mirror of
https://github.com/Sagit-chu/flvx.git
synced 2026-10-07 10:16:38 +08:00
fix: preserve manual tunnel access when revoking group grants
This commit is contained in:
+2
-1
@@ -37,7 +37,8 @@ public class SqliteSchemaMigration implements ApplicationRunner {
|
|||||||
ensureTable("CREATE TABLE IF NOT EXISTS tunnel_group_tunnel (id INTEGER PRIMARY KEY AUTOINCREMENT, tunnel_group_id INTEGER NOT NULL, tunnel_id INTEGER NOT NULL, created_time INTEGER NOT NULL)");
|
ensureTable("CREATE TABLE IF NOT EXISTS tunnel_group_tunnel (id INTEGER PRIMARY KEY AUTOINCREMENT, tunnel_group_id INTEGER NOT NULL, tunnel_id INTEGER NOT NULL, created_time INTEGER NOT NULL)");
|
||||||
ensureTable("CREATE TABLE IF NOT EXISTS user_group_user (id INTEGER PRIMARY KEY AUTOINCREMENT, user_group_id INTEGER NOT NULL, user_id INTEGER NOT NULL, created_time INTEGER NOT NULL)");
|
ensureTable("CREATE TABLE IF NOT EXISTS user_group_user (id INTEGER PRIMARY KEY AUTOINCREMENT, user_group_id INTEGER NOT NULL, user_id INTEGER NOT NULL, created_time INTEGER NOT NULL)");
|
||||||
ensureTable("CREATE TABLE IF NOT EXISTS group_permission (id INTEGER PRIMARY KEY AUTOINCREMENT, user_group_id INTEGER NOT NULL, tunnel_group_id INTEGER NOT NULL, created_time INTEGER NOT NULL)");
|
ensureTable("CREATE TABLE IF NOT EXISTS group_permission (id INTEGER PRIMARY KEY AUTOINCREMENT, user_group_id INTEGER NOT NULL, tunnel_group_id INTEGER NOT NULL, created_time INTEGER NOT NULL)");
|
||||||
ensureTable("CREATE TABLE IF NOT EXISTS group_permission_grant (id INTEGER PRIMARY KEY AUTOINCREMENT, user_group_id INTEGER NOT NULL, tunnel_group_id INTEGER NOT NULL, user_tunnel_id INTEGER NOT NULL, created_time INTEGER NOT NULL)");
|
ensureTable("CREATE TABLE IF NOT EXISTS group_permission_grant (id INTEGER PRIMARY KEY AUTOINCREMENT, user_group_id INTEGER NOT NULL, tunnel_group_id INTEGER NOT NULL, user_tunnel_id INTEGER NOT NULL, created_by_group INTEGER NOT NULL DEFAULT 0, created_time INTEGER NOT NULL)");
|
||||||
|
ensureColumn("group_permission_grant", "created_by_group", "INTEGER NOT NULL DEFAULT 0");
|
||||||
ensureTable("CREATE UNIQUE INDEX IF NOT EXISTS idx_tunnel_group_name ON tunnel_group(name)");
|
ensureTable("CREATE UNIQUE INDEX IF NOT EXISTS idx_tunnel_group_name ON tunnel_group(name)");
|
||||||
ensureTable("CREATE UNIQUE INDEX IF NOT EXISTS idx_user_group_name ON user_group(name)");
|
ensureTable("CREATE UNIQUE INDEX IF NOT EXISTS idx_user_group_name ON user_group(name)");
|
||||||
ensureTable("CREATE UNIQUE INDEX IF NOT EXISTS idx_tunnel_group_tunnel_unique ON tunnel_group_tunnel(tunnel_group_id, tunnel_id)");
|
ensureTable("CREATE UNIQUE INDEX IF NOT EXISTS idx_tunnel_group_tunnel_unique ON tunnel_group_tunnel(tunnel_group_id, tunnel_id)");
|
||||||
|
|||||||
@@ -20,5 +20,7 @@ public class GroupPermissionGrant implements Serializable {
|
|||||||
|
|
||||||
private Long userTunnelId;
|
private Long userTunnelId;
|
||||||
|
|
||||||
|
private Integer createdByGroup;
|
||||||
|
|
||||||
private Long createdTime;
|
private Long createdTime;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -430,6 +430,7 @@ public class GroupServiceImpl implements GroupService {
|
|||||||
.map(ut -> ut.getId().longValue())
|
.map(ut -> ut.getId().longValue())
|
||||||
.collect(Collectors.toSet());
|
.collect(Collectors.toSet());
|
||||||
Map<Long, Long> totalGrantCountMap = buildGrantCountMap(pairUserTunnelIds);
|
Map<Long, Long> totalGrantCountMap = buildGrantCountMap(pairUserTunnelIds);
|
||||||
|
Set<Long> groupManagedUserTunnelIds = buildGroupManagedUserTunnelIds(pairUserTunnelIds);
|
||||||
|
|
||||||
Set<Long> currentGrantUserTunnelIds = currentGrants.stream().map(GroupPermissionGrant::getUserTunnelId).collect(Collectors.toSet());
|
Set<Long> currentGrantUserTunnelIds = currentGrants.stream().map(GroupPermissionGrant::getUserTunnelId).collect(Collectors.toSet());
|
||||||
if (!desiredKeys.isEmpty()) {
|
if (!desiredKeys.isEmpty()) {
|
||||||
@@ -448,9 +449,10 @@ public class GroupServiceImpl implements GroupService {
|
|||||||
if (userTunnel == null) {
|
if (userTunnel == null) {
|
||||||
userTunnel = createGroupManagedUserTunnel(userId, tunnelId, user);
|
userTunnel = createGroupManagedUserTunnel(userId, tunnelId, user);
|
||||||
pairUserTunnelMap.put(pairKey, userTunnel);
|
pairUserTunnelMap.put(pairKey, userTunnel);
|
||||||
createGrant(userGroupId, tunnelGroupId, userTunnel.getId().longValue(), now);
|
createGrant(userGroupId, tunnelGroupId, userTunnel.getId().longValue(), true, now);
|
||||||
currentGrantUserTunnelIds.add(userTunnel.getId().longValue());
|
currentGrantUserTunnelIds.add(userTunnel.getId().longValue());
|
||||||
totalGrantCountMap.put(userTunnel.getId().longValue(), 1L);
|
totalGrantCountMap.put(userTunnel.getId().longValue(), 1L);
|
||||||
|
groupManagedUserTunnelIds.add(userTunnel.getId().longValue());
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -460,7 +462,8 @@ public class GroupServiceImpl implements GroupService {
|
|||||||
}
|
}
|
||||||
|
|
||||||
long existingGrantCount = totalGrantCountMap.getOrDefault(userTunnelId, 0L);
|
long existingGrantCount = totalGrantCountMap.getOrDefault(userTunnelId, 0L);
|
||||||
createGrant(userGroupId, tunnelGroupId, userTunnelId, now);
|
boolean createdByGroup = groupManagedUserTunnelIds.contains(userTunnelId);
|
||||||
|
createGrant(userGroupId, tunnelGroupId, userTunnelId, createdByGroup, now);
|
||||||
currentGrantUserTunnelIds.add(userTunnelId);
|
currentGrantUserTunnelIds.add(userTunnelId);
|
||||||
totalGrantCountMap.put(userTunnelId, existingGrantCount + 1L);
|
totalGrantCountMap.put(userTunnelId, existingGrantCount + 1L);
|
||||||
}
|
}
|
||||||
@@ -498,7 +501,7 @@ public class GroupServiceImpl implements GroupService {
|
|||||||
return userTunnel;
|
return userTunnel;
|
||||||
}
|
}
|
||||||
|
|
||||||
private void createGrant(Long userGroupId, Long tunnelGroupId, Long userTunnelId, long createdTime) {
|
private void createGrant(Long userGroupId, Long tunnelGroupId, Long userTunnelId, boolean createdByGroup, long createdTime) {
|
||||||
int exists = groupPermissionGrantMapper.selectCount(new QueryWrapper<GroupPermissionGrant>()
|
int exists = groupPermissionGrantMapper.selectCount(new QueryWrapper<GroupPermissionGrant>()
|
||||||
.eq("user_group_id", userGroupId)
|
.eq("user_group_id", userGroupId)
|
||||||
.eq("tunnel_group_id", tunnelGroupId)
|
.eq("tunnel_group_id", tunnelGroupId)
|
||||||
@@ -511,6 +514,7 @@ public class GroupServiceImpl implements GroupService {
|
|||||||
grant.setUserGroupId(userGroupId);
|
grant.setUserGroupId(userGroupId);
|
||||||
grant.setTunnelGroupId(tunnelGroupId);
|
grant.setTunnelGroupId(tunnelGroupId);
|
||||||
grant.setUserTunnelId(userTunnelId);
|
grant.setUserTunnelId(userTunnelId);
|
||||||
|
grant.setCreatedByGroup(createdByGroup ? 1 : 0);
|
||||||
grant.setCreatedTime(createdTime);
|
grant.setCreatedTime(createdTime);
|
||||||
groupPermissionGrantMapper.insert(grant);
|
groupPermissionGrantMapper.insert(grant);
|
||||||
}
|
}
|
||||||
@@ -528,8 +532,12 @@ public class GroupServiceImpl implements GroupService {
|
|||||||
}
|
}
|
||||||
|
|
||||||
Set<Long> candidateUserTunnelIds = new HashSet<>();
|
Set<Long> candidateUserTunnelIds = new HashSet<>();
|
||||||
|
Set<Long> groupManagedCandidates = new HashSet<>();
|
||||||
for (GroupPermissionGrant grant : grants) {
|
for (GroupPermissionGrant grant : grants) {
|
||||||
candidateUserTunnelIds.add(grant.getUserTunnelId());
|
candidateUserTunnelIds.add(grant.getUserTunnelId());
|
||||||
|
if (grant.getCreatedByGroup() != null && grant.getCreatedByGroup() == 1) {
|
||||||
|
groupManagedCandidates.add(grant.getUserTunnelId());
|
||||||
|
}
|
||||||
groupPermissionGrantMapper.deleteById(grant.getId());
|
groupPermissionGrantMapper.deleteById(grant.getId());
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -540,12 +548,25 @@ public class GroupServiceImpl implements GroupService {
|
|||||||
.collect(Collectors.toSet());
|
.collect(Collectors.toSet());
|
||||||
|
|
||||||
for (Long userTunnelId : candidateUserTunnelIds) {
|
for (Long userTunnelId : candidateUserTunnelIds) {
|
||||||
if (!stillGrantedUserTunnelIds.contains(userTunnelId)) {
|
if (!stillGrantedUserTunnelIds.contains(userTunnelId) && groupManagedCandidates.contains(userTunnelId)) {
|
||||||
userTunnelService.removeUserTunnel(userTunnelId.intValue());
|
userTunnelService.removeUserTunnel(userTunnelId.intValue());
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private Set<Long> buildGroupManagedUserTunnelIds(Set<Long> userTunnelIds) {
|
||||||
|
if (userTunnelIds.isEmpty()) {
|
||||||
|
return Collections.emptySet();
|
||||||
|
}
|
||||||
|
|
||||||
|
return groupPermissionGrantMapper.selectList(new QueryWrapper<GroupPermissionGrant>()
|
||||||
|
.in("user_tunnel_id", userTunnelIds)
|
||||||
|
.eq("created_by_group", 1))
|
||||||
|
.stream()
|
||||||
|
.map(GroupPermissionGrant::getUserTunnelId)
|
||||||
|
.collect(Collectors.toSet());
|
||||||
|
}
|
||||||
|
|
||||||
private Map<Long, Long> buildGrantCountMap(Set<Long> userTunnelIds) {
|
private Map<Long, Long> buildGrantCountMap(Set<Long> userTunnelIds) {
|
||||||
if (userTunnelIds.isEmpty()) {
|
if (userTunnelIds.isEmpty()) {
|
||||||
return new HashMap<>();
|
return new HashMap<>();
|
||||||
|
|||||||
@@ -163,6 +163,7 @@ CREATE TABLE IF NOT EXISTS group_permission_grant (
|
|||||||
user_group_id INTEGER NOT NULL,
|
user_group_id INTEGER NOT NULL,
|
||||||
tunnel_group_id INTEGER NOT NULL,
|
tunnel_group_id INTEGER NOT NULL,
|
||||||
user_tunnel_id INTEGER NOT NULL,
|
user_tunnel_id INTEGER NOT NULL,
|
||||||
|
created_by_group INTEGER NOT NULL DEFAULT 0,
|
||||||
created_time INTEGER NOT NULL
|
created_time INTEGER NOT NULL
|
||||||
);
|
);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user