You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

CurrentAction.java 10KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243
  1. /*
  2. * SonarQube
  3. * Copyright (C) 2009-2023 SonarSource SA
  4. * mailto:info AT sonarsource DOT com
  5. *
  6. * This program is free software; you can redistribute it and/or
  7. * modify it under the terms of the GNU Lesser General Public
  8. * License as published by the Free Software Foundation; either
  9. * version 3 of the License, or (at your option) any later version.
  10. *
  11. * This program is distributed in the hope that it will be useful,
  12. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  14. * Lesser General Public License for more details.
  15. *
  16. * You should have received a copy of the GNU Lesser General Public License
  17. * along with this program; if not, write to the Free Software Foundation,
  18. * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
  19. */
  20. package org.sonar.server.user.ws;
  21. import java.util.Collection;
  22. import java.util.List;
  23. import java.util.Optional;
  24. import org.sonar.api.server.ws.Change;
  25. import org.sonar.api.server.ws.Request;
  26. import org.sonar.api.server.ws.Response;
  27. import org.sonar.api.server.ws.WebService.NewController;
  28. import org.sonar.core.platform.EditionProvider;
  29. import org.sonar.core.platform.PlatformEditionProvider;
  30. import org.sonar.db.DbClient;
  31. import org.sonar.db.DbSession;
  32. import org.sonar.db.component.BranchDto;
  33. import org.sonar.db.component.ComponentDto;
  34. import org.sonar.db.permission.GlobalPermission;
  35. import org.sonar.db.project.ProjectDto;
  36. import org.sonar.db.property.PropertyQuery;
  37. import org.sonar.db.user.UserDto;
  38. import org.sonar.server.common.avatar.AvatarResolver;
  39. import org.sonar.server.permission.PermissionService;
  40. import org.sonar.server.user.UserSession;
  41. import org.sonarqube.ws.Users.CurrentWsResponse;
  42. import static com.google.common.base.Preconditions.checkState;
  43. import static com.google.common.base.Strings.emptyToNull;
  44. import static java.util.Collections.singletonList;
  45. import static java.util.Optional.empty;
  46. import static java.util.Optional.of;
  47. import static java.util.Optional.ofNullable;
  48. import static org.apache.commons.lang.StringUtils.EMPTY;
  49. import static org.sonar.api.web.UserRole.USER;
  50. import static org.sonar.server.user.ws.DismissNoticeAction.EDUCATION_PRINCIPLES;
  51. import static org.sonar.server.user.ws.DismissNoticeAction.SONARLINT_AD;
  52. import static org.sonar.server.ws.WsUtils.writeProtobuf;
  53. import static org.sonarqube.ws.Users.CurrentWsResponse.HomepageType.APPLICATION;
  54. import static org.sonarqube.ws.Users.CurrentWsResponse.HomepageType.PORTFOLIO;
  55. import static org.sonarqube.ws.Users.CurrentWsResponse.HomepageType.PROJECT;
  56. import static org.sonarqube.ws.Users.CurrentWsResponse.Permissions;
  57. import static org.sonarqube.ws.Users.CurrentWsResponse.newBuilder;
  58. import static org.sonarqube.ws.client.user.UsersWsParameters.ACTION_CURRENT;
  59. public class CurrentAction implements UsersWsAction {
  60. private final UserSession userSession;
  61. private final DbClient dbClient;
  62. private final AvatarResolver avatarResolver;
  63. private final HomepageTypes homepageTypes;
  64. private final PlatformEditionProvider editionProvider;
  65. private final PermissionService permissionService;
  66. public CurrentAction(UserSession userSession, DbClient dbClient, AvatarResolver avatarResolver, HomepageTypes homepageTypes,
  67. PlatformEditionProvider editionProvider, PermissionService permissionService) {
  68. this.userSession = userSession;
  69. this.dbClient = dbClient;
  70. this.avatarResolver = avatarResolver;
  71. this.homepageTypes = homepageTypes;
  72. this.editionProvider = editionProvider;
  73. this.permissionService = permissionService;
  74. }
  75. @Override
  76. public void define(NewController context) {
  77. context.createAction(ACTION_CURRENT)
  78. .setDescription("Get the details of the current authenticated user.")
  79. .setSince("5.2")
  80. .setInternal(true)
  81. .setHandler(this)
  82. .setResponseExample(getClass().getResource("current-example.json"))
  83. .setChangelog(
  84. new Change("6.5", "showOnboardingTutorial is now returned in the response"),
  85. new Change("7.1", "'parameter' is replaced by 'component' and 'organization' in the response"),
  86. new Change("9.2", "boolean 'usingSonarLintConnectedMode' and 'sonarLintAdSeen' fields are now returned in the response"),
  87. new Change("9.5", "showOnboardingTutorial is not returned anymore in the response"),
  88. new Change("9.6", "'sonarLintAdSeen' is removed and replaced by a 'dismissedNotices' map that support multiple values")
  89. );
  90. }
  91. @Override
  92. public void handle(Request request, Response response) throws Exception {
  93. if (userSession.isLoggedIn()) {
  94. try (DbSession dbSession = dbClient.openSession(false)) {
  95. writeProtobuf(toWsResponse(dbSession, userSession.getLogin()), request, response);
  96. }
  97. } else {
  98. writeProtobuf(newBuilder()
  99. .setIsLoggedIn(false)
  100. .setPermissions(Permissions.newBuilder().addAllGlobal(getGlobalPermissions()).build())
  101. .build(),
  102. request, response);
  103. }
  104. }
  105. private CurrentWsResponse toWsResponse(DbSession dbSession, String userLogin) {
  106. UserDto user = dbClient.userDao().selectActiveUserByLogin(dbSession, userLogin);
  107. checkState(user != null, "User login '%s' cannot be found", userLogin);
  108. Collection<String> groups = dbClient.groupMembershipDao().selectGroupsByLogins(dbSession, singletonList(userLogin)).get(userLogin);
  109. CurrentWsResponse.Builder builder = newBuilder()
  110. .setIsLoggedIn(true)
  111. .setLogin(user.getLogin())
  112. .setName(user.getName())
  113. .setLocal(user.isLocal())
  114. .addAllGroups(groups)
  115. .addAllScmAccounts(user.getSortedScmAccounts())
  116. .setPermissions(Permissions.newBuilder().addAllGlobal(getGlobalPermissions()).build())
  117. .setHomepage(buildHomepage(dbSession, user))
  118. .setUsingSonarLintConnectedMode(user.getLastSonarlintConnectionDate() != null)
  119. .putDismissedNotices(EDUCATION_PRINCIPLES, isNoticeDismissed(user, EDUCATION_PRINCIPLES))
  120. .putDismissedNotices(SONARLINT_AD, isNoticeDismissed(user, SONARLINT_AD));
  121. ofNullable(emptyToNull(user.getEmail())).ifPresent(builder::setEmail);
  122. ofNullable(emptyToNull(user.getEmail())).ifPresent(u -> builder.setAvatar(avatarResolver.create(user)));
  123. ofNullable(user.getExternalLogin()).ifPresent(builder::setExternalIdentity);
  124. ofNullable(user.getExternalIdentityProvider()).ifPresent(builder::setExternalProvider);
  125. return builder.build();
  126. }
  127. private List<String> getGlobalPermissions() {
  128. return permissionService.getGlobalPermissions().stream()
  129. .filter(userSession::hasPermission)
  130. .map(GlobalPermission::getKey)
  131. .toList();
  132. }
  133. private boolean isNoticeDismissed(UserDto user, String noticeName) {
  134. String paramKey = DismissNoticeAction.USER_DISMISS_CONSTANT + noticeName;
  135. PropertyQuery query = new PropertyQuery.Builder()
  136. .setUserUuid(user.getUuid())
  137. .setKey(paramKey)
  138. .build();
  139. try (DbSession dbSession = dbClient.openSession(false)) {
  140. return !dbClient.propertiesDao().selectByQuery(query, dbSession).isEmpty();
  141. }
  142. }
  143. private CurrentWsResponse.Homepage buildHomepage(DbSession dbSession, UserDto user) {
  144. if (noHomepageSet(user)) {
  145. return defaultHomepage();
  146. }
  147. return doBuildHomepage(dbSession, user).orElse(defaultHomepage());
  148. }
  149. private Optional<CurrentWsResponse.Homepage> doBuildHomepage(DbSession dbSession, UserDto user) {
  150. if (PROJECT.toString().equals(user.getHomepageType())) {
  151. return projectHomepage(dbSession, user);
  152. }
  153. if (APPLICATION.toString().equals(user.getHomepageType()) || PORTFOLIO.toString().equals(user.getHomepageType())) {
  154. return applicationAndPortfolioHomepage(dbSession, user);
  155. }
  156. return of(CurrentWsResponse.Homepage.newBuilder()
  157. .setType(CurrentWsResponse.HomepageType.valueOf(user.getHomepageType()))
  158. .build());
  159. }
  160. private Optional<CurrentWsResponse.Homepage> projectHomepage(DbSession dbSession, UserDto user) {
  161. Optional<BranchDto> branchOptional = ofNullable(user.getHomepageParameter()).flatMap(p -> dbClient.branchDao().selectByUuid(dbSession, p));
  162. Optional<ProjectDto> projectOptional = branchOptional.flatMap(b -> dbClient.projectDao().selectByUuid(dbSession, b.getProjectUuid()));
  163. if (shouldCleanProjectHomepage(projectOptional, branchOptional)) {
  164. cleanUserHomepageInDb(dbSession, user);
  165. return empty();
  166. }
  167. CurrentWsResponse.Homepage.Builder homepage = CurrentWsResponse.Homepage.newBuilder()
  168. .setType(CurrentWsResponse.HomepageType.valueOf(user.getHomepageType()))
  169. .setComponent(projectOptional.get().getKey());
  170. if (!branchOptional.get().getProjectUuid().equals(branchOptional.get().getUuid())) {
  171. homepage.setBranch(branchOptional.get().getKey());
  172. }
  173. return of(homepage.build());
  174. }
  175. private boolean shouldCleanProjectHomepage(Optional<ProjectDto> projectOptional, Optional<BranchDto> branchOptional) {
  176. return !projectOptional.isPresent() || !branchOptional.isPresent() || !userSession.hasEntityPermission(USER, projectOptional.get());
  177. }
  178. private Optional<CurrentWsResponse.Homepage> applicationAndPortfolioHomepage(DbSession dbSession, UserDto user) {
  179. Optional<ComponentDto> componentOptional = dbClient.componentDao().selectByUuid(dbSession, of(user.getHomepageParameter()).orElse(EMPTY));
  180. if (shouldCleanApplicationOrPortfolioHomepage(componentOptional)) {
  181. cleanUserHomepageInDb(dbSession, user);
  182. return empty();
  183. }
  184. return of(CurrentWsResponse.Homepage.newBuilder()
  185. .setType(CurrentWsResponse.HomepageType.valueOf(user.getHomepageType()))
  186. .setComponent(componentOptional.get().getKey())
  187. .build());
  188. }
  189. private boolean shouldCleanApplicationOrPortfolioHomepage(Optional<ComponentDto> componentOptional) {
  190. return !componentOptional.isPresent() || !hasValidEdition()
  191. || !userSession.hasComponentPermission(USER, componentOptional.get());
  192. }
  193. private boolean hasValidEdition() {
  194. Optional<EditionProvider.Edition> edition = editionProvider.get();
  195. if (!edition.isPresent()) {
  196. return false;
  197. }
  198. return switch (edition.get()) {
  199. case ENTERPRISE, DATACENTER -> true;
  200. default -> false;
  201. };
  202. }
  203. private void cleanUserHomepageInDb(DbSession dbSession, UserDto user) {
  204. dbClient.userDao().cleanHomepage(dbSession, user);
  205. }
  206. private CurrentWsResponse.Homepage defaultHomepage() {
  207. return CurrentWsResponse.Homepage.newBuilder()
  208. .setType(CurrentWsResponse.HomepageType.valueOf(homepageTypes.getDefaultType().name()))
  209. .build();
  210. }
  211. private static boolean noHomepageSet(UserDto user) {
  212. return user.getHomepageType() == null;
  213. }
  214. }