X-Git-Url: http://git.argeo.org/?a=blobdiff_plain;f=server%2Fruntime%2Forg.argeo.server.jcr%2Fsrc%2Fmain%2Fjava%2Forg%2Fargeo%2Fjcr%2Fsecurity%2FJcrAuthorizations.java;h=7e698602eb78c461f9d1a25fc469f1e8e2cad782;hb=659c636b913024e967b25730fac6f4d30ae173a8;hp=ddccf571935196f714b6760ca83197cf00e21e81;hpb=0efe603f0843d9b7aa7c384f6a9de0a8213ae0f4;p=lgpl%2Fargeo-commons.git diff --git a/server/runtime/org.argeo.server.jcr/src/main/java/org/argeo/jcr/security/JcrAuthorizations.java b/server/runtime/org.argeo.server.jcr/src/main/java/org/argeo/jcr/security/JcrAuthorizations.java index ddccf5719..7e698602e 100644 --- a/server/runtime/org.argeo.server.jcr/src/main/java/org/argeo/jcr/security/JcrAuthorizations.java +++ b/server/runtime/org.argeo.server.jcr/src/main/java/org/argeo/jcr/security/JcrAuthorizations.java @@ -27,19 +27,20 @@ import javax.jcr.Session; import javax.jcr.security.AccessControlManager; import javax.jcr.security.Privilege; -import org.apache.commons.logging.Log; -import org.apache.commons.logging.LogFactory; import org.argeo.ArgeoException; import org.argeo.jcr.JcrUtils; import org.argeo.util.security.SimplePrincipal; /** Apply authorizations to a JCR repository. */ public class JcrAuthorizations implements Runnable { - private final static Log log = LogFactory.getLog(JcrAuthorizations.class); + // private final static Log log = + // LogFactory.getLog(JcrAuthorizations.class); private Repository repository; private String workspace = null; + private String securityWorkspace = "security"; + /** * key := privilege1,privilege2/path/to/node
* value := group1,group2,user1 @@ -47,12 +48,45 @@ public class JcrAuthorizations implements Runnable { private Map principalPrivileges = new HashMap(); public void run() { + String currentWorkspace = workspace; + Session session = null; + try { + if (workspace != null && workspace.equals("*")) { + session = repository.login(); + String[] workspaces = session.getWorkspace() + .getAccessibleWorkspaceNames(); + JcrUtils.logoutQuietly(session); + for (String wksp : workspaces) { + currentWorkspace = wksp; + if (currentWorkspace.equals(securityWorkspace)) + continue; + session = repository.login(currentWorkspace); + initAuthorizations(session); + JcrUtils.logoutQuietly(session); + } + } else { + session = repository.login(workspace); + initAuthorizations(session); + } + } catch (Exception e) { + JcrUtils.discardQuietly(session); + throw new ArgeoException( + "Cannot set authorizations " + principalPrivileges + + " on workspace " + currentWorkspace, e); + } finally { + JcrUtils.logoutQuietly(session); + } + } + + protected void processWorkspace(String workspace) { Session session = null; try { session = repository.login(workspace); initAuthorizations(session); } catch (Exception e) { JcrUtils.discardQuietly(session); + throw new ArgeoException("Cannot set authorizations " + + principalPrivileges + " on repository " + repository, e); } finally { JcrUtils.logoutQuietly(session); } @@ -92,12 +126,20 @@ public class JcrAuthorizations implements Runnable { Principal principal = getOrCreatePrincipal(session, principalName); JcrUtils.addPrivileges(session, path, principal, privs); + // if (log.isDebugEnabled()) { + // StringBuffer privBuf = new StringBuffer(); + // for (Privilege priv : privs) + // privBuf.append(priv.getName()); + // log.debug("Added privileges " + privBuf + " to " + // + principal.getName() + " on " + path + " in '" + // + session.getWorkspace().getName() + "'"); + // } } } - if (log.isDebugEnabled()) - log.debug("All authorizations applied on workspace " - + session.getWorkspace().getName()); + // if (log.isDebugEnabled()) + // log.debug("JCR authorizations applied on '" + // + session.getWorkspace().getName() + "'"); } /** @@ -174,4 +216,8 @@ public class JcrAuthorizations implements Runnable { this.workspace = workspace; } + public void setSecurityWorkspace(String securityWorkspace) { + this.securityWorkspace = securityWorkspace; + } + }