Sign inSign up

adfinissygroup/timed-backend

By adfinissygroup

•Updated about 4 years ago

Timed timetracking software REST API built with Django

Image
1

10K+

adfinissygroup/timed-backend repository overview

⁠Timed Backend

Build Status Coverage Pyup Black License: AGPL v3

Timed timetracking software REST API built with Django

⁠Installation

Requirements

  • docker
  • docker-compose

After installing and configuring those requirements, you should be able to run the following commands to complete the installation:

Add the timed.local entries to your hosts file:

echo "127.0.0.1 timed.local" | sudo tee -a /etc/hosts

Then just start the docker-compose setup:

make start

This brings up complete local installation, including our Timed Frontend⁠ project.

You can visit it at http://timed.local⁠.

The API can be accessed at http://timed.local/api/v1⁠ and the admin interface at http://timed.local/admin/⁠.

The Keycloak admin interface can be accessed at http://timed.local/auth/admin⁠ with the account admin and password admin

⁠Development

To get the application working locally for development, make sure to create a file .env with the following content:

ENV=dev
DJANGO_OIDC_CREATE_USER=True

If you have existing users from the previous LDAP authentication, you want to add this line as well:

DJANGO_OIDC_USERNAME_CLAIM=preferred_username

The test data includes 3 users admin, fritzm and alexs with you can log into http://timed.local⁠

The username and password are identical.

To access the Django admin interface you will have to change the admin password in Django directly:

$ make shell
root@0a036a10f3c4:/app# python manage.py changepassword admin
Changing password for user 'admin'
Password: 
Password (again): 
Password changed successfully for user 'admin'

Then you'll be able to login in the Django admin interface http://timed.local/admin/⁠.

⁠Adding a user

If you want to add other users with different roles, add them in the Keycloak interface (as they would be coming from your LDAP directory). You will also have to correct their employment in the Django admin interface as it is not correctly set for the moment. Head to http://timed.local/admin/⁠ after having perform a first login with the user. You should see that new user in the Employment -> Users. Click on the user and scroll down to the Employments section to set a Location. Save the user and you should now see the Timed interface correctly under that account.

⁠Configuration

Following options can be set as environment variables to configure Timed backend in documented format⁠ according to type.

ParameterDescriptionDefault
DJANGO_ENV_FILEPath to setup environment vars in a file.env
DJANGO_DEBUGBoolean that turns on/off debug modeFalse
DJANGO_SECRET_KEYSecret key for cryptographic signingnot set (required)
DJANGO_ALLOWED_HOSTSList of hosts representing the host/domain namesnot set (required)
DJANGO_HOST_PROTOCOLProtocol host is running on (http or https)http
DJANGO_HOST_DOMAINMain host name server is reachable onnot set (required)
DJANGO_DATABASE_NAMEDatabase nametimed
DJANGO_DATABASE_USERDatabase usernametimed
DJANGO_DATABASE_HOSTDatabase hostnamelocalhost
DJANGO_DATABASE_PORTDatabase port5432
DJANGO_OIDC_DEFAULT_BASE_URLBase URL of the OIDC providerhttp://timed.local/auth/realms/timed/protocol/openid-connect⁠
DJANGO_OIDC_OP_AUTHORIZATION_ENDPOINTOIDC /auth endpoint{DJANGO_OIDC_DEFAULT_BASE_URL}/auth
DJANGO_OIDC_OP_TOKEN_ENDPOINTOIDC /token endpoint{DJANGO_OIDC_DEFAULT_BASE_URL}/token
DJANGO_OIDC_OP_USER_ENDPOINTOIDC /userinfo endpoint{DJANGO_OIDC_DEFAULT_BASE_URL}/userinfo
DJANGO_OIDC_OP_JWKS_ENDPOINTOIDC /certs endpoint{DJANGO_OIDC_DEFAULT_BASE_URL}/certs
DJANGO_OIDC_RP_CLIENT_IDClient ID by your OIDC providertimed-public
DJANGO_OIDC_RP_CLIENT_SECRETClient secret by your OIDC provider, should be None (flow start is handled by frontend)not set
DJANGO_OIDC_RP_SIGN_ALGOAlgorithm the OIDC provider uses to sign ID tokensRS256
DJANGO_OIDC_VERIFY_SSLVerify SSL on OIDC requestdev: False, prod: True
DJANGO_OIDC_CREATE_USERCreate new user if it doesn't exist in the databaseFalse
DJANGO_OIDC_USERNAME_CLAIMUsername token claim for user lookup / creationsub
DJANGO_OIDC_EMAIL_CLAIMEmail token claim for creating new users (if DJANGO_OIDC_CREATE_USER is enabled)email
DJANGO_OIDC_FIRSTNAME_CLAIMFirst name token claim for creating new users (if DJANGO_OIDC_CREATE_USER is enabled)given_name
DJANGO_OIDC_LASTNAME_CLAIMLast name token claim for creating new users (if DJANGO_OIDC_CREATE_USER is enabled)family_name
DJANGO_OIDC_BEARER_TOKEN_REVALIDATION_TIMETime (in seconds) to cache a bearer token before revalidation is needed60
DJANGO_OIDC_CHECK_INTROSPECTUse token introspection for confidential clientsTrue
DJANGO_OIDC_OP_INTROSPECT_ENDPOINTOIDC token introspection endpoint (if DJANGO_OIDC_CHECK_INTROSPECT is enabled){DJANGO_OIDC_DEFAULT_BASE_URL}/token/introspect
DJANGO_OIDC_RP_INTROSPECT_CLIENT_IDOIDC client id (if DJANGO_OIDC_CHECK_INTROSPECT is enabled) of confidential clienttimed-confidential
DJANGO_OIDC_RP_INTROSPECT_CLIENT_SECRETOIDC client secret (if DJANGO_OIDC_CHECK_INTROSPECT is enabled) of confidential clientnot set
DJANGO_OIDC_ADMIN_LOGIN_REDIRECT_URLURL of the django-admin, to which the user is redirected after successful admin logindev: http://timed.local/admin/⁠, prod: not set
DJANGO_ALLOW_LOCAL_LOGINEnable / Disable login with local user/password (in admin)True
EMAIL_URLUri of email serversmtp://localhost:25
DJANGO_DEFAULT_FROM_EMAILDefault email address to use for various responseswebmaster@localhost
DJANGO_SERVER_EMAILEmail address error messages are sent fromroot@localhost
DJANGO_ADMINSList of people who get error notificationsnot set
DJANGO_WORK_REPORT_PATHPath of custom work report templatenot set
DJANGO_SENTRY_DSNSentry DSN for error reportingnot set, set to enable Sentry integration
DJANGO_SENTRY_TRACES_SAMPLE_RATESentry trace sample rate, Set 1.0 to capture 100% of transactions1.0
DJANGO_SENTRY_SEND_DEFAULT_PIIAssociate users to errors in SentryTrue
GUNICORN_WORKERSNumber of worker processes to use8
GUNICORN_CMD_ARGSAdditional args for gunicorn⁠not set
STATIC_ROOTPath to the static files. In prod, you may want to mount a docker volume here, so it can be served by nginx/app/static
STATIC_URLURL path to the static files on the web server. Configure nginx to point this to $STATIC_ROOT/static

⁠Contributing

Look at our contributing guidelines⁠ to start with your first contribution.

⁠License

Code released under the GNU Affero General Public License v3.0⁠.

Tag summary

Content type

Image

Digest

Size

349.1 MB

Last updated

over 5 years ago

docker pull adfinissygroup/timed-backend