Machine users

This commit is contained in:
Tim Lorsbach
2026-10-07 14:59:57 +02:00
parent 8dc0e5e7a3
commit d63c40e041
6 changed files with 153 additions and 10 deletions
+15 -2
View File
@@ -18,7 +18,13 @@ Package = s.GET_PACKAGE_MODEL()
logger = logging.getLogger(__name__)
def has_secret_group(user):
def has_pes_allowance(user):
if user.principal_type == user.PrincipalType.APP:
return user.app_details.pes_allowance != user.app_details.PESAllowance.NONE
return True
def has_secret_pes_allowance(user):
"""
Determines if the specified user belongs to any secret group.
@@ -32,6 +38,9 @@ def has_secret_group(user):
bool: True if the user belongs to at least one secret group,
False otherwise.
"""
if user.principal_type == user.PrincipalType.APP:
return user.app_details.pes_allowance == user.app_details.PESAllowance.SECRET
return Group.objects.filter(secret=True, user_member=user).exists()
@@ -196,6 +205,10 @@ def get_application_token(prod: bool) -> str:
def fetch_pes(request, pes_url, user) -> dict:
if not has_pes_allowance(user):
logger.info(f"User {user.username} does not have permission to fetch PESs")
raise ValueError(f"User {user.username} does not have permission to fetch PESs")
for k, v in s.PES_API_MAPPING.items():
if pes_url.startswith(k):
@@ -215,7 +228,7 @@ def fetch_pes(request, pes_url, user) -> dict:
}
# Restrict request if user is not part of any secret group
if not has_secret_group(user):
if not has_secret_pes_allowance(user):
headers["app-classification-level-restriction"] = "restrict-pes-secret-structure-access"