Package org.nuxeo.ecm.directory.ldap
Class LDAPSession
- java.lang.Object
-
- org.nuxeo.ecm.directory.BaseSession
-
- org.nuxeo.ecm.directory.ldap.LDAPSession
-
- All Implemented Interfaces:
AutoCloseable
,EntrySource
,Session
public class LDAPSession extends BaseSession
This class represents a session against an LDAPDirectory.- Author:
- Olivier Grisel
-
-
Nested Class Summary
-
Nested classes/interfaces inherited from class org.nuxeo.ecm.directory.BaseSession
BaseSession.FieldDetector
-
-
Field Summary
Fields Modifier and Type Field Description protected DirContext
dirContext
protected Set<String>
emptySet
protected String
idAttribute
protected String
idCase
protected static String
MISSING_ID_LOWER_CASE
protected static String
MISSING_ID_UPPER_CASE
protected String
passwordHashAlgorithm
protected String
rdnAttribute
protected String
rdnField
protected String
searchBaseDn
-
Fields inherited from class org.nuxeo.ecm.directory.BaseSession
autoincrementId, computeMultiTenantId, directory, directoryName, MULTI_TENANT_ID_FORMAT, permissions, POWER_USERS_GROUP, readAllColumns, READONLY_ENTRY_FLAG, referenceClass, schemaName, substringMatchType, TENANT_ID_FIELD
-
-
Constructor Summary
Constructors Constructor Description LDAPSession(LDAPDirectory directory)
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description boolean
authenticate(String username, String password)
Checks that the credentials provided by the UserManager match those registered in the directory.protected String
changeEntryIdCase(String id, String idFieldCase)
void
close()
Closes the session and all open result sets obtained from this session.DocumentModel
createEntry(DocumentModel entry)
Creates an entry in a directory.protected DocumentModel
createEntryWithoutReferences(Map<String,Object> fieldMap)
To be implemented for specific creation.void
deleteEntry(String id, Map<String,String> map)
Deletes a directory entry by id and secondary ids.void
deleteEntryWithoutReferences(String id)
To be implemented for specific deletion.protected DocumentModel
fieldMapToDocumentModel(Map<String,Object> fieldMap)
protected Attribute
getAttributeValue(String fieldName, Object value)
DirContext
getContext()
LDAPDirectory
getDirectory()
To be implemented with a more specific return type.DocumentModel
getEntryFromSource(String id, boolean fetchReferences)
protected Object
getFieldValue(Attribute attribute, String fieldName, String entryId, boolean fetchReferences)
protected SearchResult
getLdapEntry(String id)
protected SearchResult
getLdapEntry(String id, boolean fetchAllAttributes)
protected List<String>
getMandatoryAttributes()
protected List<String>
getMandatoryAttributes(Attribute objectClassesAttribute)
protected void
handleException(Exception e, String message)
boolean
hasEntry(String id)
Returns true if session has an entry with given id.boolean
isAuthenticating()
Tells whether the directory implementation can be used as an authenticating backend for the UserManager (based on login / password check).protected DocumentModelList
ldapResultsToDocumentModels(NamingEnumeration<SearchResult> results, boolean fetchReferences)
protected DocumentModel
ldapResultToDocumentModel(SearchResult result, String entryId, boolean fetchReferences)
DocumentModelList
query(Map<String,Serializable> filter, Set<String> fulltext, Map<String,String> orderBy, boolean fetchReferences, int limit, int offset)
Executes a query with the possibility to fetch a subset of the results.DocumentModelList
query(QueryBuilder queryBuilder, boolean fetchReferences)
Executes a query with the possibility to fetch a subset of the results.List<String>
queryIds(QueryBuilder queryBuilder)
Executes a query with the possibility to fetch a subset of the results.boolean
rdnMatchesIdField()
String
toString()
protected List<String>
updateEntryWithoutReferences(DocumentModel docModel)
To be implemented for specific update.-
Methods inherited from class org.nuxeo.ecm.directory.BaseSession
addTenantId, applyQueryLimits, applyQueryLimits, canDeleteMultiTenantEntry, checkDeleteConstraints, checkPermission, computeMultiTenantDirectoryId, createEntry, createEntryModel, createEntryModel, createEntryModel, createEntryModel, createEntryModel, deleteEntry, deleteEntry, getCurrentTenantId, getEntries, getEntry, getEntry, getIdField, getPasswordField, getProjection, getProjection, hasPermission, hasPermission, isMultiTenant, isReadOnly, isReadOnlyEntry, query, query, query, query, setReadAllColumns, setReadOnlyEntry, setReadWriteEntry, toStringList, updateEntry
-
-
-
-
Field Detail
-
MISSING_ID_LOWER_CASE
protected static final String MISSING_ID_LOWER_CASE
- See Also:
- Constant Field Values
-
MISSING_ID_UPPER_CASE
protected static final String MISSING_ID_UPPER_CASE
- See Also:
- Constant Field Values
-
dirContext
protected DirContext dirContext
-
idAttribute
protected final String idAttribute
-
idCase
protected final String idCase
-
searchBaseDn
protected final String searchBaseDn
-
rdnAttribute
protected final String rdnAttribute
-
rdnField
protected final String rdnField
-
passwordHashAlgorithm
protected final String passwordHashAlgorithm
-
-
Constructor Detail
-
LDAPSession
public LDAPSession(LDAPDirectory directory)
-
-
Method Detail
-
getDirectory
public LDAPDirectory getDirectory()
Description copied from class:BaseSession
To be implemented with a more specific return type.- Specified by:
getDirectory
in classBaseSession
-
getContext
public DirContext getContext()
-
createEntryWithoutReferences
protected DocumentModel createEntryWithoutReferences(Map<String,Object> fieldMap)
Description copied from class:BaseSession
To be implemented for specific creation.- Specified by:
createEntryWithoutReferences
in classBaseSession
-
updateEntryWithoutReferences
protected List<String> updateEntryWithoutReferences(DocumentModel docModel)
Description copied from class:BaseSession
To be implemented for specific update.- Specified by:
updateEntryWithoutReferences
in classBaseSession
-
deleteEntryWithoutReferences
public void deleteEntryWithoutReferences(String id)
Description copied from class:BaseSession
To be implemented for specific deletion.- Specified by:
deleteEntryWithoutReferences
in classBaseSession
-
hasEntry
public boolean hasEntry(String id)
Description copied from interface:Session
Returns true if session has an entry with given id.
-
getLdapEntry
protected SearchResult getLdapEntry(String id) throws NamingException
- Throws:
NamingException
-
getLdapEntry
protected SearchResult getLdapEntry(String id, boolean fetchAllAttributes) throws NamingException
- Throws:
NamingException
-
deleteEntry
public void deleteEntry(String id, Map<String,String> map)
Description copied from interface:Session
Deletes a directory entry by id and secondary ids.This is used for hierarchical vocabularies, where the actual unique key is the couple (parent, id).
- Specified by:
deleteEntry
in interfaceSession
- Overrides:
deleteEntry
in classBaseSession
- Parameters:
id
- the id of the entry to delete.map
- a map of secondary key values.
-
getEntryFromSource
public DocumentModel getEntryFromSource(String id, boolean fetchReferences)
- Specified by:
getEntryFromSource
in interfaceEntrySource
- Overrides:
getEntryFromSource
in classBaseSession
-
query
public DocumentModelList query(Map<String,Serializable> filter, Set<String> fulltext, Map<String,String> orderBy, boolean fetchReferences, int limit, int offset)
Description copied from interface:Session
Executes a query with the possibility to fetch a subset of the results. org.nuxeo.ecm.directory.BaseSession provides a default implementation fetching all results to return the subset. Not recommended.limit
- maximum number of results ignored if less than 1offset
- number of rows skipped before starting, will be 0 if less than 0.- See Also:
Session.query(Map, Set, Map, boolean)
-
query
public DocumentModelList query(QueryBuilder queryBuilder, boolean fetchReferences)
Description copied from interface:Session
Executes a query with the possibility to fetch a subset of the results.- Parameters:
queryBuilder
- the query to use, including limit, offset, ordering and countTotalfetchReferences
- boolean stating if references have to be fetched- Returns:
- the list of documents, where the total size may be present if countTotal was true
-
queryIds
public List<String> queryIds(QueryBuilder queryBuilder)
Description copied from interface:Session
Executes a query with the possibility to fetch a subset of the results. Returns the matching ids.- Parameters:
queryBuilder
- the query to use, including limit, offset and ordering- Returns:
- the list of document ids
-
close
public void close()
Description copied from interface:Session
Closes the session and all open result sets obtained from this session.Releases this Connection object's resources immediately instead of waiting for them to be automatically released.
TODO: should this operation auto-commit pending changes?
-
fieldMapToDocumentModel
protected DocumentModel fieldMapToDocumentModel(Map<String,Object> fieldMap)
-
getFieldValue
protected Object getFieldValue(Attribute attribute, String fieldName, String entryId, boolean fetchReferences)
-
ldapResultsToDocumentModels
protected DocumentModelList ldapResultsToDocumentModels(NamingEnumeration<SearchResult> results, boolean fetchReferences) throws NamingException
- Throws:
NamingException
-
ldapResultToDocumentModel
protected DocumentModel ldapResultToDocumentModel(SearchResult result, String entryId, boolean fetchReferences) throws NamingException
- Throws:
NamingException
-
authenticate
public boolean authenticate(String username, String password)
Description copied from interface:Session
Checks that the credentials provided by the UserManager match those registered in the directory. If username is not in the directory, this should return false instead of throrwing an exception.- Returns:
- true is the credentials match those stored in the directory
-
isAuthenticating
public boolean isAuthenticating()
Description copied from interface:Session
Tells whether the directory implementation can be used as an authenticating backend for the UserManager (based on login / password check).- Specified by:
isAuthenticating
in interfaceSession
- Overrides:
isAuthenticating
in classBaseSession
- Returns:
- true is the directory is authentication aware
-
rdnMatchesIdField
public boolean rdnMatchesIdField()
-
getMandatoryAttributes
protected List<String> getMandatoryAttributes(Attribute objectClassesAttribute)
-
createEntry
public DocumentModel createEntry(DocumentModel entry)
Description copied from interface:Session
Creates an entry in a directory.- Specified by:
createEntry
in interfaceSession
- Overrides:
createEntry
in classBaseSession
- Parameters:
entry
- the document model representing the entry to create- Returns:
- The new entry created in the directory
-
-