mirror of
https://github.com/galaxyproject/galaxy.git
synced 2026-09-24 16:30:27 +08:00
Merge remote-tracking branch 'upstream/release_21.05' into dev
This commit is contained in:
@@ -90,6 +90,7 @@ class CustosAuthnz(IdentityProvider):
|
||||
else:
|
||||
userinfo = self._get_userinfo(oauth2_session)
|
||||
email = userinfo['email']
|
||||
username = userinfo.get('preferred_username', self._generate_username(trans, email))
|
||||
user_id = userinfo['sub']
|
||||
|
||||
# Create or update custos_authnz_token record
|
||||
@@ -113,9 +114,13 @@ class CustosAuthnz(IdentityProvider):
|
||||
message = f"There already exists a user with email {email}. To associate this external login, you must first be logged in as that existing account."
|
||||
log.exception(message)
|
||||
raise exceptions.AuthenticationFailed(message)
|
||||
else:
|
||||
elif self.config['provider'] == 'custos':
|
||||
login_redirect_url = f"{login_redirect_url}root/login?confirm=true&custos_token={json.dumps(token)}"
|
||||
return login_redirect_url, None
|
||||
else:
|
||||
user = trans.app.user_manager.create(email=email, username=username)
|
||||
if trans.app.config.user_activation_on:
|
||||
trans.app.user_manager.send_activation_email(trans, email, username)
|
||||
|
||||
custos_authnz_token = CustosAuthnzToken(user=user,
|
||||
external_user_id=user_id,
|
||||
@@ -133,7 +138,7 @@ class CustosAuthnz(IdentityProvider):
|
||||
custos_authnz_token.refresh_expiration_time = refresh_expiration_time
|
||||
trans.sa_session.add(custos_authnz_token)
|
||||
trans.sa_session.flush()
|
||||
return login_redirect_url, custos_authnz_token.user
|
||||
return "/", custos_authnz_token.user
|
||||
|
||||
def create_user(self, token, trans, login_redirect_url):
|
||||
token_dict = json.loads(token)
|
||||
@@ -309,7 +314,7 @@ class CustosAuthnz(IdentityProvider):
|
||||
self.config['authorization_endpoint'] = well_known_oidc_config['authorization_endpoint']
|
||||
self.config['token_endpoint'] = well_known_oidc_config['token_endpoint']
|
||||
self.config['userinfo_endpoint'] = well_known_oidc_config['userinfo_endpoint']
|
||||
self.config['end_session_endpoint'] = well_known_oidc_config['end_session_endpoint']
|
||||
self.config['end_session_endpoint'] = well_known_oidc_config.get('end_session_endpoint')
|
||||
|
||||
def _get_verify_param(self):
|
||||
"""Return 'ca_bundle' if 'verify_ssl' is true and 'ca_bundle' is configured."""
|
||||
|
||||
@@ -117,6 +117,10 @@ def preprocess_volumes(volumes_raw_str, container_type):
|
||||
ro for Singularity iff no subdirectories are rw (Singularity does not allow ro
|
||||
parent directories with rw subdirectories).
|
||||
|
||||
>>> preprocess_volumes(None, DOCKER_CONTAINER_TYPE)
|
||||
[]
|
||||
>>> preprocess_volumes("", DOCKER_CONTAINER_TYPE)
|
||||
[]
|
||||
>>> preprocess_volumes("/a/b", DOCKER_CONTAINER_TYPE)
|
||||
['/a/b:rw']
|
||||
>>> preprocess_volumes("/a/b:ro,/a/b/c:rw", DOCKER_CONTAINER_TYPE)
|
||||
@@ -131,6 +135,9 @@ def preprocess_volumes(volumes_raw_str, container_type):
|
||||
['/a/b', '/a/b/c']
|
||||
"""
|
||||
|
||||
if not volumes_raw_str:
|
||||
return []
|
||||
|
||||
volumes_raw_strs = [v.strip() for v in volumes_raw_str.split(",")]
|
||||
volumes = []
|
||||
rw_paths = []
|
||||
|
||||
@@ -322,7 +322,7 @@ class CustosAuthnzTestCase(unittest.TestCase):
|
||||
self.assertTrue(self._create_oauth2_session_called)
|
||||
self.assertTrue(self._fetch_token_called)
|
||||
self.assertTrue(self._get_userinfo_called)
|
||||
self.assertEqual(login_redirect_url, "http://localhost:8000/")
|
||||
self.assertEqual(login_redirect_url, "/")
|
||||
self.assertIsNotNone(user)
|
||||
|
||||
def test_callback_nonce_validation_with_bad_nonce(self):
|
||||
|
||||
Reference in New Issue
Block a user