Package org.opends.server.core
Interface BindOperation
-
- All Known Implementing Classes:
BindOperationBasis,BindOperationWrapper,LocalBackendBindOperation
public interface BindOperation extends Operation
This interface defines an operation that may be used to authenticate a user to the Directory Server. Note that for security restrictions, response messages that may be returned to the client must be carefully cleaned to ensure that they do not provide a malicious client with information that may be useful in an attack. This does impact the debugability of the server, but that can be addressed by calling thesetAuthFailureReasonmethod, which can provide a reason for a failure in a form that will not be returned to the client but may be written to a log file.
-
-
Field Summary
-
Fields inherited from interface org.opends.server.types.Operation
LOCALBACKENDOPERATIONS
-
-
Method Summary
All Methods Instance Methods Abstract Methods Modifier and Type Method Description AuthenticationInfogetAuthenticationInfo()Retrieves the authentication info that resulted from processing this bind operation.AuthenticationTypegetAuthenticationType()Retrieves the authentication type for this bind operation.org.forgerock.i18n.LocalizableMessagegetAuthFailureReason()Retrieves a human-readable message providing the reason that the authentication failed, if available.DNgetBindDN()Retrieves the bind DN for this bind operation.StringgetProtocolVersion()Retrieves a string representation of the protocol version associated with this bind request.ByteStringgetRawBindDN()Retrieves the raw, unprocessed bind DN for this bind operation as contained in the client request.EntrygetSASLAuthUserEntry()Retrieves the user entry associated with the SASL authentication attempt.ByteStringgetSASLCredentials()Retrieves the SASL credentials for this bind operation.StringgetSASLMechanism()Retrieves the SASL mechanism for this bind operation.ByteStringgetServerSASLCredentials()Retrieves the set of server SASL credentials to include in the bind response.ByteStringgetSimplePassword()Retrieves the simple authentication password for this bind operation.DNgetUserEntryDN()Retrieves the user entry DN for this bind operation.voidsetAuthenticationInfo(AuthenticationInfo authInfo)Specifies the authentication info that resulted from processing this bind operation.voidsetAuthFailureReason(org.forgerock.i18n.LocalizableMessage message)Specifies the reason that the authentication failed.voidsetProtocolVersion(String protocolVersion)Specifies the string representation of the protocol version associated with this bind request.voidsetRawBindDN(ByteString rawBindDN)Specifies the raw, unprocessed bind DN for this bind operation.voidsetSASLAuthUserEntry(Entry saslAuthUserEntry)Specifies the user entry associated with the SASL authentication attempt.voidsetSASLCredentials(String saslMechanism, ByteString saslCredentials)Specifies the SASL credentials for this bind operation.voidsetServerSASLCredentials(ByteString serverSASLCredentials)Specifies the set of server SASL credentials to include in the bind response.voidsetSimplePassword(ByteString simplePassword)Specifies the simple authentication password for this bind operation.voidsetUserEntryDN(DN userEntryDN)Set the user entry DN for this bind operation.-
Methods inherited from interface org.opends.server.types.Operation
abort, addAdditionalLogItem, addRequestControl, addResponseControl, appendErrorMessage, appendMaskedErrorMessage, cancel, checkIfCanceled, disconnectClient, dontSynchronize, getAdditionalLogItems, getAttachment, getAttachments, getAuthorizationDN, getAuthorizationEntry, getCancelRequest, getCancelResult, getClientConnection, getConnectionID, getErrorMessage, getMaskedErrorMessage, getMaskedResultCode, getMatchedDN, getMessageID, getOperationID, getOperationType, getProcessingNanoTime, getProcessingStartTime, getProcessingStopTime, getProcessingTime, getProxiedAuthorizationDN, getReferralURLs, getRequestControl, getRequestControls, getResponseControls, getResultCode, isInnerOperation, isInternalOperation, isSynchronizationOperation, operationCompleted, registerPostResponseCallback, removeAttachment, removeResponseControl, run, setAttachment, setAttachments, setAuthorizationEntry, setDontSynchronize, setErrorMessage, setInnerOperation, setInternalOperation, setMaskedErrorMessage, setMaskedResultCode, setMatchedDN, setProxiedAuthorizationDN, setReferralURLs, setResponseData, setResultCode, setSynchronizationOperation, toString, toString
-
-
-
-
Method Detail
-
getAuthenticationType
AuthenticationType getAuthenticationType()
Retrieves the authentication type for this bind operation.- Returns:
- The authentication type for this bind operation.
-
getRawBindDN
ByteString getRawBindDN()
Retrieves the raw, unprocessed bind DN for this bind operation as contained in the client request. The value may not actually contain a valid DN, as no validation will have been performed.- Returns:
- The raw, unprocessed bind DN for this bind operation as contained in the client request.
-
setRawBindDN
void setRawBindDN(ByteString rawBindDN)
Specifies the raw, unprocessed bind DN for this bind operation. This should only be called by pre-parse plugins.- Parameters:
rawBindDN- The raw, unprocessed bind DN for this bind operation.
-
getProtocolVersion
String getProtocolVersion()
Retrieves a string representation of the protocol version associated with this bind request.- Returns:
- A string representation of the protocol version associated with this bind request.
-
setProtocolVersion
void setProtocolVersion(String protocolVersion)
Specifies the string representation of the protocol version associated with this bind request.- Parameters:
protocolVersion- The string representation of the protocol version associated with this bind request.
-
getBindDN
DN getBindDN()
Retrieves the bind DN for this bind operation. This method should not be called by pre-parse plugins, as the raw value will not have been processed by that time. Instead, pre-parse plugins should call thegetRawBindDNmethod.- Returns:
- The bind DN for this bind operation, or
nullif the raw DN has not yet been processed.
-
getSimplePassword
ByteString getSimplePassword()
Retrieves the simple authentication password for this bind operation.- Returns:
- The simple authentication password for this bind operation.
-
setSimplePassword
void setSimplePassword(ByteString simplePassword)
Specifies the simple authentication password for this bind operation.- Parameters:
simplePassword- The simple authentication password for this bind operation.
-
getSASLMechanism
String getSASLMechanism()
Retrieves the SASL mechanism for this bind operation.- Returns:
- The SASL mechanism for this bind operation, or
nullif the bind does not use SASL authentication.
-
getSASLCredentials
ByteString getSASLCredentials()
Retrieves the SASL credentials for this bind operation.- Returns:
- The SASL credentials for this bind operation, or
nullif there are none or if the bind does not use SASL authentication.
-
setSASLCredentials
void setSASLCredentials(String saslMechanism, ByteString saslCredentials)
Specifies the SASL credentials for this bind operation.- Parameters:
saslMechanism- The SASL mechanism for this bind operation.saslCredentials- The SASL credentials for this bind operation, ornullif there are none.
-
getServerSASLCredentials
ByteString getServerSASLCredentials()
Retrieves the set of server SASL credentials to include in the bind response.- Returns:
- The set of server SASL credentials to include in the bind
response, or
nullif there are none.
-
setServerSASLCredentials
void setServerSASLCredentials(ByteString serverSASLCredentials)
Specifies the set of server SASL credentials to include in the bind response.- Parameters:
serverSASLCredentials- The set of server SASL credentials to include in the bind response.
-
getSASLAuthUserEntry
Entry getSASLAuthUserEntry()
Retrieves the user entry associated with the SASL authentication attempt. This should be set by any SASL mechanism in which the processing was able to get far enough to make this determination, regardless of whether the authentication was ultimately successful.- Returns:
- The user entry associated with the SASL authentication attempt, or
nullif it was not a SASL authentication or the SASL processing was not able to map the request to a user.
-
setSASLAuthUserEntry
void setSASLAuthUserEntry(Entry saslAuthUserEntry)
Specifies the user entry associated with the SASL authentication attempt. This should be set by any SASL mechanism in which the processing was able to get far enough to make this determination, regardless of whether the authentication was ultimately successful.- Parameters:
saslAuthUserEntry- The user entry associated with the SASL authentication attempt.
-
getAuthFailureReason
org.forgerock.i18n.LocalizableMessage getAuthFailureReason()
Retrieves a human-readable message providing the reason that the authentication failed, if available.- Returns:
- A human-readable message providing the reason that the
authentication failed, or
nullif none is available.
-
setAuthFailureReason
void setAuthFailureReason(org.forgerock.i18n.LocalizableMessage message)
Specifies the reason that the authentication failed.- Parameters:
message- providing the reason that the authentication failed.
-
getUserEntryDN
DN getUserEntryDN()
Retrieves the user entry DN for this bind operation. It will only be available if the bind processing has proceeded far enough to identify the user attempting to authenticate.- Returns:
- The user entry DN for this bind operation, or
nullif the bind processing has not progressed far enough to identify the user or if the user DN could not be determined.
-
getAuthenticationInfo
AuthenticationInfo getAuthenticationInfo()
Retrieves the authentication info that resulted from processing this bind operation. It will only be valid if the bind processing was successful.- Returns:
- The authentication info that resulted from processing this bind operation.
-
setAuthenticationInfo
void setAuthenticationInfo(AuthenticationInfo authInfo)
Specifies the authentication info that resulted from processing this bind operation. This method must only be called by SASL mechanism handlers during the course of processing theprocessSASLBindmethod.- Parameters:
authInfo- The authentication info that resulted from processing this bind operation.
-
setUserEntryDN
void setUserEntryDN(DN userEntryDN)
Set the user entry DN for this bind operation.- Parameters:
userEntryDN- The user entry DN for this bind operation, ornullif the bind processing has not progressed far enough to identify the user or if the user DN could not be determined.
-
-