Loading services/TS29222_CAPIF_Access_Control_Policy_API/capif_acl/core/internal_service_ops.py +11 −4 Changes for services/TS29222_CAPIF_Access_Control_Policy_API/capif_acl/core/internal_service_ops.py: 11 added lines, 4 removed lines. Original line number Diff line number Diff line Loading @@ -126,10 +126,17 @@ class InternalServiceOps(Resource): current_app.logger.debug(f"Removing ACLs for invoker: {invoker_id}") mycol = self.db.get_col_by_name(self.db.acls) mycol.update_many({"api_invoker_policies.api_invoker_id": invoker_id}, {"$pull": {"api_invoker_policies": { "api_invoker_id": invoker_id}}} ) acls = mycol.find({"api_invoker_policies.api_invoker_id": invoker_id}, {"_id": 0}) for acl in acls: new_api_invoker_policies = [policy for policy in acl["api_invoker_policies"] if policy["api_invoker_id"] != invoker_id] acl["api_invoker_policies"] = new_api_invoker_policies if not acl["api_invoker_policies"]: mycol.delete_one({'service_id': acl["service_id"], 'aef_id': acl["aef_id"]}) else: mycol.update_one({'service_id': acl["service_id"], 'aef_id': acl["aef_id"]}, { "$set": acl}) RedisEvent("ACCESS_CONTROL_POLICY_UNAVAILABLE").send_event() current_app.logger.info(f"ACLs for invoker: {invoker_id} removed") Loading services/TS29222_CAPIF_Publish_Service_API/published_apis/app.py +0 −2 Changes for services/TS29222_CAPIF_Publish_Service_API/published_apis/app.py: 0 added lines, 2 removed lines. Original line number Diff line number Diff line Loading @@ -102,7 +102,6 @@ def configure_logging(app): handlers.append(console_handler) handlers.append(file_handler) for l in loggers: for handler in handlers: l.addHandler(handler) Loading Loading @@ -144,4 +143,3 @@ scheduler.start() def up_listener(): with scheduler.app.app_context(): executor.submit(subscriber.listen()) services/TS29222_CAPIF_Security_API/capif_security/core/internal_security_ops.py +3 −0 Changes for services/TS29222_CAPIF_Security_API/capif_security/core/internal_security_ops.py: 3 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -21,5 +21,8 @@ class InternalSecurityOps(Resource): new_security_info = [info for info in security_context["security_info"] if info["aef_id"] != id and info["api_id"] != id] security_context["security_info"] = new_security_info if not security_context["security_info"]: security_col.delete_one({'api_invoker_id': security_context["api_invoker_id"]}) else: security_col.update_one({'api_invoker_id': security_context["api_invoker_id"]}, { "$set": security_context}) services/TS29222_CAPIF_Security_API/capif_security/core/servicesecurity.py +14 −9 Changes for services/TS29222_CAPIF_Security_API/capif_security/core/servicesecurity.py: 14 added lines, 9 removed lines. Original line number Diff line number Diff line Loading @@ -582,21 +582,22 @@ class SecurityOperations(Resource): current_app.logger.debug("Removing security context") invoker = self.__retrieve_invoker_from_db(api_invoker_id) success = True response = None if invoker is None: current_app.logger.warning("Invoker not found Locally") ccf_id = self.get_remote_invoker_ccf(api_invoker_id) if ccf_id: current_app.logger.info(f"Invoker found in remote CCF: {ccf_id}") return self.delete_service_security_to_other_ccf(api_invoker_id, ccf_id) success, response = self.delete_service_security_to_other_ccf(api_invoker_id, ccf_id) else: current_app.logger.warning("Invoker not found in any remote CCFs") return not_found_error(detail="Invoker not found", cause="API Invoker not exists or invalid ID") success = False response = not_found_error(detail="Invoker not found", cause="API Invoker not exists or invalid ID") if not success: return response # Local Invoker result = self.__check_invoker(api_invoker_id) if result != None: return result else: my_query = {'api_invoker_id': api_invoker_id} services_security_count = mycol.count_documents(my_query) Loading Loading @@ -697,6 +698,8 @@ class SecurityOperations(Resource): current_app.logger.debug("Updating security context") result = self.__check_invoker(api_invoker_id) if result != None: # Update only can be performed by invoker itself, then there is no reason to check if # invoker is present in other CCF. return result old_object = mycol.find_one({"api_invoker_id": api_invoker_id}) Loading Loading @@ -884,6 +887,8 @@ class SecurityOperations(Resource): try: current_app.logger.debug("Revoking security context") result = self.__check_invoker(api_invoker_id) if result != None: return result Loading Loading @@ -1101,14 +1106,14 @@ class SecurityOperations(Resource): except requests.exceptions.RequestException as exc: current_app.logger.exception( "Interconnection: Delete Security Information on {} failed: {}".format(url, str(exc))) return internal_server_error( return False, internal_server_error( detail="Could not reach interconnected CCF {}".format(url), cause=str(exc)) if response.status_code != 204: current_app.logger.error( "Interconnection: {} answered the Delete Security Information request with status {} and body: {}".format( url, response.status_code, response.text)) return internal_server_error( return False, internal_server_error( detail="Interconnected CCF {} did not delete its Security Information correctly".format(url), cause="Response status code: {} with body: {}".format(response.status_code, response.text)) Loading services/helper/helper_service/app.py +43 −2 Changes for services/helper/helper_service/app.py: 43 added lines, 2 removed lines. Original line number Diff line number Diff line Loading @@ -3,6 +3,7 @@ import logging import os import sys from pathlib import Path from logging.handlers import RotatingFileHandler import connexion import requests Loading Loading @@ -35,12 +36,52 @@ db = get_mongo() capif_config = db.get_col_by_name("capif_configuration").find_one({}) ttl_superadmin_cert = capif_config["settings"]["certificates_expiry"].get("ttl_superadmin_cert", "43000h") # Setting log level def verbose_formatter(): return logging.Formatter( '{"timestamp": "%(asctime)s", "level": "%(levelname)s", "logger": "%(name)s", "function": "%(funcName)s", "line": %(lineno)d, "message": %(message)s}', datefmt='%d/%m/%Y %H:%M:%S' ) def configure_logging(app): # Get root Logger root_logger = logging.getLogger() # Clear existing handlers del app.logger.handlers[:] del root_logger.handlers[:] # Configure both loggers = [root_logger, app.logger] handlers = [] console_handler = logging.StreamHandler() console_handler.setLevel(numeric_level) console_handler.setFormatter(verbose_formatter()) file_handler = RotatingFileHandler(filename="publish_logs.log", maxBytes=1024 * 1024 * 100, backupCount=20) file_handler.setLevel(numeric_level) file_handler.setFormatter(verbose_formatter()) handlers.append(console_handler) handlers.append(file_handler) for l in loggers: for handler in handlers: l.addHandler(handler) l.propagate = False l.setLevel(numeric_level) # Log level setup log_level = os.getenv('LOG_LEVEL', 'INFO').upper() numeric_level = getattr(logging, log_level, logging.INFO) logging.basicConfig(level=numeric_level) configure_logging(app.app) # Logger for this module logger = logging.getLogger(__name__) # Create a superadmin CSR and keys key = rsa.generate_private_key(public_exponent=65537, key_size=2048) subject = x509.Name([ Loading Loading
services/TS29222_CAPIF_Access_Control_Policy_API/capif_acl/core/internal_service_ops.py +11 −4 Changes for services/TS29222_CAPIF_Access_Control_Policy_API/capif_acl/core/internal_service_ops.py: 11 added lines, 4 removed lines. Original line number Diff line number Diff line Loading @@ -126,10 +126,17 @@ class InternalServiceOps(Resource): current_app.logger.debug(f"Removing ACLs for invoker: {invoker_id}") mycol = self.db.get_col_by_name(self.db.acls) mycol.update_many({"api_invoker_policies.api_invoker_id": invoker_id}, {"$pull": {"api_invoker_policies": { "api_invoker_id": invoker_id}}} ) acls = mycol.find({"api_invoker_policies.api_invoker_id": invoker_id}, {"_id": 0}) for acl in acls: new_api_invoker_policies = [policy for policy in acl["api_invoker_policies"] if policy["api_invoker_id"] != invoker_id] acl["api_invoker_policies"] = new_api_invoker_policies if not acl["api_invoker_policies"]: mycol.delete_one({'service_id': acl["service_id"], 'aef_id': acl["aef_id"]}) else: mycol.update_one({'service_id': acl["service_id"], 'aef_id': acl["aef_id"]}, { "$set": acl}) RedisEvent("ACCESS_CONTROL_POLICY_UNAVAILABLE").send_event() current_app.logger.info(f"ACLs for invoker: {invoker_id} removed") Loading
services/TS29222_CAPIF_Publish_Service_API/published_apis/app.py +0 −2 Changes for services/TS29222_CAPIF_Publish_Service_API/published_apis/app.py: 0 added lines, 2 removed lines. Original line number Diff line number Diff line Loading @@ -102,7 +102,6 @@ def configure_logging(app): handlers.append(console_handler) handlers.append(file_handler) for l in loggers: for handler in handlers: l.addHandler(handler) Loading Loading @@ -144,4 +143,3 @@ scheduler.start() def up_listener(): with scheduler.app.app_context(): executor.submit(subscriber.listen())
services/TS29222_CAPIF_Security_API/capif_security/core/internal_security_ops.py +3 −0 Changes for services/TS29222_CAPIF_Security_API/capif_security/core/internal_security_ops.py: 3 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -21,5 +21,8 @@ class InternalSecurityOps(Resource): new_security_info = [info for info in security_context["security_info"] if info["aef_id"] != id and info["api_id"] != id] security_context["security_info"] = new_security_info if not security_context["security_info"]: security_col.delete_one({'api_invoker_id': security_context["api_invoker_id"]}) else: security_col.update_one({'api_invoker_id': security_context["api_invoker_id"]}, { "$set": security_context})
services/TS29222_CAPIF_Security_API/capif_security/core/servicesecurity.py +14 −9 Changes for services/TS29222_CAPIF_Security_API/capif_security/core/servicesecurity.py: 14 added lines, 9 removed lines. Original line number Diff line number Diff line Loading @@ -582,21 +582,22 @@ class SecurityOperations(Resource): current_app.logger.debug("Removing security context") invoker = self.__retrieve_invoker_from_db(api_invoker_id) success = True response = None if invoker is None: current_app.logger.warning("Invoker not found Locally") ccf_id = self.get_remote_invoker_ccf(api_invoker_id) if ccf_id: current_app.logger.info(f"Invoker found in remote CCF: {ccf_id}") return self.delete_service_security_to_other_ccf(api_invoker_id, ccf_id) success, response = self.delete_service_security_to_other_ccf(api_invoker_id, ccf_id) else: current_app.logger.warning("Invoker not found in any remote CCFs") return not_found_error(detail="Invoker not found", cause="API Invoker not exists or invalid ID") success = False response = not_found_error(detail="Invoker not found", cause="API Invoker not exists or invalid ID") if not success: return response # Local Invoker result = self.__check_invoker(api_invoker_id) if result != None: return result else: my_query = {'api_invoker_id': api_invoker_id} services_security_count = mycol.count_documents(my_query) Loading Loading @@ -697,6 +698,8 @@ class SecurityOperations(Resource): current_app.logger.debug("Updating security context") result = self.__check_invoker(api_invoker_id) if result != None: # Update only can be performed by invoker itself, then there is no reason to check if # invoker is present in other CCF. return result old_object = mycol.find_one({"api_invoker_id": api_invoker_id}) Loading Loading @@ -884,6 +887,8 @@ class SecurityOperations(Resource): try: current_app.logger.debug("Revoking security context") result = self.__check_invoker(api_invoker_id) if result != None: return result Loading Loading @@ -1101,14 +1106,14 @@ class SecurityOperations(Resource): except requests.exceptions.RequestException as exc: current_app.logger.exception( "Interconnection: Delete Security Information on {} failed: {}".format(url, str(exc))) return internal_server_error( return False, internal_server_error( detail="Could not reach interconnected CCF {}".format(url), cause=str(exc)) if response.status_code != 204: current_app.logger.error( "Interconnection: {} answered the Delete Security Information request with status {} and body: {}".format( url, response.status_code, response.text)) return internal_server_error( return False, internal_server_error( detail="Interconnected CCF {} did not delete its Security Information correctly".format(url), cause="Response status code: {} with body: {}".format(response.status_code, response.text)) Loading
services/helper/helper_service/app.py +43 −2 Changes for services/helper/helper_service/app.py: 43 added lines, 2 removed lines. Original line number Diff line number Diff line Loading @@ -3,6 +3,7 @@ import logging import os import sys from pathlib import Path from logging.handlers import RotatingFileHandler import connexion import requests Loading Loading @@ -35,12 +36,52 @@ db = get_mongo() capif_config = db.get_col_by_name("capif_configuration").find_one({}) ttl_superadmin_cert = capif_config["settings"]["certificates_expiry"].get("ttl_superadmin_cert", "43000h") # Setting log level def verbose_formatter(): return logging.Formatter( '{"timestamp": "%(asctime)s", "level": "%(levelname)s", "logger": "%(name)s", "function": "%(funcName)s", "line": %(lineno)d, "message": %(message)s}', datefmt='%d/%m/%Y %H:%M:%S' ) def configure_logging(app): # Get root Logger root_logger = logging.getLogger() # Clear existing handlers del app.logger.handlers[:] del root_logger.handlers[:] # Configure both loggers = [root_logger, app.logger] handlers = [] console_handler = logging.StreamHandler() console_handler.setLevel(numeric_level) console_handler.setFormatter(verbose_formatter()) file_handler = RotatingFileHandler(filename="publish_logs.log", maxBytes=1024 * 1024 * 100, backupCount=20) file_handler.setLevel(numeric_level) file_handler.setFormatter(verbose_formatter()) handlers.append(console_handler) handlers.append(file_handler) for l in loggers: for handler in handlers: l.addHandler(handler) l.propagate = False l.setLevel(numeric_level) # Log level setup log_level = os.getenv('LOG_LEVEL', 'INFO').upper() numeric_level = getattr(logging, log_level, logging.INFO) logging.basicConfig(level=numeric_level) configure_logging(app.app) # Logger for this module logger = logging.getLogger(__name__) # Create a superadmin CSR and keys key = rsa.generate_private_key(public_exponent=65537, key_size=2048) subject = x509.Name([ Loading