diff --git a/pkg/cloudcommon/auth.go b/pkg/cloudcommon/auth.go index 89772082d6..c9661ce977 100644 --- a/pkg/cloudcommon/auth.go +++ b/pkg/cloudcommon/auth.go @@ -44,6 +44,8 @@ func InitAuth(options *Options, authComplete auth.AuthCompletedCallback) { if options.EnableRbac { policy.EnableGlobalRbac(time.Duration(options.RbacPolicySyncPeriodSeconds)*time.Second, - time.Duration(options.RbacPolicySyncFailedRetrySeconds)*time.Second) + time.Duration(options.RbacPolicySyncFailedRetrySeconds)*time.Second, + options.RbacDebug, + ) } } diff --git a/pkg/cloudcommon/consts/policy.go b/pkg/cloudcommon/consts/policy.go index 1c3e20a93e..babeb225fa 100644 --- a/pkg/cloudcommon/consts/policy.go +++ b/pkg/cloudcommon/consts/policy.go @@ -2,6 +2,7 @@ package consts var ( globalsRbacEnabled = false + globalsRbacDebug = false ) func EnableRbac() { @@ -11,3 +12,11 @@ func EnableRbac() { func IsRbacEnabled() bool { return globalsRbacEnabled } + +func EnableRbacDebug() { + globalsRbacDebug = true +} + +func IsRbacDebug() bool { + return globalsRbacDebug +} diff --git a/pkg/cloudcommon/db/rbac.go b/pkg/cloudcommon/db/rbac.go index f19ce67698..91ae46f031 100644 --- a/pkg/cloudcommon/db/rbac.go +++ b/pkg/cloudcommon/db/rbac.go @@ -61,7 +61,7 @@ func isClassActionRbacAllowed(manager IModelManager, userCred mcclient.TokenCred return true } } - result := policy.PolicyManager.Allow(false, userCred, consts.GetServiceType(), + result := policy.PolicyManager.Allow(true, userCred, consts.GetServiceType(), manager.KeywordPlural(), action, extra...) return result == rbacutils.Allow } diff --git a/pkg/cloudcommon/options.go b/pkg/cloudcommon/options.go index 576695c671..0106a3e6c9 100644 --- a/pkg/cloudcommon/options.go +++ b/pkg/cloudcommon/options.go @@ -41,6 +41,7 @@ type Options struct { SslKeyfile string `help:"ssl certification key file"` EnableRbac bool `help:"Switch on Role-based Access Control" default:"false"` + RbacDebug bool `help:"turn on rbac debug log" default:"false"` RbacPolicySyncPeriodSeconds int `help:"policy sync interval in seconds, default 15 minutes" default:"900"` RbacPolicySyncFailedRetrySeconds int `help:"seconds to wait after a failed sync, default 30 seconds" default:"30"` diff --git a/pkg/cloudcommon/policy/global.go b/pkg/cloudcommon/policy/global.go index 266d8e2c2b..dda18cfa39 100644 --- a/pkg/cloudcommon/policy/global.go +++ b/pkg/cloudcommon/policy/global.go @@ -5,9 +5,12 @@ import ( "yunion.io/x/onecloud/pkg/cloudcommon/consts" ) -func EnableGlobalRbac(refreshInterval time.Duration, retryInterval time.Duration) { +func EnableGlobalRbac(refreshInterval time.Duration, retryInterval time.Duration, debug bool) { if !consts.IsRbacEnabled() { consts.EnableRbac() + if debug { + consts.EnableRbacDebug() + } PolicyManager.start(refreshInterval, retryInterval) } } diff --git a/pkg/cloudcommon/policy/policy.go b/pkg/cloudcommon/policy/policy.go index 8505a7555f..dd426e42b5 100644 --- a/pkg/cloudcommon/policy/policy.go +++ b/pkg/cloudcommon/policy/policy.go @@ -154,6 +154,9 @@ func (manager *SPolicyManager) Allow(isAdmin bool, userCred mcclient.TokenCreden currentPriv = result } } + if consts.IsRbacDebug() { + log.Debugf("[RBAC: %v] %s %s %s %#v permission %s", isAdmin, service, resource, action, extra, currentPriv) + } return currentPriv }