mirror of
https://github.com/peeringdb/peeringdb.git
synced 2024-05-11 05:55:09 +00:00
* Change label from primary ASN to ASN * Raise validation error when trying to update ASN * first steps for dotf importer procotol (#697) * migrations (#697) * Add translation to error meessage * Make ASN readonly in table * Add test now that ASN should not be able to update * Set fac.rencode to '' for all entries and make it readonly in serializer * Add unique constraints to network ixlan ip addresses * Add migration to null out duplicate ipaddresses for deleted netixlans * Add unique constraints to network ixlan ip addresses * Add migration to null out duplicate ipaddresses for deleted netixlans * remove old migrations (#697) * fix netixlan ipaddr dedupe migration (#268) add netixlan ipaddr unique constraint migration (#268) * ixf_member_data migrations (#697) * fix table name (#697) * importer protocol (#697) * fix netixlan ipaddr dedupe migration (#268) add netixlan ipaddr unique constraint migration (#268) * ixf proposed changes notifications (#697) * Delete repeated query * Add a test to show rencode is readonly * Blank out rencode when mocking data * Remove validator now that constraint exists * Add back unique field validator w Check Deleted true * conflict resolving (#697) * UniqueFieldValidator raise error with code "unique" (#268) * conflict resolution (#697) * Add fixme comment to tests * conflict resolution (#697) * Remove now invalid undelete tests * UniqueFieldValidator raise error with code "unique" (#268) * delete admin tools for duplicate ip addresses * Make migration to delete duplicateipnetworkixlan * Add ixlan-ixpfx status matching validation, add corresponding test * delete redundant checking in test * resolve conflict ui (#697) * fix migrations hierarchy * squash migrations for ixf member data * clean up preview and post-mortem tools * remove non-sensical permission check when undeleting soft-deleted objects through unique integrity error handling * only include the ix-f data url in notifications to admincom (#697) * resolve on --skip-import (#697) * ac conflict resolution (#697) * Define more accurately the incompatible statuses for ixlan and ixpfx * Add another status test * Preventing disrupting changes (#697) * fix tests (#697) * Stop allow_ixp_update from being write only and add a global stat for automated networks * Add tests for global stats that appear in footer * Change how timezone is called with datetime, to get test_stats.py/test_generate_for_current_date to pass * test for protected entities (#697) * admincom conflict resolution refine readonly fields (#697) network notifications only if the problem is actually actionable by the network (#697) * ixp / ac notifcation when ix-f source cannot be parsed (#697) fix issue with ixlan prefix protection (#697) * migrations (#697) * code documentation (#697) * ux tweaks (#697) * UX tweaks (#697) * Fix typo * fix netixlan returned in IXFMemberData.apply when adding a new one (#697) * fix import log incosistencies (#697) * Add IXFMemberData to test * Update test data * Add protocol tests * Add tests for views * always persist changes to remote data on set_conflict (#697) * More tests * always persist changes to remote data on set_conflict (#697) * suggest-add test * net_present_at_ix should check status (#697) * Add more protocol tests * Edit language of some tests * django-peeringdb to 2.1.1 relock pipfile, pin django-ratelimit to <3 as it breaks stuff * Add net_count_ixf field to ix object (#683) * Add the IX-F Member Export URL to the ixlan API endpoint (#249) * Lock some objects from being deleted by the owner (#696) * regenerate api docs (#249) * always persist changes to remote data on set_add and set_update (#697) * IXFMemberData: always persist remote data changes during set_add and set_update, also allow for saving without touching the updated field * always persist changes to remote data on set_add and set_update (#697) * Fix suggest-add tests * IXFMemberData: always persist remote data changes during set_add and set_update, also allow for saving without touching the updated field * IXFMemberData: always persist remote data changes during set_add and set_update, also allow for saving without touching the updated field * fix issue with deletion when ixfmemberdata for entry existed previously (#697) * fix test_suggest_delete_local_ixf_no_flag (#697 tests) * fix issue with deletion when ixfmemberdata for entry existed previously (#697) * invalid ips get logged and notified to the ix via notify_error (#697) * Fix more tests * issue with previous_data when running without save (#697) properly track speed errors (#697) * reset errors on ixfmemberdata that go into pending_save (#697) * add remote_data to admin view (#697) * fix error reset inconsistency (#697) * Refine invalid data tests * remove debug output * for notifications to ac include contact points for net and ix in the message (#697) * settings to toggle ix-f tickets / emails (#697) * allow turning off ix-f notifications for net and ix separately (#697) * add jsonschema test * Add idempotent tests to updater * remove old ixf member tests * Invalid data tests when ixp_updates are enabled * fix speed error validation (#697) * fix issue with rollback (#697) * fix migration hierarchy * fix ixfmemberdata _email * django-peeringdb to 2.2 and relock * add ixf rollback tests * ixf email notifications off by default * black formatted * pyupgrade Co-authored-by: egfrank <egfrank@20c.com> Co-authored-by: Stefan Pratter <stefan@20c.com>
170 lines
4.8 KiB
Python
170 lines
4.8 KiB
Python
import json
|
|
import base64
|
|
|
|
from django.http import JsonResponse, HttpResponse
|
|
from django.conf import settings
|
|
from django.utils.translation import ugettext_lazy as _
|
|
from django.contrib.auth import authenticate
|
|
|
|
from django_namespace_perms.util import has_perms
|
|
from ratelimit.decorators import ratelimit, is_ratelimited
|
|
|
|
from peeringdb_server import ixf
|
|
from peeringdb_server.models import (
|
|
IXLan,
|
|
Network,
|
|
NetworkIXLan,
|
|
)
|
|
|
|
RATELIMITS = settings.RATELIMITS
|
|
|
|
|
|
def enable_basic_auth(fn):
|
|
"""
|
|
a simple decorator to enable basic auth for a specific view
|
|
"""
|
|
|
|
def wrapped(request, *args, **kwargs):
|
|
if "HTTP_AUTHORIZATION" in request.META:
|
|
auth = request.META["HTTP_AUTHORIZATION"].split()
|
|
if len(auth) == 2:
|
|
if auth[0].lower() == "basic":
|
|
username, password = base64.b64decode(auth[1]).split(":", 1)
|
|
request.user = authenticate(username=username, password=password)
|
|
if not request.user:
|
|
return JsonResponse(
|
|
{"non_field_errors": ["Invalid credentials"]}, status=401
|
|
)
|
|
return fn(request, *args, **kwargs)
|
|
|
|
return wrapped
|
|
|
|
|
|
def pretty_response(data):
|
|
return HttpResponse(json.dumps(data, indent=2), content_type="application/json")
|
|
|
|
|
|
def error_response(msg, status=400):
|
|
return JsonResponse({"non_field_errors": [msg]}, status=status)
|
|
|
|
|
|
@ratelimit(
|
|
key="ip", rate=RATELIMITS["view_import_ixlan_ixf_preview"], group="ixf_preview"
|
|
)
|
|
@enable_basic_auth
|
|
def view_import_ixlan_ixf_preview(request, ixlan_id):
|
|
|
|
# check if request was blocked by rate limiting
|
|
was_limited = getattr(request, "limited", False)
|
|
if was_limited:
|
|
return error_response(
|
|
_("Please wait a bit before requesting " "another ixf import preview."),
|
|
status=400,
|
|
)
|
|
|
|
try:
|
|
ixlan = IXLan.objects.get(id=ixlan_id)
|
|
except IXLan.DoesNotExist:
|
|
return error_response(_("Ixlan not found"), status=404)
|
|
|
|
if not has_perms(request.user, ixlan, "update"):
|
|
return error_response(_("Permission denied"), status=403)
|
|
|
|
importer = ixf.Importer()
|
|
importer.update(ixlan, save=False)
|
|
|
|
return pretty_response(importer.log)
|
|
|
|
|
|
@ratelimit(
|
|
key="ip", rate=RATELIMITS["view_import_net_ixf_postmortem"], group="ixf_postmortem"
|
|
)
|
|
@enable_basic_auth
|
|
def view_import_net_ixf_postmortem(request, net_id):
|
|
|
|
# check if request was blocked by rate limiting
|
|
|
|
was_limited = getattr(request, "limited", False)
|
|
if was_limited:
|
|
return error_response(
|
|
_("Please wait a bit before requesting " "another IX-F import postmortem."),
|
|
status=400,
|
|
)
|
|
|
|
# load net
|
|
|
|
try:
|
|
net = Network.objects.get(id=net_id, status="ok")
|
|
except Network.DoesNotExist:
|
|
return error_response(_("Network not found"), status=404)
|
|
|
|
if not has_perms(request.user, net, "update"):
|
|
return error_response(_("Permission denied"), status=403)
|
|
|
|
# make sure limit is within bounds and a valid number
|
|
|
|
try:
|
|
limit = int(request.GET.get("limit", 25))
|
|
except:
|
|
limit = 25
|
|
|
|
errors = []
|
|
|
|
if limit < 1:
|
|
limit = 1
|
|
|
|
elif limit > settings.IXF_POSTMORTEM_LIMIT:
|
|
errors.append(
|
|
_("Postmortem length cannot exceed {} entries").format(
|
|
settings.IXF_POSTMORTEM_LIMIT
|
|
)
|
|
)
|
|
|
|
post_mortem = ixf.PostMortem()
|
|
log = post_mortem.generate(net.asn, limit=limit)
|
|
|
|
return pretty_response({"data": log, "non_field_errors": errors})
|
|
|
|
|
|
@ratelimit(
|
|
key="ip", rate=RATELIMITS["view_import_ixlan_ixf_preview"], group="ixf_preview"
|
|
)
|
|
@enable_basic_auth
|
|
def view_import_net_ixf_preview(request, net_id):
|
|
|
|
# check if request was blocked by rate limiting
|
|
was_limited = getattr(request, "limited", False)
|
|
if was_limited:
|
|
return error_response(
|
|
_("Please wait a bit before requesting " "another ixf import preview."),
|
|
status=400,
|
|
)
|
|
|
|
try:
|
|
net = Network.objects.get(id=net_id, status="ok")
|
|
except Network.DoesNotExist:
|
|
return error_response(_("Network not found"), status=404)
|
|
|
|
if not has_perms(request.user, net, "update"):
|
|
return error_response(_("Permission denied"), status=403)
|
|
|
|
total_log = {"data": [], "errors": []}
|
|
|
|
for ixlan in net.ixlan_set_ixf_enabled:
|
|
importer = ixf.Importer()
|
|
importer.cache_only = True
|
|
success = importer.update(ixlan, asn=net.asn, save=False)
|
|
|
|
# strip suggestions
|
|
log_data = [i for i in importer.log["data"] if not "suggest-" in i["action"]]
|
|
|
|
total_log["data"].extend(log_data)
|
|
total_log["errors"].extend(
|
|
[
|
|
f"{ixlan.ix.name}({ixlan.id}): {err}"
|
|
for err in importer.log["errors"]
|
|
]
|
|
)
|
|
|
|
return pretty_response(total_log)
|