|
| 1 | +# coding=utf-8 |
| 2 | +""" |
| 3 | + @project: MaxKB |
| 4 | + @Author:虎虎 |
| 5 | + @file: workspace_user_resource_permission.py |
| 6 | + @date:2025/4/28 17:17 |
| 7 | + @desc: |
| 8 | +""" |
| 9 | +import json |
| 10 | +import os |
| 11 | + |
| 12 | +from django.core.cache import cache |
| 13 | +from django.db.models import QuerySet |
| 14 | +from django.utils.translation import gettext_lazy as _ |
| 15 | +from rest_framework import serializers |
| 16 | + |
| 17 | +from common.constants.cache_version import Cache_Version |
| 18 | +from common.constants.permission_constants import get_default_workspace_user_role_mapping_list, RoleConstants, \ |
| 19 | + ResourcePermissionGroup, ResourcePermissionRole, ResourceAuthType |
| 20 | +from common.database_model_manage.database_model_manage import DatabaseModelManage |
| 21 | +from common.db.search import native_search |
| 22 | +from common.db.sql_execute import select_list |
| 23 | +from common.exception.app_exception import AppApiException |
| 24 | +from common.utils.common import get_file_content |
| 25 | +from common.utils.split_model import group_by |
| 26 | +from knowledge.models import Knowledge |
| 27 | +from maxkb.conf import PROJECT_DIR |
| 28 | +from system_manage.models import WorkspaceUserResourcePermission, AuthTargetType |
| 29 | + |
| 30 | + |
| 31 | +class PermissionSerializer(serializers.Serializer): |
| 32 | + VIEW = serializers.BooleanField(required=True, label="可读") |
| 33 | + MANAGE = serializers.BooleanField(required=True, label="管理") |
| 34 | + ROLE = serializers.BooleanField(required=True, label="跟随角色") |
| 35 | + |
| 36 | + |
| 37 | +class UserResourcePermissionItemResponse(serializers.Serializer): |
| 38 | + id = serializers.UUIDField(required=True, label="主键id") |
| 39 | + name = serializers.CharField(required=True, label="资源名称") |
| 40 | + auth_target_type = serializers.ChoiceField(required=True, choices=AuthTargetType.choices, label="授权资源") |
| 41 | + user_id = serializers.UUIDField(required=True, label="用户id") |
| 42 | + auth_type = serializers.ChoiceField(required=True, choices=ResourceAuthType.choices, label="授权类型") |
| 43 | + permission = PermissionSerializer() |
| 44 | + |
| 45 | + |
| 46 | +class UserResourcePermissionResponse(serializers.Serializer): |
| 47 | + KNOWLEDGE = UserResourcePermissionItemResponse(many=True) |
| 48 | + |
| 49 | + |
| 50 | +class UpdateTeamMemberItemPermissionSerializer(serializers.Serializer): |
| 51 | + auth_target_type = serializers.ChoiceField(required=True, choices=AuthTargetType.choices, label="授权资源") |
| 52 | + target_id = serializers.CharField(required=True, label=_('target id')) |
| 53 | + auth_type = serializers.ChoiceField(required=True, choices=ResourceAuthType.choices, label="授权类型") |
| 54 | + permission = PermissionSerializer(required=True, many=False) |
| 55 | + |
| 56 | + |
| 57 | +class UpdateUserResourcePermissionRequest(serializers.Serializer): |
| 58 | + user_resource_permission_list = UpdateTeamMemberItemPermissionSerializer(required=True, many=True) |
| 59 | + |
| 60 | + def is_valid(self, *, workspace_id=None, raise_exception=False): |
| 61 | + super().is_valid(raise_exception=True) |
| 62 | + user_resource_permission_list = self.data.get("user_resource_permission_list") |
| 63 | + illegal_target_id_list = select_list( |
| 64 | + get_file_content( |
| 65 | + os.path.join(PROJECT_DIR, "apps", "system_manage", 'sql', 'check_member_permission_target_exists.sql')), |
| 66 | + [json.dumps(user_resource_permission_list), workspace_id]) |
| 67 | + if illegal_target_id_list is not None and len(illegal_target_id_list) > 0: |
| 68 | + raise AppApiException(500, |
| 69 | + _('Non-existent application|knowledge base id[') + str(illegal_target_id_list) + ']') |
| 70 | + |
| 71 | + |
| 72 | +class UserResourcePermissionSerializer(serializers.Serializer): |
| 73 | + workspace_id = serializers.CharField(required=True, label=_('workspace id')) |
| 74 | + |
| 75 | + def get_queryset(self): |
| 76 | + return { |
| 77 | + "knowledge_query_set": QuerySet(Knowledge) |
| 78 | + .filter(workspace_id=self.data.get('workspace_id')), |
| 79 | + 'workspace_user_resource_permission_query_set': QuerySet(WorkspaceUserResourcePermission).filter( |
| 80 | + workspace_id=self.data.get('workspace_id')) |
| 81 | + } |
| 82 | + |
| 83 | + def list(self, user, with_valid=True): |
| 84 | + if with_valid: |
| 85 | + self.is_valid(raise_exception=True) |
| 86 | + workspace_id = self.data.get("workspace_id") |
| 87 | + # 用户权限列表 |
| 88 | + user_resource_permission_list = native_search(self.get_queryset(), get_file_content( |
| 89 | + os.path.join(PROJECT_DIR, "apps", "system_manage", 'sql', 'get_user_resource_permission.sql'))) |
| 90 | + workspace_user_role_mapping_model = DatabaseModelManage.get_model("workspace_user_role_mapping") |
| 91 | + workspace_model = DatabaseModelManage.get_model("workspace_model") |
| 92 | + if workspace_user_role_mapping_model and workspace_model: |
| 93 | + workspace_user_role_mapping_list = QuerySet(workspace_user_role_mapping_model).filter(user_id=user.id, |
| 94 | + workspace_id=workspace_id) |
| 95 | + else: |
| 96 | + workspace_user_role_mapping_list = get_default_workspace_user_role_mapping_list([user.role]) |
| 97 | + is_workspace_manage = any( |
| 98 | + [workspace_user_role_mapping for workspace_user_role_mapping in workspace_user_role_mapping_list if |
| 99 | + workspace_user_role_mapping.role_id == RoleConstants.WORKSPACE_MANAGE.value]) |
| 100 | + # 如果当前用户是当前工作空间管理员那么就拥有所有权限 |
| 101 | + if is_workspace_manage: |
| 102 | + user_resource_permission_list = list( |
| 103 | + map(lambda row: {**row, |
| 104 | + 'permission': {ResourcePermissionGroup.VIEW.value: True, |
| 105 | + ResourcePermissionGroup.MANAGE.value: True, |
| 106 | + ResourcePermissionRole.ROLE.value: True}}, |
| 107 | + user_resource_permission_list)) |
| 108 | + return group_by([{**user_resource_permission, 'permission': { |
| 109 | + permission: True if user_resource_permission.get('permission_list').__contains__(permission) else False for |
| 110 | + permission in |
| 111 | + [ResourcePermissionGroup.VIEW.value, ResourcePermissionGroup.MANAGE.value, |
| 112 | + ResourcePermissionRole.ROLE.value]}} |
| 113 | + for user_resource_permission in user_resource_permission_list], |
| 114 | + key=lambda item: item.get('auth_target_type')) |
| 115 | + |
| 116 | + def edit(self, instance, user, with_valid=True): |
| 117 | + if with_valid: |
| 118 | + self.is_valid(raise_exception=True) |
| 119 | + UpdateUserResourcePermissionRequest(data=instance).is_valid(raise_exception=True, |
| 120 | + workspace_id=self.data.get('workspace_id')) |
| 121 | + workspace_id = self.data.get("workspace_id") |
| 122 | + update_list = [] |
| 123 | + save_list = [] |
| 124 | + user_resource_permission_list = instance.get('user_resource_permission_list') |
| 125 | + workspace_user_resource_permission_exist_list = QuerySet(WorkspaceUserResourcePermission).filter( |
| 126 | + workspace_id=workspace_id) |
| 127 | + for user_resource_permission in user_resource_permission_list: |
| 128 | + exist_list = [user_resource_permission_exist for user_resource_permission_exist in |
| 129 | + workspace_user_resource_permission_exist_list if |
| 130 | + user_resource_permission.get('target_id') == str(user_resource_permission_exist.target)] |
| 131 | + if len(exist_list) > 0: |
| 132 | + exist_list[0].permission_list = [key for key in user_resource_permission.get('permission').keys() if |
| 133 | + user_resource_permission.get('permission').get(key)] |
| 134 | + update_list.append(exist_list[0]) |
| 135 | + else: |
| 136 | + save_list.append(WorkspaceUserResourcePermission(target=user_resource_permission.get('target_id'), |
| 137 | + auth_target_type=user_resource_permission.get( |
| 138 | + 'auth_target_type'), |
| 139 | + permission_list=[key for key in |
| 140 | + user_resource_permission.get( |
| 141 | + 'permission').keys() if |
| 142 | + user_resource_permission.get( |
| 143 | + 'permission').get(key)], |
| 144 | + workspace_id=workspace_id, |
| 145 | + user_id=user.id, |
| 146 | + auth_type=user_resource_permission.get('auth_type'))) |
| 147 | + # 批量更新 |
| 148 | + QuerySet(WorkspaceUserResourcePermission).bulk_update(update_list, ['permission_list']) if len( |
| 149 | + update_list) > 0 else None |
| 150 | + # 批量插入 |
| 151 | + QuerySet(WorkspaceUserResourcePermission).bulk_create(save_list) if len(save_list) > 0 else None |
| 152 | + version = Cache_Version.PERMISSION_LIST.get_version() |
| 153 | + key = Cache_Version.PERMISSION_LIST.get_key(user_id=str(user.id)) |
| 154 | + cache.delete(key, version=version) |
| 155 | + return True |
0 commit comments