runners/drmaa: configurable permissive mode for guest users 'allow_guests'

If enabled, anonymous and usernames that can't be mapped to the real
users will be permitted to run as a Galaxy user.
This commit is contained in:
Marek Vavrusa
2015-04-24 17:34:23 +02:00
parent 954276340c
commit ad97c4e83a
2 changed files with 11 additions and 1 deletions
+4
View File
@@ -236,6 +236,10 @@
</destination>
<destination id="remote_cluster" runner="drmaa" tags="longjobs"/>
<destination id="java_cluster" runner="drmaa">
<!-- Allow users that are not mapped to any real users to run jobs
as a Galaxy (fallback). Default is False.
-->
<param id="allow_guests">True</param>
<!-- Set to False if cluster nodes don't shared Galaxy library,
it will perform metadata calculation locally after the job finishes.
-->
+7 -1
View File
@@ -196,9 +196,15 @@ class DRMAAJobRunner( AsynchronousJobRunner ):
return
else:
job_wrapper.change_ownership_for_run()
# if user credentials are not available, use galaxy credentials
# if user credentials are not available, use galaxy credentials (if permitted)
allow_guests = asbool(job_wrapper.job_destination.params.get( "allow_guests", False) )
pwent = job_wrapper.user_system_pwent
if pwent is None:
if not allow_guests:
fail_msg = "User %s is not mapped to any real user, and not permitted to start jobs." % job_wrapper.user
job_wrapper.fail( fail_msg )
self.ds.deleteJobTemplate( jt )
return
pwent = job_wrapper.galaxy_system_pwent
log.debug( '(%s) submitting with credentials: %s [uid: %s]' % ( galaxy_id_tag, pwent[0], pwent[2] ) )
filename = self.store_jobtemplate(job_wrapper, jt)