", user_data_url_safe)
personalisation = {
"user_name": invited_user.from_user.name,
@@ -70,26 +92,6 @@ def _create_service_invite(invited_user, invite_link_host):
json.dumps(personalisation),
ex=1800,
)
# The raw permissions are in the form "a,b,c,d"
# but need to be in the form ["a", "b", "c", "d"]
data = {}
permissions = invited_user.permissions
permissions = permissions.split(",")
permission_list = []
for permission in permissions:
permission_list.append(f"{permission}")
data["from_user_id"] = (str(invited_user.from_user.id),)
data["service_id"] = str(invited_user.service.id)
data["permissions"] = permission_list
data["folder_permissions"] = invited_user.folder_permissions
# This is for the login.gov service invite on the
# "Set Up Your Profile" path.
redis_store.set(
f"service-invite-{invited_user.email_address}",
json.dumps(data),
ex=3600 * 24,
)
send_notification_to_queue(saved_notification, queue=QueueNames.NOTIFY)
@@ -212,3 +214,9 @@ def validate_service_invitation_token(token):
invited_user = get_invited_user_by_id(invited_user_id)
return jsonify(data=invited_user_schema.dump(invited_user)), 200
def get_user_data_url_safe(data):
data = json.dumps(data)
data = base64.b64encode(data.encode("utf8"))
return data.decode("utf8")

2
poetry.lock generated
View File

@@ -2490,6 +2490,7 @@ files = [
{file = "msgpack-1.0.8-cp39-cp39-musllinux_1_1_x86_64.whl", hash = "sha256:5fbb160554e319f7b22ecf530a80a3ff496d38e8e07ae763b9e82fadfe96f273"},
{file = "msgpack-1.0.8-cp39-cp39-win32.whl", hash = "sha256:f9af38a89b6a5c04b7d18c492c8ccf2aee7048aff1ce8437c4683bb5a1df893d"},
{file = "msgpack-1.0.8-cp39-cp39-win_amd64.whl", hash = "sha256:ed59dd52075f8fc91da6053b12e8c89e37aa043f8986efd89e61fae69dc1b011"},
{file = "msgpack-1.0.8-py3-none-any.whl", hash = "sha256:24f727df1e20b9876fa6e95f840a2a2651e34c0ad147676356f4bf5fbb0206ca"},
{file = "msgpack-1.0.8.tar.gz", hash = "sha256:95c02b0e27e706e48d0e5426d1710ca78e0f0628d6e89d5b5a5b91a5f12274f3"},
]
@@ -3531,7 +3532,6 @@ files = [
{file = "PyYAML-6.0.1-cp311-cp311-win_amd64.whl", hash = "sha256:bf07ee2fef7014951eeb99f56f39c9bb4af143d8aa3c21b1677805985307da34"},
{file = "PyYAML-6.0.1-cp312-cp312-macosx_10_9_x86_64.whl", hash = "sha256:855fb52b0dc35af121542a76b9a84f8d1cd886ea97c84703eaa6d88e37a2ad28"},
{file = "PyYAML-6.0.1-cp312-cp312-macosx_11_0_arm64.whl", hash = "sha256:40df9b996c2b73138957fe23a16a4f0ba614f4c0efce1e9406a184b6d07fa3a9"},
{file = "PyYAML-6.0.1-cp312-cp312-manylinux_2_17_aarch64.manylinux2014_aarch64.whl", hash = "sha256:a08c6f0fe150303c1c6b71ebcd7213c2858041a7e01975da3a99aed1e7a378ef"},
{file = "PyYAML-6.0.1-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl", hash = "sha256:6c22bec3fbe2524cde73d7ada88f6566758a8f7227bfbf93a408a9d86bcc12a0"},
{file = "PyYAML-6.0.1-cp312-cp312-musllinux_1_1_x86_64.whl", hash = "sha256:8d4e9c88387b0f5c7d5f281e55304de64cf7f9c0021a3525bd3b1c542da3b0e4"},
{file = "PyYAML-6.0.1-cp312-cp312-win32.whl", hash = "sha256:d483d2cdf104e7c9fa60c544d92981f12ad66a457afae824d146093b8c294c54"},

View File

@@ -89,17 +89,19 @@ These steps assume shared [Terraform state credentials](#terraform-state-credent
1. Run `cf spaces` and, from the output, copy the space name for the environment you are working in, such as `notify-sandbox`.
1. Next you will set up a SpaceDeployer. Prepare to fill in these values:
* `<SPACE_NAME>` will be the string you copied from the prior step
* `<ACCOUNT_NAME>` can be anything, although we recommend something that communicates the purpose of the deployer. For example: "circleci-deployer" for the credentials CircleCI uses to deploy the application, or "sandbox-<your_name>" for credentials to run terraform manually.
1. Next you will set up a SpaceDeployer service account instance. This is something like a stub user account, just for deployment. Note these two values which you will use both to create and destroy the account:
1. `<SPACE_NAME>` will be the string you copied from the prior step
1. `<ACCOUNT_NAME>` can be anything, although we recommend something that communicates the purpose of the deployer. For example: "circleci-deployer" for the credentials CircleCI uses to deploy the application, or "sandbox-<your_name>" for credentials to run terraform manually.
Put those two values into this command:
Put those two values into this command:
```bash
./create_service_account.sh -s <SPACE_NAME> -u <ACCOUNT_NAME> > secrets.auto.tfvars
../create_service_account.sh -s <SPACE_NAME> -u <ACCOUNT_NAME> > secrets.auto.tfvars
```
The script will output the `username` (as `cf_user`) and `password` (as `cf_password`) for your `<ACCOUNT_NAME>`. The [cloud.gov service account documentation](https://cloud.gov/docs/services/cloud-gov-service-account/) has more information.
Some resources you might work on require a SpaceDeployer account with higher permissions. Add the `-m` flag to the command to get this.
The command uses the redirection operator (`>`) to write that output to the `secrets.auto.tfvars` file. Terraform will find the username and password there, and use them as input variables.
1. While still in an environment directory, initialize Terraform:
@@ -137,6 +139,8 @@ These steps assume shared [Terraform state credentials](#terraform-state-credent
./destroy_service_account.sh -s <SPACE_NAME> -u <ACCOUNT_NAME>
```
List `cf services` if you are unsure which space deployer service instances still exist
Optionally, you can also `rm secrets.auto.tfvars`
## Structure
@@ -195,3 +199,18 @@ You need to re-authenticate with the Cloud Foundry CLI
cf login -a api.fr.cloud.gov --sso
```
You may also need to log in again to the Cloud.gov website.
### CF account not authorized
```
Error: You are not authorized to perform the requested action
```
This error indicates that the Cloud Foundry user account (or service account) needs OrgManager permissions to take the action.
* When you create a SpaceDeployer service account, use the `-m` flag when running the `./create_service_account.sh` script
* Your own CF user may may also require OrgManager permissions to run the script
### Services limit
```
You have exceeded your organization's services limit.
```
Too many Cloud Foundry services have been created without being destroyed. Perhaps Terraform developers have forgotten to delete their SpaceDeployers after they finish with them. List `cf services` to see.

View File

@@ -3,7 +3,7 @@ locals {
}
module "s3" {
source = "github.com/18f/terraform-cloudgov//s3?ref=v0.7.1"
source = "github.com/18f/terraform-cloudgov//s3?ref=v0.9.1"
cf_org_name = "gsa-tts-benefits-studio"
cf_space_name = "notify-management"

View File

@@ -1,9 +1,9 @@
terraform {
required_version = "~> 1.0"
required_version = "~> 1.7"
required_providers {
cloudfoundry = {
source = "cloudfoundry-community/cloudfoundry"
version = "0.53.0"
version = "0.53.1"
}
}
}

View File

@@ -1,9 +1,9 @@
terraform {
required_version = "~> 1.0"
required_version = "~> 1.7"
required_providers {
cloudfoundry = {
source = "cloudfoundry-community/cloudfoundry"
version = "0.53.0"
version = "0.53.1"
}
}

View File

@@ -1,9 +1,9 @@
terraform {
required_version = "~> 1.0"
required_version = "~> 1.7"
required_providers {
cloudfoundry = {
source = "cloudfoundry-community/cloudfoundry"
version = "0.53.0"
version = "0.53.1"
}
}
}

View File

@@ -1,9 +1,9 @@
terraform {
required_version = "~> 1.0"
required_version = "~> 1.7"
required_providers {
cloudfoundry = {
source = "cloudfoundry-community/cloudfoundry"
version = "0.53.0"
version = "0.53.1"
}
}

View File

@@ -17,7 +17,7 @@ module "database" {
}
module "redis" {
source = "github.com/18f/terraform-cloudgov//redis?ref=v0.7.1"
source = "github.com/18f/terraform-cloudgov//redis?ref=v0.9.1"
cf_org_name = local.cf_org_name
cf_space_name = local.cf_space_name
@@ -27,7 +27,7 @@ module "redis" {
}
module "csv_upload_bucket" {
source = "github.com/18f/terraform-cloudgov//s3?ref=v0.7.1"
source = "github.com/18f/terraform-cloudgov//s3?ref=v0.9.1"
cf_org_name = local.cf_org_name
cf_space_name = local.cf_space_name

View File

@@ -1,9 +1,9 @@
terraform {
required_version = "~> 1.0"
required_version = "~> 1.7"
required_providers {
cloudfoundry = {
source = "cloudfoundry-community/cloudfoundry"
version = "0.53.0"
version = "0.53.1"
}
}

View File

@@ -1,9 +1,9 @@
terraform {
required_version = "~> 1.0"
required_version = "~> 1.7"
required_providers {
cloudfoundry = {
source = "cloudfoundry-community/cloudfoundry"
version = "0.53.0"
version = "0.53.1"
}
}
}

View File

@@ -1,9 +1,9 @@
terraform {
required_version = "~> 1.0"
required_version = "~> 1.7"
required_providers {
cloudfoundry = {
source = "cloudfoundry-community/cloudfoundry"
version = "0.53.0"
version = "0.53.1"
}
}
}

View File

@@ -1,9 +1,9 @@
terraform {
required_version = "~> 1.0"
required_version = "~> 1.7"
required_providers {
cloudfoundry = {
source = "cloudfoundry-community/cloudfoundry"
version = "0.53.0"
version = "0.53.1"
}
}
}

View File

@@ -1,9 +1,9 @@
terraform {
required_version = "~> 1.0"
required_version = "~> 1.7"
required_providers {
cloudfoundry = {
source = "cloudfoundry-community/cloudfoundry"
version = "0.53.0"
version = "0.53.1"
}
}

View File

@@ -31,6 +31,9 @@ def test_create_invited_user(
extra_args,
expected_start_of_invite_url,
):
mocker.patch("app.service_invite.rest.redis_store.raw_set")
mocker.patch("app.service_invite.rest.redis_store.raw_get")
mocked = mocker.patch("app.celery.provider_tasks.deliver_email.apply_async")
email_address = "invited_user@service.gov.uk"
invite_from = sample_service.users[0]
@@ -92,6 +95,9 @@ def test_create_invited_user(
def test_create_invited_user_without_auth_type(
admin_request, sample_service, mocker, invitation_email_template
):
mocker.patch("app.service_invite.rest.redis_store.raw_set")
mocker.patch("app.service_invite.rest.redis_store.raw_get")
mocker.patch("app.celery.provider_tasks.deliver_email.apply_async")
email_address = "invited_user@service.gov.uk"
invite_from = sample_service.users[0]
@@ -213,6 +219,9 @@ def test_resend_expired_invite(
invitation_email_template,
mocker,
):
mocker.patch("app.service_invite.rest.redis_store.raw_set")
mocker.patch("app.service_invite.rest.redis_store.raw_get")
url = f"/service/{sample_expired_user.service_id}/invite/{sample_expired_user.id}/resend"
mock_send = mocker.patch("app.service_invite.rest.send_notification_to_queue")
mock_persist = mocker.patch("app.service_invite.rest.persist_notification")