1 | |
|
2 | |
|
3 | |
|
4 | |
|
5 | |
|
6 | |
|
7 | |
|
8 | |
|
9 | |
|
10 | |
|
11 | |
|
12 | |
|
13 | |
|
14 | |
|
15 | |
|
16 | |
package org.kuali.rice.krad.authorization; |
17 | |
|
18 | |
import org.apache.commons.lang.StringUtils; |
19 | |
import org.kuali.rice.kim.api.role.Role; |
20 | |
import org.kuali.rice.kim.api.role.RoleMembership; |
21 | |
import org.kuali.rice.kim.api.services.KimApiServiceLocator; |
22 | |
import org.kuali.rice.kim.bo.role.dto.PermissionAssigneeInfo; |
23 | |
import org.kuali.rice.kim.service.PermissionService; |
24 | |
import org.kuali.rice.kim.service.support.impl.KimDerivedRoleTypeServiceBase; |
25 | |
|
26 | |
import java.util.ArrayList; |
27 | |
import java.util.HashMap; |
28 | |
import java.util.List; |
29 | |
import java.util.Map; |
30 | |
|
31 | |
|
32 | |
|
33 | |
|
34 | |
|
35 | |
|
36 | 0 | public class PermissionDerivedRoleTypeServiceImpl extends KimDerivedRoleTypeServiceBase { |
37 | |
|
38 | |
private static PermissionService permissionService; |
39 | |
private String permissionTemplateNamespace; |
40 | |
private String permissionTemplateName; |
41 | |
|
42 | |
|
43 | |
|
44 | |
public String getPermissionTemplateNamespace() { |
45 | 0 | return this.permissionTemplateNamespace; |
46 | |
} |
47 | |
|
48 | |
|
49 | |
|
50 | |
public void setPermissionTemplateNamespace(String permissionTemplateNamespace) { |
51 | 0 | this.permissionTemplateNamespace = permissionTemplateNamespace; |
52 | 0 | } |
53 | |
|
54 | |
|
55 | |
|
56 | |
public String getPermissionTemplateName() { |
57 | 0 | return this.permissionTemplateName; |
58 | |
} |
59 | |
|
60 | |
|
61 | |
|
62 | |
public void setPermissionTemplateName(String permissionTemplateName) { |
63 | 0 | this.permissionTemplateName = permissionTemplateName; |
64 | 0 | } |
65 | |
|
66 | |
protected List<PermissionAssigneeInfo> getPermissionAssignees(Map<String, String> qualification) { |
67 | 0 | return getPermissionService().getPermissionAssigneesForTemplateName(permissionTemplateNamespace, permissionTemplateName, new HashMap<String, String>(qualification), new HashMap<String, String>(qualification)); |
68 | |
} |
69 | |
|
70 | |
@Override |
71 | |
public List<RoleMembership> getRoleMembersFromApplicationRole(String namespaceCode, String roleName, Map<String, String> qualification) { |
72 | 0 | List<PermissionAssigneeInfo> permissionAssignees = getPermissionAssignees(qualification); |
73 | 0 | List<RoleMembership> members = new ArrayList<RoleMembership>(); |
74 | 0 | for (PermissionAssigneeInfo permissionAssigneeInfo : permissionAssignees) { |
75 | 0 | if (StringUtils.isNotBlank(permissionAssigneeInfo.getPrincipalId())) { |
76 | 0 | members.add(RoleMembership.Builder.create(null, null, permissionAssigneeInfo.getPrincipalId(), Role.PRINCIPAL_MEMBER_TYPE, null).build()); |
77 | 0 | } else if (StringUtils.isNotBlank(permissionAssigneeInfo.getGroupId())) { |
78 | 0 | members.add(RoleMembership.Builder.create(null, null, permissionAssigneeInfo.getGroupId(), Role.GROUP_MEMBER_TYPE, null).build()); |
79 | |
} |
80 | |
} |
81 | 0 | return members; |
82 | |
} |
83 | |
|
84 | |
|
85 | |
@Override |
86 | |
public boolean hasApplicationRole( |
87 | |
String principalId, List<String> groupIds, String namespaceCode, String roleName, Map<String, String> qualification){ |
88 | |
|
89 | 0 | return getPermissionService().isAuthorizedByTemplateName(principalId, permissionTemplateNamespace, permissionTemplateName, new HashMap<String, String>(qualification), new HashMap<String, String>(qualification)); |
90 | |
} |
91 | |
|
92 | |
|
93 | |
|
94 | |
|
95 | |
protected PermissionService getPermissionService() { |
96 | 0 | if (permissionService == null) { |
97 | 0 | permissionService = KimApiServiceLocator.getPermissionService(); |
98 | |
} |
99 | 0 | return permissionService; |
100 | |
} |
101 | |
|
102 | |
} |