-
-
Notifications
You must be signed in to change notification settings - Fork 224
Expand file tree
/
Copy pathtaccessvalidator.cpp
More file actions
217 lines (190 loc) · 6.17 KB
/
taccessvalidator.cpp
File metadata and controls
217 lines (190 loc) · 6.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
/* Copyright (c) 2011-2019, AOYAMA Kazuharu
* All rights reserved.
*
* This software may be used and distributed according to the terms of
* the New BSD License, which is incorporated herein by reference.
*/
#include <TAbstractUser>
#include <TAccessValidator>
#include <TActionContext>
#include <TActionController>
#include <TSystemGlobal>
/*!
\class TAccessValidator
The TAccessValidator class provides validation of user access.
\sa TAbstractUser class
*/
/*!
Constructor.
*/
TAccessValidator::TAccessValidator()
{
}
/*!
Sets to allow a group with \a groupKey to access to the action \a action.
*/
void TAccessValidator::setAllowGroup(const QString &groupKey, const QString &action)
{
accessRules << AccessRule(AccessRule::Group, groupKey, action, true);
}
/*!
Sets to allow a group with \a groupKey to access to the actions \a actions.
*/
void TAccessValidator::setAllowGroup(const QString &groupKey, const QStringList &actions)
{
addRules(AccessRule::Group, groupKey, actions, true);
}
/*!
Sets to deny a group with \a groupKey to access to the action \a action.
*/
void TAccessValidator::setDenyGroup(const QString &groupKey, const QString &action)
{
accessRules << AccessRule(AccessRule::Group, groupKey, action, false);
}
/*!
Sets to deny a group with \a groupKey to access to the actions \a actions.
*/
void TAccessValidator::setDenyGroup(const QString &groupKey, const QStringList &actions)
{
addRules(AccessRule::Group, groupKey, actions, false);
}
/*!
Sets to allow a user with the identity \a identityKey to access to
the action \a action.
*/
void TAccessValidator::setAllowUser(const QString &identityKey, const QString &action)
{
accessRules << AccessRule(AccessRule::User, identityKey, action, true);
}
/*!
Sets to allow a user with the identity \a identityKey to access to
the actions \a actions.
*/
void TAccessValidator::setAllowUser(const QString &identityKey, const QStringList &actions)
{
addRules(AccessRule::User, identityKey, actions, true);
}
/*!
Sets to deny a user with the identity \a identityKey to access to
the action \a action.
*/
void TAccessValidator::setDenyUser(const QString &identityKey, const QString &action)
{
accessRules << AccessRule(AccessRule::User, identityKey, action, false);
}
/*!
Sets to deny a user with the identity \a identityKey to access to
the actions \a actions.
*/
void TAccessValidator::setDenyUser(const QString &identityKey, const QStringList &actions)
{
addRules(AccessRule::User, identityKey, actions, false);
}
/*!
Sets to allow an unauthenticated user with the identity \a identityKey
to access to the action \a action.
*/
void TAccessValidator::setAllowUnauthenticatedUser(const QString &action)
{
accessRules << AccessRule(AccessRule::UnauthenticatedUser, QString(), action, true);
}
/*!
Sets to allow an unauthenticated with the identity \a identityKey to
access to the actions \a actions.
*/
void TAccessValidator::setAllowUnauthenticatedUser(const QStringList &actions)
{
addRules(AccessRule::UnauthenticatedUser, QString(), actions, true);
}
/*!
Sets to deny an unauthenticated with the identity \a identityKey to
access to the action \a action.
*/
void TAccessValidator::setDenyUnauthenticatedUser(const QString &action)
{
accessRules << AccessRule(AccessRule::UnauthenticatedUser, QString(), action, false);
}
/*!
Sets to deny an unauthenticated with the identity \a identityKey to
access to the actions \a actions.
*/
void TAccessValidator::setDenyUnauthenticatedUser(const QStringList &actions)
{
addRules(AccessRule::UnauthenticatedUser, QString(), actions, false);
}
/*!
Added a access rule to the list.
*/
void TAccessValidator::addRules(int type, const QString &key, const QStringList &actions, bool allow)
{
for (auto &act : actions) {
accessRules << AccessRule(type, key, act, allow);
}
}
/*!
Returns true if the user \a user is allowed to access to the requested
action; otherwise returns false.
*/
bool TAccessValidator::validate(const TAbstractUser *user, const TActionController *controller) const
{
bool ret = allowDefault;
Q_ASSERT(controller);
if (accessRules.isEmpty()) {
Tf::warn("No rule for access validation: {}", controller->className());
return ret;
}
if (!user || user->identityKey().isEmpty()) {
// Searches a access rule for an unauthenticated user
for (const auto &rule : accessRules) {
if (rule.type == AccessRule::UnauthenticatedUser
&& rule.action == controller->activeAction()) {
ret = rule.allow;
break;
}
}
if (ret) {
tSystemDebug("Access '{}' action by an unauthenticated user : Allow", controller->activeAction());
} else {
tSystemWarn("Access '{}' action by an unauthenticated user : Deny", controller->activeAction());
}
} else {
for (const auto &rule : accessRules) {
if (rule.action == controller->activeAction()
&& ((rule.type == AccessRule::User && rule.key == user->identityKey())
|| (!user->groupKey().isEmpty() && rule.key == user->groupKey()))) {
ret = rule.allow;
break;
}
}
if (ret) {
tSystemDebug("Access '{}' action by '{}' user : Allow", controller->activeAction(), user->identityKey());
} else {
tSystemWarn("Access '{}' action by '{}' user : Deny", controller->activeAction(), user->identityKey());
}
}
return ret;
}
/*!
Removes all access rules from the list.
*/
void TAccessValidator::clear()
{
accessRules.clear();
allowDefault = true;
}
/*!
\fn void TAccessValidator::setAllowDefault(bool allow)
Sets the default rule to allow all users to access to all actions
if \a allow is true; otherwise sets to deny any user to access
to any action. The default rule is true.
*/
/*!
\fn void TAccessValidator::setDenyDefault(bool deny)
Sets the default rule to deny any user to access to any action
if \a deny is true; otherwise sets to allow all users to access
to all actions.
*/
/*!
\class TAccessValidator::AccessRule
The AccessRule class is for internal use only.
*/