This repository has been archived on 2024-05-31. You can view files and clone it, but cannot push or open issues or pull requests.
authentik/authentik/outposts/channels.py

90 lines
2.9 KiB
Python
Raw Normal View History

2020-09-02 22:04:12 +00:00
"""Outpost websocket handler"""
from dataclasses import asdict, dataclass, field
from datetime import datetime
2020-09-02 22:04:12 +00:00
from enum import IntEnum
from typing import Any, Dict, Optional
2020-09-02 22:04:12 +00:00
from channels.exceptions import DenyConnection
2020-09-02 22:04:12 +00:00
from dacite import from_dict
from dacite.data import Data
from guardian.shortcuts import get_objects_for_user
2020-09-02 22:04:12 +00:00
from structlog import get_logger
2020-12-05 21:08:42 +00:00
from authentik.core.channels import AuthJsonConsumer
from authentik.outposts.models import OUTPOST_HELLO_INTERVAL, Outpost, OutpostState
2020-09-02 22:04:12 +00:00
LOGGER = get_logger()
class WebsocketMessageInstruction(IntEnum):
"""Commands which can be triggered over Websocket"""
# Simple message used by either side when a message is acknowledged
ACK = 0
# Message used by outposts to report their alive status
HELLO = 1
# Message sent by us to trigger an Update
TRIGGER_UPDATE = 2
@dataclass
class WebsocketMessage:
"""Complete Websocket Message that is being sent"""
instruction: int
args: Dict[str, Any] = field(default_factory=dict)
class OutpostConsumer(AuthJsonConsumer):
2020-09-02 22:04:12 +00:00
"""Handler for Outposts that connect over websockets for health checks and live updates"""
outpost: Optional[Outpost] = None
2020-09-02 22:04:12 +00:00
def connect(self):
super().connect()
2020-09-02 22:04:12 +00:00
uuid = self.scope["url_route"]["kwargs"]["pk"]
outpost = get_objects_for_user(
2020-12-05 21:08:42 +00:00
self.user, "authentik_outposts.view_outpost"
).filter(pk=uuid)
2020-09-02 22:04:12 +00:00
if not outpost.exists():
raise DenyConnection()
2020-09-02 22:04:12 +00:00
self.accept()
self.outpost = outpost.first()
OutpostState(
uid=self.channel_name, last_seen=datetime.now(), _outpost=self.outpost
).save(timeout=OUTPOST_HELLO_INTERVAL * 1.5)
LOGGER.debug("added channel to cache", channel_name=self.channel_name)
2020-09-02 22:04:12 +00:00
# pylint: disable=unused-argument
def disconnect(self, close_code):
if self.outpost:
OutpostState.for_channel(self.outpost, self.channel_name).delete()
LOGGER.debug("removed channel from cache", channel_name=self.channel_name)
2020-09-02 22:04:12 +00:00
def receive_json(self, content: Data):
msg = from_dict(WebsocketMessage, content)
state = OutpostState(
uid=self.channel_name,
last_seen=datetime.now(),
_outpost=self.outpost,
)
2020-09-02 22:04:12 +00:00
if msg.instruction == WebsocketMessageInstruction.HELLO:
state.version = msg.args.get("version", None)
2020-09-02 22:04:12 +00:00
elif msg.instruction == WebsocketMessageInstruction.ACK:
return
state.save(timeout=OUTPOST_HELLO_INTERVAL * 1.5)
2020-09-02 22:04:12 +00:00
response = WebsocketMessage(instruction=WebsocketMessageInstruction.ACK)
self.send_json(asdict(response))
# pylint: disable=unused-argument
def event_update(self, event):
"""Event handler which is called by post_save signals, Send update instruction"""
2020-09-02 22:04:12 +00:00
self.send_json(
asdict(
WebsocketMessage(instruction=WebsocketMessageInstruction.TRIGGER_UPDATE)
)
)