diff --git a/cmd/climc/shell/groups.go b/cmd/climc/shell/groups.go index 835cf2c3f1..216e8dee07 100644 --- a/cmd/climc/shell/groups.go +++ b/cmd/climc/shell/groups.go @@ -79,7 +79,7 @@ func init() { if err != nil { return err } - users, err := modules.Groups.GetUsers(s, grpId) + users, err := modules.Groups.GetUsers(s, grpId, nil) if err != nil { return err } diff --git a/pkg/cloudcommon/db/tenantcache.go b/pkg/cloudcommon/db/tenantcache.go index e52c916c49..c21b67aadb 100644 --- a/pkg/cloudcommon/db/tenantcache.go +++ b/pkg/cloudcommon/db/tenantcache.go @@ -186,8 +186,13 @@ func (manager *STenantCacheManager) fetchTenantFromKeystone(ctx context.Context, log.Debugf("fetch empty tenant!!!!\n%s", debug.Stack()) return nil, fmt.Errorf("Empty idStr") } + + // It is to query all domain's project. + query := jsonutils.NewDict() + query.Set("scope", jsonutils.NewString("system")) + s := auth.GetAdminSession(ctx, consts.GetRegion(), "v1") - tenant, err := modules.Projects.GetById(s, idStr, nil) + tenant, err := modules.Projects.GetById(s, idStr, query) if err != nil { if je, ok := err.(*httputils.JSONClientError); ok && je.Code == 404 { return nil, sql.ErrNoRows diff --git a/pkg/cloudcommon/db/usercache.go b/pkg/cloudcommon/db/usercache.go index f3f47e0a1c..87b627510e 100644 --- a/pkg/cloudcommon/db/usercache.go +++ b/pkg/cloudcommon/db/usercache.go @@ -20,6 +20,7 @@ import ( "fmt" "runtime/debug" + "yunion.io/x/jsonutils" "yunion.io/x/log" "yunion.io/x/pkg/errors" "yunion.io/x/sqlchemy" @@ -111,11 +112,17 @@ func (manager *SUserCacheManager) FetchUserFromKeystone(ctx context.Context, idS log.Debugf("fetch empty user!!!!\n%s", debug.Stack()) return nil, fmt.Errorf("Empty idStr") } + + // It's to query the full list of users(contains other domain's ones and system ones) + query := jsonutils.NewDict() + query.Set("scope", jsonutils.NewString("system")) + query.Set("system", jsonutils.JSONTrue) + s := auth.GetAdminSession(ctx, consts.GetRegion(), "v1") - user, err := modules.UsersV3.GetById(s, idStr, nil) + user, err := modules.UsersV3.GetById(s, idStr, query) if err != nil { if je, ok := err.(*httputils.JSONClientError); ok && je.Code == 404 { - user, err = modules.UsersV3.GetByName(s, idStr, nil) + user, err = modules.UsersV3.GetByName(s, idStr, query) if je, ok := err.(*httputils.JSONClientError); ok && je.Code == 404 { return nil, sql.ErrNoRows } diff --git a/pkg/mcclient/modules/mod_groups.go b/pkg/mcclient/modules/mod_groups.go index a2eee9ffa6..9e8101c6ae 100644 --- a/pkg/mcclient/modules/mod_groups.go +++ b/pkg/mcclient/modules/mod_groups.go @@ -17,6 +17,8 @@ package modules import ( "fmt" + "yunion.io/x/jsonutils" + "yunion.io/x/onecloud/pkg/mcclient" "yunion.io/x/onecloud/pkg/mcclient/modulebase" ) @@ -25,8 +27,14 @@ type GroupManager struct { modulebase.ResourceManager } -func (this *GroupManager) GetUsers(s *mcclient.ClientSession, gid string) (*modulebase.ListResult, error) { +func (this *GroupManager) GetUsers(s *mcclient.ClientSession, gid string, query jsonutils.JSONObject) (*modulebase.ListResult, error) { url := fmt.Sprintf("/groups/%s/users", gid) + if query != nil { + qs := query.QueryString() + if len(qs) > 0 { + url = fmt.Sprintf("%s?%s", url, qs) + } + } return modulebase.List(this.ResourceManager, s, url, "users") } diff --git a/pkg/notify/cache/user_group_cache.go b/pkg/notify/cache/user_group_cache.go index 50fdc5eb6d..3aef34ac71 100644 --- a/pkg/notify/cache/user_group_cache.go +++ b/pkg/notify/cache/user_group_cache.go @@ -18,6 +18,7 @@ import ( "context" "time" + "yunion.io/x/jsonutils" "yunion.io/x/log" "yunion.io/x/pkg/errors" "yunion.io/x/pkg/util/compare" @@ -103,9 +104,15 @@ func (manager *SUserGroupCacheManager) Sync(ctx context.Context, ugCache []SUser lockman.LockRawObject(ctx, manager.KeywordPlural(), groupId) defer lockman.ReleaseRawObject(ctx, manager.KeywordPlural(), groupId) - s := auth.GetAdminSession(ctx, consts.GetRegion(), "v3") syncResult := compare.SyncResult{} - users, err := modules.Groups.GetUsers(s, groupId) + + // It's to query all groups and their users. + query := jsonutils.NewDict() + query.Set("scope", jsonutils.NewString("system")) + query.Set("system", jsonutils.JSONTrue) + + s := auth.GetAdminSession(ctx, consts.GetRegion(), "v3") + users, err := modules.Groups.GetUsers(s, groupId, query) if err != nil { return nil, syncResult, errors.Wrap(err, "fetch users by group id from keystone failed") }