Package org.opends.server.core
Class AccessControlConfigManager
- java.lang.Object
-
- org.opends.server.core.AccessControlConfigManager
-
- All Implemented Interfaces:
ConfigurationChangeListener<AccessControlHandlerCfg>,AlertGenerator
public final class AccessControlConfigManager extends Object implements AlertGenerator, ConfigurationChangeListener<AccessControlHandlerCfg>
This class manages the application-wide access-control configuration.When access control is disabled a default "permissive" access control implementation is used, which permits all operations regardless of the identity of the user.
-
-
Method Summary
All Methods Static Methods Instance Methods Concrete Methods Modifier and Type Method Description ConfigChangeResultapplyConfigurationChange(AccessControlHandlerCfg configuration)Applies the configuration changes to this change listener.AccessControlHandler<?>getAccessControlHandler()Get the active access control handler.LinkedHashMap<String,String>getAlerts()Retrieves information about the set of alerts that this generator may produce.StringgetClassName()Retrieves the fully-qualified name of the Java class for this alert generator implementation.DNgetComponentEntryDN()Retrieves the DN of the configuration entry with which this alert generator is associated.static AccessControlConfigManagergetInstance()Get the single application-wide access control manager instance.voidinitializeAccessControl(ServerContext serverContext)Initializes the access control sub-system.booleanisAccessControlEnabled()Determine if access control is enabled according to the current configuration.booleanisConfigurationChangeAcceptable(AccessControlHandlerCfg configuration, List<org.forgerock.i18n.LocalizableMessage> unacceptableReasons)Indicates whether the proposed change to the configuration is acceptable to this change listener.
-
-
-
Method Detail
-
getInstance
public static AccessControlConfigManager getInstance()
Get the single application-wide access control manager instance.- Returns:
- The access control manager.
-
isAccessControlEnabled
public boolean isAccessControlEnabled()
Determine if access control is enabled according to the current configuration.- Returns:
trueif access control is enabled,falseotherwise.
-
getAccessControlHandler
public AccessControlHandler<?> getAccessControlHandler()
Get the active access control handler.When access control is disabled, this method returns a default access control implementation which permits all operations.
- Returns:
- The active access control handler (never
null).
-
initializeAccessControl
public void initializeAccessControl(ServerContext serverContext) throws ConfigException, InitializationException
Initializes the access control sub-system. This should only be called at Directory Server startup. If an error occurs then an exception will be thrown and the Directory Server will fail to start (this prevents accidental exposure of user data due to misconfiguration).- Parameters:
serverContext- The server context.- Throws:
ConfigException- If an access control configuration error is detected.InitializationException- If a problem occurs while initializing the access control handler that is not related to the Directory Server configuration.
-
isConfigurationChangeAcceptable
public boolean isConfigurationChangeAcceptable(AccessControlHandlerCfg configuration, List<org.forgerock.i18n.LocalizableMessage> unacceptableReasons)
Description copied from interface:ConfigurationChangeListenerIndicates whether the proposed change to the configuration is acceptable to this change listener.- Specified by:
isConfigurationChangeAcceptablein interfaceConfigurationChangeListener<AccessControlHandlerCfg>- Parameters:
configuration- The new configuration containing the changes.unacceptableReasons- A list that can be used to hold messages about why the provided configuration is not acceptable.- Returns:
- Returns
trueif the proposed change is acceptable, orfalseif it is not.
-
applyConfigurationChange
public ConfigChangeResult applyConfigurationChange(AccessControlHandlerCfg configuration)
Description copied from interface:ConfigurationChangeListenerApplies the configuration changes to this change listener.- Specified by:
applyConfigurationChangein interfaceConfigurationChangeListener<AccessControlHandlerCfg>- Parameters:
configuration- The new configuration containing the changes.- Returns:
- Returns information about the result of changing the configuration.
-
getComponentEntryDN
public DN getComponentEntryDN()
Description copied from interface:AlertGeneratorRetrieves the DN of the configuration entry with which this alert generator is associated.- Specified by:
getComponentEntryDNin interfaceAlertGenerator- Returns:
- The DN of the configuration entry with which this alert generator is associated.
-
getClassName
public String getClassName()
Description copied from interface:AlertGeneratorRetrieves the fully-qualified name of the Java class for this alert generator implementation.- Specified by:
getClassNamein interfaceAlertGenerator- Returns:
- The fully-qualified name of the Java class for this alert generator implementation.
-
getAlerts
public LinkedHashMap<String,String> getAlerts()
Description copied from interface:AlertGeneratorRetrieves information about the set of alerts that this generator may produce. The map returned should be between the notification type for a particular notification and the human-readable description for that notification. This alert generator must not generate any alerts with types that are not contained in this list.- Specified by:
getAlertsin interfaceAlertGenerator- Returns:
- Information about the set of alerts that this generator may produce.
-
-