return $copy;
}
-my $rules_modify_permissions = sub {
- my ($rule_env) = @_;
-
- if ($rule_env eq 'host') {
- return {
- check => ['perm', '/nodes/{node}', [ 'Sys.Modify' ]],
- };
- } elsif ($rule_env eq 'cluster' || $rule_env eq 'group') {
- return {
- check => ['perm', '/', [ 'Sys.Modify' ]],
- };
- } elsif ($rule_env eq 'vm' || $rule_env eq 'ct') {
- return {
- check => ['perm', '/vms/{vmid}', [ 'VM.Config.Network' ]],
- }
- }
-
- return undef;
-};
-
-my $rules_audit_permissions = sub {
- my ($rule_env) = @_;
-
- if ($rule_env eq 'host') {
- return {
- check => ['perm', '/nodes/{node}', [ 'Sys.Audit' ]],
- };
- } elsif ($rule_env eq 'cluster' || $rule_env eq 'group') {
- return {
- check => ['perm', '/', [ 'Sys.Audit' ]],
- };
- } elsif ($rule_env eq 'vm' || $rule_env eq 'ct') {
- return {
- check => ['perm', '/vms/{vmid}', [ 'VM.Audit' ]],
- }
- }
-
- return undef;
-};
-
sub register_get_rules {
my ($class) = @_;
path => '',
method => 'GET',
description => "List rules.",
- permissions => &$rules_audit_permissions($rule_env),
+ permissions => PVE::Firewall::rules_audit_permissions($rule_env),
parameters => {
additionalProperties => 0,
properties => $properties,
path => '{pos}',
method => 'GET',
description => "Get single rule data.",
- permissions => &$rules_audit_permissions($rule_env),
+ permissions => PVE::Firewall::rules_audit_permissions($rule_env),
parameters => {
additionalProperties => 0,
properties => $properties,
method => 'POST',
description => "Create new rule.",
protected => 1,
- permissions => &$rules_modify_permissions($rule_env),
+ permissions => PVE::Firewall::rules_modify_permissions($rule_env),
parameters => {
additionalProperties => 0,
properties => $create_rule_properties,
method => 'PUT',
description => "Modify rule data.",
protected => 1,
- permissions => &$rules_modify_permissions($rule_env),
+ permissions => PVE::Firewall::rules_modify_permissions($rule_env),
parameters => {
additionalProperties => 0,
properties => $update_rule_properties,
method => 'DELETE',
description => "Delete rule.",
protected => 1,
- permissions => &$rules_modify_permissions($rule_env),
+ permissions => PVE::Firewall::rules_modify_permissions($rule_env),
parameters => {
additionalProperties => 0,
properties => $properties,