SecurityManagerSecurityOps.java

/*
** Module   : SecurityManagerSecurityOps.java
** Abstract : Progress 4GL compatible security interface that does not use the _User metatables.
**
** Copyright (c) 2013-2022, Golden Code Development Corporation.
**
** -#- -I- --Date-- ----------------------------------Description---------------------------------
** 001 OM  20130913 First version, implementing the basic four methods: get/set with and without
**                  the logical database name.
** 002 CA  20181128 Allow assigning a USERID for a specified database without authentication.
**                  Used by cases when SET-DB-CLIENT provides a SSO CLIENT-PRINCIPAL.
** 003 IAS 20220713 Added 'lock' argument to the setUserIdDirect method
*/
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
** 
** Additional terms under GNU Affero GPL version 3 section 7:
** 
**   Under Section 7 of the GNU Affero GPL version 3, the following additional
**   terms apply to the works covered under the License.  These additional terms
**   are non-permissive additional terms allowed under Section 7 of the GNU
**   Affero GPL version 3 and may not be removed by you.
** 
**   0. Attribution Requirement.
** 
**     You must preserve all legal notices or author attributions in the covered
**     work or Appropriate Legal Notices displayed by works containing the covered
**     work.  You may not remove from the covered work any author or developer
**     credit already included within the covered work.
** 
**   1. No License To Use Trademarks.
** 
**     This license does not grant any license or rights to use the trademarks
**     Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
**     of Golden Code Development Corporation. You are not authorized to use the
**     name Golden Code, FWD, or the names of any author or contributor, for
**     publicity purposes without written authorization.
** 
**   2. No Misrepresentation of Affiliation.
** 
**     You may not represent yourself as Golden Code Development Corporation or FWD.
** 
**     You may not represent yourself for publicity purposes as associated with
**     Golden Code Development Corporation, FWD, or any author or contributor to
**     the covered work, without written authorization.
** 
**   3. No Misrepresentation of Source or Origin.
** 
**     You may not represent the covered work as solely your work.  All modified
**     versions of the covered work must be marked in a reasonable way to make it
**     clear that the modified work is not originating from Golden Code Development
**     Corporation or FWD.  All modified versions must contain the notices of
**     attribution required in this license.
*/

package com.goldencode.p2j.util;

import com.goldencode.p2j.security.SecurityManager;

/**
 * Progress 4GL compatible security interface that does not use the _User meta-table.
 * This is the first P2J approach that uses the SecurityManager for enforcing security policy.
 * <p>
 * This is the default handler for SecurityOps for user related methods.
 */
public class SecurityManagerSecurityOps
implements CustomSecurityOps
{
   /**
    * Returns the userid associated with the current user from the SecurityManager instance.
    *
    * @return   The current user context's userid or the empty string in the case of any problem.
    */
   public String getUserId()
   {
      SecurityManager sm = SecurityManager.getInstance();
      return (sm != null) ? sm.getUserId() : SecurityOps.BLANK_USER;
   }

   /**
    * Returns the userid associated with the current user of the given logical database.
    *
    * @param    dbname
    *           Logical database name.
    *
    * @return   Always return empty string as the SecurityManager is not database dependent.
    */
   public String getUserIdFromDB(String dbname)
   {
      return SecurityOps.BLANK_USER;
   }

   /**
    * Authenticates the user for specified DB connection. Checks if the user login account match
    * the corresponding record of the _User table of the database. If there are multiple database
    * connections or none is connected, an error is issued.
    *
    * @param    userid
    *           The name of the user to set as UserID.
    * @param    password
    *           The users password.
    *
    * @return   Always return <code>true</code> as the SecurityManager is not database dependent.
    */
   public boolean setUserId(String userid, String password)
   {
      return true;
   }

   /**
    * Sets the specified user ID directly, without authentication, for the given database.
    * <p>
    * This implementation is a no-op.
    * 
    * @param    userid
    *           The name of the user to set as UserID.
    * @param    dbname
    *           Logical database name.
    * @param    lock
    *           Flag  indicating that the database should be locked
    */
   @Override
   public void setUserIdDirect(String userid, String dbname, boolean lock)
   {
      // no-op
   }

   /**
    * Authenticates the user for specified DB connection. Checks if the user login account match
    * the corresponding record of the _User table of the database.  If the specified database
    * is not connected, an error is issued.
    *
    * @param    userid
    *           The name of the user to set as UserID.
    * @param    password
    *           The users password.
    * @param    dbname
    *           Logical database name.
    *
    * @return   Always return <code>true</code> as the SecurityManager is not database dependent.
    */
   public boolean setUserId(String userid, String password, String dbname)
   {
      return true;
   }

   /**
    * Check the access level for a database. This will query the _User table and return the value.
    *
    * @param   ldbname
    *          The database to query.
    *
    * @return  The access level to specified database.
    */
   @Override
   public int getAuthLevel(String ldbname)
   {
      return SecurityOps.FREE_ACCESS;
   }

   /**
    * Checks if the currently authenticated user has access to a database. When configured with
    * this SecurityOp, all users have access to all databases.
    *
    * @param   ldbName
    *          The logical name of the database.
    *
    * @return  always <code>true</code>.
    */
   @Override
   public boolean hasAccessToDatabase(String ldbName)
   {
      return true;
   }
}