mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
Merge pull request #488 in YUNIONIO/onecloud from ~QIUJIAN/onecloud:hotfix/qj-rbac-deny-any-create to release/2.3.0
* commit '1a53bba41f5172f65a051d6050a4aa0f7225c8b0': 修正:1. rbac禁止所有的创建 2. 增加rbac_debug日志选项
This commit is contained in:
@@ -44,6 +44,8 @@ func InitAuth(options *Options, authComplete auth.AuthCompletedCallback) {
|
||||
|
||||
if options.EnableRbac {
|
||||
policy.EnableGlobalRbac(time.Duration(options.RbacPolicySyncPeriodSeconds)*time.Second,
|
||||
time.Duration(options.RbacPolicySyncFailedRetrySeconds)*time.Second)
|
||||
time.Duration(options.RbacPolicySyncFailedRetrySeconds)*time.Second,
|
||||
options.RbacDebug,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -2,6 +2,7 @@ package consts
|
||||
|
||||
var (
|
||||
globalsRbacEnabled = false
|
||||
globalsRbacDebug = false
|
||||
)
|
||||
|
||||
func EnableRbac() {
|
||||
@@ -11,3 +12,11 @@ func EnableRbac() {
|
||||
func IsRbacEnabled() bool {
|
||||
return globalsRbacEnabled
|
||||
}
|
||||
|
||||
func EnableRbacDebug() {
|
||||
globalsRbacDebug = true
|
||||
}
|
||||
|
||||
func IsRbacDebug() bool {
|
||||
return globalsRbacDebug
|
||||
}
|
||||
|
||||
@@ -61,7 +61,7 @@ func isClassActionRbacAllowed(manager IModelManager, userCred mcclient.TokenCred
|
||||
return true
|
||||
}
|
||||
}
|
||||
result := policy.PolicyManager.Allow(false, userCred, consts.GetServiceType(),
|
||||
result := policy.PolicyManager.Allow(true, userCred, consts.GetServiceType(),
|
||||
manager.KeywordPlural(), action, extra...)
|
||||
return result == rbacutils.Allow
|
||||
}
|
||||
|
||||
@@ -41,6 +41,7 @@ type Options struct {
|
||||
SslKeyfile string `help:"ssl certification key file"`
|
||||
|
||||
EnableRbac bool `help:"Switch on Role-based Access Control" default:"false"`
|
||||
RbacDebug bool `help:"turn on rbac debug log" default:"false"`
|
||||
RbacPolicySyncPeriodSeconds int `help:"policy sync interval in seconds, default 15 minutes" default:"900"`
|
||||
RbacPolicySyncFailedRetrySeconds int `help:"seconds to wait after a failed sync, default 30 seconds" default:"30"`
|
||||
|
||||
|
||||
@@ -5,9 +5,12 @@ import (
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
)
|
||||
|
||||
func EnableGlobalRbac(refreshInterval time.Duration, retryInterval time.Duration) {
|
||||
func EnableGlobalRbac(refreshInterval time.Duration, retryInterval time.Duration, debug bool) {
|
||||
if !consts.IsRbacEnabled() {
|
||||
consts.EnableRbac()
|
||||
if debug {
|
||||
consts.EnableRbacDebug()
|
||||
}
|
||||
PolicyManager.start(refreshInterval, retryInterval)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -154,6 +154,9 @@ func (manager *SPolicyManager) Allow(isAdmin bool, userCred mcclient.TokenCreden
|
||||
currentPriv = result
|
||||
}
|
||||
}
|
||||
if consts.IsRbacDebug() {
|
||||
log.Debugf("[RBAC: %v] %s %s %s %#v permission %s", isAdmin, service, resource, action, extra, currentPriv)
|
||||
}
|
||||
return currentPriv
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user