2016-09-20 08:33:46 +03:00
|
|
|
import inspect
|
2016-09-20 08:04:23 +03:00
|
|
|
import json
|
2016-09-20 08:15:10 +03:00
|
|
|
import re
|
2016-09-18 02:29:00 +03:00
|
|
|
|
2016-09-20 08:15:10 +03:00
|
|
|
import six
|
2016-09-20 08:04:23 +03:00
|
|
|
from django.http import HttpResponse, HttpResponseNotAllowed
|
|
|
|
from django.http.response import HttpResponseBadRequest
|
|
|
|
from django.shortcuts import render
|
2016-09-20 09:14:59 +03:00
|
|
|
from django.utils.decorators import method_decorator
|
2016-09-20 08:15:10 +03:00
|
|
|
from django.views.generic import View
|
2016-09-20 09:14:59 +03:00
|
|
|
from django.views.decorators.csrf import ensure_csrf_cookie
|
2016-09-18 02:29:00 +03:00
|
|
|
|
2018-06-05 11:24:53 +03:00
|
|
|
from graphql import get_default_backend
|
2016-09-20 08:15:10 +03:00
|
|
|
from graphql.error import format_error as format_graphql_error
|
|
|
|
from graphql.error import GraphQLError
|
2016-09-20 08:04:23 +03:00
|
|
|
from graphql.execution import ExecutionResult
|
2016-09-20 08:15:10 +03:00
|
|
|
from graphql.type.schema import GraphQLSchema
|
2020-05-09 14:15:16 +03:00
|
|
|
from graphql.execution.middleware import MiddlewareManager
|
2016-09-18 03:09:56 +03:00
|
|
|
|
2016-09-20 08:04:23 +03:00
|
|
|
from .settings import graphene_settings
|
|
|
|
|
|
|
|
|
|
|
|
class HttpError(Exception):
|
|
|
|
def __init__(self, response, message=None, *args, **kwargs):
|
|
|
|
self.response = response
|
|
|
|
self.message = message = message or response.content.decode()
|
|
|
|
super(HttpError, self).__init__(message, *args, **kwargs)
|
|
|
|
|
|
|
|
|
|
|
|
def get_accepted_content_types(request):
|
|
|
|
def qualify(x):
|
2018-07-20 02:51:33 +03:00
|
|
|
parts = x.split(";", 1)
|
2016-09-20 08:04:23 +03:00
|
|
|
if len(parts) == 2:
|
2018-07-20 02:51:33 +03:00
|
|
|
match = re.match(r"(^|;)q=(0(\.\d{,3})?|1(\.0{,3})?)(;|$)", parts[1])
|
2016-09-20 08:04:23 +03:00
|
|
|
if match:
|
2017-12-12 05:08:42 +03:00
|
|
|
return parts[0].strip(), float(match.group(2))
|
|
|
|
return parts[0].strip(), 1
|
2016-09-20 08:04:23 +03:00
|
|
|
|
2018-07-20 02:51:33 +03:00
|
|
|
raw_content_types = request.META.get("HTTP_ACCEPT", "*/*").split(",")
|
2016-09-20 08:04:23 +03:00
|
|
|
qualified_content_types = map(qualify, raw_content_types)
|
2018-07-20 02:51:33 +03:00
|
|
|
return list(
|
|
|
|
x[0] for x in sorted(qualified_content_types, key=lambda x: x[1], reverse=True)
|
|
|
|
)
|
2016-09-20 08:04:23 +03:00
|
|
|
|
|
|
|
|
2016-09-20 08:33:46 +03:00
|
|
|
def instantiate_middleware(middlewares):
|
|
|
|
for middleware in middlewares:
|
|
|
|
if inspect.isclass(middleware):
|
|
|
|
yield middleware()
|
|
|
|
continue
|
|
|
|
yield middleware
|
|
|
|
|
|
|
|
|
2016-09-20 08:04:23 +03:00
|
|
|
class GraphQLView(View):
|
2018-07-20 02:51:33 +03:00
|
|
|
graphiql_template = "graphene/graphiql.html"
|
2020-07-12 22:48:12 +03:00
|
|
|
|
|
|
|
# Polyfill for window.fetch.
|
|
|
|
whatwg_fetch_version = "3.2.0"
|
|
|
|
whatwg_fetch_sri = "sha256-l6HCB9TT2v89oWbDdo2Z3j+PSVypKNLA/nqfzSbM8mo="
|
|
|
|
|
|
|
|
# React and ReactDOM.
|
2020-07-12 16:42:31 +03:00
|
|
|
react_version = "16.13.1"
|
2020-07-12 22:48:12 +03:00
|
|
|
react_sri = "sha256-yUhvEmYVhZ/GGshIQKArLvySDSh6cdmdcIx0spR3UP4="
|
|
|
|
react_dom_sri = "sha256-vFt3l+illeNlwThbDUdoPTqF81M8WNSZZZt3HEjsbSU="
|
|
|
|
|
|
|
|
# The GraphiQL React app.
|
|
|
|
graphiql_version = "1.0.3"
|
|
|
|
graphiql_sri = "sha256-VR4buIDY9ZXSyCNFHFNik6uSe0MhigCzgN4u7moCOTk="
|
|
|
|
graphiql_css_sri = "sha256-LwqxjyZgqXDYbpxQJ5zLQeNcf7WVNSJ+r8yp2rnWE/E="
|
|
|
|
|
|
|
|
# The websocket transport library for subscriptions.
|
|
|
|
subscriptions_transport_ws_version = "0.9.17"
|
|
|
|
subscriptions_transport_ws_sri = (
|
|
|
|
"sha256-kCDzver8iRaIQ/SVlfrIwxaBQ/avXf9GQFJRLlErBnk="
|
|
|
|
)
|
2016-09-20 08:04:23 +03:00
|
|
|
|
2016-09-20 08:50:51 +03:00
|
|
|
schema = None
|
2016-09-20 08:04:23 +03:00
|
|
|
graphiql = False
|
|
|
|
executor = None
|
2018-06-05 11:24:53 +03:00
|
|
|
backend = None
|
2016-09-20 08:04:23 +03:00
|
|
|
middleware = None
|
|
|
|
root_value = None
|
|
|
|
pretty = False
|
2016-10-31 13:56:51 +03:00
|
|
|
batch = False
|
2020-07-12 16:42:31 +03:00
|
|
|
subscription_path = None
|
2016-09-20 08:04:23 +03:00
|
|
|
|
2018-07-20 02:51:33 +03:00
|
|
|
def __init__(
|
|
|
|
self,
|
|
|
|
schema=None,
|
|
|
|
executor=None,
|
|
|
|
middleware=None,
|
|
|
|
root_value=None,
|
|
|
|
graphiql=False,
|
|
|
|
pretty=False,
|
|
|
|
batch=False,
|
|
|
|
backend=None,
|
2020-07-12 16:42:31 +03:00
|
|
|
subscription_path=None,
|
2018-07-20 02:51:33 +03:00
|
|
|
):
|
2016-09-20 08:04:23 +03:00
|
|
|
if not schema:
|
|
|
|
schema = graphene_settings.SCHEMA
|
|
|
|
|
2018-06-05 11:24:53 +03:00
|
|
|
if backend is None:
|
|
|
|
backend = get_default_backend()
|
|
|
|
|
2016-09-20 08:04:23 +03:00
|
|
|
if middleware is None:
|
|
|
|
middleware = graphene_settings.MIDDLEWARE
|
|
|
|
|
2017-07-11 13:03:08 +03:00
|
|
|
self.schema = self.schema or schema
|
2016-09-20 08:33:46 +03:00
|
|
|
if middleware is not None:
|
2020-05-09 14:15:16 +03:00
|
|
|
if isinstance(middleware, MiddlewareManager):
|
|
|
|
self.middleware = middleware
|
|
|
|
else:
|
|
|
|
self.middleware = list(instantiate_middleware(middleware))
|
2016-09-20 08:04:23 +03:00
|
|
|
self.executor = executor
|
|
|
|
self.root_value = root_value
|
2017-07-11 13:03:08 +03:00
|
|
|
self.pretty = self.pretty or pretty
|
|
|
|
self.graphiql = self.graphiql or graphiql
|
|
|
|
self.batch = self.batch or batch
|
2018-06-05 11:24:53 +03:00
|
|
|
self.backend = backend
|
2020-07-12 16:42:31 +03:00
|
|
|
if subscription_path is None:
|
2020-07-12 22:48:12 +03:00
|
|
|
self.subscription_path = graphene_settings.SUBSCRIPTION_PATH
|
2016-09-20 08:04:23 +03:00
|
|
|
|
2017-10-25 20:54:13 +03:00
|
|
|
assert isinstance(
|
2018-07-20 02:51:33 +03:00
|
|
|
self.schema, GraphQLSchema
|
|
|
|
), "A Schema is required to be provided to GraphQLView."
|
|
|
|
assert not all((graphiql, batch)), "Use either graphiql or batch processing"
|
2016-09-20 08:04:23 +03:00
|
|
|
|
|
|
|
# noinspection PyUnusedLocal
|
|
|
|
def get_root_value(self, request):
|
|
|
|
return self.root_value
|
|
|
|
|
|
|
|
def get_middleware(self, request):
|
|
|
|
return self.middleware
|
|
|
|
|
|
|
|
def get_context(self, request):
|
|
|
|
return request
|
|
|
|
|
2018-06-05 11:24:53 +03:00
|
|
|
def get_backend(self, request):
|
|
|
|
return self.backend
|
|
|
|
|
2016-09-20 09:14:59 +03:00
|
|
|
@method_decorator(ensure_csrf_cookie)
|
2016-09-20 08:04:23 +03:00
|
|
|
def dispatch(self, request, *args, **kwargs):
|
|
|
|
try:
|
2018-07-20 02:51:33 +03:00
|
|
|
if request.method.lower() not in ("get", "post"):
|
|
|
|
raise HttpError(
|
|
|
|
HttpResponseNotAllowed(
|
|
|
|
["GET", "POST"], "GraphQL only supports GET and POST requests."
|
|
|
|
)
|
|
|
|
)
|
2016-09-20 08:04:23 +03:00
|
|
|
|
|
|
|
data = self.parse_body(request)
|
2018-07-20 02:51:33 +03:00
|
|
|
show_graphiql = self.graphiql and self.can_display_graphiql(request, data)
|
2016-09-20 08:04:23 +03:00
|
|
|
|
2018-08-30 21:29:33 +03:00
|
|
|
if show_graphiql:
|
|
|
|
return self.render_graphiql(
|
2019-05-20 14:41:25 +03:00
|
|
|
request,
|
2020-07-12 22:48:12 +03:00
|
|
|
# Dependency parameters.
|
|
|
|
whatwg_fetch_version=self.whatwg_fetch_version,
|
|
|
|
whatwg_fetch_sri=self.whatwg_fetch_sri,
|
2019-05-20 14:41:25 +03:00
|
|
|
react_version=self.react_version,
|
2020-07-12 22:48:12 +03:00
|
|
|
react_sri=self.react_sri,
|
|
|
|
react_dom_sri=self.react_dom_sri,
|
|
|
|
graphiql_version=self.graphiql_version,
|
|
|
|
graphiql_sri=self.graphiql_sri,
|
|
|
|
graphiql_css_sri=self.graphiql_css_sri,
|
2020-07-12 16:42:31 +03:00
|
|
|
subscriptions_transport_ws_version=self.subscriptions_transport_ws_version,
|
2020-07-12 22:48:12 +03:00
|
|
|
subscriptions_transport_ws_sri=self.subscriptions_transport_ws_sri,
|
|
|
|
# The SUBSCRIPTION_PATH setting.
|
2020-07-12 16:42:31 +03:00
|
|
|
subscription_path=self.subscription_path,
|
2018-08-30 21:29:33 +03:00
|
|
|
)
|
|
|
|
|
2016-10-31 13:56:51 +03:00
|
|
|
if self.batch:
|
|
|
|
responses = [self.get_response(request, entry) for entry in data]
|
2018-07-20 02:51:33 +03:00
|
|
|
result = "[{}]".format(
|
|
|
|
",".join([response[0] for response in responses])
|
|
|
|
)
|
|
|
|
status_code = (
|
|
|
|
responses
|
|
|
|
and max(responses, key=lambda response: response[1])[1]
|
|
|
|
or 200
|
|
|
|
)
|
2016-09-20 08:04:23 +03:00
|
|
|
else:
|
2018-07-20 02:51:33 +03:00
|
|
|
result, status_code = self.get_response(request, data, show_graphiql)
|
2016-09-20 08:04:23 +03:00
|
|
|
|
|
|
|
return HttpResponse(
|
2018-07-20 02:51:33 +03:00
|
|
|
status=status_code, content=result, content_type="application/json"
|
2016-09-20 08:04:23 +03:00
|
|
|
)
|
|
|
|
|
|
|
|
except HttpError as e:
|
|
|
|
response = e.response
|
2018-07-20 02:51:33 +03:00
|
|
|
response["Content-Type"] = "application/json"
|
|
|
|
response.content = self.json_encode(
|
|
|
|
request, {"errors": [self.format_error(e)]}
|
|
|
|
)
|
2016-09-20 08:04:23 +03:00
|
|
|
return response
|
|
|
|
|
2016-10-31 13:56:51 +03:00
|
|
|
def get_response(self, request, data, show_graphiql=False):
|
2018-07-20 02:51:33 +03:00
|
|
|
query, variables, operation_name, id = self.get_graphql_params(request, data)
|
2016-10-31 13:56:51 +03:00
|
|
|
|
|
|
|
execution_result = self.execute_graphql_request(
|
2018-07-20 02:51:33 +03:00
|
|
|
request, data, query, variables, operation_name, show_graphiql
|
2016-10-31 13:56:51 +03:00
|
|
|
)
|
|
|
|
|
2016-10-31 14:16:58 +03:00
|
|
|
status_code = 200
|
2016-10-31 13:56:51 +03:00
|
|
|
if execution_result:
|
|
|
|
response = {}
|
|
|
|
|
|
|
|
if execution_result.errors:
|
2018-07-20 02:51:33 +03:00
|
|
|
response["errors"] = [
|
|
|
|
self.format_error(e) for e in execution_result.errors
|
|
|
|
]
|
2016-10-31 13:56:51 +03:00
|
|
|
|
|
|
|
if execution_result.invalid:
|
|
|
|
status_code = 400
|
|
|
|
else:
|
2018-07-20 02:51:33 +03:00
|
|
|
response["data"] = execution_result.data
|
2016-10-31 13:56:51 +03:00
|
|
|
|
|
|
|
if self.batch:
|
2018-07-20 02:51:33 +03:00
|
|
|
response["id"] = id
|
|
|
|
response["status"] = status_code
|
2016-10-31 13:56:51 +03:00
|
|
|
|
|
|
|
result = self.json_encode(request, response, pretty=show_graphiql)
|
|
|
|
else:
|
|
|
|
result = None
|
|
|
|
|
|
|
|
return result, status_code
|
|
|
|
|
2016-09-20 08:04:23 +03:00
|
|
|
def render_graphiql(self, request, **data):
|
|
|
|
return render(request, self.graphiql_template, data)
|
|
|
|
|
|
|
|
def json_encode(self, request, d, pretty=False):
|
2018-07-20 02:51:33 +03:00
|
|
|
if not (self.pretty or pretty) and not request.GET.get("pretty"):
|
|
|
|
return json.dumps(d, separators=(",", ":"))
|
2016-09-20 08:04:23 +03:00
|
|
|
|
2018-07-20 02:51:33 +03:00
|
|
|
return json.dumps(d, sort_keys=True, indent=2, separators=(",", ": "))
|
2016-09-20 08:04:23 +03:00
|
|
|
|
|
|
|
def parse_body(self, request):
|
|
|
|
content_type = self.get_content_type(request)
|
|
|
|
|
2018-07-20 02:51:33 +03:00
|
|
|
if content_type == "application/graphql":
|
|
|
|
return {"query": request.body.decode()}
|
2016-09-20 08:04:23 +03:00
|
|
|
|
2018-07-20 02:51:33 +03:00
|
|
|
elif content_type == "application/json":
|
2017-04-12 13:25:51 +03:00
|
|
|
# noinspection PyBroadException
|
2016-09-20 08:04:23 +03:00
|
|
|
try:
|
2018-07-20 02:51:33 +03:00
|
|
|
body = request.body.decode("utf-8")
|
2017-04-12 13:25:51 +03:00
|
|
|
except Exception as e:
|
|
|
|
raise HttpError(HttpResponseBadRequest(str(e)))
|
|
|
|
|
|
|
|
try:
|
|
|
|
request_json = json.loads(body)
|
2016-10-31 13:56:51 +03:00
|
|
|
if self.batch:
|
2017-02-20 12:08:42 +03:00
|
|
|
assert isinstance(request_json, list), (
|
2018-07-20 02:51:33 +03:00
|
|
|
"Batch requests should receive a list, but received {}."
|
2017-02-20 12:08:42 +03:00
|
|
|
).format(repr(request_json))
|
2018-07-20 02:51:33 +03:00
|
|
|
assert (
|
|
|
|
len(request_json) > 0
|
|
|
|
), "Received an empty list in the batch request."
|
2016-10-31 13:56:51 +03:00
|
|
|
else:
|
2018-07-20 02:51:33 +03:00
|
|
|
assert isinstance(
|
|
|
|
request_json, dict
|
|
|
|
), "The received data is not a valid JSON query."
|
2016-09-20 08:04:23 +03:00
|
|
|
return request_json
|
2017-02-20 12:08:42 +03:00
|
|
|
except AssertionError as e:
|
|
|
|
raise HttpError(HttpResponseBadRequest(str(e)))
|
2017-04-12 13:25:51 +03:00
|
|
|
except (TypeError, ValueError):
|
2018-07-20 02:51:33 +03:00
|
|
|
raise HttpError(HttpResponseBadRequest("POST body sent invalid JSON."))
|
2016-09-20 08:04:23 +03:00
|
|
|
|
2018-07-20 02:51:33 +03:00
|
|
|
elif content_type in [
|
|
|
|
"application/x-www-form-urlencoded",
|
|
|
|
"multipart/form-data",
|
|
|
|
]:
|
2016-09-20 08:04:23 +03:00
|
|
|
return request.POST
|
|
|
|
|
|
|
|
return {}
|
|
|
|
|
2018-07-20 02:51:33 +03:00
|
|
|
def execute_graphql_request(
|
|
|
|
self, request, data, query, variables, operation_name, show_graphiql=False
|
|
|
|
):
|
2016-09-20 08:04:23 +03:00
|
|
|
if not query:
|
|
|
|
if show_graphiql:
|
|
|
|
return None
|
2018-07-20 02:51:33 +03:00
|
|
|
raise HttpError(HttpResponseBadRequest("Must provide query string."))
|
2016-09-20 08:04:23 +03:00
|
|
|
|
|
|
|
try:
|
2018-06-05 11:24:53 +03:00
|
|
|
backend = self.get_backend(request)
|
|
|
|
document = backend.document_from_string(self.schema, query)
|
2016-09-20 08:04:23 +03:00
|
|
|
except Exception as e:
|
|
|
|
return ExecutionResult(errors=[e], invalid=True)
|
|
|
|
|
2018-07-20 02:51:33 +03:00
|
|
|
if request.method.lower() == "get":
|
2018-06-05 11:24:53 +03:00
|
|
|
operation_type = document.get_operation_type(operation_name)
|
2018-07-20 02:51:33 +03:00
|
|
|
if operation_type and operation_type != "query":
|
2016-09-20 08:04:23 +03:00
|
|
|
if show_graphiql:
|
|
|
|
return None
|
2016-09-20 08:15:10 +03:00
|
|
|
|
2018-07-20 02:51:33 +03:00
|
|
|
raise HttpError(
|
|
|
|
HttpResponseNotAllowed(
|
|
|
|
["POST"],
|
|
|
|
"Can only perform a {} operation from a POST request.".format(
|
|
|
|
operation_type
|
|
|
|
),
|
|
|
|
)
|
|
|
|
)
|
2016-09-20 08:04:23 +03:00
|
|
|
|
|
|
|
try:
|
2018-06-05 11:24:53 +03:00
|
|
|
extra_options = {}
|
|
|
|
if self.executor:
|
|
|
|
# We only include it optionally since
|
|
|
|
# executor is not a valid argument in all backends
|
2018-07-20 02:51:33 +03:00
|
|
|
extra_options["executor"] = self.executor
|
2018-06-05 11:24:53 +03:00
|
|
|
|
|
|
|
return document.execute(
|
2020-02-23 12:50:40 +03:00
|
|
|
root_value=self.get_root_value(request),
|
|
|
|
variable_values=variables,
|
2016-09-20 08:04:23 +03:00
|
|
|
operation_name=operation_name,
|
2020-02-23 12:50:40 +03:00
|
|
|
context_value=self.get_context(request),
|
2016-09-20 10:08:14 +03:00
|
|
|
middleware=self.get_middleware(request),
|
2018-06-05 11:24:53 +03:00
|
|
|
**extra_options
|
2016-09-20 08:04:23 +03:00
|
|
|
)
|
|
|
|
except Exception as e:
|
|
|
|
return ExecutionResult(errors=[e], invalid=True)
|
|
|
|
|
|
|
|
@classmethod
|
|
|
|
def can_display_graphiql(cls, request, data):
|
2018-07-20 02:51:33 +03:00
|
|
|
raw = "raw" in request.GET or "raw" in data
|
2016-09-20 08:04:23 +03:00
|
|
|
return not raw and cls.request_wants_html(request)
|
|
|
|
|
|
|
|
@classmethod
|
|
|
|
def request_wants_html(cls, request):
|
|
|
|
accepted = get_accepted_content_types(request)
|
2017-12-12 05:08:42 +03:00
|
|
|
accepted_length = len(accepted)
|
2017-12-18 19:40:19 +03:00
|
|
|
# the list will be ordered in preferred first - so we have to make
|
|
|
|
# sure the most preferred gets the highest number
|
2018-07-20 02:51:33 +03:00
|
|
|
html_priority = (
|
|
|
|
accepted_length - accepted.index("text/html")
|
|
|
|
if "text/html" in accepted
|
|
|
|
else 0
|
|
|
|
)
|
|
|
|
json_priority = (
|
|
|
|
accepted_length - accepted.index("application/json")
|
|
|
|
if "application/json" in accepted
|
|
|
|
else 0
|
|
|
|
)
|
2016-09-20 08:04:23 +03:00
|
|
|
|
2017-12-17 03:32:01 +03:00
|
|
|
return html_priority > json_priority
|
2016-09-20 08:04:23 +03:00
|
|
|
|
|
|
|
@staticmethod
|
|
|
|
def get_graphql_params(request, data):
|
2018-07-20 02:51:33 +03:00
|
|
|
query = request.GET.get("query") or data.get("query")
|
|
|
|
variables = request.GET.get("variables") or data.get("variables")
|
|
|
|
id = request.GET.get("id") or data.get("id")
|
2016-09-20 08:04:23 +03:00
|
|
|
|
|
|
|
if variables and isinstance(variables, six.text_type):
|
|
|
|
try:
|
|
|
|
variables = json.loads(variables)
|
2017-10-25 20:54:13 +03:00
|
|
|
except Exception:
|
2018-07-20 02:51:33 +03:00
|
|
|
raise HttpError(HttpResponseBadRequest("Variables are invalid JSON."))
|
2016-09-20 08:04:23 +03:00
|
|
|
|
2018-07-20 02:51:33 +03:00
|
|
|
operation_name = request.GET.get("operationName") or data.get("operationName")
|
2017-04-13 20:11:10 +03:00
|
|
|
if operation_name == "null":
|
|
|
|
operation_name = None
|
2016-09-20 08:04:23 +03:00
|
|
|
|
2016-10-31 13:56:51 +03:00
|
|
|
return query, variables, operation_name, id
|
2016-09-20 08:04:23 +03:00
|
|
|
|
|
|
|
@staticmethod
|
|
|
|
def format_error(error):
|
|
|
|
if isinstance(error, GraphQLError):
|
|
|
|
return format_graphql_error(error)
|
|
|
|
|
2018-07-20 02:51:33 +03:00
|
|
|
return {"message": six.text_type(error)}
|
2016-09-20 08:04:23 +03:00
|
|
|
|
|
|
|
@staticmethod
|
|
|
|
def get_content_type(request):
|
|
|
|
meta = request.META
|
2018-07-20 02:51:33 +03:00
|
|
|
content_type = meta.get("CONTENT_TYPE", meta.get("HTTP_CONTENT_TYPE", ""))
|
|
|
|
return content_type.split(";", 1)[0].lower()
|