-
Notifications
You must be signed in to change notification settings - Fork 95
fix: 公開向けの配信・統計・補助 API で公開状態と閲覧権限を確認する #1926
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
73fcb85
8608a75
84897aa
a82314e
5f2820e
d908598
e0b7f00
99995a8
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -49,6 +49,7 @@ | |
|
|
||
| from .config import INVENIO_CAPABILITY_URL, VALIDATE_MESSAGE, WEKO_ROOT_INDEX | ||
| from .models import ChangeListIndexes, ResourceListIndexes | ||
| from .permissions import can_download_file | ||
| from .query import get_items_by_index_tree | ||
|
|
||
| import urllib.parse | ||
|
|
@@ -475,6 +476,8 @@ def get_resource_dump_manifest(self, record_id): | |
| record = WekoRecord.get_record_by_pid(record_id) | ||
| if record: | ||
| for file in record.files: | ||
| if not can_download_file(record, file): | ||
| continue | ||
| current_app.logger.debug(file.info()) | ||
| file_info = file.info() | ||
| path = 'recid_{}/{}'.format( | ||
|
|
@@ -969,18 +972,24 @@ def get_change_dump_manifest_xml(self, record_id): | |
| else: | ||
| prev_record = None | ||
| if current_record: | ||
| list_file = [file for file in current_record.files] | ||
| list_file = [ | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix no.107 |
||
| (current_record, file) for file in current_record.files | ||
| ] | ||
| current_checksum = [ | ||
| file.info().get('checksum') for file in current_record.files | ||
| ] | ||
| prev_checksum = [] | ||
| if prev_record: | ||
| list_file.extend([file for file in prev_record.files]) | ||
| list_file.extend( | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix no.107 |
||
| [(prev_record, file) for file in prev_record.files] | ||
| ) | ||
| prev_checksum = [ | ||
| file.info().get('checksum') for file in | ||
| prev_record.files | ||
| ] | ||
| for file in list_file: | ||
| for record, file in list_file: | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix no.107 |
||
| if not can_download_file(record, file): | ||
| continue | ||
| file_info = file.info() | ||
| change = None | ||
| if file_info.get('checksum') in prev_checksum: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,87 @@ | ||
| # -*- coding: utf-8 -*- | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix no.100, 102, 104, 106, 107, 108 |
||
| # | ||
| # This file is part of WEKO3. | ||
| # Copyright (C) 2017 National Institute of Informatics. | ||
| # | ||
| # WEKO3 is free software; you can redistribute it | ||
| # and/or modify it under the terms of the GNU General Public License as | ||
| # published by the Free Software Foundation; either version 2 of the | ||
| # License, or (at your option) any later version. | ||
| # | ||
| # WEKO3 is distributed in the hope that it will be | ||
| # useful, but WITHOUT ANY WARRANTY; without even the implied warranty of | ||
| # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU | ||
| # General Public License for more details. | ||
| # | ||
| # You should have received a copy of the GNU General Public License | ||
| # along with WEKO3; if not, write to the | ||
| # Free Software Foundation, Inc., 59 Temple Place, Suite 330, Boston, | ||
| # MA 02111-1307, USA. | ||
|
|
||
| """Permissions for ResourceSync Server.""" | ||
|
|
||
| from functools import wraps | ||
|
|
||
| from flask import abort, current_app | ||
|
|
||
|
|
||
| def is_public_record(record_id): | ||
| """Check that the record is available to the public. | ||
|
|
||
| The record must be published, its publication date must have come and | ||
| it must belong to a public index. For a versioned identifier | ||
| ("<recid>.<version>") the parent record must satisfy the same | ||
| conditions. | ||
|
|
||
| :param record_id: Identifier of the record. | ||
| :return: True if the record can be distributed. | ||
| """ | ||
| from invenio_oaiserver.response import is_private_index | ||
| from weko_deposit.api import WekoRecord | ||
| from weko_records_ui.permissions import check_publish_status | ||
|
|
||
| record_ids = [str(record_id)] | ||
| if '.' in record_ids[0]: | ||
| record_ids.append(record_ids[0].split('.')[0]) | ||
|
|
||
| for _id in record_ids: | ||
| try: | ||
| record = WekoRecord.get_record_by_pid(_id) | ||
| except Exception as ex: | ||
| current_app.logger.debug(ex) | ||
| return False | ||
| if not record or not check_publish_status(record) \ | ||
| or is_private_index(record): | ||
| return False | ||
| return True | ||
|
|
||
|
|
||
| def can_download_file(record, file): | ||
| """Check that the current user can download the file of the record. | ||
|
|
||
| :param record: Record that owns the file. | ||
| :param file: File object of the record. | ||
| :return: True if the file can be downloaded. | ||
| """ | ||
| from weko_records_ui.permissions import check_file_download_permission | ||
| try: | ||
| return bool(check_file_download_permission(record, file.info())) | ||
| except Exception as ex: | ||
| current_app.logger.debug(ex) | ||
| return False | ||
|
|
||
|
|
||
| def public_record_required(param='record_id'): | ||
| """Abort with 404 unless the record in the URL is public. | ||
|
|
||
| :param param: name of the view argument holding the record identifier. | ||
| """ | ||
| def decorator(f): | ||
| @wraps(f) | ||
| def decorated(*args, **kwargs): | ||
| record_id = kwargs.get(param) | ||
| if record_id is None or not is_public_record(record_id): | ||
| abort(404) | ||
| return f(*args, **kwargs) | ||
| return decorated | ||
| return decorator | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -234,6 +234,16 @@ def _get_index_search_query(_date_from: str, _date_until: str) -> dict: | |
| "post_filter": { | ||
| "bool": { | ||
| "must": [ | ||
| { | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix no.100, 102, 104, 106, 107, 108 |
||
| # Deleted items are kept so that the change | ||
| # list can report their deletion. | ||
| "terms": { | ||
| "publish_status": [ | ||
| PublishStatus.PUBLIC.value, | ||
| PublishStatus.DELETE.value | ||
| ] | ||
| } | ||
| }, | ||
| { | ||
| "range": { | ||
| "publish_date": { | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -21,6 +21,7 @@ | |
| from weko_index_tree.models import Index | ||
|
|
||
| from .api import ChangeListHandler, ResourceListHandler | ||
| from .permissions import public_record_required | ||
| from .utils import render_capability_xml, render_well_know_resourcesync | ||
|
|
||
| blueprint = Blueprint( | ||
|
|
@@ -60,6 +61,7 @@ def resource_dump(index_id): | |
|
|
||
|
|
||
| @blueprint.route("/resync/<index_id>/<record_id>/file_content.zip") | ||
| @public_record_required() | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix no.100 |
||
| def file_content(index_id, record_id): | ||
| """Download file content.""" | ||
| resource = ResourceListHandler.get_resource_by_repository_id(index_id) | ||
|
|
@@ -80,6 +82,7 @@ def capability(): | |
|
|
||
|
|
||
| @blueprint.route("/resync/<index_id>/<record_id>/resourcedump_manifest.xml") | ||
| @public_record_required() | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix no.102 |
||
| def resource_dump_manifest(index_id, record_id): | ||
| """Render resource dump manifest.""" | ||
| resource = ResourceListHandler.get_resource_by_repository_id(index_id) | ||
|
|
@@ -138,6 +141,7 @@ def change_dump(index_id, from_date): | |
|
|
||
|
|
||
| @blueprint.route("/resync/<index_id>/<record_id>/changedump_manifest.xml") | ||
| @public_record_required() | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix no.107 |
||
| def change_dump_manifest(index_id, record_id): | ||
| """Render change dump manifest.""" | ||
| cl = ChangeListHandler.get_change_list_by_repo_id(index_id) | ||
|
|
@@ -149,6 +153,7 @@ def change_dump_manifest(index_id, record_id): | |
|
|
||
|
|
||
| @blueprint.route("/resync/<index_id>/<record_id>/change_dump_content.zip") | ||
| @public_record_required() | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix no.108 |
||
| def change_dump_content(index_id, record_id): | ||
| """Render change dump content.""" | ||
| cl = ChangeListHandler.get_change_list_by_repo_id(index_id) | ||
|
|
||
Uh oh!
There was an error while loading. Please reload this page.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
fix no.102