mirror of
https://github.com/apache/cloudstack.git
synced 2025-10-26 08:42:29 +01:00
server: allow normal users to create isolated network without source nat (#5920)
This commit is contained in:
parent
638779ca37
commit
4a1ebb3fa5
@ -1360,9 +1360,8 @@ public class NetworkServiceImpl extends ManagerBase implements NetworkService, C
|
||||
|
||||
performBasicPrivateVlanChecks(vlanId, secondaryVlanId, privateVlanType);
|
||||
|
||||
// Regular user can create Guest Isolated Source Nat enabled network or L2 network only
|
||||
if (_accountMgr.isNormalUser(caller.getId())) {
|
||||
validateNetworkOfferingForRegularUser(ntwkOff);
|
||||
if (!_accountMgr.isRootAdmin(caller.getId())) {
|
||||
validateNetworkOfferingForNonRootAdminUser(ntwkOff);
|
||||
}
|
||||
|
||||
// Don't allow to specify vlan if the caller is not ROOT admin
|
||||
@ -1454,20 +1453,16 @@ public class NetworkServiceImpl extends ManagerBase implements NetworkService, C
|
||||
return network;
|
||||
}
|
||||
|
||||
private void validateNetworkOfferingForRegularUser(NetworkOfferingVO ntwkOff) {
|
||||
private void validateNetworkOfferingForNonRootAdminUser(NetworkOfferingVO ntwkOff) {
|
||||
if (ntwkOff.getTrafficType() != TrafficType.Guest) {
|
||||
throw new InvalidParameterValueException("Regular users can only create a Guest network");
|
||||
throw new InvalidParameterValueException("This user can only create a Guest network");
|
||||
}
|
||||
if (ntwkOff.getGuestType() == GuestType.Isolated && areServicesSupportedByNetworkOffering(ntwkOff.getId(), Service.SourceNat)) {
|
||||
s_logger.debug(String.format("Creating a network from network offerings having traffic type [%s] and network type [%s] with a service [%s] enabled.",
|
||||
TrafficType.Guest, GuestType.Isolated, Service.SourceNat.getName()));
|
||||
} else if (ntwkOff.getGuestType() == GuestType.L2) {
|
||||
if (ntwkOff.getGuestType() == GuestType.L2 || ntwkOff.getGuestType() == GuestType.Isolated) {
|
||||
s_logger.debug(String.format("Creating a network from network offerings having traffic type [%s] and network type [%s].",
|
||||
TrafficType.Guest, GuestType.L2));
|
||||
TrafficType.Guest, ntwkOff.getGuestType()));
|
||||
} else {
|
||||
throw new InvalidParameterValueException(
|
||||
String.format("Regular users can only create an %s network with a service [%s] enabled, or a %s network.",
|
||||
GuestType.Isolated, Service.SourceNat.getName(), GuestType.L2));
|
||||
String.format("This user can only create an %s network or a %s network.", GuestType.Isolated, GuestType.L2));
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user