CB-1001 Role users and connections API

This commit is contained in:
Serge Rider
2021-09-02 12:31:13 +03:00
parent 6676521f42
commit e59ec00ef5
4 changed files with 41 additions and 0 deletions
@@ -83,6 +83,9 @@ public interface DBWSecurityController {
WebRole[] findRoles(String roleName) throws DBCException;
@NotNull
String[] getRoleSubjects(String roleId) throws DBCException;
void createRole(WebRole role) throws DBCException;
void updateRole(WebRole role) throws DBCException;
@@ -433,6 +433,26 @@ class CBSecurityController implements DBWSecurityController {
return readAllRoles();
}
@NotNull
@Override
public String[] getRoleSubjects(String roleId) throws DBCException {
try (Connection dbCon = database.openConnection()) {
try (PreparedStatement dbStat = dbCon.prepareStatement(
"SELECT USER_ID FROM CB_USER_ROLE WHERE ROLE_ID")) {
dbStat.setString(1, roleId);
List<String> subjects = new ArrayList<>();
try (ResultSet dbResult = dbStat.executeQuery()) {
while (dbResult.next()) {
subjects.add(dbResult.getString(1));
}
}
return subjects.toArray(new String[0]);
}
} catch (SQLException e) {
throw new DBCException("Error while reading role subjects", e);
}
}
@NotNull
private WebRole fetchRole(ResultSet dbResult) throws SQLException {
WebRole role = new WebRole(dbResult.getString("ROLE_ID"));
@@ -36,6 +36,9 @@ type AdminRoleInfo {
roleName: String
description: String
grantedUsers: [ID!]!
grantedConnections: [AdminConnectionGrantInfo!]!
rolePermissions: [ID]!
}
@@ -16,7 +16,11 @@
*/
package io.cloudbeaver.service.admin;
import io.cloudbeaver.DBWConnectionGrant;
import io.cloudbeaver.model.user.WebRole;
import io.cloudbeaver.server.CBPlatform;
import org.jkiss.dbeaver.model.exec.DBCException;
import org.jkiss.dbeaver.model.meta.Property;
import java.util.List;
@@ -51,4 +55,15 @@ public class AdminRoleInfo {
public void setRolePermissions(List<String> rolePermissions) {
this.rolePermissions = rolePermissions;
}
@Property
public DBWConnectionGrant[] getGrantedConnections() throws DBCException {
return CBPlatform.getInstance().getApplication().getSecurityController().getSubjectConnectionAccess(new String[] { getRoleId()} );
}
@Property
public String[] getGrantedUsers() throws DBCException {
return CBPlatform.getInstance().getApplication().getSecurityController().getRoleSubjects(getRoleId());
}
}