Files
leocrm/app/plugins/builtins/permissions/routes.py
T
Agent Zero e17b9c9e56
Check Cross-Plugin Imports / check (push) Has been cancelled
Phase 2: Visibility Filter & Owner ID
- Add OwnedMixin to 15 models (contact_folder, user_preference, workspace,
  mcp_server_config, agent_definition, automation_definition, report_template,
  report_instance, entity_link, comm_conversation, proactive_suggestion,
  ai_agent, ai_chat_session, tag, share_link)
- Migration 0102: Add owner_id column to 15 tables with backfill from user_id
- Fix EntityPermission Registry: remove notification, add entity_attachment,
  entity_history, subtask, calendar, folder; fix wrong class names
  (DmsFile→File, CalendarEvent→CalendarEntry, Mailbox→MailAccount)
- Add apply_visibility_filter to list endpoints in tags, tasks, mcp_client,
  automation, report_generator, ai_assistant routes
- Add owner_id to create handlers for all new OwnedMixin models
- Patch tasks/services.py and automation/services.py list methods with
  user_id and is_system_admin parameters
2026-08-04 00:03:29 +02:00

314 lines
9.7 KiB
Python

"""Permissions plugin routes — file/folder permissions, share links, public access."""
from __future__ import annotations
import secrets
import uuid
from datetime import UTC, datetime
from fastapi import APIRouter, Depends, HTTPException, Response, status
from sqlalchemy import select
from sqlalchemy.ext.asyncio import AsyncSession
from app.core.auth import hash_password, verify_password
from app.core.db import get_db
from app.core.visibility import apply_visibility_filter
from app.deps import get_current_user, require_permission
from app.plugins.builtins.permissions.models import Permission, ShareLink
from app.plugins.builtins.permissions.schemas import (
PermissionGrantRequest,
ShareLinkCreateRequest,
ShareLinkVerifyRequest,
)
router = APIRouter(
prefix="/api/v1/permissions",
tags=["permissions"],
dependencies=[Depends(require_permission("permissions:admin"))],
)
public_router = APIRouter(prefix="/api/public", tags=["public-share"])
def _parse_uuid(val: str, field: str) -> uuid.UUID:
try:
return uuid.UUID(val)
except (ValueError, TypeError):
raise HTTPException(
400, detail={"detail": f"Invalid {field}", "code": "invalid_id"}
) from None
# ─── Permissions CRUD ───
@router.get("/files/{file_id}/permissions")
async def list_permissions(
file_id: str,
db: AsyncSession = Depends(get_db),
current_user: dict = Depends(get_current_user),
):
"""List all permissions for a file."""
tenant_id = uuid.UUID(current_user["tenant_id"])
user_id = uuid.UUID(current_user["user_id"])
fid = _parse_uuid(file_id, "file_id")
result = await db.execute(
select(Permission).where(
Permission.tenant_id == tenant_id,
Permission.file_id == fid,
)
)
perms = result.scalars().all()
return [
{
"id": str(p.id),
"file_id": str(p.file_id),
"user_id": str(p.user_id),
"group_id": str(p.group_id) if p.group_id else None,
"access_level": p.access_level,
}
for p in perms
]
@router.post("/files/{file_id}/permissions", status_code=status.HTTP_201_CREATED)
async def grant_permission(
file_id: str,
body: PermissionGrantRequest,
db: AsyncSession = Depends(get_db),
current_user: dict = Depends(get_current_user),
):
"""Grant a permission on a file to a user."""
tenant_id = uuid.UUID(current_user["tenant_id"])
user_id = uuid.UUID(current_user["user_id"])
fid = _parse_uuid(file_id, "file_id")
user_id = _parse_uuid(body.user_id, "user_id")
group_id = _parse_uuid(body.group_id, "group_id") if body.group_id else None
# Check if permission already exists
existing = await db.execute(
select(Permission).where(
Permission.tenant_id == tenant_id,
Permission.file_id == fid,
Permission.user_id == user_id,
Permission.access_level == body.access_level,
)
)
if existing.scalar_one_or_none() is not None:
raise HTTPException(
409, detail={"detail": "Permission already exists", "code": "duplicate"}
)
perm = Permission(
tenant_id=tenant_id,
file_id=fid,
user_id=user_id,
group_id=group_id,
access_level=body.access_level,
)
db.add(perm)
await db.flush()
return {
"id": str(perm.id),
"file_id": str(perm.file_id),
"user_id": str(perm.user_id),
"group_id": str(perm.group_id) if perm.group_id else None,
"access_level": perm.access_level,
}
@router.delete("/files/{file_id}/permissions/{user_id}", status_code=status.HTTP_204_NO_CONTENT)
async def revoke_permission(
file_id: str,
user_id: str,
db: AsyncSession = Depends(get_db),
current_user: dict = Depends(get_current_user),
):
"""Revoke all permissions for a user on a file."""
tenant_id = uuid.UUID(current_user["tenant_id"])
user_id = uuid.UUID(current_user["user_id"])
fid = _parse_uuid(file_id, "file_id")
uid = _parse_uuid(user_id, "user_id")
result = await db.execute(
select(Permission).where(
Permission.tenant_id == tenant_id,
Permission.file_id == fid,
Permission.user_id == uid,
)
)
perms = result.scalars().all()
if not perms:
raise HTTPException(404, detail={"detail": "Permission not found", "code": "not_found"})
for p in perms:
await db.delete(p)
return Response(status_code=status.HTTP_204_NO_CONTENT)
# ─── Permission Check Helper ───
async def check_user_file_permission(
db: AsyncSession,
tenant_id: uuid.UUID,
file_id: uuid.UUID,
user_id: uuid.UUID,
required: str = "read",
) -> bool:
"""Check if user has required permission on a file."""
result = await db.execute(
select(Permission).where(
Permission.tenant_id == tenant_id,
Permission.file_id == file_id,
Permission.user_id == user_id,
)
)
perms = result.scalars().all()
if not perms:
return False
if required == "read":
return any(p.access_level in ("read", "write") for p in perms)
if required == "write":
return any(p.access_level == "write" for p in perms)
return False
# ─── Share Links ───
@router.post("/files/{file_id}/share-link")
async def create_share_link(
file_id: str,
body: ShareLinkCreateRequest,
db: AsyncSession = Depends(get_db),
current_user: dict = Depends(get_current_user),
):
"""Create a public share link for a file."""
tenant_id = uuid.UUID(current_user["tenant_id"])
user_id = uuid.UUID(current_user["user_id"])
fid = _parse_uuid(file_id, "file_id")
token = secrets.token_urlsafe(32)
password_hash = hash_password(body.password) if body.password else None
link = ShareLink(
tenant_id=tenant_id,
file_id=fid,
token=token,
password_hash=password_hash,
expires_at=body.expires_at,
access_level=body.access_level,
created_by=user_id,
)
db.add(link)
await db.flush()
return {
"id": str(link.id),
"file_id": str(link.file_id),
"token": token,
"public_url": f"/api/public/share/{token}",
"expires_at": link.expires_at.isoformat() if link.expires_at else None,
"access_level": link.access_level,
"has_password": password_hash is not None,
}
@router.delete("/share-links/{link_id}", status_code=status.HTTP_204_NO_CONTENT)
async def revoke_share_link(
link_id: str,
db: AsyncSession = Depends(get_db),
current_user: dict = Depends(get_current_user),
):
"""Revoke (delete) a share link."""
tenant_id = uuid.UUID(current_user["tenant_id"])
lid = _parse_uuid(link_id, "link_id")
result = await db.execute(
select(ShareLink).where(ShareLink.id == lid, ShareLink.tenant_id == tenant_id)
)
link = result.scalar_one_or_none()
if link is None:
raise HTTPException(404, detail={"detail": "Share link not found", "code": "not_found"})
await db.delete(link)
return Response(status_code=status.HTTP_204_NO_CONTENT)
# ─── Public Share Access (NO AUTH) ───
@public_router.get("/share/{token}")
async def public_access(
token: str,
db: AsyncSession = Depends(get_db),
):
"""Public share access — no auth required.
Returns 410 Gone if link is expired.
Returns 403 if password is required but not provided/invalid.
"""
result = await db.execute(select(ShareLink).where(ShareLink.token == token))
link = result.scalar_one_or_none()
if link is None:
raise HTTPException(404, detail={"detail": "Share link not found", "code": "not_found"})
# Check expiry
if link.expires_at is not None:
now = datetime.now(UTC)
if now > link.expires_at:
raise HTTPException(410, detail={"detail": "Share link expired", "code": "expired"})
# Check password
if link.password_hash is not None:
# Password must be provided via query param or header — check query param
# We need the request to get the password param
# For simplicity, return that password is required
raise HTTPException(
401,
detail={"detail": "Password required", "code": "password_required"},
)
return {
"file_id": str(link.file_id),
"access_level": link.access_level,
"has_password": False,
}
@public_router.post("/share/{token}")
async def public_access_with_password(
token: str,
body: ShareLinkVerifyRequest,
db: AsyncSession = Depends(get_db),
):
"""Public share access with password verification — no auth required."""
result = await db.execute(select(ShareLink).where(ShareLink.token == token))
link = result.scalar_one_or_none()
if link is None:
raise HTTPException(404, detail={"detail": "Share link not found", "code": "not_found"})
# Check expiry
if link.expires_at is not None:
now = datetime.now(UTC)
if now > link.expires_at:
raise HTTPException(410, detail={"detail": "Share link expired", "code": "expired"})
# Verify password if required
if link.password_hash is not None:
if body.password is None:
raise HTTPException(
401, detail={"detail": "Password required", "code": "password_required"}
)
if not verify_password(body.password, link.password_hash):
raise HTTPException(
403, detail={"detail": "Invalid password", "code": "invalid_password"}
)
return {
"file_id": str(link.file_id),
"access_level": link.access_level,
"has_password": link.password_hash is not None,
}