Browse Source

removed redundant permission checks

pull/14355/head
dashevchenko 10 months ago
parent
commit
1641b6a491
  1. 5
      application/src/main/java/org/thingsboard/server/controller/AssetProfileController.java
  2. 13
      application/src/main/java/org/thingsboard/server/controller/CustomerController.java
  3. 12
      application/src/main/java/org/thingsboard/server/controller/RuleChainController.java
  4. 13
      application/src/main/java/org/thingsboard/server/controller/TenantController.java
  5. 22
      application/src/main/java/org/thingsboard/server/controller/UserController.java
  6. 16
      application/src/main/java/org/thingsboard/server/controller/WidgetsBundleController.java
  7. 14
      application/src/main/java/org/thingsboard/server/service/security/permission/DefaultAccessControlService.java

5
application/src/main/java/org/thingsboard/server/controller/AssetProfileController.java

@ -237,16 +237,13 @@ public class AssetProfileController extends BaseController {
@RequestParam("assetProfileIds") String[] strAssetProfileIds) throws ThingsboardException, ExecutionException, InterruptedException {
checkArrayParameter("assetProfileIds", strAssetProfileIds);
SecurityUser user = getCurrentUser();
if (!accessControlService.hasPermission(user, Resource.ASSET_PROFILE, Operation.READ)) {
return Collections.emptyList();
}
TenantId tenantId = user.getTenantId();
List<AssetProfileId> assetProfileIds = new ArrayList<>();
for (String strAssetProfileId : strAssetProfileIds) {
assetProfileIds.add(new AssetProfileId(toUUID(strAssetProfileId)));
}
return checkNotNull(assetProfileService.findAssetProfilesByIdsAsync(tenantId, assetProfileIds).get());
return assetProfileService.findAssetProfilesByIdsAsync(tenantId, assetProfileIds).get();
}
}

13
application/src/main/java/org/thingsboard/server/controller/CustomerController.java

@ -194,7 +194,7 @@ public class CustomerController extends BaseController {
@ApiOperation(value = "Get customers by Customer Ids (getCustomersByIds)",
notes = "Returns a list of Customer objects based on the provided ids." +
TENANT_OR_CUSTOMER_AUTHORITY_PARAGRAPH)
@PreAuthorize("hasAnyAuthority('TENANT_ADMIN', 'CUSTOMER_USER')")
@PreAuthorize("hasAnyAuthority('TENANT_ADMIN')")
@GetMapping(value = "/customers", params = {"customerIds"})
public List<Customer> getCustomersByIds(
@Parameter(description = "A list of customer ids, separated by comma ','", array = @ArraySchema(schema = @Schema(type = "string")), required = true)
@ -206,16 +206,7 @@ public class CustomerController extends BaseController {
for (String strCustomerId : strCustomerIds) {
customerIds.add(new CustomerId(toUUID(strCustomerId)));
}
return Objects.requireNonNull(checkNotNull(customerService.findCustomersByTenantIdAndIdsAsync(tenantId, customerIds).get()))
.stream()
.filter(e -> {
try {
return accessControlService.hasPermission(user, Resource.CUSTOMER, Operation.READ, e.getId(), e);
} catch (ThingsboardException ex) {
return false;
}
})
.toList();
return customerService.findCustomersByTenantIdAndIdsAsync(tenantId, customerIds).get();
}
}

12
application/src/main/java/org/thingsboard/server/controller/RuleChainController.java

@ -79,7 +79,6 @@ import org.thingsboard.server.service.security.permission.Resource;
import java.util.ArrayList;
import java.util.List;
import java.util.Map;
import java.util.Objects;
import java.util.Optional;
import java.util.Set;
import java.util.concurrent.ConcurrentMap;
@ -598,16 +597,7 @@ public class RuleChainController extends BaseController {
for (String strRuleChainId : strRuleChainIds) {
ruleChainIds.add(new RuleChainId(toUUID(strRuleChainId)));
}
return Objects.requireNonNull(checkNotNull(ruleChainService.findRuleChainsByIdsAsync(tenantId, ruleChainIds).get()))
.stream()
.filter(e -> {
try {
return accessControlService.hasPermission(user, Resource.RULE_CHAIN, Operation.READ, e.getId(), e);
} catch (ThingsboardException ex) {
return false;
}
})
.toList();
return ruleChainService.findRuleChainsByIdsAsync(tenantId, ruleChainIds).get();
}
}

13
application/src/main/java/org/thingsboard/server/controller/TenantController.java

@ -174,7 +174,7 @@ public class TenantController extends BaseController {
return checkNotNull(tenantService.findTenantInfos(pageLink));
}
@PreAuthorize("hasAnyAuthority('SYS_ADMIN', 'TENANT_ADMIN')")
@PreAuthorize("hasAnyAuthority('SYS_ADMIN')")
@GetMapping(value = "/tenants", params = {"tenantIds"})
public List<Tenant> getTenantsByIds(
@Parameter(description = "A list of tenant ids, separated by comma ','", array = @ArraySchema(schema = @Schema(type = "string")))
@ -186,16 +186,7 @@ public class TenantController extends BaseController {
for (String strTenantId : strTenantIds) {
tenantIds.add(new TenantId(toUUID(strTenantId)));
}
return Objects.requireNonNull(checkNotNull(tenantService.findTenantsByIdsAsync(tenantId, tenantIds).get()))
.stream()
.filter(e -> {
try {
return accessControlService.hasPermission(user, Resource.TENANT, Operation.READ, e.getId(), e);
} catch (ThingsboardException ex) {
return false;
}
})
.toList();
return tenantService.findTenantsByIdsAsync(tenantId, tenantIds).get();
}
}

22
application/src/main/java/org/thingsboard/server/controller/UserController.java

@ -611,16 +611,18 @@ public class UserController extends BaseController {
for (String strUserId : strUserIds) {
userIds.add(new UserId(toUUID(strUserId)));
}
return Objects.requireNonNull(checkNotNull(userService.findUsersByTenantIdAndIdsAsync(tenantId, userIds).get()))
.stream()
.filter(e -> {
try {
return accessControlService.hasPermission(user, Resource.USER, Operation.READ, e.getId(), e);
} catch (ThingsboardException ex) {
return false;
}
})
.toList();
List<User> users = checkNotNull(userService.findUsersByTenantIdAndIdsAsync(tenantId, userIds).get());
return filterUsersByReadPermission(users);
}
private List<User> filterUsersByReadPermission(List<User> users) {
return users.stream().filter(user -> {
try {
return accessControlService.hasPermission(getCurrentUser(), Resource.USER, Operation.READ, user.getId(), user);
} catch (ThingsboardException e) {
return false;
}
}).collect(Collectors.toList());
}
private void checkNotReserved(String strType, UserSettingsType type) throws ThingsboardException {

16
application/src/main/java/org/thingsboard/server/controller/WidgetsBundleController.java

@ -253,23 +253,11 @@ public class WidgetsBundleController extends BaseController {
for (String strWidgetsBundleId : strWidgetsBundleIds) {
widgetsBundleIds.add(new WidgetsBundleId(toUUID(strWidgetsBundleId)));
}
List<WidgetsBundle> result;
if (Authority.SYS_ADMIN.equals(getCurrentUser().getAuthority())) {
result = checkNotNull(widgetsBundleService.findSystemWidgetsBundlesByIdsAsync(getTenantId(), widgetsBundleIds).get());
return widgetsBundleService.findSystemWidgetsBundlesByIdsAsync(getTenantId(), widgetsBundleIds).get();
} else {
result = checkNotNull(widgetsBundleService.findAllTenantWidgetsBundlesByIdsAsync(getTenantId(), widgetsBundleIds).get());
return widgetsBundleService.findAllTenantWidgetsBundlesByIdsAsync(getTenantId(), widgetsBundleIds).get();
}
return Objects.requireNonNull(result)
.stream()
.filter(e -> {
try {
return accessControlService.hasPermission(getCurrentUser(), Resource.WIDGETS_BUNDLE, Operation.READ, e.getId(), e);
} catch (ThingsboardException ex) {
return false;
}
})
.toList();
}
}

14
application/src/main/java/org/thingsboard/server/service/security/permission/DefaultAccessControlService.java

@ -58,11 +58,8 @@ public class DefaultAccessControlService implements AccessControlService {
@Override
@SuppressWarnings("unchecked")
public boolean hasPermission(SecurityUser user, Resource resource, Operation operation) throws ThingsboardException {
PermissionChecker permissionChecker = getPermissionChecker(user.getAuthority(), resource);
if (permissionChecker != null) {
return permissionChecker.hasPermission(user, operation);
}
return false;
var permissionChecker = getPermissionChecker(user.getAuthority(), resource);
return permissionChecker.hasPermission(user, operation);
}
@Override
@ -78,11 +75,8 @@ public class DefaultAccessControlService implements AccessControlService {
@Override
@SuppressWarnings("unchecked")
public <I extends EntityId, T extends HasTenantId> boolean hasPermission(SecurityUser user, Resource resource, Operation operation, I entityId, T entity) throws ThingsboardException {
PermissionChecker permissionChecker = getPermissionChecker(user.getAuthority(), resource);
if (permissionChecker != null) {
return permissionChecker.hasPermission(user, operation, entityId, entity);
}
return false;
var permissionChecker = getPermissionChecker(user.getAuthority(), resource);
return permissionChecker.hasPermission(user, operation, entityId, entity);
}
private PermissionChecker getPermissionChecker(Authority authority, Resource resource) throws ThingsboardException {

Loading…
Cancel
Save