Mercurial > hg > orthanc-authorization
annotate Plugin/IAuthorizationService.h @ 158:1bc074f956f1 0.7.1
0.7.1
author | Alain Mazy <am@osimis.io> |
---|---|
date | Mon, 25 Mar 2024 13:03:20 +0100 |
parents | 9be1ee2b8fe1 |
children | c4b908970ae4 |
rev | line source |
---|---|
1 | 1 /** |
2 * Advanced authorization plugin for Orthanc | |
68 | 3 * Copyright (C) 2017-2023 Osimis S.A., Belgium |
150 | 4 * Copyright (C) 2024-2024 Orthanc Team SRL, Belgium |
1 | 5 * |
6 * This program is free software: you can redistribute it and/or | |
7 * modify it under the terms of the GNU Affero General Public License | |
8 * as published by the Free Software Foundation, either version 3 of | |
9 * the License, or (at your option) any later version. | |
10 * | |
11 * This program is distributed in the hope that it will be useful, but | |
12 * WITHOUT ANY WARRANTY; without even the implied warranty of | |
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU | |
14 * Affero General Public License for more details. | |
15 * | |
16 * You should have received a copy of the GNU Affero General Public License | |
17 * along with this program. If not, see <http://www.gnu.org/licenses/>. | |
18 **/ | |
19 | |
20 #pragma once | |
21 | |
22 #include "AccessedResource.h" | |
23 #include "Token.h" | |
24 | |
25 #include <orthanc/OrthancCPlugin.h> | |
26 #include <boost/noncopyable.hpp> | |
69
af44dce56328
new 'auth/user-profile' Rest API route
Alain Mazy <am@osimis.io>
parents:
68
diff
changeset
|
27 #include <json/json.h> |
109 | 28 #include <set> |
1 | 29 |
30 namespace OrthancPlugins | |
31 { | |
32 // NOTE: This interface must be thread-safe | |
33 class IAuthorizationService : public boost::noncopyable | |
34 { | |
35 public: | |
72
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
36 struct OrthancResource |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
37 { |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
38 std::string dicomUid; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
39 std::string orthancId; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
40 std::string url; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
41 std::string level; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
42 }; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
43 |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
44 struct CreatedToken |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
45 { |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
46 std::string url; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
47 std::string token; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
48 }; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
49 |
74 | 50 struct DecodedToken |
51 { | |
52 std::string redirectUrl; | |
53 std::string errorCode; | |
54 std::string tokenType; | |
55 }; | |
56 | |
109 | 57 struct UserProfile |
58 { | |
59 std::string name; | |
60 std::set<std::string> permissions; | |
61 std::set<std::string> authorizedLabels; | |
113 | 62 |
63 // the source token key/value that identified the user | |
64 TokenType tokenType; | |
65 std::string tokenKey; | |
66 std::string tokenValue; | |
109 | 67 }; |
68 | |
1 | 69 virtual ~IAuthorizationService() |
70 { | |
71 } | |
72 | |
73 virtual bool IsGranted(unsigned int& validity /* out */, | |
74 OrthancPluginHttpMethod method, | |
75 const AccessedResource& access, | |
76 const Token& token, | |
77 const std::string& tokenValue) = 0; | |
78 | |
71 | 79 virtual bool IsGrantedToAnonymousUser(unsigned int& validity /* out */, |
80 OrthancPluginHttpMethod method, | |
81 const AccessedResource& access) = 0; | |
69
af44dce56328
new 'auth/user-profile' Rest API route
Alain Mazy <am@osimis.io>
parents:
68
diff
changeset
|
82 |
71 | 83 virtual bool GetUserProfile(unsigned int& validity /* out */, |
109 | 84 UserProfile& profile /* out */, |
69
af44dce56328
new 'auth/user-profile' Rest API route
Alain Mazy <am@osimis.io>
parents:
68
diff
changeset
|
85 const Token& token, |
af44dce56328
new 'auth/user-profile' Rest API route
Alain Mazy <am@osimis.io>
parents:
68
diff
changeset
|
86 const std::string& tokenValue) = 0; |
71 | 87 |
88 virtual bool GetAnonymousUserProfile(unsigned int& validity /* out */, | |
109 | 89 UserProfile& profile /* out */) = 0; |
71 | 90 |
91 virtual bool HasUserPermission(unsigned int& validity /* out */, | |
92 const std::set<std::string>& anyOfPermissions, | |
113 | 93 const UserProfile& profile) = 0; |
71 | 94 |
95 virtual bool HasAnonymousUserPermission(unsigned int& validity /* out */, | |
96 const std::set<std::string>& anyOfPermissions) = 0; | |
72
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
97 |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
98 virtual bool CreateToken(CreatedToken& response, |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
99 const std::string& tokenType, |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
100 const std::string& id, |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
101 const std::vector<OrthancResource>& resources, |
73
512247750f0a
new ValidityDuration arg in create token API
Alain Mazy <am@osimis.io>
parents:
72
diff
changeset
|
102 const std::string& expirationDateString, |
512247750f0a
new ValidityDuration arg in create token API
Alain Mazy <am@osimis.io>
parents:
72
diff
changeset
|
103 const uint64_t& validityDuration) = 0; |
72
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
104 |
74 | 105 virtual bool DecodeToken(DecodedToken& response, |
106 const std::string& tokenKey, | |
107 const std::string& tokenValue) = 0; | |
108 | |
72
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
109 virtual bool HasUserProfile() const = 0; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
110 virtual bool HasCreateToken() const = 0; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
111 virtual bool HasTokenValidation() const = 0; |
1 | 112 }; |
113 } |