| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363 | 
							- import enum
 - import json
 - from datetime import datetime
 - from typing import Any, Optional
 - 
 - import sqlalchemy as sa
 - from flask_login import UserMixin  # type: ignore[import-untyped]
 - from sqlalchemy import DateTime, String, func, select
 - from sqlalchemy.orm import Mapped, Session, mapped_column, reconstructor
 - from typing_extensions import deprecated
 - 
 - from models.base import Base
 - 
 - from .engine import db
 - from .types import StringUUID
 - 
 - 
 - class TenantAccountRole(enum.StrEnum):
 -     OWNER = "owner"
 -     ADMIN = "admin"
 -     EDITOR = "editor"
 -     NORMAL = "normal"
 -     DATASET_OPERATOR = "dataset_operator"
 - 
 -     @staticmethod
 -     def is_valid_role(role: str) -> bool:
 -         if not role:
 -             return False
 -         return role in {
 -             TenantAccountRole.OWNER,
 -             TenantAccountRole.ADMIN,
 -             TenantAccountRole.EDITOR,
 -             TenantAccountRole.NORMAL,
 -             TenantAccountRole.DATASET_OPERATOR,
 -         }
 - 
 -     @staticmethod
 -     def is_privileged_role(role: Optional["TenantAccountRole"]) -> bool:
 -         if not role:
 -             return False
 -         return role in {TenantAccountRole.OWNER, TenantAccountRole.ADMIN}
 - 
 -     @staticmethod
 -     def is_admin_role(role: Optional["TenantAccountRole"]) -> bool:
 -         if not role:
 -             return False
 -         return role == TenantAccountRole.ADMIN
 - 
 -     @staticmethod
 -     def is_non_owner_role(role: Optional["TenantAccountRole"]) -> bool:
 -         if not role:
 -             return False
 -         return role in {
 -             TenantAccountRole.ADMIN,
 -             TenantAccountRole.EDITOR,
 -             TenantAccountRole.NORMAL,
 -             TenantAccountRole.DATASET_OPERATOR,
 -         }
 - 
 -     @staticmethod
 -     def is_editing_role(role: Optional["TenantAccountRole"]) -> bool:
 -         if not role:
 -             return False
 -         return role in {TenantAccountRole.OWNER, TenantAccountRole.ADMIN, TenantAccountRole.EDITOR}
 - 
 -     @staticmethod
 -     def is_dataset_edit_role(role: Optional["TenantAccountRole"]) -> bool:
 -         if not role:
 -             return False
 -         return role in {
 -             TenantAccountRole.OWNER,
 -             TenantAccountRole.ADMIN,
 -             TenantAccountRole.EDITOR,
 -             TenantAccountRole.DATASET_OPERATOR,
 -         }
 - 
 - 
 - class AccountStatus(enum.StrEnum):
 -     PENDING = "pending"
 -     UNINITIALIZED = "uninitialized"
 -     ACTIVE = "active"
 -     BANNED = "banned"
 -     CLOSED = "closed"
 - 
 - 
 - class Account(UserMixin, Base):
 -     __tablename__ = "accounts"
 -     __table_args__ = (sa.PrimaryKeyConstraint("id", name="account_pkey"), sa.Index("account_email_idx", "email"))
 - 
 -     id: Mapped[str] = mapped_column(StringUUID, server_default=sa.text("uuid_generate_v4()"))
 -     name: Mapped[str] = mapped_column(String(255))
 -     email: Mapped[str] = mapped_column(String(255))
 -     password: Mapped[str | None] = mapped_column(String(255))
 -     password_salt: Mapped[str | None] = mapped_column(String(255))
 -     avatar: Mapped[str | None] = mapped_column(String(255), nullable=True)
 -     interface_language: Mapped[str | None] = mapped_column(String(255))
 -     interface_theme: Mapped[str | None] = mapped_column(String(255), nullable=True)
 -     timezone: Mapped[str | None] = mapped_column(String(255))
 -     last_login_at: Mapped[datetime | None] = mapped_column(DateTime, nullable=True)
 -     last_login_ip: Mapped[str | None] = mapped_column(String(255), nullable=True)
 -     last_active_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp(), nullable=False)
 -     status: Mapped[str] = mapped_column(String(16), server_default=sa.text("'active'::character varying"))
 -     initialized_at: Mapped[datetime | None] = mapped_column(DateTime, nullable=True)
 -     created_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp(), nullable=False)
 -     updated_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp(), nullable=False)
 - 
 -     @reconstructor
 -     def init_on_load(self):
 -         self.role: TenantAccountRole | None = None
 -         self._current_tenant: Tenant | None = None
 - 
 -     @property
 -     def is_password_set(self):
 -         return self.password is not None
 - 
 -     @property
 -     def current_tenant(self):
 -         return self._current_tenant
 - 
 -     @current_tenant.setter
 -     def current_tenant(self, tenant: "Tenant"):
 -         with Session(db.engine, expire_on_commit=False) as session:
 -             tenant_join_query = select(TenantAccountJoin).where(
 -                 TenantAccountJoin.tenant_id == tenant.id, TenantAccountJoin.account_id == self.id
 -             )
 -             tenant_join = session.scalar(tenant_join_query)
 -             tenant_query = select(Tenant).where(Tenant.id == tenant.id)
 -             # TODO: A workaround to reload the tenant with `expire_on_commit=False`, allowing
 -             # access to it after the session has been closed.
 -             # This prevents `DetachedInstanceError` when accessing the tenant outside
 -             # the session's lifecycle.
 -             # (The `tenant` argument is typically loaded by `db.session` without the
 -             # `expire_on_commit=False` flag, meaning its lifetime is tied to the web
 -             # request's lifecycle.)
 -             tenant_reloaded = session.scalars(tenant_query).one()
 - 
 -         if tenant_join:
 -             self.role = TenantAccountRole(tenant_join.role)
 -             self._current_tenant = tenant_reloaded
 -             return
 -         self._current_tenant = None
 - 
 -     @property
 -     def current_tenant_id(self) -> str | None:
 -         return self._current_tenant.id if self._current_tenant else None
 - 
 -     def set_tenant_id(self, tenant_id: str):
 -         query = (
 -             select(Tenant, TenantAccountJoin)
 -             .where(Tenant.id == tenant_id)
 -             .where(TenantAccountJoin.tenant_id == Tenant.id)
 -             .where(TenantAccountJoin.account_id == self.id)
 -         )
 -         with Session(db.engine, expire_on_commit=False) as session:
 -             tenant_account_join = session.execute(query).first()
 -             if not tenant_account_join:
 -                 return
 -             tenant, join = tenant_account_join
 -             self.role = TenantAccountRole(join.role)
 -             self._current_tenant = tenant
 - 
 -     @property
 -     def current_role(self):
 -         return self.role
 - 
 -     def get_status(self) -> AccountStatus:
 -         status_str = self.status
 -         return AccountStatus(status_str)
 - 
 -     @classmethod
 -     def get_by_openid(cls, provider: str, open_id: str):
 -         account_integrate = (
 -             db.session.query(AccountIntegrate)
 -             .where(AccountIntegrate.provider == provider, AccountIntegrate.open_id == open_id)
 -             .one_or_none()
 -         )
 -         if account_integrate:
 -             return db.session.query(Account).where(Account.id == account_integrate.account_id).one_or_none()
 -         return None
 - 
 -     # check current_user.current_tenant.current_role in ['admin', 'owner']
 -     @property
 -     def is_admin_or_owner(self):
 -         return TenantAccountRole.is_privileged_role(self.role)
 - 
 -     @property
 -     def is_admin(self):
 -         return TenantAccountRole.is_admin_role(self.role)
 - 
 -     @property
 -     @deprecated("Use has_edit_permission instead.")
 -     def is_editor(self):
 -         """Determines if the account has edit permissions in their current tenant (workspace).
 - 
 -         This property checks if the current role has editing privileges, which includes:
 -         - `OWNER`
 -         - `ADMIN`
 -         - `EDITOR`
 - 
 -         Note: This checks for any role with editing permission, not just the 'EDITOR' role specifically.
 -         """
 -         return self.has_edit_permission
 - 
 -     @property
 -     def has_edit_permission(self):
 -         """Determines if the account has editing permissions in their current tenant (workspace).
 - 
 -         This property checks if the current role has editing privileges, which includes:
 -         - `OWNER`
 -         - `ADMIN`
 -         - `EDITOR`
 -         """
 -         return TenantAccountRole.is_editing_role(self.role)
 - 
 -     @property
 -     def is_dataset_editor(self):
 -         return TenantAccountRole.is_dataset_edit_role(self.role)
 - 
 -     @property
 -     def is_dataset_operator(self):
 -         return self.role == TenantAccountRole.DATASET_OPERATOR
 - 
 - 
 - class TenantStatus(enum.StrEnum):
 -     NORMAL = "normal"
 -     ARCHIVE = "archive"
 - 
 - 
 - class Tenant(Base):
 -     __tablename__ = "tenants"
 -     __table_args__ = (sa.PrimaryKeyConstraint("id", name="tenant_pkey"),)
 - 
 -     id: Mapped[str] = mapped_column(StringUUID, server_default=sa.text("uuid_generate_v4()"))
 -     name: Mapped[str] = mapped_column(String(255))
 -     encrypt_public_key: Mapped[str | None] = mapped_column(sa.Text)
 -     plan: Mapped[str] = mapped_column(String(255), server_default=sa.text("'basic'::character varying"))
 -     status: Mapped[str] = mapped_column(String(255), server_default=sa.text("'normal'::character varying"))
 -     custom_config: Mapped[str | None] = mapped_column(sa.Text)
 -     created_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp(), nullable=False)
 -     updated_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp())
 - 
 -     def get_accounts(self) -> list[Account]:
 -         return list(
 -             db.session.scalars(
 -                 select(Account).where(
 -                     Account.id == TenantAccountJoin.account_id, TenantAccountJoin.tenant_id == self.id
 -                 )
 -             ).all()
 -         )
 - 
 -     @property
 -     def custom_config_dict(self) -> dict[str, Any]:
 -         return json.loads(self.custom_config) if self.custom_config else {}
 - 
 -     @custom_config_dict.setter
 -     def custom_config_dict(self, value: dict[str, Any]) -> None:
 -         self.custom_config = json.dumps(value)
 - 
 - 
 - class TenantAccountJoin(Base):
 -     __tablename__ = "tenant_account_joins"
 -     __table_args__ = (
 -         sa.PrimaryKeyConstraint("id", name="tenant_account_join_pkey"),
 -         sa.Index("tenant_account_join_account_id_idx", "account_id"),
 -         sa.Index("tenant_account_join_tenant_id_idx", "tenant_id"),
 -         sa.UniqueConstraint("tenant_id", "account_id", name="unique_tenant_account_join"),
 -     )
 - 
 -     id: Mapped[str] = mapped_column(StringUUID, server_default=sa.text("uuid_generate_v4()"))
 -     tenant_id: Mapped[str] = mapped_column(StringUUID)
 -     account_id: Mapped[str] = mapped_column(StringUUID)
 -     current: Mapped[bool] = mapped_column(sa.Boolean, server_default=sa.text("false"))
 -     role: Mapped[str] = mapped_column(String(16), server_default="normal")
 -     invited_by: Mapped[str | None] = mapped_column(StringUUID)
 -     created_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp())
 -     updated_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp())
 - 
 - 
 - class AccountIntegrate(Base):
 -     __tablename__ = "account_integrates"
 -     __table_args__ = (
 -         sa.PrimaryKeyConstraint("id", name="account_integrate_pkey"),
 -         sa.UniqueConstraint("account_id", "provider", name="unique_account_provider"),
 -         sa.UniqueConstraint("provider", "open_id", name="unique_provider_open_id"),
 -     )
 - 
 -     id: Mapped[str] = mapped_column(StringUUID, server_default=sa.text("uuid_generate_v4()"))
 -     account_id: Mapped[str] = mapped_column(StringUUID)
 -     provider: Mapped[str] = mapped_column(String(16))
 -     open_id: Mapped[str] = mapped_column(String(255))
 -     encrypted_token: Mapped[str] = mapped_column(String(255))
 -     created_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp())
 -     updated_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.current_timestamp())
 - 
 - 
 - class InvitationCode(Base):
 -     __tablename__ = "invitation_codes"
 -     __table_args__ = (
 -         sa.PrimaryKeyConstraint("id", name="invitation_code_pkey"),
 -         sa.Index("invitation_codes_batch_idx", "batch"),
 -         sa.Index("invitation_codes_code_idx", "code", "status"),
 -     )
 - 
 -     id: Mapped[int] = mapped_column(sa.Integer)
 -     batch: Mapped[str] = mapped_column(String(255))
 -     code: Mapped[str] = mapped_column(String(32))
 -     status: Mapped[str] = mapped_column(String(16), server_default=sa.text("'unused'::character varying"))
 -     used_at: Mapped[datetime | None] = mapped_column(DateTime)
 -     used_by_tenant_id: Mapped[str | None] = mapped_column(StringUUID)
 -     used_by_account_id: Mapped[str | None] = mapped_column(StringUUID)
 -     deprecated_at: Mapped[datetime | None] = mapped_column(DateTime, nullable=True)
 -     created_at: Mapped[datetime] = mapped_column(DateTime, server_default=sa.text("CURRENT_TIMESTAMP(0)"))
 - 
 - 
 - class TenantPluginPermission(Base):
 -     class InstallPermission(enum.StrEnum):
 -         EVERYONE = "everyone"
 -         ADMINS = "admins"
 -         NOBODY = "noone"
 - 
 -     class DebugPermission(enum.StrEnum):
 -         EVERYONE = "everyone"
 -         ADMINS = "admins"
 -         NOBODY = "noone"
 - 
 -     __tablename__ = "account_plugin_permissions"
 -     __table_args__ = (
 -         sa.PrimaryKeyConstraint("id", name="account_plugin_permission_pkey"),
 -         sa.UniqueConstraint("tenant_id", name="unique_tenant_plugin"),
 -     )
 - 
 -     id: Mapped[str] = mapped_column(StringUUID, server_default=sa.text("uuid_generate_v4()"))
 -     tenant_id: Mapped[str] = mapped_column(StringUUID, nullable=False)
 -     install_permission: Mapped[InstallPermission] = mapped_column(String(16), nullable=False, server_default="everyone")
 -     debug_permission: Mapped[DebugPermission] = mapped_column(String(16), nullable=False, server_default="noone")
 - 
 - 
 - class TenantPluginAutoUpgradeStrategy(Base):
 -     class StrategySetting(enum.StrEnum):
 -         DISABLED = "disabled"
 -         FIX_ONLY = "fix_only"
 -         LATEST = "latest"
 - 
 -     class UpgradeMode(enum.StrEnum):
 -         ALL = "all"
 -         PARTIAL = "partial"
 -         EXCLUDE = "exclude"
 - 
 -     __tablename__ = "tenant_plugin_auto_upgrade_strategies"
 -     __table_args__ = (
 -         sa.PrimaryKeyConstraint("id", name="tenant_plugin_auto_upgrade_strategy_pkey"),
 -         sa.UniqueConstraint("tenant_id", name="unique_tenant_plugin_auto_upgrade_strategy"),
 -     )
 - 
 -     id: Mapped[str] = mapped_column(StringUUID, server_default=sa.text("uuid_generate_v4()"))
 -     tenant_id: Mapped[str] = mapped_column(StringUUID, nullable=False)
 -     strategy_setting: Mapped[StrategySetting] = mapped_column(String(16), nullable=False, server_default="fix_only")
 -     upgrade_time_of_day: Mapped[int] = mapped_column(sa.Integer, nullable=False, default=0)  # seconds of the day
 -     upgrade_mode: Mapped[UpgradeMode] = mapped_column(String(16), nullable=False, server_default="exclude")
 -     exclude_plugins: Mapped[list[str]] = mapped_column(sa.ARRAY(String(255)), nullable=False)  # plugin_id (author/name)
 -     include_plugins: Mapped[list[str]] = mapped_column(sa.ARRAY(String(255)), nullable=False)  # plugin_id (author/name)
 -     created_at: Mapped[datetime] = mapped_column(DateTime, nullable=False, server_default=func.current_timestamp())
 -     updated_at: Mapped[datetime] = mapped_column(DateTime, nullable=False, server_default=func.current_timestamp())
 
 
  |