source: main/waeup.aaue/trunk/src/waeup/aaue/etranzact/browser.py @ 9570

Last change on this file since 9570 was 9508, checked in by Henrik Bettermann, 12 years ago

Add more security.

  • Property svn:keywords set to Id
File size: 9.9 KB
RevLine 
[7929]1## $Id: browser.py 9508 2012-11-02 10:50:58Z henrik $
2##
3## Copyright (C) 2012 Uli Fouquet & Henrik Bettermann
4## This program is free software; you can redistribute it and/or modify
5## it under the terms of the GNU General Public License as published by
6## the Free Software Foundation; either version 2 of the License, or
7## (at your option) any later version.
8##
9## This program is distributed in the hope that it will be useful,
10## but WITHOUT ANY WARRANTY; without even the implied warranty of
11## MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12## GNU General Public License for more details.
13##
14## You should have received a copy of the GNU General Public License
15## along with this program; if not, write to the Free Software
16## Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
17##
18from datetime import datetime
19import httplib
20import urllib
21from xml.dom.minidom import parseString
22import grok
[8704]23from zope.component import getUtility
24from zope.catalog.interfaces import ICatalog
[8698]25from waeup.kofa.interfaces import IUniversity
[8704]26from waeup.kofa.payments.interfaces import IPaymentWebservice
[7929]27from waeup.kofa.browser.layout import KofaPage, UtilityView
[8430]28from waeup.kofa.students.viewlets import ApprovePaymentActionButton as APABStudent
29from waeup.kofa.applicants.viewlets import ApprovePaymentActionButton as APABApplicant
[8710]30from waeup.aaue.interfaces import academic_sessions_vocab
[8444]31from waeup.aaue.interfaces import MessageFactory as _
32from waeup.aaue.students.interfaces import ICustomStudentOnlinePayment
33from waeup.aaue.applicants.interfaces import ICustomApplicantOnlinePayment
[7929]34
[8769]35#ACCEPTED_IP = ('195.219.3.181', '195.219.3.184')
[8746]36ACCEPTED_IP = None
37
[8769]38
[8698]39# Kofa's webservice
40
41class KofaFeeRequest(grok.View):
42    grok.context(IUniversity)
43    grok.name('feerequest')
44    grok.require('waeup.Public')
45
46    def update(self, PAYEE_ID=None):
[9508]47        if PAYEE_ID == None:
48            self.output = '-1'
49            return
[8746]50        real_ip = self.request.get('HTTP_X_FORWARDED_FOR', None)
[8769]51        # We can forego the logging once eTranzact payments run smoothly
52        # and the accepted IP addresses are used.
53        if real_ip:
54            self.context.logger.info('KofaFeeRequest called: %s' % real_ip)
[8746]55        if real_ip  and ACCEPTED_IP:
[8769]56            if real_ip not in  ACCEPTED_IP:
[8746]57                self.output = '-4'
58                return
[8754]59
60        # It seems eTranzact sends a POST request with an empty body but the URL
61        # contains a query string. So it's actually a GET request pretended
62        # to be a POST request. Although this does not comply with the
63        # RFC 2616 HTTP guidelines we may try to fetch the id from the QUERY_STRING
64        # value of the request.
65        #if PAYEE_ID is None:
66        #    try:
67        #        PAYEE_ID = self.request['QUERY_STRING'].split('=')[1]
68        #    except:
69        #        self.output = '-2'
70        #        return
71
[8704]72        cat = getUtility(ICatalog, name='payments_catalog')
73        results = list(cat.searchResults(p_id=(PAYEE_ID, PAYEE_ID)))
74        if len(results) != 1:
75            self.output = '-1'
[8746]76            return
77        try:
78            owner = IPaymentWebservice(results[0])
79            full_name = owner.display_fullname
80            matric_no = owner.id
81            faculty = owner.faculty
82            department = owner.department
83        except (TypeError, AttributeError):
84            self.output = '-3'
85            return
86        amount = results[0].amount_auth
87        payment_type = results[0].category
88        programme_type = results[0].p_item
89        academic_session = academic_sessions_vocab.getTerm(
90            results[0].p_session).title
91        status = results[0].p_state
92        self.output = (
93            'FULL_NAME=%s&' +
94            'FACULTY=%s&' +
95            'DEPARTMENT=%s&' +
96            'RETURN_TYPE=%s&' +
97            'PROGRAMME_TYPE=%s&' +
98            'PAYMENT_TYPE=%s&' +
99            'ACADEMIC_SESSION=%s&' +
100            'MATRIC_NO=%s&' +
101            'FEE_AMOUNT=%s&' +
102            'TRANSACTION_STATUS=%s') % (full_name, faculty,
103            department, PAYEE_ID, programme_type, payment_type,
104            academic_session, matric_no, amount, status)
[8698]105        return
106
107    def render(self):
108        return self.output
109
110
111# Requerying eTranzact payments
112
[8776]113TERMINAL_ID = '0330000046'
114QUERY_URL =   'https://www.etranzact.net/Query/queryPayoutletTransaction.jsp'
[8259]115
[8680]116# Test environment
[8776]117#QUERY_URL =   'http://demo.etranzact.com:8080/WebConnect/queryPayoutletTransaction.jsp'
118#TERMINAL_ID = '5009892289'
[8680]119
[8430]120def query_etranzact(confirmation_number, payment):
121   
[8247]122    postdict = {}
123    postdict['TERMINAL_ID'] = TERMINAL_ID
124    #postdict['RESPONSE_URL'] = 'http://dummy'
125    postdict['CONFIRMATION_NO'] = confirmation_number
126    data = urllib.urlencode(postdict)
[8682]127    payment.conf_number = confirmation_number
[8247]128    try:
129        f = urllib.urlopen(url=QUERY_URL, data=data)
130        success = f.read()
[8432]131        success = success.replace('\r\n','')
[8769]132        if 'COL6' not in success:
[8430]133            msg = _('Invalid or unsuccessful callback: ${a}',
134                mapping = {'a': success})
135            log = 'invalid callback for payment %s: %s' % (payment.p_id, success)
[8247]136            payment.p_state = 'failed'
[8430]137            return False, msg, log
[8247]138        success = success.replace('%20',' ').split('&')
139        # We expect at least two parameters
140        if len(success) < 2:
[8430]141            msg = _('Invalid callback: ${a}', mapping = {'a': success})
142            log = 'invalid callback for payment %s: %s' % (payment.p_id, success)
[8247]143            payment.p_state = 'failed'
[8430]144            return False, msg, log
[8247]145        try:
146            success_dict = dict([tuple(i.split('=')) for i in success])
147        except ValueError:
[8430]148            msg = _('Invalid callback: ${a}', mapping = {'a': success})
149            log = 'invalid callback for payment %s: %s' % (payment.p_id, success)
[8247]150            payment.p_state = 'failed'
[8430]151            return False, msg, log
[8247]152    except IOError:
[8430]153        msg = _('eTranzact IOError')
154        log = 'eTranzact IOError'
155        return False, msg, log
[8247]156    payment.r_code = u'ET'
[9327]157    payment.r_company = u'etranzact'
[8247]158    payment.r_desc = u'%s' % success_dict.get('TRANS_DESCR')
159    payment.r_amount_approved = float(success_dict.get('TRANS_AMOUNT',0.0))
160    payment.r_card_num = None
161    payment.r_pay_reference = u'%s' % success_dict.get('RECEIPT_NO')
162    if payment.r_amount_approved != payment.amount_auth:
[8430]163        msg = _('Wrong amount')
164        log = 'wrong callback for payment %s: %s' % (payment.p_id, success)
[8247]165        payment.p_state = 'failed'
[8430]166        return False, msg, log
[8717]167    #tcode = payment.p_id
168    #tcode = tcode[len(tcode)-8:len(tcode)]
[8247]169    col1 = success_dict.get('COL1')
[8717]170    #col1 = col1[len(col1)-8:len(col1)]
171    #if tcode != col1:
172    if payment.p_id != col1:
173        #msg = _('Wrong transaction code')
174        msg = _('Wrong payment id')
[8430]175        log = 'wrong callback for payment %s: %s' % (payment.p_id, success)
[8247]176        payment.p_state = 'failed'
[8430]177        return False, msg, log
178    log = 'valid callback for payment %s: %s' % (payment.p_id, success)
179    msg = _('Successful callback received')
[8247]180    payment.p_state = 'paid'
[8433]181    payment.payment_date = datetime.utcnow()
[8430]182    return True, msg, log
[8247]183
[8430]184class EtranzactEnterPinActionButtonApplicant(APABApplicant):
[8253]185    grok.context(ICustomApplicantOnlinePayment)
[8430]186    grok.require('waeup.payApplicant')
[8259]187    grok.order(3)
[7929]188    icon = 'actionicon_call.png'
189    text = _('Query eTranzact History')
[7976]190    target = 'enterpin'
[7929]191
[8430]192class EtranzactEnterPinActionButtonStudent(APABStudent):
[8253]193    grok.context(ICustomStudentOnlinePayment)
[8430]194    grok.require('waeup.payStudent')
[8259]195    grok.order(3)
[8247]196    icon = 'actionicon_call.png'
197    text = _('Query eTranzact History')
198    target = 'enterpin'
199
200class EtranzactEnterPinPageStudent(KofaPage):
[7976]201    """
202    """
[8253]203    grok.context(ICustomStudentOnlinePayment)
[7976]204    grok.name('enterpin')
205    grok.template('enterpin')
[7929]206    grok.require('waeup.payStudent')
207
[7976]208    buttonname = _('Submit to eTranzact')
209    label = _('Requery eTranzact History')
210    action = 'query_history'
[7929]211
[8247]212class EtranzactEnterPinPageApplicant(EtranzactEnterPinPageStudent):
213    """
214    """
215    grok.require('waeup.payApplicant')
[8253]216    grok.context(ICustomApplicantOnlinePayment)
[8247]217
218class EtranzactQueryHistoryPageStudent(UtilityView, grok.View):
[7929]219    """ Query history of eTranzact payments
220    """
[8253]221    grok.context(ICustomStudentOnlinePayment)
[7929]222    grok.name('query_history')
223    grok.require('waeup.payStudent')
224
225    def update(self, confirmation_number=None):
226        if self.context.p_state == 'paid':
227            self.flash(_('This ticket has already been paid.'))
228            return
[8763]229        student = self.context.student
[8430]230        success, msg, log = query_etranzact(confirmation_number,self.context)
[8764]231        student.writeLogMessage(self, log)
[8430]232        if not success:
233            self.flash(msg)
234            return
235        success, msg, log = self.context.doAfterStudentPayment()
236        if log is not None:
[8764]237            student.writeLogMessage(self, log)
[8430]238        self.flash(msg)
[8247]239        return
[7929]240
[8247]241    def render(self):
242        self.redirect(self.url(self.context, '@@index'))
243        return
[7929]244
[8247]245class EtranzactQueryHistoryPageApplicant(UtilityView, grok.View):
246    """ Query history of eTranzact payments
247    """
[8253]248    grok.context(ICustomApplicantOnlinePayment)
[8247]249    grok.name('query_history')
250    grok.require('waeup.payApplicant')
251
252    def update(self, confirmation_number=None):
[8430]253        ob_class = self.__implemented__.__name__
[8247]254        if self.context.p_state == 'paid':
255            self.flash(_('This ticket has already been paid.'))
[7929]256            return
[8247]257        applicant = self.context.__parent__
[8430]258        success, msg, log = query_etranzact(confirmation_number,self.context)
[8769]259        applicant.writeLogMessage(self, log)
[8430]260        if not success:
261            self.flash(msg)
262            return
263        success, msg, log = self.context.doAfterApplicantPayment()
264        if log is not None:
[8769]265            applicant.writeLogMessage(self, log)
[8430]266        self.flash(msg)
[7929]267        return
268
269    def render(self):
270        self.redirect(self.url(self.context, '@@index'))
[8259]271        return
Note: See TracBrowser for help on using the repository browser.