mirror of
https://github.com/jumpserver/jumpserver.git
synced 2026-01-18 00:18:49 +00:00
- 更改了资产表单,影响
- 资产创建和更新
- 增加了资产平台数据库,影响
- 平台创建更新和删除
- 更改了资产的platform字段,又一个字符字段,改为一个外键,影响
- 资产创建和更新
- 资产连接 [windows,linux]
- 测试连接等ansible任务
- 自动化云导入
- 更改了资产的序列化器,影响
- 资产创建更新列表
- 统一了树列表基础模板,影响
- 资产列表页,权限列表页,vault页,资产收集页
- 统一了导入导出组件,影响
- 资产导入导出
- 用户导入导出
- 用户组导入导出
- 系统用户导入导出
- 管理用户导入导出
- vault导出导出
- 收集用户列表导入导出
- 修改用户更新密码信号,影响
- 修改用户密码产生的改密日志
- 新增Model instance序列化工具函数,影响
- 操作日志生成
- 修改api mixin,新增 serializer_classes字段,serializer_classes = {"default": "", "display": "", "list": .., "other_action": ""}, 根据用户请求的方式返回不同的serializer_class,影响
- 用户的viewset
- 资产权限的viewset
- 统一系统配置中的tab切换
- 统一没有nav的页面,影响
- 重置密码
- 忘记密码
- 重置中设置密码
- 独立的message页面
- 修改用户组列表页,不再返还用户组下的用户,仅有数量
- 组织的一些方法变为layzproperty,避免重复计算
- 修改用户组详情页,影响
- 用户组增加删除用户
149 lines
4.8 KiB
Python
149 lines
4.8 KiB
Python
# -*- coding: utf-8 -*-
|
|
#
|
|
from django.utils.translation import ugettext_lazy as _
|
|
from rest_framework import serializers
|
|
|
|
from common.utils import validate_ssh_public_key
|
|
from common.mixins import BulkSerializerMixin
|
|
from common.serializers import AdaptedBulkListSerializer
|
|
from common.permissions import CanUpdateDeleteUser
|
|
from ..models import User
|
|
|
|
|
|
__all__ = [
|
|
'UserSerializer', 'UserPKUpdateSerializer',
|
|
'ChangeUserPasswordSerializer', 'ResetOTPSerializer',
|
|
'UserProfileSerializer', 'UserDisplaySerializer',
|
|
]
|
|
|
|
|
|
class UserSerializer(BulkSerializerMixin, serializers.ModelSerializer):
|
|
|
|
class Meta:
|
|
model = User
|
|
list_serializer_class = AdaptedBulkListSerializer
|
|
fields = [
|
|
'id', 'name', 'username', 'password', 'email', 'public_key',
|
|
'groups', 'role', 'wechat', 'phone', 'mfa_level',
|
|
'comment', 'source', 'is_valid', 'is_expired',
|
|
'is_active', 'created_by', 'is_first_login',
|
|
'date_password_last_updated', 'date_expired', 'avatar_url',
|
|
]
|
|
extra_kwargs = {
|
|
'password': {'write_only': True, 'required': False, 'allow_null': True, 'allow_blank': True},
|
|
'public_key': {'write_only': True},
|
|
'is_first_login': {'label': _('Is first login'), 'read_only': True},
|
|
'is_valid': {'label': _('Is valid')},
|
|
'is_expired': {'label': _('Is expired')},
|
|
'avatar_url': {'label': _('Avatar url')},
|
|
'created_by': {'read_only': True, 'allow_blank': True},
|
|
}
|
|
|
|
def validate_role(self, value):
|
|
request = self.context.get('request')
|
|
if not request.user.is_superuser and value != User.ROLE_USER:
|
|
role_display = dict(User.ROLE_CHOICES)[User.ROLE_USER]
|
|
msg = _("Role limit to {}".format(role_display))
|
|
raise serializers.ValidationError(msg)
|
|
return value
|
|
|
|
def validate_password(self, password):
|
|
from ..utils import check_password_rules
|
|
password_strategy = self.initial_data.get('password_strategy')
|
|
if password_strategy == '0':
|
|
return
|
|
if password_strategy is None and not password:
|
|
return
|
|
if not check_password_rules(password):
|
|
msg = _('Password does not match security rules')
|
|
raise serializers.ValidationError(msg)
|
|
return password
|
|
|
|
def validate_groups(self, groups):
|
|
role = self.initial_data.get('role')
|
|
if self.instance:
|
|
role = role or self.instance.role
|
|
if role == User.ROLE_AUDITOR:
|
|
return []
|
|
return groups
|
|
|
|
@staticmethod
|
|
def change_password_to_raw(attrs):
|
|
password = attrs.pop('password', None)
|
|
if password:
|
|
attrs['password_raw'] = password
|
|
return attrs
|
|
|
|
def validate(self, attrs):
|
|
attrs = self.change_password_to_raw(attrs)
|
|
return attrs
|
|
|
|
|
|
class UserDisplaySerializer(UserSerializer):
|
|
can_update = serializers.SerializerMethodField()
|
|
can_delete = serializers.SerializerMethodField()
|
|
|
|
class Meta(UserSerializer.Meta):
|
|
fields = UserSerializer.Meta.fields + [
|
|
'groups_display', 'role_display', 'source_display',
|
|
'can_update', 'can_delete',
|
|
]
|
|
|
|
def get_can_update(self, obj):
|
|
return CanUpdateDeleteUser.has_update_object_permission(
|
|
self.context['request'], self.context['view'], obj
|
|
)
|
|
|
|
def get_can_delete(self, obj):
|
|
return CanUpdateDeleteUser.has_delete_object_permission(
|
|
self.context['request'], self.context['view'], obj
|
|
)
|
|
|
|
def get_extra_kwargs(self):
|
|
kwargs = super().get_extra_kwargs()
|
|
kwargs.update({
|
|
'can_update': {'read_only': True},
|
|
'can_delete': {'read_only': True},
|
|
'groups_display': {'label': _('Groups name')},
|
|
'source_display': {'label': _('Source name')},
|
|
'role_display': {'label': _('Role name')},
|
|
})
|
|
return kwargs
|
|
|
|
|
|
class UserPKUpdateSerializer(serializers.ModelSerializer):
|
|
class Meta:
|
|
model = User
|
|
fields = ['id', 'public_key']
|
|
|
|
@staticmethod
|
|
def validate_public_key(value):
|
|
if not validate_ssh_public_key(value):
|
|
raise serializers.ValidationError(_('Not a valid ssh public key'))
|
|
return value
|
|
|
|
|
|
class ChangeUserPasswordSerializer(serializers.ModelSerializer):
|
|
|
|
class Meta:
|
|
model = User
|
|
fields = ['password']
|
|
|
|
|
|
class ResetOTPSerializer(serializers.Serializer):
|
|
msg = serializers.CharField(read_only=True)
|
|
|
|
def create(self, validated_data):
|
|
pass
|
|
|
|
def update(self, instance, validated_data):
|
|
pass
|
|
|
|
|
|
class UserProfileSerializer(serializers.ModelSerializer):
|
|
class Meta:
|
|
model = User
|
|
fields = [
|
|
'id', 'username', 'name', 'role', 'email'
|
|
]
|