Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
14 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ import com.netgrif.application.engine.adapter.spring.petrinet.service.ProcessRol
import com.netgrif.application.engine.adapter.spring.utils.PaginationProperties
import com.netgrif.application.engine.adapter.spring.workflow.domain.QCase
import com.netgrif.application.engine.adapter.spring.workflow.domain.QTask
import com.netgrif.application.engine.auth.service.AuthorityService
import com.netgrif.application.engine.auth.service.GroupService
import com.netgrif.application.engine.auth.service.UserDetailsServiceImpl
import com.netgrif.application.engine.auth.service.UserService
Expand All @@ -29,8 +30,12 @@ import com.netgrif.application.engine.integration.modules.ModuleHolder
import com.netgrif.application.engine.mail.domain.MailDraft
import com.netgrif.application.engine.mail.interfaces.IMailAttemptService
import com.netgrif.application.engine.mail.interfaces.IMailService
import com.netgrif.application.engine.objects.annotations.Authorize
import com.netgrif.application.engine.objects.auth.domain.AbstractUser
import com.netgrif.application.engine.objects.auth.domain.ActorTransformer
import com.netgrif.application.engine.objects.auth.domain.Authority
import com.netgrif.application.engine.objects.auth.dto.AuthoritySearchDto
import com.netgrif.application.engine.objects.auth.dto.GroupSearchDto
import com.netgrif.application.engine.menu.services.interfaces.DashboardItemService
import com.netgrif.application.engine.menu.services.interfaces.DashboardManagementService
import com.netgrif.application.engine.menu.services.interfaces.IMenuItemService
Expand Down Expand Up @@ -157,6 +162,9 @@ class ActionDelegate extends DelegateExpando {
@Autowired
GroupService groupService

@Autowired
AuthorityService authorityService

@Autowired
ProcessRoleService processRoleService

Expand Down Expand Up @@ -1414,10 +1422,16 @@ class ActionDelegate extends DelegateExpando {
changeUserByEmail(email, "email", cl)
},
name : { cl ->
changeUserByEmail(email, "name", cl)
changeUserByEmail(email, "firstName", cl)
},
firstName : { cl ->
changeUserByEmail(email, "firstName", cl)
},
surname: { cl ->
changeUserByEmail(email, "surname", cl)
changeUserByEmail(email, "lastName", cl)
},
lastName : { cl ->
changeUserByEmail(email, "lastName", cl)
},
tel : { cl ->
changeUserByEmail(email, "tel", cl)
Expand All @@ -1430,10 +1444,16 @@ class ActionDelegate extends DelegateExpando {
changeUser(id, "email", cl)
},
name : { cl ->
changeUser(id, "name", cl)
changeUser(id, "firstName", cl)
},
firstName : { cl ->
changeUser(id, "firstName", cl)
},
surname: { cl ->
changeUser(id, "surname", cl)
changeUser(id, "lastName", cl)
},
lastName : { cl ->
changeUser(id, "lastName", cl)
},
tel : { cl ->
changeUser(id, "tel", cl)
Expand All @@ -1446,10 +1466,16 @@ class ActionDelegate extends DelegateExpando {
changeUser(user, "email", cl)
},
name : { cl ->
changeUser(user, "name", cl)
changeUser(user, "firstName", cl)
},
firstName : { cl ->
changeUser(user, "firstName", cl)
},
surname: { cl ->
changeUser(user, "surname", cl)
changeUser(user, "lastName", cl)
},
lastName : { cl ->
changeUser(user, "lastName", cl)
},
tel : { cl ->
changeUser(user, "tel", cl)
Expand All @@ -1458,7 +1484,7 @@ class ActionDelegate extends DelegateExpando {
}

def changeUserByEmail(String email, String attribute, def cl) {
Optional<AbstractUser> userOptional = userService.findUserByUsername(email, null)
Optional<AbstractUser> userOptional = userService.findUserByEmail(email, null)
if (!userOptional.isPresent()) {
log.error("Cannot find user with email [" + email + "]")
return
Expand Down Expand Up @@ -3055,4 +3081,127 @@ class ActionDelegate extends DelegateExpando {
IStorageService storageService = storageResolverService.resolve(storageField.storageType)
return storageService.getPath(aCase.stringId, fileFieldId, fileName)
}

/**
* Returns page of all authorities.
*
* @param pageable page configuration, by default the whole first backend page is returned
* @return page of {@link Authority} objects
*/
Page<Authority> findAllAuthorities(Pageable pageable = PageRequest.of(0, paginationProperties.getBackendPageSize())) {
return authorityService.findAll(pageable)
}

/**
* Returns authority of given name. If the authority does not exist, it is created.
*
* @param name name of the authority
* @return existing or newly created {@link Authority}
*/
Authority getOrCreateAuthority(String name) {
return authorityService.getOrCreate(name)
}

/**
* Returns authority by its database id.
*
* @param id id of the authority
* @return found {@link Authority}
*/
Authority getAuthority(String id) {
return authorityService.getOne(id)
}

/**
* Returns authority of given name. Throws an exception if such authority does not exist.
*
* @param name name of the authority
* @return found {@link Authority}
*/
Authority getAuthorityByName(String name) {
return authorityService.findByName(name)
}

/**
* Returns authority of given name or null if such authority does not exist.
*
* @param name name of the authority
* @return found {@link Authority} or null
*/
Authority findAuthorityByName(String name) {
Optional<Authority> authority = authorityService.findOptionalByName(name)
if (authority.isEmpty()) {
log.warn("Cannot find authority with name [" + name + "]")
return null
}
return authority.get()
}

/**
* Returns authorities of given ids.
*
* @param ids ids of the authorities
* @param pageable page configuration, by default the whole first backend page is returned
* @return list of found {@link Authority} objects
*/
List<Authority> findAuthoritiesByIds(Collection<String> ids, Pageable pageable = PageRequest.of(0, paginationProperties.getBackendPageSize())) {
if (ids == null || ids.isEmpty()) {
return []
}
return authorityService.findAllByIds(ids, pageable).content
}

/**
* Returns authorities of given scope. Scope contains authorities of the same name prefix, f.e. <code>"PROCESS*"</code>
* returns authorities PROCESS_UPLOAD, PROCESS_DELETE etc. Scope <code>"*"</code> returns every authority.
*
* @param scope scope of the authorities
* @return list of found {@link Authority} objects
*/
List<Authority> findAuthoritiesByScope(String scope) {
return authorityService.findByScope(scope)
}

/**
* Searches authorities by full text query on the authority name.
*
* @param fullText text to be searched for, null or empty text returns all authorities
* @param pageable page configuration, by default the whole first backend page is returned
* @return list of found {@link Authority} objects
*/
List<Authority> searchAuthorities(String fullText, Pageable pageable = PageRequest.of(0, paginationProperties.getBackendPageSize())) {
AuthoritySearchDto searchDto = new AuthoritySearchDto()
searchDto.setFullText(fullText)
return authorityService.search(searchDto, pageable).content
}

/**
* Deletes authority of given name. Nothing happens if such authority does not exist.
*
* @param name name of the authority
*/
void deleteAuthority(String name) {
authorityService.delete(name)
}

/**
* @return set of default authorities of a user
*/
Set<Authority> defaultUserAuthorities() {
return authorityService.getDefaultUserAuthorities()
}

/**
* @return set of default authorities of an anonymous user
*/
Set<Authority> defaultAnonymousAuthorities() {
return authorityService.getDefaultAnonymousAuthorities()
}

/**
* @return set of default authorities of an admin
*/
Set<Authority> defaultAdminAuthorities() {
return authorityService.getDefaultAdminAuthorities()
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,101 @@
package com.netgrif.application.engine.auth.web;

import com.netgrif.application.engine.adapter.spring.common.web.responsebodies.ResponseMessage;
import com.netgrif.application.engine.auth.service.AuthorityService;
import com.netgrif.application.engine.auth.web.requestbodies.NewAuthorityRequest;
import com.netgrif.application.engine.auth.web.responsebodies.AuthorityDto;
import com.netgrif.application.engine.objects.annotations.Authorize;
import com.netgrif.application.engine.objects.auth.domain.Authority;
import com.netgrif.application.engine.workflow.web.responsebodies.MessageResource;
import io.swagger.v3.oas.annotations.Operation;
import io.swagger.v3.oas.annotations.security.SecurityRequirement;
import io.swagger.v3.oas.annotations.tags.Tag;
import lombok.RequiredArgsConstructor;
import lombok.extern.slf4j.Slf4j;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.boot.autoconfigure.condition.ConditionalOnProperty;
import org.springframework.data.domain.Page;
import org.springframework.data.domain.PageImpl;
import org.springframework.data.domain.Pageable;
import org.springframework.data.rest.webmvc.ResourceNotFoundException;
import org.springframework.hateoas.MediaTypes;
import org.springframework.http.MediaType;
import org.springframework.http.ResponseEntity;
import org.springframework.security.core.Authentication;
import org.springframework.web.bind.annotation.*;

import java.util.List;
import java.util.Optional;

@Slf4j
@RestController
@RequestMapping("/api/authority")
@RequiredArgsConstructor
@ConditionalOnProperty(
value = "nae.user.web.enabled",
havingValue = "true",
matchIfMissing = true
)
@Tag(name = "Authority")
public class AuthorityController {

private final AuthorityService authorityService;

@Authorize(authority = "ADMIN")
@Authorize(authority = "AUTHORITY_DELETE")
@Operation(description = "Delete authority", security = {@SecurityRequirement(name = "BasicAuth")})
@DeleteMapping(value = "/delete/{name}", consumes = MediaType.APPLICATION_JSON_VALUE, produces = MediaTypes.HAL_JSON_VALUE)
public MessageResource delete(@PathVariable String name, Authentication auth) {
try {
authorityService.delete(name);
log.info("Authority [{}] has been deleted successfully.", name);
return new MessageResource(ResponseMessage.createSuccessMessage("Authority [" + name + "] has been deleted successfully."));
} catch (IllegalArgumentException | ResourceNotFoundException e) {
log.error("Failed to delete authority [{}].", name, e);
return new MessageResource(ResponseMessage.createErrorMessage("Failed to delete authority."));
}
}

@Authorize(authority = "ADMIN")
@Authorize(authority = "AUTHORITY_CREATE")
@Operation(description = "Create authority", security = {@SecurityRequirement(name = "BasicAuth")})
@PostMapping(value = "/create", consumes = MediaType.APPLICATION_JSON_VALUE, produces = MediaTypes.HAL_JSON_VALUE)
public ResponseEntity<AuthorityDto> create(@RequestBody NewAuthorityRequest request) {
try {
Authority authority = authorityService.getOrCreate(request.name);
log.info("Authority [{}] has been created successfully.", authority);
return ResponseEntity.ok(new AuthorityDto(authority));
} catch (IllegalArgumentException | ResourceNotFoundException e) {
log.error("Failed to create authority [{}].", request.name, e);
return null;
}
}

@Operation(description = "Delete authority", security = {@SecurityRequirement(name = "BasicAuth")})
@GetMapping(value = "/all", consumes = MediaType.APPLICATION_JSON_VALUE, produces = MediaTypes.HAL_JSON_VALUE)
public ResponseEntity<Page<AuthorityDto>> getAll(Pageable pageable) {
Page<Authority> authorities = authorityService.findAll(pageable);
List<AuthorityDto> authorityDtoList = authorities.stream().map(AuthorityDto::new).toList();
return ResponseEntity.ok(new PageImpl<>(authorityDtoList, pageable, authorities.getTotalElements()));
}

@Operation(description = "Delete authority", security = {@SecurityRequirement(name = "BasicAuth")})
@GetMapping(value = "/{name}", consumes = MediaType.APPLICATION_JSON_VALUE, produces = MediaTypes.HAL_JSON_VALUE)
public ResponseEntity<AuthorityDto> getOne(@PathVariable("name") String name) {
Optional<Authority> authority = authorityService.findOptionalByName(name);
if (authority.isPresent()) {
return ResponseEntity.ok(new AuthorityDto(authority.get()));
} else {
log.error("Cannot find authority with name [{}].", name);
return null;
}
}

@Operation(description = "Delete authority", security = {@SecurityRequirement(name = "BasicAuth")})
@GetMapping(value = "/scope/{scope}", consumes = MediaType.APPLICATION_JSON_VALUE, produces = MediaTypes.HAL_JSON_VALUE)
public ResponseEntity<List<AuthorityDto>> getAllByScope(@PathVariable("scope") String scope, Authentication auth) {
List<Authority> authorities = authorityService.findByScope(scope);
List<AuthorityDto> authorityDtoList = authorities.stream().map(AuthorityDto::new).toList();
return ResponseEntity.ok(authorityDtoList);
}
}
Loading
Loading