Package org.apache.cassandra.auth
Interface IRoleManager
- All Superinterfaces:
AuthCache.BulkLoader<RoleResource,Set<Role>>
- All Known Implementing Classes:
CassandraRoleManager
Responsible for managing roles (which also includes what
used to be known as users), including creation, deletion,
alteration and the granting and revoking of roles to other
roles.
-
Nested Class Summary
Nested ClassesModifier and TypeInterfaceDescriptionstatic enumSupported options for CREATE ROLE/ALTER ROLE (and CREATE USER/ALTER USER, which are aliases provided for backwards compatibility). -
Method Summary
Modifier and TypeMethodDescriptiondefault voidaddIdentity(String identity, String role) Adds a row (identity, role) to the identity_to_role tableSubset of supportedOptions that users are allowed to alter when performing ALTER ROLE [themselves].voidalterRole(AuthenticatedUser performer, RoleResource role, RoleOptions options) Called during execution of ALTER ROLE statement.Returns all the authorized identities from the identity_to_role tablebooleancanLogin(RoleResource role) Return true if there exists a Role with the given name which has login privileges.voidcreateRole(AuthenticatedUser performer, RoleResource role, RoleOptions options) Called during execution of a CREATE ROLE statement.default voiddropIdentity(String identity) Called on the execution of DROP IDENTITY statement for removing a given identity from the identity_role table.voiddropRole(AuthenticatedUser performer, RoleResource role) Called during execution of DROP ROLE statement, as well we removing any main record of the role from the system this implies that we want to revoke this role from all other roles that it has been granted to.Called during the execution of an unqualified LIST ROLES query.getCustomOptions(RoleResource role) Where an implementation supports OPTIONS in CREATE and ALTER operations this method should return theMap<String, String>representing the custom options associated with the role, as supplied to CREATE or ALTER.getRoleDetails(RoleResource grantee) Used to retrieve detailed role info on the full set of roles granted to a grantee.getRoles(RoleResource grantee, boolean includeInherited) Called during execution of a LIST ROLES query.voidgrantRole(AuthenticatedUser performer, RoleResource role, RoleResource grantee) Called during execution of GRANT ROLE query.default booleanisExistingIdentity(String identity) Returns if an identity exists in the identity_to_rolebooleanisExistingRole(RoleResource role) Return true is a Role with the given name exists in the system.booleanisSuper(RoleResource role) Return true if there exists a Role with the given name that also has superuser status.Set of resources that should be made inaccessible to users and only accessible internally.voidrevokeRole(AuthenticatedUser performer, RoleResource role, RoleResource revokee) Called during the execution of a REVOKE ROLE query.default StringroleForIdentity(String identity) Each valid identity is associated with a role in the identity_to_role table, this method returns role of a given identityvoidsetup()Hook to perform implementation specific initialization, called once upon system startup.Set of options supported by CREATE ROLE and ALTER ROLE queries.voidHook to perform validation of an implementation's configuration (if supported).Methods inherited from interface org.apache.cassandra.auth.AuthCache.BulkLoader
bulkLoader
-
Method Details
-
supportedOptions
Set<IRoleManager.Option> supportedOptions()Set of options supported by CREATE ROLE and ALTER ROLE queries. Should never return null - always return an empty set instead. -
alterableOptions
Set<IRoleManager.Option> alterableOptions()Subset of supportedOptions that users are allowed to alter when performing ALTER ROLE [themselves]. Should never return null - always return an empty set instead. -
createRole
void createRole(AuthenticatedUser performer, RoleResource role, RoleOptions options) throws RequestValidationException, RequestExecutionException Called during execution of a CREATE ROLE statement. options are guaranteed to be a subset of supportedOptions().- Parameters:
performer- User issuing the create role statement.role- Rolei being createdoptions- Options the role will be created with- Throws:
RequestValidationExceptionRequestExecutionException
-
dropRole
void dropRole(AuthenticatedUser performer, RoleResource role) throws RequestValidationException, RequestExecutionException Called during execution of DROP ROLE statement, as well we removing any main record of the role from the system this implies that we want to revoke this role from all other roles that it has been granted to.- Parameters:
performer- User issuing the drop role statement.role- Role to be dropped.- Throws:
RequestValidationExceptionRequestExecutionException
-
alterRole
void alterRole(AuthenticatedUser performer, RoleResource role, RoleOptions options) throws RequestValidationException, RequestExecutionException Called during execution of ALTER ROLE statement. options are always guaranteed to be a subset of supportedOptions(). Furthermore, if the actor performing the query is not a superuser and is altering themself, then options are guaranteed to be a subset of alterableOptions(). Keep the body of the method blank if your implementation doesn't support modification of any options.- Parameters:
performer- User issuing the alter role statement.role- Role that will be altered.options- Options to alter.- Throws:
RequestValidationExceptionRequestExecutionException
-
grantRole
void grantRole(AuthenticatedUser performer, RoleResource role, RoleResource grantee) throws RequestValidationException, RequestExecutionException Called during execution of GRANT ROLE query. Grant an role to another existing role. A grantee that has a role granted to it will inherit any permissions of the granted role.- Parameters:
performer- User issuing the grant statement.role- Role to be granted to the grantee.grantee- Role acting as the grantee.- Throws:
RequestValidationExceptionRequestExecutionException
-
revokeRole
void revokeRole(AuthenticatedUser performer, RoleResource role, RoleResource revokee) throws RequestValidationException, RequestExecutionException Called during the execution of a REVOKE ROLE query. Revoke an granted role from an existing role. The revokee will lose any permissions inherited from the role being revoked.- Parameters:
performer- User issuing the revoke statement.role- Role to be revoked.revokee- Role from which the granted role is to be revoked.- Throws:
RequestValidationExceptionRequestExecutionException
-
getRoles
Set<RoleResource> getRoles(RoleResource grantee, boolean includeInherited) throws RequestValidationException, RequestExecutionException Called during execution of a LIST ROLES query. Returns a set of roles that have been granted to the grantee using GRANT ROLE.- Parameters:
grantee- Role whose granted roles will be listed.includeInherited- if True will list inherited roles as well as those directly granted to the grantee.- Returns:
- A list containing the granted roles for the user.
- Throws:
RequestValidationExceptionRequestExecutionException
-
getRoleDetails
Used to retrieve detailed role info on the full set of roles granted to a grantee. This method was not part of the V1 IRoleManager API, so a default impl is supplied which uses the V1 methods to retrieve the detailed role info for the grantee. This is essentially what clients of this interface would have to do themselves. Implementations can provide optimized versions of this method where the details can be retrieved more efficiently.- Parameters:
grantee- identifies the role whose granted roles are retrieved- Returns:
- A set of Role objects detailing the roles granted to the grantee, either directly or through inheritance.
-
getAllRoles
Called during the execution of an unqualified LIST ROLES query. Returns the total set of distinct roles in the system.- Returns:
- the set of all roles in the system.
- Throws:
RequestValidationExceptionRequestExecutionException
-
isSuper
Return true if there exists a Role with the given name that also has superuser status. Superuser status may be inherited from another granted role, so this method should return true if either the named Role, or any other Role it is transitively granted has superuser status.- Parameters:
role- Role whose superuser status to verify- Returns:
- true if the role exists and has superuser status, either directly or transitively, otherwise false.
-
canLogin
Return true if there exists a Role with the given name which has login privileges. Such privileges is not inherited from other granted Roles and so must be directly granted to the named Role with the LOGIN option of CREATE ROLE or ALTER ROLE- Parameters:
role- Role whose login privileges to verify- Returns:
- true if the role exists and is permitted to login, otherwise false
-
getCustomOptions
Where an implementation supports OPTIONS in CREATE and ALTER operations this method should return theMap<String, String>representing the custom options associated with the role, as supplied to CREATE or ALTER. It should never return null; if the implementation does not support OPTIONS or if none were supplied then it should return an empty map.- Parameters:
role- Role whose custom options are required- Returns:
- Key/Value pairs representing the custom options for the Role
-
isExistingRole
Return true is a Role with the given name exists in the system.- Parameters:
role- Role whose existence to verify- Returns:
- true if the name identifies an extant Role in the system, otherwise false
-
protectedResources
Set of resources that should be made inaccessible to users and only accessible internally.- Returns:
- Keyspaces and column families that will be unmodifiable by users; other resources.
-
validateConfiguration
Hook to perform validation of an implementation's configuration (if supported).- Throws:
ConfigurationException
-
setup
void setup()Hook to perform implementation specific initialization, called once upon system startup. For example, use this method to create any required keyspaces/column families. -
roleForIdentity
Each valid identity is associated with a role in the identity_to_role table, this method returns role of a given identity- Parameters:
identity- identity whose role to be retrieved- Returns:
- role of the given identity
-
authorizedIdentities
Returns all the authorized identities from the identity_to_role table- Returns:
- Map of identity -> roles
-
addIdentity
Adds a row (identity, role) to the identity_to_role table- Parameters:
identity- identity to be addedrole- role that is associated with the identity
-
isExistingIdentity
Returns if an identity exists in the identity_to_role- Parameters:
identity- identity whose existence to verify- Returns:
-
dropIdentity
Called on the execution of DROP IDENTITY statement for removing a given identity from the identity_role table. This implies we want to revoke the access for the given identity.- Parameters:
identity- identity that has to be removed from the table
-