089 resource_realms isolation next
This commit is contained in:
@@ -9,7 +9,7 @@
|
||||
<cffunction name="post" hint="Запуск выполнения операции">
|
||||
<cfargument name="instanceOperationUid" type="string" required=true hint="type:guid"/>
|
||||
|
||||
<cfset local={}/>
|
||||
<cfset var local={}/>
|
||||
<!--- <cfset local.instanceUid=#createGUID()#/> --->
|
||||
|
||||
<!--- *** Проверить наличие обязательных CFS параметров
|
||||
@@ -40,7 +40,7 @@
|
||||
|
||||
<!---
|
||||
попытаемся проверить, не упала ли операция раньше времени
|
||||
при этом стараемся исключить эффект дребезга - если мы пошлем две команды на выполнение одну за другой, вторая не должна запуститься
|
||||
при этом стараемся исключить эффект дребезга или гонок - если мы пошлем две команды на выполнение одну за другой, вторая не должна запуститься
|
||||
перезапуск операции разрешен, если она зафейлилась либо явно (оркестратор ее пометил таковой) или неявно (джоб упал, не успев отметить операцию стартовавшей)
|
||||
Возможно, эту логику нужно воспроизвести на фронте
|
||||
--->
|
||||
@@ -78,7 +78,9 @@
|
||||
|
||||
<!--- ***** тут должен быть контроль доступа на уровне параметров. Желательно по максимуму параноидальный --->
|
||||
<!--- ***** или при сабмите. Может быть, и на уровне RFS параметров тоже --->
|
||||
<cfset generateRfsParams(arguments.instanceOperationUid, arguments.usrId, arguments.contragentId, arguments.contractId)/>
|
||||
<cfset generateRfsParams(arguments.instanceOperationUid, arguments.usrId, arguments.contragentId, arguments.contractId)/><!--- *** кроме usr_id остальные параметры избыточны - информация есть у инстанса --->
|
||||
|
||||
<cfset checkRfsResourceRealmAccess(arguments.instanceOperationUid)/>
|
||||
|
||||
<!--- **************************** --->
|
||||
<cfset submitJob(arguments.instanceOperationUid)/>
|
||||
@@ -107,7 +109,7 @@
|
||||
<cfargument name="contractId" type="numeric"/>
|
||||
|
||||
<cfquery name="qSvcOperation">
|
||||
select so.svc_operation_id, io.instance_uid, so.operation, r.resource_realm
|
||||
select so.svc_operation_id, io.instance_uid, so.operation, r.resource_realm, io.resource_realm_id
|
||||
from instance_operation io
|
||||
join instance e on (io.instance_uid=e.instance_uid)
|
||||
join svc_operation so on (e.service_id=so.svc_id AND io.operation=so.operation)
|
||||
@@ -118,12 +120,17 @@
|
||||
<cfset setInstanceOperationRfsParam(arguments.instanceOperationUid, "instanceUid", qSvcOperation.instance_uid)/>
|
||||
<cfset setInstanceOperationRfsParam(arguments.instanceOperationUid, "operationUid", arguments.instanceOperationUid)/>
|
||||
<cfset setInstanceOperationRfsParam(arguments.instanceOperationUid, "modifierId", arguments.usrId)/>
|
||||
<cfset setInstanceOperationRfsParam(arguments.instanceOperationUid, "resourceRealm", qSvcOperation.resource_realm)/>
|
||||
|
||||
|
||||
<cfif qSvcOperation.operation EQ "create"><!--- несколько костыльно --->
|
||||
<cfset setInstanceOperationRfsParam(arguments.instanceOperationUid, "billingObject", "underconstruction")/>
|
||||
<cfset setInstanceOperationRfsParam(arguments.instanceOperationUid, "contragentCode", getContragentCode(arguments.contragentId))/>
|
||||
</cfif>
|
||||
|
||||
<cfif listFind("create,redeploy",qSvcOperation.operation)>
|
||||
<cfset CreateObject("component", "instance_operation_ls").checkResourceRealmId(qSvcOperation.resource_realm_id, qSvcOperation.instance_uid)/>
|
||||
<cfset setInstanceOperationRfsParam(arguments.instanceOperationUid, "resourceRealm", qSvcOperation.resource_realm)/><!--- *** для остальных операций не передаем? --->
|
||||
</cfif>
|
||||
|
||||
<cfquery name="qWriteRfsFromCfsParams">
|
||||
insert into instance_operation_param (instance_operation_uid,param,param_value)
|
||||
@@ -269,9 +276,10 @@
|
||||
|
||||
<!--- *** судя по всему, RFS параметр не обязан быть специфицирован на сервисе (никак не проверяется) --->
|
||||
<cffunction name="setInstanceOperationRfsParam">
|
||||
<cfargument name="instanceOperationUid" type="guid">
|
||||
<cfargument name="param"><!--- значение не должно содержать лишних пробелов, чувствительность к регистру определяется БД --->
|
||||
<cfargument name="val">
|
||||
<cfargument name="instanceOperationUid" type="guid"/>
|
||||
<cfargument name="param"/><!--- значение не должно содержать лишних пробелов, чувствительность к регистру определяется БД --->
|
||||
<cfargument name="val"/>
|
||||
|
||||
<cfquery name="qSaveRfsParam">
|
||||
insert into instance_operation_param (instance_operation_uid,param,param_value)
|
||||
values (
|
||||
@@ -325,5 +333,50 @@
|
||||
|
||||
<cfreturn #qContragentCode.external_code#/>
|
||||
</cffunction>
|
||||
|
||||
|
||||
<cffunction name="checkRfsResourceRealmAccess">
|
||||
<cfargument name="instanceOperationUid" type="guid">
|
||||
|
||||
<cfset var local={}/>
|
||||
|
||||
<cfquery name="local.qOperation">
|
||||
select io.operation
|
||||
from instance_operation io
|
||||
where io.instance_operation_uid=<cfqueryparam cfsqltype="cf_sql_other" value="#arguments.instanceOperationUid#" null=#!isValid("guid",arguments.instanceOperationUid)#/>
|
||||
</cfquery>
|
||||
|
||||
<cfif !listFind("create,redeploy", local.qOperation.operation)>
|
||||
<cfreturn/>
|
||||
</cfif>
|
||||
|
||||
<cfquery name="local.qContract">
|
||||
select c.contract_id
|
||||
from instance_operation io
|
||||
join instance e on (io.instance_uid=e.instance_uid)
|
||||
join specification_item si on (e.specification_item_id=si.specification_item_id)
|
||||
join specification s on (si.specification_id=s.specification_id)
|
||||
join contract c on (s.contract_id=c.contract_id)
|
||||
where io.instance_operation_uid=<cfqueryparam cfsqltype="cf_sql_other" value="#arguments.instanceOperationUid#" null=#!isValid("guid",arguments.instanceOperationUid)#/>
|
||||
</cfquery>
|
||||
|
||||
<!--- пробегаемся по RFS параметрам данной операции--->
|
||||
<cfquery name="local.qCheckResourceRealmAccess">
|
||||
select r.resource_realm_id, r.resource_realm, iop.param, iop.param_value, a.contract_id, a.is_enabled
|
||||
from resource_realm r
|
||||
join resource_realm_access a on (r.resource_realm_id=a.resource_realm_id)
|
||||
join instance_operation_param iop on (r.resource_realm=iop.param_value AND iop.param='resourceRealm')
|
||||
where iop.instance_operation_uid=<cfqueryparam cfsqltype="cf_sql_other" value="#arguments.instanceOperationUid#" null=#!isValid("guid",arguments.instanceOperationUid)#/>
|
||||
AND (a.contract_id=<cfqueryparam cfsqltype="CF_SQL_INTEGER" value=#local.qContract.contract_id# null=#!isValid("integer",local.qContract.contract_id)#/> OR a.contract_id=0)
|
||||
AND a.is_enabled
|
||||
</cfquery>
|
||||
|
||||
<cfif local.qCheckResourceRealmAccess.recordCount EQ 0>
|
||||
<cfthrow message="resource realm specified in RFS params is not available for current contract" detail="resource realm unawailable. Instance operation UID #arguments.instanceOperationUid#. Contract ID #arguments.contractId#"/>
|
||||
<cfelse>
|
||||
<!--- <cfdump var=#local.qCheckResourceRealmAccess#/><cfabort/> --->
|
||||
<!--- <cfthrow detail="wefwewewewewewer2r24"/> --->
|
||||
</cfif>
|
||||
</cffunction>
|
||||
|
||||
</cfcomponent>
|
||||
Reference in New Issue
Block a user