2014-05-25 00:55:02 +02:00
|
|
|
from datetime import date
|
|
|
|
import os
|
|
|
|
|
2014-12-17 22:19:44 +01:00
|
|
|
from django.db import models, transaction
|
2014-05-25 00:55:02 +02:00
|
|
|
from django.conf import settings
|
2014-05-24 21:53:49 +02:00
|
|
|
from django.core.exceptions import ValidationError
|
2014-05-25 00:55:02 +02:00
|
|
|
from django.utils import timezone
|
2014-05-24 23:40:54 +02:00
|
|
|
from django.utils.encoding import python_2_unicode_compatible
|
2014-05-24 21:53:49 +02:00
|
|
|
from django.utils.translation import ugettext as _
|
2014-05-24 21:28:33 +02:00
|
|
|
|
|
|
|
from model_utils.models import TimeStampedModel
|
|
|
|
|
2014-05-30 21:46:10 +02:00
|
|
|
from celery.result import AsyncResult
|
|
|
|
|
2014-05-25 00:55:02 +02:00
|
|
|
from passlib.hash import sha512_crypt
|
|
|
|
from passlib.utils import generate_password
|
|
|
|
|
2014-05-25 23:35:14 +02:00
|
|
|
from .tasks import (
|
2014-05-30 17:10:22 +02:00
|
|
|
add_ldap_user_to_group,
|
2014-05-25 23:35:14 +02:00
|
|
|
create_ldap_group,
|
|
|
|
create_ldap_user,
|
2014-05-30 17:10:22 +02:00
|
|
|
delete_ldap_group_if_empty,
|
|
|
|
delete_ldap_user,
|
|
|
|
remove_ldap_user_from_group,
|
2014-05-25 23:35:14 +02:00
|
|
|
)
|
|
|
|
|
2014-05-25 00:55:02 +02:00
|
|
|
|
2014-06-01 01:36:50 +02:00
|
|
|
CANNOT_USE_PRIMARY_GROUP_AS_ADDITIONAL = _(
|
|
|
|
"You can not use a user's primary group.")
|
|
|
|
|
|
|
|
|
2014-05-30 21:46:10 +02:00
|
|
|
class TaskResult(TimeStampedModel, models.Model):
|
|
|
|
|
|
|
|
task_uuid = models.CharField(primary_key=True, max_length=64, blank=False)
|
|
|
|
task_name = models.CharField(max_length=255, blank=False, db_index=True)
|
|
|
|
is_finished = models.BooleanField(default=False)
|
|
|
|
is_success = models.BooleanField(default=False)
|
|
|
|
state = models.CharField(max_length=10)
|
|
|
|
result_body = models.TextField(blank=True)
|
|
|
|
|
|
|
|
class Meta:
|
|
|
|
abstract = True
|
|
|
|
|
|
|
|
def _set_result_fields(self, asyncresult):
|
|
|
|
if asyncresult.ready():
|
|
|
|
self.is_finished = True
|
|
|
|
self.is_success = asyncresult.state == 'SUCCESS'
|
|
|
|
self.result_body = str(asyncresult.result)
|
|
|
|
self.state = asyncresult.state
|
|
|
|
asyncresult.get(no_ack=False)
|
|
|
|
|
|
|
|
def update_taskstatus(self):
|
|
|
|
if not self.is_finished:
|
2014-06-01 01:36:50 +02:00
|
|
|
asyncresult = AsyncResult(self.task_uuid)
|
2014-05-30 21:46:10 +02:00
|
|
|
self._set_result_fields(asyncresult)
|
|
|
|
self.save()
|
|
|
|
|
|
|
|
|
2014-05-25 00:55:02 +02:00
|
|
|
class GroupManager(models.Manager):
|
|
|
|
|
|
|
|
def get_next_gid(self):
|
|
|
|
q = self.aggregate(models.Max('gid'))
|
2014-05-25 14:53:58 +02:00
|
|
|
if q['gid__max'] is None:
|
|
|
|
return settings.OSUSER_MINGID
|
2014-05-25 00:55:02 +02:00
|
|
|
return max(settings.OSUSER_MINGID, q['gid__max'] + 1)
|
|
|
|
|
2014-05-24 21:28:33 +02:00
|
|
|
|
2014-05-24 23:40:54 +02:00
|
|
|
@python_2_unicode_compatible
|
2014-05-24 21:28:33 +02:00
|
|
|
class Group(TimeStampedModel, models.Model):
|
2014-05-24 23:40:54 +02:00
|
|
|
groupname = models.CharField(
|
|
|
|
_('Group name'), max_length=16, unique=True)
|
|
|
|
gid = models.PositiveSmallIntegerField(
|
|
|
|
_('Group ID'), unique=True, primary_key=True)
|
|
|
|
descr = models.TextField(_('Description'), blank=True)
|
|
|
|
passwd = models.CharField(
|
|
|
|
_('Group password'), max_length=128, blank=True)
|
|
|
|
|
2014-05-25 00:55:02 +02:00
|
|
|
objects = GroupManager()
|
|
|
|
|
2014-05-24 23:40:54 +02:00
|
|
|
class Meta:
|
|
|
|
verbose_name = _('Group')
|
|
|
|
verbose_name_plural = _('Groups')
|
|
|
|
|
|
|
|
def __str__(self):
|
|
|
|
return '{0} ({1})'.format(self.groupname, self.gid)
|
2014-05-24 21:28:33 +02:00
|
|
|
|
2014-05-30 17:10:22 +02:00
|
|
|
def save(self, *args, **kwargs):
|
|
|
|
super(Group, self).save(*args, **kwargs)
|
2014-05-30 21:46:10 +02:00
|
|
|
GroupTaskResult.objects.create_grouptaskresult(
|
2014-06-01 01:36:50 +02:00
|
|
|
self,
|
|
|
|
create_ldap_group.delay(self.groupname, self.gid, self.descr),
|
|
|
|
'create_ldap_group'
|
2014-05-30 21:46:10 +02:00
|
|
|
)
|
2014-05-30 17:10:22 +02:00
|
|
|
return self
|
|
|
|
|
|
|
|
def delete(self, *args, **kwargs):
|
2014-05-30 21:46:10 +02:00
|
|
|
DeleteTaskResult.objects.create_deletetaskresult(
|
|
|
|
'group', self.groupname,
|
2014-06-01 01:36:50 +02:00
|
|
|
delete_ldap_group_if_empty.delay(self.groupname),
|
2014-06-01 15:26:01 +02:00
|
|
|
'delete_ldap_group_if_empty'
|
2014-05-30 21:46:10 +02:00
|
|
|
)
|
2014-05-30 17:10:22 +02:00
|
|
|
super(Group, self).delete(*args, **kwargs)
|
|
|
|
|
2014-05-24 21:28:33 +02:00
|
|
|
|
2014-05-30 21:46:10 +02:00
|
|
|
class TaskResultManager(models.Manager):
|
|
|
|
|
2014-06-01 01:36:50 +02:00
|
|
|
def create(self, asyncresult, task_name):
|
2014-05-30 21:46:10 +02:00
|
|
|
result = self.model(
|
2014-06-01 01:36:50 +02:00
|
|
|
task_uuid=asyncresult.task_id, task_name=task_name
|
2014-05-30 21:46:10 +02:00
|
|
|
)
|
|
|
|
result._set_result_fields(asyncresult)
|
|
|
|
return result
|
|
|
|
|
|
|
|
|
|
|
|
class DeleteTaskResultManager(TaskResultManager):
|
|
|
|
|
2014-06-01 01:36:50 +02:00
|
|
|
def create_deletetaskresult(
|
|
|
|
self, modeltype, modelname, asyncresult, task_name
|
|
|
|
):
|
2014-05-30 21:46:10 +02:00
|
|
|
taskresult = super(DeleteTaskResultManager, self).create(
|
2014-06-01 01:36:50 +02:00
|
|
|
asyncresult, task_name)
|
2014-05-30 21:46:10 +02:00
|
|
|
taskresult.modeltype = modeltype
|
|
|
|
taskresult.modelname = modelname
|
|
|
|
taskresult.save()
|
|
|
|
return taskresult
|
|
|
|
|
|
|
|
|
|
|
|
class DeleteTaskResult(TaskResult):
|
|
|
|
|
|
|
|
modeltype = models.CharField(max_length=20, db_index=True)
|
|
|
|
modelname = models.CharField(max_length=255)
|
|
|
|
|
|
|
|
objects = DeleteTaskResultManager()
|
|
|
|
|
|
|
|
|
|
|
|
class GroupTaskResultManager(TaskResultManager):
|
|
|
|
|
2014-06-01 01:36:50 +02:00
|
|
|
def create_grouptaskresult(
|
|
|
|
self, group, asyncresult, task_name, commit=False
|
|
|
|
):
|
2014-05-30 21:46:10 +02:00
|
|
|
taskresult = super(GroupTaskResultManager, self).create(
|
2014-06-01 01:36:50 +02:00
|
|
|
asyncresult, task_name)
|
2014-05-30 21:46:10 +02:00
|
|
|
taskresult.group = group
|
|
|
|
taskresult.save()
|
|
|
|
return taskresult
|
|
|
|
|
|
|
|
|
|
|
|
class GroupTaskResult(TaskResult):
|
|
|
|
|
|
|
|
group = models.ForeignKey(Group)
|
|
|
|
|
|
|
|
objects = GroupTaskResultManager()
|
|
|
|
|
|
|
|
|
2014-05-25 00:55:02 +02:00
|
|
|
class UserManager(models.Manager):
|
|
|
|
|
|
|
|
def get_next_uid(self):
|
|
|
|
q = self.aggregate(models.Max('uid'))
|
2014-05-25 14:53:58 +02:00
|
|
|
if q['uid__max'] is None:
|
|
|
|
return settings.OSUSER_MINUID
|
2014-05-25 00:55:02 +02:00
|
|
|
return max(settings.OSUSER_MINUID, q['uid__max'] + 1)
|
|
|
|
|
|
|
|
def get_next_username(self):
|
|
|
|
count = 1
|
|
|
|
usernameformat = "{0}{1:02d}"
|
|
|
|
nextuser = usernameformat.format(settings.OSUSER_USERNAME_PREFIX,
|
|
|
|
count)
|
|
|
|
for user in self.values('username').filter(
|
|
|
|
username__startswith=settings.OSUSER_USERNAME_PREFIX).order_by(
|
|
|
|
'username'):
|
2014-05-25 23:35:14 +02:00
|
|
|
if user['username'] == nextuser:
|
2014-05-25 00:55:02 +02:00
|
|
|
count += 1
|
|
|
|
nextuser = usernameformat.format(
|
|
|
|
settings.OSUSER_USERNAME_PREFIX, count)
|
|
|
|
else:
|
|
|
|
break
|
|
|
|
return nextuser
|
|
|
|
|
2014-12-17 22:19:44 +01:00
|
|
|
@transaction.atomic
|
2014-05-25 23:35:14 +02:00
|
|
|
def create_user(self, username=None, password=None, commit=False):
|
2014-05-25 00:55:02 +02:00
|
|
|
uid = self.get_next_uid()
|
|
|
|
gid = Group.objects.get_next_gid()
|
|
|
|
if username is None:
|
|
|
|
username = self.get_next_username()
|
|
|
|
if password is None:
|
|
|
|
password = generate_password()
|
|
|
|
homedir = os.path.join(settings.OSUSER_HOME_BASEPATH, username)
|
|
|
|
group = Group.objects.create(groupname=username, gid=gid)
|
|
|
|
user = self.create(username=username, group=group, uid=uid,
|
|
|
|
homedir=homedir,
|
|
|
|
shell=settings.OSUSER_DEFAULT_SHELL)
|
2014-05-30 17:10:22 +02:00
|
|
|
user.set_password(password)
|
2014-05-25 23:35:14 +02:00
|
|
|
if commit:
|
|
|
|
user.save()
|
2014-05-25 00:55:02 +02:00
|
|
|
return user
|
|
|
|
|
|
|
|
|
2014-05-24 23:40:54 +02:00
|
|
|
@python_2_unicode_compatible
|
2014-05-24 21:28:33 +02:00
|
|
|
class User(TimeStampedModel, models.Model):
|
2014-05-24 23:40:54 +02:00
|
|
|
username = models.CharField(
|
|
|
|
_('User name'), max_length=64, unique=True)
|
|
|
|
uid = models.PositiveSmallIntegerField(
|
|
|
|
_('User ID'), unique=True, primary_key=True)
|
|
|
|
group = models.ForeignKey(Group, verbose_name=_('Group'))
|
|
|
|
gecos = models.CharField(_('Gecos field'), max_length=128, blank=True)
|
|
|
|
homedir = models.CharField(_('Home directory'), max_length=256)
|
|
|
|
shell = models.CharField(_('Login shell'), max_length=64)
|
|
|
|
|
2014-05-25 00:55:02 +02:00
|
|
|
objects = UserManager()
|
|
|
|
|
2014-05-24 23:40:54 +02:00
|
|
|
class Meta:
|
|
|
|
verbose_name = _('User')
|
|
|
|
verbose_name_plural = _('Users')
|
2014-05-24 21:28:33 +02:00
|
|
|
|
2014-05-24 23:40:54 +02:00
|
|
|
def __str__(self):
|
|
|
|
return '{0} ({1})'.format(self.username, self.uid)
|
2014-05-24 21:28:33 +02:00
|
|
|
|
2014-05-30 17:10:22 +02:00
|
|
|
def set_password(self, password):
|
2014-06-01 15:03:15 +02:00
|
|
|
if hasattr(self, 'shadow'):
|
|
|
|
self.shadow.set_password(password)
|
|
|
|
else:
|
|
|
|
self.shadow = Shadow.objects.create_shadow(
|
|
|
|
user=self, password=password
|
|
|
|
)
|
2014-05-30 21:46:10 +02:00
|
|
|
UserTaskResult.objects.create_usertaskresult(
|
|
|
|
self,
|
|
|
|
create_ldap_user.delay(
|
2014-06-01 00:32:06 +02:00
|
|
|
self.username, self.uid, self.group.gid, self.gecos,
|
2014-05-30 21:46:10 +02:00
|
|
|
self.homedir, self.shell, password
|
|
|
|
),
|
2014-06-01 01:36:50 +02:00
|
|
|
'create_ldap_user',
|
2014-05-30 21:46:10 +02:00
|
|
|
commit=True
|
2014-05-30 18:39:51 +02:00
|
|
|
)
|
2014-05-30 17:10:22 +02:00
|
|
|
|
|
|
|
def save(self, *args, **kwargs):
|
2014-05-30 21:46:10 +02:00
|
|
|
UserTaskResult.objects.create_usertaskresult(
|
|
|
|
self,
|
|
|
|
create_ldap_user.delay(
|
2014-06-01 00:32:06 +02:00
|
|
|
self.username, self.uid, self.group.gid, self.gecos,
|
2014-05-30 21:46:10 +02:00
|
|
|
self.homedir, self.shell, password=None
|
2014-06-01 01:36:50 +02:00
|
|
|
),
|
|
|
|
'create_ldap_user'
|
2014-05-30 18:39:51 +02:00
|
|
|
)
|
2014-05-30 17:10:22 +02:00
|
|
|
return super(User, self).save(*args, **kwargs)
|
|
|
|
|
|
|
|
def delete(self, *args, **kwargs):
|
|
|
|
for group in [
|
|
|
|
ag.group for ag in AdditionalGroup.objects.filter(user=self)
|
|
|
|
]:
|
2014-05-30 21:46:10 +02:00
|
|
|
DeleteTaskResult.objects.create_deletetaskresult(
|
|
|
|
'usergroup',
|
|
|
|
'{0} in {1}'.format(self.username, group.groupname),
|
|
|
|
remove_ldap_user_from_group.delay(
|
2014-06-01 01:36:50 +02:00
|
|
|
self.username, group.groupname),
|
|
|
|
'remove_ldap_user_from_group',
|
2014-05-30 21:46:10 +02:00
|
|
|
)
|
|
|
|
DeleteTaskResult.objects.create_deletetaskresult(
|
|
|
|
'user', self.username,
|
2014-06-01 01:36:50 +02:00
|
|
|
delete_ldap_user.delay(self.username),
|
|
|
|
'delete_ldap_user'
|
2014-05-30 21:46:10 +02:00
|
|
|
)
|
2014-05-30 17:10:22 +02:00
|
|
|
self.group.delete()
|
|
|
|
super(User, self).delete(*args, **kwargs)
|
|
|
|
|
2014-05-24 23:40:54 +02:00
|
|
|
|
2014-05-30 21:46:10 +02:00
|
|
|
class UserTaskResultManager(TaskResultManager):
|
|
|
|
|
2014-06-01 01:36:50 +02:00
|
|
|
def create_usertaskresult(
|
|
|
|
self, user, asyncresult, task_name, commit=False
|
|
|
|
):
|
|
|
|
taskresult = self.create(asyncresult, task_name)
|
2014-05-30 21:46:10 +02:00
|
|
|
taskresult.user = user
|
|
|
|
taskresult.save()
|
|
|
|
return taskresult
|
|
|
|
|
|
|
|
|
|
|
|
class UserTaskResult(TaskResult):
|
|
|
|
|
|
|
|
user = models.ForeignKey(User)
|
|
|
|
|
|
|
|
objects = UserTaskResultManager()
|
|
|
|
|
|
|
|
|
2014-05-25 00:55:02 +02:00
|
|
|
class ShadowManager(models.Manager):
|
|
|
|
|
|
|
|
def create_shadow(self, user, password):
|
|
|
|
changedays = (timezone.now().date() - date(1970, 1, 1)).days
|
|
|
|
shadow = self.create(
|
|
|
|
user=user, changedays=changedays,
|
|
|
|
minage=0, maxage=None, gracedays=7,
|
2014-06-01 14:51:33 +02:00
|
|
|
inactdays=30, expiredays=None
|
2014-05-25 00:55:02 +02:00
|
|
|
)
|
2014-06-01 14:51:33 +02:00
|
|
|
shadow.set_password(password)
|
2014-05-25 00:55:02 +02:00
|
|
|
shadow.save()
|
|
|
|
return shadow
|
|
|
|
|
|
|
|
|
2014-05-24 23:40:54 +02:00
|
|
|
@python_2_unicode_compatible
|
2014-05-24 21:28:33 +02:00
|
|
|
class Shadow(TimeStampedModel, models.Model):
|
2014-05-24 23:40:54 +02:00
|
|
|
user = models.OneToOneField(User, primary_key=True, verbose_name=_('User'))
|
|
|
|
passwd = models.CharField(_('Encrypted password'), max_length=128)
|
|
|
|
changedays = models.PositiveSmallIntegerField(
|
|
|
|
_('Date of last change'),
|
|
|
|
help_text=_('This is expressed in days since Jan 1, 1970'),
|
|
|
|
blank=True, null=True)
|
|
|
|
minage = models.PositiveSmallIntegerField(
|
|
|
|
_('Minimum age'),
|
|
|
|
help_text=_('Minimum number of days before the password can be'
|
|
|
|
' changed'),
|
|
|
|
blank=True, null=True)
|
|
|
|
maxage = models.PositiveSmallIntegerField(
|
|
|
|
_('Maximum age'),
|
|
|
|
help_text=_('Maximum number of days after which the password has to'
|
|
|
|
' be changed'),
|
|
|
|
blank=True, null=True)
|
|
|
|
gracedays = models.PositiveSmallIntegerField(
|
|
|
|
_('Grace period'),
|
|
|
|
help_text=_('The number of days before the password is going to'
|
|
|
|
' expire'),
|
|
|
|
blank=True, null=True)
|
|
|
|
inactdays = models.PositiveSmallIntegerField(
|
|
|
|
_('Inactivity period'),
|
|
|
|
help_text=_('The number of days after the password has expired during'
|
|
|
|
' which the password should still be accepted'),
|
|
|
|
blank=True, null=True)
|
|
|
|
expiredays = models.PositiveSmallIntegerField(
|
|
|
|
_('Account expiration date'),
|
|
|
|
help_text=_('The date of expiration of the account, expressed as'
|
|
|
|
' number of days since Jan 1, 1970'),
|
|
|
|
blank=True, null=True, default=None)
|
|
|
|
|
2014-05-25 00:55:02 +02:00
|
|
|
objects = ShadowManager()
|
|
|
|
|
2014-05-24 23:40:54 +02:00
|
|
|
class Meta:
|
|
|
|
verbose_name = _('Shadow password')
|
|
|
|
verbose_name_plural = _('Shadow passwords')
|
2014-05-24 21:53:49 +02:00
|
|
|
|
2014-05-24 23:40:54 +02:00
|
|
|
def __str__(self):
|
|
|
|
return 'for user {0}'.format(self.user)
|
2014-05-24 21:53:49 +02:00
|
|
|
|
2014-06-01 14:51:33 +02:00
|
|
|
def set_password(self, password):
|
|
|
|
self.passwd = sha512_crypt.encrypt(password)
|
|
|
|
|
2014-05-24 23:40:54 +02:00
|
|
|
|
|
|
|
@python_2_unicode_compatible
|
2014-05-24 21:53:49 +02:00
|
|
|
class AdditionalGroup(TimeStampedModel, models.Model):
|
|
|
|
user = models.ForeignKey(User)
|
|
|
|
group = models.ForeignKey(Group)
|
|
|
|
|
|
|
|
class Meta:
|
|
|
|
unique_together = ('user', 'group')
|
2014-05-24 23:40:54 +02:00
|
|
|
verbose_name = _('Additional group')
|
|
|
|
verbose_name_plural = _('Additional groups')
|
2014-05-24 21:53:49 +02:00
|
|
|
|
|
|
|
def clean(self):
|
|
|
|
if self.user.group == self.group:
|
2014-06-01 01:36:50 +02:00
|
|
|
raise ValidationError(CANNOT_USE_PRIMARY_GROUP_AS_ADDITIONAL)
|
2014-05-24 23:40:54 +02:00
|
|
|
|
2014-05-30 17:10:22 +02:00
|
|
|
def save(self, *args, **kwargs):
|
2014-06-01 01:36:50 +02:00
|
|
|
GroupTaskResult.objects.create_grouptaskresult(
|
|
|
|
self.group,
|
|
|
|
add_ldap_user_to_group.delay(
|
|
|
|
self.user.username, self.group.groupname),
|
|
|
|
'add_ldap_user_to_group'
|
2014-05-30 21:46:10 +02:00
|
|
|
)
|
2014-05-30 17:10:22 +02:00
|
|
|
super(AdditionalGroup, self).save(*args, **kwargs)
|
|
|
|
|
|
|
|
def delete(self, *args, **kwargs):
|
2014-05-30 21:46:10 +02:00
|
|
|
DeleteTaskResult.objects.create_deletetaskresult(
|
|
|
|
'usergroup',
|
|
|
|
str(self),
|
|
|
|
remove_ldap_user_from_group.delay(
|
2014-06-01 01:36:50 +02:00
|
|
|
self.user.username, self.group.groupname),
|
|
|
|
'remove_ldap_user_from_group'
|
2014-05-30 21:46:10 +02:00
|
|
|
)
|
2014-05-30 17:10:22 +02:00
|
|
|
super(AdditionalGroup, self).delete(*args, **kwargs)
|
|
|
|
|
2014-05-24 23:40:54 +02:00
|
|
|
def __str__(self):
|
|
|
|
return '{0} in {1}'.format(self.user, self.group)
|