admin.py 5.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143
  1. import os
  2. from functools import wraps
  3. from flask import request
  4. from flask_restful import Resource, reqparse
  5. from werkzeug.exceptions import NotFound, Unauthorized
  6. from constants.languages import supported_language
  7. from controllers.console import api
  8. from controllers.console.wraps import only_edition_cloud
  9. from extensions.ext_database import db
  10. from models.model import App, InstalledApp, RecommendedApp
  11. def admin_required(view):
  12. @wraps(view)
  13. def decorated(*args, **kwargs):
  14. if not os.getenv("ADMIN_API_KEY"):
  15. raise Unauthorized("API key is invalid.")
  16. auth_header = request.headers.get("Authorization")
  17. if auth_header is None:
  18. raise Unauthorized("Authorization header is missing.")
  19. if " " not in auth_header:
  20. raise Unauthorized("Invalid Authorization header format. Expected 'Bearer <api-key>' format.")
  21. auth_scheme, auth_token = auth_header.split(None, 1)
  22. auth_scheme = auth_scheme.lower()
  23. if auth_scheme != "bearer":
  24. raise Unauthorized("Invalid Authorization header format. Expected 'Bearer <api-key>' format.")
  25. if os.getenv("ADMIN_API_KEY") != auth_token:
  26. raise Unauthorized("API key is invalid.")
  27. return view(*args, **kwargs)
  28. return decorated
  29. class InsertExploreAppListApi(Resource):
  30. @only_edition_cloud
  31. @admin_required
  32. def post(self):
  33. parser = reqparse.RequestParser()
  34. parser.add_argument("app_id", type=str, required=True, nullable=False, location="json")
  35. parser.add_argument("desc", type=str, location="json")
  36. parser.add_argument("copyright", type=str, location="json")
  37. parser.add_argument("privacy_policy", type=str, location="json")
  38. parser.add_argument("custom_disclaimer", type=str, location="json")
  39. parser.add_argument("language", type=supported_language, required=True, nullable=False, location="json")
  40. parser.add_argument("category", type=str, required=True, nullable=False, location="json")
  41. parser.add_argument("position", type=int, required=True, nullable=False, location="json")
  42. args = parser.parse_args()
  43. app = App.query.filter(App.id == args["app_id"]).first()
  44. if not app:
  45. raise NotFound(f'App \'{args["app_id"]}\' is not found')
  46. site = app.site
  47. if not site:
  48. desc = args["desc"] if args["desc"] else ""
  49. copy_right = args["copyright"] if args["copyright"] else ""
  50. privacy_policy = args["privacy_policy"] if args["privacy_policy"] else ""
  51. custom_disclaimer = args["custom_disclaimer"] if args["custom_disclaimer"] else ""
  52. else:
  53. desc = site.description if site.description else args["desc"] if args["desc"] else ""
  54. copy_right = site.copyright if site.copyright else args["copyright"] if args["copyright"] else ""
  55. privacy_policy = (
  56. site.privacy_policy if site.privacy_policy else args["privacy_policy"] if args["privacy_policy"] else ""
  57. )
  58. custom_disclaimer = (
  59. site.custom_disclaimer
  60. if site.custom_disclaimer
  61. else args["custom_disclaimer"]
  62. if args["custom_disclaimer"]
  63. else ""
  64. )
  65. recommended_app = RecommendedApp.query.filter(RecommendedApp.app_id == args["app_id"]).first()
  66. if not recommended_app:
  67. recommended_app = RecommendedApp(
  68. app_id=app.id,
  69. description=desc,
  70. copyright=copy_right,
  71. privacy_policy=privacy_policy,
  72. custom_disclaimer=custom_disclaimer,
  73. language=args["language"],
  74. category=args["category"],
  75. position=args["position"],
  76. )
  77. db.session.add(recommended_app)
  78. app.is_public = True
  79. db.session.commit()
  80. return {"result": "success"}, 201
  81. else:
  82. recommended_app.description = desc
  83. recommended_app.copyright = copy_right
  84. recommended_app.privacy_policy = privacy_policy
  85. recommended_app.custom_disclaimer = custom_disclaimer
  86. recommended_app.language = args["language"]
  87. recommended_app.category = args["category"]
  88. recommended_app.position = args["position"]
  89. app.is_public = True
  90. db.session.commit()
  91. return {"result": "success"}, 200
  92. class InsertExploreAppApi(Resource):
  93. @only_edition_cloud
  94. @admin_required
  95. def delete(self, app_id):
  96. recommended_app = RecommendedApp.query.filter(RecommendedApp.app_id == str(app_id)).first()
  97. if not recommended_app:
  98. return {"result": "success"}, 204
  99. app = App.query.filter(App.id == recommended_app.app_id).first()
  100. if app:
  101. app.is_public = False
  102. installed_apps = InstalledApp.query.filter(
  103. InstalledApp.app_id == recommended_app.app_id, InstalledApp.tenant_id != InstalledApp.app_owner_tenant_id
  104. ).all()
  105. for installed_app in installed_apps:
  106. db.session.delete(installed_app)
  107. db.session.delete(recommended_app)
  108. db.session.commit()
  109. return {"result": "success"}, 204
  110. api.add_resource(InsertExploreAppListApi, "/admin/insert-explore-apps")
  111. api.add_resource(InsertExploreAppApi, "/admin/insert-explore-apps/<uuid:app_id>")