diff --git a/pkg/compute/models/secgroupcache.go b/pkg/compute/models/secgroupcache.go index e326d56439..103de1f2dd 100644 --- a/pkg/compute/models/secgroupcache.go +++ b/pkg/compute/models/secgroupcache.go @@ -58,9 +58,6 @@ type SSecurityGroupCache struct { // 被其他安全组引用的次数 ReferenceCount int `nullable:"false" list:"user" json:"reference_count"` - // 安全组Id - // SecgroupId string `width:"128" charset:"ascii" list:"user" create:"required"` - // 虚拟私有网络外部Id VpcId string `width:"128" charset:"ascii" list:"user" create:"required"` ExternalProjectId string `width:"128" charset:"ascii" list:"user" create:"optional"` @@ -85,13 +82,25 @@ func (manager *SSecurityGroupCacheManager) AllowCreateItem(ctx context.Context, } func (manager *SSecurityGroupCacheManager) AllowListItems(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject) bool { - return true + return db.IsProjectAllowList(userCred, manager) } func (self *SSecurityGroupCache) AllowUpdateItem(ctx context.Context, userCred mcclient.TokenCredential) bool { return false } +func (self *SSecurityGroupCache) GetOwnerId() mcclient.IIdentityProvider { + sec, err := self.GetSecgroup() + if err != nil { + return &db.SOwnerId{} + } + return &db.SOwnerId{DomainId: sec.DomainId, ProjectId: sec.ProjectId} +} + +func (manager *SSecurityGroupCacheManager) ResourceScope() rbacutils.TRbacScope { + return rbacutils.ScopeProject +} + // 安全组缓存列表 func (manager *SSecurityGroupCacheManager) ListItemFilter( ctx context.Context, @@ -124,18 +133,6 @@ func (manager *SSecurityGroupCacheManager) ListItemFilter( return nil, errors.Wrap(err, "SSecurityGroupResourceBaseManager.ListItemFilter") } - /*if defsecgroup := query.Secgroup; len(defsecgroup) > 0 { - secgroup, err := SecurityGroupManager.FetchByIdOrName(userCred, defsecgroup) - if err != nil { - if err == sql.ErrNoRows { - return nil, httperrors.NewResourceNotFoundError2(SecurityGroupManager.Keyword(), defsecgroup) - } else { - return nil, httperrors.NewGeneralError(err) - } - } - q = q.Equals("secgroup_id", secgroup.GetId()) - }*/ - return q, nil }