]> git.argeo.org Git - lgpl/argeo-commons.git/blobdiff - security/runtime/org.argeo.security.core/src/main/java/org/argeo/security/ArgeoSecurityDao.java
Improve Security
[lgpl/argeo-commons.git] / security / runtime / org.argeo.security.core / src / main / java / org / argeo / security / ArgeoSecurityDao.java
index f91e86748457669de1ce0cd31edcaae995f85742..67c4cb2ec39e9e315e3c2fa486aa9b72914020ed 100644 (file)
@@ -16,7 +16,7 @@
 
 package org.argeo.security;
 
-import java.util.List;
+import java.util.Set;
 
 /**
  * Access to the users and roles referential (dependent from the underlying
@@ -25,20 +25,33 @@ import java.util.List;
 public interface ArgeoSecurityDao {
        // public ArgeoUser getCurrentUser();
 
-       public List<ArgeoUser> listUsers();
+       /** List all users */
+       public Set<ArgeoUser> listUsers();
 
-       public List<String> listEditableRoles();
+       /** List roles that can be modified */
+       public Set<String> listEditableRoles();
 
-       public void create(ArgeoUser user);
+       /**
+        * Creates a new user in the underlying storage. <b>DO NOT CALL DIRECTLY</b>
+        * use {@link ArgeoSecurityService#newUser(ArgeoUser)} instead.
+        */
+       public void createUser(ArgeoUser user);
 
-       public void update(ArgeoUser user);
+       public void updateUser(ArgeoUser user);
 
-       public void delete(String username);
+       public void deleteUser(String username);
 
+       /**
+        * Creates a new role in the underlying storage. <b>DO NOT CALL DIRECTLY</b>
+        * use {@link ArgeoSecurityService#newRole(String)} instead.
+        */
        public void createRole(String role, String superuserName);
 
        public void deleteRole(String role);
 
+       /** List all users having this role. */
+       public Set<ArgeoUser> listUsersInRole(String role);
+
        public Boolean userExists(String username);
 
        public ArgeoUser getUser(String username);
@@ -46,4 +59,10 @@ public interface ArgeoSecurityDao {
        public ArgeoUser getUserWithPassword(String username);
 
        public String getDefaultRole();
+
+       /** Validates a raw password against an encoded one. */
+       public Boolean isPasswordValid(String encoded, String raw);
+
+       /** Encodes a raw password. */
+       public String encodePassword(String raw);
 }