Class BindOperationBasis

  • All Implemented Interfaces:
    Runnable, BindOperation, Operation, PluginOperation, PostResponseOperation, PreParseBindOperation, PreParseOperation

    public class BindOperationBasis
    extends AbstractOperation
    implements BindOperation, PreParseBindOperation
    This class defines an operation that may be used to authenticate a user to the Directory Server. Note that for security restrictions, response messages that may be returned to the client must be carefully cleaned to ensure that they do not provide a malicious client with information that may be useful in an attack. This does impact the debuggability of the server, but that can be addressed by calling the setAuthFailureReason method, which can provide a reason for a failure in a form that will not be returned to the client but may be written to a log file.
    • Constructor Detail

      • BindOperationBasis

        public BindOperationBasis​(ClientConnection clientConnection,
                                  long operationID,
                                  int messageID,
                                  List<Control> requestControls,
                                  String protocolVersion,
                                  ByteString rawBindDN,
                                  ByteString simplePassword)
        Creates a new simple bind operation with the provided information.
        Parameters:
        clientConnection - The client connection with which this operation is associated.
        operationID - The operation ID for this operation.
        messageID - The message ID of the request with which this operation is associated.
        requestControls - The set of controls included in the request.
        protocolVersion - The string representation of the protocol version associated with this bind request.
        rawBindDN - The raw, unprocessed bind DN as provided in the request from the client.
        simplePassword - The password to use for the simple authentication.
      • BindOperationBasis

        public BindOperationBasis​(ClientConnection clientConnection,
                                  long operationID,
                                  int messageID,
                                  List<Control> requestControls,
                                  String protocolVersion,
                                  ByteString rawBindDN,
                                  String saslMechanism,
                                  ByteString saslCredentials)
        Creates a new SASL bind operation with the provided information.
        Parameters:
        clientConnection - The client connection with which this operation is associated.
        operationID - The operation ID for this operation.
        messageID - The message ID of the request with which this operation is associated.
        requestControls - The set of controls included in the request.
        protocolVersion - The string representation of the protocol version associated with this bind request.
        rawBindDN - The raw, unprocessed bind DN as provided in the request from the client.
        saslMechanism - The SASL mechanism included in the request.
        saslCredentials - The optional SASL credentials included in the request.
      • BindOperationBasis

        public BindOperationBasis​(ClientConnection clientConnection,
                                  long operationID,
                                  int messageID,
                                  List<Control> requestControls,
                                  String protocolVersion,
                                  DN bindDN,
                                  ByteString simplePassword)
        Creates a new simple bind operation with the provided information.
        Parameters:
        clientConnection - The client connection with which this operation is associated.
        operationID - The operation ID for this operation.
        messageID - The message ID of the request with which this operation is associated.
        requestControls - The set of controls included in the request.
        protocolVersion - The string representation of the protocol version associated with this bind request.
        bindDN - The bind DN for this bind operation.
        simplePassword - The password to use for the simple authentication.
      • BindOperationBasis

        public BindOperationBasis​(ClientConnection clientConnection,
                                  long operationID,
                                  int messageID,
                                  List<Control> requestControls,
                                  String protocolVersion,
                                  DN bindDN,
                                  String saslMechanism,
                                  ByteString saslCredentials)
        Creates a new SASL bind operation with the provided information.
        Parameters:
        clientConnection - The client connection with which this operation is associated.
        operationID - The operation ID for this operation.
        messageID - The message ID of the request with which this operation is associated.
        requestControls - The set of controls included in the request.
        protocolVersion - The string representation of the protocol version associated with this bind request.
        bindDN - The bind DN for this bind operation.
        saslMechanism - The SASL mechanism included in the request.
        saslCredentials - The optional SASL credentials included in the request.
    • Method Detail

      • getProxiedAuthorizationDN

        public DN getProxiedAuthorizationDN()
        Description copied from interface: Operation
        Retrieves the proxied authorization DN for this operation if proxied authorization has been requested.
        Specified by:
        getProxiedAuthorizationDN in interface Operation
        Returns:
        The proxied authorization DN for this operation if proxied authorization has been requested, or null if proxied authorization has not been requested.
      • setProxiedAuthorizationDN

        public void setProxiedAuthorizationDN​(DN proxiedAuthorizationDN)
        Description copied from interface: Operation
        Set the proxied authorization DN for this operation if proxied authorization has been requested.
        Specified by:
        setProxiedAuthorizationDN in interface Operation
        Parameters:
        proxiedAuthorizationDN - The proxied authorization DN for this operation if proxied authorization has been requested, or null if proxied authorization has not been requested.
      • getRawBindDN

        public final ByteString getRawBindDN()
        Description copied from interface: BindOperation
        Retrieves the raw, unprocessed bind DN for this bind operation as contained in the client request. The value may not actually contain a valid DN, as no validation will have been performed.
        Specified by:
        getRawBindDN in interface BindOperation
        Specified by:
        getRawBindDN in interface PreParseBindOperation
        Returns:
        The raw, unprocessed bind DN for this bind operation as contained in the client request.
      • setRawBindDN

        public final void setRawBindDN​(ByteString rawBindDN)
        Description copied from interface: BindOperation
        Specifies the raw, unprocessed bind DN for this bind operation. This should only be called by pre-parse plugins.
        Specified by:
        setRawBindDN in interface BindOperation
        Specified by:
        setRawBindDN in interface PreParseBindOperation
        Parameters:
        rawBindDN - The raw, unprocessed bind DN for this bind operation.
      • getBindDN

        public final DN getBindDN()
        Description copied from interface: BindOperation
        Retrieves the bind DN for this bind operation. This method should not be called by pre-parse plugins, as the raw value will not have been processed by that time. Instead, pre-parse plugins should call the getRawBindDN method.
        Specified by:
        getBindDN in interface BindOperation
        Returns:
        The bind DN for this bind operation, or null if the raw DN has not yet been processed.
      • setSASLCredentials

        public final void setSASLCredentials​(String saslMechanism,
                                             ByteString saslCredentials)
        Description copied from interface: BindOperation
        Specifies the SASL credentials for this bind operation.
        Specified by:
        setSASLCredentials in interface BindOperation
        Specified by:
        setSASLCredentials in interface PreParseBindOperation
        Parameters:
        saslMechanism - The SASL mechanism for this bind operation.
        saslCredentials - The SASL credentials for this bind operation, or null if there are none.
      • getServerSASLCredentials

        public final ByteString getServerSASLCredentials()
        Description copied from interface: BindOperation
        Retrieves the set of server SASL credentials to include in the bind response.
        Specified by:
        getServerSASLCredentials in interface BindOperation
        Returns:
        The set of server SASL credentials to include in the bind response, or null if there are none.
      • getSASLAuthUserEntry

        public final Entry getSASLAuthUserEntry()
        Description copied from interface: BindOperation
        Retrieves the user entry associated with the SASL authentication attempt. This should be set by any SASL mechanism in which the processing was able to get far enough to make this determination, regardless of whether the authentication was ultimately successful.
        Specified by:
        getSASLAuthUserEntry in interface BindOperation
        Returns:
        The user entry associated with the SASL authentication attempt, or null if it was not a SASL authentication or the SASL processing was not able to map the request to a user.
      • setSASLAuthUserEntry

        public final void setSASLAuthUserEntry​(Entry saslAuthUserEntry)
        Description copied from interface: BindOperation
        Specifies the user entry associated with the SASL authentication attempt. This should be set by any SASL mechanism in which the processing was able to get far enough to make this determination, regardless of whether the authentication was ultimately successful.
        Specified by:
        setSASLAuthUserEntry in interface BindOperation
        Parameters:
        saslAuthUserEntry - The user entry associated with the SASL authentication attempt.
      • getAuthFailureReason

        public final org.forgerock.i18n.LocalizableMessage getAuthFailureReason()
        Description copied from interface: BindOperation
        Retrieves a human-readable message providing the reason that the authentication failed, if available.
        Specified by:
        getAuthFailureReason in interface BindOperation
        Returns:
        A human-readable message providing the reason that the authentication failed, or null if none is available.
      • getUserEntryDN

        public final DN getUserEntryDN()
        Description copied from interface: BindOperation
        Retrieves the user entry DN for this bind operation. It will only be available if the bind processing has proceeded far enough to identify the user attempting to authenticate.
        Specified by:
        getUserEntryDN in interface BindOperation
        Returns:
        The user entry DN for this bind operation, or null if the bind processing has not progressed far enough to identify the user or if the user DN could not be determined.
      • getAuthenticationInfo

        public final AuthenticationInfo getAuthenticationInfo()
        Description copied from interface: BindOperation
        Retrieves the authentication info that resulted from processing this bind operation. It will only be valid if the bind processing was successful.
        Specified by:
        getAuthenticationInfo in interface BindOperation
        Returns:
        The authentication info that resulted from processing this bind operation.
      • setAuthenticationInfo

        public final void setAuthenticationInfo​(AuthenticationInfo authInfo)
        Description copied from interface: BindOperation
        Specifies the authentication info that resulted from processing this bind operation. This method must only be called by SASL mechanism handlers during the course of processing the processSASLBind method.
        Specified by:
        setAuthenticationInfo in interface BindOperation
        Parameters:
        authInfo - The authentication info that resulted from processing this bind operation.
      • getResponseControls

        public final List<Control> getResponseControls()
        Description copied from interface: Operation
        Retrieves the set of controls to include in the response to the client. The contents of this list must not be altered.
        Specified by:
        getResponseControls in interface Operation
        Specified by:
        getResponseControls in interface PluginOperation
        Returns:
        The set of controls to include in the response to the client.
      • addResponseControl

        public final void addResponseControl​(Control control)
        Description copied from interface: Operation
        Adds the provided control to the set of controls to include in the response to the client. This method may not be called by post-response plugins.
        Specified by:
        addResponseControl in interface Operation
        Specified by:
        addResponseControl in interface PreParseOperation
        Parameters:
        control - The control to add to the set of controls to include in the response to the client.
      • removeResponseControl

        public final void removeResponseControl​(Control control)
        Description copied from interface: Operation
        Removes the provided control from the set of controls to include in the response to the client. This method may not be called by post-response plugins.
        Specified by:
        removeResponseControl in interface Operation
        Specified by:
        removeResponseControl in interface PreParseOperation
        Parameters:
        control - The control to remove from the set of controls to include in the response to the client.
      • toString

        public final void toString​(StringBuilder buffer)
        Description copied from interface: Operation
        Appends a string representation of this operation to the provided buffer.
        Specified by:
        toString in interface Operation
        Specified by:
        toString in interface PluginOperation
        Parameters:
        buffer - The buffer into which a string representation of this operation should be appended.
      • setUserEntryDN

        public void setUserEntryDN​(DN userEntryDN)
        Description copied from interface: BindOperation
        Set the user entry DN for this bind operation.
        Specified by:
        setUserEntryDN in interface BindOperation
        Parameters:
        userEntryDN - The user entry DN for this bind operation, or null if the bind processing has not progressed far enough to identify the user or if the user DN could not be determined.
      • setProtocolVersion

        public void setProtocolVersion​(String protocolVersion)
        Description copied from interface: BindOperation
        Specifies the string representation of the protocol version associated with this bind request.
        Specified by:
        setProtocolVersion in interface BindOperation
        Specified by:
        setProtocolVersion in interface PreParseBindOperation
        Parameters:
        protocolVersion - The string representation of the protocol version associated with this bind request.
      • run

        public final void run()
        Description copied from interface: Operation
        Performs the work of actually processing this operation. This should include all processing for the operation, including invoking pre-parse and post-response plugins, logging messages and any other work that might need to be done in the course of processing.
        Specified by:
        run in interface Operation
        Specified by:
        run in interface Runnable
      • updateOperationErrMsgAndResCode

        public void updateOperationErrMsgAndResCode()
        Description copied from class: AbstractOperation
        Updates the error message and the result code of the operation. This method is called because no workflows were found to process the operation.
        Overrides:
        updateOperationErrMsgAndResCode in class AbstractOperation