|  1 |     | 
     | 
  |  2 |     | 
     | 
  |  3 |     | 
     | 
  |  4 |     | 
     | 
  |  5 |     | 
     | 
  |  6 |     | 
     | 
  |  7 |     | 
     | 
  |  8 |     | 
     | 
  |  9 |     | 
     | 
  |  10 |     | 
     | 
  |  11 |     | 
     | 
  |  12 |     | 
     | 
  |  13 |     | 
     | 
  |  14 |     | 
     | 
  |  15 |     | 
     | 
  |  16 |     | 
   package org.kuali.rice.kns.authorization;  | 
  |  17 |     | 
     | 
  |  18 |     | 
   import java.util.ArrayList;  | 
  |  19 |     | 
   import java.util.List;  | 
  |  20 |     | 
     | 
  |  21 |     | 
   import org.apache.commons.lang.StringUtils;  | 
  |  22 |     | 
   import org.kuali.rice.core.xml.dto.AttributeSet;  | 
  |  23 |     | 
   import org.kuali.rice.kim.bo.Role;  | 
  |  24 |     | 
   import org.kuali.rice.kim.bo.role.dto.PermissionAssigneeInfo;  | 
  |  25 |     | 
   import org.kuali.rice.kim.bo.role.dto.RoleMembershipInfo;  | 
  |  26 |     | 
   import org.kuali.rice.kim.service.IdentityManagementService;  | 
  |  27 |     | 
   import org.kuali.rice.kim.service.KIMServiceLocator;  | 
  |  28 |     | 
   import org.kuali.rice.kim.service.support.impl.KimDerivedRoleTypeServiceBase;  | 
  |  29 |     | 
     | 
  |  30 |     | 
     | 
  |  31 |     | 
     | 
  |  32 |     | 
     | 
  |  33 |     | 
     | 
  |  34 |     | 
     | 
  |  35 |     | 
     | 
  |  36 |    0 |    public class PermissionDerivedRoleTypeServiceImpl extends KimDerivedRoleTypeServiceBase { | 
  |  37 |     | 
     | 
  |  38 |     | 
           private static IdentityManagementService identityManagementService;  | 
  |  39 |     | 
           private String permissionTemplateNamespace;  | 
  |  40 |     | 
           private String permissionTemplateName;  | 
  |  41 |     | 
             | 
  |  42 |     | 
     | 
  |  43 |     | 
     | 
  |  44 |     | 
           public String getPermissionTemplateNamespace() { | 
  |  45 |    0 |                    return this.permissionTemplateNamespace;  | 
  |  46 |     | 
           }  | 
  |  47 |     | 
             | 
  |  48 |     | 
     | 
  |  49 |     | 
     | 
  |  50 |     | 
           public void setPermissionTemplateNamespace(String permissionTemplateNamespace) { | 
  |  51 |    0 |                    this.permissionTemplateNamespace = permissionTemplateNamespace;  | 
  |  52 |    0 |            }  | 
  |  53 |     | 
             | 
  |  54 |     | 
     | 
  |  55 |     | 
     | 
  |  56 |     | 
           public String getPermissionTemplateName() { | 
  |  57 |    0 |                    return this.permissionTemplateName;  | 
  |  58 |     | 
           }  | 
  |  59 |     | 
             | 
  |  60 |     | 
     | 
  |  61 |     | 
     | 
  |  62 |     | 
           public void setPermissionTemplateName(String permissionTemplateName) { | 
  |  63 |    0 |                    this.permissionTemplateName = permissionTemplateName;  | 
  |  64 |    0 |            }  | 
  |  65 |     | 
             | 
  |  66 |     | 
           protected List<PermissionAssigneeInfo> getPermissionAssignees(AttributeSet qualification) { | 
  |  67 |    0 |                    return getIdentityManagementService().getPermissionAssigneesForTemplateName(permissionTemplateNamespace, permissionTemplateName, qualification, qualification);  | 
  |  68 |     | 
           }  | 
  |  69 |     | 
     | 
  |  70 |     | 
             | 
  |  71 |     | 
     | 
  |  72 |     | 
     | 
  |  73 |     | 
     | 
  |  74 |     | 
     | 
  |  75 |     | 
           @Override  | 
  |  76 |     | 
       public List<RoleMembershipInfo> getRoleMembersFromApplicationRole(String namespaceCode, String roleName, AttributeSet qualification) { | 
  |  77 |    0 |                    List<PermissionAssigneeInfo> permissionAssignees = getPermissionAssignees(qualification);  | 
  |  78 |    0 |                    List<RoleMembershipInfo> members = new ArrayList<RoleMembershipInfo>();  | 
  |  79 |    0 |                    for (PermissionAssigneeInfo permissionAssigneeInfo : permissionAssignees) { | 
  |  80 |    0 |                            if (StringUtils.isNotBlank(permissionAssigneeInfo.getPrincipalId())) { | 
  |  81 |    0 |                                members.add( new RoleMembershipInfo( null, null, permissionAssigneeInfo.getPrincipalId(), Role.PRINCIPAL_MEMBER_TYPE, null));  | 
  |  82 |    0 |                            } else if (StringUtils.isNotBlank(permissionAssigneeInfo.getGroupId())) { | 
  |  83 |    0 |                    members.add( new RoleMembershipInfo( null, null, permissionAssigneeInfo.getGroupId(), Role.GROUP_MEMBER_TYPE, null));  | 
  |  84 |     | 
                           }  | 
  |  85 |     | 
                   }  | 
  |  86 |    0 |                    return members;  | 
  |  87 |     | 
           }  | 
  |  88 |     | 
             | 
  |  89 |     | 
         | 
  |  90 |     | 
     | 
  |  91 |     | 
     | 
  |  92 |     | 
       @Override  | 
  |  93 |     | 
       public boolean hasApplicationRole(  | 
  |  94 |     | 
               String principalId, List<String> groupIds, String namespaceCode, String roleName, AttributeSet qualification){ | 
  |  95 |     | 
             | 
  |  96 |    0 |                return getIdentityManagementService().isAuthorizedByTemplateName(principalId,permissionTemplateNamespace, permissionTemplateName, qualification, qualification);      | 
  |  97 |     | 
           }  | 
  |  98 |     | 
         | 
  |  99 |     | 
         | 
  |  100 |     | 
     | 
  |  101 |     | 
     | 
  |  102 |     | 
       protected IdentityManagementService getIdentityManagementService(){ | 
  |  103 |    0 |            if (identityManagementService == null ) { | 
  |  104 |    0 |                    identityManagementService = KIMServiceLocator.getIdentityManagementService();  | 
  |  105 |     | 
           }  | 
  |  106 |    0 |            return identityManagementService;  | 
  |  107 |     | 
       }  | 
  |  108 |     | 
             | 
  |  109 |     | 
   }  |