Browse Source

Centralize logic for checking if user is public

pull/320/head
Chris Eykamp 9 years ago
parent
commit
ddb69646a5
  1. 6
      application/src/main/java/org/thingsboard/server/controller/CustomerController.java
  2. 8
      application/src/main/java/org/thingsboard/server/service/security/auth/jwt/RefreshTokenAuthenticationProvider.java
  3. 6
      application/src/main/java/org/thingsboard/server/service/security/auth/rest/RestAuthenticationProvider.java
  4. 8
      common/data/src/main/java/org/thingsboard/server/common/data/Customer.java

6
application/src/main/java/org/thingsboard/server/controller/CustomerController.java

@ -56,11 +56,7 @@ public class CustomerController extends BaseController {
ObjectMapper objectMapper = new ObjectMapper();
ObjectNode infoObject = objectMapper.createObjectNode();
infoObject.put("title", customer.getTitle());
boolean isPublic = false;
if (customer.getAdditionalInfo() != null && customer.getAdditionalInfo().has("isPublic")) {
isPublic = customer.getAdditionalInfo().get("isPublic").asBoolean();
}
infoObject.put("isPublic", isPublic);
infoObject.put("isPublic", customer.isPublic());
return infoObject;
} catch (Exception e) {
throw handleException(e);

8
application/src/main/java/org/thingsboard/server/service/security/auth/jwt/RefreshTokenAuthenticationProvider.java

@ -103,13 +103,11 @@ public class RefreshTokenAuthenticationProvider implements AuthenticationProvide
if (publicCustomer == null) {
throw new UsernameNotFoundException("Public entity not found by refresh token");
}
boolean isPublic = false;
if (publicCustomer.getAdditionalInfo() != null && publicCustomer.getAdditionalInfo().has("isPublic")) {
isPublic = publicCustomer.getAdditionalInfo().get("isPublic").asBoolean();
}
if (!isPublic) {
if (!publicCustomer.isPublic()) {
throw new BadCredentialsException("Refresh token is not valid");
}
User user = new User(new UserId(UUIDBased.EMPTY));
user.setTenantId(publicCustomer.getTenantId());
user.setCustomerId(publicCustomer.getId());

6
application/src/main/java/org/thingsboard/server/service/security/auth/rest/RestAuthenticationProvider.java

@ -108,11 +108,7 @@ public class RestAuthenticationProvider implements AuthenticationProvider {
if (publicCustomer == null) {
throw new UsernameNotFoundException("Public entity not found: " + publicId);
}
boolean isPublic = false;
if (publicCustomer.getAdditionalInfo() != null && publicCustomer.getAdditionalInfo().has("isPublic")) {
isPublic = publicCustomer.getAdditionalInfo().get("isPublic").asBoolean();
}
if (!isPublic) {
if (!publicCustomer.isPublic()) {
throw new BadCredentialsException("Authentication Failed. Public Id is not valid.");
}
User user = new User(new UserId(UUIDBased.EMPTY));

8
common/data/src/main/java/org/thingsboard/server/common/data/Customer.java

@ -60,6 +60,14 @@ public class Customer extends ContactBased<CustomerId> implements HasName {
public void setTitle(String title) {
this.title = title;
}
public boolean isPublic() {
if (getAdditionalInfo() != null && getAdditionalInfo().has("isPublic")) {
return getAdditionalInfo().get("isPublic").asBoolean();
}
return false;
}
@Override
@JsonProperty(access = Access.READ_ONLY)

Loading…
Cancel
Save