|
| 1 | +package io.scalecube.services.security; |
| 2 | + |
| 3 | +import io.scalecube.security.vault.VaultServiceRolesInstaller; |
| 4 | +import io.scalecube.security.vault.VaultServiceRolesInstaller.ServiceRoles; |
| 5 | +import io.scalecube.security.vault.VaultServiceRolesInstaller.ServiceRoles.Role; |
| 6 | +import io.scalecube.services.auth.ServiceRolesProcessor; |
| 7 | +import io.scalecube.services.methods.ServiceRoleDefinition; |
| 8 | +import java.util.ArrayList; |
| 9 | +import java.util.Collection; |
| 10 | +import java.util.List; |
| 11 | +import java.util.concurrent.CompletableFuture; |
| 12 | +import java.util.function.Function; |
| 13 | +import java.util.function.Supplier; |
| 14 | + |
| 15 | +public class VaultServiceRolesProcessor implements ServiceRolesProcessor { |
| 16 | + |
| 17 | + private final String vaultAddress; |
| 18 | + private final Supplier<CompletableFuture<String>> vaultTokenSupplier; |
| 19 | + private final Supplier<String> keyNameSupplier; |
| 20 | + private final Function<String, String> roleNameBuilder; |
| 21 | + |
| 22 | + /** |
| 23 | + * Constructor. |
| 24 | + * |
| 25 | + * @param vaultAddress vaultAddress |
| 26 | + * @param vaultTokenSupplier vaultTokenSupplier |
| 27 | + * @param keyNameSupplier keyNameSupplier |
| 28 | + * @param roleNameBuilder roleNameBuilder |
| 29 | + */ |
| 30 | + public VaultServiceRolesProcessor( |
| 31 | + String vaultAddress, |
| 32 | + Supplier<CompletableFuture<String>> vaultTokenSupplier, |
| 33 | + Supplier<String> keyNameSupplier, |
| 34 | + Function<String, String> roleNameBuilder) { |
| 35 | + this.vaultAddress = vaultAddress; |
| 36 | + this.vaultTokenSupplier = vaultTokenSupplier; |
| 37 | + this.keyNameSupplier = keyNameSupplier; |
| 38 | + this.roleNameBuilder = roleNameBuilder; |
| 39 | + } |
| 40 | + |
| 41 | + @Override |
| 42 | + public void process(Collection<ServiceRoleDefinition> values) { |
| 43 | + new VaultServiceRolesInstaller.Builder() |
| 44 | + .vaultAddress(vaultAddress) |
| 45 | + .vaultTokenSupplier(vaultTokenSupplier) |
| 46 | + .serviceRolesSources(List.of(() -> toServiceRoles(values))) |
| 47 | + .keyNameSupplier(keyNameSupplier) |
| 48 | + .roleNameBuilder(roleNameBuilder) |
| 49 | + .build() |
| 50 | + .install(); |
| 51 | + } |
| 52 | + |
| 53 | + private static ServiceRoles toServiceRoles(Collection<ServiceRoleDefinition> values) { |
| 54 | + return new ServiceRoles() |
| 55 | + .roles( |
| 56 | + values.stream() |
| 57 | + .map( |
| 58 | + roleDefinition -> { |
| 59 | + final var role = new Role(); |
| 60 | + role.role(roleDefinition.role()); |
| 61 | + role.permissions(new ArrayList<>(roleDefinition.permissions())); |
| 62 | + return role; |
| 63 | + }) |
| 64 | + .toList()); |
| 65 | + } |
| 66 | +} |
0 commit comments