package org.argeo.app.core;
import java.util.HashSet;
+import java.util.Optional;
import java.util.Set;
import javax.jcr.Node;
import javax.jcr.nodetype.NodeType;
import javax.jcr.security.Privilege;
import javax.security.auth.x500.X500Principal;
+import javax.xml.namespace.QName;
+import org.argeo.api.acr.Content;
+import org.argeo.api.acr.ldap.LdapAttr;
+import org.argeo.api.acr.ldap.LdapObj;
import org.argeo.api.cms.CmsConstants;
import org.argeo.api.cms.CmsSession;
import org.argeo.app.api.EntityType;
-import org.argeo.app.api.SuiteRole;
-import org.argeo.cms.auth.RoleNameUtils;
-import org.argeo.jackrabbit.security.JackrabbitSecurityUtils;
+import org.argeo.cms.RoleNameUtils;
import org.argeo.jcr.JcrException;
import org.argeo.jcr.JcrUtils;
-import org.argeo.util.naming.LdapAttrs;
/** Utilities around the Argeo Suite APIs. */
public class SuiteUtils {
userNode = usersBase.addNode(uid, NodeType.NT_UNSTRUCTURED);
userNode.addMixin(EntityType.user.get());
userNode.addMixin(NodeType.MIX_CREATED);
- userNode.setProperty(LdapAttrs.distinguishedName.property(), userDn.toString());
- userNode.setProperty(LdapAttrs.uid.property(), uid);
+ userNode.setProperty(LdapAttr.distinguishedName.property(), userDn.toString());
+ userNode.setProperty(LdapAttr.uid.property(), uid);
adminSession.save();
- JackrabbitSecurityUtils.denyPrivilege(adminSession, userNode.getPath(), SuiteRole.coworker.dn(),
- Privilege.JCR_READ);
+// JackrabbitSecurityUtils.denyPrivilege(adminSession, userNode.getPath(), SuiteRole.coworker.dn(),
+// Privilege.JCR_READ);
JcrUtils.addPrivilege(adminSession, userNode.getPath(), new X500Principal(userDn.toString()).getName(),
Privilege.JCR_READ);
JcrUtils.addPrivilege(adminSession, userNode.getPath(), CmsConstants.ROLE_USER_ADMIN,
}
}
- /** Singleton. */
- private SuiteUtils() {
-
- }
-
public static Set<String> extractRoles(String[] semiColArr) {
Set<String> res = new HashSet<>();
// TODO factorize and make it more robust
return res;
}
+ synchronized static public long findNextId(Content hierarchyUnit, QName cclass) {
+ if (!hierarchyUnit.hasContentClass(LdapObj.posixGroup.qName()))
+ throw new IllegalArgumentException(hierarchyUnit + " is not a POSIX group");
+
+ long min = hierarchyUnit.get(LdapAttr.gidNumber.qName(), Long.class).orElseThrow();
+ long currentMax = 0l;
+ for (Content childHu : hierarchyUnit) {
+ if (!childHu.hasContentClass(LdapObj.organizationalUnit.qName()))
+ continue;
+ // FIXME filter out functional hierarchy unit
+ for (Content role : childHu) {
+ if (role.hasContentClass(cclass)) {
+
+ if (LdapObj.posixAccount.qName().equals(cclass)) {
+ Long id = role.get(LdapAttr.uidNumber.qName(), Long.class).orElseThrow();
+ if (id > currentMax)
+ currentMax = id;
+ }
+ }
+ }
+ }
+ if (currentMax == 0l)
+ return min;
+ return currentMax + 1;
+ }
+
+ /** Singleton. */
+ private SuiteUtils() {
+ }
}