fix: Add 'scope=system' and 'system' for Caches when querying from Keystone.

1. Query 'scope=system' and 'system=true' is neccessary when fetching all users
   or groups from Keystone.
   Without these, users and groups in other domains (non-caller domains),
   as well as system-level users, cannot be detected.
2. Query 'scope=system' is neccessary when fetching all project from Keystone.
This commit is contained in:
Rain
2020-03-06 17:10:58 +08:00
parent 6fe428832a
commit f8642421de
5 changed files with 34 additions and 7 deletions
+6 -1
View File
@@ -186,8 +186,13 @@ func (manager *STenantCacheManager) fetchTenantFromKeystone(ctx context.Context,
log.Debugf("fetch empty tenant!!!!\n%s", debug.Stack())
return nil, fmt.Errorf("Empty idStr")
}
// It is to query all domain's project.
query := jsonutils.NewDict()
query.Set("scope", jsonutils.NewString("system"))
s := auth.GetAdminSession(ctx, consts.GetRegion(), "v1")
tenant, err := modules.Projects.GetById(s, idStr, nil)
tenant, err := modules.Projects.GetById(s, idStr, query)
if err != nil {
if je, ok := err.(*httputils.JSONClientError); ok && je.Code == 404 {
return nil, sql.ErrNoRows
+9 -2
View File
@@ -20,6 +20,7 @@ import (
"fmt"
"runtime/debug"
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/sqlchemy"
@@ -111,11 +112,17 @@ func (manager *SUserCacheManager) FetchUserFromKeystone(ctx context.Context, idS
log.Debugf("fetch empty user!!!!\n%s", debug.Stack())
return nil, fmt.Errorf("Empty idStr")
}
// It's to query the full list of users(contains other domain's ones and system ones)
query := jsonutils.NewDict()
query.Set("scope", jsonutils.NewString("system"))
query.Set("system", jsonutils.JSONTrue)
s := auth.GetAdminSession(ctx, consts.GetRegion(), "v1")
user, err := modules.UsersV3.GetById(s, idStr, nil)
user, err := modules.UsersV3.GetById(s, idStr, query)
if err != nil {
if je, ok := err.(*httputils.JSONClientError); ok && je.Code == 404 {
user, err = modules.UsersV3.GetByName(s, idStr, nil)
user, err = modules.UsersV3.GetByName(s, idStr, query)
if je, ok := err.(*httputils.JSONClientError); ok && je.Code == 404 {
return nil, sql.ErrNoRows
}