blob: f17ef69bae7f263a51388abcb5be824b1a7d2494 [file] [log] [blame]
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- NewPage -->
<html lang="en">
<head>
<!-- Generated by javadoc (1.8.0_121) on Tue Apr 25 03:06:38 SST 2017 -->
<title>ConfigFileBasedAuthenticator</title>
<meta name="date" content="2017-04-25">
<link rel="stylesheet" type="text/css" href="../../../../stylesheet.css" title="Style">
<script type="text/javascript" src="../../../../script.js"></script>
</head>
<body>
<script type="text/javascript"><!--
try {
if (location.href.indexOf('is-external=true') == -1) {
parent.document.title="ConfigFileBasedAuthenticator";
}
}
catch(err) {
}
//-->
var methods = {"i0":10};
var tabs = {65535:["t0","All Methods"],2:["t2","Instance Methods"],8:["t4","Concrete Methods"]};
var altColor = "altColor";
var rowColor = "rowColor";
var tableTab = "tableTab";
var activeTableTab = "activeTableTab";
</script>
<noscript>
<div>JavaScript is disabled on your browser.</div>
</noscript>
<!-- ========= START OF TOP NAVBAR ======= -->
<div class="topNav"><a name="navbar.top">
<!-- -->
</a>
<div class="skipNav"><a href="#skip.navbar.top" title="Skip navigation links">Skip navigation links</a></div>
<a name="navbar.top.firstrow">
<!-- -->
</a>
<ul class="navList" title="Navigation">
<li><a href="../../../../overview-summary.html">Overview</a></li>
<li><a href="package-summary.html">Package</a></li>
<li class="navBarCell1Rev">Class</li>
<li><a href="package-tree.html">Tree</a></li>
<li><a href="../../../../deprecated-list.html">Deprecated</a></li>
<li><a href="../../../../index-all.html">Index</a></li>
<li><a href="../../../../help-doc.html">Help</a></li>
</ul>
</div>
<div class="subNav">
<ul class="navList">
<li><a href="../../../../org/apache/gearpump/security/Authenticator.AuthenticationResult.html" title="interface in org.apache.gearpump.security"><span class="typeNameLink">Prev&nbsp;Class</span></a></li>
<li><a href="../../../../org/apache/gearpump/security/ConfigFileBasedAuthenticatorSpec.html" title="class in org.apache.gearpump.security"><span class="typeNameLink">Next&nbsp;Class</span></a></li>
</ul>
<ul class="navList">
<li><a href="../../../../index.html?org/apache/gearpump/security/ConfigFileBasedAuthenticator.html" target="_top">Frames</a></li>
<li><a href="ConfigFileBasedAuthenticator.html" target="_top">No&nbsp;Frames</a></li>
</ul>
<ul class="navList" id="allclasses_navbar_top">
<li><a href="../../../../allclasses-noframe.html">All&nbsp;Classes</a></li>
</ul>
<div>
<script type="text/javascript"><!--
allClassesLink = document.getElementById("allclasses_navbar_top");
if(window==top) {
allClassesLink.style.display = "block";
}
else {
allClassesLink.style.display = "none";
}
//-->
</script>
</div>
<div>
<ul class="subNavList">
<li>Summary:&nbsp;</li>
<li>Nested&nbsp;|&nbsp;</li>
<li>Field&nbsp;|&nbsp;</li>
<li><a href="#constructor.summary">Constr</a>&nbsp;|&nbsp;</li>
<li><a href="#method.summary">Method</a></li>
</ul>
<ul class="subNavList">
<li>Detail:&nbsp;</li>
<li>Field&nbsp;|&nbsp;</li>
<li><a href="#constructor.detail">Constr</a>&nbsp;|&nbsp;</li>
<li><a href="#method.detail">Method</a></li>
</ul>
</div>
<a name="skip.navbar.top">
<!-- -->
</a></div>
<!-- ========= END OF TOP NAVBAR ========= -->
<!-- ======== START OF CLASS DATA ======== -->
<div class="header">
<div class="subTitle">org.apache.gearpump.security</div>
<h2 title="Class ConfigFileBasedAuthenticator" class="title">Class ConfigFileBasedAuthenticator</h2>
</div>
<div class="contentContainer">
<ul class="inheritance">
<li>java.lang.Object</li>
<li>
<ul class="inheritance">
<li>org.apache.gearpump.security.ConfigFileBasedAuthenticator</li>
</ul>
</li>
</ul>
<div class="description">
<ul class="blockList">
<li class="blockList">
<dl>
<dt>All Implemented Interfaces:</dt>
<dd><a href="../../../../org/apache/gearpump/security/Authenticator.html" title="interface in org.apache.gearpump.security">Authenticator</a></dd>
</dl>
<hr>
<br>
<pre>public class <span class="typeNameLabel">ConfigFileBasedAuthenticator</span>
extends java.lang.Object
implements <a href="../../../../org/apache/gearpump/security/Authenticator.html" title="interface in org.apache.gearpump.security">Authenticator</a></pre>
<div class="block">UI dashboard authenticator based on configuration file.
<p>
It has three categories of users: admins, users, and guests.
admins have unlimited permission, like shutdown a cluster, add/remove machines.
users have limited permission to submit an application and etc..
guests can not submit/kill applications, but can view the application status.
<p>
see conf/gear.conf section gearpump.ui-security.config-file-based-authenticator to find
information about how to configure this authenticator.
<p>
[Security consideration]
It will keep one-way sha1 digest of password instead of password itself. The original password is
NOT kept in any way, so generally it is safe.
<p>
digesting flow (from original password to digest):
<pre><code>
random salt byte array of length 8 -&gt; byte array of (salt + sha1(salt, password)) -&gt;
base64Encode.
</code></pre>
<p>
Verification user input password with stored digest:
<pre><code>
base64Decode -&gt; extract salt -&gt; do sha1(salt, password) -&gt; generate digest:
salt + sha1 -&gt; compare the generated digest with the stored digest.
</code></pre></div>
</li>
</ul>
</div>
<div class="summary">
<ul class="blockList">
<li class="blockList">
<!-- ======== NESTED CLASS SUMMARY ======== -->
<ul class="blockList">
<li class="blockList"><a name="nested.class.summary">
<!-- -->
</a>
<h3>Nested Class Summary</h3>
<ul class="blockList">
<li class="blockList"><a name="nested.classes.inherited.from.class.org.apache.gearpump.security.Authenticator">
<!-- -->
</a>
<h3>Nested classes/interfaces inherited from interface&nbsp;org.apache.gearpump.security.<a href="../../../../org/apache/gearpump/security/Authenticator.html" title="interface in org.apache.gearpump.security">Authenticator</a></h3>
<code><a href="../../../../org/apache/gearpump/security/Authenticator.AuthenticationResult.html" title="interface in org.apache.gearpump.security">Authenticator.AuthenticationResult</a></code></li>
</ul>
</li>
</ul>
<!-- ======== CONSTRUCTOR SUMMARY ======== -->
<ul class="blockList">
<li class="blockList"><a name="constructor.summary">
<!-- -->
</a>
<h3>Constructor Summary</h3>
<table class="memberSummary" border="0" cellpadding="3" cellspacing="0" summary="Constructor Summary table, listing constructors, and an explanation">
<caption><span>Constructors</span><span class="tabEnd">&nbsp;</span></caption>
<tr>
<th class="colOne" scope="col">Constructor and Description</th>
</tr>
<tr class="altColor">
<td class="colOne"><code><span class="memberNameLink"><a href="../../../../org/apache/gearpump/security/ConfigFileBasedAuthenticator.html#ConfigFileBasedAuthenticator-com.typesafe.config.Config-">ConfigFileBasedAuthenticator</a></span>(com.typesafe.config.Config&nbsp;config)</code>&nbsp;</td>
</tr>
</table>
</li>
</ul>
<!-- ========== METHOD SUMMARY =========== -->
<ul class="blockList">
<li class="blockList"><a name="method.summary">
<!-- -->
</a>
<h3>Method Summary</h3>
<table class="memberSummary" border="0" cellpadding="3" cellspacing="0" summary="Method Summary table, listing methods, and an explanation">
<caption><span id="t0" class="activeTableTab"><span>All Methods</span><span class="tabEnd">&nbsp;</span></span><span id="t2" class="tableTab"><span><a href="javascript:show(2);">Instance Methods</a></span><span class="tabEnd">&nbsp;</span></span><span id="t4" class="tableTab"><span><a href="javascript:show(8);">Concrete Methods</a></span><span class="tabEnd">&nbsp;</span></span></caption>
<tr>
<th class="colFirst" scope="col">Modifier and Type</th>
<th class="colLast" scope="col">Method and Description</th>
</tr>
<tr id="i0" class="altColor">
<td class="colFirst"><code>scala.concurrent.Future&lt;<a href="../../../../org/apache/gearpump/security/Authenticator.AuthenticationResult.html" title="interface in org.apache.gearpump.security">Authenticator.AuthenticationResult</a>&gt;</code></td>
<td class="colLast"><code><span class="memberNameLink"><a href="../../../../org/apache/gearpump/security/ConfigFileBasedAuthenticator.html#authenticate-java.lang.String-java.lang.String-scala.concurrent.ExecutionContext-">authenticate</a></span>(java.lang.String&nbsp;user,
java.lang.String&nbsp;password,
scala.concurrent.ExecutionContext&nbsp;ec)</code>&nbsp;</td>
</tr>
</table>
<ul class="blockList">
<li class="blockList"><a name="methods.inherited.from.class.java.lang.Object">
<!-- -->
</a>
<h3>Methods inherited from class&nbsp;java.lang.Object</h3>
<code>clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait</code></li>
</ul>
</li>
</ul>
</li>
</ul>
</div>
<div class="details">
<ul class="blockList">
<li class="blockList">
<!-- ========= CONSTRUCTOR DETAIL ======== -->
<ul class="blockList">
<li class="blockList"><a name="constructor.detail">
<!-- -->
</a>
<h3>Constructor Detail</h3>
<a name="ConfigFileBasedAuthenticator-com.typesafe.config.Config-">
<!-- -->
</a>
<ul class="blockListLast">
<li class="blockList">
<h4>ConfigFileBasedAuthenticator</h4>
<pre>public&nbsp;ConfigFileBasedAuthenticator(com.typesafe.config.Config&nbsp;config)</pre>
</li>
</ul>
</li>
</ul>
<!-- ============ METHOD DETAIL ========== -->
<ul class="blockList">
<li class="blockList"><a name="method.detail">
<!-- -->
</a>
<h3>Method Detail</h3>
<a name="authenticate-java.lang.String-java.lang.String-scala.concurrent.ExecutionContext-">
<!-- -->
</a>
<ul class="blockListLast">
<li class="blockList">
<h4>authenticate</h4>
<pre>public&nbsp;scala.concurrent.Future&lt;<a href="../../../../org/apache/gearpump/security/Authenticator.AuthenticationResult.html" title="interface in org.apache.gearpump.security">Authenticator.AuthenticationResult</a>&gt;&nbsp;authenticate(java.lang.String&nbsp;user,
java.lang.String&nbsp;password,
scala.concurrent.ExecutionContext&nbsp;ec)</pre>
<dl>
<dt><span class="overrideSpecifyLabel">Specified by:</span></dt>
<dd><code><a href="../../../../org/apache/gearpump/security/Authenticator.html#authenticate-java.lang.String-java.lang.String-scala.concurrent.ExecutionContext-">authenticate</a></code>&nbsp;in interface&nbsp;<code><a href="../../../../org/apache/gearpump/security/Authenticator.html" title="interface in org.apache.gearpump.security">Authenticator</a></code></dd>
</dl>
</li>
</ul>
</li>
</ul>
</li>
</ul>
</div>
</div>
<!-- ========= END OF CLASS DATA ========= -->
<!-- ======= START OF BOTTOM NAVBAR ====== -->
<div class="bottomNav"><a name="navbar.bottom">
<!-- -->
</a>
<div class="skipNav"><a href="#skip.navbar.bottom" title="Skip navigation links">Skip navigation links</a></div>
<a name="navbar.bottom.firstrow">
<!-- -->
</a>
<ul class="navList" title="Navigation">
<li><a href="../../../../overview-summary.html">Overview</a></li>
<li><a href="package-summary.html">Package</a></li>
<li class="navBarCell1Rev">Class</li>
<li><a href="package-tree.html">Tree</a></li>
<li><a href="../../../../deprecated-list.html">Deprecated</a></li>
<li><a href="../../../../index-all.html">Index</a></li>
<li><a href="../../../../help-doc.html">Help</a></li>
</ul>
</div>
<div class="subNav">
<ul class="navList">
<li><a href="../../../../org/apache/gearpump/security/Authenticator.AuthenticationResult.html" title="interface in org.apache.gearpump.security"><span class="typeNameLink">Prev&nbsp;Class</span></a></li>
<li><a href="../../../../org/apache/gearpump/security/ConfigFileBasedAuthenticatorSpec.html" title="class in org.apache.gearpump.security"><span class="typeNameLink">Next&nbsp;Class</span></a></li>
</ul>
<ul class="navList">
<li><a href="../../../../index.html?org/apache/gearpump/security/ConfigFileBasedAuthenticator.html" target="_top">Frames</a></li>
<li><a href="ConfigFileBasedAuthenticator.html" target="_top">No&nbsp;Frames</a></li>
</ul>
<ul class="navList" id="allclasses_navbar_bottom">
<li><a href="../../../../allclasses-noframe.html">All&nbsp;Classes</a></li>
</ul>
<div>
<script type="text/javascript"><!--
allClassesLink = document.getElementById("allclasses_navbar_bottom");
if(window==top) {
allClassesLink.style.display = "block";
}
else {
allClassesLink.style.display = "none";
}
//-->
</script>
</div>
<div>
<ul class="subNavList">
<li>Summary:&nbsp;</li>
<li>Nested&nbsp;|&nbsp;</li>
<li>Field&nbsp;|&nbsp;</li>
<li><a href="#constructor.summary">Constr</a>&nbsp;|&nbsp;</li>
<li><a href="#method.summary">Method</a></li>
</ul>
<ul class="subNavList">
<li>Detail:&nbsp;</li>
<li>Field&nbsp;|&nbsp;</li>
<li><a href="#constructor.detail">Constr</a>&nbsp;|&nbsp;</li>
<li><a href="#method.detail">Method</a></li>
</ul>
</div>
<a name="skip.navbar.bottom">
<!-- -->
</a></div>
<!-- ======== END OF BOTTOM NAVBAR ======= -->
</body>
</html>