-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathauth.py
45 lines (36 loc) · 1.4 KB
/
auth.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
from flask import abort, render_template
from flask_dance.contrib.google import google
import db
def requires_auth(requirements: list[str]):
def decorator(f):
def wrapper(*args, **kwargs):
if not google.authorized:
return render_template("login_required.jinja")
userinfo = google.get("/oauth2/v3/userinfo").json()
database = db.get_db()
user = database.execute(
"SELECT * FROM users WHERE id = ?", (f"GOOGLE_{userinfo['email']}",)
).fetchone()
if not user:
# user is not in db
database.execute(
"INSERT INTO users VALUES (?, false, false, false)",
(f"GOOGLE_{userinfo['email']}",),
)
user = database.execute(
"SELECT * FROM users WHERE id = ?", (f"GOOGLE_{userinfo['email']}",)
).fetchone()
database.commit()
if requirements:
abort(403)
for requirement in requirements:
if not has_permission(user, requirement):
abort(403)
return f(*args, **kwargs, userinfo=userinfo, user=user)
wrapper.__name__ = f.__name__
return wrapper
return decorator
def has_permission(user, name):
if user["admin"]:
return True
return user[name]