fix(keystone): allow delete sso imported non-local user

allow delete SSO imported non-local users
This commit is contained in:
Qiu Jian
2021-01-21 23:50:49 +08:00
parent 366aa025d4
commit 6428ca9a15
3 changed files with 3777 additions and 4255 deletions
+3582 -3702
View File
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+9 -1
View File
@@ -757,7 +757,15 @@ func (user *SUser) ValidateDeleteCondition(ctx context.Context) error {
return errors.Wrap(err, "getIdmappings")
}
if !user.IsLocal() && len(idMappings) > 0 {
return httperrors.NewForbiddenError("cannot delete non-local user")
for _, idmaping := range idMappings {
idp, err := IdentityProviderManager.FetchIdentityProviderById(idmaping.IdpId)
if err != nil && errors.Cause(err) == sql.ErrNoRows {
return errors.Wrap(err, "IdentityProviderManager.FetchIdentityProviderById")
}
if idp != nil && idp.IsSso.IsFalse() {
return httperrors.NewForbiddenError("cannot delete non-local non-sso user")
}
}
}
err = user.ValidatePurgeCondition(ctx)
if err != nil {