feat: organize places and device workspaces with scoped heritage records
This commit is contained in:
+5
-2
@@ -64,6 +64,9 @@ class Accounts:
|
||||
raise a.Problem('用户名已存在', 409)
|
||||
role = data.get('role', 'member')
|
||||
access = data.get('familyAccess', 'none')
|
||||
heritage_access = data.get('heritageAccess', old.get('heritageAccess', 'none') if old else 'none')
|
||||
if heritage_access not in ('none', 'read', 'edit'):
|
||||
raise a.Problem('文化与财产档案权限不正确')
|
||||
if role not in ('admin', 'family_admin', 'member') or access not in ('none', 'read', 'edit'):
|
||||
raise a.Problem('权限选项不正确')
|
||||
if actor and actor['role'] != 'admin' and (role == 'admin' or (old and old['role'] == 'admin')):
|
||||
@@ -116,10 +119,10 @@ class Accounts:
|
||||
credentials = self.password(password) if password or not old else {k: old[k] for k in ('salt', 'hash')}
|
||||
user = dict(id=uid, username=username, name=a.clean_text(data.get('name', username), 80, True),
|
||||
role=role, disabled=disabled, familyId=family, siteIds=sorted(set(sites)), familyAccess=access, ptzControl=ptz_control,
|
||||
personId=person, relatedToId=related, includeSubspaces=descendants,
|
||||
personId=person, relatedToId=related, includeSubspaces=descendants, heritageAccess=heritage_access,
|
||||
relationship=a.clean_text(data.get('relationship', ''), 40), **credentials)
|
||||
# Revoke sessions when credentials or authorization change, not for label edits.
|
||||
if old and any(old.get(k) != user.get(k) for k in ('hash', 'role', 'familyId', 'siteIds', 'includeSubspaces', 'familyAccess', 'disabled', 'username', 'ptzControl', 'personId')):
|
||||
if old and any(old.get(k) != user.get(k) for k in ('hash', 'role', 'familyId', 'siteIds', 'includeSubspaces', 'familyAccess', 'heritageAccess', 'disabled', 'username', 'ptzControl', 'personId')):
|
||||
a.DB.execute('DELETE FROM sessions WHERE user_id=?', (uid,))
|
||||
a.save_object('users', user)
|
||||
a.audit('更新账号' if old else '建立账号', username)
|
||||
|
||||
Reference in New Issue
Block a user