Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions config/settings/base.py
Original file line number Diff line number Diff line change
Expand Up @@ -442,6 +442,10 @@
"SERVE_INCLUDE_SCHEMA": False,
# OTHER SETTINGS
"PREPROCESSING_HOOKS": ["documentcloud.core.utils.custom_preprocessing_hook"],
"POSTPROCESSING_HOOKS": [
"drf_spectacular.hooks.postprocess_schema_enums",
"documentcloud.core.utils.hide_processing_token",
],
}

AUTH_PAGE_LIMIT = env.int("AUTH_PAGE_LIMIT", default=1000)
Expand Down
42 changes: 42 additions & 0 deletions documentcloud/core/utils.py
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,48 @@
from documentcloud.users.stats_api.models import UserStats


class SquareletJWTAuthenticationScheme(OpenApiAuthenticationExtension):
"""Simply lets DRF advertise that you can use a JWT from Accounts to auth"""

target_class = "documentcloud.core.authentication.SquareletJWTAuthentication"
name = "jwtAuth"

def get_security_definition(self, auto_schema):
return {
"type": "http",
"scheme": "bearer",
"bearerFormat": "JWT",
"description": (
"JWT bearer token issued by MuckRock Accounts. "
"Obtain a token from https://accounts.muckrock.com/api/token/ "
"and refresh it at https://accounts.muckrock.com/api/refresh/. "
"Access tokens are valid for 5 minutes and "
"refresh tokens are valid for 24 hours"
"Send it as `Authorization: Bearer <token>`."
),
}


def hide_processing_token(
result, generator, request, public
): # pylint:disable=unused-argument
"""Since processing token is defined, we need to have it here
but pop it from security schemes as we are the only ones to use this token style
"""
result.get("components", {}).get("securitySchemes", {}).pop(
"ProcessingTokenAuthentication", None
)
for path_item in result.get("paths", {}).values():
for operation in path_item.values():
if isinstance(operation, dict) and "security" in operation:
operation["security"] = [
scheme
for scheme in operation["security"]
if "ProcessingTokenAuthentication" not in scheme
]
return result


class ProcessingTokenAuthenticationScheme(OpenApiAuthenticationExtension):
target_class = "documentcloud.core.authentication.ProcessingTokenAuthentication"
name = "ProcessingTokenAuthentication"
Expand Down
Loading