You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

datasource_auth.py 13KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323
  1. from fastapi.encoders import jsonable_encoder
  2. from flask import make_response, redirect, request
  3. from flask_login import current_user
  4. from flask_restx import Resource, reqparse
  5. from werkzeug.exceptions import Forbidden, NotFound
  6. from configs import dify_config
  7. from controllers.console import console_ns
  8. from controllers.console.wraps import (
  9. account_initialization_required,
  10. setup_required,
  11. )
  12. from core.model_runtime.errors.validate import CredentialsValidateFailedError
  13. from core.plugin.impl.oauth import OAuthHandler
  14. from libs.helper import StrLen
  15. from libs.login import login_required
  16. from models.provider_ids import DatasourceProviderID
  17. from services.datasource_provider_service import DatasourceProviderService
  18. from services.plugin.oauth_service import OAuthProxyService
  19. @console_ns.route("/oauth/plugin/<path:provider_id>/datasource/get-authorization-url")
  20. class DatasourcePluginOAuthAuthorizationUrl(Resource):
  21. @setup_required
  22. @login_required
  23. @account_initialization_required
  24. def get(self, provider_id: str):
  25. user = current_user
  26. tenant_id = user.current_tenant_id
  27. if not current_user.is_editor:
  28. raise Forbidden()
  29. credential_id = request.args.get("credential_id")
  30. datasource_provider_id = DatasourceProviderID(provider_id)
  31. provider_name = datasource_provider_id.provider_name
  32. plugin_id = datasource_provider_id.plugin_id
  33. oauth_config = DatasourceProviderService().get_oauth_client(
  34. tenant_id=tenant_id,
  35. datasource_provider_id=datasource_provider_id,
  36. )
  37. if not oauth_config:
  38. raise ValueError(f"No OAuth Client Config for {provider_id}")
  39. context_id = OAuthProxyService.create_proxy_context(
  40. user_id=current_user.id,
  41. tenant_id=tenant_id,
  42. plugin_id=plugin_id,
  43. provider=provider_name,
  44. credential_id=credential_id,
  45. )
  46. oauth_handler = OAuthHandler()
  47. redirect_uri = f"{dify_config.CONSOLE_API_URL}/console/api/oauth/plugin/{provider_id}/datasource/callback"
  48. authorization_url_response = oauth_handler.get_authorization_url(
  49. tenant_id=tenant_id,
  50. user_id=user.id,
  51. plugin_id=plugin_id,
  52. provider=provider_name,
  53. redirect_uri=redirect_uri,
  54. system_credentials=oauth_config,
  55. )
  56. response = make_response(jsonable_encoder(authorization_url_response))
  57. response.set_cookie(
  58. "context_id",
  59. context_id,
  60. httponly=True,
  61. samesite="Lax",
  62. max_age=OAuthProxyService.__MAX_AGE__,
  63. )
  64. return response
  65. @console_ns.route("/oauth/plugin/<path:provider_id>/datasource/callback")
  66. class DatasourceOAuthCallback(Resource):
  67. @setup_required
  68. def get(self, provider_id: str):
  69. context_id = request.cookies.get("context_id") or request.args.get("context_id")
  70. if not context_id:
  71. raise Forbidden("context_id not found")
  72. context = OAuthProxyService.use_proxy_context(context_id)
  73. if context is None:
  74. raise Forbidden("Invalid context_id")
  75. user_id, tenant_id = context.get("user_id"), context.get("tenant_id")
  76. datasource_provider_id = DatasourceProviderID(provider_id)
  77. plugin_id = datasource_provider_id.plugin_id
  78. datasource_provider_service = DatasourceProviderService()
  79. oauth_client_params = datasource_provider_service.get_oauth_client(
  80. tenant_id=tenant_id,
  81. datasource_provider_id=datasource_provider_id,
  82. )
  83. if not oauth_client_params:
  84. raise NotFound()
  85. redirect_uri = f"{dify_config.CONSOLE_API_URL}/console/api/oauth/plugin/{provider_id}/datasource/callback"
  86. oauth_handler = OAuthHandler()
  87. oauth_response = oauth_handler.get_credentials(
  88. tenant_id=tenant_id,
  89. user_id=user_id,
  90. plugin_id=plugin_id,
  91. provider=datasource_provider_id.provider_name,
  92. redirect_uri=redirect_uri,
  93. system_credentials=oauth_client_params,
  94. request=request,
  95. )
  96. credential_id = context.get("credential_id")
  97. if credential_id:
  98. datasource_provider_service.reauthorize_datasource_oauth_provider(
  99. tenant_id=tenant_id,
  100. provider_id=datasource_provider_id,
  101. avatar_url=oauth_response.metadata.get("avatar_url") or None,
  102. name=oauth_response.metadata.get("name") or None,
  103. expire_at=oauth_response.expires_at,
  104. credentials=dict(oauth_response.credentials),
  105. credential_id=context.get("credential_id"),
  106. )
  107. else:
  108. datasource_provider_service.add_datasource_oauth_provider(
  109. tenant_id=tenant_id,
  110. provider_id=datasource_provider_id,
  111. avatar_url=oauth_response.metadata.get("avatar_url") or None,
  112. name=oauth_response.metadata.get("name") or None,
  113. expire_at=oauth_response.expires_at,
  114. credentials=dict(oauth_response.credentials),
  115. )
  116. return redirect(f"{dify_config.CONSOLE_WEB_URL}/oauth-callback")
  117. @console_ns.route("/auth/plugin/datasource/<path:provider_id>")
  118. class DatasourceAuth(Resource):
  119. @setup_required
  120. @login_required
  121. @account_initialization_required
  122. def post(self, provider_id: str):
  123. if not current_user.is_editor:
  124. raise Forbidden()
  125. parser = reqparse.RequestParser()
  126. parser.add_argument(
  127. "name", type=StrLen(max_length=100), required=False, nullable=True, location="json", default=None
  128. )
  129. parser.add_argument("credentials", type=dict, required=True, nullable=False, location="json")
  130. args = parser.parse_args()
  131. datasource_provider_id = DatasourceProviderID(provider_id)
  132. datasource_provider_service = DatasourceProviderService()
  133. try:
  134. datasource_provider_service.add_datasource_api_key_provider(
  135. tenant_id=current_user.current_tenant_id,
  136. provider_id=datasource_provider_id,
  137. credentials=args["credentials"],
  138. name=args["name"],
  139. )
  140. except CredentialsValidateFailedError as ex:
  141. raise ValueError(str(ex))
  142. return {"result": "success"}, 200
  143. @setup_required
  144. @login_required
  145. @account_initialization_required
  146. def get(self, provider_id: str):
  147. datasource_provider_id = DatasourceProviderID(provider_id)
  148. datasource_provider_service = DatasourceProviderService()
  149. datasources = datasource_provider_service.list_datasource_credentials(
  150. tenant_id=current_user.current_tenant_id,
  151. provider=datasource_provider_id.provider_name,
  152. plugin_id=datasource_provider_id.plugin_id,
  153. )
  154. return {"result": datasources}, 200
  155. @console_ns.route("/auth/plugin/datasource/<path:provider_id>/delete")
  156. class DatasourceAuthDeleteApi(Resource):
  157. @setup_required
  158. @login_required
  159. @account_initialization_required
  160. def post(self, provider_id: str):
  161. datasource_provider_id = DatasourceProviderID(provider_id)
  162. plugin_id = datasource_provider_id.plugin_id
  163. provider_name = datasource_provider_id.provider_name
  164. if not current_user.is_editor:
  165. raise Forbidden()
  166. parser = reqparse.RequestParser()
  167. parser.add_argument("credential_id", type=str, required=True, nullable=False, location="json")
  168. args = parser.parse_args()
  169. datasource_provider_service = DatasourceProviderService()
  170. datasource_provider_service.remove_datasource_credentials(
  171. tenant_id=current_user.current_tenant_id,
  172. auth_id=args["credential_id"],
  173. provider=provider_name,
  174. plugin_id=plugin_id,
  175. )
  176. return {"result": "success"}, 200
  177. @console_ns.route("/auth/plugin/datasource/<path:provider_id>/update")
  178. class DatasourceAuthUpdateApi(Resource):
  179. @setup_required
  180. @login_required
  181. @account_initialization_required
  182. def post(self, provider_id: str):
  183. datasource_provider_id = DatasourceProviderID(provider_id)
  184. parser = reqparse.RequestParser()
  185. parser.add_argument("credentials", type=dict, required=False, nullable=True, location="json")
  186. parser.add_argument("name", type=StrLen(max_length=100), required=False, nullable=True, location="json")
  187. parser.add_argument("credential_id", type=str, required=True, nullable=False, location="json")
  188. args = parser.parse_args()
  189. if not current_user.is_editor:
  190. raise Forbidden()
  191. datasource_provider_service = DatasourceProviderService()
  192. datasource_provider_service.update_datasource_credentials(
  193. tenant_id=current_user.current_tenant_id,
  194. auth_id=args["credential_id"],
  195. provider=datasource_provider_id.provider_name,
  196. plugin_id=datasource_provider_id.plugin_id,
  197. credentials=args.get("credentials", {}),
  198. name=args.get("name", None),
  199. )
  200. return {"result": "success"}, 201
  201. @console_ns.route("/auth/plugin/datasource/list")
  202. class DatasourceAuthListApi(Resource):
  203. @setup_required
  204. @login_required
  205. @account_initialization_required
  206. def get(self):
  207. datasource_provider_service = DatasourceProviderService()
  208. datasources = datasource_provider_service.get_all_datasource_credentials(
  209. tenant_id=current_user.current_tenant_id
  210. )
  211. return {"result": jsonable_encoder(datasources)}, 200
  212. @console_ns.route("/auth/plugin/datasource/default-list")
  213. class DatasourceHardCodeAuthListApi(Resource):
  214. @setup_required
  215. @login_required
  216. @account_initialization_required
  217. def get(self):
  218. datasource_provider_service = DatasourceProviderService()
  219. datasources = datasource_provider_service.get_hard_code_datasource_credentials(
  220. tenant_id=current_user.current_tenant_id
  221. )
  222. return {"result": jsonable_encoder(datasources)}, 200
  223. @console_ns.route("/auth/plugin/datasource/<path:provider_id>/custom-client")
  224. class DatasourceAuthOauthCustomClient(Resource):
  225. @setup_required
  226. @login_required
  227. @account_initialization_required
  228. def post(self, provider_id: str):
  229. if not current_user.is_editor:
  230. raise Forbidden()
  231. parser = reqparse.RequestParser()
  232. parser.add_argument("client_params", type=dict, required=False, nullable=True, location="json")
  233. parser.add_argument("enable_oauth_custom_client", type=bool, required=False, nullable=True, location="json")
  234. args = parser.parse_args()
  235. datasource_provider_id = DatasourceProviderID(provider_id)
  236. datasource_provider_service = DatasourceProviderService()
  237. datasource_provider_service.setup_oauth_custom_client_params(
  238. tenant_id=current_user.current_tenant_id,
  239. datasource_provider_id=datasource_provider_id,
  240. client_params=args.get("client_params", {}),
  241. enabled=args.get("enable_oauth_custom_client", False),
  242. )
  243. return {"result": "success"}, 200
  244. @setup_required
  245. @login_required
  246. @account_initialization_required
  247. def delete(self, provider_id: str):
  248. datasource_provider_id = DatasourceProviderID(provider_id)
  249. datasource_provider_service = DatasourceProviderService()
  250. datasource_provider_service.remove_oauth_custom_client_params(
  251. tenant_id=current_user.current_tenant_id,
  252. datasource_provider_id=datasource_provider_id,
  253. )
  254. return {"result": "success"}, 200
  255. @console_ns.route("/auth/plugin/datasource/<path:provider_id>/default")
  256. class DatasourceAuthDefaultApi(Resource):
  257. @setup_required
  258. @login_required
  259. @account_initialization_required
  260. def post(self, provider_id: str):
  261. if not current_user.is_editor:
  262. raise Forbidden()
  263. parser = reqparse.RequestParser()
  264. parser.add_argument("id", type=str, required=True, nullable=False, location="json")
  265. args = parser.parse_args()
  266. datasource_provider_id = DatasourceProviderID(provider_id)
  267. datasource_provider_service = DatasourceProviderService()
  268. datasource_provider_service.set_default_datasource_provider(
  269. tenant_id=current_user.current_tenant_id,
  270. datasource_provider_id=datasource_provider_id,
  271. credential_id=args["id"],
  272. )
  273. return {"result": "success"}, 200
  274. @console_ns.route("/auth/plugin/datasource/<path:provider_id>/update-name")
  275. class DatasourceUpdateProviderNameApi(Resource):
  276. @setup_required
  277. @login_required
  278. @account_initialization_required
  279. def post(self, provider_id: str):
  280. if not current_user.is_editor:
  281. raise Forbidden()
  282. parser = reqparse.RequestParser()
  283. parser.add_argument("name", type=StrLen(max_length=100), required=True, nullable=False, location="json")
  284. parser.add_argument("credential_id", type=str, required=True, nullable=False, location="json")
  285. args = parser.parse_args()
  286. datasource_provider_id = DatasourceProviderID(provider_id)
  287. datasource_provider_service = DatasourceProviderService()
  288. datasource_provider_service.update_datasource_provider_name(
  289. tenant_id=current_user.current_tenant_id,
  290. datasource_provider_id=datasource_provider_id,
  291. name=args["name"],
  292. credential_id=args["credential_id"],
  293. )
  294. return {"result": "success"}, 200