Author: dj
Date: Wed Aug 17 07:44:36 2016
New Revision: 1756588
URL: http://svn.apache.org/viewvc?rev=1756588&view=rev
Log:
OAK-4678 : Backport OAK-4344 and OAK-4005
Modified:
jackrabbit/oak/branches/1.2/ (props changed)
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/main/java/org/apache/jackrabbit/oak/security/authentication/ldap/impl/LdapIdentityProvider.java
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/main/java/org/apache/jackrabbit/oak/security/authentication/ldap/impl/LdapProviderConfig.java
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/test/java/org/apache/jackrabbit/oak/security/authentication/ldap/LargeLdapProviderTest.java
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/test/java/org/apache/jackrabbit/oak/security/authentication/ldap/LdapProviderTest.java
Propchange: jackrabbit/oak/branches/1.2/
------------------------------------------------------------------------------
--- svn:mergeinfo (original)
+++ svn:mergeinfo Wed Aug 17 07:44:36 2016
@@ -1,4 +1,4 @@
/jackrabbit/oak/branches/1.0:1665962
/jackrabbit/oak/branches/1.4:1745750,1747354,1750078,1750512
-/jackrabbit/oak/trunk:1672350,1672468,1672537,1672603,1672611,1672642,1672644,1672834-1672835,1673351,1673410,1673414-1673415,1673436,1673644,1673662-1673664,1673669,1673695,1673713,1673738,1673787,1673791,1674046,1674065,1674075,1674107,1674228,1674780,1674880,1675054-1675055,1675319,1675332,1675354,1675357,1675382,1675555,1675566,1675593,1676198,1676237,1676407,1676458,1676539,1676670,1676693,1676703,1676725,1677579,1677581,1677609,1677611,1677774,1677788,1677797,1677804,1677806,1677939,1677991,1678023,1678095-1678096,1678124,1678171,1678173,1678202,1678211,1678323,1678758,1678938,1678954,1679144,1679165,1679191,1679232,1679235,1679503,1679958,1679961,1680170,1680172,1680182,1680222,1680232,1680236,1680461,1680633,1680643,1680747,1680805-1680806,1680903,1681282,1681767,1681918,1681921,1681955,1682042,1682218,1682235,1682437,1682488,1682494,1682555,1682855,1682904,1683059,1683089,1683213,1683249,1683259,1683278,1683323,1683687,1683700,1684174-1684175,1684186,1684376,1684442,1684561
,1684570,1684601,1684618,1684669,1684820,1684868,1684894,1685023,1685075,1685370,1685541,1685552,1685589-1685590,1685840,1685964,1685977,1685989,1685999,1686003,1686023,1686032,1686097,1686162,1686229,1686234,1686253,1686414,1686772,1686780,1686790,1686854,1686857,1686971,1687053-1687055,1687175,1687196,1687198,1687220,1687239-1687240,1687301,1687441,1687553,1688089-1688090,1688172,1688179,1688349,1688421,1688436,1688453,1688616,1688622,1688634,1688636,1688817,1689003-1689004,1689008,1689577,1689581,1689623,1689810,1689828,1689831,1689833,1689903,1690017,1690043,1690047,1690057,1690247,1690249,1690634-1690637,1690650,1690657,1690669,1690672,1690674,1690885,1690941,1691139,1691151,1691159,1691167,1691183,1691188,1691201,1691210,1691217-1691218,1691280,1691307,1691331-1691333,1691345,1691384-1691385,1691394,1691401,1691498,1691509,1692133-1692134,1692156,1692250,1692272,1692274,1692363,1692382,1692393,1692478,1692955,1693002,1693030,1693050,1693209,1693401,1693421,1693525-1693526,1694
007,1694393-1694394,1694651,1694653-1694654,1695032,1695050,1695122,1695280,1695299,1695420,1695457,1695482,1695492,1695507,1695521,1695540,1695571,1695829-1695830,1695905,1696190,1696194,1696242,1696285,1696375,1696522,1696578,1696759,1696916,1697363,1697373,1697383,1697410,1697582,1697589,1697616,1697672,1697896,1698096,1698144,1700191,1700231,1700397,1700403,1700506,1700571,1700709,1700718,1700720,1700727,1700749,1700769,1700775,1701065,1701613,1701619,1701733,1701743,1701750,1701768,1701806,1701810,1701814,1701907,1701948,1701955,1701959,1701965,1701986,1702014,1702022,1702045,1702051,1702241,1702272,1702371,1702387,1702405,1702423,1702426,1702428,1702860,1702866,1702942,1702960,1703212,1703382,1703395,1703411,1703428,1703430,1703568,1703592,1703758,1703858,1703878,1704256,1704282,1704285,1704457,1704479,1704490,1704614,1704629,1704636,1704655,1704670,1704886,1705005,1705027,1705043,1705055,1705250,1705268,1705273,1705323,1705677,1705701,1705871,1705992,1705998,1706009,1706037,1
706059,1706212,1706218,1706270,1706764,1706772,1707049,1707189,1707191,1707331,1707435,1707509,1707753,1708049,1708105,1708307,1708315,1708401,1708546,1708592,1708766,1709012,1709852,1709978,1710013,1710031,1710049,1710205,1710242,1710559,1710575,1710590,1710614,1710637,1710789,1710800,1710811,1710816,1710972,1711248,1711282,1711296,1711405,1711498,1711654,1712018,1712042,1712319,1712490,1712531,1712730,1712785,1712963,1713008,1713439,1713461,1713580,1713586,1713599-1713600,1713626,1713698,1713803,1713809,1714034,1714061,1714084,1714170,1714213,1714229,1714238,1714519-1714520,1714543-1714544,1714730,1714739,1714779,1714956,1714961,1715010,1715092,1715191,1715346,1715716,1715767,1715771,1715888,1715898,1716100,1716178,1716426,1716576,1716588-1716589,1716596,1716616,1716703,1716712,1716815,1716823,1716830,1716883,1717203,1717277,1717393-1717394,1717410,1717462,1717632,1717768-1717769,1717784,1717789,1717988,1718528,1718533,1718547-1718548,1718626,1718646,1718772,1718801-1718802,171889
5,1719111,1719288,1719869,1720306,1720335,1720350,1720354,1720500,1721160,1721172,1721337,1722141,1722832,1723227,1723239,1723241,1723251,1723254,1723333,1723347,1723350,1723565,1723584,1723713,1723731,1724026,1724057,1724186,1724210,1724401,1724628,1724631,1725216,1725477,1725515,1725555,1725895,1725899,1725935,1725941,1725960,1726232,1726237,1726570,1726579,1726585-1726586,1726621,1726795,1726797,1726809,1726812,1726981,1726993,1727026,1727254,1727331,1727350,1727358,1727429,1727476,1727483,1727508,1727515-1727518,1727813,1727816,1727831-1727832,1727841,1727893,1727895,1727912-1727913,1727923,1727991,1728037,1728041,1728070,1728114,1728281,1728443,1728525,1728642,1729200,1729505,1729599,1729957,1729979,1730216,1730527,1730581,1730629,1730801,1731627,1731647-1731648,1731789,1731797,1732131,1732268,1732278,1732330,1732647-1732648,1732864,1733615,1733929,1734230,1734254,1735052,1735405,1735484,1735588,1736176,1737309-1737310,1737334,1737349,1738833,1738950,1738957,1739894,1740116,174
0626,1740971,1741032,1741339,1741343,1742520,1742888,1742916,1743097,1743172,1743343,1744265,1744959,1745038,1745197,1746117,1746696,1746981,1747341-1747342,1747492,1748505,1748553,1748722,1748870,1749350,1749464,1749475,1749645,1749662,1749815,1749872,1749875,1749899,1750052,1750076-1750077,1750287,1750457,1750462,1750465,1750495,1750626,1750809,1750886,1751410,1751445-1751446,1751478,1751755,1752273-1752274,1752438,1752508,1752659,1752672,1753262,1753331-1753332,1753355,1753444,1754117,1754239,1755366
+/jackrabbit/oak/trunk:1672350,1672468,1672537,1672603,1672611,1672642,1672644,1672834-1672835,1673351,1673410,1673414-1673415,1673436,1673644,1673662-1673664,1673669,1673695,1673713,1673738,1673787,1673791,1674046,1674065,1674075,1674107,1674228,1674780,1674880,1675054-1675055,1675319,1675332,1675354,1675357,1675382,1675555,1675566,1675593,1676198,1676237,1676407,1676458,1676539,1676670,1676693,1676703,1676725,1677579,1677581,1677609,1677611,1677774,1677788,1677797,1677804,1677806,1677939,1677991,1678023,1678095-1678096,1678124,1678171,1678173,1678202,1678211,1678323,1678758,1678938,1678954,1679144,1679165,1679191,1679232,1679235,1679503,1679958,1679961,1680170,1680172,1680182,1680222,1680232,1680236,1680461,1680633,1680643,1680747,1680805-1680806,1680903,1681282,1681767,1681918,1681921,1681955,1682042,1682218,1682235,1682437,1682488,1682494,1682555,1682855,1682904,1683059,1683089,1683213,1683249,1683259,1683278,1683323,1683687,1683700,1684174-1684175,1684186,1684376,1684442,1684561
,1684570,1684601,1684618,1684669,1684820,1684868,1684894,1685023,1685075,1685370,1685541,1685552,1685589-1685590,1685840,1685964,1685977,1685989,1685999,1686003,1686023,1686032,1686097,1686162,1686229,1686234,1686253,1686414,1686772,1686780,1686790,1686854,1686857,1686971,1687053-1687055,1687175,1687196,1687198,1687220,1687239-1687240,1687301,1687441,1687553,1688089-1688090,1688172,1688179,1688349,1688421,1688436,1688453,1688616,1688622,1688634,1688636,1688817,1689003-1689004,1689008,1689577,1689581,1689623,1689810,1689828,1689831,1689833,1689903,1690017,1690043,1690047,1690057,1690247,1690249,1690634-1690637,1690650,1690657,1690669,1690672,1690674,1690885,1690941,1691139,1691151,1691159,1691167,1691183,1691188,1691201,1691210,1691217-1691218,1691280,1691307,1691331-1691333,1691345,1691384-1691385,1691394,1691401,1691498,1691509,1692133-1692134,1692156,1692250,1692272,1692274,1692363,1692382,1692393,1692478,1692955,1693002,1693030,1693050,1693209,1693401,1693421,1693525-1693526,1694
007,1694393-1694394,1694651,1694653-1694654,1695032,1695050,1695122,1695280,1695299,1695420,1695457,1695482,1695492,1695507,1695521,1695540,1695571,1695829-1695830,1695905,1696190,1696194,1696242,1696285,1696375,1696522,1696578,1696759,1696916,1697363,1697373,1697383,1697410,1697582,1697589,1697616,1697672,1697896,1698096,1698144,1700191,1700231,1700397,1700403,1700506,1700571,1700709,1700718,1700720,1700727,1700749,1700769,1700775,1701065,1701613,1701619,1701733,1701743,1701750,1701768,1701806,1701810,1701814,1701907,1701948,1701955,1701959,1701965,1701986,1702014,1702022,1702045,1702051,1702241,1702272,1702371,1702387,1702405,1702423,1702426,1702428,1702860,1702866,1702942,1702960,1703212,1703382,1703395,1703411,1703428,1703430,1703568,1703592,1703758,1703858,1703878,1704256,1704282,1704285,1704457,1704479,1704490,1704614,1704629,1704636,1704655,1704670,1704886,1705005,1705027,1705043,1705055,1705250,1705268,1705273,1705323,1705677,1705701,1705871,1705992,1705998,1706009,1706037,1
706059,1706212,1706218,1706270,1706764,1706772,1707049,1707189,1707191,1707331,1707435,1707509,1707753,1708049,1708105,1708307,1708315,1708401,1708546,1708592,1708766,1709012,1709852,1709978,1710013,1710031,1710049,1710205,1710242,1710559,1710575,1710590,1710614,1710637,1710789,1710800,1710811,1710816,1710972,1711248,1711282,1711296,1711405,1711498,1711654,1712018,1712042,1712319,1712490,1712531,1712730,1712785,1712963,1713008,1713439,1713461,1713580,1713586,1713599-1713600,1713626,1713698,1713803,1713809,1714034,1714061,1714084,1714170,1714213,1714229,1714238,1714519-1714520,1714543-1714544,1714730,1714739,1714779,1714956,1714961,1715010,1715092,1715191,1715346,1715716,1715767,1715771,1715888,1715898,1716100,1716178,1716426,1716576,1716588-1716589,1716596,1716616,1716703,1716712,1716815,1716823,1716830,1716883,1717203,1717277,1717393-1717394,1717410,1717462,1717632,1717768-1717769,1717784,1717789,1717988,1718528,1718533,1718547-1718548,1718626,1718646,1718772,1718801-1718802,171889
5,1719111,1719288,1719869,1720306,1720335,1720350,1720354,1720500,1721160,1721172,1721337,1722141,1722832,1723227,1723239,1723241,1723251,1723254,1723333,1723347,1723350,1723565,1723584,1723713,1723731,1724026,1724057,1724186,1724210,1724401,1724628,1724631,1725216,1725477,1725515,1725555,1725895,1725899,1725935,1725941,1725960,1726232,1726237,1726570,1726579,1726585-1726586,1726621,1726795,1726797,1726809,1726812,1726981,1726993,1727026,1727254,1727331,1727350,1727358,1727429,1727476,1727483,1727508,1727515-1727518,1727813,1727816,1727831-1727832,1727841,1727893,1727895,1727912-1727913,1727923,1727991,1728037,1728041,1728070,1728114,1728281,1728443,1728525,1728642,1729200,1729505,1729599,1729957,1729979,1730216,1730527,1730581,1730629,1730801,1731627,1731647-1731648,1731789,1731797,1732131,1732268,1732278,1732330,1732647-1732648,1732864,1733615,1733929,1734230,1734254,1735052,1735267,1735405,1735484,1735588,1736176,1737309-1737310,1737334,1737349,1738833,1738950,1738957,1739894,174
0116,1740626,1740971,1741032,1741339,1741343,1742520,1742888,1742916,1743097,1743172,1743343,1744265,1744959,1745038,1745197,1746117,1746696,1746981,1747341-1747342,1747492,1748505,1748553,1748722,1748870,1749350,1749464,1749475,1749645,1749662,1749815,1749872,1749875,1749899,1750052,1750076-1750077,1750287,1750457,1750462,1750465,1750495,1750626,1750809,1750886,1751410,1751445-1751446,1751478,1751755,1752198,1752202,1752273-1752274,1752438,1752508,1752659,1752672,1753262,1753331-1753332,1753355,1753444,1754117,1754239,1755366
/jackrabbit/trunk:1345480
Modified:
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/main/java/org/apache/jackrabbit/oak/security/authentication/ldap/impl/LdapIdentityProvider.java
URL:
http://svn.apache.org/viewvc/jackrabbit/oak/branches/1.2/oak-auth-ldap/src/main/java/org/apache/jackrabbit/oak/security/authentication/ldap/impl/LdapIdentityProvider.java?rev=1756588&r1=1756587&r2=1756588&view=diff
==============================================================================
---
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/main/java/org/apache/jackrabbit/oak/security/authentication/ldap/impl/LdapIdentityProvider.java
(original)
+++
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/main/java/org/apache/jackrabbit/oak/security/authentication/ldap/impl/LdapIdentityProvider.java
Wed Aug 17 07:44:36 2016
@@ -21,9 +21,9 @@ import java.util.ArrayList;
import java.util.Collections;
import java.util.HashMap;
import java.util.Iterator;
-import java.util.LinkedList;
import java.util.List;
import java.util.Map;
+import java.util.NoSuchElementException;
import javax.annotation.CheckForNull;
import javax.annotation.Nonnull;
@@ -44,13 +44,7 @@ import org.apache.directory.api.ldap.mod
import
org.apache.directory.api.ldap.model.exception.LdapAuthenticationException;
import org.apache.directory.api.ldap.model.exception.LdapException;
import
org.apache.directory.api.ldap.model.exception.LdapInvalidAttributeValueException;
-import org.apache.directory.api.ldap.model.message.Response;
-import org.apache.directory.api.ldap.model.message.ResultCodeEnum;
-import org.apache.directory.api.ldap.model.message.SearchRequest;
-import org.apache.directory.api.ldap.model.message.SearchRequestImpl;
-import org.apache.directory.api.ldap.model.message.SearchResultDone;
-import org.apache.directory.api.ldap.model.message.SearchResultEntry;
-import org.apache.directory.api.ldap.model.message.SearchScope;
+import org.apache.directory.api.ldap.model.message.*;
import org.apache.directory.api.ldap.model.message.controls.PagedResults;
import org.apache.directory.api.ldap.model.name.Dn;
import org.apache.directory.api.ldap.model.name.Rdn;
@@ -220,7 +214,7 @@ public class LdapIdentityProvider implem
LdapConnection connection = connect();
timer.mark("connect");
try {
- Entry entry = getEntry(connection, config.getUserConfig(), userId);
+ Entry entry = getEntry(connection, config.getUserConfig(), userId,
config.getCustomAttributes());
timer.mark("lookup");
if (log.isDebugEnabled()) {
log.debug("getUser({}) {}", userId, timer.getString());
@@ -245,7 +239,7 @@ public class LdapIdentityProvider implem
LdapConnection connection = connect();
timer.mark("connect");
try {
- Entry entry = getEntry(connection, config.getGroupConfig(), name);
+ Entry entry = getEntry(connection, config.getGroupConfig(), name,
config.getCustomAttributes());
timer.mark("lookup");
if (log.isDebugEnabled()) {
log.debug("getGroup({}) {}", name, timer.getString());
@@ -267,19 +261,10 @@ public class LdapIdentityProvider implem
@Nonnull
@Override
public Iterator<ExternalUser> listUsers() throws ExternalIdentityException
{
- DebugTimer timer = new DebugTimer();
- LdapConnection connection = connect();
- timer.mark("connect");
try {
- final List<Entry> entries = getEntries(connection,
config.getUserConfig());
- timer.mark("lookup");
- if (log.isDebugEnabled()) {
- log.debug("listUsers() {}", timer.getString());
- }
+ final Iterator<Entry> iter =
getEntryIterator(config.getUserConfig());
return new AbstractLazyIterator<ExternalUser>() {
- private final Iterator<Entry> iter = entries.iterator();
-
@Override
protected ExternalUser getNext() {
while (iter.hasNext()) {
@@ -293,30 +278,19 @@ public class LdapIdentityProvider implem
}
};
} catch (LdapException e) {
- throw lookupFailedException(e, timer);
+ throw lookupFailedException(e, null);
} catch (CursorException e) {
- throw lookupFailedException(e, timer);
- } finally {
- disconnect(connection);
+ throw lookupFailedException(e, null);
}
}
@Nonnull
@Override
public Iterator<ExternalGroup> listGroups() throws
ExternalIdentityException {
- DebugTimer timer = new DebugTimer();
- LdapConnection connection = connect();
- timer.mark("connect");
try {
- final List<Entry> entries = getEntries(connection,
config.getGroupConfig());
- timer.mark("lookup");
- if (log.isDebugEnabled()) {
- log.debug("listGroups() {}", timer.getString());
- }
+ final Iterator<Entry> iter =
getEntryIterator(config.getGroupConfig());
return new AbstractLazyIterator<ExternalGroup>() {
- private final Iterator<Entry> iter = entries.iterator();
-
@Override
protected ExternalGroup getNext() {
while (iter.hasNext()) {
@@ -330,11 +304,9 @@ public class LdapIdentityProvider implem
}
};
} catch (LdapException e) {
- throw lookupFailedException(e, timer);
+ throw lookupFailedException(e, null);
} catch (CursorException e) {
- throw lookupFailedException(e, timer);
- } finally {
- disconnect(connection);
+ throw lookupFailedException(e, null);
}
}
@@ -390,6 +362,7 @@ public class LdapIdentityProvider implem
}
//-----------------------------------------------------------< internal
>---
+
/**
* Collects the declared (direct) groups of an identity
* @param ref reference to the identity
@@ -567,14 +540,18 @@ public class LdapIdentityProvider implem
}
@CheckForNull
- private Entry getEntry(@Nonnull LdapConnection connection, @Nonnull
LdapProviderConfig.Identity idConfig, @Nonnull String id)
+ private Entry getEntry(@Nonnull LdapConnection connection, @Nonnull
LdapProviderConfig.Identity idConfig, @Nonnull String id, @Nonnull String[]
customAttributes)
throws CursorException, LdapException {
String searchFilter = idConfig.getSearchFilter(id);
// Create the SearchRequest object
SearchRequest req = new SearchRequestImpl();
req.setScope(SearchScope.SUBTREE);
- req.addAttributes(SchemaConstants.ALL_USER_ATTRIBUTES);
+ if (customAttributes.length == 0) {
+ req.addAttributes(SchemaConstants.ALL_USER_ATTRIBUTES);
+ } else {
+ req.addAttributes(customAttributes);
+ }
req.setTimeLimit((int) config.getSearchTimeout());
req.setBase(new Dn(idConfig.getBaseDN()));
req.setFilter(searchFilter);
@@ -610,13 +587,9 @@ public class LdapIdentityProvider implem
return resultEntry;
}
- /**
- * currently fetch all entries so that we can close the connection
afterwards. maybe switch to an iterator approach
- * later.
- */
+
@Nonnull
- private List<Entry> getEntries(@Nonnull LdapConnection connection,
@Nonnull LdapProviderConfig.Identity idConfig)
- throws CursorException, LdapException {
+ private SearchResultIterator getEntryIterator(@Nonnull
LdapProviderConfig.Identity idConfig) throws LdapException, CursorException,
ExternalIdentityException {
StringBuilder filter = new StringBuilder();
int num = 0;
for (String objectClass: idConfig.getObjectClasses()) {
@@ -634,37 +607,97 @@ public class LdapIdentityProvider implem
? "(&" + filter + ')'
: filter.toString();
- // do paged searches (OAK-2874)
- int pageSize = 1000;
- byte[] cookie = null;
+ return new SearchResultIterator(searchFilter, idConfig);
+ }
- List<Entry> result = new LinkedList<Entry>();
- do {
+ private final class SearchResultIterator implements Iterator<Entry> {
- // Create the SearchRequest object
+ private final String searchFilter;
+ private final LdapProviderConfig.Identity idConfig;
+
+ private byte[] cookie;
+ private List page = Collections.emptyList();
+ private boolean searchComplete;
+ private int pos = -1;
+
+ public SearchResultIterator(
+ @Nonnull String searchFilter,
+ @Nonnull LdapProviderConfig.Identity idConfig) throws
LdapException, CursorException, ExternalIdentityException {
+ this.searchFilter = searchFilter;
+ this.idConfig = idConfig;
+ findNextEntry();
+ }
+
+ //-------------------------------------------------------< Iterator
>---
+
+ @Override
+ public boolean hasNext() {
+ return pos >= 0;
+ }
+
+ @Override
+ public Entry next() {
+ if (hasNext()) {
+ try {
+ Entry entry = (Entry) page.get(pos);
+ findNextEntry();
+ return entry;
+ } catch (LdapException e) {
+ log.error("Error while performing LDAP search", e);
+ } catch (CursorException e) {
+ log.error("Error while performing LDAP search", e);
+ } catch (ExternalIdentityException e) {
+ log.error("Error while performing LDAP search", e);
+ }
+ }
+ throw new NoSuchElementException();
+ }
+
+ @Override
+ public void remove() {
+ throw new UnsupportedOperationException();
+ }
+
+ //-------------------------------------------------------< internal
>---
+
+ private SearchRequest createSearchRequest(LdapConnection connection,
byte[] cookie, @Nonnull String[] userAttributes) throws LdapException {
SearchRequest req = new SearchRequestImpl();
req.setScope(SearchScope.SUBTREE);
- req.addAttributes(SchemaConstants.ALL_USER_ATTRIBUTES);
+ if (userAttributes.length == 0) {
+ req.addAttributes(SchemaConstants.ALL_USER_ATTRIBUTES);
+ } else {
+ req.addAttributes(userAttributes);
+ }
req.setTimeLimit((int) config.getSearchTimeout());
req.setBase(new Dn(idConfig.getBaseDN()));
req.setFilter(searchFilter);
PagedResults pagedSearchControl = new
PagedResultsDecorator(connection.getCodecService());
- pagedSearchControl.setSize(pageSize);
+ // do paged searches (OAK-2874)
+ pagedSearchControl.setSize(1000);
pagedSearchControl.setCookie(cookie);
req.addControl(pagedSearchControl);
- // Process the request
+ return req;
+ }
+
+ private boolean loadNextPage() throws ExternalIdentityException,
LdapException, CursorException {
+ if (searchComplete) {
+ return false;
+ }
SearchCursor searchCursor = null;
+ DebugTimer timer = new DebugTimer();
+ LdapConnection connection = connect();
+ timer.mark("connect");
+ page = new ArrayList<Entry>();
try {
- searchCursor = connection.search(req);
+ searchCursor =
connection.search(createSearchRequest(connection, cookie,
config.getCustomAttributes()));
while (searchCursor.next()) {
Response response = searchCursor.get();
- // process the SearchResultEntry
if (response instanceof SearchResultEntry) {
Entry resultEntry = ((SearchResultEntry)
response).getEntry();
- result.add(resultEntry);
+ page.add(resultEntry);
if (log.isDebugEnabled()) {
log.debug("search below {} with {} found {}",
idConfig.getBaseDN(), searchFilter, resultEntry.getDn());
}
@@ -673,27 +706,38 @@ public class LdapIdentityProvider implem
SearchResultDone done = searchCursor.getSearchResultDone();
cookie = null;
- if (done.getLdapResult().getResultCode() ==
ResultCodeEnum.UNWILLING_TO_PERFORM) {
- break;
- }
+ if (done.getLdapResult().getResultCode() !=
ResultCodeEnum.UNWILLING_TO_PERFORM) {
- PagedResults ctrl = (PagedResults)
done.getControl(PagedResults.OID);
- if (ctrl != null) {
- cookie = ctrl.getCookie();
+ PagedResults ctrl = (PagedResults)
done.getControl(PagedResults.OID);
+ if (ctrl != null) {
+ cookie = ctrl.getCookie();
+ }
}
+ searchComplete = cookie == null;
+ timer.mark("lookup");
+ return !page.isEmpty();
} finally {
if (searchCursor != null) {
searchCursor.close();
}
+ disconnect(connection);
}
+ }
- } while (cookie != null);
-
- if (log.isDebugEnabled()) {
- log.debug("search below {} with {} found {} entries.",
idConfig.getBaseDN(), searchFilter, result.size());
+ private void findNextEntry() throws LdapException, CursorException,
ExternalIdentityException {
+ if (pos == -1 && !loadNextPage()) {
+ return;
+ }
+ if (pos + 1 == page.size()) {
+ pos = -1;
+ page = Collections.emptyList();
+ if (!loadNextPage()) {
+ return;
+ }
+ }
+ pos++;
}
- return result;
}
@Nonnull
Modified:
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/main/java/org/apache/jackrabbit/oak/security/authentication/ldap/impl/LdapProviderConfig.java
URL:
http://svn.apache.org/viewvc/jackrabbit/oak/branches/1.2/oak-auth-ldap/src/main/java/org/apache/jackrabbit/oak/security/authentication/ldap/impl/LdapProviderConfig.java?rev=1756588&r1=1756587&r2=1756588&view=diff
==============================================================================
---
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/main/java/org/apache/jackrabbit/oak/security/authentication/ldap/impl/LdapProviderConfig.java
(original)
+++
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/main/java/org/apache/jackrabbit/oak/security/authentication/ldap/impl/LdapProviderConfig.java
Wed Aug 17 07:44:36 2016
@@ -403,6 +403,22 @@ public class LdapProviderConfig {
public static final String PARAM_GROUP_MEMBER_ATTRIBUTE =
"group.memberAttribute";
/**
+ * @see Identity#getCustomAttributes()
+ */
+ public static final String[] PARAM_CUSTOM_ATTRIBUTES_DEFAULT = {};
+
+ /**
+ * @see Identity#getCustomAttributes()
+ */
+ @Property(
+ label = "Custom Attributes",
+ description = "Attributes retrieved when looking up LDAP entries.
Leave empty to retrieve all attributes.",
+ value = {},
+ cardinality = Integer.MAX_VALUE
+ )
+ public static final String PARAM_CUSTOM_ATTRIBUTES = "customattributes";
+
+ /**
* Defines the configuration of an identity (user or group).
*/
public class Identity {
@@ -413,6 +429,8 @@ public class LdapProviderConfig {
private String idAttribute;
+ private String[] customAttributes = {};
+
private String extraFilter;
private String filterTemplate;
@@ -575,6 +593,7 @@ public class LdapProviderConfig {
sb.append("baseDN='").append(baseDN).append('\'');
sb.append(",
objectClasses=").append(Arrays.toString(objectClasses));
sb.append(", idAttribute='").append(idAttribute).append('\'');
+ sb.append(",
userAttributes='").append(Arrays.toString(customAttributes));
sb.append(", extraFilter='").append(extraFilter).append('\'');
sb.append(",
filterTemplate='").append(filterTemplate).append('\'');
sb.append(", makeDnPath=").append(makeDnPath);
@@ -666,14 +685,14 @@ public class LdapProviderConfig {
.setNoCertCheck(params.getConfigValue(PARAM_NO_CERT_CHECK,
PARAM_NO_CERT_CHECK_DEFAULT))
.setBindDN(params.getConfigValue(PARAM_BIND_DN,
PARAM_BIND_DN_DEFAULT))
.setBindPassword(params.getConfigValue(PARAM_BIND_PASSWORD,
PARAM_BIND_PASSWORD_DEFAULT))
-
.setGroupMemberAttribute(params.getConfigValue(PARAM_GROUP_MEMBER_ATTRIBUTE,
PARAM_GROUP_MEMBER_ATTRIBUTE_DEFAULT));
+
.setGroupMemberAttribute(params.getConfigValue(PARAM_GROUP_MEMBER_ATTRIBUTE,
PARAM_GROUP_MEMBER_ATTRIBUTE_DEFAULT))
+
.setCustomAttributes(params.getConfigValue(PARAM_CUSTOM_ATTRIBUTES,
PARAM_CUSTOM_ATTRIBUTES_DEFAULT));
ConfigurationParameters.Milliseconds ms =
ConfigurationParameters.Milliseconds.of(params.getConfigValue(PARAM_SEARCH_TIMEOUT,
PARAM_SEARCH_TIMEOUT_DEFAULT));
if (ms != null) {
cfg.setSearchTimeout(ms.value);
}
-
cfg.getUserConfig()
.setBaseDN(params.getConfigValue(PARAM_USER_BASE_DN,
PARAM_USER_BASE_DN))
.setIdAttribute(params.getConfigValue(PARAM_USER_ID_ATTRIBUTE,
PARAM_USER_ID_ATTRIBUTE_DEFAULT))
@@ -721,6 +740,8 @@ public class LdapProviderConfig {
private String memberOfFilterTemplate;
+ private String[] customAttributes = PARAM_CUSTOM_ATTRIBUTES_DEFAULT;
+
private final PoolConfig adminPoolConfig = new PoolConfig()
.setMaxActive(PARAM_ADMIN_POOL_MAX_ACTIVE_DEFAULT);
@@ -963,6 +984,29 @@ public class LdapProviderConfig {
return this;
}
+ /**
+ * Optionally configures an array of attribute names that will be
retrieved when looking up LDAP entries.
+ * Defaults to the empty array indicating that all attributes will be
retrieved.
+ *
+ * @return an array of attribute names. The empty array indicates that all
attributes will be retrieved.
+ */
+ @Nonnull
+ public String[] getCustomAttributes() {
+ return customAttributes;
+ }
+
+ /**
+ * Sets the attribute names to be retrieved when looking up LDAP entries.
The empty array indicates that all attributes will be retrieved.
+ *
+ * @param customAttributes an array of attribute names
+ * @return the Identity instance
+ */
+ @Nonnull
+ public LdapProviderConfig setCustomAttributes(@Nonnull String[]
customAttributes) {
+ this.customAttributes = customAttributes;
+ return this;
+ }
+
/**
* Returns the LDAP filter that is used when searching for groups where an
identity is member of.
* The filter is based on the configuration and has the following format:
Modified:
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/test/java/org/apache/jackrabbit/oak/security/authentication/ldap/LargeLdapProviderTest.java
URL:
http://svn.apache.org/viewvc/jackrabbit/oak/branches/1.2/oak-auth-ldap/src/test/java/org/apache/jackrabbit/oak/security/authentication/ldap/LargeLdapProviderTest.java?rev=1756588&r1=1756587&r2=1756588&view=diff
==============================================================================
---
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/test/java/org/apache/jackrabbit/oak/security/authentication/ldap/LargeLdapProviderTest.java
(original)
+++
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/test/java/org/apache/jackrabbit/oak/security/authentication/ldap/LargeLdapProviderTest.java
Wed Aug 17 07:44:36 2016
@@ -56,7 +56,7 @@ public class LargeLdapProviderTest {
protected static String[] TEST_MEMBERS;
- protected static int NUM_USERS = 100;
+ protected static int NUM_USERS = 2222;
protected static int SIZE_LIMIT = 50;
Modified:
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/test/java/org/apache/jackrabbit/oak/security/authentication/ldap/LdapProviderTest.java
URL:
http://svn.apache.org/viewvc/jackrabbit/oak/branches/1.2/oak-auth-ldap/src/test/java/org/apache/jackrabbit/oak/security/authentication/ldap/LdapProviderTest.java?rev=1756588&r1=1756587&r2=1756588&view=diff
==============================================================================
---
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/test/java/org/apache/jackrabbit/oak/security/authentication/ldap/LdapProviderTest.java
(original)
+++
jackrabbit/oak/branches/1.2/oak-auth-ldap/src/test/java/org/apache/jackrabbit/oak/security/authentication/ldap/LdapProviderTest.java
Wed Aug 17 07:44:36 2016
@@ -29,7 +29,6 @@ import java.util.Map;
import javax.jcr.SimpleCredentials;
import javax.security.auth.login.LoginException;
-import com.google.common.collect.ImmutableMap;
import org.apache.directory.server.constants.ServerDNConstants;
import
org.apache.jackrabbit.oak.security.authentication.ldap.impl.LdapIdentityProvider;
import
org.apache.jackrabbit.oak.security.authentication.ldap.impl.LdapProviderConfig;
@@ -104,13 +103,19 @@ public class LdapProviderTest {
}
protected LdapIdentityProvider createIDP() {
+ //The attribute "mail" is excluded deliberately
+ return createIDP(new String[] { "objectclass", "uid", "givenname",
"description", "sn"});
+ }
+
+ protected LdapIdentityProvider createIDP(String[] userProperties) {
providerConfig = new LdapProviderConfig()
.setName(IDP_NAME)
.setHostname("127.0.0.1")
.setPort(LDAP_SERVER.getPort())
.setBindDN(ServerDNConstants.ADMIN_SYSTEM_DN)
.setBindPassword(InternalLdapServer.ADMIN_PW)
- .setGroupMemberAttribute("uniquemember");
+ .setGroupMemberAttribute("uniquemember")
+ .setCustomAttributes(userProperties);
providerConfig.getUserConfig()
.setBaseDN(ServerDNConstants.USERS_SYSTEM_DN)
@@ -204,10 +209,11 @@ public class LdapProviderTest {
Matchers.equalTo("objectclass"),
Matchers.containsInAnyOrder( "inetOrgPerson", "top",
"person", "organizationalPerson")));
assertThat(properties, Matchers.<String, Object>hasEntry("uid",
"hhornblo"));
- assertThat(properties, Matchers.<String, Object>hasEntry("mail",
"[email protected]"));
assertThat(properties, Matchers.<String, Object>hasEntry("givenname",
"Horatio"));
assertThat(properties, Matchers.<String,
Object>hasEntry("description", "Capt. Horatio Hornblower, R.N"));
assertThat(properties, Matchers.<String, Object>hasEntry("sn",
"Hornblower"));
+
+ assertThat(properties, Matchers.not(Matchers.<String,
Object>hasEntry("mail", "[email protected]")));
}
@Test