Add staff visibility workstation enrollment registration vault and category task views
This commit is contained in:
@@ -25,6 +25,7 @@ from app.modules.documents.models import (
|
||||
DocumentStorageJob,
|
||||
EngagementDocument,
|
||||
EngagementDocumentVersion,
|
||||
ERPWorkstationAgent,
|
||||
PermanentClientDocument,
|
||||
PermanentClientDocumentVersion,
|
||||
PermanentDocumentDownloadRequest,
|
||||
@@ -813,6 +814,53 @@ def authenticate_storage_node(db: Session, node_code: str | None, secret: str |
|
||||
return node
|
||||
|
||||
|
||||
|
||||
def authenticate_storage_agent(
|
||||
db: Session,
|
||||
node_code: str | None,
|
||||
secret: str | None,
|
||||
agent_instance_id: str | None = None,
|
||||
request=None,
|
||||
) -> BranchStorageNode | None:
|
||||
"""Authenticate either a legacy branch-node secret or a workstation-specific secret.
|
||||
|
||||
Existing Local Agents continue to use the branch node secret unchanged. New
|
||||
workstation enrollment packages receive a workstation-only secret so adding a
|
||||
PC no longer rotates credentials used by already-installed office systems.
|
||||
"""
|
||||
node = authenticate_storage_node(db, node_code, secret, request=request)
|
||||
if node:
|
||||
return node
|
||||
instance_id = (agent_instance_id or "").strip()
|
||||
if not node_code or not secret or not instance_id:
|
||||
return None
|
||||
node = db.execute(
|
||||
select(BranchStorageNode).where(
|
||||
BranchStorageNode.node_code == node_code,
|
||||
BranchStorageNode.is_active.is_(True),
|
||||
)
|
||||
).scalar_one_or_none()
|
||||
if not node:
|
||||
return None
|
||||
workstation = db.execute(
|
||||
select(ERPWorkstationAgent).where(
|
||||
ERPWorkstationAgent.storage_node_id == node.id,
|
||||
ERPWorkstationAgent.agent_instance_id == instance_id,
|
||||
ERPWorkstationAgent.is_active.is_(True),
|
||||
)
|
||||
).scalar_one_or_none()
|
||||
if not workstation or not workstation.workstation_secret_hash:
|
||||
return None
|
||||
if not hmac.compare_digest(workstation.workstation_secret_hash, hash_storage_secret(secret)):
|
||||
return None
|
||||
now = datetime.now(timezone.utc)
|
||||
node.last_seen_at_utc = now
|
||||
workstation.last_seen_at_utc = now
|
||||
ip = request.client.host if request and request.client else None
|
||||
node.last_seen_ip = ip
|
||||
workstation.last_seen_ip = ip
|
||||
return node
|
||||
|
||||
def list_pending_storage_jobs(db: Session, node: BranchStorageNode, limit: int = 20):
|
||||
return db.execute(
|
||||
select(DocumentStorageJob)
|
||||
|
||||
Reference in New Issue
Block a user