|
| 1 | +"""Connector OAuth routes for external knowledge sources.""" |
| 2 | + |
| 3 | +from __future__ import annotations |
| 4 | + |
| 5 | +import secrets |
| 6 | +import os |
| 7 | +from datetime import datetime, timedelta, timezone |
| 8 | +from typing import Dict, List, Literal, Optional |
| 9 | +from urllib.parse import urlencode |
| 10 | + |
| 11 | +from fastapi import APIRouter, Depends, HTTPException, Query, status |
| 12 | +from pydantic import BaseModel, Field |
| 13 | + |
| 14 | +from src.api.dependencies import require_user |
| 15 | +router = APIRouter(prefix="/api/connectors", tags=["Connectors"]) |
| 16 | + |
| 17 | +ConnectorId = Literal["notion", "google-drive"] |
| 18 | +ConnectorState = Literal["connected", "not_connected", "pending"] |
| 19 | + |
| 20 | +STATE_TTL_MINUTES = 10 |
| 21 | +MAX_PENDING_STATES = 1000 |
| 22 | + |
| 23 | + |
| 24 | +class ConnectorDefinition(BaseModel): |
| 25 | + id: ConnectorId |
| 26 | + name: str |
| 27 | + description: str |
| 28 | + auth_url: str |
| 29 | + token_url: str |
| 30 | + scopes: List[str] |
| 31 | + docs_url: str |
| 32 | + |
| 33 | + |
| 34 | +class ConnectorStatusResponse(BaseModel): |
| 35 | + id: ConnectorId |
| 36 | + name: str |
| 37 | + state: ConnectorState |
| 38 | + connected_at: Optional[datetime] = None |
| 39 | + scopes: List[str] = Field(default_factory=list) |
| 40 | + detail: str |
| 41 | + |
| 42 | + |
| 43 | +class ConnectorListResponse(BaseModel): |
| 44 | + connectors: List[ConnectorStatusResponse] |
| 45 | + |
| 46 | + |
| 47 | +class ConnectorStartResponse(BaseModel): |
| 48 | + connector_id: ConnectorId |
| 49 | + authorization_url: str |
| 50 | + state: str |
| 51 | + expires_at: datetime |
| 52 | + |
| 53 | + |
| 54 | +class ConnectorDisconnectResponse(BaseModel): |
| 55 | + connector_id: ConnectorId |
| 56 | + disconnected: bool |
| 57 | + |
| 58 | + |
| 59 | +class PendingOAuthState(BaseModel): |
| 60 | + connector_id: ConnectorId |
| 61 | + user_id: str |
| 62 | + expires_at: datetime |
| 63 | + |
| 64 | + |
| 65 | +CONNECTORS: Dict[ConnectorId, ConnectorDefinition] = { |
| 66 | + "notion": ConnectorDefinition( |
| 67 | + id="notion", |
| 68 | + name="Notion", |
| 69 | + description="Sync selected Notion pages and workspace notes into XMem memory.", |
| 70 | + auth_url="https://api.notion.com/v1/oauth/authorize", |
| 71 | + token_url="https://api.notion.com/v1/oauth/token", |
| 72 | + scopes=[], |
| 73 | + docs_url="https://developers.notion.com/docs/authorization", |
| 74 | + ), |
| 75 | + "google-drive": ConnectorDefinition( |
| 76 | + id="google-drive", |
| 77 | + name="Google Drive", |
| 78 | + description="Bring Google Drive docs and files into XMem as searchable memory.", |
| 79 | + auth_url="https://accounts.google.com/o/oauth2/v2/auth", |
| 80 | + token_url="https://oauth2.googleapis.com/token", |
| 81 | + scopes=[ |
| 82 | + "https://www.googleapis.com/auth/drive.readonly", |
| 83 | + "https://www.googleapis.com/auth/documents.readonly", |
| 84 | + ], |
| 85 | + docs_url="https://developers.google.com/identity/protocols/oauth2", |
| 86 | + ), |
| 87 | +} |
| 88 | + |
| 89 | +_pending_states: Dict[str, PendingOAuthState] = {} |
| 90 | + |
| 91 | + |
| 92 | +def _now() -> datetime: |
| 93 | + return datetime.now(timezone.utc) |
| 94 | + |
| 95 | + |
| 96 | +def _client_id(connector_id: ConnectorId) -> Optional[str]: |
| 97 | + if connector_id == "notion": |
| 98 | + return os.getenv("NOTION_CLIENT_ID") |
| 99 | + return os.getenv("GOOGLE_DRIVE_CLIENT_ID") or os.getenv("GOOGLE_CLIENT_ID") |
| 100 | + |
| 101 | + |
| 102 | +def _redirect_uri(connector_id: ConnectorId) -> str: |
| 103 | + if connector_id == "notion": |
| 104 | + return os.getenv( |
| 105 | + "NOTION_REDIRECT_URI", |
| 106 | + "http://localhost:8000/api/connectors/notion/oauth/callback", |
| 107 | + ) |
| 108 | + return os.getenv( |
| 109 | + "GOOGLE_DRIVE_REDIRECT_URI", |
| 110 | + "http://localhost:8000/api/connectors/google-drive/oauth/callback", |
| 111 | + ) |
| 112 | + |
| 113 | + |
| 114 | +def _get_connector(connector_id: str) -> ConnectorDefinition: |
| 115 | + connector = CONNECTORS.get(connector_id) # type: ignore[arg-type] |
| 116 | + if not connector: |
| 117 | + raise HTTPException(status_code=status.HTTP_404_NOT_FOUND, detail="Unknown connector") |
| 118 | + return connector |
| 119 | + |
| 120 | + |
| 121 | +def _prune_pending_states(now: Optional[datetime] = None) -> None: |
| 122 | + current_time = now or _now() |
| 123 | + expired = [ |
| 124 | + key |
| 125 | + for key, pending in _pending_states.items() |
| 126 | + if pending.expires_at <= current_time |
| 127 | + ] |
| 128 | + for key in expired: |
| 129 | + _pending_states.pop(key, None) |
| 130 | + |
| 131 | + overflow = len(_pending_states) - MAX_PENDING_STATES |
| 132 | + if overflow > 0: |
| 133 | + oldest = sorted(_pending_states.items(), key=lambda item: item[1].expires_at) |
| 134 | + for key, _pending in oldest[:overflow]: |
| 135 | + _pending_states.pop(key, None) |
| 136 | + |
| 137 | + |
| 138 | +def _status_for(user_id: str, connector: ConnectorDefinition) -> ConnectorStatusResponse: |
| 139 | + return ConnectorStatusResponse( |
| 140 | + id=connector.id, |
| 141 | + name=connector.name, |
| 142 | + state="not_connected", |
| 143 | + scopes=connector.scopes, |
| 144 | + detail="OAuth start is available; token exchange and sync storage are not connected yet.", |
| 145 | + ) |
| 146 | + |
| 147 | + |
| 148 | +def _build_authorization_url(connector: ConnectorDefinition, state: str) -> str: |
| 149 | + client_id = _client_id(connector.id) |
| 150 | + if not client_id: |
| 151 | + raise HTTPException( |
| 152 | + status_code=status.HTTP_503_SERVICE_UNAVAILABLE, |
| 153 | + detail=f"{connector.name} OAuth client ID is not configured", |
| 154 | + ) |
| 155 | + |
| 156 | + params = { |
| 157 | + "client_id": client_id, |
| 158 | + "redirect_uri": _redirect_uri(connector.id), |
| 159 | + "response_type": "code", |
| 160 | + "state": state, |
| 161 | + } |
| 162 | + if connector.id == "google-drive": |
| 163 | + params.update( |
| 164 | + { |
| 165 | + "access_type": "offline", |
| 166 | + "include_granted_scopes": "true", |
| 167 | + "prompt": "consent", |
| 168 | + "scope": " ".join(connector.scopes), |
| 169 | + } |
| 170 | + ) |
| 171 | + if connector.id == "notion": |
| 172 | + params["owner"] = "user" |
| 173 | + |
| 174 | + return f"{connector.auth_url}?{urlencode(params)}" |
| 175 | + |
| 176 | + |
| 177 | +@router.get("", response_model=ConnectorListResponse) |
| 178 | +async def list_connectors(current_user: dict = Depends(require_user)) -> ConnectorListResponse: |
| 179 | + user_id = str(current_user.get("id")) |
| 180 | + return ConnectorListResponse( |
| 181 | + connectors=[_status_for(user_id, connector) for connector in CONNECTORS.values()] |
| 182 | + ) |
| 183 | + |
| 184 | + |
| 185 | +@router.get("/{connector_id}/status", response_model=ConnectorStatusResponse) |
| 186 | +async def connector_status( |
| 187 | + connector_id: str, |
| 188 | + current_user: dict = Depends(require_user), |
| 189 | +) -> ConnectorStatusResponse: |
| 190 | + connector = _get_connector(connector_id) |
| 191 | + return _status_for(str(current_user.get("id")), connector) |
| 192 | + |
| 193 | + |
| 194 | +@router.post("/{connector_id}/oauth/start", response_model=ConnectorStartResponse) |
| 195 | +async def start_connector_oauth( |
| 196 | + connector_id: str, |
| 197 | + current_user: dict = Depends(require_user), |
| 198 | +) -> ConnectorStartResponse: |
| 199 | + connector = _get_connector(connector_id) |
| 200 | + _prune_pending_states() |
| 201 | + state = secrets.token_urlsafe(32) |
| 202 | + expires_at = _now() + timedelta(minutes=STATE_TTL_MINUTES) |
| 203 | + authorization_url = _build_authorization_url(connector, state) |
| 204 | + _pending_states[state] = PendingOAuthState( |
| 205 | + connector_id=connector.id, |
| 206 | + user_id=str(current_user.get("id")), |
| 207 | + expires_at=expires_at, |
| 208 | + ) |
| 209 | + |
| 210 | + return ConnectorStartResponse( |
| 211 | + connector_id=connector.id, |
| 212 | + authorization_url=authorization_url, |
| 213 | + state=state, |
| 214 | + expires_at=expires_at, |
| 215 | + ) |
| 216 | + |
| 217 | + |
| 218 | +@router.get("/{connector_id}/oauth/callback") |
| 219 | +async def connector_oauth_callback( |
| 220 | + connector_id: str, |
| 221 | + state: str = Query(..., min_length=1), |
| 222 | + code: Optional[str] = Query(None, min_length=1), |
| 223 | + error: Optional[str] = Query(None, min_length=1), |
| 224 | +) -> dict: |
| 225 | + connector = _get_connector(connector_id) |
| 226 | + now = _now() |
| 227 | + _prune_pending_states(now) |
| 228 | + pending = _pending_states.pop(state, None) |
| 229 | + if not pending or pending.connector_id != connector.id or pending.expires_at <= now: |
| 230 | + raise HTTPException( |
| 231 | + status_code=status.HTTP_400_BAD_REQUEST, |
| 232 | + detail="Invalid or expired connector authorization state", |
| 233 | + ) |
| 234 | + if error or not code: |
| 235 | + raise HTTPException( |
| 236 | + status_code=status.HTTP_400_BAD_REQUEST, |
| 237 | + detail=f"Authorization denied: {error or 'no authorization code received'}", |
| 238 | + ) |
| 239 | + |
| 240 | + # Token exchange, encrypted credential storage, and source ingestion are intentionally |
| 241 | + # separate follow-up steps. Do not mark the connector as connected until those exist. |
| 242 | + return { |
| 243 | + "status": "pending", |
| 244 | + "connector_id": connector.id, |
| 245 | + "detail": f"{connector.name} authorization received; token exchange is not enabled yet.", |
| 246 | + } |
| 247 | + |
| 248 | + |
| 249 | +@router.post("/{connector_id}/disconnect", response_model=ConnectorDisconnectResponse) |
| 250 | +async def disconnect_connector( |
| 251 | + connector_id: str, |
| 252 | + current_user: dict = Depends(require_user), |
| 253 | +) -> ConnectorDisconnectResponse: |
| 254 | + connector = _get_connector(connector_id) |
| 255 | + disconnected = False |
| 256 | + return ConnectorDisconnectResponse(connector_id=connector.id, disconnected=disconnected) |
0 commit comments