Package org.opends.server.core
Class BindOperationBasis
- java.lang.Object
-
- org.opends.server.types.AbstractOperation
-
- org.opends.server.core.BindOperationBasis
-
- All Implemented Interfaces:
Runnable,BindOperation,Operation,PluginOperation,PostResponseOperation,PreParseBindOperation,PreParseOperation
public class BindOperationBasis extends AbstractOperation implements BindOperation, PreParseBindOperation
This class defines an operation that may be used to authenticate a user to the Directory Server. Note that for security restrictions, response messages that may be returned to the client must be carefully cleaned to ensure that they do not provide a malicious client with information that may be useful in an attack. This does impact the debuggability of the server, but that can be addressed by calling thesetAuthFailureReasonmethod, which can provide a reason for a failure in a form that will not be returned to the client but may be written to a log file.
-
-
Field Summary
-
Fields inherited from class org.opends.server.types.AbstractOperation
cancelRequest, cancelResult, clientConnection, messageID, NO_RESPONSE_CONTROLS, operationID
-
Fields inherited from interface org.opends.server.types.Operation
LOCALBACKENDOPERATIONS
-
-
Constructor Summary
Constructors Constructor Description BindOperationBasis(ClientConnection clientConnection, long operationID, int messageID, List<Control> requestControls, String protocolVersion, ByteString rawBindDN, String saslMechanism, ByteString saslCredentials)Creates a new SASL bind operation with the provided information.BindOperationBasis(ClientConnection clientConnection, long operationID, int messageID, List<Control> requestControls, String protocolVersion, ByteString rawBindDN, ByteString simplePassword)Creates a new simple bind operation with the provided information.BindOperationBasis(ClientConnection clientConnection, long operationID, int messageID, List<Control> requestControls, String protocolVersion, DN bindDN, String saslMechanism, ByteString saslCredentials)Creates a new SASL bind operation with the provided information.BindOperationBasis(ClientConnection clientConnection, long operationID, int messageID, List<Control> requestControls, String protocolVersion, DN bindDN, ByteString simplePassword)Creates a new simple bind operation with the provided information.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description voidaddResponseControl(Control control)Adds the provided control to the set of controls to include in the response to the client.AuthenticationInfogetAuthenticationInfo()Retrieves the authentication info that resulted from processing this bind operation.AuthenticationTypegetAuthenticationType()Retrieves the authentication type for this bind operation.org.forgerock.i18n.LocalizableMessagegetAuthFailureReason()Retrieves a human-readable message providing the reason that the authentication failed, if available.DNgetBindDN()Retrieves the bind DN for this bind operation.OperationTypegetOperationType()Retrieves the operation type for this operation.StringgetProtocolVersion()Retrieves a string representation of the protocol version associated with this bind request.DNgetProxiedAuthorizationDN()Retrieves the proxied authorization DN for this operation if proxied authorization has been requested.ByteStringgetRawBindDN()Retrieves the raw, unprocessed bind DN for this bind operation as contained in the client request.List<Control>getResponseControls()Retrieves the set of controls to include in the response to the client.EntrygetSASLAuthUserEntry()Retrieves the user entry associated with the SASL authentication attempt.ByteStringgetSASLCredentials()Retrieves the SASL credentials for this bind operation.StringgetSASLMechanism()Retrieves the SASL mechanism for this bind operation.ByteStringgetServerSASLCredentials()Retrieves the set of server SASL credentials to include in the bind response.ByteStringgetSimplePassword()Retrieves the simple authentication password for this bind operation.DNgetUserEntryDN()Retrieves the user entry DN for this bind operation.voidremoveResponseControl(Control control)Removes the provided control from the set of controls to include in the response to the client.voidrun()Performs the work of actually processing this operation.voidsetAuthenticationInfo(AuthenticationInfo authInfo)Specifies the authentication info that resulted from processing this bind operation.voidsetAuthFailureReason(org.forgerock.i18n.LocalizableMessage message)Specifies the reason that the authentication failed.voidsetProtocolVersion(String protocolVersion)Specifies the string representation of the protocol version associated with this bind request.voidsetProxiedAuthorizationDN(DN proxiedAuthorizationDN)Set the proxied authorization DN for this operation if proxied authorization has been requested.voidsetRawBindDN(ByteString rawBindDN)Specifies the raw, unprocessed bind DN for this bind operation.voidsetSASLAuthUserEntry(Entry saslAuthUserEntry)Specifies the user entry associated with the SASL authentication attempt.voidsetSASLCredentials(String saslMechanism, ByteString saslCredentials)Specifies the SASL credentials for this bind operation.voidsetServerSASLCredentials(ByteString serverSASLCredentials)Specifies the set of server SASL credentials to include in the bind response.voidsetSimplePassword(ByteString simplePassword)Specifies the simple authentication password for this bind operation.voidsetUserEntryDN(DN userEntryDN)Set the user entry DN for this bind operation.voidtoString(StringBuilder buffer)Appends a string representation of this operation to the provided buffer.voidupdateOperationErrMsgAndResCode()Updates the error message and the result code of the operation.-
Methods inherited from class org.opends.server.types.AbstractOperation
abort, addAdditionalLogItem, addRequestControl, appendErrorMessage, appendMaskedErrorMessage, cancel, checkIfCanceled, disconnectClient, dontSynchronize, equals, getAdditionalLogItems, getAttachment, getAttachments, getAuthorizationDN, getAuthorizationEntry, getCancelRequest, getCancelResult, getClientConnection, getConnectionID, getErrorMessage, getMaskedErrorMessage, getMaskedResultCode, getMatchedDN, getMessageID, getOperationID, getProcessingNanoTime, getProcessingStartTime, getProcessingStopTime, getProcessingTime, getReferralURLs, getRequestControl, getRequestControls, getResultCode, getTransactionId, hashCode, invokePostResponseCallbacks, isInnerOperation, isInternalOperation, isSynchronizationOperation, operationCompleted, processOperationResult, processOperationResult, registerPostResponseCallback, removeAttachment, setAttachment, setAttachments, setAuthorizationEntry, setDontSynchronize, setErrorMessage, setInnerOperation, setInternalOperation, setMaskedErrorMessage, setMaskedResultCode, setMatchedDN, setProcessingStartTime, setProcessingStopTime, setReferralURLs, setResponseData, setResultCode, setSynchronizationOperation, toString
-
Methods inherited from class java.lang.Object
clone, finalize, getClass, notify, notifyAll, wait, wait, wait
-
Methods inherited from interface org.opends.server.types.Operation
abort, addAdditionalLogItem, addRequestControl, appendErrorMessage, appendMaskedErrorMessage, cancel, checkIfCanceled, disconnectClient, dontSynchronize, getAdditionalLogItems, getAttachment, getAttachments, getAuthorizationDN, getAuthorizationEntry, getCancelRequest, getCancelResult, getClientConnection, getConnectionID, getErrorMessage, getMaskedErrorMessage, getMaskedResultCode, getMatchedDN, getMessageID, getOperationID, getProcessingNanoTime, getProcessingStartTime, getProcessingStopTime, getProcessingTime, getReferralURLs, getRequestControl, getRequestControls, getResultCode, isInnerOperation, isInternalOperation, isSynchronizationOperation, operationCompleted, registerPostResponseCallback, removeAttachment, setAttachment, setAttachments, setAuthorizationEntry, setDontSynchronize, setErrorMessage, setInnerOperation, setInternalOperation, setMaskedErrorMessage, setMaskedResultCode, setMatchedDN, setReferralURLs, setResponseData, setResultCode, setSynchronizationOperation, toString
-
Methods inherited from interface org.opends.server.types.operation.PluginOperation
checkIfCanceled, disconnectClient, getAttachment, getAttachments, getClientConnection, getConnectionID, getMessageID, getOperationID, getProcessingStartTime, getRequestControl, getRequestControls, isInternalOperation, isSynchronizationOperation, removeAttachment, setAttachment, toString
-
Methods inherited from interface org.opends.server.types.operation.PreParseOperation
addAdditionalLogItem, addRequestControl, appendErrorMessage, getAdditionalLogItems, getErrorMessage, setErrorMessage
-
-
-
-
Constructor Detail
-
BindOperationBasis
public BindOperationBasis(ClientConnection clientConnection, long operationID, int messageID, List<Control> requestControls, String protocolVersion, ByteString rawBindDN, ByteString simplePassword)
Creates a new simple bind operation with the provided information.- Parameters:
clientConnection- The client connection with which this operation is associated.operationID- The operation ID for this operation.messageID- The message ID of the request with which this operation is associated.requestControls- The set of controls included in the request.protocolVersion- The string representation of the protocol version associated with this bind request.rawBindDN- The raw, unprocessed bind DN as provided in the request from the client.simplePassword- The password to use for the simple authentication.
-
BindOperationBasis
public BindOperationBasis(ClientConnection clientConnection, long operationID, int messageID, List<Control> requestControls, String protocolVersion, ByteString rawBindDN, String saslMechanism, ByteString saslCredentials)
Creates a new SASL bind operation with the provided information.- Parameters:
clientConnection- The client connection with which this operation is associated.operationID- The operation ID for this operation.messageID- The message ID of the request with which this operation is associated.requestControls- The set of controls included in the request.protocolVersion- The string representation of the protocol version associated with this bind request.rawBindDN- The raw, unprocessed bind DN as provided in the request from the client.saslMechanism- The SASL mechanism included in the request.saslCredentials- The optional SASL credentials included in the request.
-
BindOperationBasis
public BindOperationBasis(ClientConnection clientConnection, long operationID, int messageID, List<Control> requestControls, String protocolVersion, DN bindDN, ByteString simplePassword)
Creates a new simple bind operation with the provided information.- Parameters:
clientConnection- The client connection with which this operation is associated.operationID- The operation ID for this operation.messageID- The message ID of the request with which this operation is associated.requestControls- The set of controls included in the request.protocolVersion- The string representation of the protocol version associated with this bind request.bindDN- The bind DN for this bind operation.simplePassword- The password to use for the simple authentication.
-
BindOperationBasis
public BindOperationBasis(ClientConnection clientConnection, long operationID, int messageID, List<Control> requestControls, String protocolVersion, DN bindDN, String saslMechanism, ByteString saslCredentials)
Creates a new SASL bind operation with the provided information.- Parameters:
clientConnection- The client connection with which this operation is associated.operationID- The operation ID for this operation.messageID- The message ID of the request with which this operation is associated.requestControls- The set of controls included in the request.protocolVersion- The string representation of the protocol version associated with this bind request.bindDN- The bind DN for this bind operation.saslMechanism- The SASL mechanism included in the request.saslCredentials- The optional SASL credentials included in the request.
-
-
Method Detail
-
getProxiedAuthorizationDN
public DN getProxiedAuthorizationDN()
Description copied from interface:OperationRetrieves the proxied authorization DN for this operation if proxied authorization has been requested.- Specified by:
getProxiedAuthorizationDNin interfaceOperation- Returns:
- The proxied authorization DN for this operation if proxied
authorization has been requested, or
nullif proxied authorization has not been requested.
-
setProxiedAuthorizationDN
public void setProxiedAuthorizationDN(DN proxiedAuthorizationDN)
Description copied from interface:OperationSet the proxied authorization DN for this operation if proxied authorization has been requested.- Specified by:
setProxiedAuthorizationDNin interfaceOperation- Parameters:
proxiedAuthorizationDN- The proxied authorization DN for this operation if proxied authorization has been requested, ornullif proxied authorization has not been requested.
-
getAuthenticationType
public final AuthenticationType getAuthenticationType()
Description copied from interface:BindOperationRetrieves the authentication type for this bind operation.- Specified by:
getAuthenticationTypein interfaceBindOperation- Specified by:
getAuthenticationTypein interfacePreParseBindOperation- Returns:
- The authentication type for this bind operation.
-
getRawBindDN
public final ByteString getRawBindDN()
Description copied from interface:BindOperationRetrieves the raw, unprocessed bind DN for this bind operation as contained in the client request. The value may not actually contain a valid DN, as no validation will have been performed.- Specified by:
getRawBindDNin interfaceBindOperation- Specified by:
getRawBindDNin interfacePreParseBindOperation- Returns:
- The raw, unprocessed bind DN for this bind operation as contained in the client request.
-
setRawBindDN
public final void setRawBindDN(ByteString rawBindDN)
Description copied from interface:BindOperationSpecifies the raw, unprocessed bind DN for this bind operation. This should only be called by pre-parse plugins.- Specified by:
setRawBindDNin interfaceBindOperation- Specified by:
setRawBindDNin interfacePreParseBindOperation- Parameters:
rawBindDN- The raw, unprocessed bind DN for this bind operation.
-
getBindDN
public final DN getBindDN()
Description copied from interface:BindOperationRetrieves the bind DN for this bind operation. This method should not be called by pre-parse plugins, as the raw value will not have been processed by that time. Instead, pre-parse plugins should call thegetRawBindDNmethod.- Specified by:
getBindDNin interfaceBindOperation- Returns:
- The bind DN for this bind operation, or
nullif the raw DN has not yet been processed.
-
getSimplePassword
public final ByteString getSimplePassword()
Description copied from interface:BindOperationRetrieves the simple authentication password for this bind operation.- Specified by:
getSimplePasswordin interfaceBindOperation- Specified by:
getSimplePasswordin interfacePreParseBindOperation- Returns:
- The simple authentication password for this bind operation.
-
setSimplePassword
public final void setSimplePassword(ByteString simplePassword)
Description copied from interface:BindOperationSpecifies the simple authentication password for this bind operation.- Specified by:
setSimplePasswordin interfaceBindOperation- Specified by:
setSimplePasswordin interfacePreParseBindOperation- Parameters:
simplePassword- The simple authentication password for this bind operation.
-
getSASLMechanism
public final String getSASLMechanism()
Description copied from interface:BindOperationRetrieves the SASL mechanism for this bind operation.- Specified by:
getSASLMechanismin interfaceBindOperation- Specified by:
getSASLMechanismin interfacePreParseBindOperation- Returns:
- The SASL mechanism for this bind operation, or
nullif the bind does not use SASL authentication.
-
getSASLCredentials
public final ByteString getSASLCredentials()
Description copied from interface:BindOperationRetrieves the SASL credentials for this bind operation.- Specified by:
getSASLCredentialsin interfaceBindOperation- Specified by:
getSASLCredentialsin interfacePreParseBindOperation- Returns:
- The SASL credentials for this bind operation, or
nullif there are none or if the bind does not use SASL authentication.
-
setSASLCredentials
public final void setSASLCredentials(String saslMechanism, ByteString saslCredentials)
Description copied from interface:BindOperationSpecifies the SASL credentials for this bind operation.- Specified by:
setSASLCredentialsin interfaceBindOperation- Specified by:
setSASLCredentialsin interfacePreParseBindOperation- Parameters:
saslMechanism- The SASL mechanism for this bind operation.saslCredentials- The SASL credentials for this bind operation, ornullif there are none.
-
getServerSASLCredentials
public final ByteString getServerSASLCredentials()
Description copied from interface:BindOperationRetrieves the set of server SASL credentials to include in the bind response.- Specified by:
getServerSASLCredentialsin interfaceBindOperation- Returns:
- The set of server SASL credentials to include in the bind
response, or
nullif there are none.
-
setServerSASLCredentials
public final void setServerSASLCredentials(ByteString serverSASLCredentials)
Description copied from interface:BindOperationSpecifies the set of server SASL credentials to include in the bind response.- Specified by:
setServerSASLCredentialsin interfaceBindOperation- Specified by:
setServerSASLCredentialsin interfacePreParseBindOperation- Parameters:
serverSASLCredentials- The set of server SASL credentials to include in the bind response.
-
getSASLAuthUserEntry
public final Entry getSASLAuthUserEntry()
Description copied from interface:BindOperationRetrieves the user entry associated with the SASL authentication attempt. This should be set by any SASL mechanism in which the processing was able to get far enough to make this determination, regardless of whether the authentication was ultimately successful.- Specified by:
getSASLAuthUserEntryin interfaceBindOperation- Returns:
- The user entry associated with the SASL authentication attempt, or
nullif it was not a SASL authentication or the SASL processing was not able to map the request to a user.
-
setSASLAuthUserEntry
public final void setSASLAuthUserEntry(Entry saslAuthUserEntry)
Description copied from interface:BindOperationSpecifies the user entry associated with the SASL authentication attempt. This should be set by any SASL mechanism in which the processing was able to get far enough to make this determination, regardless of whether the authentication was ultimately successful.- Specified by:
setSASLAuthUserEntryin interfaceBindOperation- Parameters:
saslAuthUserEntry- The user entry associated with the SASL authentication attempt.
-
getAuthFailureReason
public final org.forgerock.i18n.LocalizableMessage getAuthFailureReason()
Description copied from interface:BindOperationRetrieves a human-readable message providing the reason that the authentication failed, if available.- Specified by:
getAuthFailureReasonin interfaceBindOperation- Returns:
- A human-readable message providing the reason that the
authentication failed, or
nullif none is available.
-
setAuthFailureReason
public final void setAuthFailureReason(org.forgerock.i18n.LocalizableMessage message)
Description copied from interface:BindOperationSpecifies the reason that the authentication failed.- Specified by:
setAuthFailureReasonin interfaceBindOperation- Specified by:
setAuthFailureReasonin interfacePreParseBindOperation- Parameters:
message- providing the reason that the authentication failed.
-
getUserEntryDN
public final DN getUserEntryDN()
Description copied from interface:BindOperationRetrieves the user entry DN for this bind operation. It will only be available if the bind processing has proceeded far enough to identify the user attempting to authenticate.- Specified by:
getUserEntryDNin interfaceBindOperation- Returns:
- The user entry DN for this bind operation, or
nullif the bind processing has not progressed far enough to identify the user or if the user DN could not be determined.
-
getAuthenticationInfo
public final AuthenticationInfo getAuthenticationInfo()
Description copied from interface:BindOperationRetrieves the authentication info that resulted from processing this bind operation. It will only be valid if the bind processing was successful.- Specified by:
getAuthenticationInfoin interfaceBindOperation- Returns:
- The authentication info that resulted from processing this bind operation.
-
setAuthenticationInfo
public final void setAuthenticationInfo(AuthenticationInfo authInfo)
Description copied from interface:BindOperationSpecifies the authentication info that resulted from processing this bind operation. This method must only be called by SASL mechanism handlers during the course of processing theprocessSASLBindmethod.- Specified by:
setAuthenticationInfoin interfaceBindOperation- Parameters:
authInfo- The authentication info that resulted from processing this bind operation.
-
getOperationType
public final OperationType getOperationType()
Description copied from interface:OperationRetrieves the operation type for this operation.- Specified by:
getOperationTypein interfaceOperation- Specified by:
getOperationTypein interfacePluginOperation- Returns:
- The operation type for this operation.
-
getResponseControls
public final List<Control> getResponseControls()
Description copied from interface:OperationRetrieves the set of controls to include in the response to the client. The contents of this list must not be altered.- Specified by:
getResponseControlsin interfaceOperation- Specified by:
getResponseControlsin interfacePluginOperation- Returns:
- The set of controls to include in the response to the client.
-
addResponseControl
public final void addResponseControl(Control control)
Description copied from interface:OperationAdds the provided control to the set of controls to include in the response to the client. This method may not be called by post-response plugins.- Specified by:
addResponseControlin interfaceOperation- Specified by:
addResponseControlin interfacePreParseOperation- Parameters:
control- The control to add to the set of controls to include in the response to the client.
-
removeResponseControl
public final void removeResponseControl(Control control)
Description copied from interface:OperationRemoves the provided control from the set of controls to include in the response to the client. This method may not be called by post-response plugins.- Specified by:
removeResponseControlin interfaceOperation- Specified by:
removeResponseControlin interfacePreParseOperation- Parameters:
control- The control to remove from the set of controls to include in the response to the client.
-
toString
public final void toString(StringBuilder buffer)
Description copied from interface:OperationAppends a string representation of this operation to the provided buffer.- Specified by:
toStringin interfaceOperation- Specified by:
toStringin interfacePluginOperation- Parameters:
buffer- The buffer into which a string representation of this operation should be appended.
-
setUserEntryDN
public void setUserEntryDN(DN userEntryDN)
Description copied from interface:BindOperationSet the user entry DN for this bind operation.- Specified by:
setUserEntryDNin interfaceBindOperation- Parameters:
userEntryDN- The user entry DN for this bind operation, ornullif the bind processing has not progressed far enough to identify the user or if the user DN could not be determined.
-
getProtocolVersion
public String getProtocolVersion()
Description copied from interface:BindOperationRetrieves a string representation of the protocol version associated with this bind request.- Specified by:
getProtocolVersionin interfaceBindOperation- Specified by:
getProtocolVersionin interfacePreParseBindOperation- Returns:
- A string representation of the protocol version associated with this bind request.
-
setProtocolVersion
public void setProtocolVersion(String protocolVersion)
Description copied from interface:BindOperationSpecifies the string representation of the protocol version associated with this bind request.- Specified by:
setProtocolVersionin interfaceBindOperation- Specified by:
setProtocolVersionin interfacePreParseBindOperation- Parameters:
protocolVersion- The string representation of the protocol version associated with this bind request.
-
run
public final void run()
Description copied from interface:OperationPerforms the work of actually processing this operation. This should include all processing for the operation, including invoking pre-parse and post-response plugins, logging messages and any other work that might need to be done in the course of processing.
-
updateOperationErrMsgAndResCode
public void updateOperationErrMsgAndResCode()
Description copied from class:AbstractOperationUpdates the error message and the result code of the operation. This method is called because no workflows were found to process the operation.- Overrides:
updateOperationErrMsgAndResCodein classAbstractOperation
-
-