fix: 1. allow remove current user from current project. 2. reset (#15985)

recovery-questions when resetting MFA

Co-authored-by: Qiu Jian <qiujian@yunionyun.com>
This commit is contained in:
Jian Qiu
2023-02-18 13:04:30 +08:00
committed by GitHub
co-authored by Qiu Jian
parent fd680035f4
commit eac96cdadc
2 changed files with 15 additions and 7 deletions
+8 -6
View File
@@ -420,9 +420,10 @@ func (manager *SAssignmentManager) projectRemoveAllUser(ctx context.Context, use
if user.IsAdminUser() {
return httperrors.NewForbiddenError("sysadmin is protected")
}
if user.Id == userCred.GetUserId() {
return httperrors.NewForbiddenError("cannot remove current user from current project")
}
// allow remove current user from current project. user takes the consequence
// if user.Id == userCred.GetUserId() {
// return httperrors.NewForbiddenError("cannot remove current user from current project")
// }
err := manager.batchRemove(user.Id, []string{api.AssignmentUserProject, api.AssignmentUserDomain})
if err != nil {
return errors.Wrap(err, "manager.batchRemove")
@@ -444,10 +445,11 @@ func (manager *SAssignmentManager) projectRemoveUser(ctx context.Context, userCr
if project.IsAdminProject() && user.IsAdminUser() && role.IsSystemRole() {
return httperrors.NewForbiddenError("sysadmin is protected")
}
// allow remove current user from current project, user takes the consequence
// prevent remove current user from current project
if project.Id == userCred.GetProjectId() && user.Id == userCred.GetUserId() {
return httperrors.NewForbiddenError("cannot remove current user from current project")
}
// if project.Id == userCred.GetProjectId() && user.Id == userCred.GetUserId() {
// return httperrors.NewForbiddenError("cannot remove current user from current project")
// }
if project.DomainId != user.DomainId {
// if project.DomainId != api.DEFAULT_DOMAIN_ID {
// return httperrors.NewInputParameterError("join user into project of default domain or identical domain")
+7 -1
View File
@@ -1229,7 +1229,13 @@ func (user *SUser) PerformResetCredentials(
) (jsonutils.JSONObject, error) {
err := CredentialManager.DeleteAll(ctx, userCred, user.Id, input.Type)
if err != nil {
return nil, errors.Wrap(err, "DeleteAll")
return nil, errors.Wrapf(err, "DeleteAll %s", input.Type)
}
if input.Type == api.TOTP_TYPE {
err := CredentialManager.DeleteAll(ctx, userCred, user.Id, api.RECOVERY_SECRETS_TYPE)
if err != nil {
return nil, errors.Wrapf(err, "DeleteAll %s", api.RECOVERY_SECRETS_TYPE)
}
}
return nil, nil
}