|
| 1 | +from __future__ import annotations |
| 2 | + |
1 | 3 | from dataclasses import dataclass |
2 | | -from typing import override |
| 4 | +from typing import cast, override |
3 | 5 |
|
| 6 | +from ai.backend.common.data.permission.types import RBACElementType, ScopeType |
4 | 7 | from ai.backend.manager.actions.action import BaseActionResult |
5 | 8 | from ai.backend.manager.actions.types import ActionOperationType |
| 9 | +from ai.backend.manager.data.permission.types import RBACElementRef |
6 | 10 | from ai.backend.manager.data.user.types import BulkUserCreateResultData, UserCreateResultData |
7 | 11 | from ai.backend.manager.models.user import UserRow |
8 | 12 | from ai.backend.manager.repositories.base.creator import Creator |
9 | | -from ai.backend.manager.services.user.actions.base import UserAction |
| 13 | +from ai.backend.manager.repositories.user.creators import UserCreatorSpec |
| 14 | +from ai.backend.manager.services.user.actions.base import ( |
| 15 | + UserAction, |
| 16 | + UserScopeAction, |
| 17 | + UserScopeActionResult, |
| 18 | +) |
| 19 | +from ai.backend.manager.services.user.types import UserCreateSpec |
| 20 | + |
| 21 | +__all__ = ( |
| 22 | + "CreateUserAction", |
| 23 | + "CreateUserActionResult", |
| 24 | + "UserCreateSpec", |
| 25 | + "BulkCreateUserAction", |
| 26 | + "BulkCreateUserActionResult", |
| 27 | +) |
10 | 28 |
|
11 | 29 |
|
12 | 30 | @dataclass |
13 | | -class CreateUserAction(UserAction): |
14 | | - creator: Creator[UserRow] |
| 31 | +class CreateUserAction(UserScopeAction): |
| 32 | + creator: Creator[UserRow] # spec: UserCreatorSpec |
15 | 33 | group_ids: list[str] | None = None |
16 | 34 |
|
17 | | - @override |
18 | | - def entity_id(self) -> str | None: |
19 | | - return None |
20 | | - |
21 | 35 | @override |
22 | 36 | @classmethod |
23 | 37 | def operation_type(cls) -> ActionOperationType: |
24 | 38 | return ActionOperationType.CREATE |
25 | 39 |
|
| 40 | + @override |
| 41 | + def scope_type(self) -> ScopeType: |
| 42 | + return ScopeType.DOMAIN |
| 43 | + |
| 44 | + @override |
| 45 | + def scope_id(self) -> str: |
| 46 | + spec = cast(UserCreatorSpec, self.creator.spec) |
| 47 | + return spec.domain_name |
| 48 | + |
| 49 | + @override |
| 50 | + def target_element(self) -> RBACElementRef: |
| 51 | + spec = cast(UserCreatorSpec, self.creator.spec) |
| 52 | + return RBACElementRef(RBACElementType.DOMAIN, spec.domain_name) |
| 53 | + |
26 | 54 |
|
27 | 55 | @dataclass |
28 | | -class CreateUserActionResult(BaseActionResult): |
| 56 | +class CreateUserActionResult(UserScopeActionResult): |
29 | 57 | data: UserCreateResultData |
30 | 58 |
|
31 | 59 | @override |
32 | 60 | def entity_id(self) -> str | None: |
33 | 61 | return str(self.data.user.id) |
34 | 62 |
|
| 63 | + @override |
| 64 | + def scope_type(self) -> ScopeType: |
| 65 | + return ScopeType.DOMAIN |
35 | 66 |
|
36 | | -@dataclass |
37 | | -class UserCreateSpec: |
38 | | - """Specification for creating a single user, including group assignments.""" |
39 | | - |
40 | | - creator: Creator[UserRow] |
41 | | - group_ids: list[str] | None = None |
| 67 | + @override |
| 68 | + def scope_id(self) -> str: |
| 69 | + # UserCreateResultData always has domain_name set (from creator.spec.domain_name) |
| 70 | + return self.data.user.domain_name or "" |
42 | 71 |
|
43 | 72 |
|
44 | 73 | @dataclass |
|
0 commit comments