Merge pull request #488 in YUNIONIO/onecloud from ~QIUJIAN/onecloud:hotfix/qj-rbac-deny-any-create to release/2.3.0

* commit '1a53bba41f5172f65a051d6050a4aa0f7225c8b0':
  修正:1. rbac禁止所有的创建 2. 增加rbac_debug日志选项
This commit is contained in:
邱剑
2018-11-13 22:01:18 +08:00
6 changed files with 21 additions and 3 deletions
+3 -1
View File
@@ -44,6 +44,8 @@ func InitAuth(options *Options, authComplete auth.AuthCompletedCallback) {
if options.EnableRbac {
policy.EnableGlobalRbac(time.Duration(options.RbacPolicySyncPeriodSeconds)*time.Second,
time.Duration(options.RbacPolicySyncFailedRetrySeconds)*time.Second)
time.Duration(options.RbacPolicySyncFailedRetrySeconds)*time.Second,
options.RbacDebug,
)
}
}
+9
View File
@@ -2,6 +2,7 @@ package consts
var (
globalsRbacEnabled = false
globalsRbacDebug = false
)
func EnableRbac() {
@@ -11,3 +12,11 @@ func EnableRbac() {
func IsRbacEnabled() bool {
return globalsRbacEnabled
}
func EnableRbacDebug() {
globalsRbacDebug = true
}
func IsRbacDebug() bool {
return globalsRbacDebug
}
+1 -1
View File
@@ -61,7 +61,7 @@ func isClassActionRbacAllowed(manager IModelManager, userCred mcclient.TokenCred
return true
}
}
result := policy.PolicyManager.Allow(false, userCred, consts.GetServiceType(),
result := policy.PolicyManager.Allow(true, userCred, consts.GetServiceType(),
manager.KeywordPlural(), action, extra...)
return result == rbacutils.Allow
}
+1
View File
@@ -41,6 +41,7 @@ type Options struct {
SslKeyfile string `help:"ssl certification key file"`
EnableRbac bool `help:"Switch on Role-based Access Control" default:"false"`
RbacDebug bool `help:"turn on rbac debug log" default:"false"`
RbacPolicySyncPeriodSeconds int `help:"policy sync interval in seconds, default 15 minutes" default:"900"`
RbacPolicySyncFailedRetrySeconds int `help:"seconds to wait after a failed sync, default 30 seconds" default:"30"`
+4 -1
View File
@@ -5,9 +5,12 @@ import (
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
)
func EnableGlobalRbac(refreshInterval time.Duration, retryInterval time.Duration) {
func EnableGlobalRbac(refreshInterval time.Duration, retryInterval time.Duration, debug bool) {
if !consts.IsRbacEnabled() {
consts.EnableRbac()
if debug {
consts.EnableRbacDebug()
}
PolicyManager.start(refreshInterval, retryInterval)
}
}
+3
View File
@@ -154,6 +154,9 @@ func (manager *SPolicyManager) Allow(isAdmin bool, userCred mcclient.TokenCreden
currentPriv = result
}
}
if consts.IsRbacDebug() {
log.Debugf("[RBAC: %v] %s %s %s %#v permission %s", isAdmin, service, resource, action, extra, currentPriv)
}
return currentPriv
}