2021-04-20 16:47:49 -05:00
|
|
|
import sys
|
|
|
|
|
|
|
|
from django.contrib.contenttypes.models import ContentType
|
2021-04-21 07:27:20 -05:00
|
|
|
from startup_script_utils import load_yaml
|
|
|
|
from users.models import AdminGroup, AdminUser, ObjectPermission
|
2021-04-20 16:47:49 -05:00
|
|
|
|
|
|
|
object_permissions = load_yaml("/opt/netbox/initializers/object_permissions.yml")
|
|
|
|
|
|
|
|
if object_permissions is None:
|
|
|
|
sys.exit()
|
|
|
|
|
|
|
|
|
2021-04-25 10:15:46 -05:00
|
|
|
for permission_name, permission_details in object_permissions.items():
|
2021-04-20 16:47:49 -05:00
|
|
|
|
|
|
|
object_permission, created = ObjectPermission.objects.get_or_create(
|
2021-04-25 10:15:46 -05:00
|
|
|
name=permission_name,
|
2021-04-25 10:59:13 -05:00
|
|
|
description=permission_details["description"],
|
2021-04-25 10:15:46 -05:00
|
|
|
enabled=permission_details["enabled"],
|
|
|
|
actions=permission_details["actions"],
|
2021-04-20 16:47:49 -05:00
|
|
|
)
|
|
|
|
|
2021-04-20 17:05:47 -05:00
|
|
|
# Need to try to pass a list of model_name and app_label for more than the current ALL
|
2021-04-25 10:15:46 -05:00
|
|
|
# object_types = ContentType.objects.filter(app_label__in=permission_details["object_types"])
|
|
|
|
# object_permission.object_types.set(ContentType.objects.filter(app_label__in=permission_details"object_types"]))
|
2021-04-20 16:47:49 -05:00
|
|
|
object_permission.object_types.set(ContentType.objects.all())
|
|
|
|
object_permission.save()
|
|
|
|
|
|
|
|
print("🔓 Created object permission", object_permission.name)
|
2021-04-25 10:59:13 -05:00
|
|
|
|
2021-04-25 10:15:46 -05:00
|
|
|
if permission_details.get("groups", 0):
|
|
|
|
for groupname in permission_details["groups"]:
|
|
|
|
group = AdminGroup.objects.get(name=groupname)
|
|
|
|
|
|
|
|
if group:
|
|
|
|
object_permission.groups.add(group)
|
|
|
|
print(
|
2021-04-25 10:59:13 -05:00
|
|
|
" 👥 Assigned group %s object permission of %s" % (groupname, groupname)
|
2021-04-25 10:15:46 -05:00
|
|
|
)
|
|
|
|
|
|
|
|
if permission_details.get("users", 0):
|
|
|
|
for username in permission_details["users"]:
|
|
|
|
user = AdminUser.objects.get(username=username)
|
|
|
|
|
|
|
|
if user:
|
|
|
|
object_permission.users.add(user)
|
|
|
|
print(
|
2021-04-25 10:59:13 -05:00
|
|
|
" 👤 Assigned user %s object permission of %s" % (username, groupname)
|
2021-04-25 10:15:46 -05:00
|
|
|
)
|
2021-04-20 16:47:49 -05:00
|
|
|
|
|
|
|
object_permission.save()
|