Make the user aware of permissions issues when they share a history.

This commit is contained in:
Nate Coraor
2008-09-16 13:53:07 -04:00
parent e7c4d75b34
commit 4e87b28149
2 changed files with 117 additions and 1 deletions
+34
View File
@@ -450,11 +450,45 @@ class RootController( BaseController ):
return trans.fill_template("/history/share.mako", histories=histories, email=email, send_to_err=send_to_err)
user = trans.get_user()
send_to_user = trans.app.model.User.get_by( email = email )
p = util.Params( kwd )
if p.action:
if p.action == "no_share":
trans.response.send_redirect( url_for( action='history_options' ) )
try:
send_to_group = trans.app.model.Group.select_by( name = send_to_user.email + ' private group' )[0]
except:
send_to_group = None
if not send_to_group:
return trans.show_error_message( "Couldn't locate %s's private group, please report this error." % user.email )
if not send_to_user:
send_to_err = "No such user"
elif user.email == email:
send_to_err = "You can't send histories to yourself"
else:
# if we're not checking or changing permissions, skip this step
if not p.action or ( p.action and p.action != 'share' ):
# ugly
can_change = {}
cannot_change = {}
for history in histories:
for dataset in history.active_datasets:
if not trans.app.security_agent.allow_action( send_to_user, trans.app.security_agent.permitted_actions.DATASET_ACCESS, dataset=dataset ):
if trans.app.security_agent.allow_action( user, trans.app.security_agent.permitted_actions.DATASET_MANAGE_PERMISSIONS, dataset=dataset ):
if p.action and p.action == "update":
trans.app.security_agent.associate_components( dataset=dataset, permissions=( send_to_group, [ trans.app.security_agent.permitted_actions.DATASET_ACCESS ] ) )
elif history not in can_change:
can_change[history] = [ dataset ]
else:
can_change[history].append( dataset )
else:
if p.action and p.action == "update":
pass # don't change stuff that the user doesn't have permission to change
elif history not in cannot_change:
cannot_change[history] = [ dataset ]
else:
cannot_change[history].append( dataset )
if can_change or cannot_change:
return trans.fill_template("/history/share.mako", histories=histories, email=email, send_to_err=send_to_err, can_change=can_change, cannot_change=cannot_change)
for history in histories:
new_history = history.copy( target_user=send_to_user )
new_history.name = history.name+" from "+user.email
+83 -1
View File
@@ -1,6 +1,7 @@
<%inherit file="/base.mako"/>
<%def name="title()">Share histories</%def>
%if not can_change and not cannot_change:
<div class="toolForm">
<div class="toolFormTitle">Share Histories</div>
<table>
@@ -27,4 +28,85 @@
<tr><td colspan="2" align="right"><input type="submit" name="history_share_btn" value="Submit"></td></tr>
</form>
</table>
</div>
</div>
%else:
<style type="text/css">
th
{
text-align: left;
}
td
{
vertical-align: top;
}
</style>
<form action="${h.url_for( action='history_share' )}" method="post">
%for history in histories:
<input type="hidden" name="id" value="${history.id}">
%endfor
<input type="hidden" name="email" value="${email}">
<div class="warningmessage">
The history or histories you've chosen to share contain datasets that the user you're sharing with does not have permission to access. These datasets are shown below. Datasets which the user already has permission to access are not shown.
</div>
<p/>
%if can_change:
<div class="donemessage">
The following datasets can be shared with ${email} by updating their permissions:
<p/>
<table cellpadding="0" cellspacing="8" border="0">
<tr><th>Histories</th><th>Datasets</th></tr>
%for history, datasets in can_change.items():
<tr>
<td>${history.name}</td>
<td>
%for dataset in datasets:
${dataset.name}<br/>
%endfor
</td>
</tr>
%endfor
</table>
</div>
<p/>
%endif
%if cannot_change:
<div class="errormessage">
The following datasets cannot be shared with ${email} because you do not have permission to change the permissions on them.
<p/>
<table cellpadding="0" cellspacing="8" border="0">
<tr><th>Histories</th><th>Datasets</th></tr>
%for history, datasets in cannot_change.items():
<tr>
<td>${history.name}</td>
<td>
%for dataset in datasets:
${dataset.name}<br/>
%endfor
</td>
</tr>
%endfor
</table>
</div>
<p/>
%endif
<div>
<b>How would you like to proceed?</b>
<p/>
%if can_change:
<input type="radio" name="action" value="update"> Change permissions
%if cannot_change:
(where possible)
%endif
<br/>
%endif
<input type="radio" name="action" value="share"> Share anyway
%if can_change:
(don't change any permissions)
%endif
<br/>
<input type="radio" name="action" value="no_share"> Don't share<br/>
<br/>
<input type="submit" name="submit" value="Ok"><br/>
</div>
</form>
%endif