mirror of
https://github.com/dbeaver/cloudbeaver.git
synced 2026-09-24 16:04:36 +08:00
CB-1001 Add default permissions to new role
This commit is contained in:
@@ -24,4 +24,6 @@ public class DBWConstants {
|
||||
public static final String PERMISSION_PUBLIC = "public";
|
||||
|
||||
public static final String PERMISSION_ADMIN = "admin";
|
||||
public static final String PERMISSION_USER = "user";
|
||||
|
||||
}
|
||||
|
||||
@@ -86,7 +86,7 @@ public interface DBWSecurityController {
|
||||
@NotNull
|
||||
String[] getRoleSubjects(String roleId) throws DBCException;
|
||||
|
||||
void createRole(WebRole role) throws DBCException;
|
||||
void createRole(WebRole role, String grantor) throws DBCException;
|
||||
|
||||
void updateRole(WebRole role) throws DBCException;
|
||||
|
||||
|
||||
@@ -302,7 +302,7 @@ public class CBDatabase {
|
||||
if (!CommonUtils.isEmpty(initialData.getRoles())) {
|
||||
// Create roles
|
||||
for (WebRole role : initialData.getRoles()) {
|
||||
serverController.createRole(role);
|
||||
serverController.createRole(role, adminName);
|
||||
if (adminName != null) {
|
||||
serverController.setSubjectPermissions(role.getRoleId(), role.getPermissions().toArray(new String[0]), adminName);
|
||||
}
|
||||
|
||||
+21
-12
@@ -17,6 +17,7 @@
|
||||
package io.cloudbeaver.server;
|
||||
|
||||
import io.cloudbeaver.DBWConnectionGrant;
|
||||
import io.cloudbeaver.DBWConstants;
|
||||
import io.cloudbeaver.DBWSecurityController;
|
||||
import io.cloudbeaver.DBWSecuritySubjectType;
|
||||
import io.cloudbeaver.model.session.WebSession;
|
||||
@@ -464,7 +465,7 @@ class CBSecurityController implements DBWSecurityController {
|
||||
}
|
||||
|
||||
@Override
|
||||
public void createRole(WebRole role) throws DBCException {
|
||||
public void createRole(WebRole role, String grantor) throws DBCException {
|
||||
if (isSubjectExists(role.getRoleId())) {
|
||||
throw new DBCException("User or role '" + role.getRoleId() + "' already exists");
|
||||
}
|
||||
@@ -479,6 +480,10 @@ class CBSecurityController implements DBWSecurityController {
|
||||
dbStat.setTimestamp(4, new Timestamp(System.currentTimeMillis()));
|
||||
dbStat.execute();
|
||||
}
|
||||
|
||||
insertPermissions(dbCon, role.getRoleId(),
|
||||
new String[] {DBWConstants.PERMISSION_PUBLIC, DBWConstants.PERMISSION_USER} , grantor);
|
||||
|
||||
txn.commit();
|
||||
}
|
||||
} catch (SQLException e) {
|
||||
@@ -534,17 +539,7 @@ class CBSecurityController implements DBWSecurityController {
|
||||
try (Connection dbCon = database.openConnection()) {
|
||||
try (JDBCTransaction txn = new JDBCTransaction(dbCon)) {
|
||||
JDBCUtils.executeStatement(dbCon, "DELETE FROM CB_AUTH_PERMISSIONS WHERE SUBJECT_ID=?", subjectId);
|
||||
if (!ArrayUtils.isEmpty(permissionIds)) {
|
||||
try (PreparedStatement dbStat = dbCon.prepareStatement("INSERT INTO CB_AUTH_PERMISSIONS(SUBJECT_ID,PERMISSION_ID,GRANT_TIME,GRANTED_BY) VALUES(?,?,?,?)")) {
|
||||
for (String permission : permissionIds) {
|
||||
dbStat.setString(1, subjectId);
|
||||
dbStat.setString(2, permission);
|
||||
dbStat.setTimestamp(3, new Timestamp(System.currentTimeMillis()));
|
||||
dbStat.setString(4, grantorId);
|
||||
dbStat.execute();
|
||||
}
|
||||
}
|
||||
}
|
||||
insertPermissions(dbCon, subjectId, permissionIds, grantorId);
|
||||
txn.commit();
|
||||
}
|
||||
} catch (SQLException e) {
|
||||
@@ -552,6 +547,20 @@ class CBSecurityController implements DBWSecurityController {
|
||||
}
|
||||
}
|
||||
|
||||
private void insertPermissions(Connection dbCon, String subjectId, String[] permissionIds, String grantorId) throws SQLException {
|
||||
if (!ArrayUtils.isEmpty(permissionIds)) {
|
||||
try (PreparedStatement dbStat = dbCon.prepareStatement("INSERT INTO CB_AUTH_PERMISSIONS(SUBJECT_ID,PERMISSION_ID,GRANT_TIME,GRANTED_BY) VALUES(?,?,?,?)")) {
|
||||
for (String permission : permissionIds) {
|
||||
dbStat.setString(1, subjectId);
|
||||
dbStat.setString(2, permission);
|
||||
dbStat.setTimestamp(3, new Timestamp(System.currentTimeMillis()));
|
||||
dbStat.setString(4, grantorId);
|
||||
dbStat.execute();
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@NotNull
|
||||
@Override
|
||||
public Set<String> getSubjectPermissions(String subjectId) throws DBCException {
|
||||
|
||||
+1
-1
@@ -155,7 +155,7 @@ public class WebServiceAdmin implements DBWServiceAdmin {
|
||||
WebRole newRole = new WebRole(roleId);
|
||||
newRole.setName(roleName);
|
||||
newRole.setDescription(description);
|
||||
CBPlatform.getInstance().getApplication().getSecurityController().createRole(newRole);
|
||||
CBPlatform.getInstance().getApplication().getSecurityController().createRole(newRole, webSession.getUser().getUserId());
|
||||
return new AdminRoleInfo(newRole);
|
||||
} catch (Exception e) {
|
||||
throw new DBWebException("Error creating new role", e);
|
||||
|
||||
Reference in New Issue
Block a user