11 changed files with 503 additions and 0 deletions
@ -0,0 +1,56 @@ |
|||
-- |
|||
-- Copyright © 2016-2020 The Thingsboard Authors |
|||
-- |
|||
-- Licensed under the Apache License, Version 2.0 (the "License"); |
|||
-- you may not use this file except in compliance with the License. |
|||
-- You may obtain a copy of the License at |
|||
-- |
|||
-- http://www.apache.org/licenses/LICENSE-2.0 |
|||
-- |
|||
-- Unless required by applicable law or agreed to in writing, software |
|||
-- distributed under the License is distributed on an "AS IS" BASIS, |
|||
-- WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
|||
-- See the License for the specific language governing permissions and |
|||
-- limitations under the License. |
|||
-- |
|||
|
|||
DROP TABLE IF EXISTS oauth2_client_registration; |
|||
|
|||
CREATE TABLE IF NOT EXISTS oauth2_client_registration ( |
|||
registration_id varchar(255) NOT NULL CONSTRAINT oauth2_client_registration_pkey PRIMARY KEY, |
|||
mapper_config_id varchar(31), |
|||
client_id varchar(255), |
|||
client_secret varchar(255), |
|||
authorization_uri varchar(255), |
|||
token_uri varchar(255), |
|||
redirect_uri_template varchar(255), |
|||
scope varchar(255), |
|||
authorization_grant_type varchar(255), |
|||
user_info_uri varchar(255), |
|||
user_name_attribute varchar(255), |
|||
jwk_set_uri varchar(255), |
|||
client_authentication_method varchar(255), |
|||
client_name varchar(255), |
|||
login_button_label varchar(255), |
|||
login_button_icon varchar(255) |
|||
); |
|||
|
|||
DROP TABLE IF EXISTS oauth2_mapper_config; |
|||
|
|||
CREATE TABLE IF NOT EXISTS oauth2_mapper_config ( |
|||
id varchar(31) NOT NULL CONSTRAINT oauth2_mapper_config_pkey PRIMARY KEY, |
|||
allow_user_creation boolean, |
|||
activate_user boolean, |
|||
type varchar(31), |
|||
basic_email_attribute_key varchar(31), |
|||
basic_first_name_attribute_key varchar(31), |
|||
basic_last_name_attribute_key varchar(31), |
|||
basic_tenant_name_strategy varchar(31), |
|||
basic_tenant_name_pattern varchar(255), |
|||
basic_customer_name_pattern varchar(255), |
|||
basic_default_dashboard_name varchar(255), |
|||
basic_always_full_screen boolean, |
|||
custom_url varchar(255), |
|||
custom_username varchar(255), |
|||
custom_password varchar(255) |
|||
); |
|||
@ -0,0 +1,5 @@ |
|||
package org.thingsboard.server.common.data.oauth2; |
|||
|
|||
public enum MapperType { |
|||
BASIC, CUSTOM; |
|||
} |
|||
@ -0,0 +1,21 @@ |
|||
package org.thingsboard.server.common.data.oauth2; |
|||
|
|||
import lombok.Builder; |
|||
import lombok.EqualsAndHashCode; |
|||
import lombok.Getter; |
|||
import lombok.ToString; |
|||
|
|||
@Builder(toBuilder = true) |
|||
@EqualsAndHashCode |
|||
@Getter |
|||
@ToString |
|||
public class OAuth2BasicMapperConfig { |
|||
private final String emailAttributeKey; |
|||
private final String firstNameAttributeKey; |
|||
private final String lastNameAttributeKey; |
|||
private final String tenantNameStrategy; |
|||
private final String tenantNamePattern; |
|||
private final String customerNamePattern; |
|||
private final String defaultDashboardName; |
|||
private final boolean alwaysFullScreen; |
|||
} |
|||
@ -0,0 +1,57 @@ |
|||
package org.thingsboard.server.common.data.oauth2; |
|||
|
|||
import lombok.*; |
|||
import org.thingsboard.server.common.data.BaseData; |
|||
import org.thingsboard.server.common.data.id.OAuth2IntegrationId; |
|||
|
|||
@EqualsAndHashCode(callSuper = true) |
|||
@Data |
|||
@ToString(exclude = {"clientSecret"}) |
|||
public class OAuth2ClientRegistration extends BaseData<OAuth2IntegrationId> { |
|||
|
|||
private String registrationId; |
|||
private OAuth2IntegrationId mapperConfigId; |
|||
private String clientId; |
|||
private String clientSecret; |
|||
private String authorizationUri; |
|||
private String tokenUri; |
|||
private String redirectUriTemplate; |
|||
private String scope; |
|||
private String authorizationGrantType; |
|||
private String userInfoUri; |
|||
private String userNameAttribute; |
|||
private String jwkSetUri; |
|||
private String clientAuthenticationMethod; |
|||
private String clientName; |
|||
private String loginButtonLabel; |
|||
private String loginButtonIcon; |
|||
|
|||
public OAuth2ClientRegistration() { |
|||
super(); |
|||
} |
|||
|
|||
public OAuth2ClientRegistration(OAuth2IntegrationId id) { |
|||
super(id); |
|||
} |
|||
|
|||
@Builder(toBuilder = true) |
|||
public OAuth2ClientRegistration(OAuth2IntegrationId id, String registrationId, String clientId, String clientSecret, String authorizationUri, String tokenUri, String redirectUriTemplate, String scope, String authorizationGrantType, String userInfoUri, String userNameAttribute, String jwkSetUri, String clientAuthenticationMethod, String clientName, String loginButtonLabel, String loginButtonIcon, OAuth2IntegrationId mapperConfigId) { |
|||
super(id); |
|||
this.registrationId = registrationId; |
|||
this.clientId = clientId; |
|||
this.clientSecret = clientSecret; |
|||
this.authorizationUri = authorizationUri; |
|||
this.tokenUri = tokenUri; |
|||
this.redirectUriTemplate = redirectUriTemplate; |
|||
this.scope = scope; |
|||
this.authorizationGrantType = authorizationGrantType; |
|||
this.userInfoUri = userInfoUri; |
|||
this.userNameAttribute = userNameAttribute; |
|||
this.jwkSetUri = jwkSetUri; |
|||
this.clientAuthenticationMethod = clientAuthenticationMethod; |
|||
this.clientName = clientName; |
|||
this.loginButtonLabel = loginButtonLabel; |
|||
this.loginButtonIcon = loginButtonIcon; |
|||
this.mapperConfigId = mapperConfigId; |
|||
} |
|||
} |
|||
@ -0,0 +1,16 @@ |
|||
package org.thingsboard.server.common.data.oauth2; |
|||
|
|||
import lombok.Builder; |
|||
import lombok.EqualsAndHashCode; |
|||
import lombok.Getter; |
|||
import lombok.ToString; |
|||
|
|||
@Builder(toBuilder = true) |
|||
@EqualsAndHashCode |
|||
@Getter |
|||
@ToString(exclude = {"password"}) |
|||
public class OAuth2CustomMapperConfig { |
|||
private final String url; |
|||
private final String username; |
|||
private final String password; |
|||
} |
|||
@ -0,0 +1,34 @@ |
|||
package org.thingsboard.server.common.data.oauth2; |
|||
|
|||
import lombok.*; |
|||
import org.thingsboard.server.common.data.BaseData; |
|||
import org.thingsboard.server.common.data.id.OAuth2IntegrationId; |
|||
|
|||
@EqualsAndHashCode(callSuper = true) |
|||
@Data |
|||
@ToString |
|||
public class OAuth2MapperConfig extends BaseData<OAuth2IntegrationId> { |
|||
private boolean allowUserCreation; |
|||
private boolean activateUser; |
|||
private MapperType type; |
|||
private OAuth2BasicMapperConfig basicConfig; |
|||
private OAuth2CustomMapperConfig customConfig; |
|||
|
|||
public OAuth2MapperConfig() { |
|||
super(); |
|||
} |
|||
|
|||
public OAuth2MapperConfig(OAuth2IntegrationId id) { |
|||
super(id); |
|||
} |
|||
|
|||
@Builder(toBuilder = true) |
|||
public OAuth2MapperConfig(OAuth2IntegrationId id, boolean allowUserCreation, boolean activateUser, MapperType type, OAuth2BasicMapperConfig basicConfig, OAuth2CustomMapperConfig customConfig) { |
|||
super(id); |
|||
this.allowUserCreation = allowUserCreation; |
|||
this.activateUser = activateUser; |
|||
this.type = type; |
|||
this.basicConfig = basicConfig; |
|||
this.customConfig = customConfig; |
|||
} |
|||
} |
|||
@ -0,0 +1,99 @@ |
|||
/** |
|||
* Copyright © 2016-2020 The Thingsboard Authors |
|||
* |
|||
* Licensed under the Apache License, Version 2.0 (the "License"); |
|||
* you may not use this file except in compliance with the License. |
|||
* You may obtain a copy of the License at |
|||
* |
|||
* http://www.apache.org/licenses/LICENSE-2.0
|
|||
* |
|||
* Unless required by applicable law or agreed to in writing, software |
|||
* distributed under the License is distributed on an "AS IS" BASIS, |
|||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
|||
* See the License for the specific language governing permissions and |
|||
* limitations under the License. |
|||
*/ |
|||
package org.thingsboard.server.dao.model.sql; |
|||
|
|||
import lombok.Data; |
|||
import lombok.EqualsAndHashCode; |
|||
import lombok.NoArgsConstructor; |
|||
import org.hibernate.annotations.TypeDef; |
|||
import org.thingsboard.server.common.data.EntityView; |
|||
import org.thingsboard.server.common.data.id.OAuth2IntegrationId; |
|||
import org.thingsboard.server.common.data.oauth2.OAuth2ClientRegistration; |
|||
import org.thingsboard.server.dao.model.BaseSqlEntity; |
|||
import org.thingsboard.server.dao.model.ModelConstants; |
|||
import org.thingsboard.server.dao.util.mapping.JsonStringType; |
|||
|
|||
import javax.persistence.Column; |
|||
import javax.persistence.Entity; |
|||
import javax.persistence.Table; |
|||
|
|||
@Data |
|||
@EqualsAndHashCode(callSuper = true) |
|||
@Entity |
|||
@TypeDef(name = "json", typeClass = JsonStringType.class) |
|||
@Table(name = ModelConstants.OAUTH2_CLIENT_REGISTRATION_COLUMN_FAMILY_NAME) |
|||
public class OAuth2ClientRegistrationEntity extends BaseSqlEntity<OAuth2ClientRegistration> { |
|||
|
|||
@Column(name = ModelConstants.OAUTH2_CLIENT_REGISTRATION_ID_PROPERTY) |
|||
private String registrationId; |
|||
@Column(name = ModelConstants.OAUTH2_CLIENT_REGISTRATION_MAPPER_CONFIG_ID_PROPERTY) |
|||
private String mapperConfigId; |
|||
@Column(name = ModelConstants.OAUTH2_CLIENT_ID_PROPERTY) |
|||
private String clientId; |
|||
@Column(name = ModelConstants.OAUTH2_CLIENT_SECRET_PROPERTY) |
|||
private String clientSecret; |
|||
@Column(name = ModelConstants.OAUTH2_AUTHORIZATION_URI_PROPERTY) |
|||
private String authorizationUri; |
|||
@Column(name = ModelConstants.OAUTH2_TOKEN_URI_PROPERTY) |
|||
private String tokenUri; |
|||
@Column(name = ModelConstants.OAUTH2_REDIRECT_URI_TEMPLATE_PROPERTY) |
|||
private String redirectUriTemplate; |
|||
@Column(name = ModelConstants.OAUTH2_SCOPE_PROPERTY) |
|||
private String scope; |
|||
@Column(name = ModelConstants.OAUTH2_AUTHORIZATION_GRANT_TYPE_PROPERTY) |
|||
private String authorizationGrantType; |
|||
@Column(name = ModelConstants.OAUTH2_USER_INFO_URI_PROPERTY) |
|||
private String userInfoUri; |
|||
@Column(name = ModelConstants.OAUTH2_USER_NAME_ATTRIBUTE_PROPERTY) |
|||
private String userNameAttribute; |
|||
@Column(name = ModelConstants.OAUTH2_JWK_SET_URI_PROPERTY) |
|||
private String jwkSetUri; |
|||
@Column(name = ModelConstants.OAUTH2_CLIENT_AUTHENTICATION_METHOD_PROPERTY) |
|||
private String clientAuthenticationMethod; |
|||
@Column(name = ModelConstants.OAUTH2_CLIENT_NAME_PROPERTY) |
|||
private String clientName; |
|||
@Column(name = ModelConstants.OAUTH2_LOGIN_BUTTON_LABEL_PROPERTY) |
|||
private String loginButtonLabel; |
|||
@Column(name = ModelConstants.OAUTH2_LOGIN_BUTTON_ICON_PROPERTY) |
|||
private String loginButtonIcon; |
|||
|
|||
public OAuth2ClientRegistrationEntity() { |
|||
super(); |
|||
} |
|||
|
|||
@Override |
|||
public OAuth2ClientRegistration toData() { |
|||
return OAuth2ClientRegistration.builder() |
|||
.id(new OAuth2IntegrationId(toUUID(id))) |
|||
.registrationId(registrationId) |
|||
.mapperConfigId(new OAuth2IntegrationId(toUUID(mapperConfigId))) |
|||
.clientId(clientId) |
|||
.clientSecret(clientSecret) |
|||
.authorizationUri(authorizationUri) |
|||
.tokenUri(tokenUri) |
|||
.redirectUriTemplate(redirectUriTemplate) |
|||
.scope(scope) |
|||
.authorizationGrantType(authorizationGrantType) |
|||
.userInfoUri(userInfoUri) |
|||
.userNameAttribute(userNameAttribute) |
|||
.jwkSetUri(jwkSetUri) |
|||
.clientAuthenticationMethod(clientAuthenticationMethod) |
|||
.clientName(clientName) |
|||
.loginButtonLabel(loginButtonLabel) |
|||
.loginButtonIcon(loginButtonIcon) |
|||
.build(); |
|||
} |
|||
} |
|||
@ -0,0 +1,101 @@ |
|||
/** |
|||
* Copyright © 2016-2020 The Thingsboard Authors |
|||
* <p> |
|||
* Licensed under the Apache License, Version 2.0 (the "License"); |
|||
* you may not use this file except in compliance with the License. |
|||
* You may obtain a copy of the License at |
|||
* <p> |
|||
* http://www.apache.org/licenses/LICENSE-2.0
|
|||
* <p> |
|||
* Unless required by applicable law or agreed to in writing, software |
|||
* distributed under the License is distributed on an "AS IS" BASIS, |
|||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
|||
* See the License for the specific language governing permissions and |
|||
* limitations under the License. |
|||
*/ |
|||
package org.thingsboard.server.dao.model.sql; |
|||
|
|||
import lombok.Data; |
|||
import lombok.EqualsAndHashCode; |
|||
import org.hibernate.annotations.TypeDef; |
|||
import org.thingsboard.server.common.data.id.OAuth2IntegrationId; |
|||
import org.thingsboard.server.common.data.oauth2.MapperType; |
|||
import org.thingsboard.server.common.data.oauth2.OAuth2BasicMapperConfig; |
|||
import org.thingsboard.server.common.data.oauth2.OAuth2CustomMapperConfig; |
|||
import org.thingsboard.server.common.data.oauth2.OAuth2MapperConfig; |
|||
import org.thingsboard.server.dao.model.BaseSqlEntity; |
|||
import org.thingsboard.server.dao.model.ModelConstants; |
|||
import org.thingsboard.server.dao.util.mapping.JsonStringType; |
|||
|
|||
import javax.persistence.*; |
|||
|
|||
@Data |
|||
@EqualsAndHashCode(callSuper = true) |
|||
@Entity |
|||
@TypeDef(name = "json", typeClass = JsonStringType.class) |
|||
@Table(name = ModelConstants.OAUTH2_MAPPER_CONFIG_COLUMN_FAMILY_NAME) |
|||
public class OAuth2MapperConfigEntity extends BaseSqlEntity<OAuth2MapperConfig> { |
|||
|
|||
@Column(name = ModelConstants.OAUTH2_ALLOW_USER_CREATION_PROPERTY) |
|||
private Boolean allowUserCreation; |
|||
@Column(name = ModelConstants.OAUTH2_ACTIVATE_USER_PROPERTY) |
|||
private Boolean activateUser; |
|||
@Enumerated(EnumType.STRING) |
|||
@Column(name = ModelConstants.OAUTH2_MAPPER_TYPE_PROPERTY) |
|||
private MapperType type; |
|||
@Column(name = ModelConstants.OAUTH2_EMAIL_ATTRIBUTE_KEY_PROPERTY) |
|||
private String emailAttributeKey; |
|||
@Column(name = ModelConstants.OAUTH2_FIRST_NAME_ATTRIBUTE_KEY_PROPERTY) |
|||
private String firstNameAttributeKey; |
|||
@Column(name = ModelConstants.OAUTH2_LAST_NAME_ATTRIBUTE_KEY_PROPERTY) |
|||
private String lastNameAttributeKey; |
|||
@Column(name = ModelConstants.OAUTH2_TENANT_NAME_STRATEGY_PROPERTY) |
|||
private String tenantNameStrategy; |
|||
@Column(name = ModelConstants.OAUTH2_TENANT_NAME_PATTERN_PROPERTY) |
|||
private String tenantNamePattern; |
|||
@Column(name = ModelConstants.OAUTH2_CUSTOMER_NAME_PATTERN_PROPERTY) |
|||
private String customerNamePattern; |
|||
@Column(name = ModelConstants.OAUTH2_DEFAULT_DASHBOARD_NAME_PROPERTY) |
|||
private String defaultDashboardName; |
|||
@Column(name = ModelConstants.OAUTH2_ALWAYS_FULL_SCREEN_PROPERTY) |
|||
private Boolean alwaysFullScreen; |
|||
@Column(name = ModelConstants.OAUTH2_MAPPER_URL_PROPERTY) |
|||
private String url; |
|||
@Column(name = ModelConstants.OAUTH2_MAPPER_USERNAME_PROPERTY) |
|||
private String username; |
|||
@Column(name = ModelConstants.OAUTH2_MAPPER_PASSWORD_PROPERTY) |
|||
private String password; |
|||
|
|||
public OAuth2MapperConfigEntity() { |
|||
super(); |
|||
} |
|||
|
|||
@Override |
|||
public OAuth2MapperConfig toData() { |
|||
return OAuth2MapperConfig.builder() |
|||
.id(new OAuth2IntegrationId(toUUID(id))) |
|||
.allowUserCreation(allowUserCreation) |
|||
.activateUser(activateUser) |
|||
.type(type) |
|||
.basicConfig( |
|||
OAuth2BasicMapperConfig.builder() |
|||
.emailAttributeKey(emailAttributeKey) |
|||
.firstNameAttributeKey(firstNameAttributeKey) |
|||
.lastNameAttributeKey(lastNameAttributeKey) |
|||
.tenantNameStrategy(tenantNameStrategy) |
|||
.tenantNamePattern(tenantNamePattern) |
|||
.customerNamePattern(customerNamePattern) |
|||
.defaultDashboardName(defaultDashboardName) |
|||
.alwaysFullScreen(alwaysFullScreen) |
|||
.build() |
|||
) |
|||
.customConfig( |
|||
OAuth2CustomMapperConfig.builder() |
|||
.url(url) |
|||
.username(username) |
|||
.password(password) |
|||
.build() |
|||
) |
|||
.build(); |
|||
} |
|||
} |
|||
Loading…
Reference in new issue