|  1 |     | 
     | 
  |  2 |     | 
     | 
  |  3 |     | 
     | 
  |  4 |     | 
     | 
  |  5 |     | 
     | 
  |  6 |     | 
     | 
  |  7 |     | 
     | 
  |  8 |     | 
     | 
  |  9 |     | 
     | 
  |  10 |     | 
     | 
  |  11 |     | 
     | 
  |  12 |     | 
     | 
  |  13 |     | 
     | 
  |  14 |     | 
     | 
  |  15 |     | 
     | 
  |  16 |     | 
   package org.kuali.rice.kim.service.impl;  | 
  |  17 |     | 
     | 
  |  18 |     | 
   import java.util.ArrayList;  | 
  |  19 |     | 
   import java.util.Collection;  | 
  |  20 |     | 
   import java.util.Collections;  | 
  |  21 |     | 
   import java.util.Comparator;  | 
  |  22 |     | 
   import java.util.HashMap;  | 
  |  23 |     | 
   import java.util.List;  | 
  |  24 |     | 
   import java.util.Map;  | 
  |  25 |     | 
     | 
  |  26 |     | 
   import javax.jws.WebService;  | 
  |  27 |     | 
     | 
  |  28 |     | 
   import org.apache.commons.lang.StringUtils;  | 
  |  29 |     | 
   import org.apache.log4j.Logger;  | 
  |  30 |     | 
   import org.kuali.rice.core.xml.dto.AttributeSet;  | 
  |  31 |     | 
   import org.kuali.rice.kim.bo.Role;  | 
  |  32 |     | 
   import org.kuali.rice.kim.bo.impl.PermissionImpl;  | 
  |  33 |     | 
   import org.kuali.rice.kim.bo.role.dto.KimPermissionInfo;  | 
  |  34 |     | 
   import org.kuali.rice.kim.bo.role.dto.KimPermissionTemplateInfo;  | 
  |  35 |     | 
   import org.kuali.rice.kim.bo.role.dto.PermissionAssigneeInfo;  | 
  |  36 |     | 
   import org.kuali.rice.kim.bo.role.dto.RoleMembershipInfo;  | 
  |  37 |     | 
   import org.kuali.rice.kim.bo.role.impl.KimPermissionImpl;  | 
  |  38 |     | 
   import org.kuali.rice.kim.bo.role.impl.KimPermissionTemplateImpl;  | 
  |  39 |     | 
   import org.kuali.rice.kim.bo.types.dto.AttributeDefinitionMap;  | 
  |  40 |     | 
   import org.kuali.rice.kim.bo.types.dto.KimTypeInfo;  | 
  |  41 |     | 
   import org.kuali.rice.kim.dao.KimPermissionDao;  | 
  |  42 |     | 
   import org.kuali.rice.kim.service.KIMServiceLocator;  | 
  |  43 |     | 
   import org.kuali.rice.kim.service.KIMServiceLocatorInternal;  | 
  |  44 |     | 
   import org.kuali.rice.kim.service.KIMServiceLocatorWeb;  | 
  |  45 |     | 
   import org.kuali.rice.kim.service.PermissionService;  | 
  |  46 |     | 
   import org.kuali.rice.kim.service.RoleService;  | 
  |  47 |     | 
   import org.kuali.rice.kim.service.support.KimPermissionTypeService;  | 
  |  48 |     | 
   import org.kuali.rice.kim.util.KIMWebServiceConstants;  | 
  |  49 |     | 
   import org.kuali.rice.kim.util.KimConstants;  | 
  |  50 |     | 
   import org.kuali.rice.kns.datadictionary.AttributeDefinition;  | 
  |  51 |     | 
   import org.kuali.rice.kns.lookup.CollectionIncomplete;  | 
  |  52 |     | 
   import org.kuali.rice.kns.lookup.Lookupable;  | 
  |  53 |     | 
   import org.kuali.rice.kns.service.DataDictionaryService;  | 
  |  54 |     | 
   import org.kuali.rice.kns.service.KNSServiceLocatorWeb;  | 
  |  55 |     | 
   import org.kuali.rice.kns.util.KNSPropertyConstants;  | 
  |  56 |     | 
     | 
  |  57 |     | 
     | 
  |  58 |     | 
     | 
  |  59 |     | 
     | 
  |  60 |     | 
     | 
  |  61 |     | 
     | 
  |  62 |     | 
     | 
  |  63 |     | 
   @WebService(endpointInterface = KIMWebServiceConstants.PermissionService.INTERFACE_CLASS, serviceName = KIMWebServiceConstants.PermissionService.WEB_SERVICE_NAME, portName = KIMWebServiceConstants.PermissionService.WEB_SERVICE_PORT, targetNamespace = KIMWebServiceConstants.MODULE_TARGET_NAMESPACE)  | 
  |  64 |    0 |    public class PermissionServiceImpl extends PermissionServiceBase implements PermissionService { | 
  |  65 |    0 |            private static final Logger LOG = Logger.getLogger( PermissionServiceImpl.class );  | 
  |  66 |     | 
     | 
  |  67 |     | 
           private RoleService roleService;  | 
  |  68 |     | 
           private KimPermissionDao permissionDao;  | 
  |  69 |     | 
       private KimPermissionTypeService defaultPermissionTypeService;  | 
  |  70 |     | 
             | 
  |  71 |     | 
           private List<KimPermissionTemplateInfo> allTemplates;  | 
  |  72 |     | 
             | 
  |  73 |     | 
         | 
  |  74 |     | 
         | 
  |  75 |     | 
         | 
  |  76 |     | 
         | 
  |  77 |     | 
           protected KimPermissionTypeService getPermissionTypeService( String namespaceCode, String permissionTemplateName, String permissionName, String permissionId ) { | 
  |  78 |    0 |                    StringBuffer cacheKey = new StringBuffer();  | 
  |  79 |    0 |                    if ( namespaceCode != null ) { | 
  |  80 |    0 |                            cacheKey.append( namespaceCode );  | 
  |  81 |     | 
                   }  | 
  |  82 |    0 |                    cacheKey.append( '|' );  | 
  |  83 |    0 |                    if ( permissionTemplateName != null ) { | 
  |  84 |    0 |                            cacheKey.append( permissionTemplateName );  | 
  |  85 |     | 
                   }  | 
  |  86 |    0 |                    cacheKey.append( '|' );  | 
  |  87 |    0 |                    if ( permissionName != null ) { | 
  |  88 |    0 |                            cacheKey.append( permissionName );  | 
  |  89 |     | 
                   }  | 
  |  90 |    0 |                    cacheKey.append( '|' );  | 
  |  91 |    0 |                    if ( permissionId != null ) { | 
  |  92 |    0 |                            cacheKey.append( permissionId );  | 
  |  93 |     | 
                   }  | 
  |  94 |    0 |                    String key = cacheKey.toString();  | 
  |  95 |    0 |                    KimPermissionTypeService service = getPermissionTypeServiceByNameCache().get(key);  | 
  |  96 |    0 |                    if ( service == null ) { | 
  |  97 |    0 |                            KimPermissionTemplateImpl permTemplate = null;  | 
  |  98 |    0 |                            if ( permissionTemplateName != null ) { | 
  |  99 |    0 |                                    List<KimPermissionImpl> perms = getPermissionImplsByTemplateName(namespaceCode, permissionTemplateName);  | 
  |  100 |    0 |                                    if ( !perms.isEmpty() ) { | 
  |  101 |    0 |                                            permTemplate = perms.get(0).getTemplate();  | 
  |  102 |     | 
                                   }  | 
  |  103 |    0 |                            } else if ( permissionName != null ) { | 
  |  104 |    0 |                                    List<KimPermissionImpl> perms = getPermissionImplsByName(namespaceCode, permissionName);   | 
  |  105 |    0 |                                    if ( !perms.isEmpty() ) { | 
  |  106 |    0 |                                            permTemplate = perms.get(0).getTemplate();  | 
  |  107 |     | 
                                   }  | 
  |  108 |    0 |                            } else if ( permissionId != null ) { | 
  |  109 |    0 |                                    KimPermissionImpl perm = getPermissionImpl(permissionId);  | 
  |  110 |    0 |                                    if ( perm != null ) { | 
  |  111 |    0 |                                            permTemplate = perm.getTemplate();  | 
  |  112 |     | 
                                   }  | 
  |  113 |     | 
                           }  | 
  |  114 |    0 |                            service = getPermissionTypeService( permTemplate );  | 
  |  115 |    0 |                            getPermissionTypeServiceByNameCache().put(key, service);  | 
  |  116 |     | 
                   }  | 
  |  117 |    0 |                    return service;  | 
  |  118 |     | 
           }  | 
  |  119 |     | 
     | 
  |  120 |     | 
       protected KimPermissionTypeService getPermissionTypeService( KimPermissionTemplateImpl permissionTemplate ) { | 
  |  121 |    0 |                if ( permissionTemplate == null ) { | 
  |  122 |    0 |                        throw new IllegalArgumentException( "permissionTemplate may not be null" );  | 
  |  123 |     | 
               }  | 
  |  124 |    0 |                KimTypeInfo kimType = KIMServiceLocatorWeb.getTypeInfoService().getKimType( permissionTemplate.getKimTypeId() );  | 
  |  125 |    0 |                String serviceName = kimType.getKimTypeServiceName();  | 
  |  126 |     | 
                 | 
  |  127 |    0 |                if ( StringUtils.isBlank( serviceName ) ) { | 
  |  128 |    0 |                        return getDefaultPermissionTypeService();  | 
  |  129 |     | 
               }  | 
  |  130 |     | 
               try { | 
  |  131 |    0 |                        Object service = KIMServiceLocatorInternal.getService(serviceName);  | 
  |  132 |     | 
                         | 
  |  133 |    0 |                        if ( service == null ) { | 
  |  134 |    0 |                                    throw new RuntimeException("null returned for permission type service for service name: " + serviceName); | 
  |  135 |     | 
                       }  | 
  |  136 |     | 
                         | 
  |  137 |    0 |                        if ( !(service instanceof KimPermissionTypeService)  ) { | 
  |  138 |    0 |                                throw new RuntimeException( "Service " + serviceName + " was not a KimPermissionTypeService.  Was: " + service.getClass().getName() );  | 
  |  139 |     | 
                       }  | 
  |  140 |    0 |                        return (KimPermissionTypeService)service;  | 
  |  141 |    0 |                } catch( Exception ex ) { | 
  |  142 |     | 
                         | 
  |  143 |    0 |                        throw new RuntimeException( "Error retrieving service: " + serviceName + " from the KIMServiceLocatorInternal.", ex );  | 
  |  144 |     | 
               }  | 
  |  145 |     | 
       }  | 
  |  146 |     | 
         | 
  |  147 |     | 
       protected KimPermissionTypeService getDefaultPermissionTypeService() { | 
  |  148 |    0 |                if ( defaultPermissionTypeService == null ) { | 
  |  149 |    0 |                        defaultPermissionTypeService = (KimPermissionTypeService) KIMServiceLocatorInternal.getBean(DEFAULT_PERMISSION_TYPE_SERVICE);  | 
  |  150 |     | 
               }  | 
  |  151 |    0 |                    return defaultPermissionTypeService;  | 
  |  152 |     | 
           }  | 
  |  153 |     | 
             | 
  |  154 |     | 
         | 
  |  155 |     | 
     | 
  |  156 |     | 
     | 
  |  157 |     | 
       public boolean hasPermission(String principalId, String namespaceCode, String permissionName, AttributeSet permissionDetails) { | 
  |  158 |    0 |                return isAuthorized( principalId, namespaceCode, permissionName, permissionDetails, null );  | 
  |  159 |     | 
       }  | 
  |  160 |     | 
     | 
  |  161 |     | 
         | 
  |  162 |     | 
     | 
  |  163 |     | 
     | 
  |  164 |     | 
       public boolean isAuthorized(String principalId, String namespaceCode, String permissionName, AttributeSet permissionDetails, AttributeSet qualification ) { | 
  |  165 |    0 |                List<String> roleIds = getRoleIdsForPermission( namespaceCode, permissionName, permissionDetails );  | 
  |  166 |    0 |                if ( roleIds.isEmpty() ) { | 
  |  167 |    0 |                        return false;  | 
  |  168 |     | 
               }  | 
  |  169 |    0 |                    return getRoleService().principalHasRole( principalId, roleIds, qualification );  | 
  |  170 |     | 
       }  | 
  |  171 |     | 
     | 
  |  172 |     | 
         | 
  |  173 |     | 
     | 
  |  174 |     | 
     | 
  |  175 |     | 
       public boolean hasPermissionByTemplateName(String principalId, String namespaceCode, String permissionTemplateName, AttributeSet permissionDetails) { | 
  |  176 |    0 |                return isAuthorizedByTemplateName( principalId, namespaceCode, permissionTemplateName, permissionDetails, null );  | 
  |  177 |     | 
       }  | 
  |  178 |     | 
     | 
  |  179 |     | 
         | 
  |  180 |     | 
     | 
  |  181 |     | 
     | 
  |  182 |     | 
       public boolean isAuthorizedByTemplateName(String principalId, String namespaceCode, String permissionTemplateName, AttributeSet permissionDetails, AttributeSet qualification ) { | 
  |  183 |    0 |                List<String> roleIds = getRoleIdsForPermissionTemplate( namespaceCode, permissionTemplateName, permissionDetails );  | 
  |  184 |    0 |                if ( roleIds.isEmpty() ) { | 
  |  185 |    0 |                        return false;  | 
  |  186 |     | 
               }  | 
  |  187 |    0 |                return getRoleService().principalHasRole( principalId, roleIds, qualification );  | 
  |  188 |     | 
       }  | 
  |  189 |     | 
     | 
  |  190 |     | 
         | 
  |  191 |     | 
     | 
  |  192 |     | 
     | 
  |  193 |     | 
       public List<KimPermissionInfo> getAuthorizedPermissions( String principalId, String namespaceCode, String permissionName, AttributeSet permissionDetails, AttributeSet qualification ) { | 
  |  194 |     | 
                 | 
  |  195 |    0 |                List<KimPermissionImpl> permissions = getPermissionImplsByName( namespaceCode, permissionName );  | 
  |  196 |     | 
                 | 
  |  197 |    0 |                List<KimPermissionInfo> applicablePermissions = getMatchingPermissions( permissions, permissionDetails );    | 
  |  198 |    0 |                return getPermissionsForUser(principalId, applicablePermissions, qualification);  | 
  |  199 |     | 
       }  | 
  |  200 |     | 
     | 
  |  201 |     | 
         | 
  |  202 |     | 
     | 
  |  203 |     | 
     | 
  |  204 |     | 
       public List<KimPermissionInfo> getAuthorizedPermissionsByTemplateName( String principalId, String namespaceCode, String permissionTemplateName, AttributeSet permissionDetails, AttributeSet qualification ) { | 
  |  205 |     | 
                 | 
  |  206 |    0 |                List<KimPermissionImpl> permissions = getPermissionImplsByTemplateName( namespaceCode, permissionTemplateName );  | 
  |  207 |     | 
                 | 
  |  208 |    0 |                List<KimPermissionInfo> applicablePermissions = getMatchingPermissions( permissions, permissionDetails );    | 
  |  209 |    0 |                return getPermissionsForUser(principalId, applicablePermissions, qualification);  | 
  |  210 |     | 
       }  | 
  |  211 |     | 
         | 
  |  212 |     | 
         | 
  |  213 |     | 
     | 
  |  214 |     | 
     | 
  |  215 |     | 
       protected List<KimPermissionInfo> getPermissionsForUser( String principalId, List<KimPermissionInfo> permissions, AttributeSet qualification ) { | 
  |  216 |    0 |                ArrayList<KimPermissionInfo> results = new ArrayList<KimPermissionInfo>();  | 
  |  217 |    0 |                List<KimPermissionInfo> tempList = new ArrayList<KimPermissionInfo>(1);  | 
  |  218 |    0 |                for ( KimPermissionInfo perm : permissions ) { | 
  |  219 |    0 |                        tempList.clear();  | 
  |  220 |    0 |                        tempList.add( perm );  | 
  |  221 |    0 |                        List<String> roleIds = permissionDao.getRoleIdsForPermissions( tempList );  | 
  |  222 |     | 
                         | 
  |  223 |     | 
                         | 
  |  224 |     | 
                         | 
  |  225 |    0 |                        if ( roleIds != null && !roleIds.isEmpty() ) { | 
  |  226 |    0 |                                if ( getRoleService().principalHasRole( principalId, roleIds, qualification ) ) { | 
  |  227 |    0 |                                        results.add( perm );  | 
  |  228 |     | 
                               }  | 
  |  229 |     | 
                       }  | 
  |  230 |    0 |                }  | 
  |  231 |     | 
                 | 
  |  232 |    0 |                return results;              | 
  |  233 |     | 
       }  | 
  |  234 |     | 
     | 
  |  235 |     | 
       protected Map<String,KimPermissionTypeService> getPermissionTypeServicesByTemplateId( Collection<KimPermissionImpl> permissions ) { | 
  |  236 |    0 |                Map<String,KimPermissionTypeService> permissionTypeServices = new HashMap<String, KimPermissionTypeService>( permissions.size() );  | 
  |  237 |    0 |                for ( KimPermissionImpl perm : permissions ) { | 
  |  238 |    0 |                        permissionTypeServices.put(perm.getTemplateId(), getPermissionTypeService( perm.getTemplate() ) );                                      | 
  |  239 |     | 
               }  | 
  |  240 |    0 |                return permissionTypeServices;  | 
  |  241 |     | 
       }  | 
  |  242 |     | 
         | 
  |  243 |     | 
       protected Map<String,List<KimPermissionInfo>> groupPermissionsByTemplate( Collection<KimPermissionImpl> permissions ) { | 
  |  244 |    0 |                Map<String,List<KimPermissionInfo>> results = new HashMap<String,List<KimPermissionInfo>>();  | 
  |  245 |    0 |                for ( KimPermissionImpl perm : permissions ) { | 
  |  246 |    0 |                        List<KimPermissionInfo> perms = results.get( perm.getTemplateId() );  | 
  |  247 |    0 |                        if ( perms == null ) { | 
  |  248 |    0 |                                perms = new ArrayList<KimPermissionInfo>();  | 
  |  249 |    0 |                                results.put( perm.getTemplateId(), perms );  | 
  |  250 |     | 
                       }  | 
  |  251 |    0 |                        perms.add( perm.toSimpleInfo() );  | 
  |  252 |    0 |                }  | 
  |  253 |    0 |                return results;  | 
  |  254 |     | 
       }  | 
  |  255 |     | 
         | 
  |  256 |     | 
             | 
  |  257 |     | 
     | 
  |  258 |     | 
     | 
  |  259 |     | 
     | 
  |  260 |     | 
       protected List<KimPermissionInfo> getMatchingPermissions( List<KimPermissionImpl> permissions, AttributeSet permissionDetails ) { | 
  |  261 |    0 |                List<KimPermissionInfo> applicablePermissions = new ArrayList<KimPermissionInfo>();              | 
  |  262 |    0 |                if ( permissionDetails == null || permissionDetails.isEmpty() ) { | 
  |  263 |     | 
                         | 
  |  264 |    0 |                        for ( KimPermissionImpl perm : permissions ) { | 
  |  265 |    0 |                                applicablePermissions.add( perm.toSimpleInfo() );  | 
  |  266 |     | 
                       }  | 
  |  267 |     | 
               } else { | 
  |  268 |     | 
                         | 
  |  269 |     | 
                         | 
  |  270 |    0 |                        Map<String,KimPermissionTypeService> permissionTypeServices = getPermissionTypeServicesByTemplateId( permissions );  | 
  |  271 |     | 
                         | 
  |  272 |    0 |                        Map<String,List<KimPermissionInfo>> permissionMap = groupPermissionsByTemplate( permissions );  | 
  |  273 |     | 
                         | 
  |  274 |     | 
                         | 
  |  275 |    0 |                        for ( String templateId : permissionMap.keySet() ) { | 
  |  276 |    0 |                                KimPermissionTypeService permissionTypeService = permissionTypeServices.get( templateId );  | 
  |  277 |    0 |                                List<KimPermissionInfo> permissionList = permissionMap.get( templateId );  | 
  |  278 |    0 |                                    applicablePermissions.addAll( permissionTypeService.getMatchingPermissions( permissionDetails, permissionList ) );                                      | 
  |  279 |    0 |                        }  | 
  |  280 |     | 
               }  | 
  |  281 |    0 |                return applicablePermissions;  | 
  |  282 |     | 
       }  | 
  |  283 |     | 
     | 
  |  284 |     | 
         | 
  |  285 |     | 
     | 
  |  286 |     | 
     | 
  |  287 |     | 
       public List<PermissionAssigneeInfo> getPermissionAssignees( String namespaceCode, String permissionName, AttributeSet permissionDetails, AttributeSet qualification ) { | 
  |  288 |    0 |                List<PermissionAssigneeInfo> results = new ArrayList<PermissionAssigneeInfo>();  | 
  |  289 |    0 |                List<String> roleIds = getRoleIdsForPermission( namespaceCode, permissionName, permissionDetails);  | 
  |  290 |    0 |                if ( roleIds.isEmpty() ) { | 
  |  291 |    0 |                        return results;  | 
  |  292 |     | 
               }  | 
  |  293 |    0 |                Collection<RoleMembershipInfo> roleMembers = getRoleService().getRoleMembers( roleIds, qualification );  | 
  |  294 |    0 |                for ( RoleMembershipInfo rm : roleMembers ) { | 
  |  295 |    0 |                        if ( rm.getMemberTypeCode().equals( Role.PRINCIPAL_MEMBER_TYPE ) ) { | 
  |  296 |    0 |                                results.add( new PermissionAssigneeInfo( rm.getMemberId(), null, rm.getDelegates() ) );  | 
  |  297 |    0 |                        } else if ( rm.getMemberTypeCode().equals( Role.GROUP_MEMBER_TYPE ) ) { | 
  |  298 |    0 |                                results.add( new PermissionAssigneeInfo( null, rm.getMemberId(), rm.getDelegates() ) );  | 
  |  299 |     | 
                       }  | 
  |  300 |     | 
               }  | 
  |  301 |    0 |                return results;  | 
  |  302 |     | 
       }  | 
  |  303 |     | 
         | 
  |  304 |     | 
       public List<PermissionAssigneeInfo> getPermissionAssigneesForTemplateName( String namespaceCode, String permissionTemplateName, AttributeSet permissionDetails, AttributeSet qualification ) { | 
  |  305 |    0 |                List<PermissionAssigneeInfo> results = new ArrayList<PermissionAssigneeInfo>();  | 
  |  306 |    0 |                List<String> roleIds = getRoleIdsForPermissionTemplate( namespaceCode, permissionTemplateName, permissionDetails);  | 
  |  307 |    0 |                if ( roleIds.isEmpty() ) { | 
  |  308 |    0 |                        return results;  | 
  |  309 |     | 
               }  | 
  |  310 |    0 |                Collection<RoleMembershipInfo> roleMembers = getRoleService().getRoleMembers( roleIds, qualification );  | 
  |  311 |    0 |                for ( RoleMembershipInfo rm : roleMembers ) { | 
  |  312 |    0 |                        if ( rm.getMemberTypeCode().equals( Role.PRINCIPAL_MEMBER_TYPE ) ) { | 
  |  313 |    0 |                                results.add( new PermissionAssigneeInfo( rm.getMemberId(), null, rm.getDelegates() ) );  | 
  |  314 |     | 
                       } else {  | 
  |  315 |    0 |                                results.add( new PermissionAssigneeInfo( null, rm.getMemberId(), rm.getDelegates() ) );  | 
  |  316 |     | 
                       }  | 
  |  317 |     | 
               }  | 
  |  318 |    0 |                return results;  | 
  |  319 |     | 
       }  | 
  |  320 |     | 
         | 
  |  321 |     | 
       public boolean isPermissionAssigned( String namespaceCode, String permissionName, AttributeSet permissionDetails ) { | 
  |  322 |    0 |                return !getRoleIdsForPermission(namespaceCode, permissionName, permissionDetails).isEmpty();  | 
  |  323 |     | 
       }  | 
  |  324 |     | 
         | 
  |  325 |     | 
       public boolean isPermissionDefined( String namespaceCode, String permissionName, AttributeSet permissionDetails ) { | 
  |  326 |     | 
                 | 
  |  327 |    0 |                List<KimPermissionImpl> permissions = getPermissionImplsByName( namespaceCode, permissionName );  | 
  |  328 |     | 
                 | 
  |  329 |    0 |                return !getMatchingPermissions( permissions, permissionDetails ).isEmpty();     | 
  |  330 |     | 
       }  | 
  |  331 |     | 
         | 
  |  332 |     | 
       public boolean isPermissionDefinedForTemplateName( String namespaceCode, String permissionTemplateName, AttributeSet permissionDetails ) { | 
  |  333 |     | 
                 | 
  |  334 |    0 |                List<KimPermissionImpl> permissions = getPermissionImplsByTemplateName( namespaceCode, permissionTemplateName );  | 
  |  335 |     | 
                 | 
  |  336 |    0 |                return !getMatchingPermissions( permissions, permissionDetails ).isEmpty();     | 
  |  337 |     | 
       }  | 
  |  338 |     | 
      | 
  |  339 |     | 
       public List<String> getRoleIdsForPermission( String namespaceCode, String permissionName, AttributeSet permissionDetails) { | 
  |  340 |     | 
                 | 
  |  341 |    0 |                List<KimPermissionImpl> permissions = getPermissionImplsByName( namespaceCode, permissionName );  | 
  |  342 |     | 
                 | 
  |  343 |    0 |                List<KimPermissionInfo> applicablePermissions = getMatchingPermissions( permissions, permissionDetails );              | 
  |  344 |    0 |                List<String> roleIds = getRolesForPermissionsFromCache( applicablePermissions );  | 
  |  345 |    0 |                if ( roleIds == null ) { | 
  |  346 |    0 |                        roleIds = permissionDao.getRoleIdsForPermissions( applicablePermissions );  | 
  |  347 |    0 |                        addRolesForPermissionsToCache( applicablePermissions, roleIds );  | 
  |  348 |     | 
               }  | 
  |  349 |    0 |                return roleIds;              | 
  |  350 |     | 
       }  | 
  |  351 |     | 
     | 
  |  352 |     | 
       protected List<String> getRoleIdsForPermissionTemplate( String namespaceCode, String permissionTemplateName, AttributeSet permissionDetails ) { | 
  |  353 |     | 
                 | 
  |  354 |    0 |                List<KimPermissionImpl> permissions = getPermissionImplsByTemplateName( namespaceCode, permissionTemplateName );  | 
  |  355 |     | 
                 | 
  |  356 |    0 |                List<KimPermissionInfo> applicablePermissions = getMatchingPermissions( permissions, permissionDetails );  | 
  |  357 |    0 |                List<String> roleIds = getRolesForPermissionsFromCache( applicablePermissions );  | 
  |  358 |    0 |                if ( roleIds == null ) { | 
  |  359 |    0 |                        roleIds = permissionDao.getRoleIdsForPermissions( applicablePermissions );  | 
  |  360 |    0 |                        addRolesForPermissionsToCache( applicablePermissions, roleIds );  | 
  |  361 |     | 
               }  | 
  |  362 |    0 |                return roleIds;  | 
  |  363 |     | 
       }  | 
  |  364 |     | 
         | 
  |  365 |     | 
       public List<String> getRoleIdsForPermissions( List<KimPermissionInfo> permissions ) { | 
  |  366 |    0 |                List<String> roleIds = getRolesForPermissionsFromCache( permissions );  | 
  |  367 |    0 |                if ( roleIds == null ) { | 
  |  368 |    0 |                        roleIds = permissionDao.getRoleIdsForPermissions( permissions );  | 
  |  369 |    0 |                        addRolesForPermissionsToCache( permissions, roleIds );  | 
  |  370 |     | 
               }  | 
  |  371 |    0 |                return roleIds;  | 
  |  372 |     | 
       }  | 
  |  373 |     | 
     | 
  |  374 |     | 
         | 
  |  375 |     | 
         | 
  |  376 |     | 
         | 
  |  377 |     | 
         | 
  |  378 |     | 
         | 
  |  379 |     | 
     | 
  |  380 |     | 
     | 
  |  381 |     | 
       public KimPermissionInfo getPermission(String permissionId) { | 
  |  382 |    0 |                KimPermissionImpl impl = getPermissionImpl( permissionId );  | 
  |  383 |    0 |                if ( impl != null ) { | 
  |  384 |    0 |                        return impl.toSimpleInfo();  | 
  |  385 |     | 
               }  | 
  |  386 |    0 |                return null;  | 
  |  387 |     | 
       }  | 
  |  388 |     | 
         | 
  |  389 |     | 
         | 
  |  390 |     | 
     | 
  |  391 |     | 
     | 
  |  392 |     | 
       public List<KimPermissionInfo> getPermissionsByTemplateName(String namespaceCode, String permissionTemplateName) { | 
  |  393 |    0 |                List<KimPermissionImpl> impls = getPermissionImplsByTemplateName( namespaceCode, permissionTemplateName );  | 
  |  394 |    0 |                List<KimPermissionInfo> results = new ArrayList<KimPermissionInfo>( impls.size() );  | 
  |  395 |    0 |                for ( KimPermissionImpl impl : impls ) { | 
  |  396 |    0 |                        results.add( impl.toSimpleInfo() );  | 
  |  397 |     | 
               }  | 
  |  398 |    0 |                return results;  | 
  |  399 |     | 
       }  | 
  |  400 |     | 
     | 
  |  401 |     | 
             | 
  |  402 |     | 
     | 
  |  403 |     | 
     | 
  |  404 |     | 
       public List<KimPermissionInfo> getPermissionsByName(String namespaceCode, String permissionName) { | 
  |  405 |    0 |                List<KimPermissionImpl> impls = getPermissionImplsByName( namespaceCode, permissionName );  | 
  |  406 |    0 |                List<KimPermissionInfo> results = new ArrayList<KimPermissionInfo>( impls.size() );  | 
  |  407 |    0 |                for ( KimPermissionImpl impl : impls ) { | 
  |  408 |    0 |                        results.add( impl.toSimpleInfo() );  | 
  |  409 |     | 
               }  | 
  |  410 |    0 |                return results;  | 
  |  411 |     | 
       }  | 
  |  412 |     | 
         | 
  |  413 |     | 
       @SuppressWarnings("unchecked") | 
  |  414 |     | 
           protected KimPermissionImpl getPermissionImpl(String permissionId) { | 
  |  415 |    0 |                if ( StringUtils.isBlank( permissionId ) ) { | 
  |  416 |    0 |                        return null;  | 
  |  417 |     | 
               }  | 
  |  418 |    0 |                String cacheKey = getPermissionImplByIdCacheKey(permissionId);  | 
  |  419 |    0 |                List<KimPermissionImpl> permissions = (List<KimPermissionImpl>)getCacheAdministrator().getFromCache(cacheKey);  | 
  |  420 |    0 |                if ( permissions == null ) { | 
  |  421 |    0 |                        HashMap<String,Object> pk = new HashMap<String,Object>( 1 );  | 
  |  422 |    0 |                        pk.put( KimConstants.PrimaryKeyConstants.PERMISSION_ID, permissionId );  | 
  |  423 |    0 |                        permissions = Collections.singletonList( (KimPermissionImpl)getBusinessObjectService().findByPrimaryKey( KimPermissionImpl.class, pk ) );  | 
  |  424 |    0 |                        getCacheAdministrator().putInCache(cacheKey, permissions, PERMISSION_IMPL_CACHE_GROUP);  | 
  |  425 |     | 
               }  | 
  |  426 |    0 |                return permissions.get( 0 );  | 
  |  427 |     | 
       }  | 
  |  428 |     | 
         | 
  |  429 |     | 
       @SuppressWarnings("unchecked") | 
  |  430 |     | 
           protected List<KimPermissionImpl> getPermissionImplsByTemplateName( String namespaceCode, String permissionTemplateName ) { | 
  |  431 |    0 |                String cacheKey = getPermissionImplByTemplateNameCacheKey(namespaceCode, permissionTemplateName);  | 
  |  432 |    0 |                List<KimPermissionImpl> permissions = (List<KimPermissionImpl>)getCacheAdministrator().getFromCache(cacheKey);  | 
  |  433 |    0 |                if ( permissions == null ) {             | 
  |  434 |    0 |                        HashMap<String,Object> pk = new HashMap<String,Object>( 3 );  | 
  |  435 |    0 |                        pk.put( "template.namespaceCode", namespaceCode );  | 
  |  436 |    0 |                        pk.put( "template.name", permissionTemplateName );  | 
  |  437 |    0 |                            pk.put( KNSPropertyConstants.ACTIVE, "Y" );  | 
  |  438 |    0 |                        permissions = (List<KimPermissionImpl>)getBusinessObjectService().findMatching( KimPermissionImpl.class, pk );  | 
  |  439 |    0 |                        getCacheAdministrator().putInCache(cacheKey, permissions, PERMISSION_IMPL_CACHE_GROUP);  | 
  |  440 |     | 
               }  | 
  |  441 |    0 |                return permissions;  | 
  |  442 |     | 
       }  | 
  |  443 |     | 
     | 
  |  444 |     | 
       @SuppressWarnings("unchecked") | 
  |  445 |     | 
           protected List<KimPermissionImpl> getPermissionImplsByName( String namespaceCode, String permissionName ) { | 
  |  446 |    0 |                String cacheKey = getPermissionImplByNameCacheKey(namespaceCode, permissionName);  | 
  |  447 |    0 |                List<KimPermissionImpl> permissions = (List<KimPermissionImpl>)getCacheAdministrator().getFromCache(cacheKey);  | 
  |  448 |    0 |                if ( permissions == null ) { | 
  |  449 |    0 |                        HashMap<String,Object> pk = new HashMap<String,Object>( 3 );  | 
  |  450 |    0 |                        pk.put( KimConstants.UniqueKeyConstants.NAMESPACE_CODE, namespaceCode );  | 
  |  451 |    0 |                        pk.put( KimConstants.UniqueKeyConstants.PERMISSION_NAME, permissionName );  | 
  |  452 |    0 |                            pk.put( KNSPropertyConstants.ACTIVE, "Y" );  | 
  |  453 |    0 |                        permissions = (List<KimPermissionImpl>)getBusinessObjectService().findMatching( KimPermissionImpl.class, pk );  | 
  |  454 |    0 |                        getCacheAdministrator().putInCache(cacheKey, permissions, PERMISSION_IMPL_CACHE_GROUP);  | 
  |  455 |     | 
               }  | 
  |  456 |    0 |                return permissions;  | 
  |  457 |     | 
       }  | 
  |  458 |     | 
     | 
  |  459 |     | 
         | 
  |  460 |     | 
         | 
  |  461 |     | 
         | 
  |  462 |     | 
         | 
  |  463 |     | 
         | 
  |  464 |     | 
             | 
  |  465 |     | 
             | 
  |  466 |     | 
           protected RoleService getRoleService() { | 
  |  467 |    0 |                    if ( roleService == null ) { | 
  |  468 |    0 |                            roleService = KIMServiceLocator.getRoleManagementService();  | 
  |  469 |     | 
                   }  | 
  |  470 |     | 
     | 
  |  471 |    0 |                    return roleService;  | 
  |  472 |     | 
           }  | 
  |  473 |     | 
     | 
  |  474 |     | 
           public void setRoleService(RoleService roleService) { | 
  |  475 |    0 |                    this.roleService = roleService;  | 
  |  476 |    0 |            }  | 
  |  477 |     | 
     | 
  |  478 |     | 
           public KimPermissionDao getPermissionDao() { | 
  |  479 |    0 |                    return this.permissionDao;  | 
  |  480 |     | 
           }  | 
  |  481 |     | 
     | 
  |  482 |     | 
           public void setPermissionDao(KimPermissionDao permissionDao) { | 
  |  483 |    0 |                    this.permissionDao = permissionDao;  | 
  |  484 |    0 |            }  | 
  |  485 |     | 
     | 
  |  486 |     | 
           @SuppressWarnings("unchecked") | 
  |  487 |     | 
           public List<KimPermissionInfo> lookupPermissions(Map<String, String> searchCriteria, boolean unbounded ){ | 
  |  488 |    0 |                    Collection baseResults = null;  | 
  |  489 |    0 |                    Lookupable permissionLookupable = KNSServiceLocatorWeb.getLookupable(  | 
  |  490 |     | 
                   KNSServiceLocatorWeb.getBusinessObjectDictionaryService().getLookupableID(PermissionImpl.class)  | 
  |  491 |     | 
           );  | 
  |  492 |    0 |                    permissionLookupable.setBusinessObjectClass(PermissionImpl.class);  | 
  |  493 |    0 |                    if ( unbounded ) { | 
  |  494 |    0 |                        baseResults = permissionLookupable.getSearchResultsUnbounded( searchCriteria );  | 
  |  495 |     | 
                   } else { | 
  |  496 |    0 |                            baseResults = permissionLookupable.getSearchResults(searchCriteria);  | 
  |  497 |     | 
                   }  | 
  |  498 |    0 |                    List<KimPermissionInfo> results = new ArrayList<KimPermissionInfo>( baseResults.size() );  | 
  |  499 |    0 |                    for ( KimPermissionImpl resp : (Collection<PermissionImpl>)baseResults ) { | 
  |  500 |    0 |                            results.add( resp.toSimpleInfo() );  | 
  |  501 |     | 
                   }  | 
  |  502 |    0 |                    if ( baseResults instanceof CollectionIncomplete ) { | 
  |  503 |    0 |                            results = new CollectionIncomplete<KimPermissionInfo>( results, ((CollectionIncomplete<KimPermissionInfo>)baseResults).getActualSizeIfTruncated() );   | 
  |  504 |     | 
                   }                  | 
  |  505 |    0 |                    return results;  | 
  |  506 |     | 
           }  | 
  |  507 |     | 
     | 
  |  508 |     | 
           public String getPermissionDetailLabel( String permissionId, String kimTypeId, String attributeName) { | 
  |  509 |     | 
                 | 
  |  510 |    0 |                    KimPermissionTypeService typeService = getPermissionTypeService(null, null, null, permissionId);  | 
  |  511 |    0 |                    if ( typeService != null ) { | 
  |  512 |     | 
                             | 
  |  513 |    0 |                            AttributeDefinitionMap attributes = typeService.getAttributeDefinitions( kimTypeId );  | 
  |  514 |    0 |                            String label = null;  | 
  |  515 |    0 |                            for ( AttributeDefinition attributeDef : attributes.values() ) { | 
  |  516 |    0 |                                    if ( attributeDef.getName().equals(attributeName) ) { | 
  |  517 |    0 |                                            label = attributeDef.getLabel();  | 
  |  518 |     | 
                                   }  | 
  |  519 |     | 
                           }  | 
  |  520 |     | 
                             | 
  |  521 |    0 |                            if ( label != null ) { | 
  |  522 |    0 |                                    return label;  | 
  |  523 |     | 
                           } else { | 
  |  524 |    0 |                                    return "Missing Def: " + attributeName;  | 
  |  525 |     | 
                           }  | 
  |  526 |     | 
                   } else { | 
  |  527 |    0 |                            return "No Label: " + attributeName;  | 
  |  528 |     | 
                   }  | 
  |  529 |     | 
           }  | 
  |  530 |     | 
             | 
  |  531 |     | 
             | 
  |  532 |     | 
     | 
  |  533 |     | 
     | 
  |  534 |     | 
           public KimPermissionTemplateInfo getPermissionTemplate(String permissionTemplateId) { | 
  |  535 |    0 |                    KimPermissionTemplateImpl impl = getBusinessObjectService().findBySinglePrimaryKey( KimPermissionTemplateImpl.class, permissionTemplateId );  | 
  |  536 |    0 |                    if ( impl != null ) { | 
  |  537 |    0 |                            return impl.toSimpleInfo();  | 
  |  538 |     | 
                   }  | 
  |  539 |    0 |                    return null;  | 
  |  540 |     | 
           }  | 
  |  541 |     | 
     | 
  |  542 |     | 
             | 
  |  543 |     | 
     | 
  |  544 |     | 
     | 
  |  545 |     | 
     | 
  |  546 |     | 
     | 
  |  547 |     | 
           public KimPermissionTemplateInfo getPermissionTemplateByName(String namespaceCode,  | 
  |  548 |     | 
                           String permissionTemplateName) { | 
  |  549 |    0 |                    Map<String,String> criteria = new HashMap<String,String>(2);  | 
  |  550 |    0 |                    criteria.put( KimConstants.UniqueKeyConstants.NAMESPACE_CODE, namespaceCode );  | 
  |  551 |    0 |                    criteria.put( KimConstants.UniqueKeyConstants.PERMISSION_TEMPLATE_NAME, permissionTemplateName );  | 
  |  552 |    0 |                    KimPermissionTemplateImpl impl = (KimPermissionTemplateImpl)getBusinessObjectService().findByPrimaryKey( KimPermissionTemplateImpl.class, criteria );  | 
  |  553 |    0 |                    if ( impl != null ) { | 
  |  554 |    0 |                            return impl.toSimpleInfo();  | 
  |  555 |     | 
                   }  | 
  |  556 |    0 |                    return null;  | 
  |  557 |     | 
           }  | 
  |  558 |     | 
             | 
  |  559 |     | 
           @SuppressWarnings("unchecked") | 
  |  560 |     | 
           public List<KimPermissionTemplateInfo> getAllTemplates() { | 
  |  561 |    0 |                    if ( allTemplates == null ) { | 
  |  562 |    0 |                            Map<String,String> criteria = new HashMap<String,String>(1);  | 
  |  563 |    0 |                            criteria.put( KNSPropertyConstants.ACTIVE, "Y" );  | 
  |  564 |    0 |                            List<KimPermissionTemplateImpl> impls = (List<KimPermissionTemplateImpl>)getBusinessObjectService().findMatching( KimPermissionTemplateImpl.class, criteria );  | 
  |  565 |    0 |                            List<KimPermissionTemplateInfo> infos = new ArrayList<KimPermissionTemplateInfo>( impls.size() );  | 
  |  566 |    0 |                            for ( KimPermissionTemplateImpl impl : impls ) { | 
  |  567 |    0 |                                    infos.add( impl.toSimpleInfo() );  | 
  |  568 |     | 
                           }  | 
  |  569 |    0 |                            Collections.sort(infos, new Comparator<KimPermissionTemplateInfo>() { | 
  |  570 |     | 
                                   public int compare(KimPermissionTemplateInfo tmpl1,  | 
  |  571 |     | 
                                                   KimPermissionTemplateInfo tmpl2) { | 
  |  572 |    0 |                                            int result = 0;  | 
  |  573 |    0 |                                            result = tmpl1.getNamespaceCode().compareTo(tmpl2.getNamespaceCode());  | 
  |  574 |    0 |                                            if ( result != 0 ) { | 
  |  575 |    0 |                                                    return result;  | 
  |  576 |     | 
                                           }  | 
  |  577 |    0 |                                            result = tmpl1.getName().compareTo(tmpl2.getName());  | 
  |  578 |    0 |                                            return result;  | 
  |  579 |     | 
                                   }  | 
  |  580 |     | 
                           });  | 
  |  581 |    0 |                            allTemplates = infos;  | 
  |  582 |     | 
                   }  | 
  |  583 |    0 |                    return allTemplates;  | 
  |  584 |     | 
           }  | 
  |  585 |     | 
     | 
  |  586 |     | 
         | 
  |  587 |     | 
             | 
  |  588 |     | 
           private DataDictionaryService dataDictionaryService;  | 
  |  589 |     | 
           protected DataDictionaryService getDataDictionaryService() { | 
  |  590 |    0 |                    if(dataDictionaryService == null){ | 
  |  591 |    0 |                            dataDictionaryService = KNSServiceLocatorWeb.getDataDictionaryService();  | 
  |  592 |     | 
                   }  | 
  |  593 |    0 |                    return dataDictionaryService;  | 
  |  594 |     | 
           }  | 
  |  595 |     | 
             | 
  |  596 |     | 
     | 
  |  597 |     | 
       public List<String> getRoleIdsForPermissionId(String permissionId) { | 
  |  598 |    0 |            KimPermissionInfo permissionInfo = getPermission(permissionId);  | 
  |  599 |     | 
     | 
  |  600 |    0 |            List<KimPermissionInfo> applicablePermissions = new ArrayList<KimPermissionInfo>();  | 
  |  601 |    0 |            applicablePermissions.add(permissionInfo);  | 
  |  602 |     | 
     | 
  |  603 |    0 |            List<String> roleIds = getRolesForPermissionsFromCache(applicablePermissions);  | 
  |  604 |    0 |            if (roleIds == null) { | 
  |  605 |    0 |                roleIds = permissionDao.getRoleIdsForPermissions(applicablePermissions);  | 
  |  606 |    0 |                addRolesForPermissionsToCache(applicablePermissions, roleIds);  | 
  |  607 |     | 
           }  | 
  |  608 |     | 
     | 
  |  609 |    0 |            return roleIds;  | 
  |  610 |     | 
       }  | 
  |  611 |     | 
     | 
  |  612 |     | 
       public List<KimPermissionInfo> getPermissionsByNameIncludingInactive(String namespaceCode, String permissionName) { | 
  |  613 |    0 |            List<KimPermissionImpl> impls = getPermissionImplsByNameIncludingInactive(namespaceCode, permissionName);  | 
  |  614 |    0 |            List<KimPermissionInfo> results = new ArrayList<KimPermissionInfo>(impls.size());  | 
  |  615 |    0 |            for (KimPermissionImpl impl : impls) { | 
  |  616 |    0 |                results.add(impl.toSimpleInfo());  | 
  |  617 |     | 
           }  | 
  |  618 |    0 |            return results;  | 
  |  619 |     | 
       }  | 
  |  620 |     | 
             | 
  |  621 |     | 
       @SuppressWarnings("unchecked") | 
  |  622 |     | 
       protected List<KimPermissionImpl> getPermissionImplsByNameIncludingInactive(String namespaceCode, String permissionName) { | 
  |  623 |    0 |            String cacheKey = getPermissionImplByNameCacheKey(namespaceCode, permissionName + "inactive");  | 
  |  624 |    0 |            List<KimPermissionImpl> permissions = (List<KimPermissionImpl>) getCacheAdministrator().getFromCache(cacheKey);  | 
  |  625 |    0 |            if (permissions == null) { | 
  |  626 |    0 |                HashMap<String, Object> pk = new HashMap<String, Object>(2);  | 
  |  627 |    0 |                pk.put(KimConstants.UniqueKeyConstants.NAMESPACE_CODE, namespaceCode);  | 
  |  628 |    0 |                pk.put(KimConstants.UniqueKeyConstants.PERMISSION_NAME, permissionName);  | 
  |  629 |    0 |                permissions = (List<KimPermissionImpl>) getBusinessObjectService().findMatching(KimPermissionImpl.class, pk);  | 
  |  630 |    0 |                getCacheAdministrator().putInCache(cacheKey, permissions, PERMISSION_IMPL_CACHE_GROUP);  | 
  |  631 |     | 
           }  | 
  |  632 |    0 |            return permissions;  | 
  |  633 |     | 
       }  | 
  |  634 |     | 
             | 
  |  635 |     | 
   }  |