Package org.ametys.core.right
Interface ProfileAssignmentStorage
-
- All Superinterfaces:
Prioritizable
- All Known Subinterfaces:
ModifiableProfileAssignmentStorage
- All Known Implementing Classes:
ACLAmetysObjectProfileAssignmentStorage
,JdbcProfileAssignmentStorage
,ModifiableACLAmetysObjectProfileAssignmentStorage
public interface ProfileAssignmentStorage extends Prioritizable
This interface is for read-only profile assignments storage
-
-
Nested Class Summary
Nested Classes Modifier and Type Interface Description static class
ProfileAssignmentStorage.AnonymousOrAnyConnectedKeys
Keys for method that can return profiles of anonymous or any connected userstatic class
ProfileAssignmentStorage.UserOrGroup
Keys for method that can return profiles of user or groups
-
Field Summary
Fields Modifier and Type Field Description static int
MAX_PRIORITY
Maximum priority.static int
MIN_PRIORITY
Minimum priority.
-
Method Summary
All Methods Instance Methods Abstract Methods Modifier and Type Method Description Map<ProfileAssignmentStorage.AnonymousOrAnyConnectedKeys,Set<String>>
getProfilesForAnonymousAndAnyConnectedUser(Object object)
Gets the allowed profiles any connected user has on the given objectMap<GroupIdentity,Map<ProfileAssignmentStorage.UserOrGroup,Set<String>>>
getProfilesForGroups(Object object, Set<GroupIdentity> groups)
Gets the groups that have allowed profiles assigned on the given objectMap<UserIdentity,Map<ProfileAssignmentStorage.UserOrGroup,Set<String>>>
getProfilesForUsers(Object object, UserIdentity user)
Gets the users that have allowed profiles assigned on the given objectSet<String>
hasAnonymousAnyAllowedProfile(Set<? extends Object> rootContexts, Set<String> profileIds)
Returns some profiles that are matching if anonymous user has the allowed profile for any given root context (or any sub context), given some profiles.
Only supported objects are transmittedSet<String>
hasAnyConnectedAnyAllowedProfile(Set<? extends Object> rootContexts, Set<String> profileIds)
Returns some profiles that are matching if any connected user has the allowed profile for any given root context (or any sub context), given some profiles.
Only supported objects are transmittedSet<String>
hasGroupAnyAllowedProfile(Set<? extends Object> rootContexts, Set<GroupIdentity> groups, Set<String> profileIds)
Returns some profiles that are matching if group has the allowed profile for any given root context (or any sub context), given some profiles.
Only supported objects are transmittedSet<String>
hasUserAnyAllowedProfile(Set<? extends Object> rootContexts, UserIdentity user, Set<String> profileIds)
Returns some profiles that are matching if user has the allowed profile for any given root context (or any sub context), given some profiles.
Only supported objects are transmittedboolean
isInheritanceDisallowed(Object object)
Returns true if the inheritance of permissions is disallowed on the given objectboolean
isRootContextSupported(Object rootContext)
Returns true if this profile storage supports the given object as a root context i.e.boolean
isSupported(Object object)
Returns true if this profile storage supports the given object, i.e.-
Methods inherited from interface org.ametys.runtime.plugin.component.Prioritizable
getPriority
-
-
-
-
Field Detail
-
MIN_PRIORITY
static final int MIN_PRIORITY
Minimum priority.- See Also:
- Constant Field Values
-
MAX_PRIORITY
static final int MAX_PRIORITY
Maximum priority.- See Also:
- Constant Field Values
-
-
Method Detail
-
hasAnonymousAnyAllowedProfile
Set<String> hasAnonymousAnyAllowedProfile(Set<? extends Object> rootContexts, Set<String> profileIds)
Returns some profiles that are matching if anonymous user has the allowed profile for any given root context (or any sub context), given some profiles.
Only supported objects are transmitted- Parameters:
rootContexts
- The root contexts to search rights forprofileIds
- The ids of the profiles- Returns:
- If the Set is empty, it means anonymous has no matching profile.
If the Set is non empty, it contains at least one of the given profile BUT it may not contains all the matching profiles for anonymous AND it can contains some other profiles that were not in the given profiles
-
hasAnyConnectedAnyAllowedProfile
Set<String> hasAnyConnectedAnyAllowedProfile(Set<? extends Object> rootContexts, Set<String> profileIds)
Returns some profiles that are matching if any connected user has the allowed profile for any given root context (or any sub context), given some profiles.
Only supported objects are transmitted- Parameters:
rootContexts
- The root contexts to search rights forprofileIds
- The ids of the profiles- Returns:
- If the Set is empty, it means the user has no matching profile.
If the Set is non empty, it contains at least one of the given profile BUT it may not contains all the matching profiles for the user AND it can contains some other profiles that were not in the given profiles
-
hasUserAnyAllowedProfile
Set<String> hasUserAnyAllowedProfile(Set<? extends Object> rootContexts, UserIdentity user, Set<String> profileIds)
Returns some profiles that are matching if user has the allowed profile for any given root context (or any sub context), given some profiles.
Only supported objects are transmitted- Parameters:
rootContexts
- The root contexts to search rights foruser
- The user to testprofileIds
- The ids of the profiles- Returns:
- If the Set is empty, it means any connected user has no matching profile.
If the Set is non empty, it contains at least one of the given profile BUT it may not contains all the matching profiles for anyconnected user AND it can contains some other profiles that were not in the given profiles
-
hasGroupAnyAllowedProfile
Set<String> hasGroupAnyAllowedProfile(Set<? extends Object> rootContexts, Set<GroupIdentity> groups, Set<String> profileIds)
Returns some profiles that are matching if group has the allowed profile for any given root context (or any sub context), given some profiles.
Only supported objects are transmitted- Parameters:
rootContexts
- The root contexts to search rights forgroups
- The groups to test (a single group needs to match)profileIds
- The ids of the profiles- Returns:
- If the Set is empty, it means the group has no matching profile.
If the Set is non empty, it contains at least one of the given profile BUT it may not contains all the matching profiles for the group AND it can contains some other profiles that were not in the given profiles
-
getProfilesForAnonymousAndAnyConnectedUser
Map<ProfileAssignmentStorage.AnonymousOrAnyConnectedKeys,Set<String>> getProfilesForAnonymousAndAnyConnectedUser(Object object)
Gets the allowed profiles any connected user has on the given object- Parameters:
object
- The object- Returns:
- a map containing allowed/denied profiles that anonymous and any connected user has on the given object
-
getProfilesForUsers
Map<UserIdentity,Map<ProfileAssignmentStorage.UserOrGroup,Set<String>>> getProfilesForUsers(Object object, UserIdentity user)
Gets the users that have allowed profiles assigned on the given object- Parameters:
object
- The object to testuser
- The user to get profiles for. Can be null to get profiles for all users that have rights- Returns:
- The map of allowed users with their assigned allowed/denied profiles
-
getProfilesForGroups
Map<GroupIdentity,Map<ProfileAssignmentStorage.UserOrGroup,Set<String>>> getProfilesForGroups(Object object, Set<GroupIdentity> groups)
Gets the groups that have allowed profiles assigned on the given object- Parameters:
object
- The object to testgroups
- The group to get profiles for. Can be null to get profiles for all groups that have rights- Returns:
- The map of allowed/denied groups with their assigned profiles
-
isSupported
boolean isSupported(Object object)
Returns true if this profile storage supports the given object, i.e. if it is able to retrieve the allowed users/groups on that object- Parameters:
object
- The object to test- Returns:
- true if this profile storage supports the given object
-
isRootContextSupported
boolean isRootContextSupported(Object rootContext)
Returns true if this profile storage supports the given object as a root context i.e. it can seek any permission under this object- Parameters:
rootContext
- The object to start searching- Returns:
- true if this profile storage support this a as root context to search in
-
isInheritanceDisallowed
boolean isInheritanceDisallowed(Object object)
Returns true if the inheritance of permissions is disallowed on the given object- Parameters:
object
- The object to test- Returns:
- true if the inheritance of permissions is disallowed on the given object
-
-