You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

PermissionFinder.java 8.3KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218
  1. /*
  2. * SonarQube, open source software quality management tool.
  3. * Copyright (C) 2008-2014 SonarSource
  4. * mailto:contact AT sonarsource DOT com
  5. *
  6. * SonarQube is free software; you can redistribute it and/or
  7. * modify it under the terms of the GNU Lesser General Public
  8. * License as published by the Free Software Foundation; either
  9. * version 3 of the License, or (at your option) any later version.
  10. *
  11. * SonarQube is distributed in the hope that it will be useful,
  12. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  14. * Lesser General Public License for more details.
  15. *
  16. * You should have received a copy of the GNU Lesser General Public License
  17. * along with this program; if not, write to the Free Software Foundation,
  18. * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
  19. */
  20. package org.sonar.server.permission;
  21. import com.google.common.base.Predicate;
  22. import com.google.common.collect.Iterables;
  23. import java.util.Collection;
  24. import java.util.List;
  25. import javax.annotation.Nonnull;
  26. import javax.annotation.Nullable;
  27. import org.apache.commons.lang.StringUtils;
  28. import org.sonar.api.security.DefaultGroups;
  29. import org.sonar.api.server.ServerSide;
  30. import org.sonar.api.utils.Paging;
  31. import org.sonar.core.permission.GroupWithPermission;
  32. import org.sonar.core.permission.UserWithPermission;
  33. import org.sonar.db.DbClient;
  34. import org.sonar.db.DbSession;
  35. import org.sonar.db.component.ResourceDao;
  36. import org.sonar.db.component.ResourceDto;
  37. import org.sonar.db.component.ResourceQuery;
  38. import org.sonar.db.permission.GroupWithPermissionDto;
  39. import org.sonar.db.permission.PermissionDao;
  40. import org.sonar.db.permission.PermissionQuery;
  41. import org.sonar.db.permission.PermissionTemplateDao;
  42. import org.sonar.db.permission.PermissionTemplateDto;
  43. import org.sonar.db.permission.UserWithPermissionDto;
  44. import org.sonar.server.exceptions.NotFoundException;
  45. import static com.google.common.collect.Lists.newArrayList;
  46. @ServerSide
  47. public class PermissionFinder {
  48. private final DbClient dbClient;
  49. private final PermissionDao permissionDao;
  50. private final ResourceDao resourceDao;
  51. private final PermissionTemplateDao permissionTemplateDao;
  52. public PermissionFinder(DbClient dbClient) {
  53. this.dbClient = dbClient;
  54. this.resourceDao = dbClient.resourceDao();
  55. this.permissionDao = dbClient.permissionDao();
  56. this.permissionTemplateDao = dbClient.permissionTemplateDao();
  57. }
  58. public UserWithPermissionQueryResult findUsersWithPermission(PermissionQuery query) {
  59. Long componentId = componentId(query.component());
  60. int limit = query.pageSize();
  61. DbSession dbSession = dbClient.openSession(false);
  62. try {
  63. int total = permissionDao.countUsers(dbSession, query, componentId);
  64. return toUserQueryResult(permissionDao.selectUsers(dbSession, query, componentId, offset(query), limit), total);
  65. } finally {
  66. dbClient.closeSession(dbSession);
  67. }
  68. }
  69. public UserWithPermissionQueryResult findUsersWithPermissionTemplate(PermissionQuery query) {
  70. Long permissionTemplateId = templateId(query.template());
  71. int limit = query.pageSize();
  72. DbSession dbSession = dbClient.openSession(false);
  73. try {
  74. int total = permissionTemplateDao.countUsers(dbSession, query, permissionTemplateId);
  75. return toUserQueryResult(permissionTemplateDao.selectUsers(dbSession, query, permissionTemplateId, offset(query), limit), total);
  76. } finally {
  77. dbClient.closeSession(dbSession);
  78. }
  79. }
  80. /**
  81. * Paging for groups search is done in Java in order to correctly handle the 'Anyone' group
  82. */
  83. public GroupWithPermissionQueryResult findGroupsWithPermission(PermissionQuery query) {
  84. Long componentId = componentId(query.component());
  85. DbSession dbSession = dbClient.openSession(false);
  86. try {
  87. return toGroupQueryResult(permissionDao.selectGroups(dbSession, query, componentId), query);
  88. } finally {
  89. dbClient.closeSession(dbSession);
  90. }
  91. }
  92. /**
  93. * Paging for groups search is done in Java in order to correctly handle the 'Anyone' group
  94. */
  95. public GroupWithPermissionQueryResult findGroupsWithPermissionTemplate(PermissionQuery query) {
  96. Long permissionTemplateId = templateId(query.template());
  97. DbSession dbSession = dbClient.openSession(false);
  98. try {
  99. return toGroupQueryResult(permissionTemplateDao.selectGroups(dbSession, query, permissionTemplateId), query);
  100. } finally {
  101. dbClient.closeSession(dbSession);
  102. }
  103. }
  104. private static UserWithPermissionQueryResult toUserQueryResult(List<UserWithPermissionDto> dtos, int total) {
  105. return new UserWithPermissionQueryResult(toUserWithPermissionList(dtos), total);
  106. }
  107. private static List<UserWithPermission> toUserWithPermissionList(List<UserWithPermissionDto> dtos) {
  108. List<UserWithPermission> users = newArrayList();
  109. for (UserWithPermissionDto dto : dtos) {
  110. users.add(dto.toUserWithPermission());
  111. }
  112. return users;
  113. }
  114. @Nullable
  115. private Long componentId(@Nullable String componentKey) {
  116. if (componentKey == null) {
  117. return null;
  118. } else {
  119. ResourceDto resourceDto = resourceDao.selectResource(ResourceQuery.create().setKey(componentKey));
  120. if (resourceDto == null) {
  121. throw new NotFoundException(String.format("Component '%s' does not exist", componentKey));
  122. }
  123. return resourceDto.getId();
  124. }
  125. }
  126. private GroupWithPermissionQueryResult toGroupQueryResult(List<GroupWithPermissionDto> dtos, PermissionQuery query) {
  127. addAnyoneGroup(dtos, query);
  128. List<GroupWithPermissionDto> filteredDtos = filterMembership(dtos, query);
  129. Paging paging = Paging.create(query.pageSize(), query.pageIndex(), filteredDtos.size());
  130. List<GroupWithPermission> pagedGroups = pagedGroups(filteredDtos, paging);
  131. return new GroupWithPermissionQueryResult(pagedGroups, filteredDtos.size());
  132. }
  133. private Long templateId(String templateKey) {
  134. PermissionTemplateDto dto = permissionTemplateDao.selectTemplateByKey(templateKey);
  135. if (dto == null) {
  136. throw new NotFoundException(String.format("Template '%s' does not exist", templateKey));
  137. }
  138. return dto.getId();
  139. }
  140. private static int offset(PermissionQuery query) {
  141. int pageSize = query.pageSize();
  142. int pageIndex = query.pageIndex();
  143. return (pageIndex - 1) * pageSize;
  144. }
  145. private List<GroupWithPermissionDto> filterMembership(List<GroupWithPermissionDto> dtos, PermissionQuery query) {
  146. return newArrayList(Iterables.filter(dtos, new GroupWithPermissionMatchQuery(query)));
  147. }
  148. /**
  149. * As the anyone group does not exists in db, it's not returned when it has not the permission.
  150. * We have to manually add it at the begin of the list, if it matched the search text
  151. */
  152. private void addAnyoneGroup(List<GroupWithPermissionDto> groups, PermissionQuery query) {
  153. boolean hasAnyoneGroup = Iterables.any(groups, IsAnyoneGroup.INSTANCE);
  154. if (!hasAnyoneGroup && (query.search() == null || StringUtils.containsIgnoreCase(DefaultGroups.ANYONE, query.search()))) {
  155. groups.add(0, new GroupWithPermissionDto().setName(DefaultGroups.ANYONE));
  156. }
  157. }
  158. private static List<GroupWithPermission> pagedGroups(Collection<GroupWithPermissionDto> dtos, Paging paging) {
  159. List<GroupWithPermission> groups = newArrayList();
  160. int index = 0;
  161. for (GroupWithPermissionDto dto : dtos) {
  162. if (index >= paging.offset() && groups.size() < paging.pageSize()) {
  163. groups.add(dto.toGroupWithPermission());
  164. } else if (groups.size() >= paging.pageSize()) {
  165. break;
  166. }
  167. index++;
  168. }
  169. return groups;
  170. }
  171. private static class GroupWithPermissionMatchQuery implements Predicate<GroupWithPermissionDto> {
  172. private final PermissionQuery query;
  173. public GroupWithPermissionMatchQuery(PermissionQuery query) {
  174. this.query = query;
  175. }
  176. @Override
  177. public boolean apply(@Nonnull GroupWithPermissionDto dto) {
  178. if (PermissionQuery.IN.equals(query.membership())) {
  179. return dto.getPermission() != null;
  180. } else if (PermissionQuery.OUT.equals(query.membership())) {
  181. return dto.getPermission() == null;
  182. }
  183. return true;
  184. }
  185. }
  186. private enum IsAnyoneGroup implements Predicate<GroupWithPermissionDto> {
  187. INSTANCE;
  188. @Override
  189. public boolean apply(@Nonnull GroupWithPermissionDto group) {
  190. return group.getName().equals(DefaultGroups.ANYONE);
  191. }
  192. }
  193. }