-
Notifications
You must be signed in to change notification settings - Fork 95
fix: 管理系 API の担当範囲を確認し、SWORD の登録可能ロールの設定を効かせる #1927
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -21,10 +21,12 @@ | |
| """Views for weko-admin.""" | ||
|
|
||
| import calendar | ||
| import inspect | ||
| import json | ||
| import sys | ||
| import time | ||
| from datetime import timedelta, datetime | ||
| from functools import wraps | ||
| import traceback | ||
|
|
||
| from flask import Blueprint, Response, abort, current_app, flash, json, \ | ||
|
|
@@ -541,12 +543,54 @@ def resend_failed_mail(): | |
| return jsonify(result) | ||
|
|
||
|
|
||
| def _is_repository_in_user_scope(repo_id): | ||
| """Check whether the current user administers the given repository. | ||
|
|
||
| System and Repository Administrators can handle any repository. | ||
| Other administrators are limited to the repositories they are assigned | ||
| to, in the same way as the repository selector of the admin screens. | ||
|
|
||
| :param repo_id: Repository id. | ||
| :return: True if the current user can handle the repository. | ||
| """ | ||
| from invenio_communities.models import Community | ||
| super_roles = current_app.config.get( | ||
| 'WEKO_PERMISSION_SUPER_ROLE_USER', | ||
| [WEKO_ADMIN_PERMISSION_ROLE_SYSTEM, WEKO_ADMIN_PERMISSION_ROLE_REPO]) | ||
| if any(role.name in super_roles for role in current_user.roles): | ||
| return True | ||
| if not repo_id: | ||
| return False | ||
| return any(repo.id == repo_id | ||
| for repo in Community.get_repositories_by_user(current_user)) | ||
|
|
||
|
|
||
| def _form_repository_scope_required(func): | ||
| """Require ``repo_id`` sent in the form to be in the user's scope. | ||
|
|
||
| The check applies only when the view reads ``repo_id`` from the form; | ||
| internal callers that pass ``repo_id`` explicitly are not affected. | ||
| """ | ||
| signature = inspect.signature(func) | ||
|
|
||
| @wraps(func) | ||
| def decorated_view(*args, **kwargs): | ||
| bound = signature.bind_partial(*args, **kwargs) | ||
| if not bound.arguments.get('repo_id'): | ||
| if not _is_repository_in_user_scope(request.form.get('repo_id')): | ||
| abort(403) | ||
| return func(*args, **kwargs) | ||
|
|
||
| return decorated_view | ||
|
|
||
|
|
||
| @blueprint_api.route('/sitelicensesendmail/send/<start_month>/<end_month>', | ||
| methods=['POST']) | ||
| @login_required | ||
| @roles_required([WEKO_ADMIN_PERMISSION_ROLE_SYSTEM, | ||
| WEKO_ADMIN_PERMISSION_ROLE_REPO, | ||
| WEKO_ADMIN_PERMISSION_ROLE_COMMUNITY]) | ||
| @_form_repository_scope_required | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix no.211 |
||
| def manual_send_site_license_mail(start_month, end_month, repo_id=None): | ||
| """Send site license mail by manual.""" | ||
| if not repo_id: | ||
|
|
@@ -721,6 +765,9 @@ def get_ogp_image(): | |
|
|
||
| @blueprint_api.route('/search/init_display_index/<string:selected_index>', | ||
| methods=['GET']) | ||
| @login_required | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix no.217 |
||
| @roles_required([WEKO_ADMIN_PERMISSION_ROLE_SYSTEM, | ||
| WEKO_ADMIN_PERMISSION_ROLE_REPO]) | ||
| def get_search_init_display_index(selected_index=None): | ||
| """Get search init display index. | ||
|
|
||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -13,6 +13,7 @@ | |
| from invenio_oauth2server.decorators import ( | ||
| require_api_auth, require_oauth_scopes | ||
| ) | ||
| from weko_accounts.utils import roles_required | ||
|
|
||
| from .errors import ErrorType, WekoSwordserverException | ||
|
|
||
|
|
@@ -44,6 +45,24 @@ def decorated(*args, **kwargs): | |
| return decorated | ||
| return wrapper | ||
|
|
||
| def check_deposit_role(): | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix no.571 |
||
| """Decorator to check the roles allowed to deposit items. | ||
|
|
||
| The allowed roles are read from | ||
| ``WEKO_SWORDSERVER_DEPOSIT_ROLE_ENABLE`` on each request, so that the | ||
| application configuration is applied. | ||
| """ | ||
| def wrapper(f): | ||
| @wraps(f) | ||
| def decorated(*args, **kwargs): | ||
| roles = current_app.config.get( | ||
| "WEKO_SWORDSERVER_DEPOSIT_ROLE_ENABLE", [] | ||
| ) | ||
| return roles_required(roles)(f)(*args, **kwargs) | ||
| return decorated | ||
| return wrapper | ||
|
|
||
|
|
||
| def check_on_behalf_of(): | ||
| """Decorator to check onBehalfOf header.""" | ||
| def wrapper(f): | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -35,7 +35,6 @@ | |
| from invenio_pidstore.resolver import Resolver | ||
| from werkzeug.utils import import_string | ||
|
|
||
| from weko_accounts.utils import roles_required | ||
| from weko_admin.api import TempDirInfo | ||
| from weko_deposit.api import WekoRecord | ||
| from weko_items_ui.scopes import item_create_scope, item_update_scope, item_delete_scope | ||
|
|
@@ -50,8 +49,9 @@ | |
| from weko_workflow.utils import get_site_info_name | ||
| from weko_workflow.scopes import activity_scope | ||
|
|
||
| from .config import WEKO_SWORDSERVER_DEPOSIT_ROLE_ENABLE | ||
| from .decorators import check_on_behalf_of, check_package_contents | ||
| from .decorators import ( | ||
| check_deposit_role, check_on_behalf_of, check_package_contents | ||
| ) | ||
| from .errors import ErrorType, WekoSwordserverException | ||
| from .utils import ( | ||
| check_import_file_format, | ||
|
|
@@ -172,7 +172,7 @@ def get_service_document(): | |
| @limiter.limit("") | ||
| @require_oauth_scopes(write_scope.id, actions_scope.id) | ||
| @require_oauth_scopes(item_create_scope.id) | ||
| @roles_required(WEKO_SWORDSERVER_DEPOSIT_ROLE_ENABLE) | ||
| @check_deposit_role() | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix no.571 |
||
| @check_on_behalf_of() | ||
| @check_package_contents() | ||
| def post_service_document(): | ||
|
|
@@ -488,7 +488,7 @@ def process_item(item, request_info): | |
| @limiter.limit("") | ||
| @require_oauth_scopes(write_scope.id, actions_scope.id) | ||
| @require_oauth_scopes(item_update_scope.id) | ||
| @roles_required(WEKO_SWORDSERVER_DEPOSIT_ROLE_ENABLE) | ||
| @check_deposit_role() | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix no.571 |
||
| @check_on_behalf_of() | ||
| @check_package_contents() | ||
| def put_object(recid): | ||
|
|
@@ -1202,7 +1202,7 @@ def link_key(link): | |
| @limiter.limit("") | ||
| @require_oauth_scopes(write_scope.id, actions_scope.id) | ||
| @require_oauth_scopes(item_delete_scope.id) | ||
| @roles_required(WEKO_SWORDSERVER_DEPOSIT_ROLE_ENABLE) | ||
| @check_deposit_role() | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix no.571 |
||
| @check_on_behalf_of() | ||
| def delete_object(recid): | ||
| """Deleting the entire Object | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
fix no.211