From b55030a765f040a15609c60d3f69b6cb7f00bdae Mon Sep 17 00:00:00 2001 From: James Moger <james.moger@gitblit.com> Date: Sat, 16 Apr 2011 09:27:57 -0400 Subject: [PATCH] More flexible authentication. Anonymous view, authenticated admin. --- src/com/gitblit/wicket/AuthorizationStrategy.java | 30 +++++++++++++++++++++++++++--- 1 files changed, 27 insertions(+), 3 deletions(-) diff --git a/src/com/gitblit/wicket/AuthorizationStrategy.java b/src/com/gitblit/wicket/AuthorizationStrategy.java index 0a9d652..3e7df36 100644 --- a/src/com/gitblit/wicket/AuthorizationStrategy.java +++ b/src/com/gitblit/wicket/AuthorizationStrategy.java @@ -5,6 +5,8 @@ import org.apache.wicket.authorization.IUnauthorizedComponentInstantiationListener; import org.apache.wicket.authorization.strategies.page.AbstractPageAuthorizationStrategy; +import com.gitblit.GitBlit; +import com.gitblit.Keys; import com.gitblit.wicket.pages.RepositoriesPage; public class AuthorizationStrategy extends AbstractPageAuthorizationStrategy implements IUnauthorizedComponentInstantiationListener { @@ -16,12 +18,34 @@ @Override protected boolean isPageAuthorized(Class pageClass) { if (BasePage.class.isAssignableFrom(pageClass)) { - GitBlitWebSession session = GitBlitWebSession.get(); - if (!session.isLoggedIn()) + boolean authenticateView = GitBlit.self().settings().getBoolean(Keys.web.authenticateViewPages, true); + boolean authenticateAdmin = GitBlit.self().settings().getBoolean(Keys.web.authenticateAdminPages, true); + boolean allowAdmin = GitBlit.self().settings().getBoolean(Keys.web.allowAdministration, true); + + GitBlitWebSession session = GitBlitWebSession.get(); + if (authenticateView && !session.isLoggedIn()) { + // authentication required return false; + } + User user = session.getUser(); if (pageClass.isAnnotationPresent(AdminPage.class)) { - return user.canAdmin(); + // admin page + if (allowAdmin) { + if (authenticateAdmin) { + // authenticate admin + if (user != null) { + return user.canAdmin(); + } + return false; + } else { + // no admin authentication required + return true; + } + } else { + //admin prohibited + return false; + } } } return true; -- Gitblit v1.9.1