Files
ubicloud/routes/project/location/private_subnet.rb
Jeremy Evans 6123351b74 Simplify private subnet authorization check when disconnecting private subnets
With disconnect, the ubid is passed in the path, but we still want
to use authorized_private_subnet, so have it and authorized_object
accept an id keyword argument, to use the id directly instead of
looking in the params for it.
2025-05-14 07:04:53 +09:00

103 lines
3.2 KiB
Ruby

# frozen_string_literal: true
class Clover
hash_branch(:project_location_prefix, "private-subnet") do |r|
r.get api? do
private_subnet_list
end
r.on PRIVATE_SUBNET_NAME_OR_UBID do |ps_name, ps_id|
if ps_name
r.post true do
check_visible_location
private_subnet_post(ps_name)
end
filter = {Sequel[:private_subnet][:name] => ps_name}
else
filter = {Sequel[:private_subnet][:id] => UBID.to_uuid(ps_id)}
end
filter[:location_id] = @location.id
ps = @project.private_subnets_dataset.eager(:location).first(filter)
check_found_object(ps)
r.post "connect" do
authorize("PrivateSubnet:connect", ps.id)
unless (subnet = authorized_private_subnet(key: "connected-subnet-id", perm: "PrivateSubnet:connect"))
if api?
response.status = 400
next {error: {code: 400, type: "InvalidRequest", message: "Subnet to be connected not found"}}
else
flash["error"] = "Subnet to be connected not found"
r.redirect "#{@project.path}#{ps.path}"
end
end
DB.transaction do
ps.connect_subnet(subnet)
audit_log(ps, "connect", subnet)
end
if api?
Serializers::PrivateSubnet.serialize(ps)
else
flash["notice"] = "#{subnet.name} will be connected in a few seconds"
r.redirect "#{@project.path}#{ps.path}"
end
end
r.post "disconnect", :ubid_uuid do |id|
authorize("PrivateSubnet:disconnect", ps.id)
unless (subnet = authorized_private_subnet(id:, perm: "PrivateSubnet:disconnect"))
response.status = 400
next {error: {code: 400, type: "InvalidRequest", message: "Subnet to be disconnected not found"}}
end
DB.transaction do
ps.disconnect_subnet(subnet)
audit_log(ps, "disconnect", subnet)
end
if api?
Serializers::PrivateSubnet.serialize(ps)
else
flash["notice"] = "#{subnet.name} will be disconnected in a few seconds"
204
end
end
request.get true do
authorize("PrivateSubnet:view", ps.id)
@ps = Serializers::PrivateSubnet.serialize(ps)
if api?
@ps
else
@nics = Serializers::Nic.serialize(ps.nics)
@connected_subnets = Serializers::PrivateSubnet.serialize(ps.connected_subnets)
connectable_subnets = ps.project.private_subnets.select do |ps1|
ps1_id = ps1.id
ps1_id != ps.id && !ps.connected_subnets.find { |cs| cs.id == ps1_id }
end
@connectable_subnets = Serializers::PrivateSubnet.serialize(connectable_subnets)
view "networking/private_subnet/show"
end
end
request.delete true do
authorize("PrivateSubnet:delete", ps.id)
unless ps.vms.all? { it.destroy_set? || it.strand.nil? || it.strand.label == "destroy" }
fail DependencyError.new("Private subnet '#{ps.name}' has VMs attached, first, delete them.")
end
DB.transaction do
ps.incr_destroy
audit_log(ps, "destroy")
end
204
end
end
end
end