mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
fix: 1. allow remove current user from current project. 2. reset (#15985)
recovery-questions when resetting MFA Co-authored-by: Qiu Jian <qiujian@yunionyun.com>
This commit is contained in:
@@ -420,9 +420,10 @@ func (manager *SAssignmentManager) projectRemoveAllUser(ctx context.Context, use
|
||||
if user.IsAdminUser() {
|
||||
return httperrors.NewForbiddenError("sysadmin is protected")
|
||||
}
|
||||
if user.Id == userCred.GetUserId() {
|
||||
return httperrors.NewForbiddenError("cannot remove current user from current project")
|
||||
}
|
||||
// allow remove current user from current project. user takes the consequence
|
||||
// if user.Id == userCred.GetUserId() {
|
||||
// return httperrors.NewForbiddenError("cannot remove current user from current project")
|
||||
// }
|
||||
err := manager.batchRemove(user.Id, []string{api.AssignmentUserProject, api.AssignmentUserDomain})
|
||||
if err != nil {
|
||||
return errors.Wrap(err, "manager.batchRemove")
|
||||
@@ -444,10 +445,11 @@ func (manager *SAssignmentManager) projectRemoveUser(ctx context.Context, userCr
|
||||
if project.IsAdminProject() && user.IsAdminUser() && role.IsSystemRole() {
|
||||
return httperrors.NewForbiddenError("sysadmin is protected")
|
||||
}
|
||||
// allow remove current user from current project, user takes the consequence
|
||||
// prevent remove current user from current project
|
||||
if project.Id == userCred.GetProjectId() && user.Id == userCred.GetUserId() {
|
||||
return httperrors.NewForbiddenError("cannot remove current user from current project")
|
||||
}
|
||||
// if project.Id == userCred.GetProjectId() && user.Id == userCred.GetUserId() {
|
||||
// return httperrors.NewForbiddenError("cannot remove current user from current project")
|
||||
// }
|
||||
if project.DomainId != user.DomainId {
|
||||
// if project.DomainId != api.DEFAULT_DOMAIN_ID {
|
||||
// return httperrors.NewInputParameterError("join user into project of default domain or identical domain")
|
||||
|
||||
@@ -1229,7 +1229,13 @@ func (user *SUser) PerformResetCredentials(
|
||||
) (jsonutils.JSONObject, error) {
|
||||
err := CredentialManager.DeleteAll(ctx, userCred, user.Id, input.Type)
|
||||
if err != nil {
|
||||
return nil, errors.Wrap(err, "DeleteAll")
|
||||
return nil, errors.Wrapf(err, "DeleteAll %s", input.Type)
|
||||
}
|
||||
if input.Type == api.TOTP_TYPE {
|
||||
err := CredentialManager.DeleteAll(ctx, userCred, user.Id, api.RECOVERY_SECRETS_TYPE)
|
||||
if err != nil {
|
||||
return nil, errors.Wrapf(err, "DeleteAll %s", api.RECOVERY_SECRETS_TYPE)
|
||||
}
|
||||
}
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user