You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

GitblitUserService.java 8.9KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325
  1. /*
  2. * Copyright 2011 gitblit.com.
  3. *
  4. * Licensed under the Apache License, Version 2.0 (the "License");
  5. * you may not use this file except in compliance with the License.
  6. * You may obtain a copy of the License at
  7. *
  8. * http://www.apache.org/licenses/LICENSE-2.0
  9. *
  10. * Unless required by applicable law or agreed to in writing, software
  11. * distributed under the License is distributed on an "AS IS" BASIS,
  12. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  13. * See the License for the specific language governing permissions and
  14. * limitations under the License.
  15. */
  16. package com.gitblit;
  17. import java.io.File;
  18. import java.io.IOException;
  19. import java.text.MessageFormat;
  20. import java.util.Collection;
  21. import java.util.List;
  22. import org.slf4j.Logger;
  23. import org.slf4j.LoggerFactory;
  24. import com.gitblit.Constants.AccountType;
  25. import com.gitblit.manager.IRuntimeManager;
  26. import com.gitblit.models.TeamModel;
  27. import com.gitblit.models.UserModel;
  28. import com.gitblit.utils.DeepCopier;
  29. import com.gitblit.utils.StringUtils;
  30. /**
  31. * This class wraps the default user service and is recommended as the starting
  32. * point for custom user service implementations.
  33. *
  34. * This does seem a little convoluted, but the idea is to allow IUserService to
  35. * evolve with new methods and implementations without breaking custom
  36. * authentication implementations.
  37. *
  38. * The most common implementation of a custom IUserService is to only override
  39. * authentication and then delegate all other functionality to one of Gitblit's
  40. * user services. This class optimizes that use-case.
  41. *
  42. * Extending GitblitUserService allows for authentication customization without
  43. * having to keep-up-with IUSerService API changes.
  44. *
  45. * @author James Moger
  46. *
  47. */
  48. public class GitblitUserService implements IUserService {
  49. protected IUserService serviceImpl;
  50. private final Logger logger = LoggerFactory.getLogger(GitblitUserService.class);
  51. public GitblitUserService() {
  52. }
  53. @Override
  54. public void setup(IRuntimeManager runtimeManager) {
  55. File realmFile = runtimeManager.getFileOrFolder(Keys.realm.userService, "${baseFolder}/users.conf");
  56. serviceImpl = createUserService(realmFile);
  57. logger.info("GUS delegating to " + serviceImpl.toString());
  58. }
  59. protected IUserService createUserService(File realmFile) {
  60. IUserService service = null;
  61. if (realmFile.getName().toLowerCase().endsWith(".conf")) {
  62. // v0.8.0+ config-based realm file
  63. service = new ConfigUserService(realmFile);
  64. }
  65. assert service != null;
  66. if (!realmFile.exists()) {
  67. // Create the Administrator account for a new realm file
  68. try {
  69. realmFile.createNewFile();
  70. } catch (IOException x) {
  71. logger.error(MessageFormat.format("COULD NOT CREATE REALM FILE {0}!", realmFile), x);
  72. }
  73. UserModel admin = new UserModel("admin");
  74. admin.password = "admin";
  75. admin.canAdmin = true;
  76. admin.excludeFromFederation = true;
  77. service.updateUserModel(admin);
  78. }
  79. return service;
  80. }
  81. @Override
  82. public String toString() {
  83. return getClass().getSimpleName();
  84. }
  85. @Override
  86. public boolean supportsCredentialChanges() {
  87. return serviceImpl.supportsCredentialChanges();
  88. }
  89. @Override
  90. public boolean supportsDisplayNameChanges() {
  91. return serviceImpl.supportsDisplayNameChanges();
  92. }
  93. @Override
  94. public boolean supportsEmailAddressChanges() {
  95. return serviceImpl.supportsEmailAddressChanges();
  96. }
  97. @Override
  98. public boolean supportsTeamMembershipChanges() {
  99. return serviceImpl.supportsTeamMembershipChanges();
  100. }
  101. @Override
  102. public boolean supportsCookies() {
  103. return serviceImpl.supportsCookies();
  104. }
  105. @Override
  106. public String getCookie(UserModel model) {
  107. return serviceImpl.getCookie(model);
  108. }
  109. /**
  110. * Authenticate a user based on their cookie.
  111. *
  112. * @param cookie
  113. * @return a user object or null
  114. */
  115. @Override
  116. public UserModel authenticate(char[] cookie) {
  117. UserModel user = serviceImpl.authenticate(cookie);
  118. setAccountType(user);
  119. return user;
  120. }
  121. @Override
  122. public UserModel authenticate(String username, char[] password) {
  123. UserModel user = serviceImpl.authenticate(username, password);
  124. setAccountType(user);
  125. return user;
  126. }
  127. @Override
  128. public void logout(UserModel user) {
  129. serviceImpl.logout(user);
  130. }
  131. @Override
  132. public UserModel getUserModel(String username) {
  133. UserModel user = serviceImpl.getUserModel(username);
  134. setAccountType(user);
  135. return user;
  136. }
  137. @Override
  138. public boolean updateUserModel(UserModel model) {
  139. return serviceImpl.updateUserModel(model);
  140. }
  141. @Override
  142. public boolean updateUserModels(Collection<UserModel> models) {
  143. return serviceImpl.updateUserModels(models);
  144. }
  145. @Override
  146. public boolean updateUserModel(String username, UserModel model) {
  147. if (model.isLocalAccount() || supportsCredentialChanges()) {
  148. if (!model.isLocalAccount() && !supportsTeamMembershipChanges()) {
  149. // teams are externally controlled - copy from original model
  150. UserModel existingModel = getUserModel(username);
  151. model = DeepCopier.copy(model);
  152. model.teams.clear();
  153. model.teams.addAll(existingModel.teams);
  154. }
  155. return serviceImpl.updateUserModel(username, model);
  156. }
  157. if (model.username.equals(username)) {
  158. // passwords are not persisted by the backing user service
  159. model.password = null;
  160. if (!model.isLocalAccount() && !supportsTeamMembershipChanges()) {
  161. // teams are externally controlled- copy from original model
  162. UserModel existingModel = getUserModel(username);
  163. model = DeepCopier.copy(model);
  164. model.teams.clear();
  165. model.teams.addAll(existingModel.teams);
  166. }
  167. return serviceImpl.updateUserModel(username, model);
  168. }
  169. logger.error("Users can not be renamed!");
  170. return false;
  171. }
  172. @Override
  173. public boolean deleteUserModel(UserModel model) {
  174. return serviceImpl.deleteUserModel(model);
  175. }
  176. @Override
  177. public boolean deleteUser(String username) {
  178. return serviceImpl.deleteUser(username);
  179. }
  180. @Override
  181. public List<String> getAllUsernames() {
  182. return serviceImpl.getAllUsernames();
  183. }
  184. @Override
  185. public List<UserModel> getAllUsers() {
  186. List<UserModel> users = serviceImpl.getAllUsers();
  187. for (UserModel user : users) {
  188. setAccountType(user);
  189. }
  190. return users;
  191. }
  192. @Override
  193. public List<String> getAllTeamNames() {
  194. return serviceImpl.getAllTeamNames();
  195. }
  196. @Override
  197. public List<TeamModel> getAllTeams() {
  198. return serviceImpl.getAllTeams();
  199. }
  200. @Override
  201. public List<String> getTeamNamesForRepositoryRole(String role) {
  202. return serviceImpl.getTeamNamesForRepositoryRole(role);
  203. }
  204. @Override
  205. @Deprecated
  206. public boolean setTeamnamesForRepositoryRole(String role, List<String> teamnames) {
  207. return serviceImpl.setTeamnamesForRepositoryRole(role, teamnames);
  208. }
  209. @Override
  210. public TeamModel getTeamModel(String teamname) {
  211. return serviceImpl.getTeamModel(teamname);
  212. }
  213. @Override
  214. public boolean updateTeamModel(TeamModel model) {
  215. return serviceImpl.updateTeamModel(model);
  216. }
  217. @Override
  218. public boolean updateTeamModels(Collection<TeamModel> models) {
  219. return serviceImpl.updateTeamModels(models);
  220. }
  221. @Override
  222. public boolean updateTeamModel(String teamname, TeamModel model) {
  223. if (!supportsTeamMembershipChanges()) {
  224. // teams are externally controlled - copy from original model
  225. TeamModel existingModel = getTeamModel(teamname);
  226. model = DeepCopier.copy(model);
  227. model.users.clear();
  228. model.users.addAll(existingModel.users);
  229. }
  230. return serviceImpl.updateTeamModel(teamname, model);
  231. }
  232. @Override
  233. public boolean deleteTeamModel(TeamModel model) {
  234. return serviceImpl.deleteTeamModel(model);
  235. }
  236. @Override
  237. public boolean deleteTeam(String teamname) {
  238. return serviceImpl.deleteTeam(teamname);
  239. }
  240. @Override
  241. public List<String> getUsernamesForRepositoryRole(String role) {
  242. return serviceImpl.getUsernamesForRepositoryRole(role);
  243. }
  244. @Override
  245. @Deprecated
  246. public boolean setUsernamesForRepositoryRole(String role, List<String> usernames) {
  247. return serviceImpl.setUsernamesForRepositoryRole(role, usernames);
  248. }
  249. @Override
  250. public boolean renameRepositoryRole(String oldRole, String newRole) {
  251. return serviceImpl.renameRepositoryRole(oldRole, newRole);
  252. }
  253. @Override
  254. public boolean deleteRepositoryRole(String role) {
  255. return serviceImpl.deleteRepositoryRole(role);
  256. }
  257. protected boolean isLocalAccount(String username) {
  258. UserModel user = getUserModel(username);
  259. return user != null && user.isLocalAccount();
  260. }
  261. protected void setAccountType(UserModel user) {
  262. if (user != null) {
  263. if (!StringUtils.isEmpty(user.password)
  264. && !Constants.EXTERNAL_ACCOUNT.equalsIgnoreCase(user.password)
  265. && !"StoredInLDAP".equalsIgnoreCase(user.password)) {
  266. user.accountType = AccountType.LOCAL;
  267. } else {
  268. user.accountType = getAccountType();
  269. }
  270. }
  271. }
  272. @Override
  273. public AccountType getAccountType() {
  274. return AccountType.LOCAL;
  275. }
  276. }