aboutsummaryrefslogtreecommitdiff
path: root/jb/views/auth.py
diff options
context:
space:
mode:
Diffstat (limited to 'jb/views/auth.py')
-rw-r--r--jb/views/auth.py44
1 files changed, 28 insertions, 16 deletions
diff --git a/jb/views/auth.py b/jb/views/auth.py
index 36b013f..aa3cf03 100644
--- a/jb/views/auth.py
+++ b/jb/views/auth.py
@@ -2,7 +2,7 @@ import secrets
from typing import Annotated
from urllib.parse import urlencode
-from fastapi import APIRouter, Depends, Header, HTTPException, Response, status
+from fastapi import APIRouter, Depends, Header, HTTPException, Request, Response, status
from fastapi.responses import HTMLResponse, RedirectResponse
from jb.api.auth import (
@@ -26,10 +26,7 @@ from jb.managers.email_manager import (
send_login_email,
)
from jb.managers.gr_api import GRApiManager
-from jb.managers.thl import (
- create_paypal_cashout_method_if_not_exists,
- create_paypal_cashout_method,
-)
+from jb.managers.thl import create_paypal_cashout_method_if_not_exists
from jb.models.auth import (
AccountLogin,
AmtAccountLink,
@@ -37,6 +34,7 @@ from jb.models.auth import (
User,
)
from jb.settings import render_base_html
+from jb.views.utils import get_client_ip
auth_router = APIRouter(prefix="/auth", tags=["Auth"])
@@ -80,6 +78,7 @@ def request_magic_link(body: AccountLogin) -> dict[str, str]:
@auth_router.get("/magic-link/", response_class=HTMLResponse, include_in_schema=False)
def magic_link_landing_page(
+ request: Request,
gr_api: Annotated[GRApiManager, Depends(get_gr_api_manager)],
token: str | None = None,
) -> Response:
@@ -91,7 +90,8 @@ def magic_link_landing_page(
detail="token is required",
)
response = RedirectResponse(url="/", status_code=status.HTTP_303_SEE_OTHER)
- _exchange_magic_link(token, response, gr_api)
+ client_ip = get_client_ip(request)
+ _exchange_magic_link(token, response, gr_api, client_ip=client_ip)
return response
return HTMLResponse(
render_base_html(),
@@ -105,23 +105,27 @@ def magic_link_landing_page(
@auth_router.post("/magic-link/exchange/", status_code=status.HTTP_204_NO_CONTENT)
def exchange_magic_link(
+ request: Request,
body: MagicLinkExchangeRequest,
response: Response,
gr_api: Annotated[GRApiManager, Depends(get_gr_api_manager)],
) -> None:
"""Exchange a magic link only after its landing page makes an explicit POST."""
- _exchange_magic_link(body.token, response, gr_api)
+ client_ip = get_client_ip(request)
+ _exchange_magic_link(body.token, response, gr_api, client_ip=client_ip)
-def _exchange_magic_link(token: str, response: Response, gr_api: GRApiManager) -> None:
+def _exchange_magic_link(
+ token: str, response: Response, gr_api: GRApiManager, client_ip: str
+) -> None:
user_email = consume_magic_token(token)
user = gr_api.ensure_user_exists(User.model_validate({"email": user_email}))
# create_paypal_cashout_method_if_not_exists(
# product_user_id=user.product_user_id, email=user.email
# )
- create_paypal_cashout_method(
- product_user_id=user.product_user_id, email=user.email
+ create_paypal_cashout_method_if_not_exists(
+ product_user_id=user.product_user_id, email=user.email, client_ip=client_ip
)
response.set_cookie(
@@ -173,6 +177,7 @@ def invite_amt_account_link(
@auth_router.get("/debug/", response_class=HTMLResponse, include_in_schema=False)
def link_amt_account_landing_page(
+ request: Request,
gr_api: Annotated[GRApiManager, Depends(get_gr_api_manager)],
token: str | None = None,
) -> HTMLResponse:
@@ -187,9 +192,11 @@ def link_amt_account_landing_page(
status_code=status.HTTP_400_BAD_REQUEST,
detail="token is required",
)
-
+ client_ip = get_client_ip(request)
_response = RedirectResponse(url="/", status_code=status.HTTP_303_SEE_OTHER)
- _exchange_amt_account_link(token=token, response=_response, gr_api=gr_api)
+ _exchange_amt_account_link(
+ token=token, response=_response, gr_api=gr_api, client_ip=client_ip
+ )
return HTMLResponse(
render_base_html(),
@@ -203,27 +210,32 @@ def link_amt_account_landing_page(
@auth_router.post("/link-amt/exchange/", status_code=status.HTTP_204_NO_CONTENT)
def exchange_amt_account_link(
+ request: Request,
body: MagicLinkExchangeRequest,
response: Response,
gr_api: Annotated[GRApiManager, Depends(get_gr_api_manager)],
) -> None:
"""Validate the email link, then transition the bound AMT account."""
+ client_ip = get_client_ip(request)
try:
- _exchange_amt_account_link(body.token, response, gr_api)
+ _exchange_amt_account_link(body.token, response, gr_api, client_ip=client_ip)
except ValueError as e:
LOG.error(f"Failed to exchange AMT account link: {e}")
raise HTTPException(status_code=status.HTTP_400_BAD_REQUEST, detail=str(e))
-def _exchange_amt_account_link(token: str, response: Response, gr_api: GRApiManager):
+def _exchange_amt_account_link(
+ token: str, response: Response, gr_api: GRApiManager, client_ip: str
+):
token_data = consume_amt_account_link_token(token)
email = token_data.email
amt_worker_id = token_data.amt_worker_id
user = User(email=email)
user = gr_api.transition_user_from_amt(user=user, amt_worker_id=amt_worker_id)
- # create_paypal_cashout_method_if_not_exists(product_user_id=user.product_user_id, email=user.email)
- create_paypal_cashout_method(product_user_id=user.product_user_id, email=user.email)
+ create_paypal_cashout_method_if_not_exists(
+ product_user_id=user.product_user_id, email=user.email, client_ip=client_ip
+ )
# In Mautic, associate the email with the worker ID (AFTER the user has transitioned)
get_or_create_contact(email=email, amt_worker_id=amt_worker_id)