1099
by matt.giuca
dispatch/__init__.py: Updated header comments to new policy, updated copyright. |
1 |
# IVLE - Informatics Virtual Learning Environment
|
2 |
# Copyright (C) 2007-2009 The University of Melbourne
|
|
1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
3 |
#
|
4 |
# This program is free software; you can redistribute it and/or modify
|
|
5 |
# it under the terms of the GNU General Public License as published by
|
|
6 |
# the Free Software Foundation; either version 2 of the License, or
|
|
7 |
# (at your option) any later version.
|
|
8 |
#
|
|
9 |
# This program is distributed in the hope that it will be useful,
|
|
10 |
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
11 |
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
12 |
# GNU General Public License for more details.
|
|
13 |
#
|
|
14 |
# You should have received a copy of the GNU General Public License
|
|
15 |
# along with this program; if not, write to the Free Software
|
|
16 |
# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
|
|
17 |
||
1099.1.1
by Matt Giuca
Began implementing new dispatch framework (with Will Grant and Nick Chadwick). |
18 |
# Author: Matt Giuca, Will Grant
|
1099
by matt.giuca
dispatch/__init__.py: Updated header comments to new policy, updated copyright. |
19 |
|
20 |
"""
|
|
21 |
This is a mod_python handler program. The correct way to call it is to have
|
|
22 |
Apache send all requests to be handled by the module 'dispatch'.
|
|
23 |
||
24 |
Top-level handler. Handles all requests to all pages in IVLE.
|
|
1099.1.166
by William Grant
Remove the odd handler() -> handler_() chaining in ivle.dispatch. |
25 |
Handles authentication and delegates to views for authorization,
|
26 |
then passes the request along to the appropriate view.
|
|
1099
by matt.giuca
dispatch/__init__.py: Updated header comments to new policy, updated copyright. |
27 |
"""
|
1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
28 |
|
29 |
import sys |
|
30 |
import os |
|
31 |
import os.path |
|
32 |
import urllib |
|
1673
by William Grant
Reject off-site non-GET requests. |
33 |
import urlparse |
1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
34 |
import cgi |
35 |
import traceback |
|
36 |
import logging |
|
37 |
import socket |
|
38 |
import time |
|
39 |
||
40 |
import mod_python |
|
41 |
||
42 |
from ivle import util |
|
1199
by William Grant
Populate req.config in a cleaner manner. |
43 |
import ivle.config |
1099.1.5
by William Grant
ivle.dispatch{,.{login,request}}: Fix mod_python imports to ensure that we can |
44 |
from ivle.dispatch.request import Request |
1099.1.161
by William Grant
Move ivle.dispatch.login.get_user_details() to ivle.webapp.security. |
45 |
import ivle.webapp.security |
1099.1.146
by William Grant
Add support for public mode views to the new framework. |
46 |
from ivle.webapp.base.plugins import ViewPlugin, PublicViewPlugin |
1099.1.202
by William Grant
XHTMLErrorView is now the default error view, so we get nice 404s. |
47 |
from ivle.webapp.base.xhtml import XHTMLView, XHTMLErrorView |
1673
by William Grant
Reject off-site non-GET requests. |
48 |
from ivle.webapp.errors import BadRequest, HTTPError, NotFound, Unauthorized |
1294.3.2
by William Grant
Router->Publisher |
49 |
from ivle.webapp.publisher import Publisher, PublishingError |
1294.2.18
by William Grant
Replace string-route-based dispatch with object-traversal-route one. |
50 |
from ivle.webapp import ApplicationRoot |
1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
51 |
|
1199
by William Grant
Populate req.config in a cleaner manner. |
52 |
config = ivle.config.Config() |
53 |
||
1294.2.129
by William Grant
Refuse to traverse through an object to which the user has no permissions. This stops information leakage in breadcrumbs. |
54 |
class ObjectPermissionCheckingPublisher(Publisher): |
55 |
"""A specialised publisher that checks object permissions.
|
|
56 |
||
57 |
This publisher verifies that the user holds any permission at all
|
|
58 |
on the model objects through which the resolution path passes. If
|
|
59 |
no permission is held, resolution is aborted with an Unauthorized
|
|
60 |
exception.
|
|
61 |
||
62 |
IMPORTANT: This does NOT check view permissions. It only checks
|
|
63 |
the objects in between the root and the view, exclusive!
|
|
64 |
"""
|
|
65 |
||
66 |
def traversed_to_object(self, obj): |
|
67 |
"""Check that the user has any permission at all over the object."""
|
|
68 |
if (hasattr(obj, 'get_permissions') and |
|
1544
by Matt Giuca
Added an argument 'config' to every single get_permissions method throughout the program. All calls to get_permissions pass a config. This is to allow per-site policy configurations on permissions. |
69 |
len(obj.get_permissions(self.root.user, config)) == 0): |
1294.2.130
by William Grant
If the user is an admin, indicate the object in an Unauthorized. |
70 |
# Indicate the forbidden object if this is an admin.
|
71 |
if self.root.user and self.root.user.admin: |
|
72 |
raise Unauthorized('Unauthorized: %s' % obj) |
|
73 |
else: |
|
74 |
raise Unauthorized() |
|
1294.2.129
by William Grant
Refuse to traverse through an object to which the user has no permissions. This stops information leakage in breadcrumbs. |
75 |
|
76 |
||
1294.2.133
by William Grant
Add support for public views. |
77 |
def generate_publisher(view_plugins, root, publicmode=False): |
1099.1.1
by Matt Giuca
Began implementing new dispatch framework (with Will Grant and Nick Chadwick). |
78 |
"""
|
79 |
Build a Mapper object for doing URL matching using 'routes', based on the
|
|
1099.1.59
by William Grant
Provide a media file framework in ivle.webapp.media. |
80 |
given plugin registry.
|
1099.1.1
by Matt Giuca
Began implementing new dispatch framework (with Will Grant and Nick Chadwick). |
81 |
"""
|
1294.2.129
by William Grant
Refuse to traverse through an object to which the user has no permissions. This stops information leakage in breadcrumbs. |
82 |
r = ObjectPermissionCheckingPublisher(root=root) |
1294.2.18
by William Grant
Replace string-route-based dispatch with object-traversal-route one. |
83 |
|
84 |
r.add_set_switch('api', 'api') |
|
85 |
||
1294.2.133
by William Grant
Add support for public views. |
86 |
if publicmode: |
87 |
view_attr = 'public_views' |
|
1294.2.134
by William Grant
Use a different set of routes for public mode, too. |
88 |
forward_route_attr = 'public_forward_routes' |
89 |
reverse_route_attr = 'public_reverse_routes' |
|
1294.2.133
by William Grant
Add support for public views. |
90 |
else: |
91 |
view_attr = 'views' |
|
1294.2.134
by William Grant
Use a different set of routes for public mode, too. |
92 |
forward_route_attr = 'forward_routes' |
93 |
reverse_route_attr = 'reverse_routes' |
|
94 |
||
1294.2.133
by William Grant
Add support for public views. |
95 |
|
1099.1.72
by Nick Chadwick
Dispatch now generates an index for each plugin type, allowing plugins to |
96 |
for plugin in view_plugins: |
1294.2.134
by William Grant
Use a different set of routes for public mode, too. |
97 |
if hasattr(plugin, forward_route_attr): |
98 |
for fr in getattr(plugin, forward_route_attr): |
|
1294.2.68
by William Grant
Add annotated route function support to ivle.dispatch. |
99 |
# An annotated function can also be passed in directly.
|
100 |
if hasattr(fr, '_forward_route_meta'): |
|
101 |
r.add_forward_func(fr) |
|
102 |
else: |
|
103 |
r.add_forward(*fr) |
|
104 |
||
1294.2.134
by William Grant
Use a different set of routes for public mode, too. |
105 |
if hasattr(plugin, reverse_route_attr): |
1294.2.135
by William Grant
Fix route typo. |
106 |
for rr in getattr(plugin, reverse_route_attr): |
1294.2.68
by William Grant
Add annotated route function support to ivle.dispatch. |
107 |
# An annotated function can also be passed in directly.
|
108 |
if hasattr(rr, '_reverse_route_src'): |
|
109 |
r.add_reverse_func(rr) |
|
110 |
else: |
|
111 |
r.add_reverse(*rr) |
|
1294.2.18
by William Grant
Replace string-route-based dispatch with object-traversal-route one. |
112 |
|
1294.2.133
by William Grant
Add support for public views. |
113 |
if hasattr(plugin, view_attr): |
114 |
for v in getattr(plugin, view_attr): |
|
1294.2.18
by William Grant
Replace string-route-based dispatch with object-traversal-route one. |
115 |
r.add_view(*v) |
116 |
||
117 |
return r |
|
1099.1.1
by Matt Giuca
Began implementing new dispatch framework (with Will Grant and Nick Chadwick). |
118 |
|
1099.1.166
by William Grant
Remove the odd handler() -> handler_() chaining in ivle.dispatch. |
119 |
def handler(apachereq): |
120 |
"""Handles an HTTP request.
|
|
121 |
||
1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
122 |
Intended to be called by mod_python, as a handler.
|
123 |
||
1099.1.166
by William Grant
Remove the odd handler() -> handler_() chaining in ivle.dispatch. |
124 |
@param apachereq: An Apache request object.
|
125 |
"""
|
|
126 |
# Make the request object into an IVLE request which can be given to views
|
|
1199
by William Grant
Populate req.config in a cleaner manner. |
127 |
req = Request(apachereq, config) |
1099.1.166
by William Grant
Remove the odd handler() -> handler_() chaining in ivle.dispatch. |
128 |
|
1294.2.129
by William Grant
Refuse to traverse through an object to which the user has no permissions. This stops information leakage in breadcrumbs. |
129 |
req.publisher = generate_publisher( |
1712
by William Grant
Shuffle things around so that req.user and req.store only construct when actually retrieved, and ensure they're not retrieved for media files. Saves 50ms of DB connection time per request. |
130 |
config.plugin_index[ViewPlugin], ApplicationRoot(req), |
1294.2.133
by William Grant
Add support for public views. |
131 |
publicmode=req.publicmode) |
1294.2.18
by William Grant
Replace string-route-based dispatch with object-traversal-route one. |
132 |
|
133 |
try: |
|
1294.3.3
by William Grant
req.router -> req.publisher |
134 |
obj, viewcls, subpath = req.publisher.resolve(req.uri.decode('utf-8')) |
1099.1.84
by William Grant
Handle HTTPErrors nicely in the new framework. Currently there is no facility |
135 |
try: |
1294.2.59
by William Grant
Implement optional view subpath support. |
136 |
# We 404 if we have a subpath but the view forbids it.
|
137 |
if not viewcls.subpath_allowed and subpath: |
|
138 |
raise NotFound() |
|
139 |
||
1099.1.86
by William Grant
Also capture the view object creation in the new framework's exception handler. |
140 |
# Instantiate the view, which should be a BaseView class
|
1294.2.59
by William Grant
Implement optional view subpath support. |
141 |
view = viewcls(req, obj, subpath) |
1099.1.110
by William Grant
Implement an authorization system in the new framework. This breaks the REST |
142 |
|
143 |
# Check that the request (mainly the user) is permitted to access
|
|
144 |
# the view.
|
|
145 |
if not view.authorize(req): |
|
1294.2.130
by William Grant
If the user is an admin, indicate the object in an Unauthorized. |
146 |
# Indicate the forbidden object if this is an admin.
|
147 |
if req.user and req.user.admin: |
|
148 |
raise Unauthorized('Unauthorized: %s' % view) |
|
149 |
else: |
|
150 |
raise Unauthorized() |
|
1673
by William Grant
Reject off-site non-GET requests. |
151 |
|
152 |
# Non-GET requests from other sites leave us vulnerable to
|
|
153 |
# CSRFs. Block them.
|
|
154 |
referer = req.headers_in.get('Referer') |
|
155 |
if (referer is None or |
|
156 |
urlparse.urlparse(req.headers_in.get('Referer')).netloc != |
|
157 |
req.hostname): |
|
158 |
if req.method != 'GET' and not view.offsite_posts_allowed: |
|
159 |
raise BadRequest( |
|
160 |
"Non-GET requests from external sites are forbidden "
|
|
161 |
"for security reasons.") |
|
162 |
||
1099.1.86
by William Grant
Also capture the view object creation in the new framework's exception handler. |
163 |
# Render the output
|
1099.1.84
by William Grant
Handle HTTPErrors nicely in the new framework. Currently there is no facility |
164 |
view.render(req) |
165 |
except HTTPError, e: |
|
166 |
# A view explicitly raised an HTTP error. Respect it.
|
|
167 |
req.status = e.code |
|
1099.1.91
by William Grant
Add support for custom error views. Plugins can now declare that errors |
168 |
|
169 |
# Try to find a custom error view.
|
|
1099.1.95
by William Grant
Error views are now retrieved from a class method of the view, not the plugin |
170 |
if hasattr(viewcls, 'get_error_view'): |
171 |
errviewcls = viewcls.get_error_view(e) |
|
172 |
else: |
|
1099.1.202
by William Grant
XHTMLErrorView is now the default error view, so we get nice 404s. |
173 |
errviewcls = XHTMLView.get_error_view(e) |
1099.1.95
by William Grant
Error views are now retrieved from a class method of the view, not the plugin |
174 |
|
1099.1.91
by William Grant
Add support for custom error views. Plugins can now declare that errors |
175 |
if errviewcls: |
1294.2.108
by William Grant
Display breadcrumbs on error pages too. |
176 |
errview = errviewcls(req, e, obj) |
1099.1.91
by William Grant
Add support for custom error views. Plugins can now declare that errors |
177 |
errview.render(req) |
178 |
return req.OK |
|
1099.1.135
by William Grant
In the new framework handler, either write the exception message or use |
179 |
elif e.message: |
1099.1.91
by William Grant
Add support for custom error views. Plugins can now declare that errors |
180 |
req.write(e.message) |
1099.1.135
by William Grant
In the new framework handler, either write the exception message or use |
181 |
return req.OK |
182 |
else: |
|
1099.1.91
by William Grant
Add support for custom error views. Plugins can now declare that errors |
183 |
return e.code |
1155
by William Grant
Don't handle mod_python exceptions (eg. redirects) as unknown exceptions. |
184 |
except mod_python.apache.SERVER_RETURN: |
185 |
# A mod_python-specific Apache error.
|
|
186 |
# XXX: We need to raise these because req.throw_error() uses them.
|
|
187 |
# Remove this after Google Code issue 117 is fixed.
|
|
188 |
raise
|
|
1099.1.84
by William Grant
Handle HTTPErrors nicely in the new framework. Currently there is no facility |
189 |
except Exception, e: |
190 |
# A non-HTTPError appeared. We have an unknown exception. Panic.
|
|
191 |
handle_unknown_exception(req, *sys.exc_info()) |
|
1099.1.88
by William Grant
Make sure that we don't use the old framework if the new framework crashes. |
192 |
return req.OK |
1099.1.84
by William Grant
Handle HTTPErrors nicely in the new framework. Currently there is no facility |
193 |
else: |
1712
by William Grant
Shuffle things around so that req.user and req.store only construct when actually retrieved, and ensure they're not retrieved for media files. Saves 50ms of DB connection time per request. |
194 |
# Commit the transaction if we have a store open.
|
195 |
req.commit() |
|
1099.1.84
by William Grant
Handle HTTPErrors nicely in the new framework. Currently there is no facility |
196 |
return req.OK |
1294.2.129
by William Grant
Refuse to traverse through an object to which the user has no permissions. This stops information leakage in breadcrumbs. |
197 |
except Unauthorized, e: |
198 |
# Resolution failed due to a permission check. Display a pretty
|
|
199 |
# error, or maybe a login page.
|
|
200 |
XHTMLView.get_error_view(e)(req, e, req.publisher.root).render(req) |
|
201 |
return req.OK |
|
1294.3.2
by William Grant
Router->Publisher |
202 |
except PublishingError, e: |
1294.2.107
by William Grant
Actually return a 404 if routing fails. |
203 |
req.status = 404 |
204 |
||
1294.2.122
by William Grant
Don't crash in admin check if not logged in. |
205 |
if req.user and req.user.admin: |
1294.2.48
by William Grant
Display useful NotFound data to admins. |
206 |
XHTMLErrorView(req, NotFound('Not found: ' + |
1294.2.108
by William Grant
Display breadcrumbs on error pages too. |
207 |
str(e.args)), e[0]).render(req) |
1294.2.48
by William Grant
Display useful NotFound data to admins. |
208 |
else: |
1294.2.108
by William Grant
Display breadcrumbs on error pages too. |
209 |
XHTMLErrorView(req, NotFound(), e[0]).render(req) |
1294.2.48
by William Grant
Display useful NotFound data to admins. |
210 |
|
1099.1.202
by William Grant
XHTMLErrorView is now the default error view, so we get nice 404s. |
211 |
return req.OK |
1625
by William Grant
Ensure that we always close the DB connection at request termination, even in the case of an exception. |
212 |
finally: |
1712
by William Grant
Shuffle things around so that req.user and req.store only construct when actually retrieved, and ensure they're not retrieved for media files. Saves 50ms of DB connection time per request. |
213 |
# Make sure we close the store.
|
214 |
req.cleanup() |
|
1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
215 |
|
216 |
def handle_unknown_exception(req, exc_type, exc_value, exc_traceback): |
|
217 |
"""
|
|
218 |
Given an exception that has just been thrown from IVLE, print its details
|
|
219 |
to the request.
|
|
220 |
This is a full handler. It assumes nothing has been written, and writes a
|
|
221 |
complete HTML page.
|
|
222 |
req: May be EITHER an IVLE req or an Apache req.
|
|
1099.1.157
by William Grant
Drop the 4xx-series exception handling ability from |
223 |
The handler code may pass an apache req if an exception occurs before
|
1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
224 |
the IVLE request is created.
|
225 |
"""
|
|
226 |
req.content_type = "text/html" |
|
1199
by William Grant
Populate req.config in a cleaner manner. |
227 |
logfile = os.path.join(config['paths']['logs'], 'ivle_error.log') |
1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
228 |
logfail = False |
1292
by William Grant
Revive a removed part of the top-level crash handler. |
229 |
|
1779
by William Grant
Remove IVLEError support; only fileservice used it, and the last invocation is GONE. |
230 |
req.status = mod_python.apache.HTTP_INTERNAL_SERVER_ERROR |
1286
by William Grant
Simplify (and deprettify) the crash handler. It's now only used to handle crashes, so needn't be pretty. |
231 |
|
1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
232 |
try: |
1087
by chadnickbok
Fixes Issue #3 |
233 |
publicmode = req.publicmode |
234 |
except AttributeError: |
|
1088
by chadnickbok
Fixed an issue with my previous patch to this file. Now, if |
235 |
publicmode = True |
1087
by chadnickbok
Fixes Issue #3 |
236 |
try: |
1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
237 |
login = req.user.login |
238 |
except AttributeError: |
|
239 |
login = None |
|
240 |
||
241 |
# Log File
|
|
242 |
try: |
|
243 |
for h in logging.getLogger().handlers: |
|
244 |
logging.getLogger().removeHandler(h) |
|
245 |
logging.basicConfig(level=logging.INFO, |
|
246 |
format='%(asctime)s %(levelname)s: ' + |
|
247 |
'(HTTP: ' + str(req.status) + |
|
248 |
', Ref: ' + str(login) + '@' + |
|
249 |
str(socket.gethostname()) + str(req.uri) + |
|
250 |
') %(message)s', |
|
251 |
filename=logfile, |
|
252 |
filemode='a') |
|
253 |
except IOError: |
|
254 |
logfail = True |
|
255 |
||
1099.1.157
by William Grant
Drop the 4xx-series exception handling ability from |
256 |
# A "bad" error message. We shouldn't get here unless IVLE
|
257 |
# misbehaves (which is currently very easy, if things aren't set up
|
|
258 |
# correctly).
|
|
259 |
# Write the traceback.
|
|
1286
by William Grant
Simplify (and deprettify) the crash handler. It's now only used to handle crashes, so needn't be pretty. |
260 |
|
261 |
# We need to special-case IVLEJailError, as we can get another
|
|
1099.1.157
by William Grant
Drop the 4xx-series exception handling ability from |
262 |
# almost-exception out of it.
|
263 |
if exc_type is util.IVLEJailError: |
|
264 |
tb = 'Exception information extracted from IVLEJailError:\n' |
|
265 |
tb += urllib.unquote(exc_value.info) |
|
266 |
else: |
|
267 |
tb = ''.join(traceback.format_exception(exc_type, exc_value, |
|
268 |
exc_traceback)) |
|
269 |
||
1286
by William Grant
Simplify (and deprettify) the crash handler. It's now only used to handle crashes, so needn't be pretty. |
270 |
logging.error('\n' + tb) |
1099.1.167
by William Grant
Simplify and prettify the crash handler. |
271 |
|
1099.1.157
by William Grant
Drop the 4xx-series exception handling ability from |
272 |
# Error messages are only displayed is the user is NOT a student,
|
273 |
# or if there has been a problem logging the error message
|
|
1101
by William Grant
Privileges (apart from admin) are now offering-local, not global. |
274 |
show_errors = (not publicmode) and ((login and req.user.admin) or logfail) |
1099.1.157
by William Grant
Drop the 4xx-series exception handling ability from |
275 |
req.write("""<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" |
1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
276 |
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
|
277 |
<html xmlns="http://www.w3.org/1999/xhtml">
|
|
278 |
<head><title>IVLE Internal Server Error</title></head>
|
|
279 |
<body>
|
|
1286
by William Grant
Simplify (and deprettify) the crash handler. It's now only used to handle crashes, so needn't be pretty. |
280 |
<h1>IVLE Internal Server Error</h1>
|
1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
281 |
<p>An error has occured which is the fault of the IVLE developers or
|
1099.1.175
by William Grant
Alter the crash handler to display a different message depending on whether |
282 |
administrators. """) |
283 |
||
284 |
if logfail: |
|
285 |
req.write("Please report this issue to the server administrators, " |
|
286 |
"along with the following information.") |
|
287 |
else: |
|
288 |
req.write("Details have been logged for further examination.") |
|
289 |
req.write("</p>") |
|
290 |
||
1099.1.167
by William Grant
Simplify and prettify the crash handler. |
291 |
if show_errors: |
292 |
req.write("<h2>Debugging information</h2>") |
|
1099.1.157
by William Grant
Drop the 4xx-series exception handling ability from |
293 |
req.write("<pre>\n%s\n</pre>\n"%cgi.escape(tb)) |
294 |
req.write("</body></html>") |