From 73c30aa8ae403a1e60b278ecd514ff1019f9ab9a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=B1=88=E8=BD=A9?= Date: Mon, 3 Jun 2024 18:07:04 +0800 Subject: [PATCH] fix(keystone): enable user (#20455) --- cmd/climc/shell/identity/projects.go | 10 ++++++---- cmd/climc/shell/identity/users.go | 17 +++++++++++++++++ pkg/apis/identity/input.go | 9 ++++++--- pkg/keystone/models/projects.go | 6 ++++++ pkg/keystone/models/users.go | 3 +++ pkg/mcclient/modules/identity/mod_users.go | 7 +++++++ 6 files changed, 45 insertions(+), 7 deletions(-) diff --git a/cmd/climc/shell/identity/projects.go b/cmd/climc/shell/identity/projects.go index c6ce432ac4..79ccaf7a8d 100644 --- a/cmd/climc/shell/identity/projects.go +++ b/cmd/climc/shell/identity/projects.go @@ -388,16 +388,18 @@ func init() { }) type ProjectAddUserGroupOptions struct { - Project string `help:"ID or name of project to add users/groups" positional:"true" optional:"false"` - User []string `help:"ID of user to add"` - Group []string `help:"ID of group to add"` - Role []string `help:"ID of role to add"` + Project string `help:"ID or name of project to add users/groups" positional:"true" optional:"false"` + User []string `help:"ID of user to add"` + Group []string `help:"ID of group to add"` + Role []string `help:"ID of role to add"` + EnableAllUsers bool } R(&ProjectAddUserGroupOptions{}, "project-add-user-group", "Batch add users/groups to project", func(s *mcclient.ClientSession, args *ProjectAddUserGroupOptions) error { input := api.SProjectAddUserGroupInput{} input.Users = args.User input.Groups = args.Group input.Roles = args.Role + input.EnableAllUsers = args.EnableAllUsers err := input.Validate() if err != nil { return err diff --git a/cmd/climc/shell/identity/users.go b/cmd/climc/shell/identity/users.go index e64196fd5d..9a0cc97193 100644 --- a/cmd/climc/shell/identity/users.go +++ b/cmd/climc/shell/identity/users.go @@ -413,15 +413,32 @@ func init() { return nil }) + type UserGroupsOptions struct { + USER string `help:"User ID or Name"` + Gids []string `help:"group ID or Name"` + Action string `default:"join" choices:"join|leave"` + Enabled bool + } + + R(&UserGroupsOptions{}, "user-join-groups", "Add a user to groups", func(s *mcclient.ClientSession, args *UserGroupsOptions) error { + _, err := modules.UsersV3.DoJoinGroups(s, args.USER, jsonutils.Marshal(args)) + if err != nil { + return err + } + return nil + }) + type UserJoinProjectOptions struct { User string `help:"User Id or name" optional:"false" positional:"true"` Project []string `help:"Projects to join" nargs:"+"` Role []string `help:"User join project with roles" nargs:"+"` + Enabled bool } R(&UserJoinProjectOptions{}, "user-join-project", "User join projects with roles", func(s *mcclient.ClientSession, args *UserJoinProjectOptions) error { input := api.SJoinProjectsInput{} input.Projects = args.Project input.Roles = args.Role + input.Enabled = args.Enabled result, err := modules.UsersV3.PerformAction(s, args.User, "join", jsonutils.Marshal(input)) if err != nil { return err diff --git a/pkg/apis/identity/input.go b/pkg/apis/identity/input.go index 26defaaf9c..c69d7fef27 100644 --- a/pkg/apis/identity/input.go +++ b/pkg/apis/identity/input.go @@ -232,6 +232,8 @@ type EndpointListInput struct { type SJoinProjectsInput struct { Projects []string `json:"projects"` Roles []string `json:"roles"` + // 启用用户, 仅用户禁用时生效 + Enabled bool } func (input SJoinProjectsInput) Validate() error { @@ -269,9 +271,10 @@ func (input SLeaveProjectsInput) Validate() error { } type SProjectAddUserGroupInput struct { - Users []string - Groups []string - Roles []string + Users []string + Groups []string + Roles []string + EnableAllUsers bool } func (input SProjectAddUserGroupInput) Validate() error { diff --git a/pkg/keystone/models/projects.go b/pkg/keystone/models/projects.go index a2ab56a4b2..9e0f0ca72f 100644 --- a/pkg/keystone/models/projects.go +++ b/pkg/keystone/models/projects.go @@ -735,6 +735,12 @@ func (project *SProject) PerformJoin( } } + if input.EnableAllUsers { + for i := range users { + db.EnabledPerformEnable(users[i], ctx, userCred, true) + } + } + return nil, nil } diff --git a/pkg/keystone/models/users.go b/pkg/keystone/models/users.go index d20e57dd41..0df395fa56 100644 --- a/pkg/keystone/models/users.go +++ b/pkg/keystone/models/users.go @@ -1233,6 +1233,9 @@ func (user *SUser) PerformJoin( if err != nil { return nil, errors.Wrap(err, "joinProjects") } + if input.Enabled { + db.EnabledPerformEnable(user, ctx, userCred, true) + } return nil, nil } diff --git a/pkg/mcclient/modules/identity/mod_users.go b/pkg/mcclient/modules/identity/mod_users.go index cf926128a9..1486b044cc 100644 --- a/pkg/mcclient/modules/identity/mod_users.go +++ b/pkg/mcclient/modules/identity/mod_users.go @@ -141,6 +141,13 @@ func (this *UserManagerV3) DoJoinGroups(s *mcclient.ClientSession, uid string, p return nil, httperrors.NewInputParameterError("unsupported action %s", action) } + if enabled, _ := params.Bool("enabled"); enabled && action == "join" { + _, err := this.PerformAction(s, uid, "enable", nil) + if err != nil { + return nil, err + } + } + errs := make([]error, 0) for _, gid := range gids { _gid, _ := gid.GetString()