blob: 9a3790e559a33ad8fb4df9057344848b4ad3b4fd [file] [log] [blame]
<!DOCTYPE HTML>
<html lang="en">
<head>
<title>Source code</title>
<link rel="stylesheet" type="text/css" href="../../../../../../../stylesheet.css" title="Style">
</head>
<body>
<main role="main">
<div class="sourceContainer">
<pre><span class="sourceLineNo">001</span><a id="line.1">package org.apache.archiva.redback.role.template;</a>
<span class="sourceLineNo">002</span><a id="line.2"></a>
<span class="sourceLineNo">003</span><a id="line.3">/*</a>
<span class="sourceLineNo">004</span><a id="line.4"> * Licensed to the Apache Software Foundation (ASF) under one</a>
<span class="sourceLineNo">005</span><a id="line.5"> * or more contributor license agreements. See the NOTICE file</a>
<span class="sourceLineNo">006</span><a id="line.6"> * distributed with this work for additional information</a>
<span class="sourceLineNo">007</span><a id="line.7"> * regarding copyright ownership. The ASF licenses this file</a>
<span class="sourceLineNo">008</span><a id="line.8"> * to you under the Apache License, Version 2.0 (the</a>
<span class="sourceLineNo">009</span><a id="line.9"> * "License"); you may not use this file except in compliance</a>
<span class="sourceLineNo">010</span><a id="line.10"> * with the License. You may obtain a copy of the License at</a>
<span class="sourceLineNo">011</span><a id="line.11"> *</a>
<span class="sourceLineNo">012</span><a id="line.12"> * http://www.apache.org/licenses/LICENSE-2.0</a>
<span class="sourceLineNo">013</span><a id="line.13"> *</a>
<span class="sourceLineNo">014</span><a id="line.14"> * Unless required by applicable law or agreed to in writing,</a>
<span class="sourceLineNo">015</span><a id="line.15"> * software distributed under the License is distributed on an</a>
<span class="sourceLineNo">016</span><a id="line.16"> * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY</a>
<span class="sourceLineNo">017</span><a id="line.17"> * KIND, either express or implied. See the License for the</a>
<span class="sourceLineNo">018</span><a id="line.18"> * specific language governing permissions and limitations</a>
<span class="sourceLineNo">019</span><a id="line.19"> * under the License.</a>
<span class="sourceLineNo">020</span><a id="line.20"> */</a>
<span class="sourceLineNo">021</span><a id="line.21"></a>
<span class="sourceLineNo">022</span><a id="line.22">import org.apache.archiva.redback.rbac.Operation;</a>
<span class="sourceLineNo">023</span><a id="line.23">import org.apache.archiva.redback.rbac.Permission;</a>
<span class="sourceLineNo">024</span><a id="line.24">import org.apache.archiva.redback.rbac.RbacManagerException;</a>
<span class="sourceLineNo">025</span><a id="line.25">import org.apache.archiva.redback.rbac.Resource;</a>
<span class="sourceLineNo">026</span><a id="line.26">import org.apache.archiva.redback.rbac.Role;</a>
<span class="sourceLineNo">027</span><a id="line.27">import org.apache.archiva.redback.rbac.RBACManager;</a>
<span class="sourceLineNo">028</span><a id="line.28">import org.apache.archiva.redback.role.PermanentRoleDeletionInvalid;</a>
<span class="sourceLineNo">029</span><a id="line.29">import org.apache.archiva.redback.role.RoleExistsException;</a>
<span class="sourceLineNo">030</span><a id="line.30">import org.apache.archiva.redback.role.RoleManagerException;</a>
<span class="sourceLineNo">031</span><a id="line.31">import org.apache.archiva.redback.role.RoleNotFoundException;</a>
<span class="sourceLineNo">032</span><a id="line.32">import org.apache.archiva.redback.role.model.ModelApplication;</a>
<span class="sourceLineNo">033</span><a id="line.33">import org.apache.archiva.redback.role.model.ModelOperation;</a>
<span class="sourceLineNo">034</span><a id="line.34">import org.apache.archiva.redback.role.model.ModelPermission;</a>
<span class="sourceLineNo">035</span><a id="line.35">import org.apache.archiva.redback.role.model.ModelResource;</a>
<span class="sourceLineNo">036</span><a id="line.36">import org.apache.archiva.redback.role.model.ModelRole;</a>
<span class="sourceLineNo">037</span><a id="line.37">import org.apache.archiva.redback.role.model.ModelTemplate;</a>
<span class="sourceLineNo">038</span><a id="line.38">import org.apache.archiva.redback.role.model.RedbackRoleModel;</a>
<span class="sourceLineNo">039</span><a id="line.39">import org.apache.archiva.redback.role.util.RoleModelUtils;</a>
<span class="sourceLineNo">040</span><a id="line.40">import org.slf4j.Logger;</a>
<span class="sourceLineNo">041</span><a id="line.41">import org.slf4j.LoggerFactory;</a>
<span class="sourceLineNo">042</span><a id="line.42">import org.springframework.stereotype.Service;</a>
<span class="sourceLineNo">043</span><a id="line.43"></a>
<span class="sourceLineNo">044</span><a id="line.44">import javax.inject.Inject;</a>
<span class="sourceLineNo">045</span><a id="line.45">import javax.inject.Named;</a>
<span class="sourceLineNo">046</span><a id="line.46">import java.util.ArrayList;</a>
<span class="sourceLineNo">047</span><a id="line.47">import java.util.Collections;</a>
<span class="sourceLineNo">048</span><a id="line.48">import java.util.Iterator;</a>
<span class="sourceLineNo">049</span><a id="line.49">import java.util.List;</a>
<span class="sourceLineNo">050</span><a id="line.50"></a>
<span class="sourceLineNo">051</span><a id="line.51">/**</a>
<span class="sourceLineNo">052</span><a id="line.52"> * DefaultRoleTemplateProcessor: inserts the components of a template into the rbac manager</a>
<span class="sourceLineNo">053</span><a id="line.53"> *</a>
<span class="sourceLineNo">054</span><a id="line.54"> * @author: Jesse McConnell</a>
<span class="sourceLineNo">055</span><a id="line.55"> */</a>
<span class="sourceLineNo">056</span><a id="line.56">@Service("roleTemplateProcessor")</a>
<span class="sourceLineNo">057</span><a id="line.57">public class DefaultRoleTemplateProcessor</a>
<span class="sourceLineNo">058</span><a id="line.58"> implements RoleTemplateProcessor</a>
<span class="sourceLineNo">059</span><a id="line.59">{</a>
<span class="sourceLineNo">060</span><a id="line.60"> private Logger log = LoggerFactory.getLogger( DefaultRoleTemplateProcessor.class );</a>
<span class="sourceLineNo">061</span><a id="line.61"></a>
<span class="sourceLineNo">062</span><a id="line.62"> @Inject</a>
<span class="sourceLineNo">063</span><a id="line.63"> @Named(value = "rbacManager#default")</a>
<span class="sourceLineNo">064</span><a id="line.64"> private RBACManager rbacManager;</a>
<span class="sourceLineNo">065</span><a id="line.65"></a>
<span class="sourceLineNo">066</span><a id="line.66"> @Override</a>
<span class="sourceLineNo">067</span><a id="line.67"> @SuppressWarnings("unchecked")</a>
<span class="sourceLineNo">068</span><a id="line.68"> public String create( final RedbackRoleModel model, final String templateId, final String resource )</a>
<span class="sourceLineNo">069</span><a id="line.69"> throws RoleManagerException</a>
<span class="sourceLineNo">070</span><a id="line.70"> {</a>
<span class="sourceLineNo">071</span><a id="line.71"> for ( ModelApplication application : model.getApplications() )</a>
<span class="sourceLineNo">072</span><a id="line.72"> {</a>
<span class="sourceLineNo">073</span><a id="line.73"> for ( ModelTemplate template : application.getTemplates() )</a>
<span class="sourceLineNo">074</span><a id="line.74"> {</a>
<span class="sourceLineNo">075</span><a id="line.75"> if ( templateId.equals( template.getId() ) )</a>
<span class="sourceLineNo">076</span><a id="line.76"> {</a>
<span class="sourceLineNo">077</span><a id="line.77"> // resource can be special</a>
<span class="sourceLineNo">078</span><a id="line.78"> processResource( template, resource );</a>
<span class="sourceLineNo">079</span><a id="line.79"></a>
<span class="sourceLineNo">080</span><a id="line.80"> // templates are roles that have yet to be paired with a resource for creation</a>
<span class="sourceLineNo">081</span><a id="line.81"> return processTemplate( model, template, resource );</a>
<span class="sourceLineNo">082</span><a id="line.82"></a>
<span class="sourceLineNo">083</span><a id="line.83"> }</a>
<span class="sourceLineNo">084</span><a id="line.84"> }</a>
<span class="sourceLineNo">085</span><a id="line.85"> }</a>
<span class="sourceLineNo">086</span><a id="line.86"></a>
<span class="sourceLineNo">087</span><a id="line.87"> throw new RoleNotFoundException( "unknown template '" + templateId + "'" );</a>
<span class="sourceLineNo">088</span><a id="line.88"> }</a>
<span class="sourceLineNo">089</span><a id="line.89"></a>
<span class="sourceLineNo">090</span><a id="line.90"> @Override</a>
<span class="sourceLineNo">091</span><a id="line.91"> @SuppressWarnings("unchecked")</a>
<span class="sourceLineNo">092</span><a id="line.92"> public void remove( RedbackRoleModel model, String templateId, String resource )</a>
<span class="sourceLineNo">093</span><a id="line.93"> throws RoleManagerException</a>
<span class="sourceLineNo">094</span><a id="line.94"> {</a>
<span class="sourceLineNo">095</span><a id="line.95"> for ( ModelApplication application : model.getApplications() )</a>
<span class="sourceLineNo">096</span><a id="line.96"> {</a>
<span class="sourceLineNo">097</span><a id="line.97"> for ( ModelTemplate template : application.getTemplates() )</a>
<span class="sourceLineNo">098</span><a id="line.98"> {</a>
<span class="sourceLineNo">099</span><a id="line.99"> if ( templateId.equals( template.getId() ) )</a>
<span class="sourceLineNo">100</span><a id="line.100"> {</a>
<span class="sourceLineNo">101</span><a id="line.101"> removeTemplatedRole( model, template, resource );</a>
<span class="sourceLineNo">102</span><a id="line.102"> return;</a>
<span class="sourceLineNo">103</span><a id="line.103"> }</a>
<span class="sourceLineNo">104</span><a id="line.104"> }</a>
<span class="sourceLineNo">105</span><a id="line.105"> }</a>
<span class="sourceLineNo">106</span><a id="line.106"></a>
<span class="sourceLineNo">107</span><a id="line.107"> throw new RoleManagerException( "unknown template '" + templateId + "'" );</a>
<span class="sourceLineNo">108</span><a id="line.108"> }</a>
<span class="sourceLineNo">109</span><a id="line.109"></a>
<span class="sourceLineNo">110</span><a id="line.110"> private void removeTemplatedRole( RedbackRoleModel model, ModelTemplate template, String resource )</a>
<span class="sourceLineNo">111</span><a id="line.111"> throws RoleManagerException</a>
<span class="sourceLineNo">112</span><a id="line.112"> {</a>
<span class="sourceLineNo">113</span><a id="line.113"> String roleId = getRoleId( template.getId( ), resource );</a>
<span class="sourceLineNo">114</span><a id="line.114"></a>
<span class="sourceLineNo">115</span><a id="line.115"> try</a>
<span class="sourceLineNo">116</span><a id="line.116"> {</a>
<span class="sourceLineNo">117</span><a id="line.117"> Role role = rbacManager.getRoleById( roleId );</a>
<span class="sourceLineNo">118</span><a id="line.118"></a>
<span class="sourceLineNo">119</span><a id="line.119"> if ( !role.isPermanent() )</a>
<span class="sourceLineNo">120</span><a id="line.120"> {</a>
<span class="sourceLineNo">121</span><a id="line.121"> // remove the role</a>
<span class="sourceLineNo">122</span><a id="line.122"> rbacManager.removeRole( role );</a>
<span class="sourceLineNo">123</span><a id="line.123"></a>
<span class="sourceLineNo">124</span><a id="line.124"> // remove the permissions</a>
<span class="sourceLineNo">125</span><a id="line.125"> // todo, do this in a better way too, permissions can be shared across multiple roles and that could blow chunks here.</a>
<span class="sourceLineNo">126</span><a id="line.126"> //for ( Iterator i = template.getPermissions().iterator(); i.hasNext(); )</a>
<span class="sourceLineNo">127</span><a id="line.127"> //{</a>
<span class="sourceLineNo">128</span><a id="line.128"> // ModelPermission permission = (ModelPermission) i.next();</a>
<span class="sourceLineNo">129</span><a id="line.129"> // if ( !permission.isPermanent() )</a>
<span class="sourceLineNo">130</span><a id="line.130"> // { </a>
<span class="sourceLineNo">131</span><a id="line.131"> // rbacManager.removePermission( permission.getName() + template.getDelimiter()</a>
<span class="sourceLineNo">132</span><a id="line.132"> // + resolvePermissionResource( model, permission, resolvePermissionResource( model, permission, resource ) ) ); </a>
<span class="sourceLineNo">133</span><a id="line.133"> // }</a>
<span class="sourceLineNo">134</span><a id="line.134"> //}</a>
<span class="sourceLineNo">135</span><a id="line.135"></a>
<span class="sourceLineNo">136</span><a id="line.136"> // check if we want to remove the resources</a>
<span class="sourceLineNo">137</span><a id="line.137"> Resource rbacResource = rbacManager.getResource( resource );</a>
<span class="sourceLineNo">138</span><a id="line.138"></a>
<span class="sourceLineNo">139</span><a id="line.139"> //if ( !rbacResource.isPermanent() )</a>
<span class="sourceLineNo">140</span><a id="line.140"> //{</a>
<span class="sourceLineNo">141</span><a id="line.141"> //todo we need a better way of finding if a resource is unused anymore...probably a cleaning process in the db or something</a>
<span class="sourceLineNo">142</span><a id="line.142"> //rbacManager.removeResource( rbacResource );</a>
<span class="sourceLineNo">143</span><a id="line.143"> //}</a>
<span class="sourceLineNo">144</span><a id="line.144"></a>
<span class="sourceLineNo">145</span><a id="line.145"> // todo find dangling child role references and smoke</a>
<span class="sourceLineNo">146</span><a id="line.146"> }</a>
<span class="sourceLineNo">147</span><a id="line.147"> else</a>
<span class="sourceLineNo">148</span><a id="line.148"> {</a>
<span class="sourceLineNo">149</span><a id="line.149"> throw new PermanentRoleDeletionInvalid( "Unable to remove role, it is flagged permanent: "+roleId );</a>
<span class="sourceLineNo">150</span><a id="line.150"> }</a>
<span class="sourceLineNo">151</span><a id="line.151"> }</a>
<span class="sourceLineNo">152</span><a id="line.152"> catch ( RbacManagerException e )</a>
<span class="sourceLineNo">153</span><a id="line.153"> {</a>
<span class="sourceLineNo">154</span><a id="line.154"> throw new RoleManagerException( "Unable to remove templated role: " + roleId, e );</a>
<span class="sourceLineNo">155</span><a id="line.155"> }</a>
<span class="sourceLineNo">156</span><a id="line.156"> //catch ( RoleTemplateProcessorException e )</a>
<span class="sourceLineNo">157</span><a id="line.157"> //{</a>
<span class="sourceLineNo">158</span><a id="line.158"> // throw new RoleManagerException( "unable to remove templated role, error resolving resource: Role:" + roleName + " Resource: " + resource, e );</a>
<span class="sourceLineNo">159</span><a id="line.159"> //}</a>
<span class="sourceLineNo">160</span><a id="line.160"> }</a>
<span class="sourceLineNo">161</span><a id="line.161"></a>
<span class="sourceLineNo">162</span><a id="line.162"> private void processResource( ModelTemplate template, String resource )</a>
<span class="sourceLineNo">163</span><a id="line.163"> throws RoleManagerException</a>
<span class="sourceLineNo">164</span><a id="line.164"> {</a>
<span class="sourceLineNo">165</span><a id="line.165"> if ( !rbacManager.resourceExists( resource ) )</a>
<span class="sourceLineNo">166</span><a id="line.166"> {</a>
<span class="sourceLineNo">167</span><a id="line.167"> try</a>
<span class="sourceLineNo">168</span><a id="line.168"> {</a>
<span class="sourceLineNo">169</span><a id="line.169"> Resource res = rbacManager.createResource( resource );</a>
<span class="sourceLineNo">170</span><a id="line.170"> res.setPermanent( template.isPermanentResource() );</a>
<span class="sourceLineNo">171</span><a id="line.171"> rbacManager.saveResource( res );</a>
<span class="sourceLineNo">172</span><a id="line.172"> }</a>
<span class="sourceLineNo">173</span><a id="line.173"> catch ( RbacManagerException e )</a>
<span class="sourceLineNo">174</span><a id="line.174"> {</a>
<span class="sourceLineNo">175</span><a id="line.175"> throw new RoleManagerException( "error creating resource '" + resource + "'", e );</a>
<span class="sourceLineNo">176</span><a id="line.176"> }</a>
<span class="sourceLineNo">177</span><a id="line.177"> }</a>
<span class="sourceLineNo">178</span><a id="line.178"> }</a>
<span class="sourceLineNo">179</span><a id="line.179"></a>
<span class="sourceLineNo">180</span><a id="line.180"> @Override</a>
<span class="sourceLineNo">181</span><a id="line.181"> public String getRoleId( String templateId, String resource) {</a>
<span class="sourceLineNo">182</span><a id="line.182"> return RoleModelUtils.getRoleId( templateId, resource );</a>
<span class="sourceLineNo">183</span><a id="line.183"> }</a>
<span class="sourceLineNo">184</span><a id="line.184"></a>
<span class="sourceLineNo">185</span><a id="line.185"> @SuppressWarnings("unchecked")</a>
<span class="sourceLineNo">186</span><a id="line.186"> private String processTemplate( RedbackRoleModel model, ModelTemplate template, String resource )</a>
<span class="sourceLineNo">187</span><a id="line.187"> throws RoleManagerException</a>
<span class="sourceLineNo">188</span><a id="line.188"> {</a>
<span class="sourceLineNo">189</span><a id="line.189"> final String templateName = template.getNamePrefix() + template.getDelimiter() + resource;</a>
<span class="sourceLineNo">190</span><a id="line.190"> final String roleId = getRoleId( template.getId( ), resource );</a>
<span class="sourceLineNo">191</span><a id="line.191"></a>
<span class="sourceLineNo">192</span><a id="line.192"> List&lt;Permission&gt; permissions = processPermissions( model, template, resource );</a>
<span class="sourceLineNo">193</span><a id="line.193"></a>
<span class="sourceLineNo">194</span><a id="line.194"> boolean roleExists = false;</a>
<span class="sourceLineNo">195</span><a id="line.195"></a>
<span class="sourceLineNo">196</span><a id="line.196"> try</a>
<span class="sourceLineNo">197</span><a id="line.197"> {</a>
<span class="sourceLineNo">198</span><a id="line.198"> roleExists = rbacManager.roleExists( templateName );</a>
<span class="sourceLineNo">199</span><a id="line.199"> }</a>
<span class="sourceLineNo">200</span><a id="line.200"> catch ( RbacManagerException e )</a>
<span class="sourceLineNo">201</span><a id="line.201"> {</a>
<span class="sourceLineNo">202</span><a id="line.202"> throw new RoleExistsException( e.getMessage(), e );</a>
<span class="sourceLineNo">203</span><a id="line.203"> }</a>
<span class="sourceLineNo">204</span><a id="line.204"></a>
<span class="sourceLineNo">205</span><a id="line.205"> if ( !roleExists )</a>
<span class="sourceLineNo">206</span><a id="line.206"> {</a>
<span class="sourceLineNo">207</span><a id="line.207"> try</a>
<span class="sourceLineNo">208</span><a id="line.208"> {</a>
<span class="sourceLineNo">209</span><a id="line.209"> Role role = rbacManager.createRole( templateName );</a>
<span class="sourceLineNo">210</span><a id="line.210"> role.setId( roleId );</a>
<span class="sourceLineNo">211</span><a id="line.211"> role.setModelId( template.getId() );</a>
<span class="sourceLineNo">212</span><a id="line.212"> role.setResource( resource );</a>
<span class="sourceLineNo">213</span><a id="line.213"> role.setTemplateInstance( true );</a>
<span class="sourceLineNo">214</span><a id="line.214"> role.setDescription( template.getDescription() );</a>
<span class="sourceLineNo">215</span><a id="line.215"> role.setPermanent( template.isPermanent() );</a>
<span class="sourceLineNo">216</span><a id="line.216"> role.setAssignable( template.isAssignable() );</a>
<span class="sourceLineNo">217</span><a id="line.217"></a>
<span class="sourceLineNo">218</span><a id="line.218"> // add any permissions associated with this role</a>
<span class="sourceLineNo">219</span><a id="line.219"> for ( Iterator&lt;Permission&gt; j = permissions.iterator(); j.hasNext(); )</a>
<span class="sourceLineNo">220</span><a id="line.220"> {</a>
<span class="sourceLineNo">221</span><a id="line.221"> Permission permission = j.next();</a>
<span class="sourceLineNo">222</span><a id="line.222"></a>
<span class="sourceLineNo">223</span><a id="line.223"> role.addPermission( permission );</a>
<span class="sourceLineNo">224</span><a id="line.224"> }</a>
<span class="sourceLineNo">225</span><a id="line.225"></a>
<span class="sourceLineNo">226</span><a id="line.226"> // add child roles to this role</a>
<span class="sourceLineNo">227</span><a id="line.227"> if ( template.getChildRoles() != null )</a>
<span class="sourceLineNo">228</span><a id="line.228"> {</a>
<span class="sourceLineNo">229</span><a id="line.229"> for ( String childRoleId : template.getChildRoles() )</a>
<span class="sourceLineNo">230</span><a id="line.230"> {</a>
<span class="sourceLineNo">231</span><a id="line.231"> ModelRole childRoleProfile = RoleModelUtils.getModelRole( model, childRoleId );</a>
<span class="sourceLineNo">232</span><a id="line.232"> role.addChildRoleName( childRoleProfile.getName() );</a>
<span class="sourceLineNo">233</span><a id="line.233"> role.addChildRoleId( childRoleProfile.getId() );</a>
<span class="sourceLineNo">234</span><a id="line.234"> }</a>
<span class="sourceLineNo">235</span><a id="line.235"> }</a>
<span class="sourceLineNo">236</span><a id="line.236"></a>
<span class="sourceLineNo">237</span><a id="line.237"> // add child templates to this role, be nice and make them if they don't exist</a>
<span class="sourceLineNo">238</span><a id="line.238"> if ( template.getChildTemplates() != null )</a>
<span class="sourceLineNo">239</span><a id="line.239"> {</a>
<span class="sourceLineNo">240</span><a id="line.240"> for ( String childTemplateId : template.getChildTemplates() )</a>
<span class="sourceLineNo">241</span><a id="line.241"> {</a>
<span class="sourceLineNo">242</span><a id="line.242"> ModelTemplate childModelTemplate = RoleModelUtils.getModelTemplate( model, childTemplateId );</a>
<span class="sourceLineNo">243</span><a id="line.243"></a>
<span class="sourceLineNo">244</span><a id="line.244"> if ( childModelTemplate == null )</a>
<span class="sourceLineNo">245</span><a id="line.245"> {</a>
<span class="sourceLineNo">246</span><a id="line.246"> throw new RoleManagerException(</a>
<span class="sourceLineNo">247</span><a id="line.247"> "error obtaining child template from model: template " + templateName</a>
<span class="sourceLineNo">248</span><a id="line.248"> + " # child template: " + childTemplateId );</a>
<span class="sourceLineNo">249</span><a id="line.249"> }</a>
<span class="sourceLineNo">250</span><a id="line.250"></a>
<span class="sourceLineNo">251</span><a id="line.251"> String childRoleName =</a>
<span class="sourceLineNo">252</span><a id="line.252"> childModelTemplate.getNamePrefix() + childModelTemplate.getDelimiter() + resource;</a>
<span class="sourceLineNo">253</span><a id="line.253"></a>
<span class="sourceLineNo">254</span><a id="line.254"> // check if the role exists, if it does then add it as a child, otherwise make it and add it</a>
<span class="sourceLineNo">255</span><a id="line.255"> // this should be safe since validation should protect us from template cycles</a>
<span class="sourceLineNo">256</span><a id="line.256"> if ( rbacManager.roleExists( childRoleName ) )</a>
<span class="sourceLineNo">257</span><a id="line.257"> {</a>
<span class="sourceLineNo">258</span><a id="line.258"> role.addChildRoleName( childRoleName );</a>
<span class="sourceLineNo">259</span><a id="line.259"> role.addChildRoleId( getRoleId( childTemplateId, resource ) );</a>
<span class="sourceLineNo">260</span><a id="line.260"> }</a>
<span class="sourceLineNo">261</span><a id="line.261"> else</a>
<span class="sourceLineNo">262</span><a id="line.262"> {</a>
<span class="sourceLineNo">263</span><a id="line.263"> processTemplate( model, childModelTemplate, resource );</a>
<span class="sourceLineNo">264</span><a id="line.264"></a>
<span class="sourceLineNo">265</span><a id="line.265"> role.addChildRoleName( childRoleName );</a>
<span class="sourceLineNo">266</span><a id="line.266"> role.addChildRoleId( getRoleId( childTemplateId, resource ) );</a>
<span class="sourceLineNo">267</span><a id="line.267"> }</a>
<span class="sourceLineNo">268</span><a id="line.268"> }</a>
<span class="sourceLineNo">269</span><a id="line.269"> }</a>
<span class="sourceLineNo">270</span><a id="line.270"></a>
<span class="sourceLineNo">271</span><a id="line.271"> // this role needs to be saved since it now needs to be added as a child role by </a>
<span class="sourceLineNo">272</span><a id="line.272"> // another role</a>
<span class="sourceLineNo">273</span><a id="line.273"> if ( !rbacManager.roleExists( role.getName() ) )</a>
<span class="sourceLineNo">274</span><a id="line.274"> {</a>
<span class="sourceLineNo">275</span><a id="line.275"> role = rbacManager.saveRole( role );</a>
<span class="sourceLineNo">276</span><a id="line.276"> }</a>
<span class="sourceLineNo">277</span><a id="line.277"></a>
<span class="sourceLineNo">278</span><a id="line.278"> // add link from parent roles to this new role</a>
<span class="sourceLineNo">279</span><a id="line.279"> if ( template.getParentRoles() != null )</a>
<span class="sourceLineNo">280</span><a id="line.280"> {</a>
<span class="sourceLineNo">281</span><a id="line.281"> for ( String parentRoleId : template.getParentRoles() )</a>
<span class="sourceLineNo">282</span><a id="line.282"> {</a>
<span class="sourceLineNo">283</span><a id="line.283"> ModelRole parentModelRole = RoleModelUtils.getModelRole( model, parentRoleId );</a>
<span class="sourceLineNo">284</span><a id="line.284"> Role parentRole = rbacManager.getRole( parentModelRole.getName() );</a>
<span class="sourceLineNo">285</span><a id="line.285"> parentRole.addChildRole( role );</a>
<span class="sourceLineNo">286</span><a id="line.286"> rbacManager.saveRole( parentRole );</a>
<span class="sourceLineNo">287</span><a id="line.287"> }</a>
<span class="sourceLineNo">288</span><a id="line.288"> }</a>
<span class="sourceLineNo">289</span><a id="line.289"></a>
<span class="sourceLineNo">290</span><a id="line.290"> // add child templates to this role, be nice and make them if they don't exist</a>
<span class="sourceLineNo">291</span><a id="line.291"> if ( template.getParentTemplates() != null )</a>
<span class="sourceLineNo">292</span><a id="line.292"> {</a>
<span class="sourceLineNo">293</span><a id="line.293"> for ( String parentTemplateId : template.getParentTemplates() )</a>
<span class="sourceLineNo">294</span><a id="line.294"> {</a>
<span class="sourceLineNo">295</span><a id="line.295"> ModelTemplate parentModelTemplate = RoleModelUtils.getModelTemplate( model, parentTemplateId );</a>
<span class="sourceLineNo">296</span><a id="line.296"></a>
<span class="sourceLineNo">297</span><a id="line.297"> if ( parentModelTemplate == null )</a>
<span class="sourceLineNo">298</span><a id="line.298"> {</a>
<span class="sourceLineNo">299</span><a id="line.299"> throw new RoleManagerException(</a>
<span class="sourceLineNo">300</span><a id="line.300"> "error obtaining parent template from model: template " + templateName</a>
<span class="sourceLineNo">301</span><a id="line.301"> + " # child template: " + parentTemplateId );</a>
<span class="sourceLineNo">302</span><a id="line.302"> }</a>
<span class="sourceLineNo">303</span><a id="line.303"></a>
<span class="sourceLineNo">304</span><a id="line.304"> String parentRoleName =</a>
<span class="sourceLineNo">305</span><a id="line.305"> parentModelTemplate.getNamePrefix() + parentModelTemplate.getDelimiter() + resource;</a>
<span class="sourceLineNo">306</span><a id="line.306"></a>
<span class="sourceLineNo">307</span><a id="line.307"> // check if the role exists, if it does then add it as a child, otherwise make it and add it</a>
<span class="sourceLineNo">308</span><a id="line.308"> // this should be safe since validation should protect us from template cycles</a>
<span class="sourceLineNo">309</span><a id="line.309"> if ( rbacManager.roleExists( parentRoleName ) )</a>
<span class="sourceLineNo">310</span><a id="line.310"> {</a>
<span class="sourceLineNo">311</span><a id="line.311"> Role parentRole = rbacManager.getRole( parentRoleName );</a>
<span class="sourceLineNo">312</span><a id="line.312"></a>
<span class="sourceLineNo">313</span><a id="line.313"> parentRole.addChildRole( role );</a>
<span class="sourceLineNo">314</span><a id="line.314"> rbacManager.saveRole( parentRole );</a>
<span class="sourceLineNo">315</span><a id="line.315"> }</a>
<span class="sourceLineNo">316</span><a id="line.316"> else</a>
<span class="sourceLineNo">317</span><a id="line.317"> {</a>
<span class="sourceLineNo">318</span><a id="line.318"> processTemplate( model, parentModelTemplate, resource );</a>
<span class="sourceLineNo">319</span><a id="line.319"></a>
<span class="sourceLineNo">320</span><a id="line.320"> Role parentRole = rbacManager.getRole( parentRoleName );</a>
<span class="sourceLineNo">321</span><a id="line.321"></a>
<span class="sourceLineNo">322</span><a id="line.322"> parentRole.addChildRole( role );</a>
<span class="sourceLineNo">323</span><a id="line.323"> rbacManager.saveRole( parentRole );</a>
<span class="sourceLineNo">324</span><a id="line.324"> }</a>
<span class="sourceLineNo">325</span><a id="line.325"> }</a>
<span class="sourceLineNo">326</span><a id="line.326"> }</a>
<span class="sourceLineNo">327</span><a id="line.327"></a>
<span class="sourceLineNo">328</span><a id="line.328"> }</a>
<span class="sourceLineNo">329</span><a id="line.329"> catch ( RbacManagerException e )</a>
<span class="sourceLineNo">330</span><a id="line.330"> {</a>
<span class="sourceLineNo">331</span><a id="line.331"> throw new RoleManagerException( "error creating role '" + templateName + "'", e );</a>
<span class="sourceLineNo">332</span><a id="line.332"> }</a>
<span class="sourceLineNo">333</span><a id="line.333"> }</a>
<span class="sourceLineNo">334</span><a id="line.334"> else</a>
<span class="sourceLineNo">335</span><a id="line.335"> {</a>
<span class="sourceLineNo">336</span><a id="line.336"> try</a>
<span class="sourceLineNo">337</span><a id="line.337"> {</a>
<span class="sourceLineNo">338</span><a id="line.338"> Role role = rbacManager.getRole( templateName );</a>
<span class="sourceLineNo">339</span><a id="line.339"></a>
<span class="sourceLineNo">340</span><a id="line.340"> boolean changed = false;</a>
<span class="sourceLineNo">341</span><a id="line.341"> for ( Permission permission : permissions )</a>
<span class="sourceLineNo">342</span><a id="line.342"> {</a>
<span class="sourceLineNo">343</span><a id="line.343"> if ( !role.getPermissions().contains( permission ) )</a>
<span class="sourceLineNo">344</span><a id="line.344"> {</a>
<span class="sourceLineNo">345</span><a id="line.345"> log.info( "Adding new permission '{}' to role '{}'",</a>
<span class="sourceLineNo">346</span><a id="line.346"> permission.getName(), role.getName() );</a>
<span class="sourceLineNo">347</span><a id="line.347"> role.addPermission( permission );</a>
<span class="sourceLineNo">348</span><a id="line.348"> changed = true;</a>
<span class="sourceLineNo">349</span><a id="line.349"> }</a>
<span class="sourceLineNo">350</span><a id="line.350"> }</a>
<span class="sourceLineNo">351</span><a id="line.351"></a>
<span class="sourceLineNo">352</span><a id="line.352"> // Copy list to avoid concurrent modifications</a>
<span class="sourceLineNo">353</span><a id="line.353"> List&lt;Permission&gt; oldPermissions = new ArrayList&lt;Permission&gt;( role.getPermissions() );</a>
<span class="sourceLineNo">354</span><a id="line.354"> for ( Permission permission : oldPermissions )</a>
<span class="sourceLineNo">355</span><a id="line.355"> {</a>
<span class="sourceLineNo">356</span><a id="line.356"> if ( !permissions.contains( permission ) )</a>
<span class="sourceLineNo">357</span><a id="line.357"> {</a>
<span class="sourceLineNo">358</span><a id="line.358"> log.info( "Removing old permission '{}' from role '{}'", permission.getName(), role.getName() );</a>
<span class="sourceLineNo">359</span><a id="line.359"> role.removePermission( permission );</a>
<span class="sourceLineNo">360</span><a id="line.360"> changed = true;</a>
<span class="sourceLineNo">361</span><a id="line.361"> }</a>
<span class="sourceLineNo">362</span><a id="line.362"> }</a>
<span class="sourceLineNo">363</span><a id="line.363"> if ( changed )</a>
<span class="sourceLineNo">364</span><a id="line.364"> {</a>
<span class="sourceLineNo">365</span><a id="line.365"> rbacManager.saveRole( role );</a>
<span class="sourceLineNo">366</span><a id="line.366"> }</a>
<span class="sourceLineNo">367</span><a id="line.367"> }</a>
<span class="sourceLineNo">368</span><a id="line.368"> catch ( RbacManagerException e )</a>
<span class="sourceLineNo">369</span><a id="line.369"> {</a>
<span class="sourceLineNo">370</span><a id="line.370"> throw new RoleManagerException( "error updating role '" + templateName + "'", e );</a>
<span class="sourceLineNo">371</span><a id="line.371"> }</a>
<span class="sourceLineNo">372</span><a id="line.372"> }</a>
<span class="sourceLineNo">373</span><a id="line.373"> return roleId;</a>
<span class="sourceLineNo">374</span><a id="line.374"> }</a>
<span class="sourceLineNo">375</span><a id="line.375"></a>
<span class="sourceLineNo">376</span><a id="line.376"> @SuppressWarnings("unchecked")</a>
<span class="sourceLineNo">377</span><a id="line.377"> private List&lt;Permission&gt; processPermissions( RedbackRoleModel model, ModelTemplate template, String resource )</a>
<span class="sourceLineNo">378</span><a id="line.378"> throws RoleManagerException</a>
<span class="sourceLineNo">379</span><a id="line.379"> {</a>
<span class="sourceLineNo">380</span><a id="line.380"></a>
<span class="sourceLineNo">381</span><a id="line.381"> if ( template.getPermissions() != null )</a>
<span class="sourceLineNo">382</span><a id="line.382"> {</a>
<span class="sourceLineNo">383</span><a id="line.383"> // copy list to avoid concurrent modifications</a>
<span class="sourceLineNo">384</span><a id="line.384"> List&lt;ModelPermission&gt; templatePermissions = new ArrayList&lt;ModelPermission&gt;( template.getPermissions() );</a>
<span class="sourceLineNo">385</span><a id="line.385"> List&lt;Permission&gt; rbacPermissions = new ArrayList&lt;Permission&gt;( templatePermissions.size() );</a>
<span class="sourceLineNo">386</span><a id="line.386"> for ( ModelPermission profilePermission : templatePermissions )</a>
<span class="sourceLineNo">387</span><a id="line.387"> {</a>
<span class="sourceLineNo">388</span><a id="line.388"> try</a>
<span class="sourceLineNo">389</span><a id="line.389"> {</a>
<span class="sourceLineNo">390</span><a id="line.390"> String permissionName =</a>
<span class="sourceLineNo">391</span><a id="line.391"> profilePermission.getName() + template.getDelimiter() + resolvePermissionResource( model,</a>
<span class="sourceLineNo">392</span><a id="line.392"> profilePermission,</a>
<span class="sourceLineNo">393</span><a id="line.393"> resource );</a>
<span class="sourceLineNo">394</span><a id="line.394"></a>
<span class="sourceLineNo">395</span><a id="line.395"> if ( !rbacManager.permissionExists( permissionName ) )</a>
<span class="sourceLineNo">396</span><a id="line.396"> {</a>
<span class="sourceLineNo">397</span><a id="line.397"></a>
<span class="sourceLineNo">398</span><a id="line.398"> Permission permission = rbacManager.createPermission( permissionName );</a>
<span class="sourceLineNo">399</span><a id="line.399"></a>
<span class="sourceLineNo">400</span><a id="line.400"> ModelOperation modelOperation =</a>
<span class="sourceLineNo">401</span><a id="line.401"> RoleModelUtils.getModelOperation( model, profilePermission.getOperation() );</a>
<span class="sourceLineNo">402</span><a id="line.402"> Operation rbacOperation = rbacManager.getOperation( modelOperation.getName() );</a>
<span class="sourceLineNo">403</span><a id="line.403"></a>
<span class="sourceLineNo">404</span><a id="line.404"> String permissionResource = resolvePermissionResource( model, profilePermission, resource );</a>
<span class="sourceLineNo">405</span><a id="line.405"></a>
<span class="sourceLineNo">406</span><a id="line.406"> Resource rbacResource = rbacManager.getResource( permissionResource );</a>
<span class="sourceLineNo">407</span><a id="line.407"></a>
<span class="sourceLineNo">408</span><a id="line.408"> permission.setOperation( rbacOperation );</a>
<span class="sourceLineNo">409</span><a id="line.409"> permission.setResource( rbacResource );</a>
<span class="sourceLineNo">410</span><a id="line.410"> permission.setPermanent( profilePermission.isPermanent() );</a>
<span class="sourceLineNo">411</span><a id="line.411"> permission.setDescription( profilePermission.getDescription() );</a>
<span class="sourceLineNo">412</span><a id="line.412"></a>
<span class="sourceLineNo">413</span><a id="line.413"> permission = rbacManager.savePermission( permission );</a>
<span class="sourceLineNo">414</span><a id="line.414"></a>
<span class="sourceLineNo">415</span><a id="line.415"> rbacPermissions.add( permission );</a>
<span class="sourceLineNo">416</span><a id="line.416"></a>
<span class="sourceLineNo">417</span><a id="line.417"> }</a>
<span class="sourceLineNo">418</span><a id="line.418"> else</a>
<span class="sourceLineNo">419</span><a id="line.419"> {</a>
<span class="sourceLineNo">420</span><a id="line.420"></a>
<span class="sourceLineNo">421</span><a id="line.421"> rbacPermissions.add( rbacManager.getPermission( permissionName ) );</a>
<span class="sourceLineNo">422</span><a id="line.422"></a>
<span class="sourceLineNo">423</span><a id="line.423"> }</a>
<span class="sourceLineNo">424</span><a id="line.424"> }</a>
<span class="sourceLineNo">425</span><a id="line.425"> catch ( RbacManagerException e )</a>
<span class="sourceLineNo">426</span><a id="line.426"> {</a>
<span class="sourceLineNo">427</span><a id="line.427"> throw new RoleManagerException( "unable to generate templated role: " + e.getMessage(), e );</a>
<span class="sourceLineNo">428</span><a id="line.428"> }</a>
<span class="sourceLineNo">429</span><a id="line.429"> catch ( RoleTemplateProcessorException e )</a>
<span class="sourceLineNo">430</span><a id="line.430"> {</a>
<span class="sourceLineNo">431</span><a id="line.431"> throw new RoleManagerException( "unable to resolve resource: " + resource, e );</a>
<span class="sourceLineNo">432</span><a id="line.432"> }</a>
<span class="sourceLineNo">433</span><a id="line.433"> }</a>
<span class="sourceLineNo">434</span><a id="line.434"> return rbacPermissions;</a>
<span class="sourceLineNo">435</span><a id="line.435"> }</a>
<span class="sourceLineNo">436</span><a id="line.436"></a>
<span class="sourceLineNo">437</span><a id="line.437"> return Collections.emptyList();</a>
<span class="sourceLineNo">438</span><a id="line.438"> }</a>
<span class="sourceLineNo">439</span><a id="line.439"></a>
<span class="sourceLineNo">440</span><a id="line.440"> private String resolvePermissionResource( RedbackRoleModel model, ModelPermission permission, String resource )</a>
<span class="sourceLineNo">441</span><a id="line.441"> throws RoleTemplateProcessorException</a>
<span class="sourceLineNo">442</span><a id="line.442"> {</a>
<span class="sourceLineNo">443</span><a id="line.443"> String permissionResource = permission.getResource();</a>
<span class="sourceLineNo">444</span><a id="line.444"></a>
<span class="sourceLineNo">445</span><a id="line.445"> // if permission's resource is ${resource}, return the resource passed in</a>
<span class="sourceLineNo">446</span><a id="line.446"> if ( permissionResource.startsWith( "${" ) )</a>
<span class="sourceLineNo">447</span><a id="line.447"> {</a>
<span class="sourceLineNo">448</span><a id="line.448"> String tempStr = permissionResource.substring( 2, permissionResource.indexOf( '}' ) );</a>
<span class="sourceLineNo">449</span><a id="line.449"></a>
<span class="sourceLineNo">450</span><a id="line.450"> if ( "resource".equals( tempStr ) )</a>
<span class="sourceLineNo">451</span><a id="line.451"> {</a>
<span class="sourceLineNo">452</span><a id="line.452"> return resource;</a>
<span class="sourceLineNo">453</span><a id="line.453"> }</a>
<span class="sourceLineNo">454</span><a id="line.454"> }</a>
<span class="sourceLineNo">455</span><a id="line.455"></a>
<span class="sourceLineNo">456</span><a id="line.456"> // check if the resource resolves to declared operation</a>
<span class="sourceLineNo">457</span><a id="line.457"> String declaredResource = resolveResource( model, permission.getResource() );</a>
<span class="sourceLineNo">458</span><a id="line.458"> if ( declaredResource != null )</a>
<span class="sourceLineNo">459</span><a id="line.459"> {</a>
<span class="sourceLineNo">460</span><a id="line.460"> return declaredResource;</a>
<span class="sourceLineNo">461</span><a id="line.461"> }</a>
<span class="sourceLineNo">462</span><a id="line.462"> else</a>
<span class="sourceLineNo">463</span><a id="line.463"> {</a>
<span class="sourceLineNo">464</span><a id="line.464"> // either niether of the above apply, then its the resource.</a>
<span class="sourceLineNo">465</span><a id="line.465"> return resource;</a>
<span class="sourceLineNo">466</span><a id="line.466"> }</a>
<span class="sourceLineNo">467</span><a id="line.467"> }</a>
<span class="sourceLineNo">468</span><a id="line.468"></a>
<span class="sourceLineNo">469</span><a id="line.469"> private String resolveResource( RedbackRoleModel model, String resource )</a>
<span class="sourceLineNo">470</span><a id="line.470"> throws RoleTemplateProcessorException</a>
<span class="sourceLineNo">471</span><a id="line.471"> {</a>
<span class="sourceLineNo">472</span><a id="line.472"> ModelResource resolvedResource = RoleModelUtils.getModelResource( model, resource );</a>
<span class="sourceLineNo">473</span><a id="line.473"></a>
<span class="sourceLineNo">474</span><a id="line.474"> if ( resolvedResource != null )</a>
<span class="sourceLineNo">475</span><a id="line.475"> {</a>
<span class="sourceLineNo">476</span><a id="line.476"> return resolvedResource.getName();</a>
<span class="sourceLineNo">477</span><a id="line.477"> }</a>
<span class="sourceLineNo">478</span><a id="line.478"> else</a>
<span class="sourceLineNo">479</span><a id="line.479"> {</a>
<span class="sourceLineNo">480</span><a id="line.480"> return null;</a>
<span class="sourceLineNo">481</span><a id="line.481"> }</a>
<span class="sourceLineNo">482</span><a id="line.482"> }</a>
<span class="sourceLineNo">483</span><a id="line.483"></a>
<span class="sourceLineNo">484</span><a id="line.484"> public RBACManager getRbacManager()</a>
<span class="sourceLineNo">485</span><a id="line.485"> {</a>
<span class="sourceLineNo">486</span><a id="line.486"> return rbacManager;</a>
<span class="sourceLineNo">487</span><a id="line.487"> }</a>
<span class="sourceLineNo">488</span><a id="line.488"></a>
<span class="sourceLineNo">489</span><a id="line.489"> public void setRbacManager( RBACManager rbacManager )</a>
<span class="sourceLineNo">490</span><a id="line.490"> {</a>
<span class="sourceLineNo">491</span><a id="line.491"> this.rbacManager = rbacManager;</a>
<span class="sourceLineNo">492</span><a id="line.492"> }</a>
<span class="sourceLineNo">493</span><a id="line.493">}</a>
</pre>
</div>
</main>
</body>
</html>