annotate Plugin/PermissionParser.h @ 196:55760c465c3a

Fix wrong access to POST /instances that was considered as a resource list
author Alain Mazy <am@orthanc.team>
date Mon, 24 Jun 2024 18:28:16 +0200
parents 2f1e872e8eaa
children
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
71
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
1 /**
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
2 * Advanced authorization plugin for Orthanc
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
3 * Copyright (C) 2017-2023 Osimis S.A., Belgium
150
Alain Mazy <am@osimis.io>
parents: 149
diff changeset
4 * Copyright (C) 2024-2024 Orthanc Team SRL, Belgium
188
c4b908970ae4 updated copyright, as Orthanc Team now replaces Osimis
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 150
diff changeset
5 * Copyright (C) 2021-2024 Sebastien Jodogne, ICTEAM UCLouvain, Belgium
71
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
6 *
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
7 * This program is free software: you can redistribute it and/or
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
8 * modify it under the terms of the GNU Affero General Public License
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
9 * as published by the Free Software Foundation, either version 3 of
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
10 * the License, or (at your option) any later version.
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
11 *
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
12 * This program is distributed in the hope that it will be useful, but
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
13 * WITHOUT ANY WARRANTY; without even the implied warranty of
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
15 * Affero General Public License for more details.
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
16 *
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
17 * You should have received a copy of the GNU Affero General Public License
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
18 * along with this program. If not, see <http://www.gnu.org/licenses/>.
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
19 **/
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
20
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
21 #pragma once
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
22
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
23 #include "AuthorizationParserBase.h"
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
24
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
25 #include <boost/regex.hpp>
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
26 #include <boost/thread/mutex.hpp>
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
27
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
28 namespace OrthancPlugins
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
29 {
191
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
30 class PermissionPattern : public boost::noncopyable
71
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
31 {
191
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
32 private:
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
33 OrthancPluginHttpMethod method_;
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
34 boost::regex pattern_;
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
35 std::set<std::string> permissions_;
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
36
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
37 public:
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
38 PermissionPattern(const OrthancPluginHttpMethod& method,
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
39 const std::string& patternRegex,
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
40 const std::string& permissions);
71
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
41
191
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
42 OrthancPluginHttpMethod GetMethod() const
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
43 {
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
44 return method_;
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
45 }
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
46
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
47 const boost::regex& GetPattern() const
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
48 {
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
49 return pattern_;
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
50 }
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
51
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
52 const std::set<std::string>& GetPermissions() const
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
53 {
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
54 return permissions_;
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
55 }
71
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
56 };
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
57
191
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
58 class PermissionParser : public boost::noncopyable
71
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
59 {
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
60 private:
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
61 mutable boost::mutex mutex_;
191
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
62 std::list<PermissionPattern*> permissionsPattern_;
194
85859ec3aa7e added support for roles/permissions edition
Alain Mazy <am@orthanc.team>
parents: 188
diff changeset
63 std::set<std::string> permissionsList_;
71
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
64 std::string dicomWebRoot_;
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
65 std::string oe2Root_;
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
66
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
67 public:
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
68 PermissionParser(const std::string& dicomWebRoot,
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
69 const std::string& oe2Root);
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
70
191
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
71 ~PermissionParser();
55435a4dd2c6 cppcheck
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 188
diff changeset
72
71
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
73 void Add(const std::string& method,
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
74 const std::string& patternRegex,
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
75 const std::string& permission);
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
76
149
423531fb1200 SINGLE_RESOURCE_PATTERNS to facilitate api-key support
Alain Mazy <am@osimis.io>
parents: 71
diff changeset
77 void Add(const Json::Value& configuration, const IAuthorizationParser* authorizationParser);
71
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
78
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
79 bool Parse(std::set<std::string>& permissions,
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
80 std::string& matchedPattern,
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
81 const OrthancPluginHttpMethod& method,
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
82 const std::string& uri) const;
194
85859ec3aa7e added support for roles/permissions edition
Alain Mazy <am@orthanc.team>
parents: 188
diff changeset
83
85859ec3aa7e added support for roles/permissions edition
Alain Mazy <am@orthanc.team>
parents: 188
diff changeset
84 const std::set<std::string>& GetPermissionsList() const
85859ec3aa7e added support for roles/permissions edition
Alain Mazy <am@orthanc.team>
parents: 188
diff changeset
85 {
85859ec3aa7e added support for roles/permissions edition
Alain Mazy <am@orthanc.team>
parents: 188
diff changeset
86 return permissionsList_;
85859ec3aa7e added support for roles/permissions edition
Alain Mazy <am@orthanc.team>
parents: 188
diff changeset
87 }
71
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
88 };
30fb3ce960d9 configurable user permissions
Alain Mazy <am@osimis.io>
parents:
diff changeset
89 }