From 3198c2f7d76c561828ee17813a5d39e284af3cad Mon Sep 17 00:00:00 2001 From: Qiu Jian Date: Wed, 1 Jun 2022 00:12:56 +0800 Subject: [PATCH] fix: add comments for identity models --- pkg/apis/identity/assignments.go | 36 ++++++++++++++++++++++------- pkg/apis/identity/domain.go | 17 ++++++++++---- pkg/apis/identity/project.go | 14 +++++++---- pkg/apis/identity/role.go | 9 ++++++-- pkg/apis/identity/user.go | 22 ++++++++++++++---- pkg/keystone/models/assignments.go | 10 +++++--- pkg/keystone/models/domains.go | 6 ++++- pkg/keystone/models/groups.go | 1 + pkg/keystone/models/identitybase.go | 1 + pkg/keystone/models/projects.go | 2 ++ pkg/keystone/models/users.go | 17 ++++++++++---- 11 files changed, 103 insertions(+), 32 deletions(-) diff --git a/pkg/apis/identity/assignments.go b/pkg/apis/identity/assignments.go index 0e39c9c5ad..911e8bd3b3 100644 --- a/pkg/apis/identity/assignments.go +++ b/pkg/apis/identity/assignments.go @@ -17,45 +17,65 @@ package identity import "yunion.io/x/onecloud/pkg/util/rbacutils" type SIdentityObject struct { - Id string `json:"id"` + // UUID + Id string `json:"id"` + // 名称 Name string `json:"name"` } type SDomainObject struct { SIdentityObject + + // 归属域信息 Domain SIdentityObject `json:"domain"` } type SDomainObjectWithMetadata struct { SDomainObject + + // 标签信息 Metadata map[string]string `json:"metadata"` } type SFetchDomainObject struct { SIdentityObject - Domain string `json:"domain"` + // 归属域名称 + Domain string `json:"domain"` + // 归属域ID DomainId string `json:"domain_id"` } type SFetchDomainObjectWithMetadata struct { SFetchDomainObject + // 项目标签 Metadata map[string]string `json:"metadata"` } type SRoleAssignment struct { + // 归属范围 Scope struct { - Domain SIdentityObject `json:"domain"` + // 归属域信息 + Domain SIdentityObject `json:"domain"` + // 归属项目信息,归属范围为项目时有值 Project SDomainObjectWithMetadata `json:"project"` } `json:"scope"` - User SDomainObject `json:"user"` - Group SDomainObject `json:"group"` - Role SDomainObject `json:"role"` + // 用户信息 + User SDomainObject `json:"user"` + // 用户组信息 + Group SDomainObject `json:"group"` + // 用户加入项目的角色信息 + Role SDomainObject `json:"role"` + + // 用户角色关联的权限信息 Policies struct { + // 关联的项目权限名称列表 Project []string `json:"project"` - Domain []string `json:"domain"` - System []string `json:"system"` + // 关联的域权限名称列表 + Domain []string `json:"domain"` + // 关联的系统权限名称列表 + System []string `json:"system"` } `json:"policies"` } diff --git a/pkg/apis/identity/domain.go b/pkg/apis/identity/domain.go index 2722b524ce..dffb441774 100644 --- a/pkg/apis/identity/domain.go +++ b/pkg/apis/identity/domain.go @@ -22,13 +22,20 @@ type DomainDetails struct { SDomain - UserCount int `json:"user_count"` - GroupCount int `json:"group_count"` + // 归属域的用户数量 + UserCount int `json:"user_count"` + // 归属域的用户组数量 + GroupCount int `json:"group_count"` + // 归属域的项目数量 ProjectCount int `json:"project_count"` - RoleCount int `json:"role_count"` - PolicyCount int `json:"policy_count"` - IdpCount int `json:"idp_count"` + // 归属域的角色数量 + RoleCount int `json:"role_count"` + // 归属域的权限策略数量 + PolicyCount int `json:"policy_count"` + // 归属域的认证源数量 + IdpCount int `json:"idp_count"` + // 归属该域的外部资源统计信息 ExternalResourceInfo } diff --git a/pkg/apis/identity/project.go b/pkg/apis/identity/project.go index 51f993b7e2..1ae652c438 100644 --- a/pkg/apis/identity/project.go +++ b/pkg/apis/identity/project.go @@ -21,9 +21,12 @@ import ( ) type ExternalResourceInfo struct { - ExtResource jsonutils.JSONObject `json:"ext_resource"` - ExtResourcesLastUpdate time.Time `json:"ext_resources_last_update"` - ExtResourcesNextUpdate time.Time `json:"ext_resources_next_update"` + // 外部资源统计信息(资源类别:数量) + ExtResource jsonutils.JSONObject `json:"ext_resource"` + // 外部资源统计信息上次更新时间 + ExtResourcesLastUpdate time.Time `json:"ext_resources_last_update"` + // 外部资源统计信息下次更新时间 + ExtResourcesNextUpdate time.Time `json:"ext_resources_next_update"` } type ProjectDetails struct { @@ -31,8 +34,11 @@ type ProjectDetails struct { SProject + // 加入项目的用户组数量 GroupCount int `json:"group_count"` - UserCount int `json:"user_count"` + // 加入项目的用户数量 + UserCount int `json:"user_count"` + // 归属该项目的外部资源统计信息 ExternalResourceInfo } diff --git a/pkg/apis/identity/role.go b/pkg/apis/identity/role.go index c920d357a0..17770755ef 100644 --- a/pkg/apis/identity/role.go +++ b/pkg/apis/identity/role.go @@ -25,11 +25,16 @@ type RoleDetails struct { SRole - UserCount int `json:"user_count"` - GroupCount int `json:"group_count"` + // 具有该角色的用户数量 + UserCount int `json:"user_count"` + // 具有该角色的用户组数量 + GroupCount int `json:"group_count"` + // 有该角色的用户或组的项目的数量 ProjectCount int `json:"project_count"` + // 该角色匹配的权限的名称列表 MatchPolicies []string `json:"match_policies"` + // 不同级别的权限的名称列表 Policies map[rbacutils.TRbacScope][]string `json:"policies"` } diff --git a/pkg/apis/identity/user.go b/pkg/apis/identity/user.go index 9a23388782..968b204086 100644 --- a/pkg/apis/identity/user.go +++ b/pkg/apis/identity/user.go @@ -24,24 +24,36 @@ type UserDetails struct { SUser - GroupCount int `json:"group_count"` - ProjectCount int `json:"project_count"` - CredentialCount int `json:"credential_count"` - FailedAuthCount int `json:"failed_auth_count"` - FailedAuthAt time.Time `json:"failed_auth_at"` + // 用户归属用户组的数量 + GroupCount int `json:"group_count"` + // 用户归属项目的数量 + ProjectCount int `json:"project_count"` + // 归属该用户的密钥凭证(含AKSK,TOTP,Secret等)的数量 + CredentialCount int `json:"credential_count"` + // 连续登录失败的次数 + FailedAuthCount int `json:"failed_auth_count"` + // 上传登录失败的时间 + FailedAuthAt time.Time `json:"failed_auth_at"` + // 密码过期时间(如果开启了密码过期) PasswordExpiresAt time.Time `json:"password_expires_at"` + // 登录后是否需要重置密码 NeedResetPassword bool `json:"need_reset_password"` + // 该用户关联的外部认证源的认证信息 Idps []IdpResourceInfo `json:"idps"` + // 该用户是否为本地用户(SQL维护的用户) IsLocal bool `json:"is_local"` + // 归属该用户的外部资源统计信息 ExternalResourceInfo + // 用户归属的的项目信息 Projects []SFetchDomainObjectWithMetadata `json:"projects"` } type ResetCredentialInput struct { + // 密钥的类型 Type string `json:"type"` } diff --git a/pkg/keystone/models/assignments.go b/pkg/keystone/models/assignments.go index 7416d8e2e3..fe5f91e143 100644 --- a/pkg/keystone/models/assignments.go +++ b/pkg/keystone/models/assignments.go @@ -70,10 +70,14 @@ func init() { type SAssignment struct { db.SResourceBase - Type string `width:"16" charset:"ascii" nullable:"false" primary:"true" list:"admin"` - ActorId string `width:"64" charset:"ascii" nullable:"false" primary:"true" list:"admin"` + // 关联类型,分为四类:'UserProject','GroupProject','UserDomain','GroupDomain' + Type string `width:"16" charset:"ascii" nullable:"false" primary:"true" list:"admin"` + // 用户或者用户组ID + ActorId string `width:"64" charset:"ascii" nullable:"false" primary:"true" list:"admin"` + // 项目或者域ID TargetId string `width:"64" charset:"ascii" nullable:"false" primary:"true" list:"admin"` - RoleId string `width:"64" charset:"ascii" nullable:"false" primary:"true" list:"admin"` + // 角色ID + RoleId string `width:"64" charset:"ascii" nullable:"false" primary:"true" list:"admin"` Inherited tristate.TriState `primary:"true" list:"admin"` } diff --git a/pkg/keystone/models/domains.go b/pkg/keystone/models/domains.go index 1293cd096e..eadeb246c2 100644 --- a/pkg/keystone/models/domains.go +++ b/pkg/keystone/models/domains.go @@ -58,9 +58,13 @@ func init() { type SDomain struct { db.SStandaloneResourceBase + // 额外信息 Extra *jsonutils.JSONDict `nullable:"true"` - Enabled tristate.TriState `default:"true" list:"admin" update:"admin" create:"admin_optional"` + // 改域是否启用 + Enabled tristate.TriState `default:"true" list:"admin" update:"admin" create:"admin_optional"` + + // 是否为域 IsDomain tristate.TriState `default:"false"` // IdpId string `token:"parent_id" width:"64" charset:"ascii" index:"true" list:"admin"` diff --git a/pkg/keystone/models/groups.go b/pkg/keystone/models/groups.go index 98452b7613..4ec1b9520e 100644 --- a/pkg/keystone/models/groups.go +++ b/pkg/keystone/models/groups.go @@ -67,6 +67,7 @@ func init() { type SGroup struct { SIdentityBaseResource + // 用户组的显示名称 Displayname string `with:"128" charset:"utf8" nullable:"true" list:"domain" update:"domain" create:"domain_optional"` } diff --git a/pkg/keystone/models/identitybase.go b/pkg/keystone/models/identitybase.go index 0cda9fc9e2..8b0bfc01db 100644 --- a/pkg/keystone/models/identitybase.go +++ b/pkg/keystone/models/identitybase.go @@ -63,6 +63,7 @@ type SIdentityBaseResource struct { db.SStandaloneResourceBase db.SDomainizedResourceBase + // 额外信息 Extra *jsonutils.JSONDict `nullable:"true"` // DomainId string `width:"64" charset:"ascii" default:"default" nullable:"false" index:"true" list:"user"` } diff --git a/pkg/keystone/models/projects.go b/pkg/keystone/models/projects.go index 3799dbe702..9a56505201 100644 --- a/pkg/keystone/models/projects.go +++ b/pkg/keystone/models/projects.go @@ -77,8 +77,10 @@ func init() { type SProject struct { SIdentityBaseResource + // 上级项目或域的ID ParentId string `width:"64" charset:"ascii" list:"domain" create:"domain_optional"` + // 该项目是否为域(domain) IsDomain tristate.TriState `default:"false"` } diff --git a/pkg/keystone/models/users.go b/pkg/keystone/models/users.go index 2be08ee867..be1d8d2eb4 100644 --- a/pkg/keystone/models/users.go +++ b/pkg/keystone/models/users.go @@ -81,24 +81,33 @@ type SUser struct { db.SRecordChecksumResourceBase SEnabledIdentityBaseResource - Email string `width:"64" charset:"utf8" nullable:"true" index:"true" list:"domain" update:"domain" create:"domain_optional"` + // 用户邮箱 + Email string `width:"64" charset:"utf8" nullable:"true" index:"true" list:"domain" update:"domain" create:"domain_optional"` + // 用户手机号 Mobile string `width:"20" charset:"ascii" nullable:"true" index:"true" list:"domain" update:"domain" create:"domain_optional"` + // 显示名称,用户登录后显示在右上角菜单入口 Displayname string `with:"128" charset:"utf8" nullable:"true" list:"domain" update:"domain" create:"domain_optional"` + // 上次登录时间 LastActiveAt time.Time `nullable:"true" list:"domain"` - - LastLoginIp string `nullable:"true" list:"domain"` + // 上次用户登录IP + LastLoginIp string `nullable:"true" list:"domain"` + // 上次用户登录方式,可能值有:web(web控制台),cli(命令行climc),API(api) LastLoginSource string `nullable:"true" list:"domain"` + // 是否为系统账号,系统账号不会检查密码复杂度,默认不在列表显示 IsSystemAccount tristate.TriState `default:"false" list:"domain" update:"admin" create:"admin_optional"` // deprecated DefaultProjectId string `width:"64" charset:"ascii" nullable:"true"` + // 是否允许登录Web控制台,如果是用于API访问的用户,可禁用web控制台登录 AllowWebConsole tristate.TriState `default:"true" list:"domain" update:"domain" create:"domain_optional"` - EnableMfa tristate.TriState `default:"false" list:"domain" update:"domain" create:"domain_optional"` + // 是否开启MFA + EnableMfa tristate.TriState `default:"false" list:"domain" update:"domain" create:"domain_optional"` + // 用户的默认语言设置,默认是zh_CN Lang string `width:"8" charset:"ascii" nullable:"false" list:"domain" update:"domain" create:"domain_optional"` }