mirror of
https://github.com/galaxyproject/galaxy.git
synced 2026-09-24 16:30:27 +08:00
Some Fixes for setting permisions on the current history when users login, and some preparation for the database update script.
This commit is contained in:
+1
-1
@@ -26,7 +26,7 @@ class UniverseApplication( object ):
|
||||
self.model = galaxy.model.mapping.init( self.config.file_path,
|
||||
db_url,
|
||||
self.config.database_engine_options,
|
||||
create_tables = True )
|
||||
create_tables = self.config.database_create_tables )
|
||||
# Initialize the tools
|
||||
self.toolbox = tools.ToolBox( self.config.tool_config, self.config.tool_path, self )
|
||||
#Load datatype converters
|
||||
|
||||
@@ -27,6 +27,7 @@ class Configuration( object ):
|
||||
self.database = resolve_path( kwargs.get( "database_file", "database/universe.d" ), self.root )
|
||||
self.database_connection = kwargs.get( "database_connection", False )
|
||||
self.database_engine_options = get_database_engine_options( kwargs )
|
||||
self.database_create_tables = string_as_bool( kwargs.get( "database_create_tables", "True" ) )
|
||||
# Where dataset files are stored
|
||||
self.file_path = resolve_path( kwargs.get( "file_path", "database/files" ), self.root )
|
||||
self.new_file_path = resolve_path( kwargs.get( "new_file_path", "database/tmp" ), self.root )
|
||||
|
||||
+14
-13
@@ -640,11 +640,8 @@ def db_next_hid( self ):
|
||||
raise
|
||||
|
||||
History._next_hid = db_next_hid
|
||||
|
||||
def init( file_path, url, engine_options={}, create_tables=False ):
|
||||
"""Connect mappings to the database"""
|
||||
# Connect dataset to the file path
|
||||
Dataset.file_path = file_path
|
||||
|
||||
def load_egg_for_url( url ):
|
||||
# Load the appropriate db module
|
||||
dialect = (url.split(':', 1))[0]
|
||||
try:
|
||||
@@ -658,6 +655,13 @@ def init( file_path, url, engine_options={}, create_tables=False ):
|
||||
except KeyError:
|
||||
# Let this go, it could possibly work with db's we don't support
|
||||
log.error( "database_connection contains an unknown SQLAlchemy database dialect: %s" % dialect )
|
||||
|
||||
def init( file_path, url, engine_options={}, create_tables=False ):
|
||||
"""Connect mappings to the database"""
|
||||
# Connect dataset to the file path
|
||||
Dataset.file_path = file_path
|
||||
# Load the appropriate db module
|
||||
load_egg_for_url( url )
|
||||
# Create the database engine
|
||||
engine = create_engine( url, **engine_options )
|
||||
# Connect the metadata to the database.
|
||||
@@ -680,14 +684,11 @@ def init( file_path, url, engine_options={}, create_tables=False ):
|
||||
#load local galaxy security policy
|
||||
result.security_agent = GalaxyRBACAgent( result )
|
||||
# Create private roles if necessary.
|
||||
if not result.Role.query().all():
|
||||
for user in result.User.query().all():
|
||||
role = Role( name = user.email, description = 'Private Role for ' + user.email, type = 'private' )
|
||||
role.flush()
|
||||
ura = UserRoleAssociation( user = user, role = role )
|
||||
ura.flush()
|
||||
dup = DefaultUserPermissions( user = user, action = result.security_agent.permitted_actions.DATASET_MANAGE_PERMISSIONS.action, role = role )
|
||||
dup.flush()
|
||||
if create_tables: #This should be moved to the external update script
|
||||
if not result.Role.query().all():
|
||||
for user in result.User.query().all():
|
||||
result.security_agent.create_private_user_role( user )
|
||||
result.security_agent.user_set_default_permissions( user, history=True, dataset=True, bypass_manage_permission=True )
|
||||
return result
|
||||
|
||||
def get_suite():
|
||||
|
||||
@@ -165,7 +165,7 @@ class GalaxyRBACAgent( RBACAgent ):
|
||||
else:
|
||||
return None
|
||||
return role
|
||||
def user_set_default_permissions( self, user, permissions = {}, history=False, dataset=False ):
|
||||
def user_set_default_permissions( self, user, permissions = {}, history=False, dataset=False, bypass_manage_permission=False ):
|
||||
if user is None:
|
||||
return None
|
||||
if not permissions:
|
||||
@@ -183,7 +183,7 @@ class GalaxyRBACAgent( RBACAgent ):
|
||||
dup.flush()
|
||||
if history:
|
||||
for history in user.active_histories:
|
||||
self.history_set_default_permissions( history, permissions=permissions, dataset=dataset )
|
||||
self.history_set_default_permissions( history, permissions=permissions, dataset=dataset, bypass_manage_permission=bypass_manage_permission )
|
||||
def user_get_default_permissions( self, user ):
|
||||
perms = {}
|
||||
for action in self.get_actions():
|
||||
|
||||
@@ -157,7 +157,7 @@ class User( BaseController ):
|
||||
user.flush()
|
||||
trans.app.security_agent.create_private_user_role( user )
|
||||
trans.handle_user_login( user )
|
||||
trans.app.security_agent.user_set_default_permissions( user, history=True, dataset=True )
|
||||
#trans.app.security_agent.user_set_default_permissions( user, history=True, dataset=True, bypass_manage_permission=True ) #This is taken care of by trans.handle_user_login
|
||||
trans.log_event( "User created a new account" )
|
||||
trans.log_event( "User logged in" )
|
||||
#subscribe user to email list
|
||||
|
||||
@@ -343,7 +343,7 @@ class UniverseWebTransaction( base.DefaultWebTransaction ):
|
||||
if history.user is None:
|
||||
history.user = user
|
||||
self.galaxy_session.current_history = history
|
||||
self.app.security_agent.history_set_default_permissions( history, dataset=True )
|
||||
self.app.security_agent.history_set_default_permissions( history, dataset=True, bypass_manage_permission=True )
|
||||
self.sa_session.flush( [ prev_galaxy_session, self.galaxy_session, history ] )
|
||||
self.__update_session_cookie()
|
||||
def handle_user_logout( self ):
|
||||
|
||||
@@ -1,9 +1,12 @@
|
||||
#!/usr/bin/env python
|
||||
|
||||
import sys
|
||||
import sys, os
|
||||
|
||||
assert sys.version_info[:2] >= ( 2, 4 )
|
||||
|
||||
from eggs import get_full_platform, get_noplatform
|
||||
lib = os.path.abspath( os.path.join( os.path.dirname( __file__ ), "..", "lib" ) )
|
||||
sys.path.append( lib )
|
||||
|
||||
from galaxy.eggs import get_platform, get_noplatform
|
||||
print get_noplatform()
|
||||
print get_full_platform()
|
||||
print get_platform( platform=True )
|
||||
|
||||
Reference in New Issue
Block a user