Vous ne pouvez pas sélectionner plus de 25 sujets Les noms de sujets doivent commencer par une lettre ou un nombre, peuvent contenir des tirets ('-') et peuvent comporter jusqu'à 35 caractères.

DefaultMavenManagedRepositoryService.java 18KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388
  1. package org.apache.archiva.rest.v2.svc.maven;
  2. /*
  3. * Licensed to the Apache Software Foundation (ASF) under one
  4. * or more contributor license agreements. See the NOTICE file
  5. * distributed with this work for additional information
  6. * regarding copyright ownership. The ASF licenses this file
  7. * to you under the Apache License, Version 2.0 (the
  8. * "License"); you may not use this file except in compliance
  9. * with the License. You may obtain a copy of the License at
  10. *
  11. * http://www.apache.org/licenses/LICENSE-2.0
  12. * Unless required by applicable law or agreed to in writing,
  13. * software distributed under the License is distributed on an
  14. * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
  15. * KIND, either express or implied. See the License for the
  16. * specific language governing permissions and limitations
  17. * under the License.
  18. */
  19. import org.apache.archiva.admin.model.AuditInformation;
  20. import org.apache.archiva.admin.model.RepositoryAdminException;
  21. import org.apache.archiva.admin.model.managed.ManagedRepositoryAdmin;
  22. import org.apache.archiva.components.rest.model.PagedResult;
  23. import org.apache.archiva.components.rest.util.QueryHelper;
  24. import org.apache.archiva.redback.authentication.AuthenticationResult;
  25. import org.apache.archiva.redback.authorization.AuthorizationException;
  26. import org.apache.archiva.redback.rest.services.RedbackAuthenticationThreadLocal;
  27. import org.apache.archiva.redback.rest.services.RedbackRequestInformation;
  28. import org.apache.archiva.redback.system.DefaultSecuritySession;
  29. import org.apache.archiva.redback.system.SecuritySession;
  30. import org.apache.archiva.redback.system.SecuritySystem;
  31. import org.apache.archiva.redback.users.User;
  32. import org.apache.archiva.redback.users.UserManagerException;
  33. import org.apache.archiva.redback.users.UserNotFoundException;
  34. import org.apache.archiva.repository.ManagedRepository;
  35. import org.apache.archiva.repository.ReleaseScheme;
  36. import org.apache.archiva.repository.Repository;
  37. import org.apache.archiva.repository.RepositoryRegistry;
  38. import org.apache.archiva.repository.RepositoryType;
  39. import org.apache.archiva.repository.content.ContentItem;
  40. import org.apache.archiva.repository.content.LayoutException;
  41. import org.apache.archiva.repository.storage.fs.FsStorageUtil;
  42. import org.apache.archiva.rest.api.v2.model.FileInfo;
  43. import org.apache.archiva.rest.api.v2.model.MavenManagedRepository;
  44. import org.apache.archiva.rest.api.v2.model.MavenManagedRepositoryUpdate;
  45. import org.apache.archiva.rest.api.v2.svc.ArchivaRestServiceException;
  46. import org.apache.archiva.rest.api.v2.svc.ErrorKeys;
  47. import org.apache.archiva.rest.api.v2.svc.ErrorMessage;
  48. import org.apache.archiva.rest.api.v2.svc.maven.MavenManagedRepositoryService;
  49. import org.apache.archiva.security.common.ArchivaRoleConstants;
  50. import org.apache.commons.lang3.StringUtils;
  51. import org.slf4j.Logger;
  52. import org.slf4j.LoggerFactory;
  53. import org.springframework.stereotype.Service;
  54. import javax.servlet.http.HttpServletResponse;
  55. import javax.ws.rs.core.Context;
  56. import javax.ws.rs.core.Response;
  57. import javax.ws.rs.core.UriInfo;
  58. import java.io.IOException;
  59. import java.util.Collection;
  60. import java.util.Comparator;
  61. import java.util.List;
  62. import java.util.function.Predicate;
  63. import java.util.stream.Collectors;
  64. import static org.apache.archiva.security.common.ArchivaRoleConstants.OPERATION_READ_REPOSITORY;
  65. import static org.apache.archiva.security.common.ArchivaRoleConstants.OPERATION_ADD_ARTIFACT;
  66. /**
  67. * @author Martin Stockhammer <martin_s@apache.org>
  68. */
  69. @Service("v2.managedMavenRepositoryService#rest")
  70. public class DefaultMavenManagedRepositoryService implements MavenManagedRepositoryService
  71. {
  72. @Context
  73. HttpServletResponse httpServletResponse;
  74. @Context
  75. UriInfo uriInfo;
  76. private static final Logger log = LoggerFactory.getLogger( DefaultMavenManagedRepositoryService.class );
  77. private static final QueryHelper<ManagedRepository> QUERY_HELPER = new QueryHelper<>( new String[]{"id", "name"} );
  78. static
  79. {
  80. QUERY_HELPER.addStringFilter( "id", ManagedRepository::getId );
  81. QUERY_HELPER.addStringFilter( "name", ManagedRepository::getName );
  82. QUERY_HELPER.addStringFilter( "location", (r) -> r.getLocation().toString() );
  83. QUERY_HELPER.addBooleanFilter( "snapshot", (r) -> r.getActiveReleaseSchemes( ).contains( ReleaseScheme.SNAPSHOT ) );
  84. QUERY_HELPER.addBooleanFilter( "release", (r) -> r.getActiveReleaseSchemes().contains( ReleaseScheme.RELEASE ));
  85. QUERY_HELPER.addNullsafeFieldComparator( "id", ManagedRepository::getId );
  86. QUERY_HELPER.addNullsafeFieldComparator( "name", ManagedRepository::getName );
  87. }
  88. private final ManagedRepositoryAdmin managedRepositoryAdmin;
  89. private final RepositoryRegistry repositoryRegistry;
  90. private final SecuritySystem securitySystem;
  91. public DefaultMavenManagedRepositoryService( SecuritySystem securitySystem,
  92. RepositoryRegistry repositoryRegistry,
  93. ManagedRepositoryAdmin managedRepositoryAdmin )
  94. {
  95. this.securitySystem = securitySystem;
  96. this.repositoryRegistry = repositoryRegistry;
  97. this.managedRepositoryAdmin = managedRepositoryAdmin;
  98. }
  99. protected AuditInformation getAuditInformation( )
  100. {
  101. RedbackRequestInformation redbackRequestInformation = RedbackAuthenticationThreadLocal.get( );
  102. User user;
  103. String remoteAddr;
  104. if (redbackRequestInformation==null) {
  105. user = null;
  106. remoteAddr = null;
  107. } else
  108. {
  109. user = redbackRequestInformation.getUser( );
  110. remoteAddr = redbackRequestInformation.getRemoteAddr( );
  111. }
  112. return new AuditInformation( user, remoteAddr );
  113. }
  114. @Override
  115. public PagedResult<MavenManagedRepository> getManagedRepositories( final String searchTerm, final Integer offset,
  116. final Integer limit, final List<String> orderBy,
  117. final String order ) throws ArchivaRestServiceException
  118. {
  119. try
  120. {
  121. Collection<ManagedRepository> repos = repositoryRegistry.getManagedRepositories( );
  122. final Predicate<ManagedRepository> queryFilter = QUERY_HELPER.getQueryFilter( searchTerm ).and( r -> r.getType() == RepositoryType.MAVEN );
  123. final Comparator<ManagedRepository> comparator = QUERY_HELPER.getComparator( orderBy, order );
  124. int totalCount = Math.toIntExact( repos.stream( ).filter( queryFilter ).count( ) );
  125. return PagedResult.of( totalCount, offset, limit, repos.stream( ).filter( queryFilter ).sorted( comparator )
  126. .map( MavenManagedRepository::of ).skip( offset ).limit( limit ).collect( Collectors.toList( ) ) );
  127. }
  128. catch (ArithmeticException e) {
  129. log.error( "Invalid number of repositories detected." );
  130. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.INVALID_RESULT_SET_ERROR ) );
  131. }
  132. }
  133. @Override
  134. public MavenManagedRepository getManagedRepository( String repositoryId ) throws ArchivaRestServiceException
  135. {
  136. ManagedRepository repo = repositoryRegistry.getManagedRepository( repositoryId );
  137. if (repo==null) {
  138. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.REPOSITORY_NOT_FOUND, repositoryId ), 404 );
  139. }
  140. if (repo.getType()!=RepositoryType.MAVEN) {
  141. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.REPOSITORY_WRONG_TYPE, repositoryId, repo.getType().name() ), 404 );
  142. }
  143. return MavenManagedRepository.of( repo );
  144. }
  145. @Override
  146. public Response deleteManagedRepository( String repositoryId, Boolean deleteContent ) throws ArchivaRestServiceException
  147. {
  148. MavenManagedRepository repo = getManagedRepository( repositoryId );
  149. if (repo != null)
  150. {
  151. try
  152. {
  153. managedRepositoryAdmin.deleteManagedRepository( repositoryId, getAuditInformation( ), deleteContent );
  154. return Response.ok( ).build( );
  155. }
  156. catch ( RepositoryAdminException e )
  157. {
  158. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.REPOSITORY_DELETE_FAILED, e.getMessage( ) ) );
  159. }
  160. } else {
  161. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.REPOSITORY_NOT_FOUND, repositoryId ), 404 );
  162. }
  163. }
  164. private org.apache.archiva.admin.model.beans.ManagedRepository convert(MavenManagedRepository repository) {
  165. org.apache.archiva.admin.model.beans.ManagedRepository repoBean = new org.apache.archiva.admin.model.beans.ManagedRepository( );
  166. repoBean.setId( repository.getId( ) );
  167. repoBean.setName( repository.getName() );
  168. repoBean.setDescription( repository.getDescription() );
  169. repoBean.setBlockRedeployments( repository.isBlocksRedeployments() );
  170. repoBean.setCronExpression( repository.getSchedulingDefinition() );
  171. repoBean.setLocation( repository.getLocation() );
  172. repoBean.setReleases( repository.getReleaseSchemes().contains( ReleaseScheme.RELEASE.name() ) );
  173. repoBean.setSnapshots( repository.getReleaseSchemes().contains( ReleaseScheme.SNAPSHOT.name() ) );
  174. repoBean.setScanned( repository.isScanned() );
  175. repoBean.setDeleteReleasedSnapshots( repository.isDeleteSnapshotsOfRelease() );
  176. repoBean.setSkipPackedIndexCreation( repository.isSkipPackedIndexCreation() );
  177. repoBean.setRetentionCount( repository.getRetentionCount() );
  178. repoBean.setRetentionPeriod( repository.getRetentionPeriod().getDays() );
  179. repoBean.setIndexDirectory( repository.getIndexPath() );
  180. repoBean.setPackedIndexDirectory( repository.getPackedIndexPath() );
  181. repoBean.setLayout( repository.getLayout() );
  182. repoBean.setType( RepositoryType.MAVEN.name( ) );
  183. return repoBean;
  184. }
  185. @Override
  186. public MavenManagedRepository addManagedRepository( MavenManagedRepository managedRepository ) throws ArchivaRestServiceException
  187. {
  188. final String repoId = managedRepository.getId( );
  189. if ( StringUtils.isEmpty( repoId ) ) {
  190. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.REPOSITORY_INVALID_ID, repoId ), 422 );
  191. }
  192. Repository repo = repositoryRegistry.getRepository( repoId );
  193. if (repo!=null) {
  194. httpServletResponse.setHeader( "Location", uriInfo.getAbsolutePathBuilder( ).path( repoId ).build( ).toString( ) );
  195. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.REPOSITORY_ID_EXISTS, repoId ), 303 );
  196. }
  197. try
  198. {
  199. managedRepositoryAdmin.addManagedRepository( convert( managedRepository ), managedRepository.isHasStagingRepository(), getAuditInformation() );
  200. httpServletResponse.setStatus( 201 );
  201. return MavenManagedRepository.of( repositoryRegistry.getManagedRepository( repoId ) );
  202. }
  203. catch ( RepositoryAdminException e )
  204. {
  205. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.REPOSITORY_ADMIN_ERROR, e.getMessage( ) ) );
  206. }
  207. }
  208. @Override
  209. public MavenManagedRepository updateManagedRepository( final String repositoryId, final MavenManagedRepositoryUpdate managedRepository ) throws ArchivaRestServiceException
  210. {
  211. org.apache.archiva.admin.model.beans.ManagedRepository repo = convert( managedRepository );
  212. try
  213. {
  214. managedRepositoryAdmin.updateManagedRepository( repo, managedRepository.isHasStagingRepository( ), getAuditInformation( ), managedRepository.isResetStats( ) );
  215. ManagedRepository newRepo = repositoryRegistry.getManagedRepository( managedRepository.getId( ) );
  216. if (newRepo==null) {
  217. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.REPOSITORY_UPDATE_FAILED, repositoryId ) );
  218. }
  219. return MavenManagedRepository.of( newRepo );
  220. }
  221. catch ( RepositoryAdminException e )
  222. {
  223. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.REPOSITORY_ADMIN_ERROR, e.getMessage( ) ) );
  224. }
  225. }
  226. @Override
  227. public FileInfo getFileStatus( String repositoryId, String fileLocation ) throws ArchivaRestServiceException
  228. {
  229. ManagedRepository repo = repositoryRegistry.getManagedRepository( repositoryId );
  230. if (repo==null) {
  231. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.REPOSITORY_NOT_FOUND, repositoryId ), 404 );
  232. }
  233. try
  234. {
  235. ContentItem contentItem = repo.getContent( ).toItem( fileLocation );
  236. if (contentItem.getAsset( ).exists( )) {
  237. return FileInfo.of( contentItem.getAsset( ) );
  238. } else {
  239. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.ARTIFACT_NOT_FOUND, repositoryId, fileLocation ), 404 );
  240. }
  241. }
  242. catch ( LayoutException e )
  243. {
  244. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.REPOSITORY_LAYOUT_ERROR, e.getMessage( ) ) );
  245. }
  246. }
  247. @Override
  248. public Response copyArtifact( String srcRepositoryId, String dstRepositoryId,
  249. String path ) throws ArchivaRestServiceException
  250. {
  251. final AuditInformation auditInformation = getAuditInformation( );
  252. final String userName = auditInformation.getUser( ).getUsername( );
  253. if ( StringUtils.isEmpty( userName ) )
  254. {
  255. httpServletResponse.setHeader( "WWW-Authenticate", "Bearer realm=\"archiva\"" );
  256. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.NOT_AUTHENTICATED ), 401 );
  257. }
  258. ManagedRepository srcRepo = repositoryRegistry.getManagedRepository( srcRepositoryId );
  259. if (srcRepo==null) {
  260. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.REPOSITORY_NOT_FOUND, srcRepositoryId ), 404 );
  261. }
  262. ManagedRepository dstRepo = repositoryRegistry.getManagedRepository( dstRepositoryId );
  263. if (dstRepo==null) {
  264. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.REPOSITORY_NOT_FOUND, dstRepositoryId ), 404 );
  265. }
  266. checkAuthority( auditInformation.getUser().getUsername(), srcRepositoryId, dstRepositoryId );
  267. try
  268. {
  269. ContentItem srcItem = srcRepo.getContent( ).toItem( path );
  270. ContentItem dstItem = dstRepo.getContent( ).toItem( path );
  271. if (!srcItem.getAsset().exists()){
  272. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.ARTIFACT_NOT_FOUND, srcRepositoryId, path ), 404 );
  273. }
  274. if (dstItem.getAsset().exists()) {
  275. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.ARTIFACT_EXISTS_AT_DEST, srcRepositoryId, path ), 400 );
  276. }
  277. FsStorageUtil.copyAsset( srcItem.getAsset( ), dstItem.getAsset( ), true );
  278. }
  279. catch ( LayoutException e )
  280. {
  281. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.REPOSITORY_LAYOUT_ERROR, e.getMessage() ) );
  282. }
  283. catch ( IOException e )
  284. {
  285. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.ARTIFACT_COPY_ERROR, e.getMessage() ) );
  286. }
  287. return Response.ok( ).build();
  288. }
  289. private void checkAuthority(final String userName, final String srcRepositoryId, final String dstRepositoryId ) throws ArchivaRestServiceException {
  290. User user;
  291. try
  292. {
  293. user = securitySystem.getUserManager().findUser( userName );
  294. }
  295. catch ( UserNotFoundException e )
  296. {
  297. httpServletResponse.setHeader( "WWW-Authenticate", "Bearer realm=\"archiva\"" );
  298. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.USER_NOT_FOUND, userName ), 401 );
  299. }
  300. catch ( UserManagerException e )
  301. {
  302. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.USER_MANAGER_ERROR, e.getMessage( ) ) );
  303. }
  304. // check karma on source : read
  305. AuthenticationResult authn = new AuthenticationResult( true, userName, null );
  306. SecuritySession securitySession = new DefaultSecuritySession( authn, user );
  307. try
  308. {
  309. boolean authz =
  310. securitySystem.isAuthorized( securitySession, OPERATION_READ_REPOSITORY,
  311. srcRepositoryId );
  312. if ( !authz )
  313. {
  314. throw new ArchivaRestServiceException(ErrorMessage.of( ErrorKeys.PERMISSION_REPOSITORY_DENIED, srcRepositoryId, OPERATION_READ_REPOSITORY ), 403);
  315. }
  316. }
  317. catch ( AuthorizationException e )
  318. {
  319. log.error( "Error reading permission: {}", e.getMessage(), e );
  320. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.AUTHORIZATION_ERROR, e.getMessage() ), 403);
  321. }
  322. // check karma on target: write
  323. try
  324. {
  325. boolean authz =
  326. securitySystem.isAuthorized( securitySession, ArchivaRoleConstants.OPERATION_ADD_ARTIFACT,
  327. dstRepositoryId );
  328. if ( !authz )
  329. {
  330. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.PERMISSION_REPOSITORY_DENIED, dstRepositoryId, OPERATION_ADD_ARTIFACT ) );
  331. }
  332. }
  333. catch ( AuthorizationException e )
  334. {
  335. log.error( "Error reading permission: {}", e.getMessage(), e );
  336. throw new ArchivaRestServiceException( ErrorMessage.of( ErrorKeys.AUTHORIZATION_ERROR, e.getMessage() ), 403);
  337. }
  338. }
  339. @Override
  340. public Response deleteArtifact( String repositoryId, String path ) throws ArchivaRestServiceException
  341. {
  342. return null;
  343. }
  344. @Override
  345. public Response removeProjectVersion( String repositoryId, String namespace, String projectId, String version ) throws org.apache.archiva.rest.api.services.ArchivaRestServiceException
  346. {
  347. return null;
  348. }
  349. @Override
  350. public Response deleteProject( String repositoryId, String namespace, String projectId ) throws org.apache.archiva.rest.api.services.ArchivaRestServiceException
  351. {
  352. return null;
  353. }
  354. @Override
  355. public Response deleteNamespace( String repositoryId, String namespace ) throws org.apache.archiva.rest.api.services.ArchivaRestServiceException
  356. {
  357. return null;
  358. }
  359. }