13e2eea72f
* web/user: migrate to top navbar Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org> * web/user: prepare config from server Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org> * re-sort Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org> * remove old interface Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org> * update issue template Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org> * use notification badge Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org> * web/user: re-add go-to-admin button Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org> * *: fix remaining redirects directly to admin Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org> * make settings better Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org> * api: ensure sources and stages are sorted Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org> * web/user: add sessions and consent Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org> * providers/oauth2: add post wrapper to stage Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org> * website/docs: add new interface to release notes Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org>
26 lines
959 B
Python
26 lines
959 B
Python
"""recovery views"""
|
|
from django.contrib import messages
|
|
from django.contrib.auth import login
|
|
from django.http import Http404, HttpRequest, HttpResponse
|
|
from django.shortcuts import redirect
|
|
from django.utils.translation import gettext as _
|
|
from django.views import View
|
|
|
|
from authentik.core.models import Token, TokenIntents
|
|
from authentik.stages.password import BACKEND_INBUILT
|
|
|
|
|
|
class UseTokenView(View):
|
|
"""Use token to login"""
|
|
|
|
def get(self, request: HttpRequest, key: str) -> HttpResponse:
|
|
"""Check if token exists, log user in and delete token."""
|
|
tokens = Token.filter_not_expired(key=key, intent=TokenIntents.INTENT_RECOVERY)
|
|
if not tokens.exists():
|
|
raise Http404
|
|
token = tokens.first()
|
|
login(request, token.user, backend=BACKEND_INBUILT)
|
|
token.delete()
|
|
messages.warning(request, _("Used recovery-link to authenticate."))
|
|
return redirect("authentik_core:if-user")
|