+ # Always reads operation to resource mapping from file (this is static, no need to store it in MongoDB)
+ # Operations encoding: "<METHOD> <URL>"
+ # Note: it is faster to rewrite the value than to check if it is already there or not
+ if self.config["authentication"]["backend"] == "internal":
+ return
+
+ operations = []
+ with open(self.resources_to_operations_file, "r") as stream:
+ resources_to_operations_yaml = yaml.load(stream)
+
+ for resource, operation in resources_to_operations_yaml["resources_to_operations"].items():
+ operation_key = operation.replace(".", ":")
+ if operation_key not in operations:
+ operations.append(operation_key)
+ self.resources_to_operations_mapping[resource] = operation_key
+
+ records = self.db.get_list("roles_operations")
+
+ # Loading permissions to MongoDB. If there are permissions already in MongoDB, do nothing.
+ if len(records) == 0:
+ with open(self.roles_to_operations_file, "r") as stream:
+ roles_to_operations_yaml = yaml.load(stream)
+
+ roles = []
+ for role_with_operations in roles_to_operations_yaml["roles_to_operations"]:
+ # Verifying if role already exists. If it does, send warning to log and ignore it.
+ if role_with_operations["role"] not in roles:
+ roles.append(role_with_operations["role"])
+ else:
+ self.logger.warning("Duplicated role with name: {0}. Role definition is ignored."
+ .format(role_with_operations["role"]))
+ continue
+
+ role_ops = {}
+ root = None
+
+ if not role_with_operations["operations"]:
+ continue
+
+ for operation, is_allowed in role_with_operations["operations"].items():
+ if not isinstance(is_allowed, bool):
+ continue
+
+ if operation == ".":
+ root = is_allowed
+ continue
+
+ if len(operation) != 1 and operation[-1] == ".":
+ self.logger.warning("Invalid operation {0} terminated in '.'. "
+ "Operation will be discarded"
+ .format(operation))
+ continue
+
+ operation_key = operation.replace(".", ":")
+ if operation_key not in role_ops.keys():
+ role_ops[operation_key] = is_allowed
+ else:
+ self.logger.info("In role {0}, the operation {1} with the value {2} was discarded due to "
+ "repetition.".format(role_with_operations["role"], operation, is_allowed))
+
+ if not root:
+ root = False
+ self.logger.info("Root for role {0} not defined. Default value 'False' applied."
+ .format(role_with_operations["role"]))
+
+ now = time()
+ operation_to_roles_item = {
+ "_admin": {
+ "created": now,
+ "modified": now,
+ },
+ "name": role_with_operations["role"],
+ "root": root
+ }
+
+ for operation, value in role_ops.items():
+ operation_to_roles_item[operation] = value
+
+ if self.config["authentication"]["backend"] != "internal" and \
+ role_with_operations["role"] != "anonymous":
+ keystone_id = self.backend.create_role(role_with_operations["role"])
+ operation_to_roles_item["_id"] = keystone_id["_id"]
+
+ self.db.create("roles_operations", operation_to_roles_item)
+
+ permissions = {oper: [] for oper in operations}
+ records = self.db.get_list("roles_operations")
+
+ ignore_fields = ["_id", "_admin", "name", "root"]
+ for record in records:
+ record_permissions = {oper: record["root"] for oper in operations}
+ operations_joined = [(oper, value) for oper, value in record.items() if oper not in ignore_fields]
+ operations_joined.sort(key=lambda x: x[0].count(":"))
+
+ for oper in operations_joined:
+ match = list(filter(lambda x: x.find(oper[0]) == 0, record_permissions.keys()))
+
+ for m in match:
+ record_permissions[m] = oper[1]
+
+ allowed_operations = [k for k, v in record_permissions.items() if v is True]
+
+ for allowed_op in allowed_operations:
+ permissions[allowed_op].append(record["name"])
+
+ for oper, role_list in permissions.items():
+ self.operation_to_allowed_roles[oper] = role_list
+
+ if self.config["authentication"]["backend"] != "internal":
+ self.backend.assign_role_to_user("admin", "admin", "system_admin")