mirror of
https://github.com/dbeaver/cloudbeaver.git
synced 2026-09-24 16:04:36 +08:00
dbeaver/dbeaver-ee#1313 Auth model refactoring
This commit is contained in:
+3
-2
@@ -24,7 +24,8 @@ import org.jkiss.code.NotNull;
|
||||
import org.jkiss.code.Nullable;
|
||||
import org.jkiss.dbeaver.DBException;
|
||||
import org.jkiss.dbeaver.model.DBPObject;
|
||||
import org.jkiss.dbeaver.model.access.DBASession;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
|
||||
import org.jkiss.dbeaver.model.auth.DBASession;
|
||||
import org.jkiss.dbeaver.model.runtime.DBRProgressMonitor;
|
||||
|
||||
import java.util.Map;
|
||||
@@ -33,7 +34,7 @@ import java.util.Map;
|
||||
* External auth provider.
|
||||
* Authenticates user using external user identity
|
||||
*/
|
||||
public interface DBWAuthProviderExternal<AUTH_SESSION extends DBASession> extends DBWAuthProvider<AUTH_SESSION> {
|
||||
public interface DBAAuthProviderExternal<AUTH_SESSION extends DBASession> extends DBAAuthProvider<AUTH_SESSION> {
|
||||
|
||||
/**
|
||||
* Returns new identifying credentials which can be used to find/create user in database
|
||||
@@ -1,41 +0,0 @@
|
||||
/*
|
||||
* DBeaver - Universal Database Manager
|
||||
* Copyright (C) 2010-2021 DBeaver Corp and others
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
package io.cloudbeaver.auth;
|
||||
|
||||
import io.cloudbeaver.model.session.WebSession;
|
||||
import org.jkiss.code.NotNull;
|
||||
import org.jkiss.dbeaver.DBException;
|
||||
import org.jkiss.dbeaver.model.access.DBASession;
|
||||
|
||||
import java.util.Map;
|
||||
|
||||
/**
|
||||
* Auth provider
|
||||
*/
|
||||
public interface DBWAuthProvider<AUTH_SESSION extends DBASession> {
|
||||
|
||||
AUTH_SESSION openSession(
|
||||
@NotNull WebSession mainSession,
|
||||
@NotNull Map<String, Object> providerConfig, // Auth provider configuration (e.g. 3rd party auth server address)
|
||||
@NotNull Map<String, Object> userCredentials // Saved user credentials (e.g. associated 3rd party provider user name or realm)
|
||||
) throws DBException;
|
||||
|
||||
void closeSession(@NotNull WebSession mainSession, AUTH_SESSION session) throws DBException;
|
||||
|
||||
void refreshSession(@NotNull WebSession mainSession, AUTH_SESSION session) throws DBException;
|
||||
|
||||
}
|
||||
+3
-3
@@ -16,15 +16,15 @@
|
||||
*/
|
||||
package io.cloudbeaver.auth.provider;
|
||||
|
||||
import io.cloudbeaver.auth.DBWAuthProviderExternal;
|
||||
import io.cloudbeaver.auth.DBAAuthProviderExternal;
|
||||
import io.cloudbeaver.model.user.WebUser;
|
||||
import org.jkiss.dbeaver.model.access.DBASession;
|
||||
import org.jkiss.dbeaver.model.auth.DBASession;
|
||||
import org.jkiss.utils.CommonUtils;
|
||||
|
||||
/**
|
||||
* Abstract external auth provider
|
||||
*/
|
||||
public abstract class AbstractExternalAuthProvider<SESSION extends DBASession> implements DBWAuthProviderExternal<SESSION> {
|
||||
public abstract class AbstractExternalAuthProvider<SESSION extends DBASession> implements DBAAuthProviderExternal<SESSION> {
|
||||
|
||||
public static final String META_AUTH_PROVIDER = "$provider";
|
||||
public static final String META_AUTH_SPACE_ID = "$space";
|
||||
|
||||
+9
-6
@@ -17,13 +17,10 @@
|
||||
|
||||
package io.cloudbeaver.auth.provider.fa;
|
||||
|
||||
import io.cloudbeaver.model.session.WebSession;
|
||||
import org.jkiss.code.NotNull;
|
||||
import org.jkiss.code.Nullable;
|
||||
import org.jkiss.dbeaver.model.access.DBASessionFederated;
|
||||
import org.jkiss.dbeaver.model.access.DBASessionPrincipal;
|
||||
import org.jkiss.dbeaver.model.app.DBPProject;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthSpace;
|
||||
import org.jkiss.dbeaver.model.auth.*;
|
||||
|
||||
import java.util.Map;
|
||||
|
||||
@@ -32,11 +29,11 @@ public abstract class AbstractSessionFederated implements DBASessionFederated {
|
||||
@NotNull
|
||||
protected final Map<String, Object> authParameters;
|
||||
@NotNull
|
||||
protected final WebSession parentSession;
|
||||
protected final DBASession parentSession;
|
||||
@NotNull
|
||||
protected final DBAAuthSpace space;
|
||||
|
||||
protected AbstractSessionFederated(@NotNull WebSession parentSession, @NotNull DBAAuthSpace space, @NotNull Map<String, Object> authParameters) {
|
||||
protected AbstractSessionFederated(@NotNull DBASession parentSession, @NotNull DBAAuthSpace space, @NotNull Map<String, Object> authParameters) {
|
||||
this.parentSession = parentSession;
|
||||
this.space = space;
|
||||
this.authParameters = authParameters;
|
||||
@@ -48,6 +45,12 @@ public abstract class AbstractSessionFederated implements DBASessionFederated {
|
||||
return space;
|
||||
}
|
||||
|
||||
@NotNull
|
||||
@Override
|
||||
public DBASessionContext getSessionContext() {
|
||||
return this.parentSession.getSessionContext();
|
||||
}
|
||||
|
||||
@Override
|
||||
public DBASessionPrincipal getSessionPrincipal() {
|
||||
return parentSession.getSessionPrincipal();
|
||||
|
||||
+11
-9
@@ -16,30 +16,32 @@
|
||||
*/
|
||||
package io.cloudbeaver.auth.provider.local;
|
||||
|
||||
import io.cloudbeaver.auth.DBWAuthProvider;
|
||||
import io.cloudbeaver.model.session.WebSession;
|
||||
import io.cloudbeaver.registry.WebAuthProviderDescriptor;
|
||||
import io.cloudbeaver.registry.WebAuthProviderPropertyEncryption;
|
||||
import io.cloudbeaver.registry.WebServiceRegistry;
|
||||
import io.cloudbeaver.server.CBApplication;
|
||||
import org.jkiss.code.NotNull;
|
||||
import org.jkiss.dbeaver.DBException;
|
||||
import org.jkiss.dbeaver.model.auth.AuthPropertyEncryption;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
|
||||
import org.jkiss.dbeaver.model.auth.DBASession;
|
||||
import org.jkiss.dbeaver.model.runtime.DBRProgressMonitor;
|
||||
import org.jkiss.utils.CommonUtils;
|
||||
import org.jkiss.utils.SecurityUtils;
|
||||
|
||||
import java.util.Map;
|
||||
|
||||
/**
|
||||
* Auth provider
|
||||
* Local auth provider
|
||||
*/
|
||||
public class LocalAuthProvider implements DBWAuthProvider<LocalAuthSession> {
|
||||
public class LocalAuthProvider implements DBAAuthProvider<LocalAuthSession> {
|
||||
|
||||
public static final String PROVIDER_ID = "local";
|
||||
public static final String CRED_USER = "user";
|
||||
public static final String CRED_PASSWORD = "password";
|
||||
|
||||
@Override
|
||||
public LocalAuthSession openSession(@NotNull WebSession mainSession, @NotNull Map<String, Object> providerConfig, @NotNull Map<String, Object> userCredentials) throws DBException {
|
||||
public LocalAuthSession openSession(@NotNull DBRProgressMonitor monitor, @NotNull DBASession mainSession, @NotNull Map<String, Object> providerConfig, @NotNull Map<String, Object> userCredentials) throws DBException {
|
||||
String userName = CommonUtils.toString(userCredentials.get(CRED_USER), null);
|
||||
|
||||
WebAuthProviderDescriptor authProvider = WebServiceRegistry.getInstance().getAuthProvider(PROVIDER_ID);
|
||||
@@ -56,7 +58,7 @@ public class LocalAuthProvider implements DBWAuthProvider<LocalAuthSession> {
|
||||
if (CommonUtils.isEmpty(clientPassword)) {
|
||||
throw new DBException("No user password provided");
|
||||
}
|
||||
String clientPasswordHash = WebAuthProviderPropertyEncryption.hash.encrypt(userName, clientPassword);
|
||||
String clientPasswordHash = AuthPropertyEncryption.hash.encrypt(userName, clientPassword);
|
||||
if (!storedPasswordHash.equals(clientPasswordHash)) {
|
||||
throw new DBException("Invalid user name or password");
|
||||
}
|
||||
@@ -64,12 +66,12 @@ public class LocalAuthProvider implements DBWAuthProvider<LocalAuthSession> {
|
||||
}
|
||||
|
||||
@Override
|
||||
public void closeSession(@NotNull WebSession mainSession, LocalAuthSession localAuthSession) throws DBException {
|
||||
public void closeSession(@NotNull DBASession mainSession, LocalAuthSession localAuthSession) throws DBException {
|
||||
|
||||
}
|
||||
|
||||
@Override
|
||||
public void refreshSession(@NotNull WebSession mainSession, LocalAuthSession localAuthSession) throws DBException {
|
||||
public void refreshSession(@NotNull DBRProgressMonitor monitor, @NotNull DBASession mainSession, LocalAuthSession localAuthSession) throws DBException {
|
||||
|
||||
}
|
||||
|
||||
@@ -92,7 +94,7 @@ public class LocalAuthProvider implements DBWAuthProvider<LocalAuthSession> {
|
||||
if (CommonUtils.isEmpty(oldPassword)) {
|
||||
throw new DBException("No user password provided");
|
||||
}
|
||||
String oldPasswordHash = WebAuthProviderPropertyEncryption.hash.encrypt(userName, oldPassword);
|
||||
String oldPasswordHash = AuthPropertyEncryption.hash.encrypt(userName, oldPassword);
|
||||
if (!storedPasswordHash.equals(oldPasswordHash)) {
|
||||
throw new DBException("Invalid user name or password");
|
||||
}
|
||||
|
||||
+12
-6
@@ -16,23 +16,23 @@
|
||||
*/
|
||||
package io.cloudbeaver.auth.provider.local;
|
||||
|
||||
import io.cloudbeaver.model.session.WebSession;
|
||||
import org.jkiss.code.NotNull;
|
||||
import org.jkiss.code.Nullable;
|
||||
import org.jkiss.dbeaver.model.access.DBASession;
|
||||
import org.jkiss.dbeaver.model.access.DBASessionPrincipal;
|
||||
import org.jkiss.dbeaver.model.app.DBPProject;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthSpace;
|
||||
import org.jkiss.dbeaver.model.auth.DBASession;
|
||||
import org.jkiss.dbeaver.model.auth.DBASessionContext;
|
||||
import org.jkiss.dbeaver.model.auth.DBASessionPrincipal;
|
||||
|
||||
/**
|
||||
* Local auth provider
|
||||
*/
|
||||
public class LocalAuthSession implements DBASession {
|
||||
|
||||
private final WebSession webSession;
|
||||
private final DBASession webSession;
|
||||
private final String userId;
|
||||
|
||||
LocalAuthSession(WebSession webSession, String userId) {
|
||||
LocalAuthSession(DBASession webSession, String userId) {
|
||||
this.webSession = webSession;
|
||||
this.userId = userId;
|
||||
}
|
||||
@@ -47,6 +47,12 @@ public class LocalAuthSession implements DBASession {
|
||||
return webSession.getSingletonProject();
|
||||
}
|
||||
|
||||
@NotNull
|
||||
@Override
|
||||
public DBASessionContext getSessionContext() {
|
||||
return webSession.getSessionContext();
|
||||
}
|
||||
|
||||
@Override
|
||||
public DBASessionPrincipal getSessionPrincipal() {
|
||||
return webSession.getSessionPrincipal();
|
||||
@@ -66,7 +72,7 @@ public class LocalAuthSession implements DBASession {
|
||||
@Nullable
|
||||
@Override
|
||||
public DBPProject getSingletonProject() {
|
||||
return null;
|
||||
return webSession.getSingletonProject();
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
+4
-4
@@ -17,15 +17,15 @@
|
||||
package io.cloudbeaver.model.session;
|
||||
|
||||
import io.cloudbeaver.DBWUserIdentity;
|
||||
import io.cloudbeaver.auth.DBWAuthProvider;
|
||||
import io.cloudbeaver.model.user.WebAuthProviderConfiguration;
|
||||
import io.cloudbeaver.model.user.WebUser;
|
||||
import io.cloudbeaver.model.user.WebUserOriginInfo;
|
||||
import io.cloudbeaver.registry.WebAuthProviderDescriptor;
|
||||
import org.jkiss.code.NotNull;
|
||||
import org.jkiss.dbeaver.Log;
|
||||
import org.jkiss.dbeaver.model.access.DBASession;
|
||||
import org.jkiss.dbeaver.model.access.DBASessionPrincipal;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
|
||||
import org.jkiss.dbeaver.model.auth.DBASession;
|
||||
import org.jkiss.dbeaver.model.auth.DBASessionPrincipal;
|
||||
import org.jkiss.dbeaver.model.meta.Property;
|
||||
|
||||
import java.time.OffsetDateTime;
|
||||
@@ -132,7 +132,7 @@ public class WebAuthInfo implements DBASessionPrincipal {
|
||||
void closeAuth() {
|
||||
if (authProvider != null && authSession != null) {
|
||||
try {
|
||||
DBWAuthProvider authProviderInstance = this.authProvider.getInstance();
|
||||
DBAAuthProvider authProviderInstance = this.authProvider.getInstance();
|
||||
authProviderInstance.closeSession(session, authSession);
|
||||
} catch (Exception e) {
|
||||
log.error(e);
|
||||
|
||||
+2
-5
@@ -33,13 +33,9 @@ import org.jkiss.code.Nullable;
|
||||
import org.jkiss.dbeaver.DBException;
|
||||
import org.jkiss.dbeaver.Log;
|
||||
import org.jkiss.dbeaver.model.DBPDataSourceContainer;
|
||||
import org.jkiss.dbeaver.model.access.DBASession;
|
||||
import org.jkiss.dbeaver.model.access.DBASessionPrincipal;
|
||||
import org.jkiss.dbeaver.model.app.DBPDataSourceRegistry;
|
||||
import org.jkiss.dbeaver.model.app.DBPProject;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthCredentialsProvider;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthSpace;
|
||||
import org.jkiss.dbeaver.model.auth.DBASessionContext;
|
||||
import org.jkiss.dbeaver.model.auth.*;
|
||||
import org.jkiss.dbeaver.model.connection.DBPConnectionConfiguration;
|
||||
import org.jkiss.dbeaver.model.exec.DBCException;
|
||||
import org.jkiss.dbeaver.model.impl.auth.AuthModelDatabaseNative;
|
||||
@@ -167,6 +163,7 @@ public class WebSession implements DBASession, DBAAuthCredentialsProvider, IAdap
|
||||
return sessionProject;
|
||||
}
|
||||
|
||||
@NotNull
|
||||
public DBASessionContext getSessionContext() {
|
||||
return sessionProject.getSessionContext();
|
||||
}
|
||||
|
||||
+4
-4
@@ -16,12 +16,12 @@
|
||||
*/
|
||||
package io.cloudbeaver.model.user;
|
||||
|
||||
import io.cloudbeaver.auth.DBWAuthProvider;
|
||||
import io.cloudbeaver.auth.DBWAuthProviderFederated;
|
||||
import io.cloudbeaver.auth.provider.AuthProviderConfig;
|
||||
import io.cloudbeaver.registry.WebAuthProviderDescriptor;
|
||||
import org.jkiss.dbeaver.DBException;
|
||||
import org.jkiss.dbeaver.Log;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
|
||||
import org.jkiss.dbeaver.model.meta.Property;
|
||||
|
||||
import java.util.Map;
|
||||
@@ -73,19 +73,19 @@ public class WebAuthProviderConfiguration {
|
||||
|
||||
@Property
|
||||
public String getSignInLink() throws DBException {
|
||||
DBWAuthProvider<?> instance = providerDescriptor.getInstance();
|
||||
DBAAuthProvider<?> instance = providerDescriptor.getInstance();
|
||||
return instance instanceof DBWAuthProviderFederated ? ((DBWAuthProviderFederated) instance).getSignInLink(getId(), config.getParameters()) : null;
|
||||
}
|
||||
|
||||
@Property
|
||||
public String getSignOutLink() throws DBException {
|
||||
DBWAuthProvider<?> instance = providerDescriptor.getInstance();
|
||||
DBAAuthProvider<?> instance = providerDescriptor.getInstance();
|
||||
return instance instanceof DBWAuthProviderFederated ? ((DBWAuthProviderFederated) instance).getSignOutLink(getId(), config.getParameters()) : null;
|
||||
}
|
||||
|
||||
@Property
|
||||
public String getMetadataLink() throws DBException {
|
||||
DBWAuthProvider<?> instance = providerDescriptor.getInstance();
|
||||
DBAAuthProvider<?> instance = providerDescriptor.getInstance();
|
||||
return instance instanceof DBWAuthProviderFederated ? ((DBWAuthProviderFederated) instance).getMetadataLink(getId(), config.getParameters()) : null;
|
||||
}
|
||||
|
||||
|
||||
+2
-1
@@ -22,6 +22,7 @@ import io.cloudbeaver.registry.WebAuthProviderDescriptor;
|
||||
import io.cloudbeaver.server.CBApplication;
|
||||
import io.cloudbeaver.server.CBPlatform;
|
||||
import org.jkiss.dbeaver.Log;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthCredentialsProfile;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
@@ -78,7 +79,7 @@ public class WebAuthProviderInfo {
|
||||
return result;
|
||||
}
|
||||
|
||||
public List<WebAuthProviderDescriptor.CredentialsProfile> getCredentialProfiles() {
|
||||
public List<DBAAuthCredentialsProfile> getCredentialProfiles() {
|
||||
return descriptor.getCredentialProfiles();
|
||||
}
|
||||
|
||||
|
||||
+7
-7
@@ -18,8 +18,7 @@ package io.cloudbeaver.model.user;
|
||||
|
||||
import io.cloudbeaver.DBWebException;
|
||||
import io.cloudbeaver.WebServiceUtils;
|
||||
import io.cloudbeaver.auth.DBWAuthProvider;
|
||||
import io.cloudbeaver.auth.DBWAuthProviderExternal;
|
||||
import io.cloudbeaver.auth.DBAAuthProviderExternal;
|
||||
import io.cloudbeaver.auth.provider.local.LocalAuthProvider;
|
||||
import io.cloudbeaver.model.WebObjectOrigin;
|
||||
import io.cloudbeaver.model.WebPropertyInfo;
|
||||
@@ -31,7 +30,8 @@ import org.jkiss.code.Nullable;
|
||||
import org.jkiss.dbeaver.DBException;
|
||||
import org.jkiss.dbeaver.Log;
|
||||
import org.jkiss.dbeaver.model.DBPObject;
|
||||
import org.jkiss.dbeaver.model.access.DBASession;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
|
||||
import org.jkiss.dbeaver.model.auth.DBASession;
|
||||
import org.jkiss.dbeaver.model.meta.Property;
|
||||
|
||||
import java.lang.reflect.ParameterizedType;
|
||||
@@ -101,12 +101,12 @@ public class WebUserOriginInfo implements WebObjectOrigin {
|
||||
throw new DBException("Session not authorized in auth provider '" + authProvider.getId() + "'");
|
||||
}
|
||||
DBASession authSession = authInfo.getAuthSession();
|
||||
DBWAuthProvider<?> authProvider = this.authProvider.getInstance();
|
||||
if (authSession != null && authProvider instanceof DBWAuthProviderExternal) {
|
||||
DBAAuthProvider<?> authProvider = this.authProvider.getInstance();
|
||||
if (authSession != null && authProvider instanceof DBAAuthProviderExternal) {
|
||||
if (!isValidSessionType(authSession, authProvider)) {
|
||||
return new WebPropertyInfo[0];
|
||||
}
|
||||
DBPObject userDetails = ((DBWAuthProviderExternal) authProvider).getUserDetails(
|
||||
DBPObject userDetails = ((DBAAuthProviderExternal) authProvider).getUserDetails(
|
||||
session.getProgressMonitor(),
|
||||
session,
|
||||
authSession,
|
||||
@@ -122,7 +122,7 @@ public class WebUserOriginInfo implements WebObjectOrigin {
|
||||
return new WebPropertyInfo[0];
|
||||
}
|
||||
|
||||
private static boolean isValidSessionType(DBASession authSession, DBWAuthProvider<?> authProvider) {
|
||||
private static boolean isValidSessionType(DBASession authSession, DBAAuthProvider<?> authProvider) {
|
||||
Type providerSuperClass = authProvider.getClass().getGenericSuperclass();
|
||||
if (providerSuperClass instanceof ParameterizedType) {
|
||||
Type[] typeArguments = ((ParameterizedType) providerSuperClass).getActualTypeArguments();
|
||||
|
||||
+15
-52
@@ -16,11 +16,14 @@
|
||||
*/
|
||||
package io.cloudbeaver.registry;
|
||||
|
||||
import io.cloudbeaver.auth.DBWAuthProvider;
|
||||
import org.eclipse.core.runtime.IConfigurationElement;
|
||||
import org.jkiss.code.NotNull;
|
||||
import org.jkiss.dbeaver.DBException;
|
||||
import org.jkiss.dbeaver.model.DBPImage;
|
||||
import org.jkiss.dbeaver.model.auth.AuthPropertyDescriptor;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthCredentialsProfile;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthProviderDescriptor;
|
||||
import org.jkiss.dbeaver.model.impl.AbstractDescriptor;
|
||||
import org.jkiss.dbeaver.model.impl.PropertyDescriptor;
|
||||
import org.jkiss.utils.ArrayUtils;
|
||||
@@ -31,58 +34,18 @@ import java.util.*;
|
||||
/**
|
||||
* Auth service descriptor
|
||||
*/
|
||||
public class WebAuthProviderDescriptor extends AbstractDescriptor {
|
||||
public class WebAuthProviderDescriptor extends AbstractDescriptor implements DBAAuthProviderDescriptor {
|
||||
|
||||
private final IConfigurationElement cfg;
|
||||
|
||||
private final ObjectType implType;
|
||||
private DBWAuthProvider<?> instance;
|
||||
private DBAAuthProvider<?> instance;
|
||||
private final DBPImage icon;
|
||||
private final Map<String, PropertyDescriptor> configurationParameters = new LinkedHashMap<>();
|
||||
private final List<CredentialsProfile> credentialProfiles = new ArrayList<>();
|
||||
private final List<DBAAuthCredentialsProfile> credentialProfiles = new ArrayList<>();
|
||||
private final boolean configurable;
|
||||
private final String[] requiredFeatures;
|
||||
|
||||
public static class CredentialsProfile {
|
||||
private final String id;
|
||||
private final String label;
|
||||
private final String description;
|
||||
private final Map<String, WebAuthProviderPropertyDescriptor> credentialParameters = new LinkedHashMap<>();
|
||||
public CredentialsProfile(IConfigurationElement cfg) {
|
||||
this.id = cfg.getAttribute("id");
|
||||
this.label = cfg.getAttribute("label");
|
||||
this.description = cfg.getAttribute("description");
|
||||
for (IConfigurationElement propGroup : ArrayUtils.safeArray(cfg.getChildren(PropertyDescriptor.TAG_PROPERTY_GROUP))) {
|
||||
String category = propGroup.getAttribute(PropertyDescriptor.ATTR_LABEL);
|
||||
IConfigurationElement[] propElements = propGroup.getChildren(PropertyDescriptor.TAG_PROPERTY);
|
||||
for (IConfigurationElement prop : propElements) {
|
||||
WebAuthProviderPropertyDescriptor propertyDescriptor = new WebAuthProviderPropertyDescriptor(category, prop);
|
||||
credentialParameters.put(CommonUtils.toString(propertyDescriptor.getId()), propertyDescriptor);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
public String getId() {
|
||||
return id;
|
||||
}
|
||||
|
||||
public String getLabel() {
|
||||
return label;
|
||||
}
|
||||
|
||||
public String getDescription() {
|
||||
return description;
|
||||
}
|
||||
|
||||
public List<WebAuthProviderPropertyDescriptor> getCredentialParameters() {
|
||||
return new ArrayList<>(credentialParameters.values());
|
||||
}
|
||||
|
||||
public WebAuthProviderPropertyDescriptor getCredentialParameter(String id) {
|
||||
return credentialParameters.get(id);
|
||||
}
|
||||
}
|
||||
|
||||
public WebAuthProviderDescriptor(IConfigurationElement cfg) {
|
||||
super(cfg);
|
||||
this.cfg = cfg;
|
||||
@@ -101,7 +64,7 @@ public class WebAuthProviderDescriptor extends AbstractDescriptor {
|
||||
}
|
||||
}
|
||||
for (IConfigurationElement credElement : cfg.getChildren("credentials")) {
|
||||
credentialProfiles.add(new CredentialsProfile(credElement));
|
||||
credentialProfiles.add(new DBAAuthCredentialsProfile(credElement));
|
||||
}
|
||||
|
||||
String rfList = cfg.getAttribute("requiredFeatures");
|
||||
@@ -137,13 +100,13 @@ public class WebAuthProviderDescriptor extends AbstractDescriptor {
|
||||
return new ArrayList<>(configurationParameters.values());
|
||||
}
|
||||
|
||||
public List<CredentialsProfile> getCredentialProfiles() {
|
||||
public List<DBAAuthCredentialsProfile> getCredentialProfiles() {
|
||||
return new ArrayList<>(credentialProfiles);
|
||||
}
|
||||
|
||||
public CredentialsProfile getCredentialProfileByParameters(Set<String> keySet) {
|
||||
public DBAAuthCredentialsProfile getCredentialProfileByParameters(Set<String> keySet) {
|
||||
if (credentialProfiles.size() > 1) {
|
||||
for (CredentialsProfile profile : credentialProfiles) {
|
||||
for (DBAAuthCredentialsProfile profile : credentialProfiles) {
|
||||
if (profile.getCredentialParameters().size() == keySet.size()) {
|
||||
boolean matches = true;
|
||||
for (String paramName : keySet) {
|
||||
@@ -161,9 +124,9 @@ public class WebAuthProviderDescriptor extends AbstractDescriptor {
|
||||
return credentialProfiles.get(0);
|
||||
}
|
||||
|
||||
public List<WebAuthProviderPropertyDescriptor> getCredentialParameters(Set<String> keySet) {
|
||||
public List<AuthPropertyDescriptor> getCredentialParameters(Set<String> keySet) {
|
||||
if (credentialProfiles.size() > 1) {
|
||||
for (CredentialsProfile profile : credentialProfiles) {
|
||||
for (DBAAuthCredentialsProfile profile : credentialProfiles) {
|
||||
if (profile.getCredentialParameters().size() == keySet.size()) {
|
||||
boolean matches = true;
|
||||
for (String paramName : keySet) {
|
||||
@@ -182,10 +145,10 @@ public class WebAuthProviderDescriptor extends AbstractDescriptor {
|
||||
}
|
||||
|
||||
@NotNull
|
||||
public DBWAuthProvider<?> getInstance() {
|
||||
public DBAAuthProvider<?> getInstance() {
|
||||
if (instance == null) {
|
||||
try {
|
||||
instance = implType.createInstance(DBWAuthProvider.class);
|
||||
instance = implType.createInstance(DBAAuthProvider.class);
|
||||
} catch (DBException e) {
|
||||
throw new IllegalStateException("Can not instantiate auth provider '" + implType.getImplName() + "'", e);
|
||||
}
|
||||
|
||||
-58
@@ -1,58 +0,0 @@
|
||||
/*
|
||||
* DBeaver - Universal Database Manager
|
||||
* Copyright (C) 2010-2021 DBeaver Corp and others
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
package io.cloudbeaver.registry;
|
||||
|
||||
import org.eclipse.core.runtime.IConfigurationElement;
|
||||
import org.jkiss.dbeaver.model.impl.PropertyDescriptor;
|
||||
import org.jkiss.utils.CommonUtils;
|
||||
|
||||
/**
|
||||
* Auth provider property.
|
||||
* Has some extra attributes.
|
||||
*/
|
||||
public class WebAuthProviderPropertyDescriptor extends PropertyDescriptor {
|
||||
|
||||
private final WebAuthProviderPropertyEncryption encryption;
|
||||
private final boolean identifying; // Identifying parameter. Will be used during auth for user search by credentials
|
||||
private final boolean admin; // Parameter value can be configured in admin panel
|
||||
private final boolean user; // Parameter can be passed by end-user from UI
|
||||
|
||||
public WebAuthProviderPropertyDescriptor(String category, IConfigurationElement config) {
|
||||
super(category, config);
|
||||
|
||||
this.encryption = CommonUtils.valueOf(WebAuthProviderPropertyEncryption.class, config.getAttribute("encryption"), WebAuthProviderPropertyEncryption.none);
|
||||
this.identifying = CommonUtils.getBoolean(config.getAttribute("identifying"), false);
|
||||
this.admin = CommonUtils.getBoolean(config.getAttribute("admin"), false);
|
||||
this.user = CommonUtils.getBoolean(config.getAttribute("user"), false);
|
||||
}
|
||||
|
||||
public WebAuthProviderPropertyEncryption getEncryption() {
|
||||
return encryption;
|
||||
}
|
||||
|
||||
public boolean isIdentifying() {
|
||||
return identifying;
|
||||
}
|
||||
|
||||
public boolean isAdmin() {
|
||||
return admin;
|
||||
}
|
||||
|
||||
public boolean isUser() {
|
||||
return user;
|
||||
}
|
||||
}
|
||||
-48
@@ -1,48 +0,0 @@
|
||||
/*
|
||||
* DBeaver - Universal Database Manager
|
||||
* Copyright (C) 2010-2021 DBeaver Corp and others
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
package io.cloudbeaver.registry;
|
||||
|
||||
import org.jkiss.utils.SecurityUtils;
|
||||
|
||||
/**
|
||||
* Auth provider property encryption
|
||||
*/
|
||||
public enum WebAuthProviderPropertyEncryption {
|
||||
// Non-secure property
|
||||
none {
|
||||
@Override
|
||||
public String encrypt(String salt, String value) {
|
||||
return value;
|
||||
}
|
||||
},
|
||||
// Secure property, value passed to provided as-is
|
||||
plain {
|
||||
@Override
|
||||
public String encrypt(String salt, String value) {
|
||||
return value;
|
||||
}
|
||||
},
|
||||
// Secure property, value passed as MD5 hash
|
||||
hash {
|
||||
@Override
|
||||
public String encrypt(String salt, String value) {
|
||||
return SecurityUtils.makeDigest(salt, value);
|
||||
}
|
||||
};
|
||||
|
||||
public abstract String encrypt(String salt, String value);
|
||||
}
|
||||
+7
-6
@@ -24,12 +24,13 @@ import io.cloudbeaver.model.session.WebSession;
|
||||
import io.cloudbeaver.model.user.WebRole;
|
||||
import io.cloudbeaver.model.user.WebUser;
|
||||
import io.cloudbeaver.registry.WebAuthProviderDescriptor;
|
||||
import io.cloudbeaver.registry.WebAuthProviderPropertyDescriptor;
|
||||
import io.cloudbeaver.registry.WebAuthProviderPropertyEncryption;
|
||||
import io.cloudbeaver.registry.WebServiceRegistry;
|
||||
import org.jkiss.code.NotNull;
|
||||
import org.jkiss.code.Nullable;
|
||||
import org.jkiss.dbeaver.Log;
|
||||
import org.jkiss.dbeaver.model.auth.AuthPropertyDescriptor;
|
||||
import org.jkiss.dbeaver.model.auth.AuthPropertyEncryption;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthCredentialsProfile;
|
||||
import org.jkiss.dbeaver.model.exec.DBCException;
|
||||
import org.jkiss.dbeaver.model.impl.jdbc.JDBCUtils;
|
||||
import org.jkiss.dbeaver.model.impl.jdbc.exec.JDBCTransaction;
|
||||
@@ -329,10 +330,10 @@ class CBSecurityController implements DBWSecurityController {
|
||||
public void setUserCredentials(String userId, WebAuthProviderDescriptor authProvider, Map<String, Object> credentials) throws DBCException {
|
||||
List<String[]> transformedCredentials;
|
||||
try {
|
||||
WebAuthProviderDescriptor.CredentialsProfile credProfile = authProvider.getCredentialProfileByParameters(credentials.keySet());
|
||||
DBAAuthCredentialsProfile credProfile = authProvider.getCredentialProfileByParameters(credentials.keySet());
|
||||
transformedCredentials = credentials.entrySet().stream().map(cred -> {
|
||||
String propertyName = cred.getKey();
|
||||
WebAuthProviderPropertyDescriptor property = credProfile.getCredentialParameter(propertyName);
|
||||
AuthPropertyDescriptor property = credProfile.getCredentialParameter(propertyName);
|
||||
if (property == null) {
|
||||
return null;
|
||||
}
|
||||
@@ -371,14 +372,14 @@ class CBSecurityController implements DBWSecurityController {
|
||||
@Override
|
||||
public String getUserByCredentials(WebAuthProviderDescriptor authProvider, Map<String, Object> authParameters) throws DBCException {
|
||||
Map<String, Object> identCredentials = new LinkedHashMap<>();
|
||||
for (WebAuthProviderPropertyDescriptor prop : authProvider.getCredentialParameters(authParameters.keySet())) {
|
||||
for (AuthPropertyDescriptor prop : authProvider.getCredentialParameters(authParameters.keySet())) {
|
||||
if (prop.isIdentifying()) {
|
||||
String propId = CommonUtils.toString(prop.getId());
|
||||
Object paramValue = authParameters.get(propId);
|
||||
if (paramValue == null) {
|
||||
throw new DBCException("Authentication parameter '" + prop.getId() + "' is missing");
|
||||
}
|
||||
if (prop.getEncryption() == WebAuthProviderPropertyEncryption.hash) {
|
||||
if (prop.getEncryption() == AuthPropertyEncryption.hash) {
|
||||
throw new DBCException("Hash encryption can't be used in identifying credentials");
|
||||
}
|
||||
identCredentials.put(propId, paramValue);
|
||||
|
||||
+2
-2
@@ -1,7 +1,6 @@
|
||||
package io.cloudbeaver.server.jetty;
|
||||
|
||||
import io.cloudbeaver.DBWConstants;
|
||||
import io.cloudbeaver.auth.DBWAuthProvider;
|
||||
import io.cloudbeaver.auth.DBWAuthProviderFederated;
|
||||
import io.cloudbeaver.auth.provider.AuthProviderConfig;
|
||||
import io.cloudbeaver.model.session.WebSession;
|
||||
@@ -17,6 +16,7 @@ import org.eclipse.jetty.server.ResourceService;
|
||||
import org.eclipse.jetty.servlet.DefaultServlet;
|
||||
import org.eclipse.jetty.util.resource.Resource;
|
||||
import org.jkiss.dbeaver.Log;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
|
||||
import org.jkiss.utils.CommonUtils;
|
||||
import org.jkiss.utils.IOUtils;
|
||||
|
||||
@@ -86,7 +86,7 @@ public class CBStaticServlet extends DefaultServlet {
|
||||
try {
|
||||
// We have the only provider
|
||||
// Forward to signon URL
|
||||
DBWAuthProvider<?> authProviderInstance = authProvider.getInstance();
|
||||
DBAAuthProvider<?> authProviderInstance = authProvider.getInstance();
|
||||
if (authProviderInstance instanceof DBWAuthProviderFederated) {
|
||||
WebSession webSession = CBPlatform.getInstance().getSessionManager().getWebSession(request, response, false);
|
||||
if (webSession.getUser() == null) {
|
||||
|
||||
+8
-8
@@ -20,8 +20,7 @@ import io.cloudbeaver.DBWConstants;
|
||||
import io.cloudbeaver.DBWSecurityController;
|
||||
import io.cloudbeaver.DBWUserIdentity;
|
||||
import io.cloudbeaver.DBWebException;
|
||||
import io.cloudbeaver.auth.DBWAuthProvider;
|
||||
import io.cloudbeaver.auth.DBWAuthProviderExternal;
|
||||
import io.cloudbeaver.auth.DBAAuthProviderExternal;
|
||||
import io.cloudbeaver.auth.provider.local.LocalAuthProvider;
|
||||
import io.cloudbeaver.model.WebPropertyInfo;
|
||||
import io.cloudbeaver.model.session.WebAuthInfo;
|
||||
@@ -40,7 +39,8 @@ import org.jkiss.code.NotNull;
|
||||
import org.jkiss.code.Nullable;
|
||||
import org.jkiss.dbeaver.DBException;
|
||||
import org.jkiss.dbeaver.Log;
|
||||
import org.jkiss.dbeaver.model.access.DBASession;
|
||||
import org.jkiss.dbeaver.model.auth.DBAAuthProvider;
|
||||
import org.jkiss.dbeaver.model.auth.DBASession;
|
||||
import org.jkiss.dbeaver.model.exec.DBCException;
|
||||
import org.jkiss.utils.ArrayUtils;
|
||||
import org.jkiss.utils.CommonUtils;
|
||||
@@ -92,9 +92,9 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
|
||||
}
|
||||
try {
|
||||
Map<String, Object> providerConfig = Collections.emptyMap();
|
||||
DBWAuthProvider<?> authProviderInstance = authProvider.getInstance();
|
||||
DBWAuthProviderExternal<?> authProviderExternal = authProviderInstance instanceof DBWAuthProviderExternal<?> ?
|
||||
(DBWAuthProviderExternal<?>) authProviderInstance : null;
|
||||
DBAAuthProvider<?> authProviderInstance = authProvider.getInstance();
|
||||
DBAAuthProviderExternal<?> authProviderExternal = authProviderInstance instanceof DBAAuthProviderExternal<?> ?
|
||||
(DBAAuthProviderExternal<?>) authProviderInstance : null;
|
||||
Map<String, Object> userCredentials;
|
||||
|
||||
if (authProviderExternal != null) {
|
||||
@@ -205,10 +205,10 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
|
||||
}
|
||||
|
||||
authSession = authProviderInstance.openSession(
|
||||
webSession.getProgressMonitor(),
|
||||
webSession,
|
||||
providerConfig,
|
||||
userCredentials
|
||||
);
|
||||
userCredentials);
|
||||
|
||||
WebAuthInfo authInfo = new WebAuthInfo(
|
||||
webSession,
|
||||
|
||||
Reference in New Issue
Block a user