feature/rbac permisos y roles implementados
This commit is contained in:
116
api/rbac/migrations/0001_initial.py
Normal file
116
api/rbac/migrations/0001_initial.py
Normal file
@@ -0,0 +1,116 @@
|
||||
import uuid
|
||||
import django.db.models.deletion
|
||||
from django.conf import settings
|
||||
from django.db import migrations, models
|
||||
|
||||
|
||||
class Migration(migrations.Migration):
|
||||
|
||||
initial = True
|
||||
|
||||
dependencies = [
|
||||
('organization', '0003_organizacion_apply_auto_download'),
|
||||
migrations.swappable_dependency(settings.AUTH_USER_MODEL),
|
||||
]
|
||||
|
||||
operations = [
|
||||
migrations.CreateModel(
|
||||
name='RolePermission',
|
||||
fields=[
|
||||
('id', models.BigAutoField(auto_created=True, primary_key=True, serialize=False)),
|
||||
('codename', models.CharField(max_length=100, unique=True)),
|
||||
('descripcion', models.CharField(max_length=255)),
|
||||
('modulo', models.CharField(max_length=50)),
|
||||
],
|
||||
options={
|
||||
'verbose_name': 'Permiso',
|
||||
'verbose_name_plural': 'Permisos',
|
||||
'db_table': 'rbac_role_permission',
|
||||
'ordering': ['modulo', 'codename'],
|
||||
},
|
||||
),
|
||||
migrations.CreateModel(
|
||||
name='OrganizationRole',
|
||||
fields=[
|
||||
('id', models.UUIDField(default=uuid.uuid4, editable=False, primary_key=True, serialize=False)),
|
||||
('nombre', models.CharField(max_length=100)),
|
||||
('descripcion', models.CharField(blank=True, max_length=255)),
|
||||
('is_admin_role', models.BooleanField(default=False)),
|
||||
('created_at', models.DateTimeField(auto_now_add=True)),
|
||||
('updated_at', models.DateTimeField(auto_now=True)),
|
||||
('organizacion', models.ForeignKey(
|
||||
on_delete=django.db.models.deletion.CASCADE,
|
||||
related_name='roles',
|
||||
to='organization.organizacion',
|
||||
)),
|
||||
('permissions', models.ManyToManyField(
|
||||
blank=True,
|
||||
related_name='roles',
|
||||
to='rbac.rolepermission',
|
||||
)),
|
||||
],
|
||||
options={
|
||||
'verbose_name': 'Rol de Organización',
|
||||
'verbose_name_plural': 'Roles de Organización',
|
||||
'db_table': 'rbac_organization_role',
|
||||
'ordering': ['nombre'],
|
||||
},
|
||||
),
|
||||
migrations.AddConstraint(
|
||||
model_name='organizationrole',
|
||||
constraint=models.UniqueConstraint(fields=['organizacion', 'nombre'], name='unique_role_per_org'),
|
||||
),
|
||||
migrations.CreateModel(
|
||||
name='UserRole',
|
||||
fields=[
|
||||
('id', models.UUIDField(default=uuid.uuid4, editable=False, primary_key=True, serialize=False)),
|
||||
('created_at', models.DateTimeField(auto_now_add=True)),
|
||||
('user', models.ForeignKey(
|
||||
on_delete=django.db.models.deletion.CASCADE,
|
||||
related_name='user_roles',
|
||||
to=settings.AUTH_USER_MODEL,
|
||||
)),
|
||||
('role', models.ForeignKey(
|
||||
on_delete=django.db.models.deletion.CASCADE,
|
||||
related_name='user_roles',
|
||||
to='rbac.organizationrole',
|
||||
)),
|
||||
],
|
||||
options={
|
||||
'verbose_name': 'Rol de Usuario',
|
||||
'verbose_name_plural': 'Roles de Usuario',
|
||||
'db_table': 'rbac_user_role',
|
||||
},
|
||||
),
|
||||
migrations.AddConstraint(
|
||||
model_name='userrole',
|
||||
constraint=models.UniqueConstraint(fields=['user', 'role'], name='unique_user_role'),
|
||||
),
|
||||
migrations.CreateModel(
|
||||
name='UserPermission',
|
||||
fields=[
|
||||
('id', models.UUIDField(default=uuid.uuid4, editable=False, primary_key=True, serialize=False)),
|
||||
('granted', models.BooleanField(default=True)),
|
||||
('created_at', models.DateTimeField(auto_now_add=True)),
|
||||
('user', models.ForeignKey(
|
||||
on_delete=django.db.models.deletion.CASCADE,
|
||||
related_name='rbac_permissions',
|
||||
to=settings.AUTH_USER_MODEL,
|
||||
)),
|
||||
('permission', models.ForeignKey(
|
||||
on_delete=django.db.models.deletion.CASCADE,
|
||||
related_name='user_overrides',
|
||||
to='rbac.rolepermission',
|
||||
)),
|
||||
],
|
||||
options={
|
||||
'verbose_name': 'Permiso Singular',
|
||||
'verbose_name_plural': 'Permisos Singulares',
|
||||
'db_table': 'rbac_user_permission',
|
||||
},
|
||||
),
|
||||
migrations.AddConstraint(
|
||||
model_name='userpermission',
|
||||
constraint=models.UniqueConstraint(fields=['user', 'permission'], name='unique_user_permission'),
|
||||
),
|
||||
]
|
||||
88
api/rbac/migrations/0002_data_permissions.py
Normal file
88
api/rbac/migrations/0002_data_permissions.py
Normal file
@@ -0,0 +1,88 @@
|
||||
"""
|
||||
Data migration que:
|
||||
1. Crea el catálogo global de permisos (RolePermission).
|
||||
2. Para cada Organizacion existente, crea los 5 roles por defecto con sus permisos.
|
||||
3. Para cada CustomUser existente, mapea sus auth.Group actuales al UserRole equivalente.
|
||||
|
||||
Usa get_or_create en todos los pasos — segura de ejecutar múltiples veces.
|
||||
"""
|
||||
from django.db import migrations
|
||||
|
||||
# Importamos solo constantes (no modelos ni funciones con imports de Django)
|
||||
# para que la migration sea estable ante futuros refactors del código de la app.
|
||||
from api.rbac.roles import PERMISSIONS_CATALOG, DEFAULT_ROLES
|
||||
|
||||
|
||||
def _crear_permisos(RolePermission):
|
||||
perms_map = {}
|
||||
for codename, descripcion, modulo in PERMISSIONS_CATALOG:
|
||||
perm, _ = RolePermission.objects.get_or_create(
|
||||
codename=codename,
|
||||
defaults={'descripcion': descripcion, 'modulo': modulo},
|
||||
)
|
||||
perms_map[codename] = perm
|
||||
return perms_map
|
||||
|
||||
|
||||
def _crear_roles_org(OrganizationRole, org, perms_map):
|
||||
for nombre, config in DEFAULT_ROLES.items():
|
||||
role, created = OrganizationRole.objects.get_or_create(
|
||||
organizacion=org,
|
||||
nombre=nombre,
|
||||
defaults={
|
||||
'descripcion': config['descripcion'],
|
||||
'is_admin_role': config.get('is_admin_role', False),
|
||||
},
|
||||
)
|
||||
if created:
|
||||
role_perms = [perms_map[c] for c in config['permissions'] if c in perms_map]
|
||||
role.permissions.set(role_perms)
|
||||
|
||||
|
||||
def seed_rbac_data(apps, schema_editor):
|
||||
RolePermission = apps.get_model('rbac', 'RolePermission')
|
||||
OrganizationRole = apps.get_model('rbac', 'OrganizationRole')
|
||||
UserRole = apps.get_model('rbac', 'UserRole')
|
||||
Organizacion = apps.get_model('organization', 'Organizacion')
|
||||
CustomUser = apps.get_model('cuser', 'CustomUser')
|
||||
|
||||
# Paso 1 — Catálogo de permisos
|
||||
perms_map = _crear_permisos(RolePermission)
|
||||
|
||||
# Paso 2 — Roles por defecto para cada organización existente
|
||||
for org in Organizacion.objects.all():
|
||||
_crear_roles_org(OrganizationRole, org, perms_map)
|
||||
|
||||
# Paso 3 — Mapeo de usuarios: auth.Group → UserRole
|
||||
# Solo usuarios que tengan organización asignada y grupos asignados
|
||||
for user in CustomUser.objects.filter(organizacion__isnull=False).prefetch_related('groups'):
|
||||
for group in user.groups.all():
|
||||
try:
|
||||
role = OrganizationRole.objects.get(
|
||||
organizacion=user.organizacion,
|
||||
nombre=group.name,
|
||||
)
|
||||
UserRole.objects.get_or_create(user=user, role=role)
|
||||
except OrganizationRole.DoesNotExist:
|
||||
# El grupo no tiene equivalente en los roles por defecto — se ignora
|
||||
pass
|
||||
|
||||
|
||||
def reverse_seed(apps, schema_editor):
|
||||
# Revertir borra todos los datos RBAC. Los auth.Group originales no se tocan.
|
||||
apps.get_model('rbac', 'UserRole').objects.all().delete()
|
||||
apps.get_model('rbac', 'OrganizationRole').objects.all().delete()
|
||||
apps.get_model('rbac', 'RolePermission').objects.all().delete()
|
||||
|
||||
|
||||
class Migration(migrations.Migration):
|
||||
|
||||
dependencies = [
|
||||
('rbac', '0001_initial'),
|
||||
('cuser', '0005_customuser_rfc_fk_to_m2m'),
|
||||
('organization', '0003_organizacion_apply_auto_download'),
|
||||
]
|
||||
|
||||
operations = [
|
||||
migrations.RunPython(seed_rbac_data, reverse_code=reverse_seed),
|
||||
]
|
||||
56
api/rbac/migrations/0003_notificaciones_receive.py
Normal file
56
api/rbac/migrations/0003_notificaciones_receive.py
Normal file
@@ -0,0 +1,56 @@
|
||||
"""
|
||||
Agrega el permiso notificaciones.receive al catálogo y lo asigna a todos los
|
||||
OrganizationRole que correspondan a los 5 roles por defecto (en todas las orgs).
|
||||
"""
|
||||
from django.db import migrations
|
||||
|
||||
|
||||
NUEVO_PERMISO = (
|
||||
'notificaciones.receive',
|
||||
'Recibir notificaciones automáticas de eventos',
|
||||
'notificaciones',
|
||||
)
|
||||
|
||||
# Todos los roles por defecto deben recibir notificaciones
|
||||
ROLES_CON_PERMISO = ['admin', 'developer', 'Agente Aduanal', 'user', 'Importador']
|
||||
|
||||
|
||||
def agregar_notificaciones_receive(apps, schema_editor):
|
||||
RolePermission = apps.get_model('rbac', 'RolePermission')
|
||||
OrganizationRole = apps.get_model('rbac', 'OrganizationRole')
|
||||
|
||||
codename, descripcion, modulo = NUEVO_PERMISO
|
||||
perm, _ = RolePermission.objects.get_or_create(
|
||||
codename=codename,
|
||||
defaults={'descripcion': descripcion, 'modulo': modulo},
|
||||
)
|
||||
|
||||
roles = OrganizationRole.objects.filter(nombre__in=ROLES_CON_PERMISO)
|
||||
for role in roles:
|
||||
role.permissions.add(perm)
|
||||
|
||||
|
||||
def revertir(apps, schema_editor):
|
||||
RolePermission = apps.get_model('rbac', 'RolePermission')
|
||||
OrganizationRole = apps.get_model('rbac', 'OrganizationRole')
|
||||
|
||||
try:
|
||||
perm = RolePermission.objects.get(codename='notificaciones.receive')
|
||||
except RolePermission.DoesNotExist:
|
||||
return
|
||||
|
||||
for role in OrganizationRole.objects.all():
|
||||
role.permissions.remove(perm)
|
||||
|
||||
perm.delete()
|
||||
|
||||
|
||||
class Migration(migrations.Migration):
|
||||
|
||||
dependencies = [
|
||||
('rbac', '0002_data_permissions'),
|
||||
]
|
||||
|
||||
operations = [
|
||||
migrations.RunPython(agregar_notificaciones_receive, reverse_code=revertir),
|
||||
]
|
||||
57
api/rbac/migrations/0004_auditoria_permissions.py
Normal file
57
api/rbac/migrations/0004_auditoria_permissions.py
Normal file
@@ -0,0 +1,57 @@
|
||||
"""
|
||||
Agrega los permisos auditoria.view y auditoria.process al catálogo y los asigna
|
||||
a los roles admin, developer (ambos) y Agente Aduanal (solo view).
|
||||
"""
|
||||
from django.db import migrations
|
||||
|
||||
NUEVOS_PERMISOS = [
|
||||
('auditoria.view', 'Ver estado y resultados de auditoría VUCEM', 'auditoria'),
|
||||
('auditoria.process', 'Lanzar procesos de auditoría y reauditoría', 'auditoria'),
|
||||
]
|
||||
|
||||
ROLES_AUDITORIA_FULL = ['admin', 'developer']
|
||||
ROLES_AUDITORIA_VIEW = ['Agente Aduanal']
|
||||
|
||||
|
||||
def agregar_auditoria(apps, schema_editor):
|
||||
RolePermission = apps.get_model('rbac', 'RolePermission')
|
||||
OrganizationRole = apps.get_model('rbac', 'OrganizationRole')
|
||||
|
||||
perms = {}
|
||||
for codename, descripcion, modulo in NUEVOS_PERMISOS:
|
||||
perm, _ = RolePermission.objects.get_or_create(
|
||||
codename=codename,
|
||||
defaults={'descripcion': descripcion, 'modulo': modulo},
|
||||
)
|
||||
perms[codename] = perm
|
||||
|
||||
for role in OrganizationRole.objects.filter(nombre__in=ROLES_AUDITORIA_FULL):
|
||||
role.permissions.add(perms['auditoria.view'], perms['auditoria.process'])
|
||||
|
||||
for role in OrganizationRole.objects.filter(nombre__in=ROLES_AUDITORIA_VIEW):
|
||||
role.permissions.add(perms['auditoria.view'])
|
||||
|
||||
|
||||
def revertir(apps, schema_editor):
|
||||
RolePermission = apps.get_model('rbac', 'RolePermission')
|
||||
OrganizationRole = apps.get_model('rbac', 'OrganizationRole')
|
||||
|
||||
for codename, _, _ in NUEVOS_PERMISOS:
|
||||
try:
|
||||
perm = RolePermission.objects.get(codename=codename)
|
||||
except RolePermission.DoesNotExist:
|
||||
continue
|
||||
for role in OrganizationRole.objects.all():
|
||||
role.permissions.remove(perm)
|
||||
perm.delete()
|
||||
|
||||
|
||||
class Migration(migrations.Migration):
|
||||
|
||||
dependencies = [
|
||||
('rbac', '0003_notificaciones_receive'),
|
||||
]
|
||||
|
||||
operations = [
|
||||
migrations.RunPython(agregar_auditoria, reverse_code=revertir),
|
||||
]
|
||||
0
api/rbac/migrations/__init__.py
Normal file
0
api/rbac/migrations/__init__.py
Normal file
Reference in New Issue
Block a user