Files
doczyai-pipelines/streamlit/security.py
T

90 lines
2.5 KiB
Python
Raw Normal View History

2024-03-08 17:36:36 +05:30
import streamlit as st
import msal
import requests
import boto3
from botocore.exceptions import ClientError
2024-04-18 15:33:13 -05:00
import json
2024-03-08 17:36:36 +05:30
# Replace with your own values
CLIENT_ID = 'effafe90-7ed7-43a3-ab03-19a0be2f1758'
# CLIENT_SECRET = 'bjQ8Q~lpR2uBcGI34VDu16t73doz8Crj0YY_~dgD'
2024-03-08 17:36:36 +05:30
# TENANT_ID = ''
AUTHORITY = 'https://login.microsoftonline.com/organizations/'
SCOPE = ['User.Read']
2024-05-22 16:50:47 -05:00
REDIRECT_URI = 'https://172.29.20.102:8501'
2024-03-08 17:36:36 +05:30
2024-04-18 15:33:13 -05:00
# Initialize boto3 client to interact with AWS Secrets Manager
2024-03-08 17:36:36 +05:30
2024-06-19 12:48:36 -05:00
#URL Masking
def clear_url():
js_code = """
window.history.replaceState({}, document.title, window.location.pathname);
"""
st.components.v1.html(f"<script>{js_code}</script>", height=0, width=0)
def get_secret():
secret_name = "doczy-sso-azure-app-key"
region_name = "us-east-2"
# Create a Secrets Manager client
2024-04-18 15:33:13 -05:00
# session = boto3.session.Session()
# client = session.client(
# service_name='secretsmanager',
# region_name=region_name
# )
client = boto3.client('secretsmanager', region_name=region_name)
try:
get_secret_value_response = client.get_secret_value(
SecretId=secret_name
)
except ClientError as e:
raise e
secret = get_secret_value_response['SecretString']
2024-04-18 15:33:13 -05:00
secret = json.loads(secret)['CLIENT_SECRET']
return secret
CLIENT_SECRET = get_secret()
2024-03-08 17:36:36 +05:30
app = msal.ConfidentialClientApplication(CLIENT_ID, authority=AUTHORITY, client_credential=CLIENT_SECRET)
def get_auth_url(REDIRECT_URI):
auth_url = app.get_authorization_request_url(SCOPE, redirect_uri=REDIRECT_URI)
return auth_url
2024-04-02 22:16:19 +05:30
@st.cache_data
2024-03-08 17:36:36 +05:30
def get_token_from_code(auth_code, REDIRECT_URI):
app = msal.ConfidentialClientApplication(CLIENT_ID, authority=AUTHORITY, client_credential=CLIENT_SECRET)
result = app.acquire_token_by_authorization_code(auth_code, scopes=SCOPE, redirect_uri=REDIRECT_URI)
return result['access_token']
def get_user_info(access_token):
headers = {'Authorization': f'Bearer {access_token}'}
response = requests.get('https://graph.microsoft.com/v1.0/me', headers=headers)
return response.json()
def handle_redirect(REDIRECT_URI):
if not st.session_state.get('access_token'):
code = st.query_params.get('code')
if code:
access_token = get_token_from_code(code, REDIRECT_URI)
st.session_state['access_token'] = access_token
2024-04-22 12:05:56 -05:00
st.session_state
2024-06-19 12:48:36 -05:00
#URL Masking Pt.2
if 'access_token' in st.session_state:
clear_url()
2024-04-22 12:05:56 -05:00