Вы не можете выбрать более 25 тем Темы должны начинаться с буквы или цифры, могут содержать дефисы(-) и должны содержать не более 35 символов.

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132
  1. import urllib.parse
  2. from dataclasses import dataclass
  3. import httpx
  4. @dataclass
  5. class OAuthUserInfo:
  6. id: str
  7. name: str
  8. email: str
  9. class OAuth:
  10. def __init__(self, client_id: str, client_secret: str, redirect_uri: str):
  11. self.client_id = client_id
  12. self.client_secret = client_secret
  13. self.redirect_uri = redirect_uri
  14. def get_authorization_url(self):
  15. raise NotImplementedError()
  16. def get_access_token(self, code: str):
  17. raise NotImplementedError()
  18. def get_raw_user_info(self, token: str):
  19. raise NotImplementedError()
  20. def get_user_info(self, token: str) -> OAuthUserInfo:
  21. raw_info = self.get_raw_user_info(token)
  22. return self._transform_user_info(raw_info)
  23. def _transform_user_info(self, raw_info: dict) -> OAuthUserInfo:
  24. raise NotImplementedError()
  25. class GitHubOAuth(OAuth):
  26. _AUTH_URL = "https://github.com/login/oauth/authorize"
  27. _TOKEN_URL = "https://github.com/login/oauth/access_token"
  28. _USER_INFO_URL = "https://api.github.com/user"
  29. _EMAIL_INFO_URL = "https://api.github.com/user/emails"
  30. def get_authorization_url(self, invite_token: str | None = None):
  31. params = {
  32. "client_id": self.client_id,
  33. "redirect_uri": self.redirect_uri,
  34. "scope": "user:email", # Request only basic user information
  35. }
  36. if invite_token:
  37. params["state"] = invite_token
  38. return f"{self._AUTH_URL}?{urllib.parse.urlencode(params)}"
  39. def get_access_token(self, code: str):
  40. data = {
  41. "client_id": self.client_id,
  42. "client_secret": self.client_secret,
  43. "code": code,
  44. "redirect_uri": self.redirect_uri,
  45. }
  46. headers = {"Accept": "application/json"}
  47. response = httpx.post(self._TOKEN_URL, data=data, headers=headers)
  48. response_json = response.json()
  49. access_token = response_json.get("access_token")
  50. if not access_token:
  51. raise ValueError(f"Error in GitHub OAuth: {response_json}")
  52. return access_token
  53. def get_raw_user_info(self, token: str):
  54. headers = {"Authorization": f"token {token}"}
  55. response = httpx.get(self._USER_INFO_URL, headers=headers)
  56. response.raise_for_status()
  57. user_info = response.json()
  58. email_response = httpx.get(self._EMAIL_INFO_URL, headers=headers)
  59. email_info = email_response.json()
  60. primary_email: dict = next((email for email in email_info if email["primary"] == True), {})
  61. return {**user_info, "email": primary_email.get("email", "")}
  62. def _transform_user_info(self, raw_info: dict) -> OAuthUserInfo:
  63. email = raw_info.get("email")
  64. if not email:
  65. email = f"{raw_info['id']}+{raw_info['login']}@users.noreply.github.com"
  66. return OAuthUserInfo(id=str(raw_info["id"]), name=raw_info["name"], email=email)
  67. class GoogleOAuth(OAuth):
  68. _AUTH_URL = "https://accounts.google.com/o/oauth2/v2/auth"
  69. _TOKEN_URL = "https://oauth2.googleapis.com/token"
  70. _USER_INFO_URL = "https://www.googleapis.com/oauth2/v3/userinfo"
  71. def get_authorization_url(self, invite_token: str | None = None):
  72. params = {
  73. "client_id": self.client_id,
  74. "response_type": "code",
  75. "redirect_uri": self.redirect_uri,
  76. "scope": "openid email",
  77. }
  78. if invite_token:
  79. params["state"] = invite_token
  80. return f"{self._AUTH_URL}?{urllib.parse.urlencode(params)}"
  81. def get_access_token(self, code: str):
  82. data = {
  83. "client_id": self.client_id,
  84. "client_secret": self.client_secret,
  85. "code": code,
  86. "grant_type": "authorization_code",
  87. "redirect_uri": self.redirect_uri,
  88. }
  89. headers = {"Accept": "application/json"}
  90. response = httpx.post(self._TOKEN_URL, data=data, headers=headers)
  91. response_json = response.json()
  92. access_token = response_json.get("access_token")
  93. if not access_token:
  94. raise ValueError(f"Error in Google OAuth: {response_json}")
  95. return access_token
  96. def get_raw_user_info(self, token: str):
  97. headers = {"Authorization": f"Bearer {token}"}
  98. response = httpx.get(self._USER_INFO_URL, headers=headers)
  99. response.raise_for_status()
  100. return response.json()
  101. def _transform_user_info(self, raw_info: dict) -> OAuthUserInfo:
  102. return OAuthUserInfo(id=str(raw_info["sub"]), name="", email=raw_info["email"])