StringConditionResource.java
/*
** Module : StringConditionResource.java
** Abstract : plugin to manage access to any resource with a simple string expression
**
** Copyright (c) 2014-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- ----------------------------Description-----------------------------------
** 001 GES 20160222 Created the first version, using nearly the complete implementation from
** EntryPointResource.
** 002 HC 20170612 Changes related to implementation of new GWT-based Admin client.
** 003 GBB 20230512 Logging methods replaced by CentralLogger/ConversionStatus.
*/
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
**
** Additional terms under GNU Affero GPL version 3 section 7:
**
** Under Section 7 of the GNU Affero GPL version 3, the following additional
** terms apply to the works covered under the License. These additional terms
** are non-permissive additional terms allowed under Section 7 of the GNU
** Affero GPL version 3 and may not be removed by you.
**
** 0. Attribution Requirement.
**
** You must preserve all legal notices or author attributions in the covered
** work or Appropriate Legal Notices displayed by works containing the covered
** work. You may not remove from the covered work any author or developer
** credit already included within the covered work.
**
** 1. No License To Use Trademarks.
**
** This license does not grant any license or rights to use the trademarks
** Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
** of Golden Code Development Corporation. You are not authorized to use the
** name Golden Code, FWD, or the names of any author or contributor, for
** publicity purposes without written authorization.
**
** 2. No Misrepresentation of Affiliation.
**
** You may not represent yourself as Golden Code Development Corporation or FWD.
**
** You may not represent yourself for publicity purposes as associated with
** Golden Code Development Corporation, FWD, or any author or contributor to
** the covered work, without written authorization.
**
** 3. No Misrepresentation of Source or Origin.
**
** You may not represent the covered work as solely your work. All modified
** versions of the covered work must be marked in a reasonable way to make it
** clear that the modified work is not originating from Golden Code Development
** Corporation or FWD. All modified versions must contain the notices of
** attribution required in this license.
*/
package com.goldencode.p2j.security;
import com.goldencode.p2j.directory.*;
import com.goldencode.expr.*;
import com.goldencode.p2j.util.logging.*;
import java.util.logging.*;
/**
* Implements a resource that is protected by a single string that describes the condition
* for which to allow access. That condition is a matching expression (exact match or
* regex). This is meant to be a parent class where there is almost no code in the child.
*/
public class StringConditionResource
extends AbstractResource
{
/** Logger. */
private static final CentralLogger LOG = CentralLogger.get(StringConditionResource.class);
/**
* Default constructor.
*/
public StringConditionResource()
{
}
/**
* Returns the plugin resource type name as a string.
*
* @return The plugin resource type name.
*/
public String getTypeName()
{
return "stringcondition";
}
/**
* Returns an array of descriptions, one object per the plugin's access rights item.
*
* @return An array of <code>Description</code> elements, one for each access rights item.
*/
public Description[] describeRights()
{
Description[] items = new Description[1];
items[0] = new Description(AttributeType.ATTR_STRING, // string
false, // mandatory
true, // var.size
0, // size
"allow", // text label
"Enables access if this expression evaluates true.");
return items;
}
/**
* Instantiates a plugin's class that implements the <code>Rights</code> interface, using
* the array of objects representing a set of access rights fields.
*
* @param rights
* The objects needed to create an access rights instance.
*
* @return The newly created rights instance.
*/
public Rights getRightsInstance(Object[] rights)
{
return new StringConditionRights((String)rights[0]);
}
/**
* Checks whether a given string is a valid resource name for this resource type. This
* method only checks to ensure the resource is not <code>null</code> and it is a non-
* empty string. Override this to add conditions.
*
* @param resource
* A string naming a resource.
*
* @return <code>true</code> if the name is syntactically correct.
*/
public boolean isInstanceNameValid(String resource)
{
if (resource == null || resource.length() == 0)
return false;
return true;
}
/**
* Checks whether a given array of objects representing a set of access rights fields is
* acceptable.
*
* @param rights
* An array of objects of types representing items in a rights instance.
*
* @return <code>true</code> if the array is acceptable to create a rights instance.
*/
public boolean isRightsSetValid(Object[] rights)
{
if (rights.length != 1)
return false;
if (!rights[0].getClass().isInstance(""))
return false;
return true;
}
/**
* Implements generalized access rights check worker.
*
* @param instance
* name of the particular instance of the abstract resource about
* to be accessed
*
* @return <code>true</code> if access is allowed.
*/
public boolean isAllowed(String instance)
{
Boolean cached = null;
boolean decision = false;
// check to see if there is a cached decision
cached = sm.getCachedDecision(resourceIndex, instance, 0);
if (cached != null)
{
return cached.booleanValue();
}
// initiate the ACL search
int handle = sm.openRightsSearch(resourceIndex, instance, 0);
boolean isFinerLoggable = LOG.isLoggable(Level.FINER);
if (isFinerLoggable)
{
LOG.finer("Search open: resId " + resourceIndex + ", instance " +
instance + ", handle " + handle);
}
// rights check loop
StringConditionRights rights = (StringConditionRights) sm.getNextRights(handle);
while (rights != null)
{
if (isFinerLoggable)
{
LOG.finer("Search next: handle " + handle + ", rights " + rights);
}
decision = checkSingle(rights);
if (decision)
break;
rights = (StringConditionRights) sm.getNextRights(handle);
}
if (isFinerLoggable)
{
LOG.finer("Search done: handle " + handle + ", decision " +
decision + ", cache false");
}
// close the ACL search
sm.closeRightsSearch(handle, decision, false);
return decision;
}
/**
* Implements a worker that performs access rights check on a single
* instance of the StringConditionRights object.
*
* @param rights
* The instance of StringConditionRights to check, must not be
* <code>null</code>.
*
* @return <code>true</code> if access is allowed.
*/
private boolean checkSingle(StringConditionRights rights)
{
Object obj = sm.evaluate(resourceIndex, rights, rights.getCondition());
if (obj == null || !Boolean.class.isInstance(obj))
return false;
Boolean result = (Boolean) obj;
return result.booleanValue();
}
}