diff --git a/pkg/compute/guestdrivers/kvm.go b/pkg/compute/guestdrivers/kvm.go index 63f794dc8e..c2fa738762 100644 --- a/pkg/compute/guestdrivers/kvm.go +++ b/pkg/compute/guestdrivers/kvm.go @@ -559,10 +559,9 @@ func checkAssignHost(userCred mcclient.TokenCredential, preferHost string) error return httperrors.NewBadRequestError("Host %s not found", preferHost) } host := iHost.(*models.SHost) - if db.IsAdminAllowPerform(userCred, host, "assign-host") { - } else if db.IsDomainAllowPerform(userCred, host, "assign-host") && userCred.GetProjectDomainId() == host.DomainId { - } else { - return httperrors.NewNotSufficientPrivilegeError("Only system admin can assign host") + err := host.IsAssignable(userCred) + if err != nil { + return errors.Wrap(err, "IsAssignable") } return nil } diff --git a/pkg/compute/models/guest_actions.go b/pkg/compute/models/guest_actions.go index 596c4b79ca..9e077ff69e 100644 --- a/pkg/compute/models/guest_actions.go +++ b/pkg/compute/models/guest_actions.go @@ -4417,10 +4417,9 @@ func (manager *SGuestManager) PerformBatchMigrate(ctx context.Context, userCred host := iHost.(*SHost) preferHostId = host.Id - if db.IsAdminAllowPerform(userCred, host, "assign-host") { - } else if db.IsDomainAllowPerform(userCred, host, "assign-host") && userCred.GetProjectDomainId() == host.DomainId { - } else { - return nil, httperrors.NewNotSufficientPrivilegeError("Only system admin can assign host") + err := host.IsAssignable(userCred) + if err != nil { + return nil, errors.Wrap(err, "IsAssignable") } } diff --git a/pkg/compute/models/helper.go b/pkg/compute/models/helper.go index f165f44285..cba5561de7 100644 --- a/pkg/compute/models/helper.go +++ b/pkg/compute/models/helper.go @@ -20,6 +20,7 @@ import ( "yunion.io/x/jsonutils" "yunion.io/x/log" + "yunion.io/x/pkg/errors" "yunion.io/x/pkg/utils" api "yunion.io/x/onecloud/pkg/apis/compute" @@ -73,10 +74,9 @@ func ValidateScheduleCreateData(ctx context.Context, userCred mcclient.TokenCred } baremetal := bmObj.(*SHost) - if db.IsAdminAllowPerform(userCred, baremetal, "assign-host") { - } else if db.IsDomainAllowPerform(userCred, baremetal, "assign-host") && userCred.GetProjectDomainId() == baremetal.DomainId { - } else { - return nil, httperrors.NewNotSufficientPrivilegeError("Only system admin can assign host") + err = baremetal.IsAssignable(userCred) + if err != nil { + return nil, errors.Wrap(err, "IsAssignable") } if !baremetal.GetEnabled() { diff --git a/pkg/compute/models/hosts.go b/pkg/compute/models/hosts.go index 1a9ad048fe..7869580373 100644 --- a/pkg/compute/models/hosts.go +++ b/pkg/compute/models/hosts.go @@ -4928,10 +4928,9 @@ func (host *SHost) PerformHostMaintenance(ctx context.Context, userCred mcclient } host := iHost.(*SHost) preferHostId = host.Id - if db.IsAdminAllowPerform(userCred, host, "assign-host") { - } else if db.IsDomainAllowPerform(userCred, host, "assign-host") && userCred.GetProjectDomainId() == host.DomainId { - } else { - return nil, httperrors.NewNotSufficientPrivilegeError("Only system admin can assign host") + err := host.IsAssignable(userCred) + if err != nil { + return nil, errors.Wrap(err, "IsAssignable") } } @@ -5479,3 +5478,16 @@ func (manager *SHostManager) FetchHostByExtId(extid string) *SHost { return &host } } + +func (host *SHost) IsAssignable(userCred mcclient.TokenCredential) error { + if db.IsAdminAllowPerform(userCred, host, "assign-host") { + return nil + } else if db.IsDomainAllowPerform(userCred, host, "assign-host") && + (userCred.GetProjectDomainId() == host.DomainId || + host.PublicScope == string(rbacutils.ScopeSystem) || + (host.PublicScope == string(rbacutils.ScopeDomain) && utils.IsInStringArray(userCred.GetProjectDomainId(), host.GetSharedDomains()))) { + return nil + } else { + return httperrors.NewNotSufficientPrivilegeError("Only system admin can assign host") + } +}