|
| 1 | +import html |
| 2 | +import logging |
| 3 | +from http import HTTPStatus |
| 4 | +from typing import Optional |
| 5 | +from urllib.parse import parse_qs, urlsplit |
| 6 | + |
| 7 | +from fastapi import APIRouter, HTTPException, Query, Request |
| 8 | +from fastapi.responses import HTMLResponse, JSONResponse, RedirectResponse |
| 9 | + |
| 10 | +from services.cas_service import ( |
| 11 | + CAS_SERVER_URL, |
| 12 | + CasAuthenticationError, |
| 13 | + build_login_url, |
| 14 | + build_renew_url, |
| 15 | + get_cas_config, |
| 16 | + login_with_ticket, |
| 17 | + renew_with_ticket, |
| 18 | + revoke_from_logout_request, |
| 19 | +) |
| 20 | + |
| 21 | +logger = logging.getLogger(__name__) |
| 22 | +router = APIRouter(prefix="/user/cas", tags=["cas"]) |
| 23 | + |
| 24 | + |
| 25 | +@router.get("/config") |
| 26 | +async def config(): |
| 27 | + return JSONResponse( |
| 28 | + status_code=HTTPStatus.OK, |
| 29 | + content={"message": "success", "data": get_cas_config()}, |
| 30 | + ) |
| 31 | + |
| 32 | + |
| 33 | +@router.get("/login") |
| 34 | +async def login(redirect: str = Query("/", description="URL to return to after login")): |
| 35 | + try: |
| 36 | + login_url = _require_cas_server_redirect(build_login_url(redirect)) |
| 37 | + return RedirectResponse(url=login_url, status_code=HTTPStatus.FOUND) |
| 38 | + except CasAuthenticationError as exc: |
| 39 | + logger.warning("CAS login rejected: %s", exc) |
| 40 | + raise HTTPException(status_code=HTTPStatus.BAD_REQUEST, detail="CAS login is not available") |
| 41 | + |
| 42 | + |
| 43 | +@router.get("/callback") |
| 44 | +async def callback(ticket: str = "", redirect: str = "/"): |
| 45 | + try: |
| 46 | + result = await login_with_ticket(ticket, redirect) |
| 47 | + return JSONResponse( |
| 48 | + status_code=HTTPStatus.OK, |
| 49 | + content={"message": "CAS login successful", "data": result}, |
| 50 | + ) |
| 51 | + except CasAuthenticationError as exc: |
| 52 | + logger.warning("CAS callback rejected: %s", exc) |
| 53 | + raise HTTPException(status_code=HTTPStatus.UNAUTHORIZED, detail="CAS authentication failed") |
| 54 | + except Exception as exc: |
| 55 | + logger.error(f"CAS callback failed: {exc}") |
| 56 | + raise HTTPException(status_code=HTTPStatus.INTERNAL_SERVER_ERROR, detail="CAS login failed") |
| 57 | + |
| 58 | + |
| 59 | +@router.post("/callback") |
| 60 | +async def callback_logout(request: Request, logout_request: Optional[str] = None): |
| 61 | + return await _handle_logout_request(request, logout_request, endpoint="callback") |
| 62 | + |
| 63 | + |
| 64 | +@router.get("/renew") |
| 65 | +async def renew(): |
| 66 | + try: |
| 67 | + return RedirectResponse(url=build_renew_url(), status_code=HTTPStatus.FOUND) |
| 68 | + except CasAuthenticationError as exc: |
| 69 | + logger.warning("CAS renew rejected: %s", exc) |
| 70 | + return _renew_html(False, "CAS renew failed") |
| 71 | + |
| 72 | + |
| 73 | +@router.get("/renew_callback") |
| 74 | +async def renew_callback(ticket: str = ""): |
| 75 | + if not ticket: |
| 76 | + return _renew_html(False, "CAS session is not active") |
| 77 | + try: |
| 78 | + result = await renew_with_ticket(ticket) |
| 79 | + return JSONResponse( |
| 80 | + status_code=HTTPStatus.OK, |
| 81 | + content={"message": "CAS renew successful", "data": result}, |
| 82 | + ) |
| 83 | + except Exception as exc: |
| 84 | + logger.warning(f"CAS renew failed: {exc}") |
| 85 | + return _renew_html(False, "CAS renew failed") |
| 86 | + |
| 87 | + |
| 88 | +@router.post("/logout_callback") |
| 89 | +async def logout_callback( |
| 90 | + request: Request, |
| 91 | + logout_request: Optional[str] = None, |
| 92 | +): |
| 93 | + return await _handle_logout_request(request, logout_request, endpoint="logout_callback") |
| 94 | + |
| 95 | + |
| 96 | +async def _handle_logout_request( |
| 97 | + request: Request, |
| 98 | + logout_request: Optional[str] = None, |
| 99 | + endpoint: str = "unknown", |
| 100 | +): |
| 101 | + logout_request = await _extract_logout_request(request, logout_request) |
| 102 | + logger.info( |
| 103 | + "CAS SLO %s received logoutRequest: present=%s length=%s", |
| 104 | + endpoint, |
| 105 | + bool(logout_request), |
| 106 | + len(logout_request or ""), |
| 107 | + ) |
| 108 | + result = revoke_from_logout_request(logout_request) |
| 109 | + logger.info("CAS SLO %s revoke result: %s", endpoint, result) |
| 110 | + return JSONResponse( |
| 111 | + status_code=HTTPStatus.OK, |
| 112 | + content={"message": "success", "data": result}, |
| 113 | + ) |
| 114 | + |
| 115 | + |
| 116 | +async def _extract_logout_request(request: Request, logout_request: Optional[str] = None) -> str: |
| 117 | + if logout_request: |
| 118 | + return logout_request |
| 119 | + |
| 120 | + query_logout_request = request.query_params.get("logoutRequest") or request.query_params.get("logout_request") |
| 121 | + if query_logout_request: |
| 122 | + return query_logout_request |
| 123 | + |
| 124 | + body = await request.body() |
| 125 | + raw_body = body.decode("utf-8") if body else "" |
| 126 | + if not raw_body: |
| 127 | + return "" |
| 128 | + |
| 129 | + parsed = parse_qs(raw_body) |
| 130 | + return (parsed.get("logoutRequest") or parsed.get("logout_request") or [raw_body])[0] |
| 131 | + |
| 132 | + |
| 133 | +def _renew_html(success: bool, reason: str = "") -> HTMLResponse: |
| 134 | + status = "success" if success else "failed" |
| 135 | + safe_reason = html.escape(reason) |
| 136 | + return HTMLResponse( |
| 137 | + status_code=HTTPStatus.OK, |
| 138 | + content=f"""<!doctype html> |
| 139 | +<html><body><script> |
| 140 | +window.parent && window.parent.postMessage({{ type: "cas-renew-{status}", reason: "{safe_reason}" }}, window.location.origin); |
| 141 | +</script></body></html>""", |
| 142 | + ) |
| 143 | + |
| 144 | + |
| 145 | +def _require_cas_server_redirect(url: str) -> str: |
| 146 | + parsed_url = urlsplit(url) |
| 147 | + parsed_cas = urlsplit(CAS_SERVER_URL) |
| 148 | + if ( |
| 149 | + parsed_url.scheme not in {"http", "https"} |
| 150 | + or not parsed_url.netloc |
| 151 | + or parsed_url.scheme != parsed_cas.scheme |
| 152 | + or parsed_url.netloc != parsed_cas.netloc |
| 153 | + ): |
| 154 | + logger.warning("Blocked CAS redirect outside configured server: %s", url) |
| 155 | + raise CasAuthenticationError("Invalid CAS redirect URL") |
| 156 | + return url |
0 commit comments