From 9d33639255c3d15f24eef42bc257bbc9fc76b342 Mon Sep 17 00:00:00 2001 From: Jian Qiu Date: Wed, 19 Jun 2024 09:32:44 +0800 Subject: [PATCH] fix: add predefined log policy (#20570) Co-authored-by: Qiu Jian --- pkg/keystone/locale/genpolicy.go | 22 +++++++++++++++------- pkg/keystone/locale/predefined_policies.go | 14 ++++++++++++++ pkg/keystone/locale/predefined_yaml.go | 6 ++++++ 3 files changed, 35 insertions(+), 7 deletions(-) diff --git a/pkg/keystone/locale/genpolicy.go b/pkg/keystone/locale/genpolicy.go index fb4d1c4cac..23adfcc9e8 100644 --- a/pkg/keystone/locale/genpolicy.go +++ b/pkg/keystone/locale/genpolicy.go @@ -19,6 +19,7 @@ import ( "yunion.io/x/jsonutils" "yunion.io/x/pkg/util/rbacscope" + "yunion.io/x/pkg/utils" ) var ( @@ -50,6 +51,7 @@ func getEditActionPolicy(service, resource string) jsonutils.JSONObject { perform := jsonutils.NewDict() perform.Add(denyResult, "purge") perform.Add(denyResult, "clone") + perform.Add(denyResult, "disable") if resActions, ok := adminPerformActions[service]; ok { if actions, ok := resActions[resource]; ok { for _, action := range actions { @@ -180,6 +182,8 @@ type SPolicyData struct { Description string DescriptionCN string + + AvailableRoles []string } func generatePolicies(scope rbacscope.TRbacScope, def sPolicyDefinition) []SPolicyData { @@ -205,25 +209,29 @@ func generatePolicies(scope rbacscope.TRbacScope, def sPolicyDefinition) []SPoli var roleConfs []sRoleConf if len(def.Services) > 0 { - roleConfs = []sRoleConf{ - { + if len(def.AvailableRoles) == 0 || utils.IsInStringArray("admin", def.AvailableRoles) { + roleConfs = append(roleConfs, sRoleConf{ name: "admin", policyFunc: getAdminPolicy, fullNameCN: "管理", fullName: "full", - }, - { + }) + } + if len(def.AvailableRoles) == 0 || utils.IsInStringArray("editor", def.AvailableRoles) { + roleConfs = append(roleConfs, sRoleConf{ name: "editor", policyFunc: getEditorPolicy, fullNameCN: "编辑/操作", fullName: "editor/operator", - }, - { + }) + } + if len(def.AvailableRoles) == 0 || utils.IsInStringArray("viewer", def.AvailableRoles) { + roleConfs = append(roleConfs, sRoleConf{ name: "viewer", policyFunc: getViewerPolicy, fullNameCN: "只读", fullName: "read-only", - }, + }) } } else { roleConfs = []sRoleConf{ diff --git a/pkg/keystone/locale/predefined_policies.go b/pkg/keystone/locale/predefined_policies.go index 9ce613285f..d95bb9a2d4 100644 --- a/pkg/keystone/locale/predefined_policies.go +++ b/pkg/keystone/locale/predefined_policies.go @@ -41,6 +41,8 @@ type sPolicyDefinition struct { Scope rbacscope.TRbacScope Services map[string][]string Extra map[string]map[string][]string + + AvailableRoles []string } type SRoleDefiniton struct { @@ -520,6 +522,18 @@ var ( "notify": nil, }, }, + { + Name: "log", + DescCN: "日志服务相关资源", + Desc: "resources of logger service", + Scope: rbacscope.ScopeSystem, + Services: map[string][]string{ + "log": nil, + }, + AvailableRoles: []string{ + "viewer", + }, + }, } adminPerformActions = map[string]map[string][]string{ diff --git a/pkg/keystone/locale/predefined_yaml.go b/pkg/keystone/locale/predefined_yaml.go index cf58ea712e..c7bcc07594 100644 --- a/pkg/keystone/locale/predefined_yaml.go +++ b/pkg/keystone/locale/predefined_yaml.go @@ -82,6 +82,8 @@ policy: log: actions: list: + list: allow + get: allow '*': deny splitable: deny ` @@ -105,6 +107,7 @@ policy: list: allow perform: '*': deny + disable: allow change-owner: allow purge: allow dynamicschedtags: @@ -130,6 +133,7 @@ policy: list: allow perform: '*': deny + disable: allow change-owner: allow add-secgroup: allow set-secgroup: allow @@ -161,6 +165,7 @@ policy: list: allow perform: '*': deny + disable: allow change-owner: allow purge: allow log: @@ -207,6 +212,7 @@ policy: '*': allow delete: deny perform: + disable: deny clone: deny snapshot-and-clone: deny purge: deny