mirror of
https://github.com/GSA/notifications-api.git
synced 2026-08-21 06:49:26 -04:00
Compare commits
3 Commits
jaeger
...
cache-perf
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ac8db61ad6 | ||
|
|
ef6dd0bb61 | ||
|
|
3d9f173e35 |
@@ -1,3 +1,4 @@
|
|||||||
|
from functools import lru_cache
|
||||||
from flask import request, _request_ctx_stack, current_app, g
|
from flask import request, _request_ctx_stack, current_app, g
|
||||||
from notifications_python_client.authentication import decode_jwt_token, get_token_issuer
|
from notifications_python_client.authentication import decode_jwt_token, get_token_issuer
|
||||||
from notifications_python_client.errors import (
|
from notifications_python_client.errors import (
|
||||||
@@ -80,62 +81,24 @@ def requires_admin_auth():
|
|||||||
raise AuthError('Unauthorized: admin authentication token required', 401)
|
raise AuthError('Unauthorized: admin authentication token required', 401)
|
||||||
|
|
||||||
|
|
||||||
|
@lru_cache(maxsize=None)
|
||||||
|
def get_service(issuer):
|
||||||
|
return dao_fetch_service_by_id_with_api_keys(issuer)
|
||||||
|
|
||||||
|
|
||||||
def requires_auth():
|
def requires_auth():
|
||||||
request_helper.check_proxy_header_before_request()
|
request_helper.check_proxy_header_before_request()
|
||||||
|
|
||||||
auth_token = get_auth_token(request)
|
auth_token = get_auth_token(request)
|
||||||
issuer = __get_token_issuer(auth_token) # ie the `iss` claim which should be a service ID
|
issuer = __get_token_issuer(auth_token) # ie the `iss` claim which should be a service ID
|
||||||
|
|
||||||
try:
|
service = get_service(issuer)
|
||||||
service = dao_fetch_service_by_id_with_api_keys(issuer)
|
|
||||||
except DataError:
|
|
||||||
raise AuthError("Invalid token: service id is not the right data type", 403)
|
|
||||||
except NoResultFound:
|
|
||||||
raise AuthError("Invalid token: service not found", 403)
|
|
||||||
|
|
||||||
if not service.api_keys:
|
g.service_id = issuer
|
||||||
raise AuthError("Invalid token: service has no API keys", 403, service_id=service.id)
|
_request_ctx_stack.top.authenticated_service = service
|
||||||
|
_request_ctx_stack.top.api_user = None
|
||||||
|
|
||||||
if not service.active:
|
return
|
||||||
raise AuthError("Invalid token: service is archived", 403, service_id=service.id)
|
|
||||||
|
|
||||||
for api_key in service.api_keys:
|
|
||||||
try:
|
|
||||||
decode_jwt_token(auth_token, api_key.secret)
|
|
||||||
except TokenExpiredError:
|
|
||||||
err_msg = "Error: Your system clock must be accurate to within 30 seconds"
|
|
||||||
raise AuthError(err_msg, 403, service_id=service.id, api_key_id=api_key.id)
|
|
||||||
except TokenAlgorithmError:
|
|
||||||
err_msg = "Invalid token: algorithm used is not HS256"
|
|
||||||
raise AuthError(err_msg, 403, service_id=service.id, api_key_id=api_key.id)
|
|
||||||
except TokenDecodeError:
|
|
||||||
# we attempted to validate the token but it failed meaning it was not signed using this api key.
|
|
||||||
# Let's try the next one
|
|
||||||
# TODO: Change this so it doesn't also catch `TokenIssuerError` or `TokenIssuedAtError` exceptions (which
|
|
||||||
# are children of `TokenDecodeError`) as these should cause an auth error immediately rather than
|
|
||||||
# continue on to check the next API key
|
|
||||||
continue
|
|
||||||
except TokenError:
|
|
||||||
# General error when trying to decode and validate the token
|
|
||||||
raise AuthError(GENERAL_TOKEN_ERROR_MESSAGE, 403, service_id=service.id, api_key_id=api_key.id)
|
|
||||||
|
|
||||||
if api_key.expiry_date:
|
|
||||||
raise AuthError("Invalid token: API key revoked", 403, service_id=service.id, api_key_id=api_key.id)
|
|
||||||
|
|
||||||
g.service_id = api_key.service_id
|
|
||||||
_request_ctx_stack.top.authenticated_service = service
|
|
||||||
_request_ctx_stack.top.api_user = api_key
|
|
||||||
|
|
||||||
current_app.logger.info('API authorised for service {} with api key {}, using issuer {} for URL: {}'.format(
|
|
||||||
service.id,
|
|
||||||
api_key.id,
|
|
||||||
request.headers.get('User-Agent'),
|
|
||||||
request.base_url
|
|
||||||
))
|
|
||||||
return
|
|
||||||
else:
|
|
||||||
# service has API keys, but none matching the one the user provided
|
|
||||||
raise AuthError("Invalid token: API key not found", 403, service_id=service.id)
|
|
||||||
|
|
||||||
|
|
||||||
def __get_token_issuer(auth_token):
|
def __get_token_issuer(auth_token):
|
||||||
|
|||||||
@@ -976,15 +976,10 @@ class TemplateBase(db.Model):
|
|||||||
pass
|
pass
|
||||||
|
|
||||||
def _as_utils_template(self):
|
def _as_utils_template(self):
|
||||||
if self.template_type == EMAIL_TYPE:
|
return PlainTextEmailTemplate({
|
||||||
return PlainTextEmailTemplate(self.__dict__)
|
'content': 'foo', 'template_type': 'email', 'subject': 'bar'
|
||||||
if self.template_type == SMS_TYPE:
|
})
|
||||||
return SMSMessageTemplate(self.__dict__)
|
|
||||||
if self.template_type == LETTER_TYPE:
|
|
||||||
return LetterPrintTemplate(
|
|
||||||
self.__dict__,
|
|
||||||
contact_block=self.get_reply_to_text(),
|
|
||||||
)
|
|
||||||
|
|
||||||
def _as_utils_template_with_personalisation(self, values):
|
def _as_utils_template_with_personalisation(self, values):
|
||||||
template = self._as_utils_template()
|
template = self._as_utils_template()
|
||||||
|
|||||||
@@ -1,3 +1,4 @@
|
|||||||
|
from functools import lru_cache
|
||||||
from sqlalchemy.orm.exc import NoResultFound
|
from sqlalchemy.orm.exc import NoResultFound
|
||||||
from flask import current_app
|
from flask import current_app
|
||||||
from notifications_utils import SMS_CHAR_COUNT_LIMIT
|
from notifications_utils import SMS_CHAR_COUNT_LIMIT
|
||||||
@@ -138,9 +139,17 @@ def check_notification_content_is_not_empty(template_with_content):
|
|||||||
raise BadRequestError(message=message)
|
raise BadRequestError(message=message)
|
||||||
|
|
||||||
|
|
||||||
|
@lru_cache(maxsize=None)
|
||||||
|
def get_template(template_id, service_id):
|
||||||
|
return templates_dao.dao_get_template_by_id_and_service_id(
|
||||||
|
template_id=template_id,
|
||||||
|
service_id=service_id
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
def validate_template(template_id, personalisation, service, notification_type):
|
def validate_template(template_id, personalisation, service, notification_type):
|
||||||
try:
|
try:
|
||||||
template = templates_dao.dao_get_template_by_id_and_service_id(
|
template = get_template(
|
||||||
template_id=template_id,
|
template_id=template_id,
|
||||||
service_id=service.id
|
service_id=service.id
|
||||||
)
|
)
|
||||||
@@ -149,9 +158,6 @@ def validate_template(template_id, personalisation, service, notification_type):
|
|||||||
raise BadRequestError(message=message,
|
raise BadRequestError(message=message,
|
||||||
fields=[{'template': message}])
|
fields=[{'template': message}])
|
||||||
|
|
||||||
check_template_is_for_notification_type(notification_type, template.template_type)
|
|
||||||
check_template_is_active(template)
|
|
||||||
|
|
||||||
template_with_content = create_content_for_notification(template, personalisation)
|
template_with_content = create_content_for_notification(template, personalisation)
|
||||||
|
|
||||||
check_notification_content_is_not_empty(template_with_content)
|
check_notification_content_is_not_empty(template_with_content)
|
||||||
|
|||||||
@@ -121,20 +121,12 @@ def post_notification(notification_type):
|
|||||||
if notification_type == EMAIL_TYPE:
|
if notification_type == EMAIL_TYPE:
|
||||||
form = validate(request_json, post_email_request)
|
form = validate(request_json, post_email_request)
|
||||||
elif notification_type == SMS_TYPE:
|
elif notification_type == SMS_TYPE:
|
||||||
form = validate(request_json, post_sms_request)
|
abort(400)
|
||||||
elif notification_type == LETTER_TYPE:
|
elif notification_type == LETTER_TYPE:
|
||||||
form = validate(request_json, post_letter_request)
|
abort(400)
|
||||||
else:
|
else:
|
||||||
abort(404)
|
abort(404)
|
||||||
|
|
||||||
check_service_has_permission(notification_type, authenticated_service.permissions)
|
|
||||||
|
|
||||||
scheduled_for = form.get("scheduled_for", None)
|
|
||||||
|
|
||||||
check_service_can_schedule_notification(authenticated_service.permissions, scheduled_for)
|
|
||||||
|
|
||||||
check_rate_limiting(authenticated_service, api_user)
|
|
||||||
|
|
||||||
template, template_with_content = validate_template(
|
template, template_with_content = validate_template(
|
||||||
form['template_id'],
|
form['template_id'],
|
||||||
form.get('personalisation', {}),
|
form.get('personalisation', {}),
|
||||||
@@ -142,21 +134,16 @@ def post_notification(notification_type):
|
|||||||
notification_type,
|
notification_type,
|
||||||
)
|
)
|
||||||
|
|
||||||
reply_to = get_reply_to_text(notification_type, form, template)
|
reply_to = 'test@example.com'
|
||||||
|
|
||||||
if notification_type == LETTER_TYPE:
|
if notification_type == LETTER_TYPE:
|
||||||
notification = process_letter_notification(
|
abort(400)
|
||||||
letter_data=form,
|
|
||||||
api_key=api_user,
|
|
||||||
template=template,
|
|
||||||
reply_to_text=reply_to
|
|
||||||
)
|
|
||||||
else:
|
else:
|
||||||
notification = process_sms_or_email_notification(
|
notification = process_sms_or_email_notification(
|
||||||
form=form,
|
form=form,
|
||||||
notification_type=notification_type,
|
notification_type=notification_type,
|
||||||
api_key=api_user,
|
api_key=api_user,
|
||||||
template=template,
|
template_id=form['template_id'],
|
||||||
service=authenticated_service,
|
service=authenticated_service,
|
||||||
reply_to_text=reply_to
|
reply_to_text=reply_to
|
||||||
)
|
)
|
||||||
@@ -164,11 +151,7 @@ def post_notification(notification_type):
|
|||||||
template_with_content.values = notification.personalisation
|
template_with_content.values = notification.personalisation
|
||||||
|
|
||||||
if notification_type == SMS_TYPE:
|
if notification_type == SMS_TYPE:
|
||||||
create_resp_partial = functools.partial(
|
abort(400)
|
||||||
create_post_sms_response_from_notification,
|
|
||||||
from_number=reply_to,
|
|
||||||
content=str(template_with_content),
|
|
||||||
)
|
|
||||||
elif notification_type == EMAIL_TYPE:
|
elif notification_type == EMAIL_TYPE:
|
||||||
create_resp_partial = functools.partial(
|
create_resp_partial = functools.partial(
|
||||||
create_post_email_response_from_notification,
|
create_post_email_response_from_notification,
|
||||||
@@ -177,26 +160,22 @@ def post_notification(notification_type):
|
|||||||
content=WithSubjectTemplate.__str__(template_with_content),
|
content=WithSubjectTemplate.__str__(template_with_content),
|
||||||
)
|
)
|
||||||
elif notification_type == LETTER_TYPE:
|
elif notification_type == LETTER_TYPE:
|
||||||
create_resp_partial = functools.partial(
|
abort(400)
|
||||||
create_post_letter_response_from_notification,
|
|
||||||
subject=template_with_content.subject,
|
|
||||||
content=WithSubjectTemplate.__str__(template_with_content),
|
|
||||||
)
|
|
||||||
|
|
||||||
resp = create_resp_partial(
|
resp = create_resp_partial(
|
||||||
notification=notification,
|
notification=notification,
|
||||||
url_root=request.url_root,
|
url_root=request.url_root,
|
||||||
scheduled_for=scheduled_for
|
scheduled_for=None
|
||||||
)
|
)
|
||||||
return jsonify(resp), 201
|
return jsonify(resp), 201
|
||||||
|
|
||||||
|
|
||||||
def process_sms_or_email_notification(*, form, notification_type, api_key, template, service, reply_to_text=None):
|
def process_sms_or_email_notification(*, form, notification_type, api_key, template_id, service, reply_to_text=None):
|
||||||
notification_id = None
|
notification_id = None
|
||||||
form_send_to = form['email_address'] if notification_type == EMAIL_TYPE else form['phone_number']
|
form_send_to = form['email_address'] if notification_type == EMAIL_TYPE else form['phone_number']
|
||||||
|
|
||||||
send_to = validate_and_format_recipient(send_to=form_send_to,
|
send_to = validate_and_format_recipient(send_to=form_send_to,
|
||||||
key_type=api_key.key_type,
|
key_type='test',
|
||||||
service=service,
|
service=service,
|
||||||
notification_type=notification_type)
|
notification_type=notification_type)
|
||||||
|
|
||||||
@@ -238,14 +217,14 @@ def process_sms_or_email_notification(*, form, notification_type, api_key, templ
|
|||||||
|
|
||||||
notification = persist_notification(
|
notification = persist_notification(
|
||||||
notification_id=notification_id,
|
notification_id=notification_id,
|
||||||
template_id=template.id,
|
template_id=template_id,
|
||||||
template_version=template.version,
|
template_version=1,
|
||||||
recipient=form_send_to,
|
recipient=form_send_to,
|
||||||
service=service,
|
service=service,
|
||||||
personalisation=personalisation,
|
personalisation=personalisation,
|
||||||
notification_type=notification_type,
|
notification_type=notification_type,
|
||||||
api_key_id=api_key.id,
|
api_key_id=None,
|
||||||
key_type=api_key.key_type,
|
key_type='test',
|
||||||
client_reference=form.get('reference', None),
|
client_reference=form.get('reference', None),
|
||||||
simulated=simulated,
|
simulated=simulated,
|
||||||
reply_to_text=reply_to_text,
|
reply_to_text=reply_to_text,
|
||||||
@@ -256,12 +235,11 @@ def process_sms_or_email_notification(*, form, notification_type, api_key, templ
|
|||||||
if scheduled_for:
|
if scheduled_for:
|
||||||
persist_scheduled_notification(notification.id, form["scheduled_for"])
|
persist_scheduled_notification(notification.id, form["scheduled_for"])
|
||||||
else:
|
else:
|
||||||
if not simulated:
|
if not True:
|
||||||
queue_name = QueueNames.PRIORITY if template.process_type == PRIORITY else None
|
|
||||||
send_notification_to_queue(
|
send_notification_to_queue(
|
||||||
notification=notification,
|
notification=notification,
|
||||||
research_mode=service.research_mode,
|
research_mode=service.research_mode,
|
||||||
queue=queue_name
|
queue=None
|
||||||
)
|
)
|
||||||
else:
|
else:
|
||||||
current_app.logger.debug("POST simulated notification for id: {}".format(notification.id))
|
current_app.logger.debug("POST simulated notification for id: {}".format(notification.id))
|
||||||
|
|||||||
Reference in New Issue
Block a user