diff --git a/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/WebActionSet.java b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/WebActionSet.java new file mode 100644 index 0000000000..2e036203c3 --- /dev/null +++ b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/WebActionSet.java @@ -0,0 +1,36 @@ +/* + * DBeaver - Universal Database Manager + * Copyright (C) 2010-2021 DBeaver Corp and others + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +package io.cloudbeaver; + +import java.lang.annotation.ElementType; +import java.lang.annotation.Retention; +import java.lang.annotation.RetentionPolicy; +import java.lang.annotation.Target; + +/** + * Object association annotation + */ +@Target(value = {ElementType.TYPE}) +@Retention(RetentionPolicy.RUNTIME) +public @interface WebActionSet { + + String[] requireFeatures() default { }; + + String[] requirePermissions() default { DBWConstants.PERMISSION_PUBLIC }; + +} diff --git a/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/WebServiceBindingBase.java b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/WebServiceBindingBase.java index 8a66fe1ab5..be35c0b39a 100644 --- a/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/WebServiceBindingBase.java +++ b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/WebServiceBindingBase.java @@ -140,9 +140,13 @@ public abstract class WebServiceBindingBase impleme public Object invoke(Object proxy, Method method, Object[] args) throws Throwable { try { try { + WebActionSet actionSet = method.getDeclaringClass().getAnnotation(WebActionSet.class); + if (actionSet != null) { + checkServicePermissions(method, actionSet); + } WebAction webAction = method.getAnnotation(WebAction.class); if (webAction != null) { - checkPermissions(method, webAction); + checkActionPermissions(method, webAction); } beforeWebActionCall(webAction, method); try { @@ -164,7 +168,19 @@ public abstract class WebServiceBindingBase impleme } } - private void checkPermissions(@NotNull Method method, @NotNull WebAction webAction) throws DBWebException { + private void checkServicePermissions(Method method, WebActionSet actionSet) throws DBWebException { + String[] features = actionSet.requireFeatures(); + if (features.length > 0) { + for (String feature : features) { + if (!CBApplication.getInstance().isConfigurationMode() && + !CBApplication.getInstance().getAppConfiguration().isFeatureEnabled(feature)) { + throw new DBWebException("Feature " + feature + " is disabled"); + } + } + } + } + + private void checkActionPermissions(@NotNull Method method, @NotNull WebAction webAction) throws DBWebException { String[] reqPermissions = webAction.requirePermissions(); if (reqPermissions.length == 0) { return; @@ -200,6 +216,7 @@ public abstract class WebServiceBindingBase impleme } + // Perform any checks before action call protected void beforeWebActionCall(WebAction webAction, Method method) throws DBException { }