Package org.myphotodiary.model

Examples of org.myphotodiary.model.User


    HttpSession session = req.getSession(false);
    if (session == null) {
      throw new AuthenticationException("No user session");
    }
    // Check that user is properly authenticated
    User user = (User) session.getAttribute(Configuration.userAttribute);
    if (user == null) {
      throw new AuthenticationException("No authenticated user");
    }
    if (path == null) {
      throw new AuthenticationException("Invalid resource path");
    }

    // Check if that directory path is indexed
    Directory directory;
    boolean closeEm = false;
    if (em == null) {
      em = ModelFactory.getEntityManager();
      closeEm = true;
    }
    try {
      try {
        directory = em
            .createQuery(
                "select directory from Directory directory where directory.path = ?1",
                Directory.class).setParameter(1, path)
            .getSingleResult();
      } catch (NoResultException ex) {
        // non indexed directories are public (to allow navigation)
        return;
      }

      // Refresh user and roles assignment
      List<RoleAssignment> roles;
      try {
        user = em.find(User.class, user.getUserName());
        roles = user.getRoleAssignments();
      } catch (NoResultException ex) {
        // User is no longer registered,
        throw new AuthenticationException("Unknown user");
      }

      // Check if directory group can be accessed by this user
      for (RoleAssignment roleAssignment : roles) {
        if (!roleAssignment.getGroupName().equals(directory.getGroup().getGroupName())) {
          continue;
        }
        Role.isPermitted(roleAssignment.getRole(), action);
        return;
      }
    } finally {
      if (closeEm) {
        // Close method managed EntityManager
        em.close();
      }
    }

    throw new AuthenticationException("Unauthorized user " + user.getUserName() + " for path " + path);
  }
View Full Code Here


    HttpSession session = req.getSession(false);
    if (session == null) {
      throw new AuthenticationException("No user session");
    }
    // Check that user is properly authenticated
    User user = (User) session.getAttribute(Configuration.userAttribute);
    if (user == null) {
      throw new AuthenticationException("No authenticated user");
    }

    // Non indexed directories are public
    if (directory == null) {
      return;
    }
   
    boolean closeEm = false;
    if (em == null) {
      em = ModelFactory.getEntityManager();
      closeEm = true;
    }
    try {
      // Refresh user and roles assignment
      List<RoleAssignment> roles;
      try {
        user = em.find(User.class, user.getUserName());
        roles = user.getRoleAssignments();
      } catch (NoResultException ex) {
        // User is no longer registered,
        throw new AuthenticationException("Unknown user");
      }

      // Check if directory group can be accessed by this user
      for (RoleAssignment roleAssignment : roles) {
        if (!roleAssignment.getGroupName().equals(directory.getGroup().getGroupName())) {
          continue;
        }
        Role.isPermitted(roleAssignment.getRole(), action);
        return;
      }
    } finally {
      if (closeEm) {
        // Close method managed EntityManager
        em.close();
      }
    }

    throw new AuthenticationException("Unauthorized user " + user.getUserName() + " for path " + directory.getPath());
  }
View Full Code Here

    HttpSession session = req.getSession(false);
    if (session == null) {
      throw new AuthenticationException("No user session");
    }
    // Check that user is properly authenticated
    User user = (User) session.getAttribute(Configuration.userAttribute);
    if (user == null) {
      throw new AuthenticationException("No authenticated user");
    }
    if (group == null) {
      throw new AuthenticationException("Unknown group");
    }
    String groupName = group.getGroupName();

    boolean closeEm = false;
    if (em == null) {
      em = ModelFactory.getEntityManager();
      closeEm = true;
    }
    try {
      // Refresh user and roles assignment
      List<RoleAssignment> roles;
      try {
        user = em.find(User.class, user.getUserName());
        roles = user.getRoleAssignments();
      } catch (NoResultException ex) {
        // User is no longer registered,
        throw new AuthenticationException("Unknown user");
      }

      // Check if directory group can be accessed by this user
      for (RoleAssignment roleAssignment : roles) {
        if (!roleAssignment.getGroupName().equals(groupName)) {
          continue;
        }
        Role.isPermitted(roleAssignment.getRole(), action);
        return;
      }
    } finally {
      if (closeEm) {
        // Close method managed EntityManager
        em.close();
      }
    }

    throw new AuthenticationException("Unauthorized user " + user.getUserName() + " for group " + groupName);
  }
View Full Code Here

    HttpSession session = req.getSession(false);
    if (session == null) {
      throw new AuthenticationException("No user session");
    }
    // Check that user is properly authenticated
    User user = (User) session.getAttribute(Configuration.userAttribute);
    if (user == null) {
      throw new AuthenticationException("No authenticated user");
    }

    boolean closeEm = false;
    if (em == null) {
      em = ModelFactory.getEntityManager();
      closeEm = true;
    }
    try {
      // Refresh user and roles assignment
      List<RoleAssignment> roles;
      try {
        user = em.find(User.class, user.getUserName());
        roles = user.getRoleAssignments();
      } catch (NoResultException ex) {
        // User is no longer registered,
        throw new AuthenticationException("Unknown user");
      }

      // Check if directory group can be accessed by this user
      for (RoleAssignment roleAssignment : roles) {
        Role.isPermitted(roleAssignment.getRole(), action);
        return;
      }
    } finally {
      if (closeEm) {
        // Close method managed EntityManager
        em.close();
      }
    }

    throw new AuthenticationException("Unauthorized user " + user.getUserName() + " for group ALL ");
  }
View Full Code Here

  protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
    getServletContext().log("-> SessionConfigurationSvr.doGet()\nParameters= " + request.getParameterMap().toString());

    // Get user from session. Session is necessary setup by the servlet filter
    HttpSession session = request.getSession(false);
    User user = (User) session.getAttribute(Configuration.userAttribute);
    if (user == null) {
      session.invalidate();
      response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);
      return;
    }

    EntityManager em = ModelFactory.getEntityManager();
    EntityTransaction tx = em.getTransaction();
    // reload user from database
    try {
      user = em.find(User.class, user.getUserName());
      UserConfiguration sessionConfig = user.getConfiguration();

      if (sessionConfig == null) {
        tx.begin();
        sessionConfig = new UserConfiguration(user);
        em.persist(sessionConfig);
View Full Code Here

  protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
    getServletContext().log("-> SessionConfigurationSvr.doPost()\nParameters= " + request.getParameterMap().toString());
   
    // Get user from session. Session is necessary setup by the servlet filter
    HttpSession session = request.getSession(false);
    User user = (User) session.getAttribute(Configuration.userAttribute);
    if (user == null) {
      session.invalidate();
      response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);
      return;
    }
   
    // Extract request json message
    UserConfiguration newConfig = null;
    try {
      newConfig = UserConfiguration.decode(request.getInputStream());
    }
    catch (Exception ex) {
      getServletContext().log("Cannot decode POSTed configuration parameters", ex);
      response.setStatus(HttpServletResponse.SC_BAD_REQUEST);
      return;
    }

    // Persist the session configuration into database
    EntityManager em = ModelFactory.getEntityManager();
    EntityTransaction tx = null;
    try {
      tx = em.getTransaction();
      tx.begin();
     
      user = em.find(User.class, user.getUserName());
      UserConfiguration oldConfig = user.getConfiguration();
      if (oldConfig != null) {
        oldConfig.update(newConfig);
        em.merge(oldConfig);
      }
      else {
View Full Code Here

    if ("".equals(userName)) {
      getServletContext().log("Authentication failure, missing user name");
      return authDataRsp;
    }
    // Try to authenticate new user
    User user = null;
    EntityManager em = null;
   
    try {
      em = ModelFactory.getEntityManager();

      // Check if userName exists
      user = em.find(User.class, userName);
     
      if (user == null) {
        String msg = "Authentication failure, unknown user name: " + userName;
        getServletContext().log(msg);
        throw new AuthenticationException(msg);
      }
      if (userPwd.equals(user.getPassword())) {
        getServletContext().log("Authentication sucess for user: " + userName);
        session.setAttribute(Configuration.userAttribute, user);
        authDataRsp.setAuthenticated(true);
        return authDataRsp;
      }
View Full Code Here

  protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
    getServletContext().log("-> SessionConfigurationSvr.doGet()\nParameters= " + request.getParameterMap().toString());

    // Get user from session. Session is necessary setup by the servlet filter
    HttpSession session = request.getSession(false);
    User user = (User) session.getAttribute(Configuration.userAttribute);
    if (user == null) {
      session.invalidate();
      response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);
      return;
    }

    EntityManager em = ModelFactory.getEntityManager();
    EntityTransaction tx = em.getTransaction();
    // reload user from database
    try {
      user = em.find(User.class, user.getUserName());
      UserConfiguration sessionConfig = user.getConfiguration();

      if (sessionConfig == null) {
        tx.begin();
        sessionConfig = new UserConfiguration(user);
        em.persist(sessionConfig);
View Full Code Here

  protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
    getServletContext().log("-> SessionConfigurationSvr.doPost()\nParameters= " + request.getParameterMap().toString());
   
    // Get user from session. Session is necessary setup by the servlet filter
    HttpSession session = request.getSession(false);
    User user = (User) session.getAttribute(Configuration.userAttribute);
    if (user == null) {
      session.invalidate();
      response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);
      return;
    }
   
    // Extract request json message
    UserConfiguration newConfig = null;
    try {
      newConfig = UserConfiguration.decode(request.getInputStream());
    }
    catch (Exception ex) {
      getServletContext().log("Cannot decode POSTed configuration parameters", ex);
      response.setStatus(HttpServletResponse.SC_BAD_REQUEST);
      return;
    }

    // Persist the session configuration into database
    EntityManager em = ModelFactory.getEntityManager();
    EntityTransaction tx = null;
    try {
      tx = em.getTransaction();
      tx.begin();
     
      user = em.find(User.class, user.getUserName());
      UserConfiguration oldConfig = user.getConfiguration();
      if (oldConfig != null) {
        oldConfig.update(newConfig);
        em.merge(oldConfig);
      }
      else {
View Full Code Here

      JsonUserAdminCmd.RecordRsp jsonRsp = new JsonUserAdminCmd.RecordRsp();
      try {
        // RBAC
        AccessController.checkAuthorization(request, Action.createUser, null);
       
        User user = ModelFactory.createUser(request, getServletContext(), null, null);
        jsonRsp.setResult("OK");
        jsonRsp.setRecord(user);
      }
      catch (ModelException ex) {
        getServletContext().log("User creation failure", ex);
View Full Code Here

TOP

Related Classes of org.myphotodiary.model.User

Copyright © 2018 www.massapicom. All rights reserved.
All source code are property of their respective owners. Java is a trademark of Sun Microsystems, Inc and owned by ORACLE Inc. Contact coftware#gmail.com.