1
|
package eu.dnetlib.repo.manager.config;
|
2
|
|
3
|
import com.google.gson.JsonArray;
|
4
|
import com.nimbusds.jwt.JWT;
|
5
|
import eu.dnetlib.repo.manager.service.security.AuthoritiesMapper;
|
6
|
import org.apache.log4j.Logger;
|
7
|
import org.mitre.openid.connect.client.OIDCAuthoritiesMapper;
|
8
|
import org.mitre.openid.connect.model.UserInfo;
|
9
|
import org.springframework.beans.factory.annotation.Value;
|
10
|
import org.springframework.context.annotation.ComponentScan;
|
11
|
import org.springframework.security.core.GrantedAuthority;
|
12
|
import org.springframework.security.core.authority.SimpleGrantedAuthority;
|
13
|
import org.springframework.stereotype.Component;
|
14
|
|
15
|
import java.util.*;
|
16
|
|
17
|
@ComponentScan
|
18
|
@Component
|
19
|
public class OpenAIREAuthoritiesMapper implements OIDCAuthoritiesMapper {
|
20
|
|
21
|
private static final Logger logger = Logger.getLogger(OpenAIREAuthoritiesMapper.class);
|
22
|
|
23
|
@Value("${services.repo-manager.adminEmail}")
|
24
|
String adminEmail;
|
25
|
|
26
|
@Override
|
27
|
public Collection<? extends GrantedAuthority> mapAuthorities(JWT jwtToken, UserInfo userInfo) {
|
28
|
JsonArray entitlements = null;
|
29
|
Set<GrantedAuthority> authorities = new HashSet<>();
|
30
|
if (userInfo != null && userInfo.getSource() != null) {
|
31
|
if (userInfo.getSource().getAsJsonArray("edu_person_entitlements") != null) {
|
32
|
entitlements = userInfo.getSource().getAsJsonArray("edu_person_entitlements");
|
33
|
} else if (userInfo.getSource().getAsJsonArray("eduperson_entitlement") != null) {
|
34
|
entitlements = userInfo.getSource().getAsJsonArray("eduperson_entitlement");
|
35
|
}
|
36
|
logger.debug("user info: " + userInfo + "\nentitlements: " + entitlements);
|
37
|
|
38
|
// FIXME: delete this if statement when super administrators are set
|
39
|
if (userInfo.getEmail() != null && userInfo.getEmail().equals(adminEmail)) {
|
40
|
authorities.add(new SimpleGrantedAuthority("SUPER_ADMINISTRATOR"));
|
41
|
}
|
42
|
|
43
|
authorities.addAll(AuthoritiesMapper.map(entitlements));
|
44
|
}
|
45
|
return authorities;
|
46
|
}
|
47
|
}
|
48
|
|