def combine_users_and_groups(self, usergroups): for user_id in usergroups.users.keys(): user = usergroups.users[user_id] new_groups = [] for group_id in user.groups: if group_id in usergroups.groups: group = usergroups.groups[group_id] new_groups.append(group) else: YLogger.error(self, "Unknown group id [%s] in user [%s]", group_id, user_id) user.add_groups(new_groups[:]) for group_id in usergroups.groups.keys(): group = usergroups.groups[group_id] new_groups = [] for sub_group_id in group.groups: if sub_group_id in usergroups.groups: new_group = usergroups.groups[sub_group_id] new_groups.append(new_group) else: YLogger.error(self, "Unknown group id [%s] in group [%s]", sub_group_id, group_id) group.add_groups(new_groups[:]) for sub_user_id in group.users: if sub_user_id not in usergroups.users: new_user = User(sub_user_id) for role in group.roles: new_user.add_role(role) usergroups.users[new_user.userid] = new_user else: YLogger.error(self, "Duplicate user id [%s] in group [%s]", sub_user_id, group_id)
def load_users(self, yaml_data): users = {} if 'users' in yaml_data: for user_name in yaml_data['users'].keys(): user = User(user_name) yaml_obj = yaml_data['users'][user_name] if 'roles' in yaml_obj: roles_list = yaml_obj['roles'] splits = roles_list.split(",") for role_name in splits: role_name = role_name.strip() if role_name not in user.roles: user.roles.append(role_name) else: YLogger.debug( self, "Role [%s] already exists in user [%s]", role_name, user_name) if 'groups' in yaml_obj: groups_list = yaml_obj['groups'] splits = groups_list.split(",") for group_name in splits: group_name = group_name.strip() if group_name not in user.groups: user.groups.append(group_name) else: YLogger.debug( self, "Group [%s] already exists in user [%s]", group_name, user_name) users[user.userid] = user return users
def _load_users_user(self, yaml_data, user_name, usergroups): user = User(user_name) yaml_obj = yaml_data['users'][user_name] if 'roles' in yaml_obj: self._load_users_user_roles(yaml_obj, user, user_name) if 'groups' in yaml_obj: self._load_users_user_groups(yaml_obj, user, user_name) usergroups.users[user.userid] = user
def load_usergroups(self, usersgroupsauthorisor): dbusers = self._storage_engine.session.query(AuthoriseUser) for dbuser in dbusers: user = User(dbuser.name) dbuserroles = self._storage_engine.session.query(UserRole).filter( UserRole.user == dbuser.name) for dbuserrole in dbuserroles: user.add_role(dbuserrole.role) dbusergroups = self._storage_engine.session.query( UserGroup).filter(UserGroup.user == dbuser.name) for dbusergroup in dbusergroups: user.add_group(dbusergroup.group) usersgroupsauthorisor.users[user.userid] = user groups = self._storage_engine.session.query(AuthoriseGroup) for dbgroup in groups: group = Group(dbgroup.name) groupusers = self._storage_engine.session.query(GroupUser).filter( GroupUser.group == dbgroup.name) for dbgroupuser in groupusers: group.add_user(dbgroupuser.user) groupgroups = self._storage_engine.session.query( GroupGroup).filter(GroupGroup.group == dbgroup.name) for dbgroupgroup in groupgroups: group.add_group(dbgroupgroup.subgroup) grouproles = self._storage_engine.session.query(GroupRole).filter( GroupRole.group == dbgroup.name) for dbgrouprole in grouproles: group.add_role(dbgrouprole.role) usersgroupsauthorisor.groups[group.groupid] = group self._combine_users_and_groups(usersgroupsauthorisor)
def test_users(self): user = User("keith") self.assertEqual("keith", user.userid) user.roles.append("admin1") self.assertTrue(user.has_role("admin1")) self.assertFalse(user.has_role("adminx")) group = Group("sysadmin") self.assertFalse(group.has_user("keith")) self.assertEqual([], user.groups) user.add_to_group(group) self.assertTrue(group.has_user("keith")) self.assertEqual([group], user.groups) user.add_to_group(group) self.assertTrue(group.has_user("keith")) self.assertEqual([group], user.groups)
def test_load_users_user_roles_duplicates(self): user = User("console") store = UserGroupsStore() yaml_data = yaml.load(""" roles: su, local, su """, Loader=yaml.FullLoader) store._load_users_user_roles(yaml_data, user, "console") self.assertTrue("su" in user.roles) self.assertTrue("local" in user.roles) self.assertFalse("other" in user.roles)
def test_load_users_user_groups_duplicates(self): user = User("console") store = UserGroupsStore() yaml_data = yaml.load(""" groups: sysadmin, localuser, localuser """, Loader=yaml.FullLoader) store._load_users_user_groups(yaml_data, user, "console") self.assertTrue("sysadmin" in user.groups) self.assertTrue("localuser" in user.groups) self.assertFalse("other" in user.groups)
def test_users_and_groups(self): user1 = User("keith") user1.roles.append("admin1") self.assertTrue(user1.has_role("admin1")) self.assertFalse(user1.has_role("adminx")) group1 = Group("sysadmin") group1.roles.append("admin2") self.assertTrue(group1.has_role("admin2")) group2 = Group("operations") group2.roles.append("audit") group1.groups.append(group2) user2 = User("fred") user2.groups.append(group1) user2.roles.append("admin3") self.assertTrue(user2.has_group("sysadmin")) self.assertTrue(user2.has_role("admin2")) self.assertTrue(user2.has_role("admin3")) self.assertFalse(user2.has_role("adminx"))
def test_load_users_user_groups_duplicates(self): user = User("console") config = SQLStorageConfiguration() engine = SQLStorageEngine(config) engine.initialise() store = SQLUserGroupStore(engine) yaml_data = yaml.load(""" groups: sysadmin, localuser, localuser """, Loader=yaml.FullLoader) store._load_users_user_groups(yaml_data, user, "console") self.assertTrue("sysadmin" in user.groups) self.assertTrue("localuser" in user.groups) self.assertFalse("other" in user.groups)
def test_load_users_user_roles(self): user = User("console") config = SQLStorageConfiguration() engine = SQLStorageEngine(config) engine.initialise() store = SQLUserGroupStore(engine) yaml_data = yaml.load(""" roles: su, local """, Loader=yaml.FullLoader) store._load_users_user_roles(yaml_data, user, "console") self.assertTrue("su" in user.roles) self.assertTrue("local" in user.roles) self.assertFalse("other" in user.roles)
def test_groups(self): group = Group("sysadmin") self.assertEqual("sysadmin", group.groupid) self.assertFalse(group.has_role("admin2")) group.roles.append("admin2") self.assertTrue(group.has_role("admin2")) self.assertEqual([], group.users) self.assertFalse(group.has_user("keith")) self.assertFalse(group.has_user("fred")) user = User("keith") group.add_user(user) self.assertEqual([user], group.users) self.assertTrue(group.has_user("keith")) self.assertFalse(group.has_user("fred")) group.add_user(user) self.assertEqual([user], group.users)