account.py 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310
  1. import datetime
  2. import pytz
  3. from flask import request
  4. from flask_login import current_user # type: ignore
  5. from flask_restful import Resource, fields, marshal_with, reqparse # type: ignore
  6. from configs import dify_config
  7. from constants.languages import supported_language
  8. from controllers.console import api
  9. from controllers.console.workspace.error import (
  10. AccountAlreadyInitedError,
  11. CurrentPasswordIncorrectError,
  12. InvalidAccountDeletionCodeError,
  13. InvalidInvitationCodeError,
  14. RepeatPasswordNotMatchError,
  15. )
  16. from controllers.console.wraps import account_initialization_required, enterprise_license_required, setup_required
  17. from extensions.ext_database import db
  18. from fields.member_fields import account_fields
  19. from libs.helper import TimestampField, timezone
  20. from libs.login import login_required
  21. from models import AccountIntegrate, InvitationCode
  22. from services.account_service import AccountService
  23. from services.billing_service import BillingService
  24. from services.errors.account import CurrentPasswordIncorrectError as ServiceCurrentPasswordIncorrectError
  25. class AccountInitApi(Resource):
  26. @setup_required
  27. @login_required
  28. def post(self):
  29. account = current_user
  30. if account.status == "active":
  31. raise AccountAlreadyInitedError()
  32. parser = reqparse.RequestParser()
  33. if dify_config.EDITION == "CLOUD":
  34. parser.add_argument("invitation_code", type=str, location="json")
  35. parser.add_argument("interface_language", type=supported_language, required=True, location="json")
  36. parser.add_argument("timezone", type=timezone, required=True, location="json")
  37. args = parser.parse_args()
  38. if dify_config.EDITION == "CLOUD":
  39. if not args["invitation_code"]:
  40. raise ValueError("invitation_code is required")
  41. # check invitation code
  42. invitation_code = (
  43. db.session.query(InvitationCode)
  44. .filter(
  45. InvitationCode.code == args["invitation_code"],
  46. InvitationCode.status == "unused",
  47. )
  48. .first()
  49. )
  50. if not invitation_code:
  51. raise InvalidInvitationCodeError()
  52. invitation_code.status = "used"
  53. invitation_code.used_at = datetime.datetime.now(datetime.UTC).replace(tzinfo=None)
  54. invitation_code.used_by_tenant_id = account.current_tenant_id
  55. invitation_code.used_by_account_id = account.id
  56. account.interface_language = args["interface_language"]
  57. account.timezone = args["timezone"]
  58. account.interface_theme = "light"
  59. account.status = "active"
  60. account.initialized_at = datetime.datetime.now(datetime.UTC).replace(tzinfo=None)
  61. db.session.commit()
  62. return {"result": "success"}
  63. class AccountProfileApi(Resource):
  64. @setup_required
  65. @login_required
  66. @account_initialization_required
  67. @marshal_with(account_fields)
  68. @enterprise_license_required
  69. def get(self):
  70. return current_user
  71. class AccountNameApi(Resource):
  72. @setup_required
  73. @login_required
  74. @account_initialization_required
  75. @marshal_with(account_fields)
  76. def post(self):
  77. parser = reqparse.RequestParser()
  78. parser.add_argument("name", type=str, required=True, location="json")
  79. args = parser.parse_args()
  80. # Validate account name length
  81. if len(args["name"]) < 3 or len(args["name"]) > 30:
  82. raise ValueError("Account name must be between 3 and 30 characters.")
  83. updated_account = AccountService.update_account(current_user, name=args["name"])
  84. return updated_account
  85. class AccountAvatarApi(Resource):
  86. @setup_required
  87. @login_required
  88. @account_initialization_required
  89. @marshal_with(account_fields)
  90. def post(self):
  91. parser = reqparse.RequestParser()
  92. parser.add_argument("avatar", type=str, required=True, location="json")
  93. args = parser.parse_args()
  94. updated_account = AccountService.update_account(current_user, avatar=args["avatar"])
  95. return updated_account
  96. class AccountInterfaceLanguageApi(Resource):
  97. @setup_required
  98. @login_required
  99. @account_initialization_required
  100. @marshal_with(account_fields)
  101. def post(self):
  102. parser = reqparse.RequestParser()
  103. parser.add_argument("interface_language", type=supported_language, required=True, location="json")
  104. args = parser.parse_args()
  105. updated_account = AccountService.update_account(current_user, interface_language=args["interface_language"])
  106. return updated_account
  107. class AccountInterfaceThemeApi(Resource):
  108. @setup_required
  109. @login_required
  110. @account_initialization_required
  111. @marshal_with(account_fields)
  112. def post(self):
  113. parser = reqparse.RequestParser()
  114. parser.add_argument("interface_theme", type=str, choices=["light", "dark"], required=True, location="json")
  115. args = parser.parse_args()
  116. updated_account = AccountService.update_account(current_user, interface_theme=args["interface_theme"])
  117. return updated_account
  118. class AccountTimezoneApi(Resource):
  119. @setup_required
  120. @login_required
  121. @account_initialization_required
  122. @marshal_with(account_fields)
  123. def post(self):
  124. parser = reqparse.RequestParser()
  125. parser.add_argument("timezone", type=str, required=True, location="json")
  126. args = parser.parse_args()
  127. # Validate timezone string, e.g. America/New_York, Asia/Shanghai
  128. if args["timezone"] not in pytz.all_timezones:
  129. raise ValueError("Invalid timezone string.")
  130. updated_account = AccountService.update_account(current_user, timezone=args["timezone"])
  131. return updated_account
  132. class AccountPasswordApi(Resource):
  133. @setup_required
  134. @login_required
  135. @account_initialization_required
  136. @marshal_with(account_fields)
  137. def post(self):
  138. parser = reqparse.RequestParser()
  139. parser.add_argument("password", type=str, required=False, location="json")
  140. parser.add_argument("new_password", type=str, required=True, location="json")
  141. parser.add_argument("repeat_new_password", type=str, required=True, location="json")
  142. args = parser.parse_args()
  143. if args["new_password"] != args["repeat_new_password"]:
  144. raise RepeatPasswordNotMatchError()
  145. try:
  146. AccountService.update_account_password(current_user, args["password"], args["new_password"])
  147. except ServiceCurrentPasswordIncorrectError:
  148. raise CurrentPasswordIncorrectError()
  149. return {"result": "success"}
  150. class AccountIntegrateApi(Resource):
  151. integrate_fields = {
  152. "provider": fields.String,
  153. "created_at": TimestampField,
  154. "is_bound": fields.Boolean,
  155. "link": fields.String,
  156. }
  157. integrate_list_fields = {
  158. "data": fields.List(fields.Nested(integrate_fields)),
  159. }
  160. @setup_required
  161. @login_required
  162. @account_initialization_required
  163. @marshal_with(integrate_list_fields)
  164. def get(self):
  165. account = current_user
  166. account_integrates = db.session.query(AccountIntegrate).filter(AccountIntegrate.account_id == account.id).all()
  167. base_url = request.url_root.rstrip("/")
  168. oauth_base_path = "/console/api/oauth/login"
  169. providers = ["github", "google"]
  170. integrate_data = []
  171. for provider in providers:
  172. existing_integrate = next((ai for ai in account_integrates if ai.provider == provider), None)
  173. if existing_integrate:
  174. integrate_data.append(
  175. {
  176. "id": existing_integrate.id,
  177. "provider": provider,
  178. "created_at": existing_integrate.created_at,
  179. "is_bound": True,
  180. "link": None,
  181. }
  182. )
  183. else:
  184. integrate_data.append(
  185. {
  186. "id": None,
  187. "provider": provider,
  188. "created_at": None,
  189. "is_bound": False,
  190. "link": f"{base_url}{oauth_base_path}/{provider}",
  191. }
  192. )
  193. return {"data": integrate_data}
  194. class AccountDeleteVerifyApi(Resource):
  195. @setup_required
  196. @login_required
  197. @account_initialization_required
  198. def get(self):
  199. account = current_user
  200. token, code = AccountService.generate_account_deletion_verification_code(account)
  201. AccountService.send_account_deletion_verification_email(account, code)
  202. return {"result": "success", "data": token}
  203. class AccountDeleteApi(Resource):
  204. @setup_required
  205. @login_required
  206. @account_initialization_required
  207. def post(self):
  208. account = current_user
  209. parser = reqparse.RequestParser()
  210. parser.add_argument("token", type=str, required=True, location="json")
  211. parser.add_argument("code", type=str, required=True, location="json")
  212. args = parser.parse_args()
  213. if not AccountService.verify_account_deletion_code(args["token"], args["code"]):
  214. raise InvalidAccountDeletionCodeError()
  215. AccountService.delete_account(account)
  216. return {"result": "success"}
  217. class AccountDeleteUpdateFeedbackApi(Resource):
  218. @setup_required
  219. def post(self):
  220. account = current_user
  221. parser = reqparse.RequestParser()
  222. parser.add_argument("email", type=str, required=True, location="json")
  223. parser.add_argument("feedback", type=str, required=True, location="json")
  224. args = parser.parse_args()
  225. BillingService.update_account_deletion_feedback(args["email"], args["feedback"])
  226. return {"result": "success"}
  227. # Register API resources
  228. api.add_resource(AccountInitApi, "/account/init")
  229. api.add_resource(AccountProfileApi, "/account/profile")
  230. api.add_resource(AccountNameApi, "/account/name")
  231. api.add_resource(AccountAvatarApi, "/account/avatar")
  232. api.add_resource(AccountInterfaceLanguageApi, "/account/interface-language")
  233. api.add_resource(AccountInterfaceThemeApi, "/account/interface-theme")
  234. api.add_resource(AccountTimezoneApi, "/account/timezone")
  235. api.add_resource(AccountPasswordApi, "/account/password")
  236. api.add_resource(AccountIntegrateApi, "/account/integrates")
  237. api.add_resource(AccountDeleteVerifyApi, "/account/delete/verify")
  238. api.add_resource(AccountDeleteApi, "/account/delete")
  239. api.add_resource(AccountDeleteUpdateFeedbackApi, "/account/delete/feedback")
  240. # api.add_resource(AccountEmailApi, '/account/email')
  241. # api.add_resource(AccountEmailVerifyApi, '/account/email-verify')