mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
Merge pull request #5383 from rainzm/automated-cherry-pick-of-#5378-upstream-release-3.1
Automated cherry pick of #5378: fix: Add 'scope=system' and 'system' for Caches when querying from Keystone.
This commit is contained in:
@@ -79,7 +79,7 @@ func init() {
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
users, err := modules.Groups.GetUsers(s, grpId)
|
||||
users, err := modules.Groups.GetUsers(s, grpId, nil)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
@@ -174,8 +174,13 @@ func (manager *STenantCacheManager) fetchTenantFromKeystone(ctx context.Context,
|
||||
log.Debugf("fetch empty tenant!!!!\n%s", debug.Stack())
|
||||
return nil, fmt.Errorf("Empty idStr")
|
||||
}
|
||||
|
||||
// It is to query all domain's project.
|
||||
query := jsonutils.NewDict()
|
||||
query.Set("scope", jsonutils.NewString("system"))
|
||||
|
||||
s := auth.GetAdminSession(ctx, consts.GetRegion(), "v1")
|
||||
tenant, err := modules.Projects.GetById(s, idStr, nil)
|
||||
tenant, err := modules.Projects.GetById(s, idStr, query)
|
||||
if err != nil {
|
||||
if je, ok := err.(*httputils.JSONClientError); ok && je.Code == 404 {
|
||||
return nil, sql.ErrNoRows
|
||||
|
||||
@@ -20,6 +20,7 @@ import (
|
||||
"fmt"
|
||||
"runtime/debug"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/sqlchemy"
|
||||
@@ -111,11 +112,17 @@ func (manager *SUserCacheManager) FetchUserFromKeystone(ctx context.Context, idS
|
||||
log.Debugf("fetch empty user!!!!\n%s", debug.Stack())
|
||||
return nil, fmt.Errorf("Empty idStr")
|
||||
}
|
||||
|
||||
// It's to query the full list of users(contains other domain's ones and system ones)
|
||||
query := jsonutils.NewDict()
|
||||
query.Set("scope", jsonutils.NewString("system"))
|
||||
query.Set("system", jsonutils.JSONTrue)
|
||||
|
||||
s := auth.GetAdminSession(ctx, consts.GetRegion(), "v1")
|
||||
user, err := modules.UsersV3.GetById(s, idStr, nil)
|
||||
user, err := modules.UsersV3.GetById(s, idStr, query)
|
||||
if err != nil {
|
||||
if je, ok := err.(*httputils.JSONClientError); ok && je.Code == 404 {
|
||||
user, err = modules.UsersV3.GetByName(s, idStr, nil)
|
||||
user, err = modules.UsersV3.GetByName(s, idStr, query)
|
||||
if je, ok := err.(*httputils.JSONClientError); ok && je.Code == 404 {
|
||||
return nil, sql.ErrNoRows
|
||||
}
|
||||
|
||||
@@ -17,6 +17,8 @@ package modules
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/modulebase"
|
||||
)
|
||||
@@ -25,8 +27,14 @@ type GroupManager struct {
|
||||
modulebase.ResourceManager
|
||||
}
|
||||
|
||||
func (this *GroupManager) GetUsers(s *mcclient.ClientSession, gid string) (*modulebase.ListResult, error) {
|
||||
func (this *GroupManager) GetUsers(s *mcclient.ClientSession, gid string, query jsonutils.JSONObject) (*modulebase.ListResult, error) {
|
||||
url := fmt.Sprintf("/groups/%s/users", gid)
|
||||
if query != nil {
|
||||
qs := query.QueryString()
|
||||
if len(qs) > 0 {
|
||||
url = fmt.Sprintf("%s?%s", url, qs)
|
||||
}
|
||||
}
|
||||
return modulebase.List(this.ResourceManager, s, url, "users")
|
||||
}
|
||||
|
||||
|
||||
Vendored
+9
-2
@@ -18,6 +18,7 @@ import (
|
||||
"context"
|
||||
"time"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/compare"
|
||||
@@ -103,9 +104,15 @@ func (manager *SUserGroupCacheManager) Sync(ctx context.Context, ugCache []SUser
|
||||
lockman.LockRawObject(ctx, manager.KeywordPlural(), groupId)
|
||||
defer lockman.ReleaseRawObject(ctx, manager.KeywordPlural(), groupId)
|
||||
|
||||
s := auth.GetAdminSession(ctx, consts.GetRegion(), "v3")
|
||||
syncResult := compare.SyncResult{}
|
||||
users, err := modules.Groups.GetUsers(s, groupId)
|
||||
|
||||
// It's to query all groups and their users.
|
||||
query := jsonutils.NewDict()
|
||||
query.Set("scope", jsonutils.NewString("system"))
|
||||
query.Set("system", jsonutils.JSONTrue)
|
||||
|
||||
s := auth.GetAdminSession(ctx, consts.GetRegion(), "v3")
|
||||
users, err := modules.Groups.GetUsers(s, groupId, query)
|
||||
if err != nil {
|
||||
return nil, syncResult, errors.Wrap(err, "fetch users by group id from keystone failed")
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user