This commit is contained in:
Serge Rider
2021-12-29 17:02:59 +03:00
parent 77a925e223
commit b74ef427fb
17 changed files with 89 additions and 262 deletions
@@ -24,7 +24,8 @@ import org.jkiss.code.NotNull;
import org.jkiss.code.Nullable;
import org.jkiss.dbeaver.DBException;
import org.jkiss.dbeaver.model.DBPObject;
import org.jkiss.dbeaver.model.access.DBASession;
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
import org.jkiss.dbeaver.model.auth.DBASession;
import org.jkiss.dbeaver.model.runtime.DBRProgressMonitor;
import java.util.Map;
@@ -33,7 +34,7 @@ import java.util.Map;
* External auth provider.
* Authenticates user using external user identity
*/
public interface DBWAuthProviderExternal<AUTH_SESSION extends DBASession> extends DBWAuthProvider<AUTH_SESSION> {
public interface DBAAuthProviderExternal<AUTH_SESSION extends DBASession> extends DBAAuthProvider<AUTH_SESSION> {
/**
* Returns new identifying credentials which can be used to find/create user in database
@@ -1,41 +0,0 @@
/*
* DBeaver - Universal Database Manager
* Copyright (C) 2010-2021 DBeaver Corp and others
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package io.cloudbeaver.auth;
import io.cloudbeaver.model.session.WebSession;
import org.jkiss.code.NotNull;
import org.jkiss.dbeaver.DBException;
import org.jkiss.dbeaver.model.access.DBASession;
import java.util.Map;
/**
* Auth provider
*/
public interface DBWAuthProvider<AUTH_SESSION extends DBASession> {
AUTH_SESSION openSession(
@NotNull WebSession mainSession,
@NotNull Map<String, Object> providerConfig, // Auth provider configuration (e.g. 3rd party auth server address)
@NotNull Map<String, Object> userCredentials // Saved user credentials (e.g. associated 3rd party provider user name or realm)
) throws DBException;
void closeSession(@NotNull WebSession mainSession, AUTH_SESSION session) throws DBException;
void refreshSession(@NotNull WebSession mainSession, AUTH_SESSION session) throws DBException;
}
@@ -16,15 +16,15 @@
*/
package io.cloudbeaver.auth.provider;
import io.cloudbeaver.auth.DBWAuthProviderExternal;
import io.cloudbeaver.auth.DBAAuthProviderExternal;
import io.cloudbeaver.model.user.WebUser;
import org.jkiss.dbeaver.model.access.DBASession;
import org.jkiss.dbeaver.model.auth.DBASession;
import org.jkiss.utils.CommonUtils;
/**
* Abstract external auth provider
*/
public abstract class AbstractExternalAuthProvider<SESSION extends DBASession> implements DBWAuthProviderExternal<SESSION> {
public abstract class AbstractExternalAuthProvider<SESSION extends DBASession> implements DBAAuthProviderExternal<SESSION> {
public static final String META_AUTH_PROVIDER = "$provider";
public static final String META_AUTH_SPACE_ID = "$space";
@@ -17,13 +17,10 @@
package io.cloudbeaver.auth.provider.fa;
import io.cloudbeaver.model.session.WebSession;
import org.jkiss.code.NotNull;
import org.jkiss.code.Nullable;
import org.jkiss.dbeaver.model.access.DBASessionFederated;
import org.jkiss.dbeaver.model.access.DBASessionPrincipal;
import org.jkiss.dbeaver.model.app.DBPProject;
import org.jkiss.dbeaver.model.auth.DBAAuthSpace;
import org.jkiss.dbeaver.model.auth.*;
import java.util.Map;
@@ -32,11 +29,11 @@ public abstract class AbstractSessionFederated implements DBASessionFederated {
@NotNull
protected final Map<String, Object> authParameters;
@NotNull
protected final WebSession parentSession;
protected final DBASession parentSession;
@NotNull
protected final DBAAuthSpace space;
protected AbstractSessionFederated(@NotNull WebSession parentSession, @NotNull DBAAuthSpace space, @NotNull Map<String, Object> authParameters) {
protected AbstractSessionFederated(@NotNull DBASession parentSession, @NotNull DBAAuthSpace space, @NotNull Map<String, Object> authParameters) {
this.parentSession = parentSession;
this.space = space;
this.authParameters = authParameters;
@@ -48,6 +45,12 @@ public abstract class AbstractSessionFederated implements DBASessionFederated {
return space;
}
@NotNull
@Override
public DBASessionContext getSessionContext() {
return this.parentSession.getSessionContext();
}
@Override
public DBASessionPrincipal getSessionPrincipal() {
return parentSession.getSessionPrincipal();
@@ -16,30 +16,32 @@
*/
package io.cloudbeaver.auth.provider.local;
import io.cloudbeaver.auth.DBWAuthProvider;
import io.cloudbeaver.model.session.WebSession;
import io.cloudbeaver.registry.WebAuthProviderDescriptor;
import io.cloudbeaver.registry.WebAuthProviderPropertyEncryption;
import io.cloudbeaver.registry.WebServiceRegistry;
import io.cloudbeaver.server.CBApplication;
import org.jkiss.code.NotNull;
import org.jkiss.dbeaver.DBException;
import org.jkiss.dbeaver.model.auth.AuthPropertyEncryption;
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
import org.jkiss.dbeaver.model.auth.DBASession;
import org.jkiss.dbeaver.model.runtime.DBRProgressMonitor;
import org.jkiss.utils.CommonUtils;
import org.jkiss.utils.SecurityUtils;
import java.util.Map;
/**
* Auth provider
* Local auth provider
*/
public class LocalAuthProvider implements DBWAuthProvider<LocalAuthSession> {
public class LocalAuthProvider implements DBAAuthProvider<LocalAuthSession> {
public static final String PROVIDER_ID = "local";
public static final String CRED_USER = "user";
public static final String CRED_PASSWORD = "password";
@Override
public LocalAuthSession openSession(@NotNull WebSession mainSession, @NotNull Map<String, Object> providerConfig, @NotNull Map<String, Object> userCredentials) throws DBException {
public LocalAuthSession openSession(@NotNull DBRProgressMonitor monitor, @NotNull DBASession mainSession, @NotNull Map<String, Object> providerConfig, @NotNull Map<String, Object> userCredentials) throws DBException {
String userName = CommonUtils.toString(userCredentials.get(CRED_USER), null);
WebAuthProviderDescriptor authProvider = WebServiceRegistry.getInstance().getAuthProvider(PROVIDER_ID);
@@ -56,7 +58,7 @@ public class LocalAuthProvider implements DBWAuthProvider<LocalAuthSession> {
if (CommonUtils.isEmpty(clientPassword)) {
throw new DBException("No user password provided");
}
String clientPasswordHash = WebAuthProviderPropertyEncryption.hash.encrypt(userName, clientPassword);
String clientPasswordHash = AuthPropertyEncryption.hash.encrypt(userName, clientPassword);
if (!storedPasswordHash.equals(clientPasswordHash)) {
throw new DBException("Invalid user name or password");
}
@@ -64,12 +66,12 @@ public class LocalAuthProvider implements DBWAuthProvider<LocalAuthSession> {
}
@Override
public void closeSession(@NotNull WebSession mainSession, LocalAuthSession localAuthSession) throws DBException {
public void closeSession(@NotNull DBASession mainSession, LocalAuthSession localAuthSession) throws DBException {
}
@Override
public void refreshSession(@NotNull WebSession mainSession, LocalAuthSession localAuthSession) throws DBException {
public void refreshSession(@NotNull DBRProgressMonitor monitor, @NotNull DBASession mainSession, LocalAuthSession localAuthSession) throws DBException {
}
@@ -92,7 +94,7 @@ public class LocalAuthProvider implements DBWAuthProvider<LocalAuthSession> {
if (CommonUtils.isEmpty(oldPassword)) {
throw new DBException("No user password provided");
}
String oldPasswordHash = WebAuthProviderPropertyEncryption.hash.encrypt(userName, oldPassword);
String oldPasswordHash = AuthPropertyEncryption.hash.encrypt(userName, oldPassword);
if (!storedPasswordHash.equals(oldPasswordHash)) {
throw new DBException("Invalid user name or password");
}
@@ -16,23 +16,23 @@
*/
package io.cloudbeaver.auth.provider.local;
import io.cloudbeaver.model.session.WebSession;
import org.jkiss.code.NotNull;
import org.jkiss.code.Nullable;
import org.jkiss.dbeaver.model.access.DBASession;
import org.jkiss.dbeaver.model.access.DBASessionPrincipal;
import org.jkiss.dbeaver.model.app.DBPProject;
import org.jkiss.dbeaver.model.auth.DBAAuthSpace;
import org.jkiss.dbeaver.model.auth.DBASession;
import org.jkiss.dbeaver.model.auth.DBASessionContext;
import org.jkiss.dbeaver.model.auth.DBASessionPrincipal;
/**
* Local auth provider
*/
public class LocalAuthSession implements DBASession {
private final WebSession webSession;
private final DBASession webSession;
private final String userId;
LocalAuthSession(WebSession webSession, String userId) {
LocalAuthSession(DBASession webSession, String userId) {
this.webSession = webSession;
this.userId = userId;
}
@@ -47,6 +47,12 @@ public class LocalAuthSession implements DBASession {
return webSession.getSingletonProject();
}
@NotNull
@Override
public DBASessionContext getSessionContext() {
return webSession.getSessionContext();
}
@Override
public DBASessionPrincipal getSessionPrincipal() {
return webSession.getSessionPrincipal();
@@ -66,7 +72,7 @@ public class LocalAuthSession implements DBASession {
@Nullable
@Override
public DBPProject getSingletonProject() {
return null;
return webSession.getSingletonProject();
}
}
@@ -17,15 +17,15 @@
package io.cloudbeaver.model.session;
import io.cloudbeaver.DBWUserIdentity;
import io.cloudbeaver.auth.DBWAuthProvider;
import io.cloudbeaver.model.user.WebAuthProviderConfiguration;
import io.cloudbeaver.model.user.WebUser;
import io.cloudbeaver.model.user.WebUserOriginInfo;
import io.cloudbeaver.registry.WebAuthProviderDescriptor;
import org.jkiss.code.NotNull;
import org.jkiss.dbeaver.Log;
import org.jkiss.dbeaver.model.access.DBASession;
import org.jkiss.dbeaver.model.access.DBASessionPrincipal;
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
import org.jkiss.dbeaver.model.auth.DBASession;
import org.jkiss.dbeaver.model.auth.DBASessionPrincipal;
import org.jkiss.dbeaver.model.meta.Property;
import java.time.OffsetDateTime;
@@ -132,7 +132,7 @@ public class WebAuthInfo implements DBASessionPrincipal {
void closeAuth() {
if (authProvider != null && authSession != null) {
try {
DBWAuthProvider authProviderInstance = this.authProvider.getInstance();
DBAAuthProvider authProviderInstance = this.authProvider.getInstance();
authProviderInstance.closeSession(session, authSession);
} catch (Exception e) {
log.error(e);
@@ -33,13 +33,9 @@ import org.jkiss.code.Nullable;
import org.jkiss.dbeaver.DBException;
import org.jkiss.dbeaver.Log;
import org.jkiss.dbeaver.model.DBPDataSourceContainer;
import org.jkiss.dbeaver.model.access.DBASession;
import org.jkiss.dbeaver.model.access.DBASessionPrincipal;
import org.jkiss.dbeaver.model.app.DBPDataSourceRegistry;
import org.jkiss.dbeaver.model.app.DBPProject;
import org.jkiss.dbeaver.model.auth.DBAAuthCredentialsProvider;
import org.jkiss.dbeaver.model.auth.DBAAuthSpace;
import org.jkiss.dbeaver.model.auth.DBASessionContext;
import org.jkiss.dbeaver.model.auth.*;
import org.jkiss.dbeaver.model.connection.DBPConnectionConfiguration;
import org.jkiss.dbeaver.model.exec.DBCException;
import org.jkiss.dbeaver.model.impl.auth.AuthModelDatabaseNative;
@@ -167,6 +163,7 @@ public class WebSession implements DBASession, DBAAuthCredentialsProvider, IAdap
return sessionProject;
}
@NotNull
public DBASessionContext getSessionContext() {
return sessionProject.getSessionContext();
}
@@ -16,12 +16,12 @@
*/
package io.cloudbeaver.model.user;
import io.cloudbeaver.auth.DBWAuthProvider;
import io.cloudbeaver.auth.DBWAuthProviderFederated;
import io.cloudbeaver.auth.provider.AuthProviderConfig;
import io.cloudbeaver.registry.WebAuthProviderDescriptor;
import org.jkiss.dbeaver.DBException;
import org.jkiss.dbeaver.Log;
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
import org.jkiss.dbeaver.model.meta.Property;
import java.util.Map;
@@ -73,19 +73,19 @@ public class WebAuthProviderConfiguration {
@Property
public String getSignInLink() throws DBException {
DBWAuthProvider<?> instance = providerDescriptor.getInstance();
DBAAuthProvider<?> instance = providerDescriptor.getInstance();
return instance instanceof DBWAuthProviderFederated ? ((DBWAuthProviderFederated) instance).getSignInLink(getId(), config.getParameters()) : null;
}
@Property
public String getSignOutLink() throws DBException {
DBWAuthProvider<?> instance = providerDescriptor.getInstance();
DBAAuthProvider<?> instance = providerDescriptor.getInstance();
return instance instanceof DBWAuthProviderFederated ? ((DBWAuthProviderFederated) instance).getSignOutLink(getId(), config.getParameters()) : null;
}
@Property
public String getMetadataLink() throws DBException {
DBWAuthProvider<?> instance = providerDescriptor.getInstance();
DBAAuthProvider<?> instance = providerDescriptor.getInstance();
return instance instanceof DBWAuthProviderFederated ? ((DBWAuthProviderFederated) instance).getMetadataLink(getId(), config.getParameters()) : null;
}
@@ -22,6 +22,7 @@ import io.cloudbeaver.registry.WebAuthProviderDescriptor;
import io.cloudbeaver.server.CBApplication;
import io.cloudbeaver.server.CBPlatform;
import org.jkiss.dbeaver.Log;
import org.jkiss.dbeaver.model.auth.DBAAuthCredentialsProfile;
import java.util.ArrayList;
import java.util.List;
@@ -78,7 +79,7 @@ public class WebAuthProviderInfo {
return result;
}
public List<WebAuthProviderDescriptor.CredentialsProfile> getCredentialProfiles() {
public List<DBAAuthCredentialsProfile> getCredentialProfiles() {
return descriptor.getCredentialProfiles();
}
@@ -18,8 +18,7 @@ package io.cloudbeaver.model.user;
import io.cloudbeaver.DBWebException;
import io.cloudbeaver.WebServiceUtils;
import io.cloudbeaver.auth.DBWAuthProvider;
import io.cloudbeaver.auth.DBWAuthProviderExternal;
import io.cloudbeaver.auth.DBAAuthProviderExternal;
import io.cloudbeaver.auth.provider.local.LocalAuthProvider;
import io.cloudbeaver.model.WebObjectOrigin;
import io.cloudbeaver.model.WebPropertyInfo;
@@ -31,7 +30,8 @@ import org.jkiss.code.Nullable;
import org.jkiss.dbeaver.DBException;
import org.jkiss.dbeaver.Log;
import org.jkiss.dbeaver.model.DBPObject;
import org.jkiss.dbeaver.model.access.DBASession;
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
import org.jkiss.dbeaver.model.auth.DBASession;
import org.jkiss.dbeaver.model.meta.Property;
import java.lang.reflect.ParameterizedType;
@@ -101,12 +101,12 @@ public class WebUserOriginInfo implements WebObjectOrigin {
throw new DBException("Session not authorized in auth provider '" + authProvider.getId() + "'");
}
DBASession authSession = authInfo.getAuthSession();
DBWAuthProvider<?> authProvider = this.authProvider.getInstance();
if (authSession != null && authProvider instanceof DBWAuthProviderExternal) {
DBAAuthProvider<?> authProvider = this.authProvider.getInstance();
if (authSession != null && authProvider instanceof DBAAuthProviderExternal) {
if (!isValidSessionType(authSession, authProvider)) {
return new WebPropertyInfo[0];
}
DBPObject userDetails = ((DBWAuthProviderExternal) authProvider).getUserDetails(
DBPObject userDetails = ((DBAAuthProviderExternal) authProvider).getUserDetails(
session.getProgressMonitor(),
session,
authSession,
@@ -122,7 +122,7 @@ public class WebUserOriginInfo implements WebObjectOrigin {
return new WebPropertyInfo[0];
}
private static boolean isValidSessionType(DBASession authSession, DBWAuthProvider<?> authProvider) {
private static boolean isValidSessionType(DBASession authSession, DBAAuthProvider<?> authProvider) {
Type providerSuperClass = authProvider.getClass().getGenericSuperclass();
if (providerSuperClass instanceof ParameterizedType) {
Type[] typeArguments = ((ParameterizedType) providerSuperClass).getActualTypeArguments();
@@ -16,11 +16,14 @@
*/
package io.cloudbeaver.registry;
import io.cloudbeaver.auth.DBWAuthProvider;
import org.eclipse.core.runtime.IConfigurationElement;
import org.jkiss.code.NotNull;
import org.jkiss.dbeaver.DBException;
import org.jkiss.dbeaver.model.DBPImage;
import org.jkiss.dbeaver.model.auth.AuthPropertyDescriptor;
import org.jkiss.dbeaver.model.auth.DBAAuthCredentialsProfile;
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
import org.jkiss.dbeaver.model.auth.DBAAuthProviderDescriptor;
import org.jkiss.dbeaver.model.impl.AbstractDescriptor;
import org.jkiss.dbeaver.model.impl.PropertyDescriptor;
import org.jkiss.utils.ArrayUtils;
@@ -31,58 +34,18 @@ import java.util.*;
/**
* Auth service descriptor
*/
public class WebAuthProviderDescriptor extends AbstractDescriptor {
public class WebAuthProviderDescriptor extends AbstractDescriptor implements DBAAuthProviderDescriptor {
private final IConfigurationElement cfg;
private final ObjectType implType;
private DBWAuthProvider<?> instance;
private DBAAuthProvider<?> instance;
private final DBPImage icon;
private final Map<String, PropertyDescriptor> configurationParameters = new LinkedHashMap<>();
private final List<CredentialsProfile> credentialProfiles = new ArrayList<>();
private final List<DBAAuthCredentialsProfile> credentialProfiles = new ArrayList<>();
private final boolean configurable;
private final String[] requiredFeatures;
public static class CredentialsProfile {
private final String id;
private final String label;
private final String description;
private final Map<String, WebAuthProviderPropertyDescriptor> credentialParameters = new LinkedHashMap<>();
public CredentialsProfile(IConfigurationElement cfg) {
this.id = cfg.getAttribute("id");
this.label = cfg.getAttribute("label");
this.description = cfg.getAttribute("description");
for (IConfigurationElement propGroup : ArrayUtils.safeArray(cfg.getChildren(PropertyDescriptor.TAG_PROPERTY_GROUP))) {
String category = propGroup.getAttribute(PropertyDescriptor.ATTR_LABEL);
IConfigurationElement[] propElements = propGroup.getChildren(PropertyDescriptor.TAG_PROPERTY);
for (IConfigurationElement prop : propElements) {
WebAuthProviderPropertyDescriptor propertyDescriptor = new WebAuthProviderPropertyDescriptor(category, prop);
credentialParameters.put(CommonUtils.toString(propertyDescriptor.getId()), propertyDescriptor);
}
}
}
public String getId() {
return id;
}
public String getLabel() {
return label;
}
public String getDescription() {
return description;
}
public List<WebAuthProviderPropertyDescriptor> getCredentialParameters() {
return new ArrayList<>(credentialParameters.values());
}
public WebAuthProviderPropertyDescriptor getCredentialParameter(String id) {
return credentialParameters.get(id);
}
}
public WebAuthProviderDescriptor(IConfigurationElement cfg) {
super(cfg);
this.cfg = cfg;
@@ -101,7 +64,7 @@ public class WebAuthProviderDescriptor extends AbstractDescriptor {
}
}
for (IConfigurationElement credElement : cfg.getChildren("credentials")) {
credentialProfiles.add(new CredentialsProfile(credElement));
credentialProfiles.add(new DBAAuthCredentialsProfile(credElement));
}
String rfList = cfg.getAttribute("requiredFeatures");
@@ -137,13 +100,13 @@ public class WebAuthProviderDescriptor extends AbstractDescriptor {
return new ArrayList<>(configurationParameters.values());
}
public List<CredentialsProfile> getCredentialProfiles() {
public List<DBAAuthCredentialsProfile> getCredentialProfiles() {
return new ArrayList<>(credentialProfiles);
}
public CredentialsProfile getCredentialProfileByParameters(Set<String> keySet) {
public DBAAuthCredentialsProfile getCredentialProfileByParameters(Set<String> keySet) {
if (credentialProfiles.size() > 1) {
for (CredentialsProfile profile : credentialProfiles) {
for (DBAAuthCredentialsProfile profile : credentialProfiles) {
if (profile.getCredentialParameters().size() == keySet.size()) {
boolean matches = true;
for (String paramName : keySet) {
@@ -161,9 +124,9 @@ public class WebAuthProviderDescriptor extends AbstractDescriptor {
return credentialProfiles.get(0);
}
public List<WebAuthProviderPropertyDescriptor> getCredentialParameters(Set<String> keySet) {
public List<AuthPropertyDescriptor> getCredentialParameters(Set<String> keySet) {
if (credentialProfiles.size() > 1) {
for (CredentialsProfile profile : credentialProfiles) {
for (DBAAuthCredentialsProfile profile : credentialProfiles) {
if (profile.getCredentialParameters().size() == keySet.size()) {
boolean matches = true;
for (String paramName : keySet) {
@@ -182,10 +145,10 @@ public class WebAuthProviderDescriptor extends AbstractDescriptor {
}
@NotNull
public DBWAuthProvider<?> getInstance() {
public DBAAuthProvider<?> getInstance() {
if (instance == null) {
try {
instance = implType.createInstance(DBWAuthProvider.class);
instance = implType.createInstance(DBAAuthProvider.class);
} catch (DBException e) {
throw new IllegalStateException("Can not instantiate auth provider '" + implType.getImplName() + "'", e);
}
@@ -1,58 +0,0 @@
/*
* DBeaver - Universal Database Manager
* Copyright (C) 2010-2021 DBeaver Corp and others
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package io.cloudbeaver.registry;
import org.eclipse.core.runtime.IConfigurationElement;
import org.jkiss.dbeaver.model.impl.PropertyDescriptor;
import org.jkiss.utils.CommonUtils;
/**
* Auth provider property.
* Has some extra attributes.
*/
public class WebAuthProviderPropertyDescriptor extends PropertyDescriptor {
private final WebAuthProviderPropertyEncryption encryption;
private final boolean identifying; // Identifying parameter. Will be used during auth for user search by credentials
private final boolean admin; // Parameter value can be configured in admin panel
private final boolean user; // Parameter can be passed by end-user from UI
public WebAuthProviderPropertyDescriptor(String category, IConfigurationElement config) {
super(category, config);
this.encryption = CommonUtils.valueOf(WebAuthProviderPropertyEncryption.class, config.getAttribute("encryption"), WebAuthProviderPropertyEncryption.none);
this.identifying = CommonUtils.getBoolean(config.getAttribute("identifying"), false);
this.admin = CommonUtils.getBoolean(config.getAttribute("admin"), false);
this.user = CommonUtils.getBoolean(config.getAttribute("user"), false);
}
public WebAuthProviderPropertyEncryption getEncryption() {
return encryption;
}
public boolean isIdentifying() {
return identifying;
}
public boolean isAdmin() {
return admin;
}
public boolean isUser() {
return user;
}
}
@@ -1,48 +0,0 @@
/*
* DBeaver - Universal Database Manager
* Copyright (C) 2010-2021 DBeaver Corp and others
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package io.cloudbeaver.registry;
import org.jkiss.utils.SecurityUtils;
/**
* Auth provider property encryption
*/
public enum WebAuthProviderPropertyEncryption {
// Non-secure property
none {
@Override
public String encrypt(String salt, String value) {
return value;
}
},
// Secure property, value passed to provided as-is
plain {
@Override
public String encrypt(String salt, String value) {
return value;
}
},
// Secure property, value passed as MD5 hash
hash {
@Override
public String encrypt(String salt, String value) {
return SecurityUtils.makeDigest(salt, value);
}
};
public abstract String encrypt(String salt, String value);
}
@@ -24,12 +24,13 @@ import io.cloudbeaver.model.session.WebSession;
import io.cloudbeaver.model.user.WebRole;
import io.cloudbeaver.model.user.WebUser;
import io.cloudbeaver.registry.WebAuthProviderDescriptor;
import io.cloudbeaver.registry.WebAuthProviderPropertyDescriptor;
import io.cloudbeaver.registry.WebAuthProviderPropertyEncryption;
import io.cloudbeaver.registry.WebServiceRegistry;
import org.jkiss.code.NotNull;
import org.jkiss.code.Nullable;
import org.jkiss.dbeaver.Log;
import org.jkiss.dbeaver.model.auth.AuthPropertyDescriptor;
import org.jkiss.dbeaver.model.auth.AuthPropertyEncryption;
import org.jkiss.dbeaver.model.auth.DBAAuthCredentialsProfile;
import org.jkiss.dbeaver.model.exec.DBCException;
import org.jkiss.dbeaver.model.impl.jdbc.JDBCUtils;
import org.jkiss.dbeaver.model.impl.jdbc.exec.JDBCTransaction;
@@ -329,10 +330,10 @@ class CBSecurityController implements DBWSecurityController {
public void setUserCredentials(String userId, WebAuthProviderDescriptor authProvider, Map<String, Object> credentials) throws DBCException {
List<String[]> transformedCredentials;
try {
WebAuthProviderDescriptor.CredentialsProfile credProfile = authProvider.getCredentialProfileByParameters(credentials.keySet());
DBAAuthCredentialsProfile credProfile = authProvider.getCredentialProfileByParameters(credentials.keySet());
transformedCredentials = credentials.entrySet().stream().map(cred -> {
String propertyName = cred.getKey();
WebAuthProviderPropertyDescriptor property = credProfile.getCredentialParameter(propertyName);
AuthPropertyDescriptor property = credProfile.getCredentialParameter(propertyName);
if (property == null) {
return null;
}
@@ -371,14 +372,14 @@ class CBSecurityController implements DBWSecurityController {
@Override
public String getUserByCredentials(WebAuthProviderDescriptor authProvider, Map<String, Object> authParameters) throws DBCException {
Map<String, Object> identCredentials = new LinkedHashMap<>();
for (WebAuthProviderPropertyDescriptor prop : authProvider.getCredentialParameters(authParameters.keySet())) {
for (AuthPropertyDescriptor prop : authProvider.getCredentialParameters(authParameters.keySet())) {
if (prop.isIdentifying()) {
String propId = CommonUtils.toString(prop.getId());
Object paramValue = authParameters.get(propId);
if (paramValue == null) {
throw new DBCException("Authentication parameter '" + prop.getId() + "' is missing");
}
if (prop.getEncryption() == WebAuthProviderPropertyEncryption.hash) {
if (prop.getEncryption() == AuthPropertyEncryption.hash) {
throw new DBCException("Hash encryption can't be used in identifying credentials");
}
identCredentials.put(propId, paramValue);
@@ -1,7 +1,6 @@
package io.cloudbeaver.server.jetty;
import io.cloudbeaver.DBWConstants;
import io.cloudbeaver.auth.DBWAuthProvider;
import io.cloudbeaver.auth.DBWAuthProviderFederated;
import io.cloudbeaver.auth.provider.AuthProviderConfig;
import io.cloudbeaver.model.session.WebSession;
@@ -17,6 +16,7 @@ import org.eclipse.jetty.server.ResourceService;
import org.eclipse.jetty.servlet.DefaultServlet;
import org.eclipse.jetty.util.resource.Resource;
import org.jkiss.dbeaver.Log;
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
import org.jkiss.utils.CommonUtils;
import org.jkiss.utils.IOUtils;
@@ -86,7 +86,7 @@ public class CBStaticServlet extends DefaultServlet {
try {
// We have the only provider
// Forward to signon URL
DBWAuthProvider<?> authProviderInstance = authProvider.getInstance();
DBAAuthProvider<?> authProviderInstance = authProvider.getInstance();
if (authProviderInstance instanceof DBWAuthProviderFederated) {
WebSession webSession = CBPlatform.getInstance().getSessionManager().getWebSession(request, response, false);
if (webSession.getUser() == null) {
@@ -20,8 +20,7 @@ import io.cloudbeaver.DBWConstants;
import io.cloudbeaver.DBWSecurityController;
import io.cloudbeaver.DBWUserIdentity;
import io.cloudbeaver.DBWebException;
import io.cloudbeaver.auth.DBWAuthProvider;
import io.cloudbeaver.auth.DBWAuthProviderExternal;
import io.cloudbeaver.auth.DBAAuthProviderExternal;
import io.cloudbeaver.auth.provider.local.LocalAuthProvider;
import io.cloudbeaver.model.WebPropertyInfo;
import io.cloudbeaver.model.session.WebAuthInfo;
@@ -40,7 +39,8 @@ import org.jkiss.code.NotNull;
import org.jkiss.code.Nullable;
import org.jkiss.dbeaver.DBException;
import org.jkiss.dbeaver.Log;
import org.jkiss.dbeaver.model.access.DBASession;
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
import org.jkiss.dbeaver.model.auth.DBASession;
import org.jkiss.dbeaver.model.exec.DBCException;
import org.jkiss.utils.ArrayUtils;
import org.jkiss.utils.CommonUtils;
@@ -92,9 +92,9 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
}
try {
Map<String, Object> providerConfig = Collections.emptyMap();
DBWAuthProvider<?> authProviderInstance = authProvider.getInstance();
DBWAuthProviderExternal<?> authProviderExternal = authProviderInstance instanceof DBWAuthProviderExternal<?> ?
(DBWAuthProviderExternal<?>) authProviderInstance : null;
DBAAuthProvider<?> authProviderInstance = authProvider.getInstance();
DBAAuthProviderExternal<?> authProviderExternal = authProviderInstance instanceof DBAAuthProviderExternal<?> ?
(DBAAuthProviderExternal<?>) authProviderInstance : null;
Map<String, Object> userCredentials;
if (authProviderExternal != null) {
@@ -205,10 +205,10 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
}
authSession = authProviderInstance.openSession(
webSession.getProgressMonitor(),
webSession,
providerConfig,
userCredentials
);
userCredentials);
WebAuthInfo authInfo = new WebAuthInfo(
webSession,