-
-
Notifications
You must be signed in to change notification settings - Fork 170
/
HideProps.java
80 lines (69 loc) · 3 KB
/
HideProps.java
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
/*-
* ========================LICENSE_START=================================
* restheart-security
* %%
* Copyright (C) 2018 - 2020 SoftInstigate
* %%
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
* =========================LICENSE_END==================================
*/
package org.restheart.mongodb.security;
import org.restheart.plugins.MongoInterceptor;
import org.restheart.plugins.RegisterPlugin;
import org.restheart.security.MongoPermissions;
import java.util.Set;
import org.bson.BsonDocument;
import org.restheart.exchange.MongoRequest;
import org.restheart.exchange.MongoResponse;
import org.restheart.plugins.InterceptPoint;
@RegisterPlugin(name = "mongoPermissionHideProps",
description = "Hides properties from the response according to the mongo.hideProps ACL permission",
interceptPoint = InterceptPoint.RESPONSE,
enabledByDefault = true)
public class HideProps implements MongoInterceptor {
@Override
public void handle(MongoRequest request, MongoResponse response) throws Exception {
var hiddendProps = MongoPermissions.of(request).getHideProps();
if (response.getContent().isDocument()) {
hide(response.getContent().asDocument(), hiddendProps);
} else if (response.getContent().isArray()) {
response.getContent().asArray().forEach(doc -> hide(doc.asDocument(), hiddendProps));
}
}
private void hide(BsonDocument doc, Set<String> hideProps) {
hideProps.stream().forEachOrdered(hiddenProp -> hide(doc, hiddenProp));
}
private void hide(BsonDocument doc, String hiddenProp) {
if (hiddenProp.contains(".")) {
var first = hiddenProp.substring(0, hiddenProp.indexOf("."));
if (first.length() > 0 && doc.containsKey(first) && doc.get(first).isDocument()) {
hide(doc.get(first).asDocument(), hiddenProp.substring(hiddenProp.indexOf(".")+1));
}
} else if (hiddenProp.length() > 0) {
doc.remove(hiddenProp);
}
}
@Override
public boolean resolve(MongoRequest request, MongoResponse response) {
if (!request.isHandledBy("mongo") || response.getContent() == null) {
return false;
}
var mongoPermission = MongoPermissions.of(request);
if (mongoPermission != null) {
return !mongoPermission.getHideProps().isEmpty();
} else {
return false;
}
}
}