Skip to content

Commit

Permalink
feat: performance optimize
Browse files Browse the repository at this point in the history
Signed-off-by: SuZhou-Joe <[email protected]>
  • Loading branch information
SuZhou-Joe committed Aug 17, 2023
1 parent 8b9113a commit 3221672
Showing 1 changed file with 25 additions and 8 deletions.
33 changes: 25 additions & 8 deletions src/core/server/saved_objects/permission_control/client.ts
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ import { SavedObjectsServiceStart } from '../saved_objects_service';
import { SavedObjectsBulkGetObject } from '../service';
import { ACL, Principals, TransformedPermission, PrincipalType } from './acl';
import { WORKSPACE_TYPE } from '../constants';
import { SavedObject } from '../types';

export type SavedObjectsPermissionControlContract = Pick<
SavedObjectsPermissionControl,
Expand Down Expand Up @@ -73,6 +74,27 @@ export class SavedObjectsPermissionControl {
return await this.batchValidate(request, [savedObject], permissionModes);
}

/**
* In batch validate case, the logic is a.withPermission && b.withPermission
* @param request
* @param savedObjectsGet
* @param permissionModes
* @returns
*/
public batchValidateInmemory(
request: OpenSearchDashboardsRequest,
savedObjectsGet: SavedObject[],
permissionModes: SavedObjectsPermissionModes
) {
const principals = this.getPrincipalsFromRequest(request);
const hasAllPermission = savedObjectsGet.every((item) => {
// item.permissions
const aclInstance = new ACL(item.permissions);
return aclInstance.hasPermission(permissionModes, principals);
});
return hasAllPermission;
}

/**
* In batch validate case, the logic is a.withPermission && b.withPermission
* @param request
Expand All @@ -86,16 +108,11 @@ export class SavedObjectsPermissionControl {
permissionModes: SavedObjectsPermissionModes
) {
const savedObjectsGet = await this.bulkGetSavedObjects(request, savedObjects);
if (savedObjectsGet) {
const principals = this.getPrincipalsFromRequest(request);
const hasAllPermission = savedObjectsGet.every((item) => {
// item.permissions
const aclInstance = new ACL(item.permissions);
return aclInstance.hasPermission(permissionModes, principals);
});
if (savedObjectsGet && savedObjectsGet.length) {
const result = this.batchValidateInmemory(request, savedObjectsGet, permissionModes);
return {
success: true,
result: hasAllPermission,
result,
};
}

Expand Down

0 comments on commit 3221672

Please sign in to comment.