mirror of
https://github.com/galaxyproject/galaxy.git
synced 2026-09-24 16:30:27 +08:00
Allow administrators to impersonate other users. Useful for debugging, but be aware that this gives said administrator a full session as the user, with the ability to do anything as that user (the user does not gain the administrator's privileges, however).
This commit is contained in:
@@ -71,6 +71,7 @@ class Configuration( object ):
|
||||
self.allow_user_creation = string_as_bool( kwargs.get( "allow_user_creation", "True" ) )
|
||||
self.allow_user_deletion = string_as_bool( kwargs.get( "allow_user_deletion", "False" ) )
|
||||
self.allow_user_dataset_purge = string_as_bool( kwargs.get( "allow_user_dataset_purge", "False" ) )
|
||||
self.allow_user_impersonation = string_as_bool( kwargs.get( "allow_user_impersonation", "False" ) )
|
||||
self.new_user_dataset_access_role_default_private = string_as_bool( kwargs.get( "new_user_dataset_access_role_default_private", "False" ) )
|
||||
self.template_path = resolve_path( kwargs.get( "template_path", "templates" ), self.root )
|
||||
self.template_cache = resolve_path( kwargs.get( "template_cache_path", "database/compiled_templates" ), self.root )
|
||||
|
||||
@@ -1029,6 +1029,27 @@ class AdminGalaxy( BaseUIController, Admin, AdminActions, UsesQuota, QuotaParamP
|
||||
id=trans.security.encode_id( repository.id ),
|
||||
message=message,
|
||||
status=status ) )
|
||||
@web.expose
|
||||
@web.require_admin
|
||||
def impersonate( self, trans, email=None, **kwd ):
|
||||
if not trans.app.config.allow_user_impersonation:
|
||||
return trans.show_error_message( "User impersonation is not enabled in this instance of Galaxy." )
|
||||
message = ''
|
||||
status = 'done'
|
||||
emails = None
|
||||
if email is not None:
|
||||
user = trans.sa_session.query( trans.app.model.User ).filter_by( email=email ).first()
|
||||
if user:
|
||||
trans.set_user( user )
|
||||
message = 'You are now logged in as %s, <a target="_top" href="%s">return to the home page</a>' % ( email, url_for( controller='root' ) )
|
||||
emails = []
|
||||
else:
|
||||
message = 'Invalid user selected'
|
||||
status = 'error'
|
||||
if emails is None:
|
||||
emails = [ u.email for u in trans.sa_session.query( trans.app.model.User ).enable_eagerloads( False ).all() ]
|
||||
return trans.fill_template( 'admin/impersonate.mako', emails=emails, message=message, status=status )
|
||||
|
||||
def __get_relative_install_dir( self, trans, repository ):
|
||||
# Get the directory where the repository is install.
|
||||
tool_shed = self.__clean_tool_shed_url( repository.tool_shed )
|
||||
|
||||
@@ -46,6 +46,9 @@
|
||||
<div class="toolTitle"><a href="${h.url_for( controller='admin', action='users', webapp=webapp )}" target="galaxy_main">Manage users</a></div>
|
||||
<div class="toolTitle"><a href="${h.url_for( controller='admin', action='groups', webapp=webapp )}" target="galaxy_main">Manage groups</a></div>
|
||||
<div class="toolTitle"><a href="${h.url_for( controller='admin', action='roles', webapp=webapp )}" target="galaxy_main">Manage roles</a></div>
|
||||
%if trans.app.config.allow_user_impersonation:
|
||||
<div class="toolTitle"><a href="${h.url_for( controller='admin', action='impersonate', webapp=webapp )}" target="galaxy_main">Impersonate a user</a></div>
|
||||
%endif
|
||||
</div>
|
||||
</div>
|
||||
<div class="toolSectionPad"></div>
|
||||
|
||||
@@ -405,6 +405,9 @@ use_interactive = True
|
||||
# Allow administrators to delete accounts.
|
||||
#allow_user_deletion = False
|
||||
|
||||
# Allow administrators to log in as other users (useful for debugging)
|
||||
#allow_user_impersonation = False
|
||||
|
||||
# Allow users to remove their datasets from disk immediately (otherwise,
|
||||
# datasets will be removed after a time period specified by an administrator in
|
||||
# the cleanup scripts run via cron)
|
||||
|
||||
Reference in New Issue
Block a user