From 1a53bba41f5172f65a051d6050a4aa0f7225c8b0 Mon Sep 17 00:00:00 2001 From: Qiu Jian Date: Tue, 13 Nov 2018 16:57:36 +0800 Subject: [PATCH] =?UTF-8?q?=E4=BF=AE=E6=AD=A3=EF=BC=9A1.=20rbac=E7=A6=81?= =?UTF-8?q?=E6=AD=A2=E6=89=80=E6=9C=89=E7=9A=84=E5=88=9B=E5=BB=BA=202.=20?= =?UTF-8?q?=E5=A2=9E=E5=8A=A0rbac=5Fdebug=E6=97=A5=E5=BF=97=E9=80=89?= =?UTF-8?q?=E9=A1=B9?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- pkg/cloudcommon/auth.go | 4 +++- pkg/cloudcommon/consts/policy.go | 9 +++++++++ pkg/cloudcommon/db/rbac.go | 2 +- pkg/cloudcommon/options.go | 1 + pkg/cloudcommon/policy/global.go | 5 ++++- pkg/cloudcommon/policy/policy.go | 3 +++ 6 files changed, 21 insertions(+), 3 deletions(-) diff --git a/pkg/cloudcommon/auth.go b/pkg/cloudcommon/auth.go index 89772082d6..c9661ce977 100644 --- a/pkg/cloudcommon/auth.go +++ b/pkg/cloudcommon/auth.go @@ -44,6 +44,8 @@ func InitAuth(options *Options, authComplete auth.AuthCompletedCallback) { if options.EnableRbac { policy.EnableGlobalRbac(time.Duration(options.RbacPolicySyncPeriodSeconds)*time.Second, - time.Duration(options.RbacPolicySyncFailedRetrySeconds)*time.Second) + time.Duration(options.RbacPolicySyncFailedRetrySeconds)*time.Second, + options.RbacDebug, + ) } } diff --git a/pkg/cloudcommon/consts/policy.go b/pkg/cloudcommon/consts/policy.go index 1c3e20a93e..babeb225fa 100644 --- a/pkg/cloudcommon/consts/policy.go +++ b/pkg/cloudcommon/consts/policy.go @@ -2,6 +2,7 @@ package consts var ( globalsRbacEnabled = false + globalsRbacDebug = false ) func EnableRbac() { @@ -11,3 +12,11 @@ func EnableRbac() { func IsRbacEnabled() bool { return globalsRbacEnabled } + +func EnableRbacDebug() { + globalsRbacDebug = true +} + +func IsRbacDebug() bool { + return globalsRbacDebug +} diff --git a/pkg/cloudcommon/db/rbac.go b/pkg/cloudcommon/db/rbac.go index f19ce67698..91ae46f031 100644 --- a/pkg/cloudcommon/db/rbac.go +++ b/pkg/cloudcommon/db/rbac.go @@ -61,7 +61,7 @@ func isClassActionRbacAllowed(manager IModelManager, userCred mcclient.TokenCred return true } } - result := policy.PolicyManager.Allow(false, userCred, consts.GetServiceType(), + result := policy.PolicyManager.Allow(true, userCred, consts.GetServiceType(), manager.KeywordPlural(), action, extra...) return result == rbacutils.Allow } diff --git a/pkg/cloudcommon/options.go b/pkg/cloudcommon/options.go index 576695c671..0106a3e6c9 100644 --- a/pkg/cloudcommon/options.go +++ b/pkg/cloudcommon/options.go @@ -41,6 +41,7 @@ type Options struct { SslKeyfile string `help:"ssl certification key file"` EnableRbac bool `help:"Switch on Role-based Access Control" default:"false"` + RbacDebug bool `help:"turn on rbac debug log" default:"false"` RbacPolicySyncPeriodSeconds int `help:"policy sync interval in seconds, default 15 minutes" default:"900"` RbacPolicySyncFailedRetrySeconds int `help:"seconds to wait after a failed sync, default 30 seconds" default:"30"` diff --git a/pkg/cloudcommon/policy/global.go b/pkg/cloudcommon/policy/global.go index 266d8e2c2b..dda18cfa39 100644 --- a/pkg/cloudcommon/policy/global.go +++ b/pkg/cloudcommon/policy/global.go @@ -5,9 +5,12 @@ import ( "yunion.io/x/onecloud/pkg/cloudcommon/consts" ) -func EnableGlobalRbac(refreshInterval time.Duration, retryInterval time.Duration) { +func EnableGlobalRbac(refreshInterval time.Duration, retryInterval time.Duration, debug bool) { if !consts.IsRbacEnabled() { consts.EnableRbac() + if debug { + consts.EnableRbacDebug() + } PolicyManager.start(refreshInterval, retryInterval) } } diff --git a/pkg/cloudcommon/policy/policy.go b/pkg/cloudcommon/policy/policy.go index 8505a7555f..dd426e42b5 100644 --- a/pkg/cloudcommon/policy/policy.go +++ b/pkg/cloudcommon/policy/policy.go @@ -154,6 +154,9 @@ func (manager *SPolicyManager) Allow(isAdmin bool, userCred mcclient.TokenCreden currentPriv = result } } + if consts.IsRbacDebug() { + log.Debugf("[RBAC: %v] %s %s %s %#v permission %s", isAdmin, service, resource, action, extra, currentPriv) + } return currentPriv }