You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

DefaultRedbackRuntimeConfigurationService.java 16KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420
  1. package org.apache.archiva.rest.services;
  2. /*
  3. * Licensed to the Apache Software Foundation (ASF) under one
  4. * or more contributor license agreements. See the NOTICE file
  5. * distributed with this work for additional information
  6. * regarding copyright ownership. The ASF licenses this file
  7. * to you under the Apache License, Version 2.0 (the
  8. * "License"); you may not use this file except in compliance
  9. * with the License. You may obtain a copy of the License at
  10. *
  11. * http://www.apache.org/licenses/LICENSE-2.0
  12. *
  13. * Unless required by applicable law or agreed to in writing,
  14. * software distributed under the License is distributed on an
  15. * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
  16. * KIND, either express or implied. See the License for the
  17. * specific language governing permissions and limitations
  18. * under the License.
  19. */
  20. import org.apache.archiva.admin.model.RepositoryAdminException;
  21. import org.apache.archiva.admin.model.beans.LdapConfiguration;
  22. import org.apache.archiva.admin.model.beans.RedbackRuntimeConfiguration;
  23. import org.apache.archiva.admin.model.runtime.RedbackRuntimeConfigurationAdmin;
  24. import org.apache.archiva.redback.authentication.Authenticator;
  25. import org.apache.archiva.redback.common.ldap.connection.LdapConnection;
  26. import org.apache.archiva.redback.common.ldap.connection.LdapConnectionConfiguration;
  27. import org.apache.archiva.redback.common.ldap.connection.LdapConnectionFactory;
  28. import org.apache.archiva.redback.common.ldap.connection.LdapException;
  29. import org.apache.archiva.redback.common.ldap.user.LdapUserMapper;
  30. import org.apache.archiva.components.cache.Cache;
  31. import org.apache.archiva.redback.policy.CookieSettings;
  32. import org.apache.archiva.redback.policy.PasswordRule;
  33. import org.apache.archiva.redback.rbac.RBACManager;
  34. import org.apache.archiva.redback.role.RoleManager;
  35. import org.apache.archiva.redback.users.UserManager;
  36. import org.apache.archiva.rest.api.model.ActionStatus;
  37. import org.apache.archiva.rest.api.model.RBACManagerImplementationInformation;
  38. import org.apache.archiva.rest.api.model.RedbackImplementationsInformations;
  39. import org.apache.archiva.rest.api.model.UserManagerImplementationInformation;
  40. import org.apache.archiva.rest.api.services.ArchivaRestServiceException;
  41. import org.apache.archiva.rest.api.services.RedbackRuntimeConfigurationService;
  42. import org.apache.commons.lang3.StringUtils;
  43. import org.springframework.context.ApplicationContext;
  44. import org.springframework.stereotype.Service;
  45. import javax.inject.Inject;
  46. import javax.inject.Named;
  47. import javax.naming.InvalidNameException;
  48. import javax.naming.NamingException;
  49. import java.util.ArrayList;
  50. import java.util.Collection;
  51. import java.util.Collections;
  52. import java.util.List;
  53. import java.util.Map;
  54. import java.util.Properties;
  55. /**
  56. * @author Olivier Lamy
  57. * @since 1.4-M4
  58. */
  59. @Service("redbackRuntimeConfigurationService#rest")
  60. public class DefaultRedbackRuntimeConfigurationService
  61. extends AbstractRestService
  62. implements RedbackRuntimeConfigurationService
  63. {
  64. @Inject
  65. private RedbackRuntimeConfigurationAdmin redbackRuntimeConfigurationAdmin;
  66. @Inject
  67. @Named(value = "userManager#default")
  68. private UserManager userManager;
  69. @Inject
  70. @Named(value = "rbacManager#default")
  71. private RBACManager rbacManager;
  72. @Inject
  73. private RoleManager roleManager;
  74. @Inject
  75. private ApplicationContext applicationContext;
  76. @Inject
  77. @Named(value = "ldapConnectionFactory#configurable")
  78. private LdapConnectionFactory ldapConnectionFactory;
  79. @Inject
  80. @Named(value = "cache#users")
  81. private Cache usersCache;
  82. @Inject
  83. private LdapUserMapper ldapUserMapper;
  84. @Override
  85. public RedbackRuntimeConfiguration getRedbackRuntimeConfiguration()
  86. throws ArchivaRestServiceException
  87. {
  88. try
  89. {
  90. RedbackRuntimeConfiguration redbackRuntimeConfiguration =
  91. redbackRuntimeConfigurationAdmin.getRedbackRuntimeConfiguration();
  92. log.debug( "getRedbackRuntimeConfiguration -> {}", redbackRuntimeConfiguration );
  93. return redbackRuntimeConfiguration;
  94. }
  95. catch ( RepositoryAdminException e )
  96. {
  97. throw new ArchivaRestServiceException( e.getMessage(), e );
  98. }
  99. }
  100. @Override
  101. public Boolean updateRedbackRuntimeConfiguration( RedbackRuntimeConfiguration redbackRuntimeConfiguration )
  102. throws ArchivaRestServiceException
  103. {
  104. try
  105. {
  106. // has user manager impl changed ?
  107. boolean userManagerChanged = redbackRuntimeConfiguration.getUserManagerImpls().size()
  108. != redbackRuntimeConfigurationAdmin.getRedbackRuntimeConfiguration().getUserManagerImpls().size();
  109. userManagerChanged =
  110. userManagerChanged || ( redbackRuntimeConfiguration.getUserManagerImpls().toString().hashCode()
  111. != redbackRuntimeConfigurationAdmin.getRedbackRuntimeConfiguration().getUserManagerImpls().toString().hashCode() );
  112. boolean rbacManagerChanged = redbackRuntimeConfiguration.getRbacManagerImpls().size()
  113. != redbackRuntimeConfigurationAdmin.getRedbackRuntimeConfiguration().getRbacManagerImpls().size();
  114. rbacManagerChanged =
  115. rbacManagerChanged || ( redbackRuntimeConfiguration.getRbacManagerImpls().toString().hashCode()
  116. != redbackRuntimeConfigurationAdmin.getRedbackRuntimeConfiguration().getRbacManagerImpls().toString().hashCode() );
  117. boolean ldapConfigured = false;
  118. for (String um : redbackRuntimeConfiguration.getUserManagerImpls()) {
  119. if (um.contains("ldap")) {
  120. ldapConfigured=true;
  121. }
  122. }
  123. if (!ldapConfigured) {
  124. for (String rbm : redbackRuntimeConfiguration.getRbacManagerImpls()) {
  125. if (rbm.contains("ldap")) {
  126. ldapConfigured = true;
  127. }
  128. }
  129. }
  130. redbackRuntimeConfigurationAdmin.updateRedbackRuntimeConfiguration( redbackRuntimeConfiguration );
  131. if ( userManagerChanged )
  132. {
  133. log.info( "user managerImpls changed to {} so reload it",
  134. redbackRuntimeConfiguration.getUserManagerImpls() );
  135. userManager.initialize();
  136. }
  137. if ( rbacManagerChanged )
  138. {
  139. log.info( "rbac manager changed to {} so reload it",
  140. redbackRuntimeConfiguration.getRbacManagerImpls() );
  141. rbacManager.initialize();
  142. roleManager.initialize();
  143. }
  144. if (ldapConfigured) {
  145. try {
  146. ldapConnectionFactory.initialize();
  147. } catch (Exception e) {
  148. ArchivaRestServiceException newEx = new ArchivaRestServiceException(e.getMessage(), e);
  149. newEx.setErrorKey("error.ldap.connectionFactory.init.failed");
  150. throw newEx;
  151. }
  152. }
  153. Collection<PasswordRule> passwordRules = applicationContext.getBeansOfType( PasswordRule.class ).values();
  154. for ( PasswordRule passwordRule : passwordRules )
  155. {
  156. passwordRule.initialize();
  157. }
  158. Collection<CookieSettings> cookieSettingsList =
  159. applicationContext.getBeansOfType( CookieSettings.class ).values();
  160. for ( CookieSettings cookieSettings : cookieSettingsList )
  161. {
  162. cookieSettings.initialize();
  163. }
  164. Collection<Authenticator> authenticators =
  165. applicationContext.getBeansOfType( Authenticator.class ).values();
  166. for ( Authenticator authenticator : authenticators )
  167. {
  168. try {
  169. log.debug("Initializing authenticatior "+authenticator.getId());
  170. authenticator.initialize();
  171. } catch (Exception e) {
  172. log.error("Initialization of authenticator failed "+authenticator.getId(),e);
  173. }
  174. }
  175. // users cache
  176. usersCache.setTimeToIdleSeconds(
  177. redbackRuntimeConfiguration.getUsersCacheConfiguration().getTimeToIdleSeconds() );
  178. usersCache.setTimeToLiveSeconds(
  179. redbackRuntimeConfiguration.getUsersCacheConfiguration().getTimeToLiveSeconds() );
  180. usersCache.setMaxElementsInMemory(
  181. redbackRuntimeConfiguration.getUsersCacheConfiguration().getMaxElementsInMemory() );
  182. usersCache.setMaxElementsOnDisk(
  183. redbackRuntimeConfiguration.getUsersCacheConfiguration().getMaxElementsOnDisk() );
  184. if (ldapConfigured) {
  185. try {
  186. ldapUserMapper.initialize();
  187. } catch (Exception e) {
  188. ArchivaRestServiceException newEx = new ArchivaRestServiceException(e.getMessage(), e);
  189. newEx.setErrorKey("error.ldap.userMapper.init.failed");
  190. throw newEx;
  191. }
  192. }
  193. return Boolean.TRUE;
  194. }
  195. catch (ArchivaRestServiceException e) {
  196. log.error(e.getMessage(), e);
  197. throw e;
  198. } catch ( Exception e )
  199. {
  200. log.error( e.getMessage(), e );
  201. throw new ArchivaRestServiceException(e.getMessage(), e);
  202. }
  203. }
  204. @Override
  205. public List<UserManagerImplementationInformation> getUserManagerImplementationInformations()
  206. throws ArchivaRestServiceException
  207. {
  208. Map<String, UserManager> beans = applicationContext.getBeansOfType( UserManager.class );
  209. if ( beans.isEmpty() )
  210. {
  211. return Collections.emptyList();
  212. }
  213. List<UserManagerImplementationInformation> informations = new ArrayList<>( beans.size() );
  214. for ( Map.Entry<String, UserManager> entry : beans.entrySet() )
  215. {
  216. UserManager userManager = applicationContext.getBean( entry.getKey(), UserManager.class );
  217. if ( userManager.isFinalImplementation() )
  218. {
  219. UserManagerImplementationInformation information = new UserManagerImplementationInformation();
  220. information.setBeanId( StringUtils.substringAfter( entry.getKey(), "#" ) );
  221. information.setDescriptionKey( userManager.getDescriptionKey() );
  222. information.setReadOnly( userManager.isReadOnly() );
  223. informations.add( information );
  224. }
  225. }
  226. return informations;
  227. }
  228. @Override
  229. public List<RBACManagerImplementationInformation> getRbacManagerImplementationInformations()
  230. throws ArchivaRestServiceException
  231. {
  232. Map<String, RBACManager> beans = applicationContext.getBeansOfType( RBACManager.class );
  233. if ( beans.isEmpty() )
  234. {
  235. return Collections.emptyList();
  236. }
  237. List<RBACManagerImplementationInformation> informations = new ArrayList<>( beans.size() );
  238. for ( Map.Entry<String, RBACManager> entry : beans.entrySet() )
  239. {
  240. RBACManager rbacManager = applicationContext.getBean( entry.getKey(), RBACManager.class );
  241. if ( rbacManager.isFinalImplementation() )
  242. {
  243. RBACManagerImplementationInformation information = new RBACManagerImplementationInformation();
  244. information.setBeanId( StringUtils.substringAfter( entry.getKey(), "#" ) );
  245. information.setDescriptionKey( rbacManager.getDescriptionKey() );
  246. information.setReadOnly( rbacManager.isReadOnly() );
  247. informations.add( information );
  248. }
  249. }
  250. return informations;
  251. }
  252. @Override
  253. public RedbackImplementationsInformations getRedbackImplementationsInformations()
  254. throws ArchivaRestServiceException
  255. {
  256. return new RedbackImplementationsInformations( getUserManagerImplementationInformations(),
  257. getRbacManagerImplementationInformations() );
  258. }
  259. @Override
  260. public Boolean checkLdapConnection()
  261. throws ArchivaRestServiceException
  262. {
  263. LdapConnection ldapConnection = null;
  264. try
  265. {
  266. ldapConnection = ldapConnectionFactory.getConnection();
  267. }
  268. catch ( LdapException e )
  269. {
  270. log.warn( "fail to get ldapConnection: {}", e.getMessage(), e );
  271. throw new ArchivaRestServiceException( e.getMessage(), e );
  272. }
  273. finally
  274. {
  275. if ( ldapConnection != null )
  276. {
  277. try
  278. {
  279. ldapConnection.close();
  280. }
  281. catch ( NamingException e )
  282. {
  283. log.error( "Could not close connection: {}", e.getMessage( ), e );
  284. }
  285. }
  286. }
  287. return Boolean.TRUE;
  288. }
  289. @Override
  290. public Boolean checkLdapConnection( LdapConfiguration ldapConfiguration )
  291. throws ArchivaRestServiceException
  292. {
  293. LdapConnection ldapConnection = null;
  294. try
  295. {
  296. LdapConnectionConfiguration ldapConnectionConfiguration =
  297. new LdapConnectionConfiguration( ldapConfiguration.getHostName(), ldapConfiguration.getPort(),
  298. ldapConfiguration.getBaseDn(), ldapConfiguration.getContextFactory(),
  299. ldapConfiguration.getBindDn(), ldapConfiguration.getPassword(),
  300. ldapConfiguration.getAuthenticationMethod(),
  301. toProperties( ldapConfiguration.getExtraProperties() ) );
  302. ldapConnectionConfiguration.setSsl( ldapConfiguration.isSsl() );
  303. ldapConnection = ldapConnectionFactory.getConnection( ldapConnectionConfiguration );
  304. ldapConnection.close();
  305. // verify groups dn value too
  306. ldapConnectionConfiguration =
  307. new LdapConnectionConfiguration( ldapConfiguration.getHostName(), ldapConfiguration.getPort(),
  308. ldapConfiguration.getBaseGroupsDn(),
  309. ldapConfiguration.getContextFactory(), ldapConfiguration.getBindDn(),
  310. ldapConfiguration.getPassword(),
  311. ldapConfiguration.getAuthenticationMethod(),
  312. toProperties( ldapConfiguration.getExtraProperties() ) );
  313. ldapConnectionConfiguration.setSsl( ldapConfiguration.isSsl() );
  314. ldapConnection = ldapConnectionFactory.getConnection( ldapConnectionConfiguration );
  315. }
  316. catch ( InvalidNameException e )
  317. {
  318. log.warn( "fail to get ldapConnection: {}", e.getMessage(), e );
  319. throw new ArchivaRestServiceException( e.getMessage(), e );
  320. }
  321. catch ( LdapException e )
  322. {
  323. log.warn( "fail to get ldapConnection: {}", e.getMessage(), e );
  324. throw new ArchivaRestServiceException( e.getMessage(), e );
  325. }
  326. catch ( NamingException e )
  327. {
  328. log.error( "Could not close connection: {}", e.getMessage( ), e );
  329. }
  330. finally
  331. {
  332. if ( ldapConnection != null )
  333. {
  334. try
  335. {
  336. ldapConnection.close();
  337. }
  338. catch ( NamingException e )
  339. {
  340. log.error( "Could not close connection: {}", e.getMessage( ), e );
  341. }
  342. }
  343. }
  344. return Boolean.TRUE;
  345. }
  346. private Properties toProperties( Map<String, String> map )
  347. {
  348. Properties properties = new Properties();
  349. if ( map == null || map.isEmpty() )
  350. {
  351. return properties;
  352. }
  353. for ( Map.Entry<String, String> entry : map.entrySet() )
  354. {
  355. properties.put( entry.getKey(), entry.getValue() );
  356. }
  357. return properties;
  358. }
  359. }