|
7 | 7 | from notifications_utils.clients.redis import service_cache_key |
8 | 8 | from notifications_utils.statsd_decorators import statsd |
9 | 9 | from notifications_utils.timezones import convert_utc_to_local_timezone |
| 10 | +from sqlalchemy.exc import IntegrityError |
10 | 11 | from sqlalchemy.orm import joinedload |
11 | 12 | from sqlalchemy.sql.expression import and_, asc, case, func |
12 | 13 |
|
|
41 | 42 | Service, |
42 | 43 | ServicePermission, |
43 | 44 | ServiceSmsSender, |
| 45 | + ServiceUser, |
44 | 46 | Template, |
45 | 47 | TemplateCategory, |
46 | 48 | TemplateHistory, |
@@ -348,17 +350,71 @@ def dao_add_user_to_service(service, user, permissions=None, folder_permissions= |
348 | 350 | try: |
349 | 351 | from app.dao.permissions_dao import permission_dao |
350 | 352 |
|
351 | | - service.users.append(user) |
352 | | - permission_dao.set_user_service_permission(user, service, permissions, _commit=False) |
353 | | - db.session.add(service) |
354 | | - |
355 | | - service_user = dao_get_service_user(user.id, service.id) |
356 | | - valid_template_folders = dao_get_valid_template_folders_by_id(folder_permissions) |
357 | | - service_user.folders = valid_template_folders |
358 | | - db.session.add(service_user) |
359 | | - |
| 353 | + # Check if the user is already in the service using no_autoflush |
| 354 | + with db.session.no_autoflush: # Prevent autoflush during this check |
| 355 | + service_user = ServiceUser.query.filter_by(user_id=user.id, service_id=service.id).one_or_none() |
| 356 | + |
| 357 | + if service_user: |
| 358 | + # User is already in the service, just update permissions if needed |
| 359 | + try: |
| 360 | + # Convert string permissions to actual permission values if needed |
| 361 | + permission_dao.set_user_service_permission(user, service, permissions, _commit=False) |
| 362 | + except Exception as perm_error: |
| 363 | + db.session.rollback() |
| 364 | + current_app.logger.error( |
| 365 | + f"Error updating permissions for existing user {user.id} on service {service.id}: {str(perm_error)}" |
| 366 | + ) |
| 367 | + # Try again with a fresh session |
| 368 | + db.session.close() |
| 369 | + service_user = ServiceUser.query.filter_by(user_id=user.id, service_id=service.id).one() |
| 370 | + permission_dao.set_user_service_permission(user, service, permissions, _commit=False) |
| 371 | + |
| 372 | + # Update folder permissions if needed |
| 373 | + valid_template_folders = dao_get_valid_template_folders_by_id(folder_permissions) |
| 374 | + service_user.folders = valid_template_folders |
| 375 | + db.session.add(service_user) |
| 376 | + else: |
| 377 | + # User is not in service yet, create the ServiceUser record explicitly |
| 378 | + service_user = ServiceUser(user_id=user.id, service_id=service.id) |
| 379 | + db.session.add(service_user) |
| 380 | + |
| 381 | + try: |
| 382 | + # Try to flush now to catch any IntegrityError early |
| 383 | + # before proceeding with permissions |
| 384 | + db.session.flush() |
| 385 | + except IntegrityError: |
| 386 | + # If we get an IntegrityError here, it means another request |
| 387 | + # has already created the service_user record |
| 388 | + db.session.rollback() |
| 389 | + # Fetch the existing service_user |
| 390 | + service_user = ServiceUser.query.filter_by(user_id=user.id, service_id=service.id).one() |
| 391 | + current_app.logger.info(f"Recovered from IntegrityError - user {user.id} already exists in service {service.id}") |
| 392 | + |
| 393 | + # At this point we have a valid service_user - either newly created or fetched after IntegrityError |
| 394 | + try: |
| 395 | + # Create Permission objects from strings if needed |
| 396 | + permission_dao.set_user_service_permission(user, service, permissions, _commit=False) |
| 397 | + except Exception as perm_error: |
| 398 | + # Log the permission error but continue with folder permissions |
| 399 | + current_app.logger.error( |
| 400 | + f"Error setting permissions for user {user.id} on service {service.id}: {str(perm_error)}" |
| 401 | + ) |
| 402 | + # Don't re-raise the exception - we'll continue with folder permissions |
| 403 | + |
| 404 | + # Add folder permissions |
| 405 | + try: |
| 406 | + valid_template_folders = dao_get_valid_template_folders_by_id(folder_permissions) |
| 407 | + service_user.folders = valid_template_folders |
| 408 | + db.session.add(service_user) |
| 409 | + except Exception as folder_error: |
| 410 | + # Log the folder permission error but don't fail the entire operation |
| 411 | + current_app.logger.error( |
| 412 | + f"Error setting folder permissions for user {user.id} on service {service.id}: {str(folder_error)}" |
| 413 | + ) |
| 414 | + # Don't re-raise the exception |
360 | 415 | except Exception as e: |
361 | 416 | db.session.rollback() |
| 417 | + current_app.logger.error(f"Error in dao_add_user_to_service: {str(e)}") |
362 | 418 | raise e |
363 | 419 | else: |
364 | 420 | db.session.commit() |
|
0 commit comments