Add staff visibility workstation enrollment registration vault and category task views
This commit is contained in:
@@ -52,7 +52,7 @@ def dashboard(request: Request, include_archived: bool = False):
|
||||
|
||||
|
||||
@router.get("/new", response_class=HTMLResponse)
|
||||
def new_entry(request: Request):
|
||||
def new_entry(request: Request, client_id: int | None = None, registration_id: int | None = None):
|
||||
with CommonSessionLocal() as db:
|
||||
user = _user(request, db)
|
||||
if not can_manage_vault(db, user): raise HTTPException(403, "Only firm managers may create credentials.")
|
||||
@@ -60,7 +60,21 @@ def new_entry(request: Request):
|
||||
clients = db.execute(select(Client).where(Client.tenant_id == tenant_id, Client.is_active.is_(True)).order_by(Client.client_name)).scalars().all()
|
||||
users = db.execute(select(User).where(User.tenant_id == tenant_id, User.is_active.is_(True)).order_by(User.full_name)).scalars().all()
|
||||
registrations = db.execute(select(ClientRegistration).where(ClientRegistration.tenant_id == tenant_id).order_by(ClientRegistration.registration_number)).scalars().all()
|
||||
return templates.TemplateResponse("modules/credential_vault/templates/credential_vault/form.html", _ctx(request, user, db, entry=None, clients=clients, users=users, registrations=registrations, branch_id=branch_id))
|
||||
selected_registration = None
|
||||
if registration_id:
|
||||
selected_registration = db.get(ClientRegistration, int(registration_id))
|
||||
if not selected_registration or selected_registration.tenant_id != tenant_id:
|
||||
raise HTTPException(404, "Registration record was not found in this audit firm.")
|
||||
client_id = int(selected_registration.client_id)
|
||||
if client_id and not any(int(c.id) == int(client_id) for c in clients):
|
||||
raise HTTPException(404, "Client was not found in this audit firm.")
|
||||
return templates.TemplateResponse(
|
||||
"modules/credential_vault/templates/credential_vault/form.html",
|
||||
_ctx(
|
||||
request, user, db, entry=None, clients=clients, users=users, registrations=registrations, branch_id=branch_id,
|
||||
selected_client_id=client_id, selected_registration_id=registration_id, selected_registration=selected_registration,
|
||||
),
|
||||
)
|
||||
|
||||
|
||||
@router.post("/new")
|
||||
@@ -69,7 +83,16 @@ async def save_new(request: Request, title: str=Form(...), category: str=Form("g
|
||||
user = _user(request, db); validate_csrf(request, csrf_token)
|
||||
if not can_manage_vault(db, user): raise HTTPException(403)
|
||||
tenant_id = active_tenant_id(request, user)
|
||||
entry = create_entry(db, tenant_id=tenant_id, branch_id=active_branch_id(request, user), client_id=int(client_id) if client_id else None, registration_id=int(registration_id) if registration_id else None, title=title, category=category, portal_url=portal_url, reference_number=reference_number, username=username, secret=secret, additional_secret=additional_secret, notes=notes, sensitivity=sensitivity, expires_on=_date(expires_on), rotation_due_on=_date(rotation_due_on), owner_user_id=int(owner_user_id) if owner_user_id else user.id, allowed_user_ids_csv=",".join(allowed_user_ids), actor_user_id=user.id)
|
||||
selected_client_id = int(client_id) if client_id else None
|
||||
selected_registration_id = int(registration_id) if registration_id else None
|
||||
if selected_registration_id:
|
||||
registration = db.get(ClientRegistration, selected_registration_id)
|
||||
if not registration or registration.tenant_id != tenant_id:
|
||||
raise HTTPException(400, "Selected registration is not available in this audit firm.")
|
||||
if selected_client_id and int(registration.client_id) != selected_client_id:
|
||||
raise HTTPException(400, "Selected registration does not belong to the selected client.")
|
||||
selected_client_id = int(registration.client_id)
|
||||
entry = create_entry(db, tenant_id=tenant_id, branch_id=active_branch_id(request, user), client_id=selected_client_id, registration_id=selected_registration_id, title=title, category=category, portal_url=portal_url, reference_number=reference_number, username=username, secret=secret, additional_secret=additional_secret, notes=notes, sensitivity=sensitivity, expires_on=_date(expires_on), rotation_due_on=_date(rotation_due_on), owner_user_id=int(owner_user_id) if owner_user_id else user.id, allowed_user_ids_csv=",".join(allowed_user_ids), actor_user_id=user.id)
|
||||
log_access(db, request, user, entry, "create", reason="Credential created"); db.commit()
|
||||
return RedirectResponse(f"/credential-vault/{entry.id}", 303)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user