All Downloads are FREE. Search and download functionalities are using the official Maven repository.

org.voltdb.InvocationSqlPermissionPolicy Maven / Gradle / Ivy

There is a newer version: 10.1.1
Show newest version
/* This file is part of VoltDB.
 * Copyright (C) 2008-2020 VoltDB Inc.
 *
 * This program is free software: you can redistribute it and/or modify
 * it under the terms of the GNU Affero General Public License as
 * published by the Free Software Foundation, either version 3 of the
 * License, or (at your option) any later version.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU Affero General Public License for more details.
 *
 * You should have received a copy of the GNU Affero General Public License
 * along with VoltDB.  If not, see .
 */

package org.voltdb;

import org.voltcore.logging.Level;
import org.voltcore.logging.VoltLogger;
import org.voltdb.AuthSystem.AuthUser;
import org.voltdb.catalog.Procedure;
import org.voltdb.common.Permission;
import org.voltdb.utils.LogKeys;

public class InvocationSqlPermissionPolicy extends InvocationPermissionPolicy {
    private static final VoltLogger authLog = new VoltLogger("AUTH");

    public InvocationSqlPermissionPolicy() {
    }

    /**
     *
     * @see org.voltdb.InvocationAcceptancePolicy#shouldAccept(org.voltdb.AuthSystem.AuthUser,
     *      org.voltdb.StoredProcedureInvocation, org.voltdb.catalog.Procedure,
     *      org.voltcore.network.WriteStream)
     */
    @Override
    public PolicyResult shouldAccept(AuthUser user, StoredProcedureInvocation invocation, Procedure proc) {
        if (proc.getSystemproc() && invocation.getProcName().startsWith("@AdHoc_RW")) {
            if (user.hasPermission(Permission.SQL)) {
                return PolicyResult.ALLOW;
            }
            return PolicyResult.DENY;
        }
        if (proc.getSystemproc() && invocation.getProcName().startsWith("@AdHoc")) {
            if (user.hasPermission(Permission.SQLREAD)) {
                return PolicyResult.ALLOW;
            }
            return PolicyResult.DENY;
        }

        return PolicyResult.NOT_APPLICABLE;
    }

    @Override
    public ClientResponseImpl getErrorResponse(AuthUser user, StoredProcedureInvocation invocation, Procedure procedure) {
        authLog.l7dlog(Level.INFO,
                LogKeys.auth_ClientInterface_LackingPermissionForSql.name(),
                new String[] {user.m_name}, null);
        return new ClientResponseImpl(ClientResponseImpl.UNEXPECTED_FAILURE,
                new VoltTable[0], "User does not have SQL read/write permission",
                invocation.clientHandle);
    }
}




© 2015 - 2024 Weber Informatics LLC | Privacy Policy