class DeleteRoleFromPerson(Method):
"""
Deletes the specified role from the person.
-
+
PIs can only revoke the tech and user roles from users and techs
at their sites. ins can revoke any role from any user.
returns = Parameter(int, '1 if successful')
def call(self, auth, role_id_or_name, person_id_or_email):
- # Get all roles
- roles = {}
- for role in Roles(self.api):
- roles[role['role_id']] = role['name']
- roles[role['name']] = role['role_id']
-
- if role_id_or_name not in roles:
- raise PLCInvalidArgument, "Invalid role identifier or name"
-
- if isinstance(role_id_or_name, int):
- role_id = role_id_or_name
- else:
- role_id = roles[role_id_or_name]
+ # Get role
+ roles = Roles(self.api, [role_id_or_name])
+ if not roles:
+ raise PLCInvalidArgument("Invalid role '%s'" % str(role_id_or_name))
+ role = roles[0]
# Get account information
persons = Persons(self.api, [person_id_or_email])
if not persons:
- raise PLCInvalidArgument, "No such account"
-
+ raise PLCInvalidArgument("No such account")
person = persons[0]
+ if person['peer_id'] is not None:
+ raise PLCInvalidArgument("Not a local account")
+
# Authenticated function
assert self.caller is not None
# Check if we can update this account
if not self.caller.can_update(person):
- raise PLCPermissionDenied, "Not allowed to update specified account"
+ raise PLCPermissionDenied("Not allowed to update specified account")
# Can only revoke lesser (higher) roles from others
if 'admin' not in self.caller['roles'] and \
- role_id <= min(self.caller['role_ids']):
- raise PLCPermissionDenied, "Not allowed to revoke that role"
+ role['role_id'] <= min(self.caller['role_ids']):
+ raise PLCPermissionDenied("Not allowed to revoke that role")
+
+ if role['role_id'] in person['role_ids']:
+ person.remove_role(role)
- if role_id in person['role_ids']:
- person.remove_role(role_id)
+ # Logging variables
+ self.event_objects = {'Person': [person['person_id']],
+ 'Role': [role['role_id']]}
+ self.message = "Role %d revoked from person %d" % \
+ (role['role_id'], person['person_id'])
return 1