|
6 | 6 | @date:2025/4/28 17:17 |
7 | 7 | @desc: |
8 | 8 | """ |
| 9 | +import json |
| 10 | +import os |
| 11 | + |
9 | 12 | from django.db.models import QuerySet |
10 | | -from rest_framework import serializers |
11 | 13 | from django.utils.translation import gettext_lazy as _ |
| 14 | +from rest_framework import serializers |
| 15 | + |
| 16 | +from common.constants.permission_constants import get_default_workspace_user_role_mapping_list, RoleConstants, \ |
| 17 | + ResourcePermissionGroup, ResourcePermissionRole, ResourceAuthType |
| 18 | +from common.database_model_manage.database_model_manage import DatabaseModelManage |
| 19 | +from common.db.search import native_search |
| 20 | +from common.db.sql_execute import select_list |
| 21 | +from common.exception.app_exception import AppApiException |
| 22 | +from common.utils.common import get_file_content |
| 23 | +from common.utils.split_model import group_by |
| 24 | +from knowledge.models import Knowledge |
| 25 | +from maxkb.conf import PROJECT_DIR |
| 26 | +from system_manage.models import WorkspaceUserResourcePermission, AuthTargetType |
| 27 | + |
| 28 | + |
| 29 | +class PermissionSerializer(serializers.Serializer): |
| 30 | + VIEW = serializers.BooleanField(required=True, label="可读") |
| 31 | + MANAGE = serializers.BooleanField(required=True, label="管理") |
| 32 | + ROLE = serializers.BooleanField(required=True, label="跟随角色") |
| 33 | + |
| 34 | + |
| 35 | +class UserResourcePermissionItemResponse(serializers.Serializer): |
| 36 | + id = serializers.UUIDField(required=True, label="主键id") |
| 37 | + name = serializers.CharField(required=True, label="资源名称") |
| 38 | + auth_target_type = serializers.ChoiceField(required=True, choices=AuthTargetType.choices, label="授权资源") |
| 39 | + user_id = serializers.UUIDField(required=True, label="用户id") |
| 40 | + auth_type = serializers.ChoiceField(required=True, choices=ResourceAuthType.choices, label="授权类型") |
| 41 | + permission = PermissionSerializer() |
| 42 | + |
12 | 43 |
|
13 | | -from system_manage.models import WorkspaceUserResourcePermission |
| 44 | +class UserResourcePermissionResponse(serializers.Serializer): |
| 45 | + KNOWLEDGE = UserResourcePermissionItemResponse(many=True) |
14 | 46 |
|
15 | 47 |
|
16 | | -class UserResourcePermissionResponse(serializers.ModelSerializer): |
17 | | - class Meta: |
18 | | - model = WorkspaceUserResourcePermission |
19 | | - fields = [ |
20 | | - 'id', 'workspace_id', 'user_id', 'auth_target_type', 'target', |
21 | | - 'auth_type', 'permission_list', 'create_time', 'update_time' |
22 | | - ] |
| 48 | +class UpdateTeamMemberItemPermissionSerializer(serializers.Serializer): |
| 49 | + auth_target_type = serializers.ChoiceField(required=True, choices=AuthTargetType.choices, label="授权资源") |
| 50 | + target_id = serializers.CharField(required=True, label=_('target id')) |
| 51 | + auth_type = serializers.ChoiceField(required=True, choices=ResourceAuthType.choices, label="授权类型") |
| 52 | + permission = PermissionSerializer(required=True, many=False) |
| 53 | + |
| 54 | + |
| 55 | +class UpdateUserResourcePermissionRequest(serializers.Serializer): |
| 56 | + user_resource_permission_list = UpdateTeamMemberItemPermissionSerializer(required=True, many=True) |
| 57 | + |
| 58 | + def is_valid(self, *, workspace_id=None, raise_exception=False): |
| 59 | + super().is_valid(raise_exception=True) |
| 60 | + user_resource_permission_list = self.data.get("user_resource_permission_list") |
| 61 | + illegal_target_id_list = select_list( |
| 62 | + get_file_content( |
| 63 | + os.path.join(PROJECT_DIR, "apps", "system_manage", 'sql', 'check_member_permission_target_exists.sql')), |
| 64 | + [json.dumps(user_resource_permission_list), workspace_id]) |
| 65 | + if illegal_target_id_list is not None and len(illegal_target_id_list) > 0: |
| 66 | + raise AppApiException(500, |
| 67 | + _('Non-existent application|knowledge base id[') + str(illegal_target_id_list) + ']') |
23 | 68 |
|
24 | 69 |
|
25 | 70 | class UserResourcePermissionSerializer(serializers.Serializer): |
26 | 71 | workspace_id = serializers.CharField(required=True, label=_('workspace id')) |
27 | 72 |
|
28 | | - def list(self, with_valid=True): |
| 73 | + def get_queryset(self): |
| 74 | + return { |
| 75 | + "knowledge_query_set": QuerySet(Knowledge) |
| 76 | + .filter(workspace_id=self.data.get('workspace_id')), |
| 77 | + 'workspace_user_resource_permission_query_set': QuerySet(WorkspaceUserResourcePermission).filter( |
| 78 | + workspace_id=self.data.get('workspace_id')) |
| 79 | + } |
| 80 | + |
| 81 | + def list(self, user, with_valid=True): |
| 82 | + if with_valid: |
| 83 | + self.is_valid(raise_exception=True) |
| 84 | + workspace_id = self.data.get("workspace_id") |
| 85 | + # 用户权限列表 |
| 86 | + user_resource_permission_list = native_search(self.get_queryset(), get_file_content( |
| 87 | + os.path.join(PROJECT_DIR, "apps", "system_manage", 'sql', 'get_user_resource_permission.sql'))) |
| 88 | + workspace_user_role_mapping_model = DatabaseModelManage.get_model("workspace_user_role_mapping") |
| 89 | + workspace_model = DatabaseModelManage.get_model("workspace_model") |
| 90 | + if workspace_user_role_mapping_model and workspace_model: |
| 91 | + workspace_user_role_mapping_list = QuerySet(workspace_user_role_mapping_model).filter(user_id=user.id, |
| 92 | + workspace_id=workspace_id) |
| 93 | + else: |
| 94 | + workspace_user_role_mapping_list = get_default_workspace_user_role_mapping_list([user.role]) |
| 95 | + is_workspace_manage = any( |
| 96 | + [workspace_user_role_mapping for workspace_user_role_mapping in workspace_user_role_mapping_list if |
| 97 | + workspace_user_role_mapping.role_id == RoleConstants.WORKSPACE_MANAGE.value]) |
| 98 | + # 如果当前用户是当前工作空间管理员那么就拥有所有权限 |
| 99 | + if is_workspace_manage: |
| 100 | + user_resource_permission_list = list( |
| 101 | + map(lambda row: {**row, |
| 102 | + 'permission': {ResourcePermissionGroup.VIEW.value: True, |
| 103 | + ResourcePermissionGroup.MANAGE.value: True, |
| 104 | + ResourcePermissionRole.ROLE.value: True}}, |
| 105 | + user_resource_permission_list)) |
| 106 | + return group_by([{**user_resource_permission, 'permission': { |
| 107 | + permission: True if user_resource_permission.get('permission_list').__contains__(permission) else False for |
| 108 | + permission in |
| 109 | + [ResourcePermissionGroup.VIEW.value, ResourcePermissionGroup.MANAGE.value, |
| 110 | + ResourcePermissionRole.ROLE.value]}} |
| 111 | + for user_resource_permission in user_resource_permission_list], |
| 112 | + key=lambda item: item.get('auth_target_type')) |
| 113 | + |
| 114 | + def edit(self, instance, user, with_valid=True): |
29 | 115 | if with_valid: |
30 | 116 | self.is_valid(raise_exception=True) |
| 117 | + UpdateUserResourcePermissionRequest(data=instance).is_valid(raise_exception=True, |
| 118 | + workspace_id=self.data.get('workspace_id')) |
31 | 119 | workspace_id = self.data.get("workspace_id") |
32 | | - workspace_user_resource_permission_list = QuerySet(WorkspaceUserResourcePermission).filter( |
| 120 | + update_list = [] |
| 121 | + save_list = [] |
| 122 | + user_resource_permission_list = instance.get('user_resource_permission_list') |
| 123 | + workspace_user_resource_permission_exist_list = QuerySet(WorkspaceUserResourcePermission).filter( |
33 | 124 | workspace_id=workspace_id) |
34 | | - return [UserResourcePermissionResponse(data=user_resource_permission).data for user_resource_permission in |
35 | | - workspace_user_resource_permission_list] |
| 125 | + for user_resource_permission in user_resource_permission_list: |
| 126 | + exist_list = [user_resource_permission_exist for user_resource_permission_exist in |
| 127 | + workspace_user_resource_permission_exist_list if |
| 128 | + user_resource_permission.get('target_id') == str(user_resource_permission_exist.target)] |
| 129 | + if len(exist_list) > 0: |
| 130 | + exist_list[0].permission_list = [key for key in user_resource_permission.get('permission').keys() if |
| 131 | + user_resource_permission.get('permission').get(key)] |
| 132 | + update_list.append(exist_list[0]) |
| 133 | + else: |
| 134 | + save_list.append(WorkspaceUserResourcePermission(target=user_resource_permission.get('target_id'), |
| 135 | + auth_target_type=user_resource_permission.get( |
| 136 | + 'auth_target_type'), |
| 137 | + permission_list=[key for key in |
| 138 | + user_resource_permission.get( |
| 139 | + 'permission').keys() if |
| 140 | + user_resource_permission.get( |
| 141 | + 'permission').get(key)], |
| 142 | + workspace_id=workspace_id, |
| 143 | + user_id=user.id, |
| 144 | + auth_type=user_resource_permission.get('auth_type'))) |
| 145 | + # 批量更新 |
| 146 | + QuerySet(WorkspaceUserResourcePermission).bulk_update(update_list, ['permission_list']) if len( |
| 147 | + update_list) > 0 else None |
| 148 | + # 批量插入 |
| 149 | + QuerySet(WorkspaceUserResourcePermission).bulk_create(save_list) if len(save_list) > 0 else None |
| 150 | + return True |
0 commit comments