view libervia/backend/plugins/plugin_tmp_directory_subscription.py @ 4212:5f2d496c633f

core: get rid of `pickle`: Use of `pickle` to serialise data was a technical legacy that was causing trouble to store in database, to update (if a class was serialised, a change could break update), and to security (pickle can lead to code execution). This patch remove all use of Pickle in favour in JSON, notably: - for caching data, a Pydantic model is now used instead - for SQLAlchemy model, the LegacyPickle is replaced by JSON serialisation - in XEP-0373 a class `PublicKeyMetadata` was serialised. New method `from_dict` and `to_dict` method have been implemented to do serialisation. - new methods to (de)serialise data can now be specified with Identity data types. It is notably used to (de)serialise `path` of avatars. A migration script has been created to convert data (for upgrade or downgrade), with special care for XEP-0373 case. Depending of size of database, this migration script can be long to run. rel 443
author Goffi <goffi@goffi.org>
date Fri, 23 Feb 2024 13:31:04 +0100
parents 4b842c1fb686
children
line wrap: on
line source

#!/usr/bin/env python3


# SAT plugin for directory subscription
# Copyright (C) 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016 Jérôme Poisson (goffi@goffi.org)
# Copyright (C) 2015, 2016 Adrien Cossa (souliane@mailoo.org)

# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as published by
# the Free Software Foundation, either version 3 of the License, or
# (at your option) any later version.

# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU Affero General Public License for more details.

# You should have received a copy of the GNU Affero General Public License
# along with this program.  If not, see <http://www.gnu.org/licenses/>.

from libervia.backend.core.i18n import _, D_
from libervia.backend.core.constants import Const as C
from libervia.backend.core.log import getLogger

log = getLogger(__name__)


PLUGIN_INFO = {
    C.PI_NAME: "Directory subscription plugin",
    C.PI_IMPORT_NAME: "DIRECTORY-SUBSCRIPTION",
    C.PI_TYPE: "TMP",
    C.PI_PROTOCOLS: [],
    C.PI_DEPENDENCIES: ["XEP-0050", "XEP-0055"],
    C.PI_RECOMMENDATIONS: [],
    C.PI_MAIN: "DirectorySubscription",
    C.PI_HANDLER: "no",
    C.PI_DESCRIPTION: _("""Implementation of directory subscription"""),
}


NS_COMMANDS = "http://jabber.org/protocol/commands"
CMD_UPDATE_SUBSCRIBTION = "update"


class DirectorySubscription(object):
    def __init__(self, host):
        log.info(_("Directory subscription plugin initialization"))
        self.host = host
        host.import_menu(
            (D_("Service"), D_("Directory subscription")),
            self.subscribe,
            security_limit=1,
            help_string=D_("User directory subscription"),
        )

    def subscribe(self, raw_data, profile):
        """Request available commands on the jabber search service associated to profile's host.

        @param raw_data (dict): data received from the frontend
        @param profile (unicode): %(doc_profile)s
        @return: a deferred dict{unicode: unicode}
        """
        d = self.host.plugins["XEP-0055"]._get_host_services(profile)

        def got_services(services):
            service_jid = services[0]
            session_id, session_data = self.host.plugins[
                "XEP-0050"
            ].requesting.new_session(profile=profile)
            session_data["jid"] = service_jid
            session_data["node"] = CMD_UPDATE_SUBSCRIBTION
            data = {"session_id": session_id}
            return self.host.plugins["XEP-0050"]._requesting_entity(data, profile)

        return d.addCallback(got_services)