Merge pull request #5361 from swordqiu/hotfix/qj-adjust-user-list-privilege-level

fix: allow project do user-list, group-list, returns current project user and group
This commit is contained in:
Zexi Li
2020-03-06 13:03:18 +08:00
committed by GitHub
5 changed files with 39 additions and 6 deletions
+1 -1
View File
@@ -45,7 +45,7 @@ func (manager *SDomainizedResourceBaseManager) ResourceScope() rbacutils.TRbacSc
func (manager *SDomainizedResourceBaseManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
if owner != nil {
switch scope {
case rbacutils.ScopeDomain:
case rbacutils.ScopeProject, rbacutils.ScopeDomain:
q = q.Equals("domain_id", owner.GetProjectDomainId())
}
}
+5 -5
View File
@@ -366,9 +366,7 @@ func FetchCheckQueryOwnerScope(ctx context.Context, userCred mcclient.TokenCrede
requireScope = rbacutils.ScopeSystem
}
}
}
if ownerId == nil {
} else {
ownerId = userCred
reqScopeStr, _ := data.GetString("scope")
if len(reqScopeStr) > 0 {
@@ -380,10 +378,12 @@ func FetchCheckQueryOwnerScope(ctx context.Context, userCred mcclient.TokenCrede
}
} else if action == policy.PolicyActionGet {
queryScope = allowScope
}
if resScope.HigherThan(queryScope) {
} else {
queryScope = resScope
}
// if resScope.HigherThan(queryScope) {
// queryScope = resScope
// }
requireScope = queryScope
}
if doCheckRbac && requireScope.HigherThan(allowScope) {
+12
View File
@@ -456,6 +456,18 @@ var (
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: identityapi.SERVICE_TYPE,
Resource: "users",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: identityapi.SERVICE_TYPE,
Resource: "groups",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
},
},
{
+10
View File
@@ -362,3 +362,13 @@ func (group *SGroup) PerformLeave(
}
return nil, nil
}
func (manager *SGroupManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
if owner != nil && scope == rbacutils.ScopeProject {
// if user has project level privilege, returns all groups in user's project
subq := AssignmentManager.fetchProjectGroupIdsQuery(owner.GetProjectId())
q = q.In("id", subq.SubQuery())
return q
}
return manager.SIdentityBaseResourceManager.FilterByOwner(q, owner, scope)
}
+11
View File
@@ -937,3 +937,14 @@ func (manager *SUserManager) LockUser(uid string) error {
db.OpsLog.LogEvent(usr, db.ACT_UPDATE, diff, GetDefaultAdminCred())
return nil
}
func (manager *SUserManager) FilterByOwner(q *sqlchemy.SQuery, owner mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
log.Debugf("owner: %s scope %s", jsonutils.Marshal(owner), scope)
if owner != nil && scope == rbacutils.ScopeProject {
// if user has project level privilege, returns all users in user's project
subq := AssignmentManager.fetchProjectUserIdsQuery(owner.GetProjectId())
q = q.In("id", subq.SubQuery())
return q
}
return manager.SEnabledIdentityBaseResourceManager.FilterByOwner(q, owner, scope)
}