mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
fix: add predefined log policy (#20570)
Co-authored-by: Qiu Jian <qiujian@yunionyun.com>
This commit is contained in:
@@ -19,6 +19,7 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/util/rbacscope"
|
||||
"yunion.io/x/pkg/utils"
|
||||
)
|
||||
|
||||
var (
|
||||
@@ -50,6 +51,7 @@ func getEditActionPolicy(service, resource string) jsonutils.JSONObject {
|
||||
perform := jsonutils.NewDict()
|
||||
perform.Add(denyResult, "purge")
|
||||
perform.Add(denyResult, "clone")
|
||||
perform.Add(denyResult, "disable")
|
||||
if resActions, ok := adminPerformActions[service]; ok {
|
||||
if actions, ok := resActions[resource]; ok {
|
||||
for _, action := range actions {
|
||||
@@ -180,6 +182,8 @@ type SPolicyData struct {
|
||||
|
||||
Description string
|
||||
DescriptionCN string
|
||||
|
||||
AvailableRoles []string
|
||||
}
|
||||
|
||||
func generatePolicies(scope rbacscope.TRbacScope, def sPolicyDefinition) []SPolicyData {
|
||||
@@ -205,25 +209,29 @@ func generatePolicies(scope rbacscope.TRbacScope, def sPolicyDefinition) []SPoli
|
||||
|
||||
var roleConfs []sRoleConf
|
||||
if len(def.Services) > 0 {
|
||||
roleConfs = []sRoleConf{
|
||||
{
|
||||
if len(def.AvailableRoles) == 0 || utils.IsInStringArray("admin", def.AvailableRoles) {
|
||||
roleConfs = append(roleConfs, sRoleConf{
|
||||
name: "admin",
|
||||
policyFunc: getAdminPolicy,
|
||||
fullNameCN: "管理",
|
||||
fullName: "full",
|
||||
},
|
||||
{
|
||||
})
|
||||
}
|
||||
if len(def.AvailableRoles) == 0 || utils.IsInStringArray("editor", def.AvailableRoles) {
|
||||
roleConfs = append(roleConfs, sRoleConf{
|
||||
name: "editor",
|
||||
policyFunc: getEditorPolicy,
|
||||
fullNameCN: "编辑/操作",
|
||||
fullName: "editor/operator",
|
||||
},
|
||||
{
|
||||
})
|
||||
}
|
||||
if len(def.AvailableRoles) == 0 || utils.IsInStringArray("viewer", def.AvailableRoles) {
|
||||
roleConfs = append(roleConfs, sRoleConf{
|
||||
name: "viewer",
|
||||
policyFunc: getViewerPolicy,
|
||||
fullNameCN: "只读",
|
||||
fullName: "read-only",
|
||||
},
|
||||
})
|
||||
}
|
||||
} else {
|
||||
roleConfs = []sRoleConf{
|
||||
|
||||
@@ -41,6 +41,8 @@ type sPolicyDefinition struct {
|
||||
Scope rbacscope.TRbacScope
|
||||
Services map[string][]string
|
||||
Extra map[string]map[string][]string
|
||||
|
||||
AvailableRoles []string
|
||||
}
|
||||
|
||||
type SRoleDefiniton struct {
|
||||
@@ -520,6 +522,18 @@ var (
|
||||
"notify": nil,
|
||||
},
|
||||
},
|
||||
{
|
||||
Name: "log",
|
||||
DescCN: "日志服务相关资源",
|
||||
Desc: "resources of logger service",
|
||||
Scope: rbacscope.ScopeSystem,
|
||||
Services: map[string][]string{
|
||||
"log": nil,
|
||||
},
|
||||
AvailableRoles: []string{
|
||||
"viewer",
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
adminPerformActions = map[string]map[string][]string{
|
||||
|
||||
@@ -82,6 +82,8 @@ policy:
|
||||
log:
|
||||
actions:
|
||||
list:
|
||||
list: allow
|
||||
get: allow
|
||||
'*': deny
|
||||
splitable: deny
|
||||
`
|
||||
@@ -105,6 +107,7 @@ policy:
|
||||
list: allow
|
||||
perform:
|
||||
'*': deny
|
||||
disable: allow
|
||||
change-owner: allow
|
||||
purge: allow
|
||||
dynamicschedtags:
|
||||
@@ -130,6 +133,7 @@ policy:
|
||||
list: allow
|
||||
perform:
|
||||
'*': deny
|
||||
disable: allow
|
||||
change-owner: allow
|
||||
add-secgroup: allow
|
||||
set-secgroup: allow
|
||||
@@ -161,6 +165,7 @@ policy:
|
||||
list: allow
|
||||
perform:
|
||||
'*': deny
|
||||
disable: allow
|
||||
change-owner: allow
|
||||
purge: allow
|
||||
log:
|
||||
@@ -207,6 +212,7 @@ policy:
|
||||
'*': allow
|
||||
delete: deny
|
||||
perform:
|
||||
disable: deny
|
||||
clone: deny
|
||||
snapshot-and-clone: deny
|
||||
purge: deny
|
||||
|
||||
Reference in New Issue
Block a user