]> git.argeo.org Git - lgpl/argeo-commons.git/blobdiff - security/runtime/org.argeo.security.core/src/main/java/org/argeo/security/core/DefaultSecurityService.java
Wrap roles so that it is writable
[lgpl/argeo-commons.git] / security / runtime / org.argeo.security.core / src / main / java / org / argeo / security / core / DefaultSecurityService.java
index b9b85087b31f45c1b15786e918eb2d9f5e60bc29..62ce6c759cc8506a0f523850749007acd34b0161 100644 (file)
 
 package org.argeo.security.core;
 
+import java.util.HashSet;
 import java.util.Iterator;
-import java.util.List;
+import java.util.Set;
 
-import org.argeo.ArgeoException;
 import org.argeo.security.ArgeoSecurity;
 import org.argeo.security.ArgeoSecurityDao;
 import org.argeo.security.ArgeoSecurityService;
 import org.argeo.security.ArgeoUser;
 import org.argeo.security.SimpleArgeoUser;
+import org.argeo.security.UserAdminService;
 import org.springframework.core.task.SimpleAsyncTaskExecutor;
 import org.springframework.core.task.TaskExecutor;
 import org.springframework.security.Authentication;
@@ -32,22 +33,14 @@ import org.springframework.security.AuthenticationManager;
 import org.springframework.security.context.SecurityContext;
 import org.springframework.security.context.SecurityContextHolder;
 
-public class DefaultSecurityService implements ArgeoSecurityService {
+public class DefaultSecurityService extends DefaultCurrentUserService implements
+               UserAdminService, ArgeoSecurityService {
        private ArgeoSecurity argeoSecurity = new DefaultArgeoSecurity();
        private ArgeoSecurityDao securityDao;
        private AuthenticationManager authenticationManager;
 
        private String systemAuthenticationKey;
 
-       public ArgeoUser getCurrentUser() {
-               ArgeoUser argeoUser = ArgeoUserDetails.securityContextUser();
-               if (argeoUser == null)
-                       return null;
-               if (argeoUser.getRoles().contains(securityDao.getDefaultRole()))
-                       argeoUser.getRoles().remove(securityDao.getDefaultRole());
-               return argeoUser;
-       }
-
        public ArgeoSecurityDao getSecurityDao() {
                return securityDao;
        }
@@ -59,16 +52,8 @@ public class DefaultSecurityService implements ArgeoSecurityService {
        public void updateUserPassword(String username, String password) {
                SimpleArgeoUser user = new SimpleArgeoUser(
                                securityDao.getUser(username));
-               user.setPassword(securityDao.encodePassword(password));
-               securityDao.update(user);
-       }
-
-       public void updateCurrentUserPassword(String oldPassword, String newPassword) {
-               SimpleArgeoUser user = new SimpleArgeoUser(getCurrentUser());
-               if (!securityDao.isPasswordValid(user.getPassword(), oldPassword))
-                       throw new ArgeoException("Old password is not correct.");
-               user.setPassword(securityDao.encodePassword(newPassword));
-               securityDao.update(user);
+               user.setPassword(encodePassword(password));
+               securityDao.updateUser(user);
        }
 
        public void newUser(ArgeoUser user) {
@@ -76,13 +61,21 @@ public class DefaultSecurityService implements ArgeoSecurityService {
                // normalize password
                if (user instanceof SimpleArgeoUser) {
                        if (user.getPassword() == null || user.getPassword().equals(""))
-                               ((SimpleArgeoUser) user).setPassword(securityDao
-                                               .encodePassword(user.getUsername()));
+                               ((SimpleArgeoUser) user).setPassword(encodePassword(user
+                                               .getUsername()));
                        else if (!user.getPassword().startsWith("{"))
-                               ((SimpleArgeoUser) user).setPassword(securityDao
-                                               .encodePassword(user.getPassword()));
+                               ((SimpleArgeoUser) user).setPassword(encodePassword(user
+                                               .getPassword()));
                }
-               securityDao.create(user);
+               securityDao.createUser(user);
+       }
+
+       public ArgeoUser getUser(String username) {
+               return securityDao.getUser(username);
+       }
+
+       public Boolean userExists(String username) {
+               return securityDao.userExists(username);
        }
 
        public void updateUser(ArgeoUser user) {
@@ -91,12 +84,22 @@ public class DefaultSecurityService implements ArgeoSecurityService {
                        password = securityDao.getUserWithPassword(user.getUsername())
                                        .getPassword();
                if (!password.startsWith("{"))
-                       password = securityDao.encodePassword(user.getPassword());
+                       password = encodePassword(user.getPassword());
                SimpleArgeoUser simpleArgeoUser = new SimpleArgeoUser(user);
                simpleArgeoUser.setPassword(password);
-               securityDao.update(simpleArgeoUser);
+               securityDao.updateUser(simpleArgeoUser);
        }
 
+       public void deleteUser(String username) {
+               securityDao.deleteUser(username);
+
+       }
+
+       public void deleteRole(String role) {
+               securityDao.deleteRole(role);
+       }
+
+       @Deprecated
        public TaskExecutor createSystemAuthenticatedTaskExecutor() {
                return new SimpleAsyncTaskExecutor() {
                        private static final long serialVersionUID = -8126773862193265020L;
@@ -114,6 +117,7 @@ public class DefaultSecurityService implements ArgeoSecurityService {
         * Wraps another runnable, adding security context <br/>
         * TODO: secure the call to this method with Java Security
         */
+       @Deprecated
        public Runnable wrapWithSystemAuthentication(final Runnable runnable) {
                return new Runnable() {
 
@@ -130,8 +134,9 @@ public class DefaultSecurityService implements ArgeoSecurityService {
                };
        }
 
-       public List<ArgeoUser> listUsersInRole(String role) {
-               List<ArgeoUser> lst = securityDao.listUsersInRole(role);
+       public Set<ArgeoUser> listUsersInRole(String role) {
+               Set<ArgeoUser> lst = new HashSet<ArgeoUser>(
+                               securityDao.listUsersInRole(role));
                Iterator<ArgeoUser> it = lst.iterator();
                while (it.hasNext()) {
                        if (it.next().getUsername()
@@ -143,12 +148,22 @@ public class DefaultSecurityService implements ArgeoSecurityService {
                return lst;
        }
 
+       public Set<ArgeoUser> listUsers() {
+               return securityDao.listUsers();
+       }
+
+       public Set<String> listEditableRoles() {
+               // TODO Auto-generated method stub
+               return securityDao.listEditableRoles();
+       }
+
        public void setArgeoSecurity(ArgeoSecurity argeoSecurity) {
                this.argeoSecurity = argeoSecurity;
        }
 
        public void setSecurityDao(ArgeoSecurityDao dao) {
                this.securityDao = dao;
+               setCurrentUserDao(dao);
        }
 
        public void setAuthenticationManager(