|
|
|
@ -44,6 +44,7 @@ import org.thingsboard.server.common.data.page.TimePageLink; |
|
|
|
import org.thingsboard.server.common.data.plugin.ComponentDescriptor; |
|
|
|
import org.thingsboard.server.common.data.plugin.ComponentType; |
|
|
|
import org.thingsboard.server.common.data.rule.RuleChain; |
|
|
|
import org.thingsboard.server.common.data.rule.RuleNode; |
|
|
|
import org.thingsboard.server.common.data.security.Authority; |
|
|
|
import org.thingsboard.server.common.data.widget.WidgetType; |
|
|
|
import org.thingsboard.server.common.data.widget.WidgetsBundle; |
|
|
|
@ -258,14 +259,9 @@ public abstract class BaseController { |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
void checkTenantId(TenantId tenantId) throws ThingsboardException { |
|
|
|
void checkTenantId(TenantId tenantId, Operation operation) throws ThingsboardException { |
|
|
|
validateId(tenantId, INCORRECT_TENANT_ID + tenantId); |
|
|
|
SecurityUser authUser = getCurrentUser(); |
|
|
|
if (authUser.getAuthority() != Authority.SYS_ADMIN && |
|
|
|
(authUser.getTenantId() == null || !authUser.getTenantId().equals(tenantId))) { |
|
|
|
throw new ThingsboardException(YOU_DON_T_HAVE_PERMISSION_TO_PERFORM_THIS_OPERATION, |
|
|
|
ThingsboardErrorCode.PERMISSION_DENIED); |
|
|
|
} |
|
|
|
accessControlService.checkPermission(getCurrentUser(), tenantId, Resource.TENANT, operation, tenantId); |
|
|
|
} |
|
|
|
|
|
|
|
protected TenantId getTenantId() throws ThingsboardException { |
|
|
|
@ -274,19 +270,11 @@ public abstract class BaseController { |
|
|
|
|
|
|
|
Customer checkCustomerId(CustomerId customerId, Operation operation) throws ThingsboardException { |
|
|
|
try { |
|
|
|
/*SecurityUser authUser = getCurrentUser(); |
|
|
|
if (authUser.getAuthority() == Authority.SYS_ADMIN || |
|
|
|
(authUser.getAuthority() != Authority.TENANT_ADMIN && |
|
|
|
(authUser.getCustomerId() == null || !authUser.getCustomerId().equals(customerId)))) { |
|
|
|
throw new ThingsboardException(YOU_DON_T_HAVE_PERMISSION_TO_PERFORM_THIS_OPERATION, |
|
|
|
ThingsboardErrorCode.PERMISSION_DENIED); |
|
|
|
}*/ |
|
|
|
accessControlService.checkPermission(getCurrentUser(), getCurrentUser().getTenantId(), Resource.CUSTOMER, operation, customerId); |
|
|
|
|
|
|
|
if (customerId != null && !customerId.isNullUid()) { |
|
|
|
Customer customer = customerService.findCustomerById(getTenantId(), customerId); |
|
|
|
checkNotNull(customer); |
|
|
|
//checkCustomer(customer);
|
|
|
|
accessControlService.checkPermission(getCurrentUser(), Resource.CUSTOMER, operation, customerId, customer); |
|
|
|
return customer; |
|
|
|
} else { |
|
|
|
@ -297,59 +285,49 @@ public abstract class BaseController { |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
/*private void checkCustomer(Customer customer) throws ThingsboardException { |
|
|
|
checkNotNull(customer); |
|
|
|
checkTenantId(customer.getTenantId()); |
|
|
|
}*/ |
|
|
|
|
|
|
|
User checkUserId(UserId userId) throws ThingsboardException { |
|
|
|
User checkUserId(UserId userId, Operation operation) throws ThingsboardException { |
|
|
|
try { |
|
|
|
validateId(userId, "Incorrect userId " + userId); |
|
|
|
User user = userService.findUserById(getCurrentUser().getTenantId(), userId); |
|
|
|
checkUser(user); |
|
|
|
checkNotNull(user); |
|
|
|
accessControlService.checkPermission(getCurrentUser(), Resource.USER, operation, userId, user); |
|
|
|
return user; |
|
|
|
} catch (Exception e) { |
|
|
|
throw handleException(e, false); |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
private void checkUser(User user) throws ThingsboardException { |
|
|
|
checkNotNull(user); |
|
|
|
checkTenantId(user.getTenantId()); |
|
|
|
if (user.getAuthority() == Authority.CUSTOMER_USER) { |
|
|
|
checkCustomerId(user.getCustomerId()); |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
protected void checkEntityId(EntityId entityId) throws ThingsboardException { |
|
|
|
protected void checkEntityId(EntityId entityId, Operation operation) throws ThingsboardException { |
|
|
|
try { |
|
|
|
checkNotNull(entityId); |
|
|
|
validateId(entityId.getId(), "Incorrect entityId " + entityId); |
|
|
|
SecurityUser authUser = getCurrentUser(); |
|
|
|
switch (entityId.getEntityType()) { |
|
|
|
case DEVICE: |
|
|
|
checkDevice(deviceService.findDeviceById(authUser.getTenantId(), new DeviceId(entityId.getId()))); |
|
|
|
checkDeviceId(new DeviceId(entityId.getId()), operation); |
|
|
|
return; |
|
|
|
case CUSTOMER: |
|
|
|
checkCustomerId(new CustomerId(entityId.getId())); |
|
|
|
checkCustomerId(new CustomerId(entityId.getId()), operation); |
|
|
|
return; |
|
|
|
case TENANT: |
|
|
|
checkTenantId(new TenantId(entityId.getId())); |
|
|
|
checkTenantId(new TenantId(entityId.getId()), operation); |
|
|
|
return; |
|
|
|
case RULE_CHAIN: |
|
|
|
checkRuleChain(new RuleChainId(entityId.getId())); |
|
|
|
checkRuleChain(new RuleChainId(entityId.getId()), operation); |
|
|
|
return; |
|
|
|
case RULE_NODE: |
|
|
|
checkRuleNode(new RuleNodeId(entityId.getId()), operation); |
|
|
|
return; |
|
|
|
case ASSET: |
|
|
|
checkAsset(assetService.findAssetById(authUser.getTenantId(), new AssetId(entityId.getId()))); |
|
|
|
checkAssetId(new AssetId(entityId.getId()), operation); |
|
|
|
return; |
|
|
|
case DASHBOARD: |
|
|
|
checkDashboardId(new DashboardId(entityId.getId())); |
|
|
|
checkDashboardId(new DashboardId(entityId.getId()), operation); |
|
|
|
return; |
|
|
|
case USER: |
|
|
|
checkUserId(new UserId(entityId.getId())); |
|
|
|
checkUserId(new UserId(entityId.getId()), operation); |
|
|
|
return; |
|
|
|
case ENTITY_VIEW: |
|
|
|
checkEntityViewId(new EntityViewId(entityId.getId())); |
|
|
|
checkEntityViewId(new EntityViewId(entityId.getId()), operation); |
|
|
|
return; |
|
|
|
default: |
|
|
|
throw new IllegalArgumentException("Unsupported entity type: " + entityId.getEntityType()); |
|
|
|
@ -364,7 +342,6 @@ public abstract class BaseController { |
|
|
|
validateId(deviceId, "Incorrect deviceId " + deviceId); |
|
|
|
Device device = deviceService.findDeviceById(getCurrentUser().getTenantId(), deviceId); |
|
|
|
checkNotNull(device); |
|
|
|
// checkDevice(device);
|
|
|
|
accessControlService.checkPermission(getCurrentUser(), Resource.DEVICE, operation, deviceId, device); |
|
|
|
return device; |
|
|
|
} catch (Exception e) { |
|
|
|
@ -372,18 +349,11 @@ public abstract class BaseController { |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
/*protected void checkDevice(Device device) throws ThingsboardException { |
|
|
|
checkNotNull(device); |
|
|
|
checkTenantId(device.getTenantId()); |
|
|
|
checkCustomerId(device.getCustomerId()); |
|
|
|
}*/ |
|
|
|
|
|
|
|
protected EntityView checkEntityViewId(EntityViewId entityViewId, Operation operation) throws ThingsboardException { |
|
|
|
try { |
|
|
|
validateId(entityViewId, "Incorrect entityViewId " + entityViewId); |
|
|
|
EntityView entityView = entityViewService.findEntityViewById(getCurrentUser().getTenantId(), entityViewId); |
|
|
|
checkNotNull(entityView); |
|
|
|
//checkEntityView(entityView);
|
|
|
|
accessControlService.checkPermission(getCurrentUser(), Resource.ENTITY_VIEW, operation, entityViewId, entityView); |
|
|
|
return entityView; |
|
|
|
} catch (Exception e) { |
|
|
|
@ -391,38 +361,24 @@ public abstract class BaseController { |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
/* protected void checkEntityView(EntityView entityView) throws ThingsboardException { |
|
|
|
checkNotNull(entityView); |
|
|
|
checkTenantId(entityView.getTenantId()); |
|
|
|
checkCustomerId(entityView.getCustomerId()); |
|
|
|
}*/ |
|
|
|
|
|
|
|
Asset checkAssetId(AssetId assetId, Operation operation) throws ThingsboardException { |
|
|
|
try { |
|
|
|
validateId(assetId, "Incorrect assetId " + assetId); |
|
|
|
Asset asset = assetService.findAssetById(getCurrentUser().getTenantId(), assetId); |
|
|
|
checkNotNull(asset); |
|
|
|
accessControlService.checkPermission(getCurrentUser(), Resource.ASSET, operation, assetId, asset); |
|
|
|
//checkAsset(asset);
|
|
|
|
return asset; |
|
|
|
} catch (Exception e) { |
|
|
|
throw handleException(e, false); |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
/*protected void checkAsset(Asset asset) throws ThingsboardException { |
|
|
|
checkNotNull(asset); |
|
|
|
checkTenantId(asset.getTenantId()); |
|
|
|
checkCustomerId(asset.getCustomerId()); |
|
|
|
}*/ |
|
|
|
|
|
|
|
Alarm checkAlarmId(AlarmId alarmId, Operation operation) throws ThingsboardException { |
|
|
|
try { |
|
|
|
validateId(alarmId, "Incorrect alarmId " + alarmId); |
|
|
|
Alarm alarm = alarmService.findAlarmByIdAsync(getCurrentUser().getTenantId(), alarmId).get(); |
|
|
|
checkNotNull(alarm); |
|
|
|
accessControlService.checkPermission(getCurrentUser(), Resource.ALARM, operation, alarmId, alarm); |
|
|
|
//checkAlarm(alarm);
|
|
|
|
return alarm; |
|
|
|
} catch (Exception e) { |
|
|
|
throw handleException(e, false); |
|
|
|
@ -435,67 +391,42 @@ public abstract class BaseController { |
|
|
|
AlarmInfo alarmInfo = alarmService.findAlarmInfoByIdAsync(getCurrentUser().getTenantId(), alarmId).get(); |
|
|
|
checkNotNull(alarmInfo); |
|
|
|
accessControlService.checkPermission(getCurrentUser(), Resource.ALARM, operation, alarmId, alarmInfo); |
|
|
|
//checkAlarm(alarmInfo);
|
|
|
|
return alarmInfo; |
|
|
|
} catch (Exception e) { |
|
|
|
throw handleException(e, false); |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
/* protected void checkAlarm(Alarm alarm) throws ThingsboardException { |
|
|
|
checkNotNull(alarm); |
|
|
|
checkTenantId(alarm.getTenantId()); |
|
|
|
}*/ |
|
|
|
|
|
|
|
WidgetsBundle checkWidgetsBundleId(WidgetsBundleId widgetsBundleId, boolean modify) throws ThingsboardException { |
|
|
|
WidgetsBundle checkWidgetsBundleId(WidgetsBundleId widgetsBundleId, Operation operation) throws ThingsboardException { |
|
|
|
try { |
|
|
|
validateId(widgetsBundleId, "Incorrect widgetsBundleId " + widgetsBundleId); |
|
|
|
WidgetsBundle widgetsBundle = widgetsBundleService.findWidgetsBundleById(getCurrentUser().getTenantId(), widgetsBundleId); |
|
|
|
checkWidgetsBundle(widgetsBundle, modify); |
|
|
|
checkNotNull(widgetsBundle); |
|
|
|
accessControlService.checkPermission(getCurrentUser(), Resource.WIDGETS_BUNDLE, operation, widgetsBundleId, widgetsBundle); |
|
|
|
return widgetsBundle; |
|
|
|
} catch (Exception e) { |
|
|
|
throw handleException(e, false); |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
private void checkWidgetsBundle(WidgetsBundle widgetsBundle, boolean modify) throws ThingsboardException { |
|
|
|
checkNotNull(widgetsBundle); |
|
|
|
if (widgetsBundle.getTenantId() != null && !widgetsBundle.getTenantId().getId().equals(ModelConstants.NULL_UUID)) { |
|
|
|
checkTenantId(widgetsBundle.getTenantId()); |
|
|
|
} else if (modify && getCurrentUser().getAuthority() != Authority.SYS_ADMIN) { |
|
|
|
throw new ThingsboardException(YOU_DON_T_HAVE_PERMISSION_TO_PERFORM_THIS_OPERATION, |
|
|
|
ThingsboardErrorCode.PERMISSION_DENIED); |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
WidgetType checkWidgetTypeId(WidgetTypeId widgetTypeId, boolean modify) throws ThingsboardException { |
|
|
|
WidgetType checkWidgetTypeId(WidgetTypeId widgetTypeId, Operation operation) throws ThingsboardException { |
|
|
|
try { |
|
|
|
validateId(widgetTypeId, "Incorrect widgetTypeId " + widgetTypeId); |
|
|
|
WidgetType widgetType = widgetTypeService.findWidgetTypeById(getCurrentUser().getTenantId(), widgetTypeId); |
|
|
|
checkWidgetType(widgetType, modify); |
|
|
|
checkNotNull(widgetType); |
|
|
|
accessControlService.checkPermission(getCurrentUser(), Resource.WIDGET_TYPE, operation, widgetTypeId, widgetType); |
|
|
|
return widgetType; |
|
|
|
} catch (Exception e) { |
|
|
|
throw handleException(e, false); |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
void checkWidgetType(WidgetType widgetType, boolean modify) throws ThingsboardException { |
|
|
|
checkNotNull(widgetType); |
|
|
|
if (widgetType.getTenantId() != null && !widgetType.getTenantId().getId().equals(ModelConstants.NULL_UUID)) { |
|
|
|
checkTenantId(widgetType.getTenantId()); |
|
|
|
} else if (modify && getCurrentUser().getAuthority() != Authority.SYS_ADMIN) { |
|
|
|
throw new ThingsboardException(YOU_DON_T_HAVE_PERMISSION_TO_PERFORM_THIS_OPERATION, |
|
|
|
ThingsboardErrorCode.PERMISSION_DENIED); |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
Dashboard checkDashboardId(DashboardId dashboardId, Operation operation) throws ThingsboardException { |
|
|
|
try { |
|
|
|
validateId(dashboardId, "Incorrect dashboardId " + dashboardId); |
|
|
|
Dashboard dashboard = dashboardService.findDashboardById(getCurrentUser().getTenantId(), dashboardId); |
|
|
|
checkNotNull(dashboard); |
|
|
|
accessControlService.checkPermission(getCurrentUser(), Resource.DASHBOARD, operation, dashboardId, dashboard); |
|
|
|
//checkDashboard(dashboard);
|
|
|
|
return dashboard; |
|
|
|
} catch (Exception e) { |
|
|
|
throw handleException(e, false); |
|
|
|
@ -508,25 +439,12 @@ public abstract class BaseController { |
|
|
|
DashboardInfo dashboardInfo = dashboardService.findDashboardInfoById(getCurrentUser().getTenantId(), dashboardId); |
|
|
|
checkNotNull(dashboardInfo); |
|
|
|
accessControlService.checkPermission(getCurrentUser(), Resource.DASHBOARD, operation, dashboardId, dashboardInfo); |
|
|
|
//checkDashboard(dashboardInfo);
|
|
|
|
return dashboardInfo; |
|
|
|
} catch (Exception e) { |
|
|
|
throw handleException(e, false); |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
/*private void checkDashboard(DashboardInfo dashboard) throws ThingsboardException { |
|
|
|
checkNotNull(dashboard); |
|
|
|
checkTenantId(dashboard.getTenantId()); |
|
|
|
SecurityUser authUser = getCurrentUser(); |
|
|
|
if (authUser.getAuthority() == Authority.CUSTOMER_USER) { |
|
|
|
if (!dashboard.isAssignedToCustomer(authUser.getCustomerId())) { |
|
|
|
throw new ThingsboardException(YOU_DON_T_HAVE_PERMISSION_TO_PERFORM_THIS_OPERATION, |
|
|
|
ThingsboardErrorCode.PERMISSION_DENIED); |
|
|
|
} |
|
|
|
} |
|
|
|
}*/ |
|
|
|
|
|
|
|
ComponentDescriptor checkComponentDescriptorByClazz(String clazz) throws ThingsboardException { |
|
|
|
try { |
|
|
|
log.debug("[{}] Lookup component descriptor", clazz); |
|
|
|
@ -554,24 +472,22 @@ public abstract class BaseController { |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
protected RuleChain checkRuleChain(RuleChainId ruleChainId) throws ThingsboardException { |
|
|
|
checkNotNull(ruleChainId); |
|
|
|
return checkRuleChain(ruleChainService.findRuleChainById(getCurrentUser().getTenantId(), ruleChainId)); |
|
|
|
} |
|
|
|
|
|
|
|
protected RuleChain checkRuleChain(RuleChain ruleChain) throws ThingsboardException { |
|
|
|
protected RuleChain checkRuleChain(RuleChainId ruleChainId, Operation operation) throws ThingsboardException { |
|
|
|
validateId(ruleChainId, "Incorrect ruleChainId " + ruleChainId); |
|
|
|
RuleChain ruleChain = ruleChainService.findRuleChainById(getCurrentUser().getTenantId(), ruleChainId); |
|
|
|
checkNotNull(ruleChain); |
|
|
|
SecurityUser authUser = getCurrentUser(); |
|
|
|
TenantId tenantId = ruleChain.getTenantId(); |
|
|
|
validateId(tenantId, INCORRECT_TENANT_ID + tenantId); |
|
|
|
if (authUser.getAuthority() != Authority.TENANT_ADMIN || |
|
|
|
!authUser.getTenantId().equals(tenantId)) { |
|
|
|
throw new ThingsboardException(YOU_DON_T_HAVE_PERMISSION_TO_PERFORM_THIS_OPERATION, |
|
|
|
ThingsboardErrorCode.PERMISSION_DENIED); |
|
|
|
} |
|
|
|
accessControlService.checkPermission(getCurrentUser(), Resource.RULE_CHAIN, operation, ruleChainId, ruleChain); |
|
|
|
return ruleChain; |
|
|
|
} |
|
|
|
|
|
|
|
protected RuleNode checkRuleNode(RuleNodeId ruleNodeId, Operation operation) throws ThingsboardException { |
|
|
|
validateId(ruleNodeId, "Incorrect ruleNodeId " + ruleNodeId); |
|
|
|
RuleNode ruleNode = ruleChainService.findRuleNodeById(getTenantId(), ruleNodeId); |
|
|
|
checkNotNull(ruleNode); |
|
|
|
checkRuleChain(ruleNode.getRuleChainId(), operation); |
|
|
|
return ruleNode; |
|
|
|
} |
|
|
|
|
|
|
|
|
|
|
|
protected String constructBaseUrl(HttpServletRequest request) { |
|
|
|
String scheme = request.getScheme(); |
|
|
|
|