Package org.opends.server.api
Class ClientConnection
- java.lang.Object
-
- org.opends.server.api.ClientConnection
-
- Direct Known Subclasses:
InternalClientConnection,JmxClientConnection,LDAPClientConnection,LDAPClientConnection2
@PublicAPI(stability=VOLATILE, mayInstantiate=true, mayExtend=true, mayInvoke=true) public abstract class ClientConnection extends Object
This class defines the set of methods and structures that must be implemented by a Directory Server client connection.
-
-
Nested Class Summary
Nested Classes Modifier and Type Class Description classClientConnection.Transaction
-
Field Summary
Fields Modifier and Type Field Description protected AuthenticationInfoauthenticationInfoThe set of authentication information for this client connection.protected AtomicBooleanbindInProgressIndicates if a bind request is currently in progress on this client connection.protected AtomicBooleansaslBindInProgressIndicates whether a multistage SASL bind is currently in progress on this client connection.protected AtomicBooleanstartTLSInProgressIndicates if a Start TLS request is currently in progress on this client connection.
-
Constructor Summary
Constructors Modifier Constructor Description protectedClientConnection()Performs the appropriate initialization generic to all client connections.
-
Method Summary
All Methods Static Methods Instance Methods Abstract Methods Concrete Methods Modifier and Type Method Description abstract voidcancelAllOperations(CancelRequest cancelRequest)Attempts to cancel all operations in progress on this connection.abstract voidcancelAllOperationsExcept(CancelRequest cancelRequest, int messageID)Attempts to cancel all operations in progress on this connection except the operation with the specified message ID.abstract CancelResultcancelOperation(int messageID, CancelRequest cancelRequest)Attempts to cancel the specified operation.voidderegisterPersistentSearch(PersistentSearch persistentSearch)Deregisters the provided persistent search for this client.abstract voiddisconnect(DisconnectReason disconnectReason, boolean sendNotification, org.forgerock.i18n.LocalizableMessage message)Closes the connection to the client, optionally sending it a message indicating the reason for the closure.protected voidfinalizeConnectionInternal()Performs any internal cleanup that may be necessary when this client connection is disconnected.voidfinishBind()Indicates a bind or start TLS request processing is finished and the client connection may start processing data read from the socket again.voidfinishSaslBind()Indicates a multistage SASL bind operation is finished and the client connection may accept additional LDAP messages.voidfinishStartTLS()Indicates a bind or start TLS request processing is finished and the client connection may start processing data read from the socket again.AuthenticationInfogetAuthenticationInfo()Retrieves information about the authentication that has been performed for this connection.StringgetCertificateAlias()Retrieves the alias of the server certificate that should be used for operations requiring a server certificate.ByteChannelgetChannel()Return the lowest level channel associated with a connection.abstract StringgetClientAddress()Retrieves a string representation of the address of the client.StringgetClientHostPort()Retrieves the address and port (if available) of the client system, separated by a colon.abstract intgetClientPort()Retrieves the port number for this connection on the client system if available.abstract ConnectionHandler<?>getConnectionHandler()Retrieves the connection handler that accepted this client connection.abstract longgetConnectionID()Retrieves the unique identifier that has been assigned to this connection.longgetConnectTime()Retrieves the time that this connection was established, measured in the number of milliseconds since January 1, 1970 UTC.StringgetConnectTimeString()Retrieves a string representation of the time that this connection was established.Set<Group<?>>getGroups(Operation operation)Retrieves the set of groups in which the user associated with this client connection may be considered to be a member.longgetIdleTime()Retrieves the length of time in milliseconds that this client connection has been idle.longgetIdleTimeLimit()Retrieves the maximum length of time in milliseconds that this client connection will be allowed to remain idle before it should be disconnected.DNgetKeyManagerProviderDN()Retrieves the DN of the key manager provider that should be used for operations requiring access to a key manager.abstract InetAddressgetLocalAddress()Retrieves thejava.net.InetAddressfor the Directory Server system to which the client has established the connection.intgetLookthroughLimit()Retrieves the default maximum number of entries that should checked for matches during a search.longgetMaxBlockedWriteTimeLimit()Retrieves the maximum length of time in milliseconds that attempts to write data to the client should be allowed to block.abstract StringgetMonitorSummary()Retrieves a one-line summary of this client connection in a form that is suitable for including in the monitor entry for the associated connection handler.abstract longgetNumberOfOperations()Retrieves the total number of operations performed on this connection.abstract OperationgetOperationInProgress(int messageID)Retrieves the operation in progress with the specified message ID.abstract Collection<Operation>getOperationsInProgress()Retrieves the set of operations in progress for this client connection.List<PersistentSearch>getPersistentSearches()Retrieves the set of persistent searches registered for this client.abstract StringgetProtocol()Retrieves the protocol that the client is using to communicate with the Directory Server.abstract InetAddressgetRemoteAddress()Retrieves thejava.net.InetAddressassociated with the remote client system.ObjectgetSASLAuthStateInfo()Retrieves an opaque set of information that may be used for processing multi-stage SASL binds.abstract StringgetServerAddress()Retrieves a string representation of the address on the server to which the client connected.StringgetServerHostPort()Retrieves the address and port of the server system, separated by a colon.abstract intgetServerPort()Retrieves the port number for this connection on the server system if available.intgetSizeLimit()Retrieves the size limit that will be enforced for searches performed using this client connection.SocketChannelgetSocketChannel()Return the Socket channel associated with a connection.abstract intgetSSF()Return the Security Strength Factor of a client connection.intgetTimeLimit()Retrieves the time limit that will be enforced for searches performed using this client connection.ClientConnection.TransactiongetTransaction(String id)DNgetTrustManagerProviderDN()Retrieves the DN of the trust manager provider that should be used for operations requiring access to a trust manager.SelectorgetWriteSelector()Retrieves aSelectorthat may be used to ensure that write operations complete in a timely manner, or terminate the connection in the event that they fail to do so.booleanhasAllPrivileges(Privilege[] privileges, Operation operation)Indicates whether the authenticate client has all of the specified privileges.protected booleanhasPersistentSearch(int messageID)Indicates whether a persistent search is registered on this connection for the provided message ID.static booleanhasPrivilege(Entry authorizationEntry, Privilege privilege)Indicate whether the specified authorization entry parameter has the specified privilege.booleanhasPrivilege(Privilege privilege, Operation operation)Indicates whether the authenticated client has the specified privilege.abstract booleanisConnectionValid()Returns whether the Directory Server believes this connection to be valid and available for communication.booleanisInnerConnection()Returns whether this connection is used for inner work not directly requested by an external client.booleanisMemberOf(Group<?> group, Operation operation)Indicates whether the user associated with this client connection should be considered a member of the specified group, optionally evaluated within the context of the provided operation.abstract booleanisSecure()Indicates whether this client connection is currently using a secure mechanism to communicate with the server.booleanmustChangePassword()Indicates whether the user associated with this client connection must change their password before they will be allowed to do anything else.voidregisterPersistentSearch(PersistentSearch persistentSearch)Registers the provided persistent search for this client.abstract booleanremoveOperationInProgress(int messageID)Removes the provided operation from the set of operations in progress for this client connection.booleansendIntermediateResponse(IntermediateResponse intermediateResponse)Invokes the intermediate response plugins on the provided response message and sends it to the client.protected abstract booleansendIntermediateResponseMessage(IntermediateResponse intermediateResponse)Sends the provided intermediate response message to the client.abstract voidsendResponse(Operation operation)Sends a response to the client based on the information in the provided operation.abstract voidsendSearchEntry(SearchOperation searchOperation, SearchResultEntry searchEntry)Sends the provided search result entry to the client.abstract booleansendSearchReference(SearchOperation searchOperation, SearchResultReference searchReference)Sends the provided search result reference to the client.voidsetAuthenticationInfo(AuthenticationInfo authenticationInfo)Specifies information about the authentication that has been performed for this connection.voidsetIdleTimeLimit(long idleTimeLimit)Specifies the maximum length of time in milliseconds that this client connection will be allowed to remain idle before it should be disconnected.voidsetLookthroughLimit(int lookthroughLimit)Specifies the default maximum number of entries that should be checked for matches during a search.voidsetMustChangePassword(boolean mustChangePassword)Specifies whether the user associated with this client connection must change their password before they will be allowed to do anything else.voidsetSASLAuthStateInfo(Object saslAuthState)Specifies an opaque set of information that may be used for processing multi-stage SASL binds.voidsetSizeLimit(int sizeLimit)Specifies the size limit that will be enforced for searches performed using this client connection.voidsetTimeLimit(int timeLimit)Specifies the time limit that will be enforced for searches performed using this client connection.voidsetUnauthenticated()Sets properties in this client connection to indicate that the client is unauthenticated.ClientConnection.TransactionstartTransaction()StringtoString()Retrieves a string representation of this client connection.abstract voidtoString(StringBuilder buffer)Appends a string representation of this client connection to the provided buffer.voidupdateAuthenticationInfo(Entry oldEntry, Entry newEntry)Updates the cached entry associated with either the authentication and/or authorization identity with the provided version.protected voidupdatePrivileges(Entry entry, boolean isRoot)Updates the privileges associated with this client connection object based on the provided entry for the authentication identity.
-
-
-
Field Detail
-
authenticationInfo
protected AuthenticationInfo authenticationInfo
The set of authentication information for this client connection.
-
saslBindInProgress
protected AtomicBoolean saslBindInProgress
Indicates whether a multistage SASL bind is currently in progress on this client connection. If so, then no other operations should be allowed until the bind completes.
-
bindInProgress
protected AtomicBoolean bindInProgress
Indicates if a bind request is currently in progress on this client connection. If so, then no further socket reads will occur until the request completes.
-
startTLSInProgress
protected AtomicBoolean startTLSInProgress
Indicates if a Start TLS request is currently in progress on this client connection. If so, then no further socket reads will occur until the request completes.
-
-
Method Detail
-
finalizeConnectionInternal
@PublicAPI(stability=PRIVATE, mayInstantiate=false, mayExtend=false, mayInvoke=true, notes="This method should only be invoked by connection handlers.") protected final void finalizeConnectionInternal()
Performs any internal cleanup that may be necessary when this client connection is disconnected. In this case, it will be used to ensure that the connection is deregistered with theAuthenticatedUsersmanager, and will then invoke thefinalizeClientConnectionmethod.
-
getConnectTime
public final long getConnectTime()
Retrieves the time that this connection was established, measured in the number of milliseconds since January 1, 1970 UTC.- Returns:
- The time that this connection was established, measured in the number of milliseconds since January 1, 1970 UTC.
-
getConnectTimeString
public final String getConnectTimeString()
Retrieves a string representation of the time that this connection was established.- Returns:
- A string representation of the time that this connection was established.
-
getConnectionID
public abstract long getConnectionID()
Retrieves the unique identifier that has been assigned to this connection.- Returns:
- The unique identifier that has been assigned to this connection.
-
getConnectionHandler
public abstract ConnectionHandler<?> getConnectionHandler()
Retrieves the connection handler that accepted this client connection.- Returns:
- The connection handler that accepted this client connection.
-
getProtocol
public abstract String getProtocol()
Retrieves the protocol that the client is using to communicate with the Directory Server.- Returns:
- The protocol that the client is using to communicate with the Directory Server.
-
getClientAddress
public abstract String getClientAddress()
Retrieves a string representation of the address of the client.- Returns:
- A string representation of the address of the client.
-
getClientPort
public abstract int getClientPort()
Retrieves the port number for this connection on the client system if available.- Returns:
- The port number for this connection on the client system or -1 if there is no client port associated with this connection (e.g. internal client).
-
getClientHostPort
public final String getClientHostPort()
Retrieves the address and port (if available) of the client system, separated by a colon.- Returns:
- The address and port of the client system, separated by a colon.
-
getServerAddress
public abstract String getServerAddress()
Retrieves a string representation of the address on the server to which the client connected.- Returns:
- A string representation of the address on the server to which the client connected.
-
getServerPort
public abstract int getServerPort()
Retrieves the port number for this connection on the server system if available.- Returns:
- The port number for this connection on the server system or -1 if there is no server port associated with this connection (e.g. internal client).
-
getServerHostPort
public final String getServerHostPort()
Retrieves the address and port of the server system, separated by a colon.- Returns:
- The address and port of the server system, separated by a colon.
-
getRemoteAddress
public abstract InetAddress getRemoteAddress()
Retrieves thejava.net.InetAddressassociated with the remote client system.- Returns:
- The
java.net.InetAddressassociated with the remote client system. It may benullif the client is not connected over an IP-based connection.
-
getLocalAddress
public abstract InetAddress getLocalAddress()
Retrieves thejava.net.InetAddressfor the Directory Server system to which the client has established the connection.- Returns:
- The
java.net.InetAddressfor the Directory Server system to which the client has established the connection. It may benullif the client is not connected over an IP-based connection.
-
isConnectionValid
public abstract boolean isConnectionValid()
Returns whether the Directory Server believes this connection to be valid and available for communication.- Returns:
- true if the connection is valid, false otherwise
-
isSecure
public abstract boolean isSecure()
Indicates whether this client connection is currently using a secure mechanism to communicate with the server. Note that this may change over time based on operations performed by the client or server (e.g., it may go fromfalsetotrueif if the client uses the StartTLS extended operation).- Returns:
trueif the client connection is currently using a secure mechanism to communicate with the server, orfalseif not.
-
getWriteSelector
public Selector getWriteSelector()
Retrieves aSelectorthat may be used to ensure that write operations complete in a timely manner, or terminate the connection in the event that they fail to do so. This is an optional method for client connections, and the default implementation returnsnullto indicate that the maximum blocked write time limit is not supported for this connection. Subclasses that do wish to support this functionality should return a validSelectorobject.- Returns:
- The
Selectorthat may be used to ensure that write operations complete in a timely manner, ornullif this client connection does not support maximum blocked write time limit functionality.
-
getMaxBlockedWriteTimeLimit
public long getMaxBlockedWriteTimeLimit()
Retrieves the maximum length of time in milliseconds that attempts to write data to the client should be allowed to block. A value of zero indicates there should be no limit.- Returns:
- The maximum length of time in milliseconds that attempts to write data to the client should be allowed to block, or zero if there should be no limit.
-
getNumberOfOperations
public abstract long getNumberOfOperations()
Retrieves the total number of operations performed on this connection.- Returns:
- The total number of operations performed on this connection.
-
sendResponse
public abstract void sendResponse(Operation operation)
Sends a response to the client based on the information in the provided operation.- Parameters:
operation- The operation for which to send the response.
-
sendSearchEntry
public abstract void sendSearchEntry(SearchOperation searchOperation, SearchResultEntry searchEntry) throws DirectoryException
Sends the provided search result entry to the client.- Parameters:
searchOperation- The search operation with which the entry is associated.searchEntry- The search result entry to be sent to the client.- Throws:
DirectoryException- If a problem occurs while attempting to send the entry to the client and the search should be terminated.
-
sendSearchReference
public abstract boolean sendSearchReference(SearchOperation searchOperation, SearchResultReference searchReference) throws DirectoryException
Sends the provided search result reference to the client.- Parameters:
searchOperation- The search operation with which the reference is associated.searchReference- The search result reference to be sent to the client.- Returns:
trueif the client is able to accept referrals, orfalseif the client cannot handle referrals and no more attempts should be made to send them for the associated search operation.- Throws:
DirectoryException- If a problem occurs while attempting to send the reference to the client and the search should be terminated.
-
sendIntermediateResponse
public final boolean sendIntermediateResponse(IntermediateResponse intermediateResponse)
Invokes the intermediate response plugins on the provided response message and sends it to the client.- Parameters:
intermediateResponse- The intermediate response message to be sent.- Returns:
trueif processing on the associated operation should continue, orfalseif not.
-
sendIntermediateResponseMessage
protected abstract boolean sendIntermediateResponseMessage(IntermediateResponse intermediateResponse)
Sends the provided intermediate response message to the client.- Parameters:
intermediateResponse- The intermediate response message to be sent.- Returns:
trueif processing on the associated operation should continue, orfalseif not.
-
disconnect
public abstract void disconnect(DisconnectReason disconnectReason, boolean sendNotification, org.forgerock.i18n.LocalizableMessage message)
Closes the connection to the client, optionally sending it a message indicating the reason for the closure. Note that the ability to send a notice of disconnection may not be available for all protocols or under all circumstances. Also note that when attempting to disconnect a client connection as a part of operation processing (e.g., within a plugin or other extension), thedisconnectClientmethod within that operation should be called rather than invoking this method directly.
All subclasses must invoke thefinalizeConnectionInternalmethod during the course of processing this method.- Parameters:
disconnectReason- The disconnect reason that provides the generic cause for the disconnect.sendNotification- Indicates whether to try to provide notification to the client that the connection will be closed.message- The message to send to the client. It may benullif no notification is to be sent.
-
mustChangePassword
public final boolean mustChangePassword()
Indicates whether the user associated with this client connection must change their password before they will be allowed to do anything else.- Returns:
trueif the user associated with this client connection must change their password before they will be allowed to do anything else, orfalseif not.
-
setMustChangePassword
public final void setMustChangePassword(boolean mustChangePassword)
Specifies whether the user associated with this client connection must change their password before they will be allowed to do anything else.- Parameters:
mustChangePassword- Specifies whether the user associated with this client connection must change their password before they will be allowed to do anything else.
-
getOperationsInProgress
public abstract Collection<Operation> getOperationsInProgress()
Retrieves the set of operations in progress for this client connection. This list must not be altered by any caller.- Returns:
- The set of operations in progress for this client connection.
-
getOperationInProgress
public abstract Operation getOperationInProgress(int messageID)
Retrieves the operation in progress with the specified message ID.- Parameters:
messageID- The message ID of the operation to retrieve.- Returns:
- The operation in progress with the specified message ID,
or
nullif no such operation could be found.
-
removeOperationInProgress
public abstract boolean removeOperationInProgress(int messageID)
Removes the provided operation from the set of operations in progress for this client connection. Note that this does not make any attempt to cancel any processing that may already be in progress for the operation.- Parameters:
messageID- The message ID of the operation to remove from the set of operations in progress.- Returns:
trueif the operation was found and removed from the set of operations in progress, orfalseif not.
-
getPersistentSearches
public final List<PersistentSearch> getPersistentSearches()
Retrieves the set of persistent searches registered for this client.- Returns:
- The set of persistent searches registered for this client.
-
hasPersistentSearch
protected final boolean hasPersistentSearch(int messageID)
Indicates whether a persistent search is registered on this connection for the provided message ID. A persistent search outlives the operation which started it: that operation leaves the set of operations in progress as soon as its search phase is over, but the server can still have a final response to send for it, when the search is terminated on the server side.- Parameters:
messageID- The message ID to look for.- Returns:
trueif a persistent search is registered for the provided message ID.
-
registerPersistentSearch
@PublicAPI(stability=PRIVATE, mayInstantiate=false, mayExtend=false, mayInvoke=false) public final void registerPersistentSearch(PersistentSearch persistentSearch)
Registers the provided persistent search for this client. Note that this should only be called byDirectoryServer.registerPersistentSearchand not through any other means.- Parameters:
persistentSearch- The persistent search to register for this client.
-
deregisterPersistentSearch
@PublicAPI(stability=PRIVATE, mayInstantiate=false, mayExtend=false, mayInvoke=false) public final void deregisterPersistentSearch(PersistentSearch persistentSearch)
Deregisters the provided persistent search for this client. Note that this should only be called byDirectoryServer.deregisterPersistentSearchand not through any other means.- Parameters:
persistentSearch- The persistent search to deregister for this client.
-
cancelOperation
public abstract CancelResult cancelOperation(int messageID, CancelRequest cancelRequest)
Attempts to cancel the specified operation.- Parameters:
messageID- The message ID of the operation to cancel.cancelRequest- An object providing additional information about how the cancel should be processed.- Returns:
- A cancel result that either indicates that the cancel was successful or provides a reason that it was not.
-
cancelAllOperations
public abstract void cancelAllOperations(CancelRequest cancelRequest)
Attempts to cancel all operations in progress on this connection.- Parameters:
cancelRequest- An object providing additional information about how the cancel should be processed.
-
cancelAllOperationsExcept
public abstract void cancelAllOperationsExcept(CancelRequest cancelRequest, int messageID)
Attempts to cancel all operations in progress on this connection except the operation with the specified message ID.- Parameters:
cancelRequest- An object providing additional information about how the cancel should be processed.messageID- The message ID of the operation that should not be canceled.
-
getAuthenticationInfo
public AuthenticationInfo getAuthenticationInfo()
Retrieves information about the authentication that has been performed for this connection.- Returns:
- Information about the user that is currently authenticated on this connection.
-
setAuthenticationInfo
public void setAuthenticationInfo(AuthenticationInfo authenticationInfo)
Specifies information about the authentication that has been performed for this connection.- Parameters:
authenticationInfo- Information about the authentication that has been performed for this connection. It should not benull.
-
updateAuthenticationInfo
public final void updateAuthenticationInfo(Entry oldEntry, Entry newEntry)
Updates the cached entry associated with either the authentication and/or authorization identity with the provided version.- Parameters:
oldEntry- The user entry currently serving as the authentication and/or authorization identity.newEntry- The updated entry that should replace the existing entry. It may optionally have a different DN than the old entry.
-
setUnauthenticated
public void setUnauthenticated()
Sets properties in this client connection to indicate that the client is unauthenticated. This includes setting the authentication info structure to an empty default, as well as setting the size and time limit values to their defaults.
-
hasPrivilege
public static boolean hasPrivilege(Entry authorizationEntry, Privilege privilege)
Indicate whether the specified authorization entry parameter has the specified privilege. The method can be used to perform a "what-if" scenario.- Parameters:
authorizationEntry- The authentication entry to use.privilege- The privilege to check for.- Returns:
trueif the authentication entry has the specified privilege, orfalseif not.
-
hasPrivilege
public boolean hasPrivilege(Privilege privilege, Operation operation)
Indicates whether the authenticated client has the specified privilege.- Parameters:
privilege- The privilege for which to make the determination.operation- The operation being processed which needs to make the privilege determination, ornullif there is no associated operation.- Returns:
trueif the authenticated client has the specified privilege, orfalseif not.
-
hasAllPrivileges
public boolean hasAllPrivileges(Privilege[] privileges, Operation operation)
Indicates whether the authenticate client has all of the specified privileges.- Parameters:
privileges- The array of privileges for which to make the determination.operation- The operation being processed which needs to make the privilege determination, ornullif there is no associated operation.- Returns:
trueif the authenticated client has all of the specified privileges, orfalseif not.
-
updatePrivileges
protected void updatePrivileges(Entry entry, boolean isRoot)
Updates the privileges associated with this client connection object based on the provided entry for the authentication identity.- Parameters:
entry- The entry for the authentication identity associated with this client connection.isRoot- Indicates whether the associated user is a root user and should automatically inherit the root privilege set.
-
getSASLAuthStateInfo
public final Object getSASLAuthStateInfo()
Retrieves an opaque set of information that may be used for processing multi-stage SASL binds.- Returns:
- An opaque set of information that may be used for processing multi-stage SASL binds.
-
setSASLAuthStateInfo
public final void setSASLAuthStateInfo(Object saslAuthState)
Specifies an opaque set of information that may be used for processing multi-stage SASL binds.- Parameters:
saslAuthState- An opaque set of information that may be used for processing multi-stage SASL binds.
-
getChannel
public ByteChannel getChannel()
Return the lowest level channel associated with a connection. This is normally the channel associated with the socket channel.- Returns:
- The lowest level channel associated with a connection.
-
getSocketChannel
public SocketChannel getSocketChannel()
Return the Socket channel associated with a connection.- Returns:
- The Socket channel associated with a connection.
-
getSizeLimit
public final int getSizeLimit()
Retrieves the size limit that will be enforced for searches performed using this client connection.- Returns:
- The size limit that will be enforced for searches performed using this client connection.
-
setSizeLimit
public void setSizeLimit(int sizeLimit)
Specifies the size limit that will be enforced for searches performed using this client connection.- Parameters:
sizeLimit- The size limit that will be enforced for searches performed using this client connection.
-
getIdleTimeLimit
public final long getIdleTimeLimit()
Retrieves the maximum length of time in milliseconds that this client connection will be allowed to remain idle before it should be disconnected.- Returns:
- The maximum length of time in milliseconds that this client connection will be allowed to remain idle before it should be disconnected.
-
setIdleTimeLimit
public void setIdleTimeLimit(long idleTimeLimit)
Specifies the maximum length of time in milliseconds that this client connection will be allowed to remain idle before it should be disconnected.- Parameters:
idleTimeLimit- The maximum length of time in milliseconds that this client connection will be allowed to remain idle before it should be disconnected.
-
getLookthroughLimit
public final int getLookthroughLimit()
Retrieves the default maximum number of entries that should checked for matches during a search.- Returns:
- The default maximum number of entries that should checked for matches during a search.
-
setLookthroughLimit
public void setLookthroughLimit(int lookthroughLimit)
Specifies the default maximum number of entries that should be checked for matches during a search.- Parameters:
lookthroughLimit- The default maximum number of entries that should be check for matches during a search.
-
getTimeLimit
public final int getTimeLimit()
Retrieves the time limit that will be enforced for searches performed using this client connection.- Returns:
- The time limit that will be enforced for searches performed using this client connection.
-
setTimeLimit
public void setTimeLimit(int timeLimit)
Specifies the time limit that will be enforced for searches performed using this client connection.- Parameters:
timeLimit- The time limit that will be enforced for searches performed using this client connection.
-
getMonitorSummary
public abstract String getMonitorSummary()
Retrieves a one-line summary of this client connection in a form that is suitable for including in the monitor entry for the associated connection handler. It should be in a format that is both humand readable and machine parseable (e.g., a space-delimited name-value list, with quotes around the values).- Returns:
- A one-line summary of this client connection in a form that is suitable for including in the monitor entry for the associated connection handler.
-
isMemberOf
public boolean isMemberOf(Group<?> group, Operation operation) throws DirectoryException
Indicates whether the user associated with this client connection should be considered a member of the specified group, optionally evaluated within the context of the provided operation. If an operation is given, then the determination should be made based on the authorization identity for that operation. If the operation isnull, then the determination should be made based on the authorization identity for this client connection. Note that this is a point-in-time determination and the caller must not cache the result.- Parameters:
group- The group for which to make the determination.operation- The operation to use to obtain the authorization identity for which to make the determination, ornullif the authorization identity should be obtained from this client connection.- Returns:
trueif the target user is currently a member of the specified group, orfalseif not.- Throws:
DirectoryException- If a problem occurs while attempting to make the determination.
-
getGroups
public Set<Group<?>> getGroups(Operation operation) throws DirectoryException
Retrieves the set of groups in which the user associated with this client connection may be considered to be a member. If an operation is provided, then the determination should be made based on the authorization identity for that operation. If the operation isnull, then it should be made based on the authorization identity for this client connection. Note that this is a point-in-time determination and the caller must not cache the result.- Parameters:
operation- The operation to use to obtain the authorization identity for which to retrieve the associated groups, ornullif the authorization identity should be obtained from this client connection.- Returns:
- The set of groups in which the target user is currently a member.
- Throws:
DirectoryException- If a problem occurs while attempting to make the determination.
-
getKeyManagerProviderDN
public DN getKeyManagerProviderDN()
Retrieves the DN of the key manager provider that should be used for operations requiring access to a key manager. The default implementation returnsnullto indicate that no key manager provider is available, but subclasses should override this method to return a valid DN if they perform operations which may need access to a key manager.- Returns:
- The DN of the key manager provider that should be used
for operations requiring access to a key manager, or
nullif there is no key manager provider configured for this client connection.
-
getTrustManagerProviderDN
public DN getTrustManagerProviderDN()
Retrieves the DN of the trust manager provider that should be used for operations requiring access to a trust manager. The default implementation returnsnullto indicate that no trust manager provider is available, but subclasses should override this method to return a valid DN if they perform operations which may need access to a trust manager.- Returns:
- The DN of the trust manager provider that should be used
for operations requiring access to a trust manager, or
nullif there is no trust manager provider configured for this client connection.
-
getCertificateAlias
public String getCertificateAlias()
Retrieves the alias of the server certificate that should be used for operations requiring a server certificate. The default implementation returnsnullto indicate that any alias is acceptable.- Returns:
- The alias of the server certificate that should be used
for operations requiring a server certificate, or
nullif any alias is acceptable.
-
toString
public final String toString()
Retrieves a string representation of this client connection.
-
toString
public abstract void toString(StringBuilder buffer)
Appends a string representation of this client connection to the provided buffer.- Parameters:
buffer- The buffer to which the information should be appended.
-
getIdleTime
public long getIdleTime()
Retrieves the length of time in milliseconds that this client connection has been idle.
Note that the default implementation will always return zero. Subclasses associated with connection handlers should override this method if they wish to provided idle time limit functionality.- Returns:
- The length of time in milliseconds that this client connection has been idle.
-
getSSF
public abstract int getSSF()
Return the Security Strength Factor of a client connection.- Returns:
- An integer representing the SSF value of a connection.
-
finishBind
public void finishBind()
Indicates a bind or start TLS request processing is finished and the client connection may start processing data read from the socket again. This must be called after processing each bind request in a multistage SASL bind.
-
finishStartTLS
public void finishStartTLS()
Indicates a bind or start TLS request processing is finished and the client connection may start processing data read from the socket again. This must be called after processing each bind request in a multistage SASL bind.
-
finishSaslBind
public void finishSaslBind()
Indicates a multistage SASL bind operation is finished and the client connection may accept additional LDAP messages.
-
isInnerConnection
public boolean isInnerConnection()
Returns whether this connection is used for inner work not directly requested by an external client.- Returns:
trueif this is an inner connection,falseotherwise
-
startTransaction
public ClientConnection.Transaction startTransaction()
-
getTransaction
public ClientConnection.Transaction getTransaction(String id)
-
-