2022-07-12 02:54:23 +00:00
|
|
|
|
from django.db import models
|
2023-05-09 07:29:02 +00:00
|
|
|
|
from django.db.models import Count, Q
|
2023-04-25 02:28:19 +00:00
|
|
|
|
from django.utils import timezone
|
2022-07-12 02:54:23 +00:00
|
|
|
|
from django.utils.translation import gettext_lazy as _
|
|
|
|
|
from simple_history.models import HistoricalRecords
|
|
|
|
|
|
2023-01-16 11:02:09 +00:00
|
|
|
|
from assets.models.base import AbsConnectivity
|
2023-02-16 06:21:24 +00:00
|
|
|
|
from common.utils import lazyproperty
|
2023-01-16 11:02:09 +00:00
|
|
|
|
from .base import BaseAccount
|
2023-07-31 09:39:30 +00:00
|
|
|
|
from .mixins import VaultModelMixin
|
2023-02-16 06:21:24 +00:00
|
|
|
|
from ..const import AliasAccount, Source
|
2022-07-12 02:54:23 +00:00
|
|
|
|
|
2023-07-31 09:39:30 +00:00
|
|
|
|
__all__ = ['Account', 'AccountTemplate', 'AccountHistoricalRecords']
|
2022-07-12 02:54:23 +00:00
|
|
|
|
|
|
|
|
|
|
2022-10-09 09:43:13 +00:00
|
|
|
|
class AccountHistoricalRecords(HistoricalRecords):
|
|
|
|
|
def __init__(self, *args, **kwargs):
|
|
|
|
|
self.included_fields = kwargs.pop('included_fields', None)
|
|
|
|
|
super().__init__(*args, **kwargs)
|
|
|
|
|
|
2022-10-20 12:06:58 +00:00
|
|
|
|
def post_save(self, instance, created, using=None, **kwargs):
|
|
|
|
|
if not self.included_fields:
|
|
|
|
|
return super().post_save(instance, created, using=using, **kwargs)
|
|
|
|
|
|
|
|
|
|
check_fields = set(self.included_fields) - {'version'}
|
|
|
|
|
history_attrs = instance.history.all().values(*check_fields).first()
|
|
|
|
|
if history_attrs is None:
|
|
|
|
|
return super().post_save(instance, created, using=using, **kwargs)
|
|
|
|
|
|
|
|
|
|
attrs = {field: getattr(instance, field) for field in check_fields}
|
|
|
|
|
history_attrs = set(history_attrs.items())
|
|
|
|
|
attrs = set(attrs.items())
|
|
|
|
|
diff = attrs - history_attrs
|
|
|
|
|
if not diff:
|
|
|
|
|
return
|
2023-07-31 09:39:30 +00:00
|
|
|
|
return super().post_save(instance, created, using=using, **kwargs)
|
2022-10-20 12:06:58 +00:00
|
|
|
|
|
2022-11-03 08:55:38 +00:00
|
|
|
|
def create_history_model(self, model, inherited):
|
|
|
|
|
if self.included_fields and not self.excluded_fields:
|
|
|
|
|
self.excluded_fields = [
|
|
|
|
|
field.name for field in model._meta.fields
|
|
|
|
|
if field.name not in self.included_fields
|
|
|
|
|
]
|
|
|
|
|
return super().create_history_model(model, inherited)
|
2022-10-09 09:43:13 +00:00
|
|
|
|
|
|
|
|
|
|
2022-10-22 03:17:02 +00:00
|
|
|
|
class Account(AbsConnectivity, BaseAccount):
|
2022-09-13 06:06:25 +00:00
|
|
|
|
asset = models.ForeignKey(
|
|
|
|
|
'assets.Asset', related_name='accounts',
|
|
|
|
|
on_delete=models.CASCADE, verbose_name=_('Asset')
|
|
|
|
|
)
|
|
|
|
|
su_from = models.ForeignKey(
|
2023-01-16 11:02:09 +00:00
|
|
|
|
'accounts.Account', related_name='su_to', null=True,
|
2022-09-13 06:06:25 +00:00
|
|
|
|
on_delete=models.SET_NULL, verbose_name=_("Su from")
|
|
|
|
|
)
|
2022-07-15 10:57:52 +00:00
|
|
|
|
version = models.IntegerField(default=0, verbose_name=_('Version'))
|
2023-07-31 09:39:30 +00:00
|
|
|
|
history = AccountHistoricalRecords(included_fields=['id', '_secret', 'secret_type', 'version'])
|
2022-12-27 09:45:41 +00:00
|
|
|
|
source = models.CharField(max_length=30, default=Source.LOCAL, verbose_name=_('Source'))
|
2023-04-03 10:18:31 +00:00
|
|
|
|
source_id = models.CharField(max_length=128, null=True, blank=True, verbose_name=_('Source ID'))
|
2022-07-12 02:54:23 +00:00
|
|
|
|
|
|
|
|
|
class Meta:
|
|
|
|
|
verbose_name = _('Account')
|
2022-09-13 13:07:20 +00:00
|
|
|
|
unique_together = [
|
2022-09-20 05:54:25 +00:00
|
|
|
|
('username', 'asset', 'secret_type'),
|
2022-09-13 13:07:20 +00:00
|
|
|
|
('name', 'asset'),
|
|
|
|
|
]
|
2022-07-12 02:54:23 +00:00
|
|
|
|
permissions = [
|
2022-07-27 08:51:39 +00:00
|
|
|
|
('view_accountsecret', _('Can view asset account secret')),
|
|
|
|
|
('view_historyaccount', _('Can view asset history account')),
|
|
|
|
|
('view_historyaccountsecret', _('Can view asset history account secret')),
|
2023-02-21 05:39:28 +00:00
|
|
|
|
('verify_account', _('Can verify account')),
|
|
|
|
|
('push_account', _('Can push account')),
|
2022-07-12 02:54:23 +00:00
|
|
|
|
]
|
2022-07-13 08:36:49 +00:00
|
|
|
|
|
2023-02-22 03:18:42 +00:00
|
|
|
|
def __str__(self):
|
|
|
|
|
return '{}'.format(self.username)
|
|
|
|
|
|
2022-09-06 11:57:03 +00:00
|
|
|
|
@lazyproperty
|
2022-09-23 10:59:19 +00:00
|
|
|
|
def platform(self):
|
|
|
|
|
return self.asset.platform
|
2022-09-06 11:57:03 +00:00
|
|
|
|
|
2022-12-15 08:02:34 +00:00
|
|
|
|
@lazyproperty
|
|
|
|
|
def alias(self):
|
|
|
|
|
if self.username.startswith('@'):
|
|
|
|
|
return self.username
|
|
|
|
|
return self.name
|
|
|
|
|
|
2022-12-26 10:58:21 +00:00
|
|
|
|
@lazyproperty
|
|
|
|
|
def has_secret(self):
|
|
|
|
|
return bool(self.secret)
|
|
|
|
|
|
2023-06-27 03:23:56 +00:00
|
|
|
|
@classmethod
|
|
|
|
|
def get_special_account(cls, name):
|
|
|
|
|
if name == AliasAccount.INPUT.value:
|
|
|
|
|
return cls.get_manual_account()
|
|
|
|
|
elif name == AliasAccount.ANON.value:
|
|
|
|
|
return cls.get_anonymous_account()
|
|
|
|
|
else:
|
|
|
|
|
return cls(name=name, username=name, secret=None)
|
|
|
|
|
|
2022-09-23 07:59:37 +00:00
|
|
|
|
@classmethod
|
2022-11-11 07:04:31 +00:00
|
|
|
|
def get_manual_account(cls):
|
2022-09-23 07:59:37 +00:00
|
|
|
|
""" @INPUT 手动登录的账号(any) """
|
2022-12-27 09:45:41 +00:00
|
|
|
|
return cls(name=AliasAccount.INPUT.label, username=AliasAccount.INPUT.value, secret=None)
|
2022-09-23 07:59:37 +00:00
|
|
|
|
|
2023-06-27 03:23:56 +00:00
|
|
|
|
@classmethod
|
|
|
|
|
def get_anonymous_account(cls):
|
|
|
|
|
return cls(name=AliasAccount.ANON.label, username=AliasAccount.ANON.value, secret=None)
|
|
|
|
|
|
2022-09-23 07:59:37 +00:00
|
|
|
|
@classmethod
|
2023-02-10 07:56:47 +00:00
|
|
|
|
def get_user_account(cls):
|
2022-09-23 07:59:37 +00:00
|
|
|
|
""" @USER 动态用户的账号(self) """
|
2023-02-10 07:56:47 +00:00
|
|
|
|
return cls(name=AliasAccount.USER.label, username=AliasAccount.USER.value, secret=None)
|
2022-09-23 07:59:37 +00:00
|
|
|
|
|
2023-07-19 03:36:42 +00:00
|
|
|
|
@lazyproperty
|
|
|
|
|
def versions(self):
|
|
|
|
|
return self.history.count()
|
|
|
|
|
|
2022-12-06 09:32:48 +00:00
|
|
|
|
def get_su_from_accounts(self):
|
2022-12-08 05:37:35 +00:00
|
|
|
|
""" 排除自己和以自己为 su-from 的账号 """
|
|
|
|
|
return self.asset.accounts.exclude(id=self.id).exclude(su_from=self)
|
2022-12-06 09:32:48 +00:00
|
|
|
|
|
2022-08-19 10:49:00 +00:00
|
|
|
|
|
2022-09-06 11:57:03 +00:00
|
|
|
|
class AccountTemplate(BaseAccount):
|
2023-05-09 07:29:02 +00:00
|
|
|
|
su_from = models.ForeignKey(
|
|
|
|
|
'self', related_name='su_to', null=True,
|
|
|
|
|
on_delete=models.SET_NULL, verbose_name=_("Su from")
|
|
|
|
|
)
|
|
|
|
|
|
2022-08-19 10:49:00 +00:00
|
|
|
|
class Meta:
|
|
|
|
|
verbose_name = _('Account template')
|
2022-09-06 11:57:03 +00:00
|
|
|
|
unique_together = (
|
|
|
|
|
('name', 'org_id'),
|
|
|
|
|
)
|
2022-11-28 10:43:58 +00:00
|
|
|
|
permissions = [
|
|
|
|
|
('view_accounttemplatesecret', _('Can view asset account template secret')),
|
|
|
|
|
('change_accounttemplatesecret', _('Can change asset account template secret')),
|
|
|
|
|
]
|
2022-08-19 10:49:00 +00:00
|
|
|
|
|
2023-05-09 07:29:02 +00:00
|
|
|
|
@classmethod
|
2023-06-27 02:45:50 +00:00
|
|
|
|
def get_su_from_account_templates(cls, pk=None):
|
|
|
|
|
if pk is None:
|
2023-05-09 07:29:02 +00:00
|
|
|
|
return cls.objects.all()
|
2023-07-19 02:33:12 +00:00
|
|
|
|
return cls.objects.exclude(Q(id=pk) | Q(su_from_id=pk))
|
|
|
|
|
|
|
|
|
|
def __str__(self):
|
|
|
|
|
return f'{self.name}({self.username})'
|
2023-05-09 07:29:02 +00:00
|
|
|
|
|
|
|
|
|
def get_su_from_account(self, asset):
|
|
|
|
|
su_from = self.su_from
|
|
|
|
|
if su_from and asset.platform.su_enabled:
|
|
|
|
|
account = asset.accounts.filter(
|
|
|
|
|
username=su_from.username,
|
|
|
|
|
secret_type=su_from.secret_type
|
|
|
|
|
).first()
|
|
|
|
|
return account
|
|
|
|
|
|
2023-04-25 02:28:19 +00:00
|
|
|
|
@staticmethod
|
|
|
|
|
def bulk_update_accounts(accounts, data):
|
|
|
|
|
history_model = Account.history.model
|
|
|
|
|
account_ids = accounts.values_list('id', flat=True)
|
|
|
|
|
history_accounts = history_model.objects.filter(id__in=account_ids)
|
|
|
|
|
account_id_count_map = {
|
|
|
|
|
str(i['id']): i['count']
|
|
|
|
|
for i in history_accounts.values('id').order_by('id')
|
|
|
|
|
.annotate(count=Count(1)).values('id', 'count')
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
for account in accounts:
|
|
|
|
|
account_id = str(account.id)
|
|
|
|
|
account.version = account_id_count_map.get(account_id) + 1
|
|
|
|
|
for k, v in data.items():
|
|
|
|
|
setattr(account, k, v)
|
|
|
|
|
Account.objects.bulk_update(accounts, ['version', 'secret'])
|
|
|
|
|
|
|
|
|
|
@staticmethod
|
|
|
|
|
def bulk_create_history_accounts(accounts, user_id):
|
|
|
|
|
history_model = Account.history.model
|
|
|
|
|
history_account_objs = []
|
|
|
|
|
for account in accounts:
|
|
|
|
|
history_account_objs.append(
|
|
|
|
|
history_model(
|
|
|
|
|
id=account.id,
|
|
|
|
|
version=account.version,
|
|
|
|
|
secret=account.secret,
|
|
|
|
|
secret_type=account.secret_type,
|
|
|
|
|
history_user_id=user_id,
|
|
|
|
|
history_date=timezone.now()
|
|
|
|
|
)
|
|
|
|
|
)
|
|
|
|
|
history_model.objects.bulk_create(history_account_objs)
|
|
|
|
|
|
|
|
|
|
def bulk_sync_account_secret(self, accounts, user_id):
|
|
|
|
|
""" 批量同步账号密码 """
|
|
|
|
|
if not accounts:
|
|
|
|
|
return
|
|
|
|
|
self.bulk_update_accounts(accounts, {'secret': self.secret})
|
|
|
|
|
self.bulk_create_history_accounts(accounts, user_id)
|
2023-07-31 09:39:30 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def replace_history_model_with_mixin():
|
|
|
|
|
"""
|
|
|
|
|
替换历史模型中的父类为指定的Mixin类。
|
|
|
|
|
|
|
|
|
|
Parameters:
|
|
|
|
|
model (class): 历史模型类,例如 Account.history.model
|
|
|
|
|
mixin_class (class): 要替换为的Mixin类
|
|
|
|
|
|
|
|
|
|
Returns:
|
|
|
|
|
None
|
|
|
|
|
"""
|
|
|
|
|
model = Account.history.model
|
|
|
|
|
model.__bases__ = (VaultModelMixin,) + model.__bases__
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
replace_history_model_with_mixin()
|