mirror of
https://github.com/galaxyproject/galaxy.git
synced 2026-09-24 16:30:27 +08:00
Bugfix: Allow administrators to create users when use_remote_user is enabled.
This commit is contained in:
@@ -139,7 +139,9 @@ def wrap_in_middleware( app, global_conf, **local_conf ):
|
||||
# upstream server
|
||||
if asbool(conf.get( 'use_remote_user', False )):
|
||||
from galaxy.web.framework.middleware.remoteuser import RemoteUser
|
||||
app = RemoteUser( app, maildomain=conf.get( 'remote_user_maildomain', None ), ucsc_display_sites=conf.get( 'ucsc_display_sites', [] ) )
|
||||
app = RemoteUser( app, maildomain=conf.get( 'remote_user_maildomain', None ),
|
||||
ucsc_display_sites=conf.get( 'ucsc_display_sites', [] ),
|
||||
admin_users=conf.get( 'admin_users', '' ).split( ',' ) )
|
||||
log.debug( "Enabling 'remote user' middleware" )
|
||||
# The recursive middleware allows for including requests in other
|
||||
# requests or forwarding of requests, all on the server side.
|
||||
|
||||
@@ -50,11 +50,12 @@ UCSC_ARCHAEA_SERVERS = (
|
||||
)
|
||||
|
||||
class RemoteUser( object ):
|
||||
def __init__( self, app, maildomain=None, ucsc_display_sites=[] ):
|
||||
def __init__( self, app, maildomain=None, ucsc_display_sites=[], admin_users=[] ):
|
||||
self.app = app
|
||||
self.maildomain = maildomain
|
||||
self.allow_ucsc_main = False
|
||||
self.allow_ucsc_archaea = False
|
||||
self.admin_users = admin_users
|
||||
if 'main' in ucsc_display_sites or 'test' in ucsc_display_sites:
|
||||
self.allow_ucsc_main = True
|
||||
if 'archaea' in ucsc_display_sites:
|
||||
@@ -76,14 +77,7 @@ class RemoteUser( object ):
|
||||
# un-authenticated. Any other possible values need to go here as well.
|
||||
if environ.has_key( 'HTTP_REMOTE_USER' ) and environ[ 'HTTP_REMOTE_USER' ] != '(null)':
|
||||
path_info = environ.get('PATH_INFO', '')
|
||||
if path_info.startswith( '/user' ):
|
||||
title = "Access to Galaxy user controls is disabled"
|
||||
message = """
|
||||
User controls are disabled when Galaxy is configured
|
||||
for external authentication.
|
||||
"""
|
||||
return self.error( start_response, title, message )
|
||||
elif not environ[ 'HTTP_REMOTE_USER' ].count( '@' ):
|
||||
if not environ[ 'HTTP_REMOTE_USER' ].count( '@' ):
|
||||
if self.maildomain is not None:
|
||||
environ[ 'HTTP_REMOTE_USER' ] += '@' + self.maildomain
|
||||
else:
|
||||
@@ -99,6 +93,15 @@ class RemoteUser( object ):
|
||||
before you may access Galaxy.
|
||||
"""
|
||||
return self.error( start_response, title, message )
|
||||
if path_info.startswith( '/user/create' ) and environ[ 'HTTP_REMOTE_USER' ] in self.admin_users:
|
||||
pass # admins can create users
|
||||
elif path_info.startswith( '/user' ):
|
||||
title = "Access to Galaxy user controls is disabled"
|
||||
message = """
|
||||
User controls are disabled when Galaxy is configured
|
||||
for external authentication.
|
||||
"""
|
||||
return self.error( start_response, title, message )
|
||||
return self.app( environ, start_response )
|
||||
else:
|
||||
title = "Access to Galaxy is denied"
|
||||
|
||||
Reference in New Issue
Block a user