Class AciLDAPOperationContainer
- java.lang.Object
-
- org.opends.server.authorization.dseecompat.AciLDAPOperationContainer
-
- All Implemented Interfaces:
AciEvalContext,AciTargetMatchContext
public class AciLDAPOperationContainer extends Object
The AciLDAPOperationContainer is an AciContainer extended class that wraps each LDAP operation being evaluated or tested for target matched of an ACI.
-
-
Constructor Summary
Constructors Constructor Description AciLDAPOperationContainer(ExtendedOperation operation, Entry e, int rights)Constructor interface for evaluation of the extended operation.AciLDAPOperationContainer(ModifyDNOperation operation, int rights, Entry entry)Constructor interface for the modify DN operation.AciLDAPOperationContainer(Operation operation, int rights, Entry entry)Constructor interface for all currently supported LDAP operations.AciLDAPOperationContainer(Operation operation, Entry e, AuthenticationInfo authInfo, int rights)Constructor interface for evaluation general purpose Operation, entry and rights..AciLDAPOperationContainer(Operation operation, Entry e, Control c, int rights)Constructor interface for evaluation of a control.AciLDAPOperationContainer(LocalBackendAddOperation operation, int rights)Constructor interface for the add operation.AciLDAPOperationContainer(LocalBackendCompareOperation operation, int rights)Constructor interface for the compare operation.AciLDAPOperationContainer(LocalBackendDeleteOperation operation, int rights)Constructor interface for the delete operation.AciLDAPOperationContainer(LocalBackendModifyOperation operation, int rights)Constructor interface for the modify operation.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description voidaddTargAttrFiltersMatchAci(Aci aci)Add the specified ACI to a list of ACIs that have a targattrfilters rule that matched.voidclearEvalAttributes(int v)Used to clear the mask used to detect if access checking needs to be performed on individual attributes types.List<Aci>getAllowList()Get the list allow ACIs.DNgetClientDN()Get client DN.EntrygetClientEntry()Get the client entry.StringgetControlOID()Return the OID (Object Identifier) string of the control being evaluated.AttributeTypegetCurrentAttributeType()Get the current attribute type being evaluated.ByteStringgetCurrentAttributeValue()The current attribute type value being evaluated.intgetCurrentSSF()Return the current SSF (Security Strength Factor) of the underlying connection.StringgetDecidingAciName()Return the name of the ACI that decided the last access evaluation.List<Aci>getDenyList()Get the list of deny ACIs.EnumEvalReasongetEvalReason()Return the reason the last access evaluation was evaluated the way it was.StringgetEvalSummary()Return the access evaluation summary string.StringgetExtOpOID()Return The OID (Object Identifier) string of the extended operation being evaluated.StringgetHostName()Get the hostname of the bound connection.InetAddressgetRemoteAddress()Get the address of the bound connection.DNgetResourceDN()Get the resource DN.EntrygetResourceEntry()Get the entry being evaluated.intgetRights()Return the rights for this container's LDAP operation.List<AttributeType>getSpecificAttributes()Return the list of additional attributes specified in the geteffectiverights control.StringgetTargAttrFiltersAciName()Return the name of the ACI that last matched a targattrfilters rule.booleangetTargAttrFiltersMatch()Return the value of the targAttrFiltersMatch variable.booleanhasAllOpAttributes()Return true if the evaluating ACI contained a targetattr all operational attributes rule match.booleanhasAllUserAttributes()Return true if the evaluating ACI contained a targetattr all user attributes rule match.EnumEvalResulthasAuthenticationMethod(org.opends.server.authorization.dseecompat.EnumAuthMethod authMethod, String saslMech)Determine whether the client connection has been authenticated using a specified authentication method.booleanhasEntryTestRule()True if an entry test rule was found.booleanhasEvalOpAttributes()Return true if the evaluating ACI either contained an explicitly defined operational attribute type in a targetattr target rule or both a targetattr all operational attributes rule matched and a explicitly defined targetattr target rule matched.booleanhasEvalUserAttributes()Return true if the evaluating ACI either contained an explicitly defined user attribute type in a targeattr target rule or both a targetattr all user attributes rule matched and a explicitly defined targetattr target rule matched.booleanhasGetEffectiveRightsControl()Return true if the container is being used in a geteffectiverights evaluation.booleanhasRights(int rights)Checks if the container's rights has the specified rights.booleanhasSeenEntry()Returns true if an entry has already been processed by an access proxy check.booleanhasTargAttrFiltersMatchAci(Aci aci)The context maintains a hashtable of ACIs that matched the targattrfilters keyword evaluation.booleanhasTargAttrFiltersMatchOp(int flag)Return true if an ACI that evaluated to deny or allow has an targattrfilters keyword.booleanisAddOperation()Return true if this is an add operation needed by the userattr USERDN parent inheritance level 0 processing.booleanisAnonymousUser()Check if the remote client is bound anonymously.booleanisAuthzidAuthorizationDN()Returns true if the geteffectiverights control's authZid DN is equal to the authorization entry's DN.booleanisDenyEval()Returns true if the deny list is being evaluated.booleanisFirstAttribute()True if the first attribute of the resource entry is being evaluated.booleanisGetEffectiveRightsEval()Returns true of a match context is performing a geteffectiverights evaluation.booleanisMemberOf(Group<?> group)Return true if the operation associated with this evaluation context is a member of the specified group.booleanisProxiedAuthorization()Return true if a evaluation context is being used in proxied authorization control evaluation.booleanisTargAttrFilterMatchAciEmpty()Returns true if the hashtable of ACIs that matched the targattrfilters keyword evaluation is empty.voidresetEffectiveRightsParams()Reset the values used by the geteffectiverights evaluation to original values.StringrightToString()Return a string representation of the current right being evaluated.voidsetAllowList(List<Aci> allows)Set the allow ACI list.protected voidsetControlOID(String oid)Set the the controlOID value to the specified oid string.voidsetCurrentAttributeType(AttributeType type)Set the attribute type to be evaluated.voidsetCurrentAttributeValue(ByteString value)Set the attribute value to be evaluated.voidsetDenyList(List<Aci> denys)Set the deny ACI list.voidsetEntryTestRule(boolean val)True if the target matching code found an entry test rule.voidsetEvalOpAttributes(int v)This method toggles a mask that indicates that access checking of individual operational attributes may or may not be skipped depending on if there is a single ACI containing a targetattr all operational attributes rule (targetattr="+").voidsetEvalSummary(String summary)Set the value of the summary string to the specified string.voidsetEvaluationResult(EnumEvalReason reason, Aci decidingAci)Set the reason and the ACI that decided why the last access evaluation was evaluated the way it was.voidsetEvalUserAttributes(int v)This method toggles a mask that indicates that access checking of individual user attributes may or may not be skipped depending on if there is a single ACI containing a targetattr all user attributes rule (targetattr="*").protected voidsetExtOpOID(String oid)Set the extended operation OID value to the specified oid string.voidsetGetEffectiveRightsEval()The container is going to be used in a geteffectiverights evaluation, set the flag isGetEffectiveRightsEval to true.voidsetIsFirstAttribute(boolean val)Set to true if the first attribute of the resource entry is being evaluated.voidsetRights(int rights)Set the rights of the container to the specified rights.voidsetSeenEntry(boolean val)Set to true if an entry has already been processed by an access proxy check.voidsetTargAttrFiltersAciName(String name)Save the name of the last ACI that matched a targattrfilters rule.voidsetTargAttrFiltersMatch(boolean v)Set to true if the ACI had a targattrfilter rule that matched.voidsetTargAttrFiltersMatchOp(int flag)Set a flag that specifies that a ACI that evaluated to either deny or allow contains a targattrfilters keyword.StringtoString()voiduseAuthzid(boolean v)Use the DN from the geteffectiverights control's authzId as the client DN, rather than the authorization entry's DN.
-
-
-
Constructor Detail
-
AciLDAPOperationContainer
public AciLDAPOperationContainer(Operation operation, int rights, Entry entry)
Constructor interface for all currently supported LDAP operations.- Parameters:
operation- The compare operation to evaluate.rights- The rights of a compare operation.entry- The entry for evaluation.
-
AciLDAPOperationContainer
public AciLDAPOperationContainer(LocalBackendCompareOperation operation, int rights)
Constructor interface for the compare operation.- Parameters:
operation- The compare operation to evaluate.rights- The rights of a compare operation.
-
AciLDAPOperationContainer
public AciLDAPOperationContainer(Operation operation, Entry e, AuthenticationInfo authInfo, int rights)
Constructor interface for evaluation general purpose Operation, entry and rights..- Parameters:
operation- The operation to use in the evaluation.e- The entry for evaluation.authInfo- The authentication information to use in the evaluation.rights- The rights of the operation.
-
AciLDAPOperationContainer
public AciLDAPOperationContainer(Operation operation, Entry e, Control c, int rights)
Constructor interface for evaluation of a control.- Parameters:
operation- The operation to use in the evaluation.e- An entry built especially for evaluation.c- The control to evaluate.rights- The rights of a control.
-
AciLDAPOperationContainer
public AciLDAPOperationContainer(ExtendedOperation operation, Entry e, int rights)
Constructor interface for evaluation of the extended operation.- Parameters:
operation- The extended operation to evaluate.e- An entry built especially for evaluation.rights- The rights of a extended operation.
-
AciLDAPOperationContainer
public AciLDAPOperationContainer(LocalBackendAddOperation operation, int rights)
Constructor interface for the add operation.- Parameters:
operation- The add operation to evaluate.rights- The rights of an add operation.
-
AciLDAPOperationContainer
public AciLDAPOperationContainer(LocalBackendDeleteOperation operation, int rights)
Constructor interface for the delete operation.- Parameters:
operation- The add operation to evaluate.rights- The rights of a delete operation.
-
AciLDAPOperationContainer
public AciLDAPOperationContainer(LocalBackendModifyOperation operation, int rights)
Constructor interface for the modify operation.- Parameters:
rights- The rights of modify operation.operation- The add operation to evaluate.
-
AciLDAPOperationContainer
public AciLDAPOperationContainer(ModifyDNOperation operation, int rights, Entry entry)
Constructor interface for the modify DN operation.- Parameters:
operation- The modify DN operation.rights- The rights of the modify DN operation.entry- The entry to evaluated for this modify DN.
-
-
Method Detail
-
hasSeenEntry
public boolean hasSeenEntry()
Returns true if an entry has already been processed by an access proxy check.- Returns:
- True if an entry has already been processed by an access proxy check.
-
setSeenEntry
public void setSeenEntry(boolean val)
Set to true if an entry has already been processed by an access proxy check.- Parameters:
val- The value to set the seenEntry boolean to.
-
isProxiedAuthorization
public boolean isProxiedAuthorization()
Description copied from interface:AciEvalContextReturn true if a evaluation context is being used in proxied authorization control evaluation.- Specified by:
isProxiedAuthorizationin interfaceAciEvalContext- Returns:
trueif evaluation context is being used in proxied authorization control evaluation.
-
isGetEffectiveRightsEval
public boolean isGetEffectiveRightsEval()
Description copied from interface:AciTargetMatchContextReturns true of a match context is performing a geteffectiverights evaluation.- Specified by:
isGetEffectiveRightsEvalin interfaceAciEvalContext- Specified by:
isGetEffectiveRightsEvalin interfaceAciTargetMatchContext- Returns:
- True if a match context is evaluating geteffectiverights.
-
setGetEffectiveRightsEval
public void setGetEffectiveRightsEval()
The container is going to be used in a geteffectiverights evaluation, set the flag isGetEffectiveRightsEval to true.
-
hasGetEffectiveRightsControl
public boolean hasGetEffectiveRightsControl()
Return true if the container is being used in a geteffectiverights evaluation.- Returns:
- True if the container is being used in a geteffectiverights evaluation.
-
useAuthzid
public void useAuthzid(boolean v)
Use the DN from the geteffectiverights control's authzId as the client DN, rather than the authorization entry's DN.- Parameters:
v- The valued to set the useAuthzid to.
-
getSpecificAttributes
public List<AttributeType> getSpecificAttributes()
Return the list of additional attributes specified in the geteffectiverights control.- Returns:
- The list of attributes to return rights information about in the entry.
-
addTargAttrFiltersMatchAci
public void addTargAttrFiltersMatchAci(Aci aci)
Description copied from interface:AciTargetMatchContextAdd the specified ACI to a list of ACIs that have a targattrfilters rule that matched. This is used by geteffectiverights to determine the rights of an attribute that possibly might evaluate to true.- Specified by:
addTargAttrFiltersMatchAciin interfaceAciTargetMatchContext- Parameters:
aci- The ACI to save.
-
hasTargAttrFiltersMatchAci
public boolean hasTargAttrFiltersMatchAci(Aci aci)
Description copied from interface:AciEvalContextThe context maintains a hashtable of ACIs that matched the targattrfilters keyword evaluation. The hasTargAttrFiltersMatchAci method returns true if the specified ACI is contained in that hashtable. Used in a geteffectiverights control evaluation to determine the access value to put in the "write" rights evaluation field.- Specified by:
hasTargAttrFiltersMatchAciin interfaceAciEvalContext- Parameters:
aci- The ACI that to evaluate if it contains a match during targattrfilters keyword evaluation.- Returns:
trueif a specified ACI matched targattrfilters evaluation.
-
isTargAttrFilterMatchAciEmpty
public boolean isTargAttrFilterMatchAciEmpty()
Description copied from interface:AciEvalContextReturns true if the hashtable of ACIs that matched the targattrfilters keyword evaluation is empty. Used in a geteffectiverights control evaluation to determine the access value to put in the "write" rights evaluation field.- Specified by:
isTargAttrFilterMatchAciEmptyin interfaceAciEvalContext- Returns:
trueif there were not any ACIs that matched targattrfilters keyword evaluation.
-
resetEffectiveRightsParams
public void resetEffectiveRightsParams()
Reset the values used by the geteffectiverights evaluation to original values. The geteffectiverights evaluation uses the same container repeatedly for different rights evaluations (read, write, proxy,...) and this method resets variables that are specific to a single evaluation.
-
setTargAttrFiltersAciName
public void setTargAttrFiltersAciName(String name)
Description copied from interface:AciTargetMatchContextSave the name of the last ACI that matched a targattrfilters rule. This is used by geteffectiverights evaluation.- Specified by:
setTargAttrFiltersAciNamein interfaceAciEvalContext- Specified by:
setTargAttrFiltersAciNamein interfaceAciTargetMatchContext- Parameters:
name- The ACI's name to save.
-
getTargAttrFiltersAciName
public String getTargAttrFiltersAciName()
Description copied from interface:AciEvalContextReturn the name of the ACI that last matched a targattrfilters rule. Used in geteffectiverights control evaluation.- Specified by:
getTargAttrFiltersAciNamein interfaceAciEvalContext- Returns:
- The name of the ACI that last matched a targattrfilters rule.
-
setTargAttrFiltersMatchOp
public void setTargAttrFiltersMatchOp(int flag)
Description copied from interface:AciEvalContextSet a flag that specifies that a ACI that evaluated to either deny or allow contains a targattrfilters keyword. Used by geteffectiverights control evaluation to determine the access value to put in the "write" rights evaluation field.- Specified by:
setTargAttrFiltersMatchOpin interfaceAciEvalContext- Parameters:
flag- Either the integer value representing an allow or a deny, but not both.
-
hasTargAttrFiltersMatchOp
public boolean hasTargAttrFiltersMatchOp(int flag)
Description copied from interface:AciEvalContextReturn true if an ACI that evaluated to deny or allow has an targattrfilters keyword. Used by geteffectiverights control evaluation to determine the access value to put in the "write" rights evaluation field.- Specified by:
hasTargAttrFiltersMatchOpin interfaceAciEvalContext- Parameters:
flag- The integer value specifying either a deny or allow, but not both.- Returns:
trueif the ACI has an targattrfilters keyword.
-
getDecidingAciName
public String getDecidingAciName()
Description copied from interface:AciEvalContextReturn the name of the ACI that decided the last access evaluation. Used by geteffectiverights control evaluation to build the summary string.- Specified by:
getDecidingAciNamein interfaceAciEvalContext- Returns:
- The name of the ACI that decided the last access evaluation.
-
setEvaluationResult
public void setEvaluationResult(EnumEvalReason reason, Aci decidingAci)
Description copied from interface:AciEvalContextSet the reason and the ACI that decided why the last access evaluation was evaluated the way it was. Used by geteffectiverights control evaluation to eventually build the summary string.- Specified by:
setEvaluationResultin interfaceAciEvalContext- Parameters:
reason- The enumeration representing the reason of the last access evaluation.decidingAci- The ACI that decided the last access evaluation.
-
getEvalReason
public EnumEvalReason getEvalReason()
Description copied from interface:AciEvalContextReturn the reason the last access evaluation was evaluated the way it was. Used by geteffectiverights control evaluation to build the summary string.- Specified by:
getEvalReasonin interfaceAciEvalContext- Returns:
- The enumeration representing the reason of the last access evaluation.
-
setEvalSummary
public void setEvalSummary(String summary)
Description copied from interface:AciEvalContextSet the value of the summary string to the specified string. Used in get effective rights evaluation to build summary string.- Specified by:
setEvalSummaryin interfaceAciEvalContext- Parameters:
summary- The string to set the summary string to
-
getEvalSummary
public String getEvalSummary()
Description copied from interface:AciEvalContextReturn the access evaluation summary string. Used in a geteffectiverights control evaluation when an aclRightsInfo attribute was specified in a search request.- Specified by:
getEvalSummaryin interfaceAciEvalContext- Returns:
- The string describing the access evaluation.
-
isAuthzidAuthorizationDN
public boolean isAuthzidAuthorizationDN()
Returns true if the geteffectiverights control's authZid DN is equal to the authorization entry's DN.- Returns:
- True if the authZid is equal to the authorization entry's DN.
-
setDenyList
public void setDenyList(List<Aci> denys)
Description copied from interface:AciTargetMatchContextSet the deny ACI list.- Specified by:
setDenyListin interfaceAciTargetMatchContext- Parameters:
denys- The deny ACI list.
-
setAllowList
public void setAllowList(List<Aci> allows)
Description copied from interface:AciTargetMatchContextSet the allow ACI list.- Specified by:
setAllowListin interfaceAciTargetMatchContext- Parameters:
allows- The list of allow ACIs.
-
getCurrentAttributeType
public AttributeType getCurrentAttributeType()
Description copied from interface:AciTargetMatchContextGet the current attribute type being evaluated.- Specified by:
getCurrentAttributeTypein interfaceAciEvalContext- Specified by:
getCurrentAttributeTypein interfaceAciTargetMatchContext- Returns:
- The attribute type being evaluated.
-
getCurrentAttributeValue
public ByteString getCurrentAttributeValue()
Description copied from interface:AciTargetMatchContextThe current attribute type value being evaluated.- Specified by:
getCurrentAttributeValuein interfaceAciTargetMatchContext- Returns:
- The current attribute type value being evaluated.
-
setCurrentAttributeType
public void setCurrentAttributeType(AttributeType type)
Description copied from interface:AciTargetMatchContextSet the attribute type to be evaluated.- Specified by:
setCurrentAttributeTypein interfaceAciTargetMatchContext- Parameters:
type- The attribute type to set to.
-
setCurrentAttributeValue
public void setCurrentAttributeValue(ByteString value)
Description copied from interface:AciTargetMatchContextSet the attribute value to be evaluated.- Specified by:
setCurrentAttributeValuein interfaceAciTargetMatchContext- Parameters:
value- The current attribute value to set to.
-
isFirstAttribute
public boolean isFirstAttribute()
Description copied from interface:AciTargetMatchContextTrue if the first attribute of the resource entry is being evaluated.- Specified by:
isFirstAttributein interfaceAciTargetMatchContext- Returns:
- True if this is the first attribute.
-
setIsFirstAttribute
public void setIsFirstAttribute(boolean val)
Description copied from interface:AciTargetMatchContextSet to true if the first attribute of the resource entry is being evaluated.- Specified by:
setIsFirstAttributein interfaceAciTargetMatchContext- Parameters:
val- True if this is the first attribute of the resource entry being evaluated.
-
hasEntryTestRule
public boolean hasEntryTestRule()
Description copied from interface:AciTargetMatchContextTrue if an entry test rule was found.- Specified by:
hasEntryTestRulein interfaceAciTargetMatchContext- Returns:
- True if an entry test rule was found.
-
setEntryTestRule
public void setEntryTestRule(boolean val)
Description copied from interface:AciTargetMatchContextTrue if the target matching code found an entry test rule. An entry test rule is an ACI without a targetattr target rule.- Specified by:
setEntryTestRulein interfaceAciTargetMatchContext- Parameters:
val- True if an entry test rule was found.
-
getResourceEntry
public Entry getResourceEntry()
Description copied from interface:AciTargetMatchContextGet the entry being evaluated. This is known as the resource entry.- Specified by:
getResourceEntryin interfaceAciEvalContext- Specified by:
getResourceEntryin interfaceAciTargetMatchContext- Returns:
- The entry being evaluated.
-
getClientEntry
public Entry getClientEntry()
Description copied from interface:AciEvalContextGet the client entry. The client entry is the entry that corresponds to the client DN.- Specified by:
getClientEntryin interfaceAciEvalContext- Returns:
- The client entry corresponding to the client DN.
-
getDenyList
public List<Aci> getDenyList()
Description copied from interface:AciEvalContextGet the list of deny ACIs.- Specified by:
getDenyListin interfaceAciEvalContext- Returns:
- The deny ACI list.
-
getAllowList
public List<Aci> getAllowList()
Description copied from interface:AciEvalContextGet the list allow ACIs.- Specified by:
getAllowListin interfaceAciEvalContext- Returns:
- The allow ACI list.
-
isDenyEval
public boolean isDenyEval()
Description copied from interface:AciEvalContextReturns true if the deny list is being evaluated.- Specified by:
isDenyEvalin interfaceAciEvalContext- Returns:
- True if the deny list is being evaluated.
-
isAnonymousUser
public boolean isAnonymousUser()
Description copied from interface:AciEvalContextCheck if the remote client is bound anonymously.- Specified by:
isAnonymousUserin interfaceAciEvalContext- Returns:
trueif client is bound anonymously.
-
getClientDN
public DN getClientDN()
Description copied from interface:AciEvalContextGet client DN. The client DN is the authorization DN.- Specified by:
getClientDNin interfaceAciEvalContext- Returns:
- The client DN.
-
getResourceDN
public DN getResourceDN()
Description copied from interface:AciEvalContextGet the resource DN. The resource DN is the DN of the entry being evaluated.- Specified by:
getResourceDNin interfaceAciEvalContext- Returns:
- The resource DN.
-
hasRights
public boolean hasRights(int rights)
Checks if the container's rights has the specified rights.JNR: I find the implementation in this method dubious.
- Specified by:
hasRightsin interfaceAciEvalContext- Specified by:
hasRightsin interfaceAciTargetMatchContext- Parameters:
rights- The rights to check for.- Returns:
- True if the container's rights has the specified rights.
- See Also:
EnumRight.hasRights(int, int)
-
getRights
public int getRights()
Description copied from interface:AciTargetMatchContextReturn the rights for this container's LDAP operation.- Specified by:
getRightsin interfaceAciEvalContext- Specified by:
getRightsin interfaceAciTargetMatchContext- Returns:
- The rights for the container's LDAP operation.
-
setRights
public void setRights(int rights)
Description copied from interface:AciTargetMatchContextSet the rights of the container to the specified rights.- Specified by:
setRightsin interfaceAciTargetMatchContext- Parameters:
rights- The rights to set the container's rights to.
-
getHostName
public String getHostName()
Description copied from interface:AciEvalContextGet the hostname of the bound connection.- Specified by:
getHostNamein interfaceAciEvalContext- Returns:
- The hostname of the connection.
-
getRemoteAddress
public InetAddress getRemoteAddress()
Description copied from interface:AciEvalContextGet the address of the bound connection.- Specified by:
getRemoteAddressin interfaceAciEvalContext- Returns:
- The address of the bound connection.
-
isAddOperation
public boolean isAddOperation()
Description copied from interface:AciEvalContextReturn true if this is an add operation needed by the userattr USERDN parent inheritance level 0 processing.- Specified by:
isAddOperationin interfaceAciEvalContext- Returns:
trueif this is an add operation.
-
setTargAttrFiltersMatch
public void setTargAttrFiltersMatch(boolean v)
Description copied from interface:AciTargetMatchContextSet to true if the ACI had a targattrfilter rule that matched.- Specified by:
setTargAttrFiltersMatchin interfaceAciTargetMatchContext- Parameters:
v- The value to use.
-
getTargAttrFiltersMatch
public boolean getTargAttrFiltersMatch()
Description copied from interface:AciTargetMatchContextReturn the value of the targAttrFiltersMatch variable. This is set to true if the ACI had a targattrfilter rule that matched.- Specified by:
getTargAttrFiltersMatchin interfaceAciTargetMatchContext- Returns:
- True if the ACI had a targattrfilter rule that matched.
-
getControlOID
public String getControlOID()
Description copied from interface:AciTargetMatchContextReturn the OID (Object Identifier) string of the control being evaluated.- Specified by:
getControlOIDin interfaceAciTargetMatchContext- Returns:
- The OID string of the control being evaluated.
-
getExtOpOID
public String getExtOpOID()
Description copied from interface:AciTargetMatchContextReturn The OID (Object Identifier) string of the extended operation being evaluated.- Specified by:
getExtOpOIDin interfaceAciTargetMatchContext- Returns:
- The OID string of the extended operation being evaluated.
-
setControlOID
protected void setControlOID(String oid)
Set the the controlOID value to the specified oid string.- Parameters:
oid- The control oid string.
-
setExtOpOID
protected void setExtOpOID(String oid)
Set the extended operation OID value to the specified oid string.- Parameters:
oid- The extended operation oid string.
-
hasAuthenticationMethod
public EnumEvalResult hasAuthenticationMethod(org.opends.server.authorization.dseecompat.EnumAuthMethod authMethod, String saslMech)
Description copied from interface:AciEvalContextDetermine whether the client connection has been authenticated using a specified authentication method. This method is used for the authmethod bind rule keyword.- Specified by:
hasAuthenticationMethodin interfaceAciEvalContext- Parameters:
authMethod- The required authentication method.saslMech- The required SASL mechanism if the authentication method is SASL.- Returns:
- An evaluation result indicating whether the client connection has been authenticated using the required authentication method.
-
isMemberOf
public boolean isMemberOf(Group<?> group)
Description copied from interface:AciEvalContextReturn true if the operation associated with this evaluation context is a member of the specified group. Calls the ClientConnection.isMemberOf() method, which checks authorization DN membership in the specified group.- Specified by:
isMemberOfin interfaceAciEvalContext- Parameters:
group- The group to check membership in.- Returns:
trueif the authorization DN of the operation is a member of the specified group.
-
rightToString
public String rightToString()
Return a string representation of the current right being evaluated. Used in geteffectiverights control evaluation to build summary string.JNR: I find the implementation in this method dubious.
- Specified by:
rightToStringin interfaceAciEvalContext- Returns:
- String representation of the current right being evaluated.
- See Also:
EnumRight.getEnumRight(int)
-
setEvalUserAttributes
public void setEvalUserAttributes(int v)
Description copied from interface:AciTargetMatchContextThis method toggles a mask that indicates that access checking of individual user attributes may or may not be skipped depending on if there is a single ACI containing a targetattr all user attributes rule (targetattr="*"). The only case where individual user attribute access checking can be skipped, is when a single ACI matched using a targetattr all user attributes rule and the attribute type being check is not operational.- Specified by:
setEvalUserAttributesin interfaceAciTargetMatchContext- Parameters:
v- The mask to this value.
-
setEvalOpAttributes
public void setEvalOpAttributes(int v)
Description copied from interface:AciTargetMatchContextThis method toggles a mask that indicates that access checking of individual operational attributes may or may not be skipped depending on if there is a single ACI containing a targetattr all operational attributes rule (targetattr="+"). The only case where individual operational attribute access checking can be skipped, is when a single ACI matched using a targetattr all operational attributes rule and the attribute type being check is operational.- Specified by:
setEvalOpAttributesin interfaceAciTargetMatchContext- Parameters:
v- The mask to this value.
-
hasEvalUserAttributes
public boolean hasEvalUserAttributes()
Description copied from interface:AciTargetMatchContextReturn true if the evaluating ACI either contained an explicitly defined user attribute type in a targeattr target rule or both a targetattr all user attributes rule matched and a explicitly defined targetattr target rule matched.- Specified by:
hasEvalUserAttributesin interfaceAciTargetMatchContext- Returns:
- True if the above condition was seen.
-
hasEvalOpAttributes
public boolean hasEvalOpAttributes()
Description copied from interface:AciTargetMatchContextReturn true if the evaluating ACI either contained an explicitly defined operational attribute type in a targetattr target rule or both a targetattr all operational attributes rule matched and a explicitly defined targetattr target rule matched.- Specified by:
hasEvalOpAttributesin interfaceAciTargetMatchContext- Returns:
- True if the above condition was seen.
-
hasAllUserAttributes
public boolean hasAllUserAttributes()
Return true if the evaluating ACI contained a targetattr all user attributes rule match.- Returns:
- True if the above condition was seen.
-
hasAllOpAttributes
public boolean hasAllOpAttributes()
Return true if the evaluating ACI contained a targetattr all operational attributes rule match.- Returns:
- True if the above condition was seen.
-
clearEvalAttributes
public void clearEvalAttributes(int v)
Description copied from interface:AciTargetMatchContextUsed to clear the mask used to detect if access checking needs to be performed on individual attributes types. The specified value is cleared from the mask or if the value equals 0 the mask is completely cleared.- Specified by:
clearEvalAttributesin interfaceAciTargetMatchContext- Parameters:
v- The flag to clear or 0 to set the mask to 0.
-
getCurrentSSF
public int getCurrentSSF()
Description copied from interface:AciEvalContextReturn the current SSF (Security Strength Factor) of the underlying connection.- Specified by:
getCurrentSSFin interfaceAciEvalContext- Returns:
- The current SSF of the connection.
-
-