Class DefaultSubscriptionAccessValidationService
- All Implemented Interfaces:
SubscriptionAccessValidationService
SubscriptionAccessValidationService- Author:
- karanjariwala
-
Field Summary
Fields -
Constructor Summary
ConstructorsConstructorDescriptionDefaultSubscriptionAccessValidationService(com.broadleafcommerce.resource.security.utils.service.AuthenticationUtils authenticationUtils) -
Method Summary
Modifier and TypeMethodDescriptionexpandPermissionRootsToPermissions(@NonNull String[] permissionRoots, com.broadleafcommerce.data.tracking.core.type.OperationType operationType) Constructs a map of<permissionRoot, [possiblePermissions]>for all thepermissionRootpassed into the permissionRoots for the given OperationType.<SWI extends SubscriptionWithItems>
Collection<SWI>getAccessibleSubscriptions(@NonNull String[] permissionRoots, @NonNull Collection<SWI> subscriptionWithItems, com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo) Filters aCollectionof thesubscriptionWithItemsand returns those subscriptions that are accessible to the current user (customer or account).<SWI extends SubscriptionWithItems>
org.springframework.data.domain.Page<SWI>getAccessibleSubscriptions(@NonNull String[] permissionRoots, @NonNull org.springframework.data.domain.Page<SWI> subscriptionWithItems, com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo) Filters aPageof thesubscriptionWithItemsand returns those subscriptions that are accessible to the current user (customer or account).protected com.broadleafcommerce.resource.security.utils.service.AuthenticationUtilsgetRestrictedTargets(@NonNull String[] permissionRoots, com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo) Gets aSetofsubscriptionIDsthat the currently authenticated user is allowed to access if the user has restricted authorities with the restriction type of"SUBSCRIPTION".protected com.broadleafcommerce.data.tracking.core.policy.trackable.TrackablePolicyUtilsvoidsetTrackablePolicyUtils(com.broadleafcommerce.data.tracking.core.policy.trackable.TrackablePolicyUtils trackablePolicyUtils) voidvalidateAccess(@NonNull String[] permissionRoots, @NonNull String subscriptionId, com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo) Validates whether the current user is restricted to certain subscriptions only.protected voidvalidateUserPermissions(@NonNull String[] permissionRoots, com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo) Validates whether the current user has the exact permission based onContextInfo.getOperationType()to perform the operation.
-
Field Details
-
SUBSCRIPTION_RESTRICTION_TYPE
- See Also:
-
-
Constructor Details
-
DefaultSubscriptionAccessValidationService
public DefaultSubscriptionAccessValidationService(com.broadleafcommerce.resource.security.utils.service.AuthenticationUtils authenticationUtils)
-
-
Method Details
-
validateAccess
public void validateAccess(@NonNull @NonNull String[] permissionRoots, @NonNull @NonNull String subscriptionId, @Nullable com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo) Description copied from interface:SubscriptionAccessValidationServiceValidates whether the current user is restricted to certain subscriptions only. And if restricted, validates that the user is allowed to access the givensubscriptionId.- Specified by:
validateAccessin interfaceSubscriptionAccessValidationService- Parameters:
permissionRoots- the permissionRoots that the user's access is to be checked forsubscriptionId- the subscription whose access is to be checkedcontextInfo- the context information around multi-tenant state
-
getAccessibleSubscriptions
public <SWI extends SubscriptionWithItems> Collection<SWI> getAccessibleSubscriptions(@NonNull @NonNull String[] permissionRoots, @NonNull @NonNull Collection<SWI> subscriptionWithItems, @Nullable com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo) Description copied from interface:SubscriptionAccessValidationServiceFilters aCollectionof thesubscriptionWithItemsand returns those subscriptions that are accessible to the current user (customer or account).- Specified by:
getAccessibleSubscriptionsin interfaceSubscriptionAccessValidationService- Parameters:
permissionRoots- the permissionRoots that the user's access is to be checked forsubscriptionWithItems- the collection of subscriptions to be filteredcontextInfo- the context information around multi-tenant state- Returns:
- a
CollectionofSubscriptionWithItemsthat the current user can access
-
getAccessibleSubscriptions
public <SWI extends SubscriptionWithItems> org.springframework.data.domain.Page<SWI> getAccessibleSubscriptions(@NonNull @NonNull String[] permissionRoots, @NonNull @NonNull org.springframework.data.domain.Page<SWI> subscriptionWithItems, @Nullable com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo) Description copied from interface:SubscriptionAccessValidationServiceFilters aPageof thesubscriptionWithItemsand returns those subscriptions that are accessible to the current user (customer or account).- Specified by:
getAccessibleSubscriptionsin interfaceSubscriptionAccessValidationService- Parameters:
permissionRoots- the permissionRoots that the user's access is to be checked forsubscriptionWithItems- the page of subscriptions to be filteredcontextInfo- the context information around multi-tenant state- Returns:
- a
PageofSubscriptionWithItemsthat the current user can access
-
validateUserPermissions
protected void validateUserPermissions(@NonNull @NonNull String[] permissionRoots, @Nullable com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo) Validates whether the current user has the exact permission based onContextInfo.getOperationType()to perform the operation. Internally it relies onTrackablePolicyUtils.validatePermission(ContextInfo, String[], PermissionMatchingStrategy)for validating the permissions. It uses thePermissionMatchingStrategy.ANYto checks the permissions.If the policyResponse is not
PolicyResponse.VALID, aNotPermittedExceptionis thrown.- Parameters:
permissionRoots- the main permissionRoots that the user's access is to be checked forcontextInfo- the context info
-
getRestrictedTargets
protected Set<String> getRestrictedTargets(@NonNull @NonNull String[] permissionRoots, @Nullable com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo) Gets aSetofsubscriptionIDsthat the currently authenticated user is allowed to access if the user has restricted authorities with the restriction type of"SUBSCRIPTION".If the user has no restricted authorities with the restriction type of
"SUBSCRIPTION", they can access any subscription.Currently, the subscriptions are matched according to the
PermissionMatchingStrategy.ANYstrategy in that if a user has restricted authorities like "READ_ACCOUNT_SUBSCRIPTION" -> "SUBSCRIPTION" -> [sub1, sub2, sub7], "READ_SUBSCRIPTION" -> "SUBSCRIPTION" -> [sub3, sub7] and the endpoint hasPolicypermission roots of ["ACCOUNT_SUBSCRIPTION", "SUBSCRIPTION"] withREADOperationTypethen the result of this method will have [sub1, sub2, sub3, sub7] as the restricted targets and allow the user to access to all 4 subscriptions.- Parameters:
permissionRoots- the main permissionRoots that the user's access is to be checked forcontextInfo- the context info- Returns:
- a
Setof subscriptionIds the current user can access. Returns an empty set if there are no restrictions.
-
expandPermissionRootsToPermissions
protected Map<String,List<String>> expandPermissionRootsToPermissions(@NonNull @NonNull String[] permissionRoots, @Nullable com.broadleafcommerce.data.tracking.core.type.OperationType operationType) Constructs a map of<permissionRoot, [possiblePermissions]>for all thepermissionRootpassed into the permissionRoots for the given OperationType.- Parameters:
permissionRoots- the permissionRoots for which the permissions are to be createdoperationType- the current operation being performed- Returns:
- a map of permissionRoot and its possible permissions
-
getAuthenticationUtils
protected com.broadleafcommerce.resource.security.utils.service.AuthenticationUtils getAuthenticationUtils() -
getTrackablePolicyUtils
@Nullable protected com.broadleafcommerce.data.tracking.core.policy.trackable.TrackablePolicyUtils getTrackablePolicyUtils() -
setTrackablePolicyUtils
@Autowired(required=false) public void setTrackablePolicyUtils(com.broadleafcommerce.data.tracking.core.policy.trackable.TrackablePolicyUtils trackablePolicyUtils)
-