added rbac for viewing objects
[plstackapi.git] / planetstack / core / models / site.py
1 import os
2 from django.db import models
3 from core.models import PlCoreBase
4 #from core.models import Deployment
5 from core.models import Tag
6 from django.contrib.contenttypes import generic
7 from geoposition.fields import GeopositionField
8
9 class Site(PlCoreBase):
10     """
11         A logical grouping of Nodes that are co-located at the same geographic location, which also typically corresponds to the Nodes' location in the physical network.
12     """
13     tenant_id = models.CharField(null=True, blank=True, max_length=200, help_text="Keystone tenant id")
14     name = models.CharField(max_length=200, help_text="Name for this Site")
15     site_url = models.URLField(null=True, blank=True, max_length=512, help_text="Site's Home URL Page")
16     enabled = models.BooleanField(default=True, help_text="Status for this Site")
17     location = GeopositionField()
18     longitude = models.FloatField(null=True, blank=True)
19     latitude = models.FloatField(null=True, blank=True)
20     login_base = models.CharField(max_length=50, unique=True, help_text="Prefix for Slices associated with this Site")
21     is_public = models.BooleanField(default=True, help_text="Indicates the visibility of this site to other members")
22     abbreviated_name = models.CharField(max_length=80)
23
24     deployments = models.ManyToManyField('Deployment', blank=True, related_name='sites')
25     #deployments = models.ManyToManyField('Deployment', through='SiteDeployments', blank=True)
26     tags = generic.GenericRelation(Tag)
27
28     def __unicode__(self):  return u'%s' % (self.name)
29
30     def can_update(self, user):
31         if user.is_admin:
32             return True
33         site_privs = SitePrivilege.objects.filter(user=user, site=self)
34         for site_priv in site_privs:
35             if site_priv.role.role_type == 'pi':
36                 return True
37         return False 
38
39     def save_by_user(self, user, *args, **kwds):
40         if self.can_update(user):
41             super(Site, self).save(*args, **kwds)
42
43     @staticmethod
44     def select_by_user(user):
45         if user.is_admin:
46             qs = Site.objects.all()
47         else:
48             site_ids = [sp.site.id for sp in SitePrivilege.objects.filter(user=user)]
49             site_ids.append(user.site.id)
50             qs = Site.objects.filter(id__in=site_ids)
51         return qs
52
53
54 class SiteRole(PlCoreBase):
55
56     ROLE_CHOICES = (('admin','Admin'),('pi','PI'),('tech','Tech'),('billing','Billing'))
57     role = models.CharField(choices=ROLE_CHOICES, unique=True, max_length=30)
58
59     def __unicode__(self):  return u'%s' % (self.role)
60
61 class SitePrivilege(PlCoreBase):
62
63     user = models.ForeignKey('User', related_name='site_privileges')
64     site = models.ForeignKey('Site', related_name='site_privileges')
65     role = models.ForeignKey('SiteRole')
66
67     def __unicode__(self):  return u'%s %s %s' % (self.site, self.user, self.role)
68
69     def save(self, *args, **kwds):
70         super(SitePrivilege, self).save(*args, **kwds)
71
72     def delete(self, *args, **kwds):
73         super(SitePrivilege, self).delete(*args, **kwds)
74
75     def can_update(self, user):
76         if user.is_admin:
77             return True
78         site_privs = SitePrivilege.objects.filter(user=user, site=self)
79         for site_priv in site_privs:
80             if site_priv.role.role_type == 'pi':
81                 return True
82         return False 
83
84     def save_by_user(self, user, *args, **kwds):
85         if self.can_update(user):
86             super(SitePrivilege, self).save(*args, **kwds)
87
88     @staticmethod
89     def select_by_user(user):
90         if user.is_admin:
91             qs = SitePrivilege.objects.all()
92         else:
93             sp_ids = [sp.id for sp in SitePrivilege.objects.filter(user=user)]
94             qs = SitePrivilege.objects.filter(id__in=sp_ids)
95         return qs
96
97 class Deployment(PlCoreBase):
98     name = models.CharField(max_length=200, unique=True, help_text="Name of the Deployment")
99     #sites = models.ManyToManyField('Site', through='SiteDeployments', blank=True)
100
101     def __unicode__(self):  return u'%s' % (self.name)
102
103
104 class DeploymentRole(PlCoreBase):
105
106     ROLE_CHOICES = (('admin','Admin'),)
107     role = models.CharField(choices=ROLE_CHOICES, unique=True, max_length=30)
108
109     def __unicode__(self):  return u'%s' % (self.role)
110
111 class DeploymentPrivilege(PlCoreBase):
112
113     user = models.ForeignKey('User', related_name='deployment_privileges')
114     deployment = models.ForeignKey('Deployment', related_name='deployment_privileges')
115     role = models.ForeignKey('DeploymentRole')
116
117     def __unicode__(self):  return u'%s %s %s' % (self.deployment, self.user, self.role)
118
119     def can_update(self, user):
120         if user.is_readonly:
121             return False
122         if user.is_admin:
123             return True
124         dprivs = DeploymentPrivilege.objects.filter(user=user)
125         for dpriv in dprivs:
126             if dpriv.role.role_type == 'admin':
127                 return True
128         return False
129
130     def save_by_user(self, user, *args, **kwds):
131         if self.can_update(user):
132             super(DeploymentPrivilege, self).save(*args, **kwds)
133
134     @staticmethod
135     def select_by_user(user):
136         if user.is_admin:
137             qs = DeploymentPrivilege.objects.all()
138         else:
139             dpriv_ids = [dp.id for dp in DeploymentPrivilege.objects.filter(user=user)]
140             qs = DeploymentPrivilege.objects.filter(id__in=dpriv_ids)
141         return qs 
142
143 class SiteDeployments(PlCoreBase):
144     site = models.ForeignKey(Site)
145     deployment = models.ForeignKey(Deployment)
146
147     class Meta:
148         db_table = 'site_deployments'
149         #auto_created = Site
150