PermissionBean.java 6.68 KB
package fi.insomnia.bortal.beans;

import java.security.Principal;

import javax.annotation.Resource;
import javax.annotation.security.DeclareRoles;
import javax.ejb.EJB;
import javax.ejb.LocalBean;
import javax.ejb.SessionContext;
import javax.ejb.Stateless;
import javax.resource.spi.IllegalStateException;

import org.slf4j.Logger;
import org.slf4j.LoggerFactory;

import fi.insomnia.bortal.enums.apps.BillPermission;
import fi.insomnia.bortal.enums.apps.CompoPermission;
import fi.insomnia.bortal.enums.apps.ContentPermission;
import fi.insomnia.bortal.enums.apps.EventPermission;
import fi.insomnia.bortal.enums.apps.IAppPermission;
import fi.insomnia.bortal.enums.apps.MapPermission;
import fi.insomnia.bortal.enums.apps.PollPermission;
import fi.insomnia.bortal.enums.apps.ShopPermission;
import fi.insomnia.bortal.enums.apps.SpecialPermission;
import fi.insomnia.bortal.enums.apps.TerminalPermission;
import fi.insomnia.bortal.enums.apps.UserPermission;
import fi.insomnia.bortal.facade.EventUserFacade;
import fi.insomnia.bortal.facade.UserFacade;
import fi.insomnia.bortal.model.EventUser;
import fi.insomnia.bortal.model.User;

@Stateless
@DeclareRoles({
		UserPermission.S_CREATE_NEW,
		UserPermission.S_LOGIN,
		UserPermission.S_LOGOUT,
		UserPermission.S_MODIFY,
		UserPermission.S_MODIFY_ACCOUNTEVENTS,
		UserPermission.S_VIEW_ACCOUNTEVENTS,
		UserPermission.S_VIEW_ALL,
		UserPermission.S_VIEW_SELF,
		UserPermission.S_WRITE_ROLES,
		UserPermission.S_READ_ROLES,
		UserPermission.S_ANYUSER,
		UserPermission.S_MANAGE_HTTP_SESSION,
		UserPermission.S_INVITE_USERS,
		UserPermission.S_READ_ORGROLES,
		UserPermission.S_WRITE_ORGROLES,
		UserPermission.S_VITUTTAAKO,

		MapPermission.S_VIEW,
		MapPermission.S_MANAGE_MAPS,
		MapPermission.S_MANAGE_OTHERS,
		MapPermission.S_BUY_PLACES,
		MapPermission.S_RELEASE_PLACE,

		ShopPermission.S_LIST_ALL_PRODUCTS,
		ShopPermission.S_LIST_USERPRODUCTS,
		ShopPermission.S_SHOP_TO_OTHERS,
		ShopPermission.S_MANAGE_PRODUCTS,
		ShopPermission.S_SHOP_PRODUCTS,
		ShopPermission.S_SHOP_FOODWAVE,
		ShopPermission.S_MANAGE_FOODWAVES,

		BillPermission.S_CREATE_BILL,
		BillPermission.S_READ_ALL,
		BillPermission.S_WRITE_ALL,
		BillPermission.S_VIEW_OWN,

		ContentPermission.S_MANAGE_NEWS,
		ContentPermission.S_MANAGE_PAGES,
		ContentPermission.S_MANAGE_ACTIONLOG,
		ContentPermission.S_MANAGE_MENU,

		PollPermission.S_ANSWER,
		PollPermission.S_VIEW_RESULTS,
		PollPermission.S_CREATE,

		SpecialPermission.S_SUPERADMIN,
		SpecialPermission.S_USER,
		SpecialPermission.S_ANONYMOUS,

		TerminalPermission.S_CASHIER_TERMINAL,
		TerminalPermission.S_CUSTOMER_TERMINAL,
		TerminalPermission.S_SELFHELP_TERMINAL,

		CompoPermission.S_MANAGE,
		CompoPermission.S_VOTE,
		CompoPermission.S_SUBMIT_ENTRY,
		CompoPermission.S_VIEW_COMPOS,

		EventPermission.S_MANAGE_PRIVATE_PROPERTIES,
		EventPermission.S_MANAGE_PROPERTIES,

})
@LocalBean
public class PermissionBean implements PermissionBeanLocal {

	private static final Logger logger = LoggerFactory.getLogger(PermissionBean.class);

	@Resource
	private SessionContext context;

	@EJB
	private LoggingBeanLocal loggingbean;

	@EJB
	private UserFacade userfacade;

	@EJB
	private EventUserFacade eventUserFacade;

	@EJB
	private EventBeanLocal eventbean;

	//
	// @Override
	// public boolean hasPermission(String perm) {
	// return context.isCallerInRole(perm);
	// }

	@Override
	public boolean hasPermission(IAppPermission perm) {

		if (perm == null)
		{
			return false;
		}
		return context.isCallerInRole(perm.getFullName());

	}

	// @Override
	// public boolean fatalPermission(IAppPermission permission, Object...
	// failmessage) {
	// boolean ret = hasPermission(permission);
	// if (!ret) {
	// StringBuilder message = new
	// StringBuilder().append(" permission: ").append(permission);
	// if (failmessage == null || failmessage.length == 0) {
	// message.append(" MSG: SessionHandler mbean permission exception: Permission: ")
	// .append(permission);
	// } else {
	// for (Object part : failmessage) {
	// message.append(part == null ? "NULL" : part.toString());
	// }
	// }
	// // throw new SecurityException("Foobar");
	//
	// throw new PermissionDeniedException(loggingbean, getCurrentUser(),
	// message.toString());
	// }
	// return true;
	// }
	//
	// @Override
	// public void fatalNotLoggedIn() throws PermissionDeniedException {
	// if (!isLoggedIn()) {
	// throw new PermissionDeniedException(loggingbean, getCurrentUser(),
	// "User is not logged in!");
	// }
	// }

	@Override
	public boolean isCurrentUser(User user) {
		return (context.getCallerPrincipal() == null || user == null) ? false : context.getCallerPrincipal().getName().equals(user.getLogin());
	}

	@Override
	public boolean isCurrentUser(EventUser user) {
		return user != null && isCurrentUser(user.getUser());
	}

	@Override
	public boolean isLoggedIn() {

		return !getAnonEventUser().equals(getCurrentUser()) || getCurrentUser().getUser().isSuperadmin();
	}

	@Override
	public EventUser getCurrentUser() {
		Principal principal = context.getCallerPrincipal();

		EventUser ret = eventUserFacade.findByLogin(principal.getName());
		if (ret == null) {
			ret = getAnonEventUser();
		}
		return ret;
	}

	/**
	 * Makes sure default user and public role exist and the user is member of
	 * the role.
	 */
	@Override
	public EventUser getAnonEventUser() {
		EventUser defaultUser = eventUserFacade.findByLogin(User.ANONYMOUS_LOGINNAME);
		if (defaultUser == null) {
			User user = userfacade.findByLogin(User.ANONYMOUS_LOGINNAME);
			if (user == null)
			{
				defaultUser = new EventUser(new User(), eventbean.getCurrentEvent(), null);
				defaultUser.getUser().setLogin(User.ANONYMOUS_LOGINNAME);
				defaultUser.getUser().setNick(User.ANONYMOUS_LOGINNAME);

			} else {
				defaultUser = new EventUser(user, eventbean.getCurrentEvent(), null);
			}
			eventUserFacade.create(defaultUser);
			eventUserFacade.flush();

		}
		return defaultUser;
	}

	public String getPrincipal() {

		Principal principal = context.getCallerPrincipal();
		logger.debug("Principal: {}", principal);

		String principalName = principal.getName();
		logger.debug("Principal is {}", principalName);

		return principalName;
	}

	@Override
	public String getCommonName() throws IllegalStateException {

		String dn = context.getCallerPrincipal().getName();
		String[] parts = dn.split(",");

		for (String part : parts) {
			if (part.trim().toUpperCase().startsWith("CN=")) {
				String cn = part.substring("CN=".length());
				return cn;
			}
		}

		throw new IllegalStateException("Current security principal has no CN");
	}
}