From f1b591f3be8c574d2513ea75d18eaaf5a439687d Mon Sep 17 00:00:00 2001 From: Daniel Blankenberg Date: Wed, 3 Dec 2008 17:16:40 -0500 Subject: [PATCH] Some Fixes for setting permisions on the current history when users login, and some preparation for the database update script. --- lib/galaxy/app.py | 2 +- lib/galaxy/config.py | 1 + lib/galaxy/model/mapping.py | 27 ++++++++++++++------------- lib/galaxy/security/__init__.py | 4 ++-- lib/galaxy/web/controllers/user.py | 2 +- lib/galaxy/web/framework/__init__.py | 2 +- scripts/get_platforms.py | 9 ++++++--- 7 files changed, 26 insertions(+), 21 deletions(-) diff --git a/lib/galaxy/app.py b/lib/galaxy/app.py index 21d0357b8ad..4f6ba65b916 100644 --- a/lib/galaxy/app.py +++ b/lib/galaxy/app.py @@ -26,7 +26,7 @@ class UniverseApplication( object ): self.model = galaxy.model.mapping.init( self.config.file_path, db_url, self.config.database_engine_options, - create_tables = True ) + create_tables = self.config.database_create_tables ) # Initialize the tools self.toolbox = tools.ToolBox( self.config.tool_config, self.config.tool_path, self ) #Load datatype converters diff --git a/lib/galaxy/config.py b/lib/galaxy/config.py index 332c16a2491..1eb4ff55076 100644 --- a/lib/galaxy/config.py +++ b/lib/galaxy/config.py @@ -27,6 +27,7 @@ class Configuration( object ): self.database = resolve_path( kwargs.get( "database_file", "database/universe.d" ), self.root ) self.database_connection = kwargs.get( "database_connection", False ) self.database_engine_options = get_database_engine_options( kwargs ) + self.database_create_tables = string_as_bool( kwargs.get( "database_create_tables", "True" ) ) # Where dataset files are stored self.file_path = resolve_path( kwargs.get( "file_path", "database/files" ), self.root ) self.new_file_path = resolve_path( kwargs.get( "new_file_path", "database/tmp" ), self.root ) diff --git a/lib/galaxy/model/mapping.py b/lib/galaxy/model/mapping.py index 760dfdb755c..911117542ee 100644 --- a/lib/galaxy/model/mapping.py +++ b/lib/galaxy/model/mapping.py @@ -640,11 +640,8 @@ def db_next_hid( self ): raise History._next_hid = db_next_hid - -def init( file_path, url, engine_options={}, create_tables=False ): - """Connect mappings to the database""" - # Connect dataset to the file path - Dataset.file_path = file_path + +def load_egg_for_url( url ): # Load the appropriate db module dialect = (url.split(':', 1))[0] try: @@ -658,6 +655,13 @@ def init( file_path, url, engine_options={}, create_tables=False ): except KeyError: # Let this go, it could possibly work with db's we don't support log.error( "database_connection contains an unknown SQLAlchemy database dialect: %s" % dialect ) + +def init( file_path, url, engine_options={}, create_tables=False ): + """Connect mappings to the database""" + # Connect dataset to the file path + Dataset.file_path = file_path + # Load the appropriate db module + load_egg_for_url( url ) # Create the database engine engine = create_engine( url, **engine_options ) # Connect the metadata to the database. @@ -680,14 +684,11 @@ def init( file_path, url, engine_options={}, create_tables=False ): #load local galaxy security policy result.security_agent = GalaxyRBACAgent( result ) # Create private roles if necessary. - if not result.Role.query().all(): - for user in result.User.query().all(): - role = Role( name = user.email, description = 'Private Role for ' + user.email, type = 'private' ) - role.flush() - ura = UserRoleAssociation( user = user, role = role ) - ura.flush() - dup = DefaultUserPermissions( user = user, action = result.security_agent.permitted_actions.DATASET_MANAGE_PERMISSIONS.action, role = role ) - dup.flush() + if create_tables: #This should be moved to the external update script + if not result.Role.query().all(): + for user in result.User.query().all(): + result.security_agent.create_private_user_role( user ) + result.security_agent.user_set_default_permissions( user, history=True, dataset=True, bypass_manage_permission=True ) return result def get_suite(): diff --git a/lib/galaxy/security/__init__.py b/lib/galaxy/security/__init__.py index e21aa24c759..706f4aea16a 100644 --- a/lib/galaxy/security/__init__.py +++ b/lib/galaxy/security/__init__.py @@ -165,7 +165,7 @@ class GalaxyRBACAgent( RBACAgent ): else: return None return role - def user_set_default_permissions( self, user, permissions = {}, history=False, dataset=False ): + def user_set_default_permissions( self, user, permissions = {}, history=False, dataset=False, bypass_manage_permission=False ): if user is None: return None if not permissions: @@ -183,7 +183,7 @@ class GalaxyRBACAgent( RBACAgent ): dup.flush() if history: for history in user.active_histories: - self.history_set_default_permissions( history, permissions=permissions, dataset=dataset ) + self.history_set_default_permissions( history, permissions=permissions, dataset=dataset, bypass_manage_permission=bypass_manage_permission ) def user_get_default_permissions( self, user ): perms = {} for action in self.get_actions(): diff --git a/lib/galaxy/web/controllers/user.py b/lib/galaxy/web/controllers/user.py index ca4542eb2bc..616fdf8105e 100644 --- a/lib/galaxy/web/controllers/user.py +++ b/lib/galaxy/web/controllers/user.py @@ -157,7 +157,7 @@ class User( BaseController ): user.flush() trans.app.security_agent.create_private_user_role( user ) trans.handle_user_login( user ) - trans.app.security_agent.user_set_default_permissions( user, history=True, dataset=True ) + #trans.app.security_agent.user_set_default_permissions( user, history=True, dataset=True, bypass_manage_permission=True ) #This is taken care of by trans.handle_user_login trans.log_event( "User created a new account" ) trans.log_event( "User logged in" ) #subscribe user to email list diff --git a/lib/galaxy/web/framework/__init__.py b/lib/galaxy/web/framework/__init__.py index 59324a80479..ff516f2c441 100644 --- a/lib/galaxy/web/framework/__init__.py +++ b/lib/galaxy/web/framework/__init__.py @@ -343,7 +343,7 @@ class UniverseWebTransaction( base.DefaultWebTransaction ): if history.user is None: history.user = user self.galaxy_session.current_history = history - self.app.security_agent.history_set_default_permissions( history, dataset=True ) + self.app.security_agent.history_set_default_permissions( history, dataset=True, bypass_manage_permission=True ) self.sa_session.flush( [ prev_galaxy_session, self.galaxy_session, history ] ) self.__update_session_cookie() def handle_user_logout( self ): diff --git a/scripts/get_platforms.py b/scripts/get_platforms.py index be75ca87698..3bccb74992b 100755 --- a/scripts/get_platforms.py +++ b/scripts/get_platforms.py @@ -1,9 +1,12 @@ #!/usr/bin/env python -import sys +import sys, os assert sys.version_info[:2] >= ( 2, 4 ) -from eggs import get_full_platform, get_noplatform +lib = os.path.abspath( os.path.join( os.path.dirname( __file__ ), "..", "lib" ) ) +sys.path.append( lib ) + +from galaxy.eggs import get_platform, get_noplatform print get_noplatform() -print get_full_platform() +print get_platform( platform=True )