...
|
...
|
@@ -37,6 +37,16 @@ def split_by_crlf(s): |
37
|
37
|
return [v for v in s.splitlines() if v]
|
38
|
38
|
|
39
|
39
|
|
|
40
|
+def getRedirectUrl(request): # 获取重定向地址
|
|
41
|
+ # 获取头部信息
|
|
42
|
+ X_Forwarded_Proto = request.headers.get("X-Forwarded-Proto") # 协议
|
|
43
|
+ X_Forwarded_Host = request.headers.get("X-Forwarded-Host") # host
|
|
44
|
+ if not X_Forwarded_Proto == None and not X_Forwarded_Host == None:
|
|
45
|
+ return X_Forwarded_Proto+"://"+X_Forwarded_Host
|
|
46
|
+ else:
|
|
47
|
+ return request.host_url.rstrip("/")
|
|
48
|
+
|
|
49
|
+
|
40
|
50
|
class DataManager(BlueprintApi):
|
41
|
51
|
bp = Blueprint("Auth", __name__, url_prefix="/auth")
|
42
|
52
|
|
...
|
...
|
@@ -136,25 +146,30 @@ class DataManager(BlueprintApi): |
136
|
146
|
request=request2)
|
137
|
147
|
redirect_uri = grant1.validate_authorization_request()
|
138
|
148
|
access_token = request.args.get("accesstoken")
|
139
|
|
- accesstoken = OAuth2Token.query.filter_by(
|
140
|
|
- access_token=access_token).first()
|
141
|
|
- accesstoken.revoked = True
|
142
|
|
- db.session.commit()
|
143
|
|
- user = current_user()
|
144
|
|
- remove_user()
|
145
|
149
|
|
146
|
|
- # 日志
|
147
|
|
- log = OAuthLog(user_id=user.id, username=user.username,
|
148
|
|
- auth_type=AuthEnum.Other.name.lower(),
|
149
|
|
- message="注销成功", create_time=datetime.now(),
|
150
|
|
- operate_type=OperateEnum.Logout, token=access_token,
|
151
|
|
- displayname=user.displayname, ip=request.remote_addr
|
152
|
|
- )
|
153
|
|
- db.session.add(log)
|
154
|
|
- db.session.commit()
|
|
150
|
+ if not access_token == None:
|
|
151
|
+ accesstoken = OAuth2Token.query.filter_by(
|
|
152
|
+ access_token=access_token).one_or_none()
|
|
153
|
+ if not accesstoken == None:
|
|
154
|
+ accesstoken.revoked = True
|
|
155
|
+ db.session.commit()
|
|
156
|
+ if current_user() != None:
|
|
157
|
+ remove_user()
|
|
158
|
+
|
|
159
|
+ user = User.query.get(accesstoken.user_id)
|
|
160
|
+ # 日志
|
|
161
|
+ if user != None:
|
|
162
|
+ log = OAuthLog(user_id=user.id, username=user.username,
|
|
163
|
+ auth_type=AuthEnum.Other.name.lower(),
|
|
164
|
+ message="注销成功", create_time=datetime.now(),
|
|
165
|
+ operate_type=OperateEnum.Logout, token=access_token,
|
|
166
|
+ displayname=user.displayname, ip=request.remote_addr
|
|
167
|
+ )
|
|
168
|
+ db.session.add(log)
|
|
169
|
+ db.session.commit()
|
155
|
170
|
|
156
|
171
|
except OAuth2Error as error:
|
157
|
|
- return jsonify(dict(error.get_body()))
|
|
172
|
+ StructurePrint().print(error.__str__()+":" + traceback.format_exc(), "error")
|
158
|
173
|
return redirect(redirect_uri)
|
159
|
174
|
|
160
|
175
|
"""接口"""
|
...
|
...
|
@@ -255,8 +270,9 @@ class DataManager(BlueprintApi): |
255
|
270
|
client = oauth2.WebApplicationClient(
|
256
|
271
|
configure.OA["client_id"])
|
257
|
272
|
state = client.state_generator()
|
|
273
|
+ StructurePrint().print(request.headers, "info")
|
258
|
274
|
auth_uri = client.prepare_request_uri(
|
259
|
|
- configure.OA["authorization_endpoint"], configure.OA["redirect_uri"], configure.OA["scope"], state)
|
|
275
|
+ configure.OA["authorization_endpoint"], getRedirectUrl(request) + configure.OA["redirect_uri"], configure.OA["scope"], state)
|
260
|
276
|
session["oauth_state"] = state
|
261
|
277
|
return redirect(auth_uri)
|
262
|
278
|
|
...
|
...
|
@@ -267,7 +283,7 @@ class DataManager(BlueprintApi): |
267
|
283
|
@bp.route("/oa/callback", methods=["GET"])
|
268
|
284
|
def oa_callback():
|
269
|
285
|
try:
|
270
|
|
- print(request.remote_addr)
|
|
286
|
+ auth_default_redirect_uri = configure.auth_default_redirect_uri
|
271
|
287
|
client = oauth2.WebApplicationClient(
|
272
|
288
|
configure.OA["client_id"])
|
273
|
289
|
|
...
|
...
|
@@ -280,7 +296,7 @@ class DataManager(BlueprintApi): |
280
|
296
|
|
281
|
297
|
# 获取token
|
282
|
298
|
body = client.prepare_request_body(
|
283
|
|
- code, redirect_uri=configure.OA["redirect_uri"], client_secret=configure.OA["client_secret"])
|
|
299
|
+ code, redirect_uri=getRedirectUrl(request) + configure.OA["redirect_uri"], client_secret=configure.OA["client_secret"])
|
284
|
300
|
|
285
|
301
|
r = requests.post(configure.OA["token_endpoint"], body, headers={
|
286
|
302
|
"Content-Type": "application/x-www-form-urlencoded"})
|
...
|
...
|
@@ -289,7 +305,6 @@ class DataManager(BlueprintApi): |
289
|
305
|
access_token = tokeninfo.get("access_token")
|
290
|
306
|
id_token = tokeninfo.get("id_token")
|
291
|
307
|
|
292
|
|
- auth_default_redirect_uri = configure.auth_default_redirect_uri
|
293
|
308
|
origin_type = "dci_oa" # 三方登录标识
|
294
|
309
|
if access_token:
|
295
|
310
|
# 获取用户信息
|
...
|
...
|
|