|
| 1 | +from ansible.module_utils.basic import AnsibleModule |
| 2 | +import requests |
| 3 | + |
| 4 | + |
| 5 | +def get_existing_token(base_url, username, password, user_token, module): |
| 6 | + headers = {"Accept": "application/json"} |
| 7 | + tokens_url = f"{base_url}/api/users/tokens/" |
| 8 | + |
| 9 | + try: |
| 10 | + response = requests.get(tokens_url, headers=headers, auth=(username, password)) |
| 11 | + response.raise_for_status() |
| 12 | + except requests.exceptions.RequestException as e: |
| 13 | + module.fail_json( |
| 14 | + msg=f"Failed to fetch existing tokens for user {username}: {str(e)}" |
| 15 | + ) |
| 16 | + |
| 17 | + tokens = response.json().get("results", []) |
| 18 | + return next((t for t in tokens if t.get("key") == user_token), None) |
| 19 | + |
| 20 | + |
| 21 | +def create_new_token(base_url, username, password, user_token, description, module): |
| 22 | + """Create a new Nautobot token using Basic Auth.""" |
| 23 | + tokens_url = f"{base_url}/api/users/tokens/" |
| 24 | + headers = {"Content-Type": "application/json", "Accept": "application/json"} |
| 25 | + payload = {"key": user_token, "description": description, "write_enabled": True} |
| 26 | + |
| 27 | + try: |
| 28 | + response = requests.post( |
| 29 | + tokens_url, headers=headers, json=payload, auth=(username, password) |
| 30 | + ) |
| 31 | + response.raise_for_status() |
| 32 | + except requests.exceptions.RequestException as e: |
| 33 | + module.fail_json( |
| 34 | + msg=f"Failed to create new token for user {username}: {str(e)}" |
| 35 | + ) |
| 36 | + |
| 37 | + return response.json() |
| 38 | + |
| 39 | + |
| 40 | +def run_module(): |
| 41 | + module_args = dict( |
| 42 | + base_url=dict(type="str", required=True), |
| 43 | + username=dict(type="str", required=True), |
| 44 | + password=dict(type="str", required=True, no_log=True), |
| 45 | + user_token=dict(type="str", required=True, no_log=True), |
| 46 | + token_description=dict(type="str", default="ansible-created-token"), |
| 47 | + ) |
| 48 | + |
| 49 | + module = AnsibleModule(argument_spec=module_args, supports_check_mode=True) |
| 50 | + |
| 51 | + base_url = module.params["base_url"].rstrip("/") |
| 52 | + username = module.params["username"] |
| 53 | + password = module.params["password"] |
| 54 | + user_token = module.params["user_token"] |
| 55 | + token_description = module.params["token_description"] |
| 56 | + |
| 57 | + # fetch existing token |
| 58 | + token = get_existing_token(base_url, username, password, user_token, module) |
| 59 | + if token: |
| 60 | + module.exit_json( |
| 61 | + changed=False, |
| 62 | + username=username, |
| 63 | + message=f"Found existing Nautobot token for user {username}", |
| 64 | + ) |
| 65 | + |
| 66 | + # No token found → try creating new |
| 67 | + new_token = create_new_token( |
| 68 | + base_url, username, password, user_token, token_description, module |
| 69 | + ) |
| 70 | + if not new_token: |
| 71 | + module.fail_json(msg=f"Failed to create new token for user {username}") |
| 72 | + |
| 73 | + module.exit_json( |
| 74 | + changed=True, |
| 75 | + username=username, |
| 76 | + message=f"No token found, created new Nautobot token for user {username}", |
| 77 | + ) |
| 78 | + |
| 79 | + |
| 80 | +def main(): |
| 81 | + run_module() |
| 82 | + |
| 83 | + |
| 84 | +if __name__ == "__main__": |
| 85 | + main() |
0 commit comments