feat(omny): fall back to OS login for superuser check when no pgroup is set
CI for csaxs_bec / test (push) Successful in 2m3s
CI for csaxs_bec / test (push) Successful in 2m3s
bec.active_account is a Redis-backed pgroup, only set via bec-set-account
-- a fresh dev/test session normally has it unset. _is_superuser_account()
now falls back to os.getenv("USER") in that case, matching the
account/system-user comparison convention already used in
OMNY_shared/omny_general_tools.py's _accounts_match(). Lets gac-x01dc's
superuser grant take effect without requiring bec-set-account first.
This commit is contained in:
@@ -1338,7 +1338,13 @@ class OMNY(
|
||||
)
|
||||
|
||||
def _is_superuser_account(self) -> bool:
|
||||
"""Whether the active BEC account is allowed to select advanced tomo modes."""
|
||||
"""Whether the active BEC account is allowed to select advanced tomo modes.
|
||||
|
||||
bec.active_account is a pgroup set explicitly via `bec-set-account`; when no
|
||||
pgroup has been set yet (e.g. a fresh dev/test session), fall back to the OS
|
||||
login (matches the account/system-user comparison convention already used in
|
||||
OMNY_shared/omny_general_tools.py's _accounts_match()).
|
||||
"""
|
||||
bec = builtins.__dict__.get("bec")
|
||||
try:
|
||||
account = bec.active_account
|
||||
@@ -1346,6 +1352,8 @@ class OMNY(
|
||||
return False
|
||||
if isinstance(account, bytes):
|
||||
account = account.decode()
|
||||
if not account:
|
||||
account = os.getenv("USER") or ""
|
||||
return bool(account) and account in _SUPERUSER_ACCOUNTS
|
||||
|
||||
def tomo_parameters(self):
|
||||
|
||||
@@ -192,6 +192,24 @@ def test_is_superuser_account_false_when_empty_allowlist(monkeypatch, fake_bec):
|
||||
assert omny._is_superuser_account() is False
|
||||
|
||||
|
||||
def test_is_superuser_account_falls_back_to_os_user_when_no_pgroup_set(monkeypatch, fake_bec):
|
||||
"""bec.active_account is a pgroup, only set explicitly via bec-set-account. A
|
||||
fresh dev/test session with no pgroup set must fall back to the OS login."""
|
||||
monkeypatch.setattr(omny_module, "_SUPERUSER_ACCOUNTS", frozenset({"gac-x01dc"}))
|
||||
fake_bec.active_account = ""
|
||||
monkeypatch.setenv("USER", "gac-x01dc")
|
||||
omny = make_omny()
|
||||
assert omny._is_superuser_account() is True
|
||||
|
||||
|
||||
def test_is_superuser_account_no_pgroup_and_unlisted_os_user(monkeypatch, fake_bec):
|
||||
monkeypatch.setattr(omny_module, "_SUPERUSER_ACCOUNTS", frozenset({"gac-x01dc"}))
|
||||
fake_bec.active_account = ""
|
||||
monkeypatch.setenv("USER", "someone-else")
|
||||
omny = make_omny()
|
||||
assert omny._is_superuser_account() is False
|
||||
|
||||
|
||||
def test_tomo_parameters_forces_type_1_for_non_superuser(monkeypatch, fake_bec):
|
||||
"""A non-superuser account that ends up picking an advanced tomo_type via
|
||||
the interactive prompt must be forced back to tomo_type 1."""
|
||||
|
||||
Reference in New Issue
Block a user