-
Notifications
You must be signed in to change notification settings - Fork 2.3k
/
FileRoleRepository.java
120 lines (103 loc) · 3.54 KB
/
FileRoleRepository.java
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
/*
* Copyright (c) 2002-2016 "Neo Technology,"
* Network Engine for Objects in Lund AB [http://neotechnology.com]
*
* This file is part of Neo4j.
*
* Neo4j is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, either version 3 of the
* License, or (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
package org.neo4j.server.security.enterprise.auth;
import java.io.IOException;
import java.nio.file.Files;
import java.nio.file.Path;
import java.util.List;
import java.util.regex.Pattern;
import org.neo4j.logging.Log;
import org.neo4j.logging.LogProvider;
import static java.nio.file.StandardCopyOption.ATOMIC_MOVE;
import static java.nio.file.StandardCopyOption.REPLACE_EXISTING;
/**
* Stores role data. In memory, but backed by persistent storage so changes to this repository will survive
* JVM restarts and crashes.
*/
public class FileRoleRepository extends AbstractRoleRepository
{
// TODO: Extract shared code with FileUserRepository
private final Path roleFile;
private final Log log;
private final RoleSerialization serialization = new RoleSerialization();
private final Pattern roleNamePattern = Pattern.compile( "^[a-zA-Z0-9_]+$" );
public FileRoleRepository( Path file, LogProvider logProvider )
{
this.roleFile = file.toAbsolutePath();
this.log = logProvider.getLog( getClass() );
}
@Override
public void start() throws Throwable
{
if ( Files.exists( roleFile ) )
{
loadRolesFromFile();
}
}
@Override
public boolean isValidRoleName( String roleName )
{
return roleNamePattern.matcher( roleName ).matches();
}
@Override
protected void saveRoles() throws IOException
{
saveRolesToFile();
}
private void saveRolesToFile() throws IOException
{
Path directory = roleFile.getParent();
if ( !Files.exists( directory ) )
{
Files.createDirectories( directory );
}
Path tempFile = Files.createTempFile( directory, roleFile.getFileName().toString() + "-", ".tmp" );
try
{
Files.write( tempFile, serialization.serialize( roles ) );
Files.move( tempFile, roleFile, ATOMIC_MOVE, REPLACE_EXISTING );
}
catch ( Throwable e )
{
Files.delete( tempFile );
throw e;
}
}
private void loadRolesFromFile() throws IOException
{
byte[] fileBytes = Files.readAllBytes( roleFile );
List<RoleRecord> loadedRoles;
try
{
loadedRoles = serialization.deserializeRoles( fileBytes );
}
catch ( RoleSerialization.FormatException e )
{
log.error( "Failed to read role file \"%s\" (%s)", roleFile.toAbsolutePath(), e.getMessage() );
throw new IllegalStateException( "Failed to read role file: " + roleFile );
}
roles = loadedRoles;
for ( RoleRecord role : roles )
{
rolesByName.put( role.name(), role );
populateUserMap( role );
}
}
}