Commit ef41c63e authored by Alexandre Boeglin's avatar Alexandre Boeglin

Modified security/roles assignment:

base_category can now be used to order categories while building the group id.
this way we can assure that the groups will be consistent through all the
system (eg. no conflict between 'LIL_NXD' and 'NXD_LIL')

to have the id built on (site, group) when group is fetched from an assignment
and site is statically defined, just put this in the definition:

####
Base Category:
site group

Category:
site/lille
####

Not specifiying 'site' in 'Base Category' will simply append 'site' to base_category
when determining the order and will result in (group, site) instead.
This can cause a "conflict" : if somewhere else, you choose to fetch site and statically
define group, the order will be (site, group), and thus, the two group names won't match.


git-svn-id: https://svn.erp5.org/repos/public/erp5/trunk@3739 20353a03-c40f-0410-a6d1-a30d3c3de9de
parent f7c5dd9e
...@@ -210,27 +210,38 @@ class ERP5TypeInformation( FactoryTypeInformation, RoleProviderBase ): ...@@ -210,27 +210,38 @@ class ERP5TypeInformation( FactoryTypeInformation, RoleProviderBase ):
# For each role definition, we look for the base_category_script # For each role definition, we look for the base_category_script
# and try to use it to retrieve the values for the base_category list # and try to use it to retrieve the values for the base_category list
for definition in definition_list: for definition in definition_list:
# get the list of base_categories that are statically defined
category_base_list = [x.split('/')[0] for x in definition['category']]
# get the list of base_categories that are to be fetched through the script
actual_base_category_list = [x for x in definition['base_category'] if x not in category_base_list]
# get the aggregated list of base categories, to preserve the order
category_order_list = []
category_order_list.extend(definition['base_category'])
for bc in category_base_list:
if bc not in category_order_list:
category_order_list.append(bc)
# get the script and apply it if actual_base_category_list is not empty
base_category_script = getattr(object, definition['base_category_script'], None) base_category_script = getattr(object, definition['base_category_script'], None)
if base_category_script is not None: if len(actual_base_category_list) > 0:
# call the script, which should return either a dict or a list of dicts if base_category_script is not None:
category_result = base_category_script(definition['base_category'], user_name, object, object.getPortalType()) # call the script, which should return either a dict or a list of dicts
# we also need to store the user specified order of categories, as dict are not ordered category_result = base_category_script(actual_base_category_list, user_name, object, object.getPortalType())
category_order_list = [] if type(category_result) is type({}):
category_order_list.extend(definition['base_category']) category_result = [category_result]
else:
raise RuntimeError, 'No script was defined to fetch values for'\
' base categories : %s' % ', '.join(actual_base_category_list)
else:
category_result = [{}]
# add the result to role_category_list, aggregated with category_order and statically defined categories
for category_dict in category_result:
category_value_dict = {'category_order':category_order_list}
category_value_dict.update(category_dict)
for c in definition['category']: for c in definition['category']:
bc = c.split('/')[0] bc, value = c.split('/', 1)
if bc not in category_order_list: category_value_dict[bc] = value
category_order_list.append(bc) role_category_list[role].append(category_value_dict)
# add the result to role_category_list
if type(category_result) is type({}):
category_result = [category_result]
for category_dict in category_result:
category_value_dict = {'category_order':category_order_list}
category_value_dict.update(category_dict)
for c in definition['category']:
bc, value = c.split('/', 1)
category_value_dict[bc] = value
role_category_list[role].append(category_value_dict)
# Generate security group ids from category_value_dicts # Generate security group ids from category_value_dicts
role_group_id_dict = {} role_group_id_dict = {}
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment