From a9fafc4517e81ad6c8a084d79e690df7521e199e Mon Sep 17 00:00:00 2001 From: rainzm Date: Mon, 7 Sep 2020 17:59:37 +0800 Subject: [PATCH] fix(notify): break down permissions of notifyconfigs 1. Only allow admin to create, list, update or delete. 2. Allow user to get types. --- pkg/notify/models/config.go | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/pkg/notify/models/config.go b/pkg/notify/models/config.go index a8d0f202cf..341bf2acd4 100644 --- a/pkg/notify/models/config.go +++ b/pkg/notify/models/config.go @@ -33,6 +33,7 @@ import ( notifyv2 "yunion.io/x/onecloud/pkg/notify" "yunion.io/x/onecloud/pkg/notify/oldmodels" "yunion.io/x/onecloud/pkg/notify/options" + "yunion.io/x/onecloud/pkg/util/rbacutils" "yunion.io/x/onecloud/pkg/util/stringutils2" ) @@ -358,6 +359,26 @@ func (self *SConfigManager) InitializeData() error { return nil } +func (cm *SConfigManager) ResourceScope() rbacutils.TRbacScope { + return rbacutils.ScopeUser +} + +func (cm *SConfigManager) AllowCreateItem(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data jsonutils.JSONObject) bool { + return db.IsAdminAllowCreate(userCred, cm) +} + +func (c *SConfig) AllowUpdateItem(ctx context.Context, userCred mcclient.TokenCredential) bool { + return db.IsAdminAllowUpdate(userCred, c) +} + +func (cm *SConfigManager) AllowListItems(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject) bool { + return db.IsAdminAllowList(userCred, cm) +} + +func (c *SConfig) AllowDeleteItem(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data jsonutils.JSONObject) bool { + return db.IsAdminAllowDelete(userCred, c) +} + // Fetch all SConfig struct which type is contactType. func (self *SConfigManager) GetConfigByType(contactType string) (*SConfig, error) { var config SConfig