blob: 422ff4be718ff950fc1e175987e7cd0b4ee57498 [file] [log] [blame]
Siobhan Tully4bc09f22013-04-10 21:15:21 -04001from plstackapi.core.models import Site
Tony Mackf1c12242013-04-09 16:08:43 -04002from plstackapi.core.models import *
Tony Mack02755d42013-05-02 00:00:10 -04003from plstackapi.openstack.manager import OpenStackManager
Tony Macke59a7c82013-04-27 11:08:10 -04004
Tony Mack7130ac32013-03-22 21:58:00 -04005from django.contrib import admin
Siobhan Tully53437282013-04-26 19:30:27 -04006from django.contrib.auth.models import Group
Siobhan Tully4bc09f22013-04-10 21:15:21 -04007from django import forms
Tony Mackd90cdbf2013-04-16 22:48:40 -04008from django.utils.safestring import mark_safe
Tony Mack7130ac32013-03-22 21:58:00 -04009from django.contrib.auth.admin import UserAdmin
Siobhan Tully4bc09f22013-04-10 21:15:21 -040010from django.contrib.admin.widgets import FilteredSelectMultiple
Siobhan Tully53437282013-04-26 19:30:27 -040011from django.contrib.auth.forms import ReadOnlyPasswordHashField
Tony Mack31c2b8f2013-04-26 20:01:42 -040012from django.contrib.auth.signals import user_logged_in
Tony Mack7130ac32013-03-22 21:58:00 -040013
Siobhan Tully4bc09f22013-04-10 21:15:21 -040014
15class ReadonlyTabularInline(admin.TabularInline):
16 can_delete = False
17 extra = 0
18 editable_fields = []
19
20 def get_readonly_fields(self, request, obj=None):
21 fields = []
22 for field in self.model._meta.get_all_field_names():
23 if (not field == 'id'):
24 if (field not in self.editable_fields):
25 fields.append(field)
26 return fields
27
28 def has_add_permission(self, request):
29 return False
30
31class SliverInline(admin.TabularInline):
32 model = Sliver
Tony Mack3777b012013-05-07 21:38:06 -040033 fields = ['ip', 'instance_name', 'slice', 'numberCores', 'image', 'key', 'node', 'deploymentNetwork']
Siobhan Tully4bc09f22013-04-10 21:15:21 -040034 extra = 0
Tony Mack3777b012013-05-07 21:38:06 -040035 #readonly_fields = ['ip', 'instance_name', 'image']
36 readonly_fields = ['ip', 'instance_name']
Siobhan Tully4bc09f22013-04-10 21:15:21 -040037
38class SiteInline(admin.TabularInline):
39 model = Site
40 extra = 0
41
Tony Mack00d361f2013-04-28 10:28:42 -040042class SliceInline(admin.TabularInline):
43 model = Slice
44 extra = 0
45
46class UserInline(admin.TabularInline):
47 model = PLUser
48 extra = 0
49
50class RoleInline(admin.TabularInline):
51 model = Role
52 extra = 0
53
Siobhan Tully4bc09f22013-04-10 21:15:21 -040054class NodeInline(admin.TabularInline):
55 model = Node
56 extra = 0
57
Tony Mack5e71a662013-05-03 23:30:41 -040058class PlainTextWidget(forms.HiddenInput):
59 input_type = 'hidden'
60
61 def render(self, name, value, attrs=None):
62 if value is None:
63 value = ''
Tony Mack1d6b85f2013-05-07 18:49:14 -040064 return mark_safe(str(value) + super(PlainTextWidget, self).render(name, value, attrs))
Tony Mack9bcbe4f2013-04-29 08:13:27 -040065
Siobhan Tully4bc09f22013-04-10 21:15:21 -040066class PlanetStackBaseAdmin(admin.ModelAdmin):
67 save_on_top = False
68
Tony Mackfdd4d802013-04-27 13:02:33 -040069class OSModelAdmin(PlanetStackBaseAdmin):
Tony Mackd685bfa2013-05-02 10:09:51 -040070 """Attach client connection to openstack on delete() and save()"""
Tony Mack79748612013-05-01 14:52:03 -040071
Tony Mackfdd4d802013-04-27 13:02:33 -040072 def save_model(self, request, obj, form, change):
Tony Mack38e247c2013-05-05 11:48:14 -040073 if request.user.site:
74 auth = request.session.get('auth', {})
75 auth['tenant'] = request.user.site.login_base
76 obj.os_manager = OpenStackManager(auth=auth, caller=request.user)
Tony Mackfdd4d802013-04-27 13:02:33 -040077 obj.save()
78
79 def delete_model(self, request, obj):
Tony Mack38e247c2013-05-05 11:48:14 -040080 if request.user.site:
81 auth = request.session.get('auth', {})
82 auth['tenant'] = request.user.site.login_base
83 obj.os_manager = OpenStackManager(auth=auth, caller=request.user)
Tony Mackd685bfa2013-05-02 10:09:51 -040084 obj.delete()
Tony Mack9bcbe4f2013-04-29 08:13:27 -040085
Tony Mackd685bfa2013-05-02 10:09:51 -040086class RoleAdmin(OSModelAdmin):
Tony Mack9bcbe4f2013-04-29 08:13:27 -040087 fieldsets = [
88 ('Role', {'fields': ['role_type']})
89 ]
90 list_display = ('role_type',)
Tony Mackfdd4d802013-04-27 13:02:33 -040091
Tony Mack02755d42013-05-02 00:00:10 -040092
Siobhan Tully4bc09f22013-04-10 21:15:21 -040093class DeploymentNetworkAdminForm(forms.ModelForm):
94 sites = forms.ModelMultipleChoiceField(
95 queryset=Site.objects.all(),
96 required=False,
97 widget=FilteredSelectMultiple(
98 verbose_name=('Sites'), is_stacked=False
99 )
100 )
101 class Meta:
102 model = DeploymentNetwork
103
104 def __init__(self, *args, **kwargs):
105 super(DeploymentNetworkAdminForm, self).__init__(*args, **kwargs)
106
107 if self.instance and self.instance.pk:
108 self.fields['sites'].initial = self.instance.sites.all()
109
110 def save(self, commit=True):
111 deploymentNetwork = super(DeploymentNetworkAdminForm, self).save(commit=False)
Siobhan Tully4bc09f22013-04-10 21:15:21 -0400112 if commit:
113 deploymentNetwork.save()
114
115 if deploymentNetwork.pk:
116 deploymentNetwork.sites = self.cleaned_data['sites']
117 self.save_m2m()
118
119 return deploymentNetwork
120
121class DeploymentNetworkAdmin(PlanetStackBaseAdmin):
122 form = DeploymentNetworkAdminForm
123 inlines = [NodeInline,]
124
Tony Mack5cd13202013-05-01 21:48:38 -0400125 def get_formsets(self, request, obj=None):
126 for inline in self.get_inline_instances(request, obj):
127 # hide MyInline in the add view
128 if obj is None:
129 continue
130 # give inline object access to driver and caller
Tony Macked163d72013-05-02 20:05:42 -0400131 auth = request.session.get('auth', {})
132 auth['tenant'] = request.user.site.login_base
133 inline.model.os_manager = OpenStackManager(auth=auth, caller=request.user)
Tony Mack5cd13202013-05-01 21:48:38 -0400134 yield inline.get_formset(request, obj)
135
Tony Mackfdd4d802013-04-27 13:02:33 -0400136class SiteAdmin(OSModelAdmin):
Siobhan Tully4bc09f22013-04-10 21:15:21 -0400137 fieldsets = [
138 (None, {'fields': ['name', 'site_url', 'enabled', 'is_public', 'login_base']}),
139 ('Location', {'fields': ['latitude', 'longitude']}),
140 ('Deployment Networks', {'fields': ['deployments']})
141 ]
142 list_display = ('name', 'login_base','site_url', 'enabled')
143 filter_horizontal = ('deployments',)
144 inlines = [NodeInline,]
145 search_fields = ['name']
146
Tony Mack04062832013-05-10 08:22:44 -0400147 def queryset(self, request):
148 # admins can see all keys. Users can only see sites they belong to.
149 qs = super(SiteAdmin, self).queryset(request)
150 if not request.user.is_admin:
151 valid_sites = [request.user.site.login_base]
152 roles = request.user.get_roles()
153 for tenant_list in roles.values():
154 valid_sites.extend(tenant_list)
155 qs = qs.filter(login_base__in=valid_sites)
156 return qs
157
Tony Mack5cd13202013-05-01 21:48:38 -0400158 def get_formsets(self, request, obj=None):
159 for inline in self.get_inline_instances(request, obj):
160 # hide MyInline in the add view
161 if obj is None:
162 continue
163 # give inline object access to driver and caller
Tony Mack60722062013-05-02 10:57:04 -0400164 auth = request.session.get('auth', {})
165 auth['tenant'] = request.user.site.login_base
166 inline.model.os_manager = OpenStackManager(auth=auth, caller=request.user)
Tony Mack5cd13202013-05-01 21:48:38 -0400167 yield inline.get_formset(request, obj)
168
Tony Mack9bcbe4f2013-04-29 08:13:27 -0400169class SitePrivilegeAdmin(PlanetStackBaseAdmin):
Tony Mack00d361f2013-04-28 10:28:42 -0400170 fieldsets = [
171 (None, {'fields': ['user', 'site', 'role']})
172 ]
173 list_display = ('user', 'site', 'role')
174
Tony Mack04062832013-05-10 08:22:44 -0400175 def queryset(self, request):
176 # admins can see all privileges. Users can only see privileges at sites
177 # where they have the admin role.
178 qs = super(SitePrivilegeAdmin, self).queryset(request)
179 if not request.user.is_admin:
180 roles = request.user.get_roles()
181 tenants = []
182 for (role, tenant_list) in roles:
183 if role == 'admin':
184 tenants.extend(tenant_list)
185 valid_sites = Sites.objects.filter(login_base__in=tenants)
186 qs = qs.filter(site__in=valid_sites)
187 return qs
188
Tony Mack9bcbe4f2013-04-29 08:13:27 -0400189 def save_model(self, request, obj, form, change):
190 # update openstack connection to use this site/tenant
Tony Mack93048c22013-05-02 11:20:26 -0400191 auth = request.session.get('auth', {})
192 auth['tenant'] = obj.site.login_base
193 obj.os_manager = OpenStackManager(auth=auth, caller=request.user)
Tony Mack9bcbe4f2013-04-29 08:13:27 -0400194 obj.save()
195
196 def delete_model(self, request, obj):
197 # update openstack connection to use this site/tenant
Tony Mack93048c22013-05-02 11:20:26 -0400198 auth = request.session.get('auth', {})
199 auth['tenant'] = obj.site.login_base
200 obj.os_manager = OpenStackManager(auth=auth, caller=request.user)
Tony Mack9bcbe4f2013-04-29 08:13:27 -0400201 obj.delete()
202
Tony Mackfdd4d802013-04-27 13:02:33 -0400203class KeyAdmin(OSModelAdmin):
Tony Mack759b57a2013-04-14 21:03:31 -0400204 fieldsets = [
Tony Mack416c0f22013-05-09 16:59:09 -0400205 ('Key', {'fields': ['key', 'type', 'blacklisted', 'user']})
Tony Mack759b57a2013-04-14 21:03:31 -0400206 ]
Tony Mack416c0f22013-05-09 16:59:09 -0400207 list_display = ['key', 'type', 'blacklisted', 'user']
Tony Mack8484bdb2013-04-14 20:26:03 -0400208
Tony Mackc14de8f2013-05-09 21:44:17 -0400209 def queryset(self, request):
210 # admins can see all keys. Users can only see their own key.
211 if request.user.is_admin:
212 qs = super(KeyAdmin, self).queryset(request)
213 else:
214 qs = Key.objects.filter(user=request.user)
215 return qs
Tony Mack956104d2013-04-27 12:36:19 -0400216
Tony Mackfdd4d802013-04-27 13:02:33 -0400217class SliceAdmin(OSModelAdmin):
Tony Mack659dd522013-05-06 17:06:37 -0400218 fields = ['name', 'site', 'serviceClass', 'description', 'slice_url']
219 list_display = ('name', 'site','serviceClass', 'slice_url')
Siobhan Tully4bc09f22013-04-10 21:15:21 -0400220 inlines = [SliverInline]
221
Tony Mack04062832013-05-10 08:22:44 -0400222 def queryset(self, request):
223 # admins can see all keys. Users can only see slices they belong to.
224 qs = super(SliceAdmin, self).queryset(request)
225 if not request.user.is_admin:
226 valid_slices = []
227 roles = request.user.get_roles()
228 for tenant_list in roles.values():
229 valid_slices.extend(tenant_list)
230 qs = qs.filter(name__in=valid_slices)
231 return qs
232
Tony Mack79748612013-05-01 14:52:03 -0400233 def get_formsets(self, request, obj=None):
234 for inline in self.get_inline_instances(request, obj):
235 # hide MyInline in the add view
236 if obj is None:
237 continue
238 # give inline object access to driver and caller
Tony Mack93048c22013-05-02 11:20:26 -0400239 auth = request.session.get('auth', {})
240 auth['tenant'] = obj.name # meed to connect using slice's tenant
241 inline.model.os_manager = OpenStackManager(auth=auth, caller=request.user)
Tony Mack79748612013-05-01 14:52:03 -0400242 yield inline.get_formset(request, obj)
243
Tony Mackfdd4d802013-04-27 13:02:33 -0400244 def get_queryset(self, request):
245 qs = super(SliceAdmin, self).get_queryset(request)
246 if request.user.is_superuser:
247 return qs
248 # users can only see slices at their site
249 return qs.filter(site=request.user.site)
250
Tony Mack9bcbe4f2013-04-29 08:13:27 -0400251class SliceMembershipAdmin(PlanetStackBaseAdmin):
Tony Mack00d361f2013-04-28 10:28:42 -0400252 fieldsets = [
253 (None, {'fields': ['user', 'slice', 'role']})
254 ]
255 list_display = ('user', 'slice', 'role')
Tony Mack00d361f2013-04-28 10:28:42 -0400256
Tony Mack04062832013-05-10 08:22:44 -0400257 def queryset(self, request):
258 # admins can see all memberships. Users can only see memberships of
259 # slices where they have the admin role.
260 qs = super(SliceMembershipAdmin, self).queryset(request)
261 if not request.user.is_admin:
262 roles = request.user.get_roles()
263 tenants = []
264 for (role, tenant_list) in roles:
265 if role == 'admin':
266 tenants.extend(tenant_list)
267 valid_slices = Slice.objects.filter(name__in=tenants)
268 qs = qs.filter(slice__in=valid_slices)
269 return qs
270
Tony Mack9bcbe4f2013-04-29 08:13:27 -0400271 def save_model(self, request, obj, form, change):
Tony Mack93048c22013-05-02 11:20:26 -0400272 # update openstack connection to use this site/tenant
273 auth = request.session.get('auth', {})
274 auth['tenant'] = obj.slice.name
275 obj.os_manager = OpenStackManager(auth=auth, caller=request.user)
Tony Mack9bcbe4f2013-04-29 08:13:27 -0400276 obj.save()
277
278 def delete_model(self, request, obj):
Tony Mack93048c22013-05-02 11:20:26 -0400279 # update openstack connection to use this site/tenant
280 auth = request.session.get('auth', {})
281 auth['tenant'] = obj.slice.name
282 obj.os_manager = OpenStackManager(auth=auth, caller=request.user)
Tony Mack9bcbe4f2013-04-29 08:13:27 -0400283 obj.delete()
284
Tony Mack93048c22013-05-02 11:20:26 -0400285
Siobhan Tully4bc09f22013-04-10 21:15:21 -0400286class ImageAdmin(admin.ModelAdmin):
287 fields = ['image_id', 'name', 'disk_format', 'container_format']
288
289class NodeAdmin(admin.ModelAdmin):
290 list_display = ('name', 'site', 'deploymentNetwork')
291 list_filter = ('deploymentNetwork',)
292
Tony Mackd90cdbf2013-04-16 22:48:40 -0400293
294class SliverForm(forms.ModelForm):
295 class Meta:
Tony Mack1d6b85f2013-05-07 18:49:14 -0400296 model = Sliver
Tony Mackd90cdbf2013-04-16 22:48:40 -0400297 ip = forms.CharField(widget=PlainTextWidget)
Tony Mack18261812013-05-02 16:39:20 -0400298 instance_name = forms.CharField(widget=PlainTextWidget)
Tony Mackd90cdbf2013-04-16 22:48:40 -0400299 widgets = {
300 'ip': PlainTextWidget(),
Tony Mack18261812013-05-02 16:39:20 -0400301 'instance_name': PlainTextWidget(),
Siobhan Tully53437282013-04-26 19:30:27 -0400302 }
Tony Mackd90cdbf2013-04-16 22:48:40 -0400303
Tony Mack9bcbe4f2013-04-29 08:13:27 -0400304class SliverAdmin(PlanetStackBaseAdmin):
Tony Mackd90cdbf2013-04-16 22:48:40 -0400305 form = SliverForm
Tony Mackcdec0902013-04-15 00:38:49 -0400306 fieldsets = [
Tony Mack10082022013-05-06 17:15:00 -0400307 ('Sliver', {'fields': ['ip', 'instance_name', 'slice', 'numberCores', 'image', 'key', 'node', 'deploymentNetwork']})
Tony Mackcdec0902013-04-15 00:38:49 -0400308 ]
Tony Mack10082022013-05-06 17:15:00 -0400309 list_display = ['ip', 'instance_name', 'slice', 'numberCores', 'image', 'key', 'node', 'deploymentNetwork']
Tony Mack53106f32013-04-27 16:43:01 -0400310
Tony Mack04062832013-05-10 08:22:44 -0400311 def queryset(self, request):
312 # admins can see all slivers. Users can only see slivers of
313 # the slices they belong to.
314 qs = super(SliverAdmin, self).queryset(request)
315 if not request.user.is_admin:
316 tenants = []
317 roles = request.user.get_roles()
318 for tenant_list in roles.values():
319 tenants.extend(tenant_list)
320 valid_slices = Slice.objects.filter(name__in=tenants)
321 qs = qs.filter(slice__in=valid_slices)
322 return qs
323
Tony Mack1d6b85f2013-05-07 18:49:14 -0400324 def get_formsets(self, request, obj=None):
325 # make some fields read only if we are updating an existing record
326 if obj == None:
327 #self.readonly_fields = ('ip', 'instance_name')
328 self.readonly_fields = ()
329 else:
330 self.readonly_fields = ('ip', 'instance_name', 'slice', 'image', 'key')
331
332 for inline in self.get_inline_instances(request, obj):
333 # hide MyInline in the add view
334 if obj is None:
335 continue
336 # give inline object access to driver and caller
337 auth = request.session.get('auth', {})
338 auth['tenant'] = obj.name # meed to connect using slice's tenant
339 inline.model.os_manager = OpenStackManager(auth=auth, caller=request.user)
340 yield inline.get_formset(request, obj)
341
Tony Mack53106f32013-04-27 16:43:01 -0400342 def save_model(self, request, obj, form, change):
Tony Mack951dab42013-05-02 19:51:45 -0400343 # update openstack connection to use this site/tenant
344 auth = request.session.get('auth', {})
345 auth['tenant'] = obj.slice.name
346 obj.os_manager = OpenStackManager(auth=auth, caller=request.user)
Tony Mack53106f32013-04-27 16:43:01 -0400347 obj.save()
348
349 def delete_model(self, request, obj):
Tony Mack951dab42013-05-02 19:51:45 -0400350 # update openstack connection to use this site/tenant
351 auth = request.session.get('auth', {})
352 auth['tenant'] = obj.slice.name
353 obj.os_manager = OpenStackManager(auth=auth, caller=request.user)
Tony Mack53106f32013-04-27 16:43:01 -0400354 obj.delete()
Tony Mackcdec0902013-04-15 00:38:49 -0400355
Siobhan Tully53437282013-04-26 19:30:27 -0400356class UserCreationForm(forms.ModelForm):
357 """A form for creating new users. Includes all the required
358 fields, plus a repeated password."""
359 password1 = forms.CharField(label='Password', widget=forms.PasswordInput)
360 password2 = forms.CharField(label='Password confirmation', widget=forms.PasswordInput)
361
362 class Meta:
363 model = PLUser
364 fields = ('email', 'firstname', 'lastname', 'phone', 'site')
365
366 def clean_password2(self):
367 # Check that the two password entries match
368 password1 = self.cleaned_data.get("password1")
369 password2 = self.cleaned_data.get("password2")
370 if password1 and password2 and password1 != password2:
371 raise forms.ValidationError("Passwords don't match")
372 return password2
373
374 def save(self, commit=True):
375 # Save the provided password in hashed format
376 user = super(UserCreationForm, self).save(commit=False)
Tony Mackf9f4afb2013-05-01 21:02:12 -0400377 user.password = self.cleaned_data["password1"]
378 #user.set_password(self.cleaned_data["password1"])
Siobhan Tully53437282013-04-26 19:30:27 -0400379 if commit:
380 user.save()
381 return user
382
383
384class UserChangeForm(forms.ModelForm):
385 """A form for updating users. Includes all the fields on
386 the user, but replaces the password field with admin's
387 password hash display field.
388 """
389 password = ReadOnlyPasswordHashField()
390
391 class Meta:
392 model = PLUser
393
394 def clean_password(self):
395 # Regardless of what the user provides, return the initial value.
396 # This is done here, rather than on the field, because the
397 # field does not have access to the initial value
398 return self.initial["password"]
399
400
Tony Mack53106f32013-04-27 16:43:01 -0400401class PLUserAdmin(UserAdmin, OSModelAdmin):
Siobhan Tully53437282013-04-26 19:30:27 -0400402 class Meta:
403 app_label = "core"
404
405 # The forms to add and change user instances
406 form = UserChangeForm
407 add_form = UserCreationForm
408
409 # The fields to be used in displaying the User model.
410 # These override the definitions on the base UserAdmin
411 # that reference specific fields on auth.User.
Tony Mack416c0f22013-05-09 16:59:09 -0400412 list_display = ('email', 'site', 'firstname', 'lastname', 'is_admin', 'last_login')
Siobhan Tully53437282013-04-26 19:30:27 -0400413 list_filter = ('site',)
414 fieldsets = (
415 (None, {'fields': ('email', 'password')}),
Tony Mack416c0f22013-05-09 16:59:09 -0400416 ('Personal info', {'fields': ('firstname','lastname','phone', 'is_admin', 'site')}),
Siobhan Tully53437282013-04-26 19:30:27 -0400417 #('Important dates', {'fields': ('last_login',)}),
418 )
419 add_fieldsets = (
420 (None, {
421 'classes': ('wide',),
Tony Mack416c0f22013-05-09 16:59:09 -0400422 'fields': ('email', 'firstname', 'lastname', 'phone', 'site', 'is_admin', 'password1', 'password2')}
Siobhan Tully53437282013-04-26 19:30:27 -0400423 ),
424 )
425 search_fields = ('email',)
426 ordering = ('email',)
427 filter_horizontal = ()
428
Tony Mack31c2b8f2013-04-26 20:01:42 -0400429# register a signal that caches the user's credentials when they log in
430def cache_credentials(sender, user, request, **kwds):
431 auth = {'username': request.POST['username'],
432 'password': request.POST['password']}
433 request.session['auth'] = auth
434user_logged_in.connect(cache_credentials)
435
Siobhan Tully53437282013-04-26 19:30:27 -0400436# Now register the new UserAdmin...
437admin.site.register(PLUser, PLUserAdmin)
438# ... and, since we're not using Django's builtin permissions,
439# unregister the Group model from admin.
440admin.site.unregister(Group)
441
Siobhan Tully4bc09f22013-04-10 21:15:21 -0400442admin.site.register(Site, SiteAdmin)
Tony Mack00d361f2013-04-28 10:28:42 -0400443admin.site.register(SitePrivilege, SitePrivilegeAdmin)
Siobhan Tully4bc09f22013-04-10 21:15:21 -0400444admin.site.register(Slice, SliceAdmin)
Tony Mack00d361f2013-04-28 10:28:42 -0400445admin.site.register(SliceMembership, SliceMembershipAdmin)
Siobhan Tully4bc09f22013-04-10 21:15:21 -0400446admin.site.register(Node, NodeAdmin)
Tony Mackcdec0902013-04-15 00:38:49 -0400447admin.site.register(Sliver, SliverAdmin)
Tony Mack759b57a2013-04-14 21:03:31 -0400448admin.site.register(Key, KeyAdmin)
Tony Mackfd24d0d2013-04-14 00:59:17 -0400449admin.site.register(Role, RoleAdmin)
Siobhan Tully4bc09f22013-04-10 21:15:21 -0400450admin.site.register(DeploymentNetwork, DeploymentNetworkAdmin)
Tony Mack7130ac32013-03-22 21:58:00 -0400451