/** * Gets the ApplicationUser in the current security context. Assumes the user is already authenticated, and the authenticated user is constructed through * the application's authentication mechanism. * * @return The ApplicationUser or null if not authenticated */ private ApplicationUser getApplicationUser() { Object principal = SecurityContextHolder.getContext().getAuthentication().getPrincipal(); if (principal != null && principal instanceof SecurityUserWrapper) { SecurityUserWrapper securityUserWrapper = (SecurityUserWrapper) principal; return securityUserWrapper.getApplicationUser(); } return null; }
/** * Gets the ApplicationUser in the current security context. Assumes the user is already authenticated, and the authenticated user is constructed through * the application's authentication mechanism. * * @return The ApplicationUser or null if not authenticated */ private ApplicationUser getApplicationUser() { Object principal = SecurityContextHolder.getContext().getAuthentication().getPrincipal(); if (principal != null && principal instanceof SecurityUserWrapper) { SecurityUserWrapper securityUserWrapper = (SecurityUserWrapper) principal; return securityUserWrapper.getApplicationUser(); } return null; }
/** * Gets the existing user. * * @return the existing user or null if no existing user is present. */ protected ApplicationUser getExistingUser() { ApplicationUser applicationUser = null; Authentication authentication = SecurityContextHolder.getContext().getAuthentication(); if (authentication != null) { SecurityUserWrapper securityUserWrapper = (SecurityUserWrapper) authentication.getPrincipal(); if (securityUserWrapper != null) { applicationUser = securityUserWrapper.getApplicationUser(); LOGGER.trace("Existing Application User: " + applicationUser); return applicationUser; } } return applicationUser; }
/** * Checks whether the user was generated by. * * @param authentication the Authentication containing the user object. * @param generatedByClass the class to check that the user was generated by. * * @return boolean */ public boolean isUserGeneratedByClass(Authentication authentication, Class<?> generatedByClass) { boolean isGeneratedBy = false; if (authentication != null) { SecurityUserWrapper securityUserWrapper = (SecurityUserWrapper) authentication.getPrincipal(); if (securityUserWrapper != null && securityUserWrapper.getApplicationUser().getGeneratedByClass().equals(generatedByClass)) { isGeneratedBy = true; } } return isGeneratedBy; }
@Override public UserAuthorizations getCurrentUser() { // Create the user authorizations. UserAuthorizations userAuthorizations = new UserAuthorizations(); // Get the application user. Authentication authentication = SecurityContextHolder.getContext().getAuthentication(); if (authentication != null) { SecurityUserWrapper securityUserWrapper = (SecurityUserWrapper) authentication.getPrincipal(); ApplicationUser applicationUser = securityUserWrapper.getApplicationUser(); userAuthorizations.setUserId(applicationUser.getUserId()); // If roles are present on the application user then filter the herd-specific security roles and add that information to the Current user. if (CollectionUtils.isNotEmpty(applicationUser.getRoles())) { userAuthorizations.setSecurityRoles(new ArrayList<>(getValidSecurityRoles(applicationUser.getRoles()))); } // Get all granted authorities for this user. Collection<GrantedAuthority> grantedAuthorities = securityUserWrapper.getAuthorities(); // Add relative security functions as per granted authorities, if any are present. if (CollectionUtils.isNotEmpty(grantedAuthorities)) { userAuthorizations.setSecurityFunctions( grantedAuthorities.stream().map(grantedAuthority -> new String(grantedAuthority.getAuthority())).collect(Collectors.toList())); } userAuthorizations.setNamespaceAuthorizations(new ArrayList<>(applicationUser.getNamespaceAuthorizations())); } return userAuthorizations; }
@Override public UserAuthorizations getCurrentUser() { // Create the user authorizations. UserAuthorizations userAuthorizations = new UserAuthorizations(); // Get the application user. Authentication authentication = SecurityContextHolder.getContext().getAuthentication(); if (authentication != null) { SecurityUserWrapper securityUserWrapper = (SecurityUserWrapper) authentication.getPrincipal(); ApplicationUser applicationUser = securityUserWrapper.getApplicationUser(); userAuthorizations.setUserId(applicationUser.getUserId()); // If roles are present on the application user then filter the herd-specific security roles and add that information to the Current user. if (CollectionUtils.isNotEmpty(applicationUser.getRoles())) { userAuthorizations.setSecurityRoles(new ArrayList<>(getValidSecurityRoles(applicationUser.getRoles()))); } // Get all granted authorities for this user. Collection<GrantedAuthority> grantedAuthorities = securityUserWrapper.getAuthorities(); // Add relative security functions as per granted authorities, if any are present. if (CollectionUtils.isNotEmpty(grantedAuthorities)) { userAuthorizations.setSecurityFunctions( grantedAuthorities.stream().map(grantedAuthority -> new String(grantedAuthority.getAuthority())).collect(Collectors.toList())); } userAuthorizations.setNamespaceAuthorizations(new ArrayList<>(applicationUser.getNamespaceAuthorizations())); } return userAuthorizations; }
/** * Asserts the given actual authentication's user ID is equal to the given expected user ID * * @param expectedUserId Expected user ID * @param actualAuthentication Actual authentication object */ private void assertAuthenticationUserIdEquals(String expectedUserId, Authentication actualAuthentication) { assertNotNull(actualAuthentication); assertEquals(PreAuthenticatedAuthenticationToken.class, actualAuthentication.getClass()); PreAuthenticatedAuthenticationToken preAuthenticatedAuthenticationToken = (PreAuthenticatedAuthenticationToken) actualAuthentication; Object principal = preAuthenticatedAuthenticationToken.getPrincipal(); assertNotNull(principal); assertEquals(SecurityUserWrapper.class, principal.getClass()); SecurityUserWrapper securityUserWrapper = (SecurityUserWrapper) principal; assertEquals(expectedUserId, securityUserWrapper.getUsername()); assertNotNull(securityUserWrapper.getApplicationUser()); assertEquals(expectedUserId, securityUserWrapper.getApplicationUser().getUserId()); } }