| | |
| | | /*
|
| | | * Copyright 2011 gitblit.com.
|
| | | *
|
| | | * Licensed under the Apache License, Version 2.0 (the "License");
|
| | | * you may not use this file except in compliance with the License.
|
| | | * You may obtain a copy of the License at
|
| | | *
|
| | | * http://www.apache.org/licenses/LICENSE-2.0
|
| | | *
|
| | | * Unless required by applicable law or agreed to in writing, software
|
| | | * distributed under the License is distributed on an "AS IS" BASIS,
|
| | | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
| | | * See the License for the specific language governing permissions and
|
| | | * limitations under the License.
|
| | | */
|
| | | package com.gitblit;
|
| | |
|
| | | import java.io.File;
|
| | |
| | | return null;
|
| | | }
|
| | | UserModel user = new UserModel(username);
|
| | | user.canAdmin(identity.isUserInRole(Constants.ADMIN_ROLE, null));
|
| | | user.canAdmin = identity.isUserInRole(Constants.ADMIN_ROLE, null);
|
| | |
|
| | | // Add repositories
|
| | | for (Principal principal : identity.getSubject().getPrincipals()) {
|
| | |
| | | case '#':
|
| | | // Permissions
|
| | | if (name.equalsIgnoreCase(Constants.ADMIN_ROLE)) {
|
| | | model.canAdmin(true);
|
| | | model.canAdmin = true;
|
| | | }
|
| | | break;
|
| | | default:
|
| | |
| | | Properties allUsers = readRealmFile();
|
| | | String value = allUsers.getProperty(username);
|
| | | String password = value.split(",")[0];
|
| | | model.setPassword(password);
|
| | | model.password = password;
|
| | | } catch (Throwable t) {
|
| | | logger.error(MessageFormat.format("Failed to read password for user {0}!", username), t);
|
| | | }
|
| | |
| | |
|
| | | @Override
|
| | | public boolean updateUserModel(UserModel model) {
|
| | | return updateUserModel(model.getUsername(), model);
|
| | | return updateUserModel(model.username, model);
|
| | | }
|
| | | |
| | |
|
| | | @Override
|
| | | public boolean updateUserModel(String username, UserModel model) {
|
| | | try {
|
| | | Properties allUsers = readRealmFile();
|
| | | ArrayList<String> roles = new ArrayList<String>(model.getRepositories());
|
| | | ArrayList<String> roles = new ArrayList<String>(model.repositories);
|
| | |
|
| | | // Permissions
|
| | | if (model.canAdmin()) {
|
| | | if (model.canAdmin) {
|
| | | roles.add(Constants.ADMIN_ROLE);
|
| | | }
|
| | |
|
| | | StringBuilder sb = new StringBuilder();
|
| | | sb.append(model.getPassword());
|
| | | sb.append(model.password);
|
| | | sb.append(',');
|
| | | for (String role : roles) {
|
| | | sb.append(role);
|
| | |
| | | // trim trailing comma
|
| | | sb.setLength(sb.length() - 1);
|
| | | allUsers.remove(username);
|
| | | allUsers.put(model.getUsername(), sb.toString());
|
| | | allUsers.put(model.username, sb.toString());
|
| | |
|
| | | writeRealmFile(allUsers);
|
| | |
|
| | | // Update login service
|
| | | removeUser(username);
|
| | | putUser(model.getUsername(), Credential.getCredential(model.getPassword()), roles.toArray(new String[0]));
|
| | | putUser(model.username, Credential.getCredential(model.password),
|
| | | roles.toArray(new String[0]));
|
| | | return true;
|
| | | } catch (Throwable t) {
|
| | | logger.error(MessageFormat.format("Failed to update user model {0}!", model.getUsername()), t);
|
| | | logger.error(MessageFormat.format("Failed to update user model {0}!", model.username),
|
| | | t);
|
| | | }
|
| | | return false;
|
| | | }
|
| | |
|
| | | @Override
|
| | | public boolean deleteUserModel(UserModel model) {
|
| | | return deleteUser(model.getUsername());
|
| | | return deleteUser(model.username);
|
| | | }
|
| | |
|
| | | @Override
|
| | |
| | | }
|
| | | return false;
|
| | | }
|
| | | |
| | |
|
| | | @Override
|
| | | public List<String> getAllUsernames() {
|
| | | List<String> list = new ArrayList<String>();
|
| | |
| | | // add roles to users
|
| | | for (String user : needsAddRole) {
|
| | | String userValues = allUsers.getProperty(user);
|
| | | userValues += ("," + role);
|
| | | userValues += "," + role;
|
| | | allUsers.put(user, userValues);
|
| | | String[] values = userValues.split(",");
|
| | | String password = values[0];
|
| | |
| | | allUsers.put(user, sb.toString());
|
| | |
|
| | | // update memory
|
| | | putUser(user, Credential.getCredential(password), revisedRoles.toArray(new String[0]));
|
| | | putUser(user, Credential.getCredential(password),
|
| | | revisedRoles.toArray(new String[0]));
|
| | | }
|
| | |
|
| | | // persist changes
|
| | |
| | | allUsers.put(user, sb.toString());
|
| | |
|
| | | // update memory
|
| | | putUser(user, Credential.getCredential(password), revisedRoles.toArray(new String[0]));
|
| | | putUser(user, Credential.getCredential(password),
|
| | | revisedRoles.toArray(new String[0]));
|
| | | }
|
| | |
|
| | | // persist changes
|
| | | writeRealmFile(allUsers);
|
| | | return true;
|
| | | } catch (Throwable t) {
|
| | | logger.error(MessageFormat.format("Failed to rename role {0} to {1}!", oldRole, newRole), t);
|
| | | logger.error(
|
| | | MessageFormat.format("Failed to rename role {0} to {1}!", oldRole, newRole), t);
|
| | | }
|
| | | return false;
|
| | | }
|
| | |
| | | allUsers.put(user, sb.toString());
|
| | |
|
| | | // update memory
|
| | | putUser(user, Credential.getCredential(password), revisedRoles.toArray(new String[0]));
|
| | | putUser(user, Credential.getCredential(password),
|
| | | revisedRoles.toArray(new String[0]));
|
| | | }
|
| | |
|
| | | // persist changes
|
| | |
| | | // Update realm file
|
| | | File realmFileCopy = new File(realmFile.getAbsolutePath() + ".tmp");
|
| | | FileWriter writer = new FileWriter(realmFileCopy);
|
| | | properties.store(writer, "# Git:Blit realm file format: username=password,\\#permission,repository1,repository2...");
|
| | | properties
|
| | | .store(writer,
|
| | | "# Git:Blit realm file format: username=password,\\#permission,repository1,repository2...");
|
| | | writer.close();
|
| | | if (realmFileCopy.exists() && realmFileCopy.length() > 0) {
|
| | | realmFile.delete();
|
| | | realmFileCopy.renameTo(realmFile);
|
| | | if (realmFile.delete()) {
|
| | | if (!realmFileCopy.renameTo(realmFile)) {
|
| | | throw new IOException(MessageFormat.format("Failed to rename {0} to {1}!",
|
| | | realmFileCopy.getAbsolutePath(), realmFile.getAbsolutePath()));
|
| | | }
|
| | | } else {
|
| | | throw new IOException(MessageFormat.format("Failed to delete (0)!",
|
| | | realmFile.getAbsolutePath()));
|
| | | }
|
| | | } else {
|
| | | throw new IOException("Failed to save realmfile!");
|
| | | throw new IOException(MessageFormat.format("Failed to save {0}!",
|
| | | realmFileCopy.getAbsolutePath()));
|
| | | }
|
| | | }
|
| | |
|
| | | /* ------------------------------------------------------------ */
|
| | | @Override
|
| | | public void loadUsers() throws IOException {
|
| | | if (realmFile == null)
|
| | | if (realmFile == null) {
|
| | | return;
|
| | | }
|
| | |
|
| | | if (Log.isDebugEnabled())
|
| | | if (Log.isDebugEnabled()) {
|
| | | Log.debug("Load " + this + " from " + realmFile);
|
| | | }
|
| | | Properties allUsers = readRealmFile();
|
| | |
|
| | | // Map Users
|
| | |
| | | credentials = credentials.substring(0, c).trim();
|
| | | }
|
| | |
|
| | | if (username != null && username.length() > 0 && credentials != null && credentials.length() > 0) {
|
| | | if (username != null && username.length() > 0 && credentials != null
|
| | | && credentials.length() > 0) {
|
| | | String[] roleArray = IdentityService.NO_ROLES;
|
| | | if (roles != null && roles.length() > 0) {
|
| | | roleArray = roles.split(",");
|