diff options
| author | omnom62 <omnom62@outlook.com> | 2026-10-03 16:31:19 +1000 |
|---|---|---|
| committer | omnom62 <omnom62@outlook.com> | 2026-10-03 16:31:19 +1000 |
| commit | 6e9fe2c879895ade7c66b4ee199b0bac36f2b2e6 (patch) | |
| tree | bbffa663eb39c0ab953c4e94d47756482984b5c8 /plugins/httpapi/vyos.py | |
| parent | deab3ca9931020030d15ad48faba6e26629530e0 (diff) | |
| download | rest.vyos-6e9fe2c879895ade7c66b4ee199b0bac36f2b2e6.tar.gz rest.vyos-6e9fe2c879895ade7c66b4ee199b0bac36f2b2e6.zip | |
https: T8989: auth_methods AI comments and conflicts fixed
Diffstat (limited to 'plugins/httpapi/vyos.py')
| -rw-r--r-- | plugins/httpapi/vyos.py | 75 |
1 files changed, 47 insertions, 28 deletions
diff --git a/plugins/httpapi/vyos.py b/plugins/httpapi/vyos.py index c60fbb9..30088f3 100644 --- a/plugins/httpapi/vyos.py +++ b/plugins/httpapi/vyos.py @@ -1,18 +1,13 @@ -import json -import os -import time - -from urllib.parse import urlencode -from urllib.request import Request, urlopen +# -*- coding: utf-8 -*- +# GNU General Public License v3.0+ (see COPYING or https://www.gnu.org/licenses/gpl-3.0.txt) +from __future__ import absolute_import, division, print_function -from ansible.errors import AnsibleConnectionFailure -from ansible.module_utils.connection import ConnectionError -from ansible.plugins.httpapi import HttpApiBase +__metaclass__ = type DOCUMENTATION = r""" --- -httpapi: vyos +name: vyos short_description: VyOS REST API description: - HTTPAPI plugin for interacting with VyOS REST API. @@ -72,6 +67,17 @@ options: key: oidc_client_secret """ +import json +import os +import time + +from urllib.parse import urlencode + +from ansible.errors import AnsibleConnectionFailure +from ansible.module_utils.connection import ConnectionError +from ansible.module_utils.urls import open_url +from ansible.plugins.httpapi import HttpApiBase + class HttpApi(HttpApiBase): @@ -88,12 +94,12 @@ class HttpApi(HttpApiBase): self._oidc_token = None self._oidc_token_expiry = 0 - def handle_httperror(self, exception): - if getattr(exception, "code", None) == 401: + def handle_httperror(self, exc): + if getattr(exc, "code", None) == 401: raise AnsibleConnectionFailure( - "Authentication to the VyOS REST API failed: {0}".format(exception), + "Authentication to the VyOS REST API failed: {0}".format(exc), ) - return exception + return exc # ----------------------------------------------------------------- # API key resolution -- shared by the key, header, and bearer @@ -140,9 +146,9 @@ class HttpApi(HttpApiBase): response = self._parse_response(raw_response) if not response.get("success"): raise ConnectionError(response.get("error") or "VyOS token request failed") - data = response.get("data") or {} - token = data.get("token") - expires_in = data.get("expires_in", 3600) + token_data = response.get("data") or {} + token = token_data.get("token") + expires_in = token_data.get("expires_in", 3600) self._bearer_token = token self._bearer_token_expiry = time.time() + expires_in return token @@ -155,7 +161,10 @@ class HttpApi(HttpApiBase): # ----------------------------------------------------------------- # OIDC token: fetched from an external IdP via the # client_credentials grant, cached the same way as the bearer - # token. + # token. Uses ansible.module_utils.urls.open_url rather than + # urllib.request.urlopen directly, per Ansible's own sanity + # requirement (open_url adds proxy support and consistent TLS + # validation across the whole ecosystem). # ----------------------------------------------------------------- def _fetch_oidc_token(self): @@ -170,15 +179,15 @@ class HttpApi(HttpApiBase): "client_id": self.get_option("oidc_client_id"), "client_secret": self.get_option("oidc_client_secret"), }, - ).encode("utf-8") - request = Request( - token_url, - data=body, - headers={"Content-Type": "application/x-www-form-urlencoded"}, ) try: - with urlopen(request) as resp: - payload = json.loads(resp.read()) + response = open_url( + token_url, + data=body, + headers={"Content-Type": "application/x-www-form-urlencoded"}, + method="POST", + ) + payload = json.loads(response.read()) except Exception as exc: raise ConnectionError("OIDC token fetch failed: {0}".format(exc)) @@ -202,14 +211,24 @@ class HttpApi(HttpApiBase): # material attached to the request (body field vs. header, and # which header) differs by method; the request/response envelope # itself is identical. + # + # The first parameter is named "data" (not e.g. "url_path") to + # match HttpApiBase.send_request's own signature -- pylint's + # arguments-renamed check flags an override that renames a base- + # class parameter, since that silently breaks any caller using the + # keyword form. It still carries a URL path string in this + # plugin's own usage; the **op_kwargs that follow are this + # resource's own operation details (op, path, value, ...), kept + # separate so they don't collide with the "data" name. # ----------------------------------------------------------------- - def send_request(self, url_path, **data): + def send_request(self, data, **op_kwargs): + url_path = data auth_method = self.get_option("auth_method") or "key" form_data = {} - if data: - form_data["data"] = json.dumps(data) + if op_kwargs: + form_data["data"] = json.dumps(op_kwargs) headers = {"Content-Type": "application/x-www-form-urlencoded"} |
