Created
October 13, 2022 21:02
-
-
Save simonw/daddf022e75a98ea6246ac1e12dc8759 to your computer and use it in GitHub Desktop.
Alternative version of default_permissions.py in datasette suitable for debugging
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| from datasette import hookimpl | |
| from datasette.utils import actor_matches_allow | |
| @hookimpl(tryfirst=True) | |
| def permission_allowed(datasette, actor, action, resource): | |
| print("permission_allowed actor=", actor, "action=", action, resource) | |
| async def inner(): | |
| result = await _permission_allowed(datasette, actor, action, resource)() | |
| print(" ", result) | |
| return result | |
| return inner | |
| def _permission_allowed(datasette, actor, action, resource): | |
| async def inner(): | |
| if action in ("permissions-debug", "debug-menu"): | |
| if actor and actor.get("id") == "root": | |
| return True | |
| elif action == "view-instance": | |
| allow = datasette.metadata("allow") | |
| if allow is not None: | |
| return actor_matches_allow(actor, allow) | |
| elif action == "view-database": | |
| if resource == "_internal" and (actor is None or actor.get("id") != "root"): | |
| return False | |
| database_allow = datasette.metadata("allow", database=resource) | |
| if database_allow is None: | |
| return None | |
| return actor_matches_allow(actor, database_allow) | |
| elif action == "view-table": | |
| database, table = resource | |
| tables = datasette.metadata("tables", database=database) or {} | |
| table_allow = (tables.get(table) or {}).get("allow") | |
| if table_allow is None: | |
| return None | |
| return actor_matches_allow(actor, table_allow) | |
| elif action == "view-query": | |
| # Check if this query has a "allow" block in metadata | |
| database, query_name = resource | |
| query = await datasette.get_canned_query(database, query_name, actor) | |
| assert query is not None | |
| allow = query.get("allow") | |
| if allow is None: | |
| return None | |
| return actor_matches_allow(actor, allow) | |
| elif action == "execute-sql": | |
| # Use allow_sql block from database block, or from top-level | |
| database_allow_sql = datasette.metadata("allow_sql", database=resource) | |
| if database_allow_sql is None: | |
| database_allow_sql = datasette.metadata("allow_sql") | |
| if database_allow_sql is None: | |
| return None | |
| return actor_matches_allow(actor, database_allow_sql) | |
| return inner |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment