8dd05d5431
commit270739a45a
Author: Jens Langhammer <jens.langhammer@beryju.org> Date: Thu May 28 21:50:43 2020 +0200 admin: fix policy testing form not showing the correct result commitdf8995deed
Author: Jens L <jens@beryju.org> Date: Thu May 28 21:45:54 2020 +0200 policies/*: remove Policy.negate, order, timeout (#39) policies: rewrite engine to use PolicyBinding for order/negate/timeout policies: rewrite engine to use PolicyResult instead of tuple commitfdfc6472d2
Author: Jens Langhammer <jens.langhammer@beryju.org> Date: Thu May 28 10:36:10 2020 +0200 admin: fixup some urls commitbc495828e7
Author: dependabot-preview[bot] <27856297+dependabot-preview[bot]@users.noreply.github.com> Date: Thu May 28 09:39:28 2020 +0200 build(deps): bump django-redis from 4.11.0 to 4.12.1 (#38) Bumps [django-redis](https://github.com/jazzband/django-redis) from 4.11.0 to 4.12.1. - [Release notes](https://github.com/jazzband/django-redis/releases) - [Changelog](https://github.com/jazzband/django-redis/blob/master/CHANGES.rst) - [Commits](https://github.com/jazzband/django-redis/compare/4.11.0...4.12.1) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> Co-authored-by: dependabot-preview[bot] <27856297+dependabot-preview[bot]@users.noreply.github.com> commitfa138a273f
Author: dependabot-preview[bot] <27856297+dependabot-preview[bot]@users.noreply.github.com> Date: Thu May 28 08:59:19 2020 +0200 build(deps): bump boto3 from 1.13.17 to 1.13.18 (#37) Bumps [boto3](https://github.com/boto/boto3) from 1.13.17 to 1.13.18. - [Release notes](https://github.com/boto/boto3/releases) - [Changelog](https://github.com/boto/boto3/blob/develop/CHANGELOG.rst) - [Commits](https://github.com/boto/boto3/compare/1.13.17...1.13.18) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> Co-authored-by: dependabot-preview[bot] <27856297+dependabot-preview[bot]@users.noreply.github.com>
88 lines
2.6 KiB
Python
88 lines
2.6 KiB
Python
"""Policy base models"""
|
|
from uuid import uuid4
|
|
|
|
from django.db import models
|
|
from django.utils.translation import gettext_lazy as _
|
|
from model_utils.managers import InheritanceManager
|
|
|
|
from passbook.lib.models import (
|
|
CreatedUpdatedModel,
|
|
InheritanceAutoManager,
|
|
InheritanceForeignKey,
|
|
)
|
|
from passbook.policies.exceptions import PolicyException
|
|
from passbook.policies.types import PolicyRequest, PolicyResult
|
|
|
|
|
|
class PolicyBindingModel(models.Model):
|
|
"""Base Model for objects that have policies applied to them."""
|
|
|
|
pbm_uuid = models.UUIDField(primary_key=True, editable=False, default=uuid4)
|
|
|
|
policies = models.ManyToManyField(
|
|
"Policy", through="PolicyBinding", related_name="bindings", blank=True
|
|
)
|
|
|
|
objects = InheritanceManager()
|
|
|
|
class Meta:
|
|
verbose_name = _("Policy Binding Model")
|
|
verbose_name_plural = _("Policy Binding Models")
|
|
|
|
|
|
class PolicyBinding(models.Model):
|
|
"""Relationship between a Policy and a PolicyBindingModel."""
|
|
|
|
policy_binding_uuid = models.UUIDField(
|
|
primary_key=True, editable=False, default=uuid4
|
|
)
|
|
|
|
enabled = models.BooleanField(default=True)
|
|
|
|
policy = InheritanceForeignKey("Policy", on_delete=models.CASCADE, related_name="+")
|
|
target = models.ForeignKey(
|
|
PolicyBindingModel, on_delete=models.CASCADE, related_name="+"
|
|
)
|
|
negate = models.BooleanField(
|
|
default=False,
|
|
help_text=_("Negates the outcome of the policy. Messages are unaffected."),
|
|
)
|
|
timeout = models.IntegerField(
|
|
default=30, help_text=_("Timeout after which Policy execution is terminated.")
|
|
)
|
|
|
|
order = models.IntegerField()
|
|
|
|
def __str__(self) -> str:
|
|
return f"PolicyBinding policy={self.policy} target={self.target} order={self.order}"
|
|
|
|
class Meta:
|
|
|
|
verbose_name = _("Policy Binding")
|
|
verbose_name_plural = _("Policy Bindings")
|
|
unique_together = ("policy", "target", "order")
|
|
|
|
|
|
class Policy(CreatedUpdatedModel):
|
|
"""Policies which specify if a user is authorized to use an Application. Can be overridden by
|
|
other types to add other fields, more logic, etc."""
|
|
|
|
policy_uuid = models.UUIDField(primary_key=True, editable=False, default=uuid4)
|
|
|
|
name = models.TextField(blank=True, null=True)
|
|
|
|
objects = InheritanceAutoManager()
|
|
|
|
def __str__(self):
|
|
return f"Policy {self.name}"
|
|
|
|
def passes(self, request: PolicyRequest) -> PolicyResult:
|
|
"""Check if user instance passes this policy"""
|
|
raise PolicyException()
|
|
|
|
class Meta:
|
|
base_manager_name = "objects"
|
|
|
|
verbose_name = _("Policy")
|
|
verbose_name_plural = _("Policies")
|