You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

GitblitUserService.java 8.9KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319
  1. /*
  2. * Copyright 2011 gitblit.com.
  3. *
  4. * Licensed under the Apache License, Version 2.0 (the "License");
  5. * you may not use this file except in compliance with the License.
  6. * You may obtain a copy of the License at
  7. *
  8. * http://www.apache.org/licenses/LICENSE-2.0
  9. *
  10. * Unless required by applicable law or agreed to in writing, software
  11. * distributed under the License is distributed on an "AS IS" BASIS,
  12. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  13. * See the License for the specific language governing permissions and
  14. * limitations under the License.
  15. */
  16. package com.gitblit;
  17. import java.io.File;
  18. import java.io.IOException;
  19. import java.text.MessageFormat;
  20. import java.util.Collection;
  21. import java.util.List;
  22. import org.slf4j.Logger;
  23. import org.slf4j.LoggerFactory;
  24. import com.gitblit.Constants.AccountType;
  25. import com.gitblit.manager.IRuntimeManager;
  26. import com.gitblit.models.TeamModel;
  27. import com.gitblit.models.UserModel;
  28. import com.gitblit.utils.DeepCopier;
  29. import com.gitblit.utils.StringUtils;
  30. /**
  31. * This class wraps the default user service and is recommended as the starting
  32. * point for custom user service implementations.
  33. *
  34. * This does seem a little convoluted, but the idea is to allow IUserService to
  35. * evolve with new methods and implementations without breaking custom
  36. * authentication implementations.
  37. *
  38. * The most common implementation of a custom IUserService is to only override
  39. * authentication and then delegate all other functionality to one of Gitblit's
  40. * user services. This class optimizes that use-case.
  41. *
  42. * Extending GitblitUserService allows for authentication customization without
  43. * having to keep-up-with IUSerService API changes.
  44. *
  45. * @author James Moger
  46. *
  47. */
  48. public class GitblitUserService implements IUserService {
  49. protected IUserService serviceImpl;
  50. private final Logger logger = LoggerFactory.getLogger(GitblitUserService.class);
  51. public GitblitUserService() {
  52. }
  53. @Override
  54. public void setup(IStoredSettings settings) {
  55. IRuntimeManager runtimeManager = GitBlit.getManager(IRuntimeManager.class);
  56. File realmFile = runtimeManager.getFileOrFolder(Keys.realm.userService, "${baseFolder}/users.conf");
  57. serviceImpl = createUserService(realmFile);
  58. logger.info("GUS delegating to " + serviceImpl.toString());
  59. }
  60. protected IUserService createUserService(File realmFile) {
  61. IUserService service = null;
  62. if (realmFile.getName().toLowerCase().endsWith(".conf")) {
  63. // v0.8.0+ config-based realm file
  64. service = new ConfigUserService(realmFile);
  65. }
  66. assert service != null;
  67. if (!realmFile.exists()) {
  68. // Create the Administrator account for a new realm file
  69. try {
  70. realmFile.createNewFile();
  71. } catch (IOException x) {
  72. logger.error(MessageFormat.format("COULD NOT CREATE REALM FILE {0}!", realmFile), x);
  73. }
  74. UserModel admin = new UserModel("admin");
  75. admin.password = "admin";
  76. admin.canAdmin = true;
  77. admin.excludeFromFederation = true;
  78. service.updateUserModel(admin);
  79. }
  80. return service;
  81. }
  82. @Override
  83. public String toString() {
  84. return getClass().getSimpleName();
  85. }
  86. @Override
  87. public boolean supportsCredentialChanges() {
  88. return serviceImpl.supportsCredentialChanges();
  89. }
  90. @Override
  91. public boolean supportsDisplayNameChanges() {
  92. return serviceImpl.supportsDisplayNameChanges();
  93. }
  94. @Override
  95. public boolean supportsEmailAddressChanges() {
  96. return serviceImpl.supportsEmailAddressChanges();
  97. }
  98. @Override
  99. public boolean supportsTeamMembershipChanges() {
  100. return serviceImpl.supportsTeamMembershipChanges();
  101. }
  102. @Override
  103. public boolean supportsCookies() {
  104. return serviceImpl.supportsCookies();
  105. }
  106. @Override
  107. public String getCookie(UserModel model) {
  108. return serviceImpl.getCookie(model);
  109. }
  110. @Override
  111. public UserModel authenticate(char[] cookie) {
  112. UserModel user = serviceImpl.authenticate(cookie);
  113. setAccountType(user);
  114. return user;
  115. }
  116. @Override
  117. public UserModel authenticate(String username, char[] password) {
  118. UserModel user = serviceImpl.authenticate(username, password);
  119. setAccountType(user);
  120. return user;
  121. }
  122. @Override
  123. public void logout(UserModel user) {
  124. serviceImpl.logout(user);
  125. }
  126. @Override
  127. public UserModel getUserModel(String username) {
  128. UserModel user = serviceImpl.getUserModel(username);
  129. setAccountType(user);
  130. return user;
  131. }
  132. @Override
  133. public boolean updateUserModel(UserModel model) {
  134. return serviceImpl.updateUserModel(model);
  135. }
  136. @Override
  137. public boolean updateUserModels(Collection<UserModel> models) {
  138. return serviceImpl.updateUserModels(models);
  139. }
  140. @Override
  141. public boolean updateUserModel(String username, UserModel model) {
  142. if (model.isLocalAccount() || supportsCredentialChanges()) {
  143. if (!model.isLocalAccount() && !supportsTeamMembershipChanges()) {
  144. // teams are externally controlled - copy from original model
  145. UserModel existingModel = getUserModel(username);
  146. model = DeepCopier.copy(model);
  147. model.teams.clear();
  148. model.teams.addAll(existingModel.teams);
  149. }
  150. return serviceImpl.updateUserModel(username, model);
  151. }
  152. if (model.username.equals(username)) {
  153. // passwords are not persisted by the backing user service
  154. model.password = null;
  155. if (!model.isLocalAccount() && !supportsTeamMembershipChanges()) {
  156. // teams are externally controlled- copy from original model
  157. UserModel existingModel = getUserModel(username);
  158. model = DeepCopier.copy(model);
  159. model.teams.clear();
  160. model.teams.addAll(existingModel.teams);
  161. }
  162. return serviceImpl.updateUserModel(username, model);
  163. }
  164. logger.error("Users can not be renamed!");
  165. return false;
  166. }
  167. @Override
  168. public boolean deleteUserModel(UserModel model) {
  169. return serviceImpl.deleteUserModel(model);
  170. }
  171. @Override
  172. public boolean deleteUser(String username) {
  173. return serviceImpl.deleteUser(username);
  174. }
  175. @Override
  176. public List<String> getAllUsernames() {
  177. return serviceImpl.getAllUsernames();
  178. }
  179. @Override
  180. public List<UserModel> getAllUsers() {
  181. List<UserModel> users = serviceImpl.getAllUsers();
  182. for (UserModel user : users) {
  183. setAccountType(user);
  184. }
  185. return users;
  186. }
  187. @Override
  188. public List<String> getAllTeamNames() {
  189. return serviceImpl.getAllTeamNames();
  190. }
  191. @Override
  192. public List<TeamModel> getAllTeams() {
  193. return serviceImpl.getAllTeams();
  194. }
  195. @Override
  196. public List<String> getTeamnamesForRepositoryRole(String role) {
  197. return serviceImpl.getTeamnamesForRepositoryRole(role);
  198. }
  199. @Override
  200. @Deprecated
  201. public boolean setTeamnamesForRepositoryRole(String role, List<String> teamnames) {
  202. return serviceImpl.setTeamnamesForRepositoryRole(role, teamnames);
  203. }
  204. @Override
  205. public TeamModel getTeamModel(String teamname) {
  206. return serviceImpl.getTeamModel(teamname);
  207. }
  208. @Override
  209. public boolean updateTeamModel(TeamModel model) {
  210. return serviceImpl.updateTeamModel(model);
  211. }
  212. @Override
  213. public boolean updateTeamModels(Collection<TeamModel> models) {
  214. return serviceImpl.updateTeamModels(models);
  215. }
  216. @Override
  217. public boolean updateTeamModel(String teamname, TeamModel model) {
  218. if (!supportsTeamMembershipChanges()) {
  219. // teams are externally controlled - copy from original model
  220. TeamModel existingModel = getTeamModel(teamname);
  221. model = DeepCopier.copy(model);
  222. model.users.clear();
  223. model.users.addAll(existingModel.users);
  224. }
  225. return serviceImpl.updateTeamModel(teamname, model);
  226. }
  227. @Override
  228. public boolean deleteTeamModel(TeamModel model) {
  229. return serviceImpl.deleteTeamModel(model);
  230. }
  231. @Override
  232. public boolean deleteTeam(String teamname) {
  233. return serviceImpl.deleteTeam(teamname);
  234. }
  235. @Override
  236. public List<String> getUsernamesForRepositoryRole(String role) {
  237. return serviceImpl.getUsernamesForRepositoryRole(role);
  238. }
  239. @Override
  240. @Deprecated
  241. public boolean setUsernamesForRepositoryRole(String role, List<String> usernames) {
  242. return serviceImpl.setUsernamesForRepositoryRole(role, usernames);
  243. }
  244. @Override
  245. public boolean renameRepositoryRole(String oldRole, String newRole) {
  246. return serviceImpl.renameRepositoryRole(oldRole, newRole);
  247. }
  248. @Override
  249. public boolean deleteRepositoryRole(String role) {
  250. return serviceImpl.deleteRepositoryRole(role);
  251. }
  252. protected boolean isLocalAccount(String username) {
  253. UserModel user = getUserModel(username);
  254. return user != null && user.isLocalAccount();
  255. }
  256. protected void setAccountType(UserModel user) {
  257. if (user != null) {
  258. if (!StringUtils.isEmpty(user.password)
  259. && !Constants.EXTERNAL_ACCOUNT.equalsIgnoreCase(user.password)
  260. && !"StoredInLDAP".equalsIgnoreCase(user.password)) {
  261. user.accountType = AccountType.LOCAL;
  262. } else {
  263. user.accountType = getAccountType();
  264. }
  265. }
  266. }
  267. protected AccountType getAccountType() {
  268. return AccountType.LOCAL;
  269. }
  270. }