mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
Merge pull request #14055 from swordqiu/hotfix/qj-user-reset-credential
feature: user reset credential
This commit is contained in:
@@ -28,7 +28,7 @@ import (
|
||||
func init() {
|
||||
type CredentialListOptions struct {
|
||||
Scope string `help:"scope" choices:"project|domain|system"`
|
||||
Type string `help:"credential type" choices:"totp|recovery|aksk"`
|
||||
Type string `help:"credential type" choices:"totp|recovery|aksk|enc_key"`
|
||||
User string `help:"filter by user"`
|
||||
UserDomain string `help:"the domain of user"`
|
||||
}
|
||||
|
||||
@@ -456,4 +456,17 @@ func init() {
|
||||
printObject(result)
|
||||
return nil
|
||||
})
|
||||
|
||||
type UserResetCredentialOptions struct {
|
||||
USER string `json:"-" help:"ID or name of user to operate"`
|
||||
TYPE string `json:"type" help:"Crednetial type of reset" choices:"totp|recovery|aksk|enc_key"`
|
||||
}
|
||||
R(&UserResetCredentialOptions{}, "user-reset-credentials", "Reset user credential", func(s *mcclient.ClientSession, args *UserResetCredentialOptions) error {
|
||||
result, err := modules.UsersV3.PerformAction(s, args.USER, "reset-credentials", jsonutils.Marshal(args))
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
printObject(result)
|
||||
return nil
|
||||
})
|
||||
}
|
||||
|
||||
@@ -41,3 +41,7 @@ type UserDetails struct {
|
||||
|
||||
Projects []SFetchDomainObjectWithMetadata `json:"projects"`
|
||||
}
|
||||
|
||||
type ResetCredentialInput struct {
|
||||
Type string `json:"type"`
|
||||
}
|
||||
|
||||
@@ -339,3 +339,27 @@ func (manager *SCredentialManager) QueryDistinctExtraField(q *sqlchemy.SQuery, f
|
||||
|
||||
return q, httperrors.ErrNotFound
|
||||
}
|
||||
|
||||
func (manager *SCredentialManager) FetchCredentials(uid string, credType string) ([]SCredential, error) {
|
||||
q := manager.Query().Equals("user_id", uid).Equals("type", credType)
|
||||
ret := make([]SCredential, 0)
|
||||
err := db.FetchModelObjects(manager, q, &ret)
|
||||
if err != nil && errors.Cause(err) != sql.ErrNoRows {
|
||||
return nil, errors.Wrap(err, "FetchModelObjects")
|
||||
}
|
||||
return ret, nil
|
||||
}
|
||||
|
||||
func (manager *SCredentialManager) DeleteAll(ctx context.Context, userCred mcclient.TokenCredential, uid string, credType string) error {
|
||||
creds, err := manager.FetchCredentials(uid, credType)
|
||||
if err != nil {
|
||||
return errors.Wrap(err, "FetchCredentials")
|
||||
}
|
||||
for i := range creds {
|
||||
err := creds[i].Delete(ctx, userCred)
|
||||
if err != nil {
|
||||
return errors.Wrap(err, "Delete")
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -980,14 +980,6 @@ func (user *SUser) UnlinkIdp(idpId string) error {
|
||||
return IdmappingManager.deleteAny(idpId, api.IdMappingEntityUser, user.Id)
|
||||
}
|
||||
|
||||
func (user *SUser) AllowPerformJoin(ctx context.Context,
|
||||
userCred mcclient.TokenCredential,
|
||||
query jsonutils.JSONObject,
|
||||
input api.SJoinProjectsInput,
|
||||
) bool {
|
||||
return db.IsAdminAllowPerform(ctx, userCred, user, "join")
|
||||
}
|
||||
|
||||
// 用户加入项目
|
||||
func (user *SUser) PerformJoin(
|
||||
ctx context.Context,
|
||||
@@ -1059,14 +1051,6 @@ func joinProjects(ident db.IModel, isUser bool, ctx context.Context, userCred mc
|
||||
return nil
|
||||
}
|
||||
|
||||
func (user *SUser) AllowPerformLeave(ctx context.Context,
|
||||
userCred mcclient.TokenCredential,
|
||||
query jsonutils.JSONObject,
|
||||
input api.SLeaveProjectsInput,
|
||||
) bool {
|
||||
return db.IsAdminAllowPerform(ctx, userCred, user, "leave")
|
||||
}
|
||||
|
||||
// 用户退出项目
|
||||
func (user *SUser) PerformLeave(
|
||||
ctx context.Context,
|
||||
@@ -1150,15 +1134,6 @@ func (user *SUser) GetUsages() []db.IUsage {
|
||||
}
|
||||
}
|
||||
|
||||
func (user *SUser) AllowPerformLinkIdp(
|
||||
ctx context.Context,
|
||||
userCred mcclient.TokenCredential,
|
||||
query jsonutils.JSONObject,
|
||||
input api.UserLinkIdpInput,
|
||||
) bool {
|
||||
return db.IsAdminAllowPerform(ctx, userCred, user, "link-idp")
|
||||
}
|
||||
|
||||
// 用户和IDP的指定entityId关联
|
||||
func (user *SUser) PerformLinkIdp(
|
||||
ctx context.Context,
|
||||
@@ -1187,15 +1162,6 @@ func (user *SUser) PerformLinkIdp(
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
func (user *SUser) AllowPerformUnlinkIdp(
|
||||
ctx context.Context,
|
||||
userCred mcclient.TokenCredential,
|
||||
query jsonutils.JSONObject,
|
||||
input api.UserUnlinkIdpInput,
|
||||
) bool {
|
||||
return db.IsAdminAllowPerform(ctx, userCred, user, "unlink-idp")
|
||||
}
|
||||
|
||||
// 用户和IDP的指定entityId解除关联
|
||||
func (user *SUser) PerformUnlinkIdp(
|
||||
ctx context.Context,
|
||||
@@ -1233,3 +1199,17 @@ func GetUserLangForKeyStone(uids []string) (map[string]string, error) {
|
||||
}
|
||||
return ret, nil
|
||||
}
|
||||
|
||||
// 用户加入项目
|
||||
func (user *SUser) PerformResetCredentials(
|
||||
ctx context.Context,
|
||||
userCred mcclient.TokenCredential,
|
||||
query jsonutils.JSONObject,
|
||||
input api.ResetCredentialInput,
|
||||
) (jsonutils.JSONObject, error) {
|
||||
err := CredentialManager.DeleteAll(ctx, userCred, user.Id, input.Type)
|
||||
if err != nil {
|
||||
return nil, errors.Wrap(err, "DeleteAll")
|
||||
}
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user