Merge branch 'devel' into refactor/CB-2372

This commit is contained in:
yagudin10
2022-08-03 16:28:17 +03:00
10 changed files with 115 additions and 111 deletions
@@ -27,7 +27,8 @@ import io.cloudbeaver.model.session.WebAuthInfo;
import io.cloudbeaver.registry.WebServiceRegistry;
import io.cloudbeaver.server.jetty.CBJettyServer;
import io.cloudbeaver.service.DBWServiceInitializer;
import io.cloudbeaver.service.security.SecurityPluginService;
import io.cloudbeaver.service.security.CBEmbeddedSecurityController;
import io.cloudbeaver.service.security.EmbeddedSecurityControllerFactory;
import io.cloudbeaver.utils.WebAppUtils;
import org.eclipse.core.runtime.Platform;
import org.eclipse.equinox.app.IApplicationContext;
@@ -105,7 +106,7 @@ public class CBApplication extends BaseWebApplication implements WebAuthApplicat
// Configurations
protected final Map<String, Object> productConfiguration = new HashMap<>();
private final Map<String, Object> databaseConfiguration = new HashMap<>();
protected final Map<String, Object> databaseConfiguration = new HashMap<>();
private final CBAppConfig appConfiguration = new CBAppConfig();
private Map<String, String> externalProperties = new LinkedHashMap<>();
@@ -299,6 +300,13 @@ public class CBApplication extends BaseWebApplication implements WebAuthApplicat
}
try {
initializeServer();
} catch (DBException e) {
log.error("Error initializing server", e);
return null;
}
{
try {
initializeSecurityController();
@@ -323,12 +331,6 @@ public class CBApplication extends BaseWebApplication implements WebAuthApplicat
System.setSecurityManager(new SecurityManager());
}
try {
initializeServer();
} catch (DBException e) {
log.error("Error initializing server", e);
return null;
}
runWebServer();
log.debug("Shutdown");
@@ -451,7 +453,7 @@ public class CBApplication extends BaseWebApplication implements WebAuthApplicat
}
protected SMAdminController createGlobalSecurityController() throws DBException {
return SecurityPluginService.createSecurityService(this, databaseConfiguration);
return new EmbeddedSecurityControllerFactory().createSecurityService(this, databaseConfiguration);
}
@Nullable
@@ -681,6 +683,13 @@ public class CBApplication extends BaseWebApplication implements WebAuthApplicat
}
private void shutdown() {
try {
if (securityController instanceof CBEmbeddedSecurityController) {
((CBEmbeddedSecurityController) securityController).shutdown();
}
} catch (Exception e) {
log.error(e);
}
log.debug("Cloudbeaver Server is stopping"); //$NON-NLS-1$
}
@@ -763,8 +772,13 @@ public class CBApplication extends BaseWebApplication implements WebAuthApplicat
return readConfiguration(runtimeConfigFile);
}
protected void finishSecurityServiceConfiguration(@NotNull String adminName, @Nullable String adminPassword, @NotNull List<WebAuthInfo> authInfoList) throws DBException {
SecurityPluginService.finishConfiguration(adminName, adminPassword, authInfoList);
protected void finishSecurityServiceConfiguration(@NotNull String adminName,
@Nullable String adminPassword,
@NotNull List<WebAuthInfo> authInfoList
) throws DBException {
if (securityController instanceof CBEmbeddedSecurityController) {
((CBEmbeddedSecurityController) securityController).finishConfiguration(adminName, adminPassword, authInfoList);
}
}
public synchronized void flushConfiguration() throws DBException {
@@ -15,5 +15,6 @@ Require-Bundle: org.jkiss.dbeaver.model;visibility:=reexport,
io.cloudbeaver.model
Export-Package: io.cloudbeaver.auth.provider.local,
io.cloudbeaver.auth.provider.rp,
io.cloudbeaver.service.security
io.cloudbeaver.service.security,
io.cloudbeaver.service.security.db
Automatic-Module-Name: io.cloudbeaver.service.security
@@ -2,10 +2,6 @@
<?eclipse version="3.2"?>
<plugin>
<extension point="org.jkiss.dbeaver.pluginService">
<service class="io.cloudbeaver.service.security.SecurityPluginService"/>
</extension>
<extension point="org.jkiss.dbeaver.auth.provider">
<authProvider id="local" label="Local"
description="Local name/password based authentication"
@@ -14,7 +14,7 @@
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package io.cloudbeaver.service.security.internal;
package io.cloudbeaver.service.security;
import com.google.gson.Gson;
import com.google.gson.GsonBuilder;
@@ -24,7 +24,9 @@ import io.cloudbeaver.auth.SMAuthProviderExternal;
import io.cloudbeaver.auth.SMWAuthProviderFederated;
import io.cloudbeaver.model.app.WebApplication;
import io.cloudbeaver.model.app.WebAuthConfiguration;
import io.cloudbeaver.service.security.internal.db.CBDatabase;
import io.cloudbeaver.model.session.WebAuthInfo;
import io.cloudbeaver.service.security.db.CBDatabase;
import io.cloudbeaver.service.security.internal.AuthAttemptSessionInfo;
import io.cloudbeaver.utils.WebAppUtils;
import org.jkiss.code.NotNull;
import org.jkiss.code.Nullable;
@@ -65,8 +67,8 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
private static final int TOKEN_HOURS_ALIVE_TIME = 1;
private static final String CHAR_BOOL_TRUE = "Y";
private static final String CHAR_BOOL_FALSE = "N";
protected static final String CHAR_BOOL_TRUE = "Y";
protected static final String CHAR_BOOL_FALSE = "N";
private static final String SUBJECT_USER = "U";
private static final String SUBJECT_ROLE = "R";
@@ -74,8 +76,8 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
}.getType();
private static final Gson gson = new GsonBuilder().create();
private final WebApplication application;
private final CBDatabase database;
protected final WebApplication application;
protected final CBDatabase database;
public CBEmbeddedSecurityController(WebApplication application, CBDatabase database) {
this.application = application;
@@ -99,7 +101,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
// Users
@Override
public void createUser(String userId, Map<String, String> metaParameters) throws DBCException {
public void createUser(String userId, Map<String, String> metaParameters) throws DBException {
if (isSubjectExists(userId)) {
throw new DBCException("User or role '" + userId + "' already exists");
}
@@ -1624,6 +1626,18 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
}
}
public void shutdown() {
database.shutdown();
}
public void finishConfiguration(
@NotNull String adminName,
@Nullable String adminPassword,
@NotNull List<WebAuthInfo> authInfoList
) throws DBException {
database.finishConfiguration(adminName, adminPassword, authInfoList);
}
///////////////////////////////////////////
// Utils
@@ -0,0 +1,63 @@
/*
* DBeaver - Universal Database Manager
* Copyright (C) 2010-2022 DBeaver Corp and others
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package io.cloudbeaver.service.security;
import com.google.gson.Gson;
import com.google.gson.GsonBuilder;
import com.google.gson.InstanceCreator;
import io.cloudbeaver.model.app.WebApplication;
import io.cloudbeaver.service.security.db.CBDatabase;
import io.cloudbeaver.service.security.db.CBDatabaseConfig;
import org.jkiss.dbeaver.DBException;
import java.util.Map;
/**
* Embedded Security Controller Factory
*/
public class EmbeddedSecurityControllerFactory {
/**
* Create new security controller instance
*/
public CBEmbeddedSecurityController createSecurityService(
WebApplication application,
Map<String, Object> databaseConfig
) throws DBException {
CBDatabaseConfig databaseConfiguration = new CBDatabaseConfig();
InstanceCreator<CBDatabaseConfig> dbConfigCreator = type -> databaseConfiguration;
InstanceCreator<CBDatabaseConfig.Pool> dbPoolConfigCreator = type -> databaseConfiguration.getPool();
Gson gson = new GsonBuilder()
.registerTypeAdapter(CBDatabaseConfig.class, dbConfigCreator)
.registerTypeAdapter(CBDatabaseConfig.Pool.class, dbPoolConfigCreator)
.create();
gson.fromJson(gson.toJsonTree(databaseConfig), CBDatabaseConfig.class);
var database = new CBDatabase(application, databaseConfiguration);
var securityController = createEmbeddedSecurityController(application, database);
//FIXME circular dependency
database.setAdminSecurityController(securityController);
database.initialize();
securityController.initializeMetaInformation();
return securityController;
}
protected CBEmbeddedSecurityController createEmbeddedSecurityController(WebApplication application, CBDatabase database) {
return new CBEmbeddedSecurityController(application, database);
}
}
@@ -1,84 +0,0 @@
/*
* DBeaver - Universal Database Manager
* Copyright (C) 2010-2022 DBeaver Corp and others
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package io.cloudbeaver.service.security;
import com.google.gson.Gson;
import com.google.gson.GsonBuilder;
import com.google.gson.InstanceCreator;
import io.cloudbeaver.model.app.WebApplication;
import io.cloudbeaver.model.session.WebAuthInfo;
import io.cloudbeaver.service.security.internal.CBEmbeddedSecurityController;
import io.cloudbeaver.service.security.internal.db.CBDatabase;
import io.cloudbeaver.service.security.internal.db.CBDatabaseConfig;
import org.jkiss.dbeaver.DBException;
import org.jkiss.dbeaver.Log;
import org.jkiss.dbeaver.model.security.SMAdminController;
import org.jkiss.dbeaver.runtime.IPluginService;
import java.util.List;
import java.util.Map;
public class SecurityPluginService implements IPluginService {
private static final Log log = Log.getLog(SecurityPluginService.class);
private static CBDatabase DB_INSTANCE;
private static CBEmbeddedSecurityController CONTROLLER_INSTANCE;
public static void finishConfiguration(String adminName, String adminPassword, List<WebAuthInfo> authInfoList) throws DBException {
DB_INSTANCE.finishConfiguration(adminName, adminPassword, authInfoList);
}
@Override
public void activateService() {
}
public static synchronized SMAdminController createSecurityService(WebApplication application, Map<String, Object> databaseConfig) throws DBException {
if (CONTROLLER_INSTANCE != null) {
return CONTROLLER_INSTANCE;
}
CBDatabaseConfig databaseConfiguration = new CBDatabaseConfig();
InstanceCreator<CBDatabaseConfig> dbConfigCreator = type -> databaseConfiguration;
InstanceCreator<CBDatabaseConfig.Pool> dbPoolConfigCreator = type -> databaseConfiguration.getPool();
Gson gson = new GsonBuilder()
.registerTypeAdapter(CBDatabaseConfig.class, dbConfigCreator)
.registerTypeAdapter(CBDatabaseConfig.Pool.class, dbPoolConfigCreator)
.create();
gson.fromJson(gson.toJsonTree(databaseConfig), CBDatabaseConfig.class);
DB_INSTANCE = new CBDatabase(application, databaseConfiguration);
CONTROLLER_INSTANCE = new CBEmbeddedSecurityController(application, DB_INSTANCE);
//FIXME circular dependency
DB_INSTANCE.setAdminSecurityController(CONTROLLER_INSTANCE);
DB_INSTANCE.initialize();
CONTROLLER_INSTANCE.initializeMetaInformation();
return CONTROLLER_INSTANCE;
}
@Override
public void deactivateService() {
if(DB_INSTANCE == null) {
return;
}
try {
DB_INSTANCE.shutdown();
} catch (Exception e) {
log.error(e);
}
}
}
@@ -14,7 +14,7 @@
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package io.cloudbeaver.service.security.internal.db;
package io.cloudbeaver.service.security.db;
import com.google.gson.Gson;
import com.google.gson.GsonBuilder;
@@ -14,7 +14,7 @@
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package io.cloudbeaver.service.security.internal.db;
package io.cloudbeaver.service.security.db;
/**
* Database configuration
@@ -14,7 +14,7 @@
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package io.cloudbeaver.service.security.internal.db;
package io.cloudbeaver.service.security.db;
import org.jkiss.dbeaver.model.security.user.SMRole;
@@ -16,7 +16,7 @@
*/
package io.cloudbeaver.service.security.internal.utils;
import io.cloudbeaver.service.security.internal.db.CBDatabaseConfig;
import io.cloudbeaver.service.security.db.CBDatabaseConfig;
import org.jkiss.code.Nullable;
import org.jkiss.utils.CommonUtils;