role based filtering for keys
[plstackapi.git] / plstackapi / core / models / pluser.py
1 import os
2 import datetime
3 from collections import defaultdict
4 from django.db import models
5 from plstackapi.core.models import PlCoreBase
6 from plstackapi.core.models import Site
7 from plstackapi.openstack.manager import OpenStackManager
8 from django.contrib.auth.models import User, AbstractBaseUser, UserManager, BaseUserManager
9
10 # Create your models here.
11
12 class PLUserManager(BaseUserManager):
13     def create_user(self, email, firstname, lastname, password=None):
14         """
15         Creates and saves a User with the given email, date of
16         birth and password.
17         """
18         if not email:
19             raise ValueError('Users must have an email address')
20
21         user = self.model(
22             email=PLUserManager.normalize_email(email),
23             firstname=firstname,
24             lastname=lastname,
25             password=password
26         )
27         #user.set_password(password)
28         user.is_admin = True
29         user.save(using=self._db)
30         return user
31
32     def create_superuser(self, email, firstname, lastname, password):
33         """
34         Creates and saves a superuser with the given email, date of
35         birth and password.
36         """
37         user = self.create_user(email,
38             password=password,
39             firstname=firstname,
40             lastname=lastname
41         )
42         user.is_admin = True
43         user.save(using=self._db)
44         return user
45
46
47 class PLUser(AbstractBaseUser):
48
49     class Meta:
50         app_label = "core"
51
52     email = models.EmailField(
53         verbose_name='email address',
54         max_length=255,
55         unique=True,
56         db_index=True,
57     )
58
59     user_id = models.CharField(null=True, blank=True, help_text="keystone user id", max_length=200) 
60     firstname = models.CharField(help_text="person's given name", max_length=200)
61     lastname = models.CharField(help_text="person's surname", max_length=200)
62
63     phone = models.CharField(null=True, blank=True, help_text="phone number contact", max_length=100)
64     user_url = models.URLField(null=True, blank=True)
65     site = models.ForeignKey(Site, related_name='users', verbose_name="Site this user will be homed too", null=True)
66
67     is_active = models.BooleanField(default=True)
68     is_admin = models.BooleanField(default=False)
69     is_staff = models.BooleanField(default=True)
70
71     objects = PLUserManager()
72
73     USERNAME_FIELD = 'email'
74     REQUIRED_FIELDS = ['firstname', 'lastname']
75
76     def get_full_name(self):
77         # The user is identified by their email address
78         return self.email
79
80     def get_short_name(self):
81         # The user is identified by their email address
82         return self.email
83
84     def __unicode__(self):
85         return self.email
86
87     def has_perm(self, perm, obj=None):
88         "Does the user have a specific permission?"
89         # Simplest possible answer: Yes, always
90         return True
91
92     def has_module_perms(self, app_label):
93         "Does the user have permissions to view the app `app_label`?"
94         # Simplest possible answer: Yes, always
95         return True
96
97     def get_roles(self):
98         from plstackapi.core.models.site import SitePrivilege
99         from plstackapi.core.models.slice import SliceMembership
100
101         site_privileges = SitePrivilege.objects.filter(user=self)
102         slice_memberships = SliceMembership.objects.filter(user=self)
103         roles = defaultdict(list)
104         for site_privilege in site_privileges:
105             roles[site_privilege.site.login_base].append(site_privilege.role.role_type)
106         for slice_membership in slice_memberships:
107             roles[slice_membership.slice.name].append(slice_membership.role.role_type)
108         return roles   
109
110     def save(self, *args, **kwds):
111         if not hasattr(self, 'os_manager'):
112             setattr(self, 'os_manager', OpenStackManager())
113
114         self.os_manager.save_user(self)
115         if not self.id:
116             self.set_password(self.password)    
117         super(PLUser, self).save(*args, **kwds)   
118
119     def delete(self, *args, **kwds):
120         if not hasattr(self, 'os_manager'):
121             setattr(self, 'os_manager', OpenStackManager())
122
123         self.os_manager.delete_user(self)
124         super(PLUser, self).delete(*args, **kwds)