2018-02-06 10:32:02 +00:00
|
|
|
# ~*~ coding: utf-8 ~*~
|
|
|
|
# Copyright (C) 2014-2018 Beijing DuiZhan Technology Co.,Ltd. All Rights Reserved.
|
|
|
|
#
|
|
|
|
# Licensed under the GNU General Public License v2.0 (the "License");
|
|
|
|
# you may not use this file except in compliance with the License.
|
|
|
|
# You may obtain a copy of the License at
|
|
|
|
#
|
|
|
|
# http://www.gnu.org/licenses/gpl-2.0.html
|
|
|
|
#
|
|
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
# See the License for the specific language governing permissions and
|
|
|
|
# limitations under the License.
|
|
|
|
|
2018-09-03 03:24:25 +00:00
|
|
|
from django.shortcuts import get_object_or_404
|
2019-11-12 11:00:53 +00:00
|
|
|
from django.conf import settings
|
2018-02-06 10:32:02 +00:00
|
|
|
from rest_framework.response import Response
|
2018-07-23 04:55:13 +00:00
|
|
|
|
2019-08-21 12:27:21 +00:00
|
|
|
from common.serializers import CeleryTaskSerializer
|
2018-02-06 10:32:02 +00:00
|
|
|
from common.utils import get_logger
|
2019-11-12 11:00:53 +00:00
|
|
|
from common.permissions import IsOrgAdmin, IsOrgAdminOrAppUser, NeedMFAVerify
|
2019-08-21 12:27:21 +00:00
|
|
|
from orgs.mixins.api import OrgBulkModelViewSet
|
2019-10-18 07:05:45 +00:00
|
|
|
from orgs.mixins import generics
|
2018-09-03 03:24:25 +00:00
|
|
|
from ..models import SystemUser, Asset
|
2018-02-06 10:32:02 +00:00
|
|
|
from .. import serializers
|
2019-08-21 12:27:21 +00:00
|
|
|
from ..tasks import (
|
|
|
|
push_system_user_to_assets_manual, test_system_user_connectivity_manual,
|
|
|
|
push_system_user_a_asset_manual, test_system_user_connectivity_a_asset,
|
|
|
|
)
|
2018-02-06 10:32:02 +00:00
|
|
|
|
|
|
|
|
|
|
|
logger = get_logger(__file__)
|
|
|
|
__all__ = [
|
2019-03-18 02:15:33 +00:00
|
|
|
'SystemUserViewSet', 'SystemUserAuthInfoApi', 'SystemUserAssetAuthInfoApi',
|
2018-09-03 03:24:25 +00:00
|
|
|
'SystemUserPushApi', 'SystemUserTestConnectiveApi',
|
|
|
|
'SystemUserAssetsListView', 'SystemUserPushToAssetApi',
|
2018-12-18 09:28:45 +00:00
|
|
|
'SystemUserTestAssetConnectivityApi', 'SystemUserCommandFilterRuleListApi',
|
2018-10-10 07:37:20 +00:00
|
|
|
|
2018-02-06 10:32:02 +00:00
|
|
|
]
|
|
|
|
|
|
|
|
|
2019-07-04 07:36:57 +00:00
|
|
|
class SystemUserViewSet(OrgBulkModelViewSet):
|
2018-02-06 10:32:02 +00:00
|
|
|
"""
|
|
|
|
System user api set, for add,delete,update,list,retrieve resource
|
|
|
|
"""
|
2019-10-18 07:05:45 +00:00
|
|
|
model = SystemUser
|
2018-10-31 07:31:09 +00:00
|
|
|
filter_fields = ("name", "username")
|
|
|
|
search_fields = filter_fields
|
2018-02-06 10:32:02 +00:00
|
|
|
serializer_class = serializers.SystemUserSerializer
|
2018-07-23 04:55:13 +00:00
|
|
|
permission_classes = (IsOrgAdminOrAppUser,)
|
2018-10-31 07:31:09 +00:00
|
|
|
|
2018-02-06 10:32:02 +00:00
|
|
|
|
2018-05-17 03:39:04 +00:00
|
|
|
class SystemUserAuthInfoApi(generics.RetrieveUpdateDestroyAPIView):
|
2018-02-06 10:32:02 +00:00
|
|
|
"""
|
|
|
|
Get system user auth info
|
|
|
|
"""
|
2019-10-18 07:05:45 +00:00
|
|
|
model = SystemUser
|
2018-07-23 04:55:13 +00:00
|
|
|
permission_classes = (IsOrgAdminOrAppUser,)
|
2018-03-09 04:53:08 +00:00
|
|
|
serializer_class = serializers.SystemUserAuthSerializer
|
2018-02-06 10:32:02 +00:00
|
|
|
|
2018-05-17 03:39:04 +00:00
|
|
|
def destroy(self, request, *args, **kwargs):
|
|
|
|
instance = self.get_object()
|
|
|
|
instance.clear_auth()
|
|
|
|
return Response(status=204)
|
|
|
|
|
2018-02-06 10:32:02 +00:00
|
|
|
|
2019-03-18 02:15:33 +00:00
|
|
|
class SystemUserAssetAuthInfoApi(generics.RetrieveAPIView):
|
|
|
|
"""
|
|
|
|
Get system user with asset auth info
|
|
|
|
"""
|
2019-10-18 07:05:45 +00:00
|
|
|
model = SystemUser
|
2019-03-18 02:15:33 +00:00
|
|
|
permission_classes = (IsOrgAdminOrAppUser,)
|
|
|
|
serializer_class = serializers.SystemUserAuthSerializer
|
|
|
|
|
2019-11-12 11:00:53 +00:00
|
|
|
def get_permissions(self):
|
|
|
|
if settings.CONFIG.SECURITY_VIEW_AUTH_NEED_MFA:
|
|
|
|
self.permission_classes = (IsOrgAdminOrAppUser, NeedMFAVerify)
|
|
|
|
return super().get_permissions()
|
|
|
|
|
2019-03-18 02:15:33 +00:00
|
|
|
def get_object(self):
|
|
|
|
instance = super().get_object()
|
|
|
|
aid = self.kwargs.get('aid')
|
|
|
|
asset = get_object_or_404(Asset, pk=aid)
|
|
|
|
instance.load_specific_asset_auth(asset)
|
|
|
|
return instance
|
|
|
|
|
|
|
|
|
2018-02-06 10:32:02 +00:00
|
|
|
class SystemUserPushApi(generics.RetrieveAPIView):
|
|
|
|
"""
|
|
|
|
Push system user to cluster assets api
|
|
|
|
"""
|
2019-10-18 07:05:45 +00:00
|
|
|
model = SystemUser
|
2018-07-23 04:55:13 +00:00
|
|
|
permission_classes = (IsOrgAdmin,)
|
2019-08-21 12:27:21 +00:00
|
|
|
serializer_class = CeleryTaskSerializer
|
2018-02-06 10:32:02 +00:00
|
|
|
|
|
|
|
def retrieve(self, request, *args, **kwargs):
|
|
|
|
system_user = self.get_object()
|
2018-05-09 09:35:46 +00:00
|
|
|
nodes = system_user.nodes.all()
|
|
|
|
for node in nodes:
|
|
|
|
system_user.assets.add(*tuple(node.get_all_assets()))
|
2018-04-02 08:55:39 +00:00
|
|
|
task = push_system_user_to_assets_manual.delay(system_user)
|
|
|
|
return Response({"task": task.id})
|
2018-02-06 10:32:02 +00:00
|
|
|
|
|
|
|
|
|
|
|
class SystemUserTestConnectiveApi(generics.RetrieveAPIView):
|
|
|
|
"""
|
|
|
|
Push system user to cluster assets api
|
|
|
|
"""
|
2019-10-18 07:05:45 +00:00
|
|
|
model = SystemUser
|
2018-07-23 04:55:13 +00:00
|
|
|
permission_classes = (IsOrgAdmin,)
|
2019-08-21 12:27:21 +00:00
|
|
|
serializer_class = CeleryTaskSerializer
|
2018-02-06 10:32:02 +00:00
|
|
|
|
|
|
|
def retrieve(self, request, *args, **kwargs):
|
|
|
|
system_user = self.get_object()
|
2018-12-18 09:28:45 +00:00
|
|
|
task = test_system_user_connectivity_manual.delay(system_user)
|
2018-04-02 08:55:39 +00:00
|
|
|
return Response({"task": task.id})
|
2018-09-03 03:24:25 +00:00
|
|
|
|
|
|
|
|
|
|
|
class SystemUserAssetsListView(generics.ListAPIView):
|
|
|
|
permission_classes = (IsOrgAdmin,)
|
2018-12-18 09:28:45 +00:00
|
|
|
serializer_class = serializers.AssetSimpleSerializer
|
2018-09-03 03:24:25 +00:00
|
|
|
filter_fields = ("hostname", "ip")
|
2018-12-18 09:28:45 +00:00
|
|
|
http_method_names = ['get']
|
2018-09-03 03:24:25 +00:00
|
|
|
search_fields = filter_fields
|
|
|
|
|
|
|
|
def get_object(self):
|
|
|
|
pk = self.kwargs.get('pk')
|
|
|
|
return get_object_or_404(SystemUser, pk=pk)
|
|
|
|
|
|
|
|
def get_queryset(self):
|
|
|
|
system_user = self.get_object()
|
|
|
|
return system_user.assets.all()
|
|
|
|
|
|
|
|
|
|
|
|
class SystemUserPushToAssetApi(generics.RetrieveAPIView):
|
2019-10-18 07:05:45 +00:00
|
|
|
model = SystemUser
|
2018-09-03 03:24:25 +00:00
|
|
|
permission_classes = (IsOrgAdmin,)
|
2019-01-15 02:23:30 +00:00
|
|
|
serializer_class = serializers.TaskIDSerializer
|
2018-09-03 03:24:25 +00:00
|
|
|
|
|
|
|
def retrieve(self, request, *args, **kwargs):
|
|
|
|
system_user = self.get_object()
|
|
|
|
asset_id = self.kwargs.get('aid')
|
|
|
|
asset = get_object_or_404(Asset, id=asset_id)
|
|
|
|
task = push_system_user_a_asset_manual.delay(system_user, asset)
|
|
|
|
return Response({"task": task.id})
|
|
|
|
|
|
|
|
|
2018-12-18 09:28:45 +00:00
|
|
|
class SystemUserTestAssetConnectivityApi(generics.RetrieveAPIView):
|
2019-10-18 07:05:45 +00:00
|
|
|
model = SystemUser
|
2018-09-03 03:24:25 +00:00
|
|
|
permission_classes = (IsOrgAdmin,)
|
2019-01-15 02:23:30 +00:00
|
|
|
serializer_class = serializers.TaskIDSerializer
|
2018-09-03 03:24:25 +00:00
|
|
|
|
|
|
|
def retrieve(self, request, *args, **kwargs):
|
|
|
|
system_user = self.get_object()
|
|
|
|
asset_id = self.kwargs.get('aid')
|
|
|
|
asset = get_object_or_404(Asset, id=asset_id)
|
2018-12-18 09:28:45 +00:00
|
|
|
task = test_system_user_connectivity_a_asset.delay(system_user, asset)
|
2018-10-10 07:37:20 +00:00
|
|
|
return Response({"task": task.id})
|
|
|
|
|
|
|
|
|
|
|
|
class SystemUserCommandFilterRuleListApi(generics.ListAPIView):
|
|
|
|
permission_classes = (IsOrgAdminOrAppUser,)
|
|
|
|
|
|
|
|
def get_serializer_class(self):
|
|
|
|
from ..serializers import CommandFilterRuleSerializer
|
|
|
|
return CommandFilterRuleSerializer
|
|
|
|
|
|
|
|
def get_queryset(self):
|
|
|
|
pk = self.kwargs.get('pk', None)
|
|
|
|
system_user = get_object_or_404(SystemUser, pk=pk)
|
|
|
|
return system_user.cmd_filter_rules
|