repo_permissions.py
128 lines
| 4.9 KiB
| text/x-python
|
PythonLexer
r5088 | # Copyright (C) 2011-2023 RhodeCode GmbH | |||
r1734 | # | |||
# This program is free software: you can redistribute it and/or modify | ||||
# it under the terms of the GNU Affero General Public License, version 3 | ||||
# (only), as published by the Free Software Foundation. | ||||
# | ||||
# This program is distributed in the hope that it will be useful, | ||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of | ||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||||
# GNU General Public License for more details. | ||||
# | ||||
# You should have received a copy of the GNU Affero General Public License | ||||
# along with this program. If not, see <http://www.gnu.org/licenses/>. | ||||
# | ||||
# This program is dual-licensed. If you wish to learn more about the | ||||
# RhodeCode Enterprise Edition, including its added features, Support services, | ||||
# and proprietary license terms, please see https://rhodecode.com/licenses/ | ||||
import logging | ||||
from pyramid.httpexceptions import HTTPFound | ||||
from rhodecode.apps._base import RepoAppView | ||||
from rhodecode.lib import helpers as h | ||||
from rhodecode.lib import audit_logger | ||||
from rhodecode.lib.auth import ( | ||||
r2014 | LoginRequired, HasRepoPermissionAnyDecorator, CSRFRequired) | |||
r4189 | from rhodecode.lib.utils2 import str2bool | |||
r4187 | from rhodecode.model.db import User | |||
r1734 | from rhodecode.model.forms import RepoPermsForm | |||
from rhodecode.model.meta import Session | ||||
r3824 | from rhodecode.model.permission import PermissionModel | |||
r1734 | from rhodecode.model.repo import RepoModel | |||
log = logging.getLogger(__name__) | ||||
class RepoSettingsPermissionsView(RepoAppView): | ||||
def load_default_context(self): | ||||
c = self._get_local_tmpl_context() | ||||
return c | ||||
@LoginRequired() | ||||
@HasRepoPermissionAnyDecorator('repository.admin') | ||||
def edit_permissions(self): | ||||
r3438 | _ = self.request.translate | |||
r1734 | c = self.load_default_context() | |||
c.active = 'permissions' | ||||
r3438 | if self.request.GET.get('branch_permissions'): | |||
r4462 | h.flash(_('Explicitly add user or user group with write or higher ' | |||
r3438 | 'permission to modify their branch permissions.'), | |||
category='notice') | ||||
r1734 | return self._get_template_context(c) | |||
@LoginRequired() | ||||
r2014 | @HasRepoPermissionAnyDecorator('repository.admin') | |||
r1734 | @CSRFRequired() | |||
def edit_permissions_update(self): | ||||
_ = self.request.translate | ||||
c = self.load_default_context() | ||||
c.active = 'permissions' | ||||
data = self.request.POST | ||||
# store private flag outside of HTML to verify if we can modify | ||||
r2014 | # default user permissions, prevents submission of FAKE post data | |||
r1734 | # into the form for private repos | |||
data['repo_private'] = self.db_repo.private | ||||
r2351 | form = RepoPermsForm(self.request.translate)().to_python(data) | |||
r1734 | changes = RepoModel().update_permissions( | |||
self.db_repo_name, form['perm_additions'], form['perm_updates'], | ||||
form['perm_deletions']) | ||||
action_data = { | ||||
'added': changes['added'], | ||||
'updated': changes['updated'], | ||||
'deleted': changes['deleted'], | ||||
} | ||||
r1806 | audit_logger.store_web( | |||
r1734 | 'repo.edit.permissions', action_data=action_data, | |||
user=self._rhodecode_user, repo=self.db_repo) | ||||
Session().commit() | ||||
r3985 | h.flash(_('Repository access permissions updated'), category='success') | |||
r1734 | ||||
r4187 | affected_user_ids = None | |||
if changes.get('default_user_changed', False): | ||||
# if we change the default user, we need to flush everyone permissions | ||||
r4190 | affected_user_ids = User.get_all_user_ids() | |||
r4187 | PermissionModel().flush_user_permission_caches( | |||
changes, affected_user_ids=affected_user_ids) | ||||
r2849 | ||||
r1734 | raise HTTPFound( | |||
r2014 | h.route_path('edit_repo_perms', repo_name=self.db_repo_name)) | |||
r3809 | ||||
@LoginRequired() | ||||
@HasRepoPermissionAnyDecorator('repository.admin') | ||||
@CSRFRequired() | ||||
def edit_permissions_set_private_repo(self): | ||||
_ = self.request.translate | ||||
self.load_default_context() | ||||
r4189 | private_flag = str2bool(self.request.POST.get('private')) | |||
r3809 | try: | |||
r4334 | repo = RepoModel().get(self.db_repo.repo_id) | |||
repo.private = private_flag | ||||
Session().add(repo) | ||||
RepoModel().grant_user_permission( | ||||
repo=self.db_repo, user=User.DEFAULT_USER, perm='repository.none' | ||||
) | ||||
r3809 | Session().commit() | |||
h.flash(_('Repository `{}` private mode set successfully').format(self.db_repo_name), | ||||
category='success') | ||||
r4334 | # NOTE(dan): we change repo private mode we need to notify all USERS | |||
affected_user_ids = User.get_all_user_ids() | ||||
PermissionModel().trigger_permission_flush(affected_user_ids) | ||||
r3809 | except Exception: | |||
log.exception("Exception during update of repository") | ||||
h.flash(_('Error occurred during update of repository {}').format( | ||||
self.db_repo_name), category='error') | ||||
return { | ||||
'redirect_url': h.route_path('edit_repo_perms', repo_name=self.db_repo_name), | ||||
r4189 | 'private': private_flag | |||
r3809 | } | |||