Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
LOFAR
Manage
Activity
Members
Labels
Plan
Issues
Wiki
Jira issues
Open Jira
Code
Merge requests
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Snippets
Locked files
Deploy
Releases
Package Registry
Container Registry
Model registry
Operate
Environments
Terraform modules
Analyze
Value stream analytics
Contributor analytics
Repository analytics
Code review analytics
Insights
Model experiments
Help
Help
Support
GitLab documentation
Compare GitLab plans
Community forum
Contribute to GitLab
Provide feedback
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
RadioObservatory
LOFAR
Commits
b0092e7e
Commit
b0092e7e
authored
4 years ago
by
Jörn Künsemöller
Browse files
Options
Downloads
Patches
Plain Diff
TMSS-461
: Populate permissions according to User roles confluence table
parent
9eda93fe
No related branches found
No related tags found
1 merge request
!380
TMSS-461: Populate permissions according to User roles confluence table
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
SAS/TMSS/backend/src/tmss/tmssapp/populate.py
+58
-9
58 additions, 9 deletions
SAS/TMSS/backend/src/tmss/tmssapp/populate.py
with
58 additions
and
9 deletions
SAS/TMSS/backend/src/tmss/tmssapp/populate.py
+
58
−
9
View file @
b0092e7e
...
@@ -29,6 +29,7 @@ from lofar.common import isTestEnvironment, isDevelopmentEnvironment
...
@@ -29,6 +29,7 @@ from lofar.common import isTestEnvironment, isDevelopmentEnvironment
from
concurrent.futures
import
ThreadPoolExecutor
from
concurrent.futures
import
ThreadPoolExecutor
from
django.contrib.auth.models
import
User
,
Group
,
Permission
from
django.contrib.auth.models
import
User
,
Group
,
Permission
from
django.contrib.contenttypes.models
import
ContentType
from
django.contrib.contenttypes.models
import
ContentType
from
django.db.utils
import
IntegrityError
working_dir
=
os
.
path
.
dirname
(
os
.
path
.
abspath
(
__file__
))
working_dir
=
os
.
path
.
dirname
(
os
.
path
.
abspath
(
__file__
))
...
@@ -249,24 +250,72 @@ def populate_connectors():
...
@@ -249,24 +250,72 @@ def populate_connectors():
def
populate_permissions
():
def
populate_permissions
():
logger
.
info
(
'
Populating permissions
'
)
logger
.
info
(
'
Populating permissions
'
)
perm
=
ProjectPermission
.
objects
.
create
(
name
=
'
taskdraft
'
)
populate_project_permissions
()
populate_system_permissions
()
populate_system_roles
()
populate_system_test_users
()
def
populate_project_permissions
():
# For each viewset and for each extra action create a project permission entry.
for
name
,
obj
in
inspect
.
getmembers
(
viewsets
):
if
inspect
.
isclass
(
obj
):
try
:
permission_name
=
obj
.
serializer_class
.
Meta
.
model
.
__name__
.
lower
()
logger
.
info
(
'
creating project permission %s
'
%
permission_name
)
try
:
ProjectPermission
.
objects
.
create
(
name
=
permission_name
)
except
IntegrityError
as
e
:
logger
.
debug
(
'
Skipping project permission creation for obj=%s: %s
'
%
(
obj
,
e
))
extra_actions
=
obj
.
get_extra_actions
()
if
extra_actions
:
for
action
in
extra_actions
:
action_permission_name
=
'
%s-%s
'
%
(
permission_name
,
action
.
__name__
)
logger
.
info
(
'
creating project permission %s
'
%
action_permission_name
)
try
:
ProjectPermission
.
objects
.
create
(
name
=
action_permission_name
)
except
IntegrityError
as
e
:
logger
.
debug
(
'
Skipping project permission creation for obj=%s: %s
'
%
(
obj
,
e
))
except
Exception
as
e
:
logger
.
debug
(
'
Skipping project permission creation for obj=%s: %s
'
%
(
obj
,
e
))
# Project
perm
=
ProjectPermission
.
objects
.
get
(
name
=
'
project
'
)
perm
.
GET
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
pi
'
)])
perm
.
GET
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
co_i
'
)])
perm
.
GET
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
contact_author
'
)])
perm
.
GET
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
shared_support_user
'
)])
perm
.
GET
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
shared_support_user
'
)])
perm
.
POST
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
shared_support_user
'
)])
perm
.
GET
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
friend_of_project
'
)])
perm
.
PATCH
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
friend_of_project
'
)])
perm
.
save
()
perm
.
save
()
perm
=
ProjectPermission
.
objects
.
create
(
name
=
"
taskdraft-create_task_blueprint
"
)
# Subtask
perm
.
GET
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
shared_support_user
'
)])
# Subtask-schedule
perm
=
ProjectPermission
.
objects
.
get
(
name
=
'
subtask-schedule
'
)
perm
.
GET
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
friend_of_project
'
)])
perm
.
save
()
perm
.
save
()
perm
=
ProjectPermission
.
objects
.
create
(
name
=
'
project
'
)
# SchedulingUnitDraft
perm
=
ProjectPermission
.
objects
.
get
(
name
=
'
schedulingunitdraft
'
)
perm
.
GET
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
shared_support_user
'
)])
perm
.
GET
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
shared_support_user
'
)])
perm
.
GET
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
friend_of_project
'
)])
perm
.
GET
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
contact_author
'
)])
perm
.
POST
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
shared_support_user
'
)])
perm
.
POST
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
shared_support_user
'
)])
perm
.
POST
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
friend_of_project
'
)])
perm
.
save
()
perm
.
save
()
populate_system_permissions
()
# SchedulingUnitBlueprint
populate_system_roles
()
perm
=
ProjectPermission
.
objects
.
get
(
name
=
'
schedulingunitblueprint
'
)
populate_system_test_users
()
perm
.
GET
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
shared_support_user
'
)])
perm
.
GET
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
friend_of_project
'
)])
perm
.
GET
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
contact_author
'
)])
perm
.
POST
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
shared_support_user
'
)])
# "Let's try, we may want to revoke this later and review"
perm
.
POST
.
set
([
ProjectRole
.
objects
.
get
(
value
=
'
friend_of_project
'
)])
perm
.
save
()
def
populate_system_permissions
():
def
populate_system_permissions
():
...
...
This diff is collapsed.
Click to expand it.
Preview
0%
Loading
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment