mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
fix: remove mutual dependency of cloudmux on onecloud (#15621)
Co-authored-by: Qiu Jian <qiujian@yunionyun.com>
This commit is contained in:
@@ -22,16 +22,16 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/object"
|
||||
"yunion.io/x/pkg/util/httputils"
|
||||
"yunion.io/x/pkg/util/version"
|
||||
|
||||
api "yunion.io/x/onecloud/pkg/apis/compute"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/agent/iagent"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/object"
|
||||
"yunion.io/x/onecloud/pkg/hostman/storageman"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
modules "yunion.io/x/onecloud/pkg/mcclient/modules/compute"
|
||||
"yunion.io/x/onecloud/pkg/util/httputils"
|
||||
)
|
||||
|
||||
type SZoneInfo struct {
|
||||
|
||||
@@ -19,6 +19,7 @@ import (
|
||||
"net/http"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/appsrv"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
@@ -31,7 +32,7 @@ import (
|
||||
func ExportOptionsHandler(app *appsrv.Application, options interface{}) {
|
||||
hf := func(ctx context.Context, w http.ResponseWriter, r *http.Request) {
|
||||
userCred := auth.FetchUserCredential(ctx, policy.FilterPolicyCredential)
|
||||
result := policy.PolicyManager.Allow(rbacutils.ScopeSystem, userCred, consts.GetServiceType(), "app-options", "list")
|
||||
result := policy.PolicyManager.Allow(rbacscope.ScopeSystem, userCred, consts.GetServiceType(), "app-options", "list")
|
||||
if result.Result == rbacutils.Deny {
|
||||
httperrors.ForbiddenError(ctx, w, "Not allow to access")
|
||||
return
|
||||
|
||||
@@ -23,9 +23,9 @@ import (
|
||||
"time"
|
||||
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/appctx"
|
||||
"yunion.io/x/pkg/errors"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/appctx"
|
||||
"yunion.io/x/onecloud/pkg/appsrv"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/elect"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
|
||||
@@ -18,10 +18,10 @@ import (
|
||||
"context"
|
||||
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
@@ -66,13 +66,13 @@ func ApplyQueryDistinctExtraField(
|
||||
}
|
||||
|
||||
type FilterByOwnerProvider interface {
|
||||
FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery
|
||||
FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery
|
||||
}
|
||||
|
||||
func ApplyFilterByOwner(
|
||||
q *sqlchemy.SQuery,
|
||||
owner mcclient.IIdentityProvider,
|
||||
scope rbacutils.TRbacScope,
|
||||
scope rbacscope.TRbacScope,
|
||||
managers ...FilterByOwnerProvider,
|
||||
) *sqlchemy.SQuery {
|
||||
for _, manager := range managers {
|
||||
|
||||
@@ -23,9 +23,9 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/appctx"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/appctx"
|
||||
"yunion.io/x/onecloud/pkg/appsrv"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/splitable"
|
||||
|
||||
@@ -27,6 +27,8 @@ import (
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/gotypes"
|
||||
"yunion.io/x/pkg/util/filterclause"
|
||||
"yunion.io/x/pkg/util/printutils"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/version"
|
||||
"yunion.io/x/pkg/utils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
@@ -39,7 +41,6 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/auth"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/modulebase"
|
||||
"yunion.io/x/onecloud/pkg/util/logclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
@@ -348,7 +349,7 @@ func mergeFields(metaFields, queryFields []string, isSysAdmin bool) stringutils2
|
||||
func Query2List(manager IModelManager, ctx context.Context, userCred mcclient.TokenCredential, q *sqlchemy.SQuery, query jsonutils.JSONObject, delayFetch bool) ([]jsonutils.JSONObject, error) {
|
||||
metaFields, excludeFields := listFields(manager, userCred)
|
||||
fieldFilter := jsonutils.GetQueryStringArray(query, "field")
|
||||
allowListResult := IsAllowList(rbacutils.ScopeSystem, userCred, manager)
|
||||
allowListResult := IsAllowList(rbacscope.ScopeSystem, userCred, manager)
|
||||
listF := mergeFields(metaFields, fieldFilter, allowListResult.Result.IsAllow())
|
||||
listExcludes, _, _ := stringutils2.Split(stringutils2.NewSortedStrings(excludeFields), listF)
|
||||
|
||||
@@ -526,7 +527,7 @@ func fetchContextObject(manager IModelManager, ctx context.Context, userCred mcc
|
||||
return nil, httperrors.NewInternalServerError("No such context %s(%s)", ctxId.Type, ctxId.Id)
|
||||
}
|
||||
|
||||
func ListItems(manager IModelManager, ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, ctxIds []dispatcher.SResourceContext) (*modulebase.ListResult, error) {
|
||||
func ListItems(manager IModelManager, ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, ctxIds []dispatcher.SResourceContext) (*printutils.ListResult, error) {
|
||||
var err error
|
||||
var maxLimit int64 = consts.GetMaxPagingLimit()
|
||||
limit, _ := query.Int("limit")
|
||||
@@ -626,7 +627,7 @@ func ListItems(manager IModelManager, ctx context.Context, userCred mcclient.Tok
|
||||
union, err := sqlchemy.UnionWithError(subqs...)
|
||||
if err != nil {
|
||||
if errors.Cause(err) == sql.ErrNoRows {
|
||||
emptyList := modulebase.ListResult{Data: []jsonutils.JSONObject{}}
|
||||
emptyList := printutils.ListResult{Data: []jsonutils.JSONObject{}}
|
||||
return &emptyList, nil
|
||||
} else {
|
||||
return nil, errors.Wrap(err, "sqlchemy.UnionWithError")
|
||||
@@ -654,7 +655,7 @@ func ListItems(manager IModelManager, ctx context.Context, userCred mcclient.Tok
|
||||
}
|
||||
//log.Debugf("total count %d", totalCnt)
|
||||
if totalCnt == 0 {
|
||||
emptyList := modulebase.ListResult{Data: []jsonutils.JSONObject{}}
|
||||
emptyList := printutils.ListResult{Data: []jsonutils.JSONObject{}}
|
||||
return &emptyList, nil
|
||||
}
|
||||
}
|
||||
@@ -768,7 +769,7 @@ func ListItems(manager IModelManager, ctx context.Context, userCred mcclient.Tok
|
||||
retList = retList[:limit]
|
||||
}
|
||||
nextMarker := encodePagingMarker(nextMarkers)
|
||||
retResult := modulebase.ListResult{
|
||||
retResult := printutils.ListResult{
|
||||
Data: retList, Limit: int(limit),
|
||||
NextMarker: nextMarker,
|
||||
MarkerField: strings.Join(pagingConf.MarkerFields, ","),
|
||||
@@ -820,7 +821,7 @@ func ListItems(manager IModelManager, ctx context.Context, userCred mcclient.Tok
|
||||
return calculateListResult(retList, int64(totalCnt), limit, offset, paginate), nil
|
||||
}
|
||||
|
||||
func calculateListResult(data []jsonutils.JSONObject, total, limit, offset int64, paginate bool) *modulebase.ListResult {
|
||||
func calculateListResult(data []jsonutils.JSONObject, total, limit, offset int64, paginate bool) *printutils.ListResult {
|
||||
if paginate {
|
||||
// do offset first
|
||||
if offset > 0 {
|
||||
@@ -838,7 +839,7 @@ func calculateListResult(data []jsonutils.JSONObject, total, limit, offset int64
|
||||
}
|
||||
}
|
||||
|
||||
retResult := modulebase.ListResult{Data: data, Total: int(total), Limit: int(limit), Offset: int(offset)}
|
||||
retResult := printutils.ListResult{Data: data, Total: int(total), Limit: int(limit), Offset: int(offset)}
|
||||
|
||||
return &retResult
|
||||
}
|
||||
@@ -855,7 +856,7 @@ func getExportCols(query jsonutils.JSONObject, retList []jsonutils.JSONObject) [
|
||||
return retList
|
||||
}
|
||||
|
||||
func (dispatcher *DBModelDispatcher) List(ctx context.Context, query jsonutils.JSONObject, ctxIds []dispatcher.SResourceContext) (*modulebase.ListResult, error) {
|
||||
func (dispatcher *DBModelDispatcher) List(ctx context.Context, query jsonutils.JSONObject, ctxIds []dispatcher.SResourceContext) (*printutils.ListResult, error) {
|
||||
userCred := fetchUserCredential(ctx)
|
||||
manager := dispatcher.manager.GetImmutableInstance(ctx, userCred, query)
|
||||
|
||||
@@ -913,7 +914,7 @@ func getItemDetails(manager IModelManager, item IModel, ctx context.Context, use
|
||||
return nil, errors.Wrap(err, "FetchCustomizeColumns")
|
||||
}
|
||||
if len(extraRows) == 1 {
|
||||
getFields := mergeFields(metaFields, fieldFilter, IsAllowGet(ctx, rbacutils.ScopeSystem, userCred, item))
|
||||
getFields := mergeFields(metaFields, fieldFilter, IsAllowGet(ctx, rbacscope.ScopeSystem, userCred, item))
|
||||
excludes, _, _ := stringutils2.Split(stringutils2.NewSortedStrings(excludeFields), getFields)
|
||||
return extraRows[0].CopyExcludes(excludes...), nil
|
||||
}
|
||||
@@ -1047,7 +1048,7 @@ func (dispatcher *DBModelDispatcher) GetSpecific(ctx context.Context, idStr stri
|
||||
func fetchOwnerId(ctx context.Context, manager IModelManager, userCred mcclient.TokenCredential, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error) {
|
||||
var ownerId mcclient.IIdentityProvider
|
||||
var err error
|
||||
if manager.ResourceScope() != rbacutils.ScopeSystem {
|
||||
if manager.ResourceScope() != rbacscope.ScopeSystem {
|
||||
ownerId, err = manager.FetchOwnerId(ctx, data)
|
||||
if err != nil {
|
||||
return nil, httperrors.NewGeneralError(err)
|
||||
@@ -1370,7 +1371,7 @@ func expandMultiCreateParams(manager IModelManager, data jsonutils.JSONObject, c
|
||||
return ret, nil
|
||||
}
|
||||
|
||||
func (dispatcher *DBModelDispatcher) BatchCreate(ctx context.Context, query jsonutils.JSONObject, data jsonutils.JSONObject, count int, ctxIds []dispatcher.SResourceContext) ([]modulebase.SubmitResult, error) {
|
||||
func (dispatcher *DBModelDispatcher) BatchCreate(ctx context.Context, query jsonutils.JSONObject, data jsonutils.JSONObject, count int, ctxIds []dispatcher.SResourceContext) ([]printutils.SubmitResult, error) {
|
||||
userCred := fetchUserCredential(ctx)
|
||||
manager := dispatcher.manager.GetMutableInstance(ctx, userCred, query, data)
|
||||
|
||||
@@ -1461,10 +1462,10 @@ func (dispatcher *DBModelDispatcher) BatchCreate(ctx context.Context, query json
|
||||
return nil, httperrors.NewGeneralError(errors.Wrap(err, "createResults"))
|
||||
}
|
||||
|
||||
results := make([]modulebase.SubmitResult, count)
|
||||
results := make([]printutils.SubmitResult, count)
|
||||
models := make([]IModel, 0)
|
||||
for i, res := range createResults {
|
||||
result := modulebase.SubmitResult{}
|
||||
result := printutils.SubmitResult{}
|
||||
if res.err != nil {
|
||||
jsonErr := httperrors.NewGeneralError(res.err)
|
||||
result.Status = jsonErr.Code
|
||||
|
||||
@@ -21,12 +21,12 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/util/printutils"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/db/lockman"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/policy"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/modulebase"
|
||||
)
|
||||
|
||||
type DBJointModelDispatcher struct {
|
||||
@@ -58,7 +58,7 @@ func (dispatcher *DBJointModelDispatcher) SlaveKeywordPlural() string {
|
||||
return jointManager.GetSlaveManager().KeywordPlural()
|
||||
}
|
||||
|
||||
func (dispatcher *DBJointModelDispatcher) ListMasterDescendent(ctx context.Context, idStr string, query jsonutils.JSONObject) (*modulebase.ListResult, error) {
|
||||
func (dispatcher *DBJointModelDispatcher) ListMasterDescendent(ctx context.Context, idStr string, query jsonutils.JSONObject) (*printutils.ListResult, error) {
|
||||
//log.Debugf("ListMasterDescendent %s %s", dispatcher.JointModelManager().GetMasterManager().Keyword(), idStr)
|
||||
userCred := fetchUserCredential(ctx)
|
||||
|
||||
@@ -85,7 +85,7 @@ func (dispatcher *DBJointModelDispatcher) ListMasterDescendent(ctx context.Conte
|
||||
return dispatcher._listJoint(ctx, userCred, model.(IStandaloneModel), queryDict)
|
||||
}
|
||||
|
||||
func (dispatcher *DBJointModelDispatcher) ListSlaveDescendent(ctx context.Context, idStr string, query jsonutils.JSONObject) (*modulebase.ListResult, error) {
|
||||
func (dispatcher *DBJointModelDispatcher) ListSlaveDescendent(ctx context.Context, idStr string, query jsonutils.JSONObject) (*printutils.ListResult, error) {
|
||||
//log.Debugf("ListSlaveDescendent %s %s", dispatcher.JointModelManager().GetMasterManager().Keyword(), idStr)
|
||||
userCred := fetchUserCredential(ctx)
|
||||
|
||||
@@ -112,7 +112,7 @@ func (dispatcher *DBJointModelDispatcher) ListSlaveDescendent(ctx context.Contex
|
||||
return dispatcher._listJoint(ctx, userCred, model.(IStandaloneModel), queryDict)
|
||||
}
|
||||
|
||||
func (dispatcher *DBJointModelDispatcher) _listJoint(ctx context.Context, userCred mcclient.TokenCredential, ctxModel IStandaloneModel, queryDict jsonutils.JSONObject) (*modulebase.ListResult, error) {
|
||||
func (dispatcher *DBJointModelDispatcher) _listJoint(ctx context.Context, userCred mcclient.TokenCredential, ctxModel IStandaloneModel, queryDict jsonutils.JSONObject) (*printutils.ListResult, error) {
|
||||
items, err := ListItems(dispatcher.JointModelManager(), ctx, userCred, queryDict, nil)
|
||||
if err != nil {
|
||||
log.Errorf("Fail to list items: %s", err)
|
||||
|
||||
@@ -20,6 +20,7 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/reflectutils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
@@ -28,7 +29,6 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
"yunion.io/x/onecloud/pkg/util/tagutils"
|
||||
)
|
||||
@@ -41,22 +41,22 @@ type SDomainizedResourceBase struct {
|
||||
DomainId string `width:"64" charset:"ascii" default:"default" nullable:"false" index:"true" list:"user" json:"domain_id"`
|
||||
}
|
||||
|
||||
func (manager *SDomainizedResourceBaseManager) NamespaceScope() rbacutils.TRbacScope {
|
||||
func (manager *SDomainizedResourceBaseManager) NamespaceScope() rbacscope.TRbacScope {
|
||||
if consts.IsDomainizedNamespace() {
|
||||
return rbacutils.ScopeDomain
|
||||
return rbacscope.ScopeDomain
|
||||
} else {
|
||||
return rbacutils.ScopeSystem
|
||||
return rbacscope.ScopeSystem
|
||||
}
|
||||
}
|
||||
|
||||
func (manager *SDomainizedResourceBaseManager) ResourceScope() rbacutils.TRbacScope {
|
||||
return rbacutils.ScopeDomain
|
||||
func (manager *SDomainizedResourceBaseManager) ResourceScope() rbacscope.TRbacScope {
|
||||
return rbacscope.ScopeDomain
|
||||
}
|
||||
|
||||
func (manager *SDomainizedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *SDomainizedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
if owner != nil {
|
||||
switch scope {
|
||||
case rbacutils.ScopeProject, rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeProject, rbacscope.ScopeDomain:
|
||||
q = q.Equals("domain_id", owner.GetProjectDomainId())
|
||||
}
|
||||
}
|
||||
|
||||
+24
-23
@@ -22,6 +22,7 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
@@ -309,21 +310,21 @@ func (m *sUsageManager) KeywordPlural() string {
|
||||
return "usages"
|
||||
}
|
||||
|
||||
func (m *sUsageManager) ResourceScope() rbacutils.TRbacScope {
|
||||
return rbacutils.ScopeProject
|
||||
func (m *sUsageManager) ResourceScope() rbacscope.TRbacScope {
|
||||
return rbacscope.ScopeProject
|
||||
}
|
||||
|
||||
func (m *sUsageManager) FetchOwnerId(ctx context.Context, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error) {
|
||||
return FetchProjectInfo(ctx, data)
|
||||
}
|
||||
|
||||
func FetchUsageOwnerScope(ctx context.Context, userCred mcclient.TokenCredential, data jsonutils.JSONObject) (mcclient.IIdentityProvider, rbacutils.TRbacScope, error, rbacutils.SPolicyResult) {
|
||||
func FetchUsageOwnerScope(ctx context.Context, userCred mcclient.TokenCredential, data jsonutils.JSONObject) (mcclient.IIdentityProvider, rbacscope.TRbacScope, error, rbacutils.SPolicyResult) {
|
||||
return FetchCheckQueryOwnerScope(ctx, userCred, data, &sUsageManager{}, policy.PolicyActionGet, true)
|
||||
}
|
||||
|
||||
type IScopedResourceManager interface {
|
||||
KeywordPlural() string
|
||||
ResourceScope() rbacutils.TRbacScope
|
||||
ResourceScope() rbacscope.TRbacScope
|
||||
FetchOwnerId(ctx context.Context, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error)
|
||||
}
|
||||
|
||||
@@ -334,12 +335,12 @@ func FetchCheckQueryOwnerScope(
|
||||
manager IScopedResourceManager,
|
||||
action string,
|
||||
doCheckRbac bool,
|
||||
) (mcclient.IIdentityProvider, rbacutils.TRbacScope, error, rbacutils.SPolicyResult) {
|
||||
var scope rbacutils.TRbacScope
|
||||
) (mcclient.IIdentityProvider, rbacscope.TRbacScope, error, rbacutils.SPolicyResult) {
|
||||
var scope rbacscope.TRbacScope
|
||||
|
||||
var allowScope rbacutils.TRbacScope
|
||||
var requireScope rbacutils.TRbacScope
|
||||
var queryScope rbacutils.TRbacScope
|
||||
var allowScope rbacscope.TRbacScope
|
||||
var requireScope rbacscope.TRbacScope
|
||||
var queryScope rbacscope.TRbacScope
|
||||
var policyTagFilters rbacutils.SPolicyResult
|
||||
|
||||
resScope := manager.ResourceScope()
|
||||
@@ -352,40 +353,40 @@ func FetchCheckQueryOwnerScope(
|
||||
}
|
||||
if ownerId != nil {
|
||||
switch resScope {
|
||||
case rbacutils.ScopeProject, rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeProject, rbacscope.ScopeDomain:
|
||||
if len(ownerId.GetProjectId()) > 0 {
|
||||
queryScope = rbacutils.ScopeProject
|
||||
queryScope = rbacscope.ScopeProject
|
||||
if ownerId.GetProjectId() == userCred.GetProjectId() {
|
||||
requireScope = rbacutils.ScopeProject
|
||||
requireScope = rbacscope.ScopeProject
|
||||
} else if ownerId.GetProjectDomainId() == userCred.GetProjectDomainId() {
|
||||
requireScope = rbacutils.ScopeDomain
|
||||
requireScope = rbacscope.ScopeDomain
|
||||
} else {
|
||||
requireScope = rbacutils.ScopeSystem
|
||||
requireScope = rbacscope.ScopeSystem
|
||||
}
|
||||
} else if len(ownerId.GetProjectDomainId()) > 0 {
|
||||
queryScope = rbacutils.ScopeDomain
|
||||
queryScope = rbacscope.ScopeDomain
|
||||
if ownerId.GetProjectDomainId() == userCred.GetProjectDomainId() {
|
||||
requireScope = rbacutils.ScopeDomain
|
||||
requireScope = rbacscope.ScopeDomain
|
||||
} else {
|
||||
requireScope = rbacutils.ScopeSystem
|
||||
requireScope = rbacscope.ScopeSystem
|
||||
}
|
||||
}
|
||||
case rbacutils.ScopeUser:
|
||||
queryScope = rbacutils.ScopeUser
|
||||
case rbacscope.ScopeUser:
|
||||
queryScope = rbacscope.ScopeUser
|
||||
if ownerId.GetUserId() == userCred.GetUserId() {
|
||||
requireScope = rbacutils.ScopeUser
|
||||
requireScope = rbacscope.ScopeUser
|
||||
} else {
|
||||
requireScope = rbacutils.ScopeSystem
|
||||
requireScope = rbacscope.ScopeSystem
|
||||
}
|
||||
}
|
||||
} else {
|
||||
ownerId = userCred
|
||||
reqScopeStr, _ := data.GetString("scope")
|
||||
if len(reqScopeStr) > 0 {
|
||||
queryScope = rbacutils.String2Scope(reqScopeStr)
|
||||
queryScope = rbacscope.String2Scope(reqScopeStr)
|
||||
} else if data.Contains("admin") {
|
||||
isAdmin := jsonutils.QueryBoolean(data, "admin", false)
|
||||
if isAdmin && allowScope.HigherThan(rbacutils.ScopeProject) {
|
||||
if isAdmin && allowScope.HigherThan(rbacscope.ScopeProject) {
|
||||
queryScope = allowScope
|
||||
}
|
||||
} else if action == policy.PolicyActionGet {
|
||||
|
||||
@@ -19,13 +19,13 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/apis"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
@@ -54,7 +54,7 @@ func (manager *SInfrasResourceBaseManager) GetIInfrasModelManager() IInfrasModel
|
||||
return manager.GetVirtualObject().(IInfrasModelManager)
|
||||
}
|
||||
|
||||
func (manager *SInfrasResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *SInfrasResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
return SharableManagerFilterByOwner(manager.GetIInfrasModelManager(), q, owner, scope)
|
||||
}
|
||||
|
||||
@@ -215,16 +215,16 @@ func (model *SInfrasResourceBase) Delete(ctx context.Context, userCred mcclient.
|
||||
func (model *SInfrasResourceBase) GetSharedInfo() apis.SShareInfo {
|
||||
ret := apis.SShareInfo{}
|
||||
ret.IsPublic = model.IsPublic
|
||||
ret.PublicScope = rbacutils.String2ScopeDefault(model.PublicScope, rbacutils.ScopeNone)
|
||||
ret.PublicScope = rbacscope.String2ScopeDefault(model.PublicScope, rbacscope.ScopeNone)
|
||||
ret.SharedDomains = model.GetSharedDomains()
|
||||
ret.SharedProjects = nil
|
||||
// fix
|
||||
if len(ret.SharedDomains) > 0 {
|
||||
ret.PublicScope = rbacutils.ScopeDomain
|
||||
ret.PublicScope = rbacscope.ScopeDomain
|
||||
ret.SharedProjects = nil
|
||||
ret.IsPublic = true
|
||||
} else if !ret.IsPublic {
|
||||
ret.PublicScope = rbacutils.ScopeNone
|
||||
ret.PublicScope = rbacscope.ScopeNone
|
||||
}
|
||||
return ret
|
||||
}
|
||||
@@ -248,7 +248,7 @@ func (model *SInfrasResourceBase) SyncShareState(ctx context.Context, userCred m
|
||||
if model.PublicSrc != string(apis.OWNER_SOURCE_LOCAL) {
|
||||
model.SaveSharedInfo(apis.OWNER_SOURCE_CLOUD, ctx, userCred, apis.SShareInfo{
|
||||
IsPublic: true,
|
||||
PublicScope: rbacutils.ScopeSystem,
|
||||
PublicScope: rbacscope.ScopeSystem,
|
||||
})
|
||||
}
|
||||
return
|
||||
|
||||
@@ -20,13 +20,13 @@ import (
|
||||
"time"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/object"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/appsrv"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/db/lockman"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/object"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/splitable"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
@@ -75,9 +75,9 @@ type IModelManager interface {
|
||||
FilterById(q *sqlchemy.SQuery, idStr string) *sqlchemy.SQuery
|
||||
FilterByNotId(q *sqlchemy.SQuery, idStr string) *sqlchemy.SQuery
|
||||
FilterByName(q *sqlchemy.SQuery, name string) *sqlchemy.SQuery
|
||||
FilterByOwner(q *sqlchemy.SQuery, userCred mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery
|
||||
FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery
|
||||
FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery
|
||||
FilterByOwner(q *sqlchemy.SQuery, userCred mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery
|
||||
FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery
|
||||
FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery
|
||||
FilterByUniqValues(q *sqlchemy.SQuery, uniqValues jsonutils.JSONObject) *sqlchemy.SQuery
|
||||
|
||||
// GetOwnerId(userCred mcclient.IIdentityProvider) mcclient.IIdentityProvider
|
||||
@@ -125,8 +125,8 @@ type IModelManager interface {
|
||||
FetchUniqValues(ctx context.Context, data jsonutils.JSONObject) jsonutils.JSONObject
|
||||
|
||||
/* name uniqueness scope, system/domain/project, default is system */
|
||||
NamespaceScope() rbacutils.TRbacScope
|
||||
ResourceScope() rbacutils.TRbacScope
|
||||
NamespaceScope() rbacscope.TRbacScope
|
||||
ResourceScope() rbacscope.TRbacScope
|
||||
|
||||
// 如果error为非空,说明没有匹配的field,如果为空,说明匹配上了
|
||||
QueryDistinctExtraField(q *sqlchemy.SQuery, field string) (*sqlchemy.SQuery, error)
|
||||
|
||||
@@ -22,12 +22,12 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/reflectutils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/apis"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
@@ -171,12 +171,12 @@ func (joint *SJointResourceBase) GetIJointModel() IJointModel {
|
||||
return joint.GetVirtualObject().(IJointModel)
|
||||
}
|
||||
|
||||
func (manager *SJointResourceBaseManager) ResourceScope() rbacutils.TRbacScope {
|
||||
func (manager *SJointResourceBaseManager) ResourceScope() rbacscope.TRbacScope {
|
||||
return manager.GetMasterManager().ResourceScope()
|
||||
}
|
||||
|
||||
func (manager *SJointResourceBaseManager) NamespaceScope() rbacutils.TRbacScope {
|
||||
return rbacutils.ScopeSystem
|
||||
func (manager *SJointResourceBaseManager) NamespaceScope() rbacscope.TRbacScope {
|
||||
return rbacscope.ScopeSystem
|
||||
}
|
||||
|
||||
func (manager *SJointResourceBaseManager) ValidateCreateData(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, input apis.JoinResourceBaseCreateInput) (apis.JoinResourceBaseCreateInput, error) {
|
||||
|
||||
@@ -15,14 +15,15 @@
|
||||
package db
|
||||
|
||||
import (
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
func GetLockClassKey(manager IModelManager, ownerId mcclient.IIdentityProvider) string {
|
||||
if manager.NamespaceScope() == rbacutils.ScopeSystem {
|
||||
if manager.NamespaceScope() == rbacscope.ScopeSystem {
|
||||
return ""
|
||||
} else if manager.NamespaceScope() == rbacutils.ScopeDomain {
|
||||
} else if manager.NamespaceScope() == rbacscope.ScopeDomain {
|
||||
return ownerId.GetProjectDomainId()
|
||||
} else {
|
||||
return ownerId.GetProjectId()
|
||||
|
||||
@@ -24,6 +24,8 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/printutils"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/stringutils"
|
||||
"yunion.io/x/pkg/utils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
@@ -35,8 +37,6 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/policy"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/modulebase"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
const (
|
||||
@@ -223,7 +223,7 @@ func (manager *SMetadataManager) GetPropertyTagValuePairs(
|
||||
ctx context.Context,
|
||||
userCred mcclient.TokenCredential,
|
||||
input apis.MetaGetPropertyTagValuePairsInput,
|
||||
) (*modulebase.ListResult, error) {
|
||||
) (*printutils.ListResult, error) {
|
||||
q, err := manager.fetchKeyValueQuery(ctx, userCred, input)
|
||||
if err != nil {
|
||||
return nil, errors.Wrap(err, "fetchKeyValueQuery")
|
||||
@@ -235,7 +235,7 @@ func (manager *SMetadataManager) GetPropertyTagValuePairs(
|
||||
}
|
||||
|
||||
if totalCnt == 0 {
|
||||
emptyList := modulebase.ListResult{Data: []jsonutils.JSONObject{}}
|
||||
emptyList := printutils.ListResult{Data: []jsonutils.JSONObject{}}
|
||||
return &emptyList, nil
|
||||
}
|
||||
|
||||
@@ -268,7 +268,7 @@ func (manager *SMetadataManager) GetPropertyTagValuePairs(
|
||||
if err != nil {
|
||||
return nil, errors.Wrap(err, "metadataQuery2List")
|
||||
}
|
||||
emptyList := modulebase.ListResult{
|
||||
emptyList := printutils.ListResult{
|
||||
Data: data,
|
||||
Total: totalCnt,
|
||||
Limit: int(limit),
|
||||
@@ -383,7 +383,7 @@ func (manager *SMetadataManager) ListItemFilter(ctx context.Context, q *sqlchemy
|
||||
))
|
||||
}
|
||||
|
||||
if !(input.Scope == string(rbacutils.ScopeSystem) && userCred.HasSystemAdminPrivilege()) {
|
||||
if !(input.Scope == string(rbacscope.ScopeSystem) && userCred.HasSystemAdminPrivilege()) {
|
||||
resources := input.Resources
|
||||
if len(resources) == 0 {
|
||||
for resource := range globalTables {
|
||||
@@ -432,7 +432,7 @@ func (manager *SMetadataManager) ListItemFilter(ctx context.Context, q *sqlchemy
|
||||
}
|
||||
|
||||
func (manager *SMetadataManager) GetStringValue(ctx context.Context, model IModel, key string, userCred mcclient.TokenCredential) string {
|
||||
if strings.HasPrefix(key, SYSTEM_ADMIN_PREFIX) && (userCred == nil || !IsAllowGetSpec(ctx, rbacutils.ScopeSystem, userCred, model, "metadata")) {
|
||||
if strings.HasPrefix(key, SYSTEM_ADMIN_PREFIX) && (userCred == nil || !IsAllowGetSpec(ctx, rbacscope.ScopeSystem, userCred, model, "metadata")) {
|
||||
return ""
|
||||
}
|
||||
idStr := GetModelIdstr(model)
|
||||
@@ -445,7 +445,7 @@ func (manager *SMetadataManager) GetStringValue(ctx context.Context, model IMode
|
||||
}
|
||||
|
||||
func (manager *SMetadataManager) GetJsonValue(ctx context.Context, model IModel, key string, userCred mcclient.TokenCredential) jsonutils.JSONObject {
|
||||
if strings.HasPrefix(key, SYSTEM_ADMIN_PREFIX) && (userCred == nil || !IsAllowGetSpec(ctx, rbacutils.ScopeSystem, userCred, model, "metadata")) {
|
||||
if strings.HasPrefix(key, SYSTEM_ADMIN_PREFIX) && (userCred == nil || !IsAllowGetSpec(ctx, rbacscope.ScopeSystem, userCred, model, "metadata")) {
|
||||
return nil
|
||||
}
|
||||
idStr := GetModelIdstr(model)
|
||||
@@ -645,7 +645,7 @@ func (manager *SMetadataManager) GetAll(ctx context.Context, obj IModel, keys []
|
||||
}
|
||||
ret := make(map[string]string)
|
||||
for k, v := range meta {
|
||||
if strings.HasPrefix(k, SYSTEM_ADMIN_PREFIX) && (userCred == nil || !IsAllowGetSpec(ctx, rbacutils.ScopeSystem, userCred, obj, "metadata")) {
|
||||
if strings.HasPrefix(k, SYSTEM_ADMIN_PREFIX) && (userCred == nil || !IsAllowGetSpec(ctx, rbacscope.ScopeSystem, userCred, obj, "metadata")) {
|
||||
continue
|
||||
}
|
||||
ret[k] = v
|
||||
|
||||
@@ -19,6 +19,7 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/apis"
|
||||
@@ -33,14 +34,14 @@ type SMetadataResourceBaseModelManager struct{}
|
||||
|
||||
func ObjectIdQueryWithPolicyResult(q *sqlchemy.SQuery, manager IModelManager, result rbacutils.SPolicyResult) *sqlchemy.SQuery {
|
||||
scope := manager.ResourceScope()
|
||||
if scope == rbacutils.ScopeDomain || scope == rbacutils.ScopeProject {
|
||||
if scope == rbacscope.ScopeDomain || scope == rbacscope.ScopeProject {
|
||||
if !result.DomainTags.IsEmpty() {
|
||||
tagFilters := tagutils.STagFilters{}
|
||||
tagFilters.AddFilters(result.DomainTags)
|
||||
q = ObjectIdQueryWithTagFilters(q, "domain_id", "domain", tagFilters)
|
||||
}
|
||||
}
|
||||
if scope == rbacutils.ScopeProject {
|
||||
if scope == rbacscope.ScopeProject {
|
||||
if !result.ProjectTags.IsEmpty() {
|
||||
tagFilters := tagutils.STagFilters{}
|
||||
tagFilters.AddFilters(result.ProjectTags)
|
||||
|
||||
@@ -23,16 +23,16 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/object"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/version"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/apis"
|
||||
"yunion.io/x/onecloud/pkg/appsrv"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/object"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/policy"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/splitable"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
@@ -232,15 +232,15 @@ func (manager *SModelBaseManager) FilterByName(q *sqlchemy.SQuery, name string)
|
||||
return q
|
||||
}
|
||||
|
||||
func (manager *SModelBaseManager) FilterByOwner(q *sqlchemy.SQuery, ownerId mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *SModelBaseManager) FilterByOwner(q *sqlchemy.SQuery, ownerId mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
return q
|
||||
}
|
||||
|
||||
func (manager *SModelBaseManager) FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *SModelBaseManager) FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
return q
|
||||
}
|
||||
|
||||
func (manager *SModelBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *SModelBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
return q
|
||||
}
|
||||
|
||||
@@ -346,12 +346,12 @@ func (manager *SModelBaseManager) FetchUniqValues(ctx context.Context, data json
|
||||
return nil
|
||||
}
|
||||
|
||||
func (manager *SModelBaseManager) NamespaceScope() rbacutils.TRbacScope {
|
||||
return rbacutils.ScopeSystem
|
||||
func (manager *SModelBaseManager) NamespaceScope() rbacscope.TRbacScope {
|
||||
return rbacscope.ScopeSystem
|
||||
}
|
||||
|
||||
func (manager *SModelBaseManager) ResourceScope() rbacutils.TRbacScope {
|
||||
return rbacutils.ScopeSystem
|
||||
func (manager *SModelBaseManager) ResourceScope() rbacscope.TRbacScope {
|
||||
return rbacscope.ScopeSystem
|
||||
}
|
||||
|
||||
func (manager *SModelBaseManager) AllowGetPropertyDistinctField(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject) bool {
|
||||
|
||||
@@ -25,6 +25,7 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/reflectutils"
|
||||
"yunion.io/x/pkg/util/stringutils"
|
||||
"yunion.io/x/pkg/util/timeutils"
|
||||
@@ -35,7 +36,6 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
@@ -358,17 +358,17 @@ func (manager *SOpsLogManager) LogSyncUpdate(m IModel, uds sqlchemy.UpdateDiffs,
|
||||
}
|
||||
}
|
||||
|
||||
func (self *SOpsLogManager) FilterByOwner(q *sqlchemy.SQuery, ownerId mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (self *SOpsLogManager) FilterByOwner(q *sqlchemy.SQuery, ownerId mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
if ownerId != nil {
|
||||
switch scope {
|
||||
case rbacutils.ScopeUser:
|
||||
case rbacscope.ScopeUser:
|
||||
if len(ownerId.GetUserId()) > 0 {
|
||||
/*
|
||||
* 默认只能查看本人发起的操作
|
||||
*/
|
||||
q = q.Filter(sqlchemy.Equals(q.Field("user_id"), ownerId.GetUserId()))
|
||||
}
|
||||
case rbacutils.ScopeProject:
|
||||
case rbacscope.ScopeProject:
|
||||
if len(ownerId.GetProjectId()) > 0 {
|
||||
/*
|
||||
* 项目视图可以查看本项目人员发起的操作,或者对本项目资源实施的操作, QIU Jian
|
||||
@@ -378,7 +378,7 @@ func (self *SOpsLogManager) FilterByOwner(q *sqlchemy.SQuery, ownerId mcclient.I
|
||||
sqlchemy.Equals(q.Field("owner_tenant_id"), ownerId.GetProjectId()),
|
||||
))
|
||||
}
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
if len(ownerId.GetProjectDomainId()) > 0 {
|
||||
/*
|
||||
* 域视图可以查看本域人员发起的操作,或者对本域资源实施的操作, QIU Jian
|
||||
@@ -413,8 +413,8 @@ func (self *SOpsLog) IsSharable(reqCred mcclient.IIdentityProvider) bool {
|
||||
return false
|
||||
}
|
||||
|
||||
func (manager *SOpsLogManager) ResourceScope() rbacutils.TRbacScope {
|
||||
return rbacutils.ScopeUser
|
||||
func (manager *SOpsLogManager) ResourceScope() rbacscope.TRbacScope {
|
||||
return rbacscope.ScopeUser
|
||||
}
|
||||
|
||||
func (manager *SOpsLogManager) FetchOwnerId(ctx context.Context, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error) {
|
||||
|
||||
@@ -21,6 +21,7 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/reflectutils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
@@ -29,7 +30,6 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
"yunion.io/x/onecloud/pkg/util/tagutils"
|
||||
)
|
||||
@@ -50,12 +50,12 @@ func (model *SProjectizedResourceBase) GetOwnerId() mcclient.IIdentityProvider {
|
||||
return &owner
|
||||
}
|
||||
|
||||
func (manager *SProjectizedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *SProjectizedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
if owner != nil {
|
||||
switch scope {
|
||||
case rbacutils.ScopeProject:
|
||||
case rbacscope.ScopeProject:
|
||||
q = q.Equals("tenant_id", owner.GetProjectId())
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
q = q.Equals("domain_id", owner.GetProjectDomainId())
|
||||
}
|
||||
/*if len(owner.GetProjectId()) > 0 {
|
||||
@@ -67,8 +67,8 @@ func (manager *SProjectizedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery
|
||||
return q
|
||||
}
|
||||
|
||||
func (manager *SProjectizedResourceBaseManager) ResourceScope() rbacutils.TRbacScope {
|
||||
return rbacutils.ScopeProject
|
||||
func (manager *SProjectizedResourceBaseManager) ResourceScope() rbacscope.TRbacScope {
|
||||
return rbacscope.ScopeProject
|
||||
}
|
||||
|
||||
func (manager *SProjectizedResourceBaseManager) FetchOwnerId(ctx context.Context, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error) {
|
||||
|
||||
@@ -27,13 +27,13 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/httputils"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
|
||||
proxyapi "yunion.io/x/onecloud/pkg/apis/cloudcommon/proxy"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/db"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/httputils"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
type SProxySettingManager struct {
|
||||
@@ -198,10 +198,10 @@ func (man *SProxySettingManager) InitializeData() error {
|
||||
psObj, err := man.FetchById(proxyapi.ProxySettingId_DIRECT)
|
||||
if err == nil {
|
||||
ps := psObj.(*SProxySetting)
|
||||
if !ps.IsPublic || ps.PublicScope != string(rbacutils.ScopeSystem) {
|
||||
if !ps.IsPublic || ps.PublicScope != string(rbacscope.ScopeSystem) {
|
||||
_, err = db.Update(ps, func() error {
|
||||
ps.IsPublic = true
|
||||
ps.PublicScope = string(rbacutils.ScopeSystem)
|
||||
ps.PublicScope = string(rbacscope.ScopeSystem)
|
||||
return nil
|
||||
})
|
||||
if err != nil {
|
||||
@@ -223,7 +223,7 @@ func (man *SProxySettingManager) InitializeData() error {
|
||||
ps.Name = proxyapi.ProxySettingId_DIRECT
|
||||
ps.Description = "Connect directly"
|
||||
ps.IsPublic = true
|
||||
ps.PublicScope = string(rbacutils.ScopeSystem)
|
||||
ps.PublicScope = string(rbacscope.ScopeSystem)
|
||||
if err := man.TableSpec().Insert(context.Background(), ps); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
@@ -18,10 +18,10 @@ import (
|
||||
"context"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
func FetchQueryDomain(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject) (string, error) {
|
||||
@@ -34,8 +34,8 @@ func FetchQueryDomain(ctx context.Context, userCred mcclient.TokenCredential, qu
|
||||
domainId = domainInfo.GetProjectDomainId()
|
||||
}
|
||||
scopeStr, _ := query.GetString("scope")
|
||||
queryScope := rbacutils.String2ScopeDefault(scopeStr, rbacutils.ScopeDomain)
|
||||
if queryScope != rbacutils.ScopeSystem && len(domainId) == 0 {
|
||||
queryScope := rbacscope.String2ScopeDefault(scopeStr, rbacscope.ScopeDomain)
|
||||
if queryScope != rbacscope.ScopeSystem && len(domainId) == 0 {
|
||||
domainId = userCred.GetProjectDomainId()
|
||||
}
|
||||
return domainId, nil
|
||||
|
||||
@@ -19,9 +19,9 @@ import (
|
||||
"context"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/appctx"
|
||||
"yunion.io/x/pkg/errors"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/appctx"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
)
|
||||
|
||||
|
||||
@@ -18,12 +18,13 @@ import (
|
||||
"fmt"
|
||||
"strings"
|
||||
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
type SOutOfQuotaError struct {
|
||||
scope rbacutils.TRbacScope
|
||||
scope rbacscope.TRbacScope
|
||||
name string
|
||||
limit int
|
||||
used int
|
||||
|
||||
@@ -25,10 +25,11 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/appctx"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/reflectutils"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/appctx"
|
||||
"yunion.io/x/onecloud/pkg/appsrv"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/db"
|
||||
@@ -36,7 +37,6 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/auth"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
const (
|
||||
@@ -101,7 +101,7 @@ func AddQuotaHandler(manager *SQuotaBaseManager, prefix string, app *appsrv.Appl
|
||||
fmt.Sprintf("%s/%s/domains/<domainid>/pending", prefix, manager.KeywordPlural()),
|
||||
auth.Authenticate(manager.cleanPendingUsageHandler), nil, "clean_pending_usage_for_domain", nil)
|
||||
|
||||
if manager.scope == rbacutils.ScopeProject {
|
||||
if manager.scope == rbacscope.ScopeProject {
|
||||
app.AddHandler2("GET",
|
||||
fmt.Sprintf("%s/%s/<tenantid>", prefix, manager.KeywordPlural()),
|
||||
auth.Authenticate(manager.getQuotaHandler), nil, "get_quota_for_project", nil)
|
||||
@@ -177,7 +177,7 @@ func (manager *SQuotaBaseManager) getQuotaHandler(ctx context.Context, w http.Re
|
||||
userCred := auth.FetchUserCredential(ctx, policy.FilterPolicyCredential)
|
||||
|
||||
var ownerId mcclient.IIdentityProvider
|
||||
var scope rbacutils.TRbacScope
|
||||
var scope rbacscope.TRbacScope
|
||||
var err error
|
||||
|
||||
projectId := params["<tenantid>"]
|
||||
@@ -196,10 +196,10 @@ func (manager *SQuotaBaseManager) getQuotaHandler(ctx context.Context, w http.Re
|
||||
}
|
||||
} else {
|
||||
scopeStr, _ := query.GetString("scope")
|
||||
if scopeStr == "project" && manager.scope == rbacutils.ScopeProject {
|
||||
scope = rbacutils.ScopeProject
|
||||
if scopeStr == "project" && manager.scope == rbacscope.ScopeProject {
|
||||
scope = rbacscope.ScopeProject
|
||||
} else if scopeStr == "domain" {
|
||||
scope = rbacutils.ScopeDomain
|
||||
scope = rbacscope.ScopeDomain
|
||||
} else {
|
||||
scope = manager.scope
|
||||
}
|
||||
@@ -209,7 +209,7 @@ func (manager *SQuotaBaseManager) getQuotaHandler(ctx context.Context, w http.Re
|
||||
keys := OwnerIdProjectQuotaKeys(scope, ownerId)
|
||||
refresh := jsonutils.QueryBoolean(query, "refresh", false)
|
||||
primary := jsonutils.QueryBoolean(query, "primary", false)
|
||||
quotaList, err := manager.listQuotas(ctx, userCred, keys.DomainId, keys.ProjectId, scope == rbacutils.ScopeDomain, primary, refresh)
|
||||
quotaList, err := manager.listQuotas(ctx, userCred, keys.DomainId, keys.ProjectId, scope == rbacscope.ScopeDomain, primary, refresh)
|
||||
if err != nil {
|
||||
httperrors.GeneralServerError(ctx, w, err)
|
||||
return
|
||||
@@ -217,7 +217,7 @@ func (manager *SQuotaBaseManager) getQuotaHandler(ctx context.Context, w http.Re
|
||||
if len(quotaList) == 0 {
|
||||
quota := manager.newQuota()
|
||||
var baseKeys IQuotaKeys
|
||||
if manager.scope == rbacutils.ScopeProject {
|
||||
if manager.scope == rbacscope.ScopeProject {
|
||||
baseKeys = OwnerIdProjectQuotaKeys(scope, ownerId)
|
||||
} else {
|
||||
baseKeys = OwnerIdDomainQuotaKeys(ownerId)
|
||||
@@ -226,7 +226,7 @@ func (manager *SQuotaBaseManager) getQuotaHandler(ctx context.Context, w http.Re
|
||||
quota.FetchSystemQuota()
|
||||
manager.SetQuota(ctx, userCred, quota)
|
||||
|
||||
quotaList, err = manager.listQuotas(ctx, userCred, keys.DomainId, keys.ProjectId, scope == rbacutils.ScopeDomain, primary, refresh)
|
||||
quotaList, err = manager.listQuotas(ctx, userCred, keys.DomainId, keys.ProjectId, scope == rbacscope.ScopeDomain, primary, refresh)
|
||||
if err != nil {
|
||||
httperrors.GeneralServerError(ctx, w, err)
|
||||
return
|
||||
@@ -242,45 +242,45 @@ func (manager *SQuotaBaseManager) fetchSetQuotaScope(
|
||||
isBaseQuotaKeys bool,
|
||||
) (
|
||||
mcclient.IIdentityProvider,
|
||||
rbacutils.TRbacScope,
|
||||
rbacutils.TRbacScope,
|
||||
rbacscope.TRbacScope,
|
||||
rbacscope.TRbacScope,
|
||||
error,
|
||||
) {
|
||||
var scope rbacutils.TRbacScope
|
||||
var scope rbacscope.TRbacScope
|
||||
ownerId, err := db.FetchProjectInfo(ctx, data)
|
||||
if err != nil {
|
||||
return nil, scope, scope, err
|
||||
}
|
||||
var requestScope rbacutils.TRbacScope
|
||||
var requestScope rbacscope.TRbacScope
|
||||
if ownerId != nil {
|
||||
if len(ownerId.GetProjectId()) > 0 {
|
||||
// project level
|
||||
scope = rbacutils.ScopeProject
|
||||
scope = rbacscope.ScopeProject
|
||||
if ownerId.GetProjectDomainId() == userCred.GetProjectDomainId() {
|
||||
if isBaseQuotaKeys || ownerId.GetProjectId() != userCred.GetProjectId() {
|
||||
requestScope = rbacutils.ScopeDomain
|
||||
requestScope = rbacscope.ScopeDomain
|
||||
} else {
|
||||
requestScope = rbacutils.ScopeProject
|
||||
requestScope = rbacscope.ScopeProject
|
||||
}
|
||||
} else {
|
||||
requestScope = rbacutils.ScopeSystem
|
||||
requestScope = rbacscope.ScopeSystem
|
||||
}
|
||||
} else {
|
||||
// domain level if len(ownerId.GetProjectDomainId()) > 0 {
|
||||
scope = rbacutils.ScopeDomain
|
||||
scope = rbacscope.ScopeDomain
|
||||
if isBaseQuotaKeys || ownerId.GetProjectDomainId() != userCred.GetProjectDomainId() {
|
||||
requestScope = rbacutils.ScopeSystem
|
||||
requestScope = rbacscope.ScopeSystem
|
||||
} else {
|
||||
requestScope = rbacutils.ScopeDomain
|
||||
requestScope = rbacscope.ScopeDomain
|
||||
}
|
||||
}
|
||||
} else {
|
||||
ownerId = userCred
|
||||
scope = rbacutils.ScopeProject
|
||||
scope = rbacscope.ScopeProject
|
||||
if isBaseQuotaKeys {
|
||||
requestScope = rbacutils.ScopeDomain
|
||||
requestScope = rbacscope.ScopeDomain
|
||||
} else {
|
||||
requestScope = rbacutils.ScopeProject
|
||||
requestScope = rbacscope.ScopeProject
|
||||
}
|
||||
}
|
||||
|
||||
@@ -292,7 +292,7 @@ func (manager *SQuotaBaseManager) cleanPendingUsageHandler(ctx context.Context,
|
||||
userCred := auth.FetchUserCredential(ctx, policy.FilterPolicyCredential)
|
||||
|
||||
var ownerId mcclient.IIdentityProvider
|
||||
var scope rbacutils.TRbacScope
|
||||
var scope rbacscope.TRbacScope
|
||||
var err error
|
||||
|
||||
projectId := params["<tenantid>"]
|
||||
@@ -312,16 +312,16 @@ func (manager *SQuotaBaseManager) cleanPendingUsageHandler(ctx context.Context,
|
||||
} else {
|
||||
scopeStr, _ := query.GetString("scope")
|
||||
if scopeStr == "project" {
|
||||
scope = rbacutils.ScopeProject
|
||||
scope = rbacscope.ScopeProject
|
||||
} else if scopeStr == "domain" {
|
||||
scope = rbacutils.ScopeDomain
|
||||
scope = rbacscope.ScopeDomain
|
||||
} else {
|
||||
scope = manager.scope
|
||||
}
|
||||
ownerId = userCred
|
||||
}
|
||||
var keys IQuotaKeys
|
||||
if manager.scope == rbacutils.ScopeProject {
|
||||
if manager.scope == rbacscope.ScopeProject {
|
||||
keys = OwnerIdProjectQuotaKeys(scope, ownerId)
|
||||
} else {
|
||||
keys = OwnerIdDomainQuotaKeys(ownerId)
|
||||
@@ -358,7 +358,7 @@ func (manager *SQuotaBaseManager) setQuotaHandler(ctx context.Context, w http.Re
|
||||
|
||||
// check is there any nonempty key other than domain_id and project_id
|
||||
isBaseQuota := false
|
||||
if manager.scope == rbacutils.ScopeDomain {
|
||||
if manager.scope == rbacscope.ScopeDomain {
|
||||
isBaseQuota = IsBaseDomainQuotaKeys(quota.GetKeys())
|
||||
} else {
|
||||
isBaseQuota = IsBaseProjectQuotaKeys(quota.GetKeys())
|
||||
@@ -371,7 +371,7 @@ func (manager *SQuotaBaseManager) setQuotaHandler(ctx context.Context, w http.Re
|
||||
|
||||
// fill project_id and domain_id
|
||||
var baseKeys IQuotaKeys
|
||||
if manager.scope == rbacutils.ScopeDomain {
|
||||
if manager.scope == rbacscope.ScopeDomain {
|
||||
baseKeys = OwnerIdDomainQuotaKeys(ownerId)
|
||||
} else {
|
||||
baseKeys = OwnerIdProjectQuotaKeys(scope, ownerId)
|
||||
@@ -455,7 +455,7 @@ func (manager *SQuotaBaseManager) setQuotaHandler(ctx context.Context, w http.Re
|
||||
}
|
||||
}
|
||||
|
||||
quotaList, err := manager.listQuotas(ctx, userCred, baseKeys.OwnerId().GetProjectDomainId(), baseKeys.OwnerId().GetProjectId(), scope == rbacutils.ScopeDomain, false, true)
|
||||
quotaList, err := manager.listQuotas(ctx, userCred, baseKeys.OwnerId().GetProjectDomainId(), baseKeys.OwnerId().GetProjectId(), scope == rbacscope.ScopeDomain, false, true)
|
||||
if err != nil {
|
||||
httperrors.GeneralServerError(ctx, w, err)
|
||||
return
|
||||
@@ -468,7 +468,7 @@ func (manager *SQuotaBaseManager) listDomainQuotaHandler(ctx context.Context, w
|
||||
userCred := auth.FetchUserCredential(ctx, policy.FilterPolicyCredential)
|
||||
|
||||
allowScope, policyResult := policy.PolicyManager.AllowScope(userCred, consts.GetServiceType(), manager.KeywordPlural(), policy.PolicyActionList)
|
||||
if policyResult.Result.IsAllow() && allowScope != rbacutils.ScopeSystem {
|
||||
if policyResult.Result.IsAllow() && allowScope != rbacscope.ScopeSystem {
|
||||
httperrors.ForbiddenError(ctx, w, "not allow to list domain quotas")
|
||||
return
|
||||
}
|
||||
@@ -502,7 +502,7 @@ func (manager *SQuotaBaseManager) listProjectQuotaHandler(ctx context.Context, w
|
||||
}
|
||||
|
||||
allowScope, _ := policy.PolicyManager.AllowScope(userCred, consts.GetServiceType(), manager.KeywordPlural(), policy.PolicyActionList)
|
||||
if (allowScope == rbacutils.ScopeDomain && userCred.GetProjectDomainId() == owner.GetProjectDomainId()) || allowScope == rbacutils.ScopeSystem {
|
||||
if (allowScope == rbacscope.ScopeDomain && userCred.GetProjectDomainId() == owner.GetProjectDomainId()) || allowScope == rbacscope.ScopeSystem {
|
||||
} else {
|
||||
httperrors.ForbiddenError(ctx, w, "not allow to list project quotas")
|
||||
return
|
||||
@@ -524,7 +524,7 @@ func (manager *SQuotaBaseManager) listQuotas(ctx context.Context, userCred mccli
|
||||
if len(targetDomainId) > 0 {
|
||||
q = q.Equals("domain_id", targetDomainId)
|
||||
if domainOnly {
|
||||
if manager.scope == rbacutils.ScopeProject {
|
||||
if manager.scope == rbacscope.ScopeProject {
|
||||
q = q.IsEmpty("tenant_id")
|
||||
}
|
||||
} else {
|
||||
@@ -540,7 +540,7 @@ func (manager *SQuotaBaseManager) listQuotas(ctx context.Context, userCred mccli
|
||||
} else {
|
||||
// domain only
|
||||
q = q.IsNotEmpty("domain_id")
|
||||
if manager.scope == rbacutils.ScopeProject {
|
||||
if manager.scope == rbacscope.ScopeProject {
|
||||
q = q.IsNullOrEmpty("tenant_id")
|
||||
}
|
||||
}
|
||||
|
||||
@@ -18,11 +18,11 @@ import (
|
||||
"context"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/object"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/db"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/object"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
type IQuotaKeys interface {
|
||||
@@ -32,7 +32,7 @@ type IQuotaKeys interface {
|
||||
|
||||
OwnerId() mcclient.IIdentityProvider
|
||||
|
||||
Scope() rbacutils.TRbacScope
|
||||
Scope() rbacscope.TRbacScope
|
||||
}
|
||||
|
||||
type IQuota interface {
|
||||
|
||||
@@ -22,13 +22,13 @@ import (
|
||||
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/reflectutils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
identityapi "yunion.io/x/onecloud/pkg/apis/identity"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/db"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
type SQuotaBaseManager struct {
|
||||
@@ -39,10 +39,10 @@ type SQuotaBaseManager struct {
|
||||
|
||||
nonNegative bool
|
||||
|
||||
scope rbacutils.TRbacScope
|
||||
scope rbacscope.TRbacScope
|
||||
}
|
||||
|
||||
func NewQuotaBaseManager(model interface{}, scope rbacutils.TRbacScope, tableName string, pendingStore IQuotaStore, usageStore IQuotaStore, keyword, keywordPlural string) SQuotaBaseManager {
|
||||
func NewQuotaBaseManager(model interface{}, scope rbacscope.TRbacScope, tableName string, pendingStore IQuotaStore, usageStore IQuotaStore, keyword, keywordPlural string) SQuotaBaseManager {
|
||||
pendingStore.SetVirtualObject(pendingStore)
|
||||
usageStore.SetVirtualObject(usageStore)
|
||||
return SQuotaBaseManager{
|
||||
@@ -54,7 +54,7 @@ func NewQuotaBaseManager(model interface{}, scope rbacutils.TRbacScope, tableNam
|
||||
}
|
||||
}
|
||||
|
||||
func NewQuotaUsageManager(model interface{}, scope rbacutils.TRbacScope, tableName string, keyword, keywordPlural string) SQuotaBaseManager {
|
||||
func NewQuotaUsageManager(model interface{}, scope rbacscope.TRbacScope, tableName string, keyword, keywordPlural string) SQuotaBaseManager {
|
||||
return SQuotaBaseManager{
|
||||
SResourceBaseManager: db.NewResourceBaseManager(model, tableName, keyword, keywordPlural),
|
||||
nonNegative: true,
|
||||
@@ -254,18 +254,18 @@ func (manager *SQuotaBaseManager) InitializeData() error {
|
||||
|
||||
for i := range tenants {
|
||||
obj := tenants[i]
|
||||
var scope rbacutils.TRbacScope
|
||||
var scope rbacscope.TRbacScope
|
||||
var ownerId mcclient.IIdentityProvider
|
||||
if obj.DomainId == identityapi.KeystoneDomainRoot {
|
||||
// domain
|
||||
scope = rbacutils.ScopeDomain
|
||||
scope = rbacscope.ScopeDomain
|
||||
ownerId = &db.SOwnerId{
|
||||
DomainId: tenants[i].Id,
|
||||
Domain: tenants[i].Name,
|
||||
}
|
||||
} else {
|
||||
// project
|
||||
scope = rbacutils.ScopeProject
|
||||
scope = rbacscope.ScopeProject
|
||||
ownerId = &db.SOwnerId{
|
||||
DomainId: tenants[i].DomainId,
|
||||
Domain: tenants[i].Domain,
|
||||
@@ -276,7 +276,7 @@ func (manager *SQuotaBaseManager) InitializeData() error {
|
||||
|
||||
quota := manager.newQuota()
|
||||
var baseKeys IQuotaKeys
|
||||
if manager.scope == rbacutils.ScopeDomain {
|
||||
if manager.scope == rbacscope.ScopeDomain {
|
||||
baseKeys = OwnerIdDomainQuotaKeys(ownerId)
|
||||
} else {
|
||||
baseKeys = OwnerIdProjectQuotaKeys(scope, ownerId)
|
||||
|
||||
@@ -18,9 +18,10 @@ import (
|
||||
"fmt"
|
||||
"strings"
|
||||
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/db"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
type SBaseDomainQuotaKeys struct {
|
||||
@@ -328,23 +329,23 @@ func QuotaKeyWeight(k IQuotaKeys) uint64 {
|
||||
return w
|
||||
}
|
||||
|
||||
func (k SBaseDomainQuotaKeys) Scope() rbacutils.TRbacScope {
|
||||
func (k SBaseDomainQuotaKeys) Scope() rbacscope.TRbacScope {
|
||||
if len(k.DomainId) > 0 {
|
||||
return rbacutils.ScopeDomain
|
||||
return rbacscope.ScopeDomain
|
||||
} else {
|
||||
return rbacutils.ScopeSystem
|
||||
return rbacscope.ScopeSystem
|
||||
}
|
||||
}
|
||||
|
||||
func (k SBaseProjectQuotaKeys) Scope() rbacutils.TRbacScope {
|
||||
func (k SBaseProjectQuotaKeys) Scope() rbacscope.TRbacScope {
|
||||
if len(k.DomainId) > 0 && len(k.ProjectId) > 0 {
|
||||
return rbacutils.ScopeProject
|
||||
return rbacscope.ScopeProject
|
||||
} else if len(k.DomainId) > 0 && len(k.ProjectId) == 0 {
|
||||
return rbacutils.ScopeDomain
|
||||
return rbacscope.ScopeDomain
|
||||
} else if len(k.DomainId) == 0 && len(k.ProjectId) == 0 {
|
||||
return rbacutils.ScopeSystem
|
||||
return rbacscope.ScopeSystem
|
||||
} else {
|
||||
return rbacutils.ScopeNone
|
||||
return rbacscope.ScopeNone
|
||||
}
|
||||
}
|
||||
|
||||
@@ -393,8 +394,8 @@ func IsBaseDomainQuotaKeys(k IQuotaKeys) bool {
|
||||
return true
|
||||
}
|
||||
|
||||
func OwnerIdProjectQuotaKeys(scope rbacutils.TRbacScope, ownerId mcclient.IIdentityProvider) SBaseProjectQuotaKeys {
|
||||
if scope == rbacutils.ScopeDomain {
|
||||
func OwnerIdProjectQuotaKeys(scope rbacscope.TRbacScope, ownerId mcclient.IIdentityProvider) SBaseProjectQuotaKeys {
|
||||
if scope == rbacscope.ScopeDomain {
|
||||
return SBaseProjectQuotaKeys{
|
||||
SBaseDomainQuotaKeys: SBaseDomainQuotaKeys{
|
||||
DomainId: ownerId.GetProjectDomainId(),
|
||||
|
||||
@@ -21,14 +21,14 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/db"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
func (manager *SQuotaBaseManager) ResourceScope() rbacutils.TRbacScope {
|
||||
func (manager *SQuotaBaseManager) ResourceScope() rbacscope.TRbacScope {
|
||||
return manager.scope
|
||||
}
|
||||
|
||||
|
||||
@@ -18,10 +18,10 @@ import (
|
||||
"context"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/db"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
const (
|
||||
@@ -35,12 +35,12 @@ func newDBQuotaStore() *SDBQuotaStore {
|
||||
return &SDBQuotaStore{}
|
||||
}
|
||||
|
||||
func (store *SDBQuotaStore) GetQuota(ctx context.Context, scope rbacutils.TRbacScope, ownerId mcclient.IIdentityProvider, quota IQuota) error {
|
||||
func (store *SDBQuotaStore) GetQuota(ctx context.Context, scope rbacscope.TRbacScope, ownerId mcclient.IIdentityProvider, quota IQuota) error {
|
||||
var tenant *db.STenant
|
||||
var err error
|
||||
|
||||
switch scope {
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
tenant, err = db.TenantCacheManager.FetchDomainById(ctx, ownerId.GetProjectDomainId())
|
||||
default:
|
||||
tenant, err = db.TenantCacheManager.FetchTenantById(ctx, ownerId.GetProjectId())
|
||||
|
||||
+64
-63
@@ -19,6 +19,7 @@ import (
|
||||
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/policy"
|
||||
@@ -45,35 +46,35 @@ func isObjectRbacAllowedResult(ctx context.Context, model IModel, userCred mccli
|
||||
ownerId = userCred
|
||||
}
|
||||
|
||||
var requireScope rbacutils.TRbacScope
|
||||
var requireScope rbacscope.TRbacScope
|
||||
resScope := manager.ResourceScope()
|
||||
switch resScope {
|
||||
case rbacutils.ScopeSystem:
|
||||
requireScope = rbacutils.ScopeSystem
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeSystem:
|
||||
requireScope = rbacscope.ScopeSystem
|
||||
case rbacscope.ScopeDomain:
|
||||
if ownerId != nil && objOwnerId != nil && (ownerId.GetUserId() == objOwnerId.GetUserId() && action == policy.PolicyActionGet) {
|
||||
requireScope = rbacutils.ScopeUser
|
||||
requireScope = rbacscope.ScopeUser
|
||||
} else if ownerId != nil && objOwnerId != nil && (ownerId.GetProjectDomainId() == objOwnerId.GetProjectDomainId() || objOwnerId.GetProjectDomainId() == "" || (model.IsSharable(ownerId) && action == policy.PolicyActionGet)) {
|
||||
requireScope = rbacutils.ScopeDomain
|
||||
requireScope = rbacscope.ScopeDomain
|
||||
} else {
|
||||
requireScope = rbacutils.ScopeSystem
|
||||
requireScope = rbacscope.ScopeSystem
|
||||
}
|
||||
case rbacutils.ScopeUser:
|
||||
case rbacscope.ScopeUser:
|
||||
if ownerId != nil && objOwnerId != nil && (ownerId.GetUserId() == objOwnerId.GetUserId() || objOwnerId.GetUserId() == "" || (model.IsSharable(ownerId) && action == policy.PolicyActionGet)) {
|
||||
requireScope = rbacutils.ScopeUser
|
||||
requireScope = rbacscope.ScopeUser
|
||||
} else if ownerId != nil && objOwnerId != nil && ownerId.GetProjectDomainId() == objOwnerId.GetProjectDomainId() {
|
||||
requireScope = rbacutils.ScopeDomain
|
||||
requireScope = rbacscope.ScopeDomain
|
||||
} else {
|
||||
requireScope = rbacutils.ScopeSystem
|
||||
requireScope = rbacscope.ScopeSystem
|
||||
}
|
||||
default:
|
||||
// objOwnerId should not be nil
|
||||
if ownerId != nil && objOwnerId != nil && (ownerId.GetProjectId() == objOwnerId.GetProjectId() || objOwnerId.GetProjectId() == "" || (model.IsSharable(ownerId) && action == policy.PolicyActionGet)) {
|
||||
requireScope = rbacutils.ScopeProject
|
||||
requireScope = rbacscope.ScopeProject
|
||||
} else if ownerId != nil && objOwnerId != nil && ownerId.GetProjectDomainId() == objOwnerId.GetProjectDomainId() {
|
||||
requireScope = rbacutils.ScopeDomain
|
||||
requireScope = rbacscope.ScopeDomain
|
||||
} else {
|
||||
requireScope = rbacutils.ScopeSystem
|
||||
requireScope = rbacscope.ScopeSystem
|
||||
}
|
||||
}
|
||||
|
||||
@@ -104,34 +105,34 @@ func isClassRbacAllowed(ctx context.Context, manager IModelManager, userCred mcc
|
||||
ownerId = userCred
|
||||
}
|
||||
|
||||
var requireScope rbacutils.TRbacScope
|
||||
var requireScope rbacscope.TRbacScope
|
||||
resScope := manager.ResourceScope()
|
||||
switch resScope {
|
||||
case rbacutils.ScopeSystem:
|
||||
requireScope = rbacutils.ScopeSystem
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeSystem:
|
||||
requireScope = rbacscope.ScopeSystem
|
||||
case rbacscope.ScopeDomain:
|
||||
// objOwnerId should not be nil
|
||||
if ownerId != nil && ownerId.GetProjectDomainId() == objOwnerId.GetProjectDomainId() {
|
||||
requireScope = rbacutils.ScopeDomain
|
||||
requireScope = rbacscope.ScopeDomain
|
||||
} else {
|
||||
requireScope = rbacutils.ScopeSystem
|
||||
requireScope = rbacscope.ScopeSystem
|
||||
}
|
||||
case rbacutils.ScopeUser:
|
||||
case rbacscope.ScopeUser:
|
||||
if ownerId != nil && ownerId.GetUserId() == objOwnerId.GetUserId() {
|
||||
requireScope = rbacutils.ScopeUser
|
||||
requireScope = rbacscope.ScopeUser
|
||||
} else if ownerId != nil && ownerId.GetProjectDomainId() == objOwnerId.GetProjectDomainId() {
|
||||
requireScope = rbacutils.ScopeDomain
|
||||
requireScope = rbacscope.ScopeDomain
|
||||
} else {
|
||||
requireScope = rbacutils.ScopeSystem
|
||||
requireScope = rbacscope.ScopeSystem
|
||||
}
|
||||
default:
|
||||
// objOwnerId should not be nil
|
||||
if ownerId != nil && ownerId.GetProjectId() == objOwnerId.GetProjectId() {
|
||||
requireScope = rbacutils.ScopeProject
|
||||
requireScope = rbacscope.ScopeProject
|
||||
} else if ownerId != nil && ownerId.GetProjectDomainId() == objOwnerId.GetProjectDomainId() {
|
||||
requireScope = rbacutils.ScopeDomain
|
||||
requireScope = rbacscope.ScopeDomain
|
||||
} else {
|
||||
requireScope = rbacutils.ScopeSystem
|
||||
requireScope = rbacscope.ScopeSystem
|
||||
}
|
||||
}
|
||||
|
||||
@@ -151,7 +152,7 @@ type IResource interface {
|
||||
KeywordPlural() string
|
||||
}
|
||||
|
||||
func IsAllowList(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
|
||||
func IsAllowList(scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
|
||||
if userCred == nil {
|
||||
return rbacutils.PolicyDeny
|
||||
}
|
||||
@@ -159,18 +160,18 @@ func IsAllowList(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential,
|
||||
}
|
||||
|
||||
func IsAdminAllowList(userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
|
||||
return IsAllowList(rbacutils.ScopeSystem, userCred, manager)
|
||||
return IsAllowList(rbacscope.ScopeSystem, userCred, manager)
|
||||
}
|
||||
|
||||
func IsDomainAllowList(userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
|
||||
return IsAllowList(rbacutils.ScopeDomain, userCred, manager)
|
||||
return IsAllowList(rbacscope.ScopeDomain, userCred, manager)
|
||||
}
|
||||
|
||||
func IsProjectAllowList(userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
|
||||
return IsAllowList(rbacutils.ScopeProject, userCred, manager)
|
||||
return IsAllowList(rbacscope.ScopeProject, userCred, manager)
|
||||
}
|
||||
|
||||
func IsAllowCreate(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
|
||||
func IsAllowCreate(scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
|
||||
if userCred == nil {
|
||||
return rbacutils.PolicyDeny
|
||||
}
|
||||
@@ -178,18 +179,18 @@ func IsAllowCreate(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential
|
||||
}
|
||||
|
||||
func IsAdminAllowCreate(userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
|
||||
return IsAllowCreate(rbacutils.ScopeSystem, userCred, manager)
|
||||
return IsAllowCreate(rbacscope.ScopeSystem, userCred, manager)
|
||||
}
|
||||
|
||||
func IsDomainAllowCreate(userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
|
||||
return IsAllowCreate(rbacutils.ScopeDomain, userCred, manager)
|
||||
return IsAllowCreate(rbacscope.ScopeDomain, userCred, manager)
|
||||
}
|
||||
|
||||
func IsProjectAllowCreate(userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
|
||||
return IsAllowCreate(rbacutils.ScopeProject, userCred, manager)
|
||||
return IsAllowCreate(rbacscope.ScopeProject, userCred, manager)
|
||||
}
|
||||
|
||||
func IsAllowClassPerform(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, manager IResource, action string) rbacutils.SPolicyResult {
|
||||
func IsAllowClassPerform(scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, manager IResource, action string) rbacutils.SPolicyResult {
|
||||
if userCred == nil {
|
||||
return rbacutils.PolicyDeny
|
||||
}
|
||||
@@ -197,18 +198,18 @@ func IsAllowClassPerform(scope rbacutils.TRbacScope, userCred mcclient.TokenCred
|
||||
}
|
||||
|
||||
func IsAdminAllowClassPerform(userCred mcclient.TokenCredential, manager IResource, action string) rbacutils.SPolicyResult {
|
||||
return IsAllowClassPerform(rbacutils.ScopeSystem, userCred, manager, action)
|
||||
return IsAllowClassPerform(rbacscope.ScopeSystem, userCred, manager, action)
|
||||
}
|
||||
|
||||
func IsDomainAllowClassPerform(userCred mcclient.TokenCredential, manager IResource, action string) rbacutils.SPolicyResult {
|
||||
return IsAllowClassPerform(rbacutils.ScopeDomain, userCred, manager, action)
|
||||
return IsAllowClassPerform(rbacscope.ScopeDomain, userCred, manager, action)
|
||||
}
|
||||
|
||||
func IsProjectAllowClassPerform(userCred mcclient.TokenCredential, manager IResource, action string) rbacutils.SPolicyResult {
|
||||
return IsAllowClassPerform(rbacutils.ScopeProject, userCred, manager, action)
|
||||
return IsAllowClassPerform(rbacscope.ScopeProject, userCred, manager, action)
|
||||
}
|
||||
|
||||
func IsAllowGet(ctx context.Context, scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, obj IModel) bool {
|
||||
func IsAllowGet(ctx context.Context, scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, obj IModel) bool {
|
||||
if userCred == nil {
|
||||
return false
|
||||
}
|
||||
@@ -223,18 +224,18 @@ func IsAllowGet(ctx context.Context, scope rbacutils.TRbacScope, userCred mcclie
|
||||
}
|
||||
|
||||
func IsAdminAllowGet(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
|
||||
return IsAllowGet(ctx, rbacutils.ScopeSystem, userCred, obj)
|
||||
return IsAllowGet(ctx, rbacscope.ScopeSystem, userCred, obj)
|
||||
}
|
||||
|
||||
func IsDomainAllowGet(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
|
||||
return IsAllowGet(ctx, rbacutils.ScopeDomain, userCred, obj)
|
||||
return IsAllowGet(ctx, rbacscope.ScopeDomain, userCred, obj)
|
||||
}
|
||||
|
||||
func IsProjectAllowGet(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
|
||||
return IsAllowGet(ctx, rbacutils.ScopeProject, userCred, obj)
|
||||
return IsAllowGet(ctx, rbacscope.ScopeProject, userCred, obj)
|
||||
}
|
||||
|
||||
func IsAllowGetSpec(ctx context.Context, scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
|
||||
func IsAllowGetSpec(ctx context.Context, scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
|
||||
if userCred == nil {
|
||||
return false
|
||||
}
|
||||
@@ -249,18 +250,18 @@ func IsAllowGetSpec(ctx context.Context, scope rbacutils.TRbacScope, userCred mc
|
||||
}
|
||||
|
||||
func IsAdminAllowGetSpec(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
|
||||
return IsAllowGetSpec(ctx, rbacutils.ScopeSystem, userCred, obj, spec)
|
||||
return IsAllowGetSpec(ctx, rbacscope.ScopeSystem, userCred, obj, spec)
|
||||
}
|
||||
|
||||
func IsDomainAllowGetSpec(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
|
||||
return IsAllowGetSpec(ctx, rbacutils.ScopeDomain, userCred, obj, spec)
|
||||
return IsAllowGetSpec(ctx, rbacscope.ScopeDomain, userCred, obj, spec)
|
||||
}
|
||||
|
||||
func IsProjectAllowGetSpec(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
|
||||
return IsAllowGetSpec(ctx, rbacutils.ScopeProject, userCred, obj, spec)
|
||||
return IsAllowGetSpec(ctx, rbacscope.ScopeProject, userCred, obj, spec)
|
||||
}
|
||||
|
||||
func IsAllowPerform(ctx context.Context, scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, obj IModel, action string) bool {
|
||||
func IsAllowPerform(ctx context.Context, scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, obj IModel, action string) bool {
|
||||
if userCred == nil {
|
||||
return false
|
||||
}
|
||||
@@ -275,18 +276,18 @@ func IsAllowPerform(ctx context.Context, scope rbacutils.TRbacScope, userCred mc
|
||||
}
|
||||
|
||||
func IsAdminAllowPerform(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, action string) bool {
|
||||
return IsAllowPerform(ctx, rbacutils.ScopeSystem, userCred, obj, action)
|
||||
return IsAllowPerform(ctx, rbacscope.ScopeSystem, userCred, obj, action)
|
||||
}
|
||||
|
||||
func IsDomainAllowPerform(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, action string) bool {
|
||||
return IsAllowPerform(ctx, rbacutils.ScopeDomain, userCred, obj, action)
|
||||
return IsAllowPerform(ctx, rbacscope.ScopeDomain, userCred, obj, action)
|
||||
}
|
||||
|
||||
func IsProjectAllowPerform(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, action string) bool {
|
||||
return IsAllowPerform(ctx, rbacutils.ScopeProject, userCred, obj, action)
|
||||
return IsAllowPerform(ctx, rbacscope.ScopeProject, userCred, obj, action)
|
||||
}
|
||||
|
||||
func IsAllowUpdate(ctx context.Context, scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, obj IModel) bool {
|
||||
func IsAllowUpdate(ctx context.Context, scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, obj IModel) bool {
|
||||
if userCred == nil {
|
||||
return false
|
||||
}
|
||||
@@ -301,18 +302,18 @@ func IsAllowUpdate(ctx context.Context, scope rbacutils.TRbacScope, userCred mcc
|
||||
}
|
||||
|
||||
func IsAdminAllowUpdate(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
|
||||
return IsAllowUpdate(ctx, rbacutils.ScopeSystem, userCred, obj)
|
||||
return IsAllowUpdate(ctx, rbacscope.ScopeSystem, userCred, obj)
|
||||
}
|
||||
|
||||
func IsDomainAllowUpdate(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
|
||||
return IsAllowUpdate(ctx, rbacutils.ScopeDomain, userCred, obj)
|
||||
return IsAllowUpdate(ctx, rbacscope.ScopeDomain, userCred, obj)
|
||||
}
|
||||
|
||||
func IsProjectAllowUpdate(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
|
||||
return IsAllowUpdate(ctx, rbacutils.ScopeProject, userCred, obj)
|
||||
return IsAllowUpdate(ctx, rbacscope.ScopeProject, userCred, obj)
|
||||
}
|
||||
|
||||
func IsAllowUpdateSpec(ctx context.Context, scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
|
||||
func IsAllowUpdateSpec(ctx context.Context, scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
|
||||
if userCred == nil {
|
||||
return false
|
||||
}
|
||||
@@ -327,18 +328,18 @@ func IsAllowUpdateSpec(ctx context.Context, scope rbacutils.TRbacScope, userCred
|
||||
}
|
||||
|
||||
func IsAdminAllowUpdateSpec(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
|
||||
return IsAllowUpdateSpec(ctx, rbacutils.ScopeSystem, userCred, obj, spec)
|
||||
return IsAllowUpdateSpec(ctx, rbacscope.ScopeSystem, userCred, obj, spec)
|
||||
}
|
||||
|
||||
func IsDomainAllowUpdateSpec(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
|
||||
return IsAllowUpdateSpec(ctx, rbacutils.ScopeDomain, userCred, obj, spec)
|
||||
return IsAllowUpdateSpec(ctx, rbacscope.ScopeDomain, userCred, obj, spec)
|
||||
}
|
||||
|
||||
func IsProjectAllowUpdateSpec(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
|
||||
return IsAllowUpdateSpec(ctx, rbacutils.ScopeProject, userCred, obj, spec)
|
||||
return IsAllowUpdateSpec(ctx, rbacscope.ScopeProject, userCred, obj, spec)
|
||||
}
|
||||
|
||||
func IsAllowDelete(ctx context.Context, scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, obj IModel) bool {
|
||||
func IsAllowDelete(ctx context.Context, scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, obj IModel) bool {
|
||||
if userCred == nil {
|
||||
return false
|
||||
}
|
||||
@@ -353,13 +354,13 @@ func IsAllowDelete(ctx context.Context, scope rbacutils.TRbacScope, userCred mcc
|
||||
}
|
||||
|
||||
func IsAdminAllowDelete(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
|
||||
return IsAllowDelete(ctx, rbacutils.ScopeSystem, userCred, obj)
|
||||
return IsAllowDelete(ctx, rbacscope.ScopeSystem, userCred, obj)
|
||||
}
|
||||
|
||||
func IsDomainAllowDelete(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
|
||||
return IsAllowDelete(ctx, rbacutils.ScopeDomain, userCred, obj)
|
||||
return IsAllowDelete(ctx, rbacscope.ScopeDomain, userCred, obj)
|
||||
}
|
||||
|
||||
func IsProjectAllowDelete(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
|
||||
return IsAllowDelete(ctx, rbacutils.ScopeProject, userCred, obj)
|
||||
return IsAllowDelete(ctx, rbacscope.ScopeProject, userCred, obj)
|
||||
}
|
||||
|
||||
@@ -17,6 +17,7 @@ package db
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/utils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
@@ -28,7 +29,7 @@ type omniToken struct {
|
||||
mcclient.SSimpleToken
|
||||
}
|
||||
|
||||
func (tk *omniToken) IsAllow(scope rbacutils.TRbacScope, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
|
||||
func (tk *omniToken) IsAllow(scope rbacscope.TRbacScope, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
|
||||
return rbacutils.PolicyAllow
|
||||
}
|
||||
|
||||
|
||||
@@ -24,6 +24,7 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/httputils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
@@ -31,7 +32,6 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/mcclient/auth"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/informer"
|
||||
modules "yunion.io/x/onecloud/pkg/mcclient/modules/identity"
|
||||
"yunion.io/x/onecloud/pkg/util/httputils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
|
||||
@@ -19,6 +19,7 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/reflectutils"
|
||||
"yunion.io/x/pkg/utils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
@@ -26,7 +27,6 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/apis"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
@@ -46,18 +46,18 @@ type sUniqValues struct {
|
||||
}
|
||||
|
||||
func (m *SScopedResourceBaseManager) FetchUniqValues(ctx context.Context, data jsonutils.JSONObject) jsonutils.JSONObject {
|
||||
parentScope := rbacutils.ScopeSystem
|
||||
parentScope := rbacscope.ScopeSystem
|
||||
scope, _ := data.GetString("scope")
|
||||
if scope != "" {
|
||||
parentScope = rbacutils.TRbacScope(scope)
|
||||
parentScope = rbacscope.TRbacScope(scope)
|
||||
}
|
||||
uniqValues := sUniqValues{}
|
||||
switch parentScope {
|
||||
case rbacutils.ScopeSystem:
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeSystem:
|
||||
case rbacscope.ScopeDomain:
|
||||
domain, _ := data.GetString("project_domain")
|
||||
uniqValues.Domain = domain
|
||||
case rbacutils.ScopeProject:
|
||||
case rbacscope.ScopeProject:
|
||||
project, _ := data.GetString("project")
|
||||
uniqValues.Project = project
|
||||
}
|
||||
@@ -65,19 +65,19 @@ func (m *SScopedResourceBaseManager) FetchUniqValues(ctx context.Context, data j
|
||||
return jsonutils.Marshal(uniqValues)
|
||||
}
|
||||
|
||||
func (m *SScopedResourceBaseManager) FilterByScope(q *sqlchemy.SQuery, scope rbacutils.TRbacScope, scopeResId string) *sqlchemy.SQuery {
|
||||
func (m *SScopedResourceBaseManager) FilterByScope(q *sqlchemy.SQuery, scope rbacscope.TRbacScope, scopeResId string) *sqlchemy.SQuery {
|
||||
isNotNullOrEmpty := func(field string) sqlchemy.ICondition {
|
||||
return sqlchemy.AND(sqlchemy.IsNotNull(q.Field(field)), sqlchemy.IsNotEmpty(q.Field(field)))
|
||||
}
|
||||
switch scope {
|
||||
case rbacutils.ScopeSystem:
|
||||
case rbacscope.ScopeSystem:
|
||||
q = q.IsNullOrEmpty("domain_id").IsNullOrEmpty("tenant_id")
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
q = q.IsNullOrEmpty("tenant_id").Filter(isNotNullOrEmpty("domain_id"))
|
||||
if scopeResId != "" {
|
||||
q = q.Equals("domain_id", scopeResId)
|
||||
}
|
||||
case rbacutils.ScopeProject:
|
||||
case rbacscope.ScopeProject:
|
||||
q = q.Filter(isNotNullOrEmpty("domain_id")).Filter(isNotNullOrEmpty("tenant_id"))
|
||||
if scopeResId != "" {
|
||||
q = q.Equals("tenant_id", scopeResId)
|
||||
@@ -90,34 +90,34 @@ func (m *SScopedResourceBaseManager) FilterByUniqValues(q *sqlchemy.SQuery, valu
|
||||
uniqValues := &sUniqValues{}
|
||||
values.Unmarshal(uniqValues)
|
||||
if len(uniqValues.Domain) > 0 {
|
||||
return m.FilterByScope(q, rbacutils.TRbacScope(uniqValues.Scope), uniqValues.Domain)
|
||||
return m.FilterByScope(q, rbacscope.TRbacScope(uniqValues.Scope), uniqValues.Domain)
|
||||
} else if len(uniqValues.Project) > 0 {
|
||||
return m.FilterByScope(q, rbacutils.TRbacScope(uniqValues.Scope), uniqValues.Project)
|
||||
return m.FilterByScope(q, rbacscope.TRbacScope(uniqValues.Scope), uniqValues.Project)
|
||||
} else {
|
||||
return m.FilterByScope(q, rbacutils.TRbacScope(uniqValues.Scope), "")
|
||||
return m.FilterByScope(q, rbacscope.TRbacScope(uniqValues.Scope), "")
|
||||
}
|
||||
}
|
||||
|
||||
func (m *SScopedResourceBase) IsOwner(userCred mcclient.TokenCredential) bool {
|
||||
scope := m.GetResourceScope()
|
||||
switch scope {
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
return userCred.GetProjectDomainId() == m.GetDomainId()
|
||||
case rbacutils.ScopeProject:
|
||||
case rbacscope.ScopeProject:
|
||||
return userCred.GetProjectId() == m.GetProjectId()
|
||||
}
|
||||
// system scope
|
||||
return userCred.HasSystemAdminPrivilege()
|
||||
}
|
||||
|
||||
func (m *SScopedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, userCred mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (m *SScopedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, userCred mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
if userCred == nil {
|
||||
return q
|
||||
}
|
||||
switch scope {
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
q = q.Equals("domain_id", userCred.GetProjectDomainId())
|
||||
case rbacutils.ScopeProject:
|
||||
case rbacscope.ScopeProject:
|
||||
q = q.Equals("tenant_id", userCred.GetProjectId())
|
||||
}
|
||||
return q
|
||||
@@ -125,22 +125,22 @@ func (m *SScopedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, userCred
|
||||
|
||||
func (m *SScopedResourceBaseManager) ValidateCreateData(man IScopedResourceManager, ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, input apis.ScopedResourceCreateInput) (apis.ScopedResourceCreateInput, error) {
|
||||
if input.Scope == "" {
|
||||
input.Scope = string(rbacutils.ScopeSystem)
|
||||
input.Scope = string(rbacscope.ScopeSystem)
|
||||
}
|
||||
if !utils.IsInStringArray(input.Scope, []string{
|
||||
string(rbacutils.ScopeSystem),
|
||||
string(rbacutils.ScopeDomain),
|
||||
string(rbacutils.ScopeProject)}) {
|
||||
string(rbacscope.ScopeSystem),
|
||||
string(rbacscope.ScopeDomain),
|
||||
string(rbacscope.ScopeProject)}) {
|
||||
return input, httperrors.NewInputParameterError("invalid scope %s", input.Scope)
|
||||
}
|
||||
var allowCreate bool
|
||||
switch rbacutils.TRbacScope(input.Scope) {
|
||||
case rbacutils.ScopeSystem:
|
||||
switch rbacscope.TRbacScope(input.Scope) {
|
||||
case rbacscope.ScopeSystem:
|
||||
allowCreate = IsAdminAllowCreate(userCred, man).Result.IsAllow()
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
allowCreate = IsDomainAllowCreate(userCred, man).Result.IsAllow()
|
||||
input.ProjectDomainId = ownerId.GetDomainId()
|
||||
case rbacutils.ScopeProject:
|
||||
case rbacscope.ScopeProject:
|
||||
allowCreate = IsProjectAllowCreate(userCred, man).Result.IsAllow()
|
||||
input.ProjectDomainId = ownerId.GetDomainId()
|
||||
input.ProjectId = ownerId.GetProjectId()
|
||||
@@ -151,20 +151,20 @@ func (m *SScopedResourceBaseManager) ValidateCreateData(man IScopedResourceManag
|
||||
return input, nil
|
||||
}
|
||||
|
||||
func getScopedResourceScope(domainId, projectId string) rbacutils.TRbacScope {
|
||||
func getScopedResourceScope(domainId, projectId string) rbacscope.TRbacScope {
|
||||
if domainId == "" && projectId == "" {
|
||||
return rbacutils.ScopeSystem
|
||||
return rbacscope.ScopeSystem
|
||||
}
|
||||
if domainId != "" && projectId == "" {
|
||||
return rbacutils.ScopeDomain
|
||||
return rbacscope.ScopeDomain
|
||||
}
|
||||
if domainId != "" && projectId != "" {
|
||||
return rbacutils.ScopeProject
|
||||
return rbacscope.ScopeProject
|
||||
}
|
||||
return rbacutils.ScopeNone
|
||||
return rbacscope.ScopeNone
|
||||
}
|
||||
|
||||
func (s *SScopedResourceBase) GetResourceScope() rbacutils.TRbacScope {
|
||||
func (s *SScopedResourceBase) GetResourceScope() rbacscope.TRbacScope {
|
||||
return getScopedResourceScope(s.DomainId, s.ProjectId)
|
||||
}
|
||||
|
||||
@@ -184,14 +184,14 @@ func (s *SScopedResourceBase) SetResourceScope(domainId, projectId string) error
|
||||
|
||||
func (s *SScopedResourceBase) CustomizeCreate(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, data jsonutils.JSONObject) error {
|
||||
scope, _ := data.GetString("scope")
|
||||
switch rbacutils.TRbacScope(scope) {
|
||||
case rbacutils.ScopeSystem:
|
||||
switch rbacscope.TRbacScope(scope) {
|
||||
case rbacscope.ScopeSystem:
|
||||
s.DomainId = ""
|
||||
s.ProjectId = ""
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
s.DomainId = ownerId.GetDomainId()
|
||||
s.ProjectId = ""
|
||||
case rbacutils.ScopeProject:
|
||||
case rbacscope.ScopeProject:
|
||||
s.DomainId = ownerId.GetDomainId()
|
||||
s.ProjectId = ownerId.GetProjectId()
|
||||
}
|
||||
@@ -239,11 +239,11 @@ func PerformSetScope(
|
||||
scopeToSet := getScopedResourceScope(domainId, projectId)
|
||||
var err error
|
||||
switch scopeToSet {
|
||||
case rbacutils.ScopeSystem:
|
||||
case rbacscope.ScopeSystem:
|
||||
err = setScopedResourceToSystem(ctx, obj, userCred)
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
err = setScopedResourceToDomain(ctx, obj, userCred, domainId)
|
||||
case rbacutils.ScopeProject:
|
||||
case rbacscope.ScopeProject:
|
||||
err = setScopedResourceToProject(ctx, obj, userCred, projectId)
|
||||
}
|
||||
return nil, err
|
||||
@@ -309,7 +309,7 @@ func (m *SScopedResourceBaseManager) ListItemFilter(
|
||||
return nil, errors.Wrap(err, "SProjectizedResourceBaseManager.ListItemFilter")
|
||||
}
|
||||
if query.BelongScope != "" {
|
||||
q = m.FilterByScope(q, rbacutils.TRbacScope(query.BelongScope), "")
|
||||
q = m.FilterByScope(q, rbacscope.TRbacScope(query.BelongScope), "")
|
||||
}
|
||||
return q, nil
|
||||
}
|
||||
|
||||
@@ -20,6 +20,7 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/apis"
|
||||
@@ -28,7 +29,6 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/logclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
@@ -65,7 +65,7 @@ func (manager *SSharableBaseResourceManager) FetchCustomizeColumns(
|
||||
|
||||
var resType string
|
||||
resIds := make([]string, len(rows))
|
||||
var resScope rbacutils.TRbacScope
|
||||
var resScope rbacscope.TRbacScope
|
||||
for i := range rows {
|
||||
if model, ok := objs[i].(ISharableBaseModel); ok {
|
||||
if len(resType) == 0 {
|
||||
@@ -157,48 +157,48 @@ func SharableManagerValidateCreateData(
|
||||
reqScope := resScope
|
||||
isPublic := true
|
||||
switch resScope {
|
||||
case rbacutils.ScopeProject:
|
||||
if input.PublicScope == string(rbacutils.ScopeSystem) {
|
||||
case rbacscope.ScopeProject:
|
||||
if input.PublicScope == string(rbacscope.ScopeSystem) {
|
||||
input.IsPublic = &isPublic
|
||||
reqScope = rbacutils.ScopeSystem
|
||||
} else if input.PublicScope == string(rbacutils.ScopeDomain) {
|
||||
reqScope = rbacscope.ScopeSystem
|
||||
} else if input.PublicScope == string(rbacscope.ScopeDomain) {
|
||||
if consts.GetNonDefaultDomainProjects() {
|
||||
// only if non_default_domain_projects turned on, allow sharing to domain
|
||||
input.IsPublic = &isPublic
|
||||
reqScope = rbacutils.ScopeDomain
|
||||
reqScope = rbacscope.ScopeDomain
|
||||
} else {
|
||||
input.IsPublic = &isPublic
|
||||
reqScope = rbacutils.ScopeSystem
|
||||
reqScope = rbacscope.ScopeSystem
|
||||
}
|
||||
} else if input.IsPublic != nil && *input.IsPublic && len(input.PublicScope) == 0 {
|
||||
// backward compatible, if only is_public is true, make it share to system
|
||||
input.IsPublic = &isPublic
|
||||
input.PublicScope = string(rbacutils.ScopeSystem)
|
||||
reqScope = rbacutils.ScopeSystem
|
||||
input.PublicScope = string(rbacscope.ScopeSystem)
|
||||
reqScope = rbacscope.ScopeSystem
|
||||
} else {
|
||||
input.IsPublic = nil
|
||||
input.PublicScope = "" // string(rbacutils.ScopeNone)
|
||||
input.PublicScope = "" // string(rbacscope.ScopeNone)
|
||||
}
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
if consts.GetNonDefaultDomainProjects() {
|
||||
// only if non_default_domain_projects turned on, allow sharing domain resources
|
||||
if input.PublicScope == string(rbacutils.ScopeSystem) {
|
||||
if input.PublicScope == string(rbacscope.ScopeSystem) {
|
||||
input.IsPublic = &isPublic
|
||||
reqScope = rbacutils.ScopeSystem
|
||||
reqScope = rbacscope.ScopeSystem
|
||||
} else if input.IsPublic != nil && *input.IsPublic && len(input.PublicScope) == 0 {
|
||||
// backward compatible, if only is_public is true, make it share to system
|
||||
input.IsPublic = &isPublic
|
||||
input.PublicScope = string(rbacutils.ScopeSystem)
|
||||
reqScope = rbacutils.ScopeSystem
|
||||
input.PublicScope = string(rbacscope.ScopeSystem)
|
||||
reqScope = rbacscope.ScopeSystem
|
||||
} else {
|
||||
input.IsPublic = nil
|
||||
input.PublicScope = "" // string(rbacutils.ScopeNone)
|
||||
input.PublicScope = "" // string(rbacscope.ScopeNone)
|
||||
}
|
||||
} else {
|
||||
// if non_default_domain_projects turned off, all domain resources shared to system
|
||||
input.IsPublic = &isPublic
|
||||
input.PublicScope = string(rbacutils.ScopeSystem)
|
||||
reqScope = rbacutils.ScopeSystem
|
||||
input.PublicScope = string(rbacscope.ScopeSystem)
|
||||
reqScope = rbacscope.ScopeSystem
|
||||
}
|
||||
default:
|
||||
return input, errors.Wrap(httperrors.ErrInputParameter, "the resource is not sharable")
|
||||
@@ -213,10 +213,10 @@ func SharableManagerValidateCreateData(
|
||||
return input, nil
|
||||
}
|
||||
|
||||
func SharableManagerFilterByOwner(manager IStandaloneModelManager, q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func SharableManagerFilterByOwner(manager IStandaloneModelManager, q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
if owner != nil {
|
||||
resScope := manager.ResourceScope()
|
||||
if resScope == rbacutils.ScopeProject && scope == rbacutils.ScopeProject {
|
||||
if resScope == rbacscope.ScopeProject && scope == rbacscope.ScopeProject {
|
||||
ownerProjectId := owner.GetProjectId()
|
||||
if len(ownerProjectId) > 0 {
|
||||
subq := SharedResourceManager.Query("resource_id")
|
||||
@@ -231,11 +231,11 @@ func SharableManagerFilterByOwner(manager IStandaloneModelManager, q *sqlchemy.S
|
||||
sqlchemy.Equals(q.Field("tenant_id"), ownerProjectId),
|
||||
sqlchemy.AND(
|
||||
sqlchemy.IsTrue(q.Field("is_public")),
|
||||
sqlchemy.Equals(q.Field("public_scope"), rbacutils.ScopeSystem),
|
||||
sqlchemy.Equals(q.Field("public_scope"), rbacscope.ScopeSystem),
|
||||
),
|
||||
sqlchemy.AND(
|
||||
sqlchemy.IsTrue(q.Field("is_public")),
|
||||
sqlchemy.Equals(q.Field("public_scope"), rbacutils.ScopeDomain),
|
||||
sqlchemy.Equals(q.Field("public_scope"), rbacscope.ScopeDomain),
|
||||
sqlchemy.OR(
|
||||
sqlchemy.Equals(q.Field("domain_id"), owner.GetProjectDomainId()),
|
||||
sqlchemy.In(q.Field("id"), subq2.SubQuery()),
|
||||
@@ -244,7 +244,7 @@ func SharableManagerFilterByOwner(manager IStandaloneModelManager, q *sqlchemy.S
|
||||
sqlchemy.In(q.Field("id"), subq.SubQuery()),
|
||||
))
|
||||
}
|
||||
} else if (resScope == rbacutils.ScopeDomain && (scope == rbacutils.ScopeProject || scope == rbacutils.ScopeDomain)) || (resScope == rbacutils.ScopeProject && scope == rbacutils.ScopeDomain) {
|
||||
} else if (resScope == rbacscope.ScopeDomain && (scope == rbacscope.ScopeProject || scope == rbacscope.ScopeDomain)) || (resScope == rbacscope.ScopeProject && scope == rbacscope.ScopeDomain) {
|
||||
ownerDomainId := owner.GetProjectDomainId()
|
||||
if len(ownerDomainId) > 0 {
|
||||
subq := SharedResourceManager.Query("resource_id")
|
||||
@@ -255,7 +255,7 @@ func SharableManagerFilterByOwner(manager IStandaloneModelManager, q *sqlchemy.S
|
||||
sqlchemy.Equals(q.Field("domain_id"), ownerDomainId),
|
||||
sqlchemy.AND(
|
||||
sqlchemy.IsTrue(q.Field("is_public")),
|
||||
sqlchemy.Equals(q.Field("public_scope"), rbacutils.ScopeSystem),
|
||||
sqlchemy.Equals(q.Field("public_scope"), rbacscope.ScopeSystem),
|
||||
),
|
||||
sqlchemy.AND(
|
||||
sqlchemy.IsTrue(q.Field("is_public")),
|
||||
@@ -284,9 +284,9 @@ type ISharableBaseModel interface {
|
||||
}
|
||||
|
||||
type ISharableBase interface {
|
||||
SetShare(scoe rbacutils.TRbacScope)
|
||||
SetShare(scoe rbacscope.TRbacScope)
|
||||
GetIsPublic() bool
|
||||
GetPublicScope() rbacutils.TRbacScope
|
||||
GetPublicScope() rbacscope.TRbacScope
|
||||
GetSharableTargetDomainIds() []string
|
||||
GetRequiredSharedDomainIds() []string
|
||||
GetSharedDomains() []string
|
||||
@@ -296,9 +296,9 @@ func ISharableChangeOwnerCandidateDomainIds(model ISharableBaseModel) []string {
|
||||
var candidates []string
|
||||
if model.GetIsPublic() {
|
||||
switch model.GetPublicScope() {
|
||||
case rbacutils.ScopeSystem:
|
||||
case rbacscope.ScopeSystem:
|
||||
return candidates
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
candidates = model.GetSharedDomains()
|
||||
}
|
||||
}
|
||||
@@ -346,11 +346,11 @@ func ISharableMergeShareRequireDomainIds(requiredIds ...[]string) []string {
|
||||
}
|
||||
|
||||
func SharableModelIsSharable(model ISharableBaseModel, reqUsrId mcclient.IIdentityProvider) bool {
|
||||
if model.GetIsPublic() && model.GetPublicScope() == rbacutils.ScopeSystem {
|
||||
if model.GetIsPublic() && model.GetPublicScope() == rbacscope.ScopeSystem {
|
||||
return true
|
||||
}
|
||||
ownerId := model.GetOwnerId()
|
||||
if model.GetIsPublic() && model.GetPublicScope() == rbacutils.ScopeDomain {
|
||||
if model.GetIsPublic() && model.GetPublicScope() == rbacscope.ScopeDomain {
|
||||
if ownerId != nil && ownerId.GetProjectDomainId() == reqUsrId.GetProjectDomainId() {
|
||||
return true
|
||||
}
|
||||
@@ -363,7 +363,7 @@ func SharableModelIsSharable(model ISharableBaseModel, reqUsrId mcclient.IIdenti
|
||||
return true
|
||||
}
|
||||
}
|
||||
if model.GetPublicScope() == rbacutils.ScopeProject {
|
||||
if model.GetPublicScope() == rbacscope.ScopeProject {
|
||||
if ownerId != nil && ownerId.GetProjectId() == reqUsrId.GetProjectId() {
|
||||
return true
|
||||
}
|
||||
@@ -379,9 +379,9 @@ func SharableModelIsSharable(model ISharableBaseModel, reqUsrId mcclient.IIdenti
|
||||
return false
|
||||
}
|
||||
|
||||
func (m *SSharableBaseResource) SetShare(scope rbacutils.TRbacScope) {
|
||||
func (m *SSharableBaseResource) SetShare(scope rbacscope.TRbacScope) {
|
||||
pub := false
|
||||
if scope != rbacutils.ScopeNone {
|
||||
if scope != rbacscope.ScopeNone {
|
||||
pub = true
|
||||
}
|
||||
m.IsPublic = pub
|
||||
@@ -393,25 +393,25 @@ func (m SSharableBaseResource) GetIsPublic() bool {
|
||||
return m.IsPublic
|
||||
}
|
||||
|
||||
func (m SSharableBaseResource) GetPublicScope() rbacutils.TRbacScope {
|
||||
return rbacutils.String2Scope(m.PublicScope)
|
||||
func (m SSharableBaseResource) GetPublicScope() rbacscope.TRbacScope {
|
||||
return rbacscope.String2Scope(m.PublicScope)
|
||||
}
|
||||
|
||||
func SharablePerformPublic(model ISharableBaseModel, ctx context.Context, userCred mcclient.TokenCredential, input apis.PerformPublicProjectInput) error {
|
||||
var err error
|
||||
|
||||
resourceScope := model.GetModelManager().ResourceScope()
|
||||
targetScope := rbacutils.String2ScopeDefault(input.Scope, rbacutils.ScopeSystem)
|
||||
targetScope := rbacscope.String2ScopeDefault(input.Scope, rbacscope.ScopeSystem)
|
||||
if resourceScope.HigherThan(targetScope) {
|
||||
return errors.Wrapf(httperrors.ErrNotSupported, "cannot share %s resource to %s", resourceScope, targetScope)
|
||||
}
|
||||
|
||||
if len(input.SharedProjectIds) > 0 && len(input.SharedDomainIds) > 0 {
|
||||
return errors.Wrap(httperrors.ErrInputParameter, "cannot set shared_projects and shared_domains at the same time")
|
||||
} else if len(input.SharedProjectIds) > 0 && targetScope != rbacutils.ScopeProject {
|
||||
targetScope = rbacutils.ScopeProject
|
||||
} else if len(input.SharedDomainIds) > 0 && targetScope != rbacutils.ScopeDomain {
|
||||
targetScope = rbacutils.ScopeDomain
|
||||
} else if len(input.SharedProjectIds) > 0 && targetScope != rbacscope.ScopeProject {
|
||||
targetScope = rbacscope.ScopeProject
|
||||
} else if len(input.SharedDomainIds) > 0 && targetScope != rbacscope.ScopeDomain {
|
||||
targetScope = rbacscope.ScopeDomain
|
||||
}
|
||||
|
||||
shareResult := apis.PerformPublicProjectInput{}
|
||||
@@ -421,7 +421,7 @@ func SharablePerformPublic(model ISharableBaseModel, ctx context.Context, userCr
|
||||
requireIds := model.GetRequiredSharedDomainIds()
|
||||
|
||||
switch targetScope {
|
||||
case rbacutils.ScopeProject:
|
||||
case rbacscope.ScopeProject:
|
||||
if len(requireIds) == 0 {
|
||||
return errors.Wrap(httperrors.ErrForbidden, "require to be shared to system")
|
||||
} else if len(requireIds) > 1 {
|
||||
@@ -435,9 +435,9 @@ func SharablePerformPublic(model ISharableBaseModel, ctx context.Context, userCr
|
||||
return errors.Wrap(err, "shareToTarget")
|
||||
}
|
||||
if len(shareResult.SharedProjectIds) == 0 {
|
||||
targetScope = rbacutils.ScopeNone
|
||||
targetScope = rbacscope.ScopeNone
|
||||
}
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
if !consts.GetNonDefaultDomainProjects() {
|
||||
return errors.Wrap(httperrors.ErrForbidden, "not allow to share to domain when non_default_domain_projects turned off")
|
||||
}
|
||||
@@ -452,10 +452,10 @@ func SharablePerformPublic(model ISharableBaseModel, ctx context.Context, userCr
|
||||
if err != nil {
|
||||
return errors.Wrap(err, "shareToTarget add domains")
|
||||
}
|
||||
if len(shareResult.SharedDomainIds) == 0 && resourceScope == rbacutils.ScopeDomain {
|
||||
targetScope = rbacutils.ScopeNone
|
||||
if len(shareResult.SharedDomainIds) == 0 && resourceScope == rbacscope.ScopeDomain {
|
||||
targetScope = rbacscope.ScopeNone
|
||||
}
|
||||
case rbacutils.ScopeSystem:
|
||||
case rbacscope.ScopeSystem:
|
||||
if len(candidateIds) > 0 {
|
||||
return httperrors.NewForbiddenError("sharing is limited to domains %s", jsonutils.Marshal(candidateIds))
|
||||
}
|
||||
@@ -492,7 +492,7 @@ func SharablePerformPublic(model ISharableBaseModel, ctx context.Context, userCr
|
||||
return errors.Wrap(err, "Update")
|
||||
}
|
||||
|
||||
if targetScope != rbacutils.ScopeNone {
|
||||
if targetScope != rbacscope.ScopeNone {
|
||||
OpsLog.LogEvent(model, ACT_PUBLIC, shareResult, userCred)
|
||||
logclient.AddActionLogWithContext(ctx, model, logclient.ACT_PUBLIC, shareResult, userCred, true)
|
||||
}
|
||||
@@ -502,12 +502,12 @@ func SharablePerformPublic(model ISharableBaseModel, ctx context.Context, userCr
|
||||
}
|
||||
|
||||
func SharablePerformPrivate(model ISharableBaseModel, ctx context.Context, userCred mcclient.TokenCredential) error {
|
||||
if !model.GetIsPublic() && model.GetPublicScope() == rbacutils.ScopeNone {
|
||||
if !model.GetIsPublic() && model.GetPublicScope() == rbacscope.ScopeNone {
|
||||
return nil
|
||||
}
|
||||
|
||||
resourceScope := model.GetModelManager().ResourceScope()
|
||||
if resourceScope == rbacutils.ScopeDomain && !consts.GetNonDefaultDomainProjects() {
|
||||
if resourceScope == rbacscope.ScopeDomain && !consts.GetNonDefaultDomainProjects() {
|
||||
return errors.Wrap(httperrors.ErrForbidden, "not allow to private domain resource")
|
||||
}
|
||||
|
||||
@@ -535,7 +535,7 @@ func SharablePerformPrivate(model ISharableBaseModel, ctx context.Context, userC
|
||||
}
|
||||
|
||||
diff, err := Update(model, func() error {
|
||||
model.SetShare(rbacutils.ScopeNone)
|
||||
model.SetShare(rbacscope.ScopeNone)
|
||||
return nil
|
||||
})
|
||||
|
||||
@@ -577,12 +577,12 @@ func SharableModelIsShared(model ISharableBaseModel) bool {
|
||||
return true
|
||||
}
|
||||
switch model.GetPublicScope() {
|
||||
case rbacutils.ScopeSystem:
|
||||
case rbacscope.ScopeSystem:
|
||||
if model.GetIsPublic() {
|
||||
return true
|
||||
}
|
||||
case rbacutils.ScopeDomain:
|
||||
if model.GetModelManager().ResourceScope() == rbacutils.ScopeProject {
|
||||
case rbacscope.ScopeDomain:
|
||||
if model.GetModelManager().ResourceScope() == rbacscope.ScopeProject {
|
||||
return true
|
||||
}
|
||||
}
|
||||
@@ -592,20 +592,20 @@ func SharableModelIsShared(model ISharableBaseModel) bool {
|
||||
func SharableModelCustomizeCreate(model ISharableBaseModel, ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, data jsonutils.JSONObject) error {
|
||||
if !data.Contains("public_scope") {
|
||||
resScope := model.GetModelManager().ResourceScope()
|
||||
if resScope == rbacutils.ScopeDomain && consts.GetNonDefaultDomainProjects() {
|
||||
if resScope == rbacscope.ScopeDomain && consts.GetNonDefaultDomainProjects() {
|
||||
// only if non_default_domain_projects turned on, do the following
|
||||
isManaged := false
|
||||
if managedModel, ok := model.(IManagedResourceBase); ok {
|
||||
isManaged = managedModel.IsManaged()
|
||||
}
|
||||
if !isManaged && IsAdminAllowPerform(ctx, userCred, model, "public") && ownerId.GetProjectDomainId() == userCred.GetProjectDomainId() {
|
||||
model.SetShare(rbacutils.ScopeSystem)
|
||||
data.(*jsonutils.JSONDict).Set("public_scope", jsonutils.NewString(string(rbacutils.ScopeSystem)))
|
||||
model.SetShare(rbacscope.ScopeSystem)
|
||||
data.(*jsonutils.JSONDict).Set("public_scope", jsonutils.NewString(string(rbacscope.ScopeSystem)))
|
||||
}
|
||||
}
|
||||
}
|
||||
if !data.Contains("public_scope") {
|
||||
model.SetShare(rbacutils.ScopeNone)
|
||||
model.SetShare(rbacscope.ScopeNone)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -19,12 +19,12 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/apis"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
@@ -48,7 +48,7 @@ func (manager *SSharableVirtualResourceBaseManager) GetISharableVirtualModelMana
|
||||
return manager.GetVirtualObject().(ISharableVirtualModelManager)
|
||||
}
|
||||
|
||||
func (manager *SSharableVirtualResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *SSharableVirtualResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
return SharableManagerFilterByOwner(manager.GetISharableVirtualModelManager(), q, owner, scope)
|
||||
}
|
||||
|
||||
@@ -204,20 +204,20 @@ func (model *SSharableVirtualResourceBase) Delete(ctx context.Context, userCred
|
||||
func (model *SSharableVirtualResourceBase) GetSharedInfo() apis.SShareInfo {
|
||||
ret := apis.SShareInfo{}
|
||||
ret.IsPublic = model.IsPublic
|
||||
ret.PublicScope = rbacutils.String2ScopeDefault(model.PublicScope, rbacutils.ScopeNone)
|
||||
ret.PublicScope = rbacscope.String2ScopeDefault(model.PublicScope, rbacscope.ScopeNone)
|
||||
ret.SharedDomains = model.GetSharedDomains()
|
||||
ret.SharedProjects = model.GetSharedProjects()
|
||||
// fix
|
||||
if len(ret.SharedDomains) > 0 {
|
||||
ret.PublicScope = rbacutils.ScopeDomain
|
||||
ret.PublicScope = rbacscope.ScopeDomain
|
||||
ret.SharedProjects = nil
|
||||
ret.IsPublic = true
|
||||
} else if len(ret.SharedProjects) > 0 {
|
||||
ret.PublicScope = rbacutils.ScopeProject
|
||||
ret.PublicScope = rbacscope.ScopeProject
|
||||
ret.SharedDomains = nil
|
||||
ret.IsPublic = true
|
||||
} else if !ret.IsPublic {
|
||||
ret.PublicScope = rbacutils.ScopeNone
|
||||
ret.PublicScope = rbacscope.ScopeNone
|
||||
}
|
||||
return ret
|
||||
}
|
||||
|
||||
@@ -19,13 +19,13 @@ import (
|
||||
"database/sql"
|
||||
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/utils"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/policy"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
@@ -69,7 +69,7 @@ func (manager *SSharedResourceManager) CleanModelShares(ctx context.Context, use
|
||||
var err error
|
||||
resScope := model.GetModelManager().ResourceScope()
|
||||
switch resScope {
|
||||
case rbacutils.ScopeProject:
|
||||
case rbacscope.ScopeProject:
|
||||
_, err = manager.shareToTarget(ctx, userCred, model, SharedTargetProject, nil, nil, nil)
|
||||
if err != nil {
|
||||
return errors.Wrap(err, "remove shared project")
|
||||
@@ -78,7 +78,7 @@ func (manager *SSharedResourceManager) CleanModelShares(ctx context.Context, use
|
||||
if err != nil {
|
||||
return errors.Wrap(err, "remove shared domain")
|
||||
}
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
_, err = manager.shareToTarget(ctx, userCred, model, SharedTargetDomain, nil, nil, nil)
|
||||
if err != nil {
|
||||
return errors.Wrap(err, "remove shared domain")
|
||||
@@ -96,24 +96,24 @@ func (manager *SSharedResourceManager) shareToTarget(
|
||||
candidateIds []string,
|
||||
requireDomainIds []string,
|
||||
) ([]string, error) {
|
||||
var requireScope rbacutils.TRbacScope
|
||||
var requireScope rbacscope.TRbacScope
|
||||
resScope := model.GetModelManager().ResourceScope()
|
||||
switch resScope {
|
||||
case rbacutils.ScopeProject:
|
||||
case rbacscope.ScopeProject:
|
||||
switch targetType {
|
||||
case SharedTargetProject:
|
||||
// should have domain-level privileges
|
||||
// cannot share to a project across domain
|
||||
requireScope = rbacutils.ScopeDomain
|
||||
requireScope = rbacscope.ScopeDomain
|
||||
case SharedTargetDomain:
|
||||
// should have system-level privileges
|
||||
requireScope = rbacutils.ScopeSystem
|
||||
requireScope = rbacscope.ScopeSystem
|
||||
}
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
switch targetType {
|
||||
case SharedTargetDomain:
|
||||
// should have system-level privileges
|
||||
requireScope = rbacutils.ScopeSystem
|
||||
requireScope = rbacscope.ScopeSystem
|
||||
case SharedTargetProject:
|
||||
if len(targetIds) > 0 {
|
||||
return nil, errors.Wrap(httperrors.ErrNotSupported, "cannot share a domain resource to specific project")
|
||||
|
||||
@@ -21,6 +21,7 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/stringutils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
@@ -30,7 +31,6 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/auth"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
"yunion.io/x/onecloud/pkg/util/tagutils"
|
||||
)
|
||||
@@ -101,7 +101,7 @@ func (manager *SStandaloneAnonResourceBaseManager) FilterByNotId(q *sqlchemy.SQu
|
||||
return q.NotEquals("id", idStr)
|
||||
}
|
||||
|
||||
func (manager *SStandaloneAnonResourceBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *SStandaloneAnonResourceBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
q = manager.SResourceBaseManager.FilterByHiddenSystemAttributes(q, userCred, query, scope)
|
||||
showEmulated := jsonutils.QueryBoolean(query, "show_emulated", false)
|
||||
if showEmulated {
|
||||
@@ -489,7 +489,7 @@ func (model *SStandaloneAnonResourceBase) PerformMetadata(ctx context.Context, u
|
||||
dictStore := make(map[string]interface{})
|
||||
for k, v := range input {
|
||||
// 已双下滑线开头的metadata是系统内置,普通用户不可添加,只能查看
|
||||
if strings.HasPrefix(k, SYS_TAG_PREFIX) && (userCred == nil || !IsAllowPerform(ctx, rbacutils.ScopeSystem, userCred, model, "metadata")) {
|
||||
if strings.HasPrefix(k, SYS_TAG_PREFIX) && (userCred == nil || !IsAllowPerform(ctx, rbacscope.ScopeSystem, userCred, model, "metadata")) {
|
||||
return nil, httperrors.NewForbiddenError("not allow to set system key, please remove the underscore at the beginning")
|
||||
}
|
||||
dictStore[k] = v
|
||||
|
||||
@@ -20,13 +20,13 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/reflectutils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/apis"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
@@ -60,12 +60,12 @@ func (manager *SStatusDomainLevelUserResourceBaseManager) ValidateCreateData(ctx
|
||||
return input, nil
|
||||
}
|
||||
|
||||
func (manager *SStatusDomainLevelUserResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *SStatusDomainLevelUserResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
if owner != nil {
|
||||
switch scope {
|
||||
case rbacutils.ScopeProject, rbacutils.ScopeUser:
|
||||
case rbacscope.ScopeProject, rbacscope.ScopeUser:
|
||||
return q.Equals("owner_id", owner.GetUserId())
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
sq := UserCacheManager.Query("id").Equals("domain_id", owner.GetProjectDomainId())
|
||||
q = q.Filter(
|
||||
sqlchemy.OR(
|
||||
|
||||
@@ -27,8 +27,11 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/appctx"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/gotypes"
|
||||
"yunion.io/x/pkg/util/httputils"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/reflectutils"
|
||||
"yunion.io/x/pkg/util/stringutils"
|
||||
"yunion.io/x/pkg/util/timeutils"
|
||||
@@ -37,16 +40,13 @@ import (
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/apis"
|
||||
"yunion.io/x/onecloud/pkg/appctx"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/db"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/db/lockman"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/db/quotas"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/auth"
|
||||
"yunion.io/x/onecloud/pkg/util/httputils"
|
||||
"yunion.io/x/onecloud/pkg/util/logclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
const (
|
||||
@@ -151,14 +151,14 @@ func (self *STask) GetOwnerId() mcclient.IIdentityProvider {
|
||||
return &owner
|
||||
}
|
||||
|
||||
func (manager *STaskManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *STaskManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
if owner != nil {
|
||||
switch scope {
|
||||
case rbacutils.ScopeProject:
|
||||
case rbacscope.ScopeProject:
|
||||
if len(owner.GetProjectId()) > 0 {
|
||||
q = q.Contains("user_cred", owner.GetProjectId())
|
||||
}
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
if len(owner.GetProjectDomainId()) > 0 {
|
||||
q = q.Contains("user_cred", owner.GetProjectDomainId())
|
||||
}
|
||||
|
||||
@@ -25,6 +25,7 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/httputils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
identityapi "yunion.io/x/onecloud/pkg/apis/identity"
|
||||
@@ -34,7 +35,6 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/auth"
|
||||
modules "yunion.io/x/onecloud/pkg/mcclient/modules/identity"
|
||||
"yunion.io/x/onecloud/pkg/util/httputils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
"yunion.io/x/onecloud/pkg/util/tagutils"
|
||||
)
|
||||
|
||||
@@ -21,13 +21,13 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
|
||||
identityapi "yunion.io/x/onecloud/pkg/apis/identity"
|
||||
"yunion.io/x/onecloud/pkg/appsrv"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/auth"
|
||||
modules "yunion.io/x/onecloud/pkg/mcclient/modules/identity"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
var (
|
||||
@@ -72,7 +72,7 @@ func syncDomains(ctx context.Context) error {
|
||||
s := auth.GetAdminSession(ctx, consts.GetRegion())
|
||||
query := jsonutils.NewDict()
|
||||
query.Add(jsonutils.NewInt(1024), "limit")
|
||||
query.Add(jsonutils.NewString(string(rbacutils.ScopeSystem)), "scope")
|
||||
query.Add(jsonutils.NewString(string(rbacscope.ScopeSystem)), "scope")
|
||||
query.Add(jsonutils.JSONTrue, "details")
|
||||
total := -1
|
||||
offset := 0
|
||||
@@ -101,7 +101,7 @@ func syncProjects(ctx context.Context) error {
|
||||
s := auth.GetAdminSession(ctx, consts.GetRegion())
|
||||
query := jsonutils.NewDict()
|
||||
query.Add(jsonutils.NewInt(1024), "limit")
|
||||
query.Add(jsonutils.NewString(string(rbacutils.ScopeSystem)), "scope")
|
||||
query.Add(jsonutils.NewString(string(rbacscope.ScopeSystem)), "scope")
|
||||
query.Add(jsonutils.JSONTrue, "details")
|
||||
total := -1
|
||||
offset := 0
|
||||
|
||||
@@ -24,6 +24,7 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/httputils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
@@ -31,7 +32,6 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/auth"
|
||||
modules "yunion.io/x/onecloud/pkg/mcclient/modules/identity"
|
||||
"yunion.io/x/onecloud/pkg/util/httputils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
|
||||
@@ -20,13 +20,13 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/reflectutils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/apis"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
@@ -58,7 +58,7 @@ func (manager *SUserResourceBaseManager) ListItemFilter(
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if ((query.Admin != nil && *query.Admin) || query.Scope == string(rbacutils.ScopeSystem)) && IsAdminAllowList(userCred, manager).Result.IsAllow() {
|
||||
if ((query.Admin != nil && *query.Admin) || query.Scope == string(rbacscope.ScopeSystem)) && IsAdminAllowList(userCred, manager).Result.IsAllow() {
|
||||
user := query.UserId
|
||||
if len(user) > 0 {
|
||||
uc, _ := UserCacheManager.FetchUserByIdOrName(ctx, user)
|
||||
@@ -125,9 +125,9 @@ func (manager *SUserResourceBaseManager) FetchCustomizeColumns(
|
||||
return rows
|
||||
}
|
||||
|
||||
func (manager *SUserResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *SUserResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
if owner != nil {
|
||||
if scope == rbacutils.ScopeUser {
|
||||
if scope == rbacscope.ScopeUser {
|
||||
if len(owner.GetUserId()) > 0 {
|
||||
q = q.Equals("owner_id", owner.GetUserId())
|
||||
}
|
||||
@@ -173,10 +173,10 @@ func (manager *SUserResourceBaseManager) FetchOwnerId(ctx context.Context, data
|
||||
return FetchUserInfo(ctx, data)
|
||||
}
|
||||
|
||||
func (manager *SUserResourceBaseManager) NamespaceScope() rbacutils.TRbacScope {
|
||||
return rbacutils.ScopeUser
|
||||
func (manager *SUserResourceBaseManager) NamespaceScope() rbacscope.TRbacScope {
|
||||
return rbacscope.ScopeUser
|
||||
}
|
||||
|
||||
func (manager *SUserResourceBaseManager) ResourceScope() rbacutils.TRbacScope {
|
||||
return rbacutils.ScopeUser
|
||||
func (manager *SUserResourceBaseManager) ResourceScope() rbacscope.TRbacScope {
|
||||
return rbacscope.ScopeUser
|
||||
}
|
||||
|
||||
@@ -20,12 +20,12 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/reflectutils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/apis"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
@@ -59,7 +59,7 @@ func (manager *SVirtualJointResourceBaseManager) AllowAttach(ctx context.Context
|
||||
return false
|
||||
}
|
||||
|
||||
func (manager *SVirtualJointResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *SVirtualJointResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
if owner != nil {
|
||||
masterQ := manager.GetMasterManager().Query("id")
|
||||
masterQ = manager.GetMasterManager().FilterByOwner(masterQ, owner, scope)
|
||||
@@ -72,7 +72,7 @@ func (manager *SVirtualJointResourceBaseManager) FilterByOwner(q *sqlchemy.SQuer
|
||||
return q
|
||||
}
|
||||
|
||||
func (manager *SVirtualJointResourceBaseManager) FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *SVirtualJointResourceBaseManager) FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
q = manager.SJointResourceBaseManager.FilterBySystemAttributes(q, userCred, query, scope)
|
||||
masterQ := manager.GetMasterManager().Query("id")
|
||||
masterQ = manager.GetMasterManager().FilterBySystemAttributes(masterQ, userCred, query, scope)
|
||||
@@ -84,7 +84,7 @@ func (manager *SVirtualJointResourceBaseManager) FilterBySystemAttributes(q *sql
|
||||
return q
|
||||
}
|
||||
|
||||
func (manager *SVirtualJointResourceBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *SVirtualJointResourceBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
q = manager.SJointResourceBaseManager.FilterByHiddenSystemAttributes(q, userCred, query, scope)
|
||||
masterQ := manager.GetMasterManager().Query("id")
|
||||
masterQ = manager.GetMasterManager().FilterByHiddenSystemAttributes(masterQ, userCred, query, scope)
|
||||
|
||||
@@ -22,6 +22,7 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/util/timeutils"
|
||||
"yunion.io/x/pkg/utils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
@@ -33,7 +34,6 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/logclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
@@ -76,7 +76,7 @@ func (manager *SVirtualResourceBaseManager) GetIVirtualModelManager() IVirtualMo
|
||||
return manager.GetVirtualObject().(IVirtualModelManager)
|
||||
}
|
||||
|
||||
/*func (manager *SVirtualResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
/*func (manager *SVirtualResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
q = manager.SProjectizedResourceBaseManager.FilterByOwner(q, owner, scope)
|
||||
return q
|
||||
}
|
||||
@@ -187,7 +187,7 @@ func (manager *SVirtualResourceBaseManager) GetPropertyDomainStatistics(ctx cont
|
||||
return result, q.All(&result)
|
||||
}
|
||||
|
||||
func (manager *SVirtualResourceBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *SVirtualResourceBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
q = manager.SStatusStandaloneResourceBaseManager.FilterByHiddenSystemAttributes(q, userCred, query, scope)
|
||||
|
||||
isSystem := jsonutils.QueryBoolean(query, "system", false)
|
||||
@@ -224,7 +224,7 @@ func (model *SVirtualResourceBase) SetProjectInfo(ctx context.Context, userCred
|
||||
return err
|
||||
}
|
||||
|
||||
func (manager *SVirtualResourceBaseManager) FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
|
||||
func (manager *SVirtualResourceBaseManager) FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
|
||||
q = manager.SStatusStandaloneResourceBaseManager.FilterBySystemAttributes(q, userCred, query, scope)
|
||||
|
||||
var pendingDelete string
|
||||
@@ -394,16 +394,16 @@ func (model *SVirtualResourceBase) PerformChangeOwner(ctx context.Context, userC
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
var requireScope rbacutils.TRbacScope
|
||||
var requireScope rbacscope.TRbacScope
|
||||
if ownerId.GetProjectDomainId() != model.DomainId {
|
||||
// change domain, do check
|
||||
candidates := model.GetIVirtualModel().GetChangeOwnerCandidateDomainIds()
|
||||
if len(candidates) > 0 && !utils.IsInStringArray(ownerId.GetProjectDomainId(), candidates) {
|
||||
return nil, errors.Wrap(httperrors.ErrForbidden, "target domain not in change owner candidate list")
|
||||
}
|
||||
requireScope = rbacutils.ScopeSystem
|
||||
requireScope = rbacscope.ScopeSystem
|
||||
} else {
|
||||
requireScope = rbacutils.ScopeDomain
|
||||
requireScope = rbacscope.ScopeDomain
|
||||
}
|
||||
|
||||
allowScope, policyTags := policy.PolicyManager.AllowScope(userCred, consts.GetServiceType(), model.KeywordPlural(), policy.PolicyActionPerform, "change-owner")
|
||||
|
||||
@@ -23,6 +23,7 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/gotypes"
|
||||
"yunion.io/x/pkg/util/printutils"
|
||||
"yunion.io/x/pkg/utils"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/appsrv"
|
||||
@@ -32,7 +33,6 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/policy"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/auth"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/modulebase"
|
||||
)
|
||||
|
||||
func NewEtcdModelHandler(manger base.IEtcdModelManager) *SEtcdModelHandler {
|
||||
@@ -73,12 +73,12 @@ func (disp *SEtcdModelHandler) FetchUpdateHeaderData(ctx context.Context, header
|
||||
return disp.manager.FetchUpdateHeaderData(ctx, header)
|
||||
}
|
||||
|
||||
func (disp *SEtcdModelHandler) List(ctx context.Context, query jsonutils.JSONObject, ctxIds []dispatcher.SResourceContext) (*modulebase.ListResult, error) {
|
||||
func (disp *SEtcdModelHandler) List(ctx context.Context, query jsonutils.JSONObject, ctxIds []dispatcher.SResourceContext) (*printutils.ListResult, error) {
|
||||
objs, err := disp.manager.AllJson(ctx)
|
||||
if err != nil {
|
||||
return nil, httperrors.NewGeneralError(err)
|
||||
}
|
||||
return &modulebase.ListResult{
|
||||
return &printutils.ListResult{
|
||||
Data: objs,
|
||||
Total: len(objs),
|
||||
Limit: 0,
|
||||
@@ -171,7 +171,7 @@ func (disp *SEtcdModelHandler) Create(ctx context.Context, query jsonutils.JSONO
|
||||
return nil, httperrors.NewNotImplementedError("not implemented")
|
||||
}
|
||||
|
||||
func (disp *SEtcdModelHandler) BatchCreate(ctx context.Context, query jsonutils.JSONObject, data jsonutils.JSONObject, count int, ctxIds []dispatcher.SResourceContext) ([]modulebase.SubmitResult, error) {
|
||||
func (disp *SEtcdModelHandler) BatchCreate(ctx context.Context, query jsonutils.JSONObject, data jsonutils.JSONObject, count int, ctxIds []dispatcher.SResourceContext) ([]printutils.SubmitResult, error) {
|
||||
return nil, httperrors.NewNotImplementedError("not implemented")
|
||||
}
|
||||
|
||||
|
||||
@@ -24,11 +24,11 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/object"
|
||||
"yunion.io/x/pkg/util/stringutils"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/appsrv"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/etcd"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/object"
|
||||
)
|
||||
|
||||
var (
|
||||
|
||||
@@ -18,8 +18,8 @@ import (
|
||||
"context"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/object"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/object"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
)
|
||||
|
||||
|
||||
@@ -25,16 +25,16 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/appctx"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/httputils"
|
||||
"yunion.io/x/pkg/util/sets"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/appctx"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/modulebase"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/modules/identity"
|
||||
npk "yunion.io/x/onecloud/pkg/mcclient/modules/notify"
|
||||
"yunion.io/x/onecloud/pkg/util/httputils"
|
||||
)
|
||||
|
||||
func notifySystemWarning(ctx context.Context, idstr string, name string, event string, reason string) {
|
||||
|
||||
@@ -1,15 +0,0 @@
|
||||
// Copyright 2019 Yunion
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
package object // import "yunion.io/x/onecloud/pkg/cloudcommon/object"
|
||||
@@ -1,32 +0,0 @@
|
||||
// Copyright 2019 Yunion
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
package object
|
||||
|
||||
type IObject interface {
|
||||
SetVirtualObject(virtual interface{})
|
||||
GetVirtualObject() interface{}
|
||||
}
|
||||
|
||||
type SObject struct {
|
||||
virtual interface{}
|
||||
}
|
||||
|
||||
func (o *SObject) SetVirtualObject(virtual interface{}) {
|
||||
o.virtual = virtual
|
||||
}
|
||||
|
||||
func (o *SObject) GetVirtualObject() interface{} {
|
||||
return o.virtual
|
||||
}
|
||||
@@ -33,6 +33,7 @@ import (
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/log/hooks"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/httputils"
|
||||
"yunion.io/x/pkg/util/reflectutils"
|
||||
"yunion.io/x/pkg/util/version"
|
||||
"yunion.io/x/pkg/utils"
|
||||
@@ -41,7 +42,6 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/util/atexit"
|
||||
"yunion.io/x/onecloud/pkg/util/httputils"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
@@ -15,6 +15,8 @@
|
||||
package policy
|
||||
|
||||
import (
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
@@ -22,7 +24,7 @@ var (
|
||||
predefinedDefaultPolicies = []rbacutils.SRbacPolicy{
|
||||
{
|
||||
Auth: true,
|
||||
Scope: rbacutils.ScopeSystem,
|
||||
Scope: rbacscope.ScopeSystem,
|
||||
Rules: []rbacutils.SRbacRule{
|
||||
{
|
||||
Resource: "tasks",
|
||||
@@ -38,7 +40,7 @@ var (
|
||||
},
|
||||
{
|
||||
Auth: true,
|
||||
Scope: rbacutils.ScopeProject,
|
||||
Scope: rbacscope.ScopeProject,
|
||||
Rules: []rbacutils.SRbacRule{
|
||||
{
|
||||
Resource: "tasks",
|
||||
@@ -56,7 +58,7 @@ var (
|
||||
{
|
||||
// for domain
|
||||
Auth: true,
|
||||
Scope: rbacutils.ScopeDomain,
|
||||
Scope: rbacscope.ScopeDomain,
|
||||
Rules: []rbacutils.SRbacRule{
|
||||
{
|
||||
// usages for any services
|
||||
|
||||
@@ -27,6 +27,7 @@ import (
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/gotypes"
|
||||
"yunion.io/x/pkg/util/netutils"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/apis"
|
||||
"yunion.io/x/onecloud/pkg/appsrv"
|
||||
@@ -67,7 +68,7 @@ func init() {
|
||||
}
|
||||
|
||||
type SPolicyManager struct {
|
||||
defaultPolicies map[rbacutils.TRbacScope][]*rbacutils.SRbacPolicy
|
||||
defaultPolicies map[rbacscope.TRbacScope][]*rbacutils.SRbacPolicy
|
||||
|
||||
refreshInterval time.Duration
|
||||
|
||||
@@ -85,9 +86,9 @@ type sPolicyData struct {
|
||||
Enabled bool `json:"enabled"`
|
||||
DomainId string `json:"domain_id"`
|
||||
IsPublic bool `json:"is_public"`
|
||||
PublicScope rbacutils.TRbacScope `json:"public_scope"`
|
||||
PublicScope rbacscope.TRbacScope `json:"public_scope"`
|
||||
SharedDomains []apis.SharedDomain `json:"shared_domain"`
|
||||
Scope rbacutils.TRbacScope `json:"scope"`
|
||||
Scope rbacscope.TRbacScope `json:"scope"`
|
||||
Policy jsonutils.JSONObject `json:"policy"`
|
||||
DomainTags tagutils.TTagSet `json:"domain_tags"`
|
||||
ProjectTags tagutils.TTagSet `json:"project_tags"`
|
||||
@@ -102,7 +103,7 @@ func (manager *SPolicyManager) init(refreshInterval time.Duration) {
|
||||
manager.refreshInterval = refreshInterval
|
||||
// manager.InitSync(manager)
|
||||
if len(predefinedDefaultPolicies) > 0 {
|
||||
policiesMap := make(map[rbacutils.TRbacScope][]*rbacutils.SRbacPolicy)
|
||||
policiesMap := make(map[rbacscope.TRbacScope][]*rbacutils.SRbacPolicy)
|
||||
for i := range predefinedDefaultPolicies {
|
||||
policy := predefinedDefaultPolicies[i]
|
||||
if _, ok := policiesMap[policy.Scope]; !ok {
|
||||
@@ -151,7 +152,7 @@ func policyKey(userCred mcclient.TokenCredential) string {
|
||||
return strings.Join(keys, "-")
|
||||
}
|
||||
|
||||
func permissionKey(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) string {
|
||||
func permissionKey(scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) string {
|
||||
queryKeys := []string{string(scope)}
|
||||
queryKeys = append(queryKeys, userCred.GetProjectId())
|
||||
roles := userCred.GetRoleIds()
|
||||
@@ -178,43 +179,43 @@ func permissionKey(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential
|
||||
return strings.Join(queryKeys, "-")
|
||||
}
|
||||
|
||||
func (manager *SPolicyManager) AllowScope(userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) (rbacutils.TRbacScope, rbacutils.SPolicyResult) {
|
||||
for _, scope := range []rbacutils.TRbacScope{
|
||||
rbacutils.ScopeSystem,
|
||||
rbacutils.ScopeDomain,
|
||||
rbacutils.ScopeProject,
|
||||
rbacutils.ScopeUser,
|
||||
func (manager *SPolicyManager) AllowScope(userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) (rbacscope.TRbacScope, rbacutils.SPolicyResult) {
|
||||
for _, scope := range []rbacscope.TRbacScope{
|
||||
rbacscope.ScopeSystem,
|
||||
rbacscope.ScopeDomain,
|
||||
rbacscope.ScopeProject,
|
||||
rbacscope.ScopeUser,
|
||||
} {
|
||||
result := manager.allow(scope, userCred, service, resource, action, extra...)
|
||||
if result.Result == rbacutils.Allow {
|
||||
return scope, result
|
||||
}
|
||||
}
|
||||
return rbacutils.ScopeNone, rbacutils.PolicyDeny
|
||||
return rbacscope.ScopeNone, rbacutils.PolicyDeny
|
||||
}
|
||||
|
||||
func (manager *SPolicyManager) Allow(targetScope rbacutils.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
|
||||
var retryScopes []rbacutils.TRbacScope
|
||||
func (manager *SPolicyManager) Allow(targetScope rbacscope.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
|
||||
var retryScopes []rbacscope.TRbacScope
|
||||
switch targetScope {
|
||||
case rbacutils.ScopeSystem:
|
||||
retryScopes = []rbacutils.TRbacScope{
|
||||
rbacutils.ScopeSystem,
|
||||
case rbacscope.ScopeSystem:
|
||||
retryScopes = []rbacscope.TRbacScope{
|
||||
rbacscope.ScopeSystem,
|
||||
}
|
||||
case rbacutils.ScopeDomain:
|
||||
retryScopes = []rbacutils.TRbacScope{
|
||||
rbacutils.ScopeSystem,
|
||||
rbacutils.ScopeDomain,
|
||||
case rbacscope.ScopeDomain:
|
||||
retryScopes = []rbacscope.TRbacScope{
|
||||
rbacscope.ScopeSystem,
|
||||
rbacscope.ScopeDomain,
|
||||
}
|
||||
case rbacutils.ScopeProject:
|
||||
retryScopes = []rbacutils.TRbacScope{
|
||||
rbacutils.ScopeSystem,
|
||||
rbacutils.ScopeDomain,
|
||||
rbacutils.ScopeProject,
|
||||
case rbacscope.ScopeProject:
|
||||
retryScopes = []rbacscope.TRbacScope{
|
||||
rbacscope.ScopeSystem,
|
||||
rbacscope.ScopeDomain,
|
||||
rbacscope.ScopeProject,
|
||||
}
|
||||
case rbacutils.ScopeUser:
|
||||
retryScopes = []rbacutils.TRbacScope{
|
||||
rbacutils.ScopeSystem,
|
||||
rbacutils.ScopeUser,
|
||||
case rbacscope.ScopeUser:
|
||||
retryScopes = []rbacscope.TRbacScope{
|
||||
rbacscope.ScopeSystem,
|
||||
rbacscope.ScopeUser,
|
||||
}
|
||||
}
|
||||
for _, scope := range retryScopes {
|
||||
@@ -275,7 +276,7 @@ func (manager *SPolicyManager) fetchMatchedPolicies(userCred mcclient.TokenCrede
|
||||
return res.output, res.err
|
||||
}
|
||||
|
||||
func (manager *SPolicyManager) allow(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
|
||||
func (manager *SPolicyManager) allow(scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
|
||||
// first download userCred policy
|
||||
policies, err := manager.fetchMatchedPolicies(userCred)
|
||||
if err != nil {
|
||||
@@ -302,7 +303,7 @@ func (manager *SPolicyManager) allow(scope rbacutils.TRbacScope, userCred mcclie
|
||||
}
|
||||
|
||||
/*
|
||||
func (manager *SPolicyManager) findPolicyByName(scope rbacutils.TRbacScope, name string) *rbacutils.SRbacPolicyCore {
|
||||
func (manager *SPolicyManager) findPolicyByName(scope rbacscope.TRbacScope, name string) *rbacscope.SRbacPolicyCore {
|
||||
if policies, ok := manager.policies[scope]; ok {
|
||||
for i := range policies {
|
||||
if policies[i].Id == name || policies[i].Name == name {
|
||||
@@ -313,13 +314,13 @@ func (manager *SPolicyManager) findPolicyByName(scope rbacutils.TRbacScope, name
|
||||
return nil
|
||||
}
|
||||
|
||||
func getMatchedPolicyNames(policies []rbacutils.SPolicyInfo, userCred rbacutils.IRbacIdentity) []string {
|
||||
_, matchNames := rbacutils.GetMatchedPolicies(policies, userCred)
|
||||
func getMatchedPolicyNames(policies []rbacscope.SPolicyInfo, userCred rbacscope.IRbacIdentity) []string {
|
||||
_, matchNames := rbacscope.GetMatchedPolicies(policies, userCred)
|
||||
return matchNames
|
||||
}
|
||||
|
||||
func getMatchedPolicyRules(policies []rbacutils.SPolicyInfo, userCred rbacutils.IRbacIdentity, service string, resource string, action string, extra ...string) ([]rbacutils.SRbacRule, bool) {
|
||||
matchPolicies, _ := rbacutils.GetMatchedPolicies(policies, userCred)
|
||||
func getMatchedPolicyRules(policies []rbacscope.SPolicyInfo, userCred rbacscope.IRbacIdentity, service string, resource string, action string, extra ...string) ([]rbacscope.SRbacRule, bool) {
|
||||
matchPolicies, _ := rbacscope.GetMatchedPolicies(policies, userCred)
|
||||
if len(matchPolicies) == 0 {
|
||||
return nil, false
|
||||
}
|
||||
@@ -327,7 +328,7 @@ func getMatchedPolicyRules(policies []rbacutils.SPolicyInfo, userCred rbacutils.
|
||||
}
|
||||
*/
|
||||
|
||||
func (manager *SPolicyManager) allowWithoutCache(policies rbacutils.TPolicySet, scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
|
||||
func (manager *SPolicyManager) allowWithoutCache(policies rbacutils.TPolicySet, scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
|
||||
matchRules := rbacutils.TPolicyMatches{}
|
||||
|
||||
if len(policies) == 0 {
|
||||
@@ -338,19 +339,19 @@ func (manager *SPolicyManager) allowWithoutCache(policies rbacutils.TPolicySet,
|
||||
|
||||
scopedDeny := false
|
||||
switch scope {
|
||||
case rbacutils.ScopeUser:
|
||||
case rbacscope.ScopeUser:
|
||||
if !isUserResource(service, resource) {
|
||||
scopedDeny = true
|
||||
}
|
||||
case rbacutils.ScopeProject:
|
||||
case rbacscope.ScopeProject:
|
||||
if !isProjectResource(service, resource) {
|
||||
scopedDeny = true
|
||||
}
|
||||
case rbacutils.ScopeDomain:
|
||||
case rbacscope.ScopeDomain:
|
||||
if isSystemResource(service, resource) {
|
||||
scopedDeny = true
|
||||
}
|
||||
case rbacutils.ScopeSystem:
|
||||
case rbacscope.ScopeSystem:
|
||||
// no deny at all for system scope
|
||||
}
|
||||
if scopedDeny {
|
||||
@@ -411,10 +412,10 @@ func fetchPolicyDataByIdOrName(ctx context.Context, id string) (*sPolicyData, er
|
||||
return pdata, nil
|
||||
}
|
||||
|
||||
func explainPolicyInternal(userCred mcclient.TokenCredential, policyReq jsonutils.JSONObject, policyData *sPolicyData) (rbacutils.TRbacScope, []string, rbacutils.SPolicyResult, rbacutils.SPolicyResult, error) {
|
||||
func explainPolicyInternal(userCred mcclient.TokenCredential, policyReq jsonutils.JSONObject, policyData *sPolicyData) (rbacscope.TRbacScope, []string, rbacutils.SPolicyResult, rbacutils.SPolicyResult, error) {
|
||||
policySeq, err := policyReq.GetArray()
|
||||
if err != nil {
|
||||
return rbacutils.ScopeSystem, nil, rbacutils.PolicyDeny, rbacutils.PolicyDeny, httperrors.NewInputParameterError("invalid format")
|
||||
return rbacscope.ScopeSystem, nil, rbacutils.PolicyDeny, rbacutils.PolicyDeny, httperrors.NewInputParameterError("invalid format")
|
||||
}
|
||||
service := rbacutils.WILD_MATCH
|
||||
resource := rbacutils.WILD_MATCH
|
||||
@@ -442,7 +443,7 @@ func explainPolicyInternal(userCred mcclient.TokenCredential, policyReq jsonutil
|
||||
}
|
||||
|
||||
scopeStr, _ := policySeq[0].GetString()
|
||||
scope := rbacutils.String2Scope(scopeStr)
|
||||
scope := rbacscope.String2Scope(scopeStr)
|
||||
|
||||
userResult := PolicyManager.Allow(scope, userCred, service, resource, action, extra...)
|
||||
result := userResult
|
||||
@@ -496,7 +497,7 @@ func ExplainRpc(ctx context.Context, userCred mcclient.TokenCredential, params j
|
||||
return ret, nil
|
||||
}
|
||||
|
||||
func (manager *SPolicyManager) IsScopeCapable(userCred mcclient.TokenCredential, scope rbacutils.TRbacScope) bool {
|
||||
func (manager *SPolicyManager) IsScopeCapable(userCred mcclient.TokenCredential, scope rbacscope.TRbacScope) bool {
|
||||
policies, err := manager.fetchMatchedPolicies(userCred)
|
||||
if err != nil {
|
||||
log.Errorf("fetchMatchedPolicyGroup fail %s", err)
|
||||
@@ -511,7 +512,7 @@ func (manager *SPolicyManager) IsScopeCapable(userCred mcclient.TokenCredential,
|
||||
}
|
||||
|
||||
/*
|
||||
func (manager *SPolicyManager) MatchedPolicyNames(ctx context.Context, scope rbacutils.TRbacScope, ident rbacutils.IRbacIdentity) []string {
|
||||
func (manager *SPolicyManager) MatchedPolicyNames(ctx context.Context, scope rbacscope.TRbacScope, ident rbacscope.IRbacIdentity) []string {
|
||||
policies, err := manager.fetchMatchedPolicies(ctx, userCred)
|
||||
if err != nil {
|
||||
log.Errorf("fetchMatchedPolicyGroup fail %s", err)
|
||||
@@ -540,7 +541,7 @@ func (manager *SPolicyManager) AllPolicies() map[string][]string {
|
||||
}
|
||||
|
||||
func (manager *SPolicyManager) RoleMatchPolicies(roleName string) []string {
|
||||
ident := rbacutils.NewRbacIdentity("", "", []string{roleName})
|
||||
ident := rbacscope.NewRbacIdentity("", "", []string{roleName})
|
||||
ret := make([]string, 0)
|
||||
for _, policies := range manager.policies {
|
||||
for i := range policies {
|
||||
@@ -552,17 +553,17 @@ func (manager *SPolicyManager) RoleMatchPolicies(roleName string) []string {
|
||||
return ret
|
||||
}
|
||||
|
||||
func (manager *SPolicyManager) GetMatchedPolicySet(userCred rbacutils.IRbacIdentity) (rbacutils.TRbacScope, rbacutils.TPolicySet) {
|
||||
for _, scope := range []rbacutils.TRbacScope{
|
||||
rbacutils.ScopeSystem,
|
||||
rbacutils.ScopeDomain,
|
||||
rbacutils.ScopeProject,
|
||||
func (manager *SPolicyManager) GetMatchedPolicySet(userCred rbacscope.IRbacIdentity) (rbacscope.TRbacScope, rbacscope.TPolicySet) {
|
||||
for _, scope := range []rbacscope.TRbacScope{
|
||||
rbacscope.ScopeSystem,
|
||||
rbacscope.ScopeDomain,
|
||||
rbacscope.ScopeProject,
|
||||
} {
|
||||
macthed, _ := rbacutils.GetMatchedPolicies(manager.policies[scope], userCred)
|
||||
macthed, _ := rbacscope.GetMatchedPolicies(manager.policies[scope], userCred)
|
||||
if len(macthed) > 0 {
|
||||
return scope, macthed
|
||||
}
|
||||
}
|
||||
return rbacutils.ScopeNone, nil
|
||||
return rbacscope.ScopeNone, nil
|
||||
}
|
||||
*/
|
||||
|
||||
@@ -18,6 +18,7 @@ import (
|
||||
"context"
|
||||
|
||||
"yunion.io/x/pkg/gotypes"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/auth"
|
||||
@@ -30,10 +31,10 @@ type SPolicyTokenCredential struct {
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) HasSystemAdminPrivilege() bool {
|
||||
return PolicyManager.IsScopeCapable(self.TokenCredential, rbacutils.ScopeSystem)
|
||||
return PolicyManager.IsScopeCapable(self.TokenCredential, rbacscope.ScopeSystem)
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) IsAllow(targetScope rbacutils.TRbacScope, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
|
||||
func (self *SPolicyTokenCredential) IsAllow(targetScope rbacscope.TRbacScope, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
|
||||
allowScope, result := PolicyManager.AllowScope(self.TokenCredential, service, resource, action, extra...)
|
||||
if result.Result == rbacutils.Allow && !targetScope.HigherThan(allowScope) {
|
||||
return result
|
||||
|
||||
@@ -18,9 +18,10 @@ import (
|
||||
"database/sql"
|
||||
"fmt"
|
||||
|
||||
"yunion.io/x/pkg/util/httputils"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/util/choices"
|
||||
"yunion.io/x/onecloud/pkg/util/httputils"
|
||||
)
|
||||
|
||||
var returnHttpError = true
|
||||
|
||||
@@ -22,8 +22,8 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/appctx"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/appctx"
|
||||
"yunion.io/x/onecloud/pkg/appsrv"
|
||||
)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user