account.py 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321
  1. import enum
  2. import json
  3. from flask_login import UserMixin # type: ignore
  4. from sqlalchemy import func
  5. from sqlalchemy.orm import Mapped, mapped_column
  6. from models.base import Base
  7. from .engine import db
  8. from .types import StringUUID
  9. class AccountStatus(enum.StrEnum):
  10. PENDING = "pending"
  11. UNINITIALIZED = "uninitialized"
  12. ACTIVE = "active"
  13. BANNED = "banned"
  14. CLOSED = "closed"
  15. class Account(UserMixin, Base):
  16. __tablename__ = "accounts"
  17. __table_args__ = (db.PrimaryKeyConstraint("id", name="account_pkey"), db.Index("account_email_idx", "email"))
  18. id: Mapped[str] = mapped_column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  19. name = db.Column(db.String(255), nullable=False)
  20. email = db.Column(db.String(255), nullable=False)
  21. password = db.Column(db.String(255), nullable=True)
  22. password_salt = db.Column(db.String(255), nullable=True)
  23. avatar = db.Column(db.String(255))
  24. interface_language = db.Column(db.String(255))
  25. interface_theme = db.Column(db.String(255))
  26. timezone = db.Column(db.String(255))
  27. last_login_at = db.Column(db.DateTime)
  28. last_login_ip = db.Column(db.String(255))
  29. last_active_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  30. status = db.Column(db.String(16), nullable=False, server_default=db.text("'active'::character varying"))
  31. initialized_at = db.Column(db.DateTime)
  32. created_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  33. updated_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  34. dept_id = db.Column(db.String(255), nullable=True)
  35. @property
  36. def is_password_set(self):
  37. return self.password is not None
  38. @property
  39. def current_tenant(self):
  40. # FIXME: fix the type error later, because the type is important maybe cause some bugs
  41. return self._current_tenant # type: ignore
  42. @current_tenant.setter
  43. def current_tenant(self, value: "Tenant"):
  44. tenant = value
  45. ta = TenantAccountJoin.query.filter_by(tenant_id=tenant.id, account_id=self.id).first()
  46. if ta:
  47. tenant.current_role = ta.role
  48. else:
  49. tenant = None # type: ignore
  50. self._current_tenant = tenant
  51. @property
  52. def current_tenant_id(self) -> str | None:
  53. return self._current_tenant.id if self._current_tenant else None
  54. @current_tenant_id.setter
  55. def current_tenant_id(self, value: str):
  56. try:
  57. tenant_account_join = (
  58. db.session.query(Tenant, TenantAccountJoin)
  59. .filter(Tenant.id == value)
  60. .filter(TenantAccountJoin.tenant_id == Tenant.id)
  61. .filter(TenantAccountJoin.account_id == self.id)
  62. .one_or_none()
  63. )
  64. if tenant_account_join:
  65. tenant, ta = tenant_account_join
  66. tenant.current_role = ta.role
  67. else:
  68. tenant = None
  69. except Exception:
  70. tenant = None
  71. self._current_tenant = tenant
  72. @property
  73. def current_role(self):
  74. return self._current_tenant.current_role
  75. def get_status(self) -> AccountStatus:
  76. status_str = self.status
  77. return AccountStatus(status_str)
  78. @classmethod
  79. def get_by_openid(cls, provider: str, open_id: str):
  80. account_integrate = (
  81. db.session.query(AccountIntegrate)
  82. .filter(AccountIntegrate.provider == provider, AccountIntegrate.open_id == open_id)
  83. .one_or_none()
  84. )
  85. if account_integrate:
  86. return db.session.query(Account).filter(Account.id == account_integrate.account_id).one_or_none()
  87. return None
  88. # check current_user.current_tenant.current_role in ['admin', 'owner']
  89. @property
  90. def is_admin_or_owner(self):
  91. return TenantAccountRole.is_privileged_role(self._current_tenant.current_role)
  92. @property
  93. def is_admin(self):
  94. return TenantAccountRole.is_admin_role(self._current_tenant.current_role)
  95. @property
  96. def is_editor(self):
  97. return TenantAccountRole.is_editing_role(self._current_tenant.current_role)
  98. @property
  99. def is_dataset_editor(self):
  100. return TenantAccountRole.is_dataset_edit_role(self._current_tenant.current_role)
  101. @property
  102. def is_dataset_operator(self):
  103. return self._current_tenant.current_role == TenantAccountRole.DATASET_OPERATOR
  104. @property
  105. def is_leader(self):
  106. return TenantAccountRole.is_leader_role(self._current_tenant.current_role)
  107. class TenantStatus(enum.StrEnum):
  108. NORMAL = "normal"
  109. ARCHIVE = "archive"
  110. class TenantAccountRole(enum.StrEnum):
  111. OWNER = "owner"
  112. ADMIN = "admin"
  113. EDITOR = "editor"
  114. NORMAL = "normal"
  115. DATASET_OPERATOR = "dataset_operator"
  116. LEADER = "leader"
  117. @staticmethod
  118. def is_valid_role(role: str) -> bool:
  119. if not role:
  120. return False
  121. return role in {
  122. TenantAccountRole.OWNER,
  123. TenantAccountRole.ADMIN,
  124. TenantAccountRole.EDITOR,
  125. TenantAccountRole.NORMAL,
  126. TenantAccountRole.DATASET_OPERATOR,
  127. TenantAccountRole.LEADER,
  128. }
  129. @staticmethod
  130. def is_privileged_role(role: str) -> bool:
  131. if not role:
  132. return False
  133. return role in {TenantAccountRole.OWNER, TenantAccountRole.ADMIN, TenantAccountRole.LEADER}
  134. @staticmethod
  135. def is_admin_role(role: str) -> bool:
  136. if not role:
  137. return False
  138. return role == TenantAccountRole.ADMIN
  139. @staticmethod
  140. def is_non_owner_role(role: str) -> bool:
  141. if not role:
  142. return False
  143. return role in {
  144. TenantAccountRole.ADMIN,
  145. TenantAccountRole.EDITOR,
  146. TenantAccountRole.NORMAL,
  147. TenantAccountRole.DATASET_OPERATOR,
  148. TenantAccountRole.LEADER,
  149. }
  150. @staticmethod
  151. def is_editing_role(role: str) -> bool:
  152. if not role:
  153. return False
  154. return role in {
  155. TenantAccountRole.OWNER,
  156. TenantAccountRole.ADMIN,
  157. TenantAccountRole.EDITOR,
  158. TenantAccountRole.LEADER,
  159. }
  160. @staticmethod
  161. def is_dataset_edit_role(role: str) -> bool:
  162. if not role:
  163. return False
  164. return role in {
  165. TenantAccountRole.OWNER,
  166. TenantAccountRole.ADMIN,
  167. TenantAccountRole.EDITOR,
  168. TenantAccountRole.DATASET_OPERATOR,
  169. TenantAccountRole.LEADER,
  170. }
  171. @staticmethod
  172. def is_leader_role(role: str) -> bool:
  173. if not role:
  174. return False
  175. return role == TenantAccountRole.LEADER
  176. class Tenant(db.Model): # type: ignore[name-defined]
  177. __tablename__ = "tenants"
  178. __table_args__ = (db.PrimaryKeyConstraint("id", name="tenant_pkey"),)
  179. id = db.Column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  180. name = db.Column(db.String(255), nullable=False)
  181. encrypt_public_key = db.Column(db.Text)
  182. plan = db.Column(db.String(255), nullable=False, server_default=db.text("'basic'::character varying"))
  183. status = db.Column(db.String(255), nullable=False, server_default=db.text("'normal'::character varying"))
  184. custom_config = db.Column(db.Text)
  185. created_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  186. updated_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  187. def get_accounts(self) -> list[Account]:
  188. return (
  189. db.session.query(Account)
  190. .filter(Account.id == TenantAccountJoin.account_id, TenantAccountJoin.tenant_id == self.id)
  191. .all()
  192. )
  193. @property
  194. def custom_config_dict(self) -> dict:
  195. return json.loads(self.custom_config) if self.custom_config else {}
  196. @custom_config_dict.setter
  197. def custom_config_dict(self, value: dict):
  198. self.custom_config = json.dumps(value)
  199. class TenantAccountJoin(db.Model): # type: ignore[name-defined]
  200. __tablename__ = "tenant_account_joins"
  201. __table_args__ = (
  202. db.PrimaryKeyConstraint("id", name="tenant_account_join_pkey"),
  203. db.Index("tenant_account_join_account_id_idx", "account_id"),
  204. db.Index("tenant_account_join_tenant_id_idx", "tenant_id"),
  205. db.UniqueConstraint("tenant_id", "account_id", name="unique_tenant_account_join"),
  206. )
  207. id = db.Column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  208. tenant_id = db.Column(StringUUID, nullable=False)
  209. account_id = db.Column(StringUUID, nullable=False)
  210. current = db.Column(db.Boolean, nullable=False, server_default=db.text("false"))
  211. role = db.Column(db.String(16), nullable=False, server_default="normal")
  212. invited_by = db.Column(StringUUID, nullable=True)
  213. created_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  214. updated_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  215. class AccountIntegrate(db.Model): # type: ignore[name-defined]
  216. __tablename__ = "account_integrates"
  217. __table_args__ = (
  218. db.PrimaryKeyConstraint("id", name="account_integrate_pkey"),
  219. db.UniqueConstraint("account_id", "provider", name="unique_account_provider"),
  220. db.UniqueConstraint("provider", "open_id", name="unique_provider_open_id"),
  221. )
  222. id = db.Column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  223. account_id = db.Column(StringUUID, nullable=False)
  224. provider = db.Column(db.String(16), nullable=False)
  225. open_id = db.Column(db.String(255), nullable=False)
  226. encrypted_token = db.Column(db.String(255), nullable=False)
  227. created_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  228. updated_at = db.Column(db.DateTime, nullable=False, server_default=func.current_timestamp())
  229. class InvitationCode(db.Model): # type: ignore[name-defined]
  230. __tablename__ = "invitation_codes"
  231. __table_args__ = (
  232. db.PrimaryKeyConstraint("id", name="invitation_code_pkey"),
  233. db.Index("invitation_codes_batch_idx", "batch"),
  234. db.Index("invitation_codes_code_idx", "code", "status"),
  235. )
  236. id = db.Column(db.Integer, nullable=False)
  237. batch = db.Column(db.String(255), nullable=False)
  238. code = db.Column(db.String(32), nullable=False)
  239. status = db.Column(db.String(16), nullable=False, server_default=db.text("'unused'::character varying"))
  240. used_at = db.Column(db.DateTime)
  241. used_by_tenant_id = db.Column(StringUUID)
  242. used_by_account_id = db.Column(StringUUID)
  243. deprecated_at = db.Column(db.DateTime)
  244. created_at = db.Column(db.DateTime, nullable=False, server_default=db.text("CURRENT_TIMESTAMP(0)"))
  245. class TenantPluginPermission(Base):
  246. class InstallPermission(enum.StrEnum):
  247. EVERYONE = "everyone"
  248. ADMINS = "admins"
  249. NOBODY = "noone"
  250. class DebugPermission(enum.StrEnum):
  251. EVERYONE = "everyone"
  252. ADMINS = "admins"
  253. NOBODY = "noone"
  254. __tablename__ = "account_plugin_permissions"
  255. __table_args__ = (
  256. db.PrimaryKeyConstraint("id", name="account_plugin_permission_pkey"),
  257. db.UniqueConstraint("tenant_id", name="unique_tenant_plugin"),
  258. )
  259. id: Mapped[str] = mapped_column(StringUUID, server_default=db.text("uuid_generate_v4()"))
  260. tenant_id: Mapped[str] = mapped_column(StringUUID, nullable=False)
  261. install_permission: Mapped[InstallPermission] = mapped_column(
  262. db.String(16), nullable=False, server_default="everyone"
  263. )
  264. debug_permission: Mapped[DebugPermission] = mapped_column(db.String(16), nullable=False, server_default="noone")