// $Id$
/**
* Copyright (C) 2007 EDIT
-* European Distributed Institute of Taxonomy
+* European Distributed Institute of Taxonomy
* http://www.e-taxonomy.eu
-*
+*
* The contents of this file are subject to the Mozilla Public License Version 1.1
* See LICENSE.TXT at the top of this package for the full license terms.
*/
import org.springframework.security.core.GrantedAuthority;
import org.springframework.security.core.context.SecurityContextHolder;
+import eu.etaxonomy.cdm.api.application.CdmApplicationState;
import eu.etaxonomy.cdm.api.conversation.ConversationHolder;
import eu.etaxonomy.cdm.api.conversation.IConversationEnabled;
import eu.etaxonomy.cdm.model.common.Group;
import eu.etaxonomy.cdm.model.common.User;
import eu.etaxonomy.cdm.persistence.hibernate.CdmDataChangeMap;
-import eu.etaxonomy.cdm.persistence.hibernate.permission.CdmAuthority;
+import eu.etaxonomy.taxeditor.model.AbstractUtility;
import eu.etaxonomy.taxeditor.model.IContextListener;
+import eu.etaxonomy.taxeditor.model.MessagingUtils;
/**
* <p>LoginManager class.</p>
* @version 1.0
*/
public class LoginManager extends Observable implements IConversationEnabled, IContextListener{
-
+
public static final Logger logger = Logger.getLogger(LoginManager.class);
-
+
private ConversationHolder conversation;
-
+
public LoginManager(){
CdmStore.getContextManager().addContextListener(this);
}
-
+
/**
* <p>authenticate</p>
*
* @param token a {@link org.springframework.security.authentication.UsernamePasswordAuthenticationToken} object.
+ * @return true if the login attempt was successful even if the authentication has changed or not
*/
public boolean authenticate(String username, String password){
- // close all open editors
- if(!StoreUtil.closeAll()){
- return false;
- }
-
-
- try{
- getConversationHolder().bind();
- getConversationHolder().commit();
-
- SecurityContextHolder.clearContext();
-
- UsernamePasswordAuthenticationToken token = new UsernamePasswordAuthenticationToken(username, password);
- Authentication authentication = CdmStore.getAuthenticationManager().authenticate(token);
-
- if(logger.isDebugEnabled()){
- User user = (User) authentication.getPrincipal();
- StringBuilder gaText = new StringBuilder();
- String indent = " ";
- Set<GrantedAuthority> gaSet = user.getGrantedAuthorities();
- _logGrantedAuthotities(gaText, indent, gaSet);
- for(Group gr : user.getGroups()){
- gaText.append(indent).append("gr[").append(gr.hashCode()).append("] ").append(gr.getName()).append(gr.toString()).append("\n");
- _logGrantedAuthotities(gaText, indent + indent, gr.getGrantedAuthorities());
- }
- logger.debug("User authenticated: " + user.getUsername() + "\n" + gaText.toString());
- }
-
- SecurityContextHolder.getContext().setAuthentication(authentication);
-
- this.setChanged();
- this.notifyObservers();
- return true;
- }
- catch(BadCredentialsException e){
- StoreUtil.warningDialog("Could not authenticate", this, "Could not authenticate. Reason: Bad Credentials.");
- }
- catch(LockedException e){
- StoreUtil.warningDialog("Could not authenticate", this, "Could not authenticate. Reason: Account is locked.");
- }
- catch(IllegalArgumentException e){
- StoreUtil.warningDialog("Could not authenticate", this, "Could not authenticate. Reason: Username and/or Password empty.");
- }
- return false;
+ // close all open editors
+ if(!AbstractUtility.closeAll()){
+ return false;
+ }
+
+
+ try{
+ doAuthenticate(username, password);
+ } catch (CdmAuthenticationException e) {
+ MessagingUtils.warningDialog("Could not authenticate", this, e.getMessage());
+ }
+ return true;
+ }
+
+ public void doAuthenticate(String username, String password) throws CdmAuthenticationException {
+ try {
+ SecurityContextHolder.clearContext();
+ Authentication lastAuthentication = CdmStore.getCurrentAuthentiation();
+
+ UsernamePasswordAuthenticationToken token = new UsernamePasswordAuthenticationToken(username, password);
+ Authentication authentication = CdmStore.getAuthenticationManager().authenticate(token);
+
+ User user = (User) authentication.getPrincipal();
+ /* circumventing problem with hibernate not refreshing the transient collection authorities in this case,
+ * see http://dev.e-taxonomy.eu/trac/ticket/4053 */
+ user.initAuthorities();
+
+ if(logger.isDebugEnabled()){
+ StringBuilder gaText = new StringBuilder();
+ String indent = " ";
+ Set<GrantedAuthority> gaSet = user.getGrantedAuthorities();
+ _logGrantedAuthotities(gaText, indent, gaSet);
+ for(Group gr : user.getGroups()){
+ gaText.append(indent).append("gr[").append(gr.hashCode()).append("] \"").append(gr.getName()).append("\" ").append(gr.toString()).append("\n");
+ _logGrantedAuthotities(gaText, indent + indent, gr.getGrantedAuthorities());
+ }
+ logger.debug("User authenticated: " + user.getUsername() + "\n" + gaText.toString());
+ }
+
+ authentication = new UsernamePasswordAuthenticationToken(user,password, authentication.getAuthorities());
+ SecurityContextHolder.getContext().setAuthentication(authentication);
+ CdmApplicationState.setCurrentSecurityContext(SecurityContextHolder.getContext());
+
+ if(!authentication.equals(lastAuthentication)){
+ this.setChanged();
+ this.notifyObservers();
+ }
+ } catch(BadCredentialsException e){
+ throw new CdmAuthenticationException("Login and/or Password incorrect", e);
+ } catch(LockedException e){
+ throw new CdmAuthenticationException("Account is locked", e);
+ } catch(IllegalArgumentException e){
+ throw new CdmAuthenticationException("Login and/or Password empty", e);
+ }
+
}
private void _logGrantedAuthotities(StringBuilder gaText, String indent,
gaText.append(indent).append("ga[").append(ga.hashCode()).append("] ").append(ga.toString()).append("\n");
}
}
-
+
/**
* <p>getAuthenticatedUser</p>
*
* @return a {@link eu.etaxonomy.cdm.model.common.User} object.
*/
public User getAuthenticatedUser(){
- Authentication authentication = SecurityContextHolder.getContext().getAuthentication();
-
- if(authentication != null
- && authentication.getPrincipal() != null
+ Authentication authentication = SecurityContextHolder.getContext().getAuthentication();
+
+ if(authentication != null
+ && authentication.getPrincipal() != null
&& authentication.getPrincipal() instanceof User){
return (User)authentication.getPrincipal();
}
return null;
}
-
+
public void logoutAll(){
SecurityContextHolder.clearContext();
- notifyObservers();
+ notifyObservers();
}
/* (non-Javadoc)
/**
* Whether the current user has the role admin
- *
+ *
* @return
*/
public boolean isAdmin() {
// FIXME until we have rights implemented properly we do this
- // by a simple string check. This has to change
-
+ // by a simple string check. This has to change
+
return "admin".equals(getAuthenticatedUser().getUsername());
}
@Override
public void contextAboutToStop(IMemento memento, IProgressMonitor monitor) {
-
+
}
@Override
public void contextStop(IMemento memento, IProgressMonitor monitor) {
-
+
}
@Override
@Override
public void workbenchShutdown(IMemento memento, IProgressMonitor monitor) {
-
+
}
}