Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
103 changes: 100 additions & 3 deletions conditional/__init__.py
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@

import structlog
from csh_ldap import CSHLDAP
from flask import Flask, redirect, render_template, g
from flask import Flask, redirect, render_template, request, g
from flask_migrate import Migrate
from flask_gzip import Gzip
from flask_pyoidc.flask_pyoidc import OIDCAuthentication
Expand Down Expand Up @@ -56,7 +56,17 @@ def start_of_year():


# pylint: disable=C0413
from .models.models import UserLog
from .models.models import (
CommitteeMeeting,
CurrentCoops,
FreshmanEvalData,
HouseMeeting,
MemberCommitteeAttendance,
MemberHouseMeetingAttendance,
MemberSeminarAttendance,
TechnicalSeminar,
UserLog,
)


# Configure Logging
Expand Down Expand Up @@ -130,7 +140,7 @@ def database_processor(logger, log_method, event_dict): # pylint: disable=unuse
app.register_blueprint(co_op_bp)
app.register_blueprint(log_bp)

from .util.ldap import ldap_get_member
from .util.ldap import ldap_get_member, ldap_is_active, ldap_is_intromember


@app.route('/<path:path>')
Expand Down Expand Up @@ -159,6 +169,93 @@ def health():
return {'status': 'ok'}


@app.route("/gatekeep/<username>")
def gatekeep_status(username):
token = request.headers.get("X-VOTE-TOKEN", "")
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think limiting access to this call is better done with a service account - we already have ones for services like drink and selfservice, and you could do a check on the username/email/whatever.

Personally I don't really understand why this call is being limited to vote - it would be pretty easy to pull the relevant information from LDAP + scrape /spring_evals to get the information anyway.

Regardless, I think giving vote a service account to give it authentication is a more robust solution for access control to API calls.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It would be "pretty easy" to do that, but the number of people that will do that is very little (historically probably 0), considering we all rely on our Evals Director to run the queries year after year.
Having an accessible endpoint would make it significantly more convenient, and I would imagine people would actually start looking at it.

As far as the service account vs token is concerned, a token is fine... It's "more robust" but if we are hard-coding a username in as a check, that completely 180's the robustness of it. The way this works, the token could even be shared as one shared secret/configmap in OKD, and then we can mount the same secret across multiple Deployments, so it can be rotated once in all the places.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh, I didn't consider that it could be shared as a secret/configmap in OKD. Good enough, I guess.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In what application is the /gatekeep endpoint used? I feel like that could also dictate if an account or token makes more sense

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Vote

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Token feels fine then tbh

if token != app.config["VOTE_TOKEN"]:
return "Users cannot access this page", 403

if datetime.today() < datetime(start_of_year().year, 12, 31):
semester = "Fall"
semester_start = datetime(start_of_year().year,6,1)
else:
semester = "Spring"
semester_start = datetime(start_of_year().year + 1,1,1)

# groups
ldap_member = ldap_get_member(username)
is_intro_member = ldap_is_intromember(ldap_member)
is_active_member = ldap_is_active(ldap_member) and not is_intro_member

is_on_coop = (
CurrentCoops.query.filter(
CurrentCoops.date_created > start_of_year(),
CurrentCoops.semester == semester,
CurrentCoops.uid == username,
).first()
is not None
)

passed_fall = (
FreshmanEvalData.query.filter(
FreshmanEvalData.freshman_eval_result == "Passed",
FreshmanEvalData.eval_date > start_of_year(),
FreshmanEvalData.uid == username,
).first()
is not None
)
eligibility_of_groups = (is_active_member and not is_on_coop) or passed_fall

# number of directorship meetings attended in the current semester
d_meetings = (
MemberCommitteeAttendance.query.join(
CommitteeMeeting,
MemberCommitteeAttendance.meeting_id == CommitteeMeeting.id,
)
.filter(
MemberCommitteeAttendance.uid == username,
CommitteeMeeting.approved is True,
CommitteeMeeting.date >= semester_start,
)
.count()
)
# number of technical seminars attended in the current semester
t_seminars = (
MemberSeminarAttendance.query.join(
TechnicalSeminar,
MemberSeminarAttendance.meeting_id == TechnicalSeminar.id,
)
.filter(
MemberSeminarAttendance.uid == username,
TechnicalSeminar.approved is True,
TechnicalSeminar.date >= semester_start,
)
.count()
)
# number of house meetings attended in the current semester
h_meetings = (
MemberHouseMeetingAttendance.query.join(
HouseMeeting,
MemberHouseMeetingAttendance.meeting_id == HouseMeeting.id,
)
.filter(
MemberHouseMeetingAttendance.uid == username,
HouseMeeting.date >= semester_start
)
.count()
)
result = eligibility_of_groups and (d_meetings >= 6 and t_seminars >= 2 and h_meetings >= 6)

return {
"result": result,
"h_meetings": h_meetings,
"c_meetings": d_meetings,
"t_seminars": t_seminars,
}, 200




@app.errorhandler(404)
@app.errorhandler(500)
@auth.oidc_auth("default")
Expand Down
22 changes: 16 additions & 6 deletions conditional/templates/dashboard.html
Original file line number Diff line number Diff line change
Expand Up @@ -15,12 +15,22 @@ <h3 class="username">{{ get_member_name(username) }}</h3>
<h5 class="email">{{username}}@csh.rit.edu</h5>
<div class="profile-badges">
{% if active %}
<span class="label label-success">Active</span> {% else %}
<span class="label label-danger">Inactive</span> {% endif %} {% if onfloor %}
<span class="label label-primary">On-floor Status</span> {% else %}
<span class="label label-default">Off-floor Status</span> {% endif %} {% if voting %}
<span class="label label-primary">Voting</span> {% else %}
<span class="label label-default">Non-Voting</span> {% endif %}
<span class="label label-success">Active</span>
{% else %}
<span class="label label-danger">Inactive</span>
{% endif %}

{% if onfloor %}
<span class="label label-primary">On-floor Status</span>
{% else %}
<span class="label label-default">Off-floor Status</span>
{% endif %}

{% if voting %}
<span class="label label-primary">Voting</span>
{% else %}
<span class="label label-default">Non-Voting</span>
{% endif %}
</div>
</div>
</div>
Expand Down
9 changes: 4 additions & 5 deletions conditional/util/member.py
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
from datetime import datetime

from conditional import start_of_year
from conditional import gatekeep_status, start_of_year
from conditional.models.models import CommitteeMeeting
from conditional.models.models import CurrentCoops
from conditional.models.models import FreshmanEvalData
Expand Down Expand Up @@ -32,18 +32,17 @@ def get_voting_members():
on_coop = set(member.uid for member in CurrentCoops.query.filter(
CurrentCoops.date_created > start_of_year(),
CurrentCoops.semester == semester).all())

voting_list = list(active_members - intro_members - on_coop)
voting_set = active_members - intro_members - on_coop

passed_fall = FreshmanEvalData.query.filter(
FreshmanEvalData.freshman_eval_result == "Passed",
FreshmanEvalData.eval_date > start_of_year()
).distinct()

for intro_member in passed_fall:
if intro_member.uid not in voting_list:
voting_list.append(intro_member.uid)
voting_set.add(intro_member.uid)

voting_list = list(username for username in voting_set if gatekeep_status(username))
return voting_list


Expand Down
3 changes: 3 additions & 0 deletions config.env.py
Original file line number Diff line number Diff line change
Expand Up @@ -52,3 +52,6 @@

# General config
DUES_PER_SEMESTER = env.get("CONDITIONAL_DUES_PER_SEMESTER", 80)

# Vote config
VOTE_TOKEN = env.get("CONDITIONAL_VOTE_TOKEN", "")