fix: usage filter by policy tags

This commit is contained in:
Qiu Jian
2023-01-30 21:52:17 +08:00
parent b401a961c2
commit ca04fcd0de
5 changed files with 344 additions and 175 deletions
+8
View File
@@ -343,6 +343,14 @@ type IScopedResourceManager interface {
FetchOwnerId(ctx context.Context, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error)
}
func UsagePolicyCheck(userCred mcclient.TokenCredential, manager IScopedResourceManager, scope rbacscope.TRbacScope) rbacutils.SPolicyResult {
allowScope, policyTagFilters := policy.PolicyManager.AllowScope(userCred, consts.GetServiceType(), manager.KeywordPlural(), policy.PolicyActionList)
if scope.HigherThan(allowScope) {
return rbacutils.SPolicyResult{Result: rbacutils.Deny}
}
return policyTagFilters
}
func FetchCheckQueryOwnerScope(
ctx context.Context,
userCred mcclient.TokenCredential,
+1 -1
View File
@@ -48,7 +48,7 @@ func ObjectIdQueryWithPolicyResult(q *sqlchemy.SQuery, manager IModelManager, re
q = ObjectIdQueryWithTagFilters(q, "tenant_id", "project", tagFilters)
}
}
if !result.ProjectTags.IsEmpty() {
if !result.ObjectTags.IsEmpty() {
tagFilters := tagutils.STagFilters{}
tagFilters.AddFilters(result.ObjectTags)
q = ObjectIdQueryWithTagFilters(q, "id", manager.Keyword(), tagFilters)