|
||||||||||
| PREV CLASS NEXT CLASS | FRAMES NO FRAMES | |||||||||
| SUMMARY: NESTED | FIELD | CONSTR | METHOD | DETAIL: FIELD | CONSTR | METHOD | |||||||||
java.lang.Objectorg.mmbase.security.Configurable
org.mmbase.security.Authorization
org.mmbase.security.implementation.cloud.Verify
public class Verify
Simple authorization implemenation for 'cloud' security implemenation based only on an mmbasusers builder. Read-rights on everything for everybody. User named 'admin' has rank administrator and may do everything. Normal users have no rights on a limited set of 'admin' builders. Normal users may do everything on their 'own' nodes, and on nodes with the owner field '[shared]'.
| Nested Class Summary |
|---|
| Nested classes/interfaces inherited from class org.mmbase.security.Authorization |
|---|
Authorization.QueryCheck |
| Field Summary |
|---|
| Fields inherited from class org.mmbase.security.Authorization |
|---|
COMPLETE_CHECK, NO_CHECK |
| Fields inherited from class org.mmbase.security.Configurable |
|---|
configResource, configWatcher, manager |
| Constructor Summary | |
|---|---|
Verify()
|
|
| Method Summary | |
|---|---|
boolean |
check(UserContext user,
int nodeid,
int srcnodeid,
int dstnodeid,
Operation operation)
This method should be overrided by an extending class. |
boolean |
check(UserContext user,
int nodeid,
Operation operation)
This method should be overrided by an extending class. |
Authorization.QueryCheck |
check(UserContext user,
Query query,
Operation operation)
Checks rights on a query. |
void |
create(UserContext user,
int nodeid)
This method should be overrided by an extending class. |
String |
getContext(UserContext user,
int nodeid)
This method could be overrided by an extending class. |
Set<String> |
getPossibleContexts(UserContext user,
int nodeid)
This method could be overrided by an extending class. |
protected void |
load()
This method should be overridden by an extending class. |
void |
remove(UserContext user,
int nodeid)
This method should be overrided by an extending class. |
void |
setContext(UserContext user,
int nodeid,
String context)
This method could be overrided by an extending class. |
void |
update(UserContext user,
int nodeid)
This method should be overrided by an extending class. |
| Methods inherited from class org.mmbase.security.Authorization |
|---|
check, getPossibleContexts, verify, verify, verify |
| Methods inherited from class org.mmbase.security.Configurable |
|---|
load |
| Methods inherited from class java.lang.Object |
|---|
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait |
| Constructor Detail |
|---|
public Verify()
| Method Detail |
|---|
protected void load()
Configurable
load in class Configurable
public void create(UserContext user,
int nodeid)
Authorization
create in class Authorizationuser - The UserContext, containing the information
about the user.nodeid - The id of the MMObjectNode, which has just been added to
the MMBase cloud.
public void update(UserContext user,
int nodeid)
Authorization
update in class Authorizationuser - The UserContext, containing the information about the user.nodeid - The id of the MMObjectNode, which has just been changed
in the cloud.
public void remove(UserContext user,
int nodeid)
Authorization
remove in class Authorizationuser - The UserContext, containing the information
about the user.nodeid - The id of the MMObjectNode, which has just been removed
in the cloud.
public boolean check(UserContext user,
int nodeid,
Operation operation)
Authorization
check in class Authorizationuser - The UserContext, containing the information the user.nodeid - The id of the MMObjectNode, which has to be checked.
It the action is CREATE then this will be interpreted as a typedef node.operation - The operation which will be performed.
true if the operation is permitted,
false if the operation is not permitted,
public boolean check(UserContext user,
int nodeid,
int srcnodeid,
int dstnodeid,
Operation operation)
Authorization
check in class Authorizationuser - The UserContext, containing the information about the user.nodeid - The id of the relation which has to be checked. If the operation is CREATE
then this will be interpreted as the typedef node (extending insrel) for the relation to be
created.srcnodeid - The id of the (new) source node of the relation.dstnodeid - The id of the (new) destination node of the relation.operation - The operation which will be performed (CREATE (create
relation) or CHANGE_RELATION (source and/or destination
are changed).
true if the operation is permitted,
false if the operation is not permitted,
public String getContext(UserContext user,
int nodeid)
throws SecurityException
Authorization
getContext in class Authorizationuser - The UserContext, containing the information about the user.nodeid - The id of the MMObjectNode, which has to be asserted.
SecurityException - If operation is not allowed(needs read rights)
public void setContext(UserContext user,
int nodeid,
String context)
throws SecurityException
Authorization
setContext in class Authorizationuser - The UserContext, containing the information about the user.nodeid - The id of the MMObjectNode, which has to be asserted.context - The context which rights the node will get
SecurityException - If operation is not allowed
public Set<String> getPossibleContexts(UserContext user,
int nodeid)
throws SecurityException
Authorization
getPossibleContexts in class Authorizationuser - The UserContext, containing the information
about the user.nodeid - The id of the MMObjectNode, which has to be asserted.
Set of Strings which
represent a context in readable form..
SecurityException
public Authorization.QueryCheck check(UserContext user,
Query query,
Operation operation)
Authorization
check in class Authorizationuser - The UserContext, for which the query must be consideredquery - The query to be explored
Authorization.QueryCheck structure (containing whether the constriant is sufficient, and the
new constraint or null).
|
||||||||||
| PREV CLASS NEXT CLASS | FRAMES NO FRAMES | |||||||||
| SUMMARY: NESTED | FIELD | CONSTR | METHOD | DETAIL: FIELD | CONSTR | METHOD | |||||||||