Vous ne pouvez pas sélectionner plus de 25 sujets Les noms de sujets doivent commencer par une lettre ou un nombre, peuvent contenir des tirets ('-') et peuvent comporter jusqu'à 35 caractères.

account.py 14KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339
  1. import enum
  2. import json
  3. from datetime import datetime
  4. from typing import Any, Optional
  5. import sqlalchemy as sa
  6. from flask_login import UserMixin # type: ignore[import-untyped]
  7. from sqlalchemy import DateTime, String, func, select
  8. from sqlalchemy.orm import Mapped, Session, mapped_column, reconstructor
  9. from models.base import Base
  10. from .engine import db
  11. from .types import StringUUID
  12. class TenantAccountRole(enum.StrEnum):
  13. OWNER = "owner"
  14. ADMIN = "admin"
  15. EDITOR = "editor"
  16. NORMAL = "normal"
  17. DATASET_OPERATOR = "dataset_operator"
  18. @staticmethod
  19. def is_valid_role(role: str) -> bool:
  20. if not role:
  21. return False
  22. return role in {
  23. TenantAccountRole.OWNER,
  24. TenantAccountRole.ADMIN,
  25. TenantAccountRole.EDITOR,
  26. TenantAccountRole.NORMAL,
  27. TenantAccountRole.DATASET_OPERATOR,
  28. }
  29. @staticmethod
  30. def is_privileged_role(role: Optional["TenantAccountRole"]) -> bool:
  31. if not role:
  32. return False
  33. return role in {TenantAccountRole.OWNER, TenantAccountRole.ADMIN}
  34. @staticmethod
  35. def is_admin_role(role: Optional["TenantAccountRole"]) -> bool:
  36. if not role:
  37. return False
  38. return role == TenantAccountRole.ADMIN
  39. @staticmethod
  40. def is_non_owner_role(role: Optional["TenantAccountRole"]) -> bool:
  41. if not role:
  42. return False
  43. return role in {
  44. TenantAccountRole.ADMIN,
  45. TenantAccountRole.EDITOR,
  46. TenantAccountRole.NORMAL,
  47. TenantAccountRole.DATASET_OPERATOR,
  48. }
  49. @staticmethod
  50. def is_editing_role(role: Optional["TenantAccountRole"]) -> bool:
  51. if not role:
  52. return False
  53. return role in {TenantAccountRole.OWNER, TenantAccountRole.ADMIN, TenantAccountRole.EDITOR}
  54. @staticmethod
  55. def is_dataset_edit_role(role: Optional["TenantAccountRole"]) -> bool:
  56. if not role:
  57. return False
  58. return role in {
  59. TenantAccountRole.OWNER,
  60. TenantAccountRole.ADMIN,
  61. TenantAccountRole.EDITOR,
  62. TenantAccountRole.DATASET_OPERATOR,
  63. }
  64. class AccountStatus(enum.StrEnum):
  65. PENDING = "pending"
  66. UNINITIALIZED = "uninitialized"
  67. ACTIVE = "active"
  68. BANNED = "banned"
  69. CLOSED = "closed"
  70. class Account(UserMixin, Base):
  71. __tablename__ = "accounts"
  72. __table_args__ = (sa.PrimaryKeyConstraint("id", name="account_pkey"), sa.Index("account_email_idx", "email"))
  73. id: Mapped[str] = mapped_column(StringUUID, server_default=sa.text("uuid_generate_v4()"))
  74. name: Mapped[str] = mapped_column(String(255))
  75. email: Mapped[str] = mapped_column(String(255))
  76. password: Mapped[Optional[str]] = mapped_column(String(255))
  77. password_salt: Mapped[Optional[str]] = mapped_column(String(255))
  78. avatar: Mapped[Optional[str]] = mapped_column(String(255), nullable=True)
  79. interface_language: Mapped[Optional[str]] = mapped_column(String(255))
  80. interface_theme: Mapped[Optional[str]] = mapped_column(String(255), nullable=True)
  81. timezone: Mapped[Optional[str]] = mapped_column(String(255))
  82. last_login_at: Mapped[Optional[datetime]] = mapped_column(DateTime, nullable=True)
  83. last_login_ip: Mapped[Optional[str]] = mapped_column(String(255), nullable=True)
  84. last_active_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp(), nullable=False)
  85. status: Mapped[str] = mapped_column(String(16), server_default=sa.text("'active'::character varying"))
  86. initialized_at: Mapped[Optional[datetime]] = mapped_column(DateTime, nullable=True)
  87. created_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp(), nullable=False)
  88. updated_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp(), nullable=False)
  89. @reconstructor
  90. def init_on_load(self):
  91. self.role: Optional[TenantAccountRole] = None
  92. self._current_tenant: Optional[Tenant] = None
  93. @property
  94. def is_password_set(self):
  95. return self.password is not None
  96. @property
  97. def current_tenant(self):
  98. return self._current_tenant
  99. @current_tenant.setter
  100. def current_tenant(self, tenant: "Tenant"):
  101. with Session(db.engine, expire_on_commit=False) as session:
  102. tenant_join_query = select(TenantAccountJoin).where(
  103. TenantAccountJoin.tenant_id == tenant.id, TenantAccountJoin.account_id == self.id
  104. )
  105. tenant_join = session.scalar(tenant_join_query)
  106. tenant_query = select(Tenant).where(Tenant.id == tenant.id)
  107. # TODO: A workaround to reload the tenant with `expire_on_commit=False`, allowing
  108. # access to it after the session has been closed.
  109. # This prevents `DetachedInstanceError` when accessing the tenant outside
  110. # the session's lifecycle.
  111. # (The `tenant` argument is typically loaded by `db.session` without the
  112. # `expire_on_commit=False` flag, meaning its lifetime is tied to the web
  113. # request's lifecycle.)
  114. tenant_reloaded = session.scalars(tenant_query).one()
  115. if tenant_join:
  116. self.role = TenantAccountRole(tenant_join.role)
  117. self._current_tenant = tenant_reloaded
  118. return
  119. self._current_tenant = None
  120. @property
  121. def current_tenant_id(self) -> str | None:
  122. return self._current_tenant.id if self._current_tenant else None
  123. def set_tenant_id(self, tenant_id: str):
  124. query = (
  125. select(Tenant, TenantAccountJoin)
  126. .where(Tenant.id == tenant_id)
  127. .where(TenantAccountJoin.tenant_id == Tenant.id)
  128. .where(TenantAccountJoin.account_id == self.id)
  129. )
  130. with Session(db.engine, expire_on_commit=False) as session:
  131. tenant_account_join = session.execute(query).first()
  132. if not tenant_account_join:
  133. return
  134. tenant, join = tenant_account_join
  135. self.role = TenantAccountRole(join.role)
  136. self._current_tenant = tenant
  137. @property
  138. def current_role(self):
  139. return self.role
  140. def get_status(self) -> AccountStatus:
  141. status_str = self.status
  142. return AccountStatus(status_str)
  143. @classmethod
  144. def get_by_openid(cls, provider: str, open_id: str):
  145. account_integrate = (
  146. db.session.query(AccountIntegrate)
  147. .where(AccountIntegrate.provider == provider, AccountIntegrate.open_id == open_id)
  148. .one_or_none()
  149. )
  150. if account_integrate:
  151. return db.session.query(Account).where(Account.id == account_integrate.account_id).one_or_none()
  152. return None
  153. # check current_user.current_tenant.current_role in ['admin', 'owner']
  154. @property
  155. def is_admin_or_owner(self):
  156. return TenantAccountRole.is_privileged_role(self.role)
  157. @property
  158. def is_admin(self):
  159. return TenantAccountRole.is_admin_role(self.role)
  160. @property
  161. def is_editor(self):
  162. return TenantAccountRole.is_editing_role(self.role)
  163. @property
  164. def is_dataset_editor(self):
  165. return TenantAccountRole.is_dataset_edit_role(self.role)
  166. @property
  167. def is_dataset_operator(self):
  168. return self.role == TenantAccountRole.DATASET_OPERATOR
  169. class TenantStatus(enum.StrEnum):
  170. NORMAL = "normal"
  171. ARCHIVE = "archive"
  172. class Tenant(Base):
  173. __tablename__ = "tenants"
  174. __table_args__ = (sa.PrimaryKeyConstraint("id", name="tenant_pkey"),)
  175. id: Mapped[str] = mapped_column(StringUUID, server_default=sa.text("uuid_generate_v4()"))
  176. name: Mapped[str] = mapped_column(String(255))
  177. encrypt_public_key: Mapped[Optional[str]] = mapped_column(sa.Text)
  178. plan: Mapped[str] = mapped_column(String(255), server_default=sa.text("'basic'::character varying"))
  179. status: Mapped[str] = mapped_column(String(255), server_default=sa.text("'normal'::character varying"))
  180. custom_config: Mapped[Optional[str]] = mapped_column(sa.Text)
  181. created_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp(), nullable=False)
  182. updated_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp())
  183. def get_accounts(self) -> list[Account]:
  184. return (
  185. db.session.query(Account)
  186. .where(Account.id == TenantAccountJoin.account_id, TenantAccountJoin.tenant_id == self.id)
  187. .all()
  188. )
  189. @property
  190. def custom_config_dict(self) -> dict[str, Any]:
  191. return json.loads(self.custom_config) if self.custom_config else {}
  192. @custom_config_dict.setter
  193. def custom_config_dict(self, value: dict[str, Any]) -> None:
  194. self.custom_config = json.dumps(value)
  195. class TenantAccountJoin(Base):
  196. __tablename__ = "tenant_account_joins"
  197. __table_args__ = (
  198. sa.PrimaryKeyConstraint("id", name="tenant_account_join_pkey"),
  199. sa.Index("tenant_account_join_account_id_idx", "account_id"),
  200. sa.Index("tenant_account_join_tenant_id_idx", "tenant_id"),
  201. sa.UniqueConstraint("tenant_id", "account_id", name="unique_tenant_account_join"),
  202. )
  203. id: Mapped[str] = mapped_column(StringUUID, server_default=sa.text("uuid_generate_v4()"))
  204. tenant_id: Mapped[str] = mapped_column(StringUUID)
  205. account_id: Mapped[str] = mapped_column(StringUUID)
  206. current: Mapped[bool] = mapped_column(sa.Boolean, server_default=sa.text("false"))
  207. role: Mapped[str] = mapped_column(String(16), server_default="normal")
  208. invited_by: Mapped[Optional[str]] = mapped_column(StringUUID)
  209. created_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp())
  210. updated_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp())
  211. class AccountIntegrate(Base):
  212. __tablename__ = "account_integrates"
  213. __table_args__ = (
  214. sa.PrimaryKeyConstraint("id", name="account_integrate_pkey"),
  215. sa.UniqueConstraint("account_id", "provider", name="unique_account_provider"),
  216. sa.UniqueConstraint("provider", "open_id", name="unique_provider_open_id"),
  217. )
  218. id: Mapped[str] = mapped_column(StringUUID, server_default=sa.text("uuid_generate_v4()"))
  219. account_id: Mapped[str] = mapped_column(StringUUID)
  220. provider: Mapped[str] = mapped_column(String(16))
  221. open_id: Mapped[str] = mapped_column(String(255))
  222. encrypted_token: Mapped[str] = mapped_column(String(255))
  223. created_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp())
  224. updated_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp())
  225. class InvitationCode(Base):
  226. __tablename__ = "invitation_codes"
  227. __table_args__ = (
  228. sa.PrimaryKeyConstraint("id", name="invitation_code_pkey"),
  229. sa.Index("invitation_codes_batch_idx", "batch"),
  230. sa.Index("invitation_codes_code_idx", "code", "status"),
  231. )
  232. id: Mapped[int] = mapped_column(sa.Integer)
  233. batch: Mapped[str] = mapped_column(String(255))
  234. code: Mapped[str] = mapped_column(String(32))
  235. status: Mapped[str] = mapped_column(String(16), server_default=sa.text("'unused'::character varying"))
  236. used_at: Mapped[Optional[datetime]] = mapped_column(DateTime)
  237. used_by_tenant_id: Mapped[Optional[str]] = mapped_column(StringUUID)
  238. used_by_account_id: Mapped[Optional[str]] = mapped_column(StringUUID)
  239. deprecated_at: Mapped[Optional[datetime]] = mapped_column(DateTime, nullable=True)
  240. created_at: Mapped[datetime] = mapped_column(DateTime, server_default=sa.text("CURRENT_TIMESTAMP(0)"))
  241. class TenantPluginPermission(Base):
  242. class InstallPermission(enum.StrEnum):
  243. EVERYONE = "everyone"
  244. ADMINS = "admins"
  245. NOBODY = "noone"
  246. class DebugPermission(enum.StrEnum):
  247. EVERYONE = "everyone"
  248. ADMINS = "admins"
  249. NOBODY = "noone"
  250. __tablename__ = "account_plugin_permissions"
  251. __table_args__ = (
  252. sa.PrimaryKeyConstraint("id", name="account_plugin_permission_pkey"),
  253. sa.UniqueConstraint("tenant_id", name="unique_tenant_plugin"),
  254. )
  255. id: Mapped[str] = mapped_column(StringUUID, server_default=sa.text("uuid_generate_v4()"))
  256. tenant_id: Mapped[str] = mapped_column(StringUUID, nullable=False)
  257. install_permission: Mapped[InstallPermission] = mapped_column(String(16), nullable=False, server_default="everyone")
  258. debug_permission: Mapped[DebugPermission] = mapped_column(String(16), nullable=False, server_default="noone")
  259. class TenantPluginAutoUpgradeStrategy(Base):
  260. class StrategySetting(enum.StrEnum):
  261. DISABLED = "disabled"
  262. FIX_ONLY = "fix_only"
  263. LATEST = "latest"
  264. class UpgradeMode(enum.StrEnum):
  265. ALL = "all"
  266. PARTIAL = "partial"
  267. EXCLUDE = "exclude"
  268. __tablename__ = "tenant_plugin_auto_upgrade_strategies"
  269. __table_args__ = (
  270. sa.PrimaryKeyConstraint("id", name="tenant_plugin_auto_upgrade_strategy_pkey"),
  271. sa.UniqueConstraint("tenant_id", name="unique_tenant_plugin_auto_upgrade_strategy"),
  272. )
  273. id: Mapped[str] = mapped_column(StringUUID, server_default=sa.text("uuid_generate_v4()"))
  274. tenant_id: Mapped[str] = mapped_column(StringUUID, nullable=False)
  275. strategy_setting: Mapped[StrategySetting] = mapped_column(String(16), nullable=False, server_default="fix_only")
  276. upgrade_time_of_day: Mapped[int] = mapped_column(sa.Integer, nullable=False, default=0) # seconds of the day
  277. upgrade_mode: Mapped[UpgradeMode] = mapped_column(String(16), nullable=False, server_default="exclude")
  278. exclude_plugins: Mapped[list[str]] = mapped_column(sa.ARRAY(String(255)), nullable=False) # plugin_id (author/name)
  279. include_plugins: Mapped[list[str]] = mapped_column(sa.ARRAY(String(255)), nullable=False) # plugin_id (author/name)
  280. created_at: Mapped[datetime] = mapped_column(DateTime, nullable=False, server_default=func.current_timestamp())
  281. updated_at: Mapped[datetime] = mapped_column(DateTime, nullable=False, server_default=func.current_timestamp())