Provides the security and profile-lookup operations available to app controller scripts, wrapping KademiSecurityManager for the currently running request. Reached from JS as the securityManager global, it lets a controller check roles and privileges, look up or impersonate profiles, log a user in by setting the auth cookie, and generate one-time login tokens for a website.

Group: Managers


Properties

PropertyReturnsDescription
currentProfileProfileThe profile of the currently authenticated user for this request.
currentRequestPrivsSet<Priviledge>The privileges calculated for the current user on the current resource. This just provides access to the privileges already stored on the request's attributes, it does not calculate them itself.
currentRootFolderRootFolderThe root folder for the current request, resolved by the current root folder service.
currentUserUserResourceThe currently authenticated user for this request.
rolesSet<Role>All roles available within the current account.

Methods

yield() · getCurrentUser() · getCurrentProfile() · hasRole(Profile p, String roleName) · hasDirectRole(Profile p, String roleName, Organisation targetDirectOrg) · getRoles() · getCurrentRootFolder() · findApplicableRoles(Organisation targetOrg, Profile p) · containsRole(Set<Role> roles, String roleName) · runAsUser(UserResource userRes, VarArgFunction objectMirror) · runAsUser(ProfileBean pb, VarArgFunction objectMirror) · runAsUser(String userName, VarArgFunction objectMirror) · runAsUser(Profile p, VarArgFunction objectMirror) · runAsUser(Profile p, RootFolder rf, VarArgFunction objectMirror) · generateLoginToken(String websiteName, ProfileBean profileBean) · generateLoginToken(String websiteName, boolean versioned, ProfileBean profileBean) · generateLoginToken(Website website, Branch branch, Profile p) · generateLoginToken(Website website, Branch branch, boolean forceVersioned, Profile p) · isUserInGroup(String email, String groupName) · getCurrentRequestPrivs() · containsPriv(Set<Priviledge> privs, Object priv) · getPriviledges(Profile curUser, String resourcePath) · getPriviledges(Profile curUser, CommonResource resource) · getPriviledges(Profile curUser, CommonResource resource, Narrative authNarrative)

yield()

Returns: void

Yields to the operating system. Should be called inside long-running loops that the governor cannot otherwise interrupt, so the platform's CPU time limit can be enforced.

getCurrentUser()

Returns: UserResource

The currently authenticated user for this request.

getCurrentProfile()

Returns: Profile

The profile of the currently authenticated user for this request.

hasRole(Profile p, String roleName)

Returns: boolean

Checks if the profile has the given role on any of their memberships.

ParameterDescription
pthe profile to check
roleNamethe name of the role to look for

hasDirectRole(Profile p, String roleName, Organisation targetDirectOrg)

Returns: boolean

True if the profile has a membership with the requested role which applies directly to the requested target organisation. This method does not consider hierarchy, so a role on a parent org does not apply to child orgs.

ParameterDescription
pthe profile to check
roleNamethe name of the role to look for
targetDirectOrgthe organisation the membership must apply directly to

getRoles()

Returns: Set<Role>

All roles available within the current account.

getCurrentRootFolder()

Returns: RootFolder

The root folder for the current request, resolved by the current root folder service.

findApplicableRoles(Organisation targetOrg, Profile p)

Returns: Set<Role>

Finds the roles that apply to the given profile on the given target organisation, taking organisation hierarchy into account.

ParameterDescription
targetOrgthe organisation to find applicable roles on
pthe profile to find roles for

containsRole(Set<Role> roles, String roleName)

Returns: boolean

Checks whether a set of roles contains a role with the given name.

ParameterDescription
rolesthe roles to search, may be null
roleNamethe role name to look for

runAsUser(UserResource userRes, VarArgFunction objectMirror)

Returns: Object

Runs the given JS function with the current principal switched to the given user for its duration.

ParameterDescription
userResthe user to run as
objectMirrorthe JS function to run

runAsUser(ProfileBean pb, VarArgFunction objectMirror)

Returns: Object

Runs the given JS function with the current principal switched to the profile wrapped by pb for its duration.

ParameterDescription
pbthe profile bean to run as
objectMirrorthe JS function to run

runAsUser(String userName, VarArgFunction objectMirror)

Returns: Object

Looks up a profile by user name or email within the current organisation, recursing into child organisations, then runs the given JS function with the current principal switched to that profile.

ParameterDescription
userNamethe user name or email of the profile to run as
objectMirrorthe JS function to run

runAsUser(Profile p, VarArgFunction objectMirror)

Returns: Object

Runs the given JS function with the current principal switched to the given profile, on the current root folder, for its duration.

ParameterDescription
pthe profile to run as
objectMirrorthe JS function to run

runAsUser(Profile p, RootFolder rf, VarArgFunction objectMirror)

Returns: Object

Runs the given JS function with the current principal switched to the given profile on the given root folder for its duration. Errors thrown by the function are logged and rethrown.

ParameterDescription
pthe profile to run as
rfthe root folder to run within
objectMirrorthe JS function to run

generateLoginToken(String websiteName, ProfileBean profileBean)

Returns: String

Generates a one-time login token cookie value for the profile, scoped to the live branch of the named website.

ParameterDescription
websiteNamethe name of the website to generate the token for
profileBeanthe profile to generate the token for

generateLoginToken(String websiteName, boolean versioned, ProfileBean profileBean)

Returns: String

Generates a one-time login token cookie value for the profile, scoped to the live branch of the named website, optionally forcing the versioned domain to be used.

ParameterDescription
websiteNamethe name of the website to generate the token for
versionedtrue to force use of the versioned domain name
profileBeanthe profile to generate the token for

generateLoginToken(Website website, Branch branch, Profile p)

Returns: String

Generates a one-time login token cookie value for the profile, scoped to the given website and branch.

ParameterDescription
websitethe website to generate the token for
branchthe branch used to determine the domain name
pthe profile to generate the token for, must not be null

generateLoginToken(Website website, Branch branch, boolean forceVersioned, Profile p)

Returns: String

Generates a one-time login token cookie value for the profile, scoped to the given website and branch, optionally forcing the versioned domain to be used.

ParameterDescription
websitethe website to generate the token for
branchthe branch used to determine the domain name
forceVersionedtrue to force use of the versioned domain name
pthe profile to generate the token for, must not be null

isUserInGroup(String email, String groupName)

Returns: MembershipBean

Checks whether the profile identified by the given email is a member of the named group, in the current organisation.

ParameterDescription
emailthe email address identifying the profile to check
groupNamethe name of the group to check membership of

getCurrentRequestPrivs()

Returns: Set<Priviledge>

The privileges calculated for the current user on the current resource. This just provides access to the privileges already stored on the request's attributes, it does not calculate them itself.

containsPriv(Set<Priviledge> privs, Object priv)

Returns: boolean

Checks if the given privilege is contained within the given set of privileges, either directly or implied by a broader privilege already in the set.

ParameterDescription
privsthe set of privileges to search, may be null
privthe privilege to look for, as a Priviledge instance or its name as a string

getPriviledges(Profile curUser, String resourcePath)

Returns: Set<Priviledge>

Locates a resource for the given path, and then calculates the privileges the given profile has on it.

ParameterDescription
curUserthe profile to calculate privileges for
resourcePaththe path of the resource to check privileges on

getPriviledges(Profile curUser, CommonResource resource)

Returns: Set<Priviledge>

Calculates the privileges the given profile has on the given resource.

ParameterDescription
curUserthe profile to calculate privileges for
resourcethe resource to check privileges on

getPriviledges(Profile curUser, CommonResource resource, Narrative authNarrative)

Returns: Set<Priviledge>

Calculates the privileges the given profile has on the given resource, recording how the calculation was performed on the supplied narrative.

ParameterDescription
curUserthe profile to calculate privileges for
resourcethe resource to check privileges on
authNarrativecaptures information about how the privileges were calculated, may be null
To get full access to the Kademi Hub existing customers can login here, or new customers can register here.