You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336
  1. import enum
  2. import json
  3. from datetime import datetime
  4. from typing import Optional, cast
  5. from flask_login import UserMixin # type: ignore
  6. from sqlalchemy import func
  7. from sqlalchemy.orm import Mapped, mapped_column, reconstructor
  8. from models.base import Base
  9. from .engine import db
  10. from .types import StringUUID
  11. class TenantAccountRole(enum.StrEnum):
  12. OWNER = "owner"
  13. ADMIN = "admin"
  14. EDITOR = "editor"
  15. NORMAL = "normal"
  16. DATASET_OPERATOR = "dataset_operator"
  17. @staticmethod
  18. def is_valid_role(role: str) -> bool:
  19. if not role:
  20. return False
  21. return role in {
  22. TenantAccountRole.OWNER,
  23. TenantAccountRole.ADMIN,
  24. TenantAccountRole.EDITOR,
  25. TenantAccountRole.NORMAL,
  26. TenantAccountRole.DATASET_OPERATOR,
  27. }
  28. @staticmethod
  29. def is_privileged_role(role: Optional["TenantAccountRole"]) -> bool:
  30. if not role:
  31. return False
  32. return role in {TenantAccountRole.OWNER, TenantAccountRole.ADMIN}
  33. @staticmethod
  34. def is_admin_role(role: Optional["TenantAccountRole"]) -> bool:
  35. if not role:
  36. return False
  37. return role == TenantAccountRole.ADMIN
  38. @staticmethod
  39. def is_non_owner_role(role: Optional["TenantAccountRole"]) -> bool:
  40. if not role:
  41. return False
  42. return role in {
  43. TenantAccountRole.ADMIN,
  44. TenantAccountRole.EDITOR,
  45. TenantAccountRole.NORMAL,
  46. TenantAccountRole.DATASET_OPERATOR,
  47. }
  48. @staticmethod
  49. def is_editing_role(role: Optional["TenantAccountRole"]) -> bool:
  50. if not role:
  51. return False
  52. return role in {TenantAccountRole.OWNER, TenantAccountRole.ADMIN, TenantAccountRole.EDITOR}
  53. @staticmethod
  54. def is_dataset_edit_role(role: Optional["TenantAccountRole"]) -> bool:
  55. if not role:
  56. return False
  57. return role in {
  58. TenantAccountRole.OWNER,
  59. TenantAccountRole.ADMIN,
  60. TenantAccountRole.EDITOR,
  61. TenantAccountRole.DATASET_OPERATOR,
  62. }
  63. class AccountStatus(enum.StrEnum):
  64. PENDING = "pending"
  65. UNINITIALIZED = "uninitialized"
  66. ACTIVE = "active"
  67. BANNED = "banned"
  68. CLOSED = "closed"
  69. class Account(UserMixin, Base):
  70. __tablename__ = "accounts"
  71. __table_args__ = (db.PrimaryKeyConstraint("id", name="account_pkey"), db.Index("account_email_idx", "email"))
  72. id: Mapped[str] = mapped_column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  73. name: Mapped[str] = mapped_column(db.String(255))
  74. email: Mapped[str] = mapped_column(db.String(255))
  75. password: Mapped[Optional[str]] = mapped_column(db.String(255))
  76. password_salt: Mapped[Optional[str]] = mapped_column(db.String(255))
  77. avatar: Mapped[Optional[str]] = mapped_column(db.String(255), nullable=True)
  78. interface_language: Mapped[Optional[str]] = mapped_column(db.String(255))
  79. interface_theme: Mapped[Optional[str]] = mapped_column(db.String(255), nullable=True)
  80. timezone: Mapped[Optional[str]] = mapped_column(db.String(255))
  81. last_login_at: Mapped[Optional[datetime]] = mapped_column(db.DateTime, nullable=True)
  82. last_login_ip: Mapped[Optional[str]] = mapped_column(db.String(255), nullable=True)
  83. last_active_at: Mapped[datetime] = mapped_column(
  84. db.DateTime, server_default=func.current_timestamp(), nullable=False
  85. )
  86. status: Mapped[str] = mapped_column(db.String(16), server_default=db.text("'active'::character varying"))
  87. initialized_at: Mapped[Optional[datetime]] = mapped_column(db.DateTime, nullable=True)
  88. created_at: Mapped[datetime] = mapped_column(db.DateTime, server_default=func.current_timestamp(), nullable=False)
  89. updated_at: Mapped[datetime] = mapped_column(db.DateTime, server_default=func.current_timestamp(), nullable=False)
  90. @reconstructor
  91. def init_on_load(self):
  92. self.role: Optional[TenantAccountRole] = None
  93. self._current_tenant: Optional[Tenant] = None
  94. @property
  95. def is_password_set(self):
  96. return self.password is not None
  97. @property
  98. def current_tenant(self):
  99. return self._current_tenant
  100. @current_tenant.setter
  101. def current_tenant(self, tenant: "Tenant"):
  102. ta = db.session.query(TenantAccountJoin).filter_by(tenant_id=tenant.id, account_id=self.id).first()
  103. if ta:
  104. self.role = TenantAccountRole(ta.role)
  105. self._current_tenant = tenant
  106. return
  107. self._current_tenant = None
  108. @property
  109. def current_tenant_id(self) -> str | None:
  110. return self._current_tenant.id if self._current_tenant else None
  111. def set_tenant_id(self, tenant_id: str):
  112. tenant_account_join = cast(
  113. tuple[Tenant, TenantAccountJoin],
  114. (
  115. db.session.query(Tenant, TenantAccountJoin)
  116. .filter(Tenant.id == tenant_id)
  117. .filter(TenantAccountJoin.tenant_id == Tenant.id)
  118. .filter(TenantAccountJoin.account_id == self.id)
  119. .one_or_none()
  120. ),
  121. )
  122. if not tenant_account_join:
  123. return
  124. tenant, join = tenant_account_join
  125. self.role = TenantAccountRole(join.role)
  126. self._current_tenant = tenant
  127. @property
  128. def current_role(self):
  129. return self.role
  130. def get_status(self) -> AccountStatus:
  131. status_str = self.status
  132. return AccountStatus(status_str)
  133. @classmethod
  134. def get_by_openid(cls, provider: str, open_id: str):
  135. account_integrate = (
  136. db.session.query(AccountIntegrate)
  137. .filter(AccountIntegrate.provider == provider, AccountIntegrate.open_id == open_id)
  138. .one_or_none()
  139. )
  140. if account_integrate:
  141. return db.session.query(Account).filter(Account.id == account_integrate.account_id).one_or_none()
  142. return None
  143. # check current_user.current_tenant.current_role in ['admin', 'owner']
  144. @property
  145. def is_admin_or_owner(self):
  146. return TenantAccountRole.is_privileged_role(self.role)
  147. @property
  148. def is_admin(self):
  149. return TenantAccountRole.is_admin_role(self.role)
  150. @property
  151. def is_editor(self):
  152. return TenantAccountRole.is_editing_role(self.role)
  153. @property
  154. def is_dataset_editor(self):
  155. return TenantAccountRole.is_dataset_edit_role(self.role)
  156. @property
  157. def is_dataset_operator(self):
  158. return self.role == TenantAccountRole.DATASET_OPERATOR
  159. class TenantStatus(enum.StrEnum):
  160. NORMAL = "normal"
  161. ARCHIVE = "archive"
  162. class Tenant(Base):
  163. __tablename__ = "tenants"
  164. __table_args__ = (db.PrimaryKeyConstraint("id", name="tenant_pkey"),)
  165. id: Mapped[str] = mapped_column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  166. name: Mapped[str] = mapped_column(db.String(255))
  167. encrypt_public_key = db.Column(db.Text)
  168. plan: Mapped[str] = mapped_column(db.String(255), server_default=db.text("'basic'::character varying"))
  169. status: Mapped[str] = mapped_column(db.String(255), server_default=db.text("'normal'::character varying"))
  170. custom_config: Mapped[Optional[str]] = mapped_column(db.Text)
  171. created_at: Mapped[datetime] = mapped_column(db.DateTime, server_default=func.current_timestamp(), nullable=False)
  172. updated_at: Mapped[datetime] = mapped_column(db.DateTime, server_default=func.current_timestamp())
  173. def get_accounts(self) -> list[Account]:
  174. return (
  175. db.session.query(Account)
  176. .filter(Account.id == TenantAccountJoin.account_id, TenantAccountJoin.tenant_id == self.id)
  177. .all()
  178. )
  179. @property
  180. def custom_config_dict(self) -> dict:
  181. return json.loads(self.custom_config) if self.custom_config else {}
  182. @custom_config_dict.setter
  183. def custom_config_dict(self, value: dict):
  184. self.custom_config = json.dumps(value)
  185. class TenantAccountJoin(Base):
  186. __tablename__ = "tenant_account_joins"
  187. __table_args__ = (
  188. db.PrimaryKeyConstraint("id", name="tenant_account_join_pkey"),
  189. db.Index("tenant_account_join_account_id_idx", "account_id"),
  190. db.Index("tenant_account_join_tenant_id_idx", "tenant_id"),
  191. db.UniqueConstraint("tenant_id", "account_id", name="unique_tenant_account_join"),
  192. )
  193. id: Mapped[str] = mapped_column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  194. tenant_id: Mapped[str] = mapped_column(StringUUID)
  195. account_id: Mapped[str] = mapped_column(StringUUID)
  196. current: Mapped[bool] = mapped_column(db.Boolean, server_default=db.text("false"))
  197. role: Mapped[str] = mapped_column(db.String(16), server_default="normal")
  198. invited_by: Mapped[Optional[str]] = mapped_column(StringUUID)
  199. created_at: Mapped[datetime] = mapped_column(db.DateTime, server_default=func.current_timestamp())
  200. updated_at: Mapped[datetime] = mapped_column(db.DateTime, server_default=func.current_timestamp())
  201. class AccountIntegrate(Base):
  202. __tablename__ = "account_integrates"
  203. __table_args__ = (
  204. db.PrimaryKeyConstraint("id", name="account_integrate_pkey"),
  205. db.UniqueConstraint("account_id", "provider", name="unique_account_provider"),
  206. db.UniqueConstraint("provider", "open_id", name="unique_provider_open_id"),
  207. )
  208. id: Mapped[str] = mapped_column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  209. account_id: Mapped[str] = mapped_column(StringUUID)
  210. provider: Mapped[str] = mapped_column(db.String(16))
  211. open_id: Mapped[str] = mapped_column(db.String(255))
  212. encrypted_token: Mapped[str] = mapped_column(db.String(255))
  213. created_at: Mapped[datetime] = mapped_column(db.DateTime, server_default=func.current_timestamp())
  214. updated_at: Mapped[datetime] = mapped_column(db.DateTime, server_default=func.current_timestamp())
  215. class InvitationCode(Base):
  216. __tablename__ = "invitation_codes"
  217. __table_args__ = (
  218. db.PrimaryKeyConstraint("id", name="invitation_code_pkey"),
  219. db.Index("invitation_codes_batch_idx", "batch"),
  220. db.Index("invitation_codes_code_idx", "code", "status"),
  221. )
  222. id: Mapped[int] = mapped_column(db.Integer)
  223. batch: Mapped[str] = mapped_column(db.String(255))
  224. code: Mapped[str] = mapped_column(db.String(32))
  225. status: Mapped[str] = mapped_column(db.String(16), server_default=db.text("'unused'::character varying"))
  226. used_at: Mapped[Optional[datetime]] = mapped_column(db.DateTime)
  227. used_by_tenant_id: Mapped[Optional[str]] = mapped_column(StringUUID)
  228. used_by_account_id: Mapped[Optional[str]] = mapped_column(StringUUID)
  229. deprecated_at: Mapped[Optional[datetime]] = mapped_column(db.DateTime, nullable=True)
  230. created_at: Mapped[datetime] = mapped_column(db.DateTime, server_default=db.text("CURRENT_TIMESTAMP(0)"))
  231. class TenantPluginPermission(Base):
  232. class InstallPermission(enum.StrEnum):
  233. EVERYONE = "everyone"
  234. ADMINS = "admins"
  235. NOBODY = "noone"
  236. class DebugPermission(enum.StrEnum):
  237. EVERYONE = "everyone"
  238. ADMINS = "admins"
  239. NOBODY = "noone"
  240. __tablename__ = "account_plugin_permissions"
  241. __table_args__ = (
  242. db.PrimaryKeyConstraint("id", name="account_plugin_permission_pkey"),
  243. db.UniqueConstraint("tenant_id", name="unique_tenant_plugin"),
  244. )
  245. id: Mapped[str] = mapped_column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  246. tenant_id: Mapped[str] = mapped_column(StringUUID, nullable=False)
  247. install_permission: Mapped[InstallPermission] = mapped_column(
  248. db.String(16), nullable=False, server_default="everyone"
  249. )
  250. debug_permission: Mapped[DebugPermission] = mapped_column(db.String(16), nullable=False, server_default="noone")
  251. class TenantPluginAutoUpgradeStrategy(Base):
  252. class StrategySetting(enum.StrEnum):
  253. DISABLED = "disabled"
  254. FIX_ONLY = "fix_only"
  255. LATEST = "latest"
  256. class UpgradeMode(enum.StrEnum):
  257. ALL = "all"
  258. PARTIAL = "partial"
  259. EXCLUDE = "exclude"
  260. __tablename__ = "tenant_plugin_auto_upgrade_strategies"
  261. __table_args__ = (
  262. db.PrimaryKeyConstraint("id", name="tenant_plugin_auto_upgrade_strategy_pkey"),
  263. db.UniqueConstraint("tenant_id", name="unique_tenant_plugin_auto_upgrade_strategy"),
  264. )
  265. id: Mapped[str] = mapped_column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  266. tenant_id: Mapped[str] = mapped_column(StringUUID, nullable=False)
  267. strategy_setting: Mapped[StrategySetting] = mapped_column(db.String(16), nullable=False, server_default="fix_only")
  268. upgrade_time_of_day: Mapped[int] = mapped_column(db.Integer, nullable=False, default=0) # seconds of the day
  269. upgrade_mode: Mapped[UpgradeMode] = mapped_column(db.String(16), nullable=False, server_default="exclude")
  270. exclude_plugins: Mapped[list[str]] = mapped_column(
  271. db.ARRAY(db.String(255)), nullable=False
  272. ) # plugin_id (author/name)
  273. include_plugins: Mapped[list[str]] = mapped_column(
  274. db.ARRAY(db.String(255)), nullable=False
  275. ) # plugin_id (author/name)
  276. created_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  277. updated_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())