public class AuthorizationService extends java.lang.Object implements Service
| Modifier and Type | Field and Description |
|---|---|
static java.lang.String |
ADMIN_USERS_FILE
File that contains list of admin users for Oozie.
|
static java.lang.String |
CONF_ADMIN_GROUPS
Configuration parameter to define admin groups, if NULL/empty the adminusers.txt file is used.
|
static java.lang.String |
CONF_AUTHORIZATION_ENABLED
Configuration parameter to enable or disable Oozie admin role.
|
static java.lang.String |
CONF_DEFAULT_GROUP_AS_ACL
Configuration parameter to enable old behavior default group as ACL.
|
static java.lang.String |
CONF_PREFIX |
static java.lang.String |
CONF_SECURITY_ENABLED
Configuration parameter to enable or disable Oozie admin role.
|
protected static java.lang.String |
INSTR_FAILED_AUTH_COUNTER |
protected static java.lang.String |
INSTRUMENTATION_GROUP |
DEFAULT_LOCK_TIMEOUT, lockTimeout| Constructor and Description |
|---|
AuthorizationService() |
| Modifier and Type | Method and Description |
|---|---|
void |
authorizeForAdmin(java.lang.String user,
boolean write)
Check if the user has admin privileges.
|
void |
authorizeForApp(java.lang.String user,
java.lang.String group,
java.lang.String appPath,
org.apache.hadoop.conf.Configuration jobConf)
Check if the user+group is authorized to use the specified application.
|
void |
authorizeForApp(java.lang.String user,
java.lang.String group,
java.lang.String appPath,
java.lang.String fileName,
org.apache.hadoop.conf.Configuration conf)
Check if the user+group is authorized to use the specified application.
|
void |
authorizeForGroup(java.lang.String user,
java.lang.String group)
Check if the user belongs to the group or not.
|
void |
authorizeForJob(java.lang.String user,
java.lang.String jobId,
boolean write)
Check if the user+group is authorized to operate on the specified job.
|
void |
authorizeForJobs(java.lang.String user,
java.util.Map<java.lang.String,java.util.List<java.lang.String>> filter,
java.lang.String jobType,
int start,
int len,
boolean write)
Check if the user+group is authorized to operate on the specified jobs.
|
void |
destroy()
Destroy the service.
|
java.lang.String |
getDefaultGroup(java.lang.String user)
Return the default group to which the user belongs.
|
java.lang.Class<? extends Service> |
getInterface()
Return the public interface of the service.
|
void |
init(Services services)
Initialize the service.
|
protected boolean |
isAdmin(java.lang.String user)
Check if the user has admin privileges.
|
boolean |
isAuthorizationEnabled()
Return if security is enabled or not.
|
boolean |
isSecurityEnabled()
Deprecated.
|
protected boolean |
isUserInGroup(java.lang.String user,
java.lang.String group)
Check if the user belongs to the group or not.
|
boolean |
useDefaultGroupAsAcl() |
public static final java.lang.String CONF_PREFIX
public static final java.lang.String CONF_SECURITY_ENABLED
public static final java.lang.String CONF_AUTHORIZATION_ENABLED
public static final java.lang.String CONF_DEFAULT_GROUP_AS_ACL
public static final java.lang.String CONF_ADMIN_GROUPS
public static final java.lang.String ADMIN_USERS_FILE
protected static final java.lang.String INSTRUMENTATION_GROUP
protected static final java.lang.String INSTR_FAILED_AUTH_COUNTER
public AuthorizationService()
public void init(Services services) throws ServiceException
init in interface Serviceservices - services instance.ServiceException - thrown if the service could not be initialized.@Deprecated public boolean isSecurityEnabled()
public boolean useDefaultGroupAsAcl()
public boolean isAuthorizationEnabled()
public void destroy()
public java.lang.Class<? extends Service> getInterface()
getInterface in interface ServiceAuthorizationService.protected boolean isUserInGroup(java.lang.String user, java.lang.String group) throws AuthorizationException
user - user name.group - group name.AuthorizationException - thrown if the authorization query can not be performed.public void authorizeForGroup(java.lang.String user, java.lang.String group) throws AuthorizationException
isUserInGroup(java.lang.String, java.lang.String)
method.user - user name.group - group name.AuthorizationException - thrown if the user is not authorized for the group or if the authorization query
can not be performed.public java.lang.String getDefaultGroup(java.lang.String user) throws AuthorizationException
user - user name.AuthorizationException - thrown if the default group con not be retrieved.protected boolean isAdmin(java.lang.String user)
true. If
admin is enabled it returns true if the user is in the adminusers.txt file.user - user name.public void authorizeForAdmin(java.lang.String user, boolean write) throws AuthorizationException
isUserInGroup(java.lang.String, java.lang.String) method.user - user name.write - indicates if the check is for read or write admin tasks (in this implementation this is ignored)AuthorizationException - thrown if user does not have admin privileges.public void authorizeForApp(java.lang.String user, java.lang.String group, java.lang.String appPath, org.apache.hadoop.conf.Configuration jobConf) throws AuthorizationException
user - user name.group - group name.appPath - application path.AuthorizationException - thrown if the user is not authorized for the app.public void authorizeForApp(java.lang.String user, java.lang.String group, java.lang.String appPath, java.lang.String fileName, org.apache.hadoop.conf.Configuration conf) throws AuthorizationException
user - user name.group - group name.appPath - application path.fileName - workflow or coordinator.xmlconf - AuthorizationException - thrown if the user is not authorized for the app.public void authorizeForJob(java.lang.String user, java.lang.String jobId, boolean write) throws AuthorizationException
user - user name.jobId - job id.write - indicates if the check is for read or write job tasks.AuthorizationException - thrown if the user is not authorized for the job.public void authorizeForJobs(java.lang.String user, java.util.Map<java.lang.String,java.util.List<java.lang.String>> filter, java.lang.String jobType, int start, int len, boolean write) throws AuthorizationException
user - user name.filter - filter used to select jobsstart - starting index of the jobs in DBlen - maximum amount of jobs to selectwrite - indicates if the check is for read or write job tasks.AuthorizationException - thrown if the user is not authorized for the job.Copyright © 2018 Apache Software Foundation. All Rights Reserved.