Akita Noek
7d932b6633
Add missing .all() from filter removal
2016-03-21 22:29:16 -04:00
Akita Noek
c7234f42c7
Give SU's access to all projects to protect against unreachable orphans
2016-03-21 22:28:05 -04:00
Akita Noek
7ca516da0b
Misc fixes for old projects tests
2016-03-21 22:17:16 -04:00
Akita Noek
b111484b89
old users tests: deprecated_userse -> member_role.members changes
2016-03-21 22:16:54 -04:00
Akita Noek
8c403cf77f
Fixed SU project access
2016-03-21 22:15:08 -04:00
Akita Noek
173ae3b2db
Fixed deprecated_teams relation, and typos
2016-03-21 22:14:39 -04:00
Akita Noek
54cf4b6e02
Grant project access to teams through role parenting
2016-03-21 22:13:12 -04:00
Akita Noek
e4a1a9c3bf
Fixed user/:id/projects after ripping out Team.users
2016-03-21 22:09:55 -04:00
Akita Noek
01e16f6722
Fixed user/:id/teams endpoint after ripping out Team.users
2016-03-21 22:09:18 -04:00
Akita Noek
6d62fbc541
Add test for most recent rbac m2m binding fail
2016-03-21 21:09:58 -04:00
Akita Noek
ec851492d6
Fixed Role m2m binding so it even works all the time
2016-03-21 21:09:22 -04:00
Akita Noek
4bb2f27fe5
Prefixed User.organizations and User.admin_of_organizations with deprecated_
2016-03-21 15:43:58 -04:00
Akita Noek
91690a0eb7
Removed deprecated use of admin_of_organizations
2016-03-21 15:43:21 -04:00
Akita Noek
b46bdef732
Ported old/organizations.py tests to new rbac system
2016-03-21 15:35:08 -04:00
Akita Noek
a5c355d753
Updated UserAccess to reflect new visibility requirements (and work)
2016-03-21 15:08:10 -04:00
Akita Noek
e4948f210f
Fixed up migrations
2016-03-18 16:31:53 -04:00
Akita Noek
92df6b0fb2
Merge branch 'devel' into rbac
2016-03-18 16:26:45 -04:00
Akita Noek
8addccd434
Renamed migrations to be a little more descriptive
...
Mainly for sanity when merging migrations into long running branches..
but nice anyways I think
2016-03-18 16:17:58 -04:00
Akita Noek
54aa465448
Merge remote-tracking branch 'ansible/rbac' into rbac
2016-03-18 15:42:58 -04:00
Akita Noek
beb4f95fa6
Merge remote-tracking branch 'ansible/rbac' into rbac
2016-03-18 15:42:06 -04:00
Akita Noek
5741b47c54
Merge remote-tracking branch 'ansible/devel' into merge-devel
2016-03-18 15:40:13 -04:00
Akita Noek
4fac1e96f4
Test that helps test the implemenation of role auto-reparenting
2016-03-18 15:11:13 -04:00
Akita Noek
23f0286669
Refactored ImplicitRoleField to be faster and avoid some bad looping cases
...
The role creation logic was a bit too lazy and caused some looping when
using other roles as parent roles. This refactor does all role
creation for a single model instance up front together, which helps
avoid these situations as well as eliminates some extra db updates and
inserts that would happen the old way.
2016-03-18 15:10:08 -04:00
Akita Noek
13dd27ac52
Merge branch 'rbac' of github.com:ansible/ansible-tower into rbac
2016-03-18 11:17:04 -04:00
Akita Noek
ccfb73766c
Code de-dup
2016-03-17 13:25:04 -04:00
Akita Noek
d997e93aa1
Removed attach/detach capabilities from organizations/:id/projects endpoint as it's no longer applicable
2016-03-17 10:07:57 -04:00
Akita Noek
1827de48af
more deprecated_users -> member_role.members fixes in tests
2016-03-17 08:56:02 -04:00
Akita Noek
ecf4d2872a
Fixes for schedule tests
2016-03-17 08:55:32 -04:00
Akita Noek
3ca016faaf
Revert ScheduleAccess can_* methods to route through other *Access classes
...
This takes care of all the polymorphic cases, which we'd have to
otherwise handle
2016-03-17 08:53:40 -04:00
Akita Noek
c0245317b3
flake8
2016-03-16 16:48:07 -04:00
Akita Noek
a1202a20ab
Added .all()'s needed after active flag filter removal
2016-03-16 16:47:35 -04:00
Akita Noek
8fb9ef37c2
Permission -> RBAC fixes in our inventory tests
2016-03-16 16:43:54 -04:00
Akita Noek
293fd73fe6
Missing .distinct()
2016-03-16 16:43:31 -04:00
Akita Noek
cf3c988330
Missing import
2016-03-16 16:43:13 -04:00
Akita Noek
e770a1f225
Removed unused dashboard inventory graph, doubly useless now that active flag is gone
2016-03-16 15:56:23 -04:00
Akita Noek
d9c80dade6
Active flag removal fallout fixes
2016-03-16 15:55:24 -04:00
Akita Noek
098ff82e7c
Updated inventory tests to use new rbac system
2016-03-16 15:07:16 -04:00
Akita Noek
1face5aa28
Dropped unused ResourceMixin from InventorySource
2016-03-16 14:19:31 -04:00
Akita Noek
99d3481976
Ported ad_hoc.py tests to use new RBAC system
2016-03-16 13:46:48 -04:00
Akita Noek
9e79cf733f
Added missing permission grants on a Inventory updater and executor roles
2016-03-16 13:46:15 -04:00
Akita Noek
55564cc2b4
Fix Credential admin_role to add itself under the user.admin_role when it exists
2016-03-16 13:16:26 -04:00
Akita Noek
75b8b0f4a6
Merge branch 'rbac' of github.com:ansible/ansible-tower into rbac
2016-03-16 11:58:46 -04:00
Akita Noek
46cb51ba2f
typo fix
2016-03-16 11:56:58 -04:00
Akita Noek
c308c07579
Removed Permission reference in the activity stream query
2016-03-16 11:37:21 -04:00
Akita Noek
598d5ba5ef
Fixed up JobAccess.get_queryset to use new RBAC system
2016-03-16 11:36:19 -04:00
Akita Noek
8d439c9468
Fixed up AdHocCommandAccess to not use old Permission query
2016-03-16 11:21:19 -04:00
Akita Noek
60fcbd78f1
Another users -> members_role.members fix
2016-03-16 10:54:35 -04:00
Akita Noek
65719615c4
Team users list update for .users -> .member_role.members
2016-03-16 10:40:31 -04:00
Akita Noek
460a14705a
Updated the org users and org admins api list endpoints to use new member_role.members
2016-03-16 10:29:12 -04:00
Akita Noek
7ec3b3b8b5
Fixed up User.accessible_objects to return a User queryset
...
Was returnning a RolePermission qs, needed to be a User qs to match.
Also bolted on the role_permissions GenericRelation so we could just
reuse the ResourceMixin accessible_objects code
2016-03-16 10:26:53 -04:00
Akita Noek
9909ea90c1
Fixed post delete behavior for roles, added test
2016-03-16 09:13:33 -04:00
Akita Noek
67b37e17cb
flake8 fixes
2016-03-16 08:54:59 -04:00
Akita Noek
8625edfec7
Merge branch 'rbac' of github.com:ansible/ansible-tower into rbac
2016-03-15 17:02:16 -04:00
Akita Noek
7e0d2e6729
more .users -> member_role.members
2016-03-15 17:00:20 -04:00
Akita Noek
defe4a4fd8
Made credentials accessible by system administrators and auditors
2016-03-15 16:51:44 -04:00
Akita Noek
ce669b03ad
Switched to a nicer contextmanager implemenation for role hierarchy rebuild batching
...
#1206
2016-03-15 15:30:43 -04:00
Akita Noek
e45982b011
Signal bindings to add permissions from hosts to groups/inventory
...
We should probably move this into a more generic system.. but for the
time being this works, we can refactor later if we have a similar need
elsewhere.
2016-03-15 14:47:36 -04:00
Akita Noek
b499555be4
Added auto_generated flag for RolePermissions
2016-03-15 13:36:28 -04:00
Akita Noek
ea9642f5df
Fixed missing .distinct() necessary for '&'
2016-03-15 13:06:24 -04:00
Akita Noek
e0e3954a8a
Fixed missing accessible_objects permission parameter
2016-03-15 13:05:58 -04:00
Akita Noek
f55d5d90f2
Merge branch 'rbac' of github.com:ansible/ansible-tower into rbac
2016-03-15 11:53:07 -04:00
Akita Noek
b380641e0e
Merge branch 'rbac' of github.com:ansible/ansible-tower into rbac
2016-03-15 11:46:27 -04:00
Akita Noek
721b95cf99
Dummy data generation script
...
Usage: ./manage.py generate_dummy_data --help
2016-03-15 11:45:56 -04:00
Akita Noek
d6429eb1e8
Active flag removal fix for .filter->all
2016-03-15 09:47:53 -04:00
Akita Noek
a845d5c0bb
we removed our previous 0008 migration, so moving 0009 -> 0008
2016-03-15 09:34:50 -04:00
Akita Noek
6ea99583da
Mass active flag code removal
2016-03-15 09:29:55 -04:00
Akita Noek
ba833d683e
Active flag removal: switched from using mark_inactive to delete calls
2016-03-15 09:29:28 -04:00
Akita Noek
1e7c71edfb
active flag removal in migration functions
2016-03-15 09:29:28 -04:00
Akita Noek
ddf3265bd2
Reordered system job template migration to happen after rbac migrations
...
The system job template migration creates SystemJobTemplate instances,
which necessarily depend on the RBAC modifications.
2016-03-15 09:27:06 -04:00
Akita Noek
26f73fa68e
Remove active flag from ever getting created in the rbac models
2016-03-15 09:26:31 -04:00
Akita Noek
4825b2a6fc
Do cleanup_deleted on migrate. Re-ordered active flag removal to be before system job template creation.
...
Also removed active flag deletes from remaining cleanup_deleted
management command as they will no longer be needed - but the
deletes of the authentication tokens as well as potentially disabled
users are still necessary, so the cleanup_deleted command will continue
to exist.
Reordering of the active flag removal to happen before the system job
template creation is necessary since the system job template creation
hits the license checker which at some point runs queries that depend on
the active flag, and with that code changing to not use the active flag,
we need to do the removal before we run this code.
2016-03-15 09:26:31 -04:00
Akita Noek
ec59330465
Active flag removed from Primordial Base Class
2016-03-15 09:26:31 -04:00
Akita Noek
ab23e983f8
More team/org users/admins -> member_role/admin_role updates
2016-03-14 17:00:59 -04:00
Akita Noek
c9b0625e39
More accessible_objects -> objects + filter
2016-03-14 16:50:52 -04:00
Akita Noek
05b98d4904
Removed accessible_objects filter from ActivityStream get_queryset
2016-03-14 16:32:59 -04:00
Akita Noek
495b5b9341
project test case fix, missing pytest marker
2016-03-14 16:28:57 -04:00
Akita Noek
6549a0225b
Various org.admins -> org.admin_role.members transformations
2016-03-14 16:28:24 -04:00
Akita Noek
0c0ed45b44
Removed api/v1/projects/N/organizations as it is no longer relevant
...
Also added 'organization' related field to the project
2016-03-14 16:26:15 -04:00
Akita Noek
7cf28e2f03
More project migration fixes
2016-03-14 16:01:12 -04:00
Akita Noek
9146b29770
Fix up some project multi-org -> single-org fallout
2016-03-14 15:31:05 -04:00
Akita Noek
820ed0b747
Merge branch 'rbac' of github.com:ansible/ansible-tower into rbac
2016-03-14 15:05:01 -04:00
Akita Noek
ba6752fb23
Eliminate multiple-organization projects
...
Projects are duplicated with this migration to provide a nearly
equivalent functionality.
Satisifies #1164
2016-03-14 14:57:24 -04:00
Akita Noek
97a6f23380
Fixed up migrations after last merge
2016-03-09 13:08:02 -05:00
Akita Noek
9d4e6dfc16
Merge branch 'devel' of github.com:ansible/ansible-tower into rbac
2016-03-09 12:04:05 -05:00
Akita Noek
9c78a85a70
Removed old test assertion
2016-03-09 12:03:20 -05:00
Akita Noek
1989012fd5
Moved access_list url to <whatever>/id/access_list
...
Eg: organizations/1/access_list will now return a list of all users who
have access to that organization.
This replaces our initial implementation which was resources/id/access_list
2016-03-09 11:41:42 -05:00
Akita Noek
efcd4efda2
Moved the rbac field removal migration to happen after the migrate script part of the rbac migration
2016-03-09 11:31:00 -05:00
Akita Noek
87219135af
Removed unneeded import
2016-03-09 10:39:31 -05:00
Akita Noek
b486c8d658
Merge branch 'rbac-resource-gfk' into rbac
2016-03-09 10:17:58 -05:00
Akita Noek
9aae2979d9
Replaced our 'Resource' table with a GenericForeignKey in RolePermission
2016-03-09 10:12:05 -05:00
Akita Noek
e9c3d98a44
Merge branch 'devel' of github.com:ansible/ansible-tower into rbac
2016-03-04 14:02:01 -05:00
Akita Noek
5a31804330
Just use num_pages when we're at the end of a nav list
2016-03-04 13:37:07 -05:00
Akita Noek
e28eec4a56
Fix missing semicolons
2016-03-04 11:37:47 -05:00
Akita Noek
cf5d718fa8
Fixed pagination nav issue
...
Fixes #1021
2016-03-04 11:36:57 -05:00
Akita Noek
db6117a56d
Added role description fields
...
Completes #1096
2016-03-03 16:19:10 -05:00
Akita Noek
048e65eab3
Add test to help detect incorrect role rebuilding
2016-03-03 13:54:45 -05:00
Akita Noek
c15d48a640
Locked down user/team role listing and role membership management api endpoints
2016-03-02 16:36:16 -05:00
Akita Noek
9699f34976
Made org admin role a parent of org member role so admins pick up everything members are granted
2016-03-02 09:44:55 -05:00
Akita Noek
444aed1ab2
Switch make init to use manage.py directly instead of awx-manage, saves from having to install in order to do an init
2016-03-01 15:37:00 -05:00
Akita Noek
3db13bc33c
Updated fact tests to use the divergent group fixture
...
A group fixture was created in different ways, one on devel and one on
rbac, this patch just normalizes to the one usage
2016-03-01 15:34:26 -05:00