|
|
|
|
|
from fastapi import FastAPI, Form, Depends, HTTPException, status |
|
from fastapi.requests import Request |
|
from fastapi.responses import HTMLResponse, RedirectResponse, JSONResponse |
|
from fastapi.templating import Jinja2Templates |
|
from sqlalchemy.orm import Session |
|
from auth import verify_token, oauth2_scheme, auth_views, register, UserCreate, authenticate_user, get_user_by_verification_token |
|
from database import get_db, get_user_by_email |
|
from datetime import timedelta |
|
from typing import Optional |
|
|
|
|
|
import os |
|
|
|
my_secret_key = os.environ['my_secret_key'] |
|
app = FastAPI() |
|
|
|
templates = Jinja2Templates(directory="templates") |
|
|
|
from google.cloud import recaptchaenterprise_v1 |
|
from google.cloud.recaptchaenterprise_v1 import Assessment |
|
|
|
def create_assessment( |
|
project_id: str, recaptcha_key: str, token: str, recaptcha_action: str |
|
) -> Assessment: |
|
"""Create an assessment to analyse the risk of a UI action. |
|
Args: |
|
project_id: Your Google Cloud project ID. |
|
recaptcha_key: The reCAPTCHA key associated with the site/app |
|
token: The generated token obtained from the client. |
|
recaptcha_action: Action name corresponding to the token. |
|
""" |
|
|
|
client = recaptchaenterprise_v1.RecaptchaEnterpriseServiceClient() |
|
|
|
|
|
event = recaptchaenterprise_v1.Event() |
|
event.site_key = recaptcha_key |
|
event.token = token |
|
|
|
assessment = recaptchaenterprise_v1.Assessment() |
|
assessment.event = event |
|
|
|
project_name = f"projects/{project_id}" |
|
|
|
|
|
request = recaptchaenterprise_v1.CreateAssessmentRequest() |
|
request.assessment = assessment |
|
request.parent = project_name |
|
|
|
response = client.create_assessment(request) |
|
|
|
|
|
if not response.token_properties.valid: |
|
print( |
|
"The CreateAssessment call failed because the token was " |
|
+ "invalid for the following reasons: " |
|
+ str(response.token_properties.invalid_reason) |
|
) |
|
return |
|
|
|
|
|
if response.token_properties.action != recaptcha_action: |
|
print( |
|
"The action attribute in your reCAPTCHA tag does" |
|
+ "not match the action you are expecting to score" |
|
) |
|
return |
|
else: |
|
|
|
|
|
|
|
for reason in response.risk_analysis.reasons: |
|
print(reason) |
|
print( |
|
"The reCAPTCHA score for this token is: " |
|
+ str(response.risk_analysis.score) |
|
) |
|
|
|
assessment_name = client.parse_assessment_path(response.name).get("assessment") |
|
print(f"Assessment name: {assessment_name}") |
|
return response |
|
|
|
|
|
def get_current_user(token: str = Depends(verify_token)): |
|
if not token: |
|
raise HTTPException(status_code=401, detail="Token not valid") |
|
return token |
|
|
|
@app.get("/", response_class=HTMLResponse) |
|
async def landing(request: Request): |
|
return templates.TemplateResponse("landing.html", {"request": request}) |
|
|
|
|
|
|
|
@app.get("/login", response_class=HTMLResponse) |
|
async def login(request: Request): |
|
return templates.TemplateResponse("login.html", {"request": request}) |
|
|
|
|
|
@app.post("/login") |
|
async def login_post( |
|
request: Request, |
|
email: str = Form(...), |
|
password: str = Form(...), |
|
db: Session = Depends(get_db) |
|
): |
|
if not email or not password: |
|
raise HTTPException(status_code=400, detail="Invalid email or password") |
|
|
|
user = authenticate_user(db, email, password) |
|
if user and user.is_verified: |
|
access_token = auth_views.create_access_token( |
|
data={"sub": user.email}, |
|
expires_delta=timedelta(minutes=auth_views.ACCESS_TOKEN_EXPIRE_MINUTES) |
|
) |
|
|
|
|
|
url = app.url_path_for("get_protected") |
|
|
|
|
|
|
|
response = RedirectResponse(f"{url}?token={access_token}", status_code=status.HTTP_303_SEE_OTHER) |
|
response.set_cookie(key="access_token", value=f"Bearer {access_token}", httponly=True) |
|
|
|
return response |
|
elif user and not user.is_verified: |
|
raise HTTPException( |
|
status_code=400, |
|
detail="You must verify your email before accessing this resource." |
|
) |
|
else: |
|
|
|
return templates.TemplateResponse( |
|
"login.html", |
|
{"request": request, "error_message": "Invalid email or password"} |
|
) |
|
@app.get("/register", response_class=HTMLResponse) |
|
async def register_get(request: Request): |
|
return templates.TemplateResponse("register.html", {"request": request}) |
|
|
|
|
|
@app.post("/register", response_class=HTMLResponse) |
|
async def register_post( |
|
request: Request, |
|
username: str = Form(...), |
|
email: str = Form(...), |
|
password: str = Form(...), |
|
confirm_password: str = Form(...), |
|
recaptcha_token: str = Form(...), |
|
db: Session = Depends(get_db) |
|
): |
|
|
|
project_id = 'Loginauthc' |
|
recaptcha_key = '6LdaUQIpAAAAACQFcOxakEVXK9QHpaYbic6IClNO' |
|
recaptcha_action = 'submit' |
|
|
|
|
|
assessment = await create_assessment( |
|
project_id, recaptcha_key, recaptcha_token, recaptcha_action |
|
) |
|
|
|
|
|
if not assessment or assessment.risk_analysis.score < 0.5: |
|
return templates.TemplateResponse("register.html", { |
|
"request": request, |
|
"error_message": "Captcha validation failed." |
|
}) |
|
|
|
if password != confirm_password: |
|
|
|
return templates.TemplateResponse("register.html", { |
|
"request": request, |
|
"error_message": "Passwords do not match." |
|
}) |
|
|
|
try: |
|
user = UserCreate(username=username, email=email, password=password, confirm_password=confirm_password) |
|
register(user, db) |
|
except HTTPException as e: |
|
|
|
return templates.TemplateResponse("register.html", { |
|
"request": request, |
|
"error_message": e.detail |
|
}) |
|
|
|
|
|
response = RedirectResponse("/registration_successful", status_code=status.HTTP_302_FOUND) |
|
return response |
|
|
|
|
|
@app.get("/registration_successful", response_class=HTMLResponse) |
|
async def registration_successful(request: Request): |
|
|
|
return templates.TemplateResponse("registration_successful.html", {"request": request}) |
|
|
|
|
|
@app.get("/verify/{verification_token}", response_class=HTMLResponse) |
|
async def verify_email(verification_token: str, db: Session = Depends(get_db)): |
|
user = get_user_by_verification_token(db, verification_token) |
|
if not user: |
|
raise HTTPException(status_code=400, detail="Invalid verification token") |
|
|
|
if user.is_verified: |
|
raise HTTPException(status_code=400, detail="Email already verified") |
|
|
|
user.is_verified = True |
|
user.email_verification_token = None |
|
db.commit() |
|
|
|
|
|
access_token = auth_views.create_access_token(data={"sub": user.email}, expires_delta=timedelta(minutes=auth_views.ACCESS_TOKEN_EXPIRE_MINUTES)) |
|
|
|
return RedirectResponse(url=f"/protected?token={access_token}") |
|
|
|
|
|
|
|
@app.get("/protected", response_class=HTMLResponse) |
|
async def get_protected( |
|
request: Request, |
|
db: Session = Depends(get_db), |
|
token: Optional[str] = None |
|
): |
|
|
|
token = token or request.cookies.get("access_token") |
|
if not token: |
|
raise HTTPException(status_code=status.HTTP_401_UNAUTHORIZED, detail="Not authenticated") |
|
|
|
|
|
|
|
user_email = verify_token(token) |
|
|
|
|
|
db_user = get_user_by_email(db, user_email) |
|
if db_user is None or not db_user.is_verified: |
|
raise HTTPException(status_code=status.HTTP_401_UNAUTHORIZED, detail="User not found or not verified in the database") |
|
|
|
|
|
return templates.TemplateResponse("protected.html", {"request": request, "user": db_user.username}) |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|