Skip to main content

Introduction

A product for Plone developers. You will be able to register actions on site’s contents, protected by a secret token.

Using an internal utility, or calling a provided view (@@consume-powertoken) you can run the action you have configured previously.

How to use

First of all you need the utility:

>>> from collective.powertoken.core.interfaces import IPowerTokenUtility
>>> utility = getUtility(IPowerTokenUtility)

With this you can register a new action on a site content (for example, a document):

>>> token = utility.enablePowerToken(document, 'myMagicAction')

The token must (probably) kept secret, and you must use it has you prefer (for example: develop an application that send the token by e-mail)

You can then execute the given action using the same utility:

>>> result = utility.consumeActions(document, token)

Or calling the provided view that need token and path parameters, for example:

http://myplonesite/@@consume-powertoken?token=aaaa-bbbb-cccc&path=path/to/the/content

The consumeActions can also be called with additional runtime arguments that can be used later when the action is executed:

>>> result = utility.consumeActions(document, token, runtime_parameter1='foo', runtime_parameter2=5.4)

Registering more that one action

You can also register (and then run all of theme) more that one action for a token.

>>> token = utility.enablePowerToken(document, 'myMagicAction')
>>> utility.addAction(document, token, 'myMagicAction')
>>> utility.addAction(document, token, 'aDifferentAction')

When you consume the token, all registered actions are executed in order.

>>> result = utility.consumeActions(document, token)

What action is executed?

This is only the core package so you need to look for other packages that add possible actions (or develop your own).

When you call:

>>> token = utility.enablePowerToken(document, 'myMagicAction', parameter1='foo', parameter2=5)

… you are preparing the call for an adapter called myMagicAction, saving also additional configuration parameters provided (in a special action object, see below). Know that 3rd party adapter can require specific configuration parameters to works properly.

When consumeActions is called, internally a new adapter is searched:

>>> from collective.powertoken.core.interfaces import IPowerActionProvider
>>> adapter = getMultiAdapter((document, request),
...                           IPowerActionProvider,
...                           name='myMagicAction')
>>> result = adapter.doAction(action, runtime_parameter1='foo', runtime_parameter2=5.4)

What to do with results (you can also don’t provide results) is under your control. Result is always a Python list with all results from all executed actions.

A list of all know action providers is available online (feel free to contribute and update this page with your own).

Special parameters

When calling enablePowerToken and you give additional parameters, they are stored in the action object:

roles

Default to empty list. Commonly when you call consumeActions you are performing an action keeping user’s privileges. Providing there a list of Zope roles will give you those roles instead. In this way, knowing a token, you can commonly perform unauthorized actions.

oneTime

Default to True. When you call consumeActions you commonly execute the action and remove the action from the action list. Instead you can configure an action that never expire the token when executed, so you can call it many times as you want (using the same token every time).

params

Default is an empty dict, automatically filled with every other keyword argument passed, commonly used by adapters.

Additional advanced, parameters:

unrestricted

Defaut: False. Use an unrestricted user, that always pass security check. Please note that you commonly don’t need this, just configure well roles.

username

Defaut: None. When using a different security context, like when using the roles parameter, instead of the current user’s id (or an empty string when anonymous) you can choose a new one.

Final security note

This product play with Zope security, potentially giving great power to users, simply knowing the secret token.

Be careful!

Authors

This product was developed by RedTurtle Technology team.

RedTurtle Technology Site

Changelog

0.3.0 (2012-02-15)

  • now you can add runtime parameters when consuming actions [keul]

  • updated documentation and fixed from errors [keul]

0.2.0 (2012-01-15)

  • added new option: unrestricted (you commonly don’t need this, really) [keul]

  • added new option: username [keul]

0.1.0 (2012-01-11)

  • Initial release

Release files for collective.powertoken.core 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for collective.powertoken.core 0.3.0
File Size Uploaded
collective.powertoken.core-0.3.0.tar.gz 19.0 kB Details

Release files / collective.powertoken.core-0.3.0.tar.gz

Download URL collective.powertoken.core-0.3.0.tar.gz
Size 19.0 kB
Tags Source
SHA-256 checksum
How to use checksums
072eec6040f8b885b55e929e7842f65cb61528dc43c47ed6128e349c254addc8
BLAKE2b-256 checksum
How to use checksums
95aa38c91b448cfd7ce020388317763a83f8fa9a3bf6528138cb3e5a7f316a45
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

0.3.0 This release

1 release file

0.2.0

1 release file

0.1.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page