Changeset: 2b8f97996dca for MonetDB URL: http://dev.monetdb.org/hg/MonetDB?cmd=changeset;node=2b8f97996dca Modified Files: monetdb5/ChangeLog monetdb5/mal/mal_authorize.mx Branch: default Log Message:
authorisation: no longer support access restrictions on scenarios I guess this feature is hardly used (if at all), and needlessly complicates the codebase. Any access to the server now means access to all available scenarios. This has been the default since the introduction of M5. All old interfaces are kept equal, but scenario arguments are ignored. On the next ABI bump for libmonetdb5, these should be removed. diffs (truncated from 410 to 300 lines): diff --git a/monetdb5/ChangeLog b/monetdb5/ChangeLog --- a/monetdb5/ChangeLog +++ b/monetdb5/ChangeLog @@ -1,3 +1,8 @@ # ChangeLog file for MonetDB5 # This file is updated with Maddlog +* Fri Apr 22 2011 Fabian Groffen <[email protected]> +- Authorisation no longer takes scenarios into account. Access for only + sql or mal is no longer possible. Any credentials now mean access to + all scenarios that the server has available. + diff --git a/monetdb5/mal/mal_authorize.mx b/monetdb5/mal/mal_authorize.mx --- a/monetdb5/mal/mal_authorize.mx +++ b/monetdb5/mal/mal_authorize.mx @@ -108,7 +108,6 @@ static BAT *user = NULL; static BAT *pass = NULL; -static BAT *scen = NULL; /** * Requires the current client to be the admin user thread. If not the case, @@ -162,7 +161,7 @@ void AUTHcommit() { - bat blist[4]; + bat blist[3]; blist[0] = 0; @@ -170,9 +169,7 @@ blist[1] = ABS(user->batCacheid); assert(pass); blist[2] = ABS(pass->batCacheid); - assert(pass); - blist[3] = ABS(scen->batCacheid); - TMsubcommit_list(blist, 4); + TMsubcommit_list(blist, 3); } @- @@ -191,13 +188,12 @@ str msg = MAL_SUCCEED; /* skip loading if already loaded */ - if (user != NULL && pass != NULL && scen != NULL) + if (user != NULL && pass != NULL) return(MAL_SUCCEED); /* if one is not NULL here, something is seriously screwed up */ assert (user == NULL); assert (pass == NULL); - assert (scen == NULL); /* load/create users BAT */ bid = BBPindex("M5system_auth_user"); @@ -232,23 +228,6 @@ assert(b); pass = b; - /* load/create scenario BAT */ - bid = BBPindex("M5system_auth_scen"); - if (!bid) { - b = BATnew(TYPE_oid, TYPE_str, 256); - if (b == NULL) - throw(MAL, "initTables.scen", MAL_MALLOC_FAIL " scenario table"); - - BATkey(b, TRUE); - BBPrename(BBPcacheid(b), "M5system_auth_scen"); - BATmode(b, PERSISTENT); - } else { - b = BATdescriptor(bid); - isNew = 0; - } - assert(b); - scen = b; - if (isNew == 1) { /* insert the monetdb/monetdb administrator account on a * complete fresh and new auth tables system */ @@ -276,6 +255,8 @@ /** * Checks the credentials supplied and throws an exception if invalid. * The user id of the authenticated user is returned upon success. + * The scenario argument is ignored and should be removed on the next + * ABI bump. */ str AUTHcheckCredentials( @@ -290,7 +271,6 @@ str tmp, msg= MAL_SUCCEED; str pwd = NULL; str hash = NULL; - BAT *b; BUN p, q; oid *id; BATiter useri, passi; @@ -298,7 +278,6 @@ rethrow("checkCredentials", tmp, AUTHrequireAdminOrUser(c, username)); assert(user); assert(pass); - assert(scen); if (*username == NULL || strNil(*username)) throw(INVCRED, "checkCredentials", "invalid credentials for unknown user"); @@ -342,53 +321,21 @@ } GDKfree(hash); - /* now see if the scenario is permitted (if restrictions for that - * apply) - */ - b = BATselect(scen, id, id); - if (b && BATcount(b) > 0) { - BATiter bi = bat_iterator(b); - - if (*scenario == NULL || strNil(*scenario)) { - BBPunfix(b->batCacheid); - /* of course we DO NOT tell the exact reason here again */ - throw(INVCRED, "checkCredentials", INVCRED_INVALID_USER " '%s'",*username); - } - - /* ok, there are some tuples that we have to consider */ - BATloop(b, p, q) { - tmp = (str)BUNtail(bi, p); - assert (tmp != NULL); - if (strcmp(*scenario, tmp) == 0) { - /* YAY! fun! party! We are granted access! */ - *uid = *id; - BBPunfix(b->batCacheid); - return(MAL_SUCCEED); - } - } - - BBPunfix(b->batCacheid); - /* uh oh... that we made it till here means it's wrong */ - throw(INVCRED, "checkCredentials", INVCRED_INVALID_USER " '%s'", *username); - } else { - /* no scenario restriction applies, so everything is good */ - if (b) - BBPunfix(b->batCacheid); - *uid = *id; - return(MAL_SUCCEED); - } + /* scenario restrictions are legacy from the past, we don't check + * this any more, so all is good */ + (void)scenario; + *uid = *id; + return(MAL_SUCCEED); } /** * Adds the given user with password to the administration. The scens - * BAT contains all scenarios allowed for the user. If NULL or empty, - * no restrictions for a scenario applies. The return value of this - * function is the user id of the added user. + * BAT is ignored, and should be removed on the next ABI bump. The + * return value of this function is the user id of the added user. */ str AUTHaddUser(oid *uid, Client *c, str *username, str *passwd, bat *scenarios) { - BUN p, q; - BAT *b; + BUN p; oid *id; str tmp; str hash; @@ -397,7 +344,6 @@ rethrow("addUser", tmp, AUTHrequireAdmin(c)); assert(user); assert(pass); - assert(scen); /* some pre-condition checks */ if (*username == NULL || strNil(*username)) @@ -423,30 +369,8 @@ useri = bat_iterator(user); id = (oid*)(BUNhead(useri, p)); - if (*scenarios != 0) { - b = BATdescriptor(*scenarios); - if (b == NULL) { - BATundo(user); - BATundo(pass); - throw(ILLARG, "addUser", INTERNAL_BAT_ACCESS); - } - if (b->htype != TYPE_str) { - BATundo(user); - BATundo(pass); - BBPreleaseref(b->batCacheid); - throw(ILLARG, "addUser", INTERNAL_BAT_HEAD); - } - - /* associate scenarios given in the BAT with the user */ - if (BATcount(b) > 0){ - BATiter bi = bat_iterator(b); - BATloop(b, p, q) { - /* needs force, as sql makes a view over it */ - BUNins(scen, id, BUNhead(bi, p), TRUE); - } - } - BBPreleaseref(b->batCacheid); - } + /* scenarios are no longer checked */ + (void)scenarios; /* make the stuff persistent */ AUTHcommit(); @@ -456,8 +380,7 @@ } /** - * Removes the given user from the administration. All scenarios (if - * any) and the password are removed as well. + * Removes the given user from the administration. */ str AUTHremoveUser(Client *c, str *username) { @@ -470,7 +393,6 @@ rethrow("removeUser", tmp, AUTHrequireAdmin(c)); assert(user); assert(pass); - assert(scen); /* pre-condition check */ if (*username == NULL || strNil(*username)) @@ -494,8 +416,6 @@ b = BATmirror(BATselect(BATmirror(pass), &id, &id)); assert(BATcount(b) != 0); BATdel(pass, b, FALSE); - b = BATmirror(BATselect(BATmirror(scen), &id, &id)); - BATdel(scen, b, TRUE); /* make the stuff persistent */ AUTHcommit(); @@ -649,93 +569,29 @@ } /** - * Adds the given scenario to the list of allowed scenarios for the - * given user. Note that this can result in unexpected behaviour when - * there where previously no scenarios defined for the user (which means - * all scenarios are permitted). + * Obsolete function. Retained for ABI compatibility. Should be + * removed with next ABI bump. */ str AUTHaddScenario(Client *c, str *username, str *scenario) { - BUN p; - str tmp; - oid *id; - BAT *b; - BATiter useri; + (void)c; + (void)username; + (void)scenario; - rethrow("addScenario", tmp, AUTHrequireAdmin(c)); - - /* precondition checks */ - if (*username == NULL || strNil(*username)) - throw(ILLARG, "addScenario", "username should not be nil"); - if (*scenario == NULL || strNil(*scenario)) - throw(ILLARG, "addScenario", "scenario should not be nil"); - - /* see if the user is valid */ - p = BUNfnd(BATmirror(user), *username); - if (p == BUN_NONE) - throw(MAL, "addScenario", "user '%s' does not exist", *username); - useri = bat_iterator(user); - id = (oid*)BUNhead(useri, p); - - /* see if this scenario is not already there */ - b = BATselect(BATmirror(scen), id, id); - b = BATselect(BATmirror(b), *scenario, *scenario); - if (BATcount(b) == 1) - throw(MAL, "addScenario", "scenario '%s' already exists for user '%s'", *scenario, *username); - if (BATcount(b) > 1) - throw(MAL, "addScenario", "inconsistent authorisation administration, scenario '%s' multiple times defined", *scenario); - - /* add the scenario for this user, use force as sql makes view over it */ - BUNins(scen, BUNhead(useri, p), *scenario, TRUE); - AUTHcommit(); - - return(MAL_SUCCEED); + throw(MAL, "addScenario", "scenario-based authorisation is no longer supported"); } /** - * Removes the given scenario from the list of allowed scenarios for the - * given user. Note that removing the last allowed scenario results in - * the opposite effect: it will allow any scenario to be used. + * Obsolete function. Retained for ABI compatibility. Should be + * removed with next ABI bump. */ str AUTHremoveScenario(Client *c, str *username, str *scenario) { - BUN p; _______________________________________________ Checkin-list mailing list [email protected] http://mail.monetdb.org/mailman/listinfo/checkin-list
