You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301
  1. import enum
  2. import json
  3. from typing import Optional, cast
  4. from flask_login import UserMixin # type: ignore
  5. from sqlalchemy import func
  6. from sqlalchemy.orm import Mapped, mapped_column, reconstructor
  7. from models.base import Base
  8. from .engine import db
  9. from .types import StringUUID
  10. class TenantAccountRole(enum.StrEnum):
  11. OWNER = "owner"
  12. ADMIN = "admin"
  13. EDITOR = "editor"
  14. NORMAL = "normal"
  15. DATASET_OPERATOR = "dataset_operator"
  16. @staticmethod
  17. def is_valid_role(role: str) -> bool:
  18. if not role:
  19. return False
  20. return role in {
  21. TenantAccountRole.OWNER,
  22. TenantAccountRole.ADMIN,
  23. TenantAccountRole.EDITOR,
  24. TenantAccountRole.NORMAL,
  25. TenantAccountRole.DATASET_OPERATOR,
  26. }
  27. @staticmethod
  28. def is_privileged_role(role: Optional["TenantAccountRole"]) -> bool:
  29. if not role:
  30. return False
  31. return role in {TenantAccountRole.OWNER, TenantAccountRole.ADMIN}
  32. @staticmethod
  33. def is_admin_role(role: Optional["TenantAccountRole"]) -> bool:
  34. if not role:
  35. return False
  36. return role == TenantAccountRole.ADMIN
  37. @staticmethod
  38. def is_non_owner_role(role: Optional["TenantAccountRole"]) -> bool:
  39. if not role:
  40. return False
  41. return role in {
  42. TenantAccountRole.ADMIN,
  43. TenantAccountRole.EDITOR,
  44. TenantAccountRole.NORMAL,
  45. TenantAccountRole.DATASET_OPERATOR,
  46. }
  47. @staticmethod
  48. def is_editing_role(role: Optional["TenantAccountRole"]) -> bool:
  49. if not role:
  50. return False
  51. return role in {TenantAccountRole.OWNER, TenantAccountRole.ADMIN, TenantAccountRole.EDITOR}
  52. @staticmethod
  53. def is_dataset_edit_role(role: Optional["TenantAccountRole"]) -> bool:
  54. if not role:
  55. return False
  56. return role in {
  57. TenantAccountRole.OWNER,
  58. TenantAccountRole.ADMIN,
  59. TenantAccountRole.EDITOR,
  60. TenantAccountRole.DATASET_OPERATOR,
  61. }
  62. class AccountStatus(enum.StrEnum):
  63. PENDING = "pending"
  64. UNINITIALIZED = "uninitialized"
  65. ACTIVE = "active"
  66. BANNED = "banned"
  67. CLOSED = "closed"
  68. class Account(UserMixin, Base):
  69. __tablename__ = "accounts"
  70. __table_args__ = (db.PrimaryKeyConstraint("id", name="account_pkey"), db.Index("account_email_idx", "email"))
  71. id: Mapped[str] = mapped_column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  72. name = db.Column(db.String(255), nullable=False)
  73. email = db.Column(db.String(255), nullable=False)
  74. password = db.Column(db.String(255), nullable=True)
  75. password_salt = db.Column(db.String(255), nullable=True)
  76. avatar = db.Column(db.String(255))
  77. interface_language = db.Column(db.String(255))
  78. interface_theme = db.Column(db.String(255))
  79. timezone = db.Column(db.String(255))
  80. last_login_at = db.Column(db.DateTime)
  81. last_login_ip = db.Column(db.String(255))
  82. last_active_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  83. status = db.Column(db.String(16), nullable=False, server_default=db.text("'active'::character varying"))
  84. initialized_at = db.Column(db.DateTime)
  85. created_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  86. updated_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  87. @reconstructor
  88. def init_on_load(self):
  89. self.role: Optional[TenantAccountRole] = None
  90. self._current_tenant: Optional[Tenant] = None
  91. @property
  92. def is_password_set(self):
  93. return self.password is not None
  94. @property
  95. def current_tenant(self):
  96. return self._current_tenant
  97. @current_tenant.setter
  98. def current_tenant(self, tenant: "Tenant"):
  99. ta = db.session.query(TenantAccountJoin).filter_by(tenant_id=tenant.id, account_id=self.id).first()
  100. if ta:
  101. self.role = TenantAccountRole(ta.role)
  102. self._current_tenant = tenant
  103. return
  104. self._current_tenant = None
  105. @property
  106. def current_tenant_id(self) -> str | None:
  107. return self._current_tenant.id if self._current_tenant else None
  108. def set_tenant_id(self, tenant_id: str):
  109. tenant_account_join = cast(
  110. tuple[Tenant, TenantAccountJoin],
  111. (
  112. db.session.query(Tenant, TenantAccountJoin)
  113. .filter(Tenant.id == tenant_id)
  114. .filter(TenantAccountJoin.tenant_id == Tenant.id)
  115. .filter(TenantAccountJoin.account_id == self.id)
  116. .one_or_none()
  117. ),
  118. )
  119. if not tenant_account_join:
  120. return
  121. tenant, join = tenant_account_join
  122. self.role = join.role
  123. self._current_tenant = tenant
  124. @property
  125. def current_role(self):
  126. return self.role
  127. def get_status(self) -> AccountStatus:
  128. status_str = self.status
  129. return AccountStatus(status_str)
  130. @classmethod
  131. def get_by_openid(cls, provider: str, open_id: str):
  132. account_integrate = (
  133. db.session.query(AccountIntegrate)
  134. .filter(AccountIntegrate.provider == provider, AccountIntegrate.open_id == open_id)
  135. .one_or_none()
  136. )
  137. if account_integrate:
  138. return db.session.query(Account).filter(Account.id == account_integrate.account_id).one_or_none()
  139. return None
  140. # check current_user.current_tenant.current_role in ['admin', 'owner']
  141. @property
  142. def is_admin_or_owner(self):
  143. return TenantAccountRole.is_privileged_role(self.role)
  144. @property
  145. def is_admin(self):
  146. return TenantAccountRole.is_admin_role(self.role)
  147. @property
  148. def is_editor(self):
  149. return TenantAccountRole.is_editing_role(self.role)
  150. @property
  151. def is_dataset_editor(self):
  152. return TenantAccountRole.is_dataset_edit_role(self.role)
  153. @property
  154. def is_dataset_operator(self):
  155. return self.role == TenantAccountRole.DATASET_OPERATOR
  156. class TenantStatus(enum.StrEnum):
  157. NORMAL = "normal"
  158. ARCHIVE = "archive"
  159. class Tenant(Base):
  160. __tablename__ = "tenants"
  161. __table_args__ = (db.PrimaryKeyConstraint("id", name="tenant_pkey"),)
  162. id = db.Column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  163. name = db.Column(db.String(255), nullable=False)
  164. encrypt_public_key = db.Column(db.Text)
  165. plan = db.Column(db.String(255), nullable=False, server_default=db.text("'basic'::character varying"))
  166. status = db.Column(db.String(255), nullable=False, server_default=db.text("'normal'::character varying"))
  167. custom_config = db.Column(db.Text)
  168. created_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  169. updated_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  170. def get_accounts(self) -> list[Account]:
  171. return (
  172. db.session.query(Account)
  173. .filter(Account.id == TenantAccountJoin.account_id, TenantAccountJoin.tenant_id == self.id)
  174. .all()
  175. )
  176. @property
  177. def custom_config_dict(self) -> dict:
  178. return json.loads(self.custom_config) if self.custom_config else {}
  179. @custom_config_dict.setter
  180. def custom_config_dict(self, value: dict):
  181. self.custom_config = json.dumps(value)
  182. class TenantAccountJoin(Base):
  183. __tablename__ = "tenant_account_joins"
  184. __table_args__ = (
  185. db.PrimaryKeyConstraint("id", name="tenant_account_join_pkey"),
  186. db.Index("tenant_account_join_account_id_idx", "account_id"),
  187. db.Index("tenant_account_join_tenant_id_idx", "tenant_id"),
  188. db.UniqueConstraint("tenant_id", "account_id", name="unique_tenant_account_join"),
  189. )
  190. id = db.Column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  191. tenant_id = db.Column(StringUUID, nullable=False)
  192. account_id = db.Column(StringUUID, nullable=False)
  193. current = db.Column(db.Boolean, nullable=False, server_default=db.text("false"))
  194. role = db.Column(db.String(16), nullable=False, server_default="normal")
  195. invited_by = db.Column(StringUUID, nullable=True)
  196. created_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  197. updated_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  198. class AccountIntegrate(Base):
  199. __tablename__ = "account_integrates"
  200. __table_args__ = (
  201. db.PrimaryKeyConstraint("id", name="account_integrate_pkey"),
  202. db.UniqueConstraint("account_id", "provider", name="unique_account_provider"),
  203. db.UniqueConstraint("provider", "open_id", name="unique_provider_open_id"),
  204. )
  205. id = db.Column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  206. account_id = db.Column(StringUUID, nullable=False)
  207. provider = db.Column(db.String(16), nullable=False)
  208. open_id = db.Column(db.String(255), nullable=False)
  209. encrypted_token = db.Column(db.String(255), nullable=False)
  210. created_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  211. updated_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  212. class InvitationCode(Base):
  213. __tablename__ = "invitation_codes"
  214. __table_args__ = (
  215. db.PrimaryKeyConstraint("id", name="invitation_code_pkey"),
  216. db.Index("invitation_codes_batch_idx", "batch"),
  217. db.Index("invitation_codes_code_idx", "code", "status"),
  218. )
  219. id = db.Column(db.Integer, nullable=False)
  220. batch = db.Column(db.String(255), nullable=False)
  221. code = db.Column(db.String(32), nullable=False)
  222. status = db.Column(db.String(16), nullable=False, server_default=db.text("'unused'::character varying"))
  223. used_at = db.Column(db.DateTime)
  224. used_by_tenant_id = db.Column(StringUUID)
  225. used_by_account_id = db.Column(StringUUID)
  226. deprecated_at = db.Column(db.DateTime)
  227. created_at = db.Column(db.DateTime, nullable=False, server_default=db.text("CURRENT_TIMESTAMP(0)"))
  228. class TenantPluginPermission(Base):
  229. class InstallPermission(enum.StrEnum):
  230. EVERYONE = "everyone"
  231. ADMINS = "admins"
  232. NOBODY = "noone"
  233. class DebugPermission(enum.StrEnum):
  234. EVERYONE = "everyone"
  235. ADMINS = "admins"
  236. NOBODY = "noone"
  237. __tablename__ = "account_plugin_permissions"
  238. __table_args__ = (
  239. db.PrimaryKeyConstraint("id", name="account_plugin_permission_pkey"),
  240. db.UniqueConstraint("tenant_id", name="unique_tenant_plugin"),
  241. )
  242. id: Mapped[str] = mapped_column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  243. tenant_id: Mapped[str] = mapped_column(StringUUID, nullable=False)
  244. install_permission: Mapped[InstallPermission] = mapped_column(
  245. db.String(16), nullable=False, server_default="everyone"
  246. )
  247. debug_permission: Mapped[DebugPermission] = mapped_column(db.String(16), nullable=False, server_default="noone")