Class CassandraCIDRAuthorizer

java.lang.Object
org.apache.cassandra.auth.AbstractCIDRAuthorizer
org.apache.cassandra.auth.CassandraCIDRAuthorizer
All Implemented Interfaces:
ICIDRAuthorizer

public class CassandraCIDRAuthorizer extends AbstractCIDRAuthorizer
CassandraCIDRAuthorizer is backend for CIDR authorization checks 1, Provides functionality to populate Role to CIDR permisssions cache and 2, Uses CIDR groups mapping cache as backend to lookup CIDR groups of an IP
  • Field Details

  • Constructor Details

    • CassandraCIDRAuthorizer

      public CassandraCIDRAuthorizer(Map<String,String> params)
  • Method Details

    • setup

      public void setup()
    • initCaches

      public void initCaches()
      Description copied from interface: ICIDRAuthorizer
      Init caches held by CIDR authorizer
    • invalidateCidrPermissionsCache

      public boolean invalidateCidrPermissionsCache(String roleName)
      Description copied from interface: ICIDRAuthorizer
      Invalidate given role from CIDR permissions cache
      Parameters:
      roleName - role to invalidate
      Returns:
      returns true if given role found in the cache and invalidated, false otherwise
    • loadCidrGroupsCache

      public void loadCidrGroupsCache()
      Description copied from interface: ICIDRAuthorizer
      Load CIDR groups mapping cache
    • lookupCidrGroupsForIp

      public Set<String> lookupCidrGroupsForIp(InetAddress ip)
      Description copied from interface: ICIDRAuthorizer
      Lookup IP in CIDR groups mapping cache
      Parameters:
      ip - input IP to lookup CIDR group
      Returns:
      returns best matching CIDR group for this IP
    • isMonitorMode

      protected boolean isMonitorMode()
    • hasAccessFromIp

      public boolean hasAccessFromIp(RoleResource role, InetAddress ipAddress)
      Description copied from interface: ICIDRAuthorizer
      Determines does the given role has access from CIDR groups associated with given IP
      Parameters:
      role - role to check access
      ipAddress - IP of the client
      Returns:
      returns true if role has access from given IP, false otherwise