
Apart from making keystoneclient follow the same patterns of using an adapter that we are trying to push onto other clients this severs the cyclical dependency between managers and the client object. There are a few changes that have had to be rolled into one to make the transition work. These can't be separated unfortunately as they are interdependent. * managers are now passed the adapter instead of the client. They therefore don't have reference to the other managers on the client. * The adapter has been subclassed to provide user_id as there are some managers that require user_id be provided for changing passwords etc. * client.auth_url has been replaced with a call to get_endpoint which is supported by the adapter. * management=True has been removed from all the managers and they now correctly set the interface they want. Change-Id: I49fbd50571f0c1484e1cbc3dcb2159d25b21b1bc
49 lines
1.9 KiB
Python
49 lines
1.9 KiB
Python
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
# you may not use this file except in compliance with the License.
|
|
# You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
|
# implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
|
|
from __future__ import unicode_literals
|
|
|
|
from keystoneclient import auth
|
|
from keystoneclient import base
|
|
from keystoneclient.v3.contrib.oauth1 import utils
|
|
|
|
try:
|
|
from oauthlib import oauth1
|
|
except ImportError:
|
|
oauth1 = None
|
|
|
|
|
|
class AccessToken(base.Resource):
|
|
pass
|
|
|
|
|
|
class AccessTokenManager(base.CrudManager):
|
|
"""Manager class for manipulating identity OAuth access tokens."""
|
|
resource_class = AccessToken
|
|
|
|
def create(self, consumer_key, consumer_secret, request_key,
|
|
request_secret, verifier):
|
|
endpoint = utils.OAUTH_PATH + '/access_token'
|
|
oauth_client = oauth1.Client(consumer_key,
|
|
client_secret=consumer_secret,
|
|
resource_owner_key=request_key,
|
|
resource_owner_secret=request_secret,
|
|
signature_method=oauth1.SIGNATURE_HMAC,
|
|
verifier=verifier)
|
|
url = self.api.get_endpoint(interface=auth.AUTH_INTERFACE).rstrip('/')
|
|
url, headers, body = oauth_client.sign(url + endpoint,
|
|
http_method='POST')
|
|
resp, body = self.client.post(endpoint, headers=headers)
|
|
token = utils.get_oauth_token_from_body(resp.content)
|
|
return self.resource_class(self, token)
|