2020-08-11 20:36:09 -04:00
|
|
|
import logging
|
2021-03-21 23:02:18 -05:00
|
|
|
from typing import (
|
|
|
|
Union,
|
|
|
|
List,
|
2022-01-15 02:23:50 +02:00
|
|
|
Optional, Tuple, Dict, Any
|
2021-03-21 23:02:18 -05:00
|
|
|
)
|
2022-01-26 01:45:30 +00:00
|
|
|
import tornado.web
|
|
|
|
import bleach
|
2020-08-11 20:36:09 -04:00
|
|
|
|
2022-01-15 02:23:50 +02:00
|
|
|
from app.classes.shared.authentication import authentication
|
2021-09-09 00:01:10 +02:00
|
|
|
from app.classes.shared.main_controller import Controller
|
2022-01-26 01:45:30 +00:00
|
|
|
|
2022-01-15 02:23:50 +02:00
|
|
|
from app.classes.models.users import ApiKeys
|
2021-09-09 00:01:10 +02:00
|
|
|
|
2020-08-11 20:36:09 -04:00
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
|
|
|
|
|
|
|
|
class BaseHandler(tornado.web.RequestHandler):
|
|
|
|
|
2021-04-03 13:18:43 -05:00
|
|
|
nobleach = {bool, type(None)}
|
2021-04-04 12:48:02 -05:00
|
|
|
redactables = ("pass", "api")
|
2021-04-03 13:18:43 -05:00
|
|
|
|
2022-01-15 02:23:50 +02:00
|
|
|
# noinspection PyAttributeOutsideInit
|
|
|
|
def initialize(self, controller: Controller = None, tasks_manager=None, translator=None):
|
2021-03-21 23:02:18 -05:00
|
|
|
self.controller = controller
|
|
|
|
self.tasks_manager = tasks_manager
|
2021-03-26 15:57:50 +02:00
|
|
|
self.translator = translator
|
2021-03-21 23:02:18 -05:00
|
|
|
|
2020-08-11 20:36:09 -04:00
|
|
|
def get_remote_ip(self):
|
|
|
|
remote_ip = self.request.headers.get("X-Real-IP") or \
|
|
|
|
self.request.headers.get("X-Forwarded-For") or \
|
|
|
|
self.request.remote_ip
|
|
|
|
return remote_ip
|
|
|
|
|
2022-01-15 02:23:50 +02:00
|
|
|
current_user: Optional[Tuple[Optional[ApiKeys], Dict[str, Any], Dict[str, Any]]]
|
|
|
|
def get_current_user(self) -> Optional[Tuple[Optional[ApiKeys], Dict[str, Any], Dict[str, Any]]]:
|
|
|
|
return authentication.check(self.get_cookie("token"))
|
2021-03-21 23:02:18 -05:00
|
|
|
|
2021-04-04 12:48:02 -05:00
|
|
|
def autobleach(self, name, text):
|
|
|
|
for r in self.redactables:
|
|
|
|
if r in name:
|
2022-01-26 01:45:30 +00:00
|
|
|
logger.debug(f"Auto-bleaching {name}: [**REDACTED**]")
|
2021-04-04 21:22:52 +03:00
|
|
|
break
|
2021-04-04 12:48:02 -05:00
|
|
|
else:
|
2022-01-26 01:45:30 +00:00
|
|
|
logger.debug(f"Auto-bleaching {name}: {text}")
|
2021-04-03 13:18:43 -05:00
|
|
|
if type(text) in self.nobleach:
|
2021-04-04 12:48:02 -05:00
|
|
|
logger.debug("Auto-bleaching - bypass type")
|
2021-03-21 23:02:18 -05:00
|
|
|
return text
|
|
|
|
else:
|
2021-04-03 13:18:43 -05:00
|
|
|
return bleach.clean(text)
|
2021-03-21 23:02:18 -05:00
|
|
|
|
|
|
|
def get_argument(
|
|
|
|
self,
|
|
|
|
name: str,
|
|
|
|
default: Union[None, str, tornado.web._ArgDefaultMarker] = tornado.web._ARG_DEFAULT,
|
|
|
|
strip: bool = True,
|
|
|
|
) -> Optional[str]:
|
|
|
|
arg = self._get_argument(name, default, self.request.arguments, strip)
|
2021-04-04 12:48:02 -05:00
|
|
|
return self.autobleach(name, arg)
|
2021-03-21 23:02:18 -05:00
|
|
|
|
|
|
|
def get_arguments(self, name: str, strip: bool = True) -> List[str]:
|
|
|
|
assert isinstance(strip, bool)
|
|
|
|
args = self._get_arguments(name, self.request.arguments, strip)
|
|
|
|
args_ret = []
|
|
|
|
for arg in args:
|
2021-04-04 12:48:02 -05:00
|
|
|
args_ret += self.autobleach(name, arg)
|
2021-03-21 23:02:18 -05:00
|
|
|
return args_ret
|