diff --git a/pkg/keystone/models/assignments.go b/pkg/keystone/models/assignments.go index 85fd362183..6e83b29064 100644 --- a/pkg/keystone/models/assignments.go +++ b/pkg/keystone/models/assignments.go @@ -420,9 +420,10 @@ func (manager *SAssignmentManager) projectRemoveAllUser(ctx context.Context, use if user.IsAdminUser() { return httperrors.NewForbiddenError("sysadmin is protected") } - if user.Id == userCred.GetUserId() { - return httperrors.NewForbiddenError("cannot remove current user from current project") - } + // allow remove current user from current project. user takes the consequence + // if user.Id == userCred.GetUserId() { + // return httperrors.NewForbiddenError("cannot remove current user from current project") + // } err := manager.batchRemove(user.Id, []string{api.AssignmentUserProject, api.AssignmentUserDomain}) if err != nil { return errors.Wrap(err, "manager.batchRemove") @@ -444,10 +445,11 @@ func (manager *SAssignmentManager) projectRemoveUser(ctx context.Context, userCr if project.IsAdminProject() && user.IsAdminUser() && role.IsSystemRole() { return httperrors.NewForbiddenError("sysadmin is protected") } + // allow remove current user from current project, user takes the consequence // prevent remove current user from current project - if project.Id == userCred.GetProjectId() && user.Id == userCred.GetUserId() { - return httperrors.NewForbiddenError("cannot remove current user from current project") - } + // if project.Id == userCred.GetProjectId() && user.Id == userCred.GetUserId() { + // return httperrors.NewForbiddenError("cannot remove current user from current project") + // } if project.DomainId != user.DomainId { // if project.DomainId != api.DEFAULT_DOMAIN_ID { // return httperrors.NewInputParameterError("join user into project of default domain or identical domain") diff --git a/pkg/keystone/models/users.go b/pkg/keystone/models/users.go index 6a8ce4b41b..cf884055fb 100644 --- a/pkg/keystone/models/users.go +++ b/pkg/keystone/models/users.go @@ -1229,7 +1229,13 @@ func (user *SUser) PerformResetCredentials( ) (jsonutils.JSONObject, error) { err := CredentialManager.DeleteAll(ctx, userCred, user.Id, input.Type) if err != nil { - return nil, errors.Wrap(err, "DeleteAll") + return nil, errors.Wrapf(err, "DeleteAll %s", input.Type) + } + if input.Type == api.TOTP_TYPE { + err := CredentialManager.DeleteAll(ctx, userCred, user.Id, api.RECOVERY_SECRETS_TYPE) + if err != nil { + return nil, errors.Wrapf(err, "DeleteAll %s", api.RECOVERY_SECRETS_TYPE) + } } return nil, nil }