source: main/waeup.sirp/trunk/src/waeup/sirp/permissions.py @ 7125

Last change on this file since 7125 was 7122, checked in by Henrik Bettermann, 13 years ago

Let applicants cooperate with new imagestorage. Fix tests.

Extend permissions for PortalManager?.

  • Property svn:eol-style set to native
File size: 5.9 KB
Line 
1import grok
2from zope.component import getUtilitiesFor
3from zope.interface import Interface
4from zope.securitypolicy.interfaces import IRole, IPrincipalRoleMap
5from waeup.sirp.interfaces import ILocalRolesAssignable
6
7class Public(grok.Permission):
8    """Everyone-can-do-this-permission.
9
10    This permission is meant to be applied to objects/views/pages
11    etc., that should be usable/readable by everyone.
12
13    We need this to be able to tune default permissions more
14    restrictive and open up some dedicated objects like the front
15    page.
16    """
17    grok.name('waeup.Public')
18
19class Anonymous(grok.Permission):
20    """Only-anonymous-can-do-this-permission.
21    """
22    grok.name('waeup.Anonymous')
23
24class ViewPermission(grok.Permission):
25    grok.name('waeup.View')
26
27class ManageUniversity(grok.Permission):
28    grok.name('waeup.manageUniversity')
29
30class ManageUsers(grok.Permission):
31    grok.name('waeup.manageUsers')
32
33class ManageDataCenter(grok.Permission):
34    grok.name('waeup.manageDataCenter')
35
36class ManagePortalConfiguration(grok.Permission):
37    grok.name('waeup.managePortalConfiguration')
38
39# Local Roles
40class DepartmentOfficer(grok.Role):
41    grok.name('waeup.local.DepartmentOfficer')
42    grok.title(u'Department Officer')
43    grok.permissions('waeup.manageUniversity','waeup.View', 'waeup.Public')
44
45class ClearanceOfficer(grok.Role):
46    grok.name('waeup.local.ClearanceOfficer')
47    grok.title(u'Clearance Officer')
48    # to be further defined
49    grok.permissions('waeup.View', 'waeup.Public')
50
51class CourseAdviser(grok.Role):
52    grok.name('waeup.local.CourseAdviser')
53    grok.title(u'Course Adviser')
54    # to be further defined
55    grok.permissions('waeup.View', 'waeup.Public')
56
57# Global Roles
58class PortalUser(grok.Role):
59    grok.name('waeup.PortalUser')
60    grok.title(u'Portal User')
61    grok.permissions('waeup.View', 'waeup.Public')
62
63class PortalManager(grok.Role):
64    grok.name('waeup.PortalManager')
65    grok.title(u'Portal Manager')
66    grok.permissions('waeup.manageUniversity', 'waeup.manageUsers',
67                     'waeup.View', 'waeup.Public','waeup.manageACBatches',
68                     'waeup.manageDataCenter','waeup.managePortalSettings',
69                     'waeup.managePortalConfiguration',
70                     'waeup.manageApplications', 'waeup.handleApplication',
71                     'waeup.viewStudent', 'waeup.manageStudents',
72                     'waeup.viewHostels', 'waeup.manageHostels')
73
74def getRoles():
75    """Return a list of tuples ``<ROLE-NAME>, <ROLE>``.
76    """
77    return getUtilitiesFor(IRole)
78
79def getWAeUPRoles(also_local=False):
80    """Get all WAeUP roles.
81
82    WAeUP roles are ordinary roles whose id by convention starts with
83    a ``waeup.`` prefix.
84
85    If `also_local` is ``True`` (``False`` by default), also local
86    roles are returned. Local WAeUP roles are such whose id starts
87    with ``waeup.local.`` prefix (this is also a convention).
88
89    Returns a generator of the found roles.
90    """
91    for name, item in getRoles():
92        if not name.startswith('waeup.'):
93            # Ignore non-WAeUP roles...
94            continue
95        if not also_local and name.startswith('waeup.local.'):
96            # Ignore local roles...
97            continue
98        yield item
99
100def getWAeUPRoleNames():
101    """Get the ids of all WAeUP roles.
102
103    See :func:`getWAeUPRoles` for what a 'WAeUPRole' is.
104
105    This function returns a sorted list of WAeUP role names.
106    """
107    return sorted([x.id for x in getWAeUPRoles()])
108
109
110class LocalRolesAssignable(grok.Adapter):
111    """Default implementation for `ILocalRolesAssignable`.
112
113    This adapter returns a list for dictionaries for objects for which
114    we want to know the roles assignable to them locally.
115
116    The returned dicts contain a ``name`` and a ``title`` entry which
117    give a role (``name``) and a description, for which kind of users
118    the permission is meant to be used (``title``).
119
120    Having this adapter registered we make sure, that for each normal
121    object we get a valid `ILocalRolesAssignable` adapter.
122
123    Objects that want to offer certain local roles, can do so by
124    setting a (preferably class-) attribute to a list of role ids.
125
126    You can also define different adapters for different contexts to
127    have different role lookup mechanisms become available. But in
128    normal cases it should be sufficient to use this basic adapter.
129    """
130    grok.context(Interface)
131    grok.provides(ILocalRolesAssignable)
132
133    _roles = []
134
135    def __init__(self, context):
136        self.context = context
137        role_ids = getattr(context, 'local_roles', self._roles)
138        self._roles = [(name, role) for name, role in getRoles()
139                       if name in role_ids]
140        return
141
142    def __call__(self):
143        """Get a list of dictionaries containing ``names`` (the roles to
144        assign) and ``titles`` (some description of the type of user
145        to assign each role to).
146        """
147        return [
148            dict(
149                name=name,
150                title=role.title,
151                description=role.description)
152            for name, role in self._roles]
153
154def get_users_with_local_roles(context):
155    """Get a list of dicts representing the local roles set for `context`.
156
157    Each dict returns `user_name`, `user_title`, `local_role`,
158    `local_role_title`, and `setting` for each entry in the local
159    roles map of the `context` object.
160    """
161    try:
162        role_map = IPrincipalRoleMap(context)
163    except TypeError:
164        # no map no roles.
165        raise StopIteration
166    for local_role, user_name, setting in role_map.getPrincipalsAndRoles():
167        user = grok.getSite()['users'].get(user_name,None)
168        user_title = getattr(user, 'description', user_name)
169        local_role_title = dict(getRoles())[local_role].title
170        yield dict(user_name = user_name,
171                   user_title = user_title,
172                   local_role = local_role,
173                   local_role_title = local_role_title,
174                   setting = setting)
Note: See TracBrowser for help on using the repository browser.