CB-1061 AWS assume role implementation attempt

This commit is contained in:
serge-rider
2021-08-21 20:28:47 +03:00
parent 1de7e8516f
commit c49a2e7d40
2 changed files with 83 additions and 28 deletions
@@ -0,0 +1,32 @@
/*
* DBeaver - Universal Database Manager
* Copyright (C) 2010-2021 DBeaver Corp and others
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package io.cloudbeaver;
import io.cloudbeaver.model.session.WebAuthInfo;
import org.jkiss.dbeaver.DBException;
import java.util.Map;
/**
* Auth provider which can assume authentication from another authentication (federated)
*/
public interface DBWAuthProviderAssumer {
WebAuthInfo assumeAuthentication(WebAuthInfo authInfo, Map<String, Object> authAttrs)
throws DBException;
}
@@ -18,12 +18,14 @@ package io.cloudbeaver.model.session;
import io.cloudbeaver.DBWAuthProvider;
import io.cloudbeaver.DBWUserIdentity;
import io.cloudbeaver.model.user.WebAuthProviderConfiguration;
import io.cloudbeaver.model.user.WebUser;
import io.cloudbeaver.model.user.WebUserOriginInfo;
import io.cloudbeaver.registry.WebAuthProviderDescriptor;
import org.jkiss.code.NotNull;
import org.jkiss.dbeaver.Log;
import org.jkiss.dbeaver.model.access.DBASession;
import org.jkiss.dbeaver.model.meta.Property;
import java.time.OffsetDateTime;
import java.util.Map;
@@ -38,6 +40,7 @@ public class WebAuthInfo {
private final WebSession session;
private final WebUser user;
private WebAuthProviderDescriptor authProvider;
private WebAuthProviderConfiguration authProviderConfiguration;
private DBASession authSession;
private OffsetDateTime loginTime;
private DBWUserIdentity userIdentity;
@@ -61,6 +64,46 @@ public class WebAuthInfo {
this.loginTime = loginTime;
}
@Property
public OffsetDateTime getLoginTime() {
return loginTime;
}
@Property
public String getMessage() {
return message;
}
@Property
public void setMessage(String message) {
this.message = message;
}
@Property
public WebUserOriginInfo getOrigin() {
return new WebUserOriginInfo(session, user, authProvider);
}
@Property
public String getUserId() {
return userIdentity.getId();
}
@Property
public String getDisplayName() {
return userIdentity.getDisplayName();
}
@Property
public String getAuthProvider() {
return authProvider.getId();
}
@Property
public String getAuthConfiguration() {
return authProviderConfiguration.getId();
}
public WebUser getUser() {
return user;
}
@@ -69,42 +112,22 @@ public class WebAuthInfo {
return userIdentity;
}
public String getUserId() {
return userIdentity.getId();
}
public String getDisplayName() {
return userIdentity.getDisplayName();
}
public String getAuthProvider() {
return authProvider.getId();
}
public WebAuthProviderDescriptor getAuthProviderDescriptor() {
return authProvider;
}
public WebAuthProviderConfiguration getAuthProviderConfiguration() {
return authProviderConfiguration;
}
public void setAuthProviderConfiguration(WebAuthProviderConfiguration authProviderConfiguration) {
this.authProviderConfiguration = authProviderConfiguration;
}
public DBASession getAuthSession() {
return authSession;
}
public OffsetDateTime getLoginTime() {
return loginTime;
}
public String getMessage() {
return message;
}
public void setMessage(String message) {
this.message = message;
}
public WebUserOriginInfo getOrigin() {
return new WebUserOriginInfo(session, user, authProvider);
}
void closeAuth() {
if (authProvider != null && authSession != null) {
try {