Class SharePointADAuthority
- java.lang.Object
-
- org.apache.manifoldcf.core.connector.BaseConnector
-
- org.apache.manifoldcf.authorities.authorities.BaseAuthorityConnector
-
- org.apache.manifoldcf.authorities.authorities.sharepoint.SharePointADAuthority
-
- All Implemented Interfaces:
org.apache.manifoldcf.authorities.interfaces.IAuthorityConnector,org.apache.manifoldcf.core.interfaces.IConnector
public class SharePointADAuthority extends org.apache.manifoldcf.authorities.authorities.BaseAuthorityConnectorThis is the Active Directory implementation of the IAuthorityConnector interface, as used by SharePoint in Claim Space. It is meant to be used in conjunction with other SharePoint authorities, and should ONLY be used if SharePoint native authorization is being performed in ClaimSpace mode.
-
-
Nested Class Summary
Nested Classes Modifier and Type Class Description protected static classSharePointADAuthority.AuthorizationResponseDescriptionThis is the cache object descriptor for cached access tokens from this connector.protected static classSharePointADAuthority.DCConnectionParametersClass describing the connection parameters to a domain controller.protected static classSharePointADAuthority.DCRuleClass describing a domain suffix and corresponding domain controller name rule.protected static classSharePointADAuthority.DCSessionInfoClass representing the session information for a specific domain controller connection.
-
Field Summary
Fields Modifier and Type Field Description static java.lang.String_rcsidprotected static org.apache.manifoldcf.core.interfaces.StringSetemptyStringSet-
Fields inherited from class org.apache.manifoldcf.authorities.authorities.BaseAuthorityConnector
RESPONSE_UNREACHABLE, RESPONSE_UNREACHABLE_ADDITIVE, RESPONSE_USERNOTFOUND, RESPONSE_USERNOTFOUND_ADDITIVE, RESPONSE_USERUNAUTHORIZED, RESPONSE_USERUNAUTHORIZED_ADDITIVE
-
-
Constructor Summary
Constructors Constructor Description SharePointADAuthority()Constructor.
-
Method Summary
All Methods Static Methods Instance Methods Concrete Methods Modifier and Type Method Description protected static voidaddDomainController(java.util.Set<java.lang.String> seenDomains, org.apache.manifoldcf.core.interfaces.ConfigParams parameters, java.lang.String suffix, java.lang.String domainControllerName, java.lang.String userName, java.lang.String password, java.lang.String authentication, java.lang.String userACLsUsername)protected static java.lang.StringauthenticatedUserGroup()java.lang.Stringcheck()Check connection for sanity.voidclearThreadContext()Clear thread context.voidconnect(org.apache.manifoldcf.core.interfaces.ConfigParams configParams)Connect.protected javax.naming.ldap.LdapContextcreateDCSession(java.lang.String domainController)Create or lookup a session for a domain controller.protected static java.util.Map<java.lang.String,java.lang.String>createDomainControllerMap(org.apache.manifoldcf.core.interfaces.IPasswordMapperActivity mapper, java.lang.String suffix, java.lang.String domainControllerName, java.lang.String userName, java.lang.String password, java.lang.String authentication, java.lang.String userACLsUsername)protected static java.lang.Stringdeobfuscate(java.lang.String input)voiddisconnect()Close the connection.protected static java.lang.StringeveryoneGroup()protected static voidfillInCacheTab(java.util.Map<java.lang.String,java.lang.Object> velocityContext, org.apache.manifoldcf.core.interfaces.IPasswordMapperActivity mapper, org.apache.manifoldcf.core.interfaces.ConfigParams parameters)protected static voidfillInDomainControllerTab(java.util.Map<java.lang.String,java.lang.Object> velocityContext, org.apache.manifoldcf.core.interfaces.IPasswordMapperActivity mapper, org.apache.manifoldcf.core.interfaces.ConfigParams parameters)protected java.util.List<java.lang.String>getADTokens(java.lang.String userPart, java.lang.String domainPart, java.lang.String userName)Get the AD-derived access tokens for a user and domainorg.apache.manifoldcf.authorities.interfaces.AuthorizationResponsegetAuthorizationResponse(java.lang.String userName)Obtain the access tokens for a given user name.protected org.apache.manifoldcf.authorities.interfaces.AuthorizationResponsegetAuthorizationResponseUncached(java.lang.String userName)Obtain the access tokens for a given user name, uncached.org.apache.manifoldcf.authorities.interfaces.AuthorizationResponsegetDefaultAuthorizationResponse(java.lang.String userName)Obtain the default access tokens for a given user name.protected java.lang.StringgetDistinguishedName(javax.naming.ldap.LdapContext ctx, java.lang.String userName, java.lang.String searchBase, java.lang.String userACLsUsername)Obtain the DistinguishedName for a given user logon name.protected voidgetSessionParameters()Get parameters needed for caching.protected static java.lang.StringgroupTokenFromSID(java.lang.String SID)booleanisConnected()This method is called to assess whether to count this connector instance should actually be counted as being connected.protected static java.lang.StringldapEscape(java.lang.String input)LDAP escape a string.voidoutputConfigurationBody(org.apache.manifoldcf.core.interfaces.IThreadContext threadContext, org.apache.manifoldcf.core.interfaces.IHTTPOutput out, java.util.Locale locale, org.apache.manifoldcf.core.interfaces.ConfigParams parameters, java.lang.String tabName)Output the configuration body section.voidoutputConfigurationHeader(org.apache.manifoldcf.core.interfaces.IThreadContext threadContext, org.apache.manifoldcf.core.interfaces.IHTTPOutput out, java.util.Locale locale, org.apache.manifoldcf.core.interfaces.ConfigParams parameters, java.util.List<java.lang.String> tabsArray)Output the configuration header section.voidpoll()Poll.java.lang.StringprocessConfigurationPost(org.apache.manifoldcf.core.interfaces.IThreadContext threadContext, org.apache.manifoldcf.core.interfaces.IPostParameters variableContext, java.util.Locale locale, org.apache.manifoldcf.core.interfaces.ConfigParams parameters)Process a configuration post.voidsetThreadContext(org.apache.manifoldcf.core.interfaces.IThreadContext tc)Set thread context.protected static java.lang.Stringsid2String(byte[] SID)Convert a binary SID to a stringprotected static java.lang.StringuserTokenFromLoginName(java.lang.String loginName)protected static java.lang.StringuserTokenFromSID(java.lang.String SID)voidviewConfiguration(org.apache.manifoldcf.core.interfaces.IThreadContext threadContext, org.apache.manifoldcf.core.interfaces.IHTTPOutput out, java.util.Locale locale, org.apache.manifoldcf.core.interfaces.ConfigParams parameters)View configuration.-
Methods inherited from class org.apache.manifoldcf.authorities.authorities.BaseAuthorityConnector
getAccessTokens, getDefaultAccessTokens
-
Methods inherited from class org.apache.manifoldcf.core.connector.BaseConnector
deinstall, getConfiguration, install, outputConfigurationBody, outputConfigurationHeader, outputConfigurationHeader, pack, packFixedList, packList, packList, processConfigurationPost, unpack, unpackFixedList, unpackList, viewConfiguration
-
-
-
-
Field Detail
-
_rcsid
public static final java.lang.String _rcsid
- See Also:
- Constant Field Values
-
emptyStringSet
protected static org.apache.manifoldcf.core.interfaces.StringSet emptyStringSet
-
-
Method Detail
-
setThreadContext
public void setThreadContext(org.apache.manifoldcf.core.interfaces.IThreadContext tc) throws org.apache.manifoldcf.core.interfaces.ManifoldCFExceptionSet thread context.- Specified by:
setThreadContextin interfaceorg.apache.manifoldcf.core.interfaces.IConnector- Overrides:
setThreadContextin classorg.apache.manifoldcf.core.connector.BaseConnector- Throws:
org.apache.manifoldcf.core.interfaces.ManifoldCFException
-
clearThreadContext
public void clearThreadContext()
Clear thread context.- Specified by:
clearThreadContextin interfaceorg.apache.manifoldcf.core.interfaces.IConnector- Overrides:
clearThreadContextin classorg.apache.manifoldcf.core.connector.BaseConnector
-
connect
public void connect(org.apache.manifoldcf.core.interfaces.ConfigParams configParams)
Connect. The configuration parameters are included.- Specified by:
connectin interfaceorg.apache.manifoldcf.core.interfaces.IConnector- Overrides:
connectin classorg.apache.manifoldcf.core.connector.BaseConnector- Parameters:
configParams- are the configuration parameters for this connection.
-
deobfuscate
protected static java.lang.String deobfuscate(java.lang.String input)
-
check
public java.lang.String check() throws org.apache.manifoldcf.core.interfaces.ManifoldCFExceptionCheck connection for sanity.- Specified by:
checkin interfaceorg.apache.manifoldcf.core.interfaces.IConnector- Overrides:
checkin classorg.apache.manifoldcf.core.connector.BaseConnector- Throws:
org.apache.manifoldcf.core.interfaces.ManifoldCFException
-
createDCSession
protected javax.naming.ldap.LdapContext createDCSession(java.lang.String domainController) throws org.apache.manifoldcf.core.interfaces.ManifoldCFExceptionCreate or lookup a session for a domain controller.- Throws:
org.apache.manifoldcf.core.interfaces.ManifoldCFException
-
poll
public void poll() throws org.apache.manifoldcf.core.interfaces.ManifoldCFExceptionPoll. The connection should be closed if it has been idle for too long.- Specified by:
pollin interfaceorg.apache.manifoldcf.core.interfaces.IConnector- Overrides:
pollin classorg.apache.manifoldcf.core.connector.BaseConnector- Throws:
org.apache.manifoldcf.core.interfaces.ManifoldCFException
-
isConnected
public boolean isConnected()
This method is called to assess whether to count this connector instance should actually be counted as being connected.- Specified by:
isConnectedin interfaceorg.apache.manifoldcf.core.interfaces.IConnector- Overrides:
isConnectedin classorg.apache.manifoldcf.core.connector.BaseConnector- Returns:
- true if the connector instance is actually connected.
-
disconnect
public void disconnect() throws org.apache.manifoldcf.core.interfaces.ManifoldCFExceptionClose the connection. Call this before discarding the repository connector.- Specified by:
disconnectin interfaceorg.apache.manifoldcf.core.interfaces.IConnector- Overrides:
disconnectin classorg.apache.manifoldcf.core.connector.BaseConnector- Throws:
org.apache.manifoldcf.core.interfaces.ManifoldCFException
-
getAuthorizationResponse
public org.apache.manifoldcf.authorities.interfaces.AuthorizationResponse getAuthorizationResponse(java.lang.String userName) throws org.apache.manifoldcf.core.interfaces.ManifoldCFExceptionObtain the access tokens for a given user name.- Specified by:
getAuthorizationResponsein interfaceorg.apache.manifoldcf.authorities.interfaces.IAuthorityConnector- Overrides:
getAuthorizationResponsein classorg.apache.manifoldcf.authorities.authorities.BaseAuthorityConnector- Parameters:
userName- is the user name or identifier.- Returns:
- the response tokens (according to the current authority). (Should throws an exception only when a condition cannot be properly described within the authorization response object.)
- Throws:
org.apache.manifoldcf.core.interfaces.ManifoldCFException
-
getAuthorizationResponseUncached
protected org.apache.manifoldcf.authorities.interfaces.AuthorizationResponse getAuthorizationResponseUncached(java.lang.String userName) throws org.apache.manifoldcf.core.interfaces.ManifoldCFExceptionObtain the access tokens for a given user name, uncached.- Parameters:
userName- is the user name or identifier.- Returns:
- the response tokens (according to the current authority). (Should throws an exception only when a condition cannot be properly described within the authorization response object.)
- Throws:
org.apache.manifoldcf.core.interfaces.ManifoldCFException
-
getDefaultAuthorizationResponse
public org.apache.manifoldcf.authorities.interfaces.AuthorizationResponse getDefaultAuthorizationResponse(java.lang.String userName)
Obtain the default access tokens for a given user name.- Specified by:
getDefaultAuthorizationResponsein interfaceorg.apache.manifoldcf.authorities.interfaces.IAuthorityConnector- Overrides:
getDefaultAuthorizationResponsein classorg.apache.manifoldcf.authorities.authorities.BaseAuthorityConnector- Parameters:
userName- is the user name or identifier.- Returns:
- the default response tokens, presuming that the connect method fails.
-
getADTokens
protected java.util.List<java.lang.String> getADTokens(java.lang.String userPart, java.lang.String domainPart, java.lang.String userName) throws javax.naming.NameNotFoundException, javax.naming.NamingException, org.apache.manifoldcf.core.interfaces.ManifoldCFExceptionGet the AD-derived access tokens for a user and domain- Throws:
javax.naming.NameNotFoundExceptionjavax.naming.NamingExceptionorg.apache.manifoldcf.core.interfaces.ManifoldCFException
-
everyoneGroup
protected static java.lang.String everyoneGroup()
-
authenticatedUserGroup
protected static java.lang.String authenticatedUserGroup()
-
groupTokenFromSID
protected static java.lang.String groupTokenFromSID(java.lang.String SID)
-
userTokenFromSID
protected static java.lang.String userTokenFromSID(java.lang.String SID)
-
userTokenFromLoginName
protected static java.lang.String userTokenFromLoginName(java.lang.String loginName)
-
outputConfigurationHeader
public void outputConfigurationHeader(org.apache.manifoldcf.core.interfaces.IThreadContext threadContext, org.apache.manifoldcf.core.interfaces.IHTTPOutput out, java.util.Locale locale, org.apache.manifoldcf.core.interfaces.ConfigParams parameters, java.util.List<java.lang.String> tabsArray) throws org.apache.manifoldcf.core.interfaces.ManifoldCFException, java.io.IOExceptionOutput the configuration header section. This method is called in the head section of the connector's configuration page. Its purpose is to add the required tabs to the list, and to output any javascript methods that might be needed by the configuration editing HTML.- Specified by:
outputConfigurationHeaderin interfaceorg.apache.manifoldcf.core.interfaces.IConnector- Overrides:
outputConfigurationHeaderin classorg.apache.manifoldcf.core.connector.BaseConnector- Parameters:
threadContext- is the local thread context.out- is the output to which any HTML should be sent.parameters- are the configuration parameters, as they currently exist, for this connection being configured.tabsArray- is an array of tab names. Add to this array any tab names that are specific to the connector.- Throws:
org.apache.manifoldcf.core.interfaces.ManifoldCFExceptionjava.io.IOException
-
outputConfigurationBody
public void outputConfigurationBody(org.apache.manifoldcf.core.interfaces.IThreadContext threadContext, org.apache.manifoldcf.core.interfaces.IHTTPOutput out, java.util.Locale locale, org.apache.manifoldcf.core.interfaces.ConfigParams parameters, java.lang.String tabName) throws org.apache.manifoldcf.core.interfaces.ManifoldCFException, java.io.IOExceptionOutput the configuration body section. This method is called in the body section of the authority connector's configuration page. Its purpose is to present the required form elements for editing. The coder can presume that the HTML that is output from this configuration will be within appropriate <html>, <body>, and <form> tags. The name of the form is "editconnection".- Specified by:
outputConfigurationBodyin interfaceorg.apache.manifoldcf.core.interfaces.IConnector- Overrides:
outputConfigurationBodyin classorg.apache.manifoldcf.core.connector.BaseConnector- Parameters:
threadContext- is the local thread context.out- is the output to which any HTML should be sent.parameters- are the configuration parameters, as they currently exist, for this connection being configured.tabName- is the current tab name.- Throws:
org.apache.manifoldcf.core.interfaces.ManifoldCFExceptionjava.io.IOException
-
fillInDomainControllerTab
protected static void fillInDomainControllerTab(java.util.Map<java.lang.String,java.lang.Object> velocityContext, org.apache.manifoldcf.core.interfaces.IPasswordMapperActivity mapper, org.apache.manifoldcf.core.interfaces.ConfigParams parameters)
-
createDomainControllerMap
protected static java.util.Map<java.lang.String,java.lang.String> createDomainControllerMap(org.apache.manifoldcf.core.interfaces.IPasswordMapperActivity mapper, java.lang.String suffix, java.lang.String domainControllerName, java.lang.String userName, java.lang.String password, java.lang.String authentication, java.lang.String userACLsUsername)
-
fillInCacheTab
protected static void fillInCacheTab(java.util.Map<java.lang.String,java.lang.Object> velocityContext, org.apache.manifoldcf.core.interfaces.IPasswordMapperActivity mapper, org.apache.manifoldcf.core.interfaces.ConfigParams parameters)
-
processConfigurationPost
public java.lang.String processConfigurationPost(org.apache.manifoldcf.core.interfaces.IThreadContext threadContext, org.apache.manifoldcf.core.interfaces.IPostParameters variableContext, java.util.Locale locale, org.apache.manifoldcf.core.interfaces.ConfigParams parameters) throws org.apache.manifoldcf.core.interfaces.ManifoldCFExceptionProcess a configuration post. This method is called at the start of the authority connector's configuration page, whenever there is a possibility that form data for a connection has been posted. Its purpose is to gather form information and modify the configuration parameters accordingly. The name of the posted form is "editconnection".- Specified by:
processConfigurationPostin interfaceorg.apache.manifoldcf.core.interfaces.IConnector- Overrides:
processConfigurationPostin classorg.apache.manifoldcf.core.connector.BaseConnector- Parameters:
threadContext- is the local thread context.variableContext- is the set of variables available from the post, including binary file post information.parameters- are the configuration parameters, as they currently exist, for this connection being configured.- Returns:
- null if all is well, or a string error message if there is an error that should prevent saving of the connection (and cause a redirection to an error page).
- Throws:
org.apache.manifoldcf.core.interfaces.ManifoldCFException
-
addDomainController
protected static void addDomainController(java.util.Set<java.lang.String> seenDomains, org.apache.manifoldcf.core.interfaces.ConfigParams parameters, java.lang.String suffix, java.lang.String domainControllerName, java.lang.String userName, java.lang.String password, java.lang.String authentication, java.lang.String userACLsUsername) throws org.apache.manifoldcf.core.interfaces.ManifoldCFException- Throws:
org.apache.manifoldcf.core.interfaces.ManifoldCFException
-
viewConfiguration
public void viewConfiguration(org.apache.manifoldcf.core.interfaces.IThreadContext threadContext, org.apache.manifoldcf.core.interfaces.IHTTPOutput out, java.util.Locale locale, org.apache.manifoldcf.core.interfaces.ConfigParams parameters) throws org.apache.manifoldcf.core.interfaces.ManifoldCFException, java.io.IOExceptionView configuration. This method is called in the body section of the authority connector's view configuration page. Its purpose is to present the connection information to the user. The coder can presume that the HTML that is output from this configuration will be within appropriate <html> and <body>tags.- Specified by:
viewConfigurationin interfaceorg.apache.manifoldcf.core.interfaces.IConnector- Overrides:
viewConfigurationin classorg.apache.manifoldcf.core.connector.BaseConnector- Parameters:
threadContext- is the local thread context.out- is the output to which any HTML should be sent.parameters- are the configuration parameters, as they currently exist, for this connection being configured.- Throws:
org.apache.manifoldcf.core.interfaces.ManifoldCFExceptionjava.io.IOException
-
getSessionParameters
protected void getSessionParameters() throws org.apache.manifoldcf.core.interfaces.ManifoldCFExceptionGet parameters needed for caching.- Throws:
org.apache.manifoldcf.core.interfaces.ManifoldCFException
-
getDistinguishedName
protected java.lang.String getDistinguishedName(javax.naming.ldap.LdapContext ctx, java.lang.String userName, java.lang.String searchBase, java.lang.String userACLsUsername) throws org.apache.manifoldcf.core.interfaces.ManifoldCFExceptionObtain the DistinguishedName for a given user logon name.- Parameters:
ctx- is the ldap context to use.userName- (Domain Logon Name) is the user name or identifier.searchBase- (Full Domain Name for the search ie: DC=qa-ad-76,DC=metacarta,DC=com)- Returns:
- DistinguishedName for given domain user logon name. (Should throws an exception if user is not found.)
- Throws:
org.apache.manifoldcf.core.interfaces.ManifoldCFException
-
ldapEscape
protected static java.lang.String ldapEscape(java.lang.String input)
LDAP escape a string.
-
sid2String
protected static java.lang.String sid2String(byte[] SID)
Convert a binary SID to a string
-
-