UserAccount.java
/*
** Module : UserAccount.java
** Abstract : represents a user security account
**
** Copyright (c) 2005-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- --JPRM-- --------------------------Description--------------------------------
** 001 NVS 20050307 @20195 Created. User account extends Account and
** represents personal P2J accounts.
** 002 NVS 20050311 @20286 Constructor now accepts Integer which can be
** null.
** 003 NVS 20050311 @20297 Methods scope changed to package private.
** 004 NVS 20060414 @25561 Added date and time fields and the
** setPassword() method which sets the new
** password and the date and time of the last
** password change. Changed constructor to take
** date and time parameters as well.
** 005 GES 20061003 @30111 Changed auth mode constant processing and
** cleaned up code formatting.
** 006 GES 20081104 @40343 Moved common code into the base class.
** 007 NVS 20090603 @42592 Provide enabled account status info for super().
** 008 NVS 20090604 @42593 Added password protected flag.
** 009 SVL 20090818 @43689 Fixed setPasswordAged().
** 010 SVL 20100916 Added authPlugin and modeInherited fields.
** 011 CA 20130529 Added appserver support.
** 012 CA 20140206 Back out H011: appserver agents can be started only from P2J
** processes.
** 013 CA 20220405 Added authentication and authorization for web requests. When this is enabled,
** the target API call will be executed under the authenticated FWD context, and not
** the agent's context.
** 014 GBB 20230825 OS user field added.
*/
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
**
** Additional terms under GNU Affero GPL version 3 section 7:
**
** Under Section 7 of the GNU Affero GPL version 3, the following additional
** terms apply to the works covered under the License. These additional terms
** are non-permissive additional terms allowed under Section 7 of the GNU
** Affero GPL version 3 and may not be removed by you.
**
** 0. Attribution Requirement.
**
** You must preserve all legal notices or author attributions in the covered
** work or Appropriate Legal Notices displayed by works containing the covered
** work. You may not remove from the covered work any author or developer
** credit already included within the covered work.
**
** 1. No License To Use Trademarks.
**
** This license does not grant any license or rights to use the trademarks
** Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
** of Golden Code Development Corporation. You are not authorized to use the
** name Golden Code, FWD, or the names of any author or contributor, for
** publicity purposes without written authorization.
**
** 2. No Misrepresentation of Affiliation.
**
** You may not represent yourself as Golden Code Development Corporation or FWD.
**
** You may not represent yourself for publicity purposes as associated with
** Golden Code Development Corporation, FWD, or any author or contributor to
** the covered work, without written authorization.
**
** 3. No Misrepresentation of Source or Origin.
**
** You may not represent the covered work as solely your work. All modified
** versions of the covered work must be marked in a reasonable way to make it
** clear that the modified work is not originating from Golden Code Development
** Corporation or FWD. All modified versions must contain the notices of
** attribution required in this license.
*/
package com.goldencode.p2j.security;
import com.goldencode.p2j.directory.*;
/**
* Represents a specific user security account.
*/
class UserAccount
extends Account
implements SecurityConstants
{
/** Indices of group accounts where this user belongs. */
private int[] groups = null;
/**
* Password protected account flag.
* <p>
* If set to <code>true</code>, password protection is in effect for this
* account. The password field is expected to be present. If no password
* is given to the constructor, all binary zeros are used as the password
* hash, making this account effectively disabled.
* <p>
* If set to <code>false</code>, this account is not protected. The contents
* of the password hash field does not matter and no check will be done.
*/
private boolean protect = true;
/** Hashed password for this account. */
private byte[] password = null;
/** Date password was last changed. */
private DateValue date = null;
/** Time password was last changed. */
private TimeValue time = null;
/** Password needs change flag. */
private boolean aged = false;
/** Authorization mode override for this account. */
private int mode = AUTH_MODE_NONE;
/** Custom authentication plugin class override for this account. */
private String authPlugin = null;
/** Operating system username associated with the fwd user. */
private String osUser = null;
/**
* Identifies whether this account keeps the auth mode and plugin settings
* inherited from a parent group or default server settings.
*/
private boolean modeInherited = false;
/**
* When not null, it represents the token to be used when authenticating web requests. User accounts which
* have this set can't login using the password, regardless if one is configured.
*/
private String webServiceToken = null;
/**
* Constructor.
*
* @param subjectId
* Subject ID also known as account name.
* @param enabled
* <code>true</code> if this account is enabled
* @param person
* Person's name, may be <code>null</code>.
* @param alias
* Truststore alias associated with the user's certificate, may be <code>null</code>.
* @param groups
* Indices of group accounts this where this account belongs, may be <code>null</code>.
* @param protect
* <code>true</code> if this account is password protected
* @param password
* Hashed password data, may be <code>null</code>.
* @param date
* The date the password was last changed.
* @param time
* The time the password was last changed.
* @param mode
* Authentication mode override, may be <code>null</code>. Must be one of the valid
* <code>AUTH_MODE_*</code> constants in {@link SecurityConstants}.
* @param authPlugin
* Custom authentication plugin class override for this account.
* @param osUser
* Operating system username associated with the fwd user.
* @param modeInherited
* <code>true</code> if this account keeps the auth mode and plugin settings
* inherited from a parent group or default server settings.
* @param webServiceToken
* When not null, it represents the token to be used when authenticating web requests. User
* accounts which have this set can't login using the password, regardless if one is configured.
*/
UserAccount(String subjectId,
boolean enabled,
String person,
String alias,
int[] groups,
boolean protect,
byte[] password,
DateValue date,
TimeValue time,
Integer mode,
String authPlugin,
String osUser,
boolean modeInherited,
String webServiceToken)
{
super(subjectId, enabled, person, alias);
this.groups = groups;
this.protect = protect;
this.password = password;
this.date = date;
this.time = time;
this.modeInherited = modeInherited;
this.authPlugin = authPlugin;
this.osUser = osUser;
this.webServiceToken = webServiceToken;
int modeVal = (mode != null) ? mode.intValue() : AUTH_MODE_NONE;
if (modeVal < AUTH_MODE_LOWEST || modeVal > AUTH_MODE_HIGHEST)
{
modeVal = AUTH_MODE_NONE;
}
this.mode = modeVal;
if (protect && password == null)
{
this.password = new byte[] {0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
0, 0, 0, 0, 0, 0, 0, 0, 0, 0};
}
}
/**
* Gets the account type of this account.
*
* @return Always <code>ACC_USER</code>.
*/
int getAccountType()
{
return ACC_USER;
}
/**
* Gets the password protected status of this account.
*
* @return <code>true</code> if the account is password protected
*/
boolean isProtected()
{
return protect;
}
/**
* Gets the account owner's name.
*
* @return Account owner name.
*/
String getPerson()
{
return getDescription();
}
/**
* Gets the groups to which this account belongs.
*
* @return The list of group indices.
*/
int[] getGroups()
{
return groups;
}
/**
* Gets the hashed password for this acoount.
*
* @return Hashed password data.
*/
byte[] getPassword()
{
return password;
}
/**
* Sets a new hashed password for this acoount.
*
* @param password
* The hashed password data.
* @param date
* The date the password was last changed.
* @param time
* The time the password was last changed.
*/
void setPassword(byte[] password, DateValue date, TimeValue time)
{
this.password = password;
this.date = date;
this.time = time;
aged = false;
}
/**
* Gets authorization mode override set forth for this account.
*
* @return Authorization mode override.
*/
int getAuthMode()
{
return mode;
}
/**
* Gets the operating system username associated with the fwd user.
*
* @return Operating system username.
*/
public String getOsUser()
{
return osUser;
}
/**
* Gets the last password change date.
*
* @return Last password change date.
*/
DateValue getPasswordDate()
{
return date;
}
/**
* Gets the last password change time.
*
* @return Last password change time.
*/
TimeValue getPasswordTime()
{
return time;
}
/**
* Gets password age status.
*
* @return <code>true</code> if this password is too old and needs
* changing.
*/
boolean isPasswordAged()
{
return aged;
}
/**
* Sets password age status.
*
* @param aged
* <code>true</code> if this password is too old and needs
* changing.
*/
void setPasswordAged(boolean aged)
{
this.aged = aged;
}
/**
* Get the {@link #webServiceToken}.
*
* @return See above.
*/
String getWebServiceToken()
{
return webServiceToken;
}
/**
* Gets the custom authentication plugin class for this account.
*
* @return See above.
*/
public String getAuthPlugin()
{
return authPlugin;
}
/**
* Identifies whether this account keeps the auth mode and plugin inherited
* from a parent group or default server settings.
*
* @return <code>true</code> if this account keeps the auth mode and
* plugin inherited from a parent group or default server
* settings. <code>false</code> if these are user-specific values.
*/
public boolean isModeInherited()
{
return modeInherited;
}
}