Merge branch 'devel' of https://github.com/dbeaver/cloudbeaver into devel

This commit is contained in:
Wroud
2022-06-23 18:04:38 +03:00
5 changed files with 55 additions and 29 deletions
@@ -821,7 +821,10 @@ public class WebSession extends AbstractSessionPersistent implements SMSession,
if (providerId == null) {
clearAuthTokens();
} else {
removeAuthInfo(getAuthInfo(providerId));
WebAuthInfo authInfo = getAuthInfo(providerId);
if (authInfo != null) {
removeAuthInfo(authInfo);
}
}
if (authTokens.isEmpty()) {
resetUserState();
@@ -49,6 +49,7 @@ public class CBAppConfig extends BaseWebAppConfiguration {
private boolean forwardProxy;
private boolean publicCredentialsSaveEnabled;
private boolean adminCredentialsSaveEnabled;
private boolean linkExternalCredentialsWithUser;
private boolean redirectOnFederatedAuth;
@@ -81,6 +82,7 @@ public class CBAppConfig extends BaseWebAppConfiguration {
this.resourceQuotas = new LinkedHashMap<>();
this.enableReverseProxyAuth = false;
this.forwardProxy = false;
this.linkExternalCredentialsWithUser = true;
}
public CBAppConfig(CBAppConfig src) {
@@ -101,6 +103,7 @@ public class CBAppConfig extends BaseWebAppConfiguration {
this.resourceQuotas = new LinkedHashMap<>(src.resourceQuotas);
this.enableReverseProxyAuth = src.enableReverseProxyAuth;
this.forwardProxy = src.forwardProxy;
this.linkExternalCredentialsWithUser = src.linkExternalCredentialsWithUser;
}
@@ -306,6 +309,11 @@ public class CBAppConfig extends BaseWebAppConfiguration {
}
}
public boolean isLinkExternalCredentialsWithUser() {
return linkExternalCredentialsWithUser;
}
////////////////////////////////////////////
// Reverse proxy auth
@@ -599,30 +599,39 @@ public class CBApplication extends BaseWebApplication {
}
protected Map<String, Object> readConfiguration(File configFile) throws DBException {
try (Reader reader = new InputStreamReader(new FileInputStream(configFile), StandardCharsets.UTF_8)) {
Map<String, Object> configProps = JSONUtils.parseMap(getGson(), reader);
patchConfigurationWithProperties(configProps); // patch original properties
readAdditionalConfiguration(configProps);
Map<String, Object> serverConfig = getServerConfigProps(configProps);
Map<String, Object> configProps = new LinkedHashMap<>();
if (configFile.exists()) {
log.debug("Read configuration [" + configFile.getAbsolutePath() + "]");
try (Reader reader = new InputStreamReader(new FileInputStream(configFile), StandardCharsets.UTF_8)) {
configProps.putAll(JSONUtils.parseMap(getGson(), reader));
patchConfigurationWithProperties(configProps); // patch original properties
String externalPropertiesFile = JSONUtils.getString(serverConfig, CBConstants.PARAM_EXTERNAL_PROPERTIES);
if (!CommonUtils.isEmpty(externalPropertiesFile)) {
Properties props = new Properties();
try (InputStream is = Files.newInputStream(Path.of(externalPropertiesFile))) {
props.load(is);
} catch (IOException e) {
log.error("Error loading external properties from " + externalPropertiesFile, e);
}
for (String propName : props.stringPropertyNames()) {
this.externalProperties.put(propName, props.getProperty(propName));
}
} catch (IOException e) {
throw new DBException("Error parsing server configuration", e);
}
patchConfigurationWithProperties(configProps); // patch again because properties can be changed
return configProps;
} catch (IOException e) {
throw new DBException("Error parsing server configuration", e);
}
readAdditionalConfiguration(configProps);
if (configProps.isEmpty()) {
return Map.of();
}
Map<String, Object> serverConfig = getServerConfigProps(configProps);
String externalPropertiesFile = JSONUtils.getString(serverConfig, CBConstants.PARAM_EXTERNAL_PROPERTIES);
if (!CommonUtils.isEmpty(externalPropertiesFile)) {
Properties props = new Properties();
try (InputStream is = Files.newInputStream(Path.of(externalPropertiesFile))) {
props.load(is);
} catch (IOException e) {
log.error("Error loading external properties from " + externalPropertiesFile, e);
}
for (String propName : props.stringPropertyNames()) {
this.externalProperties.put(propName, props.getProperty(propName));
}
}
patchConfigurationWithProperties(configProps); // patch again because properties can be changed
return configProps;
}
private Gson getGson() {
@@ -736,11 +745,7 @@ public class CBApplication extends BaseWebApplication {
private Map<String, Object> readRuntimeConfigurationProperties() throws DBException {
File runtimeConfigFile = getRuntimeAppConfigFile();
if (runtimeConfigFile.exists()) {
log.debug("Runtime configuration [" + runtimeConfigFile.getAbsolutePath() + "]");
return readConfiguration(runtimeConfigFile);
}
return Map.of();
return readConfiguration(runtimeConfigFile);
}
protected void finishSecurityServiceConfiguration(@NotNull String adminName, @Nullable String adminPassword, @NotNull List<WebAuthInfo> authInfoList) throws DBException {
@@ -824,6 +829,7 @@ public class CBApplication extends BaseWebApplication {
appConfigProperties.put("adminCredentialsSaveEnabled", appConfig.isAdminCredentialsSaveEnabled());
appConfigProperties.put("enableReverseProxyAuth", appConfig.isEnabledReverseProxyAuth());
appConfigProperties.put("forwardProxy", appConfig.isEnabledForwardProxy());
appConfigProperties.put("linkExternalCredentialsWithUser", appConfig.isLinkExternalCredentialsWithUser());
appConfigProperties.put(CBConstants.PARAM_RESOURCE_MANAGER_ENABLED, appConfig.isResourceManagerEnabled());
Map<String, Object> resourceQuotas = appConfig.getResourceQuotas();
@@ -146,7 +146,9 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
userId = curUser.getUserId();
if (authProviderExternal != null) {
// We may need to associate new credentials with active user
if (linkWithActiveUser) {
if (linkWithActiveUser &&
CBApplication.getInstance().getAppConfiguration().isLinkExternalCredentialsWithUser()
) {
securityController.setUserCredentials(userId, authProvider.getId(), userCredentials);
}
}
@@ -351,7 +351,7 @@ public class CBEmbeddedSecurityController implements SMAdminController {
///////////////////////////////////////////
// Credentials
private static SMAuthCredentialsProfile getCredentialProfileByParameters(SMAuthProviderDescriptor authProvider, Set<String> keySet) {
private static SMAuthCredentialsProfile getCredentialProfileByParameters(AuthProviderDescriptor authProvider, Set<String> keySet) {
List<SMAuthCredentialsProfile> credentialProfiles = authProvider.getCredentialProfiles();
if (credentialProfiles.size() > 1) {
for (SMAuthCredentialsProfile profile : credentialProfiles) {
@@ -953,6 +953,13 @@ public class CBEmbeddedSecurityController implements SMAdminController {
return new SMAuthPermissions(userId, sessionId, permissions);
}
@Override
public SMAuthProviderDescriptor[] getAvailableAuthProviders() {
return AuthProviderRegistry.getInstance().getAuthProviders().stream()
.filter(ap -> !ap.isTrusted())
.map(AuthProviderDescriptor::createDescriptorBean).toArray(SMAuthProviderDescriptor[]::new);
}
@Override
public void updateSession(@NotNull String sessionId, @Nullable String userId, @NotNull Map<String, Object> parameters) throws DBCException {
try (Connection dbCon = database.openConnection()) {