Package org.cyclos.security.access
Class TokenServiceSecurity
- java.lang.Object
-
- org.cyclos.impl.AbstractServerComponent
-
- org.cyclos.impl.AbstractNetworkedServerComponent
-
- org.cyclos.security.BaseServiceSecurity
-
- org.cyclos.security.CRUDServiceSecurity<TokenDTO,Token,TokenData,TokenDataParams>
-
- org.cyclos.security.access.TokenServiceSecurity
-
- All Implemented Interfaces:
TokenService,CRUDService<TokenDTO,TokenData,TokenDataParams>,CRUDWithConfirmationPasswordService<TokenDTO,TokenData,TokenDataParams>,Service
@Security public class TokenServiceSecurity extends CRUDServiceSecurity<TokenDTO,Token,TokenData,TokenDataParams> implements TokenService
Security forTokenService
-
-
Field Summary
-
Fields inherited from class org.cyclos.security.CRUDServiceSecurity
entityClass
-
Fields inherited from class org.cyclos.impl.AbstractNetworkedServerComponent
authHandler, conversionHandler, customFieldValueHandler, entityManagerHandler, groupsHandler, productsHandler, restBeanPropertyMapping, userLocatorHandler
-
Fields inherited from class org.cyclos.impl.AbstractServerComponent
accountHandler, configurationHandler, dataTranslationHandler, notificationHandler, profileFieldHandler, transactionHandler, translationHandler
-
-
Constructor Summary
Constructors Constructor Description TokenServiceSecurity()
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description Longactivate(TokenActionDTO dto, UserLocatorVO locator)Searches for a token with the given type and value specified in theTokenActionDTOparameter.
The token's status must beTokenStatus.UNASSIGNEDorTokenStatus.PENDING_ACTIVATIONbut assigned to the logged user or one of its operators.
If the token is unassigned then this method assigns it to the user specified by theUserLocatorVOparameter and change its status toTokenStatus.ACTIVE.
Otherwise (the token is already assigned and is pending by activation) it activates only.
This method can be used only by members (i.e.voidactivatePending(Long tokenId)Activates an already assigned token with statusTokenStatus.PENDING_ACTIVATION.
This operation can only be done by admins/brokers over tokens of managed users or member over tokens of its operators with permission to activate the correspondingTokenPrincipalTypeVO.voidassign(@NotNull Long tokenId, @NotNull UserLocatorVO user)Assigns a pending token to a user, leaving it in pending status The token status must beTokenStatus.UNASSIGNED.SerializableInputStreambarcode(TokenBarcodeParams params)Returns a barcode image of the tokenvoidblock(Long tokenId)Blocks the given tokenvoidcancel(Long tokenId)Cancels the given tokenvoidcancelNFCToken(TokenActionDTO dto)Cancels the given NFC token.protected voidcheckCreateNew(TokenDataParams params)Checks whether creating new entities with the given context parameters is allowed, throwingPermissionDeniedExceptionif notDeviceConfirmationVOcreateDeviceConfirmationForPersonalizeNFCTag(@NotNull UserLocatorVO locator, @NotNull TokenPrincipalTypeVO tokenTypeVO)Creates a new pending device confirmation for the specified user.protected voidcustomizeData(TokenData data)Can be overridden in order to process the returned data object for the given entitySerializableInputStreamdeviceConfirmationBarcodeForPersonalizeNFCTag(UserLocatorVO locator, @NotNull TokenPrincipalTypeVO tokenTypeVO, DeviceConfirmationBarcodeParams params)Generates a two-dimensional barcode (QR code), only if the confirmation was not already approved nor rejected for the given payer.protected booleandoHasManageAccess(Token entity)Should be implemented in order to return whether the caller is allowed to manage the given entity, for the given operationbooleandoHasViewAccess(Token token)Should be implemented in order to return whether the caller is allowed to view the given entity.FileInfoexportTokens(@NotNull ExportFormatVO format, @NotNull TokenQuery query)Exports the token search results to fileprotected CRUDServiceLocal<Token,TokenDTO,TokenData,TokenDataParams>getImplementation()Should be implemented in order to return the actual implementation of the serviceInitializeNFCTagDatagetInitializeNFCTagData()Returns data with the token types available to initialize a blank NFC tag.
The available tokens to personalize the tag are returned too to allow initialization and personalization at the same time.TokensListDatagetListData(TokenPrincipalTypeVO tokenType, UserLocatorVO locator)Returns data for listing tokens of a given type and userPersonalizeNFCTagDatagetPersonalizeNFCTagData(TokenPrincipalTypeVO tokenTypeVO, UserLocatorVO locator)Returns data needed to personalize a NFC tag for the specified type and user.
ThePersonalizeNFCTagData.CONFIRMATION_PASSWORD_INPUTwill be null if the logged user manages the given user.TokenSearchDatagetSearchData(TokenPrincipalTypeVO tokenType)Returns data for searching tokensbooleanhasPermissionToPersonalizeAtRegistration(UserGroup group, NFCTokenPrincipalType type, boolean asMember)Returns true if the logged user can personalize a token for the given type and also checks the user can register new users for the specified group.InitializeNFCTagResultinitializeNFCTag(NFCTagInitializeDTO dto)Initializes and optionally personalize a NFC tag with the given data.booleanisAccessible(SessionData sessionData, Token entity)Must be implemented in order to determine whether the given entity is accessible for the given session data.protected voidonBeforeSave(TokenDTO dto, Token entity)voidpersonalizeNFCTag(NFCTagPersonalizeDTO dto)Personalizes a NFC tag for the given user.voidremoveDeviceConfirmationForPersonalizeNFCTag(@NotNull UserLocatorVO locator, @NotNull TokenPrincipalTypeVO tokenTypeVO, String deviceConfirmationId)Removes a device confirmation for the given user.ExternalNFCTagAuthenticateDatarequestForExternalAuthenticate(ExternalNFCTagAuthenticateDTO dto)This method must be invoked to start a mutual authentication process between the server and the NFC tag (e.g.voidrequestNewOTPForPersonalizeNFCTag(UserLocatorVO locator, TokenPrincipalTypeVO tokenTypeVO, SendMedium medium)Generates a new OTP (removing any previous password, if any) and sends it to the user by the specified medium using the confirmation password type set for theBuiltInChannel.POSchannel for the specified user.
It has the same security controls as forTokenService.personalizeNFCTag(NFCTagPersonalizeDTO), that is the logged user must be allowed to personalize a NFC Tag for the specified user.Page<TokenVO>search(TokenQuery query)Searches for tokens.voidsetActivationDeadline(@NotNull Long tokenId, DateTime date)Changes the token activation deadline date.voidsetExpiryDate(@NotNull Long tokenId, DateTime date)Changes the token expiry date.voidunblock(Long tokenId)Unblocks the given tokenDeviceConfirmationVOviewDeviceConfirmationForPersonalizeNFCTag(@NotNull UserLocatorVO locator, @NotNull TokenPrincipalTypeVO tokenTypeVO, String deviceConfirmationId)Loads the details of a confirmation belonging to the given user.-
Methods inherited from class org.cyclos.security.CRUDServiceSecurity
canPerformOperation, canViewData, checkManageAccess, checkOperation, checkSave, checkViewAccess, find, getConfirmationPasswordInputForRemove, getData, getDataForNew, getEntityClass, hasManageAccess, hasViewAccess, load, remove, removeAll, removeAllWithConfirmationPassword, removeWithConfirmationPassword, resolveEntityCheck, save, saveWithConfirmationPassword
-
Methods inherited from class org.cyclos.security.BaseServiceSecurity
checkGuest, checkId, checkIds, checkInternalName, checkLoggedIn, checkManagesUser, checkRelatesToUser, checkScope, checkVO, checkVOs, doInitialize, getEntityCheckRegistry, getUser, initialize
-
Methods inherited from class org.cyclos.impl.AbstractNetworkedServerComponent
canManage, checkManagesUser, checkPermission, checkRelatesToUser, checkValue, clearAlreadyValidated, getBaseEntityManagerHandler, getConfiguration, getLoggedBasicUser, getLoggedUser, getProducts, getTranslatedName, getTranslatedValue, hasPermission, hasValue, inSameNetwork, inSameNetworkOrGlobal, isAdmin, isAlreadyValidated, isBroker, isGlobalAdmin, isGlobalAdminInNetwork, isGuest, isLoggedIn, isMember, isMemberOnly, isNetworkAdmin, isOperator, isRelatedToUser, isSystem, isUserManager, isUserManagerOf, message, message, permission, permission, permissionOptionalValue, permissionOptionalValue, setAlreadyValidated, toDate, toDateTime, validate
-
Methods inherited from class org.cyclos.impl.AbstractServerComponent
dataTranslationProxy, dataTranslationProxy, delete, detach, doDataTranslationProxy, find, flush, from, getApplicationContext, getFormatter, getFormatter, getFormatter, getLogger, getRemoteAddress, getSessionData, mailContentBuilder, message, message, persist, processBatch, processBatch, refresh, remove, selectFrom, subQuery, update
-
Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
-
Methods inherited from interface org.cyclos.services.CRUDService
getData, getDataForNew, load, remove, removeAll, save
-
-
-
-
Method Detail
-
activate
public Long activate(TokenActionDTO dto, UserLocatorVO locator)
Description copied from interface:TokenServiceSearches for a token with the given type and value specified in theTokenActionDTOparameter.
The token's status must beTokenStatus.UNASSIGNEDorTokenStatus.PENDING_ACTIVATIONbut assigned to the logged user or one of its operators.
If the token is unassigned then this method assigns it to the user specified by theUserLocatorVOparameter and change its status toTokenStatus.ACTIVE.
Otherwise (the token is already assigned and is pending by activation) it activates only.
This method can be used only by members (i.e. not administrators) with permission to activate the correspondingTokenPrincipalTypeVO. For administrators / brokers, seeTokenService.activatePending(Long)- Specified by:
activatein interfaceTokenService
-
activatePending
public void activatePending(Long tokenId)
Description copied from interface:TokenServiceActivates an already assigned token with statusTokenStatus.PENDING_ACTIVATION.
This operation can only be done by admins/brokers over tokens of managed users or member over tokens of its operators with permission to activate the correspondingTokenPrincipalTypeVO.- Specified by:
activatePendingin interfaceTokenService
-
assign
public void assign(@NotNull @NotNull Long tokenId, @NotNull @NotNull UserLocatorVO user) throws FrameworkExceptionDescription copied from interface:TokenServiceAssigns a pending token to a user, leaving it in pending status The token status must beTokenStatus.UNASSIGNED.- Specified by:
assignin interfaceTokenService- Throws:
FrameworkException
-
barcode
public SerializableInputStream barcode(TokenBarcodeParams params) throws FrameworkException
Description copied from interface:TokenServiceReturns a barcode image of the token- Specified by:
barcodein interfaceTokenService- Throws:
FrameworkException
-
block
public void block(Long tokenId)
Description copied from interface:TokenServiceBlocks the given token- Specified by:
blockin interfaceTokenService
-
cancel
public void cancel(Long tokenId)
Description copied from interface:TokenServiceCancels the given token- Specified by:
cancelin interfaceTokenService
-
cancelNFCToken
public void cancelNFCToken(TokenActionDTO dto)
Description copied from interface:TokenServiceCancels the given NFC token. Admins and brokers with permissions can cancel a NFC token of typeTokenType.NFC_TAG.
In case of a NFC token of typeTokenType.NFC_DEVICEonly the logged user can cancel its own token.- Specified by:
cancelNFCTokenin interfaceTokenService
-
createDeviceConfirmationForPersonalizeNFCTag
public DeviceConfirmationVO createDeviceConfirmationForPersonalizeNFCTag(@NotNull @NotNull UserLocatorVO locator, @NotNull @NotNull TokenPrincipalTypeVO tokenTypeVO) throws FrameworkException
Description copied from interface:TokenServiceCreates a new pending device confirmation for the specified user. The logged user will be notified after the confirmation was processed. It has the same security controls as forTokenService.personalizeNFCTag(NFCTagPersonalizeDTO), that is the logged user must be allowed to personalize a NFC Tag for the specified user.- Specified by:
createDeviceConfirmationForPersonalizeNFCTagin interfaceTokenServicetokenTypeVO- the principal type used to personalize the card- Throws:
FrameworkException
-
deviceConfirmationBarcodeForPersonalizeNFCTag
public SerializableInputStream deviceConfirmationBarcodeForPersonalizeNFCTag(UserLocatorVO locator, @NotNull @NotNull TokenPrincipalTypeVO tokenTypeVO, DeviceConfirmationBarcodeParams params) throws FrameworkException
Description copied from interface:TokenServiceGenerates a two-dimensional barcode (QR code), only if the confirmation was not already approved nor rejected for the given payer. It has the same security controls as forTokenService.personalizeNFCTag(NFCTagPersonalizeDTO), that is the logged user must be allowed to personalize a NFC Tag for the specified user.- Specified by:
deviceConfirmationBarcodeForPersonalizeNFCTagin interfaceTokenServicetokenTypeVO- the principal type used to personalize the card- Throws:
FrameworkException
-
doHasViewAccess
public boolean doHasViewAccess(Token token)
Description copied from class:CRUDServiceSecurityShould be implemented in order to return whether the caller is allowed to view the given entity.- Specified by:
doHasViewAccessin classCRUDServiceSecurity<TokenDTO,Token,TokenData,TokenDataParams>
-
exportTokens
public FileInfo exportTokens(@NotNull @NotNull ExportFormatVO format, @NotNull @NotNull TokenQuery query) throws FrameworkException
Description copied from interface:TokenServiceExports the token search results to file- Specified by:
exportTokensin interfaceTokenService- Throws:
FrameworkException
-
getInitializeNFCTagData
public InitializeNFCTagData getInitializeNFCTagData() throws FrameworkException
Description copied from interface:TokenServiceReturns data with the token types available to initialize a blank NFC tag.
The available tokens to personalize the tag are returned too to allow initialization and personalization at the same time. Only allowed for managers (Brokers & Administrators).- Specified by:
getInitializeNFCTagDatain interfaceTokenService- Throws:
FrameworkException- See Also:
TokenService.initializeNFCTag(NFCTagInitializeDTO)
-
getListData
public TokensListData getListData(TokenPrincipalTypeVO tokenType, UserLocatorVO locator) throws FrameworkException
Description copied from interface:TokenServiceReturns data for listing tokens of a given type and user- Specified by:
getListDatain interfaceTokenService- Throws:
FrameworkException
-
getPersonalizeNFCTagData
public PersonalizeNFCTagData getPersonalizeNFCTagData(TokenPrincipalTypeVO tokenTypeVO, UserLocatorVO locator) throws FrameworkException
Description copied from interface:TokenServiceReturns data needed to personalize a NFC tag for the specified type and user.
ThePersonalizeNFCTagData.CONFIRMATION_PASSWORD_INPUTwill be null if the logged user manages the given user. ThePersonalizeNFCTagData.TOKEN_TYPEis the token principal type the tag was initialized for.- Specified by:
getPersonalizeNFCTagDatain interfaceTokenService- Throws:
FrameworkException
-
getSearchData
public TokenSearchData getSearchData(TokenPrincipalTypeVO tokenType) throws FrameworkException
Description copied from interface:TokenServiceReturns data for searching tokens- Specified by:
getSearchDatain interfaceTokenService- Throws:
FrameworkException
-
hasPermissionToPersonalizeAtRegistration
public boolean hasPermissionToPersonalizeAtRegistration(UserGroup group, NFCTokenPrincipalType type, boolean asMember)
Returns true if the logged user can personalize a token for the given type and also checks the user can register new users for the specified group.- Parameters:
asMember- Only used if the logged user is a broker.- Returns:
-
initializeNFCTag
public InitializeNFCTagResult initializeNFCTag(NFCTagInitializeDTO dto) throws FrameworkException
Description copied from interface:TokenServiceInitializes and optionally personalize a NFC tag with the given data. If theTokenActionWithUserDTO.getUser()is not null then the token will be personalized for that user too. Returns the private keys (PICC Master Key (i.e. PMK), Application Master Key (i.e. AMK) and Operational key) to be stored into the tag.
Only allowed for managers (Brokers & Administrators).- Specified by:
initializeNFCTagin interfaceTokenService- Throws:
FrameworkException
-
isAccessible
public boolean isAccessible(SessionData sessionData, Token entity)
Description copied from class:CRUDServiceSecurityMust be implemented in order to determine whether the given entity is accessible for the given session data. This method shouldn't check the same condition asCRUDServiceSecurity.hasViewAccess(BaseEntity). If the only condition for an entity isCRUDServiceSecurity.hasViewAccess(BaseEntity), this method should return false.- Specified by:
isAccessiblein classCRUDServiceSecurity<TokenDTO,Token,TokenData,TokenDataParams>
-
personalizeNFCTag
public void personalizeNFCTag(NFCTagPersonalizeDTO dto) throws FrameworkException
Description copied from interface:TokenServicePersonalizes a NFC tag for the given user. If the logged user doesn't manages the user then the confirmation password of that user is required. This method requires a successful previous external authentication (TokenService.requestForExternalAuthenticate(ExternalNFCTagAuthenticateDTO))
The requiredNFCTagPersonalizeDTO.CYCLOS_CHALLENGEis the encrypted (hexadecimal string) challenge generated by the server (returned in the previous external authenticate) used to ensure the tag presence (internal authenticate)- Specified by:
personalizeNFCTagin interfaceTokenService- Throws:
FrameworkException- See Also:
TokenService.requestForExternalAuthenticate(ExternalNFCTagAuthenticateDTO)
-
removeDeviceConfirmationForPersonalizeNFCTag
public void removeDeviceConfirmationForPersonalizeNFCTag(@NotNull @NotNull UserLocatorVO locator, @NotNull @NotNull TokenPrincipalTypeVO tokenTypeVO, String deviceConfirmationId) throws FrameworkExceptionDescription copied from interface:TokenServiceRemoves a device confirmation for the given user. It has the same security controls as forTokenService.personalizeNFCTag(NFCTagPersonalizeDTO), that is the logged user must be allowed to personalize a NFC Tag for the specified user.- Specified by:
removeDeviceConfirmationForPersonalizeNFCTagin interfaceTokenServicetokenTypeVO- the principal type used to personalize the card- Throws:
FrameworkException
-
requestForExternalAuthenticate
public ExternalNFCTagAuthenticateData requestForExternalAuthenticate(ExternalNFCTagAuthenticateDTO dto) throws FrameworkException
Description copied from interface:TokenServiceThis method must be invoked to start a mutual authentication process between the server and the NFC tag (e.g. a card) to prove that both share the same secret key.
The authentication process is carried out in the following order:- Validate the identity of the server: external authenticate
- Validate the identity of the NFc tag: internal authenticate
- Specified by:
requestForExternalAuthenticatein interfaceTokenService- Parameters:
dto- contains the token type id (required), the token value (optional) and an encrypted challenge (required) generated by the tag in hexadecimal notation. If the token value is null then means the authentication process will be using the PICC Master Key (PMK).- Returns:
- data containing the following:
ExternalNFCTagAuthenticateData.CYCLOS_CHALLENGE: encrypted data (hexadecimal string) containing both: a new challenge generated by the server (used to validate the identity of the NFC tag, internal authenticate) and the original challenge generated by the tag processed according to the tag's authentication process. The (processed) original tag challenge will be used by the NFC tag to complete the server identity validation (external authenticate).ExternalNFCTagAuthenticateData.SESSION_KEY: A session key needed by the tag to allow send enciphered data to be written into the NFC tag
- Throws:
FrameworkException
-
requestNewOTPForPersonalizeNFCTag
public void requestNewOTPForPersonalizeNFCTag(UserLocatorVO locator, TokenPrincipalTypeVO tokenTypeVO, SendMedium medium) throws FrameworkException, SmsSendingException
Description copied from interface:TokenServiceGenerates a new OTP (removing any previous password, if any) and sends it to the user by the specified medium using the confirmation password type set for theBuiltInChannel.POSchannel for the specified user.
It has the same security controls as forTokenService.personalizeNFCTag(NFCTagPersonalizeDTO), that is the logged user must be allowed to personalize a NFC Tag for the specified user.- Specified by:
requestNewOTPForPersonalizeNFCTagin interfaceTokenServicetokenTypeVO- the principal type used to personalize the cardmedium- the medium used to send the OTP.- Throws:
SmsSendingException- only if medium isSendMedium.SMSand the OTP could not be sent to any enabled for sms phone.FrameworkException
-
search
public Page<TokenVO> search(TokenQuery query) throws FrameworkException, QueryParseException
Description copied from interface:TokenServiceSearches for tokens. This method can only be user by administrators or brokers.- Specified by:
searchin interfaceTokenService- Throws:
FrameworkExceptionQueryParseException
-
setActivationDeadline
public void setActivationDeadline(@NotNull @NotNull Long tokenId, DateTime date) throws FrameworkExceptionDescription copied from interface:TokenServiceChanges the token activation deadline date. The token status must be eitherTokenStatus.PENDING_ACTIVATIONorTokenStatus.ACTIVATION_EXPIRED.- Specified by:
setActivationDeadlinein interfaceTokenService- Throws:
FrameworkException
-
setExpiryDate
public void setExpiryDate(@NotNull @NotNull Long tokenId, DateTime date) throws FrameworkExceptionDescription copied from interface:TokenServiceChanges the token expiry date. The token status must be eitherTokenStatus.ACTIVE,TokenStatus.BLOCKEDorTokenStatus.EXPIRED.- Specified by:
setExpiryDatein interfaceTokenService- Throws:
FrameworkException
-
unblock
public void unblock(Long tokenId)
Description copied from interface:TokenServiceUnblocks the given token- Specified by:
unblockin interfaceTokenService
-
viewDeviceConfirmationForPersonalizeNFCTag
public DeviceConfirmationVO viewDeviceConfirmationForPersonalizeNFCTag(@NotNull @NotNull UserLocatorVO locator, @NotNull @NotNull TokenPrincipalTypeVO tokenTypeVO, String deviceConfirmationId) throws FrameworkException
Description copied from interface:TokenServiceLoads the details of a confirmation belonging to the given user. It has the same security controls as forTokenService.personalizeNFCTag(NFCTagPersonalizeDTO), that is the logged user must be allowed to personalize a NFC Tag for the specified user.- Specified by:
viewDeviceConfirmationForPersonalizeNFCTagin interfaceTokenServicetokenTypeVO- the principal type used to personalize the card- Throws:
FrameworkException
-
checkCreateNew
protected void checkCreateNew(TokenDataParams params)
Description copied from class:CRUDServiceSecurityChecks whether creating new entities with the given context parameters is allowed, throwingPermissionDeniedExceptionif not- Specified by:
checkCreateNewin classCRUDServiceSecurity<TokenDTO,Token,TokenData,TokenDataParams>
-
customizeData
protected void customizeData(TokenData data)
Description copied from class:CRUDServiceSecurityCan be overridden in order to process the returned data object for the given entity- Overrides:
customizeDatain classCRUDServiceSecurity<TokenDTO,Token,TokenData,TokenDataParams>
-
doHasManageAccess
protected boolean doHasManageAccess(Token entity)
Description copied from class:CRUDServiceSecurityShould be implemented in order to return whether the caller is allowed to manage the given entity, for the given operation- Specified by:
doHasManageAccessin classCRUDServiceSecurity<TokenDTO,Token,TokenData,TokenDataParams>
-
getImplementation
protected CRUDServiceLocal<Token,TokenDTO,TokenData,TokenDataParams> getImplementation()
Description copied from class:CRUDServiceSecurityShould be implemented in order to return the actual implementation of the service- Specified by:
getImplementationin classCRUDServiceSecurity<TokenDTO,Token,TokenData,TokenDataParams>
-
onBeforeSave
protected void onBeforeSave(TokenDTO dto, Token entity)
- Overrides:
onBeforeSavein classCRUDServiceSecurity<TokenDTO,Token,TokenData,TokenDataParams>
-
-