Merge pull request #8771 from swordqiu/feature/qj-allow-join-project-across-domain

feature: allow join project across domain
This commit is contained in:
Zexi Li
2020-11-13 10:39:38 +08:00
committed by GitHub
3 changed files with 13 additions and 4 deletions
+3 -2
View File
@@ -29,6 +29,7 @@ import (
"yunion.io/x/onecloud/pkg/appsrv"
"yunion.io/x/onecloud/pkg/cloudcommon/db"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/keystone/options"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/mcclient/auth"
"yunion.io/x/onecloud/pkg/util/rbacutils"
@@ -248,7 +249,7 @@ func (manager *SAssignmentManager) ProjectAddUser(ctx context.Context, userCred
return err
}
if project.DomainId != user.DomainId {
if project.DomainId != api.DEFAULT_DOMAIN_ID {
if project.DomainId != api.DEFAULT_DOMAIN_ID && !options.Options.AllowJoinProjectsAcrossDomains {
return httperrors.NewInputParameterError("join user into project of default domain or identical domain")
} else if !db.IsAllowPerform(rbacutils.ScopeSystem, userCred, user, "join-project") {
return httperrors.NewForbiddenError("not enough privilege")
@@ -348,7 +349,7 @@ func (manager *SAssignmentManager) projectAddGroup(ctx context.Context, userCred
return err
}
if project.DomainId != group.DomainId {
if project.DomainId != api.DEFAULT_DOMAIN_ID {
if project.DomainId != api.DEFAULT_DOMAIN_ID && !options.Options.AllowJoinProjectsAcrossDomains {
return httperrors.NewInputParameterError("join group into project of default domain or identical domain")
} else if !db.IsAllowPerform(rbacutils.ScopeSystem, userCred, group, "join-project") {
return httperrors.NewForbiddenError("not enough privilege")
+8 -2
View File
@@ -351,8 +351,14 @@ func (role *SRole) UpdateInContext(ctx context.Context, userCred mcclient.TokenC
if !ok {
return nil, httperrors.NewInputParameterError("not supported update context %s", ctxObjs[0].Keyword())
}
if project.DomainId != role.DomainId && !role.GetIsPublic() {
return nil, httperrors.NewInputParameterError("inconsistent domain for project and roles")
if project.DomainId != role.DomainId {
projectOwner := &db.SOwnerId{
ProjectId: project.Id,
DomainId: project.DomainId,
}
if !role.IsSharable(projectOwner) {
return nil, httperrors.NewInputParameterError("inconsistent domain for project and roles")
}
}
err := validateJoinProject(userCred, project, []string{role.Id})
if err != nil {
+2
View File
@@ -52,6 +52,8 @@ type SKeystoneOptions struct {
DefaultPolicyQuota int `default:"500" help:"default quota for policy per domain, default is 500"`
SessionEndpointType string `help:"Client session end point type"`
AllowJoinProjectsAcrossDomains bool `help:"allow users/groups to join projects across domains" default:"false"`
}
var (