dbinstance_accounts.go 28 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778
  1. // Copyright 2019 Yunion
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package models
  15. import (
  16. "context"
  17. "database/sql"
  18. "fmt"
  19. "yunion.io/x/cloudmux/pkg/cloudprovider"
  20. "yunion.io/x/jsonutils"
  21. "yunion.io/x/log"
  22. "yunion.io/x/pkg/errors"
  23. "yunion.io/x/pkg/util/compare"
  24. "yunion.io/x/pkg/util/rbacscope"
  25. "yunion.io/x/pkg/utils"
  26. "yunion.io/x/sqlchemy"
  27. api "yunion.io/x/onecloud/pkg/apis/compute"
  28. "yunion.io/x/onecloud/pkg/cloudcommon/db"
  29. "yunion.io/x/onecloud/pkg/cloudcommon/db/lockman"
  30. "yunion.io/x/onecloud/pkg/cloudcommon/db/taskman"
  31. "yunion.io/x/onecloud/pkg/httperrors"
  32. "yunion.io/x/onecloud/pkg/mcclient"
  33. "yunion.io/x/onecloud/pkg/util/seclib2"
  34. "yunion.io/x/onecloud/pkg/util/stringutils2"
  35. )
  36. // +onecloud:swagger-gen-model-singular=dbinstanceaccount
  37. // +onecloud:swagger-gen-model-plural=dbinstanceaccounts
  38. type SDBInstanceAccountManager struct {
  39. db.SStatusStandaloneResourceBaseManager
  40. SDBInstanceResourceBaseManager
  41. }
  42. var DBInstanceAccountManager *SDBInstanceAccountManager
  43. func init() {
  44. DBInstanceAccountManager = &SDBInstanceAccountManager{
  45. SStatusStandaloneResourceBaseManager: db.NewStatusStandaloneResourceBaseManager(
  46. SDBInstanceAccount{},
  47. "dbinstanceaccounts_tbl",
  48. "dbinstanceaccount",
  49. "dbinstanceaccounts",
  50. ),
  51. }
  52. DBInstanceAccountManager.SetVirtualObject(DBInstanceAccountManager)
  53. }
  54. type SDBInstanceAccount struct {
  55. db.SStatusStandaloneResourceBase
  56. Host string `width:"32" charset:"ascii" nullable:"false" list:"user" create:"optional" default:"%"`
  57. SDBInstanceResourceBase `width:"36" charset:"ascii" name:"dbinstance_id" nullable:"false" list:"user" create:"required" index:"true"`
  58. // 数据库密码
  59. Secret string `width:"256" charset:"ascii" nullable:"false" list:"user" create:"optional"`
  60. }
  61. func (manager *SDBInstanceAccountManager) GetContextManagers() [][]db.IModelManager {
  62. return [][]db.IModelManager{
  63. {DBInstanceManager},
  64. }
  65. }
  66. func (manager *SDBInstanceAccountManager) ResourceScope() rbacscope.TRbacScope {
  67. return rbacscope.ScopeProject
  68. }
  69. func (self *SDBInstanceAccount) GetOwnerId() mcclient.IIdentityProvider {
  70. instance, err := self.GetDBInstance()
  71. if err != nil {
  72. log.Errorf("failed to get instance for account %s(%s)", self.Name, self.Id)
  73. return nil
  74. }
  75. return instance.GetOwnerId()
  76. }
  77. func (manager *SDBInstanceAccountManager) FetchOwnerId(ctx context.Context, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error) {
  78. dbinstanceId, _ := data.GetString("dbinstance_id")
  79. if len(dbinstanceId) > 0 {
  80. instance, err := db.FetchById(DBInstanceManager, dbinstanceId)
  81. if err != nil {
  82. return nil, errors.Wrapf(err, "db.FetchById(DBInstanceManager, %s)", dbinstanceId)
  83. }
  84. return instance.(*SDBInstance).GetOwnerId(), nil
  85. }
  86. return db.FetchProjectInfo(ctx, data)
  87. }
  88. func (manager *SDBInstanceAccountManager) FilterByOwner(ctx context.Context, q *sqlchemy.SQuery, man db.FilterByOwnerProvider, userCred mcclient.TokenCredential, owner mcclient.IIdentityProvider, scope rbacscope.TRbacScope) *sqlchemy.SQuery {
  89. if owner != nil {
  90. sq := DBInstanceManager.Query("id")
  91. switch scope {
  92. case rbacscope.ScopeProject:
  93. sq = sq.Equals("tenant_id", owner.GetProjectId())
  94. return q.In("dbinstance_id", sq.SubQuery())
  95. case rbacscope.ScopeDomain:
  96. sq = sq.Equals("domain_id", owner.GetProjectDomainId())
  97. return q.In("dbinstance_id", sq.SubQuery())
  98. }
  99. }
  100. return q
  101. }
  102. func (self *SDBInstanceAccount) ValidateUpdateData(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, input api.DBInstanceAccountUpdateInput) (api.DBInstanceAccountUpdateInput, error) {
  103. var err error
  104. input.StatusStandaloneResourceBaseUpdateInput, err = self.SStatusStandaloneResourceBase.ValidateUpdateData(ctx, userCred, query, input.StatusStandaloneResourceBaseUpdateInput)
  105. if err != nil {
  106. return input, errors.Wrapf(err, "SStatusStandaloneResourceBase.ValidateUpdateData")
  107. }
  108. if len(input.Name) > 0 && input.Name != self.Name {
  109. return input, httperrors.NewForbiddenError("not allow update rds account name")
  110. }
  111. return input, nil
  112. }
  113. func (self *SDBInstanceAccount) getPrivilegesDetails() ([]api.DBInstancePrivilege, error) {
  114. out := []api.DBInstancePrivilege{}
  115. privileges, err := self.GetDBInstancePrivileges()
  116. if err != nil {
  117. return nil, errors.Wrap(err, "GetDBInstancePrivileges")
  118. }
  119. for _, privilege := range privileges {
  120. detail, err := privilege.GetPrivilege()
  121. if err != nil {
  122. return nil, errors.Wrap(err, "GetDetailedJson")
  123. }
  124. out = append(out, detail)
  125. }
  126. return out, nil
  127. }
  128. func (self *SDBInstanceAccount) getMoreDetails(ctx context.Context, userCred mcclient.TokenCredential, out api.DBInstanceAccountDetails) (api.DBInstanceAccountDetails, error) {
  129. privileges, err := self.getPrivilegesDetails()
  130. if err != nil {
  131. return out, err
  132. }
  133. out.DBInstanceprivileges = privileges
  134. return out, nil
  135. }
  136. func (manager *SDBInstanceAccountManager) FetchCustomizeColumns(
  137. ctx context.Context,
  138. userCred mcclient.TokenCredential,
  139. query jsonutils.JSONObject,
  140. objs []interface{},
  141. fields stringutils2.SSortedStrings,
  142. isList bool,
  143. ) []api.DBInstanceAccountDetails {
  144. rows := make([]api.DBInstanceAccountDetails, len(objs))
  145. stdRows := manager.SStatusStandaloneResourceBaseManager.FetchCustomizeColumns(ctx, userCred, query, objs, fields, isList)
  146. dbRows := manager.SDBInstanceResourceBaseManager.FetchCustomizeColumns(ctx, userCred, query, objs, fields, isList)
  147. dbinstanceIds := make([]string, len(objs))
  148. for i := range rows {
  149. rows[i] = api.DBInstanceAccountDetails{
  150. StatusStandaloneResourceDetails: stdRows[i],
  151. DBInstanceResourceInfo: dbRows[i],
  152. }
  153. account := objs[i].(*SDBInstanceAccount)
  154. rows[i], _ = account.getMoreDetails(ctx, userCred, rows[i])
  155. dbinstanceIds[i] = account.DBInstanceId
  156. }
  157. dbinstances := make(map[string]SDBInstance)
  158. err := db.FetchStandaloneObjectsByIds(DBInstanceManager, dbinstanceIds, &dbinstances)
  159. if err != nil {
  160. log.Errorf("FetchStandaloneObjectsByIds fail: %v", err)
  161. return rows
  162. }
  163. virObjs := make([]interface{}, len(objs))
  164. for i := range rows {
  165. if dbinstance, ok := dbinstances[dbinstanceIds[i]]; ok {
  166. virObjs[i] = &dbinstance
  167. rows[i].ProjectId = dbinstance.ProjectId
  168. }
  169. }
  170. projRows := DBInstanceManager.SProjectizedResourceBaseManager.FetchCustomizeColumns(ctx, userCred, query, virObjs, stringutils2.SSortedStrings{}, isList)
  171. for i := range rows {
  172. rows[i].ProjectizedResourceInfo = projRows[i]
  173. }
  174. return rows
  175. }
  176. // RDS账号列表
  177. func (manager *SDBInstanceAccountManager) ListItemFilter(
  178. ctx context.Context,
  179. q *sqlchemy.SQuery,
  180. userCred mcclient.TokenCredential,
  181. query api.DBInstanceAccountListInput,
  182. ) (*sqlchemy.SQuery, error) {
  183. q, err := manager.SStatusStandaloneResourceBaseManager.ListItemFilter(ctx, q, userCred, query.StatusStandaloneResourceListInput)
  184. if err != nil {
  185. return nil, errors.Wrap(err, "SStatusStandaloneResourceBaseManager.ListItemFilter")
  186. }
  187. q, err = manager.SDBInstanceResourceBaseManager.ListItemFilter(ctx, q, userCred, query.DBInstanceFilterListInput)
  188. if err != nil {
  189. return nil, errors.Wrap(err, "SDBInstanceResourceBaseManager.ListItemFilter")
  190. }
  191. return q, nil
  192. }
  193. func (manager *SDBInstanceAccountManager) OrderByExtraFields(
  194. ctx context.Context,
  195. q *sqlchemy.SQuery,
  196. userCred mcclient.TokenCredential,
  197. query api.DBInstanceAccountListInput,
  198. ) (*sqlchemy.SQuery, error) {
  199. q, err := manager.SStatusStandaloneResourceBaseManager.OrderByExtraFields(ctx, q, userCred, query.StatusStandaloneResourceListInput)
  200. if err != nil {
  201. return nil, errors.Wrap(err, "SStatusStandaloneResourceBaseManager.OrderByExtraFields")
  202. }
  203. q, err = manager.SDBInstanceResourceBaseManager.OrderByExtraFields(ctx, q, userCred, query.DBInstanceFilterListInput)
  204. if err != nil {
  205. return nil, errors.Wrap(err, "SDBInstanceResourceBaseManager.OrderByExtraFields")
  206. }
  207. return q, nil
  208. }
  209. func (manager *SDBInstanceAccountManager) QueryDistinctExtraField(q *sqlchemy.SQuery, field string) (*sqlchemy.SQuery, error) {
  210. q, err := manager.SStatusStandaloneResourceBaseManager.QueryDistinctExtraField(q, field)
  211. if err == nil {
  212. return q, nil
  213. }
  214. q, err = manager.SDBInstanceResourceBaseManager.QueryDistinctExtraField(q, field)
  215. if err == nil {
  216. return q, nil
  217. }
  218. return q, httperrors.ErrNotFound
  219. }
  220. type sRdsAccount struct {
  221. Name string
  222. DBInstanceId string `json:"dbinstance_id"`
  223. Host string
  224. }
  225. func (self *SDBInstanceAccount) GetUniqValues() jsonutils.JSONObject {
  226. return jsonutils.Marshal(sRdsAccount{Name: self.Name, DBInstanceId: self.DBInstanceId, Host: self.Host})
  227. }
  228. func (manager *SDBInstanceAccountManager) FetchUniqValues(ctx context.Context, data jsonutils.JSONObject) jsonutils.JSONObject {
  229. info := sRdsAccount{}
  230. data.Unmarshal(&info)
  231. return jsonutils.Marshal(info)
  232. }
  233. func (manager *SDBInstanceAccountManager) FilterByUniqValues(q *sqlchemy.SQuery, values jsonutils.JSONObject) *sqlchemy.SQuery {
  234. info := sRdsAccount{}
  235. values.Unmarshal(&info)
  236. if len(info.DBInstanceId) > 0 {
  237. q = q.Equals("dbinstance_id", info.DBInstanceId)
  238. }
  239. if len(info.Name) > 0 {
  240. q = q.Equals("name", info.Name)
  241. }
  242. if len(info.Host) > 0 {
  243. q = q.Equals("host", info.Host)
  244. }
  245. return q
  246. }
  247. func (manager *SDBInstanceAccountManager) ValidateCreateData(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, input api.DBInstanceAccountCreateInput) (*jsonutils.JSONDict, error) {
  248. if len(input.Password) > 0 {
  249. err := seclib2.ValidatePassword(input.Password)
  250. if err != nil {
  251. return nil, err
  252. }
  253. } else {
  254. input.Password = seclib2.RandomPassword2(12)
  255. }
  256. for _, instance := range []string{input.DBInstance, input.DBInstanceId} {
  257. if len(instance) > 0 {
  258. input.DBInstance = instance
  259. break
  260. }
  261. }
  262. if len(input.DBInstance) == 0 {
  263. return nil, httperrors.NewMissingParameterError("dbinstance")
  264. }
  265. _instance, err := DBInstanceManager.FetchByIdOrName(ctx, userCred, input.DBInstance)
  266. if err != nil {
  267. if err == sql.ErrNoRows {
  268. return nil, httperrors.NewResourceNotFoundError("failed to found dbinstance %s", input.DBInstance)
  269. }
  270. return nil, httperrors.NewGeneralError(errors.Wrap(err, "DBInstanceManager.FetchByIdOrName"))
  271. }
  272. instance := _instance.(*SDBInstance)
  273. input.DBInstanceId = instance.Id
  274. if instance.Status != api.DBINSTANCE_RUNNING {
  275. return nil, httperrors.NewInputParameterError("DBInstance %s(%s) status is %s require status is %s", instance.Name, instance.Id, instance.Status, api.DBINSTANCE_RUNNING)
  276. }
  277. region, err := instance.GetRegion()
  278. if err != nil {
  279. return nil, httperrors.NewGeneralError(errors.Wrapf(err, "GetRegion"))
  280. }
  281. for i, privilege := range input.Privileges {
  282. database, err := instance.GetDBInstanceDatabase(privilege.Database)
  283. if err != nil {
  284. return nil, httperrors.NewInputParameterError("failed to found dbinstance %s(%s) database %s: %v", instance.Name, instance.Id, privilege.Database, err)
  285. }
  286. input.Privileges[i].DBInstancedatabaseId = database.Id
  287. }
  288. input, err = region.GetDriver().ValidateCreateDBInstanceAccountData(ctx, userCred, ownerId, instance, input)
  289. if err != nil {
  290. return nil, err
  291. }
  292. input.StatusStandaloneResourceCreateInput, err = manager.SStatusStandaloneResourceBaseManager.ValidateCreateData(ctx, userCred, ownerId, query, input.StatusStandaloneResourceCreateInput)
  293. if err != nil {
  294. return nil, err
  295. }
  296. return input.JSON(input), nil
  297. }
  298. func (self *SDBInstanceAccount) SetPassword(passwd string) error {
  299. return self.savePassword(passwd)
  300. }
  301. func (self *SDBInstanceAccount) savePassword(secret string) error {
  302. sec, err := utils.EncryptAESBase64(self.Id, secret)
  303. if err != nil {
  304. return err
  305. }
  306. _, err = db.Update(self, func() error {
  307. self.Secret = sec
  308. return nil
  309. })
  310. return err
  311. }
  312. func (self *SDBInstanceAccount) GetPassword() (string, error) {
  313. return utils.DescryptAESBase64(self.Id, self.Secret)
  314. }
  315. func (self *SDBInstanceAccount) PostCreate(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, data jsonutils.JSONObject) {
  316. self.SStatusStandaloneResourceBase.PostCreate(ctx, userCred, ownerId, query, data)
  317. input := &api.DBInstanceAccountCreateInput{}
  318. data.Unmarshal(input)
  319. self.savePassword(input.Password)
  320. self.StartDBInstanceAccountCreateTask(ctx, userCred, data.(*jsonutils.JSONDict), "")
  321. }
  322. func (self *SDBInstanceAccount) StartDBInstanceAccountCreateTask(ctx context.Context, userCred mcclient.TokenCredential, data *jsonutils.JSONDict, parentTaskId string) error {
  323. self.SetStatus(ctx, userCred, api.DBINSTANCE_USER_CREATING, "")
  324. task, err := taskman.TaskManager.NewTask(ctx, "DBInstanceAccountCreateTask", self, userCred, data, parentTaskId, "", nil)
  325. if err != nil {
  326. return err
  327. }
  328. task.ScheduleRun(nil)
  329. return nil
  330. }
  331. func (self *SDBInstanceAccount) PerformGrantPrivilege(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data jsonutils.JSONObject) (jsonutils.JSONObject, error) {
  332. instance, err := self.GetDBInstance()
  333. if err != nil {
  334. return nil, errors.Wrap(err, "failed to found dbinstance")
  335. }
  336. databaseStr, _ := data.GetString("database")
  337. if len(databaseStr) == 0 {
  338. return nil, httperrors.NewMissingParameterError("database")
  339. }
  340. database, err := instance.GetDBInstanceDatabase(databaseStr)
  341. if err != nil {
  342. return nil, httperrors.NewInputParameterError("Failed to found database %s for dbinstance %s(%s): %v", databaseStr, instance.Name, instance.Id, err)
  343. }
  344. privilegeStr, _ := data.GetString("privilege")
  345. if len(privilegeStr) == 0 {
  346. return nil, httperrors.NewMissingParameterError("privilege")
  347. }
  348. privilege, _ := instance.GetDBInstancePrivilege(self.Id, database.Id)
  349. if privilege != nil {
  350. return nil, httperrors.NewInputParameterError("The account %s(%s) has permission %s to the database %s(%s)", self.Name, self.Id, privilege.Privilege, database.Name, database.Id)
  351. }
  352. region, err := instance.GetRegion()
  353. if err != nil {
  354. return nil, httperrors.NewGeneralError(errors.Wrapf(err, "GetRegion"))
  355. }
  356. err = region.GetDriver().ValidateDBInstanceAccountPrivilege(ctx, userCred, instance, self.Name, privilegeStr)
  357. if err != nil {
  358. return nil, err
  359. }
  360. return nil, self.StartGrantPrivilegeTask(ctx, userCred, databaseStr, privilegeStr, "")
  361. }
  362. func (self *SDBInstanceAccount) PerformSetPrivileges(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data jsonutils.JSONObject) (jsonutils.JSONObject, error) {
  363. instance, err := self.GetDBInstance()
  364. if err != nil {
  365. return nil, errors.Wrap(err, "failed to found dbinstance")
  366. }
  367. input := api.SDBInstanceSetPrivilegesInput{}
  368. err = data.Unmarshal(&input)
  369. if err != nil {
  370. return nil, httperrors.NewInputParameterError("failed to unmarshal input params: %v", err)
  371. }
  372. setPrivilege := map[string]map[string]string{
  373. "grant": map[string]string{},
  374. "revoke": map[string]string{},
  375. "input": map[string]string{},
  376. }
  377. region, err := instance.GetRegion()
  378. if err != nil {
  379. return nil, errors.Wrapf(err, "GetRegion")
  380. }
  381. for i, privilege := range input.Privileges {
  382. database, err := instance.GetDBInstanceDatabase(privilege.Database)
  383. if err != nil {
  384. return nil, httperrors.NewInputParameterError("Failed to found database %s for dbinstance %s(%s): %v", privilege.Database, instance.Name, instance.Id, err)
  385. }
  386. input.Privileges[i].DBInstancedatabaseId = database.Id
  387. err = region.GetDriver().ValidateDBInstanceAccountPrivilege(ctx, userCred, instance, self.Name, privilege.Privilege)
  388. if err != nil {
  389. return nil, err
  390. }
  391. dbPrivilege, _ := instance.GetDBInstancePrivilege(self.Id, database.Id)
  392. if dbPrivilege == nil {
  393. setPrivilege["grant"][database.Id] = privilege.Privilege
  394. } else if dbPrivilege.Privilege != privilege.Privilege {
  395. setPrivilege["grant"][database.Id] = privilege.Privilege
  396. setPrivilege["revoke"][database.Id] = dbPrivilege.Privilege
  397. }
  398. setPrivilege["input"][database.Id] = privilege.Privilege
  399. }
  400. dbPrivileges, err := self.GetDBInstancePrivileges()
  401. if err != nil {
  402. return nil, err
  403. }
  404. for _, privilege := range dbPrivileges {
  405. if _, ok := setPrivilege["input"][privilege.DBInstancedatabaseId]; !ok {
  406. setPrivilege["revoke"][privilege.DBInstancedatabaseId] = privilege.Privilege
  407. }
  408. }
  409. return nil, self.StartSetPrivilegesTask(ctx, userCred, jsonutils.Marshal(setPrivilege))
  410. }
  411. func (self *SDBInstanceAccount) StartSetPrivilegesTask(ctx context.Context, userCred mcclient.TokenCredential, data jsonutils.JSONObject) error {
  412. self.SetStatus(ctx, userCred, api.DBINSTANCE_USER_SET_PRIVILEGE, "")
  413. task, err := taskman.TaskManager.NewTask(ctx, "DBInstanceAccountSetPrivilegesTask", self, userCred, data.(*jsonutils.JSONDict), "", "", nil)
  414. if err != nil {
  415. return errors.Wrap(err, "NewTask")
  416. }
  417. task.ScheduleRun(nil)
  418. return nil
  419. }
  420. func (self *SDBInstanceAccount) StartGrantPrivilegeTask(ctx context.Context, userCred mcclient.TokenCredential, database string, privilege string, parentTaskId string) error {
  421. self.SetStatus(ctx, userCred, api.DBINSTANCE_USER_GRANT_PRIVILEGE, "")
  422. params := jsonutils.NewDict()
  423. params.Add(jsonutils.NewString(database), "database")
  424. params.Add(jsonutils.NewString(privilege), "privilege")
  425. task, err := taskman.TaskManager.NewTask(ctx, "DBInstanceAccountGrantPrivilegeTask", self, userCred, params, parentTaskId, "", nil)
  426. if err != nil {
  427. return errors.Wrap(err, "NewTask")
  428. }
  429. task.ScheduleRun(nil)
  430. return nil
  431. }
  432. func (self *SDBInstanceAccount) PerformRevokePrivilege(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data jsonutils.JSONObject) (jsonutils.JSONObject, error) {
  433. if self.Status != api.DBINSTANCE_USER_AVAILABLE {
  434. return nil, httperrors.NewInvalidStatusError("Account status is not %s current status is %s", api.DBINSTANCE_USER_AVAILABLE, self.Status)
  435. }
  436. instance, err := self.GetDBInstance()
  437. if err != nil {
  438. return nil, errors.Wrap(err, "failed to found dbinstance")
  439. }
  440. if instance.Status != api.DBINSTANCE_RUNNING {
  441. return nil, httperrors.NewInvalidStatusError("Instance status is not %s current status is %s", api.DBINSTANCE_RUNNING, instance.Status)
  442. }
  443. databaseStr, _ := data.GetString("database")
  444. if len(databaseStr) == 0 {
  445. return nil, httperrors.NewMissingParameterError("database")
  446. }
  447. database, err := instance.GetDBInstanceDatabase(databaseStr)
  448. if err != nil {
  449. return nil, httperrors.NewInputParameterError("Failed to found database %s for dbinstance %s(%s): %v", databaseStr, instance.Name, instance.Id, err)
  450. }
  451. if database.Status != api.DBINSTANCE_DATABASE_RUNNING {
  452. return nil, httperrors.NewInvalidStatusError("Database status is not %s current is %s", api.DBINSTANCE_DATABASE_RUNNING, database.Status)
  453. }
  454. privilege, err := instance.GetDBInstancePrivilege(self.Id, database.Id)
  455. if err != nil {
  456. if err == sql.ErrNoRows {
  457. return nil, httperrors.NewInputParameterError("Account %s(%s) does not have database %s(%s) permissions", self.Name, self.Id, database.Name, database.Id)
  458. }
  459. return nil, httperrors.NewGeneralError(err)
  460. }
  461. return nil, self.StartRevokePrivilegeTask(ctx, userCred, databaseStr, privilege.Privilege, "")
  462. }
  463. func (self *SDBInstanceAccount) StartRevokePrivilegeTask(ctx context.Context, userCred mcclient.TokenCredential, database string, privilege string, parentTaskId string) error {
  464. self.SetStatus(ctx, userCred, api.DBINSTANCE_USER_REVOKE_PRIVILEGE, "")
  465. params := jsonutils.NewDict()
  466. params.Add(jsonutils.NewString(database), "database")
  467. params.Add(jsonutils.NewString(privilege), "privilege")
  468. task, err := taskman.TaskManager.NewTask(ctx, "DBInstanceAccountRevokePrivilegeTask", self, userCred, params, parentTaskId, "", nil)
  469. if err != nil {
  470. return errors.Wrap(err, "NewTask")
  471. }
  472. task.ScheduleRun(nil)
  473. return nil
  474. }
  475. func (self *SDBInstanceAccount) PerformResetPassword(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data jsonutils.JSONObject) (jsonutils.JSONObject, error) {
  476. instance, err := self.GetDBInstance()
  477. if err != nil {
  478. return nil, err
  479. }
  480. passwdStr, _ := data.GetString("password")
  481. if len(passwdStr) > 0 {
  482. err = seclib2.ValidatePassword(passwdStr)
  483. if err != nil {
  484. return nil, err
  485. }
  486. }
  487. region, err := instance.GetRegion()
  488. if err != nil {
  489. return nil, err
  490. }
  491. err = region.GetDriver().ValidateResetDBInstancePassword(ctx, userCred, instance, self.Name)
  492. if err != nil {
  493. return nil, err
  494. }
  495. return nil, self.StartDBInstanceAccountResetPasswordTask(ctx, userCred, passwdStr)
  496. }
  497. func (self *SDBInstanceAccount) StartDBInstanceAccountResetPasswordTask(ctx context.Context, userCred mcclient.TokenCredential, password string) error {
  498. params := jsonutils.NewDict()
  499. if len(password) > 0 {
  500. params.Add(jsonutils.NewString(password), "password")
  501. } else {
  502. params.Add(jsonutils.NewString(seclib2.RandomPassword2(20)), "password")
  503. }
  504. self.SetStatus(ctx, userCred, api.DBINSTANCE_USER_RESET_PASSWD, "")
  505. task, err := taskman.TaskManager.NewTask(ctx, "DBInstanceAccountResetPasswordTask", self, userCred, params, "", "", nil)
  506. if err != nil {
  507. return errors.Wrapf(err, "NewTask")
  508. }
  509. task.ScheduleRun(nil)
  510. return nil
  511. }
  512. func (self *SDBInstanceAccount) GetDBInstancePrivileges() ([]SDBInstancePrivilege, error) {
  513. privileges := []SDBInstancePrivilege{}
  514. q := DBInstancePrivilegeManager.Query().Equals("dbinstanceaccount_id", self.Id)
  515. err := db.FetchModelObjects(DBInstancePrivilegeManager, q, &privileges)
  516. if err != nil {
  517. return nil, errors.Wrapf(err, "GetDBInstancePrivileges.FetchModelObjects for account %s", self.Id)
  518. }
  519. return privileges, nil
  520. }
  521. func (self *SDBInstanceAccount) GetDBInstanceDatabaseByName(dbName string) (*SDBInstanceDatabase, error) {
  522. q := DBInstanceDatabaseManager.Query().Equals("dbinstance_id", self.DBInstanceId).Equals("name", dbName)
  523. count, err := q.CountWithError()
  524. if err != nil {
  525. return nil, err
  526. }
  527. if count == 1 {
  528. database := &SDBInstanceDatabase{}
  529. database.SetModelManager(DBInstanceDatabaseManager, database)
  530. err = q.First(database)
  531. if err != nil {
  532. return nil, err
  533. }
  534. return database, nil
  535. }
  536. if count > 1 {
  537. return nil, sqlchemy.ErrDuplicateEntry
  538. }
  539. return nil, sql.ErrNoRows
  540. }
  541. func (manager *SDBInstanceAccountManager) SyncDBInstanceAccounts(ctx context.Context, userCred mcclient.TokenCredential, instance *SDBInstance, cloudAccounts []cloudprovider.ICloudDBInstanceAccount) ([]SDBInstanceAccount, []cloudprovider.ICloudDBInstanceAccount, compare.SyncResult) {
  542. lockman.LockRawObject(ctx, "dbinstance-accounts", instance.Id)
  543. defer lockman.ReleaseRawObject(ctx, "dbinstance-accounts", instance.Id)
  544. result := compare.SyncResult{}
  545. localAccounts := []SDBInstanceAccount{}
  546. remoteAccounts := []cloudprovider.ICloudDBInstanceAccount{}
  547. dbAccounts, err := instance.GetDBInstanceAccounts()
  548. if err != nil {
  549. result.Error(err)
  550. return nil, nil, result
  551. }
  552. accountMaps := map[string][]SDBInstanceAccount{}
  553. for i := range dbAccounts {
  554. key := fmt.Sprintf("%s:%s", dbAccounts[i].Name, dbAccounts[i].Host)
  555. _, ok := accountMaps[key]
  556. if !ok {
  557. accountMaps[key] = []SDBInstanceAccount{}
  558. }
  559. accountMaps[key] = append(accountMaps[key], dbAccounts[i])
  560. }
  561. remoteMaps := map[string]cloudprovider.ICloudDBInstanceAccount{}
  562. for i := range cloudAccounts {
  563. remoteMaps[fmt.Sprintf("%s:%s", cloudAccounts[i].GetName(), cloudAccounts[i].GetHost())] = cloudAccounts[i]
  564. }
  565. for key, account := range remoteMaps {
  566. locals, ok := accountMaps[key]
  567. if !ok {
  568. _account, err := manager.newFromCloudDBInstanceAccount(ctx, userCred, instance, account)
  569. if err != nil {
  570. result.AddError(err)
  571. continue
  572. }
  573. result.Add()
  574. remoteAccounts = append(remoteAccounts, account)
  575. localAccounts = append(localAccounts, *_account)
  576. continue
  577. }
  578. password := ""
  579. for i := range locals {
  580. if i == 0 {
  581. err = locals[i].SyncWithCloudDBInstanceAccount(ctx, userCred, instance, account)
  582. if err != nil {
  583. result.UpdateError(err)
  584. continue
  585. }
  586. result.Update()
  587. remoteAccounts = append(remoteAccounts, account)
  588. localAccounts = append(localAccounts, locals[0])
  589. } else {
  590. if passwd, err := locals[i].GetPassword(); err == nil && len(passwd) > 0 {
  591. password = passwd
  592. }
  593. err := locals[i].RealDelete(ctx, userCred)
  594. if err != nil {
  595. result.DeleteError(err)
  596. continue
  597. }
  598. result.Delete()
  599. }
  600. }
  601. if len(password) > 0 {
  602. locals[0].savePassword(password)
  603. }
  604. }
  605. for key, accounts := range accountMaps {
  606. _, ok := remoteMaps[key]
  607. if !ok {
  608. for i := range accounts {
  609. err := accounts[i].RealDelete(ctx, userCred)
  610. if err != nil {
  611. result.DeleteError(err)
  612. continue
  613. }
  614. result.Delete()
  615. }
  616. }
  617. }
  618. return localAccounts, remoteAccounts, result
  619. }
  620. func (self *SDBInstanceAccount) SyncWithCloudDBInstanceAccount(ctx context.Context, userCred mcclient.TokenCredential, instance *SDBInstance, extAccount cloudprovider.ICloudDBInstanceAccount) error {
  621. _, err := db.UpdateWithLock(ctx, self, func() error {
  622. self.Status = extAccount.GetStatus()
  623. return nil
  624. })
  625. if err != nil {
  626. return errors.Wrapf(err, "SyncWithCloudDBInstanceAccount.UpdateWithLock")
  627. }
  628. return nil
  629. }
  630. func (manager *SDBInstanceAccountManager) newFromCloudDBInstanceAccount(ctx context.Context, userCred mcclient.TokenCredential, instance *SDBInstance, extAccount cloudprovider.ICloudDBInstanceAccount) (*SDBInstanceAccount, error) {
  631. lockman.LockClass(ctx, manager, db.GetLockClassKey(manager, userCred))
  632. defer lockman.ReleaseClass(ctx, manager, db.GetLockClassKey(manager, userCred))
  633. account := SDBInstanceAccount{}
  634. account.SetModelManager(manager, &account)
  635. account.Name = extAccount.GetName()
  636. account.DBInstanceId = instance.Id
  637. account.Status = extAccount.GetStatus()
  638. account.Host = extAccount.GetHost()
  639. err := manager.TableSpec().Insert(ctx, &account)
  640. if err != nil {
  641. return nil, errors.Wrapf(err, "newFromCloudDBInstanceAccount.Insert")
  642. }
  643. return &account, nil
  644. }
  645. func (self *SDBInstanceAccount) Delete(ctx context.Context, userCred mcclient.TokenCredential) error {
  646. log.Infof("dbinstance account delete do nothing")
  647. return nil
  648. }
  649. func (self *SDBInstanceAccount) RealDelete(ctx context.Context, userCred mcclient.TokenCredential) error {
  650. return self.SStatusStandaloneResourceBase.Delete(ctx, userCred)
  651. }
  652. func (self *SDBInstanceAccount) CustomizeDelete(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data jsonutils.JSONObject) error {
  653. return self.StartDBInstanceAccountDeleteTask(ctx, userCred, "")
  654. }
  655. func (self *SDBInstanceAccount) StartDBInstanceAccountDeleteTask(ctx context.Context, userCred mcclient.TokenCredential, parentTaskId string) error {
  656. self.SetStatus(ctx, userCred, api.DBINSTANCE_USER_DELETING, "")
  657. task, err := taskman.TaskManager.NewTask(ctx, "DBInstanceAccountDeleteTask", self, userCred, nil, parentTaskId, "", nil)
  658. if err != nil {
  659. return err
  660. }
  661. task.ScheduleRun(nil)
  662. return nil
  663. }
  664. func (manager *SDBInstanceAccountManager) ListItemExportKeys(ctx context.Context,
  665. q *sqlchemy.SQuery,
  666. userCred mcclient.TokenCredential,
  667. keys stringutils2.SSortedStrings,
  668. ) (*sqlchemy.SQuery, error) {
  669. var err error
  670. q, err = manager.SStatusStandaloneResourceBaseManager.ListItemExportKeys(ctx, q, userCred, keys)
  671. if err != nil {
  672. return nil, errors.Wrap(err, "SStatusStandaloneResourceBaseManager.ListItemExportKeys")
  673. }
  674. if keys.ContainsAny(manager.SDBInstanceResourceBaseManager.GetExportKeys()...) {
  675. q, err = manager.SDBInstanceResourceBaseManager.ListItemExportKeys(ctx, q, userCred, keys)
  676. if err != nil {
  677. return nil, errors.Wrap(err, "SDBInstanceResourceBaseManager.ListItemExportKeys")
  678. }
  679. }
  680. return q, nil
  681. }
  682. func (manager *SDBInstanceAccountManager) InitializeData() error {
  683. sq := DBInstanceManager.Query("id")
  684. q := manager.Query().NotIn("dbinstance_id", sq.SubQuery())
  685. accounts := []SDBInstanceAccount{}
  686. err := db.FetchModelObjects(manager, q, &accounts)
  687. if err != nil {
  688. return errors.Wrapf(err, "db.FetchModelObjects")
  689. }
  690. for i := range accounts {
  691. err = accounts[i].RealDelete(context.Background(), nil)
  692. if err != nil {
  693. return errors.Wrapf(err, "purge %s", accounts[i].Id)
  694. }
  695. }
  696. log.Debugf("SDBInstanceAccountManager cleaned %d dirty data.", len(accounts))
  697. return nil
  698. }