* Add macsuck worker to collect various PortAccessEntity (NAC) attributes * Incorporate PAE feedback on #937 * missing Result/Device.pm column added * pae_is... columns instead of pae_capabilities * moved most code to Util/PortAccessEntity.pm so the update can be done in discover and macsuck * Refactor PAE attributes during discover as separate Plugin * PortAccessEntity: don't use device->dns in log string * Fix "Experimental keys on scalar is now forbidden" test failure * Revamp pae_control and add missing attribute - device.pae_control (text) is now device.pae_is_enabled (bool) - also store pae_authconfig_port_control (port mode auto/force(un)Auth) * Fix "Experimental keys on scalar is now forbidden" test failure - ... again because of botched merge - at least perlgolfed away a set of curly braces * Update PortAccessEntity.pm * Incorporate @ollyg PR feedback * allow actions without transport to run when there are also no creds * initial refactor for separate gather, process, store phases for macsuck * factor out the vlan sanity check * additional help with log of action workers * cleanup logic in check macsuck * refactor to make main phases only * some fixes * implement file slurp. amazingly the whole thing works * remove outdated noop from test * treat error as critical, use cancel to suppress further drivers * big refactor to share mac sanity code to both paths * fix inverted logic on vlan sanity filter * some code tidy * fix error in default value * fix for vlan 0 nodes input from cli * ensure imported MACs are IEEE format * add api endpoint, no useful return status yet * exit status if error from nodes PUT * suppress other networked workers when direct workers are active * better log showing worker * fix status recording to get first error or last done message * implement arpnip API PUT * avoid package redeclaration error * make sure write API methods require admin status * add doc for passing JSON data to arpnip and macsuck * update manifest * remove option to do jobs in web handler; all by queue now * use job entry timestamp for offline queued jobs * fix store username and IP on api PUT * never de-duplicate user-submitted jobs; never reset DeviceSkip for offline jobs * myworker no longer needed * make logic cleaner Co-authored-by: Christian Ramseyer <ramseyer@netnea.com>
		
			
				
	
	
		
			46 lines
		
	
	
		
			1.1 KiB
		
	
	
	
		
			Perl
		
	
	
	
	
	
			
		
		
	
	
			46 lines
		
	
	
		
			1.1 KiB
		
	
	
	
		
			Perl
		
	
	
	
	
	
| use utf8;
 | |
| package App::Netdisco::DB::Result::Virtual::UserRole;
 | |
| 
 | |
| use strict;
 | |
| use warnings;
 | |
| 
 | |
| use base 'DBIx::Class::Core';
 | |
| 
 | |
| __PACKAGE__->table_class('DBIx::Class::ResultSource::View');
 | |
| 
 | |
| __PACKAGE__->table("user_role");
 | |
| __PACKAGE__->result_source_instance->is_virtual(1);
 | |
| __PACKAGE__->result_source_instance->view_definition(<<ENDSQL
 | |
|   SELECT username, 'port_control' AS role FROM users
 | |
|     WHERE port_control
 | |
|   UNION
 | |
|   SELECT username, 'admin' AS role FROM users
 | |
|     WHERE admin
 | |
|   UNION
 | |
|   SELECT username, 'ldap' AS role FROM users
 | |
|     WHERE ldap
 | |
|   UNION
 | |
|   SELECT username, 'radius' AS role FROM users
 | |
|     WHERE radius
 | |
|   UNION
 | |
|   SELECT username, 'tacacs' AS role FROM users
 | |
|     WHERE tacacs
 | |
|   UNION
 | |
|   SELECT username, 'api' AS role FROM users
 | |
|     WHERE token IS NOT NULL AND token_from IS NOT NULL
 | |
|           AND token_from > (EXTRACT(EPOCH FROM now()) - ?)
 | |
|   UNION
 | |
|   SELECT username, 'api_admin' AS role FROM users
 | |
|     WHERE token IS NOT NULL AND token_from IS NOT NULL
 | |
|           AND token_from > (EXTRACT(EPOCH FROM now()) - ?)
 | |
|           AND admin
 | |
| ENDSQL
 | |
| );
 | |
| 
 | |
| __PACKAGE__->add_columns(
 | |
|   'username' => { data_type => 'text' },
 | |
|   'role' => { data_type => 'text' },
 | |
| );
 | |
| 
 | |
| 1;
 |