2014-04-30 23:52:05 +04:00
|
|
|
from django.contrib.auth.forms import PasswordResetForm, SetPasswordForm
|
|
|
|
from django.contrib.auth import authenticate, login, logout, get_user_model
|
|
|
|
from django.contrib.auth.tokens import default_token_generator
|
2014-05-03 02:42:29 +04:00
|
|
|
try:
|
|
|
|
from django.utils.http import urlsafe_base64_decode as uid_decoder
|
|
|
|
except:
|
|
|
|
# make compatible with django 1.5
|
|
|
|
from django.utils.http import base36_to_int as uid_decoder
|
2014-04-30 23:52:05 +04:00
|
|
|
from django.conf import settings
|
|
|
|
|
|
|
|
from rest_framework import status
|
|
|
|
from rest_framework.views import APIView
|
|
|
|
from rest_framework.response import Response
|
|
|
|
from rest_framework.generics import GenericAPIView
|
|
|
|
from rest_framework.serializers import _resolve_model
|
|
|
|
from rest_framework.permissions import IsAuthenticated, AllowAny
|
|
|
|
from rest_framework.authentication import SessionAuthentication, \
|
|
|
|
TokenAuthentication
|
|
|
|
from rest_framework.authtoken.models import Token
|
2014-10-02 13:18:23 +04:00
|
|
|
from rest_framework.generics import RetrieveUpdateAPIView
|
2014-04-30 23:52:05 +04:00
|
|
|
|
2014-07-08 13:36:59 +04:00
|
|
|
from rest_auth.serializers import (TokenSerializer, UserDetailsSerializer,
|
2014-10-02 13:18:23 +04:00
|
|
|
LoginSerializer, SetPasswordSerializer, PasswordResetSerializer)
|
2014-04-30 23:52:05 +04:00
|
|
|
|
|
|
|
|
2014-07-08 13:36:59 +04:00
|
|
|
def get_user_profile_model():
|
|
|
|
# Get the UserProfile model from the setting value
|
|
|
|
user_profile_path = getattr(settings, 'REST_PROFILE_MODULE', None)
|
|
|
|
if user_profile_path:
|
|
|
|
setattr(settings, 'AUTH_PROFILE_MODULE', user_profile_path)
|
|
|
|
return _resolve_model(user_profile_path)
|
2014-04-30 23:52:05 +04:00
|
|
|
|
|
|
|
|
|
|
|
class LoggedInRESTAPIView(APIView):
|
|
|
|
authentication_classes = ((SessionAuthentication, TokenAuthentication))
|
|
|
|
permission_classes = ((IsAuthenticated,))
|
|
|
|
|
|
|
|
|
|
|
|
class LoggedOutRESTAPIView(APIView):
|
|
|
|
permission_classes = ((AllowAny,))
|
|
|
|
|
|
|
|
|
|
|
|
class Login(LoggedOutRESTAPIView, GenericAPIView):
|
|
|
|
|
|
|
|
"""
|
|
|
|
Check the credentials and return the REST Token
|
|
|
|
if the credentials are valid and authenticated.
|
|
|
|
Calls Django Auth login method to register User ID
|
|
|
|
in Django session framework
|
|
|
|
|
|
|
|
Accept the following POST parameters: username, password
|
|
|
|
Return the REST Framework Token Object's key.
|
|
|
|
"""
|
|
|
|
|
|
|
|
serializer_class = LoginSerializer
|
2014-05-30 13:17:25 +04:00
|
|
|
token_model = Token
|
2014-10-02 13:18:23 +04:00
|
|
|
response_serializer = TokenSerializer
|
2014-04-30 23:52:05 +04:00
|
|
|
|
2014-10-02 13:18:23 +04:00
|
|
|
def get_serializer(self):
|
|
|
|
return self.serializer_class(data=self.request.DATA)
|
2014-10-01 17:31:10 +04:00
|
|
|
|
2014-10-02 13:18:23 +04:00
|
|
|
def login(self):
|
|
|
|
self.user = self.serializer.object['user']
|
|
|
|
self.token, created = self.token_model.objects.get_or_create(
|
|
|
|
user=self.user)
|
2014-10-01 17:31:10 +04:00
|
|
|
|
|
|
|
if getattr(settings, 'REST_SESSION_LOGIN', True):
|
2014-10-02 13:18:23 +04:00
|
|
|
login(self.request, self.user)
|
2014-10-01 17:31:10 +04:00
|
|
|
|
2014-10-02 13:18:23 +04:00
|
|
|
def get_response(self):
|
|
|
|
return Response(self.response_serializer(self.token).data,
|
|
|
|
status=status.HTTP_200_OK)
|
|
|
|
|
|
|
|
def get_error_response(self):
|
|
|
|
return Response(self.serializer.errors,
|
|
|
|
status=status.HTTP_400_BAD_REQUEST)
|
|
|
|
|
|
|
|
def post(self, request, *args, **kwargs):
|
|
|
|
self.serializer = self.get_serializer()
|
|
|
|
if not self.serializer.is_valid():
|
|
|
|
return self.get_error_response()
|
|
|
|
self.login()
|
|
|
|
return self.get_response()
|
2014-04-30 23:52:05 +04:00
|
|
|
|
|
|
|
|
|
|
|
class Logout(LoggedInRESTAPIView):
|
|
|
|
|
|
|
|
"""
|
|
|
|
Calls Django logout method and delete the Token object
|
|
|
|
assigned to the current User object.
|
|
|
|
|
|
|
|
Accepts/Returns nothing.
|
|
|
|
"""
|
|
|
|
|
2014-10-02 13:18:23 +04:00
|
|
|
def post(self, request):
|
2014-04-30 23:52:05 +04:00
|
|
|
try:
|
|
|
|
request.user.auth_token.delete()
|
|
|
|
except:
|
|
|
|
pass
|
|
|
|
|
|
|
|
logout(request)
|
|
|
|
|
|
|
|
return Response({"success": "Successfully logged out."},
|
|
|
|
status=status.HTTP_200_OK)
|
|
|
|
|
|
|
|
|
2014-10-02 13:18:23 +04:00
|
|
|
class UserDetails(LoggedInRESTAPIView, RetrieveUpdateAPIView):
|
2014-04-30 23:52:05 +04:00
|
|
|
|
|
|
|
"""
|
|
|
|
Returns User's details in JSON format.
|
|
|
|
|
|
|
|
Accepts the following GET parameters: token
|
|
|
|
Accepts the following POST parameters:
|
|
|
|
Required: token
|
|
|
|
Optional: email, first_name, last_name and UserProfile fields
|
|
|
|
Returns the updated UserProfile and/or User object.
|
|
|
|
"""
|
2014-10-02 13:18:23 +04:00
|
|
|
serializer_class = UserDetailsSerializer
|
2014-04-30 23:52:05 +04:00
|
|
|
|
2014-10-02 13:18:23 +04:00
|
|
|
def get_object(self):
|
|
|
|
return self.request.user
|
2014-04-30 23:52:05 +04:00
|
|
|
|
|
|
|
|
|
|
|
class PasswordReset(LoggedOutRESTAPIView, GenericAPIView):
|
|
|
|
|
|
|
|
"""
|
|
|
|
Calls Django Auth PasswordResetForm save method.
|
|
|
|
|
|
|
|
Accepts the following POST parameters: email
|
|
|
|
Returns the success/fail message.
|
|
|
|
"""
|
|
|
|
|
|
|
|
serializer_class = PasswordResetSerializer
|
2014-08-19 15:24:03 +04:00
|
|
|
password_reset_form_class = PasswordResetForm
|
2014-04-30 23:52:05 +04:00
|
|
|
|
|
|
|
def post(self, request):
|
|
|
|
# Create a serializer with request.DATA
|
|
|
|
serializer = self.serializer_class(data=request.DATA)
|
|
|
|
|
|
|
|
if serializer.is_valid():
|
|
|
|
# Create PasswordResetForm with the serializer
|
2014-08-19 15:24:03 +04:00
|
|
|
reset_form = self.password_reset_form_class(data=serializer.data)
|
2014-04-30 23:52:05 +04:00
|
|
|
|
|
|
|
if reset_form.is_valid():
|
|
|
|
# Sett some values to trigger the send_email method.
|
|
|
|
opts = {
|
|
|
|
'use_https': request.is_secure(),
|
|
|
|
'from_email': getattr(settings, 'DEFAULT_FROM_EMAIL'),
|
|
|
|
'request': request,
|
|
|
|
}
|
|
|
|
|
|
|
|
reset_form.save(**opts)
|
|
|
|
|
|
|
|
# Return the success message with OK HTTP status
|
2014-05-01 00:55:04 +04:00
|
|
|
return Response(
|
|
|
|
{"success": "Password reset e-mail has been sent."},
|
|
|
|
status=status.HTTP_200_OK)
|
2014-04-30 23:52:05 +04:00
|
|
|
|
|
|
|
else:
|
|
|
|
return Response(reset_form._errors,
|
|
|
|
status=status.HTTP_400_BAD_REQUEST)
|
|
|
|
|
|
|
|
else:
|
|
|
|
return Response(serializer.errors,
|
|
|
|
status=status.HTTP_400_BAD_REQUEST)
|
|
|
|
|
2014-05-01 00:55:04 +04:00
|
|
|
|
2014-04-30 23:52:05 +04:00
|
|
|
class PasswordResetConfirm(LoggedOutRESTAPIView, GenericAPIView):
|
2014-05-01 00:55:04 +04:00
|
|
|
|
2014-04-30 23:52:05 +04:00
|
|
|
"""
|
|
|
|
Password reset e-mail link is confirmed, therefore this resets the user's password.
|
|
|
|
|
|
|
|
Accepts the following POST parameters: new_password1, new_password2
|
2014-05-06 02:53:06 +04:00
|
|
|
Accepts the following Django URL arguments: token, uid
|
2014-04-30 23:52:05 +04:00
|
|
|
Returns the success/fail message.
|
|
|
|
"""
|
|
|
|
|
|
|
|
serializer_class = SetPasswordSerializer
|
|
|
|
|
2014-05-06 02:53:06 +04:00
|
|
|
def post(self, request, uid=None, token=None):
|
2014-04-30 23:52:05 +04:00
|
|
|
# Get the UserModel
|
|
|
|
UserModel = get_user_model()
|
|
|
|
|
|
|
|
# Decode the uidb64 to uid to get User object
|
|
|
|
try:
|
2014-05-06 02:53:06 +04:00
|
|
|
uid = uid_decoder(uid)
|
2014-04-30 23:52:05 +04:00
|
|
|
user = UserModel._default_manager.get(pk=uid)
|
|
|
|
except (TypeError, ValueError, OverflowError, UserModel.DoesNotExist):
|
|
|
|
user = None
|
|
|
|
|
|
|
|
# If we get the User object
|
|
|
|
if user:
|
2014-05-05 23:01:23 +04:00
|
|
|
serializer = self.serializer_class(data=request.DATA, user=user)
|
2014-04-30 23:52:05 +04:00
|
|
|
|
|
|
|
if serializer.is_valid():
|
|
|
|
# Construct SetPasswordForm instance
|
|
|
|
form = SetPasswordForm(user=user, data=serializer.data)
|
|
|
|
|
|
|
|
if form.is_valid():
|
|
|
|
if default_token_generator.check_token(user, token):
|
|
|
|
form.save()
|
|
|
|
|
|
|
|
# Return the success message with OK HTTP status
|
2014-05-01 00:55:04 +04:00
|
|
|
return Response(
|
|
|
|
{"success":
|
|
|
|
"Password has been reset with the new password."},
|
2014-04-30 23:52:05 +04:00
|
|
|
status=status.HTTP_200_OK)
|
|
|
|
else:
|
2014-05-01 00:55:04 +04:00
|
|
|
return Response(
|
|
|
|
{"error": "Invalid password reset token."},
|
2014-04-30 23:52:05 +04:00
|
|
|
status=status.HTTP_400_BAD_REQUEST)
|
|
|
|
else:
|
|
|
|
return Response(form._errors, status=status.HTTP_400_BAD_REQUEST)
|
|
|
|
|
|
|
|
else:
|
|
|
|
return Response(serializer.errors,
|
|
|
|
status=status.HTTP_400_BAD_REQUEST)
|
|
|
|
|
|
|
|
else:
|
2014-05-06 02:53:06 +04:00
|
|
|
return Response({"errors": "Couldn\'t find the user from uid."}, status=status.HTTP_400_BAD_REQUEST)
|
2014-04-30 23:52:05 +04:00
|
|
|
|
|
|
|
|
|
|
|
class PasswordChange(LoggedInRESTAPIView, GenericAPIView):
|
|
|
|
|
|
|
|
"""
|
|
|
|
Calls Django Auth SetPasswordForm save method.
|
|
|
|
|
|
|
|
Accepts the following POST parameters: new_password1, new_password2
|
|
|
|
Returns the success/fail message.
|
|
|
|
"""
|
|
|
|
|
|
|
|
serializer_class = SetPasswordSerializer
|
|
|
|
|
|
|
|
def post(self, request):
|
|
|
|
# Create a serializer with request.DATA
|
|
|
|
serializer = self.serializer_class(data=request.DATA)
|
|
|
|
|
|
|
|
if serializer.is_valid():
|
|
|
|
# Construct the SetPasswordForm instance
|
|
|
|
form = SetPasswordForm(user=request.user, data=serializer.data)
|
|
|
|
|
|
|
|
if form.is_valid():
|
|
|
|
form.save()
|
|
|
|
|
|
|
|
# Return the success message with OK HTTP status
|
|
|
|
return Response({"success": "New password has been saved."},
|
|
|
|
status=status.HTTP_200_OK)
|
|
|
|
|
|
|
|
else:
|
|
|
|
return Response(form._errors,
|
|
|
|
status=status.HTTP_400_BAD_REQUEST)
|
|
|
|
|
|
|
|
else:
|
|
|
|
return Response(serializer.errors,
|
|
|
|
status=status.HTTP_400_BAD_REQUEST)
|