ScoDoc/app/scodoc/sco_permissions.py

116 lines
4.7 KiB
Python
Raw Normal View History

2021-05-29 18:22:51 +02:00
# -*- mode: python -*-
# -*- coding: utf-8 -*-
2021-08-21 15:17:14 +02:00
"""Definition of ScoDoc permissions
2021-05-29 18:22:51 +02:00
used by auth
"""
2021-06-15 13:59:56 +02:00
# Définition des permissions: NE PAS CHANGER les numéros ou l'ordre des lignes !
# Les permissions sont sur un BigInt en base SQL, donc 64 bits.
2021-05-29 18:22:51 +02:00
_SCO_PERMISSIONS = (
# permission bit, symbol, description
# ScoSuperAdmin est utilisé pour:
2022-08-06 22:31:41 +02:00
# - add/delete departments
2021-05-29 18:22:51 +02:00
# - tous rôles lors creation utilisateurs
(1 << 1, "ScoSuperAdmin", "Super Administrateur"),
(1 << 2, "ScoView", "Voir"),
(1 << 3, "EnsView", "Voir les parties pour les enseignants"),
(1 << 4, "Observateur", "Observer (accès lecture restreint aux bulletins)"),
(1 << 5, "UsersAdmin", "Gérer les utilisateurs (de son département)"),
2023-09-29 22:18:54 +02:00
(1 << 6, "UsersView", "Voir les utilisateurs (de tous les départements)"),
(1 << 7, "EditPreferences", "Modifier les préférences"),
(1 << 8, "EditFormation", "Changer les formations"),
(1 << 9, "EditFormationTags", "Tagguer les formations"),
(1 << 10, "EditAllNotes", "Modifier toutes les notes"),
2023-09-29 22:18:54 +02:00
(1 << 11, "EditAllEvals", "Modifier toutes les évaluations"),
(1 << 12, "EditFormSemestre", "Mettre en place une formation (créer un semestre)"),
(1 << 13, "AbsChange", "Saisir des absences"),
(1 << 14, "AbsAddBillet", "Saisir des billets d'absences"),
2021-05-29 18:22:51 +02:00
# changer adresse/photo ou pour envoyer bulletins par mail ou pour debouche
(1 << 15, "EtudChangeAdr", "Changer les adresses d'étudiants"),
(
1 << 16,
"APIEditGroups",
"API: Modifier les groupes (obsolete, use EtudChangeGroups)",
),
(1 << 16, "EtudChangeGroups", "Modifier les groupes"),
2021-05-29 18:22:51 +02:00
# aussi pour demissions, diplomes:
(1 << 17, "EtudInscrit", "Inscrire des étudiants"),
2021-05-29 18:22:51 +02:00
# aussi pour archives:
2024-01-20 17:37:24 +01:00
(
1 << 18,
"EtudAddAnnotations",
"Éditer les annotations (et fichiers) sur étudiants",
),
# inutilisée (1 << 19, "ScoEntrepriseView", "Voir la section 'entreprises'"),
# inutilisée (1 << 20, "EntrepriseChange", "Modifier les entreprises"),
# XXX inutilisée ? (1 << 21, "EditPVJury", "Éditer les PV de jury"),
2021-05-29 18:22:51 +02:00
# ajouter maquettes Apogee (=> chef dept et secr):
(1 << 22, "EditApogee", "Gérer les exports Apogée"),
# Application relations entreprises
(1 << 23, "RelationsEntrepView", "Voir l'application relations entreprises"),
(1 << 24, "RelationsEntrepEdit", "Modifier les entreprises"),
(1 << 25, "RelationsEntrepSend", "Envoyer des offres"),
(1 << 26, "RelationsEntrepValidate", "Valide les entreprises"),
(1 << 27, "RelationsEntrepViewCorrs", "Voir les correspondants"),
(
1 << 28,
"RelationsEntrepExport",
"Exporter les données de l'application relations entreprises",
),
(1 << 29, "UsersChangeCASId", "Paramétrer l'id CAS"),
(1 << 30, "ViewEtudData", "Accéder aux données personnelles des étudiants"),
#
# XXX inutilisée ? (1 << 40, "EtudChangePhoto", "Modifier la photo d'un étudiant"),
2023-06-30 17:24:16 +02:00
# Permissions du module Assiduité)
(1 << 50, "AbsJustifView", "Visualisation des fichiers justificatifs"),
# Attention: les permissions sont codées sur 64 bits.
2021-05-29 18:22:51 +02:00
)
2022-07-24 07:14:31 +02:00
class Permission:
2021-05-29 18:22:51 +02:00
"Permissions for ScoDoc"
NBITS = 1 # maximum bits used (for formatting)
ALL_PERMISSIONS = [-1]
description = {} # { symbol : blah blah }
2021-09-13 17:10:38 +02:00
permission_by_name = {} # { symbol : int }
2022-07-24 07:14:31 +02:00
permission_by_value = {} # { int : symbol }
2021-05-29 18:22:51 +02:00
@staticmethod
def init_permissions():
2023-06-30 17:24:16 +02:00
for perm, symbol, description in _SCO_PERMISSIONS:
2021-05-29 18:22:51 +02:00
setattr(Permission, symbol, perm)
Permission.description[symbol] = description
2021-09-13 17:10:38 +02:00
Permission.permission_by_name[symbol] = perm
2022-07-24 07:14:31 +02:00
Permission.permission_by_value[perm] = symbol
2022-05-04 20:40:20 +02:00
max_perm = max(p[0] for p in _SCO_PERMISSIONS)
Permission.NBITS = max_perm.bit_length()
2021-05-29 18:22:51 +02:00
2021-09-13 17:10:38 +02:00
@staticmethod
def get_by_name(permission_name: str) -> int:
2021-09-13 23:06:42 +02:00
"""Return permission mode (integer bit field), or None if it doesn't exist."""
return Permission.permission_by_name.get(permission_name)
2021-09-13 17:10:38 +02:00
2022-07-24 07:14:31 +02:00
@staticmethod
def get_name(permission: int) -> str:
"""Return permission name, or None if it doesn't exist."""
return Permission.permission_by_value.get(permission)
@staticmethod
def permissions_names(permissions: int) -> list[str]:
"""From a bit field, return list of permission names"""
names = []
2022-08-07 11:08:12 +02:00
if permissions == 0:
return []
2022-07-24 07:14:31 +02:00
mask = 1 << (permissions.bit_length() - 1)
while mask > 0:
if mask & permissions:
name = Permission.get_name(mask)
if name is not None:
names.append(name)
mask = mask >> 1
return names
2021-05-29 18:22:51 +02:00
Permission.init_permissions()