001: /* ====================================================================
002: * The Jcorporate Apache Style Software License, Version 1.2 05-07-2002
003: *
004: * Copyright (c) 1995-2002 Jcorporate Ltd. All rights reserved.
005: *
006: * Redistribution and use in source and binary forms, with or without
007: * modification, are permitted provided that the following conditions
008: * are met:
009: *
010: * 1. Redistributions of source code must retain the above copyright
011: * notice, this list of conditions and the following disclaimer.
012: *
013: * 2. Redistributions in binary form must reproduce the above copyright
014: * notice, this list of conditions and the following disclaimer in
015: * the documentation and/or other materials provided with the
016: * distribution.
017: *
018: * 3. The end-user documentation included with the redistribution,
019: * if any, must include the following acknowledgment:
020: * "This product includes software developed by Jcorporate Ltd.
021: * (http://www.jcorporate.com/)."
022: * Alternately, this acknowledgment may appear in the software itself,
023: * if and wherever such third-party acknowledgments normally appear.
024: *
025: * 4. "Jcorporate" and product names such as "Expresso" must
026: * not be used to endorse or promote products derived from this
027: * software without prior written permission. For written permission,
028: * please contact info@jcorporate.com.
029: *
030: * 5. Products derived from this software may not be called "Expresso",
031: * or other Jcorporate product names; nor may "Expresso" or other
032: * Jcorporate product names appear in their name, without prior
033: * written permission of Jcorporate Ltd.
034: *
035: * 6. No product derived from this software may compete in the same
036: * market space, i.e. framework, without prior written permission
037: * of Jcorporate Ltd. For written permission, please contact
038: * partners@jcorporate.com.
039: *
040: * THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESSED OR IMPLIED
041: * WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
042: * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
043: * DISCLAIMED. IN NO EVENT SHALL JCORPORATE LTD OR ITS CONTRIBUTORS
044: * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
045: * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
046: * TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
047: * USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
048: * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
049: * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
050: * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
051: * SUCH DAMAGE.
052: * ====================================================================
053: *
054: * This software consists of voluntary contributions made by many
055: * individuals on behalf of the Jcorporate Ltd. Contributions back
056: * to the project(s) are encouraged when you make modifications.
057: * Please send them to support@jcorporate.com. For more information
058: * on Jcorporate Ltd. and its products, please see
059: * <http://www.jcorporate.com/>.
060: *
061: * Portions of this software are based upon other open source
062: * products and are subject to their respective licenses.
063: */
064:
065: package com.jcorporate.expresso.services.dbobj;
066:
067: import com.jcorporate.expresso.core.controller.ControllerRequest;
068: import com.jcorporate.expresso.core.db.DBException;
069: import com.jcorporate.expresso.core.dbobj.DBObject;
070: import com.jcorporate.expresso.core.dbobj.Schema;
071: import com.jcorporate.expresso.core.dbobj.SchemaFactory;
072: import com.jcorporate.expresso.core.dbobj.SecuredDBObject;
073: import com.jcorporate.expresso.core.dbobj.ValidValue;
074:
075: import java.util.Enumeration;
076: import java.util.Iterator;
077: import java.util.Vector;
078:
079: /**
080: * <p/>
081: * <p>Database Object Security: What is this user allowed to do with a given
082: * database object</p>
083: *
084: * @author Michael Nash
085: */
086: public class DBObjSecurity extends SecurityDBObject {
087: /**
088: * field names
089: */
090: public static final String DBOBJECT_NAME = "DBObjectName";
091: public static final String GROUP_NAME = "GroupName";
092: public static final String METHOD_ALLOWED_CODE = "MethodCode";
093:
094: //private static Category log = null;
095: private Vector dbObjList = null;
096:
097: /**
098: * @see com.jcorporate.expresso.core.dbobj.SecuredDBObject#SecuredDBObject
099: */
100: public DBObjSecurity() throws DBException {
101: super ();
102: } /* DBObjSecurity() */
103:
104: /**
105: * Construct a DBObjSecurity object with the given owner credentials
106: *
107: * @param uid the owner uid
108: */
109: public DBObjSecurity(int uid) throws DBException {
110: super (uid);
111: }
112:
113: /**
114: * For using DBObjects within Controllers. Initializes based upon the current
115: * user and the requested db. [Of course this can be modified later]
116: *
117: * @param request - The controller request handed to you by the framework.
118: */
119: public DBObjSecurity(ControllerRequest request) throws DBException {
120: super (request);
121: }
122:
123: /**
124: * Extends the checkAllRefs method to check for valid UserGroup
125: */
126: protected void checkAllRefs() throws DBException {
127: checkRef(GROUP_NAME, new UserGroup(
128: SecuredDBObject.SYSTEM_ACCOUNT), "Invalid "
129: + getString(getMetaData().getDescription(GROUP_NAME)));
130: } /* checkAllRefs() */
131:
132: /**
133: * Loads the schema and sets the approprate valid values for the schemas
134: * and the member's descriptions
135: *
136: * @param schemaName The schema name to load
137: * @param schemaDescrip The friendly name of the schema
138: * @param oList ??
139: */
140: private void doSchema(String schemaName, String schemaDescrip,
141: Vector oList) throws DBException {
142: /** Note: If anything goes wrong loading a schema here, we just log
143: * it and skip processing for this schema.
144: */
145: Schema oneSchema = SchemaFactory.getInstance().getSchema(
146: schemaName);
147: if (oneSchema == null) {
148: return;
149: }
150: DBObject oneDBObj = null;
151: ValidValue oneVal = null;
152:
153: /* Now add all of the objects in this schema to our list */
154: for (Enumeration e = oneSchema.getMembers(); e
155: .hasMoreElements();) {
156: oneDBObj = (DBObject) e.nextElement();
157: oneVal = new ValidValue(oneDBObj.getClass().getName(),
158: schemaDescrip + ": "
159: + oneDBObj.getMetaData().getDescription());
160: oList.addElement(oneVal);
161: }
162: } /* doSchema(String, String, Vector) */
163:
164: /**
165: * Override the method getValues to provide specific values for our
166: * multi-valued fields
167: *
168: * @param fieldName Fielname to retrieve values for
169: * @return Vector of ValidValue Value/description pairs for this field
170: * @throws DBException If the values cannot be retrieved
171: */
172: public synchronized Vector getValidValues(String fieldName)
173: throws DBException {
174: if (fieldName.equals(METHOD_ALLOWED_CODE)) {
175: Vector myValues = new Vector(4);
176: myValues.addElement(new ValidValue(SecuredDBObject.ADD,
177: "Add"));
178: myValues.addElement(new ValidValue(SecuredDBObject.UPDATE,
179: "Update"));
180: myValues.addElement(new ValidValue(SecuredDBObject.DELETE,
181: "Delete"));
182: myValues.addElement(new ValidValue(SecuredDBObject.SEARCH,
183: "Search"));
184:
185: return myValues;
186: } else if (fieldName.equals(DBOBJECT_NAME)) {
187: if (dbObjList == null) {
188: SchemaList myList = new SchemaList(
189: SecuredDBObject.SYSTEM_ACCOUNT);
190: myList.setDataContext(getDataContext());
191:
192: SchemaList oneList = null;
193: dbObjList = new Vector(10);
194: dbObjList.addElement(new ValidValue(
195: "com.jcorporate.expresso."
196: + "core.dbobj.AutoDBObject",
197: "Expresso: Automatic DB Objects"));
198: doSchema("com.jcorporate.expresso.core.ExpressoSchema",
199: "Expresso", dbObjList);
200:
201: /* Get any database objects listed as existing in another */
202:
203: /* database */
204: DBOtherMap otherList = new DBOtherMap();
205: otherList.setDataContext(getDataContext());
206:
207: DBOtherMap oneOther = null;
208:
209: for (Iterator e2 = otherList.searchAndRetrieveList()
210: .iterator(); e2.hasNext();) {
211: oneOther = (DBOtherMap) e2.next();
212: dbObjList.addElement(new ValidValue(oneOther
213: .getField("DBObjName"), oneOther
214: .getField("Descrip")));
215: }
216: /* Now get all of the schemas listed in the database as well */
217: for (Iterator sl = myList.searchAndRetrieveList()
218: .iterator(); sl.hasNext();) {
219: oneList = (SchemaList) sl.next();
220: doSchema(oneList.getField("SchemaClass"), oneList
221: .getField("Descrip"), dbObjList);
222: } /* for each schema list */
223:
224: }
225:
226: return dbObjList;
227: }
228:
229: return super .getValidValues(fieldName);
230: } /* getValidValues(String) */
231:
232: /**
233: * @see com.jcorporate.expresso.core.dbobj.SecuredDBObject#setupFields()
234: */
235: protected synchronized void setupFields() throws DBException {
236: setTargetTable("DBOBJSECURITY");
237: setName("DBOBJSECURITY");
238: setDescription("DB Object Security");
239: setCharset("ISO-8859-1");
240: addField(DBOBJECT_NAME, "varchar", 80, false, "dbobjName");
241: addField(GROUP_NAME, "char", 30, false, "groupName");
242: addField(METHOD_ALLOWED_CODE, "char", 1, false, "methodAllowed");
243: addKey(DBOBJECT_NAME);
244: addKey(METHOD_ALLOWED_CODE);
245: addKey(GROUP_NAME);
246: setStringFilter(DBOBJECT_NAME, "stripFilter");
247: setStringFilter(GROUP_NAME, "stripFilter");
248: setStringFilter(METHOD_ALLOWED_CODE, "stripFilter");
249: setMultiValued(GROUP_NAME);
250: setLookupObject(GROUP_NAME, UserGroup.class.getName());
251: setMultiValued(METHOD_ALLOWED_CODE);
252: setMultiValued(DBOBJECT_NAME);
253: } /* setupFields() */
254:
255: } /* DBObjSecurity */
|