mirror of
https://github.com/galaxyproject/galaxy.git
synced 2026-09-24 16:30:27 +08:00
Allow admins to run tools on private datasets
This commit is contained in:
@@ -97,13 +97,13 @@ class DefaultToolAction(ToolAction):
|
||||
# fetch dataset details for this input from the database.
|
||||
if collection_info and collection_info.is_mapped_over(input_name):
|
||||
action_tuples = collection_info.map_over_action_tuples(input_name)
|
||||
if not trans.app.security_agent.can_access_datasets(current_user_roles, action_tuples):
|
||||
if not trans.user_is_admin and not trans.app.security_agent.can_access_datasets(current_user_roles, action_tuples):
|
||||
raise ItemAccessibilityException("User does not have permission to use a dataset provided for input.")
|
||||
for action, role_id in action_tuples:
|
||||
record_permission(action, role_id)
|
||||
else:
|
||||
if not trans.app.security_agent.can_access_dataset(current_user_roles, data.dataset):
|
||||
raise ItemAccessibilityException(f"User does not have permission to use a dataset ({data.id}) provided for input.")
|
||||
if not trans.user_is_admin and not trans.app.security_agent.can_access_dataset(current_user_roles, data.dataset):
|
||||
raise ItemAccessibilityException(f"User does not have permission to use dataset ({data.name}) provided for input.")
|
||||
permissions = trans.app.security_agent.get_permissions(data.dataset)
|
||||
for action, roles in permissions.items():
|
||||
for role in roles:
|
||||
@@ -169,7 +169,7 @@ class DefaultToolAction(ToolAction):
|
||||
collection = value.collection
|
||||
|
||||
action_tuples = collection.dataset_action_tuples
|
||||
if not trans.app.security_agent.can_access_datasets(current_user_roles, action_tuples):
|
||||
if not trans.user_is_admin and not trans.app.security_agent.can_access_datasets(current_user_roles, action_tuples):
|
||||
raise ItemAccessibilityException("User does not have permission to use a dataset provided for input.")
|
||||
for action, role_id in action_tuples:
|
||||
record_permission(action, role_id)
|
||||
|
||||
@@ -243,6 +243,7 @@ class MockTrans:
|
||||
self.sa_session = self.app.model.context
|
||||
self.model = app.model
|
||||
self._user_is_active = True
|
||||
self.user_is_admin = False
|
||||
|
||||
def get_user_is_active(self):
|
||||
# NOTE: the real user_is_active also checks whether activation is enabled in the config
|
||||
|
||||
Reference in New Issue
Block a user