Merge pull request #14055 from swordqiu/hotfix/qj-user-reset-credential

feature: user reset credential
This commit is contained in:
Zexi Li
2022-04-18 16:29:42 +08:00
committed by GitHub
5 changed files with 56 additions and 35 deletions
+1 -1
View File
@@ -28,7 +28,7 @@ import (
func init() {
type CredentialListOptions struct {
Scope string `help:"scope" choices:"project|domain|system"`
Type string `help:"credential type" choices:"totp|recovery|aksk"`
Type string `help:"credential type" choices:"totp|recovery|aksk|enc_key"`
User string `help:"filter by user"`
UserDomain string `help:"the domain of user"`
}
+13
View File
@@ -456,4 +456,17 @@ func init() {
printObject(result)
return nil
})
type UserResetCredentialOptions struct {
USER string `json:"-" help:"ID or name of user to operate"`
TYPE string `json:"type" help:"Crednetial type of reset" choices:"totp|recovery|aksk|enc_key"`
}
R(&UserResetCredentialOptions{}, "user-reset-credentials", "Reset user credential", func(s *mcclient.ClientSession, args *UserResetCredentialOptions) error {
result, err := modules.UsersV3.PerformAction(s, args.USER, "reset-credentials", jsonutils.Marshal(args))
if err != nil {
return err
}
printObject(result)
return nil
})
}
+4
View File
@@ -41,3 +41,7 @@ type UserDetails struct {
Projects []SFetchDomainObjectWithMetadata `json:"projects"`
}
type ResetCredentialInput struct {
Type string `json:"type"`
}
+24
View File
@@ -339,3 +339,27 @@ func (manager *SCredentialManager) QueryDistinctExtraField(q *sqlchemy.SQuery, f
return q, httperrors.ErrNotFound
}
func (manager *SCredentialManager) FetchCredentials(uid string, credType string) ([]SCredential, error) {
q := manager.Query().Equals("user_id", uid).Equals("type", credType)
ret := make([]SCredential, 0)
err := db.FetchModelObjects(manager, q, &ret)
if err != nil && errors.Cause(err) != sql.ErrNoRows {
return nil, errors.Wrap(err, "FetchModelObjects")
}
return ret, nil
}
func (manager *SCredentialManager) DeleteAll(ctx context.Context, userCred mcclient.TokenCredential, uid string, credType string) error {
creds, err := manager.FetchCredentials(uid, credType)
if err != nil {
return errors.Wrap(err, "FetchCredentials")
}
for i := range creds {
err := creds[i].Delete(ctx, userCred)
if err != nil {
return errors.Wrap(err, "Delete")
}
}
return nil
}
+14 -34
View File
@@ -980,14 +980,6 @@ func (user *SUser) UnlinkIdp(idpId string) error {
return IdmappingManager.deleteAny(idpId, api.IdMappingEntityUser, user.Id)
}
func (user *SUser) AllowPerformJoin(ctx context.Context,
userCred mcclient.TokenCredential,
query jsonutils.JSONObject,
input api.SJoinProjectsInput,
) bool {
return db.IsAdminAllowPerform(ctx, userCred, user, "join")
}
// 用户加入项目
func (user *SUser) PerformJoin(
ctx context.Context,
@@ -1059,14 +1051,6 @@ func joinProjects(ident db.IModel, isUser bool, ctx context.Context, userCred mc
return nil
}
func (user *SUser) AllowPerformLeave(ctx context.Context,
userCred mcclient.TokenCredential,
query jsonutils.JSONObject,
input api.SLeaveProjectsInput,
) bool {
return db.IsAdminAllowPerform(ctx, userCred, user, "leave")
}
// 用户退出项目
func (user *SUser) PerformLeave(
ctx context.Context,
@@ -1150,15 +1134,6 @@ func (user *SUser) GetUsages() []db.IUsage {
}
}
func (user *SUser) AllowPerformLinkIdp(
ctx context.Context,
userCred mcclient.TokenCredential,
query jsonutils.JSONObject,
input api.UserLinkIdpInput,
) bool {
return db.IsAdminAllowPerform(ctx, userCred, user, "link-idp")
}
// 用户和IDP的指定entityId关联
func (user *SUser) PerformLinkIdp(
ctx context.Context,
@@ -1187,15 +1162,6 @@ func (user *SUser) PerformLinkIdp(
return nil, nil
}
func (user *SUser) AllowPerformUnlinkIdp(
ctx context.Context,
userCred mcclient.TokenCredential,
query jsonutils.JSONObject,
input api.UserUnlinkIdpInput,
) bool {
return db.IsAdminAllowPerform(ctx, userCred, user, "unlink-idp")
}
// 用户和IDP的指定entityId解除关联
func (user *SUser) PerformUnlinkIdp(
ctx context.Context,
@@ -1233,3 +1199,17 @@ func GetUserLangForKeyStone(uids []string) (map[string]string, error) {
}
return ret, nil
}
// 用户加入项目
func (user *SUser) PerformResetCredentials(
ctx context.Context,
userCred mcclient.TokenCredential,
query jsonutils.JSONObject,
input api.ResetCredentialInput,
) (jsonutils.JSONObject, error) {
err := CredentialManager.DeleteAll(ctx, userCred, user.Id, input.Type)
if err != nil {
return nil, errors.Wrap(err, "DeleteAll")
}
return nil, nil
}