Akita Noek
9dc4f3e07d
Merge pull request #1280 from anoek/rbac
...
Refactored ImplicitRoleField
2016-03-18 15:41:54 -04:00
Akita Noek
4fac1e96f4
Test that helps test the implemenation of role auto-reparenting
2016-03-18 15:11:13 -04:00
Akita Noek
23f0286669
Refactored ImplicitRoleField to be faster and avoid some bad looping cases
...
The role creation logic was a bit too lazy and caused some looping when
using other roles as parent roles. This refactor does all role
creation for a single model instance up front together, which helps
avoid these situations as well as eliminates some extra db updates and
inserts that would happen the old way.
2016-03-18 15:10:08 -04:00
Wayne Witzel III
8a1f21de12
Merge pull request #1265 from anoek/rbac
...
Various small fixes and progress on making 'old' tests work again on RBAC
2016-03-18 11:21:10 -04:00
Akita Noek
13dd27ac52
Merge branch 'rbac' of github.com:ansible/ansible-tower into rbac
2016-03-18 11:17:04 -04:00
Wayne Witzel III
3a11bca31f
Merge pull request #1270 from wwitzel3/rbac
...
Credential migration and initial tests
2016-03-17 16:28:48 -04:00
Wayne Witzel III
766190fb80
Use getattrd instead of reduce
2016-03-17 16:27:47 -04:00
Wayne Witzel III
6d249f38a7
Fix credential assertions and rename migration helpers
2016-03-17 15:41:46 -04:00
Akita Noek
ccfb73766c
Code de-dup
2016-03-17 13:25:04 -04:00
Wayne Witzel III
74e2c440a5
Rename credential migration helpers
2016-03-17 11:37:59 -04:00
Wayne Witzel III
b59e960b46
Credential migration and initial tests
2016-03-17 11:21:10 -04:00
Akita Noek
d997e93aa1
Removed attach/detach capabilities from organizations/:id/projects endpoint as it's no longer applicable
2016-03-17 10:07:57 -04:00
Akita Noek
1827de48af
more deprecated_users -> member_role.members fixes in tests
2016-03-17 08:56:02 -04:00
Akita Noek
ecf4d2872a
Fixes for schedule tests
2016-03-17 08:55:32 -04:00
Akita Noek
3ca016faaf
Revert ScheduleAccess can_* methods to route through other *Access classes
...
This takes care of all the polymorphic cases, which we'd have to
otherwise handle
2016-03-17 08:53:40 -04:00
Akita Noek
c0245317b3
flake8
2016-03-16 16:48:07 -04:00
Akita Noek
a1202a20ab
Added .all()'s needed after active flag filter removal
2016-03-16 16:47:35 -04:00
Akita Noek
8fb9ef37c2
Permission -> RBAC fixes in our inventory tests
2016-03-16 16:43:54 -04:00
Akita Noek
293fd73fe6
Missing .distinct()
2016-03-16 16:43:31 -04:00
Akita Noek
cf3c988330
Missing import
2016-03-16 16:43:13 -04:00
Akita Noek
e770a1f225
Removed unused dashboard inventory graph, doubly useless now that active flag is gone
2016-03-16 15:56:23 -04:00
Akita Noek
d9c80dade6
Active flag removal fallout fixes
2016-03-16 15:55:24 -04:00
Akita Noek
098ff82e7c
Updated inventory tests to use new rbac system
2016-03-16 15:07:16 -04:00
Akita Noek
1face5aa28
Dropped unused ResourceMixin from InventorySource
2016-03-16 14:19:31 -04:00
Akita Noek
99d3481976
Ported ad_hoc.py tests to use new RBAC system
2016-03-16 13:46:48 -04:00
Akita Noek
9e79cf733f
Added missing permission grants on a Inventory updater and executor roles
2016-03-16 13:46:15 -04:00
Akita Noek
55564cc2b4
Fix Credential admin_role to add itself under the user.admin_role when it exists
2016-03-16 13:16:26 -04:00
Akita Noek
75b8b0f4a6
Merge branch 'rbac' of github.com:ansible/ansible-tower into rbac
2016-03-16 11:58:46 -04:00
Akita Noek
46cb51ba2f
typo fix
2016-03-16 11:56:58 -04:00
Akita Noek
c308c07579
Removed Permission reference in the activity stream query
2016-03-16 11:37:21 -04:00
Akita Noek
598d5ba5ef
Fixed up JobAccess.get_queryset to use new RBAC system
2016-03-16 11:36:19 -04:00
Akita Noek
8d439c9468
Fixed up AdHocCommandAccess to not use old Permission query
2016-03-16 11:21:19 -04:00
Akita Noek
60fcbd78f1
Another users -> members_role.members fix
2016-03-16 10:54:35 -04:00
Akita Noek
65719615c4
Team users list update for .users -> .member_role.members
2016-03-16 10:40:31 -04:00
Akita Noek
460a14705a
Updated the org users and org admins api list endpoints to use new member_role.members
2016-03-16 10:29:12 -04:00
Akita Noek
7ec3b3b8b5
Fixed up User.accessible_objects to return a User queryset
...
Was returnning a RolePermission qs, needed to be a User qs to match.
Also bolted on the role_permissions GenericRelation so we could just
reuse the ResourceMixin accessible_objects code
2016-03-16 10:26:53 -04:00
Wayne Witzel III
63d8efc268
Merge pull request #1256 from anoek/rbac
...
Misc RBAC fixes and enhancements
2016-03-16 10:18:13 -04:00
Akita Noek
9909ea90c1
Fixed post delete behavior for roles, added test
2016-03-16 09:13:33 -04:00
Akita Noek
67b37e17cb
flake8 fixes
2016-03-16 08:54:59 -04:00
Akita Noek
8625edfec7
Merge branch 'rbac' of github.com:ansible/ansible-tower into rbac
2016-03-15 17:02:16 -04:00
Akita Noek
7e0d2e6729
more .users -> member_role.members
2016-03-15 17:00:20 -04:00
Akita Noek
defe4a4fd8
Made credentials accessible by system administrators and auditors
2016-03-15 16:51:44 -04:00
Akita Noek
ce669b03ad
Switched to a nicer contextmanager implemenation for role hierarchy rebuild batching
...
#1206
2016-03-15 15:30:43 -04:00
Wayne Witzel III
3197327b7f
Merge pull request #1252 from wwitzel3/rbac
...
Fixing Inventory access
2016-03-15 14:56:58 -04:00
Wayne Witzel III
0e8b7ab4f4
Fixing Inventory access
2016-03-15 14:56:35 -04:00
Akita Noek
e45982b011
Signal bindings to add permissions from hosts to groups/inventory
...
We should probably move this into a more generic system.. but for the
time being this works, we can refactor later if we have a similar need
elsewhere.
2016-03-15 14:47:36 -04:00
Akita Noek
b499555be4
Added auto_generated flag for RolePermissions
2016-03-15 13:36:28 -04:00
Akita Noek
ea9642f5df
Fixed missing .distinct() necessary for '&'
2016-03-15 13:06:24 -04:00
Akita Noek
e0e3954a8a
Fixed missing accessible_objects permission parameter
2016-03-15 13:05:58 -04:00
Akita Noek
f55d5d90f2
Merge branch 'rbac' of github.com:ansible/ansible-tower into rbac
2016-03-15 11:53:07 -04:00