2024-09-19 16:35:26 +00:00
|
|
|
import json
|
2024-10-22 08:57:06 +00:00
|
|
|
import uuid
|
|
|
|
import logging
|
2024-10-15 09:05:43 +00:00
|
|
|
|
2024-10-15 14:58:51 +00:00
|
|
|
from uuid import uuid4
|
2024-09-19 16:35:26 +00:00
|
|
|
|
2024-10-10 12:03:08 +00:00
|
|
|
from django.urls import reverse_lazy
|
2024-10-31 09:14:02 +00:00
|
|
|
from django.conf import settings
|
2024-10-15 14:58:51 +00:00
|
|
|
from django.http import JsonResponse
|
2024-09-19 16:35:26 +00:00
|
|
|
from django.shortcuts import get_object_or_404, redirect
|
|
|
|
from django.utils.translation import gettext_lazy as _
|
|
|
|
from django.views.decorators.csrf import csrf_exempt
|
2024-10-23 07:23:45 +00:00
|
|
|
from django.utils.decorators import method_decorator
|
2024-10-10 12:03:08 +00:00
|
|
|
from django_tables2 import SingleTableView
|
|
|
|
from django.views.generic.edit import (
|
|
|
|
CreateView,
|
|
|
|
DeleteView,
|
|
|
|
UpdateView,
|
|
|
|
)
|
2024-09-19 16:35:26 +00:00
|
|
|
|
2024-10-15 14:58:51 +00:00
|
|
|
from utils.save_snapshots import move_json, save_in_disk
|
2024-10-23 07:23:45 +00:00
|
|
|
from django.views.generic.edit import View
|
2024-09-19 16:35:26 +00:00
|
|
|
from dashboard.mixins import DashboardView
|
2024-11-12 17:04:59 +00:00
|
|
|
from evidence.models import SystemProperty, UserProperty, Property
|
2024-10-23 11:42:09 +00:00
|
|
|
from evidence.parse_details import ParseSnapshot
|
2024-09-19 16:35:26 +00:00
|
|
|
from evidence.parse import Build
|
2024-10-23 11:42:09 +00:00
|
|
|
from device.models import Device
|
2024-09-19 16:35:26 +00:00
|
|
|
from api.models import Token
|
|
|
|
from api.tables import TokensTable
|
|
|
|
|
|
|
|
|
2024-10-22 08:57:06 +00:00
|
|
|
logger = logging.getLogger('django')
|
|
|
|
|
|
|
|
|
2024-10-23 07:23:45 +00:00
|
|
|
class ApiMixing(View):
|
|
|
|
|
|
|
|
@method_decorator(csrf_exempt)
|
|
|
|
def dispatch(self, *args, **kwargs):
|
|
|
|
return super().dispatch(*args, **kwargs)
|
|
|
|
|
|
|
|
def auth(self):
|
|
|
|
# Authentication
|
|
|
|
auth_header = self.request.headers.get('Authorization')
|
|
|
|
if not auth_header or not auth_header.startswith('Bearer '):
|
2024-10-31 09:14:02 +00:00
|
|
|
logger.error("Invalid or missing token %s", auth_header)
|
2024-10-23 07:23:45 +00:00
|
|
|
return JsonResponse({'error': 'Invalid or missing token'}, status=401)
|
|
|
|
|
|
|
|
token = auth_header.split(' ')[1].strip("'").strip('"')
|
|
|
|
try:
|
|
|
|
uuid.UUID(token)
|
|
|
|
except Exception:
|
2024-10-31 09:14:02 +00:00
|
|
|
logger.error("Invalid or missing token %s", token)
|
2024-10-23 07:23:45 +00:00
|
|
|
return JsonResponse({'error': 'Invalid or missing token'}, status=401)
|
|
|
|
|
|
|
|
self.tk = Token.objects.filter(token=token).first()
|
|
|
|
|
|
|
|
if not self.tk:
|
2024-10-31 09:14:02 +00:00
|
|
|
logger.error("Invalid or missing token %s", token)
|
2024-10-23 07:23:45 +00:00
|
|
|
return JsonResponse({'error': 'Invalid or missing token'}, status=401)
|
|
|
|
|
|
|
|
|
|
|
|
class NewSnapshotView(ApiMixing):
|
|
|
|
|
|
|
|
def get(self, request, *args, **kwargs):
|
|
|
|
return JsonResponse({}, status=404)
|
|
|
|
|
|
|
|
def post(self, request, *args, **kwargs):
|
|
|
|
response = self.auth()
|
|
|
|
if response:
|
|
|
|
return response
|
|
|
|
|
|
|
|
# Validation snapshot
|
|
|
|
try:
|
|
|
|
data = json.loads(request.body)
|
|
|
|
except json.JSONDecodeError:
|
2024-10-31 09:14:02 +00:00
|
|
|
txt = "error: the snapshot is not a json"
|
|
|
|
logger.error("%s", txt)
|
2024-10-23 07:23:45 +00:00
|
|
|
return JsonResponse({'error': 'Invalid JSON'}, status=500)
|
|
|
|
|
|
|
|
# Process snapshot
|
|
|
|
path_name = save_in_disk(data, self.tk.owner.institution.name)
|
|
|
|
|
|
|
|
# try:
|
|
|
|
# Build(data, None, check=True)
|
|
|
|
# except Exception:
|
|
|
|
# return JsonResponse({'error': 'Invalid Snapshot'}, status=400)
|
|
|
|
|
|
|
|
if not data.get("uuid"):
|
|
|
|
txt = "error: the snapshot not have uuid"
|
2024-10-31 09:14:02 +00:00
|
|
|
logger.error("%s", txt)
|
2024-10-23 07:23:45 +00:00
|
|
|
return JsonResponse({'status': txt}, status=500)
|
|
|
|
|
2024-11-12 17:04:59 +00:00
|
|
|
exist_property = SystemProperty.objects.filter(
|
2024-10-23 07:23:45 +00:00
|
|
|
uuid=data['uuid']
|
|
|
|
).first()
|
|
|
|
|
2024-11-12 17:04:59 +00:00
|
|
|
if exist_property:
|
2024-10-23 07:23:45 +00:00
|
|
|
txt = "error: the snapshot {} exist".format(data['uuid'])
|
2024-10-31 09:14:02 +00:00
|
|
|
logger.warning("%s", txt)
|
2024-10-23 07:23:45 +00:00
|
|
|
return JsonResponse({'status': txt}, status=500)
|
|
|
|
|
|
|
|
|
|
|
|
try:
|
|
|
|
Build(data, self.tk.owner)
|
|
|
|
except Exception as err:
|
2024-10-31 09:14:02 +00:00
|
|
|
if settings.DEBUG:
|
|
|
|
logger.exception("%s", err)
|
|
|
|
snapshot_id = data.get("uuid", "")
|
|
|
|
txt = "It is not possible to parse snapshot: %s."
|
|
|
|
logger.error(txt, snapshot_id)
|
|
|
|
text = "fail: It is not possible to parse snapshot"
|
|
|
|
return JsonResponse({'status': text}, status=500)
|
2024-10-23 07:23:45 +00:00
|
|
|
|
2024-11-12 17:04:59 +00:00
|
|
|
property = SystemProperty.objects.filter(
|
2024-10-23 07:23:45 +00:00
|
|
|
uuid=data['uuid'],
|
2024-11-12 17:04:59 +00:00
|
|
|
type=Property.Type.SYSTEM,
|
2024-10-23 07:23:45 +00:00
|
|
|
# TODO this is hardcoded, it should select the user preferred algorithm
|
|
|
|
key="hidalgo1",
|
|
|
|
owner=self.tk.owner.institution
|
|
|
|
).first()
|
|
|
|
|
|
|
|
|
2024-11-12 17:04:59 +00:00
|
|
|
if not property:
|
|
|
|
logger.error("Error: No property for uuid: %s", data["uuid"])
|
2024-10-23 07:23:45 +00:00
|
|
|
return JsonResponse({'status': 'fail'}, status=500)
|
|
|
|
|
2024-11-12 17:04:59 +00:00
|
|
|
url_args = reverse_lazy("device:details", args=(property.value,))
|
2024-10-23 07:23:45 +00:00
|
|
|
url = request.build_absolute_uri(url_args)
|
|
|
|
|
|
|
|
response = {
|
|
|
|
"status": "success",
|
2024-11-12 17:04:59 +00:00
|
|
|
"dhid": property.value[:6].upper(),
|
2024-10-23 07:23:45 +00:00
|
|
|
"url": url,
|
|
|
|
# TODO replace with public_url when available
|
|
|
|
"public_url": url
|
|
|
|
}
|
|
|
|
move_json(path_name, self.tk.owner.institution.name)
|
|
|
|
|
|
|
|
return JsonResponse(response, status=200)
|
2024-09-19 16:35:26 +00:00
|
|
|
|
|
|
|
|
|
|
|
class TokenView(DashboardView, SingleTableView):
|
|
|
|
template_name = "token.html"
|
|
|
|
title = _("Credential management")
|
|
|
|
section = "Credential"
|
|
|
|
subtitle = _('Managament Tokens')
|
|
|
|
icon = 'bi bi-key'
|
|
|
|
model = Token
|
|
|
|
table_class = TokensTable
|
|
|
|
|
|
|
|
def get_queryset(self):
|
|
|
|
"""
|
|
|
|
Override the get_queryset method to filter events based on the user type.
|
|
|
|
"""
|
|
|
|
return Token.objects.filter().order_by("-id")
|
|
|
|
|
|
|
|
def get_context_data(self, **kwargs):
|
|
|
|
context = super().get_context_data(**kwargs)
|
|
|
|
context.update({
|
2024-10-10 12:03:08 +00:00
|
|
|
'tokens': Token.objects.all(),
|
2024-09-19 16:35:26 +00:00
|
|
|
})
|
|
|
|
return context
|
|
|
|
|
|
|
|
|
|
|
|
class TokenDeleteView(DashboardView, DeleteView):
|
|
|
|
model = Token
|
|
|
|
|
|
|
|
def get(self, request, *args, **kwargs):
|
|
|
|
self.pk = kwargs['pk']
|
2024-09-20 12:30:31 +00:00
|
|
|
self.object = get_object_or_404(self.model, pk=self.pk, owner=self.request.user)
|
2024-09-19 16:35:26 +00:00
|
|
|
self.object.delete()
|
|
|
|
|
|
|
|
return redirect('api:tokens')
|
|
|
|
|
|
|
|
|
2024-10-10 12:03:08 +00:00
|
|
|
class TokenNewView(DashboardView, CreateView):
|
|
|
|
template_name = "new_token.html"
|
|
|
|
title = _("Credential management")
|
|
|
|
section = "Credential"
|
|
|
|
subtitle = _('New Tokens')
|
|
|
|
icon = 'bi bi-key'
|
|
|
|
model = Token
|
|
|
|
success_url = reverse_lazy('api:tokens')
|
|
|
|
fields = (
|
|
|
|
"tag",
|
|
|
|
)
|
2024-09-19 16:35:26 +00:00
|
|
|
|
2024-10-10 12:03:08 +00:00
|
|
|
def form_valid(self, form):
|
|
|
|
form.instance.owner = self.request.user
|
|
|
|
form.instance.token = uuid4()
|
|
|
|
return super().form_valid(form)
|
2024-09-19 16:35:26 +00:00
|
|
|
|
2024-10-10 12:03:08 +00:00
|
|
|
|
|
|
|
class EditTokenView(DashboardView, UpdateView):
|
|
|
|
template_name = "new_token.html"
|
|
|
|
title = _("Credential management")
|
|
|
|
section = "Credential"
|
|
|
|
subtitle = _('New Tokens')
|
|
|
|
icon = 'bi bi-key'
|
|
|
|
model = Token
|
|
|
|
success_url = reverse_lazy('api:tokens')
|
|
|
|
fields = (
|
|
|
|
"tag",
|
|
|
|
)
|
|
|
|
|
|
|
|
def get_form_kwargs(self):
|
|
|
|
pk = self.kwargs.get('pk')
|
|
|
|
self.object = get_object_or_404(
|
|
|
|
self.model,
|
|
|
|
owner=self.request.user,
|
|
|
|
pk=pk,
|
|
|
|
)
|
|
|
|
kwargs = super().get_form_kwargs()
|
|
|
|
return kwargs
|
2024-10-23 07:23:45 +00:00
|
|
|
|
|
|
|
|
2024-10-23 11:39:16 +00:00
|
|
|
class DetailsDeviceView(ApiMixing):
|
2024-10-23 07:23:45 +00:00
|
|
|
|
|
|
|
def get(self, request, *args, **kwargs):
|
|
|
|
response = self.auth()
|
|
|
|
if response:
|
|
|
|
return response
|
|
|
|
|
2024-10-23 11:39:16 +00:00
|
|
|
self.pk = kwargs['pk']
|
|
|
|
self.object = Device(id=self.pk)
|
|
|
|
|
|
|
|
if not self.object.last_evidence:
|
|
|
|
return JsonResponse({}, status=404)
|
|
|
|
|
|
|
|
if self.object.owner != self.tk.owner.institution:
|
|
|
|
return JsonResponse({}, status=403)
|
|
|
|
|
|
|
|
data = self.get_data()
|
|
|
|
return JsonResponse(data, status=200)
|
2024-10-23 07:23:45 +00:00
|
|
|
|
|
|
|
def post(self, request, *args, **kwargs):
|
|
|
|
return JsonResponse({}, status=404)
|
2024-10-23 11:39:16 +00:00
|
|
|
|
|
|
|
def get_data(self):
|
|
|
|
data = {}
|
|
|
|
self.object.initial()
|
|
|
|
self.object.get_last_evidence()
|
|
|
|
evidence = self.object.last_evidence
|
|
|
|
|
|
|
|
if evidence.is_legacy():
|
|
|
|
data.update({
|
|
|
|
"device": evidence.get("device"),
|
|
|
|
"components": evidence.get("components"),
|
|
|
|
})
|
|
|
|
else:
|
|
|
|
evidence.get_doc()
|
|
|
|
snapshot = ParseSnapshot(evidence.doc).snapshot_json
|
|
|
|
data.update({
|
|
|
|
"device": snapshot.get("device"),
|
|
|
|
"components": snapshot.get("components"),
|
|
|
|
})
|
|
|
|
|
2024-11-12 17:04:59 +00:00
|
|
|
uuids = SystemProperty.objects.filter(
|
2024-10-23 11:39:16 +00:00
|
|
|
owner=self.tk.owner.institution,
|
|
|
|
value=self.pk
|
|
|
|
).values("uuid")
|
|
|
|
|
2024-11-12 17:04:59 +00:00
|
|
|
properties = UserProperty.objects.filter(
|
2024-10-23 11:39:16 +00:00
|
|
|
uuid__in=uuids,
|
|
|
|
owner=self.tk.owner.institution,
|
|
|
|
).values_list("key", "value")
|
|
|
|
|
2024-11-12 17:04:59 +00:00
|
|
|
data.update({"properties": list(properties)})
|
2024-10-23 11:39:16 +00:00
|
|
|
return data
|
2024-10-24 09:53:37 +00:00
|
|
|
|
|
|
|
|
2024-11-12 17:04:59 +00:00
|
|
|
class AddPropertyView(ApiMixing):
|
2024-10-24 09:53:37 +00:00
|
|
|
|
|
|
|
def post(self, request, *args, **kwargs):
|
|
|
|
response = self.auth()
|
|
|
|
if response:
|
|
|
|
return response
|
|
|
|
|
|
|
|
self.pk = kwargs['pk']
|
|
|
|
institution = self.tk.owner.institution
|
2024-11-12 17:04:59 +00:00
|
|
|
self.property = SystemProperty.objects.filter(
|
2024-10-24 09:53:37 +00:00
|
|
|
owner=institution,
|
|
|
|
value=self.pk,
|
2024-11-12 17:04:59 +00:00
|
|
|
type=Property.Type.SYSTEM
|
2024-10-24 09:53:37 +00:00
|
|
|
).first()
|
|
|
|
|
2024-11-12 17:04:59 +00:00
|
|
|
if not self.property:
|
2024-10-24 09:53:37 +00:00
|
|
|
return JsonResponse({}, status=404)
|
|
|
|
|
|
|
|
try:
|
|
|
|
data = json.loads(request.body)
|
|
|
|
key = data["key"]
|
|
|
|
value = data["value"]
|
|
|
|
except Exception:
|
2024-10-31 09:14:02 +00:00
|
|
|
logger.error("Invalid Snapshot of user %s", self.tk.owner)
|
2024-10-24 09:53:37 +00:00
|
|
|
return JsonResponse({'error': 'Invalid JSON'}, status=500)
|
|
|
|
|
2024-11-12 17:04:59 +00:00
|
|
|
UserProperty.objects.create(
|
|
|
|
uuid=self.property.uuid,
|
2024-10-24 09:53:37 +00:00
|
|
|
owner=self.tk.owner.institution,
|
|
|
|
key = key,
|
|
|
|
value = value
|
|
|
|
)
|
|
|
|
|
|
|
|
return JsonResponse({"status": "success"}, status=200)
|
|
|
|
|
|
|
|
def get(self, request, *args, **kwargs):
|
|
|
|
return JsonResponse({}, status=404)
|