Coverage for gws-app/gws/plugin/account/auth_provider.py: 0%

30 statements  

« prev     ^ index     » next       coverage.py v7.16.2, created at 2026-10-05 13:35 +0200

1"""Authorization provider for the accounts table.""" 

2 

3from typing import Optional, cast 

4 

5import gws 

6import gws.base.auth 

7 

8from . import core, helper 

9 

10 

11@gws.ext.config.authProvider('account') 

12class Config(gws.base.auth.provider.Config): 

13 """Authentication against the accounts table of the account helper.""" 

14 pass 

15 

16 

17@gws.ext.object.authProvider('account') 

18class Object(gws.base.auth.provider.Object): 

19 """Authorization provider that authenticates users against the accounts table of the account helper.""" 

20 

21 h: helper.Object 

22 """The account helper.""" 

23 

24 def configure(self): 

25 self.h = cast(helper.Object, self.root.app.helper('account')) 

26 

27 def authenticate(self, method, credentials): 

28 try: 

29 account = self.h.get_account_by_credentials(credentials, expected_status=core.Status.active) 

30 except helper.Error as exc: 

31 raise gws.ForbiddenError() from exc 

32 

33 if account: 

34 return self._make_user(account) 

35 

36 def get_user(self, local_uid): 

37 account = self.h.get_account_by_id(local_uid) 

38 if account: 

39 return self._make_user(account) 

40 

41 def _make_user(self, account: dict) -> gws.User: 

42 """Create a user from an account record. 

43 

44 The record is converted with ``gws.base.auth.user.from_record``, the primary key becomes the local user uid. 

45 """ 

46 

47 user_rec = {} 

48 

49 for k, v in account.items(): 

50 if k == self.h.adminModel.uidName: 

51 user_rec['localUid'] = str(v) 

52 else: 

53 user_rec[k] = v 

54 

55 return gws.base.auth.user.from_record(self, user_rec)