diff --git a/lib/galaxy/web/api/histories.py b/lib/galaxy/web/api/histories.py index 59a45da2760..ee1b21b3867 100644 --- a/lib/galaxy/web/api/histories.py +++ b/lib/galaxy/web/api/histories.py @@ -109,6 +109,7 @@ class HistoriesController( BaseAPIController, UsesHistoryMixin ): trans.sa_session.add( new_history ) trans.sa_session.flush() item = new_history.get_api_value(view='element', value_mapper={'id':trans.security.encode_id}) + item['url'] = url_for( 'history', id=item['id'] ) return item @web.expose_api diff --git a/lib/galaxy/web/api/libraries.py b/lib/galaxy/web/api/libraries.py index cefdf7b3ebe..98208efaf74 100644 --- a/lib/galaxy/web/api/libraries.py +++ b/lib/galaxy/web/api/libraries.py @@ -98,7 +98,7 @@ class LibrariesController( BaseAPIController ): rval['url'] = url_for( 'library', id=encoded_id ) rval['name'] = name rval['id'] = encoded_id - return [ rval ] + return rval @web.expose_api def delete( self, trans, id, **kwd ): diff --git a/lib/galaxy/web/api/permissions.py b/lib/galaxy/web/api/permissions.py index b9ab5213fd9..61665fc8156 100644 --- a/lib/galaxy/web/api/permissions.py +++ b/lib/galaxy/web/api/permissions.py @@ -40,10 +40,10 @@ class PermissionsController( BaseAPIController ): role_params = params.get( k + '_in', [] ) in_roles = [ trans.sa_session.query( trans.app.model.Role ).get( trans.security.decode_id( x ) ) for x in util.listify( role_params ) ] permissions[ trans.app.security_agent.get_action( v.action ) ] = in_roles - trans.app.security_agent.set_all_library_permissions( library, permissions ) + trans.app.security_agent.set_all_library_permissions( trans, library, permissions ) trans.sa_session.refresh( library ) # Copy the permissions to the root folder - trans.app.security_agent.copy_library_permissions( library, library.root_folder ) + trans.app.security_agent.copy_library_permissions( trans, library, library.root_folder ) message = "Permissions updated for library '%s'." % library.name item = library.get_api_value( view='element' ) diff --git a/lib/galaxy/web/api/roles.py b/lib/galaxy/web/api/roles.py index fdd3066e114..c1eb1ad862f 100644 --- a/lib/galaxy/web/api/roles.py +++ b/lib/galaxy/web/api/roles.py @@ -17,7 +17,7 @@ class RoleAPIController( BaseAPIController ): """ rval = [] for role in trans.sa_session.query( trans.app.model.Role ).filter( trans.app.model.Role.table.c.deleted == False ): - if trans.app.security_agent.ok_to_display( trans.user, role ): + if trans.user_is_admin() or trans.app.security_agent.ok_to_display( trans.user, role ): item = role.get_api_value( value_mapper={ 'id': trans.security.encode_id } ) encoded_id = trans.security.encode_id( role.id ) item['url'] = url_for( 'role', id=encoded_id ) @@ -32,7 +32,7 @@ class RoleAPIController( BaseAPIController ): """ role_id = id try: - role_id = trans.security.decode_id( role_id ) + decoded_role_id = trans.security.decode_id( role_id ) except TypeError: trans.response.status = 400 return "Malformed role id ( %s ) specified, unable to decode." % str( role_id ) @@ -40,7 +40,7 @@ class RoleAPIController( BaseAPIController ): role = trans.sa_session.query( trans.app.model.Role ).get( decoded_role_id ) except: role = None - if not role or not trans.app.security_agent.ok_to_display( trans.user, role ): + if not role or not (trans.user_is_admin() or trans.app.security_agent.ok_to_display( trans.user, role )): trans.response.status = 400 return "Invalid role id ( %s ) specified." % str( role_id ) item = role.get_api_value( view='element', value_mapper={ 'id': trans.security.encode_id } )