X-Git-Url: https://git.argeo.org/?a=blobdiff_plain;f=server%2Fruntime%2Forg.argeo.server.jcr%2Fsrc%2Fmain%2Fjava%2Forg%2Fargeo%2Fjcr%2Fsecurity%2FJcrAuthorizations.java;h=14ac2bc340f78342ebf01963245b9b835d69d364;hb=3ff30fc87c733541ee27246e7cc3fecc52efde0c;hp=ddccf571935196f714b6760ca83197cf00e21e81;hpb=0efe603f0843d9b7aa7c384f6a9de0a8213ae0f4;p=lgpl%2Fargeo-commons.git
diff --git a/server/runtime/org.argeo.server.jcr/src/main/java/org/argeo/jcr/security/JcrAuthorizations.java b/server/runtime/org.argeo.server.jcr/src/main/java/org/argeo/jcr/security/JcrAuthorizations.java
index ddccf5719..14ac2bc34 100644
--- a/server/runtime/org.argeo.server.jcr/src/main/java/org/argeo/jcr/security/JcrAuthorizations.java
+++ b/server/runtime/org.argeo.server.jcr/src/main/java/org/argeo/jcr/security/JcrAuthorizations.java
@@ -40,6 +40,8 @@ public class JcrAuthorizations implements Runnable {
private Repository repository;
private String workspace = null;
+ private String securityWorkspace = "security";
+
/**
* key := privilege1,privilege2/path/to/node
* value := group1,group2,user1
@@ -47,12 +49,45 @@ public class JcrAuthorizations implements Runnable {
private Map principalPrivileges = new HashMap();
public void run() {
+ String currentWorkspace = workspace;
+ Session session = null;
+ try {
+ if (workspace != null && workspace.equals("*")) {
+ session = repository.login();
+ String[] workspaces = session.getWorkspace()
+ .getAccessibleWorkspaceNames();
+ JcrUtils.logoutQuietly(session);
+ for (String wksp : workspaces) {
+ currentWorkspace = wksp;
+ if (currentWorkspace.equals(securityWorkspace))
+ continue;
+ session = repository.login(currentWorkspace);
+ initAuthorizations(session);
+ JcrUtils.logoutQuietly(session);
+ }
+ } else {
+ session = repository.login(workspace);
+ initAuthorizations(session);
+ }
+ } catch (Exception e) {
+ JcrUtils.discardQuietly(session);
+ throw new ArgeoException(
+ "Cannot set authorizations " + principalPrivileges
+ + " on workspace " + currentWorkspace, e);
+ } finally {
+ JcrUtils.logoutQuietly(session);
+ }
+ }
+
+ protected void processWorkspace(String workspace) {
Session session = null;
try {
session = repository.login(workspace);
initAuthorizations(session);
} catch (Exception e) {
JcrUtils.discardQuietly(session);
+ throw new ArgeoException("Cannot set authorizations "
+ + principalPrivileges + " on repository " + repository, e);
} finally {
JcrUtils.logoutQuietly(session);
}
@@ -92,12 +127,20 @@ public class JcrAuthorizations implements Runnable {
Principal principal = getOrCreatePrincipal(session,
principalName);
JcrUtils.addPrivileges(session, path, principal, privs);
+ if (log.isDebugEnabled()) {
+ StringBuffer privBuf = new StringBuffer();
+ for (Privilege priv : privs)
+ privBuf.append(priv.getName());
+ log.debug("Added privileges " + privBuf + " to "
+ + principal.getName() + " on " + path + " in '"
+ + session.getWorkspace().getName() + "'");
+ }
}
}
- if (log.isDebugEnabled())
- log.debug("All authorizations applied on workspace "
- + session.getWorkspace().getName());
+ // if (log.isDebugEnabled())
+ // log.debug("JCR authorizations applied on '"
+ // + session.getWorkspace().getName() + "'");
}
/**
@@ -174,4 +217,8 @@ public class JcrAuthorizations implements Runnable {
this.workspace = workspace;
}
+ public void setSecurityWorkspace(String securityWorkspace) {
+ this.securityWorkspace = securityWorkspace;
+ }
+
}