@ -33,9 +33,7 @@ import org.springframework.web.bind.annotation.PutMapping;
import org.springframework.web.bind.annotation.RequestBody ;
import org.springframework.web.bind.annotation.RequestHeader ;
import org.springframework.web.bind.annotation.RequestMapping ;
import org.springframework.web.bind.annotation.RequestMethod ;
import org.springframework.web.bind.annotation.RequestParam ;
import org.springframework.web.bind.annotation.ResponseBody ;
import org.springframework.web.bind.annotation.ResponseStatus ;
import org.springframework.web.bind.annotation.RestController ;
import org.thingsboard.common.util.JacksonUtil ;
@ -133,8 +131,7 @@ public class UserController extends BaseController {
"If the user has the authority of 'TENANT_ADMIN', the server checks that the requested user is owned by the same tenant. " +
"If the user has the authority of 'CUSTOMER_USER', the server checks that the requested user is owned by the same customer." )
@PreAuthorize ( "hasAnyAuthority('SYS_ADMIN', 'TENANT_ADMIN', 'CUSTOMER_USER')" )
@RequestMapping ( value = "/user/{userId}" , method = RequestMethod . GET )
@ResponseBody
@GetMapping ( value = "/user/{userId}" )
public User getUserById (
@Parameter ( description = USER_ID_PARAM_DESCRIPTION )
@PathVariable ( USER_ID ) String strUserId ) throws ThingsboardException {
@ -150,8 +147,7 @@ public class UserController extends BaseController {
"If the user who performs the request has the authority of 'SYS_ADMIN', it is possible to login as any tenant administrator. " +
"If the user who performs the request has the authority of 'TENANT_ADMIN', it is possible to login as any customer user. " )
@PreAuthorize ( "hasAnyAuthority('SYS_ADMIN', 'TENANT_ADMIN')" )
@RequestMapping ( value = "/user/tokenAccessEnabled" , method = RequestMethod . GET )
@ResponseBody
@GetMapping ( value = "/user/tokenAccessEnabled" )
public boolean isUserTokenAccessEnabled ( ) {
return userTokenAccessEnabled ;
}
@ -161,8 +157,7 @@ public class UserController extends BaseController {
"If the user who performs the request has the authority of 'SYS_ADMIN', it is possible to get the token of any tenant administrator. " +
"If the user who performs the request has the authority of 'TENANT_ADMIN', it is possible to get the token of any customer user that belongs to the same tenant. " )
@PreAuthorize ( "hasAnyAuthority('SYS_ADMIN', 'TENANT_ADMIN')" )
@RequestMapping ( value = "/user/{userId}/token" , method = RequestMethod . GET )
@ResponseBody
@GetMapping ( value = "/user/{userId}/token" )
public JwtPair getUserToken (
@Parameter ( description = USER_ID_PARAM_DESCRIPTION )
@PathVariable ( USER_ID ) String strUserId ) throws ThingsboardException {
@ -189,8 +184,7 @@ public class UserController extends BaseController {
"Remove 'id', 'tenantId' and optionally 'customerId' from the request body example (below) to create new User entity." +
"\n\nAvailable for users with 'SYS_ADMIN', 'TENANT_ADMIN' or 'CUSTOMER_USER' authority." )
@PreAuthorize ( "hasAnyAuthority('SYS_ADMIN', 'TENANT_ADMIN', 'CUSTOMER_USER')" )
@RequestMapping ( value = "/user" , method = RequestMethod . POST )
@ResponseBody
@PostMapping ( value = "/user" )
public User saveUser (
@Parameter ( description = "A JSON value representing the User." , required = true )
@RequestBody User user ,
@ -206,7 +200,7 @@ public class UserController extends BaseController {
@ApiOperation ( value = "Send or re-send the activation email" ,
notes = "Force send the activation email to the user. Useful to resend the email if user has accidentally deleted it. " + SYSTEM_OR_TENANT_AUTHORITY_PARAGRAPH )
@PreAuthorize ( "hasAnyAuthority('SYS_ADMIN', 'TENANT_ADMIN')" )
@Reque stMapping ( value = "/user/sendActivationMail" , method = RequestMethod . POST )
@Po stMapping ( value = "/user/sendActivationMail" )
@ResponseStatus ( value = HttpStatus . OK )
public void sendActivationEmail (
@Parameter ( description = "Email of the user" , required = true )
@ -229,7 +223,6 @@ public class UserController extends BaseController {
"The base url for activation link is configurable in the general settings of system administrator. " + SYSTEM_OR_TENANT_AUTHORITY_PARAGRAPH )
@PreAuthorize ( "hasAnyAuthority('SYS_ADMIN', 'TENANT_ADMIN')" )
@GetMapping ( value = "/user/{userId}/activationLink" , produces = "text/plain" )
@ResponseBody
public String getActivationLink ( @Parameter ( description = USER_ID_PARAM_DESCRIPTION )
@PathVariable ( USER_ID ) String strUserId ,
HttpServletRequest request ) throws ThingsboardException {
@ -255,7 +248,7 @@ public class UserController extends BaseController {
notes = "Deletes the User, it's credentials and all the relations (from and to the User). " +
"Referencing non-existing User Id will cause an error. " + SYSTEM_OR_TENANT_AUTHORITY_PARAGRAPH )
@PreAuthorize ( "hasAnyAuthority('SYS_ADMIN', 'TENANT_ADMIN')" )
@Request Mapping ( value = "/user/{userId}" , method = RequestMethod . DELETE )
@Delete Mapping ( value = "/user/{userId}" )
@ResponseStatus ( value = HttpStatus . OK )
public void deleteUser (
@Parameter ( description = USER_ID_PARAM_DESCRIPTION )
@ -276,8 +269,7 @@ public class UserController extends BaseController {
notes = "Returns a page of users owned by tenant or customer. The scope depends on authority of the user that performs the request." +
PAGE_DATA_PARAMETERS + TENANT_OR_CUSTOMER_AUTHORITY_PARAGRAPH )
@PreAuthorize ( "hasAnyAuthority('TENANT_ADMIN', 'CUSTOMER_USER')" )
@RequestMapping ( value = "/users" , params = { "pageSize" , "page" } , method = RequestMethod . GET )
@ResponseBody
@GetMapping ( value = "/users" , params = { "pageSize" , "page" } )
public PageData < User > getUsers (
@Parameter ( description = PAGE_SIZE_DESCRIPTION , required = true )
@RequestParam int pageSize ,
@ -302,8 +294,7 @@ public class UserController extends BaseController {
notes = "Returns page of user data objects. Search is been executed by email, firstName and " +
"lastName fields. " + PAGE_DATA_PARAMETERS + TENANT_OR_CUSTOMER_AUTHORITY_PARAGRAPH )
@PreAuthorize ( "hasAnyAuthority('TENANT_ADMIN', 'CUSTOMER_USER')" )
@RequestMapping ( value = "/users/info" , method = RequestMethod . GET )
@ResponseBody
@GetMapping ( value = "/users/info" )
public PageData < UserEmailInfo > findUsersByQuery (
@Parameter ( description = PAGE_SIZE_DESCRIPTION , required = true )
@RequestParam int pageSize ,
@ -339,8 +330,7 @@ public class UserController extends BaseController {
@ApiOperation ( value = "Get Tenant Users (getTenantAdmins)" ,
notes = "Returns a page of users owned by tenant. " + PAGE_DATA_PARAMETERS + SYSTEM_AUTHORITY_PARAGRAPH )
@PreAuthorize ( "hasAuthority('SYS_ADMIN')" )
@RequestMapping ( value = "/tenant/{tenantId}/users" , params = { "pageSize" , "page" } , method = RequestMethod . GET )
@ResponseBody
@GetMapping ( value = "/tenant/{tenantId}/users" , params = { "pageSize" , "page" } )
public PageData < User > getTenantAdmins (
@Parameter ( description = TENANT_ID_PARAM_DESCRIPTION , required = true )
@PathVariable ( TENANT_ID ) String strTenantId ,
@ -363,8 +353,7 @@ public class UserController extends BaseController {
@ApiOperation ( value = "Get Customer Users (getCustomerUsers)" ,
notes = "Returns a page of users owned by customer. " + PAGE_DATA_PARAMETERS + TENANT_AUTHORITY_PARAGRAPH )
@PreAuthorize ( "hasAuthority('TENANT_ADMIN')" )
@RequestMapping ( value = "/customer/{customerId}/users" , params = { "pageSize" , "page" } , method = RequestMethod . GET )
@ResponseBody
@GetMapping ( value = "/customer/{customerId}/users" , params = { "pageSize" , "page" } )
public PageData < User > getCustomerUsers (
@Parameter ( description = CUSTOMER_ID_PARAM_DESCRIPTION , required = true )
@PathVariable ( CUSTOMER_ID ) String strCustomerId ,
@ -389,8 +378,7 @@ public class UserController extends BaseController {
@ApiOperation ( value = "Enable/Disable User credentials (setUserCredentialsEnabled)" ,
notes = "Enables or Disables user credentials. Useful when you would like to block user account without deleting it. " + PAGE_DATA_PARAMETERS + TENANT_AUTHORITY_PARAGRAPH )
@PreAuthorize ( "hasAnyAuthority('SYS_ADMIN', 'TENANT_ADMIN')" )
@RequestMapping ( value = "/user/{userId}/userCredentialsEnabled" , method = RequestMethod . POST )
@ResponseBody
@PostMapping ( value = "/user/{userId}/userCredentialsEnabled" )
public void setUserCredentialsEnabled (
@Parameter ( description = USER_ID_PARAM_DESCRIPTION )
@PathVariable ( USER_ID ) String strUserId ,
@ -398,7 +386,7 @@ public class UserController extends BaseController {
@RequestParam ( required = false , defaultValue = "true" ) boolean userCredentialsEnabled ) throws ThingsboardException {
checkParameter ( USER_ID , strUserId ) ;
UserId userId = new UserId ( toUUID ( strUserId ) ) ;
User user = checkUserId ( userId , Operation . WRITE ) ;
checkUserId ( userId , Operation . WRITE ) ;
TenantId tenantId = getCurrentUser ( ) . getTenantId ( ) ;
userService . setUserCredentialsEnabled ( tenantId , userId , userCredentialsEnabled ) ;
@ -412,8 +400,7 @@ public class UserController extends BaseController {
"Search is been executed by email, firstName and lastName fields. " +
PAGE_DATA_PARAMETERS + TENANT_OR_CUSTOMER_AUTHORITY_PARAGRAPH )
@PreAuthorize ( "hasAnyAuthority('TENANT_ADMIN', 'CUSTOMER_USER')" )
@RequestMapping ( value = "/users/assign/{alarmId}" , params = { "pageSize" , "page" } , method = RequestMethod . GET )
@ResponseBody
@GetMapping ( value = "/users/assign/{alarmId}" , params = { "pageSize" , "page" } )
public PageData < UserEmailInfo > getUsersForAssign (
@Parameter ( description = ALARM_ID_PARAM_DESCRIPTION , required = true )
@PathVariable ( "alarmId" ) String strAlarmId ,
@ -491,7 +478,7 @@ public class UserController extends BaseController {
notes = "Delete user settings by specifying list of json element xpaths. \n " +
"Example: to delete B and C element in { \"A\": {\"B\": 5}, \"C\": 15} send A.B,C in jsonPaths request parameter" )
@PreAuthorize ( "hasAnyAuthority('SYS_ADMIN', 'TENANT_ADMIN', 'CUSTOMER_USER')" )
@Request Mapping ( value = "/user/settings/{paths}" , method = RequestMethod . DELETE )
@Delete Mapping ( value = "/user/settings/{paths}" )
public void deleteUserSettings ( @Parameter ( description = PATHS )
@PathVariable ( PATHS ) String paths ) throws ThingsboardException {
checkParameter ( USER_ID , paths ) ;
@ -531,7 +518,7 @@ public class UserController extends BaseController {
notes = "Delete user settings by specifying list of json element xpaths. \n " +
"Example: to delete B and C element in { \"A\": {\"B\": 5}, \"C\": 15} send A.B,C in jsonPaths request parameter" )
@PreAuthorize ( "hasAnyAuthority('SYS_ADMIN', 'TENANT_ADMIN', 'CUSTOMER_USER')" )
@Request Mapping ( value = "/user/settings/{type}/{paths}" , method = RequestMethod . DELETE )
@Delete Mapping ( value = "/user/settings/{type}/{paths}" )
public void deleteUserSettings ( @Parameter ( description = PATHS )
@PathVariable ( PATHS ) String paths ,
@Parameter ( description = "Settings type, case insensitive, one of: \"general\", \"quick_links\", \"doc_links\" or \"dashboards\"." )
@ -555,8 +542,7 @@ public class UserController extends BaseController {
@ApiOperation ( value = "Report action of User over the dashboard (reportUserDashboardAction)" ,
notes = "Report action of User over the dashboard. " + TENANT_OR_CUSTOMER_AUTHORITY_PARAGRAPH )
@PreAuthorize ( "hasAnyAuthority('TENANT_ADMIN', 'CUSTOMER_USER')" )
@RequestMapping ( value = "/user/dashboards/{dashboardId}/{action}" , method = RequestMethod . GET )
@ResponseBody
@GetMapping ( value = "/user/dashboards/{dashboardId}/{action}" )
public UserDashboardsInfo reportUserDashboardAction (
@Parameter ( description = DASHBOARD_ID_PARAM_DESCRIPTION )
@PathVariable ( DashboardController . DASHBOARD_ID ) String strDashboardId ,