|
|
@ -21,7 +21,10 @@ import lombok.SneakyThrows; |
|
|
import org.springframework.beans.factory.annotation.Autowired; |
|
|
import org.springframework.beans.factory.annotation.Autowired; |
|
|
import org.springframework.stereotype.Service; |
|
|
import org.springframework.stereotype.Service; |
|
|
import org.thingsboard.common.util.JacksonUtil; |
|
|
import org.thingsboard.common.util.JacksonUtil; |
|
|
import org.thingsboard.common.util.TripleFunction; |
|
|
import org.thingsboard.common.util.ThrowingBiConsumer; |
|
|
|
|
|
import org.thingsboard.common.util.ThrowingBiFunction; |
|
|
|
|
|
import org.thingsboard.common.util.ThrowingTripleConsumer; |
|
|
|
|
|
import org.thingsboard.common.util.ThrowingTripleFunction; |
|
|
import org.thingsboard.server.common.data.AdminSettings; |
|
|
import org.thingsboard.server.common.data.AdminSettings; |
|
|
import org.thingsboard.server.common.data.DataConstants; |
|
|
import org.thingsboard.server.common.data.DataConstants; |
|
|
import org.thingsboard.server.common.data.User; |
|
|
import org.thingsboard.server.common.data.User; |
|
|
@ -32,7 +35,6 @@ import org.thingsboard.server.common.data.id.UserId; |
|
|
import org.thingsboard.server.common.data.kv.BaseAttributeKvEntry; |
|
|
import org.thingsboard.server.common.data.kv.BaseAttributeKvEntry; |
|
|
import org.thingsboard.server.common.data.kv.JsonDataEntry; |
|
|
import org.thingsboard.server.common.data.kv.JsonDataEntry; |
|
|
import org.thingsboard.server.dao.attributes.AttributesService; |
|
|
import org.thingsboard.server.dao.attributes.AttributesService; |
|
|
import org.thingsboard.server.dao.service.ConstraintValidator; |
|
|
|
|
|
import org.thingsboard.server.dao.settings.AdminSettingsService; |
|
|
import org.thingsboard.server.dao.settings.AdminSettingsService; |
|
|
import org.thingsboard.server.dao.user.UserService; |
|
|
import org.thingsboard.server.dao.user.UserService; |
|
|
import org.thingsboard.server.service.security.auth.mfa.config.TwoFactorAuthSettings; |
|
|
import org.thingsboard.server.service.security.auth.mfa.config.TwoFactorAuthSettings; |
|
|
@ -47,8 +49,6 @@ import java.util.EnumMap; |
|
|
import java.util.Map; |
|
|
import java.util.Map; |
|
|
import java.util.Optional; |
|
|
import java.util.Optional; |
|
|
import java.util.concurrent.ExecutionException; |
|
|
import java.util.concurrent.ExecutionException; |
|
|
import java.util.function.BiConsumer; |
|
|
|
|
|
import java.util.function.BiFunction; |
|
|
|
|
|
|
|
|
|
|
|
@Service |
|
|
@Service |
|
|
@RequiredArgsConstructor |
|
|
@RequiredArgsConstructor |
|
|
@ -81,7 +81,7 @@ public class TwoFactorAuthService { |
|
|
} |
|
|
} |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
public <R> R processByTwoFaProvider(TenantId tenantId, TwoFactorAuthProviderType providerType, BiFunction<TwoFactorAuthProvider<TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig>, TwoFactorAuthProviderConfig, R> function) throws ThingsboardException { |
|
|
public <R> R processByTwoFaProvider(TenantId tenantId, TwoFactorAuthProviderType providerType, ThrowingBiFunction<TwoFactorAuthProvider<TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig>, TwoFactorAuthProviderConfig, R> function) throws Exception { |
|
|
TwoFactorAuthProviderConfig providerConfig = getTwoFaProviderConfig(tenantId, providerType) |
|
|
TwoFactorAuthProviderConfig providerConfig = getTwoFaProviderConfig(tenantId, providerType) |
|
|
.orElseThrow(() -> new ThingsboardException("2FA provider is not configured", ThingsboardErrorCode.BAD_REQUEST_PARAMS)); |
|
|
.orElseThrow(() -> new ThingsboardException("2FA provider is not configured", ThingsboardErrorCode.BAD_REQUEST_PARAMS)); |
|
|
TwoFactorAuthProvider<TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig> provider = getTwoFaProvider(providerType) |
|
|
TwoFactorAuthProvider<TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig> provider = getTwoFaProvider(providerType) |
|
|
@ -90,14 +90,14 @@ public class TwoFactorAuthService { |
|
|
return function.apply(provider, providerConfig); |
|
|
return function.apply(provider, providerConfig); |
|
|
} |
|
|
} |
|
|
|
|
|
|
|
|
public void processByTwoFaProvider(TenantId tenantId, TwoFactorAuthProviderType providerType, BiConsumer<TwoFactorAuthProvider<TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig>, TwoFactorAuthProviderConfig> function) throws ThingsboardException { |
|
|
public void processByTwoFaProvider(TenantId tenantId, TwoFactorAuthProviderType providerType, ThrowingBiConsumer<TwoFactorAuthProvider<TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig>, TwoFactorAuthProviderConfig> function) throws Exception { |
|
|
processByTwoFaProvider(tenantId, providerType, (provider, providerConfig) -> { |
|
|
processByTwoFaProvider(tenantId, providerType, (provider, providerConfig) -> { |
|
|
function.accept(provider, providerConfig); |
|
|
function.accept(provider, providerConfig); |
|
|
return null; |
|
|
return null; |
|
|
}); |
|
|
}); |
|
|
} |
|
|
} |
|
|
|
|
|
|
|
|
public <R> R processByTwoFaProvider(TenantId tenantId, UserId userId, TripleFunction<TwoFactorAuthProvider<TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig>, TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig, R> function) throws ThingsboardException { |
|
|
public <R> R processByTwoFaProvider(TenantId tenantId, UserId userId, ThrowingTripleFunction<TwoFactorAuthProvider<TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig>, TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig, R> function) throws Exception { |
|
|
TwoFactorAuthAccountConfig accountConfig = getTwoFaAccountConfig(tenantId, userId) |
|
|
TwoFactorAuthAccountConfig accountConfig = getTwoFaAccountConfig(tenantId, userId) |
|
|
.orElseThrow(() -> new ThingsboardException("2FA is not configured for user", ThingsboardErrorCode.BAD_REQUEST_PARAMS)); |
|
|
.orElseThrow(() -> new ThingsboardException("2FA is not configured for user", ThingsboardErrorCode.BAD_REQUEST_PARAMS)); |
|
|
|
|
|
|
|
|
@ -109,6 +109,13 @@ public class TwoFactorAuthService { |
|
|
return function.apply(provider, providerConfig, accountConfig); |
|
|
return function.apply(provider, providerConfig, accountConfig); |
|
|
} |
|
|
} |
|
|
|
|
|
|
|
|
|
|
|
public void processByTwoFaProvider(TenantId tenantId, UserId userId, ThrowingTripleConsumer<TwoFactorAuthProvider<TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig>, TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig> function) throws Exception { |
|
|
|
|
|
processByTwoFaProvider(tenantId, userId, (provider, providerConfig, accountConfig) -> { |
|
|
|
|
|
function.accept(provider, providerConfig, accountConfig); |
|
|
|
|
|
return null; |
|
|
|
|
|
}); |
|
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
public Optional<TwoFactorAuthAccountConfig> getTwoFaAccountConfig(TenantId tenantId, UserId userId) { |
|
|
public Optional<TwoFactorAuthAccountConfig> getTwoFaAccountConfig(TenantId tenantId, UserId userId) { |
|
|
User user = userService.findUserById(tenantId, userId); |
|
|
User user = userService.findUserById(tenantId, userId); |
|
|
@ -121,7 +128,6 @@ public class TwoFactorAuthService { |
|
|
} |
|
|
} |
|
|
|
|
|
|
|
|
public void saveTwoFaAccountConfig(TenantId tenantId, UserId userId, TwoFactorAuthAccountConfig accountConfig) throws ThingsboardException { |
|
|
public void saveTwoFaAccountConfig(TenantId tenantId, UserId userId, TwoFactorAuthAccountConfig accountConfig) throws ThingsboardException { |
|
|
ConstraintValidator.validateFields(accountConfig); |
|
|
|
|
|
getTwoFaProviderConfig(tenantId, accountConfig.getProviderType()) |
|
|
getTwoFaProviderConfig(tenantId, accountConfig.getProviderType()) |
|
|
.orElseThrow(() -> new ThingsboardException("2FA provider is not configured", ThingsboardErrorCode.BAD_REQUEST_PARAMS)); |
|
|
.orElseThrow(() -> new ThingsboardException("2FA provider is not configured", ThingsboardErrorCode.BAD_REQUEST_PARAMS)); |
|
|
|
|
|
|
|
|
@ -160,7 +166,6 @@ public class TwoFactorAuthService { |
|
|
|
|
|
|
|
|
@SneakyThrows({InterruptedException.class, ExecutionException.class}) |
|
|
@SneakyThrows({InterruptedException.class, ExecutionException.class}) |
|
|
public void saveTwoFaSettings(TenantId tenantId, TwoFactorAuthSettings twoFactorAuthSettings) { |
|
|
public void saveTwoFaSettings(TenantId tenantId, TwoFactorAuthSettings twoFactorAuthSettings) { |
|
|
ConstraintValidator.validateFields(twoFactorAuthSettings); |
|
|
|
|
|
if (tenantId.equals(TenantId.SYS_TENANT_ID)) { |
|
|
if (tenantId.equals(TenantId.SYS_TENANT_ID)) { |
|
|
AdminSettings settings = Optional.ofNullable(adminSettingsService.findAdminSettingsByKey(tenantId, TWO_FACTOR_AUTH_SETTINGS_KEY)) |
|
|
AdminSettings settings = Optional.ofNullable(adminSettingsService.findAdminSettingsByKey(tenantId, TWO_FACTOR_AUTH_SETTINGS_KEY)) |
|
|
.orElseGet(() -> { |
|
|
.orElseGet(() -> { |
|
|
|