Tom Joseph | 536ea32 | 2018-09-14 10:02:20 +0530 | [diff] [blame] | 1 | #pragma once |
| 2 | |
Patrick Williams | 9638afb | 2021-02-22 17:16:24 -0600 | [diff] [blame^] | 3 | #include "ldap_mapper_entry.hpp" |
| 4 | |
Tom Joseph | 536ea32 | 2018-09-14 10:02:20 +0530 | [diff] [blame] | 5 | #include <sdbusplus/bus.hpp> |
| 6 | #include <sdbusplus/server/object.hpp> |
Tom Joseph | 536ea32 | 2018-09-14 10:02:20 +0530 | [diff] [blame] | 7 | #include <xyz/openbmc_project/User/PrivilegeMapper/server.hpp> |
Patrick Williams | 9638afb | 2021-02-22 17:16:24 -0600 | [diff] [blame^] | 8 | |
Tom Joseph | 536ea32 | 2018-09-14 10:02:20 +0530 | [diff] [blame] | 9 | #include <map> |
| 10 | #include <set> |
| 11 | |
| 12 | namespace phosphor |
| 13 | { |
| 14 | |
| 15 | namespace user |
| 16 | { |
| 17 | |
| 18 | using MapperMgrIface = |
| 19 | sdbusplus::xyz::openbmc_project::User::server::PrivilegeMapper; |
| 20 | using ObjectPath = sdbusplus::message::object_path; |
| 21 | |
| 22 | // D-Bus root for LDAP privilege mapper |
| 23 | constexpr auto mapperMgrRoot = "/xyz/openbmc_project/user/ldap"; |
| 24 | |
| 25 | /** @class LDAPMapperMgr |
| 26 | * |
| 27 | * @brief Responsible for managing LDAP groups to privilege mapping. |
| 28 | */ |
| 29 | class LDAPMapperMgr : public MapperMgrIface |
| 30 | { |
| 31 | public: |
| 32 | LDAPMapperMgr() = delete; |
| 33 | ~LDAPMapperMgr() = default; |
Patrick Williams | 9638afb | 2021-02-22 17:16:24 -0600 | [diff] [blame^] | 34 | LDAPMapperMgr(const LDAPMapperMgr&) = delete; |
| 35 | LDAPMapperMgr& operator=(const LDAPMapperMgr&) = delete; |
| 36 | LDAPMapperMgr(LDAPMapperMgr&&) = delete; |
| 37 | LDAPMapperMgr& operator=(LDAPMapperMgr&&) = delete; |
Tom Joseph | 536ea32 | 2018-09-14 10:02:20 +0530 | [diff] [blame] | 38 | |
| 39 | /** @brief Constructs LDAPMapperMgr object. |
| 40 | * |
| 41 | * @param[in] bus - sdbusplus handler |
| 42 | * @param[in] path - D-Bus path |
Tom Joseph | f5bd891 | 2018-11-19 09:49:21 +0530 | [diff] [blame] | 43 | * @param[in] filePath - serialization directory path |
Tom Joseph | 536ea32 | 2018-09-14 10:02:20 +0530 | [diff] [blame] | 44 | */ |
Patrick Williams | 9638afb | 2021-02-22 17:16:24 -0600 | [diff] [blame^] | 45 | LDAPMapperMgr(sdbusplus::bus::bus& bus, const char* path, |
| 46 | const char* filePath); |
Tom Joseph | 536ea32 | 2018-09-14 10:02:20 +0530 | [diff] [blame] | 47 | |
| 48 | /** @brief Creates a mapping for the group to the privilege |
| 49 | * |
| 50 | * @param[in] groupName - Group Name to which the privilege needs to be |
| 51 | * assigned. |
| 52 | * @param[in] privilege - The privilege role associated with the group. |
| 53 | * |
| 54 | * @return On success return the D-Bus object path of the created privilege |
| 55 | * mapper entry. |
| 56 | */ |
| 57 | ObjectPath create(std::string groupName, std::string privilege) override; |
| 58 | |
| 59 | /** @brief Delete privilege mapping for LDAP group |
| 60 | * |
| 61 | * This method deletes the privilege mapping |
| 62 | * |
| 63 | * @param[in] groupName - name of the LDAP group for which privilege |
| 64 | * mapping is to be deleted. |
| 65 | */ |
| 66 | void deletePrivilegeMapper(Id id); |
| 67 | |
| 68 | /** @brief Check if LDAP group privilege mapping requested is valid |
| 69 | * |
| 70 | * Check if the privilege mapping already exists for the LDAP group name |
| 71 | * and group name is empty. |
| 72 | * |
| 73 | * @param[in] groupName - LDAP group name |
| 74 | * |
| 75 | * @return throw exception if the conditions are not met. |
| 76 | */ |
Patrick Williams | 9638afb | 2021-02-22 17:16:24 -0600 | [diff] [blame^] | 77 | void checkPrivilegeMapper(const std::string& groupName); |
Tom Joseph | 536ea32 | 2018-09-14 10:02:20 +0530 | [diff] [blame] | 78 | |
| 79 | /** @brief Check if the privilege level is a valid one |
| 80 | * |
| 81 | * @param[in] privilege - Privilege level |
| 82 | * |
| 83 | * @return throw exception if the conditions are not met. |
| 84 | */ |
Patrick Williams | 9638afb | 2021-02-22 17:16:24 -0600 | [diff] [blame^] | 85 | void checkPrivilegeLevel(const std::string& privilege); |
Tom Joseph | 536ea32 | 2018-09-14 10:02:20 +0530 | [diff] [blame] | 86 | |
Tom Joseph | 0b14c47 | 2018-09-30 01:42:59 +0530 | [diff] [blame] | 87 | /** @brief Construct LDAP mapper entry D-Bus objects from their persisted |
| 88 | * representations. |
| 89 | */ |
| 90 | void restore(); |
| 91 | |
Tom Joseph | 536ea32 | 2018-09-14 10:02:20 +0530 | [diff] [blame] | 92 | private: |
| 93 | /** @brief sdbusplus handler */ |
Patrick Williams | 9638afb | 2021-02-22 17:16:24 -0600 | [diff] [blame^] | 94 | sdbusplus::bus::bus& bus; |
Tom Joseph | 536ea32 | 2018-09-14 10:02:20 +0530 | [diff] [blame] | 95 | |
| 96 | /** @brief object path for the manager object*/ |
| 97 | const std::string path; |
| 98 | |
Tom Joseph | f5bd891 | 2018-11-19 09:49:21 +0530 | [diff] [blame] | 99 | /** @brief serialization directory path */ |
| 100 | std::string persistPath; |
| 101 | |
Tom Joseph | 536ea32 | 2018-09-14 10:02:20 +0530 | [diff] [blame] | 102 | /** @brief available privileges container */ |
Richard Marian Thomaiyar | 32be296 | 2019-11-08 17:21:53 +0530 | [diff] [blame] | 103 | std::set<std::string> privMgr = { |
| 104 | "priv-admin", |
| 105 | "priv-operator", |
| 106 | "priv-user", |
raviteja-b | fe720ff | 2020-01-31 03:38:23 -0600 | [diff] [blame] | 107 | "priv-noaccess", |
Richard Marian Thomaiyar | 32be296 | 2019-11-08 17:21:53 +0530 | [diff] [blame] | 108 | }; |
Tom Joseph | 536ea32 | 2018-09-14 10:02:20 +0530 | [diff] [blame] | 109 | |
| 110 | /** @brief Id of the last privilege mapper entry */ |
| 111 | Id entryId = 0; |
| 112 | |
| 113 | /** @brief container to hold privilege mapper objects */ |
| 114 | std::map<Id, std::unique_ptr<phosphor::user::LDAPMapperEntry>> |
| 115 | PrivilegeMapperList; |
| 116 | }; |
| 117 | |
| 118 | } // namespace user |
| 119 | } // namespace phosphor |