mirror of
				https://github.com/Alfresco/alfresco-community-repo.git
				synced 2025-10-22 15:12:38 +00:00 
			
		
		
		
	40713: Merged BRANCHES/DEV/BELARUS/V4.1-BUG-FIX-2012_08_15 to BRANCHES/DEV/V4.1-BUG-FIX:
      40604: ALF-15274  "I'm following" filter of "My Activities" dashlet doesn't work (PostgreSQL)
   40727: Fix for ALF-15469 from Alex Malinovsky - Cannot Edit Online files with special characters in names
   40733: Merged DEV (ALF-12358 and ALF-14496) to V4.1-BUG-FIX
      38973: DEV for ALF-12358 (upgrades and build plans)
      38975: Part of refactoring around the handling of deleted nodes.
             - Deleted nodes are now treated as real nodes by the NodeDAO
      38977: Fixed up queries related to bulk-loading
      38978: Fixed up Alfresco side of SOLR tracking APIs to handle removal of alf_node.node_deleted (ALF-12358)
      38979: Removed potential contention on cm:name during random file creation
      38980: Initial setup for patching of ALF-12358
      38981: Merged DEV/BELARUS/ALF-12358-4 to DEV/DEREK/ALF-12358-4
         36052: ALF-12358: Concurrency: Possible to create association references to deleted nodes
                .NodeDeleted. upgrade SQL patch for PostgreSQL is implemented:
                - SQL create scripts are updated to do not create .alf_node.deleted. column and its indexes;
                - schema references associated with .alf_node.deleted. column are updated;
                - Subscriptions DAO and schema reference are updated to use .sys:deleted. type instead of .alf_node.deleted. column;
                - .NodeStatus. receiving template was modified to receive .typeQNameId. for correct .deleted. state determination;
                - some other minor fixes
         36287: ALF-12358: Concurrency: Possible to create association references to deleted nodes
                'NodeDeleted' patch has been implemented for MySQL InnoDB, Alfresco Oracle 9, Alfresco SQL Server and PostgreSQL dialects. Not implemented for DB2 dialect!
                - DB creating scripts are modified in accordance with removal of 'alf_node.node_deleted' column and respective indexes;
                - iBATIS schema references are modified in accordance with removal of 'alf_node.node_deleted' column and respective indexes;
                - the code for handling subscriptions on deleted nodes removed;
                - subscriptions DAO schema reference is corrected respectively
         37284: ALF-12358: Concurrency: Possible to create association references to deleted nodes
                'NodeDeletd' updating patch for 4.0 version has been modified to recreate 'alf_node' table for all supported dialects.
                'SubscriptionServiceImplTest' has been extended to test whether subscriptions are being removed if node is archived.
                The new test creates fake user node and applies a custom aspect with 'archive=true' attribute
         37905: ALF-12358: Concurrency: Possible to create association references to deleted nodes
                Maintenance of the .idx_alf_node_txn_type. index has been added into the patch for all the dialects.
                SQL formatting has been changed to more compact and visually comfortable. Some minor changes for MySQL dialec
         Also:
         - Started move to 4.1 scripts
         - Fixed Schema reference files for alf_node column ordering
      38982: ALF-12358: Concurrency: Possible to create association references to deleted nodes
             - Moving scripts to V4.1 code base
             - Fixed upgrade with sequences for introduction of 'deleted' qname
      38983: Migration to 4.1 fix for ALF-12358
      38995: Fix scripts for ALF-12358
             - Fixed index removal for indexes that could not possibly have existed
             - Fixed ALF schema mappings to reflect new index names
             - Fixed PostgreSQL PK name check
      39027: Added in missing index idx_alf_node_txn_type (ALF-12358)
             - Merge note: Removed redundant index alf_node.fk_alf_node_txn
      39028: Fixed fallout from node deletion strategy (ALF-12358)
      39222: Minor test enhancements for diagnostics
   40738: ALF-11297: resurrect system-build-test (not plugged in yet, still a few failures)
   40740: Follow-up for DB2 upgrade for ALF-12358: New alf_node table ID column autoincrement value set
   40770: Merged DEV (ALF-12358) to V4.1-BUG-FIX
      39223: Merged 3.4.6HF to DEV (ALF-12358)
         39218: ALF-15109: Improved fix - must fire cascaded secondary association deletions at DbNodeServiceImpl
                level to ensure appropriate index events are fired and prevent out of sync indexes!
      39259: Merged V3.4.6HF to DEV (ALF-12358)
         39240: ALF-15109: Another attempt. Now we are firing all the right events on cascade removal of secondary associations
                           a lot of things are coming out in the wash!
                - Cascade delete secondary associations in a first recursive pass
                - Use a List of Pairs rather than a Map to avoid missing multiple associations to the same child
      39271: Added policy invocations for peer association removal when an aspect is removed
      39401: Utility class to walk a node hierarchy (primary) and gather all association data
             - Data gathered has to include secondary association pointing out of the hierarchy
             - Source and target associations gathered as well
             - TODO: Bulk queries for above
      39402: Follow up to ALF-15109: Break node deletion by removing deleteAssocsToAndFrom
             - TODO: Use NodeHierarchyWalker to gather data, fire policies and execute deletes
      39456: NodeHierarchyWalker: tests and fixes
      39457: ALF-12358: Remove in-txn manual recording of deleted and new nodes
      39917: ALF-12358: Use NodeHierarchyWalker to pick up all associations for a node hierarchy, fire policies and perform deletes
             - NOTE: Currently, in-process links back to the hierarchy prevent certain tests from passing.
             - TODO: Add detection for nodes that are about to be deleted
      40000: ALF-12358: Added support for 'beforeDeleteNodeAssociationPolicy'
      40001: ALF-12358: A node hierarchy walker to predetermine data required for deleting a hierarchy
      40002: ALF-12358: Spoof aspect 'sys:pendingDelete' that appears on all nodes within hierarchies being deleted
      40003: ALF-12358: Changes to prevent hierarchy modification during delete
             - The entire hierarchy is read before actual delete starts
             - All policies (including previously-missing assoc policies) are triggered from the recorded information
             - Nodes in the delete record cannot have new associations added / removed
             - All deletes are done on the same information so any underlying data shift causes concurrency violations
             - Archival:
               - Archival is a full copy of the hierarchy but all outbound and secondary associations are removed
               - Archival is followed by a full delete of the original hierarchy
      40128: ALF-12358: Test for linking to deleted nodes now fail even after having tested the recovery code
             - Recovery code shows this when activated: ...ERROR [...NodeDAOImpl] ALF-13066: Orphan child node has been re-homed under lost_found: (49179, ...)
      40129: ALF-12358: Added a more verbose message when association deletes don't find required rows
      40130: ALF-12358: Avoid incidental removal of associations when removing aspects if the associations are already scheduled for deletion
      40131: ALF-12358: Fix fallout for rules linking to avoid multiple deletions of the same association
      40371: ALF-12358: Fire beforeDeleteNode even when archiving
   40772: Merged DEV (ALF-12358) to V4.1-BUG-FIX
      40372: ALF-12358: Fallout in ML code
      40397: Fallout from ALF-12358: IMAP pre-commit handling must check for nodes having been deleted
             - Also fixed some TODOs and line endings for test
      40403: PersonService: Reinstated new getPeopleFilteredByProperty method
             - Also fixed test to rollback transaction after forced catch of exception
      40404: Fixed line endings, updated deprecated calls and removed unused code
      40494: ALF-12358: Fixed missing before- and after-create policy calls for the archive store
      40504: Fixed bug in rev 40494: ALF-12358: Fixed missing before- and after-create policy calls for the archive store
             - Used incorrect child node reference when calling policies and notifying indexer
      40529: ALF-12358: Fixed in-txn holding of nodes pending delete to cater for deletes triggering more deletes
      40530: Fallout from ALF-12358: Actions: Association act:scheduledAction multiplicity was not being enforced
             - act:actionSchedule nodes were not cleaned up when associated actions were deleted
             - Added onDeleteAssociation handling to clean up act:actionSchedule node
             - Fixed tests appropriately
      40556: Fallout from ALF-12358: Split out negative tests for deleteSite, which were absorbing exceptions
      40569: Tagging's beforeCommit behaviour was not checking for nodes having been deleted.
             - Added 'nodeServiceInternal' and used that to double-check that nodes still exist
             - Also removed heavily-used call to check if auditing is on
      40618: ALF-12358 fallout: Fixed policy callback details for associations of archived nodes
             - Also some more details when throwing concurrency violation when deleting associations
      40673: Fixed fallout from ALF-12358: Multilingual behaviours fixed
             - Listen to the association being removed from the ML container to the translation
             - Keep track of containers that must be deleted before committing rather than
               attempting to delete them immediately; this avoids attempts to delete associations
               that are about to be deleted (and the thing that ALF-12358 actually fixes).
      40680: Follow-up to rev 40673 (ALF-12358): Forgot to remove commented-out code
   40781: ALF-15587: Merged PATCHES/V4.0.2 to V4.1-BUG-FIX
      40780: Merged DEV to PATCHES/V4.0.2
         40777: ALF-15385 : Unable to set bpm:assingee and other properties in Activiti task via JS
            Added the initialization of runtimeService property.
   40787: Merge V4.1 (4.1) to V4.1-BUG-FIX (4.1.1)
      40782: Fix ALF-15420: Move: child files/subfolders aren't synced after moving from parent folder and updating in Alfresco on-premise/Cloud
       - Corrected the handling of moving a sub-folder out of its synced parent
      40718: Fixes: ALF-15498: Creates new nodeLock indicator (overrides locked) to cope with differences between content models when a node is locked directly using a nodeLock and when a node is locked due to it being a working copy.
   40790: Merged V3.4-BUG-FIX to V4.1-BUG-FIX
      40789: ALF-15598: Merged PATCHES/V3.4.9 to V3.4-BUG-FIX
         40671: Merged DEV to V3.4.9 (3.4.9.6)
            40658: ALF-15505: Build-up of lucene folder segments following CMIS queries (un-closed ResultSet objects?)
            - Close unclosed ResultSet.
            - Remove kind="org.alfresco.cmiskind" parameter from query.get and queries.post webscripts and now they use CMISQueryWebScript as implementation.
   40795: Fixed txn handling in the event of cleanup failure of test
   40797: Fix for ALF-15602 - XSS issue in OpenSearch Explorer webscript - unescaped search terms displayed in page
   40810: ALF-12358: Possible build fix (Derek, Neil and Jan to review)
   - Reinstate invokeBeforeMoveNode which seems to have disappeared in the refactor
   - Due to extra cascaded calls to onDeleteAssociation, SyncChangeMonitor must ignore certain events
   40827: ALF-12358: Possible build fix (Derek, Neil and Jan to review)
   - SyncChangeMonitor must ignore onDeleteAssociation calls on both sides of the association when a node is deleted
   40843: Stop deploying XAM connector to maven repo, it's gone
   40845: ALF-15406 Index Tracker seems not to gracefully stop upon shutdown keeping all other threads in waiting
      - Don't allow Quartz scheduler jobs for the OOoDirect subsystem, checking the connection to backup in a queue.
        Avoids multiple timeouts. Should just get one now. There is no need for multiple threads to be running anyway.
      - ALF-610 changes should stop the OOoDirect subsystem from running any of these Quartz jobs in the first place
        when using the default configuration in an enterprise release. So no timeout?
   40848: Merged BRANCHES/DEV/V3.4-BUG-FIX to BRANCHES/DEV/V4.1-BUG-FIX
      40847: Fix for ALF-15189 - Incorrect trimming of the date on the Advanced search by date range
   40887: ALF-15596: Deadlocks in DescriptorServiceImpl / LicenseComponent threads
   - Problem discovered by Gab
   - The two classes are mutually dependent and can end up deadlocking
   - Removed excessive synchronization from DescriptorServiceImpl
   - Now two key synchronization points - bootstrap and currentRepoDescriptor updates
   - Bootstrap synchronization controlled outside this class - no need to defend against it other than throwing IllegalStateException if accessed before bootstrapped
   - currentRepoDescriptorLock added to regulate currentRepoDescriptor accesses / updates
   - Uncovered problem in bootstrapping order - descriptorComponent must be bootstrapped before multiTenantBootstrap
   40889: ALF-15691: Poor cluster performance in user dashboard due to unnecessary cache replication
   40899: ALF-15691: Corrected duplicate property
   40900: ALF-12358 / ALF-15688: Finish the job! Make SOLR tracking work again and process deletes (Derek, Andy please review)
   - select_Txn_Nodes now uses a COALESCE query to substitute the original node ID when recorded in the PROP_ORIGINAL_ID property
   - NodesGet webscript extended so that it detects deleted nodes in the new way and also includes the noderef
   - CoreTracker avoids trying to retrieve the metadata of deleted nodes (possible because of NodesGet noderef extension)
   - SOLRTrackingComponentImpl doesn't barf when getNodesMetadata called for a cascade deleted node by CoreTracker.updateDescendantAuxDocs()
   40902: ALF-12358 / ALF-15688: Fixed unit test
   - Don't expect meta data for deleted nodes anymore (as this is generated on client side)
   - Also removed stray line of code from CoreTracker
   40917: ALF-13750: Merged V3.4-BUG-FIX to V4.1-BUG-FIX
      40915: ALF-15708: Trailing whitespace should be trimmed from properties.
         - Implemented custom properties persister to trim trailing whitespace from properties.
   40925: RUSSIAN: Translation updates based on EN r40357
git-svn-id: https://svn.alfresco.com/repos/alfresco-enterprise/alfresco/HEAD/root@40935 c4b6b30b-aa2e-2d43-bbcb-ca4b014f7261
		
	
		
			
				
	
	
		
			521 lines
		
	
	
		
			18 KiB
		
	
	
	
		
			Java
		
	
	
	
	
	
			
		
		
	
	
			521 lines
		
	
	
		
			18 KiB
		
	
	
	
		
			Java
		
	
	
	
	
	
| /*
 | |
|  * Copyright (C) 2005-2012 Alfresco Software Limited.
 | |
|  *
 | |
|  * This file is part of Alfresco
 | |
|  *
 | |
|  * Alfresco is free software: you can redistribute it and/or modify
 | |
|  * it under the terms of the GNU Lesser General Public License as published by
 | |
|  * the Free Software Foundation, either version 3 of the License, or
 | |
|  * (at your option) any later version.
 | |
|  *
 | |
|  * Alfresco is distributed in the hope that it will be useful,
 | |
|  * but WITHOUT ANY WARRANTY; without even the implied warranty of
 | |
|  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 | |
|  * GNU Lesser General Public License for more details.
 | |
|  *
 | |
|  * You should have received a copy of the GNU Lesser General Public License
 | |
|  * along with Alfresco. If not, see <http://www.gnu.org/licenses/>.
 | |
|  */
 | |
| 
 | |
| package org.alfresco.repo.avm.locking;
 | |
| 
 | |
| import java.util.HashMap;
 | |
| import java.util.List;
 | |
| import java.util.Map;
 | |
| import java.util.Set;
 | |
| 
 | |
| import org.alfresco.model.WCMAppModel;
 | |
| import org.alfresco.repo.domain.avm.AVMLockDAO;
 | |
| import org.alfresco.repo.security.authentication.AuthenticationUtil;
 | |
| import org.alfresco.service.cmr.attributes.AttributeService;
 | |
| import org.alfresco.service.cmr.attributes.DuplicateAttributeException;
 | |
| import org.alfresco.service.cmr.avm.AVMBadArgumentException;
 | |
| import org.alfresco.service.cmr.avm.locking.AVMLockingException;
 | |
| import org.alfresco.service.cmr.avm.locking.AVMLockingService;
 | |
| import org.alfresco.service.cmr.repository.NodeRef;
 | |
| import org.alfresco.service.cmr.repository.NodeService;
 | |
| import org.alfresco.service.cmr.repository.StoreRef;
 | |
| import org.alfresco.service.cmr.search.ResultSet;
 | |
| import org.alfresco.service.cmr.search.SearchService;
 | |
| import org.alfresco.service.cmr.security.AuthorityService;
 | |
| import org.alfresco.service.cmr.security.AuthorityType;
 | |
| import org.alfresco.service.cmr.security.PersonService;
 | |
| import org.alfresco.service.namespace.NamespaceService;
 | |
| import org.alfresco.util.ParameterCheck;
 | |
| import org.alfresco.wcm.util.WCMUtil;
 | |
| import org.apache.commons.logging.Log;
 | |
| import org.apache.commons.logging.LogFactory;
 | |
| 
 | |
| /**
 | |
|  * Implementation of the lock service.
 | |
|  * 
 | |
|  * @author Derek Hulley, janv
 | |
|  */
 | |
| public class AVMLockingServiceImpl implements AVMLockingService
 | |
| {
 | |
|     public static final String KEY_AVM_LOCKS = ".avm_locks";
 | |
|     public static final String KEY_LOCK_OWNER = "lock-owner";
 | |
| 
 | |
|     private static final String ROLE_CONTENT_MANAGER = "ContentManager";
 | |
| 
 | |
|     private static final Log logger = LogFactory.getLog(AVMLockingServiceImpl.class);
 | |
| 
 | |
|     private String webProjectStore;
 | |
|     private SearchService searchService;
 | |
|     private AttributeService attributeService;
 | |
|     private AuthorityService authorityService;
 | |
|     private PersonService personService;
 | |
|     private NodeService nodeService;
 | |
|     
 | |
|     private AVMLockDAO avmLockDAO;
 | |
| 
 | |
|     /**
 | |
|      * @param webProjectStore The webProjectStore to set
 | |
|      */
 | |
|     public void setWebProjectStore(String webProjectStore)
 | |
|     {
 | |
|         this.webProjectStore = webProjectStore;
 | |
|     }
 | |
| 
 | |
|     /**
 | |
|      * @param attributeService                  the service to persist attributes
 | |
|      */
 | |
|     public void setAttributeService(AttributeService attributeService)
 | |
|     {
 | |
|         this.attributeService = attributeService;
 | |
|     }
 | |
| 
 | |
|     /**
 | |
|      * @param authorityService                  the service to check validity of usernames
 | |
|      */
 | |
|     public void setAuthorityService(AuthorityService authorityService)
 | |
|     {
 | |
|         this.authorityService = authorityService;
 | |
|     }
 | |
| 
 | |
|     /**
 | |
|      * @param personService                     checks validity of person names
 | |
|      */
 | |
|     public void setPersonService(PersonService personService)
 | |
|     {
 | |
|         this.personService = personService;
 | |
|     }
 | |
|     
 | |
|     public void setSearchService(SearchService searchService)
 | |
|     {
 | |
|         this.searchService = searchService;
 | |
|     }
 | |
|     
 | |
|     public void setNodeService(NodeService nodeService)
 | |
|     {
 | |
|         this.nodeService = nodeService;
 | |
|     }
 | |
|     
 | |
|     public void setAvmLockDAO(AVMLockDAO avmLockDAO)
 | |
|     {
 | |
|         this.avmLockDAO = avmLockDAO;
 | |
|     }
 | |
|     
 | |
|     /**
 | |
|      * Appends the lock owner to the lock data.
 | |
|      */
 | |
|     private HashMap<String, String> createLockAttributes(String lockOwner, Map<String, String> lockData)
 | |
|     {
 | |
|         HashMap<String, String> lockAttributes = new HashMap<String, String>(lockData);
 | |
|         lockAttributes.put(KEY_LOCK_OWNER, lockOwner);
 | |
|         return lockAttributes;
 | |
|     }
 | |
| 
 | |
|     /**
 | |
|      * {@inheritDoc}
 | |
|      */
 | |
|     public void lock(String avmStore, String path, String lockOwner, Map<String, String> lockData)
 | |
|     {
 | |
|         ParameterCheck.mandatoryString("avmStore", avmStore);
 | |
|         ParameterCheck.mandatoryString("path", path);
 | |
|         ParameterCheck.mandatoryString("lockOwner", lockOwner);
 | |
|         path = AVMLockingServiceImpl.normalizePath(path);
 | |
|         
 | |
|         if (!authorityService.authorityExists(lockOwner) &&
 | |
|             !personService.personExists(lockOwner))
 | |
|         {
 | |
|             throw new AVMBadArgumentException("Not an Authority: " + lockOwner);
 | |
|         }
 | |
|         
 | |
|         LockState lockState = getLockState(avmStore, path, lockOwner);
 | |
|         switch (lockState)
 | |
|         {
 | |
|         case LOCK_NOT_OWNER:
 | |
|             throw new AVMLockingException("avmlockservice.locked", path, lockOwner);
 | |
|         case NO_LOCK:
 | |
|             // Lock it, assuming that the lock doesn't exist (concurrency-safe).
 | |
|             try
 | |
|             {
 | |
|                 HashMap<String, String> lockAttributes = createLockAttributes(lockOwner, lockData);
 | |
|                 attributeService.createAttribute(
 | |
|                         lockAttributes,
 | |
|                         KEY_AVM_LOCKS, avmStore, path);
 | |
|             }
 | |
|             catch (DuplicateAttributeException e)
 | |
|             {
 | |
|                 String currentLockOwner = getLockOwner(avmStore, path);
 | |
|                 // Should trigger a retry, hence we pass the exception out
 | |
|                 throw new AVMLockingException(e, "avmlockservice.locked", path, currentLockOwner);
 | |
|             }
 | |
|             break;
 | |
|         case LOCK_OWNER:
 | |
|             // Nothing to do
 | |
|             break;
 | |
|         }
 | |
|     }
 | |
| 
 | |
|     /**
 | |
|      * {@inheritDoc}
 | |
|      */
 | |
|     public boolean modifyLock(
 | |
|             String avmStore, String path, String lockOwner,
 | |
|             String newAvmStore, String newPath,
 | |
|             Map<String, String> lockData)
 | |
|     {
 | |
|         ParameterCheck.mandatoryString("avmStore", avmStore);
 | |
|         ParameterCheck.mandatoryString("path", path);
 | |
|         ParameterCheck.mandatoryString("lockOwner", lockOwner);
 | |
|         ParameterCheck.mandatoryString("newAvmStore", newAvmStore);
 | |
|         ParameterCheck.mandatoryString("newPath", newPath);
 | |
|         path = AVMLockingServiceImpl.normalizePath(path);
 | |
|         newPath = AVMLockingServiceImpl.normalizePath(newPath);
 | |
| 
 | |
|         LockState currentLockState = getLockState(avmStore, path, lockOwner);
 | |
|         switch (currentLockState)
 | |
|         {
 | |
|         case LOCK_NOT_OWNER:
 | |
|         case LOCK_OWNER:
 | |
|             // Remove the lock first
 | |
|             attributeService.removeAttribute(KEY_AVM_LOCKS, avmStore, path);
 | |
|             HashMap<String, String> lockAttributes = createLockAttributes(lockOwner, lockData);
 | |
|             attributeService.setAttribute(
 | |
|                     lockAttributes,
 | |
|                     KEY_AVM_LOCKS, newAvmStore, newPath);
 | |
|             return true;
 | |
|         case NO_LOCK:
 | |
|             // Do nothing
 | |
|             return false;
 | |
|         default:
 | |
|             throw new IllegalStateException("Unexpected enum constant");
 | |
|         }
 | |
|     }
 | |
| 
 | |
|     /**
 | |
|      * {@inheritDoc}
 | |
|      */
 | |
|     public String getLockOwner(String avmStore, String path)
 | |
|     {
 | |
|         ParameterCheck.mandatoryString("path", path);
 | |
|         path = AVMLockingServiceImpl.normalizePath(path);
 | |
| 
 | |
|         Map<String, String> lockAttributes = getLockData(avmStore, path);
 | |
|         if (lockAttributes == null)
 | |
|         {
 | |
|             return null;
 | |
|         }
 | |
|         else if (!lockAttributes.containsKey(KEY_LOCK_OWNER))
 | |
|         {
 | |
|             logger.warn("AVM lock does not have a lock owner: " + avmStore + "-" + path);
 | |
|             return null;
 | |
|         }
 | |
|         return lockAttributes.get(KEY_LOCK_OWNER);
 | |
|     }
 | |
| 
 | |
|     /**
 | |
|      * {@inheritDoc}
 | |
|      */
 | |
|     @SuppressWarnings("unchecked")
 | |
|     public Map<String, String> getLockData(String avmStore, String path)
 | |
|     {
 | |
|         ParameterCheck.mandatoryString("avmStore", avmStore);
 | |
|         ParameterCheck.mandatoryString("path", path);
 | |
|         path = AVMLockingServiceImpl.normalizePath(path);
 | |
| 
 | |
|         Map<String, String> lockAttributes = (Map<String, String>) attributeService.getAttribute(
 | |
|                 KEY_AVM_LOCKS, avmStore, path);
 | |
|         return lockAttributes;
 | |
|     }
 | |
| 
 | |
|     /**
 | |
|      * {@inheritDoc}
 | |
|      */
 | |
|     public LockState getLockState(String avmStore, String path, String lockOwner)
 | |
|     {
 | |
|         ParameterCheck.mandatoryString("avmStore", avmStore);
 | |
|         ParameterCheck.mandatoryString("lockOwner", lockOwner);
 | |
|         path = AVMLockingServiceImpl.normalizePath(path);
 | |
|         
 | |
|         String currentLockOwner = getLockOwner(avmStore, path);
 | |
|         if (currentLockOwner == null)
 | |
|         {
 | |
|             return LockState.NO_LOCK;
 | |
|         }
 | |
|         else if (currentLockOwner.equals(lockOwner))
 | |
|         {
 | |
|             return LockState.LOCK_OWNER;
 | |
|         }
 | |
|         else
 | |
|         {
 | |
|             return LockState.LOCK_NOT_OWNER;
 | |
|         }
 | |
|     }
 | |
| 
 | |
|     /**
 | |
|      * {@inheritDoc}
 | |
|      */
 | |
|     public void removeLock(String avmStore, String path)
 | |
|     {
 | |
|         ParameterCheck.mandatoryString("avmStore", avmStore);
 | |
|         ParameterCheck.mandatoryString("path", path);
 | |
|         path = AVMLockingServiceImpl.normalizePath(path);
 | |
| 
 | |
|         attributeService.removeAttribute(KEY_AVM_LOCKS, avmStore, path);
 | |
|     }
 | |
| 
 | |
|     /**
 | |
|      * {@inheritDoc}
 | |
|      */
 | |
|     public void removeLocks(String avmStore)
 | |
|     {
 | |
|         ParameterCheck.mandatoryString("avmStore", avmStore);
 | |
|         
 | |
|         attributeService.removeAttributes(KEY_AVM_LOCKS, avmStore);
 | |
|     }
 | |
|     
 | |
|     /**
 | |
|      * {@inheritDoc}
 | |
|      */
 | |
|     public void removeLocks(String avmStore, String dirPath, final Map<String, String> lockDataToMatch)
 | |
|     {
 | |
|         ParameterCheck.mandatoryString("avmStore", avmStore);
 | |
|         ParameterCheck.mandatory("lockDataToMatch", lockDataToMatch);
 | |
|         
 | |
|         final String dirPathStart;
 | |
|         if (dirPath == null)
 | |
|         {
 | |
|             dirPathStart = null;
 | |
|         }
 | |
|         else
 | |
|         {
 | |
|             dirPath = normalizePath(dirPath);
 | |
|             if (! dirPath.endsWith("/"))
 | |
|             {
 | |
|                 dirPath = dirPath + '/';
 | |
|             }
 | |
|             
 | |
|             dirPathStart = dirPath;
 | |
|         }
 | |
|         
 | |
|         // optimised to delete with single DB query
 | |
|         avmLockDAO.removeLocks(avmStore, dirPathStart, lockDataToMatch);
 | |
|     }
 | |
| 
 | |
|     /**
 | |
|      * {@inheritDoc}
 | |
|      */
 | |
|     public void removeLocks(String avmStore, final Map<String, String> lockDataToMatch)
 | |
|     {
 | |
|         removeLocks(avmStore, null, lockDataToMatch);
 | |
|     }
 | |
| 
 | |
|     /**
 | |
|      * {@inheritDoc}
 | |
|      */
 | |
|     public boolean hasAccess(String webProject, String avmPath, String lockOwner)
 | |
|     {
 | |
|         if (personService.getPerson(lockOwner) == null && !authorityService.authorityExists(lockOwner))
 | |
|         {
 | |
|             return false;
 | |
|         }
 | |
|         if (authorityService.isAdminAuthority(lockOwner))
 | |
|         {
 | |
|             return true;
 | |
|         }
 | |
|         StoreRef storeRef = new StoreRef(this.webProjectStore);
 | |
|         ResultSet results = searchService.query(
 | |
|                 storeRef,
 | |
|                 SearchService.LANGUAGE_LUCENE,
 | |
|                 "@wca\\:avmstore:\"" + webProject + '"');
 | |
|         try
 | |
|         {
 | |
|             if (results.getNodeRefs().size() == 1)
 | |
|             {
 | |
|                 return hasAccess(webProject, results.getNodeRefs().get(0), avmPath, lockOwner);
 | |
|             }
 | |
|             return false;
 | |
|         }
 | |
|         finally
 | |
|         {
 | |
|             results.close();
 | |
|         }
 | |
|     }
 | |
| 
 | |
|     /**
 | |
|      * {@inheritDoc}
 | |
|      */
 | |
|     public boolean hasAccess(NodeRef webProjectRef, String avmPath, String lockOwner)
 | |
|     {
 | |
|         if (personService.getPerson(lockOwner) == null &&
 | |
|             !authorityService.authorityExists(lockOwner))
 | |
|         {
 | |
|             return false;
 | |
|         }
 | |
|         if (authorityService.isAdminAuthority(lockOwner))
 | |
|         {
 | |
|             return true;
 | |
|         }
 | |
|         String webProject = (String)nodeService.getProperty(webProjectRef, WCMAppModel.PROP_AVMSTORE);
 | |
|         return hasAccess(webProject, webProjectRef, avmPath, lockOwner);
 | |
|     }
 | |
| 
 | |
|     private boolean hasAccess(String webProject, NodeRef webProjectRef, String avmPath, String lockOwner)
 | |
|     {
 | |
|         String[] storePath = avmPath.split(":");
 | |
|         if (storePath.length != 2)
 | |
|         {
 | |
|             throw new AVMBadArgumentException("Malformed AVM Path : " + avmPath);
 | |
|         }
 | |
|         
 | |
|         if (logger.isDebugEnabled())
 | |
|            logger.debug(
 | |
|                    "Testing lock access on path: " + avmPath +
 | |
|                    " for user: " + lockOwner + " in webproject: " + webProject);
 | |
|         
 | |
|         // check if a lock exists at all for this path in the specified webproject id
 | |
|         String path = normalizePath(storePath[1]);
 | |
|         
 | |
|         Map<String, String> lockData = getLockData(webProject, path);
 | |
|         
 | |
|         if (lockData == null)
 | |
|         {
 | |
|             if (logger.isDebugEnabled())
 | |
|                 logger.debug(" GRANTED: No lock found.");
 | |
|             return true;
 | |
|         }
 | |
|         
 | |
|         String currentLockOwner = lockData.get(KEY_LOCK_OWNER);
 | |
|         String currentLockStore = lockData.get(WCMUtil.LOCK_KEY_STORE_NAME);
 | |
|         
 | |
|         
 | |
|         // locks are ignored in a workflow store
 | |
|         if (storePath[0].contains("--workflow"))
 | |
|         {
 | |
|             if (logger.isDebugEnabled())
 | |
|                 logger.debug(" GRANTED: Workflow store path.");
 | |
|             return true;
 | |
|         }
 | |
|         
 | |
|         // locks are specific to a store - no access if the stores are different
 | |
|         if (! ((currentLockStore != null) && (currentLockStore.equals(storePath[0]))))
 | |
|         {
 | |
|             if (logger.isDebugEnabled())
 | |
|                 logger.debug(" DENIED: Store on path and lock (" + currentLockStore + ") do not match.");
 | |
|             return false;
 | |
|         }
 | |
|         
 | |
|         // check for content manager role - we allow access to all managers within the same store
 | |
|         // TODO as part of WCM refactor, consolidate with WebProject.getWebProjectUserRole
 | |
|         StringBuilder query = new StringBuilder(128);
 | |
|         query.append("+PARENT:\"").append(webProjectRef).append("\" ");
 | |
|         query.append("+TYPE:\"").append(WCMAppModel.TYPE_WEBUSER).append("\" ");
 | |
|         query.append("+@").append(NamespaceService.WCMAPP_MODEL_PREFIX).append("\\:username:\"");
 | |
|         query.append(lockOwner);
 | |
|         query.append("\"");
 | |
|         ResultSet resultSet = null;
 | |
|         List<NodeRef> nodes =null;
 | |
|         
 | |
|         try
 | |
|         {
 | |
|             resultSet = searchService.query(
 | |
|                     new StoreRef(this.webProjectStore),
 | |
|                     SearchService.LANGUAGE_LUCENE,
 | |
|                     query.toString());
 | |
|             nodes = resultSet.getNodeRefs();
 | |
|         }
 | |
|         finally
 | |
|         {
 | |
|         	if (resultSet != null) {resultSet.close();}
 | |
|         }
 | |
|         if (nodes.size() == 1)
 | |
|         {
 | |
|             String userrole = (String)nodeService.getProperty(nodes.get(0), WCMAppModel.PROP_WEBUSERROLE);
 | |
|             if (ROLE_CONTENT_MANAGER.equals(userrole))
 | |
|             {
 | |
|                 if (logger.isDebugEnabled())
 | |
|                 {
 | |
|                     logger.debug("GRANTED: Store match and user is ContentManager role in webproject.");
 | |
|                 }
 | |
|                 return true;
 | |
|             }
 | |
|         }
 | |
|         else if (nodes.size() == 0)
 | |
|         {
 | |
|         	logger.warn("hasAccess: user role not found for " + lockOwner);
 | |
|         }
 | |
|         else
 | |
|         {
 | |
|             logger.warn("hasAccess: more than one user role found for " + lockOwner);
 | |
|         }
 | |
|         
 | |
|         // finally check the owner of the lock against the specified authority
 | |
|         if (AuthorityType.getAuthorityType(currentLockOwner) == AuthorityType.EVERYONE)
 | |
|         {
 | |
|             if (logger.isDebugEnabled())
 | |
|                 logger.debug(" GRANTED: Authority EVERYONE matched lock owner.");
 | |
|             return true;
 | |
|         }
 | |
|         
 | |
|         if (checkAgainstAuthority(lockOwner, currentLockOwner))
 | |
|         {
 | |
|             if (logger.isDebugEnabled())
 | |
|                 logger.debug(" GRANTED: User matched as lock owner.");
 | |
|             return true;
 | |
|         }
 | |
|         
 | |
|         if (logger.isDebugEnabled())
 | |
|             logger.debug(" DENIED: User did not match as lock owner.");
 | |
|         return false;
 | |
|     }
 | |
| 
 | |
|     /**
 | |
|      * Helper function that checks the transitive closure of authorities for user.
 | |
|      */
 | |
|     private boolean checkAgainstAuthority(String user, String authority)
 | |
|     {
 | |
|         if (user.equalsIgnoreCase(authority))
 | |
|         {
 | |
|             return true;
 | |
|         }
 | |
|         return authorityService.getAuthoritiesForUser(user).contains(authority);
 | |
|     }
 | |
|     
 | |
|     /**
 | |
|      * Utility to get relative paths into canonical lock form
 | |
|      * 
 | |
|      * - remove first forward slash
 | |
|      * - multiple forward slashes collapsed into single foward slash
 | |
|      * 
 | |
|      * @param path The incoming path.
 | |
|      * @return The normalized path.
 | |
|      */
 | |
|     public static String normalizePath(String path)
 | |
|     {
 | |
|         path = path.toLowerCase(); // note: enables optimised removal of locks (based on path dir start)
 | |
|         
 | |
|         while (path.startsWith("/"))
 | |
|         {
 | |
|             path = path.substring(1);
 | |
|         }
 | |
|         while (path.endsWith("/"))
 | |
|         {
 | |
|             path = path.substring(0, path.length() - 1);
 | |
|         }
 | |
|         return path.replaceAll("/+", "/");
 | |
|     }
 | |
| }
 |