Search in sources :

Example 1 with AccessPolicyDTO

use of org.apache.nifi.web.api.dto.AccessPolicyDTO in project nifi by apache.

the class StandardNiFiServiceFacade method updateAccessPolicy.

// -----------------------------------------
// Write Operations
// -----------------------------------------
@Override
public AccessPolicyEntity updateAccessPolicy(final Revision revision, final AccessPolicyDTO accessPolicyDTO) {
    final Authorizable authorizable = authorizableLookup.getAccessPolicyById(accessPolicyDTO.getId());
    final RevisionUpdate<AccessPolicyDTO> snapshot = updateComponent(revision, authorizable, () -> accessPolicyDAO.updateAccessPolicy(accessPolicyDTO), accessPolicy -> {
        final Set<TenantEntity> users = accessPolicy.getUsers().stream().map(mapUserIdToTenantEntity()).collect(Collectors.toSet());
        final Set<TenantEntity> userGroups = accessPolicy.getGroups().stream().map(mapUserGroupIdToTenantEntity()).collect(Collectors.toSet());
        final ComponentReferenceEntity componentReference = createComponentReferenceEntity(accessPolicy.getResource());
        return dtoFactory.createAccessPolicyDto(accessPolicy, userGroups, users, componentReference);
    });
    final PermissionsDTO permissions = dtoFactory.createPermissionsDto(authorizable);
    return entityFactory.createAccessPolicyEntity(snapshot.getComponent(), dtoFactory.createRevisionDTO(snapshot.getLastModification()), permissions);
}
Also used : TenantEntity(org.apache.nifi.web.api.entity.TenantEntity) ComponentReferenceEntity(org.apache.nifi.web.api.entity.ComponentReferenceEntity) PermissionsDTO(org.apache.nifi.web.api.dto.PermissionsDTO) Authorizable(org.apache.nifi.authorization.resource.Authorizable) AccessPolicyDTO(org.apache.nifi.web.api.dto.AccessPolicyDTO)

Example 2 with AccessPolicyDTO

use of org.apache.nifi.web.api.dto.AccessPolicyDTO in project nifi by apache.

the class StandardNiFiServiceFacade method createAccessPolicy.

@Override
public AccessPolicyEntity createAccessPolicy(final Revision revision, final AccessPolicyDTO accessPolicyDTO) {
    final Authorizable tenantAuthorizable = authorizableLookup.getTenant();
    final String creator = NiFiUserUtils.getNiFiUserIdentity();
    final AccessPolicy newAccessPolicy = accessPolicyDAO.createAccessPolicy(accessPolicyDTO);
    final ComponentReferenceEntity componentReference = createComponentReferenceEntity(newAccessPolicy.getResource());
    final AccessPolicyDTO newAccessPolicyDto = dtoFactory.createAccessPolicyDto(newAccessPolicy, newAccessPolicy.getGroups().stream().map(mapUserGroupIdToTenantEntity()).collect(Collectors.toSet()), newAccessPolicy.getUsers().stream().map(userId -> {
        final RevisionDTO userRevision = dtoFactory.createRevisionDTO(revisionManager.getRevision(userId));
        return entityFactory.createTenantEntity(dtoFactory.createTenantDTO(userDAO.getUser(userId)), userRevision, dtoFactory.createPermissionsDto(tenantAuthorizable));
    }).collect(Collectors.toSet()), componentReference);
    final PermissionsDTO permissions = dtoFactory.createPermissionsDto(authorizableLookup.getAccessPolicyById(accessPolicyDTO.getId()));
    return entityFactory.createAccessPolicyEntity(newAccessPolicyDto, dtoFactory.createRevisionDTO(new FlowModification(revision, creator)), permissions);
}
Also used : ComponentReferenceEntity(org.apache.nifi.web.api.entity.ComponentReferenceEntity) PermissionsDTO(org.apache.nifi.web.api.dto.PermissionsDTO) Authorizable(org.apache.nifi.authorization.resource.Authorizable) AccessPolicyDTO(org.apache.nifi.web.api.dto.AccessPolicyDTO) AccessPolicy(org.apache.nifi.authorization.AccessPolicy) RevisionDTO(org.apache.nifi.web.api.dto.RevisionDTO)

Example 3 with AccessPolicyDTO

use of org.apache.nifi.web.api.dto.AccessPolicyDTO in project nifi by apache.

the class UserGroupEntityMergerTest method testMergeAccessPolicy.

@Test
public void testMergeAccessPolicy() throws Exception {
    final NodeIdentifier node1 = new NodeIdentifier("node-1", "host-1", 8080, "host-1", 19998, null, null, null, false);
    final NodeIdentifier node2 = new NodeIdentifier("node-2", "host-2", 8081, "host-2", 19999, null, null, null, false);
    final PermissionsDTO permissed = new PermissionsDTO();
    permissed.setCanRead(true);
    permissed.setCanWrite(true);
    final TenantDTO user1DTO = new TenantDTO();
    user1DTO.setId("user-1");
    final TenantEntity user1Entity = new TenantEntity();
    user1Entity.setPermissions(permissed);
    user1Entity.setId(user1DTO.getId());
    user1Entity.setComponent(user1DTO);
    final TenantDTO user2DTO = new TenantDTO();
    user1DTO.setId("user-2");
    final TenantEntity user2Entity = new TenantEntity();
    user2Entity.setPermissions(permissed);
    user2Entity.setId(user2DTO.getId());
    user2Entity.setComponent(user2DTO);
    final AccessPolicyDTO policy1DTO = new AccessPolicyDTO();
    policy1DTO.setId("policy-1");
    final AccessPolicyEntity policy1Entity = new AccessPolicyEntity();
    policy1Entity.setPermissions(permissed);
    policy1Entity.setId(policy1DTO.getId());
    policy1Entity.setComponent(policy1DTO);
    final AccessPolicyDTO policy2DTO = new AccessPolicyDTO();
    policy2DTO.setId("policy-2");
    final AccessPolicyEntity policy2Entity = new AccessPolicyEntity();
    policy2Entity.setPermissions(permissed);
    policy2Entity.setId(policy2DTO.getId());
    policy2Entity.setComponent(policy2DTO);
    final UserGroupDTO userGroup1DTO = new UserGroupDTO();
    userGroup1DTO.setId("user-1");
    userGroup1DTO.setAccessPolicies(Stream.of(policy1Entity, policy2Entity).collect(Collectors.toSet()));
    userGroup1DTO.setUsers(Stream.of(user2Entity).collect(Collectors.toSet()));
    final UserGroupEntity userGroup1Entity = new UserGroupEntity();
    userGroup1Entity.setPermissions(permissed);
    userGroup1Entity.setId(userGroup1DTO.getId());
    userGroup1Entity.setComponent(userGroup1DTO);
    final UserGroupDTO userGroup2DTO = new UserGroupDTO();
    userGroup2DTO.setId("user-2");
    userGroup2DTO.setAccessPolicies(Stream.of(policy1Entity).collect(Collectors.toSet()));
    userGroup2DTO.setUsers(Stream.of(user1Entity, user2Entity).collect(Collectors.toSet()));
    final UserGroupEntity userGroup2Entity = new UserGroupEntity();
    userGroup2Entity.setPermissions(permissed);
    userGroup2Entity.setId(userGroup2DTO.getId());
    userGroup2Entity.setComponent(userGroup2DTO);
    final Map<NodeIdentifier, UserGroupEntity> nodeMap = new HashMap<>();
    nodeMap.put(node1, userGroup1Entity);
    nodeMap.put(node2, userGroup2Entity);
    final UserGroupEntityMerger merger = new UserGroupEntityMerger();
    merger.merge(userGroup1Entity, nodeMap);
    assertEquals(1, userGroup1DTO.getUsers().size());
    assertTrue(userGroup1DTO.getAccessPolicies().contains(policy1Entity));
    assertEquals(1, userGroup1DTO.getUsers().size());
    assertTrue(userGroup1DTO.getUsers().contains(user2Entity));
}
Also used : TenantEntity(org.apache.nifi.web.api.entity.TenantEntity) HashMap(java.util.HashMap) NodeIdentifier(org.apache.nifi.cluster.protocol.NodeIdentifier) PermissionsDTO(org.apache.nifi.web.api.dto.PermissionsDTO) TenantDTO(org.apache.nifi.web.api.dto.TenantDTO) UserGroupDTO(org.apache.nifi.web.api.dto.UserGroupDTO) UserGroupEntity(org.apache.nifi.web.api.entity.UserGroupEntity) AccessPolicyDTO(org.apache.nifi.web.api.dto.AccessPolicyDTO) AccessPolicyEntity(org.apache.nifi.web.api.entity.AccessPolicyEntity) Test(org.junit.Test)

Example 4 with AccessPolicyDTO

use of org.apache.nifi.web.api.dto.AccessPolicyDTO in project nifi by apache.

the class StandardNiFiServiceFacade method deleteAccessPolicy.

@Override
public AccessPolicyEntity deleteAccessPolicy(final Revision revision, final String accessPolicyId) {
    final AccessPolicy accessPolicy = accessPolicyDAO.getAccessPolicy(accessPolicyId);
    final ComponentReferenceEntity componentReference = createComponentReferenceEntity(accessPolicy.getResource());
    final PermissionsDTO permissions = dtoFactory.createPermissionsDto(authorizableLookup.getAccessPolicyById(accessPolicyId));
    final Set<TenantEntity> userGroups = accessPolicy != null ? accessPolicy.getGroups().stream().map(mapUserGroupIdToTenantEntity()).collect(Collectors.toSet()) : null;
    final Set<TenantEntity> users = accessPolicy != null ? accessPolicy.getUsers().stream().map(mapUserIdToTenantEntity()).collect(Collectors.toSet()) : null;
    final AccessPolicyDTO snapshot = deleteComponent(revision, new Resource() {

        @Override
        public String getIdentifier() {
            return accessPolicy.getResource();
        }

        @Override
        public String getName() {
            return accessPolicy.getResource();
        }

        @Override
        public String getSafeDescription() {
            return "Policy " + accessPolicyId;
        }
    }, () -> accessPolicyDAO.deleteAccessPolicy(accessPolicyId), // no need to clean up any policies as it's already been removed above
    false, dtoFactory.createAccessPolicyDto(accessPolicy, userGroups, users, componentReference));
    return entityFactory.createAccessPolicyEntity(snapshot, null, permissions);
}
Also used : ComponentReferenceEntity(org.apache.nifi.web.api.entity.ComponentReferenceEntity) TenantEntity(org.apache.nifi.web.api.entity.TenantEntity) PermissionsDTO(org.apache.nifi.web.api.dto.PermissionsDTO) EnforcePolicyPermissionsThroughBaseResource(org.apache.nifi.authorization.resource.EnforcePolicyPermissionsThroughBaseResource) Resource(org.apache.nifi.authorization.Resource) AccessPolicyDTO(org.apache.nifi.web.api.dto.AccessPolicyDTO) AccessPolicy(org.apache.nifi.authorization.AccessPolicy)

Example 5 with AccessPolicyDTO

use of org.apache.nifi.web.api.dto.AccessPolicyDTO in project nifi by apache.

the class AccessPolicyEntityMerger method mergeComponents.

/**
 * Merges the AccessPolicyEntity responses.
 *
 * @param clientEntity the entity being returned to the client
 * @param entityMap all node responses
 */
public void mergeComponents(final AccessPolicyEntity clientEntity, final Map<NodeIdentifier, AccessPolicyEntity> entityMap) {
    final AccessPolicyDTO clientDto = clientEntity.getComponent();
    final Map<NodeIdentifier, AccessPolicyDTO> dtoMap = new HashMap<>();
    for (final Map.Entry<NodeIdentifier, AccessPolicyEntity> entry : entityMap.entrySet()) {
        final AccessPolicyEntity nodeAccessPolicyEntity = entry.getValue();
        final AccessPolicyDTO nodeAccessPolicyDto = nodeAccessPolicyEntity.getComponent();
        dtoMap.put(entry.getKey(), nodeAccessPolicyDto);
    }
    mergeDtos(clientDto, dtoMap);
}
Also used : HashMap(java.util.HashMap) NodeIdentifier(org.apache.nifi.cluster.protocol.NodeIdentifier) AccessPolicyDTO(org.apache.nifi.web.api.dto.AccessPolicyDTO) Map(java.util.Map) HashMap(java.util.HashMap) AccessPolicyEntity(org.apache.nifi.web.api.entity.AccessPolicyEntity)

Aggregations

AccessPolicyDTO (org.apache.nifi.web.api.dto.AccessPolicyDTO)10 TenantEntity (org.apache.nifi.web.api.entity.TenantEntity)6 HashMap (java.util.HashMap)5 PermissionsDTO (org.apache.nifi.web.api.dto.PermissionsDTO)5 AccessPolicyEntity (org.apache.nifi.web.api.entity.AccessPolicyEntity)5 Authorizable (org.apache.nifi.authorization.resource.Authorizable)4 NodeIdentifier (org.apache.nifi.cluster.protocol.NodeIdentifier)4 AccessPolicy (org.apache.nifi.authorization.AccessPolicy)3 ComponentReferenceEntity (org.apache.nifi.web.api.entity.ComponentReferenceEntity)3 ApiOperation (io.swagger.annotations.ApiOperation)2 ApiResponses (io.swagger.annotations.ApiResponses)2 HashSet (java.util.HashSet)2 Map (java.util.Map)2 Consumes (javax.ws.rs.Consumes)2 Produces (javax.ws.rs.Produces)2 Resource (org.apache.nifi.authorization.Resource)2 Revision (org.apache.nifi.web.Revision)2 RevisionDTO (org.apache.nifi.web.api.dto.RevisionDTO)2 TenantDTO (org.apache.nifi.web.api.dto.TenantDTO)2 Test (org.junit.Test)2