Package org.yamcs.security
Class SecurityStore
- java.lang.Object
-
- org.yamcs.security.SecurityStore
-
public class SecurityStore extends Object
Responsible for Identity and Access Management (IAM).Some security properties can be tweaked in security.yaml
-
-
Constructor Summary
Constructors Constructor Description SecurityStore()
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description voidaddObjectPrivilegeType(ObjectPrivilegeType privilegeType)voidaddSystemPrivilege(SystemPrivilege privilege)<T extends AuthModule>
TgetAuthModule(Class<T> clazz)List<AuthModule>getAuthModules()DirectorygetDirectory()UsergetGuestUser()Set<ObjectPrivilegeType>getObjectPrivilegeTypes()Set<SystemPrivilege>getSystemPrivileges()UsergetSystemUser()Returns the system user.CompletableFuture<AuthenticationInfo>login(AuthenticationToken token)Performs the login process.booleanverifyValidity(AuthenticationInfo authenticationInfo)
-
-
-
Constructor Detail
-
SecurityStore
public SecurityStore() throws InitException- Throws:
InitException
-
-
Method Detail
-
addSystemPrivilege
public void addSystemPrivilege(SystemPrivilege privilege)
-
addObjectPrivilegeType
public void addObjectPrivilegeType(ObjectPrivilegeType privilegeType)
-
getDirectory
public Directory getDirectory()
-
getAuthModules
public List<AuthModule> getAuthModules()
-
getAuthModule
public <T extends AuthModule> T getAuthModule(Class<T> clazz)
-
getSystemPrivileges
public Set<SystemPrivilege> getSystemPrivileges()
-
getObjectPrivilegeTypes
public Set<ObjectPrivilegeType> getObjectPrivilegeTypes()
-
getSystemUser
public User getSystemUser()
Returns the system user. This user object is only intended for internal use when actions require a user, yet cannot be linked to an actual user. The System user is granted all privileges.
-
getGuestUser
public User getGuestUser()
-
login
public CompletableFuture<AuthenticationInfo> login(AuthenticationToken token)
Performs the login process. Depending on how Yamcs is configured, this may involve reaching out to an external identity provider. If the login attempt is successful, the associated user is imported or resynchronized in the Yamcs internal user database.This method does not return a
Userobject. UsegetDirectory().- Returns:
- a future that resolves to the
AuthenticationInfowhen the login was successful. This contains the username as well as any other principals or credentials specific to a custom identity provider.
-
verifyValidity
public boolean verifyValidity(AuthenticationInfo authenticationInfo)
-
-