From 81dc3a955bae39d90f16441dad5a67a708177844 Mon Sep 17 00:00:00 2001 From: Nicola Soranzo Date: Wed, 11 Nov 2015 18:39:19 +0000 Subject: [PATCH 1/4] Fix typo. --- lib/galaxy/webapps/galaxy/api/history_contents.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/galaxy/webapps/galaxy/api/history_contents.py b/lib/galaxy/webapps/galaxy/api/history_contents.py index c06fe218052..138e8c0734c 100644 --- a/lib/galaxy/webapps/galaxy/api/history_contents.py +++ b/lib/galaxy/webapps/galaxy/api/history_contents.py @@ -348,7 +348,7 @@ class HistoryContentsController( BaseAPIController, UsesLibraryMixin, UsesLibrar :type history_id: str :param history_id: encoded id string of the HDA's History :type id: str - :param id: the encoded id of the history to undelete + :param id: the encoded id of the history to update :type payload: dict :param payload: a dictionary containing any or all the fields in :func:`galaxy.model.HistoryDatasetAssociation.to_dict` From 86220c7685ff831d3d5b39732706c679e77afd38 Mon Sep 17 00:00:00 2001 From: Nicola Soranzo Date: Wed, 11 Nov 2015 18:42:56 +0000 Subject: [PATCH 2/4] Extend users API with delete action. --- lib/galaxy/managers/users.py | 12 ++++++---- lib/galaxy/webapps/galaxy/api/users.py | 31 +++++++++++++++++++++----- 2 files changed, 34 insertions(+), 9 deletions(-) diff --git a/lib/galaxy/managers/users.py b/lib/galaxy/managers/users.py index 96e32ef45bb..6d7e945a309 100644 --- a/lib/galaxy/managers/users.py +++ b/lib/galaxy/managers/users.py @@ -64,6 +64,11 @@ class UserManager( base.ModelManager, deletable.PurgableManagerMixin ): self.app.security_agent.user_set_default_permissions( user, default_access_private=permissions ) return user + def delete(self, user): + user.deleted = True + self.session().add(user) + self.session().flush() + def _error_on_duplicate_email( self, email ): """ Check for a duplicate email and raise if found. @@ -249,13 +254,12 @@ class UserSerializer( base.ModelSerializer, deletable.PurgableSerializerMixin ): self.add_view( 'detailed', [ # 'update_time', # 'create_time', - + 'is_admin', 'total_disk_usage', 'nice_total_disk_usage', 'quota_percent', - - # 'deleted', - # 'purged', + 'deleted', + 'purged', # 'active', # 'preferences', diff --git a/lib/galaxy/webapps/galaxy/api/users.py b/lib/galaxy/webapps/galaxy/api/users.py index 1b65e162e50..a4cdd6e4203 100644 --- a/lib/galaxy/webapps/galaxy/api/users.py +++ b/lib/galaxy/webapps/galaxy/api/users.py @@ -6,9 +6,8 @@ import logging from sqlalchemy import false, true -from galaxy import exceptions -from galaxy import util -from galaxy import web +from galaxy import exceptions, util, web +from galaxy.managers import users from galaxy.security.validate_user_input import validate_email from galaxy.security.validate_user_input import validate_password from galaxy.security.validate_user_input import validate_publicname @@ -24,6 +23,11 @@ log = logging.getLogger( __name__ ) class UserAPIController( BaseAPIController, UsesTagsMixin, CreatesUsersMixin, CreatesApiKeysMixin ): + def __init__(self, app): + super(UserAPIController, self).__init__(app) + self.user_manager = users.UserManager(app) + self.user_serializer = users.UserSerializer( app ) + @expose_api def index( self, trans, deleted='False', f_email=None, **kwd ): """ @@ -143,10 +147,27 @@ class UserAPIController( BaseAPIController, UsesTagsMixin, CreatesUsersMixin, Cr raise exceptions.NotImplemented() @expose_api - def delete( self, trans, **kwd ): - raise exceptions.NotImplemented() + @web.require_admin + def delete( self, trans, id, **kwd ): + """ + DELETE /api/users/{id} + delete the user with the given ``id`` + + :param id: the encoded id of the user to delete + :type id: str + + :param purge: (optional) if True, purge the user + :type purge: bool + """ + purge = util.string_as_bool(kwd.get('purge', False)) + if purge: + raise exceptions.NotImplemented('Purge option has not been implemented yet') + user = self.get_user(trans, id) + self.user_manager.delete(user) + return self.user_serializer.serialize_to_view(user, view='detailed') @expose_api + @web.require_admin def undelete( self, trans, **kwd ): raise exceptions.NotImplemented() From f700e38241d302406dde9c0eef9449ae2f054c6d Mon Sep 17 00:00:00 2001 From: Nicola Soranzo Date: Wed, 11 Nov 2015 18:43:58 +0000 Subject: [PATCH 3/4] Fix is_admin value in users API show method to show if the requested user is an admin, not the current user. --- lib/galaxy/webapps/galaxy/api/users.py | 11 +---------- 1 file changed, 1 insertion(+), 10 deletions(-) diff --git a/lib/galaxy/webapps/galaxy/api/users.py b/lib/galaxy/webapps/galaxy/api/users.py index a4cdd6e4203..37ec9f6d6fc 100644 --- a/lib/galaxy/webapps/galaxy/api/users.py +++ b/lib/galaxy/webapps/galaxy/api/users.py @@ -93,16 +93,7 @@ class UserAPIController( BaseAPIController, UsesTagsMixin, CreatesUsersMixin, Cr assert not user.deleted except: raise exceptions.RequestParameterInvalidException( 'Invalid user id specified', id=id ) - - item = user.to_dict( view='element', value_mapper={ 'id': trans.security.encode_id, - 'total_disk_usage': float } ) - # add a list of tags used by the user (as strings) - item[ 'tags_used' ] = self.get_user_tags_used( trans, user=user ) - # TODO: move into api_values (needs trans, tho - can we do that with api_keys/@property??) - # TODO: works with other users (from admin)?? - item[ 'quota_percent' ] = trans.app.quota_agent.get_percent( trans=trans ) - item[ 'is_admin' ] = trans.user_is_admin() - return item + return self.user_serializer.serialize_to_view(user, view='detailed') @expose_api def create( self, trans, payload, **kwd ): From d4e7c601a095c9138f5f5841b29d345c8b2d96a9 Mon Sep 17 00:00:00 2001 From: Nicola Soranzo Date: Wed, 11 Nov 2015 18:57:06 +0000 Subject: [PATCH 4/4] Add check for allow_user_deletion. --- lib/galaxy/webapps/galaxy/api/users.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/lib/galaxy/webapps/galaxy/api/users.py b/lib/galaxy/webapps/galaxy/api/users.py index 37ec9f6d6fc..6feb1a42994 100644 --- a/lib/galaxy/webapps/galaxy/api/users.py +++ b/lib/galaxy/webapps/galaxy/api/users.py @@ -150,6 +150,8 @@ class UserAPIController( BaseAPIController, UsesTagsMixin, CreatesUsersMixin, Cr :param purge: (optional) if True, purge the user :type purge: bool """ + if not trans.app.config.allow_user_deletion: + raise exceptions.ConfigDoesNotAllowException( 'The configuration of this Galaxy instance does not allow admins to delete users.' ) purge = util.string_as_bool(kwd.get('purge', False)) if purge: raise exceptions.NotImplemented('Purge option has not been implemented yet')