mirror of
https://github.com/dbeaver/cloudbeaver.git
synced 2026-09-24 16:04:36 +08:00
CB-1430 Auth provider credentials profile API
This commit is contained in:
+7
-1
@@ -25,6 +25,7 @@ import io.cloudbeaver.server.CBPlatform;
|
||||
import org.jkiss.dbeaver.Log;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.Collections;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
|
||||
@@ -79,8 +80,13 @@ public class WebAuthProviderInfo {
|
||||
return result;
|
||||
}
|
||||
|
||||
public List<WebAuthProviderDescriptor.CredentialsProfile> getCredentialProfiles() {
|
||||
return descriptor.getCredentialProfiles();
|
||||
}
|
||||
|
||||
@Deprecated
|
||||
public List<WebAuthProviderPropertyDescriptor> getCredentialParameters() {
|
||||
return descriptor.getCredentialParameters();
|
||||
return descriptor.getCredentialParameters(Collections.emptySet());
|
||||
}
|
||||
|
||||
@Override
|
||||
|
||||
+83
-17
@@ -26,10 +26,7 @@ import org.jkiss.dbeaver.model.impl.PropertyDescriptor;
|
||||
import org.jkiss.utils.ArrayUtils;
|
||||
import org.jkiss.utils.CommonUtils;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.LinkedHashMap;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
import java.util.*;
|
||||
|
||||
/**
|
||||
* Auth service descriptor
|
||||
@@ -42,10 +39,50 @@ public class WebAuthProviderDescriptor extends AbstractDescriptor {
|
||||
private DBWAuthProvider<?> instance;
|
||||
private final DBPImage icon;
|
||||
private final Map<String, PropertyDescriptor> configurationParameters = new LinkedHashMap<>();
|
||||
private final Map<String, WebAuthProviderPropertyDescriptor> credentialParameters = new LinkedHashMap<>();
|
||||
private final List<CredentialsProfile> credentialProfiles = new ArrayList<>();
|
||||
private final boolean configurable;
|
||||
private final String[] requiredFeatures;
|
||||
|
||||
public static class CredentialsProfile {
|
||||
private final String id;
|
||||
private final String label;
|
||||
private final String description;
|
||||
private final Map<String, WebAuthProviderPropertyDescriptor> credentialParameters = new LinkedHashMap<>();
|
||||
public CredentialsProfile(IConfigurationElement cfg) {
|
||||
this.id = cfg.getAttribute("id");
|
||||
this.label = cfg.getAttribute("label");
|
||||
this.description = cfg.getAttribute("description");
|
||||
for (IConfigurationElement propGroup : ArrayUtils.safeArray(cfg.getChildren(PropertyDescriptor.TAG_PROPERTY_GROUP))) {
|
||||
String category = propGroup.getAttribute(PropertyDescriptor.ATTR_LABEL);
|
||||
IConfigurationElement[] propElements = propGroup.getChildren(PropertyDescriptor.TAG_PROPERTY);
|
||||
for (IConfigurationElement prop : propElements) {
|
||||
WebAuthProviderPropertyDescriptor propertyDescriptor = new WebAuthProviderPropertyDescriptor(category, prop);
|
||||
credentialParameters.put(CommonUtils.toString(propertyDescriptor.getId()), propertyDescriptor);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
public String getId() {
|
||||
return id;
|
||||
}
|
||||
|
||||
public String getLabel() {
|
||||
return label;
|
||||
}
|
||||
|
||||
public String getDescription() {
|
||||
return description;
|
||||
}
|
||||
|
||||
public List<WebAuthProviderPropertyDescriptor> getCredentialParameters() {
|
||||
return new ArrayList<>(credentialParameters.values());
|
||||
}
|
||||
|
||||
public WebAuthProviderPropertyDescriptor getCredentialParameter(String id) {
|
||||
return credentialParameters.get(id);
|
||||
}
|
||||
}
|
||||
|
||||
public WebAuthProviderDescriptor(IConfigurationElement cfg) {
|
||||
super(cfg);
|
||||
this.cfg = cfg;
|
||||
@@ -64,14 +101,7 @@ public class WebAuthProviderDescriptor extends AbstractDescriptor {
|
||||
}
|
||||
}
|
||||
for (IConfigurationElement credElement : cfg.getChildren("credentials")) {
|
||||
for (IConfigurationElement propGroup : ArrayUtils.safeArray(credElement.getChildren(PropertyDescriptor.TAG_PROPERTY_GROUP))) {
|
||||
String category = propGroup.getAttribute(PropertyDescriptor.ATTR_LABEL);
|
||||
IConfigurationElement[] propElements = propGroup.getChildren(PropertyDescriptor.TAG_PROPERTY);
|
||||
for (IConfigurationElement prop : propElements) {
|
||||
WebAuthProviderPropertyDescriptor propertyDescriptor = new WebAuthProviderPropertyDescriptor(category, prop);
|
||||
credentialParameters.put(CommonUtils.toString(propertyDescriptor.getId()), propertyDescriptor);
|
||||
}
|
||||
}
|
||||
credentialProfiles.add(new CredentialsProfile(credElement));
|
||||
}
|
||||
|
||||
String rfList = cfg.getAttribute("requiredFeatures");
|
||||
@@ -107,12 +137,48 @@ public class WebAuthProviderDescriptor extends AbstractDescriptor {
|
||||
return new ArrayList<>(configurationParameters.values());
|
||||
}
|
||||
|
||||
public List<WebAuthProviderPropertyDescriptor> getCredentialParameters() {
|
||||
return new ArrayList<>(credentialParameters.values());
|
||||
public List<CredentialsProfile> getCredentialProfiles() {
|
||||
return new ArrayList<>(credentialProfiles);
|
||||
}
|
||||
|
||||
public WebAuthProviderPropertyDescriptor getCredentialParameter(String id) {
|
||||
return credentialParameters.get(id);
|
||||
public CredentialsProfile getCredentialProfileByParameters(Set<String> keySet) {
|
||||
if (credentialProfiles.size() > 1) {
|
||||
for (CredentialsProfile profile : credentialProfiles) {
|
||||
if (profile.getCredentialParameters().size() == keySet.size()) {
|
||||
boolean matches = true;
|
||||
for (String paramName : keySet) {
|
||||
if (profile.getCredentialParameter(paramName) == null) {
|
||||
matches = false;
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (matches) {
|
||||
return profile;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
return credentialProfiles.get(0);
|
||||
}
|
||||
|
||||
public List<WebAuthProviderPropertyDescriptor> getCredentialParameters(Set<String> keySet) {
|
||||
if (credentialProfiles.size() > 1) {
|
||||
for (CredentialsProfile profile : credentialProfiles) {
|
||||
if (profile.getCredentialParameters().size() == keySet.size()) {
|
||||
boolean matches = true;
|
||||
for (String paramName : keySet) {
|
||||
if (profile.getCredentialParameter(paramName) == null) {
|
||||
matches = false;
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (matches) {
|
||||
return profile.getCredentialParameters();
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
return credentialProfiles.get(0).getCredentialParameters();
|
||||
}
|
||||
|
||||
@NotNull
|
||||
|
||||
+4
-4
@@ -26,10 +26,10 @@ import org.jkiss.utils.CommonUtils;
|
||||
*/
|
||||
public class WebAuthProviderPropertyDescriptor extends PropertyDescriptor {
|
||||
|
||||
private WebAuthProviderPropertyEncryption encryption;
|
||||
private boolean identifying; // Identifying parameter. Will be used during auth for user search by credentials
|
||||
private boolean admin; // Parameter value can be configured in admin panel
|
||||
private boolean user; // Parameter can be passed by end-user from UI
|
||||
private final WebAuthProviderPropertyEncryption encryption;
|
||||
private final boolean identifying; // Identifying parameter. Will be used during auth for user search by credentials
|
||||
private final boolean admin; // Parameter value can be configured in admin panel
|
||||
private final boolean user; // Parameter can be passed by end-user from UI
|
||||
|
||||
public WebAuthProviderPropertyDescriptor(String category, IConfigurationElement config) {
|
||||
super(category, config);
|
||||
|
||||
+3
-2
@@ -272,9 +272,10 @@ class CBSecurityController implements DBWSecurityController {
|
||||
public void setUserCredentials(String userId, WebAuthProviderDescriptor authProvider, Map<String, Object> credentials) throws DBCException {
|
||||
List<String[]> transformedCredentials;
|
||||
try {
|
||||
WebAuthProviderDescriptor.CredentialsProfile credProfile = authProvider.getCredentialProfileByParameters(credentials.keySet());
|
||||
transformedCredentials = credentials.entrySet().stream().map(cred -> {
|
||||
String propertyName = cred.getKey();
|
||||
WebAuthProviderPropertyDescriptor property = authProvider.getCredentialParameter(propertyName);
|
||||
WebAuthProviderPropertyDescriptor property = credProfile.getCredentialParameter(propertyName);
|
||||
if (property == null) {
|
||||
return null;
|
||||
}
|
||||
@@ -313,7 +314,7 @@ class CBSecurityController implements DBWSecurityController {
|
||||
@Override
|
||||
public String getUserByCredentials(WebAuthProviderDescriptor authProvider, Map<String, Object> authParameters) throws DBCException {
|
||||
Map<String, Object> identCredentials = new LinkedHashMap<>();
|
||||
for (WebAuthProviderPropertyDescriptor prop : authProvider.getCredentialParameters()) {
|
||||
for (WebAuthProviderPropertyDescriptor prop : authProvider.getCredentialParameters(authParameters.keySet())) {
|
||||
if (prop.isIdentifying()) {
|
||||
String propId = CommonUtils.toString(prop.getId());
|
||||
Object paramValue = authParameters.get(propId);
|
||||
|
||||
@@ -36,6 +36,13 @@ type AuthProviderConfiguration {
|
||||
metadataLink: String
|
||||
}
|
||||
|
||||
type AuthProviderCredentialsProfile {
|
||||
id: String
|
||||
label: String
|
||||
description: String
|
||||
credentialParameters: [AuthCredentialInfo!]!
|
||||
}
|
||||
|
||||
type AuthProviderInfo {
|
||||
id: ID!
|
||||
label: String!
|
||||
@@ -50,7 +57,9 @@ type AuthProviderInfo {
|
||||
# Provider configurations (applicable only if configurable=true)
|
||||
configurations: [AuthProviderConfiguration!]
|
||||
|
||||
credentialParameters: [AuthCredentialInfo!]!
|
||||
crdentialProfiles: [AuthProviderCredentialsProfile!]!
|
||||
|
||||
credentialParameters: [AuthCredentialInfo!]! @deprecated
|
||||
}
|
||||
|
||||
type UserAuthToken {
|
||||
|
||||
Reference in New Issue
Block a user