mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
Merge pull request #913 in YUNIONIO/onecloud from ~QIUJIAN/onecloud:hotfix/qj-vmware-sync-skip-failed-host to release/2.5.0
* commit '06c9e6eb7e395019f61f6901b6fe8deab1f8e1e3': make fmt 修正:1. attach权限校验总是false 2. 增加climc user default_project_id相关方法 修正:1. allowattach rbac compatible 2. server insert iso fail 修正:1. vmware同步宿主机出错后应该尽力而为地同步所有能同步的机器 2. 保存镜像时,如果缺少osType报错
This commit is contained in:
@@ -8,11 +8,13 @@ import (
|
||||
|
||||
func init() {
|
||||
type UserListOptions struct {
|
||||
Domain string `help:"Filter by domain"`
|
||||
Name string `help:"Filter by name"`
|
||||
Limit int64 `help:"Limit, default 0, i.e. no limit"`
|
||||
Offset int64 `help:"Offset, default 0, i.e. no offset"`
|
||||
Search string `help:"Search by name"`
|
||||
Domain string `help:"Filter by domain"`
|
||||
Name string `help:"Filter by name"`
|
||||
Limit int64 `help:"Limit, default 0, i.e. no limit"`
|
||||
Offset int64 `help:"Offset, default 0, i.e. no offset"`
|
||||
Search string `help:"Search by name"`
|
||||
DefaultProject string `help:"Filter by default_project_id"`
|
||||
NoDefaultProject bool `help:"Filter users without valid default_project_id"`
|
||||
}
|
||||
R(&UserListOptions{}, "user-list", "List users", func(s *mcclient.ClientSession, args *UserListOptions) error {
|
||||
mod, err := modules.GetModule(s, "users")
|
||||
@@ -39,6 +41,15 @@ func init() {
|
||||
if args.Offset > 0 {
|
||||
params.Add(jsonutils.NewInt(args.Offset), "offset")
|
||||
}
|
||||
if len(args.DefaultProject) > 0 {
|
||||
projId, err := modules.Projects.GetId(s, args.DefaultProject, nil)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
params.Add(jsonutils.NewString(projId), "default_project_id")
|
||||
} else if args.NoDefaultProject {
|
||||
params.Add(jsonutils.NewString(""), "default_project_id__iempty")
|
||||
}
|
||||
result, err := mod.List(s, params)
|
||||
if err != nil {
|
||||
return err
|
||||
@@ -219,6 +230,8 @@ func init() {
|
||||
Mobile string `help:"Mobile"`
|
||||
Enabled bool `help:"Enabled"`
|
||||
Disabled bool `help:"Disabled"`
|
||||
|
||||
DefaultProject string `help:"Default project"`
|
||||
// Option []string `help:"User options"`
|
||||
}
|
||||
R(&UserUpdateOptions{}, "user-update", "Update a user", func(s *mcclient.ClientSession, args *UserUpdateOptions) error {
|
||||
@@ -258,6 +271,13 @@ func init() {
|
||||
} else if !args.Enabled && args.Disabled {
|
||||
params.Add(jsonutils.JSONFalse, "enabled")
|
||||
}
|
||||
if len(args.DefaultProject) > 0 {
|
||||
projId, err := modules.Projects.GetId(s, args.DefaultProject, nil)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
params.Add(jsonutils.NewString(projId), "default_project_id")
|
||||
}
|
||||
/*
|
||||
if len(args.Option) > 0 {
|
||||
uoptions := jsonutils.NewDict()
|
||||
|
||||
@@ -154,7 +154,14 @@ func (dispatcher *DBJointModelDispatcher) Get(ctx context.Context, id1 string, i
|
||||
}
|
||||
|
||||
func attachItems(dispatcher *DBJointModelDispatcher, master IStandaloneModel, slave IStandaloneModel, ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data jsonutils.JSONObject) (jsonutils.JSONObject, error) {
|
||||
if !dispatcher.JointModelManager().AllowAttach(ctx, userCred, master, slave) {
|
||||
var isAllow bool
|
||||
if consts.IsRbacEnabled() {
|
||||
isAllow = isObjectRbacAllowed(master.GetModelManager(), master, userCred, policy.PolicyActionPerform, "attach") &&
|
||||
isObjectRbacAllowed(slave.GetModelManager(), slave, userCred, policy.PolicyActionPerform, "attach")
|
||||
} else {
|
||||
isAllow = dispatcher.JointModelManager().AllowAttach(ctx, userCred, master, slave)
|
||||
}
|
||||
if !isAllow {
|
||||
return nil, httperrors.NewForbiddenError("Not allow to attach")
|
||||
}
|
||||
ownerProjId, err := fetchOwnerProjectId(ctx, dispatcher.JointModelManager(), userCred, data)
|
||||
|
||||
@@ -118,6 +118,7 @@ type IModel interface {
|
||||
PostDelete(ctx context.Context, userCred mcclient.TokenCredential)
|
||||
|
||||
GetOwnerProjectId() string
|
||||
IsSharable() bool
|
||||
|
||||
CustomizedGetDetailsBody(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject) (jsonutils.JSONObject, error)
|
||||
}
|
||||
@@ -186,7 +187,7 @@ type ISharableVirtualModelManager interface {
|
||||
|
||||
type ISharableVirtualModel interface {
|
||||
IVirtualModel
|
||||
IsSharable() bool
|
||||
// IsSharable() bool
|
||||
}
|
||||
|
||||
type IAdminSharableVirtualModelManager interface {
|
||||
|
||||
@@ -103,11 +103,11 @@ func (manager *SJointResourceBaseManager) FetchByIds(masterId string, slaveId st
|
||||
}
|
||||
|
||||
func (manager *SJointResourceBaseManager) AllowListDescendent(ctx context.Context, userCred mcclient.TokenCredential, model IStandaloneModel, query jsonutils.JSONObject) bool {
|
||||
return false
|
||||
return IsAdminAllowList(userCred, manager)
|
||||
}
|
||||
|
||||
func (manager *SJointResourceBaseManager) AllowAttach(ctx context.Context, userCred mcclient.TokenCredential, master IStandaloneModel, slave IStandaloneModel) bool {
|
||||
return false
|
||||
return IsAdminAllowCreate(userCred, manager)
|
||||
}
|
||||
|
||||
func JointModelExtra(jointModel IJointModel, extra *jsonutils.JSONDict) *jsonutils.JSONDict {
|
||||
|
||||
@@ -311,6 +311,10 @@ func (model *SModelBase) GetOwnerProjectId() string {
|
||||
return ""
|
||||
}
|
||||
|
||||
func (model *SModelBase) IsSharable() bool {
|
||||
return false
|
||||
}
|
||||
|
||||
func (model *SModelBase) CustomizedGetDetailsBody(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject) (jsonutils.JSONObject, error) {
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
@@ -92,7 +92,7 @@ func isObjectRbacAllowed(manager IModelManager, model IModel, userCred mcclient.
|
||||
|
||||
if len(ownerId) > 0 {
|
||||
objOwnerId := model.GetOwnerProjectId()
|
||||
if ownerId == objOwnerId {
|
||||
if ownerId == objOwnerId || model.IsSharable() {
|
||||
isOwner = true
|
||||
requireAdmin = false
|
||||
} else {
|
||||
|
||||
@@ -313,7 +313,7 @@ func (self *SKVMGuestDriver) RequestGuestCreateAllDisks(ctx context.Context, gue
|
||||
}
|
||||
|
||||
func (self *SKVMGuestDriver) RequestGuestHotAddIso(ctx context.Context, guest *models.SGuest, path string, task taskman.ITask) error {
|
||||
return guest.StartSyncstatus(ctx, task.GetUserCred(), task.GetTaskId())
|
||||
return guest.StartSyncTask(ctx, task.GetUserCred(), false, task.GetTaskId())
|
||||
}
|
||||
|
||||
func (self *SKVMGuestDriver) RequestRebuildRootDisk(ctx context.Context, guest *models.SGuest, task taskman.ITask) error {
|
||||
|
||||
@@ -104,7 +104,11 @@ func (self *SGuest) PerformSaveImage(ctx context.Context, userCred mcclient.Toke
|
||||
if notes, err := data.GetString("notes"); err != nil && len(notes) > 0 {
|
||||
properties.Add(jsonutils.NewString(notes), "notes")
|
||||
}
|
||||
properties.Add(jsonutils.NewString(self.OsType), "os_type")
|
||||
osType := self.OsType
|
||||
if len(osType) == 0 {
|
||||
osType = "Linux"
|
||||
}
|
||||
properties.Add(jsonutils.NewString(osType), "os_type")
|
||||
kwargs.Add(properties, "properties")
|
||||
kwargs.Add(jsonutils.NewBool(restart), "restart")
|
||||
|
||||
|
||||
@@ -36,7 +36,7 @@ func syncOnPremiseCloudProviderInfo(ctx context.Context, provider *models.SCloud
|
||||
log.Infof(notes)
|
||||
if result.IsError() {
|
||||
logSyncFailed(provider, task, msg)
|
||||
return
|
||||
// return
|
||||
}
|
||||
db.OpsLog.LogEvent(provider, db.ACT_SYNC_HOST_COMPLETE, msg, task.UserCred)
|
||||
logclient.AddActionLog(provider, getAction(task.Params), notes, task.UserCred, true)
|
||||
|
||||
@@ -160,7 +160,7 @@ func init() {
|
||||
|
||||
UsersV3 = UserManagerV3{NewIdentityV3Manager("user", "users",
|
||||
[]string{},
|
||||
[]string{"ID", "Name", "Domain_Id",
|
||||
[]string{"ID", "Name", "Domain_Id", "default_project_id",
|
||||
"Enabled", "Email", "Mobile"})}
|
||||
|
||||
register(&UsersV3)
|
||||
|
||||
Reference in New Issue
Block a user