Import ES 1.5 code from supersyn repository
git-svn-id: https://svn.apache.org/repos/asf/manifoldcf/integration/elasticsearch-1.5/trunk@1688315 13f79535-47bb-0310-9956-ffa450edef68
diff --git a/CHANGES.txt b/CHANGES.txt
new file mode 100644
index 0000000..b06e256
--- /dev/null
+++ b/CHANGES.txt
@@ -0,0 +1,27 @@
+Apache ManifoldCF Plugin for Elastic Search change Log
+$Id: CHANGES.txt 1571169 2015-04-29 Bartlomiej Superson $
+
+======================= Release 3.0 =====================
+
+Plugin modified to work with Elasticsearch 1.5.2.
+
+======================= Release 2.0 =====================
+
+CONNECTORS-886: Add support for parent security. This
+change requires reindexing of all content supported by this plugin.
+(Karl Wright)
+
+======================= Release 1.1 =====================
+
+Add functionality making the plugin compatible with multi-domain
+features of ManifoldCF. Specifically, create method signatures that
+allow multiple domain/username pairs to be passed in.
+(Karl Wright)
+
+======================= Release 0.1 =====================
+
+Added the path.data parameter in the ElasticSearch server: now the data folder is created under the target folder
+(Karl Wright, Piergiorgio Lucidi)
+
+Initial commit.
+(Karl Wright)
diff --git a/DEPENDENCIES.txt b/DEPENDENCIES.txt
new file mode 100644
index 0000000..0d7e697
--- /dev/null
+++ b/DEPENDENCIES.txt
@@ -0,0 +1,11 @@
+Apache ManifoldCF Plugin for Elastic Search requires
+--------------------------------------------------
+* JRE 1.6 or above
+* mvn 2.2 or higher
+
+For building Apache ManifoldCF Plugin for Elastic Search:
+-----------------------------------------------------
+
+* Look at README.txt
+
+
diff --git a/KEYS b/KEYS
new file mode 100644
index 0000000..43f6c27
--- /dev/null
+++ b/KEYS
@@ -0,0 +1,130 @@
+(instructions copied from forrest's KEYS file)
+
+This file contains the PGP keys of various developers.
+Please don't use them for email unless you have to. Their main
+purpose is code signing.
+
+Users: pgp < KEYS
+Developers:
+ pgp -kxa <your name> and append it to this file.
+ (pgpk -ll <your name> && pgpk -xa <your name>) >> this file.
+ (gpg --list-sigs <your name>
+ && gpg --armor --export <your name>) >> this file.
+
+----------------------------------------------------------------
+pub 4096R/03824582 2010-11-19
+uid Karl David Wright (CODE SIGNING KEY) <kwright@apache.org>
+sig 3 03824582 2010-11-19 Karl David Wright (CODE SIGNING KEY) <kwright@apache.org>
+sub 4096R/EE82775D 2010-11-19
+sig 03824582 2010-11-19 Karl David Wright (CODE SIGNING KEY) <kwright@apache.org>
+
+-----BEGIN PGP PUBLIC KEY BLOCK-----
+Version: GnuPG v1.4.11 (MingW32)
+
+mQINBEzmR2IBEACvDjCt9SU4ma8kcrFitl6fTx3hAWJmosC1OLryVYVQ+g816NaD
+oRgKim6GcYC0wvQEHvlIpEq4xXqKIWhH4xko8wvV619uOqoK+Ca6dI7FzxnBcxQ5
+D0J59zXRikYO0qhNgZqdo+37l6AgaDMbgPUPq0XQO4KCo+XbluCZfRuL5UcbF4H5
+j4mxT3IgnMHtdzaceKP+wruh/Ak18w/6w+5GnE3QYYPGqlnBqPVTWQFjBDL+L9QD
+LWVBgduQQ3YXhDmfZGRBppzklPJeiWwBQH7mZqgjht0aoIvwLVgCgA6S9TRRcUtE
+maefHcGduKhENYgt0I3mWD41VpKLgq6kfbZYg1fCwtXd5If0KxxhsZmBlMGYCwcV
+TBzcBLhktPAFKquM/VCzu3DR8hAYQjYukOYMAAB2PGjaQlP4Rc4/vTQR8CE3oYR6
+pLgnPu8SjUcxomqKPFM1SCAx/BgUpMrWRNNO/0j9hhBlCDnHxxrTsPvMW+uqCHQp
+xNvneIuFPt7TSwcK1Luyoygtoj/3J/2zI9SCXrNJwZZzGfc26Lp4XVaGNEujwLeG
+Ik2EN2dHdcDJWOAv+szk5jgn6G9c0sb9bFCjSNI9yWjZLofTvheKIjC8EBBmB7LD
+FHLcjbCbFYGReBSWenkfcOyEq83vMrCwZ+WgVjdazZVnjCa7GntYIgOpIwARAQAB
+tDlLYXJsIERhdmlkIFdyaWdodCAoQ09ERSBTSUdOSU5HIEtFWSkgPGt3cmlnaHRA
+YXBhY2hlLm9yZz6JAjcEEwEKACEFAkzmR2ICGwMFCwkIBwMFFQoJCAsFFgIDAQAC
+HgECF4AACgkQ/R/wnAOCRYKhvg/+Nr/yGbkx3kEMhbrpco0P2+hM95J1DjihFh/5
+gDeQ5ISTENi9SQt7OBkIDGMS7FyeOXuvGpjrkqjp5PGkc/pTO3Flu/5bJAWNHQGF
+tNv51tJeGeDD8wotLvoJOLJfxZZ42JGww5TmkXqMeKUBOsBB7vqaLEuk8sm/xr0D
+R76b9b5zpcMUlQAA3rgS0Z6BGKE4X9WAmbCo7k0O+k0KNAOoB1WoUrnXKkwDwDQL
+eTOwQujLm7OiRz/nkvXx1YlpXi3u9TNcXArdOWU3HkYduSc2fcaHaj4WfzaX79CQ
+meiJBpYLglWqFaMPZPOgO9g12kMk0DsslvZZkqzcGjCB1yn5DnxgqpLLkzWmclFA
+FBPKmbxMA2iUNy1Kgn+ZhiBRYl1rz0UdTa3sthOn2paTc1IdDHUAubr8qkkfHtYp
+AaIuF+T7iqjs8J1SLhtBxqEJ8FMs9b0vSNWs+UTaXgbmYoaINMePtOgPVQfMU1Mk
+r5v/1DE99C7V0qi37AAdTEBKUKkjlU/gWVKs1dL+te/gl6b6KxyNt3oiTUFApzQP
+r5VVpNrEqWKqUVAzxif4v+iUsmQrnw2pwRCzXgQ9o8DfmqbKjKwwkWrTZMTCaNvw
+L2oT/miX1acMpmtV8Co02++gt439+Aw1ZenvQ+zuHXFglZjhHa68FJj+XtAof0Qf
+xuhLi5i5Ag0ETOZHYgEQAMHgiGeeGT7a+UApO2Wr8AM4vjTXUqnc/HpDdEOVBWMV
+Y28QGaG8MgkUhUMCNel1EHZgHF3PVmty9izrqpUOOIPoD9JBqH903+gkPAorloOA
+UzI4+4IHCSZPrhgU+akhBFfYW1SI/2noF8AUzTZnXamlLMeLaJIJDvHDIaKG6lxf
+hpPx9WGjmLP8Xf0D9WeIdmsJlKxWWBCCnWM9qZfLcrBk+cZhuDJbIPp9edPGu7DB
+qQXrmPTN9XnuRo1fUBhxxlNQ/gEsV/I4mKko+Pgs4bkRGk2b0p7/rkbuAWw9NVX1
++17vOAuP0AuHCDuT7qno4bH1m0zftDqcNyvNl8NphxCyfXljO/hCmujKqPOn1df6
+HpORDy1kKjJeiKWWeaacRwirncwT1AZuri75iUGHCer05yt/PoYRV2fYRw6TKt8g
+lPu/2UbNujGnSOkOthwFuWP6G6SF5oRg+YdkROaC00v7VTfLvCoZ9Rdh0ZhYrwmG
+sW6iJ/AsjSfGR5WtaU+ahliyTZnIUoGND3njgBKiI8E6YFzDs2Lh+nvynv/jmB/X
+1aPxieqXw1a6h/0BsQT/uqY7941XGAdWvSzg5NP6oL+sncjKd2VXVVi/P/dMbs+h
+W+lP4RBxT6elwuzUTUaiYeEmw2WL/A/wdPnQKjVr0HA6twMnzjjOs6AnGn85FlAZ
+ABEBAAGJAh8EGAEKAAkFAkzmR2ICGwwACgkQ/R/wnAOCRYLpOhAAltJjDcRTa2MI
+M45Z7WavWwVaXxbZNyIzOifR431oqyN0bz3C4KaDz2o8Rti9y0wTfS7cgzJFe0mC
+aXU01N7t/pK3IYhf+xe/f+iBZ3JASCGu+H3zLgY7qRm3q441AkPprwVqrGIemUFQ
+qTFiSbRi9/R0OzoY+T0ZILR7eu8EmIDhoBi0aWXlxzxHKikB5SqenZz/x5sbhZcy
+UdvNKe4iB4sfhAwMreBEFH6+/rlUIC8uWTb7IScBzSXj8R9hoAUXAH35T+sTs6nx
+QCW5XzO7YRQEgbaFUOSu3s5a1NVcFyhcDq9ASOOlg0JYNK9hi/UdyXUtAoXhn8WI
+1JD9d1kz6vke2YvXwkp+ntWK6dhHKPzwN2OrHSApOM7+9dLxqT/4buQWB1BXAD2S
+d8521WI9vzEW8qyI3rZhp3OLB5GUTFCw4POFIehKCDhET6gDz0MCYHVaEMBsySfT
+13/2vZd1gEh9BD9QHlrmxqo+gJqpw4q/usKMC3VNzw6appHSzQEfor2lpfx5WYy0
+iiCKmIlos2z+lIy9AarCBqOYjcWHjkYnb6QT1k/HKPuyBV7LMqoVPiQuxgZKqx01
+ZpDvtauiZqH+MMH2qe6n5sXhDQijGwXbAsFiorFj0/kWAEncJGpyI/u6q7GnHNS5
+H4n9zm2v9HW8fqSbQq3Ym8+WQ64+IK0=
+=gEd1
+-----END PGP PUBLIC KEY BLOCK-----
+pub 4096R/FE045966 2009-10-13
+ Key fingerprint = A46D 8682 A850 E44E 4FEC 20EB 8A8A 771F FE04 5966
+uid Grant Ingersoll (CODE SIGNING KEY) <gsingers@apache.org>
+sub 4096R/72F9E0C0 2009-10-13
+
+-----BEGIN PGP PUBLIC KEY BLOCK-----
+Version: GnuPG v1.4.7 (Darwin)
+
+mQINBErU6JEBEACsovhRB+Z8VrdTU76Qxg8u+0WiSaoilsksGgOaphWvWt0b6rA3
+PJSGuDuMJfL+lGqk+aARehiZNbNl0cGYtP4Av/fElTdSr1UlmDeFjG+7Qi7FB6KK
+vAjv4mw+XM05QRTADjpNkDfAEXGPR1GNE7lOfPvNqvAl9YMLHJOBGlVqq5ZZAPHZ
+/R6Cg7+5qHbVJKtPqSxAoPJQwg6ADwDZv9nWZfbp2VwVwBkuVxBCRBPFN+WTFmW/
+k1LSxUIeHqOG9RXo7S/DYddthE0iBzP3yKA5fs3k9zaQZNAjC92Dj/M4oDiIimqG
+DJAO7ixpQY2ug9FB4LtWkyeNRnOM1LKd3TbZNqzZt4TuhCI3C5LAfVoXRPxe4T3n
+4hvWkL/2THSKfC4u0CLGjw41rXhD86YYiIWdvxVezfESzpqZPhBrAZWfx7kB69pq
+8DxWFXCaA31S/L2I6B1ZUmpOhtxg0cDoevipne7jaqRjA7TknOC45+CrpuEkOvQO
+8rwHbtshT/JDFLPfq0ruDH21eV4QYP/JLffDGyEtoRRRr4M2DZCFkOCWIPE0l142
+5mIi0nqMSj1HK5kuwMQoNAf6vF6P6MYyGWJ8nR13CDtFOnjpOpuxZiTQhlb0cqXj
+X4yQBjFim8ztGOnHrlSh25OgeKuiCWiCIuyFGykjX21RtJ/AwiOeMr4zkwARAQAB
+tDhHcmFudCBJbmdlcnNvbGwgKENPREUgU0lHTklORyBLRVkpIDxnc2luZ2Vyc0Bh
+cGFjaGUub3JnPokCNwQTAQoAIQUCStTokQIbAwULCQgHAwUVCgkICwUWAgMBAAIe
+AQIXgAAKCRCKincf/gRZZqcfD/4+zhoLTTpTGRNutTyjPnR85aTuMUVtqYNLjEcF
+PSV7p1OPhsGd3g5iaQtwCMsbWDPRSL+Xvy4/E4D32YjUR026mzAUnICq4Z35TecT
+StIeMadgSwJ0fNvuzBB8jJfUYW6a91D9TZirEC4fRVRL1bnJvmjm0HnGLQa5uGCl
+dUMbR04YXU+5V8S6KbRtLwhiVDD/do6XKeS9PGY941sw9182mLZbIbEcQrNWf8s/
+eOnobosxg5a0WxKfSZgQfNqkkuNlsRbKwI2gSjzAl030r6pWzduvftqFdnoaOBN/
+yNM1BghAhXmb/hxjuQa0x+xan15/lY5FwDX1bdnZcEI0KHJ/FIPFgk59XJVnZYH/
+tRI6jqmxQvdliA9q6rt/ctZAYaOhmXI28eeLCmdnZKUZjiG1ORYC0tIYdOYc/nXP
+NqryDaa2OD2rMy8BM5tfQ/Om/6kavDqn/m8x0jLLuOne5Umeste3yTZ3pbJWc5GF
+izOCX0FualpLXNBWt3jCooSaj5Gx92pFgoanbtI91ouVNsC24eKOJZYibKLP5fuH
+B1sNvtPcWE3e99qOzVnolHjbDX4KzXCW+yFad714kK1vdAlDvqIt2OuEuQFggZHS
+5G5FbGjgqFUG5D0uckBmu/8lZ82YW2yhuQosa5EOMwChG1sqtsYuddbifFF78AM4
+vYnmKohGBBARCgAGBQJK1OocAAoJEMsDFRmoZ+ixVg4An0MfyRmOv0tA8/UibzyK
+KPrzo1aeAKCIV+M3L+gPT9yJ9843HxyBWL+j6bkCDQRK1OiRARAApG7lRX08hPq5
+7KRRUsK6GChneFeZZNNI35VpFQHPe8y/4ej7Ydnr37otEjIvd+14p0M+PF6igCIm
+IGp2dg57PFfoOVW+apoudAtBpWkdBSjMJQ4pCoLwyv/HSXKW6QxMZeO5OBdT4iAg
+AT36M2m/lpv5wC7g7SUJDusyFPuYtMtxAkj6TUPTFJBS4+FzhrNBoCXxILDKh0AE
+N9Sslm37tC7Le84PkiI/k0C//KqNZFQ11Cazyf0CuQKj4gLtkfBTaDenlsufAKNI
+M2pkIxtLNpx93Gcay2lVKD9Dv2i4EmQID7Vt6fZ2CP+60K7CnepLhapkfWa9Rk71
+7fqLIlXCFYdWEmuT614dnDuuuRfm12ZqT3GAx9F0elZ2yv4DrXnW1F60ASJuFnDf
+RYcbTmw2VVoDiAo2al4uoE7a2yjyv7PExB65k0Uj0n1V4PF413np3r/WLSWBxxNu
+9K8oV0KZI/UxvhMULGI23ryNTZAsoi3E44lZ0EUrJTWMRvLuewQdNpNLmlo30HNL
+VTyoIlWbzhsu4ejKVqLBs/Q9M92c/Um6FJM5owkiGBEvnRtGGWhf89RonCncwg2g
+i/rk91TTKnhGpYv3tenLjZ6qmlgMgT+KUrElqrLv02kD3xZ7+2zwhaLYWFlZN6wr
+xXlA/FDOEz3tChqG+41Vf8W26+QnC98AEQEAAYkCHwQYAQoACQUCStTokQIbDAAK
+CRCKincf/gRZZgzbEACfLTy+6afsT4wAgKYdlc+6w3bBqFnDzoG0JRIrUsVhEnjB
+xhl+RZA9XMkPvw5iAeNOWSU+SoPz8hGrv3tkGJXqfeThOAB5IVDDW8FDmm57/sl4
+2m09B+QHZ7Buw56OD90GoCSm1otkbaIUjoMTbuQxTRb1qykVHO4AgLReaeMb9jqu
+hqwxyzGzWMqVR01olgvCkSDrooYjA1ltQ84JrJhic5+zdQq1XYIv0dTPP3CcrFcy
+b6pVx+Y31hK9f0EXoNZv6Ekg6B5L7LUleB3XdCL+jI1eWlQ3DTE7+OkVcehpyygc
+JFgPVm/0KMPkHTa3Fw55YWbcrwAKGv5fWSj852pbaW/GNgDAiay0MPExEYey2cu5
+Pi8dUOmJoqcznBt9qQrrmRNWPRa1Gu9vowM9m90+jtU+Tlxo104tj8gKWVngnPhn
+v1VPKPblEwJfuqC3DQh3XWzs3AwjKLXXfwznF7slqBRT48BwdLsietnovoTsZXYg
+7ks2s/QxklWisZUxrhpZTNeA/WQKxyXwiN2sKxulwjd1PnAz5DeFQWKDNZHyHP+T
+1cqtTc96tSwb2XW3iA2uZlD4aTkrOmm3FKbauC/rFmCjkpvwpvqcIdpib4M2DgNx
+zAZ2cJnxw3f57qc9Yh5qvhDUephwOAlAy8ekc1AmX14F+mwYE3GjcqeGdEbLNw==
+=GLHu
+-----END PGP PUBLIC KEY BLOCK-----
\ No newline at end of file
diff --git a/LICENSE.txt b/LICENSE.txt
new file mode 100644
index 0000000..66a27ec
--- /dev/null
+++ b/LICENSE.txt
@@ -0,0 +1,177 @@
+ Apache License
+ Version 2.0, January 2004
+ http://www.apache.org/licenses/
+
+ TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
+
+ 1. Definitions.
+
+ "License" shall mean the terms and conditions for use, reproduction,
+ and distribution as defined by Sections 1 through 9 of this document.
+
+ "Licensor" shall mean the copyright owner or entity authorized by
+ the copyright owner that is granting the License.
+
+ "Legal Entity" shall mean the union of the acting entity and all
+ other entities that control, are controlled by, or are under common
+ control with that entity. For the purposes of this definition,
+ "control" means (i) the power, direct or indirect, to cause the
+ direction or management of such entity, whether by contract or
+ otherwise, or (ii) ownership of fifty percent (50%) or more of the
+ outstanding shares, or (iii) beneficial ownership of such entity.
+
+ "You" (or "Your") shall mean an individual or Legal Entity
+ exercising permissions granted by this License.
+
+ "Source" form shall mean the preferred form for making modifications,
+ including but not limited to software source code, documentation
+ source, and configuration files.
+
+ "Object" form shall mean any form resulting from mechanical
+ transformation or translation of a Source form, including but
+ not limited to compiled object code, generated documentation,
+ and conversions to other media types.
+
+ "Work" shall mean the work of authorship, whether in Source or
+ Object form, made available under the License, as indicated by a
+ copyright notice that is included in or attached to the work
+ (an example is provided in the Appendix below).
+
+ "Derivative Works" shall mean any work, whether in Source or Object
+ form, that is based on (or derived from) the Work and for which the
+ editorial revisions, annotations, elaborations, or other modifications
+ represent, as a whole, an original work of authorship. For the purposes
+ of this License, Derivative Works shall not include works that remain
+ separable from, or merely link (or bind by name) to the interfaces of,
+ the Work and Derivative Works thereof.
+
+ "Contribution" shall mean any work of authorship, including
+ the original version of the Work and any modifications or additions
+ to that Work or Derivative Works thereof, that is intentionally
+ submitted to Licensor for inclusion in the Work by the copyright owner
+ or by an individual or Legal Entity authorized to submit on behalf of
+ the copyright owner. For the purposes of this definition, "submitted"
+ means any form of electronic, verbal, or written communication sent
+ to the Licensor or its representatives, including but not limited to
+ communication on electronic mailing lists, source code control systems,
+ and issue tracking systems that are managed by, or on behalf of, the
+ Licensor for the purpose of discussing and improving the Work, but
+ excluding communication that is conspicuously marked or otherwise
+ designated in writing by the copyright owner as "Not a Contribution."
+
+ "Contributor" shall mean Licensor and any individual or Legal Entity
+ on behalf of whom a Contribution has been received by Licensor and
+ subsequently incorporated within the Work.
+
+ 2. Grant of Copyright License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ copyright license to reproduce, prepare Derivative Works of,
+ publicly display, publicly perform, sublicense, and distribute the
+ Work and such Derivative Works in Source or Object form.
+
+ 3. Grant of Patent License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ (except as stated in this section) patent license to make, have made,
+ use, offer to sell, sell, import, and otherwise transfer the Work,
+ where such license applies only to those patent claims licensable
+ by such Contributor that are necessarily infringed by their
+ Contribution(s) alone or by combination of their Contribution(s)
+ with the Work to which such Contribution(s) was submitted. If You
+ institute patent litigation against any entity (including a
+ cross-claim or counterclaim in a lawsuit) alleging that the Work
+ or a Contribution incorporated within the Work constitutes direct
+ or contributory patent infringement, then any patent licenses
+ granted to You under this License for that Work shall terminate
+ as of the date such litigation is filed.
+
+ 4. Redistribution. You may reproduce and distribute copies of the
+ Work or Derivative Works thereof in any medium, with or without
+ modifications, and in Source or Object form, provided that You
+ meet the following conditions:
+
+ (a) You must give any other recipients of the Work or
+ Derivative Works a copy of this License; and
+
+ (b) You must cause any modified files to carry prominent notices
+ stating that You changed the files; and
+
+ (c) You must retain, in the Source form of any Derivative Works
+ that You distribute, all copyright, patent, trademark, and
+ attribution notices from the Source form of the Work,
+ excluding those notices that do not pertain to any part of
+ the Derivative Works; and
+
+ (d) If the Work includes a "NOTICE" text file as part of its
+ distribution, then any Derivative Works that You distribute must
+ include a readable copy of the attribution notices contained
+ within such NOTICE file, excluding those notices that do not
+ pertain to any part of the Derivative Works, in at least one
+ of the following places: within a NOTICE text file distributed
+ as part of the Derivative Works; within the Source form or
+ documentation, if provided along with the Derivative Works; or,
+ within a display generated by the Derivative Works, if and
+ wherever such third-party notices normally appear. The contents
+ of the NOTICE file are for informational purposes only and
+ do not modify the License. You may add Your own attribution
+ notices within Derivative Works that You distribute, alongside
+ or as an addendum to the NOTICE text from the Work, provided
+ that such additional attribution notices cannot be construed
+ as modifying the License.
+
+ You may add Your own copyright statement to Your modifications and
+ may provide additional or different license terms and conditions
+ for use, reproduction, or distribution of Your modifications, or
+ for any such Derivative Works as a whole, provided Your use,
+ reproduction, and distribution of the Work otherwise complies with
+ the conditions stated in this License.
+
+ 5. Submission of Contributions. Unless You explicitly state otherwise,
+ any Contribution intentionally submitted for inclusion in the Work
+ by You to the Licensor shall be under the terms and conditions of
+ this License, without any additional terms or conditions.
+ Notwithstanding the above, nothing herein shall supersede or modify
+ the terms of any separate license agreement you may have executed
+ with Licensor regarding such Contributions.
+
+ 6. Trademarks. This License does not grant permission to use the trade
+ names, trademarks, service marks, or product names of the Licensor,
+ except as required for reasonable and customary use in describing the
+ origin of the Work and reproducing the content of the NOTICE file.
+
+ 7. Disclaimer of Warranty. Unless required by applicable law or
+ agreed to in writing, Licensor provides the Work (and each
+ Contributor provides its Contributions) on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
+ implied, including, without limitation, any warranties or conditions
+ of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
+ PARTICULAR PURPOSE. You are solely responsible for determining the
+ appropriateness of using or redistributing the Work and assume any
+ risks associated with Your exercise of permissions under this License.
+
+ 8. Limitation of Liability. In no event and under no legal theory,
+ whether in tort (including negligence), contract, or otherwise,
+ unless required by applicable law (such as deliberate and grossly
+ negligent acts) or agreed to in writing, shall any Contributor be
+ liable to You for damages, including any direct, indirect, special,
+ incidental, or consequential damages of any character arising as a
+ result of this License or out of the use or inability to use the
+ Work (including but not limited to damages for loss of goodwill,
+ work stoppage, computer failure or malfunction, or any and all
+ other commercial damages or losses), even if such Contributor
+ has been advised of the possibility of such damages.
+
+ 9. Accepting Warranty or Additional Liability. While redistributing
+ the Work or Derivative Works thereof, You may choose to offer,
+ and charge a fee for, acceptance of support, warranty, indemnity,
+ or other liability obligations and/or rights consistent with this
+ License. However, in accepting such obligations, You may act only
+ on Your own behalf and on Your sole responsibility, not on behalf
+ of any other Contributor, and only if You agree to indemnify,
+ defend, and hold each Contributor harmless for any liability
+ incurred by, or claims asserted against, such Contributor by reason
+ of your accepting any such warranty or additional liability.
+
+ END OF TERMS AND CONDITIONS
+
diff --git a/NOTICE.txt b/NOTICE.txt
new file mode 100644
index 0000000..6ff17d6
--- /dev/null
+++ b/NOTICE.txt
@@ -0,0 +1,8 @@
+Apache ManifoldCF Plugin for Elastic Search
+Original work Copyright 2010-2013 The Apache Software Foundation
+Modified work Copyright 2015 Bartlomiej Superson
+
+This product includes software developed by
+The Apache Software Foundation (http://www.apache.org/).
+
+This product includes software developed by Elasticsearch.
\ No newline at end of file
diff --git a/README.txt b/README.txt
new file mode 100644
index 0000000..2a2c86c
--- /dev/null
+++ b/README.txt
@@ -0,0 +1,114 @@
+# Licensed to the Apache Software Foundation (ASF) under one or more
+# contributor license agreements. See the NOTICE file distributed with
+# this work for additional information regarding copyright ownership.
+# The ASF licenses this file to You under the Apache License, Version 2.0
+# (the "License"); you may not use this file except in compliance with
+# the License. You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+Compatibility
+------------
+
+This version of this component is fully functional with Apache ManifoldCF 1.6 and
+above and with Elasticsearch 1.5.2.
+
+Upgrading
+---------
+If you are replacing a version of Apache ManifoldCF Plugin for ElasticSearch that is
+older than version 2.0, you must declare two additional fields (representing parent
+acls and parent deny acls), and reindex all your documents. Otherwise, the plugin
+will prevent you from viewing any documents.
+
+Instructions for Building Apache ManifoldCF Plugin for Elastic Search from Source
+-----------------------------------------------------------------------------
+
+1. Download the Java SE 6 JDK (Java Development Kit), or greater, from
+ http://www.oracle.com/technetwork/java/index.html.
+ You will need the JDK installed, and the %JAVA_HOME%\bin directory included
+ on your command path. To test this, issue a "java -version" command from your
+ shell and verify that the Java version is 1.6 or greater.
+
+2. Download and install Maven 2.2.1 or later. Maven installation and configuration
+ instructions can be found here:
+
+http://maven.apache.org/run-maven/index.html
+
+3. Build packages
+
+Execute the following command in order to build the JAR packages and install
+them to the local repository:
+
+mvn install
+
+The JAR packages can be found in the target folder:
+
+target/elasticsearch-plugin-mcf-<VERSION>.jar
+
+... where <VERSION> is the release version
+
+4. Building distribution assemblies
+
+Execute the following command in order to build the distribution assemblies
+
+mvn package assembly:assembly
+
+5. Fix EOL in source files
+
+Fix the archive files so the source files have the correct EOL settings:
+
+mvn antrun:run
+
+Usage
+---------
+If you want to use security filter you should pass "u" parameter to your
+HTTP query string with the name of the authenticated user.
+HTTP queries without this parameter will be processed normally.
+
+Licensing
+---------
+
+Apache ManifoldCF Plugin for Elastic Search is licensed under the
+Apache License 2.0. See the files called LICENSE.txt and NOTICE.txt
+for more information.
+
+Cryptographic Software Notice
+-----------------------------
+
+This distribution may include software that has been designed for use
+with cryptographic software. The country in which you currently reside
+may have restrictions on the import, possession, use, and/or re-export
+to another country, of encryption software. BEFORE using any encryption
+software, please check your country's laws, regulations and policies
+concerning the import, possession, or use, and re-export of encryption
+software, to see if this is permitted. See <http://www.wassenaar.org/>
+for more information.
+
+The U.S. Government Department of Commerce, Bureau of Industry and
+Security (BIS), has classified this software as Export Commodity
+Control Number (ECCN) 5D002.C.1, which includes information security
+software using or performing cryptographic functions with asymmetric
+algorithms. The form and manner of this Apache Software Foundation
+distribution makes it eligible for export under the License Exception
+ENC Technology Software Unrestricted (TSU) exception (see the BIS
+Export Administration Regulations, Section 740.13) for both object
+code and source code.
+
+The following provides more details on the included software that
+may be subject to export controls on cryptographic software:
+
+ The Apache ManifoldCF Plugin for Elastic Search does not include any
+ implementation or usage of cryptographic software at this time.
+
+Contact
+-------
+
+ o For general information visit the main project site at
+ http://manifoldcf.apache.org
+
diff --git a/pom.xml b/pom.xml
new file mode 100644
index 0000000..2b84d87
--- /dev/null
+++ b/pom.xml
@@ -0,0 +1,295 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<!--
+ Licensed to the Apache Software Foundation (ASF) under one or more
+ contributor license agreements. See the NOTICE file distributed with
+ this work for additional information regarding copyright ownership.
+ The ASF licenses this file to You under the Apache License, Version 2.0
+ (the "License"); you may not use this file except in compliance with
+ the License. You may obtain a copy of the License at
+
+ http://www.apache.org/licenses/LICENSE-2.0
+
+ Unless required by applicable law or agreed to in writing, software
+ distributed under the License is distributed on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ See the License for the specific language governing permissions and
+ limitations under the License.
+-->
+
+<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
+
+ <parent>
+ <groupId>org.apache</groupId>
+ <artifactId>apache</artifactId>
+ <version>9</version>
+ <relativePath />
+ </parent>
+
+
+ <modelVersion>4.0.0</modelVersion>
+ <groupId>org.apache.manifoldcf.elasticsearch</groupId>
+
+ <name>ManifoldCF ElasticSearch Plugin</name>
+ <artifactId>elasticsearch-plugin-mcf</artifactId>
+ <version>3.0</version>
+ <packaging>jar</packaging>
+ <description>ManifoldCF Plugin for ElasticSearch</description>
+ <inceptionYear>2015</inceptionYear>
+
+ <organization>
+ <name>The Apache Software Foundation</name>
+ <url>http://www.apache.org/</url>
+ </organization>
+
+ <!-- Move these to the parent pom, when I create a parent pom -->
+ <properties>
+ <elasticsearch.version>1.5.2</elasticsearch.version>
+ <junit.version>4.8.2</junit.version>
+ <slf4j.version>1.6.6</slf4j.version>
+ <log4j.version>1.2.16</log4j.version>
+ <httpcomponent.version>4.4.1</httpcomponent.version>
+ <jetty.version>9.2.10.v20150310</jetty.version>
+ <hamcrest.version>1.3</hamcrest.version>
+ <testng.version>6.8</testng.version>
+ </properties>
+
+ <dependencies>
+ <dependency>
+ <groupId>org.elasticsearch</groupId>
+ <artifactId>elasticsearch</artifactId>
+ <version>${elasticsearch.version}</version>
+ <scope>provided</scope>
+ </dependency>
+
+ <dependency>
+ <groupId>org.apache.httpcomponents</groupId>
+ <artifactId>httpclient</artifactId>
+ <version>${httpcomponent.version}</version>
+ </dependency>
+
+ <dependency>
+ <groupId>com.fasterxml.jackson.core</groupId>
+ <artifactId>jackson-databind</artifactId>
+ <version>2.5.3</version>
+ </dependency>
+
+ <dependency>
+ <groupId>log4j</groupId>
+ <artifactId>log4j</artifactId>
+ <version>${log4j.version}</version>
+ <scope>provided</scope>
+ </dependency>
+
+ <dependency>
+ <groupId>org.slf4j</groupId>
+ <artifactId>slf4j-api</artifactId>
+ <version>${slf4j.version}</version>
+ <scope>provided</scope>
+ </dependency>
+
+ <dependency>
+ <groupId>junit</groupId>
+ <artifactId>junit-dep</artifactId>
+ <version>${junit.version}</version>
+ <scope>test</scope>
+ </dependency>
+
+ <dependency>
+ <groupId>org.eclipse.jetty</groupId>
+ <artifactId>jetty-server</artifactId>
+ <version>${jetty.version}</version>
+ <scope>test</scope>
+ </dependency>
+
+ <dependency>
+ <groupId>org.eclipse.jetty</groupId>
+ <artifactId>jetty-servlet</artifactId>
+ <version>${jetty.version}</version>
+ <scope>test</scope>
+ </dependency>
+
+ <dependency>
+ <groupId>org.hamcrest</groupId>
+ <artifactId>hamcrest-core</artifactId>
+ <version>${hamcrest.version}</version>
+ <scope>test</scope>
+ </dependency>
+
+ <dependency>
+ <groupId>org.hamcrest</groupId>
+ <artifactId>hamcrest-library</artifactId>
+ <version>${hamcrest.version}</version>
+ <scope>test</scope>
+ </dependency>
+
+ <dependency>
+ <groupId>org.hamcrest</groupId>
+ <artifactId>hamcrest-integration</artifactId>
+ <version>${hamcrest.version}</version>
+ <scope>test</scope>
+ </dependency>
+
+ <dependency>
+ <groupId>org.testng</groupId>
+ <artifactId>testng</artifactId>
+ <version>${testng.version}</version>
+ <scope>test</scope>
+ <exclusions>
+ <exclusion>
+ <groupId>org.hamcrest</groupId>
+ <artifactId>hamcrest-core</artifactId>
+ </exclusion>
+ <exclusion>
+ <groupId>org.hamcrest</groupId>
+ <artifactId>hamcrest-library</artifactId>
+ </exclusion>
+ <exclusion>
+ <groupId>org.hamcrest</groupId>
+ <artifactId>hamcrest-integration</artifactId>
+ </exclusion>
+ <exclusion>
+ <groupId>junit</groupId>
+ <artifactId>junit</artifactId>
+ </exclusion>
+ </exclusions>
+ </dependency>
+
+ </dependencies>
+
+ <build>
+ <plugins>
+
+ <plugin>
+ <groupId>org.apache.maven.plugins</groupId>
+ <artifactId>maven-surefire-plugin</artifactId>
+ <configuration>
+ <argLine>-Xmx1024m</argLine>
+ </configuration>
+ </plugin>
+
+ <plugin>
+ <groupId>org.apache.maven.plugins</groupId>
+ <artifactId>maven-compiler-plugin</artifactId>
+ <version>2.3.2</version>
+ <configuration>
+ <source>1.6</source>
+ <target>1.6</target>
+ </configuration>
+ </plugin>
+
+ <plugin>
+ <artifactId>maven-jar-plugin</artifactId>
+ <configuration>
+ <archive>
+ <manifest>
+ <addClasspath>true</addClasspath>
+ <mainClass>fully.qualified.MainClass</mainClass>
+ </manifest>
+ <manifestEntries>
+ <Specification-Title>${project.name}</Specification-Title>
+ <Specification-Version>${project.version}</Specification-Version>
+ <Specification-Vendor>The Apache Software Foundation</Specification-Vendor>
+ <Implementation-Title>${project.name}</Implementation-Title>
+ <Implementation-Version>${project.version}</Implementation-Version>
+ <Implementation-Vendor>The Apache Software Foundation</Implementation-Vendor>
+ <Implementation-Vendor-Id>org.apache</Implementation-Vendor-Id>
+ <url>${project.url}</url>
+ </manifestEntries>
+ </archive>
+ </configuration>
+ </plugin>
+
+ <plugin>
+ <artifactId>maven-source-plugin</artifactId>
+ <executions>
+ <execution>
+ <id>attach-sources</id>
+ <goals>
+ <goal>jar</goal>
+ </goals>
+ </execution>
+ </executions>
+ <configuration>
+ <archive>
+ <!-- Ensure source jars have full manifest entries (note: defaults aren't suitable) -->
+ <manifestEntries>
+ <Specification-Title>${project.name}</Specification-Title>
+ <Specification-Version>${project.version}</Specification-Version>
+ <Specification-Vendor>The Apache Software Foundation</Specification-Vendor>
+ <Implementation-Title>${project.name}</Implementation-Title>
+ <Implementation-Version>${project.version}</Implementation-Version>
+ <Implementation-Vendor>The Apache Software Foundation</Implementation-Vendor>
+ <Implementation-Vendor-Id>org.apache</Implementation-Vendor-Id>
+ </manifestEntries>
+ </archive>
+ </configuration>
+ </plugin>
+
+ <plugin>
+ <artifactId>maven-assembly-plugin</artifactId>
+ <configuration>
+ <descriptors>
+ <descriptor>src/main/assembly/bin.xml</descriptor>
+ <descriptor>src/main/assembly/src.xml</descriptor>
+ </descriptors>
+ <descriptorRefs>
+ <descriptorRef>jar-with-dependencies</descriptorRef>
+ </descriptorRefs>
+ <tarLongFileMode>gnu</tarLongFileMode>
+ </configuration>
+ <executions>
+ <execution>
+ <id>make-my-jar-with-dependencies</id>
+ <phase>package</phase>
+ <goals>
+ <goal>single</goal>
+ </goals>
+ </execution>
+ </executions>
+ </plugin>
+
+ <plugin>
+ <artifactId>maven-antrun-plugin</artifactId>
+ <inherited>false</inherited>
+ <configuration>
+ <tasks>
+ <ant antfile="src/main/assembly/build.xml">
+ <property name="target" value="${project.build.directory}" />
+ <property name="package.name" value="${project.artifactId}-${project.version}-bin" />
+ </ant>
+ <ant antfile="src/main/assembly/build.xml">
+ <property name="target" value="${project.build.directory}" />
+ <property name="package.name" value="${project.artifactId}-${project.version}-src" />
+ </ant>
+ </tasks>
+ </configuration>
+ </plugin>
+
+ <plugin>
+ <artifactId>maven-resources-plugin</artifactId>
+ <version>2.5</version>
+ <configuration>
+ <encoding>UTF-8</encoding>
+ </configuration>
+ </plugin>
+
+ <plugin>
+ <artifactId>maven-clean-plugin</artifactId>
+ <version>2.4.1</version>
+ </plugin>
+
+ </plugins>
+
+ <resources>
+ <resource>
+ <directory>src/main/resources</directory>
+ <filtering>true</filtering>
+ <includes>
+ <include>**/*.properties</include>
+ </includes>
+ </resource>
+ </resources>
+
+ </build>
+
+</project>
\ No newline at end of file
diff --git a/src/main/assembly/bin.xml b/src/main/assembly/bin.xml
new file mode 100644
index 0000000..98b36ed
--- /dev/null
+++ b/src/main/assembly/bin.xml
@@ -0,0 +1,65 @@
+<!--
+ $HeadURL: http://svn.apache.org/repos/asf/httpcomponents/httpclient/trunk/src/main/assembly/bin-unix.xml $
+ $Revision: 687166 $
+ $Date: 2008-08-19 23:40:27 +0200 (Tue, 19 Aug 2008) $
+
+ ====================================================================
+ Licensed to the Apache Software Foundation (ASF) under one
+ or more contributor license agreements. See the NOTICE file
+ distributed with this work for additional information
+ regarding copyright ownership. The ASF licenses this file
+ to you under the Apache License, Version 2.0 (the
+ "License"); you may not use this file except in compliance
+ with the License. You may obtain a copy of the License at
+
+ http://www.apache.org/licenses/LICENSE-2.0
+
+ Unless required by applicable law or agreed to in writing,
+ software distributed under the License is distributed on an
+ "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ KIND, either express or implied. See the License for the
+ specific language governing permissions and limitations
+ under the License.
+ ====================================================================
+
+ This software consists of voluntary contributions made by many
+ individuals on behalf of the Apache Software Foundation. For more
+ information on the Apache Software Foundation, please see
+ <http://www.apache.org/>.
+ -->
+<assembly>
+ <id>bin</id>
+ <formats>
+ <format>tar.gz</format>
+ <format>zip</format>
+ </formats>
+ <moduleSets>
+ <moduleSet>
+ <binaries>
+ <outputDirectory>lib</outputDirectory>
+ <unpack>false</unpack>
+ <dependencySets>
+ <dependencySet>
+ <excludes>
+ <exclude>org.slf4j:*</exclude>
+ </excludes>
+ </dependencySet>
+ </dependencySets>
+ </binaries>
+ </moduleSet>
+ </moduleSets>
+ <fileSets>
+ <fileSet>
+ <directory></directory>
+ <outputDirectory></outputDirectory>
+ <includes>
+ <include>**/target/*.jar</include>
+ <include>README.txt</include>
+ <include>LICENSE.txt</include>
+ <include>NOTICE.txt</include>
+ <include>CHANGES.txt</include>
+ <include>DEPENDENCIES.txt</include>
+ </includes>
+ </fileSet>
+ </fileSets>
+</assembly>
diff --git a/src/main/assembly/build.xml b/src/main/assembly/build.xml
new file mode 100644
index 0000000..216625b
--- /dev/null
+++ b/src/main/assembly/build.xml
@@ -0,0 +1,65 @@
+<!--
+ Licensed to the Apache Software Foundation (ASF) under one
+ or more contributor license agreements. See the NOTICE file
+ distributed with this work for additional information
+ regarding copyright ownership. The ASF licenses this file
+ to you under the Apache License, Version 2.0 (the
+ "License"); you may not use this file except in compliance
+ with the License. You may obtain a copy of the License at
+
+ http://www.apache.org/licenses/LICENSE-2.0
+
+ Unless required by applicable law or agreed to in writing,
+ software distributed under the License is distributed on an
+ "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ KIND, either express or implied. See the License for the
+ specific language governing permissions and limitations
+ under the License.
+ ====================================================================
+
+ This software consists of voluntary contributions made by many
+ individuals on behalf of the Apache Software Foundation. For more
+ information on the Apache Software Foundation, please see
+ <http://www.apache.org />.
+ -->
+<project name="assembly-postprocess" default="fixarchives" basedir=".">
+
+ <target name="fixarchives" depends="_eolcheck,fixzip,fixtgz">
+ </target>
+
+ <target name="fixzip" unless="native.crlf">
+ <property name="tmp.dir" location="${target}/tmp"/>
+ <property name="zip.file" location="${target}/${package.name}.zip"/>
+ <delete dir="${tmp.dir}" />
+ <unzip src="${zip.file}" dest="${tmp.dir}"/>
+ <fixcrlf srcdir="${tmp.dir}" eol="crlf" eof="remove" fixlast="false"
+ includes="**/*.txt, **/*.xml, **/*.properties, **/*.java, **/*.html, **/*.css, **/*.apt, **/*.py, **/*.svg, **/*.xsl" />
+ <zip destfile="${zip.file}" basedir="${tmp.dir}" duplicate="preserve" />
+ <delete dir="${tmp.dir}" />
+ </target>
+
+ <target name="fixtgz" unless="native.lf">
+ <property name="tmp.dir" location="${target}/tmp"/>
+ <property name="gz.file" location="${target}/${package.name}.tar.gz"/>
+ <property name="tar.file" location="${target}/${package.name}.tar"/>
+ <delete dir="${tmp.dir}" />
+ <gunzip src="${gz.file}" dest="${tar.file}"/>
+ <untar src="${tar.file}" dest="${tmp.dir}"/>
+ <fixcrlf srcdir="${tmp.dir}" eol="lf" eof="remove" fixlast="false"
+ includes="**/*.txt, **/*.xml, **/*.properties, **/*.java, **/*.html, **/*.css, **/*.apt, **/*.py, **/*.svg, **/*.xsl" />
+ <tar destfile="${tar.file}" basedir="${tmp.dir}" longfile="gnu"/>
+ <gzip src="${tar.file}" destfile="${gz.file}"/>
+ <delete file="${tar.file}"/>
+ <delete dir="${tmp.dir}"/>
+ </target>
+
+ <!-- Determine if the native format is CRLF or LF (or neither) -->
+ <target name="_eolcheck">
+ <condition property="native.lf">
+ <os family="unix"/>
+ </condition>
+ <condition property="native.crlf">
+ <os family="dos"/>
+ </condition>
+ </target>
+</project>
diff --git a/src/main/assembly/src.xml b/src/main/assembly/src.xml
new file mode 100644
index 0000000..c6c11c8
--- /dev/null
+++ b/src/main/assembly/src.xml
@@ -0,0 +1,46 @@
+<!--
+ ====================================================================
+ Licensed to the Apache Software Foundation (ASF) under one
+ or more contributor license agreements. See the NOTICE file
+ distributed with this work for additional information
+ regarding copyright ownership. The ASF licenses this file
+ to you under the Apache License, Version 2.0 (the
+ "License"); you may not use this file except in compliance
+ with the License. You may obtain a copy of the License at
+
+ http://www.apache.org/licenses/LICENSE-2.0
+
+ Unless required by applicable law or agreed to in writing,
+ software distributed under the License is distributed on an
+ "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ KIND, either express or implied. See the License for the
+ specific language governing permissions and limitations
+ under the License.
+ ====================================================================
+
+ This software consists of voluntary contributions made by many
+ individuals on behalf of the Apache Software Foundation. For more
+ information on the Apache Software Foundation, please see
+ <http://www.apache.org/>.
+ -->
+<assembly>
+ <id>src</id>
+ <formats>
+ <format>tar.gz</format>
+ <format>zip</format>
+ </formats>
+ <fileSets>
+ <!-- Release materials -->
+ <fileSet>
+ <directory></directory>
+ <outputDirectory></outputDirectory>
+ <excludes>
+ <exclude>**/.*</exclude>
+ <exclude>**/.*/**</exclude>
+ <exclude>**/target/**</exclude>
+ <exclude>**/lib/**</exclude>
+ <exclude>**/data/**</exclude>
+ </excludes>
+ </fileSet>
+ </fileSets>
+</assembly>
diff --git a/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerException.java b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerException.java
new file mode 100644
index 0000000..dc06718
--- /dev/null
+++ b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerException.java
@@ -0,0 +1,39 @@
+/* $Id: AuthorizerException.java 1454684 2013-03-09 11:02:31Z kwright $ */
+/* Modified to MCFAuthorizerException.java 2015-04-28 Bart Superson */
+/**
+* Licensed to the Apache Software Foundation (ASF) under one or more
+* contributor license agreements. See the NOTICE file distributed with
+* this work for additional information regarding copyright ownership.
+* The ASF licenses this file to You under the Apache License, Version 2.0
+* (the "License"); you may not use this file except in compliance with
+* the License. You may obtain a copy of the License at
+*
+* http://www.apache.org/licenses/LICENSE-2.0
+*
+* Unless required by applicable law or agreed to in writing, software
+* distributed under the License is distributed on an "AS IS" BASIS,
+* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+* See the License for the specific language governing permissions and
+* limitations under the License.
+*/
+package org.apache.manifoldcf.elasticsearch;
+
+import org.elasticsearch.ElasticsearchException;
+
+/** This class represents exceptions for authorizing ElasticSearch requests
+* to include security. It is a singleton class whose main public method
+* is thread-safe.
+*/
+public class MCFAuthorizerException extends ElasticsearchException
+{
+ /** Constructor */
+ public MCFAuthorizerException(String message)
+ {
+ super(message);
+ }
+
+ public MCFAuthorizerException(String message, Throwable cause)
+ {
+ super(message,cause);
+ }
+}
diff --git a/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerPlugin.java b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerPlugin.java
new file mode 100644
index 0000000..51e5cde
--- /dev/null
+++ b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerPlugin.java
@@ -0,0 +1,53 @@
+/* $Id: MCFAuthorizer.java 1571011 2014-02-23 13:46:13Z kwright $ */
+/* Modified to MCFAuthorizerPlugin.java 2015-04-28 Bart Superson */
+/**
+* Licensed to the Apache Software Foundation (ASF) under one or more
+* contributor license agreements. See the NOTICE file distributed with
+* this work for additional information regarding copyright ownership.
+* The ASF licenses this file to You under the Apache License, Version 2.0
+* (the "License"); you may not use this file except in compliance with
+* the License. You may obtain a copy of the License at
+*
+* http://www.apache.org/licenses/LICENSE-2.0
+*
+* Unless required by applicable law or agreed to in writing, software
+* distributed under the License is distributed on an "AS IS" BASIS,
+* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+* See the License for the specific language governing permissions and
+* limitations under the License.
+*/
+package org.apache.manifoldcf.elasticsearch;
+
+import org.elasticsearch.common.inject.Module;
+import org.elasticsearch.common.logging.ESLogger;
+import org.elasticsearch.common.logging.Loggers;
+
+import org.elasticsearch.plugins.AbstractPlugin;
+import org.elasticsearch.rest.RestModule;
+
+public class MCFAuthorizerPlugin extends AbstractPlugin
+{
+
+ private final ESLogger log = Loggers.getLogger(this.getClass());
+
+ public MCFAuthorizerPlugin() {
+ log.info("Starting ManifoldCF Authorizer Plugin");
+ }
+
+ @Override
+ public String name() {
+ return "elasticsearch-plugin-mcf";
+ }
+
+ @Override
+ public String description() {
+ return "Plugin to connect elasticsearch with ManifoldCF";
+ }
+
+ @Override
+ public void processModule(Module module) {
+ if (module instanceof RestModule) {
+ ((RestModule) module).addRestAction(MCFAuthorizerRestSearchAction.class);
+ }
+ }
+}
diff --git a/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerRestSearchAction.java b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerRestSearchAction.java
new file mode 100644
index 0000000..5feaf31
--- /dev/null
+++ b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerRestSearchAction.java
@@ -0,0 +1,52 @@
+/* $Id: MCFAuthorizer.java 1571011 2014-02-23 13:46:13Z kwright $ */
+/* Modified to MCFAuthorizerRestSearchAction.java 2015-04-28 Bart Superson */
+/**
+* Licensed to the Apache Software Foundation (ASF) under one or more
+* contributor license agreements. See the NOTICE file distributed with
+* this work for additional information regarding copyright ownership.
+* The ASF licenses this file to You under the Apache License, Version 2.0
+* (the "License"); you may not use this file except in compliance with
+* the License. You may obtain a copy of the License at
+*
+* http://www.apache.org/licenses/LICENSE-2.0
+*
+* Unless required by applicable law or agreed to in writing, software
+* distributed under the License is distributed on an "AS IS" BASIS,
+* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+* See the License for the specific language governing permissions and
+* limitations under the License.
+*/
+package org.apache.manifoldcf.elasticsearch;
+
+import org.elasticsearch.action.search.SearchRequest;
+import org.elasticsearch.client.Client;
+import org.elasticsearch.common.inject.Inject;
+import org.elasticsearch.common.settings.Settings;
+import org.elasticsearch.rest.*;
+import org.elasticsearch.rest.action.search.RestSearchAction;
+import org.elasticsearch.rest.action.support.RestStatusToXContentListener;
+
+ /*
+ New parseSearchRequestMCF function added in utils to parse RestRequest.
+ There are also problems with security using JavaSearchAPI, because it doesn't implements setParam function
+ to set username param, but this can be ommited using JavaScriptAPI, which allows to do that.
+ Security filter can be also applied in this class but there is a problem with proper extraSource parsing.
+ There is also a possibility to create service, inject RestController into it, register RestFilter in it, which
+ should be used only if request handled by RestSearchAction and replace query from this request with
+ the same query wrapped by security filter.
+ */
+
+public class MCFAuthorizerRestSearchAction extends RestSearchAction {
+
+ @Inject
+ public MCFAuthorizerRestSearchAction(Settings settings, final RestController restController, Client client) {
+ super(settings,restController,client);
+ }
+
+ @Override
+ public void handleRequest(RestRequest request, RestChannel channel, Client client) {
+ SearchRequest searchRequest = MCFAuthorizerUtils.parseSearchRequestMCF(request);
+ searchRequest.listenerThreaded(false);
+ client.search(searchRequest, new RestStatusToXContentListener(channel));
+ }
+}
diff --git a/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerUtils.java b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerUtils.java
new file mode 100644
index 0000000..b85695a
--- /dev/null
+++ b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerUtils.java
@@ -0,0 +1,584 @@
+/* $Id: MCFAuthorizer.java 1571011 2014-02-23 13:46:13Z kwright $ */
+/* Modified to MCFAuthorizerUtils.java 2015-04-28 Bart Superson */
+/**
+* Licensed to the Apache Software Foundation (ASF) under one or more
+* contributor license agreements. See the NOTICE file distributed with
+* this work for additional information regarding copyright ownership.
+* The ASF licenses this file to You under the Apache License, Version 2.0
+* (the "License"); you may not use this file except in compliance with
+* the License. You may obtain a copy of the License at
+*
+* http://www.apache.org/licenses/LICENSE-2.0
+*
+* Unless required by applicable law or agreed to in writing, software
+* distributed under the License is distributed on an "AS IS" BASIS,
+* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+* See the License for the specific language governing permissions and
+* limitations under the License.
+*/
+package org.apache.manifoldcf.elasticsearch;
+
+import com.fasterxml.jackson.databind.JsonNode;
+import com.fasterxml.jackson.databind.ObjectMapper;
+import com.fasterxml.jackson.databind.node.ObjectNode;
+import org.apache.http.HttpResponse;
+import org.apache.http.client.methods.HttpGet;
+import org.apache.http.entity.ContentType;
+import org.apache.http.impl.client.CloseableHttpClient;
+import org.apache.http.impl.client.HttpClients;
+import org.apache.http.util.EntityUtils;
+import org.elasticsearch.ElasticsearchIllegalArgumentException;
+import org.elasticsearch.action.search.SearchRequest;
+import org.elasticsearch.action.support.IndicesOptions;
+import org.elasticsearch.common.Strings;
+import org.elasticsearch.common.logging.ESLogger;
+import org.elasticsearch.common.logging.Loggers;
+import org.elasticsearch.common.unit.TimeValue;
+import org.elasticsearch.index.query.*;
+import org.elasticsearch.rest.RestRequest;
+import org.elasticsearch.rest.action.search.RestSearchAction;
+import org.elasticsearch.rest.action.support.RestActions;
+import org.elasticsearch.search.Scroll;
+import org.elasticsearch.search.builder.SearchSourceBuilder;
+import org.elasticsearch.search.fetch.source.FetchSourceContext;
+import org.elasticsearch.search.sort.SortOrder;
+import org.elasticsearch.search.suggest.SuggestBuilders;
+import org.elasticsearch.search.suggest.term.TermSuggestionBuilder;
+
+import java.io.*;
+import java.net.URLEncoder;
+import java.util.ArrayList;
+import java.util.HashMap;
+import java.util.List;
+import java.util.Map;
+
+public class MCFAuthorizerUtils {
+
+ protected static String ALLOW_FIELD_PREFIX = "allow_token_";
+ protected static String DENY_FIELD_PREFIX = "deny_token_";
+
+ protected final static String AUTHORITY_BASE_URL = "http://localhost:8345/mcf-authority-service";
+ protected final static String FIELD_ALLOW_DOCUMENT = ALLOW_FIELD_PREFIX +"document";
+ protected final static String FIELD_DENY_DOCUMENT = DENY_FIELD_PREFIX +"document";
+ protected final static String FIELD_ALLOW_PARENT = ALLOW_FIELD_PREFIX +"share";
+ protected final static String FIELD_DENY_PARENT = DENY_FIELD_PREFIX +"share";
+ protected final static String FIELD_ALLOW_SHARE = ALLOW_FIELD_PREFIX +"parent";
+ protected final static String FIELD_DENY_SHARE = DENY_FIELD_PREFIX +"parent";
+
+ /** Special token for null security fields */
+ protected static final String NOSECURITY_TOKEN = "__nosecurity__";
+
+ private final static CloseableHttpClient httpClient = HttpClients.createDefault();
+
+ private static final ESLogger log = Loggers.getLogger("MCFAuthorizer");
+
+ public static SearchRequest parseSearchRequestMCF(RestRequest request) throws MCFAuthorizerException {
+ SearchRequest searchRequest;
+ //if(usernameAndDomain[0]==null) throw new MCFAuthorizerException("Username not passed.");
+ if(request.param("u")!=null) {
+ String[] authenticatedUserNamesAndDomains = request.param("u").split(",");
+ String[] indices = Strings.splitStringByCommaToArray(request.param("index"));
+ searchRequest = new SearchRequest(indices);
+ boolean isTemplateRequest = request.path().endsWith("/template");
+
+ if(request.hasContent() || request.hasParam("source")) {
+ FilterBuilder authorizationFilter = buildAuthorizationFilter(authenticatedUserNamesAndDomains);
+ FilteredQueryBuilder filteredQueryBuilder;
+
+ ObjectMapper objectMapper = new ObjectMapper();
+ ObjectNode modifiedJSON, innerJSON;
+ JsonNode requestJSON;
+
+ try {
+ requestJSON = objectMapper.readTree(RestActions.getRestContent(request).toBytes());
+ if (isTemplateRequest) {
+ modifiedJSON = (ObjectNode) requestJSON;
+ innerJSON = (ObjectNode)requestJSON.findValue("template");
+ filteredQueryBuilder = QueryBuilders.filteredQuery(QueryBuilders.wrapperQuery(innerJSON.findValue("query").toString()), authorizationFilter);
+ modifiedJSON.replace("template",innerJSON.set("query", objectMapper.readTree(filteredQueryBuilder.buildAsBytes().toBytes())));
+ searchRequest.templateSource(modifiedJSON.toString());
+ } else {
+ filteredQueryBuilder = QueryBuilders.filteredQuery(QueryBuilders.wrapperQuery(requestJSON.findValue("query").toString()), authorizationFilter);
+ modifiedJSON = (ObjectNode) requestJSON;
+ modifiedJSON.set("query", objectMapper.readTree(filteredQueryBuilder.buildAsBytes().toBytes()));
+ searchRequest.source(modifiedJSON.toString());
+ }
+ } catch (IOException e) {
+ e.printStackTrace();
+ throw new MCFAuthorizerException("JSON parser error");
+ }
+ }
+
+ searchRequest.extraSource(parseSearchSourceMCF(request));
+ searchRequest.searchType(request.param("search_type"));
+ searchRequest.queryCache(request.paramAsBoolean("query_cache", (Boolean)null));
+ String scroll = request.param("scroll");
+ if(scroll != null) {
+ searchRequest.scroll(new Scroll(TimeValue.parseTimeValue(scroll, (TimeValue)null)));
+ }
+
+ searchRequest.types(Strings.splitStringByCommaToArray(request.param("type")));
+ searchRequest.routing(request.param("routing"));
+ searchRequest.preference(request.param("preference"));
+ searchRequest.indicesOptions(IndicesOptions.fromRequest(request, searchRequest.indicesOptions()));
+ }
+ else {
+ searchRequest = RestSearchAction.parseSearchRequest(request);
+ }
+ return searchRequest;
+ }
+
+ public static SearchSourceBuilder parseSearchSourceMCF(RestRequest request) throws MCFAuthorizerException {
+ SearchSourceBuilder searchSourceBuilder = null;
+ String queryString = request.param("q");
+ if(queryString != null) {
+ String[] authenticatedUserNamesAndDomains = request.param("u").split(",");
+ FilterBuilder authorizationFilter = buildAuthorizationFilter(authenticatedUserNamesAndDomains);
+ QueryStringQueryBuilder from = QueryBuilders.queryStringQuery(queryString);
+ from.defaultField(request.param("df"));
+ from.analyzer(request.param("analyzer"));
+ from.analyzeWildcard(request.paramAsBoolean("analyze_wildcard", false));
+ from.lowercaseExpandedTerms(request.paramAsBoolean("lowercase_expanded_terms", true));
+ from.lenient(request.paramAsBoolean("lenient", (Boolean)null));
+ String size = request.param("default_operator");
+ if(size != null) {
+ if("OR".equals(size)) {
+ from.defaultOperator(QueryStringQueryBuilder.Operator.OR);
+ } else {
+ if(!"AND".equals(size)) {
+ throw new ElasticsearchIllegalArgumentException("Unsupported defaultOperator [" + size + "], can either be [OR] or [AND]");
+ }
+
+ from.defaultOperator(QueryStringQueryBuilder.Operator.AND);
+ }
+ }
+
+ if(searchSourceBuilder == null) {
+ searchSourceBuilder = new SearchSourceBuilder();
+ }
+
+ searchSourceBuilder.query(QueryBuilders.filteredQuery(from, authorizationFilter));
+ }
+ else {
+ if(!(request.hasContent() || request.hasParam("source"))){
+ if(searchSourceBuilder == null) {
+ searchSourceBuilder = new SearchSourceBuilder();
+ }
+ FilterBuilder authorizationFilter = buildAuthorizationFilter(request.param("u"));
+ searchSourceBuilder.query(QueryBuilders.filteredQuery(QueryBuilders.matchAllQuery(),authorizationFilter));
+ }
+ }
+
+ int var19 = request.paramAsInt("from", -1);
+ if(var19 != -1) {
+ if(searchSourceBuilder == null) {
+ searchSourceBuilder = new SearchSourceBuilder();
+ }
+
+ searchSourceBuilder.from(var19);
+ }
+
+ int var20 = request.paramAsInt("size", -1);
+ if(var20 != -1) {
+ if(searchSourceBuilder == null) {
+ searchSourceBuilder = new SearchSourceBuilder();
+ }
+
+ searchSourceBuilder.size(var20);
+ }
+
+ if(request.hasParam("explain")) {
+ if(searchSourceBuilder == null) {
+ searchSourceBuilder = new SearchSourceBuilder();
+ }
+
+ searchSourceBuilder.explain(request.paramAsBoolean("explain", (Boolean)null));
+ }
+
+ if(request.hasParam("version")) {
+ if(searchSourceBuilder == null) {
+ searchSourceBuilder = new SearchSourceBuilder();
+ }
+
+ searchSourceBuilder.version(request.paramAsBoolean("version", (Boolean)null));
+ }
+
+ if(request.hasParam("timeout")) {
+ if(searchSourceBuilder == null) {
+ searchSourceBuilder = new SearchSourceBuilder();
+ }
+
+ searchSourceBuilder.timeout(request.paramAsTime("timeout", (TimeValue)null));
+ }
+
+ if(request.hasParam("terminate_after")) {
+ if(searchSourceBuilder == null) {
+ searchSourceBuilder = new SearchSourceBuilder();
+ }
+
+ int sField = request.paramAsInt("terminate_after", 0);
+ if(sField < 0) {
+ throw new ElasticsearchIllegalArgumentException("terminateAfter must be > 0");
+ }
+
+ if(sField > 0) {
+ searchSourceBuilder.terminateAfter(sField);
+ }
+ }
+
+ String var21 = request.param("fields");
+ String suggestField;
+ if(var21 != null) {
+ if(searchSourceBuilder == null) {
+ searchSourceBuilder = new SearchSourceBuilder();
+ }
+
+ if(!Strings.hasText(var21)) {
+ searchSourceBuilder.noFields();
+ } else {
+ String[] fetchSourceContext = Strings.splitStringByCommaToArray(var21);
+ if(fetchSourceContext != null) {
+ String[] sSorts = fetchSourceContext;
+ int sIndicesBoost = fetchSourceContext.length;
+
+ for(int sStats = 0; sStats < sIndicesBoost; ++sStats) {
+ suggestField = sSorts[sStats];
+ searchSourceBuilder.field(suggestField);
+ }
+ }
+ }
+ }
+
+ FetchSourceContext var22 = FetchSourceContext.parseFromRestRequest(request);
+ if(var22 != null) {
+ if(searchSourceBuilder == null) {
+ searchSourceBuilder = new SearchSourceBuilder();
+ }
+
+ searchSourceBuilder.fetchSource(var22);
+ }
+
+ if(request.hasParam("track_scores")) {
+ if(searchSourceBuilder == null) {
+ searchSourceBuilder = new SearchSourceBuilder();
+ }
+
+ searchSourceBuilder.trackScores(request.paramAsBoolean("track_scores", false));
+ }
+
+ String var23 = request.param("sort");
+ int suggestText;
+ String indexName;
+ String[] var26;
+ if(var23 != null) {
+ if(searchSourceBuilder == null) {
+ searchSourceBuilder = new SearchSourceBuilder();
+ }
+
+ String[] var24 = Strings.splitStringByCommaToArray(var23);
+ var26 = var24;
+ int var27 = var24.length;
+
+ for(suggestText = 0; suggestText < var27; ++suggestText) {
+ String suggestSize = var26[suggestText];
+ int suggestMode = suggestSize.lastIndexOf(":");
+ if(suggestMode != -1) {
+ String divisor = suggestSize.substring(0, suggestMode);
+ indexName = suggestSize.substring(suggestMode + 1);
+ if("asc".equals(indexName)) {
+ searchSourceBuilder.sort(divisor, SortOrder.ASC);
+ } else if("desc".equals(indexName)) {
+ searchSourceBuilder.sort(divisor, SortOrder.DESC);
+ }
+ } else {
+ searchSourceBuilder.sort(suggestSize);
+ }
+ }
+ }
+
+ String var25 = request.param("indices_boost");
+ int var31;
+ String var32;
+ if(var25 != null) {
+ if(searchSourceBuilder == null) {
+ searchSourceBuilder = new SearchSourceBuilder();
+ }
+
+ var26 = Strings.splitStringByCommaToArray(var25);
+ String[] var29 = var26;
+ suggestText = var26.length;
+
+ for(var31 = 0; var31 < suggestText; ++var31) {
+ var32 = var29[var31];
+ int var33 = var32.indexOf(44);
+ if(var33 == -1) {
+ throw new ElasticsearchIllegalArgumentException("Illegal index boost [" + var32 + "], no \',\'");
+ }
+
+ indexName = var32.substring(0, var33);
+ String sBoost = var32.substring(var33 + 1);
+
+ try {
+ searchSourceBuilder.indexBoost(indexName, Float.parseFloat(sBoost));
+ } catch (NumberFormatException var18) {
+ throw new ElasticsearchIllegalArgumentException("Illegal index boost [" + var32 + "], boost not a float number");
+ }
+ }
+ }
+
+ String var28 = request.param("stats");
+ if(var28 != null) {
+ if(searchSourceBuilder == null) {
+ searchSourceBuilder = new SearchSourceBuilder();
+ }
+
+ searchSourceBuilder.stats(Strings.splitStringByCommaToArray(var28));
+ }
+
+ suggestField = request.param("suggest_field");
+ if(suggestField != null) {
+ String var30 = request.param("suggest_text", queryString);
+ var31 = request.paramAsInt("suggest_size", 5);
+ if(searchSourceBuilder == null) {
+ searchSourceBuilder = new SearchSourceBuilder();
+ }
+
+ var32 = request.param("suggest_mode");
+ searchSourceBuilder.suggest().addSuggestion(((TermSuggestionBuilder)((TermSuggestionBuilder)((TermSuggestionBuilder)SuggestBuilders.termSuggestion(suggestField).field(suggestField)).text(var30)).size(var31)).suggestMode(var32));
+ }
+
+ return searchSourceBuilder;
+ }
+
+ /** Main method for building a filter representing appropriate security.
+ *@param authenticatedUserNamesAndDomains is a list of user names and its domains in the form "user@domain".
+ *@return the filter builder.
+ */
+ public static FilterBuilder buildAuthorizationFilter(String[] authenticatedUserNamesAndDomains)
+ throws MCFAuthorizerException{
+ Map<String,String> domainMap = new HashMap<String,String>();
+ for(String buffer : authenticatedUserNamesAndDomains){
+ String[] authenticatedUserNameAndDomain = buffer.split("@", 2);
+ String authenticatedUserName = authenticatedUserNameAndDomain[0];
+ String authenticatedUserDomain;
+ if(authenticatedUserNameAndDomain.length<2) authenticatedUserDomain="";
+ else authenticatedUserDomain=authenticatedUserNameAndDomain[1];
+ domainMap.put(authenticatedUserDomain, authenticatedUserName);
+ }
+ return buildAuthorizationFilter(domainMap);
+ }
+
+
+ /** Main method for building a filter representing appropriate security.
+ *@param domainMap is a map from MCF authorization domain name to user name,
+ * and describes a complete user identity.
+ *@return the filter builder.
+ */
+ public static FilterBuilder buildAuthorizationFilter(Map<String,String> domainMap)
+ throws MCFAuthorizerException
+ {
+ if (AUTHORITY_BASE_URL == null)
+ throw new IllegalStateException("Authority base URL required for finding access tokens for a user");
+
+ if (domainMap == null || domainMap.size() == 0)
+ throw new IllegalArgumentException("Cannot find user tokens for null user");
+
+ StringBuilder sb = new StringBuilder("[");
+ boolean first = true;
+ for (String domain : domainMap.keySet())
+ {
+ if (!first)
+ sb.append(",");
+ else
+ first = false;
+ sb.append(domain).append(":").append(domainMap.get(domain));
+ }
+ sb.append("]");
+ log.info("Trying to match docs for user '"+sb.toString()+"'");
+
+ return buildAuthorizationFilter(getAccessTokens(domainMap));
+ }
+
+ /** Main method for building a filter representing appropriate security.
+ *@param authenticatedUserName is a user name in the form "user@domain".
+ *@return the filter builder.
+ */
+ public static FilterBuilder buildAuthorizationFilter(String authenticatedUserName)
+ throws MCFAuthorizerException
+ {
+ return buildAuthorizationFilter(authenticatedUserName, "");
+ }
+
+ /** Main method for building a filter representing appropriate security.
+ *@param authenticatedUserName is a user name in the form "user@domain".
+ *@param authenticatedUserDomain is the corresponding MCF authorization domain.
+ *@return the filter builder.
+ */
+ public static FilterBuilder buildAuthorizationFilter(String authenticatedUserName, String authenticatedUserDomain)
+ throws MCFAuthorizerException
+ {
+ Map<String,String> domainMap = new HashMap<String,String>();
+ domainMap.put(authenticatedUserDomain, authenticatedUserName);
+ return buildAuthorizationFilter(domainMap);
+ }
+
+ /** Main method for building a filter representing appropriate security.
+ *@param userAccessTokens are a set of tokens to use to construct the filter (presumably from mod_authz_annotate, upstream)
+ *@return the wrapped query enforcing ManifoldCF security.
+ */
+ public static FilterBuilder buildAuthorizationFilter(List<String> userAccessTokens)
+ throws MCFAuthorizerException
+ {
+ BoolFilterBuilder bq = new BoolFilterBuilder();
+
+ FilterBuilder allowShareOpen = new TermFilterBuilder(FIELD_ALLOW_SHARE,NOSECURITY_TOKEN);
+ FilterBuilder denyShareOpen = new TermFilterBuilder(FIELD_DENY_SHARE,NOSECURITY_TOKEN);
+ FilterBuilder allowParentOpen = new TermFilterBuilder(FIELD_ALLOW_PARENT,NOSECURITY_TOKEN);
+ FilterBuilder denyParentOpen = new TermFilterBuilder(FIELD_DENY_PARENT,NOSECURITY_TOKEN);
+ FilterBuilder allowDocumentOpen = new TermFilterBuilder(FIELD_ALLOW_DOCUMENT,NOSECURITY_TOKEN);
+ FilterBuilder denyDocumentOpen = new TermFilterBuilder(FIELD_DENY_DOCUMENT,NOSECURITY_TOKEN);
+
+ if (userAccessTokens == null || userAccessTokens.size() == 0)
+ {
+ // Only open documents can be included.
+ // That query is:
+ // (FIELD_ALLOW_SHARE is empty AND FIELD_DENY_SHARE is empty AND FIELD_ALLOW_DOCUMENT is empty AND FIELD_DENY_DOCUMENT is empty)
+ // We're trying to map to: -(FIELD_ALLOW_SHARE:*) , which should be pretty efficient in Solr because it is negated. If this turns out not to be so, then we should
+ // have the SolrConnector inject a special token into these fields when they otherwise would be empty, and we can trivially match on that token.
+ bq.must(allowShareOpen);
+ bq.must(denyShareOpen);
+ bq.must(allowParentOpen);
+ bq.must(denyParentOpen);
+ bq.must(allowDocumentOpen);
+ bq.must(denyDocumentOpen);
+ }
+ else
+ {
+ // Extend the query appropriately for each user access token.
+ bq.must(calculateCompleteSubquery(FIELD_ALLOW_SHARE, FIELD_DENY_SHARE,allowShareOpen,denyShareOpen,userAccessTokens));
+ bq.must(calculateCompleteSubquery(FIELD_ALLOW_DOCUMENT, FIELD_DENY_DOCUMENT,allowDocumentOpen,denyDocumentOpen,userAccessTokens));
+ bq.must(calculateCompleteSubquery(FIELD_ALLOW_PARENT, FIELD_DENY_PARENT,allowParentOpen,denyParentOpen,userAccessTokens));
+ }
+
+ return bq;
+ }
+
+ /** Calculate a complete subclause, representing something like:
+ * ((FIELD_ALLOW_SHARE is empty AND FIELD_DENY_SHARE is empty) OR FIELD_ALLOW_SHARE HAS token1 OR FIELD_ALLOW_SHARE HAS token2 ...)
+ * AND FIELD_DENY_SHARE DOESN'T_HAVE token1 AND FIELD_DENY_SHARE DOESN'T_HAVE token2 ...
+ */
+ private static FilterBuilder calculateCompleteSubquery(String allowField, String denyField, FilterBuilder allowOpen, FilterBuilder denyOpen, List<String> userAccessTokens)
+ {
+ BoolFilterBuilder bq = new BoolFilterBuilder();
+ // No ES equivalent - hope this is done right inside
+ //bq.setMaxClauseCount(1000000);
+
+ // Add the empty-acl case
+ BoolFilterBuilder subUnprotectedClause = new BoolFilterBuilder();
+ subUnprotectedClause.must(allowOpen);
+ subUnprotectedClause.must(denyOpen);
+ bq.should(subUnprotectedClause);
+ for (String accessToken : userAccessTokens)
+ {
+ bq.should(new TermFilterBuilder(allowField,accessToken));
+ bq.mustNot(new TermFilterBuilder(denyField,accessToken));
+ }
+ return bq;
+ }
+
+ /** Get access tokens given a username */
+ protected static List<String> getAccessTokens(Map<String,String> domainMap)
+ throws MCFAuthorizerException
+ {
+ try
+ {
+ StringBuilder urlBuffer = new StringBuilder(AUTHORITY_BASE_URL);
+ urlBuffer.append("/UserACLs");
+ int i = 0;
+ for (String domain : domainMap.keySet())
+ {
+ if (i == 0)
+ urlBuffer.append("?");
+ else
+ urlBuffer.append("&");
+ // For backwards compatibility, handle the singleton case specially
+ if (domainMap.size() == 1 && domain.length() == 0)
+ {
+ urlBuffer.append("username=").append(URLEncoder.encode(domainMap.get(domain),"utf-8"));
+ }
+ else
+ {
+ urlBuffer.append("username_").append(Integer.toString(i)).append("=").append(URLEncoder.encode(domainMap.get(domain),"utf-8")).append("&")
+ .append("domain_").append(Integer.toString(i)).append("=").append(URLEncoder.encode(domain,"utf-8"));
+ }
+ i++;
+ }
+ String theURL = urlBuffer.toString();
+ HttpGet method = new HttpGet(theURL);
+ try
+ {
+ HttpResponse httpResponse = httpClient.execute(method);
+ int rval = httpResponse.getStatusLine().getStatusCode();
+ if (rval != 200)
+ {
+ String response = EntityUtils.toString(httpResponse.getEntity(),"utf-8");
+ throw new MCFAuthorizerException("Couldn't fetch user's access tokens from ManifoldCF authority service: "+Integer.toString(rval)+"; "+response);
+ }
+ InputStream is = httpResponse.getEntity().getContent();
+ try
+ {
+ String charSet = ContentType.getOrDefault(httpResponse.getEntity()).getCharset().toString();
+ if (charSet == null)
+ charSet = "utf-8";
+ Reader r = new InputStreamReader(is,charSet);
+ try
+ {
+ BufferedReader br = new BufferedReader(r);
+ try
+ {
+ // Read the tokens, one line at a time. If any authorities are down, we have no current way to note that, but someday we will.
+ List<String> tokenList = new ArrayList<String>();
+ while (true)
+ {
+ String line = br.readLine();
+ if (line == null)
+ break;
+ if (line.startsWith("TOKEN:"))
+ {
+ tokenList.add(line.substring("TOKEN:".length()));
+ log.info(line);
+ }
+ else {
+ // It probably says something about the state of the authority(s) involved, so log it
+ log.info("Saw authority response "+line);
+ }
+ }
+ return tokenList;
+ }
+ finally
+ {
+ br.close();
+ }
+ }
+ finally
+ {
+ r.close();
+ }
+ }
+ finally
+ {
+ is.close();
+ }
+ }
+ finally
+ {
+ method.abort();
+ }
+ }
+ catch (IOException e)
+ {
+ throw new MCFAuthorizerException("IO exception: "+e.getMessage(),e);
+ }
+ }
+
+}
diff --git a/src/main/resources/es-plugin.properties b/src/main/resources/es-plugin.properties
new file mode 100644
index 0000000..bb023dd
--- /dev/null
+++ b/src/main/resources/es-plugin.properties
@@ -0,0 +1,2 @@
+plugin=${project.groupId}.MCFAuthorizerPlugin
+version=${project.version}
\ No newline at end of file