1 | Kofa permissions and roles |
---|
2 | ************************** |
---|
3 | |
---|
4 | Permissions and roles used in a Kofa portal. |
---|
5 | |
---|
6 | .. :doctest: |
---|
7 | .. :layer: waeup.kofa.testing.KofaUnitTestLayer |
---|
8 | |
---|
9 | Convenience functions |
---|
10 | ===================== |
---|
11 | |
---|
12 | :mod:`waeup.kofa` offers some convenience functions to handle security |
---|
13 | roles. |
---|
14 | |
---|
15 | :func:`get_all_roles` |
---|
16 | --------------------- |
---|
17 | |
---|
18 | Gives us all roles defined in Kofa. We get tuples of |
---|
19 | kind |
---|
20 | |
---|
21 | ``(<ROLE-NAME>, <ROLE>)`` |
---|
22 | |
---|
23 | where ``<ROLE-NAME>`` is the name under which a role was registered |
---|
24 | with the ZCA (a string) and ``<ROLE>`` is the real role object. |
---|
25 | |
---|
26 | >>> from waeup.kofa.permissions import get_all_roles |
---|
27 | >>> get_all_roles() |
---|
28 | <generator object...at 0x...> |
---|
29 | |
---|
30 | >>> sorted(list(get_all_roles())) |
---|
31 | [(u'waeup.ACManager', <waeup.kofa.permissions.ACManager object at 0x...] |
---|
32 | |
---|
33 | :func:`get_waeup_roles` |
---|
34 | ----------------------- |
---|
35 | |
---|
36 | Gives us all roles, except the Kofa specific roles. We can get a list |
---|
37 | with or without local roles: |
---|
38 | |
---|
39 | >>> from waeup.kofa.permissions import get_waeup_roles |
---|
40 | >>> len(list(get_waeup_roles())) |
---|
41 | 19 |
---|
42 | |
---|
43 | >>> len(list(get_waeup_roles(also_local=True))) |
---|
44 | 35 |
---|
45 | |
---|
46 | |
---|
47 | :func:`get_waeup_role_names` |
---|
48 | ---------------------------- |
---|
49 | |
---|
50 | We can get all role names defined in Kofa (except 'local' |
---|
51 | roles that are meant not to be assigned globally): |
---|
52 | |
---|
53 | >>> from waeup.kofa.permissions import get_waeup_role_names |
---|
54 | >>> list(get_waeup_role_names()) |
---|
55 | [u'waeup.ACManager', |
---|
56 | u'waeup.AcademicsManager', |
---|
57 | u'waeup.AcademicsOfficer', |
---|
58 | u'waeup.AccommodationOfficer', |
---|
59 | u'waeup.Applicant', |
---|
60 | u'waeup.ApplicationsOfficer', |
---|
61 | u'waeup.CCOfficer', |
---|
62 | u'waeup.DataCenterManager', |
---|
63 | u'waeup.ImportManager', |
---|
64 | u'waeup.PortalManager', |
---|
65 | u'waeup.Student', |
---|
66 | u'waeup.StudentImpersonator', |
---|
67 | u'waeup.StudentsClearanceOfficer', |
---|
68 | u'waeup.StudentsCourseAdviser', |
---|
69 | u'waeup.StudentsManager', |
---|
70 | u'waeup.StudentsOfficer', |
---|
71 | u'waeup.UsersManager', |
---|
72 | u'waeup.WorkflowManager', |
---|
73 | u'waeup.xmlrpcusers1'] |
---|
74 | |
---|
75 | :func:`get_users_with_local_roles` |
---|
76 | ---------------------------------- |
---|
77 | |
---|
78 | We can get all users and their roles for a certain context |
---|
79 | object. This even works for objects that cannot have local roles as |
---|
80 | they are not stored in the ZODB: |
---|
81 | |
---|
82 | >>> from waeup.kofa.permissions import get_users_with_local_roles |
---|
83 | >>> mycontext = object() |
---|
84 | >>> people_and_roles = get_users_with_local_roles(mycontext) |
---|
85 | >>> people_and_roles |
---|
86 | <generator object...at 0x...> |
---|
87 | |
---|
88 | In this case, the result is empty: |
---|
89 | |
---|
90 | >>> people_and_roles = list(people_and_roles) |
---|
91 | >>> people_and_roles |
---|
92 | [] |
---|
93 | |
---|
94 | :func:`get_users_with_role` |
---|
95 | --------------------------- |
---|
96 | |
---|
97 | We can get all users with a specific role for a certain context |
---|
98 | object: |
---|
99 | |
---|
100 | >>> from waeup.kofa.permissions import get_users_with_role |
---|
101 | >>> mycontext = object() |
---|
102 | >>> people = get_users_with_role('waeup.portalManager', mycontext) |
---|
103 | >>> people |
---|
104 | <generator object...at 0x...> |
---|
105 | |
---|
106 | In this case, the result is empty: |
---|
107 | |
---|
108 | >>> people = list(people) |
---|
109 | >>> people |
---|
110 | [] |
---|