-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathobjects.py
More file actions
84 lines (69 loc) · 2.66 KB
/
objects.py
File metadata and controls
84 lines (69 loc) · 2.66 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
class Type:
USER='users'
ROLE='roles'
SHADOW='shadows'
RESOURCE='resources'
class GenericObject:
def __init__(self, api, metadata):
self.metadata = metadata
self.api = api
class User(GenericObject):
def __init__(self, api, metadata):
GenericObject.__init__(self, api, metadata)
def modify(self, modification):
self.api.modify_user(self.metadata['oid'], modification)
def has_account(self, resource_name=None, resource_oid=None, resource_object=None):
pass
def has_indirect_account(self, resource_name=None, resource_oid=None, resource_object=None):
if not (resource_name or resource_oid or resource_object):
return False
if resource_name:
resource = self.api.search_resource({'search_operator':'and', 'search_filter':{'name':resourceName}})
elif resource_oid:
resource = Resource(self.api, {'oid':resource_oid})
elif resource_object:
resource = resource_object
if resource and 'linkRef' in self.metadata:
for shadowRef in self.metadata['linkRef']:
shadow = self.api.get_shadow(shadowRef['oid'])
for resourceRef in shadow.metadata['resourceRef']:
if resource.metadata['oid'] == resourceRef['oid']:
return True
return False
def assign_role(self, role_name=None, role_oid=None, role_object=None):
if not (role_name or role_oid or role_object):
return False
if role_name:
role = self.api.search_role({'search_operator':'and', 'search_filter':{'name':role_name}})
elif role_oid:
role = Role(self.api, {'oid':role_oid})
elif role_object:
role = role_object
if role:
self.modify({'modification_type': 'add','modification':{'assignment':'<targetRef oid="'+role.metadata['oid']+ '" type="RoleType"/>'}})
return True
return False
class Role(GenericObject):
def __init__(self, api, metadata):
GenericObject.__init__(self, api, metadata)
def modify(self, modification):
self.api.modify_role( self.metadata['oid'], modification)
def assign_role(self, role_name=None, role_oid=None, role_object=None):
if not (role_name or role_oid or role_object):
return False
if role_name:
role = self.api.search_role({'search_operator':'and', 'search_filter':{'name':role_name}})
elif role_oid:
role = Role(self.api, {'oid':role_oid})
elif role_object:
role = role_object
if role:
self.modify({'modification_type': 'add','modification':{'assignment':'<targetRef oid="'+role.metadata['oid']+ '" type="RoleType"/>'}})
return True
return False
class Shadow(GenericObject):
def __init__(self, api, metadata):
GenericObject.__init__(self, api, metadata)
class Resource(GenericObject):
def __init__(self, api, metadata):
GenericObject.__init__(self, api, metadata)