From 2004942a3ac51f06005f8e633b6f4c7405cd669e Mon Sep 17 00:00:00 2001 From: "A.Unger" Date: Mon, 22 Feb 2021 12:19:50 +0100 Subject: [PATCH] shift role initialization from accounts to settings --- accounts/pkg/command/server.go | 3 - accounts/pkg/service/v0/service.go | 34 +--- accounts/pkg/service/v0/settings.go | 194 ---------------------- settings/pkg/service/v0/service.go | 8 + settings/pkg/service/v0/settings.go | 249 +++++++++++++++++++++++++++- 5 files changed, 257 insertions(+), 231 deletions(-) delete mode 100644 accounts/pkg/service/v0/settings.go diff --git a/accounts/pkg/command/server.go b/accounts/pkg/command/server.go index d9dd5b9c9..fd4ba7938 100644 --- a/accounts/pkg/command/server.go +++ b/accounts/pkg/command/server.go @@ -160,9 +160,6 @@ func Server(cfg *config.Config) *cli.Command { ) gr.Add(func() error { - logger.Info().Str("service", server.Name()).Msg("Reporting settings bundles to settings service") - svc.RegisterSettingsBundles(&logger) - svc.RegisterPermissions(&logger) return server.Run() }, func(_ error) { logger.Info(). diff --git a/accounts/pkg/service/v0/service.go b/accounts/pkg/service/v0/service.go index a0d882dc1..9c63497e9 100644 --- a/accounts/pkg/service/v0/service.go +++ b/accounts/pkg/service/v0/service.go @@ -21,7 +21,6 @@ import ( "github.com/owncloud/ocis/ocis-pkg/log" "github.com/owncloud/ocis/ocis-pkg/roles" settings "github.com/owncloud/ocis/settings/pkg/proto/v0" - settings_svc "github.com/owncloud/ocis/settings/pkg/service/v0" ) // userDefaultGID is the default integer representing the "users" group. @@ -68,7 +67,6 @@ func New(opts ...Option) (s *Service, err error) { if err = s.createDefaultGroups(); err != nil { return nil, err } - // TODO watch folders for new records return } @@ -267,6 +265,7 @@ func (s Service) createDefaultAccounts() (err error) { }, }, } + // this only deals with the metadata service. for i := range accounts { a := &proto.Account{} err := s.repo.LoadAccount(context.Background(), accounts[i].Id, a) @@ -287,7 +286,6 @@ func (s Service) createDefaultAccounts() (err error) { } } - // TODO: can be removed again as soon as we respect the predefined UIDs and GIDs from the account. Then no autoincrement is happening, therefore we don't need to update accounts. changed := false for _, r := range results { if r.Field == "UidNumber" || r.Field == "GidNumber" { @@ -309,24 +307,6 @@ func (s Service) createDefaultAccounts() (err error) { } } } - - // set role for admin users and regular users - assignRoleToUser("058bff95-6708-4fe5-91e4-9ea3d377588b", settings_svc.BundleUUIDRoleAdmin, s.RoleService, s.log) - for _, accountID := range []string{ - "058bff95-6708-4fe5-91e4-9ea3d377588b", //moss - "ddc2004c-0977-11eb-9d3f-a793888cd0f8", //admin - "820ba2a1-3f54-4538-80a4-2d73007e30bf", //idp - "bc596f3c-c955-4328-80a0-60d018b4ad57", //reva - } { - assignRoleToUser(accountID, settings_svc.BundleUUIDRoleAdmin, s.RoleService, s.log) - } - for _, accountID := range []string{ - "4c510ada-c86b-4815-8820-42cdf82c3d51", //einstein - "f7fbf8c8-139b-4376-b307-cf0a8c2d0d9c", //marie - "932b4540-8d16-481e-8ef4-588e4b6b151c", //richard - } { - assignRoleToUser(accountID, settings_svc.BundleUUIDRoleUser, s.RoleService, s.log) - } return nil } @@ -403,18 +383,6 @@ func (s Service) createDefaultGroups() (err error) { return nil } -func assignRoleToUser(accountID, roleID string, rs settings.RoleService, logger log.Logger) (ok bool) { - _, err := rs.AssignRoleToUser(context.Background(), &settings.AssignRoleToUserRequest{ - AccountUuid: accountID, - RoleId: roleID, - }) - if err != nil { - logger.Error().Err(err).Str("accountID", accountID).Str("roleID", roleID).Msg("could not set role for account") - return false - } - return true -} - func createMetadataStorage(cfg *config.Config, logger log.Logger) storage.Repo { // for now we detect the used storage implementation based on which storage is configured // the config with defaults needs to be checked last diff --git a/accounts/pkg/service/v0/settings.go b/accounts/pkg/service/v0/settings.go deleted file mode 100644 index 339a7f725..000000000 --- a/accounts/pkg/service/v0/settings.go +++ /dev/null @@ -1,194 +0,0 @@ -package service - -import ( - "context" - - olog "github.com/owncloud/ocis/ocis-pkg/log" - "github.com/owncloud/ocis/ocis-pkg/service/grpc" - settings "github.com/owncloud/ocis/settings/pkg/proto/v0" - ssvc "github.com/owncloud/ocis/settings/pkg/service/v0" -) - -const ( - settingUUIDProfileLanguage = "aa8cfbe5-95d4-4f7e-a032-c3c01f5f062f" -) - -// RegisterSettingsBundles pushes the settings bundle definitions for this extension to the ocis-settings service. -func RegisterSettingsBundles(l *olog.Logger) { - service := settings.NewBundleService("com.owncloud.api.settings", grpc.DefaultClient) - - bundleRequests := []settings.SaveBundleRequest{ - generateBundleProfileRequest(), - } - - for i := range bundleRequests { - res, err := service.SaveBundle(context.Background(), &bundleRequests[i]) - if err != nil { - l.Err(err).Str("bundle", bundleRequests[i].Bundle.Id).Msg("Error registering bundle") - } else { - l.Info().Str("bundle", res.Bundle.Id).Msg("Successfully registered bundle") - } - } - - permissionRequests := generateProfilePermissionsRequests() - for i := range permissionRequests { - res, err := service.AddSettingToBundle(context.Background(), &permissionRequests[i]) - bundleID := permissionRequests[i].BundleId - if err != nil { - l.Err(err).Str("bundle", bundleID).Str("setting", permissionRequests[i].Setting.Id).Msg("Error adding setting to bundle") - } else { - l.Info().Str("bundle", bundleID).Str("setting", res.Setting.Id).Msg("Successfully added setting to bundle") - } - } -} - -var languageSetting = settings.Setting_SingleChoiceValue{ - SingleChoiceValue: &settings.SingleChoiceList{ - Options: []*settings.ListOption{ - { - Value: &settings.ListOptionValue{ - Option: &settings.ListOptionValue_StringValue{ - StringValue: "cs", - }, - }, - DisplayValue: "Czech", - }, - { - Value: &settings.ListOptionValue{ - Option: &settings.ListOptionValue_StringValue{ - StringValue: "de", - }, - }, - DisplayValue: "Deutsch", - }, - { - Value: &settings.ListOptionValue{ - Option: &settings.ListOptionValue_StringValue{ - StringValue: "en", - }, - }, - DisplayValue: "English", - }, - { - Value: &settings.ListOptionValue{ - Option: &settings.ListOptionValue_StringValue{ - StringValue: "es", - }, - }, - DisplayValue: "Español", - }, - { - Value: &settings.ListOptionValue{ - Option: &settings.ListOptionValue_StringValue{ - StringValue: "fr", - }, - }, - DisplayValue: "Français", - }, - { - Value: &settings.ListOptionValue{ - Option: &settings.ListOptionValue_StringValue{ - StringValue: "gl", - }, - }, - DisplayValue: "Galego", - }, - { - Value: &settings.ListOptionValue{ - Option: &settings.ListOptionValue_StringValue{ - StringValue: "it", - }, - }, - DisplayValue: "Italiano", - }, - }, - }, -} - -func generateBundleProfileRequest() settings.SaveBundleRequest { - return settings.SaveBundleRequest{ - Bundle: &settings.Bundle{ - Id: "2a506de7-99bd-4f0d-994e-c38e72c28fd9", - Name: "profile", - Extension: "ocis-accounts", - Type: settings.Bundle_TYPE_DEFAULT, - Resource: &settings.Resource{ - Type: settings.Resource_TYPE_SYSTEM, - }, - DisplayName: "Profile", - Settings: []*settings.Setting{ - { - Id: settingUUIDProfileLanguage, - Name: "language", - DisplayName: "Language", - Description: "User language", - Resource: &settings.Resource{ - Type: settings.Resource_TYPE_USER, - }, - Value: &languageSetting, - }, - }, - }, - } -} - -func generateProfilePermissionsRequests() []settings.AddSettingToBundleRequest { - // TODO: we don't want to set up permissions for settings manually in the future. Instead each setting should come with - // a set of default permissions for the default roles (guest, user, admin). - return []settings.AddSettingToBundleRequest{ - { - BundleId: ssvc.BundleUUIDRoleAdmin, - Setting: &settings.Setting{ - Id: "7d81f103-0488-4853-bce5-98dcce36d649", - Name: "language-readwrite", - DisplayName: "Permission to read and set the language (anyone)", - Resource: &settings.Resource{ - Type: settings.Resource_TYPE_SETTING, - Id: settingUUIDProfileLanguage, - }, - Value: &settings.Setting_PermissionValue{ - PermissionValue: &settings.Permission{ - Operation: settings.Permission_OPERATION_READWRITE, - Constraint: settings.Permission_CONSTRAINT_ALL, - }, - }, - }, - }, - { - BundleId: ssvc.BundleUUIDRoleUser, - Setting: &settings.Setting{ - Id: "640e00d2-4df8-41bd-b1c2-9f30a01e0e99", - Name: "language-readwrite", - DisplayName: "Permission to read and set the language (self)", - Resource: &settings.Resource{ - Type: settings.Resource_TYPE_SETTING, - Id: settingUUIDProfileLanguage, - }, - Value: &settings.Setting_PermissionValue{ - PermissionValue: &settings.Permission{ - Operation: settings.Permission_OPERATION_READWRITE, - Constraint: settings.Permission_CONSTRAINT_OWN, - }, - }, - }, - }, - { - BundleId: ssvc.BundleUUIDRoleGuest, - Setting: &settings.Setting{ - Id: "ca878636-8b1a-4fae-8282-8617a4c13597", - Name: "language-readwrite", - DisplayName: "Permission to read and set the language (self)", - Resource: &settings.Resource{ - Type: settings.Resource_TYPE_SETTING, - Id: settingUUIDProfileLanguage, - }, - Value: &settings.Setting_PermissionValue{ - PermissionValue: &settings.Permission{ - Operation: settings.Permission_OPERATION_READWRITE, - Constraint: settings.Permission_CONSTRAINT_OWN, - }, - }, - }, - }, - } -} diff --git a/settings/pkg/service/v0/service.go b/settings/pkg/service/v0/service.go index 1aed323f0..c52e85a48 100644 --- a/settings/pkg/service/v0/service.go +++ b/settings/pkg/service/v0/service.go @@ -65,6 +65,14 @@ func (g Service) RegisterDefaultRoles() { Msg("failed to register permission") } } + + // TODO(refs) iterate over defaultRoleAssignment creating such role assignments. settings.go + //g.manager.WriteRoleAssignment() + for _, req := range defaultRoleAssignments() { + if _, err := g.manager.WriteRoleAssignment(req.AccountUuid, req.RoleId); err != nil { + // handle me + } + } } // TODO: check permissions on every request diff --git a/settings/pkg/service/v0/settings.go b/settings/pkg/service/v0/settings.go index 249c53b8e..0c76da8ab 100644 --- a/settings/pkg/service/v0/settings.go +++ b/settings/pkg/service/v0/settings.go @@ -1,6 +1,8 @@ package svc -import settings "github.com/owncloud/ocis/settings/pkg/proto/v0" +import ( + settings "github.com/owncloud/ocis/settings/pkg/proto/v0" +) const ( // BundleUUIDRoleAdmin represents the admin role @@ -21,6 +23,21 @@ const ( SettingsManagementPermissionID string = "79e13b30-3e22-11eb-bc51-0b9f0bad9a58" // SettingsManagementPermissionName is the hardcoded setting name for the settings management permission SettingsManagementPermissionName string = "settings-management" + + settingUUIDProfileLanguage = "aa8cfbe5-95d4-4f7e-a032-c3c01f5f062f" + + // AccountManagementPermissionID is the hardcoded setting UUID for the account management permission + AccountManagementPermissionID string = "8e587774-d929-4215-910b-a317b1e80f73" + // AccountManagementPermissionName is the hardcoded setting name for the account management permission + AccountManagementPermissionName string = "account-management" + // GroupManagementPermissionID is the hardcoded setting UUID for the group management permission + GroupManagementPermissionID string = "522adfbe-5908-45b4-b135-41979de73245" + // GroupManagementPermissionName is the hardcoded setting name for the group management permission + GroupManagementPermissionName string = "group-management" + // SelfManagementPermissionID is the hardcoded setting UUID for the self management permission + SelfManagementPermissionID string = "e03070e9-4362-4cc6-a872-1c7cb2eb2b8e" + // SelfManagementPermissionName is the hardcoded setting name for the self management permission + SelfManagementPermissionName string = "self-management" ) // generateBundlesDefaultRoles bootstraps the default roles. @@ -29,6 +46,7 @@ func generateBundlesDefaultRoles() []*settings.Bundle { generateBundleAdminRole(), generateBundleUserRole(), generateBundleGuestRole(), + generateBundleProfileRequest(), } } @@ -74,6 +92,94 @@ func generateBundleGuestRole() *settings.Bundle { } } +var languageSetting = settings.Setting_SingleChoiceValue{ + SingleChoiceValue: &settings.SingleChoiceList{ + Options: []*settings.ListOption{ + { + Value: &settings.ListOptionValue{ + Option: &settings.ListOptionValue_StringValue{ + StringValue: "cs", + }, + }, + DisplayValue: "Czech", + }, + { + Value: &settings.ListOptionValue{ + Option: &settings.ListOptionValue_StringValue{ + StringValue: "de", + }, + }, + DisplayValue: "Deutsch", + }, + { + Value: &settings.ListOptionValue{ + Option: &settings.ListOptionValue_StringValue{ + StringValue: "en", + }, + }, + DisplayValue: "English", + }, + { + Value: &settings.ListOptionValue{ + Option: &settings.ListOptionValue_StringValue{ + StringValue: "es", + }, + }, + DisplayValue: "Español", + }, + { + Value: &settings.ListOptionValue{ + Option: &settings.ListOptionValue_StringValue{ + StringValue: "fr", + }, + }, + DisplayValue: "Français", + }, + { + Value: &settings.ListOptionValue{ + Option: &settings.ListOptionValue_StringValue{ + StringValue: "gl", + }, + }, + DisplayValue: "Galego", + }, + { + Value: &settings.ListOptionValue{ + Option: &settings.ListOptionValue_StringValue{ + StringValue: "it", + }, + }, + DisplayValue: "Italiano", + }, + }, + }, +} + +func generateBundleProfileRequest() *settings.Bundle { + return &settings.Bundle{ + Id: "2a506de7-99bd-4f0d-994e-c38e72c28fd9", + Name: "profile", + Extension: "ocis-accounts", + Type: settings.Bundle_TYPE_DEFAULT, + Resource: &settings.Resource{ + Type: settings.Resource_TYPE_SYSTEM, + }, + DisplayName: "Profile", + Settings: []*settings.Setting{ + { + Id: settingUUIDProfileLanguage, + Name: "language", + DisplayName: "Language", + Description: "User language", + Resource: &settings.Resource{ + Type: settings.Resource_TYPE_USER, + }, + Value: &languageSetting, + }, + }, + } +} + func generatePermissionRequests() []*settings.AddSettingToBundleRequest { return []*settings.AddSettingToBundleRequest{ { @@ -114,5 +220,146 @@ func generatePermissionRequests() []*settings.AddSettingToBundleRequest { }, }, }, + { + BundleId: BundleUUIDRoleAdmin, + Setting: &settings.Setting{ + Id: "7d81f103-0488-4853-bce5-98dcce36d649", + Name: "language-readwrite", + DisplayName: "Permission to read and set the language (anyone)", + Resource: &settings.Resource{ + Type: settings.Resource_TYPE_SETTING, + Id: settingUUIDProfileLanguage, + }, + Value: &settings.Setting_PermissionValue{ + PermissionValue: &settings.Permission{ + Operation: settings.Permission_OPERATION_READWRITE, + Constraint: settings.Permission_CONSTRAINT_ALL, + }, + }, + }, + }, + { + BundleId: BundleUUIDRoleUser, + Setting: &settings.Setting{ + Id: "640e00d2-4df8-41bd-b1c2-9f30a01e0e99", + Name: "language-readwrite", + DisplayName: "Permission to read and set the language (self)", + Resource: &settings.Resource{ + Type: settings.Resource_TYPE_SETTING, + Id: settingUUIDProfileLanguage, + }, + Value: &settings.Setting_PermissionValue{ + PermissionValue: &settings.Permission{ + Operation: settings.Permission_OPERATION_READWRITE, + Constraint: settings.Permission_CONSTRAINT_OWN, + }, + }, + }, + }, + { + BundleId: BundleUUIDRoleGuest, + Setting: &settings.Setting{ + Id: "ca878636-8b1a-4fae-8282-8617a4c13597", + Name: "language-readwrite", + DisplayName: "Permission to read and set the language (self)", + Resource: &settings.Resource{ + Type: settings.Resource_TYPE_SETTING, + Id: settingUUIDProfileLanguage, + }, + Value: &settings.Setting_PermissionValue{ + PermissionValue: &settings.Permission{ + Operation: settings.Permission_OPERATION_READWRITE, + Constraint: settings.Permission_CONSTRAINT_OWN, + }, + }, + }, + }, + { + BundleId: BundleUUIDRoleAdmin, + Setting: &settings.Setting{ + Id: AccountManagementPermissionID, + Name: AccountManagementPermissionName, + DisplayName: "Account Management", + Description: "This permission gives full access to everything that is related to account management.", + Resource: &settings.Resource{ + Type: settings.Resource_TYPE_USER, + Id: "all", + }, + Value: &settings.Setting_PermissionValue{ + PermissionValue: &settings.Permission{ + Operation: settings.Permission_OPERATION_READWRITE, + Constraint: settings.Permission_CONSTRAINT_ALL, + }, + }, + }, + }, + { + BundleId: BundleUUIDRoleAdmin, + Setting: &settings.Setting{ + Id: GroupManagementPermissionID, + Name: GroupManagementPermissionName, + DisplayName: "Group Management", + Description: "This permission gives full access to everything that is related to group management.", + Resource: &settings.Resource{ + Type: settings.Resource_TYPE_GROUP, + Id: "all", + }, + Value: &settings.Setting_PermissionValue{ + PermissionValue: &settings.Permission{ + Operation: settings.Permission_OPERATION_READWRITE, + Constraint: settings.Permission_CONSTRAINT_ALL, + }, + }, + }, + }, + { + BundleId: BundleUUIDRoleUser, + Setting: &settings.Setting{ + Id: SelfManagementPermissionID, + Name: SelfManagementPermissionName, + DisplayName: "Self Management", + Description: "This permission gives access to self management.", + Resource: &settings.Resource{ + Type: settings.Resource_TYPE_USER, + Id: "me", + }, + Value: &settings.Setting_PermissionValue{ + PermissionValue: &settings.Permission{ + Operation: settings.Permission_OPERATION_READWRITE, + Constraint: settings.Permission_CONSTRAINT_OWN, + }, + }, + }, + }, + } +} + +func defaultRoleAssignments() []*settings.UserRoleAssignment { + return []*settings.UserRoleAssignment{ + // default admin users + { + AccountUuid: "058bff95-6708-4fe5-91e4-9ea3d377588b", + RoleId: BundleUUIDRoleAdmin, + }, { + AccountUuid: "ddc2004c-0977-11eb-9d3f-a793888cd0f8", + RoleId: BundleUUIDRoleAdmin, + }, { + AccountUuid: "820ba2a1-3f54-4538-80a4-2d73007e30bf", + RoleId: BundleUUIDRoleAdmin, + }, { + AccountUuid: "bc596f3c-c955-4328-80a0-60d018b4ad57", + RoleId: BundleUUIDRoleAdmin, + }, + // default users with role "user" + { + AccountUuid: "4c510ada-c86b-4815-8820-42cdf82c3d51", + RoleId: BundleUUIDRoleUser, + }, { + AccountUuid: "f7fbf8c8-139b-4376-b307-cf0a8c2d0d9c", + RoleId: BundleUUIDRoleUser, + }, { + AccountUuid: "932b4540-8d16-481e-8ef4-588e4b6b151c", + RoleId: BundleUUIDRoleUser, + }, } }