mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
fix: allow turn off non-default domain projects
This commit is contained in:
@@ -83,4 +83,5 @@ func InitBaseAuth(options *common_options.BaseOptions) {
|
||||
options.RbacDebug,
|
||||
)
|
||||
}
|
||||
consts.SetNonDefaultDomainProjects(options.NonDefaultDomainProjects)
|
||||
}
|
||||
|
||||
@@ -24,6 +24,8 @@ var (
|
||||
globalServiceType = ""
|
||||
|
||||
tenantCacheExpireSeconds = 900
|
||||
|
||||
nonDefaultDomainProjects = false
|
||||
)
|
||||
|
||||
func SetRegion(region string) {
|
||||
@@ -49,3 +51,11 @@ func SetTenantCacheExpireSeconds(sec int) {
|
||||
func GetTenantCacheExpireSeconds() time.Duration {
|
||||
return time.Duration(tenantCacheExpireSeconds) * time.Second
|
||||
}
|
||||
|
||||
func SetNonDefaultDomainProjects(val bool) {
|
||||
nonDefaultDomainProjects = val
|
||||
}
|
||||
|
||||
func GetNonDefaultDomainProjects() bool {
|
||||
return nonDefaultDomainProjects
|
||||
}
|
||||
|
||||
@@ -20,6 +20,9 @@ import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/apis/identity"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
@@ -55,3 +58,10 @@ func (model *SDomainizedResourceBase) GetOwnerId() mcclient.IIdentityProvider {
|
||||
owner := SOwnerId{DomainId: model.DomainId}
|
||||
return &owner
|
||||
}
|
||||
|
||||
func ValidateCreateDomainId(domainId string) error {
|
||||
if !consts.GetNonDefaultDomainProjects() && domainId != identity.DEFAULT_DOMAIN_ID {
|
||||
return httperrors.NewForbiddenError("project in non-default domain is prohibited")
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -67,6 +67,8 @@ type BaseOptions struct {
|
||||
|
||||
CalculateQuotaUsageIntervalSeconds int `help:"interval to calculate quota usages, default 30 minutes" default:"900"`
|
||||
|
||||
NonDefaultDomainProjects bool `help:"allow projects in non-default domains" default:"false"`
|
||||
|
||||
structarg.BaseOptions
|
||||
}
|
||||
|
||||
|
||||
@@ -66,6 +66,30 @@ var (
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "vpcs",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "vpcs",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "wires",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "wires",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "schedtags",
|
||||
|
||||
Reference in New Issue
Block a user