From bf2405ba69ef458a0ff48c9442ae59ed2342bdc0 Mon Sep 17 00:00:00 2001 From: Greg Von Kuster Date: Wed, 27 Jan 2010 13:34:53 -0500 Subject: [PATCH] Some tweaks to the way roles are derived from the access permission on an item. --- lib/galaxy/security/__init__.py | 6 ++++-- lib/galaxy/web/controllers/library_common.py | 14 +++++++++++--- 2 files changed, 15 insertions(+), 5 deletions(-) diff --git a/lib/galaxy/security/__init__.py b/lib/galaxy/security/__init__.py index c34a9c24216..0472661ae45 100644 --- a/lib/galaxy/security/__init__.py +++ b/lib/galaxy/security/__init__.py @@ -138,13 +138,15 @@ class GalaxyRBACAgent( RBACAgent ): intermed.sort() return map( operator.getitem, intermed, ( -1, ) * len( intermed ) ) roles = set() - # If a library has roles associated with the LIBRARY_ACCESS permission, we need to start with them. + # If item has roles associated with the access permission, we need to start with them. access_roles = item.get_access_roles( trans ) for role in access_roles: roles.add( role ) # Each role potentially has users. We need to find all roles that each of those users have. for ura in role.users: - roles.add( ura.role ) + user = ura.user + for ura2 in user.roles: + roles.add( ura2.role ) # Each role also potentially has groups which, in turn, have members ( users ). We need to # find all roles that each group's members have. for gra in role.groups: diff --git a/lib/galaxy/web/controllers/library_common.py b/lib/galaxy/web/controllers/library_common.py index 0c018cbc905..9a8a9696b8c 100644 --- a/lib/galaxy/web/controllers/library_common.py +++ b/lib/galaxy/web/controllers/library_common.py @@ -489,10 +489,18 @@ class LibraryCommon( BaseController ): msg=util.sanitize_text( msg ), messagetype='error' ) ) lddas.append( ldda ) - # If the library is public all roles are legitimate, but if the library is restricted, only those - # roles associated with the LIBRARY_ACCESS permission are legitimate. library = trans.sa_session.query( trans.app.model.Library ).get( trans.security.decode_id( library_id ) ) - roles = trans.app.security_agent.get_legitimate_roles( trans, library ) + # If access to the dataset is restricted, then use the roles associated with the DATASET_ACCESS permission to + # determine the legitimate roles. If the dataset is public, see if access to the library is restricted. If + # it is, use the roles associated with the LIBRARY_ACCESS permission to determine the legitimate roles. If both + # the dataset and the library are public, all roles are legitimate. All of the datasets will have the same + # permissions at this point. + ldda = lddas[0] + if trans.app.security_agent.dataset_is_public( ldda.dataset ): + # The dataset is public, so check access to the library + roles = trans.app.security_agent.get_legitimate_roles( trans, library ) + else: + roles = trans.app.security_agent.get_legitimate_roles( trans, ldda.dataset ) if params.get( 'update_roles_button', False ): current_user_roles = trans.get_current_user_roles() if cntrller=='library_admin' or ( trans.app.security_agent.can_manage_library_item( current_user_roles, ldda ) and \