mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
fix: usage filter by policy tags
This commit is contained in:
@@ -343,6 +343,14 @@ type IScopedResourceManager interface {
|
||||
FetchOwnerId(ctx context.Context, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error)
|
||||
}
|
||||
|
||||
func UsagePolicyCheck(userCred mcclient.TokenCredential, manager IScopedResourceManager, scope rbacscope.TRbacScope) rbacutils.SPolicyResult {
|
||||
allowScope, policyTagFilters := policy.PolicyManager.AllowScope(userCred, consts.GetServiceType(), manager.KeywordPlural(), policy.PolicyActionList)
|
||||
if scope.HigherThan(allowScope) {
|
||||
return rbacutils.SPolicyResult{Result: rbacutils.Deny}
|
||||
}
|
||||
return policyTagFilters
|
||||
}
|
||||
|
||||
func FetchCheckQueryOwnerScope(
|
||||
ctx context.Context,
|
||||
userCred mcclient.TokenCredential,
|
||||
|
||||
@@ -48,7 +48,7 @@ func ObjectIdQueryWithPolicyResult(q *sqlchemy.SQuery, manager IModelManager, re
|
||||
q = ObjectIdQueryWithTagFilters(q, "tenant_id", "project", tagFilters)
|
||||
}
|
||||
}
|
||||
if !result.ProjectTags.IsEmpty() {
|
||||
if !result.ObjectTags.IsEmpty() {
|
||||
tagFilters := tagutils.STagFilters{}
|
||||
tagFilters.AddFilters(result.ObjectTags)
|
||||
q = ObjectIdQueryWithTagFilters(q, "id", manager.Keyword(), tagFilters)
|
||||
|
||||
Reference in New Issue
Block a user