Merge pull request #4989 from nsoranzo/fix_allow-register

Fix allow-register option in auth module
This commit is contained in:
John Chilton
2017-11-13 12:17:43 -05:00
committed by GitHub
3 changed files with 17 additions and 24 deletions
+11 -16
View File
@@ -7,7 +7,7 @@ import xml.etree.ElementTree
from collections import namedtuple
from galaxy.security.validate_user_input import validate_publicname
from galaxy.util import plugin_config, string_as_bool, string_as_bool_or_none
from galaxy.util import plugin_config, string_as_bool
log = logging.getLogger(__name__)
@@ -55,8 +55,8 @@ class AuthManager(object):
message = ''
status = 'done'
for provider, options in self.active_authenticators(email, username, password):
allow_reg = _get_tri_state(options, 'allow-register', True)
if allow_reg is None: # i.e. challenge
allow_reg = _get_allow_register(options)
if allow_reg == 'challenge':
auth_result, msg = provider.authenticate(email, username, password, options)
if auth_result is True:
break
@@ -102,7 +102,7 @@ class AuthManager(object):
else:
break # end for loop if we can't make a unique username
log.debug("Email: %s, auto-register with username: %s" % (auto_email, auto_username))
return (_get_bool(options, 'auto-register', False), auto_email, auto_username)
return (string_as_bool(options.get('auto-register', False)), auto_email, auto_username)
elif auth_result is None:
log.debug("Email: %s, Username %s, stopping due to failed non-continue" % (auto_email, auto_username))
break # end authentication (skip rest)
@@ -131,7 +131,7 @@ class AuthManager(object):
else:
auth_result = provider.authenticate_user(user, current_password, options)
if auth_result is True:
if _get_bool(options, "allow-password-change", False):
if string_as_bool(options.get("allow-password-change", False)):
return (True, '') # accept user
else:
return (False, 'Password change not supported.')
@@ -160,15 +160,10 @@ class AuthManager(object):
Authenticator = namedtuple('Authenticator', ['plugin', 'filter_template', 'options'])
def _get_bool(d, k, o):
if k in d:
return string_as_bool(d[k])
def _get_allow_register(d):
s = d.get('allow-register', True)
lower_s = str(s).lower()
if lower_s == 'challenge':
return lower_s
else:
return o
def _get_tri_state(d, k, o):
if k in d:
return string_as_bool_or_none(d[k])
else:
return o
return string_as_bool(s)
+2 -3
View File
@@ -6,9 +6,8 @@ Created on 15/07/2014
import logging
from galaxy.auth import _get_bool
from galaxy.exceptions import ConfigurationError
from galaxy.util import string_as_bool
from ..providers import AuthProvider
log = logging.getLogger(__name__)
@@ -84,7 +83,7 @@ class LDAP(AuthProvider):
if options.get('continue-on-failure', 'False') == 'False':
failure_mode = None # reject and do not continue
if _get_bool(options, 'login-use-username', False):
if string_as_bool(options.get('login-use-username', False)):
if username is None:
log.debug('LDAP authenticate: username must be used to login, cannot be None')
return (failure_mode, '', '')
+4 -5
View File
@@ -7,8 +7,7 @@ import logging
import shlex
from subprocess import PIPE, Popen
from galaxy.auth import _get_bool
from galaxy.util import string_as_bool
from ..providers import AuthProvider
log = logging.getLogger(__name__)
@@ -65,7 +64,7 @@ class PAM(AuthProvider):
log.debug("use username: {} use email {} email {} username {}".format(options.get('login-use-username'), options.get('login-use-email', False), email, username))
# check email based login first because if email exists in Galaxy DB
# we will be given the "public name" as username
if _get_bool(options, 'login-use-email', False) and email is not None:
if string_as_bool(options.get('login-use-email', False)) and email is not None:
if '@' in email:
(email_user, email_domain) = email.split('@')
pam_username = email_user
@@ -82,7 +81,7 @@ class PAM(AuthProvider):
else:
log.debug('PAM authenticate: email must be used to login, but no valid email found')
force_fail = True
elif _get_bool(options, 'login-use-username', False):
elif string_as_bool(options.get('login-use-username', False)):
# if we get here via authenticate_user then
# user will be "public name" and
# email address will be as per registered user
@@ -106,7 +105,7 @@ class PAM(AuthProvider):
return None, '', ''
pam_service = options.get('pam-service', 'galaxy')
use_helper = _get_bool(options, 'use-external-helper', False)
use_helper = string_as_bool(options.get('use-external-helper', False))
log.debug("PAM auth: will use external helper: {}".format(use_helper))
authenticated = False
if use_helper: