jumpserver/apps/settings/tasks/ldap.py

146 lines
4.6 KiB
Python
Raw Normal View History

# coding: utf-8
2024-01-11 11:07:54 +00:00
import time
2024-09-13 09:44:26 +00:00
2023-02-19 09:57:48 +00:00
from celery import shared_task
from django.conf import settings
2023-07-24 03:52:25 +00:00
from django.utils.translation import gettext_lazy as _
from common.utils import get_logger
2024-01-11 11:07:54 +00:00
from common.utils.timezone import local_now_display
2023-02-19 09:57:48 +00:00
from ops.celery.decorator import after_app_ready_start
from ops.celery.utils import (
2024-09-13 09:44:26 +00:00
create_or_update_celery_periodic_tasks
2023-02-19 09:57:48 +00:00
)
from orgs.models import Organization
2024-01-11 11:07:54 +00:00
from settings.notifications import LDAPImportMessage
from users.models import User
2023-02-19 09:57:48 +00:00
from ..utils import LDAPSyncUtil, LDAPServerUtil, LDAPImportUtil
2024-09-04 07:49:59 +00:00
__all__ = [
'sync_ldap_user', 'import_ldap_user_periodic', 'import_ldap_ha_user_periodic',
'import_ldap_user', 'import_ldap_ha_user'
]
logger = get_logger(__file__)
2024-09-04 07:49:59 +00:00
def sync_ldap_user(category='ldap'):
LDAPSyncUtil(category=category).perform_sync()
2023-02-19 09:57:48 +00:00
2024-09-04 07:49:59 +00:00
def perform_import(category, util_server):
2024-01-11 11:07:54 +00:00
start_time = time.time()
time_start_display = local_now_display()
2024-09-04 07:49:59 +00:00
logger.info(f"Start import {category} ldap user task")
2023-02-19 09:57:48 +00:00
util_import = LDAPImportUtil()
users = util_server.search()
2024-09-04 07:49:59 +00:00
2023-02-19 09:57:48 +00:00
if settings.XPACK_ENABLED:
2024-09-04 07:49:59 +00:00
org_ids = getattr(settings, f"AUTH_{category.upper()}_SYNC_ORG_IDS")
2023-02-19 09:57:48 +00:00
default_org = None
else:
org_ids = [Organization.DEFAULT_ID]
2023-02-19 09:57:48 +00:00
default_org = Organization.default()
2024-09-04 07:49:59 +00:00
orgs = list(set([Organization.get_instance(org_id, default=default_org) for org_id in org_ids]))
2024-01-11 11:07:54 +00:00
new_users, errors = util_import.perform_import(users, orgs)
2024-09-04 07:49:59 +00:00
2023-02-19 09:57:48 +00:00
if errors:
2024-09-04 07:49:59 +00:00
logger.error(f"Imported {category} LDAP users errors: {errors}")
2023-02-19 09:57:48 +00:00
else:
2024-09-04 07:49:59 +00:00
logger.info(f"Imported {len(users)} {category} users successfully")
receivers_setting = f"AUTH_{category.upper()}_SYNC_RECEIVERS"
if getattr(settings, receivers_setting, None):
user_ids = getattr(settings, receivers_setting)
2024-01-11 11:07:54 +00:00
recipient_list = User.objects.filter(id__in=list(user_ids))
end_time = time.time()
extra_kwargs = {
'orgs': orgs,
'end_time': end_time,
'start_time': start_time,
'time_start_display': time_start_display,
'new_users': new_users,
'errors': errors,
2024-01-16 05:59:48 +00:00
'cost_time': end_time - start_time,
2024-01-11 11:07:54 +00:00
}
for user in recipient_list:
LDAPImportMessage(user, extra_kwargs).publish()
2023-02-19 09:57:48 +00:00
@shared_task(
2024-09-04 07:49:59 +00:00
verbose_name=_('Periodic import ldap user'),
description=_(
2024-09-13 09:44:26 +00:00
"When LDAP auto-sync is configured, this task will be invoked to synchronize users"
)
)
2024-09-04 07:49:59 +00:00
def import_ldap_user():
perform_import('ldap', LDAPServerUtil())
@shared_task(
verbose_name=_('Periodic import ldap ha user'),
description=_(
2024-09-13 09:44:26 +00:00
"When LDAP auto-sync is configured, this task will be invoked to synchronize users"
2024-09-04 07:49:59 +00:00
)
)
def import_ldap_ha_user():
perform_import('ldap_ha', LDAPServerUtil(category='ldap_ha'))
def register_periodic_task(task_name, task_func, interval_key, enabled_key, crontab_key, **kwargs):
interval = kwargs.get(interval_key, settings.AUTH_LDAP_SYNC_INTERVAL)
enabled = kwargs.get(enabled_key, settings.AUTH_LDAP_SYNC_IS_PERIODIC)
crontab = kwargs.get(crontab_key, settings.AUTH_LDAP_SYNC_CRONTAB)
2023-02-19 09:57:48 +00:00
if isinstance(interval, int):
interval = interval * 3600
else:
interval = None
2024-09-04 07:49:59 +00:00
2023-02-19 09:57:48 +00:00
if crontab:
2024-09-04 07:49:59 +00:00
interval = None # 优先使用 crontab
2023-02-19 09:57:48 +00:00
tasks = {
task_name: {
2024-09-04 07:49:59 +00:00
'task': task_func.name,
2023-02-19 09:57:48 +00:00
'interval': interval,
'crontab': crontab,
'enabled': enabled
2023-02-19 09:57:48 +00:00
}
}
create_or_update_celery_periodic_tasks(tasks)
2024-09-04 07:49:59 +00:00
@shared_task(
verbose_name=_('Registration periodic import ldap user task'),
description=_(
2024-09-13 09:44:26 +00:00
"""When LDAP auto-sync parameters change, such as Crontab parameters, the LDAP sync task
will be re-registered or updated, and this task will be invoked"""
2024-09-04 07:49:59 +00:00
)
)
@after_app_ready_start
def import_ldap_user_periodic(**kwargs):
register_periodic_task(
'import_ldap_user_periodic', import_ldap_user,
'AUTH_LDAP_SYNC_INTERVAL', 'AUTH_LDAP_SYNC_IS_PERIODIC',
'AUTH_LDAP_SYNC_CRONTAB', **kwargs
)
@shared_task(
verbose_name=_('Registration periodic import ldap ha user task'),
description=_(
2024-09-13 09:44:26 +00:00
"""When LDAP HA auto-sync parameters change, such as Crontab parameters, the LDAP HA sync task
will be re-registered or updated, and this task will be invoked"""
2024-09-04 07:49:59 +00:00
)
)
@after_app_ready_start
def import_ldap_ha_user_periodic(**kwargs):
register_periodic_task(
'import_ldap_ha_user_periodic', import_ldap_ha_user,
'AUTH_LDAP_HA_SYNC_INTERVAL', 'AUTH_LDAP_HA_SYNC_IS_PERIODIC',
'AUTH_LDAP_HA_SYNC_CRONTAB', **kwargs
)