Coverage for gws-app/gws/plugin/account/auth_provider.py: 0%
30 statements
« prev ^ index » next coverage.py v7.16.2, created at 2026-10-05 13:35 +0200
« prev ^ index » next coverage.py v7.16.2, created at 2026-10-05 13:35 +0200
1"""Authorization provider for the accounts table."""
3from typing import Optional, cast
5import gws
6import gws.base.auth
8from . import core, helper
11@gws.ext.config.authProvider('account')
12class Config(gws.base.auth.provider.Config):
13 """Authentication against the accounts table of the account helper."""
14 pass
17@gws.ext.object.authProvider('account')
18class Object(gws.base.auth.provider.Object):
19 """Authorization provider that authenticates users against the accounts table of the account helper."""
21 h: helper.Object
22 """The account helper."""
24 def configure(self):
25 self.h = cast(helper.Object, self.root.app.helper('account'))
27 def authenticate(self, method, credentials):
28 try:
29 account = self.h.get_account_by_credentials(credentials, expected_status=core.Status.active)
30 except helper.Error as exc:
31 raise gws.ForbiddenError() from exc
33 if account:
34 return self._make_user(account)
36 def get_user(self, local_uid):
37 account = self.h.get_account_by_id(local_uid)
38 if account:
39 return self._make_user(account)
41 def _make_user(self, account: dict) -> gws.User:
42 """Create a user from an account record.
44 The record is converted with ``gws.base.auth.user.from_record``, the primary key becomes the local user uid.
45 """
47 user_rec = {}
49 for k, v in account.items():
50 if k == self.h.adminModel.uidName:
51 user_rec['localUid'] = str(v)
52 else:
53 user_rec[k] = v
55 return gws.base.auth.user.from_record(self, user_rec)