Skip to content

Commit

Permalink
Remove more auth0 stuff
Browse files Browse the repository at this point in the history
  • Loading branch information
MelissaAutumn committed Dec 7, 2023
1 parent 491637b commit 70e20b5
Show file tree
Hide file tree
Showing 4 changed files with 2 additions and 93 deletions.
1 change: 0 additions & 1 deletion backend/requirements.txt
Original file line number Diff line number Diff line change
@@ -1,5 +1,4 @@
alembic==1.9.3
auth0-python==4.0.0
argon2-cffi==23.1.0
argon2-cffi-bindings==21.2.0
caldav==1.0.1
Expand Down
90 changes: 1 addition & 89 deletions backend/src/appointment/controller/auth.py
Original file line number Diff line number Diff line change
Expand Up @@ -6,96 +6,8 @@
import os
import hashlib
import hmac
import secrets

from sqlalchemy.orm import Session
from ..database import repo, schemas, models
from fastapi_auth0 import Auth0, Auth0User
from auth0.authentication import GetToken
from auth0.management import Auth0 as ManageAuth0
from auth0.exceptions import Auth0Error, RateLimitError, TokenValidationError


domain = os.getenv("AUTH0_API_DOMAIN")
api_client_id = os.getenv("AUTH0_API_CLIENT_ID")
api_secret = os.getenv("AUTH0_API_SECRET")
api_audience = os.getenv("AUTH0_API_AUDIENCE")


class Auth:
def __init__(self):
"""verify Appointment subscription via Auth0, return user or None"""
scopes = {"read:calendars": "Read Calendar Ressources"} # TODO

# Ugly hack for testing
if os.getenv('APP_ENV') == 'test':
from types import SimpleNamespace
self.auth0 = SimpleNamespace(implicit_scheme=lambda x: x, get_user=lambda x: x)
return

self.auth0 = Auth0(domain=domain, api_audience=api_audience, scopes=scopes, auto_error=False)

def persist_user(self, db: Session, user: Auth0User, timezone: str):
"""Sync authed user to Appointment db"""
if not db:
return None
# get the current user via the authed user
api = self.init_management_api()
if not api:
logging.warning(
"[auth.persist_user] A frontend authed user (ID: %s, name: %s) was not found via management API",
str(user.id),
user.name,
)
return None
authenticated_subscriber = api.users.get(user.id)
# check if user exists as subsriber
if authenticated_subscriber:
# search for subscriber in Appointment db
db_subscriber = repo.get_subscriber_by_email(db=db, email=authenticated_subscriber["email"])
# if authenticated subscriber doesn't exist yet, add them
if db_subscriber is None:
subscriber = schemas.SubscriberBase(
username=authenticated_subscriber["email"], # username == email for now
email=authenticated_subscriber["email"],
name=authenticated_subscriber["name"],
timezone=timezone,
level=models.SubscriberLevel.pro, # TODO
)
db_subscriber = repo.create_subscriber(db=db, subscriber=subscriber)

# Generate an initial short link hash if they don't have one already
if db_subscriber.short_link_hash is None:
repo.update_subscriber(
db,
schemas.SubscriberAuth(
email=db_subscriber.email,
username=db_subscriber.username,
short_link_hash=secrets.token_hex(32),
),
db_subscriber.id,
)

return db_subscriber
return None

def init_management_api(self):
"""Helper function to get a management api token"""
try:
get_token = GetToken(domain, api_client_id, client_secret=api_secret)
token = get_token.client_credentials("https://{}/api/v2/".format(domain))
management = ManageAuth0(domain, token["access_token"])
except RateLimitError as error:
logging.error("[auth.init_management_api] A rate limit error occurred: " + str(error))
return None
except Auth0Error as error:
logging.error("[auth.init_management_api] An Auth0 error occurred: " + str(error))
return None
except TokenValidationError as error:
logging.error("[auth.init_management_api] A token validation error occurred" + str(error))
return None

return management
from ..database import repo, schemas


def sign_url(url: str):
Expand Down
1 change: 0 additions & 1 deletion backend/src/appointment/dependencies/auth.py
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,6 @@ def get_subscriber(
"""Automatically retrieve and return the subscriber"""
user = get_user_from_token(db, token)

# Error out if auth0 didn't find a user
if user is None:
raise HTTPException(403, detail='Missing bearer token')

Expand Down
3 changes: 1 addition & 2 deletions backend/src/appointment/routes/api.py
Original file line number Diff line number Diff line change
Expand Up @@ -17,10 +17,9 @@
from ..controller.calendar import CalDavConnector, Tools, GoogleConnector

from fastapi import APIRouter, Depends, HTTPException, Security, Body
from fastapi_auth0 import Auth0User
from datetime import timedelta, timezone
from ..controller.apis.google_client import GoogleClient
from ..controller.auth import signed_url_by_subscriber, Auth
from ..controller.auth import signed_url_by_subscriber
from ..database.models import Subscriber, CalendarProvider, MeetingLinkProviderType, ExternalConnectionType
from ..dependencies.google import get_google_client
from ..dependencies.auth import get_subscriber
Expand Down

0 comments on commit 70e20b5

Please sign in to comment.