mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
fix: Add 'scope=system' and 'system' for Caches when querying from Keystone.
1. Query 'scope=system' and 'system=true' is neccessary when fetching all users or groups from Keystone. Without these, users and groups in other domains (non-caller domains), as well as system-level users, cannot be detected. 2. Query 'scope=system' is neccessary when fetching all project from Keystone.
This commit is contained in:
@@ -186,8 +186,13 @@ func (manager *STenantCacheManager) fetchTenantFromKeystone(ctx context.Context,
|
||||
log.Debugf("fetch empty tenant!!!!\n%s", debug.Stack())
|
||||
return nil, fmt.Errorf("Empty idStr")
|
||||
}
|
||||
|
||||
// It is to query all domain's project.
|
||||
query := jsonutils.NewDict()
|
||||
query.Set("scope", jsonutils.NewString("system"))
|
||||
|
||||
s := auth.GetAdminSession(ctx, consts.GetRegion(), "v1")
|
||||
tenant, err := modules.Projects.GetById(s, idStr, nil)
|
||||
tenant, err := modules.Projects.GetById(s, idStr, query)
|
||||
if err != nil {
|
||||
if je, ok := err.(*httputils.JSONClientError); ok && je.Code == 404 {
|
||||
return nil, sql.ErrNoRows
|
||||
|
||||
@@ -20,6 +20,7 @@ import (
|
||||
"fmt"
|
||||
"runtime/debug"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/sqlchemy"
|
||||
@@ -111,11 +112,17 @@ func (manager *SUserCacheManager) FetchUserFromKeystone(ctx context.Context, idS
|
||||
log.Debugf("fetch empty user!!!!\n%s", debug.Stack())
|
||||
return nil, fmt.Errorf("Empty idStr")
|
||||
}
|
||||
|
||||
// It's to query the full list of users(contains other domain's ones and system ones)
|
||||
query := jsonutils.NewDict()
|
||||
query.Set("scope", jsonutils.NewString("system"))
|
||||
query.Set("system", jsonutils.JSONTrue)
|
||||
|
||||
s := auth.GetAdminSession(ctx, consts.GetRegion(), "v1")
|
||||
user, err := modules.UsersV3.GetById(s, idStr, nil)
|
||||
user, err := modules.UsersV3.GetById(s, idStr, query)
|
||||
if err != nil {
|
||||
if je, ok := err.(*httputils.JSONClientError); ok && je.Code == 404 {
|
||||
user, err = modules.UsersV3.GetByName(s, idStr, nil)
|
||||
user, err = modules.UsersV3.GetByName(s, idStr, query)
|
||||
if je, ok := err.(*httputils.JSONClientError); ok && je.Code == 404 {
|
||||
return nil, sql.ErrNoRows
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user