Package org.opends.server.protocols.ldap
Class LDAPClientConnection
- java.lang.Object
-
- org.opends.server.api.ClientConnection
-
- org.opends.server.protocols.ldap.LDAPClientConnection
-
- All Implemented Interfaces:
TLSCapableConnection
public final class LDAPClientConnection extends ClientConnection implements TLSCapableConnection
This class defines an LDAP client connection, which is a type of client connection that will be accepted by an instance of the LDAP connection handler and have its requests decoded by an LDAP request handler.
-
-
Nested Class Summary
-
Nested classes/interfaces inherited from class org.opends.server.api.ClientConnection
ClientConnection.Transaction
-
-
Field Summary
-
Fields inherited from class org.opends.server.api.ClientConnection
authenticationInfo, bindInProgress, saslBindInProgress, startTLSInProgress
-
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description voidcancelAllOperations(CancelRequest cancelRequest)Attempts to cancel all operations in progress on this connection.voidcancelAllOperationsExcept(CancelRequest cancelRequest, int messageID)Attempts to cancel all operations in progress on this connection except the operation with the specified message ID.CancelResultcancelOperation(int messageID, CancelRequest cancelRequest)Attempts to cancel the specified operation.voiddisconnect(DisconnectReason disconnectReason, boolean sendNotification, org.forgerock.i18n.LocalizableMessage message)Closes the connection to the client, optionally sending it a message indicating the reason for the closure.voidfinishBind()Indicates a bind or start TLS request processing is finished and the client connection may start processing data read from the socket again.voidfinishStartTLS()Indicates a bind or start TLS request processing is finished and the client connection may start processing data read from the socket again.ByteChannelgetChannel()Retrieves the TLS redirecting byte channel used in a LDAP client connection.StringgetClientAddress()Retrieves a string representation of the address of the client.Certificate[]getClientCertificateChain()Return the certificate chain array associated with a connection.intgetClientPort()Retrieves the port number for this connection on the client system.ConnectionHandler<?>getConnectionHandler()Retrieves the connection handler that accepted this client connection.longgetConnectionID()Retrieves the connection ID assigned to this connection.longgetIdleTime()Retrieves the length of time in milliseconds that this client connection has been idle.InetAddressgetLocalAddress()Retrieves thejava.net.InetAddressfor the Directory Server system to which the client has established the connection.longgetMaxBlockedWriteTimeLimit()Retrieves the maximum length of time in milliseconds that attempts to write data to the client should be allowed to block.StringgetMonitorSummary()Retrieves a one-line summary of this client connection in a form that is suitable for including in the monitor entry for the associated connection handler.longgetNumberOfOperations()Returns the total number of operations initiated on this connection.OperationgetOperationInProgress(int messageID)Retrieves the operation in progress with the specified message ID.Collection<Operation>getOperationsInProgress()Retrieves the set of operations in progress for this client connection.StringgetProtocol()Retrieves the protocol that the client is using to communicate with the Directory Server.InetAddressgetRemoteAddress()Retrieves thejava.net.InetAddressassociated with the remote client system.StringgetServerAddress()Retrieves a string representation of the address on the server to which the client connected.intgetServerPort()Retrieves the port number for this connection on the server system.SocketChannelgetSocketChannel()Retrieves the socket channel that can be used to communicate with the client.intgetSSF()Return the Security Strength Factor of a client connection.SelectorgetWriteSelector()Retrieves aSelectorthat may be used to ensure that write operations complete in a timely manner, or terminate the connection in the event that they fail to do so.booleanisConnectionValid()Returns whether the Directory Server believes this connection to be valid and available for communication.booleanisSecure()Indicates whether this client connection is currently using a secure mechanism to communicate with the server.booleanprepareTLS(org.forgerock.i18n.LocalizableMessageBuilder unavailableReason)Prepares this connection for using TLS and returns whether TLS protection is actually available for the underlying client connection.booleanremoveOperationInProgress(int messageID)Removes the provided operation from the set of operations in progress for this client connection.protected booleansendIntermediateResponseMessage(IntermediateResponse intermediateResponse)Sends the provided intermediate response message to the client.voidsendResponse(Operation operation)Sends a response to the client based on the information in the provided operation.voidsendSearchEntry(SearchOperation searchOperation, SearchResultEntry searchEntry)Sends the provided search result entry to the client.booleansendSearchReference(SearchOperation searchOperation, SearchResultReference searchReference)Sends the provided search result reference to the client.voidsetSASLPendingProvider(ConnectionSecurityProvider provider)Set the connection provider that is not in use.voidsetTLSPendingProvider(ConnectionSecurityProvider provider)Set the connection provider that is not in use yet.voidtoString(StringBuilder buffer)Appends a string representation of this client connection to the provided buffer.-
Methods inherited from class org.opends.server.api.ClientConnection
deregisterPersistentSearch, finalizeConnectionInternal, finishSaslBind, getAuthenticationInfo, getCertificateAlias, getClientHostPort, getConnectTime, getConnectTimeString, getGroups, getIdleTimeLimit, getKeyManagerProviderDN, getLookthroughLimit, getPersistentSearches, getSASLAuthStateInfo, getServerHostPort, getSizeLimit, getTimeLimit, getTransaction, getTrustManagerProviderDN, hasAllPrivileges, hasPersistentSearch, hasPrivilege, hasPrivilege, isInnerConnection, isMemberOf, mustChangePassword, registerPersistentSearch, sendIntermediateResponse, setAuthenticationInfo, setIdleTimeLimit, setLookthroughLimit, setMustChangePassword, setSASLAuthStateInfo, setSizeLimit, setTimeLimit, setUnauthenticated, startTransaction, toString, updateAuthenticationInfo, updatePrivileges
-
-
-
-
Method Detail
-
getConnectionID
public long getConnectionID()
Retrieves the connection ID assigned to this connection.- Specified by:
getConnectionIDin classClientConnection- Returns:
- The connection ID assigned to this connection.
-
getConnectionHandler
public ConnectionHandler<?> getConnectionHandler()
Retrieves the connection handler that accepted this client connection.- Specified by:
getConnectionHandlerin classClientConnection- Returns:
- The connection handler that accepted this client connection.
-
getSocketChannel
public SocketChannel getSocketChannel()
Retrieves the socket channel that can be used to communicate with the client.- Overrides:
getSocketChannelin classClientConnection- Returns:
- The socket channel that can be used to communicate with the client.
-
getProtocol
public String getProtocol()
Retrieves the protocol that the client is using to communicate with the Directory Server.- Specified by:
getProtocolin classClientConnection- Returns:
- The protocol that the client is using to communicate with the Directory Server.
-
getClientAddress
public String getClientAddress()
Retrieves a string representation of the address of the client.- Specified by:
getClientAddressin classClientConnection- Returns:
- A string representation of the address of the client.
-
getClientPort
public int getClientPort()
Retrieves the port number for this connection on the client system.- Specified by:
getClientPortin classClientConnection- Returns:
- The port number for this connection on the client system.
-
getServerAddress
public String getServerAddress()
Retrieves a string representation of the address on the server to which the client connected.- Specified by:
getServerAddressin classClientConnection- Returns:
- A string representation of the address on the server to which the client connected.
-
getServerPort
public int getServerPort()
Retrieves the port number for this connection on the server system.- Specified by:
getServerPortin classClientConnection- Returns:
- The port number for this connection on the server system.
-
getRemoteAddress
public InetAddress getRemoteAddress()
Retrieves thejava.net.InetAddressassociated with the remote client system.- Specified by:
getRemoteAddressin classClientConnection- Returns:
- The
java.net.InetAddressassociated with the remote client system. It may benullif the client is not connected over an IP-based connection.
-
getLocalAddress
public InetAddress getLocalAddress()
Retrieves thejava.net.InetAddressfor the Directory Server system to which the client has established the connection.- Specified by:
getLocalAddressin classClientConnection- Returns:
- The
java.net.InetAddressfor the Directory Server system to which the client has established the connection. It may benullif the client is not connected over an IP-based connection.
-
isConnectionValid
public boolean isConnectionValid()
Description copied from class:ClientConnectionReturns whether the Directory Server believes this connection to be valid and available for communication.- Specified by:
isConnectionValidin classClientConnection- Returns:
- true if the connection is valid, false otherwise
-
isSecure
public boolean isSecure()
Indicates whether this client connection is currently using a secure mechanism to communicate with the server. Note that this may change over time based on operations performed by the client or server (e.g., it may go fromfalsetotrueif the client uses the StartTLS extended operation).- Specified by:
isSecurein classClientConnection- Returns:
trueif the client connection is currently using a secure mechanism to communicate with the server, orfalseif not.
-
sendResponse
public void sendResponse(Operation operation)
Sends a response to the client based on the information in the provided operation.- Specified by:
sendResponsein classClientConnection- Parameters:
operation- The operation for which to send the response.
-
sendSearchEntry
public void sendSearchEntry(SearchOperation searchOperation, SearchResultEntry searchEntry)
Sends the provided search result entry to the client.- Specified by:
sendSearchEntryin classClientConnection- Parameters:
searchOperation- The search operation with which the entry is associated.searchEntry- The search result entry to be sent to the client.
-
sendSearchReference
public boolean sendSearchReference(SearchOperation searchOperation, SearchResultReference searchReference)
Sends the provided search result reference to the client.- Specified by:
sendSearchReferencein classClientConnection- Parameters:
searchOperation- The search operation with which the reference is associated.searchReference- The search result reference to be sent to the client.- Returns:
trueif the client is able to accept referrals, orfalseif the client cannot handle referrals and no more attempts should be made to send them for the associated search operation.
-
sendIntermediateResponseMessage
protected boolean sendIntermediateResponseMessage(IntermediateResponse intermediateResponse)
Sends the provided intermediate response message to the client.- Specified by:
sendIntermediateResponseMessagein classClientConnection- Parameters:
intermediateResponse- The intermediate response message to be sent.- Returns:
trueif processing on the associated operation should continue, orfalseif not.
-
disconnect
public void disconnect(DisconnectReason disconnectReason, boolean sendNotification, org.forgerock.i18n.LocalizableMessage message)
Closes the connection to the client, optionally sending it a message indicating the reason for the closure. Note that the ability to send a notice of disconnection may not be available for all protocols or under all circumstances.- Specified by:
disconnectin classClientConnection- Parameters:
disconnectReason- The disconnect reason that provides the generic cause for the disconnect.sendNotification- Indicates whether to try to provide notification to the client that the connection will be closed.message- The message to include in the disconnect notification response. It may benullif no message is to be sent.
-
getOperationsInProgress
public Collection<Operation> getOperationsInProgress()
Retrieves the set of operations in progress for this client connection. This list must not be altered by any caller.- Specified by:
getOperationsInProgressin classClientConnection- Returns:
- The set of operations in progress for this client connection.
-
getOperationInProgress
public Operation getOperationInProgress(int messageID)
Retrieves the operation in progress with the specified message ID.- Specified by:
getOperationInProgressin classClientConnection- Parameters:
messageID- The message ID for the operation to retrieve.- Returns:
- The operation in progress with the specified message ID, or
nullif no such operation could be found.
-
removeOperationInProgress
public boolean removeOperationInProgress(int messageID)
Removes the provided operation from the set of operations in progress for this client connection. Note that this does not make any attempt to cancel any processing that may already be in progress for the operation.- Specified by:
removeOperationInProgressin classClientConnection- Parameters:
messageID- The message ID of the operation to remove from the set of operations in progress.- Returns:
trueif the operation was found and removed from the set of operations in progress, orfalseif not.
-
cancelOperation
public CancelResult cancelOperation(int messageID, CancelRequest cancelRequest)
Attempts to cancel the specified operation.- Specified by:
cancelOperationin classClientConnection- Parameters:
messageID- The message ID of the operation to cancel.cancelRequest- An object providing additional information about how the cancel should be processed.- Returns:
- A cancel result that either indicates that the cancel was successful or provides a reason that it was not.
-
cancelAllOperations
public void cancelAllOperations(CancelRequest cancelRequest)
Attempts to cancel all operations in progress on this connection.- Specified by:
cancelAllOperationsin classClientConnection- Parameters:
cancelRequest- An object providing additional information about how the cancel should be processed.
-
cancelAllOperationsExcept
public void cancelAllOperationsExcept(CancelRequest cancelRequest, int messageID)
Attempts to cancel all operations in progress on this connection except the operation with the specified message ID.- Specified by:
cancelAllOperationsExceptin classClientConnection- Parameters:
cancelRequest- An object providing additional information about how the cancel should be processed.messageID- The message ID of the operation that should not be canceled.
-
getWriteSelector
public Selector getWriteSelector()
Description copied from class:ClientConnectionRetrieves aSelectorthat may be used to ensure that write operations complete in a timely manner, or terminate the connection in the event that they fail to do so. This is an optional method for client connections, and the default implementation returnsnullto indicate that the maximum blocked write time limit is not supported for this connection. Subclasses that do wish to support this functionality should return a validSelectorobject.- Overrides:
getWriteSelectorin classClientConnection- Returns:
- The
Selectorthat may be used to ensure that write operations complete in a timely manner, ornullif this client connection does not support maximum blocked write time limit functionality.
-
getMaxBlockedWriteTimeLimit
public long getMaxBlockedWriteTimeLimit()
Description copied from class:ClientConnectionRetrieves the maximum length of time in milliseconds that attempts to write data to the client should be allowed to block. A value of zero indicates there should be no limit.- Overrides:
getMaxBlockedWriteTimeLimitin classClientConnection- Returns:
- The maximum length of time in milliseconds that attempts to write data to the client should be allowed to block, or zero if there should be no limit.
-
getNumberOfOperations
public long getNumberOfOperations()
Returns the total number of operations initiated on this connection.- Specified by:
getNumberOfOperationsin classClientConnection- Returns:
- the total number of operations on this connection
-
getMonitorSummary
public String getMonitorSummary()
Description copied from class:ClientConnectionRetrieves a one-line summary of this client connection in a form that is suitable for including in the monitor entry for the associated connection handler. It should be in a format that is both humand readable and machine parseable (e.g., a space-delimited name-value list, with quotes around the values).- Specified by:
getMonitorSummaryin classClientConnection- Returns:
- A one-line summary of this client connection in a form that is suitable for including in the monitor entry for the associated connection handler.
-
toString
public void toString(StringBuilder buffer)
Appends a string representation of this client connection to the provided buffer.- Specified by:
toStringin classClientConnection- Parameters:
buffer- The buffer to which the information should be appended.
-
prepareTLS
public boolean prepareTLS(org.forgerock.i18n.LocalizableMessageBuilder unavailableReason)
Description copied from interface:TLSCapableConnectionPrepares this connection for using TLS and returns whether TLS protection is actually available for the underlying client connection. If there is any reason that TLS protection cannot be enabled on this client connection, then it should be appended to the provided buffer.- Specified by:
prepareTLSin interfaceTLSCapableConnection- Parameters:
unavailableReason- The buffer used to hold the reason that TLS is not available on the underlying client connection.- Returns:
trueif TLS is available on the underlying client connection, orfalseif it is not.
-
getIdleTime
public long getIdleTime()
Retrieves the length of time in milliseconds that this client connection has been idle.
Note that the default implementation will always return zero. Subclasses associated with connection handlers should override this method if they wish to provided idle time limit functionality.- Overrides:
getIdleTimein classClientConnection- Returns:
- The length of time in milliseconds that this client connection has been idle.
-
setTLSPendingProvider
public void setTLSPendingProvider(ConnectionSecurityProvider provider)
Set the connection provider that is not in use yet. Used in TLS negotiation when a clear response is needed before the connection provider is active.- Parameters:
provider- The provider that needs to be activated.
-
setSASLPendingProvider
public void setSASLPendingProvider(ConnectionSecurityProvider provider)
Set the connection provider that is not in use. Used in SASL negotiation when a clear response is needed before the connection provider is active.- Parameters:
provider- The provider that needs to be activated.
-
getClientCertificateChain
public Certificate[] getClientCertificateChain()
Return the certificate chain array associated with a connection.- Returns:
- The array of certificates associated with a connection.
-
getChannel
public ByteChannel getChannel()
Retrieves the TLS redirecting byte channel used in a LDAP client connection.- Overrides:
getChannelin classClientConnection- Returns:
- The TLS redirecting byte channel.
-
getSSF
public int getSSF()
Description copied from class:ClientConnectionReturn the Security Strength Factor of a client connection.- Specified by:
getSSFin classClientConnection- Returns:
- An integer representing the SSF value of a connection.
-
finishBind
public void finishBind()
Description copied from class:ClientConnectionIndicates a bind or start TLS request processing is finished and the client connection may start processing data read from the socket again. This must be called after processing each bind request in a multistage SASL bind.- Overrides:
finishBindin classClientConnection
-
finishStartTLS
public void finishStartTLS()
Description copied from class:ClientConnectionIndicates a bind or start TLS request processing is finished and the client connection may start processing data read from the socket again. This must be called after processing each bind request in a multistage SASL bind.- Overrides:
finishStartTLSin classClientConnection
-
-