forked from enviPath/enviPy
Machine users
This commit is contained in:
+15
-2
@@ -18,7 +18,13 @@ Package = s.GET_PACKAGE_MODEL()
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
def has_secret_group(user):
|
||||
def has_pes_allowance(user):
|
||||
if user.principal_type == user.PrincipalType.APP:
|
||||
return user.app_details.pes_allowance != user.app_details.PESAllowance.NONE
|
||||
|
||||
return True
|
||||
|
||||
def has_secret_pes_allowance(user):
|
||||
"""
|
||||
Determines if the specified user belongs to any secret group.
|
||||
|
||||
@@ -32,6 +38,9 @@ def has_secret_group(user):
|
||||
bool: True if the user belongs to at least one secret group,
|
||||
False otherwise.
|
||||
"""
|
||||
if user.principal_type == user.PrincipalType.APP:
|
||||
return user.app_details.pes_allowance == user.app_details.PESAllowance.SECRET
|
||||
|
||||
return Group.objects.filter(secret=True, user_member=user).exists()
|
||||
|
||||
|
||||
@@ -196,6 +205,10 @@ def get_application_token(prod: bool) -> str:
|
||||
|
||||
def fetch_pes(request, pes_url, user) -> dict:
|
||||
|
||||
if not has_pes_allowance(user):
|
||||
logger.info(f"User {user.username} does not have permission to fetch PESs")
|
||||
raise ValueError(f"User {user.username} does not have permission to fetch PESs")
|
||||
|
||||
for k, v in s.PES_API_MAPPING.items():
|
||||
if pes_url.startswith(k):
|
||||
|
||||
@@ -215,7 +228,7 @@ def fetch_pes(request, pes_url, user) -> dict:
|
||||
}
|
||||
|
||||
# Restrict request if user is not part of any secret group
|
||||
if not has_secret_group(user):
|
||||
if not has_secret_pes_allowance(user):
|
||||
headers["app-classification-level-restriction"] = "restrict-pes-secret-structure-access"
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user