You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

datasource_auth.py 14KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362
  1. from fastapi.encoders import jsonable_encoder
  2. from flask import make_response, redirect, request
  3. from flask_login import current_user
  4. from flask_restx import Resource, reqparse
  5. from werkzeug.exceptions import Forbidden, NotFound
  6. from configs import dify_config
  7. from controllers.console import api
  8. from controllers.console.wraps import (
  9. account_initialization_required,
  10. setup_required,
  11. )
  12. from core.model_runtime.errors.validate import CredentialsValidateFailedError
  13. from core.plugin.impl.oauth import OAuthHandler
  14. from libs.helper import StrLen
  15. from libs.login import login_required
  16. from models.provider_ids import DatasourceProviderID
  17. from services.datasource_provider_service import DatasourceProviderService
  18. from services.plugin.oauth_service import OAuthProxyService
  19. class DatasourcePluginOAuthAuthorizationUrl(Resource):
  20. @setup_required
  21. @login_required
  22. @account_initialization_required
  23. def get(self, provider_id: str):
  24. user = current_user
  25. tenant_id = user.current_tenant_id
  26. if not current_user.is_editor:
  27. raise Forbidden()
  28. credential_id = request.args.get("credential_id")
  29. datasource_provider_id = DatasourceProviderID(provider_id)
  30. provider_name = datasource_provider_id.provider_name
  31. plugin_id = datasource_provider_id.plugin_id
  32. oauth_config = DatasourceProviderService().get_oauth_client(
  33. tenant_id=tenant_id,
  34. datasource_provider_id=datasource_provider_id,
  35. )
  36. if not oauth_config:
  37. raise ValueError(f"No OAuth Client Config for {provider_id}")
  38. context_id = OAuthProxyService.create_proxy_context(
  39. user_id=current_user.id,
  40. tenant_id=tenant_id,
  41. plugin_id=plugin_id,
  42. provider=provider_name,
  43. credential_id=credential_id,
  44. )
  45. oauth_handler = OAuthHandler()
  46. redirect_uri = f"{dify_config.CONSOLE_API_URL}/console/api/oauth/plugin/{provider_id}/datasource/callback"
  47. authorization_url_response = oauth_handler.get_authorization_url(
  48. tenant_id=tenant_id,
  49. user_id=user.id,
  50. plugin_id=plugin_id,
  51. provider=provider_name,
  52. redirect_uri=redirect_uri,
  53. system_credentials=oauth_config,
  54. )
  55. response = make_response(jsonable_encoder(authorization_url_response))
  56. response.set_cookie(
  57. "context_id",
  58. context_id,
  59. httponly=True,
  60. samesite="Lax",
  61. max_age=OAuthProxyService.__MAX_AGE__,
  62. )
  63. return response
  64. class DatasourceOAuthCallback(Resource):
  65. @setup_required
  66. def get(self, provider_id: str):
  67. context_id = request.cookies.get("context_id") or request.args.get("context_id")
  68. if not context_id:
  69. raise Forbidden("context_id not found")
  70. context = OAuthProxyService.use_proxy_context(context_id)
  71. if context is None:
  72. raise Forbidden("Invalid context_id")
  73. user_id, tenant_id = context.get("user_id"), context.get("tenant_id")
  74. datasource_provider_id = DatasourceProviderID(provider_id)
  75. plugin_id = datasource_provider_id.plugin_id
  76. datasource_provider_service = DatasourceProviderService()
  77. oauth_client_params = datasource_provider_service.get_oauth_client(
  78. tenant_id=tenant_id,
  79. datasource_provider_id=datasource_provider_id,
  80. )
  81. if not oauth_client_params:
  82. raise NotFound()
  83. redirect_uri = f"{dify_config.CONSOLE_API_URL}/console/api/oauth/plugin/{provider_id}/datasource/callback"
  84. oauth_handler = OAuthHandler()
  85. oauth_response = oauth_handler.get_credentials(
  86. tenant_id=tenant_id,
  87. user_id=user_id,
  88. plugin_id=plugin_id,
  89. provider=datasource_provider_id.provider_name,
  90. redirect_uri=redirect_uri,
  91. system_credentials=oauth_client_params,
  92. request=request,
  93. )
  94. credential_id = context.get("credential_id")
  95. if credential_id:
  96. datasource_provider_service.reauthorize_datasource_oauth_provider(
  97. tenant_id=tenant_id,
  98. provider_id=datasource_provider_id,
  99. avatar_url=oauth_response.metadata.get("avatar_url") or None,
  100. name=oauth_response.metadata.get("name") or None,
  101. expire_at=oauth_response.expires_at,
  102. credentials=dict(oauth_response.credentials),
  103. credential_id=context.get("credential_id"),
  104. )
  105. else:
  106. datasource_provider_service.add_datasource_oauth_provider(
  107. tenant_id=tenant_id,
  108. provider_id=datasource_provider_id,
  109. avatar_url=oauth_response.metadata.get("avatar_url") or None,
  110. name=oauth_response.metadata.get("name") or None,
  111. expire_at=oauth_response.expires_at,
  112. credentials=dict(oauth_response.credentials),
  113. )
  114. return redirect(f"{dify_config.CONSOLE_WEB_URL}/oauth-callback")
  115. class DatasourceAuth(Resource):
  116. @setup_required
  117. @login_required
  118. @account_initialization_required
  119. def post(self, provider_id: str):
  120. if not current_user.is_editor:
  121. raise Forbidden()
  122. parser = reqparse.RequestParser()
  123. parser.add_argument(
  124. "name", type=StrLen(max_length=100), required=False, nullable=True, location="json", default=None
  125. )
  126. parser.add_argument("credentials", type=dict, required=True, nullable=False, location="json")
  127. args = parser.parse_args()
  128. datasource_provider_id = DatasourceProviderID(provider_id)
  129. datasource_provider_service = DatasourceProviderService()
  130. try:
  131. datasource_provider_service.add_datasource_api_key_provider(
  132. tenant_id=current_user.current_tenant_id,
  133. provider_id=datasource_provider_id,
  134. credentials=args["credentials"],
  135. name=args["name"],
  136. )
  137. except CredentialsValidateFailedError as ex:
  138. raise ValueError(str(ex))
  139. return {"result": "success"}, 200
  140. @setup_required
  141. @login_required
  142. @account_initialization_required
  143. def get(self, provider_id: str):
  144. datasource_provider_id = DatasourceProviderID(provider_id)
  145. datasource_provider_service = DatasourceProviderService()
  146. datasources = datasource_provider_service.list_datasource_credentials(
  147. tenant_id=current_user.current_tenant_id,
  148. provider=datasource_provider_id.provider_name,
  149. plugin_id=datasource_provider_id.plugin_id,
  150. )
  151. return {"result": datasources}, 200
  152. class DatasourceAuthDeleteApi(Resource):
  153. @setup_required
  154. @login_required
  155. @account_initialization_required
  156. def post(self, provider_id: str):
  157. datasource_provider_id = DatasourceProviderID(provider_id)
  158. plugin_id = datasource_provider_id.plugin_id
  159. provider_name = datasource_provider_id.provider_name
  160. if not current_user.is_editor:
  161. raise Forbidden()
  162. parser = reqparse.RequestParser()
  163. parser.add_argument("credential_id", type=str, required=True, nullable=False, location="json")
  164. args = parser.parse_args()
  165. datasource_provider_service = DatasourceProviderService()
  166. datasource_provider_service.remove_datasource_credentials(
  167. tenant_id=current_user.current_tenant_id,
  168. auth_id=args["credential_id"],
  169. provider=provider_name,
  170. plugin_id=plugin_id,
  171. )
  172. return {"result": "success"}, 200
  173. class DatasourceAuthUpdateApi(Resource):
  174. @setup_required
  175. @login_required
  176. @account_initialization_required
  177. def post(self, provider_id: str):
  178. datasource_provider_id = DatasourceProviderID(provider_id)
  179. parser = reqparse.RequestParser()
  180. parser.add_argument("credentials", type=dict, required=False, nullable=True, location="json")
  181. parser.add_argument("name", type=StrLen(max_length=100), required=False, nullable=True, location="json")
  182. parser.add_argument("credential_id", type=str, required=True, nullable=False, location="json")
  183. args = parser.parse_args()
  184. if not current_user.is_editor:
  185. raise Forbidden()
  186. datasource_provider_service = DatasourceProviderService()
  187. datasource_provider_service.update_datasource_credentials(
  188. tenant_id=current_user.current_tenant_id,
  189. auth_id=args["credential_id"],
  190. provider=datasource_provider_id.provider_name,
  191. plugin_id=datasource_provider_id.plugin_id,
  192. credentials=args.get("credentials", {}),
  193. name=args.get("name", None),
  194. )
  195. return {"result": "success"}, 201
  196. class DatasourceAuthListApi(Resource):
  197. @setup_required
  198. @login_required
  199. @account_initialization_required
  200. def get(self):
  201. datasource_provider_service = DatasourceProviderService()
  202. datasources = datasource_provider_service.get_all_datasource_credentials(
  203. tenant_id=current_user.current_tenant_id
  204. )
  205. return {"result": jsonable_encoder(datasources)}, 200
  206. class DatasourceHardCodeAuthListApi(Resource):
  207. @setup_required
  208. @login_required
  209. @account_initialization_required
  210. def get(self):
  211. datasource_provider_service = DatasourceProviderService()
  212. datasources = datasource_provider_service.get_hard_code_datasource_credentials(
  213. tenant_id=current_user.current_tenant_id
  214. )
  215. return {"result": jsonable_encoder(datasources)}, 200
  216. class DatasourceAuthOauthCustomClient(Resource):
  217. @setup_required
  218. @login_required
  219. @account_initialization_required
  220. def post(self, provider_id: str):
  221. if not current_user.is_editor:
  222. raise Forbidden()
  223. parser = reqparse.RequestParser()
  224. parser.add_argument("client_params", type=dict, required=False, nullable=True, location="json")
  225. parser.add_argument("enable_oauth_custom_client", type=bool, required=False, nullable=True, location="json")
  226. args = parser.parse_args()
  227. datasource_provider_id = DatasourceProviderID(provider_id)
  228. datasource_provider_service = DatasourceProviderService()
  229. datasource_provider_service.setup_oauth_custom_client_params(
  230. tenant_id=current_user.current_tenant_id,
  231. datasource_provider_id=datasource_provider_id,
  232. client_params=args.get("client_params", {}),
  233. enabled=args.get("enable_oauth_custom_client", False),
  234. )
  235. return {"result": "success"}, 200
  236. @setup_required
  237. @login_required
  238. @account_initialization_required
  239. def delete(self, provider_id: str):
  240. datasource_provider_id = DatasourceProviderID(provider_id)
  241. datasource_provider_service = DatasourceProviderService()
  242. datasource_provider_service.remove_oauth_custom_client_params(
  243. tenant_id=current_user.current_tenant_id,
  244. datasource_provider_id=datasource_provider_id,
  245. )
  246. return {"result": "success"}, 200
  247. class DatasourceAuthDefaultApi(Resource):
  248. @setup_required
  249. @login_required
  250. @account_initialization_required
  251. def post(self, provider_id: str):
  252. if not current_user.is_editor:
  253. raise Forbidden()
  254. parser = reqparse.RequestParser()
  255. parser.add_argument("id", type=str, required=True, nullable=False, location="json")
  256. args = parser.parse_args()
  257. datasource_provider_id = DatasourceProviderID(provider_id)
  258. datasource_provider_service = DatasourceProviderService()
  259. datasource_provider_service.set_default_datasource_provider(
  260. tenant_id=current_user.current_tenant_id,
  261. datasource_provider_id=datasource_provider_id,
  262. credential_id=args["id"],
  263. )
  264. return {"result": "success"}, 200
  265. class DatasourceUpdateProviderNameApi(Resource):
  266. @setup_required
  267. @login_required
  268. @account_initialization_required
  269. def post(self, provider_id: str):
  270. if not current_user.is_editor:
  271. raise Forbidden()
  272. parser = reqparse.RequestParser()
  273. parser.add_argument("name", type=StrLen(max_length=100), required=True, nullable=False, location="json")
  274. parser.add_argument("credential_id", type=str, required=True, nullable=False, location="json")
  275. args = parser.parse_args()
  276. datasource_provider_id = DatasourceProviderID(provider_id)
  277. datasource_provider_service = DatasourceProviderService()
  278. datasource_provider_service.update_datasource_provider_name(
  279. tenant_id=current_user.current_tenant_id,
  280. datasource_provider_id=datasource_provider_id,
  281. name=args["name"],
  282. credential_id=args["credential_id"],
  283. )
  284. return {"result": "success"}, 200
  285. api.add_resource(
  286. DatasourcePluginOAuthAuthorizationUrl,
  287. "/oauth/plugin/<path:provider_id>/datasource/get-authorization-url",
  288. )
  289. api.add_resource(
  290. DatasourceOAuthCallback,
  291. "/oauth/plugin/<path:provider_id>/datasource/callback",
  292. )
  293. api.add_resource(
  294. DatasourceAuth,
  295. "/auth/plugin/datasource/<path:provider_id>",
  296. )
  297. api.add_resource(
  298. DatasourceAuthUpdateApi,
  299. "/auth/plugin/datasource/<path:provider_id>/update",
  300. )
  301. api.add_resource(
  302. DatasourceAuthDeleteApi,
  303. "/auth/plugin/datasource/<path:provider_id>/delete",
  304. )
  305. api.add_resource(
  306. DatasourceAuthListApi,
  307. "/auth/plugin/datasource/list",
  308. )
  309. api.add_resource(
  310. DatasourceHardCodeAuthListApi,
  311. "/auth/plugin/datasource/default-list",
  312. )
  313. api.add_resource(
  314. DatasourceAuthOauthCustomClient,
  315. "/auth/plugin/datasource/<path:provider_id>/custom-client",
  316. )
  317. api.add_resource(
  318. DatasourceAuthDefaultApi,
  319. "/auth/plugin/datasource/<path:provider_id>/default",
  320. )
  321. api.add_resource(
  322. DatasourceUpdateProviderNameApi,
  323. "/auth/plugin/datasource/<path:provider_id>/update-name",
  324. )