Class AccessControlConfigManager

    • Method Detail

      • getInstance

        public static AccessControlConfigManager getInstance()
        Get the single application-wide access control manager instance.
        Returns:
        The access control manager.
      • isAccessControlEnabled

        public boolean isAccessControlEnabled()
        Determine if access control is enabled according to the current configuration.
        Returns:
        true if access control is enabled, false otherwise.
      • getAccessControlHandler

        public AccessControlHandler<?> getAccessControlHandler()
        Get the active access control handler.

        When access control is disabled, this method returns a default access control implementation which permits all operations.

        Returns:
        The active access control handler (never null).
      • initializeAccessControl

        public void initializeAccessControl​(ServerContext serverContext)
                                     throws ConfigException,
                                            InitializationException
        Initializes the access control sub-system. This should only be called at Directory Server startup. If an error occurs then an exception will be thrown and the Directory Server will fail to start (this prevents accidental exposure of user data due to misconfiguration).
        Parameters:
        serverContext - The server context.
        Throws:
        ConfigException - If an access control configuration error is detected.
        InitializationException - If a problem occurs while initializing the access control handler that is not related to the Directory Server configuration.
      • isConfigurationChangeAcceptable

        public boolean isConfigurationChangeAcceptable​(AccessControlHandlerCfg configuration,
                                                       List<org.forgerock.i18n.LocalizableMessage> unacceptableReasons)
        Description copied from interface: ConfigurationChangeListener
        Indicates whether the proposed change to the configuration is acceptable to this change listener.
        Specified by:
        isConfigurationChangeAcceptable in interface ConfigurationChangeListener<AccessControlHandlerCfg>
        Parameters:
        configuration - The new configuration containing the changes.
        unacceptableReasons - A list that can be used to hold messages about why the provided configuration is not acceptable.
        Returns:
        Returns true if the proposed change is acceptable, or false if it is not.
      • getComponentEntryDN

        public DN getComponentEntryDN()
        Description copied from interface: AlertGenerator
        Retrieves the DN of the configuration entry with which this alert generator is associated.
        Specified by:
        getComponentEntryDN in interface AlertGenerator
        Returns:
        The DN of the configuration entry with which this alert generator is associated.
      • getClassName

        public String getClassName()
        Description copied from interface: AlertGenerator
        Retrieves the fully-qualified name of the Java class for this alert generator implementation.
        Specified by:
        getClassName in interface AlertGenerator
        Returns:
        The fully-qualified name of the Java class for this alert generator implementation.
      • getAlerts

        public LinkedHashMap<String,​String> getAlerts()
        Description copied from interface: AlertGenerator
        Retrieves information about the set of alerts that this generator may produce. The map returned should be between the notification type for a particular notification and the human-readable description for that notification. This alert generator must not generate any alerts with types that are not contained in this list.
        Specified by:
        getAlerts in interface AlertGenerator
        Returns:
        Information about the set of alerts that this generator may produce.