[2e46f35] | 1 | #!/usr/bin/env python |
---|
[516b7cc] | 2 | |
---|
| 3 | import os, sys |
---|
| 4 | import MySQLdb |
---|
| 5 | import tempfile |
---|
| 6 | from optparse import OptionParser |
---|
| 7 | |
---|
[406f3b5] | 8 | from deter import fedid |
---|
[516b7cc] | 9 | |
---|
| 10 | class opt_parser(OptionParser): |
---|
| 11 | def __init__(self): |
---|
| 12 | OptionParser.__init__(self, usage="%prog [opts] (--help for details)", |
---|
| 13 | version="0.1") |
---|
| 14 | self.add_option('-u', '--user', dest='users', action='append', |
---|
| 15 | default=[], help="Users to extract from DB") |
---|
| 16 | self.add_option('-p', '--project', dest='projects', action='append', |
---|
| 17 | default=[], help="Projects to extract from DB") |
---|
| 18 | self.add_option('-U', '--no-user-access', dest='user_access', |
---|
| 19 | default=True, action='store_false', |
---|
| 20 | help='do not output a user-only access entry') |
---|
| 21 | self.add_option('-P', '--no-project-access', dest='project_access', |
---|
| 22 | default=True, action='store_false', |
---|
| 23 | help='do not output project-based access entries') |
---|
| 24 | |
---|
| 25 | |
---|
| 26 | def cert_to_fid(cstr): |
---|
| 27 | fd, path = tempfile.mkstemp('.pem') |
---|
| 28 | try: |
---|
| 29 | try: |
---|
| 30 | f = os.fdopen(fd, "w") |
---|
| 31 | print >>f, cstr |
---|
| 32 | f.close() |
---|
| 33 | except IOError, e: |
---|
| 34 | print >>sys.stderr, "Error creating user %s" % u |
---|
| 35 | return fedid(file=path) |
---|
| 36 | finally: |
---|
| 37 | os.remove(path) |
---|
| 38 | |
---|
| 39 | |
---|
| 40 | def add_list(l, field): |
---|
| 41 | str = "" |
---|
| 42 | for x in l: |
---|
| 43 | if str: str += " OR " |
---|
| 44 | else: str = " AND (" |
---|
| 45 | |
---|
| 46 | str += "%s='%s'" % (field, x) |
---|
| 47 | if str: str += ")" |
---|
| 48 | return str |
---|
| 49 | |
---|
| 50 | |
---|
| 51 | fids = { } |
---|
| 52 | q_start = """ |
---|
| 53 | SELECT |
---|
[f3898f7] | 54 | g.uid, |
---|
| 55 | CASE g.gid |
---|
| 56 | WHEN g.pid THEN g.pid |
---|
| 57 | ELSE CONCAT(g.pid, '/', g.gid) |
---|
| 58 | END, |
---|
[516b7cc] | 59 | CONCAT('-----BEGIN CERTIFICATE-----\\n', |
---|
| 60 | s.cert, |
---|
| 61 | '-----END CERTIFICATE-----\\n'), |
---|
| 62 | encrypted |
---|
| 63 | FROM group_membership g INNER JOIN user_sslcerts s |
---|
| 64 | ON g.uid = s.uid |
---|
[f3898f7] | 65 | WHERE revoked is NULL |
---|
[516b7cc] | 66 | """ |
---|
| 67 | q_end =""" |
---|
| 68 | ORDER BY s.uid |
---|
| 69 | """ |
---|
| 70 | |
---|
| 71 | opts, args = opt_parser().parse_args() |
---|
| 72 | |
---|
| 73 | if not ( opts.project_access or opts.user_access): |
---|
| 74 | sys.exit("No output if both --no-project-access and " +\ |
---|
| 75 | "--no-user-access are given") |
---|
| 76 | |
---|
| 77 | user_clause= add_list(opts.users, 'g.uid') |
---|
| 78 | project_clause= add_list(opts.projects, 'g.pid') |
---|
| 79 | |
---|
| 80 | query = q_start + user_clause + project_clause + q_end |
---|
| 81 | |
---|
| 82 | db = MySQLdb.connect(db='tbdb') |
---|
| 83 | c = db.cursor() |
---|
| 84 | c.execute(query) |
---|
| 85 | |
---|
| 86 | for u, p, c, e in c.fetchall(): |
---|
| 87 | fid = fids.get(c, None) |
---|
| 88 | |
---|
| 89 | if not fid: |
---|
| 90 | fid = cert_to_fid(c) |
---|
| 91 | fids[c] = fid |
---|
| 92 | if e: print "# %s (encrypted)" % u |
---|
| 93 | else: print "# %s" % u |
---|
| 94 | if opts.user_access: |
---|
| 95 | print "fedid:%s->%s" % (fid, u) |
---|
| 96 | |
---|
| 97 | if opts.project_access: |
---|
| 98 | print "fedid:%s->(%s,%s)" % (fid, p, u) |
---|