
As per the community goal of migrating the policy file the format from JSON to YAML[1], we need to do two things: 1. Change the default value of '[oslo_policy] policy_file'' config option from 'policy.json' to 'policy.yaml' with upgrade checks. 2. Deprecate the JSON formatted policy file on the project side via warning in doc and releasenotes. Also replace policy.json to policy.yaml ref from doc and tests. [1]https://governance.openstack.org/tc/goals/selected/wallaby/migrate-policy-format-from-json-to-yaml.html Change-Id: Idaa65dac1c97324d671b9a07a2f3d51bb128e8c2
57 lines
1.5 KiB
Python
57 lines
1.5 KiB
Python
# Copyright 2011-2012 OpenStack LLC.
|
|
# All Rights Reserved.
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License"); you may
|
|
# not use this file except in compliance with the License. You may obtain
|
|
# a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
|
|
# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
|
|
# License for the specific language governing permissions and limitations
|
|
# under the License.
|
|
|
|
from oslo_policy import opts
|
|
from oslo_policy import policy
|
|
|
|
from barbican.common import config
|
|
from barbican.common import policies
|
|
|
|
CONF = config.CONF
|
|
ENFORCER = None
|
|
|
|
|
|
# TODO(gmann): Remove setting the default value of config policy_file
|
|
# once oslo_policy change the default value to 'policy.yaml'.
|
|
# https://github.com/openstack/oslo.policy/blob/a626ad12fe5a3abd49d70e3e5b95589d279ab578/oslo_policy/opts.py#L49
|
|
DEFAULT_POLICY_FILE = 'policy.yaml'
|
|
opts.set_defaults(CONF, DEFAULT_POLICY_FILE)
|
|
|
|
|
|
def reset():
|
|
global ENFORCER
|
|
if ENFORCER:
|
|
ENFORCER.clear()
|
|
ENFORCER = None
|
|
|
|
|
|
def init():
|
|
global ENFORCER
|
|
global saved_file_rules
|
|
|
|
if not ENFORCER:
|
|
ENFORCER = policy.Enforcer(CONF)
|
|
register_rules(ENFORCER)
|
|
ENFORCER.load_rules()
|
|
|
|
|
|
def register_rules(enforcer):
|
|
enforcer.register_defaults(policies.list_rules())
|
|
|
|
|
|
def get_enforcer():
|
|
init()
|
|
return ENFORCER
|