mirror of
https://github.com/suitenumerique/meet.git
synced 2026-08-26 02:06:53 +00:00
🔧(backend) add setting to toggle application token exchange mechanism
Introduce a configuration flag to enable or disable the application token exchange (service account) mechanism. This allows activating alternative authentication backends without requiring full application token configuration. Required to support the upcoming add-ons authentication backend.
This commit is contained in:
@@ -23,7 +23,14 @@ class BaseJWTAuthentication(authentication.BaseAuthentication):
|
||||
"""Base JWT authentication class."""
|
||||
|
||||
def __init__(
|
||||
self, secret_key, algorithm, issuer, audience, expiration_seconds, token_type
|
||||
self,
|
||||
secret_key,
|
||||
algorithm,
|
||||
issuer,
|
||||
audience,
|
||||
expiration_seconds,
|
||||
token_type,
|
||||
is_enabled,
|
||||
):
|
||||
"""Initialize the JWT authentication backend with the given token service configuration.
|
||||
|
||||
@@ -34,10 +41,17 @@ class BaseJWTAuthentication(authentication.BaseAuthentication):
|
||||
audience: Expected token audience identifier
|
||||
expiration_seconds: Token expiration time in seconds
|
||||
token_type: Token type (e.g. Bearer)
|
||||
is_enabled: Whether this authentication backend is active
|
||||
"""
|
||||
|
||||
super().__init__()
|
||||
|
||||
self.is_enabled = is_enabled
|
||||
self._token_service = None
|
||||
|
||||
if not self.is_enabled:
|
||||
return
|
||||
|
||||
self._token_service = jwt_token.JwtTokenService(
|
||||
secret_key=secret_key,
|
||||
algorithm=algorithm,
|
||||
@@ -54,6 +68,9 @@ class BaseJWTAuthentication(authentication.BaseAuthentication):
|
||||
Tuple of (user, payload) if authentication successful, None otherwise
|
||||
"""
|
||||
|
||||
if not self.is_enabled:
|
||||
return None
|
||||
|
||||
auth_header = authentication.get_authorization_header(request).split()
|
||||
|
||||
if not auth_header or auth_header[0].lower() != b"bearer":
|
||||
@@ -186,6 +203,7 @@ class ApplicationJWTAuthentication(BaseJWTAuthentication):
|
||||
audience=settings.APPLICATION_JWT_AUDIENCE,
|
||||
expiration_seconds=settings.APPLICATION_JWT_EXPIRATION_SECONDS,
|
||||
token_type=settings.APPLICATION_JWT_TOKEN_TYPE,
|
||||
is_enabled=settings.APPLICATION_ENABLED,
|
||||
)
|
||||
|
||||
def validate_payload(self, payload):
|
||||
|
||||
@@ -20,6 +20,7 @@ from rest_framework import (
|
||||
)
|
||||
|
||||
from core import api, models
|
||||
from core.api.feature_flag import FeatureFlag
|
||||
from core.services.jwt_token import JwtTokenService
|
||||
|
||||
from . import authentication, permissions, serializers
|
||||
@@ -36,6 +37,7 @@ class ApplicationViewSet(viewsets.ViewSet):
|
||||
url_path="token",
|
||||
url_name="token",
|
||||
)
|
||||
@FeatureFlag.require("application")
|
||||
def generate_jwt_access_token(self, request, *args, **kwargs):
|
||||
"""Generate JWT access token for application delegation.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user