]> git.argeo.org Git - lgpl/argeo-commons.git/blob - org.argeo.cms/src/org/argeo/cms/internal/kernel/Activator.java
Make WebSocket activation configurable.
[lgpl/argeo-commons.git] / org.argeo.cms / src / org / argeo / cms / internal / kernel / Activator.java
1 package org.argeo.cms.internal.kernel;
2
3 import java.io.IOException;
4 import java.net.URL;
5 import java.nio.file.Files;
6 import java.nio.file.Path;
7 import java.security.AllPermission;
8 import java.util.Dictionary;
9 import java.util.List;
10 import java.util.Locale;
11
12 import javax.security.auth.login.Configuration;
13
14 import org.apache.commons.logging.Log;
15 import org.apache.commons.logging.LogFactory;
16 import org.argeo.cms.CmsException;
17 import org.argeo.ident.IdentClient;
18 import org.argeo.node.ArgeoLogger;
19 import org.argeo.node.NodeConstants;
20 import org.argeo.node.NodeDeployment;
21 import org.argeo.node.NodeInstance;
22 import org.argeo.node.NodeState;
23 import org.argeo.util.LangUtils;
24 import org.ietf.jgss.GSSCredential;
25 import org.osgi.framework.BundleActivator;
26 import org.osgi.framework.BundleContext;
27 import org.osgi.framework.Constants;
28 import org.osgi.framework.ServiceReference;
29 import org.osgi.service.condpermadmin.BundleLocationCondition;
30 import org.osgi.service.condpermadmin.ConditionInfo;
31 import org.osgi.service.condpermadmin.ConditionalPermissionAdmin;
32 import org.osgi.service.condpermadmin.ConditionalPermissionInfo;
33 import org.osgi.service.condpermadmin.ConditionalPermissionUpdate;
34 import org.osgi.service.log.LogReaderService;
35 import org.osgi.service.permissionadmin.PermissionInfo;
36 import org.osgi.service.useradmin.UserAdmin;
37 import org.osgi.util.tracker.ServiceTracker;
38
39 /**
40 * Activates the kernel. Gives access to kernel information for the rest of the
41 * bundle (and only it)
42 */
43 public class Activator implements BundleActivator {
44 private final static Log log = LogFactory.getLog(Activator.class);
45
46 private static Activator instance;
47
48 // TODO make it configurable
49 private boolean hardened = false;
50
51 private BundleContext bc;
52
53 private LogReaderService logReaderService;
54
55 private NodeLogger logger;
56 private CmsState nodeState;
57 private CmsDeployment nodeDeployment;
58 private CmsInstance nodeInstance;
59
60 private ServiceTracker<UserAdmin, NodeUserAdmin> userAdminSt;
61
62 @Override
63 public void start(BundleContext bundleContext) throws Exception {
64 Runtime.getRuntime().addShutdownHook(new CmsShutdown());
65 instance = this;
66 this.bc = bundleContext;
67 this.logReaderService = getService(LogReaderService.class);
68
69 try {
70 initSecurity();
71 initArgeoLogger();
72 initNode();
73
74 userAdminSt = new ServiceTracker<>(instance.bc, UserAdmin.class, null);
75 userAdminSt.open();
76 if (log.isTraceEnabled())
77 log.trace("Kernel bundle started");
78 } catch (Throwable e) {
79 log.error("## FATAL: CMS activator failed", e);
80 }
81 }
82
83 private void initSecurity() {
84 if (System.getProperty(KernelConstants.JAAS_CONFIG_PROP) == null) {
85 String jaasConfig = KernelConstants.JAAS_CONFIG;
86 URL url = getClass().getClassLoader().getResource(jaasConfig);
87 // System.setProperty(KernelConstants.JAAS_CONFIG_PROP,
88 // url.toExternalForm());
89 KernelUtils.setJaasConfiguration(url);
90 }
91 // explicitly load JAAS configuration
92 Configuration.getConfiguration();
93
94 // code-level permissions
95 String osgiSecurity = KernelUtils.getFrameworkProp(Constants.FRAMEWORK_SECURITY);
96 if (osgiSecurity != null && Constants.FRAMEWORK_SECURITY_OSGI.equals(osgiSecurity)) {
97 // TODO rather use a tracker?
98 ConditionalPermissionAdmin permissionAdmin = bc
99 .getService(bc.getServiceReference(ConditionalPermissionAdmin.class));
100 if (!hardened) {
101 // All permissions to all bundles
102 ConditionalPermissionUpdate update = permissionAdmin.newConditionalPermissionUpdate();
103 update.getConditionalPermissionInfos().add(permissionAdmin.newConditionalPermissionInfo(null,
104 new ConditionInfo[] {
105 new ConditionInfo(BundleLocationCondition.class.getName(), new String[] { "*" }) },
106 new PermissionInfo[] { new PermissionInfo(AllPermission.class.getName(), null, null) },
107 ConditionalPermissionInfo.ALLOW));
108 } else {
109 SecurityProfile securityProfile = new SecurityProfile() {
110 };
111 securityProfile.applySystemPermissions(permissionAdmin);
112 }
113 }
114
115 }
116
117 private void initArgeoLogger() {
118 logger = new NodeLogger(logReaderService);
119 bc.registerService(ArgeoLogger.class, logger, null);
120 }
121
122 private void initNode() throws IOException {
123 // Node state
124 Path stateUuidPath = bc.getDataFile("stateUuid").toPath();
125 String stateUuid;
126 if (Files.exists(stateUuidPath)) {
127 stateUuid = Files.readAllLines(stateUuidPath).get(0);
128 } else {
129 stateUuid = bc.getProperty(Constants.FRAMEWORK_UUID);
130 Files.write(stateUuidPath, stateUuid.getBytes());
131 }
132 nodeState = new CmsState(stateUuid);
133 Dictionary<String, Object> regProps = LangUtils.dico(Constants.SERVICE_PID, NodeConstants.NODE_STATE_PID);
134 regProps.put(NodeConstants.CN, stateUuid);
135 bc.registerService(NodeState.class, nodeState, regProps);
136
137 // Node deployment
138 nodeDeployment = new CmsDeployment();
139 bc.registerService(NodeDeployment.class, nodeDeployment, null);
140
141 // Node instance
142 nodeInstance = new CmsInstance();
143 bc.registerService(NodeInstance.class, nodeInstance, null);
144 }
145
146 @Override
147 public void stop(BundleContext bundleContext) throws Exception {
148 try {
149 if (nodeInstance != null)
150 nodeInstance.shutdown();
151 if (nodeDeployment != null)
152 nodeDeployment.shutdown();
153 if (nodeState != null)
154 nodeState.shutdown();
155
156 if (userAdminSt != null)
157 userAdminSt.close();
158
159 instance = null;
160 this.bc = null;
161 this.logReaderService = null;
162 // this.configurationAdmin = null;
163 } catch (Exception e) {
164 log.error("CMS activator shutdown failed", e);
165 }
166 }
167
168 private <T> T getService(Class<T> clazz) {
169 ServiceReference<T> sr = bc.getServiceReference(clazz);
170 if (sr == null)
171 throw new CmsException("No service available for " + clazz);
172 return bc.getService(sr);
173 }
174
175 public static NodeState getNodeState() {
176 return instance.nodeState;
177 }
178
179 public static GSSCredential getAcceptorCredentials() {
180 return getNodeUserAdmin().getAcceptorCredentials();
181 }
182
183 public static boolean isSingleUser() {
184 return getNodeUserAdmin().isSingleUser();
185 }
186
187 public static UserAdmin getUserAdmin() {
188 return (UserAdmin) getNodeUserAdmin();
189 }
190
191 public static String getHttpProxySslHeader() {
192 return KernelUtils.getFrameworkProp(NodeConstants.HTTP_PROXY_SSL_DN);
193 }
194
195 public static IdentClient getIdentClient(String remoteAddr) {
196 if (!IdentClient.isDefaultAuthdPassphraseFileAvailable())
197 return null;
198 // TODO make passphrase more configurable
199 return new IdentClient(remoteAddr);
200 }
201
202 private static NodeUserAdmin getNodeUserAdmin() {
203 NodeUserAdmin res;
204 try {
205 res = instance.userAdminSt.waitForService(60000);
206 } catch (InterruptedException e) {
207 throw new CmsException("Cannot retrieve Node user admin", e);
208 }
209 if (res == null)
210 throw new CmsException("No Node user admin found");
211
212 return res;
213 // ServiceReference<UserAdmin> sr =
214 // instance.bc.getServiceReference(UserAdmin.class);
215 // NodeUserAdmin userAdmin = (NodeUserAdmin) instance.bc.getService(sr);
216 // return userAdmin;
217
218 }
219
220 // static CmsSecurity getCmsSecurity() {
221 // return instance.nodeSecurity;
222 // }
223
224 public String[] getLocales() {
225 // TODO optimize?
226 List<Locale> locales = getNodeState().getLocales();
227 String[] res = new String[locales.size()];
228 for (int i = 0; i < locales.size(); i++)
229 res[i] = locales.get(i).toString();
230 return res;
231 }
232
233 }