mirror of
https://github.com/eclipse-sailing-analytics/sailing-analytics.git
synced 2026-10-09 22:01:02 +00:00
solving bug 2428 by pulling up the doGetAuthorizationInfo method from UsernamePasswordRealm to AbstractUserStoreBasedReal, thus sharing it with OAuthRealm
This commit is contained in:
1 parent
6a8f4d4c89
commit
b604ff0d37
3 files changed
+27
-63
No files matched your search
@@ -1,5 +1,7 @@
|
||||
package com.sap.sse.security;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
import java.util.concurrent.Callable;
|
||||
import java.util.concurrent.ExecutionException;
|
||||
import java.util.concurrent.Future;
|
||||
@@ -7,11 +9,17 @@ import java.util.concurrent.FutureTask;
|
||||
import java.util.logging.Level;
|
||||
import java.util.logging.Logger;
|
||||
|
||||
import org.apache.shiro.authc.AuthenticationException;
|
||||
import org.apache.shiro.authz.AuthorizationInfo;
|
||||
import org.apache.shiro.authz.SimpleAuthorizationInfo;
|
||||
import org.apache.shiro.realm.AuthorizingRealm;
|
||||
import org.apache.shiro.subject.PrincipalCollection;
|
||||
import org.osgi.framework.BundleContext;
|
||||
import org.osgi.util.tracker.ServiceTracker;
|
||||
|
||||
import com.sap.sse.common.Util;
|
||||
import com.sap.sse.security.impl.Activator;
|
||||
import com.sap.sse.security.shared.UserManagementException;
|
||||
|
||||
public abstract class AbstractUserStoreBasedRealm extends AuthorizingRealm {
|
||||
private static final Logger logger = Logger.getLogger(AbstractUserStoreBasedRealm.class.getName());
|
||||
@@ -83,4 +91,23 @@ public abstract class AbstractUserStoreBasedRealm extends AuthorizingRealm {
|
||||
}
|
||||
return result;
|
||||
}
|
||||
|
||||
@Override
|
||||
protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principals) {
|
||||
final SimpleAuthorizationInfo ai = new SimpleAuthorizationInfo();
|
||||
final List<String> roles = new ArrayList<>();
|
||||
final List<String> permissions = new ArrayList<>();
|
||||
for (Object r : principals) {
|
||||
String username = r.toString();
|
||||
try {
|
||||
Util.addAll(getUserStore().getRolesFromUser(username), roles);
|
||||
Util.addAll(getUserStore().getPermissionsFromUser(username), permissions);
|
||||
} catch (UserManagementException e) {
|
||||
throw new AuthenticationException(e.getMessage());
|
||||
}
|
||||
}
|
||||
ai.addRoles(roles);
|
||||
ai.addStringPermissions(permissions);
|
||||
return ai;
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,5 @@
|
||||
package com.sap.sse.security;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.Collection;
|
||||
import java.util.HashMap;
|
||||
import java.util.Map;
|
||||
import java.util.UUID;
|
||||
@@ -12,9 +10,6 @@ import org.apache.shiro.authc.AuthenticationException;
|
||||
import org.apache.shiro.authc.AuthenticationInfo;
|
||||
import org.apache.shiro.authc.AuthenticationToken;
|
||||
import org.apache.shiro.authc.SimpleAuthenticationInfo;
|
||||
import org.apache.shiro.authz.AuthorizationInfo;
|
||||
import org.apache.shiro.authz.Permission;
|
||||
import org.apache.shiro.subject.PrincipalCollection;
|
||||
import org.apache.shiro.subject.SimplePrincipalCollection;
|
||||
import org.json.simple.JSONObject;
|
||||
import org.json.simple.parser.JSONParser;
|
||||
@@ -49,37 +44,6 @@ public class OAuthRealm extends AbstractUserStoreBasedRealm {
|
||||
super();
|
||||
}
|
||||
|
||||
@Override
|
||||
protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection token) {
|
||||
AuthorizationInfo info = new AuthorizationInfo() {
|
||||
private static final long serialVersionUID = 1L;
|
||||
|
||||
@Override
|
||||
public Collection<String> getStringPermissions() {
|
||||
return new ArrayList<String>();
|
||||
}
|
||||
|
||||
@Override
|
||||
public Collection<String> getRoles() {
|
||||
ArrayList<String> roles = new ArrayList<>();
|
||||
return roles;
|
||||
}
|
||||
|
||||
@Override
|
||||
public Collection<Permission> getObjectPermissions() {
|
||||
ArrayList<Permission> permissions = new ArrayList<>();
|
||||
permissions.add(new Permission() {
|
||||
@Override
|
||||
public boolean implies(Permission arg0) {
|
||||
return false;
|
||||
}
|
||||
});
|
||||
return permissions;
|
||||
}
|
||||
};
|
||||
return info;
|
||||
}
|
||||
|
||||
@Override
|
||||
public boolean supports(AuthenticationToken token) {
|
||||
if (token == null)
|
||||
|
||||
@@ -1,20 +1,12 @@
|
||||
package com.sap.sse.security;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
import org.apache.shiro.authc.AuthenticationException;
|
||||
import org.apache.shiro.authc.AuthenticationInfo;
|
||||
import org.apache.shiro.authc.AuthenticationToken;
|
||||
import org.apache.shiro.authc.SaltedAuthenticationInfo;
|
||||
import org.apache.shiro.authc.UsernamePasswordToken;
|
||||
import org.apache.shiro.authz.AuthorizationInfo;
|
||||
import org.apache.shiro.authz.SimpleAuthorizationInfo;
|
||||
import org.apache.shiro.subject.PrincipalCollection;
|
||||
|
||||
import com.sap.sse.common.Util;
|
||||
import com.sap.sse.security.shared.Account.AccountType;
|
||||
import com.sap.sse.security.shared.UserManagementException;
|
||||
import com.sap.sse.security.shared.UsernamePasswordAccount;
|
||||
|
||||
public class UsernamePasswordRealm extends AbstractUserStoreBasedRealm {
|
||||
@@ -36,25 +28,6 @@ public class UsernamePasswordRealm extends AbstractUserStoreBasedRealm {
|
||||
return result;
|
||||
}
|
||||
|
||||
@Override
|
||||
protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principals) {
|
||||
final SimpleAuthorizationInfo ai = new SimpleAuthorizationInfo();
|
||||
final List<String> roles = new ArrayList<>();
|
||||
final List<String> permissions = new ArrayList<>();
|
||||
for (Object r : principals) {
|
||||
String username = r.toString();
|
||||
try {
|
||||
Util.addAll(getUserStore().getRolesFromUser(username), roles);
|
||||
Util.addAll(getUserStore().getPermissionsFromUser(username), permissions);
|
||||
} catch (UserManagementException e) {
|
||||
throw new AuthenticationException(e.getMessage());
|
||||
}
|
||||
}
|
||||
ai.addRoles(roles);
|
||||
ai.addStringPermissions(permissions);
|
||||
return ai;
|
||||
}
|
||||
|
||||
@Override
|
||||
protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken token) throws AuthenticationException {
|
||||
UsernamePasswordToken userPassToken = (UsernamePasswordToken) token;
|
||||
|
||||
Reference in new issue
Block a user