annotate Lib/IMPL/Web/Security.pm @ 108:c6fb6964de4c

Removed absolute modules Updated DOM model, selectNodes can now select a complex path Web DOM model release candidate
author wizard
date Fri, 14 May 2010 16:06:06 +0400
parents 0e72ad99eef7
children 1722ca51537c
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
52
15d720913562 security in work
wizard@linux-odin.local
parents:
diff changeset
1 package IMPL::Web::Security;
81
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
2 use strict;
73
wizard
parents: 66
diff changeset
3 use base qw(IMPL::Object IMPL::Security IMPL::Object::Autofill);
wizard
parents: 66
diff changeset
4
81
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
5 require IMPL::Web::Security::Session;
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
6
73
wizard
parents: 66
diff changeset
7 use IMPL::Class::Property;
81
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
8 use IMPL::Security::Auth qw(:Const);
73
wizard
parents: 66
diff changeset
9
wizard
parents: 66
diff changeset
10 __PACKAGE__->PassThroughArgs;
wizard
parents: 66
diff changeset
11
wizard
parents: 66
diff changeset
12 BEGIN {
81
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
13 public property sourceUser => prop_all;
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
14 public property sourceSession => prop_all;
73
wizard
parents: 66
diff changeset
15 }
wizard
parents: 66
diff changeset
16
107
0e72ad99eef7 Updated Web::TT
wizard
parents: 97
diff changeset
17 sub CTOR {
0e72ad99eef7 Updated Web::TT
wizard
parents: 97
diff changeset
18 my ($this) = @_;
0e72ad99eef7 Updated Web::TT
wizard
parents: 97
diff changeset
19
0e72ad99eef7 Updated Web::TT
wizard
parents: 97
diff changeset
20 die new IMPL::InvalidArgumentException("An argument is required",'sourceUser') unless $this->sourceUser;
0e72ad99eef7 Updated Web::TT
wizard
parents: 97
diff changeset
21 die new IMPL::InvalidArgumentException("An argument is required",'sourceSession') unless $this->sourceSession;
0e72ad99eef7 Updated Web::TT
wizard
parents: 97
diff changeset
22 }
0e72ad99eef7 Updated Web::TT
wizard
parents: 97
diff changeset
23
81
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
24 sub AuthUser {
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
25 my ($this,$name,$package,$challenge) = @_;
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
26
97
964587c5183c Added SecureCall to Web QueryHandlers stack
wizard
parents: 94
diff changeset
27 my $user = $this->sourceUser->find({name => $name}) or return { status => AUTH_FAIL, answer => "Can't find a user '$name'" };
81
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
28
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
29 my $auth;
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
30 if ( my $secData = $user->secData($package) ) {
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
31 $auth = $package->new($secData);
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
32 } else {
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
33 die new IMPL::SecurityException("Authentication failed","A sec data for the $package isn't found");
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
34 }
79
2d1c3f713280 ORM concept in development
wizard
parents: 73
diff changeset
35
81
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
36 my ($status,$answer) = $auth->DoAuth($challenge);
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
37
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
38 if ($status == AUTH_FAIL) {
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
39 die new IMPL::SecurityException("Authentication failed","DoAuth failed");
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
40 }
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
41
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
42 return {
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
43 status => $status,
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
44 answer => $answer,
94
79bf75223afe Fixed security related bugs
wizard
parents: 87
diff changeset
45 context => $this->MakeContext( $user, [$user->roles], $auth )
81
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
46 }
73
wizard
parents: 66
diff changeset
47 }
wizard
parents: 66
diff changeset
48
81
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
49 sub MakeContext {
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
50 my ($this,$principal,$roles,$auth) = @_;
73
wizard
parents: 66
diff changeset
51
83
74bae30eb25e (no commit message)
wizard
parents: 81
diff changeset
52 return $this->sourceSession->create(
81
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
53 {
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
54 principal => $principal,
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
55 rolesAssigned => $roles,
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
56 auth => $auth
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
57 }
077357224bec IMPL::Web::Security alpha version
Sergey
parents: 79
diff changeset
58 );
73
wizard
parents: 66
diff changeset
59 }
wizard
parents: 66
diff changeset
60
52
15d720913562 security in work
wizard@linux-odin.local
parents:
diff changeset
61 1;
15d720913562 security in work
wizard@linux-odin.local
parents:
diff changeset
62
15d720913562 security in work
wizard@linux-odin.local
parents:
diff changeset
63 __END__
15d720913562 security in work
wizard@linux-odin.local
parents:
diff changeset
64
15d720913562 security in work
wizard@linux-odin.local
parents:
diff changeset
65 =pod
15d720913562 security in work
wizard@linux-odin.local
parents:
diff changeset
66
73
wizard
parents: 66
diff changeset
67 =head1 NAME
wizard
parents: 66
diff changeset
68
wizard
parents: 66
diff changeset
69 C<IMPL::Web::Security> Модуль для аутентификации и авторизации веб запроса.
wizard
parents: 66
diff changeset
70
wizard
parents: 66
diff changeset
71 =head1 SINOPSYS
wizard
parents: 66
diff changeset
72
wizard
parents: 66
diff changeset
73 =begin code xml
wizard
parents: 66
diff changeset
74
wizard
parents: 66
diff changeset
75 <security type='IMPL::Config::Activator'>
wizard
parents: 66
diff changeset
76 <factory>IMPL::Web::Security</factory>
wizard
parents: 66
diff changeset
77 <parameters type='HASH'>
wizard
parents: 66
diff changeset
78 <sessionFactory type='IMPL::Object::Factory'>
wizard
parents: 66
diff changeset
79 <factory type='IMPL::Object::Factory'>App::Data::Session</factory>
wizard
parents: 66
diff changeset
80 <method>insert</method>
wizard
parents: 66
diff changeset
81 </sessionFactory>
wizard
parents: 66
diff changeset
82 </parameters>
wizard
parents: 66
diff changeset
83 </security>
wizard
parents: 66
diff changeset
84
wizard
parents: 66
diff changeset
85 =end code xml
wizard
parents: 66
diff changeset
86
52
15d720913562 security in work
wizard@linux-odin.local
parents:
diff changeset
87 =head1 DESCRIPTION
15d720913562 security in work
wizard@linux-odin.local
parents:
diff changeset
88
73
wizard
parents: 66
diff changeset
89 Отвечает за инфраструктуру аутентификации и авторизации запросов. Основная особенность
wizard
parents: 66
diff changeset
90 заключается в том, что запросы приходят через значительные интевалы времени, хотя и
wizard
parents: 66
diff changeset
91 относятся к одной логической транзакции. В промежутках между запросами сервер не
wizard
parents: 66
diff changeset
92 сохраняет свое состояние. Поэтому при каждом обращении сервер восстанавливает
wizard
parents: 66
diff changeset
93 контекст безопасности.
52
15d720913562 security in work
wizard@linux-odin.local
parents:
diff changeset
94
73
wizard
parents: 66
diff changeset
95 C<IMPL::Web::Session> Объект обеспечивающий сохранение состояния в рамках одной сессии
wizard
parents: 66
diff changeset
96 пользователя. Кроме контекста безопасности хранит дополнительние данные, которые необходимо
wizard
parents: 66
diff changeset
97 сохранить между обработкой запросов.
52
15d720913562 security in work
wizard@linux-odin.local
parents:
diff changeset
98
73
wizard
parents: 66
diff changeset
99 C<IMPL::Web::User> Объект, устанавливающий связь между идентификатором пользователя
wizard
parents: 66
diff changeset
100 C<IMPL::Security::Principal>, его ролями и данными безопасности для создания объектов
wizard
parents: 66
diff changeset
101 аутентификации C<IMPL::Security::Auth>.
52
15d720913562 security in work
wizard@linux-odin.local
parents:
diff changeset
102
73
wizard
parents: 66
diff changeset
103 =head1 MEMBERS
52
15d720913562 security in work
wizard@linux-odin.local
parents:
diff changeset
104
15d720913562 security in work
wizard@linux-odin.local
parents:
diff changeset
105 =cut