mirror of
https://github.com/dbeaver/cloudbeaver.git
synced 2026-09-24 16:04:36 +08:00
CB-1803 refactor sm api (#736)
* CB-1590 dc: poc users and roles admin api * CB-1803 - dc: sm controller rest api * CB-1803 resolve conflicts * CB-1803 refactor dc client * CB-1803 support additional server properties * CB-1803 support additional server properties * CB-1803 fix manifest
This commit is contained in:
+17
-4
@@ -52,6 +52,7 @@ import org.jkiss.dbeaver.model.runtime.AbstractJob;
|
||||
import org.jkiss.dbeaver.model.runtime.BaseProgressMonitor;
|
||||
import org.jkiss.dbeaver.model.runtime.DBRProgressMonitor;
|
||||
import org.jkiss.dbeaver.model.runtime.ProxyProgressMonitor;
|
||||
import org.jkiss.dbeaver.model.security.SMConstants;
|
||||
import org.jkiss.dbeaver.model.security.SMController;
|
||||
import org.jkiss.dbeaver.model.security.SMDataSourceGrant;
|
||||
import org.jkiss.dbeaver.model.sql.DBQuotaException;
|
||||
@@ -114,7 +115,7 @@ public class WebSession extends AbstractSessionPersistent implements SMSession,
|
||||
private final DBRProgressMonitor progressMonitor = new SessionProgressMonitor();
|
||||
private ProjectMetadata sessionProject;
|
||||
private final SessionContextImpl sessionAuthContext;
|
||||
private final SMController<?, ?, WebSession> securityController;
|
||||
private final SMController<?, ?> securityController;
|
||||
private final WebApplication application;
|
||||
private final Map<String, DBWSessionHandler> sessionHandlers;
|
||||
|
||||
@@ -124,7 +125,7 @@ public class WebSession extends AbstractSessionPersistent implements SMSession,
|
||||
}
|
||||
|
||||
public WebSession(HttpSession httpSession,
|
||||
SMController<?, ?, WebSession> securityController,
|
||||
SMController<?, ?> securityController,
|
||||
WebApplication application,
|
||||
Map<String, DBWSessionHandler> sessionHandlers) {
|
||||
this.id = httpSession.getId();
|
||||
@@ -221,6 +222,10 @@ public class WebSession extends AbstractSessionPersistent implements SMSession,
|
||||
return user;
|
||||
}
|
||||
|
||||
private synchronized String getUserId() {
|
||||
return user == null ? null : user.getUserId();
|
||||
}
|
||||
|
||||
public synchronized boolean hasPermission(String perm) {
|
||||
return getSessionPermissions().contains(perm);
|
||||
}
|
||||
@@ -450,12 +455,13 @@ public class WebSession extends AbstractSessionPersistent implements SMSession,
|
||||
// Persist session
|
||||
if (!this.persisted) {
|
||||
// Create new record
|
||||
securityController.createSession(this);
|
||||
securityController.createSession(this.id, getUserId(), getSessionParameters());
|
||||
this.persisted = true;
|
||||
} else {
|
||||
if (!application.isConfigurationMode()) {
|
||||
// Update record
|
||||
securityController.updateSession(this);
|
||||
//TODO use generate id from SMController
|
||||
securityController.updateSession(this.id, getUserId(), getSessionParameters());
|
||||
}
|
||||
}
|
||||
} catch (Exception e) {
|
||||
@@ -855,6 +861,13 @@ public class WebSession extends AbstractSessionPersistent implements SMSession,
|
||||
///////////////////////////////////////////////////////
|
||||
// Utils
|
||||
|
||||
private Map<String, Object> getSessionParameters() {
|
||||
var parameters = new HashMap<String, Object>();
|
||||
parameters.put(SMConstants.SESSION_PARAM_LAST_REMOTE_ADDRESS, getLastRemoteAddr());
|
||||
parameters.put(SMConstants.SESSION_PARAM_LAST_REMOTE_USER_AGENT, getLastRemoteUserAgent());
|
||||
return parameters;
|
||||
}
|
||||
|
||||
private class SessionProgressMonitor extends BaseProgressMonitor {
|
||||
@Override
|
||||
public void beginTask(String name, int totalWork) {
|
||||
|
||||
@@ -41,6 +41,11 @@ public class WebUser implements SMUser {
|
||||
this.userId = userId;
|
||||
}
|
||||
|
||||
public WebUser(@NotNull String userId, Map<String, String> metaParameters) {
|
||||
this.userId = userId;
|
||||
this.metaParameters.putAll(metaParameters);
|
||||
}
|
||||
|
||||
@NotNull
|
||||
public String getUserId() {
|
||||
return userId;
|
||||
|
||||
+3
-3
@@ -45,7 +45,7 @@ public class LocalAuthProvider implements SMAuthProvider<LocalAuthSession> {
|
||||
String userName = CommonUtils.toString(userCredentials.get(CRED_USER), null);
|
||||
|
||||
AuthProviderDescriptor authProvider = AuthProviderRegistry.getInstance().getAuthProvider(PROVIDER_ID);
|
||||
Map<String, Object> storedCredentials = CBApplication.getInstance().getSecurityController().getUserCredentials(userName, authProvider);
|
||||
Map<String, Object> storedCredentials = CBApplication.getInstance().getSecurityController().getUserCredentials(userName, authProvider.getId());
|
||||
if (storedCredentials == null) {
|
||||
throw new DBException("Invalid user name or password");
|
||||
}
|
||||
@@ -79,7 +79,7 @@ public class LocalAuthProvider implements SMAuthProvider<LocalAuthSession> {
|
||||
String userName = webSession.getUser().getUserId();
|
||||
|
||||
AuthProviderDescriptor authProvider = AuthProviderRegistry.getInstance().getAuthProvider(PROVIDER_ID);
|
||||
Map<String, Object> storedCredentials = CBApplication.getInstance().getSecurityController().getUserCredentials(userName, authProvider);
|
||||
Map<String, Object> storedCredentials = CBApplication.getInstance().getSecurityController().getUserCredentials(userName, authProvider.getId());
|
||||
if (storedCredentials == null) {
|
||||
throw new DBException("Invalid user name or password");
|
||||
}
|
||||
@@ -98,7 +98,7 @@ public class LocalAuthProvider implements SMAuthProvider<LocalAuthSession> {
|
||||
//String newPasswordHash = WebAuthProviderPropertyEncryption.hash.encrypt(userName, newPassword);
|
||||
|
||||
storedCredentials.put(CRED_PASSWORD, newPassword);
|
||||
CBApplication.getInstance().getSecurityController().setUserCredentials(userName, authProvider, storedCredentials);
|
||||
CBApplication.getInstance().getSecurityController().setUserCredentials(userName, authProvider.getId(), storedCredentials);
|
||||
return true;
|
||||
}
|
||||
|
||||
|
||||
@@ -111,7 +111,7 @@ public class CBApplication extends BaseApplicationImpl implements WebApplication
|
||||
private Map<String, String> externalProperties = new LinkedHashMap<>();
|
||||
|
||||
// Persistence
|
||||
private SMAdminController<WebUser, WebRole, WebSession> securityController;
|
||||
private SMAdminController<WebUser, WebRole> securityController;
|
||||
|
||||
private long maxSessionIdleTime = CBConstants.MAX_SESSION_IDLE_TIME;
|
||||
|
||||
@@ -174,11 +174,11 @@ public class CBApplication extends BaseApplicationImpl implements WebApplication
|
||||
return productConfiguration;
|
||||
}
|
||||
|
||||
public SMController<WebUser, WebRole, WebSession> getSecurityController() {
|
||||
public SMController<WebUser, WebRole> getSecurityController() {
|
||||
return securityController;
|
||||
}
|
||||
|
||||
public SMAdminController<WebUser, WebRole, WebSession> getAdminSecurityController() {
|
||||
public SMAdminController<WebUser, WebRole> getAdminSecurityController() {
|
||||
return securityController;
|
||||
}
|
||||
|
||||
@@ -435,7 +435,11 @@ public class CBApplication extends BaseApplicationImpl implements WebApplication
|
||||
}
|
||||
|
||||
private void initializeSecurityController() throws DBException {
|
||||
securityController = SecurityPluginService.getSecurityService(this, databaseConfiguration);
|
||||
securityController = createSecurityController();
|
||||
}
|
||||
|
||||
protected SMAdminController<WebUser, WebRole> createSecurityController() throws DBException {
|
||||
return SecurityPluginService.getSecurityService(this, databaseConfiguration);
|
||||
}
|
||||
|
||||
private void loadConfiguration(String configPath) {
|
||||
@@ -543,7 +547,8 @@ public class CBApplication extends BaseApplicationImpl implements WebApplication
|
||||
log.error("Error reading static contents from " + staticContentsFile, e);
|
||||
}
|
||||
}
|
||||
} catch (IOException e) {
|
||||
parseAdditionalServerConfiguration(serverConfig);
|
||||
} catch (IOException | DBException e) {
|
||||
log.error("Error parsing server configuration", e);
|
||||
}
|
||||
|
||||
@@ -593,6 +598,10 @@ public class CBApplication extends BaseApplicationImpl implements WebApplication
|
||||
patchConfigurationWithProperties(productConfiguration);
|
||||
}
|
||||
|
||||
protected void parseAdditionalServerConfiguration(Map<String, Object> serverConfig) throws DBException {
|
||||
|
||||
}
|
||||
|
||||
private void runWebServer() {
|
||||
log.debug("Starting Jetty server (" + serverPort + " on " + (CommonUtils.isEmpty(serverHost) ? "all interfaces" : serverHost) + ") ");
|
||||
new CBJettyServer().runServer();
|
||||
|
||||
+4
-4
@@ -128,7 +128,7 @@ public class WebServiceAdmin implements DBWServiceAdmin {
|
||||
}
|
||||
try {
|
||||
WebUser newUser = new WebUser(userName);
|
||||
CBPlatform.getInstance().getApplication().getAdminSecurityController().createUser(newUser);
|
||||
CBPlatform.getInstance().getApplication().getAdminSecurityController().createUser(newUser.getUserId(), newUser.getMetaParameters());
|
||||
return new AdminUserInfo(webSession, newUser);
|
||||
} catch (Exception e) {
|
||||
throw new DBWebException("Error creating new user", e);
|
||||
@@ -251,7 +251,7 @@ public class WebServiceAdmin implements DBWServiceAdmin {
|
||||
throw new DBWebException("Cannot change permissions in anonymous mode");
|
||||
}
|
||||
try {
|
||||
CBPlatform.getInstance().getApplication().getSecurityController().setSubjectPermissions(roleID, permissions.toArray(new String[0]), grantor.getUserId());
|
||||
CBPlatform.getInstance().getApplication().getAdminSecurityController().setSubjectPermissions(roleID, permissions, grantor.getUserId());
|
||||
return true;
|
||||
} catch (Exception e) {
|
||||
throw new DBWebException("Error setting role permissions", e);
|
||||
@@ -270,7 +270,7 @@ public class WebServiceAdmin implements DBWServiceAdmin {
|
||||
credentials.put(LocalAuthProvider.CRED_USER, userID);
|
||||
}
|
||||
try {
|
||||
CBPlatform.getInstance().getApplication().getSecurityController().setUserCredentials(userID, authProvider, credentials);
|
||||
CBPlatform.getInstance().getApplication().getSecurityController().setUserCredentials(userID, authProvider.getId(), credentials);
|
||||
return true;
|
||||
} catch (Exception e) {
|
||||
throw new DBWebException("Error setting user credentials", e);
|
||||
@@ -603,7 +603,7 @@ public class WebServiceAdmin implements DBWServiceAdmin {
|
||||
throw new DBWebException("Cannot grant access in anonymous mode");
|
||||
}
|
||||
try {
|
||||
CBApplication.getInstance().getSecurityController().setSubjectConnectionAccess(subjectId, connections.toArray(new String[0]), grantor.getUserId());
|
||||
CBApplication.getInstance().getAdminSecurityController().setSubjectConnectionAccess(subjectId, connections, grantor.getUserId());
|
||||
} catch (DBCException e) {
|
||||
throw new DBWebException("Error setting subject connection access", e);
|
||||
}
|
||||
|
||||
+3
-3
@@ -56,7 +56,7 @@ public class RPSessionHandler implements DBWSessionHandler {
|
||||
return false;
|
||||
}
|
||||
public void reverseProxyAuthentication(@NotNull HttpServletRequest request, @NotNull WebSession webSession) throws DBWebException {
|
||||
SMController<WebUser, ?, ?> securityController = CBPlatform.getInstance().getApplication().getSecurityController();
|
||||
SMController<WebUser, ?> securityController = CBPlatform.getInstance().getApplication().getSecurityController();
|
||||
AuthProviderDescriptor authProvider = AuthProviderRegistry.getInstance().getAuthProvider(AUTH_PROVIDER);
|
||||
|
||||
String userName = request.getHeader(X_USER);
|
||||
@@ -74,14 +74,14 @@ public class RPSessionHandler implements DBWSessionHandler {
|
||||
// User doesn't exist. We can create new user automatically
|
||||
// Create new user
|
||||
curUser = new WebUser(userName);
|
||||
adminSecurityController.createUser(curUser);
|
||||
adminSecurityController.createUser(curUser.getUserId(), curUser.getMetaParameters());
|
||||
|
||||
String defaultRoleName = CBPlatform.getInstance().getApplication().getAppConfiguration().getDefaultUserRole();
|
||||
if (userRoles.length == 0) {
|
||||
userRoles = new String[]{defaultRoleName};
|
||||
}
|
||||
// We need to associate new credentials with active user
|
||||
securityController.setUserCredentials(userName, authProvider, credentials);
|
||||
securityController.setUserCredentials(userName, authProvider.getId(), credentials);
|
||||
}
|
||||
adminSecurityController.setUserRoles(userName, userRoles, userName);
|
||||
user = curUser;
|
||||
|
||||
+5
-5
@@ -62,7 +62,7 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
|
||||
@NotNull String providerId,
|
||||
@NotNull Map<String, Object> authParameters,
|
||||
boolean linkWithActiveUser) throws DBWebException {
|
||||
SMController<WebUser, ?, ?> securityController = CBPlatform.getInstance().getApplication().getSecurityController();
|
||||
SMController<WebUser, ?> securityController = CBPlatform.getInstance().getApplication().getSecurityController();
|
||||
|
||||
if (CommonUtils.isEmpty(providerId)) {
|
||||
throw new DBWebException("Missing auth provider parameter");
|
||||
@@ -136,7 +136,7 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
|
||||
}
|
||||
} else {
|
||||
WebUser curUser = webSession.getUser();
|
||||
userId = securityController.getUserByCredentials(authProvider, userCredentials);
|
||||
userId = securityController.getUserByCredentials(authProvider.getId(), userCredentials);
|
||||
if (userId == null) {
|
||||
// User doesn't exist. We can create new user automatically if auth provider supports this
|
||||
if (authProviderExternal != null) {
|
||||
@@ -153,7 +153,7 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
|
||||
if (curUser == null) {
|
||||
curUser = new WebUser(userId);
|
||||
var adminSecurityController = CBPlatform.getInstance().getApplication().getAdminSecurityController();
|
||||
adminSecurityController.createUser(curUser);
|
||||
adminSecurityController.createUser(curUser.getUserId(), curUser.getMetaParameters());
|
||||
|
||||
String defaultRoleName = CBPlatform.getInstance().getApplication().getAppConfiguration().getDefaultUserRole();
|
||||
if (!CommonUtils.isEmpty(defaultRoleName)) {
|
||||
@@ -166,7 +166,7 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
|
||||
}
|
||||
// We may need to associate new credentials with active user
|
||||
if (linkWithActiveUser) {
|
||||
securityController.setUserCredentials(userId, authProvider, userCredentials);
|
||||
securityController.setUserCredentials(userId, authProvider.getId(), userCredentials);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -235,7 +235,7 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
|
||||
boolean isAdmin = false;
|
||||
|
||||
try {
|
||||
Object userId = securityController.getUserByCredentials(authProvider, userCredentials);
|
||||
Object userId = securityController.getUserByCredentials(authProvider.getId(), userCredentials);
|
||||
|
||||
if (userId != null) {
|
||||
isAdmin = securityController
|
||||
|
||||
@@ -9,9 +9,9 @@ Bundle-RequiredExecutionEnvironment: JavaSE-11
|
||||
Bundle-ActivationPolicy: lazy
|
||||
Bundle-ClassPath: .
|
||||
Require-Bundle: org.jkiss.dbeaver.model;visibility:=reexport,
|
||||
org.jkiss.dbeaver.model.sql,
|
||||
org.jkiss.dbeaver.registry;visibility:=reexport,
|
||||
org.jkiss.bundle.apache.dbcp,
|
||||
io.cloudbeaver.model
|
||||
org.jkiss.dbeaver.model.sql,
|
||||
org.jkiss.dbeaver.registry;visibility:=reexport,
|
||||
org.jkiss.bundle.apache.dbcp,
|
||||
io.cloudbeaver.model
|
||||
Export-Package: io.cloudbeaver.service.security
|
||||
Automatic-Module-Name: io.cloudbeaver.service.security
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
source.. = src/
|
||||
output.. = target/classes/
|
||||
bin.includes = .,\
|
||||
META-INF/,\
|
||||
db/,\
|
||||
plugin.xml
|
||||
META-INF/,\
|
||||
db/,\
|
||||
plugin.xml,\
|
||||
OSGI-INF/
|
||||
|
||||
+1
-2
@@ -21,7 +21,6 @@ import com.google.gson.GsonBuilder;
|
||||
import com.google.gson.InstanceCreator;
|
||||
import io.cloudbeaver.model.app.WebApplication;
|
||||
import io.cloudbeaver.model.session.WebAuthInfo;
|
||||
import io.cloudbeaver.model.session.WebSession;
|
||||
import io.cloudbeaver.model.user.WebRole;
|
||||
import io.cloudbeaver.model.user.WebUser;
|
||||
import io.cloudbeaver.service.security.internal.db.CBDatabase;
|
||||
@@ -50,7 +49,7 @@ public class SecurityPluginService implements IPluginService {
|
||||
|
||||
}
|
||||
|
||||
public static synchronized SMAdminController<WebUser, WebRole, WebSession> getSecurityService(WebApplication application, Map<String, Object> databaseConfig) throws DBException {
|
||||
public static synchronized SMAdminController<WebUser, WebRole> getSecurityService(WebApplication application, Map<String, Object> databaseConfig) throws DBException {
|
||||
if (CONTROLLER_INSTANCE != null) {
|
||||
return CONTROLLER_INSTANCE;
|
||||
}
|
||||
|
||||
+43
-38
@@ -18,18 +18,15 @@ package io.cloudbeaver.service.security.internal;
|
||||
|
||||
import io.cloudbeaver.model.user.WebUser;
|
||||
import io.cloudbeaver.service.security.internal.db.CBDatabase;
|
||||
import org.jkiss.dbeaver.model.auth.SMAuthCredentialsProfile;
|
||||
import org.jkiss.dbeaver.model.auth.SMAuthProviderDescriptor;
|
||||
import org.jkiss.dbeaver.model.auth.*;
|
||||
import org.jkiss.dbeaver.model.security.SMAdminController;
|
||||
import org.jkiss.dbeaver.model.security.SMConstants;
|
||||
import org.jkiss.dbeaver.model.security.SMDataSourceGrant;
|
||||
import org.jkiss.dbeaver.model.security.SMSubjectType;
|
||||
import io.cloudbeaver.DBWConstants;
|
||||
import io.cloudbeaver.model.session.WebSession;
|
||||
import org.jkiss.code.NotNull;
|
||||
import org.jkiss.code.Nullable;
|
||||
import org.jkiss.dbeaver.Log;
|
||||
import org.jkiss.dbeaver.model.auth.AuthPropertyDescriptor;
|
||||
import org.jkiss.dbeaver.model.auth.AuthPropertyEncryption;
|
||||
import org.jkiss.dbeaver.model.exec.DBCException;
|
||||
import org.jkiss.dbeaver.model.impl.jdbc.JDBCUtils;
|
||||
import org.jkiss.dbeaver.model.impl.jdbc.exec.JDBCTransaction;
|
||||
@@ -46,7 +43,7 @@ import java.util.stream.Collectors;
|
||||
/**
|
||||
* Server controller
|
||||
*/
|
||||
public class CBSecurityController implements SMAdminController<WebUser, WebRole, WebSession> {
|
||||
public class CBSecurityController implements SMAdminController<WebUser, WebRole> {
|
||||
|
||||
private static final Log log = Log.getLog(CBSecurityController.class);
|
||||
|
||||
@@ -79,23 +76,22 @@ public class CBSecurityController implements SMAdminController<WebUser, WebRole,
|
||||
// Users
|
||||
|
||||
@Override
|
||||
public void createUser(WebUser user) throws DBCException {
|
||||
if (isSubjectExists(user.getUserId())) {
|
||||
throw new DBCException("User or role '" + user.getUserId() + "' already exists");
|
||||
public void createUser(String userId, Map<String, String> metaParameters) throws DBCException {
|
||||
if (isSubjectExists(userId)) {
|
||||
throw new DBCException("User or role '" + userId + "' already exists");
|
||||
}
|
||||
try (Connection dbCon = database.openConnection()) {
|
||||
try (JDBCTransaction txn = new JDBCTransaction(dbCon)) {
|
||||
createAuthSubject(dbCon, user.getUserId(), SUBJECT_USER);
|
||||
createAuthSubject(dbCon, userId, SUBJECT_USER);
|
||||
try (PreparedStatement dbStat = dbCon.prepareStatement("INSERT INTO CB_USER(USER_ID,IS_ACTIVE,CREATE_TIME) VALUES(?,?,?)")) {
|
||||
dbStat.setString(1, user.getUserId());
|
||||
dbStat.setString(1, userId);
|
||||
dbStat.setString(2, CHAR_BOOL_TRUE);
|
||||
dbStat.setTimestamp(3, new Timestamp(System.currentTimeMillis()));
|
||||
dbStat.execute();
|
||||
}
|
||||
Map<String, String> metaParameters = user.getMetaParameters();
|
||||
if (!CommonUtils.isEmpty(metaParameters)) {
|
||||
try (PreparedStatement dbStat = dbCon.prepareStatement("INSERT INTO CB_USER_META(USER_ID,META_ID,META_VALUE) VALUES(?,?,?)")) {
|
||||
dbStat.setString(1, user.getUserId());
|
||||
dbStat.setString(1, userId);
|
||||
for (Map.Entry<String, String> mp : metaParameters.entrySet()) {
|
||||
dbStat.setString(2, mp.getKey());
|
||||
dbStat.setString(3, mp.getValue());
|
||||
@@ -350,8 +346,9 @@ public class CBSecurityController implements SMAdminController<WebUser, WebRole,
|
||||
}
|
||||
|
||||
@Override
|
||||
public void setUserCredentials(String userId, SMAuthProviderDescriptor authProvider, Map<String, Object> credentials) throws DBCException {
|
||||
public void setUserCredentials(String userId, String authProviderId, Map<String, Object> credentials) throws DBCException {
|
||||
List<String[]> transformedCredentials;
|
||||
AuthProviderDescriptor authProvider = getAuthProvider(authProviderId);
|
||||
try {
|
||||
SMAuthCredentialsProfile credProfile = getCredentialProfileByParameters(authProvider, credentials.keySet());
|
||||
transformedCredentials = credentials.entrySet().stream().map(cred -> {
|
||||
@@ -393,7 +390,8 @@ public class CBSecurityController implements SMAdminController<WebUser, WebRole,
|
||||
|
||||
@Nullable
|
||||
@Override
|
||||
public String getUserByCredentials(SMAuthProviderDescriptor authProvider, Map<String, Object> authParameters) throws DBCException {
|
||||
public String getUserByCredentials(String authProviderId, Map<String, Object> authParameters) throws DBCException {
|
||||
AuthProviderDescriptor authProvider = getAuthProvider(authProviderId);
|
||||
Map<String, Object> identCredentials = new LinkedHashMap<>();
|
||||
for (AuthPropertyDescriptor prop : authProvider.getCredentialParameters(authParameters.keySet())) {
|
||||
if (prop.isIdentifying()) {
|
||||
@@ -460,7 +458,8 @@ public class CBSecurityController implements SMAdminController<WebUser, WebRole,
|
||||
}
|
||||
|
||||
@Override
|
||||
public Map<String, Object> getUserCredentials(String userId, SMAuthProviderDescriptor authProvider) throws DBCException {
|
||||
public Map<String, Object> getUserCredentials(String userId, String authProviderId) throws DBCException {
|
||||
AuthProviderDescriptor authProvider = getAuthProvider(authProviderId);
|
||||
try (Connection dbCon = database.openConnection()) {
|
||||
try (PreparedStatement dbStat = dbCon.prepareStatement(
|
||||
"SELECT CRED_ID,CRED_VALUE FROM CB_USER_CREDENTIALS\n" +
|
||||
@@ -658,11 +657,11 @@ public class CBSecurityController implements SMAdminController<WebUser, WebRole,
|
||||
// Permissions
|
||||
|
||||
@Override
|
||||
public void setSubjectPermissions(String subjectId, String[] permissionIds, String grantorId) throws DBCException {
|
||||
public void setSubjectPermissions(String subjectId, List<String> permissionIds, String grantorId) throws DBCException {
|
||||
try (Connection dbCon = database.openConnection()) {
|
||||
try (JDBCTransaction txn = new JDBCTransaction(dbCon)) {
|
||||
JDBCUtils.executeStatement(dbCon, "DELETE FROM CB_AUTH_PERMISSIONS WHERE SUBJECT_ID=?", subjectId);
|
||||
insertPermissions(dbCon, subjectId, permissionIds, grantorId);
|
||||
insertPermissions(dbCon, subjectId, permissionIds.toArray(String[]::new), grantorId);
|
||||
txn.commit();
|
||||
}
|
||||
} catch (SQLException e) {
|
||||
@@ -755,28 +754,27 @@ public class CBSecurityController implements SMAdminController<WebUser, WebRole,
|
||||
}
|
||||
|
||||
@Override
|
||||
public void createSession(WebSession session) throws DBCException {
|
||||
public void createSession(@NotNull String appSessionId, @Nullable String userId, @NotNull Map<String, Object> parameters) throws DBCException {
|
||||
try (Connection dbCon = database.openConnection()) {
|
||||
try (PreparedStatement dbStat = dbCon.prepareStatement(
|
||||
"INSERT INTO CB_SESSION(SESSION_ID,USER_ID,CREATE_TIME,LAST_ACCESS_TIME,LAST_ACCESS_REMOTE_ADDRESS,LAST_ACCESS_USER_AGENT,LAST_ACCESS_INSTANCE_ID) " +
|
||||
"VALUES(?,?,?,?,?,?,?)")) {
|
||||
dbStat.setString(1, session.getSessionId());
|
||||
WebUser user = session.getUser();
|
||||
if (user == null) {
|
||||
dbStat.setString(1, appSessionId);
|
||||
if (userId == null) {
|
||||
dbStat.setNull(2, Types.VARCHAR);
|
||||
} else {
|
||||
dbStat.setString(2, user.getUserId());
|
||||
dbStat.setString(2, userId);
|
||||
}
|
||||
Timestamp currentTS = new Timestamp(System.currentTimeMillis());
|
||||
dbStat.setTimestamp(3, currentTS);
|
||||
dbStat.setTimestamp(4, currentTS);
|
||||
if (session.getLastRemoteAddr() != null) {
|
||||
dbStat.setString(5, session.getLastRemoteAddr());
|
||||
if (parameters.get(SMConstants.SESSION_PARAM_LAST_REMOTE_ADDRESS) != null) {
|
||||
dbStat.setString(5, parameters.get(SMConstants.SESSION_PARAM_LAST_REMOTE_ADDRESS).toString());
|
||||
} else {
|
||||
dbStat.setNull(5, Types.VARCHAR);
|
||||
}
|
||||
if (session.getLastRemoteUserAgent() != null) {
|
||||
dbStat.setString(6, session.getLastRemoteUserAgent());
|
||||
if (parameters.get(SMConstants.SESSION_PARAM_LAST_REMOTE_USER_AGENT) != null) {
|
||||
dbStat.setString(6, parameters.get(SMConstants.SESSION_PARAM_LAST_REMOTE_USER_AGENT).toString());
|
||||
} else {
|
||||
dbStat.setNull(6, Types.VARCHAR);
|
||||
}
|
||||
@@ -789,30 +787,29 @@ public class CBSecurityController implements SMAdminController<WebUser, WebRole,
|
||||
}
|
||||
|
||||
@Override
|
||||
public void updateSession(WebSession session) throws DBCException {
|
||||
public void updateSession(@NotNull String sessionId, @Nullable String userId, @NotNull Map<String, Object> parameters) throws DBCException {
|
||||
try (Connection dbCon = database.openConnection()) {
|
||||
try (PreparedStatement dbStat = dbCon.prepareStatement(
|
||||
"UPDATE CB_SESSION SET USER_ID=?,LAST_ACCESS_TIME=?,LAST_ACCESS_REMOTE_ADDRESS=?,LAST_ACCESS_USER_AGENT=?,LAST_ACCESS_INSTANCE_ID=? WHERE SESSION_ID=?")) {
|
||||
WebUser user = session.getUser();
|
||||
if (user == null) {
|
||||
if (userId == null) {
|
||||
dbStat.setNull(1, Types.VARCHAR);
|
||||
} else {
|
||||
dbStat.setString(1, user.getUserId());
|
||||
dbStat.setString(1, userId);
|
||||
}
|
||||
dbStat.setTimestamp(2, new Timestamp(System.currentTimeMillis()));
|
||||
if (session.getLastRemoteAddr() != null) {
|
||||
dbStat.setString(3, CommonUtils.truncateString(session.getLastRemoteAddr(), 128));
|
||||
if (parameters.get(SMConstants.SESSION_PARAM_LAST_REMOTE_ADDRESS) != null) {
|
||||
dbStat.setString(3, CommonUtils.truncateString(parameters.get(SMConstants.SESSION_PARAM_LAST_REMOTE_ADDRESS).toString(), 128));
|
||||
} else {
|
||||
dbStat.setNull(3, Types.VARCHAR);
|
||||
}
|
||||
if (session.getLastRemoteUserAgent() != null) {
|
||||
dbStat.setString(4, CommonUtils.truncateString(session.getLastRemoteUserAgent(), 255));
|
||||
if (parameters.get(SMConstants.SESSION_PARAM_LAST_REMOTE_USER_AGENT) != null) {
|
||||
dbStat.setString(4, CommonUtils.truncateString(parameters.get(SMConstants.SESSION_PARAM_LAST_REMOTE_USER_AGENT).toString(), 255));
|
||||
} else {
|
||||
dbStat.setNull(4, Types.VARCHAR);
|
||||
}
|
||||
dbStat.setString(5, database.getInstanceId());
|
||||
|
||||
dbStat.setString(6, session.getSessionId());
|
||||
dbStat.setString(6, sessionId);
|
||||
if (dbStat.executeUpdate() <= 0) {
|
||||
throw new DBCException("Session not exists in database");
|
||||
}
|
||||
@@ -876,12 +873,12 @@ public class CBSecurityController implements SMAdminController<WebUser, WebRole,
|
||||
}
|
||||
|
||||
@Override
|
||||
public void setSubjectConnectionAccess(@NotNull String subjectId, @NotNull String[] connectionIds, String grantorId) throws DBCException {
|
||||
public void setSubjectConnectionAccess(@NotNull String subjectId, @NotNull List<String> connectionIds, String grantorId) throws DBCException {
|
||||
try (Connection dbCon = database.openConnection()) {
|
||||
try (JDBCTransaction txn = new JDBCTransaction(dbCon)) {
|
||||
JDBCUtils.executeStatement(dbCon,
|
||||
"DELETE FROM CB_DATASOURCE_ACCESS WHERE SUBJECT_ID=?", subjectId);
|
||||
if (!ArrayUtils.isEmpty(connectionIds)) {
|
||||
if (!CommonUtils.isEmpty(connectionIds)) {
|
||||
try (PreparedStatement dbStat = dbCon.prepareStatement(
|
||||
"INSERT INTO CB_DATASOURCE_ACCESS(SUBJECT_ID,GRANT_TIME,GRANTED_BY,DATASOURCE_ID) VALUES(?,?,?,?)")) {
|
||||
dbStat.setString(1, subjectId);
|
||||
@@ -1008,4 +1005,12 @@ public class CBSecurityController implements SMAdminController<WebUser, WebRole,
|
||||
}
|
||||
}
|
||||
|
||||
private AuthProviderDescriptor getAuthProvider(String authProviderId) throws DBCException {
|
||||
AuthProviderDescriptor authProvider = AuthProviderRegistry.getInstance().getAuthProvider(authProviderId);
|
||||
if (authProvider == null) {
|
||||
throw new DBCException("Auth provider not found: " + authProviderId);
|
||||
}
|
||||
return authProvider;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
+6
-9
@@ -20,7 +20,6 @@ import com.google.gson.Gson;
|
||||
import com.google.gson.GsonBuilder;
|
||||
import io.cloudbeaver.auth.provider.local.LocalAuthProviderConstants;
|
||||
import io.cloudbeaver.model.app.WebApplication;
|
||||
import io.cloudbeaver.model.session.WebSession;
|
||||
import io.cloudbeaver.model.user.WebUser;
|
||||
import io.cloudbeaver.utils.WebAppUtils;
|
||||
import org.jkiss.dbeaver.model.security.SMAdminController;
|
||||
@@ -57,8 +56,6 @@ import org.jkiss.utils.SecurityUtils;
|
||||
import java.io.*;
|
||||
import java.net.InetAddress;
|
||||
import java.nio.charset.StandardCharsets;
|
||||
import java.nio.file.Files;
|
||||
import java.nio.file.Path;
|
||||
import java.sql.*;
|
||||
import java.util.*;
|
||||
|
||||
@@ -83,14 +80,14 @@ public class CBDatabase {
|
||||
private transient volatile Connection exclusiveConnection;
|
||||
|
||||
private String instanceId;
|
||||
private SMAdminController<WebUser, WebRole, WebSession> adminSecurityController;
|
||||
private SMAdminController<WebUser, WebRole> adminSecurityController;
|
||||
|
||||
public CBDatabase(WebApplication application, CBDatabaseConfig databaseConfiguration) {
|
||||
this.application = application;
|
||||
this.databaseConfiguration = databaseConfiguration;
|
||||
}
|
||||
|
||||
public void setAdminSecurityController(SMAdminController<WebUser, WebRole, WebSession> adminSecurityController) {
|
||||
public void setAdminSecurityController(SMAdminController<WebUser, WebRole> adminSecurityController) {
|
||||
this.adminSecurityController = adminSecurityController;
|
||||
}
|
||||
|
||||
@@ -220,7 +217,7 @@ public class CBDatabase {
|
||||
AuthProviderDescriptor authProvider = ai.getAuthProviderDescriptor();
|
||||
Map<String, Object> userCredentials = ai.getUserCredentials();
|
||||
if (!CommonUtils.isEmpty(userCredentials)) {
|
||||
adminSecurityController.setUserCredentials(adminName, authProvider, userCredentials);
|
||||
adminSecurityController.setUserCredentials(adminName, authProvider.getId(), userCredentials);
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -249,7 +246,7 @@ public class CBDatabase {
|
||||
WebUser adminUser = adminSecurityController.getUserById(adminName);
|
||||
if (adminUser == null) {
|
||||
adminUser = new WebUser(adminName);
|
||||
adminSecurityController.createUser(adminUser);
|
||||
adminSecurityController.createUser(adminUser.getUserId(), adminUser.getMetaParameters());
|
||||
}
|
||||
|
||||
if (!CommonUtils.isEmpty(adminPassword)) {
|
||||
@@ -262,7 +259,7 @@ public class CBDatabase {
|
||||
|
||||
AuthProviderDescriptor authProvider = AuthProviderRegistry.getInstance().getAuthProvider(LocalAuthProviderConstants.PROVIDER_ID);
|
||||
if (authProvider != null) {
|
||||
adminSecurityController.setUserCredentials(adminUser.getUserId(), authProvider, credentials);
|
||||
adminSecurityController.setUserCredentials(adminUser.getUserId(), authProvider.getId(), credentials);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -353,7 +350,7 @@ public class CBDatabase {
|
||||
for (WebRole role : initialData.getRoles()) {
|
||||
adminSecurityController.createRole(role, adminName);
|
||||
if (adminName != null) {
|
||||
adminSecurityController.setSubjectPermissions(role.getRoleId(), role.getPermissions().toArray(new String[0]), adminName);
|
||||
adminSecurityController.setSubjectPermissions(role.getRoleId(), new ArrayList<>(role.getPermissions()), adminName);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user