* feat: session authentication and god-mode implementation (#4302) * dev: move authentication to base class for credentials * chore: new account creation * dev: return error as query parameter * dev: accounts and profile endpoints for user * fix: user store updates * fix: store fixes * fix: type fixes * dev: set is_password_autoset and is_email_verifier for auth providers * dev: move all auth configuration to different apps * dev: fix circular imports * dev: remove unused imports * dev: fix imports for authentication * dev: update endpoints to use rest framework api viewa * fix: onboarding fixes * dev: session model changes * fix: session model and add check for last name first name and avatar * dev: fix referer redirect * dev: remove auth imports * dev: fix imports * dev: update migrations * fix: instance admin login * comflict: conflicts resolved * dev: fix import errors and email check endpoint * fix: error messages and redirects after login * dev: configs api * fix: is github enabled boolean * dev: merge config and instance api * conflict: merge conflict resolved * dev: instance admin sign up endpoint * dev: enable magic link login * dev: configure instance variables for github and google enabled * chore: typo fixes * fix: god mode docker file changes * build-error: resolved build errors * fix: docker compose changes * dev: add email credential check endpoint * fix: minor package changes * fix: docker related changes * dev: add nginx rules in the nginx template * dev: refactor the url patterns * fix: docker changes * fix: docker files for god-mode * fix: static export * fix: nginx conf * dev: smtp sender refused exception * fix: godmode fixes * chore: god mode revamp. * dev: add csrf secured flag * fix: oauth redirect uri and session settings * chore: god mode app changes. (#3982) * chore: send test email functionality. * style: authentication methods page UI revamp. * chore: create workspace popup. * fix: user me endpoint * dev: fix redirection after authentication * dev: handle god mode redirection * fix: redirections * fix: auth related hooks * fix: store related fixes * dev: fix session authentication for rest apis * fix: linting errors * fix: removing references of useStore= * dev: fix redirection and password validation * dev: add useUser hook * fix: build fixes and lint issues * fix: removing useApplication hook * fix: build errors * fix: delete unused files * fix: auth build fixes * fix: bugfixes * dev: alter avatar to support more than 255 chars * dev: fix profile endpoint and increase session expiry time and update session on every request * chore: resolved the migration * chore: resolved merge conflicts * dev: error codes and error messages for the auth flow * dev: instance admin sign up and sign in endpoint * dev: use zxcvbn to validate password strength * dev: add extra parameters when error handling on instance god mode * chore: auth init * chore: signin/ signup form ui updates and password strength meter. * chore: update password fields. * chore: validations and error handling. * chore: updated sign-up form * chore: updated workflow and updated the code structure * chore: instance empty state for god-mode. * chore: instance and auth wrappers update * fix: renaming godmode * fix: docker changes * chore: updated authentication wrappers * chore: updated the authentication workflow and rendered all pages * fix: build errors * fix: docker related fixes * fix: tailing slash added to space and admin for valid nginx locations * chore: seperate pages for signup and login * git-action modified for admin file changes * feature build action updated for admin app * self host modified * chore: resolved build errors and handled signin and signup in a seperate route * chore: sign-in and sign-up revamp. * fix: migration conflicts * dev: migrations * chore: handled redirection * dev: admin url * dev: create seperate endpoint for instance admin me * dev: instance admin endpoint * git action fixed * chore: handled auth wrappers * dev: add serializer and remove print logs * fix: build errors * dev: fix migrations * dev: instance folder structuring * fix: linting errors * chore: resolved build errors * chore: updated store and auth workflow and updates api service types * chore: Replaced Next Link with Anchoer tag for god-mode redirection * add 3333 port to allowed origins * make password login working again * dev: fix redirection, add admin signout endpoint and fix email credential check endpoint * fix unique code sign in * fix small build error * enable sign out * dev: add google client secret variable to configure instance * dev: add referer for redirection * fix origin urls for oauths * admin setup and login separation * dev: fix user redirection and tour completed endpoint * fix build errors * dev: add set password endpoint * dev: remove user creation logic for redirection * fix unique code page * fix forgot password * chore: onboarding revamp. * dev: fix workspace slug redirection in login * chore: invited user onboarding flow update. * chore: fix switch or delete account modal. * fix members exception * refactor auth flows and add invitations to auth flow * fix sig in sign up url * fix action url * fix build errors * dev: fix user set password when logging in * dev: reset password endpoint * chore: confirm password validation for signup and onboarding. * enable reset password * fix build error * chore: minor UI updates. * chore: forgot and reset password UI revamp. * fix authentication re directions * dev: auth redirections * change url paths for signup and signin * dev: make the user logged in when changing passwords * dev: next path redirection for web and space app * dev: next path for magic sign in endpoint * dev: github space endpoint * chore: minor ui updates and fixes in web app. * set password screen * fix multiple unique code generation * dev: next path base redirection * dev: remove print logs * dev: auth space endpoints * fix build errors * dev: invalidate cache on configuration update, god mode exception errors and authentication failed code * dev: fix space endpoints and add extra endpoints * chore: space auth revamp. * dev: add sign up for space app * fix: build errors. * fix: auth redirection logic. * chore: space app onboarding revamp. --------- Co-authored-by: pablohashescobar <nikhilschacko@gmail.com> Co-authored-by: NarayanBavisetti <narayan3119@gmail.com> Co-authored-by: gurusainath <gurusainath007@gmail.com> Co-authored-by: Prateek Shourya <prateekshourya29@gmail.com> Co-authored-by: Manish Gupta <59428681+mguptahub@users.noreply.github.com> Co-authored-by: Manish Gupta <manish@mgupta.me> Co-authored-by: = <=> Co-authored-by: rahulramesha <rahulramesham@gmail.com> * chore: updated file structure for admin * chore: updated admin-sidebar * chore: auth error handling * chore: onboarding UI updates and dark mode fixes. * chore: add `user personalization` step to onboarding profile setup screen. * chore: fix minor UI bugs * chore: authentication workflow changes * chore: handled signin workflow * style: switch or delete account workflow * chore: god mode redirection URL * feat(dashboard): improve label readability (#4321) change none label for all time in dashbard filters * chore: god-mode redirection * chore: onboarding ui updates and accept invitation workflow updates. * chore: rename unique code auth form. * style: space auth ux copy. * chore: updated intance and auth wrapper logic * chore: update default layout style. * chore: update confirm password. * chore: backend redirection * style: update banner ui * chore: minor ui updates and validation fix. * chore: removed old auth hook * chore: handled auth wrapper * chore: handled store loaders in the user * chore: handled logs * chore: add loading spinners for all auth and onboarding form buttons. * chore: add background pattern in admin auth forms and minor ui fixes. * chore: UI changes and revamp components for authentication * chore: auth UI consistency in web, space and admin. * chore: resolved build errors * chore: removed old auth hooks * chore: handled lint errors in use accounts * chore: updated authentication wrapper logic in web app * [WEB -1149] dev: update dependencies (#4333) * dev: upgrade dependencies remove unwanted dependency and add ruff as local dependency * dev: add comments * chore: authentication wrapper fetch user * chore: updated store loader * chore: removed old auth wrapper and replaced the imports with new auth wrapper * chore: join workspace invitation workflow updates * chore: build error resolved in deploy * chore: handled onboarding step error in web app * chore: SMTP Name and Password validation removed * chore: handled seo and signout logic and new user popup * chore: added redirection to plane in the sidebar * chore: resolved build errors * dev: admin session cookie update * chore: updated cookie session time for admin * dev: add start date and end date to projects (#4355) * chore: add email security dropdown and remove SMTP username and password validation. * chore: add tooltip to admin sidebar help-section. * chore: add dropdown to collapsed admin sidebar. * chore: profile themning * chore: updated page error messages and theme in command palette * dev: add email validation in email check apis * dev: remove start date and end date from project * chore: updated space folder structure and updated the store hooks * dev: error codes for authentication * chore: handled authentication in space and web apps * chore: banner redirect handling the email * dev: god mode error codes * chore: updated error codes * chore: updated onboarding images * dev: signout endpoints and saving login domain while creating sessions * feat: Self Host Data Backup (#4383) * feat: implemented backup , support for docker-compose tool, readme updated * minor fix in shell script * codacy fixes * chore: handled build errors in web * chore: updated react, react-dom, and next versions * chore: updated password autioset in the signin * dev: add logo prop to views and pages * chore: updated api service and handled the set password in store * chore: handled build errors and code cleanup * dev: return 401 when the session is not valid * dev: users/me exception for api * chore: installed lodash in space app * dev: add auth route in nginx --------- Co-authored-by: pablohashescobar <nikhilschacko@gmail.com> Co-authored-by: NarayanBavisetti <narayan3119@gmail.com> Co-authored-by: gurusainath <gurusainath007@gmail.com> Co-authored-by: Prateek Shourya <prateekshourya29@gmail.com> Co-authored-by: Manish Gupta <59428681+mguptahub@users.noreply.github.com> Co-authored-by: Manish Gupta <manish@mgupta.me> Co-authored-by: rahulramesha <rahulramesham@gmail.com> Co-authored-by: Aaryan Khandelwal <aaryankhandu123@gmail.com> Co-authored-by: Daniel Alba <56451942+redrum15@users.noreply.github.com> Co-authored-by: Nikhil <118773738+pablohashescobar@users.noreply.github.com>
344 lines
9.6 KiB
Python
344 lines
9.6 KiB
Python
"""Global Settings"""
|
|
|
|
# Python imports
|
|
import os
|
|
import ssl
|
|
from urllib.parse import urlparse
|
|
|
|
import certifi
|
|
|
|
# Third party imports
|
|
import dj_database_url
|
|
import sentry_sdk
|
|
|
|
# Django imports
|
|
from django.core.management.utils import get_random_secret_key
|
|
from sentry_sdk.integrations.celery import CeleryIntegration
|
|
from sentry_sdk.integrations.django import DjangoIntegration
|
|
from sentry_sdk.integrations.redis import RedisIntegration
|
|
|
|
BASE_DIR = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
|
|
|
|
# Secret Key
|
|
SECRET_KEY = os.environ.get("SECRET_KEY", get_random_secret_key())
|
|
|
|
# SECURITY WARNING: don't run with debug turned on in production!
|
|
DEBUG = int(os.environ.get("DEBUG", "0"))
|
|
|
|
# Allowed Hosts
|
|
ALLOWED_HOSTS = ["*"]
|
|
|
|
# Application definition
|
|
INSTALLED_APPS = [
|
|
"django.contrib.auth",
|
|
"django.contrib.contenttypes",
|
|
"django.contrib.sessions",
|
|
# Inhouse apps
|
|
"plane.analytics",
|
|
"plane.app",
|
|
"plane.space",
|
|
"plane.bgtasks",
|
|
"plane.db",
|
|
"plane.utils",
|
|
"plane.web",
|
|
"plane.middleware",
|
|
"plane.license",
|
|
"plane.api",
|
|
"plane.authentication",
|
|
# Third-party things
|
|
"rest_framework",
|
|
"corsheaders",
|
|
"django_celery_beat",
|
|
"storages",
|
|
]
|
|
|
|
# Middlewares
|
|
MIDDLEWARE = [
|
|
"corsheaders.middleware.CorsMiddleware",
|
|
"django.middleware.security.SecurityMiddleware",
|
|
"plane.authentication.middleware.session.SessionMiddleware",
|
|
"django.middleware.common.CommonMiddleware",
|
|
"django.middleware.csrf.CsrfViewMiddleware",
|
|
"django.contrib.auth.middleware.AuthenticationMiddleware",
|
|
"django.middleware.clickjacking.XFrameOptionsMiddleware",
|
|
"crum.CurrentRequestUserMiddleware",
|
|
"django.middleware.gzip.GZipMiddleware",
|
|
"plane.middleware.api_log_middleware.APITokenLogMiddleware",
|
|
]
|
|
|
|
# Rest Framework settings
|
|
REST_FRAMEWORK = {
|
|
"DEFAULT_AUTHENTICATION_CLASSES": (
|
|
"rest_framework.authentication.SessionAuthentication",
|
|
),
|
|
"DEFAULT_PERMISSION_CLASSES": (
|
|
"rest_framework.permissions.IsAuthenticated",
|
|
),
|
|
"DEFAULT_RENDERER_CLASSES": ("rest_framework.renderers.JSONRenderer",),
|
|
"DEFAULT_FILTER_BACKENDS": (
|
|
"django_filters.rest_framework.DjangoFilterBackend",
|
|
),
|
|
"EXCEPTION_HANDLER": "plane.authentication.adapter.exception.auth_exception_handler",
|
|
}
|
|
|
|
# Django Auth Backend
|
|
AUTHENTICATION_BACKENDS = (
|
|
"django.contrib.auth.backends.ModelBackend",
|
|
) # default
|
|
|
|
# Root Urls
|
|
ROOT_URLCONF = "plane.urls"
|
|
|
|
# Templates
|
|
TEMPLATES = [
|
|
{
|
|
"BACKEND": "django.template.backends.django.DjangoTemplates",
|
|
"DIRS": [
|
|
"templates",
|
|
],
|
|
"APP_DIRS": True,
|
|
"OPTIONS": {
|
|
"context_processors": [
|
|
"django.template.context_processors.debug",
|
|
"django.template.context_processors.request",
|
|
"django.contrib.auth.context_processors.auth",
|
|
"django.contrib.messages.context_processors.messages",
|
|
],
|
|
},
|
|
},
|
|
]
|
|
|
|
|
|
# CORS Settings
|
|
CORS_ALLOW_CREDENTIALS = True
|
|
cors_origins_raw = os.environ.get("CORS_ALLOWED_ORIGINS", "")
|
|
# filter out empty strings
|
|
cors_allowed_origins = [
|
|
origin.strip() for origin in cors_origins_raw.split(",") if origin.strip()
|
|
]
|
|
if cors_allowed_origins:
|
|
CORS_ALLOWED_ORIGINS = cors_allowed_origins
|
|
secure_origins = (
|
|
False
|
|
if [origin for origin in cors_allowed_origins if "http:" in origin]
|
|
else True
|
|
)
|
|
else:
|
|
CORS_ALLOW_ALL_ORIGINS = True
|
|
secure_origins = False
|
|
|
|
# Application Settings
|
|
WSGI_APPLICATION = "plane.wsgi.application"
|
|
ASGI_APPLICATION = "plane.asgi.application"
|
|
|
|
# Django Sites
|
|
SITE_ID = 1
|
|
|
|
# User Model
|
|
AUTH_USER_MODEL = "db.User"
|
|
|
|
# Database
|
|
if bool(os.environ.get("DATABASE_URL")):
|
|
# Parse database configuration from $DATABASE_URL
|
|
DATABASES = {
|
|
"default": dj_database_url.config(),
|
|
}
|
|
else:
|
|
DATABASES = {
|
|
"default": {
|
|
"ENGINE": "django.db.backends.postgresql",
|
|
"NAME": os.environ.get("POSTGRES_DB"),
|
|
"USER": os.environ.get("POSTGRES_USER"),
|
|
"PASSWORD": os.environ.get("POSTGRES_PASSWORD"),
|
|
"HOST": os.environ.get("POSTGRES_HOST"),
|
|
}
|
|
}
|
|
|
|
# Redis Config
|
|
REDIS_URL = os.environ.get("REDIS_URL")
|
|
REDIS_SSL = REDIS_URL and "rediss" in REDIS_URL
|
|
|
|
if REDIS_SSL:
|
|
CACHES = {
|
|
"default": {
|
|
"BACKEND": "django_redis.cache.RedisCache",
|
|
"LOCATION": REDIS_URL,
|
|
"OPTIONS": {
|
|
"CLIENT_CLASS": "django_redis.client.DefaultClient",
|
|
"CONNECTION_POOL_KWARGS": {"ssl_cert_reqs": False},
|
|
},
|
|
}
|
|
}
|
|
else:
|
|
CACHES = {
|
|
"default": {
|
|
"BACKEND": "django_redis.cache.RedisCache",
|
|
"LOCATION": REDIS_URL,
|
|
"OPTIONS": {
|
|
"CLIENT_CLASS": "django_redis.client.DefaultClient",
|
|
},
|
|
}
|
|
}
|
|
|
|
# Password validations
|
|
AUTH_PASSWORD_VALIDATORS = [
|
|
{
|
|
"NAME": "django.contrib.auth.password_validation.UserAttributeSimilarityValidator",
|
|
},
|
|
{
|
|
"NAME": "django.contrib.auth.password_validation.MinimumLengthValidator",
|
|
},
|
|
{
|
|
"NAME": "django.contrib.auth.password_validation.CommonPasswordValidator",
|
|
},
|
|
{
|
|
"NAME": "django.contrib.auth.password_validation.NumericPasswordValidator",
|
|
},
|
|
]
|
|
|
|
# Password reset time the number of seconds the uniquely generated uid will be valid
|
|
PASSWORD_RESET_TIMEOUT = 3600
|
|
|
|
# Static files (CSS, JavaScript, Images)
|
|
STATIC_URL = "/static/"
|
|
STATIC_ROOT = os.path.join(BASE_DIR, "static-assets", "collected-static")
|
|
STATICFILES_DIRS = (os.path.join(BASE_DIR, "static"),)
|
|
|
|
# Media Settings
|
|
MEDIA_ROOT = "mediafiles"
|
|
MEDIA_URL = "/media/"
|
|
|
|
# Internationalization
|
|
LANGUAGE_CODE = "en-us"
|
|
USE_I18N = True
|
|
USE_L10N = True
|
|
|
|
# Timezones
|
|
USE_TZ = True
|
|
TIME_ZONE = "UTC"
|
|
|
|
# Default Auto Field
|
|
DEFAULT_AUTO_FIELD = "django.db.models.BigAutoField"
|
|
|
|
# Email settings
|
|
EMAIL_BACKEND = "django.core.mail.backends.smtp.EmailBackend"
|
|
|
|
# Storage Settings
|
|
STORAGES = {
|
|
"staticfiles": {
|
|
"BACKEND": "whitenoise.storage.CompressedManifestStaticFilesStorage",
|
|
},
|
|
}
|
|
STORAGES["default"] = {
|
|
"BACKEND": "storages.backends.s3boto3.S3Boto3Storage",
|
|
}
|
|
AWS_ACCESS_KEY_ID = os.environ.get("AWS_ACCESS_KEY_ID", "access-key")
|
|
AWS_SECRET_ACCESS_KEY = os.environ.get("AWS_SECRET_ACCESS_KEY", "secret-key")
|
|
AWS_STORAGE_BUCKET_NAME = os.environ.get("AWS_S3_BUCKET_NAME", "uploads")
|
|
AWS_REGION = os.environ.get("AWS_REGION", "")
|
|
AWS_DEFAULT_ACL = "public-read"
|
|
AWS_QUERYSTRING_AUTH = False
|
|
AWS_S3_FILE_OVERWRITE = False
|
|
AWS_S3_ENDPOINT_URL = os.environ.get(
|
|
"AWS_S3_ENDPOINT_URL", None
|
|
) or os.environ.get("MINIO_ENDPOINT_URL", None)
|
|
if AWS_S3_ENDPOINT_URL:
|
|
parsed_url = urlparse(os.environ.get("WEB_URL", "http://localhost"))
|
|
AWS_S3_CUSTOM_DOMAIN = f"{parsed_url.netloc}/{AWS_STORAGE_BUCKET_NAME}"
|
|
AWS_S3_URL_PROTOCOL = f"{parsed_url.scheme}:"
|
|
|
|
|
|
# Celery Configuration
|
|
CELERY_TIMEZONE = TIME_ZONE
|
|
CELERY_TASK_SERIALIZER = "json"
|
|
CELERY_ACCEPT_CONTENT = ["application/json"]
|
|
|
|
if REDIS_SSL:
|
|
redis_url = os.environ.get("REDIS_URL")
|
|
broker_url = f"{redis_url}?ssl_cert_reqs={ssl.CERT_NONE.name}&ssl_ca_certs={certifi.where()}"
|
|
CELERY_BROKER_URL = broker_url
|
|
else:
|
|
CELERY_BROKER_URL = REDIS_URL
|
|
|
|
CELERY_IMPORTS = (
|
|
# scheduled tasks
|
|
"plane.bgtasks.issue_automation_task",
|
|
"plane.bgtasks.exporter_expired_task",
|
|
"plane.bgtasks.file_asset_task",
|
|
"plane.bgtasks.email_notification_task",
|
|
"plane.bgtasks.api_logs_task",
|
|
# management tasks
|
|
"plane.bgtasks.dummy_data_task",
|
|
)
|
|
|
|
# Sentry Settings
|
|
# Enable Sentry Settings
|
|
if bool(os.environ.get("SENTRY_DSN", False)) and os.environ.get(
|
|
"SENTRY_DSN"
|
|
).startswith("https://"):
|
|
sentry_sdk.init(
|
|
dsn=os.environ.get("SENTRY_DSN", ""),
|
|
integrations=[
|
|
DjangoIntegration(),
|
|
RedisIntegration(),
|
|
CeleryIntegration(monitor_beat_tasks=True),
|
|
],
|
|
traces_sample_rate=1,
|
|
send_default_pii=True,
|
|
environment=os.environ.get("SENTRY_ENVIRONMENT", "development"),
|
|
profiles_sample_rate=float(
|
|
os.environ.get("SENTRY_PROFILE_SAMPLE_RATE", 0.5)
|
|
),
|
|
)
|
|
|
|
|
|
# Application Envs
|
|
PROXY_BASE_URL = os.environ.get("PROXY_BASE_URL", False) # For External
|
|
|
|
FILE_SIZE_LIMIT = int(os.environ.get("FILE_SIZE_LIMIT", 5242880))
|
|
|
|
# Unsplash Access key
|
|
UNSPLASH_ACCESS_KEY = os.environ.get("UNSPLASH_ACCESS_KEY")
|
|
# Github Access Token
|
|
GITHUB_ACCESS_TOKEN = os.environ.get("GITHUB_ACCESS_TOKEN", False)
|
|
|
|
# Analytics
|
|
ANALYTICS_SECRET_KEY = os.environ.get("ANALYTICS_SECRET_KEY", False)
|
|
ANALYTICS_BASE_API = os.environ.get("ANALYTICS_BASE_API", False)
|
|
|
|
# Use Minio settings
|
|
USE_MINIO = int(os.environ.get("USE_MINIO", 0)) == 1
|
|
|
|
# Posthog settings
|
|
POSTHOG_API_KEY = os.environ.get("POSTHOG_API_KEY", False)
|
|
POSTHOG_HOST = os.environ.get("POSTHOG_HOST", False)
|
|
|
|
# instance key
|
|
INSTANCE_KEY = os.environ.get(
|
|
"INSTANCE_KEY",
|
|
"ae6517d563dfc13d8270bd45cf17b08f70b37d989128a9dab46ff687603333c3",
|
|
)
|
|
|
|
# Skip environment variable configuration
|
|
SKIP_ENV_VAR = os.environ.get("SKIP_ENV_VAR", "1") == "1"
|
|
|
|
DATA_UPLOAD_MAX_MEMORY_SIZE = int(os.environ.get("FILE_SIZE_LIMIT", 5242880))
|
|
|
|
# Cookie Settings
|
|
SESSION_COOKIE_SECURE = secure_origins
|
|
SESSION_COOKIE_HTTPONLY = True
|
|
SESSION_ENGINE = "plane.db.models.session"
|
|
SESSION_COOKIE_AGE = 604800
|
|
SESSION_COOKIE_NAME = "plane-session-id"
|
|
SESSION_COOKIE_DOMAIN = os.environ.get("COOKIE_DOMAIN", None)
|
|
SESSION_SAVE_EVERY_REQUEST = True
|
|
|
|
# Admin Cookie
|
|
ADMIN_SESSION_COOKIE_NAME = "plane-admin-session-id"
|
|
ADMIN_SESSION_COOKIE_AGE = 3600
|
|
|
|
# CSRF cookies
|
|
CSRF_COOKIE_SECURE = secure_origins
|
|
CSRF_COOKIE_HTTPONLY = True
|
|
CSRF_TRUSTED_ORIGINS = cors_allowed_origins
|
|
CSRF_COOKIE_DOMAIN = os.environ.get("COOKIE_DOMAIN", None)
|