選択できるのは25トピックまでです。 トピックは、先頭が英数字で、英数字とダッシュ('-')を使用した35文字以内のものにしてください。

user_app.py 14KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391
  1. #
  2. # Copyright 2024 The InfiniFlow Authors. All Rights Reserved.
  3. #
  4. # Licensed under the Apache License, Version 2.0 (the "License");
  5. # you may not use this file except in compliance with the License.
  6. # You may obtain a copy of the License at
  7. #
  8. # http://www.apache.org/licenses/LICENSE-2.0
  9. #
  10. # Unless required by applicable law or agreed to in writing, software
  11. # distributed under the License is distributed on an "AS IS" BASIS,
  12. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  13. # See the License for the specific language governing permissions and
  14. # limitations under the License.
  15. #
  16. import json
  17. import re
  18. from datetime import datetime
  19. from flask import request, session, redirect
  20. from werkzeug.security import generate_password_hash, check_password_hash
  21. from flask_login import login_required, current_user, login_user, logout_user
  22. from api.db.db_models import TenantLLM
  23. from api.db.services.llm_service import TenantLLMService, LLMService
  24. from api.utils.api_utils import server_error_response, validate_request
  25. from api.utils import get_uuid, get_format_time, decrypt, download_img, current_timestamp, datetime_format
  26. from api.db import UserTenantRole, LLMType, FileType
  27. from api.settings import RetCode, GITHUB_OAUTH, FEISHU_OAUTH, CHAT_MDL, EMBEDDING_MDL, ASR_MDL, IMAGE2TEXT_MDL, PARSERS, \
  28. API_KEY, \
  29. LLM_FACTORY, LLM_BASE_URL, RERANK_MDL
  30. from api.db.services.user_service import UserService, TenantService, UserTenantService
  31. from api.db.services.file_service import FileService
  32. from api.settings import stat_logger
  33. from api.utils.api_utils import get_json_result, cors_reponse
  34. @manager.route('/login', methods=['POST', 'GET'])
  35. def login():
  36. login_channel = "password"
  37. if not request.json:
  38. return get_json_result(data=False, retcode=RetCode.AUTHENTICATION_ERROR,
  39. retmsg='Unautherized!')
  40. email = request.json.get('email', "")
  41. users = UserService.query(email=email)
  42. if not users:
  43. return get_json_result(
  44. data=False, retcode=RetCode.AUTHENTICATION_ERROR, retmsg=f'This Email is not registered!')
  45. password = request.json.get('password')
  46. try:
  47. password = decrypt(password)
  48. except BaseException:
  49. return get_json_result(
  50. data=False, retcode=RetCode.SERVER_ERROR, retmsg='Fail to crypt password')
  51. user = UserService.query_user(email, password)
  52. if user:
  53. response_data = user.to_json()
  54. user.access_token = get_uuid()
  55. login_user(user)
  56. user.update_time = current_timestamp(),
  57. user.update_date = datetime_format(datetime.now()),
  58. user.save()
  59. msg = "Welcome back!"
  60. return cors_reponse(data=response_data, auth=user.get_id(), retmsg=msg)
  61. else:
  62. return get_json_result(data=False, retcode=RetCode.AUTHENTICATION_ERROR,
  63. retmsg='Email and Password do not match!')
  64. @manager.route('/github_callback', methods=['GET'])
  65. def github_callback():
  66. import requests
  67. res = requests.post(GITHUB_OAUTH.get("url"), data={
  68. "client_id": GITHUB_OAUTH.get("client_id"),
  69. "client_secret": GITHUB_OAUTH.get("secret_key"),
  70. "code": request.args.get('code')
  71. }, headers={"Accept": "application/json"})
  72. res = res.json()
  73. if "error" in res:
  74. return redirect("/?error=%s" % res["error_description"])
  75. if "user:email" not in res["scope"].split(","):
  76. return redirect("/?error=user:email not in scope")
  77. session["access_token"] = res["access_token"]
  78. session["access_token_from"] = "github"
  79. userinfo = user_info_from_github(session["access_token"])
  80. users = UserService.query(email=userinfo["email"])
  81. user_id = get_uuid()
  82. if not users:
  83. try:
  84. try:
  85. avatar = download_img(userinfo["avatar_url"])
  86. except Exception as e:
  87. stat_logger.exception(e)
  88. avatar = ""
  89. users = user_register(user_id, {
  90. "access_token": session["access_token"],
  91. "email": userinfo["email"],
  92. "avatar": avatar,
  93. "nickname": userinfo["login"],
  94. "login_channel": "github",
  95. "last_login_time": get_format_time(),
  96. "is_superuser": False,
  97. })
  98. if not users:
  99. raise Exception('Register user failure.')
  100. if len(users) > 1:
  101. raise Exception('Same E-mail exist!')
  102. user = users[0]
  103. login_user(user)
  104. return redirect("/?auth=%s" % user.get_id())
  105. except Exception as e:
  106. rollback_user_registration(user_id)
  107. stat_logger.exception(e)
  108. return redirect("/?error=%s" % str(e))
  109. user = users[0]
  110. user.access_token = get_uuid()
  111. login_user(user)
  112. user.save()
  113. return redirect("/?auth=%s" % user.get_id())
  114. @manager.route('/feishu_callback', methods=['GET'])
  115. def feishu_callback():
  116. import requests
  117. app_access_token_res = requests.post(FEISHU_OAUTH.get("app_access_token_url"), data=json.dumps({
  118. "app_id": FEISHU_OAUTH.get("app_id"),
  119. "app_secret": FEISHU_OAUTH.get("app_secret")
  120. }), headers={"Content-Type": "application/json; charset=utf-8"})
  121. app_access_token_res = app_access_token_res.json()
  122. if app_access_token_res['code'] != 0:
  123. return redirect("/?error=%s" % app_access_token_res)
  124. res = requests.post(FEISHU_OAUTH.get("user_access_token_url"), data=json.dumps({
  125. "grant_type": FEISHU_OAUTH.get("grant_type"),
  126. "code": request.args.get('code')
  127. }), headers={"Content-Type": "application/json; charset=utf-8",
  128. 'Authorization': f"Bearer {app_access_token_res['app_access_token']}"})
  129. res = res.json()
  130. if res['code'] != 0:
  131. return redirect("/?error=%s" % res["message"])
  132. if "contact:user.email:readonly" not in res["data"]["scope"].split(" "):
  133. return redirect("/?error=contact:user.email:readonly not in scope")
  134. session["access_token"] = res["data"]["access_token"]
  135. session["access_token_from"] = "feishu"
  136. userinfo = user_info_from_feishu(session["access_token"])
  137. users = UserService.query(email=userinfo["email"])
  138. user_id = get_uuid()
  139. if not users:
  140. try:
  141. try:
  142. avatar = download_img(userinfo["avatar_url"])
  143. except Exception as e:
  144. stat_logger.exception(e)
  145. avatar = ""
  146. users = user_register(user_id, {
  147. "access_token": session["access_token"],
  148. "email": userinfo["email"],
  149. "avatar": avatar,
  150. "nickname": userinfo["en_name"],
  151. "login_channel": "feishu",
  152. "last_login_time": get_format_time(),
  153. "is_superuser": False,
  154. })
  155. if not users:
  156. raise Exception('Register user failure.')
  157. if len(users) > 1:
  158. raise Exception('Same E-mail exist!')
  159. user = users[0]
  160. login_user(user)
  161. return redirect("/?auth=%s" % user.get_id())
  162. except Exception as e:
  163. rollback_user_registration(user_id)
  164. stat_logger.exception(e)
  165. return redirect("/?error=%s" % str(e))
  166. user = users[0]
  167. user.access_token = get_uuid()
  168. login_user(user)
  169. user.save()
  170. return redirect("/?auth=%s" % user.get_id())
  171. def user_info_from_feishu(access_token):
  172. import requests
  173. headers = {"Content-Type": "application/json; charset=utf-8",
  174. 'Authorization': f"Bearer {access_token}"}
  175. res = requests.get(
  176. f"https://open.feishu.cn/open-apis/authen/v1/user_info",
  177. headers=headers)
  178. user_info = res.json()["data"]
  179. user_info["email"] = None if user_info.get("email") == "" else user_info["email"]
  180. return user_info
  181. def user_info_from_github(access_token):
  182. import requests
  183. headers = {"Accept": "application/json",
  184. 'Authorization': f"token {access_token}"}
  185. res = requests.get(
  186. f"https://api.github.com/user?access_token={access_token}",
  187. headers=headers)
  188. user_info = res.json()
  189. email_info = requests.get(
  190. f"https://api.github.com/user/emails?access_token={access_token}",
  191. headers=headers).json()
  192. user_info["email"] = next(
  193. (email for email in email_info if email['primary'] == True),
  194. None)["email"]
  195. return user_info
  196. @manager.route("/logout", methods=['GET'])
  197. @login_required
  198. def log_out():
  199. current_user.access_token = ""
  200. current_user.save()
  201. logout_user()
  202. return get_json_result(data=True)
  203. @manager.route("/setting", methods=["POST"])
  204. @login_required
  205. def setting_user():
  206. update_dict = {}
  207. request_data = request.json
  208. if request_data.get("password"):
  209. new_password = request_data.get("new_password")
  210. if not check_password_hash(
  211. current_user.password, decrypt(request_data["password"])):
  212. return get_json_result(
  213. data=False, retcode=RetCode.AUTHENTICATION_ERROR, retmsg='Password error!')
  214. if new_password:
  215. update_dict["password"] = generate_password_hash(
  216. decrypt(new_password))
  217. for k in request_data.keys():
  218. if k in ["password", "new_password"]:
  219. continue
  220. update_dict[k] = request_data[k]
  221. try:
  222. UserService.update_by_id(current_user.id, update_dict)
  223. return get_json_result(data=True)
  224. except Exception as e:
  225. stat_logger.exception(e)
  226. return get_json_result(
  227. data=False, retmsg='Update failure!', retcode=RetCode.EXCEPTION_ERROR)
  228. @manager.route("/info", methods=["GET"])
  229. @login_required
  230. def user_info():
  231. return get_json_result(data=current_user.to_dict())
  232. def rollback_user_registration(user_id):
  233. try:
  234. UserService.delete_by_id(user_id)
  235. except Exception as e:
  236. pass
  237. try:
  238. TenantService.delete_by_id(user_id)
  239. except Exception as e:
  240. pass
  241. try:
  242. u = UserTenantService.query(tenant_id=user_id)
  243. if u:
  244. UserTenantService.delete_by_id(u[0].id)
  245. except Exception as e:
  246. pass
  247. try:
  248. TenantLLM.delete().where(TenantLLM.tenant_id == user_id).execute()
  249. except Exception as e:
  250. pass
  251. def user_register(user_id, user):
  252. user["id"] = user_id
  253. tenant = {
  254. "id": user_id,
  255. "name": user["nickname"] + "‘s Kingdom",
  256. "llm_id": CHAT_MDL,
  257. "embd_id": EMBEDDING_MDL,
  258. "asr_id": ASR_MDL,
  259. "parser_ids": PARSERS,
  260. "img2txt_id": IMAGE2TEXT_MDL,
  261. "rerank_id": RERANK_MDL
  262. }
  263. usr_tenant = {
  264. "tenant_id": user_id,
  265. "user_id": user_id,
  266. "invited_by": user_id,
  267. "role": UserTenantRole.OWNER
  268. }
  269. file_id = get_uuid()
  270. file = {
  271. "id": file_id,
  272. "parent_id": file_id,
  273. "tenant_id": user_id,
  274. "created_by": user_id,
  275. "name": "/",
  276. "type": FileType.FOLDER.value,
  277. "size": 0,
  278. "location": "",
  279. }
  280. tenant_llm = []
  281. for llm in LLMService.query(fid=LLM_FACTORY):
  282. tenant_llm.append({"tenant_id": user_id,
  283. "llm_factory": LLM_FACTORY,
  284. "llm_name": llm.llm_name,
  285. "model_type": llm.model_type,
  286. "api_key": API_KEY,
  287. "api_base": LLM_BASE_URL
  288. })
  289. if not UserService.save(**user):
  290. return
  291. TenantService.insert(**tenant)
  292. UserTenantService.insert(**usr_tenant)
  293. TenantLLMService.insert_many(tenant_llm)
  294. FileService.insert(file)
  295. return UserService.query(email=user["email"])
  296. @manager.route("/register", methods=["POST"])
  297. @validate_request("nickname", "email", "password")
  298. def user_add():
  299. req = request.json
  300. if UserService.query(email=req["email"]):
  301. return get_json_result(
  302. data=False, retmsg=f'Email: {req["email"]} has already registered!', retcode=RetCode.OPERATING_ERROR)
  303. if not re.match(r"^[\w\._-]+@([\w_-]+\.)+[\w-]{2,4}$", req["email"]):
  304. return get_json_result(data=False, retmsg=f'Invaliad e-mail: {req["email"]}!',
  305. retcode=RetCode.OPERATING_ERROR)
  306. user_dict = {
  307. "access_token": get_uuid(),
  308. "email": req["email"],
  309. "nickname": req["nickname"],
  310. "password": decrypt(req["password"]),
  311. "login_channel": "password",
  312. "last_login_time": get_format_time(),
  313. "is_superuser": False,
  314. }
  315. user_id = get_uuid()
  316. try:
  317. users = user_register(user_id, user_dict)
  318. if not users:
  319. raise Exception('Register user failure.')
  320. if len(users) > 1:
  321. raise Exception('Same E-mail exist!')
  322. user = users[0]
  323. login_user(user)
  324. return cors_reponse(data=user.to_json(),
  325. auth=user.get_id(), retmsg="Welcome aboard!")
  326. except Exception as e:
  327. rollback_user_registration(user_id)
  328. stat_logger.exception(e)
  329. return get_json_result(
  330. data=False, retmsg='User registration failure!', retcode=RetCode.EXCEPTION_ERROR)
  331. @manager.route("/tenant_info", methods=["GET"])
  332. @login_required
  333. def tenant_info():
  334. try:
  335. tenants = TenantService.get_by_user_id(current_user.id)[0]
  336. return get_json_result(data=tenants)
  337. except Exception as e:
  338. return server_error_response(e)
  339. @manager.route("/set_tenant_info", methods=["POST"])
  340. @login_required
  341. @validate_request("tenant_id", "asr_id", "embd_id", "img2txt_id", "llm_id")
  342. def set_tenant_info():
  343. req = request.json
  344. try:
  345. tid = req["tenant_id"]
  346. del req["tenant_id"]
  347. TenantService.update_by_id(tid, req)
  348. return get_json_result(data=True)
  349. except Exception as e:
  350. return server_error_response(e)