StringConditionResource.java

/*
** Module   : StringConditionResource.java
** Abstract : plugin to manage access to any resource with a simple string expression
**
** Copyright (c) 2014-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- ----------------------------Description-----------------------------------
** 001 GES 20160222 Created the first version, using nearly the complete implementation from
**                  EntryPointResource.
** 002 HC  20170612 Changes related to implementation of new GWT-based Admin client.
** 003 GBB 20230512 Logging methods replaced by CentralLogger/ConversionStatus.
*/ 
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
** 
** Additional terms under GNU Affero GPL version 3 section 7:
** 
**   Under Section 7 of the GNU Affero GPL version 3, the following additional
**   terms apply to the works covered under the License.  These additional terms
**   are non-permissive additional terms allowed under Section 7 of the GNU
**   Affero GPL version 3 and may not be removed by you.
** 
**   0. Attribution Requirement.
** 
**     You must preserve all legal notices or author attributions in the covered
**     work or Appropriate Legal Notices displayed by works containing the covered
**     work.  You may not remove from the covered work any author or developer
**     credit already included within the covered work.
** 
**   1. No License To Use Trademarks.
** 
**     This license does not grant any license or rights to use the trademarks
**     Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
**     of Golden Code Development Corporation. You are not authorized to use the
**     name Golden Code, FWD, or the names of any author or contributor, for
**     publicity purposes without written authorization.
** 
**   2. No Misrepresentation of Affiliation.
** 
**     You may not represent yourself as Golden Code Development Corporation or FWD.
** 
**     You may not represent yourself for publicity purposes as associated with
**     Golden Code Development Corporation, FWD, or any author or contributor to
**     the covered work, without written authorization.
** 
**   3. No Misrepresentation of Source or Origin.
** 
**     You may not represent the covered work as solely your work.  All modified
**     versions of the covered work must be marked in a reasonable way to make it
**     clear that the modified work is not originating from Golden Code Development
**     Corporation or FWD.  All modified versions must contain the notices of
**     attribution required in this license.
*/

package com.goldencode.p2j.security;

import com.goldencode.p2j.directory.*;
import com.goldencode.expr.*;
import com.goldencode.p2j.util.logging.*;

import java.util.logging.*;

/**
 * Implements a resource that is protected by a single string that describes the condition
 * for which to allow access.  That condition is a matching expression (exact match or
 * regex).  This is meant to be a parent class where there is almost no code in the child.
 */
public class StringConditionResource
extends AbstractResource
{
   /** Logger. */
   private static final CentralLogger LOG = CentralLogger.get(StringConditionResource.class);
   
   /**
    * Default constructor. 
    */
   public StringConditionResource()
   {
   }

   /**
    * Returns the plugin resource type name as a string.
    *
    * @return   The plugin resource type name.
    */
   public String getTypeName()
   {
      return "stringcondition";
   }

   /**
    * Returns an array of descriptions, one object per the plugin's access rights item.
    *
    * @return   An array of <code>Description</code> elements, one for each access rights item.
    */
   public Description[] describeRights()
   {
      Description[] items = new Description[1];
      
      items[0] = new Description(AttributeType.ATTR_STRING,    // string
                                 false,                        // mandatory
                                 true,                         // var.size  
                                 0,                            // size
                                 "allow",                      // text label
                                 "Enables access if this expression evaluates true.");

      return items;
   }

   /**
    * Instantiates a plugin's class that implements the <code>Rights</code> interface, using
    * the array of objects representing a set of access rights fields.
    *
    * @param    rights
    *           The objects needed to create an access rights instance.
    *           
    * @return   The newly created rights instance.
    */
   public Rights getRightsInstance(Object[] rights)
   {
      return new StringConditionRights((String)rights[0]);
   }

   /**
    * Checks whether a given string is a valid resource name for this resource type. This
    * method only checks to ensure the resource is not <code>null</code> and it is a non-
    * empty string.  Override this to add conditions.
    *
    * @param    resource
    *           A string naming a resource.
    *
    * @return   <code>true</code> if the name is syntactically correct. 
    */
   public boolean isInstanceNameValid(String resource)
   {
      if (resource == null || resource.length() == 0)
         return false;

      return true;
   }

   /**
    * Checks whether a given array of objects representing a set of access rights fields is
    * acceptable.
    *
    * @param    rights
    *           An array of objects of types representing items in a rights instance.
    *           
    * @return   <code>true</code> if the array is acceptable to create a rights instance.
    */
   public boolean isRightsSetValid(Object[] rights)
   {
      if (rights.length != 1)
         return false;

      if (!rights[0].getClass().isInstance(""))
         return false;

      return true;
   }

   /**
    * Implements generalized access rights check worker.
    *
    * @param    instance
    *           name of the particular instance of the abstract resource about 
    *           to be accessed
    *           
    * @return   <code>true</code> if access is allowed.
    */
   public boolean isAllowed(String instance)
   {
      Boolean cached   = null;
      boolean decision = false;

      // check to see if there is a cached decision
      cached = sm.getCachedDecision(resourceIndex, instance, 0);
      
      if (cached != null)
      {
         return cached.booleanValue();
      }

      // initiate the ACL search
      int handle = sm.openRightsSearch(resourceIndex, instance, 0);

      boolean isFinerLoggable = LOG.isLoggable(Level.FINER);
      if (isFinerLoggable)
      {
         LOG.finer("Search open: resId " + resourceIndex + ", instance " +
                      instance + ", handle " + handle);

      }
      
      // rights check loop
      StringConditionRights rights = (StringConditionRights) sm.getNextRights(handle);
      
      while (rights != null)
      {
         if (isFinerLoggable)
         {
            LOG.finer("Search next: handle " + handle + ", rights " + rights);
         }
         
         decision = checkSingle(rights);
         
         if (decision)
            break;
         
         rights = (StringConditionRights) sm.getNextRights(handle);
      }

      if (isFinerLoggable)
      {
         LOG.finer("Search done: handle " + handle + ", decision " +
                      decision + ", cache false");
      }
      
      // close the ACL search
      sm.closeRightsSearch(handle, decision, false);

      return decision;
   }

   /**
    * Implements a worker that performs access rights check on a single
    * instance of the StringConditionRights object.
    *
    * @param    rights
    *           The instance of StringConditionRights to check, must not be
    *           <code>null</code>. 
    *
    * @return   <code>true</code> if access is allowed.
    */
   private boolean checkSingle(StringConditionRights rights)
   {
      Object obj = sm.evaluate(resourceIndex, rights, rights.getCondition());
      
      if (obj == null || !Boolean.class.isInstance(obj))
         return false;

      Boolean result = (Boolean) obj;
      
      return result.booleanValue();
   }
}