提交 ce772a46 编写于 作者: C colynn

feature: role resource operation make it work

上级 5c769f37
......@@ -20,14 +20,11 @@ package constant
const (
SystemGroup = "system"
SystemAdminRole = "admin"
DevAdminRole = "devManager"
SystemMemberRole = "developer"
SystemAdminUser = "admin"
AdminDefaultPassword = "123456"
// SysDevManager = "devManager"
// TODO: change to sys devmanger
CompanyAdminRole = "devManager"
StepBuild = "build"
StepSubTaskCheckout = "checkout"
......
......@@ -28,11 +28,7 @@ type RoleController struct {
// RoleList ..
func (r *RoleController) RoleList() {
groupName := r.GetStringFromPath(":group")
if groupName == "" {
groupName = "system"
}
rsp, err := dao.GroupRoleList(groupName)
rsp, err := dao.GroupRoleList("system")
if err != nil {
r.HandleInternalServerError(err.Error())
log.Log.Error("Get role list error: %s", err.Error())
......@@ -43,10 +39,9 @@ func (r *RoleController) RoleList() {
}
func (r *RoleController) GetRole() {
groupName := r.GetStringFromPath(":group")
roleName := r.GetStringFromPath(":role")
rsp, err := dao.GetGroupRoleByName(groupName, roleName)
rsp, err := dao.GetGroupRoleByName("system", roleName)
if err != nil {
r.HandleInternalServerError(err.Error())
log.Log.Error("Get role error: %s", err.Error())
......@@ -80,11 +75,10 @@ func (r *RoleController) CreateRole() {
}
func (r *RoleController) UpdateRole() {
groupName := r.GetStringFromPath(":group")
roleName := r.GetStringFromPath(":role")
var req models.GroupRoleReq
r.DecodeJSONReq(&req)
req.Group = groupName
req.Group = "system"
req.Role = roleName
if err := req.Verify(); err != nil {
......@@ -104,10 +98,8 @@ func (r *RoleController) UpdateRole() {
}
func (r *RoleController) DeleteRole() {
groupName := r.GetStringFromPath(":group")
roleName := r.GetStringFromPath(":role")
if err := dao.DeleteGroupRole(groupName, roleName); err != nil {
if err := dao.DeleteGroupRole("system", roleName); err != nil {
r.HandleInternalServerError(err.Error())
log.Log.Error("Delete role error: %s", err.Error())
return
......@@ -166,26 +158,40 @@ func (r *RoleController) RoleUnbundling() {
r.ServeJSON()
}
func (r *RoleController) RolePolicyList() {
// groupName := r.GetStringFromPath(":group")
// roleName := r.GetStringFromPath(":role")
// TODO: need change role resources list
rsp := []string{}
func (r *RoleController) RoleOperationList() {
roleName := r.GetStringFromPath(":role")
rolesOperations, err := dao.GetRoleOperationsByRoleName(roleName)
if err != nil {
r.HandleInternalServerError(err.Error())
log.Log.Error("get role operations by role name error: %s", err.Error())
return
}
resIDs := []int64{}
for _, item := range rolesOperations {
resIDs = append(resIDs, item.OperationID)
}
rsp, err := dao.GetResourceOperationByIDs(resIDs)
if err != nil {
r.HandleInternalServerError(err.Error())
log.Log.Error("get role operations by ids error: %s", err.Error())
return
}
r.Data["json"] = NewResult(true, rsp, "")
r.ServeJSON()
}
func (r *RoleController) AddRolePolicy() {
groupName := r.GetStringFromPath(":group")
func (r *RoleController) AddRoleOperation() {
roleName := r.GetStringFromPath(":role")
var req models.GroupRolePolicyReq
r.DecodeJSONReq(&req)
req.Group = groupName
req.Group = "system"
req.Role = roleName
if err := dao.AddRoleOperation(&req); err != nil {
r.HandleInternalServerError(err.Error())
log.Log.Error("Add role policy error: %s", err.Error())
log.Log.Error("Add role operation error: %s", err.Error())
return
}
......@@ -193,13 +199,12 @@ func (r *RoleController) AddRolePolicy() {
r.ServeJSON()
}
func (r *RoleController) RemoveRolePolicy() {
groupName := r.GetStringFromPath(":group")
func (r *RoleController) RemoveRoleOperation() {
roleName := r.GetStringFromPath(":role")
var req models.GroupRolePolicyReq
r.DecodeJSONReq(&req)
req.Group = groupName
operationID, _ := r.GetInt64FromPath(":operationID")
req := models.GroupRolePolicyReq{}
req.Role = roleName
req.Operations = []int64{operationID}
if err := dao.DeleteGroupRolePolicy(&req); err != nil {
r.HandleInternalServerError(err.Error())
......
......@@ -94,10 +94,6 @@ func BatchCreateResourceType(req models.BatchResourceTypeReq) error {
if _, err := GetOrmer().Raw(sql, resourceType, resource.ResourceType.Description).Exec(); err != nil {
return err
}
sql = `insert ignore into sys_resource_operation(resource_type,resource_operation,description) values(?,'*','所有操作')`
if _, err := GetOrmer().Raw(sql, resourceType).Exec(); err != nil {
return err
}
if len(resource.ResourceOperations) > 0 {
values := ""
......@@ -137,9 +133,7 @@ func CreateResourceType(resourceType, description string) (*models.ResourceType,
if _, err := GetOrmer().Raw(sql, resourceType, description).Exec(); err != nil {
return nil, err
}
if err := AddResourceOperation(resourceType, "*", "所有操作"); err != nil {
return nil, err
}
res, err := GetResourceTypeDetail(resourceType, []string{}, []string{})
if err != nil {
return nil, err
......@@ -194,6 +188,36 @@ func GetResourceOperation(resourceType, resourceOperation string) (*models.Resou
return &op, nil
}
func GetResourceOperationByResourceTypes(resourceTypes []string) ([]*models.ResourceOperation, error) {
var resItems []*models.ResourceOperation
if _, err := GetOrmer().QueryTable("sys_resource_operation").
Filter("resource_type__in", resourceTypes).
All(&resItems); err != nil {
return nil, err
}
return resItems, nil
}
func GetResourceOperationByResourceOperations(resourceOperations []string) ([]*models.ResourceOperation, error) {
var resItems []*models.ResourceOperation
if _, err := GetOrmer().QueryTable("sys_resource_operation").
Filter("resource_operation__in", resourceOperations).
All(&resItems); err != nil {
return nil, err
}
return resItems, nil
}
func GetResourceOperationByIDs(resourceItemIDs []int64) ([]*models.ResourceOperation, error) {
var resItems []*models.ResourceOperation
if _, err := GetOrmer().QueryTable("sys_resource_operation").
Filter("id__in", resourceItemIDs).
All(&resItems); err != nil {
return nil, err
}
return resItems, nil
}
func AddResourceOperation(resourceType, resourceOperation, description string) error {
sql := `insert into sys_resource_operation(resource_type,resource_operation,description) values(?,?,?)`
if _, err := GetOrmer().Raw(sql, resourceType, resourceOperation, description).Exec(); err != nil {
......@@ -266,11 +290,7 @@ func GetUserConstraintByKey(user string, constraintKey []string) (map[string][]s
}
res := map[string][]string{}
for _, con := range constraints {
if _, ok := res[con.Constraint]; ok {
res[con.Constraint] = append(res[con.Constraint], con.Value)
} else {
res[con.Constraint] = []string{con.Value}
}
res[con.Constraint] = append(res[con.Constraint], con.Value)
}
return res, nil
}
......@@ -21,6 +21,7 @@ import (
"strings"
"github.com/go-atomci/atomci/models"
"github.com/isbrick/tools"
)
func CreateGatewayRoute(router, method, backend, resourceType, resourceOperation string) error {
......@@ -32,11 +33,15 @@ func CreateGatewayRoute(router, method, backend, resourceType, resourceOperation
}
// GetResourceRouterItems ..
func GetResourceRouterItems(resourceOperations []string) ([]models.GatewayRouter, error) {
func GetResourceRouterItems(resourceType string, resourceOperations []string) ([]models.GatewayRouter, error) {
routerItems := []models.GatewayRouter{}
query := GetOrmer().QueryTable("sys_resource_router")
if len(resourceOperations) > 0 {
query = query.Filter("resource_operation__in", resourceOperations)
if tools.IsSliceContainsStr(resourceOperations, "*") {
query = query.Filter("resource_type", resourceType)
} else {
query = query.Filter("resource_operation__in", resourceOperations)
}
}
if _, err := query.All(&routerItems); err != nil {
return nil, err
......
......@@ -50,6 +50,17 @@ func GetGroupRoleByName(group, role string) (*models.GroupRole, error) {
return &groupRole, nil
}
func GetRoleOperationsByRoleName(role string) ([]*models.GroupRoleOperation, error) {
roleOperations := []*models.GroupRoleOperation{}
if _, err := GetOrmer().QueryTable("sys_group_role_operation").
Filter("group", "system").
Filter("role", role).
All(&roleOperations); err != nil {
return nil, err
}
return roleOperations, nil
}
func CreateGroupRole(req *models.GroupRoleReq) (*models.GroupRole, error) {
role, _ := GetGroupRoleByName(req.Group, req.Role)
if role == nil {
......@@ -70,12 +81,23 @@ func CreateGroupRole(req *models.GroupRoleReq) (*models.GroupRole, error) {
// TODO: generate casbin rules rely on req.Operations
log.Log.Debug("req operations length: %v", len(req.Operations))
resourceRouterItems, err := GetResourceRouterItems(req.Operations)
resOperationItems, err := GetResourceOperationByIDs(req.Operations)
if err != nil {
log.Log.Error("when create group role, get resource router items error: %s", err.Error())
log.Log.Error("when get resource operation by ids occur error: %s", err.Error())
return nil, err
}
resTypeOperationsMapping := orderByResourceType(resOperationItems)
resourceRouterItems := []models.GatewayRouter{}
for key, item := range resTypeOperationsMapping {
resRouterItems, err := GetResourceRouterItems(key, item)
if err != nil {
log.Log.Error("when create group role, get resource router items error: %s", err.Error())
continue
}
resourceRouterItems = append(resourceRouterItems, resRouterItems...)
}
if len(resourceRouterItems) > 0 {
casbinRules := generateCasbinRules(resourceRouterItems, req.Role)
e, err := mycasbin.NewCasbin()
......@@ -171,14 +193,14 @@ func GroupRoleUnbundling(req *models.GroupRoleBundlingReq) error {
func AddRoleOperation(req *models.GroupRolePolicyReq) error {
if len(req.Operations) > 0 {
values := ""
for index, policy := range req.Operations {
for index, operationID := range req.Operations {
if index == 0 {
values = fmt.Sprintf("('%v','%v','%v')", req.Group, req.Role, policy)
values = fmt.Sprintf("('%v','%v',%v)", req.Group, req.Role, operationID)
} else {
values = values + "," + fmt.Sprintf("('%v','%v','%v')", req.Group, req.Role, policy)
values = values + "," + fmt.Sprintf("('%v','%v',%v)", req.Group, req.Role, operationID)
}
}
sql := `insert ignore into sys_group_role_operation(` + "`group`" + `,role,policy_name) values` + values
sql := `insert ignore into sys_group_role_operation(` + "`group`" + `,role, operation_id) values` + values
if _, err := GetOrmer().Raw(sql).Exec(); err != nil {
return err
}
......@@ -196,10 +218,20 @@ func DeleteGroupRolePolicy(req *models.GroupRolePolicyReq) error {
values = values + "," + fmt.Sprintf("'%v'", police)
}
}
sql := `delete from sys_group_role_operation where ` + "`group`" + `=? and role=? and policy_name in (` + values + `)`
if _, err := GetOrmer().Raw(sql, req.Group, req.Role).Exec(); err != nil {
sql := `delete from sys_group_role_operation where ` + `role=? and operation_id in (` + values + `)`
if _, err := GetOrmer().Raw(sql, req.Role).Exec(); err != nil {
return err
}
// TODO: clean casbin item
}
return nil
}
func orderByResourceType(res []*models.ResourceOperation) map[string][]string {
resMap := map[string][]string{}
for _, item := range res {
resMap[item.ResourceType] = append(resMap[item.ResourceType], item.ResourceOperation)
}
return resMap
}
......@@ -99,7 +99,7 @@ func GetUserDetail(userName string) (*models.User, error) {
user.GroupAdmin = 1
break
}
if role.Role == constant.CompanyAdminRole {
if role.Role == constant.DevAdminRole {
user.GroupAdmin = 1
}
}
......
ALTER TABLE atomci.sys_group_role_operation DROP KEY `group`;
ALTER TABLE atomci.sys_group_role_operation ADD CONSTRAINT roleOperation UNIQUE (role, operation_id);
\ No newline at end of file
......@@ -43,6 +43,7 @@ require (
github.com/google/go-cmp v0.5.5 // indirect
github.com/google/uuid v1.2.0 // indirect
github.com/gorilla/websocket v1.4.2
github.com/isbrick/tools v0.0.0-20211027093338-a3a0ded37175
github.com/kr/text v0.2.0 // indirect
github.com/nbio/st v0.0.0-20140626010706-e9e8d9816f32 // indirect
github.com/niemeyer/pretty v0.0.0-20200227124842-a10e7caefd8e // indirect
......
......@@ -416,6 +416,8 @@ github.com/inconshreveable/mousetrap v1.0.0 h1:Z8tu5sraLXCXIcARxBp/8cbvlwVa7Z1NH
github.com/inconshreveable/mousetrap v1.0.0/go.mod h1:PxqpIevigyE2G7u3NXJIT2ANytuPF1OarO4DADm73n8=
github.com/isbrick/http-client v0.0.0-20210321135403-0a5df00fdb84 h1:f+X6/PyYYWQx2LQEUwCEdZiLxYHrpc4b87KFBHrZBnE=
github.com/isbrick/http-client v0.0.0-20210321135403-0a5df00fdb84/go.mod h1:ILI7SGUToE8ebBaVw9+tdlWlj2naGFmnMU+FrQj+6ro=
github.com/isbrick/tools v0.0.0-20211027093338-a3a0ded37175 h1:HnZgYkC7M0z/0Ll+qXQS2jizZgWjSkC90j6HDmr/SuM=
github.com/isbrick/tools v0.0.0-20211027093338-a3a0ded37175/go.mod h1:3jxvSrtFqeDL15wHztv4lLjQqB1YiPU3jAewh3LwUW0=
github.com/jellevandenhooff/dkim v0.0.0-20150330215556-f50fe3d243e1/go.mod h1:E0B/fFc00Y+Rasa88328GlI/XbtyysCtTHZS8h7IrBU=
github.com/jimstudt/http-authentication v0.0.0-20140401203705-3eca13d6893a/go.mod h1:wK6yTYYcgjHE1Z1QtXACPDjcFJyBskHEdagmnq3vsP8=
github.com/jmespath/go-jmespath v0.0.0-20180206201540-c2b33e8439af/go.mod h1:Nht3zPeWKUH0NzdCt2Blrr5ys8VGpn0CEB0cQHVjt7k=
......
......@@ -93,26 +93,83 @@ func initAdminUser() (int64, error) {
// 初始化系统角色和管理员用户
func initSystemRole() error {
adminResourceItem, err := dao.GetResourceOperation("*", "*")
if err != nil {
return err
}
memberResourceOperationIDs := []int64{}
devAdminResourceOperationIDs := []int64{}
devAdminResourceOperations, err := dao.GetResourceOperationByResourceTypes([]string{"pipeline", "project", "publish"})
if err != nil {
return err
}
for _, item := range devAdminResourceOperations {
devAdminResourceOperationIDs = append(devAdminResourceOperationIDs, item.ID)
}
sysMemberResourceOperations, err := dao.GetResourceOperationByResourceOperations([]string{
"ProjectList",
"CreateProject",
"UpdateProject",
"GetProject",
"CreateProjectApp",
"UpdateProjectApp",
"GetProjectApps",
"GetProjectApp",
"GetAppsByPagination",
"GetArrange",
"SetArrange",
"GetAppBranches",
"SyncAppBranches",
"SwitchProjectBranch",
"DeleteProjectApp",
"PublishList",
"CreatePublishOrder",
"GetPublish",
"ClosePublish",
"DeletePublish",
"GetCanAddedApps",
"AddPublishApp",
"DeletePublishApp",
"GetOpertaionLogByPagination",
"GetBackTo",
"TriggerBackTo",
"GetNextStage",
"TriggerNextStage",
"GetStepInfo",
"RunStep",
"RunStepCallback",
})
if err != nil {
return err
}
for _, item := range sysMemberResourceOperations {
memberResourceOperationIDs = append(memberResourceOperationIDs, item.ID)
}
roles := []models.GroupRoleReq{
{
Group: constant.SystemGroup,
Role: constant.SystemAdminRole,
Description: "超级管理员",
Operations: []string{"*"},
Operations: []int64{adminResourceItem.ID},
},
{
Group: constant.SystemGroup,
Role: constant.SystemMemberRole,
Description: "普通成员",
// TODO: change to real resouce operation
Operations: []string{"CreateProject"},
Operations: memberResourceOperationIDs,
},
{
Group: constant.SystemGroup,
Role: constant.CompanyAdminRole,
Role: constant.DevAdminRole,
Description: "项目管理员",
// TODO: change to real resouce operation
Operations: []string{"CreateProject"},
Operations: devAdminResourceOperationIDs,
},
}
for _, role := range roles {
......
......@@ -166,7 +166,7 @@ func initOrm() {
new(GroupRoleUser),
new(GroupUserConstraint),
new(GroupRole),
new(GroupRolePolicy),
new(GroupRoleOperation),
new(Audit),
new(GatewayRouter),
......
......@@ -51,10 +51,10 @@ func (t *GroupRole) TableUnique() [][]string {
// GroupRoleReq ..
type GroupRoleReq struct {
Group string `json:"group"`
Role string `json:"role"`
Description string `json:"description"`
Operations []string `json:"operations"`
Group string `json:"group"`
Role string `json:"role"`
Description string `json:"description"`
Operations []int64 `json:"operations"`
}
// Verify ..
......@@ -76,37 +76,38 @@ type RoleRsp struct {
Description string `json:"description"`
}
type GroupRolePolicy struct {
type GroupRoleOperation struct {
Addons
Group string `orm:"column(group)" json:"group"`
Role string `orm:"column(role)" json:"role"`
PolicyName string `orm:"column(policy_name)" json:"policy_name"`
Group string `orm:"column(group)" json:"group"`
Role string `orm:"column(role)" json:"role"`
PolicyName string `orm:"column(policy_name)" json:"policy_name"`
OperationID int64 `orm:"column(operation_id)" json:"operation_id"`
}
// TableName ..
func (t *GroupRolePolicy) TableName() string {
func (t *GroupRoleOperation) TableName() string {
return "sys_group_role_operation"
}
// TableIndex ..
func (t *GroupRolePolicy) TableIndex() [][]string {
func (t *GroupRoleOperation) TableIndex() [][]string {
return [][]string{
{"Group", "Role"},
}
}
// TableUnique ..
func (t *GroupRolePolicy) TableUnique() [][]string {
func (t *GroupRoleOperation) TableUnique() [][]string {
return [][]string{
{"Group", "Role", "PolicyName"},
{"Group", "Role", "OperationID"},
}
}
// GroupRolePolicyReq ..
type GroupRolePolicyReq struct {
Group string `json:"group"`
Role string `json:"role"`
Operations []string `json:"operations"`
Group string `json:"group"`
Role string `json:"role"`
Operations []int64 `json:"operations"`
}
type GroupRoleBundlingUser struct {
......
......@@ -73,9 +73,10 @@ func init() {
beego.NSRouter("/roles", &controllers.RoleController{}, "get:RoleList;post:CreateRole"),
beego.NSRouter("/groups/:group/roles", &controllers.RoleController{}, "get:RoleList;post:CreateRole"),
beego.NSRouter("/groups/:group/roles/:role", &controllers.RoleController{}, "get:GetRole;put:UpdateRole;delete:DeleteRole"),
beego.NSRouter("/groups/:group/roles/:role/policies", &controllers.RoleController{}, "get:RolePolicyList;post:AddRolePolicy;delete:RemoveRolePolicy"),
beego.NSRouter("/roles", &controllers.RoleController{}, "get:RoleList;post:CreateRole"),
beego.NSRouter("/roles/:role", &controllers.RoleController{}, "get:GetRole;put:UpdateRole;delete:DeleteRole"),
beego.NSRouter("/roles/:role/operations", &controllers.RoleController{}, "get:RoleOperationList;post:AddRoleOperation"),
beego.NSRouter("/roles/:role/operations/:operationID", &controllers.RoleController{}, "delete:RemoveRoleOperation"),
beego.NSRouter("/groups/:group/roles/:role/bundling", &controllers.RoleController{}, "get:RoleBundlingList;post:RoleBundling;delete:RoleUnbundling"),
// PipelineStage
......
Apache License
Version 2.0, January 2004
http://www.apache.org/licenses/
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
1. Definitions.
"License" shall mean the terms and conditions for use, reproduction,
and distribution as defined by Sections 1 through 9 of this document.
"Licensor" shall mean the copyright owner or entity authorized by
the copyright owner that is granting the License.
"Legal Entity" shall mean the union of the acting entity and all
other entities that control, are controlled by, or are under common
control with that entity. For the purposes of this definition,
"control" means (i) the power, direct or indirect, to cause the
direction or management of such entity, whether by contract or
otherwise, or (ii) ownership of fifty percent (50%) or more of the
outstanding shares, or (iii) beneficial ownership of such entity.
"You" (or "Your") shall mean an individual or Legal Entity
exercising permissions granted by this License.
"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation
source, and configuration files.
"Object" form shall mean any form resulting from mechanical
transformation or translation of a Source form, including but
not limited to compiled object code, generated documentation,
and conversions to other media types.
"Work" shall mean the work of authorship, whether in Source or
Object form, made available under the License, as indicated by a
copyright notice that is included in or attached to the work
(an example is provided in the Appendix below).
"Derivative Works" shall mean any work, whether in Source or Object
form, that is based on (or derived from) the Work and for which the
editorial revisions, annotations, elaborations, or other modifications
represent, as a whole, an original work of authorship. For the purposes
of this License, Derivative Works shall not include works that remain
separable from, or merely link (or bind by name) to the interfaces of,
the Work and Derivative Works thereof.
"Contribution" shall mean any work of authorship, including
the original version of the Work and any modifications or additions
to that Work or Derivative Works thereof, that is intentionally
submitted to Licensor for inclusion in the Work by the copyright owner
or by an individual or Legal Entity authorized to submit on behalf of
the copyright owner. For the purposes of this definition, "submitted"
means any form of electronic, verbal, or written communication sent
to the Licensor or its representatives, including but not limited to
communication on electronic mailing lists, source code control systems,
and issue tracking systems that are managed by, or on behalf of, the
Licensor for the purpose of discussing and improving the Work, but
excluding communication that is conspicuously marked or otherwise
designated in writing by the copyright owner as "Not a Contribution."
"Contributor" shall mean Licensor and any individual or Legal Entity
on behalf of whom a Contribution has been received by Licensor and
subsequently incorporated within the Work.
2. Grant of Copyright License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
copyright license to reproduce, prepare Derivative Works of,
publicly display, publicly perform, sublicense, and distribute the
Work and such Derivative Works in Source or Object form.
3. Grant of Patent License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
(except as stated in this section) patent license to make, have made,
use, offer to sell, sell, import, and otherwise transfer the Work,
where such license applies only to those patent claims licensable
by such Contributor that are necessarily infringed by their
Contribution(s) alone or by combination of their Contribution(s)
with the Work to which such Contribution(s) was submitted. If You
institute patent litigation against any entity (including a
cross-claim or counterclaim in a lawsuit) alleging that the Work
or a Contribution incorporated within the Work constitutes direct
or contributory patent infringement, then any patent licenses
granted to You under this License for that Work shall terminate
as of the date such litigation is filed.
4. Redistribution. You may reproduce and distribute copies of the
Work or Derivative Works thereof in any medium, with or without
modifications, and in Source or Object form, provided that You
meet the following conditions:
(a) You must give any other recipients of the Work or
Derivative Works a copy of this License; and
(b) You must cause any modified files to carry prominent notices
stating that You changed the files; and
(c) You must retain, in the Source form of any Derivative Works
that You distribute, all copyright, patent, trademark, and
attribution notices from the Source form of the Work,
excluding those notices that do not pertain to any part of
the Derivative Works; and
(d) If the Work includes a "NOTICE" text file as part of its
distribution, then any Derivative Works that You distribute must
include a readable copy of the attribution notices contained
within such NOTICE file, excluding those notices that do not
pertain to any part of the Derivative Works, in at least one
of the following places: within a NOTICE text file distributed
as part of the Derivative Works; within the Source form or
documentation, if provided along with the Derivative Works; or,
within a display generated by the Derivative Works, if and
wherever such third-party notices normally appear. The contents
of the NOTICE file are for informational purposes only and
do not modify the License. You may add Your own attribution
notices within Derivative Works that You distribute, alongside
or as an addendum to the NOTICE text from the Work, provided
that such additional attribution notices cannot be construed
as modifying the License.
You may add Your own copyright statement to Your modifications and
may provide additional or different license terms and conditions
for use, reproduction, or distribution of Your modifications, or
for any such Derivative Works as a whole, provided Your use,
reproduction, and distribution of the Work otherwise complies with
the conditions stated in this License.
5. Submission of Contributions. Unless You explicitly state otherwise,
any Contribution intentionally submitted for inclusion in the Work
by You to the Licensor shall be under the terms and conditions of
this License, without any additional terms or conditions.
Notwithstanding the above, nothing herein shall supersede or modify
the terms of any separate license agreement you may have executed
with Licensor regarding such Contributions.
6. Trademarks. This License does not grant permission to use the trade
names, trademarks, service marks, or product names of the Licensor,
except as required for reasonable and customary use in describing the
origin of the Work and reproducing the content of the NOTICE file.
7. Disclaimer of Warranty. Unless required by applicable law or
agreed to in writing, Licensor provides the Work (and each
Contributor provides its Contributions) on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
implied, including, without limitation, any warranties or conditions
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
PARTICULAR PURPOSE. You are solely responsible for determining the
appropriateness of using or redistributing the Work and assume any
risks associated with Your exercise of permissions under this License.
8. Limitation of Liability. In no event and under no legal theory,
whether in tort (including negligence), contract, or otherwise,
unless required by applicable law (such as deliberate and grossly
negligent acts) or agreed to in writing, shall any Contributor be
liable to You for damages, including any direct, indirect, special,
incidental, or consequential damages of any character arising as a
result of this License or out of the use or inability to use the
Work (including but not limited to damages for loss of goodwill,
work stoppage, computer failure or malfunction, or any and all
other commercial damages or losses), even if such Contributor
has been advised of the possibility of such damages.
9. Accepting Warranty or Additional Liability. While redistributing
the Work or Derivative Works thereof, You may choose to offer,
and charge a fee for, acceptance of support, warranty, indemnity,
or other liability obligations and/or rights consistent with this
License. However, in accepting such obligations, You may act only
on Your own behalf and on Your sole responsibility, not on behalf
of any other Contributor, and only if You agree to indemnify,
defend, and hold each Contributor harmless for any liability
incurred by, or claims asserted against, such Contributor by reason
of your accepting any such warranty or additional liability.
END OF TERMS AND CONDITIONS
APPENDIX: How to apply the Apache License to your work.
To apply the Apache License to your work, attach the following
boilerplate notice, with the fields enclosed by brackets "[]"
replaced with your own identifying information. (Don't include
the brackets!) The text should be enclosed in the appropriate
comment syntax for the file format. We also recommend that a
file or class name and description of purpose be included on the
same "printed page" as the copyright notice for easier
identification within third-party archives.
Copyright 2020 colynn.liu
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
\ No newline at end of file
## tools
![Go](https://github.com/isbrick/tools/workflows/Go/badge.svg)
[![codecov](https://codecov.io/gh/isbrick/tools/branch/master/graph/badge.svg)](https://codecov.io/gh/isbrick/tools)
[![Go Report Card](https://goreportcard.com/badge/github.com/isbrick/tools)](https://goreportcard.com/report/github.com/isbrick/tools)
[![GoDoc](https://godoc.org/github.com/isbrick/tools?status.svg)](https://pkg.go.dev/github.com/isbrick/tools?tab=doc)
\ No newline at end of file
// Copyright 2020 tools authors
//
// Licensed under the Apache License, Version 2.0 (the "License"): you may
// not use this file except in compliance with the License. You may obtain
// a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
// WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
// License for the specific language governing permissions and limitations
// under the License.
package tools
import (
"os"
"os/exec"
"path/filepath"
"sync"
)
// EnsureAbs prepends the WorkDir to the given path if it is not an absolute path.
func EnsureAbs(path string) string {
if filepath.IsAbs(path) {
return path
}
return filepath.Join(WorkDir(), path)
}
var (
workDir string
workDirOnce sync.Once
)
// WorkDir returns the absolute path of work directory. It reads the value of envrionment
// variable GOGS_WORK_DIR. When not set, it uses the directory where the application's
// binary is located.
func WorkDir() string {
workDirOnce.Do(func() {
workDir = filepath.Dir(AppPath())
})
return workDir
}
var (
appPath string
appPathOnce sync.Once
)
// AppPath returns the absolute path of the application's binary.
func AppPath() string {
appPathOnce.Do(func() {
var err error
appPath, err = exec.LookPath(os.Args[0])
if err != nil {
panic("look executable path: " + err.Error())
}
appPath, err = filepath.Abs(appPath)
if err != nil {
panic("get absolute executable path: " + err.Error())
}
})
return appPath
}
package tools
import (
"strconv"
)
// Convert string to specify type.
type StrTo string
func (f StrTo) Exist() bool {
return string(f) != string(rune(0x1E))
}
func (f StrTo) Uint8() (uint8, error) {
v, err := strconv.ParseUint(f.String(), 10, 8)
return uint8(v), err
}
func (f StrTo) Int() (int, error) {
v, err := strconv.ParseInt(f.String(), 10, 0)
return int(v), err
}
func (f StrTo) Int64() (int64, error) {
v, err := strconv.ParseInt(f.String(), 10, 64)
return int64(v), err
}
func (f StrTo) Float64() (float64, error) {
v, err := strconv.ParseFloat(f.String(), 64)
return float64(v), err
}
func (f StrTo) MustUint8() uint8 {
v, _ := f.Uint8()
return v
}
func (f StrTo) MustInt() int {
v, _ := f.Int()
return v
}
func (f StrTo) MustInt64() int64 {
v, _ := f.Int64()
return v
}
func (f StrTo) MustFloat64() float64 {
v, _ := f.Float64()
return v
}
func (f StrTo) String() string {
if f.Exist() {
return string(f)
}
return ""
}
module github.com/isbrick/tools
go 1.14
require github.com/stretchr/testify v1.6.1
github.com/davecgh/go-spew v1.1.0 h1:ZDRjVQ15GmhC3fiQ8ni8+OwkZQO4DARzQgrnXU1Liz8=
github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
github.com/stretchr/testify v1.6.1 h1:hDPOHmpOpP40lSULcqw7IrRb/u7w6RpDC9399XyoNd0=
github.com/stretchr/testify v1.6.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405 h1:yhCVgyC4o1eVCa2tZl7eS0r+SDo693bJlVdllGtEeKM=
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c h1:dUUwHk2QECo/6vqA44rthZ8ie2QXMNeKRTHCNY2nXvo=
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
// Copyright 2020 tools authors
//
// Licensed under the Apache License, Version 2.0 (the "License"): you may
// not use this file except in compliance with the License. You may obtain
// a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
// WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
// License for the specific language governing permissions and limitations
// under the License.
package tools
import "strings"
// IsSliceContainsStr returns true if the string exists in given slice, ignore case.
func IsSliceContainsStr(sl []string, str string) bool {
str = strings.ToLower(str)
for _, s := range sl {
if strings.ToLower(s) == str {
return true
}
}
return false
}
// IsSliceContainsInt64 returns true if the int64 exists in given slice.
func IsSliceContainsInt64(sl []int64, i int64) bool {
for _, s := range sl {
if s == i {
return true
}
}
return false
}
// IsSliceContainsInt returns true if the int exists in given slice.
func IsSliceContainsInt(sl []int, i int) bool {
for _, s := range sl {
if s == i {
return true
}
}
return false
}
// IntSliceDifference int slice difference
func IntSliceDifference(slice1, slice2 []int) []int {
m := make(map[int]int)
nn := make([]int, 0)
inter := IntSliceIntersect(slice1, slice2)
for _, v := range inter {
m[v]++
}
for _, value := range slice1 {
times, _ := m[value]
if times == 0 {
nn = append(nn, value)
}
}
return nn
}
// IntSliceIntersect ..
func IntSliceIntersect(slice1, slice2 []int) []int {
m := make(map[int]int)
nn := make([]int, 0)
for _, v := range slice1 {
m[v]++
}
for _, v := range slice2 {
times, _ := m[v]
if times == 1 {
nn = append(nn, v)
}
}
return nn
}
// IntSliceUnion ..
func IntSliceUnion(slice1, slice2 []int) []int {
m := make(map[int]int)
for _, v := range slice1 {
m[v]++
}
for _, v := range slice2 {
times, _ := m[v]
if times == 0 {
slice1 = append(slice1, v)
}
}
return slice1
}
// Copyright 2020 tools authors
//
// Licensed under the Apache License, Version 2.0 (the "License"): you may
// not use this file except in compliance with the License. You may obtain
// a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
// WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
// License for the specific language governing permissions and limitations
// under the License.
package tools
// Copyright 2020 tools authors
//
// Licensed under the Apache License, Version 2.0 (the "License"): you may
// not use this file except in compliance with the License. You may obtain
// a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
// WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
// License for the specific language governing permissions and limitations
// under the License.
package tools
import (
"fmt"
"strconv"
"strings"
"time"
)
// Date Format unix time int64 to string
// eg format: YYYY-MM-DD HH:mm:SS
func Date(ti int64, format string) string {
t := time.Unix(int64(ti), 0)
return DateT(t, format)
}
// DateS Format unix time string to string
func DateS(ts string, format string) string {
i, _ := strconv.ParseInt(ts, 10, 64)
return Date(i, format)
}
// DateT ..
// Format time.Time struct to string
// MM - month - 01
// M - month - 1, single bit
// DD - day - 02
// D - day 2
// YYYY - year - 2006
// YY - year - 06
// HH - 24 hours - 03
// H - 24 hours - 3
// hh - 12 hours - 03
// h - 12 hours - 3
// mm - minute - 04
// m - minute - 4
// ss - second - 05
// s - second = 5
func DateT(t time.Time, format string) string {
res := strings.Replace(format, "MM", t.Format("01"), -1)
res = strings.Replace(res, "M", t.Format("1"), -1)
res = strings.Replace(res, "DD", t.Format("02"), -1)
res = strings.Replace(res, "D", t.Format("2"), -1)
res = strings.Replace(res, "YYYY", t.Format("2006"), -1)
res = strings.Replace(res, "YY", t.Format("06"), -1)
res = strings.Replace(res, "HH", fmt.Sprintf("%02d", t.Hour()), -1)
res = strings.Replace(res, "H", fmt.Sprintf("%d", t.Hour()), -1)
res = strings.Replace(res, "hh", t.Format("03"), -1)
res = strings.Replace(res, "h", t.Format("3"), -1)
res = strings.Replace(res, "mm", t.Format("04"), -1)
res = strings.Replace(res, "m", t.Format("4"), -1)
res = strings.Replace(res, "ss", t.Format("05"), -1)
res = strings.Replace(res, "s", t.Format("5"), -1)
return res
}
// ParseStrToDate ..
// timeStr
// format
// locationName, when locationName is "", defaultLocation rely on system env.
func ParseStrToDate(timestr, format, locationName string) (time.Time, error) {
timeFormat := timeFormatParse(format)
loc := gettimeLocation(locationName)
timeValue, err := time.ParseInLocation(timeFormat, timestr, loc)
return timeValue, err
}
// ParseDateToStr ..
// MM - month - 01
// M - month - 1, single bit
// DD - day - 02
// D - day 2
// YYYY - year - 2006
// YY - year - 06
// HH - 24 hours - 03
// H - 24 hours - 3
// hh - 12 hours - 03
// h - 12 hours - 3
// mm - minute - 04
// m - minute - 4
// ss - second - 05
// s - second = 5
func ParseDateToStr(timeValue time.Time, format string) string {
formatStr := timeFormatParse(format)
return timeValue.Format(formatStr)
}
// TimeComparison time
// 0 equal,
// 1 time1 greater than time2
// 2 time1 less than time2
func TimeComparison(time1, time2 time.Time) int {
subSeconds := time1.Sub(time2).Seconds()
if subSeconds == 0 {
return 0
} else if subSeconds > 0 {
return 1
} else {
return 2
}
}
// timeFormatParse ..
func timeFormatParse(formatStr string) string {
res := strings.Replace(formatStr, "MM", "01", -1)
res = strings.Replace(res, "M", "1", -1)
res = strings.Replace(res, "DD", "02", -1)
res = strings.Replace(res, "D", "2", -1)
res = strings.Replace(res, "YYYY", "2006", -1)
res = strings.Replace(res, "YY", "06", -1)
res = strings.Replace(res, "HH", "15", -1)
res = strings.Replace(res, "H", "15", -1)
res = strings.Replace(res, "hh", "03", -1)
res = strings.Replace(res, "h", "3", -1)
res = strings.Replace(res, "mm", "04", -1)
res = strings.Replace(res, "m", "4", -1)
res = strings.Replace(res, "ss", "05", -1)
res = strings.Replace(res, "s", "5", -1)
return res
}
// gettimeLocation
func gettimeLocation(locationName string) *time.Location {
var loc *time.Location
if locationName == "" {
loc = time.Now().Location()
} else {
loc, _ = time.LoadLocation(locationName)
}
return loc
}
......@@ -94,6 +94,9 @@ github.com/imdario/mergo
github.com/inconshreveable/mousetrap
# github.com/isbrick/http-client v0.0.0-20210321135403-0a5df00fdb84
github.com/isbrick/http-client
# github.com/isbrick/tools v0.0.0-20211027093338-a3a0ded37175
## explicit
github.com/isbrick/tools
# github.com/json-iterator/go v1.1.8
github.com/json-iterator/go
# github.com/kr/text v0.2.0
......
......@@ -494,10 +494,6 @@ const backendAPI = {
Package.httpMethods('delete', `/atomci/api/v1/groups/${group}/users/${user}`, cb);
},
// 删除用户组权限 - 角色
delGroupRole(group, role, cb) {
Package.httpMethods('delete', `/atomci/api/v1/groups/${group}/roles/${role}`, cb);
},
// 删除用户组权限 - 角色
delGroupConstraints(group, constraints, cb) {
Package.httpMethods(
'delete',
......@@ -672,12 +668,17 @@ const backendAPI = {
},
// 查询角色列表
getGroupRoleList(group, cb) {
Package.httpMethods('get', `/atomci/api/v1/groups/${group}/roles`, cb);
getGroupRoleList(cb) {
Package.httpMethods('get', `/atomci/api/v1/roles`, cb);
},
// 更新组角色
updateGroupRole(group, role, body, cb) {
Package.httpMethods('put', `/atomci/api/v1/groups/${group}/roles/${role}`, cb, body);
updateGroupRole(role, body, cb) {
Package.httpMethods('put', `/atomci/api/v1/roles/${role}`, cb, body);
},
// 删除用户组权限 - 角色
delGroupRole(group, role, cb) {
Package.httpMethods('delete', `/atomci/api/v1/roles/${role}`, cb);
},
// 资源操作
......@@ -723,17 +724,25 @@ const backendAPI = {
Package.httpMethods('get', `/atomci/api/v1/groups/${group}/users`, cb);
},
// 查询角色详情
getGroupRoleDetail(group, role, cb) {
Package.httpMethods('get', `/atomci/api/v1/groups/${group}/roles/${role}`, cb);
getGroupRoleDetail(role, cb) {
Package.httpMethods('get', `/atomci/api/v1/roles/${role}`, cb);
},
// 查询角色操作
getRoleOperations(role, cb) {
Package.httpMethods('get', `/atomci/api/v1/roles/${role}/operations`, cb);
},
// 删除角色操作
deleteRoleOperation(role, operationID, cb) {
Package.httpMethods('delete', `/atomci/api/v1/roles/${role}/operations/${operationID}`, cb);
},
// 添加角色权限策略
addRolePolicies(group, role, body, cb) {
Package.httpMethods('post', `/atomci/api/v1/groups/${group}/roles/${role}/policies`, cb, body);
},
// 删除角色权限策略
deleteRolePolicies(body, group, role, cb) {
Package.httpMethods('delete', `/atomci/api/v1/groups/${group}/roles/${role}/policies`, cb, body);
},
// 添加角色绑定用户
addRoleBindUser(group, role, body, cb) {
Package.httpMethods('post', `/atomci/api/v1/groups/${group}/roles/${role}/bundling`, cb, body);
......
......@@ -24,7 +24,7 @@
</el-form-item>
<el-form-item :label="$t('bm.authorManage.resourceOper')" prop="perPolicy" v-if="!isEdit">
<el-select v-model="form.perPolicy" :placeholder="$t('bm.add.selectOperation')" multiple filterable>
<el-option v-for="(item, index) in policyList" :key="index" :label="item.description" :value="item.resource_operation">
<el-option v-for="(item, index) in operationsList" :key="index" :label="item.description" :value="item.id">
</el-option>
</el-select>
</el-form-item>
......@@ -38,9 +38,9 @@
<script>
import { mapGetters } from 'vuex';
import { Message } from 'element-ui';
import backend from '../../../api/backend';
import createTemplate from '../../../common/createTemplate';
import validate from '../../../common/validate';
import backend from '@/api/backend';
import createTemplate from '@/common/createTemplate';
import validate from '@/common/validate';
const formData = {
role: '',
......@@ -56,7 +56,7 @@ export default {
data() {
return {
groupRoleList: [],
policyList: [],
operationsList: [],
// 是否属于编辑状态
isEdit: false,
dialogFormVisible: false,
......@@ -94,7 +94,7 @@ export default {
} else {
backend.getResourcesOperation((data) => {
if (data) {
this.policyList = data;
this.operationsList = data;
}
});
}
......@@ -151,7 +151,7 @@ export default {
};
if (this.isEdit) {
// , JSON.stringify({ "role": this.form.role })
backend.updateGroupRole("system", this.form.role, cl, () => {
backend.updateGroupRole(this.form.role, cl, () => {
successCallBack();
});
} else {
......
......@@ -96,8 +96,7 @@ export default {
}
});
} else {
// TODO: group's name use system , tmp
backend.getGroupRoleList("system", (data) => {
backend.getGroupRoleList((data) => {
if (data) {
this.curList = data.map((item) => {
if (item.policies) {
......
......@@ -20,7 +20,7 @@
</el-row>
</div>
<template>
<el-table stripe :data="dataList">
<el-table stripe :data="curList">
<el-table-column prop="role"
:label="$t('bm.add.roleName')"
sortable
......@@ -166,17 +166,9 @@ export default {
});
},
getList() {
backend.getGroupRoleList(this.group, data => {
backend.getGroupRoleList((data) => {
if (data) {
this.curList = data.map(item => {
if (item.policies) {
const policies = item.policies.map(subItem => {
return subItem.policy_name;
});
item.policy = policies.join(' ');
} else {
item.policy = '';
}
item.create_at = UtilsFn.format(new Date(item.create_at), 'yyyy-MM-dd hh:mm');
return item;
});
......
......@@ -19,18 +19,17 @@
</div>
<template>
<el-table border :data="dataList">
<el-table-column prop="policy_name" :label="$t('bm.authorManage.resourceOper')" sortable min-width="15%" :show-overflow-tooltip=true />
<el-table-column prop="policy_name" :label="$t('bm.authorManage.resourceRouter')" sortable min-width="15%" :show-overflow-tooltip=true />
<el-table-column prop="policy_name" :label="$t('bm.authorManage.resourceMethod')" sortable min-width="15%" :show-overflow-tooltip=true />
<el-table-column prop="resource_operation" :label="$t('bm.authorManage.resourceOper')" sortable min-width="15%" :show-overflow-tooltip=true />
<el-table-column prop="resource_type" :label="$t('bm.authorManage.resourceType')" sortable min-width="15%" :show-overflow-tooltip=true />
<el-table-column prop="description" :label="$t('bm.serviceM.description')" sortable min-width="15%" :show-overflow-tooltip=true />
<el-table-column prop="create_at" :label="$t('bm.serviceM.creationTime')" sortable min-width="15%" :show-overflow-tooltip=true />
<!-- <el-table-column :label="$t('bm.deployCenter.operation')" min-width="10%">
<el-table-column :label="$t('bm.deployCenter.operation')" min-width="10%">
<template slot-scope="scope">
<el-button @click="$refs.commonDelete.doDeleteBody('deleteRolePolicies', {policies: [scope.row.policy_name]}, $route.params.dept,$route.params.role)" type="text" size="small" :title="$t('bm.depManage.remove')">
<el-button @click="$refs.commonDelete.doDeleteBody('deleteRoleOperation', $route.params.role, scope.row.id)" type="text" size="small" :title="$t('bm.depManage.remove')">
{{$t('bm.depManage.remove')}}
</el-button>
</template>
</el-table-column> -->
</el-table-column>
</el-table>
</template>
<page-nav ref="page" :list="filteredList"></page-nav>
......@@ -81,15 +80,14 @@ export default {
}),
},
created() {
this.group = "system";
this.getList();
},
methods: {
getList() {
if(!this.$route.params.role) return;
backend.getGroupRoleDetail(this.group, this.$route.params.role, (data) => {
if (data && data.policies) {
this.curList = data.policies.map((item) => {
backend.getRoleOperations(this.$route.params.role, (data) => {
if (data) {
this.curList = data.map((item) => {
item.create_at = UtilsFn.format(new Date(item.create_at), 'yyyy-MM-dd hh:mm');
return item;
});
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册