|
|
@ -4,11 +4,13 @@ const { |
|
|
PermissionTypes, |
|
|
PermissionTypes, |
|
|
higherPermission, |
|
|
higherPermission, |
|
|
getBuiltinPermissionByID, |
|
|
getBuiltinPermissionByID, |
|
|
|
|
|
isPermissionLevelHigherThanRead, |
|
|
} = require("../../utilities/security/permissions") |
|
|
} = require("../../utilities/security/permissions") |
|
|
const { |
|
|
const { |
|
|
isBuiltin, |
|
|
isBuiltin, |
|
|
getDBRoleID, |
|
|
getDBRoleID, |
|
|
getExternalRoleID, |
|
|
getExternalRoleID, |
|
|
|
|
|
lowerBuiltinRoleID, |
|
|
BUILTIN_ROLES, |
|
|
BUILTIN_ROLES, |
|
|
} = require("../../utilities/security/roles") |
|
|
} = require("../../utilities/security/roles") |
|
|
const { getRoleParams, DocumentTypes } = require("../../db/utils") |
|
|
const { getRoleParams, DocumentTypes } = require("../../db/utils") |
|
|
@ -20,33 +22,31 @@ const PermissionUpdateType = { |
|
|
ADD: "add", |
|
|
ADD: "add", |
|
|
} |
|
|
} |
|
|
|
|
|
|
|
|
function getBasePermissions(resourceId) { |
|
|
const SUPPORTED_LEVELS = [PermissionLevels.WRITE, PermissionLevels.READ] |
|
|
|
|
|
|
|
|
|
|
|
function getPermissionType(resourceId) { |
|
|
const docType = DocumentTypes.filter(docType => |
|
|
const docType = DocumentTypes.filter(docType => |
|
|
resourceId.startsWith(docType) |
|
|
resourceId.startsWith(docType) |
|
|
)[0] |
|
|
)[0] |
|
|
const levelsToFind = [PermissionLevels.WRITE, PermissionLevels.READ] |
|
|
|
|
|
let type |
|
|
|
|
|
switch (docType) { |
|
|
switch (docType) { |
|
|
case DocumentTypes.TABLE: |
|
|
case DocumentTypes.TABLE: |
|
|
case DocumentTypes.ROW: |
|
|
case DocumentTypes.ROW: |
|
|
type = PermissionTypes.TABLE |
|
|
return PermissionTypes.TABLE |
|
|
break |
|
|
|
|
|
case DocumentTypes.AUTOMATION: |
|
|
case DocumentTypes.AUTOMATION: |
|
|
type = PermissionTypes.AUTOMATION |
|
|
return PermissionTypes.AUTOMATION |
|
|
break |
|
|
|
|
|
case DocumentTypes.WEBHOOK: |
|
|
case DocumentTypes.WEBHOOK: |
|
|
type = PermissionTypes.WEBHOOK |
|
|
return PermissionTypes.WEBHOOK |
|
|
break |
|
|
|
|
|
case DocumentTypes.QUERY: |
|
|
case DocumentTypes.QUERY: |
|
|
case DocumentTypes.DATASOURCE: |
|
|
case DocumentTypes.DATASOURCE: |
|
|
type = PermissionTypes.QUERY |
|
|
return PermissionTypes.QUERY |
|
|
break |
|
|
|
|
|
default: |
|
|
default: |
|
|
// views don't have an ID, will end up here
|
|
|
// views don't have an ID, will end up here
|
|
|
type = PermissionTypes.VIEW |
|
|
return PermissionTypes.VIEW |
|
|
break |
|
|
|
|
|
} |
|
|
} |
|
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
|
|
async function getBasePermissions(resourceId) { |
|
|
|
|
|
const type = getPermissionType(resourceId) |
|
|
const permissions = {} |
|
|
const permissions = {} |
|
|
for (let [roleId, role] of Object.entries(BUILTIN_ROLES)) { |
|
|
for (let [roleId, role] of Object.entries(BUILTIN_ROLES)) { |
|
|
if (!role.permissionId) { |
|
|
if (!role.permissionId) { |
|
|
@ -55,10 +55,17 @@ function getBasePermissions(resourceId) { |
|
|
const perms = getBuiltinPermissionByID(role.permissionId) |
|
|
const perms = getBuiltinPermissionByID(role.permissionId) |
|
|
const typedPermission = perms.permissions.find(perm => perm.type === type) |
|
|
const typedPermission = perms.permissions.find(perm => perm.type === type) |
|
|
if (typedPermission) { |
|
|
if (typedPermission) { |
|
|
// TODO: need to get the lowest role
|
|
|
const level = typedPermission.level |
|
|
// TODO: store the read/write with the lowest role
|
|
|
permissions[level] = lowerBuiltinRoleID(permissions[level], roleId) |
|
|
|
|
|
if (isPermissionLevelHigherThanRead(level)) { |
|
|
|
|
|
permissions[PermissionLevels.READ] = lowerBuiltinRoleID( |
|
|
|
|
|
permissions[PermissionLevels.READ], |
|
|
|
|
|
roleId |
|
|
|
|
|
) |
|
|
|
|
|
} |
|
|
} |
|
|
} |
|
|
} |
|
|
} |
|
|
|
|
|
return permissions |
|
|
} |
|
|
} |
|
|
|
|
|
|
|
|
// utility function to stop this repetition - permissions always stored under roles
|
|
|
// utility function to stop this repetition - permissions always stored under roles
|
|
|
@ -132,7 +139,7 @@ exports.fetchBuiltin = function(ctx) { |
|
|
|
|
|
|
|
|
exports.fetchLevels = function(ctx) { |
|
|
exports.fetchLevels = function(ctx) { |
|
|
// for now only provide the read/write perms externally
|
|
|
// for now only provide the read/write perms externally
|
|
|
ctx.body = [PermissionLevels.WRITE, PermissionLevels.READ] |
|
|
ctx.body = SUPPORTED_LEVELS |
|
|
} |
|
|
} |
|
|
|
|
|
|
|
|
exports.fetch = async function(ctx) { |
|
|
exports.fetch = async function(ctx) { |
|
|
@ -167,11 +174,12 @@ exports.getResourcePerms = async function(ctx) { |
|
|
) |
|
|
) |
|
|
const roles = body.rows.map(row => row.doc) |
|
|
const roles = body.rows.map(row => row.doc) |
|
|
const resourcePerms = {} |
|
|
const resourcePerms = {} |
|
|
for (let role of roles) { |
|
|
for (let level of SUPPORTED_LEVELS) { |
|
|
|
|
|
for (let role of roles) |
|
|
// update the various roleIds in the resource permissions
|
|
|
// update the various roleIds in the resource permissions
|
|
|
if (role.permissions && role.permissions[resourceId]) { |
|
|
if (role.permissions && role.permissions[resourceId]) { |
|
|
const roleId = getExternalRoleID(role._id) |
|
|
const roleId = getExternalRoleID(role._id) |
|
|
resourcePerms[roleId] = higherPermission( |
|
|
resourcePerms[level] = higherPermission( |
|
|
resourcePerms[roleId], |
|
|
resourcePerms[roleId], |
|
|
role.permissions[resourceId] |
|
|
role.permissions[resourceId] |
|
|
) |
|
|
) |
|
|
|