Mercurial > hg > orthanc-authorization
annotate Plugin/IAuthorizationService.h @ 134:89560460907d
sync
author | Sebastien Jodogne <s.jodogne@gmail.com> |
---|---|
date | Tue, 21 Nov 2023 20:07:11 +0100 |
parents | 43154740ea2e |
children | 9be1ee2b8fe1 |
rev | line source |
---|---|
1 | 1 /** |
2 * Advanced authorization plugin for Orthanc | |
68 | 3 * Copyright (C) 2017-2023 Osimis S.A., Belgium |
1 | 4 * |
5 * This program is free software: you can redistribute it and/or | |
6 * modify it under the terms of the GNU Affero General Public License | |
7 * as published by the Free Software Foundation, either version 3 of | |
8 * the License, or (at your option) any later version. | |
9 * | |
10 * This program is distributed in the hope that it will be useful, but | |
11 * WITHOUT ANY WARRANTY; without even the implied warranty of | |
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU | |
13 * Affero General Public License for more details. | |
14 * | |
15 * You should have received a copy of the GNU Affero General Public License | |
16 * along with this program. If not, see <http://www.gnu.org/licenses/>. | |
17 **/ | |
18 | |
19 #pragma once | |
20 | |
21 #include "AccessedResource.h" | |
22 #include "Token.h" | |
23 | |
24 #include <orthanc/OrthancCPlugin.h> | |
25 #include <boost/noncopyable.hpp> | |
69
af44dce56328
new 'auth/user-profile' Rest API route
Alain Mazy <am@osimis.io>
parents:
68
diff
changeset
|
26 #include <json/json.h> |
109 | 27 #include <set> |
1 | 28 |
29 namespace OrthancPlugins | |
30 { | |
31 // NOTE: This interface must be thread-safe | |
32 class IAuthorizationService : public boost::noncopyable | |
33 { | |
34 public: | |
72
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
35 struct OrthancResource |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
36 { |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
37 std::string dicomUid; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
38 std::string orthancId; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
39 std::string url; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
40 std::string level; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
41 }; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
42 |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
43 struct CreatedToken |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
44 { |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
45 std::string url; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
46 std::string token; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
47 }; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
48 |
74 | 49 struct DecodedToken |
50 { | |
51 std::string redirectUrl; | |
52 std::string errorCode; | |
53 std::string tokenType; | |
54 }; | |
55 | |
109 | 56 struct UserProfile |
57 { | |
58 std::string name; | |
59 std::set<std::string> permissions; | |
60 std::set<std::string> authorizedLabels; | |
113 | 61 |
62 // the source token key/value that identified the user | |
63 TokenType tokenType; | |
64 std::string tokenKey; | |
65 std::string tokenValue; | |
109 | 66 }; |
67 | |
1 | 68 virtual ~IAuthorizationService() |
69 { | |
70 } | |
71 | |
72 virtual bool IsGranted(unsigned int& validity /* out */, | |
73 OrthancPluginHttpMethod method, | |
74 const AccessedResource& access, | |
75 const Token& token, | |
76 const std::string& tokenValue) = 0; | |
77 | |
71 | 78 virtual bool IsGrantedToAnonymousUser(unsigned int& validity /* out */, |
79 OrthancPluginHttpMethod method, | |
80 const AccessedResource& access) = 0; | |
69
af44dce56328
new 'auth/user-profile' Rest API route
Alain Mazy <am@osimis.io>
parents:
68
diff
changeset
|
81 |
71 | 82 virtual bool GetUserProfile(unsigned int& validity /* out */, |
109 | 83 UserProfile& profile /* out */, |
69
af44dce56328
new 'auth/user-profile' Rest API route
Alain Mazy <am@osimis.io>
parents:
68
diff
changeset
|
84 const Token& token, |
af44dce56328
new 'auth/user-profile' Rest API route
Alain Mazy <am@osimis.io>
parents:
68
diff
changeset
|
85 const std::string& tokenValue) = 0; |
71 | 86 |
87 virtual bool GetAnonymousUserProfile(unsigned int& validity /* out */, | |
109 | 88 UserProfile& profile /* out */) = 0; |
71 | 89 |
90 virtual bool HasUserPermission(unsigned int& validity /* out */, | |
91 const std::set<std::string>& anyOfPermissions, | |
113 | 92 const UserProfile& profile) = 0; |
71 | 93 |
94 virtual bool HasAnonymousUserPermission(unsigned int& validity /* out */, | |
95 const std::set<std::string>& anyOfPermissions) = 0; | |
72
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
96 |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
97 virtual bool CreateToken(CreatedToken& response, |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
98 const std::string& tokenType, |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
99 const std::string& id, |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
100 const std::vector<OrthancResource>& resources, |
73
512247750f0a
new ValidityDuration arg in create token API
Alain Mazy <am@osimis.io>
parents:
72
diff
changeset
|
101 const std::string& expirationDateString, |
512247750f0a
new ValidityDuration arg in create token API
Alain Mazy <am@osimis.io>
parents:
72
diff
changeset
|
102 const uint64_t& validityDuration) = 0; |
72
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
103 |
74 | 104 virtual bool DecodeToken(DecodedToken& response, |
105 const std::string& tokenKey, | |
106 const std::string& tokenValue) = 0; | |
107 | |
72
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
108 virtual bool HasUserProfile() const = 0; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
109 virtual bool HasCreateToken() const = 0; |
e381ba725669
new PUT auth/tokens/{token-type} API route + updated interface with WebService
Alain Mazy <am@osimis.io>
parents:
71
diff
changeset
|
110 virtual bool HasTokenValidation() const = 0; |
1 | 111 }; |
112 } |