Files
SCM-Manager/scm-webapp/src/main/java/sonia/scm/user/DefaultUserManager.java

554 lines
12 KiB
Java
Raw Normal View History

/**
* Copyright (c) 2010, Sebastian Sdorra
* All rights reserved.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions are met:
*
* 1. Redistributions of source code must retain the above copyright notice,
* this list of conditions and the following disclaimer.
* 2. Redistributions in binary form must reproduce the above copyright notice,
* this list of conditions and the following disclaimer in the documentation
* and/or other materials provided with the distribution.
* 3. Neither the name of SCM-Manager; nor the names of its
* contributors may be used to endorse or promote products derived from this
* software without specific prior written permission.
*
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
* AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
* DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE FOR ANY
* DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
* (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
* LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON
* ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
* (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
* SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
*
* http://bitbucket.org/sdorra/scm-manager
*
*/
package sonia.scm.user;
//~--- non-JDK imports --------------------------------------------------------
2010-11-28 11:32:41 +01:00
import com.google.inject.Inject;
import com.google.inject.Provider;
import com.google.inject.Singleton;
import org.apache.shiro.SecurityUtils;
import org.apache.shiro.subject.Subject;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
2011-01-02 14:04:51 +01:00
import sonia.scm.HandlerEvent;
import sonia.scm.SCMContextProvider;
2011-02-12 15:43:27 +01:00
import sonia.scm.TransformFilter;
2011-02-11 19:44:10 +01:00
import sonia.scm.search.SearchRequest;
import sonia.scm.search.SearchUtil;
import sonia.scm.security.Role;
import sonia.scm.security.ScmSecurityException;
2011-01-04 17:17:48 +01:00
import sonia.scm.util.AssertUtil;
import sonia.scm.util.CollectionAppender;
import sonia.scm.util.IOUtil;
2010-11-28 11:32:41 +01:00
import sonia.scm.util.SecurityUtil;
2010-11-26 15:37:35 +01:00
import sonia.scm.util.Util;
//~--- JDK imports ------------------------------------------------------------
import java.io.IOException;
import java.io.InputStream;
import java.util.ArrayList;
import java.util.Collection;
2011-06-09 22:10:30 +02:00
import java.util.Collections;
2011-06-09 21:46:22 +02:00
import java.util.Comparator;
import java.util.List;
import java.util.Set;
2010-12-30 13:03:01 +01:00
import javax.xml.bind.JAXBContext;
import javax.xml.bind.JAXBException;
import javax.xml.bind.Unmarshaller;
/**
*
* @author Sebastian Sdorra
*/
@Singleton
public class DefaultUserManager extends AbstractUserManager
{
/** Field description */
2010-11-06 15:56:44 +01:00
public static final String ADMIN_PATH = "/sonia/scm/config/admin-account.xml";
2010-12-30 13:03:01 +01:00
/** Field description */
public static final String ANONYMOUS_PATH =
"/sonia/scm/config/anonymous-account.xml";
/** Field description */
2010-12-05 19:26:38 +01:00
public static final String STORE_NAME = "users";
2010-11-26 15:37:35 +01:00
/** the logger for XmlUserManager */
private static final Logger logger =
LoggerFactory.getLogger(DefaultUserManager.class);
2010-11-28 11:32:41 +01:00
//~--- constructors ---------------------------------------------------------
/**
* Constructs ...
*
*
* @param scurityContextProvider
* @param userDAO
* @param userListenerProvider
2010-11-28 11:32:41 +01:00
*/
@Inject
public DefaultUserManager(UserDAO userDAO,
Provider<Set<UserListener>> userListenerProvider)
2010-11-28 11:32:41 +01:00
{
this.userDAO = userDAO;
this.userListenerProvider = userListenerProvider;
2010-11-28 11:32:41 +01:00
}
//~--- methods --------------------------------------------------------------
/**
* Method description
*
*
* @throws IOException
*/
@Override
public void close() throws IOException
{
// do nothing
}
2010-12-04 15:58:13 +01:00
/**
* Method description
*
*
* @param username
*
* @return
*/
@Override
public boolean contains(String username)
{
return userDAO.contains(username);
2010-12-04 15:58:13 +01:00
}
/**
* Method description
*
*
* @param user
*
* @throws IOException
* @throws UserException
*/
@Override
public void create(User user) throws UserException, IOException
{
2012-03-16 09:44:32 +01:00
String type = user.getType();
if (Util.isEmpty(type))
{
user.setType(userDAO.getType());
}
2010-12-05 17:33:29 +01:00
if (logger.isInfoEnabled())
{
logger.info("create user {} of type {}", user.getName(), user.getType());
}
Subject subject = SecurityUtils.getSubject();
2013-04-24 08:33:32 +02:00
if (!subject.hasRole(Role.USER))
{
throw new ScmSecurityException("user is not authenticated");
}
if (!subject.hasRole(Role.ADMIN))
{
throw new ScmSecurityException("admin account is required");
}
2010-11-28 11:32:41 +01:00
if (userDAO.contains(user.getName()))
{
throw new UserAllreadyExistException(user.getName());
}
2011-01-04 17:28:09 +01:00
AssertUtil.assertIsValid(user);
2010-12-05 17:46:26 +01:00
user.setCreationDate(System.currentTimeMillis());
fireEvent(user, HandlerEvent.BEFORE_CREATE);
userDAO.add(user);
2011-01-02 14:04:51 +01:00
fireEvent(user, HandlerEvent.CREATE);
}
/**
* Method description
*
*
* @param user
*
* @throws IOException
* @throws UserException
*/
@Override
public void delete(User user) throws UserException, IOException
{
2010-12-05 17:33:29 +01:00
if (logger.isInfoEnabled())
{
logger.info("delete user {} of type {}", user.getName(), user.getType());
}
SecurityUtil.assertIsAdmin();
2010-11-28 11:32:41 +01:00
2010-11-07 15:19:00 +01:00
String name = user.getName();
if (userDAO.contains(name))
{
fireEvent(user, HandlerEvent.BEFORE_DELETE);
userDAO.delete(user);
2011-01-02 14:04:51 +01:00
fireEvent(user, HandlerEvent.DELETE);
}
else
{
throw new UserNotFoundException("user does not exists");
}
}
/**
* Method description
*
*
* @param context
*/
@Override
public void init(SCMContextProvider context)
{
// TODO improve
if (!userDAO.contains("scmadmin") &&!userDAO.contains("anonymous"))
{
2010-12-30 13:03:01 +01:00
createDefaultAccounts();
}
Set<UserListener> listeners = userListenerProvider.get();
if (Util.isNotEmpty(listeners))
{
addListeners(listeners);
}
}
/**
* Method description
*
*
* @param user
*
* @throws IOException
* @throws UserException
*/
@Override
public void modify(User user) throws UserException, IOException
{
2010-12-05 17:33:29 +01:00
if (logger.isInfoEnabled())
{
logger.info("modify user {} of type {}", user.getName(), user.getType());
}
Subject subject = SecurityUtils.getSubject();
2010-12-04 16:18:47 +01:00
if (!subject.isAuthenticated())
{
throw new ScmSecurityException("user is not authenticated");
}
User currentUser = subject.getPrincipals().oneByType(User.class);
if (!user.getName().equals(currentUser.getName())
&&!subject.hasRole(Role.ADMIN))
2010-12-04 16:18:47 +01:00
{
throw new ScmSecurityException("admin account is required");
}
2010-11-28 11:32:41 +01:00
2010-11-07 15:19:00 +01:00
String name = user.getName();
if (userDAO.contains(name))
{
2011-01-04 17:28:09 +01:00
AssertUtil.assertIsValid(user);
user.setLastModified(System.currentTimeMillis());
fireEvent(user, HandlerEvent.BEFORE_MODIFY);
userDAO.modify(user);
2011-01-02 14:04:51 +01:00
fireEvent(user, HandlerEvent.MODIFY);
}
else
{
throw new UserNotFoundException("user does not exists");
}
}
/**
* Method description
*
*
* @param user
*
* @throws IOException
* @throws UserException
*/
2010-11-26 15:37:35 +01:00
@Override
public void refresh(User user) throws UserException, IOException
{
2010-12-05 17:33:29 +01:00
if (logger.isInfoEnabled())
{
logger.info("refresh user {} of type {}", user.getName(), user.getType());
}
SecurityUtil.assertIsAdmin();
2010-11-28 11:32:41 +01:00
User fresh = userDAO.get(user.getName());
if (fresh == null)
{
throw new UserNotFoundException("user does not exists");
}
fresh.copyProperties(user);
}
2011-02-11 19:44:10 +01:00
/**
* Method description
*
*
* @param searchRequest
*
* @return
*/
@Override
public Collection<User> search(final SearchRequest searchRequest)
{
2011-02-12 11:24:08 +01:00
if (logger.isDebugEnabled())
{
logger.debug("search user with query {}", searchRequest.getQuery());
}
return SearchUtil.search(searchRequest, userDAO.getAll(),
new TransformFilter<User>()
2011-02-11 19:44:10 +01:00
{
2011-02-12 15:43:27 +01:00
@Override
public User accept(User user)
2011-02-11 19:44:10 +01:00
{
2011-02-12 15:43:27 +01:00
User result = null;
2011-02-11 19:44:10 +01:00
2011-02-12 15:43:27 +01:00
if (SearchUtil.matchesOne(searchRequest, user.getName(),
user.getDisplayName(), user.getMail()))
2011-02-11 19:44:10 +01:00
{
2011-02-12 15:43:27 +01:00
result = user.clone();
2011-02-11 19:44:10 +01:00
}
2011-02-12 15:43:27 +01:00
return result;
}
});
2011-02-11 19:44:10 +01:00
}
//~--- get methods ----------------------------------------------------------
/**
* Method description
*
*
* @param id
*
* @return
*/
2010-11-26 15:37:35 +01:00
@Override
public User get(String id)
{
2010-11-28 11:32:41 +01:00
// SecurityUtil.assertIsAdmin(scurityContextProvider);
User user = userDAO.get(id);
2010-11-07 15:19:00 +01:00
if (user != null)
{
2010-11-07 15:19:00 +01:00
user = user.clone();
}
return user;
}
/**
* Method description
*
*
* @return
*/
2010-11-26 15:37:35 +01:00
@Override
public Collection<User> getAll()
2011-06-09 22:10:30 +02:00
{
return getAll(null);
}
/**
* Method description
*
*
* @param comparator
*
* @return
*/
@Override
public Collection<User> getAll(Comparator<User> comparator)
{
SecurityUtil.assertIsAdmin();
2010-11-28 11:32:41 +01:00
2011-06-09 22:10:30 +02:00
List<User> users = new ArrayList<User>();
for (User user : userDAO.getAll())
{
2010-11-07 15:19:00 +01:00
users.add(user.clone());
}
2011-06-09 22:10:30 +02:00
if (comparator != null)
{
Collections.sort(users, comparator);
}
return users;
}
/**
* Method description
*
*
2011-06-09 21:46:22 +02:00
*
* @param comaparator
* @param start
* @param limit
*
* @return
*/
@Override
2011-06-09 21:46:22 +02:00
public Collection<User> getAll(Comparator<User> comaparator, int start,
int limit)
{
SecurityUtil.assertIsAdmin();
2011-06-09 22:11:59 +02:00
return Util.createSubCollection(userDAO.getAll(), comaparator,
new CollectionAppender<User>()
{
@Override
public void append(Collection<User> collection, User item)
{
collection.add(item.clone());
}
}, start, limit);
}
2011-06-09 21:46:22 +02:00
/**
* Method description
*
*
* @param start
* @param limit
*
* @return
*/
@Override
public Collection<User> getAll(int start, int limit)
{
return getAll(null, start, limit);
}
2012-03-16 09:44:32 +01:00
/**
* Method description
*
*
* @return
*/
@Override
public String getDefaultType()
{
return userDAO.getType();
}
2011-02-12 19:55:18 +01:00
/**
* Method description
*
*
* @return
*/
@Override
public Long getLastModified()
{
return userDAO.getLastModified();
2011-02-12 19:55:18 +01:00
}
//~--- methods --------------------------------------------------------------
/**
* Method description
*
2010-12-30 13:03:01 +01:00
*
* @param unmarshaller
* @param path
*/
2010-12-30 13:03:01 +01:00
private void createDefaultAccount(Unmarshaller unmarshaller, String path)
{
InputStream input = DefaultUserManager.class.getResourceAsStream(path);
try
{
2010-12-30 13:03:01 +01:00
User user = (User) unmarshaller.unmarshal(input);
2010-11-07 15:19:00 +01:00
user.setType(userDAO.getType());
2010-12-31 14:58:11 +01:00
user.setCreationDate(System.currentTimeMillis());
userDAO.add(user);
}
2010-11-07 15:19:00 +01:00
catch (Exception ex)
{
2010-12-30 13:03:01 +01:00
logger.error("could not create account", ex);
}
finally
{
IOUtil.close(input);
}
}
2010-12-30 13:03:01 +01:00
/**
* Method description
*
*/
private void createDefaultAccounts()
{
try
{
JAXBContext context = JAXBContext.newInstance(User.class);
Unmarshaller unmarshaller = context.createUnmarshaller();
createDefaultAccount(unmarshaller, ADMIN_PATH);
createDefaultAccount(unmarshaller, ANONYMOUS_PATH);
}
catch (JAXBException ex)
{
2012-10-04 10:50:19 +02:00
logger.error("could not create default accounts", ex);
2010-12-30 13:03:01 +01:00
}
}
//~--- fields ---------------------------------------------------------------
2010-12-05 18:02:35 +01:00
/** Field description */
private UserDAO userDAO;
/** Field description */
private Provider<Set<UserListener>> userListenerProvider;
}