Adding 'is_searchable' status for tables which should be full-text searchable.
[arvados.git] / services / api / app / models / authorized_key.rb
index b454ba3ca71fc0e044027b7fd1fc2e71847771bd..a6bc06593a58d15cfa0ae854669613650666424f 100644 (file)
@@ -2,18 +2,22 @@ class AuthorizedKey < ArvadosModel
   include AssignUuid
   include KindAndEtag
   include CommonApiTemplate
-  before_create :permission_to_set_authorized_user
-  before_update :permission_to_set_authorized_user
+  before_create :permission_to_set_authorized_user_uuid
+  before_update :permission_to_set_authorized_user_uuid
 
-  api_accessible :superuser, :extend => :common do |t|
+  belongs_to :authorized_user, :foreign_key => :authorized_user_uuid, :class_name => 'User', :primary_key => :uuid
+
+  validate :public_key_must_be_unique
+
+  api_accessible :user, extend: :common do |t|
     t.add :name
     t.add :key_type
-    t.add :authorized_user
+    t.add :authorized_user_uuid
     t.add :public_key
     t.add :expires_at
   end
 
-  def permission_to_set_authorized_user
+  def permission_to_set_authorized_user_uuid
     # Anonymous users cannot do anything here
     return false if !current_user
 
@@ -21,9 +25,26 @@ class AuthorizedKey < ArvadosModel
     return true if current_user.is_admin
 
     # All users can attach keys to their own accounts
-    return true if current_user.uuid == authorized_user
+    return true if current_user.uuid == authorized_user_uuid
 
     # Default = deny.
     false
   end
+
+  def public_key_must_be_unique
+    if self.public_key
+      key = /^ssh-(rsa|dss) [A-Za-z0-9+\/=\+]+\b/.match(self.public_key)
+      
+      if not key
+        errors.add(:public_key, "does not appear to be a valid ssh-rsa or dsa public key")
+      else
+        # Valid if no other rows have this public key
+        if self.class.where('public_key like ?', "%#{key[0]}%").any?
+          errors.add(:public_key, "already exists in the database, use a different key.")
+          return false
+        end
+      end
+    end
+    return true
+  end
 end