Class DefaultSubscriptionAccessValidationService

java.lang.Object
com.broadleafcommerce.subscriptionoperation.service.DefaultSubscriptionAccessValidationService
All Implemented Interfaces:
SubscriptionAccessValidationService

public class DefaultSubscriptionAccessValidationService extends Object implements SubscriptionAccessValidationService
Default implementation of SubscriptionAccessValidationService
Author:
karanjariwala
  • Field Summary

    Fields
    Modifier and Type
    Field
    Description
    static final String
     
  • Constructor Summary

    Constructors
    Constructor
    Description
    DefaultSubscriptionAccessValidationService(com.broadleafcommerce.resource.security.utils.service.AuthenticationUtils authenticationUtils)
     
  • Method Summary

    Modifier and Type
    Method
    Description
    protected Map<String,List<String>>
    expandPermissionRootsToPermissions(@NonNull String[] permissionRoots, com.broadleafcommerce.data.tracking.core.type.OperationType operationType)
    Constructs a map of <permissionRoot, [possiblePermissions]> for all the permissionRoot passed into the permissionRoots for the given OperationType.
    getAccessibleSubscriptions(@NonNull String[] permissionRoots, @NonNull Collection<SWI> subscriptionWithItems, com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo)
    Filters a Collection of the subscriptionWithItems and returns those subscriptions that are accessible to the current user (customer or account).
    <SWI extends SubscriptionWithItems>
    org.springframework.data.domain.Page<SWI>
    getAccessibleSubscriptions(@NonNull String[] permissionRoots, @NonNull org.springframework.data.domain.Page<SWI> subscriptionWithItems, com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo)
    Filters a Page of the subscriptionWithItems and returns those subscriptions that are accessible to the current user (customer or account).
    protected com.broadleafcommerce.resource.security.utils.service.AuthenticationUtils
     
    protected Set<String>
    getRestrictedTargets(@NonNull String[] permissionRoots, com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo)
    Gets a Set of subscriptionIDs that the currently authenticated user is allowed to access if the user has restricted authorities with the restriction type of "SUBSCRIPTION".
    protected com.broadleafcommerce.data.tracking.core.policy.trackable.TrackablePolicyUtils
     
    void
    setTrackablePolicyUtils(com.broadleafcommerce.data.tracking.core.policy.trackable.TrackablePolicyUtils trackablePolicyUtils)
     
    void
    validateAccess(@NonNull String[] permissionRoots, @NonNull String subscriptionId, com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo)
    Validates whether the current user is restricted to certain subscriptions only.
    protected void
    validateUserPermissions(@NonNull String[] permissionRoots, com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo)
    Validates whether the current user has the exact permission based on ContextInfo.getOperationType() to perform the operation.

    Methods inherited from class java.lang.Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Field Details

  • Constructor Details

    • DefaultSubscriptionAccessValidationService

      public DefaultSubscriptionAccessValidationService(com.broadleafcommerce.resource.security.utils.service.AuthenticationUtils authenticationUtils)
  • Method Details

    • validateAccess

      public void validateAccess(@NonNull @NonNull String[] permissionRoots, @NonNull @NonNull String subscriptionId, @Nullable com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo)
      Description copied from interface: SubscriptionAccessValidationService
      Validates whether the current user is restricted to certain subscriptions only. And if restricted, validates that the user is allowed to access the given subscriptionId.
      Specified by:
      validateAccess in interface SubscriptionAccessValidationService
      Parameters:
      permissionRoots - the permissionRoots that the user's access is to be checked for
      subscriptionId - the subscription whose access is to be checked
      contextInfo - the context information around multi-tenant state
    • getAccessibleSubscriptions

      public <SWI extends SubscriptionWithItems> Collection<SWI> getAccessibleSubscriptions(@NonNull @NonNull String[] permissionRoots, @NonNull @NonNull Collection<SWI> subscriptionWithItems, @Nullable com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo)
      Description copied from interface: SubscriptionAccessValidationService
      Filters a Collection of the subscriptionWithItems and returns those subscriptions that are accessible to the current user (customer or account).
      Specified by:
      getAccessibleSubscriptions in interface SubscriptionAccessValidationService
      Parameters:
      permissionRoots - the permissionRoots that the user's access is to be checked for
      subscriptionWithItems - the collection of subscriptions to be filtered
      contextInfo - the context information around multi-tenant state
      Returns:
      a Collection of SubscriptionWithItems that the current user can access
    • getAccessibleSubscriptions

      public <SWI extends SubscriptionWithItems> org.springframework.data.domain.Page<SWI> getAccessibleSubscriptions(@NonNull @NonNull String[] permissionRoots, @NonNull @NonNull org.springframework.data.domain.Page<SWI> subscriptionWithItems, @Nullable com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo)
      Description copied from interface: SubscriptionAccessValidationService
      Filters a Page of the subscriptionWithItems and returns those subscriptions that are accessible to the current user (customer or account).
      Specified by:
      getAccessibleSubscriptions in interface SubscriptionAccessValidationService
      Parameters:
      permissionRoots - the permissionRoots that the user's access is to be checked for
      subscriptionWithItems - the page of subscriptions to be filtered
      contextInfo - the context information around multi-tenant state
      Returns:
      a Page of SubscriptionWithItems that the current user can access
    • validateUserPermissions

      protected void validateUserPermissions(@NonNull @NonNull String[] permissionRoots, @Nullable com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo)
      Validates whether the current user has the exact permission based on ContextInfo.getOperationType() to perform the operation. Internally it relies on TrackablePolicyUtils.validatePermission(ContextInfo, String[], PermissionMatchingStrategy) for validating the permissions. It uses the PermissionMatchingStrategy.ANY to checks the permissions.

      If the policyResponse is not PolicyResponse.VALID, a NotPermittedException is thrown.

      Parameters:
      permissionRoots - the main permissionRoots that the user's access is to be checked for
      contextInfo - the context info
    • getRestrictedTargets

      protected Set<String> getRestrictedTargets(@NonNull @NonNull String[] permissionRoots, @Nullable com.broadleafcommerce.data.tracking.core.context.ContextInfo contextInfo)
      Gets a Set of subscriptionIDs that the currently authenticated user is allowed to access if the user has restricted authorities with the restriction type of "SUBSCRIPTION".

      If the user has no restricted authorities with the restriction type of "SUBSCRIPTION", they can access any subscription.

      Currently, the subscriptions are matched according to the PermissionMatchingStrategy.ANY strategy in that if a user has restricted authorities like "READ_ACCOUNT_SUBSCRIPTION" -> "SUBSCRIPTION" -> [sub1, sub2, sub7], "READ_SUBSCRIPTION" -> "SUBSCRIPTION" -> [sub3, sub7] and the endpoint has Policy permission roots of ["ACCOUNT_SUBSCRIPTION", "SUBSCRIPTION"] with READ OperationType then the result of this method will have [sub1, sub2, sub3, sub7] as the restricted targets and allow the user to access to all 4 subscriptions.

      Parameters:
      permissionRoots - the main permissionRoots that the user's access is to be checked for
      contextInfo - the context info
      Returns:
      a Set of subscriptionIds the current user can access. Returns an empty set if there are no restrictions.
    • expandPermissionRootsToPermissions

      protected Map<String,List<String>> expandPermissionRootsToPermissions(@NonNull @NonNull String[] permissionRoots, @Nullable com.broadleafcommerce.data.tracking.core.type.OperationType operationType)
      Constructs a map of <permissionRoot, [possiblePermissions]> for all the permissionRoot passed into the permissionRoots for the given OperationType.
      Parameters:
      permissionRoots - the permissionRoots for which the permissions are to be created
      operationType - the current operation being performed
      Returns:
      a map of permissionRoot and its possible permissions
    • getAuthenticationUtils

      protected com.broadleafcommerce.resource.security.utils.service.AuthenticationUtils getAuthenticationUtils()
    • getTrackablePolicyUtils

      @Nullable protected com.broadleafcommerce.data.tracking.core.policy.trackable.TrackablePolicyUtils getTrackablePolicyUtils()
    • setTrackablePolicyUtils

      @Autowired(required=false) public void setTrackablePolicyUtils(com.broadleafcommerce.data.tracking.core.policy.trackable.TrackablePolicyUtils trackablePolicyUtils)