Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
36 changes: 36 additions & 0 deletions dim-testsuite/tests/rights_test.py
Original file line number Diff line number Diff line change
Expand Up @@ -91,6 +91,42 @@ def test_grant(self):
assert self.user.group_get_access('usergroup') == []
self.net.group_revoke_access('usergroup', 'allocate', 'pool')

# 1. Test for the attr revoke bugfix (with dot)
self.net.group_grant_access('usergroup', 'attr', ['audit.', 'pool'])
assert self.user.ippool_get_access('pool') == [{'action': 'attr.audit.', 'group': 'usergroup', 'object': 'pool'}]
self.net.group_revoke_access('usergroup', 'attr', ['audit.', 'pool'])
assert self.user.ippool_get_access('pool') == []

# 2. Test for robustness (symmetry with direct 'attr.' prefix)
self.net.group_grant_access('usergroup', 'attr', ['attr.audit.', 'pool'])
assert self.user.ippool_get_access('pool') == [{'action': 'attr.audit.', 'group': 'usergroup', 'object': 'pool'}]
self.net.group_revoke_access('usergroup', 'attr', ['attr.audit.', 'pool'])
assert self.user.ippool_get_access('pool') == []

# 3. Test for attr revoke (without dot)
self.net.group_grant_access('usergroup', 'attr', ['audit', 'pool'])
assert self.user.ippool_get_access('pool') == [{'action': 'attr.audit', 'group': 'usergroup', 'object': 'pool'}]
self.net.group_revoke_access('usergroup', 'attr', ['audit', 'pool'])
assert self.user.ippool_get_access('pool') == []

# 4. Independence test (scenario from ticket 2)
# Grant both rights (with and without dot)
self.net.group_grant_access('usergroup', 'attr', ['audit', 'pool'])
self.net.group_grant_access('usergroup', 'attr', ['audit.', 'pool'])
rights = self.user.ippool_get_access('pool')
assert {'action': 'attr.audit', 'group': 'usergroup', 'object': 'pool'} in rights
assert {'action': 'attr.audit.', 'group': 'usergroup', 'object': 'pool'} in rights

# Delete ONLY the right without dot
self.net.group_revoke_access('usergroup', 'attr', ['audit', 'pool'])
# The right with dot MUST still be there!
assert self.user.ippool_get_access('pool') == [{'action': 'attr.audit.', 'group': 'usergroup', 'object': 'pool'}]

# Delete also the right with dot
self.net.group_revoke_access('usergroup', 'attr', ['audit.', 'pool'])
assert self.user.ippool_get_access('pool') == []


def test_group_rename(self):
self.net.group_create('usergroup1')
self.net.group_rename('usergroup1', 'usergroup')
Expand Down
1 change: 1 addition & 0 deletions dim/CHANGES
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
unreleased
----------
* fix revoking attribute rights on pools when utilizing trailing dots or prefix strings
* add support for ALIAS resource records (coexists with other types at zone apex, mutually exclusive with CNAME, disabled in DNSSEC-enabled zones)
* add support for DNAME resource records according to RFC 6672 (prevents DNAME at zone apex, prevents records under DNAME subtrees)
* improve output update performance by using bulk inserts instead of ORM for zone fan-out
Expand Down
11 changes: 10 additions & 1 deletion dim/dim/rpc.py
Original file line number Diff line number Diff line change
Expand Up @@ -197,6 +197,12 @@ def group_revoke_access(self, group, access, object=None):
rights = get_rights(access, object)
for (access, object) in rights:
object_id, object_class = get_object_id_class(access, object)
# Fixes revoke attr bug
if access == 'attr' and object:
if object[0].startswith('attr.'):
access = object[0]
else:
access = 'attr.' + object[0]
ar = AccessRight.query.filter_by(access=access,
object_id=object_id,
object_class=object_class).first()
Expand Down Expand Up @@ -4122,7 +4128,10 @@ def _group_grant_access(group, access, object):
for (access, object) in rights:
object_id, object_class = get_object_id_class(access, object)
if access == 'attr':
access = 'attr.' + object[0]
if object[0].startswith('attr.'):
access = object[0]
else:
access = 'attr.' + object[0]
group.rights.add(AccessRight.find_or_create(access=access,
object_id=object_id,
object_class=object_class))
Expand Down