mirror of
https://github.com/jumpserver/jumpserver.git
synced 2026-01-16 23:52:41 +00:00
* [Update] 统一url地址 * [Update] 修改api * [Update] 使用规范的签名 * [Update] 修改url * [Update] 修改swagger * [Update] 添加serializer class避免报错 * [Update] 修改token * [Update] 支持api key * [Update] 支持生成api key * [Update] 修改api重定向 * [Update] 修改翻译 * [Update] 添加说明文档 * [Update] 修复浏览器关闭后session不失效的问题 * [Update] 修改一些内容 * [Update] 修改 jms脚本 * [Update] 修改重定向 * [Update] 修改搜索trim * [Update] 修改搜索trim * [Update] 添加sys log * [Bugfix] 修改登陆错误 * [Update] 优化User操作private_token的接口 (#3091) * [Update] 优化User操作private_token的接口 * [Update] 优化User操作private_token的接口 2 * [Bugfix] 解决授权了一个节点,当移动节点后,被移动的节点下的资产会放到未分组节点下的问题 * [Update] 升级jquery * [Update] 默认使用page * [Update] 修改使用Orgmodel view set * [Update] 支持 nv的硬盘 https://github.com/jumpserver/jumpserver/issues/1804 * [UPdate] 解决命令执行宽度问题 * [Update] 优化节点 * [Update] 修改nodes过多时创建比较麻烦 * [Update] 修改导入 * [Update] 节点获取更新 * [Update] 修改nodes * [Update] nodes显示full value * [Update] 统一使用nodes select2 函数 * [Update] 修改磁盘大小小数 * [Update] 修改 Node service * [Update] 优化授权节点 * [Update] 修改 node permission * [Update] 修改asset permission * [Stash] * [Update] 修改node assets api * [Update] 修改tree service,支持资产数量 * [Update] 修改暂时完成 * [Update] 修改一些bug
98 lines
3.3 KiB
Python
98 lines
3.3 KiB
Python
# -*- coding: utf-8 -*-
|
|
#
|
|
|
|
from django.db.models.signals import post_save, post_delete
|
|
from django.dispatch import receiver
|
|
from django.db import transaction
|
|
from rest_framework.renderers import JSONRenderer
|
|
|
|
from jumpserver.utils import current_request
|
|
from common.utils import get_request_ip, get_logger, get_syslogger
|
|
from users.models import User
|
|
from terminal.models import Session
|
|
from . import models
|
|
from . import serializers
|
|
|
|
logger = get_logger(__name__)
|
|
sys_logger = get_syslogger("audits")
|
|
json_render = JSONRenderer()
|
|
|
|
|
|
MODELS_NEED_RECORD = (
|
|
'User', 'UserGroup', 'Asset', 'Node', 'AdminUser', 'SystemUser',
|
|
'Domain', 'Gateway', 'Organization', 'AssetPermission', 'CommandFilter',
|
|
'CommandFilterRule', 'License', 'Setting', 'Account', 'SyncInstanceTask',
|
|
)
|
|
|
|
|
|
def create_operate_log(action, sender, resource):
|
|
user = current_request.user if current_request else None
|
|
if not user or not user.is_authenticated:
|
|
return
|
|
model_name = sender._meta.object_name
|
|
if model_name not in MODELS_NEED_RECORD:
|
|
return
|
|
resource_type = sender._meta.verbose_name
|
|
remote_addr = get_request_ip(current_request)
|
|
|
|
data = {
|
|
"user": str(user), 'action': action, 'resource_type': resource_type,
|
|
'resource': str(resource), 'remote_addr': remote_addr,
|
|
}
|
|
with transaction.atomic():
|
|
try:
|
|
models.OperateLog.objects.create(**data)
|
|
except Exception as e:
|
|
logger.error("Create operate log error: {}".format(e))
|
|
|
|
|
|
@receiver(post_save, dispatch_uid="my_unique_identifier")
|
|
def on_object_created_or_update(sender, instance=None, created=False, **kwargs):
|
|
if created:
|
|
action = models.OperateLog.ACTION_CREATE
|
|
else:
|
|
action = models.OperateLog.ACTION_UPDATE
|
|
create_operate_log(action, sender, instance)
|
|
|
|
|
|
@receiver(post_delete, dispatch_uid="my_unique_identifier")
|
|
def on_object_delete(sender, instance=None, **kwargs):
|
|
create_operate_log(models.OperateLog.ACTION_DELETE, sender, instance)
|
|
|
|
|
|
@receiver(post_save, sender=User, dispatch_uid="my_unique_identifier")
|
|
def on_user_change_password(sender, instance=None, **kwargs):
|
|
if hasattr(instance, '_set_password'):
|
|
if not current_request or not current_request.user.is_authenticated:
|
|
return
|
|
with transaction.atomic():
|
|
models.PasswordChangeLog.objects.create(
|
|
user=instance, change_by=current_request.user,
|
|
remote_addr=get_request_ip(current_request),
|
|
)
|
|
|
|
|
|
def on_audits_log_create(sender, instance=None, **kwargs):
|
|
if sender == models.UserLoginLog:
|
|
category = "login_log"
|
|
serializer = serializers.LoginLogSerializer
|
|
elif sender == models.FTPLog:
|
|
serializer = serializers.FTPLogSerializer
|
|
category = "ftp_log"
|
|
elif sender == models.OperateLog:
|
|
category = "operation_log"
|
|
serializer = serializers.OperateLogSerializer
|
|
elif sender == models.PasswordChangeLog:
|
|
category = "password_change_log"
|
|
serializer = serializers.PasswordChangeLogSerializer
|
|
elif sender == Session:
|
|
category = "host_session_log"
|
|
serializer = serializers.SessionAuditSerializer
|
|
else:
|
|
return
|
|
|
|
s = serializer(instance=instance)
|
|
data = json_render.render(s.data).decode(errors='ignore')
|
|
msg = "{} - {}".format(category, data)
|
|
sys_logger.info(msg)
|