mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
Merge pull request #5362 from swordqiu/automated-cherry-pick-of-#5361-upstream-release-3.1
Automated cherry pick of #5361: fix: allow project do user-list, group-list, returns current project user and group
This commit is contained in:
@@ -42,7 +42,7 @@ func (manager *SDomainizedResourceBaseManager) ResourceScope() rbacutils.TRbacSc
|
||||
func (manager *SDomainizedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
if owner != nil {
|
||||
switch scope {
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacutils.ScopeProject, rbacutils.ScopeDomain:
|
||||
q = q.Equals("domain_id", owner.GetProjectDomainId())
|
||||
}
|
||||
}
|
||||
|
||||
@@ -365,9 +365,7 @@ func FetchCheckQueryOwnerScope(ctx context.Context, userCred mcclient.TokenCrede
|
||||
requireScope = rbacutils.ScopeSystem
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if ownerId == nil {
|
||||
} else {
|
||||
ownerId = userCred
|
||||
reqScopeStr, _ := data.GetString("scope")
|
||||
if len(reqScopeStr) > 0 {
|
||||
@@ -379,10 +377,12 @@ func FetchCheckQueryOwnerScope(ctx context.Context, userCred mcclient.TokenCrede
|
||||
}
|
||||
} else if action == policy.PolicyActionGet {
|
||||
queryScope = allowScope
|
||||
}
|
||||
if resScope.HigherThan(queryScope) {
|
||||
} else {
|
||||
queryScope = resScope
|
||||
}
|
||||
// if resScope.HigherThan(queryScope) {
|
||||
// queryScope = resScope
|
||||
// }
|
||||
requireScope = queryScope
|
||||
}
|
||||
if doCheckRbac && requireScope.HigherThan(allowScope) {
|
||||
|
||||
@@ -456,6 +456,18 @@ var (
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: identityapi.SERVICE_TYPE,
|
||||
Resource: "users",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: identityapi.SERVICE_TYPE,
|
||||
Resource: "groups",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
|
||||
@@ -316,3 +316,13 @@ func (group *SGroup) PerformLeave(
|
||||
}
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
func (manager *SGroupManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
if owner != nil && scope == rbacutils.ScopeProject {
|
||||
// if user has project level privilege, returns all groups in user's project
|
||||
subq := AssignmentManager.fetchProjectGroupIdsQuery(owner.GetProjectId())
|
||||
q = q.In("id", subq.SubQuery())
|
||||
return q
|
||||
}
|
||||
return manager.SIdentityBaseResourceManager.FilterByOwner(q, owner, scope)
|
||||
}
|
||||
|
||||
@@ -881,3 +881,14 @@ func (manager *SUserManager) LockUser(uid string) error {
|
||||
db.OpsLog.LogEvent(usr, db.ACT_UPDATE, diff, GetDefaultAdminCred())
|
||||
return nil
|
||||
}
|
||||
|
||||
func (manager *SUserManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
log.Debugf("owner: %s scope %s", jsonutils.Marshal(owner), scope)
|
||||
if owner != nil && scope == rbacutils.ScopeProject {
|
||||
// if user has project level privilege, returns all users in user's project
|
||||
subq := AssignmentManager.fetchProjectUserIdsQuery(owner.GetProjectId())
|
||||
q = q.In("id", subq.SubQuery())
|
||||
return q
|
||||
}
|
||||
return manager.SEnabledIdentityBaseResourceManager.FilterByOwner(q, owner, scope)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user