diff options
| author | stuppie | 2026-09-23 13:42:03 -0600 |
|---|---|---|
| committer | stuppie | 2026-09-23 13:42:03 -0600 |
| commit | 064a55c754e02da54b13c47028b233b265327518 (patch) | |
| tree | e8e2eef6a138c750640dab6b2239c3d8a6eb4191 /jb/views/auth.py | |
| parent | b1af1375578e41a240a4eedff73209e212a31051 (diff) | |
| download | amt-jb-064a55c754e02da54b13c47028b233b265327518.tar.gz amt-jb-064a55c754e02da54b13c47028b233b265327518.zip | |
upon login: create_paypal_cashout_method_if_not_exists using user's ip. Upon cashout request: send_cashout_confirmation_email using cashout method info looked up
Diffstat (limited to 'jb/views/auth.py')
| -rw-r--r-- | jb/views/auth.py | 44 |
1 files changed, 28 insertions, 16 deletions
diff --git a/jb/views/auth.py b/jb/views/auth.py index 36b013f..aa3cf03 100644 --- a/jb/views/auth.py +++ b/jb/views/auth.py @@ -2,7 +2,7 @@ import secrets from typing import Annotated from urllib.parse import urlencode -from fastapi import APIRouter, Depends, Header, HTTPException, Response, status +from fastapi import APIRouter, Depends, Header, HTTPException, Request, Response, status from fastapi.responses import HTMLResponse, RedirectResponse from jb.api.auth import ( @@ -26,10 +26,7 @@ from jb.managers.email_manager import ( send_login_email, ) from jb.managers.gr_api import GRApiManager -from jb.managers.thl import ( - create_paypal_cashout_method_if_not_exists, - create_paypal_cashout_method, -) +from jb.managers.thl import create_paypal_cashout_method_if_not_exists from jb.models.auth import ( AccountLogin, AmtAccountLink, @@ -37,6 +34,7 @@ from jb.models.auth import ( User, ) from jb.settings import render_base_html +from jb.views.utils import get_client_ip auth_router = APIRouter(prefix="/auth", tags=["Auth"]) @@ -80,6 +78,7 @@ def request_magic_link(body: AccountLogin) -> dict[str, str]: @auth_router.get("/magic-link/", response_class=HTMLResponse, include_in_schema=False) def magic_link_landing_page( + request: Request, gr_api: Annotated[GRApiManager, Depends(get_gr_api_manager)], token: str | None = None, ) -> Response: @@ -91,7 +90,8 @@ def magic_link_landing_page( detail="token is required", ) response = RedirectResponse(url="/", status_code=status.HTTP_303_SEE_OTHER) - _exchange_magic_link(token, response, gr_api) + client_ip = get_client_ip(request) + _exchange_magic_link(token, response, gr_api, client_ip=client_ip) return response return HTMLResponse( render_base_html(), @@ -105,23 +105,27 @@ def magic_link_landing_page( @auth_router.post("/magic-link/exchange/", status_code=status.HTTP_204_NO_CONTENT) def exchange_magic_link( + request: Request, body: MagicLinkExchangeRequest, response: Response, gr_api: Annotated[GRApiManager, Depends(get_gr_api_manager)], ) -> None: """Exchange a magic link only after its landing page makes an explicit POST.""" - _exchange_magic_link(body.token, response, gr_api) + client_ip = get_client_ip(request) + _exchange_magic_link(body.token, response, gr_api, client_ip=client_ip) -def _exchange_magic_link(token: str, response: Response, gr_api: GRApiManager) -> None: +def _exchange_magic_link( + token: str, response: Response, gr_api: GRApiManager, client_ip: str +) -> None: user_email = consume_magic_token(token) user = gr_api.ensure_user_exists(User.model_validate({"email": user_email})) # create_paypal_cashout_method_if_not_exists( # product_user_id=user.product_user_id, email=user.email # ) - create_paypal_cashout_method( - product_user_id=user.product_user_id, email=user.email + create_paypal_cashout_method_if_not_exists( + product_user_id=user.product_user_id, email=user.email, client_ip=client_ip ) response.set_cookie( @@ -173,6 +177,7 @@ def invite_amt_account_link( @auth_router.get("/debug/", response_class=HTMLResponse, include_in_schema=False) def link_amt_account_landing_page( + request: Request, gr_api: Annotated[GRApiManager, Depends(get_gr_api_manager)], token: str | None = None, ) -> HTMLResponse: @@ -187,9 +192,11 @@ def link_amt_account_landing_page( status_code=status.HTTP_400_BAD_REQUEST, detail="token is required", ) - + client_ip = get_client_ip(request) _response = RedirectResponse(url="/", status_code=status.HTTP_303_SEE_OTHER) - _exchange_amt_account_link(token=token, response=_response, gr_api=gr_api) + _exchange_amt_account_link( + token=token, response=_response, gr_api=gr_api, client_ip=client_ip + ) return HTMLResponse( render_base_html(), @@ -203,27 +210,32 @@ def link_amt_account_landing_page( @auth_router.post("/link-amt/exchange/", status_code=status.HTTP_204_NO_CONTENT) def exchange_amt_account_link( + request: Request, body: MagicLinkExchangeRequest, response: Response, gr_api: Annotated[GRApiManager, Depends(get_gr_api_manager)], ) -> None: """Validate the email link, then transition the bound AMT account.""" + client_ip = get_client_ip(request) try: - _exchange_amt_account_link(body.token, response, gr_api) + _exchange_amt_account_link(body.token, response, gr_api, client_ip=client_ip) except ValueError as e: LOG.error(f"Failed to exchange AMT account link: {e}") raise HTTPException(status_code=status.HTTP_400_BAD_REQUEST, detail=str(e)) -def _exchange_amt_account_link(token: str, response: Response, gr_api: GRApiManager): +def _exchange_amt_account_link( + token: str, response: Response, gr_api: GRApiManager, client_ip: str +): token_data = consume_amt_account_link_token(token) email = token_data.email amt_worker_id = token_data.amt_worker_id user = User(email=email) user = gr_api.transition_user_from_amt(user=user, amt_worker_id=amt_worker_id) - # create_paypal_cashout_method_if_not_exists(product_user_id=user.product_user_id, email=user.email) - create_paypal_cashout_method(product_user_id=user.product_user_id, email=user.email) + create_paypal_cashout_method_if_not_exists( + product_user_id=user.product_user_id, email=user.email, client_ip=client_ip + ) # In Mautic, associate the email with the worker ID (AFTER the user has transitioned) get_or_create_contact(email=email, amt_worker_id=amt_worker_id) |
