2014-02-18 03:38:50 +04:00
// Copyright 2014 The Gogs Authors. All rights reserved.
// Use of this source code is governed by a MIT-style
// license that can be found in the LICENSE file.
2014-02-17 19:57:23 +04:00
package models
2015-02-24 08:27:22 +03:00
import (
"fmt"
2015-03-16 11:04:27 +03:00
2016-11-03 15:29:56 +03:00
"github.com/go-gitea/gitea/modules/log"
2015-02-24 08:27:22 +03:00
)
2015-02-05 16:29:08 +03:00
type AccessMode int
2014-06-25 08:44:48 +04:00
2014-02-17 19:57:23 +04:00
const (
2016-03-06 02:08:42 +03:00
ACCESS_MODE_NONE AccessMode = iota // 0
ACCESS_MODE_READ // 1
ACCESS_MODE_WRITE // 2
ACCESS_MODE_ADMIN // 3
ACCESS_MODE_OWNER // 4
2014-02-17 19:57:23 +04:00
)
2016-03-21 19:47:54 +03:00
func ( mode AccessMode ) String ( ) string {
switch mode {
case ACCESS_MODE_READ :
return "read"
case ACCESS_MODE_WRITE :
return "write"
case ACCESS_MODE_ADMIN :
return "admin"
case ACCESS_MODE_OWNER :
return "owner"
default :
return "none"
}
}
// ParseAccessMode returns corresponding access mode to given permission string.
func ParseAccessMode ( permission string ) AccessMode {
switch permission {
case "write" :
return ACCESS_MODE_WRITE
case "admin" :
return ACCESS_MODE_ADMIN
default :
return ACCESS_MODE_READ
}
}
2015-02-05 16:29:08 +03:00
// Access represents the highest access level of a user to the repository. The only access type
// that is not in this table is the real owner of a repository. In case of an organization
// repository, the members of the owners team are in this table.
type Access struct {
ID int64 ` xorm:"pk autoincr" `
UserID int64 ` xorm:"UNIQUE(s)" `
RepoID int64 ` xorm:"UNIQUE(s)" `
Mode AccessMode
2014-02-17 19:57:23 +04:00
}
2015-02-23 10:15:53 +03:00
func accessLevel ( e Engine , u * User , repo * Repository ) ( AccessMode , error ) {
2015-02-09 14:36:33 +03:00
mode := ACCESS_MODE_NONE
2015-02-23 10:15:53 +03:00
if ! repo . IsPrivate {
2015-02-09 14:36:33 +03:00
mode = ACCESS_MODE_READ
2015-02-12 05:58:37 +03:00
}
2014-05-01 19:32:12 +04:00
2015-11-19 19:40:00 +03:00
if u == nil {
return mode , nil
}
2014-04-05 02:55:17 +04:00
2016-07-23 20:08:22 +03:00
if u . ID == repo . OwnerID {
2015-11-19 19:40:00 +03:00
return ACCESS_MODE_OWNER , nil
2014-04-12 05:47:39 +04:00
}
2015-02-05 16:29:08 +03:00
2016-07-23 20:08:22 +03:00
a := & Access { UserID : u . ID , RepoID : repo . ID }
2015-11-19 19:40:00 +03:00
if has , err := e . Get ( a ) ; ! has || err != nil {
return mode , err
}
return a . Mode , nil
2014-02-17 19:57:23 +04:00
}
2015-01-23 10:54:16 +03:00
2015-02-23 10:15:53 +03:00
// AccessLevel returns the Access a user has to a repository. Will return NoneAccess if the
// user does not have access. User can be nil!
func AccessLevel ( u * User , repo * Repository ) ( AccessMode , error ) {
return accessLevel ( x , u , repo )
}
func hasAccess ( e Engine , u * User , repo * Repository , testMode AccessMode ) ( bool , error ) {
mode , err := accessLevel ( e , u , repo )
2015-02-13 08:58:46 +03:00
return testMode <= mode , err
}
2015-02-23 10:15:53 +03:00
// HasAccess returns true if someone has the request access level. User can be nil!
func HasAccess ( u * User , repo * Repository , testMode AccessMode ) ( bool , error ) {
return hasAccess ( x , u , repo , testMode )
}
2015-11-14 01:37:02 +03:00
// GetRepositoryAccesses finds all repositories with their access mode where a user has access but does not own.
func ( u * User ) GetRepositoryAccesses ( ) ( map [ * Repository ] AccessMode , error ) {
2015-01-23 10:54:16 +03:00
accesses := make ( [ ] * Access , 0 , 10 )
2016-07-23 20:08:22 +03:00
if err := x . Find ( & accesses , & Access { UserID : u . ID } ) ; err != nil {
2015-01-23 10:54:16 +03:00
return nil , err
}
2015-02-05 16:29:08 +03:00
repos := make ( map [ * Repository ] AccessMode , len ( accesses ) )
2015-01-23 10:54:16 +03:00
for _ , access := range accesses {
2015-08-08 17:43:14 +03:00
repo , err := GetRepositoryByID ( access . RepoID )
2015-01-23 10:54:16 +03:00
if err != nil {
2015-03-16 11:04:27 +03:00
if IsErrRepoNotExist ( err ) {
2015-11-14 01:37:02 +03:00
log . Error ( 4 , "GetRepositoryByID: %v" , err )
2015-03-16 11:04:27 +03:00
continue
}
2015-01-23 10:54:16 +03:00
return nil , err
}
2015-02-12 05:58:37 +03:00
if err = repo . GetOwner ( ) ; err != nil {
2015-02-04 17:08:55 +03:00
return nil , err
2016-07-23 20:08:22 +03:00
} else if repo . OwnerID == u . ID {
2015-02-12 05:58:37 +03:00
continue
2015-02-04 17:08:55 +03:00
}
2015-01-23 10:54:16 +03:00
repos [ repo ] = access . Mode
}
return repos , nil
}
2015-02-05 16:29:08 +03:00
2016-07-24 09:32:46 +03:00
// GetAccessibleRepositories finds repositories which the user has access but does not own.
// If limit is smaller than 1 means returns all found results.
func ( user * User ) GetAccessibleRepositories ( limit int ) ( repos [ ] * Repository , _ error ) {
sess := x . Where ( "owner_id !=? " , user . ID ) . Desc ( "updated_unix" )
if limit > 0 {
sess . Limit ( limit )
repos = make ( [ ] * Repository , 0 , limit )
} else {
repos = make ( [ ] * Repository , 0 , 10 )
2015-11-14 01:37:02 +03:00
}
2016-07-24 09:32:46 +03:00
return repos , sess . Join ( "INNER" , "access" , "access.user_id = ? AND access.repo_id = repository.id" , user . ID ) . Find ( & repos )
2015-11-14 01:37:02 +03:00
}
2015-02-13 08:58:46 +03:00
func maxAccessMode ( modes ... AccessMode ) AccessMode {
max := ACCESS_MODE_NONE
for _ , mode := range modes {
if mode > max {
max = mode
}
}
return max
}
2015-03-01 05:44:09 +03:00
// FIXME: do corss-comparison so reduce deletions and additions to the minimum?
func ( repo * Repository ) refreshAccesses ( e Engine , accessMap map [ int64 ] AccessMode ) ( err error ) {
minMode := ACCESS_MODE_READ
if ! repo . IsPrivate {
minMode = ACCESS_MODE_WRITE
}
newAccesses := make ( [ ] Access , 0 , len ( accessMap ) )
for userID , mode := range accessMap {
if mode < minMode {
continue
}
newAccesses = append ( newAccesses , Access {
UserID : userID ,
2015-08-08 17:43:14 +03:00
RepoID : repo . ID ,
2015-03-01 05:44:09 +03:00
Mode : mode ,
} )
}
2015-02-13 10:56:42 +03:00
2015-03-01 05:44:09 +03:00
// Delete old accesses and insert new ones for repository.
2015-08-08 17:43:14 +03:00
if _ , err = e . Delete ( & Access { RepoID : repo . ID } ) ; err != nil {
2015-03-01 05:44:09 +03:00
return fmt . Errorf ( "delete old accesses: %v" , err )
} else if _ , err = e . Insert ( newAccesses ) ; err != nil {
return fmt . Errorf ( "insert new accesses: %v" , err )
}
2015-02-13 10:56:42 +03:00
return nil
}
2016-03-06 02:08:42 +03:00
// refreshCollaboratorAccesses retrieves repository collaborations with their access modes.
2015-03-01 05:44:09 +03:00
func ( repo * Repository ) refreshCollaboratorAccesses ( e Engine , accessMap map [ int64 ] AccessMode ) error {
2016-03-06 02:08:42 +03:00
collaborations , err := repo . getCollaborations ( e )
2015-02-05 16:29:08 +03:00
if err != nil {
2016-03-06 02:08:42 +03:00
return fmt . Errorf ( "getCollaborations: %v" , err )
2015-02-05 16:29:08 +03:00
}
2016-03-06 02:08:42 +03:00
for _ , c := range collaborations {
accessMap [ c . UserID ] = c . Mode
2015-02-05 16:29:08 +03:00
}
2015-03-01 05:44:09 +03:00
return nil
}
// recalculateTeamAccesses recalculates new accesses for teams of an organization
// except the team whose ID is given. It is used to assign a team ID when
// remove repository from that team.
func ( repo * Repository ) recalculateTeamAccesses ( e Engine , ignTeamID int64 ) ( err error ) {
accessMap := make ( map [ int64 ] AccessMode , 20 )
if err = repo . getOwner ( e ) ; err != nil {
2015-02-05 16:29:08 +03:00
return err
2015-08-28 08:51:15 +03:00
} else if ! repo . Owner . IsOrganization ( ) {
return fmt . Errorf ( "owner is not an organization: %d" , repo . OwnerID )
2015-02-05 16:29:08 +03:00
}
2015-08-28 08:51:15 +03:00
2015-07-24 11:52:01 +03:00
if err = repo . refreshCollaboratorAccesses ( e , accessMap ) ; err != nil {
return fmt . Errorf ( "refreshCollaboratorAccesses: %v" , err )
}
2015-02-05 16:29:08 +03:00
2015-08-28 08:51:15 +03:00
if err = repo . Owner . getTeams ( e ) ; err != nil {
return err
}
2015-03-25 01:14:04 +03:00
2015-08-28 08:51:15 +03:00
for _ , t := range repo . Owner . Teams {
if t . ID == ignTeamID {
continue
}
2015-02-05 16:29:08 +03:00
2015-08-28 08:51:15 +03:00
// Owner team gets owner access, and skip for teams that do not
// have relations with repository.
if t . IsOwnerTeam ( ) {
t . Authorize = ACCESS_MODE_OWNER
} else if ! t . hasRepository ( e , repo . ID ) {
continue
}
if err = t . getMembers ( e ) ; err != nil {
return fmt . Errorf ( "getMembers '%d': %v" , t . ID , err )
}
for _ , m := range t . Members {
2016-07-23 20:08:22 +03:00
accessMap [ m . ID ] = maxAccessMode ( accessMap [ m . ID ] , t . Authorize )
2015-02-05 16:29:08 +03:00
}
}
2015-03-01 05:44:09 +03:00
return repo . refreshAccesses ( e , accessMap )
}
2015-02-05 16:29:08 +03:00
2015-03-01 05:44:09 +03:00
func ( repo * Repository ) recalculateAccesses ( e Engine ) error {
2015-08-28 08:51:15 +03:00
if repo . Owner . IsOrganization ( ) {
return repo . recalculateTeamAccesses ( e , 0 )
}
2015-03-01 05:44:09 +03:00
accessMap := make ( map [ int64 ] AccessMode , 20 )
if err := repo . refreshCollaboratorAccesses ( e , accessMap ) ; err != nil {
return fmt . Errorf ( "refreshCollaboratorAccesses: %v" , err )
2015-02-05 16:29:08 +03:00
}
2015-03-01 05:44:09 +03:00
return repo . refreshAccesses ( e , accessMap )
2015-02-13 08:58:46 +03:00
}
2015-02-05 16:29:08 +03:00
2015-02-13 08:58:46 +03:00
// RecalculateAccesses recalculates all accesses for repository.
func ( r * Repository ) RecalculateAccesses ( ) error {
return r . recalculateAccesses ( x )
2015-02-05 16:29:08 +03:00
}