You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

account.py 11KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298
  1. import enum
  2. import json
  3. from typing import cast
  4. from flask_login import UserMixin # type: ignore
  5. from sqlalchemy import func
  6. from sqlalchemy.orm import Mapped, mapped_column
  7. from models.base import Base
  8. from .engine import db
  9. from .types import StringUUID
  10. class AccountStatus(enum.StrEnum):
  11. PENDING = "pending"
  12. UNINITIALIZED = "uninitialized"
  13. ACTIVE = "active"
  14. BANNED = "banned"
  15. CLOSED = "closed"
  16. class Account(UserMixin, Base):
  17. __tablename__ = "accounts"
  18. __table_args__ = (db.PrimaryKeyConstraint("id", name="account_pkey"), db.Index("account_email_idx", "email"))
  19. id: Mapped[str] = mapped_column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  20. name = db.Column(db.String(255), nullable=False)
  21. email = db.Column(db.String(255), nullable=False)
  22. password = db.Column(db.String(255), nullable=True)
  23. password_salt = db.Column(db.String(255), nullable=True)
  24. avatar = db.Column(db.String(255))
  25. interface_language = db.Column(db.String(255))
  26. interface_theme = db.Column(db.String(255))
  27. timezone = db.Column(db.String(255))
  28. last_login_at = db.Column(db.DateTime)
  29. last_login_ip = db.Column(db.String(255))
  30. last_active_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  31. status = db.Column(db.String(16), nullable=False, server_default=db.text("'active'::character varying"))
  32. initialized_at = db.Column(db.DateTime)
  33. created_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  34. updated_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  35. @property
  36. def is_password_set(self):
  37. return self.password is not None
  38. @property
  39. def current_tenant(self):
  40. return self._current_tenant # type: ignore
  41. @current_tenant.setter
  42. def current_tenant(self, value: "Tenant"):
  43. tenant = value
  44. ta = db.session.query(TenantAccountJoin).filter_by(tenant_id=tenant.id, account_id=self.id).first()
  45. if ta:
  46. tenant.current_role = ta.role
  47. else:
  48. tenant = None # type: ignore
  49. self._current_tenant = tenant
  50. @property
  51. def current_tenant_id(self) -> str | None:
  52. return self._current_tenant.id if self._current_tenant else None
  53. def set_tenant_id(self, tenant_id: str):
  54. tenant_account_join = cast(
  55. tuple[Tenant, TenantAccountJoin],
  56. (
  57. db.session.query(Tenant, TenantAccountJoin)
  58. .filter(Tenant.id == tenant_id)
  59. .filter(TenantAccountJoin.tenant_id == Tenant.id)
  60. .filter(TenantAccountJoin.account_id == self.id)
  61. .one_or_none()
  62. ),
  63. )
  64. if not tenant_account_join:
  65. return
  66. tenant, join = tenant_account_join
  67. tenant.current_role = join.role
  68. self._current_tenant = tenant
  69. @property
  70. def current_role(self):
  71. return self._current_tenant.current_role
  72. def get_status(self) -> AccountStatus:
  73. status_str = self.status
  74. return AccountStatus(status_str)
  75. @classmethod
  76. def get_by_openid(cls, provider: str, open_id: str):
  77. account_integrate = (
  78. db.session.query(AccountIntegrate)
  79. .filter(AccountIntegrate.provider == provider, AccountIntegrate.open_id == open_id)
  80. .one_or_none()
  81. )
  82. if account_integrate:
  83. return db.session.query(Account).filter(Account.id == account_integrate.account_id).one_or_none()
  84. return None
  85. # check current_user.current_tenant.current_role in ['admin', 'owner']
  86. @property
  87. def is_admin_or_owner(self):
  88. return TenantAccountRole.is_privileged_role(self._current_tenant.current_role)
  89. @property
  90. def is_admin(self):
  91. return TenantAccountRole.is_admin_role(self._current_tenant.current_role)
  92. @property
  93. def is_editor(self):
  94. return TenantAccountRole.is_editing_role(self._current_tenant.current_role)
  95. @property
  96. def is_dataset_editor(self):
  97. return TenantAccountRole.is_dataset_edit_role(self._current_tenant.current_role)
  98. @property
  99. def is_dataset_operator(self):
  100. return self._current_tenant.current_role == TenantAccountRole.DATASET_OPERATOR
  101. class TenantStatus(enum.StrEnum):
  102. NORMAL = "normal"
  103. ARCHIVE = "archive"
  104. class TenantAccountRole(enum.StrEnum):
  105. OWNER = "owner"
  106. ADMIN = "admin"
  107. EDITOR = "editor"
  108. NORMAL = "normal"
  109. DATASET_OPERATOR = "dataset_operator"
  110. @staticmethod
  111. def is_valid_role(role: str) -> bool:
  112. if not role:
  113. return False
  114. return role in {
  115. TenantAccountRole.OWNER,
  116. TenantAccountRole.ADMIN,
  117. TenantAccountRole.EDITOR,
  118. TenantAccountRole.NORMAL,
  119. TenantAccountRole.DATASET_OPERATOR,
  120. }
  121. @staticmethod
  122. def is_privileged_role(role: str) -> bool:
  123. if not role:
  124. return False
  125. return role in {TenantAccountRole.OWNER, TenantAccountRole.ADMIN}
  126. @staticmethod
  127. def is_admin_role(role: str) -> bool:
  128. if not role:
  129. return False
  130. return role == TenantAccountRole.ADMIN
  131. @staticmethod
  132. def is_non_owner_role(role: str) -> bool:
  133. if not role:
  134. return False
  135. return role in {
  136. TenantAccountRole.ADMIN,
  137. TenantAccountRole.EDITOR,
  138. TenantAccountRole.NORMAL,
  139. TenantAccountRole.DATASET_OPERATOR,
  140. }
  141. @staticmethod
  142. def is_editing_role(role: str) -> bool:
  143. if not role:
  144. return False
  145. return role in {TenantAccountRole.OWNER, TenantAccountRole.ADMIN, TenantAccountRole.EDITOR}
  146. @staticmethod
  147. def is_dataset_edit_role(role: str) -> bool:
  148. if not role:
  149. return False
  150. return role in {
  151. TenantAccountRole.OWNER,
  152. TenantAccountRole.ADMIN,
  153. TenantAccountRole.EDITOR,
  154. TenantAccountRole.DATASET_OPERATOR,
  155. }
  156. class Tenant(Base):
  157. __tablename__ = "tenants"
  158. __table_args__ = (db.PrimaryKeyConstraint("id", name="tenant_pkey"),)
  159. id = db.Column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  160. name = db.Column(db.String(255), nullable=False)
  161. encrypt_public_key = db.Column(db.Text)
  162. plan = db.Column(db.String(255), nullable=False, server_default=db.text("'basic'::character varying"))
  163. status = db.Column(db.String(255), nullable=False, server_default=db.text("'normal'::character varying"))
  164. custom_config = db.Column(db.Text)
  165. created_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  166. updated_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  167. def get_accounts(self) -> list[Account]:
  168. return (
  169. db.session.query(Account)
  170. .filter(Account.id == TenantAccountJoin.account_id, TenantAccountJoin.tenant_id == self.id)
  171. .all()
  172. )
  173. @property
  174. def custom_config_dict(self) -> dict:
  175. return json.loads(self.custom_config) if self.custom_config else {}
  176. @custom_config_dict.setter
  177. def custom_config_dict(self, value: dict):
  178. self.custom_config = json.dumps(value)
  179. class TenantAccountJoin(Base):
  180. __tablename__ = "tenant_account_joins"
  181. __table_args__ = (
  182. db.PrimaryKeyConstraint("id", name="tenant_account_join_pkey"),
  183. db.Index("tenant_account_join_account_id_idx", "account_id"),
  184. db.Index("tenant_account_join_tenant_id_idx", "tenant_id"),
  185. db.UniqueConstraint("tenant_id", "account_id", name="unique_tenant_account_join"),
  186. )
  187. id = db.Column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  188. tenant_id = db.Column(StringUUID, nullable=False)
  189. account_id = db.Column(StringUUID, nullable=False)
  190. current = db.Column(db.Boolean, nullable=False, server_default=db.text("false"))
  191. role = db.Column(db.String(16), nullable=False, server_default="normal")
  192. invited_by = db.Column(StringUUID, nullable=True)
  193. created_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  194. updated_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  195. class AccountIntegrate(Base):
  196. __tablename__ = "account_integrates"
  197. __table_args__ = (
  198. db.PrimaryKeyConstraint("id", name="account_integrate_pkey"),
  199. db.UniqueConstraint("account_id", "provider", name="unique_account_provider"),
  200. db.UniqueConstraint("provider", "open_id", name="unique_provider_open_id"),
  201. )
  202. id = db.Column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  203. account_id = db.Column(StringUUID, nullable=False)
  204. provider = db.Column(db.String(16), nullable=False)
  205. open_id = db.Column(db.String(255), nullable=False)
  206. encrypted_token = db.Column(db.String(255), nullable=False)
  207. created_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  208. updated_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  209. class InvitationCode(Base):
  210. __tablename__ = "invitation_codes"
  211. __table_args__ = (
  212. db.PrimaryKeyConstraint("id", name="invitation_code_pkey"),
  213. db.Index("invitation_codes_batch_idx", "batch"),
  214. db.Index("invitation_codes_code_idx", "code", "status"),
  215. )
  216. id = db.Column(db.Integer, nullable=False)
  217. batch = db.Column(db.String(255), nullable=False)
  218. code = db.Column(db.String(32), nullable=False)
  219. status = db.Column(db.String(16), nullable=False, server_default=db.text("'unused'::character varying"))
  220. used_at = db.Column(db.DateTime)
  221. used_by_tenant_id = db.Column(StringUUID)
  222. used_by_account_id = db.Column(StringUUID)
  223. deprecated_at = db.Column(db.DateTime)
  224. created_at = db.Column(db.DateTime, nullable=False, server_default=db.text("CURRENT_TIMESTAMP(0)"))
  225. class TenantPluginPermission(Base):
  226. class InstallPermission(enum.StrEnum):
  227. EVERYONE = "everyone"
  228. ADMINS = "admins"
  229. NOBODY = "noone"
  230. class DebugPermission(enum.StrEnum):
  231. EVERYONE = "everyone"
  232. ADMINS = "admins"
  233. NOBODY = "noone"
  234. __tablename__ = "account_plugin_permissions"
  235. __table_args__ = (
  236. db.PrimaryKeyConstraint("id", name="account_plugin_permission_pkey"),
  237. db.UniqueConstraint("tenant_id", name="unique_tenant_plugin"),
  238. )
  239. id: Mapped[str] = mapped_column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  240. tenant_id: Mapped[str] = mapped_column(StringUUID, nullable=False)
  241. install_permission: Mapped[InstallPermission] = mapped_column(
  242. db.String(16), nullable=False, server_default="everyone"
  243. )
  244. debug_permission: Mapped[DebugPermission] = mapped_column(db.String(16), nullable=False, server_default="noone")