1 |
|
|
2 |
|
|
3 |
|
|
4 |
|
|
5 |
|
|
6 |
|
|
7 |
|
|
8 |
|
|
9 |
|
|
10 |
|
|
11 |
|
|
12 |
|
|
13 |
|
|
14 |
|
|
15 |
|
|
16 |
|
|
17 |
|
|
18 |
|
|
19 |
|
|
20 |
|
package org.xwiki.extension.internal.validator; |
21 |
|
|
22 |
|
import javax.inject.Inject; |
23 |
|
import javax.inject.Named; |
24 |
|
|
25 |
|
import org.apache.commons.lang3.EnumUtils; |
26 |
|
import org.xwiki.component.namespace.Namespace; |
27 |
|
import org.xwiki.component.namespace.NamespaceUtils; |
28 |
|
import org.xwiki.extension.Extension; |
29 |
|
import org.xwiki.extension.InstallException; |
30 |
|
import org.xwiki.extension.InstalledExtension; |
31 |
|
import org.xwiki.extension.UninstallException; |
32 |
|
import org.xwiki.extension.handler.ExtensionValidator; |
33 |
|
import org.xwiki.job.Request; |
34 |
|
import org.xwiki.model.EntityType; |
35 |
|
import org.xwiki.model.reference.DocumentReference; |
36 |
|
import org.xwiki.model.reference.EntityReference; |
37 |
|
import org.xwiki.model.reference.EntityReferenceResolver; |
38 |
|
import org.xwiki.security.authorization.AccessDeniedException; |
39 |
|
import org.xwiki.security.authorization.AuthorizationManager; |
40 |
|
import org.xwiki.security.authorization.Right; |
41 |
|
|
42 |
|
|
43 |
|
@link |
44 |
|
|
45 |
|
@version |
46 |
|
@since |
47 |
|
|
|
|
| 74% |
Uncovered Elements: 19 (73) |
Complexity: 25 |
Complexity Density: 0.62 |
|
48 |
|
public abstract class AbstractExtensionValidator implements ExtensionValidator |
49 |
|
{ |
50 |
|
|
51 |
|
|
52 |
|
|
53 |
|
public static final String PROPERTY_USERREFERENCE = "user.reference"; |
54 |
|
|
55 |
|
|
56 |
|
|
57 |
|
|
58 |
|
public static final String PROPERTY_CALLERREFERENCE = "caller.reference"; |
59 |
|
|
60 |
|
|
61 |
|
|
62 |
|
|
63 |
|
public static final String PROPERTY_CHECKRIGHTS = "checkrights"; |
64 |
|
|
65 |
|
@Inject |
66 |
|
protected AuthorizationManager authorization; |
67 |
|
|
68 |
|
@Inject |
69 |
|
@Named("relative") |
70 |
|
protected EntityReferenceResolver<String> resolver; |
71 |
|
|
72 |
|
protected Right entityRight = Right.PROGRAM; |
73 |
|
|
74 |
|
|
75 |
|
@param |
76 |
|
@param |
77 |
|
@return |
78 |
|
|
|
|
| 66.7% |
Uncovered Elements: 2 (6) |
Complexity: 2 |
Complexity Density: 0.5 |
|
79 |
483 |
public static DocumentReference getRequestUserReference(String property, Request request)... |
80 |
|
{ |
81 |
483 |
Object obj = request.getProperty(property); |
82 |
|
|
83 |
483 |
if (obj instanceof DocumentReference) { |
84 |
483 |
return (DocumentReference) obj; |
85 |
|
} |
86 |
|
|
87 |
0 |
return null; |
88 |
|
} |
89 |
|
|
|
|
| 100% |
Uncovered Elements: 0 (2) |
Complexity: 1 |
Complexity Density: 0.5 |
|
90 |
323 |
protected void checkAccess(EntityReference reference, Right right, Request request) throws AccessDeniedException... |
91 |
|
{ |
92 |
|
|
93 |
323 |
checkAccess(PROPERTY_CALLERREFERENCE, reference, right, request); |
94 |
|
|
95 |
|
|
96 |
323 |
checkAccess(PROPERTY_USERREFERENCE, reference, right, request); |
97 |
|
} |
98 |
|
|
|
|
| 100% |
Uncovered Elements: 0 (4) |
Complexity: 2 |
Complexity Density: 1 |
|
99 |
646 |
private void checkAccess(String propertyCallerreference, EntityReference reference, Right right, Request request)... |
100 |
|
throws AccessDeniedException |
101 |
|
{ |
102 |
646 |
if (request.getProperty(propertyCallerreference) != null) { |
103 |
483 |
this.authorization.checkAccess(right, getRequestUserReference(propertyCallerreference, request), reference); |
104 |
|
} |
105 |
|
} |
106 |
|
|
|
|
| 100% |
Uncovered Elements: 0 (4) |
Complexity: 2 |
Complexity Density: 1 |
|
107 |
142 |
@Override... |
108 |
|
public void checkInstall(Extension extension, String namespace, Request request) throws InstallException |
109 |
|
{ |
110 |
142 |
if (request.getProperty(PROPERTY_CHECKRIGHTS) == Boolean.TRUE) { |
111 |
138 |
checkInstallInternal(extension, namespace, request); |
112 |
|
} |
113 |
|
} |
114 |
|
|
|
|
| 100% |
Uncovered Elements: 0 (1) |
Complexity: 1 |
Complexity Density: 1 |
|
115 |
187 |
protected void checkAccess(Extension extension, String namespaceString, Request request)... |
116 |
|
throws AccessDeniedException |
117 |
|
{ |
118 |
187 |
checkAccess(this.entityRight, namespaceString, request); |
119 |
|
} |
120 |
|
|
|
|
| 81% |
Uncovered Elements: 4 (21) |
Complexity: 5 |
Complexity Density: 0.38 |
|
121 |
187 |
protected void checkAccess(Right entityRight, String namespaceString, Request request) throws AccessDeniedException... |
122 |
|
{ |
123 |
187 |
Namespace namespace = NamespaceUtils.toNamespace(namespaceString); |
124 |
|
|
125 |
|
|
126 |
187 |
if (namespace == null) { |
127 |
41 |
checkRootRight(entityRight, request); |
128 |
|
|
129 |
37 |
return; |
130 |
|
} |
131 |
|
|
132 |
146 |
if (namespace.getType() != null) { |
133 |
|
|
134 |
138 |
if (namespace.getType().equals("user")) { |
135 |
0 |
EntityReference reference = this.resolver.resolve(namespace.getValue(), EntityType.DOCUMENT); |
136 |
|
|
137 |
0 |
checkUserRight(reference, request); |
138 |
|
} |
139 |
|
|
140 |
|
|
141 |
138 |
EntityType entityType = EnumUtils.getEnum(EntityType.class, namespace.getType().toUpperCase()); |
142 |
138 |
if (entityType != null) { |
143 |
138 |
EntityReference reference = this.resolver.resolve(namespace.getValue(), entityType); |
144 |
|
|
145 |
138 |
checkAccess(reference, entityRight, request); |
146 |
|
} |
147 |
|
} |
148 |
|
|
149 |
|
|
150 |
144 |
checkNamespaceRight(namespace, Right.PROGRAM, request); |
151 |
|
} |
152 |
|
|
|
|
| 100% |
Uncovered Elements: 0 (3) |
Complexity: 2 |
Complexity Density: 0.67 |
|
153 |
136 |
protected void checkInstallInternal(Extension extension, String namespace, Request request) throws InstallException... |
154 |
|
{ |
155 |
136 |
try { |
156 |
136 |
checkAccess(extension, namespace, request); |
157 |
|
} catch (AccessDeniedException e) { |
158 |
4 |
throw new InstallException(String.format("Install of extension [%s] is not allowed", extension.getId()), e); |
159 |
|
} |
160 |
|
} |
161 |
|
|
|
|
| 100% |
Uncovered Elements: 0 (1) |
Complexity: 1 |
Complexity Density: 1 |
|
162 |
41 |
private void checkRootRight(Right entityRight, Request request) throws AccessDeniedException... |
163 |
|
{ |
164 |
|
|
165 |
41 |
checkAccess(null, entityRight, request); |
166 |
|
} |
167 |
|
|
|
|
| 0% |
Uncovered Elements: 2 (2) |
Complexity: 1 |
Complexity Density: 0.5 |
|
168 |
0 |
private void checkUserRight(EntityReference reference, Request request) throws AccessDeniedException... |
169 |
|
{ |
170 |
|
|
171 |
0 |
checkUserAccess(PROPERTY_CALLERREFERENCE, reference, request); |
172 |
|
|
173 |
|
|
174 |
0 |
checkUserAccess(PROPERTY_USERREFERENCE, reference, request); |
175 |
|
} |
176 |
|
|
|
|
| 0% |
Uncovered Elements: 8 (8) |
Complexity: 3 |
Complexity Density: 0.75 |
|
177 |
0 |
private void checkUserAccess(String property, EntityReference reference, Request request)... |
178 |
|
throws AccessDeniedException |
179 |
|
{ |
180 |
0 |
if (request.getProperty(property) != null) { |
181 |
|
|
182 |
0 |
DocumentReference currentAuthorReference = getRequestUserReference(property, request); |
183 |
|
|
184 |
0 |
if (!currentAuthorReference.equals(reference)) { |
185 |
|
|
186 |
0 |
checkAccess(null, Right.PROGRAM, request); |
187 |
|
} |
188 |
|
} |
189 |
|
} |
190 |
|
|
|
|
| 100% |
Uncovered Elements: 0 (1) |
Complexity: 1 |
Complexity Density: 1 |
|
191 |
144 |
private void checkNamespaceRight(Namespace namespace, Right program, Request request) throws AccessDeniedException... |
192 |
|
{ |
193 |
|
|
194 |
144 |
checkAccess(null, Right.PROGRAM, request); |
195 |
|
} |
196 |
|
|
|
|
| 75% |
Uncovered Elements: 1 (4) |
Complexity: 2 |
Complexity Density: 1 |
|
197 |
53 |
@Override... |
198 |
|
public void checkUninstall(InstalledExtension extension, String namespace, Request request) |
199 |
|
throws UninstallException |
200 |
|
{ |
201 |
53 |
if (request.getProperty(PROPERTY_CHECKRIGHTS) == Boolean.TRUE) { |
202 |
53 |
checkUninstallInternal(extension, namespace, request); |
203 |
|
} |
204 |
|
} |
205 |
|
|
|
|
| 100% |
Uncovered Elements: 0 (3) |
Complexity: 2 |
Complexity Density: 0.67 |
|
206 |
51 |
protected void checkUninstallInternal(InstalledExtension extension, String namespace, Request request)... |
207 |
|
throws UninstallException |
208 |
|
{ |
209 |
51 |
try { |
210 |
51 |
checkAccess(extension, namespace, request); |
211 |
|
} catch (AccessDeniedException e) { |
212 |
4 |
throw new UninstallException(String.format("Uninstall of extension [%s] is not allowed", extension.getId()), |
213 |
|
e); |
214 |
|
} |
215 |
|
} |
216 |
|
} |