fix: remove mutual dependency of cloudmux on onecloud (#15621)

Co-authored-by: Qiu Jian <qiujian@yunionyun.com>
This commit is contained in:
Jian Qiu
2022-12-27 01:21:26 +08:00
committed by GitHub
co-authored by Qiu Jian
parent 9804fbaf7a
commit 21716cefb5
1123 changed files with 36590 additions and 19291 deletions
+2 -2
View File
@@ -22,16 +22,16 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/object"
"yunion.io/x/pkg/util/httputils"
"yunion.io/x/pkg/util/version"
api "yunion.io/x/onecloud/pkg/apis/compute"
"yunion.io/x/onecloud/pkg/cloudcommon/agent/iagent"
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
"yunion.io/x/onecloud/pkg/cloudcommon/object"
"yunion.io/x/onecloud/pkg/hostman/storageman"
"yunion.io/x/onecloud/pkg/mcclient"
modules "yunion.io/x/onecloud/pkg/mcclient/modules/compute"
"yunion.io/x/onecloud/pkg/util/httputils"
)
type SZoneInfo struct {
+2 -1
View File
@@ -19,6 +19,7 @@ import (
"net/http"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/onecloud/pkg/appsrv"
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
@@ -31,7 +32,7 @@ import (
func ExportOptionsHandler(app *appsrv.Application, options interface{}) {
hf := func(ctx context.Context, w http.ResponseWriter, r *http.Request) {
userCred := auth.FetchUserCredential(ctx, policy.FilterPolicyCredential)
result := policy.PolicyManager.Allow(rbacutils.ScopeSystem, userCred, consts.GetServiceType(), "app-options", "list")
result := policy.PolicyManager.Allow(rbacscope.ScopeSystem, userCred, consts.GetServiceType(), "app-options", "list")
if result.Result == rbacutils.Deny {
httperrors.ForbiddenError(ctx, w, "Not allow to access")
return
+1 -1
View File
@@ -23,9 +23,9 @@ import (
"time"
"yunion.io/x/log"
"yunion.io/x/pkg/appctx"
"yunion.io/x/pkg/errors"
"yunion.io/x/onecloud/pkg/appctx"
"yunion.io/x/onecloud/pkg/appsrv"
"yunion.io/x/onecloud/pkg/cloudcommon/elect"
"yunion.io/x/onecloud/pkg/mcclient"
+3 -3
View File
@@ -18,10 +18,10 @@ import (
"context"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
@@ -66,13 +66,13 @@ func ApplyQueryDistinctExtraField(
}
type FilterByOwnerProvider interface {
FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery
FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery
}
func ApplyFilterByOwner(
q *sqlchemy.SQuery,
owner mcclient.IIdentityProvider,
scope rbacutils.TRbacScope,
scope rbacscope.TRbacScope,
managers ...FilterByOwnerProvider,
) *sqlchemy.SQuery {
for _, manager := range managers {
+1 -1
View File
@@ -23,9 +23,9 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/appctx"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/appctx"
"yunion.io/x/onecloud/pkg/appsrv"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/splitable"
+15 -14
View File
@@ -27,6 +27,8 @@ import (
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/gotypes"
"yunion.io/x/pkg/util/filterclause"
"yunion.io/x/pkg/util/printutils"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/version"
"yunion.io/x/pkg/utils"
"yunion.io/x/sqlchemy"
@@ -39,7 +41,6 @@ import (
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/mcclient/auth"
"yunion.io/x/onecloud/pkg/mcclient/modulebase"
"yunion.io/x/onecloud/pkg/util/logclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
@@ -348,7 +349,7 @@ func mergeFields(metaFields, queryFields []string, isSysAdmin bool) stringutils2
func Query2List(manager IModelManager, ctx context.Context, userCred mcclient.TokenCredential, q *sqlchemy.SQuery, query jsonutils.JSONObject, delayFetch bool) ([]jsonutils.JSONObject, error) {
metaFields, excludeFields := listFields(manager, userCred)
fieldFilter := jsonutils.GetQueryStringArray(query, "field")
allowListResult := IsAllowList(rbacutils.ScopeSystem, userCred, manager)
allowListResult := IsAllowList(rbacscope.ScopeSystem, userCred, manager)
listF := mergeFields(metaFields, fieldFilter, allowListResult.Result.IsAllow())
listExcludes, _, _ := stringutils2.Split(stringutils2.NewSortedStrings(excludeFields), listF)
@@ -526,7 +527,7 @@ func fetchContextObject(manager IModelManager, ctx context.Context, userCred mcc
return nil, httperrors.NewInternalServerError("No such context %s(%s)", ctxId.Type, ctxId.Id)
}
func ListItems(manager IModelManager, ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, ctxIds []dispatcher.SResourceContext) (*modulebase.ListResult, error) {
func ListItems(manager IModelManager, ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, ctxIds []dispatcher.SResourceContext) (*printutils.ListResult, error) {
var err error
var maxLimit int64 = consts.GetMaxPagingLimit()
limit, _ := query.Int("limit")
@@ -626,7 +627,7 @@ func ListItems(manager IModelManager, ctx context.Context, userCred mcclient.Tok
union, err := sqlchemy.UnionWithError(subqs...)
if err != nil {
if errors.Cause(err) == sql.ErrNoRows {
emptyList := modulebase.ListResult{Data: []jsonutils.JSONObject{}}
emptyList := printutils.ListResult{Data: []jsonutils.JSONObject{}}
return &emptyList, nil
} else {
return nil, errors.Wrap(err, "sqlchemy.UnionWithError")
@@ -654,7 +655,7 @@ func ListItems(manager IModelManager, ctx context.Context, userCred mcclient.Tok
}
//log.Debugf("total count %d", totalCnt)
if totalCnt == 0 {
emptyList := modulebase.ListResult{Data: []jsonutils.JSONObject{}}
emptyList := printutils.ListResult{Data: []jsonutils.JSONObject{}}
return &emptyList, nil
}
}
@@ -768,7 +769,7 @@ func ListItems(manager IModelManager, ctx context.Context, userCred mcclient.Tok
retList = retList[:limit]
}
nextMarker := encodePagingMarker(nextMarkers)
retResult := modulebase.ListResult{
retResult := printutils.ListResult{
Data: retList, Limit: int(limit),
NextMarker: nextMarker,
MarkerField: strings.Join(pagingConf.MarkerFields, ","),
@@ -820,7 +821,7 @@ func ListItems(manager IModelManager, ctx context.Context, userCred mcclient.Tok
return calculateListResult(retList, int64(totalCnt), limit, offset, paginate), nil
}
func calculateListResult(data []jsonutils.JSONObject, total, limit, offset int64, paginate bool) *modulebase.ListResult {
func calculateListResult(data []jsonutils.JSONObject, total, limit, offset int64, paginate bool) *printutils.ListResult {
if paginate {
// do offset first
if offset > 0 {
@@ -838,7 +839,7 @@ func calculateListResult(data []jsonutils.JSONObject, total, limit, offset int64
}
}
retResult := modulebase.ListResult{Data: data, Total: int(total), Limit: int(limit), Offset: int(offset)}
retResult := printutils.ListResult{Data: data, Total: int(total), Limit: int(limit), Offset: int(offset)}
return &retResult
}
@@ -855,7 +856,7 @@ func getExportCols(query jsonutils.JSONObject, retList []jsonutils.JSONObject) [
return retList
}
func (dispatcher *DBModelDispatcher) List(ctx context.Context, query jsonutils.JSONObject, ctxIds []dispatcher.SResourceContext) (*modulebase.ListResult, error) {
func (dispatcher *DBModelDispatcher) List(ctx context.Context, query jsonutils.JSONObject, ctxIds []dispatcher.SResourceContext) (*printutils.ListResult, error) {
userCred := fetchUserCredential(ctx)
manager := dispatcher.manager.GetImmutableInstance(ctx, userCred, query)
@@ -913,7 +914,7 @@ func getItemDetails(manager IModelManager, item IModel, ctx context.Context, use
return nil, errors.Wrap(err, "FetchCustomizeColumns")
}
if len(extraRows) == 1 {
getFields := mergeFields(metaFields, fieldFilter, IsAllowGet(ctx, rbacutils.ScopeSystem, userCred, item))
getFields := mergeFields(metaFields, fieldFilter, IsAllowGet(ctx, rbacscope.ScopeSystem, userCred, item))
excludes, _, _ := stringutils2.Split(stringutils2.NewSortedStrings(excludeFields), getFields)
return extraRows[0].CopyExcludes(excludes...), nil
}
@@ -1047,7 +1048,7 @@ func (dispatcher *DBModelDispatcher) GetSpecific(ctx context.Context, idStr stri
func fetchOwnerId(ctx context.Context, manager IModelManager, userCred mcclient.TokenCredential, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error) {
var ownerId mcclient.IIdentityProvider
var err error
if manager.ResourceScope() != rbacutils.ScopeSystem {
if manager.ResourceScope() != rbacscope.ScopeSystem {
ownerId, err = manager.FetchOwnerId(ctx, data)
if err != nil {
return nil, httperrors.NewGeneralError(err)
@@ -1370,7 +1371,7 @@ func expandMultiCreateParams(manager IModelManager, data jsonutils.JSONObject, c
return ret, nil
}
func (dispatcher *DBModelDispatcher) BatchCreate(ctx context.Context, query jsonutils.JSONObject, data jsonutils.JSONObject, count int, ctxIds []dispatcher.SResourceContext) ([]modulebase.SubmitResult, error) {
func (dispatcher *DBModelDispatcher) BatchCreate(ctx context.Context, query jsonutils.JSONObject, data jsonutils.JSONObject, count int, ctxIds []dispatcher.SResourceContext) ([]printutils.SubmitResult, error) {
userCred := fetchUserCredential(ctx)
manager := dispatcher.manager.GetMutableInstance(ctx, userCred, query, data)
@@ -1461,10 +1462,10 @@ func (dispatcher *DBModelDispatcher) BatchCreate(ctx context.Context, query json
return nil, httperrors.NewGeneralError(errors.Wrap(err, "createResults"))
}
results := make([]modulebase.SubmitResult, count)
results := make([]printutils.SubmitResult, count)
models := make([]IModel, 0)
for i, res := range createResults {
result := modulebase.SubmitResult{}
result := printutils.SubmitResult{}
if res.err != nil {
jsonErr := httperrors.NewGeneralError(res.err)
result.Status = jsonErr.Code
+4 -4
View File
@@ -21,12 +21,12 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/util/printutils"
"yunion.io/x/onecloud/pkg/cloudcommon/db/lockman"
"yunion.io/x/onecloud/pkg/cloudcommon/policy"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/mcclient/modulebase"
)
type DBJointModelDispatcher struct {
@@ -58,7 +58,7 @@ func (dispatcher *DBJointModelDispatcher) SlaveKeywordPlural() string {
return jointManager.GetSlaveManager().KeywordPlural()
}
func (dispatcher *DBJointModelDispatcher) ListMasterDescendent(ctx context.Context, idStr string, query jsonutils.JSONObject) (*modulebase.ListResult, error) {
func (dispatcher *DBJointModelDispatcher) ListMasterDescendent(ctx context.Context, idStr string, query jsonutils.JSONObject) (*printutils.ListResult, error) {
//log.Debugf("ListMasterDescendent %s %s", dispatcher.JointModelManager().GetMasterManager().Keyword(), idStr)
userCred := fetchUserCredential(ctx)
@@ -85,7 +85,7 @@ func (dispatcher *DBJointModelDispatcher) ListMasterDescendent(ctx context.Conte
return dispatcher._listJoint(ctx, userCred, model.(IStandaloneModel), queryDict)
}
func (dispatcher *DBJointModelDispatcher) ListSlaveDescendent(ctx context.Context, idStr string, query jsonutils.JSONObject) (*modulebase.ListResult, error) {
func (dispatcher *DBJointModelDispatcher) ListSlaveDescendent(ctx context.Context, idStr string, query jsonutils.JSONObject) (*printutils.ListResult, error) {
//log.Debugf("ListSlaveDescendent %s %s", dispatcher.JointModelManager().GetMasterManager().Keyword(), idStr)
userCred := fetchUserCredential(ctx)
@@ -112,7 +112,7 @@ func (dispatcher *DBJointModelDispatcher) ListSlaveDescendent(ctx context.Contex
return dispatcher._listJoint(ctx, userCred, model.(IStandaloneModel), queryDict)
}
func (dispatcher *DBJointModelDispatcher) _listJoint(ctx context.Context, userCred mcclient.TokenCredential, ctxModel IStandaloneModel, queryDict jsonutils.JSONObject) (*modulebase.ListResult, error) {
func (dispatcher *DBJointModelDispatcher) _listJoint(ctx context.Context, userCred mcclient.TokenCredential, ctxModel IStandaloneModel, queryDict jsonutils.JSONObject) (*printutils.ListResult, error) {
items, err := ListItems(dispatcher.JointModelManager(), ctx, userCred, queryDict, nil)
if err != nil {
log.Errorf("Fail to list items: %s", err)
+8 -8
View File
@@ -20,6 +20,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/reflectutils"
"yunion.io/x/sqlchemy"
@@ -28,7 +29,6 @@ import (
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
"yunion.io/x/onecloud/pkg/util/tagutils"
)
@@ -41,22 +41,22 @@ type SDomainizedResourceBase struct {
DomainId string `width:"64" charset:"ascii" default:"default" nullable:"false" index:"true" list:"user" json:"domain_id"`
}
func (manager *SDomainizedResourceBaseManager) NamespaceScope() rbacutils.TRbacScope {
func (manager *SDomainizedResourceBaseManager) NamespaceScope() rbacscope.TRbacScope {
if consts.IsDomainizedNamespace() {
return rbacutils.ScopeDomain
return rbacscope.ScopeDomain
} else {
return rbacutils.ScopeSystem
return rbacscope.ScopeSystem
}
}
func (manager *SDomainizedResourceBaseManager) ResourceScope() rbacutils.TRbacScope {
return rbacutils.ScopeDomain
func (manager *SDomainizedResourceBaseManager) ResourceScope() rbacscope.TRbacScope {
return rbacscope.ScopeDomain
}
func (manager *SDomainizedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *SDomainizedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
if owner != nil {
switch scope {
case rbacutils.ScopeProject, rbacutils.ScopeDomain:
case rbacscope.ScopeProject, rbacscope.ScopeDomain:
q = q.Equals("domain_id", owner.GetProjectDomainId())
}
}
+24 -23
View File
@@ -22,6 +22,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
@@ -309,21 +310,21 @@ func (m *sUsageManager) KeywordPlural() string {
return "usages"
}
func (m *sUsageManager) ResourceScope() rbacutils.TRbacScope {
return rbacutils.ScopeProject
func (m *sUsageManager) ResourceScope() rbacscope.TRbacScope {
return rbacscope.ScopeProject
}
func (m *sUsageManager) FetchOwnerId(ctx context.Context, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error) {
return FetchProjectInfo(ctx, data)
}
func FetchUsageOwnerScope(ctx context.Context, userCred mcclient.TokenCredential, data jsonutils.JSONObject) (mcclient.IIdentityProvider, rbacutils.TRbacScope, error, rbacutils.SPolicyResult) {
func FetchUsageOwnerScope(ctx context.Context, userCred mcclient.TokenCredential, data jsonutils.JSONObject) (mcclient.IIdentityProvider, rbacscope.TRbacScope, error, rbacutils.SPolicyResult) {
return FetchCheckQueryOwnerScope(ctx, userCred, data, &sUsageManager{}, policy.PolicyActionGet, true)
}
type IScopedResourceManager interface {
KeywordPlural() string
ResourceScope() rbacutils.TRbacScope
ResourceScope() rbacscope.TRbacScope
FetchOwnerId(ctx context.Context, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error)
}
@@ -334,12 +335,12 @@ func FetchCheckQueryOwnerScope(
manager IScopedResourceManager,
action string,
doCheckRbac bool,
) (mcclient.IIdentityProvider, rbacutils.TRbacScope, error, rbacutils.SPolicyResult) {
var scope rbacutils.TRbacScope
) (mcclient.IIdentityProvider, rbacscope.TRbacScope, error, rbacutils.SPolicyResult) {
var scope rbacscope.TRbacScope
var allowScope rbacutils.TRbacScope
var requireScope rbacutils.TRbacScope
var queryScope rbacutils.TRbacScope
var allowScope rbacscope.TRbacScope
var requireScope rbacscope.TRbacScope
var queryScope rbacscope.TRbacScope
var policyTagFilters rbacutils.SPolicyResult
resScope := manager.ResourceScope()
@@ -352,40 +353,40 @@ func FetchCheckQueryOwnerScope(
}
if ownerId != nil {
switch resScope {
case rbacutils.ScopeProject, rbacutils.ScopeDomain:
case rbacscope.ScopeProject, rbacscope.ScopeDomain:
if len(ownerId.GetProjectId()) > 0 {
queryScope = rbacutils.ScopeProject
queryScope = rbacscope.ScopeProject
if ownerId.GetProjectId() == userCred.GetProjectId() {
requireScope = rbacutils.ScopeProject
requireScope = rbacscope.ScopeProject
} else if ownerId.GetProjectDomainId() == userCred.GetProjectDomainId() {
requireScope = rbacutils.ScopeDomain
requireScope = rbacscope.ScopeDomain
} else {
requireScope = rbacutils.ScopeSystem
requireScope = rbacscope.ScopeSystem
}
} else if len(ownerId.GetProjectDomainId()) > 0 {
queryScope = rbacutils.ScopeDomain
queryScope = rbacscope.ScopeDomain
if ownerId.GetProjectDomainId() == userCred.GetProjectDomainId() {
requireScope = rbacutils.ScopeDomain
requireScope = rbacscope.ScopeDomain
} else {
requireScope = rbacutils.ScopeSystem
requireScope = rbacscope.ScopeSystem
}
}
case rbacutils.ScopeUser:
queryScope = rbacutils.ScopeUser
case rbacscope.ScopeUser:
queryScope = rbacscope.ScopeUser
if ownerId.GetUserId() == userCred.GetUserId() {
requireScope = rbacutils.ScopeUser
requireScope = rbacscope.ScopeUser
} else {
requireScope = rbacutils.ScopeSystem
requireScope = rbacscope.ScopeSystem
}
}
} else {
ownerId = userCred
reqScopeStr, _ := data.GetString("scope")
if len(reqScopeStr) > 0 {
queryScope = rbacutils.String2Scope(reqScopeStr)
queryScope = rbacscope.String2Scope(reqScopeStr)
} else if data.Contains("admin") {
isAdmin := jsonutils.QueryBoolean(data, "admin", false)
if isAdmin && allowScope.HigherThan(rbacutils.ScopeProject) {
if isAdmin && allowScope.HigherThan(rbacscope.ScopeProject) {
queryScope = allowScope
}
} else if action == policy.PolicyActionGet {
+6 -6
View File
@@ -19,13 +19,13 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/apis"
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
@@ -54,7 +54,7 @@ func (manager *SInfrasResourceBaseManager) GetIInfrasModelManager() IInfrasModel
return manager.GetVirtualObject().(IInfrasModelManager)
}
func (manager *SInfrasResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *SInfrasResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
return SharableManagerFilterByOwner(manager.GetIInfrasModelManager(), q, owner, scope)
}
@@ -215,16 +215,16 @@ func (model *SInfrasResourceBase) Delete(ctx context.Context, userCred mcclient.
func (model *SInfrasResourceBase) GetSharedInfo() apis.SShareInfo {
ret := apis.SShareInfo{}
ret.IsPublic = model.IsPublic
ret.PublicScope = rbacutils.String2ScopeDefault(model.PublicScope, rbacutils.ScopeNone)
ret.PublicScope = rbacscope.String2ScopeDefault(model.PublicScope, rbacscope.ScopeNone)
ret.SharedDomains = model.GetSharedDomains()
ret.SharedProjects = nil
// fix
if len(ret.SharedDomains) > 0 {
ret.PublicScope = rbacutils.ScopeDomain
ret.PublicScope = rbacscope.ScopeDomain
ret.SharedProjects = nil
ret.IsPublic = true
} else if !ret.IsPublic {
ret.PublicScope = rbacutils.ScopeNone
ret.PublicScope = rbacscope.ScopeNone
}
return ret
}
@@ -248,7 +248,7 @@ func (model *SInfrasResourceBase) SyncShareState(ctx context.Context, userCred m
if model.PublicSrc != string(apis.OWNER_SOURCE_LOCAL) {
model.SaveSharedInfo(apis.OWNER_SOURCE_CLOUD, ctx, userCred, apis.SShareInfo{
IsPublic: true,
PublicScope: rbacutils.ScopeSystem,
PublicScope: rbacscope.ScopeSystem,
})
}
return
+7 -7
View File
@@ -20,13 +20,13 @@ import (
"time"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/object"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/appsrv"
"yunion.io/x/onecloud/pkg/cloudcommon/db/lockman"
"yunion.io/x/onecloud/pkg/cloudcommon/object"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/splitable"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
@@ -75,9 +75,9 @@ type IModelManager interface {
FilterById(q *sqlchemy.SQuery, idStr string) *sqlchemy.SQuery
FilterByNotId(q *sqlchemy.SQuery, idStr string) *sqlchemy.SQuery
FilterByName(q *sqlchemy.SQuery, name string) *sqlchemy.SQuery
FilterByOwner(q *sqlchemy.SQuery, userCred mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery
FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery
FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery
FilterByOwner(q *sqlchemy.SQuery, userCred mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery
FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery
FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery
FilterByUniqValues(q *sqlchemy.SQuery, uniqValues jsonutils.JSONObject) *sqlchemy.SQuery
// GetOwnerId(userCred mcclient.IIdentityProvider) mcclient.IIdentityProvider
@@ -125,8 +125,8 @@ type IModelManager interface {
FetchUniqValues(ctx context.Context, data jsonutils.JSONObject) jsonutils.JSONObject
/* name uniqueness scope, system/domain/project, default is system */
NamespaceScope() rbacutils.TRbacScope
ResourceScope() rbacutils.TRbacScope
NamespaceScope() rbacscope.TRbacScope
ResourceScope() rbacscope.TRbacScope
// 如果error为非空,说明没有匹配的field,如果为空,说明匹配上了
QueryDistinctExtraField(q *sqlchemy.SQuery, field string) (*sqlchemy.SQuery, error)
+4 -4
View File
@@ -22,12 +22,12 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/reflectutils"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/apis"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
@@ -171,12 +171,12 @@ func (joint *SJointResourceBase) GetIJointModel() IJointModel {
return joint.GetVirtualObject().(IJointModel)
}
func (manager *SJointResourceBaseManager) ResourceScope() rbacutils.TRbacScope {
func (manager *SJointResourceBaseManager) ResourceScope() rbacscope.TRbacScope {
return manager.GetMasterManager().ResourceScope()
}
func (manager *SJointResourceBaseManager) NamespaceScope() rbacutils.TRbacScope {
return rbacutils.ScopeSystem
func (manager *SJointResourceBaseManager) NamespaceScope() rbacscope.TRbacScope {
return rbacscope.ScopeSystem
}
func (manager *SJointResourceBaseManager) ValidateCreateData(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, input apis.JoinResourceBaseCreateInput) (apis.JoinResourceBaseCreateInput, error) {
+4 -3
View File
@@ -15,14 +15,15 @@
package db
import (
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
func GetLockClassKey(manager IModelManager, ownerId mcclient.IIdentityProvider) string {
if manager.NamespaceScope() == rbacutils.ScopeSystem {
if manager.NamespaceScope() == rbacscope.ScopeSystem {
return ""
} else if manager.NamespaceScope() == rbacutils.ScopeDomain {
} else if manager.NamespaceScope() == rbacscope.ScopeDomain {
return ownerId.GetProjectDomainId()
} else {
return ownerId.GetProjectId()
+9 -9
View File
@@ -24,6 +24,8 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/printutils"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/stringutils"
"yunion.io/x/pkg/utils"
"yunion.io/x/sqlchemy"
@@ -35,8 +37,6 @@ import (
"yunion.io/x/onecloud/pkg/cloudcommon/policy"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/mcclient/modulebase"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
const (
@@ -223,7 +223,7 @@ func (manager *SMetadataManager) GetPropertyTagValuePairs(
ctx context.Context,
userCred mcclient.TokenCredential,
input apis.MetaGetPropertyTagValuePairsInput,
) (*modulebase.ListResult, error) {
) (*printutils.ListResult, error) {
q, err := manager.fetchKeyValueQuery(ctx, userCred, input)
if err != nil {
return nil, errors.Wrap(err, "fetchKeyValueQuery")
@@ -235,7 +235,7 @@ func (manager *SMetadataManager) GetPropertyTagValuePairs(
}
if totalCnt == 0 {
emptyList := modulebase.ListResult{Data: []jsonutils.JSONObject{}}
emptyList := printutils.ListResult{Data: []jsonutils.JSONObject{}}
return &emptyList, nil
}
@@ -268,7 +268,7 @@ func (manager *SMetadataManager) GetPropertyTagValuePairs(
if err != nil {
return nil, errors.Wrap(err, "metadataQuery2List")
}
emptyList := modulebase.ListResult{
emptyList := printutils.ListResult{
Data: data,
Total: totalCnt,
Limit: int(limit),
@@ -383,7 +383,7 @@ func (manager *SMetadataManager) ListItemFilter(ctx context.Context, q *sqlchemy
))
}
if !(input.Scope == string(rbacutils.ScopeSystem) && userCred.HasSystemAdminPrivilege()) {
if !(input.Scope == string(rbacscope.ScopeSystem) && userCred.HasSystemAdminPrivilege()) {
resources := input.Resources
if len(resources) == 0 {
for resource := range globalTables {
@@ -432,7 +432,7 @@ func (manager *SMetadataManager) ListItemFilter(ctx context.Context, q *sqlchemy
}
func (manager *SMetadataManager) GetStringValue(ctx context.Context, model IModel, key string, userCred mcclient.TokenCredential) string {
if strings.HasPrefix(key, SYSTEM_ADMIN_PREFIX) && (userCred == nil || !IsAllowGetSpec(ctx, rbacutils.ScopeSystem, userCred, model, "metadata")) {
if strings.HasPrefix(key, SYSTEM_ADMIN_PREFIX) && (userCred == nil || !IsAllowGetSpec(ctx, rbacscope.ScopeSystem, userCred, model, "metadata")) {
return ""
}
idStr := GetModelIdstr(model)
@@ -445,7 +445,7 @@ func (manager *SMetadataManager) GetStringValue(ctx context.Context, model IMode
}
func (manager *SMetadataManager) GetJsonValue(ctx context.Context, model IModel, key string, userCred mcclient.TokenCredential) jsonutils.JSONObject {
if strings.HasPrefix(key, SYSTEM_ADMIN_PREFIX) && (userCred == nil || !IsAllowGetSpec(ctx, rbacutils.ScopeSystem, userCred, model, "metadata")) {
if strings.HasPrefix(key, SYSTEM_ADMIN_PREFIX) && (userCred == nil || !IsAllowGetSpec(ctx, rbacscope.ScopeSystem, userCred, model, "metadata")) {
return nil
}
idStr := GetModelIdstr(model)
@@ -645,7 +645,7 @@ func (manager *SMetadataManager) GetAll(ctx context.Context, obj IModel, keys []
}
ret := make(map[string]string)
for k, v := range meta {
if strings.HasPrefix(k, SYSTEM_ADMIN_PREFIX) && (userCred == nil || !IsAllowGetSpec(ctx, rbacutils.ScopeSystem, userCred, obj, "metadata")) {
if strings.HasPrefix(k, SYSTEM_ADMIN_PREFIX) && (userCred == nil || !IsAllowGetSpec(ctx, rbacscope.ScopeSystem, userCred, obj, "metadata")) {
continue
}
ret[k] = v
+3 -2
View File
@@ -19,6 +19,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/apis"
@@ -33,14 +34,14 @@ type SMetadataResourceBaseModelManager struct{}
func ObjectIdQueryWithPolicyResult(q *sqlchemy.SQuery, manager IModelManager, result rbacutils.SPolicyResult) *sqlchemy.SQuery {
scope := manager.ResourceScope()
if scope == rbacutils.ScopeDomain || scope == rbacutils.ScopeProject {
if scope == rbacscope.ScopeDomain || scope == rbacscope.ScopeProject {
if !result.DomainTags.IsEmpty() {
tagFilters := tagutils.STagFilters{}
tagFilters.AddFilters(result.DomainTags)
q = ObjectIdQueryWithTagFilters(q, "domain_id", "domain", tagFilters)
}
}
if scope == rbacutils.ScopeProject {
if scope == rbacscope.ScopeProject {
if !result.ProjectTags.IsEmpty() {
tagFilters := tagutils.STagFilters{}
tagFilters.AddFilters(result.ProjectTags)
+9 -9
View File
@@ -23,16 +23,16 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/object"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/version"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/apis"
"yunion.io/x/onecloud/pkg/appsrv"
"yunion.io/x/onecloud/pkg/cloudcommon/object"
"yunion.io/x/onecloud/pkg/cloudcommon/policy"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/splitable"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
@@ -232,15 +232,15 @@ func (manager *SModelBaseManager) FilterByName(q *sqlchemy.SQuery, name string)
return q
}
func (manager *SModelBaseManager) FilterByOwner(q *sqlchemy.SQuery, ownerId mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *SModelBaseManager) FilterByOwner(q *sqlchemy.SQuery, ownerId mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
return q
}
func (manager *SModelBaseManager) FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *SModelBaseManager) FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
return q
}
func (manager *SModelBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *SModelBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
return q
}
@@ -346,12 +346,12 @@ func (manager *SModelBaseManager) FetchUniqValues(ctx context.Context, data json
return nil
}
func (manager *SModelBaseManager) NamespaceScope() rbacutils.TRbacScope {
return rbacutils.ScopeSystem
func (manager *SModelBaseManager) NamespaceScope() rbacscope.TRbacScope {
return rbacscope.ScopeSystem
}
func (manager *SModelBaseManager) ResourceScope() rbacutils.TRbacScope {
return rbacutils.ScopeSystem
func (manager *SModelBaseManager) ResourceScope() rbacscope.TRbacScope {
return rbacscope.ScopeSystem
}
func (manager *SModelBaseManager) AllowGetPropertyDistinctField(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject) bool {
+7 -7
View File
@@ -25,6 +25,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/reflectutils"
"yunion.io/x/pkg/util/stringutils"
"yunion.io/x/pkg/util/timeutils"
@@ -35,7 +36,6 @@ import (
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
@@ -358,17 +358,17 @@ func (manager *SOpsLogManager) LogSyncUpdate(m IModel, uds sqlchemy.UpdateDiffs,
}
}
func (self *SOpsLogManager) FilterByOwner(q *sqlchemy.SQuery, ownerId mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (self *SOpsLogManager) FilterByOwner(q *sqlchemy.SQuery, ownerId mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
if ownerId != nil {
switch scope {
case rbacutils.ScopeUser:
case rbacscope.ScopeUser:
if len(ownerId.GetUserId()) > 0 {
/*
* 默认只能查看本人发起的操作
*/
q = q.Filter(sqlchemy.Equals(q.Field("user_id"), ownerId.GetUserId()))
}
case rbacutils.ScopeProject:
case rbacscope.ScopeProject:
if len(ownerId.GetProjectId()) > 0 {
/*
* 项目视图可以查看本项目人员发起的操作,或者对本项目资源实施的操作, QIU Jian
@@ -378,7 +378,7 @@ func (self *SOpsLogManager) FilterByOwner(q *sqlchemy.SQuery, ownerId mcclient.I
sqlchemy.Equals(q.Field("owner_tenant_id"), ownerId.GetProjectId()),
))
}
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
if len(ownerId.GetProjectDomainId()) > 0 {
/*
* 域视图可以查看本域人员发起的操作,或者对本域资源实施的操作, QIU Jian
@@ -413,8 +413,8 @@ func (self *SOpsLog) IsSharable(reqCred mcclient.IIdentityProvider) bool {
return false
}
func (manager *SOpsLogManager) ResourceScope() rbacutils.TRbacScope {
return rbacutils.ScopeUser
func (manager *SOpsLogManager) ResourceScope() rbacscope.TRbacScope {
return rbacscope.ScopeUser
}
func (manager *SOpsLogManager) FetchOwnerId(ctx context.Context, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error) {
+6 -6
View File
@@ -21,6 +21,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/reflectutils"
"yunion.io/x/sqlchemy"
@@ -29,7 +30,6 @@ import (
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
"yunion.io/x/onecloud/pkg/util/tagutils"
)
@@ -50,12 +50,12 @@ func (model *SProjectizedResourceBase) GetOwnerId() mcclient.IIdentityProvider {
return &owner
}
func (manager *SProjectizedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *SProjectizedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
if owner != nil {
switch scope {
case rbacutils.ScopeProject:
case rbacscope.ScopeProject:
q = q.Equals("tenant_id", owner.GetProjectId())
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
q = q.Equals("domain_id", owner.GetProjectDomainId())
}
/*if len(owner.GetProjectId()) > 0 {
@@ -67,8 +67,8 @@ func (manager *SProjectizedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery
return q
}
func (manager *SProjectizedResourceBaseManager) ResourceScope() rbacutils.TRbacScope {
return rbacutils.ScopeProject
func (manager *SProjectizedResourceBaseManager) ResourceScope() rbacscope.TRbacScope {
return rbacscope.ScopeProject
}
func (manager *SProjectizedResourceBaseManager) FetchOwnerId(ctx context.Context, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error) {
+5 -5
View File
@@ -27,13 +27,13 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/httputils"
"yunion.io/x/pkg/util/rbacscope"
proxyapi "yunion.io/x/onecloud/pkg/apis/cloudcommon/proxy"
"yunion.io/x/onecloud/pkg/cloudcommon/db"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/httputils"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
type SProxySettingManager struct {
@@ -198,10 +198,10 @@ func (man *SProxySettingManager) InitializeData() error {
psObj, err := man.FetchById(proxyapi.ProxySettingId_DIRECT)
if err == nil {
ps := psObj.(*SProxySetting)
if !ps.IsPublic || ps.PublicScope != string(rbacutils.ScopeSystem) {
if !ps.IsPublic || ps.PublicScope != string(rbacscope.ScopeSystem) {
_, err = db.Update(ps, func() error {
ps.IsPublic = true
ps.PublicScope = string(rbacutils.ScopeSystem)
ps.PublicScope = string(rbacscope.ScopeSystem)
return nil
})
if err != nil {
@@ -223,7 +223,7 @@ func (man *SProxySettingManager) InitializeData() error {
ps.Name = proxyapi.ProxySettingId_DIRECT
ps.Description = "Connect directly"
ps.IsPublic = true
ps.PublicScope = string(rbacutils.ScopeSystem)
ps.PublicScope = string(rbacscope.ScopeSystem)
if err := man.TableSpec().Insert(context.Background(), ps); err != nil {
return err
}
+3 -3
View File
@@ -18,10 +18,10 @@ import (
"context"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
func FetchQueryDomain(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject) (string, error) {
@@ -34,8 +34,8 @@ func FetchQueryDomain(ctx context.Context, userCred mcclient.TokenCredential, qu
domainId = domainInfo.GetProjectDomainId()
}
scopeStr, _ := query.GetString("scope")
queryScope := rbacutils.String2ScopeDefault(scopeStr, rbacutils.ScopeDomain)
if queryScope != rbacutils.ScopeSystem && len(domainId) == 0 {
queryScope := rbacscope.String2ScopeDefault(scopeStr, rbacscope.ScopeDomain)
if queryScope != rbacscope.ScopeSystem && len(domainId) == 0 {
domainId = userCred.GetProjectDomainId()
}
return domainId, nil
+1 -1
View File
@@ -19,9 +19,9 @@ import (
"context"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/appctx"
"yunion.io/x/pkg/errors"
"yunion.io/x/onecloud/pkg/appctx"
"yunion.io/x/onecloud/pkg/mcclient"
)
+3 -2
View File
@@ -18,12 +18,13 @@ import (
"fmt"
"strings"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
type SOutOfQuotaError struct {
scope rbacutils.TRbacScope
scope rbacscope.TRbacScope
name string
limit int
used int
+35 -35
View File
@@ -25,10 +25,11 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/appctx"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/reflectutils"
"yunion.io/x/onecloud/pkg/appctx"
"yunion.io/x/onecloud/pkg/appsrv"
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
"yunion.io/x/onecloud/pkg/cloudcommon/db"
@@ -36,7 +37,6 @@ import (
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/mcclient/auth"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
const (
@@ -101,7 +101,7 @@ func AddQuotaHandler(manager *SQuotaBaseManager, prefix string, app *appsrv.Appl
fmt.Sprintf("%s/%s/domains/<domainid>/pending", prefix, manager.KeywordPlural()),
auth.Authenticate(manager.cleanPendingUsageHandler), nil, "clean_pending_usage_for_domain", nil)
if manager.scope == rbacutils.ScopeProject {
if manager.scope == rbacscope.ScopeProject {
app.AddHandler2("GET",
fmt.Sprintf("%s/%s/<tenantid>", prefix, manager.KeywordPlural()),
auth.Authenticate(manager.getQuotaHandler), nil, "get_quota_for_project", nil)
@@ -177,7 +177,7 @@ func (manager *SQuotaBaseManager) getQuotaHandler(ctx context.Context, w http.Re
userCred := auth.FetchUserCredential(ctx, policy.FilterPolicyCredential)
var ownerId mcclient.IIdentityProvider
var scope rbacutils.TRbacScope
var scope rbacscope.TRbacScope
var err error
projectId := params["<tenantid>"]
@@ -196,10 +196,10 @@ func (manager *SQuotaBaseManager) getQuotaHandler(ctx context.Context, w http.Re
}
} else {
scopeStr, _ := query.GetString("scope")
if scopeStr == "project" && manager.scope == rbacutils.ScopeProject {
scope = rbacutils.ScopeProject
if scopeStr == "project" && manager.scope == rbacscope.ScopeProject {
scope = rbacscope.ScopeProject
} else if scopeStr == "domain" {
scope = rbacutils.ScopeDomain
scope = rbacscope.ScopeDomain
} else {
scope = manager.scope
}
@@ -209,7 +209,7 @@ func (manager *SQuotaBaseManager) getQuotaHandler(ctx context.Context, w http.Re
keys := OwnerIdProjectQuotaKeys(scope, ownerId)
refresh := jsonutils.QueryBoolean(query, "refresh", false)
primary := jsonutils.QueryBoolean(query, "primary", false)
quotaList, err := manager.listQuotas(ctx, userCred, keys.DomainId, keys.ProjectId, scope == rbacutils.ScopeDomain, primary, refresh)
quotaList, err := manager.listQuotas(ctx, userCred, keys.DomainId, keys.ProjectId, scope == rbacscope.ScopeDomain, primary, refresh)
if err != nil {
httperrors.GeneralServerError(ctx, w, err)
return
@@ -217,7 +217,7 @@ func (manager *SQuotaBaseManager) getQuotaHandler(ctx context.Context, w http.Re
if len(quotaList) == 0 {
quota := manager.newQuota()
var baseKeys IQuotaKeys
if manager.scope == rbacutils.ScopeProject {
if manager.scope == rbacscope.ScopeProject {
baseKeys = OwnerIdProjectQuotaKeys(scope, ownerId)
} else {
baseKeys = OwnerIdDomainQuotaKeys(ownerId)
@@ -226,7 +226,7 @@ func (manager *SQuotaBaseManager) getQuotaHandler(ctx context.Context, w http.Re
quota.FetchSystemQuota()
manager.SetQuota(ctx, userCred, quota)
quotaList, err = manager.listQuotas(ctx, userCred, keys.DomainId, keys.ProjectId, scope == rbacutils.ScopeDomain, primary, refresh)
quotaList, err = manager.listQuotas(ctx, userCred, keys.DomainId, keys.ProjectId, scope == rbacscope.ScopeDomain, primary, refresh)
if err != nil {
httperrors.GeneralServerError(ctx, w, err)
return
@@ -242,45 +242,45 @@ func (manager *SQuotaBaseManager) fetchSetQuotaScope(
isBaseQuotaKeys bool,
) (
mcclient.IIdentityProvider,
rbacutils.TRbacScope,
rbacutils.TRbacScope,
rbacscope.TRbacScope,
rbacscope.TRbacScope,
error,
) {
var scope rbacutils.TRbacScope
var scope rbacscope.TRbacScope
ownerId, err := db.FetchProjectInfo(ctx, data)
if err != nil {
return nil, scope, scope, err
}
var requestScope rbacutils.TRbacScope
var requestScope rbacscope.TRbacScope
if ownerId != nil {
if len(ownerId.GetProjectId()) > 0 {
// project level
scope = rbacutils.ScopeProject
scope = rbacscope.ScopeProject
if ownerId.GetProjectDomainId() == userCred.GetProjectDomainId() {
if isBaseQuotaKeys || ownerId.GetProjectId() != userCred.GetProjectId() {
requestScope = rbacutils.ScopeDomain
requestScope = rbacscope.ScopeDomain
} else {
requestScope = rbacutils.ScopeProject
requestScope = rbacscope.ScopeProject
}
} else {
requestScope = rbacutils.ScopeSystem
requestScope = rbacscope.ScopeSystem
}
} else {
// domain level if len(ownerId.GetProjectDomainId()) > 0 {
scope = rbacutils.ScopeDomain
scope = rbacscope.ScopeDomain
if isBaseQuotaKeys || ownerId.GetProjectDomainId() != userCred.GetProjectDomainId() {
requestScope = rbacutils.ScopeSystem
requestScope = rbacscope.ScopeSystem
} else {
requestScope = rbacutils.ScopeDomain
requestScope = rbacscope.ScopeDomain
}
}
} else {
ownerId = userCred
scope = rbacutils.ScopeProject
scope = rbacscope.ScopeProject
if isBaseQuotaKeys {
requestScope = rbacutils.ScopeDomain
requestScope = rbacscope.ScopeDomain
} else {
requestScope = rbacutils.ScopeProject
requestScope = rbacscope.ScopeProject
}
}
@@ -292,7 +292,7 @@ func (manager *SQuotaBaseManager) cleanPendingUsageHandler(ctx context.Context,
userCred := auth.FetchUserCredential(ctx, policy.FilterPolicyCredential)
var ownerId mcclient.IIdentityProvider
var scope rbacutils.TRbacScope
var scope rbacscope.TRbacScope
var err error
projectId := params["<tenantid>"]
@@ -312,16 +312,16 @@ func (manager *SQuotaBaseManager) cleanPendingUsageHandler(ctx context.Context,
} else {
scopeStr, _ := query.GetString("scope")
if scopeStr == "project" {
scope = rbacutils.ScopeProject
scope = rbacscope.ScopeProject
} else if scopeStr == "domain" {
scope = rbacutils.ScopeDomain
scope = rbacscope.ScopeDomain
} else {
scope = manager.scope
}
ownerId = userCred
}
var keys IQuotaKeys
if manager.scope == rbacutils.ScopeProject {
if manager.scope == rbacscope.ScopeProject {
keys = OwnerIdProjectQuotaKeys(scope, ownerId)
} else {
keys = OwnerIdDomainQuotaKeys(ownerId)
@@ -358,7 +358,7 @@ func (manager *SQuotaBaseManager) setQuotaHandler(ctx context.Context, w http.Re
// check is there any nonempty key other than domain_id and project_id
isBaseQuota := false
if manager.scope == rbacutils.ScopeDomain {
if manager.scope == rbacscope.ScopeDomain {
isBaseQuota = IsBaseDomainQuotaKeys(quota.GetKeys())
} else {
isBaseQuota = IsBaseProjectQuotaKeys(quota.GetKeys())
@@ -371,7 +371,7 @@ func (manager *SQuotaBaseManager) setQuotaHandler(ctx context.Context, w http.Re
// fill project_id and domain_id
var baseKeys IQuotaKeys
if manager.scope == rbacutils.ScopeDomain {
if manager.scope == rbacscope.ScopeDomain {
baseKeys = OwnerIdDomainQuotaKeys(ownerId)
} else {
baseKeys = OwnerIdProjectQuotaKeys(scope, ownerId)
@@ -455,7 +455,7 @@ func (manager *SQuotaBaseManager) setQuotaHandler(ctx context.Context, w http.Re
}
}
quotaList, err := manager.listQuotas(ctx, userCred, baseKeys.OwnerId().GetProjectDomainId(), baseKeys.OwnerId().GetProjectId(), scope == rbacutils.ScopeDomain, false, true)
quotaList, err := manager.listQuotas(ctx, userCred, baseKeys.OwnerId().GetProjectDomainId(), baseKeys.OwnerId().GetProjectId(), scope == rbacscope.ScopeDomain, false, true)
if err != nil {
httperrors.GeneralServerError(ctx, w, err)
return
@@ -468,7 +468,7 @@ func (manager *SQuotaBaseManager) listDomainQuotaHandler(ctx context.Context, w
userCred := auth.FetchUserCredential(ctx, policy.FilterPolicyCredential)
allowScope, policyResult := policy.PolicyManager.AllowScope(userCred, consts.GetServiceType(), manager.KeywordPlural(), policy.PolicyActionList)
if policyResult.Result.IsAllow() && allowScope != rbacutils.ScopeSystem {
if policyResult.Result.IsAllow() && allowScope != rbacscope.ScopeSystem {
httperrors.ForbiddenError(ctx, w, "not allow to list domain quotas")
return
}
@@ -502,7 +502,7 @@ func (manager *SQuotaBaseManager) listProjectQuotaHandler(ctx context.Context, w
}
allowScope, _ := policy.PolicyManager.AllowScope(userCred, consts.GetServiceType(), manager.KeywordPlural(), policy.PolicyActionList)
if (allowScope == rbacutils.ScopeDomain && userCred.GetProjectDomainId() == owner.GetProjectDomainId()) || allowScope == rbacutils.ScopeSystem {
if (allowScope == rbacscope.ScopeDomain && userCred.GetProjectDomainId() == owner.GetProjectDomainId()) || allowScope == rbacscope.ScopeSystem {
} else {
httperrors.ForbiddenError(ctx, w, "not allow to list project quotas")
return
@@ -524,7 +524,7 @@ func (manager *SQuotaBaseManager) listQuotas(ctx context.Context, userCred mccli
if len(targetDomainId) > 0 {
q = q.Equals("domain_id", targetDomainId)
if domainOnly {
if manager.scope == rbacutils.ScopeProject {
if manager.scope == rbacscope.ScopeProject {
q = q.IsEmpty("tenant_id")
}
} else {
@@ -540,7 +540,7 @@ func (manager *SQuotaBaseManager) listQuotas(ctx context.Context, userCred mccli
} else {
// domain only
q = q.IsNotEmpty("domain_id")
if manager.scope == rbacutils.ScopeProject {
if manager.scope == rbacscope.ScopeProject {
q = q.IsNullOrEmpty("tenant_id")
}
}
+3 -3
View File
@@ -18,11 +18,11 @@ import (
"context"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/object"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/onecloud/pkg/cloudcommon/db"
"yunion.io/x/onecloud/pkg/cloudcommon/object"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
type IQuotaKeys interface {
@@ -32,7 +32,7 @@ type IQuotaKeys interface {
OwnerId() mcclient.IIdentityProvider
Scope() rbacutils.TRbacScope
Scope() rbacscope.TRbacScope
}
type IQuota interface {
+8 -8
View File
@@ -22,13 +22,13 @@ import (
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/reflectutils"
"yunion.io/x/sqlchemy"
identityapi "yunion.io/x/onecloud/pkg/apis/identity"
"yunion.io/x/onecloud/pkg/cloudcommon/db"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
type SQuotaBaseManager struct {
@@ -39,10 +39,10 @@ type SQuotaBaseManager struct {
nonNegative bool
scope rbacutils.TRbacScope
scope rbacscope.TRbacScope
}
func NewQuotaBaseManager(model interface{}, scope rbacutils.TRbacScope, tableName string, pendingStore IQuotaStore, usageStore IQuotaStore, keyword, keywordPlural string) SQuotaBaseManager {
func NewQuotaBaseManager(model interface{}, scope rbacscope.TRbacScope, tableName string, pendingStore IQuotaStore, usageStore IQuotaStore, keyword, keywordPlural string) SQuotaBaseManager {
pendingStore.SetVirtualObject(pendingStore)
usageStore.SetVirtualObject(usageStore)
return SQuotaBaseManager{
@@ -54,7 +54,7 @@ func NewQuotaBaseManager(model interface{}, scope rbacutils.TRbacScope, tableNam
}
}
func NewQuotaUsageManager(model interface{}, scope rbacutils.TRbacScope, tableName string, keyword, keywordPlural string) SQuotaBaseManager {
func NewQuotaUsageManager(model interface{}, scope rbacscope.TRbacScope, tableName string, keyword, keywordPlural string) SQuotaBaseManager {
return SQuotaBaseManager{
SResourceBaseManager: db.NewResourceBaseManager(model, tableName, keyword, keywordPlural),
nonNegative: true,
@@ -254,18 +254,18 @@ func (manager *SQuotaBaseManager) InitializeData() error {
for i := range tenants {
obj := tenants[i]
var scope rbacutils.TRbacScope
var scope rbacscope.TRbacScope
var ownerId mcclient.IIdentityProvider
if obj.DomainId == identityapi.KeystoneDomainRoot {
// domain
scope = rbacutils.ScopeDomain
scope = rbacscope.ScopeDomain
ownerId = &db.SOwnerId{
DomainId: tenants[i].Id,
Domain: tenants[i].Name,
}
} else {
// project
scope = rbacutils.ScopeProject
scope = rbacscope.ScopeProject
ownerId = &db.SOwnerId{
DomainId: tenants[i].DomainId,
Domain: tenants[i].Domain,
@@ -276,7 +276,7 @@ func (manager *SQuotaBaseManager) InitializeData() error {
quota := manager.newQuota()
var baseKeys IQuotaKeys
if manager.scope == rbacutils.ScopeDomain {
if manager.scope == rbacscope.ScopeDomain {
baseKeys = OwnerIdDomainQuotaKeys(ownerId)
} else {
baseKeys = OwnerIdProjectQuotaKeys(scope, ownerId)
+12 -11
View File
@@ -18,9 +18,10 @@ import (
"fmt"
"strings"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/onecloud/pkg/cloudcommon/db"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
type SBaseDomainQuotaKeys struct {
@@ -328,23 +329,23 @@ func QuotaKeyWeight(k IQuotaKeys) uint64 {
return w
}
func (k SBaseDomainQuotaKeys) Scope() rbacutils.TRbacScope {
func (k SBaseDomainQuotaKeys) Scope() rbacscope.TRbacScope {
if len(k.DomainId) > 0 {
return rbacutils.ScopeDomain
return rbacscope.ScopeDomain
} else {
return rbacutils.ScopeSystem
return rbacscope.ScopeSystem
}
}
func (k SBaseProjectQuotaKeys) Scope() rbacutils.TRbacScope {
func (k SBaseProjectQuotaKeys) Scope() rbacscope.TRbacScope {
if len(k.DomainId) > 0 && len(k.ProjectId) > 0 {
return rbacutils.ScopeProject
return rbacscope.ScopeProject
} else if len(k.DomainId) > 0 && len(k.ProjectId) == 0 {
return rbacutils.ScopeDomain
return rbacscope.ScopeDomain
} else if len(k.DomainId) == 0 && len(k.ProjectId) == 0 {
return rbacutils.ScopeSystem
return rbacscope.ScopeSystem
} else {
return rbacutils.ScopeNone
return rbacscope.ScopeNone
}
}
@@ -393,8 +394,8 @@ func IsBaseDomainQuotaKeys(k IQuotaKeys) bool {
return true
}
func OwnerIdProjectQuotaKeys(scope rbacutils.TRbacScope, ownerId mcclient.IIdentityProvider) SBaseProjectQuotaKeys {
if scope == rbacutils.ScopeDomain {
func OwnerIdProjectQuotaKeys(scope rbacscope.TRbacScope, ownerId mcclient.IIdentityProvider) SBaseProjectQuotaKeys {
if scope == rbacscope.ScopeDomain {
return SBaseProjectQuotaKeys{
SBaseDomainQuotaKeys: SBaseDomainQuotaKeys{
DomainId: ownerId.GetProjectDomainId(),
+2 -2
View File
@@ -21,14 +21,14 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
"yunion.io/x/onecloud/pkg/cloudcommon/db"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
func (manager *SQuotaBaseManager) ResourceScope() rbacutils.TRbacScope {
func (manager *SQuotaBaseManager) ResourceScope() rbacscope.TRbacScope {
return manager.scope
}
+3 -3
View File
@@ -18,10 +18,10 @@ import (
"context"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/onecloud/pkg/cloudcommon/db"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
const (
@@ -35,12 +35,12 @@ func newDBQuotaStore() *SDBQuotaStore {
return &SDBQuotaStore{}
}
func (store *SDBQuotaStore) GetQuota(ctx context.Context, scope rbacutils.TRbacScope, ownerId mcclient.IIdentityProvider, quota IQuota) error {
func (store *SDBQuotaStore) GetQuota(ctx context.Context, scope rbacscope.TRbacScope, ownerId mcclient.IIdentityProvider, quota IQuota) error {
var tenant *db.STenant
var err error
switch scope {
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
tenant, err = db.TenantCacheManager.FetchDomainById(ctx, ownerId.GetProjectDomainId())
default:
tenant, err = db.TenantCacheManager.FetchTenantById(ctx, ownerId.GetProjectId())
+64 -63
View File
@@ -19,6 +19,7 @@ import (
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
"yunion.io/x/onecloud/pkg/cloudcommon/policy"
@@ -45,35 +46,35 @@ func isObjectRbacAllowedResult(ctx context.Context, model IModel, userCred mccli
ownerId = userCred
}
var requireScope rbacutils.TRbacScope
var requireScope rbacscope.TRbacScope
resScope := manager.ResourceScope()
switch resScope {
case rbacutils.ScopeSystem:
requireScope = rbacutils.ScopeSystem
case rbacutils.ScopeDomain:
case rbacscope.ScopeSystem:
requireScope = rbacscope.ScopeSystem
case rbacscope.ScopeDomain:
if ownerId != nil && objOwnerId != nil && (ownerId.GetUserId() == objOwnerId.GetUserId() && action == policy.PolicyActionGet) {
requireScope = rbacutils.ScopeUser
requireScope = rbacscope.ScopeUser
} else if ownerId != nil && objOwnerId != nil && (ownerId.GetProjectDomainId() == objOwnerId.GetProjectDomainId() || objOwnerId.GetProjectDomainId() == "" || (model.IsSharable(ownerId) && action == policy.PolicyActionGet)) {
requireScope = rbacutils.ScopeDomain
requireScope = rbacscope.ScopeDomain
} else {
requireScope = rbacutils.ScopeSystem
requireScope = rbacscope.ScopeSystem
}
case rbacutils.ScopeUser:
case rbacscope.ScopeUser:
if ownerId != nil && objOwnerId != nil && (ownerId.GetUserId() == objOwnerId.GetUserId() || objOwnerId.GetUserId() == "" || (model.IsSharable(ownerId) && action == policy.PolicyActionGet)) {
requireScope = rbacutils.ScopeUser
requireScope = rbacscope.ScopeUser
} else if ownerId != nil && objOwnerId != nil && ownerId.GetProjectDomainId() == objOwnerId.GetProjectDomainId() {
requireScope = rbacutils.ScopeDomain
requireScope = rbacscope.ScopeDomain
} else {
requireScope = rbacutils.ScopeSystem
requireScope = rbacscope.ScopeSystem
}
default:
// objOwnerId should not be nil
if ownerId != nil && objOwnerId != nil && (ownerId.GetProjectId() == objOwnerId.GetProjectId() || objOwnerId.GetProjectId() == "" || (model.IsSharable(ownerId) && action == policy.PolicyActionGet)) {
requireScope = rbacutils.ScopeProject
requireScope = rbacscope.ScopeProject
} else if ownerId != nil && objOwnerId != nil && ownerId.GetProjectDomainId() == objOwnerId.GetProjectDomainId() {
requireScope = rbacutils.ScopeDomain
requireScope = rbacscope.ScopeDomain
} else {
requireScope = rbacutils.ScopeSystem
requireScope = rbacscope.ScopeSystem
}
}
@@ -104,34 +105,34 @@ func isClassRbacAllowed(ctx context.Context, manager IModelManager, userCred mcc
ownerId = userCred
}
var requireScope rbacutils.TRbacScope
var requireScope rbacscope.TRbacScope
resScope := manager.ResourceScope()
switch resScope {
case rbacutils.ScopeSystem:
requireScope = rbacutils.ScopeSystem
case rbacutils.ScopeDomain:
case rbacscope.ScopeSystem:
requireScope = rbacscope.ScopeSystem
case rbacscope.ScopeDomain:
// objOwnerId should not be nil
if ownerId != nil && ownerId.GetProjectDomainId() == objOwnerId.GetProjectDomainId() {
requireScope = rbacutils.ScopeDomain
requireScope = rbacscope.ScopeDomain
} else {
requireScope = rbacutils.ScopeSystem
requireScope = rbacscope.ScopeSystem
}
case rbacutils.ScopeUser:
case rbacscope.ScopeUser:
if ownerId != nil && ownerId.GetUserId() == objOwnerId.GetUserId() {
requireScope = rbacutils.ScopeUser
requireScope = rbacscope.ScopeUser
} else if ownerId != nil && ownerId.GetProjectDomainId() == objOwnerId.GetProjectDomainId() {
requireScope = rbacutils.ScopeDomain
requireScope = rbacscope.ScopeDomain
} else {
requireScope = rbacutils.ScopeSystem
requireScope = rbacscope.ScopeSystem
}
default:
// objOwnerId should not be nil
if ownerId != nil && ownerId.GetProjectId() == objOwnerId.GetProjectId() {
requireScope = rbacutils.ScopeProject
requireScope = rbacscope.ScopeProject
} else if ownerId != nil && ownerId.GetProjectDomainId() == objOwnerId.GetProjectDomainId() {
requireScope = rbacutils.ScopeDomain
requireScope = rbacscope.ScopeDomain
} else {
requireScope = rbacutils.ScopeSystem
requireScope = rbacscope.ScopeSystem
}
}
@@ -151,7 +152,7 @@ type IResource interface {
KeywordPlural() string
}
func IsAllowList(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
func IsAllowList(scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
if userCred == nil {
return rbacutils.PolicyDeny
}
@@ -159,18 +160,18 @@ func IsAllowList(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential,
}
func IsAdminAllowList(userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
return IsAllowList(rbacutils.ScopeSystem, userCred, manager)
return IsAllowList(rbacscope.ScopeSystem, userCred, manager)
}
func IsDomainAllowList(userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
return IsAllowList(rbacutils.ScopeDomain, userCred, manager)
return IsAllowList(rbacscope.ScopeDomain, userCred, manager)
}
func IsProjectAllowList(userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
return IsAllowList(rbacutils.ScopeProject, userCred, manager)
return IsAllowList(rbacscope.ScopeProject, userCred, manager)
}
func IsAllowCreate(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
func IsAllowCreate(scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
if userCred == nil {
return rbacutils.PolicyDeny
}
@@ -178,18 +179,18 @@ func IsAllowCreate(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential
}
func IsAdminAllowCreate(userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
return IsAllowCreate(rbacutils.ScopeSystem, userCred, manager)
return IsAllowCreate(rbacscope.ScopeSystem, userCred, manager)
}
func IsDomainAllowCreate(userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
return IsAllowCreate(rbacutils.ScopeDomain, userCred, manager)
return IsAllowCreate(rbacscope.ScopeDomain, userCred, manager)
}
func IsProjectAllowCreate(userCred mcclient.TokenCredential, manager IResource) rbacutils.SPolicyResult {
return IsAllowCreate(rbacutils.ScopeProject, userCred, manager)
return IsAllowCreate(rbacscope.ScopeProject, userCred, manager)
}
func IsAllowClassPerform(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, manager IResource, action string) rbacutils.SPolicyResult {
func IsAllowClassPerform(scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, manager IResource, action string) rbacutils.SPolicyResult {
if userCred == nil {
return rbacutils.PolicyDeny
}
@@ -197,18 +198,18 @@ func IsAllowClassPerform(scope rbacutils.TRbacScope, userCred mcclient.TokenCred
}
func IsAdminAllowClassPerform(userCred mcclient.TokenCredential, manager IResource, action string) rbacutils.SPolicyResult {
return IsAllowClassPerform(rbacutils.ScopeSystem, userCred, manager, action)
return IsAllowClassPerform(rbacscope.ScopeSystem, userCred, manager, action)
}
func IsDomainAllowClassPerform(userCred mcclient.TokenCredential, manager IResource, action string) rbacutils.SPolicyResult {
return IsAllowClassPerform(rbacutils.ScopeDomain, userCred, manager, action)
return IsAllowClassPerform(rbacscope.ScopeDomain, userCred, manager, action)
}
func IsProjectAllowClassPerform(userCred mcclient.TokenCredential, manager IResource, action string) rbacutils.SPolicyResult {
return IsAllowClassPerform(rbacutils.ScopeProject, userCred, manager, action)
return IsAllowClassPerform(rbacscope.ScopeProject, userCred, manager, action)
}
func IsAllowGet(ctx context.Context, scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, obj IModel) bool {
func IsAllowGet(ctx context.Context, scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, obj IModel) bool {
if userCred == nil {
return false
}
@@ -223,18 +224,18 @@ func IsAllowGet(ctx context.Context, scope rbacutils.TRbacScope, userCred mcclie
}
func IsAdminAllowGet(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
return IsAllowGet(ctx, rbacutils.ScopeSystem, userCred, obj)
return IsAllowGet(ctx, rbacscope.ScopeSystem, userCred, obj)
}
func IsDomainAllowGet(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
return IsAllowGet(ctx, rbacutils.ScopeDomain, userCred, obj)
return IsAllowGet(ctx, rbacscope.ScopeDomain, userCred, obj)
}
func IsProjectAllowGet(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
return IsAllowGet(ctx, rbacutils.ScopeProject, userCred, obj)
return IsAllowGet(ctx, rbacscope.ScopeProject, userCred, obj)
}
func IsAllowGetSpec(ctx context.Context, scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
func IsAllowGetSpec(ctx context.Context, scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
if userCred == nil {
return false
}
@@ -249,18 +250,18 @@ func IsAllowGetSpec(ctx context.Context, scope rbacutils.TRbacScope, userCred mc
}
func IsAdminAllowGetSpec(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
return IsAllowGetSpec(ctx, rbacutils.ScopeSystem, userCred, obj, spec)
return IsAllowGetSpec(ctx, rbacscope.ScopeSystem, userCred, obj, spec)
}
func IsDomainAllowGetSpec(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
return IsAllowGetSpec(ctx, rbacutils.ScopeDomain, userCred, obj, spec)
return IsAllowGetSpec(ctx, rbacscope.ScopeDomain, userCred, obj, spec)
}
func IsProjectAllowGetSpec(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
return IsAllowGetSpec(ctx, rbacutils.ScopeProject, userCred, obj, spec)
return IsAllowGetSpec(ctx, rbacscope.ScopeProject, userCred, obj, spec)
}
func IsAllowPerform(ctx context.Context, scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, obj IModel, action string) bool {
func IsAllowPerform(ctx context.Context, scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, obj IModel, action string) bool {
if userCred == nil {
return false
}
@@ -275,18 +276,18 @@ func IsAllowPerform(ctx context.Context, scope rbacutils.TRbacScope, userCred mc
}
func IsAdminAllowPerform(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, action string) bool {
return IsAllowPerform(ctx, rbacutils.ScopeSystem, userCred, obj, action)
return IsAllowPerform(ctx, rbacscope.ScopeSystem, userCred, obj, action)
}
func IsDomainAllowPerform(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, action string) bool {
return IsAllowPerform(ctx, rbacutils.ScopeDomain, userCred, obj, action)
return IsAllowPerform(ctx, rbacscope.ScopeDomain, userCred, obj, action)
}
func IsProjectAllowPerform(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, action string) bool {
return IsAllowPerform(ctx, rbacutils.ScopeProject, userCred, obj, action)
return IsAllowPerform(ctx, rbacscope.ScopeProject, userCred, obj, action)
}
func IsAllowUpdate(ctx context.Context, scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, obj IModel) bool {
func IsAllowUpdate(ctx context.Context, scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, obj IModel) bool {
if userCred == nil {
return false
}
@@ -301,18 +302,18 @@ func IsAllowUpdate(ctx context.Context, scope rbacutils.TRbacScope, userCred mcc
}
func IsAdminAllowUpdate(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
return IsAllowUpdate(ctx, rbacutils.ScopeSystem, userCred, obj)
return IsAllowUpdate(ctx, rbacscope.ScopeSystem, userCred, obj)
}
func IsDomainAllowUpdate(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
return IsAllowUpdate(ctx, rbacutils.ScopeDomain, userCred, obj)
return IsAllowUpdate(ctx, rbacscope.ScopeDomain, userCred, obj)
}
func IsProjectAllowUpdate(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
return IsAllowUpdate(ctx, rbacutils.ScopeProject, userCred, obj)
return IsAllowUpdate(ctx, rbacscope.ScopeProject, userCred, obj)
}
func IsAllowUpdateSpec(ctx context.Context, scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
func IsAllowUpdateSpec(ctx context.Context, scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
if userCred == nil {
return false
}
@@ -327,18 +328,18 @@ func IsAllowUpdateSpec(ctx context.Context, scope rbacutils.TRbacScope, userCred
}
func IsAdminAllowUpdateSpec(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
return IsAllowUpdateSpec(ctx, rbacutils.ScopeSystem, userCred, obj, spec)
return IsAllowUpdateSpec(ctx, rbacscope.ScopeSystem, userCred, obj, spec)
}
func IsDomainAllowUpdateSpec(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
return IsAllowUpdateSpec(ctx, rbacutils.ScopeDomain, userCred, obj, spec)
return IsAllowUpdateSpec(ctx, rbacscope.ScopeDomain, userCred, obj, spec)
}
func IsProjectAllowUpdateSpec(ctx context.Context, userCred mcclient.TokenCredential, obj IModel, spec string) bool {
return IsAllowUpdateSpec(ctx, rbacutils.ScopeProject, userCred, obj, spec)
return IsAllowUpdateSpec(ctx, rbacscope.ScopeProject, userCred, obj, spec)
}
func IsAllowDelete(ctx context.Context, scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, obj IModel) bool {
func IsAllowDelete(ctx context.Context, scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, obj IModel) bool {
if userCred == nil {
return false
}
@@ -353,13 +354,13 @@ func IsAllowDelete(ctx context.Context, scope rbacutils.TRbacScope, userCred mcc
}
func IsAdminAllowDelete(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
return IsAllowDelete(ctx, rbacutils.ScopeSystem, userCred, obj)
return IsAllowDelete(ctx, rbacscope.ScopeSystem, userCred, obj)
}
func IsDomainAllowDelete(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
return IsAllowDelete(ctx, rbacutils.ScopeDomain, userCred, obj)
return IsAllowDelete(ctx, rbacscope.ScopeDomain, userCred, obj)
}
func IsProjectAllowDelete(ctx context.Context, userCred mcclient.TokenCredential, obj IModel) bool {
return IsAllowDelete(ctx, rbacutils.ScopeProject, userCred, obj)
return IsAllowDelete(ctx, rbacscope.ScopeProject, userCred, obj)
}
+2 -1
View File
@@ -17,6 +17,7 @@ package db
import (
"testing"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/utils"
"yunion.io/x/sqlchemy"
@@ -28,7 +29,7 @@ type omniToken struct {
mcclient.SSimpleToken
}
func (tk *omniToken) IsAllow(scope rbacutils.TRbacScope, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
func (tk *omniToken) IsAllow(scope rbacscope.TRbacScope, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
return rbacutils.PolicyAllow
}
+1 -1
View File
@@ -24,6 +24,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/httputils"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
@@ -31,7 +32,6 @@ import (
"yunion.io/x/onecloud/pkg/mcclient/auth"
"yunion.io/x/onecloud/pkg/mcclient/informer"
modules "yunion.io/x/onecloud/pkg/mcclient/modules/identity"
"yunion.io/x/onecloud/pkg/util/httputils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
+40 -40
View File
@@ -19,6 +19,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/reflectutils"
"yunion.io/x/pkg/utils"
"yunion.io/x/sqlchemy"
@@ -26,7 +27,6 @@ import (
"yunion.io/x/onecloud/pkg/apis"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
@@ -46,18 +46,18 @@ type sUniqValues struct {
}
func (m *SScopedResourceBaseManager) FetchUniqValues(ctx context.Context, data jsonutils.JSONObject) jsonutils.JSONObject {
parentScope := rbacutils.ScopeSystem
parentScope := rbacscope.ScopeSystem
scope, _ := data.GetString("scope")
if scope != "" {
parentScope = rbacutils.TRbacScope(scope)
parentScope = rbacscope.TRbacScope(scope)
}
uniqValues := sUniqValues{}
switch parentScope {
case rbacutils.ScopeSystem:
case rbacutils.ScopeDomain:
case rbacscope.ScopeSystem:
case rbacscope.ScopeDomain:
domain, _ := data.GetString("project_domain")
uniqValues.Domain = domain
case rbacutils.ScopeProject:
case rbacscope.ScopeProject:
project, _ := data.GetString("project")
uniqValues.Project = project
}
@@ -65,19 +65,19 @@ func (m *SScopedResourceBaseManager) FetchUniqValues(ctx context.Context, data j
return jsonutils.Marshal(uniqValues)
}
func (m *SScopedResourceBaseManager) FilterByScope(q *sqlchemy.SQuery, scope rbacutils.TRbacScope, scopeResId string) *sqlchemy.SQuery {
func (m *SScopedResourceBaseManager) FilterByScope(q *sqlchemy.SQuery, scope rbacscope.TRbacScope, scopeResId string) *sqlchemy.SQuery {
isNotNullOrEmpty := func(field string) sqlchemy.ICondition {
return sqlchemy.AND(sqlchemy.IsNotNull(q.Field(field)), sqlchemy.IsNotEmpty(q.Field(field)))
}
switch scope {
case rbacutils.ScopeSystem:
case rbacscope.ScopeSystem:
q = q.IsNullOrEmpty("domain_id").IsNullOrEmpty("tenant_id")
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
q = q.IsNullOrEmpty("tenant_id").Filter(isNotNullOrEmpty("domain_id"))
if scopeResId != "" {
q = q.Equals("domain_id", scopeResId)
}
case rbacutils.ScopeProject:
case rbacscope.ScopeProject:
q = q.Filter(isNotNullOrEmpty("domain_id")).Filter(isNotNullOrEmpty("tenant_id"))
if scopeResId != "" {
q = q.Equals("tenant_id", scopeResId)
@@ -90,34 +90,34 @@ func (m *SScopedResourceBaseManager) FilterByUniqValues(q *sqlchemy.SQuery, valu
uniqValues := &sUniqValues{}
values.Unmarshal(uniqValues)
if len(uniqValues.Domain) > 0 {
return m.FilterByScope(q, rbacutils.TRbacScope(uniqValues.Scope), uniqValues.Domain)
return m.FilterByScope(q, rbacscope.TRbacScope(uniqValues.Scope), uniqValues.Domain)
} else if len(uniqValues.Project) > 0 {
return m.FilterByScope(q, rbacutils.TRbacScope(uniqValues.Scope), uniqValues.Project)
return m.FilterByScope(q, rbacscope.TRbacScope(uniqValues.Scope), uniqValues.Project)
} else {
return m.FilterByScope(q, rbacutils.TRbacScope(uniqValues.Scope), "")
return m.FilterByScope(q, rbacscope.TRbacScope(uniqValues.Scope), "")
}
}
func (m *SScopedResourceBase) IsOwner(userCred mcclient.TokenCredential) bool {
scope := m.GetResourceScope()
switch scope {
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
return userCred.GetProjectDomainId() == m.GetDomainId()
case rbacutils.ScopeProject:
case rbacscope.ScopeProject:
return userCred.GetProjectId() == m.GetProjectId()
}
// system scope
return userCred.HasSystemAdminPrivilege()
}
func (m *SScopedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, userCred mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (m *SScopedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, userCred mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
if userCred == nil {
return q
}
switch scope {
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
q = q.Equals("domain_id", userCred.GetProjectDomainId())
case rbacutils.ScopeProject:
case rbacscope.ScopeProject:
q = q.Equals("tenant_id", userCred.GetProjectId())
}
return q
@@ -125,22 +125,22 @@ func (m *SScopedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, userCred
func (m *SScopedResourceBaseManager) ValidateCreateData(man IScopedResourceManager, ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, input apis.ScopedResourceCreateInput) (apis.ScopedResourceCreateInput, error) {
if input.Scope == "" {
input.Scope = string(rbacutils.ScopeSystem)
input.Scope = string(rbacscope.ScopeSystem)
}
if !utils.IsInStringArray(input.Scope, []string{
string(rbacutils.ScopeSystem),
string(rbacutils.ScopeDomain),
string(rbacutils.ScopeProject)}) {
string(rbacscope.ScopeSystem),
string(rbacscope.ScopeDomain),
string(rbacscope.ScopeProject)}) {
return input, httperrors.NewInputParameterError("invalid scope %s", input.Scope)
}
var allowCreate bool
switch rbacutils.TRbacScope(input.Scope) {
case rbacutils.ScopeSystem:
switch rbacscope.TRbacScope(input.Scope) {
case rbacscope.ScopeSystem:
allowCreate = IsAdminAllowCreate(userCred, man).Result.IsAllow()
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
allowCreate = IsDomainAllowCreate(userCred, man).Result.IsAllow()
input.ProjectDomainId = ownerId.GetDomainId()
case rbacutils.ScopeProject:
case rbacscope.ScopeProject:
allowCreate = IsProjectAllowCreate(userCred, man).Result.IsAllow()
input.ProjectDomainId = ownerId.GetDomainId()
input.ProjectId = ownerId.GetProjectId()
@@ -151,20 +151,20 @@ func (m *SScopedResourceBaseManager) ValidateCreateData(man IScopedResourceManag
return input, nil
}
func getScopedResourceScope(domainId, projectId string) rbacutils.TRbacScope {
func getScopedResourceScope(domainId, projectId string) rbacscope.TRbacScope {
if domainId == "" && projectId == "" {
return rbacutils.ScopeSystem
return rbacscope.ScopeSystem
}
if domainId != "" && projectId == "" {
return rbacutils.ScopeDomain
return rbacscope.ScopeDomain
}
if domainId != "" && projectId != "" {
return rbacutils.ScopeProject
return rbacscope.ScopeProject
}
return rbacutils.ScopeNone
return rbacscope.ScopeNone
}
func (s *SScopedResourceBase) GetResourceScope() rbacutils.TRbacScope {
func (s *SScopedResourceBase) GetResourceScope() rbacscope.TRbacScope {
return getScopedResourceScope(s.DomainId, s.ProjectId)
}
@@ -184,14 +184,14 @@ func (s *SScopedResourceBase) SetResourceScope(domainId, projectId string) error
func (s *SScopedResourceBase) CustomizeCreate(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, data jsonutils.JSONObject) error {
scope, _ := data.GetString("scope")
switch rbacutils.TRbacScope(scope) {
case rbacutils.ScopeSystem:
switch rbacscope.TRbacScope(scope) {
case rbacscope.ScopeSystem:
s.DomainId = ""
s.ProjectId = ""
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
s.DomainId = ownerId.GetDomainId()
s.ProjectId = ""
case rbacutils.ScopeProject:
case rbacscope.ScopeProject:
s.DomainId = ownerId.GetDomainId()
s.ProjectId = ownerId.GetProjectId()
}
@@ -239,11 +239,11 @@ func PerformSetScope(
scopeToSet := getScopedResourceScope(domainId, projectId)
var err error
switch scopeToSet {
case rbacutils.ScopeSystem:
case rbacscope.ScopeSystem:
err = setScopedResourceToSystem(ctx, obj, userCred)
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
err = setScopedResourceToDomain(ctx, obj, userCred, domainId)
case rbacutils.ScopeProject:
case rbacscope.ScopeProject:
err = setScopedResourceToProject(ctx, obj, userCred, projectId)
}
return nil, err
@@ -309,7 +309,7 @@ func (m *SScopedResourceBaseManager) ListItemFilter(
return nil, errors.Wrap(err, "SProjectizedResourceBaseManager.ListItemFilter")
}
if query.BelongScope != "" {
q = m.FilterByScope(q, rbacutils.TRbacScope(query.BelongScope), "")
q = m.FilterByScope(q, rbacscope.TRbacScope(query.BelongScope), "")
}
return q, nil
}
+58 -58
View File
@@ -20,6 +20,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/apis"
@@ -28,7 +29,6 @@ import (
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/logclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
@@ -65,7 +65,7 @@ func (manager *SSharableBaseResourceManager) FetchCustomizeColumns(
var resType string
resIds := make([]string, len(rows))
var resScope rbacutils.TRbacScope
var resScope rbacscope.TRbacScope
for i := range rows {
if model, ok := objs[i].(ISharableBaseModel); ok {
if len(resType) == 0 {
@@ -157,48 +157,48 @@ func SharableManagerValidateCreateData(
reqScope := resScope
isPublic := true
switch resScope {
case rbacutils.ScopeProject:
if input.PublicScope == string(rbacutils.ScopeSystem) {
case rbacscope.ScopeProject:
if input.PublicScope == string(rbacscope.ScopeSystem) {
input.IsPublic = &isPublic
reqScope = rbacutils.ScopeSystem
} else if input.PublicScope == string(rbacutils.ScopeDomain) {
reqScope = rbacscope.ScopeSystem
} else if input.PublicScope == string(rbacscope.ScopeDomain) {
if consts.GetNonDefaultDomainProjects() {
// only if non_default_domain_projects turned on, allow sharing to domain
input.IsPublic = &isPublic
reqScope = rbacutils.ScopeDomain
reqScope = rbacscope.ScopeDomain
} else {
input.IsPublic = &isPublic
reqScope = rbacutils.ScopeSystem
reqScope = rbacscope.ScopeSystem
}
} else if input.IsPublic != nil && *input.IsPublic && len(input.PublicScope) == 0 {
// backward compatible, if only is_public is true, make it share to system
input.IsPublic = &isPublic
input.PublicScope = string(rbacutils.ScopeSystem)
reqScope = rbacutils.ScopeSystem
input.PublicScope = string(rbacscope.ScopeSystem)
reqScope = rbacscope.ScopeSystem
} else {
input.IsPublic = nil
input.PublicScope = "" // string(rbacutils.ScopeNone)
input.PublicScope = "" // string(rbacscope.ScopeNone)
}
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
if consts.GetNonDefaultDomainProjects() {
// only if non_default_domain_projects turned on, allow sharing domain resources
if input.PublicScope == string(rbacutils.ScopeSystem) {
if input.PublicScope == string(rbacscope.ScopeSystem) {
input.IsPublic = &isPublic
reqScope = rbacutils.ScopeSystem
reqScope = rbacscope.ScopeSystem
} else if input.IsPublic != nil && *input.IsPublic && len(input.PublicScope) == 0 {
// backward compatible, if only is_public is true, make it share to system
input.IsPublic = &isPublic
input.PublicScope = string(rbacutils.ScopeSystem)
reqScope = rbacutils.ScopeSystem
input.PublicScope = string(rbacscope.ScopeSystem)
reqScope = rbacscope.ScopeSystem
} else {
input.IsPublic = nil
input.PublicScope = "" // string(rbacutils.ScopeNone)
input.PublicScope = "" // string(rbacscope.ScopeNone)
}
} else {
// if non_default_domain_projects turned off, all domain resources shared to system
input.IsPublic = &isPublic
input.PublicScope = string(rbacutils.ScopeSystem)
reqScope = rbacutils.ScopeSystem
input.PublicScope = string(rbacscope.ScopeSystem)
reqScope = rbacscope.ScopeSystem
}
default:
return input, errors.Wrap(httperrors.ErrInputParameter, "the resource is not sharable")
@@ -213,10 +213,10 @@ func SharableManagerValidateCreateData(
return input, nil
}
func SharableManagerFilterByOwner(manager IStandaloneModelManager, q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func SharableManagerFilterByOwner(manager IStandaloneModelManager, q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
if owner != nil {
resScope := manager.ResourceScope()
if resScope == rbacutils.ScopeProject && scope == rbacutils.ScopeProject {
if resScope == rbacscope.ScopeProject && scope == rbacscope.ScopeProject {
ownerProjectId := owner.GetProjectId()
if len(ownerProjectId) > 0 {
subq := SharedResourceManager.Query("resource_id")
@@ -231,11 +231,11 @@ func SharableManagerFilterByOwner(manager IStandaloneModelManager, q *sqlchemy.S
sqlchemy.Equals(q.Field("tenant_id"), ownerProjectId),
sqlchemy.AND(
sqlchemy.IsTrue(q.Field("is_public")),
sqlchemy.Equals(q.Field("public_scope"), rbacutils.ScopeSystem),
sqlchemy.Equals(q.Field("public_scope"), rbacscope.ScopeSystem),
),
sqlchemy.AND(
sqlchemy.IsTrue(q.Field("is_public")),
sqlchemy.Equals(q.Field("public_scope"), rbacutils.ScopeDomain),
sqlchemy.Equals(q.Field("public_scope"), rbacscope.ScopeDomain),
sqlchemy.OR(
sqlchemy.Equals(q.Field("domain_id"), owner.GetProjectDomainId()),
sqlchemy.In(q.Field("id"), subq2.SubQuery()),
@@ -244,7 +244,7 @@ func SharableManagerFilterByOwner(manager IStandaloneModelManager, q *sqlchemy.S
sqlchemy.In(q.Field("id"), subq.SubQuery()),
))
}
} else if (resScope == rbacutils.ScopeDomain && (scope == rbacutils.ScopeProject || scope == rbacutils.ScopeDomain)) || (resScope == rbacutils.ScopeProject && scope == rbacutils.ScopeDomain) {
} else if (resScope == rbacscope.ScopeDomain && (scope == rbacscope.ScopeProject || scope == rbacscope.ScopeDomain)) || (resScope == rbacscope.ScopeProject && scope == rbacscope.ScopeDomain) {
ownerDomainId := owner.GetProjectDomainId()
if len(ownerDomainId) > 0 {
subq := SharedResourceManager.Query("resource_id")
@@ -255,7 +255,7 @@ func SharableManagerFilterByOwner(manager IStandaloneModelManager, q *sqlchemy.S
sqlchemy.Equals(q.Field("domain_id"), ownerDomainId),
sqlchemy.AND(
sqlchemy.IsTrue(q.Field("is_public")),
sqlchemy.Equals(q.Field("public_scope"), rbacutils.ScopeSystem),
sqlchemy.Equals(q.Field("public_scope"), rbacscope.ScopeSystem),
),
sqlchemy.AND(
sqlchemy.IsTrue(q.Field("is_public")),
@@ -284,9 +284,9 @@ type ISharableBaseModel interface {
}
type ISharableBase interface {
SetShare(scoe rbacutils.TRbacScope)
SetShare(scoe rbacscope.TRbacScope)
GetIsPublic() bool
GetPublicScope() rbacutils.TRbacScope
GetPublicScope() rbacscope.TRbacScope
GetSharableTargetDomainIds() []string
GetRequiredSharedDomainIds() []string
GetSharedDomains() []string
@@ -296,9 +296,9 @@ func ISharableChangeOwnerCandidateDomainIds(model ISharableBaseModel) []string {
var candidates []string
if model.GetIsPublic() {
switch model.GetPublicScope() {
case rbacutils.ScopeSystem:
case rbacscope.ScopeSystem:
return candidates
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
candidates = model.GetSharedDomains()
}
}
@@ -346,11 +346,11 @@ func ISharableMergeShareRequireDomainIds(requiredIds ...[]string) []string {
}
func SharableModelIsSharable(model ISharableBaseModel, reqUsrId mcclient.IIdentityProvider) bool {
if model.GetIsPublic() && model.GetPublicScope() == rbacutils.ScopeSystem {
if model.GetIsPublic() && model.GetPublicScope() == rbacscope.ScopeSystem {
return true
}
ownerId := model.GetOwnerId()
if model.GetIsPublic() && model.GetPublicScope() == rbacutils.ScopeDomain {
if model.GetIsPublic() && model.GetPublicScope() == rbacscope.ScopeDomain {
if ownerId != nil && ownerId.GetProjectDomainId() == reqUsrId.GetProjectDomainId() {
return true
}
@@ -363,7 +363,7 @@ func SharableModelIsSharable(model ISharableBaseModel, reqUsrId mcclient.IIdenti
return true
}
}
if model.GetPublicScope() == rbacutils.ScopeProject {
if model.GetPublicScope() == rbacscope.ScopeProject {
if ownerId != nil && ownerId.GetProjectId() == reqUsrId.GetProjectId() {
return true
}
@@ -379,9 +379,9 @@ func SharableModelIsSharable(model ISharableBaseModel, reqUsrId mcclient.IIdenti
return false
}
func (m *SSharableBaseResource) SetShare(scope rbacutils.TRbacScope) {
func (m *SSharableBaseResource) SetShare(scope rbacscope.TRbacScope) {
pub := false
if scope != rbacutils.ScopeNone {
if scope != rbacscope.ScopeNone {
pub = true
}
m.IsPublic = pub
@@ -393,25 +393,25 @@ func (m SSharableBaseResource) GetIsPublic() bool {
return m.IsPublic
}
func (m SSharableBaseResource) GetPublicScope() rbacutils.TRbacScope {
return rbacutils.String2Scope(m.PublicScope)
func (m SSharableBaseResource) GetPublicScope() rbacscope.TRbacScope {
return rbacscope.String2Scope(m.PublicScope)
}
func SharablePerformPublic(model ISharableBaseModel, ctx context.Context, userCred mcclient.TokenCredential, input apis.PerformPublicProjectInput) error {
var err error
resourceScope := model.GetModelManager().ResourceScope()
targetScope := rbacutils.String2ScopeDefault(input.Scope, rbacutils.ScopeSystem)
targetScope := rbacscope.String2ScopeDefault(input.Scope, rbacscope.ScopeSystem)
if resourceScope.HigherThan(targetScope) {
return errors.Wrapf(httperrors.ErrNotSupported, "cannot share %s resource to %s", resourceScope, targetScope)
}
if len(input.SharedProjectIds) > 0 && len(input.SharedDomainIds) > 0 {
return errors.Wrap(httperrors.ErrInputParameter, "cannot set shared_projects and shared_domains at the same time")
} else if len(input.SharedProjectIds) > 0 && targetScope != rbacutils.ScopeProject {
targetScope = rbacutils.ScopeProject
} else if len(input.SharedDomainIds) > 0 && targetScope != rbacutils.ScopeDomain {
targetScope = rbacutils.ScopeDomain
} else if len(input.SharedProjectIds) > 0 && targetScope != rbacscope.ScopeProject {
targetScope = rbacscope.ScopeProject
} else if len(input.SharedDomainIds) > 0 && targetScope != rbacscope.ScopeDomain {
targetScope = rbacscope.ScopeDomain
}
shareResult := apis.PerformPublicProjectInput{}
@@ -421,7 +421,7 @@ func SharablePerformPublic(model ISharableBaseModel, ctx context.Context, userCr
requireIds := model.GetRequiredSharedDomainIds()
switch targetScope {
case rbacutils.ScopeProject:
case rbacscope.ScopeProject:
if len(requireIds) == 0 {
return errors.Wrap(httperrors.ErrForbidden, "require to be shared to system")
} else if len(requireIds) > 1 {
@@ -435,9 +435,9 @@ func SharablePerformPublic(model ISharableBaseModel, ctx context.Context, userCr
return errors.Wrap(err, "shareToTarget")
}
if len(shareResult.SharedProjectIds) == 0 {
targetScope = rbacutils.ScopeNone
targetScope = rbacscope.ScopeNone
}
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
if !consts.GetNonDefaultDomainProjects() {
return errors.Wrap(httperrors.ErrForbidden, "not allow to share to domain when non_default_domain_projects turned off")
}
@@ -452,10 +452,10 @@ func SharablePerformPublic(model ISharableBaseModel, ctx context.Context, userCr
if err != nil {
return errors.Wrap(err, "shareToTarget add domains")
}
if len(shareResult.SharedDomainIds) == 0 && resourceScope == rbacutils.ScopeDomain {
targetScope = rbacutils.ScopeNone
if len(shareResult.SharedDomainIds) == 0 && resourceScope == rbacscope.ScopeDomain {
targetScope = rbacscope.ScopeNone
}
case rbacutils.ScopeSystem:
case rbacscope.ScopeSystem:
if len(candidateIds) > 0 {
return httperrors.NewForbiddenError("sharing is limited to domains %s", jsonutils.Marshal(candidateIds))
}
@@ -492,7 +492,7 @@ func SharablePerformPublic(model ISharableBaseModel, ctx context.Context, userCr
return errors.Wrap(err, "Update")
}
if targetScope != rbacutils.ScopeNone {
if targetScope != rbacscope.ScopeNone {
OpsLog.LogEvent(model, ACT_PUBLIC, shareResult, userCred)
logclient.AddActionLogWithContext(ctx, model, logclient.ACT_PUBLIC, shareResult, userCred, true)
}
@@ -502,12 +502,12 @@ func SharablePerformPublic(model ISharableBaseModel, ctx context.Context, userCr
}
func SharablePerformPrivate(model ISharableBaseModel, ctx context.Context, userCred mcclient.TokenCredential) error {
if !model.GetIsPublic() && model.GetPublicScope() == rbacutils.ScopeNone {
if !model.GetIsPublic() && model.GetPublicScope() == rbacscope.ScopeNone {
return nil
}
resourceScope := model.GetModelManager().ResourceScope()
if resourceScope == rbacutils.ScopeDomain && !consts.GetNonDefaultDomainProjects() {
if resourceScope == rbacscope.ScopeDomain && !consts.GetNonDefaultDomainProjects() {
return errors.Wrap(httperrors.ErrForbidden, "not allow to private domain resource")
}
@@ -535,7 +535,7 @@ func SharablePerformPrivate(model ISharableBaseModel, ctx context.Context, userC
}
diff, err := Update(model, func() error {
model.SetShare(rbacutils.ScopeNone)
model.SetShare(rbacscope.ScopeNone)
return nil
})
@@ -577,12 +577,12 @@ func SharableModelIsShared(model ISharableBaseModel) bool {
return true
}
switch model.GetPublicScope() {
case rbacutils.ScopeSystem:
case rbacscope.ScopeSystem:
if model.GetIsPublic() {
return true
}
case rbacutils.ScopeDomain:
if model.GetModelManager().ResourceScope() == rbacutils.ScopeProject {
case rbacscope.ScopeDomain:
if model.GetModelManager().ResourceScope() == rbacscope.ScopeProject {
return true
}
}
@@ -592,20 +592,20 @@ func SharableModelIsShared(model ISharableBaseModel) bool {
func SharableModelCustomizeCreate(model ISharableBaseModel, ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, data jsonutils.JSONObject) error {
if !data.Contains("public_scope") {
resScope := model.GetModelManager().ResourceScope()
if resScope == rbacutils.ScopeDomain && consts.GetNonDefaultDomainProjects() {
if resScope == rbacscope.ScopeDomain && consts.GetNonDefaultDomainProjects() {
// only if non_default_domain_projects turned on, do the following
isManaged := false
if managedModel, ok := model.(IManagedResourceBase); ok {
isManaged = managedModel.IsManaged()
}
if !isManaged && IsAdminAllowPerform(ctx, userCred, model, "public") && ownerId.GetProjectDomainId() == userCred.GetProjectDomainId() {
model.SetShare(rbacutils.ScopeSystem)
data.(*jsonutils.JSONDict).Set("public_scope", jsonutils.NewString(string(rbacutils.ScopeSystem)))
model.SetShare(rbacscope.ScopeSystem)
data.(*jsonutils.JSONDict).Set("public_scope", jsonutils.NewString(string(rbacscope.ScopeSystem)))
}
}
}
if !data.Contains("public_scope") {
model.SetShare(rbacutils.ScopeNone)
model.SetShare(rbacscope.ScopeNone)
}
return nil
}
+6 -6
View File
@@ -19,12 +19,12 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/apis"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
@@ -48,7 +48,7 @@ func (manager *SSharableVirtualResourceBaseManager) GetISharableVirtualModelMana
return manager.GetVirtualObject().(ISharableVirtualModelManager)
}
func (manager *SSharableVirtualResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *SSharableVirtualResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
return SharableManagerFilterByOwner(manager.GetISharableVirtualModelManager(), q, owner, scope)
}
@@ -204,20 +204,20 @@ func (model *SSharableVirtualResourceBase) Delete(ctx context.Context, userCred
func (model *SSharableVirtualResourceBase) GetSharedInfo() apis.SShareInfo {
ret := apis.SShareInfo{}
ret.IsPublic = model.IsPublic
ret.PublicScope = rbacutils.String2ScopeDefault(model.PublicScope, rbacutils.ScopeNone)
ret.PublicScope = rbacscope.String2ScopeDefault(model.PublicScope, rbacscope.ScopeNone)
ret.SharedDomains = model.GetSharedDomains()
ret.SharedProjects = model.GetSharedProjects()
// fix
if len(ret.SharedDomains) > 0 {
ret.PublicScope = rbacutils.ScopeDomain
ret.PublicScope = rbacscope.ScopeDomain
ret.SharedProjects = nil
ret.IsPublic = true
} else if len(ret.SharedProjects) > 0 {
ret.PublicScope = rbacutils.ScopeProject
ret.PublicScope = rbacscope.ScopeProject
ret.SharedDomains = nil
ret.IsPublic = true
} else if !ret.IsPublic {
ret.PublicScope = rbacutils.ScopeNone
ret.PublicScope = rbacscope.ScopeNone
}
return ret
}
+9 -9
View File
@@ -19,13 +19,13 @@ import (
"database/sql"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/utils"
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
"yunion.io/x/onecloud/pkg/cloudcommon/policy"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
@@ -69,7 +69,7 @@ func (manager *SSharedResourceManager) CleanModelShares(ctx context.Context, use
var err error
resScope := model.GetModelManager().ResourceScope()
switch resScope {
case rbacutils.ScopeProject:
case rbacscope.ScopeProject:
_, err = manager.shareToTarget(ctx, userCred, model, SharedTargetProject, nil, nil, nil)
if err != nil {
return errors.Wrap(err, "remove shared project")
@@ -78,7 +78,7 @@ func (manager *SSharedResourceManager) CleanModelShares(ctx context.Context, use
if err != nil {
return errors.Wrap(err, "remove shared domain")
}
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
_, err = manager.shareToTarget(ctx, userCred, model, SharedTargetDomain, nil, nil, nil)
if err != nil {
return errors.Wrap(err, "remove shared domain")
@@ -96,24 +96,24 @@ func (manager *SSharedResourceManager) shareToTarget(
candidateIds []string,
requireDomainIds []string,
) ([]string, error) {
var requireScope rbacutils.TRbacScope
var requireScope rbacscope.TRbacScope
resScope := model.GetModelManager().ResourceScope()
switch resScope {
case rbacutils.ScopeProject:
case rbacscope.ScopeProject:
switch targetType {
case SharedTargetProject:
// should have domain-level privileges
// cannot share to a project across domain
requireScope = rbacutils.ScopeDomain
requireScope = rbacscope.ScopeDomain
case SharedTargetDomain:
// should have system-level privileges
requireScope = rbacutils.ScopeSystem
requireScope = rbacscope.ScopeSystem
}
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
switch targetType {
case SharedTargetDomain:
// should have system-level privileges
requireScope = rbacutils.ScopeSystem
requireScope = rbacscope.ScopeSystem
case SharedTargetProject:
if len(targetIds) > 0 {
return nil, errors.Wrap(httperrors.ErrNotSupported, "cannot share a domain resource to specific project")
+3 -3
View File
@@ -21,6 +21,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/stringutils"
"yunion.io/x/sqlchemy"
@@ -30,7 +31,6 @@ import (
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/mcclient/auth"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
"yunion.io/x/onecloud/pkg/util/tagutils"
)
@@ -101,7 +101,7 @@ func (manager *SStandaloneAnonResourceBaseManager) FilterByNotId(q *sqlchemy.SQu
return q.NotEquals("id", idStr)
}
func (manager *SStandaloneAnonResourceBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *SStandaloneAnonResourceBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
q = manager.SResourceBaseManager.FilterByHiddenSystemAttributes(q, userCred, query, scope)
showEmulated := jsonutils.QueryBoolean(query, "show_emulated", false)
if showEmulated {
@@ -489,7 +489,7 @@ func (model *SStandaloneAnonResourceBase) PerformMetadata(ctx context.Context, u
dictStore := make(map[string]interface{})
for k, v := range input {
// 已双下滑线开头的metadata是系统内置,普通用户不可添加,只能查看
if strings.HasPrefix(k, SYS_TAG_PREFIX) && (userCred == nil || !IsAllowPerform(ctx, rbacutils.ScopeSystem, userCred, model, "metadata")) {
if strings.HasPrefix(k, SYS_TAG_PREFIX) && (userCred == nil || !IsAllowPerform(ctx, rbacscope.ScopeSystem, userCred, model, "metadata")) {
return nil, httperrors.NewForbiddenError("not allow to set system key, please remove the underscore at the beginning")
}
dictStore[k] = v
@@ -20,13 +20,13 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/reflectutils"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/apis"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
@@ -60,12 +60,12 @@ func (manager *SStatusDomainLevelUserResourceBaseManager) ValidateCreateData(ctx
return input, nil
}
func (manager *SStatusDomainLevelUserResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *SStatusDomainLevelUserResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
if owner != nil {
switch scope {
case rbacutils.ScopeProject, rbacutils.ScopeUser:
case rbacscope.ScopeProject, rbacscope.ScopeUser:
return q.Equals("owner_id", owner.GetUserId())
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
sq := UserCacheManager.Query("id").Equals("domain_id", owner.GetProjectDomainId())
q = q.Filter(
sqlchemy.OR(
+6 -6
View File
@@ -27,8 +27,11 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/appctx"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/gotypes"
"yunion.io/x/pkg/util/httputils"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/reflectutils"
"yunion.io/x/pkg/util/stringutils"
"yunion.io/x/pkg/util/timeutils"
@@ -37,16 +40,13 @@ import (
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/apis"
"yunion.io/x/onecloud/pkg/appctx"
"yunion.io/x/onecloud/pkg/cloudcommon/db"
"yunion.io/x/onecloud/pkg/cloudcommon/db/lockman"
"yunion.io/x/onecloud/pkg/cloudcommon/db/quotas"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/mcclient/auth"
"yunion.io/x/onecloud/pkg/util/httputils"
"yunion.io/x/onecloud/pkg/util/logclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
const (
@@ -151,14 +151,14 @@ func (self *STask) GetOwnerId() mcclient.IIdentityProvider {
return &owner
}
func (manager *STaskManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *STaskManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
if owner != nil {
switch scope {
case rbacutils.ScopeProject:
case rbacscope.ScopeProject:
if len(owner.GetProjectId()) > 0 {
q = q.Contains("user_cred", owner.GetProjectId())
}
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
if len(owner.GetProjectDomainId()) > 0 {
q = q.Contains("user_cred", owner.GetProjectDomainId())
}
+1 -1
View File
@@ -25,6 +25,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/httputils"
"yunion.io/x/sqlchemy"
identityapi "yunion.io/x/onecloud/pkg/apis/identity"
@@ -34,7 +35,6 @@ import (
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/mcclient/auth"
modules "yunion.io/x/onecloud/pkg/mcclient/modules/identity"
"yunion.io/x/onecloud/pkg/util/httputils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
"yunion.io/x/onecloud/pkg/util/tagutils"
)
+3 -3
View File
@@ -21,13 +21,13 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
identityapi "yunion.io/x/onecloud/pkg/apis/identity"
"yunion.io/x/onecloud/pkg/appsrv"
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
"yunion.io/x/onecloud/pkg/mcclient/auth"
modules "yunion.io/x/onecloud/pkg/mcclient/modules/identity"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
var (
@@ -72,7 +72,7 @@ func syncDomains(ctx context.Context) error {
s := auth.GetAdminSession(ctx, consts.GetRegion())
query := jsonutils.NewDict()
query.Add(jsonutils.NewInt(1024), "limit")
query.Add(jsonutils.NewString(string(rbacutils.ScopeSystem)), "scope")
query.Add(jsonutils.NewString(string(rbacscope.ScopeSystem)), "scope")
query.Add(jsonutils.JSONTrue, "details")
total := -1
offset := 0
@@ -101,7 +101,7 @@ func syncProjects(ctx context.Context) error {
s := auth.GetAdminSession(ctx, consts.GetRegion())
query := jsonutils.NewDict()
query.Add(jsonutils.NewInt(1024), "limit")
query.Add(jsonutils.NewString(string(rbacutils.ScopeSystem)), "scope")
query.Add(jsonutils.NewString(string(rbacscope.ScopeSystem)), "scope")
query.Add(jsonutils.JSONTrue, "details")
total := -1
offset := 0
+1 -1
View File
@@ -24,6 +24,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/httputils"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
@@ -31,7 +32,6 @@ import (
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/mcclient/auth"
modules "yunion.io/x/onecloud/pkg/mcclient/modules/identity"
"yunion.io/x/onecloud/pkg/util/httputils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
+8 -8
View File
@@ -20,13 +20,13 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/reflectutils"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/apis"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
@@ -58,7 +58,7 @@ func (manager *SUserResourceBaseManager) ListItemFilter(
if err != nil {
return nil, err
}
if ((query.Admin != nil && *query.Admin) || query.Scope == string(rbacutils.ScopeSystem)) && IsAdminAllowList(userCred, manager).Result.IsAllow() {
if ((query.Admin != nil && *query.Admin) || query.Scope == string(rbacscope.ScopeSystem)) && IsAdminAllowList(userCred, manager).Result.IsAllow() {
user := query.UserId
if len(user) > 0 {
uc, _ := UserCacheManager.FetchUserByIdOrName(ctx, user)
@@ -125,9 +125,9 @@ func (manager *SUserResourceBaseManager) FetchCustomizeColumns(
return rows
}
func (manager *SUserResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *SUserResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
if owner != nil {
if scope == rbacutils.ScopeUser {
if scope == rbacscope.ScopeUser {
if len(owner.GetUserId()) > 0 {
q = q.Equals("owner_id", owner.GetUserId())
}
@@ -173,10 +173,10 @@ func (manager *SUserResourceBaseManager) FetchOwnerId(ctx context.Context, data
return FetchUserInfo(ctx, data)
}
func (manager *SUserResourceBaseManager) NamespaceScope() rbacutils.TRbacScope {
return rbacutils.ScopeUser
func (manager *SUserResourceBaseManager) NamespaceScope() rbacscope.TRbacScope {
return rbacscope.ScopeUser
}
func (manager *SUserResourceBaseManager) ResourceScope() rbacutils.TRbacScope {
return rbacutils.ScopeUser
func (manager *SUserResourceBaseManager) ResourceScope() rbacscope.TRbacScope {
return rbacscope.ScopeUser
}
+4 -4
View File
@@ -20,12 +20,12 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/reflectutils"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/apis"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
@@ -59,7 +59,7 @@ func (manager *SVirtualJointResourceBaseManager) AllowAttach(ctx context.Context
return false
}
func (manager *SVirtualJointResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *SVirtualJointResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
if owner != nil {
masterQ := manager.GetMasterManager().Query("id")
masterQ = manager.GetMasterManager().FilterByOwner(masterQ, owner, scope)
@@ -72,7 +72,7 @@ func (manager *SVirtualJointResourceBaseManager) FilterByOwner(q *sqlchemy.SQuer
return q
}
func (manager *SVirtualJointResourceBaseManager) FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *SVirtualJointResourceBaseManager) FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
q = manager.SJointResourceBaseManager.FilterBySystemAttributes(q, userCred, query, scope)
masterQ := manager.GetMasterManager().Query("id")
masterQ = manager.GetMasterManager().FilterBySystemAttributes(masterQ, userCred, query, scope)
@@ -84,7 +84,7 @@ func (manager *SVirtualJointResourceBaseManager) FilterBySystemAttributes(q *sql
return q
}
func (manager *SVirtualJointResourceBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *SVirtualJointResourceBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
q = manager.SJointResourceBaseManager.FilterByHiddenSystemAttributes(q, userCred, query, scope)
masterQ := manager.GetMasterManager().Query("id")
masterQ = manager.GetMasterManager().FilterByHiddenSystemAttributes(masterQ, userCred, query, scope)
+7 -7
View File
@@ -22,6 +22,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/pkg/util/timeutils"
"yunion.io/x/pkg/utils"
"yunion.io/x/sqlchemy"
@@ -33,7 +34,6 @@ import (
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/logclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
"yunion.io/x/onecloud/pkg/util/stringutils2"
)
@@ -76,7 +76,7 @@ func (manager *SVirtualResourceBaseManager) GetIVirtualModelManager() IVirtualMo
return manager.GetVirtualObject().(IVirtualModelManager)
}
/*func (manager *SVirtualResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
/*func (manager *SVirtualResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
q = manager.SProjectizedResourceBaseManager.FilterByOwner(q, owner, scope)
return q
}
@@ -187,7 +187,7 @@ func (manager *SVirtualResourceBaseManager) GetPropertyDomainStatistics(ctx cont
return result, q.All(&result)
}
func (manager *SVirtualResourceBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *SVirtualResourceBaseManager) FilterByHiddenSystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
q = manager.SStatusStandaloneResourceBaseManager.FilterByHiddenSystemAttributes(q, userCred, query, scope)
isSystem := jsonutils.QueryBoolean(query, "system", false)
@@ -224,7 +224,7 @@ func (model *SVirtualResourceBase) SetProjectInfo(ctx context.Context, userCred
return err
}
func (manager *SVirtualResourceBaseManager) FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
func (manager *SVirtualResourceBaseManager) FilterBySystemAttributes(q *sqlchemy.SQuery, userCred mcclient.TokenCredential, query jsonutils.JSONObject, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
q = manager.SStatusStandaloneResourceBaseManager.FilterBySystemAttributes(q, userCred, query, scope)
var pendingDelete string
@@ -394,16 +394,16 @@ func (model *SVirtualResourceBase) PerformChangeOwner(ctx context.Context, userC
return nil, nil
}
var requireScope rbacutils.TRbacScope
var requireScope rbacscope.TRbacScope
if ownerId.GetProjectDomainId() != model.DomainId {
// change domain, do check
candidates := model.GetIVirtualModel().GetChangeOwnerCandidateDomainIds()
if len(candidates) > 0 && !utils.IsInStringArray(ownerId.GetProjectDomainId(), candidates) {
return nil, errors.Wrap(httperrors.ErrForbidden, "target domain not in change owner candidate list")
}
requireScope = rbacutils.ScopeSystem
requireScope = rbacscope.ScopeSystem
} else {
requireScope = rbacutils.ScopeDomain
requireScope = rbacscope.ScopeDomain
}
allowScope, policyTags := policy.PolicyManager.AllowScope(userCred, consts.GetServiceType(), model.KeywordPlural(), policy.PolicyActionPerform, "change-owner")
+4 -4
View File
@@ -23,6 +23,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/gotypes"
"yunion.io/x/pkg/util/printutils"
"yunion.io/x/pkg/utils"
"yunion.io/x/onecloud/pkg/appsrv"
@@ -32,7 +33,6 @@ import (
"yunion.io/x/onecloud/pkg/cloudcommon/policy"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient/auth"
"yunion.io/x/onecloud/pkg/mcclient/modulebase"
)
func NewEtcdModelHandler(manger base.IEtcdModelManager) *SEtcdModelHandler {
@@ -73,12 +73,12 @@ func (disp *SEtcdModelHandler) FetchUpdateHeaderData(ctx context.Context, header
return disp.manager.FetchUpdateHeaderData(ctx, header)
}
func (disp *SEtcdModelHandler) List(ctx context.Context, query jsonutils.JSONObject, ctxIds []dispatcher.SResourceContext) (*modulebase.ListResult, error) {
func (disp *SEtcdModelHandler) List(ctx context.Context, query jsonutils.JSONObject, ctxIds []dispatcher.SResourceContext) (*printutils.ListResult, error) {
objs, err := disp.manager.AllJson(ctx)
if err != nil {
return nil, httperrors.NewGeneralError(err)
}
return &modulebase.ListResult{
return &printutils.ListResult{
Data: objs,
Total: len(objs),
Limit: 0,
@@ -171,7 +171,7 @@ func (disp *SEtcdModelHandler) Create(ctx context.Context, query jsonutils.JSONO
return nil, httperrors.NewNotImplementedError("not implemented")
}
func (disp *SEtcdModelHandler) BatchCreate(ctx context.Context, query jsonutils.JSONObject, data jsonutils.JSONObject, count int, ctxIds []dispatcher.SResourceContext) ([]modulebase.SubmitResult, error) {
func (disp *SEtcdModelHandler) BatchCreate(ctx context.Context, query jsonutils.JSONObject, data jsonutils.JSONObject, count int, ctxIds []dispatcher.SResourceContext) ([]printutils.SubmitResult, error) {
return nil, httperrors.NewNotImplementedError("not implemented")
}
@@ -24,11 +24,11 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/object"
"yunion.io/x/pkg/util/stringutils"
"yunion.io/x/onecloud/pkg/appsrv"
"yunion.io/x/onecloud/pkg/cloudcommon/etcd"
"yunion.io/x/onecloud/pkg/cloudcommon/object"
)
var (
@@ -18,8 +18,8 @@ import (
"context"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/object"
"yunion.io/x/onecloud/pkg/cloudcommon/object"
"yunion.io/x/onecloud/pkg/mcclient"
)
@@ -25,16 +25,16 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/appctx"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/httputils"
"yunion.io/x/pkg/util/sets"
"yunion.io/x/onecloud/pkg/appctx"
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/mcclient/modulebase"
"yunion.io/x/onecloud/pkg/mcclient/modules/identity"
npk "yunion.io/x/onecloud/pkg/mcclient/modules/notify"
"yunion.io/x/onecloud/pkg/util/httputils"
)
func notifySystemWarning(ctx context.Context, idstr string, name string, event string, reason string) {
-15
View File
@@ -1,15 +0,0 @@
// Copyright 2019 Yunion
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package object // import "yunion.io/x/onecloud/pkg/cloudcommon/object"
-32
View File
@@ -1,32 +0,0 @@
// Copyright 2019 Yunion
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package object
type IObject interface {
SetVirtualObject(virtual interface{})
GetVirtualObject() interface{}
}
type SObject struct {
virtual interface{}
}
func (o *SObject) SetVirtualObject(virtual interface{}) {
o.virtual = virtual
}
func (o *SObject) GetVirtualObject() interface{} {
return o.virtual
}
+1 -1
View File
@@ -33,6 +33,7 @@ import (
"yunion.io/x/log"
"yunion.io/x/log/hooks"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/httputils"
"yunion.io/x/pkg/util/reflectutils"
"yunion.io/x/pkg/util/version"
"yunion.io/x/pkg/utils"
@@ -41,7 +42,6 @@ import (
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/util/atexit"
"yunion.io/x/onecloud/pkg/util/httputils"
)
const (
+5 -3
View File
@@ -15,6 +15,8 @@
package policy
import (
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
@@ -22,7 +24,7 @@ var (
predefinedDefaultPolicies = []rbacutils.SRbacPolicy{
{
Auth: true,
Scope: rbacutils.ScopeSystem,
Scope: rbacscope.ScopeSystem,
Rules: []rbacutils.SRbacRule{
{
Resource: "tasks",
@@ -38,7 +40,7 @@ var (
},
{
Auth: true,
Scope: rbacutils.ScopeProject,
Scope: rbacscope.ScopeProject,
Rules: []rbacutils.SRbacRule{
{
Resource: "tasks",
@@ -56,7 +58,7 @@ var (
{
// for domain
Auth: true,
Scope: rbacutils.ScopeDomain,
Scope: rbacscope.ScopeDomain,
Rules: []rbacutils.SRbacRule{
{
// usages for any services
+55 -54
View File
@@ -27,6 +27,7 @@ import (
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/gotypes"
"yunion.io/x/pkg/util/netutils"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/onecloud/pkg/apis"
"yunion.io/x/onecloud/pkg/appsrv"
@@ -67,7 +68,7 @@ func init() {
}
type SPolicyManager struct {
defaultPolicies map[rbacutils.TRbacScope][]*rbacutils.SRbacPolicy
defaultPolicies map[rbacscope.TRbacScope][]*rbacutils.SRbacPolicy
refreshInterval time.Duration
@@ -85,9 +86,9 @@ type sPolicyData struct {
Enabled bool `json:"enabled"`
DomainId string `json:"domain_id"`
IsPublic bool `json:"is_public"`
PublicScope rbacutils.TRbacScope `json:"public_scope"`
PublicScope rbacscope.TRbacScope `json:"public_scope"`
SharedDomains []apis.SharedDomain `json:"shared_domain"`
Scope rbacutils.TRbacScope `json:"scope"`
Scope rbacscope.TRbacScope `json:"scope"`
Policy jsonutils.JSONObject `json:"policy"`
DomainTags tagutils.TTagSet `json:"domain_tags"`
ProjectTags tagutils.TTagSet `json:"project_tags"`
@@ -102,7 +103,7 @@ func (manager *SPolicyManager) init(refreshInterval time.Duration) {
manager.refreshInterval = refreshInterval
// manager.InitSync(manager)
if len(predefinedDefaultPolicies) > 0 {
policiesMap := make(map[rbacutils.TRbacScope][]*rbacutils.SRbacPolicy)
policiesMap := make(map[rbacscope.TRbacScope][]*rbacutils.SRbacPolicy)
for i := range predefinedDefaultPolicies {
policy := predefinedDefaultPolicies[i]
if _, ok := policiesMap[policy.Scope]; !ok {
@@ -151,7 +152,7 @@ func policyKey(userCred mcclient.TokenCredential) string {
return strings.Join(keys, "-")
}
func permissionKey(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) string {
func permissionKey(scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) string {
queryKeys := []string{string(scope)}
queryKeys = append(queryKeys, userCred.GetProjectId())
roles := userCred.GetRoleIds()
@@ -178,43 +179,43 @@ func permissionKey(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential
return strings.Join(queryKeys, "-")
}
func (manager *SPolicyManager) AllowScope(userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) (rbacutils.TRbacScope, rbacutils.SPolicyResult) {
for _, scope := range []rbacutils.TRbacScope{
rbacutils.ScopeSystem,
rbacutils.ScopeDomain,
rbacutils.ScopeProject,
rbacutils.ScopeUser,
func (manager *SPolicyManager) AllowScope(userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) (rbacscope.TRbacScope, rbacutils.SPolicyResult) {
for _, scope := range []rbacscope.TRbacScope{
rbacscope.ScopeSystem,
rbacscope.ScopeDomain,
rbacscope.ScopeProject,
rbacscope.ScopeUser,
} {
result := manager.allow(scope, userCred, service, resource, action, extra...)
if result.Result == rbacutils.Allow {
return scope, result
}
}
return rbacutils.ScopeNone, rbacutils.PolicyDeny
return rbacscope.ScopeNone, rbacutils.PolicyDeny
}
func (manager *SPolicyManager) Allow(targetScope rbacutils.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
var retryScopes []rbacutils.TRbacScope
func (manager *SPolicyManager) Allow(targetScope rbacscope.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
var retryScopes []rbacscope.TRbacScope
switch targetScope {
case rbacutils.ScopeSystem:
retryScopes = []rbacutils.TRbacScope{
rbacutils.ScopeSystem,
case rbacscope.ScopeSystem:
retryScopes = []rbacscope.TRbacScope{
rbacscope.ScopeSystem,
}
case rbacutils.ScopeDomain:
retryScopes = []rbacutils.TRbacScope{
rbacutils.ScopeSystem,
rbacutils.ScopeDomain,
case rbacscope.ScopeDomain:
retryScopes = []rbacscope.TRbacScope{
rbacscope.ScopeSystem,
rbacscope.ScopeDomain,
}
case rbacutils.ScopeProject:
retryScopes = []rbacutils.TRbacScope{
rbacutils.ScopeSystem,
rbacutils.ScopeDomain,
rbacutils.ScopeProject,
case rbacscope.ScopeProject:
retryScopes = []rbacscope.TRbacScope{
rbacscope.ScopeSystem,
rbacscope.ScopeDomain,
rbacscope.ScopeProject,
}
case rbacutils.ScopeUser:
retryScopes = []rbacutils.TRbacScope{
rbacutils.ScopeSystem,
rbacutils.ScopeUser,
case rbacscope.ScopeUser:
retryScopes = []rbacscope.TRbacScope{
rbacscope.ScopeSystem,
rbacscope.ScopeUser,
}
}
for _, scope := range retryScopes {
@@ -275,7 +276,7 @@ func (manager *SPolicyManager) fetchMatchedPolicies(userCred mcclient.TokenCrede
return res.output, res.err
}
func (manager *SPolicyManager) allow(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
func (manager *SPolicyManager) allow(scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
// first download userCred policy
policies, err := manager.fetchMatchedPolicies(userCred)
if err != nil {
@@ -302,7 +303,7 @@ func (manager *SPolicyManager) allow(scope rbacutils.TRbacScope, userCred mcclie
}
/*
func (manager *SPolicyManager) findPolicyByName(scope rbacutils.TRbacScope, name string) *rbacutils.SRbacPolicyCore {
func (manager *SPolicyManager) findPolicyByName(scope rbacscope.TRbacScope, name string) *rbacscope.SRbacPolicyCore {
if policies, ok := manager.policies[scope]; ok {
for i := range policies {
if policies[i].Id == name || policies[i].Name == name {
@@ -313,13 +314,13 @@ func (manager *SPolicyManager) findPolicyByName(scope rbacutils.TRbacScope, name
return nil
}
func getMatchedPolicyNames(policies []rbacutils.SPolicyInfo, userCred rbacutils.IRbacIdentity) []string {
_, matchNames := rbacutils.GetMatchedPolicies(policies, userCred)
func getMatchedPolicyNames(policies []rbacscope.SPolicyInfo, userCred rbacscope.IRbacIdentity) []string {
_, matchNames := rbacscope.GetMatchedPolicies(policies, userCred)
return matchNames
}
func getMatchedPolicyRules(policies []rbacutils.SPolicyInfo, userCred rbacutils.IRbacIdentity, service string, resource string, action string, extra ...string) ([]rbacutils.SRbacRule, bool) {
matchPolicies, _ := rbacutils.GetMatchedPolicies(policies, userCred)
func getMatchedPolicyRules(policies []rbacscope.SPolicyInfo, userCred rbacscope.IRbacIdentity, service string, resource string, action string, extra ...string) ([]rbacscope.SRbacRule, bool) {
matchPolicies, _ := rbacscope.GetMatchedPolicies(policies, userCred)
if len(matchPolicies) == 0 {
return nil, false
}
@@ -327,7 +328,7 @@ func getMatchedPolicyRules(policies []rbacutils.SPolicyInfo, userCred rbacutils.
}
*/
func (manager *SPolicyManager) allowWithoutCache(policies rbacutils.TPolicySet, scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
func (manager *SPolicyManager) allowWithoutCache(policies rbacutils.TPolicySet, scope rbacscope.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
matchRules := rbacutils.TPolicyMatches{}
if len(policies) == 0 {
@@ -338,19 +339,19 @@ func (manager *SPolicyManager) allowWithoutCache(policies rbacutils.TPolicySet,
scopedDeny := false
switch scope {
case rbacutils.ScopeUser:
case rbacscope.ScopeUser:
if !isUserResource(service, resource) {
scopedDeny = true
}
case rbacutils.ScopeProject:
case rbacscope.ScopeProject:
if !isProjectResource(service, resource) {
scopedDeny = true
}
case rbacutils.ScopeDomain:
case rbacscope.ScopeDomain:
if isSystemResource(service, resource) {
scopedDeny = true
}
case rbacutils.ScopeSystem:
case rbacscope.ScopeSystem:
// no deny at all for system scope
}
if scopedDeny {
@@ -411,10 +412,10 @@ func fetchPolicyDataByIdOrName(ctx context.Context, id string) (*sPolicyData, er
return pdata, nil
}
func explainPolicyInternal(userCred mcclient.TokenCredential, policyReq jsonutils.JSONObject, policyData *sPolicyData) (rbacutils.TRbacScope, []string, rbacutils.SPolicyResult, rbacutils.SPolicyResult, error) {
func explainPolicyInternal(userCred mcclient.TokenCredential, policyReq jsonutils.JSONObject, policyData *sPolicyData) (rbacscope.TRbacScope, []string, rbacutils.SPolicyResult, rbacutils.SPolicyResult, error) {
policySeq, err := policyReq.GetArray()
if err != nil {
return rbacutils.ScopeSystem, nil, rbacutils.PolicyDeny, rbacutils.PolicyDeny, httperrors.NewInputParameterError("invalid format")
return rbacscope.ScopeSystem, nil, rbacutils.PolicyDeny, rbacutils.PolicyDeny, httperrors.NewInputParameterError("invalid format")
}
service := rbacutils.WILD_MATCH
resource := rbacutils.WILD_MATCH
@@ -442,7 +443,7 @@ func explainPolicyInternal(userCred mcclient.TokenCredential, policyReq jsonutil
}
scopeStr, _ := policySeq[0].GetString()
scope := rbacutils.String2Scope(scopeStr)
scope := rbacscope.String2Scope(scopeStr)
userResult := PolicyManager.Allow(scope, userCred, service, resource, action, extra...)
result := userResult
@@ -496,7 +497,7 @@ func ExplainRpc(ctx context.Context, userCred mcclient.TokenCredential, params j
return ret, nil
}
func (manager *SPolicyManager) IsScopeCapable(userCred mcclient.TokenCredential, scope rbacutils.TRbacScope) bool {
func (manager *SPolicyManager) IsScopeCapable(userCred mcclient.TokenCredential, scope rbacscope.TRbacScope) bool {
policies, err := manager.fetchMatchedPolicies(userCred)
if err != nil {
log.Errorf("fetchMatchedPolicyGroup fail %s", err)
@@ -511,7 +512,7 @@ func (manager *SPolicyManager) IsScopeCapable(userCred mcclient.TokenCredential,
}
/*
func (manager *SPolicyManager) MatchedPolicyNames(ctx context.Context, scope rbacutils.TRbacScope, ident rbacutils.IRbacIdentity) []string {
func (manager *SPolicyManager) MatchedPolicyNames(ctx context.Context, scope rbacscope.TRbacScope, ident rbacscope.IRbacIdentity) []string {
policies, err := manager.fetchMatchedPolicies(ctx, userCred)
if err != nil {
log.Errorf("fetchMatchedPolicyGroup fail %s", err)
@@ -540,7 +541,7 @@ func (manager *SPolicyManager) AllPolicies() map[string][]string {
}
func (manager *SPolicyManager) RoleMatchPolicies(roleName string) []string {
ident := rbacutils.NewRbacIdentity("", "", []string{roleName})
ident := rbacscope.NewRbacIdentity("", "", []string{roleName})
ret := make([]string, 0)
for _, policies := range manager.policies {
for i := range policies {
@@ -552,17 +553,17 @@ func (manager *SPolicyManager) RoleMatchPolicies(roleName string) []string {
return ret
}
func (manager *SPolicyManager) GetMatchedPolicySet(userCred rbacutils.IRbacIdentity) (rbacutils.TRbacScope, rbacutils.TPolicySet) {
for _, scope := range []rbacutils.TRbacScope{
rbacutils.ScopeSystem,
rbacutils.ScopeDomain,
rbacutils.ScopeProject,
func (manager *SPolicyManager) GetMatchedPolicySet(userCred rbacscope.IRbacIdentity) (rbacscope.TRbacScope, rbacscope.TPolicySet) {
for _, scope := range []rbacscope.TRbacScope{
rbacscope.ScopeSystem,
rbacscope.ScopeDomain,
rbacscope.ScopeProject,
} {
macthed, _ := rbacutils.GetMatchedPolicies(manager.policies[scope], userCred)
macthed, _ := rbacscope.GetMatchedPolicies(manager.policies[scope], userCred)
if len(macthed) > 0 {
return scope, macthed
}
}
return rbacutils.ScopeNone, nil
return rbacscope.ScopeNone, nil
}
*/
+3 -2
View File
@@ -18,6 +18,7 @@ import (
"context"
"yunion.io/x/pkg/gotypes"
"yunion.io/x/pkg/util/rbacscope"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/mcclient/auth"
@@ -30,10 +31,10 @@ type SPolicyTokenCredential struct {
}
func (self *SPolicyTokenCredential) HasSystemAdminPrivilege() bool {
return PolicyManager.IsScopeCapable(self.TokenCredential, rbacutils.ScopeSystem)
return PolicyManager.IsScopeCapable(self.TokenCredential, rbacscope.ScopeSystem)
}
func (self *SPolicyTokenCredential) IsAllow(targetScope rbacutils.TRbacScope, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
func (self *SPolicyTokenCredential) IsAllow(targetScope rbacscope.TRbacScope, service string, resource string, action string, extra ...string) rbacutils.SPolicyResult {
allowScope, result := PolicyManager.AllowScope(self.TokenCredential, service, resource, action, extra...)
if result.Result == rbacutils.Allow && !targetScope.HigherThan(allowScope) {
return result
+2 -1
View File
@@ -18,9 +18,10 @@ import (
"database/sql"
"fmt"
"yunion.io/x/pkg/util/httputils"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/util/choices"
"yunion.io/x/onecloud/pkg/util/httputils"
)
var returnHttpError = true
+1 -1
View File
@@ -22,8 +22,8 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/appctx"
"yunion.io/x/onecloud/pkg/appctx"
"yunion.io/x/onecloud/pkg/appsrv"
)