Package com.illumon.iris.auth
Class AuthenticationServerBase
java.lang.Object
com.illumon.iris.auth.AuthenticationServerBase
- All Implemented Interfaces:
LocalAuthenticationServer
- Direct Known Subclasses:
GrpcAuthenticationServer
Business logic (independent of transport) for an authentication server implementation. Transport details are provided in classes derived from this one.
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionprotected final classprotected static classprotected classLinked list to help when scanning for expired tokens. -
Field Summary
FieldsModifier and TypeFieldDescriptionprotected final AuditEventLoggerprotected final @NotNull AuthHookModuleprotected final List<AuthModule>protected static final io.deephaven.hash.KeyedObjectKey<Object,AuthenticationServerBase.ClientState> protected final io.deephaven.hash.KeyedObjectHash.ValueFactory<Object,AuthenticationServerBase.ClientState> protected final io.deephaven.hash.KeyedObjectHashMap<Object,AuthenticationServerBase.ClientState> protected final com.fishlib.io.logger.Loggerprotected final booleanprotected final DataImportServerLogFactoryprotected final InetAddressstatic final intHow long will we wait for our etcd election lease to be granted or renewed, in milliseconds before determining that we had a failure.static final intWhat is the maximum frequency which we will try to renew an auth resolver lease.protected final SecureRandomprotected AuthenticationServerBase.TokenEntryListprotected final Map<Long,AuthenticationServerBase.TokenEntry> protected final ReloadableUserAuthConfig -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionbooleanaddLocalClient(LocalAuthenticationClientManager localClient, String userToAuthenticate, String effectiveUser) Inserts the localClient into this authentication server's state map.protected booleanauthenticateByDelegateToken(Object client, AuthToken delegateToken, String sessionDesc) protected booleanauthenticatedByCookie(Object client, SimpleUserContext userContext, String sessionDesc) static booleancheckHashedPassword(com.fishlib.io.logger.Logger log, String userToAuthenticate, String password, String hashed) protected NotAuthenticatedExceptionstatic StringcreateHashedPassword(char[] password) protected AuthTokencreateToken(Object client, AuthenticationServerBase.ClientState clientState, String service, String sessionDesc) protected AuthTokencreateToken(Object client, String service, AuthenticationServerBase.ClientState clientState, UserContext context, String sessionDesc) protected AuthTokencreateTokenForUser(Object client, String service, String operateAs, String sessionDesc) createTokenForUserLocal(LocalAuthenticationClientManager client, String service, String operateAs) Creates a token for the provided service and user.createTokenLocal(LocalAuthenticationClientManager client, String service) protected SimpleUserContextexternalAuthentication(Object client, String key, String sessionDesc) protected static StringfingerPrint(PublicKey key) Compute the SHA-1 digest of the key encoded as a hex stringbyte[]booleanisTokenValid(String verifyingService, AuthToken tokenToVerify) com.fishlib.io.logger.Loggerlog()static booleannullOrSameCredentials(AuthenticationServerBase.ClientState clientState, UserContext userContext) static booleannullOrSameCredentials(AuthenticationServerBase.ClientState clientState, String user, String effectiveUser) protected booleanpasswordAuthentication(Object client, String userToAuthenticate, String password, String effectiveUser, String sessionDesc) protected booleanpermittedToOperateAs(String userToAuthenticate, String effectiveUser) protected voidregisterContext(Object client, UserContext context) protected voidregisterContext(Object client, String userToAuthenticate, String effectiveUser) protected voidremoveClientState(Object client) protected AuthenticationServerBase.TokenEntryremoveToken(long tokenId) protected voidshutdown()protected voidstart()protected AuthExceptionprotected booleanuserExists(String effectiveUser) protected booleanuserExistsCached(String user) protected booleanverifyChallenge(Object client, PublicKey publicKey, byte[] response, String userToAuthenticate, String effectiveUser, String sessionDesc) booleanverifyChallengeLocal(LocalAuthenticationClientManager localClient, PublicKey publicKey, byte[] response, String userToAuthenticate, String effectiveUser)
-
Field Details
-
RESOLVER_ETCD_LEASE_RENEW_RETRY_DELAY_SECONDS
public static final int RESOLVER_ETCD_LEASE_RENEW_RETRY_DELAY_SECONDSWhat is the maximum frequency which we will try to renew an auth resolver lease. If a lease renewal times out, we will try again more quickly than the standard RESOLVER_LEASE_RENEW_SECONDS. -
RESOLVER_ETCD_LEASE_KEEPALIVE_TIMEOUT_MS
public static final int RESOLVER_ETCD_LEASE_KEEPALIVE_TIMEOUT_MSHow long will we wait for our etcd election lease to be granted or renewed, in milliseconds before determining that we had a failure. -
secureRandom
-
tokensById
-
clientStatesByEntry
protected final io.deephaven.hash.KeyedObjectHashMap<Object,AuthenticationServerBase.ClientState> clientStatesByEntry -
CLIENT_STATE_CLIENT_ENTRY_KEY
protected static final io.deephaven.hash.KeyedObjectKey<Object,AuthenticationServerBase.ClientState> CLIENT_STATE_CLIENT_ENTRY_KEY -
clientStateFactory
protected final io.deephaven.hash.KeyedObjectHash.ValueFactory<Object,AuthenticationServerBase.ClientState> clientStateFactory -
logCreator
-
log
protected final com.fishlib.io.logger.Logger log -
auditLog
-
LOG_TOKEN_EVENTS
protected final boolean LOG_TOKEN_EVENTS -
userConfig
-
authHookModule
-
authModules
-
originHost
-
tokenEntryList
-
-
Constructor Details
-
AuthenticationServerBase
public AuthenticationServerBase(DataImportServerLogFactory logFactory) throws IOException, ConfigurationVerificationException
-
-
Method Details
-
getOriginHost
- Specified by:
getOriginHostin interfaceLocalAuthenticationServer
-
start
protected void start() -
shutdown
protected void shutdown() -
checkHashedPassword
-
createHashedPassword
-
nullOrSameCredentials
public static boolean nullOrSameCredentials(AuthenticationServerBase.ClientState clientState, UserContext userContext) -
nullOrSameCredentials
public static boolean nullOrSameCredentials(AuthenticationServerBase.ClientState clientState, String user, String effectiveUser) -
removeClientState
-
passwordAuthentication
-
authenticatedByCookie
protected boolean authenticatedByCookie(Object client, SimpleUserContext userContext, String sessionDesc) -
tooManyNonces
-
getNonce
- Specified by:
getNoncein interfaceLocalAuthenticationServer
-
verifyChallengeLocal
public boolean verifyChallengeLocal(LocalAuthenticationClientManager localClient, PublicKey publicKey, byte[] response, String userToAuthenticate, String effectiveUser) - Specified by:
verifyChallengeLocalin interfaceLocalAuthenticationServer
-
addLocalClient
public boolean addLocalClient(LocalAuthenticationClientManager localClient, String userToAuthenticate, String effectiveUser) Description copied from interface:LocalAuthenticationServerInserts the localClient into this authentication server's state map.
The client is authenticated as the provided user.
- Specified by:
addLocalClientin interfaceLocalAuthenticationServer- Parameters:
localClient- the local client stateuserToAuthenticate- the authenticated user for the client state.effectiveUser- the effective user for the client state.- Returns:
- true (authentication cannot fail)
-
registerContext
-
registerContext
-
verifyChallenge
-
authenticateByDelegateToken
-
externalAuthentication
-
log
public com.fishlib.io.logger.Logger log() -
fingerPrint
Compute the SHA-1 digest of the key encoded as a hex string- Returns:
- The SHA-1 digest as a hex string or
"<error>"if it was unsuccessful
-
permittedToOperateAs
-
userExists
-
isTokenValid
- Specified by:
isTokenValidin interfaceLocalAuthenticationServer
-
createTokenLocal
- Specified by:
createTokenLocalin interfaceLocalAuthenticationServer
-
createTokenForUserLocal
public AuthToken createTokenForUserLocal(LocalAuthenticationClientManager client, String service, String operateAs) Description copied from interface:LocalAuthenticationServerCreates a token for the provided service and user.- Specified by:
createTokenForUserLocalin interfaceLocalAuthenticationServer- Parameters:
client- the client to create a token forservice- the service to create a token foroperateAs- the effective user to create a token for- Returns:
- the newly created token
-
clientNotAuthenticated
-
createToken
protected AuthToken createToken(Object client, AuthenticationServerBase.ClientState clientState, String service, String sessionDesc) -
createToken
protected AuthToken createToken(Object client, String service, AuthenticationServerBase.ClientState clientState, UserContext context, String sessionDesc) -
createTokenForUser
-
removeToken
-
userExistsCached
-
reloadConfigurationInternal
-
reloadConfiguration
-