Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -68,13 +68,17 @@ version = "5.2.0"
[project.optional-dependencies]
all = [
"social-auth-core[azuread]",
"social-auth-core[cas]",
"social-auth-core[google-onetap]",
"social-auth-core[saml]",
"social-auth-core[shopify]"
]
allpy3 = [
"social-auth-core[all]"
]
cas = [
"python-cas>=1.7.2"
]
# This is present until pip implements supports for PEP 735
# see https://github.com/pypa/pip/issues/12963
dev = [
Expand Down Expand Up @@ -129,6 +133,7 @@ check_untyped_defs = true
disallow_untyped_defs = true
ignore_missing_imports = true
module = [
"cas",
"google.appengine.*",
"onelogin.*",
"openid.*",
Expand Down
67 changes: 67 additions & 0 deletions social_core/backends/cas_generic.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
"""
Generic CAS backend

Backend to authenticat with a generic CAS server.
"""

from __future__ import annotations

from cas import CASClient, CASClientV1, CASClientV2, CASClientV3, CASClientWithSAMLV1

from social_core.exceptions import AuthTokenError, SocialAuthImproperlyConfiguredError

Check failure on line 11 in social_core/backends/cas_generic.py

View workflow job for this annotation

GitHub Actions / ty

ty (unresolved-import)

social_core/backends/cas_generic.py:11:52: unresolved-import: Module `social_core.exceptions` has no member `SocialAuthImproperlyConfiguredError`

Check failure on line 11 in social_core/backends/cas_generic.py

View workflow job for this annotation

GitHub Actions / ty

ty (unresolved-import)

social_core/backends/cas_generic.py:11:36: unresolved-import: Module `social_core.exceptions` has no member `AuthTokenError`

Check failure on line 11 in social_core/backends/cas_generic.py

View workflow job for this annotation

GitHub Actions / pylint

E0611

No name 'SocialAuthImproperlyConfiguredError' in module 'social_core.exceptions'

Check failure on line 11 in social_core/backends/cas_generic.py

View workflow job for this annotation

GitHub Actions / pylint

E0611

No name 'AuthTokenError' in module 'social_core.exceptions'

from .base import BaseAuth


class CasAuth(BaseAuth):
name = "cas"
title = "Cas"

ID_KEY = "cas_user"
SERVER_URL: str | None = None

def auth_url(self) -> str:
client = self.get_cas_client()

url = client.get_login_url()
self.log_debug(f"Redirecting to CAS login: {url}")
return url

def get_cas_client(
self,
) -> CASClientV1 | CASClientV2 | CASClientV3 | CASClientWithSAMLV1:
"""
initializes the CASClient according to
the CAS_* settings
"""
server_url = self.setting("SERVER_URL", self.SERVER_URL)
service_url = self.redirect_uri

if not server_url:
raise SocialAuthImproperlyConfiguredError

version = self.setting("VERSION", 3)
kwargs = {
"service_url": service_url,
"server_url": server_url,
"extra_login_params": self.setting("EXTRA_LOGIN_PARAMS", []),
}

# ty checks don't like __new__ to return a different type
return CASClient.__new__(CASClient, version=version, **kwargs)

def auth_complete(self, *args, **kwargs):
client = self.get_cas_client()
ticket = self.strategy.request_data().get("ticket")
user, attributes, _pgtiou = client.verify_ticket(ticket)
if user is None or attributes is None:
raise AuthTokenError(self, "Token verification did not succeed")
kwargs.update({"response": attributes | {"cas_user": user}, "backend": self})
return self.strategy.authenticate(*args, **kwargs)

def get_user_details(self, response):
return {
"username": response.get(self.id_key()),
"email": response.get(self.setting("EMAIL_FIELD", "email")),
"fullname": response.get(self.setting("NAME_FIELD", "name")),
}
73 changes: 73 additions & 0 deletions social_core/tests/backends/test_cas_generic.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
from __future__ import annotations

import urllib.parse

import responses

from social_core.tests.strategy import TEST_URI

from .base import BaseBackendTest

VALIDATION_PAYLOAD = b"""
<cas:serviceResponse xmlns:cas="http://www.yale.edu/tp/cas">
<cas:authenticationSuccess>
<cas:user>test</cas:user>
<cas:attributes>
<cas:authenticationDate>1970-01-01T00:00:00+00:00</cas:authenticationDate>
<cas:longTermAuthenticationRequestTokenUsed>false</cas:longTermAuthenticationRequestTokenUsed>
<cas:isFromNewLogin>true</cas:isFromNewLogin>
<cas:email>test@example.com</cas:email>
<cas:name>Firstname Lastname</cas:name>
</cas:attributes>
<cas:attribute name="authenticationDate" value="1970-00-00T00:00:00+00:00"/>
<cas:attribute name="longTermAuthenticationRequestTokenUsed" value="false"/>
<cas:attribute name="isFromNewLogin" value="true"/>
<cas:attribute name="email" value="test@example.com"/>
<cas:attribute name="name" value="Firstname Lastname"/>
</cas:authenticationSuccess>
</cas:serviceResponse>
"""


class CasAuthTest(BaseBackendTest):
backend_path = "social_core.backends.cas_generic.CasAuth"
expected_username = "test"
ticket = "ST-12345678"
server_url = "http://cas-server.com/"
service_url = TEST_URI
validate_endpoint = "p3/serviceValidate"

def setUp(self) -> None:
super().setUp()

Check failure on line 41 in social_core/tests/backends/test_cas_generic.py

View workflow job for this annotation

GitHub Actions / test (3.12)

CasAuthTest.test_partial_pipeline ImportError: cannot import name 'AuthTokenError' from 'social_core.exceptions' (/home/runner/work/social-core/social-core/social_core/exceptions.py)

Check failure on line 41 in social_core/tests/backends/test_cas_generic.py

View workflow job for this annotation

GitHub Actions / test (3.12)

CasAuthTest.test_login ImportError: cannot import name 'AuthTokenError' from 'social_core.exceptions' (/home/runner/work/social-core/social-core/social_core/exceptions.py)

Check failure on line 41 in social_core/tests/backends/test_cas_generic.py

View workflow job for this annotation

GitHub Actions / test (3.12)

CasAuthTest.test_auth_url ImportError: cannot import name 'AuthTokenError' from 'social_core.exceptions' (/home/runner/work/social-core/social-core/social_core/exceptions.py)

Check failure on line 41 in social_core/tests/backends/test_cas_generic.py

View workflow job for this annotation

GitHub Actions / test (3.14)

CasAuthTest.test_partial_pipeline ImportError: cannot import name 'AuthTokenError' from 'social_core.exceptions' (/home/runner/work/social-core/social-core/social_core/exceptions.py)

Check failure on line 41 in social_core/tests/backends/test_cas_generic.py

View workflow job for this annotation

GitHub Actions / test (3.14)

CasAuthTest.test_login ImportError: cannot import name 'AuthTokenError' from 'social_core.exceptions' (/home/runner/work/social-core/social-core/social_core/exceptions.py)

Check failure on line 41 in social_core/tests/backends/test_cas_generic.py

View workflow job for this annotation

GitHub Actions / test (3.14)

CasAuthTest.test_auth_url ImportError: cannot import name 'AuthTokenError' from 'social_core.exceptions' (/home/runner/work/social-core/social-core/social_core/exceptions.py)

Check failure on line 41 in social_core/tests/backends/test_cas_generic.py

View workflow job for this annotation

GitHub Actions / test (3.10)

CasAuthTest.test_partial_pipeline ImportError: cannot import name 'AuthTokenError' from 'social_core.exceptions' (/home/runner/work/social-core/social-core/social_core/exceptions.py)

Check failure on line 41 in social_core/tests/backends/test_cas_generic.py

View workflow job for this annotation

GitHub Actions / test (3.10)

CasAuthTest.test_login ImportError: cannot import name 'AuthTokenError' from 'social_core.exceptions' (/home/runner/work/social-core/social-core/social_core/exceptions.py)

Check failure on line 41 in social_core/tests/backends/test_cas_generic.py

View workflow job for this annotation

GitHub Actions / test (3.10)

CasAuthTest.test_auth_url ImportError: cannot import name 'AuthTokenError' from 'social_core.exceptions' (/home/runner/work/social-core/social-core/social_core/exceptions.py)

Check failure on line 41 in social_core/tests/backends/test_cas_generic.py

View workflow job for this annotation

GitHub Actions / test (3.11)

CasAuthTest.test_partial_pipeline ImportError: cannot import name 'AuthTokenError' from 'social_core.exceptions' (/home/runner/work/social-core/social-core/social_core/exceptions.py)

Check failure on line 41 in social_core/tests/backends/test_cas_generic.py

View workflow job for this annotation

GitHub Actions / test (3.11)

CasAuthTest.test_login ImportError: cannot import name 'AuthTokenError' from 'social_core.exceptions' (/home/runner/work/social-core/social-core/social_core/exceptions.py)

Check failure on line 41 in social_core/tests/backends/test_cas_generic.py

View workflow job for this annotation

GitHub Actions / test (3.11)

CasAuthTest.test_auth_url ImportError: cannot import name 'AuthTokenError' from 'social_core.exceptions' (/home/runner/work/social-core/social-core/social_core/exceptions.py)

Check failure on line 41 in social_core/tests/backends/test_cas_generic.py

View workflow job for this annotation

GitHub Actions / test (3.13)

CasAuthTest.test_partial_pipeline ImportError: cannot import name 'AuthTokenError' from 'social_core.exceptions' (/home/runner/work/social-core/social-core/social_core/exceptions.py)

Check failure on line 41 in social_core/tests/backends/test_cas_generic.py

View workflow job for this annotation

GitHub Actions / test (3.13)

CasAuthTest.test_login ImportError: cannot import name 'AuthTokenError' from 'social_core.exceptions' (/home/runner/work/social-core/social-core/social_core/exceptions.py)

Check failure on line 41 in social_core/tests/backends/test_cas_generic.py

View workflow job for this annotation

GitHub Actions / test (3.13)

CasAuthTest.test_auth_url ImportError: cannot import name 'AuthTokenError' from 'social_core.exceptions' (/home/runner/work/social-core/social-core/social_core/exceptions.py)
params = [("ticket", self.ticket), ("service", self.service_url)]

self.strategy.set_settings(
{
"SOCIAL_AUTH_CAS_SERVER_URL": self.server_url,
}
)

url = (
urllib.parse.urljoin(self.server_url, self.validate_endpoint)
+ "?"
+ urllib.parse.urlencode(params)
)
responses.add(responses.GET, url, VALIDATION_PAYLOAD)

def do_start(self):
self.strategy.set_request_data({"ticket": self.ticket}, self.backend)
return self.backend.complete()

def test_login(self) -> None:
self.do_login()

def test_partial_pipeline(self) -> None:
self.do_partial_pipeline()

def test_auth_url(self) -> None:
self.assertEqual(
self.backend.auth_url(),
urllib.parse.urljoin(self.server_url, "login")
+ "?"
+ urllib.parse.urlencode({"service": self.service_url}),
)
Loading