Class ReloadableUserAuthConfig

java.lang.Object
com.illumon.iris.auth.ReloadableUserAuthConfig

public class ReloadableUserAuthConfig extends Object
This class contains User authentication details that can be reloaded out-of-process to capture changes outside the current classpath.
  • Constructor Details

    • ReloadableUserAuthConfig

      public ReloadableUserAuthConfig(com.fishlib.io.logger.Logger log)
  • Method Details

    • getHashForUser

      public String getHashForUser(String user)
      Parameters:
      user - The user to check.
      Returns:
      The password has for the specified user.
    • getSudoTargetsForUser

      public Collection<String> getSudoTargetsForUser(String user)
      Parameters:
      user - The user to get sudo targets for.
      Returns:
      All of the valid users the specified user my sudo as.
    • isSudoer

      public boolean isSudoer(String user)
      Parameters:
      user - The user to check.
      Returns:
      If the specified user was a sudoer.
    • hasUser

      public boolean hasUser(String user)
      Parameters:
      user - The user to look for.
      Returns:
      If the specified user exists.
    • hasLocalUsers

      public boolean hasLocalUsers()
      Returns:
      If there are any configured local users.
    • hasAuthorizedKeys

      public boolean hasAuthorizedKeys()
      Returns:
      If there are any configured authorized keys.
    • getUserForKey

      public String getUserForKey(PublicKey key)
      Parameters:
      key - A user's public key.
      Returns:
      The user associated with a PublicKey.
    • getLocalUserCount

      public int getLocalUserCount()
      Returns:
      The number of local users.
    • getAuthKeysCount

      public int getAuthKeysCount()
      Returns:
      The number of authorized keys.
    • getSudoersCount

      public int getSudoersCount()
      Returns:
      The number of users with sudo permissions.
    • installConfig

      public void installConfig()
      Install a verified config initalized by verifyConfigs(Document).
      ImplNote:
      This method must work in tandem with verifyConfigs(Document), so the user must externally lock this object and perform both operations in the same critical section to ensure consistency
    • verifyConfigs

      public void verifyConfigs(org.jdom2.Document doc) throws ConfigurationVerificationException

      Verify a Document generated via generateConfig() or generateInNewProcess()

      A single document may be verified at a time. When a document is verified the configuration is stored locally but not activated until installConfig() is called.

      Parameters:
      doc - The XML Document.
      Throws:
      ConfigurationVerificationException - If the document was malformed.
      ImplNote:
      This method must work in tandem with installConfig(), so the user must externally lock this object and perform both operations in the same critical section to ensure consistency
    • generateConfig

      public org.jdom2.Document generateConfig() throws IOException
      Generate an XML configuration Document to be verified by verifyConfigs(Document)
      Returns:
      A Document containing the relevant user configuration details.
      Throws:
      IOException - If a problem was encountered creating the config.
    • generateInNewProcess

      public static org.jdom2.Document generateInNewProcess() throws IOException
      Generate a config XML document to be processed by verifyConfigs(Document) in another process.
      Returns:
      A Document containing the relevant user configuration details.
      Throws:
      IOException - If a problem was encountered creating the config.
      ImplNote:
      This is reused from ControllerReloadableConfiguration, because we don't want to make more dependencies if we can avoid it.
    • main

      public static void main(String... args)