accepts = [
Parameter(str, "Credential string"),
- Parameter(dict, "Record dictionary containing record fields")
+ Parameter(dict, "Record dictionary containing record fields"),
+ Mixed(Parameter(str, "Request hash"),
+ Parameter(None, "Request hash not specified"))
]
returns = Parameter(int, "String representation of gid object")
- def call(self, cred, record_dict, caller_cred=None):
+ def call(self, cred, record_dict, request_hash=None, origin_hrn=None):
+ # This cred will be an authority cred, not a user, so we cant use it to
+ # authenticate the caller's request_hash. Let just get the caller's gid
+ # from the cred and authenticate using that
+ client_gid = Credential(string=cred).get_gid_caller()
+ client_gid_str = client_gid.save_to_string(save_parents=True)
+ self.api.auth.authenticateGid(client_gid_str, [cred], request_hash)
self.api.auth.check(cred, "register")
- if caller_cred==None:
- caller_cred=cred
+ if origin_hrn==None:
+ origin_hrn=Credential(string=cred).get_gid_caller().get_hrn()
#log the call
- self.api.logger.info("interface: %s\tcaller-hrn: %s\ttarget-hrn: %s\tmethod-name: %s"%(self.api.interface, Credential(string=caller_cred).get_gid_caller().get_hrn(), None, self.name))
+ self.api.logger.info("interface: %s\tcaller-hrn: %s\ttarget-hrn: %s\tmethod-name: %s"%(self.api.interface, origin_hrn, None, self.name))
record = GeniRecord(dict = record_dict)
record['authority'] = get_authority(record['hrn'])
type = record['type']
existing_records = table.find({'type': type, 'hrn': hrn})
if existing_records:
raise ExistingRecord(hrn)
- else:
- # We will update the pointer later
- record['pointer'] = -1
- record.set_pointer(-1)
- record_id = table.insert(record)
- record['record_id'] = record_id
if type in ["authority"]:
# update the tree
pointer = sites[0]['site_id']
record.set_pointer(pointer)
+ record['pointer'] = pointer
elif (type == "slice"):
pl_record = self.api.geni_fields_to_pl_fields(type, hrn, record)
else:
pointer = slices[0]['slice_id']
record.set_pointer(pointer)
+ record['pointer'] = pointer
elif (type == "user"):
persons = self.api.plshell.GetPersons(self.api.plauth, [record['email']])
if not persons:
pointer = self.api.plshell.AddPerson(self.api.plauth, dict(record))
else:
- pointer = persons[0]['person_id']
+ raise ExistingRecord(record['email'])
if 'enabled' in record and record['enabled']:
self.api.plshell.UpdatePerson(self.api.plauth, pointer, {'enabled': record['enabled']})
# add this persons to the site only if he is being added for the first
# time by sfa and doesont already exist in plc
if not persons or not persons[0]['site_ids']:
- login_base = get_leaf(auth_name)
+ login_base = get_leaf(record['authority'])
self.api.plshell.AddPersonToSite(self.api.plauth, pointer, login_base)
# What roles should this user have?
self.api.plshell.AddRoleToPerson(self.api.plauth, 'user', pointer)
record.set_pointer(pointer)
+ record['pointer'] = pointer
# Add the user's key
if pub_key:
self.api.plshell.AddPersonKey(self.api.plauth, pointer, {'key_type' : 'ssh', 'key' : pub_key})
elif (type == "node"):
pl_record = self.api.geni_fields_to_pl_fields(type, hrn, record)
- login_base = hrn_to_pl_login_base(auth_name)
+ login_base = hrn_to_pl_login_base(record['authority'])
nodes = self.api.plshell.GetNodes(self.api.plauth, [pl_record['hostname']])
if not nodes:
pointer = self.api.plshell.AddNode(self.api.plauth, login_base, pl_record)
else:
pointer = nodes[0]['node_id']
+ record['pointer'] = pointer
record.set_pointer(pointer)
else:
raise UnknownGeniType(type)
- table.update(record)
+ record_id = table.insert(record)
+ record['record_id'] = record_id
# update membership for researchers, pis, owners, operators
self.api.update_membership(None, record)