Fix project_user role permissions
[osm/NBI.git] / osm_nbi / validation.py
index a244ac1..6e43be5 100644 (file)
@@ -566,16 +566,35 @@ pdu_edit_schema = {
 }
 
 # USERS
-project_role_mapping = {
-    "title": "",
+project_role_mappings = {
+    "title": "list pf projects/roles",
     "$schema": "http://json-schema.org/draft-04/schema#",
-    "type": "object",
-    "properties": {
-        "project": shortname_schema,
-        "role": shortname_schema
+    "type": "array",
+    "items": {
+        "type": "object",
+        "properties": {
+            "project": shortname_schema,
+            "role": shortname_schema
+        },
+        "required": ["project", "role"],
+        "additionalProperties": False
     },
-    "required": ["project", "role"],
-    "additionalProperties": False
+    "minItems": 1
+}
+project_role_mappings_optional = {
+    "title": "list of projects/roles or projects only",
+    "$schema": "http://json-schema.org/draft-04/schema#",
+    "type": "array",
+    "items": {
+        "type": "object",
+        "properties": {
+            "project": shortname_schema,
+            "role": shortname_schema
+        },
+        "required": ["project"],
+        "additionalProperties": False
+    },
+    "minItems": 1
 }
 user_new_schema = {
     "$schema": "http://json-schema.org/draft-04/schema#",
@@ -585,11 +604,7 @@ user_new_schema = {
         "username": shortname_schema,
         "password": passwd_schema,
         "projects": nameshort_list_schema,
-        "project_role_mappings": {
-            "type": "array",
-            "items": project_role_mapping,
-            "minItems": 1
-        },
+        "project_role_mappings": project_role_mappings,
     },
     "required": ["username", "password"],
     "additionalProperties": False
@@ -607,17 +622,16 @@ user_edit_schema = {
                 array_edition_schema
             ]
         },
-        "project_role_mappings": {
-            "type": "array",
-            "items": project_role_mapping,
-            "minItems": 1
-        },
+        "project_role_mappings": project_role_mappings,
+        "add_project_role_mappings": project_role_mappings,
+        "remove_project_role_mappings": project_role_mappings_optional,
     },
     "minProperties": 1,
     "additionalProperties": False
 }
 
 # PROJECTS
+topics_with_quota = ["vnfds", "nsds", "nsts", "pdus", "nsrs", "nsis", "vim_accounts", "wim_accounts", "sdns"]
 project_new_schema = {
     "$schema": "http://json-schema.org/draft-04/schema#",
     "title": "New project schema for administrators",
@@ -625,6 +639,11 @@ project_new_schema = {
     "properties": {
         "name": shortname_schema,
         "admin": bool_schema,
+        "quotas": {
+            "type": "object",
+            "properties": {topic: integer0_schema for topic in topics_with_quota},
+            "additionalProperties": False
+        },
     },
     "required": ["name"],
     "additionalProperties": False
@@ -636,6 +655,11 @@ project_edit_schema = {
     "properties": {
         "admin": bool_schema,
         "name": shortname_schema,     # To allow Project Name modification
+        "quotas": {
+            "type": "object",
+            "properties": {topic: {"oneOf": [integer0_schema, null_schema]} for topic in topics_with_quota},
+            "additionalProperties": False
+        },
     },
     "additionalProperties": False,
     "minProperties": 1
@@ -648,20 +672,34 @@ roles_new_schema = {
     "type": "object",
     "properties": {
         "name": shortname_schema,
-        "root": bool_schema,
+        "permissions": {
+            "type": "object",
+            "patternProperties": {
+                ".": bool_schema,
+            },
+            # "minProperties": 1,
+        }
     },
-    "required": ["name", "root"],
-    "additionalProperties": True
+    "required": ["name"],
+    "additionalProperties": False
 }
 roles_edit_schema = {
     "$schema": "http://json-schema.org/draft-04/schema#",
     "title": "Roles edit schema for administrators",
     "type": "object",
     "properties": {
-        "root": bool_schema,
+        "name": shortname_schema,
+        "permissions": {
+            "type": "object",
+            "patternProperties": {
+                ".": {
+                    "oneOf": [bool_schema, null_schema]
+                }
+            },
+            # "minProperties": 1,
+        }
     },
-    "required": ["root"],
-    "additionalProperties": True,
+    "additionalProperties": False,
     "minProperties": 1
 }
 
@@ -780,5 +818,5 @@ def is_valid_uuid(x):
     try:
         if UUID(x):
             return True
-    except (TypeError, ValueError):
+    except (TypeError, ValueError, AttributeError):
         return False