permissions.py 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438
  1. """Permission definitions for the group-based access control system.
  2. This module defines all permissions using a string enum with `resource:action` naming.
  3. Permissions are additive across groups - a user has all permissions from all their groups.
  4. """
  5. from backend.app.core.compat import StrEnum
  6. class Permission(StrEnum):
  7. """All available permissions in the system.
  8. Permissions follow the pattern: resource:action
  9. Actions typically include: read, create, update, delete, plus resource-specific actions.
  10. """
  11. # Printers
  12. PRINTERS_READ = "printers:read"
  13. PRINTERS_CREATE = "printers:create"
  14. PRINTERS_UPDATE = "printers:update"
  15. PRINTERS_DELETE = "printers:delete"
  16. PRINTERS_CONTROL = "printers:control" # Start/stop/pause/resume prints
  17. PRINTERS_FILES = "printers:files" # Send files to printer
  18. PRINTERS_AMS_RFID = "printers:ams_rfid" # Re-read AMS RFID tags
  19. PRINTERS_CLEAR_PLATE = "printers:clear_plate" # Confirm plate cleared for next print
  20. # Archives
  21. ARCHIVES_READ = "archives:read"
  22. ARCHIVES_CREATE = "archives:create"
  23. ARCHIVES_UPDATE_OWN = "archives:update_own"
  24. ARCHIVES_UPDATE_ALL = "archives:update_all"
  25. ARCHIVES_DELETE_OWN = "archives:delete_own"
  26. ARCHIVES_DELETE_ALL = "archives:delete_all"
  27. ARCHIVES_REPRINT_OWN = "archives:reprint_own"
  28. ARCHIVES_REPRINT_ALL = "archives:reprint_all"
  29. # Queue
  30. QUEUE_READ = "queue:read"
  31. QUEUE_CREATE = "queue:create"
  32. QUEUE_UPDATE_OWN = "queue:update_own"
  33. QUEUE_UPDATE_ALL = "queue:update_all"
  34. QUEUE_DELETE_OWN = "queue:delete_own"
  35. QUEUE_DELETE_ALL = "queue:delete_all"
  36. QUEUE_REORDER = "queue:reorder"
  37. # Library
  38. LIBRARY_READ = "library:read"
  39. LIBRARY_UPLOAD = "library:upload"
  40. LIBRARY_UPDATE_OWN = "library:update_own"
  41. LIBRARY_UPDATE_ALL = "library:update_all"
  42. LIBRARY_DELETE_OWN = "library:delete_own"
  43. LIBRARY_DELETE_ALL = "library:delete_all"
  44. # Projects
  45. PROJECTS_READ = "projects:read"
  46. PROJECTS_CREATE = "projects:create"
  47. PROJECTS_UPDATE = "projects:update"
  48. PROJECTS_DELETE = "projects:delete"
  49. # Filaments
  50. FILAMENTS_READ = "filaments:read"
  51. FILAMENTS_CREATE = "filaments:create"
  52. FILAMENTS_UPDATE = "filaments:update"
  53. FILAMENTS_DELETE = "filaments:delete"
  54. # Inventory (Spool Inventory, Spool Catalog, Color Catalog)
  55. INVENTORY_READ = "inventory:read"
  56. INVENTORY_CREATE = "inventory:create"
  57. INVENTORY_UPDATE = "inventory:update"
  58. INVENTORY_DELETE = "inventory:delete"
  59. INVENTORY_VIEW_ASSIGNMENTS = "inventory:view_assignments" # View spool-to-AMS assignments on printer cards
  60. # Smart Plugs
  61. SMART_PLUGS_READ = "smart_plugs:read"
  62. SMART_PLUGS_CREATE = "smart_plugs:create"
  63. SMART_PLUGS_UPDATE = "smart_plugs:update"
  64. SMART_PLUGS_DELETE = "smart_plugs:delete"
  65. SMART_PLUGS_CONTROL = "smart_plugs:control" # Turn on/off
  66. # Camera
  67. CAMERA_VIEW = "camera:view"
  68. # Maintenance
  69. MAINTENANCE_READ = "maintenance:read"
  70. MAINTENANCE_CREATE = "maintenance:create"
  71. MAINTENANCE_UPDATE = "maintenance:update"
  72. MAINTENANCE_DELETE = "maintenance:delete"
  73. # K-Profiles
  74. KPROFILES_READ = "kprofiles:read"
  75. KPROFILES_CREATE = "kprofiles:create"
  76. KPROFILES_UPDATE = "kprofiles:update"
  77. KPROFILES_DELETE = "kprofiles:delete"
  78. # Notifications
  79. NOTIFICATIONS_READ = "notifications:read"
  80. NOTIFICATIONS_CREATE = "notifications:create"
  81. NOTIFICATIONS_UPDATE = "notifications:update"
  82. NOTIFICATIONS_DELETE = "notifications:delete"
  83. NOTIFICATIONS_USER_EMAIL = "notifications:user_email" # Receive per-user print email notifications
  84. # Notification Templates
  85. NOTIFICATION_TEMPLATES_READ = "notification_templates:read"
  86. NOTIFICATION_TEMPLATES_UPDATE = "notification_templates:update"
  87. # External Links
  88. EXTERNAL_LINKS_READ = "external_links:read"
  89. EXTERNAL_LINKS_CREATE = "external_links:create"
  90. EXTERNAL_LINKS_UPDATE = "external_links:update"
  91. EXTERNAL_LINKS_DELETE = "external_links:delete"
  92. # Discovery (network scanning)
  93. DISCOVERY_SCAN = "discovery:scan"
  94. # Firmware
  95. FIRMWARE_READ = "firmware:read"
  96. FIRMWARE_UPDATE = "firmware:update"
  97. # AMS History
  98. AMS_HISTORY_READ = "ams_history:read"
  99. # Stats/Metrics
  100. STATS_READ = "stats:read"
  101. STATS_FILTER_BY_USER = "stats:filter_by_user"
  102. # System Info
  103. SYSTEM_READ = "system:read"
  104. # Settings (admin-level)
  105. SETTINGS_READ = "settings:read"
  106. SETTINGS_UPDATE = "settings:update"
  107. SETTINGS_BACKUP = "settings:backup"
  108. SETTINGS_RESTORE = "settings:restore"
  109. # GitHub Backup (admin-level)
  110. GITHUB_BACKUP = "github:backup"
  111. GITHUB_RESTORE = "github:restore"
  112. # Cloud Auth (admin-level)
  113. CLOUD_AUTH = "cloud:auth"
  114. # API Keys (admin-level)
  115. API_KEYS_READ = "api_keys:read"
  116. API_KEYS_CREATE = "api_keys:create"
  117. API_KEYS_UPDATE = "api_keys:update"
  118. API_KEYS_DELETE = "api_keys:delete"
  119. # Users (admin-level)
  120. USERS_READ = "users:read"
  121. USERS_CREATE = "users:create"
  122. USERS_UPDATE = "users:update"
  123. USERS_DELETE = "users:delete"
  124. # Groups (admin-level)
  125. GROUPS_READ = "groups:read"
  126. GROUPS_CREATE = "groups:create"
  127. GROUPS_UPDATE = "groups:update"
  128. GROUPS_DELETE = "groups:delete"
  129. # WebSocket connection
  130. WEBSOCKET_CONNECT = "websocket:connect"
  131. # Permission categories for UI organization
  132. PERMISSION_CATEGORIES = {
  133. "Printers": [
  134. Permission.PRINTERS_READ,
  135. Permission.PRINTERS_CREATE,
  136. Permission.PRINTERS_UPDATE,
  137. Permission.PRINTERS_DELETE,
  138. Permission.PRINTERS_CONTROL,
  139. Permission.PRINTERS_FILES,
  140. Permission.PRINTERS_AMS_RFID,
  141. Permission.PRINTERS_CLEAR_PLATE,
  142. ],
  143. "Archives": [
  144. Permission.ARCHIVES_READ,
  145. Permission.ARCHIVES_CREATE,
  146. Permission.ARCHIVES_UPDATE_OWN,
  147. Permission.ARCHIVES_UPDATE_ALL,
  148. Permission.ARCHIVES_DELETE_OWN,
  149. Permission.ARCHIVES_DELETE_ALL,
  150. Permission.ARCHIVES_REPRINT_OWN,
  151. Permission.ARCHIVES_REPRINT_ALL,
  152. ],
  153. "Queue": [
  154. Permission.QUEUE_READ,
  155. Permission.QUEUE_CREATE,
  156. Permission.QUEUE_UPDATE_OWN,
  157. Permission.QUEUE_UPDATE_ALL,
  158. Permission.QUEUE_DELETE_OWN,
  159. Permission.QUEUE_DELETE_ALL,
  160. Permission.QUEUE_REORDER,
  161. ],
  162. "Library": [
  163. Permission.LIBRARY_READ,
  164. Permission.LIBRARY_UPLOAD,
  165. Permission.LIBRARY_UPDATE_OWN,
  166. Permission.LIBRARY_UPDATE_ALL,
  167. Permission.LIBRARY_DELETE_OWN,
  168. Permission.LIBRARY_DELETE_ALL,
  169. ],
  170. "Projects": [
  171. Permission.PROJECTS_READ,
  172. Permission.PROJECTS_CREATE,
  173. Permission.PROJECTS_UPDATE,
  174. Permission.PROJECTS_DELETE,
  175. ],
  176. "Filaments": [
  177. Permission.FILAMENTS_READ,
  178. Permission.FILAMENTS_CREATE,
  179. Permission.FILAMENTS_UPDATE,
  180. Permission.FILAMENTS_DELETE,
  181. ],
  182. "Inventory": [
  183. Permission.INVENTORY_READ,
  184. Permission.INVENTORY_CREATE,
  185. Permission.INVENTORY_UPDATE,
  186. Permission.INVENTORY_DELETE,
  187. Permission.INVENTORY_VIEW_ASSIGNMENTS,
  188. ],
  189. "Smart Plugs": [
  190. Permission.SMART_PLUGS_READ,
  191. Permission.SMART_PLUGS_CREATE,
  192. Permission.SMART_PLUGS_UPDATE,
  193. Permission.SMART_PLUGS_DELETE,
  194. Permission.SMART_PLUGS_CONTROL,
  195. ],
  196. "Camera": [
  197. Permission.CAMERA_VIEW,
  198. ],
  199. "Maintenance": [
  200. Permission.MAINTENANCE_READ,
  201. Permission.MAINTENANCE_CREATE,
  202. Permission.MAINTENANCE_UPDATE,
  203. Permission.MAINTENANCE_DELETE,
  204. ],
  205. "K-Profiles": [
  206. Permission.KPROFILES_READ,
  207. Permission.KPROFILES_CREATE,
  208. Permission.KPROFILES_UPDATE,
  209. Permission.KPROFILES_DELETE,
  210. ],
  211. "Notifications": [
  212. Permission.NOTIFICATIONS_READ,
  213. Permission.NOTIFICATIONS_CREATE,
  214. Permission.NOTIFICATIONS_UPDATE,
  215. Permission.NOTIFICATIONS_DELETE,
  216. Permission.NOTIFICATIONS_USER_EMAIL,
  217. Permission.NOTIFICATION_TEMPLATES_READ,
  218. Permission.NOTIFICATION_TEMPLATES_UPDATE,
  219. ],
  220. "External Links": [
  221. Permission.EXTERNAL_LINKS_READ,
  222. Permission.EXTERNAL_LINKS_CREATE,
  223. Permission.EXTERNAL_LINKS_UPDATE,
  224. Permission.EXTERNAL_LINKS_DELETE,
  225. ],
  226. "Discovery": [
  227. Permission.DISCOVERY_SCAN,
  228. ],
  229. "Firmware": [
  230. Permission.FIRMWARE_READ,
  231. Permission.FIRMWARE_UPDATE,
  232. ],
  233. "Stats & History": [
  234. Permission.AMS_HISTORY_READ,
  235. Permission.STATS_READ,
  236. Permission.STATS_FILTER_BY_USER,
  237. ],
  238. "System": [
  239. Permission.SYSTEM_READ,
  240. ],
  241. "Settings": [
  242. Permission.SETTINGS_READ,
  243. Permission.SETTINGS_UPDATE,
  244. Permission.SETTINGS_BACKUP,
  245. Permission.SETTINGS_RESTORE,
  246. ],
  247. "Backup": [
  248. Permission.GITHUB_BACKUP,
  249. Permission.GITHUB_RESTORE,
  250. ],
  251. "Cloud": [
  252. Permission.CLOUD_AUTH,
  253. ],
  254. "API Keys": [
  255. Permission.API_KEYS_READ,
  256. Permission.API_KEYS_CREATE,
  257. Permission.API_KEYS_UPDATE,
  258. Permission.API_KEYS_DELETE,
  259. ],
  260. "User Management": [
  261. Permission.USERS_READ,
  262. Permission.USERS_CREATE,
  263. Permission.USERS_UPDATE,
  264. Permission.USERS_DELETE,
  265. Permission.GROUPS_READ,
  266. Permission.GROUPS_CREATE,
  267. Permission.GROUPS_UPDATE,
  268. Permission.GROUPS_DELETE,
  269. ],
  270. "WebSocket": [
  271. Permission.WEBSOCKET_CONNECT,
  272. ],
  273. }
  274. # All permissions as a list
  275. ALL_PERMISSIONS = [p.value for p in Permission]
  276. # Default group definitions
  277. DEFAULT_GROUPS = {
  278. "Administrators": {
  279. "description": "Full access to all features and settings",
  280. "permissions": ALL_PERMISSIONS, # All permissions
  281. "is_system": True,
  282. },
  283. "Operators": {
  284. "description": "Can control printers, manage queue and archives, view settings",
  285. "permissions": [
  286. # Printers - full control
  287. Permission.PRINTERS_READ.value,
  288. Permission.PRINTERS_CREATE.value,
  289. Permission.PRINTERS_UPDATE.value,
  290. Permission.PRINTERS_DELETE.value,
  291. Permission.PRINTERS_CONTROL.value,
  292. Permission.PRINTERS_FILES.value,
  293. Permission.PRINTERS_AMS_RFID.value,
  294. Permission.PRINTERS_CLEAR_PLATE.value,
  295. # Archives - own items only
  296. Permission.ARCHIVES_READ.value,
  297. Permission.ARCHIVES_CREATE.value,
  298. Permission.ARCHIVES_UPDATE_OWN.value,
  299. Permission.ARCHIVES_DELETE_OWN.value,
  300. Permission.ARCHIVES_REPRINT_OWN.value,
  301. # Queue - own items only
  302. Permission.QUEUE_READ.value,
  303. Permission.QUEUE_CREATE.value,
  304. Permission.QUEUE_UPDATE_OWN.value,
  305. Permission.QUEUE_DELETE_OWN.value,
  306. Permission.QUEUE_REORDER.value,
  307. # Library - own items only
  308. Permission.LIBRARY_READ.value,
  309. Permission.LIBRARY_UPLOAD.value,
  310. Permission.LIBRARY_UPDATE_OWN.value,
  311. Permission.LIBRARY_DELETE_OWN.value,
  312. # Projects - full access
  313. Permission.PROJECTS_READ.value,
  314. Permission.PROJECTS_CREATE.value,
  315. Permission.PROJECTS_UPDATE.value,
  316. Permission.PROJECTS_DELETE.value,
  317. # Filaments - full access
  318. Permission.FILAMENTS_READ.value,
  319. Permission.FILAMENTS_CREATE.value,
  320. Permission.FILAMENTS_UPDATE.value,
  321. Permission.FILAMENTS_DELETE.value,
  322. # Inventory - full access
  323. Permission.INVENTORY_READ.value,
  324. Permission.INVENTORY_CREATE.value,
  325. Permission.INVENTORY_UPDATE.value,
  326. Permission.INVENTORY_DELETE.value,
  327. Permission.INVENTORY_VIEW_ASSIGNMENTS.value,
  328. # Smart Plugs - full access
  329. Permission.SMART_PLUGS_READ.value,
  330. Permission.SMART_PLUGS_CREATE.value,
  331. Permission.SMART_PLUGS_UPDATE.value,
  332. Permission.SMART_PLUGS_DELETE.value,
  333. Permission.SMART_PLUGS_CONTROL.value,
  334. # Camera - view
  335. Permission.CAMERA_VIEW.value,
  336. # Maintenance - full access
  337. Permission.MAINTENANCE_READ.value,
  338. Permission.MAINTENANCE_CREATE.value,
  339. Permission.MAINTENANCE_UPDATE.value,
  340. Permission.MAINTENANCE_DELETE.value,
  341. # K-Profiles - full access
  342. Permission.KPROFILES_READ.value,
  343. Permission.KPROFILES_CREATE.value,
  344. Permission.KPROFILES_UPDATE.value,
  345. Permission.KPROFILES_DELETE.value,
  346. # Notifications - full access
  347. Permission.NOTIFICATIONS_READ.value,
  348. Permission.NOTIFICATIONS_CREATE.value,
  349. Permission.NOTIFICATIONS_UPDATE.value,
  350. Permission.NOTIFICATIONS_DELETE.value,
  351. Permission.NOTIFICATIONS_USER_EMAIL.value,
  352. Permission.NOTIFICATION_TEMPLATES_READ.value,
  353. Permission.NOTIFICATION_TEMPLATES_UPDATE.value,
  354. # External Links - full access
  355. Permission.EXTERNAL_LINKS_READ.value,
  356. Permission.EXTERNAL_LINKS_CREATE.value,
  357. Permission.EXTERNAL_LINKS_UPDATE.value,
  358. Permission.EXTERNAL_LINKS_DELETE.value,
  359. # Discovery
  360. Permission.DISCOVERY_SCAN.value,
  361. # Firmware - read only
  362. Permission.FIRMWARE_READ.value,
  363. # Stats & History
  364. Permission.AMS_HISTORY_READ.value,
  365. Permission.STATS_READ.value,
  366. Permission.SYSTEM_READ.value,
  367. # Settings - read only
  368. Permission.SETTINGS_READ.value,
  369. # WebSocket
  370. Permission.WEBSOCKET_CONNECT.value,
  371. ],
  372. "is_system": True,
  373. },
  374. "Viewers": {
  375. "description": "Read-only access to printers, archives, and queue",
  376. "permissions": [
  377. # Read-only access
  378. Permission.PRINTERS_READ.value,
  379. Permission.ARCHIVES_READ.value,
  380. Permission.QUEUE_READ.value,
  381. Permission.LIBRARY_READ.value,
  382. Permission.PROJECTS_READ.value,
  383. Permission.FILAMENTS_READ.value,
  384. Permission.INVENTORY_READ.value,
  385. Permission.INVENTORY_VIEW_ASSIGNMENTS.value,
  386. Permission.SMART_PLUGS_READ.value,
  387. Permission.CAMERA_VIEW.value,
  388. Permission.MAINTENANCE_READ.value,
  389. Permission.KPROFILES_READ.value,
  390. Permission.NOTIFICATIONS_READ.value,
  391. Permission.NOTIFICATION_TEMPLATES_READ.value,
  392. Permission.EXTERNAL_LINKS_READ.value,
  393. Permission.FIRMWARE_READ.value,
  394. Permission.AMS_HISTORY_READ.value,
  395. Permission.STATS_READ.value,
  396. Permission.SYSTEM_READ.value,
  397. Permission.SETTINGS_READ.value,
  398. Permission.WEBSOCKET_CONNECT.value,
  399. ],
  400. "is_system": True,
  401. },
  402. }