From ad97c4e83acd8afb32e30c016b448ef7c7d1d204 Mon Sep 17 00:00:00 2001 From: Marek Vavrusa Date: Fri, 24 Apr 2015 17:34:23 +0200 Subject: [PATCH] runners/drmaa: configurable permissive mode for guest users 'allow_guests' If enabled, anonymous and usernames that can't be mapped to the real users will be permitted to run as a Galaxy user. --- config/job_conf.xml.sample_advanced | 4 ++++ lib/galaxy/jobs/runners/drmaa.py | 8 +++++++- 2 files changed, 11 insertions(+), 1 deletion(-) diff --git a/config/job_conf.xml.sample_advanced b/config/job_conf.xml.sample_advanced index d50265e00be..132f9edff5b 100644 --- a/config/job_conf.xml.sample_advanced +++ b/config/job_conf.xml.sample_advanced @@ -236,6 +236,10 @@ + + True diff --git a/lib/galaxy/jobs/runners/drmaa.py b/lib/galaxy/jobs/runners/drmaa.py index a453e4953e6..488ef93d8ec 100644 --- a/lib/galaxy/jobs/runners/drmaa.py +++ b/lib/galaxy/jobs/runners/drmaa.py @@ -196,9 +196,15 @@ class DRMAAJobRunner( AsynchronousJobRunner ): return else: job_wrapper.change_ownership_for_run() - # if user credentials are not available, use galaxy credentials + # if user credentials are not available, use galaxy credentials (if permitted) + allow_guests = asbool(job_wrapper.job_destination.params.get( "allow_guests", False) ) pwent = job_wrapper.user_system_pwent if pwent is None: + if not allow_guests: + fail_msg = "User %s is not mapped to any real user, and not permitted to start jobs." % job_wrapper.user + job_wrapper.fail( fail_msg ) + self.ds.deleteJobTemplate( jt ) + return pwent = job_wrapper.galaxy_system_pwent log.debug( '(%s) submitting with credentials: %s [uid: %s]' % ( galaxy_id_tag, pwent[0], pwent[2] ) ) filename = self.store_jobtemplate(job_wrapper, jt)