CB-3008 TE: limit access to private project (#1467)

* CB-3008 TE: limit access to private project

Creates an "isPrivateProjectsAccessible" flag in the RM config with default == false, which excludes private projects from the getProjects request on the TE-only backend.

* CB-3008 TE: limit access to private project

Implements same behavior in all products

* CB-3092
Run CB product in Idea without Eclipse manual configuration

Fixes user permissions check

* CB-3008 TE: limit access to private project

Code style fixes

---------

Co-authored-by: Iaroslav Emelianov <iaroslav.emelianov@dbeaver.com>
This commit is contained in:
Yaroslav Emelyanov
2023-02-28 22:26:12 +03:00
committed by GitHub
co-authored by Iaroslav Emelianov
parent 5824cba180
commit eb0186e243
3 changed files with 11 additions and 6 deletions
@@ -41,4 +41,8 @@ public interface WebAppConfiguration {
boolean isFeaturesEnabled(String[] requiredFeatures);
boolean isFeatureEnabled(String id);
default boolean isSupportsCustomConnections() {
return true;
}
}
@@ -40,7 +40,6 @@ import org.jkiss.dbeaver.model.impl.auth.SessionContextImpl;
import org.jkiss.dbeaver.model.rm.*;
import org.jkiss.dbeaver.model.runtime.VoidProgressMonitor;
import org.jkiss.dbeaver.model.security.SMController;
import org.jkiss.dbeaver.model.security.SMObjectType;
import org.jkiss.dbeaver.model.security.SMObjects;
import org.jkiss.dbeaver.model.sql.DBQuotaException;
import org.jkiss.dbeaver.registry.*;
@@ -152,16 +151,18 @@ public class LocalResourceController implements RMController {
projects.add(globalProject);
}
// check if user has permission for private project
var hasPrivateProjectPermission = activeUserCreds != null &&
activeUserCreds.hasPermission(DBWConstants.PERMISSION_PRIVATE_PROJECT_ACCESS);
if (!WebAppUtils.getWebApplication().isMultiNode() || hasPrivateProjectPermission) {
// Checking if private projects are enabled in the configuration and if the user has permission to them
var webApp = WebAppUtils.getWebApplication();
var userHasPrivateProjectPermission = !webApp.isMultiNode() ||
activeUserCreds != null && activeUserCreds.hasPermission(DBWConstants.PERMISSION_PRIVATE_PROJECT_ACCESS);
if (webApp.getAppConfiguration().isSupportsCustomConnections() && userHasPrivateProjectPermission) {
var userProjectPermission = getProjectPermissions(null, RMProjectType.USER);
RMProject userProject = makeProjectFromPath(getPrivateProjectPath(), userProjectPermission, RMProjectType.USER, false);
if (userProject != null) {
projects.add(0, userProject);
}
}
projects.sort(Comparator.comparing(RMProject::getDisplayName));
return projects.toArray(new RMProject[0]);
}
@@ -120,7 +120,7 @@ public class CBAppConfig extends BaseAuthWebAppConfiguration implements WebAuthC
public void setResourceManagerEnabled(boolean resourceManagerEnabled) {
this.resourceManagerEnabled = resourceManagerEnabled;
}
public boolean isSupportsCustomConnections() {
return supportsCustomConnections;
}