feat: only tenant owner can subscription. (#1770)

This commit is contained in:
Garfield Dai 2023-12-18 16:59:31 +08:00 committed by GitHub
parent 354d033e60
commit 2de73991ff
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 19 additions and 1 deletions

View File

@ -37,6 +37,8 @@ class Subscription(Resource):
parser.add_argument('interval', type=str, required=True, location='args', choices=['month', 'year']) parser.add_argument('interval', type=str, required=True, location='args', choices=['month', 'year'])
args = parser.parse_args() args = parser.parse_args()
BillingService.is_tenant_owner(current_user)
return BillingService.get_subscription(args['plan'], return BillingService.get_subscription(args['plan'],
args['interval'], args['interval'],
current_user.email, current_user.email,
@ -50,7 +52,7 @@ class Invoices(Resource):
@account_initialization_required @account_initialization_required
@only_edition_cloud @only_edition_cloud
def get(self): def get(self):
BillingService.is_tenant_owner(current_user)
return BillingService.get_invoices(current_user.email) return BillingService.get_invoices(current_user.email)

View File

@ -1,6 +1,10 @@
import os import os
import requests import requests
from extensions.ext_database import db
from models.account import TenantAccountJoin
class BillingService: class BillingService:
base_url = os.environ.get('BILLING_API_URL', 'BILLING_API_URL') base_url = os.environ.get('BILLING_API_URL', 'BILLING_API_URL')
@ -55,3 +59,15 @@ class BillingService:
response = requests.request(method, url, json=json, params=params, headers=headers) response = requests.request(method, url, json=json, params=params, headers=headers)
return response.json() return response.json()
@staticmethod
def is_tenant_owner(current_user):
tenant_id = current_user.current_tenant_id
join = db.session.query(TenantAccountJoin).filter(
TenantAccountJoin.tenant_id == tenant_id,
TenantAccountJoin.account_id == current_user.id
).first()
if join.role != 'owner':
raise ValueError('Only tenant owner can perform this action')