2 // ========================================================================
3 // Copyright (c) 1995-2014 Mort Bay Consulting Pty. Ltd.
4 // ------------------------------------------------------------------------
5 // All rights reserved. This program and the accompanying materials
6 // are made available under the terms of the Eclipse Public License v1.0
7 // and Apache License v2.0 which accompanies this distribution.
9 // The Eclipse Public License is available at
10 // http://www.eclipse.org/legal/epl-v10.html
12 // The Apache License v2.0 is available at
13 // http://www.opensource.org/licenses/apache2.0.php
15 // You may elect to redistribute this code under either of these licenses.
16 // ========================================================================
19 package org.eclipse.jetty.security;
21 import java.io.IOException;
23 import org.eclipse.jetty.security.PropertyUserStore.UserListener;
24 import org.eclipse.jetty.server.UserIdentity;
25 import org.eclipse.jetty.util.Scanner;
26 import org.eclipse.jetty.util.log.Log;
27 import org.eclipse.jetty.util.log.Logger;
28 import org.eclipse.jetty.util.resource.Resource;
29 import org.eclipse.jetty.util.security.Credential;
31 /* ------------------------------------------------------------ */
33 * Properties User Realm.
35 * An implementation of UserRealm that stores users and roles in-memory in HashMaps.
37 * Typically these maps are populated by calling the load() method or passing a properties resource to the constructor. The format of the properties file is:
40 * username: password [,rolename ...]
43 * Passwords may be clear text, obfuscated or checksummed. The class com.eclipse.Util.Password should be used to generate obfuscated passwords or password
46 * If DIGEST Authentication is used, the password must be in a recoverable format, either plain text or OBF:.
48 public class HashLoginService extends MappedLoginService implements UserListener
50 private static final Logger LOG = Log.getLogger(HashLoginService.class);
52 private PropertyUserStore _propertyUserStore;
53 private String _config;
54 private Resource _configResource;
55 private Scanner _scanner;
56 private int _refreshInterval = 0;// default is not to reload
58 /* ------------------------------------------------------------ */
59 public HashLoginService()
63 /* ------------------------------------------------------------ */
64 public HashLoginService(String name)
69 /* ------------------------------------------------------------ */
70 public HashLoginService(String name, String config)
76 /* ------------------------------------------------------------ */
77 public String getConfig()
82 /* ------------------------------------------------------------ */
83 public void getConfig(String config)
88 /* ------------------------------------------------------------ */
89 public Resource getConfigResource()
91 return _configResource;
94 /* ------------------------------------------------------------ */
96 * Load realm users from properties file. The property file maps usernames to password specs followed by an optional comma separated list of role names.
99 * Filename or url of user properties file.
101 public void setConfig(String config)
106 /* ------------------------------------------------------------ */
107 public void setRefreshInterval(int msec)
109 _refreshInterval = msec;
112 /* ------------------------------------------------------------ */
113 public int getRefreshInterval()
115 return _refreshInterval;
118 /* ------------------------------------------------------------ */
120 protected UserIdentity loadUser(String username)
125 /* ------------------------------------------------------------ */
127 public void loadUsers() throws IOException
129 // TODO: Consider refactoring MappedLoginService to not have to override with unused methods
132 /* ------------------------------------------------------------ */
134 * @see org.eclipse.jetty.util.component.AbstractLifeCycle#doStart()
137 protected void doStart() throws Exception
141 if (_propertyUserStore == null)
143 if(LOG.isDebugEnabled())
144 LOG.debug("doStart: Starting new PropertyUserStore. PropertiesFile: " + _config + " refreshInterval: " + _refreshInterval);
146 _propertyUserStore = new PropertyUserStore();
147 _propertyUserStore.setRefreshInterval(_refreshInterval);
148 _propertyUserStore.setConfig(_config);
149 _propertyUserStore.registerUserListener(this);
150 _propertyUserStore.start();
154 /* ------------------------------------------------------------ */
156 * @see org.eclipse.jetty.util.component.AbstractLifeCycle#doStop()
159 protected void doStop() throws Exception
162 if (_scanner != null)
167 /* ------------------------------------------------------------ */
169 public void update(String userName, Credential credential, String[] roleArray)
171 if (LOG.isDebugEnabled())
172 LOG.debug("update: " + userName + " Roles: " + roleArray.length);
173 putUser(userName,credential,roleArray);
176 /* ------------------------------------------------------------ */
178 public void remove(String userName)
180 if (LOG.isDebugEnabled())
181 LOG.debug("remove: " + userName);
182 removeUser(userName);