aboutsummaryrefslogtreecommitdiff
path: root/jb/views/auth.py
diff options
context:
space:
mode:
Diffstat (limited to 'jb/views/auth.py')
-rw-r--r--jb/views/auth.py102
1 files changed, 94 insertions, 8 deletions
diff --git a/jb/views/auth.py b/jb/views/auth.py
index cc1224f..ba1a6f8 100644
--- a/jb/views/auth.py
+++ b/jb/views/auth.py
@@ -2,7 +2,16 @@ import secrets
from typing import Annotated
from urllib.parse import urlencode
-from fastapi import APIRouter, Depends, Header, HTTPException, Response, status
+from fastapi import (
+ APIRouter,
+ BackgroundTasks,
+ Depends,
+ Header,
+ HTTPException,
+ Request,
+ Response,
+ status,
+)
from fastapi.responses import HTMLResponse, RedirectResponse
from jb.api.auth import (
@@ -26,6 +35,7 @@ from jb.managers.email_manager import (
send_login_email,
)
from jb.managers.gr_api import GRApiManager
+from jb.managers.thl import create_paypal_cashout_method_if_not_exists
from jb.models.auth import (
AccountLogin,
AmtAccountLink,
@@ -33,10 +43,24 @@ from jb.models.auth import (
User,
)
from jb.settings import render_base_html
+from jb.views.utils import get_client_ip
auth_router = APIRouter(prefix="/auth", tags=["Auth"])
+def try_create_paypal_cashout_method_if_not_exists(
+ product_user_id: str, email: str, client_ip: str
+) -> None:
+ try:
+ create_paypal_cashout_method_if_not_exists(
+ product_user_id=product_user_id,
+ email=email,
+ client_ip=client_ip,
+ )
+ except Exception:
+ LOG.exception("Failed to create PayPal cashout method for %s", product_user_id)
+
+
def authenticate_invite_amt_account_link(
authorization: Annotated[str | None, Header()] = None,
) -> None:
@@ -76,6 +100,8 @@ def request_magic_link(body: AccountLogin) -> dict[str, str]:
@auth_router.get("/magic-link/", response_class=HTMLResponse, include_in_schema=False)
def magic_link_landing_page(
+ request: Request,
+ background_tasks: BackgroundTasks,
gr_api: Annotated[GRApiManager, Depends(get_gr_api_manager)],
token: str | None = None,
) -> Response:
@@ -87,7 +113,14 @@ def magic_link_landing_page(
detail="token is required",
)
response = RedirectResponse(url="/", status_code=status.HTTP_303_SEE_OTHER)
- _exchange_magic_link(token, response, gr_api)
+ client_ip = get_client_ip(request)
+ _exchange_magic_link(
+ token,
+ response,
+ gr_api,
+ client_ip=client_ip,
+ background_tasks=background_tasks,
+ )
return response
return HTMLResponse(
render_base_html(),
@@ -101,17 +134,41 @@ def magic_link_landing_page(
@auth_router.post("/magic-link/exchange/", status_code=status.HTTP_204_NO_CONTENT)
def exchange_magic_link(
+ request: Request,
+ background_tasks: BackgroundTasks,
body: MagicLinkExchangeRequest,
response: Response,
gr_api: Annotated[GRApiManager, Depends(get_gr_api_manager)],
) -> None:
"""Exchange a magic link only after its landing page makes an explicit POST."""
- _exchange_magic_link(body.token, response, gr_api)
+ client_ip = get_client_ip(request)
+ _exchange_magic_link(
+ body.token,
+ response,
+ gr_api,
+ client_ip=client_ip,
+ background_tasks=background_tasks,
+ )
-def _exchange_magic_link(token: str, response: Response, gr_api: GRApiManager) -> None:
+def _exchange_magic_link(
+ token: str,
+ response: Response,
+ gr_api: GRApiManager,
+ client_ip: str,
+ background_tasks: BackgroundTasks,
+) -> None:
user_email = consume_magic_token(token)
user = gr_api.ensure_user_exists(User.model_validate({"email": user_email}))
+
+ # Cashout setup is not required for login and should not delay the response.
+ background_tasks.add_task(
+ try_create_paypal_cashout_method_if_not_exists,
+ product_user_id=user.product_user_id,
+ email=str(user.email),
+ client_ip=client_ip,
+ )
+
response.set_cookie(
key=SESSION_COOKIE_NAME,
value=create_session(user.product_user_id),
@@ -161,6 +218,8 @@ def invite_amt_account_link(
@auth_router.get("/debug/", response_class=HTMLResponse, include_in_schema=False)
def link_amt_account_landing_page(
+ request: Request,
+ background_tasks: BackgroundTasks,
gr_api: Annotated[GRApiManager, Depends(get_gr_api_manager)],
token: str | None = None,
) -> HTMLResponse:
@@ -175,9 +234,15 @@ def link_amt_account_landing_page(
status_code=status.HTTP_400_BAD_REQUEST,
detail="token is required",
)
-
+ client_ip = get_client_ip(request)
_response = RedirectResponse(url="/", status_code=status.HTTP_303_SEE_OTHER)
- _exchange_amt_account_link(token=token, response=_response, gr_api=gr_api)
+ _exchange_amt_account_link(
+ token=token,
+ response=_response,
+ gr_api=gr_api,
+ client_ip=client_ip,
+ background_tasks=background_tasks,
+ )
return HTMLResponse(
render_base_html(),
@@ -191,25 +256,46 @@ def link_amt_account_landing_page(
@auth_router.post("/link-amt/exchange/", status_code=status.HTTP_204_NO_CONTENT)
def exchange_amt_account_link(
+ request: Request,
+ background_tasks: BackgroundTasks,
body: MagicLinkExchangeRequest,
response: Response,
gr_api: Annotated[GRApiManager, Depends(get_gr_api_manager)],
) -> None:
"""Validate the email link, then transition the bound AMT account."""
+ client_ip = get_client_ip(request)
try:
- _exchange_amt_account_link(body.token, response, gr_api)
+ _exchange_amt_account_link(
+ body.token,
+ response,
+ gr_api,
+ client_ip=client_ip,
+ background_tasks=background_tasks,
+ )
except ValueError as e:
LOG.error(f"Failed to exchange AMT account link: {e}")
raise HTTPException(status_code=status.HTTP_400_BAD_REQUEST, detail=str(e))
-def _exchange_amt_account_link(token: str, response: Response, gr_api: GRApiManager):
+def _exchange_amt_account_link(
+ token: str,
+ response: Response,
+ gr_api: GRApiManager,
+ client_ip: str,
+ background_tasks: BackgroundTasks,
+):
token_data = consume_amt_account_link_token(token)
email = token_data.email
amt_worker_id = token_data.amt_worker_id
user = User(email=email)
user = gr_api.transition_user_from_amt(user=user, amt_worker_id=amt_worker_id)
+ background_tasks.add_task(
+ try_create_paypal_cashout_method_if_not_exists,
+ product_user_id=user.product_user_id,
+ email=str(user.email),
+ client_ip=client_ip,
+ )
# In Mautic, associate the email with the worker ID (AFTER the user has transitioned)
get_or_create_contact(email=email, amt_worker_id=amt_worker_id)