mirror of
https://github.com/dbeaver/cloudbeaver.git
synced 2026-09-24 16:04:36 +08:00
Merge branch 'devel' into refactor/CB-2372
This commit is contained in:
@@ -27,7 +27,8 @@ import io.cloudbeaver.model.session.WebAuthInfo;
|
||||
import io.cloudbeaver.registry.WebServiceRegistry;
|
||||
import io.cloudbeaver.server.jetty.CBJettyServer;
|
||||
import io.cloudbeaver.service.DBWServiceInitializer;
|
||||
import io.cloudbeaver.service.security.SecurityPluginService;
|
||||
import io.cloudbeaver.service.security.CBEmbeddedSecurityController;
|
||||
import io.cloudbeaver.service.security.EmbeddedSecurityControllerFactory;
|
||||
import io.cloudbeaver.utils.WebAppUtils;
|
||||
import org.eclipse.core.runtime.Platform;
|
||||
import org.eclipse.equinox.app.IApplicationContext;
|
||||
@@ -105,7 +106,7 @@ public class CBApplication extends BaseWebApplication implements WebAuthApplicat
|
||||
|
||||
// Configurations
|
||||
protected final Map<String, Object> productConfiguration = new HashMap<>();
|
||||
private final Map<String, Object> databaseConfiguration = new HashMap<>();
|
||||
protected final Map<String, Object> databaseConfiguration = new HashMap<>();
|
||||
private final CBAppConfig appConfiguration = new CBAppConfig();
|
||||
private Map<String, String> externalProperties = new LinkedHashMap<>();
|
||||
|
||||
@@ -299,6 +300,13 @@ public class CBApplication extends BaseWebApplication implements WebAuthApplicat
|
||||
|
||||
}
|
||||
|
||||
try {
|
||||
initializeServer();
|
||||
} catch (DBException e) {
|
||||
log.error("Error initializing server", e);
|
||||
return null;
|
||||
}
|
||||
|
||||
{
|
||||
try {
|
||||
initializeSecurityController();
|
||||
@@ -323,12 +331,6 @@ public class CBApplication extends BaseWebApplication implements WebAuthApplicat
|
||||
System.setSecurityManager(new SecurityManager());
|
||||
}
|
||||
|
||||
try {
|
||||
initializeServer();
|
||||
} catch (DBException e) {
|
||||
log.error("Error initializing server", e);
|
||||
return null;
|
||||
}
|
||||
runWebServer();
|
||||
|
||||
log.debug("Shutdown");
|
||||
@@ -451,7 +453,7 @@ public class CBApplication extends BaseWebApplication implements WebAuthApplicat
|
||||
}
|
||||
|
||||
protected SMAdminController createGlobalSecurityController() throws DBException {
|
||||
return SecurityPluginService.createSecurityService(this, databaseConfiguration);
|
||||
return new EmbeddedSecurityControllerFactory().createSecurityService(this, databaseConfiguration);
|
||||
}
|
||||
|
||||
@Nullable
|
||||
@@ -681,6 +683,13 @@ public class CBApplication extends BaseWebApplication implements WebAuthApplicat
|
||||
}
|
||||
|
||||
private void shutdown() {
|
||||
try {
|
||||
if (securityController instanceof CBEmbeddedSecurityController) {
|
||||
((CBEmbeddedSecurityController) securityController).shutdown();
|
||||
}
|
||||
} catch (Exception e) {
|
||||
log.error(e);
|
||||
}
|
||||
log.debug("Cloudbeaver Server is stopping"); //$NON-NLS-1$
|
||||
}
|
||||
|
||||
@@ -763,8 +772,13 @@ public class CBApplication extends BaseWebApplication implements WebAuthApplicat
|
||||
return readConfiguration(runtimeConfigFile);
|
||||
}
|
||||
|
||||
protected void finishSecurityServiceConfiguration(@NotNull String adminName, @Nullable String adminPassword, @NotNull List<WebAuthInfo> authInfoList) throws DBException {
|
||||
SecurityPluginService.finishConfiguration(adminName, adminPassword, authInfoList);
|
||||
protected void finishSecurityServiceConfiguration(@NotNull String adminName,
|
||||
@Nullable String adminPassword,
|
||||
@NotNull List<WebAuthInfo> authInfoList
|
||||
) throws DBException {
|
||||
if (securityController instanceof CBEmbeddedSecurityController) {
|
||||
((CBEmbeddedSecurityController) securityController).finishConfiguration(adminName, adminPassword, authInfoList);
|
||||
}
|
||||
}
|
||||
|
||||
public synchronized void flushConfiguration() throws DBException {
|
||||
|
||||
@@ -15,5 +15,6 @@ Require-Bundle: org.jkiss.dbeaver.model;visibility:=reexport,
|
||||
io.cloudbeaver.model
|
||||
Export-Package: io.cloudbeaver.auth.provider.local,
|
||||
io.cloudbeaver.auth.provider.rp,
|
||||
io.cloudbeaver.service.security
|
||||
io.cloudbeaver.service.security,
|
||||
io.cloudbeaver.service.security.db
|
||||
Automatic-Module-Name: io.cloudbeaver.service.security
|
||||
|
||||
@@ -2,10 +2,6 @@
|
||||
<?eclipse version="3.2"?>
|
||||
|
||||
<plugin>
|
||||
<extension point="org.jkiss.dbeaver.pluginService">
|
||||
<service class="io.cloudbeaver.service.security.SecurityPluginService"/>
|
||||
</extension>
|
||||
|
||||
<extension point="org.jkiss.dbeaver.auth.provider">
|
||||
<authProvider id="local" label="Local"
|
||||
description="Local name/password based authentication"
|
||||
|
||||
+21
-7
@@ -14,7 +14,7 @@
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
package io.cloudbeaver.service.security.internal;
|
||||
package io.cloudbeaver.service.security;
|
||||
|
||||
import com.google.gson.Gson;
|
||||
import com.google.gson.GsonBuilder;
|
||||
@@ -24,7 +24,9 @@ import io.cloudbeaver.auth.SMAuthProviderExternal;
|
||||
import io.cloudbeaver.auth.SMWAuthProviderFederated;
|
||||
import io.cloudbeaver.model.app.WebApplication;
|
||||
import io.cloudbeaver.model.app.WebAuthConfiguration;
|
||||
import io.cloudbeaver.service.security.internal.db.CBDatabase;
|
||||
import io.cloudbeaver.model.session.WebAuthInfo;
|
||||
import io.cloudbeaver.service.security.db.CBDatabase;
|
||||
import io.cloudbeaver.service.security.internal.AuthAttemptSessionInfo;
|
||||
import io.cloudbeaver.utils.WebAppUtils;
|
||||
import org.jkiss.code.NotNull;
|
||||
import org.jkiss.code.Nullable;
|
||||
@@ -65,8 +67,8 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
|
||||
private static final int TOKEN_HOURS_ALIVE_TIME = 1;
|
||||
|
||||
private static final String CHAR_BOOL_TRUE = "Y";
|
||||
private static final String CHAR_BOOL_FALSE = "N";
|
||||
protected static final String CHAR_BOOL_TRUE = "Y";
|
||||
protected static final String CHAR_BOOL_FALSE = "N";
|
||||
|
||||
private static final String SUBJECT_USER = "U";
|
||||
private static final String SUBJECT_ROLE = "R";
|
||||
@@ -74,8 +76,8 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
}.getType();
|
||||
private static final Gson gson = new GsonBuilder().create();
|
||||
|
||||
private final WebApplication application;
|
||||
private final CBDatabase database;
|
||||
protected final WebApplication application;
|
||||
protected final CBDatabase database;
|
||||
|
||||
public CBEmbeddedSecurityController(WebApplication application, CBDatabase database) {
|
||||
this.application = application;
|
||||
@@ -99,7 +101,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
// Users
|
||||
|
||||
@Override
|
||||
public void createUser(String userId, Map<String, String> metaParameters) throws DBCException {
|
||||
public void createUser(String userId, Map<String, String> metaParameters) throws DBException {
|
||||
if (isSubjectExists(userId)) {
|
||||
throw new DBCException("User or role '" + userId + "' already exists");
|
||||
}
|
||||
@@ -1624,6 +1626,18 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
}
|
||||
}
|
||||
|
||||
public void shutdown() {
|
||||
database.shutdown();
|
||||
}
|
||||
|
||||
public void finishConfiguration(
|
||||
@NotNull String adminName,
|
||||
@Nullable String adminPassword,
|
||||
@NotNull List<WebAuthInfo> authInfoList
|
||||
) throws DBException {
|
||||
database.finishConfiguration(adminName, adminPassword, authInfoList);
|
||||
}
|
||||
|
||||
///////////////////////////////////////////
|
||||
// Utils
|
||||
|
||||
+63
@@ -0,0 +1,63 @@
|
||||
/*
|
||||
* DBeaver - Universal Database Manager
|
||||
* Copyright (C) 2010-2022 DBeaver Corp and others
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
package io.cloudbeaver.service.security;
|
||||
|
||||
import com.google.gson.Gson;
|
||||
import com.google.gson.GsonBuilder;
|
||||
import com.google.gson.InstanceCreator;
|
||||
import io.cloudbeaver.model.app.WebApplication;
|
||||
import io.cloudbeaver.service.security.db.CBDatabase;
|
||||
import io.cloudbeaver.service.security.db.CBDatabaseConfig;
|
||||
import org.jkiss.dbeaver.DBException;
|
||||
|
||||
import java.util.Map;
|
||||
|
||||
/**
|
||||
* Embedded Security Controller Factory
|
||||
*/
|
||||
public class EmbeddedSecurityControllerFactory {
|
||||
|
||||
/**
|
||||
* Create new security controller instance
|
||||
*/
|
||||
public CBEmbeddedSecurityController createSecurityService(
|
||||
WebApplication application,
|
||||
Map<String, Object> databaseConfig
|
||||
) throws DBException {
|
||||
CBDatabaseConfig databaseConfiguration = new CBDatabaseConfig();
|
||||
InstanceCreator<CBDatabaseConfig> dbConfigCreator = type -> databaseConfiguration;
|
||||
InstanceCreator<CBDatabaseConfig.Pool> dbPoolConfigCreator = type -> databaseConfiguration.getPool();
|
||||
Gson gson = new GsonBuilder()
|
||||
.registerTypeAdapter(CBDatabaseConfig.class, dbConfigCreator)
|
||||
.registerTypeAdapter(CBDatabaseConfig.Pool.class, dbPoolConfigCreator)
|
||||
.create();
|
||||
gson.fromJson(gson.toJsonTree(databaseConfig), CBDatabaseConfig.class);
|
||||
|
||||
var database = new CBDatabase(application, databaseConfiguration);
|
||||
var securityController = createEmbeddedSecurityController(application, database);
|
||||
//FIXME circular dependency
|
||||
database.setAdminSecurityController(securityController);
|
||||
|
||||
database.initialize();
|
||||
securityController.initializeMetaInformation();
|
||||
return securityController;
|
||||
}
|
||||
|
||||
protected CBEmbeddedSecurityController createEmbeddedSecurityController(WebApplication application, CBDatabase database) {
|
||||
return new CBEmbeddedSecurityController(application, database);
|
||||
}
|
||||
}
|
||||
-84
@@ -1,84 +0,0 @@
|
||||
/*
|
||||
* DBeaver - Universal Database Manager
|
||||
* Copyright (C) 2010-2022 DBeaver Corp and others
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
package io.cloudbeaver.service.security;
|
||||
|
||||
import com.google.gson.Gson;
|
||||
import com.google.gson.GsonBuilder;
|
||||
import com.google.gson.InstanceCreator;
|
||||
import io.cloudbeaver.model.app.WebApplication;
|
||||
import io.cloudbeaver.model.session.WebAuthInfo;
|
||||
import io.cloudbeaver.service.security.internal.CBEmbeddedSecurityController;
|
||||
import io.cloudbeaver.service.security.internal.db.CBDatabase;
|
||||
import io.cloudbeaver.service.security.internal.db.CBDatabaseConfig;
|
||||
import org.jkiss.dbeaver.DBException;
|
||||
import org.jkiss.dbeaver.Log;
|
||||
import org.jkiss.dbeaver.model.security.SMAdminController;
|
||||
import org.jkiss.dbeaver.runtime.IPluginService;
|
||||
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
|
||||
public class SecurityPluginService implements IPluginService {
|
||||
private static final Log log = Log.getLog(SecurityPluginService.class);
|
||||
|
||||
private static CBDatabase DB_INSTANCE;
|
||||
private static CBEmbeddedSecurityController CONTROLLER_INSTANCE;
|
||||
|
||||
public static void finishConfiguration(String adminName, String adminPassword, List<WebAuthInfo> authInfoList) throws DBException {
|
||||
DB_INSTANCE.finishConfiguration(adminName, adminPassword, authInfoList);
|
||||
}
|
||||
|
||||
@Override
|
||||
public void activateService() {
|
||||
|
||||
}
|
||||
|
||||
public static synchronized SMAdminController createSecurityService(WebApplication application, Map<String, Object> databaseConfig) throws DBException {
|
||||
if (CONTROLLER_INSTANCE != null) {
|
||||
return CONTROLLER_INSTANCE;
|
||||
}
|
||||
CBDatabaseConfig databaseConfiguration = new CBDatabaseConfig();
|
||||
InstanceCreator<CBDatabaseConfig> dbConfigCreator = type -> databaseConfiguration;
|
||||
InstanceCreator<CBDatabaseConfig.Pool> dbPoolConfigCreator = type -> databaseConfiguration.getPool();
|
||||
Gson gson = new GsonBuilder()
|
||||
.registerTypeAdapter(CBDatabaseConfig.class, dbConfigCreator)
|
||||
.registerTypeAdapter(CBDatabaseConfig.Pool.class, dbPoolConfigCreator)
|
||||
.create();
|
||||
gson.fromJson(gson.toJsonTree(databaseConfig), CBDatabaseConfig.class);
|
||||
|
||||
DB_INSTANCE = new CBDatabase(application, databaseConfiguration);
|
||||
CONTROLLER_INSTANCE = new CBEmbeddedSecurityController(application, DB_INSTANCE);
|
||||
//FIXME circular dependency
|
||||
DB_INSTANCE.setAdminSecurityController(CONTROLLER_INSTANCE);
|
||||
|
||||
DB_INSTANCE.initialize();
|
||||
CONTROLLER_INSTANCE.initializeMetaInformation();
|
||||
return CONTROLLER_INSTANCE;
|
||||
}
|
||||
|
||||
@Override
|
||||
public void deactivateService() {
|
||||
if(DB_INSTANCE == null) {
|
||||
return;
|
||||
}
|
||||
try {
|
||||
DB_INSTANCE.shutdown();
|
||||
} catch (Exception e) {
|
||||
log.error(e);
|
||||
}
|
||||
}
|
||||
}
|
||||
+1
-1
@@ -14,7 +14,7 @@
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
package io.cloudbeaver.service.security.internal.db;
|
||||
package io.cloudbeaver.service.security.db;
|
||||
|
||||
import com.google.gson.Gson;
|
||||
import com.google.gson.GsonBuilder;
|
||||
+1
-1
@@ -14,7 +14,7 @@
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
package io.cloudbeaver.service.security.internal.db;
|
||||
package io.cloudbeaver.service.security.db;
|
||||
|
||||
/**
|
||||
* Database configuration
|
||||
+1
-1
@@ -14,7 +14,7 @@
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
package io.cloudbeaver.service.security.internal.db;
|
||||
package io.cloudbeaver.service.security.db;
|
||||
|
||||
import org.jkiss.dbeaver.model.security.user.SMRole;
|
||||
|
||||
+1
-1
@@ -16,7 +16,7 @@
|
||||
*/
|
||||
package io.cloudbeaver.service.security.internal.utils;
|
||||
|
||||
import io.cloudbeaver.service.security.internal.db.CBDatabaseConfig;
|
||||
import io.cloudbeaver.service.security.db.CBDatabaseConfig;
|
||||
import org.jkiss.code.Nullable;
|
||||
import org.jkiss.utils.CommonUtils;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user