Some tweaks to the way roles are derived from the access permission on an item.

This commit is contained in:
Greg Von Kuster
2010-01-27 13:34:53 -05:00
parent 237c801655
commit bf2405ba69
2 changed files with 15 additions and 5 deletions
+4 -2
View File
@@ -138,13 +138,15 @@ class GalaxyRBACAgent( RBACAgent ):
intermed.sort()
return map( operator.getitem, intermed, ( -1, ) * len( intermed ) )
roles = set()
# If a library has roles associated with the LIBRARY_ACCESS permission, we need to start with them.
# If item has roles associated with the access permission, we need to start with them.
access_roles = item.get_access_roles( trans )
for role in access_roles:
roles.add( role )
# Each role potentially has users. We need to find all roles that each of those users have.
for ura in role.users:
roles.add( ura.role )
user = ura.user
for ura2 in user.roles:
roles.add( ura2.role )
# Each role also potentially has groups which, in turn, have members ( users ). We need to
# find all roles that each group's members have.
for gra in role.groups:
+11 -3
View File
@@ -489,10 +489,18 @@ class LibraryCommon( BaseController ):
msg=util.sanitize_text( msg ),
messagetype='error' ) )
lddas.append( ldda )
# If the library is public all roles are legitimate, but if the library is restricted, only those
# roles associated with the LIBRARY_ACCESS permission are legitimate.
library = trans.sa_session.query( trans.app.model.Library ).get( trans.security.decode_id( library_id ) )
roles = trans.app.security_agent.get_legitimate_roles( trans, library )
# If access to the dataset is restricted, then use the roles associated with the DATASET_ACCESS permission to
# determine the legitimate roles. If the dataset is public, see if access to the library is restricted. If
# it is, use the roles associated with the LIBRARY_ACCESS permission to determine the legitimate roles. If both
# the dataset and the library are public, all roles are legitimate. All of the datasets will have the same
# permissions at this point.
ldda = lddas[0]
if trans.app.security_agent.dataset_is_public( ldda.dataset ):
# The dataset is public, so check access to the library
roles = trans.app.security_agent.get_legitimate_roles( trans, library )
else:
roles = trans.app.security_agent.get_legitimate_roles( trans, ldda.dataset )
if params.get( 'update_roles_button', False ):
current_user_roles = trans.get_current_user_roles()
if cntrller=='library_admin' or ( trans.app.security_agent.can_manage_library_item( current_user_roles, ldda ) and \