return $scfg;
};
+my $api_sdn_vnets_config = sub {
+ my ($cfg, $id) = @_;
+
+ my $scfg = dclone(PVE::Network::SDN::Vnets::sdn_vnets_config($cfg, $id));
+ $scfg->{vnet} = $id;
+ $scfg->{digest} = $cfg->{digest};
+
+ return $scfg;
+};
+
+my $check_vnet_access = sub {
+ my ($vnet, $privs) = @_;
+
+ my $cfg = PVE::Network::SDN::Vnets::config();
+ my $rpcenv = PVE::RPCEnvironment::get();
+ my $authuser = $rpcenv->get_user();
+ my $scfg = &$api_sdn_vnets_config($cfg, $vnet);
+ my $zoneid = $scfg->{zone};
+ $rpcenv->check_any($authuser, "/sdn/zones/$zoneid/$vnet", $privs);
+};
+
__PACKAGE__->register_method ({
name => 'index',
path => '',
method => 'GET',
description => "SDN subnets index.",
permissions => {
- description => "Only list entries where you have 'SDN.Audit' or 'SDN.Allocate' permissions on '/sdn/subnets/<subnet>'",
+ description => "Only list entries where you have 'SDN.Audit' or 'SDN.Allocate' permissions on '/sdn/zones/<zone>/<vnet>'",
user => 'all',
},
parameters => {
code => sub {
my ($param) = @_;
- my $rpcenv = PVE::RPCEnvironment::get();
- my $authuser = $rpcenv->get_user();
-
- my $vnetid = $param->{vnet};
+ my $vnetid = $param->{vnet};
+ my $privs = [ 'SDN.Audit', 'SDN.Allocate' ];
+ &$check_vnet_access($vnetid, $privs);
my $cfg = {};
if($param->{pending}) {
my @sids = PVE::Network::SDN::Subnets::sdn_subnets_ids($cfg);
my $res = [];
foreach my $id (@sids) {
- my $privs = [ 'SDN.Audit', 'SDN.Allocate' ];
- next if !$rpcenv->check_any($authuser, "/sdn/vnets/$vnetid/subnets/$id", $privs, 1);
-
my $scfg = &$api_sdn_subnets_config($cfg, $id);
next if !$scfg->{vnet} || $scfg->{vnet} ne $vnetid;
push @$res, $scfg;
method => 'GET',
description => "Read sdn subnet configuration.",
permissions => {
- check => ['perm', '/sdn/vnets/{vnet}/subnets/{subnet}', ['SDN.Allocate']],
- },
-
+ description => "Require 'SDN.Audit' or 'SDN.Allocate' permissions on '/sdn/zones/<zone>/<vnet>'",
+ user => 'all',
+ },
parameters => {
additionalProperties => 0,
properties => {
code => sub {
my ($param) = @_;
+ my $vnet = extract_param($param, 'vnet');
+ my $privs = [ 'SDN.Audit', 'SDN.Allocate' ];
+ &$check_vnet_access($vnet, $privs);
+
my $cfg = {};
if($param->{pending}) {
my $running_cfg = PVE::Network::SDN::running_config();
my $scfg = &$api_sdn_subnets_config($cfg, $param->{subnet});
- raise_param_exc({ vnet => "wrong vnet"}) if $param->{vnet} ne $scfg->{vnet};
+ raise_param_exc({ vnet => "wrong vnet"}) if $vnet ne $scfg->{vnet};
return $scfg;
}});
method => 'POST',
description => "Create a new sdn subnet object.",
permissions => {
- check => ['perm', '/sdn/vnets/{vnet}/subnets', ['SDN.Allocate']],
+ description => "Require 'SDN.Allocate' permission on '/sdn/zones/<zone>/<vnet>'",
+ user => 'all',
},
parameters => PVE::Network::SDN::SubnetPlugin->createSchema(),
returns => { type => 'null' },
my $type = extract_param($param, 'type');
my $cidr = extract_param($param, 'subnet');
+ my $vnet = $param->{vnet};
+ my $privs = [ 'SDN.Allocate' ];
+ &$check_vnet_access($vnet, $privs);
+
# create /etc/pve/sdn directory
PVE::Cluster::check_cfs_quorum();
mkdir("/etc/pve/sdn") if ! -d '/etc/pve/sdn';
method => 'PUT',
description => "Update sdn subnet object configuration.",
permissions => {
- check => ['perm', '/sdn/vnets/{vnet}/subnets', ['SDN.Allocate']],
+ description => "Require 'SDN.Allocate' permission on '/sdn/zones/<zone>/<vnet>'",
+ user => 'all',
},
parameters => PVE::Network::SDN::SubnetPlugin->updateSchema(),
returns => { type => 'null' },
my $id = extract_param($param, 'subnet');
my $digest = extract_param($param, 'digest');
+ my $vnet = $param->{vnet};
+
+ my $privs = [ 'SDN.Allocate' ];
+ &$check_vnet_access($vnet, $privs);
PVE::Network::SDN::lock_sdn_config(
sub {
my $cfg = PVE::Network::SDN::Subnets::config();
my $zone_cfg = PVE::Network::SDN::Zones::config();
my $vnet_cfg = PVE::Network::SDN::Vnets::config();
- my $vnet = $param->{vnet};
my $zoneid = $vnet_cfg->{ids}->{$vnet}->{zone};
my $zone = $zone_cfg->{ids}->{$zoneid};
method => 'DELETE',
description => "Delete sdn subnet object configuration.",
permissions => {
- check => ['perm', '/sdn/vnets/{vnet}/subnets', ['SDN.Allocate']],
+ description => "Require 'SDN.Allocate' permission on '/sdn/zones/<zone>/<vnet>'",
+ user => 'all',
},
parameters => {
additionalProperties => 0,
my ($param) = @_;
my $id = extract_param($param, 'subnet');
+ my $vnet = extract_param($param, 'vnet');
+ my $privs = [ 'SDN.Allocate' ];
+ &$check_vnet_access($vnet, $privs);
PVE::Network::SDN::lock_sdn_config(
sub {
PVE::Network::SDN::SubnetPlugin->on_delete_hook($id, $cfg, $vnets_cfg);
my $zone_cfg = PVE::Network::SDN::Zones::config();
- my $vnet = $param->{vnet};
my $zoneid = $vnets_cfg->{ids}->{$vnet}->{zone};
my $zone = $zone_cfg->{ids}->{$zoneid};
}
};
+my $check_vnet_access = sub {
+ my ($vnet, $privs) = @_;
+
+ my $cfg = PVE::Network::SDN::Vnets::config();
+ my $rpcenv = PVE::RPCEnvironment::get();
+ my $authuser = $rpcenv->get_user();
+ my $scfg = &$api_sdn_vnets_config($cfg, $vnet);
+ my $zoneid = $scfg->{zone};
+ $rpcenv->check_any($authuser, "/sdn/zones/$zoneid/$vnet", $privs);
+};
+
__PACKAGE__->register_method ({
name => 'index',
path => '',
description => "SDN vnets index.",
permissions => {
description => "Only list entries where you have 'SDN.Audit' or 'SDN.Allocate'"
- ." permissions on '/sdn/vnets/<vnet>'",
+ ." permissions on '/sdn/zones/<zone>/<vnet>'",
user => 'all',
},
parameters => {
my $res = [];
foreach my $id (@sids) {
my $privs = [ 'SDN.Audit', 'SDN.Allocate' ];
- next if !$rpcenv->check_any($authuser, "/sdn/vnets/$id", $privs, 1);
-
my $scfg = &$api_sdn_vnets_config($cfg, $id);
+ my $zoneid = $scfg->{zone};
+ next if !$rpcenv->check_any($authuser, "/sdn/zones/$zoneid/$id", $privs, 1);
+
push @$res, $scfg;
}
method => 'GET',
description => "Read sdn vnet configuration.",
permissions => {
- check => ['perm', '/sdn/vnets/{vnet}', ['SDN.Allocate']],
- },
+ description => "Require 'SDN.Audit' or 'SDN.Allocate' permissions on '/sdn/zones/<zone>/<vnet>'",
+ user => 'all',
+ },
parameters => {
additionalProperties => 0,
properties => {
code => sub {
my ($param) = @_;
+ my $id = extract_param($param, 'vnet');
+
+ my $privs = [ 'SDN.Audit', 'SDN.Allocate' ];
+ &$check_vnet_access($id, $privs);
+
my $cfg = {};
if($param->{pending}) {
my $running_cfg = PVE::Network::SDN::running_config();
$cfg = PVE::Network::SDN::Vnets::config();
}
- return $api_sdn_vnets_config->($cfg, $param->{vnet});
+ return $api_sdn_vnets_config->($cfg, $id);
}});
__PACKAGE__->register_method ({
method => 'POST',
description => "Create a new sdn vnet object.",
permissions => {
- check => ['perm', '/sdn/vnets', ['SDN.Allocate']],
+ check => ['perm', '/sdn/zones/{zone}', ['SDN.Allocate']],
},
parameters => PVE::Network::SDN::VnetPlugin->createSchema(),
returns => { type => 'null' },
method => 'PUT',
description => "Update sdn vnet object configuration.",
permissions => {
- check => ['perm', '/sdn/vnets', ['SDN.Allocate']],
+ description => "Require 'SDN.Allocate' permission on '/sdn/zones/<zone>/<vnet>'",
+ user => 'all',
},
parameters => PVE::Network::SDN::VnetPlugin->updateSchema(),
returns => { type => 'null' },
my $id = extract_param($param, 'vnet');
my $digest = extract_param($param, 'digest');
+ my $privs = [ 'SDN.Allocate' ];
+ &$check_vnet_access($id, $privs);
+
PVE::Network::SDN::lock_sdn_config(sub {
my $cfg = PVE::Network::SDN::Vnets::config();
PVE::SectionConfig::assert_if_modified($cfg, $digest);
-
my $opts = PVE::Network::SDN::VnetPlugin->check_config($id, $param, 0, 1);
raise_param_exc({ zone => "missing zone"}) if !$opts->{zone};
my $subnets = PVE::Network::SDN::Vnets::get_subnets($id);
method => 'DELETE',
description => "Delete sdn vnet object configuration.",
permissions => {
- check => ['perm', '/sdn/vnets', ['SDN.Allocate']],
+ description => "Require 'SDN.Allocate' permission on '/sdn/zones/<zone>/<vnet>'",
+ user => 'all',
},
parameters => {
additionalProperties => 0,
my $id = extract_param($param, 'vnet');
+ my $privs = [ 'SDN.Allocate' ];
+ &$check_vnet_access($id, $privs);
+
PVE::Network::SDN::lock_sdn_config(sub {
my $cfg = PVE::Network::SDN::Vnets::config();
my $scfg = PVE::Network::SDN::Vnets::sdn_vnets_config($cfg, $id); # check if exists