+18


![dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>](/assets/img/avatar_default.png)

![autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>](/assets/img/avatar_default.png)




FFXN
GitHub
yyh
盐粒 Yanli
autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Tianle
dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Yunlu Wen
zyssyz123
Claude Opus 4.7
chariri
Asuka Minato
Copilot Autofix powered by AI
Nian
非法操作
Carmen Fernández Ruiz
wangxiaolei
QuantumGhost
L1nSn0w
Evan
Escape0707
Jingyi
Amr Sherif
ZHOU ZHICHEN
unknown
JzoNg
Xiyuan Chen
-LAN-
107bba0116
Signed-off-by: dependabot[bot] <[email protected]> Signed-off-by: EvanYao826 <[email protected]> Co-authored-by: yyh <[email protected]> Co-authored-by: 盐粒 Yanli <[email protected]> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Tianle <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Yunlu Wen <[email protected]> Co-authored-by: zyssyz123 <[email protected]> Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]> Co-authored-by: chariri <[email protected]> Co-authored-by: Asuka Minato <[email protected]> Co-authored-by: Copilot Autofix powered by AI <[email protected]> Co-authored-by: Nian <[email protected]> Co-authored-by: 非法操作 <[email protected]> Co-authored-by: Carmen Fernández Ruiz <[email protected]> Co-authored-by: wangxiaolei <[email protected]> Co-authored-by: QuantumGhost <[email protected]> Co-authored-by: L1nSn0w <[email protected]> Co-authored-by: Evan <[email protected]> Co-authored-by: Escape0707 <[email protected]> Co-authored-by: Jingyi <[email protected]> Co-authored-by: Amr Sherif <[email protected]> Co-authored-by: ZHOU ZHICHEN <[email protected]> Co-authored-by: unknown <[email protected]> Co-authored-by: JzoNg <[email protected]> Co-authored-by: Xiyuan Chen <[email protected]> Co-authored-by: -LAN- <[email protected]>
68 lines
2.4 KiB
Python
68 lines
2.4 KiB
Python
from __future__ import annotations
|
|
|
|
from werkzeug.exceptions import Forbidden, InternalServerError, NotFound, Unauthorized
|
|
|
|
from controllers.openapi.auth.data import AuthData
|
|
from core.app.entities.app_invoke_entities import InvokeFrom
|
|
from extensions.ext_database import db
|
|
from models.account import TenantStatus
|
|
from services.account_service import AccountService, TenantService
|
|
from services.app_service import AppService
|
|
from services.end_user_service import EndUserService
|
|
from services.enterprise.enterprise_service import EnterpriseService, WebAppAccessMode
|
|
|
|
|
|
def load_app(data: AuthData) -> None:
|
|
app_id = data.path_params["app_id"]
|
|
app = AppService.get_app_by_id(db.session, app_id)
|
|
if not app or app.status != "normal":
|
|
raise NotFound("app not found")
|
|
if not app.enable_api:
|
|
raise Forbidden("service_api_disabled")
|
|
data.app = app
|
|
|
|
|
|
def load_tenant(data: AuthData) -> None:
|
|
if data.app is None:
|
|
raise InternalServerError("pipeline_invariant_violated: app not loaded before load_tenant")
|
|
tenant = TenantService.get_tenant_by_id(db.session, str(data.app.tenant_id))
|
|
if tenant is None or tenant.status == TenantStatus.ARCHIVE:
|
|
raise Forbidden("workspace unavailable")
|
|
data.tenant = tenant
|
|
|
|
|
|
def load_account(data: AuthData) -> None:
|
|
account = AccountService.get_account_by_id(db.session, str(data.account_id))
|
|
if account is None:
|
|
raise Unauthorized("account not found")
|
|
if data.tenant:
|
|
account.current_tenant = data.tenant
|
|
data.caller = account
|
|
data.caller_kind = "account"
|
|
|
|
|
|
def resolve_external_user(data: AuthData) -> None:
|
|
if data.tenant is None or data.app is None or data.external_identity is None:
|
|
raise Unauthorized("missing context for external user resolution")
|
|
end_user = EndUserService.get_or_create_end_user_by_type(
|
|
InvokeFrom.OPENAPI,
|
|
tenant_id=str(data.tenant.id),
|
|
app_id=str(data.app.id),
|
|
user_id=data.external_identity.email,
|
|
)
|
|
data.caller = end_user
|
|
data.caller_kind = "end_user"
|
|
|
|
|
|
def load_app_access_mode(data: AuthData) -> None:
|
|
if data.app is None:
|
|
return
|
|
try:
|
|
settings = EnterpriseService.WebAppAuth.get_app_access_mode_by_id(app_id=str(data.app.id))
|
|
if settings is None:
|
|
data.app_access_mode = None
|
|
return
|
|
data.app_access_mode = WebAppAccessMode(settings.access_mode)
|
|
except ValueError:
|
|
data.app_access_mode = None
|