2 // ========================================================================
3 // Copyright (c) 1995-2014 Mort Bay Consulting Pty. Ltd.
4 // ------------------------------------------------------------------------
5 // All rights reserved. This program and the accompanying materials
6 // are made available under the terms of the Eclipse Public License v1.0
7 // and Apache License v2.0 which accompanies this distribution.
9 // The Eclipse Public License is available at
10 // http://www.eclipse.org/legal/epl-v10.html
12 // The Apache License v2.0 is available at
13 // http://www.opensource.org/licenses/apache2.0.php
15 // You may elect to redistribute this code under either of these licenses.
16 // ========================================================================
19 package org.eclipse.jetty.security;
21 import java.security.Principal;
23 import javax.security.auth.Subject;
25 import org.eclipse.jetty.server.Request;
26 import org.eclipse.jetty.server.UserIdentity;
28 /* ------------------------------------------------------------ */
30 * Associates UserIdentities from with threads and UserIdentity.Contexts.
33 public interface IdentityService
35 final static String[] NO_ROLES = new String[]{};
37 /* ------------------------------------------------------------ */
39 * Associate a user identity with the current thread.
40 * This is called with as a thread enters the
41 * {@link SecurityHandler#handle(String, Request, javax.servlet.http.HttpServletRequest, javax.servlet.http.HttpServletResponse)}
42 * method and then again with a null argument as that call exits.
43 * @param user The current user or null for no user to associated.
44 * @return an object representing the previous associated state
46 Object associate(UserIdentity user);
48 /* ------------------------------------------------------------ */
50 * Disassociate the user identity from the current thread
51 * and restore previous identity.
52 * @param previous The opaque object returned from a call to {@link IdentityService#associate(UserIdentity)}
54 void disassociate(Object previous);
56 /* ------------------------------------------------------------ */
58 * Associate a runas Token with the current user and thread.
59 * @param user The UserIdentity
60 * @param token The runAsToken to associate.
61 * @return The previous runAsToken or null.
63 Object setRunAs(UserIdentity user, RunAsToken token);
65 /* ------------------------------------------------------------ */
67 * Disassociate the current runAsToken from the thread
68 * and reassociate the previous token.
69 * @param token RUNAS returned from previous associateRunAs call
71 void unsetRunAs(Object token);
73 /* ------------------------------------------------------------ */
75 * Create a new UserIdentity for use with this identity service.
76 * The UserIdentity should be immutable and able to be cached.
78 * @param subject Subject to include in UserIdentity
79 * @param userPrincipal Principal to include in UserIdentity. This will be returned from getUserPrincipal calls
80 * @param roles set of roles to include in UserIdentity.
81 * @return A new immutable UserIdententity
83 UserIdentity newUserIdentity(Subject subject, Principal userPrincipal, String[] roles);
85 /* ------------------------------------------------------------ */
87 * Create a new RunAsToken from a runAsName (normally a role).
88 * @param runAsName Normally a role name
89 * @return A new immutable RunAsToken
91 RunAsToken newRunAsToken(String runAsName);
93 /* ------------------------------------------------------------ */
94 UserIdentity getSystemUserIdentity();