diff --git a/lib/galaxy/security/__init__.py b/lib/galaxy/security/__init__.py index 1bd3127a24c..3932868341e 100644 --- a/lib/galaxy/security/__init__.py +++ b/lib/galaxy/security/__init__.py @@ -318,6 +318,26 @@ class GalaxyRBACAgent( RBACAgent ): for user in users: self.associate_components( user=user, role=sharing_role ) self.set_dataset_permission( dataset, { self.permitted_actions.DATASET_ACCESS : [ sharing_role ] } ) + def set_entity_user_associations( self, users=[], roles=[], groups=[], delete_existing_assocs=True ): + for user in users: + if delete_existing_assocs: + for a in user.non_private_roles + user.groups: + a.delete() + a.flush() + for role in roles: + self.associate_components( user=user, role=role ) + for group in groups: + self.associate_components( user=user, group=group ) + def set_entity_group_associations( self, groups=[], users=[], roles=[], delete_existing_assocs=True ): + for group in groups: + if delete_existing_assocs: + for a in group.roles + group.users: + a.delete() + a.flush() + for role in roles: + self.associate_components( group=group, role=role ) + for user in users: + self.associate_components( group=group, user=user ) def set_entity_role_associations( self, roles=[], users=[], groups=[], delete_existing_assocs=True ): for role in roles: if delete_existing_assocs: diff --git a/lib/galaxy/util/__init__.py b/lib/galaxy/util/__init__.py index 42416f54aeb..0e266ba2763 100644 --- a/lib/galaxy/util/__init__.py +++ b/lib/galaxy/util/__init__.py @@ -85,6 +85,7 @@ mapped_chars = { '>' :'__gt__', ']' :'__cb__', '{' :'__oc__', '}' :'__cc__', + '@' : '__at__' } def restore_text(text): @@ -273,6 +274,8 @@ def listify( item ): return [] elif isinstance( item, list ): return item + elif isinstance( item, str ) and item.count( ',' ): + return item.split( ',' ) else: return [ item ] diff --git a/lib/galaxy/web/controllers/admin.py b/lib/galaxy/web/controllers/admin.py index 12d10584438..23a6e90b87a 100644 --- a/lib/galaxy/web/controllers/admin.py +++ b/lib/galaxy/web/controllers/admin.py @@ -56,58 +56,74 @@ class Admin( BaseController ): params = util.Params( kwd ) msg = util.restore_text( params.get( 'msg', '' ) ) messagetype = params.get( 'messagetype', 'done' ) - users = trans.app.model.User.filter( trans.app.model.User.table.c.deleted==False ).order_by( trans.app.model.User.table.c.email ).all() - groups = trans.app.model.Group.query() \ - .filter( trans.app.model.Group.table.c.deleted==False ) \ - .order_by( trans.app.model.Group.table.c.name ) \ - .all() - return trans.fill_template( '/admin/dataset_security/role_create.mako', - users=users, - groups=groups, + if params.get( 'create_role_button', False ): + name = util.restore_text( params.name ) + description = util.restore_text( params.description ) + in_users = util.listify( params.get( 'in_users', [] ) ) + in_groups = util.listify( params.get( 'in_groups', [] ) ) + if not name or not description: + msg = "Enter a valid name and a description" + elif trans.app.model.Role.filter( trans.app.model.Role.table.c.name==name ).first(): + msg = "A role with that name already exists" + else: + # Create the role + role = trans.app.model.Role( name=name, description=description, type=trans.app.model.Role.types.ADMIN ) + role.flush() + # Create the UserRoleAssociations + for user in [ trans.app.model.User.get( x ) for x in in_users ]: + ura = trans.app.model.UserRoleAssociation( user, role ) + ura.flush() + # Create the GroupRoleAssociations + for group in [ trans.app.model.Group.get( x ) for x in in_groups ]: + gra = trans.app.model.GroupRoleAssociation( group, role ) + gra.flush() + msg = "Role '%s' has been created with %d associated users and %d associated groups" % ( role.name, len( in_users ), len( in_groups ) ) + trans.response.send_redirect( web.url_for( controller='admin', action='roles', msg=util.sanitize_text( msg ), messagetype='done' ) ) + trans.response.send_redirect( web.url_for( controller='admin', action='create_role', msg=util.sanitize_text( msg ), messagetype='error' ) ) + out_users = [] + for user in trans.app.model.User.filter( trans.app.model.User.table.c.deleted==False ).order_by( trans.app.model.User.table.c.email ).all(): + out_users.append( ( user.id, user.email ) ) + out_groups = [] + for group in trans.app.model.Group.filter( trans.app.model.Group.table.c.deleted==False ).order_by( trans.app.model.Group.table.c.name ).all(): + out_groups.append( ( group.id, group.name ) ) + return trans.fill_template( '/admin/dataset_security/role_create.mako', + in_users=[], + out_users=out_users, + in_groups=[], + out_groups=out_groups, msg=msg, messagetype=messagetype ) @web.expose @web.require_admin - def new_role( self, trans, **kwd ): - params = util.Params( kwd ) - name = util.restore_text( params.name ) - description = util.restore_text( params.description ) - if not name or not description: - msg = "Enter a valid name and a description" - elif trans.app.model.Role.filter( trans.app.model.Role.table.c.name==name ).first(): - msg = "A role with that name already exists" - else: - # Create the role - role = trans.app.model.Role( name=name, description=description, type=trans.app.model.Role.types.ADMIN ) - role.flush() - # Add the users - users = util.listify( params.users ) - for user_id in users: - user = trans.app.model.User.get( user_id ) - # Create the UserRoleAssociation - ura = trans.app.model.UserRoleAssociation( user, role ) - ura.flush() - # Add the groups - groups = util.listify( params.groups ) - for group_id in groups: - group = trans.app.model.Group.get( group_id ) - # Create the GroupRoleAssociation - gra = trans.app.model.GroupRoleAssociation( group, role ) - gra.flush() - msg = "The new role has been created with %s associated users and %s associated groups" % ( str( len( users ) ), str( len( groups ) ) ) - trans.response.send_redirect( web.url_for( controller='admin', action='roles', msg=msg, messagetype='done' ) ) - trans.response.send_redirect( web.url_for( controller='admin', action='create_role', msg=msg, messagetype='error' ) ) - @web.expose - @web.require_admin def role( self, trans, **kwd ): params = util.Params( kwd ) msg = util.restore_text( params.get( 'msg', '' ) ) messagetype = params.get( 'messagetype', 'done' ) role = trans.app.model.Role.get( int( params.role_id ) ) if params.get( 'role_members_edit_button', False ): - self.role_members_edit( trans, **kwd ) - if params.get( 'rename', False ): + in_users = [ trans.app.model.User.get( x ) for x in util.listify( params.in_users ) ] + for ura in role.users: + user = trans.app.model.User.get( ura.user_id ) + if user not in in_users: + # Delete DefaultUserPermissions for previously associated users that have been removed from the role + for dup in user.default_permissions: + if role == dup.role: + dup.delete() + dup.flush() + # Delete DefaultHistoryPermissions for previously associated users that have been removed from the role + for history in user.histories: + for dhp in history.default_permissions: + if role == dhp.role: + dhp.delete() + dhp.flush() + in_groups = [ trans.app.model.Group.get( x ) for x in util.listify( params.in_groups ) ] + trans.app.security_agent.set_entity_role_associations( roles=[ role ], users=in_users, groups=in_groups ) + role.refresh() + msg = "Role '%s' has been updated with %d associated users and %d associated groups" % ( role.name, len( in_users ), len( in_groups ) ) + trans.response.send_redirect( web.url_for( action='roles', msg=util.sanitize_text( msg ), messagetype=messagetype ) ) + elif params.get( 'rename', False ): if params.rename == 'submitted': + old_name = role.name new_name = util.restore_text( params.name ) new_description = util.restore_text( params.description ) if not new_name: @@ -120,8 +136,8 @@ class Admin( BaseController ): role.name = new_name role.description = new_description role.flush() - msg = 'The role has been renamed to %s' % new_name - return trans.response.send_redirect( web.url_for( action='roles', msg=msg, messagetype='done' ) ) + msg = "Role '%s' has been renamed to '%s'" % ( old_name, new_name ) + return trans.response.send_redirect( web.url_for( action='roles', msg=util.sanitize_text( msg ), messagetype='done' ) ) return trans.fill_template( '/admin/dataset_security/role_rename.mako', role=role, msg=msg, messagetype=messagetype ) in_users = [] out_users = [] @@ -132,7 +148,7 @@ class Admin( BaseController ): in_users.append( ( user.id, user.email ) ) else: out_users.append( ( user.id, user.email ) ) - for group in trans.app.model.Group.query().order_by( trans.app.model.Group.table.c.name ).all(): + for group in trans.app.model.Group.filter( trans.app.model.Group.table.c.deleted==False ).order_by( trans.app.model.Group.table.c.name ).all(): if group in [ x.group for x in role.groups ]: in_groups.append( ( group.id, group.name ) ) else: @@ -173,40 +189,13 @@ class Admin( BaseController ): messagetype=messagetype ) @web.expose @web.require_admin - def role_members_edit( self, trans, **kwd ): - params = util.Params( kwd ) - msg = util.restore_text( params.get( 'msg', '' ) ) - messagetype = params.get( 'messagetype', 'done' ) - role = trans.app.model.Role.get( int( params.role_id ) ) - in_users = [ trans.app.model.User.get( x ) for x in util.listify( params.in_users ) ] - for ura in role.users: - user = trans.app.model.User.get( ura.user_id ) - if user not in in_users: - # Delete DefaultUserPermissions for previously associated users that have been removed from the role - for dup in user.default_permissions: - if role == dup.role: - dup.delete() - dup.flush() - # Delete DefaultHistoryPermissions for previously associated users that have been removed from the role - for history in user.histories: - for dhp in history.default_permissions: - if role == dhp.role: - dhp.delete() - dhp.flush() - in_groups = [ trans.app.model.Group.get( x ) for x in util.listify( params.in_groups ) ] - trans.app.security_agent.set_entity_role_associations( roles=[ role ], users=in_users, groups=in_groups ) - role.refresh() - msg = "The role has been updated with %s associated users and %s associated groups" % ( str( len( in_users ) ), str( len( in_groups ) ) ) - trans.response.send_redirect( web.url_for( action='roles', msg=msg, messagetype=messagetype ) ) - @web.expose - @web.require_admin def mark_role_deleted( self, trans, **kwd ): params = util.Params( kwd ) role = trans.app.model.Role.get( int( params.role_id ) ) role.deleted = True role.flush() - msg = "The role has been marked as deleted." - trans.response.send_redirect( web.url_for( action='roles', msg=msg, messagetype='done' ) ) + msg = "Role '%s' has been marked as deleted." % role.name + trans.response.send_redirect( web.url_for( action='roles', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def deleted_roles( self, trans, **kwd ): @@ -239,8 +228,8 @@ class Admin( BaseController ): role = trans.app.model.Role.get( int( params.role_id ) ) role.deleted = False role.flush() - msg = "The role has been marked as not deleted." - trans.response.send_redirect( web.url_for( action='roles', msg=msg, messagetype='done' ) ) + msg = "Role '%s' has been marked as not deleted." % role.name + trans.response.send_redirect( web.url_for( action='roles', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def purge_role( self, trans, **kwd ): @@ -255,8 +244,8 @@ class Admin( BaseController ): role = trans.app.model.Role.get( int( params.role_id ) ) if not role.deleted: # We should never reach here, but just in case there is a bug somewhere... - msg = "The role has not been deleted, so it cannot be purged." - trans.response.send_redirect( web.url_for( action='roles', msg=msg, messagetype='error' ) ) + msg = "Role '%s' has not been deleted, so it cannot be purged." % role.name + trans.response.send_redirect( web.url_for( action='roles', msg=util.sanitize_text( msg ), messagetype='error' ) ) # Delete UserRoleAssociations for ura in role.users: user = trans.app.model.User.get( ura.user_id ) @@ -281,9 +270,9 @@ class Admin( BaseController ): for adra in role.actions: adra.delete() adra.flush() - msg = "The following have been purged from the database for the role: " + msg = "The following have been purged from the database for role '%s': " % role.name msg += "DefaultUserPermissions, DefaultHistoryPermissions, UserRoleAssociations, GroupRoleAssociations, ActionDatasetRoleAssociations." - trans.response.send_redirect( web.url_for( action='deleted_roles', msg=msg, messagetype='done' ) ) + trans.response.send_redirect( web.url_for( action='deleted_roles', msg=util.sanitize_text( msg ), messagetype='done' ) ) # Galaxy Group Stuff @web.expose @@ -315,12 +304,19 @@ class Admin( BaseController ): @web.require_admin def group( self, trans, **kwd ): params = util.Params( kwd ) - group_id = int( params.group_id ) msg = util.restore_text( params.get( 'msg', '' ) ) messagetype = params.get( 'messagetype', 'done' ) - group = trans.app.model.Group.get( group_id ) + group = trans.app.model.Group.get( int( params.group_id ) ) + if params.get( 'group_roles_users_edit_button', False ): + in_roles = [ trans.app.model.Role.get( x ) for x in util.listify( params.in_roles ) ] + in_users = [ trans.app.model.User.get( x ) for x in util.listify( params.in_users ) ] + trans.app.security_agent.set_entity_group_associations( groups=[ group ], roles=in_roles, users=in_users ) + group.refresh() + msg += "Group '%s' has been updated with %d associated roles and %d associated users" % ( group.name, len( in_roles ), len( in_users ) ) + trans.response.send_redirect( web.url_for( action='groups', msg=util.sanitize_text( msg ), messagetype=messagetype ) ) if params.get( 'rename', False ): if params.rename == 'submitted': + old_name = group.name new_name = util.restore_text( params.name ) if not new_name: msg = 'Enter a valid name' @@ -331,133 +327,74 @@ class Admin( BaseController ): else: group.name = new_name group.flush() - msg = 'The group has been renamed to %s' % new_name - return trans.response.send_redirect( web.url_for( action='groups', msg=msg, messagetype='done' ) ) + msg = "Group '%s' has been renamed to '%s'" % ( old_name, new_name ) + return trans.response.send_redirect( web.url_for( action='groups', msg=util.sanitize_text( msg ), messagetype='done' ) ) return trans.fill_template( '/admin/dataset_security/group_rename.mako', group=group, msg=msg, messagetype=messagetype ) - # Get the group members - users = [] - for uga in group.members: - users.append( trans.app.model.User.get( uga.user_id ) ) - roles = [] - for gra in group.roles: - roles.append( trans.app.model.Role.get( gra.role_id ) ) - msg += 'Group %s currently has %d members and is associated with %d roles' % ( group.name, len( users ), len( roles ) ) - return trans.fill_template( '/admin/dataset_security/group.mako', group=group, users=users, roles=roles, msg=msg, messagetype='done' ) + in_roles = [] + out_roles = [] + in_users = [] + out_users = [] + for role in trans.app.model.Role.filter( trans.app.model.Role.table.c.deleted==False ).order_by( trans.app.model.Role.table.c.name ).all(): + if role in [ x.role for x in group.roles ]: + in_roles.append( ( role.id, role.name ) ) + else: + out_roles.append( ( role.id, role.name ) ) + for user in trans.app.model.User.filter( trans.app.model.User.table.c.deleted==False ).order_by( trans.app.model.User.table.c.email ).all(): + if user in [ x.user for x in group.users ]: + in_users.append( ( user.id, user.email ) ) + else: + out_users.append( ( user.id, user.email ) ) + msg += 'Group %s is currently associated with %d roles and %d users' % ( group.name, len( in_roles ), len( in_users ) ) + return trans.fill_template( '/admin/dataset_security/group.mako', + group=group, + in_roles=in_roles, + out_roles=out_roles, + in_users=in_users, + out_users=out_users, + msg=msg, + messagetype=messagetype ) @web.expose @web.require_admin def create_group( self, trans, **kwd ): params = util.Params( kwd ) msg = util.restore_text( params.get( 'msg', '' ) ) messagetype = params.get( 'messagetype', 'done' ) - users = trans.app.model.User.filter( trans.app.model.User.table.c.deleted==False ) \ - .order_by( trans.app.model.User.table.c.email ).all() - roles = trans.app.model.Role.query() \ - .filter( and_( trans.app.model.Role.table.c.deleted == False, - trans.app.model.Role.table.c.type != trans.app.model.Role.types.PRIVATE ) ) \ - .order_by( trans.app.model.Role.table.c.name ).all() - return trans.fill_template( '/admin/dataset_security/group_create.mako', users=users, roles=roles, msg=msg, messagetype=messagetype ) - @web.expose - @web.require_admin - def new_group( self, trans, **kwd ): - params = util.Params( kwd ) - name = util.restore_text( params.name ) - if not name: - msg = "Enter a valid name" - elif trans.app.model.Group.filter( trans.app.model.Group.table.c.name==name ).first(): - msg = "A group with that name already exists" - else: - # Create the group - group = trans.app.model.Group( name ) - group.flush() - # Add the members - members = util.listify( params.members ) - for user_id in members: - user = trans.app.model.User.get( user_id ) - # Create the UserGroupAssociation - uga = trans.app.model.UserGroupAssociation( user, group ) - uga.flush() - # Add the roles - roles = util.listify( params.roles ) - for role_id in roles: - role = trans.app.model.Role.get( role_id ) - # Create the GroupRoleAssociation - gra = trans.app.model.GroupRoleAssociation( group, role ) - gra.flush() - msg = "The new group has been created with %s members and %s associated roles" % ( str( len( members ) ), str( len( roles ) ) ) - trans.response.send_redirect( web.url_for( controller='admin', action='groups', msg=msg, messagetype='done' ) ) - trans.response.send_redirect( web.url_for( controller='admin', action='create_group', msg=msg, messagetype='error' ) ) - @web.expose - @web.require_admin - def group_members_edit( self, trans, **kwd ): - params = util.Params( kwd ) - group = trans.app.model.Group.get( int( params.group_id ) ) - if 'group_members_edit_button' in kwd: - members = util.listify( params.members ) - # This is tricky since we have default association tables with - # records referring to members of this group. Because of this, - # we'll need to handle changes to the member list rather than the - # simpler approach of deleting all existing members and creating - # new records for user_ids in the received members param. - # First remove existing members that are not in the received members param - for uga in group.members: - if uga.user_id not in members: - # Delete the UserGroupAssociation - uga.delete() - uga.flush() - # Then add all new members to the group - for user_id in members: - user = trans.app.model.User.get( user_id ) - if user not in group.members: + if params.get( 'create_group_button', False ): + name = util.restore_text( params.name ) + in_users = util.listify( params.get( 'in_users', [] ) ) + in_roles = util.listify( params.get( 'in_roles', [] ) ) + if not name: + msg = "Enter a valid name" + elif trans.app.model.Group.filter( trans.app.model.Group.table.c.name==name ).first(): + msg = "A group with that name already exists" + else: + # Create the group + group = trans.app.model.Group( name=name ) + group.flush() + # Create the UserRoleAssociations + for user in [ trans.app.model.User.get( x ) for x in in_users ]: uga = trans.app.model.UserGroupAssociation( user, group ) uga.flush() - msg = "Group membership has been updated with a total of %d members" % len( members ) - trans.response.send_redirect( web.url_for( action='groups', msg=msg, messagetype='done' ) ) - members = [] - for uga in group.members: - members.append ( trans.app.model.User.get( uga.user_id ) ) - users = trans.app.model.User.filter( trans.app.model.User.table.c.deleted==False ).order_by( trans.app.model.User.table.c.email ).all() - msg = "%s currently has %s members" % ( group.name, len( members ) ) - return trans.fill_template( '/admin/dataset_security/group_members_edit.mako', group=group, members=members, users=users, msg=msg, messagetype='done' ) - @web.expose - @web.require_admin - def group_roles_edit( self, trans, **kwd ): - params = util.Params( kwd ) - group = trans.app.model.Group.get( int( params.group_id ) ) - if 'group_roles_edit_button' in kwd: - roles = util.listify( params.roles ) - # This is tricky since we have default association tables with - # records referring to roles of this group. Because of this, - # we'll need to handle changes to the role list rather than the - # simpler approach of deleting all existing roles and creating - # new records for role_ids in the received roles param. - # First remove existing roles that are not in the received roles param - for gra in group.roles: - if gra.role_id not in roles: - # Delete the GroupRoleAssociation - gra.delete() - gra.flush() - group.refresh() - # Then add all new roles to the group - for role_id in roles: - role = trans.app.model.Role.get( role_id ) - if role not in group.roles: + # Create the GroupRoleAssociations + for role in [ trans.app.model.Role.get( x ) for x in in_roles ]: gra = trans.app.model.GroupRoleAssociation( group, role ) gra.flush() - msg = "Group updated with a total of %s associated roles" % len( roles ) - trans.response.send_redirect( web.url_for( action='groups', msg=msg, messagetype='done' ) ) - roles=trans.app.model.Role.filter( and_( trans.app.model.Role.table.c.type != trans.app.model.Role.types.PRIVATE, - trans.app.model.Role.table.c.deleted == False ) ) \ - .order_by( trans.app.model.Role.table.c.name ).all() - group_roles = [] - for gra in group.roles: - group_roles.append ( trans.app.model.Role.get( gra.role_id ) ) - msg = "%s is currently associated with %s roles" % ( group.name, len( group_roles ) ) - return trans.fill_template( '/admin/dataset_security/group_roles_edit.mako', - group=group, - group_roles=group_roles, - roles=roles, + msg = "Group '%s' has been created with %d associated users and %d associated roles" % ( name, len( in_users ), len( in_roles ) ) + trans.response.send_redirect( web.url_for( controller='admin', action='groups', msg=util.sanitize_text( msg ), messagetype='done' ) ) + trans.response.send_redirect( web.url_for( controller='admin', action='create_group', msg=util.sanitize_text( msg ), messagetype='error' ) ) + out_users = [] + for user in trans.app.model.User.filter( trans.app.model.User.table.c.deleted==False ).order_by( trans.app.model.User.table.c.email ).all(): + out_users.append( ( user.id, user.email ) ) + out_roles = [] + for role in trans.app.model.Role.filter( trans.app.model.Role.table.c.deleted==False ).order_by( trans.app.model.Role.table.c.name ).all(): + out_roles.append( ( role.id, role.name ) ) + return trans.fill_template( '/admin/dataset_security/group_create.mako', + in_users=[], + out_users=out_users, + in_roles=[], + out_roles=out_roles, msg=msg, - messagetype='done' ) + messagetype=messagetype ) @web.expose @web.require_admin def mark_group_deleted( self, trans, **kwd ): @@ -465,8 +402,8 @@ class Admin( BaseController ): group = trans.app.model.Group.get( int( params.group_id ) ) group.deleted = True group.flush() - msg = "The group has been marked as deleted." - trans.response.send_redirect( web.url_for( action='groups', msg=msg, messagetype='done' ) ) + msg = "Group '%s' has been marked as deleted." % group.name + trans.response.send_redirect( web.url_for( action='groups', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def deleted_groups( self, trans, **kwd ): @@ -499,8 +436,8 @@ class Admin( BaseController ): group = trans.app.model.Group.get( int( params.group_id ) ) group.deleted = False group.flush() - msg = "The group has been marked as not deleted." - trans.response.send_redirect( web.url_for( action='groups', msg=msg, messagetype='done' ) ) + msg = "Group '%s' has been marked as not deleted." % group.name + trans.response.send_redirect( web.url_for( action='groups', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def purge_group( self, trans, **kwd ): @@ -510,8 +447,8 @@ class Admin( BaseController ): group = trans.app.model.Group.get( int( params.group_id ) ) if not group.deleted: # We should never reach here, but just in case there is a bug somewhere... - msg = "The group has not been deleted, so it cannot be purged." - trans.response.send_redirect( web.url_for( action='groups', msg=msg, messagetype='error' ) ) + msg = "Group '%s' has not been deleted, so it cannot be purged." % group.name + trans.response.send_redirect( web.url_for( action='groups', msg=util.sanitize_text( msg ), messagetype='error' ) ) # Delete UserGroupAssociations for uga in group.users: uga.delete() @@ -521,8 +458,8 @@ class Admin( BaseController ): gra.delete() gra.flush() # Delete the Group - msg = "The following have been purged from the database for the group: UserGroupAssociations, GroupRoleAssociations." - trans.response.send_redirect( web.url_for( action='deleted_groups', msg=msg, messagetype='done' ) ) + msg = "The following have been purged from the database for group '%s': UserGroupAssociations, GroupRoleAssociations." % group.name + trans.response.send_redirect( web.url_for( action='deleted_groups', msg=util.sanitize_text( msg ), messagetype='done' ) ) # Galaxy User Stuff @web.expose @@ -571,7 +508,7 @@ class Admin( BaseController ): if mail.close(): msg + ". However, subscribing to the mailing list has failed." messagetype = 'error' - trans.response.send_redirect( web.url_for( action='users', msg=msg, messagetype=messagetype ) ) + trans.response.send_redirect( web.url_for( action='users', msg=util.sanitize_text( msg ), messagetype=messagetype ) ) return trans.fill_template( '/admin/user/create.mako', msg=msg, messagetype=messagetype, @@ -605,7 +542,7 @@ class Admin( BaseController ): trans.log_event( "Admin reset password for user %s" % user.email ) msg = 'Password reset' messagetype = 'done' - trans.response.send_redirect( web.url_for( action='users', msg=msg, messagetype=messagetype ) ) + trans.response.send_redirect( web.url_for( action='users', msg=util.sanitize_text( msg ), messagetype=messagetype ) ) return trans.fill_template( '/admin/user/reset_password.mako', msg=msg, messagetype=messagetype, @@ -621,8 +558,8 @@ class Admin( BaseController ): user = trans.app.model.User.get( int( params.user_id ) ) user.deleted = True user.flush() - msg = "The user has been marked as deleted." - trans.response.send_redirect( web.url_for( action='users', msg=msg, messagetype='done' ) ) + msg = "User '%s' has been marked as deleted." % user.email + trans.response.send_redirect( web.url_for( action='users', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def undelete_user( self, trans, **kwd ): @@ -630,8 +567,8 @@ class Admin( BaseController ): user = trans.app.model.User.get( int( params.user_id ) ) user.deleted = False user.flush() - msg = "The user has been marked as not deleted." - trans.response.send_redirect( web.url_for( action='users', msg=msg, messagetype='done' ) ) + msg = "User '%s' has been marked as not deleted." % user.email + trans.response.send_redirect( web.url_for( action='users', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def purge_user( self, trans, **kwd ): @@ -652,8 +589,8 @@ class Admin( BaseController ): user = trans.app.model.User.get( int( params.user_id ) ) if not user.deleted: # We should never reach here, but just in case there is a bug somewhere... - msg = "The account has not been deleted, so it cannot be purged." - trans.response.send_redirect( web.url_for( action='users', msg=msg, messagetype='error' ) ) + msg = "User '%s' has not been deleted, so it cannot be purged." % user.email + trans.response.send_redirect( web.url_for( action='users', msg=util.sanitize_text( msg ), messagetype='error' ) ) private_role = trans.app.security_agent.get_private_user_role( user ) # Delete DefaultUserPermissions EXCEPT FOR THE PRIVATE ROLE for dup in user.default_permissions: @@ -691,8 +628,8 @@ class Admin( BaseController ): # Purge the user user.purged = True user.flush() - msg = "The user has been marked as purged." - trans.response.send_redirect( web.url_for( action='deleted_users', msg=msg, messagetype='done' ) ) + msg = "User '%s' has been marked as purged." % user.email + trans.response.send_redirect( web.url_for( action='deleted_users', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def deleted_users( self, trans, **kwd ): @@ -730,169 +667,125 @@ class Admin( BaseController ): @web.require_admin def user( self, trans, **kwd ): params = util.Params( kwd ) - user_id = int( params.user_id ) msg = util.restore_text( params.get( 'msg', '' ) ) messagetype = params.get( 'messagetype', 'done' ) - user = trans.app.model.User.get( user_id ) - # Get the groups to which the user belongs - groups = [] - for uga in user.groups: - groups.append( trans.app.model.Group.get( uga.group_id ) ) - # Get the roles associated with the user - roles = [] - for ura in user.roles: - roles.append( trans.app.model.Role.get( ura.role_id ) ) - msg += 'User %s is currently a member of %s groups and is associated with %s roles' % ( user.email, str( len( groups ) ), str( len( roles ) ) ) - return trans.fill_template( '/admin/dataset_security/user.mako', user=user, groups=groups, roles=roles, msg=msg, messagetype='done' ) - @web.expose - @web.require_admin - def user_groups_edit( self, trans, **kwd ): - params = util.Params( kwd ) user = trans.app.model.User.get( int( params.user_id ) ) - user_groups = [] - for uga in user.groups: - user_groups.append ( trans.app.model.Group.get( uga.group_id ) ) - groups = trans.app.model.Group.query() \ - .filter( trans.app.model.Group.table.c.deleted==False ) \ - .order_by( trans.app.model.Group.table.c.name ) \ - .all() - msg = 'User %s is currently a member of %d groups' % ( user.email, len( user_groups ) ) - return trans.fill_template( '/admin/dataset_security/user_groups_edit.mako', - user=user, - user_groups=user_groups, - groups=groups, - msg=msg, - messagetype='done' ) - @web.expose - @web.require_admin - def user_roles_edit( self, trans, **kwd ): - params = util.Params( kwd ) - user = trans.app.model.User.get( int( params.user_id ) ) - if 'user_roles_edit_button' in kwd: - roles = util.listify( params.roles ) - # This is tricky since we have default association tables with - # records referring to roles of this user. Because of this, - # we'll need to handle changes to the role list rather than the - # simpler approach of deleting all existing roles and creating - # new records for role_ids in the received roles param. - # First remove existing roles that are not in the received roles param - for ura in user.roles: - role = trans.app.model.Role.get( ura.role_id ) - if role.type != trans.app.model.Role.types.PRIVATE and ura.role_id not in roles: - # Delete the UserRoleAssociation - ura.delete() - ura.flush() + if params.get( 'user_roles_groups_edit_button', False ): + in_roles = [ trans.app.model.Role.get( x ) for x in util.listify( params.in_roles ) ] + in_groups = [ trans.app.model.Group.get( x ) for x in util.listify( params.in_groups ) ] + trans.app.security_agent.set_entity_user_associations( users=[ user ], roles=in_roles, groups=in_groups ) user.refresh() - # Then associate all new roles with the user - for role_id in roles: - role = trans.app.model.Role.get( role_id ) - if role not in user.roles: - ura = trans.app.model.UserRoleAssociation( user, role ) - ura.flush() - msg = "User updated with a total of %d associated roles" % len( roles ) - trans.response.send_redirect( web.url_for( action='users', msg=msg, messagetype='done' ) ) - roles=trans.app.model.Role.filter( trans.app.model.Role.table.c.type != trans.app.model.Role.types.PRIVATE ) \ - .order_by( trans.app.model.Role.table.c.name ).all() - user_roles = [] - for ura in user.roles: - user_roles.append ( trans.app.model.Role.get( ura.role_id ) ) - msg = "%s is currently associated with %s roles ( private roles are not displayed )" % ( user.email, len( user_roles ) ) - return trans.fill_template( '/admin/dataset_security/user_roles_edit.mako', user=user, user_roles=user_roles, roles=roles, msg=msg, messagetype='done' ) - @web.expose - @web.require_admin - def update_user_groups( self, trans, **kwd ): - params = util.Params( kwd ) - user_id = int( params.user_id ) - groups = util.listify( params.groups ) - user = trans.app.model.User.get( user_id ) - # First remove existing UserGroupAssociations that are not in the received groups param - for uga in user.groups: - if uga.group_id not in groups: - # Delete the UserGroupAssociation - uga.delete() - uga.flush() - # Then add all new groups to the user - for group_id in groups: - group = trans.app.model.Group.get( group_id ) - if group not in user.groups: - uga = trans.app.model.UserGroupAssociation( user, group ) - uga.flush() - msg = "User %s now belongs to %s groups" % ( user.email, len( groups ) ) - trans.response.send_redirect( web.url_for( action='users', msg=msg, messagetype='done' ) ) - + msg += "User '%s' has been updated with %d associated roles and %d associated groups (private roles are not displayed)" % \ + ( user.email, len( in_roles ), len( in_groups ) ) + trans.response.send_redirect( web.url_for( action='users', msg=util.sanitize_text( msg ), messagetype=messagetype ) ) + in_roles = [] + out_roles = [] + in_groups = [] + out_groups = [] + for role in trans.app.model.Role.filter( trans.app.model.Role.table.c.deleted==False ).order_by( trans.app.model.Role.table.c.name ).all(): + if role in [ x.role for x in user.roles ]: + in_roles.append( ( role.id, role.name ) ) + else: + out_roles.append( ( role.id, role.name ) ) + for group in trans.app.model.Group.filter( trans.app.model.Group.table.c.deleted==False ).order_by( trans.app.model.Group.table.c.name ).all(): + if group in [ x.group for x in user.groups ]: + in_groups.append( ( group.id, group.name ) ) + else: + out_groups.append( ( group.id, group.name ) ) + msg += "User '%s' is currently associated with %d roles and is a member of %d groups" % ( user.email, len( in_roles ), len( in_groups ) ) + return trans.fill_template( '/admin/dataset_security/user.mako', + user=user, + in_roles=in_roles, + out_roles=out_roles, + in_groups=in_groups, + out_groups=out_groups, + msg=msg, + messagetype=messagetype ) # Utility methods to enable removal of associations - redirects are key @web.expose @web.require_admin def remove_group_from_role( self, trans, **kwd ): params = util.Params( kwd ) group_id = int( params.group_id ) + group = trans.app.model.Group.get( group_id ) role_id = int( params.role_id ) + role = trans.app.model.Role.get( role_id ) gra = trans.app.model.GroupRoleAssociation.filter( and_( trans.app.model.GroupRoleAssociation.table.c.group_id==group_id, trans.app.model.GroupRoleAssociation.table.c.role_id==role_id ) ).first() gra.delete() gra.flush() - msg = "Group removed from role. " - trans.response.send_redirect( web.url_for( action='roles', msg=msg, messagetype='done' ) ) + msg = "Group '%s' removed from role '%s'" % ( group.name, role.name ) + trans.response.send_redirect( web.url_for( action='roles', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def remove_group_from_user( self, trans, **kwd ): params = util.Params( kwd ) group_id = int( params.group_id ) + group = trans.app.model.Group.get( group_id ) user_id = int( params.user_id ) + user = trans.app.model.User.get( user_id ) uga = trans.app.model.UserGroupAssociation.filter( and_( trans.app.model.UserGroupAssociation.table.c.group_id==group_id, trans.app.model.UserGroupAssociation.table.c.user_id==user_id ) ).first() uga.delete() uga.flush() - msg = "User removed from group. " - trans.response.send_redirect( web.url_for( action='user', msg=msg, messagetype='done' ) ) + msg = "Group '%s' removed from user '%s'" % ( group.name, user.email ) + trans.response.send_redirect( web.url_for( action='users', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def remove_role_from_group( self, trans, **kwd ): params = util.Params( kwd ) role_id = int( params.role_id ) + role = trans.app.model.Role.get( role_id ) group_id = int( params.group_id ) + group = trans.app.model.Group.get( group_id ) gra = trans.app.model.GroupRoleAssociation.filter( and_( trans.app.model.GroupRoleAssociation.table.c.role_id==role_id, trans.app.model.GroupRoleAssociation.table.c.group_id==group_id ) ).first() gra.delete() gra.flush() - msg = "Role removed from group. " - trans.response.send_redirect( web.url_for( action='group', group_id=group_id, msg=msg, messagetype='done' ) ) + msg = "Role '%s' removed from group '%s'" % ( role.name, group.name ) + trans.response.send_redirect( web.url_for( action='groups', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def remove_role_from_user( self, trans, **kwd ): params = util.Params( kwd ) user_id = int( params.user_id ) + user = trans.app.model.User.get( user_id ) role_id = int( params.role_id ) + role = trans.app.model.Role.get( role_id ) ura = trans.app.model.UserRoleAssociation.filter( and_( trans.app.model.UserRoleAssociation.table.c.user_id==user_id, trans.app.model.UserRoleAssociation.table.c.role_id==role_id ) ).first() ura.delete() ura.flush() - msg = "User removed from role. " - trans.response.send_redirect( web.url_for( action='roles', msg=msg, messagetype='done' ) ) + msg = "Role '%s' removed from user '%s'" % ( role.name, user.email ) + trans.response.send_redirect( web.url_for( action='users', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def remove_user_from_group( self, trans, **kwd ): params = util.Params( kwd ) user_id = int( params.user_id ) + user = trans.app.model.User.get( user_id ) group_id = int( params.group_id ) + group = trans.app.model.Group.get( group_id ) uga = trans.app.model.UserGroupAssociation.filter( and_( trans.app.model.UserGroupAssociation.table.c.user_id==user_id, trans.app.model.UserGroupAssociation.table.c.group_id==group_id ) ).first() uga.delete() uga.flush() - msg = "User removed from group. " - trans.response.send_redirect( web.url_for( action='group', group_id=group_id, msg=msg, messagetype='done' ) ) + msg = "User '%s' removed from group '%s'" % ( user.email, group.name ) + trans.response.send_redirect( web.url_for( action='groups', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def remove_user_from_role( self, trans, **kwd ): params = util.Params( kwd ) user_id = int( params.user_id ) + user = trans.app.model.User.get( user_id ) role_id = int( params.role_id ) + role = trans.app.model.Role.get( role_id ) ura = trans.app.model.UserRoleAssociation.filter( and_( trans.app.model.UserRoleAssociation.table.c.user_id==user_id, trans.app.model.UserRoleAssociation.table.c.role_id==role_id ) ).first() ura.delete() ura.flush() - msg = "User removed from role. " - trans.response.send_redirect( web.url_for( action='user', user_id=user_id, msg=msg, messagetype='done' ) ) + msg = "User '%s' removed from role '%s'" % ( user.email, role.name ) + trans.response.send_redirect( web.url_for( action='roles', msg=util.sanitize_text( msg ), messagetype='done' ) ) # Galaxy Library Stuff @web.expose @@ -924,10 +817,10 @@ class Admin( BaseController ): action = 'delete' else: msg = 'Invalid action attempted on library' - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='error' ) ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='error' ) ) if not id and not action == 'new': msg = "You must specify a library to %s." % action - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='error' ) ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='error' ) ) if not action == 'new': library = trans.app.model.Library.get( int( id ) ) if action == 'new': @@ -939,10 +832,11 @@ class Admin( BaseController ): library.root_folder = root_folder library.flush() msg = 'The new library named %s has been created' % library.name - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='done' ) ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='done' ) ) return trans.fill_template( '/admin/library/new_library.mako', msg=msg, messagetype=messagetype ) elif action == 'rename': if params.rename == 'submitted': + old_name = library.name new_name = util.restore_text( params.name ) new_description = util.restore_text( params.description ) if not new_name: @@ -956,8 +850,8 @@ class Admin( BaseController ): library.name = new_name library.description = new_description library.flush() - msg = 'The library has been renamed to %s' % new_name - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='done' ) ) + msg = "Library '%s' has been renamed to '%s'" % ( old_name, new_name ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='done' ) ) return trans.fill_template( '/admin/library/rename_library.mako', library=library, msg=msg, messagetype=messagetype ) elif action == 'delete': def delete_folder( library_folder ): @@ -975,8 +869,8 @@ class Admin( BaseController ): delete_folder( library.root_folder ) library.deleted = True library.flush() - msg = 'The library and all of its contents have been marked deleted' - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='done' ) ) + msg = "Library '%s' and all of its contents have been marked deleted" % library.name + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def deleted_libraries( self, trans, **kwd ): @@ -1007,8 +901,8 @@ class Admin( BaseController ): undelete_folder( library.root_folder ) library.deleted = False library.flush() - msg = "The library and all of its contents have been marked not deleted" - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='done' ) ) + msg = "Library '%s' and all of its contents have been marked not deleted" % library.name + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def purge_library( self, trans, **kwd ): @@ -1034,8 +928,8 @@ class Admin( BaseController ): purge_folder( library.root_folder ) library.purged = True library.flush() - msg = "The library and all of its contents have been purged, datasets will be removed from disk via the cleanup_datasets script" - return trans.response.send_redirect( web.url_for( action='deleted_libraries', msg=msg, messagetype='done' ) ) + msg = "Library '%s' and all of its contents have been purged, datasets will be removed from disk via the cleanup_datasets script" % library.name + return trans.response.send_redirect( web.url_for( action='deleted_libraries', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def folder( self, trans, id, **kwd ): @@ -1050,11 +944,11 @@ class Admin( BaseController ): action = 'delete' else: msg = "Invalid action attempted on folder." - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='error' ) ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='error' ) ) folder = trans.app.model.LibraryFolder.get( id ) if not folder: msg = "Invalid folder specified, id: %s" % str( id ) - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='error' ) ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='error' ) ) if action == 'new': if params.new == 'submitted': new_folder = trans.app.model.LibraryFolder( name=util.restore_text( params.name ), @@ -1065,11 +959,12 @@ class Admin( BaseController ): new_folder.genome_build = util.dbnames.default_value folder.add_folder( new_folder ) new_folder.flush() - msg = 'The new folder named %s has been added to this library' % new_folder.name - return trans.response.send_redirect( web.url_for( action='folder', id=new_folder.id, msg=msg, messagetype='done' ) ) + msg = "New folder named '%s' has been added to this library" % new_folder.name + return trans.response.send_redirect( web.url_for( action='folder', id=new_folder.id, msg=util.sanitize_text( msg ), messagetype='done' ) ) return trans.fill_template( '/admin/library/new_folder.mako', folder=folder, msg=msg, messagetype=messagetype ) elif action == 'rename': if params.rename == 'submitted': + old_name = folder.name new_name = util.restore_text( params.name ) new_description = util.restore_text( params.description ) if not new_name: @@ -1079,8 +974,8 @@ class Admin( BaseController ): folder.name = new_name folder.description = new_description folder.flush() - msg = 'The folder has been renamed to %s' % new_name - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='done' ) ) + msg = "Folder '%s'has been renamed to '%s'" % ( old_name, new_name ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='done' ) ) return trans.fill_template( '/admin/library/rename_folder.mako', folder=folder, msg=msg, messagetype=messagetype ) elif action == 'delete': def delete_folder( folder ): @@ -1093,8 +988,8 @@ class Admin( BaseController ): folder.deleted = True folder.flush() delete_folder( folder ) - msg = 'The folder %s and all of its contents have been marked deleted' % folder.name - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='done' ) ) + msg = "Folder '%s' and all of its contents have been marked deleted" % folder.name + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='done' ) ) @web.expose @web.require_admin def dataset( self, trans, id=None, name="Unnamed", info='no info', extension=None, folder_id=None, dbkey=None, **kwd ): @@ -1189,7 +1084,7 @@ class Admin( BaseController ): msg = 'Select a file, enter a URL or Text, or select a server directory.' else: msg = 'Select a file, enter a URL or enter Text.' - trans.response.send_redirect( web.url_for( action='dataset', folder_id=folder_id, msg=msg, messagetype='done' ) ) + trans.response.send_redirect( web.url_for( action='dataset', folder_id=folder_id, msg=util.sanitize_text( msg ), messagetype='done' ) ) space_to_tab = params.get( 'space_to_tab', False ) if space_to_tab and space_to_tab not in [ "None", None ]: space_to_tab = True @@ -1269,10 +1164,16 @@ class Admin( BaseController ): total_added = len( created_lfda_ids.split( ',' ) ) msg = "%i new datasets added to the library ( each is selected below ). " % total_added msg += "Click the Go button at the bottom of this page to edit the permissions on these datasets if necessary." - trans.response.send_redirect( web.url_for( action='library_browser', created_lfda_ids=created_lfda_ids, msg=msg, messagetype='done' ) ) + trans.response.send_redirect( web.url_for( action='library_browser', + created_lfda_ids=created_lfda_ids, + msg=util.sanitize_text( msg ), + messagetype='done' ) ) else: msg = "Upload failed" - trans.response.send_redirect( web.url_for( action='library_browser', created_lfda_ids=created_lfda_ids, msg=msg, messagetype='error' ) ) + trans.response.send_redirect( web.url_for( action='library_browser', + created_lfda_ids=created_lfda_ids, + msg=util.sanitize_text( msg ), + messagetype='error' ) ) # No dataset(s) specified, display upload form elif not id: @@ -1304,7 +1205,7 @@ class Admin( BaseController ): lda = trans.app.model.LibraryFolderDatasetAssociation.get( id ) if not lda: msg = "Invalid dataset specified, id: %s" %str( id ) - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='error' ) ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='error' ) ) # Copied from edit attributes for 'regular' datasets with some additions p = util.Params(kwd, safe=False) @@ -1339,7 +1240,7 @@ class Admin( BaseController ): lda.datatype.after_edit( lda ) trans.app.model.flush() msg = 'Attributes updated for dataset %s' % lda.name - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='done' ) ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='done' ) ) elif p.detect: # The user clicked the Auto-detect button on the 'Edit Attributes' form for name, spec in lda.datatype.metadata_spec.items(): @@ -1351,13 +1252,13 @@ class Admin( BaseController ): lda.datatype.after_edit( lda ) trans.app.model.flush() msg = 'Attributes updated for dataset %s' % lda.name - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='done' ) ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='done' ) ) elif p.delete: # The user selected the "Remove this dataset from the library" pop-up menu option lda.deleted = True lda.flush() msg = 'Dataset %s has been removed from this library' % lda.name - trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='done' ) ) + trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='done' ) ) lda.datatype.before_edit( lda ) if "dbkey" in lda.datatype.metadata_spec and not lda.metadata.dbkey: # Copy dbkey into metadata, for backwards compatability @@ -1383,11 +1284,11 @@ class Admin( BaseController ): lfda = trans.app.model.LibraryFolderDatasetAssociation.get( id ) if lfda is None: msg = 'You specified an invalid dataset id: %s' %str( id ) - trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='error' ) ) + trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='error' ) ) lfdas.append( lfda ) if len( lfdas ) < 2: msg = 'You must specify at least two datasets on which to modify permissions, ids you sent: %s' % str( ids ) - trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='error' ) ) + trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='error' ) ) if 'update_roles' in kwd: #p = util.Params( kwd ) permissions = {} @@ -1398,7 +1299,7 @@ class Admin( BaseController ): trans.app.security_agent.set_all_dataset_permissions( lfda.dataset, permissions ) lfda.dataset.refresh() msg = 'Permissions and roles have been updated on %d datasets' % len( lfdas ) - trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='done' ) ) + trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='done' ) ) # Ensure that the permissions across all datasets are identical. Otherwise, we can't update together. tmp = [] for lfda in lfdas: @@ -1407,7 +1308,7 @@ class Admin( BaseController ): tmp.append( perms ) if len( tmp ) != 1: msg = 'The datasets you selected do not have identical permissions, so they can not be updated together' - trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='error' ) ) + trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='error' ) ) else: return trans.fill_template( "/admin/library/dataset.mako", dataset=lfdas ) @web.expose @@ -1417,7 +1318,7 @@ class Admin( BaseController ): folder = trans.app.model.LibraryFolder.get( folder_id ) except: msg = "Invalid folder id: %s" % str( folder_id ) - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='error' ) ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='error' ) ) params = util.Params( kwd ) msg = util.restore_text( params.get( 'msg', '' ) ) messagetype = params.get( 'messagetype', 'done' ) @@ -1426,7 +1327,7 @@ class Admin( BaseController ): history.refresh() if not history.active_datasets: msg = 'Your current history is empty' - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='error' ) ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='error' ) ) if params.get( 'add_dataset_from_history_button', False ): if not isinstance( ids, list ): if ids: @@ -1442,10 +1343,10 @@ class Admin( BaseController ): dataset_names.append( data.name ) else: msg = "The requested dataset id %s is invalid" % str( data_id ) - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='error' ) ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='error' ) ) if dataset_names: msg = "Added the following datasets to the library folder: %s" % ( ", ".join( dataset_names ) ) - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='done' ) ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='done' ) ) else: msg = 'Select at least one dataset from the list' messagetype = 'error' @@ -1459,7 +1360,7 @@ class Admin( BaseController ): dataset = trans.app.model.Dataset.get( lfda.dataset_id ) if not dataset: msg = 'Invalid id %s received for file downlaod' % str( id ) - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='error' ) ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='error' ) ) mime = trans.app.datatypes_registry.get_mimetype_by_extension( lfda.extension.lower() ) trans.response.set_content_type( mime ) fStat = os.stat( lfda.file_name ) @@ -1472,7 +1373,7 @@ class Admin( BaseController ): return open( lfda.file_name ) except: msg = 'This dataset contains no content' - return trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='error' ) ) + return trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='error' ) ) def check_gzip( self, temp_name ): """ @@ -1500,12 +1401,12 @@ class Admin( BaseController ): if params.get( 'action_on_datasets_button', False ): if not params.dataset_ids: msg = "At least one dataset must be selected for %s" % params.action - trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='error' ) ) + trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='error' ) ) dataset_ids = util.listify( params.dataset_ids ) if params.action == 'edit': trans.response.send_redirect( web.url_for( action='dataset', id=",".join( dataset_ids ), - msg=msg, + msg=util.sanitize_text( msg ), messagetype=messagetype ) ) elif params.action == 'delete': for id in dataset_ids: @@ -1513,12 +1414,12 @@ class Admin( BaseController ): lfda.deleted = True lfda.flush() msg = "The selected datasets have been removed from this library" - trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='done' ) ) + trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='done' ) ) else: msg = "Action %s is not yet implemented" % str( params.action ) - trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype='error' ) ) + trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype='error' ) ) else: - trans.response.send_redirect( web.url_for( action='library_browser', msg=msg, messagetype=messagetype ) ) + trans.response.send_redirect( web.url_for( action='library_browser', msg=util.sanitize_text( msg ), messagetype=messagetype ) ) @web.expose @web.require_admin def delete_dataset( self, trans, id=None, **kwd): @@ -1530,12 +1431,12 @@ class Admin( BaseController ): msg = "Dataset %s was deleted from library folder %s" % ( lfda.name, lfda.folder.name ) trans.response.send_redirect( web.url_for( action='folder', id=str( lfda.folder.id ), - msg=msg, + msg=util.sanitize_text( msg ), messagetype='done' ) ) msg = "You did not specify a dataset to delete." return trans.response.send_redirect( web.url_for( action='folder', id=str( lfda.folder.id ), - msg=msg, + msg=util.sanitize_text( msg ), messagetype='error' ) ) @web.expose diff --git a/templates/admin/dataset_security/deleted_groups.mako b/templates/admin/dataset_security/deleted_groups.mako index 1e0751e3dd2..422c80073bd 100644 --- a/templates/admin/dataset_security/deleted_groups.mako +++ b/templates/admin/dataset_security/deleted_groups.mako @@ -26,7 +26,7 @@ %if not anchored: diff --git a/templates/admin/dataset_security/deleted_roles.mako b/templates/admin/dataset_security/deleted_roles.mako index 64153e05e50..9975997d92e 100644 --- a/templates/admin/dataset_security/deleted_roles.mako +++ b/templates/admin/dataset_security/deleted_roles.mako @@ -9,7 +9,7 @@ %endif - ${role.description} + ${role.name}
Undelete @@ -78,10 +78,10 @@ groups = role_tuple[1] users = role_tuple[2] %> - %if render_quick_find and not role.description.upper().startswith( curr_anchor ): + %if render_quick_find and not role.name.upper().startswith( curr_anchor ): <% anchored = False %> %endif - %if render_quick_find and role.description.upper().startswith( curr_anchor ): + %if render_quick_find and role.name.upper().startswith( curr_anchor ): %if not anchored: ${render_row( role, groups, users, ctr, anchored, curr_anchor )} <% anchored = True %> @@ -90,7 +90,7 @@ %endif %elif render_quick_find: %for anchor in anchors[ anchor_loc: ]: - %if role.description.upper().startswith( anchor ): + %if role.name.upper().startswith( anchor ): %if not anchored: <% curr_anchor = anchor %> ${render_row( role, groups, users, ctr, anchored, curr_anchor )} diff --git a/templates/admin/dataset_security/group.mako b/templates/admin/dataset_security/group.mako index 64c809e0ee0..354bf7ea6c9 100644 --- a/templates/admin/dataset_security/group.mako +++ b/templates/admin/dataset_security/group.mako @@ -1,57 +1,83 @@ <%inherit file="/base.mako"/> <%namespace file="/message.mako" import="render_msg" /> -## Render a role -<%def name="render_role( group, role )"> -
  • - %if role and not role.type == trans.app.model.Role.types.PRIVATE: - ${role.description} - -
    - Remove role from group -
    - %elif role: - ${role.description} - %endif -
  • +<%def name="javascripts()"> + ${parent.javascripts()} + -## Render a user -<%def name="render_user( group, user )"> -
  • - ${user.email} - -
    - Remove user from group -
    -
  • +<%def name="render_select( name, options )"> + + + %if msg: ${render_msg( msg, messagetype )} %endif -%if len( users ) > 0 or len( roles ) > 0: - - - - - - - - - -
    Users associated with ${group.name}Roles associated with ${group.name}
    -
      - %for user in users: - ${render_user( group, user )} - %endfor -
    -
    -
      - %for role in roles: - ${render_role( group, role )} - %endfor -
    -
    -%endif +
    +
    Group '${group.name}'
    +
    +
    +
    +
    + Roles associated with '${group.name}'
    + ${render_select( "in_roles", in_roles )}
    + +
    +
    + Roles not associated with '${group.name}'
    + ${render_select( "out_roles", out_roles )}
    + +
    +
    +
    +
    + Users associated with '${group.name}'
    + ${render_select( "in_users", in_users )}
    + +
    +
    + Users not associated with '${group.name}'
    + ${render_select( "out_users", out_users )}
    + +
    +
    +
    + +
    +
    +
    +
    diff --git a/templates/admin/dataset_security/group_create.mako b/templates/admin/dataset_security/group_create.mako index 69e82acc749..a4ee022a2a9 100644 --- a/templates/admin/dataset_security/group_create.mako +++ b/templates/admin/dataset_security/group_create.mako @@ -1,115 +1,86 @@ <%inherit file="/base.mako"/> <%namespace file="/message.mako" import="render_msg" /> -## Render a user row -<%def name="render_user_row( user, ctr )"> - %if ctr % 2 == 1: - - %else: - - %endif - ${user.email} - +<%def name="javascripts()"> + ${parent.javascripts()} + -## Render a role row -<%def name="render_role_row( role, ctr, anchored, curr_anchor )"> - %if ctr % 2 == 1: - - %else: - - %endif - - %if not anchored: -
    top
    -  ${role.name}: ${role.description} - %else: -  ${role.name}: ${role.description} - %endif - - +<%def name="render_select( name, options )"> + -

    Create Group

    + %if msg: ${render_msg( msg, messagetype )} %endif -
    - - - <% - render_quick_find = len( users ) > 50 - ctr = 0 - %> - %if render_quick_find: - <% - anchors = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'] - anchor_loc = 0 - anchored = False - curr_anchor = 'A' - %> - - - - %endif - - - - - - ## Render users - - ## Render roles - - - -
    Name:
    - Jump to letter: - %for a in anchors: - | ${a} - %endfor -
    Select to add users to groupSelect to associate roles with group
    - - %for ctr, user in enumerate( users ): - ${render_user_row( user, ctr )} - %endfor -
    -
    - <% curr_anchor = 'A' %> - - %for ctr, role in enumerate( roles ): - %if render_quick_find and not role.description.upper().startswith( curr_anchor ): - <% anchored = False %> - %endif - %if render_quick_find and role.description.upper().startswith( curr_anchor ): - %if not anchored: - ${render_role_row( role, ctr, anchored, curr_anchor )} - <% anchored = True %> - %else: - ${render_role_row( role, ctr, anchored, curr_anchor )} - %endif - %elif render_quick_find: - %for anchor in anchors[ anchor_loc: ]: - %if role.description.upper().startswith( anchor ): - %if not anchored: - <% curr_anchor = anchor %> - ${render_role_row( role, ctr, anchored, curr_anchor )} - <% anchored = True %> - %else: - ${render_role_row( role, ctr, anchored, curr_anchor )} - %endif - <% - anchor_loc = anchors.index( anchor ) - break - %> - %endif - %endfor - %else: - ${render_role_row( role, ctr, True, '' )} - %endif - %endfor -
    -
    -
    +
    +
    Create Role
    +
    +
    +
    + Name: +
    +
    +
    + Groups associated with new role
    + ${render_select( "in_roles", in_roles )}
    + +
    +
    + Groups not associated with new role
    + ${render_select( "out_roles", out_roles )}
    + +
    +
    +
    +
    + Users associated with new role
    + ${render_select( "in_users", in_users )}
    + +
    +
    + Users not associated with new role
    + ${render_select( "out_users", out_users )}
    + +
    +
    +
    + +
    +
    +
    +
    diff --git a/templates/admin/dataset_security/group_members_edit.mako b/templates/admin/dataset_security/group_members_edit.mako deleted file mode 100644 index c10cbc1e9ee..00000000000 --- a/templates/admin/dataset_security/group_members_edit.mako +++ /dev/null @@ -1,101 +0,0 @@ -<%inherit file="/base.mako"/> -<%namespace file="/message.mako" import="render_msg" /> - -## Render a row -<%def name="render_row( user, ctr, anchored, curr_anchor, check )"> - %if ctr % 2 == 1: - - %else: - - %endif - - %if check: - ${user.email} - %else: - ${user.email} - %endif - %if not anchored: - -
    top
    - %endif - - - - -  - -%if msg: - ${render_msg( msg, messagetype )} -%endif - -%if len( users ) == 0: - There are no Galaxy users -%else: -
    - - - <% - render_quick_find = len( users ) > 50 - ctr = 0 - %> - %if render_quick_find: - <% - anchors = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'] - anchor_loc = 0 - anchored = False - curr_anchor = 'A' - %> - - - - %endif - - %for ctr, user in enumerate( users ): - <% check = False %> - %for member in members: - %if member.email == user.email: - <% - check = True - break - %> - %endif - %endfor - %if render_quick_find and not user.email.upper().startswith( curr_anchor ): - <% anchored = False %> - %endif - %if render_quick_find and user.email.upper().startswith( curr_anchor ): - %if not anchored: - ${render_row( user, ctr, anchored, curr_anchor, check )} - <% anchored = True %> - %else: - ${render_row( user, ctr, anchored, curr_anchor, check )} - %endif - %elif render_quick_find: - %for anchor in anchors[ anchor_loc: ]: - %if user.email.upper().startswith( anchor ): - %if not anchored: - <% curr_anchor = anchor %> - ${render_row( user, ctr, anchored, curr_anchor, check )} - <% anchored = True %> - %else: - ${render_row( user, ctr, anchored, curr_anchor, check )} - %endif - <% - anchor_loc = anchors.index( anchor ) - break - %> - %endif - %endfor - %else: - ${render_row( user, ctr, True, '', check )} - %endif - %endfor - -
    - Jump to letter: - %for a in anchors: - | ${a} - %endfor -
    Select to add user to ${group.name}
    -
    -%endif diff --git a/templates/admin/dataset_security/group_roles_edit.mako b/templates/admin/dataset_security/group_roles_edit.mako deleted file mode 100644 index c574715d1c3..00000000000 --- a/templates/admin/dataset_security/group_roles_edit.mako +++ /dev/null @@ -1,110 +0,0 @@ -<%inherit file="/base.mako"/> -<%namespace file="/message.mako" import="render_msg" /> - -## Render a row -<%def name="render_row( role, ctr, anchored, curr_anchor, check )"> - %if ctr % 2 == 1: - - %else: - - %endif - - %if check: - ${role.name} - %else: - ${role.name} - %endif - - ${role.description} - - ${role.type} - %if not anchored: - -
    top
    - %endif - - - - -  - -%if msg: - ${render_msg( msg, messagetype )} -%endif - -%if len( roles ) == 0: - There are no Galaxy roles -%else: -
    - - - <% - render_quick_find = len( roles ) > 50 - ctr = 0 - %> - %if render_quick_find: - <% - anchors = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'] - anchor_loc = 0 - anchored = False - curr_anchor = 'A' - %> - - - - %endif - - - - - - %for ctr, role in enumerate( roles ): - <% check = False %> - %for group_role in group_roles: - %if group_role.name == role.name: - <% - check = True - break - %> - %endif - %endfor - %if render_quick_find and not role.description.upper().startswith( curr_anchor ): - <% anchored = False %> - %endif - %if render_quick_find and role.description.upper().startswith( curr_anchor ): - %if not anchored: - ${render_row( role, ctr, anchored, curr_anchor, check )} - <% anchored = True %> - %else: - ${render_row( role, ctr, anchored, curr_anchor, check )} - %endif - %elif render_quick_find: - %for anchor in anchors[ anchor_loc: ]: - %if role.description.upper().startswith( anchor ): - %if not anchored: - <% curr_anchor = anchor %> - ${render_row( role, ctr, anchored, curr_anchor, check )} - <% anchored = True %> - %else: - ${render_row( role, ctr, anchored, curr_anchor, check )} - %endif - <% - anchor_loc = anchors.index( anchor ) - break - %> - %endif - %endfor - %else: - ${render_row( role, ctr, True, '', check )} - %endif - %endfor - -
    - Jump to letter: - %for a in anchors: - | ${a} - %endfor -
    Select to associate role with ${group.name}DescriptionRole Type
    -
    -%endif - diff --git a/templates/admin/dataset_security/groups.mako b/templates/admin/dataset_security/groups.mako index 366a9951ef2..52bfcc59c0c 100644 --- a/templates/admin/dataset_security/groups.mako +++ b/templates/admin/dataset_security/groups.mako @@ -13,15 +13,20 @@
    Rename this group - Change associated users - Change associated roles + Change associated users and roles Mark group deleted
    @@ -30,9 +35,13 @@ %for role in roles:
  • %if not role.type == trans.app.model.Role.types.PRIVATE: - ${role.description} + ${role.name} + +
    + Remove role from group +
    %else: - ${role.description} + ${role.name} %endif
  • %endfor diff --git a/templates/admin/dataset_security/role_create.mako b/templates/admin/dataset_security/role_create.mako index 34c940a9d2a..b987248bd5e 100644 --- a/templates/admin/dataset_security/role_create.mako +++ b/templates/admin/dataset_security/role_create.mako @@ -1,118 +1,87 @@ <%inherit file="/base.mako"/> <%namespace file="/message.mako" import="render_msg" /> -## Render a user row -<%def name="render_user_row( user, ctr )"> - %if ctr % 2 == 1: - - %else: - - %endif - ${user.email} - +<%def name="javascripts()"> + ${parent.javascripts()} + -## Render a group row -<%def name="render_group_row( group, ctr, anchored, curr_anchor )"> - %if ctr % 2 == 1: - - %else: - - %endif - - %if not anchored: -
    top
    - ${group.name} - %else: - ${group.name} - %endif - - +<%def name="render_select( name, options )"> + -

    Create Role

    + %if msg: ${render_msg( msg, messagetype )} %endif -
    - - - - - - <% - render_quick_find = len( users ) > 50 - ctr = 0 - %> - %if render_quick_find: - <% - anchors = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'] - anchor_loc = 0 - anchored = False - curr_anchor = 'A' - %> - - - - %endif - - - - - - ## Render users - - ## Render roles - - - -
    Name: Description:
    - Jump to letter: - %for a in anchors: - | ${a} - %endfor -
    Select to associate users with roleSelect to associate groups with role
    - - %for ctr, user in enumerate( users ): - ${render_user_row( user, ctr )} - %endfor -
    -
    - <% curr_anchor = 'A' %> - - %for ctr, group in enumerate( groups ): - %if render_quick_find and not group.name.upper().startswith( curr_anchor ): - <% anchored = False %> - %endif - %if render_quick_find and group.name.upper().startswith( curr_anchor ): - %if not anchored: - ${render_group_row( group, ctr, anchored, curr_anchor )} - <% anchored = True %> - %else: - ${render_group_row( group, ctr, anchored, curr_anchor )} - %endif - %elif render_quick_find: - %for anchor in anchors[ anchor_loc: ]: - %if group.name.upper().startswith( anchor ): - %if not anchored: - <% curr_anchor = anchor %> - ${render_group_row( group, ctr, anchored, curr_anchor )} - <% anchored = True %> - %else: - ${render_group_row( group, ctr, anchored, curr_anchor )} - %endif - <% - anchor_loc = anchors.index( anchor ) - break - %> - %endif - %endfor - %else: - ${render_group_row( group, ctr, True, '' )} - %endif - %endfor -
    -
    -
    +
    +
    Create Role
    +
    +
    +
    + Name: + Description: +
    +
    +
    + Groups associated with new role
    + ${render_select( "in_groups", in_groups )}
    + +
    +
    + Groups not associated with new role
    + ${render_select( "out_groups", out_groups )}
    + +
    +
    +
    +
    + Users associated with new role
    + ${render_select( "in_users", in_users )}
    + +
    +
    + Users not associated with new role
    + ${render_select( "out_users", out_users )}
    + +
    +
    +
    + +
    +
    +
    +
    diff --git a/templates/admin/dataset_security/roles.mako b/templates/admin/dataset_security/roles.mako index 1f7d9df74b0..734e50cb3bd 100644 --- a/templates/admin/dataset_security/roles.mako +++ b/templates/admin/dataset_security/roles.mako @@ -9,7 +9,7 @@ %endif - ${role.name} + ${role.name}
    Rename this role diff --git a/templates/admin/dataset_security/user.mako b/templates/admin/dataset_security/user.mako index 5db4cf72afa..5cc757ed1a0 100644 --- a/templates/admin/dataset_security/user.mako +++ b/templates/admin/dataset_security/user.mako @@ -1,57 +1,83 @@ <%inherit file="/base.mako"/> <%namespace file="/message.mako" import="render_msg" /> -## Render a role -<%def name="render_role( user, role )"> -
  • - %if role and not role.type == trans.app.model.Role.types.PRIVATE: - ${role.description} - -
    - Remove user from role -
    - %elif role: - ${role.description} - %endif -
  • +<%def name="javascripts()"> + ${parent.javascripts()} + -## Render a group -<%def name="render_group( user, group )"> -
  • - ${group.name} - -
    - Remove user from group -
    -
  • +<%def name="render_select( name, options )"> + + + %if msg: ${render_msg( msg, messagetype )} %endif -%if len( groups ) > 0 or len( roles ) > 0: - - - - - - - - - -
    Groups of which ${user.email} is a memberRoles associated with ${user.email}
    -
      - %for group in groups: - ${render_group( user, group )} - %endfor -
    -
    -
      - %for role in roles: - ${render_role( user, role )} - %endfor -
    -
    -%endif +
    +
    User '${user.email}'
    +
    +
    +
    +
    + Roles associated with '${user.email}'
    + ${render_select( "in_roles", in_roles )}
    + +
    +
    + Roles not associated with '${user.email}'
    + ${render_select( "out_roles", out_roles )}
    + +
    +
    +
    +
    + Groups associated with '${user.email}'
    + ${render_select( "in_groups", in_groups )}
    + +
    +
    + Groups not associated with '${user.email}'
    + ${render_select( "out_groups", out_groups )}
    + +
    +
    +
    + +
    +
    +
    +
    diff --git a/templates/admin/dataset_security/user_groups_edit.mako b/templates/admin/dataset_security/user_groups_edit.mako deleted file mode 100644 index d380dc44a9d..00000000000 --- a/templates/admin/dataset_security/user_groups_edit.mako +++ /dev/null @@ -1,100 +0,0 @@ -<%inherit file="/base.mako"/> -<%namespace file="/message.mako" import="render_msg" /> - -## Render a row -<%def name="render_row( group, ctr, anchored, curr_anchor, check )"> - %if ctr % 2 == 1: - - %else: - - %endif - - %if check: - ${group.name} - %else: - ${group.name} - %endif - %if not anchored: - -
    top
    - %endif - - - - -  - -%if msg: - ${render_msg( msg, messagetype )} -%endif - -%if len( groups ) == 0: - There are no Galaxy groups -%else: -
    - - <% - render_quick_find = len( groups ) > 50 - ctr = 0 - %> - %if render_quick_find: - <% - anchors = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'] - anchor_loc = 0 - anchored = False - curr_anchor = 'A' - %> - - - - %endif - - %for ctr, group in enumerate( groups ): - <% check = False %> - %for user_group in user_groups: - %if user_group.id == group.id: - <% - check = True - break - %> - %endif - %endfor - %if render_quick_find and not group.name.upper().startswith( curr_anchor ): - <% anchored = False %> - %endif - %if render_quick_find and group.name.upper().startswith( curr_anchor ): - %if not anchored: - ${render_row( group, ctr, anchored, curr_anchor, check )} - <% anchored = True %> - %else: - ${render_row( group, ctr, anchored, curr_anchor, check )} - %endif - %elif render_quick_find: - %for anchor in anchors[ anchor_loc: ]: - %if group.name.upper().startswith( anchor ): - %if not anchored: - <% curr_anchor = anchor %> - ${render_row( group, ctr, anchored, curr_anchor, check )} - <% anchored = True %> - %else: - ${render_row( group, ctr, anchored, curr_anchor, check )} - %endif - <% - anchor_loc = anchors.index( anchor ) - break - %> - %endif - %endfor - %else: - ${render_row( group, ctr, True, '', check )} - %endif - %endfor - -
    - Jump to letter: - %for a in anchors: - | ${a} - %endfor -
    Select to add ${user.email} to group
    -
    -%endif diff --git a/templates/admin/dataset_security/user_roles_edit.mako b/templates/admin/dataset_security/user_roles_edit.mako deleted file mode 100644 index d4636f53ed5..00000000000 --- a/templates/admin/dataset_security/user_roles_edit.mako +++ /dev/null @@ -1,101 +0,0 @@ -<%inherit file="/base.mako"/> -<%namespace file="/message.mako" import="render_msg" /> - -## Render a row -<%def name="render_row( role, ctr, anchored, curr_anchor, check )"> - %if ctr % 2 == 1: - - %else: - - %endif - - %if check: - ${role.name} - %else: - ${role.name} - %endif - %if not anchored: - -
    top
    - %endif - - - - -  - -%if msg: - ${render_msg( msg, messagetype )} -%endif - -%if len( roles ) == 0: - There are no Galaxy roles -%else: -
    - - - <% - render_quick_find = len( roles ) > 50 - ctr = 0 - %> - %if render_quick_find: - <% - anchors = ['A','B','C','D','E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S','T','U','V','W','X','Y','Z'] - anchor_loc = 0 - anchored = False - curr_anchor = 'A' - %> - - - - %endif - - %for ctr, role in enumerate( roles ): - <% check = False %> - %for user_role in user_roles: - %if user_role.id == role.id: - <% - check = True - break - %> - %endif - %endfor - %if render_quick_find and not role.name.upper().startswith( curr_anchor ): - <% anchored = False %> - %endif - %if render_quick_find and role.name.upper().startswith( curr_anchor ): - %if not anchored: - ${render_row( role, ctr, anchored, curr_anchor, check )} - <% anchored = True %> - %else: - ${render_row( role, ctr, anchored, curr_anchor, check )} - %endif - %elif render_quick_find: - %for anchor in anchors[ anchor_loc: ]: - %if role.name.upper().startswith( anchor ): - %if not anchored: - <% curr_anchor = anchor %> - ${render_row( role, ctr, anchored, curr_anchor, check )} - <% anchored = True %> - %else: - ${render_row( role, ctr, anchored, curr_anchor, check )} - %endif - <% - anchor_loc = anchors.index( anchor ) - break - %> - %endif - %endfor - %else: - ${render_row( role, ctr, True, '', check )} - %endif - %endfor - -
    - Jump to letter: - %for a in anchors: - | ${a} - %endfor -
    Select to associate role with ${user.email}
    -
    -%endif diff --git a/templates/admin/dataset_security/users.mako b/templates/admin/dataset_security/users.mako index 84abc332ac9..f189f299cf8 100644 --- a/templates/admin/dataset_security/users.mako +++ b/templates/admin/dataset_security/users.mako @@ -13,8 +13,7 @@
    Reset password - Change associated groups - Change associated roles + Change associated groups and roles %if allow_user_deletion: Mark user deleted %endif @@ -23,14 +22,26 @@ %if not anchored: diff --git a/templates/admin/library/new_dataset.mako b/templates/admin/library/new_dataset.mako index 3888d629aee..074d6e6f7ca 100644 --- a/templates/admin/library/new_dataset.mako +++ b/templates/admin/library/new_dataset.mako @@ -93,7 +93,7 @@
    diff --git a/templates/dataset/edit_attributes.mako b/templates/dataset/edit_attributes.mako index c29b77677b0..3a450ba83d3 100644 --- a/templates/dataset/edit_attributes.mako +++ b/templates/dataset/edit_attributes.mako @@ -180,7 +180,7 @@
  • ${action.description}
  • %endif diff --git a/templates/dataset/security_common.mako b/templates/dataset/security_common.mako index 517836f18d4..039a9a7ba6d 100644 --- a/templates/dataset/security_common.mako +++ b/templates/dataset/security_common.mako @@ -12,7 +12,7 @@ Roles associated:

    @@ -21,7 +21,7 @@ Roles not associated:

    diff --git a/test/base/twilltestcase.py b/test/base/twilltestcase.py index d361c08aa39..ef0ccecb703 100644 --- a/test/base/twilltestcase.py +++ b/test/base/twilltestcase.py @@ -626,56 +626,51 @@ class TwillTestCase( unittest.TestCase ): tc.submit( "reset_user_password_button" ) self.check_page_for_string( "Password reset" ) self.home() - def mark_user_deleted( self, user_id=4 ): + def mark_user_deleted( self, user_id=4, email='' ): """Mark a user as deleted""" self.home() self.visit_url( "%s/admin/mark_user_deleted?user_id=%s" % ( self.url, str( user_id ) ) ) - self.check_page_for_string( "The user has been marked as deleted." ) + check_str = "User '%s' has been marked as deleted." % email + self.check_page_for_string( check_str ) self.home() - def undelete_user( self, user_id ): + def undelete_user( self, user_id=4, email='' ): """Undelete a user""" self.home() self.visit_url( "%s/admin/undelete_user?user_id=%s" % ( self.url, user_id ) ) - self.check_page_for_string( 'The user has been marked as not deleted' ) + check_str = "User '%s' has been marked as not deleted" % email + self.check_page_for_string( check_str ) self.home() - def purge_user( self, user_id ): + def purge_user( self, user_id, email ): """Purge a user account""" self.home() self.visit_url( "%s/admin/purge_user?user_id=%s" % ( self.url, user_id ) ) - self.check_page_for_string( 'The user has been marked as purged.' ) + check_str = "User '%s' has been marked as purged." % email + self.check_page_for_string( check_str ) self.home() - def user_roles_edit( self, user_id, role_ids=[] ): - """Change roles associated with an existing user""" + def associate_roles_and_groups_with_user( self, user_id, email, role_ids=[], group_ids=[] ): self.home() - self.visit_url( "%s/admin/user_roles_edit?user_id=%s" % ( self.url, user_id ) ) - self.check_page_for_string( 'Select to associate role with' ) - for role_id in role_ids: - tc.fv( "1", "roles", role_id ) - tc.submit( "user_roles_edit_button" ) - self.check_page_for_string( 'User updated with a total of' ) + url = "%s/admin/user?user_id=%s&user_roles_groups_edit_button=Save" % ( self.url, user_id ) + if role_ids: + url += "&in_roles=%s" % ','.join( role_ids ) + if group_ids: + url += "&in_groups=%s" % ','.join( group_ids ) + self.visit_url( url ) + check_str = "User '%s' has been updated with %d associated roles and %d associated groups" % ( email, len( role_ids ), len( group_ids ) ) + self.check_page_for_string( check_str ) self.home() # Tests associated with roles - def create_role( self, name='Role One', description="This is Role One", user_ids=[], group_ids=[], private_role='' ): + def create_role( self, name='Role One', description="This is Role One", in_user_ids=[], in_group_ids=[], private_role='' ): """Create a new role""" + url = "%s/admin/create_role?create_role_button=Save&name=%s&description=%s" % ( self.url, name.replace( ' ', '+' ), description.replace( ' ', '+' ) ) + if in_user_ids: + url += "&in_users=%s" % ','.join( in_user_ids ) + if in_group_ids: + url += "&in_groups=%s" % ','.join( in_group_ids ) self.home() - self.visit_url( "%s/admin/create_role" % self.url ) - self.check_page_for_string( "Create Role" ) - tc.fv( "1", "name", name ) - tc.fv( "1", "description", description ) - for user_id in user_ids: - tc.fv( "1", "users", user_id ) - for group_id in group_ids: - tc.fv( "1", "groups", group_id ) - tc.submit( "create_role_button" ) - check_str = "The new role has been created with %s associated users and %s associated groups" % ( str( len( user_ids ) ), str( len( group_ids ) ) ) - try: - self.check_page_for_string( check_str ) - previously_created = False - except: - # The role may have been created on a previous test run - self.check_page_for_string( "A role with that name already exists" ) - previously_created = True + self.visit_url( url ) + check_str = "Role '%s' has been created with %d associated users and %d associated groups" % ( name, len( in_user_ids ), len( in_group_ids ) ) + self.check_page_for_string( check_str ) if private_role: # Make sure no private roles are displayed try: @@ -686,10 +681,9 @@ class TwillTestCase( unittest.TestCase ): # Reaching here is the behavior we want since no private roles should be displayed pass self.home() - self.visit_page( "admin/roles" ) - self.check_page_for_string( description ) + self.visit_url( "%s/admin/roles" % self.url ) + self.check_page_for_string( name ) self.home() - return previously_created def rename_role( self, role_id, name='Role One Renamed', description='This is Role One Re-described' ): """Rename a role""" self.home() @@ -699,82 +693,56 @@ class TwillTestCase( unittest.TestCase ): tc.fv( "1", "description", description ) tc.submit( "rename_role_button" ) self.home() - def mark_role_deleted( self, role_id ): + def mark_role_deleted( self, role_id, role_name ): """Mark a role as deleted""" self.home() self.visit_url( "%s/admin/mark_role_deleted?role_id=%s" % ( self.url, role_id ) ) - self.check_page_for_string( 'The role has been marked as deleted' ) + check_str = "Role '%s' has been marked as deleted" % role_name + self.check_page_for_string( check_str ) self.home() - def undelete_role( self, role_id ): + def undelete_role( self, role_id, role_name ): """Undelete an existing role""" self.home() self.visit_url( "%s/admin/undelete_role?role_id=%s" % ( self.url, role_id ) ) - self.check_page_for_string( 'The role has been marked as not deleted' ) + check_str = "Role '%s' has been marked as not deleted" % role_name + self.check_page_for_string( check_str ) self.home() - def purge_role( self, role_id ): + def purge_role( self, role_id, role_name ): """Purge an existing role""" self.home() self.visit_url( "%s/admin/purge_role?role_id=%s" % ( self.url, role_id ) ) - check_str = "The following have been purged from the database for the role: " + check_str = "The following have been purged from the database for role '%s': " % role_name check_str += "DefaultUserPermissions, DefaultHistoryPermissions, UserRoleAssociations, GroupRoleAssociations, ActionDatasetRoleAssociations." self.check_page_for_string( check_str ) self.home() - def associate_groups_with_role( self, role_id, group_names=[] ): - """Add groups to an existing role""" - # NOTE: To get this to work with twill, all select lists must contain at least 1 option value - # before tc.submit or twill throws an exception, which is: ParseError: OPTION outside of SELECT + def associate_users_and_groups_with_role( self, role_id, role_name, user_ids=[], group_ids=[] ): self.home() - self.visit_url( "%s/admin/role?role_id=%s" % ( self.url, role_id ) ) - self.check_page_for_string( 'Groups associated with' ) - # All group_ids passed in MUST be in the out_groups form field - for group_name in group_names: - tc.fv( "1", "out_groups", group_name ) # note the buttons... - tc.submit( "groups_add_button" ) - tc.submit( "role_members_edit_button" ) + url = "%s/admin/role?role_id=%s&role_members_edit_button=Save" % ( self.url, role_id ) + if user_ids: + url += "&in_users=%s" % ','.join( user_ids ) + if group_ids: + url += "&in_groups=%s" % ','.join( group_ids ) + self.visit_url( url ) + check_str = "Role '%s' has been updated with %d associated users and %d associated groups" % ( role_name, len( user_ids ), len( group_ids ) ) + self.check_page_for_string( check_str ) self.home() - def associate_users_with_role( self, role_id, user_emails=[] ): - """Add a users to an existing role""" - # NOTE: To get this to work with twill, all select lists must contain at least 1 option value - # before tc.submit or twill throws an exception, which is: ParseError: OPTION outside of SELECT - self.home() - self.visit_url( "%s/admin/role?role_id=%s" % ( self.url, role_id ) ) - self.check_page_for_string( 'Users associated with' ) - for user_email in user_emails: - tc.fv( "1", "out_users", user_email ) - tc.submit( "users_add_button" ) - tc.submit( "role_members_edit_button" ) - self.home() - + # Tests associated with groups - def create_group( self, name='Group One', user_ids=[], role_ids=[] ): - """Create a new group with members and associated role""" + def create_group( self, name='Group One', in_user_ids=[], in_role_ids=[] ): + """Create a new group""" + url = "%s/admin/create_group?create_group_button=Save&name=%s" % ( self.url, name.replace( ' ', '+' ) ) + if in_user_ids: + url += "&in_users=%s" % ','.join( in_user_ids ) + if in_role_ids: + url += "&in_roles=%s" % ','.join( in_role_ids ) self.home() - self.visit_url( "%s/admin/create_group" % self.url ) - self.check_page_for_string( "Create Group" ) - # Make sure no private roles are displayed - try: - self.check_page_for_string( 'Private Role for' ) - raise AssertionError( 'Private role displayed on Create Group page' ) - except AssertionError: - # Reaching here is the behavior we want since no private roles should be displayed - pass - tc.fv( "1", "name", name ) - for user_id in user_ids: - tc.fv( "1", "members", user_id ) - for role_id in role_ids: - tc.fv( "1", "roles", role_id ) - tc.submit( "create_group_button" ) - try: - self.check_page_for_string( "The new group has been created" ) - previously_created = False - except: - self.check_page_for_string( "A group with that name already exists" ) - previously_created = True + self.visit_url( url ) + check_str = "Group '%s' has been created with %d associated users and %d associated roles" % ( name, len( in_user_ids ), len( in_role_ids ) ) + self.check_page_for_string( check_str ) self.home() - self.visit_page( "admin/groups" ) + self.visit_url( "%s/admin/groups" % self.url ) self.check_page_for_string( name ) self.home() - return previously_created def rename_group( self, group_id, name='Group One Renamed' ): """Rename a group""" self.home() @@ -783,63 +751,60 @@ class TwillTestCase( unittest.TestCase ): tc.fv( "1", "name", name ) tc.submit( "rename_group_button" ) self.home() - def group_members_edit( self, group_id, user_ids=[] ): - """Add members to an existing group""" + def associate_users_and_roles_with_group( self, group_id, group_name, user_ids=[], role_ids=[] ): self.home() - self.visit_url( "%s/admin/group_members_edit?group_id=%s" % ( self.url, group_id ) ) - self.check_page_for_string( 'Select to add user to' ) - for user_id in user_ids: - tc.fv( "1", "members", user_id ) - tc.submit( "group_members_edit_button" ) - self.check_page_for_string( 'Group membership has been updated' ) + url = "%s/admin/group?group_id=%s&group_roles_users_edit_button=Save" % ( self.url, group_id ) + if user_ids: + url += "&in_users=%s" % ','.join( user_ids ) + if role_ids: + url += "&in_roles=%s" % ','.join( role_ids ) + self.visit_url( url ) + check_str = "Group '%s' has been updated with %d associated roles and %d associated users" % ( group_name, len( role_ids ), len( user_ids ) ) + self.check_page_for_string( check_str ) self.home() - def group_roles_edit( self, group_id, role_ids=[] ): - """Change roles associated with an existing group""" - self.home() - self.visit_url( "%s/admin/group_roles_edit?group_id=%s" % ( self.url, group_id ) ) - self.check_page_for_string( 'Select to associate role with' ) - for role_id in role_ids: - tc.fv( "1", "roles", role_id ) - tc.submit( "group_roles_edit_button" ) - self.check_page_for_string( 'Group updated with a total of' ) - self.home() - def mark_group_deleted( self, group_id ): + def mark_group_deleted( self, group_id, group_name ): """Mark a group as deleted""" self.home() self.visit_url( "%s/admin/mark_group_deleted?group_id=%s" % ( self.url, group_id ) ) - self.check_page_for_string( 'The group has been marked as deleted' ) + check_str = "Group '%s' has been marked as deleted" % group_name + self.check_page_for_string( check_str ) self.home() - def undelete_group( self, group_id ): + def undelete_group( self, group_id, group_name ): """Undelete an existing group""" self.home() self.visit_url( "%s/admin/undelete_group?group_id=%s" % ( self.url, group_id ) ) - self.check_page_for_string( 'The group has been marked as not deleted' ) + check_str = "Group '%s' has been marked as not deleted" % group_name + self.check_page_for_string( check_str ) self.home() - def purge_group( self, group_id ): + def purge_group( self, group_id, group_name ): """Purge an existing group""" self.home() self.visit_url( "%s/admin/purge_group?group_id=%s" % ( self.url, group_id ) ) - self.check_page_for_string( "The following have been purged from the database for the group: UserGroupAssociations, GroupRoleAssociations." ) + check_str = "The following have been purged from the database for group '%s': UserGroupAssociations, GroupRoleAssociations." % group_name + self.check_page_for_string( check_str ) self.home() # Utility methods to test removal of associations - def remove_role_from_group( self, role_id, group_id ): + def remove_role_from_group( self, role_id, role_name, group_id, group_name ): """Remove a role from a group""" self.home() self.visit_url( "%s/admin/remove_role_from_group?role_id=%s&group_id=%s" % ( self.url, role_id, group_id ) ) - self.check_page_for_string( 'Role removed from group' ) + check_str = "Role '%s' removed from group '%s'" % ( role_name, group_name ) + self.check_page_for_string( check_str ) self.home() - def remove_user_from_group( self, user_id, group_id ): + def remove_user_from_group( self, user_id, email, group_id, group_name ): """Remove a user from a group""" self.home() self.visit_url( "%s/admin/remove_user_from_group?user_id=%s&group_id=%s" % ( self.url, user_id, group_id ) ) - self.check_page_for_string( 'User removed from group' ) + check_str = "User '%s' removed from group '%s'" % ( email, group_name ) + self.check_page_for_string( check_str ) self.home() - def remove_user_from_role( self, user_id, role_id ): + def remove_user_from_role( self, user_id, email, role_id, role_name ): """Remove a user from a role""" self.home() self.visit_url( "%s/admin/remove_user_from_role?user_id=%s&role_id=%s" % ( self.url, user_id, role_id ) ) - self.check_page_for_string( 'User removed from role' ) + check_str = "User '%s' removed from role '%s'" % ( email, role_name ) + self.check_page_for_string( check_str ) self.home() # Library stuff @@ -921,25 +886,28 @@ class TwillTestCase( unittest.TestCase ): library_dir = "%s" % self.file_dir tc.fv( "1", "server_dir", "library" ) for role_tuple in roles_tuple: - tc.fv( "1", "roles", role_tuple[1] ) # role_tuple[1] is the role description + tc.fv( "1", "roles", role_tuple[1] ) # role_tuple[1] is the role name tc.submit( "new_dataset_button" ) self.check_page_for_string( '3 new datasets added to the library' ) self.home() - def mark_library_deleted( self, library_id ): + def mark_library_deleted( self, library_id, library_name ): """Mark a library as deleted""" self.home() self.visit_url( "%s/admin/library?id=%s&delete=True" % ( self.url, library_id ) ) - self.check_page_for_string( 'The library and all of its contents have been marked deleted' ) + check_str = "Library '%s' and all of its contents have been marked deleted" % library_name + self.check_page_for_string( check_str ) self.home() - def undelete_library( self, library_id ): + def undelete_library( self, library_id, library_name ): """Mark a library as not deleted""" self.home() self.visit_url( "%s/admin/undelete_library?id=%s" % ( self.url, library_id ) ) - self.check_page_for_string( 'The library and all of its contents have been marked not deleted' ) + check_str = "Library '%s' and all of its contents have been marked not deleted" % library_name + self.check_page_for_string( check_str ) self.home() - def purge_library( self, library_id ): + def purge_library( self, library_id, library_name ): """Purge a library""" self.home() self.visit_url( "%s/admin/purge_library?id=%s" % ( self.url, library_id ) ) - self.check_page_for_string( 'The library and all of its contents have been purged' ) + check_str = "Library '%s' and all of its contents have been purged" % library_name + self.check_page_for_string( check_str ) self.home() diff --git a/test/functional/test_security_and_libraries.py b/test/functional/test_security_and_libraries.py index e66a2248515..693769ad24f 100644 --- a/test/functional/test_security_and_libraries.py +++ b/test/functional/test_security_and_libraries.py @@ -17,7 +17,7 @@ class TestSecurityAndLibraries( TwillTestCase ): self.check_page_for_string( not_logged_in_security_msg ) self.visit_url( "%s/admin/create_role" % self.url ) self.check_page_for_string( not_logged_in_security_msg ) - self.visit_url( "%s/admin/new_role" % self.url ) + self.visit_url( "%s/admin/create_role" % self.url ) self.check_page_for_string( not_logged_in_security_msg ) self.visit_url( "%s/admin/role" % self.url ) self.check_page_for_string( not_logged_in_security_msg ) @@ -25,7 +25,6 @@ class TestSecurityAndLibraries( TwillTestCase ): self.check_page_for_string( not_logged_in_security_msg ) self.visit_url( "%s/admin/create_group" % self.url ) self.check_page_for_string( not_logged_in_security_msg ) - self.visit_url( "%s/admin/group_members_edit?group_id=0" % self.url ) self.check_page_for_string( not_logged_in_security_msg ) self.visit_url( "%s/admin/users" % self.url ) self.check_page_for_string( not_logged_in_security_msg ) @@ -281,30 +280,24 @@ class TestSecurityAndLibraries( TwillTestCase ): self.reset_password_as_admin( user_id=regular_user3.id, password='testuser' ) def test_035_mark_user_deleted( self ): """Testing marking a user account as deleted""" - self.mark_user_deleted( user_id=regular_user3.id ) + self.mark_user_deleted( user_id=regular_user3.id, email=regular_user3.email ) # Deleting a user should not delete any associations regular_user3.refresh() if not regular_user3.active_histories: raise AssertionError( 'HistoryDatasetAssociations for regular_user3 were incorrectly deleted when the user was marked deleted' ) def test_040_undelete_user( self ): """Testing undeleting a user account""" - self.undelete_user( user_id=regular_user3.id ) + self.undelete_user( user_id=regular_user3.id, email=regular_user3.email ) def test_045_create_role( self ): """Testing creating new role with 3 members, then renaming it""" name = 'Role One' - description = "This is Role One's description" + description = "This is Role Ones description" user_ids=[ str( admin_user.id ), str( regular_user1.id ), str( regular_user3.id ) ] - previously_created = self.create_role( name=name, description=description, user_ids=user_ids, private_role=admin_user.email ) + self.create_role( name=name, description=description, in_user_ids=user_ids, in_group_ids=[], private_role=admin_user.email ) # Get the role object for later tests global role_one role_one = galaxy.model.Role.filter( galaxy.model.Role.table.c.name==name ).first() assert role_one is not None, 'Problem retrieving role named "Role One" from the database' - if previously_created: - # Since the role was created in a previous test run, we need to associate the required users with it - role_ids = [ str( role_one.id ) ] - for user_id in user_ids: - self.user_roles_edit( user_id, role_ids=role_ids ) - role_one.refresh() # Make sure UserRoleAssociations are correct if len( role_one.users ) != len( user_ids ): raise AssertionError( '%d UserRoleAssociations were created for role id %d when it was created ( should have been %d )' \ @@ -312,13 +305,13 @@ class TestSecurityAndLibraries( TwillTestCase ): # Each of the following users should now have 3 role associations, their private role, role_one and sharing_role for user in [ admin_user, regular_user1 ]: user.refresh() - if not previously_created and len( user.roles ) != 3: + if len( user.roles ) != 3: raise AssertionError( '%d UserRoleAssociations are associated with user %s ( should be 3 )' \ % ( len( user.roles ), user.email ) ) # Each of the following users should now have 2 role associations, their private role and role_one for user in [ regular_user3 ]: user.refresh() - if not previously_created and len( user.roles ) != 2: + if len( user.roles ) != 2: raise AssertionError( '%d UserRoleAssociations are associated with user %s ( should be 2 )' \ % ( len( user.roles ), user.email ) ) # Rename the role @@ -336,15 +329,11 @@ class TestSecurityAndLibraries( TwillTestCase ): name = "Group One's Name" user_ids=[ str( admin_user.id ), str( regular_user1.id ), str( regular_user3.id ) ] role_ids=[ str( role_one.id ) ] - previously_created = self.create_group( name=name, user_ids=user_ids, role_ids=role_ids ) + self.create_group( name=name, in_user_ids=user_ids, in_role_ids=role_ids ) # Get the group object for later tests global group_one group_one = galaxy.model.Group.filter( galaxy.model.Group.table.c.name==name ).first() assert group_one is not None, 'Problem retrieving group named "Group One" from the database' - if previously_created: - # group_one was created during a previous test run, so create associations - self.group_members_edit( str( group_one.id ), user_ids=user_ids ) - self.group_roles_edit( str( group_one.id ), role_ids=role_ids ) # Make sure UserGroupAssociations are correct if len( group_one.users ) != len( user_ids ): raise AssertionError( '%d UserGroupAssociations were created for group id %d when it was created ( should have been %d )' \ @@ -369,7 +358,7 @@ class TestSecurityAndLibraries( TwillTestCase ): def test_055_add_members_and_role_to_group( self ): """Testing editing user membership and role associations of an existing group""" name = 'Group Two' - previously_created = self.create_group( name=name, user_ids=[], role_ids=[] ) + self.create_group( name=name, in_user_ids=[], in_role_ids=[] ) # Get the group object for later tests global group_two group_two = galaxy.model.Group.filter( galaxy.model.Group.table.c.name==name ).first() @@ -383,58 +372,25 @@ class TestSecurityAndLibraries( TwillTestCase ): % ( len( group_two.roles ), group_two.id ) ) group_two_id = str( group_two.id ) user_ids = [ str( regular_user1.id ) ] - # Add users to group_two based on user_ids - self.group_members_edit( group_two_id, user_ids=user_ids ) - self.home() - self.visit_url( "%s/admin/group_members_edit?group_id=%s" % ( self.url, group_two_id ) ) - # Make sure UserGroupAssociations are correct - check_str = '%s currently has %d members' % ( name, len( user_ids ) ) - self.check_page_for_string( check_str ) role_ids = [ str( role_one.id ) ] - # Associate roles with group_two based on roles_ids - self.group_roles_edit( group_two_id, role_ids=role_ids ) - self.home() - self.visit_url( "%s/admin/group_roles_edit?group_id=%s" % ( self.url, group_two_id ) ) - # Make sure GroupRoleAssociation are correct - check_str = '%s is currently associated with %d roles' % ( name, len( role_ids ) ) - self.check_page_for_string( check_str ) - # Create another group -needed for the following test - name = 'Group Three' - previously_created = self.create_group( name=name, user_ids=[], role_ids=[] ) - # Get the group object for later tests - global group_three - group_three = galaxy.model.Group.filter( galaxy.model.Group.table.c.name==name ).first() - assert group_three is not None, 'Problem retrieving group named "Group Three" from the database' - group_three_id = str( group_three.id ) + self.associate_users_and_roles_with_group( group_two.id, group_two.name, user_ids=user_ids, role_ids=role_ids ) def test_060_create_role_with_user_and_group_associations( self ): """Testing creating a role with user and group associations""" # NOTE: To get this to work with twill, all select lists on the ~/admin/role page must contain at least # 1 option value or twill throws an exception, which is: ParseError: OPTION outside of SELECT - # Due to this bug in twill, we create the role, associating it with at least 1 user and 1 group. We - # also must ensure that each of the form fields will contain at least 1 value prior to submitting the form, - # so we had to create group_three in the previous test + # Due to this bug in twill, we create the role, we bypass the page and visit the URL in the + # associate_users_and_groups_with_role() method. name = 'Role Two' description = 'This is Role Two' user_ids=[ str( admin_user.id ) ] group_ids=[ str( group_two.id ) ] private_role=admin_user.email - # STEP 1: create the role - previously_created = self.create_role( name=name, - description=description, - user_ids=user_ids, - group_ids=group_ids, - private_role=private_role ) + # Create the role + self.create_role( name=name, description=description, in_user_ids=user_ids, in_group_ids=group_ids, private_role=private_role ) # Get the role object for later tests global role_two role_two = galaxy.model.Role.filter( galaxy.model.Role.table.c.name==name ).first() assert role_two is not None, 'Problem retrieving role named "Role Two" from the database' - if previously_created: - # role_two was created during a previous test run, so create associations - user_id = user_ids[0] - role_ids = [ str( role_two.id) ] - self.user_roles_edit( user_id, role_ids=role_ids ) - group_id = group_ids[0] - self.group_roles_edit( group_id, role_ids=role_ids ) # Make sure UserRoleAssociations are correct if len( role_two.users ) != len( user_ids ): raise AssertionError( '%d UserRoleAssociations were created for role id %d when it was created with %d members' \ @@ -452,12 +408,6 @@ class TestSecurityAndLibraries( TwillTestCase ): group_two.refresh() if len( group_two.roles ) != 2: raise AssertionError( '%d GroupRoleAssociations are associated with group id %d ( should be 2 )' % ( len( group_two.roles ), group_two.id ) ) - # STEP 2: associate the role with a group not yet associated - # TODO: Twill throws an exception on this... - #group_names = [ group_one.name ] - #self.associate_groups_with_role( str( role_two.id ), group_names=group_names ) - #self.visit_page( 'admin/roles' ) - #self.check_page_for_string( group_one.name ) def test_065_change_user_role_associations( self ): """Testing changing roles associated with a user""" # Create a new role with no associations @@ -466,18 +416,21 @@ class TestSecurityAndLibraries( TwillTestCase ): user_ids=[] group_ids=[] private_role=admin_user.email - previously_created = self.create_role( name=name, - description=description, - user_ids=user_ids, - group_ids=group_ids, - private_role=private_role ) + self.create_role( name=name, description=description, in_user_ids=user_ids, in_group_ids=group_ids, private_role=private_role ) # Get the role object for later tests global role_three role_three = galaxy.model.Role.filter( galaxy.model.Role.table.c.name==name ).first() assert role_three is not None, 'Problem retrieving role named "Role Three" from the database' # Associate the role with a user - role_ids = [ str( role_three.id ) ] - self.user_roles_edit( str( admin_user.id ), role_ids=role_ids ) + admin_user.refresh() + role_ids = [] + for ura in admin_user.non_private_roles: + role_ids.append( str( ura.role_id ) ) + role_ids.append( str( role_three.id ) ) + group_ids = [] + for uga in admin_user.groups: + group_ids.append( str( uga.group_id ) ) + self.associate_roles_and_groups_with_user( str( admin_user.id ), str( admin_user.email ), role_ids=role_ids, group_ids=group_ids ) admin_user.refresh() # admin_user should now be associated with 5 roles: private, role_one, role_two, role_three and sharing_role if len( admin_user.roles ) != 5: @@ -742,7 +695,7 @@ class TestSecurityAndLibraries( TwillTestCase ): str( adra.action ) ) def test_115_add_datasets_from_library_dir( self ): """Testing adding 3 datasets from a library directory to a folder""" - roles_tuple = [ ( str( role_one.id ), role_one.description ) ] + roles_tuple = [ ( str( role_one.id ), role_one.name ) ] self.add_datasets_from_library_dir( str( folder_one.id ), roles_tuple=roles_tuple ) def test_120_change_permissions_on_datasets_imported_from_library( self ): """Testing changing the permissions on library datasets imported into a history""" @@ -833,7 +786,7 @@ class TestSecurityAndLibraries( TwillTestCase ): self.home() self.visit_url( '%s/admin/groups' % self.url ) self.check_page_for_string( group_two.name ) - self.mark_group_deleted( str( group_two.id ) ) + self.mark_group_deleted( str( group_two.id ), group_two.name ) group_two.refresh() if not group_two.deleted: raise AssertionError( '%s was not correctly marked as deleted.' % group_two.name ) @@ -844,7 +797,7 @@ class TestSecurityAndLibraries( TwillTestCase ): raise AssertionError( '%s incorrectly lost all role associations when it was marked as deleted.' % group_two.name ) def test_130_undelete_group( self ): """Testing undeleting a deleted group""" - self.undelete_group( str( group_two.id ) ) + self.undelete_group( str( group_two.id ), group_two.name ) group_two.refresh() if group_two.deleted: raise AssertionError( '%s was not correctly marked as not deleted.' % group_two.name ) @@ -853,7 +806,7 @@ class TestSecurityAndLibraries( TwillTestCase ): self.home() self.visit_url( '%s/admin/roles' % self.url ) self.check_page_for_string( role_two.name ) - self.mark_role_deleted( str( role_two.id ) ) + self.mark_role_deleted( str( role_two.id ), role_two.name ) role_two.refresh() if not role_two.deleted: raise AssertionError( '%s was not correctly marked as deleted.' % role_two.name ) @@ -864,10 +817,10 @@ class TestSecurityAndLibraries( TwillTestCase ): raise AssertionError( '%s incorrectly lost all group associations when it was marked as deleted.' % role_two.name ) def test_140_undelete_role( self ): """Testing undeleting a deleted role""" - self.undelete_role( str( role_two.id ) ) + self.undelete_role( str( role_two.id ), role_two.name ) def test_145_mark_library_deleted( self ): """Testing marking a library as deleted""" - self.mark_library_deleted( str( library_one.id ) ) + self.mark_library_deleted( str( library_one.id ), library_one.name ) # Make sure the library was deleted library_one.refresh() if not library_one.deleted: @@ -893,7 +846,7 @@ class TestSecurityAndLibraries( TwillTestCase ): check_folder( library_one.root_folder ) def test_150_undelete_library( self ): """Testing marking a library as not deleted""" - self.undelete_library( str( library_one.id ) ) + self.undelete_library( str( library_one.id ), library_one.name ) # Make sure the library is undeleted library_one.refresh() if library_one.deleted: @@ -917,7 +870,7 @@ class TestSecurityAndLibraries( TwillTestCase ): raise AssertionError( 'The dataset with id "%s" has not been marked as undeleted.' % lfda.dataset.id ) check_folder( library_one.root_folder ) # Mark library as deleted again so we can test purging it - self.mark_library_deleted( str( library_one.id ) ) + self.mark_library_deleted( str( library_one.id ), library_one.name ) # Make sure the library is deleted again library_one.refresh() if not library_one.deleted: @@ -925,8 +878,8 @@ class TestSecurityAndLibraries( TwillTestCase ): ( str( library_one.id ), library_one.name ) ) def test_155_purge_user( self ): """Testing purging a user account""" - self.mark_user_deleted( user_id=regular_user3.id ) - self.purge_user( user_id=regular_user3.id ) + self.mark_user_deleted( user_id=regular_user3.id, email=regular_user3.email ) + self.purge_user( str( regular_user3.id ), regular_user3.email ) regular_user3.refresh() if not regular_user3.purged: raise AssertionError( 'User %s was not marked as purged.' % regular_user3.email ) @@ -979,8 +932,8 @@ class TestSecurityAndLibraries( TwillTestCase ): def test_165_purge_group( self ): """Testing purging a group""" group_id = str( group_two.id ) - self.mark_group_deleted( group_id ) - self.purge_group( group_id ) + self.mark_group_deleted( group_id, group_two.name ) + self.purge_group( group_id, group_two.name ) # Make sure there are no UserGroupAssociations uga = galaxy.model.UserGroupAssociation.filter( galaxy.model.UserGroupAssociation.table.c.group_id == group_id ).all() if uga: @@ -990,12 +943,12 @@ class TestSecurityAndLibraries( TwillTestCase ): if gra: raise AssertionError( "Purging the group did not delete the GroupRoleAssociations for group_id '%s'" % group_id ) # Undelete the group for later test runs - self.undelete_group( group_id ) + self.undelete_group( group_id, group_two.name ) def test_170_purge_role( self ): """Testing purging a role""" role_id = str( role_two.id ) - self.mark_role_deleted( role_id ) - self.purge_role( role_id ) + self.mark_role_deleted( role_id, role_two.name ) + self.purge_role( role_id, role_two.name ) # Make sure there are no UserRoleAssociations uras = galaxy.model.UserRoleAssociation.filter( galaxy.model.UserRoleAssociation.table.c.role_id == role_id ).all() if uras: @@ -1022,10 +975,10 @@ class TestSecurityAndLibraries( TwillTestCase ): # TODO: If we decide to implement the GUI feature for un-purging a role, replace this with a method call role_two.purged = False role_two.flush() - self.undelete_role( str( role_two.id ) ) + self.undelete_role( str( role_two.id ), role_two.name ) def test_180_purge_library( self ): """Testing purging a library""" - self.purge_library( str( library_one.id ) ) + self.purge_library( str( library_one.id ), library_one.name ) # Make sure the library was purged library_one.refresh() if not library_one.purged: @@ -1053,22 +1006,34 @@ class TestSecurityAndLibraries( TwillTestCase ): def test_185_reset_data_for_later_test_runs( self ): """Reseting data to enable later test runs to pass""" ################## - # Reset admin_user + # Eliminate all non-private roles ################## - # Eliminate all role associations except private - self.remove_user_from_role( str( admin_user.id ), str( role_one.id ) ) - self.remove_user_from_role( str( admin_user.id ), str( role_three.id ) ) - self.remove_user_from_role( str( admin_user.id ), str( sharing_role.id ) ) - admin_user.refresh() - if len( admin_user.roles) != 1: - raise AssertionError( '%d UserRoleAssociations are associated with %s ( should be 1 )' % ( len( admin_user.roles ), admin_user.email ) ) - # Eliminate all group associations - self.remove_user_from_group( str( admin_user.id ), str( group_one.id ) ) - admin_user.refresh() - if admin_user.groups: - raise AssertionError( '%d UserGroupAssociations are associated with %s ( should be 0 )' % ( len( admin_user.groups ), admin_user.email ) ) + for role in [ role_one, role_two, role_three, sharing_role ]: + self.mark_role_deleted( str( role.id ), role.name ) + self.purge_role( str( role.id ), role.name ) + # Manually delete the role from the database + role.refresh() + role.delete() + role.flush() + ################## + # Eliminate all groups + ################## + for group in [ group_one, group_two ]: + self.mark_group_deleted( str( group.id ), group.name ) + self.purge_group( str( group.id ), group.name ) + # Manually delete the group from the database + group.refresh() + group.delete() + group.flush() + ################## + # Make sure all users are associated only with their private roles + ################## + for user in [ admin_user, regular_user1, regular_user2, regular_user3 ]: + user.refresh() + if len( user.roles) != 1: + raise AssertionError( '%d UserRoleAssociations are associated with %s ( should be 1 )' % ( len( user.roles ), user.email ) ) ##################### - # Reset regular_user1 + # Reset DefaultHistoryPermissions for regular_user1 ##################### self.logout() self.login( email='test1@bx.psu.edu' ) @@ -1079,28 +1044,3 @@ class TestSecurityAndLibraries( TwillTestCase ): self.user_set_default_permissions( permissions_in=permissions_in, permissions_out=permissions_out, role_id=role_id ) self.logout() self.login( email='test@bx.psu.edu' ) - # Eliminate all role associations except private - self.remove_user_from_role( str( regular_user1.id ), str( role_one.id ) ) - self.remove_user_from_role( str( regular_user1.id ), str( sharing_role.id ) ) - regular_user1.refresh() - if len( regular_user1.roles) != 1: - raise AssertionError( '%d UserRoleAssociations are associated with %s ( should be 1 )' % ( len( regular_user1.roles ), regular_user1.email ) ) - # Eliminate all group associations - self.remove_user_from_group( str( regular_user1.id ), str( group_one.id ) ) - regular_user1.refresh() - if regular_user1.groups: - raise AssertionError( '%d UserGroupAssociations are associated with %s ( should be 0 )' % ( len( regular_user1.groups ), regular_user1.email ) ) - # Delete the record for sharing_role from the role table so that it can be created correctly in later test runs - self.mark_role_deleted( str( sharing_role.id ) ) - self.purge_role( str( sharing_role.id ) ) - sharing_role.refresh() - sharing_role.delete() - sharing_role.flush() - ################# - # Reset group_one - ################# - # Eliminate all role associations - self.remove_role_from_group( str( role_one.id ), str( group_one.id ) ) - group_one.refresh() - if group_one.roles: - raise AssertionError( '%d GroupRoleAssociations are associated with group %s ( should be 0 )' % ( len( group_one.roles ), group_one.name ) )