mirror of
https://github.com/ansible/awx.git
synced 2026-05-17 14:27:42 -02:30
Add better 403 error message for Job template create (#15307)
* Add better 403 error message for Job template create To create Job template u need access to projects and inventory --------- Co-authored-by: Chris Meyers <chris.meyers.fsu@gmail.com>
This commit is contained in:
@@ -2392,6 +2392,14 @@ class JobTemplateList(ListCreateAPIView):
|
|||||||
serializer_class = serializers.JobTemplateSerializer
|
serializer_class = serializers.JobTemplateSerializer
|
||||||
always_allow_superuser = False
|
always_allow_superuser = False
|
||||||
|
|
||||||
|
def check_permissions(self, request):
|
||||||
|
if request.method == 'POST':
|
||||||
|
can_access, messages = request.user.can_access_with_errors(self.model, 'add', request.data)
|
||||||
|
if not can_access:
|
||||||
|
self.permission_denied(request, message=messages)
|
||||||
|
|
||||||
|
super(JobTemplateList, self).check_permissions(request)
|
||||||
|
|
||||||
|
|
||||||
class JobTemplateDetail(RelatedJobsPreventDeleteMixin, RetrieveUpdateDestroyAPIView):
|
class JobTemplateDetail(RelatedJobsPreventDeleteMixin, RetrieveUpdateDestroyAPIView):
|
||||||
model = models.JobTemplate
|
model = models.JobTemplate
|
||||||
|
|||||||
@@ -1595,6 +1595,8 @@ class JobTemplateAccess(NotificationAttachMixin, UnifiedCredentialsMixin, BaseAc
|
|||||||
inventory = get_value(Inventory, 'inventory')
|
inventory = get_value(Inventory, 'inventory')
|
||||||
if inventory:
|
if inventory:
|
||||||
if self.user not in inventory.use_role:
|
if self.user not in inventory.use_role:
|
||||||
|
if self.save_messages:
|
||||||
|
self.messages['inventory'] = [_('You do not have use permission on Inventory')]
|
||||||
return False
|
return False
|
||||||
|
|
||||||
if not self.check_related('execution_environment', ExecutionEnvironment, data, role_field='read_role'):
|
if not self.check_related('execution_environment', ExecutionEnvironment, data, role_field='read_role'):
|
||||||
@@ -1603,11 +1605,16 @@ class JobTemplateAccess(NotificationAttachMixin, UnifiedCredentialsMixin, BaseAc
|
|||||||
project = get_value(Project, 'project')
|
project = get_value(Project, 'project')
|
||||||
# If the user has admin access to the project (as an org admin), should
|
# If the user has admin access to the project (as an org admin), should
|
||||||
# be able to proceed without additional checks.
|
# be able to proceed without additional checks.
|
||||||
if project:
|
if not project:
|
||||||
return self.user in project.use_role
|
|
||||||
else:
|
|
||||||
return False
|
return False
|
||||||
|
|
||||||
|
if self.user not in project.use_role:
|
||||||
|
if self.save_messages:
|
||||||
|
self.messages['project'] = [_('You do not have use permission on Project')]
|
||||||
|
return False
|
||||||
|
|
||||||
|
return True
|
||||||
|
|
||||||
@check_superuser
|
@check_superuser
|
||||||
def can_copy_related(self, obj):
|
def can_copy_related(self, obj):
|
||||||
"""
|
"""
|
||||||
|
|||||||
@@ -182,8 +182,14 @@ def test_job_template_creator_access(project, organization, rando, post, setup_m
|
|||||||
|
|
||||||
@pytest.mark.django_db
|
@pytest.mark.django_db
|
||||||
@pytest.mark.job_permissions
|
@pytest.mark.job_permissions
|
||||||
@pytest.mark.parametrize('lacking', ['project', 'inventory'])
|
@pytest.mark.parametrize(
|
||||||
def test_job_template_insufficient_creator_permissions(lacking, project, inventory, organization, rando, post):
|
'lacking,reason',
|
||||||
|
[
|
||||||
|
('project', 'You do not have use permission on Project'),
|
||||||
|
('inventory', 'You do not have use permission on Inventory'),
|
||||||
|
],
|
||||||
|
)
|
||||||
|
def test_job_template_insufficient_creator_permissions(lacking, reason, project, inventory, organization, rando, post):
|
||||||
if lacking != 'project':
|
if lacking != 'project':
|
||||||
project.use_role.members.add(rando)
|
project.use_role.members.add(rando)
|
||||||
else:
|
else:
|
||||||
@@ -192,12 +198,13 @@ def test_job_template_insufficient_creator_permissions(lacking, project, invento
|
|||||||
inventory.use_role.members.add(rando)
|
inventory.use_role.members.add(rando)
|
||||||
else:
|
else:
|
||||||
inventory.read_role.members.add(rando)
|
inventory.read_role.members.add(rando)
|
||||||
post(
|
response = post(
|
||||||
url=reverse('api:job_template_list'),
|
url=reverse('api:job_template_list'),
|
||||||
data=dict(name='newly-created-jt', inventory=inventory.id, project=project.pk, playbook='helloworld.yml'),
|
data=dict(name='newly-created-jt', inventory=inventory.id, project=project.pk, playbook='helloworld.yml'),
|
||||||
user=rando,
|
user=rando,
|
||||||
expect=403,
|
expect=403,
|
||||||
)
|
)
|
||||||
|
assert reason in response.data[lacking]
|
||||||
|
|
||||||
|
|
||||||
@pytest.mark.django_db
|
@pytest.mark.django_db
|
||||||
|
|||||||
Reference in New Issue
Block a user