fix(keystone): support user filter by role project

This commit is contained in:
ioito
2023-03-06 10:29:33 +08:00
parent a5c9f2b278
commit a250925752
3 changed files with 20 additions and 6 deletions
+7 -6
View File
@@ -27,12 +27,13 @@ import (
func init() {
type UserListOptions struct {
options.BaseListOptions
Name string `help:"Filter by name"`
OrderByDomain string `help:"order by domain name" choices:"asc|desc"`
Role string `help:"Filter by role"`
RoleAssignmentDomainId string `help:"filter role assignment domain"`
IdpId string `help:"filter by idp_id"`
IdpEntityId string `help:"filter by idp_entity_id"`
Name string `help:"Filter by name"`
OrderByDomain string `help:"order by domain name" choices:"asc|desc"`
Role string `help:"Filter by role"`
RoleAssignmentDomainId string `help:"filter role assignment domain"`
RoleAssignmentProjectId string `help:"filter role assignment project"`
IdpId string `help:"filter by idp_id"`
IdpEntityId string `help:"filter by idp_entity_id"`
}
R(&UserListOptions{}, "user-list", "List users", func(s *mcclient.ClientSession, args *UserListOptions) error {
params, err := options.ListStructToParams(args)
+2
View File
@@ -191,6 +191,8 @@ type UserListInput struct {
// 角色生效所在的域
RoleAssignmentDomainId string `json:"role_assignment_domain_id"`
// 角色生效所在的项目
RoleAssignmentProjectId string `json:"role_assignment_project_id"`
// email
Email string `json:"email"`
+11
View File
@@ -427,6 +427,17 @@ func (manager *SUserManager) ListItemFilter(
projects := ProjectManager.Query("id").Equals("domain_id", domain.GetId()).SubQuery()
subq = subq.In("target_id", projects.Query())
}
if len(query.RoleAssignmentProjectId) > 0 {
project, err := ProjectManager.FetchByIdOrName(userCred, query.RoleAssignmentProjectId)
if err != nil {
if err == sql.ErrNoRows {
return nil, httperrors.NewResourceNotFoundError2(ProjectManager.Keyword(), query.RoleAssignmentProjectId)
} else {
return nil, httperrors.NewGeneralError(err)
}
}
subq = subq.Equals("target_id", project.GetId())
}
q = q.In("id", subq.SubQuery().Query())
}