X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=PLC%2FMethods%2FDeleteRoleFromPerson.py;h=009b0b270065a9ae8d6e6c488ecf32238c27fb86;hb=12d17e7f285289f67146404be7bfe8862daf731c;hp=2f0d5793dcd58b1e157563e24f31556b8968a637;hpb=3f30de17c58880c0f6f1d64ea573c3fe56e32a38;p=plcapi.git diff --git a/PLC/Methods/DeleteRoleFromPerson.py b/PLC/Methods/DeleteRoleFromPerson.py index 2f0d579..009b0b2 100644 --- a/PLC/Methods/DeleteRoleFromPerson.py +++ b/PLC/Methods/DeleteRoleFromPerson.py @@ -27,31 +27,23 @@ class DeleteRoleFromPerson(Method): returns = Parameter(int, '1 if successful') - event_type = 'DeleteFrom' - object_type = 'Person' def call(self, auth, role_id_or_name, person_id_or_email): - # Get all roles - roles = {} - for role in Roles(self.api): - roles[role['role_id']] = role['name'] - roles[role['name']] = role['role_id'] - - if role_id_or_name not in roles: - raise PLCInvalidArgument, "Invalid role identifier or name" - - if isinstance(role_id_or_name, int): - role_id = role_id_or_name - else: - role_id = roles[role_id_or_name] + # Get role + roles = Roles(self.api, [role_id_or_name]) + if not roles: + raise PLCInvalidArgument, "Invalid role '%s'" % unicode(role_id_or_name) + role = roles[0] # Get account information persons = Persons(self.api, [person_id_or_email]) if not persons: raise PLCInvalidArgument, "No such account" - person = persons[0] + if person['peer_id'] is not None: + raise PLCInvalidArgument, "Not a local account" + # Authenticated function assert self.caller is not None @@ -61,12 +53,15 @@ class DeleteRoleFromPerson(Method): # Can only revoke lesser (higher) roles from others if 'admin' not in self.caller['roles'] and \ - role_id <= min(self.caller['role_ids']): + role['role_id'] <= min(self.caller['role_ids']): raise PLCPermissionDenied, "Not allowed to revoke that role" - if role_id in person['role_ids']: - person.remove_role(role_id) + if role['role_id'] in person['role_ids']: + person.remove_role(role) + # Logging variables self.object_ids = [person['person_id']] + self.message = "Role %d revoked from person %d" % \ + (role['role_id'], person['person_id']) return 1