Class: Cisco::AaaAuthorizationService
- Defined in:
- lib/cisco_node_utils/aaa_authorization_service.rb
Overview
AaaAuthorizationService - node util class for aaa authorization management
Instance Attribute Summary collapse
-
#name ⇒ Object
readonly
Returns the value of attribute name.
-
#type ⇒ Object
readonly
Returns the value of attribute type.
Class Method Summary collapse
Instance Method Summary collapse
-
#default_groups ⇒ Object
default is [].
-
#default_method ⇒ Object
default is :local.
- #destroy ⇒ Object
-
#groups ⇒ Object
groups aren't retrieved via the usual CLI regex memory type because there can be an arbitrary number of groups and specifying a repeating memory regex only captures the last match ex: aaa authorization console group group1 group2 group3 local.
-
#groups_method_set(grps, m) ⇒ Object
groups and method must be set in the same CLI string aaa authorization login
/ local | group <group1 [group2, ...]> [local]. -
#initialize(type, name, create = true) ⇒ AaaAuthorizationService
constructor
A new instance of AaaAuthorizationService.
- #method ⇒ Object
Methods inherited from NodeUtil
config_get, #config_get, config_get_default, #config_get_default, #config_set, config_set, #node, node, #show
Constructor Details
#initialize(type, name, create = true) ⇒ AaaAuthorizationService
Returns a new instance of AaaAuthorizationService.
26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 |
# File 'lib/cisco_node_utils/aaa_authorization_service.rb', line 26 def initialize(type, name, create=true) fail TypeError unless name.is_a? String fail TypeError unless type.is_a? Symbol # only console and default are supported currently fail ArgumentError unless %w(console default).include? name fail ArgumentError unless %i(commands config_commands ssh_certificate ssh_publickey).include? type @name = name @type = type type_str = AaaAuthorizationService.auth_type_sym_to_str(type) return unless create config_set('aaa_authorization_service', 'method', '', type_str, name) end |
Instance Attribute Details
#name ⇒ Object (readonly)
Returns the value of attribute name.
24 25 26 |
# File 'lib/cisco_node_utils/aaa_authorization_service.rb', line 24 def name @name end |
#type ⇒ Object (readonly)
Returns the value of attribute type.
24 25 26 |
# File 'lib/cisco_node_utils/aaa_authorization_service.rb', line 24 def type @type end |
Class Method Details
.auth_type_str_to_sym(str) ⇒ Object
146 147 148 |
# File 'lib/cisco_node_utils/aaa_authorization_service.rb', line 146 def self.auth_type_str_to_sym(str) str.sub('-', '_').to_sym end |
.auth_type_sym_to_str(sym) ⇒ Object
142 143 144 |
# File 'lib/cisco_node_utils/aaa_authorization_service.rb', line 142 def self.auth_type_sym_to_str(sym) sym.to_s.sub('_', '-') end |
.services ⇒ Object
42 43 44 45 46 47 48 49 50 51 52 53 |
# File 'lib/cisco_node_utils/aaa_authorization_service.rb', line 42 def self.services servs = {} servs_arr = config_get('aaa_authorization_service', 'services') unless servs_arr.nil? servs_arr.each do |type, name| type = auth_type_str_to_sym(type) servs[type] ||= {} servs[type][name] = AaaAuthorizationService.new(type, name, false) end end servs end |
Instance Method Details
#default_groups ⇒ Object
default is []
101 102 103 |
# File 'lib/cisco_node_utils/aaa_authorization_service.rb', line 101 def default_groups config_get_default('aaa_authorization_service', 'groups') end |
#default_method ⇒ Object
default is :local
112 113 114 |
# File 'lib/cisco_node_utils/aaa_authorization_service.rb', line 112 def default_method config_get_default('aaa_authorization_service', 'method') end |
#destroy ⇒ Object
55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 |
# File 'lib/cisco_node_utils/aaa_authorization_service.rb', line 55 def destroy # must specify exact current config string to unconfigure m = method m_str = m == :unselected ? '' : m.to_s g_str = groups.join(' ') t_str = AaaAuthorizationService.auth_type_sym_to_str(@type) if g_str.empty? # cannot remove no groups + local, so do nothing in this case unless m == :local config_set('aaa_authorization_service', 'method', 'no', t_str, @name) end else config_set('aaa_authorization_service', 'groups', 'no', t_str, @name, g_str, m_str) end end |
#groups ⇒ Object
groups aren't retrieved via the usual CLI regex memory type because there can be an arbitrary number of groups and specifying a repeating memory regex only captures the last match ex: aaa authorization console group group1 group2 group3 local
78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 |
# File 'lib/cisco_node_utils/aaa_authorization_service.rb', line 78 def groups # config_get returns the following format: # [{"appl_subtype": "console", # "cmd_type": "config-commands", # "methods": "group foo bar local "}], ... hsh_arr = config_get('aaa_authorization_service', 'groups') fail 'unable to retrieve aaa groups information' if hsh_arr.empty? type_s = AaaAuthorizationService.auth_type_sym_to_str(@type) hsh = hsh_arr.find do |x| x['appl_subtype'] == @name && x['cmd_type'] == type_s end fail "no aaa info for #{@type},#{@name}" if hsh.nil? fail "no aaa info for #{@type},#{@name}. api/feature change?" unless hsh.key? 'methods' # ex: ["group", "group1", "local"] grps = hsh['methods'].strip.split # return [] if grps.size == 1 # remove local, group keywords grps -= %w(local group) grps end |
#groups_method_set(grps, m) ⇒ Object
groups and method must be set in the same CLI string
aaa authorization login
119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 |
# File 'lib/cisco_node_utils/aaa_authorization_service.rb', line 119 def groups_method_set(grps, m) fail TypeError unless grps.is_a? Array fail TypeError unless grps.all? { |x| x.is_a? String } fail TypeError unless m.is_a? Symbol # only the following are supported (unselected = blank) fail ArgumentError unless [:local, :unselected].include? m # raise "type 'local' not allowed when groups are configured" if # m == :local and not grps.empty? m_str = m == :unselected ? '' : m.to_s g_str = grps.join(' ') t_str = AaaAuthorizationService.auth_type_sym_to_str(@type) # config_set depends on whether we're setting groups or not if g_str.empty? config_set('aaa_authorization_service', 'method', '', t_str, @name) else config_set('aaa_authorization_service', 'groups', '', t_str, @name, g_str, m_str) end end |
#method ⇒ Object
105 106 107 108 109 |
# File 'lib/cisco_node_utils/aaa_authorization_service.rb', line 105 def method t_str = AaaAuthorizationService.auth_type_sym_to_str(@type) m = config_get('aaa_authorization_service', 'method', @name, t_str) m.nil? ? :unselected : m.to_sym end |