1 # Copyright (C) The Arvados Authors. All rights reserved.
3 # SPDX-License-Identifier: AGPL-3.0
7 class Log < ArvadosModel
10 include CommonApiTemplate
11 serialize :properties, Hash
12 before_validation :set_default_event_at
13 after_save :send_notify
14 after_commit { AuditLogs.tidy_in_background }
16 api_accessible :user, extend: :common do |t|
19 t.add :object_owner_uuid
28 if k = ArvadosModel::resource_class_for_uuid(object_uuid)
33 def fill_object(thing)
34 self.object_uuid ||= thing.uuid
35 if respond_to? :object_owner_uuid=
36 # Skip this if the object_owner_uuid migration hasn't happened
37 # yet, i.e., we're in the process of migrating an old database.
38 self.object_owner_uuid = thing.owner_uuid
40 self.summary ||= "#{self.event_type} of #{thing.uuid}"
44 def fill_properties(age, etag_prop, attrs_prop)
45 self.properties.merge!({"#{age}_etag" => etag_prop,
46 "#{age}_attributes" => attrs_prop})
50 fill_properties('new', thing.andand.etag, thing.andand.logged_attributes)
53 self.event_at = thing.created_at
55 self.event_at = thing.modified_at
57 self.event_at = db_current_time
62 def self.readable_by(*users_list)
63 if users_list.select { |u| u.is_admin }.any?
66 user_uuids = users_list.map { |u| u.uuid }
67 uuid_list = user_uuids + users_list.flat_map { |u| u.groups_i_can(:read) }
69 permitted = "(SELECT head_uuid FROM links WHERE link_class='permission' AND tail_uuid IN (:uuids))"
70 joins("LEFT JOIN container_requests ON container_requests.container_uuid=logs.object_uuid").
71 where("logs.object_uuid IN #{permitted} OR "+
72 "container_requests.uuid IN (:uuids) OR "+
73 "container_requests.owner_uuid IN (:uuids) OR "+
74 "logs.object_uuid IN (:uuids) OR "+
75 "logs.owner_uuid IN (:uuids) OR "+
76 "logs.object_owner_uuid IN (:uuids)",
82 def permission_to_create
86 def permission_to_update
87 current_user.andand.is_admin
90 alias_method :permission_to_delete, :permission_to_update
92 def set_default_event_at
93 self.event_at ||= db_current_time
97 # don't log start state on logs
100 def log_change(event_type)
101 # Don't log changes to logs.
104 def ensure_valid_uuids
105 # logs can have references to deleted objects
109 ActiveRecord::Base.connection.execute "NOTIFY logs, '#{self.id}'"