Skip to content
Projects
Groups
Snippets
Help
Loading...
Sign in
Toggle navigation
J
jumpserver
Project
Project
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
ops
jumpserver
Commits
7106e915
Commit
7106e915
authored
Nov 30, 2015
by
ibuler
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
modify sudo
parent
f7c8ad6f
Hide whitespace changes
Inline
Side-by-side
Showing
4 changed files
with
16 additions
and
42 deletions
+16
-42
ansible_api.py
jperm/ansible_api.py
+2
-17
views.py
jperm/views.py
+2
-19
perm_role_detail.html
templates/jperm/perm_role_detail.html
+1
-1
role_sudo.j2
templates/jperm/role_sudo.j2
+11
-5
No files found.
jperm/ansible_api.py
View file @
7106e915
...
@@ -442,23 +442,8 @@ class Tasks(Command):
...
@@ -442,23 +442,8 @@ class Tasks(Command):
:return:
:return:
"""
"""
module_args1
=
file_path
module_args1
=
file_path
ret1
=
self
.
__run
(
module_args1
,
"script"
)
ret
=
self
.
__run
(
module_args1
,
"script"
)
module_args2
=
'visudo -c | grep "parsed OK" &> /dev/null && echo "ok" || echo "failed"'
return
ret
ret2
=
self
.
__run
(
module_args2
,
"shell"
)
ret2_status
=
[
host_value
.
get
(
"stdout"
)
for
host_value
in
ret2
[
"result"
][
"contacted"
]
.
values
()]
result
=
{}
if
not
ret1
[
"msg"
]:
result
[
"step1"
]
=
"ok"
else
:
result
[
"msg"
]
=
ret1
[
"msg"
]
if
not
ret2
[
"msg"
]
and
"failed"
not
in
ret2_status
:
result
[
"step2"
]
=
"ok"
else
:
result
[
"msg"
]
=
ret1
[
"msg"
]
return
result
class
CustomAggregateStats
(
callbacks
.
AggregateStats
):
class
CustomAggregateStats
(
callbacks
.
AggregateStats
):
...
...
jperm/views.py
View file @
7106e915
...
@@ -410,25 +410,8 @@ def perm_role_push(request):
...
@@ -410,25 +410,8 @@ def perm_role_push(request):
for
asset_group
in
asset_groups_obj
:
for
asset_group
in
asset_groups_obj
:
group_assets_obj
.
extend
(
asset_group
.
asset_set
.
all
())
group_assets_obj
.
extend
(
asset_group
.
asset_set
.
all
())
calc_assets
=
list
(
set
(
assets_obj
)
|
set
(
group_assets_obj
))
calc_assets
=
list
(
set
(
assets_obj
)
|
set
(
group_assets_obj
))
# 生成Inventory
# push_resource = []
# for asset in calc_assets:
# if asset.use_default_auth:
# username = Setting.field1
# port = Setting.field2
# password = Setting.field3
# else:
# username = asset.username
# password = asset.password
# port = asset.port
# push_resource.append({"hostname": asset.ip,
# "port": port,
# "username": username,
# "password": password})
push_resource
=
gen_resource
(
calc_assets
)
push_resource
=
gen_resource
(
calc_assets
)
logger
.
debug
(
'Push role res:
%
s'
%
push_resource
)
logger
.
debug
(
'推送role res:
%
s'
%
push_resource
)
# 调用Ansible API 进行推送
# 调用Ansible API 进行推送
password_push
=
True
if
request
.
POST
.
get
(
"use_password"
)
else
False
password_push
=
True
if
request
.
POST
.
get
(
"use_password"
)
else
False
...
@@ -463,7 +446,7 @@ def perm_role_push(request):
...
@@ -463,7 +446,7 @@ def perm_role_push(request):
if
ret
[
'sudo'
]
.
get
(
'msg'
):
if
ret
[
'sudo'
]
.
get
(
'msg'
):
ret_failed
=
ret
[
'sudo'
]
.
get
(
'msg'
)
ret_failed
=
ret
[
'sudo'
]
.
get
(
'msg'
)
os
.
remove
(
add_sudo_script
)
#
os.remove(add_sudo_script)
logger
.
debug
(
'推送role结果:
%
s'
%
ret
)
logger
.
debug
(
'推送role结果:
%
s'
%
ret
)
logger
.
debug
(
'推送role错误:
%
s'
%
ret_failed
)
logger
.
debug
(
'推送role错误:
%
s'
%
ret_failed
)
...
...
templates/jperm/perm_role_detail.html
View file @
7106e915
...
@@ -204,7 +204,7 @@
...
@@ -204,7 +204,7 @@
<div
class=
"col-sm-4"
>
<div
class=
"col-sm-4"
>
<div
class=
"ibox float-e-margins"
>
<div
class=
"ibox float-e-margins"
>
<div
class=
"ibox-title"
>
<div
class=
"ibox-title"
>
<span
class=
"label label-
primary
"
><b>
未推送主机
</b></span>
<span
class=
"label label-
danger
"
><b>
未推送主机
</b></span>
<div
class=
"ibox-tools"
>
<div
class=
"ibox-tools"
>
<a
class=
"collapse-link"
>
<a
class=
"collapse-link"
>
<i
class=
"fa fa-chevron-up"
></i>
<i
class=
"fa fa-chevron-up"
></i>
...
...
templates/jperm/role_sudo.j2
View file @
7106e915
#!/bin/bash
#!/bin/bash
sudo
_file
=
/etc/sudoers
real
_file
=
/etc/sudoers
tmp_file
=
$(
mktemp
/tmp/XXXXXXX
)
# Add Command Aliases
# Add Command Aliases
add_cmd_alias
()
{
add_cmd_alias
()
{
sudo_file
=
$1
{
%
for
sudo
in
sudo_alias %
}
{
%
for
sudo
in
sudo_alias %
}
if
$(
grep
'^Cmnd_Alias {{ sudo.name }}'
${
sudo_file
}
&> /dev/null
)
;
then
if
$(
grep
'^Cmnd_Alias {{ sudo.name }}'
${
sudo_file
}
&> /dev/null
)
;
then
sed
-i
's@^Cmnd_Alias.*{{ sudo.name }}.*@Cmnd_Alias {{ sudo.name }} = {{ sudo.commands }}@g'
${
sudo_file
}
sed
-i
's@^Cmnd_Alias.*{{ sudo.name }}.*@Cmnd_Alias {{ sudo.name }} = {{ sudo.commands }}@g'
${
sudo_file
}
...
@@ -17,6 +18,7 @@ add_cmd_alias() {
...
@@ -17,6 +18,7 @@ add_cmd_alias() {
add_role_chosen
()
{
add_role_chosen
()
{
sudo_file
=
$1
{
%
for
role,
alias
in
role_chosen_aliase.items %
}
{
%
for
role,
alias
in
role_chosen_aliase.items %
}
if
$(
grep
'^{{ role }}.*'
${
sudo_file
}
&> /dev/null
)
;
then
if
$(
grep
'^{{ role }}.*'
${
sudo_file
}
&> /dev/null
)
;
then
sed
-i
's@^{{ role }}.*@{{ role }} ALL = NOPASSWD: {{ alias }}@g'
${
sudo_file
}
sed
-i
's@^{{ role }}.*@{{ role }} ALL = NOPASSWD: {{ alias }}@g'
${
sudo_file
}
...
@@ -26,6 +28,11 @@ add_role_chosen() {
...
@@ -26,6 +28,11 @@ add_role_chosen() {
{
% endfor %
}
{
% endfor %
}
}
}
check_syntax
(){
visudo
-c
-f
$1
}
cp
$real_file
$tmp_file
&&
add_cmd_alias
$tmp_file
&&
add_role_chosen
$tmp_file
||
exit
1
check_syntax
$tmp_file
&&
add_cmd_alias
$real_file
&&
add_role_chosen
$real_file
&&
rm
-f
$tmp_file
||
exit
2
check_syntax
$real_file
add_cmd_alias
add_role_chosen
\ No newline at end of file
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment