Package org.opends.server.core
Class AuthenticatedUsers
- java.lang.Object
-
- org.opends.server.api.plugin.DirectoryServerPlugin<PluginCfg>
-
- org.opends.server.api.plugin.InternalDirectoryServerPlugin
-
- org.opends.server.core.AuthenticatedUsers
-
public class AuthenticatedUsers extends InternalDirectoryServerPlugin
This class provides a data structure which maps an authenticated user DN to the set of client connections authenticated as that user. Note that a single client connection may be registered with two different user DNs if the client has different authentication and authorization identities.
This class also provides a mechanism for detecting changes to authenticated user entries and notifying the corresponding client connections so that they can update their cached versions.
The user map is aConcurrentHashMap, so registering and deregistering a connection (which happens on every bind and unbind) is lock-free at the map level and only contends at the granularity of a single hash bin. Each value is a concurrent set with O(1) add/remove, so many connections authenticating as the same user (e.g. an application service account) do not degrade: a copy-on-write set here would copy the whole connection array under the bin lock on every bind. The subtree operations triggered by changes to authenticated user entries (delete / modify / modify DN) are rare and scan the key set, which the concurrent map supports with weakly-consistent iteration.
-
-
Constructor Summary
Constructors Constructor Description AuthenticatedUsers()Creates a new instance of this authenticated users object.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description PluginResult.PostResponsedoPostResponse(PostResponseDeleteOperation op)Performs any necessary processing that should be done after the Directory Server has completed all processing for a delete operation and has sent the response to the client.PluginResult.PostResponsedoPostResponse(PostResponseModifyDNOperation op)Performs any necessary processing that should be done after the Directory Server has completed all processing for a modify DN operation and has sent the response to the client.PluginResult.PostResponsedoPostResponse(PostResponseModifyOperation op)Performs any necessary processing that should be done after the Directory Server has completed all processing for a modify operation and has sent the response to the client.Set<ClientConnection>get(DN userDN)Retrieves the set of client connections authenticated as the specified user.voidput(DN userDN, ClientConnection clientConnection)Registers the provided user DN and client connection with this object.voidremove(DN userDN, ClientConnection clientConnection)Deregisters the provided user DN and client connection with this object.-
Methods inherited from class org.opends.server.api.plugin.InternalDirectoryServerPlugin
initializePlugin, isConfigurationAcceptable
-
Methods inherited from class org.opends.server.api.plugin.DirectoryServerPlugin
doLDIFExport, doLDIFImport, doLDIFImportBegin, doLDIFImportEnd, doPostConnect, doPostDisconnect, doPostOperation, doPostOperation, doPostOperation, doPostOperation, doPostOperation, doPostOperation, doPostOperation, doPostOperation, doPostOperation, doPostOperation, doPostResponse, doPostResponse, doPostResponse, doPostResponse, doPostResponse, doPostSynchronization, doPostSynchronization, doPostSynchronization, doPostSynchronization, doPreOperation, doPreOperation, doPreOperation, doPreOperation, doPreOperation, doPreOperation, doPreOperation, doPreOperation, doPreParse, doPreParse, doPreParse, doPreParse, doPreParse, doPreParse, doPreParse, doPreParse, doPreParse, doPreParse, doShutdown, doStartup, finalizePlugin, getPluginEntryDN, getPluginTypes, getServerContext, initializeInternal, invokeForInternalOperations, processIntermediateResponse, processSearchEntry, processSearchReference, processSubordinateDelete, processSubordinateModifyDN, setInvokeForInternalOperations
-
-
-
-
Method Detail
-
put
public void put(DN userDN, ClientConnection clientConnection)
Registers the provided user DN and client connection with this object.- Parameters:
userDN- The DN of the user associated with the provided client connection.clientConnection- The client connection over which the user is authenticated.
-
remove
public void remove(DN userDN, ClientConnection clientConnection)
Deregisters the provided user DN and client connection with this object.- Parameters:
userDN- The DN of the user associated with the provided client connection.clientConnection- The client connection over which the user is authenticated.
-
get
public Set<ClientConnection> get(DN userDN)
Retrieves the set of client connections authenticated as the specified user. This method is only intended for internal testing use and should not be called for any other purpose.- Parameters:
userDN- The DN of the user for which to retrieve the corresponding set of client connections.- Returns:
- The set of client connections authenticated as the specified user,
or
nullif there are none.
-
doPostResponse
public PluginResult.PostResponse doPostResponse(PostResponseDeleteOperation op)
Description copied from class:DirectoryServerPluginPerforms any necessary processing that should be done after the Directory Server has completed all processing for a delete operation and has sent the response to the client.- Overrides:
doPostResponsein classDirectoryServerPlugin<PluginCfg>- Parameters:
op- The delete operation for which processing has completed and the response has been sent to the client.- Returns:
- Information about the result of the plugin processing.
-
doPostResponse
public PluginResult.PostResponse doPostResponse(PostResponseModifyOperation op)
Description copied from class:DirectoryServerPluginPerforms any necessary processing that should be done after the Directory Server has completed all processing for a modify operation and has sent the response to the client.- Overrides:
doPostResponsein classDirectoryServerPlugin<PluginCfg>- Parameters:
op- The modify operation for which processing has completed and the response has been sent to the client.- Returns:
- Information about the result of the plugin processing.
-
doPostResponse
public PluginResult.PostResponse doPostResponse(PostResponseModifyDNOperation op)
Description copied from class:DirectoryServerPluginPerforms any necessary processing that should be done after the Directory Server has completed all processing for a modify DN operation and has sent the response to the client.- Overrides:
doPostResponsein classDirectoryServerPlugin<PluginCfg>- Parameters:
op- The modifyDN operation for which processing has completed and the response has been sent to the client.- Returns:
- Information about the result of the plugin processing.
-
-