jumpserver/apps/perms/serializers/permission.py

134 lines
4.9 KiB
Python
Raw Normal View History

2016-10-19 11:30:55 +00:00
# -*- coding: utf-8 -*-
#
2016-11-10 08:59:50 +00:00
from rest_framework import serializers
from rest_framework.fields import empty
2020-11-11 02:27:18 +00:00
from django.utils.translation import ugettext_lazy as _
2021-07-30 11:13:47 +00:00
from django.db.models import Q
2021-04-29 11:10:45 +00:00
2022-08-17 03:54:18 +00:00
from assets.models import Asset, Node
from users.models import User, UserGroup
from perms.models import AssetPermission, Action
from orgs.mixins.serializers import BulkOrgResourceModelSerializer
__all__ = ['AssetPermissionSerializer', 'ActionsField']
class ActionsField(serializers.MultipleChoiceField):
def __init__(self, **kwargs):
kwargs['choices'] = Action.CHOICES
super().__init__(**kwargs)
def run_validation(self, data=empty):
data = super(ActionsField, self).run_validation(data)
if isinstance(data, list):
data = Action.choices_to_value(value=data)
return data
def to_representation(self, value):
return Action.value_to_choices(value)
def to_internal_value(self, data):
if not self.allow_empty and not data:
self.fail('empty')
if not data:
return data
return Action.choices_to_value(data)
2016-11-04 10:33:16 +00:00
2019-06-30 12:10:34 +00:00
class ActionsDisplayField(ActionsField):
def to_representation(self, value):
values = super().to_representation(value)
choices = dict(Action.CHOICES)
return [choices.get(i) for i in values]
2019-06-30 12:10:34 +00:00
class AssetPermissionSerializer(BulkOrgResourceModelSerializer):
users_display = serializers.ListField(
child=serializers.CharField(), label=_('Users display'), required=False
)
user_groups_display = serializers.ListField(
child=serializers.CharField(), label=_('User groups display'), required=False
)
assets_display = serializers.ListField(
child=serializers.CharField(), label=_('Assets display'), required=False
)
nodes_display = serializers.ListField(
child=serializers.CharField(), label=_('Nodes display'), required=False
)
2021-07-30 11:13:47 +00:00
actions = ActionsField(required=False, allow_null=True, label=_("Actions"))
is_valid = serializers.BooleanField(read_only=True, label=_("Is valid"))
2021-03-11 12:09:23 +00:00
is_expired = serializers.BooleanField(read_only=True, label=_('Is expired'))
2018-04-10 12:29:06 +00:00
2018-02-01 09:14:15 +00:00
class Meta:
2018-04-08 12:02:40 +00:00
model = AssetPermission
fields_mini = ['id', 'name']
fields_small = fields_mini + [
'is_active', 'is_expired', 'is_valid', 'actions',
'accounts',
'created_by', 'date_created', 'date_expired',
2021-09-09 06:37:43 +00:00
'date_start', 'comment', 'from_ticket'
2020-05-09 06:51:19 +00:00
]
fields_m2m = [
2021-07-30 11:13:47 +00:00
'users', 'users_display', 'user_groups', 'user_groups_display', 'assets',
'assets_display', 'nodes', 'nodes_display',
'users_amount', 'user_groups_amount', 'assets_amount',
2022-07-28 10:50:58 +00:00
'nodes_amount',
2020-05-09 06:51:19 +00:00
]
fields = fields_small + fields_m2m
2021-09-09 06:37:43 +00:00
read_only_fields = ['created_by', 'date_created', 'from_ticket']
2020-11-11 02:27:18 +00:00
extra_kwargs = {
'users_amount': {'label': _('Users amount')},
'user_groups_amount': {'label': _('User groups amount')},
'assets_amount': {'label': _('Assets amount')},
'nodes_amount': {'label': _('Nodes amount')},
'actions': {'label': _('Actions')},
'is_expired': {'label': _('Is expired')},
'is_valid': {'label': _('Is valid')},
2020-11-11 02:27:18 +00:00
}
2020-05-09 06:51:19 +00:00
@classmethod
def setup_eager_loading(cls, queryset):
""" Perform necessary eager loading of data. """
2021-07-30 11:13:47 +00:00
queryset = queryset.prefetch_related(
2022-07-28 10:50:58 +00:00
'users', 'user_groups', 'assets', 'nodes',
2021-07-30 11:13:47 +00:00
)
2020-05-09 06:51:19 +00:00
return queryset
2021-07-30 11:13:47 +00:00
@staticmethod
def perform_display_create(instance, **kwargs):
# 用户
users_to_set = User.objects.filter(
2021-07-30 11:13:47 +00:00
Q(name__in=kwargs.get('users_display')) |
Q(username__in=kwargs.get('users_display'))
).distinct()
instance.users.add(*users_to_set)
# 用户组
2021-07-30 11:13:47 +00:00
user_groups_to_set = UserGroup.objects.filter(
name__in=kwargs.get('user_groups_display')
).distinct()
instance.user_groups.add(*user_groups_to_set)
# 资产
assets_to_set = Asset.objects.filter(
2021-07-30 11:13:47 +00:00
Q(ip__in=kwargs.get('assets_display')) |
Q(name__in=kwargs.get('assets_display'))
).distinct()
instance.assets.add(*assets_to_set)
# 节点
2021-07-30 11:13:47 +00:00
nodes_to_set = Node.objects.filter(
full_value__in=kwargs.get('nodes_display')
).distinct()
instance.nodes.add(*nodes_to_set)
def create(self, validated_data):
display = {
2021-07-30 11:13:47 +00:00
'users_display': validated_data.pop('users_display', ''),
'user_groups_display': validated_data.pop('user_groups_display', ''),
'assets_display': validated_data.pop('assets_display', ''),
'nodes_display': validated_data.pop('nodes_display', '')
}
instance = super().create(validated_data)
self.perform_display_create(instance, **display)
return instance
2021-04-29 11:10:45 +00:00