Skip to content

Commit 187ab6f

Browse files
committed
Merge branch 'master' into production
2 parents d792306 + daac5c7 commit 187ab6f

17 files changed

+332
-56
lines changed

package-lock.json

Lines changed: 21 additions & 21 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,13 +2,13 @@
22
"name": "perun",
33
"version": "0.0.0-development",
44
"devDependencies": {
5-
"@commitlint/cli": "17.7.1",
5+
"@commitlint/cli": "17.7.2",
66
"@commitlint/config-conventional": "17.7.0",
7-
"@commitlint/cz-commitlint": "17.7.1",
7+
"@commitlint/cz-commitlint": "17.7.2",
88
"@semantic-release/changelog": "6.0.3",
99
"@semantic-release/exec": "6.0.3",
1010
"@semantic-release/git": "10.0.1",
11-
"@semantic-release/github": "9.0.7",
11+
"@semantic-release/github": "9.2.1",
1212
"commitizen": "4.3.0",
1313
"conventional-changelog-conventionalcommits": "6.1.0",
1414
"inquirer": "8.2.6",

perun-base/src/main/resources/perun-roles.yml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6209,6 +6209,15 @@ perun_policies:
62096209
include_policies:
62106210
- default_policy
62116211

6212+
getAssociatedResources_Facility_User_policy:
6213+
policy_roles:
6214+
- FACILITYADMIN: Facility
6215+
- FACILITYOBSERVER: Facility
6216+
- SELF: User
6217+
- PERUNOBSERVER:
6218+
include_policies:
6219+
- default_policy
6220+
62126221
findUsers_String_policy:
62136222
policy_roles:
62146223
- PERUNOBSERVER:
@@ -7924,6 +7933,7 @@ perun_policies:
79247933
- PERUNOBSERVER:
79257934
- GROUPADMIN: Group
79267935
- GROUPOBSERVER: Group
7936+
- GROUPMEMBERSHIPMANAGER: Group
79277937
include_policies:
79287938
- default_policy
79297939

perun-core/src/main/java/cz/metacentrum/perun/core/api/UsersManager.java

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -716,6 +716,21 @@ UserExtSource getUserExtSourceByExtLogin(PerunSession perunSession, ExtSource so
716716
*/
717717
List<RichResource> getAssignedRichResources(PerunSession sess, User user) throws UserNotExistsException, PrivilegeException;
718718

719+
/**
720+
* Return all resources of specified facility with which user is associated through all his members.
721+
* Does not require ACTIVE group-resource assignment.
722+
*
723+
* @param sess
724+
* @param facility
725+
* @param user
726+
* @return All resources with which user is associated
727+
*
728+
* @throws UserNotExistsException
729+
* @throws FacilityNotExistsException
730+
* @throws PrivilegeException
731+
*/
732+
List<Resource> getAssociatedResources(PerunSession sess, Facility facility, User user) throws UserNotExistsException, FacilityNotExistsException, PrivilegeException;
733+
719734
/**
720735
* Returns list of users who matches the searchString, searching name, id, uuid, email, logins.
721736
*

perun-core/src/main/java/cz/metacentrum/perun/core/blImpl/AttributesManagerBlImpl.java

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -103,6 +103,7 @@
103103
import cz.metacentrum.perun.core.impl.Utils;
104104
import cz.metacentrum.perun.core.impl.modules.attributes.urn_perun_entityless_attribute_def_def_identityAlertsTemplates;
105105
import cz.metacentrum.perun.core.impl.modules.attributes.urn_perun_entityless_attribute_def_def_namespace_GIDRanges;
106+
import cz.metacentrum.perun.core.impl.modules.attributes.urn_perun_facility_attribute_def_def_unixGID_namespace;
106107
import cz.metacentrum.perun.core.impl.modules.attributes.urn_perun_facility_attribute_def_virt_GIDRanges;
107108
import cz.metacentrum.perun.core.impl.modules.attributes.urn_perun_group_attribute_def_def_applicationAutoRejectMessages;
108109
import cz.metacentrum.perun.core.impl.modules.attributes.urn_perun_group_attribute_def_def_groupStructureResources;
@@ -7904,6 +7905,18 @@ protected void initialize() {
79047905
policies.add(Triple.of(Role.PROXY, READ, RoleObject.None));
79057906
attributes.put(attr, createInitialPolicyCollections(policies));
79067907

7908+
//urn:perun:facility:attribute-def:def:unixGID-namespace
7909+
attr = new AttributeDefinition( (new urn_perun_facility_attribute_def_def_unixGID_namespace()).getAttributeDefinition());
7910+
//set attribute rights (with dummy id of attribute - not known yet)
7911+
policies = new ArrayList<>();
7912+
policies.add(Triple.of(Role.MEMBERSHIP, READ, RoleObject.Facility));
7913+
policies.add(Triple.of(Role.VOADMIN, READ, RoleObject.Vo));
7914+
policies.add(Triple.of(Role.GROUPADMIN, READ, RoleObject.Group));
7915+
policies.add(Triple.of(Role.FACILITYADMIN, READ, RoleObject.Facility));
7916+
policies.add(Triple.of(Role.FACILITYADMIN, WRITE, RoleObject.Facility));
7917+
policies.add(Triple.of(Role.PROXY, READ, RoleObject.None));
7918+
attributes.put(attr, createInitialPolicyCollections(policies));
7919+
79077920
//urn:perun:resource:attribute-def:def:userSettingsName
79087921
attr = new AttributeDefinition();
79097922
attr.setNamespace(AttributesManager.NS_RESOURCE_ATTR_DEF);

perun-core/src/main/java/cz/metacentrum/perun/core/entry/UsersManagerEntry.java

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -839,6 +839,20 @@ public List<RichResource> getAssignedRichResources(PerunSession sess, User user)
839839
return getUsersManagerBl().getAssignedRichResources(sess, user);
840840
}
841841

842+
@Override
843+
public List<Resource> getAssociatedResources(PerunSession sess, Facility facility, User user) throws UserNotExistsException, FacilityNotExistsException, PrivilegeException {
844+
Utils.checkPerunSession(sess);
845+
846+
if(!AuthzResolver.authorizedInternal(sess, "getAssociatedResources_Facility_User_policy", facility, user)) {
847+
throw new PrivilegeException(sess, "getAssociatedResources");
848+
}
849+
850+
getUsersManagerBl().checkUserExists(sess, user);
851+
perunBl.getFacilitiesManagerBl().checkFacilityExists(sess, facility);
852+
853+
return getUsersManagerBl().getAssociatedResources(sess, facility, user);
854+
}
855+
842856
@Override
843857
public List<User> findUsers(PerunSession sess, String searchString) throws PrivilegeException {
844858
Utils.checkPerunSession(sess);

perun-core/src/main/java/cz/metacentrum/perun/core/impl/modules/attributes/urn_perun_facility_attribute_def_def_unixGID_namespace.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ public AttributeDefinition getAttributeDefinition() {
4141
attr.setFriendlyName("unixGID-namespace");
4242
attr.setDisplayName("GID namespace");
4343
attr.setType(String.class.getName());
44-
attr.setDescription("Namespace of UnixGID.");
44+
attr.setDescription("Define namespace for unix groups GIDs on Facility.");
4545
return attr;
4646
}
4747
}

perun-core/src/main/java/cz/metacentrum/perun/core/impl/modules/attributes/urn_perun_user_attribute_def_def_mfaEnforceSettings.java

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -149,8 +149,9 @@ public void checkAttributeSemantics(PerunSessionImpl perunSession, User user, At
149149

150150
Attribute mfaCategory = null;
151151
try {
152-
Map<String, Attribute> mfaCategories = perunSession.getPerunBl().getAttributesManagerBl().getEntitylessAttributesWithKeys(perunSession, AttributesManager.NS_ENTITYLESS_ATTR_DEF + ":mfaCategories", Collections.singletonList("categories"));
153-
mfaCategory = mfaCategories.get("categories");
152+
String param = attribute.getFriendlyNameParameter();
153+
Map<String, Attribute> mfaCategories = perunSession.getPerunBl().getAttributesManagerBl().getEntitylessAttributesWithKeys(perunSession, AttributesManager.NS_ENTITYLESS_ATTR_DEF + ":mfaCategories", Collections.singletonList(param));
154+
mfaCategory = mfaCategories.get(param);
154155
} catch (AttributeNotExistsException e) {
155156
throw new WrongReferenceAttributeValueException("Attribute mfa categories does not exist.");
156157
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,63 @@
1+
package cz.metacentrum.perun.core.impl.modules.attributes;
2+
3+
import cz.metacentrum.perun.core.api.Attribute;
4+
import cz.metacentrum.perun.core.api.AttributeDefinition;
5+
import cz.metacentrum.perun.core.api.AttributesManager;
6+
import cz.metacentrum.perun.core.api.User;
7+
import cz.metacentrum.perun.core.api.exceptions.AttributeNotExistsException;
8+
import cz.metacentrum.perun.core.api.exceptions.WrongAttributeAssignmentException;
9+
import cz.metacentrum.perun.core.impl.PerunSessionImpl;
10+
import cz.metacentrum.perun.core.impl.Utils;
11+
import cz.metacentrum.perun.core.implApi.modules.attributes.SkipValueCheckDuringDependencyCheck;
12+
import cz.metacentrum.perun.core.implApi.modules.attributes.UserVirtualAttributesModuleAbstract;
13+
import org.slf4j.Logger;
14+
import org.slf4j.LoggerFactory;
15+
16+
import java.util.ArrayList;
17+
import java.util.List;
18+
19+
/**
20+
* Contains login in the MU namespace concatenated with @muni.cz if it is available, null otherwise
21+
*/
22+
@SkipValueCheckDuringDependencyCheck
23+
public class urn_perun_user_attribute_def_virt_scopedLogin_namespace_mu extends UserVirtualAttributesModuleAbstract {
24+
private final static Logger log = LoggerFactory.getLogger(urn_perun_user_attribute_def_virt_scopedLogin_namespace_mu.class);
25+
26+
private static final String A_U_D_loginNamespace_mu = AttributesManager.NS_USER_ATTR_DEF + ":login-namespace:mu";
27+
28+
@Override
29+
public Attribute getAttributeValue(PerunSessionImpl perunSession, User user, AttributeDefinition attribute) {
30+
Attribute attr = new Attribute(attribute);
31+
try {
32+
Attribute defLogin = perunSession.getPerunBl().getAttributesManagerBl().getAttribute(perunSession, user, A_U_D_loginNamespace_mu);
33+
Utils.copyAttributeToVirtualAttributeWithValue(defLogin, attr);
34+
} catch (AttributeNotExistsException e) {
35+
// We log the non-existing attribute, but we don't throw an exception.
36+
log.warn("Attribute {} does not exist.", A_U_D_loginNamespace_mu);
37+
} catch (WrongAttributeAssignmentException e) {
38+
// It's OK, we just return attribute with value null
39+
}
40+
if (attr.getValue() != null) {
41+
attr.setValue(attr.getValue() + "@muni.cz");
42+
}
43+
return attr;
44+
}
45+
46+
@Override
47+
public List<String> getStrongDependencies() {
48+
List<String> strongDependencies = new ArrayList<>();
49+
strongDependencies.add(A_U_D_loginNamespace_mu);
50+
return strongDependencies;
51+
}
52+
53+
@Override
54+
public AttributeDefinition getAttributeDefinition() {
55+
AttributeDefinition attr = new AttributeDefinition();
56+
attr.setNamespace(AttributesManager.NS_USER_ATTR_VIRT);
57+
attr.setFriendlyName("scopedLogin-namespace:mu");
58+
attr.setDisplayName("Login + @muni.cz in namespace: mu");
59+
attr.setType(String.class.getName());
60+
attr.setDescription("Contains an optional login (UCO) concatenated with domain (@muni.cz) in namespace mu if the user has it.");
61+
return attr;
62+
}
63+
}

perun-core/src/main/java/cz/metacentrum/perun/core/impl/modules/attributes/urn_perun_user_attribute_def_virt_voPersonExternalAffiliation.java

Lines changed: 12 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,7 @@
4747
import java.util.Map;
4848
import java.util.Set;
4949
import java.util.regex.Pattern;
50+
import java.util.stream.Collectors;
5051

5152
/**
5253
* All affiliations collected from:
@@ -125,8 +126,18 @@ public Attribute getAttributeValue(PerunSessionImpl sess, User user, AttributeDe
125126
valuesWithoutDuplicities.addAll(getAffiliationsManuallyAssigned(sess, user));
126127
valuesWithoutDuplicities.addAll(getAffiliationsFromGroups(sess, user));
127128

129+
// remove duplicities, by accepting only the first occurrence of each value (other occurences, case-insensitive, will be removed)
130+
Set<String> valuesWithoutDuplicitiesCaseInsensitive = new HashSet<>();
131+
for (String value: valuesWithoutDuplicities) {
132+
boolean isDuplicity = valuesWithoutDuplicitiesCaseInsensitive.stream().anyMatch(value::equalsIgnoreCase);
133+
if (isDuplicity) {
134+
continue;
135+
}
136+
valuesWithoutDuplicitiesCaseInsensitive.add(value);
137+
}
138+
128139
//convert set to list (values in list will be without duplicities)
129-
destinationAttribute.setValue(new ArrayList<>(valuesWithoutDuplicities));
140+
destinationAttribute.setValue(new ArrayList<>(valuesWithoutDuplicitiesCaseInsensitive));
130141
return destinationAttribute;
131142
}
132143

0 commit comments

Comments
 (0)