UserAccount.java

/*
** Module   : UserAccount.java
** Abstract : represents a user security account
**
** Copyright (c) 2005-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- --JPRM-- --------------------------Description--------------------------------
** 001 NVS 20050307   @20195 Created. User account extends Account and 
**                           represents personal P2J accounts.
** 002 NVS 20050311   @20286 Constructor now accepts Integer which can be
**                           null.
** 003 NVS 20050311   @20297 Methods scope changed to package private.
** 004 NVS 20060414   @25561 Added date and time fields and the 
**                           setPassword() method which sets the new
**                           password and the date and time of the last
**                           password change. Changed constructor to take
**                           date and time parameters as well.
** 005 GES 20061003   @30111 Changed auth mode constant processing and
**                           cleaned up code formatting.
** 006 GES 20081104   @40343 Moved common code into the base class.
** 007 NVS 20090603   @42592 Provide enabled account status info for super().
** 008 NVS 20090604   @42593 Added password protected flag.
** 009 SVL 20090818   @43689 Fixed setPasswordAged().
** 010 SVL 20100916          Added authPlugin and modeInherited fields.
** 011 CA  20130529          Added appserver support.
** 012 CA  20140206          Back out H011: appserver agents can be started only from P2J
**                           processes.
** 013 CA  20220405          Added authentication and authorization for web requests.  When this is enabled, 
**                           the target API call will be executed under the authenticated FWD context, and not 
**                           the agent's context.
** 014 GBB 20230825          OS user field added.
*/ 
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
** 
** Additional terms under GNU Affero GPL version 3 section 7:
** 
**   Under Section 7 of the GNU Affero GPL version 3, the following additional
**   terms apply to the works covered under the License.  These additional terms
**   are non-permissive additional terms allowed under Section 7 of the GNU
**   Affero GPL version 3 and may not be removed by you.
** 
**   0. Attribution Requirement.
** 
**     You must preserve all legal notices or author attributions in the covered
**     work or Appropriate Legal Notices displayed by works containing the covered
**     work.  You may not remove from the covered work any author or developer
**     credit already included within the covered work.
** 
**   1. No License To Use Trademarks.
** 
**     This license does not grant any license or rights to use the trademarks
**     Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
**     of Golden Code Development Corporation. You are not authorized to use the
**     name Golden Code, FWD, or the names of any author or contributor, for
**     publicity purposes without written authorization.
** 
**   2. No Misrepresentation of Affiliation.
** 
**     You may not represent yourself as Golden Code Development Corporation or FWD.
** 
**     You may not represent yourself for publicity purposes as associated with
**     Golden Code Development Corporation, FWD, or any author or contributor to
**     the covered work, without written authorization.
** 
**   3. No Misrepresentation of Source or Origin.
** 
**     You may not represent the covered work as solely your work.  All modified
**     versions of the covered work must be marked in a reasonable way to make it
**     clear that the modified work is not originating from Golden Code Development
**     Corporation or FWD.  All modified versions must contain the notices of
**     attribution required in this license.
*/

package com.goldencode.p2j.security;

import com.goldencode.p2j.directory.*;

/**
 * Represents a specific user security account. 
 */
class UserAccount
extends Account
implements SecurityConstants
{
   /** Indices of group accounts where this user belongs. */
   private int[] groups = null;

   /** 
    * Password protected account flag.
    * <p>
    * If set to <code>true</code>, password protection is in effect for this
    * account. The password field is expected to be present. If no password
    * is given to the constructor, all binary zeros are used as the password
    * hash, making this account effectively disabled.
    * <p>
    * If set to <code>false</code>, this account is not protected. The contents
    * of the password hash field does not matter and no check will be done.
    */
   private boolean protect = true;
   
   /** Hashed password for this account. */
   private byte[] password = null;

   /** Date password was last changed. */
   private DateValue date = null;

   /** Time password was last changed. */
   private TimeValue time = null;

   /** Password needs change flag. */
   private boolean aged = false;

   /** Authorization mode override for this account. */
   private int mode = AUTH_MODE_NONE;

   /** Custom authentication plugin class override for this account. */
   private String authPlugin = null;

   /** Operating system username associated with the fwd user. */
   private String osUser = null;

   /**
    * Identifies whether this account keeps the auth mode and plugin settings
    * inherited from a parent group or default server settings. 
    */
   private boolean modeInherited = false;
   
   /**
    * When not null, it represents the token to be used when authenticating web requests. User accounts which 
    * have this set can't login using the password, regardless if one is configured. 
    */ 
   private String webServiceToken = null;

   /**
    * Constructor.
    *
    * @param    subjectId
    *           Subject ID also known as account name.
    * @param    enabled
    *           <code>true</code> if this account is enabled
    * @param    person     
    *           Person's name, may be <code>null</code>.
    * @param    alias
    *           Truststore alias associated with the user's certificate, may be <code>null</code>.
    * @param    groups
    *           Indices of group accounts this where this account belongs, may be <code>null</code>.
    * @param    protect
    *           <code>true</code> if this account is password protected
    * @param    password
    *           Hashed password data, may be <code>null</code>.
    * @param    date
    *           The date the password was last changed.
    * @param    time
    *           The time the password was last changed.
    * @param    mode
    *           Authentication mode override, may be <code>null</code>. Must be one of the valid
    *           <code>AUTH_MODE_*</code> constants in {@link SecurityConstants}.
    * @param    authPlugin
    *           Custom authentication plugin class override for this account.
    * @param    osUser
    *           Operating system username associated with the fwd user.
    * @param    modeInherited
    *           <code>true</code> if this account keeps the auth mode and plugin settings 
    *           inherited from a parent group or default server settings. 
    * @param    webServiceToken
    *           When not null, it represents the token to be used when authenticating web requests. User  
    *           accounts which have this set can't login using the password, regardless if one is configured.
    */
   UserAccount(String    subjectId,
               boolean   enabled,
               String    person,
               String    alias, 
               int[]     groups,
               boolean   protect,
               byte[]    password,
               DateValue date,
               TimeValue time,
               Integer   mode,
               String    authPlugin,
               String    osUser,
               boolean   modeInherited,
               String    webServiceToken)
   {
      super(subjectId, enabled, person, alias);
      this.groups   = groups;
      this.protect  = protect;
      this.password = password;
      this.date     = date;
      this.time     = time;
      this.modeInherited = modeInherited;
      this.authPlugin    = authPlugin;
      this.osUser   = osUser;
      this.webServiceToken = webServiceToken;
      
      int modeVal = (mode != null) ? mode.intValue() : AUTH_MODE_NONE;
      
      if (modeVal < AUTH_MODE_LOWEST || modeVal > AUTH_MODE_HIGHEST) 
      {
         modeVal = AUTH_MODE_NONE;
      }
      
      this.mode = modeVal;
      
      if (protect && password == null)
      {
         this.password = new byte[] {0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
                                     0, 0, 0, 0, 0, 0, 0, 0, 0, 0};
      }
   }

   /**
    * Gets the account type of this account.
    *
    * @return   Always <code>ACC_USER</code>.
    */
   int getAccountType()
   {
      return ACC_USER;
   }

   /**
    * Gets the password protected status of this account.
    *
    * @return   <code>true</code> if the account is password protected
    */
   boolean isProtected()
   {
      return protect;
   }
   
   /**
    * Gets the account owner's name.
    *
    * @return   Account owner name.
    */
   String getPerson()
   {
      return getDescription();
   }

   /**
    * Gets the groups to which this account belongs.
    *
    * @return   The list of group indices.
    */
   int[] getGroups()
   {
      return groups;
   }

   /**
    * Gets the hashed password for this acoount.
    *
    * @return   Hashed password data.
    */
   byte[] getPassword()
   {
      return password;
   }

   /**
    * Sets a new hashed password for this acoount.
    *
    * @param    password
    *           The hashed password data.
    * @param    date
    *           The date the password was last changed.
    * @param    time
    *           The time the password was last changed.
    */
   void setPassword(byte[] password, DateValue date, TimeValue time)
   {
      this.password = password;
      this.date     = date;
      this.time     = time;
      aged = false;
   }

   /**
    * Gets authorization mode override set forth for this account.
    *
    * @return   Authorization mode override.
    */
   int getAuthMode()
   {
      return mode;
   }

   /**
    * Gets the operating system username associated with the fwd user.
    *
    * @return   Operating system username.
    */
   public String getOsUser()
   {
      return osUser;
   }
   
   /**
    * Gets the last password change date.
    *
    * @return   Last password change date.
    */
   DateValue getPasswordDate()
   {
      return date;
   }

   /**
    * Gets the last password change time.
    *
    * @return   Last password change time.
    */
   TimeValue getPasswordTime()
   {
      return time;
   }

   /**
    * Gets password age status.
    *
    * @return   <code>true</code> if this password is too old and needs
    *           changing.
    */
   boolean isPasswordAged()
   {
      return aged;
   }

   /**
    * Sets password age status.
    *
    * @param    aged
    *           <code>true</code> if this password is too old and needs
    *           changing.
    */
   void setPasswordAged(boolean aged)
   {
      this.aged = aged;
   }

   /**
    * Get the {@link #webServiceToken}.
    * 
    * @return   See above.
    */
   String getWebServiceToken()
   {
      return webServiceToken;
   }

   /**
    * Gets the custom authentication plugin class for this account.
    *
    * @return See above.
    */
   public String getAuthPlugin()
   {
      return authPlugin;
   }

   /**
    * Identifies whether this account keeps the auth mode and plugin inherited
    * from a parent group or default server settings.
    *
    * @return  <code>true</code> if this account keeps the auth mode and
    *          plugin inherited from a parent group or default server
    *          settings. <code>false</code> if these are user-specific values. 
    */
   public boolean isModeInherited()
   {
      return modeInherited;
   }
}