Search in sources :

Example 41 with Resource

use of javax.annotation.Resource in project alien4cloud by alien4cloud.

the class ResourcePermissionEventsListener method deleteGroupPermissionOn.

private void deleteGroupPermissionOn(String groupId, Class<?>... resourceClasses) throws IOException, ClassNotFoundException {
    FilterBuilder resourceFilter = FilterBuilders.nestedFilter("groupPermissions", FilterBuilders.termFilter("groupPermissions.key", groupId));
    deletePermissions(resourceFilter, groupId, ((resource, subjectId) -> resourcePermissionService.revokePermission(resource, Subject.GROUP, subjectId)), resourceClasses);
}
Also used : BeforeApplicationDeleted(org.alien4cloud.alm.events.BeforeApplicationDeleted) Arrays(java.util.Arrays) TypeScanner(alien4cloud.utils.TypeScanner) GetMultipleDataResult(alien4cloud.dao.model.GetMultipleDataResult) FilterBuilder(org.elasticsearch.index.query.FilterBuilder) Subject(alien4cloud.security.Subject) AbstractSecurityEnabledResource(alien4cloud.security.AbstractSecurityEnabledResource) GroupDeletedEvent(alien4cloud.security.event.GroupDeletedEvent) FilterBuilders(org.elasticsearch.index.query.FilterBuilders) Resource(javax.annotation.Resource) EventListener(org.springframework.context.event.EventListener) Set(java.util.Set) IGenericSearchDAO(alien4cloud.dao.IGenericSearchDAO) ArrayUtils(org.apache.commons.lang3.ArrayUtils) IOException(java.io.IOException) Collectors(java.util.stream.Collectors) Sets(com.google.common.collect.Sets) BeforeApplicationEnvironmentDeleted(org.alien4cloud.alm.events.BeforeApplicationEnvironmentDeleted) Component(org.springframework.stereotype.Component) BeforeApplicationEnvironmentTypeDeleted(org.alien4cloud.alm.events.BeforeApplicationEnvironmentTypeDeleted) UserDeletedEvent(alien4cloud.security.event.UserDeletedEvent) LocationResourceTemplate(alien4cloud.model.orchestrators.locations.LocationResourceTemplate) AfterPermissionRevokedEvent(org.alien4cloud.alm.events.AfterPermissionRevokedEvent) FilterBuilder(org.elasticsearch.index.query.FilterBuilder)

Example 42 with Resource

use of javax.annotation.Resource in project alien4cloud by alien4cloud.

the class ResourcePermissionEventsListener method deleteApplicationPermissionOn.

private void deleteApplicationPermissionOn(String applicationId, Class<?>... resourceClasses) throws IOException, ClassNotFoundException {
    FilterBuilder resourceFilter = FilterBuilders.nestedFilter("applicationPermissions", FilterBuilders.termFilter("applicationPermissions.key", applicationId));
    deletePermissions(resourceFilter, applicationId, ((resource, subjectId) -> resourcePermissionService.revokePermission(resource, Subject.APPLICATION, subjectId)), resourceClasses);
}
Also used : BeforeApplicationDeleted(org.alien4cloud.alm.events.BeforeApplicationDeleted) Arrays(java.util.Arrays) TypeScanner(alien4cloud.utils.TypeScanner) GetMultipleDataResult(alien4cloud.dao.model.GetMultipleDataResult) FilterBuilder(org.elasticsearch.index.query.FilterBuilder) Subject(alien4cloud.security.Subject) AbstractSecurityEnabledResource(alien4cloud.security.AbstractSecurityEnabledResource) GroupDeletedEvent(alien4cloud.security.event.GroupDeletedEvent) FilterBuilders(org.elasticsearch.index.query.FilterBuilders) Resource(javax.annotation.Resource) EventListener(org.springframework.context.event.EventListener) Set(java.util.Set) IGenericSearchDAO(alien4cloud.dao.IGenericSearchDAO) ArrayUtils(org.apache.commons.lang3.ArrayUtils) IOException(java.io.IOException) Collectors(java.util.stream.Collectors) Sets(com.google.common.collect.Sets) BeforeApplicationEnvironmentDeleted(org.alien4cloud.alm.events.BeforeApplicationEnvironmentDeleted) Component(org.springframework.stereotype.Component) BeforeApplicationEnvironmentTypeDeleted(org.alien4cloud.alm.events.BeforeApplicationEnvironmentTypeDeleted) UserDeletedEvent(alien4cloud.security.event.UserDeletedEvent) LocationResourceTemplate(alien4cloud.model.orchestrators.locations.LocationResourceTemplate) AfterPermissionRevokedEvent(org.alien4cloud.alm.events.AfterPermissionRevokedEvent) FilterBuilder(org.elasticsearch.index.query.FilterBuilder)

Example 43 with Resource

use of javax.annotation.Resource in project alien4cloud by alien4cloud.

the class ResourcePermissionEventsListener method deleteEnvironmentTypePermissionOn.

private void deleteEnvironmentTypePermissionOn(String environmentId, Class<?>... resourceClasses) throws IOException, ClassNotFoundException {
    FilterBuilder resourceFilter = FilterBuilders.nestedFilter("environmentTypePermissions", FilterBuilders.termFilter("environmentTypePermissions.key", environmentId));
    deletePermissions(resourceFilter, environmentId, ((resource, subjectId) -> resourcePermissionService.revokePermission(resource, Subject.ENVIRONMENT_TYPE, subjectId)), resourceClasses);
}
Also used : BeforeApplicationDeleted(org.alien4cloud.alm.events.BeforeApplicationDeleted) Arrays(java.util.Arrays) TypeScanner(alien4cloud.utils.TypeScanner) GetMultipleDataResult(alien4cloud.dao.model.GetMultipleDataResult) FilterBuilder(org.elasticsearch.index.query.FilterBuilder) Subject(alien4cloud.security.Subject) AbstractSecurityEnabledResource(alien4cloud.security.AbstractSecurityEnabledResource) GroupDeletedEvent(alien4cloud.security.event.GroupDeletedEvent) FilterBuilders(org.elasticsearch.index.query.FilterBuilders) Resource(javax.annotation.Resource) EventListener(org.springframework.context.event.EventListener) Set(java.util.Set) IGenericSearchDAO(alien4cloud.dao.IGenericSearchDAO) ArrayUtils(org.apache.commons.lang3.ArrayUtils) IOException(java.io.IOException) Collectors(java.util.stream.Collectors) Sets(com.google.common.collect.Sets) BeforeApplicationEnvironmentDeleted(org.alien4cloud.alm.events.BeforeApplicationEnvironmentDeleted) Component(org.springframework.stereotype.Component) BeforeApplicationEnvironmentTypeDeleted(org.alien4cloud.alm.events.BeforeApplicationEnvironmentTypeDeleted) UserDeletedEvent(alien4cloud.security.event.UserDeletedEvent) LocationResourceTemplate(alien4cloud.model.orchestrators.locations.LocationResourceTemplate) AfterPermissionRevokedEvent(org.alien4cloud.alm.events.AfterPermissionRevokedEvent) FilterBuilder(org.elasticsearch.index.query.FilterBuilder)

Example 44 with Resource

use of javax.annotation.Resource in project alien4cloud by alien4cloud.

the class ResourcePermissionService method grantAuthorizedEnvironmentsAndEnvTypesPerApplication.

public void grantAuthorizedEnvironmentsAndEnvTypesPerApplication(AbstractSecurityEnabledResource resource, String[] applicationsToAdd, String[] environmentsToAdd, String[] environmentTypesToAdd) {
    List<String> envIds = Lists.newArrayList();
    IResourceSaver noSave = null;
    if (ArrayUtils.isNotEmpty(applicationsToAdd)) {
        grantPermission(resource, noSave, Subject.APPLICATION, applicationsToAdd);
        // when an app is added, all eventual existing env authorizations are removed
        for (String applicationToAddId : applicationsToAdd) {
            ApplicationEnvironment[] aes = applicationEnvironmentService.getByApplicationId(applicationToAddId);
            for (ApplicationEnvironment ae : aes) {
                envIds.add(ae.getId());
            }
        }
        if (!envIds.isEmpty()) {
            revokePermission(resource, noSave, Subject.ENVIRONMENT, envIds.toArray(new String[envIds.size()]));
        }
        // remove all all eventual existing env type authorizations
        Set<String> envTypes = Sets.newHashSet();
        for (String applicationToAddId : applicationsToAdd) {
            for (EnvironmentType envType : EnvironmentType.values()) {
                envTypes.add(applicationToAddId + ":" + envType.toString());
            }
        }
        if (!envTypes.isEmpty()) {
            revokePermission(resource, noSave, Subject.ENVIRONMENT_TYPE, envTypes.toArray(new String[envTypes.size()]));
        }
    }
    if (ArrayUtils.isNotEmpty(environmentsToAdd)) {
        List<String> envToAddSet = Arrays.stream(environmentsToAdd).filter(env -> !envIds.contains(env)).collect(Collectors.toList());
        grantPermission(resource, noSave, Subject.ENVIRONMENT, envToAddSet.toArray(new String[envToAddSet.size()]));
    }
    if (ArrayUtils.isNotEmpty(environmentTypesToAdd)) {
        grantPermission(resource, noSave, Subject.ENVIRONMENT_TYPE, environmentTypesToAdd);
    }
    alienDAO.save(resource);
}
Also used : BeforePermissionRevokedEvent(org.alien4cloud.alm.events.BeforePermissionRevokedEvent) Lists(org.elasticsearch.common.collect.Lists) Arrays(java.util.Arrays) ApplicationEnvironmentService(alien4cloud.application.ApplicationEnvironmentService) Subject(alien4cloud.security.Subject) AbstractSecurityEnabledResource(alien4cloud.security.AbstractSecurityEnabledResource) ArrayUtils(org.apache.commons.lang3.ArrayUtils) User(alien4cloud.security.model.User) Inject(javax.inject.Inject) Service(org.springframework.stereotype.Service) Map(java.util.Map) ApplicationEventPublisher(org.springframework.context.ApplicationEventPublisher) MapUtils(org.apache.commons.collections4.MapUtils) Permission(alien4cloud.security.Permission) ApplicationEnvironment(alien4cloud.model.application.ApplicationEnvironment) Resource(javax.annotation.Resource) Set(java.util.Set) IGenericSearchDAO(alien4cloud.dao.IGenericSearchDAO) Collectors(java.util.stream.Collectors) Sets(com.google.common.collect.Sets) IAlienGroupDao(alien4cloud.security.groups.IAlienGroupDao) IAlienUserDao(alien4cloud.security.users.IAlienUserDao) List(java.util.List) ISecurityEnabledResource(alien4cloud.security.ISecurityEnabledResource) Group(alien4cloud.security.model.Group) EnvironmentType(alien4cloud.model.application.EnvironmentType) AllArgsConstructor(lombok.AllArgsConstructor) Comparator(java.util.Comparator) AfterPermissionRevokedEvent(org.alien4cloud.alm.events.AfterPermissionRevokedEvent) NoArgsConstructor(lombok.NoArgsConstructor) EnvironmentType(alien4cloud.model.application.EnvironmentType) ApplicationEnvironment(alien4cloud.model.application.ApplicationEnvironment)

Example 45 with Resource

use of javax.annotation.Resource in project alien4cloud by alien4cloud.

the class AbstractLocationResourcesBatchSecurityController method processGrantForSubjectType.

private void processGrantForSubjectType(Subject subjectType, String orchestratorId, String locationId, String[] resources, String[] subjects) {
    if (ArrayUtils.isEmpty(resources)) {
        return;
    }
    Location location = locationService.getLocation(orchestratorId, locationId);
    locationSecurityService.grantAuthorizationOnLocationIfNecessary(location, subjectType, subjects);
    Arrays.stream(resources).forEach(resourceId -> {
        AbstractLocationResourceTemplate resourceTemplate = locationResourceService.getOrFail(resourceId);
        // prefer using locationResourceService.saveResource so that the location update date is update.
        // This will then trigger a deployment topology update
        resourcePermissionService.grantPermission(resourceTemplate, (resource -> locationResourceService.saveResource(location, (AbstractLocationResourceTemplate) resource)), subjectType, subjects);
    });
}
Also used : PathVariable(org.springframework.web.bind.annotation.PathVariable) Arrays(java.util.Arrays) ApplicationEnvironmentService(alien4cloud.application.ApplicationEnvironmentService) PreAuthorize(org.springframework.security.access.prepost.PreAuthorize) Subject(alien4cloud.security.Subject) LocationService(alien4cloud.orchestrators.locations.services.LocationService) ResourcePermissionService(alien4cloud.authorization.ResourcePermissionService) RequestMapping(org.springframework.web.bind.annotation.RequestMapping) ArrayUtils(org.apache.commons.lang3.ArrayUtils) LocationSecurityService(alien4cloud.orchestrators.locations.services.LocationSecurityService) Location(alien4cloud.model.orchestrators.locations.Location) RequestBody(org.springframework.web.bind.annotation.RequestBody) ApiOperation(io.swagger.annotations.ApiOperation) Audit(alien4cloud.audit.annotation.Audit) RestResponseBuilder(alien4cloud.rest.model.RestResponseBuilder) RestResponse(alien4cloud.rest.model.RestResponse) ILocationResourceService(alien4cloud.orchestrators.locations.services.ILocationResourceService) ApplicationEnvironment(alien4cloud.model.application.ApplicationEnvironment) MediaType(org.springframework.http.MediaType) Resource(javax.annotation.Resource) Set(java.util.Set) RequestMethod(org.springframework.web.bind.annotation.RequestMethod) Collectors(java.util.stream.Collectors) Sets(com.google.common.collect.Sets) SubjectsAuthorizationRequest(alien4cloud.rest.orchestrator.model.SubjectsAuthorizationRequest) List(java.util.List) AbstractLocationResourceTemplate(alien4cloud.model.orchestrators.locations.AbstractLocationResourceTemplate) ApplicationEnvironmentAuthorizationUpdateRequest(alien4cloud.rest.orchestrator.model.ApplicationEnvironmentAuthorizationUpdateRequest) AbstractLocationResourceTemplate(alien4cloud.model.orchestrators.locations.AbstractLocationResourceTemplate) Location(alien4cloud.model.orchestrators.locations.Location)

Aggregations

Resource (javax.annotation.Resource)56 Collectors (java.util.stream.Collectors)22 Set (java.util.Set)20 List (java.util.List)18 Subject (alien4cloud.security.Subject)17 Sets (com.google.common.collect.Sets)17 Arrays (java.util.Arrays)17 ArrayUtils (org.apache.commons.lang3.ArrayUtils)15 IGenericSearchDAO (alien4cloud.dao.IGenericSearchDAO)14 ApplicationEnvironmentService (alien4cloud.application.ApplicationEnvironmentService)12 ApplicationEnvironment (alien4cloud.model.application.ApplicationEnvironment)12 Audit (alien4cloud.audit.annotation.Audit)11 ResourcePermissionService (alien4cloud.authorization.ResourcePermissionService)11 RestResponse (alien4cloud.rest.model.RestResponse)11 RestResponseBuilder (alien4cloud.rest.model.RestResponseBuilder)11 ApplicationEnvironmentAuthorizationUpdateRequest (alien4cloud.rest.orchestrator.model.ApplicationEnvironmentAuthorizationUpdateRequest)11 ApiOperation (io.swagger.annotations.ApiOperation)11 IOException (java.io.IOException)11 MediaType (org.springframework.http.MediaType)11 PreAuthorize (org.springframework.security.access.prepost.PreAuthorize)11