diff options
Diffstat (limited to 'gn_auth/auth/authorisation/roles/models.py')
| -rw-r--r-- | gn_auth/auth/authorisation/roles/models.py | 21 |
1 files changed, 20 insertions, 1 deletions
diff --git a/gn_auth/auth/authorisation/roles/models.py b/gn_auth/auth/authorisation/roles/models.py index 6faeaca..89556a6 100644 --- a/gn_auth/auth/authorisation/roles/models.py +++ b/gn_auth/auth/authorisation/roles/models.py @@ -4,12 +4,12 @@ from functools import reduce from dataclasses import dataclass from typing import Sequence, Iterable, Optional +from gn_libs import sqlite3 as db from pymonad.either import Left, Right, Either from gn_auth.auth.errors import NotFoundError, AuthorisationError from gn_auth.auth.authorisation.resources.base import Resource -from ...db import sqlite3 as db from ...authentication.users import User from ..checks import authorised_p @@ -255,6 +255,25 @@ def assign_user_role_by_name( }) +def unassign_user_role_by_name( + cursor: db.DbCursor, user: User, resource_id: UUID, role_name: str): + """Revoke a role from `user` on `resource_id` by the role's name.""" + cursor.execute( + "SELECT role_id FROM roles WHERE role_name=:role_name", + {"role_name": role_name}) + role = cursor.fetchone() + if role: + cursor.execute( + ("DELETE FROM user_roles " + "WHERE user_id=:user_id AND role_id=:role_id " + "AND resource_id=:resource_id"), + { + "user_id": str(user.user_id), + "role_id": role["role_id"], + "resource_id": str(resource_id) + }) + + def role_by_id(conn: db.DbConnection, role_id: UUID) -> Optional[Role]: """Fetch a role from the database by its ID.""" with db.cursor(conn) as cursor: |
