solving bug 2428 by pulling up the doGetAuthorizationInfo method from UsernamePasswordRealm to AbstractUserStoreBasedReal, thus sharing it with OAuthRealm

This commit is contained in:
Axel Uhl committed 2014-12-01 17:54:09 +01:00
1 parent 6a8f4d4c89
commit b604ff0d37
3 files changed
+27 -63

No files matched your search

@@ -1,5 +1,7 @@
package com.sap.sse.security;
import java.util.ArrayList;
import java.util.List;
import java.util.concurrent.Callable;
import java.util.concurrent.ExecutionException;
import java.util.concurrent.Future;
@@ -7,11 +9,17 @@ import java.util.concurrent.FutureTask;
import java.util.logging.Level;
import java.util.logging.Logger;
import org.apache.shiro.authc.AuthenticationException;
import org.apache.shiro.authz.AuthorizationInfo;
import org.apache.shiro.authz.SimpleAuthorizationInfo;
import org.apache.shiro.realm.AuthorizingRealm;
import org.apache.shiro.subject.PrincipalCollection;
import org.osgi.framework.BundleContext;
import org.osgi.util.tracker.ServiceTracker;
import com.sap.sse.common.Util;
import com.sap.sse.security.impl.Activator;
import com.sap.sse.security.shared.UserManagementException;
public abstract class AbstractUserStoreBasedRealm extends AuthorizingRealm {
private static final Logger logger = Logger.getLogger(AbstractUserStoreBasedRealm.class.getName());
@@ -83,4 +91,23 @@ public abstract class AbstractUserStoreBasedRealm extends AuthorizingRealm {
}
return result;
}
@Override
protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principals) {
final SimpleAuthorizationInfo ai = new SimpleAuthorizationInfo();
final List<String> roles = new ArrayList<>();
final List<String> permissions = new ArrayList<>();
for (Object r : principals) {
String username = r.toString();
try {
Util.addAll(getUserStore().getRolesFromUser(username), roles);
Util.addAll(getUserStore().getPermissionsFromUser(username), permissions);
} catch (UserManagementException e) {
throw new AuthenticationException(e.getMessage());
}
}
ai.addRoles(roles);
ai.addStringPermissions(permissions);
return ai;
}
}
@@ -1,7 +1,5 @@
package com.sap.sse.security;
import java.util.ArrayList;
import java.util.Collection;
import java.util.HashMap;
import java.util.Map;
import java.util.UUID;
@@ -12,9 +10,6 @@ import org.apache.shiro.authc.AuthenticationException;
import org.apache.shiro.authc.AuthenticationInfo;
import org.apache.shiro.authc.AuthenticationToken;
import org.apache.shiro.authc.SimpleAuthenticationInfo;
import org.apache.shiro.authz.AuthorizationInfo;
import org.apache.shiro.authz.Permission;
import org.apache.shiro.subject.PrincipalCollection;
import org.apache.shiro.subject.SimplePrincipalCollection;
import org.json.simple.JSONObject;
import org.json.simple.parser.JSONParser;
@@ -49,37 +44,6 @@ public class OAuthRealm extends AbstractUserStoreBasedRealm {
super();
}
@Override
protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection token) {
AuthorizationInfo info = new AuthorizationInfo() {
private static final long serialVersionUID = 1L;
@Override
public Collection<String> getStringPermissions() {
return new ArrayList<String>();
}
@Override
public Collection<String> getRoles() {
ArrayList<String> roles = new ArrayList<>();
return roles;
}
@Override
public Collection<Permission> getObjectPermissions() {
ArrayList<Permission> permissions = new ArrayList<>();
permissions.add(new Permission() {
@Override
public boolean implies(Permission arg0) {
return false;
}
});
return permissions;
}
};
return info;
}
@Override
public boolean supports(AuthenticationToken token) {
if (token == null)
@@ -1,20 +1,12 @@
package com.sap.sse.security;
import java.util.ArrayList;
import java.util.List;
import org.apache.shiro.authc.AuthenticationException;
import org.apache.shiro.authc.AuthenticationInfo;
import org.apache.shiro.authc.AuthenticationToken;
import org.apache.shiro.authc.SaltedAuthenticationInfo;
import org.apache.shiro.authc.UsernamePasswordToken;
import org.apache.shiro.authz.AuthorizationInfo;
import org.apache.shiro.authz.SimpleAuthorizationInfo;
import org.apache.shiro.subject.PrincipalCollection;
import com.sap.sse.common.Util;
import com.sap.sse.security.shared.Account.AccountType;
import com.sap.sse.security.shared.UserManagementException;
import com.sap.sse.security.shared.UsernamePasswordAccount;
public class UsernamePasswordRealm extends AbstractUserStoreBasedRealm {
@@ -36,25 +28,6 @@ public class UsernamePasswordRealm extends AbstractUserStoreBasedRealm {
return result;
}
@Override
protected AuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principals) {
final SimpleAuthorizationInfo ai = new SimpleAuthorizationInfo();
final List<String> roles = new ArrayList<>();
final List<String> permissions = new ArrayList<>();
for (Object r : principals) {
String username = r.toString();
try {
Util.addAll(getUserStore().getRolesFromUser(username), roles);
Util.addAll(getUserStore().getPermissionsFromUser(username), permissions);
} catch (UserManagementException e) {
throw new AuthenticationException(e.getMessage());
}
}
ai.addRoles(roles);
ai.addStringPermissions(permissions);
return ai;
}
@Override
protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken token) throws AuthenticationException {
UsernamePasswordToken userPassToken = (UsernamePasswordToken) token;