MCPcopy Create free account
hub / github.com/Keeper-Security/Commander / _default_acl

Method _default_acl

keepercommander/discovery_common/process.py:305–356  ·  view source on GitHub ↗
(self,
                     discovery_vertex: DAGVertex,
                     content: DiscoveryObject,
                     discovery_parent_vertex: DAGVertex)

Source from the content-addressed store, hash-verified

303 return content
304
305 def _default_acl(self,
306 discovery_vertex: DAGVertex,
307 content: DiscoveryObject,
308 discovery_parent_vertex: DAGVertex) -> UserAcl:
309 # Check to see if this user already belongs to another record vertex, or belongs to this one.
310 belongs_to = False
311 is_admin = False
312 is_iam_user = False
313
314 parent_content = DiscoveryObject.get_discovery_object(discovery_parent_vertex)
315
316 # User record the already exists.
317 # This means the vertex has a record UID, doesn't mean it exists in the vault.
318 # It may have been added during this processing.
319 if content.record_exists is False:
320 belongs_to = True
321
322 # Is this user the admin for the resource?
323 if parent_content.access_user is not None:
324 # If this user record's user matches the user that was used to log into the parent resource,
325 # then this user is the admin for the parent resource.
326 if parent_content.access_user.user == content.item.user:
327 is_admin = True
328
329 # User record does not exist.
330 else:
331 belongs_to_record_vertex = self.record_link.acl_has_belong_to_vertex(discovery_vertex)
332
333 # If the user doesn't belong to any other vertex, it will be long the parent resource.
334 if belongs_to_record_vertex is None:
335 self.logger.debug(" user vertex does not belong to another resource vertex")
336 belongs_to = True
337
338 else:
339 parent_record_vertex = self.record_link.get_record_uid(discovery_parent_vertex)
340 if parent_record_vertex is not None:
341 if belongs_to_record_vertex == parent_record_vertex:
342 self.logger.debug(" user vertex already belongs to the parent resource vertex")
343 belongs_to = True
344 else:
345 self.logger.debug(" user vertex does not belong to any other resource vertex")
346
347 # If the parent resource is a provider, then this user is an IAM user.
348 if parent_content.object_type_value == "providers":
349 is_iam_user = True
350
351 acl = UserAcl.default()
352 acl.belongs_to = belongs_to
353 acl.is_admin = is_admin
354 acl.is_iam_user = is_iam_user
355
356 return acl
357
358 def _directory_exists(self, domain: str, directory_info_func: Callable, context: Any) -> Optional[DirectoryResult]:
359

Callers 2

_process_levelMethod · 0.95

Calls 5

get_discovery_objectMethod · 0.80
defaultMethod · 0.80
debugMethod · 0.45
get_record_uidMethod · 0.45

Tested by

no test coverage detected