X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=api.py;h=6baaf3e0953d1a0fcc0bd684f07bbe211e392126;hb=dd5d1e422d6ee5dd8a9986ab3506be27c9c88280;hp=6484f48a7a5c014a1ea0118ac26ff6b5d6ca60a3;hpb=d99180f837ae3fcd754a5cdc0a17a9efbe16a2fe;p=nodemanager.git diff --git a/api.py b/api.py index 6484f48..6baaf3e 100644 --- a/api.py +++ b/api.py @@ -21,6 +21,7 @@ import xmlrpclib import accounts import database import logger +import sliver_vs import ticket import tools @@ -49,13 +50,26 @@ def Help(): @export_to_api(1) def Ticket(tkt): """Ticket(tkt): deliver a ticket""" - succeeded = False - if type(tkt) == str: + try: data = ticket.verify(tkt) if data != None: deliver_ticket(data) - succeeded = True - if not succeeded: raise xmlrpclib.Fault(102, 'Invalid argument: the sole argument must be a valid ticket as returned from GetTicket().') + except Exception, err: + raise xmlrpclib.Fault(102, 'Ticket error: ' + str(err)) + +@export_to_api(0) +def GetXIDs(): + """GetXIDs(): return an dictionary mapping slice names to XIDs""" + return dict([(pwent[0], pwent[2]) for pwent in pwd.getpwall() if pwent[6] == sliver_vs.Sliver_VS.SHELL]) + +@export_to_api(0) +def GetSSHKeys(): + """GetSSHKeys(): return an dictionary mapping slice names to SSH keys""" + keydict = {} + for rec in database.db.itervalues(): + if 'keys' in rec: + keydict[rec['name']] = rec['keys'] + return keydict @export_to_api(1) def Create(rec): @@ -129,11 +143,11 @@ class APIRequestHandler(SimpleXMLRPCServer.SimpleXMLRPCRequestHandler): ucred = self.request.getsockopt(socket.SOL_SOCKET, SO_PEERCRED, sizeof_struct_ucred) xid = struct.unpack('3i', ucred)[2] caller_name = pwd.getpwuid(xid)[0] - if method_name not in ('Help', 'Ticket'): + if method_name not in ('Help', 'Ticket', 'GetXIDs', 'GetSSHKeys'): target_name = args[0] target_rec = database.db.get(target_name) if not (target_rec and target_rec['type'].startswith('sliver.')): raise xmlrpclib.Fault(102, 'Invalid argument: the first argument must be a sliver name.') - if not (caller_name in (args[0], 'root') or (caller_name, method_name) in target_rec['delegations']): raise xmlrpclib.Fault(108, 'Permission denied.') + if not (caller_name in (args[0], 'root') or (caller_name, method_name) in target_rec['delegations'] or (caller_name == 'utah_elab_delegate' and target_name.startswith('utah_'))): raise xmlrpclib.Fault(108, 'Permission denied.') result = method(target_rec, *args[1:]) else: result = method(*args) if result == None: result = 1