feature: recode cloudcommon policy default/resource codes

This commit is contained in:
Qiu Jian
2020-03-30 19:35:55 +08:00
parent 6d31c95b71
commit 09bc348c66
40 changed files with 1336 additions and 573 deletions
+14
View File
@@ -1 +1,15 @@
// Copyright 2019 Yunion
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package proxy // import "yunion.io/x/onecloud/pkg/cloudcommon/db/proxy"
+14
View File
@@ -1,3 +1,17 @@
// Copyright 2019 Yunion
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package proxy
import (
-477
View File
@@ -15,7 +15,6 @@
package policy
import (
identityapi "yunion.io/x/onecloud/pkg/apis/identity"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
@@ -30,144 +29,6 @@ var (
Action: PolicyActionPerform,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "hosts",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "zones",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "zones",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "metadatas",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "storages",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "storages",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "vpcs",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "vpcs",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "wires",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "wires",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "cloudregions",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "cloudregions",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "cachedimages",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "cachedimages",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "dbinstance_skus",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "dbinstance_skus",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "serverskus",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "serverskus",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "secgrouprules",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "elasticcacheskus",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "elasticcacheskus",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "secgrouprules",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "loadbalancerclusters",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "yunionagent",
Resource: "notices",
@@ -186,132 +47,6 @@ var (
Action: PolicyActionCreate,
Result: rbacutils.Allow,
},
{
Service: identityapi.SERVICE_TYPE,
Resource: "services",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: identityapi.SERVICE_TYPE,
Resource: "services",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
},
},
{
Auth: true,
Scope: rbacutils.ScopeUser,
Rules: []rbacutils.SRbacRule{
{
Service: "compute",
Resource: "keypairs",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "keypairs",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "keypairs",
Action: PolicyActionCreate,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "keypairs",
Action: PolicyActionUpdate,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "keypairs",
Action: PolicyActionDelete,
Result: rbacutils.Allow,
},
{
Service: "identity",
Resource: "credentials",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "identity",
Resource: "credentials",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "identity",
Resource: "credentials",
Action: PolicyActionCreate,
Result: rbacutils.Allow,
},
{
Service: "identity",
Resource: "credentials",
Action: PolicyActionUpdate,
Result: rbacutils.Allow,
},
{
Service: "identity",
Resource: "credentials",
Action: PolicyActionDelete,
Result: rbacutils.Allow,
},
{
Service: "yunionconf",
Resource: "parameters",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "yunionconf",
Resource: "parameters",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "yunionconf",
Resource: "parameters",
Action: PolicyActionCreate,
Result: rbacutils.Allow,
},
{
Service: "yunionconf",
Resource: "parameters",
Action: PolicyActionUpdate,
Result: rbacutils.Allow,
},
{
Service: "notify",
Resource: "contacts",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "notify",
Resource: "contacts",
Action: PolicyActionCreate,
Result: rbacutils.Allow,
},
{
Service: "notify",
Resource: "contacts",
Action: PolicyActionUpdate,
Result: rbacutils.Allow,
},
{
Service: "notify",
Resource: "contacts",
Action: PolicyActionDelete,
Result: rbacutils.Allow,
},
},
},
{
@@ -323,78 +58,6 @@ var (
Action: PolicyActionPerform,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "quotas",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "quotas",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "region_quotas",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "region_quotas",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "zone_quotas",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "zone_quotas",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "project_quotas",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "project_quotas",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "domain_quotas",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "domain_quotas",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "image",
Resource: "image_quotas",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "image",
Resource: "image_quotas",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
// usages for any services
// Service: "compute",
@@ -402,78 +65,6 @@ var (
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "networks",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "networks",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "image",
Resource: "images",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "image",
Resource: "images",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "image",
Resource: "guestimages",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "image",
Resource: "guestimages",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "log",
Resource: "actions",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "log",
Resource: "actions",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "cloudproviders",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "cloudproviders",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: identityapi.SERVICE_TYPE,
Resource: "users",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: identityapi.SERVICE_TYPE,
Resource: "groups",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
},
},
{
@@ -495,39 +86,11 @@ var (
},
},
},
{
// for anonymous update torrent status
Auth: false,
Scope: rbacutils.ScopeSystem,
Rules: []rbacutils.SRbacRule{
{
Service: "image",
Resource: "images",
Action: PolicyActionPerform,
Extra: []string{"update-torrent-status"},
Result: rbacutils.Allow,
},
},
},
{
// for domain
Auth: true,
Scope: rbacutils.ScopeDomain,
Rules: []rbacutils.SRbacRule{
{
// quotas for any services
// Service: "compute",
Resource: "quotas",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
// quotas for any services
// Service: "compute",
Resource: "quotas",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
// usages for any services
// Service: "compute",
@@ -535,46 +98,6 @@ var (
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: identityapi.SERVICE_TYPE,
Resource: "domains",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
},
},
{
// for policies administration
Auth: true,
Scope: rbacutils.ScopeSystem,
DomainId: identityapi.DEFAULT_DOMAIN_ID,
Projects: []string{identityapi.SystemAdminProject},
Roles: []string{identityapi.SystemAdminRole},
Rules: []rbacutils.SRbacRule{
{
Service: identityapi.SERVICE_TYPE,
Resource: "policies",
Action: PolicyActionCreate,
Result: rbacutils.Allow,
},
{
Service: identityapi.SERVICE_TYPE,
Resource: "policies",
Action: PolicyActionUpdate,
Result: rbacutils.Allow,
},
{
Service: identityapi.SERVICE_TYPE,
Resource: "policies",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: identityapi.SERVICE_TYPE,
Resource: "policies",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
},
},
}
+15 -89
View File
@@ -14,52 +14,11 @@
package policy
import "yunion.io/x/pkg/utils"
import (
"yunion.io/x/pkg/utils"
)
var (
computeSystemResources = []string{
"zones",
"cloudregions",
"serverskus",
"cachedimages",
"dynamicschedtags",
"baremetalagents",
"schedpolicies",
"dnsrecords",
"metadatas",
"loadbalancerclusters",
"loadbalanceragents",
"isolated-devices",
"reservedips",
}
computeDomainResources = []string{
"cloudaccounts",
"cloudproviders",
"recyclebins",
// migrate system resources to domain resources
"hosts",
"vpcs",
"storages",
"wires",
"globalvpcs",
"route_tables",
"networkinterfaces",
"natgateways",
"natsentries",
"natdentries",
}
computeUserResources = []string{
"keypairs",
}
notifySystemResources = []string{
"configs",
}
notifyDomainResources = []string{}
notifyUserResources = []string{
"contacts",
}
meterSystemResources = []string{
"rates",
"res_results",
@@ -79,75 +38,30 @@ var (
yunionagentDomainResources = []string{}
yunionagentUserResources = []string{}
yunionconfSystemResources = []string{}
yunionconfDomainResources = []string{}
yunionconfUserResources = []string{
"parameters",
}
logSystemResources = []string{}
logDomainResources = []string{}
logUserResources = []string{}
identitySystemResources = []string{
"identity_providers",
"domains",
"services",
"endpoints",
}
identityDomainResources = []string{
"users",
"groups",
"projects",
"roles",
"policies",
}
identityUserResources = []string{}
itsmSystemResources = []string{
"process-definitions",
}
itsmDomainResources = []string{}
itsmUserResources = []string{}
cloudeventSystemResoruces = []string{
"cloudevents",
}
systemResources = map[string][]string{
"compute": computeSystemResources,
"notify": notifySystemResources,
"meter": meterSystemResources,
"k8s": k8sSystemResources,
"yunionagent": yunionagentSystemResources,
"yunionconf": yunionconfSystemResources,
"log": logSystemResources,
"identity": identitySystemResources,
"itsm": itsmSystemResources,
"cloudevent": cloudeventSystemResoruces,
}
domainResources = map[string][]string{
"compute": computeDomainResources,
"notify": notifyDomainResources,
"meter": meterDomainResources,
"k8s": k8sDomainResources,
"yunionagent": yunionagentDomainResources,
"yunionconf": yunionconfDomainResources,
"log": logDomainResources,
"identity": identityDomainResources,
"itsm": itsmDomainResources,
}
userResources = map[string][]string{
"compute": computeUserResources,
"notify": notifyUserResources,
"meter": meterUserResources,
"k8s": k8sUserResources,
"yunionagent": yunionagentUserResources,
"yunionconf": yunionconfUserResources,
"log": logUserResources,
"identity": identityUserResources,
"itsm": itsmUserResources,
}
)
@@ -206,3 +120,15 @@ func isProjectResource(service string, resource string) bool {
}
return true
}
func RegisterSystemResources(service string, resources []string) {
systemResources[service] = resources
}
func RegisterDomainResources(service string, resources []string) {
domainResources[service] = resources
}
func RegisterUserResources(service string, resources []string) {
userResources[service] = resources
}