Fix Bug 924: User is not allowed to upload NS Descriptors for project_user(role)
[osm/NBI.git] / osm_nbi / validation.py
index b8953b5..69caff7 100644 (file)
@@ -1,7 +1,22 @@
 # -*- coding: utf-8 -*-
 
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+#    http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
+# implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
 from jsonschema import validate as js_v, exceptions as js_e
 from http import HTTPStatus
+from copy import deepcopy
+from uuid import UUID   # To test for valid UUID
 
 __author__ = "Alfonso Tierno <alfonso.tiernosepulveda@telefonica.com>"
 __version__ = "0.1"
@@ -13,7 +28,7 @@ Validator of input data using JSON schemas for those items that not contains an
 
 # Basis schemas
 patern_name = "^[ -~]+$"
-nameshort_schema = {"type": "string", "minLength": 1, "maxLength": 60, "pattern": "^[^,;()\\.\\$'\"]+$"}
+shortname_schema = {"type": "string", "minLength": 1, "maxLength": 60, "pattern": "^[^,;()\\.\\$'\"]+$"}
 passwd_schema = {"type": "string", "minLength": 1, "maxLength": 60}
 name_schema = {"type": "string", "minLength": 1, "maxLength": 255, "pattern": "^[^,;()'\"]+$"}
 string_schema = {"type": "string", "minLength": 1, "maxLength": 255}
@@ -55,7 +70,7 @@ size_schema = {"type": "integer", "minimum": 1, "maximum": 100}
 array_edition_schema = {
     "type": "object",
     "patternProperties": {
-        "^\\$": "Any"
+        "^\\$": {}
     },
     "additionalProperties": False,
     "minProperties": 1,
@@ -63,7 +78,7 @@ array_edition_schema = {
 nameshort_list_schema = {
     "type": "array",
     "minItems": 1,
-    "items": nameshort_schema,
+    "items": shortname_schema,
 }
 
 
@@ -157,6 +172,17 @@ ip_profile_update_schema = {
     "additionalProperties": False
 }
 
+provider_network_schema = {
+    "title": "provider network validation schame",
+    "$schema": "http://json-schema.org/draft-04/schema#",
+    "type": "object",
+    "properties": {
+        "physical-network": name_schema,
+        "segmentation-id": name_schema,
+    },
+    "additionalProperties": False
+}
+
 ns_instantiate_internal_vld = {
     "title": "ns action instantiate input schema for vdu",
     "$schema": "http://json-schema.org/draft-04/schema#",
@@ -164,7 +190,9 @@ ns_instantiate_internal_vld = {
     "properties": {
         "name": name_schema,
         "vim-network-name": name_schema,
+        "vim-network-id": name_schema,
         "ip-profile": ip_profile_update_schema,
+        "provider-network": provider_network_schema,
         "internal-connection-point": {
             "type": "array",
             "minItems": 1,
@@ -186,6 +214,44 @@ ns_instantiate_internal_vld = {
     "additionalProperties": False
 }
 
+additional_params_for_vnf = {
+    "type": "array",
+    "items": {
+        "type": "object",
+        "properties": {
+            "member-vnf-index": name_schema,
+            "additionalParams": object_schema,
+            "additionalParamsForVdu": {
+                "type": "array",
+                "items": {
+                    "type": "object",
+                    "properties": {
+                        "vdu_id": name_schema,
+                        "additionalParams": object_schema,
+                    },
+                    "required": ["vdu_id", "additionalParams"],
+                    "additionalProperties": False,
+                },
+            },
+            "additionalParamsForKdu": {
+                "type": "array",
+                "items": {
+                    "type": "object",
+                    "properties": {
+                        "kdu_name": name_schema,
+                        "additionalParams": object_schema,
+                    },
+                    "required": ["kdu_name", "additionalParams"],
+                    "additionalProperties": False,
+                },
+            },
+        },
+        "required": ["member-vnf-index"],
+        "minProperties": 2,
+        "additionalProperties": False
+    }
+}
+
 ns_instantiate = {
     "title": "ns action instantiate input schema",
     "$schema": "http://json-schema.org/draft-04/schema#",
@@ -195,9 +261,12 @@ ns_instantiate = {
         "nsInstanceId": id_schema,
         "netsliceInstanceId": id_schema,
         "nsName": name_schema,
-        "nsDescription": {"oneOf": [description_schema, {"type": "null"}]},
+        "nsDescription": {"oneOf": [description_schema, null_schema]},
         "nsdId": id_schema,
         "vimAccountId": id_schema,
+        "wimAccountId": {"OneOf": [id_schema, bool_schema, null_schema]},
+        "additionalParamsForNs": object_schema,
+        "additionalParamsForVnf": additional_params_for_vnf,
         "ssh_keys": {"type": "array", "items": {"type": "string"}},
         "nsr_id": id_schema,
         "vduImage": name_schema,
@@ -233,7 +302,11 @@ ns_instantiate = {
                 "properties": {
                     "name": string_schema,
                     "vim-network-name": {"OneOf": [string_schema, object_schema]},
+                    "vim-network-id": {"OneOf": [string_schema, object_schema]},
+                    "ns-net": object_schema,
+                    "wimAccountId": {"OneOf": [id_schema, bool_schema, null_schema]},
                     "ip-profile": object_schema,
+                    "provider-network": provider_network_schema,
                     "vnfd-connection-point-ref": {
                         "type": "array",
                         "minItems": 1,
@@ -270,6 +343,8 @@ ns_action = {   # TODO for the moment it is only contemplated the vnfd primitive
         "member_vnf_index": name_schema,
         "vnf_member_index": name_schema,  # TODO for backward compatibility. To remove in future
         "vdu_id": name_schema,
+        "vdu_count_index": integer0_schema,
+        "kdu_name": name_schema,
         "primitive": name_schema,
         "primitive_params": {"type": "object"},
     },
@@ -311,6 +386,9 @@ ns_scale = {   # TODO for the moment it is only VDU-scaling
 
 
 schema_version = {"type": "string", "enum": ["1.0"]}
+schema_type = {"type": "string"}
+vim_type = shortname_schema  # {"enum": ["openstack", "openvim", "vmware", "opennebula", "aws", "azure", "fos"]}
+
 vim_account_edit_schema = {
     "title": "vim_account edit input schema",
     "$schema": "http://json-schema.org/draft-04/schema#",
@@ -318,20 +396,19 @@ vim_account_edit_schema = {
     "properties": {
         "name": name_schema,
         "description": description_schema,
-        "type": nameshort_schema,  # currently "openvim" or "openstack", can be enlarged with plugins
         "vim": name_schema,
         "datacenter": name_schema,
+        "vim_type": vim_type,
         "vim_url": description_schema,
-        "vim_url_admin": description_schema,
-        "vim_tenant": name_schema,
+        "vim_url_admin": description_schema,
+        "vim_tenant": name_schema,
         "vim_tenant_name": name_schema,
-        "vim_username": nameshort_schema,
+        "vim_user": shortname_schema,
         "vim_password": passwd_schema,
         "config": {"type": "object"}
     },
     "additionalProperties": False
 }
-schema_type = {"type": "string"}
 
 vim_account_new_schema = {
     "title": "vim_account creation input schema",
@@ -344,12 +421,12 @@ vim_account_new_schema = {
         "description": description_schema,
         "vim": name_schema,
         "datacenter": name_schema,
-        "vim_type": {"enum": ["openstack", "openvim", "vmware", "opennebula", "aws"]},
+        "vim_type": vim_type,
         "vim_url": description_schema,
         # "vim_url_admin": description_schema,
         # "vim_tenant": name_schema,
         "vim_tenant_name": name_schema,
-        "vim_user": nameshort_schema,
+        "vim_user": shortname_schema,
         "vim_password": passwd_schema,
         "config": {"type": "object"}
     },
@@ -357,6 +434,49 @@ vim_account_new_schema = {
     "additionalProperties": False
 }
 
+wim_type = shortname_schema  # {"enum": ["tapi", "onos", "odl", "dynpac", "fake"]}
+
+wim_account_edit_schema = {
+    "title": "wim_account edit input schema",
+    "$schema": "http://json-schema.org/draft-04/schema#",
+    "type": "object",
+    "properties": {
+        "name": name_schema,
+        "description": description_schema,
+        "wim": name_schema,
+        "wim_type": wim_type,
+        "wim_url": description_schema,
+        "user": shortname_schema,
+        "password": passwd_schema,
+        "config": {"type": "object"}
+    },
+    "additionalProperties": False
+}
+
+wim_account_new_schema = {
+    "title": "wim_account creation input schema",
+    "$schema": "http://json-schema.org/draft-04/schema#",
+    "type": "object",
+    "properties": {
+        "schema_version": schema_version,
+        "schema_type": schema_type,
+        "name": name_schema,
+        "description": description_schema,
+        "wim": name_schema,
+        "wim_type": wim_type,
+        "wim_url": description_schema,
+        "user": shortname_schema,
+        "password": passwd_schema,
+        "config": {
+            "type": "object",
+            "patternProperties": {
+                ".": {"not": {"type": "null"}}
+            }
+        }
+    },
+    "required": ["name", "wim_url", "wim_type"],
+    "additionalProperties": False
+}
 
 sdn_properties = {
     "name": name_schema,
@@ -366,7 +486,7 @@ sdn_properties = {
     "port": port_schema,
     "type": {"type": "string", "enum": ["opendaylight", "floodlight", "onos"]},
     "version": {"type": "string", "minLength": 1, "maxLength": 12},
-    "user": nameshort_schema,
+    "user": shortname_schema,
     "password": passwd_schema
 }
 sdn_new_schema = {
@@ -392,14 +512,14 @@ sdn_port_mapping_schema = {
     "items": {
         "type": "object",
         "properties": {
-            "compute_node": nameshort_schema,
+            "compute_node": shortname_schema,
             "ports": {
                 "type": "array",
                 "items": {
                     "type": "object",
                     "properties": {
                         "pci": pci_extended_schema,
-                        "switch_port": nameshort_schema,
+                        "switch_port": shortname_schema,
                         "switch_mac": mac_schema
                     },
                     "required": ["pci"]
@@ -421,22 +541,91 @@ sdn_external_port_schema = {
     "required": ["port"]
 }
 
+# K8s Clusters
+k8scluster_nets_schema = {
+    "title": "k8scluster nets input schema",
+    "$schema": "http://json-schema.org/draft-04/schema#",
+    "type": "object",
+    "patternProperties": {".": {"oneOf": [description_schema, null_schema]}},
+    "minProperties": 1,
+    "additionalProperties": False
+}
+k8scluster_new_schema = {
+    "title": "k8scluster creation input schema",
+    "$schema": "http://json-schema.org/draft-04/schema#",
+    "type": "object",
+    "properties": {
+        "schema_version": schema_version,
+        "schema_type": schema_type,
+        "name": name_schema,
+        "description": description_schema,
+        "credentials": object_schema,
+        "vim_account": id_schema,
+        "k8s_version": string_schema,
+        "nets": k8scluster_nets_schema,
+        "namespace": name_schema,
+        "cni": nameshort_list_schema,
+    },
+    "required": ["name", "credentials", "vim_account", "k8s_version", "nets"],
+    "additionalProperties": False
+}
+k8scluster_edit_schema = {
+    "title": "vim_account edit input schema",
+    "$schema": "http://json-schema.org/draft-04/schema#",
+    "type": "object",
+    "properties": {
+        "name": name_schema,
+        "description": description_schema,
+        "credentials": object_schema,
+        "vim_account": id_schema,
+        "k8s_version": string_schema,
+        "nets": k8scluster_nets_schema,
+        "namespace": name_schema,
+        "cni": nameshort_list_schema,
+    },
+    "additionalProperties": False
+}
+
+# K8s Repos
+k8srepo_types = {"enum": ["helm-chart", "juju-bundle"]}
+k8srepo_properties = {
+    "name": name_schema,
+    "description": description_schema,
+    "type": k8srepo_types,
+    "url": description_schema,
+}
+k8srepo_new_schema = {
+    "title": "k8scluster creation input schema",
+    "$schema": "http://json-schema.org/draft-04/schema#",
+    "type": "object",
+    "properties": k8srepo_properties,
+    "required": ["name", "type", "url"],
+    "additionalProperties": False
+}
+k8srepo_edit_schema = {
+    "title": "vim_account edit input schema",
+    "$schema": "http://json-schema.org/draft-04/schema#",
+    "type": "object",
+    "properties": k8srepo_properties,
+    "additionalProperties": False
+}
+
 # PDUs
 pdu_interface = {
     "type": "object",
     "properties": {
-        "name": nameshort_schema,
+        "name": shortname_schema,
         "mgmt": bool_schema,
         "type": {"enum": ["overlay", 'underlay']},
         "ip-address": ip_schema,
         # TODO, add user, password, ssh-key
         "mac-address": mac_schema,
-        "vim-network-name": nameshort_schema,  # interface is connected to one vim network, or switch port
-        # TODO "vim-network-id": nameshort_schema,
+        "vim-network-name": shortname_schema,  # interface is connected to one vim network, or switch port
+        "vim-network-id": shortname_schema,
         # # provide this in case SDN assist must deal with this interface
         # "switch-dpid": dpid_Schema,
-        # "switch-port": nameshort_schema,
-        # "switch-mac": nameshort_schema,
+        # "switch-port": shortname_schema,
+        # "switch-mac": shortname_schema,
         # "switch-vlan": vlan_schema,
     },
     "required": ["name", "mgmt", "ip-address"],
@@ -447,8 +636,8 @@ pdu_new_schema = {
     "$schema": "http://json-schema.org/draft-04/schema#",
     "type": "object",
     "properties": {
-        "name": nameshort_schema,
-        "type": nameshort_schema,
+        "name": shortname_schema,
+        "type": shortname_schema,
         "description": description_schema,
         "shared": bool_schema,
         "vims": nameshort_list_schema,
@@ -468,13 +657,13 @@ pdu_edit_schema = {
     "$schema": "http://json-schema.org/draft-04/schema#",
     "type": "object",
     "properties": {
-        "name": nameshort_schema,
-        "type": nameshort_schema,
+        "name": shortname_schema,
+        "type": shortname_schema,
         "description": description_schema,
         "shared": bool_schema,
-        "vims": {"oneOff": [array_edition_schema, nameshort_list_schema]},
-        "vim_accounts": {"oneOff": [array_edition_schema, nameshort_list_schema]},
-        "interfaces": {"oneOff": [
+        "vims": {"oneOf": [array_edition_schema, nameshort_list_schema]},
+        "vim_accounts": {"oneOf": [array_edition_schema, nameshort_list_schema]},
+        "interfaces": {"oneOf": [
             array_edition_schema,
             {
                 "type": "array",
@@ -488,16 +677,47 @@ pdu_edit_schema = {
 }
 
 # USERS
+project_role_mappings = {
+    "title": "list pf projects/roles",
+    "$schema": "http://json-schema.org/draft-04/schema#",
+    "type": "array",
+    "items": {
+        "type": "object",
+        "properties": {
+            "project": shortname_schema,
+            "role": shortname_schema
+        },
+        "required": ["project", "role"],
+        "additionalProperties": False
+    },
+    "minItems": 1
+}
+project_role_mappings_optional = {
+    "title": "list of projects/roles or projects only",
+    "$schema": "http://json-schema.org/draft-04/schema#",
+    "type": "array",
+    "items": {
+        "type": "object",
+        "properties": {
+            "project": shortname_schema,
+            "role": shortname_schema
+        },
+        "required": ["project"],
+        "additionalProperties": False
+    },
+    "minItems": 1
+}
 user_new_schema = {
     "$schema": "http://json-schema.org/draft-04/schema#",
     "title": "New user schema",
     "type": "object",
     "properties": {
-        "username": nameshort_schema,
+        "username": shortname_schema,
         "password": passwd_schema,
         "projects": nameshort_list_schema,
+        "project_role_mappings": project_role_mappings,
     },
-    "required": ["username", "password", "projects"],
+    "required": ["username", "password"],
     "additionalProperties": False
 }
 user_edit_schema = {
@@ -506,25 +726,36 @@ user_edit_schema = {
     "type": "object",
     "properties": {
         "password": passwd_schema,
+        "username": shortname_schema,     # To allow User Name modification
         "projects": {
-            "oneOff": [
+            "oneOf": [
                 nameshort_list_schema,
                 array_edition_schema
             ]
         },
+        "project_role_mappings": project_role_mappings,
+        "add_project_role_mappings": project_role_mappings,
+        "remove_project_role_mappings": project_role_mappings_optional,
     },
     "minProperties": 1,
     "additionalProperties": False
 }
 
 # PROJECTS
+topics_with_quota = ["vnfds", "nsds", "nsts", "pdus", "nsrs", "nsis", "vim_accounts", "wim_accounts", "sdns",
+                     "k8sclusters", "k8srepos"]
 project_new_schema = {
     "$schema": "http://json-schema.org/draft-04/schema#",
     "title": "New project schema for administrators",
     "type": "object",
     "properties": {
-        "name": nameshort_schema,
+        "name": shortname_schema,
         "admin": bool_schema,
+        "quotas": {
+            "type": "object",
+            "properties": {topic: integer0_schema for topic in topics_with_quota},
+            "additionalProperties": False
+        },
     },
     "required": ["name"],
     "additionalProperties": False
@@ -535,6 +766,50 @@ project_edit_schema = {
     "type": "object",
     "properties": {
         "admin": bool_schema,
+        "name": shortname_schema,     # To allow Project Name modification
+        "quotas": {
+            "type": "object",
+            "properties": {topic: {"oneOf": [integer0_schema, null_schema]} for topic in topics_with_quota},
+            "additionalProperties": False
+        },
+    },
+    "additionalProperties": False,
+    "minProperties": 1
+}
+
+# ROLES
+roles_new_schema = {
+    "$schema": "http://json-schema.org/draft-04/schema#",
+    "title": "New role schema for administrators",
+    "type": "object",
+    "properties": {
+        "name": shortname_schema,
+        "permissions": {
+            "type": "object",
+            "patternProperties": {
+                ".": bool_schema,
+            },
+            # "minProperties": 1,
+        }
+    },
+    "required": ["name"],
+    "additionalProperties": False
+}
+roles_edit_schema = {
+    "$schema": "http://json-schema.org/draft-04/schema#",
+    "title": "Roles edit schema for administrators",
+    "type": "object",
+    "properties": {
+        "name": shortname_schema,
+        "permissions": {
+            "type": "object",
+            "patternProperties": {
+                ".": {
+                    "oneOf": [bool_schema, null_schema]
+                }
+            },
+            # "minProperties": 1,
+        }
     },
     "additionalProperties": False,
     "minProperties": 1
@@ -562,26 +837,51 @@ nbi_edit_input_schemas = {
 }
 
 # NETSLICE SCHEMAS
+nsi_subnet_instantiate = deepcopy(ns_instantiate)
+nsi_subnet_instantiate["title"] = "netslice subnet instantiation params input schema"
+nsi_subnet_instantiate["properties"]["id"] = name_schema
+del nsi_subnet_instantiate["required"]
+
+nsi_vld_instantiate = {
+    "title": "netslice vld instantiation params input schema",
+    "$schema": "http://json-schema.org/draft-04/schema#",
+    "type": "object",
+    "properties": {
+        "name": string_schema,
+        "vim-network-name": {"OneOf": [string_schema, object_schema]},
+        "vim-network-id": {"OneOf": [string_schema, object_schema]},
+        "ip-profile": object_schema,
+    },
+    "required": ["name"],
+    "additionalProperties": False
+}
+
 nsi_instantiate = {
     "title": "netslice action instantiate input schema",
     "$schema": "http://json-schema.org/draft-04/schema#",
     "type": "object",
     "properties": {
         "lcmOperationType": string_schema,
-        "nsiInstanceId": id_schema,
+        "netsliceInstanceId": id_schema,
         "nsiName": name_schema,
-        "nsiDescription": {"oneOf": [description_schema, {"type": "null"}]},
-        "nstdId": string_schema,
+        "nsiDescription": {"oneOf": [description_schema, null_schema]},
+        "nstId": string_schema,
         "vimAccountId": id_schema,
         "ssh_keys": {"type": "string"},
         "nsi_id": id_schema,
-        "ns": {
+        "additionalParamsForNsi": object_schema,
+        "netslice-subnet": {
             "type": "array",
             "minItems": 1,
-            "items": ns_instantiate
+            "items": nsi_subnet_instantiate
+        },
+        "netslice-vld": {
+            "type": "array",
+            "minItems": 1,
+            "items": nsi_vld_instantiate
         },
     },
-    "required": ["nsiName", "nstdId", "vimAccountId"],
+    "required": ["nsiName", "nstId", "vimAccountId"],
     "additionalProperties": False
 }
 
@@ -590,7 +890,7 @@ nsi_action = {
 }
 
 nsi_terminate = {
-    
+
 }
 
 
@@ -619,3 +919,16 @@ def validate_input(indata, schema_to_use):
         raise ValidationError("Format error {} '{}' ".format(error_pos, e.message))
     except js_e.SchemaError:
         raise ValidationError("Bad json schema {}".format(schema_to_use), http_code=HTTPStatus.INTERNAL_SERVER_ERROR)
+
+
+def is_valid_uuid(x):
+    """
+    Test for a valid UUID
+    :param x: string to test
+    :return: True if x is a valid uuid, False otherwise
+    """
+    try:
+        if UUID(x):
+            return True
+    except (TypeError, ValueError, AttributeError):
+        return False