From 7257de1722318226e7e621054e7009eed5400285 Mon Sep 17 00:00:00 2001 From: Alexandru Mahmoud Date: Mon, 14 Jun 2021 16:57:02 -0400 Subject: [PATCH 1/4] Temporary fix for keycloak OIDC --- lib/galaxy/authnz/custos_authnz.py | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/lib/galaxy/authnz/custos_authnz.py b/lib/galaxy/authnz/custos_authnz.py index f2a22191dd3..e5eef15b196 100644 --- a/lib/galaxy/authnz/custos_authnz.py +++ b/lib/galaxy/authnz/custos_authnz.py @@ -87,6 +87,7 @@ class CustosAuthnz(IdentityProvider): else: userinfo = self._get_userinfo(oauth2_session) email = userinfo['email'] + username = userinfo.get('preferred_username', self._generate_username(trans, email)) user_id = userinfo['sub'] # Create or update custos_authnz_token record @@ -110,9 +111,13 @@ class CustosAuthnz(IdentityProvider): message = "There already exists a user with email %s. To associate this external login, you must first be logged in as that existing account." % email log.exception(message) raise exceptions.AuthenticationFailed(message) - else: - login_redirect_url = login_redirect_url + 'root/login?confirm=true&custos_token=' + json.dumps(token) + elif self.config['provider'] == 'custos': + login_redirect_url = f"{login_redirect_url}root/login?confirm=true&custos_token={json.dumps(token)}" return login_redirect_url, None + else: + user = trans.app.user_manager.create(email=email, username=username) + if trans.app.config.user_activation_on: + trans.app.user_manager.send_activation_email(trans, email, username) custos_authnz_token = CustosAuthnzToken(user=user, external_user_id=user_id, @@ -130,7 +135,7 @@ class CustosAuthnz(IdentityProvider): custos_authnz_token.refresh_expiration_time = refresh_expiration_time trans.sa_session.add(custos_authnz_token) trans.sa_session.flush() - return login_redirect_url, custos_authnz_token.user + return "/", custos_authnz_token.user def create_user(self, token, trans, login_redirect_url): token_dict = json.loads(token) From fb6522121cbb7d1dcf956e77f59e95d47c9d61b3 Mon Sep 17 00:00:00 2001 From: Nuwan Goonasekera <2070605+nuwang@users.noreply.github.com> Date: Sat, 31 Jul 2021 18:50:29 +0530 Subject: [PATCH 2/4] [21.05] Make authnz end session endpoint optional to support various providers --- lib/galaxy/authnz/custos_authnz.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/galaxy/authnz/custos_authnz.py b/lib/galaxy/authnz/custos_authnz.py index 73c5aa1d2c9..b9ed90c4aa8 100644 --- a/lib/galaxy/authnz/custos_authnz.py +++ b/lib/galaxy/authnz/custos_authnz.py @@ -310,7 +310,7 @@ class CustosAuthnz(IdentityProvider): self.config['authorization_endpoint'] = well_known_oidc_config['authorization_endpoint'] self.config['token_endpoint'] = well_known_oidc_config['token_endpoint'] self.config['userinfo_endpoint'] = well_known_oidc_config['userinfo_endpoint'] - self.config['end_session_endpoint'] = well_known_oidc_config['end_session_endpoint'] + self.config['end_session_endpoint'] = well_known_oidc_config.get('end_session_endpoint') def _get_verify_param(self): """Return 'ca_bundle' if 'verify_ssl' is true and 'ca_bundle' is configured.""" From 1fee6893248169c17dc69ad3c4961a4d0313b338 Mon Sep 17 00:00:00 2001 From: Nuwan Goonasekera <2070605+nuwang@users.noreply.github.com> Date: Mon, 26 Jul 2021 16:52:29 +0530 Subject: [PATCH 3/4] Allow absolute or relative url in assertion --- test/unit/authnz/test_custos_authnz.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/test/unit/authnz/test_custos_authnz.py b/test/unit/authnz/test_custos_authnz.py index 2b71f40d16b..4cf04f52215 100644 --- a/test/unit/authnz/test_custos_authnz.py +++ b/test/unit/authnz/test_custos_authnz.py @@ -313,7 +313,7 @@ class CustosAuthnzTestCase(unittest.TestCase): self.assertTrue(self._create_oauth2_session_called) self.assertTrue(self._fetch_token_called) self.assertTrue(self._get_userinfo_called) - self.assertEqual(login_redirect_url, "http://localhost:8000/") + self.assertEqual(login_redirect_url, "/") self.assertIsNotNone(user) def test_callback_nonce_validation_with_bad_nonce(self): From ed53b05f61aee216c1bf1aea933c9281d6050f8a Mon Sep 17 00:00:00 2001 From: Nate Coraor Date: Thu, 12 Aug 2021 16:50:18 -0400 Subject: [PATCH 4/4] Fix for empty docker_volumes/singularity_volumes in job config --- lib/galaxy/tool_util/deps/container_classes.py | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/lib/galaxy/tool_util/deps/container_classes.py b/lib/galaxy/tool_util/deps/container_classes.py index e9cc48803ec..29ec8bb7148 100644 --- a/lib/galaxy/tool_util/deps/container_classes.py +++ b/lib/galaxy/tool_util/deps/container_classes.py @@ -117,6 +117,10 @@ def preprocess_volumes(volumes_raw_str, container_type): ro for Singularity iff no subdirectories are rw (Singularity does not allow ro parent directories with rw subdirectories). + >>> preprocess_volumes(None, DOCKER_CONTAINER_TYPE) + [] + >>> preprocess_volumes("", DOCKER_CONTAINER_TYPE) + [] >>> preprocess_volumes("/a/b", DOCKER_CONTAINER_TYPE) ['/a/b:rw'] >>> preprocess_volumes("/a/b:ro,/a/b/c:rw", DOCKER_CONTAINER_TYPE) @@ -131,6 +135,9 @@ def preprocess_volumes(volumes_raw_str, container_type): ['/a/b', '/a/b/c'] """ + if not volumes_raw_str: + return [] + volumes_raw_strs = [v.strip() for v in volumes_raw_str.split(",")] volumes = [] rw_paths = []