X-Git-Url: https://git.arvados.org/arvados.git/blobdiff_plain/a3787ef83a0538097fb6f802f675be740a241ebc..c0818b26246432407b8cd76a887dd61a7e824cd0:/apps/workbench/app/controllers/users_controller.rb diff --git a/apps/workbench/app/controllers/users_controller.rb b/apps/workbench/app/controllers/users_controller.rb index 86e982368c..d657f92603 100644 --- a/apps/workbench/app/controllers/users_controller.rb +++ b/apps/workbench/app/controllers/users_controller.rb @@ -35,7 +35,7 @@ class UsersController < ApplicationController def activity @breadcrumb_page_name = nil - @users = User.limit(params[:limit] || 1000).all + @users = User.limit(params[:limit]) @user_activity = {} @activity = { logins: {}, @@ -52,15 +52,15 @@ class UsersController < ApplicationController 1.month.ago.beginning_of_month, Time.now.beginning_of_month]] @spans.each do |span, threshold_start, threshold_end| - @activity[:logins][span] = Log. + @activity[:logins][span] = Log.select(%w(uuid modified_by_user_uuid)). filter([[:event_type, '=', 'login'], [:object_kind, '=', 'arvados#user'], [:created_at, '>=', threshold_start], [:created_at, '<', threshold_end]]) - @activity[:jobs][span] = Job. + @activity[:jobs][span] = Job.select(%w(uuid modified_by_user_uuid)). filter([[:created_at, '>=', threshold_start], [:created_at, '<', threshold_end]]) - @activity[:pipeline_instances][span] = PipelineInstance. + @activity[:pipeline_instances][span] = PipelineInstance.select(%w(uuid modified_by_user_uuid)). filter([[:created_at, '>=', threshold_start], [:created_at, '<', threshold_end]]) @activity.each do |type, act| @@ -88,7 +88,7 @@ class UsersController < ApplicationController def storage @breadcrumb_page_name = nil - @users = User.limit(params[:limit] || 1000).all + @users = User.limit(params[:limit]) @user_storage = {} total_storage = {} @log_date = {} @@ -139,7 +139,6 @@ class UsersController < ApplicationController end def home - @showallalerts = false @my_ssh_keys = AuthorizedKey.where(authorized_user_uuid: current_user.uuid) @my_tag_links = {} @@ -159,7 +158,7 @@ class UsersController < ApplicationController @persist_state[uuid] = 'cache' end - Link.limit(1000).filter([['head_uuid', 'in', collection_uuids], + Link.filter([['head_uuid', 'in', collection_uuids], ['link_class', 'in', ['tag', 'resources']]]). each do |link| case link.link_class @@ -213,6 +212,22 @@ class UsersController < ApplicationController end if User.setup setup_params + if params[:groups] + new_groups = params[:groups].split(',').map(&:strip).compact.select{|i| !i.to_s.empty?} + can_login_perms = Link.where(tail_uuid: params[:user_email], + head_kind: 'arvados#user', + link_class: 'permission', + name: 'can_login') + if can_login_perms.any? + perm = can_login_perms.first + props = perm.properties + if new_groups != props[:groups] + props[:groups] = new_groups + perm.save! + end + end + end + format.js else self.render_error status: 422 @@ -241,14 +256,25 @@ class UsersController < ApplicationController ['tail_uuid', '=', current_user.uuid], ['link_class', '=', 'permission'], ]) - @my_repositories = Repository.where uuid: repo_links.collect(&:head_uuid) + + owned_repositories = Repository.where(owner_uuid: current_user.uuid) + + @my_repositories = (Repository.where(uuid: repo_links.collect(&:head_uuid)) | + owned_repositories). + uniq { |repo| repo.uuid } + + @repo_writable = {} repo_links.each do |link| if link.name.in? ['can_write', 'can_manage'] - @repo_writable[link.head_uuid] = true + @repo_writable[link.head_uuid] = link.name end end + owned_repositories.each do |repo| + @repo_writable[repo.uuid] = 'can_manage' + end + # virtual machines the current user can login into @my_vm_logins = {} Link.where(tail_uuid: current_user.uuid, @@ -303,6 +329,12 @@ class UsersController < ApplicationController end end + def request_shell_access + logger.warn "request_access: #{params.inspect}" + params['request_url'] = request.url + RequestShellAccessReporter.send_request(current_user, params).deliver + end + protected def find_current_links user @@ -313,14 +345,15 @@ class UsersController < ApplicationController end # oid login perm - oid_login_perms = Link.where(tail_uuid: user.email, + can_login_perms = Link.where(tail_uuid: user.email, head_kind: 'arvados#user', link_class: 'permission', name: 'can_login') - if oid_login_perms.any? - prefix_properties = oid_login_perms.first.properties - current_selections[:identity_url_prefix] = prefix_properties[:identity_url_prefix] + if can_login_perms.any? + perm_properties = can_login_perms.first.properties + current_selections[:identity_url_prefix] = perm_properties[:identity_url_prefix] + current_selections[:groups] = perm_properties[:groups].andand.join(', ') end # repo perm