Merge pull request #14371 from swordqiu/hotfix/qj-add-notes-for-identity-models

fix: add comments for identity models
This commit is contained in:
Zexi Li
2022-06-01 10:01:40 +08:00
committed by GitHub
11 changed files with 103 additions and 32 deletions
+28 -8
View File
@@ -17,45 +17,65 @@ package identity
import "yunion.io/x/onecloud/pkg/util/rbacutils"
type SIdentityObject struct {
Id string `json:"id"`
// UUID
Id string `json:"id"`
// 名称
Name string `json:"name"`
}
type SDomainObject struct {
SIdentityObject
// 归属域信息
Domain SIdentityObject `json:"domain"`
}
type SDomainObjectWithMetadata struct {
SDomainObject
// 标签信息
Metadata map[string]string `json:"metadata"`
}
type SFetchDomainObject struct {
SIdentityObject
Domain string `json:"domain"`
// 归属域名称
Domain string `json:"domain"`
// 归属域ID
DomainId string `json:"domain_id"`
}
type SFetchDomainObjectWithMetadata struct {
SFetchDomainObject
// 项目标签
Metadata map[string]string `json:"metadata"`
}
type SRoleAssignment struct {
// 归属范围
Scope struct {
Domain SIdentityObject `json:"domain"`
// 归属域信息
Domain SIdentityObject `json:"domain"`
// 归属项目信息,归属范围为项目时有值
Project SDomainObjectWithMetadata `json:"project"`
} `json:"scope"`
User SDomainObject `json:"user"`
Group SDomainObject `json:"group"`
Role SDomainObject `json:"role"`
// 用户信息
User SDomainObject `json:"user"`
// 用户组信息
Group SDomainObject `json:"group"`
// 用户加入项目的角色信息
Role SDomainObject `json:"role"`
// 用户角色关联的权限信息
Policies struct {
// 关联的项目权限名称列表
Project []string `json:"project"`
Domain []string `json:"domain"`
System []string `json:"system"`
// 关联的域权限名称列表
Domain []string `json:"domain"`
// 关联的系统权限名称列表
System []string `json:"system"`
} `json:"policies"`
}
+12 -5
View File
@@ -22,13 +22,20 @@ type DomainDetails struct {
SDomain
UserCount int `json:"user_count"`
GroupCount int `json:"group_count"`
// 归属域的用户数量
UserCount int `json:"user_count"`
// 归属域的用户组数量
GroupCount int `json:"group_count"`
// 归属域的项目数量
ProjectCount int `json:"project_count"`
RoleCount int `json:"role_count"`
PolicyCount int `json:"policy_count"`
IdpCount int `json:"idp_count"`
// 归属域的角色数量
RoleCount int `json:"role_count"`
// 归属域的权限策略数量
PolicyCount int `json:"policy_count"`
// 归属域的认证源数量
IdpCount int `json:"idp_count"`
// 归属该域的外部资源统计信息
ExternalResourceInfo
}
+10 -4
View File
@@ -21,9 +21,12 @@ import (
)
type ExternalResourceInfo struct {
ExtResource jsonutils.JSONObject `json:"ext_resource"`
ExtResourcesLastUpdate time.Time `json:"ext_resources_last_update"`
ExtResourcesNextUpdate time.Time `json:"ext_resources_next_update"`
// 外部资源统计信息(资源类别:数量)
ExtResource jsonutils.JSONObject `json:"ext_resource"`
// 外部资源统计信息上次更新时间
ExtResourcesLastUpdate time.Time `json:"ext_resources_last_update"`
// 外部资源统计信息下次更新时间
ExtResourcesNextUpdate time.Time `json:"ext_resources_next_update"`
}
type ProjectDetails struct {
@@ -31,8 +34,11 @@ type ProjectDetails struct {
SProject
// 加入项目的用户组数量
GroupCount int `json:"group_count"`
UserCount int `json:"user_count"`
// 加入项目的用户数量
UserCount int `json:"user_count"`
// 归属该项目的外部资源统计信息
ExternalResourceInfo
}
+7 -2
View File
@@ -25,11 +25,16 @@ type RoleDetails struct {
SRole
UserCount int `json:"user_count"`
GroupCount int `json:"group_count"`
// 具有该角色的用户数量
UserCount int `json:"user_count"`
// 具有该角色的用户组数量
GroupCount int `json:"group_count"`
// 有该角色的用户或组的项目的数量
ProjectCount int `json:"project_count"`
// 该角色匹配的权限的名称列表
MatchPolicies []string `json:"match_policies"`
// 不同级别的权限的名称列表
Policies map[rbacutils.TRbacScope][]string `json:"policies"`
}
+17 -5
View File
@@ -24,24 +24,36 @@ type UserDetails struct {
SUser
GroupCount int `json:"group_count"`
ProjectCount int `json:"project_count"`
CredentialCount int `json:"credential_count"`
FailedAuthCount int `json:"failed_auth_count"`
FailedAuthAt time.Time `json:"failed_auth_at"`
// 用户归属用户组的数量
GroupCount int `json:"group_count"`
// 用户归属项目的数量
ProjectCount int `json:"project_count"`
// 归属该用户的密钥凭证(含AKSK,TOTP,Secret等)的数量
CredentialCount int `json:"credential_count"`
// 连续登录失败的次数
FailedAuthCount int `json:"failed_auth_count"`
// 上传登录失败的时间
FailedAuthAt time.Time `json:"failed_auth_at"`
// 密码过期时间(如果开启了密码过期)
PasswordExpiresAt time.Time `json:"password_expires_at"`
// 登录后是否需要重置密码
NeedResetPassword bool `json:"need_reset_password"`
// 该用户关联的外部认证源的认证信息
Idps []IdpResourceInfo `json:"idps"`
// 该用户是否为本地用户(SQL维护的用户)
IsLocal bool `json:"is_local"`
// 归属该用户的外部资源统计信息
ExternalResourceInfo
// 用户归属的的项目信息
Projects []SFetchDomainObjectWithMetadata `json:"projects"`
}
type ResetCredentialInput struct {
// 密钥的类型
Type string `json:"type"`
}
+7 -3
View File
@@ -70,10 +70,14 @@ func init() {
type SAssignment struct {
db.SResourceBase
Type string `width:"16" charset:"ascii" nullable:"false" primary:"true" list:"admin"`
ActorId string `width:"64" charset:"ascii" nullable:"false" primary:"true" list:"admin"`
// 关联类型,分为四类:'UserProject','GroupProject','UserDomain','GroupDomain'
Type string `width:"16" charset:"ascii" nullable:"false" primary:"true" list:"admin"`
// 用户或者用户组ID
ActorId string `width:"64" charset:"ascii" nullable:"false" primary:"true" list:"admin"`
// 项目或者域ID
TargetId string `width:"64" charset:"ascii" nullable:"false" primary:"true" list:"admin"`
RoleId string `width:"64" charset:"ascii" nullable:"false" primary:"true" list:"admin"`
// 角色ID
RoleId string `width:"64" charset:"ascii" nullable:"false" primary:"true" list:"admin"`
Inherited tristate.TriState `primary:"true" list:"admin"`
}
+5 -1
View File
@@ -58,9 +58,13 @@ func init() {
type SDomain struct {
db.SStandaloneResourceBase
// 额外信息
Extra *jsonutils.JSONDict `nullable:"true"`
Enabled tristate.TriState `default:"true" list:"admin" update:"admin" create:"admin_optional"`
// 改域是否启用
Enabled tristate.TriState `default:"true" list:"admin" update:"admin" create:"admin_optional"`
// 是否为域
IsDomain tristate.TriState `default:"false"`
// IdpId string `token:"parent_id" width:"64" charset:"ascii" index:"true" list:"admin"`
+1
View File
@@ -67,6 +67,7 @@ func init() {
type SGroup struct {
SIdentityBaseResource
// 用户组的显示名称
Displayname string `with:"128" charset:"utf8" nullable:"true" list:"domain" update:"domain" create:"domain_optional"`
}
+1
View File
@@ -63,6 +63,7 @@ type SIdentityBaseResource struct {
db.SStandaloneResourceBase
db.SDomainizedResourceBase
// 额外信息
Extra *jsonutils.JSONDict `nullable:"true"`
// DomainId string `width:"64" charset:"ascii" default:"default" nullable:"false" index:"true" list:"user"`
}
+2
View File
@@ -77,8 +77,10 @@ func init() {
type SProject struct {
SIdentityBaseResource
// 上级项目或域的ID
ParentId string `width:"64" charset:"ascii" list:"domain" create:"domain_optional"`
// 该项目是否为域(domain)
IsDomain tristate.TriState `default:"false"`
}
+13 -4
View File
@@ -81,24 +81,33 @@ type SUser struct {
db.SRecordChecksumResourceBase
SEnabledIdentityBaseResource
Email string `width:"64" charset:"utf8" nullable:"true" index:"true" list:"domain" update:"domain" create:"domain_optional"`
// 用户邮箱
Email string `width:"64" charset:"utf8" nullable:"true" index:"true" list:"domain" update:"domain" create:"domain_optional"`
// 用户手机号
Mobile string `width:"20" charset:"ascii" nullable:"true" index:"true" list:"domain" update:"domain" create:"domain_optional"`
// 显示名称,用户登录后显示在右上角菜单入口
Displayname string `with:"128" charset:"utf8" nullable:"true" list:"domain" update:"domain" create:"domain_optional"`
// 上次登录时间
LastActiveAt time.Time `nullable:"true" list:"domain"`
LastLoginIp string `nullable:"true" list:"domain"`
// 上次用户登录IP
LastLoginIp string `nullable:"true" list:"domain"`
// 上次用户登录方式,可能值有:web(web控制台),cli(命令行climc),API(api)
LastLoginSource string `nullable:"true" list:"domain"`
// 是否为系统账号,系统账号不会检查密码复杂度,默认不在列表显示
IsSystemAccount tristate.TriState `default:"false" list:"domain" update:"admin" create:"admin_optional"`
// deprecated
DefaultProjectId string `width:"64" charset:"ascii" nullable:"true"`
// 是否允许登录Web控制台,如果是用于API访问的用户,可禁用web控制台登录
AllowWebConsole tristate.TriState `default:"true" list:"domain" update:"domain" create:"domain_optional"`
EnableMfa tristate.TriState `default:"false" list:"domain" update:"domain" create:"domain_optional"`
// 是否开启MFA
EnableMfa tristate.TriState `default:"false" list:"domain" update:"domain" create:"domain_optional"`
// 用户的默认语言设置,默认是zh_CN
Lang string `width:"8" charset:"ascii" nullable:"false" list:"domain" update:"domain" create:"domain_optional"`
}