mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
Merge branch 'release/2.3.0' of ssh://git.yunion.io/~qiujian/onecloud into hotfix/qj-resolve-conflict-2.4.0-20181203-1
Conflicts: Gopkg.lock
This commit is contained in:
+16
-106
@@ -1,9 +1,8 @@
|
||||
package policy
|
||||
|
||||
import (
|
||||
"time"
|
||||
"yunion.io/x/log"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/gotypes"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
@@ -12,123 +11,34 @@ import (
|
||||
)
|
||||
|
||||
type SPolicyTokenCredential struct {
|
||||
Token mcclient.TokenCredential
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) String() string {
|
||||
return self.Token.String()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) IsZero() bool {
|
||||
return self.Token.IsZero()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetProjectId() string {
|
||||
return self.Token.GetProjectId()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetTenantId() string {
|
||||
return self.Token.GetTenantId()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetUserId() string {
|
||||
return self.Token.GetUserId()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetServiceURL(service, region, zone, endpointType string) (string, error) {
|
||||
return self.Token.GetServiceURL(service, region, zone, endpointType)
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetServiceURLs(service, region, zone, endpointType string) ([]string, error) {
|
||||
return self.Token.GetServiceURLs(service, region, zone, endpointType)
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetTokenString() string {
|
||||
return self.Token.GetTokenString()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetDomainId() string {
|
||||
return self.Token.GetDomainId()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetDomainName() string {
|
||||
return self.Token.GetDomainName()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetTenantName() string {
|
||||
return self.Token.GetTenantName()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetProjectName() string {
|
||||
return self.Token.GetProjectName()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetUserName() string {
|
||||
return self.Token.GetUserName()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetRoles() []string {
|
||||
return self.Token.GetRoles()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetExpires() time.Time {
|
||||
return self.Token.GetExpires()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) IsValid() bool {
|
||||
return self.Token.IsValid()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) ValidDuration() time.Duration {
|
||||
return self.Token.ValidDuration()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetRegions() []string {
|
||||
return self.Token.GetRegions()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetServiceCatalog() mcclient.IServiceCatalog {
|
||||
return self.Token.GetServiceCatalog()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetCatalogData(serviceTypes []string, region string) jsonutils.JSONObject {
|
||||
return self.Token.GetCatalogData(serviceTypes, region)
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetInternalServices(region string) []string {
|
||||
return self.Token.GetInternalServices(region)
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetExternalServices(region string) []mcclient.ExternalService {
|
||||
return self.Token.GetExternalServices(region)
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) GetEndpoints(region string, endpointType string) []mcclient.Endpoint {
|
||||
return self.Token.GetEndpoints(region, endpointType)
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) ToJson() jsonutils.JSONObject {
|
||||
return self.Token.ToJson()
|
||||
// usage embedded interface
|
||||
mcclient.TokenCredential
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) HasSystemAdminPrivelege() bool {
|
||||
if consts.IsRbacEnabled() {
|
||||
return PolicyManager.IsAdminCapable(self.Token)
|
||||
return PolicyManager.IsAdminCapable(self.TokenCredential)
|
||||
}
|
||||
return self.Token.HasSystemAdminPrivelege()
|
||||
return self.TokenCredential.HasSystemAdminPrivelege()
|
||||
}
|
||||
|
||||
func (self *SPolicyTokenCredential) IsAdminAllow(service string, resource string, action string, extra ...string) bool {
|
||||
if consts.IsRbacEnabled() {
|
||||
result := PolicyManager.Allow(true, self.Token, service, resource, action, extra...)
|
||||
result := PolicyManager.Allow(true, self.TokenCredential, service, resource, action, extra...)
|
||||
return result == rbacutils.AdminAllow
|
||||
}
|
||||
return self.Token.IsAdminAllow(service, resource, action, extra...)
|
||||
return self.TokenCredential.IsAdminAllow(service, resource, action, extra...)
|
||||
}
|
||||
|
||||
func init() {
|
||||
gotypes.RegisterSerializable(mcclient.TokenCredentialType, func() gotypes.ISerializable {
|
||||
return &SPolicyTokenCredential{}
|
||||
gotypes.RegisterSerializableTransformer(mcclient.TokenCredentialType, func(input gotypes.ISerializable) gotypes.ISerializable {
|
||||
log.Debugf("do TokenCredential transform for %#v", input)
|
||||
switch val := input.(type) {
|
||||
case *mcclient.SSimpleToken:
|
||||
return &SPolicyTokenCredential{val}
|
||||
default:
|
||||
return val
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
@@ -140,6 +50,6 @@ func FilterPolicyCredential(token mcclient.TokenCredential) mcclient.TokenCreden
|
||||
case *SPolicyTokenCredential:
|
||||
return token
|
||||
default:
|
||||
return &SPolicyTokenCredential{Token: token}
|
||||
return &SPolicyTokenCredential{TokenCredential: token}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user