fix: allow turn off non-default domain projects

This commit is contained in:
Qiu Jian
2019-07-27 15:52:02 +08:00
committed by Yousong Zhou
parent 8ddcfa99dd
commit fea61697e9
18 changed files with 96 additions and 15 deletions
+1
View File
@@ -83,4 +83,5 @@ func InitBaseAuth(options *common_options.BaseOptions) {
options.RbacDebug,
)
}
consts.SetNonDefaultDomainProjects(options.NonDefaultDomainProjects)
}
+10
View File
@@ -24,6 +24,8 @@ var (
globalServiceType = ""
tenantCacheExpireSeconds = 900
nonDefaultDomainProjects = false
)
func SetRegion(region string) {
@@ -49,3 +51,11 @@ func SetTenantCacheExpireSeconds(sec int) {
func GetTenantCacheExpireSeconds() time.Duration {
return time.Duration(tenantCacheExpireSeconds) * time.Second
}
func SetNonDefaultDomainProjects(val bool) {
nonDefaultDomainProjects = val
}
func GetNonDefaultDomainProjects() bool {
return nonDefaultDomainProjects
}
+10
View File
@@ -20,6 +20,9 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/apis/identity"
"yunion.io/x/onecloud/pkg/cloudcommon/consts"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
@@ -55,3 +58,10 @@ func (model *SDomainizedResourceBase) GetOwnerId() mcclient.IIdentityProvider {
owner := SOwnerId{DomainId: model.DomainId}
return &owner
}
func ValidateCreateDomainId(domainId string) error {
if !consts.GetNonDefaultDomainProjects() && domainId != identity.DEFAULT_DOMAIN_ID {
return httperrors.NewForbiddenError("project in non-default domain is prohibited")
}
return nil
}
+2
View File
@@ -67,6 +67,8 @@ type BaseOptions struct {
CalculateQuotaUsageIntervalSeconds int `help:"interval to calculate quota usages, default 30 minutes" default:"900"`
NonDefaultDomainProjects bool `help:"allow projects in non-default domains" default:"false"`
structarg.BaseOptions
}
+24
View File
@@ -66,6 +66,30 @@ var (
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "vpcs",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "vpcs",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "wires",
Action: PolicyActionList,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "wires",
Action: PolicyActionGet,
Result: rbacutils.Allow,
},
{
Service: "compute",
Resource: "schedtags",